memstick: ms_block: reject a card that reports too many blocks

Summary

CVECVE-2026-68478
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-08-15 06:20:47 UTC
Updated2026-08-17 06:17:57 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: memstick: ms_block: reject a card that reports too many blocks msb_ftl_initialize() computes the zone count from the card block count with no bound: msb->zone_count = msb->block_count / MS_BLOCKS_IN_ZONE; ... for (i = 0; i < msb->zone_count; i++) msb->free_block_count[i] = MS_BLOCKS_IN_ZONE; msb->block_count is a card value. msb_read_boot_blocks() reads number_of_blocks from the card boot page and byte swaps it. free_block_count is a fixed int[MS_MAX_ZONES]. MS_MAX_ZONES is 16, so the valid indices are 0 to 15. The init loop above indexes it by zone_count. msb_mark_block_used() and msb_mark_block_unused() index it by pba / MS_BLOCKS_IN_ZONE, for pba up to block_count - 1. A card may report up to 65535 blocks. A block_count above 8192 (MS_MAX_ZONES * MS_BLOCKS_IN_ZONE) lets the pba index reach 16. That writes past free_block_count[] and corrupts struct msb_data. A larger count runs the init loop past the end too. A real Memory Stick has at most 16 zones. So it has at most 8192 blocks. msb_ftl_initialize() now rejects a card that reports more than MS_MAX_ZONES * MS_BLOCKS_IN_ZONE blocks.

Risk And Classification

EPSS: 0.002100000 probability, percentile 0.115390000 (date 2026-08-17)

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 0ab30494bc4f3bc1ea4659b7c5d97c5218554a63 a4b9961efe8640f50800811b4a2b2046b3dc2ccc git Not specified
CNA Linux Linux affected 0ab30494bc4f3bc1ea4659b7c5d97c5218554a63 8937b11f1c3896e066c3fb07387ba17bc8c50b8a git Not specified
CNA Linux Linux affected 0ab30494bc4f3bc1ea4659b7c5d97c5218554a63 f1c675ecf6e5ad02722f0019f729d8bb588d502e git Not specified
CNA Linux Linux affected 0ab30494bc4f3bc1ea4659b7c5d97c5218554a63 d5db3439ee8d1c165a09a47e984c4ba508c130df git Not specified
CNA Linux Linux affected 0ab30494bc4f3bc1ea4659b7c5d97c5218554a63 b86666ac4009a252501cc17242582a7ec9ed976e git Not specified
CNA Linux Linux affected 0ab30494bc4f3bc1ea4659b7c5d97c5218554a63 39151f0708c84221e94cdd6aa070aba5d7cb1c01 git Not specified
CNA Linux Linux affected 0ab30494bc4f3bc1ea4659b7c5d97c5218554a63 47f0c7d856c67c9935546d2644f18c0d0131b449 git Not specified
CNA Linux Linux affected 0ab30494bc4f3bc1ea4659b7c5d97c5218554a63 718178f524b98bc920d74bc771aed823c8b81425 git Not specified
CNA Linux Linux affected 3.12 Not specified
CNA Linux Linux unaffected 3.12 semver Not specified
CNA Linux Linux unaffected 5.10.261 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.212 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.178 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.145 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.97 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.40 6.18.* semver Not specified
CNA Linux Linux unaffected 7.1.5 7.1.* semver Not specified
CNA Linux Linux unaffected 7.2 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/f1c675ecf6e5ad02722f0019f729d8bb588d502e 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/a4b9961efe8640f50800811b4a2b2046b3dc2ccc 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/d5db3439ee8d1c165a09a47e984c4ba508c130df 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/39151f0708c84221e94cdd6aa070aba5d7cb1c01 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/8937b11f1c3896e066c3fb07387ba17bc8c50b8a 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/b86666ac4009a252501cc17242582a7ec9ed976e 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/718178f524b98bc920d74bc771aed823c8b81425 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/47f0c7d856c67c9935546d2644f18c0d0131b449 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report