Answer in brief
CVE-2026-72107 records a Unknown severity vulnerability in dm era: fix out-of-bounds memory access for non-zero start sector. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2026-72107 records a Unknown severity vulnerability in dm era: fix out-of-bounds memory access for non-zero start sector. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=eec40579d84873dfb7021eb24c50360f073237c5 <fe94a0b14010a3c267ff9a2508afb4f27ff1c5bf || >=eec40579d84873dfb7021eb24c50360f073237c5 <e3ffa8e492e5cdee62d916ee3e9244ccce2b73c5 || >=eec40579d84873dfb7021eb24c50360f073237c5 <9946a7176bd8c25ddd6e5f1799c54e572ee6bf0f || >=eec40579d84873dfb7021eb24c50360f073237c5 <7e1822f83c5a1ee7b4a19e98edde8770a10b4c71 || >=eec40579d84873dfb7021eb24c50360f073237c5 <db5f9b4601f0012038e5a2628aedec2f47933380 || >=eec40579d84873dfb7021eb24c50360f073237c5 <1fcb5e29dd7a5b85adb9d8b539911741d878e829 || >=eec40579d84873dfb7021eb24c50360f073237c5 <bafe3e720cdac38cd7ea4eb7852a8f2dbe1bbfe6 || >=eec40579d84873dfb7021eb24c50360f073237c5 <a868196f03c2b19418ae3d2b69e195d668a271e5 | fe94a0b14010a3c267ff9a2508afb4f27ff1c5bf, e3ffa8e492e5cdee62d916ee3e9244ccce2b73c5, 9946a7176bd8c25ddd6e5f1799c54e572ee6bf0f, 7e1822f83c5a1ee7b4a19e98edde8770a10b4c71, db5f9b4601f0012038e5a2628aedec2f47933380, 1fcb5e29dd7a5b85adb9d8b539911741d878e829, bafe3e720cdac38cd7ea4eb7852a8f2dbe1bbfe6, a868196f03c2b19418ae3d2b69e195d668a271e5 |
| Linux/Linuxgeneric | 3.15 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: dm era: fix out-of-bounds memory access for non-zero start sector dm-era tracks writes in target-relative blocks, but era_map() calculates the writeset block before applying the target offset. Tables with a non-zero start sector can therefore pass an absolute mapped-device block to metadata_current_marked(). If the absolute block is beyond the current writeset size, writeset_marked() tests past the end of the in-core bitset. KASAN reports this as a vmalloc-out-of-bounds access. Apply the target offset before calculating the era block so writeset lookups use the target-relative block number.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=eec40579d84873dfb7021eb24c50360f073237c5 <fe94a0b14010a3c267ff9a2508afb4f27ff1c5bf || >=eec40579d84873dfb7021eb24c50360f073237c5 <e3ffa8e492e5cdee62d916ee3e9244ccce2b73c5 || >=eec40579d84873dfb7021eb24c50360f073237c5 <9946a7176bd8c25ddd6e5f1799c54e572ee6bf0f || >=eec40579d84873dfb7021eb24c50360f073237c5 <7e1822f83c5a1ee7b4a19e98edde8770a10b4c71 || >=eec40579d84873dfb7021eb24c50360f073237c5 <db5f9b4601f0012038e5a2628aedec2f47933380 || >=eec40579d84873dfb7021eb24c50360f073237c5 <1fcb5e29dd7a5b85adb9d8b539911741d878e829 || >=eec40579d84873dfb7021eb24c50360f073237c5 <bafe3e720cdac38cd7ea4eb7852a8f2dbe1bbfe6 || >=eec40579d84873dfb7021eb24c50360f073237c5 <a868196f03c2b19418ae3d2b69e195d668a271e5 | fe94a0b14010a3c267ff9a2508afb4f27ff1c5bf, e3ffa8e492e5cdee62d916ee3e9244ccce2b73c5, 9946a7176bd8c25ddd6e5f1799c54e572ee6bf0f, 7e1822f83c5a1ee7b4a19e98edde8770a10b4c71, db5f9b4601f0012038e5a2628aedec2f47933380, 1fcb5e29dd7a5b85adb9d8b539911741d878e829, bafe3e720cdac38cd7ea4eb7852a8f2dbe1bbfe6, a868196f03c2b19418ae3d2b69e195d668a271e5 |
| Linux/Linuxgeneric | 3.15 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: dm era: fix out-of-bounds memory access for non-zero start sector dm-era tracks writes in target-relative blocks, but era_map() calculates the writeset block before applying the target offset. Tables with a non-zero start sector can therefore pass an absolute mapped-device block to metadata_current_marked(). If the absolute block is beyond the current writeset size, writeset_marked() tests past the end of the in-core bitset. KASAN reports this as a vmalloc-out-of-bounds access. Apply the target offset before calculating the era block so writeset lookups use the target-relative block number.
Quoted source text, attributed separately from HOL analysis.