CVE-2026-19617

NameCVE-2026-19617
DescriptionA flaw was found in libdm. A local attacker could craft a malicious Logical Volume Manager (LVM) metadata configuration with deeply nested structures. This could lead to uncontrolled recursion in the libdm configuration file parser, exhausting the stack and causing any LVM command reading the metadata to crash. This vulnerability results in a Denial of Service (DoS) for affected systems.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
lvm2 (PTS)bullseye2.03.11-2.1vulnerable
bookworm2.03.16-2vulnerable
forky, sid, trixie2.03.31-2vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
lvm2source(unstable)(unfixed)

Notes

https://bugzilla.redhat.com/show_bug.cgi?id=2514626

Search for package or bug name: Reporting problems