Action not permitted
Modal body text goes here.
Modal Title
Modal Body
CERTFR-2026-AVI-1069
Vulnerability from certfr_avis
De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Elles permettent à un attaquant de provoquer une élévation de privilèges, une atteinte à la confidentialité des données et un déni de service.
Solutions
Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).
Impacted products
References
| Title | Publication Time | Tags | |||
|---|---|---|---|---|---|
|
|||||
{
"$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
"affected_systems": [
{
"description": "Debian 12 bookworm versions ant\u00e9rieures \u00e0 6.12.101-1~deb12u1",
"product": {
"name": "Debian",
"vendor": {
"name": "Debian",
"scada": false
}
}
}
],
"affected_systems_content": "",
"content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
"cves": [
{
"name": "CVE-2026-68116",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68116"
},
{
"name": "CVE-2026-68147",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68147"
},
{
"name": "CVE-2026-68343",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68343"
},
{
"name": "CVE-2026-68450",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68450"
},
{
"name": "CVE-2026-68271",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68271"
},
{
"name": "CVE-2026-64561",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64561"
},
{
"name": "CVE-2026-72051",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72051"
},
{
"name": "CVE-2026-68416",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68416"
},
{
"name": "CVE-2026-68193",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68193"
},
{
"name": "CVE-2026-68388",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68388"
},
{
"name": "CVE-2026-68204",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68204"
},
{
"name": "CVE-2026-68302",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68302"
},
{
"name": "CVE-2026-68141",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68141"
},
{
"name": "CVE-2026-68225",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68225"
},
{
"name": "CVE-2026-53090",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-53090"
},
{
"name": "CVE-2026-68339",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68339"
},
{
"name": "CVE-2026-68439",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68439"
},
{
"name": "CVE-2026-68218",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68218"
},
{
"name": "CVE-2026-68129",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68129"
},
{
"name": "CVE-2026-68245",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68245"
},
{
"name": "CVE-2026-68428",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68428"
},
{
"name": "CVE-2026-68313",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68313"
},
{
"name": "CVE-2026-72130",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72130"
},
{
"name": "CVE-2026-68317",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68317"
},
{
"name": "CVE-2026-68443",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68443"
},
{
"name": "CVE-2026-68326",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68326"
},
{
"name": "CVE-2026-68184",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68184"
},
{
"name": "CVE-2026-68228",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68228"
},
{
"name": "CVE-2026-72125",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72125"
},
{
"name": "CVE-2026-68417",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68417"
},
{
"name": "CVE-2026-68338",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68338"
},
{
"name": "CVE-2026-68248",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68248"
},
{
"name": "CVE-2026-68165",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68165"
},
{
"name": "CVE-2026-68277",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68277"
},
{
"name": "CVE-2026-72015",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72015"
},
{
"name": "CVE-2026-68410",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68410"
},
{
"name": "CVE-2026-68437",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68437"
},
{
"name": "CVE-2026-68261",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68261"
},
{
"name": "CVE-2026-68128",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68128"
},
{
"name": "CVE-2026-68164",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68164"
},
{
"name": "CVE-2026-68304",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68304"
},
{
"name": "CVE-2026-68155",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68155"
},
{
"name": "CVE-2026-45901",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-45901"
},
{
"name": "CVE-2026-64574",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64574"
},
{
"name": "CVE-2026-68294",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68294"
},
{
"name": "CVE-2026-68102",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68102"
},
{
"name": "CVE-2026-68385",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68385"
},
{
"name": "CVE-2026-68446",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68446"
},
{
"name": "CVE-2026-68408",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68408"
},
{
"name": "CVE-2026-68226",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68226"
},
{
"name": "CVE-2026-68350",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68350"
},
{
"name": "CVE-2026-68419",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68419"
},
{
"name": "CVE-2026-68297",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68297"
},
{
"name": "CVE-2026-68199",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68199"
},
{
"name": "CVE-2026-68296",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68296"
},
{
"name": "CVE-2026-68425",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68425"
},
{
"name": "CVE-2026-68293",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68293"
},
{
"name": "CVE-2026-68365",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68365"
},
{
"name": "CVE-2026-72183",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72183"
},
{
"name": "CVE-2026-72254",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72254"
},
{
"name": "CVE-2026-68320",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68320"
},
{
"name": "CVE-2026-68176",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68176"
},
{
"name": "CVE-2026-68280",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68280"
},
{
"name": "CVE-2026-68362",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68362"
},
{
"name": "CVE-2026-68430",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68430"
},
{
"name": "CVE-2026-68427",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68427"
},
{
"name": "CVE-2026-68324",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68324"
},
{
"name": "CVE-2026-68308",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68308"
},
{
"name": "CVE-2026-68179",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68179"
},
{
"name": "CVE-2026-72260",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72260"
},
{
"name": "CVE-2026-68210",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68210"
},
{
"name": "CVE-2026-68120",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68120"
},
{
"name": "CVE-2026-72372",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72372"
},
{
"name": "CVE-2026-68309",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68309"
},
{
"name": "CVE-2026-68096",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68096"
},
{
"name": "CVE-2026-68403",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68403"
},
{
"name": "CVE-2026-68139",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68139"
},
{
"name": "CVE-2026-68442",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68442"
},
{
"name": "CVE-2026-68093",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68093"
},
{
"name": "CVE-2026-64584",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64584"
},
{
"name": "CVE-2026-72299",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72299"
},
{
"name": "CVE-2026-68310",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68310"
},
{
"name": "CVE-2026-68115",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68115"
},
{
"name": "CVE-2026-68133",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68133"
},
{
"name": "CVE-2026-68221",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68221"
},
{
"name": "CVE-2026-68246",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68246"
},
{
"name": "CVE-2026-64563",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64563"
},
{
"name": "CVE-2026-68405",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68405"
},
{
"name": "CVE-2026-68219",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68219"
},
{
"name": "CVE-2026-68216",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68216"
},
{
"name": "CVE-2026-64580",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64580"
},
{
"name": "CVE-2026-68328",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68328"
},
{
"name": "CVE-2026-68394",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68394"
},
{
"name": "CVE-2026-68196",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68196"
},
{
"name": "CVE-2026-64280",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64280"
},
{
"name": "CVE-2026-68269",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68269"
},
{
"name": "CVE-2026-68255",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68255"
},
{
"name": "CVE-2026-72017",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72017"
},
{
"name": "CVE-2026-68363",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68363"
},
{
"name": "CVE-2026-68213",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68213"
},
{
"name": "CVE-2026-68278",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68278"
},
{
"name": "CVE-2026-68145",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68145"
},
{
"name": "CVE-2026-72113",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72113"
},
{
"name": "CVE-2026-68361",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68361"
},
{
"name": "CVE-2026-68181",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68181"
},
{
"name": "CVE-2026-64570",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64570"
},
{
"name": "CVE-2026-68113",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68113"
},
{
"name": "CVE-2026-72213",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72213"
},
{
"name": "CVE-2026-68160",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68160"
},
{
"name": "CVE-2026-68100",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68100"
},
{
"name": "CVE-2026-68157",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68157"
},
{
"name": "CVE-2026-68368",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68368"
},
{
"name": "CVE-2026-68281",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68281"
},
{
"name": "CVE-2026-68335",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68335"
},
{
"name": "CVE-2026-68329",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68329"
},
{
"name": "CVE-2026-68189",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68189"
},
{
"name": "CVE-2026-68212",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68212"
},
{
"name": "CVE-2026-64568",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64568"
},
{
"name": "CVE-2026-72101",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72101"
},
{
"name": "CVE-2026-68119",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68119"
},
{
"name": "CVE-2026-68389",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68389"
},
{
"name": "CVE-2026-68314",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68314"
},
{
"name": "CVE-2026-68215",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68215"
},
{
"name": "CVE-2026-68099",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68099"
},
{
"name": "CVE-2026-68369",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68369"
},
{
"name": "CVE-2026-72253",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72253"
},
{
"name": "CVE-2026-68340",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68340"
},
{
"name": "CVE-2026-72137",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72137"
},
{
"name": "CVE-2026-68352",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68352"
},
{
"name": "CVE-2026-68106",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68106"
},
{
"name": "CVE-2026-72103",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72103"
},
{
"name": "CVE-2026-68197",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68197"
},
{
"name": "CVE-2026-72040",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72040"
},
{
"name": "CVE-2026-68315",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68315"
},
{
"name": "CVE-2026-68346",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68346"
},
{
"name": "CVE-2026-68377",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68377"
},
{
"name": "CVE-2026-72114",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72114"
},
{
"name": "CVE-2026-68175",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68175"
},
{
"name": "CVE-2026-68413",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68413"
},
{
"name": "CVE-2026-68372",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68372"
},
{
"name": "CVE-2026-68357",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68357"
},
{
"name": "CVE-2026-68376",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68376"
},
{
"name": "CVE-2026-64583",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64583"
},
{
"name": "CVE-2026-68262",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68262"
},
{
"name": "CVE-2026-68194",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68194"
},
{
"name": "CVE-2026-68127",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68127"
},
{
"name": "CVE-2026-68112",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68112"
},
{
"name": "CVE-2026-72142",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72142"
},
{
"name": "CVE-2026-72062",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72062"
},
{
"name": "CVE-2026-68146",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68146"
},
{
"name": "CVE-2026-68202",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68202"
},
{
"name": "CVE-2026-68104",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68104"
},
{
"name": "CVE-2026-72065",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72065"
},
{
"name": "CVE-2026-68137",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68137"
},
{
"name": "CVE-2026-68143",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68143"
},
{
"name": "CVE-2026-68349",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68349"
},
{
"name": "CVE-2026-68257",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68257"
},
{
"name": "CVE-2026-68252",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68252"
},
{
"name": "CVE-2026-72070",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72070"
},
{
"name": "CVE-2026-68351",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68351"
},
{
"name": "CVE-2026-68301",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68301"
},
{
"name": "CVE-2026-68402",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68402"
},
{
"name": "CVE-2026-68117",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68117"
},
{
"name": "CVE-2026-68333",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68333"
},
{
"name": "CVE-2026-68386",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68386"
},
{
"name": "CVE-2026-68111",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68111"
},
{
"name": "CVE-2026-64577",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64577"
},
{
"name": "CVE-2026-68142",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68142"
},
{
"name": "CVE-2026-68243",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68243"
},
{
"name": "CVE-2026-68209",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68209"
},
{
"name": "CVE-2026-68306",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68306"
},
{
"name": "CVE-2026-68207",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68207"
},
{
"name": "CVE-2026-68373",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68373"
},
{
"name": "CVE-2026-68185",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68185"
},
{
"name": "CVE-2026-68206",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68206"
},
{
"name": "CVE-2026-68110",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68110"
},
{
"name": "CVE-2026-72117",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72117"
},
{
"name": "CVE-2026-68391",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68391"
},
{
"name": "CVE-2026-68227",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68227"
},
{
"name": "CVE-2026-68348",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68348"
},
{
"name": "CVE-2026-68331",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68331"
},
{
"name": "CVE-2025-40098",
"url": "https://www.cve.org/CVERecord?id=CVE-2025-40098"
},
{
"name": "CVE-2026-72030",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72030"
},
{
"name": "CVE-2026-68432",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68432"
},
{
"name": "CVE-2026-68319",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68319"
},
{
"name": "CVE-2026-68186",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68186"
},
{
"name": "CVE-2026-68148",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68148"
},
{
"name": "CVE-2026-68344",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68344"
},
{
"name": "CVE-2026-45897",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-45897"
},
{
"name": "CVE-2026-64578",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64578"
},
{
"name": "CVE-2026-68398",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68398"
},
{
"name": "CVE-2026-68429",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68429"
},
{
"name": "CVE-2026-68136",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68136"
},
{
"name": "CVE-2026-68395",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68395"
},
{
"name": "CVE-2026-68144",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68144"
},
{
"name": "CVE-2026-68263",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68263"
},
{
"name": "CVE-2026-68299",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68299"
},
{
"name": "CVE-2026-68366",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68366"
},
{
"name": "CVE-2026-68156",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68156"
},
{
"name": "CVE-2026-68187",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68187"
},
{
"name": "CVE-2026-68121",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68121"
},
{
"name": "CVE-2026-68231",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68231"
},
{
"name": "CVE-2026-68182",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68182"
},
{
"name": "CVE-2026-68422",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68422"
},
{
"name": "CVE-2026-68327",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68327"
},
{
"name": "CVE-2026-68358",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68358"
},
{
"name": "CVE-2026-68433",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68433"
},
{
"name": "CVE-2026-68190",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68190"
},
{
"name": "CVE-2026-68195",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68195"
},
{
"name": "CVE-2026-68318",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68318"
},
{
"name": "CVE-2026-68200",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68200"
},
{
"name": "CVE-2026-68279",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68279"
},
{
"name": "CVE-2026-68205",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68205"
},
{
"name": "CVE-2026-68234",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68234"
},
{
"name": "CVE-2026-68311",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68311"
},
{
"name": "CVE-2026-68321",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68321"
},
{
"name": "CVE-2026-68256",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68256"
},
{
"name": "CVE-2026-68140",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68140"
},
{
"name": "CVE-2026-68445",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68445"
},
{
"name": "CVE-2026-64562",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64562"
},
{
"name": "CVE-2026-72023",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72023"
},
{
"name": "CVE-2026-68434",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68434"
},
{
"name": "CVE-2026-68444",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68444"
},
{
"name": "CVE-2026-68153",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68153"
},
{
"name": "CVE-2026-64571",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64571"
},
{
"name": "CVE-2026-72168",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72168"
},
{
"name": "CVE-2026-68188",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68188"
},
{
"name": "CVE-2026-68161",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68161"
},
{
"name": "CVE-2026-68259",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68259"
},
{
"name": "CVE-2026-68235",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68235"
},
{
"name": "CVE-2026-68223",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68223"
},
{
"name": "CVE-2026-72116",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72116"
},
{
"name": "CVE-2026-72244",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72244"
},
{
"name": "CVE-2026-68414",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68414"
},
{
"name": "CVE-2026-68411",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68411"
},
{
"name": "CVE-2026-68131",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68131"
},
{
"name": "CVE-2026-68214",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68214"
},
{
"name": "CVE-2026-68217",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68217"
},
{
"name": "CVE-2026-68222",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68222"
},
{
"name": "CVE-2026-72045",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72045"
},
{
"name": "CVE-2026-68124",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68124"
},
{
"name": "CVE-2026-68381",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68381"
},
{
"name": "CVE-2026-72305",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72305"
},
{
"name": "CVE-2026-68250",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68250"
},
{
"name": "CVE-2026-68371",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68371"
},
{
"name": "CVE-2026-68397",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68397"
},
{
"name": "CVE-2026-64572",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64572"
},
{
"name": "CVE-2026-68126",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68126"
},
{
"name": "CVE-2026-68396",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68396"
},
{
"name": "CVE-2026-72147",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72147"
},
{
"name": "CVE-2026-68449",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68449"
},
{
"name": "CVE-2026-68125",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68125"
},
{
"name": "CVE-2026-68135",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68135"
},
{
"name": "CVE-2026-72121",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72121"
},
{
"name": "CVE-2026-72032",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72032"
},
{
"name": "CVE-2026-68374",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68374"
},
{
"name": "CVE-2026-68360",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68360"
},
{
"name": "CVE-2026-68244",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68244"
},
{
"name": "CVE-2026-64579",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64579"
},
{
"name": "CVE-2026-68249",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68249"
},
{
"name": "CVE-2026-68107",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68107"
},
{
"name": "CVE-2026-72146",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72146"
},
{
"name": "CVE-2026-72175",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72175"
},
{
"name": "CVE-2026-68392",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68392"
},
{
"name": "CVE-2026-68300",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68300"
},
{
"name": "CVE-2026-68260",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68260"
},
{
"name": "CVE-2026-68229",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68229"
},
{
"name": "CVE-2026-68284",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68284"
},
{
"name": "CVE-2026-68152",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68152"
},
{
"name": "CVE-2026-68353",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68353"
},
{
"name": "CVE-2026-68108",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68108"
},
{
"name": "CVE-2026-64565",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64565"
},
{
"name": "CVE-2026-68158",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68158"
},
{
"name": "CVE-2026-64573",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64573"
},
{
"name": "CVE-2026-68325",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68325"
},
{
"name": "CVE-2026-68307",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68307"
},
{
"name": "CVE-2026-68355",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68355"
},
{
"name": "CVE-2026-68098",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68098"
},
{
"name": "CVE-2026-74436",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74436"
},
{
"name": "CVE-2026-68097",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68097"
},
{
"name": "CVE-2026-68180",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68180"
},
{
"name": "CVE-2026-68247",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68247"
},
{
"name": "CVE-2026-68407",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68407"
},
{
"name": "CVE-2026-68203",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68203"
},
{
"name": "CVE-2026-68123",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68123"
},
{
"name": "CVE-2026-53078",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-53078"
},
{
"name": "CVE-2026-64205",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64205"
},
{
"name": "CVE-2026-68162",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68162"
},
{
"name": "CVE-2026-68220",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68220"
},
{
"name": "CVE-2026-68354",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68354"
},
{
"name": "CVE-2026-68149",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68149"
},
{
"name": "CVE-2026-68178",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68178"
},
{
"name": "CVE-2026-68183",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68183"
},
{
"name": "CVE-2026-68251",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68251"
},
{
"name": "CVE-2026-68151",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68151"
},
{
"name": "CVE-2026-72069",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72069"
},
{
"name": "CVE-2026-68359",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68359"
},
{
"name": "CVE-2026-64290",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64290"
},
{
"name": "CVE-2026-68370",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68370"
},
{
"name": "CVE-2026-64567",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64567"
},
{
"name": "CVE-2026-68236",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68236"
},
{
"name": "CVE-2026-64576",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64576"
},
{
"name": "CVE-2026-68192",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68192"
},
{
"name": "CVE-2026-72124",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72124"
},
{
"name": "CVE-2026-68272",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68272"
},
{
"name": "CVE-2026-64564",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64564"
},
{
"name": "CVE-2026-72046",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72046"
},
{
"name": "CVE-2026-72119",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72119"
},
{
"name": "CVE-2026-68406",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68406"
},
{
"name": "CVE-2026-72115",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72115"
},
{
"name": "CVE-2026-68130",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68130"
},
{
"name": "CVE-2026-72118",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72118"
},
{
"name": "CVE-2026-68336",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68336"
},
{
"name": "CVE-2026-68201",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68201"
},
{
"name": "CVE-2026-64569",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64569"
},
{
"name": "CVE-2026-68290",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68290"
},
{
"name": "CVE-2026-68154",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68154"
}
],
"initial_release_date": "2026-08-21T00:00:00",
"last_revision_date": "2026-08-21T00:00:00",
"links": [],
"reference": "CERTFR-2026-AVI-1069",
"revisions": [
{
"description": "Version initiale",
"revision_date": "2026-08-21T00:00:00.000000"
}
],
"risks": [
{
"description": "D\u00e9ni de service"
},
{
"description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
},
{
"description": "\u00c9l\u00e9vation de privil\u00e8ges"
}
],
"summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans le noyau Linux de Debian LTS. Elles permettent \u00e0 un attaquant de provoquer une \u00e9l\u00e9vation de privil\u00e8ges, une atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es et un d\u00e9ni de service.",
"title": "Multiples vuln\u00e9rabilit\u00e9s dans le noyau Linux de Debian LTS",
"vendor_advisories": [
{
"published_at": "2026-08-18",
"title": "Bulletin de s\u00e9curit\u00e9 Debian LTS msg00035",
"url": "https://lists.debian.org/debian-lts-announce/2026/08/msg00035.html"
}
]
}
CVE-2026-68352 (GCVE-0-2026-68352)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: ath6kl: fix OOB read from firmware IE lengths in connect event
The firmware-controlled beacon_ie_len, assoc_req_len, and assoc_resp_len
fields in ath6kl_wmi_connect_event_rx() are not validated against the
buffer length. Their sum (up to 765) can exceed the actual WMI event
data, causing out-of-bounds reads during IE parsing and state corruption
of wmi->is_wmm_enabled.
Add a check that the total IE length fits within the buffer.
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/ath/ath6kl/wmi.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "7cae33e3e09a080db96e3a8980c2c8d288318320",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "1eeed9efc9a40e0635e910c37fee86543041b4e1",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "a38d7d6376b295245b53bc98b7ca682c027abaf7",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "1c690f7c4c5b37108ac8c98b94ce1b3c655a4f5e",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "d70c0a850c21b57a6f46ce363860203389bbeaa6",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "33b5342d2080657054ddf89ef1199b426a37dae8",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "94e1bfcefe8264a207c2fda2febb954e70a34b42",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "6b47b29730de3232b919d8362749f6814c5f2a33",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/ath/ath6kl/wmi.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.2"
},
{
"lessThan": "3.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath6kl: fix OOB read from firmware IE lengths in connect event\n\nThe firmware-controlled beacon_ie_len, assoc_req_len, and assoc_resp_len\nfields in ath6kl_wmi_connect_event_rx() are not validated against the\nbuffer length. Their sum (up to 765) can exceed the actual WMI event\ndata, causing out-of-bounds reads during IE parsing and state corruption\nof wmi-\u003eis_wmm_enabled.\n\nAdd a check that the total IE length fits within the buffer."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The malformed connect event is produced from the 802.11 association exchange with the peer AP, so a rogue/evil-twin AP or frame-injecting attacker within radio range of the ath6kl station supplies the oversized IE lengths; no local access is needed but the attacker must share the wireless link layer.\nAC:L - The attacker controls the beacon/assoc-request/assoc-response IE content and declared lengths and can force repeated (re)association or roaming with deauth frames until the connect event is emitted, so triggering is reliable and repeatable with no conditions outside the attacker\u0027s control.\nPR:N - No credentials or local account are required; the connect event is processed as part of establishing the link with an attacker-controlled AP, before any user-level authorization on the victim system is involved.\nUI:N - No victim action is needed \u2014 a station with a saved profile auto-associates, and the SME_CONNECTED roam path (cfg80211_roamed) processes the same event while the station is already connected, entirely attacker-driven.\nS:U - The out-of-bounds read, the corrupted wmi-\u003eis_wmm_enabled state and any resulting crash are all confined to the kernel of the affected host; no VM, IOMMU or sandbox boundary is crossed.\nC:H - Up to 765 bytes of adjacent kernel heap past the WMI event buffer are read and then exported to userspace: copied into the cfg80211 BSS IE cache (readable via unprivileged nl80211 GET_SCAN) and delivered as req_ie/resp_ie in cfg80211_connect_result()/cfg80211_roamed(), a repeatable kernel memory disclosure rather than a few stray bytes.\nI:L - There is no out-of-bounds write, but out-of-bounds bytes drive driver state: wmi-\u003eis_wmm_enabled is set from memory beyond the buffer and bogus IE data is inserted into the cfg80211 BSS cache, giving limited attacker-influenced modification of kernel-held data.\nA:H - The IE walk dereferences up to 765 bytes past the received skb and can run off the end of the allocation into unmapped memory (or trip KASAN/DEBUG_PAGEALLOC), producing a kernel oops/panic that the adjacent attacker can retrigger at will."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:55.758Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/7cae33e3e09a080db96e3a8980c2c8d288318320"
},
{
"url": "https://git.kernel.org/stable/c/1eeed9efc9a40e0635e910c37fee86543041b4e1"
},
{
"url": "https://git.kernel.org/stable/c/a38d7d6376b295245b53bc98b7ca682c027abaf7"
},
{
"url": "https://git.kernel.org/stable/c/1c690f7c4c5b37108ac8c98b94ce1b3c655a4f5e"
},
{
"url": "https://git.kernel.org/stable/c/d70c0a850c21b57a6f46ce363860203389bbeaa6"
},
{
"url": "https://git.kernel.org/stable/c/33b5342d2080657054ddf89ef1199b426a37dae8"
},
{
"url": "https://git.kernel.org/stable/c/94e1bfcefe8264a207c2fda2febb954e70a34b42"
},
{
"url": "https://git.kernel.org/stable/c/6b47b29730de3232b919d8362749f6814c5f2a33"
}
],
"title": "wifi: ath6kl: fix OOB read from firmware IE lengths in connect event",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68352",
"datePublished": "2026-08-10T12:03:29.304Z",
"dateReserved": "2026-07-30T09:28:09.384Z",
"dateUpdated": "2026-08-19T16:33:55.758Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68137 (GCVE-0-2026-68137)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/x25: fix use-after-free in x25_kill_by_neigh()
x25_kill_by_neigh() walks the global X.25 socket list looking for sockets
attached to a terminating neighbour. x25_list_lock protects list membership
while the lookup is in progress, but it does not pin a socket's lifetime
after the lock is dropped.
The function currently drops x25_list_lock before calling lock_sock(s). A
concurrent close can run x25_release(), remove the same socket from
x25_list, and drop the last socket reference in that window. The neighbour
teardown path can then lock or inspect a freed struct sock/struct x25_sock.
Take sock_hold(s) while x25_list_lock still proves that the list entry is
live, then drop the temporary reference after the socket has been locked,
rechecked, and released. Recheck x25_sk(s)->neighbour after lock_sock(),
because another path may have disconnected the socket before this path
acquired the socket lock. Restart the list walk after each disconnect
because the list lock was dropped and the previous iterator state may no
longer be valid.
A QEMU/KASAN run against origin/master reproduced a slab-use-after-free in
x25_kill_by_neigh().
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 5c94b6205e87411dbe9dc1ca088eb36b8837fb47 Version: 409570a619c1cda2e0fde6018a256b9e3d3ba0ee Version: 7781607938c8371d4c2b243527430241c62e39c2 Version: 7781607938c8371d4c2b243527430241c62e39c2 Version: 7781607938c8371d4c2b243527430241c62e39c2 Version: 7781607938c8371d4c2b243527430241c62e39c2 Version: 7781607938c8371d4c2b243527430241c62e39c2 Version: 7781607938c8371d4c2b243527430241c62e39c2 Version: dffc859d1d9560da594e4282091781b8d2715f00 Version: 858642789ada1b48630f322e59416ca9fca3e6b7 Version: 4c240c5a105557e4546d0836e694868f22fd09b0 Version: 9acf05b4e7b55fdb712ef7b331dbce5bcd391d0f Version: 4a279d7ee1c65411b4055ecd428b8aa2b1711c1f Version: 671529db75e6be777bb1c76aa07c2bdd2992be6d Version: 5.10.110 ≤ Version: 5.15.33 ≤ Version: 4.9.311 ≤ Version: 4.14.276 ≤ Version: 4.19.238 ≤ Version: 5.4.189 ≤ Version: 5.16.19 ≤ Version: 5.17.2 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/x25/af_x25.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "db6b04f6d65549bb1c7bc8e64a92e7b7d03be676",
"status": "affected",
"version": "5c94b6205e87411dbe9dc1ca088eb36b8837fb47",
"versionType": "git"
},
{
"lessThan": "5e8a754ac2009a88a7b99ab61eab6296eed360f3",
"status": "affected",
"version": "409570a619c1cda2e0fde6018a256b9e3d3ba0ee",
"versionType": "git"
},
{
"lessThan": "c98a454d1a9e1bd09d5fd55a7aa589b199340b88",
"status": "affected",
"version": "7781607938c8371d4c2b243527430241c62e39c2",
"versionType": "git"
},
{
"lessThan": "3f4fe26c20c30bd5a2e2583e80685def0b27858c",
"status": "affected",
"version": "7781607938c8371d4c2b243527430241c62e39c2",
"versionType": "git"
},
{
"lessThan": "610678d4be94b619c751572e8a58de705592cd07",
"status": "affected",
"version": "7781607938c8371d4c2b243527430241c62e39c2",
"versionType": "git"
},
{
"lessThan": "ec6d91a1bf2ebd767d3d43f6d249ee0ed3f4558a",
"status": "affected",
"version": "7781607938c8371d4c2b243527430241c62e39c2",
"versionType": "git"
},
{
"lessThan": "9aabda553184346f74810e2ee1d96920b4612e3f",
"status": "affected",
"version": "7781607938c8371d4c2b243527430241c62e39c2",
"versionType": "git"
},
{
"lessThan": "5499e0602d2faafd42c580d25f615903c3fbe11b",
"status": "affected",
"version": "7781607938c8371d4c2b243527430241c62e39c2",
"versionType": "git"
},
{
"status": "affected",
"version": "dffc859d1d9560da594e4282091781b8d2715f00",
"versionType": "git"
},
{
"status": "affected",
"version": "858642789ada1b48630f322e59416ca9fca3e6b7",
"versionType": "git"
},
{
"status": "affected",
"version": "4c240c5a105557e4546d0836e694868f22fd09b0",
"versionType": "git"
},
{
"status": "affected",
"version": "9acf05b4e7b55fdb712ef7b331dbce5bcd391d0f",
"versionType": "git"
},
{
"status": "affected",
"version": "4a279d7ee1c65411b4055ecd428b8aa2b1711c1f",
"versionType": "git"
},
{
"status": "affected",
"version": "671529db75e6be777bb1c76aa07c2bdd2992be6d",
"versionType": "git"
},
{
"lessThan": "5.10.265",
"status": "affected",
"version": "5.10.110",
"versionType": "semver"
},
{
"lessThan": "5.15.216",
"status": "affected",
"version": "5.15.33",
"versionType": "semver"
},
{
"lessThan": "4.10",
"status": "affected",
"version": "4.9.311",
"versionType": "semver"
},
{
"lessThan": "4.15",
"status": "affected",
"version": "4.14.276",
"versionType": "semver"
},
{
"lessThan": "4.20",
"status": "affected",
"version": "4.19.238",
"versionType": "semver"
},
{
"lessThan": "5.5",
"status": "affected",
"version": "5.4.189",
"versionType": "semver"
},
{
"lessThan": "5.17",
"status": "affected",
"version": "5.16.19",
"versionType": "semver"
},
{
"lessThan": "5.18",
"status": "affected",
"version": "5.17.2",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/x25/af_x25.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.18"
},
{
"lessThan": "5.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.10.110",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.15.33",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.9.311",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.14.276",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.19.238",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.4.189",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.16.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.17.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/x25: fix use-after-free in x25_kill_by_neigh()\n\nx25_kill_by_neigh() walks the global X.25 socket list looking for sockets\nattached to a terminating neighbour. x25_list_lock protects list membership\nwhile the lookup is in progress, but it does not pin a socket\u0027s lifetime\nafter the lock is dropped.\n\nThe function currently drops x25_list_lock before calling lock_sock(s). A\nconcurrent close can run x25_release(), remove the same socket from\nx25_list, and drop the last socket reference in that window. The neighbour\nteardown path can then lock or inspect a freed struct sock/struct x25_sock.\n\nTake sock_hold(s) while x25_list_lock still proves that the list entry is\nlive, then drop the temporary reference after the socket has been locked,\nrechecked, and released. Recheck x25_sk(s)-\u003eneighbour after lock_sock(),\nbecause another path may have disconnected the socket before this path\nacquired the socket lock. Restart the list walk after each disconnect\nbecause the list lock was dropped and the previous iterator state may no\nlonger be valid.\n\nA QEMU/KASAN run against origin/master reproduced a slab-use-after-free in\nx25_kill_by_neigh()."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - x25_kill_by_neigh() is invoked from the net stack when inbound X.25 link-control frames (RESTART_REQUEST/CONFIRMATION with LCI 0, or IFACE_DISCONNECT) are processed on ARPHRD_X25 interfaces via the ETH_P_X25 packet handler, the normal WAN-facing path in telecom/banking/industrial X.25 deployments.\nAC:L - This is a use-after-free race between neighbour teardown and socket close(); an attacker controls both sides by racing close() on an AF_X25 socket against RESTART/terminate frames they send, and KASAN reproduced the slab-UAF under controlled testing.\nPR:N - A remote X.25 peer on the WAN needs no Linux credentials to deliver RESTART/terminate frames that reach x25_kill_by_neigh(); exploitation races that path against any local X.25 consumer closing sockets, without the attacker holding privileges on the victim host.\nUI:N - No victim user interaction is required beyond normal automated X.25 service operation (accepting calls, reconnecting, or closing sessions) that can be timed against remotely injected link-control frames.\nS:U - The vulnerability corrupts kernel heap memory within the host kernel security boundary; it does not cross VM, container, or IOMMU isolation boundaries.\nC:H - Use-after-free on struct sock/x25_sock lets an attacker influence reuse of freed slab objects, enabling arbitrary kernel memory disclosure per CNA guidance for kernel UAF bugs.\nI:H - Use-after-free on socket structures can be leveraged through heap shaping into arbitrary kernel writes, privilege escalation, or code execution per CNA guidance for kernel UAF bugs.\nA:H - The bug is a confirmed slab use-after-free in kernel context (KASAN-reproduced) that can oops or panic the kernel during lock_sock()/x25_disconnect() even before full exploit development."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:29:54.672Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/db6b04f6d65549bb1c7bc8e64a92e7b7d03be676"
},
{
"url": "https://git.kernel.org/stable/c/5e8a754ac2009a88a7b99ab61eab6296eed360f3"
},
{
"url": "https://git.kernel.org/stable/c/c98a454d1a9e1bd09d5fd55a7aa589b199340b88"
},
{
"url": "https://git.kernel.org/stable/c/3f4fe26c20c30bd5a2e2583e80685def0b27858c"
},
{
"url": "https://git.kernel.org/stable/c/610678d4be94b619c751572e8a58de705592cd07"
},
{
"url": "https://git.kernel.org/stable/c/ec6d91a1bf2ebd767d3d43f6d249ee0ed3f4558a"
},
{
"url": "https://git.kernel.org/stable/c/9aabda553184346f74810e2ee1d96920b4612e3f"
},
{
"url": "https://git.kernel.org/stable/c/5499e0602d2faafd42c580d25f615903c3fbe11b"
}
],
"title": "net/x25: fix use-after-free in x25_kill_by_neigh()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68137",
"datePublished": "2026-08-10T11:59:00.740Z",
"dateReserved": "2026-07-30T09:28:09.370Z",
"dateUpdated": "2026-08-19T16:29:54.672Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68370 (GCVE-0-2026-68370)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback
dummy_hcd embeds a single shared usb_request (dum->fifo_req) that the
"emulated single-request FIFO" fast-path in dummy_queue() reuses for
small IN transfers: it copies the caller's request into it
(req->req = *_req) and queues it, treating list_empty(&fifo_req.queue)
as "the slot is free".
The completion side (dummy_timer/transfer/nuke/dummy_dequeue) follows
the standard pattern: list_del_init(&req->queue) unlinks the request,
then the lock is dropped and usb_gadget_giveback_request() invokes
req->complete(). But list_del_init() makes fifo_req.queue look empty
*before* the completion callback returns, so a concurrent dummy_queue()
on another CPU sees the slot as free, reuses fifo_req and runs
req->req = *_req -- overwriting req->complete while dummy_timer is
mid-calling it. The indirect call then jumps to a clobbered pointer,
causing a general protection fault / page fault in dummy_timer
(syzkaller extid faf3a6cf579fc65591ca). The clobbering write is an
in-bounds memcpy on a live shared object, so KASAN cannot flag it.
Add a fifo_req_busy bit covering the shared request's whole lifetime:
set it in dummy_queue() when the FIFO fast-path takes fifo_req (making
it the fast-path guard, replacing the list_empty(&fifo_req.queue)
test), and clear it after the completion callback has returned, via a
dummy_giveback() helper used at all four gadget-request giveback
sites. The shared slot can no longer be reused until its completion
callback has finished.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/gadget/udc/dummy_hcd.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "16a685172abc9233728830e27d26ffa778975b51",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "95f30a21612cc65761c58ba044b1767699437317",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "3cab0e5498d0fbb21fe1a9181f7bda9a844a697e",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "e2b2740f1242bc70b5b46da2cdbbaa419f490e59",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "67b589d09a96882d56842dced5698ed8dd06ce45",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "e239ea91b48180ed48a86ac25643832a02c88456",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "e24b33618231034bf01dfaff4fd3409d4b4d5b2e",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "d5e5cd3654d2b5359a12ea6586120f05b28634ee",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/usb/gadget/udc/dummy_hcd.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: dummy_hcd: prevent fifo_req reuse during giveback\n\ndummy_hcd embeds a single shared usb_request (dum-\u003efifo_req) that the\n\"emulated single-request FIFO\" fast-path in dummy_queue() reuses for\nsmall IN transfers: it copies the caller\u0027s request into it\n(req-\u003ereq = *_req) and queues it, treating list_empty(\u0026fifo_req.queue)\nas \"the slot is free\".\n\nThe completion side (dummy_timer/transfer/nuke/dummy_dequeue) follows\nthe standard pattern: list_del_init(\u0026req-\u003equeue) unlinks the request,\nthen the lock is dropped and usb_gadget_giveback_request() invokes\nreq-\u003ecomplete(). But list_del_init() makes fifo_req.queue look empty\n*before* the completion callback returns, so a concurrent dummy_queue()\non another CPU sees the slot as free, reuses fifo_req and runs\nreq-\u003ereq = *_req -- overwriting req-\u003ecomplete while dummy_timer is\nmid-calling it. The indirect call then jumps to a clobbered pointer,\ncausing a general protection fault / page fault in dummy_timer\n(syzkaller extid faf3a6cf579fc65591ca). The clobbering write is an\nin-bounds memcpy on a live shared object, so KASAN cannot flag it.\n\nAdd a fifo_req_busy bit covering the shared request\u0027s whole lifetime:\nset it in dummy_queue() when the FIFO fast-path takes fifo_req (making\nit the fast-path guard, replacing the list_empty(\u0026fifo_req.queue)\ntest), and clear it after the completion callback has returned, via a\ndummy_giveback() helper used at all four gadget-request giveback\nsites. The shared slot can no longer be reused until its completion\ncallback has finished."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - dummy_hcd is a purely virtual UDC/HCD pair with no physical port; both sides of the race are driven locally \u2014 gadget-side `usb_ep_queue()` via raw-gadget ioctls, gadgetfs/functionfs endpoint writes or configfs function traffic, and the host side by the in-software `dummy_timer`/URB path. No cable, hardware, or network access is involved, matching the AV:L used for other dummy_hcd/gadget bugs.\nAC:L - The attacker controls both sides of the race: it queues small IN requests on one CPU in a tight loop while the periodic 1 ms `dummy_timer` frame processing performs giveback on another, and the fast-path guard (`list_empty(\u0026fifo_req.queue)`) is cleared before the callback returns, so the window is entered on essentially every iteration and can be retried indefinitely.\nPR:L - No capability check exists anywhere on the path \u2014 `dummy_queue()` and the giveback sites perform none; reachability is gated only by node/mount permissions on /dev/raw-gadget, gadgetfs or the gadget configfs/functionfs tree, which on Android and embedded/industrial systems are routinely delegated to non-root system accounts, so basic local access suffices.\nUI:N - The attacker performs every step itself \u2014 enabling the gadget, queueing the IN transfers, and letting the emulated frame timer run \u2014 with no action required from any other user or victim.\nS:U - The corrupted object and the resulting control-flow hijack are entirely within the kernel\u0027s own security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - The in-flight copy overwrites `fifo_req.req.buf`, `length`, `actual` and `context` of the live shared request, so the completion path and the host-side `transfer()` memcpy operate with mismatched buffer/length/context pairs, letting an attacker steer reads out of unintended kernel memory and surface them through the emulated host transfer \u2014 a kernel memory disclosure primitive.\nI:H - `req-\u003ereq = *_req` clobbers the `complete` function pointer while `usb_gadget_giveback_request()` is dereferencing it, giving a torn/stale indirect call plus a `context` mismatch (type confusion) that is a direct control-flow hijack primitive; the same race also lets the shared `fifo_buf` be written under a stale length, yielding controllable kernel writes.\nA:H - The reported effect is a general protection fault / kernel page fault in `dummy_timer` (syzbot faf3a6cf579fc65591ca) from calling through the clobbered pointer, i.e. a kernel oops that an unprivileged local attacker can trigger repeatedly."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:31.156Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/16a685172abc9233728830e27d26ffa778975b51"
},
{
"url": "https://git.kernel.org/stable/c/95f30a21612cc65761c58ba044b1767699437317"
},
{
"url": "https://git.kernel.org/stable/c/3cab0e5498d0fbb21fe1a9181f7bda9a844a697e"
},
{
"url": "https://git.kernel.org/stable/c/e2b2740f1242bc70b5b46da2cdbbaa419f490e59"
},
{
"url": "https://git.kernel.org/stable/c/67b589d09a96882d56842dced5698ed8dd06ce45"
},
{
"url": "https://git.kernel.org/stable/c/e239ea91b48180ed48a86ac25643832a02c88456"
},
{
"url": "https://git.kernel.org/stable/c/e24b33618231034bf01dfaff4fd3409d4b4d5b2e"
},
{
"url": "https://git.kernel.org/stable/c/d5e5cd3654d2b5359a12ea6586120f05b28634ee"
}
],
"title": "usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68370",
"datePublished": "2026-08-10T12:03:48.320Z",
"dateReserved": "2026-07-30T09:28:09.386Z",
"dateUpdated": "2026-08-19T16:34:31.156Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68344 (GCVE-0-2026-68344)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
usb: atm: ueagle-atm: reject descriptors that confuse probe and disconnect
uea_probe() distinguishes a pre-firmware device from a post-firmware one
using the USB id (UEA_IS_PREFIRM()), and stores a different object as the
interface data in each case: a 'struct completion' for a pre-firmware
device (to be waited on in .disconnect()), or a 'struct usbatm_data' for a
post-firmware one.
uea_disconnect() instead tells the two apart by the number of interfaces
of the active configuration (a pre-firmware device exposes a single
interface, ADI930 has 2 and eagle has 3), and casts the interface data
accordingly.
Because the two handlers use different criteria, a crafted device that
advertises a pre-firmware id together with a multi-interface descriptor
(or a post-firmware id with a single interface) makes them disagree: the
small 'struct completion' stored by uea_probe() is then passed to
usbatm_usb_disconnect(), which casts it to 'struct usbatm_data' and takes
instance->serialize, reading past the end of the allocation:
BUG: KASAN: slab-out-of-bounds in __mutex_lock+0x152a/0x1b80
Read of size 8 at addr ffff8880470e2c60 by task kworker/1:2/982
...
__mutex_lock+0x152a/0x1b80
usbatm_usb_disconnect+0x70/0x820
uea_disconnect+0x133/0x2c0
usb_unbind_interface+0x1dd/0x9e0
...
which belongs to the cache kmalloc-96 of size 96
The buggy address is located 0 bytes to the right of
allocated 96-byte region [ffff8880470e2c00, ffff8880470e2c60)
Reject such inconsistent descriptors in uea_probe() so that both handlers
always make the same pre/post-firmware decision.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d85f19aaef42a03e3e4765d659c761c8750a7f23 Version: 76861031b43a18065d13f9ffb8595d25c7576005 Version: bbfedc84714064ea4845e6b76f96316eb5bb65d8 Version: f2a6abc670104fc3e383ee3b1cf35c070485e3df Version: c581e30ae5b332d8acef64475a211b3f82099941 Version: 509b51327320bdeaef1969248177a446ded073ab Version: ddcdac47e1f2651c7be60e299f98faf981522797 Version: e2674dfbed8a30d57e2bc872c4bfa6c3eec918bf |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/atm/ueagle-atm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "9e7312844429379108ea9523a5ed934f142bb177",
"status": "affected",
"version": "d85f19aaef42a03e3e4765d659c761c8750a7f23",
"versionType": "git"
},
{
"lessThan": "f92832262718443feb4e5df2bf70424ba842629e",
"status": "affected",
"version": "76861031b43a18065d13f9ffb8595d25c7576005",
"versionType": "git"
},
{
"lessThan": "e814ae925f6f575325124c29dde518b92c822b83",
"status": "affected",
"version": "bbfedc84714064ea4845e6b76f96316eb5bb65d8",
"versionType": "git"
},
{
"lessThan": "c035b1198906dd5bd3df9a3045b59254bad1ea7a",
"status": "affected",
"version": "f2a6abc670104fc3e383ee3b1cf35c070485e3df",
"versionType": "git"
},
{
"lessThan": "9904a46401198872ab3de34fd11f383831ef3428",
"status": "affected",
"version": "c581e30ae5b332d8acef64475a211b3f82099941",
"versionType": "git"
},
{
"lessThan": "d0a57f19fe2865b9747484f5f9c631f944ed9a0f",
"status": "affected",
"version": "509b51327320bdeaef1969248177a446ded073ab",
"versionType": "git"
},
{
"lessThan": "0cc0c4c14150bb5a16b88dd61368f96cd4caa9ce",
"status": "affected",
"version": "ddcdac47e1f2651c7be60e299f98faf981522797",
"versionType": "git"
},
{
"lessThan": "71132cedd1ecbc4032d76e9928c18a10f7e39b80",
"status": "affected",
"version": "e2674dfbed8a30d57e2bc872c4bfa6c3eec918bf",
"versionType": "git"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/atm/ueagle-atm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "5.10.265",
"status": "affected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThan": "5.15.216",
"status": "affected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThan": "6.1.183",
"status": "affected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThan": "6.6.148",
"status": "affected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThan": "6.12.101",
"status": "affected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThan": "6.18.42",
"status": "affected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThan": "7.1.6",
"status": "affected",
"version": "7.1.5",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.10.261",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.15.212",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "6.1.178",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.6.145",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.12.97",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.18.40",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "7.1.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: atm: ueagle-atm: reject descriptors that confuse probe and disconnect\n\nuea_probe() distinguishes a pre-firmware device from a post-firmware one\nusing the USB id (UEA_IS_PREFIRM()), and stores a different object as the\ninterface data in each case: a \u0027struct completion\u0027 for a pre-firmware\ndevice (to be waited on in .disconnect()), or a \u0027struct usbatm_data\u0027 for a\npost-firmware one.\n\nuea_disconnect() instead tells the two apart by the number of interfaces\nof the active configuration (a pre-firmware device exposes a single\ninterface, ADI930 has 2 and eagle has 3), and casts the interface data\naccordingly.\n\nBecause the two handlers use different criteria, a crafted device that\nadvertises a pre-firmware id together with a multi-interface descriptor\n(or a post-firmware id with a single interface) makes them disagree: the\nsmall \u0027struct completion\u0027 stored by uea_probe() is then passed to\nusbatm_usb_disconnect(), which casts it to \u0027struct usbatm_data\u0027 and takes\ninstance-\u003eserialize, reading past the end of the allocation:\n\n BUG: KASAN: slab-out-of-bounds in __mutex_lock+0x152a/0x1b80\n Read of size 8 at addr ffff8880470e2c60 by task kworker/1:2/982\n ...\n __mutex_lock+0x152a/0x1b80\n usbatm_usb_disconnect+0x70/0x820\n uea_disconnect+0x133/0x2c0\n usb_unbind_interface+0x1dd/0x9e0\n ...\n which belongs to the cache kmalloc-96 of size 96\n The buggy address is located 0 bytes to the right of\n allocated 96-byte region [ffff8880470e2c00, ffff8880470e2c60)\n\nReject such inconsistent descriptors in uea_probe() so that both handlers\nalways make the same pre/post-firmware decision."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:45.376Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/9e7312844429379108ea9523a5ed934f142bb177"
},
{
"url": "https://git.kernel.org/stable/c/f92832262718443feb4e5df2bf70424ba842629e"
},
{
"url": "https://git.kernel.org/stable/c/e814ae925f6f575325124c29dde518b92c822b83"
},
{
"url": "https://git.kernel.org/stable/c/c035b1198906dd5bd3df9a3045b59254bad1ea7a"
},
{
"url": "https://git.kernel.org/stable/c/9904a46401198872ab3de34fd11f383831ef3428"
},
{
"url": "https://git.kernel.org/stable/c/d0a57f19fe2865b9747484f5f9c631f944ed9a0f"
},
{
"url": "https://git.kernel.org/stable/c/0cc0c4c14150bb5a16b88dd61368f96cd4caa9ce"
},
{
"url": "https://git.kernel.org/stable/c/71132cedd1ecbc4032d76e9928c18a10f7e39b80"
}
],
"title": "usb: atm: ueagle-atm: reject descriptors that confuse probe and disconnect",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68344",
"datePublished": "2026-08-10T12:03:20.917Z",
"dateReserved": "2026-07-30T09:28:09.384Z",
"dateUpdated": "2026-08-19T16:33:45.376Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64568 (GCVE-0-2026-64568)
Vulnerability from cvelistv5
Published
2026-08-05 08:08
Modified
2026-08-17 04:57
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure
ieee80211_set_unsol_bcast_probe_resp() calls kfree_rcu() on the old
template before allocating the replacement. If the kzalloc() then fails,
it returns -ENOMEM while link->u.ap.unsol_bcast_probe_resp still points
at the object already queued for freeing. A later update or AP teardown
re-queues that same rcu_head; the second free is caught by KASAN when the
RCU sheaf is processed in softirq:
BUG: KASAN: double-free in rcu_free_sheaf (mm/slub.c:5850)
Free of addr ffff88800d06f300 by task exploit/145
...
__rcu_free_sheaf_prepare (mm/slub.c:2634 mm/slub.c:2940)
rcu_free_sheaf (mm/slub.c:5850)
rcu_core (kernel/rcu/tree.c:2617 kernel/rcu/tree.c:2869)
handle_softirqs (kernel/softirq.c:622)
The buggy address belongs to the cache kmalloc-128 of size 128
Queue the old object for kfree_rcu() only after the new one is published,
matching ieee80211_set_probe_resp() and ieee80211_set_s1g_short_beacon().
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/mac80211/cfg.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ca27a81cd77b698e5eb586a011bee6800c7ee4bd",
"status": "affected",
"version": "3b1c256eb4aedfc71dd97d5951ccff824b41d628",
"versionType": "git"
},
{
"lessThan": "d62b55b7c7dc62887d7fd5648fb38f0bfaef53ae",
"status": "affected",
"version": "3b1c256eb4aedfc71dd97d5951ccff824b41d628",
"versionType": "git"
},
{
"lessThan": "0ace76e410d7f7d813b605825a3e593a79c3958f",
"status": "affected",
"version": "3b1c256eb4aedfc71dd97d5951ccff824b41d628",
"versionType": "git"
},
{
"lessThan": "1d067abcd37062426c59ec73dbc4e87a63f33fea",
"status": "affected",
"version": "3b1c256eb4aedfc71dd97d5951ccff824b41d628",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/mac80211/cfg.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.7"
},
{
"lessThan": "6.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure\n\nieee80211_set_unsol_bcast_probe_resp() calls kfree_rcu() on the old\ntemplate before allocating the replacement. If the kzalloc() then fails,\nit returns -ENOMEM while link-\u003eu.ap.unsol_bcast_probe_resp still points\nat the object already queued for freeing. A later update or AP teardown\nre-queues that same rcu_head; the second free is caught by KASAN when the\nRCU sheaf is processed in softirq:\n\n BUG: KASAN: double-free in rcu_free_sheaf (mm/slub.c:5850)\n Free of addr ffff88800d06f300 by task exploit/145\n ...\n __rcu_free_sheaf_prepare (mm/slub.c:2634 mm/slub.c:2940)\n rcu_free_sheaf (mm/slub.c:5850)\n rcu_core (kernel/rcu/tree.c:2617 kernel/rcu/tree.c:2869)\n handle_softirqs (kernel/softirq.c:622)\n The buggy address belongs to the cache kmalloc-128 of size 128\n\nQueue the old object for kfree_rcu() only after the new one is published,\nmatching ieee80211_set_probe_resp() and ieee80211_set_s1g_short_beacon()."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Triggered only via local nl80211 SoftAP config (NL80211_CMD_START_AP/SET_BEACON/CHANNEL_SWITCH/COLOR_CHANGE \u2192 ieee80211_set_unsol_bcast_probe_resp), not by processing over-the-air WiFi frames or remote packets.\nAC:L - The attacker fully controls the SET_BEACON/STOP_AP sequence and can force the GFP_KERNEL kzalloc failure (e.g. memory pressure/memcg) with an attacker-chosen template size; no race or condition outside attacker influence is required.\nPR:L - START_AP and SET_BEACON use GENL_UNS_ADMIN_PERM (CAP_NET_ADMIN in the wiphy netns user_ns). Per CNA guidance that capability via user namespaces scores Low, not init-namespace root High.\nUI:N - The attacker issues the nl80211 commands to set the unsolicited broadcast probe response template and later tear down or update the AP; no separate victim action is required.\nS:U - Impact stays inside the host kernel mac80211 heap (local privilege-escalation class) and does not cross a VM, IOMMU, or other separate security authority.\nC:H - After the failed alloc the dangling unsol_bcast_probe_resp pointer can be read via ieee80211_get_unsol_bcast_probe_resp_tmpl and the object is double-freed; double-free/UAF enables heap reuse and arbitrary kernel memory disclosure.\nI:H - Double-free of the attacker-sized kmalloc unsol_bcast_probe_resp template (and subsequent stop_ap/update re-free) is classic heap corruption enabling spray/arbitrary-write and control-flow hijack primitives.\nA:H - The bug is a KASAN-confirmed double-free in rcu_free_sheaf softirq processing (task exploit/145) and can oops/panic the kernel, fully denying availability."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:57:46.839Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ca27a81cd77b698e5eb586a011bee6800c7ee4bd"
},
{
"url": "https://git.kernel.org/stable/c/d62b55b7c7dc62887d7fd5648fb38f0bfaef53ae"
},
{
"url": "https://git.kernel.org/stable/c/0ace76e410d7f7d813b605825a3e593a79c3958f"
},
{
"url": "https://git.kernel.org/stable/c/1d067abcd37062426c59ec73dbc4e87a63f33fea"
}
],
"title": "wifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64568",
"datePublished": "2026-08-05T08:08:06.625Z",
"dateReserved": "2026-07-19T15:36:31.797Z",
"dateUpdated": "2026-08-17T04:57:46.839Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68248 (GCVE-0-2026-68248)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-19 16:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/i915: Return NULL on error in active_instance
Avoid returning &node->base when node is NULL due to OOM
during GFP_ATOMIC allocation.
Discovered using AI-assisted static analysis confirmed by
Intel Product Security.
(cherry picked from commit 6029bc064f0b1bac184203a50fbaaf070fa18832)
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: bfaae47db3c0989c0ca82a1d59ca3088860b1845 Version: bfaae47db3c0989c0ca82a1d59ca3088860b1845 Version: bfaae47db3c0989c0ca82a1d59ca3088860b1845 Version: bfaae47db3c0989c0ca82a1d59ca3088860b1845 Version: bfaae47db3c0989c0ca82a1d59ca3088860b1845 Version: bfaae47db3c0989c0ca82a1d59ca3088860b1845 Version: bfaae47db3c0989c0ca82a1d59ca3088860b1845 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/i915/i915_active.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a727a004d14580b2fc9bec9e1a9ea60a9016cfcf",
"status": "affected",
"version": "bfaae47db3c0989c0ca82a1d59ca3088860b1845",
"versionType": "git"
},
{
"lessThan": "2bc7c50ffca43e1824cf29738d0572f1eb21f261",
"status": "affected",
"version": "bfaae47db3c0989c0ca82a1d59ca3088860b1845",
"versionType": "git"
},
{
"lessThan": "32c1a2afa90dd07df931f0b12578de1dbb751f0c",
"status": "affected",
"version": "bfaae47db3c0989c0ca82a1d59ca3088860b1845",
"versionType": "git"
},
{
"lessThan": "b238d86e7f43afde8e830ef5b8d89ffedbbc7613",
"status": "affected",
"version": "bfaae47db3c0989c0ca82a1d59ca3088860b1845",
"versionType": "git"
},
{
"lessThan": "cbec6a57959ab503e3ad4ad6edd51efb585dce92",
"status": "affected",
"version": "bfaae47db3c0989c0ca82a1d59ca3088860b1845",
"versionType": "git"
},
{
"lessThan": "58b7e63ca0cd964190957ddd169c899256acaee9",
"status": "affected",
"version": "bfaae47db3c0989c0ca82a1d59ca3088860b1845",
"versionType": "git"
},
{
"lessThan": "1e33f0de5fdcd09e51fdec1e5822448970b6420f",
"status": "affected",
"version": "bfaae47db3c0989c0ca82a1d59ca3088860b1845",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/i915/i915_active.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.13"
},
{
"lessThan": "5.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/i915: Return NULL on error in active_instance\n\nAvoid returning \u0026node-\u003ebase when node is NULL due to OOM\nduring GFP_ATOMIC allocation.\n\nDiscovered using AI-assisted static analysis confirmed by\nIntel Product Security.\n\n(cherry picked from commit 6029bc064f0b1bac184203a50fbaaf070fa18832)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:32:15.977Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a727a004d14580b2fc9bec9e1a9ea60a9016cfcf"
},
{
"url": "https://git.kernel.org/stable/c/2bc7c50ffca43e1824cf29738d0572f1eb21f261"
},
{
"url": "https://git.kernel.org/stable/c/32c1a2afa90dd07df931f0b12578de1dbb751f0c"
},
{
"url": "https://git.kernel.org/stable/c/b238d86e7f43afde8e830ef5b8d89ffedbbc7613"
},
{
"url": "https://git.kernel.org/stable/c/cbec6a57959ab503e3ad4ad6edd51efb585dce92"
},
{
"url": "https://git.kernel.org/stable/c/58b7e63ca0cd964190957ddd169c899256acaee9"
},
{
"url": "https://git.kernel.org/stable/c/1e33f0de5fdcd09e51fdec1e5822448970b6420f"
}
],
"title": "drm/i915: Return NULL on error in active_instance",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68248",
"datePublished": "2026-08-10T12:01:14.485Z",
"dateReserved": "2026-07-30T09:28:09.377Z",
"dateUpdated": "2026-08-19T16:32:15.977Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72030 (GCVE-0-2026-72030)
Vulnerability from cvelistv5
Published
2026-08-15 05:51
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ata: libata-core: Reject an invalid concurrent positioning ranges count
ata_dev_config_cpr() takes the number of range descriptors from buf[0]
of the concurrent positioning ranges log (up to 255), which the device
reports independently of the log size in the GPL directory. The count is
then walked at a fixed 32-byte stride in two places with no bound: the
log read here, and the INQUIRY VPD page B9h emitter, which writes one
descriptor per range into the fixed 2048-byte ata_scsi_rbuf. A device
reporting a count larger than its own log overflows the read buffer (up
to 7704 bytes past a 512-byte slab), and a count above 62 overflows the
response buffer on the emit side.
Bound the count once, on probe, against both the log the device returned
and the number of descriptors the VPD B9h response buffer can hold
(ATA_DEV_MAX_CPR, derived from the rbuf size). Reject an out-of-range
count with a warning; this keeps the emitter in bounds with no separate
change there.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: fe22e1c2f705676a705d821301fc52eecc2fe055 Version: fe22e1c2f705676a705d821301fc52eecc2fe055 Version: fe22e1c2f705676a705d821301fc52eecc2fe055 Version: fe22e1c2f705676a705d821301fc52eecc2fe055 Version: fe22e1c2f705676a705d821301fc52eecc2fe055 Version: fe22e1c2f705676a705d821301fc52eecc2fe055 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/ata/libata-core.c",
"drivers/ata/libata-scsi.c",
"drivers/ata/libata.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "01d7d321e6046f87ba270aeeffdc5260209bd91e",
"status": "affected",
"version": "fe22e1c2f705676a705d821301fc52eecc2fe055",
"versionType": "git"
},
{
"lessThan": "4cb4b4dd8853c4ab3057efe238b2c34277772176",
"status": "affected",
"version": "fe22e1c2f705676a705d821301fc52eecc2fe055",
"versionType": "git"
},
{
"lessThan": "b1607f0ee5f5e53e0aa66f41794085b7cc98f5d1",
"status": "affected",
"version": "fe22e1c2f705676a705d821301fc52eecc2fe055",
"versionType": "git"
},
{
"lessThan": "4c1e8ccd8655ee8cf1bcb1b7dfee72c9fa941fd4",
"status": "affected",
"version": "fe22e1c2f705676a705d821301fc52eecc2fe055",
"versionType": "git"
},
{
"lessThan": "d43efd1b5d976203e6f1ef26f67e8b1a7bc2751b",
"status": "affected",
"version": "fe22e1c2f705676a705d821301fc52eecc2fe055",
"versionType": "git"
},
{
"lessThan": "533a0b940f901c15e5cbbd4b5d66e871c209e8ce",
"status": "affected",
"version": "fe22e1c2f705676a705d821301fc52eecc2fe055",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/ata/libata-core.c",
"drivers/ata/libata-scsi.c",
"drivers/ata/libata.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.16"
},
{
"lessThan": "5.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.16",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nata: libata-core: Reject an invalid concurrent positioning ranges count\n\nata_dev_config_cpr() takes the number of range descriptors from buf[0]\nof the concurrent positioning ranges log (up to 255), which the device\nreports independently of the log size in the GPL directory. The count is\nthen walked at a fixed 32-byte stride in two places with no bound: the\nlog read here, and the INQUIRY VPD page B9h emitter, which writes one\ndescriptor per range into the fixed 2048-byte ata_scsi_rbuf. A device\nreporting a count larger than its own log overflows the read buffer (up\nto 7704 bytes past a 512-byte slab), and a count above 62 overflows the\nresponse buffer on the emit side.\n\nBound the count once, on probe, against both the log the device returned\nand the number of descriptors the VPD B9h response buffer can hold\n(ATA_DEV_MAX_CPR, derived from the rbuf size). Reject an out-of-range\ncount with a warning; this keeps the emitter in bounds with no separate\nchange there."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:28.762Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/01d7d321e6046f87ba270aeeffdc5260209bd91e"
},
{
"url": "https://git.kernel.org/stable/c/4cb4b4dd8853c4ab3057efe238b2c34277772176"
},
{
"url": "https://git.kernel.org/stable/c/b1607f0ee5f5e53e0aa66f41794085b7cc98f5d1"
},
{
"url": "https://git.kernel.org/stable/c/4c1e8ccd8655ee8cf1bcb1b7dfee72c9fa941fd4"
},
{
"url": "https://git.kernel.org/stable/c/d43efd1b5d976203e6f1ef26f67e8b1a7bc2751b"
},
{
"url": "https://git.kernel.org/stable/c/533a0b940f901c15e5cbbd4b5d66e871c209e8ce"
}
],
"title": "ata: libata-core: Reject an invalid concurrent positioning ranges count",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72030",
"datePublished": "2026-08-15T05:51:53.189Z",
"dateReserved": "2026-08-09T03:40:39.901Z",
"dateUpdated": "2026-08-23T12:46:28.762Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72137 (GCVE-0-2026-72137)
Vulnerability from cvelistv5
Published
2026-08-15 05:53
Modified
2026-08-17 05:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
xfrm: nat_keepalive: avoid double free on send error
nat_keepalive_send() frees the keepalive skb whenever the IPv4 or IPv6
send helper reports an error.
That cleanup is only correct before the skb is handed to the output
path. Once ip_build_and_send_pkt() or ip6_xmit() takes ownership, the
networking stack may already have consumed the skb before returning an
error, so freeing it again is unsafe.
Handle the pre-handoff failure cases inside nat_keepalive_send_ipv4()
and nat_keepalive_send_ipv6(), where the caller still owns the skb, and
keep nat_keepalive_send() responsible only for family dispatch and the
unsupported-family cleanup path.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/xfrm/xfrm_nat_keepalive.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "d0a4dc7efa825bce60a8da8f7d43c864a159abde",
"status": "affected",
"version": "f531d13bdfe3f4f084aaa8acae2cb0f02295f5ae",
"versionType": "git"
},
{
"lessThan": "5b0c4c916f202b8fd13d12afb6af62b385622f81",
"status": "affected",
"version": "f531d13bdfe3f4f084aaa8acae2cb0f02295f5ae",
"versionType": "git"
},
{
"lessThan": "a8a7e6a9ff8a4c1f067694ddbd44be67fdf36693",
"status": "affected",
"version": "f531d13bdfe3f4f084aaa8acae2cb0f02295f5ae",
"versionType": "git"
},
{
"lessThan": "226f4a490d1a938fc838d8f8c46a4eca864c0d78",
"status": "affected",
"version": "f531d13bdfe3f4f084aaa8acae2cb0f02295f5ae",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/xfrm/xfrm_nat_keepalive.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.11"
},
{
"lessThan": "6.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: nat_keepalive: avoid double free on send error\n\nnat_keepalive_send() frees the keepalive skb whenever the IPv4 or IPv6\nsend helper reports an error.\n\nThat cleanup is only correct before the skb is handed to the output\npath. Once ip_build_and_send_pkt() or ip6_xmit() takes ownership, the\nnetworking stack may already have consumed the skb before returning an\nerror, so freeing it again is unsafe.\n\nHandle the pre-handoff failure cases inside nat_keepalive_send_ipv4()\nand nat_keepalive_send_ipv6(), where the caller still owns the skb, and\nkeep nat_keepalive_send() responsible only for family dispatch and the\nunsupported-family cleanup path."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - On internet-facing IPsec VPN gateways using kernel NAT keepalive, a remote attacker can induce post-handoff outbound send failures (e.g., ENOMEM from network-driven memory pressure) when periodic keepalives are transmitted, reaching the vulnerable double-free path.\nAC:L - After an outbound ESP-in-UDP SA has NAT keepalive configured, an attacker can reliably force send errors where the stack already consumed the skb (ip6_xmit EMSGSIZE, ip_finish_output2 neighbour/ENOMEM paths) without uncontrollable races or memory layout dependencies.\nPR:N - Remote exploitation requires no privileges on the victim; it only needs a typical IPsec NAT-T deployment where userspace already set XFRMA_NAT_KEEPALIVE_INTERVAL. Local exploitation via user namespaces needs only CAP_NET_ADMIN (PR:L), not root in the init namespace.\nUI:N - No victim or administrator interaction is needed during exploitation; NAT keepalives are sent automatically by the kernel delayed work queue on the configured interval once the XFRM SA exists.\nS:U - Impact is kernel heap corruption and privilege escalation within the same security authority; this is not a VM escape, container breakout, or IOMMU/DMA boundary bypass.\nC:H - The skb double-free corrupts the slab allocator and yields use-after-free primitives that can be leveraged for arbitrary kernel memory disclosure, not merely a bounded leak or crash-only NULL dereference.\nI:H - Double-free heap corruption enables attacker-controlled reallocation of freed sk_buff objects, supporting arbitrary kernel memory writes, control-flow hijacking, and local privilege escalation.\nA:H - The double-free reliably causes slab corruption, kernel oops, or panic during keepalive send-error cleanup, providing immediate and repeatable denial of service on affected systems."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:40:47.767Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/d0a4dc7efa825bce60a8da8f7d43c864a159abde"
},
{
"url": "https://git.kernel.org/stable/c/5b0c4c916f202b8fd13d12afb6af62b385622f81"
},
{
"url": "https://git.kernel.org/stable/c/a8a7e6a9ff8a4c1f067694ddbd44be67fdf36693"
},
{
"url": "https://git.kernel.org/stable/c/226f4a490d1a938fc838d8f8c46a4eca864c0d78"
}
],
"title": "xfrm: nat_keepalive: avoid double free on send error",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72137",
"datePublished": "2026-08-15T05:53:11.812Z",
"dateReserved": "2026-08-09T03:40:39.908Z",
"dateUpdated": "2026-08-17T05:40:47.767Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68310 (GCVE-0-2026-68310)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: mt76: mt7915: guard HE capability lookups
mt7915_mcu_bss_he_tlv() and mt7915_mcu_sta_bfer_tlv() both run after
checking HE support, then dereference the HE PHY capability returned by
mt76_connac_get_he_phy_cap(). That helper can return NULL when no
capability entry matches the vif type.
Fetch the capability before appending the TLV and skip the HE-specific
setup when no matching capability is available.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: e6d557a78b6016eee7b9cd6832343efd32cc0b27 Version: e6d557a78b6016eee7b9cd6832343efd32cc0b27 Version: e6d557a78b6016eee7b9cd6832343efd32cc0b27 Version: e6d557a78b6016eee7b9cd6832343efd32cc0b27 Version: e6d557a78b6016eee7b9cd6832343efd32cc0b27 Version: e6d557a78b6016eee7b9cd6832343efd32cc0b27 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/mediatek/mt76/mt7915/mcu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "8d5f1f4d2ea2c9d626ccc28dba7ea0df862acc67",
"status": "affected",
"version": "e6d557a78b6016eee7b9cd6832343efd32cc0b27",
"versionType": "git"
},
{
"lessThan": "23a2b98e754da04e0e90314d5fa8ca44349590fb",
"status": "affected",
"version": "e6d557a78b6016eee7b9cd6832343efd32cc0b27",
"versionType": "git"
},
{
"lessThan": "a031f454f14e3e76ad03bcb23918e1a82b4b0869",
"status": "affected",
"version": "e6d557a78b6016eee7b9cd6832343efd32cc0b27",
"versionType": "git"
},
{
"lessThan": "871549814eb4da081f1e93cc0c7ea626a310a966",
"status": "affected",
"version": "e6d557a78b6016eee7b9cd6832343efd32cc0b27",
"versionType": "git"
},
{
"lessThan": "6f99a5667c6c7c3e0da1d3c4dc8dfb103042609e",
"status": "affected",
"version": "e6d557a78b6016eee7b9cd6832343efd32cc0b27",
"versionType": "git"
},
{
"lessThan": "8e9db062654a388d0fa587acbeeae68dd33eba41",
"status": "affected",
"version": "e6d557a78b6016eee7b9cd6832343efd32cc0b27",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/mediatek/mt76/mt7915/mcu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.18"
},
{
"lessThan": "5.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.18",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7915: guard HE capability lookups\n\nmt7915_mcu_bss_he_tlv() and mt7915_mcu_sta_bfer_tlv() both run after\nchecking HE support, then dereference the HE PHY capability returned by\nmt76_connac_get_he_phy_cap(). That helper can return NULL when no\ncapability entry matches the vif type.\n\nFetch the capability before appending the TLV and skip the HE-specific\nsetup when no matching capability is available."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:03.090Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/8d5f1f4d2ea2c9d626ccc28dba7ea0df862acc67"
},
{
"url": "https://git.kernel.org/stable/c/23a2b98e754da04e0e90314d5fa8ca44349590fb"
},
{
"url": "https://git.kernel.org/stable/c/a031f454f14e3e76ad03bcb23918e1a82b4b0869"
},
{
"url": "https://git.kernel.org/stable/c/871549814eb4da081f1e93cc0c7ea626a310a966"
},
{
"url": "https://git.kernel.org/stable/c/6f99a5667c6c7c3e0da1d3c4dc8dfb103042609e"
},
{
"url": "https://git.kernel.org/stable/c/8e9db062654a388d0fa587acbeeae68dd33eba41"
}
],
"title": "wifi: mt76: mt7915: guard HE capability lookups",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68310",
"datePublished": "2026-08-10T12:02:44.917Z",
"dateReserved": "2026-07-30T09:28:09.381Z",
"dateUpdated": "2026-08-19T16:33:03.090Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72372 (GCVE-0-2026-72372)
Vulnerability from cvelistv5
Published
2026-08-15 05:56
Modified
2026-08-17 05:43
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
afs: Fix lack of locking around modifications of net->cells_dyn_ino
Fix the lack of locking around modifications of net->cells_dyn_ino by
taking net->cells_lock exclusively. This also requires to cell to be
removed from net->cells_dyn_ino in afs_destroy_cell_work() rather than in
afs_cell_destroy() as the latter runs in RCU cleanup context and sleeping
locks cannot be taken there.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/afs/cell.c",
"fs/afs/dynroot.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "4d8a2fe8847859f4fa4e9a2fa1221c9c1158e66b",
"status": "affected",
"version": "537b0105952578531f748c7fb3ce36ae9a514784",
"versionType": "git"
},
{
"lessThan": "2ffb70a8a01988046bb207b7d0af9358a8337378",
"status": "affected",
"version": "1d0b929fc070b4115403a0a6206a0c6a62dd61f5",
"versionType": "git"
},
{
"lessThan": "e94f92fd56c553a8bf9421c3289e1b85c7c08857",
"status": "affected",
"version": "1d0b929fc070b4115403a0a6206a0c6a62dd61f5",
"versionType": "git"
},
{
"lessThan": "55e841836c6f4646490f7b0347192b7a92d431ba",
"status": "affected",
"version": "1d0b929fc070b4115403a0a6206a0c6a62dd61f5",
"versionType": "git"
},
{
"lessThan": "6.12.101",
"status": "affected",
"version": "6.12.97",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/afs/cell.c",
"fs/afs/dynroot.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.15"
},
{
"lessThan": "6.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.12.97",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "6.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "6.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nafs: Fix lack of locking around modifications of net-\u003ecells_dyn_ino\n\nFix the lack of locking around modifications of net-\u003ecells_dyn_ino by\ntaking net-\u003ecells_lock exclusively. This also requires to cell to be\nremoved from net-\u003ecells_dyn_ino in afs_destroy_cell_work() rather than in\nafs_cell_destroy() as the latter runs in RCU cleanup context and sleeping\nlocks cannot be taken there."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached only through local VFS operations on an AFS dynroot mount (getdents/readdir via afs_dynroot_readdir, lookup via afs_dynroot_lookup_cell) and cell create/destroy paths (afs_alloc_cell/afs_destroy_cell_work), not from remote AFS/RxRPC packet handling.\nAC:L - An attacker can reliably win the race by running concurrent threads that repeatedly readdir /afs while creating and expiring cells through lookups or /proc/net/afs/cells writes; syzbot and public PoCs reproduced the slab UAF within minutes without uncontrollable layout dependencies.\nPR:L - Exploitation requires only an unprivileged local user who can access a dynroot mount (typical world-readable /afs on AFS clients) or mount AFS with -o dyn inside a user namespace where CAP_SYS_ADMIN is available; real init-namespace root is not required.\nUI:N - No victim interaction is needed once dynroot is available; the attacker directly issues the readdir and cell-creation syscalls that race unsynchronized idr_alloc_cyclic, idr_remove, and idr_get_next on net-\u003ecells_dyn_ino.\nS:U - Impact is confined to kernel memory integrity and privilege boundaries within the host kernel; it does not cross VM, container, or IOMMU security scopes into a different authority.\nC:H - Concurrent idr_remove during afs_dynroot_readdir_cells leaves idr_get_next with a dangling afs_cell pointer, causing slab use-after-free reads of cell-\u003ename and cell-\u003estate (confirmed by KASAN in afs_dynroot_readdir) and enabling further kernel memory disclosure.\nI:H - IDR tree corruption and use-after-free of afs_cell objects provide attacker-influenced heap corruption primitives that can be developed into arbitrary kernel writes or control-flow hijack, not merely a benign error return.\nA:H - The race causes kernel oops/panic from corrupted IDR traversal or use-after-free during dir_emit; repeated triggering can crash or hang the system, satisfying high availability impact."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:43:25.401Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/4d8a2fe8847859f4fa4e9a2fa1221c9c1158e66b"
},
{
"url": "https://git.kernel.org/stable/c/2ffb70a8a01988046bb207b7d0af9358a8337378"
},
{
"url": "https://git.kernel.org/stable/c/e94f92fd56c553a8bf9421c3289e1b85c7c08857"
},
{
"url": "https://git.kernel.org/stable/c/55e841836c6f4646490f7b0347192b7a92d431ba"
}
],
"title": "afs: Fix lack of locking around modifications of net-\u003ecells_dyn_ino",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72372",
"datePublished": "2026-08-15T05:56:07.916Z",
"dateReserved": "2026-08-09T03:40:39.922Z",
"dateUpdated": "2026-08-17T05:43:25.401Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68153 (GCVE-0-2026-68153)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
libceph: remove debugfs files before client teardown
ceph_destroy_client() tears down the monitor client before removing
the per-client debugfs files. A concurrent read of the monmap debugfs
file can enter monmap_show() after ceph_monc_stop() has freed
monc->monmap, triggering a use-after-free.
Remove the debugfs files before stopping the OSD and monitor clients.
debugfs_remove() drains active handlers and prevents new accesses, so
the debugfs callbacks can no longer race the rest of client teardown.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 76aa844d5b2fb8c839180d3f5874e333b297e5fd Version: 76aa844d5b2fb8c839180d3f5874e333b297e5fd Version: 76aa844d5b2fb8c839180d3f5874e333b297e5fd Version: 76aa844d5b2fb8c839180d3f5874e333b297e5fd Version: 76aa844d5b2fb8c839180d3f5874e333b297e5fd Version: 76aa844d5b2fb8c839180d3f5874e333b297e5fd Version: 76aa844d5b2fb8c839180d3f5874e333b297e5fd Version: 76aa844d5b2fb8c839180d3f5874e333b297e5fd |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ceph/ceph_common.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ac78549d186090ee7125d28c3a8c376573b36194",
"status": "affected",
"version": "76aa844d5b2fb8c839180d3f5874e333b297e5fd",
"versionType": "git"
},
{
"lessThan": "463a264e9094384112a5c8b46f0a9ddaf8566904",
"status": "affected",
"version": "76aa844d5b2fb8c839180d3f5874e333b297e5fd",
"versionType": "git"
},
{
"lessThan": "fe46b7e06f14f6f94766832df309b249cb689d27",
"status": "affected",
"version": "76aa844d5b2fb8c839180d3f5874e333b297e5fd",
"versionType": "git"
},
{
"lessThan": "fc1010e7e0204ece6cc0f9af4f473e9553535eab",
"status": "affected",
"version": "76aa844d5b2fb8c839180d3f5874e333b297e5fd",
"versionType": "git"
},
{
"lessThan": "d3dc8889d39a676bf840132bd5c5c48cb0daba23",
"status": "affected",
"version": "76aa844d5b2fb8c839180d3f5874e333b297e5fd",
"versionType": "git"
},
{
"lessThan": "8f5a3abc54ba24dbceb14cc3a719908c4f688091",
"status": "affected",
"version": "76aa844d5b2fb8c839180d3f5874e333b297e5fd",
"versionType": "git"
},
{
"lessThan": "b9fedda2f628e030384228de0dafc574b7fb0c2f",
"status": "affected",
"version": "76aa844d5b2fb8c839180d3f5874e333b297e5fd",
"versionType": "git"
},
{
"lessThan": "e4c804726c4afce3ba648b982d564f6af2cfa328",
"status": "affected",
"version": "76aa844d5b2fb8c839180d3f5874e333b297e5fd",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ceph/ceph_common.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.34"
},
{
"lessThan": "2.6.34",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.34",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: remove debugfs files before client teardown\n\nceph_destroy_client() tears down the monitor client before removing\nthe per-client debugfs files. A concurrent read of the monmap debugfs\nfile can enter monmap_show() after ceph_monc_stop() has freed\nmonc-\u003emonmap, triggering a use-after-free.\n\nRemove the debugfs files before stopping the OSD and monitor clients.\ndebugfs_remove() drains active handlers and prevents new accesses, so\nthe debugfs callbacks can no longer race the rest of client teardown."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires local access to debugfs via read() on /sys/kernel/debug/ceph/client*/monmap concurrent with local ceph client teardown via umount or rbd unmap; the bug is not reachable through Ceph network protocol handlers.\nAC:L - The attacker controls both sides of the race by concurrently reading the monmap debugfs file while triggering ceph_destroy_client() via umount/rbd teardown, and can retry until the window between ceph_monc_stop() and debugfs removal is hit.\nPR:L - An unprivileged local user can use user-namespace capabilities (CAP_DAC_READ_SEARCH) to read root-owned debugfs files and race reads against libceph client teardown during automated volume detach or service restarts on Ceph storage nodes.\nUI:N - No victim user interaction is required; a local attacker can independently issue debugfs reads and trigger or time against client teardown without requiring another user to click, open files, or mount filesystems.\nS:U - The use-after-free corrupts kernel heap memory within the same kernel security domain and does not cross VM, container, or IOMMU boundaries; impact is standard kernel privilege escalation or crash.\nC:H - The use-after-free on monc-\u003emonmap permits reading freed heap memory containing monitor addresses and entity metadata, and UAF primitives are routinely leveraged for arbitrary kernel memory disclosure.\nI:H - Heap use-after-free on the variable-length ceph_monmap structure enables memory corruption that can be groomed into arbitrary kernel write primitives and local privilege escalation via control-flow hijacking.\nA:H - Concurrent access to freed monmap memory during debugfs iteration can cause kernel oops, BUG, or panic, and UAF corruption reliably threatens system availability even when full exploitation is not attempted."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:30:18.048Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ac78549d186090ee7125d28c3a8c376573b36194"
},
{
"url": "https://git.kernel.org/stable/c/463a264e9094384112a5c8b46f0a9ddaf8566904"
},
{
"url": "https://git.kernel.org/stable/c/fe46b7e06f14f6f94766832df309b249cb689d27"
},
{
"url": "https://git.kernel.org/stable/c/fc1010e7e0204ece6cc0f9af4f473e9553535eab"
},
{
"url": "https://git.kernel.org/stable/c/d3dc8889d39a676bf840132bd5c5c48cb0daba23"
},
{
"url": "https://git.kernel.org/stable/c/8f5a3abc54ba24dbceb14cc3a719908c4f688091"
},
{
"url": "https://git.kernel.org/stable/c/b9fedda2f628e030384228de0dafc574b7fb0c2f"
},
{
"url": "https://git.kernel.org/stable/c/e4c804726c4afce3ba648b982d564f6af2cfa328"
}
],
"title": "libceph: remove debugfs files before client teardown",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68153",
"datePublished": "2026-08-10T11:59:19.302Z",
"dateReserved": "2026-07-30T09:28:09.371Z",
"dateUpdated": "2026-08-19T16:30:18.048Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72017 (GCVE-0-2026-72017)
Vulnerability from cvelistv5
Published
2026-08-15 05:51
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: macb: drop in-flight Tx SKBs on close
The MACB driver has since forever leaked the outgoing SKBs that
have not yet been marked as completed. They live in queue->tx_skb
which gets freed without remorse nor checking.
macb_free_consistent() gets called in a few codepaths, but only close will
trigger the added expressions. In macb_open() and macb_alloc_consistent()
failure cases, queues' tx_skb just got allocated and are empty.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 89e5785fc8a6b9eafd37f2318a9a76d479c796be Version: 89e5785fc8a6b9eafd37f2318a9a76d479c796be Version: 89e5785fc8a6b9eafd37f2318a9a76d479c796be Version: 89e5785fc8a6b9eafd37f2318a9a76d479c796be Version: 89e5785fc8a6b9eafd37f2318a9a76d479c796be Version: 89e5785fc8a6b9eafd37f2318a9a76d479c796be |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/cadence/macb_main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "0e9797dc4ebdefe1b7f931b1f92d5e98e5dbf655",
"status": "affected",
"version": "89e5785fc8a6b9eafd37f2318a9a76d479c796be",
"versionType": "git"
},
{
"lessThan": "6124bd785073659c99385094657b77382ebce11b",
"status": "affected",
"version": "89e5785fc8a6b9eafd37f2318a9a76d479c796be",
"versionType": "git"
},
{
"lessThan": "2143fdc0ce27adbb1caaa1a97e0bfb9f3750aef4",
"status": "affected",
"version": "89e5785fc8a6b9eafd37f2318a9a76d479c796be",
"versionType": "git"
},
{
"lessThan": "26b131b2d5b55a81ef6182769d28105a870c0eb2",
"status": "affected",
"version": "89e5785fc8a6b9eafd37f2318a9a76d479c796be",
"versionType": "git"
},
{
"lessThan": "109241d9880488aafd8e104832b4d4859ad57244",
"status": "affected",
"version": "89e5785fc8a6b9eafd37f2318a9a76d479c796be",
"versionType": "git"
},
{
"lessThan": "27f575836cfebbf872dec020428742b10650a955",
"status": "affected",
"version": "89e5785fc8a6b9eafd37f2318a9a76d479c796be",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/cadence/macb_main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.20"
},
{
"lessThan": "2.6.20",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "2.6.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "2.6.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "2.6.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.20",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: macb: drop in-flight Tx SKBs on close\n\nThe MACB driver has since forever leaked the outgoing SKBs that\nhave not yet been marked as completed. They live in queue-\u003etx_skb\nwhich gets freed without remorse nor checking.\n\nmacb_free_consistent() gets called in a few codepaths, but only close will\ntrigger the added expressions. In macb_open() and macb_alloc_consistent()\nfailure cases, queues\u0027 tx_skb just got allocated and are empty."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:26.593Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/0e9797dc4ebdefe1b7f931b1f92d5e98e5dbf655"
},
{
"url": "https://git.kernel.org/stable/c/6124bd785073659c99385094657b77382ebce11b"
},
{
"url": "https://git.kernel.org/stable/c/2143fdc0ce27adbb1caaa1a97e0bfb9f3750aef4"
},
{
"url": "https://git.kernel.org/stable/c/26b131b2d5b55a81ef6182769d28105a870c0eb2"
},
{
"url": "https://git.kernel.org/stable/c/109241d9880488aafd8e104832b4d4859ad57244"
},
{
"url": "https://git.kernel.org/stable/c/27f575836cfebbf872dec020428742b10650a955"
}
],
"title": "net: macb: drop in-flight Tx SKBs on close",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72017",
"datePublished": "2026-08-15T05:51:44.698Z",
"dateReserved": "2026-08-09T03:40:39.900Z",
"dateUpdated": "2026-08-23T12:46:26.593Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68218 (GCVE-0-2026-68218)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: pci: dm1105: Free allocated workqueue
Destroy allocated workqueue in remove() callback to free its resources,
thus fixing memory leak.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 519a4bdcf8221c6b2d129b3c720761b7cab7f2c1 Version: 519a4bdcf8221c6b2d129b3c720761b7cab7f2c1 Version: 519a4bdcf8221c6b2d129b3c720761b7cab7f2c1 Version: 519a4bdcf8221c6b2d129b3c720761b7cab7f2c1 Version: 519a4bdcf8221c6b2d129b3c720761b7cab7f2c1 Version: 519a4bdcf8221c6b2d129b3c720761b7cab7f2c1 Version: 519a4bdcf8221c6b2d129b3c720761b7cab7f2c1 Version: 519a4bdcf8221c6b2d129b3c720761b7cab7f2c1 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/pci/dm1105/dm1105.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "078e0750b5e60277e44d780d70c6997c46569df2",
"status": "affected",
"version": "519a4bdcf8221c6b2d129b3c720761b7cab7f2c1",
"versionType": "git"
},
{
"lessThan": "d97f2e37516aa151582c8b2296021332db6da906",
"status": "affected",
"version": "519a4bdcf8221c6b2d129b3c720761b7cab7f2c1",
"versionType": "git"
},
{
"lessThan": "df5cd8b30c750f4edd0766982437d3472a0dbbd4",
"status": "affected",
"version": "519a4bdcf8221c6b2d129b3c720761b7cab7f2c1",
"versionType": "git"
},
{
"lessThan": "46715fecc38a2d341c3ff680f295de6e8aec72c0",
"status": "affected",
"version": "519a4bdcf8221c6b2d129b3c720761b7cab7f2c1",
"versionType": "git"
},
{
"lessThan": "8d753c8c37afc0910ed5ddc014645b05d6266add",
"status": "affected",
"version": "519a4bdcf8221c6b2d129b3c720761b7cab7f2c1",
"versionType": "git"
},
{
"lessThan": "08ddfd628a2dbd9d385da677afccd893d0ab37e1",
"status": "affected",
"version": "519a4bdcf8221c6b2d129b3c720761b7cab7f2c1",
"versionType": "git"
},
{
"lessThan": "0c2b4c45fce012e88904b8c66b5cd786535c0b8c",
"status": "affected",
"version": "519a4bdcf8221c6b2d129b3c720761b7cab7f2c1",
"versionType": "git"
},
{
"lessThan": "1a65db225b25bb8c8febf16974c060e0cc242eb9",
"status": "affected",
"version": "519a4bdcf8221c6b2d129b3c720761b7cab7f2c1",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/pci/dm1105/dm1105.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.31"
},
{
"lessThan": "2.6.31",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.31",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: pci: dm1105: Free allocated workqueue\n\nDestroy allocated workqueue in remove() callback to free its resources,\nthus fixing memory leak."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:50.280Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/078e0750b5e60277e44d780d70c6997c46569df2"
},
{
"url": "https://git.kernel.org/stable/c/d97f2e37516aa151582c8b2296021332db6da906"
},
{
"url": "https://git.kernel.org/stable/c/df5cd8b30c750f4edd0766982437d3472a0dbbd4"
},
{
"url": "https://git.kernel.org/stable/c/46715fecc38a2d341c3ff680f295de6e8aec72c0"
},
{
"url": "https://git.kernel.org/stable/c/8d753c8c37afc0910ed5ddc014645b05d6266add"
},
{
"url": "https://git.kernel.org/stable/c/08ddfd628a2dbd9d385da677afccd893d0ab37e1"
},
{
"url": "https://git.kernel.org/stable/c/0c2b4c45fce012e88904b8c66b5cd786535c0b8c"
},
{
"url": "https://git.kernel.org/stable/c/1a65db225b25bb8c8febf16974c060e0cc242eb9"
}
],
"title": "media: pci: dm1105: Free allocated workqueue",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68218",
"datePublished": "2026-08-10T12:00:38.175Z",
"dateReserved": "2026-07-30T09:28:09.375Z",
"dateUpdated": "2026-08-19T16:31:50.280Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68205 (GCVE-0-2026-68205)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor()
The v4l2 helper v4l2_async_register_subdev_sensor() calls
v4l2_async_register_subdev(), which is a macro that expands to
__v4l2_async_register_subdev(sd,THIS_MODULE). Since the macro is expanded
inside v4l2-fwnode.c, THIS_MODULE resolves to the v4l2-fwnode module
rather than the sensor driver module that originally set sd->owner. When
v4l2-fwnode is built-in, THIS_MODULE evaluates to NULL, which then
overwrites the sensor driver's owner with NULL.
This causes the problem that the sensor module's reference count is never
incremented during async registration, so the module can be removed while
the subdevice is still in use by a notifier (e.g., a CSI-2 receiver
bridge driver).
Fix this by renaming v4l2_async_register_subdev_sensor() to
__v4l2_async_register_subdev_sensor() with an added explicit module
argument and introducing a wrapper macro:
#define v4l2_async_register_subdev_sensor(sd) \
__v4l2_async_register_subdev_sensor(sd, THIS_MODULE)
This ensures the sensor driver module is properly referenced even when
the sensor driver does not init the owner field before calling
v4l2_async_register_subdev_sensor() and prevents premature module removal.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: aef69d54755d45edefbf347a51efd1673d7daed9 Version: aef69d54755d45edefbf347a51efd1673d7daed9 Version: aef69d54755d45edefbf347a51efd1673d7daed9 Version: aef69d54755d45edefbf347a51efd1673d7daed9 Version: aef69d54755d45edefbf347a51efd1673d7daed9 Version: aef69d54755d45edefbf347a51efd1673d7daed9 Version: aef69d54755d45edefbf347a51efd1673d7daed9 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/v4l2-core/v4l2-fwnode.c",
"include/media/v4l2-async.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "f35e85a9d919d7954d9a7752e4644c0b403ad025",
"status": "affected",
"version": "aef69d54755d45edefbf347a51efd1673d7daed9",
"versionType": "git"
},
{
"lessThan": "c5e47cf9a6cffef73a1ed40b3648e6097aac165a",
"status": "affected",
"version": "aef69d54755d45edefbf347a51efd1673d7daed9",
"versionType": "git"
},
{
"lessThan": "47ef04cd13d38010b580056a9d8840aaab944841",
"status": "affected",
"version": "aef69d54755d45edefbf347a51efd1673d7daed9",
"versionType": "git"
},
{
"lessThan": "caea6bc68c925d63ca33d21b2255f47181943d61",
"status": "affected",
"version": "aef69d54755d45edefbf347a51efd1673d7daed9",
"versionType": "git"
},
{
"lessThan": "cf9732fd6c4f2f803ccfc46d89489b6635590270",
"status": "affected",
"version": "aef69d54755d45edefbf347a51efd1673d7daed9",
"versionType": "git"
},
{
"lessThan": "067887ff93fddbb3a3fb84c900bc654ecfe5ba61",
"status": "affected",
"version": "aef69d54755d45edefbf347a51efd1673d7daed9",
"versionType": "git"
},
{
"lessThan": "06cb687a5132fcffe624c0070576ab852ac6b568",
"status": "affected",
"version": "aef69d54755d45edefbf347a51efd1673d7daed9",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/v4l2-core/v4l2-fwnode.c",
"include/media/v4l2-async.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.15"
},
{
"lessThan": "4.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor()\n\nThe v4l2 helper v4l2_async_register_subdev_sensor() calls\nv4l2_async_register_subdev(), which is a macro that expands to\n__v4l2_async_register_subdev(sd,THIS_MODULE). Since the macro is expanded\ninside v4l2-fwnode.c, THIS_MODULE resolves to the v4l2-fwnode module\nrather than the sensor driver module that originally set sd-\u003eowner. When\nv4l2-fwnode is built-in, THIS_MODULE evaluates to NULL, which then\noverwrites the sensor driver\u0027s owner with NULL.\n\nThis causes the problem that the sensor module\u0027s reference count is never\nincremented during async registration, so the module can be removed while\nthe subdevice is still in use by a notifier (e.g., a CSI-2 receiver\nbridge driver).\n\nFix this by renaming v4l2_async_register_subdev_sensor() to\n__v4l2_async_register_subdev_sensor() with an added explicit module\nargument and introducing a wrapper macro:\n #define v4l2_async_register_subdev_sensor(sd) \\\n __v4l2_async_register_subdev_sensor(sd, THIS_MODULE)\n\nThis ensures the sensor driver module is properly referenced even when\nthe sensor driver does not init the owner field before calling\nv4l2_async_register_subdev_sensor() and prevents premature module removal."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:09.673Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/f35e85a9d919d7954d9a7752e4644c0b403ad025"
},
{
"url": "https://git.kernel.org/stable/c/c5e47cf9a6cffef73a1ed40b3648e6097aac165a"
},
{
"url": "https://git.kernel.org/stable/c/47ef04cd13d38010b580056a9d8840aaab944841"
},
{
"url": "https://git.kernel.org/stable/c/caea6bc68c925d63ca33d21b2255f47181943d61"
},
{
"url": "https://git.kernel.org/stable/c/cf9732fd6c4f2f803ccfc46d89489b6635590270"
},
{
"url": "https://git.kernel.org/stable/c/067887ff93fddbb3a3fb84c900bc654ecfe5ba61"
},
{
"url": "https://git.kernel.org/stable/c/06cb687a5132fcffe624c0070576ab852ac6b568"
}
],
"title": "media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68205",
"datePublished": "2026-08-10T12:00:24.265Z",
"dateReserved": "2026-07-30T09:28:09.374Z",
"dateUpdated": "2026-08-23T12:46:09.673Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68388 (GCVE-0-2026-68388)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
smb/client: handle overlapping allocated ranges in fallocate
smb3_simple_fallocate_range() can skip holes when an allocated range
returned by the server starts before the current fallocate offset. The
skipped hole is not zero-filled, but fallocate still returns success. A
later write to that hole may therefore fail with ENOSPC.
The function queries allocated ranges so that it can preserve existing
contents and write zeroes only into holes. However, the server may return
a range that starts before the current fallocate offset.
For example, assume the fallocate request is [100, 400) and the only
allocated range returned by the server is [0, 200):
Request: [100, 400)
Server range: [ 0, 200) allocated
Correct:
[100, 200) allocated data, skip
[200, 400) hole, zero-fill
Current:
[100, 300) skipped
[300, 400) zero-filled afterwards
The current code adds the full server range length, 200, to the current
offset 100 and moves to 300. As a result, the hole in [200, 300) is
skipped without being zero-filled.
Fix this by advancing only over the part of the allocated range that
overlaps the current fallocate offset. Ignore ranges that end before the
current offset and reject ranges whose end offset overflows.
This also prevents a malformed range length from causing an out-of-bounds
zero-buffer read.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: c406bb9ece6ef63721daab106f132ff4b4234e81 Version: 966a3cb7c7db786452a87afdc3b48858fc4d4d6b Version: 966a3cb7c7db786452a87afdc3b48858fc4d4d6b Version: 966a3cb7c7db786452a87afdc3b48858fc4d4d6b Version: 966a3cb7c7db786452a87afdc3b48858fc4d4d6b Version: 966a3cb7c7db786452a87afdc3b48858fc4d4d6b Version: 966a3cb7c7db786452a87afdc3b48858fc4d4d6b Version: 966a3cb7c7db786452a87afdc3b48858fc4d4d6b Version: 2f9f4a2d0e6fcf0673ed51195e06e47abe966900 Version: 5e397c943424de94879830e72c95f2679e297a76 Version: 5.10.50 ≤ Version: 5.12.17 ≤ Version: 5.13.2 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/smb/client/smb2ops.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "aeb58a4eb39a7ff4d7782b4f4ada0fda5e0675d2",
"status": "affected",
"version": "c406bb9ece6ef63721daab106f132ff4b4234e81",
"versionType": "git"
},
{
"lessThan": "01719883235507b1585e4c51e320d9a7113dc698",
"status": "affected",
"version": "966a3cb7c7db786452a87afdc3b48858fc4d4d6b",
"versionType": "git"
},
{
"lessThan": "f47c7277c03a636fcc3a57969f2dc09567b3c050",
"status": "affected",
"version": "966a3cb7c7db786452a87afdc3b48858fc4d4d6b",
"versionType": "git"
},
{
"lessThan": "437637f5ff3f573b2edf8571de91fb00a21eb4e6",
"status": "affected",
"version": "966a3cb7c7db786452a87afdc3b48858fc4d4d6b",
"versionType": "git"
},
{
"lessThan": "377fe3e583e46369ee1004d5cfe12271d6589a68",
"status": "affected",
"version": "966a3cb7c7db786452a87afdc3b48858fc4d4d6b",
"versionType": "git"
},
{
"lessThan": "7e08ab7a061b17ac1989a225c6afb53f44a86808",
"status": "affected",
"version": "966a3cb7c7db786452a87afdc3b48858fc4d4d6b",
"versionType": "git"
},
{
"lessThan": "a4a09e5142835633fffbde68bd0a039ba4d4bf97",
"status": "affected",
"version": "966a3cb7c7db786452a87afdc3b48858fc4d4d6b",
"versionType": "git"
},
{
"lessThan": "b09ae45d85dc816987a71db9eebc54b0ae288e94",
"status": "affected",
"version": "966a3cb7c7db786452a87afdc3b48858fc4d4d6b",
"versionType": "git"
},
{
"status": "affected",
"version": "2f9f4a2d0e6fcf0673ed51195e06e47abe966900",
"versionType": "git"
},
{
"status": "affected",
"version": "5e397c943424de94879830e72c95f2679e297a76",
"versionType": "git"
},
{
"lessThan": "5.10.265",
"status": "affected",
"version": "5.10.50",
"versionType": "semver"
},
{
"lessThan": "5.13",
"status": "affected",
"version": "5.12.17",
"versionType": "semver"
},
{
"lessThan": "5.14",
"status": "affected",
"version": "5.13.2",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/smb/client/smb2ops.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.14"
},
{
"lessThan": "5.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.10.50",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.12.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.13.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb/client: handle overlapping allocated ranges in fallocate\n\nsmb3_simple_fallocate_range() can skip holes when an allocated range\nreturned by the server starts before the current fallocate offset. The\nskipped hole is not zero-filled, but fallocate still returns success. A\nlater write to that hole may therefore fail with ENOSPC.\n\nThe function queries allocated ranges so that it can preserve existing\ncontents and write zeroes only into holes. However, the server may return\na range that starts before the current fallocate offset.\n\nFor example, assume the fallocate request is [100, 400) and the only\nallocated range returned by the server is [0, 200):\n\n Request: [100, 400)\n Server range: [ 0, 200) allocated\n\n Correct:\n [100, 200) allocated data, skip\n [200, 400) hole, zero-fill\n\n Current:\n [100, 300) skipped\n [300, 400) zero-filled afterwards\n\nThe current code adds the full server range length, 200, to the current\noffset 100 and moves to 300. As a result, the hole in [200, 300) is\nskipped without being zero-filled.\n\nFix this by advancing only over the part of the allocated range that\noverlaps the current fallocate offset. Ignore ranges that end before the\ncurrent offset and reject ranges whose end offset overflows.\n\nThis also prevents a malformed range length from causing an out-of-bounds\nzero-buffer read."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The malformed input is the FSCTL_QUERY_ALLOCATED_RANGES response parsed by the SMB client from a remote peer, so a malicious, compromised, or MITM\u0027d SMB server exploits this purely over the network (TCP/445) against the mounted client.\nAC:L - The server fully and deterministically controls the returned range file_offset/length fields; a single record with bit 63 set in length reliably inflates the loop\u0027s len past the 1 MB buffer with no race, timing, or memory-layout precondition.\nPR:N - The attacker is the remote SMB server (or a network MITM) and needs no account, credentials, or privileges on the victim client; only the pre-existing SMB session the client itself established is required.\nUI:N - Against an already-mounted share (fstab/autofs/systemd automount) a compromised or MITM\u0027d server needs no victim action, and fallocate/posix_fallocate is issued routinely by ordinary applications such as databases, VM images, and download managers.\nS:U - The out-of-bounds read, the corrupted write offsets, and the resulting crash all stay within the kernel of the client host; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - Because smb3_simple_fallocate_write_range() advances buf by every 64 KB chunk written, the inflated length walks far past the 1 MB kvzalloc\u0027d zero buffer and transmits adjacent kernel heap memory straight back to the attacker\u0027s server, yielding a large sequential kernel memory disclosure.\nI:H - The negative length drives off backwards and lets attacker-chosen offsets be zero-filled over ranges of the victim\u0027s file that hold real data, and the original defect makes fallocate report success while leaving holes unallocated, silently breaking the allocation guarantee applications rely on.\nA:H - The out-of-bounds read walks potentially gigabytes past the allocation and will fault on unmapped or guard pages, causing a kernel oops/panic, while the inflated length also drives an extremely long 64 KB-at-a-time write loop that stalls the caller."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:42.827Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/aeb58a4eb39a7ff4d7782b4f4ada0fda5e0675d2"
},
{
"url": "https://git.kernel.org/stable/c/01719883235507b1585e4c51e320d9a7113dc698"
},
{
"url": "https://git.kernel.org/stable/c/f47c7277c03a636fcc3a57969f2dc09567b3c050"
},
{
"url": "https://git.kernel.org/stable/c/437637f5ff3f573b2edf8571de91fb00a21eb4e6"
},
{
"url": "https://git.kernel.org/stable/c/377fe3e583e46369ee1004d5cfe12271d6589a68"
},
{
"url": "https://git.kernel.org/stable/c/7e08ab7a061b17ac1989a225c6afb53f44a86808"
},
{
"url": "https://git.kernel.org/stable/c/a4a09e5142835633fffbde68bd0a039ba4d4bf97"
},
{
"url": "https://git.kernel.org/stable/c/b09ae45d85dc816987a71db9eebc54b0ae288e94"
}
],
"title": "smb/client: handle overlapping allocated ranges in fallocate",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68388",
"datePublished": "2026-08-10T12:04:07.304Z",
"dateReserved": "2026-07-30T09:28:09.388Z",
"dateUpdated": "2026-08-19T16:34:42.827Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72168 (GCVE-0-2026-72168)
Vulnerability from cvelistv5
Published
2026-08-15 05:53
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
mtd: maps: vmu-flash: fix fault in unaligned fixup
Use kzalloc_obj() / kzalloc_objs() to allocate the memcard structs,
instead of kmalloc_obj() / kmalloc_objs() to prevent access to
uninitialized data.
Fixes runtime error: Fault in unaligned fixup: 0000 [#1] at
mtd_get_fact_prot_info.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 47a72688fae7298e1ad5fdc9bff7e04b6a549620 Version: 47a72688fae7298e1ad5fdc9bff7e04b6a549620 Version: 47a72688fae7298e1ad5fdc9bff7e04b6a549620 Version: 47a72688fae7298e1ad5fdc9bff7e04b6a549620 Version: 47a72688fae7298e1ad5fdc9bff7e04b6a549620 Version: 47a72688fae7298e1ad5fdc9bff7e04b6a549620 Version: 47a72688fae7298e1ad5fdc9bff7e04b6a549620 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/mtd/maps/vmu-flash.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "f781e80c9f1e52d92535c076573b0cdafab04864",
"status": "affected",
"version": "47a72688fae7298e1ad5fdc9bff7e04b6a549620",
"versionType": "git"
},
{
"lessThan": "631edc934e476991a04723d3283e6628d077f8c1",
"status": "affected",
"version": "47a72688fae7298e1ad5fdc9bff7e04b6a549620",
"versionType": "git"
},
{
"lessThan": "90494884cd9f02c38b4eafb0ed3b0e1a4410e2ac",
"status": "affected",
"version": "47a72688fae7298e1ad5fdc9bff7e04b6a549620",
"versionType": "git"
},
{
"lessThan": "01928835d80829e615a492aa66c629b953ec7bef",
"status": "affected",
"version": "47a72688fae7298e1ad5fdc9bff7e04b6a549620",
"versionType": "git"
},
{
"lessThan": "19360c25135fccb6bbafbee49a5f66baf9a311af",
"status": "affected",
"version": "47a72688fae7298e1ad5fdc9bff7e04b6a549620",
"versionType": "git"
},
{
"lessThan": "455519f6b70f46ac6cbf41a75ac76ec5e59040f2",
"status": "affected",
"version": "47a72688fae7298e1ad5fdc9bff7e04b6a549620",
"versionType": "git"
},
{
"lessThan": "79d1661502c6e4b6f626185cef72cf2fa78116e1",
"status": "affected",
"version": "47a72688fae7298e1ad5fdc9bff7e04b6a549620",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/mtd/maps/vmu-flash.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.30"
},
{
"lessThan": "2.6.30",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "2.6.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "2.6.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "2.6.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "2.6.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.30",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmtd: maps: vmu-flash: fix fault in unaligned fixup\n\nUse kzalloc_obj() / kzalloc_objs() to allocate the memcard structs,\ninstead of kmalloc_obj() / kmalloc_objs() to prevent access to\nuninitialized data.\n\nFixes runtime error: Fault in unaligned fixup: 0000 [#1] at\nmtd_get_fact_prot_info."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:58.190Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/f781e80c9f1e52d92535c076573b0cdafab04864"
},
{
"url": "https://git.kernel.org/stable/c/631edc934e476991a04723d3283e6628d077f8c1"
},
{
"url": "https://git.kernel.org/stable/c/90494884cd9f02c38b4eafb0ed3b0e1a4410e2ac"
},
{
"url": "https://git.kernel.org/stable/c/01928835d80829e615a492aa66c629b953ec7bef"
},
{
"url": "https://git.kernel.org/stable/c/19360c25135fccb6bbafbee49a5f66baf9a311af"
},
{
"url": "https://git.kernel.org/stable/c/455519f6b70f46ac6cbf41a75ac76ec5e59040f2"
},
{
"url": "https://git.kernel.org/stable/c/79d1661502c6e4b6f626185cef72cf2fa78116e1"
}
],
"title": "mtd: maps: vmu-flash: fix fault in unaligned fixup",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72168",
"datePublished": "2026-08-15T05:53:34.868Z",
"dateReserved": "2026-08-09T03:40:39.910Z",
"dateUpdated": "2026-08-23T12:46:58.190Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68165 (GCVE-0-2026-68165)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
mm/damon/core: validate ranges in damon_set_regions()
DAMON core logic assumes zero length regions don't exist. However, a few
DAMON API callers including DAMON_SYSFS, DAMON_RECLAIM and DAMON_LRU_SORT
allow users to set empty monitoring target regions. This could result in
WARN_ONCE() on CONFIG_DAMON_DEBUG_SANITY enabled kernel, and
divide-by-zero from damon_merge_two_regions().
For example, the WANR_ONCE() can be triggered like below.
# grep DAMON_DEBUG_SANITY /boot/config-$(uname -r)
# CONFIG_DAMON_DEBUG_SANITY=y
# damo start
# cd /sys/kernel/mm/damon/admin/kdamonds/0
# echo 0 > contexts/0/targets/0/regions/0/start
# echo 0 > contexts/0/targets/0/regions/0/end
# echo commit > state
# dmesg
[....]
[ 73.705780] ------------[ cut here ]------------
[ 73.707552] start 0 >= end 0
[ 73.708452] WARNING: mm/damon/core.c:359 at damon_new_region+0x6e/0x80, CPU#1: kdamond.0/758
[...]
All DAMON API callers eventually use damon_set_regions() to setup the
regions. Add the validation logic in the function.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 43b0536cb4710e7bb591edfda7e68a1c327a3409 Version: 43b0536cb4710e7bb591edfda7e68a1c327a3409 Version: 43b0536cb4710e7bb591edfda7e68a1c327a3409 Version: 43b0536cb4710e7bb591edfda7e68a1c327a3409 Version: 43b0536cb4710e7bb591edfda7e68a1c327a3409 Version: 43b0536cb4710e7bb591edfda7e68a1c327a3409 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"mm/damon/core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "71cf8a3ee1c18cfa8b88cc14bac9c2f43dd29f9b",
"status": "affected",
"version": "43b0536cb4710e7bb591edfda7e68a1c327a3409",
"versionType": "git"
},
{
"lessThan": "b585facbafbb5cf117b37b1c75819ac046646c27",
"status": "affected",
"version": "43b0536cb4710e7bb591edfda7e68a1c327a3409",
"versionType": "git"
},
{
"lessThan": "c927b73a5694c735314ea10e7c81c07f9bd51ad7",
"status": "affected",
"version": "43b0536cb4710e7bb591edfda7e68a1c327a3409",
"versionType": "git"
},
{
"lessThan": "4b6f1d6d5d07855bd1bb9e64922b049062138bfa",
"status": "affected",
"version": "43b0536cb4710e7bb591edfda7e68a1c327a3409",
"versionType": "git"
},
{
"lessThan": "43aaddd0fa92010a68adeda7744c7cf497a1c8e9",
"status": "affected",
"version": "43b0536cb4710e7bb591edfda7e68a1c327a3409",
"versionType": "git"
},
{
"lessThan": "1292c0ecb1caefb8ca064a3639d5673991e8810c",
"status": "affected",
"version": "43b0536cb4710e7bb591edfda7e68a1c327a3409",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"mm/damon/core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.16"
},
{
"lessThan": "5.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.16",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/damon/core: validate ranges in damon_set_regions()\n\nDAMON core logic assumes zero length regions don\u0027t exist. However, a few\nDAMON API callers including DAMON_SYSFS, DAMON_RECLAIM and DAMON_LRU_SORT\nallow users to set empty monitoring target regions. This could result in\nWARN_ONCE() on CONFIG_DAMON_DEBUG_SANITY enabled kernel, and\ndivide-by-zero from damon_merge_two_regions().\n\nFor example, the WANR_ONCE() can be triggered like below.\n\n # grep DAMON_DEBUG_SANITY /boot/config-$(uname -r)\n # CONFIG_DAMON_DEBUG_SANITY=y\n # damo start\n # cd /sys/kernel/mm/damon/admin/kdamonds/0\n # echo 0 \u003e contexts/0/targets/0/regions/0/start\n # echo 0 \u003e contexts/0/targets/0/regions/0/end\n # echo commit \u003e state\n # dmesg\n [....]\n [ 73.705780] ------------[ cut here ]------------\n [ 73.707552] start 0 \u003e= end 0\n [ 73.708452] WARNING: mm/damon/core.c:359 at damon_new_region+0x6e/0x80, CPU#1: kdamond.0/758\n [...]\n\nAll DAMON API callers eventually use damon_set_regions() to setup the\nregions. Add the validation logic in the function."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:30:37.581Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/71cf8a3ee1c18cfa8b88cc14bac9c2f43dd29f9b"
},
{
"url": "https://git.kernel.org/stable/c/b585facbafbb5cf117b37b1c75819ac046646c27"
},
{
"url": "https://git.kernel.org/stable/c/c927b73a5694c735314ea10e7c81c07f9bd51ad7"
},
{
"url": "https://git.kernel.org/stable/c/4b6f1d6d5d07855bd1bb9e64922b049062138bfa"
},
{
"url": "https://git.kernel.org/stable/c/43aaddd0fa92010a68adeda7744c7cf497a1c8e9"
},
{
"url": "https://git.kernel.org/stable/c/1292c0ecb1caefb8ca064a3639d5673991e8810c"
}
],
"title": "mm/damon/core: validate ranges in damon_set_regions()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68165",
"datePublished": "2026-08-10T11:59:33.152Z",
"dateReserved": "2026-07-30T09:28:09.372Z",
"dateUpdated": "2026-08-19T16:30:37.581Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68391 (GCVE-0-2026-68391)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-17 05:04
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds
Dereferencing RCU-protected pointers outside critical sections is
invalid and may lead to UAF. Use of hci_conn in hci_sync callbacks also
needs to hold refcount to avoid UAF.
Take appropriate locks for hci_conn lookups, and take refcount for
hci_conn pointers stored in mgmt_pending_cmd so that the pointer stays
valid.
When accessing conn->state, ensure hdev->lock is held to avoid data
race.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/bluetooth/mgmt.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b56f2ecafc08f372bf0529f9c4f3f429cb1702dc",
"status": "affected",
"version": "7b445e220db9a2c58be5d09bbbd322abf1b1452a",
"versionType": "git"
},
{
"lessThan": "f915e74b6f18293d1d69a2a3305ef321ff7c0172",
"status": "affected",
"version": "7b445e220db9a2c58be5d09bbbd322abf1b1452a",
"versionType": "git"
},
{
"lessThan": "d5b3b484b62bb0f4542e7622789d28871626cdf0",
"status": "affected",
"version": "7b445e220db9a2c58be5d09bbbd322abf1b1452a",
"versionType": "git"
},
{
"lessThan": "ecdcb55ea1c01dda074406f38058785a69526734",
"status": "affected",
"version": "7b445e220db9a2c58be5d09bbbd322abf1b1452a",
"versionType": "git"
},
{
"lessThan": "da55f570191d5d72f10c607a7043b947eb05ea46",
"status": "affected",
"version": "7b445e220db9a2c58be5d09bbbd322abf1b1452a",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/bluetooth/mgmt.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.0"
},
{
"lessThan": "6.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds\n\nDereferencing RCU-protected pointers outside critical sections is\ninvalid and may lead to UAF. Use of hci_conn in hci_sync callbacks also\nneeds to hold refcount to avoid UAF.\n\nTake appropriate locks for hci_conn lookups, and take refcount for\nhci_conn pointers stored in mgmt_pending_cmd so that the pointer stays\nvalid.\n\nWhen accessing conn-\u003estate, ensure hdev-\u003elock is held to avoid data\nrace."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Both sides of the race are local: the vulnerable path is entered only by writing MGMT_OP_GET_CONN_INFO/MGMT_OP_GET_CLOCK_INFO to an AF_BLUETOOTH/BTPROTO_HCI socket bound to HCI_CHANNEL_CONTROL, and the free is driven by a local disconnect/device-teardown. A remote or adjacent Bluetooth peer cannot inject mgmt commands, so the vector is local even though the subsystem is Bluetooth.\nAC:L - The attacker owns both sides of the race: one thread loops GET_CONN_INFO/GET_CLOCK_INFO, whose sync callback blocks in __hci_cmd_sync waiting on the controller for up to HCI_CMD_TIMEOUT, while another issues MGMT_OP_DISCONNECT or HCIDEVDOWN to free the hci_conn inside that wide window; with an emulated controller the response timing is fully controlled, and the sequence can be retried indefinitely.\nPR:L - The opcodes lack HCI_MGMT_UNTRUSTED so they need a trusted mgmt socket (CAP_NET_ADMIN), which kernel CNA practice for the Bluetooth mgmt interface treats as low privilege: it is a delegable capability held by the non-root bluetoothd service account and Android\u0027s sandboxed Bluetooth process rather than full init-namespace root.\nUI:N - The attacker performs every step itself \u2014 queueing the mgmt command and tearing down the connection or the HCI index \u2014 with no victim action, pairing, or user-initiated Bluetooth operation required.\nS:U - The use-after-free and the resulting heap corruption stay entirely within the kernel\u0027s own security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - get_conn_info_complete()/get_clock_info_complete() read rssi, tx_power, max_tx_power, clock and clock_accuracy from a freed hci_conn and return them to userspace over the mgmt socket; hci_conn comes from a general-purpose kmalloc cache, so grooming the reclaimed slab turns this into a repeatable kernel-memory disclosure oracle.\nI:H - The dangling cmd-\u003euser_data points at a freed, sprayable struct-device-embedded object that can be reclaimed with attacker-shaped data and is later put/released, and the unlocked lookup also propagates a stale conn-\u003ehandle into hci_read_rssi_sync/hci_read_clock_sync so the host acts on a handle that may have been reused by another link \u2014 sufficient for controlled corruption after heap grooming.\nA:H - Dereferencing the freed hci_conn in the hci_cmd_sync completion callback is a slab use-after-free that produces a KASAN splat and can oops or panic the kernel when the slab has been returned to the page allocator, and it can be re-triggered in a loop for sustained denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:04:39.043Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b56f2ecafc08f372bf0529f9c4f3f429cb1702dc"
},
{
"url": "https://git.kernel.org/stable/c/f915e74b6f18293d1d69a2a3305ef321ff7c0172"
},
{
"url": "https://git.kernel.org/stable/c/d5b3b484b62bb0f4542e7622789d28871626cdf0"
},
{
"url": "https://git.kernel.org/stable/c/ecdcb55ea1c01dda074406f38058785a69526734"
},
{
"url": "https://git.kernel.org/stable/c/da55f570191d5d72f10c607a7043b947eb05ea46"
}
],
"title": "Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68391",
"datePublished": "2026-08-10T12:04:10.564Z",
"dateReserved": "2026-07-30T09:28:09.388Z",
"dateUpdated": "2026-08-17T05:04:39.043Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68256 (GCVE-0-2026-68256)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-17 05:01
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: detect_link_and_local_sink: DP alt mode timeout path leaks prev_sink reference
prev_sink is unconditionally retained via dc_sink_retain at function
entry, but the DP alt mode timeout path inside SIGNAL_TYPE_DISPLAY_PORT
returns false without releasing prev_sink. All other return paths in the
function correctly call dc_sink_release(prev_sink), making this the only
missing cleanup.
(cherry picked from commit 45510cf662dcf46b5d8926d454f338809f107b9d)
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/display/dc/link/link_detection.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "f9922828a4ebd26286fbe0286cc61695e7d9b07b",
"status": "affected",
"version": "54618888d1ea7a26f8bccfb89e3c2420350c8047",
"versionType": "git"
},
{
"lessThan": "a59e493567d18ef3858be9368acd132a01ebfa09",
"status": "affected",
"version": "54618888d1ea7a26f8bccfb89e3c2420350c8047",
"versionType": "git"
},
{
"lessThan": "4ee77643e6194f2deb62fe62f04396f9825e27d8",
"status": "affected",
"version": "54618888d1ea7a26f8bccfb89e3c2420350c8047",
"versionType": "git"
},
{
"lessThan": "58ea24dd96848626039296e9e8510270ec8dc4bf",
"status": "affected",
"version": "54618888d1ea7a26f8bccfb89e3c2420350c8047",
"versionType": "git"
},
{
"lessThan": "a6e14b976be48eebd8769cb5b883a6af7fc5ade1",
"status": "affected",
"version": "54618888d1ea7a26f8bccfb89e3c2420350c8047",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/display/dc/link/link_detection.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.3"
},
{
"lessThan": "6.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: detect_link_and_local_sink: DP alt mode timeout path leaks prev_sink reference\n\nprev_sink is unconditionally retained via dc_sink_retain at function\n entry, but the DP alt mode timeout path inside SIGNAL_TYPE_DISPLAY_PORT\n returns false without releasing prev_sink. All other return paths in the\n function correctly call dc_sink_release(prev_sink), making this the only\n missing cleanup.\n\n(cherry picked from commit 45510cf662dcf46b5d8926d454f338809f107b9d)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:01:47.968Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/f9922828a4ebd26286fbe0286cc61695e7d9b07b"
},
{
"url": "https://git.kernel.org/stable/c/a59e493567d18ef3858be9368acd132a01ebfa09"
},
{
"url": "https://git.kernel.org/stable/c/4ee77643e6194f2deb62fe62f04396f9825e27d8"
},
{
"url": "https://git.kernel.org/stable/c/58ea24dd96848626039296e9e8510270ec8dc4bf"
},
{
"url": "https://git.kernel.org/stable/c/a6e14b976be48eebd8769cb5b883a6af7fc5ade1"
}
],
"title": "drm/amd/display: detect_link_and_local_sink: DP alt mode timeout path leaks prev_sink reference",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68256",
"datePublished": "2026-08-10T12:01:26.406Z",
"dateReserved": "2026-07-30T09:28:09.378Z",
"dateUpdated": "2026-08-17T05:01:47.968Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68189 (GCVE-0-2026-68189)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci_sync: Protect UUID list traversal
The hci_sync conversion moved class-of-device and EIR generation from an
HCI request built under hdev->lock to asynchronous command sync work.
The worker holds hdev->req_lock, but that lock does not serialize access
to hdev->uuids against add_uuid() and remove_uuid(), which update the
list under hdev->lock.
The following interleaving can therefore occur:
CPU0 (command sync work) CPU1 (management socket)
fetch uuid from the list
list_del(&uuid->list)
kfree(uuid)
read uuid->size
KASAN reports the resulting use-after-free:
BUG: KASAN: slab-use-after-free in eir_create+0xb8f/0xee0
Read of size 1 at addr ffff88810dbd8620 by task kworker/u17:0/87
Workqueue: hci0 hci_cmd_sync_work
Call Trace:
eir_create+0xb8f/0xee0
hci_update_eir_sync+0x1c0/0x330
hci_cmd_sync_work+0x13c/0x290
process_one_work+0x63a/0x1070
worker_thread+0x45b/0xd10
Allocated by task 86:
__kasan_kmalloc+0x8f/0xa0
add_uuid+0x18a/0x4b0
hci_sock_sendmsg+0x1033/0x1ea0
Freed by task 92:
__kasan_slab_free+0x43/0x70
kfree+0x131/0x3c0
remove_uuid+0x25e/0x560
hci_sock_sendmsg+0x1033/0x1ea0
Hold hdev->lock while generating and committing the class-of-device and
EIR snapshots. Release it before sending an HCI command, so controller
waits do not happen under the device lock. This protects all UUID list
walks in these paths and restores the serialization lost in the command
sync conversion.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 161510ccf91c961638940b03abb1ee804be53a97 Version: 161510ccf91c961638940b03abb1ee804be53a97 Version: 161510ccf91c961638940b03abb1ee804be53a97 Version: 161510ccf91c961638940b03abb1ee804be53a97 Version: 161510ccf91c961638940b03abb1ee804be53a97 Version: 161510ccf91c961638940b03abb1ee804be53a97 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/bluetooth/hci_sync.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "30bc6248f035a792d1b1f4cc761b32fd5827b55f",
"status": "affected",
"version": "161510ccf91c961638940b03abb1ee804be53a97",
"versionType": "git"
},
{
"lessThan": "e4fa2c5c261d736b8e58759fdef3a968d510630c",
"status": "affected",
"version": "161510ccf91c961638940b03abb1ee804be53a97",
"versionType": "git"
},
{
"lessThan": "a351f68fb24828b23a971e00b8238ee0e8a40380",
"status": "affected",
"version": "161510ccf91c961638940b03abb1ee804be53a97",
"versionType": "git"
},
{
"lessThan": "a42f5536ea9c00e13f0c0fbb330feed95e2365ca",
"status": "affected",
"version": "161510ccf91c961638940b03abb1ee804be53a97",
"versionType": "git"
},
{
"lessThan": "fe13adc258df88d95789e5673c7ba5178b5f8b28",
"status": "affected",
"version": "161510ccf91c961638940b03abb1ee804be53a97",
"versionType": "git"
},
{
"lessThan": "e9027ffbf5a0f3c12ca8900822e884eae9f0821b",
"status": "affected",
"version": "161510ccf91c961638940b03abb1ee804be53a97",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/bluetooth/hci_sync.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.17"
},
{
"lessThan": "5.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.17",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_sync: Protect UUID list traversal\n\nThe hci_sync conversion moved class-of-device and EIR generation from an\nHCI request built under hdev-\u003elock to asynchronous command sync work.\nThe worker holds hdev-\u003ereq_lock, but that lock does not serialize access\nto hdev-\u003euuids against add_uuid() and remove_uuid(), which update the\nlist under hdev-\u003elock.\n\nThe following interleaving can therefore occur:\n\n CPU0 (command sync work) CPU1 (management socket)\n fetch uuid from the list\n list_del(\u0026uuid-\u003elist)\n kfree(uuid)\n read uuid-\u003esize\n\nKASAN reports the resulting use-after-free:\n\n BUG: KASAN: slab-use-after-free in eir_create+0xb8f/0xee0\n Read of size 1 at addr ffff88810dbd8620 by task kworker/u17:0/87\n Workqueue: hci0 hci_cmd_sync_work\n Call Trace:\n eir_create+0xb8f/0xee0\n hci_update_eir_sync+0x1c0/0x330\n hci_cmd_sync_work+0x13c/0x290\n process_one_work+0x63a/0x1070\n worker_thread+0x45b/0xd10\n\n Allocated by task 86:\n __kasan_kmalloc+0x8f/0xa0\n add_uuid+0x18a/0x4b0\n hci_sock_sendmsg+0x1033/0x1ea0\n\n Freed by task 92:\n __kasan_slab_free+0x43/0x70\n kfree+0x131/0x3c0\n remove_uuid+0x25e/0x560\n hci_sock_sendmsg+0x1033/0x1ea0\n\nHold hdev-\u003elock while generating and committing the class-of-device and\nEIR snapshots. Release it before sending an HCI command, so controller\nwaits do not happen under the device lock. This protects all UUID list\nwalks in these paths and restores the serialization lost in the command\nsync conversion."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires concurrent MGMT_OP_ADD_UUID/MGMT_REMOVE_UUID commands through a local AF_BLUETOOTH HCI management socket (hci_sock_sendmsg), not reception of over-the-air Bluetooth protocol traffic from a remote peer.\nAC:L - The attacker controls both sides of the race by issuing concurrent management socket commands from threads or processes they own; KASAN shows reliable interleaving between hci_cmd_sync_work and remove_uuid without attacker-uncontrollable timing or memory layout.\nPR:L - MGMT_OP_ADD_UUID and MGMT_OP_REMOVE_UUID require HCI_SOCK_TRUSTED, set only when the socket binder holds CAP_NET_ADMIN; per kernel CNA guidance CAP_NET_ADMIN reachable via user namespaces (unshare -Urn) maps to PR:L, not PR:H.\nUI:N - No victim interaction is required; the attacker directly issues local management commands that queue hci_cmd_sync_work and concurrently modify the UUID list to trigger the use-after-free.\nS:U - The vulnerability causes kernel heap corruption and local privilege escalation within the same host security authority; it does not cross VM, container, or IOMMU security boundaries.\nC:H - KASAN-confirmed slab use-after-free reading freed bt_uuid fields (uuid-\u003esize and uuid data) during eir_create traversal enables arbitrary kernel memory disclosure via heap spraying and reuse of freed kmalloc objects.\nI:H - Slab UAF on bt_uuid during list traversal enables attacker-controlled reallocation of freed objects, providing heap corruption primitives that can be leveraged for arbitrary kernel writes and control-flow hijacking.\nA:H - The confirmed use-after-free in eir_create on the hci_cmd_sync_work path causes kernel oops or panic; repeated concurrent add/remove UUID operations can reliably crash or hang the system."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:01.944Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/30bc6248f035a792d1b1f4cc761b32fd5827b55f"
},
{
"url": "https://git.kernel.org/stable/c/e4fa2c5c261d736b8e58759fdef3a968d510630c"
},
{
"url": "https://git.kernel.org/stable/c/a351f68fb24828b23a971e00b8238ee0e8a40380"
},
{
"url": "https://git.kernel.org/stable/c/a42f5536ea9c00e13f0c0fbb330feed95e2365ca"
},
{
"url": "https://git.kernel.org/stable/c/fe13adc258df88d95789e5673c7ba5178b5f8b28"
},
{
"url": "https://git.kernel.org/stable/c/e9027ffbf5a0f3c12ca8900822e884eae9f0821b"
}
],
"title": "Bluetooth: hci_sync: Protect UUID list traversal",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68189",
"datePublished": "2026-08-10T12:00:01.711Z",
"dateReserved": "2026-07-30T09:28:09.373Z",
"dateUpdated": "2026-08-19T16:31:01.944Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68251 (GCVE-0-2026-68251)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-19 16:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu/sdma6.0: replace BUG_ON() with WARN_ON()
There's no need to crash the kernel for these cases.
(cherry picked from commit c17a508a7d652da3728f8bbc481bfffe96d65a87)
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 61a039d1757b148717b9e10ea0cd30e5da6cf919 Version: 61a039d1757b148717b9e10ea0cd30e5da6cf919 Version: 61a039d1757b148717b9e10ea0cd30e5da6cf919 Version: 61a039d1757b148717b9e10ea0cd30e5da6cf919 Version: 61a039d1757b148717b9e10ea0cd30e5da6cf919 Version: 61a039d1757b148717b9e10ea0cd30e5da6cf919 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/sdma_v6_0.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "e7575e1e654a7ec8cc5e170f6dc30c81c708ddda",
"status": "affected",
"version": "61a039d1757b148717b9e10ea0cd30e5da6cf919",
"versionType": "git"
},
{
"lessThan": "2eb06c88426b6c8de602c608959f3a56ac51861e",
"status": "affected",
"version": "61a039d1757b148717b9e10ea0cd30e5da6cf919",
"versionType": "git"
},
{
"lessThan": "e7f31c9a61533062a704f90b9f63064045249693",
"status": "affected",
"version": "61a039d1757b148717b9e10ea0cd30e5da6cf919",
"versionType": "git"
},
{
"lessThan": "51fd52087165180967cf7d5ee99badee7e172ea0",
"status": "affected",
"version": "61a039d1757b148717b9e10ea0cd30e5da6cf919",
"versionType": "git"
},
{
"lessThan": "9df8a7f09e305249872b536555793b28e77b7de9",
"status": "affected",
"version": "61a039d1757b148717b9e10ea0cd30e5da6cf919",
"versionType": "git"
},
{
"lessThan": "ec42c96c322e5cc48099ab5e67b5cbe236cb1949",
"status": "affected",
"version": "61a039d1757b148717b9e10ea0cd30e5da6cf919",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/sdma_v6_0.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.19"
},
{
"lessThan": "5.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/sdma6.0: replace BUG_ON() with WARN_ON()\n\nThere\u0027s no need to crash the kernel for these cases.\n\n(cherry picked from commit c17a508a7d652da3728f8bbc481bfffe96d65a87)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:32:23.355Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/e7575e1e654a7ec8cc5e170f6dc30c81c708ddda"
},
{
"url": "https://git.kernel.org/stable/c/2eb06c88426b6c8de602c608959f3a56ac51861e"
},
{
"url": "https://git.kernel.org/stable/c/e7f31c9a61533062a704f90b9f63064045249693"
},
{
"url": "https://git.kernel.org/stable/c/51fd52087165180967cf7d5ee99badee7e172ea0"
},
{
"url": "https://git.kernel.org/stable/c/9df8a7f09e305249872b536555793b28e77b7de9"
},
{
"url": "https://git.kernel.org/stable/c/ec42c96c322e5cc48099ab5e67b5cbe236cb1949"
}
],
"title": "drm/amdgpu/sdma6.0: replace BUG_ON() with WARN_ON()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68251",
"datePublished": "2026-08-10T12:01:17.402Z",
"dateReserved": "2026-07-30T09:28:09.377Z",
"dateUpdated": "2026-08-19T16:32:23.355Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68220 (GCVE-0-2026-68220)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-17 05:01
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: nxp: imx8-isi: Add missing v4l2_subdev_cleanup() in crossbar and pipe
Both mxc_isi_crossbar_init() and mxc_isi_pipe_init() call
v4l2_subdev_init_finalize() which allocates the subdev active state,
but neither mxc_isi_crossbar_cleanup() nor mxc_isi_pipe_cleanup()
calls v4l2_subdev_cleanup() to free it.
This causes a memory leak on every rmmod, reported by kmemleak:
unreferenced object 0xffff0000d06fc800 (size 192):
comm "(udev-worker)", pid 254, jiffies 4294913455
backtrace (crc 36eeae58):
kmemleak_alloc+0x34/0x40
__kvmalloc_node_noprof+0x5f8/0x7d8
__v4l2_subdev_state_alloc+0x1fc/0x30c
__v4l2_subdev_init_finalize+0x178/0x368
Add the missing v4l2_subdev_cleanup() calls before media_entity_cleanup()
in both crossbar and pipe cleanup paths.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/platform/nxp/imx8-isi/imx8-isi-crossbar.c",
"drivers/media/platform/nxp/imx8-isi/imx8-isi-pipe.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "549dd1afce2cf79a826d1f9742effb4565d52871",
"status": "affected",
"version": "cf21f328fcafacf4f96e7a30ef9dceede1076378",
"versionType": "git"
},
{
"lessThan": "f04ec98605420e7c2c1ad6d2f6fb26692d4f218a",
"status": "affected",
"version": "cf21f328fcafacf4f96e7a30ef9dceede1076378",
"versionType": "git"
},
{
"lessThan": "9e61258fbc3cfc053e4c2ed72254c2de76772354",
"status": "affected",
"version": "cf21f328fcafacf4f96e7a30ef9dceede1076378",
"versionType": "git"
},
{
"lessThan": "9c5ddbabc31fda93a508d9b8f0c776a4a08e49f5",
"status": "affected",
"version": "cf21f328fcafacf4f96e7a30ef9dceede1076378",
"versionType": "git"
},
{
"lessThan": "567418eedd25b3d86d489807682030b4b98b73d9",
"status": "affected",
"version": "cf21f328fcafacf4f96e7a30ef9dceede1076378",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/platform/nxp/imx8-isi/imx8-isi-crossbar.c",
"drivers/media/platform/nxp/imx8-isi/imx8-isi-pipe.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.4"
},
{
"lessThan": "6.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: nxp: imx8-isi: Add missing v4l2_subdev_cleanup() in crossbar and pipe\n\nBoth mxc_isi_crossbar_init() and mxc_isi_pipe_init() call\nv4l2_subdev_init_finalize() which allocates the subdev active state,\nbut neither mxc_isi_crossbar_cleanup() nor mxc_isi_pipe_cleanup()\ncalls v4l2_subdev_cleanup() to free it.\n\nThis causes a memory leak on every rmmod, reported by kmemleak:\n\n unreferenced object 0xffff0000d06fc800 (size 192):\n comm \"(udev-worker)\", pid 254, jiffies 4294913455\n backtrace (crc 36eeae58):\n kmemleak_alloc+0x34/0x40\n __kvmalloc_node_noprof+0x5f8/0x7d8\n __v4l2_subdev_state_alloc+0x1fc/0x30c\n __v4l2_subdev_init_finalize+0x178/0x368\n\nAdd the missing v4l2_subdev_cleanup() calls before media_entity_cleanup()\nin both crossbar and pipe cleanup paths."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:01:06.897Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/549dd1afce2cf79a826d1f9742effb4565d52871"
},
{
"url": "https://git.kernel.org/stable/c/f04ec98605420e7c2c1ad6d2f6fb26692d4f218a"
},
{
"url": "https://git.kernel.org/stable/c/9e61258fbc3cfc053e4c2ed72254c2de76772354"
},
{
"url": "https://git.kernel.org/stable/c/9c5ddbabc31fda93a508d9b8f0c776a4a08e49f5"
},
{
"url": "https://git.kernel.org/stable/c/567418eedd25b3d86d489807682030b4b98b73d9"
}
],
"title": "media: nxp: imx8-isi: Add missing v4l2_subdev_cleanup() in crossbar and pipe",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68220",
"datePublished": "2026-08-10T12:00:40.434Z",
"dateReserved": "2026-07-30T09:28:09.375Z",
"dateUpdated": "2026-08-17T05:01:06.897Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68313 (GCVE-0-2026-68313)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
tipc: fix infinite loop in __tipc_nl_compat_dumpit
cmd->dumpit callback can return a negative errno, causing an infinite
loop due to the while(len) condition. As the loop never terminates,
genl_mutex is never released, and other tasks waiting on it starve in D
state.
Check dumpit's return value, propagate it and jump to err_out on error.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d0796d1ef63deb38147729664691ba3090930b26 Version: d0796d1ef63deb38147729664691ba3090930b26 Version: d0796d1ef63deb38147729664691ba3090930b26 Version: d0796d1ef63deb38147729664691ba3090930b26 Version: d0796d1ef63deb38147729664691ba3090930b26 Version: d0796d1ef63deb38147729664691ba3090930b26 Version: d0796d1ef63deb38147729664691ba3090930b26 Version: d0796d1ef63deb38147729664691ba3090930b26 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/tipc/netlink_compat.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "2a1c1397275f27e33b6a2a565d81cfef0deb6656",
"status": "affected",
"version": "d0796d1ef63deb38147729664691ba3090930b26",
"versionType": "git"
},
{
"lessThan": "98d09766cee3182aae292886e2fef0cbe8dba537",
"status": "affected",
"version": "d0796d1ef63deb38147729664691ba3090930b26",
"versionType": "git"
},
{
"lessThan": "9cd8c88e1336ec0fbe02af1ddf2b52838d30fae4",
"status": "affected",
"version": "d0796d1ef63deb38147729664691ba3090930b26",
"versionType": "git"
},
{
"lessThan": "f9c669d9f4cac832fe31193cdbc24c6a9d99398b",
"status": "affected",
"version": "d0796d1ef63deb38147729664691ba3090930b26",
"versionType": "git"
},
{
"lessThan": "1ab78af2140189b735b8d3b889b0284128cb2013",
"status": "affected",
"version": "d0796d1ef63deb38147729664691ba3090930b26",
"versionType": "git"
},
{
"lessThan": "e740e90ca8e7f70d9eac1aa31a8b3e0e4d32b2ef",
"status": "affected",
"version": "d0796d1ef63deb38147729664691ba3090930b26",
"versionType": "git"
},
{
"lessThan": "b8f3b8efa5f99081b14de1a7ffa68a81bf01bd48",
"status": "affected",
"version": "d0796d1ef63deb38147729664691ba3090930b26",
"versionType": "git"
},
{
"lessThan": "22f8aa35964e8f2ab026578f45befc9605fd1b28",
"status": "affected",
"version": "d0796d1ef63deb38147729664691ba3090930b26",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/tipc/netlink_compat.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.0"
},
{
"lessThan": "4.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: fix infinite loop in __tipc_nl_compat_dumpit\n\ncmd-\u003edumpit callback can return a negative errno, causing an infinite\nloop due to the while(len) condition. As the loop never terminates,\ngenl_mutex is never released, and other tasks waiting on it starve in D\nstate.\n\nCheck dumpit\u0027s return value, propagate it and jump to err_out on error."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:05.750Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/2a1c1397275f27e33b6a2a565d81cfef0deb6656"
},
{
"url": "https://git.kernel.org/stable/c/98d09766cee3182aae292886e2fef0cbe8dba537"
},
{
"url": "https://git.kernel.org/stable/c/9cd8c88e1336ec0fbe02af1ddf2b52838d30fae4"
},
{
"url": "https://git.kernel.org/stable/c/f9c669d9f4cac832fe31193cdbc24c6a9d99398b"
},
{
"url": "https://git.kernel.org/stable/c/1ab78af2140189b735b8d3b889b0284128cb2013"
},
{
"url": "https://git.kernel.org/stable/c/e740e90ca8e7f70d9eac1aa31a8b3e0e4d32b2ef"
},
{
"url": "https://git.kernel.org/stable/c/b8f3b8efa5f99081b14de1a7ffa68a81bf01bd48"
},
{
"url": "https://git.kernel.org/stable/c/22f8aa35964e8f2ab026578f45befc9605fd1b28"
}
],
"title": "tipc: fix infinite loop in __tipc_nl_compat_dumpit",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68313",
"datePublished": "2026-08-10T12:02:48.120Z",
"dateReserved": "2026-07-30T09:28:09.381Z",
"dateUpdated": "2026-08-19T16:33:05.750Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68204 (GCVE-0-2026-68204)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: vivid: check for vb2_is_busy() when toggling caps
The vivid_update_format_cap/out() functions must only be called if the
capture/output queue are not busy. But for the controls that select
the CROP/COMPOSE/SCALE capability that is not checked.
Only when streaming starts will they be set to 'grabbed' and it is
impossible to change the control, but between REQBUFS and STREAMON you
are still allowed to set these controls. Since vivid_update_format_cap/out
will change the format, this can cause unexpected results.
Besides adding these checks, also add a WARN_ON in
vivid_update_format_cap/out() if the queue is busy.
I'm 90% certain that this is the cause of this syzbot bug:
https://syzkaller.appspot.com/bug?extid=dac8f5eaa46837e97b89
But since we never have reproducers, it is hard to be certain. In any case,
these checks are needed regardless.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 73c3f48230cda01402ae189b05d56f1f7e0d53c9 Version: 73c3f48230cda01402ae189b05d56f1f7e0d53c9 Version: 73c3f48230cda01402ae189b05d56f1f7e0d53c9 Version: 73c3f48230cda01402ae189b05d56f1f7e0d53c9 Version: 73c3f48230cda01402ae189b05d56f1f7e0d53c9 Version: 73c3f48230cda01402ae189b05d56f1f7e0d53c9 Version: 73c3f48230cda01402ae189b05d56f1f7e0d53c9 Version: 73c3f48230cda01402ae189b05d56f1f7e0d53c9 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/test-drivers/vivid/vivid-ctrls.c",
"drivers/media/test-drivers/vivid/vivid-vid-cap.c",
"drivers/media/test-drivers/vivid/vivid-vid-out.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "0a820f03727b509b887f3216a574062948761f34",
"status": "affected",
"version": "73c3f48230cda01402ae189b05d56f1f7e0d53c9",
"versionType": "git"
},
{
"lessThan": "bbc96bc75de0fcd9bb6ac48798b206e3b09ec865",
"status": "affected",
"version": "73c3f48230cda01402ae189b05d56f1f7e0d53c9",
"versionType": "git"
},
{
"lessThan": "6a5bc8aea111ccbca71ef2b9c868d5c81f2e89de",
"status": "affected",
"version": "73c3f48230cda01402ae189b05d56f1f7e0d53c9",
"versionType": "git"
},
{
"lessThan": "a9cd0e8fb0b21faaa71199d9d3feb305c18ff576",
"status": "affected",
"version": "73c3f48230cda01402ae189b05d56f1f7e0d53c9",
"versionType": "git"
},
{
"lessThan": "abaec6747304581f8d4a9936352fa10e13325f07",
"status": "affected",
"version": "73c3f48230cda01402ae189b05d56f1f7e0d53c9",
"versionType": "git"
},
{
"lessThan": "492c97cb50feaa60ccd7792d3d6b904ed8ec61bf",
"status": "affected",
"version": "73c3f48230cda01402ae189b05d56f1f7e0d53c9",
"versionType": "git"
},
{
"lessThan": "daf2d92669b4a659d805d88d811161c70cd325ee",
"status": "affected",
"version": "73c3f48230cda01402ae189b05d56f1f7e0d53c9",
"versionType": "git"
},
{
"lessThan": "c2d1a2130c93f6d758af58590b86b2254c7a1dec",
"status": "affected",
"version": "73c3f48230cda01402ae189b05d56f1f7e0d53c9",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/test-drivers/vivid/vivid-ctrls.c",
"drivers/media/test-drivers/vivid/vivid-vid-cap.c",
"drivers/media/test-drivers/vivid/vivid-vid-out.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.18"
},
{
"lessThan": "3.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.18",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: vivid: check for vb2_is_busy() when toggling caps\n\nThe vivid_update_format_cap/out() functions must only be called if the\ncapture/output queue are not busy. But for the controls that select\nthe CROP/COMPOSE/SCALE capability that is not checked.\n\nOnly when streaming starts will they be set to \u0027grabbed\u0027 and it is\nimpossible to change the control, but between REQBUFS and STREAMON you\nare still allowed to set these controls. Since vivid_update_format_cap/out\nwill change the format, this can cause unexpected results.\n\nBesides adding these checks, also add a WARN_ON in\nvivid_update_format_cap/out() if the queue is busy.\n\nI\u0027m 90% certain that this is the cause of this syzbot bug:\n\nhttps://syzkaller.appspot.com/bug?extid=dac8f5eaa46837e97b89\n\nBut since we never have reproducers, it is hard to be certain. In any case,\nthese checks are needed regardless."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached purely through local ioctls (VIDIOC_REQBUFS/PREPARE_BUF/S_EXT_CTRLS/STREAMON) on the /dev/videoN character device exposed by the vivid driver. There is no remote or network component.\nAC:L - The attacker fully controls both the initial buffer allocation size and the later geometry change, so the undersized-buffer overflow is produced deterministically by a fixed ioctl sequence with no race or memory-layout precondition.\nPR:L - No capability check exists on the V4L2 control or buffer ioctls; any process able to open /dev/videoN can trigger it, which on desktops/Android and container images with video devices bind-mounted means an ordinary unprivileged user (video group / logind ACL).\nUI:N - The entire sequence is performed by the attacking process itself against a device node it opens; no victim action or cooperation is needed.\nS:U - The corruption stays within the kernel\u0027s own memory and security authority; no VM, IOMMU or sandbox boundary is crossed by the overflow itself.\nC:H - The stale-geometry mismatch also drives out-of-bounds reads on the output path and lets adjacent kernel allocations be read back through the mmap\u0027ed plane, and the resulting heap corruption can be shaped into a broader kernel-memory disclosure primitive.\nI:H - The capture kthread writes a full frame using the enlarged geometry into a plane allocated for the smaller format, giving an out-of-bounds kernel write of attacker-chosen length and largely attacker-influenced (test-pattern) content, which is exploitable for kernel memory corruption.\nA:H - Overwriting memory past the vb2 plane reliably corrupts neighbouring allocations or hits a vmalloc guard page, producing KASAN splats, oopses and kernel panics; the post-fix WARN_ON also panics on panic_on_warn systems."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:23.943Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/0a820f03727b509b887f3216a574062948761f34"
},
{
"url": "https://git.kernel.org/stable/c/bbc96bc75de0fcd9bb6ac48798b206e3b09ec865"
},
{
"url": "https://git.kernel.org/stable/c/6a5bc8aea111ccbca71ef2b9c868d5c81f2e89de"
},
{
"url": "https://git.kernel.org/stable/c/a9cd0e8fb0b21faaa71199d9d3feb305c18ff576"
},
{
"url": "https://git.kernel.org/stable/c/abaec6747304581f8d4a9936352fa10e13325f07"
},
{
"url": "https://git.kernel.org/stable/c/492c97cb50feaa60ccd7792d3d6b904ed8ec61bf"
},
{
"url": "https://git.kernel.org/stable/c/daf2d92669b4a659d805d88d811161c70cd325ee"
},
{
"url": "https://git.kernel.org/stable/c/c2d1a2130c93f6d758af58590b86b2254c7a1dec"
}
],
"title": "media: vivid: check for vb2_is_busy() when toggling caps",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68204",
"datePublished": "2026-08-10T12:00:23.311Z",
"dateReserved": "2026-07-30T09:28:09.374Z",
"dateUpdated": "2026-08-19T16:31:23.943Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68100 (GCVE-0-2026-68100)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-23 12:45
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: validate num_subauth when copying ACE in set_ntacl_dacl
set_ntacl_dacl() copies each ACE from the attacker-controlled stored
security descriptor verbatim into the response DACL without checking
sid.num_subauth. The ACE bytes (including an unchecked num_subauth)
originate from an authenticated SMB2_SET_INFO(SecInfo=DACL) that is
stored raw via ksmbd_vfs_set_sd_xattr(); parse_dacl() rejects a bad ACE
with `break` rather than an error, so parse_sec_desc() still returns
success and the malformed SD reaches the xattr intact.
On a subsequent SMB2_QUERY_INFO(SecInfo=DACL) for an inode carrying a
POSIX access ACL, build_sec_desc() -> set_ntacl_dacl() ->
set_posix_acl_entries_dacl() walks the copied ACEs and reads
ntace->sid.sub_auth[ntace->sid.num_subauth - 1]
with num_subauth taken straight from the stored SD. Since sub_auth[]
is fixed at SID_MAX_SUB_AUTHORITIES (15), a crafted num_subauth (e.g.
255) drives an out-of-bounds heap read of ~1 KB with an offset fully
controlled by an authenticated client.
The sibling functions already gate this field:
parse_dacl() -- num_subauth == 0 || > SID_MAX_SUB_AUTHORITIES
parse_sid() -- num_subauth > SID_MAX_SUB_AUTHORITIES
smb_copy_sid() -- min_t(u8, num_subauth, SID_MAX_SUB_AUTHORITIES)
set_ntacl_dacl() is the lone inconsistent path that omits the check.
Add the same num_subauth validation in set_ntacl_dacl() before copying
the ACE, matching the gate already enforced by parse_dacl().
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 Version: e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 Version: e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 Version: e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 Version: e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 Version: e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/smb/server/smbacl.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "26cb845e22a00c85bf566337417fa33492395f10",
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"versionType": "git"
},
{
"lessThan": "e31fada5143784bc05c7ae44c79eed9b7a2e147e",
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"versionType": "git"
},
{
"lessThan": "fb3dc8e6da46a1ccad1956cda57de29d9b3033e0",
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"versionType": "git"
},
{
"lessThan": "b6d3cc6a524416dfdb2b47e4bba2e7e20011d056",
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"versionType": "git"
},
{
"lessThan": "5acbd3012fd4a7ccfebd91ea6f784120084eb897",
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"versionType": "git"
},
{
"lessThan": "47f0b34f6bc98ed85bfdc293e8f3e432ec24958d",
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/smb/server/smbacl.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.15"
},
{
"lessThan": "5.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: validate num_subauth when copying ACE in set_ntacl_dacl\n\nset_ntacl_dacl() copies each ACE from the attacker-controlled stored\nsecurity descriptor verbatim into the response DACL without checking\nsid.num_subauth. The ACE bytes (including an unchecked num_subauth)\noriginate from an authenticated SMB2_SET_INFO(SecInfo=DACL) that is\nstored raw via ksmbd_vfs_set_sd_xattr(); parse_dacl() rejects a bad ACE\nwith `break` rather than an error, so parse_sec_desc() still returns\nsuccess and the malformed SD reaches the xattr intact.\n\nOn a subsequent SMB2_QUERY_INFO(SecInfo=DACL) for an inode carrying a\nPOSIX access ACL, build_sec_desc() -\u003e set_ntacl_dacl() -\u003e\nset_posix_acl_entries_dacl() walks the copied ACEs and reads\n\n ntace-\u003esid.sub_auth[ntace-\u003esid.num_subauth - 1]\n\nwith num_subauth taken straight from the stored SD. Since sub_auth[]\nis fixed at SID_MAX_SUB_AUTHORITIES (15), a crafted num_subauth (e.g.\n255) drives an out-of-bounds heap read of ~1 KB with an offset fully\ncontrolled by an authenticated client.\n\nThe sibling functions already gate this field:\n parse_dacl() -- num_subauth == 0 || \u003e SID_MAX_SUB_AUTHORITIES\n parse_sid() -- num_subauth \u003e SID_MAX_SUB_AUTHORITIES\n smb_copy_sid() -- min_t(u8, num_subauth, SID_MAX_SUB_AUTHORITIES)\nset_ntacl_dacl() is the lone inconsistent path that omits the check.\n\nAdd the same num_subauth validation in set_ntacl_dacl() before copying\nthe ACE, matching the gate already enforced by parse_dacl()."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - ksmbd is the in-kernel SMB3 server on TCP/445; both SMB2_SET_INFO(SecInfo=DACL) and SMB2_QUERY_INFO(SecInfo=DACL) are handled from remote SMB2 PDUs in smb2_set_info()/smb2_query_info() via ksmbd_conn_handler_loop(), with no local syscall or physical access required.\nAC:L - Once ksmbd is running with ACL-xattr shares, an attacker deterministically plants a malformed DACL via SET_INFO and triggers the read on QUERY_INFO; num_subauth fully controls the OOB offset, with no race, timing window, or victim-dependent memory layout required.\nPR:L - SMB2_SET_INFO/QUERY_INFO require a valid post-authentication session (smb2_check_user_session) and SET_INFO SECURITY additionally requires FILE_WRITE_DAC/FILE_WRITE_OWNER on the open handle; this is a low-privilege authenticated SMB client, not a pre-auth or root-only path.\nUI:N - Exploitation is driven entirely by the attacker\u0027s own SMB2 SET_INFO and QUERY_INFO requests over the network; no local user, administrator, or victim client must perform any separate action.\nS:U - The out-of-bounds read and any resulting disclosure or crash occur entirely within kernel ksmbd server memory on the host; no VM, IOMMU, container, or other security-boundary escape is involved.\nC:H - Crafted num_subauth (e.g. 255) makes set_posix_acl_entries_dacl() index far past the 15-element sub_auth[] array, performing an attacker-offset-controlled ~1 KB out-of-bounds kernel heap read whose value is compared during DACL rebuild, enabling kernel memory disclosure.\nI:N - The defect is an out-of-bounds read during ACE deduplication; no kernel memory is written, no attacker-controlled data is persisted beyond the intentionally stored security descriptor, and no code-execution or arbitrary-write primitive is introduced.\nA:H - An unchecked multi-hundred-byte read past the smb_ace SID sub_auth array can cross slab/object boundaries and fault on hardened or KASAN builds; any unvalidated kernel out-of-bounds access is treated as capable of oops/panic and full host denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:45:50.170Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/26cb845e22a00c85bf566337417fa33492395f10"
},
{
"url": "https://git.kernel.org/stable/c/e31fada5143784bc05c7ae44c79eed9b7a2e147e"
},
{
"url": "https://git.kernel.org/stable/c/fb3dc8e6da46a1ccad1956cda57de29d9b3033e0"
},
{
"url": "https://git.kernel.org/stable/c/b6d3cc6a524416dfdb2b47e4bba2e7e20011d056"
},
{
"url": "https://git.kernel.org/stable/c/5acbd3012fd4a7ccfebd91ea6f784120084eb897"
},
{
"url": "https://git.kernel.org/stable/c/47f0b34f6bc98ed85bfdc293e8f3e432ec24958d"
}
],
"title": "ksmbd: validate num_subauth when copying ACE in set_ntacl_dacl",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68100",
"datePublished": "2026-08-10T11:58:15.233Z",
"dateReserved": "2026-07-30T09:28:09.368Z",
"dateUpdated": "2026-08-23T12:45:50.170Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68319 (GCVE-0-2026-68319)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-17 05:03
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
pds_core: fix deadlock between reset thread and remove
pci_reset_function() acquires device_lock before performing the reset.
pdsc_remove() is called by the PCI core with device_lock already held.
If pdsc_pci_reset_thread() is running when pdsc_remove() is called,
destroy_workqueue() will block waiting for the work to complete, while
the work is blocked waiting for device_lock - deadlock.
Use pci_try_reset_function() which uses pci_dev_trylock() internally.
This acquires both the device lock and the PCI config access lock
without blocking - if either lock is contended, it returns -EAGAIN
immediately. This avoids the deadlock while also ensuring proper
config space access serialization during the reset.
The pci_dev_get/put calls are also removed as they were unnecessary -
the driver-owned workqueue is destroyed in pdsc_remove(), guaranteeing
the work completes before remove returns. The PCI core holds its
reference to pci_dev throughout the entire unbind sequence.
References
| URL | Tags | |
|---|---|---|
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 81665adf25d28a00a986533f1d3a5df76b79cad9 Version: 81665adf25d28a00a986533f1d3a5df76b79cad9 Version: 81665adf25d28a00a986533f1d3a5df76b79cad9 Version: 81665adf25d28a00a986533f1d3a5df76b79cad9 Version: 38407914d48273d7f8ab765b9243658afe1c3ab6 Version: 6.8.7 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/amd/pds_core/core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "90d9f3ef28843e6c35149324b8eefb427a7435c2",
"status": "affected",
"version": "81665adf25d28a00a986533f1d3a5df76b79cad9",
"versionType": "git"
},
{
"lessThan": "19ef775c91c6bf4bd2b60f6616f4e28b621cdd6a",
"status": "affected",
"version": "81665adf25d28a00a986533f1d3a5df76b79cad9",
"versionType": "git"
},
{
"lessThan": "54f905821f26d385fba407a920b51f0a752c76dc",
"status": "affected",
"version": "81665adf25d28a00a986533f1d3a5df76b79cad9",
"versionType": "git"
},
{
"lessThan": "ab0eec0ff0a421737a37f510ceab5c6ea59cd05a",
"status": "affected",
"version": "81665adf25d28a00a986533f1d3a5df76b79cad9",
"versionType": "git"
},
{
"status": "affected",
"version": "38407914d48273d7f8ab765b9243658afe1c3ab6",
"versionType": "git"
},
{
"lessThan": "6.9",
"status": "affected",
"version": "6.8.7",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/amd/pds_core/core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.9"
},
{
"lessThan": "6.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.8.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\npds_core: fix deadlock between reset thread and remove\n\npci_reset_function() acquires device_lock before performing the reset.\npdsc_remove() is called by the PCI core with device_lock already held.\nIf pdsc_pci_reset_thread() is running when pdsc_remove() is called,\ndestroy_workqueue() will block waiting for the work to complete, while\nthe work is blocked waiting for device_lock - deadlock.\n\nUse pci_try_reset_function() which uses pci_dev_trylock() internally.\nThis acquires both the device lock and the PCI config access lock\nwithout blocking - if either lock is contended, it returns -EAGAIN\nimmediately. This avoids the deadlock while also ensuring proper\nconfig space access serialization during the reset.\n\nThe pci_dev_get/put calls are also removed as they were unnecessary -\nthe driver-owned workqueue is destroyed in pdsc_remove(), guaranteeing\nthe work completes before remove returns. The PCI core holds its\nreference to pci_dev throughout the entire unbind sequence."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:03:16.659Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/90d9f3ef28843e6c35149324b8eefb427a7435c2"
},
{
"url": "https://git.kernel.org/stable/c/19ef775c91c6bf4bd2b60f6616f4e28b621cdd6a"
},
{
"url": "https://git.kernel.org/stable/c/54f905821f26d385fba407a920b51f0a752c76dc"
},
{
"url": "https://git.kernel.org/stable/c/ab0eec0ff0a421737a37f510ceab5c6ea59cd05a"
}
],
"title": "pds_core: fix deadlock between reset thread and remove",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68319",
"datePublished": "2026-08-10T12:02:54.173Z",
"dateReserved": "2026-07-30T09:28:09.382Z",
"dateUpdated": "2026-08-17T05:03:16.659Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64561 (GCVE-0-2026-64561)
Vulnerability from cvelistv5
Published
2026-08-04 06:23
Modified
2026-08-27 12:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
KVM: x86: Check for invalid/obsolete root *after* making MMU pages available
Check for a "stale" page fault, i.e. for an invalid and/or obsolete root,
after making MMU pages available for the shadow MMU. If reclaiming shadow
pages zaps an in-use root, i.e. marks it invalid, then KVM will attempt to
map memory into an invalid root. On its own, populating an invalid root is
"fine", but because child shadow pages inherit their parent's role, any
children created during the map/fetch will be created as invalid pages,
thus violating KVM's invariant that invalid pages are never on the list of
active MMU pages.
Note, the underlying flaw has existed since KVM first started tracking
invalid roots in 2008 (commit 2e53d63acba7, "KVM: MMU: ignore zapped root
pagetables"), but the true badness only came along in 2020 (Linux 5.9)
with the invariant that invalid shadow pages can't be on the list of
active pages.
Note #2, inheriting role.invalid when creating child shadow pages is also
far from ideal; that flaw will be addressed separately.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: f95eec9bed76d42194c23153cb1cc8f186bf91cb Version: f95eec9bed76d42194c23153cb1cc8f186bf91cb Version: f95eec9bed76d42194c23153cb1cc8f186bf91cb Version: f95eec9bed76d42194c23153cb1cc8f186bf91cb Version: f95eec9bed76d42194c23153cb1cc8f186bf91cb Version: f95eec9bed76d42194c23153cb1cc8f186bf91cb Version: f95eec9bed76d42194c23153cb1cc8f186bf91cb |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"arch/x86/kvm/mmu/mmu.c",
"arch/x86/kvm/mmu/paging_tmpl.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "62ef67af1878fa2cd066642f2f59e33ade95f637",
"status": "affected",
"version": "f95eec9bed76d42194c23153cb1cc8f186bf91cb",
"versionType": "git"
},
{
"lessThan": "65c4f7a1028cf01a93a2762d679c289810ede990",
"status": "affected",
"version": "f95eec9bed76d42194c23153cb1cc8f186bf91cb",
"versionType": "git"
},
{
"lessThan": "35e77467610c4a37cb0ff54ee56b85f73b1f5700",
"status": "affected",
"version": "f95eec9bed76d42194c23153cb1cc8f186bf91cb",
"versionType": "git"
},
{
"lessThan": "0026dbb7de8ea76e97d6edf42fc3cc084564e2bf",
"status": "affected",
"version": "f95eec9bed76d42194c23153cb1cc8f186bf91cb",
"versionType": "git"
},
{
"lessThan": "f3477a6a4164f15287444eda685b5f6405dbd1e5",
"status": "affected",
"version": "f95eec9bed76d42194c23153cb1cc8f186bf91cb",
"versionType": "git"
},
{
"lessThan": "bce0d3c26e2c761a4bf43c8949f333fc7374eb2d",
"status": "affected",
"version": "f95eec9bed76d42194c23153cb1cc8f186bf91cb",
"versionType": "git"
},
{
"lessThan": "2abd5287f08319fa35764566b15c6e22cb1068db",
"status": "affected",
"version": "f95eec9bed76d42194c23153cb1cc8f186bf91cb",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"arch/x86/kvm/mmu/mmu.c",
"arch/x86/kvm/mmu/paging_tmpl.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.9"
},
{
"lessThan": "5.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.218",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.218",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: x86: Check for invalid/obsolete root *after* making MMU pages available\n\nCheck for a \"stale\" page fault, i.e. for an invalid and/or obsolete root,\nafter making MMU pages available for the shadow MMU. If reclaiming shadow\npages zaps an in-use root, i.e. marks it invalid, then KVM will attempt to\nmap memory into an invalid root. On its own, populating an invalid root is\n\"fine\", but because child shadow pages inherit their parent\u0027s role, any\nchildren created during the map/fetch will be created as invalid pages,\nthus violating KVM\u0027s invariant that invalid pages are never on the list of\nactive MMU pages.\n\nNote, the underlying flaw has existed since KVM first started tracking\ninvalid roots in 2008 (commit 2e53d63acba7, \"KVM: MMU: ignore zapped root\npagetables\"), but the true badness only came along in 2020 (Linux 5.9)\nwith the invariant that invalid shadow pages can\u0027t be on the list of\nactive pages.\n\nNote #2, inheriting role.invalid when creating child shadow pages is also\nfar from ideal; that flaw will be addressed separately."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable shadow-MMU page-fault path is reached via local KVM_RUN handling of guest EPT/shadow faults (and nested EPT via paging_tmpl), not by network or adjacent-radio packets.\nAC:L - An attacker who can run nested or shadow-MMU guests controls MMU pressure (heavy nested mappings and/or KVM_SET_NR_MMU_PAGES) and concurrent faults so reclaim zaps an in-use root during make_mmu_pages_available; no attacker-uncontrollable condition is required.\nPR:L - Exploitation needs /dev/kvm access or a nested-capable guest on the host, privileges commonly available to kvm-group users or cloud tenants, not real init-namespace root or CAP_SYS_ADMIN on the create/run path.\nUI:N - Once the attacker can run the guest, they trigger reclaim and page faults entirely through their own vCPU activity with no action by another user.\nS:C - Guest-controlled faults corrupt host KVM MMU state (invalid shadow pages on active_mmu_pages and subsequent list handling), crossing the guest-to-host virtualization boundary into the host kernel authority.\nC:H - Invalid children on active_mmu_pages break zap accounting assumptions so later prepare_zap list_add on still-linked entries corrupts kernel lists, a memory-corruption primitive that can be leveraged for arbitrary host reads.\nI:H - The same active-list invariant break and linked-list corruption in host MMU teardown/reclaim paths yield writable host corruption suitable for control-flow or structure hijacking, not merely a benign accounting glitch.\nA:H - WARN_ON_ONCE skips, infinite zap loops, list corruption, and host oops/hangs are reachable when invalid shadow pages remain on active_mmu_pages, causing host and co-located VM denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T12:39:43.193Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/62ef67af1878fa2cd066642f2f59e33ade95f637"
},
{
"url": "https://git.kernel.org/stable/c/65c4f7a1028cf01a93a2762d679c289810ede990"
},
{
"url": "https://git.kernel.org/stable/c/35e77467610c4a37cb0ff54ee56b85f73b1f5700"
},
{
"url": "https://git.kernel.org/stable/c/0026dbb7de8ea76e97d6edf42fc3cc084564e2bf"
},
{
"url": "https://git.kernel.org/stable/c/f3477a6a4164f15287444eda685b5f6405dbd1e5"
},
{
"url": "https://git.kernel.org/stable/c/bce0d3c26e2c761a4bf43c8949f333fc7374eb2d"
},
{
"url": "https://git.kernel.org/stable/c/2abd5287f08319fa35764566b15c6e22cb1068db"
},
{
"url": "https://github.com/V4bel/Zapscape"
}
],
"title": "KVM: x86: Check for invalid/obsolete root *after* making MMU pages available",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64561",
"datePublished": "2026-08-04T06:23:21.094Z",
"dateReserved": "2026-07-19T15:36:31.796Z",
"dateUpdated": "2026-08-27T12:39:43.193Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68377 (GCVE-0-2026-68377)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/sched: act_tunnel_key: Defer dst_release to RCU callback
Fix a race-condition use-after-free in tunnel_key_release_params().
The function releases the metadata_dst of the old params synchronously
via dst_release() while deferring the params struct free with
kfree_rcu(). A concurrent tunnel_key_act() reader on the datapath may
still hold the old params pointer (under rcu_read_lock_bh) and proceed
to call dst_clone(¶ms->tcft_enc_metadata->dst) after the writer's
dst_release has already pushed the dst's rcuref to RCUREF_DEAD.
zdi-disclosures@trendmicro.com produced a poc which i (and Victor) verified
that KASAN reports:
==================================================================
BUG: KASAN: slab-use-after-free in instrument_atomic_read_write include/linux/instrumented.h:112
BUG: KASAN: slab-use-after-free in atomic_sub_return_release include/linux/atomic/atomic-instrumented.h:326
BUG: KASAN: slab-use-after-free in __rcuref_put include/linux/rcuref.h:109
BUG: KASAN: slab-use-after-free in rcuref_put include/linux/rcuref.h:173
BUG: KASAN: slab-use-after-free in dst_release+0x5b/0x370 net/core/dst.c:168
Write of size 4 at addr ffff88806158de40 by task poc/9388
CPU: 0 UID: 0 PID: 9388 Comm: poc Tainted: G W 7.1.0-rc7 #7 PREEMPT(lazy)
Tainted: [W]=WARN
Hardware name: QEMU Ubuntu 25.10 PC v2 (i440FX + PIIX, + 10.1 machine, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
Call Trace:
<TASK>
__dump_stack lib/dump_stack.c:94
dump_stack_lvl+0x100/0x190 lib/dump_stack.c:120
print_address_description mm/kasan/report.c:378
print_report+0x139/0x4ad mm/kasan/report.c:482
kasan_report+0xe4/0x1d0 mm/kasan/report.c:595
check_region_inline mm/kasan/generic.c:186
kasan_check_range+0x125/0x200 mm/kasan/generic.c:200
instrument_atomic_read_write include/linux/instrumented.h:112
atomic_sub_return_release include/linux/atomic/atomic-instrumented.h:326
__rcuref_put include/linux/rcuref.h:109
rcuref_put include/linux/rcuref.h:173
dst_release+0x5b/0x370 net/core/dst.c:168
refdst_drop include/net/dst.h:272
skb_dst_drop include/net/dst.h:284
skb_release_head_state+0x293/0x400 net/core/skbuff.c:1163
skb_release_all net/core/skbuff.c:1187
[..]
Allocated by task 9391:
kasan_save_stack+0x30/0x50 mm/kasan/common.c:57
kasan_save_track+0x14/0x30 mm/kasan/common.c:78
poison_kmalloc_redzone mm/kasan/common.c:398
__kasan_kmalloc+0x9a/0xb0 mm/kasan/common.c:415
kasan_kmalloc include/linux/kasan.h:263
__do_kmalloc_node mm/slub.c:5296
__kmalloc_noprof+0x2f1/0x830 mm/slub.c:5308
kmalloc_noprof include/linux/slab.h:954
kzalloc_noprof include/linux/slab.h:1188
offload_action_alloc+0x2f/0x130 net/core/flow_offload.c:35
tcf_action_offload_add_ex+0x1ba/0x880 net/sched/act_api.c:258
tcf_action_offload_add net/sched/act_api.c:293
tcf_action_init+0x66e/0xa20 net/sched/act_api.c:1547
tcf_action_add+0xf6/0x5d0 net/sched/act_api.c:2101
[..]
Freed by task 9391:
kasan_save_stack+0x30/0x50 mm/kasan/common.c:57
kasan_save_track+0x14/0x30 mm/kasan/common.c:78
kasan_save_free_info+0x3b/0x70 mm/kasan/generic.c:584
poison_slab_object mm/kasan/common.c:253
__kasan_slab_free+0x6b/0x90 mm/kasan/common.c:285
kasan_slab_free include/linux/kasan.h:235
slab_free_hook mm/slub.c:2689
slab_free mm/slub.c:6251
kfree+0x21f/0x6b0 mm/slub.c:6566
tcf_action_offload_add_ex+0x4ad/0x880 net/sched/act_api.c:284
tcf_action_offload_add net/sched/act_api.c:293
tcf_action_init+0x66e/0xa20 net/sched/act_api.c:1547
tcf_action_add+0xf6/0x5d0 net/sched/act_api.c:2101
The buggy address belongs to the object at ffff88806158de00
which belongs to the cache kmalloc-256 of size 256
The buggy address is located 64 bytes inside of
freed 256-byte region [ffff88806158de00, ffff88806158df00)
The buggy address belongs to the physical page:
page: refcount:0 mapcount:0 mapping:0000000000000000 index:0xffff88806158d600 pfn:0x6158c
head: order:1 mapcount:0 entire_map
---truncated---
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 9174c3df1cd181c14913138d50ccbe539bb08335 Version: 9174c3df1cd181c14913138d50ccbe539bb08335 Version: 9174c3df1cd181c14913138d50ccbe539bb08335 Version: 9174c3df1cd181c14913138d50ccbe539bb08335 Version: 9174c3df1cd181c14913138d50ccbe539bb08335 Version: 9174c3df1cd181c14913138d50ccbe539bb08335 Version: 9174c3df1cd181c14913138d50ccbe539bb08335 Version: 9174c3df1cd181c14913138d50ccbe539bb08335 Version: 02239e797ac75f89a05622a27d04695f08c1ca89 Version: ca9b7a65a2c97579fcdd509d454d48e3a5c49af8 Version: 4.19.19 ≤ Version: 4.20.6 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/sched/act_tunnel_key.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b5931f020b681fdcb9378262d89b61cb3c7ebbf8",
"status": "affected",
"version": "9174c3df1cd181c14913138d50ccbe539bb08335",
"versionType": "git"
},
{
"lessThan": "389d03992dabb80488228e8119b9dd6d0f58e1a6",
"status": "affected",
"version": "9174c3df1cd181c14913138d50ccbe539bb08335",
"versionType": "git"
},
{
"lessThan": "676ad6aa7cec89a08d2a5ce3cd5959e313f29733",
"status": "affected",
"version": "9174c3df1cd181c14913138d50ccbe539bb08335",
"versionType": "git"
},
{
"lessThan": "531dbb5bb98e52ad26be7e90f9f8bec707c5bd0e",
"status": "affected",
"version": "9174c3df1cd181c14913138d50ccbe539bb08335",
"versionType": "git"
},
{
"lessThan": "2200a00ff247f70f5dcdb4e6f14b0d48ddac5467",
"status": "affected",
"version": "9174c3df1cd181c14913138d50ccbe539bb08335",
"versionType": "git"
},
{
"lessThan": "fed1b1ddab41a0e7a462ac690a0c8af6ff793624",
"status": "affected",
"version": "9174c3df1cd181c14913138d50ccbe539bb08335",
"versionType": "git"
},
{
"lessThan": "2791a501da508b704a617b4dba29db54a65bc9f7",
"status": "affected",
"version": "9174c3df1cd181c14913138d50ccbe539bb08335",
"versionType": "git"
},
{
"lessThan": "f1f5c8a3955f8fda3f84ed883ac8daa1847e724c",
"status": "affected",
"version": "9174c3df1cd181c14913138d50ccbe539bb08335",
"versionType": "git"
},
{
"status": "affected",
"version": "02239e797ac75f89a05622a27d04695f08c1ca89",
"versionType": "git"
},
{
"status": "affected",
"version": "ca9b7a65a2c97579fcdd509d454d48e3a5c49af8",
"versionType": "git"
},
{
"lessThan": "4.20",
"status": "affected",
"version": "4.19.19",
"versionType": "semver"
},
{
"lessThan": "4.21",
"status": "affected",
"version": "4.20.6",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/sched/act_tunnel_key.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.0"
},
{
"lessThan": "5.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.19.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.20.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: act_tunnel_key: Defer dst_release to RCU callback\n\nFix a race-condition use-after-free in tunnel_key_release_params().\n\nThe function releases the metadata_dst of the old params synchronously\nvia dst_release() while deferring the params struct free with\nkfree_rcu(). A concurrent tunnel_key_act() reader on the datapath may\nstill hold the old params pointer (under rcu_read_lock_bh) and proceed\nto call dst_clone(\u0026params-\u003etcft_enc_metadata-\u003edst) after the writer\u0027s\ndst_release has already pushed the dst\u0027s rcuref to RCUREF_DEAD.\n\nzdi-disclosures@trendmicro.com produced a poc which i (and Victor) verified\nthat KASAN reports:\n\n==================================================================\nBUG: KASAN: slab-use-after-free in instrument_atomic_read_write include/linux/instrumented.h:112\nBUG: KASAN: slab-use-after-free in atomic_sub_return_release include/linux/atomic/atomic-instrumented.h:326\nBUG: KASAN: slab-use-after-free in __rcuref_put include/linux/rcuref.h:109\nBUG: KASAN: slab-use-after-free in rcuref_put include/linux/rcuref.h:173\nBUG: KASAN: slab-use-after-free in dst_release+0x5b/0x370 net/core/dst.c:168\nWrite of size 4 at addr ffff88806158de40 by task poc/9388\n\nCPU: 0 UID: 0 PID: 9388 Comm: poc Tainted: G W 7.1.0-rc7 #7 PREEMPT(lazy)\nTainted: [W]=WARN\nHardware name: QEMU Ubuntu 25.10 PC v2 (i440FX + PIIX, + 10.1 machine, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\nCall Trace:\n \u003cTASK\u003e\n __dump_stack lib/dump_stack.c:94\n dump_stack_lvl+0x100/0x190 lib/dump_stack.c:120\n print_address_description mm/kasan/report.c:378\n print_report+0x139/0x4ad mm/kasan/report.c:482\n kasan_report+0xe4/0x1d0 mm/kasan/report.c:595\n check_region_inline mm/kasan/generic.c:186\n kasan_check_range+0x125/0x200 mm/kasan/generic.c:200\n instrument_atomic_read_write include/linux/instrumented.h:112\n atomic_sub_return_release include/linux/atomic/atomic-instrumented.h:326\n __rcuref_put include/linux/rcuref.h:109\n rcuref_put include/linux/rcuref.h:173\n dst_release+0x5b/0x370 net/core/dst.c:168\n refdst_drop include/net/dst.h:272\n skb_dst_drop include/net/dst.h:284\n skb_release_head_state+0x293/0x400 net/core/skbuff.c:1163\n skb_release_all net/core/skbuff.c:1187\n[..]\nAllocated by task 9391:\n kasan_save_stack+0x30/0x50 mm/kasan/common.c:57\n kasan_save_track+0x14/0x30 mm/kasan/common.c:78\n poison_kmalloc_redzone mm/kasan/common.c:398\n __kasan_kmalloc+0x9a/0xb0 mm/kasan/common.c:415\n kasan_kmalloc include/linux/kasan.h:263\n __do_kmalloc_node mm/slub.c:5296\n __kmalloc_noprof+0x2f1/0x830 mm/slub.c:5308\n kmalloc_noprof include/linux/slab.h:954\n kzalloc_noprof include/linux/slab.h:1188\n offload_action_alloc+0x2f/0x130 net/core/flow_offload.c:35\n tcf_action_offload_add_ex+0x1ba/0x880 net/sched/act_api.c:258\n tcf_action_offload_add net/sched/act_api.c:293\n tcf_action_init+0x66e/0xa20 net/sched/act_api.c:1547\n tcf_action_add+0xf6/0x5d0 net/sched/act_api.c:2101\n[..]\nFreed by task 9391:\n kasan_save_stack+0x30/0x50 mm/kasan/common.c:57\n kasan_save_track+0x14/0x30 mm/kasan/common.c:78\n kasan_save_free_info+0x3b/0x70 mm/kasan/generic.c:584\n poison_slab_object mm/kasan/common.c:253\n __kasan_slab_free+0x6b/0x90 mm/kasan/common.c:285\n kasan_slab_free include/linux/kasan.h:235\n slab_free_hook mm/slub.c:2689\n slab_free mm/slub.c:6251\n kfree+0x21f/0x6b0 mm/slub.c:6566\n tcf_action_offload_add_ex+0x4ad/0x880 net/sched/act_api.c:284\n tcf_action_offload_add net/sched/act_api.c:293\n tcf_action_init+0x66e/0xa20 net/sched/act_api.c:1547\n tcf_action_add+0xf6/0x5d0 net/sched/act_api.c:2101\n\nThe buggy address belongs to the object at ffff88806158de00\n which belongs to the cache kmalloc-256 of size 256\nThe buggy address is located 64 bytes inside of\n freed 256-byte region [ffff88806158de00, ffff88806158df00)\n\nThe buggy address belongs to the physical page:\npage: refcount:0 mapcount:0 mapping:0000000000000000 index:0xffff88806158d600 pfn:0x6158c\nhead: order:1 mapcount:0 entire_map\n---truncated---"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable window is opened via the tc/rtnetlink RTM_NEWACTION path (`tc action replace ... tunnel_key set`) and closed by locally generated traffic through a clsact/ingress filter, both requiring local system access rather than remote packets.\nAC:L - The attacker controls both sides of the race \u2014 one thread repeatedly replaces the tunnel_key action while another pumps packets through the filter \u2014 and can widen the window with qdisc backlog, so the UAF is reliably reproducible (a ZDI PoC reproduced it under KASAN).\nPR:L - The action-add path is gated only by netlink_capable(skb, CAP_NET_ADMIN), which is namespace-relative and obtainable by any unprivileged user via `unshare -Urn`; the packet side runs in the attacker\u0027s own netns.\nUI:N - Both the netlink action replace and the packet transmission that dereferences the stale params are performed entirely by the attacker\u0027s own processes; no victim action is involved.\nS:U - The corruption is confined to kernel heap memory within the same security authority; there is no VM, IOMMU, or sandbox boundary crossed.\nC:H - The freed metadata_dst sits in the general-purpose kmalloc-256 cache and remains attached to an skb, so tx paths read tunnel metadata out of reclaimed memory, giving an attacker who sprays the slab a route to disclose kernel data and defeat KASLR.\nI:H - The stale dst_clone/skb_dst_drop pair performs atomic 4-byte read-modify-write operations on a freed, attacker-reclaimable slab object, yielding a refcount-corruption primitive that is a well-established stepping stone to arbitrary write and privilege escalation.\nA:H - The use-after-free reliably corrupts slab memory and triggers KASAN-reported faults; unmitigated it causes kernel oops or panic, and the race can be repeated at will by an unprivileged user."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:38.220Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b5931f020b681fdcb9378262d89b61cb3c7ebbf8"
},
{
"url": "https://git.kernel.org/stable/c/389d03992dabb80488228e8119b9dd6d0f58e1a6"
},
{
"url": "https://git.kernel.org/stable/c/676ad6aa7cec89a08d2a5ce3cd5959e313f29733"
},
{
"url": "https://git.kernel.org/stable/c/531dbb5bb98e52ad26be7e90f9f8bec707c5bd0e"
},
{
"url": "https://git.kernel.org/stable/c/2200a00ff247f70f5dcdb4e6f14b0d48ddac5467"
},
{
"url": "https://git.kernel.org/stable/c/fed1b1ddab41a0e7a462ac690a0c8af6ff793624"
},
{
"url": "https://git.kernel.org/stable/c/2791a501da508b704a617b4dba29db54a65bc9f7"
},
{
"url": "https://git.kernel.org/stable/c/f1f5c8a3955f8fda3f84ed883ac8daa1847e724c"
}
],
"title": "net/sched: act_tunnel_key: Defer dst_release to RCU callback",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68377",
"datePublished": "2026-08-10T12:03:55.643Z",
"dateReserved": "2026-07-30T09:28:09.386Z",
"dateUpdated": "2026-08-19T16:34:38.220Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68314 (GCVE-0-2026-68314)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-17 05:03
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: mctp i3c: clean up notifier and buses if driver register fails
mctp_i3c_mod_init() registers the I3C bus notifier and then walks the
existing buses with i3c_for_each_bus_locked(mctp_i3c_bus_add_new, NULL)
before registering the I3C device driver. If i3c_driver_register()
fails, the function returns the error directly, leaving the notifier
registered and every mctp_i3c_bus object created for the existing buses
allocated. The notifier is left pointing into the module that failed to
load and the bus list is leaked.
Mirror the module exit path on this failure: unregister the notifier and
tear down the buses that were added before returning the error.
This issue was identified during our ongoing static-analysis research while
reviewing kernel code.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/mctp/mctp-i3c.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "49d15cfab247c0f60ce1800bdcd66850beea7b3a",
"status": "affected",
"version": "c8755b29b58ec65be17bcb8c40763d2dcb1f1db5",
"versionType": "git"
},
{
"lessThan": "a8bd8c109da5a87f0c5db0c23cf550d039fde77c",
"status": "affected",
"version": "c8755b29b58ec65be17bcb8c40763d2dcb1f1db5",
"versionType": "git"
},
{
"lessThan": "a40e83a34eaa2be64372286040696f04eabcd09f",
"status": "affected",
"version": "c8755b29b58ec65be17bcb8c40763d2dcb1f1db5",
"versionType": "git"
},
{
"lessThan": "03d1057305ef17ac3f5936ac1580bc9a1a826e14",
"status": "affected",
"version": "c8755b29b58ec65be17bcb8c40763d2dcb1f1db5",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/mctp/mctp-i3c.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.7"
},
{
"lessThan": "6.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mctp i3c: clean up notifier and buses if driver register fails\n\nmctp_i3c_mod_init() registers the I3C bus notifier and then walks the\nexisting buses with i3c_for_each_bus_locked(mctp_i3c_bus_add_new, NULL)\nbefore registering the I3C device driver. If i3c_driver_register()\nfails, the function returns the error directly, leaving the notifier\nregistered and every mctp_i3c_bus object created for the existing buses\nallocated. The notifier is left pointing into the module that failed to\nload and the bus list is leaked.\n\nMirror the module exit path on this failure: unregister the notifier and\ntear down the buses that were added before returning the error.\n\nThis issue was identified during our ongoing static-analysis research while\nreviewing kernel code."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The stale notifier and leftover mctpi3cN netdevs are reached from the local system \u2014 an AF_MCTP socket transmit or a local I3C bus hotplug event \u2014 not from any remote or adjacent network peer.\nAC:L - Once module init has failed, the leftover state is deterministic and any local user can drive traffic into the freed module\u0027s netdev ops or wait for a bus event with no additional conditions to win.\nPR:L - After the failed load leaves the interfaces registered, an ordinary unprivileged user can open an AF_MCTP socket and send on the stale mctpi3cN interface, dereferencing function pointers in freed module memory without any capability.\nUI:N - No victim action is needed; the leftover netdevs and notifier are globally visible and can be exercised directly by the attacker or by ordinary I3C bus events.\nS:U - The stale pointers and leaked objects are all kernel-side resources within the same security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - Execution against freed module text/data is a use-after-free of a region that can be reclaimed and shaped by the attacker, permitting disclosure of arbitrary kernel memory contents through the reused allocation.\nI:H - Calling through notifier_call and netdev_ops pointers residing in freed module memory yields control-flow hijack once that memory is reallocated, giving an arbitrary write / code execution primitive.\nA:H - Even without successful reclamation, invoking the stale notifier or the leftover netdev\u0027s ops jumps into unmapped or reused memory and reliably oopses/panics the kernel; the leaked netdevs and kthread are also never freed."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:03:10.989Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/49d15cfab247c0f60ce1800bdcd66850beea7b3a"
},
{
"url": "https://git.kernel.org/stable/c/a8bd8c109da5a87f0c5db0c23cf550d039fde77c"
},
{
"url": "https://git.kernel.org/stable/c/a40e83a34eaa2be64372286040696f04eabcd09f"
},
{
"url": "https://git.kernel.org/stable/c/03d1057305ef17ac3f5936ac1580bc9a1a826e14"
}
],
"title": "net: mctp i3c: clean up notifier and buses if driver register fails",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68314",
"datePublished": "2026-08-10T12:02:49.124Z",
"dateReserved": "2026-07-30T09:28:09.382Z",
"dateUpdated": "2026-08-17T05:03:10.989Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68359 (GCVE-0-2026-68359)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
hwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop
Calling hid_hw_stop() does not stop the device IO.
This results in a race condition between hid_input_report() and the point
immediately following the execution of hid_device_io_start() within
the driver probe function. If the probe operation fails after "io start"
has been initiated, this race condition will result in a UAF vulnerability.
Fix the problem by calling hid_device_io_stop() before calling
hid_hw_stop().
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 53e68c20aeb1e23419bed811aa3a309ceda200f9 Version: 53e68c20aeb1e23419bed811aa3a309ceda200f9 Version: 53e68c20aeb1e23419bed811aa3a309ceda200f9 Version: 53e68c20aeb1e23419bed811aa3a309ceda200f9 Version: 53e68c20aeb1e23419bed811aa3a309ceda200f9 Version: 53e68c20aeb1e23419bed811aa3a309ceda200f9 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/hwmon/nzxt-smart2.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "761249a3d92db83ae19670c4ecdf73c0a85bcb61",
"status": "affected",
"version": "53e68c20aeb1e23419bed811aa3a309ceda200f9",
"versionType": "git"
},
{
"lessThan": "185c0880397aee9def0af5a59ea65f22f37ad658",
"status": "affected",
"version": "53e68c20aeb1e23419bed811aa3a309ceda200f9",
"versionType": "git"
},
{
"lessThan": "a2a15de020597efbff84b4281dd472e5860b7e3e",
"status": "affected",
"version": "53e68c20aeb1e23419bed811aa3a309ceda200f9",
"versionType": "git"
},
{
"lessThan": "205cff797a94757ec88ba299c8e2bf2e1e3f4bbf",
"status": "affected",
"version": "53e68c20aeb1e23419bed811aa3a309ceda200f9",
"versionType": "git"
},
{
"lessThan": "18d7c523891004226bccdba39dd681eca22ceb8a",
"status": "affected",
"version": "53e68c20aeb1e23419bed811aa3a309ceda200f9",
"versionType": "git"
},
{
"lessThan": "59d104b54b0b42e30fd2a68d24ee5c49dcc54d1e",
"status": "affected",
"version": "53e68c20aeb1e23419bed811aa3a309ceda200f9",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/hwmon/nzxt-smart2.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.17"
},
{
"lessThan": "5.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.17",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop\n\nCalling hid_hw_stop() does not stop the device IO.\nThis results in a race condition between hid_input_report() and the point\nimmediately following the execution of hid_device_io_start() within\nthe driver probe function. If the probe operation fails after \"io start\"\nhas been initiated, this race condition will result in a UAF vulnerability.\n\nFix the problem by calling hid_device_io_stop() before calling\nhid_hw_stop()."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:08.117Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/761249a3d92db83ae19670c4ecdf73c0a85bcb61"
},
{
"url": "https://git.kernel.org/stable/c/185c0880397aee9def0af5a59ea65f22f37ad658"
},
{
"url": "https://git.kernel.org/stable/c/a2a15de020597efbff84b4281dd472e5860b7e3e"
},
{
"url": "https://git.kernel.org/stable/c/205cff797a94757ec88ba299c8e2bf2e1e3f4bbf"
},
{
"url": "https://git.kernel.org/stable/c/18d7c523891004226bccdba39dd681eca22ceb8a"
},
{
"url": "https://git.kernel.org/stable/c/59d104b54b0b42e30fd2a68d24ee5c49dcc54d1e"
}
],
"title": "hwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68359",
"datePublished": "2026-08-10T12:03:36.254Z",
"dateReserved": "2026-07-30T09:28:09.385Z",
"dateUpdated": "2026-08-19T16:34:08.117Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68148 (GCVE-0-2026-68148)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
fscrypt: Add missing superblock check in find_or_insert_direct_key()
The legacy 'fscrypt_direct_keys' table caches master keys that are used
by v1 encryption policies that have FSCRYPT_POLICY_FLAG_DIRECT_KEY.
It's just a global table for all filesystems (since the keys can be
provided by the legacy process-subscribed keyrings mechanism, which
makes it difficult to reuse super_block::s_master_keys).
The entries in it ('struct fscrypt_direct_key') do contain a super_block
pointer, though, for passing to fscrypt_destroy_inline_crypt_key() when
the last inode that references the key is evicted.
However, when finding the fscrypt_direct_key for an inode, we weren't
actually comparing the super_block pointer. As a result, inodes with
different super_blocks could point to the same fscrypt_direct_key. That
could extend the lifetime of a fscrypt_direct_key beyond the
super_block it points to, causing a use-after-free later.
Fix this by creating distinct fscrypt_direct_key structs for distinct
super_block structs.
Note that this problem doesn't exist in the v2 policy equivalent
("per-mode keys"), since the data structures there are per super_block.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 22e9947a4b2ba255888541bd0111cf00b9b16586 Version: 22e9947a4b2ba255888541bd0111cf00b9b16586 Version: 22e9947a4b2ba255888541bd0111cf00b9b16586 Version: 22e9947a4b2ba255888541bd0111cf00b9b16586 Version: 22e9947a4b2ba255888541bd0111cf00b9b16586 Version: 22e9947a4b2ba255888541bd0111cf00b9b16586 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/crypto/keysetup_v1.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "965b5bc8cf5031225e057979ce660fec2bd5fbfc",
"status": "affected",
"version": "22e9947a4b2ba255888541bd0111cf00b9b16586",
"versionType": "git"
},
{
"lessThan": "330249609b70778094a7a36f5b6bcfa6362121d4",
"status": "affected",
"version": "22e9947a4b2ba255888541bd0111cf00b9b16586",
"versionType": "git"
},
{
"lessThan": "deff41898a5ae3a47db5fa1896a494aa95efda5d",
"status": "affected",
"version": "22e9947a4b2ba255888541bd0111cf00b9b16586",
"versionType": "git"
},
{
"lessThan": "95376fe9c145be35566991df99c53134943d992f",
"status": "affected",
"version": "22e9947a4b2ba255888541bd0111cf00b9b16586",
"versionType": "git"
},
{
"lessThan": "466f187b501a5ac8e1ea2ccf3ccd5c46108d8830",
"status": "affected",
"version": "22e9947a4b2ba255888541bd0111cf00b9b16586",
"versionType": "git"
},
{
"lessThan": "b5fa40226e71c17847b9ff2816c6ca4133d0d994",
"status": "affected",
"version": "22e9947a4b2ba255888541bd0111cf00b9b16586",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/crypto/keysetup_v1.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.1"
},
{
"lessThan": "6.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "6.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfscrypt: Add missing superblock check in find_or_insert_direct_key()\n\nThe legacy \u0027fscrypt_direct_keys\u0027 table caches master keys that are used\nby v1 encryption policies that have FSCRYPT_POLICY_FLAG_DIRECT_KEY.\nIt\u0027s just a global table for all filesystems (since the keys can be\nprovided by the legacy process-subscribed keyrings mechanism, which\nmakes it difficult to reuse super_block::s_master_keys).\n\nThe entries in it (\u0027struct fscrypt_direct_key\u0027) do contain a super_block\npointer, though, for passing to fscrypt_destroy_inline_crypt_key() when\nthe last inode that references the key is evicted.\n\nHowever, when finding the fscrypt_direct_key for an inode, we weren\u0027t\nactually comparing the super_block pointer. As a result, inodes with\ndifferent super_blocks could point to the same fscrypt_direct_key. That\ncould extend the lifetime of a fscrypt_direct_key beyond the\nsuper_block it points to, causing a use-after-free later.\n\nFix this by creating distinct fscrypt_direct_key structs for distinct\nsuper_block structs.\n\nNote that this problem doesn\u0027t exist in the v2 policy equivalent\n(\"per-mode keys\"), since the data structures there are per super_block."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The flaw is reached only through local syscalls (mount/umount, FS_IOC_SET_ENCRYPTION_POLICY, and file I/O that calls fscrypt_get_encryption_info -\u003e find_or_insert_direct_key); fscrypt is not invoked from network-facing kernel services.\nAC:L - An attacker who can mount two encrypted filesystems with the same v1 DIRECT_KEY master key, share the global cache entry, then unmount the first superblock can deterministically trigger eviction-time cleanup on a freed super_block without races or victim-dependent timing.\nPR:L - Exploitation requires mounting/unmounting filesystems and setting v1 DIRECT_KEY policies (CAP_SYS_ADMIN in a user/mount namespace) or supplying keys via process keyrings; per kernel guidance, CAP_SYS_ADMIN obtainable in user namespaces maps to PR:L.\nUI:N - No separate victim action is required; the attacker sets v1 DIRECT_KEY policies, accesses encrypted inodes on two mounts, and controls unmount/eviction to hit the vulnerable refcount and cleanup path.\nS:U - The use-after-free corrupts kernel heap memory and enables local privilege escalation within the same kernel; it does not cross VM, hypervisor, or IOMMU security boundaries.\nC:H - Extending a fscrypt_direct_key past its super_block lifetime causes cleanup to dereference a freed super_block in fscrypt_destroy_inline_crypt_key(), a use-after-free that can leak kernel memory and support arbitrary-read exploitation primitives.\nI:H - Use-after-free during inline-crypto key destruction on a dangling super_block pointer can be leveraged for heap corruption and arbitrary kernel writes, enabling local privilege escalation rather than only a controlled crash.\nA:H - Evicting the last inode holding the mismatched fscrypt_direct_key dereferences a freed super_block during key teardown, which can cause kernel oops/panic and complete local denial of service on encrypted mobile/embedded and server systems using inline encryption."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:30:13.417Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/965b5bc8cf5031225e057979ce660fec2bd5fbfc"
},
{
"url": "https://git.kernel.org/stable/c/330249609b70778094a7a36f5b6bcfa6362121d4"
},
{
"url": "https://git.kernel.org/stable/c/deff41898a5ae3a47db5fa1896a494aa95efda5d"
},
{
"url": "https://git.kernel.org/stable/c/95376fe9c145be35566991df99c53134943d992f"
},
{
"url": "https://git.kernel.org/stable/c/466f187b501a5ac8e1ea2ccf3ccd5c46108d8830"
},
{
"url": "https://git.kernel.org/stable/c/b5fa40226e71c17847b9ff2816c6ca4133d0d994"
}
],
"title": "fscrypt: Add missing superblock check in find_or_insert_direct_key()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68148",
"datePublished": "2026-08-10T11:59:13.413Z",
"dateReserved": "2026-07-30T09:28:09.371Z",
"dateUpdated": "2026-08-19T16:30:13.417Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68343 (GCVE-0-2026-68343)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
smb: client: validate DFS referral PathConsumed
parse_dfs_referrals() validates that the response contains the fixed
referral entry array and, on for-next, the per-referral string offsets.
