What is CVE-2026-19617?
CVE-2026-19617 is a vulnerability in libdm where a local attacker can craft malicious LVM metadata with deeply nested structures. This triggers uncontrolled recursion in the parser, exhausting the stack and disrupting LVM commands reading the metadata. Users should ensure LVM metadata is obtained from trusted sources.
Azərbaycanca: CVE-2026-19617 libdm kitabxanasında tapılan boşluqdur. Lokal təcavüzkar dərin iç-içə strukturlara malik zərərli LVM metadata konfiqurasiyası yaradaraq stack tükənməsinə səbəb ola bilər. Təsirə məruz qalmamaq üçün LVM əmrlərini yalnız etibarlı metadata ilə işlətmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400
FAQ1
How can a local attacker exploiting CVE-2026-19617 cause stack exhaustion?
A local attacker can craft malicious LVM metadata with deeply nested structures, triggering uncontrolled recursion in the libdm parser and exhausting the stack.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.