Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Linux Linux — dm log: fix out-of-bounds write due to region_count overflow
AV AC PR UI S C I A CVSS EPSS %ile KEV
L L L N U H H H 7.8 .0014 3.9 —
AFFECTED
Product Versions Fixed
Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 – —
Linux 2.6.12 – 5.10.258
TIMELINE
Jun 9 Reserved by Linux
Jun 24 Published (CNA: Linux)
Aug 17 RESCORED — CVE-2026-53059 (Linux). CVSS 6.3 → 7.8 (NVD).
Description
In the Linux kernel, the following vulnerability has been resolved:
dm log: fix out-of-bounds write due to region_count overflow
The local variable region_count in create_log_context() is declared as
unsigned int (32-bit), but dm_sector_div_up() returns sector_t (64-bit).
When a device-mapper target has a sufficiently large ti->len with a small
region_size, the division result can exceed UINT_MAX. The truncated
value is then used to calculate bitset_size, causing clean_bits,
sync_bits, and recovering_bits to be allocated far smaller than needed
for the actual number of regions.
Subsequent log operations (log_set_bit, log_clear_bit, log_test_bit) use
region indices derived from the full untruncated region space, causing
out-of-bounds writes to kernel heap memory allocated by vmalloc.
This can be reproduced by creating a mirror target whose region_count
overflows 32 bits:
dmsetup create bigzero --table '0 8589934594 zero'
dmsetup create mymirror --table '0 8589934594 mirror \
core 2 2 nosync 2 /dev/mapper/bigzero 0 \
/dev/mapper/bigzero 0'
The status output confirms the truncation (sync_count=1 instead of
4294967297, because 0x100000001 was truncated to 1):
$ dmsetup status mymirror
0 8589934594 mirror 2 254:1 254:1 1/4294967297 ...
This leads to a kernel crash in core_in_sync:
BUG: scheduling while atomic: (udev-worker)/9150/0x00000000
RIP: 0010:core_in_sync+0x14/0x30 [dm_log]
CR2: 0000000000000008
Fixing recursive fault but reboot is needed!
Fix by widening the local region_count to sector_t and adding an
explicit overflow check before the value is assigned to lc->region_count.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| June 9, 2026 | Reserved | Reserved by Linux |
| June 24, 2026 | Published | Published (CNA: Linux) |
| August 17, 2026 | RESCORED | RESCORED — CVE-2026-53059 (Linux). CVSS 6.3 → 7.8 (NVD). |
Affected
Affected products and packages — 2 rows
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Linux | Linux | — | 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 | — |
| Linux | Linux | — | 2.6.12 | 5.10.258 |
References (20)
- https://access.redhat.com/errata/RHSA-2026:45114 [vendor-advisory, x_refsource_REDHAT]
- https://access.redhat.com/errata/RHSA-2026:45115 [vendor-advisory, x_refsource_REDHAT]
- https://access.redhat.com/errata/RHSA-2026:45116 [vendor-advisory, x_refsource_REDHAT]
- https://access.redhat.com/errata/RHSA-2026:45192 [vendor-advisory, x_refsource_REDHAT]
- https://access.redhat.com/errata/RHSA-2026:47248 [vendor-advisory, x_refsource_REDHAT]
- https://access.redhat.com/errata/RHSA-2026:52649 [vendor-advisory, x_refsource_REDHAT]
- https://access.redhat.com/errata/RHSA-2026:53989 [vendor-advisory, x_refsource_REDHAT]
- https://access.redhat.com/errata/RHSA-2026:55445 [vendor-advisory, x_refsource_REDHAT]
- https://access.redhat.com/errata/RHSA-2026:56574 [vendor-advisory, x_refsource_REDHAT]
- https://access.redhat.com/security/cve/CVE-2026-53059 [vdb-entry, x_refsource_REDHAT]
- https://bugzilla.redhat.com/show_bug.cgi?id=2492277 [issue-tracking, x_refsource_REDHAT]
- https://git.kernel.org/stable/c/12bd5b88e91a02785244ff1d20fb157e96e9cdc8
- https://git.kernel.org/stable/c/3ec74da927b4e171a6fc0e77b1188ba4d019af51
- https://git.kernel.org/stable/c/44ab8875ae4a2842bde2d756bed195d375e0debb
- https://git.kernel.org/stable/c/4ec8323b9f0764a14d532b1ae9b87f8a9fecb867
- https://git.kernel.org/stable/c/b455903eed4558982be0811f5b7f44f6bbc4ff57
- https://git.kernel.org/stable/c/c20e36b7631d83e7535877f08af8b0af72c44b1a
- https://git.kernel.org/stable/c/d4ac87567f86a55c3c92e9a5144dcd943a9772a1
- https://git.kernel.org/stable/c/defe483e47173768c227532694dc78cb65db5f09
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53059.json [x_sadp-csaf-vex]
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-53059 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.