However, the response also contains a PathConsumed value that is later
used for DFS path parsing.
If a malformed response provides a PathConsumed value larger than the
search name, later DFS parsing can advance beyond the end of the path.
Validate PathConsumed against the search name length before storing it in
the parsed referral.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 4ecce920e13ace16a5ba45efe8909946c28fb2ad Version: 4ecce920e13ace16a5ba45efe8909946c28fb2ad Version: 4ecce920e13ace16a5ba45efe8909946c28fb2ad Version: 4ecce920e13ace16a5ba45efe8909946c28fb2ad Version: 4ecce920e13ace16a5ba45efe8909946c28fb2ad Version: 4ecce920e13ace16a5ba45efe8909946c28fb2ad |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/smb/client/misc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "bfebe5110fd135d86d65a0a346e14c106b02028b",
"status": "affected",
"version": "4ecce920e13ace16a5ba45efe8909946c28fb2ad",
"versionType": "git"
},
{
"lessThan": "5b439f39f33ec15d319ced3b025e122346fba987",
"status": "affected",
"version": "4ecce920e13ace16a5ba45efe8909946c28fb2ad",
"versionType": "git"
},
{
"lessThan": "285bd4a5f3f156aa5869843b47a1b1380b774241",
"status": "affected",
"version": "4ecce920e13ace16a5ba45efe8909946c28fb2ad",
"versionType": "git"
},
{
"lessThan": "2fdd6d196c656b376cc251e1e9ff110b3ed522e1",
"status": "affected",
"version": "4ecce920e13ace16a5ba45efe8909946c28fb2ad",
"versionType": "git"
},
{
"lessThan": "9f88a99ed511651b2dc2177d6854b2d1b8322e75",
"status": "affected",
"version": "4ecce920e13ace16a5ba45efe8909946c28fb2ad",
"versionType": "git"
},
{
"lessThan": "f6f5ee2aa33b350c671721b965251c42cebb962e",
"status": "affected",
"version": "4ecce920e13ace16a5ba45efe8909946c28fb2ad",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/smb/client/misc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.11"
},
{
"lessThan": "4.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: validate DFS referral PathConsumed\n\nparse_dfs_referrals() validates that the response contains the fixed\nreferral entry array and, on for-next, the per-referral string offsets.\nHowever, the response also contains a PathConsumed value that is later\nused for DFS path parsing.\n\nIf a malformed response provides a PathConsumed value larger than the\nsearch name, later DFS parsing can advance beyond the end of the path.\n\nValidate PathConsumed against the search name length before storing it in\nthe parsed referral."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The tainted PathConsumed value comes directly from a GET_DFS_REFERRAL response received over TCP/445 from the SMB server, so a malicious or MITM-positioned server on the network fully controls the input to the vulnerable code.\nAC:L - The server simply sets an oversized PathConsumed (up to 65535, and it can also clear the SMB1 UNICODE flag to select the completely unvalidated branch); the resulting out-of-bounds walk past the path buffer is deterministic and needs no race or memory-layout luck.\nPR:N - The attacker is the remote server (or a MITM on an unsigned connection) and needs no account or privilege on the victim client; the client parses the referral response as part of establishing the connection.\nUI:N - DFS referral walks are performed automatically by autofs/systemd automounts, fstab mounts at boot and reconnect-driven remounts, so a forged referral can be delivered without any user action.\nS:U - The out-of-bounds access stays within the kernel\u0027s own memory and mount context on the client; no VM, IOMMU or sandbox boundary is crossed.\nC:H - prepath = full_path + path_consumed points past the end of the heap path string, and cifs_build_devname() strlen()s and copies from there, splicing adjacent kernel heap contents (up to ~64KB away) into the constructed UNC/prefixpath that is then observable via the mount source and /proc/mounts.\nI:N - The defect is purely an out-of-bounds read; all subsequent allocations and copies are sized from the same over-read string, so no kernel memory is written or corrupted.\nA:H - With PathConsumed up to 65535 the pointer can run far past a small slab object into an unmapped or guarded page, so strlen() on it oopses the mounting task (and panics on panic_on_oops systems)."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:43.025Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/bfebe5110fd135d86d65a0a346e14c106b02028b"
},
{
"url": "https://git.kernel.org/stable/c/5b439f39f33ec15d319ced3b025e122346fba987"
},
{
"url": "https://git.kernel.org/stable/c/285bd4a5f3f156aa5869843b47a1b1380b774241"
},
{
"url": "https://git.kernel.org/stable/c/2fdd6d196c656b376cc251e1e9ff110b3ed522e1"
},
{
"url": "https://git.kernel.org/stable/c/9f88a99ed511651b2dc2177d6854b2d1b8322e75"
},
{
"url": "https://git.kernel.org/stable/c/f6f5ee2aa33b350c671721b965251c42cebb962e"
}
],
"title": "smb: client: validate DFS referral PathConsumed",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68343",
"datePublished": "2026-08-10T12:03:19.939Z",
"dateReserved": "2026-07-30T09:28:09.384Z",
"dateUpdated": "2026-08-19T16:33:43.025Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68130 (GCVE-0-2026-68130)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-23 12:45
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: defer destroy_previous_session() until after NTLM authentication
In ntlm_authenticate(), destroy_previous_session() is called using a
user pointer resolved from the client-supplied NTLM blob username field
before the NTLMv2 response is validated. An authenticated attacker can
set the NTLM blob username to match a victim account and set
PreviousSessionId to the victim's session ID; destroy_previous_session()
destroys the victim's session while ksmbd_decode_ntlmssp_auth_blob()
subsequently rejects the request with -EPERM.
Move destroy_previous_session() and the prev_id assignment to after
ksmbd_decode_ntlmssp_auth_blob() returns success and use sess->user
rather than the pre-authentication lookup result. This matches the
ordering already used by krb5_authenticate(), where
destroy_previous_session() is called only after
ksmbd_krb5_authenticate() returns success.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 Version: e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 Version: e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 Version: e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 Version: e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 Version: e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 Version: e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/smb/server/smb2pdu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ab0230257ebdf48b07eaa679a8c92bc842fe3498",
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"versionType": "git"
},
{
"lessThan": "370b0ec8822b69c9073265e16b7daaa8201c9a4f",
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"versionType": "git"
},
{
"lessThan": "5c833074b549e5db125436a6f681af682261f785",
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"versionType": "git"
},
{
"lessThan": "243f1614ef2aca2d62a744575f1c24b07cd42757",
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"versionType": "git"
},
{
"lessThan": "18705cace0619fd2123737dcd028147774f38181",
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"versionType": "git"
},
{
"lessThan": "0ff12308c8a6c16ab68f0a487ffa93d69001dc18",
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"versionType": "git"
},
{
"lessThan": "c74801ee524f477c174a1899782b6c3b6918d407",
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/smb/server/smb2pdu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.15"
},
{
"lessThan": "5.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: defer destroy_previous_session() until after NTLM authentication\n\nIn ntlm_authenticate(), destroy_previous_session() is called using a\nuser pointer resolved from the client-supplied NTLM blob username field\nbefore the NTLMv2 response is validated. An authenticated attacker can\nset the NTLM blob username to match a victim account and set\nPreviousSessionId to the victim\u0027s session ID; destroy_previous_session()\ndestroys the victim\u0027s session while ksmbd_decode_ntlmssp_auth_blob()\nsubsequently rejects the request with -EPERM.\n\nMove destroy_previous_session() and the prev_id assignment to after\nksmbd_decode_ntlmssp_auth_blob() returns success and use sess-\u003euser\nrather than the pre-authentication lookup result. This matches the\nordering already used by krb5_authenticate(), where\ndestroy_previous_session() is called only after\nksmbd_krb5_authenticate() returns success."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:45:52.403Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ab0230257ebdf48b07eaa679a8c92bc842fe3498"
},
{
"url": "https://git.kernel.org/stable/c/370b0ec8822b69c9073265e16b7daaa8201c9a4f"
},
{
"url": "https://git.kernel.org/stable/c/5c833074b549e5db125436a6f681af682261f785"
},
{
"url": "https://git.kernel.org/stable/c/243f1614ef2aca2d62a744575f1c24b07cd42757"
},
{
"url": "https://git.kernel.org/stable/c/18705cace0619fd2123737dcd028147774f38181"
},
{
"url": "https://git.kernel.org/stable/c/0ff12308c8a6c16ab68f0a487ffa93d69001dc18"
},
{
"url": "https://git.kernel.org/stable/c/c74801ee524f477c174a1899782b6c3b6918d407"
}
],
"title": "ksmbd: defer destroy_previous_session() until after NTLM authentication",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68130",
"datePublished": "2026-08-10T11:58:52.653Z",
"dateReserved": "2026-07-30T09:28:09.370Z",
"dateUpdated": "2026-08-23T12:45:52.403Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68110 (GCVE-0-2026-68110)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-17 04:58
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu/sdma4.4.2: replace BUG_ON() with WARN_ON()
There's no need to crash the kernel for these cases.
(cherry picked from commit fa4f86a148271e325e95287630a3a15a9cd35fdc)
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/sdma_v4_4_2.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "256d6f4803a93df96579c1ffdcb56518b9304f76",
"status": "affected",
"version": "7138fc88fdc1f999a547657af8623d3a2a862fc1",
"versionType": "git"
},
{
"lessThan": "ca50e541191fab519ed628182e1472e21d60e2ce",
"status": "affected",
"version": "7138fc88fdc1f999a547657af8623d3a2a862fc1",
"versionType": "git"
},
{
"lessThan": "dc3f5da1ba8e280d31676ce15b937e4302235b03",
"status": "affected",
"version": "7138fc88fdc1f999a547657af8623d3a2a862fc1",
"versionType": "git"
},
{
"lessThan": "cbe3b293d0ee926e595f53513d7c027d1c3e5be5",
"status": "affected",
"version": "7138fc88fdc1f999a547657af8623d3a2a862fc1",
"versionType": "git"
},
{
"lessThan": "40cdbe9fa424cc6264a7aed93a04bd7d69109d9e",
"status": "affected",
"version": "7138fc88fdc1f999a547657af8623d3a2a862fc1",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/sdma_v4_4_2.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.4"
},
{
"lessThan": "6.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/sdma4.4.2: replace BUG_ON() with WARN_ON()\n\nThere\u0027s no need to crash the kernel for these cases.\n\n(cherry picked from commit fa4f86a148271e325e95287630a3a15a9cd35fdc)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:58:59.664Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/256d6f4803a93df96579c1ffdcb56518b9304f76"
},
{
"url": "https://git.kernel.org/stable/c/ca50e541191fab519ed628182e1472e21d60e2ce"
},
{
"url": "https://git.kernel.org/stable/c/dc3f5da1ba8e280d31676ce15b937e4302235b03"
},
{
"url": "https://git.kernel.org/stable/c/cbe3b293d0ee926e595f53513d7c027d1c3e5be5"
},
{
"url": "https://git.kernel.org/stable/c/40cdbe9fa424cc6264a7aed93a04bd7d69109d9e"
}
],
"title": "drm/amdgpu/sdma4.4.2: replace BUG_ON() with WARN_ON()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68110",
"datePublished": "2026-08-10T11:58:27.478Z",
"dateReserved": "2026-07-30T09:28:09.368Z",
"dateUpdated": "2026-08-17T04:58:59.664Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68386 (GCVE-0-2026-68386)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
bpf, sockmap: Reject unhashed UDP sockets on sockmap update
UDP sockets get SOCK_RCU_FREE set when (auto-)bound. This means
sk_is_refcounted(unbound) = true, while sk_is_refcounted(bound) = false.
Because sockmap accepts unbound UDP sockets, a BPF program can increment a
socket's refcount via lookup. If the socket is subsequently bound, the
transition from unbound to bound causes bpf_sk_release() to skip the
decrement of the refcount, causing a memory leak.
unreferenced object 0xffff88810bc2eb40 (size 1984):
comm "test_progs", pid 2451, jiffies 4295320596
hex dump (first 32 bytes):
7f 00 00 01 7f 00 00 01 d2 04 1b b7 04 d2 00 00 ................
02 00 01 40 00 00 00 00 00 00 00 00 00 00 00 00 ...@............
backtrace (crc bdee079d):
kmem_cache_alloc_noprof+0x557/0x660
sk_prot_alloc+0x69/0x240
sk_alloc+0x30/0x460
inet_create+0x2ce/0xf80
__sock_create+0x25b/0x5c0
__sys_socket+0x119/0x1d0
__x64_sys_socket+0x72/0xd0
do_syscall_64+0xa1/0x5f0
entry_SYSCALL_64_after_hwframe+0x76/0x7e
Instead of special-casing for refcounted sockets, reject unhashed UDP
sockets during sockmap updates, as there is no benefit to supporting those.
This effectively reverts the commit under Fixes, with two exceptions:
1. sock_map_sk_state_allowed() maintains a fall-through `return true`.
2. In the spirit of commit b8b8315e39ff ("bpf, sockmap: Remove unhash
handler for BPF sockmap usage"), the proto::unhash BPF handler is not
reintroduced.
Historical note: this issue is related to commit 67312adc96b5 ("bpf: reject
unhashed sockets in bpf_sk_assign").
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 0c48eefae712c2fd91480346a07a1a9cd0f9470b Version: 0c48eefae712c2fd91480346a07a1a9cd0f9470b Version: 0c48eefae712c2fd91480346a07a1a9cd0f9470b Version: 0c48eefae712c2fd91480346a07a1a9cd0f9470b Version: 0c48eefae712c2fd91480346a07a1a9cd0f9470b Version: 0c48eefae712c2fd91480346a07a1a9cd0f9470b |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/core/sock_map.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "2271276ac5279d2d204be7739a1a28d4ef6cf608",
"status": "affected",
"version": "0c48eefae712c2fd91480346a07a1a9cd0f9470b",
"versionType": "git"
},
{
"lessThan": "7ffe529e7127411806c8692fb1490f552c629dc2",
"status": "affected",
"version": "0c48eefae712c2fd91480346a07a1a9cd0f9470b",
"versionType": "git"
},
{
"lessThan": "17b7ef6b86112a4e61cee1e9009a4b318e3225c5",
"status": "affected",
"version": "0c48eefae712c2fd91480346a07a1a9cd0f9470b",
"versionType": "git"
},
{
"lessThan": "250474c69bc3fc48a5fc21d7c349f279caad947a",
"status": "affected",
"version": "0c48eefae712c2fd91480346a07a1a9cd0f9470b",
"versionType": "git"
},
{
"lessThan": "8692655da369961128658cf8539334b6a960ecb0",
"status": "affected",
"version": "0c48eefae712c2fd91480346a07a1a9cd0f9470b",
"versionType": "git"
},
{
"lessThan": "66efd3368ae10d05e08fbe6425b50fdec7186ac7",
"status": "affected",
"version": "0c48eefae712c2fd91480346a07a1a9cd0f9470b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/core/sock_map.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.15"
},
{
"lessThan": "5.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf, sockmap: Reject unhashed UDP sockets on sockmap update\n\nUDP sockets get SOCK_RCU_FREE set when (auto-)bound. This means\nsk_is_refcounted(unbound) = true, while sk_is_refcounted(bound) = false.\n\nBecause sockmap accepts unbound UDP sockets, a BPF program can increment a\nsocket\u0027s refcount via lookup. If the socket is subsequently bound, the\ntransition from unbound to bound causes bpf_sk_release() to skip the\ndecrement of the refcount, causing a memory leak.\n\nunreferenced object 0xffff88810bc2eb40 (size 1984):\n comm \"test_progs\", pid 2451, jiffies 4295320596\n hex dump (first 32 bytes):\n 7f 00 00 01 7f 00 00 01 d2 04 1b b7 04 d2 00 00 ................\n 02 00 01 40 00 00 00 00 00 00 00 00 00 00 00 00 ...@............\n backtrace (crc bdee079d):\n kmem_cache_alloc_noprof+0x557/0x660\n sk_prot_alloc+0x69/0x240\n sk_alloc+0x30/0x460\n inet_create+0x2ce/0xf80\n __sock_create+0x25b/0x5c0\n __sys_socket+0x119/0x1d0\n __x64_sys_socket+0x72/0xd0\n do_syscall_64+0xa1/0x5f0\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nInstead of special-casing for refcounted sockets, reject unhashed UDP\nsockets during sockmap updates, as there is no benefit to supporting those.\nThis effectively reverts the commit under Fixes, with two exceptions:\n\n1. sock_map_sk_state_allowed() maintains a fall-through `return true`.\n2. In the spirit of commit b8b8315e39ff (\"bpf, sockmap: Remove unhash\n handler for BPF sockmap usage\"), the proto::unhash BPF handler is not\n reintroduced.\n\nHistorical note: this issue is related to commit 67312adc96b5 (\"bpf: reject\nunhashed sockets in bpf_sk_assign\")."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:40.363Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/2271276ac5279d2d204be7739a1a28d4ef6cf608"
},
{
"url": "https://git.kernel.org/stable/c/7ffe529e7127411806c8692fb1490f552c629dc2"
},
{
"url": "https://git.kernel.org/stable/c/17b7ef6b86112a4e61cee1e9009a4b318e3225c5"
},
{
"url": "https://git.kernel.org/stable/c/250474c69bc3fc48a5fc21d7c349f279caad947a"
},
{
"url": "https://git.kernel.org/stable/c/8692655da369961128658cf8539334b6a960ecb0"
},
{
"url": "https://git.kernel.org/stable/c/66efd3368ae10d05e08fbe6425b50fdec7186ac7"
}
],
"title": "bpf, sockmap: Reject unhashed UDP sockets on sockmap update",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68386",
"datePublished": "2026-08-10T12:04:05.306Z",
"dateReserved": "2026-07-30T09:28:09.388Z",
"dateUpdated": "2026-08-19T16:34:40.363Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68315 (GCVE-0-2026-68315)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
sctp: validate stream count in sctp_process_strreset_inreq()
When processing a RESET_IN_REQUEST from a peer,
sctp_process_strreset_inreq() derives the stream count from the
parameter length but does not check whether the resulting
RESET_OUT_REQUEST would exceed SCTP_MAX_CHUNK_LEN.
The OUT request header (sctp_strreset_outreq, 16 bytes) is 8 bytes
larger than the IN request header (sctp_strreset_inreq, 8 bytes).
Generally, the IP payload is bounded to 65535 bytes, so the stream
list cannot be large enough to trigger the overflow. However, on
interfaces with MTU > 65535 (e.g., loopback with IPv6 jumbograms), a
stream list that fits within the incoming IN parameter can cause a
__u16 overflow in sctp_make_strreset_req() when computing the OUT
request size, leading to an undersized skb allocation and a kernel
BUG:
net/core/skbuff.c:207 skb_panic
net/core/skbuff.c:2625 skb_put
net/sctp/sm_make_chunk.c:1535 sctp_addto_chunk
net/sctp/sm_make_chunk.c:3695 sctp_make_strreset_req
net/sctp/stream.c:655 sctp_process_strreset_inreq
The local setsockopt path validates the generated reset request size.
However, for an incoming-only reset, it accounts for the smaller IN
request even though the peer must generate an OUT request with the same
stream list. Such a request cannot be completed successfully by the
peer.
Reject peer IN requests whose corresponding OUT request would exceed
SCTP_MAX_CHUNK_LEN. Also tighten the local check so it does not send an
IN request that would require an oversized OUT request from the peer.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137 Version: 7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137 Version: 7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137 Version: 7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137 Version: 7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137 Version: 7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137 Version: 7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137 Version: 7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/sctp/stream.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "61327d8e7cfb0259d527be17202630f556213249",
"status": "affected",
"version": "7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137",
"versionType": "git"
},
{
"lessThan": "7cf7439948e3bf639119119922c88ec190874ca3",
"status": "affected",
"version": "7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137",
"versionType": "git"
},
{
"lessThan": "60c47dea5d320d2fc706e9aad1db38a04df0a056",
"status": "affected",
"version": "7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137",
"versionType": "git"
},
{
"lessThan": "b255d8cd6cc68045ae9eecbac3b3c14e1f176c9b",
"status": "affected",
"version": "7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137",
"versionType": "git"
},
{
"lessThan": "6f0e39d180cd7cced647381b6fa14fd83d261047",
"status": "affected",
"version": "7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137",
"versionType": "git"
},
{
"lessThan": "1a10fe1aa9c01f41b389a31906a77d538637c9d9",
"status": "affected",
"version": "7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137",
"versionType": "git"
},
{
"lessThan": "00ae679cb21a035491fdad8d58dc6d79cc68b675",
"status": "affected",
"version": "7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137",
"versionType": "git"
},
{
"lessThan": "18ae07691d43183d270de8be9dc8e027906015d9",
"status": "affected",
"version": "7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/sctp/stream.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.11"
},
{
"lessThan": "4.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: validate stream count in sctp_process_strreset_inreq()\n\nWhen processing a RESET_IN_REQUEST from a peer,\nsctp_process_strreset_inreq() derives the stream count from the\nparameter length but does not check whether the resulting\nRESET_OUT_REQUEST would exceed SCTP_MAX_CHUNK_LEN.\n\nThe OUT request header (sctp_strreset_outreq, 16 bytes) is 8 bytes\nlarger than the IN request header (sctp_strreset_inreq, 8 bytes).\nGenerally, the IP payload is bounded to 65535 bytes, so the stream\nlist cannot be large enough to trigger the overflow. However, on\ninterfaces with MTU \u003e 65535 (e.g., loopback with IPv6 jumbograms), a\nstream list that fits within the incoming IN parameter can cause a\n__u16 overflow in sctp_make_strreset_req() when computing the OUT\nrequest size, leading to an undersized skb allocation and a kernel\nBUG:\n\n net/core/skbuff.c:207 skb_panic\n net/core/skbuff.c:2625 skb_put\n net/sctp/sm_make_chunk.c:1535 sctp_addto_chunk\n net/sctp/sm_make_chunk.c:3695 sctp_make_strreset_req\n net/sctp/stream.c:655 sctp_process_strreset_inreq\n\nThe local setsockopt path validates the generated reset request size.\nHowever, for an incoming-only reset, it accounts for the smaller IN\nrequest even though the peer must generate an OUT request with the same\nstream list. Such a request cannot be completed successfully by the\npeer.\n\nReject peer IN requests whose corresponding OUT request would exceed\nSCTP_MAX_CHUNK_LEN. Also tighten the local check so it does not send an\nIN request that would require an oversized OUT request from the peer."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The vulnerability is triggered by processing an SCTP RECONF chunk (RESET_IN_REQUEST) received from a remote/loopback peer in the in-kernel SCTP stack; per kernel guidance net-stack bugs reachable via received packets are Network.\nAC:L - The attacker fully controls the stream list length in the IN request, and the required MTU\u003e65535 is the default for loopback (65536), so the panic is reliably triggerable; stream-reset must be enabled but that is a deployment condition, not an attacker-uncontrollable one.\nPR:N - Sending the RECONF chunk only requires an established SCTP association, which any peer can set up without authentication or credentials; the bug is reached during normal association-scoped packet processing.\nUI:N - No victim interaction is needed; the attacker simply sends a crafted RECONF chunk to an established association.\nS:U - The crash occurs within the kernel\u0027s own security scope with no crossing of a security boundary such as VM or IOMMU.\nC:N - The bug is a controlled BUG()/skb_over_panic that aborts before any out-of-bounds access, disclosing no memory contents.\nI:N - The panic fires before the oversized copy executes, so no memory is written or modified out of bounds.\nA:H - The undersized skb allocation causes skb_put to invoke skb_over_panic \u2192 BUG(), producing a kernel panic (denial of service)."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:08.206Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/61327d8e7cfb0259d527be17202630f556213249"
},
{
"url": "https://git.kernel.org/stable/c/7cf7439948e3bf639119119922c88ec190874ca3"
},
{
"url": "https://git.kernel.org/stable/c/60c47dea5d320d2fc706e9aad1db38a04df0a056"
},
{
"url": "https://git.kernel.org/stable/c/b255d8cd6cc68045ae9eecbac3b3c14e1f176c9b"
},
{
"url": "https://git.kernel.org/stable/c/6f0e39d180cd7cced647381b6fa14fd83d261047"
},
{
"url": "https://git.kernel.org/stable/c/1a10fe1aa9c01f41b389a31906a77d538637c9d9"
},
{
"url": "https://git.kernel.org/stable/c/00ae679cb21a035491fdad8d58dc6d79cc68b675"
},
{
"url": "https://git.kernel.org/stable/c/18ae07691d43183d270de8be9dc8e027906015d9"
}
],
"title": "sctp: validate stream count in sctp_process_strreset_inreq()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68315",
"datePublished": "2026-08-10T12:02:50.156Z",
"dateReserved": "2026-07-30T09:28:09.382Z",
"dateUpdated": "2026-08-19T16:33:08.206Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68411 (GCVE-0-2026-68411)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-19 16:35
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211_hwsim: clamp virtio RX length before skb_put
hwsim_virtio_rx_work() passes the virtqueue used-ring length reported by
the device straight to skb_put() on a fixed-size receive skb. A backend
reporting a length larger than the skb tailroom drives skb_put() past the
buffer end and hits skb_over_panic() -- a host-triggerable guest panic
(denial of service).
Clamp the length to the skb's available room before skb_put(). A
conforming device never reports more than the posted buffer size, so valid
frames are unaffected; a truncated over-report then fails the
length/header checks in hwsim_virtio_handle_cmd() and is dropped, so
truncating rather than dropping here cannot be turned into a parsing
problem.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 5d44fe7c9808c56e136e59147bd932f5491520f1 Version: 5d44fe7c9808c56e136e59147bd932f5491520f1 Version: 5d44fe7c9808c56e136e59147bd932f5491520f1 Version: 5d44fe7c9808c56e136e59147bd932f5491520f1 Version: 5d44fe7c9808c56e136e59147bd932f5491520f1 Version: 5d44fe7c9808c56e136e59147bd932f5491520f1 Version: 5d44fe7c9808c56e136e59147bd932f5491520f1 Version: 5d44fe7c9808c56e136e59147bd932f5491520f1 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/virtual/mac80211_hwsim_main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "7f9d678b870fca8eaf1d46fa915cba0b1d5b387a",
"status": "affected",
"version": "5d44fe7c9808c56e136e59147bd932f5491520f1",
"versionType": "git"
},
{
"lessThan": "909573d6a9b67354fc0515952574564e7c909c62",
"status": "affected",
"version": "5d44fe7c9808c56e136e59147bd932f5491520f1",
"versionType": "git"
},
{
"lessThan": "5779e4a33e1666ddfeba43e96e29c4a9e5254ff0",
"status": "affected",
"version": "5d44fe7c9808c56e136e59147bd932f5491520f1",
"versionType": "git"
},
{
"lessThan": "82c5a30a66e2a7337d99476c67d6fc1a99c4250e",
"status": "affected",
"version": "5d44fe7c9808c56e136e59147bd932f5491520f1",
"versionType": "git"
},
{
"lessThan": "fade308845c89f784da8a6780c1e77258488f1b6",
"status": "affected",
"version": "5d44fe7c9808c56e136e59147bd932f5491520f1",
"versionType": "git"
},
{
"lessThan": "6dc76371a9a360c29de00df5b11563102d9d675a",
"status": "affected",
"version": "5d44fe7c9808c56e136e59147bd932f5491520f1",
"versionType": "git"
},
{
"lessThan": "99dc05c75acc3c8cde8d89c5371f4b569de5ac62",
"status": "affected",
"version": "5d44fe7c9808c56e136e59147bd932f5491520f1",
"versionType": "git"
},
{
"lessThan": "10a2b430f8f06ae14b9590b6f6faa6b588ef0654",
"status": "affected",
"version": "5d44fe7c9808c56e136e59147bd932f5491520f1",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/virtual/mac80211_hwsim_main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.7"
},
{
"lessThan": "5.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211_hwsim: clamp virtio RX length before skb_put\n\nhwsim_virtio_rx_work() passes the virtqueue used-ring length reported by\nthe device straight to skb_put() on a fixed-size receive skb. A backend\nreporting a length larger than the skb tailroom drives skb_put() past the\nbuffer end and hits skb_over_panic() -- a host-triggerable guest panic\n(denial of service).\n\nClamp the length to the skb\u0027s available room before skb_put(). A\nconforming device never reports more than the posted buffer size, so valid\nframes are unaffected; a truncated over-report then fails the\nlength/header checks in hwsim_virtio_handle_cmd() and is dropped, so\ntruncating rather than dropping here cannot be turned into a parsing\nproblem."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:35:07.403Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/7f9d678b870fca8eaf1d46fa915cba0b1d5b387a"
},
{
"url": "https://git.kernel.org/stable/c/909573d6a9b67354fc0515952574564e7c909c62"
},
{
"url": "https://git.kernel.org/stable/c/5779e4a33e1666ddfeba43e96e29c4a9e5254ff0"
},
{
"url": "https://git.kernel.org/stable/c/82c5a30a66e2a7337d99476c67d6fc1a99c4250e"
},
{
"url": "https://git.kernel.org/stable/c/fade308845c89f784da8a6780c1e77258488f1b6"
},
{
"url": "https://git.kernel.org/stable/c/6dc76371a9a360c29de00df5b11563102d9d675a"
},
{
"url": "https://git.kernel.org/stable/c/99dc05c75acc3c8cde8d89c5371f4b569de5ac62"
},
{
"url": "https://git.kernel.org/stable/c/10a2b430f8f06ae14b9590b6f6faa6b588ef0654"
}
],
"title": "wifi: mac80211_hwsim: clamp virtio RX length before skb_put",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68411",
"datePublished": "2026-08-10T12:04:31.532Z",
"dateReserved": "2026-07-30T09:28:09.391Z",
"dateUpdated": "2026-08-19T16:35:07.403Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68260 (GCVE-0-2026-68260)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-17 05:01
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/imagination: acquire vm_ctx->lock before mapping memory to GPU VM
The drm gpuvm code doesn't protect find operation against map operation,
and the driver needs to ensure a map operation shouldn't happen when a
find operation is in progress.
In some cases a find operation will be in progress when doing map/unmap
operations, and the find operation will do a NULL pointer dereference.
An example of the stack trace of such NULL dereference is shown below:
```
Unable to handle kernel access to user memory without uaccess routines at
virtual address 0000000000000010
[<ffffffff01e989d4>] drm_gpuva_find+0x28/0x6c [drm_gpuvm]
[<ffffffff01ed3a40>] pvr_vm_unmap+0x34/0x68 [powervr]
[<ffffffff01ec69da>] pvr_ioctl_vm_unmap+0x2e/0x50 [powervr]
[<ffffffff8080ce0a>] drm_ioctl_kernel+0x8e/0xdc
[<ffffffff8080d016>] drm_ioctl+0x1be/0x3e0
[<ffffffff802bec3e>] __riscv_sys_ioctl+0xba/0xc4
[<ffffffff80d858b2>] do_trap_ecall_u+0x23e/0x3f4
[<ffffffff80d92288>] handle_exception+0x168/0x174
```
As all occurences of drm_gpuva_find*() are already guarded by
vm_ctx->lock, make pvr_vm_map() to acquire this lock to prevent
disturbing any find operation. This fixes the NULL deference problem in
drm_gpuva_find*().
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/imagination/pvr_vm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "1f1f2618e44b21a7d4eb30d3bbd7e015ffbbbadf",
"status": "affected",
"version": "ff5f643de0bf27874c4033cd57a0bd034b5c7d11",
"versionType": "git"
},
{
"lessThan": "6253bb56bb2ebdf317d8b599ce737a2510cc2e17",
"status": "affected",
"version": "ff5f643de0bf27874c4033cd57a0bd034b5c7d11",
"versionType": "git"
},
{
"lessThan": "15f58d44c24477a6ebffa44ec05207b81cfa55d9",
"status": "affected",
"version": "ff5f643de0bf27874c4033cd57a0bd034b5c7d11",
"versionType": "git"
},
{
"lessThan": "17e2030f37600994440f875dc410615d5c66ee6d",
"status": "affected",
"version": "ff5f643de0bf27874c4033cd57a0bd034b5c7d11",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/imagination/pvr_vm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.8"
},
{
"lessThan": "6.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/imagination: acquire vm_ctx-\u003elock before mapping memory to GPU VM\n\nThe drm gpuvm code doesn\u0027t protect find operation against map operation,\nand the driver needs to ensure a map operation shouldn\u0027t happen when a\nfind operation is in progress.\n\nIn some cases a find operation will be in progress when doing map/unmap\noperations, and the find operation will do a NULL pointer dereference.\n\nAn example of the stack trace of such NULL dereference is shown below:\n\n```\nUnable to handle kernel access to user memory without uaccess routines at\nvirtual address 0000000000000010\n\n[\u003cffffffff01e989d4\u003e] drm_gpuva_find+0x28/0x6c [drm_gpuvm]\n[\u003cffffffff01ed3a40\u003e] pvr_vm_unmap+0x34/0x68 [powervr]\n[\u003cffffffff01ec69da\u003e] pvr_ioctl_vm_unmap+0x2e/0x50 [powervr]\n[\u003cffffffff8080ce0a\u003e] drm_ioctl_kernel+0x8e/0xdc\n[\u003cffffffff8080d016\u003e] drm_ioctl+0x1be/0x3e0\n[\u003cffffffff802bec3e\u003e] __riscv_sys_ioctl+0xba/0xc4\n[\u003cffffffff80d858b2\u003e] do_trap_ecall_u+0x23e/0x3f4\n[\u003cffffffff80d92288\u003e] handle_exception+0x168/0x174\n```\n\nAs all occurences of drm_gpuva_find*() are already guarded by\nvm_ctx-\u003elock, make pvr_vm_map() to acquire this lock to prevent\ndisturbing any find operation. This fixes the NULL deference problem in\ndrm_gpuva_find*()."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Triggered through the DRM_IOCTL_PVR_VM_MAP/VM_UNMAP ioctls on the PowerVR render node (/dev/dri/renderD*), which requires local access to the device file; no network or physical path exists.\nAC:L - The attacker owns both sides of the race, issuing concurrent VM_MAP and VM_UNMAP ioctls from two threads on the same fd and vm_ctx handle, and can retry indefinitely with attacker-chosen mapping layouts that force split/remap (free) paths.\nPR:L - The ioctls are marked DRM_RENDER_ALLOW, so no DRM master, root, or capability is needed; any unprivileged process able to open the render node (world-accessible or graphics-group on Android/embedded PowerVR devices) can reach the code.\nUI:N - The attacker performs the entire sequence itself by opening the render node, creating a VM context and issuing concurrent map/unmap ioctls; no victim action is involved.\nS:U - The corruption stays within the kernel\u0027s own security authority on the affected host; no VM, IOMMU or sandbox boundary is crossed by the flaw itself.\nC:H - The unlocked map path frees drm_gpuva objects via pvr_vm_gpuva_remap()/pvr_vm_gpuva_unmap() while a concurrent find returns them, yielding a use-after-free whose reclaimed contents the attacker can groom to read kernel memory; racing MMU updates can also leave GPU page tables mapping unintended pages.\nI:H - The same use-after-free plus unsynchronized rb interval-tree insert/remove gives attacker-influenced writes through a freed/corrupted structure, and the racing pvr_mmu_map/unmap operations can corrupt GPU page tables, which is leveragable into arbitrary memory modification.\nA:H - The reported failure is an immediate kernel NULL pointer dereference in drm_gpuva_find(), and tree corruption or use-after-free reliably produces oopses, and the ioctl can be re-issued to crash the system at will."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:01:52.352Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/1f1f2618e44b21a7d4eb30d3bbd7e015ffbbbadf"
},
{
"url": "https://git.kernel.org/stable/c/6253bb56bb2ebdf317d8b599ce737a2510cc2e17"
},
{
"url": "https://git.kernel.org/stable/c/15f58d44c24477a6ebffa44ec05207b81cfa55d9"
},
{
"url": "https://git.kernel.org/stable/c/17e2030f37600994440f875dc410615d5c66ee6d"
}
],
"title": "drm/imagination: acquire vm_ctx-\u003elock before mapping memory to GPU VM",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68260",
"datePublished": "2026-08-10T12:01:34.414Z",
"dateReserved": "2026-07-30T09:28:09.378Z",
"dateUpdated": "2026-08-17T05:01:52.352Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68112 (GCVE-0-2026-68112)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-18 06:55
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu/gfx9.4.3: replace BUG_ON() with WARN_ON()
There's no need to crash the kernel for these cases.
(cherry picked from commit 5676593d08998d7a6d9e2d51d6b54b3820e3755c)
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/gfx_v9_4_3.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c59b57c2e0c8cced4350ff7792361ba2a79ee85c",
"status": "affected",
"version": "b1023571479020e9e9c15a51b43bf8e15406952b",
"versionType": "git"
},
{
"lessThan": "cfb02825277526bd216b56be555a97a9e8612682",
"status": "affected",
"version": "b1023571479020e9e9c15a51b43bf8e15406952b",
"versionType": "git"
},
{
"lessThan": "05aea3344c422fe95299bb1b21a04de30c7ea198",
"status": "affected",
"version": "b1023571479020e9e9c15a51b43bf8e15406952b",
"versionType": "git"
},
{
"lessThan": "ac89ea915e8b848c7cbe97b1aad2dc4f5770c6d7",
"status": "affected",
"version": "b1023571479020e9e9c15a51b43bf8e15406952b",
"versionType": "git"
},
{
"lessThan": "00f4050f7c367d7bdce347ca279ce467c434cf15",
"status": "affected",
"version": "b1023571479020e9e9c15a51b43bf8e15406952b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/gfx_v9_4_3.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.12"
},
{
"lessThan": "4.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/gfx9.4.3: replace BUG_ON() with WARN_ON()\n\nThere\u0027s no need to crash the kernel for these cases.\n\n(cherry picked from commit 5676593d08998d7a6d9e2d51d6b54b3820e3755c)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-18T06:55:36.971Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c59b57c2e0c8cced4350ff7792361ba2a79ee85c"
},
{
"url": "https://git.kernel.org/stable/c/cfb02825277526bd216b56be555a97a9e8612682"
},
{
"url": "https://git.kernel.org/stable/c/05aea3344c422fe95299bb1b21a04de30c7ea198"
},
{
"url": "https://git.kernel.org/stable/c/ac89ea915e8b848c7cbe97b1aad2dc4f5770c6d7"
},
{
"url": "https://git.kernel.org/stable/c/00f4050f7c367d7bdce347ca279ce467c434cf15"
}
],
"title": "drm/amdgpu/gfx9.4.3: replace BUG_ON() with WARN_ON()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68112",
"datePublished": "2026-08-10T11:58:29.670Z",
"dateReserved": "2026-07-30T09:28:09.369Z",
"dateUpdated": "2026-08-18T06:55:36.971Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72299 (GCVE-0-2026-72299)
Vulnerability from cvelistv5
Published
2026-08-15 05:55
Modified
2026-08-23 12:47
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
tipc: restrict socket queue dumps in enqueue tracepoints
tipc_sk_enqueue() runs with sk->sk_lock.slock held while the socket is
owned by user context. The spinlock protects the backlog queue in this
path, but it does not serialize against the socket owner consuming or
purging sk_receive_queue.
KASAN reported:
CPU: 14 UID: 0 PID: 1050 Comm: tipc3 Not tainted 7.1.0-rc6+ #126 PREEMPT(lazy)
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014
Call Trace:
<TASK>
dump_stack_lvl+0x76/0xa0 lib/dump_stack.c:123
print_report+0xce/0x5b0 mm/kasan/report.c:482
kasan_report+0xc6/0x100 mm/kasan/report.c:597
__asan_report_load4_noabort+0x14/0x30 mm/kasan/report_generic.c:380
tipc_skb_dump+0x1327/0x16f0 net/tipc/trace.c:73
tipc_list_dump+0x208/0x2e0 net/tipc/trace.c:187
tipc_sk_dump+0xaf6/0xd60 net/tipc/socket.c:3996
trace_event_raw_event_tipc_sk_class+0x312/0x5a0 net/tipc/trace.h:188
tipc_sk_rcv+0xb1d/0x1d50 net/tipc/socket.c:2497
tipc_node_xmit+0x1c3/0x1440 net/tipc/node.c:1689
__tipc_sendmsg+0x97a/0x1440 net/tipc/socket.c:1512
tipc_sendmsg+0x52/0x80 net/tipc/socket.c:1400
sock_sendmsg+0x2f6/0x3e0 net/socket.c:825
splice_to_socket+0x7f9/0x1010 fs/splice.c:884
do_splice+0xe21/0x2330 fs/splice.c:936
__do_splice+0x153/0x260 fs/splice.c:1431
__x64_sys_splice+0x150/0x230 fs/splice.c:1616
x64_sys_call+0xeb5/0x2790 arch/x86/entry/syscall_64.c:41
do_syscall_64+0xf3/0x620 arch/x86/entry/syscall_64.c:63
entry_SYSCALL_64_after_hwframe+0x76/0x7e arch/x86/entry/entry_64.S:130
RIP: 0033:0x71624e8aafe2
Code: 08 0f 85 71 3a ff ff 49 89 fb 48 89 f0 48 89 d7 48 89 ce 4c 89 c2 4d 89 ca 4c 8b 44 24 08 4c 8b 4c 24 10 4c 89 5c 24 08 0f 05 <c3> 66 2e 0f 1f 84 00 00 00 00 00 66 2e 0f 1f 84 00 00 00 00 00 66
RSP: 002b:0000716157ffed68 EFLAGS: 00000246 ORIG_RAX: 0000000000000113
RAX: ffffffffffffffda RBX: 0000716157fff6c0 RCX: 000071624e8aafe2
RDX: 000000000000005f RSI: 0000000000000000 RDI: 0000000000000066
RBP: 0000716157ffed90 R08: 0000000000008000 R09: 0000000000000001
R10: 0000000000000000 R11: 0000000000000246 R12: ffffffffffffff00
R13: 0000000000000021 R14: 0000000000000000 R15: 00007fff89799c40
</TASK>
The TIPC_DUMP_ALL tracepoints in tipc_sk_enqueue() also dump
sk_receive_queue and can therefore dereference skbs that the socket
owner has already dequeued or freed. Restrict these dumps to
TIPC_DUMP_SK_BKLGQ, which matches the queue protected by the held
spinlock.
Keep the change limited to the enqueue path, where the unsafe queue dump
is reachable while the socket is owned by user context.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 01e661ebfbad40e6280fb8ec25f2861d39ba4387 Version: 01e661ebfbad40e6280fb8ec25f2861d39ba4387 Version: 01e661ebfbad40e6280fb8ec25f2861d39ba4387 Version: 01e661ebfbad40e6280fb8ec25f2861d39ba4387 Version: 01e661ebfbad40e6280fb8ec25f2861d39ba4387 Version: 01e661ebfbad40e6280fb8ec25f2861d39ba4387 Version: 01e661ebfbad40e6280fb8ec25f2861d39ba4387 Version: 01e661ebfbad40e6280fb8ec25f2861d39ba4387 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/tipc/socket.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ae5d0d9ce767b20a5580bb6dc5e06f3e1b8a0fb0",
"status": "affected",
"version": "01e661ebfbad40e6280fb8ec25f2861d39ba4387",
"versionType": "git"
},
{
"lessThan": "273ff83c49b82e4267373adbe629e6ee8aeaa16c",
"status": "affected",
"version": "01e661ebfbad40e6280fb8ec25f2861d39ba4387",
"versionType": "git"
},
{
"lessThan": "258fb15b30db4f3941ab335d5e02f744baf1da54",
"status": "affected",
"version": "01e661ebfbad40e6280fb8ec25f2861d39ba4387",
"versionType": "git"
},
{
"lessThan": "12876864f9de5fa6f611a30c6c17e405a773bf0a",
"status": "affected",
"version": "01e661ebfbad40e6280fb8ec25f2861d39ba4387",
"versionType": "git"
},
{
"lessThan": "b9e100815f4b55e9ccaf6af9a3aba173eb13d381",
"status": "affected",
"version": "01e661ebfbad40e6280fb8ec25f2861d39ba4387",
"versionType": "git"
},
{
"lessThan": "61a55fa24a5d737436018764a647fe5b6cb36371",
"status": "affected",
"version": "01e661ebfbad40e6280fb8ec25f2861d39ba4387",
"versionType": "git"
},
{
"lessThan": "6acbbe54215d5f4251593000cff2bf51d6748713",
"status": "affected",
"version": "01e661ebfbad40e6280fb8ec25f2861d39ba4387",
"versionType": "git"
},
{
"lessThan": "acd7df8d955480a6f6e5bb809da67b1500cc3cf4",
"status": "affected",
"version": "01e661ebfbad40e6280fb8ec25f2861d39ba4387",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/tipc/socket.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.0"
},
{
"lessThan": "5.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: restrict socket queue dumps in enqueue tracepoints\n\ntipc_sk_enqueue() runs with sk-\u003esk_lock.slock held while the socket is\nowned by user context. The spinlock protects the backlog queue in this\npath, but it does not serialize against the socket owner consuming or\npurging sk_receive_queue.\n\nKASAN reported:\n\n CPU: 14 UID: 0 PID: 1050 Comm: tipc3 Not tainted 7.1.0-rc6+ #126 PREEMPT(lazy)\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014\n Call Trace:\n \u003cTASK\u003e\n dump_stack_lvl+0x76/0xa0 lib/dump_stack.c:123\n print_report+0xce/0x5b0 mm/kasan/report.c:482\n kasan_report+0xc6/0x100 mm/kasan/report.c:597\n __asan_report_load4_noabort+0x14/0x30 mm/kasan/report_generic.c:380\n tipc_skb_dump+0x1327/0x16f0 net/tipc/trace.c:73\n tipc_list_dump+0x208/0x2e0 net/tipc/trace.c:187\n tipc_sk_dump+0xaf6/0xd60 net/tipc/socket.c:3996\n trace_event_raw_event_tipc_sk_class+0x312/0x5a0 net/tipc/trace.h:188\n tipc_sk_rcv+0xb1d/0x1d50 net/tipc/socket.c:2497\n tipc_node_xmit+0x1c3/0x1440 net/tipc/node.c:1689\n __tipc_sendmsg+0x97a/0x1440 net/tipc/socket.c:1512\n tipc_sendmsg+0x52/0x80 net/tipc/socket.c:1400\n sock_sendmsg+0x2f6/0x3e0 net/socket.c:825\n splice_to_socket+0x7f9/0x1010 fs/splice.c:884\n do_splice+0xe21/0x2330 fs/splice.c:936\n __do_splice+0x153/0x260 fs/splice.c:1431\n __x64_sys_splice+0x150/0x230 fs/splice.c:1616\n x64_sys_call+0xeb5/0x2790 arch/x86/entry/syscall_64.c:41\n do_syscall_64+0xf3/0x620 arch/x86/entry/syscall_64.c:63\n entry_SYSCALL_64_after_hwframe+0x76/0x7e arch/x86/entry/entry_64.S:130\n RIP: 0033:0x71624e8aafe2\n Code: 08 0f 85 71 3a ff ff 49 89 fb 48 89 f0 48 89 d7 48 89 ce 4c 89 c2 4d 89 ca 4c 8b 44 24 08 4c 8b 4c 24 10 4c 89 5c 24 08 0f 05 \u003cc3\u003e 66 2e 0f 1f 84 00 00 00 00 00 66 2e 0f 1f 84 00 00 00 00 00 66\n RSP: 002b:0000716157ffed68 EFLAGS: 00000246 ORIG_RAX: 0000000000000113\n RAX: ffffffffffffffda RBX: 0000716157fff6c0 RCX: 000071624e8aafe2\n RDX: 000000000000005f RSI: 0000000000000000 RDI: 0000000000000066\n RBP: 0000716157ffed90 R08: 0000000000008000 R09: 0000000000000001\n R10: 0000000000000000 R11: 0000000000000246 R12: ffffffffffffff00\n R13: 0000000000000021 R14: 0000000000000000 R15: 00007fff89799c40\n \u003c/TASK\u003e\n\nThe TIPC_DUMP_ALL tracepoints in tipc_sk_enqueue() also dump\nsk_receive_queue and can therefore dereference skbs that the socket\nowner has already dequeued or freed. Restrict these dumps to\nTIPC_DUMP_SK_BKLGQ, which matches the queue protected by the held\nspinlock.\n\nKeep the change limited to the enqueue path, where the unsafe queue dump\nis reachable while the socket is owned by user context."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - tipc_sk_enqueue() is invoked from tipc_sk_rcv() on inbound TIPC traffic (tipc_rcv()/tipc_link_rcv() from UDP/Ethernet bearers) and on loopback xmit; a remote cluster peer can deliver packets that hit the enqueue trace path while the destination socket is user-owned.\nAC:L - This is a controllable race between enqueue-time TIPC_DUMP_ALL trace dumps of sk_receive_queue and the socket owner dequeuing/freeing those skbs; the attacker drives both sides via concurrent recvmsg/splice/sendmsg threads or by flooding TIPC messages while a receiver holds lock_sock().\nPR:N - TIPC data-plane delivery to an existing socket/port needs no authentication or victim credentials; any local user may open AF_TIPC sockets (including via user namespaces with CAP_NET_ADMIN), and default sk_filter sysctl matches all sockets once trace events are enabled.\nUI:N - Exploitation needs no victim interaction beyond normal socket/cluster I/O; the attacker controls message injection and thread timing without requiring mounts, prompts, or other deliberate user actions.\nS:U - The flaw is a kernel sk_buff use-after-free in the TIPC socket path and its impact stays within the kernel security authority; it does not by itself cross VM, IOMMU, or hypervisor isolation boundaries.\nC:H - KASAN reported __asan_report_load4 in tipc_skb_dump() reading freed skb/message fields from sk_receive_queue; this UAF read of attacker-influenced heap objects can disclose kernel memory and supports further info-leak exploitation.\nI:H - Concurrent enqueue tracing walks queue pointers while skbs are freed by the socket owner, creating a classic UAF on sk_buff slabs that can be groomed for arbitrary kernel memory corruption and privilege escalation.\nA:H - Dereferencing freed skbs during tipc_list_dump()/tipc_skb_dump() can oops or panic the kernel; UAF in the TIPC receive/enqueue path is a high-availability risk even when not fully weaponized for code execution."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:47:12.393Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ae5d0d9ce767b20a5580bb6dc5e06f3e1b8a0fb0"
},
{
"url": "https://git.kernel.org/stable/c/273ff83c49b82e4267373adbe629e6ee8aeaa16c"
},
{
"url": "https://git.kernel.org/stable/c/258fb15b30db4f3941ab335d5e02f744baf1da54"
},
{
"url": "https://git.kernel.org/stable/c/12876864f9de5fa6f611a30c6c17e405a773bf0a"
},
{
"url": "https://git.kernel.org/stable/c/b9e100815f4b55e9ccaf6af9a3aba173eb13d381"
},
{
"url": "https://git.kernel.org/stable/c/61a55fa24a5d737436018764a647fe5b6cb36371"
},
{
"url": "https://git.kernel.org/stable/c/6acbbe54215d5f4251593000cff2bf51d6748713"
},
{
"url": "https://git.kernel.org/stable/c/acd7df8d955480a6f6e5bb809da67b1500cc3cf4"
}
],
"title": "tipc: restrict socket queue dumps in enqueue tracepoints",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72299",
"datePublished": "2026-08-15T05:55:19.147Z",
"dateReserved": "2026-08-09T03:40:39.918Z",
"dateUpdated": "2026-08-23T12:47:12.393Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68317 (GCVE-0-2026-68317)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-17 05:03
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
pds_core: fix auxiliary device add/del races
Two paths add or delete the same slot (pf->vfs[vf_id].padev): a VF's
pdsc_reset_done() and the PF's devlink enable_vnet/disable_vnet handler.
They serialize on config_lock, but neither guards the slot under it
correctly.
add() registers and stores a new auxiliary device without first checking
the slot, so a second add of an already-populated slot leaks the first
device. del() makes that check outside config_lock, so two concurrent
dels can both pass it; the first clears the slot, and the second
dereferences a NULL pointer.
Check and update the slot under config_lock in both paths.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 0861fccd43b8bafb533d97308862d20b7db3a2ad Version: f41e27b746241e57d968d1d61c008322338ca258 Version: b699bdc720c0255d1bb76cecba7382c1f2107af5 Version: b699bdc720c0255d1bb76cecba7382c1f2107af5 Version: b699bdc720c0255d1bb76cecba7382c1f2107af5 Version: fec5f7af1d5f64a38f9224cd27b274d1af55a7ed Version: 6.6.90 ≤ Version: 6.12.28 ≤ Version: 6.14.6 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/amd/pds_core/auxbus.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "646b58b543f3bb1641e9123b75ff7799fe7b42f1",
"status": "affected",
"version": "0861fccd43b8bafb533d97308862d20b7db3a2ad",
"versionType": "git"
},
{
"lessThan": "ef194751fed50cf3452017b63f00142a0ab40c70",
"status": "affected",
"version": "f41e27b746241e57d968d1d61c008322338ca258",
"versionType": "git"
},
{
"lessThan": "cf0ed2ba202f5c3b300ec1bf7ff0b5d555f7d518",
"status": "affected",
"version": "b699bdc720c0255d1bb76cecba7382c1f2107af5",
"versionType": "git"
},
{
"lessThan": "bdeab32a7a91acd295d52a2d4ab1cc3f2da5e454",
"status": "affected",
"version": "b699bdc720c0255d1bb76cecba7382c1f2107af5",
"versionType": "git"
},
{
"lessThan": "bfa33cd513c7ceb93c5a4c30e5662acd73c0a916",
"status": "affected",
"version": "b699bdc720c0255d1bb76cecba7382c1f2107af5",
"versionType": "git"
},
{
"status": "affected",
"version": "fec5f7af1d5f64a38f9224cd27b274d1af55a7ed",
"versionType": "git"
},
{
"lessThan": "6.6.148",
"status": "affected",
"version": "6.6.90",
"versionType": "semver"
},
{
"lessThan": "6.12.101",
"status": "affected",
"version": "6.12.28",
"versionType": "semver"
},
{
"lessThan": "6.15",
"status": "affected",
"version": "6.14.6",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/amd/pds_core/auxbus.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.15"
},
{
"lessThan": "6.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.6.90",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.12.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.14.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\npds_core: fix auxiliary device add/del races\n\nTwo paths add or delete the same slot (pf-\u003evfs[vf_id].padev): a VF\u0027s\npdsc_reset_done() and the PF\u0027s devlink enable_vnet/disable_vnet handler.\nThey serialize on config_lock, but neither guards the slot under it\ncorrectly.\n\nadd() registers and stores a new auxiliary device without first checking\nthe slot, so a second add of an already-populated slot leaks the first\ndevice. del() makes that check outside config_lock, so two concurrent\ndels can both pass it; the first clears the slot, and the second\ndereferences a NULL pointer.\n\nCheck and update the slot under config_lock in both paths."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:03:14.295Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/646b58b543f3bb1641e9123b75ff7799fe7b42f1"
},
{
"url": "https://git.kernel.org/stable/c/ef194751fed50cf3452017b63f00142a0ab40c70"
},
{
"url": "https://git.kernel.org/stable/c/cf0ed2ba202f5c3b300ec1bf7ff0b5d555f7d518"
},
{
"url": "https://git.kernel.org/stable/c/bdeab32a7a91acd295d52a2d4ab1cc3f2da5e454"
},
{
"url": "https://git.kernel.org/stable/c/bfa33cd513c7ceb93c5a4c30e5662acd73c0a916"
}
],
"title": "pds_core: fix auxiliary device add/del races",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68317",
"datePublished": "2026-08-10T12:02:52.185Z",
"dateReserved": "2026-07-30T09:28:09.382Z",
"dateUpdated": "2026-08-17T05:03:14.295Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68272 (GCVE-0-2026-68272)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-17 05:02
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1
Add a minimum-length check for the AMDGPU_CHUNK_ID_CP_GFX_SHADOW chunk in
amdgpu_cs_pass1(), matching the gate already present for the IB, FENCE and
BO_HANDLES chunk types.
The CP_GFX_SHADOW case previously shared a bare break with the dependency
and syncobj chunk types, which do not dereference a fixed-size struct. When
userspace submits this chunk with length_dw == 0, vmemdup_array_user() is
called with size 0 and returns ZERO_SIZE_PTR, which passes the IS_ERR()
check. amdgpu_cs_p2_shadow() then dereferences chunk->kdata as a struct
drm_amdgpu_cs_chunk_cp_gfx_shadow (reading shadow->flags), faulting on the
ZERO_SIZE_PTR and causing a NULL-pointer dereference.
This is reachable by an unprivileged process in the render group. Reject
undersized chunks with -EINVAL during pass1 so the bad submission is
rejected before pass2 ever dereferences the data.
(cherry picked from commit 7f61b2eef7415eccdb40850aca0de94211948657)
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/amdgpu_cs.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "3f190956404da55560056ce20606010e18bc059c",
"status": "affected",
"version": "ac9287055ff16a092416c76a19006764e4c6a978",
"versionType": "git"
},
{
"lessThan": "2aa9ea2bd5146d237c8cc16d8737d878b0298a94",
"status": "affected",
"version": "ac9287055ff16a092416c76a19006764e4c6a978",
"versionType": "git"
},
{
"lessThan": "315d2e5741a81b0be763e80413a2677e22b7e596",
"status": "affected",
"version": "ac9287055ff16a092416c76a19006764e4c6a978",
"versionType": "git"
},
{
"lessThan": "24668ca3ec19434d7a9574bf9112f2b0614c3a4e",
"status": "affected",
"version": "ac9287055ff16a092416c76a19006764e4c6a978",
"versionType": "git"
},
{
"lessThan": "84c4c36acd5c4b2558b5069f869a165b2c655c84",
"status": "affected",
"version": "ac9287055ff16a092416c76a19006764e4c6a978",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/amdgpu_cs.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.5"
},
{
"lessThan": "6.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1\n\nAdd a minimum-length check for the AMDGPU_CHUNK_ID_CP_GFX_SHADOW chunk in\namdgpu_cs_pass1(), matching the gate already present for the IB, FENCE and\nBO_HANDLES chunk types.\n\nThe CP_GFX_SHADOW case previously shared a bare break with the dependency\nand syncobj chunk types, which do not dereference a fixed-size struct. When\nuserspace submits this chunk with length_dw == 0, vmemdup_array_user() is\ncalled with size 0 and returns ZERO_SIZE_PTR, which passes the IS_ERR()\ncheck. amdgpu_cs_p2_shadow() then dereferences chunk-\u003ekdata as a struct\ndrm_amdgpu_cs_chunk_cp_gfx_shadow (reading shadow-\u003eflags), faulting on the\nZERO_SIZE_PTR and causing a NULL-pointer dereference.\n\nThis is reachable by an unprivileged process in the render group. Reject\nundersized chunks with -EINVAL during pass1 so the bad submission is\nrejected before pass2 ever dereferences the data.\n\n(cherry picked from commit 7f61b2eef7415eccdb40850aca0de94211948657)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:02:05.775Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/3f190956404da55560056ce20606010e18bc059c"
},
{
"url": "https://git.kernel.org/stable/c/2aa9ea2bd5146d237c8cc16d8737d878b0298a94"
},
{
"url": "https://git.kernel.org/stable/c/315d2e5741a81b0be763e80413a2677e22b7e596"
},
{
"url": "https://git.kernel.org/stable/c/24668ca3ec19434d7a9574bf9112f2b0614c3a4e"
},
{
"url": "https://git.kernel.org/stable/c/84c4c36acd5c4b2558b5069f869a165b2c655c84"
}
],
"title": "drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68272",
"datePublished": "2026-08-10T12:01:47.708Z",
"dateReserved": "2026-07-30T09:28:09.378Z",
"dateUpdated": "2026-08-17T05:02:05.775Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64567 (GCVE-0-2026-64567)
Vulnerability from cvelistv5
Published
2026-08-05 08:08
Modified
2026-08-19 16:28
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
btrfs: reject free space cache with more entries than pages
When loading a v1 free space cache, __load_free_space_cache() takes
num_entries and num_bitmaps straight from the on-disk
btrfs_free_space_header. That header is stored in the tree_root under a key
with type 0, which the tree-checker has no case for, so neither count is
validated before the load trusts it.
The load loops num_entries times and maps the next page whenever the current
one runs out, going through io_ctl_check_crc() -> io_ctl_map_page(), which
does io_ctl->pages[io_ctl->index++]. But pages[] is allocated in
io_ctl_init() from the cache inode's i_size, not from num_entries:
num_pages = DIV_ROUND_UP(i_size_read(inode), PAGE_SIZE);
io_ctl->pages = kcalloc(num_pages, sizeof(struct page *), GFP_NOFS);
So if num_entries claims more records than the pages can hold, io_ctl->index
runs off the end of pages[]. The write side never hits this because
io_ctl_add_entry() and io_ctl_add_bitmap() both stop once
io_ctl->index >= io_ctl->num_pages; the read side just never had the same
check.
To trigger it, take a clean cache (num_entries = <N> here), set num_entries
in the header to 0x10000, and fix up the leaf checksum so it still passes
the tree-checker. The cache inode has i_size = 65536, so num_pages is 16 and
pages[] is a 16-pointer (kmalloc-128) array. The load now tries to read
65536 entries, io_ctl->index walks up to 16, and pages[16] is read past the
array:
BUG: KASAN: slab-out-of-bounds in io_ctl_check_crc (fs/btrfs/free-space-cache.c:420 fs/btrfs/free-space-cache.c:565)
Read of size 8 at addr ffff88800c833a80 by task kworker/u8:3/58
io_ctl_check_crc (fs/btrfs/free-space-cache.c:420 fs/btrfs/free-space-cache.c:565)
__load_free_space_cache (fs/btrfs/free-space-cache.c:655 fs/btrfs/free-space-cache.c:820)
load_free_space_cache (fs/btrfs/free-space-cache.c:1017)
caching_thread (fs/btrfs/block-group.c:880)
btrfs_work_helper (fs/btrfs/async-thread.c:312)
process_one_work
worker_thread
kthread
ret_from_fork
free-space-cache.c:420 is io_ctl_map_page(), inlined into io_ctl_check_crc()
at line 565, which is why that is the frame KASAN names. The out-of-bounds
slot is then treated as a struct page and handed to crc32c(), so the bad
read turns into a GP fault.
Add the missing check to io_ctl_check_crc(), which is where both the entry
loop and the bitmap loop end up. When num_entries is too large the load now
fails like any corrupt cache: __load_free_space_cache() drops it and rebuilds
the free space from the extent tree, so a valid cache is never rejected.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 5b0e95bf607ddd59b39f52d3d55e6581c817b530 Version: 5b0e95bf607ddd59b39f52d3d55e6581c817b530 Version: 5b0e95bf607ddd59b39f52d3d55e6581c817b530 Version: 5b0e95bf607ddd59b39f52d3d55e6581c817b530 Version: 5b0e95bf607ddd59b39f52d3d55e6581c817b530 Version: 5b0e95bf607ddd59b39f52d3d55e6581c817b530 Version: 5b0e95bf607ddd59b39f52d3d55e6581c817b530 Version: 5b0e95bf607ddd59b39f52d3d55e6581c817b530 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/btrfs/free-space-cache.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "8ded74c654a982dc8581a17b0caa7fcedb20de69",
"status": "affected",
"version": "5b0e95bf607ddd59b39f52d3d55e6581c817b530",
"versionType": "git"
},
{
"lessThan": "c9c38066b6446e83668c041702bb639b0ca49363",
"status": "affected",
"version": "5b0e95bf607ddd59b39f52d3d55e6581c817b530",
"versionType": "git"
},
{
"lessThan": "094734c7aaa2b36751dc32480a680a4952685e78",
"status": "affected",
"version": "5b0e95bf607ddd59b39f52d3d55e6581c817b530",
"versionType": "git"
},
{
"lessThan": "33878ba25e2638bc0c61623d7a05c9ca2b74c039",
"status": "affected",
"version": "5b0e95bf607ddd59b39f52d3d55e6581c817b530",
"versionType": "git"
},
{
"lessThan": "404a0b986e0b6e79738fdf1f0ebbbc43b9acd2a2",
"status": "affected",
"version": "5b0e95bf607ddd59b39f52d3d55e6581c817b530",
"versionType": "git"
},
{
"lessThan": "5e1b2ca6b34939e70fb0785e8222b53cf060016f",
"status": "affected",
"version": "5b0e95bf607ddd59b39f52d3d55e6581c817b530",
"versionType": "git"
},
{
"lessThan": "f9fef131fa3f59b857217f522fa5ea430d1b707c",
"status": "affected",
"version": "5b0e95bf607ddd59b39f52d3d55e6581c817b530",
"versionType": "git"
},
{
"lessThan": "a2d8d5647ed854e38f941741aea45b9eb15a6350",
"status": "affected",
"version": "5b0e95bf607ddd59b39f52d3d55e6581c817b530",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/btrfs/free-space-cache.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.2"
},
{
"lessThan": "3.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: reject free space cache with more entries than pages\n\nWhen loading a v1 free space cache, __load_free_space_cache() takes\nnum_entries and num_bitmaps straight from the on-disk\nbtrfs_free_space_header. That header is stored in the tree_root under a key\nwith type 0, which the tree-checker has no case for, so neither count is\nvalidated before the load trusts it.\n\nThe load loops num_entries times and maps the next page whenever the current\none runs out, going through io_ctl_check_crc() -\u003e io_ctl_map_page(), which\ndoes io_ctl-\u003epages[io_ctl-\u003eindex++]. But pages[] is allocated in\nio_ctl_init() from the cache inode\u0027s i_size, not from num_entries:\n\n\tnum_pages = DIV_ROUND_UP(i_size_read(inode), PAGE_SIZE);\n\tio_ctl-\u003epages = kcalloc(num_pages, sizeof(struct page *), GFP_NOFS);\n\nSo if num_entries claims more records than the pages can hold, io_ctl-\u003eindex\nruns off the end of pages[]. The write side never hits this because\nio_ctl_add_entry() and io_ctl_add_bitmap() both stop once\nio_ctl-\u003eindex \u003e= io_ctl-\u003enum_pages; the read side just never had the same\ncheck.\n\nTo trigger it, take a clean cache (num_entries = \u003cN\u003e here), set num_entries\nin the header to 0x10000, and fix up the leaf checksum so it still passes\nthe tree-checker. The cache inode has i_size = 65536, so num_pages is 16 and\npages[] is a 16-pointer (kmalloc-128) array. The load now tries to read\n65536 entries, io_ctl-\u003eindex walks up to 16, and pages[16] is read past the\narray:\n\n BUG: KASAN: slab-out-of-bounds in io_ctl_check_crc (fs/btrfs/free-space-cache.c:420 fs/btrfs/free-space-cache.c:565)\n Read of size 8 at addr ffff88800c833a80 by task kworker/u8:3/58\n io_ctl_check_crc (fs/btrfs/free-space-cache.c:420 fs/btrfs/free-space-cache.c:565)\n __load_free_space_cache (fs/btrfs/free-space-cache.c:655 fs/btrfs/free-space-cache.c:820)\n load_free_space_cache (fs/btrfs/free-space-cache.c:1017)\n caching_thread (fs/btrfs/block-group.c:880)\n btrfs_work_helper (fs/btrfs/async-thread.c:312)\n process_one_work\n worker_thread\n kthread\n ret_from_fork\n\nfree-space-cache.c:420 is io_ctl_map_page(), inlined into io_ctl_check_crc()\nat line 565, which is why that is the frame KASAN names. The out-of-bounds\nslot is then treated as a struct page and handed to crc32c(), so the bad\nread turns into a GP fault.\n\nAdd the missing check to io_ctl_check_crc(), which is where both the entry\nloop and the bitmap loop end up. When num_entries is too large the load now\nfails like any corrupt cache: __load_free_space_cache() drops it and rebuilds\nthe free space from the extent tree, so a valid cache is never rejected."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached only by mounting a crafted btrfs image so caching_thread \u2192 load_free_space_cache \u2192 __load_free_space_cache runs; there is no network or adjacent protocol path into v1 free-space cache loading.\nAC:L - The attacker authors a v1 cache with inflated num_entries (and a matching leaf checksum); cache_generation auto-enables SPACE_CACHE on mount, and the OOB in io_ctl_check_crc/io_ctl_map_page is deterministic with no race or uncontrolled condition.\nPR:L - btrfs lacks FS_USERNS_MOUNT, but an unprivileged local user can loop-setup and mount a crafted image via udisks2/polkit on typical desktops/kiosks; real init-namespace root is not required.\nUI:N - In the loop/udisks mount scenario the attacker mounts the image themselves; no separate victim must open a file, click through a prompt, or otherwise interact.\nS:U - The slab OOB and resulting kernel memory misuse stay inside the host kernel\u0027s authority; no VM escape, IOMMU bypass, or sandbox boundary is crossed.\nC:H - An out-of-bounds pages[] read yields a forged struct page pointer that is passed to page_address/crc32c and then used as the source for further cache parsing, giving an arbitrary kernel-memory read primitive once adjacent slab contents are groomed.\nI:H - The forged page pointer continues into entry/bitmap load paths (including copy_page into kernel bitmaps and linking attacker-controlled free-space records), a memory-corruption primitive exploitable for arbitrary write and control-flow hijack.\nA:H - Without a valid page pointer the OOB dereference reliably faults (KASAN slab-OOB then GP fault on crc32c as in the report), crashing or oopsing the kernel."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:28:41.793Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/8ded74c654a982dc8581a17b0caa7fcedb20de69"
},
{
"url": "https://git.kernel.org/stable/c/c9c38066b6446e83668c041702bb639b0ca49363"
},
{
"url": "https://git.kernel.org/stable/c/094734c7aaa2b36751dc32480a680a4952685e78"
},
{
"url": "https://git.kernel.org/stable/c/33878ba25e2638bc0c61623d7a05c9ca2b74c039"
},
{
"url": "https://git.kernel.org/stable/c/404a0b986e0b6e79738fdf1f0ebbbc43b9acd2a2"
},
{
"url": "https://git.kernel.org/stable/c/5e1b2ca6b34939e70fb0785e8222b53cf060016f"
},
{
"url": "https://git.kernel.org/stable/c/f9fef131fa3f59b857217f522fa5ea430d1b707c"
},
{
"url": "https://git.kernel.org/stable/c/a2d8d5647ed854e38f941741aea45b9eb15a6350"
}
],
"title": "btrfs: reject free space cache with more entries than pages",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64567",
"datePublished": "2026-08-05T08:08:06.015Z",
"dateReserved": "2026-07-19T15:36:31.797Z",
"dateUpdated": "2026-08-19T16:28:41.793Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68308 (GCVE-0-2026-68308)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-17 05:03
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: mt76: mt7996: check pointer returned by mt76_connac_get_he_phy_cap()
mt76_connac_get_he_phy_cap routine can theoretically return NULL so
check cap pointer before dereferencing it.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/mediatek/mt76/mt7996/mcu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "4fd85fd2373501b7386e93a5ce4a549d7c4e64e3",
"status": "affected",
"version": "98686cd21624c75a043e96812beadddf4f6f48e5",
"versionType": "git"
},
{
"lessThan": "8b8a079e22ce9fc3c0d05b148ef67e4c6e576678",
"status": "affected",
"version": "98686cd21624c75a043e96812beadddf4f6f48e5",
"versionType": "git"
},
{
"lessThan": "d14238523ca4c6f5fcb54d1920eb2f8525a7711f",
"status": "affected",
"version": "98686cd21624c75a043e96812beadddf4f6f48e5",
"versionType": "git"
},
{
"lessThan": "8bc7167e8a86489b7cb96a69cf1fb671d6df014b",
"status": "affected",
"version": "98686cd21624c75a043e96812beadddf4f6f48e5",
"versionType": "git"
},
{
"lessThan": "e858cf6bf99880343348ff1e8c942aaff1d9d592",
"status": "affected",
"version": "98686cd21624c75a043e96812beadddf4f6f48e5",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/mediatek/mt76/mt7996/mcu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.2"
},
{
"lessThan": "6.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7996: check pointer returned by mt76_connac_get_he_phy_cap()\n\nmt76_connac_get_he_phy_cap routine can theoretically return NULL so\ncheck cap pointer before dereferencing it."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:03:00.803Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/4fd85fd2373501b7386e93a5ce4a549d7c4e64e3"
},
{
"url": "https://git.kernel.org/stable/c/8b8a079e22ce9fc3c0d05b148ef67e4c6e576678"
},
{
"url": "https://git.kernel.org/stable/c/d14238523ca4c6f5fcb54d1920eb2f8525a7711f"
},
{
"url": "https://git.kernel.org/stable/c/8bc7167e8a86489b7cb96a69cf1fb671d6df014b"
},
{
"url": "https://git.kernel.org/stable/c/e858cf6bf99880343348ff1e8c942aaff1d9d592"
}
],
"title": "wifi: mt76: mt7996: check pointer returned by mt76_connac_get_he_phy_cap()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68308",
"datePublished": "2026-08-10T12:02:42.934Z",
"dateReserved": "2026-07-30T09:28:09.381Z",
"dateUpdated": "2026-08-17T05:03:00.803Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68154 (GCVE-0-2026-68154)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
libceph: reject zero bucket types in crush_decode
CRUSH bucket type 0 is reserved for devices. The mapper relies on
that invariant and uses type 0 to identify leaf devices.
If crush_decode() accepts a bucket with type 0, a malformed CRUSH map
can make the mapper treat a negative bucket ID as a device and pass it
to is_out(), which then indexes the OSD weight array with a negative
value.
Reject zero bucket types while decoding the CRUSH map so the invalid
state never reaches the mapper.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: f24e9980eb860d8600cbe5ef3d2fd9295320d229 Version: f24e9980eb860d8600cbe5ef3d2fd9295320d229 Version: f24e9980eb860d8600cbe5ef3d2fd9295320d229 Version: f24e9980eb860d8600cbe5ef3d2fd9295320d229 Version: f24e9980eb860d8600cbe5ef3d2fd9295320d229 Version: f24e9980eb860d8600cbe5ef3d2fd9295320d229 Version: f24e9980eb860d8600cbe5ef3d2fd9295320d229 Version: f24e9980eb860d8600cbe5ef3d2fd9295320d229 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ceph/osdmap.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "952ca5dc99913d169263f59fd689f586729a13c1",
"status": "affected",
"version": "f24e9980eb860d8600cbe5ef3d2fd9295320d229",
"versionType": "git"
},
{
"lessThan": "146461f09565afe3665e65b0423d3d6b0fe806c5",
"status": "affected",
"version": "f24e9980eb860d8600cbe5ef3d2fd9295320d229",
"versionType": "git"
},
{
"lessThan": "80fc40e11cda1b5d990a3f69c6efa344fb5cd987",
"status": "affected",
"version": "f24e9980eb860d8600cbe5ef3d2fd9295320d229",
"versionType": "git"
},
{
"lessThan": "b8a9fb6bf806f9c4891e71ae1beab0c07c23a877",
"status": "affected",
"version": "f24e9980eb860d8600cbe5ef3d2fd9295320d229",
"versionType": "git"
},
{
"lessThan": "826cd1de5802fd392922785f9b64d76e65d2a100",
"status": "affected",
"version": "f24e9980eb860d8600cbe5ef3d2fd9295320d229",
"versionType": "git"
},
{
"lessThan": "3b2f1937f5fce8b7dd5432e7693e3cc8b5eece56",
"status": "affected",
"version": "f24e9980eb860d8600cbe5ef3d2fd9295320d229",
"versionType": "git"
},
{
"lessThan": "70998f91030ee083ecb336a1dff0701c20a38081",
"status": "affected",
"version": "f24e9980eb860d8600cbe5ef3d2fd9295320d229",
"versionType": "git"
},
{
"lessThan": "05f90284223381005d6bcddab3fda4a97f9c3401",
"status": "affected",
"version": "f24e9980eb860d8600cbe5ef3d2fd9295320d229",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ceph/osdmap.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.34"
},
{
"lessThan": "2.6.34",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.34",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: reject zero bucket types in crush_decode\n\nCRUSH bucket type 0 is reserved for devices. The mapper relies on\nthat invariant and uses type 0 to identify leaf devices.\n\nIf crush_decode() accepts a bucket with type 0, a malformed CRUSH map\ncan make the mapper treat a negative bucket ID as a device and pass it\nto is_out(), which then indexes the OSD weight array with a negative\nvalue.\n\nReject zero bucket types while decoding the CRUSH map so the invalid\nstate never reaches the mapper."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The flaw is reached when the in-kernel Ceph client decodes a crafted CRUSH map inside CEPH_MSG_OSD_MAP received over TCP from a Ceph monitor or OSD, which is a standard network-delivered cluster control message on connected storage clients.\nAC:L - An attacker can reliably craft a CRUSH map with a bucket whose type field is zero and controlled hierarchy/items so crush_do_rule() later calls is_out() with a negative index, without races, victim-specific memory layout, or rare kernel build options.\nPR:N - No local privileges on the victim host are required; a remote attacker who controls, compromises, or MITMs the authenticated Ceph monitor/OSD peer can deliver the malicious OSD map over the established client cluster connection.\nUI:N - No additional victim action is needed at exploit time because poisoned OSD maps are processed automatically and CRUSH placement is recalculated during routine map updates, request rescanning, and normal Ceph client I/O.\nS:U - The vulnerability corrupts or reads kernel memory on the host running the Ceph client, affecting that kernel security domain rather than crossing a VM, container sandbox, or IOMMU boundary.\nC:H - When a type-0 bucket makes the mapper treat a negative bucket ID as a device, is_out() indexes osd_weight[] with a negative value, causing an out-of-bounds read of adjacent kernel memory beyond the OSD weight array.\nI:H - This out-of-bounds kernel heap access during CRUSH placement is memory corruption in a privileged parser/mapper path that can be leveraged for further kernel memory control and arbitrary code execution, not only information disclosure.\nA:H - The invalid negative indexing during CRUSH mapping can dereference unmapped or non-resident memory and trigger a kernel oops or panic, causing complete loss of availability on affected Ceph client hosts."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:30:20.481Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/952ca5dc99913d169263f59fd689f586729a13c1"
},
{
"url": "https://git.kernel.org/stable/c/146461f09565afe3665e65b0423d3d6b0fe806c5"
},
{
"url": "https://git.kernel.org/stable/c/80fc40e11cda1b5d990a3f69c6efa344fb5cd987"
},
{
"url": "https://git.kernel.org/stable/c/b8a9fb6bf806f9c4891e71ae1beab0c07c23a877"
},
{
"url": "https://git.kernel.org/stable/c/826cd1de5802fd392922785f9b64d76e65d2a100"
},
{
"url": "https://git.kernel.org/stable/c/3b2f1937f5fce8b7dd5432e7693e3cc8b5eece56"
},
{
"url": "https://git.kernel.org/stable/c/70998f91030ee083ecb336a1dff0701c20a38081"
},
{
"url": "https://git.kernel.org/stable/c/05f90284223381005d6bcddab3fda4a97f9c3401"
}
],
"title": "libceph: reject zero bucket types in crush_decode",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68154",
"datePublished": "2026-08-10T11:59:20.250Z",
"dateReserved": "2026-07-30T09:28:09.371Z",
"dateUpdated": "2026-08-19T16:30:20.481Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68245 (GCVE-0-2026-68245)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-18 06:55
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: fix lifetime issue of amdgpu_vm_get_task_info_pasid()
The vm pointer returned from amdgpu_vm_get_vm_from_pasid() is only
valid while the lock is still being held. Once xa_unlock_irqrestore is
called and returned, the pointer is no longer under lock and is subject
to modification. Since, the caller still dereferences vm->task_info in
amdgpu_vm_get_task_info_vm() after the lock is removed, this causes a
use after unlock problem.
Remove the lifetime issue present in amdgpu_vm_get_task_info_pasid()
through removing the amdgpu_vm_get_vm_from_pasid() function from
amdgpu_vm.c and making the relevant code inline to hold the lock while
it is still in use.
(cherry picked from commit 9d01579f3f868b333acc901815972685989092c7)
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/amdgpu_vm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "fe16a7e5336ae888751984e30c451fbf7cfa5df7",
"status": "affected",
"version": "b8f67b9ddf4f8fe6dd536590712b5912ad78f99c",
"versionType": "git"
},
{
"lessThan": "1173190412fb9d12e7efce76734118d9712ff970",
"status": "affected",
"version": "b8f67b9ddf4f8fe6dd536590712b5912ad78f99c",
"versionType": "git"
},
{
"lessThan": "5d5fb9124a2bba96a7807086d8fe0f7ce810d546",
"status": "affected",
"version": "b8f67b9ddf4f8fe6dd536590712b5912ad78f99c",
"versionType": "git"
},
{
"lessThan": "04cc4aa3617b0ed67e859f91f09de5d896a46f3a",
"status": "affected",
"version": "b8f67b9ddf4f8fe6dd536590712b5912ad78f99c",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/amdgpu_vm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.9"
},
{
"lessThan": "6.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: fix lifetime issue of amdgpu_vm_get_task_info_pasid()\n\nThe vm pointer returned from amdgpu_vm_get_vm_from_pasid() is only\nvalid while the lock is still being held. Once xa_unlock_irqrestore is\ncalled and returned, the pointer is no longer under lock and is subject\nto modification. Since, the caller still dereferences vm-\u003etask_info in\namdgpu_vm_get_task_info_vm() after the lock is removed, this causes a\nuse after unlock problem.\n\nRemove the lifetime issue present in amdgpu_vm_get_task_info_pasid()\nthrough removing the amdgpu_vm_get_vm_from_pasid() function from\namdgpu_vm.c and making the relevant code inline to hold the lock while\nit is still in use.\n\n(cherry picked from commit 9d01579f3f868b333acc901815972685989092c7)"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable code is reached through the amdgpu DRM device (render node) via command submission causing a GPU VM page fault or a ring timeout; this requires local access to /dev/dri/renderD*, with no network exposure.\nAC:L - The attacker controls both sides of the race: it can generate GPU page faults or job timeouts at will while concurrently closing DRM file descriptors to free the amdgpu_vm/fpriv, and can retry the race arbitrarily many times until it wins.\nPR:L - Only an unprivileged local account with access to the AMD GPU render node is needed; render nodes are world/group accessible by default on desktop, Android and container workloads, and no capability is checked on the CS/fault path.\nUI:N - The attacker\u0027s own processes generate the GPU faults and the concurrent VM teardown; no action by any other user is required.\nS:U - The corruption stays within the kernel\u0027s own security authority \u2014 the freed amdgpu_vm/amdgpu_task_info are kernel heap objects, with no crossing of a VM or IOMMU boundary.\nC:H - The stale vm pointer is dereferenced after free, reading vm-\u003etask_info out of reallocated kernel heap memory, and the resulting task_info contents (process name, pid, tgid) are then printed/exported, allowing disclosure of attacker-groomed or unrelated kernel data.\nI:H - kref_get() is performed on memory that may already be freed and reallocated, writing an increment into another object\u0027s fields, and the paired kref_put() can drop a foreign refcount to zero \u2014 a classic use-after-free/refcount-corruption primitive leveraged for arbitrary write and privilege escalation.\nA:H - The use-after-free occurs in a GPU interrupt handler and the reset/timeout path; dereferencing freed memory or corrupting a reused slab object readily oopses or panics the kernel, and it can be retriggered repeatedly."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-18T06:55:46.886Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/fe16a7e5336ae888751984e30c451fbf7cfa5df7"
},
{
"url": "https://git.kernel.org/stable/c/1173190412fb9d12e7efce76734118d9712ff970"
},
{
"url": "https://git.kernel.org/stable/c/5d5fb9124a2bba96a7807086d8fe0f7ce810d546"
},
{
"url": "https://git.kernel.org/stable/c/04cc4aa3617b0ed67e859f91f09de5d896a46f3a"
}
],
"title": "drm/amdgpu: fix lifetime issue of amdgpu_vm_get_task_info_pasid()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68245",
"datePublished": "2026-08-10T12:01:11.501Z",
"dateReserved": "2026-07-30T09:28:09.377Z",
"dateUpdated": "2026-08-18T06:55:46.886Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72305 (GCVE-0-2026-72305)
Vulnerability from cvelistv5
Published
2026-08-15 05:55
Modified
2026-08-23 12:47
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
VDUSE: avoid leaking information to userspace
The bounceing is not necessarily page aligned, so current VDUSE can
leak kernel information through mapping bounce pages to
userspace. Allocate bounce pages with __GFP_ZERO to avoid leaking
information to userspace.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 8c773d53fb7b64267b0f55c1d3517cb8c5e29b3c Version: 8c773d53fb7b64267b0f55c1d3517cb8c5e29b3c Version: 8c773d53fb7b64267b0f55c1d3517cb8c5e29b3c Version: 8c773d53fb7b64267b0f55c1d3517cb8c5e29b3c Version: 8c773d53fb7b64267b0f55c1d3517cb8c5e29b3c Version: 8c773d53fb7b64267b0f55c1d3517cb8c5e29b3c Version: 8c773d53fb7b64267b0f55c1d3517cb8c5e29b3c |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/vdpa/vdpa_user/iova_domain.c",
"drivers/vdpa/vdpa_user/vduse_dev.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "41e27a6aca608c9e04f091c29c420d03fafe0313",
"status": "affected",
"version": "8c773d53fb7b64267b0f55c1d3517cb8c5e29b3c",
"versionType": "git"
},
{
"lessThan": "3ae878f262bd1445c8c31511856a99962a05fe16",
"status": "affected",
"version": "8c773d53fb7b64267b0f55c1d3517cb8c5e29b3c",
"versionType": "git"
},
{
"lessThan": "fde25641cbddd0c084e3320d08f755e7e6acfae5",
"status": "affected",
"version": "8c773d53fb7b64267b0f55c1d3517cb8c5e29b3c",
"versionType": "git"
},
{
"lessThan": "5e88c1bc3a41d9a260dd42bae8ad18fd4f35bbe1",
"status": "affected",
"version": "8c773d53fb7b64267b0f55c1d3517cb8c5e29b3c",
"versionType": "git"
},
{
"lessThan": "690fb82c4122f8c2656fa4f842275132771b68b9",
"status": "affected",
"version": "8c773d53fb7b64267b0f55c1d3517cb8c5e29b3c",
"versionType": "git"
},
{
"lessThan": "00335df9da2011e095f846d645cc2e9fd2907659",
"status": "affected",
"version": "8c773d53fb7b64267b0f55c1d3517cb8c5e29b3c",
"versionType": "git"
},
{
"lessThan": "9c1523803445ee0348f62b77793266dd981596e0",
"status": "affected",
"version": "8c773d53fb7b64267b0f55c1d3517cb8c5e29b3c",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/vdpa/vdpa_user/iova_domain.c",
"drivers/vdpa/vdpa_user/vduse_dev.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.15"
},
{
"lessThan": "5.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nVDUSE: avoid leaking information to userspace\n\nThe bounceing is not necessarily page aligned, so current VDUSE can\nleak kernel information through mapping bounce pages to\nuserspace. Allocate bounce pages with __GFP_ZERO to avoid leaking\ninformation to userspace."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:47:13.473Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/41e27a6aca608c9e04f091c29c420d03fafe0313"
},
{
"url": "https://git.kernel.org/stable/c/3ae878f262bd1445c8c31511856a99962a05fe16"
},
{
"url": "https://git.kernel.org/stable/c/fde25641cbddd0c084e3320d08f755e7e6acfae5"
},
{
"url": "https://git.kernel.org/stable/c/5e88c1bc3a41d9a260dd42bae8ad18fd4f35bbe1"
},
{
"url": "https://git.kernel.org/stable/c/690fb82c4122f8c2656fa4f842275132771b68b9"
},
{
"url": "https://git.kernel.org/stable/c/00335df9da2011e095f846d645cc2e9fd2907659"
},
{
"url": "https://git.kernel.org/stable/c/9c1523803445ee0348f62b77793266dd981596e0"
}
],
"title": "VDUSE: avoid leaking information to userspace",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72305",
"datePublished": "2026-08-15T05:55:22.914Z",
"dateReserved": "2026-08-09T03:40:39.918Z",
"dateUpdated": "2026-08-23T12:47:13.473Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68209 (GCVE-0-2026-68209)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: sun4i-csi: Return queued buffers on start_streaming() failure
The vb2 framework hands buffers to the driver via buf_queue() before
calling start_streaming(). If start_streaming() returns an error
without first returning those buffers via vb2_buffer_done(),
vb2_start_streaming() fires WARN_ON(owned_by_drv_count) and the queued
buffers leak.
sun4i_csi_start_streaming() returned -EINVAL when no matching CSI
format could be found, before any setup (scratch buffer allocation,
pipeline start) had been performed. The remaining error paths already
converge on the err_clear_dma_queue label, which calls
return_all_buffers(..., VB2_BUF_STATE_QUEUED) under csi->qlock. Jump
to that label directly: the intermediate err_disable_device /
err_disable_pipeline / err_free_scratch_buffer labels are skipped,
which is correct because nothing they would undo has happened yet.
This mirrors the uvcvideo fix in commit 4cf3b6fd54eb ("media: uvcvideo:
Return queued buffers on start_streaming() failure").
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 577bbf23b758848f0c4a50d346460b690c753024 Version: 577bbf23b758848f0c4a50d346460b690c753024 Version: 577bbf23b758848f0c4a50d346460b690c753024 Version: 577bbf23b758848f0c4a50d346460b690c753024 Version: 577bbf23b758848f0c4a50d346460b690c753024 Version: 577bbf23b758848f0c4a50d346460b690c753024 Version: 577bbf23b758848f0c4a50d346460b690c753024 Version: 577bbf23b758848f0c4a50d346460b690c753024 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/platform/sunxi/sun4i-csi/sun4i_dma.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "29fce7bcb3b959f6d4fdcdff7d26330152fdf98d",
"status": "affected",
"version": "577bbf23b758848f0c4a50d346460b690c753024",
"versionType": "git"
},
{
"lessThan": "7c2c30e282745a83d332c3cf92d1c0bcc491ac54",
"status": "affected",
"version": "577bbf23b758848f0c4a50d346460b690c753024",
"versionType": "git"
},
{
"lessThan": "3c0bd793b0083fd4639ba7f60d1e7db8c8ac459a",
"status": "affected",
"version": "577bbf23b758848f0c4a50d346460b690c753024",
"versionType": "git"
},
{
"lessThan": "4872161e6fbe4e1783daea8bff79caddfae0fb82",
"status": "affected",
"version": "577bbf23b758848f0c4a50d346460b690c753024",
"versionType": "git"
},
{
"lessThan": "a8abecc638a7feb20b78fabd563b05e30c071331",
"status": "affected",
"version": "577bbf23b758848f0c4a50d346460b690c753024",
"versionType": "git"
},
{
"lessThan": "b5184b3f0e9d4cc47059ba1138c9a73d43d2493f",
"status": "affected",
"version": "577bbf23b758848f0c4a50d346460b690c753024",
"versionType": "git"
},
{
"lessThan": "668face37fdb6b6900645dc8777195498541c9a7",
"status": "affected",
"version": "577bbf23b758848f0c4a50d346460b690c753024",
"versionType": "git"
},
{
"lessThan": "bbba3e260a62810a717b4442a3bb96d0ec0f6309",
"status": "affected",
"version": "577bbf23b758848f0c4a50d346460b690c753024",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/platform/sunxi/sun4i-csi/sun4i_dma.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.4"
},
{
"lessThan": "5.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: sun4i-csi: Return queued buffers on start_streaming() failure\n\nThe vb2 framework hands buffers to the driver via buf_queue() before\ncalling start_streaming(). If start_streaming() returns an error\nwithout first returning those buffers via vb2_buffer_done(),\nvb2_start_streaming() fires WARN_ON(owned_by_drv_count) and the queued\nbuffers leak.\n\nsun4i_csi_start_streaming() returned -EINVAL when no matching CSI\nformat could be found, before any setup (scratch buffer allocation,\npipeline start) had been performed. The remaining error paths already\nconverge on the err_clear_dma_queue label, which calls\nreturn_all_buffers(..., VB2_BUF_STATE_QUEUED) under csi-\u003eqlock. Jump\nto that label directly: the intermediate err_disable_device /\nerr_disable_pipeline / err_free_scratch_buffer labels are skipped,\nwhich is correct because nothing they would undo has happened yet.\n\nThis mirrors the uvcvideo fix in commit 4cf3b6fd54eb (\"media: uvcvideo:\nReturn queued buffers on start_streaming() failure\")."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable code is reached only through local V4L2 ioctls (VIDIOC_S_FMT, VIDIOC_REQBUFS, VIDIOC_QBUF, VIDIOC_STREAMON) on the sun4i-csi /dev/videoN character device. There is no network, adjacent-network, or remote data path into sun4i_csi_start_streaming().\nAC:L - The attacker deterministically drives the sequence itself: configure the capture format, queue buffers, then issue STREAMON so the driver returns an error after vb2 has already handed the buffers over. No race, timing window, or memory layout outside the attacker\u0027s control is involved, and the sequence can be retried without limit.\nPR:L - sun4i_csi_open() and the entire queue/streamon path perform no capability checks; only an open file descriptor on the video node is needed, which udev grants to the active local user via the video group and 70-uaccess.rules (or the Android CAMERA context). That is ordinary unprivileged local access, not root.\nUI:N - The attacker performs the whole open/S_FMT/QBUF/STREAMON/REQBUFS sequence inside its own process. No victim action, cooperation, or pre-existing session state is required.\nS:U - The damage is confined to kernel heap and sun4i-csi driver state within the same OS security authority. Nothing crosses a hypervisor, IOMMU, or sandbox boundary.\nC:H - Buffers stay linked on csi-\u003ebuf_list after vb2 force-reclaims them, and the list head is only initialized once at probe. A later REQBUFS(0) or close frees those vb2 buffers while the driver still holds pointers, so sun4i_csi_buffer_fill_all()/return_all_buffers() read through freed slab objects the attacker can reclaim and shape, disclosing kernel heap contents.\nI:H - The stale list linkage yields list_add_tail()/list_del() operations on freed nodes, giving a write-what-where style list-corruption primitive, and the DMA fill path writes buffer addresses through the dangling entries. Under conservative memory-corruption scoring this is high integrity impact.\nA:H - The immediate effect is the WARN_ON(owned_by_drv_count) splat in vb2_start_streaming(), which panics on panic_on_warn systems, and the resulting dangling buf_list produces use-after-free oopses or slab corruption on the next streaming attempt or buffer release."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:31.902Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/29fce7bcb3b959f6d4fdcdff7d26330152fdf98d"
},
{
"url": "https://git.kernel.org/stable/c/7c2c30e282745a83d332c3cf92d1c0bcc491ac54"
},
{
"url": "https://git.kernel.org/stable/c/3c0bd793b0083fd4639ba7f60d1e7db8c8ac459a"
},
{
"url": "https://git.kernel.org/stable/c/4872161e6fbe4e1783daea8bff79caddfae0fb82"
},
{
"url": "https://git.kernel.org/stable/c/a8abecc638a7feb20b78fabd563b05e30c071331"
},
{
"url": "https://git.kernel.org/stable/c/b5184b3f0e9d4cc47059ba1138c9a73d43d2493f"
},
{
"url": "https://git.kernel.org/stable/c/668face37fdb6b6900645dc8777195498541c9a7"
},
{
"url": "https://git.kernel.org/stable/c/bbba3e260a62810a717b4442a3bb96d0ec0f6309"
}
],
"title": "media: sun4i-csi: Return queued buffers on start_streaming() failure",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68209",
"datePublished": "2026-08-10T12:00:28.245Z",
"dateReserved": "2026-07-30T09:28:09.374Z",
"dateUpdated": "2026-08-19T16:31:31.902Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68190 (GCVE-0-2026-68190)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
staging: rtl8723bs: fix OOB reads in rtw_get_wps_ie()
rtw_get_wps_ie() iterates over IE data from network frames without
validating that the IE header and payload fit within the remaining
buffer before reading them. Specifically:
- in_ie[cnt + 1] is read without checking cnt + 1 < in_len
- memcmp(&in_ie[cnt + 2], ...) accesses cnt + 2 without bounds check
- in_ie[cnt + 1] is used as length without verifying payload fits
Add bounds checks at the top of the loop body to break early if fewer
than 2 bytes remain for the IE header, or if the declared payload
extends past the end of the buffer. Also require at least 4 bytes of
payload before comparing the WPS OUI.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/staging/rtl8723bs/core/rtw_ieee80211.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c670efe69ec8a3360bfa596436f0250a3bf15d42",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "23b630e334f7e8f76bb22a18aca350da995af905",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "b9d9a4cd2e59df7281992a076464d2536e80c674",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "630fdca3f2437fee3ffd437c4b646ccf84c7be87",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "875479f18835ac11e21a83e88f3d4dc7ccdcd0c4",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "23c31f107b4f8f420a754a45d12599bdb78f9bb8",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "0e95ff792ae0aa6fbad9455943e9e1e4062670e9",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/staging/rtl8723bs/core/rtw_ieee80211.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.12"
},
{
"lessThan": "4.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: rtl8723bs: fix OOB reads in rtw_get_wps_ie()\n\nrtw_get_wps_ie() iterates over IE data from network frames without\nvalidating that the IE header and payload fit within the remaining\nbuffer before reading them. Specifically:\n\n- in_ie[cnt + 1] is read without checking cnt + 1 \u003c in_len\n- memcmp(\u0026in_ie[cnt + 2], ...) accesses cnt + 2 without bounds check\n- in_ie[cnt + 1] is used as length without verifying payload fits\n\nAdd bounds checks at the top of the loop body to break early if fewer\nthan 2 bytes remain for the IE header, or if the declared payload\nextends past the end of the buffer. Also require at least 4 bytes of\npayload before comparing the WPS OUI."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:04.402Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c670efe69ec8a3360bfa596436f0250a3bf15d42"
},
{
"url": "https://git.kernel.org/stable/c/23b630e334f7e8f76bb22a18aca350da995af905"
},
{
"url": "https://git.kernel.org/stable/c/b9d9a4cd2e59df7281992a076464d2536e80c674"
},
{
"url": "https://git.kernel.org/stable/c/630fdca3f2437fee3ffd437c4b646ccf84c7be87"
},
{
"url": "https://git.kernel.org/stable/c/875479f18835ac11e21a83e88f3d4dc7ccdcd0c4"
},
{
"url": "https://git.kernel.org/stable/c/23c31f107b4f8f420a754a45d12599bdb78f9bb8"
},
{
"url": "https://git.kernel.org/stable/c/0e95ff792ae0aa6fbad9455943e9e1e4062670e9"
}
],
"title": "staging: rtl8723bs: fix OOB reads in rtw_get_wps_ie()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68190",
"datePublished": "2026-08-10T12:00:07.764Z",
"dateReserved": "2026-07-30T09:28:09.373Z",
"dateUpdated": "2026-08-19T16:31:04.402Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68115 (GCVE-0-2026-68115)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-19 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu/gfx10: replace BUG_ON() with WARN_ON()
There's no need to crash the kernel for these cases.
(cherry picked from commit ac6f00beb658239bced4aaed9efbb04a35348d48)
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: a644d85a5cd4efbb1eb62751ef8a98a70d9794bc Version: a644d85a5cd4efbb1eb62751ef8a98a70d9794bc Version: a644d85a5cd4efbb1eb62751ef8a98a70d9794bc Version: a644d85a5cd4efbb1eb62751ef8a98a70d9794bc Version: a644d85a5cd4efbb1eb62751ef8a98a70d9794bc Version: a644d85a5cd4efbb1eb62751ef8a98a70d9794bc Version: a644d85a5cd4efbb1eb62751ef8a98a70d9794bc Version: a644d85a5cd4efbb1eb62751ef8a98a70d9794bc |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/gfx_v10_0.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a5de4c9065db8653a3af8a1d4cf5f3c0024c480a",
"status": "affected",
"version": "a644d85a5cd4efbb1eb62751ef8a98a70d9794bc",
"versionType": "git"
},
{
"lessThan": "e994f4391b574bd57e7ac183ab93c3d60e8d4d55",
"status": "affected",
"version": "a644d85a5cd4efbb1eb62751ef8a98a70d9794bc",
"versionType": "git"
},
{
"lessThan": "5c23b018c64f9e8f28e407f313616dccd51b684f",
"status": "affected",
"version": "a644d85a5cd4efbb1eb62751ef8a98a70d9794bc",
"versionType": "git"
},
{
"lessThan": "793cdf17ddf9dc662a94cae86ce005565ef3c1c2",
"status": "affected",
"version": "a644d85a5cd4efbb1eb62751ef8a98a70d9794bc",
"versionType": "git"
},
{
"lessThan": "6c8cfdc2321c1284dc4320ac148867ea8f6419bd",
"status": "affected",
"version": "a644d85a5cd4efbb1eb62751ef8a98a70d9794bc",
"versionType": "git"
},
{
"lessThan": "7e22de67e545d0f72595514d3a66675e9d074adc",
"status": "affected",
"version": "a644d85a5cd4efbb1eb62751ef8a98a70d9794bc",
"versionType": "git"
},
{
"lessThan": "2929a932b0d70f481dbcb6994181544b07913de0",
"status": "affected",
"version": "a644d85a5cd4efbb1eb62751ef8a98a70d9794bc",
"versionType": "git"
},
{
"lessThan": "d06c4173a7c38c7a39e98859f839ce714c7af2c9",
"status": "affected",
"version": "a644d85a5cd4efbb1eb62751ef8a98a70d9794bc",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/gfx_v10_0.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.3"
},
{
"lessThan": "5.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/gfx10: replace BUG_ON() with WARN_ON()\n\nThere\u0027s no need to crash the kernel for these cases.\n\n(cherry picked from commit ac6f00beb658239bced4aaed9efbb04a35348d48)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:29:26.881Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a5de4c9065db8653a3af8a1d4cf5f3c0024c480a"
},
{
"url": "https://git.kernel.org/stable/c/e994f4391b574bd57e7ac183ab93c3d60e8d4d55"
},
{
"url": "https://git.kernel.org/stable/c/5c23b018c64f9e8f28e407f313616dccd51b684f"
},
{
"url": "https://git.kernel.org/stable/c/793cdf17ddf9dc662a94cae86ce005565ef3c1c2"
},
{
"url": "https://git.kernel.org/stable/c/6c8cfdc2321c1284dc4320ac148867ea8f6419bd"
},
{
"url": "https://git.kernel.org/stable/c/7e22de67e545d0f72595514d3a66675e9d074adc"
},
{
"url": "https://git.kernel.org/stable/c/2929a932b0d70f481dbcb6994181544b07913de0"
},
{
"url": "https://git.kernel.org/stable/c/d06c4173a7c38c7a39e98859f839ce714c7af2c9"
}
],
"title": "drm/amdgpu/gfx10: replace BUG_ON() with WARN_ON()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68115",
"datePublished": "2026-08-10T11:58:33.594Z",
"dateReserved": "2026-07-30T09:28:09.369Z",
"dateUpdated": "2026-08-19T16:29:26.881Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68278 (GCVE-0-2026-68278)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/dp/mst: fix buffer overflows in sideband chunk accumulation
drm_dp_sideband_append_payload() has three related bugs when processing
device-provided sideband reply data:
1. Zero-length curchunk_len underflow: msg_len is a 6-bit field taken
directly from the DP sideband header. If a device sends msg_len=0,
curchunk_len is set to zero. The condition (curchunk_idx >= curchunk_len)
is immediately true, and curchunk_len-1 wraps to 255 (u8 underflow).
drm_dp_msg_data_crc4() reads 255 bytes from chunk[48], then memcpy()
writes 255 bytes into msg[], both far out of bounds.
2. chunk[48] overflow: curchunk_len can reach 63 (6-bit field). chunk[] is
only 48 bytes. Multi-iteration payload assembly appends 16-byte blocks
until curchunk_idx reaches curchunk_len, writing up to 15 bytes past
the end of chunk[] into msg[].
3. msg[256] overflow: each chunk contributes (curchunk_len-1) bytes to
msg[]. No check ensures curlen + (curchunk_len-1) stays within msg[256],
so the memcpy can spill into adjacent struct fields.
All three are reachable from any DP MST device that can forge sideband
reply messages on a physical connection.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/display/drm_dp_mst_topology.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ef2ecb6cf268debf3890df99fea01b6452dcf78e",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "d4e05dedb252ed3e540a0c9be511e427f098110a",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "4d5109075a787de28c9e89940f9dee45269f91fa",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "53937a2787d29c7a460e984dc4f20ff6ac91dc65",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "ef0dbcc200c3389f1f781ab181932a97e54b51af",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "1e5827839ad0ceb0079d1560c321fa3656b54f21",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "a6366b551079c79bf7bdbadd74c97358bcfe2d58",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "55bd5e685bda455b9b50c835f8c8442d52a344a3",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/display/drm_dp_mst_topology.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.17"
},
{
"lessThan": "3.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.17",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/dp/mst: fix buffer overflows in sideband chunk accumulation\n\ndrm_dp_sideband_append_payload() has three related bugs when processing\ndevice-provided sideband reply data:\n\n1. Zero-length curchunk_len underflow: msg_len is a 6-bit field taken\n directly from the DP sideband header. If a device sends msg_len=0,\n curchunk_len is set to zero. The condition (curchunk_idx \u003e= curchunk_len)\n is immediately true, and curchunk_len-1 wraps to 255 (u8 underflow).\n drm_dp_msg_data_crc4() reads 255 bytes from chunk[48], then memcpy()\n writes 255 bytes into msg[], both far out of bounds.\n\n2. chunk[48] overflow: curchunk_len can reach 63 (6-bit field). chunk[] is\n only 48 bytes. Multi-iteration payload assembly appends 16-byte blocks\n until curchunk_idx reaches curchunk_len, writing up to 15 bytes past\n the end of chunk[] into msg[].\n\n3. msg[256] overflow: each chunk contributes (curchunk_len-1) bytes to\n msg[]. No check ensures curlen + (curchunk_len-1) stays within msg[256],\n so the memcpy can spill into adjacent struct fields.\n\nAll three are reachable from any DP MST device that can forge sideband\nreply messages on a physical connection."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:15.450Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ef2ecb6cf268debf3890df99fea01b6452dcf78e"
},
{
"url": "https://git.kernel.org/stable/c/d4e05dedb252ed3e540a0c9be511e427f098110a"
},
{
"url": "https://git.kernel.org/stable/c/4d5109075a787de28c9e89940f9dee45269f91fa"
},
{
"url": "https://git.kernel.org/stable/c/53937a2787d29c7a460e984dc4f20ff6ac91dc65"
},
{
"url": "https://git.kernel.org/stable/c/ef0dbcc200c3389f1f781ab181932a97e54b51af"
},
{
"url": "https://git.kernel.org/stable/c/1e5827839ad0ceb0079d1560c321fa3656b54f21"
},
{
"url": "https://git.kernel.org/stable/c/a6366b551079c79bf7bdbadd74c97358bcfe2d58"
},
{
"url": "https://git.kernel.org/stable/c/55bd5e685bda455b9b50c835f8c8442d52a344a3"
}
],
"title": "drm/dp/mst: fix buffer overflows in sideband chunk accumulation",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68278",
"datePublished": "2026-08-10T12:01:54.285Z",
"dateReserved": "2026-07-30T09:28:09.379Z",
"dateUpdated": "2026-08-23T12:46:15.450Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64571 (GCVE-0-2026-64571)
Vulnerability from cvelistv5
Published
2026-08-05 08:08
Modified
2026-08-19 16:28
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: p54: validate RX frame length in p54_rx_eeprom_readback()
p54_rx_eeprom_readback() copies the requested EEPROM slice out of a
device-supplied readback frame without checking that the skb actually holds
that many bytes. Commit da1b9a55ff11 ("wifi: p54: prevent buffer-overflow in
p54_rx_eeprom_readback()") closed the destination overflow by copying a
fixed priv->eeprom_slice_size (and rejecting a mismatched advertised len),
but the source side is still unbounded: nothing verifies the frame is long
enough to supply that many bytes.
A malicious USB device can send a short frame whose advertised len matches
priv->eeprom_slice_size while the payload is truncated. The equality check
passes and memcpy() reads past the end of the skb, leaking adjacent heap:
BUG: KASAN: slab-out-of-bounds in p54_rx (drivers/net/wireless/intersil/p54/txrx.c:507)
Read of size 1016 at addr ffff88800f077114 by task swapper/0/0
Call Trace:
<IRQ>
...
__asan_memcpy (mm/kasan/shadow.c:105)
p54_rx (drivers/net/wireless/intersil/p54/txrx.c:507)
p54u_rx_cb (drivers/net/wireless/intersil/p54/p54usb.c:163)
__usb_hcd_giveback_urb (drivers/usb/core/hcd.c:1657)
dummy_timer (drivers/usb/gadget/udc/dummy_hcd.c:2005)
...
</IRQ>
The buggy address belongs to the object at ffff88800f0770c0
which belongs to the cache skbuff_small_head of size 704
The buggy address is located 84 bytes inside of
allocated 704-byte region [ffff88800f0770c0, ffff88800f077380)
Check that the slice fits in the skb before copying.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 7cb770729ba895f73253dfcd46c3fcba45d896f9 Version: 7cb770729ba895f73253dfcd46c3fcba45d896f9 Version: 7cb770729ba895f73253dfcd46c3fcba45d896f9 Version: 7cb770729ba895f73253dfcd46c3fcba45d896f9 Version: 7cb770729ba895f73253dfcd46c3fcba45d896f9 Version: 7cb770729ba895f73253dfcd46c3fcba45d896f9 Version: 7cb770729ba895f73253dfcd46c3fcba45d896f9 Version: 7cb770729ba895f73253dfcd46c3fcba45d896f9 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/intersil/p54/txrx.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "7a456ffcd20bd92ad0ef46c1aaa0e39e3be1f7e7",
"status": "affected",
"version": "7cb770729ba895f73253dfcd46c3fcba45d896f9",
"versionType": "git"
},
{
"lessThan": "88f7044f92b8326fbfab26d0d8ed297c367ebb76",
"status": "affected",
"version": "7cb770729ba895f73253dfcd46c3fcba45d896f9",
"versionType": "git"
},
{
"lessThan": "f21b7e096fe5371bf697cd410537fb434a763f5e",
"status": "affected",
"version": "7cb770729ba895f73253dfcd46c3fcba45d896f9",
"versionType": "git"
},
{
"lessThan": "25c3b85af3fc4f8043159b14e65790fc3bbdaf48",
"status": "affected",
"version": "7cb770729ba895f73253dfcd46c3fcba45d896f9",
"versionType": "git"
},
{
"lessThan": "f46f8f9c43fd02f4dd5f716d4bda296a523c04f0",
"status": "affected",
"version": "7cb770729ba895f73253dfcd46c3fcba45d896f9",
"versionType": "git"
},
{
"lessThan": "d38f5d868a0a4770e3bcd0925e16c46acdbc9509",
"status": "affected",
"version": "7cb770729ba895f73253dfcd46c3fcba45d896f9",
"versionType": "git"
},
{
"lessThan": "9096e1f7014174067239a63df18ae5f28301990d",
"status": "affected",
"version": "7cb770729ba895f73253dfcd46c3fcba45d896f9",
"versionType": "git"
},
{
"lessThan": "ebd6d37fa94bee929e0b4c9ca19fdf9b1dcf6cea",
"status": "affected",
"version": "7cb770729ba895f73253dfcd46c3fcba45d896f9",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/intersil/p54/txrx.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.28"
},
{
"lessThan": "2.6.28",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.28",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: p54: validate RX frame length in p54_rx_eeprom_readback()\n\np54_rx_eeprom_readback() copies the requested EEPROM slice out of a\ndevice-supplied readback frame without checking that the skb actually holds\nthat many bytes. Commit da1b9a55ff11 (\"wifi: p54: prevent buffer-overflow in\np54_rx_eeprom_readback()\") closed the destination overflow by copying a\nfixed priv-\u003eeeprom_slice_size (and rejecting a mismatched advertised len),\nbut the source side is still unbounded: nothing verifies the frame is long\nenough to supply that many bytes.\n\nA malicious USB device can send a short frame whose advertised len matches\npriv-\u003eeeprom_slice_size while the payload is truncated. The equality check\npasses and memcpy() reads past the end of the skb, leaking adjacent heap:\n\n BUG: KASAN: slab-out-of-bounds in p54_rx (drivers/net/wireless/intersil/p54/txrx.c:507)\n Read of size 1016 at addr ffff88800f077114 by task swapper/0/0\n Call Trace:\n \u003cIRQ\u003e\n ...\n __asan_memcpy (mm/kasan/shadow.c:105)\n p54_rx (drivers/net/wireless/intersil/p54/txrx.c:507)\n p54u_rx_cb (drivers/net/wireless/intersil/p54/p54usb.c:163)\n __usb_hcd_giveback_urb (drivers/usb/core/hcd.c:1657)\n dummy_timer (drivers/usb/gadget/udc/dummy_hcd.c:2005)\n ...\n \u003c/IRQ\u003e\n\n The buggy address belongs to the object at ffff88800f0770c0\n which belongs to the cache skbuff_small_head of size 704\n The buggy address is located 84 bytes inside of\n allocated 704-byte region [ffff88800f0770c0, ffff88800f077380)\n\nCheck that the slice fits in the skb before copying."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:28:46.775Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/7a456ffcd20bd92ad0ef46c1aaa0e39e3be1f7e7"
},
{
"url": "https://git.kernel.org/stable/c/88f7044f92b8326fbfab26d0d8ed297c367ebb76"
},
{
"url": "https://git.kernel.org/stable/c/f21b7e096fe5371bf697cd410537fb434a763f5e"
},
{
"url": "https://git.kernel.org/stable/c/25c3b85af3fc4f8043159b14e65790fc3bbdaf48"
},
{
"url": "https://git.kernel.org/stable/c/f46f8f9c43fd02f4dd5f716d4bda296a523c04f0"
},
{
"url": "https://git.kernel.org/stable/c/d38f5d868a0a4770e3bcd0925e16c46acdbc9509"
},
{
"url": "https://git.kernel.org/stable/c/9096e1f7014174067239a63df18ae5f28301990d"
},
{
"url": "https://git.kernel.org/stable/c/ebd6d37fa94bee929e0b4c9ca19fdf9b1dcf6cea"
}
],
"title": "wifi: p54: validate RX frame length in p54_rx_eeprom_readback()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64571",
"datePublished": "2026-08-05T08:08:08.466Z",
"dateReserved": "2026-07-19T15:36:31.797Z",
"dateUpdated": "2026-08-19T16:28:46.775Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68214 (GCVE-0-2026-68214)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: rtl2832: fix use-after-free in rtl2832_remove()
cancel_delayed_work_sync() is called before i2c_mux_del_adapters()
in rtl2832_remove(). While the cancel waits for any running instance
of i2c_gate_work to finish, it does not prevent the timer from being
rescheduled by a concurrent thread.
During probe, the r820t_attach() call attempts I2C transfers through
the mux adapter. These transfers go through i2c_mux_master_xfer(),
which calls rtl2832_deselect() after the transfer completes,
rescheduling i2c_gate_work via schedule_delayed_work(). If this
transfer is still in flight when rtl2832_remove() runs,
rtl2832_deselect() can reschedule i2c_gate_work after it has been
cancelled, causing a use-after-free when kfree(dev) is called.
Fix this by calling i2c_mux_del_adapters() before
cancel_delayed_work_sync(). Once the mux adapter is unregistered, no
new I2C transfers can go through it, so rtl2832_deselect() can no
longer reschedule i2c_gate_work. The subsequent
cancel_delayed_work_sync() is then guaranteed to be final.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: cddcc40b1b1553010acb89add84c64b5d123ec94 Version: cddcc40b1b1553010acb89add84c64b5d123ec94 Version: cddcc40b1b1553010acb89add84c64b5d123ec94 Version: cddcc40b1b1553010acb89add84c64b5d123ec94 Version: cddcc40b1b1553010acb89add84c64b5d123ec94 Version: cddcc40b1b1553010acb89add84c64b5d123ec94 Version: cddcc40b1b1553010acb89add84c64b5d123ec94 Version: cddcc40b1b1553010acb89add84c64b5d123ec94 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/dvb-frontends/rtl2832.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "1e8a6bc19403661661fed5ae82f6eca6c9cdfad2",
"status": "affected",
"version": "cddcc40b1b1553010acb89add84c64b5d123ec94",
"versionType": "git"
},
{
"lessThan": "68a9c0290897c1436ddceb8cea604c93377a0299",
"status": "affected",
"version": "cddcc40b1b1553010acb89add84c64b5d123ec94",
"versionType": "git"
},
{
"lessThan": "13c06056699e66ff7109ba68658cc6ea4a23f516",
"status": "affected",
"version": "cddcc40b1b1553010acb89add84c64b5d123ec94",
"versionType": "git"
},
{
"lessThan": "9acd5bbbe1df8e487e49488692c224496d4c9e16",
"status": "affected",
"version": "cddcc40b1b1553010acb89add84c64b5d123ec94",
"versionType": "git"
},
{
"lessThan": "24bef237eef8dd1ebcffb129ba21891ddad0d309",
"status": "affected",
"version": "cddcc40b1b1553010acb89add84c64b5d123ec94",
"versionType": "git"
},
{
"lessThan": "2c71bda6edc630a1f8c3c45d8df5fc22d234e042",
"status": "affected",
"version": "cddcc40b1b1553010acb89add84c64b5d123ec94",
"versionType": "git"
},
{
"lessThan": "90d781711418881f8c836c2a859cc2886625d750",
"status": "affected",
"version": "cddcc40b1b1553010acb89add84c64b5d123ec94",
"versionType": "git"
},
{
"lessThan": "680daf40a82d483949f87f0d8f98639dc47e610c",
"status": "affected",
"version": "cddcc40b1b1553010acb89add84c64b5d123ec94",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/dvb-frontends/rtl2832.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.7"
},
{
"lessThan": "4.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: rtl2832: fix use-after-free in rtl2832_remove()\n\ncancel_delayed_work_sync() is called before i2c_mux_del_adapters()\nin rtl2832_remove(). While the cancel waits for any running instance\nof i2c_gate_work to finish, it does not prevent the timer from being\nrescheduled by a concurrent thread.\n\nDuring probe, the r820t_attach() call attempts I2C transfers through\nthe mux adapter. These transfers go through i2c_mux_master_xfer(),\nwhich calls rtl2832_deselect() after the transfer completes,\nrescheduling i2c_gate_work via schedule_delayed_work(). If this\ntransfer is still in flight when rtl2832_remove() runs,\nrtl2832_deselect() can reschedule i2c_gate_work after it has been\ncancelled, causing a use-after-free when kfree(dev) is called.\n\nFix this by calling i2c_mux_del_adapters() before\ncancel_delayed_work_sync(). Once the mux adapter is unregistered, no\nnew I2C transfers can go through it, so rtl2832_deselect() can no\nlonger reschedule i2c_gate_work. The subsequent\ncancel_delayed_work_sync() is then guaranteed to be final."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:42.193Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/1e8a6bc19403661661fed5ae82f6eca6c9cdfad2"
},
{
"url": "https://git.kernel.org/stable/c/68a9c0290897c1436ddceb8cea604c93377a0299"
},
{
"url": "https://git.kernel.org/stable/c/13c06056699e66ff7109ba68658cc6ea4a23f516"
},
{
"url": "https://git.kernel.org/stable/c/9acd5bbbe1df8e487e49488692c224496d4c9e16"
},
{
"url": "https://git.kernel.org/stable/c/24bef237eef8dd1ebcffb129ba21891ddad0d309"
},
{
"url": "https://git.kernel.org/stable/c/2c71bda6edc630a1f8c3c45d8df5fc22d234e042"
},
{
"url": "https://git.kernel.org/stable/c/90d781711418881f8c836c2a859cc2886625d750"
},
{
"url": "https://git.kernel.org/stable/c/680daf40a82d483949f87f0d8f98639dc47e610c"
}
],
"title": "media: rtl2832: fix use-after-free in rtl2832_remove()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68214",
"datePublished": "2026-08-10T12:00:33.539Z",
"dateReserved": "2026-07-30T09:28:09.375Z",
"dateUpdated": "2026-08-19T16:31:42.193Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72070 (GCVE-0-2026-72070)
Vulnerability from cvelistv5
Published
2026-08-15 05:52
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: libertas_tf: fix use-after-free in lbtf_free_adapter()
lbtf_free_adapter() calls timer_delete(&priv->command_timer), which does
not wait for a running command_timer_fn() callback. lbtf_free_adapter()
runs on the teardown path right before ieee80211_free_hw() frees priv,
both in lbtf_remove_card() and in the probe error path. command_timer is
armed by mod_timer() in lbtf_cmd() whenever a firmware command is sent.
command_timer_fn() dereferences priv. If a command times out as the
device is removed, command_timer_fn() runs concurrently with teardown and
dereferences priv after it has been freed.
This is the same use-after-free that commit 03cc8f90d053 ("wifi: libertas:
fix use-after-free in lbs_free_adapter()") fixed in the sibling libertas
driver. The libertas_tf variant has the identical pattern and was left
unchanged. Use timer_delete_sync() so any in-flight callback completes
before priv is freed.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 06b16ae5319251c26377afcb401e46056d5673f4 Version: 06b16ae5319251c26377afcb401e46056d5673f4 Version: 06b16ae5319251c26377afcb401e46056d5673f4 Version: 06b16ae5319251c26377afcb401e46056d5673f4 Version: 06b16ae5319251c26377afcb401e46056d5673f4 Version: 06b16ae5319251c26377afcb401e46056d5673f4 Version: 06b16ae5319251c26377afcb401e46056d5673f4 Version: 06b16ae5319251c26377afcb401e46056d5673f4 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/marvell/libertas_tf/main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "bd75636681588c67006279abdb9a76a708b3ce29",
"status": "affected",
"version": "06b16ae5319251c26377afcb401e46056d5673f4",
"versionType": "git"
},
{
"lessThan": "2fba1d3b2f031a2c68e566a6d45cc5b7a8d6683d",
"status": "affected",
"version": "06b16ae5319251c26377afcb401e46056d5673f4",
"versionType": "git"
},
{
"lessThan": "9392fd5de555272449d3d8c63410ea00f8ec853a",
"status": "affected",
"version": "06b16ae5319251c26377afcb401e46056d5673f4",
"versionType": "git"
},
{
"lessThan": "4714e95f5d61cb9c5c7c6c4e68b618f37bc6ffcf",
"status": "affected",
"version": "06b16ae5319251c26377afcb401e46056d5673f4",
"versionType": "git"
},
{
"lessThan": "066b59e84f90d270cc15f0370166155aca507630",
"status": "affected",
"version": "06b16ae5319251c26377afcb401e46056d5673f4",
"versionType": "git"
},
{
"lessThan": "fcff712d0e3d183843ec3916470ee6cc3455baad",
"status": "affected",
"version": "06b16ae5319251c26377afcb401e46056d5673f4",
"versionType": "git"
},
{
"lessThan": "bcf7968cb97ce4312588042cf2712f04caff6d8f",
"status": "affected",
"version": "06b16ae5319251c26377afcb401e46056d5673f4",
"versionType": "git"
},
{
"lessThan": "aa6dcd5c8dd9ba1d7d0f60093bcda41c0d6d438d",
"status": "affected",
"version": "06b16ae5319251c26377afcb401e46056d5673f4",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/marvell/libertas_tf/main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.28"
},
{
"lessThan": "2.6.28",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.28",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: libertas_tf: fix use-after-free in lbtf_free_adapter()\n\nlbtf_free_adapter() calls timer_delete(\u0026priv-\u003ecommand_timer), which does\nnot wait for a running command_timer_fn() callback. lbtf_free_adapter()\nruns on the teardown path right before ieee80211_free_hw() frees priv,\nboth in lbtf_remove_card() and in the probe error path. command_timer is\narmed by mod_timer() in lbtf_cmd() whenever a firmware command is sent.\ncommand_timer_fn() dereferences priv. If a command times out as the\ndevice is removed, command_timer_fn() runs concurrently with teardown and\ndereferences priv after it has been freed.\n\nThis is the same use-after-free that commit 03cc8f90d053 (\"wifi: libertas:\nfix use-after-free in lbs_free_adapter()\") fixed in the sibling libertas\ndriver. The libertas_tf variant has the identical pattern and was left\nunchanged. Use timer_delete_sync() so any in-flight callback completes\nbefore priv is freed."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:42.921Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/bd75636681588c67006279abdb9a76a708b3ce29"
},
{
"url": "https://git.kernel.org/stable/c/2fba1d3b2f031a2c68e566a6d45cc5b7a8d6683d"
},
{
"url": "https://git.kernel.org/stable/c/9392fd5de555272449d3d8c63410ea00f8ec853a"
},
{
"url": "https://git.kernel.org/stable/c/4714e95f5d61cb9c5c7c6c4e68b618f37bc6ffcf"
},
{
"url": "https://git.kernel.org/stable/c/066b59e84f90d270cc15f0370166155aca507630"
},
{
"url": "https://git.kernel.org/stable/c/fcff712d0e3d183843ec3916470ee6cc3455baad"
},
{
"url": "https://git.kernel.org/stable/c/bcf7968cb97ce4312588042cf2712f04caff6d8f"
},
{
"url": "https://git.kernel.org/stable/c/aa6dcd5c8dd9ba1d7d0f60093bcda41c0d6d438d"
}
],
"title": "wifi: libertas_tf: fix use-after-free in lbtf_free_adapter()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72070",
"datePublished": "2026-08-15T05:52:22.486Z",
"dateReserved": "2026-08-09T03:40:39.904Z",
"dateUpdated": "2026-08-23T12:46:42.921Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68385 (GCVE-0-2026-68385)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-17 05:04
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
s390/checksum: Fix csum_partial() without vector facility
Currently csum_partial() calls csum_copy() with copy=false and dst=NULL.
On machines without the vector facility, csum_copy() falls back to
cksm(dst, ...), causing the checksum to be calculated from address zero
instead of the source buffer.
The VX implementation already checksums data loaded from src. Make the
fallback do the same by passing src to cksm().
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"arch/s390/lib/csum-partial.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "5fc0a2a6eeb99cac991242bb48796c7749ce3261",
"status": "affected",
"version": "dcd3e1de9d17dc43dfed87a9fc814b9dec508043",
"versionType": "git"
},
{
"lessThan": "1d9a2f01b3c4e5c88e06b2db4b5460c2ec884722",
"status": "affected",
"version": "dcd3e1de9d17dc43dfed87a9fc814b9dec508043",
"versionType": "git"
},
{
"lessThan": "898bb2814f38399108bdd2113f38d97383a7036a",
"status": "affected",
"version": "dcd3e1de9d17dc43dfed87a9fc814b9dec508043",
"versionType": "git"
},
{
"lessThan": "4bb06b60d982355e22647b3d12d6619419f8c1fa",
"status": "affected",
"version": "dcd3e1de9d17dc43dfed87a9fc814b9dec508043",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"arch/s390/lib/csum-partial.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.9"
},
{
"lessThan": "6.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/checksum: Fix csum_partial() without vector facility\n\nCurrently csum_partial() calls csum_copy() with copy=false and dst=NULL.\nOn machines without the vector facility, csum_copy() falls back to\ncksm(dst, ...), causing the checksum to be calculated from address zero\ninstead of the source buffer.\n\nThe VX implementation already checksums data loaded from src. Make the\nfallback do the same by passing src to cksm()."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - csum_partial() is the s390 software checksum used by the network stack on received and transmitted packets (skb_checksum, __skb_checksum_complete, ICMP/UDP/TCP, tunnels, GSO fallback); a remote peer both triggers the code and observes the resulting bad checksum values in packets sent back to it, with no local access needed.\nAC:L - On any affected system (a machine or guest without the vector facility, i.e. pre-z13 hardware or a z/VM/KVM/QEMU CPU model lacking VX) the wrong-address checksum happens unconditionally and deterministically on every call, and eliciting replies of chosen lengths (e.g. ICMP echo) is trivially repeatable.\nPR:N - No credentials or account are needed; simply sending packets to the host (or receiving its traffic) exercises the software checksum path, and the leaked checksum values are returned to an unauthenticated remote party.\nUI:N - Packet processing and checksum computation occur automatically in the kernel network stack with no action by any local user or administrator.\nS:U - The faulty read and its consequences stay within the kernel\u0027s own security authority; no hypervisor, IOMMU, or sandbox boundary is crossed.\nC:H - The checksum is computed over kernel memory at address 0 (the s390 lowcore: kernel stack/task pointers, PSWs, per-CPU state, and following low kernel memory) for an attacker-influenced length, and that value is emitted in transmitted packet checksum fields; differencing results over successive lengths reconstructs kernel memory contents remotely, defeating KASLR and disclosing kernel pointers.\nI:H - Computed checksums no longer depend on packet contents, so IP/TCP/UDP checksum verification is fully defeated: corrupted or attacker-modified payloads are accepted as valid by the stack and delivered to applications, destroying the integrity protection the checksum exists to provide.\nA:H - All software-checksummed traffic carries or fails bogus checksums and is dropped, causing loss of network connectivity on affected machines, and where the identity mapping base is randomized or the lowcore is relocated the read from address 0 hits unmapped memory and triggers a program check / kernel crash."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:04:31.922Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/5fc0a2a6eeb99cac991242bb48796c7749ce3261"
},
{
"url": "https://git.kernel.org/stable/c/1d9a2f01b3c4e5c88e06b2db4b5460c2ec884722"
},
{
"url": "https://git.kernel.org/stable/c/898bb2814f38399108bdd2113f38d97383a7036a"
},
{
"url": "https://git.kernel.org/stable/c/4bb06b60d982355e22647b3d12d6619419f8c1fa"
}
],
"title": "s390/checksum: Fix csum_partial() without vector facility",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68385",
"datePublished": "2026-08-10T12:04:04.281Z",
"dateReserved": "2026-07-30T09:28:09.387Z",
"dateUpdated": "2026-08-17T05:04:31.922Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68257 (GCVE-0-2026-68257)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-18 06:55
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdkfd: fix 32-bit overflow in CWSR total size calculation
total_cwsr_size was computed in 32-bit before being used as a BO/SVM
allocation size.
With large ctx_save_restore_area_size and debug_memory_size
multiplied by the XCC count, the product can wrap,
yielding an undersized CWSR save area that firmware later overruns.
Promote total_cwsr_size to u64 and use check_add_overflow()/
check_mul_overflow() in both kfd_queue_acquire_buffers() and
kfd_queue_release_buffers().
(cherry picked from commit 319f7e13423ae3f486b9aea82f9ad2d6af0ee608)
References
| URL | Tags | |
|---|---|---|
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 325aa07165394b8e866ffe9ec1d4c99d9195b2f2 Version: d15deafab5d722afb9e2f83c5edcdef9d9d98bd1 Version: d15deafab5d722afb9e2f83c5edcdef9d9d98bd1 Version: d15deafab5d722afb9e2f83c5edcdef9d9d98bd1 Version: 63600103d2ac5c09fdeec5b931b396e4e0efd5d8 Version: 6.12.59 ≤ Version: 6.17.9 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdkfd/kfd_queue.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b88ffe6593607364a8c06a48c6f29e55437cdf8e",
"status": "affected",
"version": "325aa07165394b8e866ffe9ec1d4c99d9195b2f2",
"versionType": "git"
},
{
"lessThan": "abce3276c57e36c955627307469b9f009057a467",
"status": "affected",
"version": "d15deafab5d722afb9e2f83c5edcdef9d9d98bd1",
"versionType": "git"
},
{
"lessThan": "865532d54eb57b660b1cb1b0e1755776ce21b849",
"status": "affected",
"version": "d15deafab5d722afb9e2f83c5edcdef9d9d98bd1",
"versionType": "git"
},
{
"lessThan": "2b0386d4293920e690c0e017708f999b93cc729b",
"status": "affected",
"version": "d15deafab5d722afb9e2f83c5edcdef9d9d98bd1",
"versionType": "git"
},
{
"status": "affected",
"version": "63600103d2ac5c09fdeec5b931b396e4e0efd5d8",
"versionType": "git"
},
{
"lessThan": "6.12.101",
"status": "affected",
"version": "6.12.59",
"versionType": "semver"
},
{
"lessThan": "6.18",
"status": "affected",
"version": "6.17.9",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdkfd/kfd_queue.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.18"
},
{
"lessThan": "6.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.12.59",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.17.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdkfd: fix 32-bit overflow in CWSR total size calculation\n\ntotal_cwsr_size was computed in 32-bit before being used as a BO/SVM\nallocation size.\nWith large ctx_save_restore_area_size and debug_memory_size\nmultiplied by the XCC count, the product can wrap,\nyielding an undersized CWSR save area that firmware later overruns.\n\nPromote total_cwsr_size to u64 and use check_add_overflow()/\ncheck_mul_overflow() in both kfd_queue_acquire_buffers() and\nkfd_queue_release_buffers().\n\n(cherry picked from commit 319f7e13423ae3f486b9aea82f9ad2d6af0ee608)"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Triggered through the AMDKFD_IOC_CREATE_QUEUE ioctl on the local /dev/kfd character device; the attacker-controlled ctx_save_restore_size field comes straight from the ioctl argument struct with no remote reachability.\nAC:L - The overflow is pure deterministic arithmetic on a value the attacker fully controls \u2014 passing ctx_save_restore_size near 2^32 (or /NUM_XCC on multi-XCC MI300 parts) reliably wraps total_cwsr_size to 0 or a small value on every attempt, with no race or layout dependency.\nPR:L - Requires only an unprivileged local account with access to /dev/kfd, which is granted to the render group and is routinely available to ordinary users on ROCm hosts, GPU compute nodes, containers, Steam Deck/desktop and Chrome OS style systems; no capabilities are checked on this path.\nUI:N - The attacker creates the malicious compute queue entirely from its own process via a single ioctl; no action by any other user or administrator is needed.\nS:U - The undersized CWSR area and the resulting firmware overrun stay within the kernel/GPU driver security authority of the same machine; there is no hypervisor or IOMMU boundary crossed.\nC:H - With validation bypassed, CP firmware save/restore reads span memory adjacent to the tiny validated buffer and load it into wave state the attacker\u0027s shader can read back, and get_wave_state copies per-XCC control-stack contents out of the unvalidated region, giving a broad out-of-bounds disclosure primitive.\nI:H - The queue is programmed with the full unwrapped save size and per-XCC base offsets, so firmware performs large out-of-bounds writes of wave/control-stack data beyond the buffer that was actually validated and reference-counted, and the bypassed queue_refcount lets those buffers be unmapped or freed while the queue is live \u2014 an attacker-influenced memory-corruption primitive.\nA:H - Overrunning the CWSR save area drives the GPU into unmapped VA on preemption, causing VM faults, queue hangs and driver-initiated GPU resets that take down all GPU workloads on the machine, including other tenants on shared compute nodes."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-18T06:55:54.208Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b88ffe6593607364a8c06a48c6f29e55437cdf8e"
},
{
"url": "https://git.kernel.org/stable/c/abce3276c57e36c955627307469b9f009057a467"
},
{
"url": "https://git.kernel.org/stable/c/865532d54eb57b660b1cb1b0e1755776ce21b849"
},
{
"url": "https://git.kernel.org/stable/c/2b0386d4293920e690c0e017708f999b93cc729b"
}
],
"title": "drm/amdkfd: fix 32-bit overflow in CWSR total size calculation",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68257",
"datePublished": "2026-08-10T12:01:30.547Z",
"dateReserved": "2026-07-30T09:28:09.378Z",
"dateUpdated": "2026-08-18T06:55:54.208Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68362 (GCVE-0-2026-68362)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: ath11k: fix NULL pointer dereference in ath11k_hal_srng_access_begin
In ATH11K_QMI_EVENT_FW_READY, ATH11K_FLAG_REGISTERED is set
unconditionally even when ath11k_core_qmi_firmware_ready() fails.
This leaves the driver in an inconsistent state where
initialization is considered complete although the firmware ready
handling did not finish successfully. During the subsequent SSR,
the driver enters the restart path based on this incorrect state
and dereferences uninitialized srng members, resulting in a NULL
pointer dereference.
Call trace:
ath11k_hal_srng_access_begin+0xc/0x60 [ath11k] (P)
ath11k_ce_cleanup_pipes+0x17c/0x180 [ath11k]
ath11k_core_restart+0x40/0x168 [ath11k]
Fix this by:
- skipping firmware_ready if ATH11K_FLAG_REGISTERED is already set
- setting ATH11K_FLAG_REGISTERED only when firmware_ready succeeds
- setting ATH11K_FLAG_QMI_FAIL and aborting the FW_READY handling
on error
Tested-on: WCN6750 hw1.0 AHB WLAN.MSL.2.0.c2-00204-QCAMSLSWPLZ-1
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 6fe62a8cec51c756159c71be35a16b2cc8cbd4c0 Version: 6fe62a8cec51c756159c71be35a16b2cc8cbd4c0 Version: 6fe62a8cec51c756159c71be35a16b2cc8cbd4c0 Version: 6fe62a8cec51c756159c71be35a16b2cc8cbd4c0 Version: 6fe62a8cec51c756159c71be35a16b2cc8cbd4c0 Version: 6fe62a8cec51c756159c71be35a16b2cc8cbd4c0 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/ath/ath11k/qmi.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "66bf998b18334ca97321433e4ab783b6ff267e9d",
"status": "affected",
"version": "6fe62a8cec51c756159c71be35a16b2cc8cbd4c0",
"versionType": "git"
},
{
"lessThan": "e517e207300edcf7f3a8f6c45f9155c0e419ffb9",
"status": "affected",
"version": "6fe62a8cec51c756159c71be35a16b2cc8cbd4c0",
"versionType": "git"
},
{
"lessThan": "d6bba659ac30d862ee7bab92862cd6e514f07521",
"status": "affected",
"version": "6fe62a8cec51c756159c71be35a16b2cc8cbd4c0",
"versionType": "git"
},
{
"lessThan": "e5394605f9a985cc3a8263e610ba84b33cbe7b0c",
"status": "affected",
"version": "6fe62a8cec51c756159c71be35a16b2cc8cbd4c0",
"versionType": "git"
},
{
"lessThan": "4abb4e284d8897176e91d7a3168ee29ed876bb41",
"status": "affected",
"version": "6fe62a8cec51c756159c71be35a16b2cc8cbd4c0",
"versionType": "git"
},
{
"lessThan": "e8d85672dd7e2523f774caafba8f858384e18df7",
"status": "affected",
"version": "6fe62a8cec51c756159c71be35a16b2cc8cbd4c0",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/ath/ath11k/qmi.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.1"
},
{
"lessThan": "6.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "6.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath11k: fix NULL pointer dereference in ath11k_hal_srng_access_begin\n\nIn ATH11K_QMI_EVENT_FW_READY, ATH11K_FLAG_REGISTERED is set\nunconditionally even when ath11k_core_qmi_firmware_ready() fails.\nThis leaves the driver in an inconsistent state where\ninitialization is considered complete although the firmware ready\nhandling did not finish successfully. During the subsequent SSR,\nthe driver enters the restart path based on this incorrect state\nand dereferences uninitialized srng members, resulting in a NULL\npointer dereference.\n\nCall trace:\n ath11k_hal_srng_access_begin+0xc/0x60 [ath11k] (P)\n ath11k_ce_cleanup_pipes+0x17c/0x180 [ath11k]\n ath11k_core_restart+0x40/0x168 [ath11k]\n\nFix this by:\n- skipping firmware_ready if ATH11K_FLAG_REGISTERED is already set\n- setting ATH11K_FLAG_REGISTERED only when firmware_ready succeeds\n- setting ATH11K_FLAG_QMI_FAIL and aborting the FW_READY handling\non error\n\nTested-on: WCN6750 hw1.0 AHB WLAN.MSL.2.0.c2-00204-QCAMSLSWPLZ-1"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:15.793Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/66bf998b18334ca97321433e4ab783b6ff267e9d"
},
{
"url": "https://git.kernel.org/stable/c/e517e207300edcf7f3a8f6c45f9155c0e419ffb9"
},
{
"url": "https://git.kernel.org/stable/c/d6bba659ac30d862ee7bab92862cd6e514f07521"
},
{
"url": "https://git.kernel.org/stable/c/e5394605f9a985cc3a8263e610ba84b33cbe7b0c"
},
{
"url": "https://git.kernel.org/stable/c/4abb4e284d8897176e91d7a3168ee29ed876bb41"
},
{
"url": "https://git.kernel.org/stable/c/e8d85672dd7e2523f774caafba8f858384e18df7"
}
],
"title": "wifi: ath11k: fix NULL pointer dereference in ath11k_hal_srng_access_begin",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68362",
"datePublished": "2026-08-10T12:03:39.363Z",
"dateReserved": "2026-07-30T09:28:09.385Z",
"dateUpdated": "2026-08-19T16:34:15.793Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2025-40098 (GCVE-0-2025-40098)
Vulnerability from cvelistv5
Published
2025-10-30 09:48
Modified
2026-08-03 09:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ALSA: hda: cs35l41: Fix NULL pointer dereference in cs35l41_get_acpi_mute_state()
Return value of a function acpi_evaluate_dsm() is dereferenced without
checking for NULL, but it is usually checked for this function.
acpi_evaluate_dsm() may return NULL, when acpi_evaluate_object() returns
acpi_status other than ACPI_SUCCESS, so add a check to prevent the crach.
Found by Linux Verification Center (linuxtesting.org) with SVACE.
References
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"sound/hda/codecs/side-codecs/cs35l41_hda.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "19129a365d2bd019fb60662b36b2655931997f12",
"status": "affected",
"version": "447106e92a0c86c332d40710436f38f64c322cd6",
"versionType": "git"
},
{
"lessThan": "b518386db2b993d786c431caa9f46ce063c5cb05",
"status": "affected",
"version": "447106e92a0c86c332d40710436f38f64c322cd6",
"versionType": "git"
},
{
"lessThan": "8527bbb33936340525a3504a00932b2f8fd75754",
"status": "affected",
"version": "447106e92a0c86c332d40710436f38f64c322cd6",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"sound/hda/codecs/side-codecs/cs35l41_hda.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.7"
},
{
"lessThan": "6.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.17.*",
"status": "unaffected",
"version": "6.17.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "6.18",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.17.5",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18",
"versionStartIncluding": "6.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: hda: cs35l41: Fix NULL pointer dereference in cs35l41_get_acpi_mute_state()\n\nReturn value of a function acpi_evaluate_dsm() is dereferenced without\nchecking for NULL, but it is usually checked for this function.\n\nacpi_evaluate_dsm() may return NULL, when acpi_evaluate_object() returns\nacpi_status other than ACPI_SUCCESS, so add a check to prevent the crach.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-03T09:32:26.104Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/19129a365d2bd019fb60662b36b2655931997f12"
},
{
"url": "https://git.kernel.org/stable/c/b518386db2b993d786c431caa9f46ce063c5cb05"
},
{
"url": "https://git.kernel.org/stable/c/8527bbb33936340525a3504a00932b2f8fd75754"
}
],
"title": "ALSA: hda: cs35l41: Fix NULL pointer dereference in cs35l41_get_acpi_mute_state()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2025-40098",
"datePublished": "2025-10-30T09:48:05.200Z",
"dateReserved": "2025-04-16T07:20:57.164Z",
"dateUpdated": "2026-08-03T09:32:26.104Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68437 (GCVE-0-2026-68437)
Vulnerability from cvelistv5
Published
2026-08-12 00:07
Modified
2026-08-17 05:05
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/imagination: Fit paired fragment job in the correct CCCB
For geometry jobs with a paired fragment job, at the moment, the
DRM scheduler's prepare_job() callback:
- checks for internal (driver) dependencies for the geometry job;
- calls into pvr_queue_get_paired_frag_job_dep() to check for external
dependencies for the fragment job (the two jobs are submitted together
but the common scheduler code doesn't know about it, so this needs to
be done at this point in time);
- calls into the prepare_job() callback again, but for the fragment job,
to check its internal dependencies as well, passing the fragment job's
drm_sched_job and the geometry job's drm_sched_entity / pvr_queue.
The problem with the last step is that pvr_queue_prepare_job() doesn't
always take the mismatched fragment job and geometry queue into account,
in particular when checking whether there is space for the fragment
command to be submitted, so the code ends up checking for space in the
geometry (i.e. wrong) CCCB.
The rest of the nested prepare_job() callback happens to work fine at
the moment as the other internal dependencies are not relevant for a
paired fragment job.
Move the initialisation of a paired fragment job's done fence and CCCB
fence to pvr_queue_get_paired_frag_job_dep(), inferring the correct
queue from the fragment job itself.
This fixes cases where prepare_job() wrongly assumed that there was
enough space for a paired fragment job in its own CCCB, unblocking
run_job(), which then returned early without writing the full sequence
of commands to the CCCB.
The above lead to kernel warnings such as the following and potentially
job timeouts (depending on waiters on the missing commands):
[ 552.421075] WARNING: drivers/gpu/drm/imagination/pvr_cccb.c:178 at pvr_cccb_write_command_with_header+0x2c4/0x330 [powervr], CPU#2: kworker/u16:5/63
[ 552.421230] Modules linked in:
[ 552.421592] CPU: 2 UID: 0 PID: 63 Comm: kworker/u16:5 Tainted: G W 7.0.0-rc2-gc5d053e4dccb #39 PREEMPT
[ 552.421625] Tainted: [W]=WARN
[ 552.421637] Hardware name: Texas Instruments AM625 SK (DT)
[ 552.421655] Workqueue: powervr-sched drm_sched_run_job_work [gpu_sched]
[ 552.421744] pstate: 80000005 (Nzcv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)
[ 552.421766] pc : pvr_cccb_write_command_with_header+0x2c4/0x330 [powervr]
[ 552.421850] lr : pvr_queue_submit_job_to_cccb+0x57c/0xa74 [powervr]
[ 552.421923] sp : ffff800084c47650
[ 552.421936] x29: ffff800084c47740 x28: 0000000000000df8 x27: ffff800088a77000
[ 552.421979] x26: 0000000000000030 x25: ffff800084c47680 x24: 0000000000001000
[ 552.422017] x23: ffff800084c47820 x22: 1ffff00010988ecc x21: 0000000000000008
[ 552.422055] x20: 0000000000000208 x19: ffff000006ad5a88 x18: 0000000000000000
[ 552.422093] x17: 0000000020020000 x16: 0000000000020000 x15: 0000000000000000
[ 552.422130] x14: 0000000000000000 x13: 0000000000000000 x12: 0000000000000000
[ 552.422167] x11: 000000000000f2f2 x10: 00000000f3000000 x9 : 00000000f3f3f3f3
[ 552.422204] x8 : 00000000f2f2f200 x7 : ffff700010988ecc x6 : 0000000000000008
[ 552.422241] x5 : 0000000000000000 x4 : 1ffff0001114ee00 x3 : 0000000000000000
[ 552.422278] x2 : 0000000000000007 x1 : 0000000000000fff x0 : 000000000000002f
[ 552.422316] Call trace:
[ 552.422330] pvr_cccb_write_command_with_header+0x2c4/0x330 [powervr] (P)
[ 552.422411] pvr_queue_submit_job_to_cccb+0x57c/0xa74 [powervr]
[ 552.422486] pvr_queue_run_job+0x3a4/0x990 [powervr]
[ 552.422562] drm_sched_run_job_work+0x580/0xd48 [gpu_sched]
[ 552.422623] process_one_work+0x520/0x1288
[ 552.422657] worker_thread+0x3f0/0xb3c
[ 552.422679] kthread+0x334/0x3d8
[ 552.422706] ret_from_fork+0x10/0x20
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/imagination/pvr_queue.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "15a9863929206911a08b6f62de9c5da6931dbc9e",
"status": "affected",
"version": "eaf01ee5ba28b97f96a3d3eec4c5fbfb37ee4cde",
"versionType": "git"
},
{
"lessThan": "e2c29d51c0f65459ae5bbf7ccc302df4c359c473",
"status": "affected",
"version": "eaf01ee5ba28b97f96a3d3eec4c5fbfb37ee4cde",
"versionType": "git"
},
{
"lessThan": "4ddf82c18ee4b3d14ec7fa002c4039b46c961abc",
"status": "affected",
"version": "eaf01ee5ba28b97f96a3d3eec4c5fbfb37ee4cde",
"versionType": "git"
},
{
"lessThan": "4baf9e70cb756d78dd56419f8baee2978a72d0c3",
"status": "affected",
"version": "eaf01ee5ba28b97f96a3d3eec4c5fbfb37ee4cde",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/imagination/pvr_queue.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.8"
},
{
"lessThan": "6.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/imagination: Fit paired fragment job in the correct CCCB\n\nFor geometry jobs with a paired fragment job, at the moment, the\nDRM scheduler\u0027s prepare_job() callback:\n\n- checks for internal (driver) dependencies for the geometry job;\n- calls into pvr_queue_get_paired_frag_job_dep() to check for external\n dependencies for the fragment job (the two jobs are submitted together\n but the common scheduler code doesn\u0027t know about it, so this needs to\n be done at this point in time);\n- calls into the prepare_job() callback again, but for the fragment job,\n to check its internal dependencies as well, passing the fragment job\u0027s\n drm_sched_job and the geometry job\u0027s drm_sched_entity / pvr_queue.\n\nThe problem with the last step is that pvr_queue_prepare_job() doesn\u0027t\nalways take the mismatched fragment job and geometry queue into account,\nin particular when checking whether there is space for the fragment\ncommand to be submitted, so the code ends up checking for space in the\ngeometry (i.e. wrong) CCCB.\nThe rest of the nested prepare_job() callback happens to work fine at\nthe moment as the other internal dependencies are not relevant for a\npaired fragment job.\n\nMove the initialisation of a paired fragment job\u0027s done fence and CCCB\nfence to pvr_queue_get_paired_frag_job_dep(), inferring the correct\nqueue from the fragment job itself.\n\nThis fixes cases where prepare_job() wrongly assumed that there was\nenough space for a paired fragment job in its own CCCB, unblocking\nrun_job(), which then returned early without writing the full sequence\nof commands to the CCCB.\n\nThe above lead to kernel warnings such as the following and potentially\njob timeouts (depending on waiters on the missing commands):\n\n [ 552.421075] WARNING: drivers/gpu/drm/imagination/pvr_cccb.c:178 at pvr_cccb_write_command_with_header+0x2c4/0x330 [powervr], CPU#2: kworker/u16:5/63\n [ 552.421230] Modules linked in:\n [ 552.421592] CPU: 2 UID: 0 PID: 63 Comm: kworker/u16:5 Tainted: G W 7.0.0-rc2-gc5d053e4dccb #39 PREEMPT\n [ 552.421625] Tainted: [W]=WARN\n [ 552.421637] Hardware name: Texas Instruments AM625 SK (DT)\n [ 552.421655] Workqueue: powervr-sched drm_sched_run_job_work [gpu_sched]\n [ 552.421744] pstate: 80000005 (Nzcv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n [ 552.421766] pc : pvr_cccb_write_command_with_header+0x2c4/0x330 [powervr]\n [ 552.421850] lr : pvr_queue_submit_job_to_cccb+0x57c/0xa74 [powervr]\n [ 552.421923] sp : ffff800084c47650\n [ 552.421936] x29: ffff800084c47740 x28: 0000000000000df8 x27: ffff800088a77000\n [ 552.421979] x26: 0000000000000030 x25: ffff800084c47680 x24: 0000000000001000\n [ 552.422017] x23: ffff800084c47820 x22: 1ffff00010988ecc x21: 0000000000000008\n [ 552.422055] x20: 0000000000000208 x19: ffff000006ad5a88 x18: 0000000000000000\n [ 552.422093] x17: 0000000020020000 x16: 0000000000020000 x15: 0000000000000000\n [ 552.422130] x14: 0000000000000000 x13: 0000000000000000 x12: 0000000000000000\n [ 552.422167] x11: 000000000000f2f2 x10: 00000000f3000000 x9 : 00000000f3f3f3f3\n [ 552.422204] x8 : 00000000f2f2f200 x7 : ffff700010988ecc x6 : 0000000000000008\n [ 552.422241] x5 : 0000000000000000 x4 : 1ffff0001114ee00 x3 : 0000000000000000\n [ 552.422278] x2 : 0000000000000007 x1 : 0000000000000fff x0 : 000000000000002f\n [ 552.422316] Call trace:\n [ 552.422330] pvr_cccb_write_command_with_header+0x2c4/0x330 [powervr] (P)\n [ 552.422411] pvr_queue_submit_job_to_cccb+0x57c/0xa74 [powervr]\n [ 552.422486] pvr_queue_run_job+0x3a4/0x990 [powervr]\n [ 552.422562] drm_sched_run_job_work+0x580/0xd48 [gpu_sched]\n [ 552.422623] process_one_work+0x520/0x1288\n [ 552.422657] worker_thread+0x3f0/0xb3c\n [ 552.422679] kthread+0x334/0x3d8\n [ 552.422706] ret_from_fork+0x10/0x20"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:05:34.181Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/15a9863929206911a08b6f62de9c5da6931dbc9e"
},
{
"url": "https://git.kernel.org/stable/c/e2c29d51c0f65459ae5bbf7ccc302df4c359c473"
},
{
"url": "https://git.kernel.org/stable/c/4ddf82c18ee4b3d14ec7fa002c4039b46c961abc"
},
{
"url": "https://git.kernel.org/stable/c/4baf9e70cb756d78dd56419f8baee2978a72d0c3"
}
],
"title": "drm/imagination: Fit paired fragment job in the correct CCCB",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68437",
"datePublished": "2026-08-12T00:07:25.745Z",
"dateReserved": "2026-07-30T09:28:09.394Z",
"dateUpdated": "2026-08-17T05:05:34.181Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68185 (GCVE-0-2026-68185)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-18 06:55
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
LoongArch: Move jump_label_init() before parse_early_param()
When enabling both CONFIG_MEM_ALLOC_PROFILING=y and
CONFIG_MEM_ALLOC_PROFILING_ENABLED_BY_DEFAULT=y, then diabling memory
profiling by adding the boot parameter 'sysctl.vm.mem_profiling=0' will
cause the kernel failed to boot.
After analysis, this is because jump_label_init() must be called before
parse_early_param(), the early param handlers may modify static keys by
static_branch_enable/disable().
Fix this by moving jump_label_init() to before parse_early_param(). The
solution is similar to other architectures.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"arch/loongarch/kernel/setup.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "4b40e590efb350c54480d7e883f054d3609a94c6",
"status": "affected",
"version": "628c3bb40e9a8cefc0a6fde28b7b66bfe46d1dc2",
"versionType": "git"
},
{
"lessThan": "38b025fcdc45bdf5140a5726a1fbb2e694ea047b",
"status": "affected",
"version": "628c3bb40e9a8cefc0a6fde28b7b66bfe46d1dc2",
"versionType": "git"
},
{
"lessThan": "881e9f3c4e117b100880b1c5de3a0da8e455a78f",
"status": "affected",
"version": "628c3bb40e9a8cefc0a6fde28b7b66bfe46d1dc2",
"versionType": "git"
},
{
"lessThan": "ea68d444a658783234a06f05414e41cf93a18fb2",
"status": "affected",
"version": "628c3bb40e9a8cefc0a6fde28b7b66bfe46d1dc2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"arch/loongarch/kernel/setup.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.19"
},
{
"lessThan": "5.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nLoongArch: Move jump_label_init() before parse_early_param()\n\nWhen enabling both CONFIG_MEM_ALLOC_PROFILING=y and\nCONFIG_MEM_ALLOC_PROFILING_ENABLED_BY_DEFAULT=y, then diabling memory\nprofiling by adding the boot parameter \u0027sysctl.vm.mem_profiling=0\u0027 will\ncause the kernel failed to boot.\n\nAfter analysis, this is because jump_label_init() must be called before\nparse_early_param(), the early param handlers may modify static keys by\nstatic_branch_enable/disable().\n\nFix this by moving jump_label_init() to before parse_early_param(). The\nsolution is similar to other architectures."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-18T06:55:43.188Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/4b40e590efb350c54480d7e883f054d3609a94c6"
},
{
"url": "https://git.kernel.org/stable/c/38b025fcdc45bdf5140a5726a1fbb2e694ea047b"
},
{
"url": "https://git.kernel.org/stable/c/881e9f3c4e117b100880b1c5de3a0da8e455a78f"
},
{
"url": "https://git.kernel.org/stable/c/ea68d444a658783234a06f05414e41cf93a18fb2"
}
],
"title": "LoongArch: Move jump_label_init() before parse_early_param()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68185",
"datePublished": "2026-08-10T11:59:57.327Z",
"dateReserved": "2026-07-30T09:28:09.373Z",
"dateUpdated": "2026-08-18T06:55:43.188Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68277 (GCVE-0-2026-68277)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers
Three sideband reply parsers read 16-bit fields as:
val = (raw->msg[idx] << 8) | (raw->msg[idx+1]);
and check bounds only after the fact. When idx == raw->curlen,
raw->msg[idx+1] reads one byte past the received message data into
the following struct fields (curchunk_len, curchunk_idx, curlen).
Affected functions:
- drm_dp_sideband_parse_enum_path_resources_ack()
full_payload_bw_number and avail_payload_bw_number fields
- drm_dp_sideband_parse_allocate_payload_ack()
allocated_pbn field
- drm_dp_sideband_parse_query_payload_ack()
allocated_pbn field
Fix by using a single combined check (idx + 2 > curlen) before each
2-byte read. Since the check is strictly tighter than idx > curlen,
no separate step is needed.
[added fixes tag]
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/display/drm_dp_mst_topology.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c1f72a13d54ffd16647d3fa540d961f5deba8790",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "192e146c2d57ad033b0d418ec64ee390f8dc074e",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "6e3107e6522109a07fc9bb0fc4ec463f1982e113",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "bdf0508b1e6785d4a8982c637e97e68d60b47d7b",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "0bcd7675c69a2462a8531fcd9e4d096e9c7ec5df",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "d5c70523cafa26ad2c7a37b612849abe2683baa8",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "68a624416d1dd481b3e5b7ea0e8a070a9b8a2c73",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "6b89ba3dba2f583626fb693e47e951ffb8bf591f",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/display/drm_dp_mst_topology.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.17"
},
{
"lessThan": "3.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.17",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers\n\nThree sideband reply parsers read 16-bit fields as:\n\n val = (raw-\u003emsg[idx] \u003c\u003c 8) | (raw-\u003emsg[idx+1]);\n\nand check bounds only after the fact. When idx == raw-\u003ecurlen,\nraw-\u003emsg[idx+1] reads one byte past the received message data into\nthe following struct fields (curchunk_len, curchunk_idx, curlen).\n\nAffected functions:\n - drm_dp_sideband_parse_enum_path_resources_ack()\n full_payload_bw_number and avail_payload_bw_number fields\n - drm_dp_sideband_parse_allocate_payload_ack()\n allocated_pbn field\n - drm_dp_sideband_parse_query_payload_ack()\n allocated_pbn field\n\nFix by using a single combined check (idx + 2 \u003e curlen) before each\n2-byte read. Since the check is strictly tighter than idx \u003e curlen,\nno separate step is needed.\n\n[added fixes tag]"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:14.372Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c1f72a13d54ffd16647d3fa540d961f5deba8790"
},
{
"url": "https://git.kernel.org/stable/c/192e146c2d57ad033b0d418ec64ee390f8dc074e"
},
{
"url": "https://git.kernel.org/stable/c/6e3107e6522109a07fc9bb0fc4ec463f1982e113"
},
{
"url": "https://git.kernel.org/stable/c/bdf0508b1e6785d4a8982c637e97e68d60b47d7b"
},
{
"url": "https://git.kernel.org/stable/c/0bcd7675c69a2462a8531fcd9e4d096e9c7ec5df"
},
{
"url": "https://git.kernel.org/stable/c/d5c70523cafa26ad2c7a37b612849abe2683baa8"
},
{
"url": "https://git.kernel.org/stable/c/68a624416d1dd481b3e5b7ea0e8a070a9b8a2c73"
},
{
"url": "https://git.kernel.org/stable/c/6b89ba3dba2f583626fb693e47e951ffb8bf591f"
}
],
"title": "drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68277",
"datePublished": "2026-08-10T12:01:53.085Z",
"dateReserved": "2026-07-30T09:28:09.379Z",
"dateUpdated": "2026-08-23T12:46:14.372Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72015 (GCVE-0-2026-72015)
Vulnerability from cvelistv5
Published
2026-08-15 05:51
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
fs/resctrl: Fix double-add of pseudo-locked region's RMID to free list
A pseudo-locked group's RMID is freed when it is created. On unmount
rmdir_all_sub() unconditionally frees all RMID of all groups, resulting
in a double-free of the pseudo-locked group's RMID. The consequence of this
is that the original free results in the pseudo-locked group's RMID being
added to the rmid_free_lru linked list and the second free then attempts
to add the same RMID entry to the rmid_free_lru again.
Do not double-free a pseudo-locked group's RMID.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: e0bdfe8e36f3fbbdc91e70bf927f743ca23917b0 Version: e0bdfe8e36f3fbbdc91e70bf927f743ca23917b0 Version: e0bdfe8e36f3fbbdc91e70bf927f743ca23917b0 Version: e0bdfe8e36f3fbbdc91e70bf927f743ca23917b0 Version: e0bdfe8e36f3fbbdc91e70bf927f743ca23917b0 Version: e0bdfe8e36f3fbbdc91e70bf927f743ca23917b0 Version: e0bdfe8e36f3fbbdc91e70bf927f743ca23917b0 Version: e0bdfe8e36f3fbbdc91e70bf927f743ca23917b0 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/resctrl/rdtgroup.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "bab7dbba38ed3011972c3d9be2dcdca7575cbe32",
"status": "affected",
"version": "e0bdfe8e36f3fbbdc91e70bf927f743ca23917b0",
"versionType": "git"
},
{
"lessThan": "ad12e70d7dc3c94a05efc61d1e4861078e0e162b",
"status": "affected",
"version": "e0bdfe8e36f3fbbdc91e70bf927f743ca23917b0",
"versionType": "git"
},
{
"lessThan": "52b769165f20b38092f28ce064b4b143471540a7",
"status": "affected",
"version": "e0bdfe8e36f3fbbdc91e70bf927f743ca23917b0",
"versionType": "git"
},
{
"lessThan": "9168176894332312c12ef052e784735dbf4ffe3f",
"status": "affected",
"version": "e0bdfe8e36f3fbbdc91e70bf927f743ca23917b0",
"versionType": "git"
},
{
"lessThan": "b2fe9e140aa94b2816aab7ebc692b543e418f5e3",
"status": "affected",
"version": "e0bdfe8e36f3fbbdc91e70bf927f743ca23917b0",
"versionType": "git"
},
{
"lessThan": "52007bfdce5310e8c8a29849bfbfb188a1e50ca0",
"status": "affected",
"version": "e0bdfe8e36f3fbbdc91e70bf927f743ca23917b0",
"versionType": "git"
},
{
"lessThan": "f7628eea9212e185a09df3aea603ca8580b8678d",
"status": "affected",
"version": "e0bdfe8e36f3fbbdc91e70bf927f743ca23917b0",
"versionType": "git"
},
{
"lessThan": "b9f089723aee892efc77c349ae47a6b452b293c4",
"status": "affected",
"version": "e0bdfe8e36f3fbbdc91e70bf927f743ca23917b0",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/resctrl/rdtgroup.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.19"
},
{
"lessThan": "4.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs/resctrl: Fix double-add of pseudo-locked region\u0027s RMID to free list\n\nA pseudo-locked group\u0027s RMID is freed when it is created. On unmount\nrmdir_all_sub() unconditionally frees all RMID of all groups, resulting\nin a double-free of the pseudo-locked group\u0027s RMID. The consequence of this\nis that the original free results in the pseudo-locked group\u0027s RMID being\nadded to the rmid_free_lru linked list and the second free then attempts\nto add the same RMID entry to the rmid_free_lru again.\n\nDo not double-free a pseudo-locked group\u0027s RMID."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:25.496Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/bab7dbba38ed3011972c3d9be2dcdca7575cbe32"
},
{
"url": "https://git.kernel.org/stable/c/ad12e70d7dc3c94a05efc61d1e4861078e0e162b"
},
{
"url": "https://git.kernel.org/stable/c/52b769165f20b38092f28ce064b4b143471540a7"
},
{
"url": "https://git.kernel.org/stable/c/9168176894332312c12ef052e784735dbf4ffe3f"
},
{
"url": "https://git.kernel.org/stable/c/b2fe9e140aa94b2816aab7ebc692b543e418f5e3"
},
{
"url": "https://git.kernel.org/stable/c/52007bfdce5310e8c8a29849bfbfb188a1e50ca0"
},
{
"url": "https://git.kernel.org/stable/c/f7628eea9212e185a09df3aea603ca8580b8678d"
},
{
"url": "https://git.kernel.org/stable/c/b9f089723aee892efc77c349ae47a6b452b293c4"
}
],
"title": "fs/resctrl: Fix double-add of pseudo-locked region\u0027s RMID to free list",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72015",
"datePublished": "2026-08-15T05:51:43.390Z",
"dateReserved": "2026-08-09T03:40:39.900Z",
"dateUpdated": "2026-08-23T12:46:25.496Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68293 (GCVE-0-2026-68293)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-17 05:02
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/mlx5: Fix MCIA register buffer overflow on 32 dword reads
The MCIA register can return up to 32 dwords (128 bytes) when the device
advertises the mcia_32dwords capability, but struct
mlx5_ifc_mcia_reg_bits only defines dword_0..11, leaving room for just
12 dwords (48 bytes) of data.
mlx5_query_mcia() clamps the read size to mlx5_mcia_max_bytes() and then
memcpy()s that many bytes out of the register, potentially reading past
the end of the 'out' buffer. On kernels built with FORTIFY_SOURCE this
is caught as a buffer overflow while reading the module EEPROM via
ethtool:
detected buffer overflow in memcpy
kernel BUG at lib/string_helpers.c:1048!
RIP: 0010:fortify_panic+0x13/0x20
Call Trace:
mlx5_query_mcia.isra.0+0x200/0x210 [mlx5_core]
mlx5_query_module_eeprom_by_page+0x4a/0xa0 [mlx5_core]
mlx5e_get_module_eeprom_by_page+0xbb/0x120 [mlx5_core]
eeprom_prepare_data+0xf3/0x170
ethnl_default_doit+0xf1/0x3b0
Extend the mcia_reg layout to 32 dwords.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/mellanox/mlx5/core/port.c",
"include/linux/mlx5/mlx5_ifc.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "5be4eebd5a3a198dab0adcd550e1cadca79bdfed",
"status": "affected",
"version": "271907ee2f29cd1078fd219f0778fd824fb1971c",
"versionType": "git"
},
{
"lessThan": "87b39a8c875ca744b7de69af0a8ef8874cffccf1",
"status": "affected",
"version": "271907ee2f29cd1078fd219f0778fd824fb1971c",
"versionType": "git"
},
{
"lessThan": "88b2a16ddac3357e3f1d528e758b51e2c945d546",
"status": "affected",
"version": "271907ee2f29cd1078fd219f0778fd824fb1971c",
"versionType": "git"
},
{
"lessThan": "11c057d23465c7a5817a7284c896d19d54c0b616",
"status": "affected",
"version": "271907ee2f29cd1078fd219f0778fd824fb1971c",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/mellanox/mlx5/core/port.c",
"include/linux/mlx5/mlx5_ifc.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.18"
},
{
"lessThan": "5.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.18",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: Fix MCIA register buffer overflow on 32 dword reads\n\nThe MCIA register can return up to 32 dwords (128 bytes) when the device\nadvertises the mcia_32dwords capability, but struct\nmlx5_ifc_mcia_reg_bits only defines dword_0..11, leaving room for just\n12 dwords (48 bytes) of data.\n\nmlx5_query_mcia() clamps the read size to mlx5_mcia_max_bytes() and then\nmemcpy()s that many bytes out of the register, potentially reading past\nthe end of the \u0027out\u0027 buffer. On kernels built with FORTIFY_SOURCE this\nis caught as a buffer overflow while reading the module EEPROM via\nethtool:\n\n detected buffer overflow in memcpy\n kernel BUG at lib/string_helpers.c:1048!\n RIP: 0010:fortify_panic+0x13/0x20\n Call Trace:\n mlx5_query_mcia.isra.0+0x200/0x210 [mlx5_core]\n mlx5_query_module_eeprom_by_page+0x4a/0xa0 [mlx5_core]\n mlx5e_get_module_eeprom_by_page+0xbb/0x120 [mlx5_core]\n eeprom_prepare_data+0xf3/0x170\n ethnl_default_doit+0xf1/0x3b0\n\nExtend the mcia_reg layout to 32 dwords."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached only through local ethtool interfaces on the mlx5 netdev \u2014 the ETHTOOL_MSG_MODULE_EEPROM_GET genetlink message or the ETHTOOL_GMODULEEEPROM ioctl on a socket. No remote peer or received packet can trigger it.\nAC:L - A single ethtool module-EEPROM read of 128 bytes deterministically triggers the over-read on any adapter whose firmware advertises mcia_32dwords, which is the normal case on modern ConnectX hardware with a transceiver installed. No race, no memory-layout grooming, fully repeatable.\nPR:L - Both entry points check ns_capable(net-\u003euser_ns, CAP_NET_ADMIN), which is namespace-relative, so the root of an unprivileged user namespace owning a netns that holds an mlx5 VF/subfunction netdev (a standard SR-IOV container setup) can trigger it without any privilege in the initial namespace.\nUI:N - The attacker triggers the read entirely on their own by issuing an ethtool query; no action by another user or administrator is needed.\nS:U - The out-of-bounds read and its consequences are confined to the kernel of the same host; no VM, IOMMU, or other security-authority boundary is crossed.\nC:H - Up to 80 bytes of kernel stack adjacent to the 64-byte \u0027out\u0027 buffer are memcpy()\u0027d into the EEPROM data returned to userspace, disclosing saved registers, pointers and potentially return addresses or the stack canary \u2014 enough to defeat KASLR and stack protection and aid further exploitation.\nI:N - The defect is purely a read overflow; the destination buffer is sized from the caller\u0027s own request length, so no kernel memory is written out of bounds and no data is modified.\nA:H - On the widely enabled CONFIG_FORTIFY_SOURCE the copy hits fortify_panic(), producing a kernel BUG/oops in mlx5_query_mcia() while rtnl/netdev locks are held (per the reported trace), wedging networking and panicking outright with panic_on_oops."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:02:29.111Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/5be4eebd5a3a198dab0adcd550e1cadca79bdfed"
},
{
"url": "https://git.kernel.org/stable/c/87b39a8c875ca744b7de69af0a8ef8874cffccf1"
},
{
"url": "https://git.kernel.org/stable/c/88b2a16ddac3357e3f1d528e758b51e2c945d546"
},
{
"url": "https://git.kernel.org/stable/c/11c057d23465c7a5817a7284c896d19d54c0b616"
}
],
"title": "net/mlx5: Fix MCIA register buffer overflow on 32 dword reads",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68293",
"datePublished": "2026-08-10T12:02:26.414Z",
"dateReserved": "2026-07-30T09:28:09.380Z",
"dateUpdated": "2026-08-17T05:02:29.111Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68405 (GCVE-0-2026-68405)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock
ieee80211_do_stop() removes AP_VLAN packets from the parent AP
ps->bc_buf while holding ps->bc_buf.lock with IRQs disabled. It then
calls ieee80211_free_txskb() before dropping the lock.
ieee80211_free_txskb() is not just a passive SKB release. For SKBs with
TX status state it can report a dropped frame through cfg80211/nl80211,
and that path can reach netlink tap transmit. This is the same reason
the pending queue cleanup in ieee80211_do_stop() already unlinks SKBs
under the queue lock and frees them after IRQ state is restored.
The buggy scenario involves two paths, with each column showing the
order within that path:
AP_VLAN management TX: AP_VLAN stop:
1. attach ACK-status state 1. clear the running state
2. queue a multicast SKB on 2. take ps->bc_buf.lock with IRQs
parent ps->bc_buf disabled
3. unlink the AP_VLAN SKB
4. call ieee80211_free_txskb()
Unlink matching AP_VLAN SKBs from ps->bc_buf under the existing lock,
but move them to a local free queue. Drop the lock and restore IRQ state
before calling ieee80211_free_txskb().
WARNING: kernel/softirq.c:430 at __local_bh_enable_ip
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 397a7a24ef8c2967a3e8090013f9c54714110c48 Version: 397a7a24ef8c2967a3e8090013f9c54714110c48 Version: 397a7a24ef8c2967a3e8090013f9c54714110c48 Version: 397a7a24ef8c2967a3e8090013f9c54714110c48 Version: 397a7a24ef8c2967a3e8090013f9c54714110c48 Version: 397a7a24ef8c2967a3e8090013f9c54714110c48 Version: 397a7a24ef8c2967a3e8090013f9c54714110c48 Version: 397a7a24ef8c2967a3e8090013f9c54714110c48 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/mac80211/iface.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "0d2619e708e2ef02ba1c91642ea261d3f19d8f9a",
"status": "affected",
"version": "397a7a24ef8c2967a3e8090013f9c54714110c48",
"versionType": "git"
},
{
"lessThan": "659a81b62a61440b85e02c09903be861ae7679e5",
"status": "affected",
"version": "397a7a24ef8c2967a3e8090013f9c54714110c48",
"versionType": "git"
},
{
"lessThan": "aa01ef0ebbc3289154229ef58e65baf289eb9789",
"status": "affected",
"version": "397a7a24ef8c2967a3e8090013f9c54714110c48",
"versionType": "git"
},
{
"lessThan": "be9dfcb0654c1f6c0fce7ba2a909683bb6f1e0ef",
"status": "affected",
"version": "397a7a24ef8c2967a3e8090013f9c54714110c48",
"versionType": "git"
},
{
"lessThan": "962f755a47d7ec3bbf6c709697d7f4c5f798441d",
"status": "affected",
"version": "397a7a24ef8c2967a3e8090013f9c54714110c48",
"versionType": "git"
},
{
"lessThan": "a424985c3ef2a87ce6057a853e18d0c441a86be8",
"status": "affected",
"version": "397a7a24ef8c2967a3e8090013f9c54714110c48",
"versionType": "git"
},
{
"lessThan": "4b8abf43bf34791c99d99dc3be13f897adefc461",
"status": "affected",
"version": "397a7a24ef8c2967a3e8090013f9c54714110c48",
"versionType": "git"
},
{
"lessThan": "f3858d5b1432098c1936e03d6e03dd0e33facf60",
"status": "affected",
"version": "397a7a24ef8c2967a3e8090013f9c54714110c48",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/mac80211/iface.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.9"
},
{
"lessThan": "3.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock\n\nieee80211_do_stop() removes AP_VLAN packets from the parent AP\nps-\u003ebc_buf while holding ps-\u003ebc_buf.lock with IRQs disabled. It then\ncalls ieee80211_free_txskb() before dropping the lock.\n\nieee80211_free_txskb() is not just a passive SKB release. For SKBs with\nTX status state it can report a dropped frame through cfg80211/nl80211,\nand that path can reach netlink tap transmit. This is the same reason\nthe pending queue cleanup in ieee80211_do_stop() already unlinks SKBs\nunder the queue lock and frees them after IRQ state is restored.\n\nThe buggy scenario involves two paths, with each column showing the\norder within that path:\n\nAP_VLAN management TX: AP_VLAN stop:\n1. attach ACK-status state 1. clear the running state\n2. queue a multicast SKB on 2. take ps-\u003ebc_buf.lock with IRQs\n parent ps-\u003ebc_buf disabled\n 3. unlink the AP_VLAN SKB\n 4. call ieee80211_free_txskb()\n\nUnlink matching AP_VLAN SKBs from ps-\u003ebc_buf under the existing lock,\nbut move them to a local free queue. Drop the lock and restore IRQ state\nbefore calling ieee80211_free_txskb().\n\nWARNING: kernel/softirq.c:430 at __local_bh_enable_ip"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:57.265Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/0d2619e708e2ef02ba1c91642ea261d3f19d8f9a"
},
{
"url": "https://git.kernel.org/stable/c/659a81b62a61440b85e02c09903be861ae7679e5"
},
{
"url": "https://git.kernel.org/stable/c/aa01ef0ebbc3289154229ef58e65baf289eb9789"
},
{
"url": "https://git.kernel.org/stable/c/be9dfcb0654c1f6c0fce7ba2a909683bb6f1e0ef"
},
{
"url": "https://git.kernel.org/stable/c/962f755a47d7ec3bbf6c709697d7f4c5f798441d"
},
{
"url": "https://git.kernel.org/stable/c/a424985c3ef2a87ce6057a853e18d0c441a86be8"
},
{
"url": "https://git.kernel.org/stable/c/4b8abf43bf34791c99d99dc3be13f897adefc461"
},
{
"url": "https://git.kernel.org/stable/c/f3858d5b1432098c1936e03d6e03dd0e33facf60"
}
],
"title": "wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68405",
"datePublished": "2026-08-10T12:04:25.241Z",
"dateReserved": "2026-07-30T09:28:09.390Z",
"dateUpdated": "2026-08-19T16:34:57.265Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64573 (GCVE-0-2026-64573)
Vulnerability from cvelistv5
Published
2026-08-05 08:08
Modified
2026-08-19 16:28
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: qca: fix NVM tag length underflow in TLV parser
In the TLV_TYPE_NVM branch of qca_tlv_check_data() the tag loop bound is
"while (idx < length - sizeof(struct tlv_type_nvm))". "length" is a signed
int from the firmware TLV header and sizeof(struct tlv_type_nvm) is a
size_t (12), so "length" is converted to size_t and any firmware-supplied
"length" < 12 makes the subtraction wrap to a huge value. The loop body
then reads a 12-byte struct tlv_type_nvm past the end of the short
vmalloc'd firmware buffer (and the EDL_TAG_ID_* handlers can write past it).
Rewrite the bound as "idx + sizeof(struct tlv_type_nvm) <= length"; both
operands are non-negative, so it no longer underflows and a "length" too
small for one record correctly skips the loop.
BUG: KASAN: vmalloc-out-of-bounds in qca_download_firmware.isra.0 (drivers/bluetooth/btqca.c:421)
Read of size 2 at addr ffffc900000e5004 by task kworker/u9:0/52
Workqueue: hci0 hci_power_on
Call Trace:
...
kasan_report (mm/kasan/report.c:595)
qca_download_firmware.isra.0 (drivers/bluetooth/btqca.c:421 drivers/bluetooth/btqca.c:617)
qca_uart_setup (drivers/bluetooth/btqca.c:948)
qca_setup (drivers/bluetooth/hci_qca.c:2029)
hci_uart_setup (drivers/bluetooth/hci_ldisc.c:438)
hci_dev_open_sync (net/bluetooth/hci_sync.c:5227)
hci_power_on (net/bluetooth/hci_core.c:920)
process_one_work (kernel/workqueue.c:3322)
worker_thread (kernel/workqueue.c:3486)
kthread (kernel/kthread.c:436)
ret_from_fork (arch/x86/kernel/process.c:158)
ret_from_fork_asm (arch/x86/entry/entry_64.S:245)
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ed53949cc92e28aaa3463d246942bda1fbb7f307 Version: 1caceadfb50432dbf6d808796cb6c34ebb6d662c Version: 427281f9498ed614f9aabc80e46ec077c487da6d Version: 2e4edfa1e2bd821a317e7d006517dcf2f3fac68d Version: 2e4edfa1e2bd821a317e7d006517dcf2f3fac68d Version: 2e4edfa1e2bd821a317e7d006517dcf2f3fac68d Version: 2e4edfa1e2bd821a317e7d006517dcf2f3fac68d Version: 02f05ed44b71152d5e11d29be28aed91c0489b4e Version: 5.15.159 ≤ Version: 6.1.91 ≤ Version: 6.6.31 ≤ Version: 6.8.10 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/bluetooth/btqca.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a7ee11441d71ab036a705d110a415421f5a4a898",
"status": "affected",
"version": "ed53949cc92e28aaa3463d246942bda1fbb7f307",
"versionType": "git"
},
{
"lessThan": "5d34e537755d2f9eba2d4e54d70126f987ef20b4",
"status": "affected",
"version": "1caceadfb50432dbf6d808796cb6c34ebb6d662c",
"versionType": "git"
},
{
"lessThan": "70354dbb5f72d9a76da7b031de3cbaf6c7d8fc24",
"status": "affected",
"version": "427281f9498ed614f9aabc80e46ec077c487da6d",
"versionType": "git"
},
{
"lessThan": "59fd2f075bca94f030c7c78e94878ea0803d7690",
"status": "affected",
"version": "2e4edfa1e2bd821a317e7d006517dcf2f3fac68d",
"versionType": "git"
},
{
"lessThan": "a087ed960fce54e9302796229e9d545bbc9bcd4a",
"status": "affected",
"version": "2e4edfa1e2bd821a317e7d006517dcf2f3fac68d",
"versionType": "git"
},
{
"lessThan": "4fcfb5b2c736785464ff9745f94c6726c5ee2d85",
"status": "affected",
"version": "2e4edfa1e2bd821a317e7d006517dcf2f3fac68d",
"versionType": "git"
},
{
"lessThan": "c90164ca0f7036942ba088eb7ea8d3f6c2352020",
"status": "affected",
"version": "2e4edfa1e2bd821a317e7d006517dcf2f3fac68d",
"versionType": "git"
},
{
"status": "affected",
"version": "02f05ed44b71152d5e11d29be28aed91c0489b4e",
"versionType": "git"
},
{
"lessThan": "5.15.216",
"status": "affected",
"version": "5.15.159",
"versionType": "semver"
},
{
"lessThan": "6.1.183",
"status": "affected",
"version": "6.1.91",
"versionType": "semver"
},
{
"lessThan": "6.6.148",
"status": "affected",
"version": "6.6.31",
"versionType": "semver"
},
{
"lessThan": "6.9",
"status": "affected",
"version": "6.8.10",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/bluetooth/btqca.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.9"
},
{
"lessThan": "6.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.15.159",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "6.1.91",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.6.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.8.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: qca: fix NVM tag length underflow in TLV parser\n\nIn the TLV_TYPE_NVM branch of qca_tlv_check_data() the tag loop bound is\n\"while (idx \u003c length - sizeof(struct tlv_type_nvm))\". \"length\" is a signed\nint from the firmware TLV header and sizeof(struct tlv_type_nvm) is a\nsize_t (12), so \"length\" is converted to size_t and any firmware-supplied\n\"length\" \u003c 12 makes the subtraction wrap to a huge value. The loop body\nthen reads a 12-byte struct tlv_type_nvm past the end of the short\nvmalloc\u0027d firmware buffer (and the EDL_TAG_ID_* handlers can write past it).\n\nRewrite the bound as \"idx + sizeof(struct tlv_type_nvm) \u003c= length\"; both\noperands are non-negative, so it no longer underflows and a \"length\" too\nsmall for one record correctly skips the loop.\n\n BUG: KASAN: vmalloc-out-of-bounds in qca_download_firmware.isra.0 (drivers/bluetooth/btqca.c:421)\n Read of size 2 at addr ffffc900000e5004 by task kworker/u9:0/52\n Workqueue: hci0 hci_power_on\n Call Trace:\n ...\n kasan_report (mm/kasan/report.c:595)\n qca_download_firmware.isra.0 (drivers/bluetooth/btqca.c:421 drivers/bluetooth/btqca.c:617)\n qca_uart_setup (drivers/bluetooth/btqca.c:948)\n qca_setup (drivers/bluetooth/hci_qca.c:2029)\n hci_uart_setup (drivers/bluetooth/hci_ldisc.c:438)\n hci_dev_open_sync (net/bluetooth/hci_sync.c:5227)\n hci_power_on (net/bluetooth/hci_core.c:920)\n process_one_work (kernel/workqueue.c:3322)\n worker_thread (kernel/workqueue.c:3486)\n kthread (kernel/kthread.c:436)\n ret_from_fork (arch/x86/kernel/process.c:158)\n ret_from_fork_asm (arch/x86/entry/entry_64.S:245)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:28:52.002Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a7ee11441d71ab036a705d110a415421f5a4a898"
},
{
"url": "https://git.kernel.org/stable/c/5d34e537755d2f9eba2d4e54d70126f987ef20b4"
},
{
"url": "https://git.kernel.org/stable/c/70354dbb5f72d9a76da7b031de3cbaf6c7d8fc24"
},
{
"url": "https://git.kernel.org/stable/c/59fd2f075bca94f030c7c78e94878ea0803d7690"
},
{
"url": "https://git.kernel.org/stable/c/a087ed960fce54e9302796229e9d545bbc9bcd4a"
},
{
"url": "https://git.kernel.org/stable/c/4fcfb5b2c736785464ff9745f94c6726c5ee2d85"
},
{
"url": "https://git.kernel.org/stable/c/c90164ca0f7036942ba088eb7ea8d3f6c2352020"
}
],
"title": "Bluetooth: qca: fix NVM tag length underflow in TLV parser",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64573",
"datePublished": "2026-08-05T08:08:09.669Z",
"dateReserved": "2026-07-19T15:36:31.797Z",
"dateUpdated": "2026-08-19T16:28:52.002Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72051 (GCVE-0-2026-72051)
Vulnerability from cvelistv5
Published
2026-08-15 05:52
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: ip6_tunnel: require CAP_NET_ADMIN in the device netns for changelink
ip6_tnl_changelink() operates on at most two netns, dev_net(dev) and the
tunnel link netns t->net. They differ once the device is created in or
moved to a netns other than the one the request runs in. The rtnl
changelink path checks CAP_NET_ADMIN only against dev_net(dev), so a
caller privileged there but not in t->net can rewrite a tunnel that
lives in t->net.
Gate ip6_tnl_changelink() on rtnl_dev_link_net_capable() at its top,
before any attribute is parsed.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 0bd8762824e73a3cce7b7560a97463301764b616 Version: 0bd8762824e73a3cce7b7560a97463301764b616 Version: 0bd8762824e73a3cce7b7560a97463301764b616 Version: 0bd8762824e73a3cce7b7560a97463301764b616 Version: 0bd8762824e73a3cce7b7560a97463301764b616 Version: 0bd8762824e73a3cce7b7560a97463301764b616 Version: 0bd8762824e73a3cce7b7560a97463301764b616 Version: 0bd8762824e73a3cce7b7560a97463301764b616 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ipv6/ip6_tunnel.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "2d53ee7daabe733deb81f51d2cc90188f8ad59a1",
"status": "affected",
"version": "0bd8762824e73a3cce7b7560a97463301764b616",
"versionType": "git"
},
{
"lessThan": "82e53e7281c71e174f9f5877c566a623c637b406",
"status": "affected",
"version": "0bd8762824e73a3cce7b7560a97463301764b616",
"versionType": "git"
},
{
"lessThan": "5252db8fb604321133138c7069d6fc3fcd89cdee",
"status": "affected",
"version": "0bd8762824e73a3cce7b7560a97463301764b616",
"versionType": "git"
},
{
"lessThan": "2636d061bc237a2446a146e42dcc6563acfa7432",
"status": "affected",
"version": "0bd8762824e73a3cce7b7560a97463301764b616",
"versionType": "git"
},
{
"lessThan": "7f68f7928484f463a5bc0d50e6fdd8d16f55a5aa",
"status": "affected",
"version": "0bd8762824e73a3cce7b7560a97463301764b616",
"versionType": "git"
},
{
"lessThan": "234cd54fc500f69db43e37de38603da617fbbeea",
"status": "affected",
"version": "0bd8762824e73a3cce7b7560a97463301764b616",
"versionType": "git"
},
{
"lessThan": "d4bcc202a3530c856e1cb183384bc9cc8fddab22",
"status": "affected",
"version": "0bd8762824e73a3cce7b7560a97463301764b616",
"versionType": "git"
},
{
"lessThan": "2496fa0b7d180b3ad356b514e7ff93bb14e6140a",
"status": "affected",
"version": "0bd8762824e73a3cce7b7560a97463301764b616",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ipv6/ip6_tunnel.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.12"
},
{
"lessThan": "3.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ip6_tunnel: require CAP_NET_ADMIN in the device netns for changelink\n\nip6_tnl_changelink() operates on at most two netns, dev_net(dev) and the\ntunnel link netns t-\u003enet. They differ once the device is created in or\nmoved to a netns other than the one the request runs in. The rtnl\nchangelink path checks CAP_NET_ADMIN only against dev_net(dev), so a\ncaller privileged there but not in t-\u003enet can rewrite a tunnel that\nlives in t-\u003enet.\n\nGate ip6_tnl_changelink() on rtnl_dev_link_net_capable() at its top,\nbefore any attribute is parsed."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires RTM_NEWLINK changelink over a local rtnetlink socket; ip6_tnl_changelink is only reachable from rtnl configuration, not from received IPv6 packets processed by ip6_tnl_rcv.\nAC:L - Once an ip6tnl device exists with t-\u003enet differing from dev_net(dev) (IFLA_LINK_NETNSID newlink or IFLA_NET_NS_FD migration), a single deterministic netlink changelink bypasses the missing check with no race or memory-layout dependency.\nPR:L - The rtnl entry path requires CAP_NET_ADMIN only in dev_net(dev), obtainable by an unprivileged local user via unshare --user --map-root-user --net; no CAP_NET_ADMIN in the sticky link netns t-\u003enet is required.\nUI:N - The attack is fully programmatic through netlink from the attacker\u0027s own process; no victim action such as mounting a filesystem, opening a file, or clicking is required.\nS:C - Authorization is checked against dev_net(dev) while ip6_tnl_changelink mutates tunnel state in t-\u003enet via ip6_tnl_update, crossing from the attacker\u0027s net/user namespace into another tenant\u0027s or the host\u0027s network namespace.\nC:H - An attacker can rewrite IFLA_IPTUN_LOCAL/REMOTE, link, fwmark, and encap parameters to redirect IPv6/IPv4-over-IPv6 tunnel traffic to an attacker-controlled endpoint and read all tunneled payloads in the victim link netns.\nI:H - Unauthorized changelink updates live tunnel endpoints, underlay link, encap ports, and flowinfo/fwmark in t-\u003enet, enabling redirection and injection of traffic carried over the ip6tnl tunnel.\nA:H - Rewriting tunnel remote/local addresses, underlay device, or encap parameters breaks cross-netns IPv6 tunnel connectivity, causing sustained loss of service for every workload depending on the affected ip6tnl tunnel."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:34.252Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/2d53ee7daabe733deb81f51d2cc90188f8ad59a1"
},
{
"url": "https://git.kernel.org/stable/c/82e53e7281c71e174f9f5877c566a623c637b406"
},
{
"url": "https://git.kernel.org/stable/c/5252db8fb604321133138c7069d6fc3fcd89cdee"
},
{
"url": "https://git.kernel.org/stable/c/2636d061bc237a2446a146e42dcc6563acfa7432"
},
{
"url": "https://git.kernel.org/stable/c/7f68f7928484f463a5bc0d50e6fdd8d16f55a5aa"
},
{
"url": "https://git.kernel.org/stable/c/234cd54fc500f69db43e37de38603da617fbbeea"
},
{
"url": "https://git.kernel.org/stable/c/d4bcc202a3530c856e1cb183384bc9cc8fddab22"
},
{
"url": "https://git.kernel.org/stable/c/2496fa0b7d180b3ad356b514e7ff93bb14e6140a"
}
],
"title": "net: ip6_tunnel: require CAP_NET_ADMIN in the device netns for changelink",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72051",
"datePublished": "2026-08-15T05:52:08.445Z",
"dateReserved": "2026-08-09T03:40:39.902Z",
"dateUpdated": "2026-08-23T12:46:34.252Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68096 (GCVE-0-2026-68096)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-23 12:45
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
audit: fix recursive locking deadlock in audit_dupe_exe()
A deadlock occurs in the audit subsystem when duplicating
executable-related rules.
