Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Avoid importing LVM physical volumes from untrusted sources without first inspecting the metadata. Systems using LVM on shared or externally-attached storage should ensure that only trusted administrators can write to the underlying block devices.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 14 Aug 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in libdm. A remote attacker could craft a malicious Logical Volume Manager (LVM) metadata configuration with deeply nested structures. This could lead to uncontrolled recursion in the libdm configuration file parser, exhausting the stack and causing any LVM command reading the metadata to crash. This vulnerability results in a Denial of Service (DoS) for affected systems. | A flaw was found in libdm. A local attacker could craft a malicious Logical Volume Manager (LVM) metadata configuration with deeply nested structures. This could lead to uncontrolled recursion in the libdm configuration file parser, exhausting the stack and causing any LVM command reading the metadata to crash. This vulnerability results in a Denial of Service (DoS) for affected systems. |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Fri, 14 Aug 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in libdm. A remote attacker could craft a malicious Logical Volume Manager (LVM) metadata configuration with deeply nested structures. This could lead to uncontrolled recursion in the libdm configuration file parser, exhausting the stack and causing any LVM command reading the metadata to crash. This vulnerability results in a Denial of Service (DoS) for affected systems. | |
| Title | Libdm: lvm2: libdm: denial of service via uncontrolled recursion in config parser | |
| First Time appeared |
Redhat
Redhat enterprise Linux Redhat hummingbird Redhat openshift |
|
| Weaknesses | CWE-770 | |
| CPEs | cpe:/a:redhat:hummingbird:1 cpe:/a:redhat:openshift:4 cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux Redhat hummingbird Redhat openshift |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-08-14T07:09:52.646Z
Reserved: 2026-08-12T13:42:07.874Z
Link: CVE-2026-19617
No data.
Status : Received
Published: 2026-08-14T06:17:14.410
Modified: 2026-08-14T08:17:37.933
Link: CVE-2026-19617
No data.
OpenCVE Enrichment
Updated: 2026-08-14T08:30:04Z