CVE-2026-43132 PUBLISHED

dm-verity: correctly handle dm_bufio_client_create() failure

Assigner: Linux
Reserved: 01.05.2026 Published: 06.05.2026 Updated: 06.05.2026

In the Linux kernel, the following vulnerability has been resolved:

dm-verity: correctly handle dm_bufio_client_create() failure

If either of the calls to dm_bufio_client_create() in verity_fec_ctr() fails, then dm_bufio_client_destroy() is later called with an ERR_PTR() argument. That causes a crash. Fix this.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from a739ff3f543afbb4a041c16cd0182c8e8d366e70 to 6283e49af87a9c121bb01e5a64a7fe5706c210bc (excl.)
  • affected from a739ff3f543afbb4a041c16cd0182c8e8d366e70 to d3e1f1adc8a0289efe2d2cdc90edb8c6ffe0b5ef (excl.)
  • affected from a739ff3f543afbb4a041c16cd0182c8e8d366e70 to 5c2217ddb3b7e7ac25f4ebe9061258fc8f1c9167 (excl.)
  • affected from a739ff3f543afbb4a041c16cd0182c8e8d366e70 to 031f2adc1499b112a39ac316bbab3c80bba16cf2 (excl.)
  • affected from a739ff3f543afbb4a041c16cd0182c8e8d366e70 to 9b8dc1d327e2928f3da59ced0595d850d31c0936 (excl.)
  • affected from a739ff3f543afbb4a041c16cd0182c8e8d366e70 to 451cc650e40e8c3222d37877a9e4be0fcaacb9c8 (excl.)
  • affected from a739ff3f543afbb4a041c16cd0182c8e8d366e70 to b154a868a3856fb5216c4f82981d8a503832e095 (excl.)
  • affected from a739ff3f543afbb4a041c16cd0182c8e8d366e70 to 119f4f04186fa4f33ee6bd39af145cdaff1ff17f (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 4.5 is affected
  • unaffected from 0 to 4.5 (excl.)
  • unaffected from 5.10.252 to 5.10.* (incl.)
  • unaffected from 5.15.202 to 5.15.* (incl.)
  • unaffected from 6.1.165 to 6.1.* (incl.)
  • unaffected from 6.6.128 to 6.6.* (incl.)
  • unaffected from 6.12.75 to 6.12.* (incl.)
  • unaffected from 6.18.16 to 6.18.* (incl.)
  • unaffected from 6.19.6 to 6.19.* (incl.)
  • unaffected from 7.0 to * (incl.)

References