CVE-2026-72105
Last modified
CVE-2026-72105 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: dm-log: fix a bitset_size overflow on 32bit machines Commit c20e36b7631d ("dm log: fix out-of-bounds write due to region_count overflow") made sure that region_count could fit in an unsigned int. But the bitmap memory isn't allocated based on region_count. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: dm-log: fix a bitset_size overflow on 32bit machines Commit c20e36b7631d ("dm log: fix out-of-bounds write due to region_count overflow") made sure that region_count could fit in an unsigned int. But the bitmap memory isn't allocated based on region_count. It uses bitset_size (a size_t variable). The first step of calculating bitset_size is to set it to region_count, rounded up to a multiple of BITS_PER_LONG. If region_size is less than BITS_PER_LONG smaller than UINT_MAX, it will get rounded up to 2^32. On a 32bit architecture, this will make bitset_size wrap around to 0 and fail, despite region_count being valid. Since bitset_size gets divided by 8, it can hold any valid region_count. It just needs a special case to handle the rollover. If it is 0, the value rolled over, and bitset size should be set to the number of bytes needed to hold 2^32 bits.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 44ab8875ae4a2842bde2d756bed195d375e0debb, < cdc4ddf9db2cb79f4ab86b1a509b7ac21b0b6cf5; >= defe483e47173768c227532694dc78cb65db5f09, < 4b0de5a3ac1fd42acb0dc1f80ac5747e3287d723; >= 3ec74da927b4e171a6fc0e77b1188ba4d019af51, < 567602fa72d57169365cbc589e0b8c3be900636d; >= d4ac87567f86a55c3c92e9a5144dcd943a9772a1, < d05e0edfecf5260e6dddd28b2f0cce02bfc6ed7a; >= 12bd5b88e91a02785244ff1d20fb157e96e9cdc8, < 1c3412b584e1fb6c665ff33ba7259253bc0082cb; >= b455903eed4558982be0811f5b7f44f6bbc4ff57, < e0b0163a65758ec3a2361ae1cea407898c27f21e; >= c20e36b7631d83e7535877f08af8b0af72c44b1a, < 79feb87ab2396d49b9b65e4bb815d33cc71cba47; >= c20e36b7631d83e7535877f08af8b0af72c44b1a, < 9743132a41f4d9d0e54c5f2adcb821b04796bab1; 4ec8323b9f0764a14d532b1ae9b87f8a9fecb867; >= 5.10.258, < 5.10.261; >= 5.15.209, < 5.15.212; >= 6.1.175, < 6.1.178; >= 6.6.141, < 6.6.145; >= 6.12.91, < 6.12.97; >= 6.18.33, < 6.18.40; >= 7.0.10, < 7.1 |
| Linux | Linux | 7.1 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-72105?
How severe is CVE-2026-72105?
How do I fix CVE-2026-72105?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-7210`xml.parsers.expat` and `xml.etree.ElementTree` use insuffic…7.5
- CVE-2026-72100In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2026-72101In the Linux kernel, the following vulnerability has been re…
- CVE-2026-72102In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-72103In the Linux kernel, the following vulnerability has been re…7.3
- CVE-2026-72104In the Linux kernel, the following vulnerability has been re…
- CVE-2026-72106In the Linux kernel, the following vulnerability has been re…
- CVE-2026-72107In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2026-72108In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-72109In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-7211A weakness has been identified in dvladimirov MCP up to 0.1.…7.3
- CVE-2026-72110In the Linux kernel, the following vulnerability has been re…7.8
Are you affected by CVE-2026-72105?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
