cbcvebase.
CVE-2026-46294
published 2026-06-08

CVE-2026-46294: In the Linux kernel, the following vulnerability has been resolved: dm: fix a buffer overflow in ioctl processing Tony Asleson (using Claude) found a buffer…

PriorityP344high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.14%
4.0th percentile
In the Linux kernel, the following vulnerability has been resolved: dm: fix a buffer overflow in ioctl processing Tony Asleson (using Claude) found a buffer overflow in dm-ioctl in the function retrieve_status: 1. The code in retrieve_status checks that the output string fits into the output buffer and writes the output string there 2. Then, the code aligns the "outptr" variable to the next 8-byte boundary: outptr = align_ptr(outptr); 3. The alignment doesn't check overflow, so outptr could point past the buffer end 4. The "for" loop is iterated again, it executes: remaining = len - (outptr - outbuf); 5. If "outptr" points past "outbuf + len", the arithmetics wraps around and the variable "remaining" contains unusually high number 6. With "remaining" being high, the code writes more data past the end of the buffer Luckily, this bug has no security implications because: 1. Only root can issue device mapper ioctls 2. The commonly used libraries that communicate with device mapper (libdevmapper and devicemapper-rs) use buffer size that is aligned to 8 bytes - thus, "outptr = align_ptr(outptr)" can't overshoot the input buffer and the bug can't happen accidentally

Affected

51 ranges· showing 25
VendorProductVersion rangeFixed in
linuxlinux
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < c8c5311237448f6ffeecc9aec2362e3692623668c8c5311237448f6ffeecc9aec2362e3692623668
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 448ee8fb79c26a26599ffa4b2adeb4322d3d3d8c448ee8fb79c26a26599ffa4b2adeb4322d3d3d8c
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 526ff9126a0ae087b65726e1faf31114c718020d526ff9126a0ae087b65726e1faf31114c718020d
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < f0b0b09d9840838ae77ccdd6a62de0daef4e6e0af0b0b09d9840838ae77ccdd6a62de0daef4e6e0a
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < d271631023cbe1cbe7c31a0275ab797883be6e0ad271631023cbe1cbe7c31a0275ab797883be6e0a
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 5af6a879e915ae7bcd83695c316ebb32e1c61bc25af6a879e915ae7bcd83695c316ebb32e1c61bc2
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 8daa6c708ef524089ae43f2aed9190acb26d7df88daa6c708ef524089ae43f2aed9190acb26d7df8
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 2fa49cc884f6496a915c35621ba4da35649bf1592fa49cc884f6496a915c35621ba4da35649bf159
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 2.6.12.1 < 5.10.2585.10.258
linuxlinux_kernel>= 5.11 < 5.15.2095.15.209
linuxlinux_kernel>= 5.16 < 6.1.1756.1.175
linuxlinux_kernel>= 6.13 < 6.18.306.18.30
linuxlinux_kernel>= 6.19 < 7.0.77.0.7
linuxlinux_kernel>= 6.2 < 6.6.1406.6.140
linuxlinux_kernel>= 6.7 < 6.12.886.12.88
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-5.15

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_ubuntu7.1HIGH
vendor_redhat7.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.