CVE-2026-72098
Reported by Linux · Published August 15, 2026
In the Linux kernel, the following vulnerability has been resolved: dm-verity: fix buffer overflow in FEC calculation There's a buffer overflow in dm-verity-fec: if (neras && *neras <= v->fec->roots) fio->erasures[(*neras)++] = i; This allows *neras to reach roots + 1 (the post-increment pushes it past roots). This value is then passed as no_eras to decode_rs8(). Inside the RS decoder (lib/reed_solomon/decode_rs.c:113-121), the erasure locator polynomial loop writes lambda[j] where j can reach nroots + 1 — one element past the end of lambda[] (which is sized nroots + 1, valid indices 0..nroots). The out-of-bounds write lands on syn[0], corrupting the syndrome buffer.
EPSS 0.66% · 50.2th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | a739ff3f543afbb4a041c16cd0182c8e8d366e70, a739ff3f543afbb4a041c16cd0182c8e8d366e70, a739ff3f543afbb4a041c16cd0182c8e8d366e70 |
| Linux | Linux | 4.5, 0, 6.18.42 |
| Linux | Linux | 7.2, a739ff3f543afbb4a041c16cd0182c8e8d366e70, a739ff3f543afbb4a041c16cd0182c8e8d366e70 |
| linux | linux_kernel | 4.5, 4.5, 4.5 |
Timeline
- Aug 15, 2026 Coalition ESS Score
- Aug 15, 2026 CVE Published
- Aug 17, 2026 CVE Updated
- Aug 19, 2026 Security Advisory
- Aug 24, 2026 EPSS Score
- Aug 26, 2026 EPSS Score
- Aug 28, 2026 EPSS Score
- Aug 30, 2026 EPSS Score
- Sep 3, 2026 EPSS Score
- Sep 5, 2026 EPSS Score
- Sep 6, 2026 EPSS Score
- Sep 9, 2026 EPSS Score