When a file is moved (e.g., via do_renameat2()), the VFS layer locks
the parent directory (I_MUTEX_PARENT), which synchronously triggers an
fsnotify_move event. If an existing executable audit rule matches the
file being moved, the audit subsystem catches this event and calls
audit_dupe_exe() to duplicate the watch and update the rule. Then,
audit_alloc_mark() would call kern_path_parent() to resolve the path,
leading to a blind attempt to acquire the exact same I_MUTEX_PARENT lock
already held by the task, resulting in the following recursive locking
deadlock:
============================================
WARNING: possible recursive locking detected
6.12.0-55.27.1.el10_0.x86_64+debug #1 Not tainted
--------------------------------------------
mv/5099 is trying to acquire lock:
ffff888132845358 (&inode->i_sb->s_type->i_mutex_dir_key/1){+.+.}-{3:3},
at: __kern_path_locked+0x10a/0x2f0
but task is already holding lock:
ffff888132846b58 (&inode->i_sb->s_type->i_mutex_dir_key/1){+.+.}-{3:3},
at: lock_two_directories+0x13f/0x2b0
other info that might help us debug this:
Possible unsafe locking scenario:
CPU0
----
lock(&inode->i_sb->s_type->i_mutex_dir_key/1);
lock(&inode->i_sb->s_type->i_mutex_dir_key/1);
*** DEADLOCK ***
May be due to missing lock nesting notation
6 locks held by mv/5099:
#0: ffff888112a9c440 (sb_writers#13)
at: do_renameat2+0x34c/0xbc0
#1: ffff888112a9c790 (&type->s_vfs_rename_key#3)
at: do_renameat2+0x415/0xbc0
#2: ffff888132846b58 (&inode->i_sb->s_type->i_mutex_dir_key/1)
at: lock_two_directories+0x13f/0x2b0
#3: ffff888132845358 (&inode->i_sb->s_type->i_mutex_dir_key/5)
at: lock_two_directories+0x175/0x2b0
#4: ffffffffb3a1fb10 (&fsnotify_mark_srcu)
at: fsnotify+0x454/0x28a0
#5: ffffffffaf886230 (audit_filter_mutex)
at: audit_update_watch+0x36/0x11e0
stack backtrace:
Call Trace:
<TASK>
dump_stack_lvl+0x6f/0xb0
print_deadlock_bug.cold+0xbd/0xca
validate_chain+0x83a/0xf00
__lock_acquire+0xcac/0x1d20
lock_acquire.part.0+0x11b/0x360
down_write_nested+0x9f/0x230
__kern_path_locked+0x10a/0x2f0
kern_path_locked+0x26/0x40
audit_alloc_mark+0xfb/0x4f0
audit_dupe_exe+0x6c/0xe0
audit_dupe_rule+0x6c2/0xc00
audit_update_watch+0x4cc/0x11e0
audit_watch_handle_event+0x12c/0x1b0
send_to_group+0x5d0/0x8b0
fsnotify+0x615/0x28a0
fsnotify_move+0x1d8/0x630
vfs_rename+0xdcd/0x1df0
do_renameat2+0x9d4/0xbc0
__x64_sys_renameat+0x192/0x260
do_syscall_64+0x92/0x180
entry_SYSCALL_64_after_hwframe+0x76/0x7e
RIP: 0033:0x7f0491fe8c4e
Code: 0f 1f 40 00 48 8b 15 c1 e1 16 00 f7 d8 64 89 02 b8 ff ff ff ff
c3 66 0f 1f 44 00 00 f3 0f 1e fa 49 89 ca b8 08 01 00 00 0f 05 <48>
3d 00 f0 ff ff 77 0a c3 66 0f 1f 84 00 00 00 00 00 48 8b 15 89
RSP: 002b:00007ffc7210bf38 EFLAGS: 00000246 ORIG_RAX: 0000000000000108
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f0491fe8c4e
RDX: 0000000000000003 RSI: 00007ffc7210e6c8 RDI: 00000000ffffff9c
RBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000001
R10: 00005575eb2dae2a R11: 0000000000000246 R12: 00005575eb2dae2a
R13: 00007ffc7210e6c8 R14: 0000000000000003 R15: 00000000ffffff9c
</TASK>
The aforementioned deadlock can be consistently reproduced by running
the script below:
audit-dupe-exe-deadlock.sh
--------------------------
#!/bin/bash
auditctl -D
mkdir -p /tmp/foo
touch /tmp/file
auditctl -a always,exit -F exe=/tmp/file -F path=/tmp/file -S all -k dr
mv /tmp/file /tmp/foo/file
rm -Rf /tmp/foo
This patch fixes the issue by introducing struct audit_watch_ctx to pass
the fsnotify event context down to audit_alloc_mark(). By utilizing the
already-resolved directory inode provided by the event, we bypass the
kern_path_parent() path resol
---truncated---
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 34d99af52ad40bd498ba66970579a5bc1fb1a3bc Version: 34d99af52ad40bd498ba66970579a5bc1fb1a3bc Version: 34d99af52ad40bd498ba66970579a5bc1fb1a3bc Version: 34d99af52ad40bd498ba66970579a5bc1fb1a3bc Version: 34d99af52ad40bd498ba66970579a5bc1fb1a3bc Version: 34d99af52ad40bd498ba66970579a5bc1fb1a3bc Version: 34d99af52ad40bd498ba66970579a5bc1fb1a3bc Version: 34d99af52ad40bd498ba66970579a5bc1fb1a3bc |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"kernel/audit.h",
"kernel/audit_fsnotify.c",
"kernel/audit_watch.c",
"kernel/auditfilter.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "6114c3f21eb2ae175401736da744b684705e7ed9",
"status": "affected",
"version": "34d99af52ad40bd498ba66970579a5bc1fb1a3bc",
"versionType": "git"
},
{
"lessThan": "f6fda0ac6661c23b8356dfb1cc423960cc6f0593",
"status": "affected",
"version": "34d99af52ad40bd498ba66970579a5bc1fb1a3bc",
"versionType": "git"
},
{
"lessThan": "3bbb4931f7cd84cecf29ec222c0732bf9ad4da9f",
"status": "affected",
"version": "34d99af52ad40bd498ba66970579a5bc1fb1a3bc",
"versionType": "git"
},
{
"lessThan": "36eb77f14b4e6f2dc1008c1fabe31236397be27a",
"status": "affected",
"version": "34d99af52ad40bd498ba66970579a5bc1fb1a3bc",
"versionType": "git"
},
{
"lessThan": "7d1f66c69898ffb1a718926c32a777ecc471caca",
"status": "affected",
"version": "34d99af52ad40bd498ba66970579a5bc1fb1a3bc",
"versionType": "git"
},
{
"lessThan": "40879c39d6740f3dddfb52b5d6ba7fb8cceb84d8",
"status": "affected",
"version": "34d99af52ad40bd498ba66970579a5bc1fb1a3bc",
"versionType": "git"
},
{
"lessThan": "3b601938314c24fcd1afb6659cad92fe96c9c2f8",
"status": "affected",
"version": "34d99af52ad40bd498ba66970579a5bc1fb1a3bc",
"versionType": "git"
},
{
"lessThan": "81905b5acbe77284734438df3fbec1158e6429a3",
"status": "affected",
"version": "34d99af52ad40bd498ba66970579a5bc1fb1a3bc",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"kernel/audit.h",
"kernel/audit_fsnotify.c",
"kernel/audit_watch.c",
"kernel/auditfilter.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.3"
},
{
"lessThan": "4.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\naudit: fix recursive locking deadlock in audit_dupe_exe()\n\nA deadlock occurs in the audit subsystem when duplicating\nexecutable-related rules.\n\nWhen a file is moved (e.g., via do_renameat2()), the VFS layer locks\nthe parent directory (I_MUTEX_PARENT), which synchronously triggers an\nfsnotify_move event. If an existing executable audit rule matches the\nfile being moved, the audit subsystem catches this event and calls\naudit_dupe_exe() to duplicate the watch and update the rule. Then,\naudit_alloc_mark() would call kern_path_parent() to resolve the path,\nleading to a blind attempt to acquire the exact same I_MUTEX_PARENT lock\nalready held by the task, resulting in the following recursive locking\ndeadlock:\n\n ============================================\n WARNING: possible recursive locking detected\n 6.12.0-55.27.1.el10_0.x86_64+debug #1 Not tainted\n --------------------------------------------\n mv/5099 is trying to acquire lock:\n ffff888132845358 (\u0026inode-\u003ei_sb-\u003es_type-\u003ei_mutex_dir_key/1){+.+.}-{3:3},\n at: __kern_path_locked+0x10a/0x2f0\n\n but task is already holding lock:\n ffff888132846b58 (\u0026inode-\u003ei_sb-\u003es_type-\u003ei_mutex_dir_key/1){+.+.}-{3:3},\n at: lock_two_directories+0x13f/0x2b0\n\n other info that might help us debug this:\n Possible unsafe locking scenario:\n\n CPU0\n ----\n lock(\u0026inode-\u003ei_sb-\u003es_type-\u003ei_mutex_dir_key/1);\n lock(\u0026inode-\u003ei_sb-\u003es_type-\u003ei_mutex_dir_key/1);\n\n *** DEADLOCK ***\n\n May be due to missing lock nesting notation\n\n 6 locks held by mv/5099:\n #0: ffff888112a9c440 (sb_writers#13)\n at: do_renameat2+0x34c/0xbc0\n #1: ffff888112a9c790 (\u0026type-\u003es_vfs_rename_key#3)\n at: do_renameat2+0x415/0xbc0\n #2: ffff888132846b58 (\u0026inode-\u003ei_sb-\u003es_type-\u003ei_mutex_dir_key/1)\n at: lock_two_directories+0x13f/0x2b0\n #3: ffff888132845358 (\u0026inode-\u003ei_sb-\u003es_type-\u003ei_mutex_dir_key/5)\n at: lock_two_directories+0x175/0x2b0\n #4: ffffffffb3a1fb10 (\u0026fsnotify_mark_srcu)\n at: fsnotify+0x454/0x28a0\n #5: ffffffffaf886230 (audit_filter_mutex)\n at: audit_update_watch+0x36/0x11e0\n\n stack backtrace:\n Call Trace:\n \u003cTASK\u003e\n dump_stack_lvl+0x6f/0xb0\n print_deadlock_bug.cold+0xbd/0xca\n validate_chain+0x83a/0xf00\n __lock_acquire+0xcac/0x1d20\n lock_acquire.part.0+0x11b/0x360\n down_write_nested+0x9f/0x230\n __kern_path_locked+0x10a/0x2f0\n kern_path_locked+0x26/0x40\n audit_alloc_mark+0xfb/0x4f0\n audit_dupe_exe+0x6c/0xe0\n audit_dupe_rule+0x6c2/0xc00\n audit_update_watch+0x4cc/0x11e0\n audit_watch_handle_event+0x12c/0x1b0\n send_to_group+0x5d0/0x8b0\n fsnotify+0x615/0x28a0\n fsnotify_move+0x1d8/0x630\n vfs_rename+0xdcd/0x1df0\n do_renameat2+0x9d4/0xbc0\n __x64_sys_renameat+0x192/0x260\n do_syscall_64+0x92/0x180\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n RIP: 0033:0x7f0491fe8c4e\n Code: 0f 1f 40 00 48 8b 15 c1 e1 16 00 f7 d8 64 89 02 b8 ff ff ff ff\n c3 66 0f 1f 44 00 00 f3 0f 1e fa 49 89 ca b8 08 01 00 00 0f 05 \u003c48\u003e\n 3d 00 f0 ff ff 77 0a c3 66 0f 1f 84 00 00 00 00 00 48 8b 15 89\n RSP: 002b:00007ffc7210bf38 EFLAGS: 00000246 ORIG_RAX: 0000000000000108\n RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f0491fe8c4e\n RDX: 0000000000000003 RSI: 00007ffc7210e6c8 RDI: 00000000ffffff9c\n RBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000001\n R10: 00005575eb2dae2a R11: 0000000000000246 R12: 00005575eb2dae2a\n R13: 00007ffc7210e6c8 R14: 0000000000000003 R15: 00000000ffffff9c\n \u003c/TASK\u003e\n\nThe aforementioned deadlock can be consistently reproduced by running\nthe script below:\n\n audit-dupe-exe-deadlock.sh\n --------------------------\n #!/bin/bash\n auditctl -D\n mkdir -p /tmp/foo\n touch /tmp/file\n auditctl -a always,exit -F exe=/tmp/file -F path=/tmp/file -S all -k dr\n mv /tmp/file /tmp/foo/file\n rm -Rf /tmp/foo\n\nThis patch fixes the issue by introducing struct audit_watch_ctx to pass\nthe fsnotify event context down to audit_alloc_mark(). By utilizing the\nalready-resolved directory inode provided by the event, we bypass the\nkern_path_parent() path resol\n---truncated---"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The deadlock is triggered when vfs_rename() emits fsnotify_move() during rename processing; on NFS (nfsd) and SMB (ksmbd) servers a remote client rename request reaches this same synchronous audit_update_watch()-\u003eaudit_dupe_exe()-\u003eaudit_alloc_mark()-\u003ekern_path_parent() path, not only local renameat().\nAC:L - Once an audit rule combining exe= and path= watches exists, the fix commit shows the recursive directory-lock deadlock is consistently reproduced by a simple rename/move; the attacker controls when the rename occurs and no race or special memory layout is required.\nPR:N - Triggering requires only the ability to rename the watched file on a local or network-exported path; a remote NFS/SMB client can issue that rename without local shell access, CAP_AUDIT_CONTROL, or other elevated server-side Unix privileges beyond export write access.\nUI:N - No victim interaction is required; the attacker or any client performing the rename directly invokes the vulnerable fsnotify/audit path without needing another user to open files, click links, or mount filesystems.\nS:U - Impact is confined to the vulnerable kernel host where the rename is processed (task hang/deadlock during audit rule update); it does not cross VM, IOMMU, or sandbox security boundaries.\nC:N - This is a recursive mutex deadlock with no memory corruption, out-of-bounds access, or use-after-free; no attacker-controlled information disclosure occurs beyond optional lockdep diagnostics on debug kernels.\nI:N - The bug does not modify kernel or user data and provides no write primitive or code-execution path; it only deadlocks the calling context while holding VFS directory locks and audit_filter_mutex.\nA:H - The vulnerability causes a deterministic recursive locking deadlock that permanently hangs the rename task while holding directory inode locks and audit_filter_mutex, denying that operation and potentially blocking audit processing and directory operations system-wide."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:45:47.969Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/6114c3f21eb2ae175401736da744b684705e7ed9"
},
{
"url": "https://git.kernel.org/stable/c/f6fda0ac6661c23b8356dfb1cc423960cc6f0593"
},
{
"url": "https://git.kernel.org/stable/c/3bbb4931f7cd84cecf29ec222c0732bf9ad4da9f"
},
{
"url": "https://git.kernel.org/stable/c/36eb77f14b4e6f2dc1008c1fabe31236397be27a"
},
{
"url": "https://git.kernel.org/stable/c/7d1f66c69898ffb1a718926c32a777ecc471caca"
},
{
"url": "https://git.kernel.org/stable/c/40879c39d6740f3dddfb52b5d6ba7fb8cceb84d8"
},
{
"url": "https://git.kernel.org/stable/c/3b601938314c24fcd1afb6659cad92fe96c9c2f8"
},
{
"url": "https://git.kernel.org/stable/c/81905b5acbe77284734438df3fbec1158e6429a3"
}
],
"title": "audit: fix recursive locking deadlock in audit_dupe_exe()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68096",
"datePublished": "2026-08-10T11:58:09.951Z",
"dateReserved": "2026-07-30T09:28:09.368Z",
"dateUpdated": "2026-08-23T12:45:47.969Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68442 (GCVE-0-2026-68442)
Vulnerability from cvelistv5
Published
2026-08-12 00:07
Modified
2026-08-17 05:05
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
btrfs: don't propagate EXTENT_FLAG_LOGGING to split extent maps
When btrfs_drop_extent_map_range() splits an extent map, the new split
maps inherit the original map's flags through a local 'flags' variable.
Commit f86f7a75e2fb ("btrfs: use the flags of an extent map to identify
the compression type") changed the EXTENT_FLAG_LOGGING clearing to
operate on em->flags instead of that local 'flags' copy, so a split of
an extent map that is currently being logged wrongly inherits
EXTENT_FLAG_LOGGING.
The flag is then never cleared on the split, and when it is freed while
still on the inode's modified_extents list (for example by the extent
map shrinker) it trips the WARN_ON(!list_empty(&em->list)) in
btrfs_free_extent_map() and leads to a use-after-free.
Clear EXTENT_FLAG_LOGGING from the local 'flags' copy used for the
splits and only clear EXTENT_FLAG_PINNED from em->flags, restoring the
behaviour prior to f86f7a75e2fb.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/btrfs/extent_map.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "2a9246a424f45f33a1b8367052611ebe874868ad",
"status": "affected",
"version": "f86f7a75e2fb5fd7d31d00eab8a392f97ba42ce9",
"versionType": "git"
},
{
"lessThan": "9304713b70e7e1450e3a76e758836fe5391bfa95",
"status": "affected",
"version": "f86f7a75e2fb5fd7d31d00eab8a392f97ba42ce9",
"versionType": "git"
},
{
"lessThan": "0e465c63f103a5ce6849614d6bda048d70eebec8",
"status": "affected",
"version": "f86f7a75e2fb5fd7d31d00eab8a392f97ba42ce9",
"versionType": "git"
},
{
"lessThan": "5eff4d5b17fa1950e80bfd1ba43dc0699e61a644",
"status": "affected",
"version": "f86f7a75e2fb5fd7d31d00eab8a392f97ba42ce9",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/btrfs/extent_map.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.8"
},
{
"lessThan": "6.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: don\u0027t propagate EXTENT_FLAG_LOGGING to split extent maps\n\nWhen btrfs_drop_extent_map_range() splits an extent map, the new split\nmaps inherit the original map\u0027s flags through a local \u0027flags\u0027 variable.\nCommit f86f7a75e2fb (\"btrfs: use the flags of an extent map to identify\nthe compression type\") changed the EXTENT_FLAG_LOGGING clearing to\noperate on em-\u003eflags instead of that local \u0027flags\u0027 copy, so a split of\nan extent map that is currently being logged wrongly inherits\nEXTENT_FLAG_LOGGING.\n\nThe flag is then never cleared on the split, and when it is freed while\nstill on the inode\u0027s modified_extents list (for example by the extent\nmap shrinker) it trips the WARN_ON(!list_empty(\u0026em-\u003elist)) in\nbtrfs_free_extent_map() and leads to a use-after-free.\n\nClear EXTENT_FLAG_LOGGING from the local \u0027flags\u0027 copy used for the\nsplits and only clear EXTENT_FLAG_PINNED from em-\u003eflags, restoring the\nbehaviour prior to f86f7a75e2fb."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is in the btrfs in-memory extent map code, reached only through local file operations (write/writeback, fallocate punch hole, truncate, clone, fsync) on a btrfs filesystem; no remote protocol data is involved.\nAC:L - Although the flag is only mis-propagated while an fsync has an extent map flagged for logging, the attacker controls both sides of the race - one thread loops fsync() while another loops writes/punch-hole on the same file - and the resulting bogus map is then freed deterministically by any later drop of that range.\nPR:L - Any unprivileged local user who can create and write a file on a btrfs filesystem (btrfs is the default root fs on several major distros, and /tmp or a home directory suffices) can drive the splitting and logging paths; no capabilities are required.\nUI:N - The attacker performs all the required operations itself (write, punch hole, fsync on its own file); no victim action or administrator involvement is needed.\nS:U - The corruption is confined to kernel memory within the same security authority; there is no crossing of a VM, IOMMU, or other boundary.\nC:H - The freed extent_map stays linked in the inode\u0027s modified_extents list, so later traversal in btrfs_log_changed_extents() dereferences freed slab memory; an attacker who reallocates the object controls what is read back, giving a use-after-free read primitive usable to disclose kernel memory.\nI:H - The dangling list node is written through by list_del_init()/list_add_tail() during fsync, writing attacker-influenced pointers into and from a freed heap object; such list-corruption use-after-frees are the classic basis for arbitrary write and privilege escalation.\nA:H - The bug already trips WARN_ON(!list_empty(\u0026em-\u003elist)) and then operates on freed memory, causing list corruption and an oops or panic (immediately fatal with panic_on_warn or list debugging enabled), which an unprivileged user can trigger repeatedly."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:05:39.676Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/2a9246a424f45f33a1b8367052611ebe874868ad"
},
{
"url": "https://git.kernel.org/stable/c/9304713b70e7e1450e3a76e758836fe5391bfa95"
},
{
"url": "https://git.kernel.org/stable/c/0e465c63f103a5ce6849614d6bda048d70eebec8"
},
{
"url": "https://git.kernel.org/stable/c/5eff4d5b17fa1950e80bfd1ba43dc0699e61a644"
}
],
"title": "btrfs: don\u0027t propagate EXTENT_FLAG_LOGGING to split extent maps",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68442",
"datePublished": "2026-08-12T00:07:31.981Z",
"dateReserved": "2026-07-30T09:28:09.394Z",
"dateUpdated": "2026-08-17T05:05:39.676Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68307 (GCVE-0-2026-68307)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-17 05:02
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: mt76: mt7925: fix crash in reset link replay
During reset recovery, mt7925_vif_connect_iter() replays firmware state
for links tracked in mvif->valid_links. After MLO link changes or MCU
timeout recovery, the driver bitmap can temporarily contain a link whose
mac80211 bss_conf has already gone away.
This can pass a NULL bss_conf to mt76_connac_mcu_uni_add_dev(), matching
the crash where x1, the second argument, is NULL:
pc : mt76_connac_mcu_uni_add_dev+0x8c/0x1f8 [mt76_connac_lib]
lr : mt7925_vif_connect_iter+0x9c/0x168 [mt7925_common]
x2 : ffffff80a77f6018 x1 : 0000000000000000 x0 : ffffff8099402080
Call trace:
mt76_connac_mcu_uni_add_dev+0x8c/0x1f8 [mt76_connac_lib]
mt7925_vif_connect_iter+0x9c/0x168 [mt7925_common]
mt7925_mac_reset_work+0x264/0x2f8 [mt7925_common]
Skip missing bss_conf entries before replaying the link. Non-MLO AP/STA
reset replay is unchanged because the helper still returns &vif->bss_conf
for the legacy link.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/mediatek/mt76/mt7925/mac.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "d9326796a378f80be5f9fd60983c62fdccdf2f0b",
"status": "affected",
"version": "14061994184df6bb89cba31657ee1db24480e92a",
"versionType": "git"
},
{
"lessThan": "95b0cf02731c74e073ef8937f5526bd4442a0326",
"status": "affected",
"version": "14061994184df6bb89cba31657ee1db24480e92a",
"versionType": "git"
},
{
"lessThan": "89d03bda560d635f66d495f37b46a187fd4edfdf",
"status": "affected",
"version": "14061994184df6bb89cba31657ee1db24480e92a",
"versionType": "git"
},
{
"lessThan": "bd8b2ec838184236c3fcbf738a926328836adf12",
"status": "affected",
"version": "14061994184df6bb89cba31657ee1db24480e92a",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/mediatek/mt76/mt7925/mac.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.11"
},
{
"lessThan": "6.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7925: fix crash in reset link replay\n\nDuring reset recovery, mt7925_vif_connect_iter() replays firmware state\nfor links tracked in mvif-\u003evalid_links. After MLO link changes or MCU\ntimeout recovery, the driver bitmap can temporarily contain a link whose\nmac80211 bss_conf has already gone away.\n\nThis can pass a NULL bss_conf to mt76_connac_mcu_uni_add_dev(), matching\nthe crash where x1, the second argument, is NULL:\n\npc : mt76_connac_mcu_uni_add_dev+0x8c/0x1f8 [mt76_connac_lib]\nlr : mt7925_vif_connect_iter+0x9c/0x168 [mt7925_common]\nx2 : ffffff80a77f6018 x1 : 0000000000000000 x0 : ffffff8099402080\nCall trace:\nmt76_connac_mcu_uni_add_dev+0x8c/0x1f8 [mt76_connac_lib]\nmt7925_vif_connect_iter+0x9c/0x168 [mt7925_common]\nmt7925_mac_reset_work+0x264/0x2f8 [mt7925_common]\n\nSkip missing bss_conf entries before replaying the link. Non-MLO AP/STA\nreset replay is unchanged because the helper still returns \u0026vif-\u003ebss_conf\nfor the legacy link."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:02:59.698Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/d9326796a378f80be5f9fd60983c62fdccdf2f0b"
},
{
"url": "https://git.kernel.org/stable/c/95b0cf02731c74e073ef8937f5526bd4442a0326"
},
{
"url": "https://git.kernel.org/stable/c/89d03bda560d635f66d495f37b46a187fd4edfdf"
},
{
"url": "https://git.kernel.org/stable/c/bd8b2ec838184236c3fcbf738a926328836adf12"
}
],
"title": "wifi: mt76: mt7925: fix crash in reset link replay",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68307",
"datePublished": "2026-08-10T12:02:41.904Z",
"dateReserved": "2026-07-30T09:28:09.381Z",
"dateUpdated": "2026-08-17T05:02:59.698Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68395 (GCVE-0-2026-68395)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is registered
sata_dwc_enable_interrupts() is called before platform_get_irq() and
ata_host_activate(), leaving the SATA controller's interrupt mask
enabled without a registered handler. If a later step fails (irq
request, phy init, etc.) or if the controller asserts an interrupt
during probe, the irq line may fire with no handler, causing a
spurious interrupt storm.
Move sata_dwc_enable_interrupts() after ata_host_activate() so that
interrupts are only unmasked once the handler is registered and the
core is fully initialized.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 62936009f35a6659cc3ebe0d90c754182d60da73 Version: 62936009f35a6659cc3ebe0d90c754182d60da73 Version: 62936009f35a6659cc3ebe0d90c754182d60da73 Version: 62936009f35a6659cc3ebe0d90c754182d60da73 Version: 62936009f35a6659cc3ebe0d90c754182d60da73 Version: 62936009f35a6659cc3ebe0d90c754182d60da73 Version: 62936009f35a6659cc3ebe0d90c754182d60da73 Version: 62936009f35a6659cc3ebe0d90c754182d60da73 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/ata/sata_dwc_460ex.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "60b922442e9c208832e2699f128ef078f9f50faa",
"status": "affected",
"version": "62936009f35a6659cc3ebe0d90c754182d60da73",
"versionType": "git"
},
{
"lessThan": "d031957a6284e03c709f95cb8fc6f8891d4432ba",
"status": "affected",
"version": "62936009f35a6659cc3ebe0d90c754182d60da73",
"versionType": "git"
},
{
"lessThan": "8fbad29f399ba11c3b070ef5baf1c4b3e13ed838",
"status": "affected",
"version": "62936009f35a6659cc3ebe0d90c754182d60da73",
"versionType": "git"
},
{
"lessThan": "fbe7df5d3a3aed2456667a4825e4ff98d6df6ca4",
"status": "affected",
"version": "62936009f35a6659cc3ebe0d90c754182d60da73",
"versionType": "git"
},
{
"lessThan": "23d4c50fdc0dfe3ad4f9647a3b7d486de807dcda",
"status": "affected",
"version": "62936009f35a6659cc3ebe0d90c754182d60da73",
"versionType": "git"
},
{
"lessThan": "daa80b422ed920a3c0c45153020b0ad7af7fb5a5",
"status": "affected",
"version": "62936009f35a6659cc3ebe0d90c754182d60da73",
"versionType": "git"
},
{
"lessThan": "5d0797d6940b8dc894f950c52f7af0b42cb55ed0",
"status": "affected",
"version": "62936009f35a6659cc3ebe0d90c754182d60da73",
"versionType": "git"
},
{
"lessThan": "4bbc16a353a98023e5ddfca7c1fc0e49971cf4d0",
"status": "affected",
"version": "62936009f35a6659cc3ebe0d90c754182d60da73",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/ata/sata_dwc_460ex.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.36"
},
{
"lessThan": "2.6.36",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.36",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.36",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.36",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.36",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.36",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.36",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.36",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.36",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is registered\n\nsata_dwc_enable_interrupts() is called before platform_get_irq() and\nata_host_activate(), leaving the SATA controller\u0027s interrupt mask\nenabled without a registered handler. If a later step fails (irq\nrequest, phy init, etc.) or if the controller asserts an interrupt\nduring probe, the irq line may fire with no handler, causing a\nspurious interrupt storm.\n\nMove sata_dwc_enable_interrupts() after ata_host_activate() so that\ninterrupts are only unmasked once the handler is registered and the\ncore is fully initialized."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:45.284Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/60b922442e9c208832e2699f128ef078f9f50faa"
},
{
"url": "https://git.kernel.org/stable/c/d031957a6284e03c709f95cb8fc6f8891d4432ba"
},
{
"url": "https://git.kernel.org/stable/c/8fbad29f399ba11c3b070ef5baf1c4b3e13ed838"
},
{
"url": "https://git.kernel.org/stable/c/fbe7df5d3a3aed2456667a4825e4ff98d6df6ca4"
},
{
"url": "https://git.kernel.org/stable/c/23d4c50fdc0dfe3ad4f9647a3b7d486de807dcda"
},
{
"url": "https://git.kernel.org/stable/c/daa80b422ed920a3c0c45153020b0ad7af7fb5a5"
},
{
"url": "https://git.kernel.org/stable/c/5d0797d6940b8dc894f950c52f7af0b42cb55ed0"
},
{
"url": "https://git.kernel.org/stable/c/4bbc16a353a98023e5ddfca7c1fc0e49971cf4d0"
}
],
"title": "ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is registered",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68395",
"datePublished": "2026-08-10T12:04:14.545Z",
"dateReserved": "2026-07-30T09:28:09.389Z",
"dateUpdated": "2026-08-19T16:34:45.284Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68373 (GCVE-0-2026-68373)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: at76c50x-usb: avoid length underflow in at76_guess_freq()
at76_guess_freq() checks only that the received frame is at least a bare
802.11 header (24 bytes) before subtracting the fixed management-body
offset:
len -= el_off;
For both beacon and probe response frames, el_off is 36. If the frame is
shorter than el_off, subtracting it causes the calculated IE length to
wrap. The length is eventually passed to cfg80211_find_elem_match() as a
very large unsigned value, so the element walk runs beyond the RX skb.
This path is reached from at76_rx_tasklet() while scanning. If the device
delivers a truncated beacon or probe response, the oversized IE length
causes an out-of-bounds read during scanning.
Skip the IE lookup if the frame does not reach the variable elements,
before subtracting el_off.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1264b951463a00efebe1bb596499aaad620ec8af Version: 1264b951463a00efebe1bb596499aaad620ec8af Version: 1264b951463a00efebe1bb596499aaad620ec8af Version: 1264b951463a00efebe1bb596499aaad620ec8af Version: 1264b951463a00efebe1bb596499aaad620ec8af Version: 1264b951463a00efebe1bb596499aaad620ec8af Version: 1264b951463a00efebe1bb596499aaad620ec8af Version: 1264b951463a00efebe1bb596499aaad620ec8af |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/atmel/at76c50x-usb.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "cb831aff2f850f72bc5ff5ad77d0a70bb5a84061",
"status": "affected",
"version": "1264b951463a00efebe1bb596499aaad620ec8af",
"versionType": "git"
},
{
"lessThan": "4875680d1703f56afa6257ba30244f2fb44ed205",
"status": "affected",
"version": "1264b951463a00efebe1bb596499aaad620ec8af",
"versionType": "git"
},
{
"lessThan": "b406f33d234f98c8b310fdab5cbb492d85e98e49",
"status": "affected",
"version": "1264b951463a00efebe1bb596499aaad620ec8af",
"versionType": "git"
},
{
"lessThan": "e165a1d295e7e814e13b0f92c86e5d48309509ce",
"status": "affected",
"version": "1264b951463a00efebe1bb596499aaad620ec8af",
"versionType": "git"
},
{
"lessThan": "bcde7249d45f52f994a9872bedf45994472ade77",
"status": "affected",
"version": "1264b951463a00efebe1bb596499aaad620ec8af",
"versionType": "git"
},
{
"lessThan": "fb1b50ab699211e777dca5ccfb648788b6a6e519",
"status": "affected",
"version": "1264b951463a00efebe1bb596499aaad620ec8af",
"versionType": "git"
},
{
"lessThan": "f742d9c98b5c504fc9e6744eef13a721c2aea486",
"status": "affected",
"version": "1264b951463a00efebe1bb596499aaad620ec8af",
"versionType": "git"
},
{
"lessThan": "61a799ffd1e5a4fd3702d547828b7ff3d161468e",
"status": "affected",
"version": "1264b951463a00efebe1bb596499aaad620ec8af",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/atmel/at76c50x-usb.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.30"
},
{
"lessThan": "2.6.30",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.30",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: at76c50x-usb: avoid length underflow in at76_guess_freq()\n\nat76_guess_freq() checks only that the received frame is at least a bare\n802.11 header (24 bytes) before subtracting the fixed management-body\noffset:\n\n\tlen -= el_off;\n\nFor both beacon and probe response frames, el_off is 36. If the frame is\nshorter than el_off, subtracting it causes the calculated IE length to\nwrap. The length is eventually passed to cfg80211_find_elem_match() as a\nvery large unsigned value, so the element walk runs beyond the RX skb.\n\nThis path is reached from at76_rx_tasklet() while scanning. If the device\ndelivers a truncated beacon or probe response, the oversized IE length\ncauses an out-of-bounds read during scanning.\n\nSkip the IE lookup if the frame does not reach the variable elements,\nbefore subtracting el_off."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The malformed frame is an over-the-air 802.11 beacon or probe response received by the at76c50x USB WLAN dongle and parsed in at76_rx_tasklet(); an attacker only needs to be within radio range of the victim, which is the adjacent-network (WiFi frame injection) case.\nAC:L - The attacker simply transmits a beacon/probe response whose body is shorter than the 36-byte fixed management offset with a valid FCS, and can repeat it continuously or answer the victim\u0027s probe requests during the routine scans that set priv-\u003escanning, so triggering is reliable and fully attacker-timed.\nPR:N - No authentication, association, or any local privilege is required; the frame is parsed during scanning before any association or key exchange, so an entirely unauthenticated radio-range attacker reaches the bug.\nUI:N - Background and periodic scans are issued automatically by wpa_supplicant/NetworkManager without any user action, so no victim interaction is needed for the vulnerable path to run.\nS:U - The out-of-bounds read stays within the kernel\u0027s own memory and security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - The underflowed length becomes ~4GB when widened to unsigned int, so the element walk reads far past the ~2.5KB RX skb slab object, and the out-of-bounds byte taken as el[2] is turned into rx_status.freq that userspace observes in scan results, allowing repeated frames to leak adjacent kernel heap contents.\nI:N - The defect is purely a read overrun; nothing outside the skb is written and the only attacker-influenced value is the reported channel/frequency, giving no memory-corruption or control-flow primitive.\nA:H - The unbounded element walk runs off the slab and can dereference unmapped memory while executing in tasklet/softirq context, producing a kernel oops or panic that the attacker can trigger repeatedly with injected frames."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:33.308Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/cb831aff2f850f72bc5ff5ad77d0a70bb5a84061"
},
{
"url": "https://git.kernel.org/stable/c/4875680d1703f56afa6257ba30244f2fb44ed205"
},
{
"url": "https://git.kernel.org/stable/c/b406f33d234f98c8b310fdab5cbb492d85e98e49"
},
{
"url": "https://git.kernel.org/stable/c/e165a1d295e7e814e13b0f92c86e5d48309509ce"
},
{
"url": "https://git.kernel.org/stable/c/bcde7249d45f52f994a9872bedf45994472ade77"
},
{
"url": "https://git.kernel.org/stable/c/fb1b50ab699211e777dca5ccfb648788b6a6e519"
},
{
"url": "https://git.kernel.org/stable/c/f742d9c98b5c504fc9e6744eef13a721c2aea486"
},
{
"url": "https://git.kernel.org/stable/c/61a799ffd1e5a4fd3702d547828b7ff3d161468e"
}
],
"title": "wifi: at76c50x-usb: avoid length underflow in at76_guess_freq()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68373",
"datePublished": "2026-08-10T12:03:51.663Z",
"dateReserved": "2026-07-30T09:28:09.386Z",
"dateUpdated": "2026-08-19T16:34:33.308Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64563 (GCVE-0-2026-64563)
Vulnerability from cvelistv5
Published
2026-08-04 06:23
Modified
2026-08-19 16:28
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
rhashtable: clear stale iter->p on table restart
rhashtable_walk_start_check() has two restart paths when resuming a walk.
When iter->walker.tbl is valid, it re-validates iter->p against the table
and sets iter->p = NULL if the object is gone. When iter->walker.tbl is
NULL (table was freed during resize), it resets slot and skip but forgets
to clear iter->p.
rhashtable_walk_next() then dereferences the stale iter->p, reading
freed memory. This is a use-after-free.
Any caller that does multi-fragment rhashtable walks across
walk_stop/walk_start boundaries is affected. Concrete cases include
netlink_diag (__netlink_diag_dump in net/netlink/diag.c) and TIPC
(tipc_nl_sk_walk in net/tipc/socket.c).
Crash stack (netlink_diag):
BUG: KASAN: slab-use-after-free in rhashtable_walk_next+0x365/0x3c0
Read of size 8 at addr ffff88801a9d2438 (freed kmalloc-2k, offset 1080)
Call Trace:
rhashtable_walk_next+0x365/0x3c0 (lib/rhashtable.c:1016)
__netlink_diag_dump+0x160/0x760 (net/netlink/diag.c:122)
netlink_diag_dump+0xc2/0x240
netlink_dump+0x5bc/0x1270
netlink_recvmsg+0x7a3/0x980
sock_recvmsg+0x1bc/0x200
__sys_recvfrom+0x1d4/0x2c0
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 5d240a8936f6a1d3ece06701e8c4d830a2eca8a8 Version: 5d240a8936f6a1d3ece06701e8c4d830a2eca8a8 Version: 5d240a8936f6a1d3ece06701e8c4d830a2eca8a8 Version: 5d240a8936f6a1d3ece06701e8c4d830a2eca8a8 Version: 5d240a8936f6a1d3ece06701e8c4d830a2eca8a8 Version: 5d240a8936f6a1d3ece06701e8c4d830a2eca8a8 Version: 5d240a8936f6a1d3ece06701e8c4d830a2eca8a8 Version: 5d240a8936f6a1d3ece06701e8c4d830a2eca8a8 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"lib/rhashtable.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ba510b5e9fe396497d31162acb579f210adfe6c8",
"status": "affected",
"version": "5d240a8936f6a1d3ece06701e8c4d830a2eca8a8",
"versionType": "git"
},
{
"lessThan": "a0406c40c6638c5ae50257db6297b2fba6c9ba16",
"status": "affected",
"version": "5d240a8936f6a1d3ece06701e8c4d830a2eca8a8",
"versionType": "git"
},
{
"lessThan": "0955b65c2b47c30b439e2cf1b1e375073aa0413a",
"status": "affected",
"version": "5d240a8936f6a1d3ece06701e8c4d830a2eca8a8",
"versionType": "git"
},
{
"lessThan": "c39643ad99fea749be50615550e8f0e6d6e60694",
"status": "affected",
"version": "5d240a8936f6a1d3ece06701e8c4d830a2eca8a8",
"versionType": "git"
},
{
"lessThan": "042fda5c088015f18838e5c692659a7be60aeb26",
"status": "affected",
"version": "5d240a8936f6a1d3ece06701e8c4d830a2eca8a8",
"versionType": "git"
},
{
"lessThan": "3ff7c1dbf722cf3fa538672452ba182318e0fcc3",
"status": "affected",
"version": "5d240a8936f6a1d3ece06701e8c4d830a2eca8a8",
"versionType": "git"
},
{
"lessThan": "4169d9fb92f313ff8e7e83d733c1ecdcc93eebd3",
"status": "affected",
"version": "5d240a8936f6a1d3ece06701e8c4d830a2eca8a8",
"versionType": "git"
},
{
"lessThan": "8173f7e2ce67e6ca1d4763f3da14e5b01ce77456",
"status": "affected",
"version": "5d240a8936f6a1d3ece06701e8c4d830a2eca8a8",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"lib/rhashtable.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.18"
},
{
"lessThan": "4.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.18",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nrhashtable: clear stale iter-\u003ep on table restart\n\nrhashtable_walk_start_check() has two restart paths when resuming a walk.\nWhen iter-\u003ewalker.tbl is valid, it re-validates iter-\u003ep against the table\nand sets iter-\u003ep = NULL if the object is gone. When iter-\u003ewalker.tbl is\nNULL (table was freed during resize), it resets slot and skip but forgets\nto clear iter-\u003ep.\n\nrhashtable_walk_next() then dereferences the stale iter-\u003ep, reading\nfreed memory. This is a use-after-free.\n\nAny caller that does multi-fragment rhashtable walks across\nwalk_stop/walk_start boundaries is affected. Concrete cases include\nnetlink_diag (__netlink_diag_dump in net/netlink/diag.c) and TIPC\n(tipc_nl_sk_walk in net/tipc/socket.c).\n\nCrash stack (netlink_diag):\n BUG: KASAN: slab-use-after-free in rhashtable_walk_next+0x365/0x3c0\n Read of size 8 at addr ffff88801a9d2438 (freed kmalloc-2k, offset 1080)\n Call Trace:\n rhashtable_walk_next+0x365/0x3c0 (lib/rhashtable.c:1016)\n __netlink_diag_dump+0x160/0x760 (net/netlink/diag.c:122)\n netlink_diag_dump+0xc2/0x240\n netlink_dump+0x5bc/0x1270\n netlink_recvmsg+0x7a3/0x980\n sock_recvmsg+0x1bc/0x200\n __sys_recvfrom+0x1d4/0x2c0"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Triggered via local netlink sock_diag dumps (e.g. netlink_diag over NETLINK_SOCK_DIAG) and similar local dump walkers such as TIPC_NL_SOCK_GET; not reachable from remote packet processing.\nAC:L - Attacker controls both sides of the race by running a multi-fragment rhashtable dump while concurrently creating/destroying netlink (or TIPC) sockets to force table resize and free the walked object.\nPR:L - An unprivileged local user can open NETLINK_SOCK_DIAG and dump without CAP_NET_ADMIN; CAP_NET_ADMIN is only required for SOCK_DESTROY, and TIPC_NL_SOCK_GET likewise has no admin permission flag.\nUI:N - Exploitation requires only attacker-issued syscalls (netlink dump plus concurrent socket churn); no victim action is needed.\nS:U - Impact is memory corruption within the host kernel authority (local privilege escalation/crash), not a cross-boundary escape such as guest-to-host or IOMMU bypass.\nC:H - Use-after-free read of a freed hashed object (e.g. netlink_sock) can be reclaimed via heap spray, yielding an arbitrary read primitive through subsequent walk/diag use of the corrupted pointer.\nI:H - UAF on a reclaimable slab object enables heap spraying and fake-object injection into the walk path, which can be leveraged for arbitrary write or control-flow hijacking.\nA:H - The demonstrated KASAN slab-use-after-free in rhashtable_walk_next can oops/panic the kernel, and UAFs remain crashable even when not fully exploited."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:28:34.797Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ba510b5e9fe396497d31162acb579f210adfe6c8"
},
{
"url": "https://git.kernel.org/stable/c/a0406c40c6638c5ae50257db6297b2fba6c9ba16"
},
{
"url": "https://git.kernel.org/stable/c/0955b65c2b47c30b439e2cf1b1e375073aa0413a"
},
{
"url": "https://git.kernel.org/stable/c/c39643ad99fea749be50615550e8f0e6d6e60694"
},
{
"url": "https://git.kernel.org/stable/c/042fda5c088015f18838e5c692659a7be60aeb26"
},
{
"url": "https://git.kernel.org/stable/c/3ff7c1dbf722cf3fa538672452ba182318e0fcc3"
},
{
"url": "https://git.kernel.org/stable/c/4169d9fb92f313ff8e7e83d733c1ecdcc93eebd3"
},
{
"url": "https://git.kernel.org/stable/c/8173f7e2ce67e6ca1d4763f3da14e5b01ce77456"
}
],
"title": "rhashtable: clear stale iter-\u003ep on table restart",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64563",
"datePublished": "2026-08-04T06:23:22.601Z",
"dateReserved": "2026-07-19T15:36:31.797Z",
"dateUpdated": "2026-08-19T16:28:34.797Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64580 (GCVE-0-2026-64580)
Vulnerability from cvelistv5
Published
2026-08-05 08:09
Modified
2026-08-19 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
xfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst()
On the error path where in6_dev_get(dev) returns NULL, xfrm6_fill_dst()
releases the device reference with netdev_put() but leaves
xdst->u.dst.dev set. dst_destroy() later calls netdev_put(dst->dev)
again, so the same net_device reference is released twice, underflowing
its refcount (ref_tracker WARNING + "unregister_netdevice: waiting for
<dev> to become free").
Clear xdst->u.dst.dev after the netdev_put(), the same way the XFRM
device-offload paths xfrm_dev_state_add() and xfrm_dev_policy_add() in
net/xfrm/xfrm_device.c NULL ->dev when releasing the reference on error.
ref_tracker: reference already released.
ref_tracker: allocated in:
xfrm6_fill_dst (net/ipv6/xfrm6_policy.c:86)
...
udpv6_sendmsg (net/ipv6/udp.c:1696)
...
ref_tracker: freed in:
xfrm6_fill_dst (net/ipv6/xfrm6_policy.c:90)
...
WARNING: lib/ref_tracker.c:322 at ref_tracker_free+0x58b/0x780
dst_destroy (net/core/dst.c:115)
rcu_core
handle_softirqs
...
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 84c4a9dfbf430861e7588d95ae3ff61535dca351 Version: 84c4a9dfbf430861e7588d95ae3ff61535dca351 Version: 84c4a9dfbf430861e7588d95ae3ff61535dca351 Version: 84c4a9dfbf430861e7588d95ae3ff61535dca351 Version: 84c4a9dfbf430861e7588d95ae3ff61535dca351 Version: 84c4a9dfbf430861e7588d95ae3ff61535dca351 Version: a7e22d0c0e81dde129a51ee413644124f4b59954 Version: 01b0d887f67a388fb2a658ee2bdd74e5ba146818 Version: a98124aac0b5adc5de8ae54f11322781cb4d85c3 Version: e27b7bee743d921f037b1da6f071237345bef7c1 Version: 3.0.79 ≤ Version: 3.2.46 ≤ Version: 3.4.46 ≤ Version: 3.9.3 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ipv6/xfrm6_policy.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "97e032e5733e49471fb73de117ea2ac1ac7c479a",
"status": "affected",
"version": "84c4a9dfbf430861e7588d95ae3ff61535dca351",
"versionType": "git"
},
{
"lessThan": "df6856c2dda9187601d29b5fbd7a81b3b178cedf",
"status": "affected",
"version": "84c4a9dfbf430861e7588d95ae3ff61535dca351",
"versionType": "git"
},
{
"lessThan": "43de8a49335e611adb271bbd52e84dfbc11fc185",
"status": "affected",
"version": "84c4a9dfbf430861e7588d95ae3ff61535dca351",
"versionType": "git"
},
{
"lessThan": "ff636d7b7cba6dea82ecf580415ea57f2c1a11b6",
"status": "affected",
"version": "84c4a9dfbf430861e7588d95ae3ff61535dca351",
"versionType": "git"
},
{
"lessThan": "e078da1b4e11390cff3201c19a9a1fe70c5b934f",
"status": "affected",
"version": "84c4a9dfbf430861e7588d95ae3ff61535dca351",
"versionType": "git"
},
{
"lessThan": "136992de9bb91871084ae52d172610541c76e4d2",
"status": "affected",
"version": "84c4a9dfbf430861e7588d95ae3ff61535dca351",
"versionType": "git"
},
{
"status": "affected",
"version": "a7e22d0c0e81dde129a51ee413644124f4b59954",
"versionType": "git"
},
{
"status": "affected",
"version": "01b0d887f67a388fb2a658ee2bdd74e5ba146818",
"versionType": "git"
},
{
"status": "affected",
"version": "a98124aac0b5adc5de8ae54f11322781cb4d85c3",
"versionType": "git"
},
{
"status": "affected",
"version": "e27b7bee743d921f037b1da6f071237345bef7c1",
"versionType": "git"
},
{
"lessThan": "3.1",
"status": "affected",
"version": "3.0.79",
"versionType": "semver"
},
{
"lessThan": "3.3",
"status": "affected",
"version": "3.2.46",
"versionType": "semver"
},
{
"lessThan": "3.5",
"status": "affected",
"version": "3.4.46",
"versionType": "semver"
},
{
"lessThan": "3.10",
"status": "affected",
"version": "3.9.3",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ipv6/xfrm6_policy.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.10"
},
{
"lessThan": "3.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.0.79",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.2.46",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.4.46",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.9.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst()\n\nOn the error path where in6_dev_get(dev) returns NULL, xfrm6_fill_dst()\nreleases the device reference with netdev_put() but leaves\nxdst-\u003eu.dst.dev set. dst_destroy() later calls netdev_put(dst-\u003edev)\nagain, so the same net_device reference is released twice, underflowing\nits refcount (ref_tracker WARNING + \"unregister_netdevice: waiting for\n\u003cdev\u003e to become free\").\n\nClear xdst-\u003eu.dst.dev after the netdev_put(), the same way the XFRM\ndevice-offload paths xfrm_dev_state_add() and xfrm_dev_policy_add() in\nnet/xfrm/xfrm_device.c NULL -\u003edev when releasing the reference on error.\n\n ref_tracker: reference already released.\n ref_tracker: allocated in:\n xfrm6_fill_dst (net/ipv6/xfrm6_policy.c:86)\n ...\n udpv6_sendmsg (net/ipv6/udp.c:1696)\n ...\n ref_tracker: freed in:\n xfrm6_fill_dst (net/ipv6/xfrm6_policy.c:90)\n ...\n WARNING: lib/ref_tracker.c:322 at ref_tracker_free+0x58b/0x780\n dst_destroy (net/core/dst.c:115)\n rcu_core\n handle_softirqs\n ..."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached on the local IPv6 outbound path (udpv6_sendmsg \u2192 xfrm_lookup \u2192 xfrm6_fill_dst) after configuring XFRM policy/state via netlink or IPV6_XFRM_POLICY; a remote peer cannot drive that configuration or the device state that makes in6_dev_get fail.\nAC:L - An attacker in their own netns can create interfaces, install IPv6 XFRM policy/state, generate matching UDP traffic, and concurrently drop MTU below IPV6_MIN_MTU or unregister the device to clear ip6_ptr, so they control both sides of the window that hits the error path; once entered, the double netdev_put is deterministic.\nPR:L - XFRM configuration requires CAP_NET_ADMIN via netlink_net_capable/sockopt_ns_capable, which is ns_capable() in the netns user_ns, so an unprivileged user obtains it with unshare -Urn rather than real init-namespace root.\nUI:N - No victim action is required; the attacker configures XFRM, manipulates their own netdevs, and sends packets entirely with their own processes.\nS:U - The impact is kernel net_device refcount corruption within the same host kernel authority; this is ordinary local privilege-escalation/DoS territory, not a VM escape or IOMMU/sandbox boundary cross.\nC:H - The leftover dst.dev causes a second netdev_put in dst_destroy, underflowing the net_device refcount and enabling use-after-free of the device object, which per kernel UAF guidance yields a high confidentiality/info-disclosure primitive.\nI:H - A net_device refcount underflow/UAF is heap memory corruption that can be shaped via reuse/spraying into arbitrary write or control-flow hijack, so integrity impact is high.\nA:H - Even without full exploitation, the double put triggers ref_tracker warnings and can oops/panic or hang device unregister (unregister_netdevice waiting for the device to become free), so availability impact is high."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:29:07.038Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/97e032e5733e49471fb73de117ea2ac1ac7c479a"
},
{
"url": "https://git.kernel.org/stable/c/df6856c2dda9187601d29b5fbd7a81b3b178cedf"
},
{
"url": "https://git.kernel.org/stable/c/43de8a49335e611adb271bbd52e84dfbc11fc185"
},
{
"url": "https://git.kernel.org/stable/c/ff636d7b7cba6dea82ecf580415ea57f2c1a11b6"
},
{
"url": "https://git.kernel.org/stable/c/e078da1b4e11390cff3201c19a9a1fe70c5b934f"
},
{
"url": "https://git.kernel.org/stable/c/136992de9bb91871084ae52d172610541c76e4d2"
}
],
"title": "xfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64580",
"datePublished": "2026-08-05T08:09:34.946Z",
"dateReserved": "2026-07-19T15:36:31.798Z",
"dateUpdated": "2026-08-19T16:29:07.038Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68271 (GCVE-0-2026-68271)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-17 05:02
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/nouveau: fix reversed error cleanup order in ucopy functions
nouveau_uvmm_vm_bind_ucopy() and nouveau_exec_ucopy() place their error
cleanup labels in allocation order rather than reverse allocation order.
On a u_memcpya() failure for in_sync.s, the goto to err_free_ops (or
err_free_pushs) frees the first allocation and then falls through to
err_free_ins, which calls u_free() on args->in_sync.s.
Since args->in_sync.s still holds the ERR_PTR returned by the failed
u_memcpya(), and ERR_PTR values are not caught by ZERO_OR_NULL_PTR(),
kvfree() proceeds to dereference it, which can result in a kernel oops.
A failure for out_sync.s instead jumps to err_free_ins and skips freeing
the first allocation, leading to a memory leak.
Fix by swapping the cleanup label order so resources are freed in the
correct reverse allocation sequence.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/nouveau/nouveau_exec.c",
"drivers/gpu/drm/nouveau/nouveau_uvmm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "2473ac314387a5def7244eb6d6a345934ed140bf",
"status": "affected",
"version": "b88baab828713ce0b49b185444b2ee83bed373a8",
"versionType": "git"
},
{
"lessThan": "e15c25c7972d38a9f6bf8c3f7f29179a67263eba",
"status": "affected",
"version": "b88baab828713ce0b49b185444b2ee83bed373a8",
"versionType": "git"
},
{
"lessThan": "4e109faa9ea2b6c04cc5a99e76db3126575a59d1",
"status": "affected",
"version": "b88baab828713ce0b49b185444b2ee83bed373a8",
"versionType": "git"
},
{
"lessThan": "ebbaf64d2635d1e78196c067fa8fa582a7dc17f7",
"status": "affected",
"version": "b88baab828713ce0b49b185444b2ee83bed373a8",
"versionType": "git"
},
{
"lessThan": "ab99ead646b1b833ecd57fe577a2816f2e848167",
"status": "affected",
"version": "b88baab828713ce0b49b185444b2ee83bed373a8",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/nouveau/nouveau_exec.c",
"drivers/gpu/drm/nouveau/nouveau_uvmm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.6"
},
{
"lessThan": "6.6",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/nouveau: fix reversed error cleanup order in ucopy functions\n\nnouveau_uvmm_vm_bind_ucopy() and nouveau_exec_ucopy() place their error\ncleanup labels in allocation order rather than reverse allocation order.\nOn a u_memcpya() failure for in_sync.s, the goto to err_free_ops (or\nerr_free_pushs) frees the first allocation and then falls through to\nerr_free_ins, which calls u_free() on args-\u003ein_sync.s.\n\nSince args-\u003ein_sync.s still holds the ERR_PTR returned by the failed\nu_memcpya(), and ERR_PTR values are not caught by ZERO_OR_NULL_PTR(),\nkvfree() proceeds to dereference it, which can result in a kernel oops.\nA failure for out_sync.s instead jumps to err_free_ins and skips freeing\nthe first allocation, leading to a memory leak.\n\nFix by swapping the cleanup label order so resources are freed in the\ncorrect reverse allocation sequence."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:02:04.681Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/2473ac314387a5def7244eb6d6a345934ed140bf"
},
{
"url": "https://git.kernel.org/stable/c/e15c25c7972d38a9f6bf8c3f7f29179a67263eba"
},
{
"url": "https://git.kernel.org/stable/c/4e109faa9ea2b6c04cc5a99e76db3126575a59d1"
},
{
"url": "https://git.kernel.org/stable/c/ebbaf64d2635d1e78196c067fa8fa582a7dc17f7"
},
{
"url": "https://git.kernel.org/stable/c/ab99ead646b1b833ecd57fe577a2816f2e848167"
}
],
"title": "drm/nouveau: fix reversed error cleanup order in ucopy functions",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68271",
"datePublished": "2026-08-10T12:01:46.534Z",
"dateReserved": "2026-07-30T09:28:09.378Z",
"dateUpdated": "2026-08-17T05:02:04.681Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68433 (GCVE-0-2026-68433)
Vulnerability from cvelistv5
Published
2026-08-12 00:07
Modified
2026-08-19 16:35
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
libceph: bound get_version reply decode to front len
handle_get_version_reply() uses msg->front_alloc_len as the decode
boundary for MON_GET_VERSION_REPLY. That is the size of the reused
reply buffer, not the number of bytes actually received.
A truncated reply can therefore pass ceph_decode_need() and decode the
second u64 from stale tail bytes left in the buffer by an earlier
message, causing an uninitialized memory read.
Use msg->front.iov_len as the receive-side decode boundary, matching
other libceph reply handlers and limiting decoding to the bytes that
were actually read from the wire.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 513a8243d67f8e8d27f2883bd2f18bc87c7ca376 Version: 513a8243d67f8e8d27f2883bd2f18bc87c7ca376 Version: 513a8243d67f8e8d27f2883bd2f18bc87c7ca376 Version: 513a8243d67f8e8d27f2883bd2f18bc87c7ca376 Version: 513a8243d67f8e8d27f2883bd2f18bc87c7ca376 Version: 513a8243d67f8e8d27f2883bd2f18bc87c7ca376 Version: 513a8243d67f8e8d27f2883bd2f18bc87c7ca376 Version: 513a8243d67f8e8d27f2883bd2f18bc87c7ca376 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ceph/mon_client.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "1307028f082756bf453e1889aee9983d30643a4b",
"status": "affected",
"version": "513a8243d67f8e8d27f2883bd2f18bc87c7ca376",
"versionType": "git"
},
{
"lessThan": "f6cbf6878f3a1503c872ba8f1e69a58ee68d8b2e",
"status": "affected",
"version": "513a8243d67f8e8d27f2883bd2f18bc87c7ca376",
"versionType": "git"
},
{
"lessThan": "72a35070fcefa229b1b031aa7482ad3788e18f07",
"status": "affected",
"version": "513a8243d67f8e8d27f2883bd2f18bc87c7ca376",
"versionType": "git"
},
{
"lessThan": "340e0386aa39da181015bee38f309018c335ce16",
"status": "affected",
"version": "513a8243d67f8e8d27f2883bd2f18bc87c7ca376",
"versionType": "git"
},
{
"lessThan": "d60de8253c85a02d0e6194b0735e7a562981a04c",
"status": "affected",
"version": "513a8243d67f8e8d27f2883bd2f18bc87c7ca376",
"versionType": "git"
},
{
"lessThan": "4e7ebfaa0d14cf50e44041bfde38070d6dbc019f",
"status": "affected",
"version": "513a8243d67f8e8d27f2883bd2f18bc87c7ca376",
"versionType": "git"
},
{
"lessThan": "0d934c934ec746d53fc7e4f53239792647bbae63",
"status": "affected",
"version": "513a8243d67f8e8d27f2883bd2f18bc87c7ca376",
"versionType": "git"
},
{
"lessThan": "d3c32939fa0e3ee9b883b9a0fd1972c5c444e3d0",
"status": "affected",
"version": "513a8243d67f8e8d27f2883bd2f18bc87c7ca376",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ceph/mon_client.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.16"
},
{
"lessThan": "3.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.16",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: bound get_version reply decode to front len\n\nhandle_get_version_reply() uses msg-\u003efront_alloc_len as the decode\nboundary for MON_GET_VERSION_REPLY. That is the size of the reused\nreply buffer, not the number of bytes actually received.\n\nA truncated reply can therefore pass ceph_decode_need() and decode the\nsecond u64 from stale tail bytes left in the buffer by an earlier\nmessage, causing an uninitialized memory read.\n\nUse msg-\u003efront.iov_len as the receive-side decode boundary, matching\nother libceph reply handlers and limiting decoding to the bytes that\nwere actually read from the wire."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.6,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The malformed MON_GET_VERSION_REPLY arrives over the ceph messenger TCP connection to a monitor; a malicious/compromised ceph-mon or an on-path attacker on the msgr1/crc-mode session triggers the bug purely with received network data.\nAC:L - The attacker fully controls the reply\u0027s hdr.front_len and tid, so truncating the reply to 8 bytes reliably makes the handler decode past the received data every time; no race or memory-layout condition outside attacker control is involved.\nPR:N - The vulnerable decode runs on any reply the client accepts for an outstanding generic request; the attacker acts as the remote server/peer and needs no credentials or account on the victim kernel client.\nUI:N - An already-mounted CephFS/RBD client issues mon_get_version requests automatically (osdmap checks, pool-dne checks, remount/latest-map waits), so no local user action is needed once the client is connected.\nS:U - The uninitialized read and the resulting bogus epoch stay within the kernel\u0027s own libceph client state; no security authority other than the affected kernel is impacted.\nC:L - Eight bytes of uninitialized kvmalloc\u0027d heap (or stale bytes of a prior reply) are consumed as req-\u003eu.newest; the read stays inside the 32-byte allocation and is not copied to userspace, so it is a small bounded uninitialized-memory disclosure that only leaks indirectly through client behaviour.\nI:L - The attacker causes kernel state (req-\u003eu.newest, r_map_dne_bound, linger map_dne_bound) to be populated from uninitialized memory rather than the wire, corrupting osdmap-epoch bookkeeping and leading to wrong pool-does-not-exist decisions, but gives no arbitrary write.\nA:H - A zero stale value trips WARN_ON(greq-\u003eresult || !greq-\u003eu.newest) in map_check_cb()/linger_map_check_cb() (panic with panic_on_warn), while a huge garbage epoch makes ceph_monc_wait_osdmap() block until mount_timeout or indefinitely and makes check_pool_dne() abort in-flight requests with -ENOENT; all repeatable at will."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:35:33.508Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/1307028f082756bf453e1889aee9983d30643a4b"
},
{
"url": "https://git.kernel.org/stable/c/f6cbf6878f3a1503c872ba8f1e69a58ee68d8b2e"
},
{
"url": "https://git.kernel.org/stable/c/72a35070fcefa229b1b031aa7482ad3788e18f07"
},
{
"url": "https://git.kernel.org/stable/c/340e0386aa39da181015bee38f309018c335ce16"
},
{
"url": "https://git.kernel.org/stable/c/d60de8253c85a02d0e6194b0735e7a562981a04c"
},
{
"url": "https://git.kernel.org/stable/c/4e7ebfaa0d14cf50e44041bfde38070d6dbc019f"
},
{
"url": "https://git.kernel.org/stable/c/0d934c934ec746d53fc7e4f53239792647bbae63"
},
{
"url": "https://git.kernel.org/stable/c/d3c32939fa0e3ee9b883b9a0fd1972c5c444e3d0"
}
],
"title": "libceph: bound get_version reply decode to front len",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68433",
"datePublished": "2026-08-12T00:07:20.455Z",
"dateReserved": "2026-07-30T09:28:09.393Z",
"dateUpdated": "2026-08-19T16:35:33.508Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72260 (GCVE-0-2026-72260)
Vulnerability from cvelistv5
Published
2026-08-15 05:54
Modified
2026-08-23 12:47
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ASoC: mediatek: mt8192: Check runtime resume during probe
The MT8192 AFE probe enables runtime PM temporarily while reinitializing
the regmap cache from hardware, but it uses pm_runtime_get_sync()
without checking the return value. If runtime resume fails, probe keeps
going without the device necessarily being accessible, and
pm_runtime_get_sync() may leave the PM usage count incremented.
The regmap_reinit_cache() failure path also returns before dropping the
temporary PM reference and before clearing pm_runtime_bypass_reg_ctl.
Use pm_runtime_resume_and_get() so resume failures do not leak a usage
count, and clear the temporary bypass flag after dropping the probe PM
reference on all regmap_reinit_cache() outcomes.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 125ab5d588b0b3b842064c4d53a666ca74521ae8 Version: 125ab5d588b0b3b842064c4d53a666ca74521ae8 Version: 125ab5d588b0b3b842064c4d53a666ca74521ae8 Version: 125ab5d588b0b3b842064c4d53a666ca74521ae8 Version: 125ab5d588b0b3b842064c4d53a666ca74521ae8 Version: 125ab5d588b0b3b842064c4d53a666ca74521ae8 Version: 125ab5d588b0b3b842064c4d53a666ca74521ae8 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"sound/soc/mediatek/mt8192/mt8192-afe-pcm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "9339266a8a720889d0385cfd78ba6652fe7bb1a8",
"status": "affected",
"version": "125ab5d588b0b3b842064c4d53a666ca74521ae8",
"versionType": "git"
},
{
"lessThan": "91b20e8c9b64042056d14394c89c81fc16a1c327",
"status": "affected",
"version": "125ab5d588b0b3b842064c4d53a666ca74521ae8",
"versionType": "git"
},
{
"lessThan": "6e2ee6eacc3ec7b339753abcf33812d27e03efe5",
"status": "affected",
"version": "125ab5d588b0b3b842064c4d53a666ca74521ae8",
"versionType": "git"
},
{
"lessThan": "faa97a1a6cab01cd3e2055deb4db4e57efc43ff2",
"status": "affected",
"version": "125ab5d588b0b3b842064c4d53a666ca74521ae8",
"versionType": "git"
},
{
"lessThan": "e0f276f1918a202e9c3ac72baffd311cecb6b8db",
"status": "affected",
"version": "125ab5d588b0b3b842064c4d53a666ca74521ae8",
"versionType": "git"
},
{
"lessThan": "f6e424835cc05d215c57b6370b2c1e353dd02915",
"status": "affected",
"version": "125ab5d588b0b3b842064c4d53a666ca74521ae8",
"versionType": "git"
},
{
"lessThan": "e24d5dde56a50946020b134fa8448869093db76a",
"status": "affected",
"version": "125ab5d588b0b3b842064c4d53a666ca74521ae8",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"sound/soc/mediatek/mt8192/mt8192-afe-pcm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.11"
},
{
"lessThan": "5.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: mediatek: mt8192: Check runtime resume during probe\n\nThe MT8192 AFE probe enables runtime PM temporarily while reinitializing\nthe regmap cache from hardware, but it uses pm_runtime_get_sync()\nwithout checking the return value. If runtime resume fails, probe keeps\ngoing without the device necessarily being accessible, and\npm_runtime_get_sync() may leave the PM usage count incremented.\n\nThe regmap_reinit_cache() failure path also returns before dropping the\ntemporary PM reference and before clearing pm_runtime_bypass_reg_ctl.\n\nUse pm_runtime_resume_and_get() so resume failures do not leak a usage\ncount, and clear the temporary bypass flag after dropping the probe PM\nreference on all regmap_reinit_cache() outcomes."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:47:10.221Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/9339266a8a720889d0385cfd78ba6652fe7bb1a8"
},
{
"url": "https://git.kernel.org/stable/c/91b20e8c9b64042056d14394c89c81fc16a1c327"
},
{
"url": "https://git.kernel.org/stable/c/6e2ee6eacc3ec7b339753abcf33812d27e03efe5"
},
{
"url": "https://git.kernel.org/stable/c/faa97a1a6cab01cd3e2055deb4db4e57efc43ff2"
},
{
"url": "https://git.kernel.org/stable/c/e0f276f1918a202e9c3ac72baffd311cecb6b8db"
},
{
"url": "https://git.kernel.org/stable/c/f6e424835cc05d215c57b6370b2c1e353dd02915"
},
{
"url": "https://git.kernel.org/stable/c/e24d5dde56a50946020b134fa8448869093db76a"
}
],
"title": "ASoC: mediatek: mt8192: Check runtime resume during probe",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72260",
"datePublished": "2026-08-15T05:54:48.409Z",
"dateReserved": "2026-08-09T03:40:39.915Z",
"dateUpdated": "2026-08-23T12:47:10.221Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68202 (GCVE-0-2026-68202)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ALSA: seq: close a re-opened queue timer in the destructor
queue_delete() closes the queue timer, then frees it. snd_seq_timer_close()
clears q->timer->timeri. snd_use_lock_sync() then drains borrowers, and
snd_seq_timer_delete() frees q->timer.
A borrower can re-open the timer inside that window. A SET_QUEUE_CLIENT
that took a queueptr() use_lock reference before the queue was unlinked
runs snd_seq_timer_open() after the close. Open refuses re-open only while
timeri is set, and the close just cleared it, so it re-opens timeri.
snd_seq_timer_delete() does not close that instance. Its snd_seq_timer_stop()
is a no-op, because running was cleared first. So it frees q->timer with the
instance still live. The queue is freed next.
The instance stays on the global timer with callback_data pointing at the
freed queue. A non-owner START on the unlocked queue arms it. The next tick
derefs the freed queue in snd_seq_timer_interrupt().
Reachable by an unprivileged user with access to /dev/snd/seq. No CAP and
no queue ownership required.
Close any lingering instance in the destructor. There, ->timeri can no
longer change: the queue is unlinked and all use_lock borrowers have
drained, so no snd_seq_queue_use() can re-open it. Close it before clearing
q->timer. snd_timer_close() waits for any in-flight snd_seq_timer_interrupt()
to finish, and that callback still reads q->timer (via snd_seq_check_queue()),
so q->timer must stay valid until it drains.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"sound/core/seq/seq_timer.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b7feeaca1f53b10df9b4de9eaf611767ca70dc92",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "7478ef94b49bc9789cf1a003deec58b42283dde4",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "9d9be6fc30f384f92c4e1b8ed40bd9d4796b7833",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "fb40d03ed792a8a8bf77aa0ee15df57b0ff78b07",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "24f0cabf173539f048946c8fc221131dc221f277",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "6a10025c7fd09a7d2af37a3ae1da188569fce470",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "31a6163e301d832060f8236f1ed17cbc1ca198df",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "2c4dc0ed50b05cd847a4b34b8cebf0775f19aeb9",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"sound/core/seq/seq_timer.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: seq: close a re-opened queue timer in the destructor\n\nqueue_delete() closes the queue timer, then frees it. snd_seq_timer_close()\nclears q-\u003etimer-\u003etimeri. snd_use_lock_sync() then drains borrowers, and\nsnd_seq_timer_delete() frees q-\u003etimer.\n\nA borrower can re-open the timer inside that window. A SET_QUEUE_CLIENT\nthat took a queueptr() use_lock reference before the queue was unlinked\nruns snd_seq_timer_open() after the close. Open refuses re-open only while\ntimeri is set, and the close just cleared it, so it re-opens timeri.\n\nsnd_seq_timer_delete() does not close that instance. Its snd_seq_timer_stop()\nis a no-op, because running was cleared first. So it frees q-\u003etimer with the\ninstance still live. The queue is freed next.\n\nThe instance stays on the global timer with callback_data pointing at the\nfreed queue. A non-owner START on the unlocked queue arms it. The next tick\nderefs the freed queue in snd_seq_timer_interrupt().\n\nReachable by an unprivileged user with access to /dev/snd/seq. No CAP and\nno queue ownership required.\n\nClose any lingering instance in the destructor. There, -\u003etimeri can no\nlonger change: the queue is unlinked and all use_lock borrowers have\ndrained, so no snd_seq_queue_use() can re-open it. Close it before clearing\nq-\u003etimer. snd_timer_close() waits for any in-flight snd_seq_timer_interrupt()\nto finish, and that callback still reads q-\u003etimer (via snd_seq_check_queue()),\nso q-\u003etimer must stay valid until it drains."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached through ioctls on the local character device /dev/snd/seq (SNDRV_SEQ_IOCTL_CREATE_QUEUE/DELETE_QUEUE/SET_QUEUE_CLIENT); no network or adjacent-network path exists to the ALSA sequencer.\nAC:L - The attacker controls both sides of the race \u2014 one thread deletes the queue while another spins on SET_QUEUE_CLIENT holding a queueptr() reference \u2014 and can retry the loop indefinitely on a default kernel with CONFIG_SND_SEQUENCER, so the window is reliably hit.\nPR:L - Only an unprivileged local user able to open /dev/snd/seq is needed; snd_seq_queue_use() performs no owner or access check and no capability is required, as the fix commit states explicitly.\nUI:N - The attacker\u0027s own threads create, delete and re-use the queue and the global system timer fires on its own; no victim action is involved.\nS:U - The use-after-free corrupts kernel heap objects within the same kernel security authority, giving at most kernel privilege escalation rather than crossing a VM, IOMMU or sandbox boundary.\nC:H - The stale timer instance dereferences the freed snd_seq_queue and snd_seq_timer, reading tick/time fields and freed prioq pointers that can be reclaimed by attacker-sprayed objects, giving a route to disclose arbitrary kernel memory.\nI:H - snd_seq_timer_interrupt() writes cur_time, tick and last_update into the freed snd_seq_timer slab and snd_seq_check_queue() dispatches events through freed queue pointers, yielding a controllable write primitive on reclaimed heap memory suitable for privilege escalation.\nA:H - Even unexploited, the timer callback derefs freed memory and takes a spinlock in a freed object from interrupt context, causing oops, lock corruption or panic \u2014 a repeatable denial of service for any local user."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:08.116Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b7feeaca1f53b10df9b4de9eaf611767ca70dc92"
},
{
"url": "https://git.kernel.org/stable/c/7478ef94b49bc9789cf1a003deec58b42283dde4"
},
{
"url": "https://git.kernel.org/stable/c/9d9be6fc30f384f92c4e1b8ed40bd9d4796b7833"
},
{
"url": "https://git.kernel.org/stable/c/fb40d03ed792a8a8bf77aa0ee15df57b0ff78b07"
},
{
"url": "https://git.kernel.org/stable/c/24f0cabf173539f048946c8fc221131dc221f277"
},
{
"url": "https://git.kernel.org/stable/c/6a10025c7fd09a7d2af37a3ae1da188569fce470"
},
{
"url": "https://git.kernel.org/stable/c/31a6163e301d832060f8236f1ed17cbc1ca198df"
},
{
"url": "https://git.kernel.org/stable/c/2c4dc0ed50b05cd847a4b34b8cebf0775f19aeb9"
}
],
"title": "ALSA: seq: close a re-opened queue timer in the destructor",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68202",
"datePublished": "2026-08-10T12:00:21.279Z",
"dateReserved": "2026-07-30T09:28:09.374Z",
"dateUpdated": "2026-08-23T12:46:08.116Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72115 (GCVE-0-2026-72115)
Vulnerability from cvelistv5
Published
2026-08-15 05:52
Modified
2026-08-19 16:36
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
can: bcm: track a single source interface for ANYDEV timeout/throttle ops
An ANYDEV rx op (ifindex == 0) with an active RX timeout and/or
throttle timer has no defined semantics when matching frames arrive
from several interfaces: bcm_rx_handler() can run concurrently for
the same op on different CPUs, racing hrtimer_cancel()/
bcm_rx_starttimer() against bcm_rx_timeout_handler() and causing
spurious RX_TIMEOUT notifications and last_frames corruption. The
same concurrency lets throttled multiplex frames from different
interfaces clobber the single rx_ifindex/rx_stamp fields shared by
the op.
Add op->if_detected to track the first interface that delivers a
matching frame while a timeout/throttle timer is configured, and
reject frames from any other interface for that op. The claim is
decided in bcm_rx_handler() before hrtimer_cancel() touches
op->timer, so a rejected frame can never disturb the claimed
interface's watchdog. RTR-mode ops are excluded via RX_RTR_FRAME,
independent of kt_ival1/kt_ival2, since those may briefly hold a
stale value from an earlier non-RTR configuration.
The claim is released in bcm_notify() on NETDEV_UNREGISTER and in
bcm_rx_setup() when SETTIMER reconfigures the timer values.
A (re-)claim is only possible on CAN devices in NETREG_REGISTERED
dev->reg_state to cover the release in bcm_notify() where reg_state
becomes NETREG_UNREGISTERING until synchronize_net().
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/can/bcm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "f147f48837cb1426521f5b3c3b3134c71128a25d",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "57cf104da4cf450ae9c16801a3164604b801d2cc",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "03dfe347c398fa41a7e30e8dc538f12568c183e6",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "18b45251e74e35668f0dd0c470549384ae191ecf",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "3ff8c24b421070a2db99a5cdb86edc9ff339418e",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "eca8b44d51fc6ab61022258ec968e55e3073b79e",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "b6317022b685a430a3ae420456716e3c0c02ef4b",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "2f5976f54a04e9f18b25283036ac3136be453b17",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/can/bcm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.25"
},
{
"lessThan": "2.6.25",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.25",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: bcm: track a single source interface for ANYDEV timeout/throttle ops\n\nAn ANYDEV rx op (ifindex == 0) with an active RX timeout and/or\nthrottle timer has no defined semantics when matching frames arrive\nfrom several interfaces: bcm_rx_handler() can run concurrently for\nthe same op on different CPUs, racing hrtimer_cancel()/\nbcm_rx_starttimer() against bcm_rx_timeout_handler() and causing\nspurious RX_TIMEOUT notifications and last_frames corruption. The\nsame concurrency lets throttled multiplex frames from different\ninterfaces clobber the single rx_ifindex/rx_stamp fields shared by\nthe op.\n\nAdd op-\u003eif_detected to track the first interface that delivers a\nmatching frame while a timeout/throttle timer is configured, and\nreject frames from any other interface for that op. The claim is\ndecided in bcm_rx_handler() before hrtimer_cancel() touches\nop-\u003etimer, so a rejected frame can never disturb the claimed\ninterface\u0027s watchdog. RTR-mode ops are excluded via RX_RTR_FRAME,\nindependent of kt_ival1/kt_ival2, since those may briefly hold a\nstale value from an earlier non-RTR configuration.\n\nThe claim is released in bcm_notify() on NETDEV_UNREGISTER and in\nbcm_rx_setup() when SETTIMER reconfigures the timer values.\n\nA (re-)claim is only possible on CAN devices in NETREG_REGISTERED\ndev-\u003ereg_state to cover the release in bcm_notify() where reg_state\nbecomes NETREG_UNREGISTERING until synchronize_net()."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - bcm_rx_handler() is reached from the CAN driver RX path when matching frames arrive on multiple interfaces; on automotive/industrial systems an attacker on shared CAN segment(s) can inject concurrent frames without host shell access once an ANYDEV BCM RX op with active timeout/throttle timers exists.\nAC:L - The attacker controls both sides of the race by flooding matching frames on multiple CAN interfaces (or paired vcan devices) to run bcm_rx_handler() concurrently on different CPUs, racing hrtimer_cancel/bcm_rx_starttimer against bcm_rx_timeout_handler and interleaved last_frames writers.\nPR:N - No Linux capability or account is required to deliver triggering CAN traffic on multiple interfaces; bcm_rx_handler() runs from the unauthenticated netdev RX path once any ANYDEV BCM RX op with active kt_ival1/kt_ival2 timers exists, as commonly configured by telematics/diagnostic daemons.\nUI:N - Exploitation requires no victim interaction beyond normal system operation; malicious or concurrent CAN frames are processed automatically in softirq without mounts, file opens, or user prompts.\nS:U - Impact is confined to corrupted BCM state and incorrect CAN notifications delivered to the subscribing userspace process within the same kernel/host security boundary; no VM, container, or IOMMU escape is involved.\nC:H - Concurrent bcm_rx_handler() and bcm_rx_timeout_handler() races corrupt op-\u003elast_frames heap buffers via unsynchronized memcpy/memset, mixing attacker-controlled CAN payloads from different interfaces and leaking cross-bus frame content through bcm_send_to_user().\nI:H - last_frames corruption lets attacker-controlled frames from one interface overwrite or interleave with another\u0027s stored/throttled state, misattributing RX_CHANGED/RX_TIMEOUT notifications and corrupting safety- or security-relevant CAN monitoring and control decisions.\nA:N - The race corrupts per-op BCM buffers and emits spurious RX_TIMEOUT events but does not dereference freed objects, overrun buffer bounds, or fault the kernel; no oops, panic, hang, or sustained kernel denial of service is indicated."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:36:03.316Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/f147f48837cb1426521f5b3c3b3134c71128a25d"
},
{
"url": "https://git.kernel.org/stable/c/57cf104da4cf450ae9c16801a3164604b801d2cc"
},
{
"url": "https://git.kernel.org/stable/c/03dfe347c398fa41a7e30e8dc538f12568c183e6"
},
{
"url": "https://git.kernel.org/stable/c/18b45251e74e35668f0dd0c470549384ae191ecf"
},
{
"url": "https://git.kernel.org/stable/c/3ff8c24b421070a2db99a5cdb86edc9ff339418e"
},
{
"url": "https://git.kernel.org/stable/c/eca8b44d51fc6ab61022258ec968e55e3073b79e"
},
{
"url": "https://git.kernel.org/stable/c/b6317022b685a430a3ae420456716e3c0c02ef4b"
},
{
"url": "https://git.kernel.org/stable/c/2f5976f54a04e9f18b25283036ac3136be453b17"
}
],
"title": "can: bcm: track a single source interface for ANYDEV timeout/throttle ops",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72115",
"datePublished": "2026-08-15T05:52:55.524Z",
"dateReserved": "2026-08-09T03:40:39.906Z",
"dateUpdated": "2026-08-19T16:36:03.316Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68349 (GCVE-0-2026-68349)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: carl9170: fix buffer overflow in rx_stream failover path
The failover continuation in carl9170_rx_stream() copies the full tlen
from the second USB transfer instead of capping at rx_failover_missing
bytes. When both transfers are near maximum size, the total exceeds the
65535-byte failover SKB, triggering skb_over_panic.
Limit the copy size to the missing byte count.
[Fix checkpatch CHECK:PARENTHESIS_ALIGNMENT]
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/ath/carl9170/rx.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "5fb00a09e9b0375e1ad9d4fefc4a62a67e7ea658",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "48c81fb523ecdc6a4b8654944ff32e499f21e6d0",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "a1ce01764a812c22a47d30aea78e347aebd3eea1",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "5acfa18de66b6089b81c1c0bf1a3ae3c940ec39e",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "b9dfee5e63ee9b5c47be9e344ebc5bd3f43fca78",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "4503829843353dbb18b879c35be1cdfc9af677b7",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "21f59906ea75618fdd46a7e32754d54fbee083ea",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "a1a21995c2e1cc2ca6b2226cfe4f5f018370182a",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/ath/carl9170/rx.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.37"
},
{
"lessThan": "2.6.37",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.37",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: carl9170: fix buffer overflow in rx_stream failover path\n\nThe failover continuation in carl9170_rx_stream() copies the full tlen\nfrom the second USB transfer instead of capping at rx_failover_missing\nbytes. When both transfers are near maximum size, the total exceeds the\n65535-byte failover SKB, triggering skb_over_panic.\n\nLimit the copy size to the missing byte count.\n\n[Fix checkpatch CHECK:PARENTHESIS_ALIGNMENT]"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:47.832Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/5fb00a09e9b0375e1ad9d4fefc4a62a67e7ea658"
},
{
"url": "https://git.kernel.org/stable/c/48c81fb523ecdc6a4b8654944ff32e499f21e6d0"
},
{
"url": "https://git.kernel.org/stable/c/a1ce01764a812c22a47d30aea78e347aebd3eea1"
},
{
"url": "https://git.kernel.org/stable/c/5acfa18de66b6089b81c1c0bf1a3ae3c940ec39e"
},
{
"url": "https://git.kernel.org/stable/c/b9dfee5e63ee9b5c47be9e344ebc5bd3f43fca78"
},
{
"url": "https://git.kernel.org/stable/c/4503829843353dbb18b879c35be1cdfc9af677b7"
},
{
"url": "https://git.kernel.org/stable/c/21f59906ea75618fdd46a7e32754d54fbee083ea"
},
{
"url": "https://git.kernel.org/stable/c/a1a21995c2e1cc2ca6b2226cfe4f5f018370182a"
}
],
"title": "wifi: carl9170: fix buffer overflow in rx_stream failover path",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68349",
"datePublished": "2026-08-10T12:03:26.166Z",
"dateReserved": "2026-07-30T09:28:09.384Z",
"dateUpdated": "2026-08-19T16:33:47.832Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68235 (GCVE-0-2026-68235)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-18 06:55
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: dce100: skip non-DP stream encoders for DP MST
On DCE8-class ASICs (e.g. Bonaire), the resource pool contains digital
DIG stream encoders plus one analog DAC encoder. When assigning a stream
encoder for a second DisplayPort MST stream, if the preferred digital
encoder is already acquired, dce100_find_first_free_match_stream_enc_for_link()
falls back to the first free pool entry. That entry may be the analog
encoder, whose funcs table lacks DP hooks such as dp_set_stream_attribute.
The subsequent atomic commit then dereferences NULL function pointers in
link_set_dpms_on() and crashes.
Skip encoders without dp_set_stream_attribute when the stream uses a DP
signal (including MST). Use dc_is_dp_signal(stream->signal) for the MST
fallback path instead of checking only the link connector signal.
Tested on:
- GPU: AMD Radeon R7 260X (Bonaire / DCE8)
- Board: Supermicro C9X299-PG300
- Setup: DP MST daisy chain, hotplug second monitor or have it connected on boot
- Kernel: 7.1.3 (issue observed since 6.19)
- Result: kernel oops without patch; dual monitors stable with patch
(cherry picked from commit 28ec64943e3ee4d9b8d30cea61e380f1429953a8)
References
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/display/dc/resource/dce100/dce100_resource.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ed2d86aef9fa4c43f82da0fca91a60f7326d7d03",
"status": "affected",
"version": "5834c33fd3f6f2a26dd4d6d4bbc7b8ed1c2ac4aa",
"versionType": "git"
},
{
"lessThan": "d340cba0df4cf327c7e89c7c1a4e79d4771d7dd5",
"status": "affected",
"version": "5834c33fd3f6f2a26dd4d6d4bbc7b8ed1c2ac4aa",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/display/dc/resource/dce100/dce100_resource.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.19"
},
{
"lessThan": "6.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: dce100: skip non-DP stream encoders for DP MST\n\nOn DCE8-class ASICs (e.g. Bonaire), the resource pool contains digital\nDIG stream encoders plus one analog DAC encoder. When assigning a stream\nencoder for a second DisplayPort MST stream, if the preferred digital\nencoder is already acquired, dce100_find_first_free_match_stream_enc_for_link()\nfalls back to the first free pool entry. That entry may be the analog\nencoder, whose funcs table lacks DP hooks such as dp_set_stream_attribute.\nThe subsequent atomic commit then dereferences NULL function pointers in\nlink_set_dpms_on() and crashes.\n\nSkip encoders without dp_set_stream_attribute when the stream uses a DP\nsignal (including MST). Use dc_is_dp_signal(stream-\u003esignal) for the MST\nfallback path instead of checking only the link connector signal.\n\nTested on:\n- GPU: AMD Radeon R7 260X (Bonaire / DCE8)\n- Board: Supermicro C9X299-PG300\n- Setup: DP MST daisy chain, hotplug second monitor or have it connected on boot\n- Kernel: 7.1.3 (issue observed since 6.19)\n- Result: kernel oops without patch; dual monitors stable with patch\n\n(cherry picked from commit 28ec64943e3ee4d9b8d30cea61e380f1429953a8)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-18T06:55:45.652Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ed2d86aef9fa4c43f82da0fca91a60f7326d7d03"
},
{
"url": "https://git.kernel.org/stable/c/d340cba0df4cf327c7e89c7c1a4e79d4771d7dd5"
}
],
"title": "drm/amd/display: dce100: skip non-DP stream encoders for DP MST",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68235",
"datePublished": "2026-08-10T12:01:00.099Z",
"dateReserved": "2026-07-30T09:28:09.376Z",
"dateUpdated": "2026-08-18T06:55:45.652Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68318 (GCVE-0-2026-68318)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-17 05:03
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
pds_core: fix use-after-free on workqueue during remove
In pdsc_remove(), the workqueue is destroyed before pdsc_teardown()
is called. This ordering allows two paths to queue work on the
destroyed workqueue:
1. If pdsc_teardown() -> pdsc_devcmd_reset() times out, the error
path in pdsc_devcmd_locked() queues health_work.
2. A NotifyQ event can trigger the ISR and queue work before free_irq()
is called in pdsc_teardown().
Fix by moving destroy_workqueue() after pdsc_teardown() so the
workqueue outlives every queuer; destroy_workqueue() then flushes any
work still pending.
Draining the queued work also requires ordering the teardown so the
resources that work touches are freed last:
- In pdsc_qcq_free(), after freeing the interrupt, cancel_work_sync()
the queue's work and only then clear qcq->intx, so
pdsc_process_adminq()'s read of qcq->intx for interrupt-credit
return cannot race with the clear.
- Free adminqcq before notifyqcq: the shared adminq ISR is released
when adminqcq is freed, and the adminq work accesses notifyqcq, so
both must be stopped before notifyqcq is freed.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/amd/pds_core/core.c",
"drivers/net/ethernet/amd/pds_core/main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "224214eb4182ff20a665b615a90b66017539dd75",
"status": "affected",
"version": "01ba61b55b2041a39c54aefb3153c770dd59a0ef",
"versionType": "git"
},
{
"lessThan": "9e0f80fac50ab95dd75537c8ecaf5051d01f19b5",
"status": "affected",
"version": "01ba61b55b2041a39c54aefb3153c770dd59a0ef",
"versionType": "git"
},
{
"lessThan": "ecc7a7d7569ec1d6a61e18372696b9de97635156",
"status": "affected",
"version": "01ba61b55b2041a39c54aefb3153c770dd59a0ef",
"versionType": "git"
},
{
"lessThan": "0ad134881508c36b65c1a8864f8bec53adbd3327",
"status": "affected",
"version": "01ba61b55b2041a39c54aefb3153c770dd59a0ef",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/amd/pds_core/core.c",
"drivers/net/ethernet/amd/pds_core/main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.4"
},
{
"lessThan": "6.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\npds_core: fix use-after-free on workqueue during remove\n\nIn pdsc_remove(), the workqueue is destroyed before pdsc_teardown()\nis called. This ordering allows two paths to queue work on the\ndestroyed workqueue:\n\n1. If pdsc_teardown() -\u003e pdsc_devcmd_reset() times out, the error\n path in pdsc_devcmd_locked() queues health_work.\n\n2. A NotifyQ event can trigger the ISR and queue work before free_irq()\n is called in pdsc_teardown().\n\nFix by moving destroy_workqueue() after pdsc_teardown() so the\nworkqueue outlives every queuer; destroy_workqueue() then flushes any\nwork still pending.\n\nDraining the queued work also requires ordering the teardown so the\nresources that work touches are freed last:\n\n - In pdsc_qcq_free(), after freeing the interrupt, cancel_work_sync()\n the queue\u0027s work and only then clear qcq-\u003eintx, so\n pdsc_process_adminq()\u0027s read of qcq-\u003eintx for interrupt-credit\n return cannot race with the clear.\n\n - Free adminqcq before notifyqcq: the shared adminq ISR is released\n when adminqcq is freed, and the adminq work accesses notifyqcq, so\n both must be stopped before notifyqcq is freed."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:03:15.551Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/224214eb4182ff20a665b615a90b66017539dd75"
},
{
"url": "https://git.kernel.org/stable/c/9e0f80fac50ab95dd75537c8ecaf5051d01f19b5"
},
{
"url": "https://git.kernel.org/stable/c/ecc7a7d7569ec1d6a61e18372696b9de97635156"
},
{
"url": "https://git.kernel.org/stable/c/0ad134881508c36b65c1a8864f8bec53adbd3327"
}
],
"title": "pds_core: fix use-after-free on workqueue during remove",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68318",
"datePublished": "2026-08-10T12:02:53.197Z",
"dateReserved": "2026-07-30T09:28:09.382Z",
"dateUpdated": "2026-08-17T05:03:15.551Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72117 (GCVE-0-2026-72117)
Vulnerability from cvelistv5
Published
2026-08-15 05:52
Modified
2026-08-19 16:36
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
can: bcm: fix data race on rx_stamp/rx_ifindex in bcm_rx_handler()
For an rx op subscribed on all interfaces (ifindex == 0), the same op
is registered once in the shared per-netns wildcard filter list, so
bcm_rx_handler() can run concurrently on different CPUs for frames
arriving on different net devices.
op->rx_stamp and op->rx_ifindex were written before bcm_rx_update_lock was
taken, allowing concurrent writers to race each other - including a torn
store of the 64-bit rx_stamp on 32-bit platforms.
Beyond a torn store bcm_send_to_user() must report the timestamp/ifindex
of the very same frame whose content it is delivering. So the assignment
is placed in the same unbroken bcm_rx_update_lock section as the content
comparison.
As a side effect, the RTR-request frame feature (which never reach
bcm_send_to_user()) no longer updates rx_stamp/rx_ifindex, since only
the notification path needs them.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/can/bcm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b64f60c468d149aca22ea56bb842b9730215aaa5",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "c8a5d7cb095d3b12bd9dcf752d6ca0ff50872ac5",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "4b97410f4bba18d2ee2784c8e089104f387bc27c",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "5f246b96ab47523ec9b8ea870b5c567a3cb1eb1c",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "656ff69ef235699035e57d9e1ae417e62a38aa7f",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "136de17f38630307991c59aa7080012a99451783",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "c312b750bb5ac3348cfc85dab25e90937bd4d251",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "58fd6cbc8541216af1d7ed272ea7ac2b66d50fd8",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/can/bcm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.25"
},
{
"lessThan": "2.6.25",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.25",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: bcm: fix data race on rx_stamp/rx_ifindex in bcm_rx_handler()\n\nFor an rx op subscribed on all interfaces (ifindex == 0), the same op\nis registered once in the shared per-netns wildcard filter list, so\nbcm_rx_handler() can run concurrently on different CPUs for frames\narriving on different net devices.\n\nop-\u003erx_stamp and op-\u003erx_ifindex were written before bcm_rx_update_lock was\ntaken, allowing concurrent writers to race each other - including a torn\nstore of the 64-bit rx_stamp on 32-bit platforms.\n\nBeyond a torn store bcm_send_to_user() must report the timestamp/ifindex\nof the very same frame whose content it is delivering. So the assignment\nis placed in the same unbroken bcm_rx_update_lock section as the content\ncomparison.\n\nAs a side effect, the RTR-request frame feature (which never reach\nbcm_send_to_user()) no longer updates rx_stamp/rx_ifindex, since only\nthe notification path needs them."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:36:08.847Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b64f60c468d149aca22ea56bb842b9730215aaa5"
},
{
"url": "https://git.kernel.org/stable/c/c8a5d7cb095d3b12bd9dcf752d6ca0ff50872ac5"
},
{
"url": "https://git.kernel.org/stable/c/4b97410f4bba18d2ee2784c8e089104f387bc27c"
},
{
"url": "https://git.kernel.org/stable/c/5f246b96ab47523ec9b8ea870b5c567a3cb1eb1c"
},
{
"url": "https://git.kernel.org/stable/c/656ff69ef235699035e57d9e1ae417e62a38aa7f"
},
{
"url": "https://git.kernel.org/stable/c/136de17f38630307991c59aa7080012a99451783"
},
{
"url": "https://git.kernel.org/stable/c/c312b750bb5ac3348cfc85dab25e90937bd4d251"
},
{
"url": "https://git.kernel.org/stable/c/58fd6cbc8541216af1d7ed272ea7ac2b66d50fd8"
}
],
"title": "can: bcm: fix data race on rx_stamp/rx_ifindex in bcm_rx_handler()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72117",
"datePublished": "2026-08-15T05:52:56.991Z",
"dateReserved": "2026-08-09T03:40:39.906Z",
"dateUpdated": "2026-08-19T16:36:08.847Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68252 (GCVE-0-2026-68252)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-18 06:55
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu/sdma7.0: replace BUG_ON() with WARN_ON()
There's no need to crash the kernel for these cases.
(cherry picked from commit 9723a8bed3aa251a26bee4583bac9d8fb064dd44)
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/sdma_v7_0.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "395bf099ef7153227600a2d8cb087f45c4a277b6",
"status": "affected",
"version": "b412351e91bde3a6ec546b598087bdc3fcc458ee",
"versionType": "git"
},
{
"lessThan": "4c09483325360373656214cc7a2fd29dc73037a5",
"status": "affected",
"version": "b412351e91bde3a6ec546b598087bdc3fcc458ee",
"versionType": "git"
},
{
"lessThan": "bcbd53d25da879bbce75faad9888c9a56e942fec",
"status": "affected",
"version": "b412351e91bde3a6ec546b598087bdc3fcc458ee",
"versionType": "git"
},
{
"lessThan": "e80e28f398f5d9f6e361ffb56382d2e74fc87556",
"status": "affected",
"version": "b412351e91bde3a6ec546b598087bdc3fcc458ee",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/sdma_v7_0.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.11"
},
{
"lessThan": "6.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/sdma7.0: replace BUG_ON() with WARN_ON()\n\nThere\u0027s no need to crash the kernel for these cases.\n\n(cherry picked from commit 9723a8bed3aa251a26bee4583bac9d8fb064dd44)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-18T06:55:52.977Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/395bf099ef7153227600a2d8cb087f45c4a277b6"
},
{
"url": "https://git.kernel.org/stable/c/4c09483325360373656214cc7a2fd29dc73037a5"
},
{
"url": "https://git.kernel.org/stable/c/bcbd53d25da879bbce75faad9888c9a56e942fec"
},
{
"url": "https://git.kernel.org/stable/c/e80e28f398f5d9f6e361ffb56382d2e74fc87556"
}
],
"title": "drm/amdgpu/sdma7.0: replace BUG_ON() with WARN_ON()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68252",
"datePublished": "2026-08-10T12:01:18.379Z",
"dateReserved": "2026-07-30T09:28:09.377Z",
"dateUpdated": "2026-08-18T06:55:52.977Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68376 (GCVE-0-2026-68376)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
sctp: fix auth_hmacs array size in struct sctp_cookie
The auth_hmacs array in struct sctp_cookie is supposed to store a complete
SCTP_AUTH_HMAC_ALGO parameter, which consists of a struct sctp_paramhdr
followed by N HMAC identifiers.
However, the array size was calculated using an extra 2 bytes instead of
sizeof(struct sctp_paramhdr), which is 4 bytes. When four HMAC identifiers
are configured, the HMAC-ALGO parameter stored in the endpoint is larger
than the auth_hmacs buffer in the cookie.
As a result, sctp_association_init() copies beyond the end of auth_hmacs
when initializing the association, corrupting the adjacent auth_chunks
field. This can lead to an invalid HMAC identifier being accepted and later
cause an out-of-bounds read in sctp_auth_get_hmac().
Fix the array size calculation by including the full SCTP parameter header
size.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1f485649f52929d9937b346a920a522a7363e202 Version: 1f485649f52929d9937b346a920a522a7363e202 Version: 1f485649f52929d9937b346a920a522a7363e202 Version: 1f485649f52929d9937b346a920a522a7363e202 Version: 1f485649f52929d9937b346a920a522a7363e202 Version: 1f485649f52929d9937b346a920a522a7363e202 Version: 1f485649f52929d9937b346a920a522a7363e202 Version: 1f485649f52929d9937b346a920a522a7363e202 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"include/net/sctp/structs.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "317731d01b03c529809df36d3a7d149677a8729d",
"status": "affected",
"version": "1f485649f52929d9937b346a920a522a7363e202",
"versionType": "git"
},
{
"lessThan": "0528485f27016a42804abe01aa61b39d85fa803e",
"status": "affected",
"version": "1f485649f52929d9937b346a920a522a7363e202",
"versionType": "git"
},
{
"lessThan": "ee5e65964f456adfe14d526fba0bd055de98ecf3",
"status": "affected",
"version": "1f485649f52929d9937b346a920a522a7363e202",
"versionType": "git"
},
{
"lessThan": "0b4414e43e0861d67276031cc21401d7e87de3da",
"status": "affected",
"version": "1f485649f52929d9937b346a920a522a7363e202",
"versionType": "git"
},
{
"lessThan": "d0a59ba58578e2b330fff80a44fe519f3ba7d8c7",
"status": "affected",
"version": "1f485649f52929d9937b346a920a522a7363e202",
"versionType": "git"
},
{
"lessThan": "a8d20ba0ab518c9ccbcde258f25fc1ee6e51d5db",
"status": "affected",
"version": "1f485649f52929d9937b346a920a522a7363e202",
"versionType": "git"
},
{
"lessThan": "3aa40c3bccac2312ea7cf97f329190637f972b5d",
"status": "affected",
"version": "1f485649f52929d9937b346a920a522a7363e202",
"versionType": "git"
},
{
"lessThan": "e0b5252a59383b77d1b8dbeda00b7184dd95f4d3",
"status": "affected",
"version": "1f485649f52929d9937b346a920a522a7363e202",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"include/net/sctp/structs.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.24"
},
{
"lessThan": "2.6.24",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.24",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: fix auth_hmacs array size in struct sctp_cookie\n\nThe auth_hmacs array in struct sctp_cookie is supposed to store a complete\nSCTP_AUTH_HMAC_ALGO parameter, which consists of a struct sctp_paramhdr\nfollowed by N HMAC identifiers.\n\nHowever, the array size was calculated using an extra 2 bytes instead of\nsizeof(struct sctp_paramhdr), which is 4 bytes. When four HMAC identifiers\nare configured, the HMAC-ALGO parameter stored in the endpoint is larger\nthan the auth_hmacs buffer in the cookie.\n\nAs a result, sctp_association_init() copies beyond the end of auth_hmacs\nwhen initializing the association, corrupting the adjacent auth_chunks\nfield. This can lead to an invalid HMAC identifier being accepted and later\ncause an out-of-bounds read in sctp_auth_get_hmac().\n\nFix the array size calculation by including the full SCTP parameter header\nsize."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The out-of-bounds index is taken directly from the `hmac_id` field of an AUTH chunk received from a remote SCTP peer and processed in sctp_sf_eat_auth()/sctp_sf_authenticate(), which is the normal SCTP packet-receive path in net/sctp.\nAC:H - The overflow only occurs when the victim endpoint was configured with exactly four HMAC identifiers via setsockopt(SCTP_HMAC_IDENT); three or fewer fit the buffer exactly. That local socket configuration is beyond a remote attacker\u0027s control, though a local user can arrange it and then attack over loopback.\nPR:N - Once the endpoint is so configured, any peer that completes an ordinary SCTP handshake can send the malformed AUTH chunk; the bogus hmac_id is accepted and dereferenced before any shared-key or HMAC verification, so no credentials of any kind are needed.\nUI:N - The AUTH chunk is consumed automatically by the kernel SCTP state machine on packet receipt; no action by any local user or administrator is needed at attack time.\nS:U - The corruption and the subsequent out-of-bounds accesses are confined to kernel memory within the same security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - sctp_auth_get_hmac() reads far past the 4-entry sctp_hmac_list, and on kernels before the HMAC library conversion sctp_auth_calculate_hmac() reads a function-table pointer ~262 KB beyond the 4-pointer ep-\u003eauth_hmacs heap array; the accepted/rejected signature length acts as an oracle leaking the out-of-bounds value.\nI:H - The wild crypto_shash pointer fetched out of bounds is passed straight to crypto_shash_setkey()/crypto_shash_tfm_digest(), giving an attacker-groomable indirect call and write target; on current kernels a fixed 32-byte HMAC is written into a digest area sized from out-of-bounds data.\nA:H - Dereferencing an out-of-bounds heap pointer as a crypto transform, or writing a 32-byte digest into an undersized skb region, reliably oopses or panics the kernel, and the attack can be repeated on every association."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:35.759Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/317731d01b03c529809df36d3a7d149677a8729d"
},
{
"url": "https://git.kernel.org/stable/c/0528485f27016a42804abe01aa61b39d85fa803e"
},
{
"url": "https://git.kernel.org/stable/c/ee5e65964f456adfe14d526fba0bd055de98ecf3"
},
{
"url": "https://git.kernel.org/stable/c/0b4414e43e0861d67276031cc21401d7e87de3da"
},
{
"url": "https://git.kernel.org/stable/c/d0a59ba58578e2b330fff80a44fe519f3ba7d8c7"
},
{
"url": "https://git.kernel.org/stable/c/a8d20ba0ab518c9ccbcde258f25fc1ee6e51d5db"
},
{
"url": "https://git.kernel.org/stable/c/3aa40c3bccac2312ea7cf97f329190637f972b5d"
},
{
"url": "https://git.kernel.org/stable/c/e0b5252a59383b77d1b8dbeda00b7184dd95f4d3"
}
],
"title": "sctp: fix auth_hmacs array size in struct sctp_cookie",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68376",
"datePublished": "2026-08-10T12:03:54.666Z",
"dateReserved": "2026-07-30T09:28:09.386Z",
"dateUpdated": "2026-08-19T16:34:35.759Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64574 (GCVE-0-2026-64574)
Vulnerability from cvelistv5
Published
2026-08-05 08:08
Modified
2026-08-17 04:57
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: tear down new links on vif update error path
When ieee80211_vif_update_links() adds new links it allocates a link
container for each and calls ieee80211_link_init() (which registers the
per-link debugfs files with file->private_data pointing into the container)
and ieee80211_link_setup(). If the subsequent drv_change_vif_links() fails,
the error path restores the old pointers and jumps to 'free', which frees
the new containers but never removes their debugfs entries or stops the
links. The debugfs files survive with file->private_data dangling at the
freed container, so a later open()+read() (e.g. link-1/txpower)
dereferences freed memory in ieee80211_if_read_link(), a use-after-free.
The removal path already dismantles links correctly via
ieee80211_tear_down_links(), which removes each link's keys and debugfs
entries and calls ieee80211_link_stop(); the add path on the error branch
does not. Commit be1ba9ed221f ("wifi: mac80211: avoid weird state in error
path") hardened this same error path for the link-removal case
(new_links == 0) but left the newly-added links' teardown unaddressed.
drv_change_vif_links() can fail at runtime on MLO drivers (internal
allocation / queue / firmware command failures).
Remove the new links' debugfs entries and stop them before freeing.
BUG: KASAN: slab-use-after-free in ieee80211_if_read_link (net/mac80211/debugfs_netdev.c:127)
Read of size 8 at addr ffff888011290000 by task exploit/145
Call Trace:
...
ieee80211_if_read_link (net/mac80211/debugfs_netdev.c:127)
short_proxy_read (fs/debugfs/file.c:373)
vfs_read (fs/read_write.c:572)
ksys_read (fs/read_write.c:716)
do_syscall_64 (arch/x86/entry/syscall_64.c:94)
entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)
...
Oops: general protection fault, probably for non-canonical address 0xdffffc000000000a
RIP: 0010:ieee80211_if_read_link (net/mac80211/debugfs_netdev.c:127)
Kernel panic - not syncing: Fatal exception
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/mac80211/link.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "329589417214d3b7221432e5b266ed2bba7ff674",
"status": "affected",
"version": "170cd6a66d9a164180eb4dc72d50afa6ce1ce566",
"versionType": "git"
},
{
"lessThan": "c57d97f381306bbfba174e8f708419e007824e0c",
"status": "affected",
"version": "170cd6a66d9a164180eb4dc72d50afa6ce1ce566",
"versionType": "git"
},
{
"lessThan": "0f7eaeb950adb77f71beb546e5ab30f90b41fe6f",
"status": "affected",
"version": "170cd6a66d9a164180eb4dc72d50afa6ce1ce566",
"versionType": "git"
},
{
"lessThan": "901a73523e093beff123b54b1ceaf3113f18acc9",
"status": "affected",
"version": "170cd6a66d9a164180eb4dc72d50afa6ce1ce566",
"versionType": "git"
},
{
"lessThan": "952c02b33f56207a160421bcd61e7ac53c9c59ae",
"status": "affected",
"version": "170cd6a66d9a164180eb4dc72d50afa6ce1ce566",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/mac80211/link.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.4"
},
{
"lessThan": "6.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: tear down new links on vif update error path\n\nWhen ieee80211_vif_update_links() adds new links it allocates a link\ncontainer for each and calls ieee80211_link_init() (which registers the\nper-link debugfs files with file-\u003eprivate_data pointing into the container)\nand ieee80211_link_setup(). If the subsequent drv_change_vif_links() fails,\nthe error path restores the old pointers and jumps to \u0027free\u0027, which frees\nthe new containers but never removes their debugfs entries or stops the\nlinks. The debugfs files survive with file-\u003eprivate_data dangling at the\nfreed container, so a later open()+read() (e.g. link-1/txpower)\ndereferences freed memory in ieee80211_if_read_link(), a use-after-free.\n\nThe removal path already dismantles links correctly via\nieee80211_tear_down_links(), which removes each link\u0027s keys and debugfs\nentries and calls ieee80211_link_stop(); the add path on the error branch\ndoes not. Commit be1ba9ed221f (\"wifi: mac80211: avoid weird state in error\npath\") hardened this same error path for the link-removal case\n(new_links == 0) but left the newly-added links\u0027 teardown unaddressed.\n\ndrv_change_vif_links() can fail at runtime on MLO drivers (internal\nallocation / queue / firmware command failures).\n\nRemove the new links\u0027 debugfs entries and stop them before freeing.\n\n BUG: KASAN: slab-use-after-free in ieee80211_if_read_link (net/mac80211/debugfs_netdev.c:127)\n Read of size 8 at addr ffff888011290000 by task exploit/145\n Call Trace:\n ...\n ieee80211_if_read_link (net/mac80211/debugfs_netdev.c:127)\n short_proxy_read (fs/debugfs/file.c:373)\n vfs_read (fs/read_write.c:572)\n ksys_read (fs/read_write.c:716)\n do_syscall_64 (arch/x86/entry/syscall_64.c:94)\n entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)\n ...\n Oops: general protection fault, probably for non-canonical address 0xdffffc000000000a\n RIP: 0010:ieee80211_if_read_link (net/mac80211/debugfs_netdev.c:127)\n Kernel panic - not syncing: Fatal exception"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached via local nl80211 link updates (NL80211_CMD_ADD_LINK / ieee80211_vif_set_links \u2192 ieee80211_vif_update_links) and completed by a local debugfs open/read of the dangling per-link file, not by processing over-the-air frames alone.\nAC:L - An attacker can reliably force the error path by adding an MLO AP link whose MAC duplicates an existing link so ieee80211_check_dup_link_addrs() fails after ieee80211_link_init() already registered debugfs, then read the leftover file; no attacker-independent condition is required.\nPR:L - NL80211_CMD_ADD_LINK is gated by GENL_UNS_ADMIN_PERM (CAP_NET_ADMIN in the netns user_ns), which an unprivileged user can obtain via user/net namespaces or common WiFi management paths, so privileges are Low rather than init-namespace root.\nUI:N - The attacker issues the nl80211 ADD_LINK sequence and the subsequent debugfs read themselves; no separate victim action such as mounting a filesystem or opening a hostile file is required.\nS:U - The use-after-free and resulting kernel memory corruption stay within the host mac80211/debugfs authority and do not cross a VM, IOMMU, or other separate security boundary.\nC:H - Dangling debugfs file-\u003eprivate_data points at the freed link_container; reading it (ieee80211_if_read_link) is a slab use-after-free that can be reclaimed/sprayed for arbitrary kernel memory disclosure.\nI:H - The same freed link object is the debugfs private_data for readable/writable per-link files, so UAF reclaim enables attacker-controlled structure contents and control-flow hijack consistent with kernel UAF integrity High.\nA:H - The fix commit\u2019s KASAN slab-use-after-free in ieee80211_if_read_link leads to a general protection fault and kernel panic, so availability impact is High even without full exploitation."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:57:54.008Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/329589417214d3b7221432e5b266ed2bba7ff674"
},
{
"url": "https://git.kernel.org/stable/c/c57d97f381306bbfba174e8f708419e007824e0c"
},
{
"url": "https://git.kernel.org/stable/c/0f7eaeb950adb77f71beb546e5ab30f90b41fe6f"
},
{
"url": "https://git.kernel.org/stable/c/901a73523e093beff123b54b1ceaf3113f18acc9"
},
{
"url": "https://git.kernel.org/stable/c/952c02b33f56207a160421bcd61e7ac53c9c59ae"
}
],
"title": "wifi: mac80211: tear down new links on vif update error path",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64574",
"datePublished": "2026-08-05T08:08:10.272Z",
"dateReserved": "2026-07-19T15:36:31.797Z",
"dateUpdated": "2026-08-17T04:57:54.008Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72113 (GCVE-0-2026-72113)
Vulnerability from cvelistv5
Published
2026-08-15 05:52
Modified
2026-08-19 16:35
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
can: bcm: add missing device refcount for CAN filter removal
sashiko-bot remarked a problem with a concurrent device unregistration
in isotp.c which also is present in the bcm.c code. A former fix for raw.c
commit c275a176e4b6 ("can: raw: add missing refcount for memory leak fix")
introduced a netdevice_tracker which solves the issue for bcm.c too.
bcm_release(), bcm_delete_rx_op() and bcm_notifier() relied on
dev_get_by_index(ifindex) to re-find the device for an rx_op before
unregistering its filter. If a concurrent NETDEV_UNREGISTER has already
unlisted the device from the ifindex table, that lookup fails and
can_rx_unregister() is silently skipped, leaving a stale CAN filter
pointing at the soon-to-be-freed bcm_op/socket.
Hold a netdev_hold()/netdev_put() tracked reference on op->rx_reg_dev
from the moment the rx filter is registered in bcm_rx_setup() until it
is unregistered in bcm_rx_unreg(), and use that reference directly in
bcm_release() and bcm_delete_rx_op() instead of re-looking the device
up by ifindex.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/can/bcm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "bd5232663524e94cc5aad861dca11e3db8e2ab6f",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "ee8b36d0faca08f35b889b6e9aa850695e5b8ba9",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "dcaee869913c7210cd47ed0a8f27349d7bdcdb7b",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "84aa4807816e405c1bf87114fc63e06d244281ef",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "633bda66fbf309f5de5e1ad6defe8e6b1d77a20f",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "b024c21c9066f6957b7d4a8f2037e4b000c5e041",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "04d23061bbf18d5d81022eb21e9d32e99d24468d",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "d59948293ea34b6337ce2b5febab8510de70048c",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/can/bcm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.25"
},
{
"lessThan": "2.6.25",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.25",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: bcm: add missing device refcount for CAN filter removal\n\nsashiko-bot remarked a problem with a concurrent device unregistration\nin isotp.c which also is present in the bcm.c code. A former fix for raw.c\ncommit c275a176e4b6 (\"can: raw: add missing refcount for memory leak fix\")\nintroduced a netdevice_tracker which solves the issue for bcm.c too.\n\nbcm_release(), bcm_delete_rx_op() and bcm_notifier() relied on\ndev_get_by_index(ifindex) to re-find the device for an rx_op before\nunregistering its filter. If a concurrent NETDEV_UNREGISTER has already\nunlisted the device from the ifindex table, that lookup fails and\ncan_rx_unregister() is silently skipped, leaving a stale CAN filter\npointing at the soon-to-be-freed bcm_op/socket.\n\nHold a netdev_hold()/netdev_put() tracked reference on op-\u003erx_reg_dev\nfrom the moment the rx filter is registered in bcm_rx_setup() until it\nis unregistered in bcm_rx_unreg(), and use that reference directly in\nbcm_release() and bcm_delete_rx_op() instead of re-looking the device\nup by ifindex."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires local syscalls (socket/sendmsg/close) on PF_CAN/CAN_BCM and concurrent netdev teardown via netlink; the flaw is in local filter cleanup, not remote IP packet handling.\nAC:L - An attacker can reliably win the race by concurrently closing the BCM socket or issuing RX_DELETE while deleting the bound vcan/CAN interface from the same user namespace.\nPR:L - BCM sockets need no special capability, and CAP_NET_ADMIN for creating/deleting vcan interfaces is obtainable by unprivileged users via user namespaces (unshare -Urn).\nUI:N - No victim interaction is required; exploitation is fully attacker-driven through BCM socket setup, concurrent netdev removal, and subsequent CAN traffic to hit the stale filter.\nS:U - Impact is confined to kernel memory corruption and privilege escalation within the same security authority; it does not cross VM, container, or IOMMU boundaries.\nC:H - Stale CAN filters leave a use-after-free on freed bcm_op structures; bcm_rx_handler dereferences attacker-influenced freed memory, enabling arbitrary kernel memory disclosure via heap grooming.\nI:H - The UAF in bcm_rx_handler provides write primitives over freed bcm_op fields (timers, frame buffers, socket pointers), enabling control-flow hijacking and arbitrary kernel code execution.\nA:H - Accessing the freed bcm_op from bcm_rx_handler causes kernel oops/panic; UAF is inherently crash-prone even before full exploitation."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:35:58.404Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/bd5232663524e94cc5aad861dca11e3db8e2ab6f"
},
{
"url": "https://git.kernel.org/stable/c/ee8b36d0faca08f35b889b6e9aa850695e5b8ba9"
},
{
"url": "https://git.kernel.org/stable/c/dcaee869913c7210cd47ed0a8f27349d7bdcdb7b"
},
{
"url": "https://git.kernel.org/stable/c/84aa4807816e405c1bf87114fc63e06d244281ef"
},
{
"url": "https://git.kernel.org/stable/c/633bda66fbf309f5de5e1ad6defe8e6b1d77a20f"
},
{
"url": "https://git.kernel.org/stable/c/b024c21c9066f6957b7d4a8f2037e4b000c5e041"
},
{
"url": "https://git.kernel.org/stable/c/04d23061bbf18d5d81022eb21e9d32e99d24468d"
},
{
"url": "https://git.kernel.org/stable/c/d59948293ea34b6337ce2b5febab8510de70048c"
}
],
"title": "can: bcm: add missing device refcount for CAN filter removal",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72113",
"datePublished": "2026-08-15T05:52:54.001Z",
"dateReserved": "2026-08-09T03:40:39.906Z",
"dateUpdated": "2026-08-19T16:35:58.404Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68333 (GCVE-0-2026-68333)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
dpaa2-switch: put MAC endpoint device on disconnect
fsl_mc_get_endpoint() returns the MAC endpoint device with a reference
taken through device_find_child(). The switch port connect path stores
that device in mac->mc_dev and keeps it for the lifetime of the connected
MAC object.
However, the disconnect path only closes the MAC and frees the dpaa2_mac
object. It does not drop the endpoint device reference stored in
mac->mc_dev, so every successful connect leaks that device reference when
the MAC is later disconnected.
Drop the endpoint device reference before freeing the dpaa2_mac object.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 84cba72956fddf29ba666f885c39ed147024c125 Version: 84cba72956fddf29ba666f885c39ed147024c125 Version: 84cba72956fddf29ba666f885c39ed147024c125 Version: 84cba72956fddf29ba666f885c39ed147024c125 Version: 84cba72956fddf29ba666f885c39ed147024c125 Version: 84cba72956fddf29ba666f885c39ed147024c125 Version: 84cba72956fddf29ba666f885c39ed147024c125 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/freescale/dpaa2/dpaa2-switch.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "196f7301537814bef0f5915f87cd73d6d1235c19",
"status": "affected",
"version": "84cba72956fddf29ba666f885c39ed147024c125",
"versionType": "git"
},
{
"lessThan": "0e9a6811eb6198ab17538cd01fa155d133b238ed",
"status": "affected",
"version": "84cba72956fddf29ba666f885c39ed147024c125",
"versionType": "git"
},
{
"lessThan": "1f4ca61b7a93de3dfa5161bcd38ecb99bb091c38",
"status": "affected",
"version": "84cba72956fddf29ba666f885c39ed147024c125",
"versionType": "git"
},
{
"lessThan": "680eecc850d36a280df9780496bc603fec17b2d6",
"status": "affected",
"version": "84cba72956fddf29ba666f885c39ed147024c125",
"versionType": "git"
},
{
"lessThan": "26ac2d3602347f0377fbcd5214bc28a9d735ae68",
"status": "affected",
"version": "84cba72956fddf29ba666f885c39ed147024c125",
"versionType": "git"
},
{
"lessThan": "c27694ff6748e08fcd2fdba89018439d75b8198f",
"status": "affected",
"version": "84cba72956fddf29ba666f885c39ed147024c125",
"versionType": "git"
},
{
"lessThan": "4c1eabbef7a1707635652e956e39db1269c3af2b",
"status": "affected",
"version": "84cba72956fddf29ba666f885c39ed147024c125",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/freescale/dpaa2/dpaa2-switch.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.15"
},
{
"lessThan": "5.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndpaa2-switch: put MAC endpoint device on disconnect\n\nfsl_mc_get_endpoint() returns the MAC endpoint device with a reference\ntaken through device_find_child(). The switch port connect path stores\nthat device in mac-\u003emc_dev and keeps it for the lifetime of the connected\nMAC object.\n\nHowever, the disconnect path only closes the MAC and frees the dpaa2_mac\nobject. It does not drop the endpoint device reference stored in\nmac-\u003emc_dev, so every successful connect leaks that device reference when\nthe MAC is later disconnected.\n\nDrop the endpoint device reference before freeing the dpaa2_mac object."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:30.627Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/196f7301537814bef0f5915f87cd73d6d1235c19"
},
{
"url": "https://git.kernel.org/stable/c/0e9a6811eb6198ab17538cd01fa155d133b238ed"
},
{
"url": "https://git.kernel.org/stable/c/1f4ca61b7a93de3dfa5161bcd38ecb99bb091c38"
},
{
"url": "https://git.kernel.org/stable/c/680eecc850d36a280df9780496bc603fec17b2d6"
},
{
"url": "https://git.kernel.org/stable/c/26ac2d3602347f0377fbcd5214bc28a9d735ae68"
},
{
"url": "https://git.kernel.org/stable/c/c27694ff6748e08fcd2fdba89018439d75b8198f"
},
{
"url": "https://git.kernel.org/stable/c/4c1eabbef7a1707635652e956e39db1269c3af2b"
}
],
"title": "dpaa2-switch: put MAC endpoint device on disconnect",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68333",
"datePublished": "2026-08-10T12:03:09.524Z",
"dateReserved": "2026-07-30T09:28:09.383Z",
"dateUpdated": "2026-08-19T16:33:30.627Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68284 (GCVE-0-2026-68284)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-19 16:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg()
tcp_bpf_sendmsg() keeps msg_tx across sk_stream_wait_memory(), which
drops and reacquires the socket lock. Its error path tries to decide
whether msg_tx names the local temporary message by comparing it with
the current value of psock->cork.
This comparison is unsafe when two threads send on the same socket:
Thread A Thread B
msg_tx = psock->cork
sk_msg_alloc() fails
sk_stream_wait_memory()
releases the socket lock acquires the socket lock
completes the cork
psock->cork = NULL
frees the cork
reacquires the socket lock
msg_tx != psock->cork
sk_msg_free(msg_tx)
The stale cork is therefore mistaken for the local temporary message
and freed again. KASAN reported:
BUG: KASAN: slab-use-after-free in sk_msg_free+0x49/0x50
Read of size 4 at addr ffff88810c908800 by task poc/90
Call Trace:
sk_msg_free+0x49/0x50
tcp_bpf_sendmsg+0x14f5/0x1cc0
__sys_sendto+0x32c/0x3a0
__x64_sys_sendto+0xdb/0x1b0
Allocated by task 89:
__kasan_kmalloc+0x8f/0xa0
tcp_bpf_sendmsg+0x16b3/0x1cc0
Freed by task 91:
__kasan_slab_free+0x43/0x70
kfree+0x131/0x3c0
tcp_bpf_sendmsg+0xec3/0x1cc0
msg_tx can only name the stack-local tmp or the shared cork. Check for
tmp directly so a changed psock->cork cannot turn a shared message into
an apparent local one.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 604326b41a6fb9b4a78b6179335decee0365cd8c Version: 604326b41a6fb9b4a78b6179335decee0365cd8c Version: 604326b41a6fb9b4a78b6179335decee0365cd8c Version: 604326b41a6fb9b4a78b6179335decee0365cd8c Version: 604326b41a6fb9b4a78b6179335decee0365cd8c Version: 604326b41a6fb9b4a78b6179335decee0365cd8c Version: 604326b41a6fb9b4a78b6179335decee0365cd8c Version: 604326b41a6fb9b4a78b6179335decee0365cd8c |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ipv4/tcp_bpf.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "0688e6fe599d2d39147ae9ece97944c6e1815ebf",
"status": "affected",
"version": "604326b41a6fb9b4a78b6179335decee0365cd8c",
"versionType": "git"
},
{
"lessThan": "b2bcbeabfd843d47468fa095b1bd08ddb90cf616",
"status": "affected",
"version": "604326b41a6fb9b4a78b6179335decee0365cd8c",
"versionType": "git"
},
{
"lessThan": "54be47e7cbb936429c3bbdfc526ea943954aaf80",
"status": "affected",
"version": "604326b41a6fb9b4a78b6179335decee0365cd8c",
"versionType": "git"
},
{
"lessThan": "ee762f684eefa59de34d9ed93cab08336e834f47",
"status": "affected",
"version": "604326b41a6fb9b4a78b6179335decee0365cd8c",
"versionType": "git"
},
{
"lessThan": "cde4d6bcd9b73073c66498f6723c7b364c4dbc18",
"status": "affected",
"version": "604326b41a6fb9b4a78b6179335decee0365cd8c",
"versionType": "git"
},
{
"lessThan": "786d690257ec7a0c839f8710456e444ce3f1348b",
"status": "affected",
"version": "604326b41a6fb9b4a78b6179335decee0365cd8c",
"versionType": "git"
},
{
"lessThan": "752b1159ed5d0c48fe169a3721b96660a9822aa1",
"status": "affected",
"version": "604326b41a6fb9b4a78b6179335decee0365cd8c",
"versionType": "git"
},
{
"lessThan": "2d66a033864e27ab8d5e44cb36f31d9d2413bee4",
"status": "affected",
"version": "604326b41a6fb9b4a78b6179335decee0365cd8c",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ipv4/tcp_bpf.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.20"
},
{
"lessThan": "4.20",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.20",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg()\n\ntcp_bpf_sendmsg() keeps msg_tx across sk_stream_wait_memory(), which\ndrops and reacquires the socket lock. Its error path tries to decide\nwhether msg_tx names the local temporary message by comparing it with\nthe current value of psock-\u003ecork.\n\nThis comparison is unsafe when two threads send on the same socket:\n\n Thread A Thread B\n msg_tx = psock-\u003ecork\n sk_msg_alloc() fails\n sk_stream_wait_memory()\n releases the socket lock acquires the socket lock\n completes the cork\n psock-\u003ecork = NULL\n frees the cork\n reacquires the socket lock\n msg_tx != psock-\u003ecork\n sk_msg_free(msg_tx)\n\nThe stale cork is therefore mistaken for the local temporary message\nand freed again. KASAN reported:\n\n BUG: KASAN: slab-use-after-free in sk_msg_free+0x49/0x50\n Read of size 4 at addr ffff88810c908800 by task poc/90\n Call Trace:\n sk_msg_free+0x49/0x50\n tcp_bpf_sendmsg+0x14f5/0x1cc0\n __sys_sendto+0x32c/0x3a0\n __x64_sys_sendto+0xdb/0x1b0\n Allocated by task 89:\n __kasan_kmalloc+0x8f/0xa0\n tcp_bpf_sendmsg+0x16b3/0x1cc0\n Freed by task 91:\n __kasan_slab_free+0x43/0x70\n kfree+0x131/0x3c0\n tcp_bpf_sendmsg+0xec3/0x1cc0\n\nmsg_tx can only name the stack-local tmp or the shared cork. Check for\ntmp directly so a changed psock-\u003ecork cannot turn a shared message into\nan apparent local one."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerability is triggered by local `sendmsg()`/`sendto()` syscalls issued concurrently by two threads on the same TCP socket attached to a BPF sockmap; the remote peer cannot drive the race, so this is a local attack surface.\nAC:L - The attacker controls both sides of the race: it owns both sending threads, can force the `wait_for_memory` path deterministically with a small SO_SNDBUF plus a large blocking send, and can force `sk_stream_wait_memory()` to fail via SO_SNDTIMEO or a socket error, making the stale-cork free reliably reachable.\nPR:L - Once the sockmap and sk_msg verdict/cork program are installed by the platform (a standard deployment such as Cilium/Istio sockops acceleration), an ordinary unprivileged local process owning a socket in the map triggers the bug with plain send syscalls; no capability check guards `tcp_bpf_sendmsg()` itself.\nUI:N - The attacker\u0027s own two threads perform all the required sends; no action by any other user or victim process is needed.\nS:U - The use-after-free corrupts kernel slab and page state within the same kernel security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - `sk_msg_free()` reads the freed `sk_msg` cork object (KASAN slab-use-after-free read), and by reclaiming that slab object with attacker-groomed data the freed scatterlist can be steered to leak or expose arbitrary kernel memory contents.\nI:H - Beyond the stale read, the path re-frees the cork\u0027s scatterlist pages and uncharges socket memory, giving a double-free/page-refcount-underflow primitive on an attacker-groomable slab object, which is classically leveraged into arbitrary kernel write and control-flow hijack.\nA:H - The use-after-free and duplicate page release corrupt slab and page allocator state, reliably producing a kernel oops or panic and taking the whole system down."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:32:41.174Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/0688e6fe599d2d39147ae9ece97944c6e1815ebf"
},
{
"url": "https://git.kernel.org/stable/c/b2bcbeabfd843d47468fa095b1bd08ddb90cf616"
},
{
"url": "https://git.kernel.org/stable/c/54be47e7cbb936429c3bbdfc526ea943954aaf80"
},
{
"url": "https://git.kernel.org/stable/c/ee762f684eefa59de34d9ed93cab08336e834f47"
},
{
"url": "https://git.kernel.org/stable/c/cde4d6bcd9b73073c66498f6723c7b364c4dbc18"
},
{
"url": "https://git.kernel.org/stable/c/786d690257ec7a0c839f8710456e444ce3f1348b"
},
{
"url": "https://git.kernel.org/stable/c/752b1159ed5d0c48fe169a3721b96660a9822aa1"
},
{
"url": "https://git.kernel.org/stable/c/2d66a033864e27ab8d5e44cb36f31d9d2413bee4"
}
],
"title": "bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68284",
"datePublished": "2026-08-10T12:02:16.572Z",
"dateReserved": "2026-07-30T09:28:09.379Z",
"dateUpdated": "2026-08-19T16:32:41.174Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72114 (GCVE-0-2026-72114)
Vulnerability from cvelistv5
Published
2026-08-15 05:52
Modified
2026-08-19 16:36
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
can: bcm: validate frame length in bcm_rx_setup() for RTR replies
bcm_tx_setup() validates cf->len against the CAN/CAN FD DLC limits
before installing frames for TX_SETUP, but bcm_rx_setup() never did
the same for the RTR-reply frame configured via RX_SETUP with
RX_RTR_FRAME.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/can/bcm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "cc1f9569f1c1adf74fa69d6f716a31b58a2fc6ce",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "204f2b232717bc470ddb9e1da1d27dd9c6ef0caa",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "e061624c0a86c3c26a2bf017e432fbc93ad68f3a",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "7d966cdee006911d3957e1a4e72cb93c39cd8c1e",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "1b475c0c72f44622a320a4386ce9e76f85e69bc7",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "deb6a697cce3f021e731df543597f37a5e54caab",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "59bfddea64159594feb62ef11b7d7a33c8ee3783",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "62ec41f364648be79d54d94d0d240ee326948afd",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/can/bcm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.25"
},
{
"lessThan": "2.6.25",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.25",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: bcm: validate frame length in bcm_rx_setup() for RTR replies\n\nbcm_tx_setup() validates cf-\u003elen against the CAN/CAN FD DLC limits\nbefore installing frames for TX_SETUP, but bcm_rx_setup() never did\nthe same for the RTR-reply frame configured via RX_SETUP with\nRX_RTR_FRAME."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The missing validation is in bcm_rx_setup(), reached only via local PF_CAN SOCK_DGRAM CAN_BCM syscalls (socket/connect/sendmsg RX_SETUP with RX_RTR_FRAME); it is not triggered by remote IP services or by CAN bus traffic alone.\nAC:L - An attacker reliably installs a malformed RTR-reply frame with a single RX_SETUP sendmsg and can trigger bcm_can_tx() by sending or waiting for a matching RTR on the bound interface, with no races or layout dependencies beyond their control.\nPR:L - can_create(), bcm_connect(), and bcm_sendmsg() perform no capability checks; any local user with access to a CAN interface (including vcan created with CAP_NET_ADMIN in an unprivileged user namespace) can open BCM sockets and program RX_SETUP RTR replies.\nUI:N - Exploitation requires only the attacker opening a BCM socket and sending RX_SETUP messages; no victim interaction such as mounting filesystems or opening files is needed once local CAN access exists.\nS:U - Impact is kernel memory corruption and unauthorized CAN frame transmission within the same host security domain; it does not cross VM, container, or IOMMU boundaries even when frames reach an adjacent vehicle or industrial CAN segment.\nC:H - Unvalidated cf-\u003elen values are stored in op-\u003eframes and later passed to bcm_can_tx()/can_send(); many CAN driver ndo_start_xmit paths memcpy(cf-\u003edata, cf-\u003elen) trusting len, enabling out-of-bounds kernel reads when invalid lengths bypass or race skb validation.\nI:H - Attacker-controlled len in the RTR-reply frame can drive out-of-bounds memcpy writes in CAN USB/SPI/hardware xmit paths and inject attacker-crafted frame payloads onto safety-critical automotive, factory, or embedded CAN buses when RTR requests are answered.\nA:H - Out-of-bounds accesses in CAN driver transmit paths from trusted-but-invalid len values can cause kernel WARN/Oops/panic on hardened builds, and repeated malformed RTR-reply transmission attempts can wedge TX queues or disrupt CAN service on affected systems."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:36:00.857Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/cc1f9569f1c1adf74fa69d6f716a31b58a2fc6ce"
},
{
"url": "https://git.kernel.org/stable/c/204f2b232717bc470ddb9e1da1d27dd9c6ef0caa"
},
{
"url": "https://git.kernel.org/stable/c/e061624c0a86c3c26a2bf017e432fbc93ad68f3a"
},
{
"url": "https://git.kernel.org/stable/c/7d966cdee006911d3957e1a4e72cb93c39cd8c1e"
},
{
"url": "https://git.kernel.org/stable/c/1b475c0c72f44622a320a4386ce9e76f85e69bc7"
},
{
"url": "https://git.kernel.org/stable/c/deb6a697cce3f021e731df543597f37a5e54caab"
},
{
"url": "https://git.kernel.org/stable/c/59bfddea64159594feb62ef11b7d7a33c8ee3783"
},
{
"url": "https://git.kernel.org/stable/c/62ec41f364648be79d54d94d0d240ee326948afd"
}
],
"title": "can: bcm: validate frame length in bcm_rx_setup() for RTR replies",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72114",
"datePublished": "2026-08-15T05:52:54.750Z",
"dateReserved": "2026-08-09T03:40:39.906Z",
"dateUpdated": "2026-08-19T16:36:00.857Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68131 (GCVE-0-2026-68131)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-19 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
rbd: Reset positive result codes to zero in object map update path
In a reply message to an RBD request, a positive result code indicates
a data payload, which is not allowed for writes. While
rbd_osd_req_callback() already resets a positive result code for writes
to zero, rbd_object_map_callback() does not. This allows a corrupted
reply to an object map update to trigger the rbd_assert(*result < 0) in
__rbd_obj_handle_request(). This happens, because
rbd_object_map_callback() calls rbd_obj_handle_request() ->
__rbd_obj_handle_request() and passes this positive result code. From
__rbd_obj_handle_request(), rbd_obj_advance_write() is called, which
leaves the positive result code unchanged and returns true. Therefore,
the if(done && *result) branch is executed in __rbd_obj_handle_request()
and the assertion triggers.
This patch fixes the issue by adjusting the logic in the
rbd_object_map_callback() path. A positive result code for an object map
update is now reset to zero (similar to rbd_osd_req_callback()), and the
message is subsequently handled the same way as if the result code was
zero from the beginning. Additionally, a WARN_ON_ONCE() is added for
this case.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 22e8bd51bb0469d1a524130a057f894ff632376a Version: 22e8bd51bb0469d1a524130a057f894ff632376a Version: 22e8bd51bb0469d1a524130a057f894ff632376a Version: 22e8bd51bb0469d1a524130a057f894ff632376a Version: 22e8bd51bb0469d1a524130a057f894ff632376a Version: 22e8bd51bb0469d1a524130a057f894ff632376a Version: 22e8bd51bb0469d1a524130a057f894ff632376a Version: 22e8bd51bb0469d1a524130a057f894ff632376a |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/block/rbd.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "cf1167292f606deaddac35ec384eba48f08a68d2",
"status": "affected",
"version": "22e8bd51bb0469d1a524130a057f894ff632376a",
"versionType": "git"
},
{
"lessThan": "da926959bf791441ba06a80571708c3d0d3cc08f",
"status": "affected",
"version": "22e8bd51bb0469d1a524130a057f894ff632376a",
"versionType": "git"
},
{
"lessThan": "6f33d9d539fb94e5a17589c2dfe271ff9bb64904",
"status": "affected",
"version": "22e8bd51bb0469d1a524130a057f894ff632376a",
"versionType": "git"
},
{
"lessThan": "14995c4250f04b58bf6fc00e0e973a2e1b3cfb9b",
"status": "affected",
"version": "22e8bd51bb0469d1a524130a057f894ff632376a",
"versionType": "git"
},
{
"lessThan": "2419aa74081007dc4d14ff5640659052dfdfd69a",
"status": "affected",
"version": "22e8bd51bb0469d1a524130a057f894ff632376a",
"versionType": "git"
},
{
"lessThan": "34f2a2f32af570dfcc532ad70c080629ee1c32b0",
"status": "affected",
"version": "22e8bd51bb0469d1a524130a057f894ff632376a",
"versionType": "git"
},
{
"lessThan": "b1a61366933224b3ad80975c4d01ac2cc6931ecf",
"status": "affected",
"version": "22e8bd51bb0469d1a524130a057f894ff632376a",
"versionType": "git"
},
{
"lessThan": "a6c4250b81bd30beae94e1b7a4b26fa1193ad2e4",
"status": "affected",
"version": "22e8bd51bb0469d1a524130a057f894ff632376a",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/block/rbd.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.3"
},
{
"lessThan": "5.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nrbd: Reset positive result codes to zero in object map update path\n\nIn a reply message to an RBD request, a positive result code indicates\na data payload, which is not allowed for writes. While\nrbd_osd_req_callback() already resets a positive result code for writes\nto zero, rbd_object_map_callback() does not. This allows a corrupted\nreply to an object map update to trigger the rbd_assert(*result \u003c 0) in\n__rbd_obj_handle_request(). This happens, because\nrbd_object_map_callback() calls rbd_obj_handle_request() -\u003e\n__rbd_obj_handle_request() and passes this positive result code. From\n__rbd_obj_handle_request(), rbd_obj_advance_write() is called, which\nleaves the positive result code unchanged and returns true. Therefore,\nthe if(done \u0026\u0026 *result) branch is executed in __rbd_obj_handle_request()\nand the assertion triggers.\n\nThis patch fixes the issue by adjusting the logic in the\nrbd_object_map_callback() path. A positive result code for an object map\nupdate is now reset to zero (similar to rbd_osd_req_callback()), and the\nmessage is subsequently handled the same way as if the result code was\nzero from the beginning. Additionally, a WARN_ON_ONCE() is added for\nthis case."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The crash is triggered when libceph processes a crafted MOSDOpReply over the Ceph TCP connection and passes a positive r_result into rbd_object_map_callback(); a compromised or malicious OSD/monitor peer can deliver this without any local syscall on the victim.\nAC:L - An attacker controlling the Ceph OSD can deterministically reply to any object-map update request with a positive result code whenever the mapped image has RBD_FEATURE_OBJECT_MAP and write I/O is in flight, with no race or victim-specific memory layout required.\nPR:N - No privileges on the victim host are needed; exploitation only requires the kernel RBD client to be connected to an attacker-controlled or compromised Ceph cluster, consistent with other libceph client CVE scoring where the remote storage peer drives the bug.\nUI:N - After RBD is mapped, object-map updates are driven automatically by block-layer write I/O; no further interactive user action is required at exploit time beyond normal background storage activity on the mapped device.\nS:U - The BUG() panic affects only the kernel on the host running the RBD client and does not cross VM, container, or IOMMU security boundaries to another authority.\nC:N - The vulnerable path returns immediately on a positive result without decoding reply payload or corrupting memory; impact is limited to an assertion failure with no information disclosure primitive.\nI:N - No kernel or user data is modified; the positive result code is mishandled and triggers rbd_assert(*result \u003c 0) leading to BUG(), not an arbitrary write or code-execution primitive.\nA:H - RBD_DEBUG is unconditionally defined so rbd_assert() invokes BUG(), causing a kernel panic that fully denies availability on any host with an affected RBD mapping when a malicious OSD reply is received."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:29:49.752Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/cf1167292f606deaddac35ec384eba48f08a68d2"
},
{
"url": "https://git.kernel.org/stable/c/da926959bf791441ba06a80571708c3d0d3cc08f"
},
{
"url": "https://git.kernel.org/stable/c/6f33d9d539fb94e5a17589c2dfe271ff9bb64904"
},
{
"url": "https://git.kernel.org/stable/c/14995c4250f04b58bf6fc00e0e973a2e1b3cfb9b"
},
{
"url": "https://git.kernel.org/stable/c/2419aa74081007dc4d14ff5640659052dfdfd69a"
},
{
"url": "https://git.kernel.org/stable/c/34f2a2f32af570dfcc532ad70c080629ee1c32b0"
},
{
"url": "https://git.kernel.org/stable/c/b1a61366933224b3ad80975c4d01ac2cc6931ecf"
},
{
"url": "https://git.kernel.org/stable/c/a6c4250b81bd30beae94e1b7a4b26fa1193ad2e4"
}
],
"title": "rbd: Reset positive result codes to zero in object map update path",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68131",
"datePublished": "2026-08-10T11:58:54.155Z",
"dateReserved": "2026-07-30T09:28:09.370Z",
"dateUpdated": "2026-08-19T16:29:49.752Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68306 (GCVE-0-2026-68306)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-17 05:02
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: mt76: mt7996: fix possible NULL-pointer deref in mt7996_mcu_sta_bfer_eht()
mt76_connac_get_eht_phy_cap routine can theoretically return NULL so
check cap pointer before dereferencing it.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/mediatek/mt76/mt7996/mcu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "2b1882cf313ae44181146629b3578a7826c672c9",
"status": "affected",
"version": "ba01944adee9f4a71cf2879b9529057fd8de1972",
"versionType": "git"
},
{
"lessThan": "3e4f848f4a620e1d77c38459e73cf3b362f7bc6b",
"status": "affected",
"version": "ba01944adee9f4a71cf2879b9529057fd8de1972",
"versionType": "git"
},
{
"lessThan": "d5628f39fccc107dca00b98a491d9848898599f7",
"status": "affected",
"version": "ba01944adee9f4a71cf2879b9529057fd8de1972",
"versionType": "git"
},
{
"lessThan": "45c496756c6f6df6c3aeb5b2cb996993d2f14687",
"status": "affected",
"version": "ba01944adee9f4a71cf2879b9529057fd8de1972",
"versionType": "git"
},
{
"lessThan": "2fffc472bec490c8357defcee9c075ca74467352",
"status": "affected",
"version": "ba01944adee9f4a71cf2879b9529057fd8de1972",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/mediatek/mt76/mt7996/mcu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.3"
},
{
"lessThan": "6.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7996: fix possible NULL-pointer deref in mt7996_mcu_sta_bfer_eht()\n\nmt76_connac_get_eht_phy_cap routine can theoretically return NULL so\ncheck cap pointer before dereferencing it."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:02:58.582Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/2b1882cf313ae44181146629b3578a7826c672c9"
},
{
"url": "https://git.kernel.org/stable/c/3e4f848f4a620e1d77c38459e73cf3b362f7bc6b"
},
{
"url": "https://git.kernel.org/stable/c/d5628f39fccc107dca00b98a491d9848898599f7"
},
{
"url": "https://git.kernel.org/stable/c/45c496756c6f6df6c3aeb5b2cb996993d2f14687"
},
{
"url": "https://git.kernel.org/stable/c/2fffc472bec490c8357defcee9c075ca74467352"
}
],
"title": "wifi: mt76: mt7996: fix possible NULL-pointer deref in mt7996_mcu_sta_bfer_eht()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68306",
"datePublished": "2026-08-10T12:02:40.907Z",
"dateReserved": "2026-07-30T09:28:09.381Z",
"dateUpdated": "2026-08-17T05:02:58.582Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68410 (GCVE-0-2026-68410)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-19 16:35
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: libertas: fix memory leak in helper_firmware_cb()
helper_firmware_cb() neglects to free the single-stage firmware image
after a successful async load, leading to a memory leak in the USB
firmware-download path.
Fix this memory leak by calling release_firmware() immediately after
lbs_fw_loaded() returns.
The bug was first flagged by an experimental analysis tool we are
developing for kernel memory-management bugs while analyzing
v6.13-rc1. The tool is still under development and is not yet publicly
available. Manual inspection confirms that the bug is still present in
the current wireless tree.
An x86_64 allyesconfig build showed no new warnings. As we do not have
compatible Libertas USB hardware for exercising this firmware-download
path, no runtime testing was able to be performed.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1dfba3060fe7ee03ccec25a91d35085142dfc295 Version: 1dfba3060fe7ee03ccec25a91d35085142dfc295 Version: 1dfba3060fe7ee03ccec25a91d35085142dfc295 Version: 1dfba3060fe7ee03ccec25a91d35085142dfc295 Version: 1dfba3060fe7ee03ccec25a91d35085142dfc295 Version: 1dfba3060fe7ee03ccec25a91d35085142dfc295 Version: 1dfba3060fe7ee03ccec25a91d35085142dfc295 Version: 1dfba3060fe7ee03ccec25a91d35085142dfc295 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/marvell/libertas/firmware.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "6c1f54a04813676c5a2150d99331c8d21f199374",
"status": "affected",
"version": "1dfba3060fe7ee03ccec25a91d35085142dfc295",
"versionType": "git"
},
{
"lessThan": "7f28722b3e4e0c8d49c859fea4a9b1fa13b5ae06",
"status": "affected",
"version": "1dfba3060fe7ee03ccec25a91d35085142dfc295",
"versionType": "git"
},
{
"lessThan": "ce829286f4935f1eb6b5dcb64da02910ce149c76",
"status": "affected",
"version": "1dfba3060fe7ee03ccec25a91d35085142dfc295",
"versionType": "git"
},
{
"lessThan": "d497b7566e74920acfe283dd6b2cbf1682890796",
"status": "affected",
"version": "1dfba3060fe7ee03ccec25a91d35085142dfc295",
"versionType": "git"
},
{
"lessThan": "eaeb1d74a47fc4864f2c754c0b9d654a9b7dc55c",
"status": "affected",
"version": "1dfba3060fe7ee03ccec25a91d35085142dfc295",
"versionType": "git"
},
{
"lessThan": "6cda91bbb8dc3d22ef0323008a12dcf73a5129da",
"status": "affected",
"version": "1dfba3060fe7ee03ccec25a91d35085142dfc295",
"versionType": "git"
},
{
"lessThan": "644640cde2fb216e6567de5eee780a38dbc95928",
"status": "affected",
"version": "1dfba3060fe7ee03ccec25a91d35085142dfc295",
"versionType": "git"
},
{
"lessThan": "63c2391deefb31e1b801b7f32bd502ca4808639b",
"status": "affected",
"version": "1dfba3060fe7ee03ccec25a91d35085142dfc295",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/marvell/libertas/firmware.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.13"
},
{
"lessThan": "3.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: libertas: fix memory leak in helper_firmware_cb()\n\nhelper_firmware_cb() neglects to free the single-stage firmware image\nafter a successful async load, leading to a memory leak in the USB\nfirmware-download path.\n\nFix this memory leak by calling release_firmware() immediately after\nlbs_fw_loaded() returns.\n\nThe bug was first flagged by an experimental analysis tool we are\ndeveloping for kernel memory-management bugs while analyzing\nv6.13-rc1. The tool is still under development and is not yet publicly\navailable. Manual inspection confirms that the bug is still present in\nthe current wireless tree.\n\nAn x86_64 allyesconfig build showed no new warnings. As we do not have\ncompatible Libertas USB hardware for exercising this firmware-download\npath, no runtime testing was able to be performed."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:35:04.634Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/6c1f54a04813676c5a2150d99331c8d21f199374"
},
{
"url": "https://git.kernel.org/stable/c/7f28722b3e4e0c8d49c859fea4a9b1fa13b5ae06"
},
{
"url": "https://git.kernel.org/stable/c/ce829286f4935f1eb6b5dcb64da02910ce149c76"
},
{
"url": "https://git.kernel.org/stable/c/d497b7566e74920acfe283dd6b2cbf1682890796"
},
{
"url": "https://git.kernel.org/stable/c/eaeb1d74a47fc4864f2c754c0b9d654a9b7dc55c"
},
{
"url": "https://git.kernel.org/stable/c/6cda91bbb8dc3d22ef0323008a12dcf73a5129da"
},
{
"url": "https://git.kernel.org/stable/c/644640cde2fb216e6567de5eee780a38dbc95928"
},
{
"url": "https://git.kernel.org/stable/c/63c2391deefb31e1b801b7f32bd502ca4808639b"
}
],
"title": "wifi: libertas: fix memory leak in helper_firmware_cb()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68410",
"datePublished": "2026-08-10T12:04:30.194Z",
"dateReserved": "2026-07-30T09:28:09.390Z",
"dateUpdated": "2026-08-19T16:35:04.634Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68181 (GCVE-0-2026-68181)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
mei: bus: access mei_device under device_lock on cleanup
Fix couple of problems in mei_cl_bus_dev_release():
mei_cl_flush_queues() is running without lock.
bus->file_list access after mei_dev_bus_put(bus) can become a
use-after-free if this was the last reference to bus.
Protect queues cleanup and WARN traversal by device lock there
to avoid the concurrent access problems.
Move WARN traversal before mei_dev_bus_put(bus).
This file uses bus variable name for mei_device, adjust
code of mei_cl_bus_dev_release() to use bus variable too.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 6f2a6ef86b23a30b92ad57981de537bce67bfa45 Version: 24f4ceeaeee7983c07590149556a0e33efe2ec90 Version: 612c8d21ce6e37b73f3106aec7ffa35959d40261 Version: 35e8a426b16adbecae7a4e0e3c00fc8d0273db53 Version: 35e8a426b16adbecae7a4e0e3c00fc8d0273db53 Version: 35e8a426b16adbecae7a4e0e3c00fc8d0273db53 Version: 2f29dce5a5ae06a7db32e4491d72269329a86eeb Version: 28de6ca5276a94b0589ae1bf026b89fa0eaf14c0 Version: 6.1.149 ≤ Version: 6.6.103 ≤ Version: 6.12.43 ≤ Version: 6.15.11 ≤ Version: 6.16.2 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/misc/mei/bus.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "02e3a755086db847d795f2593ebc45e8ee4f1755",
"status": "affected",
"version": "6f2a6ef86b23a30b92ad57981de537bce67bfa45",
"versionType": "git"
},
{
"lessThan": "441559d4c595f839b39f0ab6a4ae628427c2fd9e",
"status": "affected",
"version": "24f4ceeaeee7983c07590149556a0e33efe2ec90",
"versionType": "git"
},
{
"lessThan": "c88c030a324c9018b77894a19b2564eb66862020",
"status": "affected",
"version": "612c8d21ce6e37b73f3106aec7ffa35959d40261",
"versionType": "git"
},
{
"lessThan": "59dd34854202d9a3faaa87a85205e553fe7150e1",
"status": "affected",
"version": "35e8a426b16adbecae7a4e0e3c00fc8d0273db53",
"versionType": "git"
},
{
"lessThan": "7cf79e8d682fe93777268f029668ce5e214237fd",
"status": "affected",
"version": "35e8a426b16adbecae7a4e0e3c00fc8d0273db53",
"versionType": "git"
},
{
"lessThan": "f112ea910e554d58b4b39a4492b7d302f0f4204f",
"status": "affected",
"version": "35e8a426b16adbecae7a4e0e3c00fc8d0273db53",
"versionType": "git"
},
{
"status": "affected",
"version": "2f29dce5a5ae06a7db32e4491d72269329a86eeb",
"versionType": "git"
},
{
"status": "affected",
"version": "28de6ca5276a94b0589ae1bf026b89fa0eaf14c0",
"versionType": "git"
},
{
"lessThan": "6.1.184",
"status": "affected",
"version": "6.1.149",
"versionType": "semver"
},
{
"lessThan": "6.6.148",
"status": "affected",
"version": "6.6.103",
"versionType": "semver"
},
{
"lessThan": "6.12.101",
"status": "affected",
"version": "6.12.43",
"versionType": "semver"
},
{
"lessThan": "6.16",
"status": "affected",
"version": "6.15.11",
"versionType": "semver"
},
{
"lessThan": "6.17",
"status": "affected",
"version": "6.16.2",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/misc/mei/bus.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.17"
},
{
"lessThan": "6.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "6.1.149",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.6.103",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.12.43",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.15.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.16.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmei: bus: access mei_device under device_lock on cleanup\n\nFix couple of problems in mei_cl_bus_dev_release():\n\nmei_cl_flush_queues() is running without lock.\nbus-\u003efile_list access after mei_dev_bus_put(bus) can become a\nuse-after-free if this was the last reference to bus.\n\nProtect queues cleanup and WARN traversal by device lock there\nto avoid the concurrent access problems.\nMove WARN traversal before mei_dev_bus_put(bus).\n\nThis file uses bus variable name for mei_device, adjust\ncode of mei_cl_bus_dev_release() to use bus variable too."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:04.934Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/02e3a755086db847d795f2593ebc45e8ee4f1755"
},
{
"url": "https://git.kernel.org/stable/c/441559d4c595f839b39f0ab6a4ae628427c2fd9e"
},
{
"url": "https://git.kernel.org/stable/c/c88c030a324c9018b77894a19b2564eb66862020"
},
{
"url": "https://git.kernel.org/stable/c/59dd34854202d9a3faaa87a85205e553fe7150e1"
},
{
"url": "https://git.kernel.org/stable/c/7cf79e8d682fe93777268f029668ce5e214237fd"
},
{
"url": "https://git.kernel.org/stable/c/f112ea910e554d58b4b39a4492b7d302f0f4204f"
}
],
"title": "mei: bus: access mei_device under device_lock on cleanup",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68181",
"datePublished": "2026-08-10T11:59:52.724Z",
"dateReserved": "2026-07-30T09:28:09.373Z",
"dateUpdated": "2026-08-23T12:46:04.934Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68324 (GCVE-0-2026-68324)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
iommu/intel: Fix out-of-bounds memset in dmar_latency_disable()
dmar_latency_disable() intends to zero out only the single
latency_statistic entry for the given type, but the memset size was
computed as sizeof(*lstat) * DMAR_LATENCY_NUM, which clears the entire
array starting from &lstat[type].
When type > 0, this writes beyond the end of the allocated array,
corrupting adjacent memory.
Fix by using sizeof(*lstat) to clear only the target entry.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 55ee5e67a59a1b6f388d7a1c7b24022145f47a3e Version: 55ee5e67a59a1b6f388d7a1c7b24022145f47a3e Version: 55ee5e67a59a1b6f388d7a1c7b24022145f47a3e Version: 55ee5e67a59a1b6f388d7a1c7b24022145f47a3e Version: 55ee5e67a59a1b6f388d7a1c7b24022145f47a3e Version: 55ee5e67a59a1b6f388d7a1c7b24022145f47a3e Version: 55ee5e67a59a1b6f388d7a1c7b24022145f47a3e |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/iommu/intel/perf.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "80f3605991461679c298ea2045c350ee3cf36de3",
"status": "affected",
"version": "55ee5e67a59a1b6f388d7a1c7b24022145f47a3e",
"versionType": "git"
},
{
"lessThan": "104d89cf5b01cb66ff975d91ed42f61b3904df53",
"status": "affected",
"version": "55ee5e67a59a1b6f388d7a1c7b24022145f47a3e",
"versionType": "git"
},
{
"lessThan": "3078d82e7fe9048a2b90a992e71af7cd7ef881fa",
"status": "affected",
"version": "55ee5e67a59a1b6f388d7a1c7b24022145f47a3e",
"versionType": "git"
},
{
"lessThan": "866a35735e56b9dc81cbc33899255134adf6d8b3",
"status": "affected",
"version": "55ee5e67a59a1b6f388d7a1c7b24022145f47a3e",
"versionType": "git"
},
{
"lessThan": "d06fea9b85f038690f55e72fe0c45e113715a85a",
"status": "affected",
"version": "55ee5e67a59a1b6f388d7a1c7b24022145f47a3e",
"versionType": "git"
},
{
"lessThan": "0e28ca1c3204b51068579defc904a0dfba5e5c57",
"status": "affected",
"version": "55ee5e67a59a1b6f388d7a1c7b24022145f47a3e",
"versionType": "git"
},
{
"lessThan": "754f8efe45f87e3a9c6871b645b2f9d46d1b407b",
"status": "affected",
"version": "55ee5e67a59a1b6f388d7a1c7b24022145f47a3e",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/iommu/intel/perf.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.14"
},
{
"lessThan": "5.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\niommu/intel: Fix out-of-bounds memset in dmar_latency_disable()\n\ndmar_latency_disable() intends to zero out only the single\nlatency_statistic entry for the given type, but the memset size was\ncomputed as sizeof(*lstat) * DMAR_LATENCY_NUM, which clears the entire\narray starting from \u0026lstat[type].\n\nWhen type \u003e 0, this writes beyond the end of the allocated array,\ncorrupting adjacent memory.\n\nFix by using sizeof(*lstat) to clear only the target entry."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:15.575Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/80f3605991461679c298ea2045c350ee3cf36de3"
},
{
"url": "https://git.kernel.org/stable/c/104d89cf5b01cb66ff975d91ed42f61b3904df53"
},
{
"url": "https://git.kernel.org/stable/c/3078d82e7fe9048a2b90a992e71af7cd7ef881fa"
},
{
"url": "https://git.kernel.org/stable/c/866a35735e56b9dc81cbc33899255134adf6d8b3"
},
{
"url": "https://git.kernel.org/stable/c/d06fea9b85f038690f55e72fe0c45e113715a85a"
},
{
"url": "https://git.kernel.org/stable/c/0e28ca1c3204b51068579defc904a0dfba5e5c57"
},
{
"url": "https://git.kernel.org/stable/c/754f8efe45f87e3a9c6871b645b2f9d46d1b407b"
}
],
"title": "iommu/intel: Fix out-of-bounds memset in dmar_latency_disable()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68324",
"datePublished": "2026-08-10T12:03:00.073Z",
"dateReserved": "2026-07-30T09:28:09.382Z",
"dateUpdated": "2026-08-19T16:33:15.575Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68371 (GCVE-0-2026-68371)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
usb: musb: omap2430: Do not put borrowed of_node in probe
omap2430_probe() stores pdev->dev.of_node in a local np variable. This is
a borrowed pointer and the probe function does not take a reference to
it.
The success and error paths nevertheless call of_node_put(np). This drops
a reference that is owned by the platform device, and can leave
pdev->dev.of_node with an unbalanced reference count.
Do not put the borrowed platform device node from omap2430_probe().
References taken for the child MUSB device are handled by the device core,
and the ctrl-module phandle reference is still released separately.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 22b60658a90260e3fbd57824e3afe5682c6afcf5 Version: ffbe2feac59b37c8dc536727552b4f375e1b9aec Version: ffbe2feac59b37c8dc536727552b4f375e1b9aec Version: ffbe2feac59b37c8dc536727552b4f375e1b9aec Version: ffbe2feac59b37c8dc536727552b4f375e1b9aec Version: ffbe2feac59b37c8dc536727552b4f375e1b9aec Version: fed43efc00ba6ac8c6b95828cd5acfa3d45eca4d Version: 6.1.2 ≤ Version: 6.0.16 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/musb/omap2430.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "f0e68402d13cd9ffb289da50e65d4429d0002174",
"status": "affected",
"version": "22b60658a90260e3fbd57824e3afe5682c6afcf5",
"versionType": "git"
},
{
"lessThan": "eed56f105a7f70cbcfceb4df6deb6870fc58214d",
"status": "affected",
"version": "ffbe2feac59b37c8dc536727552b4f375e1b9aec",
"versionType": "git"
},
{
"lessThan": "58d1c81c0b54a0b9aa6d6af077b09aa2f1bd2193",
"status": "affected",
"version": "ffbe2feac59b37c8dc536727552b4f375e1b9aec",
"versionType": "git"
},
{
"lessThan": "0950ac52426b0ab32d3b8cf4afe1711668b19cb8",
"status": "affected",
"version": "ffbe2feac59b37c8dc536727552b4f375e1b9aec",
"versionType": "git"
},
{
"lessThan": "6c525c851e5912b9753622d796f2bc55c4913b04",
"status": "affected",
"version": "ffbe2feac59b37c8dc536727552b4f375e1b9aec",
"versionType": "git"
},
{
"lessThan": "c947360ae63eee1c9eacc030dd6f5a53f717addf",
"status": "affected",
"version": "ffbe2feac59b37c8dc536727552b4f375e1b9aec",
"versionType": "git"
},
{
"status": "affected",
"version": "fed43efc00ba6ac8c6b95828cd5acfa3d45eca4d",
"versionType": "git"
},
{
"lessThan": "6.1.184",
"status": "affected",
"version": "6.1.2",
"versionType": "semver"
},
{
"lessThan": "6.1",
"status": "affected",
"version": "6.0.16",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/usb/musb/omap2430.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.2"
},
{
"lessThan": "6.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "6.1.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "6.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.0.16",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: musb: omap2430: Do not put borrowed of_node in probe\n\nomap2430_probe() stores pdev-\u003edev.of_node in a local np variable. This is\na borrowed pointer and the probe function does not take a reference to\nit.\n\nThe success and error paths nevertheless call of_node_put(np). This drops\na reference that is owned by the platform device, and can leave\npdev-\u003edev.of_node with an unbalanced reference count.\n\nDo not put the borrowed platform device node from omap2430_probe().\nReferences taken for the child MUSB device are handled by the device core,\nand the ctrl-module phandle reference is still released separately."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.4,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - omap2430_probe() is reached only via the local driver model - boot-time platform bus match on the OMAP MUSB device-tree node, deferred-probe retries, sysfs bind/unbind of musb-omap2430, or module load/unload. There is no network, adjacent-network, or remote path, and leveraging the prematurely released kobject name/OF node requires local heap manipulation in the same kmalloc cache.\nAC:L - The stray of_node_put(np) is unconditional on both the success return and the err_put_musb error path, so every probe invocation drops a reference the driver never took. There is no race to win, no timing window, and no memory-layout precondition; the imbalance occurs deterministically on each probe and reproduces at will through bind/unbind cycles.\nPR:N - No credential, capability, or namespace check exists on the path - the platform bus binds the OMAP MUSB node and drops the reference during kernel boot, before any user session exists, so the underflowed device_node state arises with zero privileges. Deliberate re-triggering via sysfs unbind would need root, but that is not needed for the vulnerable condition to occur.\nUI:N - The musb-omap2430 platform driver binds automatically when the device-tree node is populated, and deferred-probe retries run unattended during boot; no administrator action, victim interaction, mount, or file open is required for the unbalanced of_node_put() to execute.\nS:U - The corrupted struct device_node, its embedded kobject, and the OF tree all belong to the kernel\u0027s own security authority, and the faulting code runs in that same kernel context. No hypervisor, IOMMU, or sandbox boundary is crossed.\nC:H - The premature release drives kobject_cleanup(), which kfree_const()s kobj-\u003ename while the device_node stays reachable via pdev-\u003edev.of_node, the OF tree, and phandle lookups, so later kobject_name()/sysfs/%pOF accesses read back reclaimed heap contents an attacker can spray. The bad of_node_put() splat with dump_stack() additionally leaks kernel pointers and a full stack trace.\nI:H - A device_node whose backing kobject has been released and whose slab-allocated name has been freed yields write primitives once the memory is reclaimed: the embedded fwnode_handle.ops table is dereferenced by fwnode_call_int_op(), kobj.ktype-\u003erelease is invoked on the next put, and the parent/child/sibling and device-link list heads permit list-manipulation writes during OF tree operations.\nA:H - Reaching zero produces \"ERROR: of_node_release() detected bad of_node_put()\" with dump_stack(), and the next get/put triggers a refcount_t underflow; use-after-free WARN - an outright panic under panic_on_warn. __kobject_del() also tears down the node\u0027s /sys/firmware/devicetree entries and cascades puts onto the parent node, and dereferencing the released node oopses the kernel."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:19.885Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/f0e68402d13cd9ffb289da50e65d4429d0002174"
},
{
"url": "https://git.kernel.org/stable/c/eed56f105a7f70cbcfceb4df6deb6870fc58214d"
},
{
"url": "https://git.kernel.org/stable/c/58d1c81c0b54a0b9aa6d6af077b09aa2f1bd2193"
},
{
"url": "https://git.kernel.org/stable/c/0950ac52426b0ab32d3b8cf4afe1711668b19cb8"
},
{
"url": "https://git.kernel.org/stable/c/6c525c851e5912b9753622d796f2bc55c4913b04"
},
{
"url": "https://git.kernel.org/stable/c/c947360ae63eee1c9eacc030dd6f5a53f717addf"
}
],
"title": "usb: musb: omap2430: Do not put borrowed of_node in probe",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68371",
"datePublished": "2026-08-10T12:03:49.287Z",
"dateReserved": "2026-07-30T09:28:09.386Z",
"dateUpdated": "2026-08-23T12:46:19.885Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68396 (GCVE-0-2026-68396)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-17 05:04
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
scsi: core: wake eh reliably when using scsi_schedule_eh
Drivers which use the scsi_schedule_eh function to run the error handler
currently risk the error handler thread never waking once all commands are
timed out or inactive. There is no enforced memory order between setting
the host into error recovery state and counting busy commands. This can
result in a race with scsi_dec_host_busy where neither CPU sees both
conditions of all commands inactive and the host error state to request
waking the error handler.
To fix this, run the scsi_schedule_eh's scsi_eh_wakeup from a new work item
which will use rcu to ensure scsi_schedule_eh's call to scsi_host_busy will
occur after the error state is globally visible and will be seen by any
current scsi_dec_host_busy callers.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/scsi/hosts.c",
"drivers/scsi/scsi_error.c",
"drivers/scsi/scsi_priv.h",
"include/scsi/scsi_host.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "866efe8ae8b8b4d095501001b026e1022734be28",
"status": "affected",
"version": "6eb045e092efefafc6687409a6fa6d1dabf0fb69",
"versionType": "git"
},
{
"lessThan": "c7a15091237205770bd9bd4d14eb1f3029d97a34",
"status": "affected",
"version": "6eb045e092efefafc6687409a6fa6d1dabf0fb69",
"versionType": "git"
},
{
"lessThan": "24d7abda6a2a19e113334accc10029f6a4b57257",
"status": "affected",
"version": "6eb045e092efefafc6687409a6fa6d1dabf0fb69",
"versionType": "git"
},
{
"lessThan": "dccf3b1798b70f94e958b3d00b83010399e6fb05",
"status": "affected",
"version": "6eb045e092efefafc6687409a6fa6d1dabf0fb69",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/scsi/hosts.c",
"drivers/scsi/scsi_error.c",
"drivers/scsi/scsi_priv.h",
"include/scsi/scsi_host.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.5"
},
{
"lessThan": "5.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: core: wake eh reliably when using scsi_schedule_eh\n\nDrivers which use the scsi_schedule_eh function to run the error handler\ncurrently risk the error handler thread never waking once all commands are\ntimed out or inactive. There is no enforced memory order between setting\nthe host into error recovery state and counting busy commands. This can\nresult in a race with scsi_dec_host_busy where neither CPU sees both\nconditions of all commands inactive and the host error state to request\nwaking the error handler.\n\nTo fix this, run the scsi_schedule_eh\u0027s scsi_eh_wakeup from a new work item\nwhich will use rcu to ensure scsi_schedule_eh\u0027s call to scsi_host_busy will\noccur after the error state is globally visible and will be seen by any\ncurrent scsi_dec_host_busy callers."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:04:44.555Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/866efe8ae8b8b4d095501001b026e1022734be28"
},
{
"url": "https://git.kernel.org/stable/c/c7a15091237205770bd9bd4d14eb1f3029d97a34"
},
{
"url": "https://git.kernel.org/stable/c/24d7abda6a2a19e113334accc10029f6a4b57257"
},
{
"url": "https://git.kernel.org/stable/c/dccf3b1798b70f94e958b3d00b83010399e6fb05"
}
],
"title": "scsi: core: wake eh reliably when using scsi_schedule_eh",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68396",
"datePublished": "2026-08-10T12:04:15.607Z",
"dateReserved": "2026-07-30T09:28:09.389Z",
"dateUpdated": "2026-08-17T05:04:44.555Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68381 (GCVE-0-2026-68381)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-17 05:04
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: pin conn during async oplock break notification
smb2_oplock_break_noti() and smb2_lease_break_noti() store a ksmbd_conn
pointer in an async ksmbd_work and then queue that work on ksmbd-io. The
work only increments conn->r_count, which prevents teardown from passing
the pending-request wait after the increment, but it does not pin the
struct ksmbd_conn object.
If connection teardown races with an oplock break notification, the last
conn reference can be dropped before the queued worker finishes. The
worker then uses the freed conn in ksmbd_conn_write() and
ksmbd_conn_r_count_dec().
Take a real conn reference when publishing the conn pointer to the async
work item, and drop it after the notification work has decremented
r_count. Apply the same lifetime rule to lease break notification, which
uses the same work->conn pattern.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 09aeab68033161cb54f194da93e51a11aee6144b Version: a4261bbc33fbf99b99c80aa3a2c5097611802980 Version: 3aa660c059240e0c795217182cf7df32909dd917 Version: 3aa660c059240e0c795217182cf7df32909dd917 Version: 3aa660c059240e0c795217182cf7df32909dd917 Version: f17d1c63a76b0fe8e9c78023a86507a3a6d62cfa Version: 6.6.84 ≤ Version: 6.12.20 ≤ Version: 6.13.8 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/smb/server/oplock.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "0f72fc9659d7f585460d43c158055df5afdcffb6",
"status": "affected",
"version": "09aeab68033161cb54f194da93e51a11aee6144b",
"versionType": "git"
},
{
"lessThan": "793e1c7041b93af96ff87e678329bc16aee7ba88",
"status": "affected",
"version": "a4261bbc33fbf99b99c80aa3a2c5097611802980",
"versionType": "git"
},
{
"lessThan": "6ecb252efa0b413ac3d9979fb4eec247f8fc1258",
"status": "affected",
"version": "3aa660c059240e0c795217182cf7df32909dd917",
"versionType": "git"
},
{
"lessThan": "14062c74e5b25c27edcff7a2fe0dc701c930b372",
"status": "affected",
"version": "3aa660c059240e0c795217182cf7df32909dd917",
"versionType": "git"
},
{
"lessThan": "aa5d8f3f96aa11a4a54ce993c11ce8af11c546f9",
"status": "affected",
"version": "3aa660c059240e0c795217182cf7df32909dd917",
"versionType": "git"
},
{
"status": "affected",
"version": "f17d1c63a76b0fe8e9c78023a86507a3a6d62cfa",
"versionType": "git"
},
{
"lessThan": "6.6.148",
"status": "affected",
"version": "6.6.84",
"versionType": "semver"
},
{
"lessThan": "6.12.101",
"status": "affected",
"version": "6.12.20",
"versionType": "semver"
},
{
"lessThan": "6.14",
"status": "affected",
"version": "6.13.8",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/smb/server/oplock.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.14"
},
{
"lessThan": "6.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.6.84",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.12.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.13.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: pin conn during async oplock break notification\n\nsmb2_oplock_break_noti() and smb2_lease_break_noti() store a ksmbd_conn\npointer in an async ksmbd_work and then queue that work on ksmbd-io. The\nwork only increments conn-\u003er_count, which prevents teardown from passing\nthe pending-request wait after the increment, but it does not pin the\nstruct ksmbd_conn object.\n\nIf connection teardown races with an oplock break notification, the last\nconn reference can be dropped before the queued worker finishes. The\nworker then uses the freed conn in ksmbd_conn_write() and\nksmbd_conn_r_count_dec().\n\nTake a real conn reference when publishing the conn pointer to the async\nwork item, and drop it after the notification work has decremented\nr_count. Apply the same lifetime rule to lease break notification, which\nuses the same work-\u003econn pattern."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - ksmbd is the in-kernel SMB server listening on TCP/445 (and SMB-Direct); the oplock/lease break notification path is driven entirely by remote SMB2 CREATE/close traffic and connection teardown, so a remote peer reaches the freed-conn use over the network.\nAC:L - The attacker controls both sides of the race: one connection holds a batch oplock/lease while a second connection opens the same file to force the async break, and the first connection is then abruptly dropped so teardown passes the r_count wait before the increment lands; this can be retried across arbitrarily many connections.\nPR:N - ksmbd share access is commonly exposed with guest/anonymous mapping, so an unauthenticated or trivially-credentialed remote client can open files and trigger oplock/lease breaks; consistent with prior ksmbd connection-lifetime UAF scoring, no meaningful privilege gate protects this path.\nUI:N - No victim action is needed; the attacker\u0027s own two SMB connections create the oplock break and the racing disconnect entirely on their own initiative.\nS:U - The freed object and the corrupted state are both kernel memory owned by the ksmbd server within the same security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - Use-after-free of struct ksmbd_conn lets the attacker reclaim the slab object with attacker-shaped data and have the worker read conn-\u003etransport and response state from it, enabling disclosure of kernel memory and pointer values, potentially leaked back over the SMB connection.\nI:H - ksmbd_conn_write() dereferences conn-\u003etransport-\u003eops-\u003ewritev from the freed object and indirectly calls it, and ksmbd_conn_lock()/ksmbd_conn_r_count_dec() perform mutex and atomic/waitqueue writes into freed memory, giving heap-spray-based control-flow hijack and arbitrary-write potential.\nA:H - Even without successful exploitation, using a freed ksmbd_conn (mutex operations, transport pointer dereference, waitqueue wakeup) reliably causes memory corruption, oops, or kernel panic, taking down the whole system."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:04:27.523Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/0f72fc9659d7f585460d43c158055df5afdcffb6"
},
{
"url": "https://git.kernel.org/stable/c/793e1c7041b93af96ff87e678329bc16aee7ba88"
},
{
"url": "https://git.kernel.org/stable/c/6ecb252efa0b413ac3d9979fb4eec247f8fc1258"
},
{
"url": "https://git.kernel.org/stable/c/14062c74e5b25c27edcff7a2fe0dc701c930b372"
},
{
"url": "https://git.kernel.org/stable/c/aa5d8f3f96aa11a4a54ce993c11ce8af11c546f9"
}
],
"title": "ksmbd: pin conn during async oplock break notification",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68381",
"datePublished": "2026-08-10T12:03:59.849Z",
"dateReserved": "2026-07-30T09:28:09.387Z",
"dateUpdated": "2026-08-17T05:04:27.523Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68304 (GCVE-0-2026-68304)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-19 16:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: brcmfmac: fix 802.1X-SHA256 call trace warning
Based on wpa_auth as 1x_256 mode, need to set up
"use_fwsup" with BRCMF_PROFILE_FWSUP_1X.
Or it will happen trace warning when call brcmf_cfg80211_set_pmk().
[ 4481.831101] ------------[ cut here ]------------
[ 4481.831102] WARNING: CPU: 1 PID: 2997 at
drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c:7242 brcmf_cfg80211_set_pmk+0x77/0xd0 [brcmfmac]
[...]
[ 4481.831202] Call Trace:
[ 4481.831204] <TASK>
[ 4481.831205] nl80211_set_pmk+0x183/0x250 [cfg80211]
[ 4481.831233] genl_family_rcv_msg_doit+0xea/0x150
[ 4481.831237] genl_rcv_msg+0x104/0x240
[ 4481.831239] ? cfg80211_probe_status+0x2c0/0x2c0 [cfg80211]
[ 4481.831257] ? genl_family_rcv_msg_doit+0x150/0x150
[ 4481.831259] netlink_rcv_skb+0x4e/0x100
[ 4481.831261] genl_rcv+0x24/0x40
[ 4481.831262] netlink_unicast+0x236/0x380
[ 4481.831264] netlink_sendmsg+0x250/0x4b0
[ 4481.831266] sock_sendmsg+0x5c/0x70
[ 4481.831269] ____sys_sendmsg+0x236/0x2b0
[ 4481.831271] ? copy_msghdr_from_user+0x6d/0xa0
[ 4481.831272] ___sys_sendmsg+0x86/0xd0
[ 4481.831274] ? avc_has_perm+0x8c/0x1a0
[ 4481.831276] ? preempt_count_add+0x6a/0xa0
[ 4481.831279] ? sock_has_perm+0x82/0xa0
[ 4481.831280] __sys_sendmsg+0x57/0xa0
[ 4481.831282] do_syscall_64+0x38/0x90
[ 4481.831284] entry_SYSCALL_64_after_hwframe+0x63/0xcd
[ 4481.831286] RIP: 0033:0x7fd270d369b4
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 2526ff21aa77c205f72e8263335f20b7d7e636fc Version: 2526ff21aa77c205f72e8263335f20b7d7e636fc Version: 2526ff21aa77c205f72e8263335f20b7d7e636fc Version: 2526ff21aa77c205f72e8263335f20b7d7e636fc Version: 2526ff21aa77c205f72e8263335f20b7d7e636fc Version: 2526ff21aa77c205f72e8263335f20b7d7e636fc Version: 2526ff21aa77c205f72e8263335f20b7d7e636fc Version: 2526ff21aa77c205f72e8263335f20b7d7e636fc |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "fe27cc1feecde0e6a0a9a04b7ad3262ed5f99252",
"status": "affected",
"version": "2526ff21aa77c205f72e8263335f20b7d7e636fc",
"versionType": "git"
},
{
"lessThan": "47989a233df369c2c2263ab0a5cbd8c8dad253a5",
"status": "affected",
"version": "2526ff21aa77c205f72e8263335f20b7d7e636fc",
"versionType": "git"
},
{
"lessThan": "d0395840e3266397de94ecd3c91e1c188c7667c6",
"status": "affected",
"version": "2526ff21aa77c205f72e8263335f20b7d7e636fc",
"versionType": "git"
},
{
"lessThan": "137e4710da626290495b174e2eb1d5e889a4b165",
"status": "affected",
"version": "2526ff21aa77c205f72e8263335f20b7d7e636fc",
"versionType": "git"
},
{
"lessThan": "d3ac5b35ec85c41ccf8ec524d47b520e72edaca1",
"status": "affected",
"version": "2526ff21aa77c205f72e8263335f20b7d7e636fc",
"versionType": "git"
},
{
"lessThan": "00ebbf030d8c4a1cb89cbbae15e28332373649db",
"status": "affected",
"version": "2526ff21aa77c205f72e8263335f20b7d7e636fc",
"versionType": "git"
},
{
"lessThan": "bd4fac033bb95fcad898cf6734e869991b2561cb",
"status": "affected",
"version": "2526ff21aa77c205f72e8263335f20b7d7e636fc",
"versionType": "git"
},
{
"lessThan": "7cb34f6c4fe8a68af621d870abe63bfca2275dd6",
"status": "affected",
"version": "2526ff21aa77c205f72e8263335f20b7d7e636fc",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.13"
},
{
"lessThan": "4.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: brcmfmac: fix 802.1X-SHA256 call trace warning\n\nBased on wpa_auth as 1x_256 mode, need to set up\n\"use_fwsup\" with BRCMF_PROFILE_FWSUP_1X.\nOr it will happen trace warning when call brcmf_cfg80211_set_pmk().\n\n[ 4481.831101] ------------[ cut here ]------------\n[ 4481.831102] WARNING: CPU: 1 PID: 2997 at\ndrivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c:7242 brcmf_cfg80211_set_pmk+0x77/0xd0 [brcmfmac]\n[...]\n[ 4481.831202] Call Trace:\n[ 4481.831204] \u00a0\u003cTASK\u003e\n[ 4481.831205] \u00a0nl80211_set_pmk+0x183/0x250 [cfg80211]\n[ 4481.831233] \u00a0genl_family_rcv_msg_doit+0xea/0x150\n[ 4481.831237] \u00a0genl_rcv_msg+0x104/0x240\n[ 4481.831239] \u00a0? cfg80211_probe_status+0x2c0/0x2c0 [cfg80211]\n[ 4481.831257] \u00a0? genl_family_rcv_msg_doit+0x150/0x150\n[ 4481.831259] \u00a0netlink_rcv_skb+0x4e/0x100\n[ 4481.831261] \u00a0genl_rcv+0x24/0x40\n[ 4481.831262] \u00a0netlink_unicast+0x236/0x380\n[ 4481.831264] \u00a0netlink_sendmsg+0x250/0x4b0\n[ 4481.831266] \u00a0sock_sendmsg+0x5c/0x70\n[ 4481.831269] \u00a0____sys_sendmsg+0x236/0x2b0\n[ 4481.831271] \u00a0? copy_msghdr_from_user+0x6d/0xa0\n[ 4481.831272] \u00a0___sys_sendmsg+0x86/0xd0\n[ 4481.831274] \u00a0? avc_has_perm+0x8c/0x1a0\n[ 4481.831276] \u00a0? preempt_count_add+0x6a/0xa0\n[ 4481.831279] \u00a0? sock_has_perm+0x82/0xa0\n[ 4481.831280] \u00a0__sys_sendmsg+0x57/0xa0\n[ 4481.831282] \u00a0do_syscall_64+0x38/0x90\n[ 4481.831284] \u00a0entry_SYSCALL_64_after_hwframe+0x63/0xcd\n[ 4481.831286] RIP: 0033:0x7fd270d369b4"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:32:58.379Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/fe27cc1feecde0e6a0a9a04b7ad3262ed5f99252"
},
{
"url": "https://git.kernel.org/stable/c/47989a233df369c2c2263ab0a5cbd8c8dad253a5"
},
{
"url": "https://git.kernel.org/stable/c/d0395840e3266397de94ecd3c91e1c188c7667c6"
},
{
"url": "https://git.kernel.org/stable/c/137e4710da626290495b174e2eb1d5e889a4b165"
},
{
"url": "https://git.kernel.org/stable/c/d3ac5b35ec85c41ccf8ec524d47b520e72edaca1"
},
{
"url": "https://git.kernel.org/stable/c/00ebbf030d8c4a1cb89cbbae15e28332373649db"
},
{
"url": "https://git.kernel.org/stable/c/bd4fac033bb95fcad898cf6734e869991b2561cb"
},
{
"url": "https://git.kernel.org/stable/c/7cb34f6c4fe8a68af621d870abe63bfca2275dd6"
}
],
"title": "wifi: brcmfmac: fix 802.1X-SHA256 call trace warning",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68304",
"datePublished": "2026-08-10T12:02:38.515Z",
"dateReserved": "2026-07-30T09:28:09.381Z",
"dateUpdated": "2026-08-19T16:32:58.379Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72147 (GCVE-0-2026-72147)
Vulnerability from cvelistv5
Published
2026-08-15 05:53
Modified
2026-08-17 05:09
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
dmaengine: dw-edma-pcie: Reject devices without driver data
dw_edma_pcie_probe() treats the PCI device ID driver_data as the
template for the controller layout and copies it unconditionally. A
device bound dynamically via sysfs can match the driver without that
data, which leads to a NULL pointer dereference.
Reject such matches before enabling the device.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/dma/dw-edma/dw-edma-pcie.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "2733b5dcb5a4ba4446f7bac954b97e4501dcaa64",
"status": "affected",
"version": "41aaff2a2ac01c5f5415f9de9cd7015ac2b8d569",
"versionType": "git"
},
{
"lessThan": "a1042599fa8f9e313be176eb1ea1ae199f983419",
"status": "affected",
"version": "41aaff2a2ac01c5f5415f9de9cd7015ac2b8d569",
"versionType": "git"
},
{
"lessThan": "043acb00e4edd4b9ffb9dd0e357482dcd9086486",
"status": "affected",
"version": "41aaff2a2ac01c5f5415f9de9cd7015ac2b8d569",
"versionType": "git"
},
{
"lessThan": "044f7b3252d4fb2143d4999eec2800c08f1001ed",
"status": "affected",
"version": "41aaff2a2ac01c5f5415f9de9cd7015ac2b8d569",
"versionType": "git"
},
{
"lessThan": "11d7cfe0c119691b2dafbb699bbca90258c678aa",
"status": "affected",
"version": "41aaff2a2ac01c5f5415f9de9cd7015ac2b8d569",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/dma/dw-edma/dw-edma-pcie.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.3"
},
{
"lessThan": "5.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: dw-edma-pcie: Reject devices without driver data\n\ndw_edma_pcie_probe() treats the PCI device ID driver_data as the\ntemplate for the controller layout and copies it unconditionally. A\ndevice bound dynamically via sysfs can match the driver without that\ndata, which leads to a NULL pointer dereference.\n\nReject such matches before enabling the device."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:09:06.340Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/2733b5dcb5a4ba4446f7bac954b97e4501dcaa64"
},
{
"url": "https://git.kernel.org/stable/c/a1042599fa8f9e313be176eb1ea1ae199f983419"
},
{
"url": "https://git.kernel.org/stable/c/043acb00e4edd4b9ffb9dd0e357482dcd9086486"
},
{
"url": "https://git.kernel.org/stable/c/044f7b3252d4fb2143d4999eec2800c08f1001ed"
},
{
"url": "https://git.kernel.org/stable/c/11d7cfe0c119691b2dafbb699bbca90258c678aa"
}
],
"title": "dmaengine: dw-edma-pcie: Reject devices without driver data",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72147",
"datePublished": "2026-08-15T05:53:19.170Z",
"dateReserved": "2026-08-09T03:40:39.908Z",
"dateUpdated": "2026-08-17T05:09:06.340Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68439 (GCVE-0-2026-68439)
Vulnerability from cvelistv5
Published
2026-08-12 00:07
Modified
2026-08-17 05:05
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: mt76: mt7925: fix possible NULL-pointer deref in mt7925_mcu_bss_he_tlv()
mt76_connac_get_he_phy_cap routine can theoretically return NULL so
check cap pointer before dereferencing it.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/mediatek/mt76/mt7925/mcu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "42288cca984fb72ad3ebe43d4e7fdce9dcabfdb5",
"status": "affected",
"version": "c948b5da6bbec742b433138e3e3f9537a85af2e5",
"versionType": "git"
},
{
"lessThan": "313343ab8cab7417973e7bdd43d3c3e93044b447",
"status": "affected",
"version": "c948b5da6bbec742b433138e3e3f9537a85af2e5",
"versionType": "git"
},
{
"lessThan": "856f1588a2590e70b119e76c15315615a36aebc8",
"status": "affected",
"version": "c948b5da6bbec742b433138e3e3f9537a85af2e5",
"versionType": "git"
},
{
"lessThan": "8d1b6738c1ab48c086b17e7994034aca94258931",
"status": "affected",
"version": "c948b5da6bbec742b433138e3e3f9537a85af2e5",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/mediatek/mt76/mt7925/mcu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.7"
},
{
"lessThan": "6.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7925: fix possible NULL-pointer deref in mt7925_mcu_bss_he_tlv()\n\nmt76_connac_get_he_phy_cap routine can theoretically return NULL so\ncheck cap pointer before dereferencing it."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:05:36.346Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/42288cca984fb72ad3ebe43d4e7fdce9dcabfdb5"
},
{
"url": "https://git.kernel.org/stable/c/313343ab8cab7417973e7bdd43d3c3e93044b447"
},
{
"url": "https://git.kernel.org/stable/c/856f1588a2590e70b119e76c15315615a36aebc8"
},
{
"url": "https://git.kernel.org/stable/c/8d1b6738c1ab48c086b17e7994034aca94258931"
}
],
"title": "wifi: mt76: mt7925: fix possible NULL-pointer deref in mt7925_mcu_bss_he_tlv()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68439",
"datePublished": "2026-08-12T00:07:28.625Z",
"dateReserved": "2026-07-30T09:28:09.394Z",
"dateUpdated": "2026-08-17T05:05:36.346Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68133 (GCVE-0-2026-68133)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-17 04:59
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ice: fix PTP Call Trace during PTP release
If a PF reset occurs when the PTP state is ICE_PTP_UNINIT, then
ice_ptp_rebuild() will update the state to ICE_PTP_ERROR. This will
result in the following PTP release call trace during driver unload:
kernel BUG at lib/list_debug.c:52!
ice_ptp_release+0x332/0x3c0 [ice]
ice_deinit_features.part.0+0x10e/0x120 [ice]
ice_remove+0x100/0x220 [ice]
This was observed when passing PF1 through to a VM. ice_ptp_init()
fails because ctrl_pf is NULL and sets the state to ICE_PTP_UNINIT.
Fix by detecting the ICE_PTP_UNINIT state in ice_ptp_rebuild() and
returning without error, preventing the invalid state transition to
ICE_PTP_ERROR. The only valid path to ICE_PTP_ERROR is from
ICE_PTP_RESETTING after a failed rebuild.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/intel/ice/ice_ptp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "7d517b255f669cedd09830214d55f2f413b34481",
"status": "affected",
"version": "8293e4cb2ff54b1ec4f7206dcb74c908f62a3fb8",
"versionType": "git"
},
{
"lessThan": "e4406cbdd915f702d2ed9ee8b30683a16b06c6ac",
"status": "affected",
"version": "8293e4cb2ff54b1ec4f7206dcb74c908f62a3fb8",
"versionType": "git"
},
{
"lessThan": "14fceda28069fdbe1bb49cdb6e1774892b583348",
"status": "affected",
"version": "8293e4cb2ff54b1ec4f7206dcb74c908f62a3fb8",
"versionType": "git"
},
{
"lessThan": "f6a7e00b81e35ef1325234925f2fe1e53b466f92",
"status": "affected",
"version": "8293e4cb2ff54b1ec4f7206dcb74c908f62a3fb8",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/intel/ice/ice_ptp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.9"
},
{
"lessThan": "6.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nice: fix PTP Call Trace during PTP release\n\nIf a PF reset occurs when the PTP state is ICE_PTP_UNINIT, then\nice_ptp_rebuild() will update the state to ICE_PTP_ERROR. This will\nresult in the following PTP release call trace during driver unload:\n\n kernel BUG at lib/list_debug.c:52!\n ice_ptp_release+0x332/0x3c0 [ice]\n ice_deinit_features.part.0+0x10e/0x120 [ice]\n ice_remove+0x100/0x220 [ice]\n\nThis was observed when passing PF1 through to a VM. ice_ptp_init()\nfails because ctrl_pf is NULL and sets the state to ICE_PTP_UNINIT.\n\nFix by detecting the ICE_PTP_UNINIT state in ice_ptp_rebuild() and\nreturning without error, preventing the invalid state transition to\nICE_PTP_ERROR. The only valid path to ICE_PTP_ERROR is from\nICE_PTP_RESETTING after a failed rebuild."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:59:25.287Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/7d517b255f669cedd09830214d55f2f413b34481"
},
{
"url": "https://git.kernel.org/stable/c/e4406cbdd915f702d2ed9ee8b30683a16b06c6ac"
},
{
"url": "https://git.kernel.org/stable/c/14fceda28069fdbe1bb49cdb6e1774892b583348"
},
{
"url": "https://git.kernel.org/stable/c/f6a7e00b81e35ef1325234925f2fe1e53b466f92"
}
],
"title": "ice: fix PTP Call Trace during PTP release",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68133",
"datePublished": "2026-08-10T11:58:56.223Z",
"dateReserved": "2026-07-30T09:28:09.370Z",
"dateUpdated": "2026-08-17T04:59:25.287Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68125 (GCVE-0-2026-68125)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-19 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
mac802154: llsec: reject frames shorter than the authentication tag
llsec_do_decrypt_auth() computes the associated-data length for the
AEAD request as
assoclen += datalen - authlen;
where datalen is the number of bytes after the MAC header and authlen
(4, 8 or 16) is the length of the authentication tag. Nothing verifies
that the frame actually carries at least authlen payload bytes. A
secured frame whose payload is shorter than the tag makes
datalen - authlen negative; assoclen is then passed to
aead_request_set_ad() as an unsigned value close to 4 GiB, so
crypto_aead_decrypt() walks far off the end of the scatterlist that
only spans the real frame.
The frame is fully attacker-controlled and reaches this path from any
IEEE 802.15.4 peer in radio range. Reject frames whose payload is
shorter than the authentication tag before the subtraction.
