CVE-2026-68478
CVE CVE-2026-68478EUVD EUVD-2026-59100Veröffentlicht 2026-08-15T05:51:33.000ZZuletzt geändert 2026-08-17T05:06:21.000Z
Was das Advisory beschreibt
In the Linux kernel, the following vulnerability has been resolved: memstick: ms_block: reject a card that reports too many blocks msb_ftl_initialize() computes the zone count from the card block count with no bound: msb->zone_count = msb->block_count / MS_BLOCKS_IN_ZONE; ... for (i = 0; i < msb->zone_count; i++) msb->free_block_count[i] = MS_BLOCKS_IN_ZONE; msb->block_count is a card value. msb_read_boot_blocks() reads number_of_blocks from the card boot page and byte swaps it. free_block_count is a fixed int[MS_MAX_ZONES]. MS_MAX_ZONES is 16, so the valid indices are 0 to 15. The init loop above indexes it by zone_count. msb_mark_block_used() and msb_mark_block_unused() index it by pba / MS_BLOCKS_IN_ZONE, for pba up to block_count - 1. A card may report up to 65535 blocks. A block_count above 8192 (MS_MAX_ZONES * MS_BLOCKS_IN_ZONE) lets the pba index reach 16. That writes past free_block_count[] and corrupts struct msb_data. A larger count runs the init loop past the end too. A real Memory Stick has at most 16 zones. So it has at most 8192 blocks. msb_ftl_initialize() now rejects a card that reports more than MS_MAX_ZONES * MS_BLOCKS_IN_ZONE blocks.
Quelle: EUVD (ENISA), im Wortlaut der Meldung.
Produkte, die das Advisory nennt
Diese Angaben stammen aus der Meldung selbst, nicht aus einer Prüfung durch uns.
- Linux — Linux 0ab30494bc4f3bc1ea4659b7c5d97c5218554a63 <718178f524b98bc920d74bc771aed823c8b81425; patch: 7.1.5; patch: 6.18.40; 3.12; patch: 6.6.145; patch: 7.2; 0ab30494bc4f3bc1ea4659b7c5d97c5218554a63 <8937b11f1c3896e066c3fb07387ba17bc8c50b8a; 0ab30494bc4f3bc1ea4659b7c5d97c5218554a63 <b86666ac4009a252501cc17242582a7ec9ed976e; patch: 6.12.97; 0ab30494bc4f3bc1ea4659b7c5d97c5218554a63 <a4b9961efe8640f50800811b4a2b2046b3dc2ccc; 0ab30494bc4f3bc1ea4659b7c5d97c5218554a63 <d5db3439ee8d1c165a09a47e984c4ba508c130df; patch: 5.10.261; patch: 0; 0ab30494bc4f3bc1ea4659b7c5d97c5218554a63 <47f0c7d856c67c9935546d2644f18c0d0131b449; 0ab30494bc4f3bc1ea4659b7c5d97c5218554a63 <39151f0708c84221e94cdd6aa070aba5d7cb1c01; patch: 6.1.178; 0ab30494bc4f3bc1ea4659b7c5d97c5218554a63 <f1c675ecf6e5ad02722f0019f729d8bb588d502e; patch: 5.15.212
Die genannten Versionen sind die Angabe der Meldung. Patchlage vergleicht keine Versionsnummern und leitet aus ihnen keine Aussage ab — welche Version installiert ist, muss ein Mensch nachsehen.
Im Produktkatalog geführt
Für diese Produkte kann ein Bestand in Patchlage erfasst werden. Ein Advisory dazu erscheint am Morgen danach im Lagebericht.
- Linux — Linux
Betrifft das einen Ihrer Kundenbestände?
Diese Seite kann die Frage nicht beantworten — sie kennt Ihren Bestand nicht. Wer seine Umgebungen erfasst hat, bekommt die Antwort am Morgen nach der Veröffentlichung, zusammen mit einem Absatz, den er unverändert an den Kunden weitergeben kann.
28 Tage testenPatchlage meldet Treffer und Verdachtsfälle. Zu allem anderen sagt dieses System nichts — weder diese Seite noch der Lagebericht behauptet je, dass ein Bestand sicher ist.