block: recompute nr_integrity_segments in blk_insert_cloned_request
Published Jul 24, 2026
9.8
CRITICALCVSS 3.1
EPSS 0.46%
Description
blk_insert_cloned_request() already recomputes nr_phys_segments against the bottom queue, because "the queue settings related to segment counting may differ from the original queue." The exact same reasoning applies to integrity segments: a stacked driver's underlying queue can have tighter virt_boundary_mask, seg_boundary_mask, or max_segment_size than the top queue, in which case blk_rq_count_integrity_sg() against the bottom queue produces a different count than the cached rq->nr_integrity_segments inherited from the source request by blk_rq_prep_clone().
When the cached count is lower than the bottom queue's actual count, blk_rq_map_integrity_sg() trips
BUG_ON(segments > rq->nr_integrity_segments);
on dispatch. The same families of stacked setups that motivated the existing nr_phys_segments recompute -- dm-multipath fanning out to nvme-rdma in particular -- can produce this.
Mirror the nr_phys_segments handling: when the request carries integrity, recompute nr_integrity_segments against the bottom queue and reject the request if it exceeds the bottom queue's max_integrity_segments. blk_rq_count_integrity_sg() and queue_max_integrity_segments() are both already available via <linux/blk-integrity.h>, which blk-mq.c includes.
This closes a latent gap in the stacking contract and brings the integrity-segment accounting in line with the existing phys-segment accounting.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 6.12StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<6.12
- Version 6.12.92StatusunaffectedConstraints<=6.12.*
- Version 6.18.34StatusunaffectedConstraints<=6.18.*
- Version 7.0.11StatusunaffectedConstraints<=7.0.*
- Version 7.1StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
- ≥ 6.12 · < 6.12.92
- ≥ 6.13 · < 6.18.34
- ≥ 6.19 · < 7.0.11
- 7.1
- 7.1
- 7.1
No data.
Red Hat Enterprise Linux 10
kernel
Fix deferred
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Fix deferred
Red Hat Enterprise Linux 9
kernel-rt
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (10)
- https://access.redhat.com/security/cve/CVE-2026-64232 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2506791 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-48640 Advisory
- https://git.kernel.org/stable/c/0943f81e1b3176f27dbaf6db268fc69d8a94f0ba Patch
- https://git.kernel.org/stable/c/2c6e6a18a37b905cb584eb0dda3ae482162a81ca Patch
- https://git.kernel.org/stable/c/42929c98d044f126508baf54a65b0f87f932fa75 Patch
- https://git.kernel.org/stable/c/53a01bcc0242590eda4c452a5bd996f62457113b Patch
- https://lore.kernel.org/linux-cve-announce/2026072419-CVE-2026-64232-51ea@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2026-64232
- https://www.cve.org/CVERecord?id=CVE-2026-64232
Change history (0)
No recorded changes yet.