Dynamically reproduced on a KASAN kernel as a general-protection-fault
in the AEAD scatterwalk, and the fix confirmed.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 4c14a2fb5d143e4ed94143be2b8c1961b47df9af Version: 4c14a2fb5d143e4ed94143be2b8c1961b47df9af Version: 4c14a2fb5d143e4ed94143be2b8c1961b47df9af Version: 4c14a2fb5d143e4ed94143be2b8c1961b47df9af Version: 4c14a2fb5d143e4ed94143be2b8c1961b47df9af Version: 4c14a2fb5d143e4ed94143be2b8c1961b47df9af Version: 4c14a2fb5d143e4ed94143be2b8c1961b47df9af Version: 4c14a2fb5d143e4ed94143be2b8c1961b47df9af |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/mac802154/llsec.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "f27ce82eb04960465df71634b196a48a4ecafd50",
"status": "affected",
"version": "4c14a2fb5d143e4ed94143be2b8c1961b47df9af",
"versionType": "git"
},
{
"lessThan": "2d6b42a61373144298070668fddf06efe79cf2ff",
"status": "affected",
"version": "4c14a2fb5d143e4ed94143be2b8c1961b47df9af",
"versionType": "git"
},
{
"lessThan": "ec7e62d77193131227df49d654d118fdf5a59892",
"status": "affected",
"version": "4c14a2fb5d143e4ed94143be2b8c1961b47df9af",
"versionType": "git"
},
{
"lessThan": "5bbf0cd9b6a7076af86c75e87e180099be2e11ae",
"status": "affected",
"version": "4c14a2fb5d143e4ed94143be2b8c1961b47df9af",
"versionType": "git"
},
{
"lessThan": "de80808f37d99c6dc67bb6f97eea00c8f57a8821",
"status": "affected",
"version": "4c14a2fb5d143e4ed94143be2b8c1961b47df9af",
"versionType": "git"
},
{
"lessThan": "f20dedce0429b293d4bad604e0d3f65d8ac96c83",
"status": "affected",
"version": "4c14a2fb5d143e4ed94143be2b8c1961b47df9af",
"versionType": "git"
},
{
"lessThan": "e09e0301d616c1ef38a5e64e8e4326fd39df13cc",
"status": "affected",
"version": "4c14a2fb5d143e4ed94143be2b8c1961b47df9af",
"versionType": "git"
},
{
"lessThan": "fd3a3f28ed60c6af4b2a39933b151d6b27842c3b",
"status": "affected",
"version": "4c14a2fb5d143e4ed94143be2b8c1961b47df9af",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/mac802154/llsec.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.16"
},
{
"lessThan": "3.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.16",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmac802154: llsec: reject frames shorter than the authentication tag\n\nllsec_do_decrypt_auth() computes the associated-data length for the\nAEAD request as\n\n\tassoclen += datalen - authlen;\n\nwhere datalen is the number of bytes after the MAC header and authlen\n(4, 8 or 16) is the length of the authentication tag. Nothing verifies\nthat the frame actually carries at least authlen payload bytes. A\nsecured frame whose payload is shorter than the tag makes\ndatalen - authlen negative; assoclen is then passed to\naead_request_set_ad() as an unsigned value close to 4 GiB, so\ncrypto_aead_decrypt() walks far off the end of the scatterlist that\nonly spans the real frame.\n\nThe frame is fully attacker-controlled and reaches this path from any\nIEEE 802.15.4 peer in radio range. Reject frames whose payload is\nshorter than the authentication tag before the subtraction.\n\nDynamically reproduced on a KASAN kernel as a general-protection-fault\nin the AEAD scatterwalk, and the fix confirmed."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - Exploitation requires sending crafted IEEE 802.15.4 frames over the WPAN radio interface; any peer within RF range can reach mac802154 receive/decrypt without IP routing or local shell access, matching Adjacent wireless attack guidance like Bluetooth.\nAC:L - The attacker fully controls frame length and security header fields; once LLSEC is enabled on the victim, a single undersized MIC-only secured frame reliably triggers the assoclen underflow and was dynamically reproduced as a KASAN GPF.\nPR:N - No Linux credentials or capabilities are required on the target; exploitation is performed by an over-the-air 802.15.4 peer spoofing a known PAN device/key/frame counter, not via local syscalls, ioctl, or netlink.\nUI:N - No victim user action is needed beyond normal operation of an LLSEC-enabled 802.15.4 interface; the malicious frame is processed automatically in the softirq receive path before delivery to userspace.\nS:U - Impact is confined to kernel memory and availability on the attacked host\u0027s WPAN stack; it does not cross a VM, container, or IOMMU security boundary into a separate authority.\nC:H - The wrapped assoclen makes crypto_aead_decrypt() scatterwalk read gigabytes beyond the skb-backed scatterlist, causing out-of-bounds kernel memory reads that can disclose adjacent heap or slab data and enable further exploitation primitives.\nI:H - Kernel memory corruption in the AEAD decrypt scatterwalk path can be leveraged for control-flow hijack or arbitrary write primitives beyond the demonstrated crash, consistent with high integrity impact for exploitable OOB access in crypto handlers.\nA:H - The bug was reproduced on a KASAN kernel as a general-protection fault in the AEAD scatterwalk, and repeated malicious frames can panic or hang the kernel on LLSEC-enabled coordinators, gateways, and IoT border routers."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:29:39.507Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/f27ce82eb04960465df71634b196a48a4ecafd50"
},
{
"url": "https://git.kernel.org/stable/c/2d6b42a61373144298070668fddf06efe79cf2ff"
},
{
"url": "https://git.kernel.org/stable/c/ec7e62d77193131227df49d654d118fdf5a59892"
},
{
"url": "https://git.kernel.org/stable/c/5bbf0cd9b6a7076af86c75e87e180099be2e11ae"
},
{
"url": "https://git.kernel.org/stable/c/de80808f37d99c6dc67bb6f97eea00c8f57a8821"
},
{
"url": "https://git.kernel.org/stable/c/f20dedce0429b293d4bad604e0d3f65d8ac96c83"
},
{
"url": "https://git.kernel.org/stable/c/e09e0301d616c1ef38a5e64e8e4326fd39df13cc"
},
{
"url": "https://git.kernel.org/stable/c/fd3a3f28ed60c6af4b2a39933b151d6b27842c3b"
}
],
"title": "mac802154: llsec: reject frames shorter than the authentication tag",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68125",
"datePublished": "2026-08-10T11:58:46.198Z",
"dateReserved": "2026-07-30T09:28:09.369Z",
"dateUpdated": "2026-08-19T16:29:39.507Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68213 (GCVE-0-2026-68213)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: rtl2832_sdr: Return queued buffers on start_streaming() failure
The vb2 framework hands buffers to the driver via buf_queue() before
calling start_streaming(). If start_streaming() returns an error
without first returning those buffers via vb2_buffer_done(),
vb2_start_streaming() fires WARN_ON(owned_by_drv_count) and the queued
buffers leak.
rtl2832_sdr_start_streaming() had multiple error paths that hit this
trap: two direct early returns (-ENODEV, -ERESTARTSYS), plus six
`goto err` paths covering subdev s_power, tuner setup, ADC setup,
stream-buffer allocation, urb allocation, and urb submission failures.
None of them returned the queued buffers.
The original function had no distinct success exit and fell straight
through into the err label, which previously only did mutex_unlock and
"return ret". Adding queued-buffer cleanup at err must therefore be
paired with an explicit success return; otherwise every successful
start would also drain the buffer queue and kill streaming. Add that
success return, then add rtl2832_sdr_cleanup_queued_bufs() at the err
label and before each early return.
The cleanup helper takes a vb2_buffer_state argument so that the
start_streaming error paths can pass VB2_BUF_STATE_QUEUED (as
expected by userspace on start_streaming failure) while stop_streaming
keeps its existing VB2_BUF_STATE_ERROR semantics.
This mirrors the uvcvideo fix in commit 4cf3b6fd54eb ("media: uvcvideo:
Return queued buffers on start_streaming() failure").
The err label still does not roll back power_ctrl(), frontend_ctrl(),
the POWER_ON flag, or stream/URB allocations that may have happened
before the failing step. Those are pre-existing leaks of a different
class and are not addressed here.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 771138920eafa399f68d3492c8a75dfeea23474b Version: 771138920eafa399f68d3492c8a75dfeea23474b Version: 771138920eafa399f68d3492c8a75dfeea23474b Version: 771138920eafa399f68d3492c8a75dfeea23474b Version: 771138920eafa399f68d3492c8a75dfeea23474b Version: 771138920eafa399f68d3492c8a75dfeea23474b Version: 771138920eafa399f68d3492c8a75dfeea23474b Version: 771138920eafa399f68d3492c8a75dfeea23474b |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/dvb-frontends/rtl2832_sdr.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "fd1e11fc3849169285e48b2d4ec441614ad2ea74",
"status": "affected",
"version": "771138920eafa399f68d3492c8a75dfeea23474b",
"versionType": "git"
},
{
"lessThan": "772f2550fe32357557d3b2f88e02f7cf477f0789",
"status": "affected",
"version": "771138920eafa399f68d3492c8a75dfeea23474b",
"versionType": "git"
},
{
"lessThan": "a248273f8af6e630a03e823274385725974009b5",
"status": "affected",
"version": "771138920eafa399f68d3492c8a75dfeea23474b",
"versionType": "git"
},
{
"lessThan": "465dc8e71d2db2ed603e749fa71392bcdccf07eb",
"status": "affected",
"version": "771138920eafa399f68d3492c8a75dfeea23474b",
"versionType": "git"
},
{
"lessThan": "0b08c0403cf672a121ace4eff647a9b240bd4e1b",
"status": "affected",
"version": "771138920eafa399f68d3492c8a75dfeea23474b",
"versionType": "git"
},
{
"lessThan": "894e83509c66910112b9eaeaa8cd66cd9806db91",
"status": "affected",
"version": "771138920eafa399f68d3492c8a75dfeea23474b",
"versionType": "git"
},
{
"lessThan": "fc0b18782aab4e35078efe72863df8eab46560a8",
"status": "affected",
"version": "771138920eafa399f68d3492c8a75dfeea23474b",
"versionType": "git"
},
{
"lessThan": "33ca0aab6f4bd90921fc1395478f38f72c4d19af",
"status": "affected",
"version": "771138920eafa399f68d3492c8a75dfeea23474b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/dvb-frontends/rtl2832_sdr.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.15"
},
{
"lessThan": "3.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: rtl2832_sdr: Return queued buffers on start_streaming() failure\n\nThe vb2 framework hands buffers to the driver via buf_queue() before\ncalling start_streaming(). If start_streaming() returns an error\nwithout first returning those buffers via vb2_buffer_done(),\nvb2_start_streaming() fires WARN_ON(owned_by_drv_count) and the queued\nbuffers leak.\n\nrtl2832_sdr_start_streaming() had multiple error paths that hit this\ntrap: two direct early returns (-ENODEV, -ERESTARTSYS), plus six\n`goto err` paths covering subdev s_power, tuner setup, ADC setup,\nstream-buffer allocation, urb allocation, and urb submission failures.\nNone of them returned the queued buffers.\n\nThe original function had no distinct success exit and fell straight\nthrough into the err label, which previously only did mutex_unlock and\n\"return ret\". Adding queued-buffer cleanup at err must therefore be\npaired with an explicit success return; otherwise every successful\nstart would also drain the buffer queue and kill streaming. Add that\nsuccess return, then add rtl2832_sdr_cleanup_queued_bufs() at the err\nlabel and before each early return.\n\nThe cleanup helper takes a vb2_buffer_state argument so that the\nstart_streaming error paths can pass VB2_BUF_STATE_QUEUED (as\nexpected by userspace on start_streaming failure) while stop_streaming\nkeeps its existing VB2_BUF_STATE_ERROR semantics.\n\nThis mirrors the uvcvideo fix in commit 4cf3b6fd54eb (\"media: uvcvideo:\nReturn queued buffers on start_streaming() failure\").\n\nThe err label still does not roll back power_ctrl(), frontend_ctrl(),\nthe POWER_ON flag, or stream/URB allocations that may have happened\nbefore the failing step. Those are pre-existing leaks of a different\nclass and are not addressed here."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Triggered entirely through ioctls on the V4L2 SDR device node /dev/swradio0 (VIDIOC_REQBUFS/QBUF/STREAMON); no network or physical interaction is required, since the failure path is reached via lock contention and signal delivery from local threads.\nAC:L - The attacker controls both sides: one thread holds dev-\u003ev4l2_lock via slow USB-backed ioctls while another calls STREAMON and a third signals it, forcing the -ERESTARTSYS path deterministically and retryably; no condition lies outside attacker influence.\nPR:L - Requires only an unprivileged local account with access to the SDR video node, which is customarily group-video readable/writable on desktop, embedded and Android-style deployments; no CAP_SYS_ADMIN or root is needed.\nUI:N - The full sequence (REQBUFS, QBUF, STREAMON, close, reopen) is performed by the attacker\u0027s own process; no victim action or cooperation is involved at any point.\nS:U - The corruption is confined to kernel heap objects owned by the same kernel security authority; no VM, IOMMU or sandbox boundary is crossed.\nC:H - The stale dev-\u003equeued_bufs entries point at freed vb2 buffer objects that the attacker can reclaim via heap spraying, and the URB completion handler dereferences them, yielding a use-after-free read primitive over kernel memory.\nI:H - A later buf_queue() performs list_add_tail() through the dangling list head, writing kernel pointers into freed, attacker-reclaimed memory, and vb2_buffer_done() operates on a forged buffer \u2014 a classic UAF write primitive usable for control-flow hijack.\nA:H - The immediate effect is WARN_ON(owned_by_drv_count) in vb2_start_streaming() (a panic under panic_on_warn) plus list corruption; the resulting use-after-free reliably oopses the kernel and can be repeated at will."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:39.730Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/fd1e11fc3849169285e48b2d4ec441614ad2ea74"
},
{
"url": "https://git.kernel.org/stable/c/772f2550fe32357557d3b2f88e02f7cf477f0789"
},
{
"url": "https://git.kernel.org/stable/c/a248273f8af6e630a03e823274385725974009b5"
},
{
"url": "https://git.kernel.org/stable/c/465dc8e71d2db2ed603e749fa71392bcdccf07eb"
},
{
"url": "https://git.kernel.org/stable/c/0b08c0403cf672a121ace4eff647a9b240bd4e1b"
},
{
"url": "https://git.kernel.org/stable/c/894e83509c66910112b9eaeaa8cd66cd9806db91"
},
{
"url": "https://git.kernel.org/stable/c/fc0b18782aab4e35078efe72863df8eab46560a8"
},
{
"url": "https://git.kernel.org/stable/c/33ca0aab6f4bd90921fc1395478f38f72c4d19af"
}
],
"title": "media: rtl2832_sdr: Return queued buffers on start_streaming() failure",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68213",
"datePublished": "2026-08-10T12:00:32.514Z",
"dateReserved": "2026-07-30T09:28:09.375Z",
"dateUpdated": "2026-08-19T16:31:39.730Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68372 (GCVE-0-2026-68372)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-17 05:04
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
usb: core: port: Deattach Type-C connector on component unbind
connector_unbind() is the mirror of connector_bind(), but it is missing
the symmetric call to typec_deattach() that connector_bind() makes via:
if (port_dev->child)
typec_attach(port_dev->connector, &port_dev->child->dev);
When a Thunderbolt dock is unplugged, two teardown paths race:
1. The component framework calls connector_unbind() first, which sets
port_dev->connector = NULL without calling typec_deattach(). This
leaves port->usb2_dev/port->usb3_dev in struct typec_port pointing at
the USB device that is about to be freed.
2. usb_disconnect() then calls typec_deattach(port_dev->connector, ...),
but port_dev->connector is already NULL, so the call is a no-op and
port->usb2_dev is never cleared.
3. Concurrently, UCSI detects a PD partner-disconnect event and calls
typec_unregister_partner(), which reads port->usb2_dev (now a dangling
pointer to freed memory) and passes it to typec_partner_unlink_device()
-> sysfs_remove_link() -> dev_name() on the freed device, corrupting
the typec/UCSI partner state.
This corruption leaves the Thunderbolt tunnel in an inconsistent state on
the next dock hot-plug. On affected hardware the dock's I225/igc NIC fails
to enumerate: AER fires a slot reset while the igc driver is still
initialising ("PCIe link lost"), and the subsequent igc_reset attempt hits
igc_rd32 on an already-detached device:
igc 0000:2e:00.0 eth0: PCIe link lost, device now detached
igc: Failed to read reg 0x0!
WARNING: CPU: 9 PID: 129 at drivers/net/ethernet/intel/igc/igc_main.c:7005
igc_rd32+0xa4/0xc0 [igc]
Call Trace:
igc_disable_pcie_master+0x16/0xa0 [igc]
igc_reset_hw_base+0x14/0x170 [igc]
igc_reset+0x63/0x110 [igc]
igc_io_slot_reset+0x9e/0xd0 [igc]
report_slot_reset+0x5d/0xc0
pcie_do_recovery+0x209/0x400
aer_isr_one_error_type+0x235/0x430
aer_isr+0x4e/0x80
irq_thread+0xf4/0x1f0
4. UCSI later handles the PD partner-disconnect and calls
typec_unregister_partner(), which still sees the stale port->usb2_dev
and tries to remove its sysfs link a second time:
kernfs: can not remove 'typec', no directory
WARNING: CPU: 6 PID: 55 at fs/kernfs/dir.c:1706 kernfs_remove_by_name_ns+0xe9/0xf0
Workqueue: events ucsi_handle_connector_change [typec_ucsi]
Call Trace:
sysfs_remove_link+0x19/0x50
typec_unregister_partner+0x6e/0x120 [typec]
ucsi_unregister_partner+0x107/0x150 [typec_ucsi]
ucsi_handle_connector_change+0x3ec/0x490 [typec_ucsi]
process_one_work+0x18e/0x3e0
worker_thread+0x2e3/0x420
kthread+0x10a/0x230
ret_from_fork+0x121/0x140
ret_from_fork_asm+0x1a/0x30
With worse timing the same stale pointer is dereferenced after the
backing memory is freed, turning the warning into a use-after-free.
Fix the asymmetry: call typec_deattach() before clearing
port_dev->connector, matching what connector_bind() does on the bind side.
typec_partner_deattach() is already protected by port->partner_link_lock,
so it serialises safely with the concurrent typec_unregister_partner() path.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/core/port.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "78d361e60caf1999d51bda0e1b1004f5d39fcfbc",
"status": "affected",
"version": "11110783f5ea866318831a56353c6f1c3fc0d8ed",
"versionType": "git"
},
{
"lessThan": "7714fb896ed308cf13d32d317040adc4f200b8e4",
"status": "affected",
"version": "11110783f5ea866318831a56353c6f1c3fc0d8ed",
"versionType": "git"
},
{
"lessThan": "e00109b5adf71635919248e9ab6300a662e6a3e8",
"status": "affected",
"version": "11110783f5ea866318831a56353c6f1c3fc0d8ed",
"versionType": "git"
},
{
"lessThan": "e0b291fe117964037e0ba382eff4bb365d531c3a",
"status": "affected",
"version": "11110783f5ea866318831a56353c6f1c3fc0d8ed",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/usb/core/port.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.7"
},
{
"lessThan": "6.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: core: port: Deattach Type-C connector on component unbind\n\nconnector_unbind() is the mirror of connector_bind(), but it is missing\nthe symmetric call to typec_deattach() that connector_bind() makes via:\n\n if (port_dev-\u003echild)\n typec_attach(port_dev-\u003econnector, \u0026port_dev-\u003echild-\u003edev);\n\nWhen a Thunderbolt dock is unplugged, two teardown paths race:\n\n1. The component framework calls connector_unbind() first, which sets\n port_dev-\u003econnector = NULL without calling typec_deattach(). This\n leaves port-\u003eusb2_dev/port-\u003eusb3_dev in struct typec_port pointing at\n the USB device that is about to be freed.\n\n2. usb_disconnect() then calls typec_deattach(port_dev-\u003econnector, ...),\n but port_dev-\u003econnector is already NULL, so the call is a no-op and\n port-\u003eusb2_dev is never cleared.\n\n3. Concurrently, UCSI detects a PD partner-disconnect event and calls\n typec_unregister_partner(), which reads port-\u003eusb2_dev (now a dangling\n pointer to freed memory) and passes it to typec_partner_unlink_device()\n -\u003e sysfs_remove_link() -\u003e dev_name() on the freed device, corrupting\n the typec/UCSI partner state.\n\nThis corruption leaves the Thunderbolt tunnel in an inconsistent state on\nthe next dock hot-plug. On affected hardware the dock\u0027s I225/igc NIC fails\nto enumerate: AER fires a slot reset while the igc driver is still\ninitialising (\"PCIe link lost\"), and the subsequent igc_reset attempt hits\nigc_rd32 on an already-detached device:\n\n igc 0000:2e:00.0 eth0: PCIe link lost, device now detached\n igc: Failed to read reg 0x0!\n WARNING: CPU: 9 PID: 129 at drivers/net/ethernet/intel/igc/igc_main.c:7005\n igc_rd32+0xa4/0xc0 [igc]\n Call Trace:\n igc_disable_pcie_master+0x16/0xa0 [igc]\n igc_reset_hw_base+0x14/0x170 [igc]\n igc_reset+0x63/0x110 [igc]\n igc_io_slot_reset+0x9e/0xd0 [igc]\n report_slot_reset+0x5d/0xc0\n pcie_do_recovery+0x209/0x400\n aer_isr_one_error_type+0x235/0x430\n aer_isr+0x4e/0x80\n irq_thread+0xf4/0x1f0\n\n4. UCSI later handles the PD partner-disconnect and calls\n typec_unregister_partner(), which still sees the stale port-\u003eusb2_dev\n and tries to remove its sysfs link a second time:\n\n kernfs: can not remove \u0027typec\u0027, no directory\n WARNING: CPU: 6 PID: 55 at fs/kernfs/dir.c:1706 kernfs_remove_by_name_ns+0xe9/0xf0\n Workqueue: events ucsi_handle_connector_change [typec_ucsi]\n Call Trace:\n sysfs_remove_link+0x19/0x50\n typec_unregister_partner+0x6e/0x120 [typec]\n ucsi_unregister_partner+0x107/0x150 [typec_ucsi]\n ucsi_handle_connector_change+0x3ec/0x490 [typec_ucsi]\n process_one_work+0x18e/0x3e0\n worker_thread+0x2e3/0x420\n kthread+0x10a/0x230\n ret_from_fork+0x121/0x140\n ret_from_fork_asm+0x1a/0x30\n\n With worse timing the same stale pointer is dereferenced after the\n backing memory is freed, turning the warning into a use-after-free.\n\nFix the asymmetry: call typec_deattach() before clearing\nport_dev-\u003econnector, matching what connector_bind() does on the bind side.\ntypec_partner_deattach() is already protected by port-\u003epartner_link_lock,\nso it serialises safely with the concurrent typec_unregister_partner() path."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:04:17.570Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/78d361e60caf1999d51bda0e1b1004f5d39fcfbc"
},
{
"url": "https://git.kernel.org/stable/c/7714fb896ed308cf13d32d317040adc4f200b8e4"
},
{
"url": "https://git.kernel.org/stable/c/e00109b5adf71635919248e9ab6300a662e6a3e8"
},
{
"url": "https://git.kernel.org/stable/c/e0b291fe117964037e0ba382eff4bb365d531c3a"
}
],
"title": "usb: core: port: Deattach Type-C connector on component unbind",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68372",
"datePublished": "2026-08-10T12:03:50.292Z",
"dateReserved": "2026-07-30T09:28:09.386Z",
"dateUpdated": "2026-08-17T05:04:17.570Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64569 (GCVE-0-2026-64569)
Vulnerability from cvelistv5
Published
2026-08-05 08:08
Modified
2026-08-19 16:28
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n
On CONFIG_INET=n builds, mpls_valid_fib_dump_req() walks the parsed
attribute table itself instead of calling ip_valid_fib_dump_req(). The
RTA_OIF arm passes tb[RTA_OIF] to nla_get_u32() without checking it is
present, so an RTM_GETROUTE dump for AF_MPLS with strict checking and no
RTA_OIF hits a NULL dereference.
RTM_GETROUTE is RTNL_KIND_GET, which rtnetlink_rcv_msg() permits without
CAP_NET_ADMIN, so an unprivileged user can trigger it.
Oops: general protection fault, probably for non-canonical address
0xdffffc0000000000: 0000 [#1] SMP KASAN NOPTI
KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]
RIP: 0010:mpls_valid_fib_dump_req (net/mpls/af_mpls.c:2189)
Call Trace:
mpls_dump_routes (net/mpls/af_mpls.c:2236)
netlink_dump (net/netlink/af_netlink.c:2331)
__netlink_dump_start (net/netlink/af_netlink.c:2446)
rtnetlink_rcv_msg (net/core/rtnetlink.c:7033)
netlink_rcv_skb (net/netlink/af_netlink.c:2556)
netlink_unicast (net/netlink/af_netlink.c:1345)
netlink_sendmsg (net/netlink/af_netlink.c:1900)
__sock_sendmsg (net/socket.c:790)
____sys_sendmsg (net/socket.c:2684)
___sys_sendmsg (net/socket.c:2738)
__sys_sendmsg (net/socket.c:2770)
do_syscall_64 (arch/x86/entry/syscall_64.c:94)
entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)
Skip unset attributes, as ip_valid_fib_dump_req() does.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 196cfebf897266c3450519e916bab9daff74e52c Version: 196cfebf897266c3450519e916bab9daff74e52c Version: 196cfebf897266c3450519e916bab9daff74e52c Version: 196cfebf897266c3450519e916bab9daff74e52c Version: 196cfebf897266c3450519e916bab9daff74e52c Version: 196cfebf897266c3450519e916bab9daff74e52c Version: 196cfebf897266c3450519e916bab9daff74e52c Version: 196cfebf897266c3450519e916bab9daff74e52c |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/mpls/af_mpls.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "bfc1cb5d6a8308e493e307f1c823d2107abc0a47",
"status": "affected",
"version": "196cfebf897266c3450519e916bab9daff74e52c",
"versionType": "git"
},
{
"lessThan": "03b5a2c29afc8e634924c75d6ee94140e70de88d",
"status": "affected",
"version": "196cfebf897266c3450519e916bab9daff74e52c",
"versionType": "git"
},
{
"lessThan": "e796ce9ef4356dc7cbbaa8373843f77852f2814d",
"status": "affected",
"version": "196cfebf897266c3450519e916bab9daff74e52c",
"versionType": "git"
},
{
"lessThan": "d6eee7cd078aaf9dd75efc801f6c9b608a37cd71",
"status": "affected",
"version": "196cfebf897266c3450519e916bab9daff74e52c",
"versionType": "git"
},
{
"lessThan": "ad6284ced6a15e4abd57ca4d0793b7bd15ca52ce",
"status": "affected",
"version": "196cfebf897266c3450519e916bab9daff74e52c",
"versionType": "git"
},
{
"lessThan": "5f6e7b32bd1fbde10fd31a4143260735ea535b8a",
"status": "affected",
"version": "196cfebf897266c3450519e916bab9daff74e52c",
"versionType": "git"
},
{
"lessThan": "06db79411a280707c7e4bf4b221ff4e664b51502",
"status": "affected",
"version": "196cfebf897266c3450519e916bab9daff74e52c",
"versionType": "git"
},
{
"lessThan": "56d96fededd61192cd7cc8d2b0f36adfd59036c3",
"status": "affected",
"version": "196cfebf897266c3450519e916bab9daff74e52c",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/mpls/af_mpls.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.20"
},
{
"lessThan": "4.20",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.20",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n\n\nOn CONFIG_INET=n builds, mpls_valid_fib_dump_req() walks the parsed\nattribute table itself instead of calling ip_valid_fib_dump_req(). The\nRTA_OIF arm passes tb[RTA_OIF] to nla_get_u32() without checking it is\npresent, so an RTM_GETROUTE dump for AF_MPLS with strict checking and no\nRTA_OIF hits a NULL dereference.\n\nRTM_GETROUTE is RTNL_KIND_GET, which rtnetlink_rcv_msg() permits without\nCAP_NET_ADMIN, so an unprivileged user can trigger it.\n\n Oops: general protection fault, probably for non-canonical address\n 0xdffffc0000000000: 0000 [#1] SMP KASAN NOPTI\n KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]\n RIP: 0010:mpls_valid_fib_dump_req (net/mpls/af_mpls.c:2189)\n Call Trace:\n mpls_dump_routes (net/mpls/af_mpls.c:2236)\n netlink_dump (net/netlink/af_netlink.c:2331)\n __netlink_dump_start (net/netlink/af_netlink.c:2446)\n rtnetlink_rcv_msg (net/core/rtnetlink.c:7033)\n netlink_rcv_skb (net/netlink/af_netlink.c:2556)\n netlink_unicast (net/netlink/af_netlink.c:1345)\n netlink_sendmsg (net/netlink/af_netlink.c:1900)\n __sock_sendmsg (net/socket.c:790)\n ____sys_sendmsg (net/socket.c:2684)\n ___sys_sendmsg (net/socket.c:2738)\n __sys_sendmsg (net/socket.c:2770)\n do_syscall_64 (arch/x86/entry/syscall_64.c:94)\n entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)\n\nSkip unset attributes, as ip_valid_fib_dump_req() does."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:28:44.216Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/bfc1cb5d6a8308e493e307f1c823d2107abc0a47"
},
{
"url": "https://git.kernel.org/stable/c/03b5a2c29afc8e634924c75d6ee94140e70de88d"
},
{
"url": "https://git.kernel.org/stable/c/e796ce9ef4356dc7cbbaa8373843f77852f2814d"
},
{
"url": "https://git.kernel.org/stable/c/d6eee7cd078aaf9dd75efc801f6c9b608a37cd71"
},
{
"url": "https://git.kernel.org/stable/c/ad6284ced6a15e4abd57ca4d0793b7bd15ca52ce"
},
{
"url": "https://git.kernel.org/stable/c/5f6e7b32bd1fbde10fd31a4143260735ea535b8a"
},
{
"url": "https://git.kernel.org/stable/c/06db79411a280707c7e4bf4b221ff4e664b51502"
},
{
"url": "https://git.kernel.org/stable/c/56d96fededd61192cd7cc8d2b0f36adfd59036c3"
}
],
"title": "mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64569",
"datePublished": "2026-08-05T08:08:07.233Z",
"dateReserved": "2026-07-19T15:36:31.797Z",
"dateUpdated": "2026-08-19T16:28:44.216Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68309 (GCVE-0-2026-68309)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: mt76: connac: fix possible NULL-pointer deref in mt76_connac_mcu_uni_bss_he_tlv()
mt76_connac_get_he_phy_cap routine can theoretically return NULL so
check cap pointer before dereferencing it.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d0e274af2f2e44b9d496f5d2c0431fdd2ea76fb8 Version: d0e274af2f2e44b9d496f5d2c0431fdd2ea76fb8 Version: d0e274af2f2e44b9d496f5d2c0431fdd2ea76fb8 Version: d0e274af2f2e44b9d496f5d2c0431fdd2ea76fb8 Version: d0e274af2f2e44b9d496f5d2c0431fdd2ea76fb8 Version: d0e274af2f2e44b9d496f5d2c0431fdd2ea76fb8 Version: d0e274af2f2e44b9d496f5d2c0431fdd2ea76fb8 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/mediatek/mt76/mt76_connac_mcu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "d1f8705d6545d20950991785306d08884b0056fc",
"status": "affected",
"version": "d0e274af2f2e44b9d496f5d2c0431fdd2ea76fb8",
"versionType": "git"
},
{
"lessThan": "91eb15c026debd8b7bfbd83f062e6245a4e69964",
"status": "affected",
"version": "d0e274af2f2e44b9d496f5d2c0431fdd2ea76fb8",
"versionType": "git"
},
{
"lessThan": "b09508dd7bc4a8948ea00603041a918c09788502",
"status": "affected",
"version": "d0e274af2f2e44b9d496f5d2c0431fdd2ea76fb8",
"versionType": "git"
},
{
"lessThan": "2afc2d5098866518a5c446a2e647b1b3f43daaf4",
"status": "affected",
"version": "d0e274af2f2e44b9d496f5d2c0431fdd2ea76fb8",
"versionType": "git"
},
{
"lessThan": "c058786b09cfab080125bc3ee7928a181dcbd37a",
"status": "affected",
"version": "d0e274af2f2e44b9d496f5d2c0431fdd2ea76fb8",
"versionType": "git"
},
{
"lessThan": "8709c66e665a2a09192853d4f3d0fb4bd0f76403",
"status": "affected",
"version": "d0e274af2f2e44b9d496f5d2c0431fdd2ea76fb8",
"versionType": "git"
},
{
"lessThan": "2c1fb2335f5e3afb34f91bc07ecb63517c328090",
"status": "affected",
"version": "d0e274af2f2e44b9d496f5d2c0431fdd2ea76fb8",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/mediatek/mt76/mt76_connac_mcu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.12"
},
{
"lessThan": "5.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: connac: fix possible NULL-pointer deref in mt76_connac_mcu_uni_bss_he_tlv()\n\nmt76_connac_get_he_phy_cap routine can theoretically return NULL so\ncheck cap pointer before dereferencing it."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:00.744Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/d1f8705d6545d20950991785306d08884b0056fc"
},
{
"url": "https://git.kernel.org/stable/c/91eb15c026debd8b7bfbd83f062e6245a4e69964"
},
{
"url": "https://git.kernel.org/stable/c/b09508dd7bc4a8948ea00603041a918c09788502"
},
{
"url": "https://git.kernel.org/stable/c/2afc2d5098866518a5c446a2e647b1b3f43daaf4"
},
{
"url": "https://git.kernel.org/stable/c/c058786b09cfab080125bc3ee7928a181dcbd37a"
},
{
"url": "https://git.kernel.org/stable/c/8709c66e665a2a09192853d4f3d0fb4bd0f76403"
},
{
"url": "https://git.kernel.org/stable/c/2c1fb2335f5e3afb34f91bc07ecb63517c328090"
}
],
"title": "wifi: mt76: connac: fix possible NULL-pointer deref in mt76_connac_mcu_uni_bss_he_tlv()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68309",
"datePublished": "2026-08-10T12:02:43.950Z",
"dateReserved": "2026-07-30T09:28:09.381Z",
"dateUpdated": "2026-08-19T16:33:00.744Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68234 (GCVE-0-2026-68234)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: fix bo->pin leaking in amdgpu_bo_create_reserved
amdgpu_bo_create_reserved() only allocates a new BO when
*bo_ptr (struct amdgpu_bo **bo_ptr as input parameter) is
NULL, it simply skips creation when *bo_ptr is non-NULL.
But it unconditionally reserves, pins, gart allocates
and maps the BO afterwards.
When the same non-NULL BO pointer is passed in again,
for example firmware buffers that live in adev and are
re-loaded on every resume / cp_resume / start
under AMDGPU_FW_LOAD_DIRECT, amdgpu_bo_pin() just increases
pin_count unconditionally, however the matching teardown only unpins
once, so pin_count never drops to zero, so TTM is not able
to move, swap or evict a BO, causing BO leaks.
This commit fixes this issue by only pinning the bo
once at creation, and repeated calls no longer
take additional pin references.
(cherry picked from commit 3ddc0ae76202c447b6aec61e907b852bc94671cf)
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 53766e5adac75872e9d413cdbfd0e47ae40701f9 Version: 53766e5adac75872e9d413cdbfd0e47ae40701f9 Version: 53766e5adac75872e9d413cdbfd0e47ae40701f9 Version: 53766e5adac75872e9d413cdbfd0e47ae40701f9 Version: 53766e5adac75872e9d413cdbfd0e47ae40701f9 Version: 53766e5adac75872e9d413cdbfd0e47ae40701f9 Version: 53766e5adac75872e9d413cdbfd0e47ae40701f9 Version: 53766e5adac75872e9d413cdbfd0e47ae40701f9 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/amdgpu_object.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "7aea619d9f186dcf0f1289879e9edb69d2b56639",
"status": "affected",
"version": "53766e5adac75872e9d413cdbfd0e47ae40701f9",
"versionType": "git"
},
{
"lessThan": "b572d0814c1366701ca704286589fab025802566",
"status": "affected",
"version": "53766e5adac75872e9d413cdbfd0e47ae40701f9",
"versionType": "git"
},
{
"lessThan": "e06e0885725a16304b7723aeb478a78cca9dc96a",
"status": "affected",
"version": "53766e5adac75872e9d413cdbfd0e47ae40701f9",
"versionType": "git"
},
{
"lessThan": "51eeef1949c11d3dcb5f422a5d9b3f09ebe8a1bc",
"status": "affected",
"version": "53766e5adac75872e9d413cdbfd0e47ae40701f9",
"versionType": "git"
},
{
"lessThan": "2f390b4c83011452753fd84972f657d2b00a952b",
"status": "affected",
"version": "53766e5adac75872e9d413cdbfd0e47ae40701f9",
"versionType": "git"
},
{
"lessThan": "ba7b6444097a73ccd3d3ac9e2be4ebb73d226460",
"status": "affected",
"version": "53766e5adac75872e9d413cdbfd0e47ae40701f9",
"versionType": "git"
},
{
"lessThan": "9743f60013273987abf415dc47474683d22aaee9",
"status": "affected",
"version": "53766e5adac75872e9d413cdbfd0e47ae40701f9",
"versionType": "git"
},
{
"lessThan": "a2f895f3c852063258d62e9f74b081de07ca95df",
"status": "affected",
"version": "53766e5adac75872e9d413cdbfd0e47ae40701f9",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/amdgpu_object.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.14"
},
{
"lessThan": "4.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: fix bo-\u003epin leaking in amdgpu_bo_create_reserved\n\namdgpu_bo_create_reserved() only allocates a new BO when\n*bo_ptr (struct amdgpu_bo **bo_ptr as input parameter) is\nNULL, it simply skips creation when *bo_ptr is non-NULL.\nBut it unconditionally reserves, pins, gart allocates\nand maps the BO afterwards.\n\nWhen the same non-NULL BO pointer is passed in again,\nfor example firmware buffers that live in adev and are\nre-loaded on every resume / cp_resume / start\nunder AMDGPU_FW_LOAD_DIRECT, amdgpu_bo_pin() just increases\npin_count unconditionally, however the matching teardown only unpins\nonce, so pin_count never drops to zero, so TTM is not able\nto move, swap or evict a BO, causing BO leaks.\n\nThis commit fixes this issue by only pinning the bo\nonce at creation, and repeated calls no longer\ntake additional pin references.\n\n(cherry picked from commit 3ddc0ae76202c447b6aec61e907b852bc94671cf)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:32:06.457Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/7aea619d9f186dcf0f1289879e9edb69d2b56639"
},
{
"url": "https://git.kernel.org/stable/c/b572d0814c1366701ca704286589fab025802566"
},
{
"url": "https://git.kernel.org/stable/c/e06e0885725a16304b7723aeb478a78cca9dc96a"
},
{
"url": "https://git.kernel.org/stable/c/51eeef1949c11d3dcb5f422a5d9b3f09ebe8a1bc"
},
{
"url": "https://git.kernel.org/stable/c/2f390b4c83011452753fd84972f657d2b00a952b"
},
{
"url": "https://git.kernel.org/stable/c/ba7b6444097a73ccd3d3ac9e2be4ebb73d226460"
},
{
"url": "https://git.kernel.org/stable/c/9743f60013273987abf415dc47474683d22aaee9"
},
{
"url": "https://git.kernel.org/stable/c/a2f895f3c852063258d62e9f74b081de07ca95df"
}
],
"title": "drm/amdgpu: fix bo-\u003epin leaking in amdgpu_bo_create_reserved",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68234",
"datePublished": "2026-08-10T12:00:59.074Z",
"dateReserved": "2026-07-30T09:28:09.376Z",
"dateUpdated": "2026-08-19T16:32:06.457Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68302 (GCVE-0-2026-68302)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-19 16:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
amt: re-read skb header pointers after every pull
Several AMT receive and transmit paths cache a pointer into the skb head
(ip_hdr(), ipv6_hdr(), eth_hdr() or the AMT message header) and then call
a helper that can reallocate that head before the cached pointer is used
again. pskb_may_pull(), ip_mc_may_pull(), ipv6_mc_may_pull(),
iptunnel_pull_header(), ip_mc_check_igmp() and ipv6_mc_check_mld() can all
free the old head and move the data, so a pointer taken before the call
dangles afterwards and the later access is a use-after-free of the freed
head.
The affected sites are:
amt_rcv() caches ip_hdr() before amt_parse_type() pulls, then reads
iph->saddr.
amt_dev_xmit() caches ip_hdr()/ipv6_hdr() before ip_mc_check_igmp()/
ipv6_mc_check_mld() and pskb_may_pull(), then reads the group address.
amt_multicast_data_handler() caches eth_hdr() before pskb_may_pull(),
then writes the L2 header.
amt_membership_query_handler() caches the AMT header, the outer and
inner eth_hdr() and ip_hdr() before iptunnel_pull_header() and several
pulls, then reads and writes them.
amt_igmpv3_report_handler() and amt_mldv2_report_handler() cache
ip_hdr()/ipv6_hdr() and the current group record and read the record
count from the report header inside the record loop, across the
*_mc_may_pull() calls.
amt_update_handler() caches ip_hdr() and the AMT membership-update
header before pskb_may_pull(), iptunnel_pull_header(),
ip_mc_check_igmp() and the report handler, then reads iph->daddr and
amtmu->nonce / amtmu->response_mac.
Fix each site by either snapshotting the scalar that is used after the
pull before the first pull runs, or re-deriving the header pointer from
the skb after the last pull that can move the head. Values that are
stable across the pull (source and group address, the response MAC and
nonce, the record count, the outer source MAC) are snapshotted; pointers
that are written through or read repeatedly are re-derived.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: cbc21dc1cfe949e37b2a54c71511579f1899e8d4 Version: cbc21dc1cfe949e37b2a54c71511579f1899e8d4 Version: cbc21dc1cfe949e37b2a54c71511579f1899e8d4 Version: cbc21dc1cfe949e37b2a54c71511579f1899e8d4 Version: cbc21dc1cfe949e37b2a54c71511579f1899e8d4 Version: cbc21dc1cfe949e37b2a54c71511579f1899e8d4 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/amt.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "37ff890f9c18dfbcf57e17199901d4fd1e4c174e",
"status": "affected",
"version": "cbc21dc1cfe949e37b2a54c71511579f1899e8d4",
"versionType": "git"
},
{
"lessThan": "9005b221cb1f9c3c1a2ef656fb0e8fa80c0a187e",
"status": "affected",
"version": "cbc21dc1cfe949e37b2a54c71511579f1899e8d4",
"versionType": "git"
},
{
"lessThan": "7746d588d42a4ac0117b68ed8e9b22a9da53dfb7",
"status": "affected",
"version": "cbc21dc1cfe949e37b2a54c71511579f1899e8d4",
"versionType": "git"
},
{
"lessThan": "ca0e8b661957f777591efe874cd9d9a63619cd99",
"status": "affected",
"version": "cbc21dc1cfe949e37b2a54c71511579f1899e8d4",
"versionType": "git"
},
{
"lessThan": "7f48e3ddad8e97545b25788b8203b3a539df1621",
"status": "affected",
"version": "cbc21dc1cfe949e37b2a54c71511579f1899e8d4",
"versionType": "git"
},
{
"lessThan": "3656a79f94c471827a08f2cacce5f94ad5e52c24",
"status": "affected",
"version": "cbc21dc1cfe949e37b2a54c71511579f1899e8d4",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/amt.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.16"
},
{
"lessThan": "5.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.16",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\namt: re-read skb header pointers after every pull\n\nSeveral AMT receive and transmit paths cache a pointer into the skb head\n(ip_hdr(), ipv6_hdr(), eth_hdr() or the AMT message header) and then call\na helper that can reallocate that head before the cached pointer is used\nagain. pskb_may_pull(), ip_mc_may_pull(), ipv6_mc_may_pull(),\niptunnel_pull_header(), ip_mc_check_igmp() and ipv6_mc_check_mld() can all\nfree the old head and move the data, so a pointer taken before the call\ndangles afterwards and the later access is a use-after-free of the freed\nhead.\n\nThe affected sites are:\n\n amt_rcv() caches ip_hdr() before amt_parse_type() pulls, then reads\n iph-\u003esaddr.\n\n amt_dev_xmit() caches ip_hdr()/ipv6_hdr() before ip_mc_check_igmp()/\n ipv6_mc_check_mld() and pskb_may_pull(), then reads the group address.\n\n amt_multicast_data_handler() caches eth_hdr() before pskb_may_pull(),\n then writes the L2 header.\n\n amt_membership_query_handler() caches the AMT header, the outer and\n inner eth_hdr() and ip_hdr() before iptunnel_pull_header() and several\n pulls, then reads and writes them.\n\n amt_igmpv3_report_handler() and amt_mldv2_report_handler() cache\n ip_hdr()/ipv6_hdr() and the current group record and read the record\n count from the report header inside the record loop, across the\n *_mc_may_pull() calls.\n\n amt_update_handler() caches ip_hdr() and the AMT membership-update\n header before pskb_may_pull(), iptunnel_pull_header(),\n ip_mc_check_igmp() and the report handler, then reads iph-\u003edaddr and\n amtmu-\u003enonce / amtmu-\u003eresponse_mac.\n\nFix each site by either snapshotting the scalar that is used after the\npull before the first pull runs, or re-deriving the header pointer from\nthe skb after the last pull that can move the head. Values that are\nstable across the pull (source and group address, the response MAC and\nnonce, the record count, the outer source MAC) are snapshotted; pointers\nthat are written through or read repeatedly are re-derived."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - AMT is a routable UDP tunnel (port 2268); all affected handlers run from amt_rcv(), the UDP encap receive callback, on packets from arbitrary remote hosts across the internet. No same-segment requirement exists.\nAC:L - The attacker chooses the packet sizes and fragmentation that make the skb non-linear or cloned, so the pskb_may_pull()/iptunnel_pull_header()/ip_mc_check_igmp() calls deterministically reallocate the skb head and strand the cached pointers; no race or uncontrollable state is involved.\nPR:N - AMT has no authentication: amt_request_handler() creates a tunnel for any source IP and returns the nonce/response MAC to the sender, so an unauthenticated remote host can complete the handshake and then reach the vulnerable update/report paths; gateway paths need only a spoofed relay source address.\nUI:N - Exploitation is entirely driven by inbound UDP packets processed in softirq context; no local user action or interaction is required on the target relay or gateway.\nS:U - The use-after-free corrupts kernel heap memory within the same kernel security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - Stale header pointers are read after the head is freed, so freed heap contents are consumed as source/group addresses and record counts, and are copied into the destination MAC of frames delivered up the stack, leaking reallocated kernel memory to the attacker; UAF reads generally enable broader disclosure.\nI:H - amt_multicast_data_handler() and amt_membership_query_handler() write through the dangling pointers (eth-\u003eh_proto, ip_eth_mc_map()/ipv6_eth_mc_map() into eth-\u003eh_dest, ether_addr_copy of h_source), giving an attacker-influenced heap write into freed and likely reallocated memory, a classic control-flow hijack primitive.\nA:H - Use-after-free reads and writes on a freed skb head corrupt the slab and readily cause KASAN splats, oopses, or kernel panic, and the packets triggering it can be sent repeatedly by an unauthenticated remote attacker."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:32:55.916Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/37ff890f9c18dfbcf57e17199901d4fd1e4c174e"
},
{
"url": "https://git.kernel.org/stable/c/9005b221cb1f9c3c1a2ef656fb0e8fa80c0a187e"
},
{
"url": "https://git.kernel.org/stable/c/7746d588d42a4ac0117b68ed8e9b22a9da53dfb7"
},
{
"url": "https://git.kernel.org/stable/c/ca0e8b661957f777591efe874cd9d9a63619cd99"
},
{
"url": "https://git.kernel.org/stable/c/7f48e3ddad8e97545b25788b8203b3a539df1621"
},
{
"url": "https://git.kernel.org/stable/c/3656a79f94c471827a08f2cacce5f94ad5e52c24"
}
],
"title": "amt: re-read skb header pointers after every pull",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68302",
"datePublished": "2026-08-10T12:02:36.313Z",
"dateReserved": "2026-07-30T09:28:09.381Z",
"dateUpdated": "2026-08-19T16:32:55.916Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68193 (GCVE-0-2026-68193)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-17 05:00
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses
PKT_TYPE_TXRX_NOTIFY is an mmio-only event, but mt7925_rx_check() and
mt7925_queue_rx_skb() dispatch it to mt7925_mac_tx_free() on every bus.
mt7925_mac_tx_free() cleans the DMA tx queues with
mt76_queue_tx_cleanup(), which calls queue_ops->tx_cleanup(). Only the
mmio queue ops implement that callback; on USB it is NULL, so a
TXRX_NOTIFY there calls a NULL pointer in the RX worker:
BUG: kernel NULL pointer dereference, address: 0000000000000000
RIP: 0010:0x0
Call Trace:
mt7925_mac_tx_free+0x58/0x350 [mt7925_common]
mt7925_rx_check+0xe2/0x130 [mt7925_common]
mt76u_rx_worker+0x1b9/0x620 [mt76_usb]
Drop the event on non-mmio buses via mt76_is_mmio(), as in
commit 5683e1488aa9 ("wifi: mt76: connac: do not check WED status for
non-mmio devices").
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/mediatek/mt76/mt7925/mac.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "0c8c4cd0ca60b45c4b05a39e3769b8473d6836eb",
"status": "affected",
"version": "c948b5da6bbec742b433138e3e3f9537a85af2e5",
"versionType": "git"
},
{
"lessThan": "9cb72f67e1502aabba51aab9ac04ae7c386ee194",
"status": "affected",
"version": "c948b5da6bbec742b433138e3e3f9537a85af2e5",
"versionType": "git"
},
{
"lessThan": "9677e86a5f7d680fe280a5f8999bc57353e360d7",
"status": "affected",
"version": "c948b5da6bbec742b433138e3e3f9537a85af2e5",
"versionType": "git"
},
{
"lessThan": "feeff151c83e7f0ffcdedcad5343852d23d1f6e1",
"status": "affected",
"version": "c948b5da6bbec742b433138e3e3f9537a85af2e5",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/mediatek/mt76/mt7925/mac.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.7"
},
{
"lessThan": "6.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses\n\nPKT_TYPE_TXRX_NOTIFY is an mmio-only event, but mt7925_rx_check() and\nmt7925_queue_rx_skb() dispatch it to mt7925_mac_tx_free() on every bus.\nmt7925_mac_tx_free() cleans the DMA tx queues with\nmt76_queue_tx_cleanup(), which calls queue_ops-\u003etx_cleanup(). Only the\nmmio queue ops implement that callback; on USB it is NULL, so a\nTXRX_NOTIFY there calls a NULL pointer in the RX worker:\n\n BUG: kernel NULL pointer dereference, address: 0000000000000000\n RIP: 0010:0x0\n Call Trace:\n mt7925_mac_tx_free+0x58/0x350 [mt7925_common]\n mt7925_rx_check+0xe2/0x130 [mt7925_common]\n mt76u_rx_worker+0x1b9/0x620 [mt76_usb]\n\nDrop the event on non-mmio buses via mt76_is_mmio(), as in\ncommit 5683e1488aa9 (\"wifi: mt76: connac: do not check WED status for\nnon-mmio devices\")."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:00:36.015Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/0c8c4cd0ca60b45c4b05a39e3769b8473d6836eb"
},
{
"url": "https://git.kernel.org/stable/c/9cb72f67e1502aabba51aab9ac04ae7c386ee194"
},
{
"url": "https://git.kernel.org/stable/c/9677e86a5f7d680fe280a5f8999bc57353e360d7"
},
{
"url": "https://git.kernel.org/stable/c/feeff151c83e7f0ffcdedcad5343852d23d1f6e1"
}
],
"title": "wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68193",
"datePublished": "2026-08-10T12:00:11.110Z",
"dateReserved": "2026-07-30T09:28:09.373Z",
"dateUpdated": "2026-08-17T05:00:36.015Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68366 (GCVE-0-2026-68366)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer
uvc_send_response() builds the UVC control response from a user-supplied
struct uvc_request_data:
req->length = min_t(unsigned int, uvc->event_length, data->length);
...
memcpy(req->buf, data->data, req->length);
req->length is clamped to uvc->event_length, which is taken from the
host control request wLength (up to UVC_MAX_REQUEST_SIZE, 64), and to
data->length, which comes from the UVCIOC_SEND_RESPONSE ioctl and is
only checked for being negative. The source buffer data->data is only
60 bytes, so a response with uvc->event_length and data->length both
greater than 60 makes memcpy() read past the end of data->data.
Clamp req->length to sizeof(data->data) as well.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: a5eaaa1f33e771fa1651a4a7652b8a5f9fa7f6c1 Version: a5eaaa1f33e771fa1651a4a7652b8a5f9fa7f6c1 Version: a5eaaa1f33e771fa1651a4a7652b8a5f9fa7f6c1 Version: a5eaaa1f33e771fa1651a4a7652b8a5f9fa7f6c1 Version: a5eaaa1f33e771fa1651a4a7652b8a5f9fa7f6c1 Version: a5eaaa1f33e771fa1651a4a7652b8a5f9fa7f6c1 Version: a5eaaa1f33e771fa1651a4a7652b8a5f9fa7f6c1 Version: a5eaaa1f33e771fa1651a4a7652b8a5f9fa7f6c1 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/gadget/function/uvc_v4l2.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "eaf783c005299a702f2cc96b08cd21ede081f098",
"status": "affected",
"version": "a5eaaa1f33e771fa1651a4a7652b8a5f9fa7f6c1",
"versionType": "git"
},
{
"lessThan": "568e68d8f80395a64848aa2946af8ade72da0ffb",
"status": "affected",
"version": "a5eaaa1f33e771fa1651a4a7652b8a5f9fa7f6c1",
"versionType": "git"
},
{
"lessThan": "82ec2c1e456b17451f0736c3983402642f961733",
"status": "affected",
"version": "a5eaaa1f33e771fa1651a4a7652b8a5f9fa7f6c1",
"versionType": "git"
},
{
"lessThan": "4e116372b7a4f87df0dc0ed4b0ab5b0bb0cc5796",
"status": "affected",
"version": "a5eaaa1f33e771fa1651a4a7652b8a5f9fa7f6c1",
"versionType": "git"
},
{
"lessThan": "662f6c6c6ff8a6c508e1646c09cae74e28f3cca6",
"status": "affected",
"version": "a5eaaa1f33e771fa1651a4a7652b8a5f9fa7f6c1",
"versionType": "git"
},
{
"lessThan": "1f03658f3e9b2f8fd1d1003ba389a0390b49a350",
"status": "affected",
"version": "a5eaaa1f33e771fa1651a4a7652b8a5f9fa7f6c1",
"versionType": "git"
},
{
"lessThan": "c8510fbbea09ef0170b56b14dc2b5890dc75be07",
"status": "affected",
"version": "a5eaaa1f33e771fa1651a4a7652b8a5f9fa7f6c1",
"versionType": "git"
},
{
"lessThan": "b70dc75e85ba968b7b76eebfe5d63000080b875b",
"status": "affected",
"version": "a5eaaa1f33e771fa1651a4a7652b8a5f9fa7f6c1",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/usb/gadget/function/uvc_v4l2.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.10"
},
{
"lessThan": "3.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer\n\nuvc_send_response() builds the UVC control response from a user-supplied\nstruct uvc_request_data:\n\n\treq-\u003elength = min_t(unsigned int, uvc-\u003eevent_length, data-\u003elength);\n\t...\n\tmemcpy(req-\u003ebuf, data-\u003edata, req-\u003elength);\n\nreq-\u003elength is clamped to uvc-\u003eevent_length, which is taken from the\nhost control request wLength (up to UVC_MAX_REQUEST_SIZE, 64), and to\ndata-\u003elength, which comes from the UVCIOC_SEND_RESPONSE ioctl and is\nonly checked for being negative. The source buffer data-\u003edata is only\n60 bytes, so a response with uvc-\u003eevent_length and data-\u003elength both\ngreater than 60 makes memcpy() read past the end of data-\u003edata.\n\nClamp req-\u003elength to sizeof(data-\u003edata) as well."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:23.776Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/eaf783c005299a702f2cc96b08cd21ede081f098"
},
{
"url": "https://git.kernel.org/stable/c/568e68d8f80395a64848aa2946af8ade72da0ffb"
},
{
"url": "https://git.kernel.org/stable/c/82ec2c1e456b17451f0736c3983402642f961733"
},
{
"url": "https://git.kernel.org/stable/c/4e116372b7a4f87df0dc0ed4b0ab5b0bb0cc5796"
},
{
"url": "https://git.kernel.org/stable/c/662f6c6c6ff8a6c508e1646c09cae74e28f3cca6"
},
{
"url": "https://git.kernel.org/stable/c/1f03658f3e9b2f8fd1d1003ba389a0390b49a350"
},
{
"url": "https://git.kernel.org/stable/c/c8510fbbea09ef0170b56b14dc2b5890dc75be07"
},
{
"url": "https://git.kernel.org/stable/c/b70dc75e85ba968b7b76eebfe5d63000080b875b"
}
],
"title": "usb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68366",
"datePublished": "2026-08-10T12:03:43.304Z",
"dateReserved": "2026-07-30T09:28:09.385Z",
"dateUpdated": "2026-08-19T16:34:23.776Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68175 (GCVE-0-2026-68175)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
tracing: Fix resource leak on mmiotrace trace_pipe close
The mmiotrace tracer was added May 12th 2008. At that time, resources
created in pipe_open() could not be freed because there was not
pipe_close function pointer of the tracer. The pipe_close function pointer
was added in December 7th, 2009, but the mmiotrace tracer was not updated.
mmio_pipe_open() allocates a header_iter and takes a pci_dev reference
when trace_pipe is opened. mmio_close() frees them, but it was only
wired to the tracer's .close callback.
tracing_release_pipe() invokes .pipe_close, not .close, when the
trace_pipe file is released. As a result, closing trace_pipe with the
mmiotrace tracer active leaked the header_iter allocation and left a
stale pci_dev reference.
Set .pipe_close to mmio_close, matching how function_graph wires both
callbacks to the same handler.
Note, if the trace_pipe is read to completion, it will clean up the
resources, but if one were to run:
# head -n 1 /sys/kernel/tracing/trace_pipe
VERSION 20070824
Over and over again, it would trigger a massive leak.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: c521efd1700a8c0f7ce26f011f5eaecca17fabfa Version: c521efd1700a8c0f7ce26f011f5eaecca17fabfa Version: c521efd1700a8c0f7ce26f011f5eaecca17fabfa Version: c521efd1700a8c0f7ce26f011f5eaecca17fabfa Version: c521efd1700a8c0f7ce26f011f5eaecca17fabfa Version: c521efd1700a8c0f7ce26f011f5eaecca17fabfa Version: c521efd1700a8c0f7ce26f011f5eaecca17fabfa Version: c521efd1700a8c0f7ce26f011f5eaecca17fabfa |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"kernel/trace/trace_mmiotrace.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "7871128ea41217fa6a58bbbcb44cb0d2e9e60966",
"status": "affected",
"version": "c521efd1700a8c0f7ce26f011f5eaecca17fabfa",
"versionType": "git"
},
{
"lessThan": "1d0b59e2b203c02149d8f63607329debe36b3ec5",
"status": "affected",
"version": "c521efd1700a8c0f7ce26f011f5eaecca17fabfa",
"versionType": "git"
},
{
"lessThan": "581ac13e12e77d6c64f8719083bdf95209308919",
"status": "affected",
"version": "c521efd1700a8c0f7ce26f011f5eaecca17fabfa",
"versionType": "git"
},
{
"lessThan": "f9e6dfe341fb31c95b9655eb6b1db8b3ae090817",
"status": "affected",
"version": "c521efd1700a8c0f7ce26f011f5eaecca17fabfa",
"versionType": "git"
},
{
"lessThan": "594e1cf3f736779a535873fd5988162d827bfe4f",
"status": "affected",
"version": "c521efd1700a8c0f7ce26f011f5eaecca17fabfa",
"versionType": "git"
},
{
"lessThan": "cf5a82bef623b969a609f2b7e392d06dbae34aa6",
"status": "affected",
"version": "c521efd1700a8c0f7ce26f011f5eaecca17fabfa",
"versionType": "git"
},
{
"lessThan": "cb459fec4f7b13caf646101ff076e94ef38434d8",
"status": "affected",
"version": "c521efd1700a8c0f7ce26f011f5eaecca17fabfa",
"versionType": "git"
},
{
"lessThan": "c1d87e724ae55e781b7cc7ccafb34d9e668582b2",
"status": "affected",
"version": "c521efd1700a8c0f7ce26f011f5eaecca17fabfa",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"kernel/trace/trace_mmiotrace.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.33"
},
{
"lessThan": "2.6.33",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.33",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.33",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.33",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.33",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.33",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.33",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.33",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.33",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Fix resource leak on mmiotrace trace_pipe close\n\nThe mmiotrace tracer was added May 12th 2008. At that time, resources\ncreated in pipe_open() could not be freed because there was not\npipe_close function pointer of the tracer. The pipe_close function pointer\nwas added in December 7th, 2009, but the mmiotrace tracer was not updated.\n\nmmio_pipe_open() allocates a header_iter and takes a pci_dev reference\nwhen trace_pipe is opened. mmio_close() frees them, but it was only\nwired to the tracer\u0027s .close callback.\n\ntracing_release_pipe() invokes .pipe_close, not .close, when the\ntrace_pipe file is released. As a result, closing trace_pipe with the\nmmiotrace tracer active leaked the header_iter allocation and left a\nstale pci_dev reference.\n\nSet .pipe_close to mmio_close, matching how function_graph wires both\ncallbacks to the same handler.\n\nNote, if the trace_pipe is read to completion, it will clean up the\nresources, but if one were to run:\n\n # head -n 1 /sys/kernel/tracing/trace_pipe\n VERSION 20070824\n\nOver and over again, it would trigger a massive leak."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:30:39.826Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/7871128ea41217fa6a58bbbcb44cb0d2e9e60966"
},
{
"url": "https://git.kernel.org/stable/c/1d0b59e2b203c02149d8f63607329debe36b3ec5"
},
{
"url": "https://git.kernel.org/stable/c/581ac13e12e77d6c64f8719083bdf95209308919"
},
{
"url": "https://git.kernel.org/stable/c/f9e6dfe341fb31c95b9655eb6b1db8b3ae090817"
},
{
"url": "https://git.kernel.org/stable/c/594e1cf3f736779a535873fd5988162d827bfe4f"
},
{
"url": "https://git.kernel.org/stable/c/cf5a82bef623b969a609f2b7e392d06dbae34aa6"
},
{
"url": "https://git.kernel.org/stable/c/cb459fec4f7b13caf646101ff076e94ef38434d8"
},
{
"url": "https://git.kernel.org/stable/c/c1d87e724ae55e781b7cc7ccafb34d9e668582b2"
}
],
"title": "tracing: Fix resource leak on mmiotrace trace_pipe close",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68175",
"datePublished": "2026-08-10T11:59:45.965Z",
"dateReserved": "2026-07-30T09:28:09.372Z",
"dateUpdated": "2026-08-19T16:30:39.826Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68446 (GCVE-0-2026-68446)
Vulnerability from cvelistv5
Published
2026-08-12 00:07
Modified
2026-08-19 16:35
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/vmwgfx: Validate vmw_surface_metadata::array_size
This field comes from userspace and should be validated against specific
limits depending on which Shader Model (SM) is available.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 504901dbb0b565fcbe466b0c56f3131586df5afd Version: 504901dbb0b565fcbe466b0c56f3131586df5afd Version: 504901dbb0b565fcbe466b0c56f3131586df5afd Version: 504901dbb0b565fcbe466b0c56f3131586df5afd Version: 504901dbb0b565fcbe466b0c56f3131586df5afd Version: 504901dbb0b565fcbe466b0c56f3131586df5afd Version: 504901dbb0b565fcbe466b0c56f3131586df5afd Version: 504901dbb0b565fcbe466b0c56f3131586df5afd |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/vmwgfx/vmwgfx_surface.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "e949adf2d42678fb391a41db277e2fcb12090566",
"status": "affected",
"version": "504901dbb0b565fcbe466b0c56f3131586df5afd",
"versionType": "git"
},
{
"lessThan": "0403cec2aff8037bc246cf9a0831eb169ddcd9df",
"status": "affected",
"version": "504901dbb0b565fcbe466b0c56f3131586df5afd",
"versionType": "git"
},
{
"lessThan": "aded8463466ede7a7fbd1bbf821756c67c83e89b",
"status": "affected",
"version": "504901dbb0b565fcbe466b0c56f3131586df5afd",
"versionType": "git"
},
{
"lessThan": "5ff94e1279176b539d451e3e754fdcbd1a8d520a",
"status": "affected",
"version": "504901dbb0b565fcbe466b0c56f3131586df5afd",
"versionType": "git"
},
{
"lessThan": "71779fe8bf403a9b3e28dc59229fa556db32d35d",
"status": "affected",
"version": "504901dbb0b565fcbe466b0c56f3131586df5afd",
"versionType": "git"
},
{
"lessThan": "b1379f0c42b88cb60b9f3757eb5d1e73ad460ed8",
"status": "affected",
"version": "504901dbb0b565fcbe466b0c56f3131586df5afd",
"versionType": "git"
},
{
"lessThan": "6910ccaf41678f7761ba2e57d72b77d056320b4d",
"status": "affected",
"version": "504901dbb0b565fcbe466b0c56f3131586df5afd",
"versionType": "git"
},
{
"lessThan": "a4f55260f7f7d4dc4d0ee55063dfb0c457b77991",
"status": "affected",
"version": "504901dbb0b565fcbe466b0c56f3131586df5afd",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/vmwgfx/vmwgfx_surface.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.7"
},
{
"lessThan": "5.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vmwgfx: Validate vmw_surface_metadata::array_size\n\nThis field comes from userspace and should be validated against specific\nlimits depending on which Shader Model (SM) is available."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached through the DRM_IOCTL_VMW_GB_SURFACE_CREATE/_EXT ioctls on the vmwgfx render node (/dev/dri/renderD128), i.e. local access to the device file on a VMware guest; no network or physical access is involved.\nAC:L - The attacker directly supplies array_size, mip_levels and base_size in a single ioctl and can deterministically choose values that wrap the 32-bit size/subresource computations; no race or uncontrolled precondition is required.\nPR:L - Both ioctls are registered DRM_RENDER_ALLOW, so an unprivileged local user (or containerized workload) holding the normal render-node permissions can call them without DRM master, root, or any capability.\nUI:N - Exploitation is entirely attacker-driven via ioctl calls on an already-open render node; no action by another user or administrator is needed.\nS:U - The unvalidated value corrupts guest kernel memory and device-command state within the same kernel security authority; no VM/IOMMU or sandbox boundary is crossed by the flaw itself.\nC:H - The wrapped res-\u003eguest_memory_size makes the backing buffer far smaller than the surface the host device is told to service, and the undersized dirty-\u003eboxes array is indexed out of bounds, giving out-of-bounds reads of adjacent kernel heap data that can be leaked back through surface contents.\nI:H - The u32 overflows in vmw_surface_get_serialized_size() and num_layers*num_mip yield an undersized backing BO and dirty-tracking array, producing controlled out-of-bounds heap writes (SVGA3dBox data and device DMA past the buffer) usable for heap corruption and privilege escalation.\nA:H - Out-of-bounds writes past kvzalloc\u0027d dirty trackers and BO-sized mismatches reliably corrupt kernel heap metadata, causing oopses/panics; huge array_size values also drive enormous allocations, so a local user can crash the guest kernel."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:35:40.576Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/e949adf2d42678fb391a41db277e2fcb12090566"
},
{
"url": "https://git.kernel.org/stable/c/0403cec2aff8037bc246cf9a0831eb169ddcd9df"
},
{
"url": "https://git.kernel.org/stable/c/aded8463466ede7a7fbd1bbf821756c67c83e89b"
},
{
"url": "https://git.kernel.org/stable/c/5ff94e1279176b539d451e3e754fdcbd1a8d520a"
},
{
"url": "https://git.kernel.org/stable/c/71779fe8bf403a9b3e28dc59229fa556db32d35d"
},
{
"url": "https://git.kernel.org/stable/c/b1379f0c42b88cb60b9f3757eb5d1e73ad460ed8"
},
{
"url": "https://git.kernel.org/stable/c/6910ccaf41678f7761ba2e57d72b77d056320b4d"
},
{
"url": "https://git.kernel.org/stable/c/a4f55260f7f7d4dc4d0ee55063dfb0c457b77991"
}
],
"title": "drm/vmwgfx: Validate vmw_surface_metadata::array_size",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68446",
"datePublished": "2026-08-12T00:07:37.385Z",
"dateReserved": "2026-07-30T09:28:09.395Z",
"dateUpdated": "2026-08-19T16:35:40.576Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68225 (GCVE-0-2026-68225)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-17 05:01
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: i2c: alvium: fix critical pointer access in alvium_ctrl_init
The current implementation of alvium_ctrl_init creates several controls in
function alvium_ctrl_init and uses the returned pointer without check. That
can cause write access over NULL-pointer for several controls. The reworked
code checks the pointers before adding flags.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/i2c/alvium-csi2.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "4bacfda44d36f165f6cb57bea408912886400ffa",
"status": "affected",
"version": "0a7af872915ee34668edf7e4018648a226d9e7f9",
"versionType": "git"
},
{
"lessThan": "7337c88205ed0ffc654f40266be0d3c3eb15fb29",
"status": "affected",
"version": "0a7af872915ee34668edf7e4018648a226d9e7f9",
"versionType": "git"
},
{
"lessThan": "eb2f934646aefb06314cecd1deb020794829b207",
"status": "affected",
"version": "0a7af872915ee34668edf7e4018648a226d9e7f9",
"versionType": "git"
},
{
"lessThan": "4f6f28ff24709710c08557c127b3e4c3fb1b4159",
"status": "affected",
"version": "0a7af872915ee34668edf7e4018648a226d9e7f9",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/i2c/alvium-csi2.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.8"
},
{
"lessThan": "6.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: i2c: alvium: fix critical pointer access in alvium_ctrl_init\n\nThe current implementation of alvium_ctrl_init creates several controls in\nfunction alvium_ctrl_init and uses the returned pointer without check. That\ncan cause write access over NULL-pointer for several controls. The reworked\ncode checks the pointers before adding flags."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:01:13.016Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/4bacfda44d36f165f6cb57bea408912886400ffa"
},
{
"url": "https://git.kernel.org/stable/c/7337c88205ed0ffc654f40266be0d3c3eb15fb29"
},
{
"url": "https://git.kernel.org/stable/c/eb2f934646aefb06314cecd1deb020794829b207"
},
{
"url": "https://git.kernel.org/stable/c/4f6f28ff24709710c08557c127b3e4c3fb1b4159"
}
],
"title": "media: i2c: alvium: fix critical pointer access in alvium_ctrl_init",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68225",
"datePublished": "2026-08-10T12:00:47.085Z",
"dateReserved": "2026-07-30T09:28:09.375Z",
"dateUpdated": "2026-08-17T05:01:13.016Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72023 (GCVE-0-2026-72023)
Vulnerability from cvelistv5
Published
2026-08-15 05:51
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
octeontx2-pf: fix SQB pointer leak on init failure
otx2_init_hw_resources() initializes SQ aura and pool resources before
several later setup steps. On failure, err_free_sq_ptrs only frees SQB
pages, leaving the per-SQ sqb_ptrs arrays behind.
Use otx2_free_sq_res() for the SQ unwind path and let it free sqb_ptrs
even when sq->sqe has not been allocated yet.
The bug was first flagged by an experimental analysis tool we are
developing for kernel memory-management bugs while analyzing
v6.13-rc1. The tool is still under development and is not yet publicly
available. Manual inspection confirms that the bug is still
present in v7.1.1.
An x86_64 allyesconfig build showed no new warnings. As we do not have an
OcteonTX2 PF device and the corresponding AF mailbox setup to test with,
no runtime testing was able to be performed.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: caa2da34fd25a37e9fd43343b6966fb9d730a6d5 Version: caa2da34fd25a37e9fd43343b6966fb9d730a6d5 Version: caa2da34fd25a37e9fd43343b6966fb9d730a6d5 Version: caa2da34fd25a37e9fd43343b6966fb9d730a6d5 Version: caa2da34fd25a37e9fd43343b6966fb9d730a6d5 Version: caa2da34fd25a37e9fd43343b6966fb9d730a6d5 Version: caa2da34fd25a37e9fd43343b6966fb9d730a6d5 Version: caa2da34fd25a37e9fd43343b6966fb9d730a6d5 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/marvell/octeontx2/nic/otx2_pf.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "fca9c22633169a6c5d429a32e439121b6419e2be",
"status": "affected",
"version": "caa2da34fd25a37e9fd43343b6966fb9d730a6d5",
"versionType": "git"
},
{
"lessThan": "42c2836f10ac0427dac9e9a923d6ee2189dec544",
"status": "affected",
"version": "caa2da34fd25a37e9fd43343b6966fb9d730a6d5",
"versionType": "git"
},
{
"lessThan": "2cac2eac935ed7e0a9203204e036a1f6090ebc3d",
"status": "affected",
"version": "caa2da34fd25a37e9fd43343b6966fb9d730a6d5",
"versionType": "git"
},
{
"lessThan": "148d7ec0a3a98839c320e6cdd112e2e88bfb091b",
"status": "affected",
"version": "caa2da34fd25a37e9fd43343b6966fb9d730a6d5",
"versionType": "git"
},
{
"lessThan": "5e023fe2569e630ba23b5558ebe4bf4837af4d16",
"status": "affected",
"version": "caa2da34fd25a37e9fd43343b6966fb9d730a6d5",
"versionType": "git"
},
{
"lessThan": "5df30f05db96552903680a17f858d250dfd9e86e",
"status": "affected",
"version": "caa2da34fd25a37e9fd43343b6966fb9d730a6d5",
"versionType": "git"
},
{
"lessThan": "23d917acd9c9a9fd999688ec3fdde7aa58ab8a14",
"status": "affected",
"version": "caa2da34fd25a37e9fd43343b6966fb9d730a6d5",
"versionType": "git"
},
{
"lessThan": "62e7df6d042aeebd5efb581074e28865c04477be",
"status": "affected",
"version": "caa2da34fd25a37e9fd43343b6966fb9d730a6d5",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/marvell/octeontx2/nic/otx2_pf.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.6"
},
{
"lessThan": "5.6",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nocteontx2-pf: fix SQB pointer leak on init failure\n\notx2_init_hw_resources() initializes SQ aura and pool resources before\nseveral later setup steps. On failure, err_free_sq_ptrs only frees SQB\npages, leaving the per-SQ sqb_ptrs arrays behind.\n\nUse otx2_free_sq_res() for the SQ unwind path and let it free sqb_ptrs\neven when sq-\u003esqe has not been allocated yet.\n\nThe bug was first flagged by an experimental analysis tool we are\ndeveloping for kernel memory-management bugs while analyzing\nv6.13-rc1. The tool is still under development and is not yet publicly\navailable. Manual inspection confirms that the bug is still\npresent in v7.1.1.\n\nAn x86_64 allyesconfig build showed no new warnings. As we do not have an\nOcteonTX2 PF device and the corresponding AF mailbox setup to test with,\nno runtime testing was able to be performed."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:27.683Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/fca9c22633169a6c5d429a32e439121b6419e2be"
},
{
"url": "https://git.kernel.org/stable/c/42c2836f10ac0427dac9e9a923d6ee2189dec544"
},
{
"url": "https://git.kernel.org/stable/c/2cac2eac935ed7e0a9203204e036a1f6090ebc3d"
},
{
"url": "https://git.kernel.org/stable/c/148d7ec0a3a98839c320e6cdd112e2e88bfb091b"
},
{
"url": "https://git.kernel.org/stable/c/5e023fe2569e630ba23b5558ebe4bf4837af4d16"
},
{
"url": "https://git.kernel.org/stable/c/5df30f05db96552903680a17f858d250dfd9e86e"
},
{
"url": "https://git.kernel.org/stable/c/23d917acd9c9a9fd999688ec3fdde7aa58ab8a14"
},
{
"url": "https://git.kernel.org/stable/c/62e7df6d042aeebd5efb581074e28865c04477be"
}
],
"title": "octeontx2-pf: fix SQB pointer leak on init failure",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72023",
"datePublished": "2026-08-15T05:51:48.629Z",
"dateReserved": "2026-08-09T03:40:39.900Z",
"dateUpdated": "2026-08-23T12:46:27.683Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68201 (GCVE-0-2026-68201)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-17 05:00
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ALSA: timer: drain a slave's callback before its master detaches it
snd_timer_close_locked() drains the closing instance's own in-flight
callback (IFLG_CALLBACK) before freeing it, but not its slaves'. When a
master instance is closed, remove_slave_links() clears each slave's
->timer; the slave's own close then reads timer == NULL and takes the
branch that skips the drain entirely (snd_timer_stop_slave() also no-ops
on a NULL timer). So a slave whose callback is still running when the
master is closed is freed underneath the live callback, leading to
use-after-free.
Drain the slaves too before remove_slave_links() severs them.
snd_timer_stop() has already taken this instance off the active list, so
no new slave callback can be queued. Take the slaves off the ack list so
a pending one can't fire either, then wait for any that is already in
flight.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"sound/core/timer.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "cd461bcfcdf8d6b6b5365941c1d3859f8bc77aa0",
"status": "affected",
"version": "37745918e0e7575bc40f38da93a99b9fa6406224",
"versionType": "git"
},
{
"lessThan": "426c0ff1c433d6030610ad4f9375746dfe931caa",
"status": "affected",
"version": "37745918e0e7575bc40f38da93a99b9fa6406224",
"versionType": "git"
},
{
"lessThan": "2b298997786876b225cff2446e11a0fa6f602f6d",
"status": "affected",
"version": "37745918e0e7575bc40f38da93a99b9fa6406224",
"versionType": "git"
},
{
"lessThan": "bdefe1346a8e6b8dc8593406dc2617e985fcbcab",
"status": "affected",
"version": "37745918e0e7575bc40f38da93a99b9fa6406224",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"sound/core/timer.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.12"
},
{
"lessThan": "6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: timer: drain a slave\u0027s callback before its master detaches it\n\nsnd_timer_close_locked() drains the closing instance\u0027s own in-flight\ncallback (IFLG_CALLBACK) before freeing it, but not its slaves\u0027. When a\nmaster instance is closed, remove_slave_links() clears each slave\u0027s\n-\u003etimer; the slave\u0027s own close then reads timer == NULL and takes the\nbranch that skips the drain entirely (snd_timer_stop_slave() also no-ops\non a NULL timer). So a slave whose callback is still running when the\nmaster is closed is freed underneath the live callback, leading to\nuse-after-free.\n\nDrain the slaves too before remove_slave_links() severs them.\nsnd_timer_stop() has already taken this instance off the active list, so\nno new slave callback can be queued. Take the slaves off the ack list so\na pending one can\u0027t fire either, then wait for any that is already in\nflight."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached only through the local ALSA timer character device /dev/snd/timer (open, SNDRV_TIMER_IOCTL_SELECT/START/CREATE/TRIGGER, close) \u2014 no remote or network path exists into sound/core/timer.c.\nAC:L - The attacker owns both sides of the race: it creates the master/slave instances, drives callback delivery itself via the userspace-driven timer\u0027s SNDRV_TIMER_IOCTL_TRIGGER ioctl, and chooses the close ordering, and can widen the window with many slaves and queued events, so the UAF is reliably reproducible.\nPR:L - No capable() or CAP_* check exists on any part of the path; any local user with access to /dev/snd/timer (normal for desktop/Android audio-group users and sandboxed apps) can create utimers and open master and slave instances.\nUI:N - A single unprivileged process performs all steps \u2014 open, select, start, trigger and close \u2014 with no action from any other user or victim process required.\nS:U - The corruption is confined to the kernel\u0027s own heap and the ALSA timer subsystem; no VM, IOMMU or other security-authority boundary is crossed.\nC:H - The freed snd_timer_instance/snd_timer_user objects can be reclaimed by attacker-sprayed data, and the still-running callback reads and later exposes freed-slab contents through the timer read queue, enabling disclosure of arbitrary kernel heap data.\nI:H - The in-flight callback writes attacker-influenced tread records into the already-freed tqueue and performs list and waitqueue updates on freed memory, giving a controllable use-after-free write usable for heap corruption and control-flow hijack.\nA:H - The use-after-free corrupts slab memory and list pointers, readily producing an oops, list_del corruption BUG or panic that takes down the whole system."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:00:44.787Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/cd461bcfcdf8d6b6b5365941c1d3859f8bc77aa0"
},
{
"url": "https://git.kernel.org/stable/c/426c0ff1c433d6030610ad4f9375746dfe931caa"
},
{
"url": "https://git.kernel.org/stable/c/2b298997786876b225cff2446e11a0fa6f602f6d"
},
{
"url": "https://git.kernel.org/stable/c/bdefe1346a8e6b8dc8593406dc2617e985fcbcab"
}
],
"title": "ALSA: timer: drain a slave\u0027s callback before its master detaches it",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68201",
"datePublished": "2026-08-10T12:00:20.280Z",
"dateReserved": "2026-07-30T09:28:09.374Z",
"dateUpdated": "2026-08-17T05:00:44.787Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68244 (GCVE-0-2026-68244)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-19 16:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/i915/gem: Do not leak siblings[] on proto context error
After a successful BALANCE/PARALLEL_SUBMIT extension on context
creation, error during processing of next user extension leaks
the siblings[] array. Fix that.
Discovered using AI-assisted static analysis confirmed by
Intel Product Security.
(cherry picked from commit aa65e0a4b51b3b54b53e4142aaa2d997aa1061ff)
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d4433c7600f794623d6802395542cf4ca4f1b1f9 Version: d4433c7600f794623d6802395542cf4ca4f1b1f9 Version: d4433c7600f794623d6802395542cf4ca4f1b1f9 Version: d4433c7600f794623d6802395542cf4ca4f1b1f9 Version: d4433c7600f794623d6802395542cf4ca4f1b1f9 Version: d4433c7600f794623d6802395542cf4ca4f1b1f9 Version: d4433c7600f794623d6802395542cf4ca4f1b1f9 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/i915/gem/i915_gem_context.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "60b7d701ffae0c3a69e838f984cc80d8ca929f5d",
"status": "affected",
"version": "d4433c7600f794623d6802395542cf4ca4f1b1f9",
"versionType": "git"
},
{
"lessThan": "e600672f11a1d9215f5432ca58f0b9823917a292",
"status": "affected",
"version": "d4433c7600f794623d6802395542cf4ca4f1b1f9",
"versionType": "git"
},
{
"lessThan": "f014702fbd48d06a3d7a06e4bb4075d406376cf0",
"status": "affected",
"version": "d4433c7600f794623d6802395542cf4ca4f1b1f9",
"versionType": "git"
},
{
"lessThan": "8431a4d7ff95c7f9c6fb1dbbbc9cdadf29d4f6d5",
"status": "affected",
"version": "d4433c7600f794623d6802395542cf4ca4f1b1f9",
"versionType": "git"
},
{
"lessThan": "37951ce1567ccf8c86c7a1b8fb7d55a32c821b87",
"status": "affected",
"version": "d4433c7600f794623d6802395542cf4ca4f1b1f9",
"versionType": "git"
},
{
"lessThan": "6cdbef8f60f313684e641628d64aa85960080d3f",
"status": "affected",
"version": "d4433c7600f794623d6802395542cf4ca4f1b1f9",
"versionType": "git"
},
{
"lessThan": "eed3de2acf6aa5154d49098b026710b646db67ee",
"status": "affected",
"version": "d4433c7600f794623d6802395542cf4ca4f1b1f9",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/i915/gem/i915_gem_context.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.15"
},
{
"lessThan": "5.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/i915/gem: Do not leak siblings[] on proto context error\n\nAfter a successful BALANCE/PARALLEL_SUBMIT extension on context\ncreation, error during processing of next user extension leaks\nthe siblings[] array. Fix that.\n\nDiscovered using AI-assisted static analysis confirmed by\nIntel Product Security.\n\n(cherry picked from commit aa65e0a4b51b3b54b53e4142aaa2d997aa1061ff)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:32:11.063Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/60b7d701ffae0c3a69e838f984cc80d8ca929f5d"
},
{
"url": "https://git.kernel.org/stable/c/e600672f11a1d9215f5432ca58f0b9823917a292"
},
{
"url": "https://git.kernel.org/stable/c/f014702fbd48d06a3d7a06e4bb4075d406376cf0"
},
{
"url": "https://git.kernel.org/stable/c/8431a4d7ff95c7f9c6fb1dbbbc9cdadf29d4f6d5"
},
{
"url": "https://git.kernel.org/stable/c/37951ce1567ccf8c86c7a1b8fb7d55a32c821b87"
},
{
"url": "https://git.kernel.org/stable/c/6cdbef8f60f313684e641628d64aa85960080d3f"
},
{
"url": "https://git.kernel.org/stable/c/eed3de2acf6aa5154d49098b026710b646db67ee"
}
],
"title": "drm/i915/gem: Do not leak siblings[] on proto context error",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68244",
"datePublished": "2026-08-10T12:01:10.469Z",
"dateReserved": "2026-07-30T09:28:09.377Z",
"dateUpdated": "2026-08-19T16:32:11.063Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68207 (GCVE-0-2026-68207)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: ti: vpe: unwind v4l2 device registration on probe error
If the vpe_top resource is missing, vpe_probe() returns -ENODEV after
v4l2_device_register() has succeeded. Probe failures do not call the
driver's remove callback, so the v4l2 device remains registered on that
error path.
Route that failure through the existing v4l2_device_unregister() unwind
label, matching the other errors after v4l2_device_register().
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 4d59c7d455853edca990848b1cb7c482b4628f32 Version: 4d59c7d455853edca990848b1cb7c482b4628f32 Version: 4d59c7d455853edca990848b1cb7c482b4628f32 Version: 4d59c7d455853edca990848b1cb7c482b4628f32 Version: 4d59c7d455853edca990848b1cb7c482b4628f32 Version: 4d59c7d455853edca990848b1cb7c482b4628f32 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/platform/ti/vpe/vpe.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "0f0a60c000876bcd808a70d602c758c2e64c77d8",
"status": "affected",
"version": "4d59c7d455853edca990848b1cb7c482b4628f32",
"versionType": "git"
},
{
"lessThan": "4ecf0cc0cf59032a89bcdf36fbbb03bff5455fd9",
"status": "affected",
"version": "4d59c7d455853edca990848b1cb7c482b4628f32",
"versionType": "git"
},
{
"lessThan": "7d383357905de975e1dbde639e5fa7477075d104",
"status": "affected",
"version": "4d59c7d455853edca990848b1cb7c482b4628f32",
"versionType": "git"
},
{
"lessThan": "7e6521dd747eca3cb3d4cd3ddcf20f266494f63d",
"status": "affected",
"version": "4d59c7d455853edca990848b1cb7c482b4628f32",
"versionType": "git"
},
{
"lessThan": "fcbbaf9cb9722a82f0221c56114037fc537f4ada",
"status": "affected",
"version": "4d59c7d455853edca990848b1cb7c482b4628f32",
"versionType": "git"
},
{
"lessThan": "e0f1c9a90ef665f2587c274a8fed59f2dfc575a6",
"status": "affected",
"version": "4d59c7d455853edca990848b1cb7c482b4628f32",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/platform/ti/vpe/vpe.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.5"
},
{
"lessThan": "5.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: ti: vpe: unwind v4l2 device registration on probe error\n\nIf the vpe_top resource is missing, vpe_probe() returns -ENODEV after\nv4l2_device_register() has succeeded. Probe failures do not call the\ndriver\u0027s remove callback, so the v4l2 device remains registered on that\nerror path.\n\nRoute that failure through the existing v4l2_device_unregister() unwind\nlabel, matching the other errors after v4l2_device_register()."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:29.282Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/0f0a60c000876bcd808a70d602c758c2e64c77d8"
},
{
"url": "https://git.kernel.org/stable/c/4ecf0cc0cf59032a89bcdf36fbbb03bff5455fd9"
},
{
"url": "https://git.kernel.org/stable/c/7d383357905de975e1dbde639e5fa7477075d104"
},
{
"url": "https://git.kernel.org/stable/c/7e6521dd747eca3cb3d4cd3ddcf20f266494f63d"
},
{
"url": "https://git.kernel.org/stable/c/fcbbaf9cb9722a82f0221c56114037fc537f4ada"
},
{
"url": "https://git.kernel.org/stable/c/e0f1c9a90ef665f2587c274a8fed59f2dfc575a6"
}
],
"title": "media: ti: vpe: unwind v4l2 device registration on probe error",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68207",
"datePublished": "2026-08-10T12:00:26.322Z",
"dateReserved": "2026-07-30T09:28:09.374Z",
"dateUpdated": "2026-08-19T16:31:29.282Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68340 (GCVE-0-2026-68340)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
hwmon: occ: validate poll response sensor blocks
The OCC poll response parser walks a counted list of sensor data blocks.
It used the static backing-array capacity as the parse boundary, but a
transport response makes only data_length bytes current and valid. A
truncated response can therefore make the parser consume a block header or
block extent outside the current response.
Use data_length as the parent boundary, prove the fixed poll header and
each current block header before reading them, and prove the complete block
before advancing. Keep parsed sensor metadata local until the complete
response has passed validation, then publish it. Propagate
malformed-response errors before publishing the OCC as active.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: aa195fe49b033db545ad986cdb2c431c37bea557 Version: aa195fe49b033db545ad986cdb2c431c37bea557 Version: aa195fe49b033db545ad986cdb2c431c37bea557 Version: aa195fe49b033db545ad986cdb2c431c37bea557 Version: aa195fe49b033db545ad986cdb2c431c37bea557 Version: aa195fe49b033db545ad986cdb2c431c37bea557 Version: aa195fe49b033db545ad986cdb2c431c37bea557 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/hwmon/occ/common.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "6e6c72c37433640514db325408bd6913ad28fe69",
"status": "affected",
"version": "aa195fe49b033db545ad986cdb2c431c37bea557",
"versionType": "git"
},
{
"lessThan": "1902e9572901d37901e3db1f3f6b0885f4e49a66",
"status": "affected",
"version": "aa195fe49b033db545ad986cdb2c431c37bea557",
"versionType": "git"
},
{
"lessThan": "112525534ab5cff482d35897ca4ca11fd3a76f46",
"status": "affected",
"version": "aa195fe49b033db545ad986cdb2c431c37bea557",
"versionType": "git"
},
{
"lessThan": "54cb78eceb4e286ccd5a5c01a4632157860d47f0",
"status": "affected",
"version": "aa195fe49b033db545ad986cdb2c431c37bea557",
"versionType": "git"
},
{
"lessThan": "538d862cc0dbd5c732fe26d5aad98eae039e6676",
"status": "affected",
"version": "aa195fe49b033db545ad986cdb2c431c37bea557",
"versionType": "git"
},
{
"lessThan": "b042e538e98b939fccfffc464e2c34c29f0e96ef",
"status": "affected",
"version": "aa195fe49b033db545ad986cdb2c431c37bea557",
"versionType": "git"
},
{
"lessThan": "70e76e700fc6c46afb4e17aec099a1ea089b4a22",
"status": "affected",
"version": "aa195fe49b033db545ad986cdb2c431c37bea557",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/hwmon/occ/common.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.0"
},
{
"lessThan": "5.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: occ: validate poll response sensor blocks\n\nThe OCC poll response parser walks a counted list of sensor data blocks.\nIt used the static backing-array capacity as the parse boundary, but a\ntransport response makes only data_length bytes current and valid. A\ntruncated response can therefore make the parser consume a block header or\nblock extent outside the current response.\n\nUse data_length as the parent boundary, prove the fixed poll header and\neach current block header before reading them, and prove the complete block\nbefore advancing. Keep parsed sensor metadata local until the complete\nresponse has passed validation, then publish it. Propagate\nmalformed-response errors before publishing the OCC as active."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.7,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The malformed poll response reaches the BMC kernel over the local FSI/SBE or I2C link to the attached POWER OCC (drivers/hwmon/occ/p9_sbe.c, p8_i2c.c); there is no network protocol involved, but no physical access is needed either since a bare-metal host-side attacker can drive OCC firmware in software.\nAC:L - The attacker fully controls the response contents and its data_length, so simply returning a truncated poll response with a large num_sensor_data_blocks deterministically drives the parser past the valid data. No race, memory-layout guess, or uncontrolled precondition is involved.\nPR:N - occ_setup() calls occ_active(occ, true) during driver probe unless ibm,no-poll-on-init is set, so the malformed response is parsed automatically at bind with no credentials on the affected BMC system; the OCC-side attacker holds no privileges in the victim kernel\u0027s authority.\nUI:N - Parsing happens automatically during driver probe, or from the management daemon\u0027s periodic occ_active write; no victim action such as mounting or opening a file is required.\nS:U - The out-of-bounds reads and corrupted sensor metadata are confined to the kernel that parses the response; no IOMMU, hypervisor, or sandbox boundary is crossed by the impact itself.\nC:H - Sensor metadata (data pointer, num_sensors, version) is taken from bytes outside the valid response, and consumers index it with fixed per-version struct sizes in occ_setup_sensor_attrs() and every occ_show_* handler, reading far past the devm-allocated occ object and exposing kernel heap contents through world-readable hwmon sysfs attributes.\nI:N - The parse path only reads; the unvalidated lengths yield out-of-bounds loads and bogus metadata, but no attacker-controlled data is written outside any object and no control-flow-hijack primitive is created.\nA:H - Out-of-bounds reads of up to a couple of kilobytes past the allocation can hit unmapped memory or trip KASAN/BUG and oops the kernel, and pre-fix the OCC was marked active with invalid sensor state, leaving the hwmon device in an inconsistent, unusable condition."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:40.900Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/6e6c72c37433640514db325408bd6913ad28fe69"
},
{
"url": "https://git.kernel.org/stable/c/1902e9572901d37901e3db1f3f6b0885f4e49a66"
},
{
"url": "https://git.kernel.org/stable/c/112525534ab5cff482d35897ca4ca11fd3a76f46"
},
{
"url": "https://git.kernel.org/stable/c/54cb78eceb4e286ccd5a5c01a4632157860d47f0"
},
{
"url": "https://git.kernel.org/stable/c/538d862cc0dbd5c732fe26d5aad98eae039e6676"
},
{
"url": "https://git.kernel.org/stable/c/b042e538e98b939fccfffc464e2c34c29f0e96ef"
},
{
"url": "https://git.kernel.org/stable/c/70e76e700fc6c46afb4e17aec099a1ea089b4a22"
}
],
"title": "hwmon: occ: validate poll response sensor blocks",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68340",
"datePublished": "2026-08-10T12:03:16.552Z",
"dateReserved": "2026-07-30T09:28:09.384Z",
"dateUpdated": "2026-08-19T16:33:40.900Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68226 (GCVE-0-2026-68226)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: cx23885: add ioremap return check and cleanup
Add a check for the return value of pci_ioremap_bar()
in cx23885_dev_setup().
If ioremap for BAR0 fails, release the already allocated
PCI memory region,
decrement the device count, and return -ENODEV.
This prevents a potential null pointer dereference and
ensures proper cleanup
on memory mapping failure.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d19770e5178a4bc49641711246360c25781d20a4 Version: d19770e5178a4bc49641711246360c25781d20a4 Version: d19770e5178a4bc49641711246360c25781d20a4 Version: d19770e5178a4bc49641711246360c25781d20a4 Version: d19770e5178a4bc49641711246360c25781d20a4 Version: d19770e5178a4bc49641711246360c25781d20a4 Version: d19770e5178a4bc49641711246360c25781d20a4 Version: d19770e5178a4bc49641711246360c25781d20a4 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/pci/cx23885/cx23885-core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "f58f4b571bd75c78bbf15441086ba0c2830c1aa5",
"status": "affected",
"version": "d19770e5178a4bc49641711246360c25781d20a4",
"versionType": "git"
},
{
"lessThan": "9052fec0bb84eace81ac7bad071266052870cdf3",
"status": "affected",
"version": "d19770e5178a4bc49641711246360c25781d20a4",
"versionType": "git"
},
{
"lessThan": "6a7636e3d5204fb18fdf1c3f909a3d9d9e24064c",
"status": "affected",
"version": "d19770e5178a4bc49641711246360c25781d20a4",
"versionType": "git"
},
{
"lessThan": "8fbdca4c99f68734e9b6c030973fb61a11bede15",
"status": "affected",
"version": "d19770e5178a4bc49641711246360c25781d20a4",
"versionType": "git"
},
{
"lessThan": "83540d86d717735b52a43e4ba1b784da5cc2310a",
"status": "affected",
"version": "d19770e5178a4bc49641711246360c25781d20a4",
"versionType": "git"
},
{
"lessThan": "c68c4ce72feb6fcccc843eb3baa7af60189ed567",
"status": "affected",
"version": "d19770e5178a4bc49641711246360c25781d20a4",
"versionType": "git"
},
{
"lessThan": "ff3c670a1de3a714f5644e37b9446fe7c3299fd3",
"status": "affected",
"version": "d19770e5178a4bc49641711246360c25781d20a4",
"versionType": "git"
},
{
"lessThan": "a0701e387b46e2481c05b47f1235b954bfc2af3e",
"status": "affected",
"version": "d19770e5178a4bc49641711246360c25781d20a4",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/pci/cx23885/cx23885-core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.24"
},
{
"lessThan": "2.6.24",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.24",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: cx23885: add ioremap return check and cleanup\n\nAdd a check for the return value of pci_ioremap_bar()\nin cx23885_dev_setup().\nIf ioremap for BAR0 fails, release the already allocated\nPCI memory region,\ndecrement the device count, and return -ENODEV.\n\nThis prevents a potential null pointer dereference and\nensures proper cleanup\non memory mapping failure."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:56.630Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/f58f4b571bd75c78bbf15441086ba0c2830c1aa5"
},
{
"url": "https://git.kernel.org/stable/c/9052fec0bb84eace81ac7bad071266052870cdf3"
},
{
"url": "https://git.kernel.org/stable/c/6a7636e3d5204fb18fdf1c3f909a3d9d9e24064c"
},
{
"url": "https://git.kernel.org/stable/c/8fbdca4c99f68734e9b6c030973fb61a11bede15"
},
{
"url": "https://git.kernel.org/stable/c/83540d86d717735b52a43e4ba1b784da5cc2310a"
},
{
"url": "https://git.kernel.org/stable/c/c68c4ce72feb6fcccc843eb3baa7af60189ed567"
},
{
"url": "https://git.kernel.org/stable/c/ff3c670a1de3a714f5644e37b9446fe7c3299fd3"
},
{
"url": "https://git.kernel.org/stable/c/a0701e387b46e2481c05b47f1235b954bfc2af3e"
}
],
"title": "media: cx23885: add ioremap return check and cleanup",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68226",
"datePublished": "2026-08-10T12:00:48.349Z",
"dateReserved": "2026-07-30T09:28:09.376Z",
"dateUpdated": "2026-08-19T16:31:56.630Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68353 (GCVE-0-2026-68353)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler
The firmware-controlled num_msg field (u8, 0-255) drives the loop in
ath6kl_wmi_tx_complete_event_rx() without validation against the buffer
length. This allows out-of-bounds reads of up to 1020 bytes past the
WMI event buffer when the firmware sends an inflated num_msg.
Add a check that the buffer is large enough to hold the fixed struct
and the num_msg variable-length entries.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/ath/ath6kl/wmi.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "5297299c3fa6133275db0be99d69cd759b6cbfe9",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "35196a07603f8c94a4943093bc26d5b5826285f8",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "0e0fc04af9b443c6b425f00fb604ff599bc80d1d",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "69ac7ba3a3df6654e7daa82674575a8c4a1a63ea",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "289edc3c71344b89e6522891147cfb8f61b088bb",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "eb636fbc443149b3501c3f97e26225ddcb314a0f",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "c38b0d5c661951b5dd082bdf31f8a57a0ce6e540",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "3a21c89215cc18f1a97c5e5bfd1da6d4f3d44495",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/ath/ath6kl/wmi.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.2"
},
{
"lessThan": "3.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler\n\nThe firmware-controlled num_msg field (u8, 0-255) drives the loop in\nath6kl_wmi_tx_complete_event_rx() without validation against the buffer\nlength. This allows out-of-bounds reads of up to 1020 bytes past the\nWMI event buffer when the firmware sends an inflated num_msg.\n\nAdd a check that the buffer is large enough to hold the fixed struct\nand the num_msg variable-length entries."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The vulnerable handler parses WMI control events delivered by the ath6kl AR600x wireless firmware over SDIO/USB; an attacker on the same wireless segment who subverts or influences the wireless device\u0027s firmware supplies the malformed event, matching the adjacent-network vector used for other ath driver event-parsing flaws.\nAC:L - Triggering requires only a WMI_TX_COMPLETE_EVENTID event whose payload is shorter than num_msg * 4 bytes; the loop bound is taken directly from the event with no validation, so the read happens deterministically every time.\nPR:N - The event is processed in the driver\u0027s asynchronous control-message receive path with no capability check, no syscall entry, and no authentication or association gate; the attacker needs no credentials on the target system.\nUI:N - The WMI event is handled automatically by the driver as soon as the interface is running; no victim action such as opening a file or issuing a command is needed.\nS:U - The out-of-bounds read stays within the kernel\u0027s own memory and security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - Up to 1020 bytes past the event buffer are read and the contents are emitted through ath6kl_dbg() into the kernel log on debug builds, disclosing adjacent kernel heap data well beyond a small bounded read.\nI:N - The loop only reads and prints the out-of-bounds entries; there is no write to kernel memory and no attacker-controlled pointer is dereferenced for modification.\nA:H - The read can walk past the end of the slab allocation into unmapped or redzoned memory, producing an oops or a KASAN panic on hardened/debug kernels and thus a full loss of availability."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:58.283Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/5297299c3fa6133275db0be99d69cd759b6cbfe9"
},
{
"url": "https://git.kernel.org/stable/c/35196a07603f8c94a4943093bc26d5b5826285f8"
},
{
"url": "https://git.kernel.org/stable/c/0e0fc04af9b443c6b425f00fb604ff599bc80d1d"
},
{
"url": "https://git.kernel.org/stable/c/69ac7ba3a3df6654e7daa82674575a8c4a1a63ea"
},
{
"url": "https://git.kernel.org/stable/c/289edc3c71344b89e6522891147cfb8f61b088bb"
},
{
"url": "https://git.kernel.org/stable/c/eb636fbc443149b3501c3f97e26225ddcb314a0f"
},
{
"url": "https://git.kernel.org/stable/c/c38b0d5c661951b5dd082bdf31f8a57a0ce6e540"
},
{
"url": "https://git.kernel.org/stable/c/3a21c89215cc18f1a97c5e5bfd1da6d4f3d44495"
}
],
"title": "wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68353",
"datePublished": "2026-08-10T12:03:30.330Z",
"dateReserved": "2026-07-30T09:28:09.385Z",
"dateUpdated": "2026-08-19T16:33:58.283Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68365 (GCVE-0-2026-68365)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
USB: serial: io_edgeport: cap received transmit credits
The interrupt-status packet reports transmit credits returned by the
device. edge_interrupt_callback() adds the 16-bit value to txCredits
without checking maxTxCredits.
edge_write() uses txCredits minus the software FIFO count as the amount
of data that fits. Since the FIFO is allocated with maxTxCredits bytes,
txCredits exceeding maxTxCredits can cause OOB write in ring buffer.
Cap accumulated credits at maxTxCredits. Conforming devices should never
hit the cap.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/serial/io_edgeport.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "d9dd87bc1d7e8476d29d68883542ec6198d385c6",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "5b39d3da15344b87ef54a0a04f65b52622747e99",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "63c4e55d0741cfaf00515e807cad9293445cd348",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "ee57992c053a6d395e98ced2d4c9cc3b42d8c27a",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "64b687f9694777754285d489abbefa3784bc78da",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "cbe00048b69d67c8a78293cb7681b4c9963b26c7",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "1e47d8228b8767c8ac722aedb388f70adeeda43d",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "faaddd811c5099f11a5f52e68a6b31a5898cda4f",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/usb/serial/io_edgeport.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: serial: io_edgeport: cap received transmit credits\n\nThe interrupt-status packet reports transmit credits returned by the\ndevice. edge_interrupt_callback() adds the 16-bit value to txCredits\nwithout checking maxTxCredits.\n\nedge_write() uses txCredits minus the software FIFO count as the amount\nof data that fits. Since the FIFO is allocated with maxTxCredits bytes,\ntxCredits exceeding maxTxCredits can cause OOB write in ring buffer.\n\nCap accumulated credits at maxTxCredits. Conforming devices should never\nhit the cap."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:21.018Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/d9dd87bc1d7e8476d29d68883542ec6198d385c6"
},
{
"url": "https://git.kernel.org/stable/c/5b39d3da15344b87ef54a0a04f65b52622747e99"
},
{
"url": "https://git.kernel.org/stable/c/63c4e55d0741cfaf00515e807cad9293445cd348"
},
{
"url": "https://git.kernel.org/stable/c/ee57992c053a6d395e98ced2d4c9cc3b42d8c27a"
},
{
"url": "https://git.kernel.org/stable/c/64b687f9694777754285d489abbefa3784bc78da"
},
{
"url": "https://git.kernel.org/stable/c/cbe00048b69d67c8a78293cb7681b4c9963b26c7"
},
{
"url": "https://git.kernel.org/stable/c/1e47d8228b8767c8ac722aedb388f70adeeda43d"
},
{
"url": "https://git.kernel.org/stable/c/faaddd811c5099f11a5f52e68a6b31a5898cda4f"
}
],
"title": "USB: serial: io_edgeport: cap received transmit credits",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68365",
"datePublished": "2026-08-10T12:03:42.358Z",
"dateReserved": "2026-07-30T09:28:09.385Z",
"dateUpdated": "2026-08-19T16:34:21.018Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68450 (GCVE-0-2026-68450)
Vulnerability from cvelistv5
Published
2026-08-12 00:51
Modified
2026-08-19 16:35
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
btrfs: free mapping node on duplicate reloc root insert
__add_reloc_root() allocates a mapping_node before inserting it into
rc->reloc_root_tree. If rb_simple_insert() finds an existing entry, it
returns the existing rb_node and leaves the newly allocated node unlinked.
The error path then returns -EEXIST without freeing the new node. Since
the node was never inserted into reloc_root_tree, the later cleanup in
put_reloc_control() cannot find it either.
Free the newly allocated node before returning -EEXIST.
The callers currently assert that -EEXIST should not happen, so this is a
defensive cleanup for an unexpected duplicate insert path. If the path is
ever reached, the local allocation should still be released.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 57a304cfd43b2b4a5b44b8f5dc026abb34183068 Version: 57a304cfd43b2b4a5b44b8f5dc026abb34183068 Version: 57a304cfd43b2b4a5b44b8f5dc026abb34183068 Version: 57a304cfd43b2b4a5b44b8f5dc026abb34183068 Version: 57a304cfd43b2b4a5b44b8f5dc026abb34183068 Version: 57a304cfd43b2b4a5b44b8f5dc026abb34183068 Version: 57a304cfd43b2b4a5b44b8f5dc026abb34183068 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/btrfs/relocation.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "29d9746812d8b7c37d594f484e994fd552c3ec33",
"status": "affected",
"version": "57a304cfd43b2b4a5b44b8f5dc026abb34183068",
"versionType": "git"
},
{
"lessThan": "b7c5b8e1d5f0779dfbabc3068b7ac0f12e53b3a8",
"status": "affected",
"version": "57a304cfd43b2b4a5b44b8f5dc026abb34183068",
"versionType": "git"
},
{
"lessThan": "92bedc0455552b42ada1a1f42b0e3a8593cdfccc",
"status": "affected",
"version": "57a304cfd43b2b4a5b44b8f5dc026abb34183068",
"versionType": "git"
},
{
"lessThan": "14a8be9428435ee17f17fae7991215c246b7fd43",
"status": "affected",
"version": "57a304cfd43b2b4a5b44b8f5dc026abb34183068",
"versionType": "git"
},
{
"lessThan": "797dc567146c7e3c4f8d9680e4fbc76e0a6d9151",
"status": "affected",
"version": "57a304cfd43b2b4a5b44b8f5dc026abb34183068",
"versionType": "git"
},
{
"lessThan": "ae0629ff9ccb836416ada129f4edc7efea6eaaad",
"status": "affected",
"version": "57a304cfd43b2b4a5b44b8f5dc026abb34183068",
"versionType": "git"
},
{
"lessThan": "6a8269b6459ed870a8156c106a0f597383907872",
"status": "affected",
"version": "57a304cfd43b2b4a5b44b8f5dc026abb34183068",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/btrfs/relocation.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.13"
},
{
"lessThan": "5.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: free mapping node on duplicate reloc root insert\n\n__add_reloc_root() allocates a mapping_node before inserting it into\nrc-\u003ereloc_root_tree. If rb_simple_insert() finds an existing entry, it\nreturns the existing rb_node and leaves the newly allocated node unlinked.\n\nThe error path then returns -EEXIST without freeing the new node. Since\nthe node was never inserted into reloc_root_tree, the later cleanup in\nput_reloc_control() cannot find it either.\n\nFree the newly allocated node before returning -EEXIST.\n\nThe callers currently assert that -EEXIST should not happen, so this is a\ndefensive cleanup for an unexpected duplicate insert path. If the path is\never reached, the local allocation should still be released."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:35:45.490Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/29d9746812d8b7c37d594f484e994fd552c3ec33"
},
{
"url": "https://git.kernel.org/stable/c/b7c5b8e1d5f0779dfbabc3068b7ac0f12e53b3a8"
},
{
"url": "https://git.kernel.org/stable/c/92bedc0455552b42ada1a1f42b0e3a8593cdfccc"
},
{
"url": "https://git.kernel.org/stable/c/14a8be9428435ee17f17fae7991215c246b7fd43"
},
{
"url": "https://git.kernel.org/stable/c/797dc567146c7e3c4f8d9680e4fbc76e0a6d9151"
},
{
"url": "https://git.kernel.org/stable/c/ae0629ff9ccb836416ada129f4edc7efea6eaaad"
},
{
"url": "https://git.kernel.org/stable/c/6a8269b6459ed870a8156c106a0f597383907872"
}
],
"title": "btrfs: free mapping node on duplicate reloc root insert",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68450",
"datePublished": "2026-08-12T00:51:48.970Z",
"dateReserved": "2026-07-30T09:28:09.395Z",
"dateUpdated": "2026-08-19T16:35:45.490Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68219 (GCVE-0-2026-68219)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-17 05:01
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: nxp: imx8-isi: Fix potential out-of-bounds issues
The maximum downscaling factor supported by ISI can be up to 16. Add
minimum value constraint before applying the setting to hardware.
Otherwise, the process will not respond even when Ctrl+C is executed.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/platform/nxp/imx8-isi/imx8-isi-core.h",
"drivers/media/platform/nxp/imx8-isi/imx8-isi-m2m.c",
"drivers/media/platform/nxp/imx8-isi/imx8-isi-pipe.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "690cdda752f3dc6b7a8b2d4a243e0207b66a1f37",
"status": "affected",
"version": "cf21f328fcafacf4f96e7a30ef9dceede1076378",
"versionType": "git"
},
{
"lessThan": "ba7e1b06cbdad3b7c3314390cca22aff42f655d4",
"status": "affected",
"version": "cf21f328fcafacf4f96e7a30ef9dceede1076378",
"versionType": "git"
},
{
"lessThan": "28ae75dba701d7aa69a36802c398582933d3e0e6",
"status": "affected",
"version": "cf21f328fcafacf4f96e7a30ef9dceede1076378",
"versionType": "git"
},
{
"lessThan": "75cdfaa7c908ca06d564170da9c80fb579f149a5",
"status": "affected",
"version": "cf21f328fcafacf4f96e7a30ef9dceede1076378",
"versionType": "git"
},
{
"lessThan": "57a7ec5c9f38ce6c4d6209c4b75c8e57e1fea6cf",
"status": "affected",
"version": "cf21f328fcafacf4f96e7a30ef9dceede1076378",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/platform/nxp/imx8-isi/imx8-isi-core.h",
"drivers/media/platform/nxp/imx8-isi/imx8-isi-m2m.c",
"drivers/media/platform/nxp/imx8-isi/imx8-isi-pipe.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.4"
},
{
"lessThan": "6.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: nxp: imx8-isi: Fix potential out-of-bounds issues\n\nThe maximum downscaling factor supported by ISI can be up to 16. Add\nminimum value constraint before applying the setting to hardware.\nOtherwise, the process will not respond even when Ctrl+C is executed."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerability is reached exclusively through V4L2 ioctls (VIDIOC_S_FMT on the /dev/videoX M2M node, or VIDIOC_SUBDEV_S_SELECTION on the ISI pipe subdev), which require local access to the device node. There is no remote or adjacent-network path into the imx8-isi driver.\nAC:L - Exploitation is a deterministic ioctl sequence: set a large OUTPUT format, set a 1x1 CAPTURE format (accepted because the bound was only min() against the source size and MXC_ISI_MIN_WIDTH/HEIGHT = 1), queue buffers and stream. No race, timing window, or uncontrollable memory-layout condition is involved.\nPR:L - The attacker only needs to open the ISI video device node; no capability check exists anywhere along the path from the ioctl handler to mxc_isi_channel_set_scaling(). On the i.MX8 embedded, automotive and vision devices where this driver runs, /dev/video* is routinely accessible to ordinary unprivileged applications via the video/camera group.\nUI:N - The attacking process performs the entire sequence itself \u2014 open, S_FMT, REQBUFS, QBUF, STREAMON \u2014 with no victim action, no separate privileged process, and no administrator step required.\nS:U - The corruption and the hang stay within the kernel of the same machine; the ISI DMA write targets kernel memory adjacent to the video buffer and does not cross a VM, hypervisor or IOMMU security boundary.\nC:H - The scaler saturates at a 16x factor while the destination buffer and CHNL_OUT_BUF_PITCH are sized from the far smaller requested format, so the ISI DMA engine overruns the video buffer into adjacent kernel memory; such heap corruption in DMA-able memory is leverageable to disclose kernel memory contents, and stale buffer content is returned to userspace.\nI:H - The hardware writes an image much larger than the allocated destination buffer, producing an out-of-bounds DMA write whose contents are the attacker\u0027s own input frame in M2M mode \u2014 an attacker-controlled overwrite of kernel memory following the buffer, sufficient for control-flow-relevant corruption.\nA:H - The fix commit states the transaction never completes and \"the process will not respond even when Ctrl+C is executed\", leaving an unkillable task and a wedged ISI channel that denies the imaging pipeline to all users; the accompanying out-of-bounds DMA write can additionally panic the kernel."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:01:05.813Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/690cdda752f3dc6b7a8b2d4a243e0207b66a1f37"
},
{
"url": "https://git.kernel.org/stable/c/ba7e1b06cbdad3b7c3314390cca22aff42f655d4"
},
{
"url": "https://git.kernel.org/stable/c/28ae75dba701d7aa69a36802c398582933d3e0e6"
},
{
"url": "https://git.kernel.org/stable/c/75cdfaa7c908ca06d564170da9c80fb579f149a5"
},
{
"url": "https://git.kernel.org/stable/c/57a7ec5c9f38ce6c4d6209c4b75c8e57e1fea6cf"
}
],
"title": "media: nxp: imx8-isi: Fix potential out-of-bounds issues",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68219",
"datePublished": "2026-08-10T12:00:39.405Z",
"dateReserved": "2026-07-30T09:28:09.375Z",
"dateUpdated": "2026-08-17T05:01:05.813Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72065 (GCVE-0-2026-72065)
Vulnerability from cvelistv5
Published
2026-08-15 05:52
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: mana: Validate the packet length reported by the NIC
Validate the packet length reported in the RX CQE before passing it
to skb processing. The CQE is supplied by the NIC device and should
not be blindly trusted.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f Version: ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f Version: ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f Version: ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f Version: ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f Version: ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f Version: ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/microsoft/mana/mana_en.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a631f82f89c76084ad5b2b9c043d3b391ffa56d8",
"status": "affected",
"version": "ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f",
"versionType": "git"
},
{
"lessThan": "d2568e64d01f480200063fadd67d6938f676c66f",
"status": "affected",
"version": "ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f",
"versionType": "git"
},
{
"lessThan": "2e276b14b6d378372bf0152df89286cbe7632fb0",
"status": "affected",
"version": "ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f",
"versionType": "git"
},
{
"lessThan": "6080189291d958604dcefe513a13900835ac982f",
"status": "affected",
"version": "ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f",
"versionType": "git"
},
{
"lessThan": "6d13eaa13341a8f80aaf86f78591e1b1d393711d",
"status": "affected",
"version": "ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f",
"versionType": "git"
},
{
"lessThan": "282c5214ca4eb3799158c76782646e86d2945d1b",
"status": "affected",
"version": "ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f",
"versionType": "git"
},
{
"lessThan": "2e2a83b4998af4384e677d3b2ac08565274279bf",
"status": "affected",
"version": "ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/microsoft/mana/mana_en.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.13"
},
{
"lessThan": "5.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mana: Validate the packet length reported by the NIC\n\nValidate the packet length reported in the RX CQE before passing it\nto skb processing. The CQE is supplied by the NIC device and should\nnot be blindly trusted."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - On internet-facing Azure VMs, remote packets drive MANA RX through IRQ/NAPI into mana_poll_rx_cq()/mana_process_rx_cqe(), where device-written RX CQE pkt_len is trusted and passed to skb/XDP processing without bounds checks against rxq-\u003edatasize.\nAC:L - The attacker can repeatedly send traffic to trigger RX completions until the MANA backend reports pkt_len above rxq-\u003edatasize; once that CQE arrives, mana_refill_rx_oob() and mana_rx_skb() misuse the length deterministically with no race or special memory layout.\nPR:N - The vulnerable path is the netdev NAPI receive handler before any socket or credential checks; an unauthenticated remote sender only needs packets routed to the VM\u0027s MANA interface, with no local account or capability on the victim.\nUI:N - RX CQEs are handled automatically from hardware interrupts and NAPI polling once the interface is up; no victim mount, ioctl, or other interactive action is required beyond normal network reception.\nS:U - Out-of-bounds access and crashes occur in the guest kernel processing MANA RX buffers; impact stays within that kernel security authority and does not by itself cross a VM/host or IOMMU boundary.\nC:H - Unchecked pkt_len is used in page_pool_dma_sync_for_cpu(), xdp_prepare_buff()/bpf_prog_run_xdp(), and skb_put()/eth_type_trans(), enabling reads well past the DMA-mapped rxq-\u003edatasize region and leaking adjacent kernel heap/page memory.\nI:H - Oversized pkt_len expands skb and XDP data bounds beyond the posted RX buffer, corrupting adjacent kernel memory and providing attacker-influenced metadata/control corruption primitives consistent with high integrity impact for OOB memory corruption.\nA:H - Processing an oversized pkt_len can kernel oops/panic from skb_put bounds failures or unmapped reads in softirq/NAPI context, and the remote attacker can retrigger the condition for sustained denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:40.741Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a631f82f89c76084ad5b2b9c043d3b391ffa56d8"
},
{
"url": "https://git.kernel.org/stable/c/d2568e64d01f480200063fadd67d6938f676c66f"
},
{
"url": "https://git.kernel.org/stable/c/2e276b14b6d378372bf0152df89286cbe7632fb0"
},
{
"url": "https://git.kernel.org/stable/c/6080189291d958604dcefe513a13900835ac982f"
},
{
"url": "https://git.kernel.org/stable/c/6d13eaa13341a8f80aaf86f78591e1b1d393711d"
},
{
"url": "https://git.kernel.org/stable/c/282c5214ca4eb3799158c76782646e86d2945d1b"
},
{
"url": "https://git.kernel.org/stable/c/2e2a83b4998af4384e677d3b2ac08565274279bf"
}
],
"title": "net: mana: Validate the packet length reported by the NIC",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72065",
"datePublished": "2026-08-15T05:52:18.801Z",
"dateReserved": "2026-08-09T03:40:39.903Z",
"dateUpdated": "2026-08-23T12:46:40.741Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68294 (GCVE-0-2026-68294)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-19 16:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: qrtr: restrict socket creation to the initial network namespace
QRTR keeps its entire port and node state in module-global variables
that are not partitioned per network namespace: qrtr_local_nid is a
single global node id (always 1) and qrtr_ports is a single global
xarray. qrtr_port_lookup() and qrtr_local_enqueue() operate on that
global state with no network-namespace check, and qrtr_create() places
no restriction on the namespace a socket is created in.
As a result an unprivileged process that creates an AF_QIPCRTR socket
in a separate network namespace, e.g. via
unshare(CLONE_NEWUSER | CLONE_NEWNET), can send QRTR datagrams -
including control-plane messages such as QRTR_TYPE_NEW_SERVER - to QRTR
sockets owned by another namespace, and vice versa. The receiving
socket sees such a message as coming from node id 1, indistinguishable
from a legitimate local client, breaking the isolation that network
namespaces are expected to provide.
QRTR is a transport to global hardware endpoints (the modem and other
remote processors) and has no per-namespace semantics; its in-kernel
name service already creates its socket in init_net only. Confine the
socket family to the initial network namespace, as other
non-namespace-aware socket families do (see llc_ui_create() and the
ieee802154 socket code).
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: bdabad3e363d825ddf9679dd431cca0b2c30f881 Version: bdabad3e363d825ddf9679dd431cca0b2c30f881 Version: bdabad3e363d825ddf9679dd431cca0b2c30f881 Version: bdabad3e363d825ddf9679dd431cca0b2c30f881 Version: bdabad3e363d825ddf9679dd431cca0b2c30f881 Version: bdabad3e363d825ddf9679dd431cca0b2c30f881 Version: bdabad3e363d825ddf9679dd431cca0b2c30f881 Version: bdabad3e363d825ddf9679dd431cca0b2c30f881 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/qrtr/af_qrtr.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "7814f6a3415cad38aa8d6dfc573df778260d66aa",
"status": "affected",
"version": "bdabad3e363d825ddf9679dd431cca0b2c30f881",
"versionType": "git"
},
{
"lessThan": "2d22b94a154ccb9755dddfff802fe3e2b1adbab5",
"status": "affected",
"version": "bdabad3e363d825ddf9679dd431cca0b2c30f881",
"versionType": "git"
},
{
"lessThan": "8d351fe0654a20c9f95a61b05d24ebe6d4be3fbb",
"status": "affected",
"version": "bdabad3e363d825ddf9679dd431cca0b2c30f881",
"versionType": "git"
},
{
"lessThan": "4b95e1f0d6e6342c427cb341ee18a894b146b789",
"status": "affected",
"version": "bdabad3e363d825ddf9679dd431cca0b2c30f881",
"versionType": "git"
},
{
"lessThan": "f488116df769bdaf89c93371350e49e12133e70f",
"status": "affected",
"version": "bdabad3e363d825ddf9679dd431cca0b2c30f881",
"versionType": "git"
},
{
"lessThan": "8150c48fb978e01689f94ed80148f8a7499ae571",
"status": "affected",
"version": "bdabad3e363d825ddf9679dd431cca0b2c30f881",
"versionType": "git"
},
{
"lessThan": "659b9b4f194bb56b9903cc95e786ef1d438baa7d",
"status": "affected",
"version": "bdabad3e363d825ddf9679dd431cca0b2c30f881",
"versionType": "git"
},
{
"lessThan": "3b536db8fb32da9e9c62f2bb45e2e319331f0426",
"status": "affected",
"version": "bdabad3e363d825ddf9679dd431cca0b2c30f881",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/qrtr/af_qrtr.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.7"
},
{
"lessThan": "4.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: qrtr: restrict socket creation to the initial network namespace\n\nQRTR keeps its entire port and node state in module-global variables\nthat are not partitioned per network namespace: qrtr_local_nid is a\nsingle global node id (always 1) and qrtr_ports is a single global\nxarray. qrtr_port_lookup() and qrtr_local_enqueue() operate on that\nglobal state with no network-namespace check, and qrtr_create() places\nno restriction on the namespace a socket is created in.\n\nAs a result an unprivileged process that creates an AF_QIPCRTR socket\nin a separate network namespace, e.g. via\nunshare(CLONE_NEWUSER | CLONE_NEWNET), can send QRTR datagrams -\nincluding control-plane messages such as QRTR_TYPE_NEW_SERVER - to QRTR\nsockets owned by another namespace, and vice versa. The receiving\nsocket sees such a message as coming from node id 1, indistinguishable\nfrom a legitimate local client, breaking the isolation that network\nnamespaces are expected to provide.\n\nQRTR is a transport to global hardware endpoints (the modem and other\nremote processors) and has no per-namespace semantics; its in-kernel\nname service already creates its socket in init_net only. Confine the\nsocket family to the initial network namespace, as other\nnon-namespace-aware socket families do (see llc_ui_create() and the\nieee802154 socket code)."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires local access to issue socket()/sendmsg() syscalls on an AF_QIPCRTR socket from within a network namespace on the target system; there is no remote packet path into qrtr_create().\nAC:L - The attack is fully deterministic: unshare(CLONE_NEWUSER|CLONE_NEWNET), create an AF_QIPCRTR socket (module autoloads via net-pf-42), and sendmsg() to node 1. No race, no memory-layout dependency, no victim state required.\nPR:L - Any unprivileged local user can create the required network namespace via unshare(CLONE_NEWUSER|CLONE_NEWNET), and a containerized process is already in one; the CAP_NET_ADMIN check at qrtr_port_assign() only gates low/control ports and is not needed for this attack.\nUI:N - The attacker performs all steps itself; no action by any other user or administrator is required to trigger the cross-namespace delivery.\nS:C - The flaw defeats the network-namespace confinement boundary itself: a process sandboxed in its own netns reaches the init_net global QRTR control plane, the in-kernel name service, and host-owned sockets, impacting resources under a different security authority than the attacker\u0027s container.\nC:H - By spoofing QRTR_TYPE_NEW_SERVER to the name service, a confined attacker registers itself as a well-known service so legitimate host clients direct their QMI traffic to it, and it can address modem/remote-processor endpoints directly, exposing sensitive telephony data it was isolated from.\nI:H - The attacker can inject arbitrary control-plane messages (NEW_SERVER, DEL_SERVER, BYE, DEL_CLIENT) that the receiver cannot distinguish from a legitimate node-1 client, corrupting the global service registry and allowing forged replies to host clients and commands to the modem.\nA:H - A single spoofed QRTR_TYPE_BYE makes ctrl_cmd_bye() delete every server registered on the local node and broadcast their removal, and the QRTR_NS_MAX_SERVERS/MAX_LOOKUPS limits can be exhausted, causing complete and repeatable loss of QRTR/modem IPC service for the whole system."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:32:43.629Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/7814f6a3415cad38aa8d6dfc573df778260d66aa"
},
{
"url": "https://git.kernel.org/stable/c/2d22b94a154ccb9755dddfff802fe3e2b1adbab5"
},
{
"url": "https://git.kernel.org/stable/c/8d351fe0654a20c9f95a61b05d24ebe6d4be3fbb"
},
{
"url": "https://git.kernel.org/stable/c/4b95e1f0d6e6342c427cb341ee18a894b146b789"
},
{
"url": "https://git.kernel.org/stable/c/f488116df769bdaf89c93371350e49e12133e70f"
},
{
"url": "https://git.kernel.org/stable/c/8150c48fb978e01689f94ed80148f8a7499ae571"
},
{
"url": "https://git.kernel.org/stable/c/659b9b4f194bb56b9903cc95e786ef1d438baa7d"
},
{
"url": "https://git.kernel.org/stable/c/3b536db8fb32da9e9c62f2bb45e2e319331f0426"
}
],
"title": "net: qrtr: restrict socket creation to the initial network namespace",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68294",
"datePublished": "2026-08-10T12:02:27.423Z",
"dateReserved": "2026-07-30T09:28:09.380Z",
"dateUpdated": "2026-08-19T16:32:43.629Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68192 (GCVE-0-2026-68192)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: brcmfmac: make release_scratchbuffers idempotent
brcmf_pcie_release_scratchbuffers() frees the shared.scratch and
shared.ringupd DMA buffers with dma_free_coherent() but does not clear
the pointers afterwards, unlike the sibling release_ringbuffers() which
NULLs commonrings/flowrings/idxbuf on release.
Both the bus_reset .reset callback (brcmf_pcie_reset) and
brcmf_pcie_remove() call release_scratchbuffers. When reset teardown
has run before removal, remove's own teardown would call
dma_free_coherent() a second time on the already-freed DMA allocation.
NULL the pointers after free, matching release_ringbuffers(), so a later
release observes that the allocation has already been released. This
patch makes repeated sequential release safe; the reset-work lifetime is
handled separately by the following patch.
This issue was found by an in-house static analysis tool.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 4684997d9eea29380000e062755aa6d368d789a3 Version: 4684997d9eea29380000e062755aa6d368d789a3 Version: 4684997d9eea29380000e062755aa6d368d789a3 Version: 4684997d9eea29380000e062755aa6d368d789a3 Version: 4684997d9eea29380000e062755aa6d368d789a3 Version: 4684997d9eea29380000e062755aa6d368d789a3 Version: 4684997d9eea29380000e062755aa6d368d789a3 Version: 4684997d9eea29380000e062755aa6d368d789a3 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/broadcom/brcm80211/brcmfmac/pcie.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "81c58a206d1deee01f4c29236d4154c0872f2a38",
"status": "affected",
"version": "4684997d9eea29380000e062755aa6d368d789a3",
"versionType": "git"
},
{
"lessThan": "382ee00b2d1e31869ae576a60d3fbe7a2153512f",
"status": "affected",
"version": "4684997d9eea29380000e062755aa6d368d789a3",
"versionType": "git"
},
{
"lessThan": "739b686aecdb14a6065300ea53401f043e51fd22",
"status": "affected",
"version": "4684997d9eea29380000e062755aa6d368d789a3",
"versionType": "git"
},
{
"lessThan": "b7d1d8cb1bdca56aecebacd2896615da0acc126a",
"status": "affected",
"version": "4684997d9eea29380000e062755aa6d368d789a3",
"versionType": "git"
},
{
"lessThan": "5a045c2f0fbf029873d2295178fa0785ade35af0",
"status": "affected",
"version": "4684997d9eea29380000e062755aa6d368d789a3",
"versionType": "git"
},
{
"lessThan": "044fca8f45ba9ab6ca526163155234cf88287ff5",
"status": "affected",
"version": "4684997d9eea29380000e062755aa6d368d789a3",
"versionType": "git"
},
{
"lessThan": "0ca80328df23f851c86866720d4977783c919ee6",
"status": "affected",
"version": "4684997d9eea29380000e062755aa6d368d789a3",
"versionType": "git"
},
{
"lessThan": "538c51e9d124cf656f2dd0c0394a8545efc7102d",
"status": "affected",
"version": "4684997d9eea29380000e062755aa6d368d789a3",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/broadcom/brcm80211/brcmfmac/pcie.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.2"
},
{
"lessThan": "5.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: brcmfmac: make release_scratchbuffers idempotent\n\nbrcmf_pcie_release_scratchbuffers() frees the shared.scratch and\nshared.ringupd DMA buffers with dma_free_coherent() but does not clear\nthe pointers afterwards, unlike the sibling release_ringbuffers() which\nNULLs commonrings/flowrings/idxbuf on release.\n\nBoth the bus_reset .reset callback (brcmf_pcie_reset) and\nbrcmf_pcie_remove() call release_scratchbuffers. When reset teardown\nhas run before removal, remove\u0027s own teardown would call\ndma_free_coherent() a second time on the already-freed DMA allocation.\n\nNULL the pointers after free, matching release_ringbuffers(), so a later\nrelease observes that the allocation has already been released. This\npatch makes repeated sequential release safe; the reset-work lifetime is\nhandled separately by the following patch.\n\nThis issue was found by an in-house static analysis tool."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The flaw is reached during brcmfmac PCIe bus reset/teardown after firmware halt; brcmf_fw_crashed() is invoked from the threaded IRQ handler on BRCMF_D2H_DEV_FWHALT mailbox data from the WiFi firmware, which an adjacent attacker can trigger with crafted over-the-air WiFi traffic to crash the dongle.\nAC:L - An attacker who induces firmware halt controls the reset sequence; brcmf_pcie_reset() always frees scratch buffers first and a later brcmf_pcie_remove() or failed brcmf_pcie_setup() teardown calls release_scratchbuffers() again on the same stale pointers, making the double-free deterministic without races they cannot influence.\nPR:N - No host privileges are required because crashing Broadcom FullMAC firmware via adjacent WiFi frames reaches brcmf_fw_crashed() without authentication, CAP_NET_ADMIN, or local access; the debugfs reset path is root-only but is not needed for the highest-impact attack scenario.\nUI:N - Exploitation only requires a victim with an active brcmfmac PCIe WiFi interface within RF range; no victim click, file open, driver unload, or other explicit user action is needed beyond normal always-on WiFi operation on laptops and embedded hosts using Broadcom PCIe FullMAC chips.\nS:U - The vulnerability corrupts kernel DMA/page-allocator state and enables host kernel privilege escalation within the same security authority; it does not cross VM, container, or IOMMU boundaries, so scope remains unchanged.\nC:H - Calling dma_free_coherent() twice on the same scratch and ringupd DMA allocations is a double-free of kernel coherent memory; this allocator-metadata corruption can be leveraged for arbitrary kernel memory disclosure even when full exploitation is not attempted, per kernel CVSS guidance for memory corruption.\nI:H - Double-free of dma_alloc_coherent buffers corrupts the kernel DMA/page heap freelist, enabling attacker-controlled reallocation and arbitrary kernel writes or control-flow hijack on systems with BRCMFMAC_PCIE enabled and a reachable Broadcom PCIe FullMAC wireless device.\nA:H - Re-freeing already released DMA-coherent allocations during driver reset or removal typically causes immediate kernel BUG/oops/panic or fatal allocator corruption during teardown, guaranteeing severe host availability loss on affected Broadcom PCIe WiFi systems even when code execution is not achieved."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:06.873Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/81c58a206d1deee01f4c29236d4154c0872f2a38"
},
{
"url": "https://git.kernel.org/stable/c/382ee00b2d1e31869ae576a60d3fbe7a2153512f"
},
{
"url": "https://git.kernel.org/stable/c/739b686aecdb14a6065300ea53401f043e51fd22"
},
{
"url": "https://git.kernel.org/stable/c/b7d1d8cb1bdca56aecebacd2896615da0acc126a"
},
{
"url": "https://git.kernel.org/stable/c/5a045c2f0fbf029873d2295178fa0785ade35af0"
},
{
"url": "https://git.kernel.org/stable/c/044fca8f45ba9ab6ca526163155234cf88287ff5"
},
{
"url": "https://git.kernel.org/stable/c/0ca80328df23f851c86866720d4977783c919ee6"
},
{
"url": "https://git.kernel.org/stable/c/538c51e9d124cf656f2dd0c0394a8545efc7102d"
}
],
"title": "wifi: brcmfmac: make release_scratchbuffers idempotent",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68192",
"datePublished": "2026-08-10T12:00:10.041Z",
"dateReserved": "2026-07-30T09:28:09.373Z",
"dateUpdated": "2026-08-19T16:31:06.873Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68351 (GCVE-0-2026-68351)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read
When the firmware sends a command response with a length mismatch,
carl9170_cmd_callback() logs the mismatch and calls carl9170_restart()
but then falls through to memcpy(ar->readbuf, buffer + 4, len - 4).
Since len comes from the firmware and can exceed ar->readlen, this
copies more data than the readbuf was allocated for.
Bound the memcpy to min(len - 4, ar->readlen) so that the response
is still completed -- avoiding repeated restarts from queued garbage --
while preventing an overread past the response buffer.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/ath/carl9170/rx.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "38e240996a6a78c94ab07d461fd66e361d55c3c4",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "2d05c321d27624c413c950278d2dc8e0f44a8950",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "525036b20ef01d814a7fcd0567d123992e4479fa",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "f74e34e66379e487a09009a4f2d42470051672bd",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "500c36649f270de05a56591fcc1aaaa36687958e",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "9aee949c68dc6dccbc54333537b109c53fe2079f",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "cb7a38810cf25738176dac32dec7a146b3f959cf",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "4cde55b2feff9504d1f993ab80e84e7ccb62791c",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/ath/carl9170/rx.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.37"
},
{
"lessThan": "2.6.37",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.37",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: carl9170: bound memcpy length in cmd callback to prevent OOB read\n\nWhen the firmware sends a command response with a length mismatch,\ncarl9170_cmd_callback() logs the mismatch and calls carl9170_restart()\nbut then falls through to memcpy(ar-\u003ereadbuf, buffer + 4, len - 4).\nSince len comes from the firmware and can exceed ar-\u003ereadlen, this\ncopies more data than the readbuf was allocated for.\n\nBound the memcpy to min(len - 4, ar-\u003ereadlen) so that the response\nis still completed -- avoiding repeated restarts from queued garbage --\nwhile preventing an overread past the response buffer."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:53.098Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/38e240996a6a78c94ab07d461fd66e361d55c3c4"
},
{
"url": "https://git.kernel.org/stable/c/2d05c321d27624c413c950278d2dc8e0f44a8950"
},
{
"url": "https://git.kernel.org/stable/c/525036b20ef01d814a7fcd0567d123992e4479fa"
},
{
"url": "https://git.kernel.org/stable/c/f74e34e66379e487a09009a4f2d42470051672bd"
},
{
"url": "https://git.kernel.org/stable/c/500c36649f270de05a56591fcc1aaaa36687958e"
},
{
"url": "https://git.kernel.org/stable/c/9aee949c68dc6dccbc54333537b109c53fe2079f"
},
{
"url": "https://git.kernel.org/stable/c/cb7a38810cf25738176dac32dec7a146b3f959cf"
},
{
"url": "https://git.kernel.org/stable/c/4cde55b2feff9504d1f993ab80e84e7ccb62791c"
}
],
"title": "wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68351",
"datePublished": "2026-08-10T12:03:28.312Z",
"dateReserved": "2026-07-30T09:28:09.384Z",
"dateUpdated": "2026-08-19T16:33:53.098Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68145 (GCVE-0-2026-68145)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-23 12:45
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
iomap: fix out-of-bounds bitmap_set() with zero-length range
ifs_set_range_dirty() and ifs_set_range_uptodate() compute last_blk
as (off + len - 1) >> i_blkbits. When off is 0 and len is 0, the
unsigned subtraction underflows to SIZE_MAX, producing a huge
last_blk and nr_blks value that causes bitmap_set() to write far
beyond the ifs->state allocation.
Regarding ifs_set_range_uptodate(), it is temporarily safe because len
cannot be passed in as 0. However, for ifs_set_range_dirty() this is
reachable from __iomap_write_end(): when copy_folio_from_iter_atomic()
returns 0 (e.g. user buffer fault) and the folio is already uptodate,
the guard at the top of __iomap_write_end() does not trigger because
!folio_test_uptodate() is false, and iomap_set_range_dirty() is called
with copied == 0.
Add a !len guard to both functions before the computation, so that a
zero-length range is a no-op.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/iomap/buffered-io.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "48829622212f6b8f49155889aecc818ba28ba680",
"status": "affected",
"version": "4ce02c67972211be488408c275c8fbf19faf29b3",
"versionType": "git"
},
{
"lessThan": "fb4fad9105c88b1d82f1b3c39e3b6abea8249af6",
"status": "affected",
"version": "4ce02c67972211be488408c275c8fbf19faf29b3",
"versionType": "git"
},
{
"lessThan": "7037e7bdcd26f46c080b8ce307dee5cb471c4b7c",
"status": "affected",
"version": "4ce02c67972211be488408c275c8fbf19faf29b3",
"versionType": "git"
},
{
"lessThan": "c5b6a48a8a716a7730e39af1cad083dc4ec955ce",
"status": "affected",
"version": "4ce02c67972211be488408c275c8fbf19faf29b3",
"versionType": "git"
},
{
"lessThan": "9c7d8f7c8994c790fca501dc45ce66e7356cbe05",
"status": "affected",
"version": "4ce02c67972211be488408c275c8fbf19faf29b3",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/iomap/buffered-io.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.6"
},
{
"lessThan": "6.6",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "6.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\niomap: fix out-of-bounds bitmap_set() with zero-length range\n\nifs_set_range_dirty() and ifs_set_range_uptodate() compute last_blk\nas (off + len - 1) \u003e\u003e i_blkbits. When off is 0 and len is 0, the\nunsigned subtraction underflows to SIZE_MAX, producing a huge\nlast_blk and nr_blks value that causes bitmap_set() to write far\nbeyond the ifs-\u003estate allocation.\n\nRegarding ifs_set_range_uptodate(), it is temporarily safe because len\ncannot be passed in as 0. However, for ifs_set_range_dirty() this is\nreachable from __iomap_write_end(): when copy_folio_from_iter_atomic()\nreturns 0 (e.g. user buffer fault) and the folio is already uptodate,\nthe guard at the top of __iomap_write_end() does not trigger because\n!folio_test_uptodate() is false, and iomap_set_range_dirty() is called\nwith copied == 0.\n\nAdd a !len guard to both functions before the computation, so that a\nzero-length range is a no-op."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached via the buffered write() path through iomap_file_buffered_write() when copy_folio_from_iter_atomic() returns 0; NFS/ksmbd server writes use kernel bvec iterators and do not hit this user-buffer fault path.\nAC:L - An attacker can reliably trigger copied==0 by racing munmap/remap against write() on an already-uptodate folio (TOCTOU after fault_in_iov_iter_readable), controlling both sides of the race on systems where folio size exceeds filesystem block size.\nPR:L - Only standard local write permission to a file on an iomap-backed filesystem (XFS, GFS2, FUSE writeback-cache, zonefs, NTFS) is required; no CAP_SYS_ADMIN or other elevated capability is needed beyond creating/triggering writes to attacker-writable files.\nUI:N - Exploitation requires only the attacker\u0027s own write operations to a writable file; no action by another user or administrator (such as mounting a filesystem or opening a file on the victim\u0027s behalf) is needed.\nS:U - Successful exploitation corrupts host kernel heap memory and enables local privilege escalation within the same kernel security domain; it does not inherently cross VM, container, or IOMMU boundaries.\nC:H - ifs_set_range_dirty() with len==0 underflows to SIZE_MAX and bitmap_set() writes far beyond the small kzalloc_flex(ifs-\u003estate) allocation, corrupting adjacent kmalloc objects in ways that can be leveraged for arbitrary kernel memory disclosure.\nI:H - The out-of-bounds bitmap_set() is a large heap overwrite primitive adjacent to the iomap_folio_state allocation, enabling control of kernel data structures and arbitrary code execution via standard heap exploitation techniques.\nA:H - The massive out-of-bounds write can immediately corrupt critical kernel heap metadata or adjacent objects, causing kernel oops/panic or unrecoverable memory corruption even before full exploitation is attempted."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:45:56.875Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/48829622212f6b8f49155889aecc818ba28ba680"
},
{
"url": "https://git.kernel.org/stable/c/fb4fad9105c88b1d82f1b3c39e3b6abea8249af6"
},
{
"url": "https://git.kernel.org/stable/c/7037e7bdcd26f46c080b8ce307dee5cb471c4b7c"
},
{
"url": "https://git.kernel.org/stable/c/c5b6a48a8a716a7730e39af1cad083dc4ec955ce"
},
{
"url": "https://git.kernel.org/stable/c/9c7d8f7c8994c790fca501dc45ce66e7356cbe05"
}
],
"title": "iomap: fix out-of-bounds bitmap_set() with zero-length range",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68145",
"datePublished": "2026-08-10T11:59:09.721Z",
"dateReserved": "2026-07-30T09:28:09.371Z",
"dateUpdated": "2026-08-23T12:45:56.875Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68158 (GCVE-0-2026-68158)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
libceph: Fix multiplication overflow in decode_new_up_state_weight()
If a message of type CEPH_MSG_OSD_MAP contains a (maliciously) corrupted
osdmap, out-of-bounds memory accesses may occur in
decode_new_up_state_weight(). This happens because the bounds check for
the new_state part is based on calculating its length depending on a len
value read from the incoming message. This calculation may overflow
leading to an incorrect bounds check. Subsequently, out-of-bounds reads
may occur when decoding this part.
This patch switches the multiplication to use check_mul_overflow() to
abort processing the osdmap if an overflow occurred. Therefore,
osdmaps/messages containing large values for len that result in a
multiplication overflow are treated as invalid.
[ idryomov: rename new_state_len -> new_state_item_size, formatting ]
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 930c532869774ebf8af9efe9484c597f896a7d46 Version: 930c532869774ebf8af9efe9484c597f896a7d46 Version: 930c532869774ebf8af9efe9484c597f896a7d46 Version: 930c532869774ebf8af9efe9484c597f896a7d46 Version: 930c532869774ebf8af9efe9484c597f896a7d46 Version: 930c532869774ebf8af9efe9484c597f896a7d46 Version: 930c532869774ebf8af9efe9484c597f896a7d46 Version: 930c532869774ebf8af9efe9484c597f896a7d46 Version: 1196c36fd53c3b1615eb02f986cb727b1dfc1047 Version: bbc3aa6b0e6050b2b2e04a08dd4d6423d576b196 Version: 6b96b2d473701b45df3fea8dd9796b6ec39e6d54 Version: 7405d73cea0d0e6c541f5c534078feeb46188844 Version: 8777c9f654637d56f4c4ca54eb1bc7c609b70085 Version: 6831c98ce0b8a3e88db64aa224372effd0dcc694 Version: 032951d32c13b7564dfba82758260cb7aa1149d2 Version: 14877928f10667a5606383885d004f7185f33718 Version: 3.10.103 ≤ Version: 3.12.63 ≤ Version: 3.14.75 ≤ Version: 3.16.39 ≤ Version: 3.18.39 ≤ Version: 4.1.30 ≤ Version: 4.4.17 ≤ Version: 4.6.6 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ceph/osdmap.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "2ceee3b77b83052648c40fef965f836fd7699d26",
"status": "affected",
"version": "930c532869774ebf8af9efe9484c597f896a7d46",
"versionType": "git"
},
{
"lessThan": "e4473751cc37db41f3f7da25d64a23e0c74570f1",
"status": "affected",
"version": "930c532869774ebf8af9efe9484c597f896a7d46",
"versionType": "git"
},
{
"lessThan": "f6961070c326bd158c38fa48756cde2bd78c4aaa",
"status": "affected",
"version": "930c532869774ebf8af9efe9484c597f896a7d46",
"versionType": "git"
},
{
"lessThan": "05c90e059269f087becfcce23348496085835c29",
"status": "affected",
"version": "930c532869774ebf8af9efe9484c597f896a7d46",
"versionType": "git"
},
{
"lessThan": "143ba49ead77ec483c0326f8aaad8649874e99c4",
"status": "affected",
"version": "930c532869774ebf8af9efe9484c597f896a7d46",
"versionType": "git"
},
{
"lessThan": "1732d89dfcd74f6fde9ce70900d316c4a151c153",
"status": "affected",
"version": "930c532869774ebf8af9efe9484c597f896a7d46",
"versionType": "git"
},
{
"lessThan": "bee4b5b53e7bff0467fd916cc44c9b190733c6bd",
"status": "affected",
"version": "930c532869774ebf8af9efe9484c597f896a7d46",
"versionType": "git"
},
{
"lessThan": "98917a499ec7064c14fc56d180a4fd636fc2784c",
"status": "affected",
"version": "930c532869774ebf8af9efe9484c597f896a7d46",
"versionType": "git"
},
{
"status": "affected",
"version": "1196c36fd53c3b1615eb02f986cb727b1dfc1047",
"versionType": "git"
},
{
"status": "affected",
"version": "bbc3aa6b0e6050b2b2e04a08dd4d6423d576b196",
"versionType": "git"
},
{
"status": "affected",
"version": "6b96b2d473701b45df3fea8dd9796b6ec39e6d54",
"versionType": "git"
},
{
"status": "affected",
"version": "7405d73cea0d0e6c541f5c534078feeb46188844",
"versionType": "git"
},
{
"status": "affected",
"version": "8777c9f654637d56f4c4ca54eb1bc7c609b70085",
"versionType": "git"
},
{
"status": "affected",
"version": "6831c98ce0b8a3e88db64aa224372effd0dcc694",
"versionType": "git"
},
{
"status": "affected",
"version": "032951d32c13b7564dfba82758260cb7aa1149d2",
"versionType": "git"
},
{
"status": "affected",
"version": "14877928f10667a5606383885d004f7185f33718",
"versionType": "git"
},
{
"lessThan": "3.11",
"status": "affected",
"version": "3.10.103",
"versionType": "semver"
},
{
"lessThan": "3.13",
"status": "affected",
"version": "3.12.63",
"versionType": "semver"
},
{
"lessThan": "3.15",
"status": "affected",
"version": "3.14.75",
"versionType": "semver"
},
{
"lessThan": "3.17",
"status": "affected",
"version": "3.16.39",
"versionType": "semver"
},
{
"lessThan": "3.19",
"status": "affected",
"version": "3.18.39",
"versionType": "semver"
},
{
"lessThan": "4.2",
"status": "affected",
"version": "4.1.30",
"versionType": "semver"
},
{
"lessThan": "4.5",
"status": "affected",
"version": "4.4.17",
"versionType": "semver"
},
{
"lessThan": "4.7",
"status": "affected",
"version": "4.6.6",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ceph/osdmap.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.7"
},
{
"lessThan": "4.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.10.103",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.12.63",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.14.75",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.16.39",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.18.39",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.1.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.6.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: Fix multiplication overflow in decode_new_up_state_weight()\n\nIf a message of type CEPH_MSG_OSD_MAP contains a (maliciously) corrupted\nosdmap, out-of-bounds memory accesses may occur in\ndecode_new_up_state_weight(). This happens because the bounds check for\nthe new_state part is based on calculating its length depending on a len\nvalue read from the incoming message. This calculation may overflow\nleading to an incorrect bounds check. Subsequently, out-of-bounds reads\nmay occur when decoding this part.\n\nThis patch switches the multiplication to use check_mul_overflow() to\nabort processing the osdmap if an overflow occurred. Therefore,\nosdmaps/messages containing large values for len that result in a\nmultiplication overflow are treated as invalid.\n\n[ idryomov: rename new_state_len -\u003e new_state_item_size, formatting ]"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - Malformed incremental osdmap data is delivered in CEPH_MSG_OSD_MAP over TCP from a Ceph monitor (mon_dispatch) or OSD (osd_dispatch) to libceph clients (CephFS/RBD), and the overflow is triggered while decoding received network bytes in osdmap_apply_incremental().\nAC:L - A compromised or attacker-controlled monitor/OSD can publish an incremental osdmap with epoch N+1 and a crafted new_state length that wraps the multiply, reliably bypassing bounds checks without races or victim-specific memory layout.\nPR:N - Exploitation requires no privileges on the victim host; a malicious cluster peer or on-path attacker that can deliver forged osdmaps to an already-connected kernel Ceph client needs no local account, capabilities, or user-namespace tricks.\nUI:N - Once a host is a Ceph client, osdmap subscriptions and updates are applied automatically by the kernel; no additional mount, open, or interactive step is needed at exploit time beyond the existing client session.\nS:U - Impact is confined to kernel memory and libceph client state on the Ceph client host (info leak, map corruption, crash, or privilege escalation); it does not cross VM, IOMMU, or sandbox boundaries to another security authority.\nC:H - Integer-overflow bypass lets decode_new_up_state_weight() run bare ceph_decode_32/8 loops past the message end, performing out-of-bounds reads of adjacent kernel heap/slack memory that can disclose pointers and other sensitive data.\nI:H - Misaligned decoding also drives attacker-controlled osd/xorstate/weight values into map-\u003eosd_weight[], map-\u003eosd_state[], and map-\u003eosd_addr[] updates (including memset), corrupting kernel osdmap state in ways usable for further exploitation.\nA:H - Unbounded out-of-bounds reads while parsing osdmaps can fault on unmapped pages and trigger kernel oops/panic; map corruption can also cause persistent client failure, repeatable on each malicious incremental map."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:30:30.014Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/2ceee3b77b83052648c40fef965f836fd7699d26"
},
{
"url": "https://git.kernel.org/stable/c/e4473751cc37db41f3f7da25d64a23e0c74570f1"
},
{
"url": "https://git.kernel.org/stable/c/f6961070c326bd158c38fa48756cde2bd78c4aaa"
},
{
"url": "https://git.kernel.org/stable/c/05c90e059269f087becfcce23348496085835c29"
},
{
"url": "https://git.kernel.org/stable/c/143ba49ead77ec483c0326f8aaad8649874e99c4"
},
{
"url": "https://git.kernel.org/stable/c/1732d89dfcd74f6fde9ce70900d316c4a151c153"
},
{
"url": "https://git.kernel.org/stable/c/bee4b5b53e7bff0467fd916cc44c9b190733c6bd"
},
{
"url": "https://git.kernel.org/stable/c/98917a499ec7064c14fc56d180a4fd636fc2784c"
}
],
"title": "libceph: Fix multiplication overflow in decode_new_up_state_weight()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68158",
"datePublished": "2026-08-10T11:59:24.675Z",
"dateReserved": "2026-07-30T09:28:09.371Z",
"dateUpdated": "2026-08-19T16:30:30.014Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68162 (GCVE-0-2026-68162)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
sctp: avoid auth_enable sysctl UAF during netns teardown
proc_sctp_do_auth() updates the SCTP control socket after changing
net.sctp.auth_enable. The handler gets the per-net SCTP state from
ctl->data, so an already opened sysctl file can still target a network
namespace while that namespace is being torn down.
SCTP previously registered its per-net sysctls from sctp_defaults_init(),
while the control socket is created later from sctp_ctrlsock_init(). This
exposed a window during initialization where auth_enable was writable
before net->sctp.ctl_sock existed, and a teardown window where auth_enable
stayed writable after inet_ctl_sock_destroy() had released the control
socket.
Move the per-net SCTP sysctl registration into sctp_ctrlsock_init() after
sctp_ctl_sock_init() succeeds, and unregister the sysctl table before
destroying the control socket in sctp_ctrlsock_exit(). If sysctl
registration fails after the control socket was created, destroy the
control socket in the same init path.
Make sctp_sysctl_net_unregister() tolerate a missing header and clear the
saved pointer so init-error and exit paths can safely share the unregister
helper.
References
| URL | Tags | ||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 10c869a52f266e40f548cc3c565d14930a5edafc Version: dc583e7e5f8515ca489c0df28e4362a70eade382 Version: bd2a2939423566c654545fa3e96a656662a0af9e Version: 1b67030d39f2b00f94ac1f0af11ba6657589e4d3 Version: 7ec30c54f339c640aa7e49d7e9f7bbed6bd42bf6 Version: c184bc621e3cef03ac9ba81a50dda2dae6a21d36 Version: 15649fd5415eda664ef35780c2013adeb5d9c695 Version: 15649fd5415eda664ef35780c2013adeb5d9c695 Version: 15649fd5415eda664ef35780c2013adeb5d9c695 Version: 5.4.290 ≤ Version: 5.10.234 ≤ Version: 5.15.177 ≤ Version: 6.1.125 ≤ Version: 6.6.72 ≤ Version: 6.12.10 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/sctp/protocol.c",
"net/sctp/sysctl.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "19573dcddb8819fd68d6cd1f916c1c99c3fa4ff4",
"status": "affected",
"version": "10c869a52f266e40f548cc3c565d14930a5edafc",
"versionType": "git"
},
{
"lessThan": "ceb7190b5c873d4a1267a1600c5aa52c600e929f",
"status": "affected",
"version": "dc583e7e5f8515ca489c0df28e4362a70eade382",
"versionType": "git"
},
{
"lessThan": "fd66854a22661929245f3d2b244c432bc8b1a150",
"status": "affected",
"version": "bd2a2939423566c654545fa3e96a656662a0af9e",
"versionType": "git"
},
{
"lessThan": "158f3cc332dc53f43ec20060233d7c3cecd6d912",
"status": "affected",
"version": "1b67030d39f2b00f94ac1f0af11ba6657589e4d3",
"versionType": "git"
},
{
"lessThan": "66700c0719675e0e118ae83b2d7168dacd69dd3d",
"status": "affected",
"version": "7ec30c54f339c640aa7e49d7e9f7bbed6bd42bf6",
"versionType": "git"
},
{
"lessThan": "626bda8cfe43dff19a9833ff6ba055a817b5455c",
"status": "affected",
"version": "c184bc621e3cef03ac9ba81a50dda2dae6a21d36",
"versionType": "git"
},
{
"lessThan": "be6aae9d1b91c603adb35872d37d40e83daf8758",
"status": "affected",
"version": "15649fd5415eda664ef35780c2013adeb5d9c695",
"versionType": "git"
},
{
"lessThan": "a50e73488e0bbdd262b3be3c9a1d8dd078382381",
"status": "affected",
"version": "15649fd5415eda664ef35780c2013adeb5d9c695",
"versionType": "git"
},
{
"lessThan": "f8d5e7846025f4ab15a461235f8ebae9094a361a",
"status": "affected",
"version": "15649fd5415eda664ef35780c2013adeb5d9c695",
"versionType": "git"
},
{
"lessThan": "5.4.292",
"status": "affected",
"version": "5.4.290",
"versionType": "semver"
},
{
"lessThan": "5.10.266",
"status": "affected",
"version": "5.10.234",
"versionType": "semver"
},
{
"lessThan": "5.15.217",
"status": "affected",
"version": "5.15.177",
"versionType": "semver"
},
{
"lessThan": "6.1.184",
"status": "affected",
"version": "6.1.125",
"versionType": "semver"
},
{
"lessThan": "6.6.151",
"status": "affected",
"version": "6.6.72",
"versionType": "semver"
},
{
"lessThan": "6.12.101",
"status": "affected",
"version": "6.12.10",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/sctp/protocol.c",
"net/sctp/sysctl.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.13"
},
{
"lessThan": "6.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.4.*",
"status": "unaffected",
"version": "5.4.292",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.4.292",
"versionStartIncluding": "5.4.290",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "5.10.234",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.15.177",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "6.1.125",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "6.6.72",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.12.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: avoid auth_enable sysctl UAF during netns teardown\n\nproc_sctp_do_auth() updates the SCTP control socket after changing\nnet.sctp.auth_enable. The handler gets the per-net SCTP state from\nctl-\u003edata, so an already opened sysctl file can still target a network\nnamespace while that namespace is being torn down.\n\nSCTP previously registered its per-net sysctls from sctp_defaults_init(),\nwhile the control socket is created later from sctp_ctrlsock_init(). This\nexposed a window during initialization where auth_enable was writable\nbefore net-\u003esctp.ctl_sock existed, and a teardown window where auth_enable\nstayed writable after inet_ctl_sock_destroy() had released the control\nsocket.\n\nMove the per-net SCTP sysctl registration into sctp_ctrlsock_init() after\nsctp_ctl_sock_init() succeeds, and unregister the sysctl table before\ndestroying the control socket in sctp_ctrlsock_exit(). If sysctl\nregistration fails after the control socket was created, destroy the\ncontrol socket in the same init path.\n\nMake sctp_sysctl_net_unregister() tolerate a missing header and clear the\nsaved pointer so init-error and exit paths can safely share the unregister\nhelper."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is triggered only by writing the per-net sysctl net.sctp.auth_enable via /proc/sys (proc_sctp_do_auth); it is not reachable from SCTP packet receive, sockets, or other remote protocol paths.\nAC:L - An attacker can open the sysctl file, concurrently destroy the target network namespace, and repeatedly write during teardown; pernet exit destroys ctl_sock before unregistering sysctls, and the attacker controls both sides of that race.\nPR:L - Exploitation requires writing a mode 0644 sysctl in a network namespace; an unprivileged host user with CAP_NET_ADMIN via user namespaces can create a netns, become namespace root, and write net/sctp/auth_enable without init-namespace privileges.\nUI:N - No victim interaction is required beyond the attacker opening the sysctl and triggering namespace teardown in their own threads or processes.\nS:U - Impact is confined to kernel memory corruption and privilege escalation within the same host/kernel security domain; it does not cross VM, container, or IOMMU boundaries by itself.\nC:H - proc_sctp_do_auth dereferences net-\u003esctp.ctl_sock after inet_ctl_sock_destroy; lock_sock and sctp_sk(sk)-\u003eep access freed socket/endpoint memory, a use-after-free that can disclose or infer heap contents.\nI:H - On a successful write, the handler sets sctp_sk(sk)-\u003eep-\u003eauth_enable on a freed endpoint object, giving a controlled heap write primitive that can be developed into arbitrary kernel modification or code execution.\nA:H - Use-after-free on the SCTP control socket/endpoint during sysctl processing can cause kernel oops/panic from lock_sock or ep access on freed memory, even when full exploitation is not attempted."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:01.222Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/19573dcddb8819fd68d6cd1f916c1c99c3fa4ff4"
},
{
"url": "https://git.kernel.org/stable/c/ceb7190b5c873d4a1267a1600c5aa52c600e929f"
},
{
"url": "https://git.kernel.org/stable/c/fd66854a22661929245f3d2b244c432bc8b1a150"
},
{
"url": "https://git.kernel.org/stable/c/158f3cc332dc53f43ec20060233d7c3cecd6d912"
},
{
"url": "https://git.kernel.org/stable/c/66700c0719675e0e118ae83b2d7168dacd69dd3d"
},
{
"url": "https://git.kernel.org/stable/c/626bda8cfe43dff19a9833ff6ba055a817b5455c"
},
{
"url": "https://git.kernel.org/stable/c/be6aae9d1b91c603adb35872d37d40e83daf8758"
},
{
"url": "https://git.kernel.org/stable/c/a50e73488e0bbdd262b3be3c9a1d8dd078382381"
},
{
"url": "https://git.kernel.org/stable/c/f8d5e7846025f4ab15a461235f8ebae9094a361a"
}
],
"title": "sctp: avoid auth_enable sysctl UAF during netns teardown",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68162",
"datePublished": "2026-08-10T11:59:29.099Z",
"dateReserved": "2026-07-30T09:28:09.372Z",
"dateUpdated": "2026-08-23T12:46:01.222Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68146 (GCVE-0-2026-68146)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-23 12:45
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ftrace: Add global mutex to serialize trace_parser access
In ftrace, the trace_parser structure is allocated and initialized when
a trace file is opened, and is subsequently used across write and release
handlers to parse user input.
The affected handler paths and their specific functions are:
- Open paths: ftrace_regex_open(), ftrace_graph_open()
- Write paths: ftrace_regex_write(), ftrace_graph_write()
- Release paths: ftrace_regex_release(), ftrace_graph_release()
If userspace opens a trace file descriptor and shares it across multiple
threads, concurrent write calls will race on the parser's internal state,
specifically the 'idx', 'cont', and 'buffer' fields, leading to corrupted
input or undefined behavior.
Fix this by adding a global mutex, parser_lock, to serialize all access
to trace_parser across write and release paths, preventing concurrent
corruption of parser state.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 689fd8b65d669b96d612ccc37d6fb87bf7ed6907 Version: 689fd8b65d669b96d612ccc37d6fb87bf7ed6907 Version: 689fd8b65d669b96d612ccc37d6fb87bf7ed6907 Version: 689fd8b65d669b96d612ccc37d6fb87bf7ed6907 Version: 689fd8b65d669b96d612ccc37d6fb87bf7ed6907 Version: 689fd8b65d669b96d612ccc37d6fb87bf7ed6907 Version: 689fd8b65d669b96d612ccc37d6fb87bf7ed6907 Version: 689fd8b65d669b96d612ccc37d6fb87bf7ed6907 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"kernel/trace/ftrace.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a29bc20ea5f0cb79c6287f2c6182c5eeb8e6c01f",
"status": "affected",
"version": "689fd8b65d669b96d612ccc37d6fb87bf7ed6907",
"versionType": "git"
},
{
"lessThan": "db76744d588086695371ecdd982694395628ba48",
"status": "affected",
"version": "689fd8b65d669b96d612ccc37d6fb87bf7ed6907",
"versionType": "git"
},
{
"lessThan": "1474fe4453505b6be720b5bb94be1c927de3314a",
"status": "affected",
"version": "689fd8b65d669b96d612ccc37d6fb87bf7ed6907",
"versionType": "git"
},
{
"lessThan": "3d0dd138a06c782f8b755cd1b6f9909494514ce1",
"status": "affected",
"version": "689fd8b65d669b96d612ccc37d6fb87bf7ed6907",
"versionType": "git"
},
{
"lessThan": "90be137813e1a5bdfd671e40fe28004fb959d3e4",
"status": "affected",
"version": "689fd8b65d669b96d612ccc37d6fb87bf7ed6907",
"versionType": "git"
},
{
"lessThan": "65bf73bee1a4f3722208ae46afc0fa5de76b9a0a",
"status": "affected",
"version": "689fd8b65d669b96d612ccc37d6fb87bf7ed6907",
"versionType": "git"
},
{
"lessThan": "e807c9193d9493c7a0d039158ebb955050a76df1",
"status": "affected",
"version": "689fd8b65d669b96d612ccc37d6fb87bf7ed6907",
"versionType": "git"
},
{
"lessThan": "7720b63bcef3f54c7fe288774b720a227d54a306",
"status": "affected",
"version": "689fd8b65d669b96d612ccc37d6fb87bf7ed6907",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"kernel/trace/ftrace.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.32"
},
{
"lessThan": "2.6.32",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "2.6.32",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "2.6.32",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.32",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.32",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.32",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.32",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.32",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.32",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nftrace: Add global mutex to serialize trace_parser access\n\nIn ftrace, the trace_parser structure is allocated and initialized when\na trace file is opened, and is subsequently used across write and release\nhandlers to parse user input.\n\nThe affected handler paths and their specific functions are:\n - Open paths: ftrace_regex_open(), ftrace_graph_open()\n - Write paths: ftrace_regex_write(), ftrace_graph_write()\n - Release paths: ftrace_regex_release(), ftrace_graph_release()\n\nIf userspace opens a trace file descriptor and shares it across multiple\nthreads, concurrent write calls will race on the parser\u0027s internal state,\nspecifically the \u0027idx\u0027, \u0027cont\u0027, and \u0027buffer\u0027 fields, leading to corrupted\ninput or undefined behavior.\n\nFix this by adding a global mutex, parser_lock, to serialize all access\nto trace_parser across write and release paths, preventing concurrent\ncorruption of parser state."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:45:57.951Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a29bc20ea5f0cb79c6287f2c6182c5eeb8e6c01f"
},
{
"url": "https://git.kernel.org/stable/c/db76744d588086695371ecdd982694395628ba48"
},
{
"url": "https://git.kernel.org/stable/c/1474fe4453505b6be720b5bb94be1c927de3314a"
},
{
"url": "https://git.kernel.org/stable/c/3d0dd138a06c782f8b755cd1b6f9909494514ce1"
},
{
"url": "https://git.kernel.org/stable/c/90be137813e1a5bdfd671e40fe28004fb959d3e4"
},
{
"url": "https://git.kernel.org/stable/c/65bf73bee1a4f3722208ae46afc0fa5de76b9a0a"
},
{
"url": "https://git.kernel.org/stable/c/e807c9193d9493c7a0d039158ebb955050a76df1"
},
{
"url": "https://git.kernel.org/stable/c/7720b63bcef3f54c7fe288774b720a227d54a306"
}
],
"title": "ftrace: Add global mutex to serialize trace_parser access",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68146",
"datePublished": "2026-08-10T11:59:11.273Z",
"dateReserved": "2026-07-30T09:28:09.371Z",
"dateUpdated": "2026-08-23T12:45:57.951Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68126 (GCVE-0-2026-68126)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-17 04:59
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
mac802154: hold an interface reference across the scan worker
mac802154_scan_worker() captures the scanning sub-interface under RCU
and then keeps dereferencing sdata->dev after rcu_read_unlock() and
outside the rtnl -- in the failure traces, in
mac802154_transmit_beacon_req() (skb->dev = sdata->dev), and in the
end_scan cleanup. Nothing keeps that netdev alive across the worker
iteration.
A concurrent DEL_INTERFACE or PHY removal can unregister the interface
once the worker drops the rtnl between its two drv_set_channel()
sections. unregister_netdevice() frees the netdev asynchronously from
netdev_run_todo() with the rtnl already dropped, so neither holding the
rtnl nor the per-PHY IEEE802154_IS_SCANNING flag prevents a stale worker
iteration from dereferencing the freed netdev -- a KASAN
slab-use-after-free, reachable by racing TRIGGER_SCAN against
DEL_INTERFACE (both CAP_NET_ADMIN).
Pin the netdev with netdev_hold() while the RCU read lock is still held,
and release it at every worker exit.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/mac802154/scan.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "bd7110f0caa32426140ff302a209c53294ef2cfd",
"status": "affected",
"version": "57588c71177f0bfc08509c2c3a9bfe32850c0786",
"versionType": "git"
},
{
"lessThan": "dd4754194a706163294b6141460101b99082c8c7",
"status": "affected",
"version": "57588c71177f0bfc08509c2c3a9bfe32850c0786",
"versionType": "git"
},
{
"lessThan": "59c1d5463b7bc5a2cdaae27108d1dfd67edc7d1b",
"status": "affected",
"version": "57588c71177f0bfc08509c2c3a9bfe32850c0786",
"versionType": "git"
},
{
"lessThan": "5f303f622f6bb8907c405e5123a0ab0f70fb0065",
"status": "affected",
"version": "57588c71177f0bfc08509c2c3a9bfe32850c0786",
"versionType": "git"
},
{
"lessThan": "234e5e898b713bc0b3a631b6f002897f43d046c8",
"status": "affected",
"version": "57588c71177f0bfc08509c2c3a9bfe32850c0786",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/mac802154/scan.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.3"
},
{
"lessThan": "6.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmac802154: hold an interface reference across the scan worker\n\nmac802154_scan_worker() captures the scanning sub-interface under RCU\nand then keeps dereferencing sdata-\u003edev after rcu_read_unlock() and\noutside the rtnl -- in the failure traces, in\nmac802154_transmit_beacon_req() (skb-\u003edev = sdata-\u003edev), and in the\nend_scan cleanup. Nothing keeps that netdev alive across the worker\niteration.\n\nA concurrent DEL_INTERFACE or PHY removal can unregister the interface\nonce the worker drops the rtnl between its two drv_set_channel()\nsections. unregister_netdevice() frees the netdev asynchronously from\nnetdev_run_todo() with the rtnl already dropped, so neither holding the\nrtnl nor the per-PHY IEEE802154_IS_SCANNING flag prevents a stale worker\niteration from dereferencing the freed netdev -- a KASAN\nslab-use-after-free, reachable by racing TRIGGER_SCAN against\nDEL_INTERFACE (both CAP_NET_ADMIN).\n\nPin the netdev with netdev_hold() while the RCU read lock is still held,\nand release it at every worker exit."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:59:17.559Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/bd7110f0caa32426140ff302a209c53294ef2cfd"
},
{
"url": "https://git.kernel.org/stable/c/dd4754194a706163294b6141460101b99082c8c7"
},
{
"url": "https://git.kernel.org/stable/c/59c1d5463b7bc5a2cdaae27108d1dfd67edc7d1b"
},
{
"url": "https://git.kernel.org/stable/c/5f303f622f6bb8907c405e5123a0ab0f70fb0065"
},
{
"url": "https://git.kernel.org/stable/c/234e5e898b713bc0b3a631b6f002897f43d046c8"
}
],
"title": "mac802154: hold an interface reference across the scan worker",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68126",
"datePublished": "2026-08-10T11:58:47.478Z",
"dateReserved": "2026-07-30T09:28:09.369Z",
"dateUpdated": "2026-08-17T04:59:17.559Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72116 (GCVE-0-2026-72116)
Vulnerability from cvelistv5
Published
2026-08-15 05:52
Modified
2026-08-19 16:36
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
can: bcm: fix stale rx/tx ops after device removal
RX: an RX_SETUP update(!) for an existing op skipped can_rx_register()
unconditionally, even when a concurrent NETDEV_UNREGISTER had already
torn down its registration (op->rx_reg_dev == NULL). This silently
did not re-enable frame delivery for that updated filter. bcm_rx_setup()
now re-registers in that case, while leaving rx_ops with ifindex = 0
(all CAN devices) which never carry a tracked rx_reg_dev registered as-is.
TX: bcm_notify() only handled bo->rx_ops on NETDEV_UNREGISTER, leaving
tx_ops with an active cyclic transmission re-arming its hrtimer
indefinitely to execute bcm_tx_timeout_handler(). Cancelling the hrtimer
prevents the runaway timer and any injection into a later reused ifindex,
since nothing else calls bcm_can_tx() for the op until an explicit
TX_SETUP update re-arms it.
Unlike bcm_rx_unreg(), which clears the tracked rx_reg_dev for rx_ops,
the ifindex is intentionally left unchanged for tx_ops. bcm_tx_setup()
always rejects ifindex 0, so clearing it would strand the op: neither a
later TX_SETUP (bcm_find_op()) nor TX_DELETE (bcm_delete_tx_op()) could
ever find it again, since both require an exact ifindex match.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/can/bcm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "d30a36066ed3abefb72ae18901f71841ba18b350",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "ca829677ffa2de5d79e06366e19ac1e4f5cc78dd",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "9517d8fb0b191398d35b9b7f8c719c1cc7761cb1",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "60d8a7942f4ed2d975207aaeba1adb576707e53d",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "f749e4564952d60e96930c09f2be99955d07c22e",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "6be3e1fedf03eab36a2c09d755d1171287b2014b",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "b31d0933509c5a35c0be5736a2ce8df0d1bf112c",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "3b762c0d950383ab7a002686c9136b9aa55d2d70",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/can/bcm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.25"
},
{
"lessThan": "2.6.25",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.25",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: bcm: fix stale rx/tx ops after device removal\n\nRX: an RX_SETUP update(!) for an existing op skipped can_rx_register()\nunconditionally, even when a concurrent NETDEV_UNREGISTER had already\ntorn down its registration (op-\u003erx_reg_dev == NULL). This silently\ndid not re-enable frame delivery for that updated filter. bcm_rx_setup()\nnow re-registers in that case, while leaving rx_ops with ifindex = 0\n(all CAN devices) which never carry a tracked rx_reg_dev registered as-is.\n\nTX: bcm_notify() only handled bo-\u003erx_ops on NETDEV_UNREGISTER, leaving\ntx_ops with an active cyclic transmission re-arming its hrtimer\nindefinitely to execute bcm_tx_timeout_handler(). Cancelling the hrtimer\nprevents the runaway timer and any injection into a later reused ifindex,\nsince nothing else calls bcm_can_tx() for the op until an explicit\nTX_SETUP update re-arms it.\n\nUnlike bcm_rx_unreg(), which clears the tracked rx_reg_dev for rx_ops,\nthe ifindex is intentionally left unchanged for tx_ops. bcm_tx_setup()\nalways rejects ifindex 0, so clearing it would strand the op: neither a\nlater TX_SETUP (bcm_find_op()) nor TX_DELETE (bcm_delete_tx_op()) could\never find it again, since both require an exact ifindex match."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached only via local PF_CAN/CAN_BCM syscalls (socket/connect/sendmsg TX_SETUP or RX_SETUP); bcm_tx_timeout_handler() is driven by a local hrtimer, not by remote network services or CAN bus frames alone.\nAC:L - An attacker controls both sides by arming cyclic TX with SETTIMER/STARTTIMER, then triggering or waiting for NETDEV_UNREGISTER (e.g., concurrent ip link del in a user namespace) while ifindex reuse is normal kernel behavior, making injection reliably achievable.\nPR:L - can_create(), bcm_connect(), and bcm_sendmsg() perform no capability checks; any local user with CAN access (or CAP_NET_ADMIN in an unprivileged user namespace to create vcan) can open BCM sockets and program cyclic TX/RX ops.\nUI:N - Exploitation requires only the attacker opening a BCM socket and sending TX_SETUP/RX_SETUP messages; no victim action such as mounting media or opening files is needed once local CAN access exists.\nS:U - Impact is unauthorized CAN transmission/monitoring disruption within the same kernel host; it does not cross VM, container, or IOMMU security boundaries even when frames reach an adjacent vehicle or factory CAN segment.\nC:N - The flaw causes stale timer-driven transmission and missed RX re-registration, not kernel memory disclosure; no out-of-bounds read, UAF, or other information-leak primitive is present in this bug.\nI:H - After NETDEV_UNREGISTER, orphaned tx_ops keep bcm_can_tx() running with a stale ifindex, so attacker-crafted cyclic CAN frames can be injected onto any later netdev that reuses that ifindex, including safety-critical automotive or industrial buses.\nA:H - Uncancelled hrtimers on stale tx_ops re-arm bcm_tx_timeout_handler() indefinitely after device removal, causing persistent timer/softirq CPU consumption, and the RX_SETUP path can silently stop frame delivery after unregister races."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:36:05.976Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/d30a36066ed3abefb72ae18901f71841ba18b350"
},
{
"url": "https://git.kernel.org/stable/c/ca829677ffa2de5d79e06366e19ac1e4f5cc78dd"
},
{
"url": "https://git.kernel.org/stable/c/9517d8fb0b191398d35b9b7f8c719c1cc7761cb1"
},
{
"url": "https://git.kernel.org/stable/c/60d8a7942f4ed2d975207aaeba1adb576707e53d"
},
{
"url": "https://git.kernel.org/stable/c/f749e4564952d60e96930c09f2be99955d07c22e"
},
{
"url": "https://git.kernel.org/stable/c/6be3e1fedf03eab36a2c09d755d1171287b2014b"
},
{
"url": "https://git.kernel.org/stable/c/b31d0933509c5a35c0be5736a2ce8df0d1bf112c"
},
{
"url": "https://git.kernel.org/stable/c/3b762c0d950383ab7a002686c9136b9aa55d2d70"
}
],
"title": "can: bcm: fix stale rx/tx ops after device removal",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72116",
"datePublished": "2026-08-15T05:52:56.260Z",
"dateReserved": "2026-08-09T03:40:39.906Z",
"dateUpdated": "2026-08-19T16:36:05.976Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68416 (GCVE-0-2026-68416)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-17 05:05
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
mtd: fix double free and WARN_ON in add_mtd_device() error paths
When device_register() or mtd_nvmem_add() fails inside
add_mtd_device() for a partition, the error handling triggers
mtd_release() via put_device() or device_unregister(). mtd_release()
calls release_mtd_partition() which frees the mtd_info structure.
However, callers such as mtd_add_partition() and add_mtd_partitions()
also call free_partition() in their error paths, resulting in a double
free.
Additionally, release_mtd_partition() hits WARN_ON(!list_empty(
&mtd->part.node)) because the partition node is still linked in the
parent's partitions list when the release callback fires from the
add_mtd_device() error path.
Fix this by overriding dev->type and dev->release before put_device()
in the error paths, so that device_release() invokes a no-op function
instead of mtd_release(). For the mtd_nvmem_add() failure case,
device_unregister() is replaced with device_del() to separate the
device removal from the final kobject reference drop, allowing the
override to take effect before put_device() is called.
The callers' error paths (list_del + free_partition) remain the sole
owners of mtd_info lifetime on add_mtd_device() failure, which is the
expected contract.
The normal partition teardown path is not affected: del_mtd_device()
goes through kref_put() -> mtd_device_release() -> device_unregister()
with dev->type still set to &mtd_devtype, so mtd_release() ->
release_mtd_partition() continues to work correctly for the regular
removal case.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/mtd/mtdcore.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ffe21a3545b439e7b11578a701c22a847c149561",
"status": "affected",
"version": "19bfa9ebebb5ec0695def57eb1d80de7e9cab369",
"versionType": "git"
},
{
"lessThan": "e1e96aca1bdf391e2f49531c270ffc134e5b49a5",
"status": "affected",
"version": "19bfa9ebebb5ec0695def57eb1d80de7e9cab369",
"versionType": "git"
},
{
"lessThan": "f98ae09c727dcf34f745c875661c64b642e4abfa",
"status": "affected",
"version": "19bfa9ebebb5ec0695def57eb1d80de7e9cab369",
"versionType": "git"
},
{
"lessThan": "820f983d641937a787e841ee4b93501f69f5683e",
"status": "affected",
"version": "19bfa9ebebb5ec0695def57eb1d80de7e9cab369",
"versionType": "git"
},
{
"lessThan": "9d4af746af8ce27eefc2338b2feaa1e01f28b6c3",
"status": "affected",
"version": "19bfa9ebebb5ec0695def57eb1d80de7e9cab369",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/mtd/mtdcore.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.6"
},
{
"lessThan": "6.6",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmtd: fix double free and WARN_ON in add_mtd_device() error paths\n\nWhen device_register() or mtd_nvmem_add() fails inside\nadd_mtd_device() for a partition, the error handling triggers\nmtd_release() via put_device() or device_unregister(). mtd_release()\ncalls release_mtd_partition() which frees the mtd_info structure.\nHowever, callers such as mtd_add_partition() and add_mtd_partitions()\nalso call free_partition() in their error paths, resulting in a double\nfree.\n\nAdditionally, release_mtd_partition() hits WARN_ON(!list_empty(\n\u0026mtd-\u003epart.node)) because the partition node is still linked in the\nparent\u0027s partitions list when the release callback fires from the\nadd_mtd_device() error path.\n\nFix this by overriding dev-\u003etype and dev-\u003erelease before put_device()\nin the error paths, so that device_release() invokes a no-op function\ninstead of mtd_release(). For the mtd_nvmem_add() failure case,\ndevice_unregister() is replaced with device_del() to separate the\ndevice removal from the final kobject reference drop, allowing the\noverride to take effect before put_device() is called.\n\nThe callers\u0027 error paths (list_del + free_partition) remain the sole\nowners of mtd_info lifetime on add_mtd_device() failure, which is the\nexpected contract.\n\nThe normal partition teardown path is not affected: del_mtd_device()\ngoes through kref_put() -\u003e mtd_device_release() -\u003e device_unregister()\nwith dev-\u003etype still set to \u0026mtd_devtype, so mtd_release() -\u003e\nrelease_mtd_partition() continues to work correctly for the regular\nremoval case."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:05:10.971Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ffe21a3545b439e7b11578a701c22a847c149561"
},
{
"url": "https://git.kernel.org/stable/c/e1e96aca1bdf391e2f49531c270ffc134e5b49a5"
},
{
"url": "https://git.kernel.org/stable/c/f98ae09c727dcf34f745c875661c64b642e4abfa"
},
{
"url": "https://git.kernel.org/stable/c/820f983d641937a787e841ee4b93501f69f5683e"
},
{
"url": "https://git.kernel.org/stable/c/9d4af746af8ce27eefc2338b2feaa1e01f28b6c3"
}
],
"title": "mtd: fix double free and WARN_ON in add_mtd_device() error paths",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68416",
"datePublished": "2026-08-10T12:04:36.582Z",
"dateReserved": "2026-07-30T09:28:09.391Z",
"dateUpdated": "2026-08-17T05:05:10.971Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72101 (GCVE-0-2026-72101)
Vulnerability from cvelistv5
Published
2026-08-15 05:52
Modified
2026-08-17 05:08
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
dm-integrity: fix leaking uninitialized kernel memory
If hash size is less than device's tuple size, dm-integrity is supposed
to zero the remaining space. There was a bug in the code that zeroing
didn't work. This commit fixes it.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/md/dm-integrity.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "50af3e51dc709384701dbc721b4bd865285c5f2c",
"status": "affected",
"version": "fb0987682c629c1d2c476f35f6fde405a5e304a4",
"versionType": "git"
},
{
"lessThan": "0c4e9bb1d4101030f55c869f18bd3ece39a77bbb",
"status": "affected",
"version": "fb0987682c629c1d2c476f35f6fde405a5e304a4",
"versionType": "git"
},
{
"lessThan": "8f0af8493009a61b4313e0a8c6e03fbc36fd43f9",
"status": "affected",
"version": "fb0987682c629c1d2c476f35f6fde405a5e304a4",
"versionType": "git"
},
{
"lessThan": "7bb03b2b01b814a9fc14afbfc2cbb2cca5b34750",
"status": "affected",
"version": "fb0987682c629c1d2c476f35f6fde405a5e304a4",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/md/dm-integrity.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.11"
},
{
"lessThan": "6.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndm-integrity: fix leaking uninitialized kernel memory\n\nIf hash size is less than device\u0027s tuple size, dm-integrity is supposed\nto zero the remaining space. There was a bug in the code that zeroing\ndidn\u0027t work. This commit fixes it."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:08:13.573Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/50af3e51dc709384701dbc721b4bd865285c5f2c"
},
{
"url": "https://git.kernel.org/stable/c/0c4e9bb1d4101030f55c869f18bd3ece39a77bbb"
},
{
"url": "https://git.kernel.org/stable/c/8f0af8493009a61b4313e0a8c6e03fbc36fd43f9"
},
{
"url": "https://git.kernel.org/stable/c/7bb03b2b01b814a9fc14afbfc2cbb2cca5b34750"
}
],
"title": "dm-integrity: fix leaking uninitialized kernel memory",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72101",
"datePublished": "2026-08-15T05:52:45.548Z",
"dateReserved": "2026-08-09T03:40:39.905Z",
"dateUpdated": "2026-08-17T05:08:13.573Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68143 (GCVE-0-2026-68143)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: slip: serialize receive against buffer reallocation
sl_realloc_bufs() replaces rbuff and updates buffsize while holding
sl->lock. slip_receive_buf() reads those fields and writes through rbuff
without holding the lock.
An MTU change can therefore race with receive processing. An MTU shrink
can expose the new smaller rbuff with the old larger bound, causing an
out-of-bounds write. A receive callback which already loaded the old
rbuff can instead continue writing after that buffer has been freed.
Serialize receive processing with sl_realloc_bufs() by holding sl->lock
while consuming each receive batch.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/slip/slip.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "8180daf2b66155f84ec4f9e3f95488c8a3421716",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "189a550eb7e1dc10018718ddfc46d003ffe58653",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "1be09d175b627fad7f6bec7ad27b8a4a99863912",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "eb3836eab47487823f362e6985e170a1e15f20fd",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "44401f7dd9940ced7098930ef64f5a332f279fc2",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "5d07b178bef511d69558cfc89fe1129258dc39f8",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "0e37bbd6d617eb52bace49390e99eaedc1af73ce",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "ee7f9bb9320add61f7b367d7e6cd55e3a3a4d65d",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/slip/slip.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: slip: serialize receive against buffer reallocation\n\nsl_realloc_bufs() replaces rbuff and updates buffsize while holding\nsl-\u003elock. slip_receive_buf() reads those fields and writes through rbuff\nwithout holding the lock.\n\nAn MTU change can therefore race with receive processing. An MTU shrink\ncan expose the new smaller rbuff with the old larger bound, causing an\nout-of-bounds write. A receive callback which already loaded the old\nrbuff can instead continue writing after that buffer has been freed.\n\nSerialize receive processing with sl_realloc_bufs() by holding sl-\u003elock\nwhile consuming each receive batch."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is in the SLIP TTY line discipline; triggering the MTU shrink/realloc race requires SIOCSIFMTU/RTM_SETLINK (CAP_NET_ADMIN) on the host, so a single attacker must have local access even if SLIP frames arrive over a serial backhaul.\nAC:L - An attacker with CAP_NET_ADMIN can concurrently hammer MTU changes via ioctl/rtnetlink and inject SLIP frames on the bound TTY/PTY, controlling both sides of the race without depending on uncontrollable timing.\nPR:L - SIOCSIFMTU requires CAP_NET_ADMIN in the interface network namespace, obtainable by an unprivileged user via user namespaces; exploitation targets already-active SLIP links and does not repeat slip_open()\u0027s init-namespace check.\nUI:N - No end-user or administrator interaction is required during exploitation once a SLIP interface is active; the attacker drives both MTU reallocation and receive processing directly.\nS:U - Heap corruption is confined to kernel SLIP receive buffers and adjacent kmalloc objects; impact is standard kernel memory corruption and local privilege escalation, not a cross-VM or sandbox boundary escape.\nC:H - The race yields heap out-of-bounds writes and use-after-free writes on freed rbuff kmalloc objects; per kernel guidance, this class of memory corruption enables arbitrary kernel memory disclosure.\nI:H - Writing past the reallocated rbuff boundary or into a freed buffer corrupts adjacent heap metadata/objects, providing primitives for arbitrary kernel writes and control-flow hijacking.\nA:H - Out-of-bounds and use-after-free corruption of kernel heap memory reliably causes kernel oops/panic during the race even when not fully weaponized for code execution."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:30:04.807Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/8180daf2b66155f84ec4f9e3f95488c8a3421716"
},
{
"url": "https://git.kernel.org/stable/c/189a550eb7e1dc10018718ddfc46d003ffe58653"
},
{
"url": "https://git.kernel.org/stable/c/1be09d175b627fad7f6bec7ad27b8a4a99863912"
},
{
"url": "https://git.kernel.org/stable/c/eb3836eab47487823f362e6985e170a1e15f20fd"
},
{
"url": "https://git.kernel.org/stable/c/44401f7dd9940ced7098930ef64f5a332f279fc2"
},
{
"url": "https://git.kernel.org/stable/c/5d07b178bef511d69558cfc89fe1129258dc39f8"
},
{
"url": "https://git.kernel.org/stable/c/0e37bbd6d617eb52bace49390e99eaedc1af73ce"
},
{
"url": "https://git.kernel.org/stable/c/ee7f9bb9320add61f7b367d7e6cd55e3a3a4d65d"
}
],
"title": "net: slip: serialize receive against buffer reallocation",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68143",
"datePublished": "2026-08-10T11:59:07.354Z",
"dateReserved": "2026-07-30T09:28:09.370Z",
"dateUpdated": "2026-08-19T16:30:04.807Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72040 (GCVE-0-2026-72040)
Vulnerability from cvelistv5
Published
2026-08-15 05:51
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ipmi: fix refcount leak in i_ipmi_request()
When a caller provides a `supplied_recv` message to i_ipmi_request(),
the function increments the user's `nr_msgs` reference count. If an
error occurs later, the out_err cleanup path only frees the recv_msg
if the function allocated it itself (i.e., !supplied_recv). In the
supplied_recv case the cleanup is skipped, leaving the reference count
elevated. The caller ipmi_request_supply_msgs() does not release the
supplied_recv on error, so the reference is permanently leaked.
Fix this by explicitly reverting the reference count operations when a
supplied recv_msg with a valid user pointer is present in the error
path: decrement nr_msgs and drop the user's kref.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: f63723ca7d7623f9dae1990973cd158671f03c56 Version: 348121b29594d42d1635648fd3ed31dfa25351d5 Version: 53d6e403affbf6df2c859a0ea00ccfc1e72090ca Version: b52da4054ee0bf9ecb44996f2c83236ff50b3812 Version: b52da4054ee0bf9ecb44996f2c83236ff50b3812 Version: b52da4054ee0bf9ecb44996f2c83236ff50b3812 Version: 0ed73be9a2547ffb9b5c1d879ad9bfab73d920b5 Version: 6.1.157 ≤ Version: 6.6.113 ≤ Version: 6.12.54 ≤ Version: 6.17.4 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/char/ipmi/ipmi_msghandler.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "122ca6b2af714e114c9b872a48372ace31a9ab1f",
"status": "affected",
"version": "f63723ca7d7623f9dae1990973cd158671f03c56",
"versionType": "git"
},
{
"lessThan": "9409e18ffe7378d202efe1cf69989df9f67b0369",
"status": "affected",
"version": "348121b29594d42d1635648fd3ed31dfa25351d5",
"versionType": "git"
},
{
"lessThan": "e2a3b77df6aef031455dd83ea8ed4344b7dca1f9",
"status": "affected",
"version": "53d6e403affbf6df2c859a0ea00ccfc1e72090ca",
"versionType": "git"
},
{
"lessThan": "f5c5065963024390ddad51bd455d1adc710de575",
"status": "affected",
"version": "b52da4054ee0bf9ecb44996f2c83236ff50b3812",
"versionType": "git"
},
{
"lessThan": "0fd23994ec8c5436d9f0b50848deb87ed933e6b3",
"status": "affected",
"version": "b52da4054ee0bf9ecb44996f2c83236ff50b3812",
"versionType": "git"
},
{
"lessThan": "a3f3859cecacb64f18fd446271ece9a3b3f2d4de",
"status": "affected",
"version": "b52da4054ee0bf9ecb44996f2c83236ff50b3812",
"versionType": "git"
},
{
"status": "affected",
"version": "0ed73be9a2547ffb9b5c1d879ad9bfab73d920b5",
"versionType": "git"
},
{
"lessThan": "6.1.184",
"status": "affected",
"version": "6.1.157",
"versionType": "semver"
},
{
"lessThan": "6.6.148",
"status": "affected",
"version": "6.6.113",
"versionType": "semver"
},
{
"lessThan": "6.12.101",
"status": "affected",
"version": "6.12.54",
"versionType": "semver"
},
{
"lessThan": "6.18",
"status": "affected",
"version": "6.17.4",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/char/ipmi/ipmi_msghandler.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.18"
},
{
"lessThan": "6.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "6.1.157",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.6.113",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.12.54",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "6.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "6.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.17.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nipmi: fix refcount leak in i_ipmi_request()\n\nWhen a caller provides a `supplied_recv` message to i_ipmi_request(),\nthe function increments the user\u0027s `nr_msgs` reference count. If an\nerror occurs later, the out_err cleanup path only frees the recv_msg\nif the function allocated it itself (i.e., !supplied_recv). In the\nsupplied_recv case the cleanup is skipped, leaving the reference count\nelevated. The caller ipmi_request_supply_msgs() does not release the\nsupplied_recv on error, so the reference is permanently leaked.\n\nFix this by explicitly reverting the reference count operations when a\nsupplied recv_msg with a valid user pointer is present in the error\npath: decrement nr_msgs and drop the user\u0027s kref."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:30.954Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/122ca6b2af714e114c9b872a48372ace31a9ab1f"
},
{
"url": "https://git.kernel.org/stable/c/9409e18ffe7378d202efe1cf69989df9f67b0369"
},
{
"url": "https://git.kernel.org/stable/c/e2a3b77df6aef031455dd83ea8ed4344b7dca1f9"
},
{
"url": "https://git.kernel.org/stable/c/f5c5065963024390ddad51bd455d1adc710de575"
},
{
"url": "https://git.kernel.org/stable/c/0fd23994ec8c5436d9f0b50848deb87ed933e6b3"
},
{
"url": "https://git.kernel.org/stable/c/a3f3859cecacb64f18fd446271ece9a3b3f2d4de"
}
],
"title": "ipmi: fix refcount leak in i_ipmi_request()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72040",
"datePublished": "2026-08-15T05:51:59.975Z",
"dateReserved": "2026-08-09T03:40:39.901Z",
"dateUpdated": "2026-08-23T12:46:30.954Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68104 (GCVE-0-2026-68104)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-19 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: invoke pm_genpd_remove() before freeing genpd
Call pm_genpd_remove() to unregister from global list prior to releasing
acp_genpd memory, and clear the pointer after free.
