CyberRota Analysis
AI-GeneratedThe vulnerability in the Linux kernel's dm-verity component allows for a buffer overflow during the Forward Error Correction (FEC) calculation, potentially leading to memory corruption. This flaw can be exploited to manipulate the syndrome buffer, which may result in system instability or unauthorized access to sensitive data. Organizations utilizing Linux systems, particularly those relying on dm-verity for data integrity, should prioritize patching this issue to mitigate potential risks.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: dm-verity: fix buffer overflow in FEC calculation There's a buffer overflow in dm-verity-fec: if (neras && *neras <= v->fec->roots) fio->erasures[(*neras)++] = i; This allows *neras to reach roots + 1 (the post-increment pushes it past roots). This value is then passed as no_eras to decode_rs8(). Inside the RS decoder (lib/reed_solomon/decode_rs.c:113-121), the erasure locator polynomial loop writes lambda[j] where j can reach nroots + 1 — one element past the end of lambda[] (which is sized nroots + 1, valid indices 0..nroots). The out-of-bounds write lands on syn[0], corrupting the syndrome buffer.