Answer in brief
CVE-2026-89559 records a Unknown severity vulnerability in libnvdimm/labels: Prevent integer overflow in __nd_label_validate(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=564e871aa66f548a947b23808d3140f326381f0c <e057efcc9c71d90099d9ee00bed0748d0e9fd586 || >=564e871aa66f548a947b23808d3140f326381f0c <09e649117c54b7e1c004f22eaa19efbadd9ac856 || >=564e871aa66f548a947b23808d3140f326381f0c <69a734359639fca16a0dd73ab17a34943e76c68b || >=564e871aa66f548a947b23808d3140f326381f0c <037770686126155eafc44501312989e2837b9659 | e057efcc9c71d90099d9ee00bed0748d0e9fd586, 09e649117c54b7e1c004f22eaa19efbadd9ac856, 69a734359639fca16a0dd73ab17a34943e76c68b, 037770686126155eafc44501312989e2837b9659 |
| Linux/Linuxgeneric | 4.13 | Not reported |
Published upstream
Sep 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 11, 2026
In the Linux kernel, the following vulnerability has been resolved: libnvdimm/labels: Prevent integer overflow in __nd_label_validate() The on-media namespace index field nslot is a u32 read from the DIMM label storage area. __nd_label_validate() bounds it against the config area size, but sizeof_namespace_label() returns unsigned, so the product nslot * label_size is evaluated in 32-bit and wraps modulo 2^32 before the comparison. A crafted nslot passes the bound and is then used as the loop trip count in nd_label_data_init(), whose memset() walks off the end of the config_size buffer: an out-of-bounds write. The field is not trusted -- it comes from the medium, or from userspace via ND_CMD_SET_CONFIG_DATA. Evaluate the product in 64-bit so the bound check is exact; conforming labels are unaffected. The check was safe when introduced by commit 4a826c83db4e ("libnvdimm: namespace indices: read and validate"): it multiplied by sizeof(struct nd_namespace_label), a size_t, so on a 64-bit build the product did not wrap. Commit 564e871aa66f ("libnvdimm, label: add v1.2 nvdimm label definitions") narrowed it to 32 bits when the label size became a runtime value read via sizeof_namespace_label().
Quoted source text, attributed separately from HOL analysis.