{"id":"CVE-2026-68478","summary":"memstick: ms_block: reject a card that reports too many blocks","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nmemstick: ms_block: reject a card that reports too many blocks\n\nmsb_ftl_initialize() computes the zone count from the card block count\nwith no bound:\n\n\tmsb-\u003ezone_count = msb-\u003eblock_count / MS_BLOCKS_IN_ZONE;\n\t...\n\tfor (i = 0; i \u003c msb-\u003ezone_count; i++)\n\t\tmsb-\u003efree_block_count[i] = MS_BLOCKS_IN_ZONE;\n\nmsb-\u003eblock_count is a card value. msb_read_boot_blocks() reads\nnumber_of_blocks from the card boot page and byte swaps it.\nfree_block_count is a fixed int[MS_MAX_ZONES]. MS_MAX_ZONES is 16, so the\nvalid indices are 0 to 15. The init loop above indexes it by zone_count.\nmsb_mark_block_used() and msb_mark_block_unused() index it by\npba / MS_BLOCKS_IN_ZONE, for pba up to block_count - 1. A card may report\nup to 65535 blocks. A block_count above 8192 (MS_MAX_ZONES *\nMS_BLOCKS_IN_ZONE) lets the pba index reach 16. That writes past\nfree_block_count[] and corrupts struct msb_data. A larger count runs the\ninit loop past the end too.\n\nA real Memory Stick has at most 16 zones. So it has at most 8192 blocks.\nmsb_ftl_initialize() now rejects a card that reports more than\nMS_MAX_ZONES * MS_BLOCKS_IN_ZONE blocks.","modified":"2026-08-18T03:31:01.717651174Z","published":"2026-08-15T05:51:33.441Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68478.json","cna_assigner":"Linux"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/39151f0708c84221e94cdd6aa070aba5d7cb1c01"},{"type":"WEB","url":"https://git.kernel.org/stable/c/47f0c7d856c67c9935546d2644f18c0d0131b449"},{"type":"WEB","url":"https://git.kernel.org/stable/c/718178f524b98bc920d74bc771aed823c8b81425"},{"type":"WEB","url":"https://git.kernel.org/stable/c/8937b11f1c3896e066c3fb07387ba17bc8c50b8a"},{"type":"WEB","url":"https://git.kernel.org/stable/c/a4b9961efe8640f50800811b4a2b2046b3dc2ccc"},{"type":"WEB","url":"https://git.kernel.org/stable/c/b86666ac4009a252501cc17242582a7ec9ed976e"},{"type":"WEB","url":"https://git.kernel.org/stable/c/d5db3439ee8d1c165a09a47e984c4ba508c130df"},{"type":"WEB","url":"https://git.kernel.org/stable/c/f1c675ecf6e5ad02722f0019f729d8bb588d502e"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68478.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-68478"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"0ab30494bc4f3bc1ea4659b7c5d97c5218554a63"},{"fixed":"a4b9961efe8640f50800811b4a2b2046b3dc2ccc"},{"fixed":"8937b11f1c3896e066c3fb07387ba17bc8c50b8a"},{"fixed":"f1c675ecf6e5ad02722f0019f729d8bb588d502e"},{"fixed":"d5db3439ee8d1c165a09a47e984c4ba508c130df"},{"fixed":"b86666ac4009a252501cc17242582a7ec9ed976e"},{"fixed":"39151f0708c84221e94cdd6aa070aba5d7cb1c01"},{"fixed":"47f0c7d856c67c9935546d2644f18c0d0131b449"},{"fixed":"718178f524b98bc920d74bc771aed823c8b81425"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68478.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.12.0"},{"fixed":"5.10.261"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.212"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.178"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.145"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.97"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.40"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.1.5"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68478.json"}}],"schema_version":"1.9.0"}