CVE-2026-68478: memstick: ms_block: reject a card that reports too many blocks
Greg Kroah-Hartman <[email protected]>
| Newsgroups | org.kernel.vger.linux-cve-announce |
|---|---|
| Message-ID | <2026081506-CVE-2026-68478-8b6c@gregkh> |
From: Greg Kroah-Hartman <[email protected]> Description =========== In the Linux kernel, the following vulnerability has been resolved: memstick: ms_block: reject a card that reports too many blocks msb_ftl_initialize() computes the zone count from the card block count with no bound: msb->zone_count = msb->block_count / MS_BLOCKS_IN_ZONE; ... for (i = 0; i < msb->zone_count; i++) msb->free_block_count[i] = MS_BLOCKS_IN_ZONE; msb->block_count is a card value. msb_read_boot_blocks() reads number_of_blocks from the card boot page and byte swaps it. free_block_count is a fixed int[MS_MAX_ZONES]. MS_MAX_ZONES is 16, so the valid indices are 0 to 15. The init loop above indexes it by zone_count. msb_mark_block_used() and msb_mark_block_unused() index it by pba / MS_BLOCKS_IN_ZONE, for pba up to block_count - 1. A card may report up to 65535 blocks. A block_count above 8192 (MS_MAX_ZONES * MS_BLOCKS_IN_ZONE) lets the pba index reach 16. That writes past free_block_count[] and corrupts struct msb_data. A larger count runs the init loop past the end too. A real Memory Stick has at most 16 zones. So it has at most 8192 blocks. msb_ftl_initialize() now rejects a card that reports more than MS_MAX_ZONES * MS_BLOCKS_IN_ZONE blocks. The Linux kernel CVE team has assigned CVE-2026-68478 to this issue. Affected and fixed versions =========================== Issue introduced in 3.12 with commit 0ab30494bc4f3bc1ea4659b7c5d97c5218554a63 and fixed in 5.10.261 with commit a4b9961efe8640f50800811b4a2b2046b3dc2ccc Issue introduced in 3.12 with commit 0ab30494bc4f3bc1ea4659b7c5d97c5218554a63 and fixed in 5.15.212 with commit 8937b11f1c3896e066c3fb07387ba17bc8c50b8a Issue introduced in 3.12 with commit 0ab30494bc4f3bc1ea4659b7c5d97c5218554a63 and fixed in 6.1.178 with commit f1c675ecf6e5ad02722f0019f729d8bb588d502e Issue introduced in 3.12 with commit 0ab30494bc4f3bc1ea4659b7c5d97c5218554a63 and fixed in 6.6.145 with commit d5db3439ee8d1c165a09a47e984c4ba508c130df Issue introduced in 3.12 with commit 0ab30494bc4f3bc1ea4659b7c5d97c5218554a63 and fixed in 6.12.97 with commit b86666ac4009a252501cc17242582a7ec9ed976e Issue introduced in 3.12 with commit 0ab30494bc4f3bc1ea4659b7c5d97c5218554a63 and fixed in 6.18.40 with commit 39151f0708c84221e94cdd6aa070aba5d7cb1c01 Issue introduced in 3.12 with commit 0ab30494bc4f3bc1ea4659b7c5d97c5218554a63 and fixed in 7.1.5 with commit 47f0c7d856c67c9935546d2644f18c0d0131b449 Issue introduced in 3.12 with commit 0ab30494bc4f3bc1ea4659b7c5d97c5218554a63 and fixed in 7.2-rc4 with commit 718178f524b98bc920d74bc771aed823c8b81425 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-68478 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: drivers/memstick/core/ms_block.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/a4b9961efe8640f50800811b4a2b2046b3dc2ccc https://git.kernel.org/stable/c/8937b11f1c3896e066c3fb07387ba17bc8c50b8a https://git.kernel.org/stable/c/f1c675ecf6e5ad02722f0019f729d8bb588d502e https://git.kernel.org/stable/c/d5db3439ee8d1c165a09a47e984c4ba508c130df https://git.kernel.org/stable/c/b86666ac4009a252501cc17242582a7ec9ed976e https://git.kernel.org/stable/c/39151f0708c84221e94cdd6aa070aba5d7cb1c01 https://git.kernel.org/stable/c/47f0c7d856c67c9935546d2644f18c0d0131b449 https://git.kernel.org/stable/c/718178f524b98bc920d74bc771aed823c8b81425