(cherry picked from commit cd8650d7a91ee8b768e202354672553faa5cc1f2)
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 25030321ba2860c56651429a4f28d94a6483d952 Version: 25030321ba2860c56651429a4f28d94a6483d952 Version: 25030321ba2860c56651429a4f28d94a6483d952 Version: 25030321ba2860c56651429a4f28d94a6483d952 Version: 25030321ba2860c56651429a4f28d94a6483d952 Version: 25030321ba2860c56651429a4f28d94a6483d952 Version: 25030321ba2860c56651429a4f28d94a6483d952 Version: 25030321ba2860c56651429a4f28d94a6483d952 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/amdgpu_acp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "4d7c10b0bf09d90c81818752decbdb1966b62702",
"status": "affected",
"version": "25030321ba2860c56651429a4f28d94a6483d952",
"versionType": "git"
},
{
"lessThan": "493adf29d66f23888f0e29888b6bc9512acd0825",
"status": "affected",
"version": "25030321ba2860c56651429a4f28d94a6483d952",
"versionType": "git"
},
{
"lessThan": "2e406b86144c1f732eb344f1f1e09043856cfc33",
"status": "affected",
"version": "25030321ba2860c56651429a4f28d94a6483d952",
"versionType": "git"
},
{
"lessThan": "bdfc7f1e0900ef1361b828c4f69b72701f8a0a86",
"status": "affected",
"version": "25030321ba2860c56651429a4f28d94a6483d952",
"versionType": "git"
},
{
"lessThan": "5c0a82283271759fff445ac27182072f200a888c",
"status": "affected",
"version": "25030321ba2860c56651429a4f28d94a6483d952",
"versionType": "git"
},
{
"lessThan": "08fee493e0261f9e4120a5c8e7e42e8a723574e8",
"status": "affected",
"version": "25030321ba2860c56651429a4f28d94a6483d952",
"versionType": "git"
},
{
"lessThan": "930a5dc3df4aa5e10393134bd5313d616dbebaf6",
"status": "affected",
"version": "25030321ba2860c56651429a4f28d94a6483d952",
"versionType": "git"
},
{
"lessThan": "28c9b3c5dc35cc790d11e26ca3fc6e068be63998",
"status": "affected",
"version": "25030321ba2860c56651429a4f28d94a6483d952",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/amdgpu_acp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.6"
},
{
"lessThan": "4.6",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: invoke pm_genpd_remove() before freeing genpd\n\nCall pm_genpd_remove() to unregister from global list prior to releasing\nacp_genpd memory, and clear the pointer after free.\n\n(cherry picked from commit cd8650d7a91ee8b768e202354672553faa5cc1f2)"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is in acp_hw_fini during amdgpu driver teardown (amdgpu_pci_remove/amdgpu_driver_unload_kms), reachable via local PCI unbind/module unload or a failed amdgpu init cleanup after opening a DRM render node; there is no network-facing entry point.\nAC:L - Once the AMDGPU ACP block has been initialized, calling acp_hw_fini deterministically frees acp_genpd without unregistering it from the global genpd list; no race or special memory layout is required to leave a dangling list entry.\nPR:L - Unprivileged users with access to /dev/dri/renderD* can autoload amdgpu and trigger the fini path if initialization fails after ACP setup; the same bug also fires on privileged driver unload/hot-unplug teardown of AMDGPU on ACP-capable APUs (Carrizo/Stoney).\nUI:N - Exploitation does not require any victim interaction such as clicking links or mounting filesystems; triggering driver teardown or a failed init cleanup is sufficient once the attacker can open the DRM device or unload the driver.\nS:U - The use-after-free corrupts kernel heap metadata/objects in the same kernel security domain during AMDGPU/ACP teardown; it does not by itself cross VM, container, or IOMMU boundaries to impact a separate authority.\nC:H - Freeing the generic_pm_domain while it remains linked on the global gpd_list is a kernel use-after-free; subsequent genpd list walks can read attacker-influenced freed memory, enabling information disclosure and kernel pointer leaks.\nI:H - The dangling genpd entry allows the power-domain core to perform reads/writes through a freed acp_pm_domain/generic_pm_domain object, providing a standard heap UAF primitive that can be developed into arbitrary kernel memory corruption or code execution.\nA:H - Dereferencing the freed genpd from the global list during later power-management operations can cause kernel oops/panic or hang, and the UAF can be leveraged for a reliable denial-of-service even when full exploitation is not attempted."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:29:17.502Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/4d7c10b0bf09d90c81818752decbdb1966b62702"
},
{
"url": "https://git.kernel.org/stable/c/493adf29d66f23888f0e29888b6bc9512acd0825"
},
{
"url": "https://git.kernel.org/stable/c/2e406b86144c1f732eb344f1f1e09043856cfc33"
},
{
"url": "https://git.kernel.org/stable/c/bdfc7f1e0900ef1361b828c4f69b72701f8a0a86"
},
{
"url": "https://git.kernel.org/stable/c/5c0a82283271759fff445ac27182072f200a888c"
},
{
"url": "https://git.kernel.org/stable/c/08fee493e0261f9e4120a5c8e7e42e8a723574e8"
},
{
"url": "https://git.kernel.org/stable/c/930a5dc3df4aa5e10393134bd5313d616dbebaf6"
},
{
"url": "https://git.kernel.org/stable/c/28c9b3c5dc35cc790d11e26ca3fc6e068be63998"
}
],
"title": "drm/amdgpu: invoke pm_genpd_remove() before freeing genpd",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68104",
"datePublished": "2026-08-10T11:58:20.614Z",
"dateReserved": "2026-07-30T09:28:09.368Z",
"dateUpdated": "2026-08-19T16:29:17.502Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68119 (GCVE-0-2026-68119)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-17 04:59
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
tcp: initialize standalone TCP-AO response padding
tcp_v4_send_ack() and tcp_v6_send_response() construct standalone TCP
responses with TCP-AO options. The option length carries the actual MAC
length, but the TCP header length includes the option rounded up to a
four-byte boundary.
tcp_ao_hash_hdr() writes the MAC only. Thus, when the MAC length is not
four-byte aligned, the one to three bytes after the MAC are left
uninitialized and may be transmitted. For the normal TCP-AO hashing
mode, those bytes also have to be initialized before computing the MAC.
Initialize only the alignment padding in the TCP-AO branches, before
hashing the header. Use TCPOPT_NOP, as in the normal TCP-AO output path.
This avoids adding work to non-AO TCP responses while preserving a valid
authenticated header.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ipv4/tcp_ipv4.c",
"net/ipv6/tcp_ipv6.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "bbb7db8c74b0b5d17a695136f0f0806ecd0118f6",
"status": "affected",
"version": "decde2586b34b99684faff1eab41e5c496c27fb6",
"versionType": "git"
},
{
"lessThan": "fadaff3f66e124c3a62237f9c881819a8ac90309",
"status": "affected",
"version": "decde2586b34b99684faff1eab41e5c496c27fb6",
"versionType": "git"
},
{
"lessThan": "a859b280441fb02f64ed4037f03d5c0c34a7a595",
"status": "affected",
"version": "decde2586b34b99684faff1eab41e5c496c27fb6",
"versionType": "git"
},
{
"lessThan": "e1a9d3cc11829c5414a75eb39c704f461936eb24",
"status": "affected",
"version": "decde2586b34b99684faff1eab41e5c496c27fb6",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ipv4/tcp_ipv4.c",
"net/ipv6/tcp_ipv6.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.7"
},
{
"lessThan": "6.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: initialize standalone TCP-AO response padding\n\ntcp_v4_send_ack() and tcp_v6_send_response() construct standalone TCP\nresponses with TCP-AO options. The option length carries the actual MAC\nlength, but the TCP header length includes the option rounded up to a\nfour-byte boundary.\n\ntcp_ao_hash_hdr() writes the MAC only. Thus, when the MAC length is not\nfour-byte aligned, the one to three bytes after the MAC are left\nuninitialized and may be transmitted. For the normal TCP-AO hashing\nmode, those bytes also have to be initialized before computing the MAC.\n\nInitialize only the alignment padding in the TCP-AO branches, before\nhashing the header. Use TCPOPT_NOP, as in the normal TCP-AO output path.\nThis avoids adding work to non-AO TCP responses while preserving a valid\nauthenticated header."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - Remote attackers reach tcp_v4_send_ack() and tcp_v6_send_response() by sending IPv4/IPv6 TCP segments into tcp_v4_rcv()/tcp_v6_rcv() SYN-RECV, TIME-WAIT, and reset paths that build standalone TCP-AO-signed ACK/RST replies transmitted back over the network.\nAC:L - On Internet-facing TCP-AO deployments (BGP/route-server successors to TCP-MD5), an attacker reliably elicits qualifying standalone responses by sending crafted TCP segments; no race, timing lottery, or uncontrollable memory layout is required beyond the peer using a non-4-byte-aligned MAC length.\nPR:N - The uninitialized bytes are returned to the remote packet sender in standalone TCP-AO ACK/RST replies; triggering requires only network reachability to a TCP-AO-enabled listener or an existing TCP-AO TIME-WAIT socket, with no local credentials on the victim host.\nUI:N - No end-user action is needed beyond normal exposure of a TCP-AO-protected network service; the attacker alone sends the triggering TCP segments and captures the padded replies.\nS:U - Kernel stack or skb memory is disclosed to a remote TCP peer within the same host kernel security authority; this is not a VM escape, IOMMU bypass, or other cross-boundary scope change.\nC:H - One to three uninitialized bytes in TCP-AO option alignment padding from the on-stack IPv4 response buffer or IPv6 skb head are transmitted on every qualifying standalone ACK/RST and can be harvested repeatedly to recover kernel stack or skb contents.\nI:N - The bug only fails to initialize alignment padding before transmission; it does not write to or corrupt kernel, socket, or application memory.\nA:N - Standalone TCP-AO responses are still transmitted successfully with no kernel oops, panic, hang, or denial of service; only confidentiality of the leaked padding bytes is affected."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:59:09.650Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/bbb7db8c74b0b5d17a695136f0f0806ecd0118f6"
},
{
"url": "https://git.kernel.org/stable/c/fadaff3f66e124c3a62237f9c881819a8ac90309"
},
{
"url": "https://git.kernel.org/stable/c/a859b280441fb02f64ed4037f03d5c0c34a7a595"
},
{
"url": "https://git.kernel.org/stable/c/e1a9d3cc11829c5414a75eb39c704f461936eb24"
}
],
"title": "tcp: initialize standalone TCP-AO response padding",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68119",
"datePublished": "2026-08-10T11:58:39.026Z",
"dateReserved": "2026-07-30T09:28:09.369Z",
"dateUpdated": "2026-08-17T04:59:09.650Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68188 (GCVE-0-2026-68188)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: RFCOMM: Fix session UAF in set_termios
rfcomm_tty_set_termios() tests dlc->session without rfcomm_mutex and
later passes the pointer to rfcomm_send_rpn(). The latter dereferences
both session->initiator and session->sock. Meanwhile, krfcommd can
unlink the DLC and free the session while holding rfcomm_mutex.
The race can proceed as follows:
TTY ioctl task krfcommd
-------------- --------
load dlc->session
enter rfcomm_send_rpn()
lock rfcomm_mutex
clear dlc->session
free session
unlock rfcomm_mutex
read session->initiator
KASAN reported:
BUG: KASAN: slab-use-after-free in rfcomm_send_rpn+0x297/0x2a0
Read of size 4 at addr ffff88810012a850 by task poc/92
Call Trace:
rfcomm_send_rpn+0x297/0x2a0
rfcomm_tty_set_termios+0x50d/0x850
tty_set_termios+0x596/0x950
set_termios+0x46a/0x6e0
tty_mode_ioctl+0x152/0xbd0
tty_ioctl+0x915/0x1240
__x64_sys_ioctl+0x134/0x1c0
Allocated by task 92:
rfcomm_session_add+0x9e/0x2e0
rfcomm_dlc_open+0x8b1/0xe00
rfcomm_dev_activate+0x85/0x1a0
rfcomm_tty_open+0x90/0x280
Freed by task 68:
kfree+0x131/0x3c0
rfcomm_session_del+0x119/0x180
rfcomm_run+0x737/0x4710
Add rfcomm_dlc_send_rpn(), which holds rfcomm_mutex while it verifies
that the DLC is still attached and sends the RPN frame. Have the TTY
path use the helper and drop its unlocked session check. This keeps the
session valid through both the frame construction and socket send.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 3a5e903c09aed19ca4a1bb26d87b8d6461a93818 Version: 3a5e903c09aed19ca4a1bb26d87b8d6461a93818 Version: 3a5e903c09aed19ca4a1bb26d87b8d6461a93818 Version: 3a5e903c09aed19ca4a1bb26d87b8d6461a93818 Version: 3a5e903c09aed19ca4a1bb26d87b8d6461a93818 Version: 3a5e903c09aed19ca4a1bb26d87b8d6461a93818 Version: 3a5e903c09aed19ca4a1bb26d87b8d6461a93818 Version: 3a5e903c09aed19ca4a1bb26d87b8d6461a93818 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"include/net/bluetooth/rfcomm.h",
"net/bluetooth/rfcomm/core.c",
"net/bluetooth/rfcomm/tty.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "4eac4576a072084b06459de6c054b4ebc764b4ea",
"status": "affected",
"version": "3a5e903c09aed19ca4a1bb26d87b8d6461a93818",
"versionType": "git"
},
{
"lessThan": "82c383f9031f1ce919ac6c3c06bc5bd492a6b078",
"status": "affected",
"version": "3a5e903c09aed19ca4a1bb26d87b8d6461a93818",
"versionType": "git"
},
{
"lessThan": "c5c060597247131f90f39ea7c8c978fa0c2e79d0",
"status": "affected",
"version": "3a5e903c09aed19ca4a1bb26d87b8d6461a93818",
"versionType": "git"
},
{
"lessThan": "2894bd8c68e97accd758ca6e5fc375d7e9e8882c",
"status": "affected",
"version": "3a5e903c09aed19ca4a1bb26d87b8d6461a93818",
"versionType": "git"
},
{
"lessThan": "a82a9d3891f5607030b0672c255087a12bb9837b",
"status": "affected",
"version": "3a5e903c09aed19ca4a1bb26d87b8d6461a93818",
"versionType": "git"
},
{
"lessThan": "780b04d09c941262ee2a2b4a09906451b69df8a6",
"status": "affected",
"version": "3a5e903c09aed19ca4a1bb26d87b8d6461a93818",
"versionType": "git"
},
{
"lessThan": "98bc68194e37bfa5e8ddc80b5c1eb0be4dc607ea",
"status": "affected",
"version": "3a5e903c09aed19ca4a1bb26d87b8d6461a93818",
"versionType": "git"
},
{
"lessThan": "c783399efc22d035443f1dfbf2a09bf9562aaa5e",
"status": "affected",
"version": "3a5e903c09aed19ca4a1bb26d87b8d6461a93818",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"include/net/bluetooth/rfcomm.h",
"net/bluetooth/rfcomm/core.c",
"net/bluetooth/rfcomm/tty.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.14"
},
{
"lessThan": "2.6.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: RFCOMM: Fix session UAF in set_termios\n\nrfcomm_tty_set_termios() tests dlc-\u003esession without rfcomm_mutex and\nlater passes the pointer to rfcomm_send_rpn(). The latter dereferences\nboth session-\u003einitiator and session-\u003esock. Meanwhile, krfcommd can\nunlink the DLC and free the session while holding rfcomm_mutex.\n\nThe race can proceed as follows:\n\n TTY ioctl task krfcommd\n -------------- --------\n load dlc-\u003esession\n enter rfcomm_send_rpn()\n lock rfcomm_mutex\n clear dlc-\u003esession\n free session\n unlock rfcomm_mutex\n read session-\u003einitiator\n\nKASAN reported:\n\n BUG: KASAN: slab-use-after-free in rfcomm_send_rpn+0x297/0x2a0\n Read of size 4 at addr ffff88810012a850 by task poc/92\n\n Call Trace:\n rfcomm_send_rpn+0x297/0x2a0\n rfcomm_tty_set_termios+0x50d/0x850\n tty_set_termios+0x596/0x950\n set_termios+0x46a/0x6e0\n tty_mode_ioctl+0x152/0xbd0\n tty_ioctl+0x915/0x1240\n __x64_sys_ioctl+0x134/0x1c0\n\n Allocated by task 92:\n rfcomm_session_add+0x9e/0x2e0\n rfcomm_dlc_open+0x8b1/0xe00\n rfcomm_dev_activate+0x85/0x1a0\n rfcomm_tty_open+0x90/0x280\n\n Freed by task 68:\n kfree+0x131/0x3c0\n rfcomm_session_del+0x119/0x180\n rfcomm_run+0x737/0x4710\n\nAdd rfcomm_dlc_send_rpn(), which holds rfcomm_mutex while it verifies\nthat the DLC is still attached and sends the RPN frame. Have the TTY\npath use the helper and drop its unlocked session check. This keeps the\nsession valid through both the frame construction and socket send."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:30:59.491Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/4eac4576a072084b06459de6c054b4ebc764b4ea"
},
{
"url": "https://git.kernel.org/stable/c/82c383f9031f1ce919ac6c3c06bc5bd492a6b078"
},
{
"url": "https://git.kernel.org/stable/c/c5c060597247131f90f39ea7c8c978fa0c2e79d0"
},
{
"url": "https://git.kernel.org/stable/c/2894bd8c68e97accd758ca6e5fc375d7e9e8882c"
},
{
"url": "https://git.kernel.org/stable/c/a82a9d3891f5607030b0672c255087a12bb9837b"
},
{
"url": "https://git.kernel.org/stable/c/780b04d09c941262ee2a2b4a09906451b69df8a6"
},
{
"url": "https://git.kernel.org/stable/c/98bc68194e37bfa5e8ddc80b5c1eb0be4dc607ea"
},
{
"url": "https://git.kernel.org/stable/c/c783399efc22d035443f1dfbf2a09bf9562aaa5e"
}
],
"title": "Bluetooth: RFCOMM: Fix session UAF in set_termios",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68188",
"datePublished": "2026-08-10T12:00:00.521Z",
"dateReserved": "2026-07-30T09:28:09.373Z",
"dateUpdated": "2026-08-19T16:30:59.491Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68184 (GCVE-0-2026-68184)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
cdrom: fix stack out-of-bounds read in CDROMVOLCTRL
mmc_ioctl_cdrom_volume() first reads the audio control mode page into a
32-byte stack buffer with cgc->buflen set to 24. If the device reports a
block descriptor, the function increases cgc->buflen to include that
descriptor and reads the page again.
For CDROMVOLCTRL, the function then builds a MODE SELECT parameter list
by moving cgc->buffer forward by offset - 8 bytes. This drops the block
descriptor from the outgoing payload and leaves a new 8-byte mode
parameter header in front of the audio control page. However, cgc->buflen
is left unchanged.
With a standard 8-byte block descriptor, cgc->buffer points at buffer + 8
but cgc->buflen remains 32. cdrom_mode_select() therefore asks the low
level packet path to write 32 bytes from that adjusted pointer, reading 8
bytes past the end of the 32-byte stack buffer.
This is not hit by CDROMVOLREAD, and CDROMVOLCTRL only triggers it on
drives that return a non-zero block descriptor length, which helps explain
why it has gone unnoticed. The overread is also sent to the device as
extra MODE SELECT payload, so it may not produce an obvious local failure.
Reduce cgc->buflen by the same amount as the buffer pointer adjustment so
the MODE SELECT transfer covers only the intended parameter list.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/cdrom/cdrom.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "45c65df5339deea3cf204902aac383fe995941a7",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "0329b661349f42f9616f2733da67edffbbb8455d",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "e150c9a10baee55d3bfbc96dbe66b205e8b4fd44",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "7344c84e32413e5c8832f74b8a612b0194e5c051",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "35b68e24c5a69fa4545f46f05f6c849223034cb6",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "d43c5c0c935522deae7339e0c2399365f3bf0016",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "f3e2715a150066f09aa82c30fa983fb184ad6dd5",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "b27e195d4db8dea263050bdbeb11881b2999c9c6",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/cdrom/cdrom.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncdrom: fix stack out-of-bounds read in CDROMVOLCTRL\n\nmmc_ioctl_cdrom_volume() first reads the audio control mode page into a\n32-byte stack buffer with cgc-\u003ebuflen set to 24. If the device reports a\nblock descriptor, the function increases cgc-\u003ebuflen to include that\ndescriptor and reads the page again.\n\nFor CDROMVOLCTRL, the function then builds a MODE SELECT parameter list\nby moving cgc-\u003ebuffer forward by offset - 8 bytes. This drops the block\ndescriptor from the outgoing payload and leaves a new 8-byte mode\nparameter header in front of the audio control page. However, cgc-\u003ebuflen\nis left unchanged.\n\nWith a standard 8-byte block descriptor, cgc-\u003ebuffer points at buffer + 8\nbut cgc-\u003ebuflen remains 32. cdrom_mode_select() therefore asks the low\nlevel packet path to write 32 bytes from that adjusted pointer, reading 8\nbytes past the end of the 32-byte stack buffer.\n\nThis is not hit by CDROMVOLREAD, and CDROMVOLCTRL only triggers it on\ndrives that return a non-zero block descriptor length, which helps explain\nwhy it has gone unnoticed. The overread is also sent to the device as\nextra MODE SELECT payload, so it may not produce an obvious local failure.\n\nReduce cgc-\u003ebuflen by the same amount as the buffer pointer adjustment so\nthe MODE SELECT transfer covers only the intended parameter list."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:30:51.908Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/45c65df5339deea3cf204902aac383fe995941a7"
},
{
"url": "https://git.kernel.org/stable/c/0329b661349f42f9616f2733da67edffbbb8455d"
},
{
"url": "https://git.kernel.org/stable/c/e150c9a10baee55d3bfbc96dbe66b205e8b4fd44"
},
{
"url": "https://git.kernel.org/stable/c/7344c84e32413e5c8832f74b8a612b0194e5c051"
},
{
"url": "https://git.kernel.org/stable/c/35b68e24c5a69fa4545f46f05f6c849223034cb6"
},
{
"url": "https://git.kernel.org/stable/c/d43c5c0c935522deae7339e0c2399365f3bf0016"
},
{
"url": "https://git.kernel.org/stable/c/f3e2715a150066f09aa82c30fa983fb184ad6dd5"
},
{
"url": "https://git.kernel.org/stable/c/b27e195d4db8dea263050bdbeb11881b2999c9c6"
}
],
"title": "cdrom: fix stack out-of-bounds read in CDROMVOLCTRL",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68184",
"datePublished": "2026-08-10T11:59:56.319Z",
"dateReserved": "2026-07-30T09:28:09.373Z",
"dateUpdated": "2026-08-19T16:30:51.908Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68152 (GCVE-0-2026-68152)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-17 04:59
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
amt: fix use-after-free in AMT delayed works
When an AMT device is removed, pending delayed works can still access
the freed amt_dev structure, which may result in kernel crashes or
memory corruption.
amt_dev_stop() cancels req_wq and discovery_wq with
cancel_delayed_work_sync(), but these works can be scheduled again
from event_wq after the cancellation. This allows delayed works to
access the freed amt_dev structure after the netdev has been released.
The following is a simple race scenario:
CPU0 CPU1
amt_dev_stop()
cancel_delayed_work_sync()
amt_event_work()
mod_delayed_work(req_wq)
free netdev
req_wq accesses freed amt_dev
Use disable_delayed_work_sync() in amt_dev_stop() to prevent req_wq and
discovery_wq from being queued again and wait for running work items
to complete.
The delayed works are disabled after initialization in
amt_newlink() and enabled only when the device is successfully opened.
This keeps the delayed work lifecycle synchronized with the lifetime
of the AMT device.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/amt.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a46bfa01e01df0f6f6dc4b0be18db002d6d2dbd2",
"status": "affected",
"version": "cbc21dc1cfe949e37b2a54c71511579f1899e8d4",
"versionType": "git"
},
{
"lessThan": "1a644db2cf59f164cdf3c75995bab5aadc097528",
"status": "affected",
"version": "cbc21dc1cfe949e37b2a54c71511579f1899e8d4",
"versionType": "git"
},
{
"lessThan": "006340cf06881b6ff49767d8b6f3c4f7b892670c",
"status": "affected",
"version": "cbc21dc1cfe949e37b2a54c71511579f1899e8d4",
"versionType": "git"
},
{
"lessThan": "ea20c44935d6142daecfa9b39d635033a7553e1b",
"status": "affected",
"version": "cbc21dc1cfe949e37b2a54c71511579f1899e8d4",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/amt.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.16"
},
{
"lessThan": "5.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.16",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\namt: fix use-after-free in AMT delayed works\n\nWhen an AMT device is removed, pending delayed works can still access\nthe freed amt_dev structure, which may result in kernel crashes or\nmemory corruption.\n\namt_dev_stop() cancels req_wq and discovery_wq with\ncancel_delayed_work_sync(), but these works can be scheduled again\nfrom event_wq after the cancellation. This allows delayed works to\naccess the freed amt_dev structure after the netdev has been released.\n\nThe following is a simple race scenario:\n\nCPU0 CPU1\n\namt_dev_stop()\ncancel_delayed_work_sync()\n amt_event_work()\n mod_delayed_work(req_wq)\nfree netdev\n req_wq accesses freed amt_dev\n\nUse disable_delayed_work_sync() in amt_dev_stop() to prevent req_wq and\ndiscovery_wq from being queued again and wait for running work items\nto complete.\n\nThe delayed works are disabled after initialization in\namt_newlink() and enabled only when the device is successfully opened.\nThis keeps the delayed work lifecycle synchronized with the lifetime\nof the AMT device."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires triggering amt_dev_stop() via local rtnetlink (RTM_DELLINK/ip link del) or ndo_stop on an AMT gateway netdev; the UAF race in teardown is not reachable by remote UDP alone without this privileged local device-removal path.\nAC:L - The attacker controls both sides of the race by concurrently deleting/bringing down the AMT interface while flooding AMT UDP packets or letting discovery/request timers fire, reliably re-queuing req_wq/discovery_wq via amt_event_work during the cancel_work_sync window.\nPR:L - Creating, opening, and removing AMT virtual interfaces requires CAP_NET_ADMIN via rtnetlink, which unprivileged users can obtain inside a user network namespace (unshare -Urn), but not without any privileges at all.\nUI:N - No victim user interaction is required; a single attacker with namespace CAP_NET_ADMIN can create an AMT gateway, bring it up, and race interface teardown against self-generated AMT traffic or delayed-work events.\nS:U - Successful exploitation corrupts kernel heap memory and can escalate privileges within the same kernel, but does not inherently cross VM, container, or IOMMU security boundaries into a separate authority domain.\nC:H - Use-after-free of the amt_dev structure embedded in netdev private data allows accessing attacker-influenced freed heap memory, enabling arbitrary kernel memory disclosure through standard UAF exploitation techniques.\nI:H - The UAF on amt_dev delayed-work handlers can corrupt kernel heap metadata and adjacent objects, providing primitives for arbitrary kernel memory writes and potential code execution as acknowledged in the fix commit.\nA:H - Use-after-free in amt_req_work/amt_discovery_work accessing freed amt_dev during netdev teardown can cause kernel oops, panic, or hang, and the fix commit explicitly warns of kernel crashes and memory corruption."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:59:47.614Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a46bfa01e01df0f6f6dc4b0be18db002d6d2dbd2"
},
{
"url": "https://git.kernel.org/stable/c/1a644db2cf59f164cdf3c75995bab5aadc097528"
},
{
"url": "https://git.kernel.org/stable/c/006340cf06881b6ff49767d8b6f3c4f7b892670c"
},
{
"url": "https://git.kernel.org/stable/c/ea20c44935d6142daecfa9b39d635033a7553e1b"
}
],
"title": "amt: fix use-after-free in AMT delayed works",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68152",
"datePublished": "2026-08-10T11:59:18.270Z",
"dateReserved": "2026-07-30T09:28:09.371Z",
"dateUpdated": "2026-08-17T04:59:47.614Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72118 (GCVE-0-2026-72118)
Vulnerability from cvelistv5
Published
2026-08-15 05:52
Modified
2026-08-19 16:36
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
can: bcm: fix CAN frame rx/tx statistics
KCSAN detected a data race within the bcm_rx_handler() when two CAN frames
have been simultaneously received and processed in a single rx op by two
different CPUs.
Use atomic operations with (signed) long data types to access the
statistics in the hot path to fix the KCSAN complaint.
Additionally simplify the update and check of statistics overflow by
using the atomic operations in separate bcm_update_[rx|tx]_stats()
functions. The rx variant runs under bcm_rx_update_lock to prevent
races when resetting the two rx counters; the tx variant runs under
bcm_tx_lock and only needs to guard its own counter's overflow.
As the rx path resets its values already at LONG_MAX / 100, there is
no conflict between the two locking domains (bcm_rx_update_lock vs.
bcm_tx_lock) even for ops that use both paths.
The rx statistics update and the frames_filtered update in
bcm_rx_changed() were previously performed in two separate
bcm_rx_update_lock sections. For an rx op subscribed on all interfaces
(ifindex == 0), bcm_rx_handler() can run concurrently on different
CPUs, so a counter reset by one CPU between these two sections could
leave frames_filtered larger than frames_abs on another CPU, producing
a bogus (even negative) reduction percentage in procfs. Update the
statistics in the same critical section as bcm_rx_changed() to close
this gap, which also removes the now unneeded extra lock/unlock pair
around the traffic_flags calculation.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/can/bcm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "640acf3566fc897065127001be875ebc5401c218",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "47fca0d1620f2d4fab0677564989ef2b9c225c66",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "fd75884eae40a7be47867cbfc9fc84a80bb8ddb4",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "8b2783172d92edd650de6006ebd1c800937021ab",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "970caff5c1a63702c80e08d920256bcb5f88ecc5",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "8104bcdb2612fdda95169ddc3b49747b2ff98d24",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "df47f07cdc801a6afe05a486b5a343c3e532a93c",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "e6c24ba95fc3f1b5e1dcd28b1c6e59ef61a9daa5",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/can/bcm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.25"
},
{
"lessThan": "2.6.25",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.25",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: bcm: fix CAN frame rx/tx statistics\n\nKCSAN detected a data race within the bcm_rx_handler() when two CAN frames\nhave been simultaneously received and processed in a single rx op by two\ndifferent CPUs.\n\nUse atomic operations with (signed) long data types to access the\nstatistics in the hot path to fix the KCSAN complaint.\n\nAdditionally simplify the update and check of statistics overflow by\nusing the atomic operations in separate bcm_update_[rx|tx]_stats()\nfunctions. The rx variant runs under bcm_rx_update_lock to prevent\nraces when resetting the two rx counters; the tx variant runs under\nbcm_tx_lock and only needs to guard its own counter\u0027s overflow.\n\nAs the rx path resets its values already at LONG_MAX / 100, there is\nno conflict between the two locking domains (bcm_rx_update_lock vs.\nbcm_tx_lock) even for ops that use both paths.\n\nThe rx statistics update and the frames_filtered update in\nbcm_rx_changed() were previously performed in two separate\nbcm_rx_update_lock sections. For an rx op subscribed on all interfaces\n(ifindex == 0), bcm_rx_handler() can run concurrently on different\nCPUs, so a counter reset by one CPU between these two sections could\nleave frames_filtered larger than frames_abs on another CPU, producing\na bogus (even negative) reduction percentage in procfs. Update the\nstatistics in the same critical section as bcm_rx_changed() to close\nthis gap, which also removes the now unneeded extra lock/unlock pair\naround the traffic_flags calculation."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:36:11.603Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/640acf3566fc897065127001be875ebc5401c218"
},
{
"url": "https://git.kernel.org/stable/c/47fca0d1620f2d4fab0677564989ef2b9c225c66"
},
{
"url": "https://git.kernel.org/stable/c/fd75884eae40a7be47867cbfc9fc84a80bb8ddb4"
},
{
"url": "https://git.kernel.org/stable/c/8b2783172d92edd650de6006ebd1c800937021ab"
},
{
"url": "https://git.kernel.org/stable/c/970caff5c1a63702c80e08d920256bcb5f88ecc5"
},
{
"url": "https://git.kernel.org/stable/c/8104bcdb2612fdda95169ddc3b49747b2ff98d24"
},
{
"url": "https://git.kernel.org/stable/c/df47f07cdc801a6afe05a486b5a343c3e532a93c"
},
{
"url": "https://git.kernel.org/stable/c/e6c24ba95fc3f1b5e1dcd28b1c6e59ef61a9daa5"
}
],
"title": "can: bcm: fix CAN frame rx/tx statistics",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72118",
"datePublished": "2026-08-15T05:52:57.734Z",
"dateReserved": "2026-08-09T03:40:39.906Z",
"dateUpdated": "2026-08-19T16:36:11.603Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64576 (GCVE-0-2026-64576)
Vulnerability from cvelistv5
Published
2026-08-05 08:09
Modified
2026-08-19 16:28
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
nexthop: initialize extack in nh_res_bucket_migrate()
nh_res_bucket_migrate() passes an uninitialized netlink_ext_ack to
call_nexthop_res_bucket_notifiers(). When
nh_notifier_res_bucket_info_init() fails (e.g. the kzalloc returns
-ENOMEM), the error is propagated back before any notifier sets
extack._msg, and the error path formats the stale pointer with
pr_err_ratelimited("%s\n", extack._msg). With CONFIG_INIT_STACK_NONE
this dereferences uninitialized stack memory:
Oops: general protection fault, probably for non-canonical address ...
KASAN: maybe wild-memory-access in range [...]
RIP: 0010:string (lib/vsprintf.c:730)
vsnprintf (lib/vsprintf.c:2945)
_printk (kernel/printk/printk.c:2504)
nh_res_bucket_migrate (net/ipv4/nexthop.c:1816)
nh_res_table_upkeep (net/ipv4/nexthop.c:1866)
rtm_new_nexthop (net/ipv4/nexthop.c:3323)
rtnetlink_rcv_msg (net/core/rtnetlink.c:7076)
netlink_sendmsg (net/netlink/af_netlink.c:1900)
Kernel panic - not syncing: Fatal exception
Zero-initialize extack so _msg is NULL on error paths that never set it.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 7c37c7e00411b3d1e0c5292368317aca69d1f324 Version: 7c37c7e00411b3d1e0c5292368317aca69d1f324 Version: 7c37c7e00411b3d1e0c5292368317aca69d1f324 Version: 7c37c7e00411b3d1e0c5292368317aca69d1f324 Version: 7c37c7e00411b3d1e0c5292368317aca69d1f324 Version: 7c37c7e00411b3d1e0c5292368317aca69d1f324 Version: 7c37c7e00411b3d1e0c5292368317aca69d1f324 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ipv4/nexthop.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "eacd2e2117e8682f937967fda1022e7f1c22d91a",
"status": "affected",
"version": "7c37c7e00411b3d1e0c5292368317aca69d1f324",
"versionType": "git"
},
{
"lessThan": "37bbd7e1d8df0bec3d187e961783e20c30533d2c",
"status": "affected",
"version": "7c37c7e00411b3d1e0c5292368317aca69d1f324",
"versionType": "git"
},
{
"lessThan": "c0936c131a71657afc635d0db2ab096d15d473e1",
"status": "affected",
"version": "7c37c7e00411b3d1e0c5292368317aca69d1f324",
"versionType": "git"
},
{
"lessThan": "3081702ea5aca0aeed9c1ade8eadf6cde8db6b7d",
"status": "affected",
"version": "7c37c7e00411b3d1e0c5292368317aca69d1f324",
"versionType": "git"
},
{
"lessThan": "d536bf205c71f700f6de2086038c3e1d77724715",
"status": "affected",
"version": "7c37c7e00411b3d1e0c5292368317aca69d1f324",
"versionType": "git"
},
{
"lessThan": "18506d7263768d76ac8e057ba55a4d9da50aad66",
"status": "affected",
"version": "7c37c7e00411b3d1e0c5292368317aca69d1f324",
"versionType": "git"
},
{
"lessThan": "6347c5314cee49f364aaf2e40ff15415a57a116e",
"status": "affected",
"version": "7c37c7e00411b3d1e0c5292368317aca69d1f324",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ipv4/nexthop.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.13"
},
{
"lessThan": "5.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnexthop: initialize extack in nh_res_bucket_migrate()\n\nnh_res_bucket_migrate() passes an uninitialized netlink_ext_ack to\ncall_nexthop_res_bucket_notifiers(). When\nnh_notifier_res_bucket_info_init() fails (e.g. the kzalloc returns\n-ENOMEM), the error is propagated back before any notifier sets\nextack._msg, and the error path formats the stale pointer with\npr_err_ratelimited(\"%s\\n\", extack._msg). With CONFIG_INIT_STACK_NONE\nthis dereferences uninitialized stack memory:\n\n Oops: general protection fault, probably for non-canonical address ...\n KASAN: maybe wild-memory-access in range [...]\n RIP: 0010:string (lib/vsprintf.c:730)\n vsnprintf (lib/vsprintf.c:2945)\n _printk (kernel/printk/printk.c:2504)\n nh_res_bucket_migrate (net/ipv4/nexthop.c:1816)\n nh_res_table_upkeep (net/ipv4/nexthop.c:1866)\n rtm_new_nexthop (net/ipv4/nexthop.c:3323)\n rtnetlink_rcv_msg (net/core/rtnetlink.c:7076)\n netlink_sendmsg (net/netlink/af_netlink.c:1900)\n Kernel panic - not syncing: Fatal exception\n\nZero-initialize extack so _msg is NULL on error paths that never set it."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Triggered via local RTM_NEWNEXTHOP over rtnetlink (sendmsg \u2192 rtnetlink_rcv_msg \u2192 rtm_new_nexthop \u2192 nh_res_table_upkeep \u2192 nh_res_bucket_migrate), not by processing remote packets.\nAC:L - An attacker can create resilient nexthop groups, ensure notifiers are registered (e.g. VXLAN pernet init), force bucket migration, and induce the kzalloc -ENOMEM path; stack contents are groomable, with no attacker-independent condition required.\nPR:L - rtnetlink_rcv_msg requires CAP_NET_ADMIN via netlink_net_capable() against the socket netns user_ns, which an unprivileged user obtains with unshare -Urn, so privileges are Low not High.\nUI:N - The attacker issues the netlink nexthop configuration and triggers migration themselves; no victim action is required.\nS:U - Impact stays within the host kernel networking authority; this is a local DoS/disclosure bug, not a VM escape, IOMMU bypass, or other cross-boundary scope change.\nC:H - pr_err_ratelimited(\"%s\") dereferences an uninitialized extack._msg pointer as a C string, enabling an attacker-groomable wild kernel read into the log, consistent with treating unbounded wild/OOB reads as Confidentiality High.\nI:N - The defect only reads through the stale _msg pointer for printing; there is no write, free, or other memory-corruption integrity primitive.\nA:H - The wild %s dereference causes a general protection fault / KASAN wild-memory-access and kernel panic, as shown in the fix commit report, so Availability is High."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:28:57.222Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/eacd2e2117e8682f937967fda1022e7f1c22d91a"
},
{
"url": "https://git.kernel.org/stable/c/37bbd7e1d8df0bec3d187e961783e20c30533d2c"
},
{
"url": "https://git.kernel.org/stable/c/c0936c131a71657afc635d0db2ab096d15d473e1"
},
{
"url": "https://git.kernel.org/stable/c/3081702ea5aca0aeed9c1ade8eadf6cde8db6b7d"
},
{
"url": "https://git.kernel.org/stable/c/d536bf205c71f700f6de2086038c3e1d77724715"
},
{
"url": "https://git.kernel.org/stable/c/18506d7263768d76ac8e057ba55a4d9da50aad66"
},
{
"url": "https://git.kernel.org/stable/c/6347c5314cee49f364aaf2e40ff15415a57a116e"
}
],
"title": "nexthop: initialize extack in nh_res_bucket_migrate()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64576",
"datePublished": "2026-08-05T08:09:32.529Z",
"dateReserved": "2026-07-19T15:36:31.798Z",
"dateUpdated": "2026-08-19T16:28:57.222Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68215 (GCVE-0-2026-68215)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: radio-si476x: Unregister v4l2_device on probe failure
si476x_radio_probe() registers radio->v4l2dev before allocating the V4L2
controls and before registering the video device. If any of those later
steps fails, probe returns through the exit label after freeing only the
control handler.
A failed probe does not call si476x_radio_remove(), so the
v4l2_device_unregister() there is not reached. This leaves the parent
device reference taken by v4l2_device_register() behind on the error path.
Unregister the V4L2 device in the probe error path after freeing the
controls.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: b879a9c2a755d4ddf9e685258de6435710fd2f03 Version: b879a9c2a755d4ddf9e685258de6435710fd2f03 Version: b879a9c2a755d4ddf9e685258de6435710fd2f03 Version: b879a9c2a755d4ddf9e685258de6435710fd2f03 Version: b879a9c2a755d4ddf9e685258de6435710fd2f03 Version: b879a9c2a755d4ddf9e685258de6435710fd2f03 Version: b879a9c2a755d4ddf9e685258de6435710fd2f03 Version: b879a9c2a755d4ddf9e685258de6435710fd2f03 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/radio/radio-si476x.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "828f8d2181aa09ff3d8b67e1d9c92d0dfc81026f",
"status": "affected",
"version": "b879a9c2a755d4ddf9e685258de6435710fd2f03",
"versionType": "git"
},
{
"lessThan": "cac1c4f08cb2d8beaad16f7ddc7911f3711daa9f",
"status": "affected",
"version": "b879a9c2a755d4ddf9e685258de6435710fd2f03",
"versionType": "git"
},
{
"lessThan": "7cf393f176317a126d71e88e4b6e25e83499b465",
"status": "affected",
"version": "b879a9c2a755d4ddf9e685258de6435710fd2f03",
"versionType": "git"
},
{
"lessThan": "4ca9c9f12b1bc341a0a3bbbd2090fd182db53771",
"status": "affected",
"version": "b879a9c2a755d4ddf9e685258de6435710fd2f03",
"versionType": "git"
},
{
"lessThan": "7ef9f1659404544a8dddd68842bafcb4a38197af",
"status": "affected",
"version": "b879a9c2a755d4ddf9e685258de6435710fd2f03",
"versionType": "git"
},
{
"lessThan": "64cb15878b35e5574ff4f80a0b613a79e47867ba",
"status": "affected",
"version": "b879a9c2a755d4ddf9e685258de6435710fd2f03",
"versionType": "git"
},
{
"lessThan": "730c235d7d2c80a401dac56b0f5066c889aa442d",
"status": "affected",
"version": "b879a9c2a755d4ddf9e685258de6435710fd2f03",
"versionType": "git"
},
{
"lessThan": "436a693af04ffb889aaf87cb69ec1f2b21d3569c",
"status": "affected",
"version": "b879a9c2a755d4ddf9e685258de6435710fd2f03",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/radio/radio-si476x.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.10"
},
{
"lessThan": "3.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: radio-si476x: Unregister v4l2_device on probe failure\n\nsi476x_radio_probe() registers radio-\u003ev4l2dev before allocating the V4L2\ncontrols and before registering the video device. If any of those later\nsteps fails, probe returns through the exit label after freeing only the\ncontrol handler.\n\nA failed probe does not call si476x_radio_remove(), so the\nv4l2_device_unregister() there is not reached. This leaves the parent\ndevice reference taken by v4l2_device_register() behind on the error path.\n\nUnregister the V4L2 device in the probe error path after freeing the\ncontrols."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:44.648Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/828f8d2181aa09ff3d8b67e1d9c92d0dfc81026f"
},
{
"url": "https://git.kernel.org/stable/c/cac1c4f08cb2d8beaad16f7ddc7911f3711daa9f"
},
{
"url": "https://git.kernel.org/stable/c/7cf393f176317a126d71e88e4b6e25e83499b465"
},
{
"url": "https://git.kernel.org/stable/c/4ca9c9f12b1bc341a0a3bbbd2090fd182db53771"
},
{
"url": "https://git.kernel.org/stable/c/7ef9f1659404544a8dddd68842bafcb4a38197af"
},
{
"url": "https://git.kernel.org/stable/c/64cb15878b35e5574ff4f80a0b613a79e47867ba"
},
{
"url": "https://git.kernel.org/stable/c/730c235d7d2c80a401dac56b0f5066c889aa442d"
},
{
"url": "https://git.kernel.org/stable/c/436a693af04ffb889aaf87cb69ec1f2b21d3569c"
}
],
"title": "media: radio-si476x: Unregister v4l2_device on probe failure",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68215",
"datePublished": "2026-08-10T12:00:34.560Z",
"dateReserved": "2026-07-30T09:28:09.375Z",
"dateUpdated": "2026-08-19T16:31:44.648Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68368 (GCVE-0-2026-68368)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb()
When unpacking host-supplied NTBs, ncm_unwrap_ntb() checks datagram length
against frame_max but does not verify that the datagram fits within the
declared block length. Additionally, when decoding multiple NTBs from a
single socket buffer, subsequent block lengths are not checked against the
actual remaining buffer data.
With these checks missing, a malicious USB host can specify datagram
offsets and lengths that point beyond the block, or supply secondary NTB
headers declaring lengths larger than the buffer. skb_put_data() then
copies adjacent kernel memory from skb_shared_info into the network skb.
Fix this by verifying that sufficient buffer space remains for the NTB
header before parsing, handling zero-length block declarations, ensuring
that block lengths never exceed the remaining buffer space, and verifying
that each datagram payload stays strictly within the block boundary.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 2b74b0a04d3e9f9f08ff026e5663dce88ff94e52 Version: 2b74b0a04d3e9f9f08ff026e5663dce88ff94e52 Version: 2b74b0a04d3e9f9f08ff026e5663dce88ff94e52 Version: 2b74b0a04d3e9f9f08ff026e5663dce88ff94e52 Version: 2b74b0a04d3e9f9f08ff026e5663dce88ff94e52 Version: 2b74b0a04d3e9f9f08ff026e5663dce88ff94e52 Version: 2b74b0a04d3e9f9f08ff026e5663dce88ff94e52 Version: 2b74b0a04d3e9f9f08ff026e5663dce88ff94e52 Version: f7e0611e207d8908c4f2858e244370529a76dbf7 Version: b88ad6e714284b33a47834f5f2a294c2b37c66aa Version: 471b23586387a32857778c511be60ab31c98dcfd Version: 4f529c4d1e436230d3af7c09a3239677a14d2b46 Version: ae6a5394d9fbe118bc95cfe376d6a9d91d7547e8 Version: 5bdf93a2f5459f944b416b188178ca4a92fd206f Version: ff3ba016263ee93a1c6209bf5ab1599de7ab1512 Version: e7ca00f35d8a17af1ae19d529193ebc21bfda164 Version: 4.9.235 ≤ Version: 4.14.196 ≤ Version: 4.19.143 ≤ Version: 5.4.62 ≤ Version: 5.8.6 ≤ Version: 4.14.328 ≤ Version: 4.19.297 ≤ Version: 5.4.259 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/gadget/function/f_ncm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "35d15bbaec0557330e774ec31412ef508de6e0e0",
"status": "affected",
"version": "2b74b0a04d3e9f9f08ff026e5663dce88ff94e52",
"versionType": "git"
},
{
"lessThan": "6b2be489eaa6293e60549005d91f15ceb150510f",
"status": "affected",
"version": "2b74b0a04d3e9f9f08ff026e5663dce88ff94e52",
"versionType": "git"
},
{
"lessThan": "f87ed889f0f7417b8938c98d8833f559b755373c",
"status": "affected",
"version": "2b74b0a04d3e9f9f08ff026e5663dce88ff94e52",
"versionType": "git"
},
{
"lessThan": "e07751d0527ccc2a1c32eb0b0b7da3b4b9b5381f",
"status": "affected",
"version": "2b74b0a04d3e9f9f08ff026e5663dce88ff94e52",
"versionType": "git"
},
{
"lessThan": "fff1059d139ef798bab917990524faaf25854ca8",
"status": "affected",
"version": "2b74b0a04d3e9f9f08ff026e5663dce88ff94e52",
"versionType": "git"
},
{
"lessThan": "40c706a0224bde194667e3378c689b542fec4b44",
"status": "affected",
"version": "2b74b0a04d3e9f9f08ff026e5663dce88ff94e52",
"versionType": "git"
},
{
"lessThan": "41fd5f2fb0027d3773ae949e3247c2e0a2a7fe5c",
"status": "affected",
"version": "2b74b0a04d3e9f9f08ff026e5663dce88ff94e52",
"versionType": "git"
},
{
"lessThan": "1febec7e47cdcd01f43fb0211094e3010474666e",
"status": "affected",
"version": "2b74b0a04d3e9f9f08ff026e5663dce88ff94e52",
"versionType": "git"
},
{
"status": "affected",
"version": "f7e0611e207d8908c4f2858e244370529a76dbf7",
"versionType": "git"
},
{
"status": "affected",
"version": "b88ad6e714284b33a47834f5f2a294c2b37c66aa",
"versionType": "git"
},
{
"status": "affected",
"version": "471b23586387a32857778c511be60ab31c98dcfd",
"versionType": "git"
},
{
"status": "affected",
"version": "4f529c4d1e436230d3af7c09a3239677a14d2b46",
"versionType": "git"
},
{
"status": "affected",
"version": "ae6a5394d9fbe118bc95cfe376d6a9d91d7547e8",
"versionType": "git"
},
{
"status": "affected",
"version": "5bdf93a2f5459f944b416b188178ca4a92fd206f",
"versionType": "git"
},
{
"status": "affected",
"version": "ff3ba016263ee93a1c6209bf5ab1599de7ab1512",
"versionType": "git"
},
{
"status": "affected",
"version": "e7ca00f35d8a17af1ae19d529193ebc21bfda164",
"versionType": "git"
},
{
"lessThan": "4.10",
"status": "affected",
"version": "4.9.235",
"versionType": "semver"
},
{
"lessThan": "4.15",
"status": "affected",
"version": "4.14.196",
"versionType": "semver"
},
{
"lessThan": "4.20",
"status": "affected",
"version": "4.19.143",
"versionType": "semver"
},
{
"lessThan": "5.5",
"status": "affected",
"version": "5.4.62",
"versionType": "semver"
},
{
"lessThan": "5.9",
"status": "affected",
"version": "5.8.6",
"versionType": "semver"
},
{
"lessThan": "4.15",
"status": "affected",
"version": "4.14.328",
"versionType": "semver"
},
{
"lessThan": "4.20",
"status": "affected",
"version": "4.19.297",
"versionType": "semver"
},
{
"lessThan": "5.5",
"status": "affected",
"version": "5.4.259",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/usb/gadget/function/f_ncm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.9"
},
{
"lessThan": "5.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.9.235",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.14.196",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.19.143",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.4.62",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.8.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.14.328",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.19.297",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.4.259",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb()\n\nWhen unpacking host-supplied NTBs, ncm_unwrap_ntb() checks datagram length\nagainst frame_max but does not verify that the datagram fits within the\ndeclared block length. Additionally, when decoding multiple NTBs from a\nsingle socket buffer, subsequent block lengths are not checked against the\nactual remaining buffer data.\n\nWith these checks missing, a malicious USB host can specify datagram\noffsets and lengths that point beyond the block, or supply secondary NTB\nheaders declaring lengths larger than the buffer. skb_put_data() then\ncopies adjacent kernel memory from skb_shared_info into the network skb.\n\nFix this by verifying that sufficient buffer space remains for the NTB\nheader before parsing, handling zero-length block declarations, ensuring\nthat block lengths never exceed the remaining buffer space, and verifying\nthat each datagram payload stays strictly within the block boundary."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:26.235Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/35d15bbaec0557330e774ec31412ef508de6e0e0"
},
{
"url": "https://git.kernel.org/stable/c/6b2be489eaa6293e60549005d91f15ceb150510f"
},
{
"url": "https://git.kernel.org/stable/c/f87ed889f0f7417b8938c98d8833f559b755373c"
},
{
"url": "https://git.kernel.org/stable/c/e07751d0527ccc2a1c32eb0b0b7da3b4b9b5381f"
},
{
"url": "https://git.kernel.org/stable/c/fff1059d139ef798bab917990524faaf25854ca8"
},
{
"url": "https://git.kernel.org/stable/c/40c706a0224bde194667e3378c689b542fec4b44"
},
{
"url": "https://git.kernel.org/stable/c/41fd5f2fb0027d3773ae949e3247c2e0a2a7fe5c"
},
{
"url": "https://git.kernel.org/stable/c/1febec7e47cdcd01f43fb0211094e3010474666e"
}
],
"title": "usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68368",
"datePublished": "2026-08-10T12:03:45.579Z",
"dateReserved": "2026-07-30T09:28:09.386Z",
"dateUpdated": "2026-08-19T16:34:26.235Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68216 (GCVE-0-2026-68216)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: pwc: Return queued buffers on start_streaming() failure
The vb2 framework hands buffers to the driver via buf_queue() before
calling start_streaming(). If start_streaming() returns an error
without first returning those buffers via vb2_buffer_done(),
vb2_start_streaming() fires WARN_ON(owned_by_drv_count) and the queued
buffers leak.
pwc's start_streaming() had two early returns that hit this trap:
-ENODEV when the USB device was already disconnected, and -ERESTARTSYS
when mutex_lock_interruptible() was interrupted by a signal. Call the
existing pwc_cleanup_queued_bufs() helper with VB2_BUF_STATE_QUEUED
before returning (matching the state already used by the
pwc_isoc_init() error path in the same function).
This mirrors the uvcvideo fix in commit 4cf3b6fd54eb ("media: uvcvideo:
Return queued buffers on start_streaming() failure").
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ceede9fa8939e40ad0ddb4ad1355f45c6f1d3478 Version: ceede9fa8939e40ad0ddb4ad1355f45c6f1d3478 Version: ceede9fa8939e40ad0ddb4ad1355f45c6f1d3478 Version: ceede9fa8939e40ad0ddb4ad1355f45c6f1d3478 Version: ceede9fa8939e40ad0ddb4ad1355f45c6f1d3478 Version: ceede9fa8939e40ad0ddb4ad1355f45c6f1d3478 Version: ceede9fa8939e40ad0ddb4ad1355f45c6f1d3478 Version: ceede9fa8939e40ad0ddb4ad1355f45c6f1d3478 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/usb/pwc/pwc-if.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "d552852bf76b7dfb35b4593fc874d8dd2f1b1bf3",
"status": "affected",
"version": "ceede9fa8939e40ad0ddb4ad1355f45c6f1d3478",
"versionType": "git"
},
{
"lessThan": "0362ae30b61b3053ee3095c1b8f179197ec4f539",
"status": "affected",
"version": "ceede9fa8939e40ad0ddb4ad1355f45c6f1d3478",
"versionType": "git"
},
{
"lessThan": "fa78e590852751d3ad32f33f6b4e210fe6ccbe9b",
"status": "affected",
"version": "ceede9fa8939e40ad0ddb4ad1355f45c6f1d3478",
"versionType": "git"
},
{
"lessThan": "f2f9fcacd81953dde6cb86312ab13ca13e689664",
"status": "affected",
"version": "ceede9fa8939e40ad0ddb4ad1355f45c6f1d3478",
"versionType": "git"
},
{
"lessThan": "5d7cc2634c3843a1414a0f6407aa17f1f91dee60",
"status": "affected",
"version": "ceede9fa8939e40ad0ddb4ad1355f45c6f1d3478",
"versionType": "git"
},
{
"lessThan": "cb16b79a2be2cec9c3ebe4147490817c4d8b1de3",
"status": "affected",
"version": "ceede9fa8939e40ad0ddb4ad1355f45c6f1d3478",
"versionType": "git"
},
{
"lessThan": "a4f8f629983f643333e49df90557805469bcbb25",
"status": "affected",
"version": "ceede9fa8939e40ad0ddb4ad1355f45c6f1d3478",
"versionType": "git"
},
{
"lessThan": "975b2ee20e569d47821e4f6c9761b4664d48a6a4",
"status": "affected",
"version": "ceede9fa8939e40ad0ddb4ad1355f45c6f1d3478",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/usb/pwc/pwc-if.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.5"
},
{
"lessThan": "3.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: pwc: Return queued buffers on start_streaming() failure\n\nThe vb2 framework hands buffers to the driver via buf_queue() before\ncalling start_streaming(). If start_streaming() returns an error\nwithout first returning those buffers via vb2_buffer_done(),\nvb2_start_streaming() fires WARN_ON(owned_by_drv_count) and the queued\nbuffers leak.\n\npwc\u0027s start_streaming() had two early returns that hit this trap:\n-ENODEV when the USB device was already disconnected, and -ERESTARTSYS\nwhen mutex_lock_interruptible() was interrupted by a signal. Call the\nexisting pwc_cleanup_queued_bufs() helper with VB2_BUF_STATE_QUEUED\nbefore returning (matching the state already used by the\npwc_isoc_init() error path in the same function).\n\nThis mirrors the uvcvideo fix in commit 4cf3b6fd54eb (\"media: uvcvideo:\nReturn queued buffers on start_streaming() failure\")."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached through the VIDIOC_STREAMON ioctl on a local V4L2 device node (/dev/videoN) exposed by the pwc USB webcam driver, so the attacker needs local access to the system rather than network reachability.\nAC:L - The -ERESTARTSYS path is triggered deterministically by the attacker: hold pdev-\u003ev4l2_lock from a second thread/fd and send a signal to the thread blocked in mutex_lock_interruptible() inside start_streaming(), so both sides of the timing window are attacker-controlled and repeatable.\nPR:L - Only an unprivileged local account with access to the video device node (typical for desktop, kiosk and embedded video appliances, where the video group or logind ACLs grant it) is needed; no capabilities or root are required.\nUI:N - The attacker performs the entire sequence (REQBUFS, QBUF, STREAMON, signal delivery) from its own process; no action by any other user is needed.\nS:U - The buffer-accounting breakage and the resulting list corruption stay within the kernel\u0027s own security authority; no VM, IOMMU or sandbox boundary is crossed.\nC:H - Buffers left on pdev-\u003equeued_bufs after vb2 has already reclaimed them to QUEUED are re-linked on the next STREAMON, so the same pwc_frame_buf can be filled and completed while vb2 considers it userspace-owned, allowing an attacker to read kernel-managed frame data through stale mmap\u0027ed buffers.\nI:H - The double list_add_tail() of an already-linked buf-\u003elist node corrupts the driver\u0027s queued-buffer list and desynchronizes vb2\u0027s owned_by_drv_count, giving overlapping kernel/userspace ownership of buffer objects that can be leveraged for controlled modification of kernel-side state.\nA:H - Each attempt fires WARN_ON(owned_by_drv_count) in vb2_start_streaming(), which panics the machine on panic_on_warn kernels, and the leaked/corrupted buffer list additionally leads to lost buffers and unstable streaming state on subsequent STREAMON/STREAMOFF cycles."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:47.114Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/d552852bf76b7dfb35b4593fc874d8dd2f1b1bf3"
},
{
"url": "https://git.kernel.org/stable/c/0362ae30b61b3053ee3095c1b8f179197ec4f539"
},
{
"url": "https://git.kernel.org/stable/c/fa78e590852751d3ad32f33f6b4e210fe6ccbe9b"
},
{
"url": "https://git.kernel.org/stable/c/f2f9fcacd81953dde6cb86312ab13ca13e689664"
},
{
"url": "https://git.kernel.org/stable/c/5d7cc2634c3843a1414a0f6407aa17f1f91dee60"
},
{
"url": "https://git.kernel.org/stable/c/cb16b79a2be2cec9c3ebe4147490817c4d8b1de3"
},
{
"url": "https://git.kernel.org/stable/c/a4f8f629983f643333e49df90557805469bcbb25"
},
{
"url": "https://git.kernel.org/stable/c/975b2ee20e569d47821e4f6c9761b4664d48a6a4"
}
],
"title": "media: pwc: Return queued buffers on start_streaming() failure",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68216",
"datePublished": "2026-08-10T12:00:35.592Z",
"dateReserved": "2026-07-30T09:28:09.375Z",
"dateUpdated": "2026-08-19T16:31:47.114Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68321 (GCVE-0-2026-68321)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-17 05:03
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: txgbe: fix FDIR filter leak on remove
Perfect FDIR filters can be added while the interface is down and are
kept on the software list for later restore. unregister_netdev() only
calls ndo_stop when the device is up, so txgbe_fdir_filter_exit() in
txgbe_close() is skipped in that case and the filters are leaked on
driver remove. Free the filter list from txgbe_remove() as well.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/wangxun/txgbe/txgbe_main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "5c2f04258be2645cdd8f87553990948e7054e7fb",
"status": "affected",
"version": "4bdb441105dcea40ac6e01756314c0fdf5173ce1",
"versionType": "git"
},
{
"lessThan": "2d34421bfa261f7e83bea2f2f75fa75e0c3037d1",
"status": "affected",
"version": "4bdb441105dcea40ac6e01756314c0fdf5173ce1",
"versionType": "git"
},
{
"lessThan": "4946dea2386333e5d93bfb36df803fefb5a8c635",
"status": "affected",
"version": "4bdb441105dcea40ac6e01756314c0fdf5173ce1",
"versionType": "git"
},
{
"lessThan": "ecaa37826340520664a4e5522f803ff48fc3f564",
"status": "affected",
"version": "4bdb441105dcea40ac6e01756314c0fdf5173ce1",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/wangxun/txgbe/txgbe_main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.11"
},
{
"lessThan": "6.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: txgbe: fix FDIR filter leak on remove\n\nPerfect FDIR filters can be added while the interface is down and are\nkept on the software list for later restore. unregister_netdev() only\ncalls ndo_stop when the device is up, so txgbe_fdir_filter_exit() in\ntxgbe_close() is skipped in that case and the filters are leaked on\ndriver remove. Free the filter list from txgbe_remove() as well."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:03:18.882Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/5c2f04258be2645cdd8f87553990948e7054e7fb"
},
{
"url": "https://git.kernel.org/stable/c/2d34421bfa261f7e83bea2f2f75fa75e0c3037d1"
},
{
"url": "https://git.kernel.org/stable/c/4946dea2386333e5d93bfb36df803fefb5a8c635"
},
{
"url": "https://git.kernel.org/stable/c/ecaa37826340520664a4e5522f803ff48fc3f564"
}
],
"title": "net: txgbe: fix FDIR filter leak on remove",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68321",
"datePublished": "2026-08-10T12:02:56.166Z",
"dateReserved": "2026-07-30T09:28:09.382Z",
"dateUpdated": "2026-08-17T05:03:18.882Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68157 (GCVE-0-2026-68157)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
libceph: guard missing CRUSH type name lookup
Localized read selection can walk a parent bucket whose name exists in
the CRUSH map while its type has no matching entry in type_names.
get_immediate_parent() then dereferences a NULL type_cn and passes an
invalid pointer into strcmp(), causing a null-ptr-deref.
Skip such malformed parent buckets unless both the bucket name and type
name metadata are present. This keeps malformed hierarchy data from
crashing locality lookup and safely falls back to "not local".
[ idryomov: add WARN_ON_ONCE ]
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 117d96a04f007ce8fc2e292369056c3bd09f6f63 Version: 117d96a04f007ce8fc2e292369056c3bd09f6f63 Version: 117d96a04f007ce8fc2e292369056c3bd09f6f63 Version: 117d96a04f007ce8fc2e292369056c3bd09f6f63 Version: 117d96a04f007ce8fc2e292369056c3bd09f6f63 Version: 117d96a04f007ce8fc2e292369056c3bd09f6f63 Version: 117d96a04f007ce8fc2e292369056c3bd09f6f63 Version: 117d96a04f007ce8fc2e292369056c3bd09f6f63 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ceph/osdmap.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "cbfcba275326c8c7dae9acd8f4a0d4c316fdafb0",
"status": "affected",
"version": "117d96a04f007ce8fc2e292369056c3bd09f6f63",
"versionType": "git"
},
{
"lessThan": "8ff579ac03d6e9d17d6d9c8443110167c14a382d",
"status": "affected",
"version": "117d96a04f007ce8fc2e292369056c3bd09f6f63",
"versionType": "git"
},
{
"lessThan": "6a4b75d90f0cfbf22c14742ab35a803bc13f36ec",
"status": "affected",
"version": "117d96a04f007ce8fc2e292369056c3bd09f6f63",
"versionType": "git"
},
{
"lessThan": "c46d82c47afc968d6ee8ef4470fa2dd35b765c21",
"status": "affected",
"version": "117d96a04f007ce8fc2e292369056c3bd09f6f63",
"versionType": "git"
},
{
"lessThan": "3767c9f0c1bbd98dd25cb088356a0fc6c1f09f50",
"status": "affected",
"version": "117d96a04f007ce8fc2e292369056c3bd09f6f63",
"versionType": "git"
},
{
"lessThan": "4716a64b7cc2797741f7be4e283ace78a9dff37d",
"status": "affected",
"version": "117d96a04f007ce8fc2e292369056c3bd09f6f63",
"versionType": "git"
},
{
"lessThan": "db9cc9fd9660b2d69ee66f5a4cbec83c21a1c64d",
"status": "affected",
"version": "117d96a04f007ce8fc2e292369056c3bd09f6f63",
"versionType": "git"
},
{
"lessThan": "bbeae12fda3384a90fbebc8a19ba9d33f85b5361",
"status": "affected",
"version": "117d96a04f007ce8fc2e292369056c3bd09f6f63",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ceph/osdmap.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.8"
},
{
"lessThan": "5.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: guard missing CRUSH type name lookup\n\nLocalized read selection can walk a parent bucket whose name exists in\nthe CRUSH map while its type has no matching entry in type_names.\nget_immediate_parent() then dereferences a NULL type_cn and passes an\ninvalid pointer into strcmp(), causing a null-ptr-deref.\n\nSkip such malformed parent buckets unless both the bucket name and type\nname metadata are present. This keeps malformed hierarchy data from\ncrashing locality lookup and safely falls back to \"not local\".\n\n[ idryomov: add WARN_ON_ONCE ]"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - Malformed CRUSH hierarchy data is delivered to the kernel Ceph client in CEPH_MSG_OSD_MAP over TCP from a monitor or OSD peer, stored in libceph, and later triggers get_immediate_parent() during localized-read target selection on RBD/CephFS client I/O.\nAC:L - A compromised or attacker-controlled Ceph monitor can publish an osdmap whose CRUSH buckets have names but missing type_names entries; once applied, the NULL dereference is reliably hit on subsequent localize-read calc_target() paths without further attacker-controlled timing.\nPR:N - Exploitation requires no privileges on the victim host; any machine acting as a kernel Ceph client that receives a forged osdmap from a cluster peer over the network can be attacked without local capabilities or user-namespace tricks.\nUI:N - No victim user action is needed at exploitation time beyond the host already being a Ceph client with localized reads enabled; forged osdmaps are applied automatically and the crash fires on subsequent kernel client read or map-rescan operations.\nS:U - Impact is confined to kernel memory on the Ceph client host (crash or potential escalation within that host); it does not cross VM, IOMMU, or sandbox boundaries to other security authorities.\nC:N - The failure is a NULL pointer dereference when accessing type_cn-\u003ecn_name; there is no out-of-bounds read, use-after-free, or other memory corruption that could disclose kernel data.\nI:N - The bug causes a NULL pointer dereference crash only; no attacker-controlled write, heap corruption, or control-flow hijack primitive is created by this defect.\nA:H - The NULL pointer dereference in get_immediate_parent() during CRUSH locality lookup causes a kernel oops or panic, denying all service on the affected Ceph client host."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:30:27.540Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/cbfcba275326c8c7dae9acd8f4a0d4c316fdafb0"
},
{
"url": "https://git.kernel.org/stable/c/8ff579ac03d6e9d17d6d9c8443110167c14a382d"
},
{
"url": "https://git.kernel.org/stable/c/6a4b75d90f0cfbf22c14742ab35a803bc13f36ec"
},
{
"url": "https://git.kernel.org/stable/c/c46d82c47afc968d6ee8ef4470fa2dd35b765c21"
},
{
"url": "https://git.kernel.org/stable/c/3767c9f0c1bbd98dd25cb088356a0fc6c1f09f50"
},
{
"url": "https://git.kernel.org/stable/c/4716a64b7cc2797741f7be4e283ace78a9dff37d"
},
{
"url": "https://git.kernel.org/stable/c/db9cc9fd9660b2d69ee66f5a4cbec83c21a1c64d"
},
{
"url": "https://git.kernel.org/stable/c/bbeae12fda3384a90fbebc8a19ba9d33f85b5361"
}
],
"title": "libceph: guard missing CRUSH type name lookup",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68157",
"datePublished": "2026-08-10T11:59:23.692Z",
"dateReserved": "2026-07-30T09:28:09.371Z",
"dateUpdated": "2026-08-19T16:30:27.540Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68124 (GCVE-0-2026-68124)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-19 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
mctp: serial: handle zero-length frames to prevent rx buffer overflow
The MCTP serial receive state machine reads a frame length byte in
mctp_serial_push_header() case 2 and validates it upper-bound-only:
if (c > MCTP_SERIAL_FRAME_MTU) {
dev->rxstate = STATE_ERR;
} else {
dev->rxlen = c;
dev->rxpos = 0;
dev->rxstate = STATE_DATA;
...
}
A length of zero passes this check, so rxlen is set to 0 and the state
machine advances to STATE_DATA. In mctp_serial_push() STATE_DATA, the
incoming byte is stored and rxpos incremented before the terminator is
dev->rxbuf[dev->rxpos] = c;
dev->rxpos++;
dev->rxstate = STATE_DATA;
if (dev->rxpos == dev->rxlen) {
dev->rxpos = 0;
dev->rxstate = STATE_TRAILER;
}
With rxlen == 0 the "rxpos == rxlen" terminator can never fire (rxpos is
already 1 on the first data byte), so subsequent bytes are written past
the end of the fixed 74-byte rxbuf, which is the last member of the
netdev private area. Every following data byte is an attacker-controlled
1-byte out-of-bounds heap write, and the overflow continues until a
frame (0x7e) or escape byte resets the parser -- effectively unbounded.
Reaching this requires CAP_NET_ADMIN to attach the N_MCTP line
discipline and bring the resulting mctpserialN netdev up, after which
the bytes arrive via the tty receive path.
Route a zero-length frame straight to STATE_TRAILER instead of
STATE_DATA. The trailer/framing bytes are still consumed, and the frame
resolves to a zero-length skb that the MCTP core rejects; the parser
never enters STATE_DATA with rxlen == 0, so the out-of-bounds write can
no longer occur.
KASAN, on a frame of 0x7e 0x01 0x00 followed by data bytes (before this
change):
UBSAN: array-index-out-of-bounds in drivers/net/mctp/mctp-serial.c:370
index 74 is out of range for type 'u8 [74]'
BUG: KASAN: slab-out-of-bounds in mctp_serial_tty_receive_buf
Write of size 1 at addr ... by task kworker/u16:0
mctp_serial_tty_receive_buf
tty_ldisc_receive_buf
flush_to_ldisc
Allocated by task 152:
alloc_netdev_mqs
mctp_serial_open
v2: route zero-length frames to STATE_TRAILER instead of STATE_ERR so
the trailer/framing bytes are still consumed (Jeremy Kerr).
Found by 0sec automated security-research tooling (https://0sec.ai).
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: a0c2ccd9b5ad0a9e838158404e041b5a8ff762dd Version: a0c2ccd9b5ad0a9e838158404e041b5a8ff762dd Version: a0c2ccd9b5ad0a9e838158404e041b5a8ff762dd Version: a0c2ccd9b5ad0a9e838158404e041b5a8ff762dd Version: a0c2ccd9b5ad0a9e838158404e041b5a8ff762dd Version: a0c2ccd9b5ad0a9e838158404e041b5a8ff762dd |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/mctp/mctp-serial.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "64b96ae7912244d55257aa330d9569ee0a8f8d99",
"status": "affected",
"version": "a0c2ccd9b5ad0a9e838158404e041b5a8ff762dd",
"versionType": "git"
},
{
"lessThan": "36dc6d6964a3b90411cc7944cd9b8b6f67b9807b",
"status": "affected",
"version": "a0c2ccd9b5ad0a9e838158404e041b5a8ff762dd",
"versionType": "git"
},
{
"lessThan": "68819427bc07eca7963a9e8be19e5272cc29186c",
"status": "affected",
"version": "a0c2ccd9b5ad0a9e838158404e041b5a8ff762dd",
"versionType": "git"
},
{
"lessThan": "f80ba170d7b3a44e3d244a2c8e06031d61bf3b23",
"status": "affected",
"version": "a0c2ccd9b5ad0a9e838158404e041b5a8ff762dd",
"versionType": "git"
},
{
"lessThan": "06a6b606129c8a25cd457760f5370f3ff01fe05d",
"status": "affected",
"version": "a0c2ccd9b5ad0a9e838158404e041b5a8ff762dd",
"versionType": "git"
},
{
"lessThan": "793b9b729f1e8de57be8c8daf1a9838be96cabed",
"status": "affected",
"version": "a0c2ccd9b5ad0a9e838158404e041b5a8ff762dd",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/mctp/mctp-serial.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.17"
},
{
"lessThan": "5.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.17",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmctp: serial: handle zero-length frames to prevent rx buffer overflow\n\nThe MCTP serial receive state machine reads a frame length byte in\nmctp_serial_push_header() case 2 and validates it upper-bound-only:\n\n\tif (c \u003e MCTP_SERIAL_FRAME_MTU) {\n\t\tdev-\u003erxstate = STATE_ERR;\n\t} else {\n\t\tdev-\u003erxlen = c;\n\t\tdev-\u003erxpos = 0;\n\t\tdev-\u003erxstate = STATE_DATA;\n\t\t...\n\t}\n\nA length of zero passes this check, so rxlen is set to 0 and the state\nmachine advances to STATE_DATA. In mctp_serial_push() STATE_DATA, the\nincoming byte is stored and rxpos incremented before the terminator is\n\n\tdev-\u003erxbuf[dev-\u003erxpos] = c;\n\tdev-\u003erxpos++;\n\tdev-\u003erxstate = STATE_DATA;\n\tif (dev-\u003erxpos == dev-\u003erxlen) {\n\t\tdev-\u003erxpos = 0;\n\t\tdev-\u003erxstate = STATE_TRAILER;\n\t}\n\nWith rxlen == 0 the \"rxpos == rxlen\" terminator can never fire (rxpos is\nalready 1 on the first data byte), so subsequent bytes are written past\nthe end of the fixed 74-byte rxbuf, which is the last member of the\nnetdev private area. Every following data byte is an attacker-controlled\n1-byte out-of-bounds heap write, and the overflow continues until a\nframe (0x7e) or escape byte resets the parser -- effectively unbounded.\n\nReaching this requires CAP_NET_ADMIN to attach the N_MCTP line\ndiscipline and bring the resulting mctpserialN netdev up, after which\nthe bytes arrive via the tty receive path.\n\nRoute a zero-length frame straight to STATE_TRAILER instead of\nSTATE_DATA. The trailer/framing bytes are still consumed, and the frame\nresolves to a zero-length skb that the MCTP core rejects; the parser\nnever enters STATE_DATA with rxlen == 0, so the out-of-bounds write can\nno longer occur.\n\nKASAN, on a frame of 0x7e 0x01 0x00 followed by data bytes (before this\nchange):\n\n UBSAN: array-index-out-of-bounds in drivers/net/mctp/mctp-serial.c:370\n index 74 is out of range for type \u0027u8 [74]\u0027\n BUG: KASAN: slab-out-of-bounds in mctp_serial_tty_receive_buf\n Write of size 1 at addr ... by task kworker/u16:0\n mctp_serial_tty_receive_buf\n tty_ldisc_receive_buf\n flush_to_ldisc\n Allocated by task 152:\n alloc_netdev_mqs\n mctp_serial_open\n\nv2: route zero-length frames to STATE_TRAILER instead of STATE_ERR so\n the trailer/framing bytes are still consumed (Jeremy Kerr).\n\nFound by 0sec automated security-research tooling (https://0sec.ai)."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.6,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The bug is triggered in mctp_serial_tty_receive_buf() by crafted DSP0253 serial frames; on BMC/datacenter systems MCTP-over-serial links management controllers on a shared management LAN, letting an adjacent unauthenticated peer inject 0x7e/0x01/0x00 frames without using host syscalls.\nAC:L - Exploitation is deterministic: a zero-length length byte bypasses the upper-bound check, then each following serial byte is a controlled 1-byte heap OOB write until 0x7e/0x7d resets the parser; no races or attacker-uncontrollable memory layout are required.\nPR:N - Triggering the overflow only requires delivering malicious serial bytes to an already-configured, running mctpserial netdev; a remote/adjacent MCTP peer or compromised management controller needs no Linux host credentials, CAP_NET_ADMIN, or root on the victim.\nUI:N - No victim user action is required at exploit time; administrative enablement of MCTP serial is deployment configuration, not end-user interaction under CVSS.\nS:C - Kconfig documents virtio-serial VM interconnect for MCTP serial; a malicious guest sending crafted frames to the host-side mctpserial binding can corrupt host kernel heap memory, crossing the guest/host virtualization security boundary.\nC:H - Each overflow byte is attacker-controlled and the write stream is effectively unbounded past the 74-byte rxbuf (last netdev private field), enabling slab-out-of-bounds corruption that can be leveraged for arbitrary kernel memory disclosure.\nI:H - Sustained attacker-controlled out-of-bounds heap writes can corrupt adjacent kmalloc objects, function pointers, and netdev state, providing a standard path to arbitrary kernel write and privilege-escalating code execution.\nA:H - KASAN/UBSAN report slab-out-of-bounds and array-index-out-of-bounds in mctp_serial_tty_receive_buf via flush_to_ldisc; continued overflow reliably causes kernel oops/panic or hang during tty receive processing."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:29:36.851Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/64b96ae7912244d55257aa330d9569ee0a8f8d99"
},
{
"url": "https://git.kernel.org/stable/c/36dc6d6964a3b90411cc7944cd9b8b6f67b9807b"
},
{
"url": "https://git.kernel.org/stable/c/68819427bc07eca7963a9e8be19e5272cc29186c"
},
{
"url": "https://git.kernel.org/stable/c/f80ba170d7b3a44e3d244a2c8e06031d61bf3b23"
},
{
"url": "https://git.kernel.org/stable/c/06a6b606129c8a25cd457760f5370f3ff01fe05d"
},
{
"url": "https://git.kernel.org/stable/c/793b9b729f1e8de57be8c8daf1a9838be96cabed"
}
],
"title": "mctp: serial: handle zero-length frames to prevent rx buffer overflow",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68124",
"datePublished": "2026-08-10T11:58:44.997Z",
"dateReserved": "2026-07-30T09:28:09.369Z",
"dateUpdated": "2026-08-19T16:29:36.851Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68249 (GCVE-0-2026-68249)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-19 16:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON()
There's no need to crash the kernel for these cases.
(cherry picked from commit 8d144a0eb09537055841af48c9e7c2d4cd48e84d)
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: fef6e24c8b0243c3c43723949091cf999bb39c56 Version: fef6e24c8b0243c3c43723949091cf999bb39c56 Version: fef6e24c8b0243c3c43723949091cf999bb39c56 Version: fef6e24c8b0243c3c43723949091cf999bb39c56 Version: fef6e24c8b0243c3c43723949091cf999bb39c56 Version: fef6e24c8b0243c3c43723949091cf999bb39c56 Version: fef6e24c8b0243c3c43723949091cf999bb39c56 Version: fef6e24c8b0243c3c43723949091cf999bb39c56 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/sdma_v5_0.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "5960a8b54a19367540d93980a4d0e9edbb8acf4e",
"status": "affected",
"version": "fef6e24c8b0243c3c43723949091cf999bb39c56",
"versionType": "git"
},
{
"lessThan": "0c0dcc146f0c3091a9ef416cb8bbfdf5b5e169d5",
"status": "affected",
"version": "fef6e24c8b0243c3c43723949091cf999bb39c56",
"versionType": "git"
},
{
"lessThan": "84254337df02406996068315c2b6f06d8cc64452",
"status": "affected",
"version": "fef6e24c8b0243c3c43723949091cf999bb39c56",
"versionType": "git"
},
{
"lessThan": "f6212bc1bbd936fd9f7d77168b0c8b0019477b64",
"status": "affected",
"version": "fef6e24c8b0243c3c43723949091cf999bb39c56",
"versionType": "git"
},
{
"lessThan": "28337e5d7df429bac7de64b17f1a595147778caa",
"status": "affected",
"version": "fef6e24c8b0243c3c43723949091cf999bb39c56",
"versionType": "git"
},
{
"lessThan": "d20b5c139b2906bcd8ab4bfe5b8be500318161d1",
"status": "affected",
"version": "fef6e24c8b0243c3c43723949091cf999bb39c56",
"versionType": "git"
},
{
"lessThan": "0027cb19b0449ad6babedb1af285a713ab05c97f",
"status": "affected",
"version": "fef6e24c8b0243c3c43723949091cf999bb39c56",
"versionType": "git"
},
{
"lessThan": "9e98ed3113943257ad6e5c1e6beddbdb482a70ad",
"status": "affected",
"version": "fef6e24c8b0243c3c43723949091cf999bb39c56",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/sdma_v5_0.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.3"
},
{
"lessThan": "5.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON()\n\nThere\u0027s no need to crash the kernel for these cases.\n\n(cherry picked from commit 8d144a0eb09537055841af48c9e7c2d4cd48e84d)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:32:18.750Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/5960a8b54a19367540d93980a4d0e9edbb8acf4e"
},
{
"url": "https://git.kernel.org/stable/c/0c0dcc146f0c3091a9ef416cb8bbfdf5b5e169d5"
},
{
"url": "https://git.kernel.org/stable/c/84254337df02406996068315c2b6f06d8cc64452"
},
{
"url": "https://git.kernel.org/stable/c/f6212bc1bbd936fd9f7d77168b0c8b0019477b64"
},
{
"url": "https://git.kernel.org/stable/c/28337e5d7df429bac7de64b17f1a595147778caa"
},
{
"url": "https://git.kernel.org/stable/c/d20b5c139b2906bcd8ab4bfe5b8be500318161d1"
},
{
"url": "https://git.kernel.org/stable/c/0027cb19b0449ad6babedb1af285a713ab05c97f"
},
{
"url": "https://git.kernel.org/stable/c/9e98ed3113943257ad6e5c1e6beddbdb482a70ad"
}
],
"title": "drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68249",
"datePublished": "2026-08-10T12:01:15.453Z",
"dateReserved": "2026-07-30T09:28:09.377Z",
"dateUpdated": "2026-08-19T16:32:18.750Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68136 (GCVE-0-2026-68136)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-23 12:45
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: gro: fix double aggregation of flush-marked skbs
Commit 0ab03f353d36 ("net-gro: Fix GRO flush when receiving a GSO
packet.") added a flush check to skb_gro_receive(), but
skb_gro_receive_list() lacks the same validation.
As a result, packets marked with NAPI_GRO_CB(skb)->flush may still be
re-aggregated.
This allows already-GRO'd packets with existing frag_list to be
re-aggregated into a new GRO session, corrupting the frag_list chain
structure. When skb_segment() attempts to unpack these malformed packets,
it encounters invalid state and triggers a kernel panic.
Scenario (Tethering/Device forwarding):
1. Driver: Generated aggregated packet P1 via LRO with frag_list
2. Dev A: Receives aggregated fraglist packet and flush flag set
3. Dev A: Re-enters GRO, skb_gro_receive_list() is called
4. Missing flush check allows re-aggregation despite flush flag
5. Frag_list chain becomes corrupted (loops or dangling refs)
6. Dev B: TX path calls skb_segment(), crashes on corrupted frag_list
Root cause in skb_segment():
The check at line ~4891:
if (hsize <= 0 && i >= nfrags && skb_headlen(list_skb) &&
(skb_headlen(list_skb) == len || sg)) {
When frag_list is corrupted by double aggregation, when list_skb is
a NULL pointer from skb->next, skb_headlen(list_skb) dereference
NULL/corrupted pointers occurs.
Call Trace:
skb_headlen(NULL skb)
skb_segment
tcp_gso_segment
tcp4_gso_segment
inet_gso_segment
skb_mac_gso_segment
__skb_gso_segment
skb_gso_segment
validate_xmit_skb
validate_xmit_skb_list
sch_direct_xmit
qdisc_restart
__qdisc_run
qdisc_run
net_tx_action
Fix: Add NAPI_GRO_CB(skb)->flush validation to the early-return check in
skb_gro_receive_list(), matching the defensive programming pattern of
skb_gro_receive().
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 3a1296a38d0cf62bffb9a03c585cbd5dbf15d596 Version: 3a1296a38d0cf62bffb9a03c585cbd5dbf15d596 Version: 3a1296a38d0cf62bffb9a03c585cbd5dbf15d596 Version: 3a1296a38d0cf62bffb9a03c585cbd5dbf15d596 Version: 3a1296a38d0cf62bffb9a03c585cbd5dbf15d596 Version: 3a1296a38d0cf62bffb9a03c585cbd5dbf15d596 Version: 3a1296a38d0cf62bffb9a03c585cbd5dbf15d596 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/core/gro.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "7fc7e35212cf58c134310fb47566a844297ceae9",
"status": "affected",
"version": "3a1296a38d0cf62bffb9a03c585cbd5dbf15d596",
"versionType": "git"
},
{
"lessThan": "d1fb23f8f794ac4683127bd49a6422bd87e0ac02",
"status": "affected",
"version": "3a1296a38d0cf62bffb9a03c585cbd5dbf15d596",
"versionType": "git"
},
{
"lessThan": "db3e82da616f52e2b27e25e7be3fde2f2a5e54d6",
"status": "affected",
"version": "3a1296a38d0cf62bffb9a03c585cbd5dbf15d596",
"versionType": "git"
},
{
"lessThan": "107e1a469f53a2a70874f3f12bf6fcd23925da1d",
"status": "affected",
"version": "3a1296a38d0cf62bffb9a03c585cbd5dbf15d596",
"versionType": "git"
},
{
"lessThan": "a4dfd46cc8f08a29c6183794790547d0945f3d45",
"status": "affected",
"version": "3a1296a38d0cf62bffb9a03c585cbd5dbf15d596",
"versionType": "git"
},
{
"lessThan": "fc0c0f7a207f0cd2d2aa725696c907f7d03af9e0",
"status": "affected",
"version": "3a1296a38d0cf62bffb9a03c585cbd5dbf15d596",
"versionType": "git"
},
{
"lessThan": "e751256486d0ded20f5a9f9863467f1dce65142f",
"status": "affected",
"version": "3a1296a38d0cf62bffb9a03c585cbd5dbf15d596",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/core/gro.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.6"
},
{
"lessThan": "5.6",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: gro: fix double aggregation of flush-marked skbs\n\nCommit 0ab03f353d36 (\"net-gro: Fix GRO flush when receiving a GSO\npacket.\") added a flush check to skb_gro_receive(), but\nskb_gro_receive_list() lacks the same validation.\n\nAs a result, packets marked with NAPI_GRO_CB(skb)-\u003eflush may still be\nre-aggregated.\n\nThis allows already-GRO\u0027d packets with existing frag_list to be\nre-aggregated into a new GRO session, corrupting the frag_list chain\nstructure. When skb_segment() attempts to unpack these malformed packets,\nit encounters invalid state and triggers a kernel panic.\n\nScenario (Tethering/Device forwarding):\n 1. Driver: Generated aggregated packet P1 via LRO with frag_list\n 2. Dev A: Receives aggregated fraglist packet and flush flag set\n 3. Dev A: Re-enters GRO, skb_gro_receive_list() is called\n 4. Missing flush check allows re-aggregation despite flush flag\n 5. Frag_list chain becomes corrupted (loops or dangling refs)\n 6. Dev B: TX path calls skb_segment(), crashes on corrupted frag_list\n\nRoot cause in skb_segment():\n The check at line ~4891:\n if (hsize \u003c= 0 \u0026\u0026 i \u003e= nfrags \u0026\u0026 skb_headlen(list_skb) \u0026\u0026\n (skb_headlen(list_skb) == len || sg)) {\n\n When frag_list is corrupted by double aggregation, when list_skb is\n a NULL pointer from skb-\u003enext, skb_headlen(list_skb) dereference\n NULL/corrupted pointers occurs.\n\nCall Trace:\n skb_headlen(NULL skb)\n skb_segment\n tcp_gso_segment\n tcp4_gso_segment\n inet_gso_segment\n skb_mac_gso_segment\n __skb_gso_segment\n skb_gso_segment\n validate_xmit_skb\n validate_xmit_skb_list\n sch_direct_xmit\n qdisc_restart\n __qdisc_run\n qdisc_run\n net_tx_action\n\nFix: Add NAPI_GRO_CB(skb)-\u003eflush validation to the early-return check in\nskb_gro_receive_list(), matching the defensive programming pattern of\nskb_gro_receive()."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug is reached from the standard NAPI GRO receive path processing remotely originated TCP/IP packets (napi_gro_receive\u2192dev_gro_receive\u2192tcp_gro_receive\u2192skb_gro_receive_list), including tethering/NAT/forwarding scenarios where packets re-enter GRO on a second netdev after driver LRO or prior GRO aggregation.\nAC:L - An attacker can reliably trigger the bug by crafting a TCP stream through a forwarding host with rx-gro-list enabled, without races or victim-specific timing; the commit documents a deterministic tethering/forwarding repro where flush-marked frag_list skbs are re-aggregated and later crash skb_segment.\nPR:N - No local privileges or authentication are required; any remote peer that can send TCP traffic through a vulnerable forwarding/tethering/NAT Linux host can reach the GRO fraglist merge path, which performs no capability or credential checks on the receive path.\nUI:N - Exploitation requires only network-delivered packets and normal kernel forwarding/GRO processing; the victim does not need to open files, mount filesystems, click links, or perform any deliberate action beyond routine network operation.\nS:U - Impact is confined to kernel memory corruption and panic within the same host kernel security domain during packet GRO aggregation and subsequent segmentation on transmit; it does not cross VM, container, or IOMMU boundaries to affect a separate security authority.\nC:H - Double aggregation corrupts the skb frag_list chain (loops, dangling references, NULL/corrupted list_skb pointers), constituting kernel heap memory corruption that can be read during skb_segment processing and is classifiable as a high-impact info-disclosure primitive beyond a simple crash.\nI:H - Re-aggregating flush-marked skbs with existing frag_list corrupts skb linked-list structure and reference relationships in kernel memory, enabling potential control of subsequent skb metadata and write/control-flow primitives during GSO segmentation, not merely integrity-preserving packet drops.\nA:H - Corrupted frag_list state causes skb_segment to dereference a NULL or invalid list_skb via skb_headlen(), producing a kernel panic/oops on the transmit path (sch_direct_xmit/qdisc_run), fully denying availability of the affected system."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:45:54.689Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/7fc7e35212cf58c134310fb47566a844297ceae9"
},
{
"url": "https://git.kernel.org/stable/c/d1fb23f8f794ac4683127bd49a6422bd87e0ac02"
},
{
"url": "https://git.kernel.org/stable/c/db3e82da616f52e2b27e25e7be3fde2f2a5e54d6"
},
{
"url": "https://git.kernel.org/stable/c/107e1a469f53a2a70874f3f12bf6fcd23925da1d"
},
{
"url": "https://git.kernel.org/stable/c/a4dfd46cc8f08a29c6183794790547d0945f3d45"
},
{
"url": "https://git.kernel.org/stable/c/fc0c0f7a207f0cd2d2aa725696c907f7d03af9e0"
},
{
"url": "https://git.kernel.org/stable/c/e751256486d0ded20f5a9f9863467f1dce65142f"
}
],
"title": "net: gro: fix double aggregation of flush-marked skbs",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68136",
"datePublished": "2026-08-10T11:58:59.450Z",
"dateReserved": "2026-07-30T09:28:09.370Z",
"dateUpdated": "2026-08-23T12:45:54.689Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68127 (GCVE-0-2026-68127)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-19 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ila: reload IPv6 header after pskb_may_pull in checksum adjust
ila_csum_adjust_transport() caches ip6h = ipv6_hdr(skb) before calling
pskb_may_pull(). On a non-linear skb whose transport header sits in a page
fragment, pskb_may_pull() can call __pskb_pull_tail() / pskb_expand_head()
and free the old skb head, leaving ip6h dangling; the following
get_csum_diff(ip6h, p) then reads freed memory. ila_update_ipv6_locator()
uses ip6h (and the iaddr derived from it) again after the csum-adjust
call and additionally writes the new locator through that pointer.
Impact: a remote IPv6 packet routed through a configured ILA
csum-adjust-transport route or receive-side mapping triggers a
slab-use-after-free in ila_update_ipv6_locator() (KASAN). The route or
mapping requires CAP_NET_ADMIN to configure, but trigger packets are
unauthenticated once it exists.
Reload ip6h after each pskb_may_pull() in ila_csum_adjust_transport()
before the csum-diff read. In ila_update_ipv6_locator() only the
ILA_CSUM_ADJUST_TRANSPORT case pulls the skb, so reload ip6h and iaddr in
that case alone before the destination-address write; the neutral-map
modes never pull and keep their cached pointers.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 33f11d16142b06588eedfc1dd8cf93790979a712 Version: 33f11d16142b06588eedfc1dd8cf93790979a712 Version: 33f11d16142b06588eedfc1dd8cf93790979a712 Version: 33f11d16142b06588eedfc1dd8cf93790979a712 Version: 33f11d16142b06588eedfc1dd8cf93790979a712 Version: 33f11d16142b06588eedfc1dd8cf93790979a712 Version: 33f11d16142b06588eedfc1dd8cf93790979a712 Version: 33f11d16142b06588eedfc1dd8cf93790979a712 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ipv6/ila/ila_common.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "e451a904606c571f731ef7a06b3398619dce5300",
"status": "affected",
"version": "33f11d16142b06588eedfc1dd8cf93790979a712",
"versionType": "git"
},
{
"lessThan": "1eadcb43893b897ade85ac5bf5c618054bc3c655",
"status": "affected",
"version": "33f11d16142b06588eedfc1dd8cf93790979a712",
"versionType": "git"
},
{
"lessThan": "ba353caafb06ccee57b78d3254e3cebf1dea4a93",
"status": "affected",
"version": "33f11d16142b06588eedfc1dd8cf93790979a712",
"versionType": "git"
},
{
"lessThan": "896a9512d0d83c2a4b357e5585b7b62a8e3f95c1",
"status": "affected",
"version": "33f11d16142b06588eedfc1dd8cf93790979a712",
"versionType": "git"
},
{
"lessThan": "7097a0280b178237265681be66d1bef11d15894b",
"status": "affected",
"version": "33f11d16142b06588eedfc1dd8cf93790979a712",
"versionType": "git"
},
{
"lessThan": "472aba2603ca74c4f7722cb0c0296942b0776b8d",
"status": "affected",
"version": "33f11d16142b06588eedfc1dd8cf93790979a712",
"versionType": "git"
},
{
"lessThan": "c6a13ae00dab3a1a8c7cf2f843f0fc9e8d4b0ccc",
"status": "affected",
"version": "33f11d16142b06588eedfc1dd8cf93790979a712",
"versionType": "git"
},
{
"lessThan": "92d3817649df2b0b6a008a686c8275c88d7ef594",
"status": "affected",
"version": "33f11d16142b06588eedfc1dd8cf93790979a712",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ipv6/ila/ila_common.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.5"
},
{
"lessThan": "4.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nila: reload IPv6 header after pskb_may_pull in checksum adjust\n\nila_csum_adjust_transport() caches ip6h = ipv6_hdr(skb) before calling\npskb_may_pull(). On a non-linear skb whose transport header sits in a page\nfragment, pskb_may_pull() can call __pskb_pull_tail() / pskb_expand_head()\nand free the old skb head, leaving ip6h dangling; the following\nget_csum_diff(ip6h, p) then reads freed memory. ila_update_ipv6_locator()\nuses ip6h (and the iaddr derived from it) again after the csum-adjust\ncall and additionally writes the new locator through that pointer.\n\nImpact: a remote IPv6 packet routed through a configured ILA\ncsum-adjust-transport route or receive-side mapping triggers a\nslab-use-after-free in ila_update_ipv6_locator() (KASAN). The route or\nmapping requires CAP_NET_ADMIN to configure, but trigger packets are\nunauthenticated once it exists.\n\nReload ip6h after each pskb_may_pull() in ila_csum_adjust_transport()\nbefore the csum-diff read. In ila_update_ipv6_locator() only the\nILA_CSUM_ADJUST_TRANSPORT case pulls the skb, so reload ip6h and iaddr in\nthat case alone before the destination-address write; the neutral-map\nmodes never pull and keep their cached pointers."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug is reached from ipv6_rcv() through NF_INET_PRE_ROUTING (ila_nf_input) or IPv6 routing/LWT input/output when remote IPv6 packets matching a configured ILA csum-adjust-transport mapping or route are processed; no local syscall is required on internet-facing routers, gateways, or NVO3/overlay hosts.\nAC:L - Once ILA csum-adjust-transport is configured, a remote attacker can reliably send IPv6 TCP/UDP/ICMPv6 packets whose transport headers live in skb page fragments so pskb_may_pull() reallocates the head; they control packet layout and can retry without races or uncontrollable memory layout.\nPR:N - Trigger packets are processed unauthenticated on the network datapath; although ILA routes/mappings require CAP_NET_ADMIN to install, that is operator infrastructure (also obtainable in a user netns), not a privilege the remote attacker needs to send the malformed IPv6 packets that hit ila_update_ipv6_locator().\nUI:N - No victim user action is required beyond normal IPv6 packet delivery; exploitation is fully automated once the affected ILA configuration exists and the attacker sends crafted packets to the host.\nS:U - The slab use-after-free corrupts kernel packet-processing memory within the host kernel security authority; it is not a VM escape, container breakout, or IOMMU/DMA boundary bypass.\nC:H - ila_csum_adjust_transport() reads the cached IPv6 header via get_csum_diff(ip6h, p) after pskb_may_pull() frees the old skb head, causing a slab use-after-free read of freed memory that can disclose kernel heap contents.\nI:H - ila_update_ipv6_locator() then writes iaddr-\u003eloc = p-\u003elocator through the same stale iaddr pointer derived from the freed header, giving a slab use-after-free write primitive that can be leveraged for arbitrary memory corruption and control-flow hijacking.\nA:H - The freed skb-head slab use-after-free was reproduced under KASAN and can cause kernel oops/panic during IPv6 receive/forwarding; even unsuccessful exploitation typically crashes or destabilizes the host."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:29:41.771Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/e451a904606c571f731ef7a06b3398619dce5300"
},
{
"url": "https://git.kernel.org/stable/c/1eadcb43893b897ade85ac5bf5c618054bc3c655"
},
{
"url": "https://git.kernel.org/stable/c/ba353caafb06ccee57b78d3254e3cebf1dea4a93"
},
{
"url": "https://git.kernel.org/stable/c/896a9512d0d83c2a4b357e5585b7b62a8e3f95c1"
},
{
"url": "https://git.kernel.org/stable/c/7097a0280b178237265681be66d1bef11d15894b"
},
{
"url": "https://git.kernel.org/stable/c/472aba2603ca74c4f7722cb0c0296942b0776b8d"
},
{
"url": "https://git.kernel.org/stable/c/c6a13ae00dab3a1a8c7cf2f843f0fc9e8d4b0ccc"
},
{
"url": "https://git.kernel.org/stable/c/92d3817649df2b0b6a008a686c8275c88d7ef594"
}
],
"title": "ila: reload IPv6 header after pskb_may_pull in checksum adjust",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68127",
"datePublished": "2026-08-10T11:58:48.489Z",
"dateReserved": "2026-07-30T09:28:09.369Z",
"dateUpdated": "2026-08-19T16:29:41.771Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68422 (GCVE-0-2026-68422)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-19 16:35
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots()
If we have an unexpected reloc_root for our root, we jump to the out label
but never drop the reference we obtained for root, resulting in a leak.
Add a missing btrfs_put_root() call.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 24213fa46c7080c31d79aa2e3e2f0d9480cab700 Version: 24213fa46c7080c31d79aa2e3e2f0d9480cab700 Version: 24213fa46c7080c31d79aa2e3e2f0d9480cab700 Version: 24213fa46c7080c31d79aa2e3e2f0d9480cab700 Version: 24213fa46c7080c31d79aa2e3e2f0d9480cab700 Version: 24213fa46c7080c31d79aa2e3e2f0d9480cab700 Version: 24213fa46c7080c31d79aa2e3e2f0d9480cab700 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/btrfs/relocation.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "f89df93e8aefa4c1c813f835559f2ac727f79766",
"status": "affected",
"version": "24213fa46c7080c31d79aa2e3e2f0d9480cab700",
"versionType": "git"
},
{
"lessThan": "3f586b4c92e4272fcd01bf0db0590b63acf3e85b",
"status": "affected",
"version": "24213fa46c7080c31d79aa2e3e2f0d9480cab700",
"versionType": "git"
},
{
"lessThan": "b3d39b03799600c76c33486e2d29b73a771023db",
"status": "affected",
"version": "24213fa46c7080c31d79aa2e3e2f0d9480cab700",
"versionType": "git"
},
{
"lessThan": "72f673d1c1deb819554d3e7e154f6d84301eb735",
"status": "affected",
"version": "24213fa46c7080c31d79aa2e3e2f0d9480cab700",
"versionType": "git"
},
{
"lessThan": "60a23d4ea169e27403f3bb023bb98036797c0206",
"status": "affected",
"version": "24213fa46c7080c31d79aa2e3e2f0d9480cab700",
"versionType": "git"
},
{
"lessThan": "7591d1727067d6063247901ad25c4bdc4e5695c4",
"status": "affected",
"version": "24213fa46c7080c31d79aa2e3e2f0d9480cab700",
"versionType": "git"
},
{
"lessThan": "ce6050bafb4e33377dc17fcc357736bfc351180c",
"status": "affected",
"version": "24213fa46c7080c31d79aa2e3e2f0d9480cab700",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/btrfs/relocation.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.13"
},
{
"lessThan": "5.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots()\n\nIf we have an unexpected reloc_root for our root, we jump to the out label\nbut never drop the reference we obtained for root, resulting in a leak.\nAdd a missing btrfs_put_root() call."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:35:17.540Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/f89df93e8aefa4c1c813f835559f2ac727f79766"
},
{
"url": "https://git.kernel.org/stable/c/3f586b4c92e4272fcd01bf0db0590b63acf3e85b"
},
{
"url": "https://git.kernel.org/stable/c/b3d39b03799600c76c33486e2d29b73a771023db"
},
{
"url": "https://git.kernel.org/stable/c/72f673d1c1deb819554d3e7e154f6d84301eb735"
},
{
"url": "https://git.kernel.org/stable/c/60a23d4ea169e27403f3bb023bb98036797c0206"
},
{
"url": "https://git.kernel.org/stable/c/7591d1727067d6063247901ad25c4bdc4e5695c4"
},
{
"url": "https://git.kernel.org/stable/c/ce6050bafb4e33377dc17fcc357736bfc351180c"
}
],
"title": "btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68422",
"datePublished": "2026-08-10T12:04:42.949Z",
"dateReserved": "2026-07-30T09:28:09.392Z",
"dateUpdated": "2026-08-19T16:35:17.540Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68151 (GCVE-0-2026-68151)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
binfmt_elf_fdpic: only honour the first PT_INTERP
The program header scan handles PT_INTERP from a switch nested in the
scan loop, so its break leaves the switch and not the loop. A binary
carrying more than one PT_INTERP runs the case again and overwrites both
interpreter_name and interpreter. The previous name allocation leaks and
so does the previous interpreter reference, along with the write denial
open_exec() took on it. The denial is never released, so the file stays
unwritable for as long as the system runs.
An unprivileged caller reaches this with a crafted binary and repeats it
at will. binfmt_elf stops at the first PT_INTERP. Do the same here.
The flaw dates back to the driver's introduction in the pre-git history
tree introduced in v2.6.11 by 91808d6ebe39 ("[PATCH] FRV: Add FDPIC ELF
binary format driver").
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/binfmt_elf_fdpic.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "9854538349aaf6fb88ed33b56987954ac1716151",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "3c31397b0a75310217f1f2f3c7bdfd8af67aec4c",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "849a7bd9d266e43a457db5c6b322600f916a2127",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "e4563e07ef5c938d5332c5c44721db976f214bc6",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "21eaf5594a33d16343a011c752624099c30e918f",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "89b9121c3b0162655fc2f190b714ae64f1aa8cae",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "69ecc199880bf7e8d06224c82dc411d18f9285f8",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "3349ef6a366a61d631f6a263d12cea240957719d",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/binfmt_elf_fdpic.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbinfmt_elf_fdpic: only honour the first PT_INTERP\n\nThe program header scan handles PT_INTERP from a switch nested in the\nscan loop, so its break leaves the switch and not the loop. A binary\ncarrying more than one PT_INTERP runs the case again and overwrites both\ninterpreter_name and interpreter. The previous name allocation leaks and\nso does the previous interpreter reference, along with the write denial\nopen_exec() took on it. The denial is never released, so the file stays\nunwritable for as long as the system runs.\n\nAn unprivileged caller reaches this with a crafted binary and repeats it\nat will. binfmt_elf stops at the first PT_INTERP. Do the same here.\n\nThe flaw dates back to the driver\u0027s introduction in the pre-git history\ntree introduced in v2.6.11 by 91808d6ebe39 (\"[PATCH] FRV: Add FDPIC ELF\nbinary format driver\")."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:30:15.558Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/9854538349aaf6fb88ed33b56987954ac1716151"
},
{
"url": "https://git.kernel.org/stable/c/3c31397b0a75310217f1f2f3c7bdfd8af67aec4c"
},
{
"url": "https://git.kernel.org/stable/c/849a7bd9d266e43a457db5c6b322600f916a2127"
},
{
"url": "https://git.kernel.org/stable/c/e4563e07ef5c938d5332c5c44721db976f214bc6"
},
{
"url": "https://git.kernel.org/stable/c/21eaf5594a33d16343a011c752624099c30e918f"
},
{
"url": "https://git.kernel.org/stable/c/89b9121c3b0162655fc2f190b714ae64f1aa8cae"
},
{
"url": "https://git.kernel.org/stable/c/69ecc199880bf7e8d06224c82dc411d18f9285f8"
},
{
"url": "https://git.kernel.org/stable/c/3349ef6a366a61d631f6a263d12cea240957719d"
}
],
"title": "binfmt_elf_fdpic: only honour the first PT_INTERP",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68151",
"datePublished": "2026-08-10T11:59:16.878Z",
"dateReserved": "2026-07-30T09:28:09.371Z",
"dateUpdated": "2026-08-19T16:30:15.558Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68195 (GCVE-0-2026-68195)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses
PKT_TYPE_TXRX_NOTIFY is an mmio-only event, but mt7615_rx_check() and
mt7615_queue_rx_skb() dispatch it to mt7615_mac_tx_free() on every bus.
mt7615_mac_tx_free() cleans the DMA tx queues with
mt76_queue_tx_cleanup(), which calls queue_ops->tx_cleanup(). Only the
mmio queue ops implement that callback; on the mt7663 USB and SDIO
buses it is NULL, so a TXRX_NOTIFY there calls a NULL pointer in the RX
worker. Same defect as the mt7921 and mt7925 patches in this series.
Drop the event on non-mmio buses via mt76_is_mmio(), as in
commit 5683e1488aa9 ("wifi: mt76: connac: do not check WED status for
non-mmio devices").
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: eb99cc95c3b6513b495c4839ac4917206705f657 Version: eb99cc95c3b6513b495c4839ac4917206705f657 Version: eb99cc95c3b6513b495c4839ac4917206705f657 Version: eb99cc95c3b6513b495c4839ac4917206705f657 Version: eb99cc95c3b6513b495c4839ac4917206705f657 Version: eb99cc95c3b6513b495c4839ac4917206705f657 Version: eb99cc95c3b6513b495c4839ac4917206705f657 Version: eb99cc95c3b6513b495c4839ac4917206705f657 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/mediatek/mt76/mt7615/mac.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "664f8bbc61e45e062679da512bf12f8f6fb26a1b",
"status": "affected",
"version": "eb99cc95c3b6513b495c4839ac4917206705f657",
"versionType": "git"
},
{
"lessThan": "1a099d630b8667fa622662b85e35a0ef659fb343",
"status": "affected",
"version": "eb99cc95c3b6513b495c4839ac4917206705f657",
"versionType": "git"
},
{
"lessThan": "a0b3e8d8726c3830102a18946c766c94c953c7f2",
"status": "affected",
"version": "eb99cc95c3b6513b495c4839ac4917206705f657",
"versionType": "git"
},
{
"lessThan": "f2a72f47c5fb4ba6887e85bbe809d7e5b318d9d5",
"status": "affected",
"version": "eb99cc95c3b6513b495c4839ac4917206705f657",
"versionType": "git"
},
{
"lessThan": "88c98ef247a3126fea9bbbda953a18a2f36c3ea7",
"status": "affected",
"version": "eb99cc95c3b6513b495c4839ac4917206705f657",
"versionType": "git"
},
{
"lessThan": "ab4d213393e846baa6437497f94dda7553cbeda7",
"status": "affected",
"version": "eb99cc95c3b6513b495c4839ac4917206705f657",
"versionType": "git"
},
{
"lessThan": "b2ab73b8123ce6cf2bc32634bfee4928676ffa66",
"status": "affected",
"version": "eb99cc95c3b6513b495c4839ac4917206705f657",
"versionType": "git"
},
{
"lessThan": "39afc46c0243d10b7795e6e6cf4ae91f41732120",
"status": "affected",
"version": "eb99cc95c3b6513b495c4839ac4917206705f657",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/mediatek/mt76/mt7615/mac.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.8"
},
{
"lessThan": "5.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses\n\nPKT_TYPE_TXRX_NOTIFY is an mmio-only event, but mt7615_rx_check() and\nmt7615_queue_rx_skb() dispatch it to mt7615_mac_tx_free() on every bus.\nmt7615_mac_tx_free() cleans the DMA tx queues with\nmt76_queue_tx_cleanup(), which calls queue_ops-\u003etx_cleanup(). Only the\nmmio queue ops implement that callback; on the mt7663 USB and SDIO\nbuses it is NULL, so a TXRX_NOTIFY there calls a NULL pointer in the RX\nworker. Same defect as the mt7921 and mt7925 patches in this series.\n\nDrop the event on non-mmio buses via mt76_is_mmio(), as in\ncommit 5683e1488aa9 (\"wifi: mt76: connac: do not check WED status for\nnon-mmio devices\")."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:11.475Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/664f8bbc61e45e062679da512bf12f8f6fb26a1b"
},
{
"url": "https://git.kernel.org/stable/c/1a099d630b8667fa622662b85e35a0ef659fb343"
},
{
"url": "https://git.kernel.org/stable/c/a0b3e8d8726c3830102a18946c766c94c953c7f2"
},
{
"url": "https://git.kernel.org/stable/c/f2a72f47c5fb4ba6887e85bbe809d7e5b318d9d5"
},
{
"url": "https://git.kernel.org/stable/c/88c98ef247a3126fea9bbbda953a18a2f36c3ea7"
},
{
"url": "https://git.kernel.org/stable/c/ab4d213393e846baa6437497f94dda7553cbeda7"
},
{
"url": "https://git.kernel.org/stable/c/b2ab73b8123ce6cf2bc32634bfee4928676ffa66"
},
{
"url": "https://git.kernel.org/stable/c/39afc46c0243d10b7795e6e6cf4ae91f41732120"
}
],
"title": "wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68195",
"datePublished": "2026-08-10T12:00:13.627Z",
"dateReserved": "2026-07-30T09:28:09.374Z",
"dateUpdated": "2026-08-19T16:31:11.475Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68194 (GCVE-0-2026-68194)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio buses
PKT_TYPE_TXRX_NOTIFY is an mmio-only event, but mt7921_rx_check() and
mt7921_queue_rx_skb() dispatch it to mt7921_mac_tx_free() on every bus.
mt7921_mac_tx_free() cleans the DMA tx queues with
mt76_queue_tx_cleanup(), which calls queue_ops->tx_cleanup(). Only the
mmio queue ops implement that callback; on USB and SDIO it is NULL, so
a TXRX_NOTIFY there calls a NULL pointer in the RX worker:
BUG: kernel NULL pointer dereference, address: 0000000000000000
RIP: 0010:0x0
Call Trace:
mt7921_mac_tx_free+0x64/0x310 [mt7921_common]
mt7921_rx_check+0x5f/0xf0 [mt7921_common]
mt76u_rx_worker+0x1b9/0x620 [mt76_usb]
Drop the event on non-mmio buses via mt76_is_mmio(), as in
commit 5683e1488aa9 ("wifi: mt76: connac: do not check WED status for
non-mmio devices").
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 48fab5bbef4092d925ab3214773ad12e68807223 Version: 48fab5bbef4092d925ab3214773ad12e68807223 Version: 48fab5bbef4092d925ab3214773ad12e68807223 Version: 48fab5bbef4092d925ab3214773ad12e68807223 Version: 48fab5bbef4092d925ab3214773ad12e68807223 Version: 48fab5bbef4092d925ab3214773ad12e68807223 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/mediatek/mt76/mt7921/mac.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "7003a2cbddd7917933c1f169c7874cfa6ab852c3",
"status": "affected",
"version": "48fab5bbef4092d925ab3214773ad12e68807223",
"versionType": "git"
},
{
"lessThan": "ef2ee5f820c3ef87643b51e960c20b4a14d8336b",
"status": "affected",
"version": "48fab5bbef4092d925ab3214773ad12e68807223",
"versionType": "git"
},
{
"lessThan": "ecf995b828191829ba4a87169bccabcbeb5c9c32",
"status": "affected",
"version": "48fab5bbef4092d925ab3214773ad12e68807223",
"versionType": "git"
},
{
"lessThan": "263816e92e8d66c81c98ccab2b5d2191ed08ec71",
"status": "affected",
"version": "48fab5bbef4092d925ab3214773ad12e68807223",
"versionType": "git"
},
{
"lessThan": "24475d2ddc8d8dfd82f4d2be0d951401f86911a6",
"status": "affected",
"version": "48fab5bbef4092d925ab3214773ad12e68807223",
"versionType": "git"
},
{
"lessThan": "da4082e91acabc1498611ed8ccc53f0610baefc6",
"status": "affected",
"version": "48fab5bbef4092d925ab3214773ad12e68807223",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/mediatek/mt76/mt7921/mac.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.16"
},
{
"lessThan": "5.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.16",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio buses\n\nPKT_TYPE_TXRX_NOTIFY is an mmio-only event, but mt7921_rx_check() and\nmt7921_queue_rx_skb() dispatch it to mt7921_mac_tx_free() on every bus.\nmt7921_mac_tx_free() cleans the DMA tx queues with\nmt76_queue_tx_cleanup(), which calls queue_ops-\u003etx_cleanup(). Only the\nmmio queue ops implement that callback; on USB and SDIO it is NULL, so\na TXRX_NOTIFY there calls a NULL pointer in the RX worker:\n\n BUG: kernel NULL pointer dereference, address: 0000000000000000\n RIP: 0010:0x0\n Call Trace:\n mt7921_mac_tx_free+0x64/0x310 [mt7921_common]\n mt7921_rx_check+0x5f/0xf0 [mt7921_common]\n mt76u_rx_worker+0x1b9/0x620 [mt76_usb]\n\nDrop the event on non-mmio buses via mt76_is_mmio(), as in\ncommit 5683e1488aa9 (\"wifi: mt76: connac: do not check WED status for\nnon-mmio devices\")."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:09.017Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/7003a2cbddd7917933c1f169c7874cfa6ab852c3"
},
{
"url": "https://git.kernel.org/stable/c/ef2ee5f820c3ef87643b51e960c20b4a14d8336b"
},
{
"url": "https://git.kernel.org/stable/c/ecf995b828191829ba4a87169bccabcbeb5c9c32"
},
{
"url": "https://git.kernel.org/stable/c/263816e92e8d66c81c98ccab2b5d2191ed08ec71"
},
{
"url": "https://git.kernel.org/stable/c/24475d2ddc8d8dfd82f4d2be0d951401f86911a6"
},
{
"url": "https://git.kernel.org/stable/c/da4082e91acabc1498611ed8ccc53f0610baefc6"
}
],
"title": "wifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio buses",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68194",
"datePublished": "2026-08-10T12:00:12.245Z",
"dateReserved": "2026-07-30T09:28:09.374Z",
"dateUpdated": "2026-08-19T16:31:09.017Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68428 (GCVE-0-2026-68428)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-19 16:35
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
KVM: x86/mmu: Fix use-after-free on vendor module reload
mmu_destroy_caches() destroys pte_list_desc_cache and
mmu_page_header_cache, but leaves both pointers unchanged. The pointers
live in kvm.ko, and therefore survive when a vendor module is unloaded
while kvm.ko remains loaded.
If creation of pte_list_desc_cache fails during a subsequent vendor
module load, its assignment sets pte_list_desc_cache to NULL and the
error path calls mmu_destroy_caches(). mmu_page_header_cache still
points to the cache destroyed during the preceding vendor module
unload. Passing that stale pointer to kmem_cache_destroy() causes a
slab use-after-free.
Reproduce the issue on a v7.1.3 kernel with CONFIG_KASAN=y,
CONFIG_KASAN_GENERIC=y, CONFIG_KVM=m, and CONFIG_KVM_INTEL=m. A
one-shot test hook forces pte_list_desc_cache to NULL on the second
invocation of kvm_mmu_vendor_module_init():
1. Load kvm.ko and kvm-intel.ko, creating both caches.
2. Unload only kvm_intel, leaving kvm.ko loaded.
3. Reload kvm_intel and force initialization through the -ENOMEM path.
KASAN reports:
BUG: KASAN: slab-use-after-free in
kvm_mmu_vendor_module_init+0x5b/0x170 [kvm]
...
kmem_cache_destroy+0x21/0x1d0
kvm_mmu_vendor_module_init+0x5b/0x170 [kvm]
...
Allocated by task 16817:
__kmem_cache_create_args+0x12c/0x3b0
__kmem_cache_create.constprop.0+0xb6/0xf0 [kvm]
kvm_mmu_vendor_module_init+0x13b/0x170 [kvm]
...
Freed by task 16820:
kmem_cache_destroy+0x117/0x1d0
kvm_mmu_vendor_module_exit+0x21/0x30 [kvm]
Clear both pointers immediately after destroying their caches so that
the stored state reflects the caches' lifetime and repeated cleanup is
safe.
With the fix applied, the same injected vendor module reload fails with
-ENOMEM as expected and produces no KASAN report.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: cb498ea2ce1d3f3c0bc0a2522241dca10263e437 Version: cb498ea2ce1d3f3c0bc0a2522241dca10263e437 Version: cb498ea2ce1d3f3c0bc0a2522241dca10263e437 Version: cb498ea2ce1d3f3c0bc0a2522241dca10263e437 Version: cb498ea2ce1d3f3c0bc0a2522241dca10263e437 Version: cb498ea2ce1d3f3c0bc0a2522241dca10263e437 Version: cb498ea2ce1d3f3c0bc0a2522241dca10263e437 Version: cb498ea2ce1d3f3c0bc0a2522241dca10263e437 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"arch/x86/kvm/mmu/mmu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "034b7fa1f5846d69eb51f12ce6d1c71871e83c2d",
"status": "affected",
"version": "cb498ea2ce1d3f3c0bc0a2522241dca10263e437",
"versionType": "git"
},
{
"lessThan": "42272b0f239f3a89f9c26a01cc37aee06138b1b7",
"status": "affected",
"version": "cb498ea2ce1d3f3c0bc0a2522241dca10263e437",
"versionType": "git"
},
{
"lessThan": "940950d5cd86f250dca578279ad5ca63b4e0986b",
"status": "affected",
"version": "cb498ea2ce1d3f3c0bc0a2522241dca10263e437",
"versionType": "git"
},
{
"lessThan": "6f4be73880302d5642c83a0813fdfe1f5fd4b6e3",
"status": "affected",
"version": "cb498ea2ce1d3f3c0bc0a2522241dca10263e437",
"versionType": "git"
},
{
"lessThan": "32b9f89ed9e6d7a45075d64089c254a7f6e13695",
"status": "affected",
"version": "cb498ea2ce1d3f3c0bc0a2522241dca10263e437",
"versionType": "git"
},
{
"lessThan": "ec9daa8fd1b6f45545c9839dca55bd867fad9e13",
"status": "affected",
"version": "cb498ea2ce1d3f3c0bc0a2522241dca10263e437",
"versionType": "git"
},
{
"lessThan": "43cfb20d62ffe49626d62beecfc32eb6f262191c",
"status": "affected",
"version": "cb498ea2ce1d3f3c0bc0a2522241dca10263e437",
"versionType": "git"
},
{
"lessThan": "52f2f7c30126037975389aa04d24c506a5177c35",
"status": "affected",
"version": "cb498ea2ce1d3f3c0bc0a2522241dca10263e437",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"arch/x86/kvm/mmu/mmu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.25"
},
{
"lessThan": "2.6.25",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.25",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: x86/mmu: Fix use-after-free on vendor module reload\n\nmmu_destroy_caches() destroys pte_list_desc_cache and\nmmu_page_header_cache, but leaves both pointers unchanged. The pointers\nlive in kvm.ko, and therefore survive when a vendor module is unloaded\nwhile kvm.ko remains loaded.\n\nIf creation of pte_list_desc_cache fails during a subsequent vendor\nmodule load, its assignment sets pte_list_desc_cache to NULL and the\nerror path calls mmu_destroy_caches(). mmu_page_header_cache still\npoints to the cache destroyed during the preceding vendor module\nunload. Passing that stale pointer to kmem_cache_destroy() causes a\nslab use-after-free.\n\nReproduce the issue on a v7.1.3 kernel with CONFIG_KASAN=y,\nCONFIG_KASAN_GENERIC=y, CONFIG_KVM=m, and CONFIG_KVM_INTEL=m. A\none-shot test hook forces pte_list_desc_cache to NULL on the second\ninvocation of kvm_mmu_vendor_module_init():\n\n 1. Load kvm.ko and kvm-intel.ko, creating both caches.\n 2. Unload only kvm_intel, leaving kvm.ko loaded.\n 3. Reload kvm_intel and force initialization through the -ENOMEM path.\n\nKASAN reports:\n\n BUG: KASAN: slab-use-after-free in\n kvm_mmu_vendor_module_init+0x5b/0x170 [kvm]\n ...\n kmem_cache_destroy+0x21/0x1d0\n kvm_mmu_vendor_module_init+0x5b/0x170 [kvm]\n ...\n Allocated by task 16817:\n __kmem_cache_create_args+0x12c/0x3b0\n __kmem_cache_create.constprop.0+0xb6/0xf0 [kvm]\n kvm_mmu_vendor_module_init+0x13b/0x170 [kvm]\n ...\n Freed by task 16820:\n kmem_cache_destroy+0x117/0x1d0\n kvm_mmu_vendor_module_exit+0x21/0x30 [kvm]\n\nClear both pointers immediately after destroying their caches so that\nthe stored state reflects the caches\u0027 lifetime and repeated cleanup is\nsafe.\n\nWith the fix applied, the same injected vendor module reload fails with\n-ENOMEM as expected and produces no KASAN report."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:35:25.214Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/034b7fa1f5846d69eb51f12ce6d1c71871e83c2d"
},
{
"url": "https://git.kernel.org/stable/c/42272b0f239f3a89f9c26a01cc37aee06138b1b7"
},
{
"url": "https://git.kernel.org/stable/c/940950d5cd86f250dca578279ad5ca63b4e0986b"
},
{
"url": "https://git.kernel.org/stable/c/6f4be73880302d5642c83a0813fdfe1f5fd4b6e3"
},
{
"url": "https://git.kernel.org/stable/c/32b9f89ed9e6d7a45075d64089c254a7f6e13695"
},
{
"url": "https://git.kernel.org/stable/c/ec9daa8fd1b6f45545c9839dca55bd867fad9e13"
},
{
"url": "https://git.kernel.org/stable/c/43cfb20d62ffe49626d62beecfc32eb6f262191c"
},
{
"url": "https://git.kernel.org/stable/c/52f2f7c30126037975389aa04d24c506a5177c35"
}
],
"title": "KVM: x86/mmu: Fix use-after-free on vendor module reload",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68428",
"datePublished": "2026-08-10T12:04:48.905Z",
"dateReserved": "2026-07-30T09:28:09.393Z",
"dateUpdated": "2026-08-19T16:35:25.214Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68247 (GCVE-0-2026-68247)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-17 05:01
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/i915/bios: range check LFP Data Block panel_type2
While the panel_type from LFP Data Block is range checked, panel_type2
is not. Add a few helpers for range checking, and use them to not only
check panel_type2, but also improve clarity and correctness in the panel
type selection.
Discovered using AI-assisted static analysis confirmed by Intel Product
Security.
v2:
- Fix commit message typo (Michał)
- Add is_panel_type_pnp() (Ville)
(cherry picked from commit c9ebe5d2f25729d6cfbbb1235d640bf67f9275df)
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/i915/display/intel_bios.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "e7b5694645b03e80830dc141b59fc65aac693c70",
"status": "affected",
"version": "6434cf630086eea2d091f122f5802582a05d9d1c",
"versionType": "git"
},
{
"lessThan": "8b2da44446f9dce2ae50fee78bac2734d4277143",
"status": "affected",
"version": "6434cf630086eea2d091f122f5802582a05d9d1c",
"versionType": "git"
},
{
"lessThan": "8887b94d2fc93071bf6ff09c39d474510e6f582f",
"status": "affected",
"version": "6434cf630086eea2d091f122f5802582a05d9d1c",
"versionType": "git"
},
{
"lessThan": "2084503f2d087bf956198e7f6eb25b03a7049cb2",
"status": "affected",
"version": "6434cf630086eea2d091f122f5802582a05d9d1c",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/i915/display/intel_bios.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.0"
},
{
"lessThan": "6.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/i915/bios: range check LFP Data Block panel_type2\n\nWhile the panel_type from LFP Data Block is range checked, panel_type2\nis not. Add a few helpers for range checking, and use them to not only\ncheck panel_type2, but also improve clarity and correctness in the panel\ntype selection.\n\nDiscovered using AI-assisted static analysis confirmed by Intel Product\nSecurity.\n\nv2:\n- Fix commit message typo (Micha\u0142)\n- Add is_panel_type_pnp() (Ville)\n\n(cherry picked from commit c9ebe5d2f25729d6cfbbb1235d640bf67f9275df)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:01:37.262Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/e7b5694645b03e80830dc141b59fc65aac693c70"
},
{
"url": "https://git.kernel.org/stable/c/8b2da44446f9dce2ae50fee78bac2734d4277143"
},
{
"url": "https://git.kernel.org/stable/c/8887b94d2fc93071bf6ff09c39d474510e6f582f"
},
{
"url": "https://git.kernel.org/stable/c/2084503f2d087bf956198e7f6eb25b03a7049cb2"
}
],
"title": "drm/i915/bios: range check LFP Data Block panel_type2",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68247",
"datePublished": "2026-08-10T12:01:13.466Z",
"dateReserved": "2026-07-30T09:28:09.377Z",
"dateUpdated": "2026-08-17T05:01:37.262Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68186 (GCVE-0-2026-68186)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
binfmt_misc: set have_execfd only once the interpreter is opened
load_misc_binary() raises bprm->have_execfd as soon as it sees the 'O'
(or 'C') flag. This happens well before it opens the interpreter. If
that open fails the flag stays set on the bprm. binfmt_misc is at the
head of the format list so an interpreter open failure that returns
-ENOEXEC lets the search fall through to a later format. This means it
runs the matched binary directly having never staged an interpreter. So
bprm->executable is NULL while have_execfd falsely claims a descriptor
is present.
Consequently, begin_new_exec() dereferences the missing executable:
would_dump(bprm, bprm->executable);
and NULL derefs. Had it not, the hand-off later in the same function
would have failed anyway. FD_ADD(0, bprm->executable) rejects a NULL
file with -ENOMEM. Both sites are past the point of no return so the
exec cannot be unwound either way.
This can be reached by unprivileged users as binfmt_misc can be mounted
in user namespaces. So a user can register an 'O' entry whose
interpreter lives on a FUSE mount, have the FUSE server fail the open
with -ENOEXEC and execute a native ELF file that matches the entry.
have_execfd only means anything alongside the executable it describes
which is not set until the interpreter has been opened and staged.
So lets raise it there, next to execfd_creds, which is already set at
that point. An open failure now leaves it clear, so the fallback format
derives credentials from the binary and emits no AT_EXECFD, as it would
for any native exec. The argv rewrite load_misc_binary() performs before
the open is still not undone. This means the binary sees the interpreter
path in argv[0] and its own path in argv[1] but that predates this
change and only became observable once the exec stopped faulting.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: bc2bf338d54b7aadaed49bb45b9e10d4592b2a46 Version: bc2bf338d54b7aadaed49bb45b9e10d4592b2a46 Version: bc2bf338d54b7aadaed49bb45b9e10d4592b2a46 Version: bc2bf338d54b7aadaed49bb45b9e10d4592b2a46 Version: bc2bf338d54b7aadaed49bb45b9e10d4592b2a46 Version: bc2bf338d54b7aadaed49bb45b9e10d4592b2a46 Version: bc2bf338d54b7aadaed49bb45b9e10d4592b2a46 Version: bc2bf338d54b7aadaed49bb45b9e10d4592b2a46 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/binfmt_misc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a8e9e9450df44e9dd529ec5beff283f48f4f4b97",
"status": "affected",
"version": "bc2bf338d54b7aadaed49bb45b9e10d4592b2a46",
"versionType": "git"
},
{
"lessThan": "a261dc49d99681c9c71f38d16e31812dc3e30412",
"status": "affected",
"version": "bc2bf338d54b7aadaed49bb45b9e10d4592b2a46",
"versionType": "git"
},
{
"lessThan": "40c09b7a1d4e0a4866042c87c2bd911bb57566c8",
"status": "affected",
"version": "bc2bf338d54b7aadaed49bb45b9e10d4592b2a46",
"versionType": "git"
},
{
"lessThan": "0f19d54e2524f0bf183b82f365ae4e49b4a2f788",
"status": "affected",
"version": "bc2bf338d54b7aadaed49bb45b9e10d4592b2a46",
"versionType": "git"
},
{
"lessThan": "2dd0298905e97795a9c5ec30cf5b41975f821632",
"status": "affected",
"version": "bc2bf338d54b7aadaed49bb45b9e10d4592b2a46",
"versionType": "git"
},
{
"lessThan": "1cd4e9b7967dab48c9f79a00b06ffff7208c0993",
"status": "affected",
"version": "bc2bf338d54b7aadaed49bb45b9e10d4592b2a46",
"versionType": "git"
},
{
"lessThan": "5ccc99d58f94fad258c9c375715b3974e48620e8",
"status": "affected",
"version": "bc2bf338d54b7aadaed49bb45b9e10d4592b2a46",
"versionType": "git"
},
{
"lessThan": "bbf5f639918dc011aaf60aab8480218758ee68c5",
"status": "affected",
"version": "bc2bf338d54b7aadaed49bb45b9e10d4592b2a46",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/binfmt_misc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.8"
},
{
"lessThan": "5.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbinfmt_misc: set have_execfd only once the interpreter is opened\n\nload_misc_binary() raises bprm-\u003ehave_execfd as soon as it sees the \u0027O\u0027\n(or \u0027C\u0027) flag. This happens well before it opens the interpreter. If\nthat open fails the flag stays set on the bprm. binfmt_misc is at the\nhead of the format list so an interpreter open failure that returns\n-ENOEXEC lets the search fall through to a later format. This means it\nruns the matched binary directly having never staged an interpreter. So\nbprm-\u003eexecutable is NULL while have_execfd falsely claims a descriptor\nis present.\n\nConsequently, begin_new_exec() dereferences the missing executable:\n\n would_dump(bprm, bprm-\u003eexecutable);\n\nand NULL derefs. Had it not, the hand-off later in the same function\nwould have failed anyway. FD_ADD(0, bprm-\u003eexecutable) rejects a NULL\nfile with -ENOMEM. Both sites are past the point of no return so the\nexec cannot be unwound either way.\n\nThis can be reached by unprivileged users as binfmt_misc can be mounted\nin user namespaces. So a user can register an \u0027O\u0027 entry whose\ninterpreter lives on a FUSE mount, have the FUSE server fail the open\nwith -ENOEXEC and execute a native ELF file that matches the entry.\n\nhave_execfd only means anything alongside the executable it describes\nwhich is not set until the interpreter has been opened and staged.\nSo lets raise it there, next to execfd_creds, which is already set at\nthat point. An open failure now leaves it clear, so the fallback format\nderives credentials from the binary and emits no AT_EXECFD, as it would\nfor any native exec. The argv rewrite load_misc_binary() performs before\nthe open is still not undone. This means the binary sees the interpreter\npath in argv[0] and its own path in argv[1] but that predates this\nchange and only became observable once the exec stopped faulting."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:30:54.269Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a8e9e9450df44e9dd529ec5beff283f48f4f4b97"
},
{
"url": "https://git.kernel.org/stable/c/a261dc49d99681c9c71f38d16e31812dc3e30412"
},
{
"url": "https://git.kernel.org/stable/c/40c09b7a1d4e0a4866042c87c2bd911bb57566c8"
},
{
"url": "https://git.kernel.org/stable/c/0f19d54e2524f0bf183b82f365ae4e49b4a2f788"
},
{
"url": "https://git.kernel.org/stable/c/2dd0298905e97795a9c5ec30cf5b41975f821632"
},
{
"url": "https://git.kernel.org/stable/c/1cd4e9b7967dab48c9f79a00b06ffff7208c0993"
},
{
"url": "https://git.kernel.org/stable/c/5ccc99d58f94fad258c9c375715b3974e48620e8"
},
{
"url": "https://git.kernel.org/stable/c/bbf5f639918dc011aaf60aab8480218758ee68c5"
}
],
"title": "binfmt_misc: set have_execfd only once the interpreter is opened",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68186",
"datePublished": "2026-08-10T11:59:58.299Z",
"dateReserved": "2026-07-30T09:28:09.373Z",
"dateUpdated": "2026-08-19T16:30:54.269Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72103 (GCVE-0-2026-72103)
Vulnerability from cvelistv5
Published
2026-08-15 05:52
Modified
2026-08-17 05:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
dm: avoid leaking the caller's thread keyring via the table device file
The refactoring in commit a28d893eb327 ("md: port block device access to file")
accidentally causes the caller's thread keyring to be kept alive long
beyond the caller's lifetime.
As a result, "cryptsetup luksSuspend" silently fails to wipe the
LUKS volume key from memory.
In detail: "cryptsetup luksOpen" uses its supposedly ephemeral thread
keyring to pass the volume key to the kernel. dm-crypt's
crypt_set_keyring_key() copies the key material into its own
crypt_config structure and then drops its own reference to the key in
the keyring with key_put().
With this fix, restoring pre-v6.9 behavior, the copy in the thread
keyring is then promptly garbage collected, such that exactly one copy
of the volume key remains. This single copy is correctly wiped from
memory on "cryptsetup luksSuspend".
Without this fix, the thread keyring and the volume key in it remains.
This second copy is only freed on "luksClose". "luksSuspend" neither
knows about this copy nor has any way to remove it, so the key remains
recoverable from RAM after a suspend that is documented to have wiped it.
This fix should not introduce new security problems, as the code is
anyway gated by CAP_SYS_ADMIN. The device-mapper core, not the calling
task, is the legitimate owner of this long-lived file.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/md/dm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "d3eb8451d529ea452740d1a2bc395a1d20c48133",
"status": "affected",
"version": "a28d893eb3270cf62c10dd8777af0d8452cdc072",
"versionType": "git"
},
{
"lessThan": "8ced1d242c34e342defcccdb00663354f212aae6",
"status": "affected",
"version": "a28d893eb3270cf62c10dd8777af0d8452cdc072",
"versionType": "git"
},
{
"lessThan": "f00105be6a593920e9bc7949a069d4a116888851",
"status": "affected",
"version": "a28d893eb3270cf62c10dd8777af0d8452cdc072",
"versionType": "git"
},
{
"lessThan": "981ccd97f7153d310dfa92a534525bbaf46752c2",
"status": "affected",
"version": "a28d893eb3270cf62c10dd8777af0d8452cdc072",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/md/dm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.9"
},
{
"lessThan": "6.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndm: avoid leaking the caller\u0027s thread keyring via the table device file\n\nThe refactoring in commit a28d893eb327 (\"md: port block device access to file\")\naccidentally causes the caller\u0027s thread keyring to be kept alive long\nbeyond the caller\u0027s lifetime.\n\nAs a result, \"cryptsetup luksSuspend\" silently fails to wipe the\nLUKS volume key from memory.\n\nIn detail: \"cryptsetup luksOpen\" uses its supposedly ephemeral thread\nkeyring to pass the volume key to the kernel. dm-crypt\u0027s\ncrypt_set_keyring_key() copies the key material into its own\ncrypt_config structure and then drops its own reference to the key in\nthe keyring with key_put().\n\nWith this fix, restoring pre-v6.9 behavior, the copy in the thread\nkeyring is then promptly garbage collected, such that exactly one copy\nof the volume key remains. This single copy is correctly wiped from\nmemory on \"cryptsetup luksSuspend\".\n\nWithout this fix, the thread keyring and the volume key in it remains.\nThis second copy is only freed on \"luksClose\". \"luksSuspend\" neither\nknows about this copy nor has any way to remove it, so the key remains\nrecoverable from RAM after a suspend that is documented to have wiped it.\n\nThis fix should not introduce new security problems, as the code is\nanyway gated by CAP_SYS_ADMIN. The device-mapper core, not the calling\ntask, is the legitimate owner of this long-lived file."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is in open_table_device(), reached when CAP_SYS_ADMIN holders ioctl DM_TABLE_LOAD on /dev/mapper/control; table_load\u2192populate_table\u2192crypt_ctr\u2192dm_get_device\u2192bdev_file_open_by_dev pins caller creds. No network or physical-bus path reaches this code.\nAC:L - On every dm-crypt table load using cryptsetup\u0027s standard :logon: thread-keyring key path, bdev_file_open_by_dev unconditionally pins current_cred() into the long-lived table-device file; the extra volume-key copy then survives luksSuspend until luksClose with no race or victim-dependent heap layout.\nPR:L - ctl_ioctl requires capable(CAP_SYS_ADMIN) before dm commands; per kernel CNA guidance CAP_SYS_ADMIN obtainable in a user namespace maps to Low, and attackers routinely use namespace-level dm-crypt/LUKS administration on servers, containers, and encrypted workstations.\nUI:N - Exploitation does not require a victim to open untrusted files or mount attacker media; the latent leaked key is created by routine automated cryptsetup luksOpen/luksSuspend during boot and system suspend on LUKS deployments.\nS:U - The flaw only prevents wiping a dm-crypt volume key still held in a pinned thread keyring within the host kernel; it does not cross VM/hypervisor, IOMMU, or other separate security-authority boundaries.\nC:H - luksSuspend is documented to remove all in-kernel copies of the LUKS volume key, but the pinned logon-key payload in the leaked thread keyring remains recoverable from RAM via forensic access until luksClose, exposing the full disk-encryption key.\nI:H - Recovery of the dm-crypt volume key grants an attacker unrestricted read and write access to the entire LUKS-protected block device, enabling undetected modification of all encrypted data the suspend operation was meant to keep inaccessible.\nA:L - The pinned bdev_file keeps the caller\u0027s credentials and thread keyring (with logon key material) allocated for the dm device lifetime; this is a long-lived kernel memory retention/leak without crash, though not a service outage."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:40:17.887Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/d3eb8451d529ea452740d1a2bc395a1d20c48133"
},
{
"url": "https://git.kernel.org/stable/c/8ced1d242c34e342defcccdb00663354f212aae6"
},
{
"url": "https://git.kernel.org/stable/c/f00105be6a593920e9bc7949a069d4a116888851"
},
{
"url": "https://git.kernel.org/stable/c/981ccd97f7153d310dfa92a534525bbaf46752c2"
}
],
"title": "dm: avoid leaking the caller\u0027s thread keyring via the table device file",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72103",
"datePublished": "2026-08-15T05:52:46.824Z",
"dateReserved": "2026-08-09T03:40:39.906Z",
"dateUpdated": "2026-08-17T05:40:17.887Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68183 (GCVE-0-2026-68183)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
firmware: stratix10-svc: fix memory leaks and list corruption bugs
Fix a memory leak when gen_pool_alloc() fails by freeing pmem on the error
path. Switch pmem allocation from devm_kzalloc() to kzalloc() with
explicit kfree() in the free path to match its list-managed lifetime.
Remove the erroneous list_del(&svc_data_mem) which corrupted the list head
on failed lookups.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 7ca5ce896524f5292e610b27d168269e5ab74951 Version: 7ca5ce896524f5292e610b27d168269e5ab74951 Version: 7ca5ce896524f5292e610b27d168269e5ab74951 Version: 7ca5ce896524f5292e610b27d168269e5ab74951 Version: 7ca5ce896524f5292e610b27d168269e5ab74951 Version: 7ca5ce896524f5292e610b27d168269e5ab74951 Version: 7ca5ce896524f5292e610b27d168269e5ab74951 Version: 7ca5ce896524f5292e610b27d168269e5ab74951 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/firmware/stratix10-svc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "76cff60d7fcb08da537f529bf32a0927bb17265f",
"status": "affected",
"version": "7ca5ce896524f5292e610b27d168269e5ab74951",
"versionType": "git"
},
{
"lessThan": "b9206568e08424fd817a4aeca4f944e241d2f530",
"status": "affected",
"version": "7ca5ce896524f5292e610b27d168269e5ab74951",
"versionType": "git"
},
{
"lessThan": "5df709d59227994888d7dbb7ea6c83316f0b79c0",
"status": "affected",
"version": "7ca5ce896524f5292e610b27d168269e5ab74951",
"versionType": "git"
},
{
"lessThan": "95f702e372964aff486338783f49e28a40a53127",
"status": "affected",
"version": "7ca5ce896524f5292e610b27d168269e5ab74951",
"versionType": "git"
},
{
"lessThan": "fff6e5ff0318315998b540896537eaaa2ebf9f7b",
"status": "affected",
"version": "7ca5ce896524f5292e610b27d168269e5ab74951",
"versionType": "git"
},
{
"lessThan": "4f2db41a09eba7a45abd140bb86ffc519c191886",
"status": "affected",
"version": "7ca5ce896524f5292e610b27d168269e5ab74951",
"versionType": "git"
},
{
"lessThan": "8e93a083456d78f6b0aa1f58d2b0c7071a2a7a47",
"status": "affected",
"version": "7ca5ce896524f5292e610b27d168269e5ab74951",
"versionType": "git"
},
{
"lessThan": "9119ceb76e987c2ec2b549ea100e3268ce3a1c7c",
"status": "affected",
"version": "7ca5ce896524f5292e610b27d168269e5ab74951",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/firmware/stratix10-svc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.0"
},
{
"lessThan": "5.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: stratix10-svc: fix memory leaks and list corruption bugs\n\nFix a memory leak when gen_pool_alloc() fails by freeing pmem on the error\npath. Switch pmem allocation from devm_kzalloc() to kzalloc() with\nexplicit kfree() in the free path to match its list-managed lifetime.\nRemove the erroneous list_del(\u0026svc_data_mem) which corrupted the list head\non failed lookups."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:30:49.896Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/76cff60d7fcb08da537f529bf32a0927bb17265f"
},
{
"url": "https://git.kernel.org/stable/c/b9206568e08424fd817a4aeca4f944e241d2f530"
},
{
"url": "https://git.kernel.org/stable/c/5df709d59227994888d7dbb7ea6c83316f0b79c0"
},
{
"url": "https://git.kernel.org/stable/c/95f702e372964aff486338783f49e28a40a53127"
},
{
"url": "https://git.kernel.org/stable/c/fff6e5ff0318315998b540896537eaaa2ebf9f7b"
},
{
"url": "https://git.kernel.org/stable/c/4f2db41a09eba7a45abd140bb86ffc519c191886"
},
{
"url": "https://git.kernel.org/stable/c/8e93a083456d78f6b0aa1f58d2b0c7071a2a7a47"
},
{
"url": "https://git.kernel.org/stable/c/9119ceb76e987c2ec2b549ea100e3268ce3a1c7c"
}
],
"title": "firmware: stratix10-svc: fix memory leaks and list corruption bugs",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68183",
"datePublished": "2026-08-10T11:59:54.836Z",
"dateReserved": "2026-07-30T09:28:09.373Z",
"dateUpdated": "2026-08-19T16:30:49.896Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68299 (GCVE-0-2026-68299)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-19 16:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets
vmxnet3_get_hdr_len() assumes gdesc->rcd.v4/v6/tcp always describe the
outer header, but for a Geneve-encapsulated packet the device can set
them based on the inner header instead, signalled by the
VMXNET3_RCD_HDR_INNER_SHIFT bit in the completion descriptor. Since the
function never skips the outer encapsulation, this mismatch triggers:
- BUG_ON(hdr.ipv4->protocol != IPPROTO_TCP), because the outer
protocol is UDP (Geneve), not TCP.
- BUG_ON(hdr.eth->h_proto != ...), when the tunnel's outer and inner
IP versions differ (e.g. outer IPv6/inner IPv4 or vice versa).
Check VMXNET3_RCD_HDR_INNER_SHIFT up front and bail out, since the
function cannot locate the inner header it would need to parse. Also
convert the remaining BUG_ON()s in this function to return 0
defensively.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 45dac1d6ea045ae56e4df8d9c70c92c7412bd4fc Version: 45dac1d6ea045ae56e4df8d9c70c92c7412bd4fc Version: 45dac1d6ea045ae56e4df8d9c70c92c7412bd4fc Version: 45dac1d6ea045ae56e4df8d9c70c92c7412bd4fc Version: 45dac1d6ea045ae56e4df8d9c70c92c7412bd4fc Version: 45dac1d6ea045ae56e4df8d9c70c92c7412bd4fc Version: 45dac1d6ea045ae56e4df8d9c70c92c7412bd4fc Version: 45dac1d6ea045ae56e4df8d9c70c92c7412bd4fc |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/vmxnet3/vmxnet3_drv.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "2ddf51fcb6dd7d55ceef38e2e1a5ab2ab7fd47b0",
"status": "affected",
"version": "45dac1d6ea045ae56e4df8d9c70c92c7412bd4fc",
"versionType": "git"
},
{
"lessThan": "fbab6b73cc086e32698c86e43d1b16bf17d24c36",
"status": "affected",
"version": "45dac1d6ea045ae56e4df8d9c70c92c7412bd4fc",
"versionType": "git"
},
{
"lessThan": "28e382646417c7e2be9c9a7079eddf627ff52b90",
"status": "affected",
"version": "45dac1d6ea045ae56e4df8d9c70c92c7412bd4fc",
"versionType": "git"
},
{
"lessThan": "667b6e52048eaf4dbcf1707ed87ffd44abb9cb38",
"status": "affected",
"version": "45dac1d6ea045ae56e4df8d9c70c92c7412bd4fc",
"versionType": "git"
},
{
"lessThan": "28cb5d8d13b4c1faf3f688f62e5df82fe7b438d8",
"status": "affected",
"version": "45dac1d6ea045ae56e4df8d9c70c92c7412bd4fc",
"versionType": "git"
},
{
"lessThan": "4fdb0f162ccdbe9626863b10003855703253fa29",
"status": "affected",
"version": "45dac1d6ea045ae56e4df8d9c70c92c7412bd4fc",
"versionType": "git"
},
{
"lessThan": "b28596baf87e25a078789f1c05817c8a3bf71257",
"status": "affected",
"version": "45dac1d6ea045ae56e4df8d9c70c92c7412bd4fc",
"versionType": "git"
},
{
"lessThan": "34a71f5361fc3adb5b7138da78750b0d535a8252",
"status": "affected",
"version": "45dac1d6ea045ae56e4df8d9c70c92c7412bd4fc",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/vmxnet3/vmxnet3_drv.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.2"
},
{
"lessThan": "4.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nvmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets\n\nvmxnet3_get_hdr_len() assumes gdesc-\u003ercd.v4/v6/tcp always describe the\nouter header, but for a Geneve-encapsulated packet the device can set\nthem based on the inner header instead, signalled by the\nVMXNET3_RCD_HDR_INNER_SHIFT bit in the completion descriptor. Since the\nfunction never skips the outer encapsulation, this mismatch triggers:\n\n- BUG_ON(hdr.ipv4-\u003eprotocol != IPPROTO_TCP), because the outer\n protocol is UDP (Geneve), not TCP.\n- BUG_ON(hdr.eth-\u003eh_proto != ...), when the tunnel\u0027s outer and inner\n IP versions differ (e.g. outer IPv6/inner IPv4 or vice versa).\n\nCheck VMXNET3_RCD_HDR_INNER_SHIFT up front and bail out, since the\nfunction cannot locate the inner header it would need to parse. Also\nconvert the remaining BUG_ON()s in this function to return 0\ndefensively."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug is triggered purely by a received Geneve-encapsulated packet processed in the vmxnet3 RX completion path (vmxnet3_rq_rx_complete -\u003e vmxnet3_get_hdr_len); any remote host that can deliver such a frame to a VMware guest\u0027s vmxnet3 interface reaches the code, with no local access required.\nAC:L - The attacker only needs to send Geneve-encapsulated TCP traffic larger than the MTU to the target; the device then sets rcd.v4/v6/tcp from the inner header and the outer UDP protocol (or an outer/inner IP version mismatch) deterministically hits the BUG_ON, with no race or memory-layout dependency.\nPR:N - Packet reception and header-length estimation occur in the driver\u0027s NAPI RX path before any socket, credential, or authentication check, so an entirely unauthenticated remote sender triggers it.\nUI:N - The panic happens during normal NAPI RX processing of an incoming packet; no action by any local user or administrator is needed.\nS:U - The BUG_ON crashes the kernel that owns the vmxnet3 interface, and impact stays entirely within that kernel\u0027s security authority with no crossing into the hypervisor or another domain.\nC:N - The header parsing is bounded by the explicit skb_headlen()/maplen checks, so no out-of-bounds read occurs and no kernel memory contents are disclosed to the attacker before the BUG_ON aborts.\nI:N - No out-of-bounds or attacker-controlled write occurs; the mismatch is caught by the BUG_ON assertion, which halts execution rather than corrupting kernel memory or control flow.\nA:H - Hitting BUG_ON() in softirq/NAPI context oopses and panics the kernel, taking down the entire guest; a remote attacker can repeat it with a single crafted Geneve packet stream for a persistent denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:32:48.545Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/2ddf51fcb6dd7d55ceef38e2e1a5ab2ab7fd47b0"
},
{
"url": "https://git.kernel.org/stable/c/fbab6b73cc086e32698c86e43d1b16bf17d24c36"
},
{
"url": "https://git.kernel.org/stable/c/28e382646417c7e2be9c9a7079eddf627ff52b90"
},
{
"url": "https://git.kernel.org/stable/c/667b6e52048eaf4dbcf1707ed87ffd44abb9cb38"
},
{
"url": "https://git.kernel.org/stable/c/28cb5d8d13b4c1faf3f688f62e5df82fe7b438d8"
},
{
"url": "https://git.kernel.org/stable/c/4fdb0f162ccdbe9626863b10003855703253fa29"
},
{
"url": "https://git.kernel.org/stable/c/b28596baf87e25a078789f1c05817c8a3bf71257"
},
{
"url": "https://git.kernel.org/stable/c/34a71f5361fc3adb5b7138da78750b0d535a8252"
}
],
"title": "vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68299",
"datePublished": "2026-08-10T12:02:33.213Z",
"dateReserved": "2026-07-30T09:28:09.380Z",
"dateUpdated": "2026-08-19T16:32:48.545Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-45901 (GCVE-0-2026-45901)
Vulnerability from cvelistv5
Published
2026-05-27 12:17
Modified
2026-08-03 09:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_tables: revert commit_mutex usage in reset path
It causes circular lock dependency between commit_mutex, nfnl_subsys_ipset
and nlk_cb_mutex when nft reset, ipset list, and iptables-nft with '-m set'
rule run at the same time.
Previous patches made it safe to run individual reset handlers concurrently
so commit_mutex is no longer required to prevent this.
References
| URL | Tags | |
|---|---|---|
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 3cb03edb4de33fd04c4ea55f47397b96a8657c53 Version: 3cb03edb4de33fd04c4ea55f47397b96a8657c53 Version: 3cb03edb4de33fd04c4ea55f47397b96a8657c53 Version: 3cb03edb4de33fd04c4ea55f47397b96a8657c53 Version: fb1adb05ea87b6149e65a31e511756c4f470d0cd Version: f123293db16dcd0cd81b246ae60e6362f0025d0a Version: 6.1.107 ≤ Version: 6.6.48 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/netfilter/nf_tables_api.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "d66bedfe97a2bc321fa8118e669aae988038f729",
"status": "affected",
"version": "3cb03edb4de33fd04c4ea55f47397b96a8657c53",
"versionType": "git"
},
{
"lessThan": "f6410d18c1e2da325df02be989d5bca5ed38b086",
"status": "affected",
"version": "3cb03edb4de33fd04c4ea55f47397b96a8657c53",
"versionType": "git"
},
{
"lessThan": "ee3978b6a0dcd4215cb7cedcba705a12174786a7",
"status": "affected",
"version": "3cb03edb4de33fd04c4ea55f47397b96a8657c53",
"versionType": "git"
},
{
"lessThan": "7f261bb906bf527c4a6e2a646e2d5f3679f2a8bc",
"status": "affected",
"version": "3cb03edb4de33fd04c4ea55f47397b96a8657c53",
"versionType": "git"
},
{
"status": "affected",
"version": "fb1adb05ea87b6149e65a31e511756c4f470d0cd",
"versionType": "git"
},
{
"status": "affected",
"version": "f123293db16dcd0cd81b246ae60e6362f0025d0a",
"versionType": "git"
},
{
"lessThan": "6.2",
"status": "affected",
"version": "6.1.107",
"versionType": "semver"
},
{
"lessThan": "6.7",
"status": "affected",
"version": "6.6.48",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/netfilter/nf_tables_api.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.7"
},
{
"lessThan": "6.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.19.*",
"status": "unaffected",
"version": "6.19.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.0",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.19.4",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.1.107",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.6.48",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: revert commit_mutex usage in reset path\n\nIt causes circular lock dependency between commit_mutex, nfnl_subsys_ipset\nand nlk_cb_mutex when nft reset, ipset list, and iptables-nft with \u0027-m set\u0027\nrule run at the same time.\n\nPrevious patches made it safe to run individual reset handlers concurrently\nso commit_mutex is no longer required to prevent this."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-03T09:32:31.525Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/d66bedfe97a2bc321fa8118e669aae988038f729"
},
{
"url": "https://git.kernel.org/stable/c/f6410d18c1e2da325df02be989d5bca5ed38b086"
},
{
"url": "https://git.kernel.org/stable/c/ee3978b6a0dcd4215cb7cedcba705a12174786a7"
},
{
"url": "https://git.kernel.org/stable/c/7f261bb906bf527c4a6e2a646e2d5f3679f2a8bc"
}
],
"title": "netfilter: nf_tables: revert commit_mutex usage in reset path",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-45901",
"datePublished": "2026-05-27T12:17:09.861Z",
"dateReserved": "2026-05-13T15:03:33.084Z",
"dateUpdated": "2026-08-03T09:32:31.525Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68243 (GCVE-0-2026-68243)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-19 16:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU
Setting context engine slot N into I915_ENGINE_CLASS_INVALID /
I915_ENGINE_CLASS_INVALID_NONE and attempting to apply
I915_CONTEXT_PARAM_SSEU to the same slot N will deref NULL.
Fix that.
Discovered using AI-assisted static analysis confirmed by
Intel Product Security.
(cherry picked from commit 36eda5b5c2d40da41cc0a5403c26986237cf9e87)
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d4433c7600f794623d6802395542cf4ca4f1b1f9 Version: d4433c7600f794623d6802395542cf4ca4f1b1f9 Version: d4433c7600f794623d6802395542cf4ca4f1b1f9 Version: d4433c7600f794623d6802395542cf4ca4f1b1f9 Version: d4433c7600f794623d6802395542cf4ca4f1b1f9 Version: d4433c7600f794623d6802395542cf4ca4f1b1f9 Version: d4433c7600f794623d6802395542cf4ca4f1b1f9 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/i915/gem/i915_gem_context.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "97a4872ef927dee301d76085cb19f6e36d4a53a4",
"status": "affected",
"version": "d4433c7600f794623d6802395542cf4ca4f1b1f9",
"versionType": "git"
},
{
"lessThan": "b226dee4ee1fff2909f79e8ad700b7082f8d3569",
"status": "affected",
"version": "d4433c7600f794623d6802395542cf4ca4f1b1f9",
"versionType": "git"
},
{
"lessThan": "edd2edaca52ada833c341c8b264aaea9dd93369c",
"status": "affected",
"version": "d4433c7600f794623d6802395542cf4ca4f1b1f9",
"versionType": "git"
},
{
"lessThan": "9923c223d38fcd9602f41cc31d480e5299d9a38e",
"status": "affected",
"version": "d4433c7600f794623d6802395542cf4ca4f1b1f9",
"versionType": "git"
},
{
"lessThan": "726f27bca93e6c83b263542669132ee1d0eb693e",
"status": "affected",
"version": "d4433c7600f794623d6802395542cf4ca4f1b1f9",
"versionType": "git"
},
{
"lessThan": "97f236379f06a5082d37c6a764edd56bb58a94cd",
"status": "affected",
"version": "d4433c7600f794623d6802395542cf4ca4f1b1f9",
"versionType": "git"
},
{
"lessThan": "2b56757a9a7456825eb668fde92299e01c5e2721",
"status": "affected",
"version": "d4433c7600f794623d6802395542cf4ca4f1b1f9",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/i915/gem/i915_gem_context.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.15"
},
{
"lessThan": "5.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU\n\nSetting context engine slot N into I915_ENGINE_CLASS_INVALID /\nI915_ENGINE_CLASS_INVALID_NONE and attempting to apply\nI915_CONTEXT_PARAM_SSEU to the same slot N will deref NULL.\nFix that.\n\nDiscovered using AI-assisted static analysis confirmed by\nIntel Product Security.\n\n(cherry picked from commit 36eda5b5c2d40da41cc0a5403c26986237cf9e87)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:32:08.740Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/97a4872ef927dee301d76085cb19f6e36d4a53a4"
},
{
"url": "https://git.kernel.org/stable/c/b226dee4ee1fff2909f79e8ad700b7082f8d3569"
},
{
"url": "https://git.kernel.org/stable/c/edd2edaca52ada833c341c8b264aaea9dd93369c"
},
{
"url": "https://git.kernel.org/stable/c/9923c223d38fcd9602f41cc31d480e5299d9a38e"
},
{
"url": "https://git.kernel.org/stable/c/726f27bca93e6c83b263542669132ee1d0eb693e"
},
{
"url": "https://git.kernel.org/stable/c/97f236379f06a5082d37c6a764edd56bb58a94cd"
},
{
"url": "https://git.kernel.org/stable/c/2b56757a9a7456825eb668fde92299e01c5e2721"
}
],
"title": "drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68243",
"datePublished": "2026-08-10T12:01:09.484Z",
"dateReserved": "2026-07-30T09:28:09.377Z",
"dateUpdated": "2026-08-19T16:32:08.740Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68417 (GCVE-0-2026-68417)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-19 16:35
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
RDMA/siw: publish QP after initialization
siw_create_qp() currently calls siw_qp_add() before the queues, CQ
pointers, state, completion, and device list entry are ready. A QPN
lookup can therefore reach a QP that is still being constructed.
Move siw_qp_add() to the end of siw_create_qp(), after QP
initialization and before adding the QP to the siw device list.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: f29dd55b0236f7a26a4b9dd69186e3c04266797b Version: f29dd55b0236f7a26a4b9dd69186e3c04266797b Version: f29dd55b0236f7a26a4b9dd69186e3c04266797b Version: f29dd55b0236f7a26a4b9dd69186e3c04266797b Version: f29dd55b0236f7a26a4b9dd69186e3c04266797b Version: f29dd55b0236f7a26a4b9dd69186e3c04266797b Version: f29dd55b0236f7a26a4b9dd69186e3c04266797b |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/sw/siw/siw_verbs.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "3c9d128219964dcea897bf6139b88242e987be8f",
"status": "affected",
"version": "f29dd55b0236f7a26a4b9dd69186e3c04266797b",
"versionType": "git"
},
{
"lessThan": "3ff82e3841ecab1ff38d5817c969a019d266c83c",
"status": "affected",
"version": "f29dd55b0236f7a26a4b9dd69186e3c04266797b",
"versionType": "git"
},
{
"lessThan": "36e91a58397ca8c978e38a0bf389f0c6113fa8ca",
"status": "affected",
"version": "f29dd55b0236f7a26a4b9dd69186e3c04266797b",
"versionType": "git"
},
{
"lessThan": "74912ad168f87d6b2b670a87987bb302d6e64aa1",
"status": "affected",
"version": "f29dd55b0236f7a26a4b9dd69186e3c04266797b",
"versionType": "git"
},
{
"lessThan": "fcc9d50022bcdb1f9f7ed04955c72b4a7355af3d",
"status": "affected",
"version": "f29dd55b0236f7a26a4b9dd69186e3c04266797b",
"versionType": "git"
},
{
"lessThan": "52f9fcb191143448df55fd215ff09c5207fed43e",
"status": "affected",
"version": "f29dd55b0236f7a26a4b9dd69186e3c04266797b",
"versionType": "git"
},
{
"lessThan": "bb27fcc67c429d97f785c92c35a6c5adebb05d7f",
"status": "affected",
"version": "f29dd55b0236f7a26a4b9dd69186e3c04266797b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/sw/siw/siw_verbs.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.3"
},
{
"lessThan": "5.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/siw: publish QP after initialization\n\nsiw_create_qp() currently calls siw_qp_add() before the queues, CQ\npointers, state, completion, and device list entry are ready. A QPN\nlookup can therefore reach a QP that is still being constructed.\n\nMove siw_qp_add() to the end of siw_create_qp(), after QP\ninitialization and before adding the QP to the siw device list."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires local access to the RDMA character devices (/dev/infiniband/uverbsN for create_qp and /dev/infiniband/rdma_cm for the QPN lookup); no network packet reaches the racing code path without a local trigger first.\nAC:L - The attacker controls both sides of the race: one thread issues create_qp while another issues rdma_connect/rdma_accept with an attacker-supplied qp_num, and QPNs from xa_alloc(XA_FLAGS_ALLOC1) are predictable. The post-publish failure can be made deterministic by passing a short udata-\u003eoutlen, so the window is wide and repeatable at will.\nPR:L - Any unprivileged local user with access to the siw uverbs and rdma_cm character devices can create QPs and issue rdma_connect/rdma_accept with an arbitrary qp_num; no capability check gates siw_create_qp, siw_connect or siw_accept.\nUI:N - The attacker drives both the QP creation and the concurrent QPN lookup from its own threads; no action by any other user or administrator is needed.\nS:U - The corruption is confined to kernel memory managed by the same kernel security authority; there is no crossing of a VM, IOMMU or sandbox boundary.\nC:H - The siw_qp object can be kfree\u0027d by the ib core error path while the CM thread still holds a reference, giving a use-after-free on a slab object the attacker can groom and read back through QP/CM state, enabling disclosure of arbitrary kernel memory.\nI:H - After the free, siw_free_qp() performs list_del(\u0026qp-\u003edevq), vfree() of four pointer fields and siw_put_tx_cpu(qp-\u003etx_cpu) using values read from reallocated attacker-controlled memory, yielding arbitrary-pointer free, list-unlink writes and out-of-range per-CPU decrements suitable for control-flow hijacking.\nA:H - Even without exploitation the race reliably causes kernel crashes: NULL sendq/recvq/scq/rcq dereferences, list_del on an uninitialized devq head, waits on an uninitialized qp_free completion, and use-after-free oopses."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:35:15.087Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/3c9d128219964dcea897bf6139b88242e987be8f"
},
{
"url": "https://git.kernel.org/stable/c/3ff82e3841ecab1ff38d5817c969a019d266c83c"
},
{
"url": "https://git.kernel.org/stable/c/36e91a58397ca8c978e38a0bf389f0c6113fa8ca"
},
{
"url": "https://git.kernel.org/stable/c/74912ad168f87d6b2b670a87987bb302d6e64aa1"
},
{
"url": "https://git.kernel.org/stable/c/fcc9d50022bcdb1f9f7ed04955c72b4a7355af3d"
},
{
"url": "https://git.kernel.org/stable/c/52f9fcb191143448df55fd215ff09c5207fed43e"
},
{
"url": "https://git.kernel.org/stable/c/bb27fcc67c429d97f785c92c35a6c5adebb05d7f"
}
],
"title": "RDMA/siw: publish QP after initialization",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68417",
"datePublished": "2026-08-10T12:04:37.936Z",
"dateReserved": "2026-07-30T09:28:09.391Z",
"dateUpdated": "2026-08-19T16:35:15.087Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72062 (GCVE-0-2026-72062)
Vulnerability from cvelistv5
Published
2026-08-15 05:52
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
gpio: mt7621: avoid corruption of shared interrupt trigger state
The bank-shared fields like 'rising' and 'falling' are modified using
non-atomic read-modify-write operations. Since every gpio chip instance
represents an entire bank of 32 pins, if 'mediatek_gpio_irq_type()' is
called concurrently for different IRQs on the same bank a possible overwrite
of each other's configuration is possible. Thus, protect this state with
'gpio_generic_lock_irqsave' lock in the same way it is handled in irp_chip
'mediatek_gpio_irq_mask()' and 'mediatek_gpio_irq_unmask()' callbacks.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 4ba9c3afda41213ec98c30053e32963892e6dc7c Version: 4ba9c3afda41213ec98c30053e32963892e6dc7c Version: 4ba9c3afda41213ec98c30053e32963892e6dc7c Version: 4ba9c3afda41213ec98c30053e32963892e6dc7c Version: 4ba9c3afda41213ec98c30053e32963892e6dc7c Version: 4ba9c3afda41213ec98c30053e32963892e6dc7c |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpio/gpio-mt7621.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "bddf9314a57a243dd11ed945ba11e146e331257e",
"status": "affected",
"version": "4ba9c3afda41213ec98c30053e32963892e6dc7c",
"versionType": "git"
},
{
"lessThan": "207d3ebf36f654a43a934addeb4d6775cb2dd667",
"status": "affected",
"version": "4ba9c3afda41213ec98c30053e32963892e6dc7c",
"versionType": "git"
},
{
"lessThan": "877a243006788aaa586b2d087f27c9f3628071b0",
"status": "affected",
"version": "4ba9c3afda41213ec98c30053e32963892e6dc7c",
"versionType": "git"
},
{
"lessThan": "d3b9026ef78da3018a7d2c5a9c9d611de6d45c47",
"status": "affected",
"version": "4ba9c3afda41213ec98c30053e32963892e6dc7c",
"versionType": "git"
},
{
"lessThan": "a60a40c9ba30edd06d3fb4215fdf430ed968728e",
"status": "affected",
"version": "4ba9c3afda41213ec98c30053e32963892e6dc7c",
"versionType": "git"
},
{
"lessThan": "1781172526d1092323af443fa03f00e6de560401",
"status": "affected",
"version": "4ba9c3afda41213ec98c30053e32963892e6dc7c",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpio/gpio-mt7621.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.19"
},
{
"lessThan": "4.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ngpio: mt7621: avoid corruption of shared interrupt trigger state\n\nThe bank-shared fields like \u0027rising\u0027 and \u0027falling\u0027 are modified using\nnon-atomic read-modify-write operations. Since every gpio chip instance\nrepresents an entire bank of 32 pins, if \u0027mediatek_gpio_irq_type()\u0027 is\ncalled concurrently for different IRQs on the same bank a possible overwrite\nof each other\u0027s configuration is possible. Thus, protect this state with\n\u0027gpio_generic_lock_irqsave\u0027 lock in the same way it is handled in irp_chip\n\u0027mediatek_gpio_irq_mask()\u0027 and \u0027mediatek_gpio_irq_unmask()\u0027 callbacks."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:38.586Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/bddf9314a57a243dd11ed945ba11e146e331257e"
},
{
"url": "https://git.kernel.org/stable/c/207d3ebf36f654a43a934addeb4d6775cb2dd667"
},
{
"url": "https://git.kernel.org/stable/c/877a243006788aaa586b2d087f27c9f3628071b0"
},
{
"url": "https://git.kernel.org/stable/c/d3b9026ef78da3018a7d2c5a9c9d611de6d45c47"
},
{
"url": "https://git.kernel.org/stable/c/a60a40c9ba30edd06d3fb4215fdf430ed968728e"
},
{
"url": "https://git.kernel.org/stable/c/1781172526d1092323af443fa03f00e6de560401"
}
],
"title": "gpio: mt7621: avoid corruption of shared interrupt trigger state",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72062",
"datePublished": "2026-08-15T05:52:16.564Z",
"dateReserved": "2026-08-09T03:40:39.903Z",
"dateUpdated": "2026-08-23T12:46:38.586Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68449 (GCVE-0-2026-68449)
Vulnerability from cvelistv5
Published
2026-08-12 00:51
Modified
2026-08-19 16:35
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ata: sata_dwc_460ex: fix infinite loop in NCQ tag completion bit-scanning
The hand-rolled bit-scanning loop in the NCQ completion path has an
infinite loop bug. When tag_mask has only high bits set (e.g.
0x80000000), the inner while loop left-shifts tag_mask until it
overflows to 0. At that point !(0 & 1) is always true and 0 <<= 1
stays 0, causing an infinite loop in hardirq context with a spinlock
held.
Replace the open-coded bit-scanning with __ffs() which correctly
finds the least significant set bit and is bounded by the width of
the argument.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 62936009f35a6659cc3ebe0d90c754182d60da73 Version: 62936009f35a6659cc3ebe0d90c754182d60da73 Version: 62936009f35a6659cc3ebe0d90c754182d60da73 Version: 62936009f35a6659cc3ebe0d90c754182d60da73 Version: 62936009f35a6659cc3ebe0d90c754182d60da73 Version: 62936009f35a6659cc3ebe0d90c754182d60da73 Version: 62936009f35a6659cc3ebe0d90c754182d60da73 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/ata/sata_dwc_460ex.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ea9fa4dabe476f85fe73df30a6ab61a23c22fda4",
"status": "affected",
"version": "62936009f35a6659cc3ebe0d90c754182d60da73",
"versionType": "git"
},
{
"lessThan": "d72e8089dc332ac48293512ef0de77cbe0e04d25",
"status": "affected",
"version": "62936009f35a6659cc3ebe0d90c754182d60da73",
"versionType": "git"
},
{
"lessThan": "4c6e64cae2b2dab32ad9099faa339f6a72c0ce16",
"status": "affected",
"version": "62936009f35a6659cc3ebe0d90c754182d60da73",
"versionType": "git"
},
{
"lessThan": "8c5de0d8ab6824cfdadcbbe1be4c6c9d9f4c1f80",
"status": "affected",
"version": "62936009f35a6659cc3ebe0d90c754182d60da73",
"versionType": "git"
},
{
"lessThan": "1842d45f461a78988254631893329bdf4596e954",
"status": "affected",
"version": "62936009f35a6659cc3ebe0d90c754182d60da73",
"versionType": "git"
},
{
"lessThan": "29b916d3556bd12a95be7c56ca391b8cd572f8be",
"status": "affected",
"version": "62936009f35a6659cc3ebe0d90c754182d60da73",
"versionType": "git"
},
{
"lessThan": "c2130f6553f4a5cbdc259de069600117a995f197",
"status": "affected",
"version": "62936009f35a6659cc3ebe0d90c754182d60da73",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/ata/sata_dwc_460ex.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.36"
},
{
"lessThan": "2.6.36",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.36",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.36",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.36",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.36",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.36",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.36",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.36",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nata: sata_dwc_460ex: fix infinite loop in NCQ tag completion bit-scanning\n\nThe hand-rolled bit-scanning loop in the NCQ completion path has an\ninfinite loop bug. When tag_mask has only high bits set (e.g.\n0x80000000), the inner while loop left-shifts tag_mask until it\noverflows to 0. At that point !(0 \u0026 1) is always true and 0 \u003c\u003c= 1\nstays 0, causing an infinite loop in hardirq context with a spinlock\nheld.\n\nReplace the open-coded bit-scanning with __ffs() which correctly\nfinds the least significant set bit and is bounded by the width of\nthe argument."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:35:43.051Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ea9fa4dabe476f85fe73df30a6ab61a23c22fda4"
},
{
"url": "https://git.kernel.org/stable/c/d72e8089dc332ac48293512ef0de77cbe0e04d25"
},
{
"url": "https://git.kernel.org/stable/c/4c6e64cae2b2dab32ad9099faa339f6a72c0ce16"
},
{
"url": "https://git.kernel.org/stable/c/8c5de0d8ab6824cfdadcbbe1be4c6c9d9f4c1f80"
},
{
"url": "https://git.kernel.org/stable/c/1842d45f461a78988254631893329bdf4596e954"
},
{
"url": "https://git.kernel.org/stable/c/29b916d3556bd12a95be7c56ca391b8cd572f8be"
},
{
"url": "https://git.kernel.org/stable/c/c2130f6553f4a5cbdc259de069600117a995f197"
}
],
"title": "ata: sata_dwc_460ex: fix infinite loop in NCQ tag completion bit-scanning",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68449",
"datePublished": "2026-08-12T00:51:47.140Z",
"dateReserved": "2026-07-30T09:28:09.395Z",
"dateUpdated": "2026-08-19T16:35:43.051Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68363 (GCVE-0-2026-68363)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request
ath9k_hif_request_firmware() re-arms an asynchronous firmware load via
request_firmware_nowait(), passing hif_dev as the completion context, and
then still dereferences hif_dev:
dev_info(&hif_dev->udev->dev, "ath9k_htc: Firmware %s requested\n",
hif_dev->fw_name);
The re-armed callback ath9k_hif_usb_firmware_cb() runs on the "events"
workqueue and, when the firmware is missing, walks the retry chain into
ath9k_hif_usb_firmware_fail() -> complete_all(&hif_dev->fw_done). That
releases the wait_for_completion(&hif_dev->fw_done) in a concurrent
ath9k_hif_usb_disconnect(), which then kfree()s hif_dev. The trailing
dev_info() in the frame that re-armed the request can therefore read freed
memory (hif_dev->udev, the first field of struct hif_device_usb):
BUG: KASAN: slab-use-after-free in ath9k_hif_request_firmware
Read of size 8 ... by task kworker/...
ath9k_hif_request_firmware
ath9k_hif_usb_firmware_cb drivers/net/wireless/ath/ath9k/hif_usb.c:1247
request_firmware_work_func
Allocated by ...:
ath9k_hif_usb_probe drivers/net/wireless/ath/ath9k/hif_usb.c
Freed by ...:
ath9k_hif_usb_disconnect -> kfree drivers/net/wireless/ath/ath9k/hif_usb.c
The fw_done barrier only makes disconnect wait for the firmware chain to
*terminate*; it does not protect the outer ath9k_hif_request_firmware()
frame that re-armed the request and keeps touching hif_dev afterwards.
Drop the post-request dev_info(): it is the only use of hif_dev after the
async request is armed, and it is purely informational (the dev_err() on the
failure path runs only when request_firmware_nowait() did not arm a callback,
so hif_dev is still alive there).
This was first reported by syzbot as a single, non-reproduced crash that was
later auto-obsoleted, and was independently rediscovered by the reFuzz fuzzer,
which produced a C reproducer (USB-gadget connect/disconnect of an ath9k_htc
device whose firmware download fails). The vulnerable code is unchanged and
still present in v7.1-rc6, where the slab-use-after-free reproduces under KASAN
once the (sub-microsecond) race window is widened.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: e904cf6fe23022cde4e0ea9d41601411a315a3dc Version: e904cf6fe23022cde4e0ea9d41601411a315a3dc Version: e904cf6fe23022cde4e0ea9d41601411a315a3dc Version: e904cf6fe23022cde4e0ea9d41601411a315a3dc Version: e904cf6fe23022cde4e0ea9d41601411a315a3dc Version: e904cf6fe23022cde4e0ea9d41601411a315a3dc Version: e904cf6fe23022cde4e0ea9d41601411a315a3dc Version: e904cf6fe23022cde4e0ea9d41601411a315a3dc |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/ath/ath9k/hif_usb.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "47ed81aaa7f94d9808f4719e78a760c2ec1e6c86",
"status": "affected",
"version": "e904cf6fe23022cde4e0ea9d41601411a315a3dc",
"versionType": "git"
},
{
"lessThan": "48de0c6952192b0771fca468df4364d11ec74ad9",
"status": "affected",
"version": "e904cf6fe23022cde4e0ea9d41601411a315a3dc",
"versionType": "git"
},
{
"lessThan": "063497cc9f320ab71a7a937c3bc0a23e630aefe2",
"status": "affected",
"version": "e904cf6fe23022cde4e0ea9d41601411a315a3dc",
"versionType": "git"
},
{
"lessThan": "7f184ca38a90889f3f6665ff96748b95da39dbee",
"status": "affected",
"version": "e904cf6fe23022cde4e0ea9d41601411a315a3dc",
"versionType": "git"
},
{
"lessThan": "10b0ce629123a3737b4eda50188f73bb7be7b68b",
"status": "affected",
"version": "e904cf6fe23022cde4e0ea9d41601411a315a3dc",
"versionType": "git"
},
{
"lessThan": "48a69cedde7388294e4ea6fd804156cd62bc04fc",
"status": "affected",
"version": "e904cf6fe23022cde4e0ea9d41601411a315a3dc",
"versionType": "git"
},
{
"lessThan": "7c9046d92c4b9789c9d9d775e4fd5f34be64cb0a",
"status": "affected",
"version": "e904cf6fe23022cde4e0ea9d41601411a315a3dc",
"versionType": "git"
},
{
"lessThan": "dad9f96945d77ecd4708f730c06ef54dcd8cc057",
"status": "affected",
"version": "e904cf6fe23022cde4e0ea9d41601411a315a3dc",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/ath/ath9k/hif_usb.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.4"
},
{
"lessThan": "4.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath9k: hif_usb: don\u0027t dereference hif_dev after re-arming firmware request\n\nath9k_hif_request_firmware() re-arms an asynchronous firmware load via\nrequest_firmware_nowait(), passing hif_dev as the completion context, and\nthen still dereferences hif_dev:\n\n\tdev_info(\u0026hif_dev-\u003eudev-\u003edev, \"ath9k_htc: Firmware %s requested\\n\",\n\t\t hif_dev-\u003efw_name);\n\nThe re-armed callback ath9k_hif_usb_firmware_cb() runs on the \"events\"\nworkqueue and, when the firmware is missing, walks the retry chain into\nath9k_hif_usb_firmware_fail() -\u003e complete_all(\u0026hif_dev-\u003efw_done). That\nreleases the wait_for_completion(\u0026hif_dev-\u003efw_done) in a concurrent\nath9k_hif_usb_disconnect(), which then kfree()s hif_dev. The trailing\ndev_info() in the frame that re-armed the request can therefore read freed\nmemory (hif_dev-\u003eudev, the first field of struct hif_device_usb):\n\n BUG: KASAN: slab-use-after-free in ath9k_hif_request_firmware\n Read of size 8 ... by task kworker/...\n ath9k_hif_request_firmware\n ath9k_hif_usb_firmware_cb drivers/net/wireless/ath/ath9k/hif_usb.c:1247\n request_firmware_work_func\n Allocated by ...:\n ath9k_hif_usb_probe drivers/net/wireless/ath/ath9k/hif_usb.c\n Freed by ...:\n ath9k_hif_usb_disconnect -\u003e kfree drivers/net/wireless/ath/ath9k/hif_usb.c\n\nThe fw_done barrier only makes disconnect wait for the firmware chain to\n*terminate*; it does not protect the outer ath9k_hif_request_firmware()\nframe that re-armed the request and keeps touching hif_dev afterwards.\n\nDrop the post-request dev_info(): it is the only use of hif_dev after the\nasync request is armed, and it is purely informational (the dev_err() on the\nfailure path runs only when request_firmware_nowait() did not arm a callback,\nso hif_dev is still alive there).\n\nThis was first reported by syzbot as a single, non-reproduced crash that was\nlater auto-obsoleted, and was independently rediscovered by the reFuzz fuzzer,\nwhich produced a C reproducer (USB-gadget connect/disconnect of an ath9k_htc\ndevice whose firmware download fails). The vulnerable code is unchanged and\nstill present in v7.1-rc6, where the slab-use-after-free reproduces under KASAN\nonce the (sub-microsecond) race window is widened."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:18.694Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/47ed81aaa7f94d9808f4719e78a760c2ec1e6c86"
},
{
"url": "https://git.kernel.org/stable/c/48de0c6952192b0771fca468df4364d11ec74ad9"
},
{
"url": "https://git.kernel.org/stable/c/063497cc9f320ab71a7a937c3bc0a23e630aefe2"
},
{
"url": "https://git.kernel.org/stable/c/7f184ca38a90889f3f6665ff96748b95da39dbee"
},
{
"url": "https://git.kernel.org/stable/c/10b0ce629123a3737b4eda50188f73bb7be7b68b"
},
{
"url": "https://git.kernel.org/stable/c/48a69cedde7388294e4ea6fd804156cd62bc04fc"
},
{
"url": "https://git.kernel.org/stable/c/7c9046d92c4b9789c9d9d775e4fd5f34be64cb0a"
},
{
"url": "https://git.kernel.org/stable/c/dad9f96945d77ecd4708f730c06ef54dcd8cc057"
}
],
"title": "wifi: ath9k: hif_usb: don\u0027t dereference hif_dev after re-arming firmware request",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68363",
"datePublished": "2026-08-10T12:03:40.355Z",
"dateReserved": "2026-07-30T09:28:09.385Z",
"dateUpdated": "2026-08-19T16:34:18.694Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68111 (GCVE-0-2026-68111)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-19 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON()
There's no need to crash the kernel for these cases.
(cherry picked from commit b71604f8685b0eba07866f4e8dc30f93e1931054)
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: b1023571479020e9e9c15a51b43bf8e15406952b Version: b1023571479020e9e9c15a51b43bf8e15406952b Version: b1023571479020e9e9c15a51b43bf8e15406952b Version: b1023571479020e9e9c15a51b43bf8e15406952b Version: b1023571479020e9e9c15a51b43bf8e15406952b Version: b1023571479020e9e9c15a51b43bf8e15406952b Version: b1023571479020e9e9c15a51b43bf8e15406952b Version: b1023571479020e9e9c15a51b43bf8e15406952b |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/gfx_v9_0.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "67965f576f9337e387dc8efaf9a46cb6b7ea12cb",
"status": "affected",
"version": "b1023571479020e9e9c15a51b43bf8e15406952b",
"versionType": "git"
},
{
"lessThan": "9b5e4fa18fea1e7f6017e1af02fa10276628d9a0",
"status": "affected",
"version": "b1023571479020e9e9c15a51b43bf8e15406952b",
"versionType": "git"
},
{
"lessThan": "6978b10861850b93292fcd6b22a5495d69fce276",
"status": "affected",
"version": "b1023571479020e9e9c15a51b43bf8e15406952b",
"versionType": "git"
},
{
"lessThan": "6c8b9c1f03c7169c9577098b0c3035617606f8d4",
"status": "affected",
"version": "b1023571479020e9e9c15a51b43bf8e15406952b",
"versionType": "git"
},
{
"lessThan": "d74a6351d3f64e1f8a0fba28b369c0eeecf517f1",
"status": "affected",
"version": "b1023571479020e9e9c15a51b43bf8e15406952b",
"versionType": "git"
},
{
"lessThan": "042c047e8bc9c9ada7574028a8e4592102e2e1fd",
"status": "affected",
"version": "b1023571479020e9e9c15a51b43bf8e15406952b",
"versionType": "git"
},
{
"lessThan": "43768ad42b8f1a91652b86e0731ac14d6853cebb",
"status": "affected",
"version": "b1023571479020e9e9c15a51b43bf8e15406952b",
"versionType": "git"
},
{
"lessThan": "6302be10b521f5106ce01eb5a724b9e7945a5061",
"status": "affected",
"version": "b1023571479020e9e9c15a51b43bf8e15406952b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/gfx_v9_0.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.12"
},
{
"lessThan": "4.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/gfx9: replace BUG_ON() with WARN_ON()\n\nThere\u0027s no need to crash the kernel for these cases.\n\n(cherry picked from commit b71604f8685b0eba07866f4e8dc30f93e1931054)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:29:24.565Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/67965f576f9337e387dc8efaf9a46cb6b7ea12cb"
},
{
"url": "https://git.kernel.org/stable/c/9b5e4fa18fea1e7f6017e1af02fa10276628d9a0"
},
{
"url": "https://git.kernel.org/stable/c/6978b10861850b93292fcd6b22a5495d69fce276"
},
{
"url": "https://git.kernel.org/stable/c/6c8b9c1f03c7169c9577098b0c3035617606f8d4"
},
{
"url": "https://git.kernel.org/stable/c/d74a6351d3f64e1f8a0fba28b369c0eeecf517f1"
},
{
"url": "https://git.kernel.org/stable/c/042c047e8bc9c9ada7574028a8e4592102e2e1fd"
},
{
"url": "https://git.kernel.org/stable/c/43768ad42b8f1a91652b86e0731ac14d6853cebb"
},
{
"url": "https://git.kernel.org/stable/c/6302be10b521f5106ce01eb5a724b9e7945a5061"
}
],
"title": "drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68111",
"datePublished": "2026-08-10T11:58:28.489Z",
"dateReserved": "2026-07-30T09:28:09.368Z",
"dateUpdated": "2026-08-19T16:29:24.565Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74436 (GCVE-0-2026-74436)
Vulnerability from cvelistv5
Published
2026-08-15 05:59
Modified
2026-08-23 12:47
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
rxrpc: serialize kernel accept preallocation with socket teardown
rxrpc_kernel_charge_accept() reads rx->backlog without any
socket/backlog synchronization and passes that raw pointer into
rxrpc_service_prealloc_one(). A concurrent rxrpc_discard_prealloc()
sets rx->backlog = NULL and frees the backlog rings, so a kernel
preallocation worker can keep using a freed struct rxrpc_backlog
while updating *_backlog_head/tail and array slots.
Serialize the state check and backlog lookup with the socket lock,
and reject kernel preallocation once teardown has disabled
listening or discarded the service backlog.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 00e907127e6f86d0f9b122d9b4347a8aa09a8b61 Version: 00e907127e6f86d0f9b122d9b4347a8aa09a8b61 Version: 00e907127e6f86d0f9b122d9b4347a8aa09a8b61 Version: 00e907127e6f86d0f9b122d9b4347a8aa09a8b61 Version: 00e907127e6f86d0f9b122d9b4347a8aa09a8b61 Version: 00e907127e6f86d0f9b122d9b4347a8aa09a8b61 Version: 00e907127e6f86d0f9b122d9b4347a8aa09a8b61 Version: 00e907127e6f86d0f9b122d9b4347a8aa09a8b61 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/rxrpc/call_accept.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "d6207326b4ca0ae1041281b6af9df53f8080669a",
"status": "affected",
"version": "00e907127e6f86d0f9b122d9b4347a8aa09a8b61",
"versionType": "git"
},
{
"lessThan": "11b429b84c87cb5a0152f14e7d6cb649ed363901",
"status": "affected",
"version": "00e907127e6f86d0f9b122d9b4347a8aa09a8b61",
"versionType": "git"
},
{
"lessThan": "c20d983968f239574290cf804a58cde18ad1c559",
"status": "affected",
"version": "00e907127e6f86d0f9b122d9b4347a8aa09a8b61",
"versionType": "git"
},
{
"lessThan": "0337cdba0c477f176c0459bed012109453184573",
"status": "affected",
"version": "00e907127e6f86d0f9b122d9b4347a8aa09a8b61",
"versionType": "git"
},
{
"lessThan": "dfa0b2bbc5e50119f89c6b5407faa5ed86dfa7c5",
"status": "affected",
"version": "00e907127e6f86d0f9b122d9b4347a8aa09a8b61",
"versionType": "git"
},
{
"lessThan": "35a967ff8b24db09ee429c39c5b5e6571639997d",
"status": "affected",
"version": "00e907127e6f86d0f9b122d9b4347a8aa09a8b61",
"versionType": "git"
},
{
"lessThan": "1741378a7a83dfd8e53a9196730df709b903cd33",
"status": "affected",
"version": "00e907127e6f86d0f9b122d9b4347a8aa09a8b61",
"versionType": "git"
},
{
"lessThan": "dc175389b18c29a5303ee83169ec653adfae3e17",
"status": "affected",
"version": "00e907127e6f86d0f9b122d9b4347a8aa09a8b61",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/rxrpc/call_accept.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.9"
},
{
"lessThan": "4.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nrxrpc: serialize kernel accept preallocation with socket teardown\n\nrxrpc_kernel_charge_accept() reads rx-\u003ebacklog without any\nsocket/backlog synchronization and passes that raw pointer into\nrxrpc_service_prealloc_one(). A concurrent rxrpc_discard_prealloc()\nsets rx-\u003ebacklog = NULL and frees the backlog rings, so a kernel\npreallocation worker can keep using a freed struct rxrpc_backlog\nwhile updating *_backlog_head/tail and array slots.\n\nSerialize the state check and backlog lookup with the socket lock,\nand reject kernel preallocation once teardown has disabled\nlistening or discarded the service backlog."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - RxRPC is a UDP network protocol; remote peers can send packets to AFS callback-manager listeners (port 7001) that instantiate incoming calls and queue kernel preallocation work reaching rxrpc_kernel_charge_accept().\nAC:L - The attacker controls the preallocation side by flooding concurrent rxrpc/AFS callback traffic while a peer thread tears down the same socket via listen(0), shutdown, or close during AFS netns exit, creating a winnable race.\nPR:N - No local account, capability, or authentication is required to reach the vulnerable preallocation path; any remote host that can deliver rxrpc/UDP packets to a listening AFS callback manager can drive the charge_accept worker.\nUI:N - Exploitation requires no victim interaction beyond normal background AFS service operation; the attacker triggers the bug purely through network traffic timed against automatic or administrative socket teardown.\nS:U - The use-after-free corrupts kernel heap metadata and rxrpc backlog structures within kernel memory, enabling local privilege escalation but not crossing a VM, container, or IOMMU security boundary by itself.\nC:H - Concurrent use of a freed struct rxrpc_backlog allows reads and corruption of recycled slab memory, providing a standard kmalloc UAF primitive that can leak kernel pointers and sensitive data.\nI:H - The race writes peer, connection, and call pointers plus head/tail indices into freed backlog ring slots, enabling heap grooming and arbitrary kernel memory corruption exploitable for code execution.\nA:H - Use-after-free on the backlog structure during concurrent head/tail and pointer-array updates can cause kernel oops, panic, or hang, and repeated triggering enables sustained denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:47:16.782Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/d6207326b4ca0ae1041281b6af9df53f8080669a"
},
{
"url": "https://git.kernel.org/stable/c/11b429b84c87cb5a0152f14e7d6cb649ed363901"
},
{
"url": "https://git.kernel.org/stable/c/c20d983968f239574290cf804a58cde18ad1c559"
},
{
"url": "https://git.kernel.org/stable/c/0337cdba0c477f176c0459bed012109453184573"
},
{
"url": "https://git.kernel.org/stable/c/dfa0b2bbc5e50119f89c6b5407faa5ed86dfa7c5"
},
{
"url": "https://git.kernel.org/stable/c/35a967ff8b24db09ee429c39c5b5e6571639997d"
},
{
"url": "https://git.kernel.org/stable/c/1741378a7a83dfd8e53a9196730df709b903cd33"
},
{
"url": "https://git.kernel.org/stable/c/dc175389b18c29a5303ee83169ec653adfae3e17"
}
],
"title": "rxrpc: serialize kernel accept preallocation with socket teardown",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74436",
"datePublished": "2026-08-15T05:59:34.687Z",
"dateReserved": "2026-08-15T05:44:03.896Z",
"dateUpdated": "2026-08-23T12:47:16.782Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68229 (GCVE-0-2026-68229)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: cedrus: skip invalid H.264 reference list entries
Cedrus consumes H.264 ref_pic_list0/ref_pic_list1 entries from the
stateless slice control and later uses their indices to look up
decode->dpb[] in _cedrus_write_ref_list().
Rejecting such controls in cedrus_try_ctrl() would break existing
userspace, since stateless H.264 reference lists may legitimately carry
out-of-range indices for missing references. Instead, guard the actual
DPB lookup in Cedrus and skip entries whose indices do not fit the fixed
V4L2_H264_NUM_DPB_ENTRIES array.
