CVE-2026-19617

A flaw was found in libdm. A local attacker could craft a malicious Logical Volume Manager (LVM) metadata configuration with deeply nested structures. This could lead to uncontrolled recursion in the libdm configuration file parser, exhausting the stack and causing any LVM command reading the metadata to crash. This vulnerability results in a Denial of Service (DoS) for affected systems.
References
Link Resource
https://access.redhat.com/security/cve/CVE-2026-19617 Mitigation Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2514626 Issue Tracking Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:hardened_images:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-14 06:17

Updated : 2026-09-01 13:18


NVD link : CVE-2026-19617

Mitre link : CVE-2026-19617

CVE.ORG link : CVE-2026-19617


JSON object : View

Products Affected

redhat

  • enterprise_linux
  • openshift_container_platform
  • hardened_images
CWE
CWE-770

Allocation of Resources Without Limits or Throttling