CVE-2026-46289: lib/scatterlist: fix length calculations in extract_kvec_to_sg
In the Linux kernel, the following vulnerability has been resolved:
lib/scatterlist: fix length calculations in extractkvectosg
Patch series "Fix bugs in extractitertosg()", v3.
Fix bugs in the kvec and user variants of extractitertosg. This series is growing due to useful remarks made by sashiko.dev.
The main bugs are: - The length for an sglist entry when extracting from a kvec can exceed the number of bytes in the page. This is obviously not intended. - When extracting a user buffer the sglist is temporarily used as a scratch buffer for extracted page pointers. If the sglist already contains some elements this scratch buffer could overlap with existing entries in the sglist.
The series adds test cases to the kunitioviter test that demonstrate all of these bugs. Additionally, there is a memory leak fix for the test itself.
The bugs were orignally introduced into kernel v6.3 where the function lived in fs/netfs/iterator.c. It was later moved to lib/scatterlist.c in v6.5. Thus the actual fix is only marked for backports to v6.5+.
This patch (of 5):
When extracting from a kvec to a scatterlist, do not cross page boundaries. The required length was already calculated but not used as intended.
Adjust the copied length if the loop runs out of sglist entries without extracting everything.
While there, return immediately from extractitertosg if there are no sglist entries at all.
A subsequent commit will add kunit test cases that demonstrate that the patch is necessary.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.6.141.1-1 - Upgrade
Upgrade
lib/scatterlist.cto a version that resolves this vulnerability.Fixed in v6.5+
Event History
Frequently Asked Questions
What is the severity of CVE-2026-46289?
CVE-2026-46289 has been assigned a risk score of 37.
How do I fix CVE-2026-46289?
To fix CVE-2026-46289, it is recommended to update the Linux kernel to the latest patched version.
What components are affected by CVE-2026-46289?
CVE-2026-46289 affects the Linux kernel specifically in the lib/scatterlist module.
What is the nature of the vulnerability in CVE-2026-46289?
CVE-2026-46289 involves incorrect length calculations in the extract_kvec_to_sg function.
When was CVE-2026-46289 published?
CVE-2026-46289 was published on June 8, 2026.