This keeps the fix local to the driver use site and avoids out-of-bounds
reads from malformed or unsupported reference list entries.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: e000e1fa4bdbd783149e7f97cf3be61e1c0bab8c Version: e000e1fa4bdbd783149e7f97cf3be61e1c0bab8c Version: e000e1fa4bdbd783149e7f97cf3be61e1c0bab8c Version: e000e1fa4bdbd783149e7f97cf3be61e1c0bab8c Version: e000e1fa4bdbd783149e7f97cf3be61e1c0bab8c Version: e000e1fa4bdbd783149e7f97cf3be61e1c0bab8c Version: e000e1fa4bdbd783149e7f97cf3be61e1c0bab8c Version: e000e1fa4bdbd783149e7f97cf3be61e1c0bab8c |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/staging/media/sunxi/cedrus/cedrus_h264.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a6a109771c51920beb620f30778c29da823cc34c",
"status": "affected",
"version": "e000e1fa4bdbd783149e7f97cf3be61e1c0bab8c",
"versionType": "git"
},
{
"lessThan": "7ff6f728a2433b420bb372cb0e8a4eea3f2e1a4b",
"status": "affected",
"version": "e000e1fa4bdbd783149e7f97cf3be61e1c0bab8c",
"versionType": "git"
},
{
"lessThan": "1db34683b0fbbcb3bc162380c11514ea0a44e8ab",
"status": "affected",
"version": "e000e1fa4bdbd783149e7f97cf3be61e1c0bab8c",
"versionType": "git"
},
{
"lessThan": "2ee8327c85b3ac7b532d2d6a1e3a295d5ad7414a",
"status": "affected",
"version": "e000e1fa4bdbd783149e7f97cf3be61e1c0bab8c",
"versionType": "git"
},
{
"lessThan": "0af8945fcae742d099f59f3c725eb67235953a31",
"status": "affected",
"version": "e000e1fa4bdbd783149e7f97cf3be61e1c0bab8c",
"versionType": "git"
},
{
"lessThan": "9924cb548ee7753a6473997949c3ec48092de0b0",
"status": "affected",
"version": "e000e1fa4bdbd783149e7f97cf3be61e1c0bab8c",
"versionType": "git"
},
{
"lessThan": "e53112c2de88982e66c369aee2120d5efd78df30",
"status": "affected",
"version": "e000e1fa4bdbd783149e7f97cf3be61e1c0bab8c",
"versionType": "git"
},
{
"lessThan": "10358ea986c3c85516d1c8206486464f79d36e76",
"status": "affected",
"version": "e000e1fa4bdbd783149e7f97cf3be61e1c0bab8c",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/staging/media/sunxi/cedrus/cedrus_h264.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.10"
},
{
"lessThan": "5.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: cedrus: skip invalid H.264 reference list entries\n\nCedrus consumes H.264 ref_pic_list0/ref_pic_list1 entries from the\nstateless slice control and later uses their indices to look up\ndecode-\u003edpb[] in _cedrus_write_ref_list().\n\nRejecting such controls in cedrus_try_ctrl() would break existing\nuserspace, since stateless H.264 reference lists may legitimately carry\nout-of-range indices for missing references. Instead, guard the actual\nDPB lookup in Cedrus and skip entries whose indices do not fit the fixed\nV4L2_H264_NUM_DPB_ENTRIES array.\n\nThis keeps the fix local to the driver use site and avoids out-of-bounds\nreads from malformed or unsupported reference list entries."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached only through the local V4L2 interface on the cedrus video device node (/dev/videoN) via VIDIOC_S_EXT_CTRLS plus QBUF/STREAMON ioctls. There is no remote or network-facing path to the stateless H.264 decoder.\nAC:L - The attacker fully and deterministically controls the out-of-range value: ref_pic_list0/1[i].index is a u8 copied verbatim from the control payload with no validation, so any index in 16..255 immediately produces the out-of-bounds dpb[] access on the next decode run. No race, timing, or uncontrollable memory-layout condition is involved.\nPR:L - Only an unprivileged local account with access to the cedrus video device node is needed (typically the \u0027video\u0027 group, or the media/camera service on Android and embedded Allwinner devices). No capability, CAP_SYS_ADMIN, or root check exists anywhere on the path \u2014 cedrus_try_ctrl() validates only SPS chroma format and bit depth.\nUI:N - The attacking process performs the entire sequence itself \u2014 open the device, set the crafted H.264 slice-params control, queue buffers, start streaming. No victim action, file open, or media mount is required.\nS:U - The out-of-bounds read stays within the kernel\u0027s own memory and security authority; no VM, IOMMU, or sandbox boundary is crossed. This is a standard in-kernel driver memory-safety defect.\nC:H - decode-\u003edpb[] holds 16 32-byte entries at the start of a ~560-byte control allocation, so an attacker-chosen index up to 255 reads at offset 8160 \u2014 about 7.6 KB of adjacent kernel heap beyond the object. The read flags/reference_ts values are consumed by the ACTIVE test and vb2_find_buffer() timestamp lookup, giving an attacker-steerable oracle over unrelated kernel heap contents.\nI:N - The defect is purely a read: num_ref is bounded to V4L2_H264_REF_LIST_LEN by v4l2-ctrls-core.c, so the sram_array[CEDRUS_MAX_REF_IDX] stores stay in bounds, and only a legitimately-looked-up buffer position is written to hardware SRAM. No kernel memory is modified out of bounds.\nA:H - Reading several kilobytes past the end of a slab object can walk off the slab page into an unmapped or poisoned region, and trips KASAN/hardening checks, producing a kernel oops. The trigger is trivially repeatable from an unprivileged process, so the crash can be induced at will."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:32:01.546Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a6a109771c51920beb620f30778c29da823cc34c"
},
{
"url": "https://git.kernel.org/stable/c/7ff6f728a2433b420bb372cb0e8a4eea3f2e1a4b"
},
{
"url": "https://git.kernel.org/stable/c/1db34683b0fbbcb3bc162380c11514ea0a44e8ab"
},
{
"url": "https://git.kernel.org/stable/c/2ee8327c85b3ac7b532d2d6a1e3a295d5ad7414a"
},
{
"url": "https://git.kernel.org/stable/c/0af8945fcae742d099f59f3c725eb67235953a31"
},
{
"url": "https://git.kernel.org/stable/c/9924cb548ee7753a6473997949c3ec48092de0b0"
},
{
"url": "https://git.kernel.org/stable/c/e53112c2de88982e66c369aee2120d5efd78df30"
},
{
"url": "https://git.kernel.org/stable/c/10358ea986c3c85516d1c8206486464f79d36e76"
}
],
"title": "media: cedrus: skip invalid H.264 reference list entries",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68229",
"datePublished": "2026-08-10T12:00:51.935Z",
"dateReserved": "2026-07-30T09:28:09.376Z",
"dateUpdated": "2026-08-19T16:32:01.546Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68217 (GCVE-0-2026-68217)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: pwc: Drain fill_buf on start_streaming() failure
pwc_isoc_init() submits its isochronous URBs with
usb_submit_urb(.., GFP_KERNEL) in a loop. After the first URB is
submitted, its completion handler pwc_isoc_handler() can run on another
CPU before the loop finishes:
start_streaming()
pwc_isoc_init()
usb_submit_urb(urbs[0], GFP_KERNEL)
pwc_isoc_handler(urbs[0])
pdev->fill_buf =
pwc_get_next_fill_buf(pdev)
usb_submit_urb(urbs[i>0], ..) -> fails
pwc_isoc_cleanup(pdev) /* kills URBs */
return ret;
pwc_cleanup_queued_bufs(pdev, VB2_BUF_STATE_QUEUED)
pwc_get_next_fill_buf() detaches a buffer from pdev->queued_bufs and
stores it in pdev->fill_buf. The error path in start_streaming() only
drains pdev->queued_bufs, so the buffer parked in pdev->fill_buf is
leaked. vb2_start_streaming() then triggers
WARN_ON(owned_by_drv_count).
stop_streaming() already handles this since commit 80b0963e1698
("[media] pwc: fix WARN_ON"), which added the fill_buf drain in the
teardown path but not in the start_streaming() error path. Mirror that
handling on failure so start_streaming() returns with no buffer owned
by the driver.
Issue identified by automated review of the INV-003 series at
https://sashiko.dev/
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 885fe18f5542fe283a17f70583383c6cadcba1c3 Version: 885fe18f5542fe283a17f70583383c6cadcba1c3 Version: 885fe18f5542fe283a17f70583383c6cadcba1c3 Version: 885fe18f5542fe283a17f70583383c6cadcba1c3 Version: 885fe18f5542fe283a17f70583383c6cadcba1c3 Version: 885fe18f5542fe283a17f70583383c6cadcba1c3 Version: 885fe18f5542fe283a17f70583383c6cadcba1c3 Version: 885fe18f5542fe283a17f70583383c6cadcba1c3 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/usb/pwc/pwc-if.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "97f3c15957ec7e6d249f05407ad947c0644df24d",
"status": "affected",
"version": "885fe18f5542fe283a17f70583383c6cadcba1c3",
"versionType": "git"
},
{
"lessThan": "a4afffd148991a826e8995362fb10cf8705c1130",
"status": "affected",
"version": "885fe18f5542fe283a17f70583383c6cadcba1c3",
"versionType": "git"
},
{
"lessThan": "eabe9a59640698137d7382d5b549e95dc37f7565",
"status": "affected",
"version": "885fe18f5542fe283a17f70583383c6cadcba1c3",
"versionType": "git"
},
{
"lessThan": "a56e7641e09bd80b976e944ae759109b86fd5b38",
"status": "affected",
"version": "885fe18f5542fe283a17f70583383c6cadcba1c3",
"versionType": "git"
},
{
"lessThan": "acc789b2173070638cad89c2b61d33ed338be0dd",
"status": "affected",
"version": "885fe18f5542fe283a17f70583383c6cadcba1c3",
"versionType": "git"
},
{
"lessThan": "9afd605dcd96c7a45f338eded1de16679b30e1df",
"status": "affected",
"version": "885fe18f5542fe283a17f70583383c6cadcba1c3",
"versionType": "git"
},
{
"lessThan": "5d4812668b03f823b5044789d6aa77fe56b42587",
"status": "affected",
"version": "885fe18f5542fe283a17f70583383c6cadcba1c3",
"versionType": "git"
},
{
"lessThan": "906e410dcffbbd99fb4081abab817a830033aa28",
"status": "affected",
"version": "885fe18f5542fe283a17f70583383c6cadcba1c3",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/usb/pwc/pwc-if.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.1"
},
{
"lessThan": "3.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: pwc: Drain fill_buf on start_streaming() failure\n\npwc_isoc_init() submits its isochronous URBs with\nusb_submit_urb(.., GFP_KERNEL) in a loop. After the first URB is\nsubmitted, its completion handler pwc_isoc_handler() can run on another\nCPU before the loop finishes:\n\n start_streaming()\n pwc_isoc_init()\n usb_submit_urb(urbs[0], GFP_KERNEL)\n pwc_isoc_handler(urbs[0])\n pdev-\u003efill_buf =\n pwc_get_next_fill_buf(pdev)\n usb_submit_urb(urbs[i\u003e0], ..) -\u003e fails\n pwc_isoc_cleanup(pdev) /* kills URBs */\n return ret;\n pwc_cleanup_queued_bufs(pdev, VB2_BUF_STATE_QUEUED)\n\npwc_get_next_fill_buf() detaches a buffer from pdev-\u003equeued_bufs and\nstores it in pdev-\u003efill_buf. The error path in start_streaming() only\ndrains pdev-\u003equeued_bufs, so the buffer parked in pdev-\u003efill_buf is\nleaked. vb2_start_streaming() then triggers\nWARN_ON(owned_by_drv_count).\n\nstop_streaming() already handles this since commit 80b0963e1698\n(\"[media] pwc: fix WARN_ON\"), which added the fill_buf drain in the\nteardown path but not in the start_streaming() error path. Mirror that\nhandling on failure so start_streaming() returns with no buffer owned\nby the driver.\n\nIssue identified by automated review of the INV-003 series at\nhttps://sashiko.dev/"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:48.858Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/97f3c15957ec7e6d249f05407ad947c0644df24d"
},
{
"url": "https://git.kernel.org/stable/c/a4afffd148991a826e8995362fb10cf8705c1130"
},
{
"url": "https://git.kernel.org/stable/c/eabe9a59640698137d7382d5b549e95dc37f7565"
},
{
"url": "https://git.kernel.org/stable/c/a56e7641e09bd80b976e944ae759109b86fd5b38"
},
{
"url": "https://git.kernel.org/stable/c/acc789b2173070638cad89c2b61d33ed338be0dd"
},
{
"url": "https://git.kernel.org/stable/c/9afd605dcd96c7a45f338eded1de16679b30e1df"
},
{
"url": "https://git.kernel.org/stable/c/5d4812668b03f823b5044789d6aa77fe56b42587"
},
{
"url": "https://git.kernel.org/stable/c/906e410dcffbbd99fb4081abab817a830033aa28"
}
],
"title": "media: pwc: Drain fill_buf on start_streaming() failure",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68217",
"datePublished": "2026-08-10T12:00:36.773Z",
"dateReserved": "2026-07-30T09:28:09.375Z",
"dateUpdated": "2026-08-19T16:31:48.858Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68392 (GCVE-0-2026-68392)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: mgmt: fix locking in unpair_device/disconnect_sync
Dereferencing RCU-protected pointers outside critical sections is
invalid and may lead to UAF.
Take hdev->lock for hci_conn lookup and hci_abort_conn(). Don't use RCU
to ensure the conn is fully initialized at this point.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 7fe4d391e937c2f048a43ff4b421e677f10d83c0 Version: 249c88e7fb45b6b705040c5af4bd0d0f2bc9735c Version: 227a0cdf4a028a73dc256d0f5144b4808d718893 Version: 227a0cdf4a028a73dc256d0f5144b4808d718893 Version: 227a0cdf4a028a73dc256d0f5144b4808d718893 Version: 227a0cdf4a028a73dc256d0f5144b4808d718893 Version: 58afdc9b18871eb1d461c725be9e9f3f44a39aeb Version: 6.6.51 ≤ Version: 6.10.10 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/bluetooth/mgmt.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "74f3e6e21ebc6c418d348f8ce68aef6fe6d82c82",
"status": "affected",
"version": "7fe4d391e937c2f048a43ff4b421e677f10d83c0",
"versionType": "git"
},
{
"lessThan": "8bc83f9ef6789571f399ff631a2a14a12b6d8585",
"status": "affected",
"version": "249c88e7fb45b6b705040c5af4bd0d0f2bc9735c",
"versionType": "git"
},
{
"lessThan": "579faba5ede6df6b7f36777c431dc8dcf9d272e7",
"status": "affected",
"version": "227a0cdf4a028a73dc256d0f5144b4808d718893",
"versionType": "git"
},
{
"lessThan": "ca58ad287bfc5b9d31a72ecb8650289df2b57250",
"status": "affected",
"version": "227a0cdf4a028a73dc256d0f5144b4808d718893",
"versionType": "git"
},
{
"lessThan": "b11511006f9e17000de3f4cadee451364f658ca3",
"status": "affected",
"version": "227a0cdf4a028a73dc256d0f5144b4808d718893",
"versionType": "git"
},
{
"lessThan": "16cd66443957e4ad42155c6fec401012f600c6f8",
"status": "affected",
"version": "227a0cdf4a028a73dc256d0f5144b4808d718893",
"versionType": "git"
},
{
"status": "affected",
"version": "58afdc9b18871eb1d461c725be9e9f3f44a39aeb",
"versionType": "git"
},
{
"lessThan": "6.6.148",
"status": "affected",
"version": "6.6.51",
"versionType": "semver"
},
{
"lessThan": "6.11",
"status": "affected",
"version": "6.10.10",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/bluetooth/mgmt.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.11"
},
{
"lessThan": "6.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.6.51",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.10.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: mgmt: fix locking in unpair_device/disconnect_sync\n\nDereferencing RCU-protected pointers outside critical sections is\ninvalid and may lead to UAF.\n\nTake hdev-\u003elock for hci_conn lookup and hci_abort_conn(). Don\u0027t use RCU\nto ensure the conn is fully initialized at this point."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable path is entered by a local process sending MGMT_OP_DISCONNECT/MGMT_OP_UNPAIR_DEVICE on an AF_BLUETOOTH/BTPROTO_HCI socket bound to HCI_CHANNEL_CONTROL, and the freeing side is drivable locally via /dev/vhci events or ioctl(HCIDEVDOWN)/hci_conn_hash_flush; no over-the-air access is required.\nAC:L - The attacker controls both sides of the race \u2014 repeatedly queuing the mgmt command while tearing the connection down (vhci-injected disconnect-complete, HCIDEVDOWN, or connection timeout) \u2014 and can retry indefinitely, so the window is reached reliably.\nPR:L - The mgmt command needs a trusted control socket, but that capability is routinely held by the Bluetooth daemon and exposed to unprivileged session users through BlueZ Disconnect/RemoveDevice D-Bus methods, so an ordinary local user can drive the path with attacker-chosen addresses.\nUI:N - Both the mgmt command and the concurrent connection teardown are initiated programmatically by the attacker; no victim action such as pairing confirmation or opening a file is needed.\nS:U - The corruption is confined to kernel heap objects managed by the Bluetooth subsystem within the same security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - hci_abort_conn() dereferences the freed hci_conn (conn-\u003ehdev, conn-\u003eabort_reason, conn-\u003ehandle) after it has been unlinked and released, so an attacker who reclaims the slab with controlled data obtains a read primitive over kernel memory and can leak pointers.\nI:H - The use-after-free is not read-only: hci_abort_conn() stores the attacker-reachable reason byte into conn-\u003eabort_reason and hci_conn_get() increments a refcount inside the freed object, giving a write primitive into reclaimed heap memory that is leverageable for control-flow hijack.\nA:H - Dereferencing a freed or partially initialized hci_conn and then queuing abort_conn_sync on it produces slab-use-after-free oopses, refcount underflow, and kernel panics, crashing the system."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:21.017Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/74f3e6e21ebc6c418d348f8ce68aef6fe6d82c82"
},
{
"url": "https://git.kernel.org/stable/c/8bc83f9ef6789571f399ff631a2a14a12b6d8585"
},
{
"url": "https://git.kernel.org/stable/c/579faba5ede6df6b7f36777c431dc8dcf9d272e7"
},
{
"url": "https://git.kernel.org/stable/c/ca58ad287bfc5b9d31a72ecb8650289df2b57250"
},
{
"url": "https://git.kernel.org/stable/c/b11511006f9e17000de3f4cadee451364f658ca3"
},
{
"url": "https://git.kernel.org/stable/c/16cd66443957e4ad42155c6fec401012f600c6f8"
}
],
"title": "Bluetooth: mgmt: fix locking in unpair_device/disconnect_sync",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68392",
"datePublished": "2026-08-10T12:04:11.543Z",
"dateReserved": "2026-07-30T09:28:09.388Z",
"dateUpdated": "2026-08-23T12:46:21.017Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68180 (GCVE-0-2026-68180)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
intel_th: fix MSC output device reference leak
intel_th_output_open() looks up the output device with
bus_find_device_by_devt(), which returns the device with a reference that
must be dropped after use.
commit 95fc36a234da ("intel_th: fix device leak on output open()")
attempted to drop the reference from intel_th_output_release(). However,
a successful open replaces file->f_op with the output driver file
operations before returning, so close runs the output driver release
callback instead.
For MSC outputs, close runs intel_th_msc_release(), which only removes
the per-file iterator and does not drop the device reference taken by
intel_th_output_open(). Consequently, every successful MSC output open
leaks one device reference.
Drop the device reference from intel_th_msc_release(), which is the
release path actually used for MSC output files. Remove the now-unused
intel_th_output_release() callback from intel_th_output_fops.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: af4b9467296b9a16ebc008147238070236982b6d Version: 64015cbf06e8bb75b81ae95b997e847b55280f7f Version: b71e64ef7ff9443835d1333e3e80ab1e49e5209f Version: bf7785434b5d05d940d936b78925080950bd54dd Version: 0fca16c5591534cc1fec8b6181277ee3a3d0f26c Version: f9b059bda4276f2bb72cb98ec7875a747f042ea2 Version: 95fc36a234da24bbc5f476f8104a5a15f99ed3e3 Version: 95fc36a234da24bbc5f476f8104a5a15f99ed3e3 Version: 5.10.249 ≤ Version: 5.15.199 ≤ Version: 6.1.162 ≤ Version: 6.6.122 ≤ Version: 6.12.68 ≤ Version: 6.18.8 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/hwtracing/intel_th/core.c",
"drivers/hwtracing/intel_th/msu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "12ad4fad748e6e563ff4480f03b89134a41b5c37",
"status": "affected",
"version": "af4b9467296b9a16ebc008147238070236982b6d",
"versionType": "git"
},
{
"lessThan": "df55842fddbcdb80e6dd16680439c0f780ed592e",
"status": "affected",
"version": "64015cbf06e8bb75b81ae95b997e847b55280f7f",
"versionType": "git"
},
{
"lessThan": "141641a70ed337e54487f766ede745fc2ce44c42",
"status": "affected",
"version": "b71e64ef7ff9443835d1333e3e80ab1e49e5209f",
"versionType": "git"
},
{
"lessThan": "ddcf2064d7ec5a8c9afa7cb74442320e443502bc",
"status": "affected",
"version": "bf7785434b5d05d940d936b78925080950bd54dd",
"versionType": "git"
},
{
"lessThan": "26e27b8dcef1e4df6f30d8f25b3304a506d482b3",
"status": "affected",
"version": "0fca16c5591534cc1fec8b6181277ee3a3d0f26c",
"versionType": "git"
},
{
"lessThan": "caba30eb8bd321c465ecfc7d850ee85f5b353496",
"status": "affected",
"version": "f9b059bda4276f2bb72cb98ec7875a747f042ea2",
"versionType": "git"
},
{
"lessThan": "c3a28f9cb82425fe0835048ed3677f321e780691",
"status": "affected",
"version": "95fc36a234da24bbc5f476f8104a5a15f99ed3e3",
"versionType": "git"
},
{
"lessThan": "761b785a0cfbce43761227bc42a7f984f31f8921",
"status": "affected",
"version": "95fc36a234da24bbc5f476f8104a5a15f99ed3e3",
"versionType": "git"
},
{
"lessThan": "5.10.265",
"status": "affected",
"version": "5.10.249",
"versionType": "semver"
},
{
"lessThan": "5.15.216",
"status": "affected",
"version": "5.15.199",
"versionType": "semver"
},
{
"lessThan": "6.1.183",
"status": "affected",
"version": "6.1.162",
"versionType": "semver"
},
{
"lessThan": "6.6.148",
"status": "affected",
"version": "6.6.122",
"versionType": "semver"
},
{
"lessThan": "6.12.101",
"status": "affected",
"version": "6.12.68",
"versionType": "semver"
},
{
"lessThan": "6.18.42",
"status": "affected",
"version": "6.18.8",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/hwtracing/intel_th/core.c",
"drivers/hwtracing/intel_th/msu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.19"
},
{
"lessThan": "6.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.10.249",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.15.199",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "6.1.162",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.6.122",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.12.68",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.18.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nintel_th: fix MSC output device reference leak\n\nintel_th_output_open() looks up the output device with\nbus_find_device_by_devt(), which returns the device with a reference that\nmust be dropped after use.\n\ncommit 95fc36a234da (\"intel_th: fix device leak on output open()\")\nattempted to drop the reference from intel_th_output_release(). However,\na successful open replaces file-\u003ef_op with the output driver file\noperations before returning, so close runs the output driver release\ncallback instead.\n\nFor MSC outputs, close runs intel_th_msc_release(), which only removes\nthe per-file iterator and does not drop the device reference taken by\nintel_th_output_open(). Consequently, every successful MSC output open\nleaks one device reference.\n\nDrop the device reference from intel_th_msc_release(), which is the\nrelease path actually used for MSC output files. Remove the now-unused\nintel_th_output_release() callback from intel_th_output_fops."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:30:44.755Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/12ad4fad748e6e563ff4480f03b89134a41b5c37"
},
{
"url": "https://git.kernel.org/stable/c/df55842fddbcdb80e6dd16680439c0f780ed592e"
},
{
"url": "https://git.kernel.org/stable/c/141641a70ed337e54487f766ede745fc2ce44c42"
},
{
"url": "https://git.kernel.org/stable/c/ddcf2064d7ec5a8c9afa7cb74442320e443502bc"
},
{
"url": "https://git.kernel.org/stable/c/26e27b8dcef1e4df6f30d8f25b3304a506d482b3"
},
{
"url": "https://git.kernel.org/stable/c/caba30eb8bd321c465ecfc7d850ee85f5b353496"
},
{
"url": "https://git.kernel.org/stable/c/c3a28f9cb82425fe0835048ed3677f321e780691"
},
{
"url": "https://git.kernel.org/stable/c/761b785a0cfbce43761227bc42a7f984f31f8921"
}
],
"title": "intel_th: fix MSC output device reference leak",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68180",
"datePublished": "2026-08-10T11:59:51.694Z",
"dateReserved": "2026-07-30T09:28:09.373Z",
"dateUpdated": "2026-08-19T16:30:44.755Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72254 (GCVE-0-2026-72254)
Vulnerability from cvelistv5
Published
2026-08-15 05:54
Modified
2026-08-17 05:42
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nft_fib: reject fib expression on the netdev egress hook
A fib expression in a netdev egress base chain dereferences nft_in(pkt),
NULL on the transmit path, causing a NULL pointer dereference at eval.
nft_fib_validate() masks the hook with NF_INET_* values, but netdev hook
numbers are a separate enum that aliases them (NF_NETDEV_EGRESS ==
NF_INET_LOCAL_IN), so an egress chain passes validation and then faults.
Add nft_fib_netdev_validate() that limits each result/flag to the netdev
hook where the device it reads exists: the input-device cases (OIF,
OIFNAME, ADDRTYPE with F_IIF) to ingress, the output-device case (ADDRTYPE
with F_OIF) to egress, ADDRTYPE with no device flag to both. Also restrict
nft_fib_validate() to NFPROTO_IPV4/IPV6/INET so its NF_INET_* masks are
not applied to another family's hooks.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/netfilter/nft_fib.c",
"net/netfilter/nft_fib_netdev.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "4fee43759b489559a491f7c95f9bfa7a1d0c7a10",
"status": "affected",
"version": "42df6e1d221dddc0f2acf2be37e68d553ad65f96",
"versionType": "git"
},
{
"lessThan": "568931f26af4727a51e8521f72efbc78d3b82410",
"status": "affected",
"version": "42df6e1d221dddc0f2acf2be37e68d553ad65f96",
"versionType": "git"
},
{
"lessThan": "d01c913febead04a01a5f3a6374d1f45504dc523",
"status": "affected",
"version": "42df6e1d221dddc0f2acf2be37e68d553ad65f96",
"versionType": "git"
},
{
"lessThan": "f68305267ebda7e839b5e8f77e8d77535a3d5a0f",
"status": "affected",
"version": "42df6e1d221dddc0f2acf2be37e68d553ad65f96",
"versionType": "git"
},
{
"lessThan": "d07955dd34ecae17d35d8c7d0a273a3fba653a8c",
"status": "affected",
"version": "42df6e1d221dddc0f2acf2be37e68d553ad65f96",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/netfilter/nft_fib.c",
"net/netfilter/nft_fib_netdev.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.16"
},
{
"lessThan": "5.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.16",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_fib: reject fib expression on the netdev egress hook\n\nA fib expression in a netdev egress base chain dereferences nft_in(pkt),\nNULL on the transmit path, causing a NULL pointer dereference at eval.\nnft_fib_validate() masks the hook with NF_INET_* values, but netdev hook\nnumbers are a separate enum that aliases them (NF_NETDEV_EGRESS ==\nNF_INET_LOCAL_IN), so an egress chain passes validation and then faults.\n\nAdd nft_fib_netdev_validate() that limits each result/flag to the netdev\nhook where the device it reads exists: the input-device cases (OIF,\nOIFNAME, ADDRTYPE with F_IIF) to ingress, the output-device case (ADDRTYPE\nwith F_OIF) to egress, ADDRTYPE with no device flag to both. Also restrict\nnft_fib_validate() to NFPROTO_IPV4/IPV6/INET so its NF_INET_* masks are\nnot applied to another family\u0027s hooks."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - Once a netdev egress fib rule is installed, evaluation runs on the packet transmit datapath (nf_hook_egress in __dev_queue_xmit); a remote peer can trigger it by causing the host to send matching IPv4/IPv6 traffic through the hooked interface, matching prior netfilter CNA treatment of pre-deployed nftables rules (e.g. CVE-2026-52998).\nAC:L - No race or uncontrollable victim state is required; with an affected egress fib rule present, the attacker reliably triggers the NULL dereference on the next matching outbound packet by controlling protocol headers and normal connection traffic.\nPR:N - Runtime exploitation needs only network traffic through the netdev egress hook; although installing the fib rule requires CAP_NET_ADMIN, validation incorrectly accepts it as legal, so orchestration or administrators can deploy it and remote attackers need no target credentials or local privileges.\nUI:N - No victim interaction is required beyond ordinary network traffic processing; the kernel automatically evaluates the fib expression on egress without mounts, file opens, or user prompts.\nS:U - Impact is a kernel NULL-pointer fault and host-wide denial of service within the same kernel/network-filtering security authority; it does not constitute VM escape, IOMMU bypass, or another cross-authority boundary change.\nC:N - The failure mode is a NULL pointer dereference of nft_in(pkt) on egress (in is NULL in nf_hook_state_init); there is no use-after-free, out-of-bounds read, or other attacker-controlled memory disclosure primitive.\nI:N - The bug does not corrupt writable memory or provide control-flow hijack; it only dereferences a NULL input device pointer during fib lookup/skipping and cannot modify kernel or user data beyond the immediate fault.\nA:H - The NULL dereference in nft_fib_netdev_eval/nft_fib4_eval/nft_fib6_eval on netdev egress causes a kernel oops/panic-class fault during packet transmission, denying system availability until reboot."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:42:07.408Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/4fee43759b489559a491f7c95f9bfa7a1d0c7a10"
},
{
"url": "https://git.kernel.org/stable/c/568931f26af4727a51e8521f72efbc78d3b82410"
},
{
"url": "https://git.kernel.org/stable/c/d01c913febead04a01a5f3a6374d1f45504dc523"
},
{
"url": "https://git.kernel.org/stable/c/f68305267ebda7e839b5e8f77e8d77535a3d5a0f"
},
{
"url": "https://git.kernel.org/stable/c/d07955dd34ecae17d35d8c7d0a273a3fba653a8c"
}
],
"title": "netfilter: nft_fib: reject fib expression on the netdev egress hook",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72254",
"datePublished": "2026-08-15T05:54:42.239Z",
"dateReserved": "2026-08-09T03:40:39.915Z",
"dateUpdated": "2026-08-17T05:42:07.408Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68106 (GCVE-0-2026-68106)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-19 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: fix division by zero with invalid uvd dimensions
When width or height is less than 16, width_in_mb or height_in_mb
becomes 0, leading to fs_in_mb being 0. This causes a division by
zero when calculating num_dpb_buffer in H264 and H264 Perf decode
paths.
Add validation to reject frames with width < 16 or height < 16
before performing any calculations that depend on these values.
V2: Format change - move up all vaiable definitions.
V3: Use warn_once to avoid spam.
(cherry picked from commit 3e41d26c70b0a459d041cc19482a226c4b7423cb)
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d38ceaf99ed015f2a0b9af3499791bd3a3daae21 Version: d38ceaf99ed015f2a0b9af3499791bd3a3daae21 Version: d38ceaf99ed015f2a0b9af3499791bd3a3daae21 Version: d38ceaf99ed015f2a0b9af3499791bd3a3daae21 Version: d38ceaf99ed015f2a0b9af3499791bd3a3daae21 Version: d38ceaf99ed015f2a0b9af3499791bd3a3daae21 Version: d38ceaf99ed015f2a0b9af3499791bd3a3daae21 Version: d38ceaf99ed015f2a0b9af3499791bd3a3daae21 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/amdgpu_uvd.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "004d0453cfef16f056cb7b8bc04f69f19cf9df32",
"status": "affected",
"version": "d38ceaf99ed015f2a0b9af3499791bd3a3daae21",
"versionType": "git"
},
{
"lessThan": "00ee64910ecf748cc15b23bbcbea472c203ec1e8",
"status": "affected",
"version": "d38ceaf99ed015f2a0b9af3499791bd3a3daae21",
"versionType": "git"
},
{
"lessThan": "81c9b4921f62d1642b9d775524ae9240e521a5ed",
"status": "affected",
"version": "d38ceaf99ed015f2a0b9af3499791bd3a3daae21",
"versionType": "git"
},
{
"lessThan": "52f9a588296432accf2982f7d258192a37562f4f",
"status": "affected",
"version": "d38ceaf99ed015f2a0b9af3499791bd3a3daae21",
"versionType": "git"
},
{
"lessThan": "a00946b5ab7c25da5685ca9c58f50ff6f43c0fdf",
"status": "affected",
"version": "d38ceaf99ed015f2a0b9af3499791bd3a3daae21",
"versionType": "git"
},
{
"lessThan": "ffb33d466a68cea3e8a3dbed04d79037a3cbabd1",
"status": "affected",
"version": "d38ceaf99ed015f2a0b9af3499791bd3a3daae21",
"versionType": "git"
},
{
"lessThan": "be725ab23aa45c11a5afef3e2a9f6d8c084ae5dc",
"status": "affected",
"version": "d38ceaf99ed015f2a0b9af3499791bd3a3daae21",
"versionType": "git"
},
{
"lessThan": "0c01c811be47e6b146552dd59bfedbea8f09b8f4",
"status": "affected",
"version": "d38ceaf99ed015f2a0b9af3499791bd3a3daae21",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/amdgpu_uvd.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.2"
},
{
"lessThan": "4.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: fix division by zero with invalid uvd dimensions\n\nWhen width or height is less than 16, width_in_mb or height_in_mb\nbecomes 0, leading to fs_in_mb being 0. This causes a division by\nzero when calculating num_dpb_buffer in H264 and H264 Perf decode\npaths.\n\nAdd validation to reject frames with width \u003c 16 or height \u003c 16\nbefore performing any calculations that depend on these values.\n\nV2: Format change - move up all vaiable definitions.\nV3: Use warn_once to avoid spam.\n\n(cherry picked from commit 3e41d26c70b0a459d041cc19482a226c4b7423cb)"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The flaw is reached only via the AMDGPU_CS DRM ioctl on a local render node (/dev/dri/renderD*), traversing amdgpu_cs_ioctl, amdgpu_cs_patch_ibs, amdgpu_uvd_ring_parse_cs, and amdgpu_uvd_cs_msg_decode; it is not reachable from any network-facing kernel service.\nAC:L - An attacker with render-node access fully controls the UVD decode message fields (stream_type H264/H264 Perf, width, height, level) in their own BO and can reliably trigger width or height \u003c 16 after creating a valid UVD session handle.\nPR:L - Exploitation requires only standard unprivileged local access to the AMDGPU DRM render node (DRM_AUTH|DRM_RENDER_ALLOW on AMDGPU_CS), not root or capabilities outside the render/video group; user namespaces do not grant this access by themselves.\nUI:N - No victim interaction is required; a local attacker can directly submit a crafted UVD command stream through AMDGPU_CS ioctl without needing another user to open media, mount a filesystem, or take any other action.\nS:U - Impact is confined to the kernel/GPU driver security domain on the local host (kernel oops or GPU memory corruption within the attacker\u0027s DRM client); it does not cross VM, IOMMU, or sandbox boundaries to affect a different security authority.\nC:H - On x86, kernel-mode divide-by-zero causes a fatal trap; on architectures where unsigned division by zero returns zero, underestimated DPB buffer sizes can pass validation, enabling GPU out-of-bounds reads of adjacent mapped buffers that may hold sensitive data.\nI:H - Underestimated buffer-size calculations from zero macroblock counts can let undersized DPB buffers pass kernel validation, permitting the UVD engine to perform out-of-bounds writes into adjacent GPU-mapped memory that could be leveraged for further memory corruption.\nA:H - Triggering the divide-by-zero in kernel context during CS parsing causes an x86 divide-error exception leading to die()/kernel oops, crashing or hanging the system; repeated submissions can deny GPU/video availability on affected UVD hardware (v3.1-v6.0)."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:29:19.954Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/004d0453cfef16f056cb7b8bc04f69f19cf9df32"
},
{
"url": "https://git.kernel.org/stable/c/00ee64910ecf748cc15b23bbcbea472c203ec1e8"
},
{
"url": "https://git.kernel.org/stable/c/81c9b4921f62d1642b9d775524ae9240e521a5ed"
},
{
"url": "https://git.kernel.org/stable/c/52f9a588296432accf2982f7d258192a37562f4f"
},
{
"url": "https://git.kernel.org/stable/c/a00946b5ab7c25da5685ca9c58f50ff6f43c0fdf"
},
{
"url": "https://git.kernel.org/stable/c/ffb33d466a68cea3e8a3dbed04d79037a3cbabd1"
},
{
"url": "https://git.kernel.org/stable/c/be725ab23aa45c11a5afef3e2a9f6d8c084ae5dc"
},
{
"url": "https://git.kernel.org/stable/c/0c01c811be47e6b146552dd59bfedbea8f09b8f4"
}
],
"title": "drm/amdgpu: fix division by zero with invalid uvd dimensions",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68106",
"datePublished": "2026-08-10T11:58:23.108Z",
"dateReserved": "2026-07-30T09:28:09.368Z",
"dateUpdated": "2026-08-19T16:29:19.954Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68269 (GCVE-0-2026-68269)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-19 16:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/i915/gem: Add missing nospec on parallel submit slot
Add missing Spectre mitigation for userspace controlled parallel
submission slot.
Discovered using AI-assisted static analysis confirmed by Intel
Product Security.
(cherry picked from commit 15b9353deff3cf72331c387780de3cf9c316b643)
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: e5e32171a2cf1e434d4f88e12467f3e47d0ec618 Version: e5e32171a2cf1e434d4f88e12467f3e47d0ec618 Version: e5e32171a2cf1e434d4f88e12467f3e47d0ec618 Version: e5e32171a2cf1e434d4f88e12467f3e47d0ec618 Version: e5e32171a2cf1e434d4f88e12467f3e47d0ec618 Version: e5e32171a2cf1e434d4f88e12467f3e47d0ec618 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/i915/gem/i915_gem_context.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "0ac3bab10c62997727a0a90f819a27d337347f93",
"status": "affected",
"version": "e5e32171a2cf1e434d4f88e12467f3e47d0ec618",
"versionType": "git"
},
{
"lessThan": "4a27275d275971c9ea29d3d240ea4a224ad368a2",
"status": "affected",
"version": "e5e32171a2cf1e434d4f88e12467f3e47d0ec618",
"versionType": "git"
},
{
"lessThan": "be393175306694de5da1d1a23a8ea4149baa09f1",
"status": "affected",
"version": "e5e32171a2cf1e434d4f88e12467f3e47d0ec618",
"versionType": "git"
},
{
"lessThan": "45db277b2e1e34bcc99a0852026791108339ec3e",
"status": "affected",
"version": "e5e32171a2cf1e434d4f88e12467f3e47d0ec618",
"versionType": "git"
},
{
"lessThan": "c41a54619e95f860bf2950dd679ab353380ecd2b",
"status": "affected",
"version": "e5e32171a2cf1e434d4f88e12467f3e47d0ec618",
"versionType": "git"
},
{
"lessThan": "914a76a9f08366434bf595700f62026b7a19a9cc",
"status": "affected",
"version": "e5e32171a2cf1e434d4f88e12467f3e47d0ec618",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/i915/gem/i915_gem_context.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.16"
},
{
"lessThan": "5.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.16",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/i915/gem: Add missing nospec on parallel submit slot\n\nAdd missing Spectre mitigation for userspace controlled parallel\nsubmission slot.\n\nDiscovered using AI-assisted static analysis confirmed by Intel\nProduct Security.\n\n(cherry picked from commit 15b9353deff3cf72331c387780de3cf9c316b643)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:32:30.915Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/0ac3bab10c62997727a0a90f819a27d337347f93"
},
{
"url": "https://git.kernel.org/stable/c/4a27275d275971c9ea29d3d240ea4a224ad368a2"
},
{
"url": "https://git.kernel.org/stable/c/be393175306694de5da1d1a23a8ea4149baa09f1"
},
{
"url": "https://git.kernel.org/stable/c/45db277b2e1e34bcc99a0852026791108339ec3e"
},
{
"url": "https://git.kernel.org/stable/c/c41a54619e95f860bf2950dd679ab353380ecd2b"
},
{
"url": "https://git.kernel.org/stable/c/914a76a9f08366434bf595700f62026b7a19a9cc"
}
],
"title": "drm/i915/gem: Add missing nospec on parallel submit slot",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68269",
"datePublished": "2026-08-10T12:01:44.575Z",
"dateReserved": "2026-07-30T09:28:09.378Z",
"dateUpdated": "2026-08-19T16:32:30.915Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68164 (GCVE-0-2026-68164)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
mm/damon/core: disallow overlapping input ranges for damon_set_regions()
damon_set_regions() assumes the input ranges are sorted by the address and
don't overlap each other. Hence the assumption was initially to be
explicitly validated. But commit 97d482f4592f ("mm/damon/sysfs: reuse
damon_set_regions() for regions setting") has mistakenly removed the
validation.
This can make DAMON behave in unexpected ways. At the best, the
monitoring results snapshot will just look weird since there will be
overlapping regions. DAMOS will also work weirdly, applying the same
action multiple times for overlapping regions, and make DAMOS quota weird.
More seriously, depending on the setup and regions updates sequence,
negative size regions can be made. It will trigger WARN_ONCE() if the
kernel is built with CONFIG_DAMON_DEBUG_SANITY=y. Depending on the
monitoring results, the negative size region can further trigger division
by zero in damon_merge_two_regions().
Note that some of the consequences including the WARN_ONCE() and the
divide by zero depend on commits that were introduced after the root cause
commit 97d482f4592f ("mm/damon/sysfs: reuse damon_set_regions() for
regions setting").
Fix the problems by checking the assumption and returning an error if
the input ranges don't meet the assumption.
The issue was discovered [1] by Sashiko.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 97d482f4592fde2322c319f07bc54f3a0d37861c Version: 97d482f4592fde2322c319f07bc54f3a0d37861c Version: 97d482f4592fde2322c319f07bc54f3a0d37861c Version: 97d482f4592fde2322c319f07bc54f3a0d37861c Version: 97d482f4592fde2322c319f07bc54f3a0d37861c Version: 97d482f4592fde2322c319f07bc54f3a0d37861c |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"mm/damon/core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a5c453fffb6f2ce75fc10b5d8bc475f1758010bd",
"status": "affected",
"version": "97d482f4592fde2322c319f07bc54f3a0d37861c",
"versionType": "git"
},
{
"lessThan": "4b4a3e7ef7bb622237495db9ba4dfd7417d6530e",
"status": "affected",
"version": "97d482f4592fde2322c319f07bc54f3a0d37861c",
"versionType": "git"
},
{
"lessThan": "06a4beeeec8f03f0b3e9c78a98f1ae4f0f18cfbd",
"status": "affected",
"version": "97d482f4592fde2322c319f07bc54f3a0d37861c",
"versionType": "git"
},
{
"lessThan": "6ce0db97fb37ab8cf8596edca0e3de8618ab009a",
"status": "affected",
"version": "97d482f4592fde2322c319f07bc54f3a0d37861c",
"versionType": "git"
},
{
"lessThan": "e33adf96afb5883f84b0d98747976bde293e33cb",
"status": "affected",
"version": "97d482f4592fde2322c319f07bc54f3a0d37861c",
"versionType": "git"
},
{
"lessThan": "954157679ec34661c2e87e7eb796104a797c32db",
"status": "affected",
"version": "97d482f4592fde2322c319f07bc54f3a0d37861c",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"mm/damon/core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.19"
},
{
"lessThan": "5.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/damon/core: disallow overlapping input ranges for damon_set_regions()\n\ndamon_set_regions() assumes the input ranges are sorted by the address and\ndon\u0027t overlap each other. Hence the assumption was initially to be\nexplicitly validated. But commit 97d482f4592f (\"mm/damon/sysfs: reuse\ndamon_set_regions() for regions setting\") has mistakenly removed the\nvalidation.\n\nThis can make DAMON behave in unexpected ways. At the best, the\nmonitoring results snapshot will just look weird since there will be\noverlapping regions. DAMOS will also work weirdly, applying the same\naction multiple times for overlapping regions, and make DAMOS quota weird.\nMore seriously, depending on the setup and regions updates sequence,\nnegative size regions can be made. It will trigger WARN_ONCE() if the\nkernel is built with CONFIG_DAMON_DEBUG_SANITY=y. Depending on the\nmonitoring results, the negative size region can further trigger division\nby zero in damon_merge_two_regions().\n\nNote that some of the consequences including the WARN_ONCE() and the\ndivide by zero depend on commits that were introduced after the root cause\ncommit 97d482f4592f (\"mm/damon/sysfs: reuse damon_set_regions() for\nregions setting\").\n\nFix the problems by checking the assumption and returning an error if\nthe input ranges don\u0027t meet the assumption.\n\nThe issue was discovered [1] by Sashiko."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:30:34.916Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a5c453fffb6f2ce75fc10b5d8bc475f1758010bd"
},
{
"url": "https://git.kernel.org/stable/c/4b4a3e7ef7bb622237495db9ba4dfd7417d6530e"
},
{
"url": "https://git.kernel.org/stable/c/06a4beeeec8f03f0b3e9c78a98f1ae4f0f18cfbd"
},
{
"url": "https://git.kernel.org/stable/c/6ce0db97fb37ab8cf8596edca0e3de8618ab009a"
},
{
"url": "https://git.kernel.org/stable/c/e33adf96afb5883f84b0d98747976bde293e33cb"
},
{
"url": "https://git.kernel.org/stable/c/954157679ec34661c2e87e7eb796104a797c32db"
}
],
"title": "mm/damon/core: disallow overlapping input ranges for damon_set_regions()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68164",
"datePublished": "2026-08-10T11:59:31.670Z",
"dateReserved": "2026-07-30T09:28:09.372Z",
"dateUpdated": "2026-08-19T16:30:34.916Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-53090 (GCVE-0-2026-53090)
Vulnerability from cvelistv5
Published
2026-06-24 16:30
Modified
2026-08-19 16:28
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
bpf: Fix ld_{abs,ind} failure path analysis in subprogs
Usage of ld_{abs,ind} instructions got extended into subprogs some time
ago via commit 09b28d76eac4 ("bpf: Add abnormal return checks."). These
are only allowed in subprograms when the latter are BTF annotated and
have scalar return types.
The code generator in bpf_gen_ld_abs() has an abnormal exit path (r0=0 +
exit) from legacy cBPF times. While the enforcement is on scalar return
types, the verifier must also simulate the path of abnormal exit if the
packet data load via ld_{abs,ind} failed.
This is currently not the case. Fix it by having the verifier simulate
both success and failure paths, and extend it in similar ways as we do
for tail calls. The success path (r0=unknown, continue to next insn) is
pushed onto stack for later validation and the r0=0 and return to the
caller is done on the fall-through side.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 09b28d76eac48e922dc293da1aa2b2b85c32aeee Version: 09b28d76eac48e922dc293da1aa2b2b85c32aeee Version: 09b28d76eac48e922dc293da1aa2b2b85c32aeee Version: 09b28d76eac48e922dc293da1aa2b2b85c32aeee Version: 09b28d76eac48e922dc293da1aa2b2b85c32aeee Version: 09b28d76eac48e922dc293da1aa2b2b85c32aeee Version: 09b28d76eac48e922dc293da1aa2b2b85c32aeee Version: 09b28d76eac48e922dc293da1aa2b2b85c32aeee |
||
{
"containers": {
"adp": [
{
"affected": [
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:10"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 10",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:6"
],
"defaultStatus": "unaffected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 6",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:7"
],
"defaultStatus": "unaffected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 7",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:7"
],
"defaultStatus": "unaffected",
"packageName": "kernel-rt",
"product": "Red Hat Enterprise Linux 7",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:8"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 8",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:8"
],
"defaultStatus": "affected",
"packageName": "kernel-rt",
"product": "Red Hat Enterprise Linux 8",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:9"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 9",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:9"
],
"defaultStatus": "affected",
"packageName": "kernel-rt",
"product": "Red Hat Enterprise Linux 9",
"vendor": "Red Hat"
}
],
"datePublic": "2026-06-24T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "A flaw was found in the Linux kernel\u0027s Berkeley Packet Filter (BPF) verifier. When `ld_{abs,ind}` instructions are used in BPF subprograms, the verifier fails to correctly simulate the abnormal exit path if packet data loading fails. This oversight could lead to unexpected behavior or bypass of security checks within the BPF execution environment."
}
],
"metrics": [
{
"other": {
"content": {
"namespace": "https://access.redhat.com/security/updates/classification/",
"value": "Moderate"
},
"type": "Red Hat severity rating"
}
},
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 6.4,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "HIGH",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-253",
"description": "Incorrect Check of Function Return Value",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-07-15T00:45:02.069Z",
"orgId": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
"shortName": "redhat-SADP"
},
"references": [
{
"tags": [
"vdb-entry",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/security/cve/CVE-2026-53090"
},
{
"name": "RHBZ#2492305",
"tags": [
"issue-tracking",
"x_refsource_REDHAT"
],
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492305"
},
{
"tags": [
"x_sadp-csaf-vex"
],
"url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53090.json"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-06-24T00:00:00.000Z",
"value": "Reported to Red Hat."
},
{
"lang": "en",
"time": "2026-06-24T00:00:00.000Z",
"value": "Made public."
}
],
"title": "kernel: bpf: Fix ld_{abs,ind} failure path analysis in subprogs",
"x_adpType": "supplier",
"x_generator": {
"engine": "sadp-cli 1.0.0"
}
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"kernel/bpf/verifier.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "928d354ae3557e8f755a227e67be88034eb3cd7f",
"status": "affected",
"version": "09b28d76eac48e922dc293da1aa2b2b85c32aeee",
"versionType": "git"
},
{
"lessThan": "8a800497d9f6c2ec9c2c1ba7b71d0ac2ea7f7bbe",
"status": "affected",
"version": "09b28d76eac48e922dc293da1aa2b2b85c32aeee",
"versionType": "git"
},
{
"lessThan": "de1055e7f9e67af32b1f3376066272b04e5223c0",
"status": "affected",
"version": "09b28d76eac48e922dc293da1aa2b2b85c32aeee",
"versionType": "git"
},
{
"lessThan": "37ad2bb11e9de92cb7b94548705eeedd87f7d392",
"status": "affected",
"version": "09b28d76eac48e922dc293da1aa2b2b85c32aeee",
"versionType": "git"
},
{
"lessThan": "8674e2db06cff6b50f2216eed9a761d15425bb34",
"status": "affected",
"version": "09b28d76eac48e922dc293da1aa2b2b85c32aeee",
"versionType": "git"
},
{
"lessThan": "ce01a4e5cfac7adbe0be565f90cd32ecbb2f8337",
"status": "affected",
"version": "09b28d76eac48e922dc293da1aa2b2b85c32aeee",
"versionType": "git"
},
{
"lessThan": "d846d83bdacbd8f14fc45c63b8c1d22608452e1c",
"status": "affected",
"version": "09b28d76eac48e922dc293da1aa2b2b85c32aeee",
"versionType": "git"
},
{
"lessThan": "ee861486e377edc55361c08dcbceab3f6b6577bd",
"status": "affected",
"version": "09b28d76eac48e922dc293da1aa2b2b85c32aeee",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"kernel/bpf/verifier.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.10"
},
{
"lessThan": "5.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.10",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "5.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix ld_{abs,ind} failure path analysis in subprogs\n\nUsage of ld_{abs,ind} instructions got extended into subprogs some time\nago via commit 09b28d76eac4 (\"bpf: Add abnormal return checks.\"). These\nare only allowed in subprograms when the latter are BTF annotated and\nhave scalar return types.\n\nThe code generator in bpf_gen_ld_abs() has an abnormal exit path (r0=0 +\nexit) from legacy cBPF times. While the enforcement is on scalar return\ntypes, the verifier must also simulate the path of abnormal exit if the\npacket data load via ld_{abs,ind} failed.\n\nThis is currently not the case. Fix it by having the verifier simulate\nboth success and failure paths, and extend it in similar ways as we do\nfor tail calls. The success path (r0=unknown, continue to next insn) is\npushed onto stack for later validation and the r0=0 and return to the\ncaller is done on the fall-through side."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The attacker must locally invoke the bpf() syscall to load a crafted BPF program; packets only trigger the already-loaded malicious program path.\nAC:L - The attacker controls the BPF bytecode, BTF annotations, and packet length needed to force the ld_abs/ld_ind failure path, with no race or external timing dependency.\nPR:L - The needed subprogram/BTF path requires CAP_BPF-equivalent BPF loading privileges, but BPF tokens can delegate these checks into a user namespace. Under the higher-severity rule, this is Low rather than High.\nUI:N - No victim action is required after the local attacker loads and triggers the crafted BPF program.\nS:U - The vulnerability compromises kernel execution within the same host security authority; it is standard local kernel privilege escalation, not a VM or hardware boundary escape.\nC:H - This is a verifier bypass where an unmodeled runtime path can execute code the verifier considered unreachable, enabling unsafe register and pointer use. Such BPF verifier bypasses can be developed into arbitrary kernel memory disclosure.\nI:H - The same unverified runtime path can be shaped into unsafe memory operations, making arbitrary kernel memory write or code execution defensible.\nA:H - Even without full exploitation, executing verifier-unchecked BPF operations can crash or panic the kernel, and the attacker can repeatedly trigger the path."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:28:06.530Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/928d354ae3557e8f755a227e67be88034eb3cd7f"
},
{
"url": "https://git.kernel.org/stable/c/8a800497d9f6c2ec9c2c1ba7b71d0ac2ea7f7bbe"
},
{
"url": "https://git.kernel.org/stable/c/de1055e7f9e67af32b1f3376066272b04e5223c0"
},
{
"url": "https://git.kernel.org/stable/c/37ad2bb11e9de92cb7b94548705eeedd87f7d392"
},
{
"url": "https://git.kernel.org/stable/c/8674e2db06cff6b50f2216eed9a761d15425bb34"
},
{
"url": "https://git.kernel.org/stable/c/ce01a4e5cfac7adbe0be565f90cd32ecbb2f8337"
},
{
"url": "https://git.kernel.org/stable/c/d846d83bdacbd8f14fc45c63b8c1d22608452e1c"
},
{
"url": "https://git.kernel.org/stable/c/ee861486e377edc55361c08dcbceab3f6b6577bd"
}
],
"title": "bpf: Fix ld_{abs,ind} failure path analysis in subprogs",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-53090",
"datePublished": "2026-06-24T16:30:29.413Z",
"dateReserved": "2026-06-09T07:44:35.384Z",
"dateUpdated": "2026-08-19T16:28:06.530Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68414 (GCVE-0-2026-68414)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-19 16:35
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: cfg80211: cancel sched scan results work on unregister
cfg80211_sched_scan_results() can queue rdev->sched_scan_res_wk from a
driver result notification while a scheduled scan request is present. The
work callback recovers the containing cfg80211_registered_device and then
locks the wiphy and walks the scheduled-scan request list.
wiphy_unregister() already makes the wiphy unreachable and drains rdev work
items before cfg80211_dev_free() can release the object, but it does not
drain sched_scan_res_wk. A queued or running result work item can therefore
cross the unregister/free boundary and access freed rdev state.
The buggy scenario involves two paths, with each column showing the order
within that path:
scheduled-scan result path: unregister/free path:
1. cfg80211_sched_scan_results() 1. interface teardown stops and
queues rdev->sched_scan_res_wk. removes the scheduled scan request.
2. cfg80211_wq starts the work 2. wiphy_unregister() drains other
item and recovers rdev. rdev work items.
3. The worker locks rdev->wiphy 3. cfg80211_dev_free() destroys and
and walks rdev state. frees rdev.
Cancel sched_scan_res_wk in wiphy_unregister() alongside the other rdev
work items. cancel_work_sync() removes a pending result notification and
waits for an already running callback, so cfg80211_dev_free() cannot free
rdev while this work item is still active.
Validation reproduced this kernel report:
BUG: KASAN: use-after-free in cfg80211_sched_scan_results_wk+0x4a6/0x530
Workqueue: cfg80211 cfg80211_sched_scan_results_wk [cfg80211]
Read of size 8
Call trace:
dump_stack_lvl+0x66/0xa0
print_report+0xce/0x630
cfg80211_sched_scan_results_wk+0x4a6/0x530
srso_alias_return_thunk+0x5/0xfbef5
__virt_addr_valid+0x224/0x430
kasan_report+0xac/0xe0
lockdep_hardirqs_on_prepare+0xea/0x1a0
process_one_work+0x8d0/0x18f0 (kernel/workqueue.c:3212)
lock_is_held_type+0x8f/0x100
worker_thread+0x5ad/0xfd0
__kthread_parkme+0xc6/0x200
kthread+0x31e/0x410
trace_hardirqs_on+0x1a/0x170
ret_from_fork+0x576/0x810
__switch_to+0x57e/0xe20
__switch_to_asm+0x33/0x70
ret_from_fork_asm+0x1a/0x30
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 807f8a8c300435d5483e8d78df9dcdbc27333166 Version: 807f8a8c300435d5483e8d78df9dcdbc27333166 Version: 807f8a8c300435d5483e8d78df9dcdbc27333166 Version: 807f8a8c300435d5483e8d78df9dcdbc27333166 Version: 807f8a8c300435d5483e8d78df9dcdbc27333166 Version: 807f8a8c300435d5483e8d78df9dcdbc27333166 Version: 807f8a8c300435d5483e8d78df9dcdbc27333166 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/wireless/core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c0fa1f3a4b021a5c6373169fd6c9bb4261d676a0",
"status": "affected",
"version": "807f8a8c300435d5483e8d78df9dcdbc27333166",
"versionType": "git"
},
{
"lessThan": "b51b42b974461fd0f688baad85f10e2b8ab215c5",
"status": "affected",
"version": "807f8a8c300435d5483e8d78df9dcdbc27333166",
"versionType": "git"
},
{
"lessThan": "3368457b4871ae8f0f88d19c9a3e6270e850ede6",
"status": "affected",
"version": "807f8a8c300435d5483e8d78df9dcdbc27333166",
"versionType": "git"
},
{
"lessThan": "308ffdf575560d7e7b8b21f1e3ca6276630f73bf",
"status": "affected",
"version": "807f8a8c300435d5483e8d78df9dcdbc27333166",
"versionType": "git"
},
{
"lessThan": "9293574ac208d18c11073538851fb69355beb3b5",
"status": "affected",
"version": "807f8a8c300435d5483e8d78df9dcdbc27333166",
"versionType": "git"
},
{
"lessThan": "b119c70b24776c8ab2a2c0515397b3b0ad4e66cd",
"status": "affected",
"version": "807f8a8c300435d5483e8d78df9dcdbc27333166",
"versionType": "git"
},
{
"lessThan": "edf0730be33696a1bd142792830d392129e495cc",
"status": "affected",
"version": "807f8a8c300435d5483e8d78df9dcdbc27333166",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/wireless/core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.0"
},
{
"lessThan": "3.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: cfg80211: cancel sched scan results work on unregister\n\ncfg80211_sched_scan_results() can queue rdev-\u003esched_scan_res_wk from a\ndriver result notification while a scheduled scan request is present. The\nwork callback recovers the containing cfg80211_registered_device and then\nlocks the wiphy and walks the scheduled-scan request list.\n\nwiphy_unregister() already makes the wiphy unreachable and drains rdev work\nitems before cfg80211_dev_free() can release the object, but it does not\ndrain sched_scan_res_wk. A queued or running result work item can therefore\ncross the unregister/free boundary and access freed rdev state.\n\nThe buggy scenario involves two paths, with each column showing the order\nwithin that path:\n\nscheduled-scan result path: unregister/free path:\n1. cfg80211_sched_scan_results() 1. interface teardown stops and\n queues rdev-\u003esched_scan_res_wk. removes the scheduled scan request.\n2. cfg80211_wq starts the work 2. wiphy_unregister() drains other\n item and recovers rdev. rdev work items.\n3. The worker locks rdev-\u003ewiphy 3. cfg80211_dev_free() destroys and\n and walks rdev state. frees rdev.\n\nCancel sched_scan_res_wk in wiphy_unregister() alongside the other rdev\nwork items. cancel_work_sync() removes a pending result notification and\nwaits for an already running callback, so cfg80211_dev_free() cannot free\nrdev while this work item is still active.\n\nValidation reproduced this kernel report:\nBUG: KASAN: use-after-free in cfg80211_sched_scan_results_wk+0x4a6/0x530\nWorkqueue: cfg80211 cfg80211_sched_scan_results_wk [cfg80211]\nRead of size 8\nCall trace:\n dump_stack_lvl+0x66/0xa0\n print_report+0xce/0x630\n cfg80211_sched_scan_results_wk+0x4a6/0x530\n srso_alias_return_thunk+0x5/0xfbef5\n __virt_addr_valid+0x224/0x430\n kasan_report+0xac/0xe0\n lockdep_hardirqs_on_prepare+0xea/0x1a0\n process_one_work+0x8d0/0x18f0 (kernel/workqueue.c:3212)\n lock_is_held_type+0x8f/0x100\n worker_thread+0x5ad/0xfd0\n __kthread_parkme+0xc6/0x200\n kthread+0x31e/0x410\n trace_hardirqs_on+0x1a/0x170\n ret_from_fork+0x576/0x810\n __switch_to+0x57e/0xe20\n __switch_to_asm+0x33/0x70\n ret_from_fork_asm+0x1a/0x30"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The work item is queued from driver PNO/background-scan match notifications that are produced by received 802.11 frames, so an attacker within WiFi range can drive cfg80211_sched_scan_results() by beaconing SSIDs matching the device\u0027s scheduled-scan match set. This is 802.11 frame injection, i.e. adjacent network reach.\nAC:H - The UAF requires the result-notification work to be queued or running exactly while wiphy_unregister()/cfg80211_dev_free() tears the rdev down; the attacker can drive and time the result notifications but cannot force the device-removal/module-unload half of the race, which is a condition outside their control.\nPR:N - No credentials or association are needed \u2014 an unauthenticated attacker in range simply transmits beacons/probe responses matching the scheduled scan already running on the victim (started by the system\u0027s normal wpa_supplicant/NetworkManager PNO), and the driver notifies cfg80211 unconditionally.\nUI:N - Scheduled scan runs continuously in the background on typical laptop, phone and embedded WiFi deployments, and the unregister side is a system/device event; no victim action such as opening a file or mounting anything is required.\nS:U - The freed object and all corrupted state are cfg80211 kernel structures, so the impact stays within the kernel\u0027s own security authority with no crossing of a VM, IOMMU or sandbox boundary.\nC:H - The worker reads freed rdev memory and then feeds freed scheduled-scan request contents into nl80211_send_sched_scan(), leaking reclaimed slab data to userspace netlink listeners; a controlled reallocation of the freed rdev gives an arbitrary-read style disclosure primitive.\nI:H - After the free the worker performs writes into the freed object \u2014 mutex_lock on rdev-\u003ewiphy.mtx, spin_lock on rdev-\u003ebss_lock, clearing req-\u003ereport_results, and list/refcount manipulation in __cfg80211_bss_expire() \u2014 which corrupts whatever object reclaims the slab and is leverageable for control-flow hijack via heap spraying.\nA:H - The confirmed KASAN use-after-free in cfg80211_sched_scan_results_wk() corrupts and dereferences freed memory from a workqueue context, reliably producing an oops/panic and taking down the system."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:35:12.312Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c0fa1f3a4b021a5c6373169fd6c9bb4261d676a0"
},
{
"url": "https://git.kernel.org/stable/c/b51b42b974461fd0f688baad85f10e2b8ab215c5"
},
{
"url": "https://git.kernel.org/stable/c/3368457b4871ae8f0f88d19c9a3e6270e850ede6"
},
{
"url": "https://git.kernel.org/stable/c/308ffdf575560d7e7b8b21f1e3ca6276630f73bf"
},
{
"url": "https://git.kernel.org/stable/c/9293574ac208d18c11073538851fb69355beb3b5"
},
{
"url": "https://git.kernel.org/stable/c/b119c70b24776c8ab2a2c0515397b3b0ad4e66cd"
},
{
"url": "https://git.kernel.org/stable/c/edf0730be33696a1bd142792830d392129e495cc"
}
],
"title": "wifi: cfg80211: cancel sched scan results work on unregister",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68414",
"datePublished": "2026-08-10T12:04:34.459Z",
"dateReserved": "2026-07-30T09:28:09.391Z",
"dateUpdated": "2026-08-19T16:35:12.312Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68107 (GCVE-0-2026-68107)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-17 04:58
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu/vcn4: avoid rereading IB param length
Reuse the parameter length returned by
vcn_v4_0_enc_find_ib_param() instead of rereading it from
the IB.
This avoids a potential TOCTOU issue if the IB contents
change between reads.
(cherry picked from commit dbb02b4755f8c1f3773263f2d779872c1c0c073a)
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: cfdde9197ecd957281507be99af172671a57755c Version: 6dc4eddeb7e6cca7e1ab32cafbda79d06e652d84 Version: 2b10cb58d7a3fd621ec9b2ba765a092e562ef998 Version: 2b10cb58d7a3fd621ec9b2ba765a092e562ef998 Version: 2b10cb58d7a3fd621ec9b2ba765a092e562ef998 Version: b1dc92f55b22a80ded8f0263c9ef4ba902303895 Version: 6.6.107 ≤ Version: 6.12.48 ≤ Version: 6.16.8 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/vcn_v4_0.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "bbbe6a2a8d8dc87243438d3ffea2083b52d882d9",
"status": "affected",
"version": "cfdde9197ecd957281507be99af172671a57755c",
"versionType": "git"
},
{
"lessThan": "ff6aa542d91d76a185f69bd1997b94a560ff5f6b",
"status": "affected",
"version": "6dc4eddeb7e6cca7e1ab32cafbda79d06e652d84",
"versionType": "git"
},
{
"lessThan": "bd868c077f67589ed2a714307ceaade5f246e302",
"status": "affected",
"version": "2b10cb58d7a3fd621ec9b2ba765a092e562ef998",
"versionType": "git"
},
{
"lessThan": "c309626bf91fa0a0b583575654e6e14e81f818a3",
"status": "affected",
"version": "2b10cb58d7a3fd621ec9b2ba765a092e562ef998",
"versionType": "git"
},
{
"lessThan": "3b4082fabc67c9780b06eb959e59dd92fa79c0f0",
"status": "affected",
"version": "2b10cb58d7a3fd621ec9b2ba765a092e562ef998",
"versionType": "git"
},
{
"status": "affected",
"version": "b1dc92f55b22a80ded8f0263c9ef4ba902303895",
"versionType": "git"
},
{
"lessThan": "6.6.148",
"status": "affected",
"version": "6.6.107",
"versionType": "semver"
},
{
"lessThan": "6.12.101",
"status": "affected",
"version": "6.12.48",
"versionType": "semver"
},
{
"lessThan": "6.17",
"status": "affected",
"version": "6.16.8",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/vcn_v4_0.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.17"
},
{
"lessThan": "6.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.6.107",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.12.48",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.16.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/vcn4: avoid rereading IB param length\n\nReuse the parameter length returned by\nvcn_v4_0_enc_find_ib_param() instead of rereading it from\nthe IB.\n\nThis avoids a potential TOCTOU issue if the IB contents\nchange between reads.\n\n(cherry picked from commit dbb02b4755f8c1f3773263f2d779872c1c0c073a)"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The flaw is only reachable through the local AMDGPU_CS DRM ioctl on /dev/dri/renderD* (amdgpu_cs_ioctl \u2192 amdgpu_cs_patch_jobs \u2192 amdgpu_cs_patch_ibs), which kmaps the user IB and calls vcn_v4_0_ring_patch_cs_in_place(); no network or physical-device path exists.\nAC:L - patch_cs_in_place reads IB contents directly from attacker-mapped GEM memory without copying; a concurrent thread can change the param-length dword between vcn_v4_0_enc_find_ib_param()\u0027s initial read and the later idx+=amdgpu_ib_get_value(ib,idx)/4, so the attacker controls both sides of the TOCTOU race.\nPR:L - AMDGPU_CS is registered with DRM_AUTH|DRM_RENDER_ALLOW, so any local user who can open the AMDGPU render node (typical render/video group on desktops, gaming handhelds, and GPU cloud instances) can submit VCN4 command buffers without root or init-namespace capabilities.\nUI:N - Exploitation requires only the attacker submitting crafted VCN encode IBs through their own DRM context; no separate victim action such as opening a file, mounting a filesystem, or interacting with malicious content is needed.\nS:C - On VFIO GPU-passthrough and cloud ML hosts, a malicious VM guest submits VCN command streams through the assigned AMD GPU to corrupt host amdgpu kernel state, crossing the guest-to-hypervisor security boundary analogous to a device-model escape.\nC:H - Racing the length dword smaller under-advances IB iteration so nested RADEON_VCN_ENGINE_INFO entries inside a parent package are reached; vcn_v4_0_dec_msg() then reads user-mapped message buffers without snapshotting, enabling TOCTOU check/use mismatches on length/offset fields and out-of-bounds kernel reads past validated bounds.\nI:H - The same nested-entry bypass plus unsnapshotted dec_msg parsing lets userspace rewrite offset/size after kernel validation, driving out-of-bounds accesses in the message loop; skipping vcn_v4_0_limit_sched() via mis-iteration also leaves scheduler/BO state inconsistently modified in attacker-influenceable ways.\nA:H - Racing the length field to zero on re-read makes idx+=0 and re-enters the same ENGINE_INFO entry indefinitely, soft-locking the CS ioctl path; vcn_v4_0_limit_sched() may also block in dma_fence_wait(), yielding repeatable kernel denial-of-service on shared GPU hosts."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:58:56.350Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/bbbe6a2a8d8dc87243438d3ffea2083b52d882d9"
},
{
"url": "https://git.kernel.org/stable/c/ff6aa542d91d76a185f69bd1997b94a560ff5f6b"
},
{
"url": "https://git.kernel.org/stable/c/bd868c077f67589ed2a714307ceaade5f246e302"
},
{
"url": "https://git.kernel.org/stable/c/c309626bf91fa0a0b583575654e6e14e81f818a3"
},
{
"url": "https://git.kernel.org/stable/c/3b4082fabc67c9780b06eb959e59dd92fa79c0f0"
}
],
"title": "drm/amdgpu/vcn4: avoid rereading IB param length",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68107",
"datePublished": "2026-08-10T11:58:24.135Z",
"dateReserved": "2026-07-30T09:28:09.368Z",
"dateUpdated": "2026-08-17T04:58:56.350Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68129 (GCVE-0-2026-68129)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-19 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
gve: fix Rx queue stall on alloc failure
When the system is under extreme memory pressure, page allocations can
fail during the Rx buffer refill loop. If the number of buffers posted
to hardware falls below a critical low threshold and the refill loop
exits due to allocation failures, the queue can stall:
1. The device drops incoming packets because there are no descriptors.
2. Since no packets are processed, no Rx completions are generated.
3. Because no completions occur, NAPI is never scheduled, preventing
the refill loop from running again even after memory is freed.
This results in a permanent queue stall.
Resolve this by introducing a starvation recovery timer for each Rx queue.
If the number of buffers posted to hardware falls below a critical low
threshold, start a timer to periodically reschedule NAPI. Once NAPI runs
and successfully refills the queue above the threshold, the timer is
not rescheduled.
The threshold is set to 32 because a single maximum-sized Receive Segment
Coalescing (RSC) packet can consume up to 19 descriptors in the Rx path.
Lower thresholds (such as 8 or 16) would be insufficient to process a
complete maximum-sized RSC packet, risking packet drops or unexpected
hardware behavior under memory pressure. Setting the threshold to 32
guarantees a safe margin to handle at least one full RSC packet.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 9b8dd5e5ea48bbb7532d20c4093a79d8283e4029 Version: 9b8dd5e5ea48bbb7532d20c4093a79d8283e4029 Version: 9b8dd5e5ea48bbb7532d20c4093a79d8283e4029 Version: 9b8dd5e5ea48bbb7532d20c4093a79d8283e4029 Version: 9b8dd5e5ea48bbb7532d20c4093a79d8283e4029 Version: 9b8dd5e5ea48bbb7532d20c4093a79d8283e4029 Version: 9b8dd5e5ea48bbb7532d20c4093a79d8283e4029 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/google/gve/gve.h",
"drivers/net/ethernet/google/gve/gve_rx_dqo.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "9db46e19e5d6bdcd4bf811284a5b0df1b984ef80",
"status": "affected",
"version": "9b8dd5e5ea48bbb7532d20c4093a79d8283e4029",
"versionType": "git"
},
{
"lessThan": "42d525e751c61b876b2b0ae4e71ba7a8ab0c2777",
"status": "affected",
"version": "9b8dd5e5ea48bbb7532d20c4093a79d8283e4029",
"versionType": "git"
},
{
"lessThan": "299d5728a7312fdd02059b074aebbe4ebbd391e4",
"status": "affected",
"version": "9b8dd5e5ea48bbb7532d20c4093a79d8283e4029",
"versionType": "git"
},
{
"lessThan": "0c317349b4baa5038d1fc373bf46d5a2419d1710",
"status": "affected",
"version": "9b8dd5e5ea48bbb7532d20c4093a79d8283e4029",
"versionType": "git"
},
{
"lessThan": "91e0249f3ef62b75fe8c9c9372eaba32876e4b3a",
"status": "affected",
"version": "9b8dd5e5ea48bbb7532d20c4093a79d8283e4029",
"versionType": "git"
},
{
"lessThan": "689b9f588d2d7323dc66293fe594a68d030f400f",
"status": "affected",
"version": "9b8dd5e5ea48bbb7532d20c4093a79d8283e4029",
"versionType": "git"
},
{
"lessThan": "b65352a1bac64442ad95e64f385b40ccb9f1b0db",
"status": "affected",
"version": "9b8dd5e5ea48bbb7532d20c4093a79d8283e4029",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/google/gve/gve.h",
"drivers/net/ethernet/google/gve/gve_rx_dqo.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.14"
},
{
"lessThan": "5.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ngve: fix Rx queue stall on alloc failure\n\nWhen the system is under extreme memory pressure, page allocations can\nfail during the Rx buffer refill loop. If the number of buffers posted\nto hardware falls below a critical low threshold and the refill loop\nexits due to allocation failures, the queue can stall:\n\n1. The device drops incoming packets because there are no descriptors.\n2. Since no packets are processed, no Rx completions are generated.\n3. Because no completions occur, NAPI is never scheduled, preventing\n the refill loop from running again even after memory is freed.\n\nThis results in a permanent queue stall.\n\nResolve this by introducing a starvation recovery timer for each Rx queue.\nIf the number of buffers posted to hardware falls below a critical low\nthreshold, start a timer to periodically reschedule NAPI. Once NAPI runs\nand successfully refills the queue above the threshold, the timer is\nnot rescheduled.\n\nThe threshold is set to 32 because a single maximum-sized Receive Segment\nCoalescing (RSC) packet can consume up to 19 descriptors in the Rx path.\nLower thresholds (such as 8 or 16) would be insufficient to process a\ncomplete maximum-sized RSC packet, risking packet drops or unexpected\nhardware behavior under memory pressure. Setting the threshold to 32\nguarantees a safe margin to handle at least one full RSC packet."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The flaw is in the gVNIC receive/refill path driven by incoming network traffic on internet-facing Google Cloud VMs; remote packets trigger NAPI polling that reaches gve_rx_post_buffers_dqo() where the stall occurs.\nAC:L - An attacker can reliably drive the vulnerable refill loop by sending high-volume traffic to exhaust RX page-pool buffers and pressure GFP_ATOMIC allocations; no race or rare layout is required beyond sustained network load.\nPR:N - Exploitation requires only the ability to send packets to the VM\u0027s gVNIC interface; no local account, capabilities, or authentication is needed on internet-reachable cloud instances.\nUI:N - No victim interaction is required; the permanent RX queue stall is triggered automatically during kernel packet receive processing under memory pressure.\nS:U - Impact is confined to the affected guest\u0027s network stack and does not cross VM, container, or IOMMU security boundaries; it is a guest-local denial of service, not an escape.\nC:N - This is a resource-management logic bug causing queue starvation with no out-of-bounds access, use-after-free, or information disclosure; no kernel or user memory is read by the attacker.\nI:N - The bug causes a permanent receive-queue stall without modifying kernel data structures, user data, or enabling code execution; there is no integrity impact beyond loss of connectivity.\nA:H - A failed refill below the 32-descriptor threshold permanently stalls the RX queue because no completions schedule NAPI again, causing lasting loss of network receive capability until reboot."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:29:44.226Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/9db46e19e5d6bdcd4bf811284a5b0df1b984ef80"
},
{
"url": "https://git.kernel.org/stable/c/42d525e751c61b876b2b0ae4e71ba7a8ab0c2777"
},
{
"url": "https://git.kernel.org/stable/c/299d5728a7312fdd02059b074aebbe4ebbd391e4"
},
{
"url": "https://git.kernel.org/stable/c/0c317349b4baa5038d1fc373bf46d5a2419d1710"
},
{
"url": "https://git.kernel.org/stable/c/91e0249f3ef62b75fe8c9c9372eaba32876e4b3a"
},
{
"url": "https://git.kernel.org/stable/c/689b9f588d2d7323dc66293fe594a68d030f400f"
},
{
"url": "https://git.kernel.org/stable/c/b65352a1bac64442ad95e64f385b40ccb9f1b0db"
}
],
"title": "gve: fix Rx queue stall on alloc failure",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68129",
"datePublished": "2026-08-10T11:58:51.406Z",
"dateReserved": "2026-07-30T09:28:09.370Z",
"dateUpdated": "2026-08-19T16:29:44.226Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68113 (GCVE-0-2026-68113)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-18 06:55
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu/gfx12: replace BUG_ON() with WARN_ON()
There's no need to crash the kernel for these cases.
(cherry picked from commit f952076f76d62f783e8ba4995a7c400d39354ccf)
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/gfx_v12_0.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "eef69b826b2036314b59020dfa6083fc859bfcc1",
"status": "affected",
"version": "52cb80c12e8a647aa9c903903d58916e6c1c4d38",
"versionType": "git"
},
{
"lessThan": "987bedd3ea89d747d1c5ab708ce3293e2f033b6c",
"status": "affected",
"version": "52cb80c12e8a647aa9c903903d58916e6c1c4d38",
"versionType": "git"
},
{
"lessThan": "81597685c0d73b9c2e1a89c12c576ab80d1c00f4",
"status": "affected",
"version": "52cb80c12e8a647aa9c903903d58916e6c1c4d38",
"versionType": "git"
},
{
"lessThan": "cd3b3efa1ced05528d9128755338baa62a6b562d",
"status": "affected",
"version": "52cb80c12e8a647aa9c903903d58916e6c1c4d38",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/gfx_v12_0.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.11"
},
{
"lessThan": "6.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/gfx12: replace BUG_ON() with WARN_ON()\n\nThere\u0027s no need to crash the kernel for these cases.\n\n(cherry picked from commit f952076f76d62f783e8ba4995a7c400d39354ccf)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-18T06:55:38.263Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/eef69b826b2036314b59020dfa6083fc859bfcc1"
},
{
"url": "https://git.kernel.org/stable/c/987bedd3ea89d747d1c5ab708ce3293e2f033b6c"
},
{
"url": "https://git.kernel.org/stable/c/81597685c0d73b9c2e1a89c12c576ab80d1c00f4"
},
{
"url": "https://git.kernel.org/stable/c/cd3b3efa1ced05528d9128755338baa62a6b562d"
}
],
"title": "drm/amdgpu/gfx12: replace BUG_ON() with WARN_ON()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68113",
"datePublished": "2026-08-10T11:58:31.059Z",
"dateReserved": "2026-07-30T09:28:09.369Z",
"dateUpdated": "2026-08-18T06:55:38.263Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64578 (GCVE-0-2026-64578)
Vulnerability from cvelistv5
Published
2026-08-05 08:09
Modified
2026-08-19 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: validate compound request size before reading StructureSize2
When ksmbd validates a compound (chained) SMB2 request,
ksmbd_smb2_check_message() reads pdu->StructureSize2 without first
checking that the compound element is large enough to contain it.
StructureSize2 is a 2-byte field at offset 64
(__SMB2_HEADER_STRUCTURE_SIZE) from the start of each element.
The compound-walking logic only guarantees that a full 64-byte SMB2
header is present for the trailing element: when NextCommand is 0, len is
reduced to the number of bytes remaining after next_smb2_rcv_hdr_off. A
remote client can craft a compound request whose last element has exactly
64 bytes, so the 2-byte StructureSize2 read at offset 64 extends one byte
past the receive buffer, producing a slab-out-of-bounds read.
BUG: KASAN: slab-out-of-bounds in ksmbd_smb2_check_message (fs/smb/server/smb2misc.c:402)
Read of size 2 at addr ffff888012ae31ac by task kworker/0:1/14
The buggy address is located 172 bytes inside of allocated 173-byte region
Workqueue: ksmbd-io handle_ksmbd_work
Call Trace:
...
kasan_report (mm/kasan/report.c:595)
ksmbd_smb2_check_message (fs/smb/server/smb2misc.c:402)
handle_ksmbd_work (fs/smb/server/server.c:119)
process_one_work (kernel/workqueue.c:3314)
worker_thread (kernel/workqueue.c:3397)
kthread (kernel/kthread.c:436)
ret_from_fork (arch/x86/kernel/process.c:158)
ret_from_fork_asm (arch/x86/entry/entry_64.S:245)
Reject any compound element that is too small to hold StructureSize2
before dereferencing it.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 Version: e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 Version: e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 Version: e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 Version: e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 Version: e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 Version: e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/smb/server/smb2misc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "415d0fff0451ad7ad4caa910f2bb0f562f0fd60f",
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"versionType": "git"
},
{
"lessThan": "1b6740525f5af90868d557c31b496ae689c8c549",
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"versionType": "git"
},
{
"lessThan": "2c307126ed8e7adddab82b8e31d962d3a2156ab1",
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"versionType": "git"
},
{
"lessThan": "f7550a91ab211726f59cb137523b7a9eae1ac6eb",
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"versionType": "git"
},
{
"lessThan": "f0e337e7db67cc1c832958bbb6c4026bdceacfdb",
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"versionType": "git"
},
{
"lessThan": "ea128f06d2fb2186f0cac0c9f3e953e4d1f5c29a",
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"versionType": "git"
},
{
"lessThan": "15b38176fd1530372905c602fde51fe89ec8c877",
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/smb/server/smb2misc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.15"
},
{
"lessThan": "5.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: validate compound request size before reading StructureSize2\n\nWhen ksmbd validates a compound (chained) SMB2 request,\nksmbd_smb2_check_message() reads pdu-\u003eStructureSize2 without first\nchecking that the compound element is large enough to contain it.\nStructureSize2 is a 2-byte field at offset 64\n(__SMB2_HEADER_STRUCTURE_SIZE) from the start of each element.\n\nThe compound-walking logic only guarantees that a full 64-byte SMB2\nheader is present for the trailing element: when NextCommand is 0, len is\nreduced to the number of bytes remaining after next_smb2_rcv_hdr_off. A\nremote client can craft a compound request whose last element has exactly\n64 bytes, so the 2-byte StructureSize2 read at offset 64 extends one byte\npast the receive buffer, producing a slab-out-of-bounds read.\n\n BUG: KASAN: slab-out-of-bounds in ksmbd_smb2_check_message (fs/smb/server/smb2misc.c:402)\n Read of size 2 at addr ffff888012ae31ac by task kworker/0:1/14\n The buggy address is located 172 bytes inside of allocated 173-byte region\n Workqueue: ksmbd-io handle_ksmbd_work\n Call Trace:\n ...\n kasan_report (mm/kasan/report.c:595)\n ksmbd_smb2_check_message (fs/smb/server/smb2misc.c:402)\n handle_ksmbd_work (fs/smb/server/server.c:119)\n process_one_work (kernel/workqueue.c:3314)\n worker_thread (kernel/workqueue.c:3397)\n kthread (kernel/kthread.c:436)\n ret_from_fork (arch/x86/kernel/process.c:158)\n ret_from_fork_asm (arch/x86/entry/entry_64.S:245)\n\nReject any compound element that is too small to hold StructureSize2\nbefore dereferencing it."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.2,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - ksmbd is an in-kernel SMB server reached over TCP/445; a remote client triggers the bug by sending a crafted compound SMB2 request that is processed in handle_ksmbd_work() \u2192 ksmbd_verify_smb_message() \u2192 ksmbd_smb2_check_message().\nAC:L - The attacker fully controls compound layout and can set the trailing element\u0027s remaining length to exactly 64 bytes so StructureSize2 is read one byte past the receive buffer; no race or attacker-uncontrollable condition is required.\nPR:N - On affected kernels before the compound SESSION_VALID check, a compound NtLmNegotiate SESSION_SETUP (pre-auth, no credentials) sets work-\u003esess and the trailing element still reaches ksmbd_smb2_check_message(); guest/anonymous SESSION_SETUP likewise needs no host privileges.\nUI:N - Exploitation requires only attacker-sent SMB2 protocol traffic to a listening ksmbd service; no victim user action is needed.\nS:U - The out-of-bounds read and any resulting kernel impact occur in the host ksmbd/workqueue context and do not cross a VM, IOMMU, or other security-authority boundary.\nC:L - The flaw is a strictly bounded slab out-of-bounds read of one byte past the receive buffer (2-byte StructureSize2 at offset 64 when only 64 bytes remain); it may disclose adjacent slab contents but not an arbitrary read primitive.\nI:N - The bug only reads past the buffer for a StructureSize2 comparison; for a 64-byte trailing element every valid command size is then rejected, and there is no out-of-bounds write or other modification primitive.\nA:H - KASAN reports a slab-out-of-bounds BUG in ksmbd_smb2_check_message(), and the same access can oops/panic hardened or redzone-enabled kernels; a remote peer can retrigger it with further crafted compound requests."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:29:02.136Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/415d0fff0451ad7ad4caa910f2bb0f562f0fd60f"
},
{
"url": "https://git.kernel.org/stable/c/1b6740525f5af90868d557c31b496ae689c8c549"
},
{
"url": "https://git.kernel.org/stable/c/2c307126ed8e7adddab82b8e31d962d3a2156ab1"
},
{
"url": "https://git.kernel.org/stable/c/f7550a91ab211726f59cb137523b7a9eae1ac6eb"
},
{
"url": "https://git.kernel.org/stable/c/f0e337e7db67cc1c832958bbb6c4026bdceacfdb"
},
{
"url": "https://git.kernel.org/stable/c/ea128f06d2fb2186f0cac0c9f3e953e4d1f5c29a"
},
{
"url": "https://git.kernel.org/stable/c/15b38176fd1530372905c602fde51fe89ec8c877"
}
],
"title": "ksmbd: validate compound request size before reading StructureSize2",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64578",
"datePublished": "2026-08-05T08:09:33.740Z",
"dateReserved": "2026-07-19T15:36:31.798Z",
"dateUpdated": "2026-08-19T16:29:02.136Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72124 (GCVE-0-2026-72124)
Vulnerability from cvelistv5
Published
2026-08-15 05:53
Modified
2026-08-19 16:36
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
can: isotp: serialize TX state transitions under so->rx_lock
The TX state machine (so->tx.state) is driven from three contexts:
sendmsg() claiming and progressing a transfer, the RX path consuming
Flow Control/echo frames, and two hrtimers timing out a stalled
transfer. Mixing a lock-free cmpxchg() claim in sendmsg() with
hrtimer_cancel() calls made under so->rx_lock elsewhere left windows
where a frame or timer callback could act on a state that had already
moved on, corrupting an unrelated transfer.
so->rx_lock now covers the full lifecycle of a TX claim: sendmsg()
takes it to check so->tx.state is ISOTP_IDLE, switch it to
ISOTP_SENDING, bump so->tx_gen and drain the previous transfer's
timers - all as one critical section. isotp_rcv_fc()/isotp_rcv_cf()
already run under this lock via isotp_rcv(), and isotp_rcv_echo() now
takes it itself, so none of them can ever observe a transfer mid-claim.
This also means a transfer can no longer be handed to sendmsg()'s
cleanup paths (signal or send error) while another thread is
concurrently claiming or finishing it, so those paths can cancel
timers and reset the state unconditionally.
isotp_release() claims the socket the same way, so a racing sendmsg()
sees a consistent ISOTP_SHUTDOWN and skips arming its timer or sending.
Only the hrtimer callbacks stay outside so->rx_lock, since they run
under so->rx_lock's cancellation elsewhere and taking it themselves
would deadlock. so->tx_gen lets them recognize whether the transfer
they timed out is still the one currently active, so they don't
report an error against a transfer that has since completed or been
superseded.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: e057dd3fc20ffb3d7f150af46542a51b59b90127 Version: e057dd3fc20ffb3d7f150af46542a51b59b90127 Version: e057dd3fc20ffb3d7f150af46542a51b59b90127 Version: e057dd3fc20ffb3d7f150af46542a51b59b90127 Version: e057dd3fc20ffb3d7f150af46542a51b59b90127 Version: e057dd3fc20ffb3d7f150af46542a51b59b90127 Version: e057dd3fc20ffb3d7f150af46542a51b59b90127 Version: e057dd3fc20ffb3d7f150af46542a51b59b90127 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/can/isotp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "bbedeb67a9a684f2fb78c55bd3662c400526715e",
"status": "affected",
"version": "e057dd3fc20ffb3d7f150af46542a51b59b90127",
"versionType": "git"
},
{
"lessThan": "377a8f500704da42ed86a4541ed930e9dcfdb2ea",
"status": "affected",
"version": "e057dd3fc20ffb3d7f150af46542a51b59b90127",
"versionType": "git"
},
{
"lessThan": "6da8119e8dd542194103139812d1a4b7dcd1aedd",
"status": "affected",
"version": "e057dd3fc20ffb3d7f150af46542a51b59b90127",
"versionType": "git"
},
{
"lessThan": "0b05eca9589f609e2491b528dccf683168a4cda8",
"status": "affected",
"version": "e057dd3fc20ffb3d7f150af46542a51b59b90127",
"versionType": "git"
},
{
"lessThan": "a7d90e7b5e75d7406c889fe36e9a61ee364a00cb",
"status": "affected",
"version": "e057dd3fc20ffb3d7f150af46542a51b59b90127",
"versionType": "git"
},
{
"lessThan": "37beb16e08cae94cc05840c7274225e3b0b38ae7",
"status": "affected",
"version": "e057dd3fc20ffb3d7f150af46542a51b59b90127",
"versionType": "git"
},
{
"lessThan": "4f1fdf1a1c317bcac0c6b6c8e12642c9983de1ca",
"status": "affected",
"version": "e057dd3fc20ffb3d7f150af46542a51b59b90127",
"versionType": "git"
},
{
"lessThan": "cf070fe33bfbd1a4c21236078fadb35dd223a157",
"status": "affected",
"version": "e057dd3fc20ffb3d7f150af46542a51b59b90127",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/can/isotp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.10"
},
{
"lessThan": "5.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: isotp: serialize TX state transitions under so-\u003erx_lock\n\nThe TX state machine (so-\u003etx.state) is driven from three contexts:\nsendmsg() claiming and progressing a transfer, the RX path consuming\nFlow Control/echo frames, and two hrtimers timing out a stalled\ntransfer. Mixing a lock-free cmpxchg() claim in sendmsg() with\nhrtimer_cancel() calls made under so-\u003erx_lock elsewhere left windows\nwhere a frame or timer callback could act on a state that had already\nmoved on, corrupting an unrelated transfer.\n\nso-\u003erx_lock now covers the full lifecycle of a TX claim: sendmsg()\ntakes it to check so-\u003etx.state is ISOTP_IDLE, switch it to\nISOTP_SENDING, bump so-\u003etx_gen and drain the previous transfer\u0027s\ntimers - all as one critical section. isotp_rcv_fc()/isotp_rcv_cf()\nalready run under this lock via isotp_rcv(), and isotp_rcv_echo() now\ntakes it itself, so none of them can ever observe a transfer mid-claim.\nThis also means a transfer can no longer be handed to sendmsg()\u0027s\ncleanup paths (signal or send error) while another thread is\nconcurrently claiming or finishing it, so those paths can cancel\ntimers and reset the state unconditionally.\n\nisotp_release() claims the socket the same way, so a racing sendmsg()\nsees a consistent ISOTP_SHUTDOWN and skips arming its timer or sending.\n\nOnly the hrtimer callbacks stay outside so-\u003erx_lock, since they run\nunder so-\u003erx_lock\u0027s cancellation elsewhere and taking it themselves\nwould deadlock. so-\u003etx_gen lets them recognize whether the transfer\nthey timed out is still the one currently active, so they don\u0027t\nreport an error against a transfer that has since completed or been\nsuperseded."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The bug is hit on the SocketCAN receive path (can_rcv\u2192isotp_rcv/isotp_rcv_echo for FC/echo frames) racing sendmsg() and hrtimers; in automotive/industrial ISO-TP (UDS) deployments an attacker on the same CAN segment can inject timed FC/echo frames without host shell access.\nAC:L - The attacker controls both sides of the race via concurrent sendmsg()/close() threads plus crafted FC/echo traffic and timer timing; sashiko-bot/syzkaller reproduces it reliably with no conditions outside attacker influence.\nPR:N - Once a victim ISO-TP socket is bound and transmitting (normal diagnostic behavior), an unauthenticated CAN bus peer needs no Linux credentials; CAN_ISOTP socket create/bind/sendmsg paths impose no capability checks.\nUI:N - No victim interaction beyond routine background ISO-TP traffic on an already-bound socket; the attacker drives concurrent transfers and FC/echo timing to hit the unsynchronized TX state transitions.\nS:U - Impact is kernel ISO-TP/socket heap corruption within the same OS security authority, without inherent VM escape, container breakout, or IOMMU boundary crossing.\nC:H - Mis-serialized so-\u003etx.state, tx.idx, and rx reassembly state lets stale echo/FC/timer handlers operate on the wrong transfer, enabling out-of-bounds reads from tpcon tx/rx buffers and adjacent kernel heap disclosure.\nI:H - The same cross-transfer corruption writes through tpcon buffers and socket state (indices, sequence numbers, timers), yielding attacker-influenced kernel heap corruption rather than a benign protocol error.\nA:H - Stale timers and handlers acting on superseded transfers can provoke sk_err storms, skb/state corruption, and kernel oops/panic in softirq/timer context, matching prior isotp timer race failures and repeatable DoS."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:36:21.129Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/bbedeb67a9a684f2fb78c55bd3662c400526715e"
},
{
"url": "https://git.kernel.org/stable/c/377a8f500704da42ed86a4541ed930e9dcfdb2ea"
},
{
"url": "https://git.kernel.org/stable/c/6da8119e8dd542194103139812d1a4b7dcd1aedd"
},
{
"url": "https://git.kernel.org/stable/c/0b05eca9589f609e2491b528dccf683168a4cda8"
},
{
"url": "https://git.kernel.org/stable/c/a7d90e7b5e75d7406c889fe36e9a61ee364a00cb"
},
{
"url": "https://git.kernel.org/stable/c/37beb16e08cae94cc05840c7274225e3b0b38ae7"
},
{
"url": "https://git.kernel.org/stable/c/4f1fdf1a1c317bcac0c6b6c8e12642c9983de1ca"
},
{
"url": "https://git.kernel.org/stable/c/cf070fe33bfbd1a4c21236078fadb35dd223a157"
}
],
"title": "can: isotp: serialize TX state transitions under so-\u003erx_lock",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72124",
"datePublished": "2026-08-15T05:53:02.172Z",
"dateReserved": "2026-08-09T03:40:39.907Z",
"dateUpdated": "2026-08-19T16:36:21.129Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68097 (GCVE-0-2026-68097)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-17 04:58
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: validate ACE size against SID sub-authorities
set_ntacl_dacl() validates sid.num_subauth before copying an ACE, but
does not verify that the declared ACE size contains all sub-authorities
described by that field. An undersized ACE can therefore be copied
and later make the POSIX ACL deduplication walk inspect data beyond
the copied ACE boundary.
The existing initial bound check is also too small. It only ensures
that the ACE size field is accessible before set_ntacl_dacl() reads
sid.num_subauth farther into the input buffer.
Require enough input for the fixed SID header before accessing
num_subauth, reject ACEs smaller than that header, and skip ACEs
whose declared size cannot contain the complete SID. This makes the
validation consistent with the other ACE walk paths.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/smb/server/smbacl.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b7cb5bf0855470799f12da825de91e48951b3876",
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"versionType": "git"
},
{
"lessThan": "62d80d7c2d9428085e7458ad4c06ca8c0984039b",
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"versionType": "git"
},
{
"lessThan": "337022d9dfac441c3b35e4455a51aa981996e02e",
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"versionType": "git"
},
{
"lessThan": "61fd3559199f7fa693dcbff35e59477e24af041a",
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"versionType": "git"
},
{
"lessThan": "5152c6d49e3fd4e9f2e857c57527aead752f1f87",
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/smb/server/smbacl.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.15"
},
{
"lessThan": "5.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: validate ACE size against SID sub-authorities\n\nset_ntacl_dacl() validates sid.num_subauth before copying an ACE, but\ndoes not verify that the declared ACE size contains all sub-authorities\ndescribed by that field. An undersized ACE can therefore be copied\nand later make the POSIX ACL deduplication walk inspect data beyond\nthe copied ACE boundary.\n\nThe existing initial bound check is also too small. It only ensures\nthat the ACE size field is accessible before set_ntacl_dacl() reads\nsid.num_subauth farther into the input buffer.\n\nRequire enough input for the fixed SID header before accessing\nnum_subauth, reject ACEs smaller than that header, and skip ACEs\nwhose declared size cannot contain the complete SID. This makes the\nvalidation consistent with the other ACE walk paths."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug is in ksmbd ACL handling reached from SMB2 network commands on TCP/445; build_sec_desc() is invoked from SMB2_QUERY_INFO(SecInfo) after reading attacker-supplied NT security descriptors stored via the server.\nAC:L - An attacker fully controls ACE size and SID sub-authority fields in SMB SET_INFO/CREATE_SD_BUFFER payloads; parse_sec_desc() stores the raw SD despite parse_dacl() skipping bad ACEs, so a subsequent QUERY_INFO reliably triggers the flawed copy and dedup walk.\nPR:L - Exploitation requires an authenticated SMB session and FILE_WRITE_DAC or FILE_WRITE_OWNER to plant the malformed SD (or CREATE_SD_BUFFER on create), but no server administrator or host root privileges; guest/writable share access is sufficient.\nUI:N - No end-user interaction is required beyond the attacker (or any client) issuing normal SMB file security operations against ksmbd; no mount, open-in-client, or other victim action is needed.\nS:U - The vulnerability is confined to kernel ksmbd processing of SMB security descriptors and does not cross a VM, container, or IOMMU security boundary; impact remains within the kernel/host security authority.\nC:H - Undersized ACEs are copied with attacker-controlled num_subauth, and set_posix_acl_entries_dacl() reads ntace-\u003esid.sub_auth[num_subauth-1] and advances by attacker-controlled ACE size, causing out-of-bounds kernel heap reads and a comparison oracle that can disclose kernel memory.\nI:H - The same inconsistent ACE metadata and unbounded dedup pointer arithmetic corrupt kernel heap ACL construction during security-descriptor rebuild; per kernel guidance, this class of memory corruption is treated as potentially chainable to arbitrary kernel writes and code execution.\nA:H - Walking ACEs with attacker-controlled size fields against a truncated copy can read beyond the allocated scratch buffer and fault the kernel (oops/panic), and the bug class is triggered on every QUERY_INFO that rebuilds DACLs from poisoned xattrs."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:58:45.888Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b7cb5bf0855470799f12da825de91e48951b3876"
},
{
"url": "https://git.kernel.org/stable/c/62d80d7c2d9428085e7458ad4c06ca8c0984039b"
},
{
"url": "https://git.kernel.org/stable/c/337022d9dfac441c3b35e4455a51aa981996e02e"
},
{
"url": "https://git.kernel.org/stable/c/61fd3559199f7fa693dcbff35e59477e24af041a"
},
{
"url": "https://git.kernel.org/stable/c/5152c6d49e3fd4e9f2e857c57527aead752f1f87"
}
],
"title": "ksmbd: validate ACE size against SID sub-authorities",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68097",
"datePublished": "2026-08-10T11:58:11.289Z",
"dateReserved": "2026-07-30T09:28:09.368Z",
"dateUpdated": "2026-08-17T04:58:45.888Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68348 (GCVE-0-2026-68348)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-17 05:03
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ASoC: tas2781: bound firmware description string parsing
The TAS2781 firmware parser reads several variable-length description
strings with strlen() before checking that the string terminator is
present inside the firmware blob. A malformed firmware image without a
NUL terminator can therefore make the parser walk past the end of the
firmware buffer before the later size checks run.
Add a small bounded string-length helper and use it for all description
fields that are parsed from the firmware buffer. Keep the existing size
checks for the fixed bytes that follow each string.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"sound/soc/codecs/tas2781-fmwlib.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "3ddb0d3e36507615e5ef010a879357a54870adf5",
"status": "affected",
"version": "915f5eadebd29ba185ac506766a90120153b7e14",
"versionType": "git"
},
{
"lessThan": "0ec45e80a82785ee147516fdecf5c93707dec119",
"status": "affected",
"version": "915f5eadebd29ba185ac506766a90120153b7e14",
"versionType": "git"
},
{
"lessThan": "41ae2b7d37c3dd82302167496836cca9f0328374",
"status": "affected",
"version": "915f5eadebd29ba185ac506766a90120153b7e14",
"versionType": "git"
},
{
"lessThan": "e75ef37d83c90b09bedb601624b47e168202b226",
"status": "affected",
"version": "915f5eadebd29ba185ac506766a90120153b7e14",
"versionType": "git"
},
{
"lessThan": "bc889dfcea9294a1eae7f8e2f3573a90764ae4d0",
"status": "affected",
"version": "915f5eadebd29ba185ac506766a90120153b7e14",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"sound/soc/codecs/tas2781-fmwlib.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.5"
},
{
"lessThan": "6.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: tas2781: bound firmware description string parsing\n\nThe TAS2781 firmware parser reads several variable-length description\nstrings with strlen() before checking that the string terminator is\npresent inside the firmware blob. A malformed firmware image without a\nNUL terminator can therefore make the parser walk past the end of the\nfirmware buffer before the later size checks run.\n\nAdd a small bounded string-length helper and use it for all description\nfields that are parsed from the firmware buffer. Keep the existing size\nchecks for the fixed bytes that follow each string."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The malformed blob is consumed by request_firmware() from the local firmware search path during tas2781 codec probe (tasdevice_dsp_parser/tas2781_load_calibration); there is no network, adjacent-network, or peer-supplied data path into the parser, so local presence on the affected system is required.\nAC:L - Simply omitting the NUL terminator at the end of a coef/cal .bin file makes strlen() run past fmw-\u003esize deterministically on every load \u2014 no race, no timing window, and no memory-layout precondition the attacker cannot influence.\nPR:L - The parsing path contains no capability, credential, or privilege check whatsoever, and the firmware search path on many embedded/Android/appliance deployments lives on a vendor or data partition writable by non-root system accounts; a low-privileged local account is therefore sufficient to be positioned to place the blob.\nUI:N - Parsing runs from the asynchronous request_firmware_nowait() completion callback during device probe/bind; once the file is in place it is consumed automatically at the next boot or driver bind with no victim action required.\nS:U - The out-of-bounds read occurs in kernel memory belonging to the same kernel that hosts the vulnerable codec driver, with no crossing of a VM, IOMMU, or sandbox boundary.\nC:H - strlen() is unbounded \u2014 it walks from the description offset through arbitrary kernel memory adjacent to the firmware buffer until a zero byte is found, so the read is not confined to a few bytes and touches heap/vmalloc contents outside the intended allocation.\nI:N - The defect is purely a read: the computed length is re-validated against fmw-\u003esize afterwards (and int/size_t promotion makes overflowed sums fail the check), so no out-of-bounds write or corrupted parse offset results from the OOB strlen.\nA:H - Firmware buffers are vmalloc/kmalloc allocations, so a strlen() walk past the end readily crosses into an unmapped page or guard page and produces a kernel oops/panic, which is High availability impact."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:03:50.265Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/3ddb0d3e36507615e5ef010a879357a54870adf5"
},
{
"url": "https://git.kernel.org/stable/c/0ec45e80a82785ee147516fdecf5c93707dec119"
},
{
"url": "https://git.kernel.org/stable/c/41ae2b7d37c3dd82302167496836cca9f0328374"
},
{
"url": "https://git.kernel.org/stable/c/e75ef37d83c90b09bedb601624b47e168202b226"
},
{
"url": "https://git.kernel.org/stable/c/bc889dfcea9294a1eae7f8e2f3573a90764ae4d0"
}
],
"title": "ASoC: tas2781: bound firmware description string parsing",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68348",
"datePublished": "2026-08-10T12:03:25.193Z",
"dateReserved": "2026-07-30T09:28:09.384Z",
"dateUpdated": "2026-08-17T05:03:50.265Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72175 (GCVE-0-2026-72175)
Vulnerability from cvelistv5
Published
2026-08-15 05:53
Modified
2026-08-17 05:41
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
fs/proc/task_mmu: fix make_uffd_wp_huge_pte() prot-update race
Patch series "userfaultfd/pagemap: pre-existing fixes".
These are pre-existing bug fixes that were carried at the front of the
userfaultfd RWP working-set-tracking series up to v5 [1]. Per review
feedback that fixes should not sit in the middle of a feature series, they
are split out and sent on their own; the RWP series is reposted rebased on
top of this.
All six were flagged by the Sashiko AI review of the RWP series and carry
independent of RWP, apply to mm-new directly, and carry Cc: stable@.
1: fs/proc/task_mmu: a missing huge_ptep_modify_prot_start() in
make_uffd_wp_huge_pte() can lose hardware Dirty/Accessed updates
when PAGEMAP_SCAN write-protects a hugetlb PTE.
2: fs/proc/task_mmu: pagemap_scan_hugetlb_entry() compares the range
against HPAGE_SIZE rather than the hstate page size, so it never
write-protects gigantic hugetlb pages.
3: fs/proc/task_mmu: PAGEMAP_SCAN with PM_SCAN_WP_MATCHING over an
unpopulated hugetlb range self-deadlocks -- pagemap_scan_pte_hole()
calls uffd_wp_range() while walk_hugetlb_range() holds the hugetlb
vma lock for read, and hugetlb_change_protection() then takes it
for write. Install the marker inline instead.
4: mm/huge_memory: change_non_present_huge_pmd() drops pmd_swp_uffd_wp
on a device-private PMD permission downgrade, silently losing the
uffd-wp marker.
5: userfaultfd: must_wait() applies pte_write() to a locklessly read
PTE without checking pte_present(), so swap/migration entries
decode random offset bits and a thread can stay parked on a stale
fault.
6: userfaultfd: __VMA_UFFD_FLAGS feeds VMA_UFFD_MINOR_BIT (41) to
mk_vma_flags() unconditionally, an out-of-bounds write into the
single-word vma_flags_t on 32-bit. Build the mask from config-gated
per-mode masks so an unavailable bit is never materialised.
This patch (of 6):
make_uffd_wp_huge_pte() arms the UFFD_WP bit on a present HugeTLB PTE by
calling huge_ptep_modify_prot_commit() with a ptent snapshot that was
fetched without the corresponding huge_ptep_modify_prot_start(). The
start helper is what atomically clears the entry so the kernel-owned
snapshot stays consistent until the commit; without it, the hardware may
set Dirty or Accessed in the live PTE between the original read and the
commit, and huge_ptep_modify_prot_commit() (whose generic implementation
just calls set_huge_pte_at()) then writes the stale snapshot back over the
live hardware bits, losing the update.
The non-hugetlb sibling make_uffd_wp_pte() does this correctly via
ptep_modify_prot_start() / ptep_modify_prot_commit(). Mirror that pattern
for the present-PTE branch. The migration case stays as-is -- migration
entries are non-present, so there's no hardware update to race against.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/proc/task_mmu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "50a25249a6355db74c2c1b6be541b4caab9f3655",
"status": "affected",
"version": "52526ca7fdb905a768a93f8faa418e9b988fc34b",
"versionType": "git"
},
{
"lessThan": "8e39ed92d7c5c6bfc08dc45153916f49a4e98bab",
"status": "affected",
"version": "52526ca7fdb905a768a93f8faa418e9b988fc34b",
"versionType": "git"
},
{
"lessThan": "6b7f774b8882445d9174681747d37c42548686a4",
"status": "affected",
"version": "52526ca7fdb905a768a93f8faa418e9b988fc34b",
"versionType": "git"
},
{
"lessThan": "04718f7c9290f95385f0dd328758753dc1c36dec",
"status": "affected",
"version": "52526ca7fdb905a768a93f8faa418e9b988fc34b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/proc/task_mmu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.7"
},
{
"lessThan": "6.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs/proc/task_mmu: fix make_uffd_wp_huge_pte() prot-update race\n\nPatch series \"userfaultfd/pagemap: pre-existing fixes\".\n\nThese are pre-existing bug fixes that were carried at the front of the\nuserfaultfd RWP working-set-tracking series up to v5 [1]. Per review\nfeedback that fixes should not sit in the middle of a feature series, they\nare split out and sent on their own; the RWP series is reposted rebased on\ntop of this.\n\nAll six were flagged by the Sashiko AI review of the RWP series and carry\nindependent of RWP, apply to mm-new directly, and carry Cc: stable@.\n\n 1: fs/proc/task_mmu: a missing huge_ptep_modify_prot_start() in\n make_uffd_wp_huge_pte() can lose hardware Dirty/Accessed updates\n when PAGEMAP_SCAN write-protects a hugetlb PTE.\n\n 2: fs/proc/task_mmu: pagemap_scan_hugetlb_entry() compares the range\n against HPAGE_SIZE rather than the hstate page size, so it never\n write-protects gigantic hugetlb pages.\n\n 3: fs/proc/task_mmu: PAGEMAP_SCAN with PM_SCAN_WP_MATCHING over an\n unpopulated hugetlb range self-deadlocks -- pagemap_scan_pte_hole()\n calls uffd_wp_range() while walk_hugetlb_range() holds the hugetlb\n vma lock for read, and hugetlb_change_protection() then takes it\n for write. Install the marker inline instead.\n\n 4: mm/huge_memory: change_non_present_huge_pmd() drops pmd_swp_uffd_wp\n on a device-private PMD permission downgrade, silently losing the\n uffd-wp marker.\n\n 5: userfaultfd: must_wait() applies pte_write() to a locklessly read\n PTE without checking pte_present(), so swap/migration entries\n decode random offset bits and a thread can stay parked on a stale\n fault.\n\n 6: userfaultfd: __VMA_UFFD_FLAGS feeds VMA_UFFD_MINOR_BIT (41) to\n mk_vma_flags() unconditionally, an out-of-bounds write into the\n single-word vma_flags_t on 32-bit. Build the mask from config-gated\n per-mode masks so an unavailable bit is never materialised.\n\n\nThis patch (of 6):\n\nmake_uffd_wp_huge_pte() arms the UFFD_WP bit on a present HugeTLB PTE by\ncalling huge_ptep_modify_prot_commit() with a ptent snapshot that was\nfetched without the corresponding huge_ptep_modify_prot_start(). The\nstart helper is what atomically clears the entry so the kernel-owned\nsnapshot stays consistent until the commit; without it, the hardware may\nset Dirty or Accessed in the live PTE between the original read and the\ncommit, and huge_ptep_modify_prot_commit() (whose generic implementation\njust calls set_huge_pte_at()) then writes the stale snapshot back over the\nlive hardware bits, losing the update.\n\nThe non-hugetlb sibling make_uffd_wp_pte() does this correctly via\nptep_modify_prot_start() / ptep_modify_prot_commit(). Mirror that pattern\nfor the present-PTE branch. The migration case stays as-is -- migration\nentries are non-present, so there\u0027s no hardware update to race against."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached only through the PAGEMAP_SCAN ioctl on /proc/\u003cpid\u003e/pagemap, which requires local access to a process address space and cannot be triggered remotely.\nAC:L - The attacker controls both sides of the race by issuing PAGEMAP_SCAN with PM_SCAN_WP_MATCHING while concurrently writing the same present HugeTLB page from another thread in the target process.\nPR:L - Any unprivileged local user can open /proc/self/pagemap and trigger the ioctl; ptrace read checks also allow same-UID access to another process\u0027s pagemap without real root privileges.\nUI:N - No victim user action is required; exploitation is performed entirely by the attacker ioctl-ing pagemap and racing writes against their own or same-UID process mappings.\nS:U - The vulnerability corrupts PTE metadata within the target mm only and does not cross VM, container, or kernel/user security boundaries.\nC:H - Stale HugeTLB PTE commits can clear hardware Dirty/Accessed bits; this PTE corruption can expose stale file-backed data to other mappers or userfaultfd migration consumers instead of current memory contents.\nI:H - Lost Dirty bits break folio dirty tracking and writeback for HugeTLB mappings, allowing silent loss or corruption of in-memory modifications that should have been persisted or migrated.\nA:N - The race corrupts PTE metadata without causing kernel oops, panic, or hang; availability impact is limited to incorrect page state rather than system crash."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:41:11.530Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/50a25249a6355db74c2c1b6be541b4caab9f3655"
},
{
"url": "https://git.kernel.org/stable/c/8e39ed92d7c5c6bfc08dc45153916f49a4e98bab"
},
{
"url": "https://git.kernel.org/stable/c/6b7f774b8882445d9174681747d37c42548686a4"
},
{
"url": "https://git.kernel.org/stable/c/04718f7c9290f95385f0dd328758753dc1c36dec"
}
],
"title": "fs/proc/task_mmu: fix make_uffd_wp_huge_pte() prot-update race",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72175",
"datePublished": "2026-08-15T05:53:40.011Z",
"dateReserved": "2026-08-09T03:40:39.910Z",
"dateUpdated": "2026-08-17T05:41:11.530Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68389 (GCVE-0-2026-68389)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-17 05:04
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci_qca: Clear memdump state on invalid dump size
qca_controller_memdump() allocates qca->qca_memdump before processing
the first dump packet. For a sequence-zero packet it then disables IBS,
marks memdump collection active, and reads the advertised dump size.
If the controller reports a zero dump size, the error path frees the
local qca_memdump object and returns without clearing qca->qca_memdump
or undoing the collection state. A later memdump work item initializes
its local pointer from qca->qca_memdump and skips allocation when that
pointer is non-NULL, so it can operate on freed memory. The stale
collection and IBS-disabled flags can also leave waiters or later
transmit handling blocked behind an aborted dump.
Clear the saved pointer and memdump state before returning from the
invalid-size path, matching the cleanup used when hci_devcd_init() fails.
A static analysis checker reported the stale memdump state, and manual
source review confirmed the invalid-size failure path.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/bluetooth/hci_qca.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "5a3945e8dea6c9a8ec9e981169ac9487e1d6ad6a",
"status": "affected",
"version": "06d3fdfcdf5cefb06f2024b9d3dad356779399cf",
"versionType": "git"
},
{
"lessThan": "069258d5111eed9ac9586bee42d03d38e2975715",
"status": "affected",
"version": "06d3fdfcdf5cefb06f2024b9d3dad356779399cf",
"versionType": "git"
},
{
"lessThan": "cefb44c367b2b52e50f97bc8526d39df9bcf5e60",
"status": "affected",
"version": "06d3fdfcdf5cefb06f2024b9d3dad356779399cf",
"versionType": "git"
},
{
"lessThan": "2363a757694752426fc47f3eadde15cf5f791fa5",
"status": "affected",
"version": "06d3fdfcdf5cefb06f2024b9d3dad356779399cf",
"versionType": "git"
},
{
"lessThan": "bf587a10c33e5571a299742e45bc18960b9912e7",
"status": "affected",
"version": "06d3fdfcdf5cefb06f2024b9d3dad356779399cf",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/bluetooth/hci_qca.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.6"
},
{
"lessThan": "6.6",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_qca: Clear memdump state on invalid dump size\n\nqca_controller_memdump() allocates qca-\u003eqca_memdump before processing\nthe first dump packet. For a sequence-zero packet it then disables IBS,\nmarks memdump collection active, and reads the advertised dump size.\n\nIf the controller reports a zero dump size, the error path frees the\nlocal qca_memdump object and returns without clearing qca-\u003eqca_memdump\nor undoing the collection state. A later memdump work item initializes\nits local pointer from qca-\u003eqca_memdump and skips allocation when that\npointer is non-NULL, so it can operate on freed memory. The stale\ncollection and IBS-disabled flags can also leave waiters or later\ntransmit handling blocked behind an aborted dump.\n\nClear the saved pointer and memdump state before returning from the\ninvalid-size path, matching the cleanup used when hci_devcd_init() fails.\n\nA static analysis checker reported the stale memdump state, and manual\nsource review confirmed the invalid-size failure path."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The vulnerable memdump packets arrive as QCA vendor HCI events (QCA_SSR_DUMP_HANDLE) emitted by the Bluetooth controller after a firmware crash/SSR, a state a nearby attacker induces or controls by attacking QCA controller firmware over the radio link, matching the CNA convention of scoring controller-event-driven Bluetooth driver bugs as Adjacent.\nAC:L - An attacker controlling the controller-to-host HCI stream deterministically triggers the flaw by sending a sequence-0 memdump packet with dump_size 0 followed by any further memdump packet; there is no race and no attacker-uncontrollable timing or memory-layout precondition.\nPR:N - No host credentials or authentication are needed: the memdump event is consumed unconditionally by qca_recv_event() on the driver receive path with no pairing, bonding, or capability check before qca_controller_memdump() runs.\nUI:N - SSR/memdump handling is fully automatic \u2014 qca_controller_memdump_event() queues the work item on receipt, so no local user has to open, mount, or confirm anything.\nS:U - The dangling pointer, use-after-free writes, and double free all occur in the host kernel\u0027s own heap and authority; no VM escape, IOMMU bypass, or sandbox boundary is crossed.\nC:H - The stale qca-\u003eqca_memdump gives a use-after-free on a kmalloc-16 object that an attacker can reclaim with another kernel allocation, and the freed fields (received_dump/ram_dump_size) then drive hci_devcd_append() length arithmetic, yielding attacker-influenced kernel memory disclosure per UAF exploitation.\nI:H - The reused freed object receives attacker-supplied 32-bit values (ram_dump_size straight from the packet, plus current_seq_no/received_dump) and is later kfree()d again, providing a controlled heap write and double-free primitive usable for arbitrary write and control-flow hijack.\nA:H - Beyond the use-after-free/double-free oops (KASAN slab-use-after-free), the uncleared QCA_MEMDUMP_COLLECTION and QCA_IBS_DISABLED flags leave wait_on_bit_timeout() waiters and the IBS transmit path stalled behind an aborted dump, persistently wedging the Bluetooth device."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:04:36.839Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/5a3945e8dea6c9a8ec9e981169ac9487e1d6ad6a"
},
{
"url": "https://git.kernel.org/stable/c/069258d5111eed9ac9586bee42d03d38e2975715"
},
{
"url": "https://git.kernel.org/stable/c/cefb44c367b2b52e50f97bc8526d39df9bcf5e60"
},
{
"url": "https://git.kernel.org/stable/c/2363a757694752426fc47f3eadde15cf5f791fa5"
},
{
"url": "https://git.kernel.org/stable/c/bf587a10c33e5571a299742e45bc18960b9912e7"
}
],
"title": "Bluetooth: hci_qca: Clear memdump state on invalid dump size",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68389",
"datePublished": "2026-08-10T12:04:08.306Z",
"dateReserved": "2026-07-30T09:28:09.388Z",
"dateUpdated": "2026-08-17T05:04:36.839Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68231 (GCVE-0-2026-68231)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: airspy: Return queued buffers on start_streaming() failure
The vb2 framework hands buffers to the driver via buf_queue() before
calling start_streaming(). If start_streaming() returns an error
without first returning those buffers via vb2_buffer_done(),
vb2_start_streaming() fires WARN_ON(owned_by_drv_count) and the queued
buffers leak.
airspy_start_streaming() returned -ENODEV early when the USB device had
been disconnected (s->udev == NULL) without returning any buffers that
buf_queue() had already accepted. Take v4l2_lock first and jump to the
existing err_clear_bit label, which already drains s->queued_bufs via
vb2_buffer_done(..., VB2_BUF_STATE_QUEUED) before unlocking.
This mirrors the uvcvideo fix in commit 4cf3b6fd54eb ("media: uvcvideo:
Return queued buffers on start_streaming() failure").
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 634fe5033951b80ef4b98d8f047cb1083d29170d Version: 634fe5033951b80ef4b98d8f047cb1083d29170d Version: 634fe5033951b80ef4b98d8f047cb1083d29170d Version: 634fe5033951b80ef4b98d8f047cb1083d29170d Version: 634fe5033951b80ef4b98d8f047cb1083d29170d Version: 634fe5033951b80ef4b98d8f047cb1083d29170d Version: 634fe5033951b80ef4b98d8f047cb1083d29170d Version: 634fe5033951b80ef4b98d8f047cb1083d29170d |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/usb/airspy/airspy.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "badceeb82a9d8d8e98d07859f3c89130ae1998b9",
"status": "affected",
"version": "634fe5033951b80ef4b98d8f047cb1083d29170d",
"versionType": "git"
},
{
"lessThan": "122ce0c0af629a8765ddf1adf6fb85c6db3d47cb",
"status": "affected",
"version": "634fe5033951b80ef4b98d8f047cb1083d29170d",
"versionType": "git"
},
{
"lessThan": "bcdf261c4c29077fc3da6449f7eda77357046205",
"status": "affected",
"version": "634fe5033951b80ef4b98d8f047cb1083d29170d",
"versionType": "git"
},
{
"lessThan": "877686a74ecdc93dcaee09dbac566e819059c9e7",
"status": "affected",
"version": "634fe5033951b80ef4b98d8f047cb1083d29170d",
"versionType": "git"
},
{
"lessThan": "cd42623d698b59f1fe5768f78a4101c28d5feb2e",
"status": "affected",
"version": "634fe5033951b80ef4b98d8f047cb1083d29170d",
"versionType": "git"
},
{
"lessThan": "73bd2779865372b1017d4f555b45270aa2d0d710",
"status": "affected",
"version": "634fe5033951b80ef4b98d8f047cb1083d29170d",
"versionType": "git"
},
{
"lessThan": "170fcc945bc094b1c956bf555c070692826a3eff",
"status": "affected",
"version": "634fe5033951b80ef4b98d8f047cb1083d29170d",
"versionType": "git"
},
{
"lessThan": "04344d0b4929caa94c0df72f767752aa0935ef5d",
"status": "affected",
"version": "634fe5033951b80ef4b98d8f047cb1083d29170d",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/usb/airspy/airspy.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.17"
},
{
"lessThan": "3.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.17",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: airspy: Return queued buffers on start_streaming() failure\n\nThe vb2 framework hands buffers to the driver via buf_queue() before\ncalling start_streaming(). If start_streaming() returns an error\nwithout first returning those buffers via vb2_buffer_done(),\nvb2_start_streaming() fires WARN_ON(owned_by_drv_count) and the queued\nbuffers leak.\n\nairspy_start_streaming() returned -ENODEV early when the USB device had\nbeen disconnected (s-\u003eudev == NULL) without returning any buffers that\nbuf_queue() had already accepted. Take v4l2_lock first and jump to the\nexisting err_clear_bit label, which already drains s-\u003equeued_bufs via\nvb2_buffer_done(..., VB2_BUF_STATE_QUEUED) before unlocking.\n\nThis mirrors the uvcvideo fix in commit 4cf3b6fd54eb (\"media: uvcvideo:\nReturn queued buffers on start_streaming() failure\")."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:32:04.017Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/badceeb82a9d8d8e98d07859f3c89130ae1998b9"
},
{
"url": "https://git.kernel.org/stable/c/122ce0c0af629a8765ddf1adf6fb85c6db3d47cb"
},
{
"url": "https://git.kernel.org/stable/c/bcdf261c4c29077fc3da6449f7eda77357046205"
},
{
"url": "https://git.kernel.org/stable/c/877686a74ecdc93dcaee09dbac566e819059c9e7"
},
{
"url": "https://git.kernel.org/stable/c/cd42623d698b59f1fe5768f78a4101c28d5feb2e"
},
{
"url": "https://git.kernel.org/stable/c/73bd2779865372b1017d4f555b45270aa2d0d710"
},
{
"url": "https://git.kernel.org/stable/c/170fcc945bc094b1c956bf555c070692826a3eff"
},
{
"url": "https://git.kernel.org/stable/c/04344d0b4929caa94c0df72f767752aa0935ef5d"
}
],
"title": "media: airspy: Return queued buffers on start_streaming() failure",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68231",
"datePublished": "2026-08-10T12:00:54.801Z",
"dateReserved": "2026-07-30T09:28:09.376Z",
"dateUpdated": "2026-08-19T16:32:04.017Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68160 (GCVE-0-2026-68160)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps()
ceph_handle_caps() reads snap_trace_len from the wire-format
ceph_mds_caps header and uses it unconditionally to build a fake
end pointer (snaptrace + snaptrace_len) that is later handed to
ceph_update_snap_trace() in the CEPH_CAP_OP_IMPORT case:
snaptrace = h + 1;
snaptrace_len = le32_to_cpu(h->snap_trace_len);
p = snaptrace + snaptrace_len;
...
case CEPH_CAP_OP_IMPORT:
if (snaptrace_len) {
...
if (ceph_update_snap_trace(mdsc, snaptrace,
snaptrace + snaptrace_len,
false, &realm)) { ... }
ceph_update_snap_trace() then decodes a struct ceph_mds_snap_realm
from snaptrace using ceph_decode_need(&p, e, sizeof(*ri), bad)
with the attacker-supplied fake end e == snaptrace + snaptrace_len.
With snaptrace_len == 0xFFFFFFFF the bound check is trivially
satisfied, ri = p reads sizeof(struct ceph_mds_snap_realm) past
the legitimate msg->front buffer, and ri->num_snaps /
ri->num_prior_parent_snaps then drive further out-of-bounds
reads of the encoded snap arrays.
The eleven msg_version >= 2 .. msg_version >= 12 decoder blocks
above the op switch each catch this OOB through their
ceph_decode_*_safe() / ceph_decode_need() helpers, but they sit
behind a hdr.version-gated if, so a malicious or compromised
MDS that sets msg->hdr.version = 1 reaches the IMPORT path with
no version-gated decoder having validated snap_trace_len. The
shape has been present since ceph_handle_caps() was introduced.
Validate snap_trace_len against the message front buffer before
consuming it, using the canonical ceph_decode_need() / ceph_has_room()
helper. The helper bounds the length with subtraction (n <= end - p,
guarded by end >= p) rather than pointer addition, so it is wrap-safe
for the attacker-controlled u32 length on 32-bit builds where
p + snap_trace_len could overflow the address space. This matches the
rest of the ceph decode path (e.g. the pool_ns_len check a few lines
below), and the existing goto bad cleanup already covers this exit
path.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: a8599bd821d084d04a3290fffae1071624ec00ea Version: a8599bd821d084d04a3290fffae1071624ec00ea Version: a8599bd821d084d04a3290fffae1071624ec00ea Version: a8599bd821d084d04a3290fffae1071624ec00ea Version: a8599bd821d084d04a3290fffae1071624ec00ea Version: a8599bd821d084d04a3290fffae1071624ec00ea Version: a8599bd821d084d04a3290fffae1071624ec00ea Version: a8599bd821d084d04a3290fffae1071624ec00ea |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/ceph/caps.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "f913192fc782288e060dafc329b2346934be34cc",
"status": "affected",
"version": "a8599bd821d084d04a3290fffae1071624ec00ea",
"versionType": "git"
},
{
"lessThan": "0c011137194036424e974677e0f1592e22a33d8c",
"status": "affected",
"version": "a8599bd821d084d04a3290fffae1071624ec00ea",
"versionType": "git"
},
{
"lessThan": "cc93f68a31c9b831abf2db8647b5f5b10329d793",
"status": "affected",
"version": "a8599bd821d084d04a3290fffae1071624ec00ea",
"versionType": "git"
},
{
"lessThan": "9081c71796724ffe96cba253f68fbe42363c5295",
"status": "affected",
"version": "a8599bd821d084d04a3290fffae1071624ec00ea",
"versionType": "git"
},
{
"lessThan": "03b417afce19ee6b6e61f1bbbbebac924c9f36d1",
"status": "affected",
"version": "a8599bd821d084d04a3290fffae1071624ec00ea",
"versionType": "git"
},
{
"lessThan": "a4228b93706fb74a484e6ffb271c1cc2af3a2ddb",
"status": "affected",
"version": "a8599bd821d084d04a3290fffae1071624ec00ea",
"versionType": "git"
},
{
"lessThan": "71893c342a26bcff92eaab0b2b75d64aed19308a",
"status": "affected",
"version": "a8599bd821d084d04a3290fffae1071624ec00ea",
"versionType": "git"
},
{
"lessThan": "4dbc71bcaf9a30abf3920a4e2cc4ed33bba78c02",
"status": "affected",
"version": "a8599bd821d084d04a3290fffae1071624ec00ea",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/ceph/caps.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.34"
},
{
"lessThan": "2.6.34",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.34",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps()\n\nceph_handle_caps() reads snap_trace_len from the wire-format\nceph_mds_caps header and uses it unconditionally to build a fake\nend pointer (snaptrace + snaptrace_len) that is later handed to\nceph_update_snap_trace() in the CEPH_CAP_OP_IMPORT case:\n\n snaptrace = h + 1;\n snaptrace_len = le32_to_cpu(h-\u003esnap_trace_len);\n p = snaptrace + snaptrace_len;\n ...\n case CEPH_CAP_OP_IMPORT:\n if (snaptrace_len) {\n ...\n if (ceph_update_snap_trace(mdsc, snaptrace,\n snaptrace + snaptrace_len,\n false, \u0026realm)) { ... }\n\nceph_update_snap_trace() then decodes a struct ceph_mds_snap_realm\nfrom snaptrace using ceph_decode_need(\u0026p, e, sizeof(*ri), bad)\nwith the attacker-supplied fake end e == snaptrace + snaptrace_len.\nWith snaptrace_len == 0xFFFFFFFF the bound check is trivially\nsatisfied, ri = p reads sizeof(struct ceph_mds_snap_realm) past\nthe legitimate msg-\u003efront buffer, and ri-\u003enum_snaps /\nri-\u003enum_prior_parent_snaps then drive further out-of-bounds\nreads of the encoded snap arrays.\n\nThe eleven msg_version \u003e= 2 .. msg_version \u003e= 12 decoder blocks\nabove the op switch each catch this OOB through their\nceph_decode_*_safe() / ceph_decode_need() helpers, but they sit\nbehind a hdr.version-gated if, so a malicious or compromised\nMDS that sets msg-\u003ehdr.version = 1 reaches the IMPORT path with\nno version-gated decoder having validated snap_trace_len. The\nshape has been present since ceph_handle_caps() was introduced.\n\nValidate snap_trace_len against the message front buffer before\nconsuming it, using the canonical ceph_decode_need() / ceph_has_room()\nhelper. The helper bounds the length with subtraction (n \u003c= end - p,\nguarded by end \u003e= p) rather than pointer addition, so it is wrap-safe\nfor the attacker-controlled u32 length on 32-bit builds where\np + snap_trace_len could overflow the address space. This matches the\nrest of the ceph decode path (e.g. the pool_ns_len check a few lines\nbelow), and the existing goto bad cleanup already covers this exit\npath."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - CEPH_MSG_CLIENT_CAPS is received over the kernel Ceph messenger TCP connection from an MDS peer; mds_dispatch() passes it directly to ceph_handle_caps(), so a malicious or compromised MDS (or on-path attacker on an unsigned msgr session) reaches the bug with network data alone.\nAC:L - The attacker fully controls msg-\u003ehdr.version and snap_trace_len in the caps header; setting version=1 bypasses all version-gated decoders and snap_trace_len=0xFFFFFFFF yields a fake end pointer that reliably defeats ceph_decode_need(), with no race or memory-layout dependency.\nPR:N - Exploitation requires only the ability to send crafted caps messages as the remote MDS peer on an established session; the attacker needs no account, mount privilege, or other credentials on the victim host beyond the client already being connected to that cluster.\nUI:N - Once CephFS is mounted and the MDS session is open, CEPH_CAP_OP_IMPORT caps messages are delivered and processed automatically during normal cap migration and MDS failover; no additional local user action is needed at exploit time beyond prior cluster connectivity.\nS:U - The out-of-bounds read and resulting snap-realm corruption affect only the kernel CephFS client\u2019s internal state within the same kernel security authority; there is no VM escape, sandbox breakout, or cross-authority boundary crossing.\nC:H - ceph_update_snap_trace() decodes struct ceph_mds_snap_realm and snap arrays using an attacker-supplied fake end pointer, reading sizeof(*ri) and further attacker-influenced extents past the legitimate msg-\u003efront buffer into adjacent kernel memory without copying to userspace.\nI:H - Out-of-bounds kernel memory is interpreted as snap-realm metadata and copied via dup_array() into newly allocated kernel heap structures (realm-\u003esnaps, realm-\u003eprior_parent_snaps), corrupting authoritative snap state and providing a memory-corruption primitive that could be leveraged for further kernel compromise.\nA:H - Out-of-bounds reads can fault on unmapped pages causing a kernel oops; the ceph_update_snap_trace() error path issues WARN(1), fences I/O via CEPH_MOUNT_FENCE_IO, and can close all MDS sessions\u2014effects an attacker can trigger repeatedly at will."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:30:32.455Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/f913192fc782288e060dafc329b2346934be34cc"
},
{
"url": "https://git.kernel.org/stable/c/0c011137194036424e974677e0f1592e22a33d8c"
},
{
"url": "https://git.kernel.org/stable/c/cc93f68a31c9b831abf2db8647b5f5b10329d793"
},
{
"url": "https://git.kernel.org/stable/c/9081c71796724ffe96cba253f68fbe42363c5295"
},
{
"url": "https://git.kernel.org/stable/c/03b417afce19ee6b6e61f1bbbbebac924c9f36d1"
},
{
"url": "https://git.kernel.org/stable/c/a4228b93706fb74a484e6ffb271c1cc2af3a2ddb"
},
{
"url": "https://git.kernel.org/stable/c/71893c342a26bcff92eaab0b2b75d64aed19308a"
},
{
"url": "https://git.kernel.org/stable/c/4dbc71bcaf9a30abf3920a4e2cc4ed33bba78c02"
}
],
"title": "ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68160",
"datePublished": "2026-08-10T11:59:26.741Z",
"dateReserved": "2026-07-30T09:28:09.371Z",
"dateUpdated": "2026-08-19T16:30:32.455Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68223 (GCVE-0-2026-68223)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: meson: vdec: Fix memory leak in error path of vdec_open
The vdec_open() function previously jumped directly to
err_m2m_release when vdec_init_ctrls() failed, skipping
release of the m2m context. This caused a resource leak.
Fix it by introducing a proper err_m2m_ctx_release label
that calls v4l2_m2m_ctx_release(sess->m2m_ctx) before
releasing the m2m device.
This was identified via kmemleak:
unreferenced object 0xffff0000205d6878 (size 8):
comm "v4l_id", pid 5289, jiffies 4294938580
hex dump (first 8 bytes):
40 d2 49 18 00 00 ff ff @.I.....
backtrace (crc d3204599):
kmemleak_alloc+0xc8/0xf0
__kvmalloc_node_noprof+0x60c/0x850
v4l2_ctrl_handler_init_class+0x1b4/0x2e8 [videodev]
vdec_open+0x1f4/0x788 [meson_vdec]
v4l2_open+0x144/0x460 [videodev]
chrdev_open+0x1ac/0x500
do_dentry_open+0x3f0/0xfe8
vfs_open+0x68/0x320
do_open+0x2d8/0x9a8
path_openat+0x1d0/0x4f0
do_filp_open+0x190/0x380
do_sys_openat2+0xf8/0x1b0
__arm64_sys_openat+0x13c/0x1e8
invoke_syscall+0xdc/0x268
el0_svc_common.constprop.0+0x178/0x258
do_el0_svc+0x4c/0x70
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 3e7f51bd96077acad6acd7b45668f65b44233c4e Version: 3e7f51bd96077acad6acd7b45668f65b44233c4e Version: 3e7f51bd96077acad6acd7b45668f65b44233c4e Version: 3e7f51bd96077acad6acd7b45668f65b44233c4e Version: 3e7f51bd96077acad6acd7b45668f65b44233c4e Version: 3e7f51bd96077acad6acd7b45668f65b44233c4e Version: 3e7f51bd96077acad6acd7b45668f65b44233c4e Version: 3e7f51bd96077acad6acd7b45668f65b44233c4e |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/staging/media/meson/vdec/vdec.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "5f97120d1a50c9efffe54425fac42bb7ef13ac86",
"status": "affected",
"version": "3e7f51bd96077acad6acd7b45668f65b44233c4e",
"versionType": "git"
},
{
"lessThan": "fb77d6f4580f316c9148b942af0028ee489d121e",
"status": "affected",
"version": "3e7f51bd96077acad6acd7b45668f65b44233c4e",
"versionType": "git"
},
{
"lessThan": "d9058a19731036c03a779bfe8c3ca0d9aa198599",
"status": "affected",
"version": "3e7f51bd96077acad6acd7b45668f65b44233c4e",
"versionType": "git"
},
{
"lessThan": "c6cd08a71a630f19b10c318e76e3c56e1dd10e00",
"status": "affected",
"version": "3e7f51bd96077acad6acd7b45668f65b44233c4e",
"versionType": "git"
},
{
"lessThan": "2cf0171ad594860e31723c671e37824ce12c01ea",
"status": "affected",
"version": "3e7f51bd96077acad6acd7b45668f65b44233c4e",
"versionType": "git"
},
{
"lessThan": "1391b75bf0119b5d37f1c1c3078d452a01967f9b",
"status": "affected",
"version": "3e7f51bd96077acad6acd7b45668f65b44233c4e",
"versionType": "git"
},
{
"lessThan": "99f3527bd1a27ff798d59177ed045b0dd87deaef",
"status": "affected",
"version": "3e7f51bd96077acad6acd7b45668f65b44233c4e",
"versionType": "git"
},
{
"lessThan": "940f161f734b25f175a95d2684c2021f6323693a",
"status": "affected",
"version": "3e7f51bd96077acad6acd7b45668f65b44233c4e",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/staging/media/meson/vdec/vdec.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.3"
},
{
"lessThan": "5.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: meson: vdec: Fix memory leak in error path of vdec_open\n\nThe vdec_open() function previously jumped directly to\nerr_m2m_release when vdec_init_ctrls() failed, skipping\nrelease of the m2m context. This caused a resource leak.\n\nFix it by introducing a proper err_m2m_ctx_release label\nthat calls v4l2_m2m_ctx_release(sess-\u003em2m_ctx) before\nreleasing the m2m device.\n\nThis was identified via kmemleak:\nunreferenced object 0xffff0000205d6878 (size 8):\n comm \"v4l_id\", pid 5289, jiffies 4294938580\n hex dump (first 8 bytes):\n 40 d2 49 18 00 00 ff ff @.I.....\n backtrace (crc d3204599):\n kmemleak_alloc+0xc8/0xf0\n __kvmalloc_node_noprof+0x60c/0x850\n v4l2_ctrl_handler_init_class+0x1b4/0x2e8 [videodev]\n vdec_open+0x1f4/0x788 [meson_vdec]\n v4l2_open+0x144/0x460 [videodev]\n chrdev_open+0x1ac/0x500\n do_dentry_open+0x3f0/0xfe8\n vfs_open+0x68/0x320\n do_open+0x2d8/0x9a8\n path_openat+0x1d0/0x4f0\n do_filp_open+0x190/0x380\n do_sys_openat2+0xf8/0x1b0\n __arm64_sys_openat+0x13c/0x1e8\n invoke_syscall+0xdc/0x268\n el0_svc_common.constprop.0+0x178/0x258\n do_el0_svc+0x4c/0x70"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:54.081Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/5f97120d1a50c9efffe54425fac42bb7ef13ac86"
},
{
"url": "https://git.kernel.org/stable/c/fb77d6f4580f316c9148b942af0028ee489d121e"
},
{
"url": "https://git.kernel.org/stable/c/d9058a19731036c03a779bfe8c3ca0d9aa198599"
},
{
"url": "https://git.kernel.org/stable/c/c6cd08a71a630f19b10c318e76e3c56e1dd10e00"
},
{
"url": "https://git.kernel.org/stable/c/2cf0171ad594860e31723c671e37824ce12c01ea"
},
{
"url": "https://git.kernel.org/stable/c/1391b75bf0119b5d37f1c1c3078d452a01967f9b"
},
{
"url": "https://git.kernel.org/stable/c/99f3527bd1a27ff798d59177ed045b0dd87deaef"
},
{
"url": "https://git.kernel.org/stable/c/940f161f734b25f175a95d2684c2021f6323693a"
}
],
"title": "media: meson: vdec: Fix memory leak in error path of vdec_open",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68223",
"datePublished": "2026-08-10T12:00:44.123Z",
"dateReserved": "2026-07-30T09:28:09.375Z",
"dateUpdated": "2026-08-19T16:31:54.081Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68335 (GCVE-0-2026-68335)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
rds: drop incoming messages that cross network namespace boundaries
rds_find_bound() looks up the destination socket using a global
rhashtable keyed solely on (addr, port, scope_id). Network namespaces
are not part of the key, so a sender in netns A can deliver an incoming
message (inc) to a socket that lives in a different netns B.
When this happens, inc->i_conn points to an rds_connection whose c_net
is netns A, but the receiving rs lives in netns B. Once the child
process that created netns A exits, cleanup_net() calls
rds_loop_exit_net() -> rds_loop_kill_conns() -> rds_conn_destroy(),
freeing that connection. If the survivor socket in netns B still holds
the inc, any subsequent dereference of inc->i_conn is a use-after-free.
There are two dangerous sites in rds_clear_recv_queue():
1. inc->i_conn->c_lcong (offset 88 of freed rds_connection, size 200)
read via rds_recv_rcvbuf_delta() -- confirmed by KASAN.
2. inc->i_conn->c_trans->inc_free(inc) (function pointer at offset 80)
called via rds_inc_put() when the inc refcount reaches zero -- same
race window, potential call-through-freed-object primitive.
The bug is reachable from unprivileged user namespaces
(CLONE_NEWUSER + CLONE_NEWNET), available since Linux 3.8.
Fix this by rejecting the delivery in rds_recv_incoming() when the
socket returned by rds_find_bound() belongs to a different network
namespace than the connection that carried the message. Use the
existing rds_conn_net() / sock_net() helpers and net_eq() for the
comparison.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: c809195f5523dd4d09403bbb1c9732d548aa0d1e Version: c809195f5523dd4d09403bbb1c9732d548aa0d1e Version: c809195f5523dd4d09403bbb1c9732d548aa0d1e Version: c809195f5523dd4d09403bbb1c9732d548aa0d1e Version: c809195f5523dd4d09403bbb1c9732d548aa0d1e Version: c809195f5523dd4d09403bbb1c9732d548aa0d1e Version: c809195f5523dd4d09403bbb1c9732d548aa0d1e Version: c809195f5523dd4d09403bbb1c9732d548aa0d1e Version: c827073c95fde388bc65fe5227f944eaf859b9f0 Version: 4.17.19 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/rds/recv.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "742ff6f02545212e991cd8b45011e40d2c2ef25a",
"status": "affected",
"version": "c809195f5523dd4d09403bbb1c9732d548aa0d1e",
"versionType": "git"
},
{
"lessThan": "abff41fd928328bbf3dda1140beb2e61fa424ccd",
"status": "affected",
"version": "c809195f5523dd4d09403bbb1c9732d548aa0d1e",
"versionType": "git"
},
{
"lessThan": "03c574112e5d066df0ddce36d7438e850bcf3050",
"status": "affected",
"version": "c809195f5523dd4d09403bbb1c9732d548aa0d1e",
"versionType": "git"
},
{
"lessThan": "1e2e2d9806944fe485824d617c8b7c78116c22db",
"status": "affected",
"version": "c809195f5523dd4d09403bbb1c9732d548aa0d1e",
"versionType": "git"
},
{
"lessThan": "cfb3ce07b705e486e022a2f2b1242b48f13981ff",
"status": "affected",
"version": "c809195f5523dd4d09403bbb1c9732d548aa0d1e",
"versionType": "git"
},
{
"lessThan": "9591042533140dfe6608d9344806d567dcd39d02",
"status": "affected",
"version": "c809195f5523dd4d09403bbb1c9732d548aa0d1e",
"versionType": "git"
},
{
"lessThan": "0f8690e3869109cd5803ccb400889d20a0b54e0e",
"status": "affected",
"version": "c809195f5523dd4d09403bbb1c9732d548aa0d1e",
"versionType": "git"
},
{
"lessThan": "5521ae71e32a8069ed4ca6e792179dc57bc43ab2",
"status": "affected",
"version": "c809195f5523dd4d09403bbb1c9732d548aa0d1e",
"versionType": "git"
},
{
"status": "affected",
"version": "c827073c95fde388bc65fe5227f944eaf859b9f0",
"versionType": "git"
},
{
"lessThan": "4.18",
"status": "affected",
"version": "4.17.19",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/rds/recv.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.18"
},
{
"lessThan": "4.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.17.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nrds: drop incoming messages that cross network namespace boundaries\n\nrds_find_bound() looks up the destination socket using a global\nrhashtable keyed solely on (addr, port, scope_id). Network namespaces\nare not part of the key, so a sender in netns A can deliver an incoming\nmessage (inc) to a socket that lives in a different netns B.\n\nWhen this happens, inc-\u003ei_conn points to an rds_connection whose c_net\nis netns A, but the receiving rs lives in netns B. Once the child\nprocess that created netns A exits, cleanup_net() calls\nrds_loop_exit_net() -\u003e rds_loop_kill_conns() -\u003e rds_conn_destroy(),\nfreeing that connection. If the survivor socket in netns B still holds\nthe inc, any subsequent dereference of inc-\u003ei_conn is a use-after-free.\n\nThere are two dangerous sites in rds_clear_recv_queue():\n 1. inc-\u003ei_conn-\u003ec_lcong (offset 88 of freed rds_connection, size 200)\n read via rds_recv_rcvbuf_delta() -- confirmed by KASAN.\n 2. inc-\u003ei_conn-\u003ec_trans-\u003einc_free(inc) (function pointer at offset 80)\n called via rds_inc_put() when the inc refcount reaches zero -- same\n race window, potential call-through-freed-object primitive.\n\nThe bug is reachable from unprivileged user namespaces\n(CLONE_NEWUSER + CLONE_NEWNET), available since Linux 3.8.\n\nFix this by rejecting the delivery in rds_recv_incoming() when the\nsocket returned by rds_find_bound() belongs to a different network\nnamespace than the connection that carried the message. Use the\nexisting rds_conn_net() / sock_net() helpers and net_eq() for the\ncomparison."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires local syscall access: the attacker must create RDS sockets and a network namespace (CLONE_NEWUSER|CLONE_NEWNET), then trigger namespace teardown to free the connection. A remote RDS peer cannot drive the netns-destruction half of the sequence, so the vulnerability is reachable only locally.\nAC:L - The attacker controls the entire sequence deterministically \u2014 bind a socket in one netns, send a loopback RDS message from a second netns so the inc is queued cross-netns, then exit that netns to free inc-\u003ei_conn. No race must be won and no uncontrollable precondition exists; the UAF is confirmed reproducible under KASAN.\nPR:L - Only an unprivileged local user account is required; the needed CAP_NET_ADMIN for creating and configuring the second network namespace is obtained inside a user namespace the attacker owns, as the commit explicitly notes (\"reachable from unprivileged user namespaces\").\nUI:N - The attacker performs every step \u2014 socket creation, cross-netns send, namespace teardown, and the subsequent read/close that dereferences the freed connection \u2014 with no action from any other user or administrator.\nS:U - The use-after-free corrupts kernel memory within the same kernel security authority; there is no crossing of a hypervisor, IOMMU, or comparable trust boundary.\nC:H - The stale inc-\u003ei_conn is dereferenced to read c_lcong from a freed 200-byte rds_connection, and the freed slot can be reclaimed with attacker-groomed data, giving a use-after-free read primitive usable to disclose kernel memory contents.\nI:H - rds_inc_put() calls inc-\u003ei_conn-\u003ec_trans-\u003einc_free(inc) through a function pointer at offset 80 of the freed object \u2014 an indirect call through freed memory that the commit calls a \"call-through-freed-object primitive\", which after heap reclamation is a control-flow hijack path leading to arbitrary kernel modification.\nA:H - Dereferencing the freed rds_connection in rds_clear_recv_queue() and calling through its freed transport vtable reliably corrupts kernel state and panics the machine (KASAN-confirmed use-after-free), causing a full denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:33.100Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/742ff6f02545212e991cd8b45011e40d2c2ef25a"
},
{
"url": "https://git.kernel.org/stable/c/abff41fd928328bbf3dda1140beb2e61fa424ccd"
},
{
"url": "https://git.kernel.org/stable/c/03c574112e5d066df0ddce36d7438e850bcf3050"
},
{
"url": "https://git.kernel.org/stable/c/1e2e2d9806944fe485824d617c8b7c78116c22db"
},
{
"url": "https://git.kernel.org/stable/c/cfb3ce07b705e486e022a2f2b1242b48f13981ff"
},
{
"url": "https://git.kernel.org/stable/c/9591042533140dfe6608d9344806d567dcd39d02"
},
{
"url": "https://git.kernel.org/stable/c/0f8690e3869109cd5803ccb400889d20a0b54e0e"
},
{
"url": "https://git.kernel.org/stable/c/5521ae71e32a8069ed4ca6e792179dc57bc43ab2"
}
],
"title": "rds: drop incoming messages that cross network namespace boundaries",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68335",
"datePublished": "2026-08-10T12:03:11.547Z",
"dateReserved": "2026-07-30T09:28:09.383Z",
"dateUpdated": "2026-08-19T16:33:33.100Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64583 (GCVE-0-2026-64583)
Vulnerability from cvelistv5
Published
2026-08-06 07:06
Modified
2026-08-23 12:45
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown
The Broadcom BDC UDC driver registers its IRQ handler with
devm_request_irq() in bdc_udc_init(), so the IRQ is released by devm
only after bdc_remove() returns. devm releases resources in reverse
LIFO order, but bdc_remove() runs bdc_udc_exit() and bdc_hw_exit() ->
bdc_mem_free() manually before returning: bdc_udc_exit() tears down
individual endpoint objects via bdc_free_ep(), while bdc_hw_exit() ->
bdc_mem_free() frees and NULLs the DMA-coherent status-report ring
(bdc->srr.sr_bds) and kfree()s bdc->bdc_ep_array. Both happen while
the IRQ handler (bdc_udc_interrupt, requested with IRQF_SHARED)
remains deliverable in the window up to the post-remove devm
free_irq().
On receipt of a shared interrupt in that window, bdc_udc_interrupt()
dereferences bdc->srr.sr_bds[bdc->srr.dqp_index] (NULL or freed DMA)
and dispatches sr_handler callbacks that index into bdc_ep_array,
causing a NULL-deref or use-after-free.
The same window affects the delayed_work bdc->func_wake_notify, which is
armed from the IRQ handler via bdc_sr_uspc() -> handle_link_state_change()
-> schedule_delayed_work() and may self-rearm from its own callback
bdc_func_wake_timer(). No cancel exists anywhere in the driver, so a
queued work item that fires after bdc_remove() returns and the bdc
structure is devm-freed dereferences freed memory.
Replace devm_request_irq() with request_irq() and add an explicit
free_irq(bdc->irq, bdc) in bdc_remove(). Clear BDC_GIE before
free_irq() to stop the device from asserting interrupts, then
free_irq() drains any in-flight handler, then cancel_delayed_work_sync()
drains the func_wake_notify delayed work. This ordering ensures the
IRQ handler and delayed work cannot interfere with the subsequent
endpoint and DMA teardown in bdc_udc_exit() and bdc_hw_exit(). Wire the
matching free_irq() into the bdc_udc_init() error path so the IRQ is
released on probe failure, and route the bdc_init_ep() failure through
err0 instead of returning directly.
This issue was found by an in-house static analysis tool.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: efed421a94e62a7ddbc76acba4312b70e4be958f Version: efed421a94e62a7ddbc76acba4312b70e4be958f Version: efed421a94e62a7ddbc76acba4312b70e4be958f Version: efed421a94e62a7ddbc76acba4312b70e4be958f Version: efed421a94e62a7ddbc76acba4312b70e4be958f Version: efed421a94e62a7ddbc76acba4312b70e4be958f Version: efed421a94e62a7ddbc76acba4312b70e4be958f Version: efed421a94e62a7ddbc76acba4312b70e4be958f |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/gadget/udc/bdc/bdc_core.c",
"drivers/usb/gadget/udc/bdc/bdc_udc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "eac1107e54679db2df2c36d8bba3b66d3ab6cbcd",
"status": "affected",
"version": "efed421a94e62a7ddbc76acba4312b70e4be958f",
"versionType": "git"
},
{
"lessThan": "0b0b76e31b3991a899ae724eb97d359de0c0f1b1",
"status": "affected",
"version": "efed421a94e62a7ddbc76acba4312b70e4be958f",
"versionType": "git"
},
{
"lessThan": "3fe181952b8a1aeb167d4503c794c0f5050f08ed",
"status": "affected",
"version": "efed421a94e62a7ddbc76acba4312b70e4be958f",
"versionType": "git"
},
{
"lessThan": "1a1d7158420df6b8fa1efc0cdd6ab704801a4fc8",
"status": "affected",
"version": "efed421a94e62a7ddbc76acba4312b70e4be958f",
"versionType": "git"
},
{
"lessThan": "f6fc21ec7ccd83726ba766d73d0b8cc03e726475",
"status": "affected",
"version": "efed421a94e62a7ddbc76acba4312b70e4be958f",
"versionType": "git"
},
{
"lessThan": "dcf3e2f164435b5844706cb8eefef29ebee0eedb",
"status": "affected",
"version": "efed421a94e62a7ddbc76acba4312b70e4be958f",
"versionType": "git"
},
{
"lessThan": "d4964a74717107697999f48bcb4e80a9c0679a27",
"status": "affected",
"version": "efed421a94e62a7ddbc76acba4312b70e4be958f",
"versionType": "git"
},
{
"lessThan": "0583f2fbf8f86ae3a0ce054f96783dd83e65d9bb",
"status": "affected",
"version": "efed421a94e62a7ddbc76acba4312b70e4be958f",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/usb/gadget/udc/bdc/bdc_core.c",
"drivers/usb/gadget/udc/bdc/bdc_udc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.19"
},
{
"lessThan": "3.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown\n\nThe Broadcom BDC UDC driver registers its IRQ handler with\ndevm_request_irq() in bdc_udc_init(), so the IRQ is released by devm\nonly after bdc_remove() returns. devm releases resources in reverse\nLIFO order, but bdc_remove() runs bdc_udc_exit() and bdc_hw_exit() -\u003e\nbdc_mem_free() manually before returning: bdc_udc_exit() tears down\nindividual endpoint objects via bdc_free_ep(), while bdc_hw_exit() -\u003e\nbdc_mem_free() frees and NULLs the DMA-coherent status-report ring\n(bdc-\u003esrr.sr_bds) and kfree()s bdc-\u003ebdc_ep_array. Both happen while\nthe IRQ handler (bdc_udc_interrupt, requested with IRQF_SHARED)\nremains deliverable in the window up to the post-remove devm\nfree_irq().\n\nOn receipt of a shared interrupt in that window, bdc_udc_interrupt()\ndereferences bdc-\u003esrr.sr_bds[bdc-\u003esrr.dqp_index] (NULL or freed DMA)\nand dispatches sr_handler callbacks that index into bdc_ep_array,\ncausing a NULL-deref or use-after-free.\n\nThe same window affects the delayed_work bdc-\u003efunc_wake_notify, which is\narmed from the IRQ handler via bdc_sr_uspc() -\u003e handle_link_state_change()\n-\u003e schedule_delayed_work() and may self-rearm from its own callback\nbdc_func_wake_timer(). No cancel exists anywhere in the driver, so a\nqueued work item that fires after bdc_remove() returns and the bdc\nstructure is devm-freed dereferences freed memory.\n\nReplace devm_request_irq() with request_irq() and add an explicit\nfree_irq(bdc-\u003eirq, bdc) in bdc_remove(). Clear BDC_GIE before\nfree_irq() to stop the device from asserting interrupts, then\nfree_irq() drains any in-flight handler, then cancel_delayed_work_sync()\ndrains the func_wake_notify delayed work. This ordering ensures the\nIRQ handler and delayed work cannot interfere with the subsequent\nendpoint and DMA teardown in bdc_udc_exit() and bdc_hw_exit(). Wire the\nmatching free_irq() into the bdc_udc_init() error path so the IRQ is\nreleased on probe failure, and route the bdc_init_ep() failure through\nerr0 instead of returning directly.\n\nThis issue was found by an in-house static analysis tool."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable window opens on local BDC platform-driver teardown (sysfs unbind/rmmod \u2192 bdc_remove), not on parsing USB host packets; that matches other USB gadget/UDC teardown UAFs scored AV:L and is higher severity than Physical.\nAC:L - The attacker controls remove/bind retries; a pending func_wake_notify (never cancelled before the fix) runs deterministically on the post-remove freed bdc, and IRQF_SHARED plus USB activity can also hit the IRQ window during teardown.\nPR:L - Highest reasonable exposure is a local account managing the gadget/UDC on Android or Broadcom STB systems where platform unbind is delegated beyond init-namespace root; uncertain Low vs High, so Low per the overestimate rule.\nUI:N - The attacker performs driver remove and any prior link-state activity that arms func_wake_notify themselves; no separate victim mount, open, or other interaction is required.\nS:U - NULL-deref/use-after-free of sr_bds, bdc_ep_array, and the delayed-work bdc object stays inside the host kernel authority and does not cross a VM, IOMMU, or sandbox boundary.\nC:H - Use-after-free of the DMA status-report ring, endpoint array, and the bdc object via IRQ/work handlers allows reclaim/spray and disclosure of kernel memory, which per UAF guidance is High.\nI:H - The same UAF paths write through freed endpoint/status structures and run delayed work on a freed bdc, enabling heap corruption and control-flow hijack suitable for privilege escalation.\nA:H - Dereferencing NULL/freed sr_bds in hard-IRQ context or executing bdc_func_wake_timer on a post-remove freed bdc causes kernel oops/panic, so availability impact is High."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:45:42.500Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/eac1107e54679db2df2c36d8bba3b66d3ab6cbcd"
},
{
"url": "https://git.kernel.org/stable/c/0b0b76e31b3991a899ae724eb97d359de0c0f1b1"
},
{
"url": "https://git.kernel.org/stable/c/3fe181952b8a1aeb167d4503c794c0f5050f08ed"
},
{
"url": "https://git.kernel.org/stable/c/1a1d7158420df6b8fa1efc0cdd6ab704801a4fc8"
},
{
"url": "https://git.kernel.org/stable/c/f6fc21ec7ccd83726ba766d73d0b8cc03e726475"
},
{
"url": "https://git.kernel.org/stable/c/dcf3e2f164435b5844706cb8eefef29ebee0eedb"
},
{
"url": "https://git.kernel.org/stable/c/d4964a74717107697999f48bcb4e80a9c0679a27"
},
{
"url": "https://git.kernel.org/stable/c/0583f2fbf8f86ae3a0ce054f96783dd83e65d9bb"
}
],
"title": "usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64583",
"datePublished": "2026-08-06T07:06:25.335Z",
"dateReserved": "2026-07-19T15:36:31.798Z",
"dateUpdated": "2026-08-23T12:45:42.500Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68179 (GCVE-0-2026-68179)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-17 05:00
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
misc: nsm: only unlock nsm_dev on post-lock error paths
nsm_dev_ioctl() jumps to the common out label even when the initial
copy_from_user() fails before nsm->lock has been taken. The error path
then blindly unlocks a mutex that was never acquired.
This issue was found by our static analysis tool and then manually
reviewed against the current tree.
The grounded PoC kept the miscdevice ioctl entry and the pre-lock
copy_from_user(&raw, argp, _IOC_SIZE(cmd)) failure path by issuing
NSM_IOCTL_RAW with an invalid user pointer. That failure reaches the
shared out label before mutex_lock(&nsm->lock). Lockdep reported:
WARNING: bad unlock balance detected!
exploit/193 is trying to release lock (&global_nsm.lock) at:
nsm_dev_ioctl+0x5f/0xcf [vuln_msv]
but there are no more locks to release!
no locks held by exploit/193.
Return immediately on the pre-lock copy_from_user() failure and keep the
common unlock label for the post-lock paths only.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/misc/nsm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "4aa3f7d48e91eb74a363c1b4d7dbdd28f5b341fb",
"status": "affected",
"version": "b9873755a6c8ccfce79094c4dce9efa3ecb1a749",
"versionType": "git"
},
{
"lessThan": "8f068342096b027181b168d91fef7ac7a2c64b25",
"status": "affected",
"version": "b9873755a6c8ccfce79094c4dce9efa3ecb1a749",
"versionType": "git"
},
{
"lessThan": "f318f5a872cb9096536e759b23ae5c9873bb80ed",
"status": "affected",
"version": "b9873755a6c8ccfce79094c4dce9efa3ecb1a749",
"versionType": "git"
},
{
"lessThan": "ce1fed11d18e163baf7f875152a33bf80f625c1a",
"status": "affected",
"version": "b9873755a6c8ccfce79094c4dce9efa3ecb1a749",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/misc/nsm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.8"
},
{
"lessThan": "6.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmisc: nsm: only unlock nsm_dev on post-lock error paths\n\nnsm_dev_ioctl() jumps to the common out label even when the initial\ncopy_from_user() fails before nsm-\u003elock has been taken. The error path\nthen blindly unlocks a mutex that was never acquired.\n\nThis issue was found by our static analysis tool and then manually\nreviewed against the current tree.\n\nThe grounded PoC kept the miscdevice ioctl entry and the pre-lock\ncopy_from_user(\u0026raw, argp, _IOC_SIZE(cmd)) failure path by issuing\nNSM_IOCTL_RAW with an invalid user pointer. That failure reaches the\nshared out label before mutex_lock(\u0026nsm-\u003elock). Lockdep reported:\n\n WARNING: bad unlock balance detected!\n exploit/193 is trying to release lock (\u0026global_nsm.lock) at:\n nsm_dev_ioctl+0x5f/0xcf [vuln_msv]\n but there are no more locks to release!\n no locks held by exploit/193.\n\nReturn immediately on the pre-lock copy_from_user() failure and keep the\ncommon unlock label for the post-lock paths only."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.4,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The flaw is reached only via the local ioctl syscall on /dev/nsm (open plus ioctl through vfs_ioctl to nsm_dev_ioctl); it is not exposed through any network protocol or remote service.\nAC:L - An attacker can reliably trigger the pre-lock copy_from_user failure with an invalid userspace pointer and can control the race by issuing concurrent ioctl or /dev/hwrng reads against the same nsm-\u003elock.\nPR:N - The driver registers /dev/nsm as mode 0666 and performs no capability or permission checks in nsm_dev_ioctl, so any local process can open the device and issue NSM_IOCTL_RAW without elevated privileges.\nUI:N - Exploitation requires only the attacker issuing a crafted ioctl with an invalid argument pointer; no victim interaction, mounting, or other user action is needed.\nS:U - Impact is confined to corruption and privilege within the guest Nitro Enclave kernel; it does not cross into the hypervisor, parent instance, or another VM security boundary.\nC:H - Unlocking a mutex not held by the caller can clear owner while another context still holds nsm-\u003elock, permitting concurrent unsynchronized access to shared nsm_msg buffers and virtio response data.\nI:H - Premature mutex release enables overlapping virtqueue operations and corruption of shared kernel message state, a memory-safety defect that can be leveraged for arbitrary kernel integrity compromise.\nA:H - The bug triggers lockdep bad-unlock warnings and kernel oops, and concurrent unsynchronized virtio access can panic, hang, or otherwise deny service to the enclave."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:00:20.666Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/4aa3f7d48e91eb74a363c1b4d7dbdd28f5b341fb"
},
{
"url": "https://git.kernel.org/stable/c/8f068342096b027181b168d91fef7ac7a2c64b25"
},
{
"url": "https://git.kernel.org/stable/c/f318f5a872cb9096536e759b23ae5c9873bb80ed"
},
{
"url": "https://git.kernel.org/stable/c/ce1fed11d18e163baf7f875152a33bf80f625c1a"
}
],
"title": "misc: nsm: only unlock nsm_dev on post-lock error paths",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68179",
"datePublished": "2026-08-10T11:59:50.667Z",
"dateReserved": "2026-07-30T09:28:09.373Z",
"dateUpdated": "2026-08-17T05:00:20.666Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68259 (GCVE-0-2026-68259)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-19 16:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdkfd: Check bounds in allocate_event_notification_slot
The valid event ids go from 0 to KFD_SIGNAL_EVENT_LIMIT
allocate_event_notification_slot has an option to specify
an event id to allocate at, used by CRIU. We weren't checking
the bounds on that value.
Check them.
v2: Lower bounds check is unecessary because of idr_alloc
already rejecting negative numbers. Upper bounds check should
be KFD_SIGNAL_EVENT_LIMIT since the signal mode mappings might
not yet exist
(cherry picked from commit 6853f1f6cbbeb3f53ebbbd7286536aeb2c5d5f50)
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 40e8a766a761f7fdc8530347527b344fddf6f1a8 Version: 40e8a766a761f7fdc8530347527b344fddf6f1a8 Version: 40e8a766a761f7fdc8530347527b344fddf6f1a8 Version: 40e8a766a761f7fdc8530347527b344fddf6f1a8 Version: 40e8a766a761f7fdc8530347527b344fddf6f1a8 Version: 40e8a766a761f7fdc8530347527b344fddf6f1a8 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdkfd/kfd_events.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "6884fc142b17f456caac50c14505f509bfbcd012",
"status": "affected",
"version": "40e8a766a761f7fdc8530347527b344fddf6f1a8",
"versionType": "git"
},
{
"lessThan": "85eedff5f0c4aba5a66bc37a1bd6bcecd0d77b53",
"status": "affected",
"version": "40e8a766a761f7fdc8530347527b344fddf6f1a8",
"versionType": "git"
},
{
"lessThan": "4622214f0542f64b02c250db0f9c677eeb032d9b",
"status": "affected",
"version": "40e8a766a761f7fdc8530347527b344fddf6f1a8",
"versionType": "git"
},
{
"lessThan": "50319efb865f72db45f191c8709511746d58ee0a",
"status": "affected",
"version": "40e8a766a761f7fdc8530347527b344fddf6f1a8",
"versionType": "git"
},
{
"lessThan": "abeeb1947d81610c65349db4d89c6151f270e136",
"status": "affected",
"version": "40e8a766a761f7fdc8530347527b344fddf6f1a8",
"versionType": "git"
},
{
"lessThan": "bb52249fbbe948875155ccd45cd8d74bf4ae747b",
"status": "affected",
"version": "40e8a766a761f7fdc8530347527b344fddf6f1a8",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdkfd/kfd_events.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.18"
},
{
"lessThan": "5.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.18",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdkfd: Check bounds in allocate_event_notification_slot\n\nThe valid event ids go from 0 to KFD_SIGNAL_EVENT_LIMIT\n\nallocate_event_notification_slot has an option to specify\nan event id to allocate at, used by CRIU. We weren\u0027t checking\nthe bounds on that value.\n\nCheck them.\n\nv2: Lower bounds check is unecessary because of idr_alloc\nalready rejecting negative numbers. Upper bounds check should\nbe KFD_SIGNAL_EVENT_LIMIT since the signal mode mappings might\nnot yet exist\n\n(cherry picked from commit 6853f1f6cbbeb3f53ebbbd7286536aeb2c5d5f50)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:32:28.586Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/6884fc142b17f456caac50c14505f509bfbcd012"
},
{
"url": "https://git.kernel.org/stable/c/85eedff5f0c4aba5a66bc37a1bd6bcecd0d77b53"
},
{
"url": "https://git.kernel.org/stable/c/4622214f0542f64b02c250db0f9c677eeb032d9b"
},
{
"url": "https://git.kernel.org/stable/c/50319efb865f72db45f191c8709511746d58ee0a"
},
{
"url": "https://git.kernel.org/stable/c/abeeb1947d81610c65349db4d89c6151f270e136"
},
{
"url": "https://git.kernel.org/stable/c/bb52249fbbe948875155ccd45cd8d74bf4ae747b"
}
],
"title": "drm/amdkfd: Check bounds in allocate_event_notification_slot",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68259",
"datePublished": "2026-08-10T12:01:33.110Z",
"dateReserved": "2026-07-30T09:28:09.378Z",
"dateUpdated": "2026-08-19T16:32:28.586Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68142 (GCVE-0-2026-68142)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
geneve: require CAP_NET_ADMIN in the device netns for changelink
A tunnel changelink() operates on at most two netns, dev_net(dev) and
the sticky underlay netns geneve->net. They differ once the device is
created in or moved to a netns other than the one the request runs in.
The rtnl changelink path checks CAP_NET_ADMIN only against dev_net(dev),
so a caller privileged there but not in geneve->net can rewrite a geneve
device whose underlay lives in geneve->net.
geneve_changelink() applies the new configuration against geneve->net:
geneve_link_config() and the geneve_quiesce()/geneve_unquiesce() pair
reopen the underlay sockets in that netns (geneve_sock_add() uses
geneve->net), so the same reasoning as the tunnel changelink series
applies here.
Gate geneve_changelink() with rtnl_dev_link_net_capable(), at the top of
the op before any attribute is parsed, matching ipgre_changelink() and
the rest of the "require CAP_NET_ADMIN in the device netns for
changelink" series.
Found by 0sec automated security-research tooling (https://0sec.ai).
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 5b861f6baa3a22a48d7a4ad0ce38a223d36c978a Version: 5b861f6baa3a22a48d7a4ad0ce38a223d36c978a Version: 5b861f6baa3a22a48d7a4ad0ce38a223d36c978a Version: 5b861f6baa3a22a48d7a4ad0ce38a223d36c978a Version: 5b861f6baa3a22a48d7a4ad0ce38a223d36c978a Version: 5b861f6baa3a22a48d7a4ad0ce38a223d36c978a Version: 5b861f6baa3a22a48d7a4ad0ce38a223d36c978a Version: 5b861f6baa3a22a48d7a4ad0ce38a223d36c978a |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/geneve.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a5522963c57f12df5f9db804ebfc472b58eef0ae",
"status": "affected",
"version": "5b861f6baa3a22a48d7a4ad0ce38a223d36c978a",
"versionType": "git"
},
{
"lessThan": "278c6a31ee27c931c722202c8c06cc3253923254",
"status": "affected",
"version": "5b861f6baa3a22a48d7a4ad0ce38a223d36c978a",
"versionType": "git"
},
{
"lessThan": "11a7d989d00160481a273eb4f7f05f64b5a6ffdf",
"status": "affected",
"version": "5b861f6baa3a22a48d7a4ad0ce38a223d36c978a",
"versionType": "git"
},
{
"lessThan": "2abdacc927c92fa6a9cc8341e8c9b88dcb561553",
"status": "affected",
"version": "5b861f6baa3a22a48d7a4ad0ce38a223d36c978a",
"versionType": "git"
},
{
"lessThan": "9de5518fc1fab583526a8f66b8e505c4864dc60a",
"status": "affected",
"version": "5b861f6baa3a22a48d7a4ad0ce38a223d36c978a",
"versionType": "git"
},
{
"lessThan": "f8c498585d2a08aa623748353c3e61467b7e9fd2",
"status": "affected",
"version": "5b861f6baa3a22a48d7a4ad0ce38a223d36c978a",
"versionType": "git"
},
{
"lessThan": "95f45e20f1b2cec13823f0f68060ab4b2261b2c1",
"status": "affected",
"version": "5b861f6baa3a22a48d7a4ad0ce38a223d36c978a",
"versionType": "git"
},
{
"lessThan": "8efb8f8bbb353b8f2fdf4f37534c6d96c9f69e01",
"status": "affected",
"version": "5b861f6baa3a22a48d7a4ad0ce38a223d36c978a",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/geneve.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.14"
},
{
"lessThan": "4.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ngeneve: require CAP_NET_ADMIN in the device netns for changelink\n\nA tunnel changelink() operates on at most two netns, dev_net(dev) and\nthe sticky underlay netns geneve-\u003enet. They differ once the device is\ncreated in or moved to a netns other than the one the request runs in.\nThe rtnl changelink path checks CAP_NET_ADMIN only against dev_net(dev),\nso a caller privileged there but not in geneve-\u003enet can rewrite a geneve\ndevice whose underlay lives in geneve-\u003enet.\n\ngeneve_changelink() applies the new configuration against geneve-\u003enet:\ngeneve_link_config() and the geneve_quiesce()/geneve_unquiesce() pair\nreopen the underlay sockets in that netns (geneve_sock_add() uses\ngeneve-\u003enet), so the same reasoning as the tunnel changelink series\napplies here.\n\nGate geneve_changelink() with rtnl_dev_link_net_capable(), at the top of\nthe op before any attribute is parsed, matching ipgre_changelink() and\nthe rest of the \"require CAP_NET_ADMIN in the device netns for\nchangelink\" series.\n\nFound by 0sec automated security-research tooling (https://0sec.ai)."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires issuing RTM_NEWLINK changelink over a local rtnetlink socket; geneve_changelink is only reachable from the rtnl configuration path, not from received GENEVE/UDP network packets.\nAC:L - Once a geneve device exists with geneve-\u003enet differing from dev_net(dev) (via IFLA_NET_NS_FD migration or IFLA_LINK_NETNSID newlink), a single deterministic netlink changelink bypasses the missing check with no race or memory-layout dependency.\nPR:L - The rtnl entry path requires CAP_NET_ADMIN in dev_net(dev), obtainable by an unprivileged local user inside a user+network namespace via unshare --user --map-root-user --net; no CAP_NET_ADMIN in the sticky underlay netns geneve-\u003enet is needed.\nUI:N - The attack is fully programmatic through netlink from the attacker\u0027s own process; no victim action such as mounting a filesystem, opening a file, or clicking is required.\nS:C - geneve_changelink applies geneve_link_config() and geneve_quiesce()/geneve_unquiesce() (reopening underlay sockets via geneve_sock_add() in geneve-\u003enet) while authorization is checked only against dev_net(dev), crossing into another tenant\u0027s or the host\u0027s network namespace.\nC:H - An attacker can set IFLA_GENEVE_REMOTE/REMOTE6 to redirect encapsulated overlay traffic to an attacker-controlled endpoint and read tunneled payloads from the victim underlay netns.\nI:H - Unauthorized changelink mutates live tunnel remote endpoint, TTL/TOS/DF/label, and MTU in geneve-\u003enet, enabling redirection and injection of overlay traffic without authorization in that namespace.\nA:H - geneve_quiesce() drops in-flight tunnel traffic and rewriting the remote endpoint or MTU breaks production GENEVE overlays (Kubernetes/OVN/cloud SDN), causing sustained loss of connectivity for dependent services."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:30:02.355Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a5522963c57f12df5f9db804ebfc472b58eef0ae"
},
{
"url": "https://git.kernel.org/stable/c/278c6a31ee27c931c722202c8c06cc3253923254"
},
{
"url": "https://git.kernel.org/stable/c/11a7d989d00160481a273eb4f7f05f64b5a6ffdf"
},
{
"url": "https://git.kernel.org/stable/c/2abdacc927c92fa6a9cc8341e8c9b88dcb561553"
},
{
"url": "https://git.kernel.org/stable/c/9de5518fc1fab583526a8f66b8e505c4864dc60a"
},
{
"url": "https://git.kernel.org/stable/c/f8c498585d2a08aa623748353c3e61467b7e9fd2"
},
{
"url": "https://git.kernel.org/stable/c/95f45e20f1b2cec13823f0f68060ab4b2261b2c1"
},
{
"url": "https://git.kernel.org/stable/c/8efb8f8bbb353b8f2fdf4f37534c6d96c9f69e01"
}
],
"title": "geneve: require CAP_NET_ADMIN in the device netns for changelink",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68142",
"datePublished": "2026-08-10T11:59:06.048Z",
"dateReserved": "2026-07-30T09:28:09.370Z",
"dateUpdated": "2026-08-19T16:30:02.355Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68338 (GCVE-0-2026-68338)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/packet: avoid fanout hook re-registration after unregister
packet_set_ring() temporarily detaches a socket from packet delivery while
reconfiguring its ring. It records the previous running state, clears
po->num, unregisters the protocol hook when needed, drops po->bind_lock,
and later restores po->num and re-registers the hook from the saved
was_running value.
That unlocked window can race with NETDEV_UNREGISTER. The notifier can
observe the socket as not running, skip __unregister_prot_hook(), and
invalidate the per-socket binding by setting po->ifindex to -1 and clearing
po->prot_hook.dev. A one-member fanout group can still retain its shared
fanout hook device pointer. When packet_set_ring() resumes, re-registering
solely from the stale was_running state can re-add the fanout hook after
the device has been unregistered.
Treat po->ifindex == -1 as an invalidated binding after reacquiring
po->bind_lock. This is distinct from ifindex 0, the normal
unbound/wildcard state: ifindex -1 marks an existing device binding that
was invalidated when the device was unregistered. Restore po->num as
before, but do not re-register the hook if device unregister already
detached the socket.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: dc99f600698dcac69b8f56dda9a8a00d645c5ffc Version: dc99f600698dcac69b8f56dda9a8a00d645c5ffc Version: dc99f600698dcac69b8f56dda9a8a00d645c5ffc Version: dc99f600698dcac69b8f56dda9a8a00d645c5ffc Version: dc99f600698dcac69b8f56dda9a8a00d645c5ffc Version: dc99f600698dcac69b8f56dda9a8a00d645c5ffc Version: dc99f600698dcac69b8f56dda9a8a00d645c5ffc Version: dc99f600698dcac69b8f56dda9a8a00d645c5ffc |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/packet/af_packet.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "acb40ebfa5c4d62f84339fcbf713f2a9fd033a71",
"status": "affected",
"version": "dc99f600698dcac69b8f56dda9a8a00d645c5ffc",
"versionType": "git"
},
{
"lessThan": "c820f4b7f2fa38f8769db0d0cefdd94e2721504d",
"status": "affected",
"version": "dc99f600698dcac69b8f56dda9a8a00d645c5ffc",
"versionType": "git"
},
{
"lessThan": "4628efbdc7affd094181f5263e65c1062e31f15f",
"status": "affected",
"version": "dc99f600698dcac69b8f56dda9a8a00d645c5ffc",
"versionType": "git"
},
{
"lessThan": "80ec024d53a05c60ad1d08968dcf745f10c1665c",
"status": "affected",
"version": "dc99f600698dcac69b8f56dda9a8a00d645c5ffc",
"versionType": "git"
},
{
"lessThan": "0a052e0808e015e68144a9877e6ef42b952c49fa",
"status": "affected",
"version": "dc99f600698dcac69b8f56dda9a8a00d645c5ffc",
"versionType": "git"
},
{
"lessThan": "1bc55c29cd85818e9052f17deb287d5a11fb817f",
"status": "affected",
"version": "dc99f600698dcac69b8f56dda9a8a00d645c5ffc",
"versionType": "git"
},
{
"lessThan": "a885387dae7986a55bae5c77a15bdd447f64e9b9",
"status": "affected",
"version": "dc99f600698dcac69b8f56dda9a8a00d645c5ffc",
"versionType": "git"
},
{
"lessThan": "50aff80475abd3533eef4320477037e6fcc6b56e",
"status": "affected",
"version": "dc99f600698dcac69b8f56dda9a8a00d645c5ffc",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/packet/af_packet.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.1"
},
{
"lessThan": "3.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/packet: avoid fanout hook re-registration after unregister\n\npacket_set_ring() temporarily detaches a socket from packet delivery while\nreconfiguring its ring. It records the previous running state, clears\npo-\u003enum, unregisters the protocol hook when needed, drops po-\u003ebind_lock,\nand later restores po-\u003enum and re-registers the hook from the saved\nwas_running value.\n\nThat unlocked window can race with NETDEV_UNREGISTER. The notifier can\nobserve the socket as not running, skip __unregister_prot_hook(), and\ninvalidate the per-socket binding by setting po-\u003eifindex to -1 and clearing\npo-\u003eprot_hook.dev. A one-member fanout group can still retain its shared\nfanout hook device pointer. When packet_set_ring() resumes, re-registering\nsolely from the stale was_running state can re-add the fanout hook after\nthe device has been unregistered.\n\nTreat po-\u003eifindex == -1 as an invalidated binding after reacquiring\npo-\u003ebind_lock. This is distinct from ifindex 0, the normal\nunbound/wildcard state: ifindex -1 marks an existing device binding that\nwas invalidated when the device was unregistered. Restore po-\u003enum as\nbefore, but do not re-register the hook if device unregister already\ndetached the socket."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is triggered through local syscalls \u2014 creating an AF_PACKET socket, PACKET_FANOUT/bind setsockopt, PACKET_RX_RING setsockopt, and a netlink device unregister \u2014 with no remote packet processing involved.\nAC:L - The attacker controls both sides of the race: it issues the packet_set_ring() reconfiguration and deletes the bound netdev in its own netns, and the unlocked window spans synchronize_net() plus the ring swap, making it wide and reliably winnable.\nPR:L - AF_PACKET requires CAP_NET_RAW and device unregistration CAP_NET_ADMIN, but an unprivileged user obtains both via user+network namespaces (unshare -Urn) and can create and delete veth/dummy devices there.\nUI:N - The attacker performs every step itself \u2014 socket setup, ring reconfiguration and device teardown \u2014 with no action required from any other user.\nS:U - The stale hook registration and resulting corruption stay within the kernel\u0027s own security authority; no hypervisor, IOMMU or other trust boundary is crossed.\nC:H - The fanout packet_type is left linked into a net_device that is being torn down, a dangling registration on soon-to-be-freed memory; such stale-pointer state in the ptype lists can be leveraged for kernel memory disclosure.\nI:H - The dangling list node in the freed net_device\u0027s ptype list yields a list_del write into freed memory when the hook is later removed, a controllable write primitive typical of use-after-free exploitation.\nA:H - The re-added hook makes netdev_run_todo() hit BUG_ON(!list_empty(\u0026dev-\u003eptype_all)) while RTNL is held, oopsing the kernel and permanently wedging all further network configuration \u2014 a repeatable, unprivileged host-wide denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:38.308Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/acb40ebfa5c4d62f84339fcbf713f2a9fd033a71"
},
{
"url": "https://git.kernel.org/stable/c/c820f4b7f2fa38f8769db0d0cefdd94e2721504d"
},
{
"url": "https://git.kernel.org/stable/c/4628efbdc7affd094181f5263e65c1062e31f15f"
},
{
"url": "https://git.kernel.org/stable/c/80ec024d53a05c60ad1d08968dcf745f10c1665c"
},
{
"url": "https://git.kernel.org/stable/c/0a052e0808e015e68144a9877e6ef42b952c49fa"
},
{
"url": "https://git.kernel.org/stable/c/1bc55c29cd85818e9052f17deb287d5a11fb817f"
},
{
"url": "https://git.kernel.org/stable/c/a885387dae7986a55bae5c77a15bdd447f64e9b9"
},
{
"url": "https://git.kernel.org/stable/c/50aff80475abd3533eef4320477037e6fcc6b56e"
}
],
"title": "net/packet: avoid fanout hook re-registration after unregister",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68338",
"datePublished": "2026-08-10T12:03:14.549Z",
"dateReserved": "2026-07-30T09:28:09.384Z",
"dateUpdated": "2026-08-19T16:33:38.308Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72121 (GCVE-0-2026-72121)
Vulnerability from cvelistv5
Published
2026-08-15 05:52
Modified
2026-08-19 16:36
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
can: bcm: add locking when updating filter and timer values
KCSAN detected a simultaneous access to timer values that can be
overwritten in bcm_rx_setup() when updating timer and filter content
while bcm_rx_handler(), bcm_rx_timeout_handler() or bcm_rx_thr_handler()
run concurrently on incoming CAN traffic.
Protect the timer (ival1/ival2/kt_ival1/kt_ival2/kt_lastmsg) and filter
(nframes/flags/frames/last_frames) updates in bcm_rx_setup() with a new
per-op bcm_rx_update_lock, taken with the matching scope in the RX
handlers. memcpy_from_msg() is staged into a temporary buffer before the
lock is taken, since it can sleep and must not run under a spinlock.
hrtimer_cancel() is always called without bcm_rx_update_lock held, since
bcm_rx_timeout_handler()/bcm_rx_thr_handler() take the same lock and a
running callback would otherwise deadlock against the canceller.
Also close a related race: bcm_rx_setup() cleared the RTR flag in the
stored reply frame's can_id as a separate, unprotected step after the
frame content was already installed, so a concurrent bcm_rx_handler()
could transmit a stale reply with CAN_RTR_FLAG still set. Fold that
normalization into the initial frame preparation instead (on the staged
buffer for updates, directly on op->frames pre-registration for new
ops), so the installed frame is always atomically self-consistent.
bcm_rx_handler()'s RX_RTR_FRAME check now takes a lock-protected
snapshot of op->flags before deciding whether to call bcm_can_tx(),
but does not hold the lock across that call.
Also take a lock-protected snapshot of the currframe in bcm_can_tx()
to avoid partly overwrites by content updates in bcm_tx_setup().
Finally check if a TX_RESET_MULTI_IDX/SETTIMER might have reset
op->currframe between the two locked sections in bcm_can_tx().
Omit calling hrtimer_forward() with zero interval in bcm_rx_thr_handler().
kt_ival2 may have been concurrently cleared by bcm_rx_setup() before it
cancels this timer, so check kt_ival2 inside the bcm_rx_update_lock.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 7595de7bc56e0e52b74e56c90f7e247bf626d628 Version: fbd8fdc2b218e979cfe422b139b8f74c12419d1f Version: 2a437b86ac5a9893c902f30ef66815bf13587bf6 Version: 76c84c3728178b2d38d5604e399dfe8b0752645e Version: cc55dd28c20a6611e30596019b3b2f636819a4c0 Version: c2aba69d0c36a496ab4f2e81e9c2b271f2693fd7 Version: c2aba69d0c36a496ab4f2e81e9c2b271f2693fd7 Version: c2aba69d0c36a496ab4f2e81e9c2b271f2693fd7 Version: 8f1c022541bf5a923c8d6fa483112c15250f30a4 Version: c4e8a172501e677ebd8ea9d9161d97dc4df56fbd Version: 5.10.238 ≤ Version: 5.15.185 ≤ Version: 6.1.141 ≤ Version: 6.6.93 ≤ Version: 6.12.31 ≤ Version: 5.4.294 ≤ Version: 6.14.9 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/can/bcm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "96994180bd7b248b0cc698afe926e23fc1bda59b",
"status": "affected",
"version": "7595de7bc56e0e52b74e56c90f7e247bf626d628",
"versionType": "git"
},
{
"lessThan": "caa8704a7f3cb7806331596195385437126ecb3a",
"status": "affected",
"version": "fbd8fdc2b218e979cfe422b139b8f74c12419d1f",
"versionType": "git"
},
{
"lessThan": "a7c369e7da8203e2b5be12bbcac7b9ab2ed5b658",
"status": "affected",
"version": "2a437b86ac5a9893c902f30ef66815bf13587bf6",
"versionType": "git"
},
{
"lessThan": "a7eb6db1cd3f7b556a301dc1265945ad112089f7",
"status": "affected",
"version": "76c84c3728178b2d38d5604e399dfe8b0752645e",
"versionType": "git"
},
{
"lessThan": "834cbca3b12e46887f7a9b35f1981a888360ea4c",
"status": "affected",
"version": "cc55dd28c20a6611e30596019b3b2f636819a4c0",
"versionType": "git"
},
{
"lessThan": "19b1994069dd29478ba767de1f98f14a088198dc",
"status": "affected",
"version": "c2aba69d0c36a496ab4f2e81e9c2b271f2693fd7",
"versionType": "git"
},
{
"lessThan": "fc9f5ee1b073bd233d9c604e338af4ebb42cbc33",
"status": "affected",
"version": "c2aba69d0c36a496ab4f2e81e9c2b271f2693fd7",
"versionType": "git"
},
{
"lessThan": "749179c2e25b95d22499ed29096b3e02d6dfd2b4",
"status": "affected",
"version": "c2aba69d0c36a496ab4f2e81e9c2b271f2693fd7",
"versionType": "git"
},
{
"status": "affected",
"version": "8f1c022541bf5a923c8d6fa483112c15250f30a4",
"versionType": "git"
},
{
"status": "affected",
"version": "c4e8a172501e677ebd8ea9d9161d97dc4df56fbd",
"versionType": "git"
},
{
"lessThan": "5.10.265",
"status": "affected",
"version": "5.10.238",
"versionType": "semver"
},
{
"lessThan": "5.15.216",
"status": "affected",
"version": "5.15.185",
"versionType": "semver"
},
{
"lessThan": "6.1.183",
"status": "affected",
"version": "6.1.141",
"versionType": "semver"
},
{
"lessThan": "6.6.148",
"status": "affected",
"version": "6.6.93",
"versionType": "semver"
},
{
"lessThan": "6.12.101",
"status": "affected",
"version": "6.12.31",
"versionType": "semver"
},
{
"lessThan": "5.5",
"status": "affected",
"version": "5.4.294",
"versionType": "semver"
},
{
"lessThan": "6.15",
"status": "affected",
"version": "6.14.9",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/can/bcm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.15"
},
{
"lessThan": "6.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.10.238",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.15.185",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "6.1.141",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.6.93",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.12.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "6.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.4.294",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.14.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: bcm: add locking when updating filter and timer values\n\nKCSAN detected a simultaneous access to timer values that can be\noverwritten in bcm_rx_setup() when updating timer and filter content\nwhile bcm_rx_handler(), bcm_rx_timeout_handler() or bcm_rx_thr_handler()\nrun concurrently on incoming CAN traffic.\n\nProtect the timer (ival1/ival2/kt_ival1/kt_ival2/kt_lastmsg) and filter\n(nframes/flags/frames/last_frames) updates in bcm_rx_setup() with a new\nper-op bcm_rx_update_lock, taken with the matching scope in the RX\nhandlers. memcpy_from_msg() is staged into a temporary buffer before the\nlock is taken, since it can sleep and must not run under a spinlock.\n\nhrtimer_cancel() is always called without bcm_rx_update_lock held, since\nbcm_rx_timeout_handler()/bcm_rx_thr_handler() take the same lock and a\nrunning callback would otherwise deadlock against the canceller.\n\nAlso close a related race: bcm_rx_setup() cleared the RTR flag in the\nstored reply frame\u0027s can_id as a separate, unprotected step after the\nframe content was already installed, so a concurrent bcm_rx_handler()\ncould transmit a stale reply with CAN_RTR_FLAG still set. Fold that\nnormalization into the initial frame preparation instead (on the staged\nbuffer for updates, directly on op-\u003eframes pre-registration for new\nops), so the installed frame is always atomically self-consistent.\n\nbcm_rx_handler()\u0027s RX_RTR_FRAME check now takes a lock-protected\nsnapshot of op-\u003eflags before deciding whether to call bcm_can_tx(),\nbut does not hold the lock across that call.\n\nAlso take a lock-protected snapshot of the currframe in bcm_can_tx()\nto avoid partly overwrites by content updates in bcm_tx_setup().\nFinally check if a TX_RESET_MULTI_IDX/SETTIMER might have reset\nop-\u003ecurrframe between the two locked sections in bcm_can_tx().\n\nOmit calling hrtimer_forward() with zero interval in bcm_rx_thr_handler().\nkt_ival2 may have been concurrently cleared by bcm_rx_setup() before it\ncancels this timer, so check kt_ival2 inside the bcm_rx_update_lock."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The race is driven by concurrent CAN frame reception in bcm_rx_handler()/timer callbacks on a shared CAN segment (automotive OBD/ECU bus, factory controllers, CAN-USB adapters), an adjacent broadcast medium comparable to Bluetooth/WiFi segment access.\nAC:L - An attacker controls both race sides by flooding RX_SETUP via sendmsg while concurrently injecting matching CAN frames or armed timers; syzbot reliably reproduced the KCSAN race without timing conditions beyond attacker control.\nPR:N - CAN_BCM sockets impose no capability checks in can_create()/bcm_sendmsg(), and a bus participant can trigger the RX handler path without any Linux credentials while racing BCM configuration updates from local services.\nUI:N - Exploitation requires no victim interaction beyond normal background CAN/BCM activity on systems that already use the Broadcast Manager for monitoring or diagnostics.\nS:U - Impact is confined to kernel memory corruption and privilege boundaries within the same host; this is not a VM escape, IOMMU bypass, or cross-authority sandbox breakout.\nC:H - Unlocked concurrent updates to nframes/flags/frames/last_frames permit torn reads and out-of-bounds accesses in handler loops and timeout memset, matching the prior BCM race class that produced KASAN slab-out-of-bounds reads.\nI:H - Partial overwrites of op-\u003eframes during bcm_can_tx(), stale RTR replies transmitted on the bus, and size-mismatched memset/memcpy against concurrently shrinking buffers enable arbitrary CAN injection and kernel heap corruption.\nA:H - Concurrent timer corruption (hrtimer_forward with zero kt_ival2), torn structure fields, and heap corruption from racing memset/copy operations can cause kernel oops, panic, or sustained denial of service on CAN-equipped systems."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:36:16.520Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/96994180bd7b248b0cc698afe926e23fc1bda59b"
},
{
"url": "https://git.kernel.org/stable/c/caa8704a7f3cb7806331596195385437126ecb3a"
},
{
"url": "https://git.kernel.org/stable/c/a7c369e7da8203e2b5be12bbcac7b9ab2ed5b658"
},
{
"url": "https://git.kernel.org/stable/c/a7eb6db1cd3f7b556a301dc1265945ad112089f7"
},
{
"url": "https://git.kernel.org/stable/c/834cbca3b12e46887f7a9b35f1981a888360ea4c"
},
{
"url": "https://git.kernel.org/stable/c/19b1994069dd29478ba767de1f98f14a088198dc"
},
{
"url": "https://git.kernel.org/stable/c/fc9f5ee1b073bd233d9c604e338af4ebb42cbc33"
},
{
"url": "https://git.kernel.org/stable/c/749179c2e25b95d22499ed29096b3e02d6dfd2b4"
}
],
"title": "can: bcm: add locking when updating filter and timer values",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72121",
"datePublished": "2026-08-15T05:52:59.959Z",
"dateReserved": "2026-08-09T03:40:39.907Z",
"dateUpdated": "2026-08-19T16:36:16.520Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68328 (GCVE-0-2026-68328)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
nfp: Check resource mutex allocation
nfp_cpp_resource_find() allocates a CPP mutex handle for the matching
resource-table entry and then reports success. nfp_resource_try_acquire()
immediately passes that handle to nfp_cpp_mutex_trylock().
However, nfp_cpp_mutex_alloc() returns NULL on failure. If that happens
for a matching table entry, the resource lookup still returns success and
the following trylock dereferences a NULL mutex pointer while opening the
resource.
nfp_resource_acquire() already treats failure to allocate the table mutex
as -ENOMEM. Do the same for the resource mutex and fail the lookup before
publishing the rest of the resource handle.
This issue was found by a static analysis checker and confirmed by
manual source review.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: f01a2161577d31b14581e0db3bbbdfa963f145b6 Version: f01a2161577d31b14581e0db3bbbdfa963f145b6 Version: f01a2161577d31b14581e0db3bbbdfa963f145b6 Version: f01a2161577d31b14581e0db3bbbdfa963f145b6 Version: f01a2161577d31b14581e0db3bbbdfa963f145b6 Version: f01a2161577d31b14581e0db3bbbdfa963f145b6 Version: f01a2161577d31b14581e0db3bbbdfa963f145b6 Version: f01a2161577d31b14581e0db3bbbdfa963f145b6 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/netronome/nfp/nfpcore/nfp_resource.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "18737a48acc87e4cbe41d6fea9a3f44eae490e24",
"status": "affected",
"version": "f01a2161577d31b14581e0db3bbbdfa963f145b6",
"versionType": "git"
},
{
"lessThan": "423523f96a681428ce6e214eaf47f0d8242319de",
"status": "affected",
"version": "f01a2161577d31b14581e0db3bbbdfa963f145b6",
"versionType": "git"
},
{
"lessThan": "0dbd85a8cc35c14bd26e686fa5fae8c64a7958ae",
"status": "affected",
"version": "f01a2161577d31b14581e0db3bbbdfa963f145b6",
"versionType": "git"
},
{
"lessThan": "6dbd428119cb1fd1b73cf6968c711f4ea964dc8b",
"status": "affected",
"version": "f01a2161577d31b14581e0db3bbbdfa963f145b6",
"versionType": "git"
},
{
"lessThan": "cfa119aa781c4044dab5b4c1e5864600f53a26bc",
"status": "affected",
"version": "f01a2161577d31b14581e0db3bbbdfa963f145b6",
"versionType": "git"
},
{
"lessThan": "3b1d4fc3b73ea6faf008a0996ce6190c6e43efc3",
"status": "affected",
"version": "f01a2161577d31b14581e0db3bbbdfa963f145b6",
"versionType": "git"
},
{
"lessThan": "a7dc30b6828c3a30252892827b12b676749f250f",
"status": "affected",
"version": "f01a2161577d31b14581e0db3bbbdfa963f145b6",
"versionType": "git"
},
{
"lessThan": "a61b4db34a753bdf5c9e77a7f3d3dddd41dcfacc",
"status": "affected",
"version": "f01a2161577d31b14581e0db3bbbdfa963f145b6",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/netronome/nfp/nfpcore/nfp_resource.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.11"
},
{
"lessThan": "4.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfp: Check resource mutex allocation\n\nnfp_cpp_resource_find() allocates a CPP mutex handle for the matching\nresource-table entry and then reports success. nfp_resource_try_acquire()\nimmediately passes that handle to nfp_cpp_mutex_trylock().\n\nHowever, nfp_cpp_mutex_alloc() returns NULL on failure. If that happens\nfor a matching table entry, the resource lookup still returns success and\nthe following trylock dereferences a NULL mutex pointer while opening the\nresource.\n\nnfp_resource_acquire() already treats failure to allocate the table mutex\nas -ENOMEM. Do the same for the resource mutex and fail the lookup before\npublishing the rest of the resource handle.\n\nThis issue was found by a static analysis checker and confirmed by\nmanual source review."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:25.716Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/18737a48acc87e4cbe41d6fea9a3f44eae490e24"
},
{
"url": "https://git.kernel.org/stable/c/423523f96a681428ce6e214eaf47f0d8242319de"
},
{
"url": "https://git.kernel.org/stable/c/0dbd85a8cc35c14bd26e686fa5fae8c64a7958ae"
},
{
"url": "https://git.kernel.org/stable/c/6dbd428119cb1fd1b73cf6968c711f4ea964dc8b"
},
{
"url": "https://git.kernel.org/stable/c/cfa119aa781c4044dab5b4c1e5864600f53a26bc"
},
{
"url": "https://git.kernel.org/stable/c/3b1d4fc3b73ea6faf008a0996ce6190c6e43efc3"
},
{
"url": "https://git.kernel.org/stable/c/a7dc30b6828c3a30252892827b12b676749f250f"
},
{
"url": "https://git.kernel.org/stable/c/a61b4db34a753bdf5c9e77a7f3d3dddd41dcfacc"
}
],
"title": "nfp: Check resource mutex allocation",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68328",
"datePublished": "2026-08-10T12:03:04.560Z",
"dateReserved": "2026-07-30T09:28:09.382Z",
"dateUpdated": "2026-08-19T16:33:25.716Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68279 (GCVE-0-2026-68279)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers
drm_dp_sideband_parse_remote_dpcd_read() reads num_bytes from the raw
message and then unconditionally does:
memcpy(bytes, &raw->msg[idx], num_bytes);
without checking that idx + num_bytes <= raw->curlen. raw->msg[] is
256 bytes; if a malicious or misbehaving MST hub sets num_bytes larger
than the remaining payload, the memcpy reads past the received data
into whatever follows in raw->msg[].
drm_dp_sideband_parse_remote_i2c_read_ack() has the same flaw (noted
with a /* TODO check */ comment since the code was introduced).
Fix both functions by using a single combined check
(idx + num_bytes > curlen) before each memcpy. Since num_bytes is u8,
it is always >= 0, so this strictly subsumes the simpler idx > curlen
form and no separate step is needed.
[added missing fixes tag]
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/display/drm_dp_mst_topology.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "185de1d74e658e2edb723ba76fa61903f77d8a68",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "d7b9b1e33b4ed8c48d4db6e6e21c257ebbbb2586",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "c2fbda0fe0163c55ba3820ee6cea0c6b43622eda",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "22d9f7fc1aaabaf73d5f30e8b0c9aa814ecd6ed2",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "04d953f50d61e542e94a5977822cc53735f8c0ce",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "533d9e2bede4aeefdc2a0561d7071cfede95958f",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "e6ef5455b06cb4e5d181aabcd723791587c79f12",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "1a8f537f5a1eeac941f262fe73078d6b08ba83c0",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/display/drm_dp_mst_topology.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.17"
},
{
"lessThan": "3.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.17",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers\n\ndrm_dp_sideband_parse_remote_dpcd_read() reads num_bytes from the raw\nmessage and then unconditionally does:\n\n memcpy(bytes, \u0026raw-\u003emsg[idx], num_bytes);\n\nwithout checking that idx + num_bytes \u003c= raw-\u003ecurlen. raw-\u003emsg[] is\n256 bytes; if a malicious or misbehaving MST hub sets num_bytes larger\nthan the remaining payload, the memcpy reads past the received data\ninto whatever follows in raw-\u003emsg[].\n\ndrm_dp_sideband_parse_remote_i2c_read_ack() has the same flaw (noted\nwith a /* TODO check */ comment since the code was introduced).\n\nFix both functions by using a single combined check\n(idx + num_bytes \u003e curlen) before each memcpy. Since num_bytes is u8,\nit is always \u003e= 0, so this strictly subsumes the simpler idx \u003e curlen\nform and no separate step is needed.\n\n[added missing fixes tag]"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:16.563Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/185de1d74e658e2edb723ba76fa61903f77d8a68"
},
{
"url": "https://git.kernel.org/stable/c/d7b9b1e33b4ed8c48d4db6e6e21c257ebbbb2586"
},
{
"url": "https://git.kernel.org/stable/c/c2fbda0fe0163c55ba3820ee6cea0c6b43622eda"
},
{
"url": "https://git.kernel.org/stable/c/22d9f7fc1aaabaf73d5f30e8b0c9aa814ecd6ed2"
},
{
"url": "https://git.kernel.org/stable/c/04d953f50d61e542e94a5977822cc53735f8c0ce"
},
{
"url": "https://git.kernel.org/stable/c/533d9e2bede4aeefdc2a0561d7071cfede95958f"
},
{
"url": "https://git.kernel.org/stable/c/e6ef5455b06cb4e5d181aabcd723791587c79f12"
},
{
"url": "https://git.kernel.org/stable/c/1a8f537f5a1eeac941f262fe73078d6b08ba83c0"
}
],
"title": "drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68279",
"datePublished": "2026-08-10T12:02:09.423Z",
"dateReserved": "2026-07-30T09:28:09.379Z",
"dateUpdated": "2026-08-23T12:46:16.563Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64290 (GCVE-0-2026-64290)
Vulnerability from cvelistv5
Published
2026-07-25 08:49
Modified
2026-08-17 04:52
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
iommufd: Break the loop on failure in iommufd_fault_fops_read()
On a copy_to_user() failure inside the inner list_for_each_entry, only the
inner loop breaks; the outer while re-fetches the just-restored fault group
and retries the failing copy_to_user() forever, spinning the reader at 100%
CPU with fault->mutex held.
Check rc after the inner loop and break the outer while as well.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/iommu/iommufd/eventq.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a38e0714affc5c0bbb40cba5a65d6d32a5e72a71",
"status": "affected",
"version": "07838f7fd529c8a6de44b601d4b7057e6c8d36ed",
"versionType": "git"
},
{
"lessThan": "5539da127d03c1f6c2e2a49fdfbe331a0ccbdea8",
"status": "affected",
"version": "07838f7fd529c8a6de44b601d4b7057e6c8d36ed",
"versionType": "git"
},
{
"lessThan": "f66c16b175509642ee7082df57c9bf3deaebae1a",
"status": "affected",
"version": "07838f7fd529c8a6de44b601d4b7057e6c8d36ed",
"versionType": "git"
},
{
"lessThan": "172fc8b19825a0f5884c38f2289188284e2d45ee",
"status": "affected",
"version": "07838f7fd529c8a6de44b601d4b7057e6c8d36ed",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/iommu/iommufd/eventq.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.11"
},
{
"lessThan": "6.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\niommufd: Break the loop on failure in iommufd_fault_fops_read()\n\nOn a copy_to_user() failure inside the inner list_for_each_entry, only the\ninner loop breaks; the outer while re-fetches the just-restored fault group\nand retries the failing copy_to_user() forever, spinning the reader at 100%\nCPU with fault-\u003emutex held.\n\nCheck rc after the inner loop and break the outer while as well."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:52:47.176Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a38e0714affc5c0bbb40cba5a65d6d32a5e72a71"
},
{
"url": "https://git.kernel.org/stable/c/5539da127d03c1f6c2e2a49fdfbe331a0ccbdea8"
},
{
"url": "https://git.kernel.org/stable/c/f66c16b175509642ee7082df57c9bf3deaebae1a"
},
{
"url": "https://git.kernel.org/stable/c/172fc8b19825a0f5884c38f2289188284e2d45ee"
}
],
"title": "iommufd: Break the loop on failure in iommufd_fault_fops_read()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64290",
"datePublished": "2026-07-25T08:49:30.049Z",
"dateReserved": "2026-07-19T15:36:31.778Z",
"dateUpdated": "2026-08-17T04:52:47.176Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68182 (GCVE-0-2026-68182)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
comedi: comedi_parport: deal with premature interrupt
Syzbot reported a general protection fault in
`comedi_get_is_subdevice_running()`, which was called from the interrupt
handler `parport_interrupt()` in the "comedi_parport" driver, but it
does not currently have a C reproducer for the problem. It's
probably due to a premature interrupt for one of two reasons:
1. The driver sets up the interrupt handler before the comedi subdevices
used by the interrupt handler have been allocated, but does not
disable the interrupt in the parallel port's CTRL register first.
2. The driver uses a user-supplied I/O port base address which Syzbot
would have supplied, but it might not be backed by real parallel port
hardware.
Change the initialization order in the driver's comedi "attach" handler
(`parport_attach()`) so that the hardware registers are initialized
before the interrupt handler is requested. This should prevent
premature interrupts occurring for real hardware.
Also add a test to the interrupt handler to ensure the comedi device is
fully attached and return early if it isn't.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 241ab6ad7108e51c67881f7881c5e46f0400cdb1 Version: 241ab6ad7108e51c67881f7881c5e46f0400cdb1 Version: 241ab6ad7108e51c67881f7881c5e46f0400cdb1 Version: 241ab6ad7108e51c67881f7881c5e46f0400cdb1 Version: 241ab6ad7108e51c67881f7881c5e46f0400cdb1 Version: 241ab6ad7108e51c67881f7881c5e46f0400cdb1 Version: 241ab6ad7108e51c67881f7881c5e46f0400cdb1 Version: 241ab6ad7108e51c67881f7881c5e46f0400cdb1 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/comedi/drivers/comedi_parport.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "6ed34611e569fc1a1169905c5228fd0eb2806c1b",
"status": "affected",
"version": "241ab6ad7108e51c67881f7881c5e46f0400cdb1",
"versionType": "git"
},
{
"lessThan": "48ef18e5eb6b8a9c546038b2ab89a841fcd97fe7",
"status": "affected",
"version": "241ab6ad7108e51c67881f7881c5e46f0400cdb1",
"versionType": "git"
},
{
"lessThan": "a88b25db815ff6edace81b0bb0f4a201133bd215",
"status": "affected",
"version": "241ab6ad7108e51c67881f7881c5e46f0400cdb1",
"versionType": "git"
},
{
"lessThan": "b061bb4dca49fd93063359d3805387235818778c",
"status": "affected",
"version": "241ab6ad7108e51c67881f7881c5e46f0400cdb1",
"versionType": "git"
},
{
"lessThan": "086a9ae3c5df63ec11033a8c0b3f6a1fd295ddd1",
"status": "affected",
"version": "241ab6ad7108e51c67881f7881c5e46f0400cdb1",
"versionType": "git"
},
{
"lessThan": "cf26dd2d841583c54a87005c4934b92fddb930c3",
"status": "affected",
"version": "241ab6ad7108e51c67881f7881c5e46f0400cdb1",
"versionType": "git"
},
{
"lessThan": "5d059ce0e6a2f6f8b97273499d47b8f917097b48",
"status": "affected",
"version": "241ab6ad7108e51c67881f7881c5e46f0400cdb1",
"versionType": "git"
},
{
"lessThan": "17221216ae8ce6a24e8a4e787382e3ebc81b88a8",
"status": "affected",
"version": "241ab6ad7108e51c67881f7881c5e46f0400cdb1",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/comedi/drivers/comedi_parport.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.29"
},
{
"lessThan": "2.6.29",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.29",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.29",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.29",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.29",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.29",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.29",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.29",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.29",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncomedi: comedi_parport: deal with premature interrupt\n\nSyzbot reported a general protection fault in\n`comedi_get_is_subdevice_running()`, which was called from the interrupt\nhandler `parport_interrupt()` in the \"comedi_parport\" driver, but it\ndoes not currently have a C reproducer for the problem. It\u0027s\nprobably due to a premature interrupt for one of two reasons:\n\n1. The driver sets up the interrupt handler before the comedi subdevices\n used by the interrupt handler have been allocated, but does not\n disable the interrupt in the parallel port\u0027s CTRL register first.\n2. The driver uses a user-supplied I/O port base address which Syzbot\n would have supplied, but it might not be backed by real parallel port\n hardware.\n\nChange the initialization order in the driver\u0027s comedi \"attach\" handler\n(`parport_attach()`) so that the hardware registers are initialized\nbefore the interrupt handler is requested. This should prevent\npremature interrupts occurring for real hardware.\n\nAlso add a test to the interrupt handler to ensure the comedi device is\nfully attached and return early if it isn\u0027t."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:30:47.491Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/6ed34611e569fc1a1169905c5228fd0eb2806c1b"
},
{
"url": "https://git.kernel.org/stable/c/48ef18e5eb6b8a9c546038b2ab89a841fcd97fe7"
},
{
"url": "https://git.kernel.org/stable/c/a88b25db815ff6edace81b0bb0f4a201133bd215"
},
{
"url": "https://git.kernel.org/stable/c/b061bb4dca49fd93063359d3805387235818778c"
},
{
"url": "https://git.kernel.org/stable/c/086a9ae3c5df63ec11033a8c0b3f6a1fd295ddd1"
},
{
"url": "https://git.kernel.org/stable/c/cf26dd2d841583c54a87005c4934b92fddb930c3"
},
{
"url": "https://git.kernel.org/stable/c/5d059ce0e6a2f6f8b97273499d47b8f917097b48"
},
{
"url": "https://git.kernel.org/stable/c/17221216ae8ce6a24e8a4e787382e3ebc81b88a8"
}
],
"title": "comedi: comedi_parport: deal with premature interrupt",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68182",
"datePublished": "2026-08-10T11:59:53.793Z",
"dateReserved": "2026-07-30T09:28:09.373Z",
"dateUpdated": "2026-08-19T16:30:47.491Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68144 (GCVE-0-2026-68144)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
phonet: pep: fix use-after-free in pep_get_sb()
pep_get_sb() doesn't consider that pskb_may_pull() might have relocated
the skb data, and continue to access the older pointer, causing UAF.
Reproduced under KASAN:
BUG: KASAN: slab-use-after-free in pep_get_sb+0x234/0x3b0
Read of size 1 at addr ff11000105510f50 by task repro/157
pep_get_sb+0x234/0x3b0
pipe_handler_do_rcv+0x5f7/0xa10
pep_do_rcv+0x203/0x410
__sk_receive_skb+0x471/0x4a0
phonet_rcv+0x5b3/0x6c0
__netif_receive_skb+0xcc/0x1d0
Refetch the header with skb_header_pointer() after pskb_may_pull(), so
the possibly stale pointer is no longer dereferenced. There are better
ways to solve this, but, this is the less instrusive one.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 9641458d3ec42def729fde64669abf07f3220cd5 Version: 9641458d3ec42def729fde64669abf07f3220cd5 Version: 9641458d3ec42def729fde64669abf07f3220cd5 Version: 9641458d3ec42def729fde64669abf07f3220cd5 Version: 9641458d3ec42def729fde64669abf07f3220cd5 Version: 9641458d3ec42def729fde64669abf07f3220cd5 Version: 9641458d3ec42def729fde64669abf07f3220cd5 Version: 9641458d3ec42def729fde64669abf07f3220cd5 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/phonet/pep.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c4a52cb4da8d57d060b1d52085d25147a238dac2",
"status": "affected",
"version": "9641458d3ec42def729fde64669abf07f3220cd5",
"versionType": "git"
},
{
"lessThan": "df198743859fefba2f824115f8151dd62d7ad6d8",
"status": "affected",
"version": "9641458d3ec42def729fde64669abf07f3220cd5",
"versionType": "git"
},
{
"lessThan": "1d81e19fc57a5ee55b4497d01bc0510d76fb9578",
"status": "affected",
"version": "9641458d3ec42def729fde64669abf07f3220cd5",
"versionType": "git"
},
{
"lessThan": "8d931a75a38b9bb584a4071f5ebbd52755fc35ee",
"status": "affected",
"version": "9641458d3ec42def729fde64669abf07f3220cd5",
"versionType": "git"
},
{
"lessThan": "17f78c0c0d41d738ee236eb6e841e39395188054",
"status": "affected",
"version": "9641458d3ec42def729fde64669abf07f3220cd5",
"versionType": "git"
},
{
"lessThan": "a48a889b60f73edb0399a8b08284a2ab0bd0295f",
"status": "affected",
"version": "9641458d3ec42def729fde64669abf07f3220cd5",
"versionType": "git"
},
{
"lessThan": "25e3641beb51333bfbb155af2fd2573a61113af2",
"status": "affected",
"version": "9641458d3ec42def729fde64669abf07f3220cd5",
"versionType": "git"
},
{
"lessThan": "0f71f852a96af9685858ce59fda34ecbf85c283d",
"status": "affected",
"version": "9641458d3ec42def729fde64669abf07f3220cd5",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/phonet/pep.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.28"
},
{
"lessThan": "2.6.28",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.28",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nphonet: pep: fix use-after-free in pep_get_sb()\n\npep_get_sb() doesn\u0027t consider that pskb_may_pull() might have relocated\nthe skb data, and continue to access the older pointer, causing UAF.\n\nReproduced under KASAN:\n\n BUG: KASAN: slab-use-after-free in pep_get_sb+0x234/0x3b0\n Read of size 1 at addr ff11000105510f50 by task repro/157\n pep_get_sb+0x234/0x3b0\n pipe_handler_do_rcv+0x5f7/0xa10\n pep_do_rcv+0x203/0x410\n __sk_receive_skb+0x471/0x4a0\n phonet_rcv+0x5b3/0x6c0\n __netif_receive_skb+0xcc/0x1d0\n\nRefetch the header with skb_header_pointer() after pskb_may_pull(), so\nthe possibly stale pointer is no longer dereferenced. There are better\nways to solve this, but, this is the less instrusive one."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug is hit in phonet_rcv() via __netif_receive_skb() when processing inbound Phonet pipe packets on a netdev; on modem-equipped phones this path is reachable from the cellular/BT-facing modem link without local access.\nAC:L - The attacker fully controls crafted TLV sb_len values in Phonet pipe messages to deterministically force pskb_may_pull() skb head reallocation; no race or victim-specific state beyond an existing/connecting pipe socket is required.\nPR:N - Exploitation requires only delivering a malformed Phonet packet to a listening/connecting pipe endpoint; phonet_rcv() performs no authentication or capability checks before delivering to pep_do_rcv() and pep_get_sb().\nUI:N - No end-user action is needed; triggering only requires a background phonet pipe listener or an in-progress connect/accept on affected Nokia/modem platforms where phonet daemons run continuously.\nS:U - Impact is confined to kernel memory/process integrity on the affected host; successful exploitation yields local privilege escalation within the same kernel security domain, not a cross-VM or cross-container boundary escape.\nC:H - Confirmed slab use-after-free read in pep_get_sb(); stale post-realloc pointer dereference can leak adjacent heap contents and is a standard primitive for arbitrary kernel memory disclosure.\nI:H - Use-after-free on skb header memory enables heap grooming and control of freed object contents, providing a well-established path to arbitrary kernel writes and code execution beyond the immediate one-byte read.\nA:H - KASAN reproduced a slab use-after-free oops in pep_get_sb() during packet receive; even without full exploit development, malformed Phonet pipe packets can reliably panic or hang the kernel on affected systems."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:30:06.882Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c4a52cb4da8d57d060b1d52085d25147a238dac2"
},
{
"url": "https://git.kernel.org/stable/c/df198743859fefba2f824115f8151dd62d7ad6d8"
},
{
"url": "https://git.kernel.org/stable/c/1d81e19fc57a5ee55b4497d01bc0510d76fb9578"
},
{
"url": "https://git.kernel.org/stable/c/8d931a75a38b9bb584a4071f5ebbd52755fc35ee"
},
{
"url": "https://git.kernel.org/stable/c/17f78c0c0d41d738ee236eb6e841e39395188054"
},
{
"url": "https://git.kernel.org/stable/c/a48a889b60f73edb0399a8b08284a2ab0bd0295f"
},
{
"url": "https://git.kernel.org/stable/c/25e3641beb51333bfbb155af2fd2573a61113af2"
},
{
"url": "https://git.kernel.org/stable/c/0f71f852a96af9685858ce59fda34ecbf85c283d"
}
],
"title": "phonet: pep: fix use-after-free in pep_get_sb()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68144",
"datePublished": "2026-08-10T11:59:08.437Z",
"dateReserved": "2026-07-30T09:28:09.370Z",
"dateUpdated": "2026-08-19T16:30:06.882Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68108 (GCVE-0-2026-68108)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-19 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu/vce: fix integer overflow in image size
Fix a security vulnerability where malicious VCE command streams
with oversized dimensions (e.g. 65536×65536) cause 32-bit integer
overflow, wrapping the calculated buffer size to 0. This bypasses
validation and allows GPU firmware to perform out-of-bound memory
access.
The fix uses 64-bit arithmetic to detect overflow and rejects
invalid dimensions before they reach the hardware.
V2: remove redundant check
V3: modify max height value
V4: remove size64
(cherry picked from commit cbe408dba581755ad1279a487ec786d8927d778d)
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: f1689ec1b0b1256d0e69653cd4aaeee44aafdf5c Version: f1689ec1b0b1256d0e69653cd4aaeee44aafdf5c Version: f1689ec1b0b1256d0e69653cd4aaeee44aafdf5c Version: f1689ec1b0b1256d0e69653cd4aaeee44aafdf5c Version: f1689ec1b0b1256d0e69653cd4aaeee44aafdf5c Version: f1689ec1b0b1256d0e69653cd4aaeee44aafdf5c |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/amdgpu_vce.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "893db20383800cfe92e638705984eebb13bc81a5",
"status": "affected",
"version": "f1689ec1b0b1256d0e69653cd4aaeee44aafdf5c",
"versionType": "git"
},
{
"lessThan": "a07430abd556de3707adfcadcc60db3fa64e4b2b",
"status": "affected",
"version": "f1689ec1b0b1256d0e69653cd4aaeee44aafdf5c",
"versionType": "git"
},
{
"lessThan": "a6d7065b91a14790980ce6f4960db0ca8c3c9940",
"status": "affected",
"version": "f1689ec1b0b1256d0e69653cd4aaeee44aafdf5c",
"versionType": "git"
},
{
"lessThan": "7eebef042c12dfe0568593ee6a8926d16505925e",
"status": "affected",
"version": "f1689ec1b0b1256d0e69653cd4aaeee44aafdf5c",
"versionType": "git"
},
{
"lessThan": "00c311a13d225266800c712f2b7db2711c6897de",
"status": "affected",
"version": "f1689ec1b0b1256d0e69653cd4aaeee44aafdf5c",
"versionType": "git"
},
{
"lessThan": "186bfdc4e26d019b2e7570cb121964a1d89b2e5b",
"status": "affected",
"version": "f1689ec1b0b1256d0e69653cd4aaeee44aafdf5c",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/amdgpu_vce.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.2"
},
{
"lessThan": "4.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/vce: fix integer overflow in image size\n\nFix a security vulnerability where malicious VCE command streams\nwith oversized dimensions (e.g. 65536\u00d765536) cause 32-bit integer\noverflow, wrapping the calculated buffer size to 0. This bypasses\nvalidation and allows GPU firmware to perform out-of-bound memory\naccess.\n\nThe fix uses 64-bit arithmetic to detect overflow and rejects\ninvalid dimensions before they reach the hardware.\n\nV2: remove redundant check\nV3: modify max height value\nV4: remove size64\n\n(cherry picked from commit cbe408dba581755ad1279a487ec786d8927d778d)"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The flaw is reached only through the AMDGPU_CS DRM ioctl on a local render node (/dev/dri/renderD*); there is no network, adjacent-radio, or physical-device path to the VCE command-stream parser.\nAC:L - On affected AMD GPUs using physical-mode VCE parsing, an attacker fully controls the IB and can set create-command dimensions (e.g., 65536x65536) to deterministically overflow the 32-bit size to zero without races or uncontrollable layout conditions.\nPR:L - Exploitation requires only unprivileged local access to the amdgpu DRM render node; AMDGPU_CS is gated by DRM_AUTH|DRM_RENDER_ALLOW with no root, DRM-master, or non-namespace capability requirement.\nUI:N - No victim interaction is needed beyond the attacker submitting crafted VCE command buffers through their own render-node context; no third party must open files or take other actions.\nS:C - Bypassing size-based BO relocation/validation lets VCE firmware DMA outside the intended buffer boundaries, crossing the GPU memory-isolation boundary that kernel validation is meant to enforce on GART/VRAM mappings.\nC:H - With validation defeated, VCE firmware can read arbitrarily beyond undersized encode/context/MV buffers, exposing other GPU-accessible memory including GTT-mapped system memory and adjacent VRAM allocations.\nI:H - The same out-of-bounds VCE firmware accesses enable arbitrary writes to GPU-mapped memory beyond validated buffers, providing memory-corruption primitives suitable for privilege escalation or control-flow influence.\nA:H - Oversized VCE operations against undersized buffers can trigger GPU page faults, engine hangs, GPU resets, or broader system disruption that the attacker can repeat via further command submissions."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:29:22.109Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/893db20383800cfe92e638705984eebb13bc81a5"
},
{
"url": "https://git.kernel.org/stable/c/a07430abd556de3707adfcadcc60db3fa64e4b2b"
},
{
"url": "https://git.kernel.org/stable/c/a6d7065b91a14790980ce6f4960db0ca8c3c9940"
},
{
"url": "https://git.kernel.org/stable/c/7eebef042c12dfe0568593ee6a8926d16505925e"
},
{
"url": "https://git.kernel.org/stable/c/00c311a13d225266800c712f2b7db2711c6897de"
},
{
"url": "https://git.kernel.org/stable/c/186bfdc4e26d019b2e7570cb121964a1d89b2e5b"
}
],
"title": "drm/amdgpu/vce: fix integer overflow in image size",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68108",
"datePublished": "2026-08-10T11:58:25.241Z",
"dateReserved": "2026-07-30T09:28:09.368Z",
"dateUpdated": "2026-08-19T16:29:22.109Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64280 (GCVE-0-2026-64280)
Vulnerability from cvelistv5
Published
2026-07-25 08:49
Modified
2026-08-23 12:45
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region()
afu_ioctl_dma_map() accepts a 64-bit length from userspace via
DFL_FPGA_PORT_DMA_MAP ioctl without an upper bound check. The value
is passed to afu_dma_pin_pages() where npages is derived as
length >> PAGE_SHIFT and passed to pin_user_pages_fast() which takes
int nr_pages, causing implicit truncation if length is very large.
Validate map.length at the ioctl entry point before calling
afu_dma_map_region(), rejecting values whose page count exceeds
INT_MAX.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: fa8dda1edef9ebc3af467c644c5533ac97171e12 Version: fa8dda1edef9ebc3af467c644c5533ac97171e12 Version: fa8dda1edef9ebc3af467c644c5533ac97171e12 Version: fa8dda1edef9ebc3af467c644c5533ac97171e12 Version: fa8dda1edef9ebc3af467c644c5533ac97171e12 Version: fa8dda1edef9ebc3af467c644c5533ac97171e12 Version: fa8dda1edef9ebc3af467c644c5533ac97171e12 Version: fa8dda1edef9ebc3af467c644c5533ac97171e12 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/fpga/dfl-afu-main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "5352d488ce4ae5e8c68c080ad4c3a5f084ad5fbc",
"status": "affected",
"version": "fa8dda1edef9ebc3af467c644c5533ac97171e12",
"versionType": "git"
},
{
"lessThan": "d7e787eee2ea619b6dbb98890472ee73daf2e7fd",
"status": "affected",
"version": "fa8dda1edef9ebc3af467c644c5533ac97171e12",
"versionType": "git"
},
{
"lessThan": "a6a3884ff500f04f3088d6d09eec803cd35331a2",
"status": "affected",
"version": "fa8dda1edef9ebc3af467c644c5533ac97171e12",
"versionType": "git"
},
{
"lessThan": "16381bda90b261a656ded0568630c1b857b2ebc8",
"status": "affected",
"version": "fa8dda1edef9ebc3af467c644c5533ac97171e12",
"versionType": "git"
},
{
"lessThan": "b50e6cd2395cde615f59b624819998d28c0668d6",
"status": "affected",
"version": "fa8dda1edef9ebc3af467c644c5533ac97171e12",
"versionType": "git"
},
{
"lessThan": "59070040fd12e0b78d7b4d341d9f9a183237c5ff",
"status": "affected",
"version": "fa8dda1edef9ebc3af467c644c5533ac97171e12",
"versionType": "git"
},
{
"lessThan": "fb2c0eab51ae5b02d2bae7d67c2cfbec39b57231",
"status": "affected",
"version": "fa8dda1edef9ebc3af467c644c5533ac97171e12",
"versionType": "git"
},
{
"lessThan": "fc3b071a7c8dc0f5d56defddf6e6fd5aaa3e1e27",
"status": "affected",
"version": "fa8dda1edef9ebc3af467c644c5533ac97171e12",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/fpga/dfl-afu-main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.19"
},
{
"lessThan": "4.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfpga: dfl-afu: validate DMA mapping length in afu_dma_map_region()\n\nafu_ioctl_dma_map() accepts a 64-bit length from userspace via\nDFL_FPGA_PORT_DMA_MAP ioctl without an upper bound check. The value\nis passed to afu_dma_pin_pages() where npages is derived as\nlength \u003e\u003e PAGE_SHIFT and passed to pin_user_pages_fast() which takes\nint nr_pages, causing implicit truncation if length is very large.\n\nValidate map.length at the ioctl entry point before calling\nafu_dma_map_region(), rejecting values whose page count exceeds\nINT_MAX."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable path is reached locally through DFL_FPGA_PORT_DMA_MAP on a /dev/dfl-port.* character device.\nAC:L - A page-aligned length whose page count wraps to zero or a small positive integer deterministically triggers the mismatch; no race or condition outside the attacker\u2019s control is required.\nPR:L - The ioctl contains no capability or namespace privilege check, so any unprivileged user granted access to the port device can trigger it.\nUI:N - The attacker independently opens the device and submits the malicious ioctl without any victim action.\nS:C - The oversized DMA mapping can cross the IOMMU-enforced boundary between the assigned user buffer and host physical memory, affecting kernel and other-user resources.\nC:H - A small positive page-count wrap can create an enormous DMA-readable mapping after pinning only a few pages, exposing host memory beyond the authorized buffer; teardown also performs unbounded out-of-bounds pointer reads.\nI:H - The mapping is DMA_BIDIRECTIONAL, permitting writes beyond the pinned buffer, while the oversized unpin operation can corrupt unrelated page reference counts through out-of-bounds page pointers.\nA:H - A zero page-count wrap causes a deterministic pages[0] dereference from a zero-sized allocation, while other wrapped counts can produce an unbounded unpin traversal and kernel crash."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:45:39.157Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/5352d488ce4ae5e8c68c080ad4c3a5f084ad5fbc"
},
{
"url": "https://git.kernel.org/stable/c/d7e787eee2ea619b6dbb98890472ee73daf2e7fd"
},
{
"url": "https://git.kernel.org/stable/c/a6a3884ff500f04f3088d6d09eec803cd35331a2"
},
{
"url": "https://git.kernel.org/stable/c/16381bda90b261a656ded0568630c1b857b2ebc8"
},
{
"url": "https://git.kernel.org/stable/c/b50e6cd2395cde615f59b624819998d28c0668d6"
},
{
"url": "https://git.kernel.org/stable/c/59070040fd12e0b78d7b4d341d9f9a183237c5ff"
},
{
"url": "https://git.kernel.org/stable/c/fb2c0eab51ae5b02d2bae7d67c2cfbec39b57231"
},
{
"url": "https://git.kernel.org/stable/c/fc3b071a7c8dc0f5d56defddf6e6fd5aaa3e1e27"
}
],
"title": "fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64280",
"datePublished": "2026-07-25T08:49:23.753Z",
"dateReserved": "2026-07-19T15:36:31.777Z",
"dateUpdated": "2026-08-23T12:45:39.157Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68121 (GCVE-0-2026-68121)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-19 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
pppoe: reload header pointer after dev_hard_header()
pppoe_sendmsg() saves a pointer to the PPPoE header before calling
dev_hard_header(). Device header callbacks are allowed to reallocate the
skb head, invalidating pointers into it.
This can happen when a send is blocked in copy_from_user() while the first
non-Ethernet port is added to an empty team device. The team's delegated
GRE header callback then expands the skb head. PPPoE subsequently writes
six bytes through the stale pointer into the freed head.
Reload the PPPoE header through the skb's network-header offset after
device header creation. pskb_expand_head() updates that offset when it
relocates the head.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ppp/pppoe.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "7a56e7c9b08e08fd55a1bcada24cf4fe3782b722",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "6eed5ae7887a93160803d2b81ff88e75eefd4a4c",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "ba3409369c5413cdf0dcbf3a928f76b48e8c3e6a",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "e6493a4d1ee17595766165fa446d45b7e0c318d0",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "7e9fbd7f96bcde63a7c798fe16b38cedee7a1501",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "6866abf59976d273164a6624234d96a967280223",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "bed4caecd723693f750e13adbb2c42ca1249a3fd",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "e9c238f6fe42fb1b4dba3a578277de32cb487937",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ppp/pppoe.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\npppoe: reload header pointer after dev_hard_header()\n\npppoe_sendmsg() saves a pointer to the PPPoE header before calling\ndev_hard_header(). Device header callbacks are allowed to reallocate the\nskb head, invalidating pointers into it.\n\nThis can happen when a send is blocked in copy_from_user() while the first\nnon-Ethernet port is added to an empty team device. The team\u0027s delegated\nGRE header callback then expands the skb head. PPPoE subsequently writes\nsix bytes through the stale pointer into the freed head.\n\nReload the PPPoE header through the skb\u0027s network-header offset after\ndevice header creation. pskb_expand_head() updates that offset when it\nrelocates the head."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is in pppoe_sendmsg(), reached only via the local sendmsg() syscall on a PF_PPPOX/PPPoE socket; it is not triggered by remote packet reception or in-kernel PPP transmit paths such as __pppoe_xmit().\nAC:L - Exploitation requires a race between copy_from_user() blocking in sendmsg and changing team header_ops (e.g., adding the first non-Ethernet GRE port), which an attacker can drive with concurrent threads and retries rather than uncontrollable timing.\nPR:L - PPPoE sockets can be created without special privileges, and configuring the team/GRE topology needed to trigger dev_hard_header() head expansion is achievable with CAP_NET_ADMIN inside an unprivileged user/network namespace (unshare -Urn).\nUI:N - No victim interaction is required; exploitation is fully attacker-driven through socket I/O and netlink/rtnl configuration of the team device.\nS:U - Impact is kernel heap corruption and privilege escalation within the same kernel security authority, not a cross-boundary escape such as guest-to-host VM breakout or IOMMU bypass.\nC:H - Writing PPPoE header fields through a stale pointer after pskb_expand_head() frees the old skb head is a slab use-after-free; freed kmalloc objects can be reclaimed for sensitive data, enabling arbitrary kernel memory disclosure.\nI:H - The post-dev_hard_header() memcpy/ph-\u003elength stores up to eight attacker-influenced bytes into freed skb head memory, providing a heap corruption primitive that can be developed into arbitrary kernel writes or code execution.\nA:H - Use-after-free writes into freed slab memory commonly cause kernel oops/panic and can be triggered repeatedly via sendmsg, yielding persistent denial of service even when full exploitation is not attempted."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:29:31.935Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/7a56e7c9b08e08fd55a1bcada24cf4fe3782b722"
},
{
"url": "https://git.kernel.org/stable/c/6eed5ae7887a93160803d2b81ff88e75eefd4a4c"
},
{
"url": "https://git.kernel.org/stable/c/ba3409369c5413cdf0dcbf3a928f76b48e8c3e6a"
},
{
"url": "https://git.kernel.org/stable/c/e6493a4d1ee17595766165fa446d45b7e0c318d0"
},
{
"url": "https://git.kernel.org/stable/c/7e9fbd7f96bcde63a7c798fe16b38cedee7a1501"
},
{
"url": "https://git.kernel.org/stable/c/6866abf59976d273164a6624234d96a967280223"
},
{
"url": "https://git.kernel.org/stable/c/bed4caecd723693f750e13adbb2c42ca1249a3fd"
},
{
"url": "https://git.kernel.org/stable/c/e9c238f6fe42fb1b4dba3a578277de32cb487937"
}
],
"title": "pppoe: reload header pointer after dev_hard_header()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68121",
"datePublished": "2026-08-10T11:58:41.489Z",
"dateReserved": "2026-07-30T09:28:09.369Z",
"dateUpdated": "2026-08-19T16:29:31.935Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68346 (GCVE-0-2026-68346)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-17 05:03
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ALSA: hda: cs35l41: validate and free ACPI mute object
cs35l41_get_acpi_mute_state() evaluates a _DSM method to get the ACPI
mute state and reads the first byte from the returned object.
However, the returned ACPI object is owned by the caller and is never
freed after use, so each successful query leaks the _DSM result object.
The code also assumes that the returned object is a buffer with at least
one byte. A malformed firmware response can return a different object
type or an empty buffer, and the direct ret->buffer.pointer dereference
can then access an invalid pointer.
Use the typed _DSM helper, validate that the returned buffer contains at
least one byte, and free the ACPI object after reading it.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"sound/hda/codecs/side-codecs/cs35l41_hda.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "7fea0c89ed39a13d9a31163a74f8c62de30a4ffc",
"status": "affected",
"version": "447106e92a0c86c332d40710436f38f64c322cd6",
"versionType": "git"
},
{
"lessThan": "08433c71f15984ddd5f5a307cf3f0aa9b84583aa",
"status": "affected",
"version": "447106e92a0c86c332d40710436f38f64c322cd6",
"versionType": "git"
},
{
"lessThan": "d5dfdf43259ad9d054052012095b1630e7366dcf",
"status": "affected",
"version": "447106e92a0c86c332d40710436f38f64c322cd6",
"versionType": "git"
},
{
"lessThan": "3b597d24dc0455ae926f1053f97c2725038fc3cd",
"status": "affected",
"version": "447106e92a0c86c332d40710436f38f64c322cd6",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"sound/hda/codecs/side-codecs/cs35l41_hda.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.7"
},
{
"lessThan": "6.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: hda: cs35l41: validate and free ACPI mute object\n\ncs35l41_get_acpi_mute_state() evaluates a _DSM method to get the ACPI\nmute state and reads the first byte from the returned object.\n\nHowever, the returned ACPI object is owned by the caller and is never\nfreed after use, so each successful query leaks the _DSM result object.\n\nThe code also assumes that the returned object is a buffer with at least\none byte. A malformed firmware response can return a different object\ntype or an empty buffer, and the direct ret-\u003ebuffer.pointer dereference\ncan then access an invalid pointer.\n\nUse the typed _DSM helper, validate that the returned buffer contains at\nleast one byte, and free the ACPI object after reading it."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:03:46.731Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/7fea0c89ed39a13d9a31163a74f8c62de30a4ffc"
},
{
"url": "https://git.kernel.org/stable/c/08433c71f15984ddd5f5a307cf3f0aa9b84583aa"
},
{
"url": "https://git.kernel.org/stable/c/d5dfdf43259ad9d054052012095b1630e7366dcf"
},
{
"url": "https://git.kernel.org/stable/c/3b597d24dc0455ae926f1053f97c2725038fc3cd"
}
],
"title": "ALSA: hda: cs35l41: validate and free ACPI mute object",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68346",
"datePublished": "2026-08-10T12:03:23.079Z",
"dateReserved": "2026-07-30T09:28:09.384Z",
"dateUpdated": "2026-08-17T05:03:46.731Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68406 (GCVE-0-2026-68406)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: cfg80211: validate PMSR FTM preamble range
PMSR FTM request parsing accepts preamble values outside the
enumerated nl80211 preamble range.
Reject out-of-range values before using them in the parser capability
bit test using the policy.
[drop unnecessary check]
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 9bb7e0f24e7e7d00daa1219b14539e2e602649b2 Version: 9bb7e0f24e7e7d00daa1219b14539e2e602649b2 Version: 9bb7e0f24e7e7d00daa1219b14539e2e602649b2 Version: 9bb7e0f24e7e7d00daa1219b14539e2e602649b2 Version: 9bb7e0f24e7e7d00daa1219b14539e2e602649b2 Version: 9bb7e0f24e7e7d00daa1219b14539e2e602649b2 Version: 9bb7e0f24e7e7d00daa1219b14539e2e602649b2 Version: 9bb7e0f24e7e7d00daa1219b14539e2e602649b2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/wireless/nl80211.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "73ada9f23c2c7fac74474ea2a38ceb265bae17f1",
"status": "affected",
"version": "9bb7e0f24e7e7d00daa1219b14539e2e602649b2",
"versionType": "git"
},
{
"lessThan": "2b97fa1bce7731f6a244f3d4407c61858f09b93f",
"status": "affected",
"version": "9bb7e0f24e7e7d00daa1219b14539e2e602649b2",
"versionType": "git"
},
{
"lessThan": "9b33f260db3971f572dda0b45dd28d477cf51ed1",
"status": "affected",
"version": "9bb7e0f24e7e7d00daa1219b14539e2e602649b2",
"versionType": "git"
},
{
"lessThan": "44ea65d779e2d23b2264fea6af2d0c666a3ec9fb",
"status": "affected",
"version": "9bb7e0f24e7e7d00daa1219b14539e2e602649b2",
"versionType": "git"
},
{
"lessThan": "922d71fbaf99c1d5318151a0cb0a42ad448d07d9",
"status": "affected",
"version": "9bb7e0f24e7e7d00daa1219b14539e2e602649b2",
"versionType": "git"
},
{
"lessThan": "cfbda103aeae61071a122a6fc2bfe98cffbd7165",
"status": "affected",
"version": "9bb7e0f24e7e7d00daa1219b14539e2e602649b2",
"versionType": "git"
},
{
"lessThan": "58320cb47df2accc7a20bb72c0150280732fa58f",
"status": "affected",
"version": "9bb7e0f24e7e7d00daa1219b14539e2e602649b2",
"versionType": "git"
},
{
"lessThan": "36230936468f0ba4930e94aef496fc229d4bb951",
"status": "affected",
"version": "9bb7e0f24e7e7d00daa1219b14539e2e602649b2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/wireless/nl80211.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.0"
},
{
"lessThan": "5.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: cfg80211: validate PMSR FTM preamble range\n\nPMSR FTM request parsing accepts preamble values outside the\nenumerated nl80211 preamble range.\n\nReject out-of-range values before using them in the parser capability\nbit test using the policy.\n\n[drop unnecessary check]"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:59.823Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/73ada9f23c2c7fac74474ea2a38ceb265bae17f1"
},
{
"url": "https://git.kernel.org/stable/c/2b97fa1bce7731f6a244f3d4407c61858f09b93f"
},
{
"url": "https://git.kernel.org/stable/c/9b33f260db3971f572dda0b45dd28d477cf51ed1"
},
{
"url": "https://git.kernel.org/stable/c/44ea65d779e2d23b2264fea6af2d0c666a3ec9fb"
},
{
"url": "https://git.kernel.org/stable/c/922d71fbaf99c1d5318151a0cb0a42ad448d07d9"
},
{
"url": "https://git.kernel.org/stable/c/cfbda103aeae61071a122a6fc2bfe98cffbd7165"
},
{
"url": "https://git.kernel.org/stable/c/58320cb47df2accc7a20bb72c0150280732fa58f"
},
{
"url": "https://git.kernel.org/stable/c/36230936468f0ba4930e94aef496fc229d4bb951"
}
],
"title": "wifi: cfg80211: validate PMSR FTM preamble range",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68406",
"datePublished": "2026-08-10T12:04:26.251Z",
"dateReserved": "2026-07-30T09:28:09.390Z",
"dateUpdated": "2026-08-19T16:34:59.823Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68210 (GCVE-0-2026-68210)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: stm32: dcmi: unregister notifier on probe failure
dcmi_graph_init() registers the async notifier before dcmi_probe() toggles
the reset line. If reset_control_assert() or reset_control_deassert()
fails afterwards, probe returns through err_cleanup and the driver core
will not call dcmi_remove().
Unregister the notifier before cleaning it up on that error path,
matching the successful remove path and the V4L2 async notifier lifetime
rules.
[hverkuil: added Fixes tag]
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d079f94c90469f413920b9f2b201537fac2ceb06 Version: d079f94c90469f413920b9f2b201537fac2ceb06 Version: d079f94c90469f413920b9f2b201537fac2ceb06 Version: d079f94c90469f413920b9f2b201537fac2ceb06 Version: d079f94c90469f413920b9f2b201537fac2ceb06 Version: d079f94c90469f413920b9f2b201537fac2ceb06 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/platform/st/stm32/stm32-dcmi.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "222a9301b086852b90d3b092fef436c3f4e927c4",
"status": "affected",
"version": "d079f94c90469f413920b9f2b201537fac2ceb06",
"versionType": "git"
},
{
"lessThan": "37ff63c5d7119cbc5c6bacdcc658add6008a8e1f",
"status": "affected",
"version": "d079f94c90469f413920b9f2b201537fac2ceb06",
"versionType": "git"
},
{
"lessThan": "6c6f22b7e6cbc4e8c1e359fc9b190419391c3db7",
"status": "affected",
"version": "d079f94c90469f413920b9f2b201537fac2ceb06",
"versionType": "git"
},
{
"lessThan": "931abe1deb65b919d23fa203d7f6d6fbd4fccd8e",
"status": "affected",
"version": "d079f94c90469f413920b9f2b201537fac2ceb06",
"versionType": "git"
},
{
"lessThan": "4b7ee504969e074725e439c949f2483e5fa5572a",
"status": "affected",
"version": "d079f94c90469f413920b9f2b201537fac2ceb06",
"versionType": "git"
},
{
"lessThan": "084973ebd67b28f0945c5d45408f86c58b540110",
"status": "affected",
"version": "d079f94c90469f413920b9f2b201537fac2ceb06",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/platform/st/stm32/stm32-dcmi.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.20"
},
{
"lessThan": "4.20",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.20",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: stm32: dcmi: unregister notifier on probe failure\n\ndcmi_graph_init() registers the async notifier before dcmi_probe() toggles\nthe reset line. If reset_control_assert() or reset_control_deassert()\nfails afterwards, probe returns through err_cleanup and the driver core\nwill not call dcmi_remove().\n\nUnregister the notifier before cleaning it up on that error path,\nmatching the successful remove path and the V4L2 async notifier lifetime\nrules.\n\n[hverkuil: added Fixes tag]"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The affected code is a platform camera-interface driver probe path on STM32 SoCs; it is reached only through local device/driver binding on the machine itself, with the resulting dangling notifier consumed by in-kernel V4L2 subdev registration. No network or remote data path reaches this code.\nAC:L - Once the driver has probe-failed on the reset line, the stale notifier remains on the global v4l2 notifier_list indefinitely, and any subsequent subdev registration deterministically walks the freed object; no race or unpredictable memory layout must be won to reach the freed dereference.\nPR:L - A local user account on the device is sufficient to interact with the media/V4L2 stack and trigger subdev registration paths that walk the corrupted global notifier list; no root or administrative capability is needed to consume the dangling pointer.\nUI:N - The stale notifier is left behind automatically by the failing probe path and is dereferenced by kernel-internal V4L2 async registration; no victim action such as opening a file or mounting a filesystem is required.\nS:U - The freed memory, the corrupted list, and the resulting impact are all within the kernel\u0027s own security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - The devm-allocated stm32_dcmi object containing the notifier is freed while still linked into the global notifier_list, so reallocated heap contents are read back as notifier state and traversed as list pointers, which can be leveraged to disclose kernel memory.\nI:H - Traversal and eventual list_del of the freed notifier_entry performs writes through attacker-influenceable heap contents, giving a use-after-free list-corruption primitive that can be shaped into an arbitrary write and control-flow hijack.\nA:H - Dereferencing and unlinking a freed notifier from the global list reliably produces list corruption and an oops or panic in the V4L2 async core, taking down the kernel."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:34.517Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/222a9301b086852b90d3b092fef436c3f4e927c4"
},
{
"url": "https://git.kernel.org/stable/c/37ff63c5d7119cbc5c6bacdcc658add6008a8e1f"
},
{
"url": "https://git.kernel.org/stable/c/6c6f22b7e6cbc4e8c1e359fc9b190419391c3db7"
},
{
"url": "https://git.kernel.org/stable/c/931abe1deb65b919d23fa203d7f6d6fbd4fccd8e"
},
{
"url": "https://git.kernel.org/stable/c/4b7ee504969e074725e439c949f2483e5fa5572a"
},
{
"url": "https://git.kernel.org/stable/c/084973ebd67b28f0945c5d45408f86c58b540110"
}
],
"title": "media: stm32: dcmi: unregister notifier on probe failure",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68210",
"datePublished": "2026-08-10T12:00:29.515Z",
"dateReserved": "2026-07-30T09:28:09.375Z",
"dateUpdated": "2026-08-19T16:31:34.517Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68102 (GCVE-0-2026-68102)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-17 04:58
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: fix aperture mapping leak
amdgpu_pci_remove() calls drm_dev_unplug() before invoking the driver
fini routines. This causes drm_dev_enter() in amdgpu_ttm_fini() to
always return false, so iounmap(aper_base_kaddr) never runs on normal
driver unload, leaving an orphaned entry in the x86 PAT interval tree.
On connected_to_cpu hardware, the aperture is mapped write-back (WB) via
ioremap_cache(). On reload, IP discovery calls memremap(..., MEMREMAP_WC)
over the same range. The WC vs WB conflict causes:
ioremap error for 0x..., requested 0x1, got 0x0
amdgpu: discovery failed: -2
Fix by switching to devres-managed mappings so cleanup is guaranteed
regardless of drm_dev_enter() state:
- connected_to_cpu path: devm_memremap(MEMREMAP_WB). For
IORESOURCE_SYSTEM_RAM ranges this takes the try_ram_remap() shortcut,
returning __va(offset) from the existing kernel direct map. No new
ioremap VA or PAT entry is created, so there is nothing to orphan.
- dGPU path: devm_ioremap_wc() registers iounmap() as a devres action,
guaranteeing cleanup at device_del() time.
Also remove iounmap(aper_base_kaddr) from amdgpu_device_unmap_mmio()
since the mapping is now devres-owned.
v2: Remove redundant x86_64 guard (Lijo)
(cherry picked from commit d871e99879cb5fd1fa798b006b4888887e63a17a)
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/amdgpu_device.c",
"drivers/gpu/drm/amd/amdgpu/amdgpu_ttm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "67bc3647e418e23dc0d17604bdba634a73de809f",
"status": "affected",
"version": "9d0af8b4def0de6b734ec8db08e96da0458facb6",
"versionType": "git"
},
{
"lessThan": "a343d028ad6c174da8dc6af560c51e6d140a6727",
"status": "affected",
"version": "9d0af8b4def0de6b734ec8db08e96da0458facb6",
"versionType": "git"
},
{
"lessThan": "6405c4e75b3bcf0e72bd7a0ff5f1ed0c475e23aa",
"status": "affected",
"version": "9d0af8b4def0de6b734ec8db08e96da0458facb6",
"versionType": "git"
},
{
"lessThan": "f5988b5c300a32ff751724ffd33d5a8d5873e4a7",
"status": "affected",
"version": "9d0af8b4def0de6b734ec8db08e96da0458facb6",
"versionType": "git"
},
{
"lessThan": "ea772a440d56b285f4d491affac50ecd41f6b402",
"status": "affected",
"version": "9d0af8b4def0de6b734ec8db08e96da0458facb6",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/amdgpu_device.c",
"drivers/gpu/drm/amd/amdgpu/amdgpu_ttm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.13"
},
{
"lessThan": "5.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: fix aperture mapping leak\n\namdgpu_pci_remove() calls drm_dev_unplug() before invoking the driver\nfini routines. This causes drm_dev_enter() in amdgpu_ttm_fini() to\nalways return false, so iounmap(aper_base_kaddr) never runs on normal\ndriver unload, leaving an orphaned entry in the x86 PAT interval tree.\n\nOn connected_to_cpu hardware, the aperture is mapped write-back (WB) via\nioremap_cache(). On reload, IP discovery calls memremap(..., MEMREMAP_WC)\nover the same range. The WC vs WB conflict causes:\n\n ioremap error for 0x..., requested 0x1, got 0x0\n amdgpu: discovery failed: -2\n\nFix by switching to devres-managed mappings so cleanup is guaranteed\nregardless of drm_dev_enter() state:\n\n- connected_to_cpu path: devm_memremap(MEMREMAP_WB). For\n IORESOURCE_SYSTEM_RAM ranges this takes the try_ram_remap() shortcut,\n returning __va(offset) from the existing kernel direct map. No new\n ioremap VA or PAT entry is created, so there is nothing to orphan.\n\n- dGPU path: devm_ioremap_wc() registers iounmap() as a devres action,\n guaranteeing cleanup at device_del() time.\n\nAlso remove iounmap(aper_base_kaddr) from amdgpu_device_unmap_mmio()\nsince the mapping is now devres-owned.\n\nv2: Remove redundant x86_64 guard (Lijo)\n\n(cherry picked from commit d871e99879cb5fd1fa798b006b4888887e63a17a)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:58:50.338Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/67bc3647e418e23dc0d17604bdba634a73de809f"
},
{
"url": "https://git.kernel.org/stable/c/a343d028ad6c174da8dc6af560c51e6d140a6727"
},
{
"url": "https://git.kernel.org/stable/c/6405c4e75b3bcf0e72bd7a0ff5f1ed0c475e23aa"
},
{
"url": "https://git.kernel.org/stable/c/f5988b5c300a32ff751724ffd33d5a8d5873e4a7"
},
{
"url": "https://git.kernel.org/stable/c/ea772a440d56b285f4d491affac50ecd41f6b402"
}
],
"title": "drm/amdgpu: fix aperture mapping leak",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68102",
"datePublished": "2026-08-10T11:58:18.093Z",
"dateReserved": "2026-07-30T09:28:09.368Z",
"dateUpdated": "2026-08-17T04:58:50.338Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68429 (GCVE-0-2026-68429)
Vulnerability from cvelistv5
Published
2026-08-12 00:07
Modified
2026-08-17 05:05
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/dp_mst: Handle torn-down topology gracefully in drm_dp_mst_topology_queue_probe()
A hotplug or link-loss event can tear down the MST topology
(setting mgr->mst_state = false and mgr->mst_primary = NULL) concurrently
with a caller invoking drm_dp_mst_topology_queue_probe(). Since the check
is already performed under mgr->lock, the condition is not a programming
error but a valid race -- the topology was valid when the caller decided
to call this function, but was torn down before the lock was acquired.
Replace the drm_WARN_ON() with a graceful early return. This eliminates
spurious kernel warnings and the resulting compositor crashes observed
when connecting/disconnecting DP MST monitors, while keeping the correct
behavior of doing nothing when MST is not active. A drm_dbg_mst() trace
is added so the skipped probe remains observable under MST debug logging.
The existing WARN_ON(mgr->mst_primary) in drm_dp_mst_topology_mgr_set_mst()
already catches the case where the topology is initialized twice, so no
diagnostic coverage is lost.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 5f57a96e92c60f62da91d58ceb5e5acd40e7d594 Version: dbaeef363ea54f4c18112874b77503c72ba60fec Version: dbaeef363ea54f4c18112874b77503c72ba60fec Version: dbaeef363ea54f4c18112874b77503c72ba60fec Version: dbaeef363ea54f4c18112874b77503c72ba60fec Version: 6.6.86 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/display/drm_dp_mst_topology.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b1d05cc61dfa6c4bd5e67855bec6a03e955f512d",
"status": "affected",
"version": "5f57a96e92c60f62da91d58ceb5e5acd40e7d594",
"versionType": "git"
},
{
"lessThan": "4ed6d08c4a59ee6a8cb806347f6d9873de5d229e",
"status": "affected",
"version": "dbaeef363ea54f4c18112874b77503c72ba60fec",
"versionType": "git"
},
{
"lessThan": "8c6d84a54823cd839e6ce22af559925f1320c310",
"status": "affected",
"version": "dbaeef363ea54f4c18112874b77503c72ba60fec",
"versionType": "git"
},
{
"lessThan": "afdff9103818656627920c21822e48a6dae2906f",
"status": "affected",
"version": "dbaeef363ea54f4c18112874b77503c72ba60fec",
"versionType": "git"
},
{
"lessThan": "613059875958e7b217b250ed14c3b189f9488421",
"status": "affected",
"version": "dbaeef363ea54f4c18112874b77503c72ba60fec",
"versionType": "git"
},
{
"lessThan": "6.6.148",
"status": "affected",
"version": "6.6.86",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/display/drm_dp_mst_topology.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.12"
},
{
"lessThan": "6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.6.86",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/dp_mst: Handle torn-down topology gracefully in drm_dp_mst_topology_queue_probe()\n\nA hotplug or link-loss event can tear down the MST topology\n(setting mgr-\u003emst_state = false and mgr-\u003emst_primary = NULL) concurrently\nwith a caller invoking drm_dp_mst_topology_queue_probe(). Since the check\nis already performed under mgr-\u003elock, the condition is not a programming\nerror but a valid race -- the topology was valid when the caller decided\nto call this function, but was torn down before the lock was acquired.\n\nReplace the drm_WARN_ON() with a graceful early return. This eliminates\nspurious kernel warnings and the resulting compositor crashes observed\nwhen connecting/disconnecting DP MST monitors, while keeping the correct\nbehavior of doing nothing when MST is not active. A drm_dbg_mst() trace\nis added so the skipped probe remains observable under MST debug logging.\n\nThe existing WARN_ON(mgr-\u003emst_primary) in drm_dp_mst_topology_mgr_set_mst()\nalready catches the case where the topology is initialized twice, so no\ndiagnostic coverage is lost."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:05:25.387Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b1d05cc61dfa6c4bd5e67855bec6a03e955f512d"
},
{
"url": "https://git.kernel.org/stable/c/4ed6d08c4a59ee6a8cb806347f6d9873de5d229e"
},
{
"url": "https://git.kernel.org/stable/c/8c6d84a54823cd839e6ce22af559925f1320c310"
},
{
"url": "https://git.kernel.org/stable/c/afdff9103818656627920c21822e48a6dae2906f"
},
{
"url": "https://git.kernel.org/stable/c/613059875958e7b217b250ed14c3b189f9488421"
}
],
"title": "drm/dp_mst: Handle torn-down topology gracefully in drm_dp_mst_topology_queue_probe()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68429",
"datePublished": "2026-08-12T00:07:14.640Z",
"dateReserved": "2026-07-30T09:28:09.393Z",
"dateUpdated": "2026-08-17T05:05:25.387Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68203 (GCVE-0-2026-68203)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-17 05:00
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: vivid: fix cleanup bugs in vivid_init()
When platform_device_register() fails in vivid_init(), the embedded
struct device in vivid_pdev has already been initialized by
device_initialize(), but the failure path jumps to free_output_strings
without dropping the device reference for the current platform device:
vivid_init()
-> platform_device_register(&vivid_pdev)
-> device_initialize(&vivid_pdev.dev)
-> setup_pdev_dma_masks(&vivid_pdev)
-> platform_device_add(&vivid_pdev)
This leads to a reference leak when platform_device_register() fails.
Fix this by calling platform_device_put() before jumping to the common
cleanup path.
Also, the unreg_driver label incorrectly calls
platform_driver_register() instead of platform_driver_unregister(),
which breaks cleanup when workqueue creation fails after successful
driver registration. Fix that as well.
The reference leak was identified by a static analysis tool I developed
and confirmed by manual review. The incorrect cleanup call was found
during code inspection.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/test-drivers/vivid/vivid-core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "4385092a86b94e1f332db35a3766108978c0722f",
"status": "affected",
"version": "f46d740fb0258982f00ffdbddc6486e674edafb5",
"versionType": "git"
},
{
"lessThan": "1349af7f87df57940619f5b87990b799dac9ed8a",
"status": "affected",
"version": "f46d740fb0258982f00ffdbddc6486e674edafb5",
"versionType": "git"
},
{
"lessThan": "6d51ad8f1c50c50d1abcc97fd243179967184c6a",
"status": "affected",
"version": "f46d740fb0258982f00ffdbddc6486e674edafb5",
"versionType": "git"
},
{
"lessThan": "a07c179a92e949172ca52f6d4a13202ea88cd4b7",
"status": "affected",
"version": "f46d740fb0258982f00ffdbddc6486e674edafb5",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/test-drivers/vivid/vivid-core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.1"
},
{
"lessThan": "4.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: vivid: fix cleanup bugs in vivid_init()\n\nWhen platform_device_register() fails in vivid_init(), the embedded\nstruct device in vivid_pdev has already been initialized by\ndevice_initialize(), but the failure path jumps to free_output_strings\nwithout dropping the device reference for the current platform device:\n\n vivid_init()\n -\u003e platform_device_register(\u0026vivid_pdev)\n -\u003e device_initialize(\u0026vivid_pdev.dev)\n -\u003e setup_pdev_dma_masks(\u0026vivid_pdev)\n -\u003e platform_device_add(\u0026vivid_pdev)\n\nThis leads to a reference leak when platform_device_register() fails.\nFix this by calling platform_device_put() before jumping to the common\ncleanup path.\n\nAlso, the unreg_driver label incorrectly calls\nplatform_driver_register() instead of platform_driver_unregister(),\nwhich breaks cleanup when workqueue creation fails after successful\ndriver registration. Fix that as well.\n\nThe reference leak was identified by a static analysis tool I developed\nand confirmed by manual review. The incorrect cleanup call was found\nduring code inspection."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:00:47.012Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/4385092a86b94e1f332db35a3766108978c0722f"
},
{
"url": "https://git.kernel.org/stable/c/1349af7f87df57940619f5b87990b799dac9ed8a"
},
{
"url": "https://git.kernel.org/stable/c/6d51ad8f1c50c50d1abcc97fd243179967184c6a"
},
{
"url": "https://git.kernel.org/stable/c/a07c179a92e949172ca52f6d4a13202ea88cd4b7"
}
],
"title": "media: vivid: fix cleanup bugs in vivid_init()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68203",
"datePublished": "2026-08-10T12:00:22.319Z",
"dateReserved": "2026-07-30T09:28:09.374Z",
"dateUpdated": "2026-08-17T05:00:47.012Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68430 (GCVE-0-2026-68430)
Vulnerability from cvelistv5
Published
2026-08-12 00:07
Modified
2026-08-19 16:35
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu/gfx8: drop unecessary BUG_ON()
There's no need to crash the kernel for this case.
(cherry picked from commit 4d7c25208ca612b754f3bf39e9f16e725b828891)
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 4e638ae9c1e7a2b85155f2dd91c8105ce109ea7e Version: 4e638ae9c1e7a2b85155f2dd91c8105ce109ea7e Version: 4e638ae9c1e7a2b85155f2dd91c8105ce109ea7e Version: 4e638ae9c1e7a2b85155f2dd91c8105ce109ea7e Version: 4e638ae9c1e7a2b85155f2dd91c8105ce109ea7e Version: 4e638ae9c1e7a2b85155f2dd91c8105ce109ea7e Version: 4e638ae9c1e7a2b85155f2dd91c8105ce109ea7e Version: 4e638ae9c1e7a2b85155f2dd91c8105ce109ea7e |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/gfx_v8_0.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "69004f1f769f7f6e9e34f4390d98a12aa0b4ab98",
"status": "affected",
"version": "4e638ae9c1e7a2b85155f2dd91c8105ce109ea7e",
"versionType": "git"
},
{
"lessThan": "26ad939b402a754b0624840dfaeebd86d7ff2a22",
"status": "affected",
"version": "4e638ae9c1e7a2b85155f2dd91c8105ce109ea7e",
"versionType": "git"
},
{
"lessThan": "0027afe3dc97a4964a9ea0fb5a3457de06d85f5b",
"status": "affected",
"version": "4e638ae9c1e7a2b85155f2dd91c8105ce109ea7e",
"versionType": "git"
},
{
"lessThan": "ab05af6c345bc8460052c60de657ce6d4a2386f7",
"status": "affected",
"version": "4e638ae9c1e7a2b85155f2dd91c8105ce109ea7e",
"versionType": "git"
},
{
"lessThan": "2404600dca5c0979485c6f2d9c62bd356a98870a",
"status": "affected",
"version": "4e638ae9c1e7a2b85155f2dd91c8105ce109ea7e",
"versionType": "git"
},
{
"lessThan": "f70bd5235d9efc2ee2f70293eea51888c5f2a54d",
"status": "affected",
"version": "4e638ae9c1e7a2b85155f2dd91c8105ce109ea7e",
"versionType": "git"
},
{
"lessThan": "db85aa861b8214fa0d1d8405c01488f604a455a0",
"status": "affected",
"version": "4e638ae9c1e7a2b85155f2dd91c8105ce109ea7e",
"versionType": "git"
},
{
"lessThan": "84a1a8a952ab4b8c23c5dd1f2eea4049cb4914f5",
"status": "affected",
"version": "4e638ae9c1e7a2b85155f2dd91c8105ce109ea7e",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/gfx_v8_0.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.11"
},
{
"lessThan": "4.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/gfx8: drop unecessary BUG_ON()\n\nThere\u0027s no need to crash the kernel for this case.\n\n(cherry picked from commit 4d7c25208ca612b754f3bf39e9f16e725b828891)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:35:27.984Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/69004f1f769f7f6e9e34f4390d98a12aa0b4ab98"
},
{
"url": "https://git.kernel.org/stable/c/26ad939b402a754b0624840dfaeebd86d7ff2a22"
},
{
"url": "https://git.kernel.org/stable/c/0027afe3dc97a4964a9ea0fb5a3457de06d85f5b"
},
{
"url": "https://git.kernel.org/stable/c/ab05af6c345bc8460052c60de657ce6d4a2386f7"
},
{
"url": "https://git.kernel.org/stable/c/2404600dca5c0979485c6f2d9c62bd356a98870a"
},
{
"url": "https://git.kernel.org/stable/c/f70bd5235d9efc2ee2f70293eea51888c5f2a54d"
},
{
"url": "https://git.kernel.org/stable/c/db85aa861b8214fa0d1d8405c01488f604a455a0"
},
{
"url": "https://git.kernel.org/stable/c/84a1a8a952ab4b8c23c5dd1f2eea4049cb4914f5"
}
],
"title": "drm/amdgpu/gfx8: drop unecessary BUG_ON()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68430",
"datePublished": "2026-08-12T00:07:15.927Z",
"dateReserved": "2026-07-30T09:28:09.393Z",
"dateUpdated": "2026-08-19T16:35:27.984Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68255 (GCVE-0-2026-68255)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/virtio: bound EDID block reads to the response buffer
virtio_get_edid_block() validates the read offset only against the
device-supplied resp->size field, never against the fixed-size resp->edid
array. The EDID block index is driven by the device-supplied extension
count, so a malicious virtio-gpu backend can advertise a large size
together with a high block count and read far past the array into adjacent
kernel memory, which is then surfaced in the parsed EDID (an out-of-bounds
read / info leak).
Also reject any read whose end exceeds the size of the edid array.
Conforming EDID responses stay within the array and are unaffected.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: b4b01b4995fb15b55a2d067eb405917f5ab32709 Version: b4b01b4995fb15b55a2d067eb405917f5ab32709 Version: b4b01b4995fb15b55a2d067eb405917f5ab32709 Version: b4b01b4995fb15b55a2d067eb405917f5ab32709 Version: b4b01b4995fb15b55a2d067eb405917f5ab32709 Version: b4b01b4995fb15b55a2d067eb405917f5ab32709 Version: b4b01b4995fb15b55a2d067eb405917f5ab32709 Version: b4b01b4995fb15b55a2d067eb405917f5ab32709 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/virtio/virtgpu_vq.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "65ce911f341ad8ff0c08922eff5bb6db75666eb0",
"status": "affected",
"version": "b4b01b4995fb15b55a2d067eb405917f5ab32709",
"versionType": "git"
},
{
"lessThan": "64bedd2758eccbc74d39f7006a7ec16fa39dc901",
"status": "affected",
"version": "b4b01b4995fb15b55a2d067eb405917f5ab32709",
"versionType": "git"
},
{
"lessThan": "3f506a85a905b080cadc029a1651a310479090a6",
"status": "affected",
"version": "b4b01b4995fb15b55a2d067eb405917f5ab32709",
"versionType": "git"
},
{
"lessThan": "9fc2a017c5d597937e0c28b9a9669844aa796c42",
"status": "affected",
"version": "b4b01b4995fb15b55a2d067eb405917f5ab32709",
"versionType": "git"
},
{
"lessThan": "2757e6e803092cf0aeaf4b735e16b5d3bdc705c5",
"status": "affected",
"version": "b4b01b4995fb15b55a2d067eb405917f5ab32709",
"versionType": "git"
},
{
"lessThan": "35be0e2c6862abcd5e5f5445261f1fd910d4a9b4",
"status": "affected",
"version": "b4b01b4995fb15b55a2d067eb405917f5ab32709",
"versionType": "git"
},
{
"lessThan": "375c1934ef0196d3b6d3a1eae3232bef8dae7bf7",
"status": "affected",
"version": "b4b01b4995fb15b55a2d067eb405917f5ab32709",
"versionType": "git"
},
{
"lessThan": "4e1a53892ba7f8a3e1da6bfc53c83ae7c812dccd",
"status": "affected",
"version": "b4b01b4995fb15b55a2d067eb405917f5ab32709",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/virtio/virtgpu_vq.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.0"
},
{
"lessThan": "5.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/virtio: bound EDID block reads to the response buffer\n\nvirtio_get_edid_block() validates the read offset only against the\ndevice-supplied resp-\u003esize field, never against the fixed-size resp-\u003eedid\narray. The EDID block index is driven by the device-supplied extension\ncount, so a malicious virtio-gpu backend can advertise a large size\ntogether with a high block count and read far past the array into adjacent\nkernel memory, which is then surfaced in the parsed EDID (an out-of-bounds\nread / info leak).\n\nAlso reject any read whose end exceeds the size of the edid array.\nConforming EDID responses stay within the array and are unaffected."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.7,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The attacker is a malicious or compromised virtio-gpu backend (host/hypervisor device emulation or a vhost-user device process) supplying crafted EDID responses over the virtqueue; this is device-to-guest-kernel access, not remote network access.\nAC:L - The device fully controls resp-\u003esize, the EDID extension count and the timing of the read by raising VIRTIO_GPU_EVENT_DISPLAY config-change interrupts, so it can trigger the out-of-bounds read reliably and repeatedly with no conditions outside its control.\nPR:N - No guest credentials are needed at all: the vulnerable path runs in the virtio-gpu probe and the config-changed workqueue in kernel context, driven purely by device responses.\nUI:N - EDID re-reads are initiated automatically at probe and on device-raised display events; no guest user has to open, mount or interact with anything.\nS:U - The out-of-bounds read and the resulting disclosure both occur within the guest kernel\u0027s own security authority; no IOMMU, VM or sandbox boundary is crossed by the impact itself.\nC:H - Block indices up to 255 give start offsets of ~32 KB past the 1024-byte resp-\u003eedid array, reading far beyond the kmalloc\u0027d response object into adjacent kernel heap memory, which is then surfaced as parsed EDID via the connector blob property and world-readable sysfs edid file, and hex-dumped for bad blocks.\nI:N - Destination buffers in _drm_do_get_edid() are allocated from the block count, so the flaw is strictly an over-read of the response buffer with no out-of-bounds write or kernel data modification.\nA:H - The memcpy can walk tens of kilobytes past the slab object into unmapped or guarded memory, causing an oops/panic (and an immediate BUG under KASAN/hardened builds), and the device can repeat it at will."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:13.247Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/65ce911f341ad8ff0c08922eff5bb6db75666eb0"
},
{
"url": "https://git.kernel.org/stable/c/64bedd2758eccbc74d39f7006a7ec16fa39dc901"
},
{
"url": "https://git.kernel.org/stable/c/3f506a85a905b080cadc029a1651a310479090a6"
},
{
"url": "https://git.kernel.org/stable/c/9fc2a017c5d597937e0c28b9a9669844aa796c42"
},
{
"url": "https://git.kernel.org/stable/c/2757e6e803092cf0aeaf4b735e16b5d3bdc705c5"
},
{
"url": "https://git.kernel.org/stable/c/35be0e2c6862abcd5e5f5445261f1fd910d4a9b4"
},
{
"url": "https://git.kernel.org/stable/c/375c1934ef0196d3b6d3a1eae3232bef8dae7bf7"
},
{
"url": "https://git.kernel.org/stable/c/4e1a53892ba7f8a3e1da6bfc53c83ae7c812dccd"
}
],
"title": "drm/virtio: bound EDID block reads to the response buffer",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68255",
"datePublished": "2026-08-10T12:01:24.835Z",
"dateReserved": "2026-07-30T09:28:09.377Z",
"dateUpdated": "2026-08-23T12:46:13.247Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72125 (GCVE-0-2026-72125)
Vulnerability from cvelistv5
Published
2026-08-15 05:53
Modified
2026-08-19 16:36
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
can: isotp: fix use-after-free race with concurrent NETDEV_UNREGISTER
isotp_release() looked up the bound network device via dev_get_by_index()
using the stored ifindex. During device unregistration the device is
unlisted from the ifindex hash before the NETDEV_UNREGISTER notifier
chain runs, so a concurrent isotp_release() could find no device, skip
can_rx_unregister() entirely, and still proceed to free the socket.
Since isotp_release() had already removed itself from the isotp
notifier list at that point, isotp_notify() would never get a chance to
clean up either, leaving a stale CAN filter that keeps pointing at the
freed socket.
Fix this the same way raw.c already does: hold a tracked reference to
the bound net_device in the socket (so->dev/so->dev_tracker) from
bind() onward instead of re-resolving it from the ifindex, and
serialize bind()/release() with rtnl_lock() so that so->dev is always
consistent with what the NETDEV_UNREGISTER notifier sees. so->dev
stays valid regardless of ifindex-hash unlisting, and is only ever
cleared by whichever of isotp_release()/isotp_notify() gets there
first, so the filter is always removed exactly once.
isotp_bind() now rejects a (re)bind with -EAGAIN while so->[tx|rx].state
isn't ISOTP_IDLE yet, so a timer left running by a prior
NETDEV_UNREGISTER can't act on a newly bound so->ifindex. Both checks
share the same lock_sock() section, so there is no window in which a
concurrent isotp_notify() clearing so->bound could be missed.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: e057dd3fc20ffb3d7f150af46542a51b59b90127 Version: e057dd3fc20ffb3d7f150af46542a51b59b90127 Version: e057dd3fc20ffb3d7f150af46542a51b59b90127 Version: e057dd3fc20ffb3d7f150af46542a51b59b90127 Version: e057dd3fc20ffb3d7f150af46542a51b59b90127 Version: e057dd3fc20ffb3d7f150af46542a51b59b90127 Version: e057dd3fc20ffb3d7f150af46542a51b59b90127 Version: e057dd3fc20ffb3d7f150af46542a51b59b90127 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/can/isotp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "f311bbb29bb06aaab69ba45a6e4b11323d20b8f9",
"status": "affected",
"version": "e057dd3fc20ffb3d7f150af46542a51b59b90127",
"versionType": "git"
},
{
"lessThan": "8e018f4335590460ebcf0c2b493ed38ba1a35204",
"status": "affected",
"version": "e057dd3fc20ffb3d7f150af46542a51b59b90127",
"versionType": "git"
},
{
"lessThan": "33b9cd9245e2a4b800f99ed1cc53d64960614152",
"status": "affected",
"version": "e057dd3fc20ffb3d7f150af46542a51b59b90127",
"versionType": "git"
},
{
"lessThan": "0b811c4bbe3ec9ad611e90a540fe8b51b3bb8a96",
"status": "affected",
"version": "e057dd3fc20ffb3d7f150af46542a51b59b90127",
"versionType": "git"
},
{
"lessThan": "43884dc7963beef2328f507f4fe680bdc173eb80",
"status": "affected",
"version": "e057dd3fc20ffb3d7f150af46542a51b59b90127",
"versionType": "git"
},
{
"lessThan": "7bef39ba76eb7307ed22a50329e0f5776dbeda58",
"status": "affected",
"version": "e057dd3fc20ffb3d7f150af46542a51b59b90127",
"versionType": "git"
},
{
"lessThan": "e442b62ba5a7756c17e05a77b32cdd085a2b6138",
"status": "affected",
"version": "e057dd3fc20ffb3d7f150af46542a51b59b90127",
"versionType": "git"
},
{
"lessThan": "20bab8b88baac140ca3701116e1d486c7f51e311",
"status": "affected",
"version": "e057dd3fc20ffb3d7f150af46542a51b59b90127",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/can/isotp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.10"
},
{
"lessThan": "5.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: isotp: fix use-after-free race with concurrent NETDEV_UNREGISTER\n\nisotp_release() looked up the bound network device via dev_get_by_index()\nusing the stored ifindex. During device unregistration the device is\nunlisted from the ifindex hash before the NETDEV_UNREGISTER notifier\nchain runs, so a concurrent isotp_release() could find no device, skip\ncan_rx_unregister() entirely, and still proceed to free the socket.\nSince isotp_release() had already removed itself from the isotp\nnotifier list at that point, isotp_notify() would never get a chance to\nclean up either, leaving a stale CAN filter that keeps pointing at the\nfreed socket.\n\nFix this the same way raw.c already does: hold a tracked reference to\nthe bound net_device in the socket (so-\u003edev/so-\u003edev_tracker) from\nbind() onward instead of re-resolving it from the ifindex, and\nserialize bind()/release() with rtnl_lock() so that so-\u003edev is always\nconsistent with what the NETDEV_UNREGISTER notifier sees. so-\u003edev\nstays valid regardless of ifindex-hash unlisting, and is only ever\ncleared by whichever of isotp_release()/isotp_notify() gets there\nfirst, so the filter is always removed exactly once.\n\nisotp_bind() now rejects a (re)bind with -EAGAIN while so-\u003e[tx|rx].state\nisn\u0027t ISOTP_IDLE yet, so a timer left running by a prior\nNETDEV_UNREGISTER can\u0027t act on a newly bound so-\u003eifindex. Both checks\nshare the same lock_sock() section, so there is no window in which a\nconcurrent isotp_notify() clearing so-\u003ebound could be missed."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires local AF_CAN ISO-TP socket operations (socket/bind/close) racing NETDEV_UNREGISTER on the bound CAN interface; stale-filter UAF is triggered via local frame injection or an existing bound interface, not a remote IP/network service.\nAC:L - The attacker controls both sides of the race by concurrently closing the ISO-TP socket and unregistering the bound CAN device (e.g., vcan create/delete with CAP_NET_ADMIN in a user namespace), and can retry until the stale RX filter is left on a freed socket.\nPR:L - No init-namespace root is required: any local user can open CAN_ISOTP sockets, and CAP_NET_ADMIN obtainable in user namespaces suffices to create/delete vcan and drive the unregister path used in automotive/embedded ISO-TP (UDS) deployments.\nUI:N - No victim interaction is needed; the use-after-free is triggered by the attacker\u0027s own concurrent close()/NETDEV_UNREGISTER operations and subsequent CAN frames sent to the bound IDs.\nS:U - Impact is kernel heap corruption and potential privilege escalation within the same OS security boundary; it does not inherently cross VM, container, or IOMMU isolation boundaries.\nC:H - A stale can_rx filter keeps calling isotp_rcv()/isotp_rcv_echo() with a freed isotp_sock, enabling reads of reallocated slab contents through socket state, sock_queue_rcv_skb(), and protocol parsing on attacker-influenced memory.\nI:H - The UAF path performs extensive writes to freed socket state (RX/TX buffers, timers, generation counters) and can emit CAN traffic, providing primitives for heap shaping and control-flow hijack rather than a crash-only fault.\nA:H - Use-after-free in softirq CAN receive callbacks commonly causes kernel oops/panic from dereferencing or writing freed isotp_sock/timer state, even before reliable exploitation."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:36:23.877Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/f311bbb29bb06aaab69ba45a6e4b11323d20b8f9"
},
{
"url": "https://git.kernel.org/stable/c/8e018f4335590460ebcf0c2b493ed38ba1a35204"
},
{
"url": "https://git.kernel.org/stable/c/33b9cd9245e2a4b800f99ed1cc53d64960614152"
},
{
"url": "https://git.kernel.org/stable/c/0b811c4bbe3ec9ad611e90a540fe8b51b3bb8a96"
},
{
"url": "https://git.kernel.org/stable/c/43884dc7963beef2328f507f4fe680bdc173eb80"
},
{
"url": "https://git.kernel.org/stable/c/7bef39ba76eb7307ed22a50329e0f5776dbeda58"
},
{
"url": "https://git.kernel.org/stable/c/e442b62ba5a7756c17e05a77b32cdd085a2b6138"
},
{
"url": "https://git.kernel.org/stable/c/20bab8b88baac140ca3701116e1d486c7f51e311"
}
],
"title": "can: isotp: fix use-after-free race with concurrent NETDEV_UNREGISTER",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72125",
"datePublished": "2026-08-15T05:53:02.905Z",
"dateReserved": "2026-08-09T03:40:39.907Z",
"dateUpdated": "2026-08-19T16:36:23.877Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64579 (GCVE-0-2026-64579)
Vulnerability from cvelistv5
Published
2026-08-05 08:09
Modified
2026-08-19 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert
xfrm_hash_rebuild()'s first loop preallocates the bins/chains the reinsert
loop needs, so the reinsert (after hlist_del_rcu()) cannot allocate or
fail. But its guard is inverted: it skips policies with prefixlen <
threshold and preallocates for the rest.
prefixlen < threshold is exactly when policy_hash_bysel() returns NULL and
the reinsert takes the allocating xfrm_policy_inexact_insert() path. So the
loop preallocates for the exact policies (which never allocate) and skips
the inexact ones, whose bin/node is then allocated GFP_ATOMIC during
reinsert. On failure the error path only WARN_ONCE()s and continues,
leaving a poisoned bydst node; the next rebuild's hlist_del_rcu()
dereferences LIST_POISON2 and takes a GPF. Reachable under memory pressure,
deterministic via failslab.
Invert the guard so preallocation covers exactly the reinserted policies;
the reinsert then allocates nothing and cannot fail.
Crash:
Oops: general protection fault, probably for non-canonical address
0xfbd59c0000000024: 0000 [#1] SMP KASAN NOPTI
KASAN: maybe wild-memory-access in range [0xdead...]
...
Workqueue: events xfrm_hash_rebuild
RIP: 0010:xfrm_hash_rebuild+0x5b3/0x1190
RAX: dead000000000122 (LIST_POISON2 + offset)
...
Call Trace:
hlist_del_rcu (include/linux/rculist.h:599)
xfrm_hash_rebuild (net/xfrm/xfrm_policy.c:1365)
process_one_work (kernel/workqueue.c:3322)
worker_thread (kernel/workqueue.c:3486)
kthread (kernel/kthread.c:436)
ret_from_fork (arch/x86/kernel/process.c:158)
ret_from_fork_asm (arch/x86/entry/entry_64.S:245)
...
Kernel panic - not syncing: Fatal exception in interrupt
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 24969facd704a5f0dd8e08da86bf32a9ce972bee Version: 24969facd704a5f0dd8e08da86bf32a9ce972bee Version: 24969facd704a5f0dd8e08da86bf32a9ce972bee Version: 24969facd704a5f0dd8e08da86bf32a9ce972bee Version: 24969facd704a5f0dd8e08da86bf32a9ce972bee Version: 24969facd704a5f0dd8e08da86bf32a9ce972bee Version: 24969facd704a5f0dd8e08da86bf32a9ce972bee Version: 24969facd704a5f0dd8e08da86bf32a9ce972bee |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/xfrm/xfrm_policy.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "e48f4c3e3df35b34be719d72d737bbeaca77cf0c",
"status": "affected",
"version": "24969facd704a5f0dd8e08da86bf32a9ce972bee",
"versionType": "git"
},
{
"lessThan": "1cdeed9df1306f1a277e715600772640d63defa9",
"status": "affected",
"version": "24969facd704a5f0dd8e08da86bf32a9ce972bee",
"versionType": "git"
},
{
"lessThan": "43a4d510523779891cf8eca7ffb4a086b0b5d8bf",
"status": "affected",
"version": "24969facd704a5f0dd8e08da86bf32a9ce972bee",
"versionType": "git"
},
{
"lessThan": "d9d9cc21cc90014724a14c447e3d587be9447107",
"status": "affected",
"version": "24969facd704a5f0dd8e08da86bf32a9ce972bee",
"versionType": "git"
},
{
"lessThan": "94c00391a5117530188334f740ce26d3f1256190",
"status": "affected",
"version": "24969facd704a5f0dd8e08da86bf32a9ce972bee",
"versionType": "git"
},
{
"lessThan": "7acc5ed2f33608a3d83b64f50a5766843b6e2485",
"status": "affected",
"version": "24969facd704a5f0dd8e08da86bf32a9ce972bee",
"versionType": "git"
},
{
"lessThan": "6aa3796d18a9fda953ad76a62b57bf6c145cb9ef",
"status": "affected",
"version": "24969facd704a5f0dd8e08da86bf32a9ce972bee",
"versionType": "git"
},
{
"lessThan": "f38f8cce2f7e79775b3db7e8a5eacda04ac908e4",
"status": "affected",
"version": "24969facd704a5f0dd8e08da86bf32a9ce972bee",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/xfrm/xfrm_policy.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.0"
},
{
"lessThan": "5.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert\n\nxfrm_hash_rebuild()\u0027s first loop preallocates the bins/chains the reinsert\nloop needs, so the reinsert (after hlist_del_rcu()) cannot allocate or\nfail. But its guard is inverted: it skips policies with prefixlen \u003c\nthreshold and preallocates for the rest.\n\nprefixlen \u003c threshold is exactly when policy_hash_bysel() returns NULL and\nthe reinsert takes the allocating xfrm_policy_inexact_insert() path. So the\nloop preallocates for the exact policies (which never allocate) and skips\nthe inexact ones, whose bin/node is then allocated GFP_ATOMIC during\nreinsert. On failure the error path only WARN_ONCE()s and continues,\nleaving a poisoned bydst node; the next rebuild\u0027s hlist_del_rcu()\ndereferences LIST_POISON2 and takes a GPF. Reachable under memory pressure,\ndeterministic via failslab.\n\nInvert the guard so preallocation covers exactly the reinserted policies;\nthe reinsert then allocates nothing and cannot fail.\n\nCrash:\n Oops: general protection fault, probably for non-canonical address\n 0xfbd59c0000000024: 0000 [#1] SMP KASAN NOPTI\n KASAN: maybe wild-memory-access in range [0xdead...]\n ...\n Workqueue: events xfrm_hash_rebuild\n RIP: 0010:xfrm_hash_rebuild+0x5b3/0x1190\n RAX: dead000000000122 (LIST_POISON2 + offset)\n ...\n Call Trace:\n hlist_del_rcu (include/linux/rculist.h:599)\n xfrm_hash_rebuild (net/xfrm/xfrm_policy.c:1365)\n process_one_work (kernel/workqueue.c:3322)\n worker_thread (kernel/workqueue.c:3486)\n kthread (kernel/kthread.c:436)\n ret_from_fork (arch/x86/kernel/process.c:158)\n ret_from_fork_asm (arch/x86/entry/entry_64.S:245)\n ...\n Kernel panic - not syncing: Fatal exception in interrupt"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:29:04.594Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/e48f4c3e3df35b34be719d72d737bbeaca77cf0c"
},
{
"url": "https://git.kernel.org/stable/c/1cdeed9df1306f1a277e715600772640d63defa9"
},
{
"url": "https://git.kernel.org/stable/c/43a4d510523779891cf8eca7ffb4a086b0b5d8bf"
},
{
"url": "https://git.kernel.org/stable/c/d9d9cc21cc90014724a14c447e3d587be9447107"
},
{
"url": "https://git.kernel.org/stable/c/94c00391a5117530188334f740ce26d3f1256190"
},
{
"url": "https://git.kernel.org/stable/c/7acc5ed2f33608a3d83b64f50a5766843b6e2485"
},
{
"url": "https://git.kernel.org/stable/c/6aa3796d18a9fda953ad76a62b57bf6c145cb9ef"
},
{
"url": "https://git.kernel.org/stable/c/f38f8cce2f7e79775b3db7e8a5eacda04ac908e4"
}
],
"title": "xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64579",
"datePublished": "2026-08-05T08:09:34.346Z",
"dateReserved": "2026-07-19T15:36:31.798Z",
"dateUpdated": "2026-08-19T16:29:04.594Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68123 (GCVE-0-2026-68123)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-19 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
openvswitch: fix GSO userspace truncation underflow
OVS_ACTION_ATTR_TRUNC currently stores a delta from the original skb
length in OVS_CB(skb)->cutlen. When a later userspace action segments a
GSO skb, queue_gso_packets() reuses that delta for each smaller segment.
A segment can then reach queue_userspace_packet() with cutlen greater
than skb->len, underflowing the length passed to skb_zerocopy().
Store the maximum preserved length instead and bound each consumer
against the current skb length. Use U32_MAX as the no-truncation
sentinel so the value remains valid if skb geometry changes before a
consumer handles it.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: f2a4d086ed4c588d32fe9b7aa67fead7280e7bf1 Version: f2a4d086ed4c588d32fe9b7aa67fead7280e7bf1 Version: f2a4d086ed4c588d32fe9b7aa67fead7280e7bf1 Version: f2a4d086ed4c588d32fe9b7aa67fead7280e7bf1 Version: f2a4d086ed4c588d32fe9b7aa67fead7280e7bf1 Version: f2a4d086ed4c588d32fe9b7aa67fead7280e7bf1 Version: f2a4d086ed4c588d32fe9b7aa67fead7280e7bf1 Version: f2a4d086ed4c588d32fe9b7aa67fead7280e7bf1 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/openvswitch/actions.c",
"net/openvswitch/datapath.c",
"net/openvswitch/datapath.h",
"net/openvswitch/vport.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "50a6a85f3d6b1d22d8436848606cdef5d2c490b4",
"status": "affected",
"version": "f2a4d086ed4c588d32fe9b7aa67fead7280e7bf1",
"versionType": "git"
},
{
"lessThan": "2623c48cc3a8da9a1886fd8f65c0e348f4406fd6",
"status": "affected",
"version": "f2a4d086ed4c588d32fe9b7aa67fead7280e7bf1",
"versionType": "git"
},
{
"lessThan": "e211b081901ffca76674082c73eeaed53524c369",
"status": "affected",
"version": "f2a4d086ed4c588d32fe9b7aa67fead7280e7bf1",
"versionType": "git"
},
{
"lessThan": "a16eaaf7c0b0ccdef6166707d90ffbc6eebf6855",
"status": "affected",
"version": "f2a4d086ed4c588d32fe9b7aa67fead7280e7bf1",
"versionType": "git"
},
{
"lessThan": "fbfa3ad2ad6f3a5624aba5211c46290fb98cc9dc",
"status": "affected",
"version": "f2a4d086ed4c588d32fe9b7aa67fead7280e7bf1",
"versionType": "git"
},
{
"lessThan": "100a23b1613e9218e0af654ef102352c713f0263",
"status": "affected",
"version": "f2a4d086ed4c588d32fe9b7aa67fead7280e7bf1",
"versionType": "git"
},
{
"lessThan": "ea85dbcbe8d4056ecb54352f97743d138ea4c407",
"status": "affected",
"version": "f2a4d086ed4c588d32fe9b7aa67fead7280e7bf1",
"versionType": "git"
},
{
"lessThan": "4032f8ed10fcb84d41c508dfb04be96589f78dfe",
"status": "affected",
"version": "f2a4d086ed4c588d32fe9b7aa67fead7280e7bf1",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/openvswitch/actions.c",
"net/openvswitch/datapath.c",
"net/openvswitch/datapath.h",
"net/openvswitch/vport.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.8"
},
{
"lessThan": "4.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nopenvswitch: fix GSO userspace truncation underflow\n\nOVS_ACTION_ATTR_TRUNC currently stores a delta from the original skb\nlength in OVS_CB(skb)-\u003ecutlen. When a later userspace action segments a\nGSO skb, queue_gso_packets() reuses that delta for each smaller segment.\nA segment can then reach queue_userspace_packet() with cutlen greater\nthan skb-\u003elen, underflowing the length passed to skb_zerocopy().\n\nStore the maximum preserved length instead and bound each consumer\nagainst the current skb length. Use U32_MAX as the no-truncation\nsentinel so the value remains valid if skb geometry changes before a\nconsumer handles it."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - Ingress packets reach ovs_vport_receive() through netdev rx_handlers or tunnel vports; GRO-coalesced GSO skbs from remote senders traverse this path into queue_gso_packets(), so the underflow is reachable from the network without physical access.\nAC:L - The attacker chooses truncation max_len relative to GSO super-skb size and sends traffic that GRO segments predictably; no timing race or fragile heap layout is required to make cutlen exceed a child segment length after __skb_gso_segment().\nPR:N - In multi-tenant cloud/OVN deployments, a remote VM or container can send crafted GSO traffic into the host OVS datapath to hit provider-installed TRUNC+USERSPACE sampling flows without possessing any Linux capabilities on the host.\nUI:N - Triggering the flaw requires only network traffic matching existing OVS flow actions; no victim login, file open, mount, or other interactive step is needed.\nS:U - Impact is kernel memory corruption and crash/escalation within the host kernel security domain; it does not cross a guest-to-hypervisor, VM, or hardware IOMMU trust boundary by itself.\nC:H - Unsigned underflow makes skb-\u003elen-cutlen enormous for skb_zerocopy()/skb_copy_bits(), enabling out-of-bounds reads from the source skb and adjacent slab data, i.e., an exploitable information-disclosure primitive.\nI:H - The same underflowed length can expand destination skbs via skb_len_add()/nlattr sizing, corrupting kernel heap metadata and yielding a write primitive suitable for control-flow hijacking.\nA:H - The miscopied lengths can BUG the skb helpers or cause immediate kernel oops/panic during zerocopy/trim handling, and corrupted metadata can crash the system even if exploitation is not completed."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:29:34.391Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/50a6a85f3d6b1d22d8436848606cdef5d2c490b4"
},
{
"url": "https://git.kernel.org/stable/c/2623c48cc3a8da9a1886fd8f65c0e348f4406fd6"
},
{
"url": "https://git.kernel.org/stable/c/e211b081901ffca76674082c73eeaed53524c369"
},
{
"url": "https://git.kernel.org/stable/c/a16eaaf7c0b0ccdef6166707d90ffbc6eebf6855"
},
{
"url": "https://git.kernel.org/stable/c/fbfa3ad2ad6f3a5624aba5211c46290fb98cc9dc"
},
{
"url": "https://git.kernel.org/stable/c/100a23b1613e9218e0af654ef102352c713f0263"
},
{
"url": "https://git.kernel.org/stable/c/ea85dbcbe8d4056ecb54352f97743d138ea4c407"
},
{
"url": "https://git.kernel.org/stable/c/4032f8ed10fcb84d41c508dfb04be96589f78dfe"
}
],
"title": "openvswitch: fix GSO userspace truncation underflow",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68123",
"datePublished": "2026-08-10T11:58:43.727Z",
"dateReserved": "2026-07-30T09:28:09.369Z",
"dateUpdated": "2026-08-19T16:29:34.391Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68212 (GCVE-0-2026-68212)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: saa7134: Fix a possible memory leak in saa7134_video_init1
In saa7134_video_init1(), the return value of the first
saa7134_pgtable_alloc() is not checked. If it fails, the function
continues as if successful, leaving the driver with an invalid page
table. Additionally, if vb2_queue_init() for the VBI queue fails after
the video queue page table has been allocated, the allocated memory is
not freed before returning. The second saa7134_pgtable_alloc() also
lacks a return value check. Errors occur during device probing before
the device is fully registered, the normal cleanup path in
saa7134_finidev() is not executed, leading to memory leaks and
potential use of uninitialized DMA resources.
Check the return value of both saa7134_pgtable_alloc() calls and
propagate errors. On failure of any later step, free allocated page
tables to avoid memory leaks. Ensure control handlers are also
released on error to prevent further resource leakage.
Found by code review.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: a00e68888d5d2b583b13d7d58204a27207af95fd Version: a00e68888d5d2b583b13d7d58204a27207af95fd Version: a00e68888d5d2b583b13d7d58204a27207af95fd Version: a00e68888d5d2b583b13d7d58204a27207af95fd Version: a00e68888d5d2b583b13d7d58204a27207af95fd Version: a00e68888d5d2b583b13d7d58204a27207af95fd Version: a00e68888d5d2b583b13d7d58204a27207af95fd Version: a00e68888d5d2b583b13d7d58204a27207af95fd |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/pci/saa7134/saa7134-video.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "e773b1d4bd191e7520bf9e02cb676d62c1b20556",
"status": "affected",
"version": "a00e68888d5d2b583b13d7d58204a27207af95fd",
"versionType": "git"
},
{
"lessThan": "44e16e3e022bf4a26adf03bc05a6dd5ffc34ef6d",
"status": "affected",
"version": "a00e68888d5d2b583b13d7d58204a27207af95fd",
"versionType": "git"
},
{
"lessThan": "34082a48376fd225a5c3d971c8962eb1320a54e0",
"status": "affected",
"version": "a00e68888d5d2b583b13d7d58204a27207af95fd",
"versionType": "git"
},
{
"lessThan": "134c979dd721e22f196d71026432ee37d1f5cc38",
"status": "affected",
"version": "a00e68888d5d2b583b13d7d58204a27207af95fd",
"versionType": "git"
},
{
"lessThan": "e1ef361ee31d1dba5dcae2cdd50f9c1352df0c23",
"status": "affected",
"version": "a00e68888d5d2b583b13d7d58204a27207af95fd",
"versionType": "git"
},
{
"lessThan": "b7936e8cbec1b96b126058eeb005e5b9111df38e",
"status": "affected",
"version": "a00e68888d5d2b583b13d7d58204a27207af95fd",
"versionType": "git"
},
{
"lessThan": "1731dd61b6c0b7435c139951d2b7eada6c9667a8",
"status": "affected",
"version": "a00e68888d5d2b583b13d7d58204a27207af95fd",
"versionType": "git"
},
{
"lessThan": "f86ed548386e3050e5f8f25b450d09dc009d9a88",
"status": "affected",
"version": "a00e68888d5d2b583b13d7d58204a27207af95fd",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/pci/saa7134/saa7134-video.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.16"
},
{
"lessThan": "3.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.16",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: saa7134: Fix a possible memory leak in saa7134_video_init1\n\nIn saa7134_video_init1(), the return value of the first\nsaa7134_pgtable_alloc() is not checked. If it fails, the function\ncontinues as if successful, leaving the driver with an invalid page\ntable. Additionally, if vb2_queue_init() for the VBI queue fails after\nthe video queue page table has been allocated, the allocated memory is\nnot freed before returning. The second saa7134_pgtable_alloc() also\nlacks a return value check. Errors occur during device probing before\nthe device is fully registered, the normal cleanup path in\nsaa7134_finidev() is not executed, leading to memory leaks and\npotential use of uninitialized DMA resources.\n\nCheck the return value of both saa7134_pgtable_alloc() calls and\npropagate errors. On failure of any later step, free allocated page\ntables to avoid memory leaks. Ensure control handlers are also\nreleased on error to prevent further resource leakage.\n\nFound by code review."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:37.074Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/e773b1d4bd191e7520bf9e02cb676d62c1b20556"
},
{
"url": "https://git.kernel.org/stable/c/44e16e3e022bf4a26adf03bc05a6dd5ffc34ef6d"
},
{
"url": "https://git.kernel.org/stable/c/34082a48376fd225a5c3d971c8962eb1320a54e0"
},
{
"url": "https://git.kernel.org/stable/c/134c979dd721e22f196d71026432ee37d1f5cc38"
},
{
"url": "https://git.kernel.org/stable/c/e1ef361ee31d1dba5dcae2cdd50f9c1352df0c23"
},
{
"url": "https://git.kernel.org/stable/c/b7936e8cbec1b96b126058eeb005e5b9111df38e"
},
{
"url": "https://git.kernel.org/stable/c/1731dd61b6c0b7435c139951d2b7eada6c9667a8"
},
{
"url": "https://git.kernel.org/stable/c/f86ed548386e3050e5f8f25b450d09dc009d9a88"
}
],
"title": "media: saa7134: Fix a possible memory leak in saa7134_video_init1",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68212",
"datePublished": "2026-08-10T12:00:31.498Z",
"dateReserved": "2026-07-30T09:28:09.375Z",
"dateUpdated": "2026-08-19T16:31:37.074Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68149 (GCVE-0-2026-68149)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-17 04:59
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
fs: preserve ACL_DONT_CACHE state in forget_cached_acl()
The ACL_DONT_CACHE state is meant to be a constant state for the inode
for filesystems that want to opt out of posix acl caching.
Commit facd61053cff1 ("fuse: fixes after adapting to new posix acl api")
used this facility to opt out of posix acl caching for fuse inodes with
fuse server that does not negotiate FUSE_POSIX_ACL (fc->posix_acl).
The commit also takes care to gate the forget_all_cached_acls() call in
fuse_set_acl() on fc->posix_acl because there is no need for it, but
there are other placed in fuse code which call forget_all_cached_acls()
unconditional to fc->posix_acl and those cause the loss of the
ACL_DONT_CACHE state.
This is not only a functional bug. Properly timed, a get_acl() from this
fuse filesystem can return a stale cached value, as was observed in tests,
because set_acl() does not invalidate the unintentional acl cache.
We could fix this in fuse, but it actually makes no sense for the vfs
helper forget_cached_acl() to invalidate the ACL_DONT_CACHE state, so
let it not do that to fix fuse and future users of ACL_DONT_CACHE.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/posix_acl.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b98fad81f1202b0eb26aacf3ff4cc7a21ed3b5bf",
"status": "affected",
"version": "facd61053cff100973921d4d45d47cf53c747ec6",
"versionType": "git"
},
{
"lessThan": "834ddf899484a2f23129080e8773bc04f4691d07",
"status": "affected",
"version": "facd61053cff100973921d4d45d47cf53c747ec6",
"versionType": "git"
},
{
"lessThan": "a019b074903b3ad0a9726087efd0e8291452023b",
"status": "affected",
"version": "facd61053cff100973921d4d45d47cf53c747ec6",
"versionType": "git"
},
{
"lessThan": "ca03a7984a34f48085fd013e0d2cf4e6420b4acf",
"status": "affected",
"version": "facd61053cff100973921d4d45d47cf53c747ec6",
"versionType": "git"
},
{
"lessThan": "4b9a5458d02e214ef2b384124ca626e3e381d778",
"status": "affected",
"version": "facd61053cff100973921d4d45d47cf53c747ec6",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/posix_acl.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.2"
},
{
"lessThan": "6.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs: preserve ACL_DONT_CACHE state in forget_cached_acl()\n\nThe ACL_DONT_CACHE state is meant to be a constant state for the inode\nfor filesystems that want to opt out of posix acl caching.\n\nCommit facd61053cff1 (\"fuse: fixes after adapting to new posix acl api\")\nused this facility to opt out of posix acl caching for fuse inodes with\nfuse server that does not negotiate FUSE_POSIX_ACL (fc-\u003eposix_acl).\n\nThe commit also takes care to gate the forget_all_cached_acls() call in\nfuse_set_acl() on fc-\u003eposix_acl because there is no need for it, but\nthere are other placed in fuse code which call forget_all_cached_acls()\nunconditional to fc-\u003eposix_acl and those cause the loss of the\nACL_DONT_CACHE state.\n\nThis is not only a functional bug. Properly timed, a get_acl() from this\nfuse filesystem can return a stale cached value, as was observed in tests,\nbecause set_acl() does not invalidate the unintentional acl cache.\n\nWe could fix this in fuse, but it actually makes no sense for the vfs\nhelper forget_cached_acl() to invalidate the ACL_DONT_CACHE state, so\nlet it not do that to fix fuse and future users of ACL_DONT_CACHE."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.4,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires local VFS syscalls (getxattr, statx, open, read, write) on a FUSE-backed mount; the bug is in kernel ACL caching, not in a network protocol handler.\nAC:L - The attacker controls the full trigger sequence (stat/getattr to clear ACL_DONT_CACHE, getxattr to populate cache, ACL change, then access) and can drive timing with concurrent threads without depending on uncontrollable system state.\nPR:L - Any unprivileged local user who can mount or access a FUSE filesystem (fusermount, user namespaces, virtio-fs/SSHFS mounts with allow_other) can reach the vulnerable code paths on files within that mount.\nUI:N - Exploitation is fully attacker-driven through syscall sequences on the FUSE mount; no victim click, mount action, or other interactive cooperation is required beyond routine filesystem use.\nS:C - On virtio-fs/Kata/Firecracker shared host directories, stale kernel ACL enforcement can let a guest/container process access host-exported files beyond the permissions the host administrator intended, crossing that isolation boundary.\nC:H - Stale permissive cached ACLs cause check_acl()/posix_acl_permission() to authorize reads of files that should be denied after ACL tightening, enabling unauthorized disclosure of protected file contents on default_permissions mounts.\nI:H - The same stale ACL bypass lets an attacker obtain write permission enforced by the kernel VFS on files whose ACLs were subsequently restricted, enabling unauthorized modification of protected data.\nA:N - This is a stale-cache logic bug with no memory corruption, kernel crash, panic, or hang; observed impact is incorrect ACL enforcement and authorization bypass, not availability loss."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:59:43.618Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b98fad81f1202b0eb26aacf3ff4cc7a21ed3b5bf"
},
{
"url": "https://git.kernel.org/stable/c/834ddf899484a2f23129080e8773bc04f4691d07"
},
{
"url": "https://git.kernel.org/stable/c/a019b074903b3ad0a9726087efd0e8291452023b"
},
{
"url": "https://git.kernel.org/stable/c/ca03a7984a34f48085fd013e0d2cf4e6420b4acf"
},
{
"url": "https://git.kernel.org/stable/c/4b9a5458d02e214ef2b384124ca626e3e381d778"
}
],
"title": "fs: preserve ACL_DONT_CACHE state in forget_cached_acl()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68149",
"datePublished": "2026-08-10T11:59:14.645Z",
"dateReserved": "2026-07-30T09:28:09.371Z",
"dateUpdated": "2026-08-17T04:59:43.618Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68228 (GCVE-0-2026-68228)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-17 05:01
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: chips-media: wave5: Move src_buf Removal to finish_encode
During encoder processing, there is a case where the IRQ response could
return the buffer back to userspace via v4l2_m2m_buf_done call. In this
time, userspace could queue up this same buffer before start_encode removes
the index from the ready queue. This would then lead to a case where the
buffer in the ready queue could be a self loop due to the
WRITE_ONCE(prev->next, new) call in __list_add.
When __list_del is finally called, the loop is already made so nothing
points back to ready queue list head and pointers are poisoned.
A buffer should not be marked as DONE before the buffer is removed from
m2m ready queue. Move removal entirely to finish_encode.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/platform/chips-media/wave5/wave5-vpu-enc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "1ee2b2b189ddc7b23c8eee1145de42b8bd19fb06",
"status": "affected",
"version": "9707a6254a8a6b978bde811a44fe07d86c229d1c",
"versionType": "git"
},
{
"lessThan": "f24ca8b53fe15db40957bdaa40c9aa68e1557bbe",
"status": "affected",
"version": "9707a6254a8a6b978bde811a44fe07d86c229d1c",
"versionType": "git"
},
{
"lessThan": "d681227ce43bfd74b6eb69beecd9b0bec1fd8b48",
"status": "affected",
"version": "9707a6254a8a6b978bde811a44fe07d86c229d1c",
"versionType": "git"
},
{
"lessThan": "b20157147089a9c16a38c7810e2fe6f2df8e3277",
"status": "affected",
"version": "9707a6254a8a6b978bde811a44fe07d86c229d1c",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/platform/chips-media/wave5/wave5-vpu-enc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.8"
},
{
"lessThan": "6.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: chips-media: wave5: Move src_buf Removal to finish_encode\n\nDuring encoder processing, there is a case where the IRQ response could\nreturn the buffer back to userspace via v4l2_m2m_buf_done call. In this\ntime, userspace could queue up this same buffer before start_encode removes\nthe index from the ready queue. This would then lead to a case where the\nbuffer in the ready queue could be a self loop due to the\nWRITE_ONCE(prev-\u003enext, new) call in __list_add.\n\nWhen __list_del is finally called, the loop is already made so nothing\npoints back to ready queue list head and pointers are poisoned.\n\nA buffer should not be marked as DONE before the buffer is removed from\nm2m ready queue. Move removal entirely to finish_encode."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The flaw is reached only through V4L2 ioctls (REQBUFS/QBUF/DQBUF/STREAMON) on the local Wave5 encoder device node /dev/videoX; no network or remote input path exists.\nAC:L - Although a race, the attacker controls both sides: it drives the QBUF timing against the encode-completion IRQ and can retry on every encoded frame in a tight loop until the window is hit, so triggering is reliable.\nPR:L - An unprivileged local process that can open the encoder video node (normal on Android/embedded TI platforms where media apps hold access, or any user in the video group) can drive the full encode sequence; no capabilities are checked.\nUI:N - The attacking process performs all encode setup and buffer queueing itself; no action by another user or victim is needed.\nS:U - Corruption is confined to kernel memory managed by the same kernel security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - The m2m ready-queue list corruption plus a vb2 buffer simultaneously owned by userspace and the driver yields dangling/poisoned kernel pointers and buffer state confusion that can be leveraged to read kernel memory contents.\nI:H - Doubly-linked list corruption gives an attacker-influenced write through list_add/list_del on a self-looped node, and a freed-then-reused buffer object, both of which are classic primitives for controlled kernel memory modification.\nA:H - The self-loop and subsequent __list_del leave the ready queue head detached with poisoned pointers, causing LIST_POISON dereference oops, unterminated list traversal, or a use-after-free crash that takes down the kernel."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:01:16.349Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/1ee2b2b189ddc7b23c8eee1145de42b8bd19fb06"
},
{
"url": "https://git.kernel.org/stable/c/f24ca8b53fe15db40957bdaa40c9aa68e1557bbe"
},
{
"url": "https://git.kernel.org/stable/c/d681227ce43bfd74b6eb69beecd9b0bec1fd8b48"
},
{
"url": "https://git.kernel.org/stable/c/b20157147089a9c16a38c7810e2fe6f2df8e3277"
}
],
"title": "media: chips-media: wave5: Move src_buf Removal to finish_encode",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68228",
"datePublished": "2026-08-10T12:00:50.892Z",
"dateReserved": "2026-07-30T09:28:09.376Z",
"dateUpdated": "2026-08-17T05:01:16.349Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64577 (GCVE-0-2026-64577)
Vulnerability from cvelistv5
Published
2026-08-05 08:09
Modified
2026-08-19 16:28
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
gtp: check skb_pull_data() return in gtp1u_send_echo_resp()
gtp1u_send_echo_resp() ignores skb_pull_data()'s return value. Its
caller gtp1u_udp_encap_recv() only guarantees 16 bytes (udphdr +
gtp1_header), but the pull requests 20 (gtp1_header_long + udphdr). For
a 16-19 byte echo request the pull fails and returns NULL without
advancing skb->data; execution continues, and the following skb_push()
plus the IP header pushed by iptunnel_xmit() move skb->data below
skb->head, tripping skb_under_panic().
Fix it by dropping the packet when skb_pull_data() fails.
skbuff: skb_under_panic: ...
kernel BUG at net/core/skbuff.c:214!
Call Trace:
skb_push (net/core/skbuff.c:2648)
iptunnel_xmit (net/ipv4/ip_tunnel_core.c:82)
gtp_encap_recv (drivers/net/gtp.c:701 drivers/net/gtp.c:808 drivers/net/gtp.c:920)
udp_queue_rcv_one_skb (net/ipv4/udp.c:2388)
...
Kernel panic - not syncing: Fatal exception in interrupt
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 9af41cc33471ea1efa6f77e188f055cc77d0a5c5 Version: 9af41cc33471ea1efa6f77e188f055cc77d0a5c5 Version: 9af41cc33471ea1efa6f77e188f055cc77d0a5c5 Version: 9af41cc33471ea1efa6f77e188f055cc77d0a5c5 Version: 9af41cc33471ea1efa6f77e188f055cc77d0a5c5 Version: 9af41cc33471ea1efa6f77e188f055cc77d0a5c5 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/gtp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "9033fe49926f0e7421fefee922dc086417e905cf",
"status": "affected",
"version": "9af41cc33471ea1efa6f77e188f055cc77d0a5c5",
"versionType": "git"
},
{
"lessThan": "b3c733eaae7f362601c28ac1533d47a961cd3e1c",
"status": "affected",
"version": "9af41cc33471ea1efa6f77e188f055cc77d0a5c5",
"versionType": "git"
},
{
"lessThan": "4fc7923871d176ce0e5fecf4a9b7bb915af790ed",
"status": "affected",
"version": "9af41cc33471ea1efa6f77e188f055cc77d0a5c5",
"versionType": "git"
},
{
"lessThan": "961e9b1e33445f8e42859ecc020c9f60d8b69a8b",
"status": "affected",
"version": "9af41cc33471ea1efa6f77e188f055cc77d0a5c5",
"versionType": "git"
},
{
"lessThan": "cf45d748e437b8dd2dd987f27ee79c8c86f95c88",
"status": "affected",
"version": "9af41cc33471ea1efa6f77e188f055cc77d0a5c5",
"versionType": "git"
},
{
"lessThan": "cd170f051dba9ac146fabcd1b91726487c0cb9fa",
"status": "affected",
"version": "9af41cc33471ea1efa6f77e188f055cc77d0a5c5",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/gtp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.18"
},
{
"lessThan": "5.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.18",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ngtp: check skb_pull_data() return in gtp1u_send_echo_resp()\n\ngtp1u_send_echo_resp() ignores skb_pull_data()\u0027s return value. Its\ncaller gtp1u_udp_encap_recv() only guarantees 16 bytes (udphdr +\ngtp1_header), but the pull requests 20 (gtp1_header_long + udphdr). For\na 16-19 byte echo request the pull fails and returns NULL without\nadvancing skb-\u003edata; execution continues, and the following skb_push()\nplus the IP header pushed by iptunnel_xmit() move skb-\u003edata below\nskb-\u003ehead, tripping skb_under_panic().\n\nFix it by dropping the packet when skb_pull_data() fails.\n\n skbuff: skb_under_panic: ...\n kernel BUG at net/core/skbuff.c:214!\n Call Trace:\n skb_push (net/core/skbuff.c:2648)\n iptunnel_xmit (net/ipv4/ip_tunnel_core.c:82)\n gtp_encap_recv (drivers/net/gtp.c:701 drivers/net/gtp.c:808 drivers/net/gtp.c:920)\n udp_queue_rcv_one_skb (net/ipv4/udp.c:2388)\n ...\n Kernel panic - not syncing: Fatal exception in interrupt"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - A crafted GTP-U Echo Request to UDP port 2152 reaches gtp_encap_recv \u2192 gtp1u_udp_encap_recv \u2192 gtp1u_send_echo_resp via the in-kernel UDP encap receive path, so a remote IP peer can trigger the bug without local access.\nAC:L - The attacker fully controls the packet: a 16\u201319 byte GTP-U Echo Request with the S flag set and TEID 0 reliably fails the unchecked 20-byte pull and drives the subsequent skb_push path into skb_under_panic with no race or external condition required.\nPR:N - GTP-U echo handling runs on unauthenticated received UDP datagrams once a GTP device with kernel-created sockets exists; the attacker needs no credentials or local privileges on the target.\nUI:N - No victim action is required; packet delivery to the GTP-U encap socket alone invokes the vulnerable echo-response path.\nS:U - Impact is a kernel BUG/panic in the host GTP/network stack within the same security authority; it does not cross a VM, IOMMU, or other separate boundary.\nC:N - The failure is a deterministic skb headroom underflow caught by skb_under_panic/BUG with no out-of-bounds read, UAF, or other information-disclosure primitive identified.\nI:N - skb_push detects data \u003c head and BUG()s before further attacker-controlled writes; this is an availability crash, not an exploitable write or control-flow hijack primitive.\nA:H - The commit-reproduced path hits skb_under_panic and a fatal kernel BUG in interrupt context, causing kernel panic and full denial of service that can be retriggered by further crafted echo requests."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:28:59.684Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/9033fe49926f0e7421fefee922dc086417e905cf"
},
{
"url": "https://git.kernel.org/stable/c/b3c733eaae7f362601c28ac1533d47a961cd3e1c"
},
{
"url": "https://git.kernel.org/stable/c/4fc7923871d176ce0e5fecf4a9b7bb915af790ed"
},
{
"url": "https://git.kernel.org/stable/c/961e9b1e33445f8e42859ecc020c9f60d8b69a8b"
},
{
"url": "https://git.kernel.org/stable/c/cf45d748e437b8dd2dd987f27ee79c8c86f95c88"
},
{
"url": "https://git.kernel.org/stable/c/cd170f051dba9ac146fabcd1b91726487c0cb9fa"
}
],
"title": "gtp: check skb_pull_data() return in gtp1u_send_echo_resp()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64577",
"datePublished": "2026-08-05T08:09:33.135Z",
"dateReserved": "2026-07-19T15:36:31.798Z",
"dateUpdated": "2026-08-19T16:28:59.684Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68355 (GCVE-0-2026-68355)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: ath11k: fix potential buffer underflow in ath11k_hal_rx_msdu_list_get()
When the first entry in msdu_details has a zero buffer address,
the code accesses msdu_details[i - 1] with i == 0, causing a
buffer underflow.
Fix similarly to ath12k_wifi7_hal_rx_msdu_list_get() by adding
a separate check for i == 0 before the main condition to prevent
the out-of-bounds access.
Found by Linux Verification Center (linuxtesting.org) with SVACE.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d5c65159f2895379e11ca13f62feabe93278985d Version: d5c65159f2895379e11ca13f62feabe93278985d Version: d5c65159f2895379e11ca13f62feabe93278985d Version: d5c65159f2895379e11ca13f62feabe93278985d Version: d5c65159f2895379e11ca13f62feabe93278985d Version: d5c65159f2895379e11ca13f62feabe93278985d Version: d5c65159f2895379e11ca13f62feabe93278985d Version: d5c65159f2895379e11ca13f62feabe93278985d |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/ath/ath11k/dp_rx.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "085a5fde5bac29c01059e69399b417e91c0a6c18",
"status": "affected",
"version": "d5c65159f2895379e11ca13f62feabe93278985d",
"versionType": "git"
},
{
"lessThan": "31ea4b175bc3ab430be15834d9ee8a1ce65bee15",
"status": "affected",
"version": "d5c65159f2895379e11ca13f62feabe93278985d",
"versionType": "git"
},
{
"lessThan": "20d18a5ec6ec364fcaf0d03af6fc43dcc42c6591",
"status": "affected",
"version": "d5c65159f2895379e11ca13f62feabe93278985d",
"versionType": "git"
},
{
"lessThan": "69a6a4f60b2da92c0bdfd9264b8ffe053f51f52a",
"status": "affected",
"version": "d5c65159f2895379e11ca13f62feabe93278985d",
"versionType": "git"
},
{
"lessThan": "904367381a922aa2dc3e8bd2488e6c9180516c7a",
"status": "affected",
"version": "d5c65159f2895379e11ca13f62feabe93278985d",
"versionType": "git"
},
{
"lessThan": "a154ca3c441a67d36b3a9ea63a4f11b06abe6223",
"status": "affected",
"version": "d5c65159f2895379e11ca13f62feabe93278985d",
"versionType": "git"
},
{
"lessThan": "725c1c3a8c5d920a7d3f5887412f2ad8e95a74f5",
"status": "affected",
"version": "d5c65159f2895379e11ca13f62feabe93278985d",
"versionType": "git"
},
{
"lessThan": "7f11e70629650ff6ea140984e5ce188b775b2683",
"status": "affected",
"version": "d5c65159f2895379e11ca13f62feabe93278985d",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/ath/ath11k/dp_rx.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.6"
},
{
"lessThan": "5.6",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath11k: fix potential buffer underflow in ath11k_hal_rx_msdu_list_get()\n\nWhen the first entry in msdu_details has a zero buffer address,\nthe code accesses msdu_details[i - 1] with i == 0, causing a\nbuffer underflow.\n\nFix similarly to ath12k_wifi7_hal_rx_msdu_list_get() by adding\na separate check for i == 0 before the main condition to prevent\nthe out-of-bounds access.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:03.197Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/085a5fde5bac29c01059e69399b417e91c0a6c18"
},
{
"url": "https://git.kernel.org/stable/c/31ea4b175bc3ab430be15834d9ee8a1ce65bee15"
},
{
"url": "https://git.kernel.org/stable/c/20d18a5ec6ec364fcaf0d03af6fc43dcc42c6591"
},
{
"url": "https://git.kernel.org/stable/c/69a6a4f60b2da92c0bdfd9264b8ffe053f51f52a"
},
{
"url": "https://git.kernel.org/stable/c/904367381a922aa2dc3e8bd2488e6c9180516c7a"
},
{
"url": "https://git.kernel.org/stable/c/a154ca3c441a67d36b3a9ea63a4f11b06abe6223"
},
{
"url": "https://git.kernel.org/stable/c/725c1c3a8c5d920a7d3f5887412f2ad8e95a74f5"
},
{
"url": "https://git.kernel.org/stable/c/7f11e70629650ff6ea140984e5ce188b775b2683"
}
],
"title": "wifi: ath11k: fix potential buffer underflow in ath11k_hal_rx_msdu_list_get()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68355",
"datePublished": "2026-08-10T12:03:32.321Z",
"dateReserved": "2026-07-30T09:28:09.385Z",
"dateUpdated": "2026-08-19T16:34:03.197Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68116 (GCVE-0-2026-68116)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-17 04:59
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
vxlan: mdb: Fix source list corruption on a failed replace
When replacing the source list of an MDB remote entry, all existing
sources are first marked for deletion and vxlan_mdb_remote_srcs_add()
is then called to add the new source list. Sources present in the new
list have their deletion mark cleared, and any sources left marked
afterwards are removed.
If vxlan_mdb_remote_srcs_add() fails partway through, its error path
deletes all entries on the remote's source list. That rollback is only
correct for its other caller, vxlan_mdb_remote_add(), where the remote
was just allocated and the list contains solely entries added during
the call. On the replace path the list also holds pre-existing sources,
so a failed replace tears them down together with their (S, G)
forwarding entries instead of leaving the entry unchanged.
This is reachable from an existing (*, G) remote. An EXCLUDE filter
that loses sources starts forwarding traffic that should be blocked,
while an INCLUDE filter that loses sources drops traffic that should be
forwarded.
Mark entries created during the current pass with a new
VXLAN_SGRP_F_NEW flag. On failure, delete only those entries and clear
the deletion mark on the pre-existing ones, so a failed replace leaves
the source list untouched. Retain the flag until the whole operation
succeeds and then clear it. Also stop vxlan_mdb_remote_src_add() from
deleting a pre-existing entry it only looked up when adding that
entry's forwarding entry fails.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/vxlan/vxlan_mdb.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "5bc8fc1d2ff802eec839e03adef5df597421898d",
"status": "affected",
"version": "a3a48de5eade770e911d35291217bdd69ce04ef1",
"versionType": "git"
},
{
"lessThan": "2c54dff57606590fa4abec46bab6bea3133f1539",
"status": "affected",
"version": "a3a48de5eade770e911d35291217bdd69ce04ef1",
"versionType": "git"
},
{
"lessThan": "79370b573e92e8f190eb5f9a511fa5398340d8b2",
"status": "affected",
"version": "a3a48de5eade770e911d35291217bdd69ce04ef1",
"versionType": "git"
},
{
"lessThan": "54a3c27b357dfb34f327f89bfadeb998bef8051e",
"status": "affected",
"version": "a3a48de5eade770e911d35291217bdd69ce04ef1",
"versionType": "git"
},
{
"lessThan": "dcd9b465965422b9654f6026e8a2fa8984f74c3c",
"status": "affected",
"version": "a3a48de5eade770e911d35291217bdd69ce04ef1",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/vxlan/vxlan_mdb.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.4"
},
{
"lessThan": "6.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nvxlan: mdb: Fix source list corruption on a failed replace\n\nWhen replacing the source list of an MDB remote entry, all existing\nsources are first marked for deletion and vxlan_mdb_remote_srcs_add()\nis then called to add the new source list. Sources present in the new\nlist have their deletion mark cleared, and any sources left marked\nafterwards are removed.\n\nIf vxlan_mdb_remote_srcs_add() fails partway through, its error path\ndeletes all entries on the remote\u0027s source list. That rollback is only\ncorrect for its other caller, vxlan_mdb_remote_add(), where the remote\nwas just allocated and the list contains solely entries added during\nthe call. On the replace path the list also holds pre-existing sources,\nso a failed replace tears them down together with their (S, G)\nforwarding entries instead of leaving the entry unchanged.\n\nThis is reachable from an existing (*, G) remote. An EXCLUDE filter\nthat loses sources starts forwarding traffic that should be blocked,\nwhile an INCLUDE filter that loses sources drops traffic that should be\nforwarded.\n\nMark entries created during the current pass with a new\nVXLAN_SGRP_F_NEW flag. On failure, delete only those entries and clear\nthe deletion mark on the pre-existing ones, so a failed replace leaves\nthe source list untouched. Retain the flag until the whole operation\nsucceeds and then clear it. Also stop vxlan_mdb_remote_src_add() from\ndeleting a pre-existing entry it only looked up when adding that\nentry\u0027s forwarding entry fails."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.9,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is only reachable via the RTM_NEWMDB rtnetlink control path (ndo_mdb_add); multicast data-plane packets use vxlan_mdb_xmit and never hit the replace/rollback logic.\nAC:L - An attacker with CAP_NET_ADMIN can create an existing (*,G) remote, issue NLM_F_REPLACE with a new source list, and reliably force vxlan_mdb_remote_srcs_add() to fail mid-loop (e.g., ENOMEM via memory pressure) to trigger the bad rollback.\nPR:L - rtnetlink requires CAP_NET_ADMIN for RTM_NEWMDB; this capability is obtainable by unprivileged users inside user/network namespaces, not solely by init-namespace root.\nUI:N - Exploitation requires only crafted rtnetlink MDB messages from a process with network-admin capability; no victim user action is needed.\nS:C - A corrupted EXCLUDE source list forwards multicast that policy intended to block to VXLAN remote peers, crossing intended overlay segmentation boundaries beyond the misconfigured netdev\u0027s local authority.\nC:L - EXCLUDE filter corruption removes per-source block rules, causing multicast payloads from previously blocked sources to be encapsulated and delivered to unauthorized VXLAN remotes.\nI:L - Failed replace corrupts MDB source lists and (S,G) forwarding state, causing unauthorized multicast delivery (EXCLUDE) or dropping traffic that should be forwarded (INCLUDE).\nA:H - INCLUDE filter corruption can wipe all source entries on a (*,G) remote, causing vxlan_mdb_xmit to permanently drop all multicast for that group until MDB state is manually repaired."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:59:06.287Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/5bc8fc1d2ff802eec839e03adef5df597421898d"
},
{
"url": "https://git.kernel.org/stable/c/2c54dff57606590fa4abec46bab6bea3133f1539"
},
{
"url": "https://git.kernel.org/stable/c/79370b573e92e8f190eb5f9a511fa5398340d8b2"
},
{
"url": "https://git.kernel.org/stable/c/54a3c27b357dfb34f327f89bfadeb998bef8051e"
},
{
"url": "https://git.kernel.org/stable/c/dcd9b465965422b9654f6026e8a2fa8984f74c3c"
}
],
"title": "vxlan: mdb: Fix source list corruption on a failed replace",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68116",
"datePublished": "2026-08-10T11:58:34.612Z",
"dateReserved": "2026-07-30T09:28:09.369Z",
"dateUpdated": "2026-08-17T04:59:06.287Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68135 (GCVE-0-2026-68135)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-19 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: hip04: fix RX buffer leak on build_skb failure
When build_skb() fails in hip04_rx_poll(), the driver jumps to the
refill path without releasing the current RX buffer and its DMA mapping.
Installing a replacement buffer then overwrites the slot references and
leaks both resources.
Keep the current slot intact and return budget so NAPI retries the same
buffer. Also free a newly allocated RX fragment when dma_map_single()
fails.
This issue was found by an in-house static analysis tool.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 701a0fd5231866db08cebcd502894699f49cb960 Version: 701a0fd5231866db08cebcd502894699f49cb960 Version: 701a0fd5231866db08cebcd502894699f49cb960 Version: 701a0fd5231866db08cebcd502894699f49cb960 Version: 701a0fd5231866db08cebcd502894699f49cb960 Version: 701a0fd5231866db08cebcd502894699f49cb960 Version: 701a0fd5231866db08cebcd502894699f49cb960 Version: 701a0fd5231866db08cebcd502894699f49cb960 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/hisilicon/hip04_eth.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "690ecc13a4032e5cae1dc6659512f32b033533b0",
"status": "affected",
"version": "701a0fd5231866db08cebcd502894699f49cb960",
"versionType": "git"
},
{
"lessThan": "2b19fe277645fd1aeb18fd4ecdcf31966080dee7",
"status": "affected",
"version": "701a0fd5231866db08cebcd502894699f49cb960",
"versionType": "git"
},
{
"lessThan": "bcd43ee1f25b682151df213c06a99b2e1c1cf2e5",
"status": "affected",
"version": "701a0fd5231866db08cebcd502894699f49cb960",
"versionType": "git"
},
{
"lessThan": "e054dcd990d8180cde529ea28ce0838e76a5ad5e",
"status": "affected",
"version": "701a0fd5231866db08cebcd502894699f49cb960",
"versionType": "git"
},
{
"lessThan": "67a7614bde310da006ab259f4f163d3fb0f9e253",
"status": "affected",
"version": "701a0fd5231866db08cebcd502894699f49cb960",
"versionType": "git"
},
{
"lessThan": "80d977f280b4eccd4ac5369871d0ecb2b9c9a49d",
"status": "affected",
"version": "701a0fd5231866db08cebcd502894699f49cb960",
"versionType": "git"
},
{
"lessThan": "a0f247d63489a107bbc3b712a77b302af2a2a173",
"status": "affected",
"version": "701a0fd5231866db08cebcd502894699f49cb960",
"versionType": "git"
},
{
"lessThan": "14fa65d10f5696b063a7d8d26e8291ea84a2c6ed",
"status": "affected",
"version": "701a0fd5231866db08cebcd502894699f49cb960",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/hisilicon/hip04_eth.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.5"
},
{
"lessThan": "4.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: hip04: fix RX buffer leak on build_skb failure\n\nWhen build_skb() fails in hip04_rx_poll(), the driver jumps to the\nrefill path without releasing the current RX buffer and its DMA mapping.\nInstalling a replacement buffer then overwrites the slot references and\nleaks both resources.\n\nKeep the current slot intact and return budget so NAPI retries the same\nbuffer. Also free a newly allocated RX fragment when dma_map_single()\nfails.\n\nThis issue was found by an in-house static analysis tool."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:29:52.114Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/690ecc13a4032e5cae1dc6659512f32b033533b0"
},
{
"url": "https://git.kernel.org/stable/c/2b19fe277645fd1aeb18fd4ecdcf31966080dee7"
},
{
"url": "https://git.kernel.org/stable/c/bcd43ee1f25b682151df213c06a99b2e1c1cf2e5"
},
{
"url": "https://git.kernel.org/stable/c/e054dcd990d8180cde529ea28ce0838e76a5ad5e"
},
{
"url": "https://git.kernel.org/stable/c/67a7614bde310da006ab259f4f163d3fb0f9e253"
},
{
"url": "https://git.kernel.org/stable/c/80d977f280b4eccd4ac5369871d0ecb2b9c9a49d"
},
{
"url": "https://git.kernel.org/stable/c/a0f247d63489a107bbc3b712a77b302af2a2a173"
},
{
"url": "https://git.kernel.org/stable/c/14fa65d10f5696b063a7d8d26e8291ea84a2c6ed"
}
],
"title": "net: hip04: fix RX buffer leak on build_skb failure",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68135",
"datePublished": "2026-08-10T11:58:58.463Z",
"dateReserved": "2026-07-30T09:28:09.370Z",
"dateUpdated": "2026-08-19T16:29:52.114Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68339 (GCVE-0-2026-68339)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-17 05:03
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: btusb: validate Realtek vendor event length
btusb_recv_event_realtek() reads the event code at data[0] and the Realtek
subevent code at data[2] before deciding whether to consume a vendor event
as a coredump.
For example, the two-byte event ff 00 contains a complete vendor-event
header declaring zero parameters. The old classifier still reads a
nonexistent third byte and can misclassify the event as a coredump if the
adjacent byte is 0x34.
Require the HCI event header and first parameter to be present before
inspecting the Realtek subevent code. Short events continue through the
normal HCI receive path, which owns their protocol validation.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/bluetooth/btusb.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "8de58bfa26e028f99271dde5a92107cd07f5e063",
"status": "affected",
"version": "044014ce85a17c0b7fab8e5df0925792010c29b2",
"versionType": "git"
},
{
"lessThan": "400267bab0f4076088e163e58cad2bb41c3cf5e7",
"status": "affected",
"version": "044014ce85a17c0b7fab8e5df0925792010c29b2",
"versionType": "git"
},
{
"lessThan": "8881daaafadbe7fb2b7341d16a3949114409c90c",
"status": "affected",
"version": "044014ce85a17c0b7fab8e5df0925792010c29b2",
"versionType": "git"
},
{
"lessThan": "24b0758193d70da47ef8b979153d2a181dbdf34e",
"status": "affected",
"version": "044014ce85a17c0b7fab8e5df0925792010c29b2",
"versionType": "git"
},
{
"lessThan": "df541cd485ff80a5ddc579d99687bc7506df9851",
"status": "affected",
"version": "044014ce85a17c0b7fab8e5df0925792010c29b2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/bluetooth/btusb.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.6"
},
{
"lessThan": "6.6",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: btusb: validate Realtek vendor event length\n\nbtusb_recv_event_realtek() reads the event code at data[0] and the Realtek\nsubevent code at data[2] before deciding whether to consume a vendor event\nas a coredump.\n\nFor example, the two-byte event ff 00 contains a complete vendor-event\nheader declaring zero parameters. The old classifier still reads a\nnonexistent third byte and can misclassify the event as a coredump if the\nadjacent byte is 0x34.\n\nRequire the HCI event header and first parameter to be present before\ninspecting the Realtek subevent code. Short events continue through the\nnormal HCI receive path, which owns their protocol validation."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:03:38.589Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/8de58bfa26e028f99271dde5a92107cd07f5e063"
},
{
"url": "https://git.kernel.org/stable/c/400267bab0f4076088e163e58cad2bb41c3cf5e7"
},
{
"url": "https://git.kernel.org/stable/c/8881daaafadbe7fb2b7341d16a3949114409c90c"
},
{
"url": "https://git.kernel.org/stable/c/24b0758193d70da47ef8b979153d2a181dbdf34e"
},
{
"url": "https://git.kernel.org/stable/c/df541cd485ff80a5ddc579d99687bc7506df9851"
}
],
"title": "Bluetooth: btusb: validate Realtek vendor event length",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68339",
"datePublished": "2026-08-10T12:03:15.551Z",
"dateReserved": "2026-07-30T09:28:09.384Z",
"dateUpdated": "2026-08-17T05:03:38.589Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68117 (GCVE-0-2026-68117)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-19 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
tipc: clear sock->sk on the failed-insert path in tipc_sk_create()
When tipc_sk_create() fails to insert the new socket (tipc_sk_insert()
returns non-zero), its error path frees the sk with sk_free() but leaves
sock->sk pointing at the freed object:
if (tipc_sk_insert(tsk)) {
sk_free(sk);
pr_warn("Socket create failed; port number exhausted\n");
return -EINVAL;
}
This is harmless for plain socket(): the syscall layer clears sock->ops
before releasing, so tipc_release() is never called. It is not harmless
on the accept() path. tipc_accept() creates the pre-allocated child
socket with tipc_sk_create(net, new_sock, 0, kern); on failure it leaves
new_sock->sk dangling and new_sock->ops non-NULL, and do_accept() then
fput()s the new file, so __sock_release() -> tipc_release() runs
lock_sock(new_sock->sk) on the freed sk -- a use-after-free write of the
sk_lock spinlock.
tipc_release() already guards this exact "failed accept() releases a
pre-allocated child" case with "if (sk == NULL) return 0;", but the
guard is bypassed because tipc_sk_create() left sock->sk non-NULL
(dangling) rather than NULL.
Clear sock->sk on the failed-insert path so the existing tipc_release()
NULL check fires and the use-after-free is avoided.
The tipc_sk_insert() failure is reached when the per-netns socket
rhashtable hits its max_size (tsk_rht_params.max_size = 1048576, ~2M
elements) -- i.e. once a netns holds ~2M TIPC sockets every insert
returns -E2BIG.
BUG: KASAN: slab-use-after-free in lock_sock_nested (net/core/sock.c:3839)
Write of size 8 at addr ffff8880047cdc38 by task init/1
lock_sock_nested (net/core/sock.c:3839)
tipc_release (net/tipc/socket.c:638)
__sock_release (net/socket.c:710)
sock_close (net/socket.c:1501)
__fput (fs/file_table.c:512)
Allocated by task 1:
sk_alloc (net/core/sock.c:2308)
tipc_sk_create (net/tipc/socket.c:487)
tipc_accept (net/tipc/socket.c:2744)
do_accept (net/socket.c:2034)
Freed by task 1:
__sk_destruct (net/core/sock.c:2391)
tipc_sk_create (net/tipc/socket.c:504)
tipc_accept (net/tipc/socket.c:2744)
do_accept (net/socket.c:2034)
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: efa78f2ae363428525fb4981bb63c555ee79f3c7 Version: 833ecd0eae76eadf81d6d747bb5bc992d1151867 Version: 00aff3590fc0a73bddd3b743863c14e76fd35c0c Version: 00aff3590fc0a73bddd3b743863c14e76fd35c0c Version: 00aff3590fc0a73bddd3b743863c14e76fd35c0c Version: 00aff3590fc0a73bddd3b743863c14e76fd35c0c Version: 00aff3590fc0a73bddd3b743863c14e76fd35c0c Version: 00aff3590fc0a73bddd3b743863c14e76fd35c0c Version: 638fa20b618b2bbcf86da71231624cc82121a036 Version: 7bc9e7f70bc57d8f02ffea2a42094281effb15ef Version: ef488669b2652bde5b6ee5a409a5b048a2a50db4 Version: 4919d82f7041157a421ca9bf39a78551d5ad8a1b Version: 3b2957fc09fe1ac7f07f40dd50dd5f93e3f3a7a2 Version: 5.10.132 ≤ Version: 5.15.56 ≤ Version: 4.9.324 ≤ Version: 4.14.289 ≤ Version: 4.19.253 ≤ Version: 5.4.207 ≤ Version: 5.18.13 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/tipc/socket.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "efebc23e9b29e3e5a9e2127dd066929f7f0d315e",
"status": "affected",
"version": "efa78f2ae363428525fb4981bb63c555ee79f3c7",
"versionType": "git"
},
{
"lessThan": "8d6f26d48e61ef34f1921289401dbf36b10816af",
"status": "affected",
"version": "833ecd0eae76eadf81d6d747bb5bc992d1151867",
"versionType": "git"
},
{
"lessThan": "82f59aa27f33bd014a7d8739371ab5712d15e33b",
"status": "affected",
"version": "00aff3590fc0a73bddd3b743863c14e76fd35c0c",
"versionType": "git"
},
{
"lessThan": "b07d87b31631edb6529e6cdcca790a7489d1250d",
"status": "affected",
"version": "00aff3590fc0a73bddd3b743863c14e76fd35c0c",
"versionType": "git"
},
{
"lessThan": "dd29891ed840f6b8d020b759d0dc4a00b1d6e4ea",
"status": "affected",
"version": "00aff3590fc0a73bddd3b743863c14e76fd35c0c",
"versionType": "git"
},
{
"lessThan": "5f5a41a48dbf9eda57b67ce23e548602cf7195a6",
"status": "affected",
"version": "00aff3590fc0a73bddd3b743863c14e76fd35c0c",
"versionType": "git"
},
{
"lessThan": "f9596b1566616a8be0592dbceccb6344a7c6f6bb",
"status": "affected",
"version": "00aff3590fc0a73bddd3b743863c14e76fd35c0c",
"versionType": "git"
},
{
"lessThan": "ba0533fc163f905fe817cfabdf8ed4058da44800",
"status": "affected",
"version": "00aff3590fc0a73bddd3b743863c14e76fd35c0c",
"versionType": "git"
},
{
"status": "affected",
"version": "638fa20b618b2bbcf86da71231624cc82121a036",
"versionType": "git"
},
{
"status": "affected",
"version": "7bc9e7f70bc57d8f02ffea2a42094281effb15ef",
"versionType": "git"
},
{
"status": "affected",
"version": "ef488669b2652bde5b6ee5a409a5b048a2a50db4",
"versionType": "git"
},
{
"status": "affected",
"version": "4919d82f7041157a421ca9bf39a78551d5ad8a1b",
"versionType": "git"
},
{
"status": "affected",
"version": "3b2957fc09fe1ac7f07f40dd50dd5f93e3f3a7a2",
"versionType": "git"
},
{
"lessThan": "5.10.265",
"status": "affected",
"version": "5.10.132",
"versionType": "semver"
},
{
"lessThan": "5.15.216",
"status": "affected",
"version": "5.15.56",
"versionType": "semver"
},
{
"lessThan": "4.10",
"status": "affected",
"version": "4.9.324",
"versionType": "semver"
},
{
"lessThan": "4.15",
"status": "affected",
"version": "4.14.289",
"versionType": "semver"
},
{
"lessThan": "4.20",
"status": "affected",
"version": "4.19.253",
"versionType": "semver"
},
{
"lessThan": "5.5",
"status": "affected",
"version": "5.4.207",
"versionType": "semver"
},
{
"lessThan": "5.19",
"status": "affected",
"version": "5.18.13",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/tipc/socket.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.19"
},
{
"lessThan": "5.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.10.132",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.15.56",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.9.324",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.14.289",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.19.253",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.4.207",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.18.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: clear sock-\u003esk on the failed-insert path in tipc_sk_create()\n\nWhen tipc_sk_create() fails to insert the new socket (tipc_sk_insert()\nreturns non-zero), its error path frees the sk with sk_free() but leaves\nsock-\u003esk pointing at the freed object:\n\n\tif (tipc_sk_insert(tsk)) {\n\t\tsk_free(sk);\n\t\tpr_warn(\"Socket create failed; port number exhausted\\n\");\n\t\treturn -EINVAL;\n\t}\n\nThis is harmless for plain socket(): the syscall layer clears sock-\u003eops\nbefore releasing, so tipc_release() is never called. It is not harmless\non the accept() path. tipc_accept() creates the pre-allocated child\nsocket with tipc_sk_create(net, new_sock, 0, kern); on failure it leaves\nnew_sock-\u003esk dangling and new_sock-\u003eops non-NULL, and do_accept() then\nfput()s the new file, so __sock_release() -\u003e tipc_release() runs\nlock_sock(new_sock-\u003esk) on the freed sk -- a use-after-free write of the\nsk_lock spinlock.\n\ntipc_release() already guards this exact \"failed accept() releases a\npre-allocated child\" case with \"if (sk == NULL) return 0;\", but the\nguard is bypassed because tipc_sk_create() left sock-\u003esk non-NULL\n(dangling) rather than NULL.\n\nClear sock-\u003esk on the failed-insert path so the existing tipc_release()\nNULL check fires and the use-after-free is avoided.\n\nThe tipc_sk_insert() failure is reached when the per-netns socket\nrhashtable hits its max_size (tsk_rht_params.max_size = 1048576, ~2M\nelements) -- i.e. once a netns holds ~2M TIPC sockets every insert\nreturns -E2BIG.\n\n BUG: KASAN: slab-use-after-free in lock_sock_nested (net/core/sock.c:3839)\n Write of size 8 at addr ffff8880047cdc38 by task init/1\n lock_sock_nested (net/core/sock.c:3839)\n tipc_release (net/tipc/socket.c:638)\n __sock_release (net/socket.c:710)\n sock_close (net/socket.c:1501)\n __fput (fs/file_table.c:512)\n Allocated by task 1:\n sk_alloc (net/core/sock.c:2308)\n tipc_sk_create (net/tipc/socket.c:487)\n tipc_accept (net/tipc/socket.c:2744)\n do_accept (net/socket.c:2034)\n Freed by task 1:\n __sk_destruct (net/core/sock.c:2391)\n tipc_sk_create (net/tipc/socket.c:504)\n tipc_accept (net/tipc/socket.c:2744)\n do_accept (net/socket.c:2034)"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug is hit in tipc_accept() when a listening SOCK_STREAM/SOCK_SEQPACKET socket accepts an incoming TIPC connection; peers reach this path over default UDP/Ethernet bearers (e.g. UDP/6118) without local syscall access.\nAC:L - An attacker can deterministically fill the per-netns TIPC socket rhashtable (~2M entries) by opening many sockets or connections, then trigger the failed-insert accept() cleanup path that performs lock_sock() on the freed sk.\nPR:N - No elevated Linux capabilities are required to create AF_TIPC stream/seqpacket sockets or send unauthenticated TIPC SYN traffic to a listening cluster service; only LSM policy may restrict access.\nUI:N - Exploitation needs no end-user action beyond a server\u2019s normal accept() loop processing inbound TIPC connection requests queued by the network stack.\nS:U - The use-after-free corrupts kernel heap memory within the same kernel security domain; impact is kernel privilege escalation or crash, not a VM/hypervisor or IOMMU boundary crossing.\nC:H - tipc_release() calls lock_sock() on a freed struct sock, a slab use-after-free that can be groomed for arbitrary kernel memory disclosure via controlled reuse of the freed socket object.\nI:H - The UAF performs an 8-byte write to sk_lock on freed memory during socket teardown, enabling heap corruption and potential arbitrary kernel write or code execution primitives.\nA:H - KASAN reports slab-use-after-free in lock_sock_nested during tipc_release on the failed accept() path, causing kernel oops/panic and denial of service even without full exploitation."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:29:29.277Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/efebc23e9b29e3e5a9e2127dd066929f7f0d315e"
},
{
"url": "https://git.kernel.org/stable/c/8d6f26d48e61ef34f1921289401dbf36b10816af"
},
{
"url": "https://git.kernel.org/stable/c/82f59aa27f33bd014a7d8739371ab5712d15e33b"
},
{
"url": "https://git.kernel.org/stable/c/b07d87b31631edb6529e6cdcca790a7489d1250d"
},
{
"url": "https://git.kernel.org/stable/c/dd29891ed840f6b8d020b759d0dc4a00b1d6e4ea"
},
{
"url": "https://git.kernel.org/stable/c/5f5a41a48dbf9eda57b67ce23e548602cf7195a6"
},
{
"url": "https://git.kernel.org/stable/c/f9596b1566616a8be0592dbceccb6344a7c6f6bb"
},
{
"url": "https://git.kernel.org/stable/c/ba0533fc163f905fe817cfabdf8ed4058da44800"
}
],
"title": "tipc: clear sock-\u003esk on the failed-insert path in tipc_sk_create()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68117",
"datePublished": "2026-08-10T11:58:36.675Z",
"dateReserved": "2026-07-30T09:28:09.369Z",
"dateUpdated": "2026-08-19T16:29:29.277Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72045 (GCVE-0-2026-72045)
Vulnerability from cvelistv5
Published
2026-08-15 05:52
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
octeontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF
rvu_mbox_handler_lmtst_tbl_setup() uses req->base_pcifunc as a direct
index into the LMT map table to read another function's LMTLINE
physical base address and copy it into the caller's own LMT map table
entry. The mailbox dispatcher authenticates req->hdr.pcifunc from the
IRQ source, but req->base_pcifunc is a separate payload field and is
not sanitized.
Reject the request with -EPERM when a VF caller's base_pcifunc is not a
valid function under its own PF. is_pf_func_valid() bounds the FUNC field
to the PF's configured VF count, keeping the computed index inside the
caller's own slot block.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 893ae97214c385be02f8ec097298cc48c7f0d905 Version: 893ae97214c385be02f8ec097298cc48c7f0d905 Version: 893ae97214c385be02f8ec097298cc48c7f0d905 Version: 893ae97214c385be02f8ec097298cc48c7f0d905 Version: 893ae97214c385be02f8ec097298cc48c7f0d905 Version: 893ae97214c385be02f8ec097298cc48c7f0d905 Version: 893ae97214c385be02f8ec097298cc48c7f0d905 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/marvell/octeontx2/af/rvu_cn10k.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "04c014e49b9f53d58a8f94adece8a0af3ae1b85c",
"status": "affected",
"version": "893ae97214c385be02f8ec097298cc48c7f0d905",
"versionType": "git"
},
{
"lessThan": "6967dd944be2a71eddab3a2ae1a1a4dd9e5f8eed",
"status": "affected",
"version": "893ae97214c385be02f8ec097298cc48c7f0d905",
"versionType": "git"
},
{
"lessThan": "e9c5b03208507dd6d58b0c23a2c60b5c2f4c1b11",
"status": "affected",
"version": "893ae97214c385be02f8ec097298cc48c7f0d905",
"versionType": "git"
},
{
"lessThan": "54535692bec9ef464adc714108eb19e49e38b5a2",
"status": "affected",
"version": "893ae97214c385be02f8ec097298cc48c7f0d905",
"versionType": "git"
},
{
"lessThan": "c73b8795b45f4ad5a95120d2e9b435ea4616e08e",
"status": "affected",
"version": "893ae97214c385be02f8ec097298cc48c7f0d905",
"versionType": "git"
},
{
"lessThan": "59da37fee81a8d76079313348ca13c5bc90dd6ae",
"status": "affected",
"version": "893ae97214c385be02f8ec097298cc48c7f0d905",
"versionType": "git"
},
{
"lessThan": "8cdcf3d2caacdee7ddd363705fb4d93b0c1a0915",
"status": "affected",
"version": "893ae97214c385be02f8ec097298cc48c7f0d905",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/marvell/octeontx2/af/rvu_cn10k.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.14"
},
{
"lessThan": "5.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nocteontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF\n\nrvu_mbox_handler_lmtst_tbl_setup() uses req-\u003ebase_pcifunc as a direct\nindex into the LMT map table to read another function\u0027s LMTLINE\nphysical base address and copy it into the caller\u0027s own LMT map table\nentry. The mailbox dispatcher authenticates req-\u003ehdr.pcifunc from the\nIRQ source, but req-\u003ebase_pcifunc is a separate payload field and is\nnot sanitized.\n\nReject the request with -EPERM when a VF caller\u0027s base_pcifunc is not a\nvalid function under its own PF. is_pf_func_valid() bounds the FUNC field\nto the PF\u0027s configured VF count, keeping the computed index inside the\ncaller\u0027s own slot block."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires local control of an assigned Marvell CN10K/OCTEONTX2 SR-IOV VF and sending a crafted LMTST_TBL_SETUP mailbox message over the PCI VF\u2192AF control path (rvu_afvf_mbox_handler\u2192rvu_mbox_handler_lmtst_tbl_setup); it is not reachable via remote packet delivery.\nAC:L - Once a VF is assigned, the attacker fully controls the unsanitized base_pcifunc payload field and can trigger the flaw deterministically with a single mailbox message; no race, special memory layout, or victim timing is required.\nPR:L - Only control of an assigned VF is needed (typical cloud/tenant VM or container with SR-IOV passthrough, or guest root/CAP_NET_ADMIN managing the VF); host init-namespace root is not required and unprivileged host users cannot reach this hardware mailbox without the VF device.\nUI:N - No victim user action is required; the attacker directly sends the malicious LMTST_TBL_SETUP mailbox request from their VF to the AF handler.\nS:C - A malicious VF tenant can retarget hardware LMTLINE stores to another PF/VF\u0027s memory region, crossing the SR-IOV tenant isolation boundary and enabling guest-to-host or guest-to-guest impact on shared CN10K NIC deployments.\nC:H - Redirecting a VF\u0027s LMT map entry to another function\u0027s LMTLINE region lets the attacker read victim in-flight packet/crypto submission metadata and buffer pointers from shared hardware LMT memory, constituting cross-tenant information disclosure beyond the attacker\u0027s scope.\nI:H - After the map-table redirect, the attacker\u0027s LMTST flush operations (packet TX SQE submission, NPA aura free, CPT enqueue) are hardware-written into the victim\u0027s LMTLINE physical pages, enabling arbitrary cross-tenant memory corruption and potential control of victim I/O submission state.\nA:H - Corrupting another PF/VF\u0027s LMTLINE submission buffers can crash or hang the victim\u0027s networking/crypto stack (guest kernel oops/panic or persistent TX failure) and the attack can be repeated on demand by resending mailbox requests."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:33.156Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/04c014e49b9f53d58a8f94adece8a0af3ae1b85c"
},
{
"url": "https://git.kernel.org/stable/c/6967dd944be2a71eddab3a2ae1a1a4dd9e5f8eed"
},
{
"url": "https://git.kernel.org/stable/c/e9c5b03208507dd6d58b0c23a2c60b5c2f4c1b11"
},
{
"url": "https://git.kernel.org/stable/c/54535692bec9ef464adc714108eb19e49e38b5a2"
},
{
"url": "https://git.kernel.org/stable/c/c73b8795b45f4ad5a95120d2e9b435ea4616e08e"
},
{
"url": "https://git.kernel.org/stable/c/59da37fee81a8d76079313348ca13c5bc90dd6ae"
},
{
"url": "https://git.kernel.org/stable/c/8cdcf3d2caacdee7ddd363705fb4d93b0c1a0915"
}
],
"title": "octeontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72045",
"datePublished": "2026-08-15T05:52:04.038Z",
"dateReserved": "2026-08-09T03:40:39.902Z",
"dateUpdated": "2026-08-23T12:46:33.156Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72119 (GCVE-0-2026-72119)
Vulnerability from cvelistv5
Published
2026-08-15 05:52
Modified
2026-08-19 16:36
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
can: bcm: extend bcm_tx_lock usage for data and timer updates
Stage new CAN frame content for an existing tx op into a kmalloc()'d
buffer and validate it there, mirroring the approach already used in
bcm_rx_setup(). Only copy the validated data into op->frames while
holding op->bcm_tx_lock, so bcm_can_tx() and bcm_tx_timeout_handler()
can no longer observe a partially updated or unvalidated frame.
Add a missing error path for memcpy_from_msg() when copying CAN frame
data from userspace.
Also move the kt_ival1/kt_ival2/ival1/ival2 updates in bcm_tx_setup()
under op->bcm_tx_lock, and read kt_ival1/kt_ival2/count under the same
lock in bcm_tx_set_expiry() and bcm_tx_timeout_handler(), closing the
torn 64-bit ktime_t read on 32-bit platforms.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 7595de7bc56e0e52b74e56c90f7e247bf626d628 Version: fbd8fdc2b218e979cfe422b139b8f74c12419d1f Version: 2a437b86ac5a9893c902f30ef66815bf13587bf6 Version: 76c84c3728178b2d38d5604e399dfe8b0752645e Version: cc55dd28c20a6611e30596019b3b2f636819a4c0 Version: c2aba69d0c36a496ab4f2e81e9c2b271f2693fd7 Version: c2aba69d0c36a496ab4f2e81e9c2b271f2693fd7 Version: c2aba69d0c36a496ab4f2e81e9c2b271f2693fd7 Version: 8f1c022541bf5a923c8d6fa483112c15250f30a4 Version: c4e8a172501e677ebd8ea9d9161d97dc4df56fbd Version: 5.10.238 ≤ Version: 5.15.185 ≤ Version: 6.1.141 ≤ Version: 6.6.93 ≤ Version: 6.12.31 ≤ Version: 5.4.294 ≤ Version: 6.14.9 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/can/bcm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a538b072ee074c9b41b9d9c15a6861a963e30755",
"status": "affected",
"version": "7595de7bc56e0e52b74e56c90f7e247bf626d628",
"versionType": "git"
},
{
"lessThan": "63422347b4c782f429748b2a09cd3cf3b77e6abd",
"status": "affected",
"version": "fbd8fdc2b218e979cfe422b139b8f74c12419d1f",
"versionType": "git"
},
{
"lessThan": "37917e432e50b7de2b64230974380132a30f7270",
"status": "affected",
"version": "2a437b86ac5a9893c902f30ef66815bf13587bf6",
"versionType": "git"
},
{
"lessThan": "52f06e7603780de100233713ddaf971d422e10ef",
"status": "affected",
"version": "76c84c3728178b2d38d5604e399dfe8b0752645e",
"versionType": "git"
},
{
"lessThan": "972fd66bb08fdef1090abe43196ca8da07216d13",
"status": "affected",
"version": "cc55dd28c20a6611e30596019b3b2f636819a4c0",
"versionType": "git"
},
{
"lessThan": "bd46f55dec608daa44b45dcf3328517630ad8e40",
"status": "affected",
"version": "c2aba69d0c36a496ab4f2e81e9c2b271f2693fd7",
"versionType": "git"
},
{
"lessThan": "337f966c00662d81ad82cf5a4bbb150b2e32c0d4",
"status": "affected",
"version": "c2aba69d0c36a496ab4f2e81e9c2b271f2693fd7",
"versionType": "git"
},
{
"lessThan": "12ce799f7ab1e05bd8fbf79e46f403bfe5597ebc",
"status": "affected",
"version": "c2aba69d0c36a496ab4f2e81e9c2b271f2693fd7",
"versionType": "git"
},
{
"status": "affected",
"version": "8f1c022541bf5a923c8d6fa483112c15250f30a4",
"versionType": "git"
},
{
"status": "affected",
"version": "c4e8a172501e677ebd8ea9d9161d97dc4df56fbd",
"versionType": "git"
},
{
"lessThan": "5.10.265",
"status": "affected",
"version": "5.10.238",
"versionType": "semver"
},
{
"lessThan": "5.15.216",
"status": "affected",
"version": "5.15.185",
"versionType": "semver"
},
{
"lessThan": "6.1.183",
"status": "affected",
"version": "6.1.141",
"versionType": "semver"
},
{
"lessThan": "6.6.148",
"status": "affected",
"version": "6.6.93",
"versionType": "semver"
},
{
"lessThan": "6.12.101",
"status": "affected",
"version": "6.12.31",
"versionType": "semver"
},
{
"lessThan": "5.5",
"status": "affected",
"version": "5.4.294",
"versionType": "semver"
},
{
"lessThan": "6.15",
"status": "affected",
"version": "6.14.9",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/can/bcm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.15"
},
{
"lessThan": "6.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.10.238",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.15.185",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "6.1.141",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.6.93",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.12.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "6.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.4.294",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.14.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: bcm: extend bcm_tx_lock usage for data and timer updates\n\nStage new CAN frame content for an existing tx op into a kmalloc()\u0027d\nbuffer and validate it there, mirroring the approach already used in\nbcm_rx_setup(). Only copy the validated data into op-\u003eframes while\nholding op-\u003ebcm_tx_lock, so bcm_can_tx() and bcm_tx_timeout_handler()\ncan no longer observe a partially updated or unvalidated frame.\n\nAdd a missing error path for memcpy_from_msg() when copying CAN frame\ndata from userspace.\n\nAlso move the kt_ival1/kt_ival2/ival1/ival2 updates in bcm_tx_setup()\nunder op-\u003ebcm_tx_lock, and read kt_ival1/kt_ival2/count under the same\nlock in bcm_tx_set_expiry() and bcm_tx_timeout_handler(), closing the\ntorn 64-bit ktime_t read on 32-bit platforms."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached only through PF_CAN/CAN_BCM socket sendmsg() TX_SETUP updates racing hrtimer-driven bcm_can_tx(); it is not triggered by remote network services or CAN bus traffic alone.\nAC:L - The attacker controls both sides of the race by creating cyclic TX ops with STARTTIMER/SETTIMER and repeatedly issuing TX_SETUP while the softirq hrtimer fires, making the window reliably winnable without external timing luck.\nPR:L - bcm_sendmsg()/bcm_connect() enforce no capability checks; any local user with access to a CAN interface (including vcan created with CAP_NET_ADMIN inside an unprivileged user namespace) can open BCM sockets and drive TX_SETUP.\nUI:N - Exploitation requires only the attacker opening a BCM socket and sending TX_SETUP messages; no victim interaction such as mounting filesystems or opening files is needed.\nS:U - Impact is confined to kernel memory/state corruption and local privilege effects on the host running CAN BCM; it does not cross a VM, container, or IOMMU security boundary by itself.\nC:H - Racing updates can let bcm_can_tx() transmit partially updated or unvalidated frames (e.g., len\u003e64) before bcm_tx_setup() rejects them, and many CAN driver xmit paths memcpy(cf-\u003edata, cf-\u003elen) trusting len, causing kernel out-of-bounds reads.\nI:H - Concurrent unsynchronized writes to op-\u003eframes, flags, count, and ktime_t timer fields corrupt shared in-kernel BCM state that directly feeds skb construction and driver transmission, providing attacker-influenced memory corruption primitives.\nA:H - Observing torn/unvalidated frames in bcm_can_tx() during active timers can trigger kernel WARN/Oops/panic via out-of-bounds accesses in CAN drivers, and torn ktime_t/count reads can disrupt cyclic transmission causing denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:36:13.917Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a538b072ee074c9b41b9d9c15a6861a963e30755"
},
{
"url": "https://git.kernel.org/stable/c/63422347b4c782f429748b2a09cd3cf3b77e6abd"
},
{
"url": "https://git.kernel.org/stable/c/37917e432e50b7de2b64230974380132a30f7270"
},
{
"url": "https://git.kernel.org/stable/c/52f06e7603780de100233713ddaf971d422e10ef"
},
{
"url": "https://git.kernel.org/stable/c/972fd66bb08fdef1090abe43196ca8da07216d13"
},
{
"url": "https://git.kernel.org/stable/c/bd46f55dec608daa44b45dcf3328517630ad8e40"
},
{
"url": "https://git.kernel.org/stable/c/337f966c00662d81ad82cf5a4bbb150b2e32c0d4"
},
{
"url": "https://git.kernel.org/stable/c/12ce799f7ab1e05bd8fbf79e46f403bfe5597ebc"
}
],
"title": "can: bcm: extend bcm_tx_lock usage for data and timer updates",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72119",
"datePublished": "2026-08-15T05:52:58.479Z",
"dateReserved": "2026-08-09T03:40:39.906Z",
"dateUpdated": "2026-08-19T16:36:13.917Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68374 (GCVE-0-2026-68374)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-18 06:55
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
usb: core: sysfs: add lock to bos_descriptors_read()
Add a lock to the function bos_descriptors_read().
This function accesses udev->bos, which could be simultaneously freed in
usb_reset_and_verify_device(), a function that is commonly called in
drivers all over the kernel.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/core/sysfs.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c07caee449c968842a350bfefa049889923b8240",
"status": "affected",
"version": "12fc84e8c4288cc8ed5f14a35e077130c2cfece2",
"versionType": "git"
},
{
"lessThan": "217774e143d7b5a88739193284b6421be3978601",
"status": "affected",
"version": "12fc84e8c4288cc8ed5f14a35e077130c2cfece2",
"versionType": "git"
},
{
"lessThan": "ab82adf5e63b2d89ead7933ab753b9cedbe028e9",
"status": "affected",
"version": "12fc84e8c4288cc8ed5f14a35e077130c2cfece2",
"versionType": "git"
},
{
"lessThan": "4e0197fbb0eec588795d5431716a244d9ac8fa93",
"status": "affected",
"version": "12fc84e8c4288cc8ed5f14a35e077130c2cfece2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/usb/core/sysfs.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.9"
},
{
"lessThan": "6.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: core: sysfs: add lock to bos_descriptors_read()\n\nAdd a lock to the function bos_descriptors_read().\n\nThis function accesses udev-\u003ebos, which could be simultaneously freed in\nusb_reset_and_verify_device(), a function that is commonly called in\ndrivers all over the kernel."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable code is reached by a local read() on the world-readable sysfs attribute /sys/bus/usb/devices/*/bos_descriptors, and the racing reset is driven locally via the usbfs USBDEVFS_RESET ioctl or driver error recovery. No network or physical access to the bug itself is required.\nAC:L - The attacker controls both sides of the race: a loop of read() calls on the sysfs file plus repeated USBDEVFS_RESET ioctls (or induced driver resets), and the reset window spanning re-enumeration is milliseconds wide, so the race can be won reliably with retries.\nPR:L - The bos_descriptors binary attribute is BIN_ATTR_RO (0444), readable by any unprivileged local user; the device-reset side is available to the seat user through usbfs uaccess/plugdev ACLs on desktops, kiosks and containers with USB device access.\nUI:N - No victim action is needed; the attacker performs both the sysfs read and the device reset entirely on its own, with no cooperation from another user or process.\nS:U - The use-after-free corrupts and discloses kernel heap memory within the same kernel security authority; no VM, IOMMU or sandbox boundary is crossed.\nC:H - The memcpy reads from an already-kfree()d BOS buffer and copies up to 65535 bytes straight to userspace, and because wTotalLength itself is read from the reclaimed object the read can extend past the original allocation, leaking arbitrary reallocated kernel heap contents.\nI:H - This is a use-after-free on a kmalloc\u0027d object whose contents the attacker can influence by heap spraying into the freed slot; such UAFs on hot kernel slabs are a standard primitive for corrupting adjacent/reallocated kernel state and hijacking control flow.\nA:H - Dereferencing the freed usb_host_bos and copying a length derived from reclaimed memory readily runs off the end of the slab into unmapped or poisoned pages, producing a KASAN report, oops or panic that takes the machine down."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-18T06:55:59.462Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c07caee449c968842a350bfefa049889923b8240"
},
{
"url": "https://git.kernel.org/stable/c/217774e143d7b5a88739193284b6421be3978601"
},
{
"url": "https://git.kernel.org/stable/c/ab82adf5e63b2d89ead7933ab753b9cedbe028e9"
},
{
"url": "https://git.kernel.org/stable/c/4e0197fbb0eec588795d5431716a244d9ac8fa93"
}
],
"title": "usb: core: sysfs: add lock to bos_descriptors_read()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68374",
"datePublished": "2026-08-10T12:03:52.701Z",
"dateReserved": "2026-07-30T09:28:09.386Z",
"dateUpdated": "2026-08-18T06:55:59.462Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68250 (GCVE-0-2026-68250)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-19 16:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON()
There's no need to crash the kernel for these cases.
(cherry picked from commit ae658afc7f47f6147371ec42cc6b1a793dfdb5af)
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 157e72e831cb8f323108b5df6d0b148aef9507fb Version: 157e72e831cb8f323108b5df6d0b148aef9507fb Version: 157e72e831cb8f323108b5df6d0b148aef9507fb Version: 157e72e831cb8f323108b5df6d0b148aef9507fb Version: 157e72e831cb8f323108b5df6d0b148aef9507fb Version: 157e72e831cb8f323108b5df6d0b148aef9507fb Version: 157e72e831cb8f323108b5df6d0b148aef9507fb Version: 157e72e831cb8f323108b5df6d0b148aef9507fb |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/sdma_v5_2.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "55995d8da162acbadfd5fb0f08675e8e1c0bdb63",
"status": "affected",
"version": "157e72e831cb8f323108b5df6d0b148aef9507fb",
"versionType": "git"
},
{
"lessThan": "f718334e4aa3768f6e68d235945eca2987c6687c",
"status": "affected",
"version": "157e72e831cb8f323108b5df6d0b148aef9507fb",
"versionType": "git"
},
{
"lessThan": "6d27435df2a4ca4945f4313344a5da5bc6b54075",
"status": "affected",
"version": "157e72e831cb8f323108b5df6d0b148aef9507fb",
"versionType": "git"
},
{
"lessThan": "01dfea84df919cfbec4064151d327480ae5c120d",
"status": "affected",
"version": "157e72e831cb8f323108b5df6d0b148aef9507fb",
"versionType": "git"
},
{
"lessThan": "b665c1845488c6cd869da3d31b5978015977f898",
"status": "affected",
"version": "157e72e831cb8f323108b5df6d0b148aef9507fb",
"versionType": "git"
},
{
"lessThan": "09da54636bac146c1a3c461c4e7eb08d355bb86e",
"status": "affected",
"version": "157e72e831cb8f323108b5df6d0b148aef9507fb",
"versionType": "git"
},
{
"lessThan": "2051bbbfbd44ff51637b01a5a3dbee6630f90d57",
"status": "affected",
"version": "157e72e831cb8f323108b5df6d0b148aef9507fb",
"versionType": "git"
},
{
"lessThan": "b9dd618a635d39fbb211454b6e8837b2a7f10fb0",
"status": "affected",
"version": "157e72e831cb8f323108b5df6d0b148aef9507fb",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/sdma_v5_2.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.9"
},
{
"lessThan": "5.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON()\n\nThere\u0027s no need to crash the kernel for these cases.\n\n(cherry picked from commit ae658afc7f47f6147371ec42cc6b1a793dfdb5af)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:32:21.015Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/55995d8da162acbadfd5fb0f08675e8e1c0bdb63"
},
{
"url": "https://git.kernel.org/stable/c/f718334e4aa3768f6e68d235945eca2987c6687c"
},
{
"url": "https://git.kernel.org/stable/c/6d27435df2a4ca4945f4313344a5da5bc6b54075"
},
{
"url": "https://git.kernel.org/stable/c/01dfea84df919cfbec4064151d327480ae5c120d"
},
{
"url": "https://git.kernel.org/stable/c/b665c1845488c6cd869da3d31b5978015977f898"
},
{
"url": "https://git.kernel.org/stable/c/09da54636bac146c1a3c461c4e7eb08d355bb86e"
},
{
"url": "https://git.kernel.org/stable/c/2051bbbfbd44ff51637b01a5a3dbee6630f90d57"
},
{
"url": "https://git.kernel.org/stable/c/b9dd618a635d39fbb211454b6e8837b2a7f10fb0"
}
],
"title": "drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68250",
"datePublished": "2026-08-10T12:01:16.435Z",
"dateReserved": "2026-07-30T09:28:09.377Z",
"dateUpdated": "2026-08-19T16:32:21.015Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72146 (GCVE-0-2026-72146)
Vulnerability from cvelistv5
Published
2026-08-15 05:53
Modified
2026-08-19 16:36
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
dmaengine: sh: rz-dmac: Move interrupt request after everything is set up
Once the interrupt is requested, the interrupt handler may run immediately.
Since the IRQ handler can access channel->ch_base, which is initialized
only after requesting the IRQ, this may lead to invalid memory access.
Likewise, the IRQ thread may access uninitialized data (the ld_free,
ld_queue, and ld_active lists), which may also lead to issues.
Request the interrupts only after everything is set up. To keep the error
path simpler, use dmam_alloc_coherent() instead of dma_alloc_coherent().
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 5000d37042a61ca556fde2782ca40dbfa802ea16 Version: 5000d37042a61ca556fde2782ca40dbfa802ea16 Version: 5000d37042a61ca556fde2782ca40dbfa802ea16 Version: 5000d37042a61ca556fde2782ca40dbfa802ea16 Version: 5000d37042a61ca556fde2782ca40dbfa802ea16 Version: 5000d37042a61ca556fde2782ca40dbfa802ea16 Version: 5000d37042a61ca556fde2782ca40dbfa802ea16 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/dma/sh/rz-dmac.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "d24d53323e817d79a4bd111bd10b34dbc96e64a8",
"status": "affected",
"version": "5000d37042a61ca556fde2782ca40dbfa802ea16",
"versionType": "git"
},
{
"lessThan": "0e0c5b3cf374ebf3c589741751e1fbc67f53ec2f",
"status": "affected",
"version": "5000d37042a61ca556fde2782ca40dbfa802ea16",
"versionType": "git"
},
{
"lessThan": "5b12de6229d662864ee22c11d4876652b40120f0",
"status": "affected",
"version": "5000d37042a61ca556fde2782ca40dbfa802ea16",
"versionType": "git"
},
{
"lessThan": "2a4d9e2234c3f817bb0ddbc8680d09ce9be84f93",
"status": "affected",
"version": "5000d37042a61ca556fde2782ca40dbfa802ea16",
"versionType": "git"
},
{
"lessThan": "ec9f66c91bffdb69d309bae6dfb387562db7ebc8",
"status": "affected",
"version": "5000d37042a61ca556fde2782ca40dbfa802ea16",
"versionType": "git"
},
{
"lessThan": "07ae600bd353b22f31a8f1007269744fafc7f123",
"status": "affected",
"version": "5000d37042a61ca556fde2782ca40dbfa802ea16",
"versionType": "git"
},
{
"lessThan": "731712403ddb39d1a76a11abf339a0615bc85de7",
"status": "affected",
"version": "5000d37042a61ca556fde2782ca40dbfa802ea16",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/dma/sh/rz-dmac.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.15"
},
{
"lessThan": "5.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: sh: rz-dmac: Move interrupt request after everything is set up\n\nOnce the interrupt is requested, the interrupt handler may run immediately.\nSince the IRQ handler can access channel-\u003ech_base, which is initialized\nonly after requesting the IRQ, this may lead to invalid memory access.\nLikewise, the IRQ thread may access uninitialized data (the ld_free,\nld_queue, and ld_active lists), which may also lead to issues.\n\nRequest the interrupts only after everything is set up. To keep the error\npath simpler, use dmam_alloc_coherent() instead of dma_alloc_coherent()."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.4,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The flaw triggers in rz_dmac_chan_probe() during Renesas RZ/G2L/V2H/T2H platform DMAC driver initialization at boot or module load; there is no network, Bluetooth, or runtime syscall path to the vulnerable devm_request_threaded_irq() ordering.\nAC:L - Once the DMAC channel IRQ line is asserted when devm_request_threaded_irq() is called after reset_deassert, the hardirq/thread handlers run immediately before ch_base or lists are initialized; stale post-reset interrupt state on these SoCs makes this timing plausible without luck.\nPR:N - rz_dmac_probe() performs no capability or authentication checks before requesting per-channel IRQs; on affected Renesas embedded boards the vulnerable probe sequence runs automatically during kernel boot without the attacker holding Linux privileges.\nUI:N - No victim action is required; pending/latched DMAC channel interrupts during driver probe at boot or reboot can invoke the buggy handlers without anyone opening device nodes or configuring DMA transfers.\nS:U - Impact is kernel NULL dereference, list/spinlock corruption, and MMIO faults within the host kernel; this is not a VM escape, container sandbox breakout, or documented IOMMU security-boundary bypass.\nC:H - The threaded IRQ handler may lock an uninitialized vc.lock and walk uninitialized ld_active/ld_queue/ld_free lists, causing invalid kernel memory reads and list-metadata exposure beyond a pure bounded fault.\nI:H - The hardirq path issues readl/writel through uninitialized ch_base (NULL/low MMIO), and list/spinlock corruption in the IRQ thread can corrupt kernel heap metadata and enable control-flow hijack primitives.\nA:H - Invalid MMIO via NULL ch_base and corrupted IRQ-thread list handling can cause kernel oops/panic during probe on affected embedded systems, causing full loss of availability until reboot."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:36:26.048Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/d24d53323e817d79a4bd111bd10b34dbc96e64a8"
},
{
"url": "https://git.kernel.org/stable/c/0e0c5b3cf374ebf3c589741751e1fbc67f53ec2f"
},
{
"url": "https://git.kernel.org/stable/c/5b12de6229d662864ee22c11d4876652b40120f0"
},
{
"url": "https://git.kernel.org/stable/c/2a4d9e2234c3f817bb0ddbc8680d09ce9be84f93"
},
{
"url": "https://git.kernel.org/stable/c/ec9f66c91bffdb69d309bae6dfb387562db7ebc8"
},
{
"url": "https://git.kernel.org/stable/c/07ae600bd353b22f31a8f1007269744fafc7f123"
},
{
"url": "https://git.kernel.org/stable/c/731712403ddb39d1a76a11abf339a0615bc85de7"
}
],
"title": "dmaengine: sh: rz-dmac: Move interrupt request after everything is set up",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72146",
"datePublished": "2026-08-15T05:53:18.431Z",
"dateReserved": "2026-08-09T03:40:39.908Z",
"dateUpdated": "2026-08-19T16:36:26.048Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68296 (GCVE-0-2026-68296)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-17 05:02
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: gre: fix lltx regression for GRE tunnels with SEQ/CSUM
Before commit 00d066a4d4ed ("netdev_features: convert NETIF_F_LLTX to
dev->lltx"), NETIF_F_LLTX was set unconditionally in both
__gre_tunnel_init() and ip6gre_tnl_init_features() alongside
GRE_FEATURES:
dev->features |= GRE_FEATURES | NETIF_F_LLTX;
When that commit converted NETIF_F_LLTX to the dev->lltx flag, it
placed 'dev->lltx = true' after the SEQ/CSUM early returns instead
of before them. This causes GRE/GRETAP/ip6gre tunnels with SEQ or
CSUM+encap to lose lockless TX, reintroducing _xmit_lock acquisition
around their ndo_start_xmit. Since GRE xmit re-enters the stack via
ip_tunnel_xmit(), holding _xmit_lock risks ABBA deadlock with the
underlay device.
CPU0 CPU1
---- ----
lock(&qdisc_xmit_lock_key#6);
lock(&qdisc_xmit_lock_key#3);
lock(&qdisc_xmit_lock_key#6);
lock(&qdisc_xmit_lock_key#3);
Fix by moving dev->lltx = true before the early returns in both
functions, restoring the original unconditional behavior.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ipv4/ip_gre.c",
"net/ipv6/ip6_gre.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "9f948e9aede9678f4103457daf2bc9dd54c65a06",
"status": "affected",
"version": "00d066a4d4edbe559ba6c35153da71d4b2b8a383",
"versionType": "git"
},
{
"lessThan": "15a1c5f2ed2eeb3daad8d5766fd506aeda4710f3",
"status": "affected",
"version": "00d066a4d4edbe559ba6c35153da71d4b2b8a383",
"versionType": "git"
},
{
"lessThan": "2bffe379023512d280337c70faeb6a8cc435db5e",
"status": "affected",
"version": "00d066a4d4edbe559ba6c35153da71d4b2b8a383",
"versionType": "git"
},
{
"lessThan": "675ed582c1aa4d919dd535490de08c015005c653",
"status": "affected",
"version": "00d066a4d4edbe559ba6c35153da71d4b2b8a383",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ipv4/ip_gre.c",
"net/ipv6/ip6_gre.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.12"
},
{
"lessThan": "6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: gre: fix lltx regression for GRE tunnels with SEQ/CSUM\n\nBefore commit 00d066a4d4ed (\"netdev_features: convert NETIF_F_LLTX to\ndev-\u003elltx\"), NETIF_F_LLTX was set unconditionally in both\n__gre_tunnel_init() and ip6gre_tnl_init_features() alongside\nGRE_FEATURES:\n\n dev-\u003efeatures |= GRE_FEATURES | NETIF_F_LLTX;\n\nWhen that commit converted NETIF_F_LLTX to the dev-\u003elltx flag, it\nplaced \u0027dev-\u003elltx = true\u0027 after the SEQ/CSUM early returns instead\nof before them. This causes GRE/GRETAP/ip6gre tunnels with SEQ or\nCSUM+encap to lose lockless TX, reintroducing _xmit_lock acquisition\naround their ndo_start_xmit. Since GRE xmit re-enters the stack via\nip_tunnel_xmit(), holding _xmit_lock risks ABBA deadlock with the\nunderlay device.\n\n CPU0 CPU1\n ---- ----\n lock(\u0026qdisc_xmit_lock_key#6);\n lock(\u0026qdisc_xmit_lock_key#3);\n lock(\u0026qdisc_xmit_lock_key#6);\n lock(\u0026qdisc_xmit_lock_key#3);\n\nFix by moving dev-\u003elltx = true before the early returns in both\nfunctions, restoring the original unconditional behavior."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:02:32.404Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/9f948e9aede9678f4103457daf2bc9dd54c65a06"
},
{
"url": "https://git.kernel.org/stable/c/15a1c5f2ed2eeb3daad8d5766fd506aeda4710f3"
},
{
"url": "https://git.kernel.org/stable/c/2bffe379023512d280337c70faeb6a8cc435db5e"
},
{
"url": "https://git.kernel.org/stable/c/675ed582c1aa4d919dd535490de08c015005c653"
}
],
"title": "net: gre: fix lltx regression for GRE tunnels with SEQ/CSUM",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68296",
"datePublished": "2026-08-10T12:02:29.464Z",
"dateReserved": "2026-07-30T09:28:09.380Z",
"dateUpdated": "2026-08-17T05:02:32.404Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68300 (GCVE-0-2026-68300)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-19 16:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
sctp: auth: verify auth requirement when auth_chunk is NULL
sctp_auth_chunk_verify() returns true unconditionally when
chunk->auth_chunk is NULL, silently skipping authentication.
This is incorrect when:
1. skb_clone() failed in the BH receive path, leaving auth_chunk
NULL. In sctp_endpoint_bh_rcv() asoc is NULL for new
connections, so the early sctp_auth_recv_cid() check cannot
catch this.
2. No AUTH chunk precedes COOKIE-ECHO, so skb_clone() is never
called and auth_chunk remains NULL.
Fix by checking sctp_auth_recv_cid() when auth_chunk is NULL:
if authentication is required, return false to drop the chunk;
otherwise continue normally.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: bbd0d59809f923ea2b540cbd781b32110e249f6e Version: bbd0d59809f923ea2b540cbd781b32110e249f6e Version: bbd0d59809f923ea2b540cbd781b32110e249f6e Version: bbd0d59809f923ea2b540cbd781b32110e249f6e Version: bbd0d59809f923ea2b540cbd781b32110e249f6e Version: bbd0d59809f923ea2b540cbd781b32110e249f6e Version: bbd0d59809f923ea2b540cbd781b32110e249f6e Version: bbd0d59809f923ea2b540cbd781b32110e249f6e |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/sctp/sm_statefuns.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a129792b3aef15002746c13522781d92ed3522c3",
"status": "affected",
"version": "bbd0d59809f923ea2b540cbd781b32110e249f6e",
"versionType": "git"
},
{
"lessThan": "5a022ac51ad83b4ce6c898f4b9eefc65bd26b247",
"status": "affected",
"version": "bbd0d59809f923ea2b540cbd781b32110e249f6e",
"versionType": "git"
},
{
"lessThan": "6caf0e8590c0bf05a76b0d387726adf3a6f3725c",
"status": "affected",
"version": "bbd0d59809f923ea2b540cbd781b32110e249f6e",
"versionType": "git"
},
{
"lessThan": "ec2e157fc9678a9bc411305a25aec3fd337d7efb",
"status": "affected",
"version": "bbd0d59809f923ea2b540cbd781b32110e249f6e",
"versionType": "git"
},
{
"lessThan": "28c5fdce9dd955d2baf5e28987819b6d7cfaf646",
"status": "affected",
"version": "bbd0d59809f923ea2b540cbd781b32110e249f6e",
"versionType": "git"
},
{
"lessThan": "18957373920caf5cdaf5cf32e5d1d7a99ca7700a",
"status": "affected",
"version": "bbd0d59809f923ea2b540cbd781b32110e249f6e",
"versionType": "git"
},
{
"lessThan": "83f5031f2a6a49d696eb4cc0898345d12f9c6451",
"status": "affected",
"version": "bbd0d59809f923ea2b540cbd781b32110e249f6e",
"versionType": "git"
},
{
"lessThan": "8e04823c120b376ef7dab14b60ebf6823aa16c14",
"status": "affected",
"version": "bbd0d59809f923ea2b540cbd781b32110e249f6e",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/sctp/sm_statefuns.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.24"
},
{
"lessThan": "2.6.24",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.24",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: auth: verify auth requirement when auth_chunk is NULL\n\nsctp_auth_chunk_verify() returns true unconditionally when\nchunk-\u003eauth_chunk is NULL, silently skipping authentication.\nThis is incorrect when:\n\n1. skb_clone() failed in the BH receive path, leaving auth_chunk\n NULL. In sctp_endpoint_bh_rcv() asoc is NULL for new\n connections, so the early sctp_auth_recv_cid() check cannot\n catch this.\n\n2. No AUTH chunk precedes COOKIE-ECHO, so skb_clone() is never\n called and auth_chunk remains NULL.\n\nFix by checking sctp_auth_recv_cid() when auth_chunk is NULL:\nif authentication is required, return false to drop the chunk;\notherwise continue normally."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The vulnerable code is SCTP COOKIE-ECHO chunk processing in the kernel\u0027s SCTP state machine, reached directly from packets received on the network from any remote peer over an arbitrarily routed SCTP connection.\nAC:L - The attacker deterministically triggers the bypass by completing a normal INIT/INIT-ACK exchange with the AUTH extension advertised and then sending COOKIE-ECHO with no preceding AUTH chunk; no race, no memory-layout dependency, and every step is under the attacker\u0027s control.\nPR:N - This is the pre-authentication association-establishment path itself; the attacker needs no credentials, no shared SCTP-AUTH key, and no account, since the bug is precisely that the required authentication is skipped.\nUI:N - The listening SCTP endpoint processes the crafted COOKIE-ECHO automatically in the receive path; no action by any local user or administrator is needed.\nS:U - The bypass affects the SCTP association and the application relying on it within the same host security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - An unauthenticated peer is admitted as an apparently authenticated one, and because peer.auth_capable is set the SCTP_AUTH_NO_AUTH notification is suppressed so the application cannot detect it, giving the attacker full read access to all data the service sends on that association.\nI:H - The attacker can inject arbitrary SCTP data and control chunks into the service as a trusted, supposedly key-verified peer, and can use the dupcook restart path to update or replace an existing association\u0027s state without authentication.\nA:H - Authenticating COOKIE-ECHO is the RFC 4895 defense against unauthorized association restart; bypassing it lets an attacker reset/take over an established association, dropping its queued state and denying service to the legitimate peer, and lets unauthorized peers consume association and accept-queue resources on an endpoint meant to admit only key-holding peers."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:32:51.209Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a129792b3aef15002746c13522781d92ed3522c3"
},
{
"url": "https://git.kernel.org/stable/c/5a022ac51ad83b4ce6c898f4b9eefc65bd26b247"
},
{
"url": "https://git.kernel.org/stable/c/6caf0e8590c0bf05a76b0d387726adf3a6f3725c"
},
{
"url": "https://git.kernel.org/stable/c/ec2e157fc9678a9bc411305a25aec3fd337d7efb"
},
{
"url": "https://git.kernel.org/stable/c/28c5fdce9dd955d2baf5e28987819b6d7cfaf646"
},
{
"url": "https://git.kernel.org/stable/c/18957373920caf5cdaf5cf32e5d1d7a99ca7700a"
},
{
"url": "https://git.kernel.org/stable/c/83f5031f2a6a49d696eb4cc0898345d12f9c6451"
},
{
"url": "https://git.kernel.org/stable/c/8e04823c120b376ef7dab14b60ebf6823aa16c14"
}
],
"title": "sctp: auth: verify auth requirement when auth_chunk is NULL",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68300",
"datePublished": "2026-08-10T12:02:34.168Z",
"dateReserved": "2026-07-30T09:28:09.380Z",
"dateUpdated": "2026-08-19T16:32:51.209Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68139 (GCVE-0-2026-68139)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-17 04:59
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/mlx5e: Use sender devcom for MPV master-up
After PCIe DPC recovery, mlx5 reloads the affected functions and
replays multiport affiliation events. In the reported failure, the
first relevant device error was:
pcieport 0000:10:01.1: DPC: containment event
pcieport 0000:10:01.1: PCIe Bus Error: severity=Uncorrected (Fatal)
pcieport 0000:10:01.1: [ 5] SDES (First)
mlx5 recovered the PCI functions and resumed 0000:11:00.1. During
that resume, RDMA multiport binding replayed
MLX5_DRIVER_EVENT_AFFILIATION_DONE and mlx5e sent
MPV_DEVCOM_MASTER_UP. The host then panicked with:
BUG: kernel NULL pointer dereference, address: 0000000000000010
RIP: mlx5_devcom_comp_set_ready+0x5/0x40 [mlx5_core]
RDI: 0000000000000000
Call trace included:
mlx5_devcom_comp_set_ready
mlx5e_devcom_event_mpv
mlx5_devcom_send_event
mlx5_ib_bind_slave_port
mlx5r_mp_probe
mlx5_pci_resume
MPV devcom registration publishes mlx5e private data to the component
peer list before mlx5e_devcom_init_mpv() stores the returned component
device in priv->devcom. A concurrent master-up event can therefore
reach a peer whose private data is visible but whose priv->devcom
backpointer is still NULL.
MPV_DEVCOM_MASTER_UP already carries the sender/master mlx5e private
data as event_data. The ready bit is stored on the shared devcom
component, not on an individual peer. Use the sender devcom when
marking the MPV component ready.
