Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-72098

dm-verity: fix buffer overflow in FEC calculation
Back to all
CVE

CVE-2026-72098

dm-verity: fix buffer overflow in FEC calculation

In the Linux kernel, the following vulnerability has been resolved:

dm-verity: fix buffer overflow in FEC calculation

There's a buffer overflow in dm-verity-fec:

if (neras && *neras <= v->fec->roots)

fio->erasures[(*neras)++] = i;

This allows *neras to reach roots + 1 (the post-increment pushes it past

roots). This value is then passed as noeras to decoders8(). Inside the

RS decoder (lib/reedsolomon/decoders.c:113-121), the erasure locator

polynomial loop writes lambda[j] where j can reach nroots + 1 — one

element past the end of lambda[] (which is sized nroots + 1, valid

indices 0..nroots). The out-of-bounds write lands on syn[0], corrupting

the syndrome buffer.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.8
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://git.kernel.org/stable/c/31d6e6c0ba8d5a7bd59660035a089307100c5e8e, https://git.kernel.org/stable/c/5488d3a69d205e28f74f18857b853aa12e778e66, https://git.kernel.org/stable/c/f7990c2b0f08b8841fcd2652d1d7002f5994a7a7, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72098.json, https://nvd.nist.gov/vuln/detail/CVE-2026-72098, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0.00646%
EPSS Percentile
0.48325%
Introduced Version
a739ff3f543afbb4a041c16cd0182c8e8d366e70,4.5.0,6.19.0,0
Fix Available
31d6e6c0ba8d5a7bd59660035a089307100c5e8e,6.18.42,7.1.5

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading