CVE-2026-53059

HIGHNVD 7.87.8
EchelonGraph scoreMEDIUM confidence

This high-severity CVE scores 7.8 under NVD CVSS v3. EPSS exploit probability: 0.1%, top 97% of all CVEs by exploit prediction. GitHub Security Advisory enrichment pending alignment with NVD CVSS.

Triggered by: NVD CVSS baseline
Sources: epss, ghsa, nvd
Trending — 3 sources updated this week
7.8
EchelonGraph verdictPlan a fixSerious severity, but no confirmed exploitation yet.
  • High severity, but no confirmed exploitation yet
CISA-KEV: Not listedEPSS: 0%CVSS: 7.8Exploit: NoneExposed: 0

No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.

In the Linux kernel, the following vulnerability has been resolved:

dm log: fix out-of-bounds write due to region_count overflow

The local variable region_count in create_log_context() is declared as unsigned int (32-bit), but dm_sector_div_up() returns sector_t (64-bit). When a device-mapper target has a sufficiently large ti->len with a small region_size, the division result can exceed UINT_MAX. The truncated value is then used to calculate bitset_size, causing clean_bits, sync_bits, and recovering_bits to be allocated far smaller than needed for the actual number of regions.

Subsequent log operations (log_set_bit, log_clear_bit, log_test_bit) use region indices derived from the full untruncated region space, causing out-of-bounds writes to kernel heap memory allocated by vmalloc.

This can be reproduced by creating a mirror target whose region_count overflows 32 bits:

dmsetup create bigzero --table '0 8589934594 zero' dmsetup create mymirror --table '0 8589934594 mirror \ core 2 2 nosync 2 /dev/mapper/bigzero 0 \ /dev/mapper/bigzero 0'

The status output confirms the truncation (sync_count=1 instead of 4294967297, because 0x100000001 was truncated to 1):

$ dmsetup status mymirror 0 8589934594 mirror 2 254:1 254:1 1/4294967297 ...

This leads to a kernel crash in core_in_sync:

BUG: scheduling while atomic: (udev-worker)/9150/0x00000000 RIP: 0010:core_in_sync+0x14/0x30 [dm_log] CR2: 0000000000000008 Fixing recursive fault but reboot is needed!

Fix by widening the local region_count to sector_t and adding an explicit overflow check before the value is assigned to lc->region_count.

CVSS v3
7.8
EG Score
7.8(medium)
EG Risk
40(Track)
EG Risk 40/100SSVC: Track

EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).

How it’s computed
Severity78% × 45%
Exploitation0% × 40%
Automatability30% × 15%
Action: Routine — remediate on your standard cadence.
EPSS
3.4%
KEV
Not listed

Published

June 24, 2026

Last Modified

July 24, 2026

Advisory Details (10)

Auto-updated Jul 1, 2026
Patch available. Sources: redhat.
redhat

2492277 – (CVE-2026-53059) CVE-2026-53059 kernel: dm log: fix out-of-bounds write due to region_count overflow

https://bugzilla.redhat.com/show_bug.cgi?id=2492277
redhat Patch Available

cve-details

https://access.redhat.com/security/cve/CVE-2026-53059
generic

dm log: fix out-of-bounds write due to region_count overflow - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/defe483e47173768c227532694dc78cb65db5f09
generic

dm log: fix out-of-bounds write due to region_count overflow - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/d4ac87567f86a55c3c92e9a5144dcd943a9772a1
generic

dm log: fix out-of-bounds write due to region_count overflow - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/c20e36b7631d83e7535877f08af8b0af72c44b1a
generic

dm log: fix out-of-bounds write due to region_count overflow - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/b455903eed4558982be0811f5b7f44f6bbc4ff57
generic

dm log: fix out-of-bounds write due to region_count overflow - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/4ec8323b9f0764a14d532b1ae9b87f8a9fecb867
generic

dm log: fix out-of-bounds write due to region_count overflow - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/44ab8875ae4a2842bde2d756bed195d375e0debb
generic

dm log: fix out-of-bounds write due to region_count overflow - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/3ec74da927b4e171a6fc0e77b1188ba4d019af51
generic

dm log: fix out-of-bounds write due to region_count overflow - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/12bd5b88e91a02785244ff1d20fb157e96e9cdc8

Weakness Classification(2)

MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.

Data Freshness Timeline

(refreshed 11× in last 7d / 91× in last 30d)

Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.

  1. 2026-07-25 14:18 UTCEPSS rescore
  2. 2026-07-24 14:18 UTCEPSS rescore
  3. 2026-07-23 14:18 UTCEPSS rescore
  4. 2026-07-23 03:19 UTCEG score recompute 0.80
  5. 2026-07-22 14:08 UTCEPSS rescore
  6. 2026-07-21 19:19 UTCNVD updateCVSS v3 → 7.8 · severity → HIGH
  7. 2026-07-21 15:25 UTCEPSS rescore
  8. 2026-07-20 17:08 UTCEPSS rescore
  9. 2026-07-19 14:31 UTCEPSS rescore
  10. 2026-07-19 14:31 UTCEPSS rescore
  11. 2026-07-19 02:29 UTCEPSS rescore
  12. 2026-07-18 10:04 UTCEPSS rescore
  13. 2026-07-16 21:47 UTCVendor advisory
  14. 2026-07-16 21:47 UTCGHSA enrichment
  15. 2026-07-16 17:03 UTCEPSS rescore
  16. 2026-07-16 09:33 UTCVendor advisory
  17. 2026-07-16 09:33 UTCGHSA enrichment
  18. 2026-07-15 21:18 UTCVendor advisory
  19. 2026-07-15 21:18 UTCGHSA enrichment
  20. 2026-07-15 16:57 UTCEPSS rescore
  21. 2026-07-15 16:57 UTCEPSS rescore
  22. 2026-07-15 09:04 UTCVendor advisory
  23. 2026-07-15 09:04 UTCGHSA enrichment
  24. 2026-07-15 02:00 UTCEPSS rescore
  25. 2026-07-15 02:00 UTCEPSS rescore
Show 69 more
  1. 2026-07-14 20:42 UTCVendor advisory
  2. 2026-07-14 20:42 UTCGHSA enrichment
  3. 2026-07-14 08:19 UTCVendor advisory
  4. 2026-07-14 08:19 UTCGHSA enrichment
  5. 2026-07-13 22:31 UTCEPSS rescore
  6. 2026-07-13 19:58 UTCGHSA enrichment
  7. 2026-07-13 07:44 UTCGHSA enrichment
  8. 2026-07-13 06:13 UTCEPSS rescore
  9. 2026-07-13 06:13 UTCEPSS rescore
  10. 2026-07-12 19:30 UTCVendor advisory
  11. 2026-07-12 19:30 UTCGHSA enrichment
  12. 2026-07-12 07:15 UTCVendor advisory
  13. 2026-07-12 07:15 UTCGHSA enrichment
  14. 2026-07-12 05:46 UTCEPSS rescore
  15. 2026-07-11 18:58 UTCVendor advisory
  16. 2026-07-11 18:58 UTCGHSA enrichment
  17. 2026-07-11 08:27 UTCEPSS rescore
  18. 2026-07-11 08:27 UTCEPSS rescore
  19. 2026-07-11 06:44 UTCVendor advisory
  20. 2026-07-11 06:44 UTCGHSA enrichment
  21. 2026-07-10 18:29 UTCVendor advisory
  22. 2026-07-10 18:29 UTCGHSA enrichment
  23. 2026-07-10 06:15 UTCGHSA enrichment
  24. 2026-07-09 19:10 UTCEPSS rescore
  25. 2026-07-09 19:10 UTCEPSS rescore
  26. 2026-07-09 17:59 UTCGHSA enrichment
  27. 2026-07-09 05:44 UTCGHSA enrichment
  28. 2026-07-08 17:30 UTCGHSA enrichment
  29. 2026-07-08 15:16 UTCEPSS rescore
  30. 2026-07-08 15:16 UTCEPSS rescore
  31. 2026-07-08 05:15 UTCGHSA enrichment
  32. 2026-07-07 17:00 UTCGHSA enrichment
  33. 2026-07-07 13:46 UTCEPSS rescore
  34. 2026-07-07 13:46 UTCEPSS rescore
  35. 2026-07-07 04:45 UTCGHSA enrichment
  36. 2026-07-06 16:30 UTCGHSA enrichment
  37. 2026-07-06 16:27 UTCEPSS rescore
  38. 2026-07-06 16:27 UTCEPSS rescore
  39. 2026-07-06 04:06 UTCGHSA enrichment
  40. 2026-07-06 02:23 UTCEPSS rescore
  41. 2026-07-06 02:23 UTCEPSS rescore
  42. 2026-07-05 15:52 UTCGHSA enrichment
  43. 2026-07-05 03:37 UTCGHSA enrichment
  44. 2026-07-05 02:31 UTCEPSS rescore
  45. 2026-07-05 02:30 UTCEPSS rescore
  46. 2026-07-04 15:22 UTCGHSA enrichment
  47. 2026-07-04 06:31 UTCEPSS rescore
  48. 2026-07-04 03:06 UTCGHSA enrichment
  49. 2026-07-03 14:48 UTCGHSA enrichment
  50. 2026-07-03 02:34 UTCGHSA enrichment
  51. 2026-07-02 16:57 UTCNVD updateCVSS v3 → 6.3 · severity → MEDIUM
  52. 2026-07-02 14:20 UTCGHSA enrichment
  53. 2026-07-02 02:04 UTCGHSA enrichment
  54. 2026-07-01 15:07 UTCEPSS rescore
  55. 2026-07-01 13:49 UTCGHSA enrichment
  56. 2026-07-01 01:34 UTCEG score recompute 7.00
  57. 2026-07-01 01:34 UTCGHSA enrichment
  58. 2026-06-30 23:22 UTCEPSS rescore
  59. 2026-06-30 04:34 UTCNVD updateCVSS v3 → 7 · severity → HIGH
  60. 2026-06-29 14:06 UTCEPSS rescore
  61. 2026-06-29 14:06 UTCEPSS rescore
  62. 2026-06-28 14:07 UTCEPSS rescore
  63. 2026-06-28 04:56 UTCEPSS rescore
  64. 2026-06-28 04:56 UTCEPSS rescore
  65. 2026-06-27 21:55 UTCGHSA enrichment
  66. 2026-06-27 03:08 UTCEPSS rescore
  67. 2026-06-25 13:49 UTCEPSS rescore
  68. 2026-06-24 18:16 UTCEG score recompute
  69. 2026-06-24 18:03 UTCNVD updatefirst tracked

Frequently asked(5)

What is CVE-2026-53059?
CVE-2026-53059 is a high vulnerability published on June 24, 2026. In the Linux kernel, the following vulnerability has been resolved: dm log: fix out-of-bounds write due to region_count overflow The local variable regioncount in createlog_context() is declared as unsigned int (32-bit), but dmsectordivup() returns sectort (64-bit). When a device-mapper target has…
When was CVE-2026-53059 disclosed?
CVE-2026-53059 was first published in the National Vulnerability Database on June 24, 2026, with the most recent update on July 24, 2026. EchelonGraph re-ingests CVE updates from NVD on a 2-hour cycle, so this page reflects the latest published state.
Is CVE-2026-53059 actively exploited?
CVE-2026-53059 is not currently on CISA's Known Exploited Vulnerabilities catalog. FIRST EPSS estimates a 3.4% percentile likelihood of exploitation in the next 30 days — higher percentiles indicate greater predicted risk.
What is the CVSS score of CVE-2026-53059?
CVE-2026-53059 has a CVSS v3 base score of 7.8 (NVD).
How do I remediate CVE-2026-53059?
Patch to the fixed version published by the affected vendor. Where vendor advisories exist for CVE-2026-53059, EchelonGraph cross-links them in the Vendor Advisories panel below — those typically contain the canonical remediation steps, fixed version numbers, and any vendor-specific mitigations.

Dependency Blast Radius

Explore the affected products and dependency analysis for CVE-2026-53059

Explore →

Is Your Infrastructure Affected by CVE-2026-53059?

EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.