CVE-2026-93257: block: handle nogenerate/noverify properly in fs-integrity

Published Sep 24, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

block: handle nogenerate/noverify properly in fs-integrity

Check the BIPCHECK flags before generating or verifying PI information, otherwise this can be incorrectly called for non-PI metadata and cause generation of incorrect metadata and crashed in the verification handler.

The new behavior matches that of the block layer auto-generated metadata.

Affected Software

1 affected component
Linux Linux kernel

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Check the BIP_CHECK flags before generating or verifying protection information (PI) metadata.

    Linux kernel fs-integrity BIP_CHECK flags = check before generating or verifying PI information

Event History

Sep 24, 2026
CVE Published
via MITRE·03:51 PM
Data Sourced
via MITRE·03:51 PM
Description
Data Sourced
via NVD·04:17 PM
Description

Frequently Asked Questions

1

What configurations are exposed to this issue?

Systems using fs-integrity with protection-information handling are affected when BIP_CHECK nogenerate or noverify flags are not honored. The issue involves non-PI metadata being incorrectly sent through PI generation or verification handling.

2

What can happen if the issue is triggered?

Incorrect metadata may be generated, and the verification handler can crash. The description does not state any additional attacker prerequisites or impact beyond this failure mode.

3

How can I determine whether a system needs the fix?

Review whether the running kernel includes either referenced stable commit and whether the deployment uses fs-integrity protection-information metadata handling. The provided data does not identify affected kernel versions.

4

What should be done if patching cannot happen immediately?

The provided information does not specify a workaround. Reducing or avoiding fs-integrity PI operations involving non-PI metadata may limit exposure, but this is not stated as a validated mitigation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203