CVE-2026-46115 (GCVE-0-2026-46115)
Vulnerability from cvelistv5
Published
2026-05-28 09:35
Modified
2026-08-05 12:29
Severity ?
Summary
In the Linux kernel, the following vulnerability has been resolved: block: add pgmap check to biovec_phys_mergeable biovec_phys_mergeable() is used by the request merge, DMA mapping, and integrity merge paths to decide if two physically contiguous bvec segments can be coalesced into one. It currently has no check for whether the segments belong to different dev_pagemaps. When zone device memory is registered in multiple chunks, each chunk gets its own dev_pagemap. A single bio can legitimately contain bvecs from different pgmaps -- iov_iter_extract_bvecs() breaks at pgmap boundaries but the outer loop in bio_iov_iter_get_pages() continues filling the same bio. If such bvecs are physically contiguous, biovec_phys_mergeable() will coalesce them, making it impossible to recover the correct pgmap for the merged segment via page_pgmap(). Add a zone_device_pages_have_same_pgmap() check to prevent merging bvec segments that span different pgmaps.
Impacted products
Vendor Product Version
Linux Linux Version: 49580e690755d0e51ed7aa2c33225dd884fa738a
Version: 49580e690755d0e51ed7aa2c33225dd884fa738a
Version: 49580e690755d0e51ed7aa2c33225dd884fa738a
Version: 49580e690755d0e51ed7aa2c33225dd884fa738a
Version: 49580e690755d0e51ed7aa2c33225dd884fa738a
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "block/blk.h"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "3d2ecbd444b01d6500671d1a582b7393943cf539",
              "status": "affected",
              "version": "49580e690755d0e51ed7aa2c33225dd884fa738a",
              "versionType": "git"
            },
            {
              "lessThan": "a7f3aa8c9df3905fe820ae36b67ba56b81587574",
              "status": "affected",
              "version": "49580e690755d0e51ed7aa2c33225dd884fa738a",
              "versionType": "git"
            },
            {
              "lessThan": "f17d521075325b8afc42d1baa1c28a5e9aca111f",
              "status": "affected",
              "version": "49580e690755d0e51ed7aa2c33225dd884fa738a",
              "versionType": "git"
            },
            {
              "lessThan": "f632dab4b841554cd6416058c61886d7db176581",
              "status": "affected",
              "version": "49580e690755d0e51ed7aa2c33225dd884fa738a",
              "versionType": "git"
            },
            {
              "lessThan": "13920e4b7b784b40cf4519ff1f0f3e513476a499",
              "status": "affected",
              "version": "49580e690755d0e51ed7aa2c33225dd884fa738a",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "block/blk.h"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.2"
            },
            {
              "lessThan": "6.2",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.140",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.88",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.18.*",
              "status": "unaffected",
              "version": "6.18.30",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "7.0.*",
              "status": "unaffected",
              "version": "7.0.7",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.1",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.140",
                  "versionStartIncluding": "6.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.88",
                  "versionStartIncluding": "6.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18.30",
                  "versionStartIncluding": "6.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.0.7",
                  "versionStartIncluding": "6.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.1",
                  "versionStartIncluding": "6.2",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nblock: add pgmap check to biovec_phys_mergeable\n\nbiovec_phys_mergeable() is used by the request merge, DMA mapping,\nand integrity merge paths to decide if two physically contiguous\nbvec segments can be coalesced into one. It currently has no check\nfor whether the segments belong to different dev_pagemaps.\n\nWhen zone device memory is registered in multiple chunks, each chunk\ngets its own dev_pagemap. A single bio can legitimately contain\nbvecs from different pgmaps -- iov_iter_extract_bvecs() breaks at\npgmap boundaries but the outer loop in bio_iov_iter_get_pages()\ncontinues filling the same bio. If such bvecs are physically\ncontiguous, biovec_phys_mergeable() will coalesce them, making it\nimpossible to recover the correct pgmap for the merged segment\nvia page_pgmap().\n\nAdd a zone_device_pages_have_same_pgmap() check to prevent merging\nbvec segments that span different pgmaps."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:N - Reachable via remotely-initiated NVMe-oF (nvmet-tcp/nvmet-rdma) I/O on a P2PDMA-backed namespace; remote read/write commands drive the block-layer merge/SG-mapping path (`biovec_phys_mergeable`) over P2P buffers on the target.\nAC:L - Adjacent chunks of multi-chunk P2P/zone-device memory are physically contiguous, so the missing pgmap check makes the bad coalesce occur deterministically once such memory backs the I/O; repeated/large I/O reliably straddles a pgmap boundary.\nPR:N - NVMe-oF targets are commonly deployed without in-band cryptographic authentication, so a connected (unauthenticated) initiator can issue the I/O that reaches the vulnerable path.\nUI:N - Exploitation requires only that the attacker issue normal I/O commands; no victim/administrator interaction is needed.\nS:U - The corruption stays within the kernel\u0027s own block/DMA handling and adjacent device memory; it does not cross into a separately-managed security authority such as a VM host.\nC:H - A misdirected DMA on a read maps the spillover pages to the wrong pgmap\u0027s bus address, so data from unrelated device memory can be returned to the attacker \u2014 an arbitrary-read/disclosure-class primitive.\nI:H - A misdirected DMA on a write transfers data to the wrong physical/device address, corrupting unrelated device or host memory \u2014 an out-of-bounds write primitive.\nA:H - Wrong/invalid DMA bus addresses cause IOMMU faults, device errors, and kernel oops/hangs, crashing the I/O path or the system."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T12:29:47.285Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/3d2ecbd444b01d6500671d1a582b7393943cf539"
        },
        {
          "url": "https://git.kernel.org/stable/c/a7f3aa8c9df3905fe820ae36b67ba56b81587574"
        },
        {
          "url": "https://git.kernel.org/stable/c/f17d521075325b8afc42d1baa1c28a5e9aca111f"
        },
        {
          "url": "https://git.kernel.org/stable/c/f632dab4b841554cd6416058c61886d7db176581"
        },
        {
          "url": "https://git.kernel.org/stable/c/13920e4b7b784b40cf4519ff1f0f3e513476a499"
        }
      ],
      "title": "block: add pgmap check to biovec_phys_mergeable",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-46115",
    "datePublished": "2026-05-28T09:35:26.735Z",
    "dateReserved": "2026-05-13T15:03:33.098Z",
    "dateUpdated": "2026-08-05T12:29:47.285Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…