This preserves the readiness transition while avoiding a NULL
dereference of the peer devcom pointer during affiliation replay after
PCI error recovery.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/mellanox/mlx5/core/en_main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c698b2735613f1f35c55688bd2252f75f31c49ad",
"status": "affected",
"version": "bf11485f8419f90ffaa3804fd01d8468fcc56e23",
"versionType": "git"
},
{
"lessThan": "40f9a124ebbe0d60fe165fb3f87515c35b2d72f5",
"status": "affected",
"version": "bf11485f8419f90ffaa3804fd01d8468fcc56e23",
"versionType": "git"
},
{
"lessThan": "a60c81f168c9fe4f5d84302d1e32b717f5a8a933",
"status": "affected",
"version": "bf11485f8419f90ffaa3804fd01d8468fcc56e23",
"versionType": "git"
},
{
"lessThan": "e32649b4bad90a6216d8e93cd7dd050af8ac9740",
"status": "affected",
"version": "bf11485f8419f90ffaa3804fd01d8468fcc56e23",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/mellanox/mlx5/core/en_main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.7"
},
{
"lessThan": "6.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: Use sender devcom for MPV master-up\n\nAfter PCIe DPC recovery, mlx5 reloads the affected functions and\nreplays multiport affiliation events. In the reported failure, the\nfirst relevant device error was:\n\n pcieport 0000:10:01.1: DPC: containment event\n pcieport 0000:10:01.1: PCIe Bus Error: severity=Uncorrected (Fatal)\n pcieport 0000:10:01.1: [ 5] SDES (First)\n\nmlx5 recovered the PCI functions and resumed 0000:11:00.1. During\nthat resume, RDMA multiport binding replayed\nMLX5_DRIVER_EVENT_AFFILIATION_DONE and mlx5e sent\nMPV_DEVCOM_MASTER_UP. The host then panicked with:\n\n BUG: kernel NULL pointer dereference, address: 0000000000000010\n RIP: mlx5_devcom_comp_set_ready+0x5/0x40 [mlx5_core]\n RDI: 0000000000000000\n\nCall trace included:\n\n mlx5_devcom_comp_set_ready\n mlx5e_devcom_event_mpv\n mlx5_devcom_send_event\n mlx5_ib_bind_slave_port\n mlx5r_mp_probe\n mlx5_pci_resume\n\nMPV devcom registration publishes mlx5e private data to the component\npeer list before mlx5e_devcom_init_mpv() stores the returned component\ndevice in priv-\u003edevcom. A concurrent master-up event can therefore\nreach a peer whose private data is visible but whose priv-\u003edevcom\nbackpointer is still NULL.\n\nMPV_DEVCOM_MASTER_UP already carries the sender/master mlx5e private\ndata as event_data. The ready bit is stored on the shared devcom\ncomponent, not on an individual peer. Use the sender devcom when\nmarking the MPV component ready.\n\nThis preserves the readiness transition while avoiding a NULL\ndereference of the peer devcom pointer during affiliation replay after\nPCI error recovery."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:59:32.634Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c698b2735613f1f35c55688bd2252f75f31c49ad"
},
{
"url": "https://git.kernel.org/stable/c/40f9a124ebbe0d60fe165fb3f87515c35b2d72f5"
},
{
"url": "https://git.kernel.org/stable/c/a60c81f168c9fe4f5d84302d1e32b717f5a8a933"
},
{
"url": "https://git.kernel.org/stable/c/e32649b4bad90a6216d8e93cd7dd050af8ac9740"
}
],
"title": "net/mlx5e: Use sender devcom for MPV master-up",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68139",
"datePublished": "2026-08-10T11:59:02.768Z",
"dateReserved": "2026-07-30T09:28:09.370Z",
"dateUpdated": "2026-08-17T04:59:32.634Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68327 (GCVE-0-2026-68327)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wan: wanxl: Only reset hardware after BAR mapping
wanxl_pci_init_one() stores the freshly allocated card in driver data
before the PLX BAR is mapped. Several early probe failures then unwind
through wanxl_pci_remove_one(), including failure to allocate the coherent
status area or to restore the DMA mask.
wanxl_pci_remove_one() unconditionally calls wanxl_reset(), and
wanxl_reset() dereferences card->plx. On those early failures card->plx
is still NULL, so the error path can dereference a NULL MMIO pointer.
Only issue the hardware reset once the BAR mapping exists. The remaining
cleanup in wanxl_pci_remove_one() already checks whether later resources
were allocated.
This issue was found by a static analysis checker and confirmed by
manual source review.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wan/wanxl.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ef394eeb9d5ec6db8d979eec6d27f56c2ebc6523",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "3d9617d856ebddcdddbab0ce877c397420f59f55",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "897e289db1e4d00ca6419cfe733c646492147270",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "f4834132773f15ffb255127499c8443947fa7d0f",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "b9e2ff70e96acf83693b27987e0390bad9f83efa",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "59cbe6cfa0fa23c192351cc284e30707309f6741",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "2fe22d58b3797d741570f9873b26653fd511576c",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "91957b89da995607cb654b1f9a3c126ddbaee10f",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wan/wanxl.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwan: wanxl: Only reset hardware after BAR mapping\n\nwanxl_pci_init_one() stores the freshly allocated card in driver data\nbefore the PLX BAR is mapped. Several early probe failures then unwind\nthrough wanxl_pci_remove_one(), including failure to allocate the coherent\nstatus area or to restore the DMA mask.\n\nwanxl_pci_remove_one() unconditionally calls wanxl_reset(), and\nwanxl_reset() dereferences card-\u003eplx. On those early failures card-\u003eplx\nis still NULL, so the error path can dereference a NULL MMIO pointer.\n\nOnly issue the hardware reset once the BAR mapping exists. The remaining\ncleanup in wanxl_pci_remove_one() already checks whether later resources\nwere allocated.\n\nThis issue was found by a static analysis checker and confirmed by\nmanual source review."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:23.256Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ef394eeb9d5ec6db8d979eec6d27f56c2ebc6523"
},
{
"url": "https://git.kernel.org/stable/c/3d9617d856ebddcdddbab0ce877c397420f59f55"
},
{
"url": "https://git.kernel.org/stable/c/897e289db1e4d00ca6419cfe733c646492147270"
},
{
"url": "https://git.kernel.org/stable/c/f4834132773f15ffb255127499c8443947fa7d0f"
},
{
"url": "https://git.kernel.org/stable/c/b9e2ff70e96acf83693b27987e0390bad9f83efa"
},
{
"url": "https://git.kernel.org/stable/c/59cbe6cfa0fa23c192351cc284e30707309f6741"
},
{
"url": "https://git.kernel.org/stable/c/2fe22d58b3797d741570f9873b26653fd511576c"
},
{
"url": "https://git.kernel.org/stable/c/91957b89da995607cb654b1f9a3c126ddbaee10f"
}
],
"title": "wan: wanxl: Only reset hardware after BAR mapping",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68327",
"datePublished": "2026-08-10T12:03:03.398Z",
"dateReserved": "2026-07-30T09:28:09.382Z",
"dateUpdated": "2026-08-19T16:33:23.256Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68311 (GCVE-0-2026-68311)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-17 05:03
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: mt76: mt7925: guard link STA in decap offload
mt7925_sta_set_decap_offload() iterates over the vif valid_links mask
when updating decap offload state for an MLO station. The station may not
have a link STA for every valid link of the vif, so mt792x_sta_to_link()
can return NULL for a link that belongs to the vif but not to the station.
The function currently dereferences mlink before checking whether the
link WCID is ready. If mlink is NULL, setting or clearing
MT_WCID_FLAG_HDR_TRANS dereferences a NULL pointer.
Skip links without a station link before touching mlink->wcid.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/mediatek/mt76/mt7925/main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "1e608cae1ba0b4a600b752efa223fd2be376b143",
"status": "affected",
"version": "b859ad65309a5f1654e8b284de582831fc88e2d8",
"versionType": "git"
},
{
"lessThan": "f1ee53e08fdd2906e90c6a6d71e1368fcd52bfc3",
"status": "affected",
"version": "b859ad65309a5f1654e8b284de582831fc88e2d8",
"versionType": "git"
},
{
"lessThan": "d86883f7e8f03a5b81b4e59f2c0b6c05f79e01fd",
"status": "affected",
"version": "b859ad65309a5f1654e8b284de582831fc88e2d8",
"versionType": "git"
},
{
"lessThan": "96ea44f2269f30364cffa054ee3a87e595bef0d4",
"status": "affected",
"version": "b859ad65309a5f1654e8b284de582831fc88e2d8",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/mediatek/mt76/mt7925/main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.11"
},
{
"lessThan": "6.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7925: guard link STA in decap offload\n\nmt7925_sta_set_decap_offload() iterates over the vif valid_links mask\nwhen updating decap offload state for an MLO station. The station may not\nhave a link STA for every valid link of the vif, so mt792x_sta_to_link()\ncan return NULL for a link that belongs to the vif but not to the station.\n\nThe function currently dereferences mlink before checking whether the\nlink WCID is ready. If mlink is NULL, setting or clearing\nMT_WCID_FLAG_HDR_TRANS dereferences a NULL pointer.\n\nSkip links without a station link before touching mlink-\u003ewcid."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:03:07.684Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/1e608cae1ba0b4a600b752efa223fd2be376b143"
},
{
"url": "https://git.kernel.org/stable/c/f1ee53e08fdd2906e90c6a6d71e1368fcd52bfc3"
},
{
"url": "https://git.kernel.org/stable/c/d86883f7e8f03a5b81b4e59f2c0b6c05f79e01fd"
},
{
"url": "https://git.kernel.org/stable/c/96ea44f2269f30364cffa054ee3a87e595bef0d4"
}
],
"title": "wifi: mt76: mt7925: guard link STA in decap offload",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68311",
"datePublished": "2026-08-10T12:02:45.919Z",
"dateReserved": "2026-07-30T09:28:09.381Z",
"dateUpdated": "2026-08-17T05:03:07.684Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68187 (GCVE-0-2026-68187)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
exec: fix unsigned loop counter wrap in transfer_args_to_stack()
The stop value is derived from bprm->p >> PAGE_SHIFT. The index variable
is an unsigned long. If bprm->p drops below PAGE_SIZE and stop becomes
zero the loop condition index >= stop is always true.
After the index == 0 iteration the decrement wraps to ULONG_MAX and
bprm->page[ULONG_MAX] reads sizeof(void *) bytes in front of the array.
The pointer has wrapped to -1. That garbage pointer is then passed to
kmap_local_page() and PAGE_SIZE bytes are copied from wherever that
lands into the stack of the process being created. And the loop doesn't
terminate either...
Getting there only requires bprm->p < PAGE_SIZE. On !MMU
bprm_set_stack_limit() and bprm_hit_stack_limit() are empty. So the only
constraint on how far bprm->p is pushed down is valid_arg_len(), i.e.
that each individual string still fits in what is left.
bprm->p starts at PAGE_SIZE * MAX_ARG_PAGES - sizeof(void *) so a
single argument or environment string of a little over 31 pages leaves
it in the first page:
Oops - load access fault [#1]
CPU: 0 UID: 0 PID: 1 Comm: victim Not tainted 7.2.0-rc4 #1
epc : __memcpy+0xd4/0xf8
ra : transfer_args_to_stack+0xaa/0xae
s4 : ffffffffffffffff s2 : 0000000000000000
a1 : ffffffdc98000000 a2 : 0000000000001000
status: 0000000a00001880 badaddr: ffffffdc98000000 cause: 0000000000000005
[<801a5324>] __memcpy+0xd4/0xf8
[<800d5f6a>] load_flat_binary+0x43a/0x65e
[<800a2de4>] bprm_execve+0x1d4/0x316
[<800a351a>] do_execveat_common+0x12e/0x138
[<800a3d44>] __riscv_sys_execve+0x38/0x4e
Kernel panic - not syncing: Fatal exception in interrupt
This is an arcane bug but we should still fix it.
Count down from MAX_ARG_PAGES so the loop ends when index reaches stop,
stop == 0 included. The iterations performed are unchanged for every
other value of stop.
Only CONFIG_MMU=n builds are affected, transfer_args_to_stack() is used
by binfmt_flat and binfmt_elf_fdpic on nommu only.
The loop predates git history. commit 7e7ec6a93434
("elf_fdpic_transfer_args_to_stack(): make it generic") only moved it
from binfmt_elf_fdpic.c into fs/exec.c and narrowed the copy to the used
part of the first page. The condition and the decrement are unchanged
from 2.6.12-rc2.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/exec.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a9eb5c4949008034909bc34ecfa0843ecc1d0ab3",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "67cf5cdad823afb0530d6d0341fbf4ca07e93a09",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "66e20942890a383eb39b2009a2ceb4c2ebec37ef",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "c62bb00caba66e01fb578d5f0302f247dc64930a",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "dfc2a00742af4cb7251c1a8fbce4fbae3cc0de4e",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "2bc6bf70d41055377f390d06f0f3521deb62fd3b",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "55fa2c7f2b15583d1a2fe1b5abcc24377359339f",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "16cc4f5c1c4b9e45eca7f7deefa5410a292db599",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/exec.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nexec: fix unsigned loop counter wrap in transfer_args_to_stack()\n\nThe stop value is derived from bprm-\u003ep \u003e\u003e PAGE_SHIFT. The index variable\nis an unsigned long. If bprm-\u003ep drops below PAGE_SIZE and stop becomes\nzero the loop condition index \u003e= stop is always true.\n\nAfter the index == 0 iteration the decrement wraps to ULONG_MAX and\nbprm-\u003epage[ULONG_MAX] reads sizeof(void *) bytes in front of the array.\nThe pointer has wrapped to -1. That garbage pointer is then passed to\nkmap_local_page() and PAGE_SIZE bytes are copied from wherever that\nlands into the stack of the process being created. And the loop doesn\u0027t\nterminate either...\n\nGetting there only requires bprm-\u003ep \u003c PAGE_SIZE. On !MMU\nbprm_set_stack_limit() and bprm_hit_stack_limit() are empty. So the only\nconstraint on how far bprm-\u003ep is pushed down is valid_arg_len(), i.e.\nthat each individual string still fits in what is left.\n\nbprm-\u003ep starts at PAGE_SIZE * MAX_ARG_PAGES - sizeof(void *) so a\nsingle argument or environment string of a little over 31 pages leaves\nit in the first page:\n\n Oops - load access fault [#1]\n CPU: 0 UID: 0 PID: 1 Comm: victim Not tainted 7.2.0-rc4 #1\n epc : __memcpy+0xd4/0xf8\n ra : transfer_args_to_stack+0xaa/0xae\n s4 : ffffffffffffffff s2 : 0000000000000000\n a1 : ffffffdc98000000 a2 : 0000000000001000\n status: 0000000a00001880 badaddr: ffffffdc98000000 cause: 0000000000000005\n [\u003c801a5324\u003e] __memcpy+0xd4/0xf8\n [\u003c800d5f6a\u003e] load_flat_binary+0x43a/0x65e\n [\u003c800a2de4\u003e] bprm_execve+0x1d4/0x316\n [\u003c800a351a\u003e] do_execveat_common+0x12e/0x138\n [\u003c800a3d44\u003e] __riscv_sys_execve+0x38/0x4e\n Kernel panic - not syncing: Fatal exception in interrupt\n\nThis is an arcane bug but we should still fix it.\n\nCount down from MAX_ARG_PAGES so the loop ends when index reaches stop,\nstop == 0 included. The iterations performed are unchanged for every\nother value of stop.\n\nOnly CONFIG_MMU=n builds are affected, transfer_args_to_stack() is used\nby binfmt_flat and binfmt_elf_fdpic on nommu only.\n\nThe loop predates git history. commit 7e7ec6a93434\n(\"elf_fdpic_transfer_args_to_stack(): make it generic\") only moved it\nfrom binfmt_elf_fdpic.c into fs/exec.c and narrowed the copy to the used\npart of the first page. The condition and the decrement are unchanged\nfrom 2.6.12-rc2."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:30:56.724Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a9eb5c4949008034909bc34ecfa0843ecc1d0ab3"
},
{
"url": "https://git.kernel.org/stable/c/67cf5cdad823afb0530d6d0341fbf4ca07e93a09"
},
{
"url": "https://git.kernel.org/stable/c/66e20942890a383eb39b2009a2ceb4c2ebec37ef"
},
{
"url": "https://git.kernel.org/stable/c/c62bb00caba66e01fb578d5f0302f247dc64930a"
},
{
"url": "https://git.kernel.org/stable/c/dfc2a00742af4cb7251c1a8fbce4fbae3cc0de4e"
},
{
"url": "https://git.kernel.org/stable/c/2bc6bf70d41055377f390d06f0f3521deb62fd3b"
},
{
"url": "https://git.kernel.org/stable/c/55fa2c7f2b15583d1a2fe1b5abcc24377359339f"
},
{
"url": "https://git.kernel.org/stable/c/16cc4f5c1c4b9e45eca7f7deefa5410a292db599"
}
],
"title": "exec: fix unsigned loop counter wrap in transfer_args_to_stack()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68187",
"datePublished": "2026-08-10T11:59:59.303Z",
"dateReserved": "2026-07-30T09:28:09.373Z",
"dateUpdated": "2026-08-19T16:30:56.724Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68325 (GCVE-0-2026-68325)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
iommu/amd: Bound the early ACPI HID map
The ivrs_acpihid command-line parser appends entries to a fixed
four-element early_acpihid_map array. Unlike the sibling IOAPIC and HPET
parsers, it does not reject a fifth entry before incrementing the map size.
Check the capacity at the common found label before parsing the HID and
UID or writing the entry.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ca3bf5d47cec8b7614bcb2e9132c40081d6d81db Version: ca3bf5d47cec8b7614bcb2e9132c40081d6d81db Version: ca3bf5d47cec8b7614bcb2e9132c40081d6d81db Version: ca3bf5d47cec8b7614bcb2e9132c40081d6d81db Version: ca3bf5d47cec8b7614bcb2e9132c40081d6d81db Version: ca3bf5d47cec8b7614bcb2e9132c40081d6d81db Version: ca3bf5d47cec8b7614bcb2e9132c40081d6d81db Version: ca3bf5d47cec8b7614bcb2e9132c40081d6d81db |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/iommu/amd/init.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "9ae6b1b972ce01d3316c8a5f7f58c8b3668cc6bb",
"status": "affected",
"version": "ca3bf5d47cec8b7614bcb2e9132c40081d6d81db",
"versionType": "git"
},
{
"lessThan": "e5e0098f8cd82f8b3c8687a8f686309565d51745",
"status": "affected",
"version": "ca3bf5d47cec8b7614bcb2e9132c40081d6d81db",
"versionType": "git"
},
{
"lessThan": "afe7ea0520c49586703f210865ace2d70b017e48",
"status": "affected",
"version": "ca3bf5d47cec8b7614bcb2e9132c40081d6d81db",
"versionType": "git"
},
{
"lessThan": "1e31d2394e0db69541b1591d46c5ad6431c81db3",
"status": "affected",
"version": "ca3bf5d47cec8b7614bcb2e9132c40081d6d81db",
"versionType": "git"
},
{
"lessThan": "abe5d7962f09adada9c4fb25b816dddd3f97c55d",
"status": "affected",
"version": "ca3bf5d47cec8b7614bcb2e9132c40081d6d81db",
"versionType": "git"
},
{
"lessThan": "e5ebe8544df1a1c3611739a8622156094fe470df",
"status": "affected",
"version": "ca3bf5d47cec8b7614bcb2e9132c40081d6d81db",
"versionType": "git"
},
{
"lessThan": "030a8e84f8f1b6e96f469c84a13a225c3699910b",
"status": "affected",
"version": "ca3bf5d47cec8b7614bcb2e9132c40081d6d81db",
"versionType": "git"
},
{
"lessThan": "fb80117fddb5b477218dc99bb53911b72c3847f8",
"status": "affected",
"version": "ca3bf5d47cec8b7614bcb2e9132c40081d6d81db",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/iommu/amd/init.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.7"
},
{
"lessThan": "4.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\niommu/amd: Bound the early ACPI HID map\n\nThe ivrs_acpihid command-line parser appends entries to a fixed\nfour-element early_acpihid_map array. Unlike the sibling IOAPIC and HPET\nparsers, it does not reject a fifth entry before incrementing the map size.\n\nCheck the capacity at the common found label before parsing the HID and\nUID or writing the entry."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:18.080Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/9ae6b1b972ce01d3316c8a5f7f58c8b3668cc6bb"
},
{
"url": "https://git.kernel.org/stable/c/e5e0098f8cd82f8b3c8687a8f686309565d51745"
},
{
"url": "https://git.kernel.org/stable/c/afe7ea0520c49586703f210865ace2d70b017e48"
},
{
"url": "https://git.kernel.org/stable/c/1e31d2394e0db69541b1591d46c5ad6431c81db3"
},
{
"url": "https://git.kernel.org/stable/c/abe5d7962f09adada9c4fb25b816dddd3f97c55d"
},
{
"url": "https://git.kernel.org/stable/c/e5ebe8544df1a1c3611739a8622156094fe470df"
},
{
"url": "https://git.kernel.org/stable/c/030a8e84f8f1b6e96f469c84a13a225c3699910b"
},
{
"url": "https://git.kernel.org/stable/c/fb80117fddb5b477218dc99bb53911b72c3847f8"
}
],
"title": "iommu/amd: Bound the early ACPI HID map",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68325",
"datePublished": "2026-08-10T12:03:01.384Z",
"dateReserved": "2026-07-30T09:28:09.382Z",
"dateUpdated": "2026-08-19T16:33:18.080Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68200 (GCVE-0-2026-68200)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-17 05:00
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ALSA: timer: don't re-enter an instance callback that is still running
The userspace-driven timer (utimer) TRIGGER ioctl calls
snd_timer_interrupt() directly with no serialization, so two threads
triggering the same utimer can run snd_timer_interrupt() on one
snd_timer concurrently.
snd_timer_process_callbacks() drops timer->lock around each instance
callback and marks the in-flight callback with the single
SNDRV_TIMER_IFLG_CALLBACK bit; snd_timer_close_locked() waits on that
bit to drain an in-flight callback before freeing the instance. The bit
cannot represent two concurrent callbacks: when a second interrupt
re-queues an instance whose callback is still running, both run at once,
the first to finish clears the bit, and the close-path drain then frees
the instance (and its callback_data) while the other callback is still
live - a use-after-free reachable by any user able to open
/dev/snd/timer, both via a user timer instance and via a sequencer queue
timer bound to the utimer.
snd_timer_interrupt() sets IFLG_CALLBACK before dropping timer->lock, so
a concurrent interrupt already observes it under the lock. Skip
re-queuing an instance (and its slaves) to the ack/sack list while its
callback is in flight; the accumulated pticks are delivered on the next
tick, so no event is lost.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"sound/core/timer.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "996c24377eea4d4506b7c3ccbbf1e490440b5e0b",
"status": "affected",
"version": "37745918e0e7575bc40f38da93a99b9fa6406224",
"versionType": "git"
},
{
"lessThan": "1395327a96614885552bae5fbb650e6dd182d49b",
"status": "affected",
"version": "37745918e0e7575bc40f38da93a99b9fa6406224",
"versionType": "git"
},
{
"lessThan": "c1078130a4cd7e738f4b73afe99b3e68cbfbf884",
"status": "affected",
"version": "37745918e0e7575bc40f38da93a99b9fa6406224",
"versionType": "git"
},
{
"lessThan": "70d28bfcd6224eed75986b3b987b997e59643fa4",
"status": "affected",
"version": "37745918e0e7575bc40f38da93a99b9fa6406224",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"sound/core/timer.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.12"
},
{
"lessThan": "6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: timer: don\u0027t re-enter an instance callback that is still running\n\nThe userspace-driven timer (utimer) TRIGGER ioctl calls\nsnd_timer_interrupt() directly with no serialization, so two threads\ntriggering the same utimer can run snd_timer_interrupt() on one\nsnd_timer concurrently.\n\nsnd_timer_process_callbacks() drops timer-\u003elock around each instance\ncallback and marks the in-flight callback with the single\nSNDRV_TIMER_IFLG_CALLBACK bit; snd_timer_close_locked() waits on that\nbit to drain an in-flight callback before freeing the instance. The bit\ncannot represent two concurrent callbacks: when a second interrupt\nre-queues an instance whose callback is still running, both run at once,\nthe first to finish clears the bit, and the close-path drain then frees\nthe instance (and its callback_data) while the other callback is still\nlive - a use-after-free reachable by any user able to open\n/dev/snd/timer, both via a user timer instance and via a sequencer queue\ntimer bound to the utimer.\n\nsnd_timer_interrupt() sets IFLG_CALLBACK before dropping timer-\u003elock, so\na concurrent interrupt already observes it under the lock. Skip\nre-queuing an instance (and its slaves) to the ack/sack list while its\ncallback is in flight; the accumulated pticks are delivered on the next\ntick, so no event is lost."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached purely through local syscalls: opening /dev/snd/timer, the SNDRV_TIMER_IOCTL_CREATE ioctl to obtain a utimer fd, and concurrent SNDRV_TIMER_IOCTL_TRIGGER ioctls on that fd. No network or physical access is involved.\nAC:L - The attacker owns every side of the race: two of its own threads issue the TRIGGER ioctls that run snd_timer_interrupt() concurrently, while a third closes the timer instance, and the ioctl can be spammed in a tight loop until the window is hit. Nothing depends on conditions outside attacker control.\nPR:L - Only the ability to open /dev/snd/timer is needed, which any member of the audio group, any logged-in desktop session (granted via logind ACLs), or any Android media/app process has. No capabilities, no root, and the commit explicitly states it is reachable by \"any user able to open /dev/snd/timer\".\nUI:N - The attacking process creates the utimer, triggers it from its own threads, and closes the instance entirely on its own. No victim action, no filesystem mount, and no privileged helper participation is required.\nS:U - The use-after-free corrupts kernel slab memory in the same security authority as the attacked kernel; there is no VM, IOMMU, or sandbox boundary crossed by the freed snd_timer_instance or its callback_data.\nC:H - The freed snd_timer_instance and its callback_data (snd_timer_user with its event ring buffer, or snd_seq_queue) are re-read by the still-running callback after being reallocated, so an attacker who heap-sprays the slot can turn the dangling read/queue-append into disclosure of arbitrary reallocated kernel memory back through the timer read() interface.\nI:H - The live callback (snd_timer_user_tinterrupt/ccallback or the sequencer queue tick handler) keeps writing into the freed object - event queue indices, pointers, and spinlock state - giving a controlled write into attacker-groomed slab contents, a classic UAF primitive leveragable for control-flow hijack and privilege escalation.\nA:H - Even without successful grooming, the concurrent callback touches freed memory and manipulates list heads of a destroyed instance, producing list corruption, KASAN splats, and kernel oops or panic; the ioctl can be re-run repeatedly to crash the machine at will."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:00:43.695Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/996c24377eea4d4506b7c3ccbbf1e490440b5e0b"
},
{
"url": "https://git.kernel.org/stable/c/1395327a96614885552bae5fbb650e6dd182d49b"
},
{
"url": "https://git.kernel.org/stable/c/c1078130a4cd7e738f4b73afe99b3e68cbfbf884"
},
{
"url": "https://git.kernel.org/stable/c/70d28bfcd6224eed75986b3b987b997e59643fa4"
}
],
"title": "ALSA: timer: don\u0027t re-enter an instance callback that is still running",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68200",
"datePublished": "2026-08-10T12:00:19.253Z",
"dateReserved": "2026-07-30T09:28:09.374Z",
"dateUpdated": "2026-08-17T05:00:43.695Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68427 (GCVE-0-2026-68427)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-19 16:35
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings
__host1x_bo_unpin() drops the last reference to the mapping and frees
it, so we can't dereference mapping afterwards. The cache itself
outlives the mapping, so use the cache local variable instead.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: af755456299d44e4ed6af3b7c70a7f03ea37fdf1 Version: 71c017b3f83ff72638f2a1b1d6d4e7bc61d30231 Version: 0e9dd7cfb9986b78cc81eca126ccfbf57f4c0602 Version: 8c0d3cf0d5108c96317e0eca92b60dd368867cef Version: df63c76f9c8d881ca7bce1aecfba512328d0527d Version: 3cbf5e3c46e66d9b3b6b91099bb720c6cb1be3bc |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/host1x/bus.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "86a9bd8c8f422d5f3079da31e151868902fcc702",
"status": "affected",
"version": "af755456299d44e4ed6af3b7c70a7f03ea37fdf1",
"versionType": "git"
},
{
"lessThan": "abeff53233b984571b87582bb588b4b38ef4ea50",
"status": "affected",
"version": "71c017b3f83ff72638f2a1b1d6d4e7bc61d30231",
"versionType": "git"
},
{
"lessThan": "5b7e5f84d3d4cea10c3764d2da274810a7934228",
"status": "affected",
"version": "0e9dd7cfb9986b78cc81eca126ccfbf57f4c0602",
"versionType": "git"
},
{
"lessThan": "5f4de3c717d34a24d555af581947742980778c02",
"status": "affected",
"version": "8c0d3cf0d5108c96317e0eca92b60dd368867cef",
"versionType": "git"
},
{
"lessThan": "b773faa32b0a98c3eb2b50d96de631681e5d1157",
"status": "affected",
"version": "df63c76f9c8d881ca7bce1aecfba512328d0527d",
"versionType": "git"
},
{
"lessThan": "266cddf7bd0f6c79b6c0633aef742a22bf70265b",
"status": "affected",
"version": "3cbf5e3c46e66d9b3b6b91099bb720c6cb1be3bc",
"versionType": "git"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/host1x/bus.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "6.1.183",
"status": "affected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThan": "6.6.148",
"status": "affected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThan": "6.12.101",
"status": "affected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThan": "6.18.42",
"status": "affected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThan": "7.1.6",
"status": "affected",
"version": "7.1.5",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "6.1.178",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.6.145",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.12.97",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.18.40",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "7.1.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ngpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings\n\n__host1x_bo_unpin() drops the last reference to the mapping and frees\nit, so we can\u0027t dereference mapping afterwards. The cache itself\noutlives the mapping, so use the cache local variable instead."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable path is reached only through the Tegra DRM/KMS device node (/dev/dri/card0): a local process pins a GEM buffer as a scanout framebuffer via an atomic commit and then destroys the handle, invoking tegra_bo_free_object() -\u003e host1x_bo_clear_cached_mappings(). No network or remote input reaches this code.\nAC:L - The use-after-free is unconditional and deterministic \u2014 every cached mapping freed by host1x_bo_clear_cached_mappings() is dereferenced again for the mutex_unlock. No race must be won and no special memory layout is needed; the attacker fully controls buffer creation, scanout pinning, and the destroy that triggers the free.\nPR:L - An unprivileged local user with access to the Tegra DRM device (video/graphics group, the logged-in console/compositor user on Android, automotive and embedded Tegra systems) can create GEM buffers, present them on a plane and free them. No root or CAP_SYS_ADMIN is required.\nUI:N - The attacking process performs the whole sequence itself \u2014 GEM allocation, atomic plane commit, and handle destruction \u2014 with no action by any other user or victim process.\nS:U - The corruption stays within the kernel\u0027s own memory and security authority; there is no crossing into another VM, IOMMU domain, or sandbox boundary.\nC:H - The freed host1x_bo_mapping is read after kfree() to obtain the cache pointer; with slab reuse the attacker can groom the freed object so the read returns attacker-influenced data, and the resulting UAF primitive can be leveraged to disclose kernel memory contents.\nI:H - mutex_unlock() writes to the lock word at the address read from freed memory, so a reallocated/poisoned mapping object yields a write through an attacker-influenceable pointer \u2014 a classic UAF write primitive usable for heap corruption and control-flow hijacking.\nA:H - Dereferencing the freed mapping reliably oopses under slab poisoning/KASAN, and unlocking a bogus mutex address corrupts kernel state, causing a panic or hang; the sequence can be repeated at will to keep the system down."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:35:22.452Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/86a9bd8c8f422d5f3079da31e151868902fcc702"
},
{
"url": "https://git.kernel.org/stable/c/abeff53233b984571b87582bb588b4b38ef4ea50"
},
{
"url": "https://git.kernel.org/stable/c/5b7e5f84d3d4cea10c3764d2da274810a7934228"
},
{
"url": "https://git.kernel.org/stable/c/5f4de3c717d34a24d555af581947742980778c02"
},
{
"url": "https://git.kernel.org/stable/c/b773faa32b0a98c3eb2b50d96de631681e5d1157"
},
{
"url": "https://git.kernel.org/stable/c/266cddf7bd0f6c79b6c0633aef742a22bf70265b"
}
],
"title": "gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68427",
"datePublished": "2026-08-10T12:04:47.915Z",
"dateReserved": "2026-07-30T09:28:09.392Z",
"dateUpdated": "2026-08-19T16:35:22.452Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68320 (GCVE-0-2026-68320)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid
sctp_auth_ep_add_chunkid() uses SCTP_NUM_CHUNK_TYPES (20) as the
capacity limit for ep->auth_chunk_list, allowing it to hold up to
20 chunk entries (param_hdr.length up to 24). However, the copy
destination asoc->c.auth_chunks in struct sctp_cookie is only
SCTP_AUTH_MAX_CHUNKS (16) entries (20 bytes). When more than 16
chunks are added, sctp_association_init() memcpy overflows the
destination by up to 4 bytes.
Fix by using SCTP_AUTH_MAX_CHUNKS as the capacity limit, matching
the destination capacity.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1f485649f52929d9937b346a920a522a7363e202 Version: 1f485649f52929d9937b346a920a522a7363e202 Version: 1f485649f52929d9937b346a920a522a7363e202 Version: 1f485649f52929d9937b346a920a522a7363e202 Version: 1f485649f52929d9937b346a920a522a7363e202 Version: 1f485649f52929d9937b346a920a522a7363e202 Version: 1f485649f52929d9937b346a920a522a7363e202 Version: 1f485649f52929d9937b346a920a522a7363e202 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/sctp/auth.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "3d22a7da2e264f407c729f33a0a346ff76108bc6",
"status": "affected",
"version": "1f485649f52929d9937b346a920a522a7363e202",
"versionType": "git"
},
{
"lessThan": "6837c1c19a259518974cbc5a52017646e3906564",
"status": "affected",
"version": "1f485649f52929d9937b346a920a522a7363e202",
"versionType": "git"
},
{
"lessThan": "54bb4c03fa17cdcb157c26c33e60a78cf32960f5",
"status": "affected",
"version": "1f485649f52929d9937b346a920a522a7363e202",
"versionType": "git"
},
{
"lessThan": "5a365f1e423444c5da7eb689a8661633dad43e48",
"status": "affected",
"version": "1f485649f52929d9937b346a920a522a7363e202",
"versionType": "git"
},
{
"lessThan": "886e28e14ab655012779016d251fef53d103aa12",
"status": "affected",
"version": "1f485649f52929d9937b346a920a522a7363e202",
"versionType": "git"
},
{
"lessThan": "11092d79eb2b7c0068382f72fc2416d1786bb2e0",
"status": "affected",
"version": "1f485649f52929d9937b346a920a522a7363e202",
"versionType": "git"
},
{
"lessThan": "b6ea3dda09eb4d5caf7bbc00f857688cf9e98255",
"status": "affected",
"version": "1f485649f52929d9937b346a920a522a7363e202",
"versionType": "git"
},
{
"lessThan": "ff04b26794a16a8a879eb4fd2c02c2d6b03850e9",
"status": "affected",
"version": "1f485649f52929d9937b346a920a522a7363e202",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/sctp/auth.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.24"
},
{
"lessThan": "2.6.24",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.24",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid\n\nsctp_auth_ep_add_chunkid() uses SCTP_NUM_CHUNK_TYPES (20) as the\ncapacity limit for ep-\u003eauth_chunk_list, allowing it to hold up to\n20 chunk entries (param_hdr.length up to 24). However, the copy\ndestination asoc-\u003ec.auth_chunks in struct sctp_cookie is only\nSCTP_AUTH_MAX_CHUNKS (16) entries (20 bytes). When more than 16\nchunks are added, sctp_association_init() memcpy overflows the\ndestination by up to 4 bytes.\n\nFix by using SCTP_AUTH_MAX_CHUNKS as the capacity limit, matching\nthe destination capacity."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The overflow condition can only be created locally: an attacker must call setsockopt(SCTP_AUTH_SUPPORTED) and then setsockopt(SCTP_AUTH_CHUNK) more than 16 times on an SCTP socket they own. A remote peer can trigger the memcpy by connecting to such a socket, but cannot itself populate the oversized chunk list.\nAC:L - The sequence is fully deterministic and entirely under attacker control \u2014 enable AUTH, add 17-20 distinct chunk IDs, then create an association via connect() or accept(); no race, timing window, or memory-layout condition is involved.\nPR:L - Creating an IPPROTO_SCTP socket and issuing SCTP_AUTH_SUPPORTED/SCTP_AUTH_CHUNK setsockopts requires no capability; sctp_setsockopt_auth_supported() enables AUTH per-endpoint regardless of the net.sctp.auth_enable sysctl, so any unprivileged local user reaches the bug.\nUI:N - The attacker performs every step from their own process \u2014 socket setup, setsockopt calls, and association establishment \u2014 with no action required from any other user or administrator.\nS:U - The corruption and the over-read are confined to the kernel\u0027s own SCTP association object; no other security authority or privilege domain is crossed.\nC:L - sctp_make_init()/sctp_make_init_ack() copy ntohs(auth_chunks-\u003elength) bytes from the 20-byte field, emitting up to 4 bytes past it (the adjacent raw_addr_list_len) inside the CHUNKS parameter of INIT/INIT-ACK sent to the remote peer \u2014 a real but small, strictly bounded out-of-bounds read.\nI:H - sctp_association_init() writes up to 4 bytes of fully attacker-chosen data (the chunk-ID values) past the end of asoc-\u003ec.auth_chunks into the adjacent kernel struct field, an out-of-bounds write of controlled content into kernel memory.\nA:H - On CONFIG_FORTIFY_SOURCE kernels the memcpy is flagged as a field-spanning write and emits a WARN, which is fatal on the widely used panic_on_warn configurations, and the out-of-bounds write itself corrupts SCTP association state; the trigger is cheap and repeatable by any local user."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:10.661Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/3d22a7da2e264f407c729f33a0a346ff76108bc6"
},
{
"url": "https://git.kernel.org/stable/c/6837c1c19a259518974cbc5a52017646e3906564"
},
{
"url": "https://git.kernel.org/stable/c/54bb4c03fa17cdcb157c26c33e60a78cf32960f5"
},
{
"url": "https://git.kernel.org/stable/c/5a365f1e423444c5da7eb689a8661633dad43e48"
},
{
"url": "https://git.kernel.org/stable/c/886e28e14ab655012779016d251fef53d103aa12"
},
{
"url": "https://git.kernel.org/stable/c/11092d79eb2b7c0068382f72fc2416d1786bb2e0"
},
{
"url": "https://git.kernel.org/stable/c/b6ea3dda09eb4d5caf7bbc00f857688cf9e98255"
},
{
"url": "https://git.kernel.org/stable/c/ff04b26794a16a8a879eb4fd2c02c2d6b03850e9"
}
],
"title": "sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68320",
"datePublished": "2026-08-10T12:02:55.144Z",
"dateReserved": "2026-07-30T09:28:09.382Z",
"dateUpdated": "2026-08-19T16:33:10.661Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68161 (GCVE-0-2026-68161)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-17 04:59
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
sctp: close UDP tunnel sockets during netns teardown
proc_sctp_do_udp_port() starts per-net SCTP UDP tunneling sockets when
net.sctp.udp_port is set, and stops/restarts them when the sysctl value
changes. The netns exit path does not stop these sockets, so a namespace
can be torn down while its SCTP UDP tunnel sockets are still installed.
Close the UDP tunnel sockets from sctp_ctrlsock_exit() after unregistering
the per-net sysctl table. This prevents new sysctl writes from racing in
while the sockets are being released, and closes the sockets before the
control socket is destroyed.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/sctp/protocol.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c6eb2d615210b80339548ab07c0230edaab9a6c7",
"status": "affected",
"version": "046c052b475e7119b6a30e3483e2888fc606a2f8",
"versionType": "git"
},
{
"lessThan": "8ff78591d309c50a4fdab683b68dd8d512a270dd",
"status": "affected",
"version": "046c052b475e7119b6a30e3483e2888fc606a2f8",
"versionType": "git"
},
{
"lessThan": "3bf0e349cbb4f975f35eb22753acc346b89c66a0",
"status": "affected",
"version": "046c052b475e7119b6a30e3483e2888fc606a2f8",
"versionType": "git"
},
{
"lessThan": "37ff9794be48d0caa37687e04d09675f9c849121",
"status": "affected",
"version": "046c052b475e7119b6a30e3483e2888fc606a2f8",
"versionType": "git"
},
{
"lessThan": "ffb2bd7ade36ec4da32c46a6eddbf4515316d08c",
"status": "affected",
"version": "046c052b475e7119b6a30e3483e2888fc606a2f8",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/sctp/protocol.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.11"
},
{
"lessThan": "5.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: close UDP tunnel sockets during netns teardown\n\nproc_sctp_do_udp_port() starts per-net SCTP UDP tunneling sockets when\nnet.sctp.udp_port is set, and stops/restarts them when the sysctl value\nchanges. The netns exit path does not stop these sockets, so a namespace\ncan be torn down while its SCTP UDP tunnel sockets are still installed.\n\nClose the UDP tunnel sockets from sctp_ctrlsock_exit() after unregistering\nthe per-net sysctl table. This prevents new sysctl writes from racing in\nwhile the sockets are being released, and closes the sockets before the\ncontrol socket is destroyed."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - Stale SCTP UDP tunnel sockets left installed after netns teardown still receive remote SCTP-over-UDP (RFC 6951) on the configured net.sctp.udp_port; packets enter sctp_udp_rcv\u2192sctp_rcv in softirq and touch freed per-net SCTP/UDP state.\nAC:L - An attacker can repeatedly race namespace deletion against SCTP-over-UDP traffic they send or receive, controlling both teardown timing and packet delivery; no attacker-uncontrollable memory layout or rare kernel config is required beyond SCTP being enabled.\nPR:N - On SCTP-over-UDP deployments where net.sctp.udp_port is already configured, any remote SCTP peer needs no credentials on the target; alternatively an unprivileged local user obtains CAP_NET_ADMIN via user namespaces to set udp_port and destroy the namespace.\nUI:N - Exploitation requires only attacker-driven SCTP-over-UDP traffic and namespace lifecycle events (e.g., container restart); no victim must mount a filesystem, open a file, or take any separate interactive action.\nS:U - Impact is host-kernel slab use-after-free and memory corruption within the same OS security authority; it does not cross VM, IOMMU, or sandbox boundaries to affect a separate security domain.\nC:H - Use-after-free of struct net and SCTP UDP tunnel socket state lets an attacker influence freed slab contents and obtain arbitrary kernel memory read primitives through subsequent SCTP/UDP lookups and socket processing.\nI:H - The UAF enables heap grooming and reuse of freed per-net/socket objects in SCTP/UDP handlers, supporting arbitrary kernel writes and control-flow hijack typical of slab use-after-free exploitation.\nA:H - Dereferencing SCTP/UDP tunnel sockets and per-net state after netns free causes slab use-after-free detections, kernel oops, or panic; even unexploited UAF commonly crashes or hangs the host."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:59:57.755Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c6eb2d615210b80339548ab07c0230edaab9a6c7"
},
{
"url": "https://git.kernel.org/stable/c/8ff78591d309c50a4fdab683b68dd8d512a270dd"
},
{
"url": "https://git.kernel.org/stable/c/3bf0e349cbb4f975f35eb22753acc346b89c66a0"
},
{
"url": "https://git.kernel.org/stable/c/37ff9794be48d0caa37687e04d09675f9c849121"
},
{
"url": "https://git.kernel.org/stable/c/ffb2bd7ade36ec4da32c46a6eddbf4515316d08c"
}
],
"title": "sctp: close UDP tunnel sockets during netns teardown",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68161",
"datePublished": "2026-08-10T11:59:28.072Z",
"dateReserved": "2026-07-30T09:28:09.372Z",
"dateUpdated": "2026-08-17T04:59:57.755Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68407 (GCVE-0-2026-68407)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-19 16:35
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: nl80211: free RNR data on MBSSID mismatch
nl80211_parse_beacon() rejects EMA RNR data when there are fewer RNR
entries than MBSSID entries.
The rejected RNR allocation has not been attached to the beacon data yet,
so free it before returning the error.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 56189d7bc30531def6b999f27940ee43c6ff2569 Version: dbbb27e183b1568d5a907ace1cd144b0709ea52a Version: dbbb27e183b1568d5a907ace1cd144b0709ea52a Version: dbbb27e183b1568d5a907ace1cd144b0709ea52a Version: dbbb27e183b1568d5a907ace1cd144b0709ea52a Version: dbbb27e183b1568d5a907ace1cd144b0709ea52a Version: 6.1.160 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/wireless/nl80211.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "4b76fc30c80b240107a7de3c7560113c9290eafc",
"status": "affected",
"version": "56189d7bc30531def6b999f27940ee43c6ff2569",
"versionType": "git"
},
{
"lessThan": "fa9592ef7de11f8c7042315d9bc20e91a97f679e",
"status": "affected",
"version": "dbbb27e183b1568d5a907ace1cd144b0709ea52a",
"versionType": "git"
},
{
"lessThan": "312c8b9d7836ef58e552619a8c19be08b04032bb",
"status": "affected",
"version": "dbbb27e183b1568d5a907ace1cd144b0709ea52a",
"versionType": "git"
},
{
"lessThan": "fb052a6e2fa866384d8edc237746583ec94c15af",
"status": "affected",
"version": "dbbb27e183b1568d5a907ace1cd144b0709ea52a",
"versionType": "git"
},
{
"lessThan": "6f919f29e9b75793104709987131b8d910d7800a",
"status": "affected",
"version": "dbbb27e183b1568d5a907ace1cd144b0709ea52a",
"versionType": "git"
},
{
"lessThan": "07a95ec2b54774201fdf4ef7ffb0ca2ab19ed29c",
"status": "affected",
"version": "dbbb27e183b1568d5a907ace1cd144b0709ea52a",
"versionType": "git"
},
{
"lessThan": "6.1.183",
"status": "affected",
"version": "6.1.160",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/wireless/nl80211.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.4"
},
{
"lessThan": "6.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "6.1.160",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: nl80211: free RNR data on MBSSID mismatch\n\nnl80211_parse_beacon() rejects EMA RNR data when there are fewer RNR\nentries than MBSSID entries.\n\nThe rejected RNR allocation has not been attached to the beacon data yet,\nso free it before returning the error."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:35:02.178Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/4b76fc30c80b240107a7de3c7560113c9290eafc"
},
{
"url": "https://git.kernel.org/stable/c/fa9592ef7de11f8c7042315d9bc20e91a97f679e"
},
{
"url": "https://git.kernel.org/stable/c/312c8b9d7836ef58e552619a8c19be08b04032bb"
},
{
"url": "https://git.kernel.org/stable/c/fb052a6e2fa866384d8edc237746583ec94c15af"
},
{
"url": "https://git.kernel.org/stable/c/6f919f29e9b75793104709987131b8d910d7800a"
},
{
"url": "https://git.kernel.org/stable/c/07a95ec2b54774201fdf4ef7ffb0ca2ab19ed29c"
}
],
"title": "wifi: nl80211: free RNR data on MBSSID mismatch",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68407",
"datePublished": "2026-08-10T12:04:27.252Z",
"dateReserved": "2026-07-30T09:28:09.390Z",
"dateUpdated": "2026-08-19T16:35:02.178Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68402 (GCVE-0-2026-68402)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: cfg80211: bound element ID read when checking non-inheritance
cfg80211_is_element_inherited() reads the first data octet of the
candidate element (id = elem->data[0]) to look it up in an extension
non-inheritance list. It does so after testing elem->id, but without
verifying that the element actually has a data octet. A zero-length
extension element (WLAN_EID_EXTENSION with length 0) therefore makes it
read one octet past the end of the element.
_ieee802_11_parse_elems_full() runs this check for every element of a
frame once a non-inheritance context exists -- e.g. while parsing a
per-STA profile of a Multi-Link element in a (re)association response,
or a non-transmitted BSS profile -- so a crafted frame from an AP can
trigger a one-octet slab-out-of-bounds read during element parsing:
BUG: KASAN: slab-out-of-bounds in cfg80211_is_element_inherited
Read of size 1 ... in net/wireless/scan.c
Return early (treat the element as inherited) when an extension element
carries no data, mirroring the existing handling of empty ID lists.
The bug was found by fuzzing ieee802_11_parse_elems_full() under KASAN.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3 Version: f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3 Version: f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3 Version: f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3 Version: f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3 Version: f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3 Version: f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3 Version: f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/wireless/scan.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "521dd5fe6d12b0d3c275f919738dc3a07117f4a5",
"status": "affected",
"version": "f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3",
"versionType": "git"
},
{
"lessThan": "24154c172246ae3f0e69bb17c9111095685ceedc",
"status": "affected",
"version": "f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3",
"versionType": "git"
},
{
"lessThan": "2d31ebb26a14f103c9cdc5287fb20cb2d4bde901",
"status": "affected",
"version": "f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3",
"versionType": "git"
},
{
"lessThan": "20c308d9a57722801961f816395bf825f7bde6bc",
"status": "affected",
"version": "f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3",
"versionType": "git"
},
{
"lessThan": "84bd907361c56fbd5523eceb2682cb39da059bd5",
"status": "affected",
"version": "f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3",
"versionType": "git"
},
{
"lessThan": "11ac7a5e75f5132f1778e0c60981d30dc29fb869",
"status": "affected",
"version": "f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3",
"versionType": "git"
},
{
"lessThan": "ddf2773bcc8e49a43c561f22ec1e7924215d7947",
"status": "affected",
"version": "f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3",
"versionType": "git"
},
{
"lessThan": "cb8afea4655ff004fa7feee825d5c79783525383",
"status": "affected",
"version": "f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/wireless/scan.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.2"
},
{
"lessThan": "5.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: cfg80211: bound element ID read when checking non-inheritance\n\ncfg80211_is_element_inherited() reads the first data octet of the\ncandidate element (id = elem-\u003edata[0]) to look it up in an extension\nnon-inheritance list. It does so after testing elem-\u003eid, but without\nverifying that the element actually has a data octet. A zero-length\nextension element (WLAN_EID_EXTENSION with length 0) therefore makes it\nread one octet past the end of the element.\n\n_ieee802_11_parse_elems_full() runs this check for every element of a\nframe once a non-inheritance context exists -- e.g. while parsing a\nper-STA profile of a Multi-Link element in a (re)association response,\nor a non-transmitted BSS profile -- so a crafted frame from an AP can\ntrigger a one-octet slab-out-of-bounds read during element parsing:\n\n BUG: KASAN: slab-out-of-bounds in cfg80211_is_element_inherited\n Read of size 1 ... in net/wireless/scan.c\n\nReturn early (treat the element as inherited) when an extension element\ncarries no data, mirroring the existing handling of empty ID lists.\n\nThe bug was found by fuzzing ieee802_11_parse_elems_full() under KASAN."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The malformed element arrives in an 802.11 management frame (beacon, probe response, ML probe response or (re)association response) processed by mac80211\u0027s element parser, so the attacker must be a rogue/spoofing AP within radio range of the victim station.\nAC:L - The attacker fully controls the frame contents and simply appends a zero-length WLAN_EID_EXTENSION element inside a frame that already establishes a non-inheritance context (multi-BSSID non-transmitted profile or a Multi-Link per-STA profile), which reliably triggers the over-read every time.\nPR:N - Beacons, probe responses and association responses are parsed before or independently of any authentication or key establishment, so an unauthenticated attacker with no credentials on the network can deliver the crafted frame.\nUI:N - Stations parse beacons and probe/association responses automatically as part of scanning, roaming and staying associated; no action by the device owner is needed for the crafted frame to be processed.\nS:U - The out-of-bounds read stays within the kernel\u0027s own memory and security authority; no other component or privilege domain is crossed.\nC:L - The read is a single octet past the end of the slab object, and its value is only compared against the non-inheritance ID list, influencing whether an element is parsed \u2014 this leaks at most a narrow side-channel oracle about one adjacent heap byte rather than arbitrary memory.\nI:N - The defect is purely a read; no kernel memory is written or corrupted, and the only consequence is a possibly wrong inherit/skip decision for one element in a frame the attacker already controls.\nA:H - The slab out-of-bounds access is fatal on KASAN, hardened or debug-allocator kernels (the bug was reported as a KASAN slab-out-of-bounds splat), and can be re-triggered at will by an adjacent unauthenticated attacker to repeatedly panic the machine."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:52.049Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/521dd5fe6d12b0d3c275f919738dc3a07117f4a5"
},
{
"url": "https://git.kernel.org/stable/c/24154c172246ae3f0e69bb17c9111095685ceedc"
},
{
"url": "https://git.kernel.org/stable/c/2d31ebb26a14f103c9cdc5287fb20cb2d4bde901"
},
{
"url": "https://git.kernel.org/stable/c/20c308d9a57722801961f816395bf825f7bde6bc"
},
{
"url": "https://git.kernel.org/stable/c/84bd907361c56fbd5523eceb2682cb39da059bd5"
},
{
"url": "https://git.kernel.org/stable/c/11ac7a5e75f5132f1778e0c60981d30dc29fb869"
},
{
"url": "https://git.kernel.org/stable/c/ddf2773bcc8e49a43c561f22ec1e7924215d7947"
},
{
"url": "https://git.kernel.org/stable/c/cb8afea4655ff004fa7feee825d5c79783525383"
}
],
"title": "wifi: cfg80211: bound element ID read when checking non-inheritance",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68402",
"datePublished": "2026-08-10T12:04:22.113Z",
"dateReserved": "2026-07-30T09:28:09.389Z",
"dateUpdated": "2026-08-19T16:34:52.049Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68147 (GCVE-0-2026-68147)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
fscrypt: Avoid dynamic allocation in fscrypt_get_devices()
When a blk_crypto_key starts being used or is evicted, fs/crypto/ calls
fscrypt_get_devices() to get the filesystem's list of block devices,
then iterates over them and calls blk_crypto_config_supported(),
blk_crypto_start_using_key(), or blk_crypto_evict_key() on each one.
Currently, the block device pointers are placed in a dynamically
allocated array. This dynamic allocation is problematic because:
- It can fail, especially at the fscrypt_destroy_inline_crypt_key() call
site when it's invoked for inode eviction under direct reclaim.
- fscrypt_destroy_inline_crypt_key() doesn't handle the failure. It
just zeroizes and frees the blk_crypto_key without calling
blk_crypto_evict_key(). That causes a use-after-free.
For now, let's fix this in the straightforward and easily-backportable
way by switching to an on-stack array. Currently the fscrypt
multi-device functionality is used only by f2fs, which has a hardcoded
limit of 8 block devices. An on-stack array works fine for that.
(Of course, this solution won't scale up to large number of block
devices. For that we'd need a different solution, like moving the block
device iteration into the filesystem. Or in the case of btrfs, which
will only support blk-crypto-fallback, we should make it just call
blk-crypto-fallback directly, so the block devices won't be needed.)
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 22e9947a4b2ba255888541bd0111cf00b9b16586 Version: 22e9947a4b2ba255888541bd0111cf00b9b16586 Version: 22e9947a4b2ba255888541bd0111cf00b9b16586 Version: 22e9947a4b2ba255888541bd0111cf00b9b16586 Version: 22e9947a4b2ba255888541bd0111cf00b9b16586 Version: 22e9947a4b2ba255888541bd0111cf00b9b16586 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/crypto/inline_crypt.c",
"fs/f2fs/super.c",
"include/linux/fscrypt.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "bab016bb80d74a9d1f7d4121a7fc1cb529b470e0",
"status": "affected",
"version": "22e9947a4b2ba255888541bd0111cf00b9b16586",
"versionType": "git"
},
{
"lessThan": "4462ac3d90e897dda52ce4b6af2d526ddae835a8",
"status": "affected",
"version": "22e9947a4b2ba255888541bd0111cf00b9b16586",
"versionType": "git"
},
{
"lessThan": "97a688563be71ec6fefc071aff69a66c69dbe244",
"status": "affected",
"version": "22e9947a4b2ba255888541bd0111cf00b9b16586",
"versionType": "git"
},
{
"lessThan": "81ea8e8221853950c47dac7164f27c63a96f8f86",
"status": "affected",
"version": "22e9947a4b2ba255888541bd0111cf00b9b16586",
"versionType": "git"
},
{
"lessThan": "bc2d630296e0e049210ec05ff08459a6893ae749",
"status": "affected",
"version": "22e9947a4b2ba255888541bd0111cf00b9b16586",
"versionType": "git"
},
{
"lessThan": "6fe4e4b8259e1330945b5f3c9476e08473b8e0e8",
"status": "affected",
"version": "22e9947a4b2ba255888541bd0111cf00b9b16586",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/crypto/inline_crypt.c",
"fs/f2fs/super.c",
"include/linux/fscrypt.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.1"
},
{
"lessThan": "6.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "6.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfscrypt: Avoid dynamic allocation in fscrypt_get_devices()\n\nWhen a blk_crypto_key starts being used or is evicted, fs/crypto/ calls\nfscrypt_get_devices() to get the filesystem\u0027s list of block devices,\nthen iterates over them and calls blk_crypto_config_supported(),\nblk_crypto_start_using_key(), or blk_crypto_evict_key() on each one.\n\nCurrently, the block device pointers are placed in a dynamically\nallocated array. This dynamic allocation is problematic because:\n\n- It can fail, especially at the fscrypt_destroy_inline_crypt_key() call\n site when it\u0027s invoked for inode eviction under direct reclaim.\n\n- fscrypt_destroy_inline_crypt_key() doesn\u0027t handle the failure. It\n just zeroizes and frees the blk_crypto_key without calling\n blk_crypto_evict_key(). That causes a use-after-free.\n\nFor now, let\u0027s fix this in the straightforward and easily-backportable\nway by switching to an on-stack array. Currently the fscrypt\nmulti-device functionality is used only by f2fs, which has a hardcoded\nlimit of 8 block devices. An on-stack array works fine for that.\n\n(Of course, this solution won\u0027t scale up to large number of block\ndevices. For that we\u0027d need a different solution, like moving the block\ndevice iteration into the filesystem. Or in the case of btrfs, which\nwill only support blk-crypto-fallback, we should make it just call\nblk-crypto-fallback directly, so the block devices won\u0027t be needed.)"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached only via local fscrypt/inline-crypto teardown (fscrypt_destroy_inline_crypt_key) during inode eviction or key removal on ext4/f2fs, triggered by local syscalls/ioctls and file operations, not by any network-facing kernel service.\nAC:L - An attacker can reliably induce the kmalloc failure by creating memory pressure while closing encrypted inodes or removing v2 fscrypt keys, especially under direct reclaim where the commit notes this path fails; both sides of the race are attacker-controlled.\nPR:L - Exploitation requires only a local unprivileged user on an inlinecrypt-mounted filesystem: v2 FS_IOC_ADD/REMOVE_ENCRYPTION_KEY are unprivileged, and the attacker can create/close their own encrypted files to drive fscrypt_put_encryption_info into the buggy destroy path.\nUI:N - No victim interaction is required; the attacker triggers memory pressure and encrypted inode/key teardown themselves through normal local file and fscrypt ioctl operations on systems already mounted with inline encryption.\nS:U - Impact is confined to kernel memory corruption and privilege escalation within the same kernel security domain; this is not a VM escape, IOMMU bypass, or other cross-authority boundary violation.\nC:H - Skipping blk_crypto_evict_key before kfree_sensitive leaves dangling slot-\u003ekey/bio_crypt_ctx pointers to a freed blk_crypto_key (containing raw key bytes), a classic use-after-free that enables arbitrary kernel memory disclosure and heap grooming.\nI:H - The use-after-free of blk_crypto_key structures still registered in blk-crypto keyslot hash tables can be leveraged for heap corruption and control-flow hijacking, yielding arbitrary kernel write or local privilege escalation primitives.\nA:H - Dereferencing the prematurely freed blk_crypto_key during subsequent block I/O or keyslot lookups can cause kernel oops/panic; use-after-free in the block crypto path also inherently threatens system availability even before full exploitation."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:30:11.166Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/bab016bb80d74a9d1f7d4121a7fc1cb529b470e0"
},
{
"url": "https://git.kernel.org/stable/c/4462ac3d90e897dda52ce4b6af2d526ddae835a8"
},
{
"url": "https://git.kernel.org/stable/c/97a688563be71ec6fefc071aff69a66c69dbe244"
},
{
"url": "https://git.kernel.org/stable/c/81ea8e8221853950c47dac7164f27c63a96f8f86"
},
{
"url": "https://git.kernel.org/stable/c/bc2d630296e0e049210ec05ff08459a6893ae749"
},
{
"url": "https://git.kernel.org/stable/c/6fe4e4b8259e1330945b5f3c9476e08473b8e0e8"
}
],
"title": "fscrypt: Avoid dynamic allocation in fscrypt_get_devices()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68147",
"datePublished": "2026-08-10T11:59:12.308Z",
"dateReserved": "2026-07-30T09:28:09.371Z",
"dateUpdated": "2026-08-19T16:30:11.166Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68432 (GCVE-0-2026-68432)
Vulnerability from cvelistv5
Published
2026-08-12 00:07
Modified
2026-08-19 16:35
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
vxlan: require CAP_NET_ADMIN in the device netns for changelink
A tunnel changelink() operates on at most two netns, dev_net(dev) and
the sticky underlay netns vxlan->net. They differ once the device is
created in or moved to a netns other than the one the request runs in.
The rtnl changelink path checks CAP_NET_ADMIN only against dev_net(dev),
so a caller privileged there but not in vxlan->net can rewrite a vxlan
device whose underlay lives in vxlan->net.
vxlan_changelink() validates and applies the new configuration against
vxlan->net (vxlan_config_validate(vxlan->net, ...)) and can reopen the
underlay socket in that netns, so the same reasoning as the tunnel
changelink series applies here.
Gate vxlan_changelink() with rtnl_dev_link_net_capable(), at the top of
the op before any attribute is parsed, matching ipgre_changelink() and
the rest of the "require CAP_NET_ADMIN in the device netns for
changelink" series.
Found by 0sec automated security-research tooling (https://0sec.ai).
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 8bcdc4f3a20be949df54b67e5ae2734daabb5792 Version: 8bcdc4f3a20be949df54b67e5ae2734daabb5792 Version: 8bcdc4f3a20be949df54b67e5ae2734daabb5792 Version: 8bcdc4f3a20be949df54b67e5ae2734daabb5792 Version: 8bcdc4f3a20be949df54b67e5ae2734daabb5792 Version: 8bcdc4f3a20be949df54b67e5ae2734daabb5792 Version: 8bcdc4f3a20be949df54b67e5ae2734daabb5792 Version: 8bcdc4f3a20be949df54b67e5ae2734daabb5792 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/vxlan/vxlan_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b95a8743e58f7efed5ddc4cb73829b66f17feab0",
"status": "affected",
"version": "8bcdc4f3a20be949df54b67e5ae2734daabb5792",
"versionType": "git"
},
{
"lessThan": "7465ade989ba84adc2bfa58bad3ca25d249f0f7a",
"status": "affected",
"version": "8bcdc4f3a20be949df54b67e5ae2734daabb5792",
"versionType": "git"
},
{
"lessThan": "0aa580a8bbbed2507b4582a1f0ef581d480d06ed",
"status": "affected",
"version": "8bcdc4f3a20be949df54b67e5ae2734daabb5792",
"versionType": "git"
},
{
"lessThan": "b3793d7dccb192ffff29894d11824db6251acdd5",
"status": "affected",
"version": "8bcdc4f3a20be949df54b67e5ae2734daabb5792",
"versionType": "git"
},
{
"lessThan": "32d10c46bfde3e9b274e9e1bd6399d0ebea8f60f",
"status": "affected",
"version": "8bcdc4f3a20be949df54b67e5ae2734daabb5792",
"versionType": "git"
},
{
"lessThan": "730c7e5fea7f06e0cdf21c547222ec93234fd1d6",
"status": "affected",
"version": "8bcdc4f3a20be949df54b67e5ae2734daabb5792",
"versionType": "git"
},
{
"lessThan": "e8ad0d311e225939a9a6c745d6cc384c7364ec87",
"status": "affected",
"version": "8bcdc4f3a20be949df54b67e5ae2734daabb5792",
"versionType": "git"
},
{
"lessThan": "3a61bd9637f3d929aa846e4eb3d98b48c26fcb0e",
"status": "affected",
"version": "8bcdc4f3a20be949df54b67e5ae2734daabb5792",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/vxlan/vxlan_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.11"
},
{
"lessThan": "4.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nvxlan: require CAP_NET_ADMIN in the device netns for changelink\n\nA tunnel changelink() operates on at most two netns, dev_net(dev) and\nthe sticky underlay netns vxlan-\u003enet. They differ once the device is\ncreated in or moved to a netns other than the one the request runs in.\nThe rtnl changelink path checks CAP_NET_ADMIN only against dev_net(dev),\nso a caller privileged there but not in vxlan-\u003enet can rewrite a vxlan\ndevice whose underlay lives in vxlan-\u003enet.\n\nvxlan_changelink() validates and applies the new configuration against\nvxlan-\u003enet (vxlan_config_validate(vxlan-\u003enet, ...)) and can reopen the\nunderlay socket in that netns, so the same reasoning as the tunnel\nchangelink series applies here.\n\nGate vxlan_changelink() with rtnl_dev_link_net_capable(), at the top of\nthe op before any attribute is parsed, matching ipgre_changelink() and\nthe rest of the \"require CAP_NET_ADMIN in the device netns for\nchangelink\" series.\n\nFound by 0sec automated security-research tooling (https://0sec.ai)."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires issuing an RTM_NEWLINK changelink request over an rtnetlink socket on the local system, matching the kernel guidance that netlink configuration paths are Local.\nAC:L - Once a cross-namespace vxlan device is present in the caller\u0027s netns, the missing check is bypassed by a single deterministic netlink changelink call with no race, timing, or memory-layout dependency.\nPR:L - The rtnl entry path only requires CAP_NET_ADMIN in dev_net(dev), which an unprivileged user obtains inside a user namespace via unshare --user --map-root-user --net; no privilege in the underlay netns vxlan-\u003enet is needed.\nUI:N - The attack is fully programmatic through netlink from the attacker\u0027s own process; no victim action such as mounting, opening a file, or clicking is required.\nS:C - Authorization is evaluated against dev_net(dev) while the configuration is validated and applied against vxlan-\u003enet, so the impact crosses from the attacker\u0027s net/user namespace into another tenant\u0027s or the host\u0027s network namespace.\nC:H - The attacker can rewrite IFLA_VXLAN_GROUP/LOCAL and the underlay IFLA_VXLAN_LINK so encapsulated overlay traffic in the victim netns is sent to an attacker-controlled endpoint, exposing tunneled payloads.\nI:H - Unauthorized changelink mutates live tunnel state in the victim underlay netns (remote/local addresses, lower device, TOS/TTL/label, learning and proxy/RSC flags, default-remote FDB entries), enabling redirection and injection of overlay traffic.\nA:H - Rewriting the remote group, source address, or lower device tears down and re-establishes multicast group membership and forwarding state, causing sustained loss of connectivity for every service riding the affected VXLAN overlay."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:35:30.743Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b95a8743e58f7efed5ddc4cb73829b66f17feab0"
},
{
"url": "https://git.kernel.org/stable/c/7465ade989ba84adc2bfa58bad3ca25d249f0f7a"
},
{
"url": "https://git.kernel.org/stable/c/0aa580a8bbbed2507b4582a1f0ef581d480d06ed"
},
{
"url": "https://git.kernel.org/stable/c/b3793d7dccb192ffff29894d11824db6251acdd5"
},
{
"url": "https://git.kernel.org/stable/c/32d10c46bfde3e9b274e9e1bd6399d0ebea8f60f"
},
{
"url": "https://git.kernel.org/stable/c/730c7e5fea7f06e0cdf21c547222ec93234fd1d6"
},
{
"url": "https://git.kernel.org/stable/c/e8ad0d311e225939a9a6c745d6cc384c7364ec87"
},
{
"url": "https://git.kernel.org/stable/c/3a61bd9637f3d929aa846e4eb3d98b48c26fcb0e"
}
],
"title": "vxlan: require CAP_NET_ADMIN in the device netns for changelink",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68432",
"datePublished": "2026-08-12T00:07:18.806Z",
"dateReserved": "2026-07-30T09:28:09.393Z",
"dateUpdated": "2026-08-19T16:35:30.743Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68297 (GCVE-0-2026-68297)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-19 16:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
tipc: fix u16 MTU truncation in media and bearer MTU validation
Both TIPC_NL_MEDIA_SET and TIPC_NL_BEARER_SET accept user-supplied
MTU values but only enforce a minimum bound, not a maximum. When a user
sets the MTU to a value exceeding U16_MAX (65535), it passes validation
but is silently truncated when assigned to u16 fields l->mtu and
l->advertised_mtu in tipc_link_create(). Values like 65536 (0x10000)
truncate to 0, causing a division by zero in tipc_link_set_queue_limits()
which computes TIPC_MAX_PUBL / (l->mtu / ITEM_SIZE). Other overflowing
values (e.g. 65537-131071) produce small incorrect MTU values, resulting
in link malfunction behaviors.
Crash stack (triggered as unprivileged user via user namespace):
tipc_link_set_queue_limits net/tipc/link.c:2531
tipc_link_create net/tipc/link.c:520
tipc_node_check_dest net/tipc/node.c:1279
tipc_disc_rcv net/tipc/discover.c:252
tipc_rcv net/tipc/node.c:2129
tipc_udp_recv net/tipc/udp_media.c:392
Two independent paths lack the upper bound check:
1. tipc_udp_mtu_bad() -- called from __tipc_nl_media_set() (MEDIA_SET)
2. inline check in __tipc_nl_bearer_set() at bearer.c:1160 (BEARER_SET)
Fix both by rejecting MTU values above U16_MAX.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 901271e0403af638c224987c2a4e55cebade7e91 Version: 901271e0403af638c224987c2a4e55cebade7e91 Version: 901271e0403af638c224987c2a4e55cebade7e91 Version: 901271e0403af638c224987c2a4e55cebade7e91 Version: 901271e0403af638c224987c2a4e55cebade7e91 Version: 901271e0403af638c224987c2a4e55cebade7e91 Version: 901271e0403af638c224987c2a4e55cebade7e91 Version: 901271e0403af638c224987c2a4e55cebade7e91 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/tipc/netlink.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "8bfdfe0dbb36a650b7c4dec1aeae078319938a0b",
"status": "affected",
"version": "901271e0403af638c224987c2a4e55cebade7e91",
"versionType": "git"
},
{
"lessThan": "dc4b577a083b361d25e118dc96d8281255ebe22c",
"status": "affected",
"version": "901271e0403af638c224987c2a4e55cebade7e91",
"versionType": "git"
},
{
"lessThan": "dfdfd987f1917c84766e097a6120a1f3f1634940",
"status": "affected",
"version": "901271e0403af638c224987c2a4e55cebade7e91",
"versionType": "git"
},
{
"lessThan": "f02334a9e378f7e07232b26dc3d2ab353339f040",
"status": "affected",
"version": "901271e0403af638c224987c2a4e55cebade7e91",
"versionType": "git"
},
{
"lessThan": "f4013598b69457dbea350df52e52daea6faef8eb",
"status": "affected",
"version": "901271e0403af638c224987c2a4e55cebade7e91",
"versionType": "git"
},
{
"lessThan": "1b8fb5a20508bfb0db854e01214888c761b3a911",
"status": "affected",
"version": "901271e0403af638c224987c2a4e55cebade7e91",
"versionType": "git"
},
{
"lessThan": "c1cda72f6acec02ebd45d913bf8527ff77336ba6",
"status": "affected",
"version": "901271e0403af638c224987c2a4e55cebade7e91",
"versionType": "git"
},
{
"lessThan": "9f29cd8a8e7901a2617c8064ce9f50fc67b97cb8",
"status": "affected",
"version": "901271e0403af638c224987c2a4e55cebade7e91",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/tipc/netlink.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.18"
},
{
"lessThan": "4.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.18",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: fix u16 MTU truncation in media and bearer MTU validation\n\nBoth TIPC_NL_MEDIA_SET and TIPC_NL_BEARER_SET accept user-supplied\nMTU values but only enforce a minimum bound, not a maximum. When a user\nsets the MTU to a value exceeding U16_MAX (65535), it passes validation\nbut is silently truncated when assigned to u16 fields l-\u003emtu and\nl-\u003eadvertised_mtu in tipc_link_create(). Values like 65536 (0x10000)\ntruncate to 0, causing a division by zero in tipc_link_set_queue_limits()\nwhich computes TIPC_MAX_PUBL / (l-\u003emtu / ITEM_SIZE). Other overflowing\nvalues (e.g. 65537-131071) produce small incorrect MTU values, resulting\nin link malfunction behaviors.\n\nCrash stack (triggered as unprivileged user via user namespace):\n\n tipc_link_set_queue_limits net/tipc/link.c:2531\n tipc_link_create net/tipc/link.c:520\n tipc_node_check_dest net/tipc/node.c:1279\n tipc_disc_rcv net/tipc/discover.c:252\n tipc_rcv net/tipc/node.c:2129\n tipc_udp_recv net/tipc/udp_media.c:392\n\nTwo independent paths lack the upper bound check:\n1. tipc_udp_mtu_bad() -- called from __tipc_nl_media_set() (MEDIA_SET)\n2. inline check in __tipc_nl_bearer_set() at bearer.c:1160 (BEARER_SET)\n\nFix both by rejecting MTU values above U16_MAX."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The attack begins with a local TIPC netlink command (TIPC_NL_BEARER_SET/TIPC_NL_MEDIA_SET) setting an out-of-range MTU, with the crash/corruption then triggered by locally generated discovery traffic and sendmsg() in the attacker\u0027s own network namespace.\nAC:L - The attacker fully controls both the bad MTU value and the discovery packet that creates the link, so the truncation and subsequent divide-by-zero or undersized-fragment path trigger deterministically on every attempt.\nPR:L - Both netlink ops are gated by GENL_UNS_ADMIN_PERM, i.e. CAP_NET_ADMIN in the owning user namespace, which any unprivileged user obtains via `unshare -Urn`; the commit message explicitly reports the crash reproduced as an unprivileged user through a user namespace.\nUI:N - The attacker performs every step (bearer setup, MTU configuration, packet injection, sendmsg) with no action from any other user or administrator.\nS:U - The truncated MTU corrupts only kernel state within the same kernel security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - Truncated MTUs below the TIPC header size propagate into tipc_msg_build() as pktmax, driving negative fragment remainders and oversized copies into undersized skbs; the resulting heap corruption and adjacent-object exposure can be leveraged to read kernel memory.\nI:H - The undersized-fragment path writes INT_H_SIZE plus header bytes and then a negative-length (huge unsigned) user copy into a buffer allocated at the truncated MTU size, giving an attacker-controlled linear heap overflow suitable for control-flow hijacking.\nA:H - MTU values truncating to under 20 make tipc_link_set_queue_limits() divide by zero inside tipc_link_create(), which runs in softirq context from tipc_udp_recv()/tipc_disc_rcv(), producing a kernel oops that is typically fatal in interrupt context."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:32:46.091Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/8bfdfe0dbb36a650b7c4dec1aeae078319938a0b"
},
{
"url": "https://git.kernel.org/stable/c/dc4b577a083b361d25e118dc96d8281255ebe22c"
},
{
"url": "https://git.kernel.org/stable/c/dfdfd987f1917c84766e097a6120a1f3f1634940"
},
{
"url": "https://git.kernel.org/stable/c/f02334a9e378f7e07232b26dc3d2ab353339f040"
},
{
"url": "https://git.kernel.org/stable/c/f4013598b69457dbea350df52e52daea6faef8eb"
},
{
"url": "https://git.kernel.org/stable/c/1b8fb5a20508bfb0db854e01214888c761b3a911"
},
{
"url": "https://git.kernel.org/stable/c/c1cda72f6acec02ebd45d913bf8527ff77336ba6"
},
{
"url": "https://git.kernel.org/stable/c/9f29cd8a8e7901a2617c8064ce9f50fc67b97cb8"
}
],
"title": "tipc: fix u16 MTU truncation in media and bearer MTU validation",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68297",
"datePublished": "2026-08-10T12:02:30.721Z",
"dateReserved": "2026-07-30T09:28:09.380Z",
"dateUpdated": "2026-08-19T16:32:46.091Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72244 (GCVE-0-2026-72244)
Vulnerability from cvelistv5
Published
2026-08-15 05:54
Modified
2026-08-17 05:41
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
gpu/buddy: bail out of try_harder when alignment cannot be honoured
The try_harder contiguous fallback could return a range whose start
offset did not match the caller's min_block_size. When a candidate's
start is misaligned, realign it: free the misaligned run and reallocate
exactly @size at the next lower min_block_size boundary. This keeps the
returned size unchanged with no surplus to trim, and rejects the request
only when no aligned candidate fits.
v2: align misaligned candidates down to min_block_size instead of
bailing out, for both the RHS and LHS paths (Matthew).
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/buddy.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "4289531106ee175a6eb45db7d4f2734d1dae9887",
"status": "affected",
"version": "0a1844bf0b532d84324453374ad6845f64066c28",
"versionType": "git"
},
{
"lessThan": "7185c5262435b93e5eeffa647008992256b9c51a",
"status": "affected",
"version": "0a1844bf0b532d84324453374ad6845f64066c28",
"versionType": "git"
},
{
"lessThan": "419d7d9306491f3e0e417cf794844c73cabee090",
"status": "affected",
"version": "0a1844bf0b532d84324453374ad6845f64066c28",
"versionType": "git"
},
{
"lessThan": "56bc6384314fb9ae98975fb2af8b143097ede3dc",
"status": "affected",
"version": "0a1844bf0b532d84324453374ad6845f64066c28",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/buddy.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.7"
},
{
"lessThan": "6.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ngpu/buddy: bail out of try_harder when alignment cannot be honoured\n\nThe try_harder contiguous fallback could return a range whose start\noffset did not match the caller\u0027s min_block_size. When a candidate\u0027s\nstart is misaligned, realign it: free the misaligned run and reallocate\nexactly @size at the next lower min_block_size boundary. This keeps the\nreturned size unchanged with no surplus to trim, and rejects the request\nonly when no aligned candidate fits.\n\nv2: align misaligned candidates down to min_block_size instead of\n bailing out, for both the RHS and LHS paths (Matthew)."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is in gpu_buddy_alloc_blocks() reached only via DRM GEM/TTM VRAM allocation ioctls (e.g. AMDGPU_GEM_CREATE, I915_GEM_CREATE, XE_GEM_CREATE) on /dev/dri/renderD*, requiring a local process with render-node access, not remote network input.\nAC:L - An attacker can deterministically fragment VRAM with many GEM allocations and frees, then request GPU_BUDDY_CONTIGUOUS_ALLOCATION to force __alloc_contig_try_harder; no race or attacker-uncontrollable memory layout is required.\nPR:L - Exploitation needs only standard unprivileged GPU client access to a DRM render node (render/video group membership), not real root or capabilities outside user namespaces; DRM_RENDER_ALLOW ioctls are available to normal desktop, container, and cloud GPU tenants.\nUI:N - No victim interaction is required; the attacker fully controls the allocation pattern and contiguous GEM creation requests needed to reach the vulnerable try_harder fallback path.\nS:U - Impact is cross-process GPU VRAM corruption or disclosure within the same kernel GPU memory authority (e.g. another user\u0027s buffers, page tables), not a VM escape, IOMMU/DMA boundary bypass, or other cross-authority scope change.\nC:H - __alloc_contig_try_harder could return a misaligned or undersized contiguous range versus min_block_size; drivers trust this without post-check, so GPU page tables/DMA can read adjacent VRAM outside the intended buffer, enabling cross-allocation information disclosure.\nI:H - The same misaligned or short contiguous mapping lets GPU hardware write beyond the allocated VRAM window, corrupting neighboring buffers (including page tables) and providing an out-of-bounds write primitive in GPU memory space.\nA:H - Incorrect contiguous VRAM placement can trigger GPU faults, AMDGPU/i915/XE recovery resets, display/compute hangs, and repeated driver-level failures when workloads use the corrupted mapping, causing high availability loss on affected systems."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:41:57.417Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/4289531106ee175a6eb45db7d4f2734d1dae9887"
},
{
"url": "https://git.kernel.org/stable/c/7185c5262435b93e5eeffa647008992256b9c51a"
},
{
"url": "https://git.kernel.org/stable/c/419d7d9306491f3e0e417cf794844c73cabee090"
},
{
"url": "https://git.kernel.org/stable/c/56bc6384314fb9ae98975fb2af8b143097ede3dc"
}
],
"title": "gpu/buddy: bail out of try_harder when alignment cannot be honoured",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72244",
"datePublished": "2026-08-15T05:54:31.866Z",
"dateReserved": "2026-08-09T03:40:39.914Z",
"dateUpdated": "2026-08-17T05:41:57.417Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68403 (GCVE-0-2026-68403)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: brcmfmac: initialize SDIO data work before cleanup
brcmf_sdio_probe() stores the newly allocated bus in sdiodev->bus before
allocating the ordered workqueue. If that allocation fails, the function
jumps to fail and calls brcmf_sdio_remove().
brcmf_sdio_remove() unconditionally cancels bus->datawork. Initialize the
work item before the first failure path that can reach brcmf_sdio_remove(),
so the cleanup path always observes a valid work object.
This issue was found by our static analysis tool and then confirmed by
manual review of the probe error path and the remove-time work drain. The
problem pattern is an early setup failure that reaches a cleanup helper
which cancels an embedded work item before its initializer has run.
A QEMU PoC forced alloc_ordered_workqueue() to fail at the same point in
brcmf_sdio_probe(), before INIT_WORK(&bus->datawork) is reached. The
resulting fail path calls brcmf_sdio_remove(), and DEBUG_OBJECTS reports
the invalid work drain with brcmf_sdio_probe() and brcmf_sdio_remove() in
the stack.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 9982464379e81ece51ced03ebecbbcd34ea367a6 Version: 9982464379e81ece51ced03ebecbbcd34ea367a6 Version: 9982464379e81ece51ced03ebecbbcd34ea367a6 Version: 9982464379e81ece51ced03ebecbbcd34ea367a6 Version: 9982464379e81ece51ced03ebecbbcd34ea367a6 Version: 9982464379e81ece51ced03ebecbbcd34ea367a6 Version: 9982464379e81ece51ced03ebecbbcd34ea367a6 Version: 9982464379e81ece51ced03ebecbbcd34ea367a6 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/broadcom/brcm80211/brcmfmac/sdio.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "860887d22890417d43ef8298f0cc4865e29b54de",
"status": "affected",
"version": "9982464379e81ece51ced03ebecbbcd34ea367a6",
"versionType": "git"
},
{
"lessThan": "9a4be91e5bb032b34cb3c962f6d4f82e7ef09364",
"status": "affected",
"version": "9982464379e81ece51ced03ebecbbcd34ea367a6",
"versionType": "git"
},
{
"lessThan": "fb12c87ae855346321af72e57a93c146205f1090",
"status": "affected",
"version": "9982464379e81ece51ced03ebecbbcd34ea367a6",
"versionType": "git"
},
{
"lessThan": "f50a2b9e57a751e70ae9a272875d80d39eaccd6a",
"status": "affected",
"version": "9982464379e81ece51ced03ebecbbcd34ea367a6",
"versionType": "git"
},
{
"lessThan": "6bd21ec8549a5854dd64204a66289952917a924c",
"status": "affected",
"version": "9982464379e81ece51ced03ebecbbcd34ea367a6",
"versionType": "git"
},
{
"lessThan": "5c342437ea44bb829680ca9e4f683dd5b325b219",
"status": "affected",
"version": "9982464379e81ece51ced03ebecbbcd34ea367a6",
"versionType": "git"
},
{
"lessThan": "c73c3fc1c7ca5a927639f0884624cb244ba791e4",
"status": "affected",
"version": "9982464379e81ece51ced03ebecbbcd34ea367a6",
"versionType": "git"
},
{
"lessThan": "2a665946e0407a05a3f81bd56a08553c446498e0",
"status": "affected",
"version": "9982464379e81ece51ced03ebecbbcd34ea367a6",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/broadcom/brcm80211/brcmfmac/sdio.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.1"
},
{
"lessThan": "4.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: brcmfmac: initialize SDIO data work before cleanup\n\nbrcmf_sdio_probe() stores the newly allocated bus in sdiodev-\u003ebus before\nallocating the ordered workqueue. If that allocation fails, the function\njumps to fail and calls brcmf_sdio_remove().\n\nbrcmf_sdio_remove() unconditionally cancels bus-\u003edatawork. Initialize the\nwork item before the first failure path that can reach brcmf_sdio_remove(),\nso the cleanup path always observes a valid work object.\n\nThis issue was found by our static analysis tool and then confirmed by\nmanual review of the probe error path and the remove-time work drain. The\nproblem pattern is an early setup failure that reaches a cleanup helper\nwhich cancels an embedded work item before its initializer has run.\n\nA QEMU PoC forced alloc_ordered_workqueue() to fail at the same point in\nbrcmf_sdio_probe(), before INIT_WORK(\u0026bus-\u003edatawork) is reached. The\nresulting fail path calls brcmf_sdio_remove(), and DEBUG_OBJECTS reports\nthe invalid work drain with brcmf_sdio_probe() and brcmf_sdio_remove() in\nthe stack."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:54.805Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/860887d22890417d43ef8298f0cc4865e29b54de"
},
{
"url": "https://git.kernel.org/stable/c/9a4be91e5bb032b34cb3c962f6d4f82e7ef09364"
},
{
"url": "https://git.kernel.org/stable/c/fb12c87ae855346321af72e57a93c146205f1090"
},
{
"url": "https://git.kernel.org/stable/c/f50a2b9e57a751e70ae9a272875d80d39eaccd6a"
},
{
"url": "https://git.kernel.org/stable/c/6bd21ec8549a5854dd64204a66289952917a924c"
},
{
"url": "https://git.kernel.org/stable/c/5c342437ea44bb829680ca9e4f683dd5b325b219"
},
{
"url": "https://git.kernel.org/stable/c/c73c3fc1c7ca5a927639f0884624cb244ba791e4"
},
{
"url": "https://git.kernel.org/stable/c/2a665946e0407a05a3f81bd56a08553c446498e0"
}
],
"title": "wifi: brcmfmac: initialize SDIO data work before cleanup",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68403",
"datePublished": "2026-08-10T12:04:23.150Z",
"dateReserved": "2026-07-30T09:28:09.390Z",
"dateUpdated": "2026-08-19T16:34:54.805Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68227 (GCVE-0-2026-68227)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: cx231xx: fix devres lifetime
USB drivers bind to USB interfaces and any device managed resources
should have their lifetime tied to the interface rather than parent USB
device. This avoids issues like memory leaks when drivers are unbound
without their devices being physically disconnected (e.g. on probe
deferral or configuration changes).
Fix the driver state lifetime so that it is released on driver unbind.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 184a82784d50ad82aadc3917a3bdd8314a0e9b9b Version: 184a82784d50ad82aadc3917a3bdd8314a0e9b9b Version: 184a82784d50ad82aadc3917a3bdd8314a0e9b9b Version: 184a82784d50ad82aadc3917a3bdd8314a0e9b9b Version: 184a82784d50ad82aadc3917a3bdd8314a0e9b9b Version: 184a82784d50ad82aadc3917a3bdd8314a0e9b9b Version: 184a82784d50ad82aadc3917a3bdd8314a0e9b9b Version: 184a82784d50ad82aadc3917a3bdd8314a0e9b9b |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/usb/cx231xx/cx231xx-cards.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "1770fc4e2b47b1185e6f688d4012bc91f7543854",
"status": "affected",
"version": "184a82784d50ad82aadc3917a3bdd8314a0e9b9b",
"versionType": "git"
},
{
"lessThan": "c07f535bcdd3f956d4c32085535368f46ba99ba0",
"status": "affected",
"version": "184a82784d50ad82aadc3917a3bdd8314a0e9b9b",
"versionType": "git"
},
{
"lessThan": "0ea4b6fd49f7bed3a7e2b8734c15d9699dabe26f",
"status": "affected",
"version": "184a82784d50ad82aadc3917a3bdd8314a0e9b9b",
"versionType": "git"
},
{
"lessThan": "a373f1a5137e96549a795e7fb9efb5de0ae1d065",
"status": "affected",
"version": "184a82784d50ad82aadc3917a3bdd8314a0e9b9b",
"versionType": "git"
},
{
"lessThan": "c5ccb01eb1107acb6aab8ce8fe5a523f215c837e",
"status": "affected",
"version": "184a82784d50ad82aadc3917a3bdd8314a0e9b9b",
"versionType": "git"
},
{
"lessThan": "f468b7ee5d6332b01e6c538179a4c720e6dae93b",
"status": "affected",
"version": "184a82784d50ad82aadc3917a3bdd8314a0e9b9b",
"versionType": "git"
},
{
"lessThan": "e797e252bfb3d0d4b3d38e4faef817e05869c240",
"status": "affected",
"version": "184a82784d50ad82aadc3917a3bdd8314a0e9b9b",
"versionType": "git"
},
{
"lessThan": "7d6358ab02866e5b7ed8d3a00805297617bbb0ec",
"status": "affected",
"version": "184a82784d50ad82aadc3917a3bdd8314a0e9b9b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/usb/cx231xx/cx231xx-cards.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.17"
},
{
"lessThan": "3.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.17",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: cx231xx: fix devres lifetime\n\nUSB drivers bind to USB interfaces and any device managed resources\nshould have their lifetime tied to the interface rather than parent USB\ndevice. This avoids issues like memory leaks when drivers are unbound\nwithout their devices being physically disconnected (e.g. on probe\ndeferral or configuration changes).\n\nFix the driver state lifetime so that it is released on driver unbind."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:59.091Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/1770fc4e2b47b1185e6f688d4012bc91f7543854"
},
{
"url": "https://git.kernel.org/stable/c/c07f535bcdd3f956d4c32085535368f46ba99ba0"
},
{
"url": "https://git.kernel.org/stable/c/0ea4b6fd49f7bed3a7e2b8734c15d9699dabe26f"
},
{
"url": "https://git.kernel.org/stable/c/a373f1a5137e96549a795e7fb9efb5de0ae1d065"
},
{
"url": "https://git.kernel.org/stable/c/c5ccb01eb1107acb6aab8ce8fe5a523f215c837e"
},
{
"url": "https://git.kernel.org/stable/c/f468b7ee5d6332b01e6c538179a4c720e6dae93b"
},
{
"url": "https://git.kernel.org/stable/c/e797e252bfb3d0d4b3d38e4faef817e05869c240"
},
{
"url": "https://git.kernel.org/stable/c/7d6358ab02866e5b7ed8d3a00805297617bbb0ec"
}
],
"title": "media: cx231xx: fix devres lifetime",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68227",
"datePublished": "2026-08-10T12:00:49.821Z",
"dateReserved": "2026-07-30T09:28:09.376Z",
"dateUpdated": "2026-08-19T16:31:59.091Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68281 (GCVE-0-2026-68281)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-17 05:02
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/imagination: Count paired job fence as dependency in prepare_job()
The DRM scheduler's prepare_job() callback counts the remaining
non-signaled native dependencies for a job, preventing job submission
until those (plus job data and fence update) can fit in the job queue's
CCCB.
This means checking which dependencies can be waited upon in the
firmware, i.e. whether they are backed by a UFO object, i.e. whether
their drm_sched_fence::parent has been assigned to a
pvr_queue_fence::base fence. That happens when the job owning the fence
is submitted to the firmware.
Paired geometry and fragment jobs are submitted at the same time, which
means the dependency between them can't be checked this way before
submission.
Update job_count_remaining_native_deps() to take into account the
dependency between paired jobs.
This fixes cases where prepare_job() underestimated the space left in
an almost full fragment CCCB, wrongly unblocking run_job(), which then
returned early without writing the full sequence of commands to the
CCCB.
The above lead to kernel warnings such as the following and potentially
job timeouts (depending on waiters on the missing commands):
[ 375.702979] WARNING: drivers/gpu/drm/imagination/pvr_cccb.c:178 at pvr_cccb_write_command_with_header+0x2c4/0x330 [powervr], CPU#1: kworker/u16:3/47
[ 375.703160] Modules linked in:
[ 375.703571] CPU: 1 UID: 0 PID: 47 Comm: kworker/u16:3 Tainted: G W 7.0.0-rc2-g817eb6b11ad5 #40 PREEMPT
[ 375.703613] Tainted: [W]=WARN
[ 375.703627] Hardware name: Texas Instruments AM625 SK (DT)
[ 375.703645] Workqueue: powervr-sched drm_sched_run_job_work [gpu_sched]
[ 375.703741] pstate: 80000005 (Nzcv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)
[ 375.703764] pc : pvr_cccb_write_command_with_header+0x2c4/0x330 [powervr]
[ 375.703847] lr : pvr_queue_submit_job_to_cccb+0x578/0xa70 [powervr]
[ 375.703921] sp : ffff800084a97650
[ 375.703934] x29: ffff800084a97740 x28: 0000000000000958 x27: ffff80008565d000
[ 375.703979] x26: 0000000000000030 x25: ffff800084a97680 x24: 0000000000001000
[ 375.704017] x23: ffff800084a97820 x22: 1ffff00010952ecc x21: 0000000000000008
[ 375.704056] x20: 00000000000006a8 x19: ffff00002ff7da88 x18: 0000000000000000
[ 375.704093] x17: 0000000020020000 x16: 0000000000020000 x15: 0000000000000000
[ 375.704132] x14: 0000000000000000 x13: 0000000000000000 x12: 0000000000000000
[ 375.704168] x11: 000000000000f2f2 x10: 00000000f3000000 x9 : 00000000f3f3f3f3
[ 375.704206] x8 : 00000000f2f2f200 x7 : ffff700010952ecc x6 : 0000000000000008
[ 375.704243] x5 : 0000000000000000 x4 : 1ffff00010acba00 x3 : 0000000000000000
[ 375.704279] x2 : 0000000000000007 x1 : 0000000000000fff x0 : 000000000000002f
[ 375.704317] Call trace:
[ 375.704331] pvr_cccb_write_command_with_header+0x2c4/0x330 [powervr] (P)
[ 375.704411] pvr_queue_submit_job_to_cccb+0x578/0xa70 [powervr]
[ 375.704487] pvr_queue_run_job+0x3a4/0x990 [powervr]
[ 375.704562] drm_sched_run_job_work+0x580/0xd48 [gpu_sched]
[ 375.704623] process_one_work+0x520/0x1288
[ 375.704658] worker_thread+0x3f0/0xb3c
[ 375.704680] kthread+0x334/0x3d8
[ 375.704706] ret_from_fork+0x10/0x20
[ 375.704736] ---[ end trace 0000000000000000 ]---
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/imagination/pvr_queue.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "02b0da249c8f78d2bbf9f498bbd371c66142b0af",
"status": "affected",
"version": "eaf01ee5ba28b97f96a3d3eec4c5fbfb37ee4cde",
"versionType": "git"
},
{
"lessThan": "943fa73ea0efa335d9c1800fcfac47915de4ff89",
"status": "affected",
"version": "eaf01ee5ba28b97f96a3d3eec4c5fbfb37ee4cde",
"versionType": "git"
},
{
"lessThan": "a673171502e87acb5a9e2923f4cf9dce521fd05e",
"status": "affected",
"version": "eaf01ee5ba28b97f96a3d3eec4c5fbfb37ee4cde",
"versionType": "git"
},
{
"lessThan": "9cd74f935306cd857f46686975c43383e1d95f94",
"status": "affected",
"version": "eaf01ee5ba28b97f96a3d3eec4c5fbfb37ee4cde",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/imagination/pvr_queue.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.8"
},
{
"lessThan": "6.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/imagination: Count paired job fence as dependency in prepare_job()\n\nThe DRM scheduler\u0027s prepare_job() callback counts the remaining\nnon-signaled native dependencies for a job, preventing job submission\nuntil those (plus job data and fence update) can fit in the job queue\u0027s\nCCCB.\n\nThis means checking which dependencies can be waited upon in the\nfirmware, i.e. whether they are backed by a UFO object, i.e. whether\ntheir drm_sched_fence::parent has been assigned to a\npvr_queue_fence::base fence. That happens when the job owning the fence\nis submitted to the firmware.\n\nPaired geometry and fragment jobs are submitted at the same time, which\nmeans the dependency between them can\u0027t be checked this way before\nsubmission.\n\nUpdate job_count_remaining_native_deps() to take into account the\ndependency between paired jobs.\n\nThis fixes cases where prepare_job() underestimated the space left in\nan almost full fragment CCCB, wrongly unblocking run_job(), which then\nreturned early without writing the full sequence of commands to the\nCCCB.\n\nThe above lead to kernel warnings such as the following and potentially\njob timeouts (depending on waiters on the missing commands):\n\n [ 375.702979] WARNING: drivers/gpu/drm/imagination/pvr_cccb.c:178 at pvr_cccb_write_command_with_header+0x2c4/0x330 [powervr], CPU#1: kworker/u16:3/47\n [ 375.703160] Modules linked in:\n [ 375.703571] CPU: 1 UID: 0 PID: 47 Comm: kworker/u16:3 Tainted: G W 7.0.0-rc2-g817eb6b11ad5 #40 PREEMPT\n [ 375.703613] Tainted: [W]=WARN\n [ 375.703627] Hardware name: Texas Instruments AM625 SK (DT)\n [ 375.703645] Workqueue: powervr-sched drm_sched_run_job_work [gpu_sched]\n [ 375.703741] pstate: 80000005 (Nzcv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n [ 375.703764] pc : pvr_cccb_write_command_with_header+0x2c4/0x330 [powervr]\n [ 375.703847] lr : pvr_queue_submit_job_to_cccb+0x578/0xa70 [powervr]\n [ 375.703921] sp : ffff800084a97650\n [ 375.703934] x29: ffff800084a97740 x28: 0000000000000958 x27: ffff80008565d000\n [ 375.703979] x26: 0000000000000030 x25: ffff800084a97680 x24: 0000000000001000\n [ 375.704017] x23: ffff800084a97820 x22: 1ffff00010952ecc x21: 0000000000000008\n [ 375.704056] x20: 00000000000006a8 x19: ffff00002ff7da88 x18: 0000000000000000\n [ 375.704093] x17: 0000000020020000 x16: 0000000000020000 x15: 0000000000000000\n [ 375.704132] x14: 0000000000000000 x13: 0000000000000000 x12: 0000000000000000\n [ 375.704168] x11: 000000000000f2f2 x10: 00000000f3000000 x9 : 00000000f3f3f3f3\n [ 375.704206] x8 : 00000000f2f2f200 x7 : ffff700010952ecc x6 : 0000000000000008\n [ 375.704243] x5 : 0000000000000000 x4 : 1ffff00010acba00 x3 : 0000000000000000\n [ 375.704279] x2 : 0000000000000007 x1 : 0000000000000fff x0 : 000000000000002f\n [ 375.704317] Call trace:\n [ 375.704331] pvr_cccb_write_command_with_header+0x2c4/0x330 [powervr] (P)\n [ 375.704411] pvr_queue_submit_job_to_cccb+0x578/0xa70 [powervr]\n [ 375.704487] pvr_queue_run_job+0x3a4/0x990 [powervr]\n [ 375.704562] drm_sched_run_job_work+0x580/0xd48 [gpu_sched]\n [ 375.704623] process_one_work+0x520/0x1288\n [ 375.704658] worker_thread+0x3f0/0xb3c\n [ 375.704680] kthread+0x334/0x3d8\n [ 375.704706] ret_from_fork+0x10/0x20\n [ 375.704736] ---[ end trace 0000000000000000 ]---"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:02:15.934Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/02b0da249c8f78d2bbf9f498bbd371c66142b0af"
},
{
"url": "https://git.kernel.org/stable/c/943fa73ea0efa335d9c1800fcfac47915de4ff89"
},
{
"url": "https://git.kernel.org/stable/c/a673171502e87acb5a9e2923f4cf9dce521fd05e"
},
{
"url": "https://git.kernel.org/stable/c/9cd74f935306cd857f46686975c43383e1d95f94"
}
],
"title": "drm/imagination: Count paired job fence as dependency in prepare_job()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68281",
"datePublished": "2026-08-10T12:02:13.103Z",
"dateReserved": "2026-07-30T09:28:09.379Z",
"dateUpdated": "2026-08-17T05:02:15.934Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68354 (GCVE-0-2026-68354)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
firewire: net: Fix fragmented datagram reassembly
fwnet_frag_new() keeps a sorted list of received fragments for a partial
datagram. When a new fragment is adjacent to an existing fragment, the
code checks whether the new fragment also closes the gap to the next or
previous list entry.
Those neighbor lookups currently assume that the current fragment always
has a real next or previous fragment. At a list edge, the next or
previous entry is the list head, not a struct fwnet_fragment_info.
The gap checks also compare against the old edge of the current fragment
instead of the edge after adding the new fragment. As a result, a
fragment that bridges two existing ranges may leave two adjacent ranges
unmerged, so fwnet_pd_is_complete() can miss a complete datagram.
Check for the list head before looking up the neighboring fragment, and
compare the neighbor against the new fragment's far edge when deciding
whether to merge all three ranges.
This issue was found by a static analysis checker and confirmed by
manual source review.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: c76acec6d55107b652a37c90b36c00bc8b04dabb Version: c76acec6d55107b652a37c90b36c00bc8b04dabb Version: c76acec6d55107b652a37c90b36c00bc8b04dabb Version: c76acec6d55107b652a37c90b36c00bc8b04dabb Version: c76acec6d55107b652a37c90b36c00bc8b04dabb Version: c76acec6d55107b652a37c90b36c00bc8b04dabb Version: c76acec6d55107b652a37c90b36c00bc8b04dabb Version: c76acec6d55107b652a37c90b36c00bc8b04dabb |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/firewire/net.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "1aaf16031d65ccd4576451a79f7dabbec994c111",
"status": "affected",
"version": "c76acec6d55107b652a37c90b36c00bc8b04dabb",
"versionType": "git"
},
{
"lessThan": "0a219b2a01b4fe93706717e3bcacf7f62967b26f",
"status": "affected",
"version": "c76acec6d55107b652a37c90b36c00bc8b04dabb",
"versionType": "git"
},
{
"lessThan": "268cea3800eda5fa3ee04a49ee2973b8766a8df3",
"status": "affected",
"version": "c76acec6d55107b652a37c90b36c00bc8b04dabb",
"versionType": "git"
},
{
"lessThan": "b7d633c7c92321be98724b1d365e8ce507f2f349",
"status": "affected",
"version": "c76acec6d55107b652a37c90b36c00bc8b04dabb",
"versionType": "git"
},
{
"lessThan": "22e05b8ddbcf7d22c7f1598786e86635547e554d",
"status": "affected",
"version": "c76acec6d55107b652a37c90b36c00bc8b04dabb",
"versionType": "git"
},
{
"lessThan": "0177e578d7a885037b0fb82286c12e9d0360cc10",
"status": "affected",
"version": "c76acec6d55107b652a37c90b36c00bc8b04dabb",
"versionType": "git"
},
{
"lessThan": "2a5aa4e9b89227d1a1690fb8d5b81e5f3b261999",
"status": "affected",
"version": "c76acec6d55107b652a37c90b36c00bc8b04dabb",
"versionType": "git"
},
{
"lessThan": "d52a13adbb8ccbab99cd3bad36804e87d8b5c052",
"status": "affected",
"version": "c76acec6d55107b652a37c90b36c00bc8b04dabb",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/firewire/net.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.31"
},
{
"lessThan": "2.6.31",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.31",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfirewire: net: Fix fragmented datagram reassembly\n\nfwnet_frag_new() keeps a sorted list of received fragments for a partial\ndatagram. When a new fragment is adjacent to an existing fragment, the\ncode checks whether the new fragment also closes the gap to the next or\nprevious list entry.\n\nThose neighbor lookups currently assume that the current fragment always\nhas a real next or previous fragment. At a list edge, the next or\nprevious entry is the list head, not a struct fwnet_fragment_info.\n\nThe gap checks also compare against the old edge of the current fragment\ninstead of the edge after adding the new fragment. As a result, a\nfragment that bridges two existing ranges may leave two adjacent ranges\nunmerged, so fwnet_pd_is_complete() can miss a complete datagram.\n\nCheck for the list head before looking up the neighboring fragment, and\ncompare the neighbor against the new fragment\u0027s far edge when deciding\nwhether to merge all three ranges.\n\nThis issue was found by a static analysis checker and confirmed by\nmanual source review."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The vulnerable reassembly code processes IP-over-1394 (RFC 2734) fragments arriving from another node on the shared IEEE 1394 bus via fwnet_receive_packet/fwnet_receive_broadcast -\u003e fwnet_incoming_packet -\u003e fwnet_pd_update -\u003e fwnet_frag_new, matching this CNA\u0027s Adjacent shared-physical-segment model for FireWire (CVE-2023-53432, CVE-2024-50113).\nAC:L - The attacker fully controls fg_off, dg_size and fragment ordering (12-bit fields, 0-4095) and can create unlimited fresh partial datagrams, so they can sweep every boundary offset against the aliased pd-\u003eskb bits and groom skb allocation until the type-confused compare matches; once it does, the list-head corruption and misaligned kfree are deterministic, with no attacker-uncontrollable race involved.\nPR:N - fwnet_receive_packet accepts TCODE_WRITE_BLOCK_REQUEST payloads from any bus peer and fwnet_receive_broadcast processes GASP packets automatically, with no credentials, capability check, or authentication anywhere on the path to fwnet_frag_new.\nUI:N - Fragment reassembly runs entirely in FireWire IRQ/softirq context once the firewire-net interface is up; the attacker\u0027s own node supplies the fragments and no victim action such as opening, mounting, or clicking is needed.\nS:U - The corruption is confined to kernel slab objects (fwnet_partial_datagram, sk_buff) under the same kernel security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - list_entry() on the list head reads the low 32 bits of pd-\u003eskb as fragment metadata (a kernel-pointer disclosure primitive), the missed merge lets fwnet_pd_is_complete() hand up an skb whose unwritten gaps contain uninitialized heap data, and the resulting slab freelist corruption from kfree() of an interior pointer yields overlapping objects usable for arbitrary kernel memory read.\nI:H - The prepend branch performs fi2-\u003elen += fi-\u003elen + len directly into bits 16-31 of pd-\u003eskb, giving a partially attacker-influenced write to a kernel pointer that is later passed to dev_kfree_skb_any() (arbitrary free), while the append branch\u0027s kfree() of pd+16 corrupts the SLUB freelist into attacker-groomable overlapping allocations - both classic control-flow-hijack primitives.\nA:H - list_del() on the list head leaves pd-\u003efi_list poisoned, and the immediately following fwnet_pd_is_complete() dereferences LIST_POISON1 in interrupt context while holding dev-\u003elock with IRQs disabled, oopsing or hanging the machine; the misaligned kfree() also trips slab debug BUGs, and a bus peer can repeat the packet flood to crash the system at will."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:00.740Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/1aaf16031d65ccd4576451a79f7dabbec994c111"
},
{
"url": "https://git.kernel.org/stable/c/0a219b2a01b4fe93706717e3bcacf7f62967b26f"
},
{
"url": "https://git.kernel.org/stable/c/268cea3800eda5fa3ee04a49ee2973b8766a8df3"
},
{
"url": "https://git.kernel.org/stable/c/b7d633c7c92321be98724b1d365e8ce507f2f349"
},
{
"url": "https://git.kernel.org/stable/c/22e05b8ddbcf7d22c7f1598786e86635547e554d"
},
{
"url": "https://git.kernel.org/stable/c/0177e578d7a885037b0fb82286c12e9d0360cc10"
},
{
"url": "https://git.kernel.org/stable/c/2a5aa4e9b89227d1a1690fb8d5b81e5f3b261999"
},
{
"url": "https://git.kernel.org/stable/c/d52a13adbb8ccbab99cd3bad36804e87d8b5c052"
}
],
"title": "firewire: net: Fix fragmented datagram reassembly",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68354",
"datePublished": "2026-08-10T12:03:31.348Z",
"dateReserved": "2026-07-30T09:28:09.385Z",
"dateUpdated": "2026-08-19T16:34:00.740Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68178 (GCVE-0-2026-68178)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-17 05:00
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
misc: nsm: pin the module while the device is open
misc_open() installs a misc driver's file operations with fops_get(),
which pins file_operations::owner before replacing the file's f_op. The
NSM misc device leaves nsm_dev_fops.owner unset, so opening /dev/nsm does
not take a module reference on the nsm driver.
If the driver is built as a module, an open file descriptor can therefore
survive rmmod of the module that provides its ioctl callbacks. A later
ioctl through that descriptor can call into unloaded module text.
Set nsm_dev_fops.owner to THIS_MODULE so the misc core holds the module
while any /dev/nsm file descriptor is open, matching the lifetime
expectation for the installed file operations.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/misc/nsm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "1996639f824ce9468395cdb7bcb8f467fa787e77",
"status": "affected",
"version": "b9873755a6c8ccfce79094c4dce9efa3ecb1a749",
"versionType": "git"
},
{
"lessThan": "1da310b94504d42001e9c32c43c5dc105b777e5f",
"status": "affected",
"version": "b9873755a6c8ccfce79094c4dce9efa3ecb1a749",
"versionType": "git"
},
{
"lessThan": "9e9a82d00c3d10129fc310a7547b24a679d5d920",
"status": "affected",
"version": "b9873755a6c8ccfce79094c4dce9efa3ecb1a749",
"versionType": "git"
},
{
"lessThan": "3b231f1e9990f4c21220d0a69733ce2105891ff9",
"status": "affected",
"version": "b9873755a6c8ccfce79094c4dce9efa3ecb1a749",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/misc/nsm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.8"
},
{
"lessThan": "6.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmisc: nsm: pin the module while the device is open\n\nmisc_open() installs a misc driver\u0027s file operations with fops_get(),\nwhich pins file_operations::owner before replacing the file\u0027s f_op. The\nNSM misc device leaves nsm_dev_fops.owner unset, so opening /dev/nsm does\nnot take a module reference on the nsm driver.\n\nIf the driver is built as a module, an open file descriptor can therefore\nsurvive rmmod of the module that provides its ioctl callbacks. A later\nioctl through that descriptor can call into unloaded module text.\n\nSet nsm_dev_fops.owner to THIS_MODULE so the misc core holds the module\nwhile any /dev/nsm file descriptor is open, matching the lifetime\nexpectation for the installed file operations."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached only via local open()/ioctl syscalls on /dev/nsm (misc_open through vfs_ioctl to nsm_dev_ioctl); the Nitro Secure Module virtio driver has no network, adjacent-wireless, or physical attack surface.\nAC:L - When CONFIG_NSM=m the attacker controls the full sequence: open /dev/nsm to install fops, delete_module(\"nsm\") while fops_get(NULL) leaves the module unpinned, then ioctl on the stale fd to call unloaded text without races or external timing.\nPR:L - /dev/nsm is registered mode 0666 with no capable() checks in nsm_dev_ioctl, so any local process can open and ioctl; unloading the module needs CAP_SYS_MODULE, treated as low-privilege local capability per similar module-lifetime UAF scoring on permissive/user-namespace kernels.\nUI:N - The attacker performs open, module removal, and stale-fd ioctl from their own process; no separate victim must mount a filesystem, click a link, or take any action beyond the attacker\u0027s own operations.\nS:U - The use-after-free corrupts guest kernel memory and executes in kernel context within the Nitro Enclave; impact does not cross hypervisor, parent-instance, VM, or IOMMU security boundaries.\nC:H - Stale ioctl calls into freed module text and file_to_nsm() dereferences freed devm nsm state, exposing reclaimed kernel/module memory and adjacent virtio message buffers through the UAF window.\nI:H - Dispatching nsm_dev_ioctl through freed vmalloc module text is a kernel use-after-free that can be shaped with heap spraying to hijack control flow and achieve arbitrary kernel code execution.\nA:H - Executing code from an unloaded module or dereferencing freed nsm/virtqueue state on ioctl reliably causes kernel oops or panic, and the attacker can repeat the stale-fd ioctl to deny service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:00:19.564Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/1996639f824ce9468395cdb7bcb8f467fa787e77"
},
{
"url": "https://git.kernel.org/stable/c/1da310b94504d42001e9c32c43c5dc105b777e5f"
},
{
"url": "https://git.kernel.org/stable/c/9e9a82d00c3d10129fc310a7547b24a679d5d920"
},
{
"url": "https://git.kernel.org/stable/c/3b231f1e9990f4c21220d0a69733ce2105891ff9"
}
],
"title": "misc: nsm: pin the module while the device is open",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68178",
"datePublished": "2026-08-10T11:59:49.344Z",
"dateReserved": "2026-07-30T09:28:09.373Z",
"dateUpdated": "2026-08-17T05:00:19.564Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68360 (GCVE-0-2026-68360)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop
Calling hid_hw_stop() does not stop the device IO.
This results in a race condition between hid_input_report() and the point
immediately following the execution of hid_device_io_start() within
the driver probe function. If the probe operation fails after "io start"
has been initiated, this race condition will result in a UAF vulnerability.
Fix the problem by calling hid_device_io_stop() before calling
hid_hw_stop().
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 40c3a445422579db8ad96c234dbe6c0ab3f6b936 Version: 40c3a445422579db8ad96c234dbe6c0ab3f6b936 Version: 40c3a445422579db8ad96c234dbe6c0ab3f6b936 Version: 40c3a445422579db8ad96c234dbe6c0ab3f6b936 Version: 40c3a445422579db8ad96c234dbe6c0ab3f6b936 Version: 40c3a445422579db8ad96c234dbe6c0ab3f6b936 Version: 40c3a445422579db8ad96c234dbe6c0ab3f6b936 Version: 40c3a445422579db8ad96c234dbe6c0ab3f6b936 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/hwmon/corsair-cpro.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "3df2b67793babbea7951b5f601d6df891c63b5d8",
"status": "affected",
"version": "40c3a445422579db8ad96c234dbe6c0ab3f6b936",
"versionType": "git"
},
{
"lessThan": "5e07f292ab5591bf4f588aa7abd22ec86c25d076",
"status": "affected",
"version": "40c3a445422579db8ad96c234dbe6c0ab3f6b936",
"versionType": "git"
},
{
"lessThan": "6c5f31fdf28455a7fd573bda452c80b7b6700247",
"status": "affected",
"version": "40c3a445422579db8ad96c234dbe6c0ab3f6b936",
"versionType": "git"
},
{
"lessThan": "0975c42ed2a3bf32125a920e5d19194289126210",
"status": "affected",
"version": "40c3a445422579db8ad96c234dbe6c0ab3f6b936",
"versionType": "git"
},
{
"lessThan": "c7757db58957ac20cdec6ce575dbd44a6375664e",
"status": "affected",
"version": "40c3a445422579db8ad96c234dbe6c0ab3f6b936",
"versionType": "git"
},
{
"lessThan": "56d2deb6448378118dbe68c4fbb3fbae5f65b18c",
"status": "affected",
"version": "40c3a445422579db8ad96c234dbe6c0ab3f6b936",
"versionType": "git"
},
{
"lessThan": "1a634f464d6153dfa4d7e73a3d78236b65a64ee9",
"status": "affected",
"version": "40c3a445422579db8ad96c234dbe6c0ab3f6b936",
"versionType": "git"
},
{
"lessThan": "94c87871b051d7ad758828a805215a2ec194512a",
"status": "affected",
"version": "40c3a445422579db8ad96c234dbe6c0ab3f6b936",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/hwmon/corsair-cpro.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.9"
},
{
"lessThan": "5.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop\n\nCalling hid_hw_stop() does not stop the device IO.\nThis results in a race condition between hid_input_report() and the point\nimmediately following the execution of hid_device_io_start() within\nthe driver probe function. If the probe operation fails after \"io start\"\nhas been initiated, this race condition will result in a UAF vulnerability.\n\nFix the problem by calling hid_device_io_stop() before calling\nhid_hw_stop()."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:10.569Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/3df2b67793babbea7951b5f601d6df891c63b5d8"
},
{
"url": "https://git.kernel.org/stable/c/5e07f292ab5591bf4f588aa7abd22ec86c25d076"
},
{
"url": "https://git.kernel.org/stable/c/6c5f31fdf28455a7fd573bda452c80b7b6700247"
},
{
"url": "https://git.kernel.org/stable/c/0975c42ed2a3bf32125a920e5d19194289126210"
},
{
"url": "https://git.kernel.org/stable/c/c7757db58957ac20cdec6ce575dbd44a6375664e"
},
{
"url": "https://git.kernel.org/stable/c/56d2deb6448378118dbe68c4fbb3fbae5f65b18c"
},
{
"url": "https://git.kernel.org/stable/c/1a634f464d6153dfa4d7e73a3d78236b65a64ee9"
},
{
"url": "https://git.kernel.org/stable/c/94c87871b051d7ad758828a805215a2ec194512a"
}
],
"title": "hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68360",
"datePublished": "2026-08-10T12:03:37.298Z",
"dateReserved": "2026-07-30T09:28:09.385Z",
"dateUpdated": "2026-08-19T16:34:10.569Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68140 (GCVE-0-2026-68140)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/iucv: fix use-after-free of a severed iucv_path
af_iucv queues not-yet-received message notifications on iucv->message_q,
each holding a raw pointer to the connection's iucv_path. When the peer
severs the connection, iucv_sever_path() frees that path with
iucv_path_free() but leaves the notifications queued. A later recvmsg()
drains message_q via iucv_process_message_q() and hands the stale path to
message_receive() -- a use-after-free of the freed iucv_path.
Drop the queued notifications when the path is severed; once the path is
gone they can no longer be received. This also frees the notifications
leaked when a socket is closed with messages still queued.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: f0703c80e5156406ad947cb67fe277725b48080f Version: f0703c80e5156406ad947cb67fe277725b48080f Version: f0703c80e5156406ad947cb67fe277725b48080f Version: f0703c80e5156406ad947cb67fe277725b48080f Version: f0703c80e5156406ad947cb67fe277725b48080f Version: f0703c80e5156406ad947cb67fe277725b48080f Version: f0703c80e5156406ad947cb67fe277725b48080f Version: f0703c80e5156406ad947cb67fe277725b48080f |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/iucv/af_iucv.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "5f08c5e50bcb4680069bd3f9edd5728308816ded",
"status": "affected",
"version": "f0703c80e5156406ad947cb67fe277725b48080f",
"versionType": "git"
},
{
"lessThan": "c24faf11bd31bfe0500aca12cbdd5a573a954a5d",
"status": "affected",
"version": "f0703c80e5156406ad947cb67fe277725b48080f",
"versionType": "git"
},
{
"lessThan": "99ddb33748698296a6f17b9b34aa3d16a406bb3c",
"status": "affected",
"version": "f0703c80e5156406ad947cb67fe277725b48080f",
"versionType": "git"
},
{
"lessThan": "23658b350b4107e8292045c2044983fd426fa15d",
"status": "affected",
"version": "f0703c80e5156406ad947cb67fe277725b48080f",
"versionType": "git"
},
{
"lessThan": "a5bbaddf69853117f28173c3f5c8fc14c6b2ec82",
"status": "affected",
"version": "f0703c80e5156406ad947cb67fe277725b48080f",
"versionType": "git"
},
{
"lessThan": "900cd6d8119b7f3ae5c4bf82f922ff5957df43db",
"status": "affected",
"version": "f0703c80e5156406ad947cb67fe277725b48080f",
"versionType": "git"
},
{
"lessThan": "f579582c03ed526281a8450159baf1d35099a85f",
"status": "affected",
"version": "f0703c80e5156406ad947cb67fe277725b48080f",
"versionType": "git"
},
{
"lessThan": "be7cc4656eb1f54029610e82d1f0fdd3f9b5ec0a",
"status": "affected",
"version": "f0703c80e5156406ad947cb67fe277725b48080f",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/iucv/af_iucv.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.24"
},
{
"lessThan": "2.6.24",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.24",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/iucv: fix use-after-free of a severed iucv_path\n\naf_iucv queues not-yet-received message notifications on iucv-\u003emessage_q,\neach holding a raw pointer to the connection\u0027s iucv_path. When the peer\nsevers the connection, iucv_sever_path() frees that path with\niucv_path_free() but leaves the notifications queued. A later recvmsg()\ndrains message_q via iucv_process_message_q() and hands the stale path to\nmessage_receive() -- a use-after-free of the freed iucv_path.\n\nDrop the queued notifications when the path is severed; once the path is\ngone they can no longer be received. This also frees the notifications\nleaked when a socket is closed with messages still queued."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - An adjacent z/VM guest or LPAR peer can establish an AF_IUCV connection and deliver IUCV message_pending and path_severed events to a victim; exploitation requires same-CPC IUCV reachability, not Internet-wide access.\nAC:L - The attacker deterministically floods IUCV messages to fill message_q, severs the connection to free iucv_path, then victim recvmsg() drains the stale queue; no uncontrollable timing or memory-layout luck is required.\nPR:N - On the victim, no local Linux account or capability is needed; any unauthorized adjacent IUCV peer that completes the AF_IUCV handshake can flood messages and sever the path against a listening service.\nUI:N - No special victim action is required beyond normal server recvmsg() on an established IUCV session; the attacker drives connection setup, message flood, and path sever entirely from the peer side.\nS:U - Impact is kernel memory corruption within the victim Linux guest; it does not cross hypervisor, VM-escape, or IOMMU security boundaries.\nC:H - Queued notifications dereference a freed struct iucv_path in message_receive(), passing stale pathid and private fields into CP IUCV RECEIVE calls\u2014a classic UAF enabling attacker-controlled heap reuse and kernel memory disclosure.\nI:H - Use-after-free of iucv_path lets an attacker reclaim the freed object and supply forged pathid and list pointers used by __iucv_message_receive(), providing heap corruption primitives suitable for arbitrary kernel write or code execution.\nA:H - Processing the stale path in iucv_process_message_q() dereferences freed kernel memory during message_receive(), reliably causing kernel oops or panic and total loss of availability even before full exploitation."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:29:57.127Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/5f08c5e50bcb4680069bd3f9edd5728308816ded"
},
{
"url": "https://git.kernel.org/stable/c/c24faf11bd31bfe0500aca12cbdd5a573a954a5d"
},
{
"url": "https://git.kernel.org/stable/c/99ddb33748698296a6f17b9b34aa3d16a406bb3c"
},
{
"url": "https://git.kernel.org/stable/c/23658b350b4107e8292045c2044983fd426fa15d"
},
{
"url": "https://git.kernel.org/stable/c/a5bbaddf69853117f28173c3f5c8fc14c6b2ec82"
},
{
"url": "https://git.kernel.org/stable/c/900cd6d8119b7f3ae5c4bf82f922ff5957df43db"
},
{
"url": "https://git.kernel.org/stable/c/f579582c03ed526281a8450159baf1d35099a85f"
},
{
"url": "https://git.kernel.org/stable/c/be7cc4656eb1f54029610e82d1f0fdd3f9b5ec0a"
}
],
"title": "net/iucv: fix use-after-free of a severed iucv_path",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68140",
"datePublished": "2026-08-10T11:59:03.761Z",
"dateReserved": "2026-07-30T09:28:09.370Z",
"dateUpdated": "2026-08-19T16:29:57.127Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68301 (GCVE-0-2026-68301)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-19 16:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: hsr: fix memory leak on slave unregistration by removing synced VLANs
When an HSR master device is brought UP, it auto-adds VLAN 0 via
vlan_vid0_add(), which propagates VID 0 to its slave devices (slave A and B).
If a slave device is later unregistered while HSR is active (e.g., during
netns cleanup or interface destruction), hsr_del_port() is called to
detach the slave port from the HSR master. However, hsr_del_port() currently
does not delete the VLAN IDs that were synced to the slave device by HSR.
As a result, the slave device retains a refcount on VID 0 (and any other
synced VLANs). When the slave device is destroyed, its vlan_info /
vlan_vid_info structure remains allocated, leading to a memory leak.
Fix this by calling vlan_vids_del_by_dev(port->dev, master->dev) in
hsr_del_port() before unlinking slave A or slave B ports, matching the
propagation logic in hsr_ndo_vlan_rx_add_vid() / hsr_ndo_vlan_rx_kill_vid()
and the cleanup behavior in bonding and team drivers.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1100242709d5644856131a9dd25d32672ebe7357 Version: a2accc07bdcfb0c7ab2cacdca6a1fe8267816efa Version: 72dbae1f2f2159395089405c6c54632f2613f1be Version: c707d2c5541d2bb94131968ad5dfeb06427a1dba Version: 1a8a63a5305e95519de6f941922dfcd8179f82e5 Version: 1a8a63a5305e95519de6f941922dfcd8179f82e5 Version: 1a8a63a5305e95519de6f941922dfcd8179f82e5 Version: 5.15.194 ≤ Version: 6.1.153 ≤ Version: 6.6.107 ≤ Version: 6.12.48 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/hsr/hsr_slave.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ccc822e9e4f09a6c2ca73ad5334570441947f94f",
"status": "affected",
"version": "1100242709d5644856131a9dd25d32672ebe7357",
"versionType": "git"
},
{
"lessThan": "79ff0547676acdeceda445c3fce4071b0a887b70",
"status": "affected",
"version": "a2accc07bdcfb0c7ab2cacdca6a1fe8267816efa",
"versionType": "git"
},
{
"lessThan": "f72c312af6c7897ab0f8a2b5a63f917a207a4143",
"status": "affected",
"version": "72dbae1f2f2159395089405c6c54632f2613f1be",
"versionType": "git"
},
{
"lessThan": "21d48408479a17eb65568a765930adea37e4d804",
"status": "affected",
"version": "c707d2c5541d2bb94131968ad5dfeb06427a1dba",
"versionType": "git"
},
{
"lessThan": "b5ded444621b6180df9f3d4e07045fc1fc1e8cd9",
"status": "affected",
"version": "1a8a63a5305e95519de6f941922dfcd8179f82e5",
"versionType": "git"
},
{
"lessThan": "ae995b8002d3af134560a706c0e111a89e26317c",
"status": "affected",
"version": "1a8a63a5305e95519de6f941922dfcd8179f82e5",
"versionType": "git"
},
{
"lessThan": "dcf15eaf5641812f1cfc5e96537380132a7da89d",
"status": "affected",
"version": "1a8a63a5305e95519de6f941922dfcd8179f82e5",
"versionType": "git"
},
{
"lessThan": "5.15.216",
"status": "affected",
"version": "5.15.194",
"versionType": "semver"
},
{
"lessThan": "6.1.183",
"status": "affected",
"version": "6.1.153",
"versionType": "semver"
},
{
"lessThan": "6.6.148",
"status": "affected",
"version": "6.6.107",
"versionType": "semver"
},
{
"lessThan": "6.12.101",
"status": "affected",
"version": "6.12.48",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/hsr/hsr_slave.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.13"
},
{
"lessThan": "6.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.15.194",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "6.1.153",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.6.107",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.12.48",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: hsr: fix memory leak on slave unregistration by removing synced VLANs\n\nWhen an HSR master device is brought UP, it auto-adds VLAN 0 via\nvlan_vid0_add(), which propagates VID 0 to its slave devices (slave A and B).\n\nIf a slave device is later unregistered while HSR is active (e.g., during\nnetns cleanup or interface destruction), hsr_del_port() is called to\ndetach the slave port from the HSR master. However, hsr_del_port() currently\ndoes not delete the VLAN IDs that were synced to the slave device by HSR.\n\nAs a result, the slave device retains a refcount on VID 0 (and any other\nsynced VLANs). When the slave device is destroyed, its vlan_info /\nvlan_vid_info structure remains allocated, leading to a memory leak.\n\nFix this by calling vlan_vids_del_by_dev(port-\u003edev, master-\u003edev) in\nhsr_del_port() before unlinking slave A or slave B ports, matching the\npropagation logic in hsr_ndo_vlan_rx_add_vid() / hsr_ndo_vlan_rx_kill_vid()\nand the cleanup behavior in bonding and team drivers."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:32:53.463Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ccc822e9e4f09a6c2ca73ad5334570441947f94f"
},
{
"url": "https://git.kernel.org/stable/c/79ff0547676acdeceda445c3fce4071b0a887b70"
},
{
"url": "https://git.kernel.org/stable/c/f72c312af6c7897ab0f8a2b5a63f917a207a4143"
},
{
"url": "https://git.kernel.org/stable/c/21d48408479a17eb65568a765930adea37e4d804"
},
{
"url": "https://git.kernel.org/stable/c/b5ded444621b6180df9f3d4e07045fc1fc1e8cd9"
},
{
"url": "https://git.kernel.org/stable/c/ae995b8002d3af134560a706c0e111a89e26317c"
},
{
"url": "https://git.kernel.org/stable/c/dcf15eaf5641812f1cfc5e96537380132a7da89d"
}
],
"title": "net: hsr: fix memory leak on slave unregistration by removing synced VLANs",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68301",
"datePublished": "2026-08-10T12:02:35.155Z",
"dateReserved": "2026-07-30T09:28:09.380Z",
"dateUpdated": "2026-08-19T16:32:53.463Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68444 (GCVE-0-2026-68444)
Vulnerability from cvelistv5
Published
2026-08-12 00:07
Modified
2026-08-19 16:35
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
firmware: arm_ffa: Fix NULL dereference in ffa_partition_info_get()
ffa_partition_info_get() passes uuid_str directly to uuid_parse()
without a NULL check. When a caller passes NULL, uuid_parse() ->
__uuid_parse() -> uuid_is_valid() dereferences the pointer, causing
a kernel panic:
| Unable to handle kernel NULL pointer dereference at virtual address
| 0000000000000040
| pc : uuid_parse+0x40/0xac
| lr : ffa_partition_info_get+0x1c/0x94 [arm_ffa]
Add a NULL guard before uuid_parse() so a NULL argument returns
-ENODEV instead of crashing. Callers are expected to always supply
a valid partition UUID, so NULL is not a supported input.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d0c0bce831223b08e5bade2cefc93c3ddb790796 Version: d0c0bce831223b08e5bade2cefc93c3ddb790796 Version: d0c0bce831223b08e5bade2cefc93c3ddb790796 Version: d0c0bce831223b08e5bade2cefc93c3ddb790796 Version: d0c0bce831223b08e5bade2cefc93c3ddb790796 Version: d0c0bce831223b08e5bade2cefc93c3ddb790796 Version: d0c0bce831223b08e5bade2cefc93c3ddb790796 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/firmware/arm_ffa/driver.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "7dfb020e3048411fbca91e9ad6174da9a2d3e2b3",
"status": "affected",
"version": "d0c0bce831223b08e5bade2cefc93c3ddb790796",
"versionType": "git"
},
{
"lessThan": "ddf85f0c32e05baafbd9c3a44859858db90eec48",
"status": "affected",
"version": "d0c0bce831223b08e5bade2cefc93c3ddb790796",
"versionType": "git"
},
{
"lessThan": "86f5ea90f73bb7154593bb96f3411e197f3d4fbe",
"status": "affected",
"version": "d0c0bce831223b08e5bade2cefc93c3ddb790796",
"versionType": "git"
},
{
"lessThan": "7201e56e52d18abf4cd0a2fee45daf9dc08b5b97",
"status": "affected",
"version": "d0c0bce831223b08e5bade2cefc93c3ddb790796",
"versionType": "git"
},
{
"lessThan": "996c5c19d5b5ac5b98a7b5a406b548305841c301",
"status": "affected",
"version": "d0c0bce831223b08e5bade2cefc93c3ddb790796",
"versionType": "git"
},
{
"lessThan": "12a42c610e4432e7708cc48d607e5903fffe0aad",
"status": "affected",
"version": "d0c0bce831223b08e5bade2cefc93c3ddb790796",
"versionType": "git"
},
{
"lessThan": "8ae5f8e4836667fcaffdf2e3c6068b0a8b364dd8",
"status": "affected",
"version": "d0c0bce831223b08e5bade2cefc93c3ddb790796",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/firmware/arm_ffa/driver.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.14"
},
{
"lessThan": "5.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: arm_ffa: Fix NULL dereference in ffa_partition_info_get()\n\nffa_partition_info_get() passes uuid_str directly to uuid_parse()\nwithout a NULL check. When a caller passes NULL, uuid_parse() -\u003e\n__uuid_parse() -\u003e uuid_is_valid() dereferences the pointer, causing\na kernel panic:\n\n | Unable to handle kernel NULL pointer dereference at virtual address\n | 0000000000000040\n | pc : uuid_parse+0x40/0xac\n | lr : ffa_partition_info_get+0x1c/0x94 [arm_ffa]\n\nAdd a NULL guard before uuid_parse() so a NULL argument returns\n-ENODEV instead of crashing. Callers are expected to always supply\na valid partition UUID, so NULL is not a supported input."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:35:38.125Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/7dfb020e3048411fbca91e9ad6174da9a2d3e2b3"
},
{
"url": "https://git.kernel.org/stable/c/ddf85f0c32e05baafbd9c3a44859858db90eec48"
},
{
"url": "https://git.kernel.org/stable/c/86f5ea90f73bb7154593bb96f3411e197f3d4fbe"
},
{
"url": "https://git.kernel.org/stable/c/7201e56e52d18abf4cd0a2fee45daf9dc08b5b97"
},
{
"url": "https://git.kernel.org/stable/c/996c5c19d5b5ac5b98a7b5a406b548305841c301"
},
{
"url": "https://git.kernel.org/stable/c/12a42c610e4432e7708cc48d607e5903fffe0aad"
},
{
"url": "https://git.kernel.org/stable/c/8ae5f8e4836667fcaffdf2e3c6068b0a8b364dd8"
}
],
"title": "firmware: arm_ffa: Fix NULL dereference in ffa_partition_info_get()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68444",
"datePublished": "2026-08-12T00:07:34.609Z",
"dateReserved": "2026-07-30T09:28:09.394Z",
"dateUpdated": "2026-08-19T16:35:38.125Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64564 (GCVE-0-2026-64564)
Vulnerability from cvelistv5
Published
2026-08-04 06:23
Modified
2026-08-19 16:28
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
sctp: don't free the ASCONF's own transport in DEL-IP processing
sctp_process_asconf() caches the transport the ASCONF chunk is processed
against in asconf->transport (== chunk->transport, set once in sctp_rcv()).
For an ASCONF located through its Address Parameter by
__sctp_rcv_asconf_lookup(), that cached transport corresponds to the
Address Parameter, which need not be the packet's source address.
sctp_process_asconf_param() rejects a DEL-IP for the packet source address
(ADDIP D8, SCTP_ERROR_DEL_SRC_IP), but nothing protects asconf->transport.
A single ASCONF can therefore carry, in order:
[Address Parameter L] [DEL-IP L] [DEL-IP 0.0.0.0]
where L differs from the source. The DEL-IP for L passes the D8 check and
calls sctp_assoc_rm_peer() on the transport that asconf->transport still
points at, freeing it (RCU-deferred). The following wildcard DEL-IP then
reuses the now-dangling asconf->transport in sctp_assoc_set_primary() and
sctp_assoc_del_nonprimary_peers(): set_primary() dereferences the freed
transport (->ipaddr, ->state) and plants the dangling pointer into
asoc->peer.primary_path / active_path, and del_nonprimary_peers(), keeping
only the pointer that is no longer on the list, removes every real
transport, leaving the association with a transport_count of 0 and
primary_path/active_path pointing at freed memory.
Reject a DEL-IP that targets the transport the ASCONF is being processed
against, mirroring the existing source-address guard, so the wildcard
branch can never reuse a freed transport.
References
| URL | Tags | ||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 42e30bf3463cd37d73839376662cb79b4d5c416c Version: 42e30bf3463cd37d73839376662cb79b4d5c416c Version: 42e30bf3463cd37d73839376662cb79b4d5c416c Version: 42e30bf3463cd37d73839376662cb79b4d5c416c Version: 42e30bf3463cd37d73839376662cb79b4d5c416c Version: 42e30bf3463cd37d73839376662cb79b4d5c416c Version: 42e30bf3463cd37d73839376662cb79b4d5c416c Version: 42e30bf3463cd37d73839376662cb79b4d5c416c |
||
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2026-08-08T01:31:36.501Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"url": "http://www.openwall.com/lists/oss-security/2026/08/06/3"
},
{
"url": "http://www.openwall.com/lists/oss-security/2026/08/06/4"
},
{
"url": "http://www.openwall.com/lists/oss-security/2026/08/06/13"
},
{
"url": "http://www.openwall.com/lists/oss-security/2026/08/07/1"
},
{
"url": "http://www.openwall.com/lists/oss-security/2026/08/07/2"
},
{
"url": "http://www.openwall.com/lists/oss-security/2026/08/07/8"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/sctp/sm_make_chunk.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a9ce31be4cb1a5dd82b3e0a1d0c3e7cbdcd31293",
"status": "affected",
"version": "42e30bf3463cd37d73839376662cb79b4d5c416c",
"versionType": "git"
},
{
"lessThan": "a63afa1f9b12d5293cbe0b77fd45dc0632533a13",
"status": "affected",
"version": "42e30bf3463cd37d73839376662cb79b4d5c416c",
"versionType": "git"
},
{
"lessThan": "2b324ba3494ae958cba16a453e3e71489b4de7fc",
"status": "affected",
"version": "42e30bf3463cd37d73839376662cb79b4d5c416c",
"versionType": "git"
},
{
"lessThan": "fedeb4468987bcaff85fe3061de5ae052d414740",
"status": "affected",
"version": "42e30bf3463cd37d73839376662cb79b4d5c416c",
"versionType": "git"
},
{
"lessThan": "74e8f3e7114f0e26d1b2c4c048044db9fcc27603",
"status": "affected",
"version": "42e30bf3463cd37d73839376662cb79b4d5c416c",
"versionType": "git"
},
{
"lessThan": "85aca407c560aba81b5ce9d3d6cf94c74077d19b",
"status": "affected",
"version": "42e30bf3463cd37d73839376662cb79b4d5c416c",
"versionType": "git"
},
{
"lessThan": "d136b29bf91dd8e3161281b87de597b7311d9462",
"status": "affected",
"version": "42e30bf3463cd37d73839376662cb79b4d5c416c",
"versionType": "git"
},
{
"lessThan": "9b2854f86f0b56e9027d68e7a3fc909d1a9b566f",
"status": "affected",
"version": "42e30bf3463cd37d73839376662cb79b4d5c416c",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/sctp/sm_make_chunk.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.25"
},
{
"lessThan": "2.6.25",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.25",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: don\u0027t free the ASCONF\u0027s own transport in DEL-IP processing\n\nsctp_process_asconf() caches the transport the ASCONF chunk is processed\nagainst in asconf-\u003etransport (== chunk-\u003etransport, set once in sctp_rcv()).\nFor an ASCONF located through its Address Parameter by\n__sctp_rcv_asconf_lookup(), that cached transport corresponds to the\nAddress Parameter, which need not be the packet\u0027s source address.\n\nsctp_process_asconf_param() rejects a DEL-IP for the packet source address\n(ADDIP D8, SCTP_ERROR_DEL_SRC_IP), but nothing protects asconf-\u003etransport.\nA single ASCONF can therefore carry, in order:\n\n [Address Parameter L] [DEL-IP L] [DEL-IP 0.0.0.0]\n\nwhere L differs from the source. The DEL-IP for L passes the D8 check and\ncalls sctp_assoc_rm_peer() on the transport that asconf-\u003etransport still\npoints at, freeing it (RCU-deferred). The following wildcard DEL-IP then\nreuses the now-dangling asconf-\u003etransport in sctp_assoc_set_primary() and\nsctp_assoc_del_nonprimary_peers(): set_primary() dereferences the freed\ntransport (-\u003eipaddr, -\u003estate) and plants the dangling pointer into\nasoc-\u003epeer.primary_path / active_path, and del_nonprimary_peers(), keeping\nonly the pointer that is no longer on the list, removes every real\ntransport, leaving the association with a transport_count of 0 and\nprimary_path/active_path pointing at freed memory.\n\nReject a DEL-IP that targets the transport the ASCONF is being processed\nagainst, mirroring the existing source-address guard, so the wildcard\nbranch can never reuse a freed transport."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug is in SCTP ASCONF receive processing (sctp_rcv \u2192 sctp_sf_do_asconf \u2192 sctp_process_asconf \u2192 sctp_process_asconf_param); a remote peer triggers it by sending a crafted ASCONF over IP/IPv6 on an established association, matching kernel guidance that net/ stack bugs reachable via received packets are Network.\nAC:L - A single attacker-controlled ASCONF with [Address Parameter L][DEL-IP L][DEL-IP 0.0.0.0] reliably frees asconf-\u003etransport then reuses it in the same softirq; the peer fully controls multi-homing, serial, and parameter order, with no race or other condition outside attacker influence.\nPR:N - Any remote SCTP peer that completes a normal association with ADD-IP negotiated can send the ASCONF; SCTP-AUTH keys come from the handshake the peer itself performs (or addip_noauth), and no local credentials or capabilities on the target are required.\nUI:N - Exploitation requires only attacker-sent SCTP packets processed automatically in the receive/state-machine path; no victim user action such as opening a file or mounting a device is needed.\nS:U - Impact is confined to the vulnerable host kernel (sctp_transport UAF / crash or privilege escalation) and does not cross a VM, IOMMU, or other security-authority boundary.\nC:H - This is a heap use-after-free of an sctp_transport planted into primary_path/active_path after RCU-deferred free; freed-object reuse yields arbitrary kernel read primitives, scored High per UAF guidance.\nI:H - The same transport UAF enables heap spraying and write/control-flow hijacking via later dereferences of the dangling primary_path/active_path, so integrity impact is High.\nA:H - set_primary() immediately dereferences the freed transport and leaves the association with transport_count 0 and dangling path pointers, causing a reproducible kernel oops/panic on subsequent use, which is High availability impact."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:28:36.947Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a9ce31be4cb1a5dd82b3e0a1d0c3e7cbdcd31293"
},
{
"url": "https://git.kernel.org/stable/c/a63afa1f9b12d5293cbe0b77fd45dc0632533a13"
},
{
"url": "https://git.kernel.org/stable/c/2b324ba3494ae958cba16a453e3e71489b4de7fc"
},
{
"url": "https://git.kernel.org/stable/c/fedeb4468987bcaff85fe3061de5ae052d414740"
},
{
"url": "https://git.kernel.org/stable/c/74e8f3e7114f0e26d1b2c4c048044db9fcc27603"
},
{
"url": "https://git.kernel.org/stable/c/85aca407c560aba81b5ce9d3d6cf94c74077d19b"
},
{
"url": "https://git.kernel.org/stable/c/d136b29bf91dd8e3161281b87de597b7311d9462"
},
{
"url": "https://git.kernel.org/stable/c/9b2854f86f0b56e9027d68e7a3fc909d1a9b566f"
},
{
"url": "https://matrix.tencent.com/en/2026/08/06/sctphantom-CVE-2026-64564"
}
],
"title": "sctp: don\u0027t free the ASCONF\u0027s own transport in DEL-IP processing",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64564",
"datePublished": "2026-08-04T06:23:23.339Z",
"dateReserved": "2026-07-19T15:36:31.797Z",
"dateUpdated": "2026-08-19T16:28:36.947Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68336 (GCVE-0-2026-68336)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
bonding: fix devconf_all NULL dereference when IPv6 is disabled
When booting with the 'ipv6.disable=1' parameter, the devconf_all is
never initialized because inet6_init() exits before addrconf_init() is
called which initializes it. bond_send_validate(), however, will still
call bond_ns_send_all() even ipv6 is indeed disabled. It will lead to
NULL derefence of net->ipv6.devconf_all in ip6_pol_route().
BUG: kernel NULL pointer dereference, address: 000000000000000c
[...]
Workqueue: bond0 bond_arp_monitor [bonding]
RIP: 0010:ip6_pol_route+0x69/0x480
[...]
Call Trace:
<TASK>
? srso_return_thunk+0x5/0x5f
? __pfx_ip6_pol_route_output+0x10/0x10
fib6_rule_lookup+0xfe/0x260
? wakeup_preempt+0x8a/0x90
? srso_return_thunk+0x5/0x5f
? srso_return_thunk+0x5/0x5f
? sched_balance_rq+0x369/0x810
ip6_route_output_flags+0xd7/0x170
bond_ns_send_all+0xde/0x280 [bonding]
bond_ab_arp_probe+0x296/0x320 [bonding]
? srso_return_thunk+0x5/0x5f
bond_activebackup_arp_mon+0xb4/0x2c0 [bonding]
process_one_work+0x196/0x370
worker_thread+0x1af/0x320
? srso_return_thunk+0x5/0x5f
? __pfx_worker_thread+0x10/0x10
kthread+0xe3/0x120
? __pfx_kthread+0x10/0x10
ret_from_fork+0x199/0x260
? __pfx_kthread+0x10/0x10
ret_from_fork_asm+0x1a/0x30
</TASK>
Fix this by adding ipv6_mod_enabled() condition check in the caller.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 4e24be018eb9dbcefa4b01c07e298b147dc1a4d7 Version: 4e24be018eb9dbcefa4b01c07e298b147dc1a4d7 Version: 4e24be018eb9dbcefa4b01c07e298b147dc1a4d7 Version: 4e24be018eb9dbcefa4b01c07e298b147dc1a4d7 Version: 4e24be018eb9dbcefa4b01c07e298b147dc1a4d7 Version: 4e24be018eb9dbcefa4b01c07e298b147dc1a4d7 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/bonding/bond_main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "451c2d5422a309393aa8ae161fc1a527c2f19ab2",
"status": "affected",
"version": "4e24be018eb9dbcefa4b01c07e298b147dc1a4d7",
"versionType": "git"
},
{
"lessThan": "2a4bad24ac5296b262ad821aa5e08bb265e6b154",
"status": "affected",
"version": "4e24be018eb9dbcefa4b01c07e298b147dc1a4d7",
"versionType": "git"
},
{
"lessThan": "690ce66782778e8c4b1fdd79c0b0890a100e9522",
"status": "affected",
"version": "4e24be018eb9dbcefa4b01c07e298b147dc1a4d7",
"versionType": "git"
},
{
"lessThan": "992dce02bdabbd9883255ea9b36494e34a7821d7",
"status": "affected",
"version": "4e24be018eb9dbcefa4b01c07e298b147dc1a4d7",
"versionType": "git"
},
{
"lessThan": "738039ad21e20ca2c5bbde2f5a4f5ad5fb718038",
"status": "affected",
"version": "4e24be018eb9dbcefa4b01c07e298b147dc1a4d7",
"versionType": "git"
},
{
"lessThan": "1c975de3343cdef506f2eecc833cc1f14b0401c4",
"status": "affected",
"version": "4e24be018eb9dbcefa4b01c07e298b147dc1a4d7",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/bonding/bond_main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.18"
},
{
"lessThan": "5.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.18",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbonding: fix devconf_all NULL dereference when IPv6 is disabled\n\nWhen booting with the \u0027ipv6.disable=1\u0027 parameter, the devconf_all is\nnever initialized because inet6_init() exits before addrconf_init() is\ncalled which initializes it. bond_send_validate(), however, will still\ncall bond_ns_send_all() even ipv6 is indeed disabled. It will lead to\nNULL derefence of net-\u003eipv6.devconf_all in ip6_pol_route().\n\n BUG: kernel NULL pointer dereference, address: 000000000000000c\n [...]\n Workqueue: bond0 bond_arp_monitor [bonding]\n RIP: 0010:ip6_pol_route+0x69/0x480\n [...]\n Call Trace:\n \u003cTASK\u003e\n ? srso_return_thunk+0x5/0x5f\n ? __pfx_ip6_pol_route_output+0x10/0x10\n fib6_rule_lookup+0xfe/0x260\n ? wakeup_preempt+0x8a/0x90\n ? srso_return_thunk+0x5/0x5f\n ? srso_return_thunk+0x5/0x5f\n ? sched_balance_rq+0x369/0x810\n ip6_route_output_flags+0xd7/0x170\n bond_ns_send_all+0xde/0x280 [bonding]\n bond_ab_arp_probe+0x296/0x320 [bonding]\n ? srso_return_thunk+0x5/0x5f\n bond_activebackup_arp_mon+0xb4/0x2c0 [bonding]\n process_one_work+0x196/0x370\n worker_thread+0x1af/0x320\n ? srso_return_thunk+0x5/0x5f\n ? __pfx_worker_thread+0x10/0x10\n kthread+0xe3/0x120\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x199/0x260\n ? __pfx_kthread+0x10/0x10\n ret_from_fork_asm+0x1a/0x30\n \u003c/TASK\u003e\n\nFix this by adding ipv6_mod_enabled() condition check in the caller."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:35.547Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/451c2d5422a309393aa8ae161fc1a527c2f19ab2"
},
{
"url": "https://git.kernel.org/stable/c/2a4bad24ac5296b262ad821aa5e08bb265e6b154"
},
{
"url": "https://git.kernel.org/stable/c/690ce66782778e8c4b1fdd79c0b0890a100e9522"
},
{
"url": "https://git.kernel.org/stable/c/992dce02bdabbd9883255ea9b36494e34a7821d7"
},
{
"url": "https://git.kernel.org/stable/c/738039ad21e20ca2c5bbde2f5a4f5ad5fb718038"
},
{
"url": "https://git.kernel.org/stable/c/1c975de3343cdef506f2eecc833cc1f14b0401c4"
}
],
"title": "bonding: fix devconf_all NULL dereference when IPv6 is disabled",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68336",
"datePublished": "2026-08-10T12:03:12.592Z",
"dateReserved": "2026-07-30T09:28:09.383Z",
"dateUpdated": "2026-08-19T16:33:35.547Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72032 (GCVE-0-2026-72032)
Vulnerability from cvelistv5
Published
2026-08-15 05:51
Modified
2026-08-17 05:06
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/mlx5: HWS, fix matcher leak on resize target setup failure
hws_bwc_matcher_move() allocates a replacement matcher before setting it
as the resize target. If mlx5hws_matcher_resize_set_target() fails, the
replacement matcher is not attached anywhere and is leaked.
Fix the leak by destroying the replacement matcher before returning from
the resize-target failure path.
The bug was first flagged by an experimental analysis tool we are
developing for kernel memory-management bugs while analyzing
v6.13-rc1. The tool is still under development and is not yet publicly
available. Manual inspection confirms that the bug is still
present in v7.1.1.
An x86_64 allyesconfig build showed no new warnings. As we do not have a
mlx5 HWS-capable device to test with, no runtime testing was able to be
performed.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/mellanox/mlx5/core/steering/hws/bwc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a751ccdc6ea9bde154f25a5ba66926f462f96c19",
"status": "affected",
"version": "2111bb970c787b16b002dc726c1d296ce87a00fb",
"versionType": "git"
},
{
"lessThan": "1dce4f4bb3c1c02080b1a45bdd2abb2913a6642a",
"status": "affected",
"version": "2111bb970c787b16b002dc726c1d296ce87a00fb",
"versionType": "git"
},
{
"lessThan": "ae0265f0a95aaacef59d560a3e1ea36db8be9a52",
"status": "affected",
"version": "2111bb970c787b16b002dc726c1d296ce87a00fb",
"versionType": "git"
},
{
"lessThan": "bb09d0e64ecaa0aa0f7d1133a1696ed74dead295",
"status": "affected",
"version": "2111bb970c787b16b002dc726c1d296ce87a00fb",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/mellanox/mlx5/core/steering/hws/bwc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.12"
},
{
"lessThan": "6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: HWS, fix matcher leak on resize target setup failure\n\nhws_bwc_matcher_move() allocates a replacement matcher before setting it\nas the resize target. If mlx5hws_matcher_resize_set_target() fails, the\nreplacement matcher is not attached anywhere and is leaked.\n\nFix the leak by destroying the replacement matcher before returning from\nthe resize-target failure path.\n\nThe bug was first flagged by an experimental analysis tool we are\ndeveloping for kernel memory-management bugs while analyzing\nv6.13-rc1. The tool is still under development and is not yet publicly\navailable. Manual inspection confirms that the bug is still\npresent in v7.1.1.\n\nAn x86_64 allyesconfig build showed no new warnings. As we do not have a\nmlx5 HWS-capable device to test with, no runtime testing was able to be\nperformed."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:06:57.395Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a751ccdc6ea9bde154f25a5ba66926f462f96c19"
},
{
"url": "https://git.kernel.org/stable/c/1dce4f4bb3c1c02080b1a45bdd2abb2913a6642a"
},
{
"url": "https://git.kernel.org/stable/c/ae0265f0a95aaacef59d560a3e1ea36db8be9a52"
},
{
"url": "https://git.kernel.org/stable/c/bb09d0e64ecaa0aa0f7d1133a1696ed74dead295"
}
],
"title": "net/mlx5: HWS, fix matcher leak on resize target setup failure",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72032",
"datePublished": "2026-08-15T05:51:54.461Z",
"dateReserved": "2026-08-09T03:40:39.901Z",
"dateUpdated": "2026-08-17T05:06:57.395Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68206 (GCVE-0-2026-68206)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: v4l2-ctrls: validate HEVC active reference counts
HEVC slice parameters are shared stateless V4L2 controls, but the common
validation path does not verify the active L0/L1 reference counts before
driver-specific code consumes them.
The original report came from Cedrus, but the active count bounds are
not Cedrus-specific. Validate them in the common HEVC slice control path
so stateless HEVC drivers get the same basic guarantees as soon as the
control is queued.
Do not reject ref_idx_l0/ref_idx_l1 entries here. Existing userspace may
use out-of-range sentinel values such as 0xff for missing references, and
some hardware can use that information for concealment. Keep this common
check limited to the active reference counts.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d395a78db9eabd12633b39e05c80e803543b6590 Version: d395a78db9eabd12633b39e05c80e803543b6590 Version: d395a78db9eabd12633b39e05c80e803543b6590 Version: d395a78db9eabd12633b39e05c80e803543b6590 Version: d395a78db9eabd12633b39e05c80e803543b6590 Version: d395a78db9eabd12633b39e05c80e803543b6590 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/v4l2-core/v4l2-ctrls-core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "3299c3905f3fb439ebd892658b87bc76c93ae116",
"status": "affected",
"version": "d395a78db9eabd12633b39e05c80e803543b6590",
"versionType": "git"
},
{
"lessThan": "9a998cc1c348769262d433acb7d238c5fac4b2e0",
"status": "affected",
"version": "d395a78db9eabd12633b39e05c80e803543b6590",
"versionType": "git"
},
{
"lessThan": "dbaf0e0023e2f9332c5164822def7f80b7d2c5ef",
"status": "affected",
"version": "d395a78db9eabd12633b39e05c80e803543b6590",
"versionType": "git"
},
{
"lessThan": "3068ab802fc98b121dcb451e1f7f4d338ffc7a19",
"status": "affected",
"version": "d395a78db9eabd12633b39e05c80e803543b6590",
"versionType": "git"
},
{
"lessThan": "b01df98a6669d2b67d8aed816021b327fd905998",
"status": "affected",
"version": "d395a78db9eabd12633b39e05c80e803543b6590",
"versionType": "git"
},
{
"lessThan": "afbe4bc252d90a6f8fad869b06d5430f615f22f9",
"status": "affected",
"version": "d395a78db9eabd12633b39e05c80e803543b6590",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/v4l2-core/v4l2-ctrls-core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.14"
},
{
"lessThan": "5.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: v4l2-ctrls: validate HEVC active reference counts\n\nHEVC slice parameters are shared stateless V4L2 controls, but the common\nvalidation path does not verify the active L0/L1 reference counts before\ndriver-specific code consumes them.\n\nThe original report came from Cedrus, but the active count bounds are\nnot Cedrus-specific. Validate them in the common HEVC slice control path\nso stateless HEVC drivers get the same basic guarantees as soon as the\ncontrol is queued.\n\nDo not reject ref_idx_l0/ref_idx_l1 entries here. Existing userspace may\nuse out-of-range sentinel values such as 0xff for missing references, and\nsome hardware can use that information for concealment. Keep this common\ncheck limited to the active reference counts."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The control is only settable through VIDIOC_S_EXT_CTRLS on the local V4L2 stateless decoder node (/dev/videoN), followed by QBUF/STREAMON on the same fd. There is no network or remote path into the HEVC slice-params control.\nAC:L - The attacker supplies num_ref_idx_l0/l1_active_minus1 verbatim as a u8; any value in 16..254 deterministically drives the loops in cedrus_h265_is_low_delay() and rkvdec_hevc set_ps_field() out of bounds on the very next decode run. No race, timing window, or uncontrollable memory layout is involved.\nPR:L - Only an unprivileged local account holding the video device node is required (typically the \u0027video\u0027 group, or the media/codec service reachable from sandboxed apps on Android and embedded Allwinner/Rockchip devices). cedrus_try_ctrl() checks only SPS chroma format and bit depth; no capability or root check exists on the path.\nUI:N - The attacking process performs the whole sequence itself: open the decoder, set the crafted HEVC slice-params control, queue buffers and start streaming. No victim action, media file, or mount is needed.\nS:U - The out-of-bounds accesses stay inside the kernel\u0027s own slab and DMA memory within the same security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - decode_params-\u003edpb[] holds 16 16-byte entries at the tail of a ~336-byte control allocation, so an index up to 255 reads roughly 3.8 KB of adjacent kernel heap; the pred-weight loops likewise read 240 bytes past slice_params. Those OOB bytes are fed into decoder SRAM and steer the low-delay decision, giving an attacker-steerable oracle over unrelated kernel memory.\nI:H - In rkvdec-hevc, REF_PIC_IDX_L0(i)/REF_PIC_LONG_TERM_L1(i) with i up to 255 resolve to bit offset ~1276 in an 8-word rkvdec_rps_packet, so set_ps_field() performs an out-of-bounds write of attacker-chosen bits at an attacker-chosen offset into (and past the end of) the coherent DMA priv_tbl, corrupting hardware descriptor state and adjacent memory.\nA:H - Reading several kilobytes past a slab object can walk into an unmapped or poisoned region and trips KASAN/hardening checks, while the rkvdec out-of-bounds write corrupts the DMA table handed to the decoder; either yields a kernel oops or wedged hardware, repeatable at will from an unprivileged process."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:26.837Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/3299c3905f3fb439ebd892658b87bc76c93ae116"
},
{
"url": "https://git.kernel.org/stable/c/9a998cc1c348769262d433acb7d238c5fac4b2e0"
},
{
"url": "https://git.kernel.org/stable/c/dbaf0e0023e2f9332c5164822def7f80b7d2c5ef"
},
{
"url": "https://git.kernel.org/stable/c/3068ab802fc98b121dcb451e1f7f4d338ffc7a19"
},
{
"url": "https://git.kernel.org/stable/c/b01df98a6669d2b67d8aed816021b327fd905998"
},
{
"url": "https://git.kernel.org/stable/c/afbe4bc252d90a6f8fad869b06d5430f615f22f9"
}
],
"title": "media: v4l2-ctrls: validate HEVC active reference counts",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68206",
"datePublished": "2026-08-10T12:00:25.309Z",
"dateReserved": "2026-07-30T09:28:09.374Z",
"dateUpdated": "2026-08-19T16:31:26.837Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68350 (GCVE-0-2026-68350)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: carl9170: fix OOB read from off-by-two in TX status handler
The bounds check in carl9170_tx_process_status() uses
`i > ((cmd->hdr.len / 2) + 1)` which is off by two, allowing
2 extra iterations past valid _tx_status entries when the firmware-
controlled hdr.ext exceeds hdr.len/2. Fix by using the correct
comparison `i >= (cmd->hdr.len / 2)`.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/ath/carl9170/tx.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "9bf8d8510b7bed20320dead0f8cdcf8e610ec8db",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "2c030c20f112bd8f6aa59d09501835605f01bf9d",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "73462e8e602047a03e538d971a79ad67a4ba9a5d",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "7ed0dce8613c92111d2a3836ced2ab03190ba20e",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "e8a862a3da457ddc50633c346dc645d559da09ae",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "fab6ff91d5b8c4af62e2ced42fb357fa3eb9fd59",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "423c836f934814b8fdbe53b24a79d021a0ee8454",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "a3f42f1049ad80c65560d2b078ad426c3134f78d",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/ath/carl9170/tx.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.37"
},
{
"lessThan": "2.6.37",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.37",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: carl9170: fix OOB read from off-by-two in TX status handler\n\nThe bounds check in carl9170_tx_process_status() uses\n`i \u003e ((cmd-\u003ehdr.len / 2) + 1)` which is off by two, allowing\n2 extra iterations past valid _tx_status entries when the firmware-\ncontrolled hdr.ext exceeds hdr.len/2. Fix by using the correct\ncomparison `i \u003e= (cmd-\u003ehdr.len / 2)`."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:50.606Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/9bf8d8510b7bed20320dead0f8cdcf8e610ec8db"
},
{
"url": "https://git.kernel.org/stable/c/2c030c20f112bd8f6aa59d09501835605f01bf9d"
},
{
"url": "https://git.kernel.org/stable/c/73462e8e602047a03e538d971a79ad67a4ba9a5d"
},
{
"url": "https://git.kernel.org/stable/c/7ed0dce8613c92111d2a3836ced2ab03190ba20e"
},
{
"url": "https://git.kernel.org/stable/c/e8a862a3da457ddc50633c346dc645d559da09ae"
},
{
"url": "https://git.kernel.org/stable/c/fab6ff91d5b8c4af62e2ced42fb357fa3eb9fd59"
},
{
"url": "https://git.kernel.org/stable/c/423c836f934814b8fdbe53b24a79d021a0ee8454"
},
{
"url": "https://git.kernel.org/stable/c/a3f42f1049ad80c65560d2b078ad426c3134f78d"
}
],
"title": "wifi: carl9170: fix OOB read from off-by-two in TX status handler",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68350",
"datePublished": "2026-08-10T12:03:27.314Z",
"dateReserved": "2026-07-30T09:28:09.384Z",
"dateUpdated": "2026-08-19T16:33:50.606Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72046 (GCVE-0-2026-72046)
Vulnerability from cvelistv5
Published
2026-08-15 05:52
Modified
2026-08-17 05:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
gve: fix header buffer corruption with header-split and HW-GRO
The DQO RX datapath programs a per-buffer-queue-descriptor
header_buf_addr at post time and reads the split header back at
completion time. Both the post and the read currently index the
header buffer by queue position rather than by the buffer's identity:
- post (gve_rx_post_buffers_dqo): header_buf_addr is computed from
bufq->tail
- read (gve_rx_dqo): the header is read from desc_idx (the completion
queue head index)
This relies on the buffer-queue index and the completion-queue index
being equal for the start of every packet, i.e. on the device consuming
posted buffers and returning completions in the exact same order. That
assumption does not hold once HW-GRO is enabled with multiple
flows: coalesced segments are accepted and completed in an order that
may differ from the order buffers were posted, and segments from
different flows may interleave.
That results in two problems:
1. Wrong header slot on read. Because the read offset is derived from
the completion index (desc_idx) while the device wrote the header to
the address programmed for the buffer's buf_id, the driver can copy
a header belonging to a different packet. This shows up as
throughput drop (about 30% drop and large numbers of TCP
retransmissions) with header-split and HW-GRO both enabled and many
streams.
2. Header buffer reused while still owned by the device. The driver
advances bufq->head by one per completion and re-posts buffers based
on that. Arrival of N RX completions only guarantees that at least N
RX buffer descriptors have been read by the device. It does not
guarantee that the device has relinquished the ownership of all the
buffers corresponding to those N descriptors. With out-of-order
completions (e.g. the completion for a packet copied into buffer N
arrives before the completion for a packet copied into buffer N-1),
the driver can re-post and overwrite a header buffer that the device
is still going to write into, corrupting the header of a packet
whose completion has not yet been processed.
Fix both issues by indexing the header buffer by buf_id on both the post
and read paths. Reading from buf_id's slot is therefore always correct
regardless of completion ordering (fixes problem 1).
Indexing by buf_id also ties each header slot to the lifetime of its
buffer state. A buffer state is only returned to the free/recycle lists
when its own completion (buf_id) is processed, so its header slot can
only be re-posted after the device is done with it. This makes header
slot reuse safe under out-of-order completions (fixes problem 2).
Allocate (gve_rx_alloc_hdr_bufs) and free (gve_rx_free_hdr_bufs) the
header buffers based on num_buf_states to match the buf_id indexing.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/google/gve/gve_rx_dqo.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "84d3753d4bf284ef770ead6dee2270aaabb3ef41",
"status": "affected",
"version": "5e37d8254e7f551dda62e7590e819d69c7491845",
"versionType": "git"
},
{
"lessThan": "35267819b25074084130b6a7be18bbaf44d3ae74",
"status": "affected",
"version": "5e37d8254e7f551dda62e7590e819d69c7491845",
"versionType": "git"
},
{
"lessThan": "9f8e7f59b0c2f466be74bd923726b0f5496c27ad",
"status": "affected",
"version": "5e37d8254e7f551dda62e7590e819d69c7491845",
"versionType": "git"
},
{
"lessThan": "d676c9a73bdcd8237425dbb826f2bd1a25c36e40",
"status": "affected",
"version": "5e37d8254e7f551dda62e7590e819d69c7491845",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/google/gve/gve_rx_dqo.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.9"
},
{
"lessThan": "6.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ngve: fix header buffer corruption with header-split and HW-GRO\n\nThe DQO RX datapath programs a per-buffer-queue-descriptor\nheader_buf_addr at post time and reads the split header back at\ncompletion time. Both the post and the read currently index the\nheader buffer by queue position rather than by the buffer\u0027s identity:\n\n - post (gve_rx_post_buffers_dqo): header_buf_addr is computed from\n bufq-\u003etail\n - read (gve_rx_dqo): the header is read from desc_idx (the completion\n queue head index)\n\nThis relies on the buffer-queue index and the completion-queue index\nbeing equal for the start of every packet, i.e. on the device consuming\nposted buffers and returning completions in the exact same order. That\nassumption does not hold once HW-GRO is enabled with multiple\nflows: coalesced segments are accepted and completed in an order that\nmay differ from the order buffers were posted, and segments from\ndifferent flows may interleave.\n\nThat results in two problems:\n\n1. Wrong header slot on read. Because the read offset is derived from\n the completion index (desc_idx) while the device wrote the header to\n the address programmed for the buffer\u0027s buf_id, the driver can copy\n a header belonging to a different packet. This shows up as\n throughput drop (about 30% drop and large numbers of TCP\n retransmissions) with header-split and HW-GRO both enabled and many\n streams.\n\n2. Header buffer reused while still owned by the device. The driver\n advances bufq-\u003ehead by one per completion and re-posts buffers based\n on that. Arrival of N RX completions only guarantees that at least N\n RX buffer descriptors have been read by the device. It does not\n guarantee that the device has relinquished the ownership of all the\n buffers corresponding to those N descriptors. With out-of-order\n completions (e.g. the completion for a packet copied into buffer N\n arrives before the completion for a packet copied into buffer N-1),\n the driver can re-post and overwrite a header buffer that the device\n is still going to write into, corrupting the header of a packet\n whose completion has not yet been processed.\n\nFix both issues by indexing the header buffer by buf_id on both the post\nand read paths. Reading from buf_id\u0027s slot is therefore always correct\nregardless of completion ordering (fixes problem 1).\n\nIndexing by buf_id also ties each header slot to the lifetime of its\nbuffer state. A buffer state is only returned to the free/recycle lists\nwhen its own completion (buf_id) is processed, so its header slot can\nonly be re-posted after the device is done with it. This makes header\nslot reuse safe under out-of-order completions (fixes problem 2).\n\nAllocate (gve_rx_alloc_hdr_bufs) and free (gve_rx_free_hdr_bufs) the\nheader buffers based on num_buf_states to match the buf_id indexing."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The flaw is in the GVE driver RX NAPI path triggered by incoming network frames; a remote peer can reach gve_rx_dqo()/gve_rx_post_buffers_dqo() by sending TCP traffic to an internet-facing GVE interface (e.g., GCP VM) without local access.\nAC:L - Once header-split and HW-GRO are enabled, an attacker can reliably trigger out-of-order HW-GRO completions by opening many concurrent TCP flows to the target; no race against uncontrollable victim state is required beyond normal multi-stream traffic patterns.\nPR:N - Exploitation requires only the ability to send network packets to the host; no local account, capabilities, or authentication on the victim is needed. Header-split being enabled is victim configuration, not attacker privilege.\nUI:N - No victim user action is required during exploitation beyond the host already receiving network traffic on its GVE interface; the attacker does not depend on the user mounting filesystems or opening files.\nS:U - Impact is confined to the guest kernel network stack and driver DMA header buffers on the affected VM; it does not cross a VM/host or IOMMU security boundary to affect the hypervisor or other tenants.\nC:H - Out-of-order completions cause the driver to read the wrong header slot, mixing headers between packets/flows and disclosing other connections\u0027 L3/L4 header bytes; premature header-buffer reuse also corrupts DMA data the driver later copies into skbs.\nI:H - The driver can repost and overwrite header DMA buffers while the device is still writing them, corrupting packet headers fed into the stack; wrong headers paired with payloads can break protocol parsing and constitutes exploitable kernel memory corruption.\nA:H - The bug causes severe TCP throughput collapse, massive retransmissions, and dropped/corrupted packets; header-buffer corruption and malformed skbs can also destabilize the kernel RX path and cause oopses or loss of network availability on the host."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:39:45.577Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/84d3753d4bf284ef770ead6dee2270aaabb3ef41"
},
{
"url": "https://git.kernel.org/stable/c/35267819b25074084130b6a7be18bbaf44d3ae74"
},
{
"url": "https://git.kernel.org/stable/c/9f8e7f59b0c2f466be74bd923726b0f5496c27ad"
},
{
"url": "https://git.kernel.org/stable/c/d676c9a73bdcd8237425dbb826f2bd1a25c36e40"
}
],
"title": "gve: fix header buffer corruption with header-split and HW-GRO",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72046",
"datePublished": "2026-08-15T05:52:04.769Z",
"dateReserved": "2026-08-09T03:40:39.902Z",
"dateUpdated": "2026-08-17T05:39:45.577Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68443 (GCVE-0-2026-68443)
Vulnerability from cvelistv5
Published
2026-08-12 00:07
Modified
2026-08-17 05:05
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
hwmon: (gigabyte_waterforce) Stop device IO before calling hid_hw_stop
Calling hid_hw_stop() does not stop the device IO.
This results in a race condition between hid_input_report() and the point
immediately following the execution of hid_device_io_start() within
the driver probe function. If the probe operation fails after "io start"
has been initiated, this race condition will result in a UAF vulnerability.
Fix the problem by calling hid_device_io_stop() before calling
hid_hw_stop().
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/hwmon/gigabyte_waterforce.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a855f678ba37ef82c4dd22926ad740ecfb8dbedf",
"status": "affected",
"version": "42ac68e3d4ba06ad17bc56b790dbccc37e76e0ba",
"versionType": "git"
},
{
"lessThan": "f36e12cc8cfe996d627b8a82bd9df9e43270f6e2",
"status": "affected",
"version": "42ac68e3d4ba06ad17bc56b790dbccc37e76e0ba",
"versionType": "git"
},
{
"lessThan": "0842e9faab04f784d01125085195031252ff9695",
"status": "affected",
"version": "42ac68e3d4ba06ad17bc56b790dbccc37e76e0ba",
"versionType": "git"
},
{
"lessThan": "ff0c5c53d08274e200b48a4d53aa078265e873cb",
"status": "affected",
"version": "42ac68e3d4ba06ad17bc56b790dbccc37e76e0ba",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/hwmon/gigabyte_waterforce.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.8"
},
{
"lessThan": "6.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (gigabyte_waterforce) Stop device IO before calling hid_hw_stop\n\nCalling hid_hw_stop() does not stop the device IO.\nThis results in a race condition between hid_input_report() and the point\nimmediately following the execution of hid_device_io_start() within\nthe driver probe function. If the probe operation fails after \"io start\"\nhas been initiated, this race condition will result in a UAF vulnerability.\n\nFix the problem by calling hid_device_io_stop() before calling\nhid_hw_stop()."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:05:40.768Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a855f678ba37ef82c4dd22926ad740ecfb8dbedf"
},
{
"url": "https://git.kernel.org/stable/c/f36e12cc8cfe996d627b8a82bd9df9e43270f6e2"
},
{
"url": "https://git.kernel.org/stable/c/0842e9faab04f784d01125085195031252ff9695"
},
{
"url": "https://git.kernel.org/stable/c/ff0c5c53d08274e200b48a4d53aa078265e873cb"
}
],
"title": "hwmon: (gigabyte_waterforce) Stop device IO before calling hid_hw_stop",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68443",
"datePublished": "2026-08-12T00:07:33.319Z",
"dateReserved": "2026-07-30T09:28:09.394Z",
"dateUpdated": "2026-08-17T05:05:40.768Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68445 (GCVE-0-2026-68445)
Vulnerability from cvelistv5
Published
2026-08-12 00:07
Modified
2026-08-17 05:05
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/vc4: Prevent shader BO mappings from becoming writable
vc4_gem_object_mmap() rejects a writable mapping of a validated shader
BO, but leaves VM_MAYWRITE set. Userspace can map the BO read-only and
then turn it writable with mprotect().
Validated shader BOs must stay read-only: the validator checks the
instructions once and the GPU trusts them afterwards. A writable
mapping lets userspace rewrite the code after validation, bypassing the
validator.
Clear VM_MAYWRITE on the read-only path so the mapping cannot be
upgraded, as i915 already does for its read-only objects.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/vc4/vc4_bo.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "9f0ee411fc2d76333d6087c5862ffa907cf7a175",
"status": "affected",
"version": "463873d5701427f2964a0b4b72c45f1f14b6df87",
"versionType": "git"
},
{
"lessThan": "019e6ad247f7fd038d2e009789f6d9bfcccb1ae7",
"status": "affected",
"version": "463873d5701427f2964a0b4b72c45f1f14b6df87",
"versionType": "git"
},
{
"lessThan": "6deaa317201851c644c431b57682e54d06b35838",
"status": "affected",
"version": "463873d5701427f2964a0b4b72c45f1f14b6df87",
"versionType": "git"
},
{
"lessThan": "fe168ef1d232d734d9998fd74822e2e20930dfff",
"status": "affected",
"version": "463873d5701427f2964a0b4b72c45f1f14b6df87",
"versionType": "git"
},
{
"lessThan": "0c9e6367639548307d3f578f6943ce72c9d39087",
"status": "affected",
"version": "463873d5701427f2964a0b4b72c45f1f14b6df87",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/vc4/vc4_bo.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.5"
},
{
"lessThan": "4.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vc4: Prevent shader BO mappings from becoming writable\n\nvc4_gem_object_mmap() rejects a writable mapping of a validated shader\nBO, but leaves VM_MAYWRITE set. Userspace can map the BO read-only and\nthen turn it writable with mprotect().\n\nValidated shader BOs must stay read-only: the validator checks the\ninstructions once and the GPU trusts them afterwards. A writable\nmapping lets userspace rewrite the code after validation, bypassing the\nvalidator.\n\nClear VM_MAYWRITE on the read-only path so the mapping cannot be\nupgraded, as i915 already does for its read-only objects."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires local access to the vc4 DRM render node (/dev/dri/renderD*) to issue VC4_CREATE_SHADER_BO, VC4_MMAP_BO, mmap/mprotect and VC4_SUBMIT_CL; there is no remote or network-facing path to this code.\nAC:L - The attacker fully controls every step: create a shader that passes validation, map it PROT_READ, upgrade it with mprotect(PROT_WRITE), rewrite the instructions and submit. There is no race, no memory-layout dependency, and it works on the default configuration of any VC4 (Raspberry Pi) system.\nPR:L - VC4_CREATE_SHADER_BO, VC4_MMAP_BO and VC4_SUBMIT_CL are all DRM_RENDER_ALLOW ioctls, so an ordinary unprivileged user with render-node access (the default for logged-in/graphical users on Raspberry Pi and embedded VC4 devices) can perform the whole sequence. No capability check is involved.\nUI:N - The attacking process performs the entire sequence itself; no action by another user or administrator is needed.\nS:U - The vulnerable driver and the compromised resource (kernel/system memory) are both under the kernel\u0027s security authority; this is a standard local kernel privilege escalation rather than a VM or hypervisor boundary escape.\nC:H - Post-validation rewriting of shader code lets the GPU, which has no IOMMU on VC4, read arbitrary system memory via texture, uniform and direct-addressed TMU lookups \u2014 exactly the disclosure the validator exists to prevent, giving arbitrary kernel memory read.\nI:H - Unvalidated QPU code can use the VPM write address register in general-purpose DMA mode to write to arbitrary physical addresses, an arbitrary kernel-memory write primitive that yields full privilege escalation and code execution.\nA:H - The same arbitrary DMA writes and unbounded shader execution readily corrupt kernel structures or hang the GPU, causing kernel panics or a full system hang triggerable at will by an unprivileged user."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:05:42.989Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/9f0ee411fc2d76333d6087c5862ffa907cf7a175"
},
{
"url": "https://git.kernel.org/stable/c/019e6ad247f7fd038d2e009789f6d9bfcccb1ae7"
},
{
"url": "https://git.kernel.org/stable/c/6deaa317201851c644c431b57682e54d06b35838"
},
{
"url": "https://git.kernel.org/stable/c/fe168ef1d232d734d9998fd74822e2e20930dfff"
},
{
"url": "https://git.kernel.org/stable/c/0c9e6367639548307d3f578f6943ce72c9d39087"
}
],
"title": "drm/vc4: Prevent shader BO mappings from becoming writable",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68445",
"datePublished": "2026-08-12T00:07:36.230Z",
"dateReserved": "2026-07-30T09:28:09.394Z",
"dateUpdated": "2026-08-17T05:05:42.989Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72183 (GCVE-0-2026-72183)
Vulnerability from cvelistv5
Published
2026-08-15 05:53
Modified
2026-08-17 05:41
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
landlock: Fix LANDLOCK_SCOPE_SIGNAL bypass on the SIGIO path
LANDLOCK_SCOPE_SIGNAL must prevent a sandboxed process from signaling
processes outside its Landlock domain. It can be bypassed through the
asynchronous SIGIO delivery path.
A sandboxed process that owns any file or socket can arm it with
fcntl(fd, F_SETOWN, -pgid), fcntl(fd, F_SETSIG, SIGKILL) and O_ASYNC, so
that an I/O event makes the kernel deliver the chosen signal to the
whole process group. As the head of its process group's task list (the
default position right after fork()) that group can also hold the
non-sandboxed process that launched it, e.g. a supervisor or a security
monitor. The sandbox can thus kill or signal the processes
LANDLOCK_SCOPE_SIGNAL is meant to protect from it.
The scope is enforced in hook_file_send_sigiotask() against the Landlock
domain recorded at F_SETOWN time, not the live domain of the sender.
control_current_fowner() decides whether to record that domain and skips
recording it when the fowner target is in the caller's thread group,
which is safe only for a single-task target (PIDTYPE_PID, PIDTYPE_TGID).
For a process group (PIDTYPE_PGID) pid_task() returns only one member;
recording is skipped whenever that member shares the caller's thread
group, and hook_file_send_sigiotask() then lets the signal fan out to
the whole group unchecked.
Record the domain for every non single-process target so the scope is
enforced against each group member at delivery time.
That recording is necessary but not sufficient on its own: the kernel
signals a process group through its members' thread-group leaders, and
the leader of the registrant's own process can carry a different
Landlock domain than the sibling thread that armed the owner.
domain_is_scoped() would then deny that leader, even though commit
18eb75f3af40 ("landlock: Always allow signals between threads of the
same process") requires same-process delivery to be allowed.
hook_task_kill() avoids this by evaluating same_thread_group() live, per
recipient; the SIGIO path instead delegates the whole decision to a
single registration-time check, which a process-group fan-out cannot
honor.
So also record the registrant's thread group next to its domain and
exempt it at delivery: hook_file_send_sigiotask() allows the signal
whenever the recipient belongs to the registrant's own process,
restoring the same-process guarantee while keeping out-of-domain group
members blocked. The direct kill() path (hook_task_kill) already
evaluates the live domain and is unaffected.
[mic: Check pid_type earlier and improve comment, fix commit message,
fix comment formatting]
References
| URL | Tags | |
|---|---|---|
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 332facfa80751b80006c2f95b13c6d208ab0aee1 Version: 18eb75f3af40be1f0fc2025d4ff821711222a2fd Version: 18eb75f3af40be1f0fc2025d4ff821711222a2fd Version: 18eb75f3af40be1f0fc2025d4ff821711222a2fd Version: 6861348d863c0eaa4af67492d640a9644a829c59 Version: 0906a9685d7057aea982e970da3e1cf3e5aca68b Version: 6.12.24 ≤ Version: 6.13.12 ≤ Version: 6.14.3 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"security/landlock/fs.c",
"security/landlock/fs.h",
"security/landlock/task.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "7a92e9fd1d496a610b40e0c4253fd54e7496f5ab",
"status": "affected",
"version": "332facfa80751b80006c2f95b13c6d208ab0aee1",
"versionType": "git"
},
{
"lessThan": "1f18aac2637220b5847d073447498e81ddca10b2",
"status": "affected",
"version": "18eb75f3af40be1f0fc2025d4ff821711222a2fd",
"versionType": "git"
},
{
"lessThan": "04916f7dc6d37cd478b06c86398c34a6963ac8c9",
"status": "affected",
"version": "18eb75f3af40be1f0fc2025d4ff821711222a2fd",
"versionType": "git"
},
{
"lessThan": "4b80320ca7ed03d6e683f95b6066565dc97b9f92",
"status": "affected",
"version": "18eb75f3af40be1f0fc2025d4ff821711222a2fd",
"versionType": "git"
},
{
"status": "affected",
"version": "6861348d863c0eaa4af67492d640a9644a829c59",
"versionType": "git"
},
{
"status": "affected",
"version": "0906a9685d7057aea982e970da3e1cf3e5aca68b",
"versionType": "git"
},
{
"lessThan": "6.12.101",
"status": "affected",
"version": "6.12.24",
"versionType": "semver"
},
{
"lessThan": "6.14",
"status": "affected",
"version": "6.13.12",
"versionType": "semver"
},
{
"lessThan": "6.15",
"status": "affected",
"version": "6.14.3",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"security/landlock/fs.c",
"security/landlock/fs.h",
"security/landlock/task.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.15"
},
{
"lessThan": "6.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.12.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "6.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "6.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.13.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.14.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nlandlock: Fix LANDLOCK_SCOPE_SIGNAL bypass on the SIGIO path\n\nLANDLOCK_SCOPE_SIGNAL must prevent a sandboxed process from signaling\nprocesses outside its Landlock domain. It can be bypassed through the\nasynchronous SIGIO delivery path.\n\nA sandboxed process that owns any file or socket can arm it with\nfcntl(fd, F_SETOWN, -pgid), fcntl(fd, F_SETSIG, SIGKILL) and O_ASYNC, so\nthat an I/O event makes the kernel deliver the chosen signal to the\nwhole process group. As the head of its process group\u0027s task list (the\ndefault position right after fork()) that group can also hold the\nnon-sandboxed process that launched it, e.g. a supervisor or a security\nmonitor. The sandbox can thus kill or signal the processes\nLANDLOCK_SCOPE_SIGNAL is meant to protect from it.\n\nThe scope is enforced in hook_file_send_sigiotask() against the Landlock\ndomain recorded at F_SETOWN time, not the live domain of the sender.\ncontrol_current_fowner() decides whether to record that domain and skips\nrecording it when the fowner target is in the caller\u0027s thread group,\nwhich is safe only for a single-task target (PIDTYPE_PID, PIDTYPE_TGID).\nFor a process group (PIDTYPE_PGID) pid_task() returns only one member;\nrecording is skipped whenever that member shares the caller\u0027s thread\ngroup, and hook_file_send_sigiotask() then lets the signal fan out to\nthe whole group unchecked.\n\nRecord the domain for every non single-process target so the scope is\nenforced against each group member at delivery time.\n\nThat recording is necessary but not sufficient on its own: the kernel\nsignals a process group through its members\u0027 thread-group leaders, and\nthe leader of the registrant\u0027s own process can carry a different\nLandlock domain than the sibling thread that armed the owner.\ndomain_is_scoped() would then deny that leader, even though commit\n18eb75f3af40 (\"landlock: Always allow signals between threads of the\nsame process\") requires same-process delivery to be allowed.\nhook_task_kill() avoids this by evaluating same_thread_group() live, per\nrecipient; the SIGIO path instead delegates the whole decision to a\nsingle registration-time check, which a process-group fan-out cannot\nhonor.\n\nSo also record the registrant\u0027s thread group next to its domain and\nexempt it at delivery: hook_file_send_sigiotask() allows the signal\nwhenever the recipient belongs to the registrant\u0027s own process,\nrestoring the same-process guarantee while keeping out-of-domain group\nmembers blocked. The direct kill() path (hook_task_kill) already\nevaluates the live domain and is unaffected.\n\n[mic: Check pid_type earlier and improve comment, fix commit message,\nfix comment formatting]"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.4,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires local syscalls (fcntl F_SETOWN/F_SETSIG/F_SETFL, landlock_restrict_self, and pipe or socket I/O); the bug is in hook_file_send_sigiotask() on the SIGIO path with no network, Bluetooth, or physical entry point.\nAC:L - The attacker controls every step (fork into the launcher process group, apply LANDLOCK_SCOPE_SIGNAL, arm O_ASYNC with -pgid, trigger I/O); the upstream selftest reproduces the bypass deterministically with no race or layout dependency.\nPR:L - Only an ordinary local user running inside a Landlock sandbox with LANDLOCK_SCOPE_SIGNAL is needed; landlock_restrict_self() and fcntl() require no capabilities (selftests call drop_caps()), matching other Landlock CVE scoring.\nUI:N - The exploited supervisor or monitor is the attacker\u0027s own parent in the shared process group; escalation is driven entirely by the sandboxed process\u0027s syscalls with no separate victim interaction.\nS:C - This bypasses LANDLOCK_SCOPE_SIGNAL, letting a confined process signal or SIGKILL tasks outside its Landlock domain (e.g., the unsandboxed launcher), crossing the sandbox security authority like CVE-2024-42318.\nC:N - The flaw only skips signal-scope enforcement on asynchronous SIGIO delivery; it does not read kernel or victim memory or leak pointers, and no confidentiality primitive is created even with arbitrary signal choice.\nI:H - A sandboxed attacker can deliver arbitrary signals including SIGKILL to every out-of-domain process group member reachable via fcntl(F_SETOWN,-pgid)/O_ASYNC, completely defeating the integrity of LANDLOCK_SCOPE_SIGNAL protections.\nA:H - SIGKILL (explicitly shown in the fix commit) or other fatal/control signals terminate the supervisor, security monitor, or peer processes the policy was meant to isolate, causing high availability loss."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:41:13.731Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/7a92e9fd1d496a610b40e0c4253fd54e7496f5ab"
},
{
"url": "https://git.kernel.org/stable/c/1f18aac2637220b5847d073447498e81ddca10b2"
},
{
"url": "https://git.kernel.org/stable/c/04916f7dc6d37cd478b06c86398c34a6963ac8c9"
},
{
"url": "https://git.kernel.org/stable/c/4b80320ca7ed03d6e683f95b6066565dc97b9f92"
}
],
"title": "landlock: Fix LANDLOCK_SCOPE_SIGNAL bypass on the SIGIO path",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72183",
"datePublished": "2026-08-15T05:53:45.922Z",
"dateReserved": "2026-08-09T03:40:39.910Z",
"dateUpdated": "2026-08-17T05:41:13.731Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68155 (GCVE-0-2026-68155)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
libceph: Reject monmaps advertising zero monitors
A message of type CEPH_MSG_MON_MAP contains a monmap that is sent from a
monitor to the client. This monmap contains information about the
existing monitors in the cluster. Currently, a monmap indicating that
there are zero monitors in the cluster is treated as valid. However, it
is impossible to have zero monitors in the cluster and still receive a
valid monmap from a monitor. Therefore, such a monmap must be corrupted
and should be treated as invalid. Furthermore, a monmap with a monitor
count of zero can subsequently crash the client when attempting to open
a session with a monitor in __open_session(). This happens because the
"BUG_ON(monc->monmap->num_mon < 1)" assertion in pick_new_mon() is
triggered.
This patch extends a check in ceph_monmap_decode() to also reject
arriving mon_maps with num_mon == 0 rather than only with
num_mon > CEPH_MAX_MON.
[ idryomov: drop "log output for unusual values of num_mon" part ]
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ba75bb98cfb93b62c54af25bf67ff90857264bbe Version: ba75bb98cfb93b62c54af25bf67ff90857264bbe Version: ba75bb98cfb93b62c54af25bf67ff90857264bbe Version: ba75bb98cfb93b62c54af25bf67ff90857264bbe Version: ba75bb98cfb93b62c54af25bf67ff90857264bbe Version: ba75bb98cfb93b62c54af25bf67ff90857264bbe Version: ba75bb98cfb93b62c54af25bf67ff90857264bbe |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ceph/mon_client.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "caf082ef8609a6ac26159ce115f55ab7d00231a3",
"status": "affected",
"version": "ba75bb98cfb93b62c54af25bf67ff90857264bbe",
"versionType": "git"
},
{
"lessThan": "e3ccd4ecab09b22f507f49cb7ed9990c7158ceab",
"status": "affected",
"version": "ba75bb98cfb93b62c54af25bf67ff90857264bbe",
"versionType": "git"
},
{
"lessThan": "0591a15815b498be628a937146e44487d599ba33",
"status": "affected",
"version": "ba75bb98cfb93b62c54af25bf67ff90857264bbe",
"versionType": "git"
},
{
"lessThan": "cd0d41bc569632eaaeccde9d2a6bc919ec00c407",
"status": "affected",
"version": "ba75bb98cfb93b62c54af25bf67ff90857264bbe",
"versionType": "git"
},
{
"lessThan": "e67e8b694872c9bc66996040f9de9242f6236ed9",
"status": "affected",
"version": "ba75bb98cfb93b62c54af25bf67ff90857264bbe",
"versionType": "git"
},
{
"lessThan": "3b249546f59c3d6d3592c10657f82bc3f1faa07c",
"status": "affected",
"version": "ba75bb98cfb93b62c54af25bf67ff90857264bbe",
"versionType": "git"
},
{
"lessThan": "40480eee361ed9676b3f844d532ac28b47251634",
"status": "affected",
"version": "ba75bb98cfb93b62c54af25bf67ff90857264bbe",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ceph/mon_client.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.34"
},
{
"lessThan": "2.6.34",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.34",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: Reject monmaps advertising zero monitors\n\nA message of type CEPH_MSG_MON_MAP contains a monmap that is sent from a\nmonitor to the client. This monmap contains information about the\nexisting monitors in the cluster. Currently, a monmap indicating that\nthere are zero monitors in the cluster is treated as valid. However, it\nis impossible to have zero monitors in the cluster and still receive a\nvalid monmap from a monitor. Therefore, such a monmap must be corrupted\nand should be treated as invalid. Furthermore, a monmap with a monitor\ncount of zero can subsequently crash the client when attempting to open\na session with a monitor in __open_session(). This happens because the\n\"BUG_ON(monc-\u003emonmap-\u003enum_mon \u003c 1)\" assertion in pick_new_mon() is\ntriggered.\n\nThis patch extends a check in ceph_monmap_decode() to also reject\narriving mon_maps with num_mon == 0 rather than only with\nnum_mon \u003e CEPH_MAX_MON.\n\n[ idryomov: drop \"log output for unusual values of num_mon\" part ]"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug is reached when libceph decodes CEPH_MSG_MON_MAP from a remote Ceph monitor over the kernel client\u0027s established TCP/msgr2 session (mon_dispatch -\u003e ceph_monc_handle_map -\u003e ceph_monmap_decode), which is a network protocol attack surface on CephFS/RBD/cloud nodes.\nAC:L - An attacker who can send monitor protocol messages only needs to set num_mon=0 in the monmap; once accepted, any later session reopen (keepalive timeout, hunt, or connection fault) deterministically hits BUG_ON in pick_new_mon without races or special memory layout.\nPR:N - In the highest-impact scenario a malicious or compromised Ceph monitor (or equivalent authenticated cluster peer) sends the malformed monmap to already-connected kernel clients; the attacker needs no local privileges on the victim host.\nUI:N - After a Ceph client session exists, monmap updates are delivered and processed automatically by the kernel monitor client; no further mount, open, or other victim interaction is required to accept the bad map and later crash on reconnect.\nS:U - Exploitation causes a kernel BUG/panic within the same kernel security domain and does not cross VM, container, IOMMU, or other security boundaries.\nC:N - The failure mode is a BUG_ON assertion in pick_new_mon when num_mon is zero; there is no memory corruption, out-of-bounds access, or other information disclosure primitive on the vulnerable path.\nI:N - Accepting num_mon==0 only stores an empty monmap and later triggers a deliberate kernel BUG; attacker input does not corrupt or modify arbitrary kernel memory or enable code execution.\nA:H - BUG_ON(monc-\u003emonmap-\u003enum_mon \u003c 1) in pick_new_mon during __open_session causes a kernel oops/panic, fully denying availability of the affected host until reboot."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:30:22.933Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/caf082ef8609a6ac26159ce115f55ab7d00231a3"
},
{
"url": "https://git.kernel.org/stable/c/e3ccd4ecab09b22f507f49cb7ed9990c7158ceab"
},
{
"url": "https://git.kernel.org/stable/c/0591a15815b498be628a937146e44487d599ba33"
},
{
"url": "https://git.kernel.org/stable/c/cd0d41bc569632eaaeccde9d2a6bc919ec00c407"
},
{
"url": "https://git.kernel.org/stable/c/e67e8b694872c9bc66996040f9de9242f6236ed9"
},
{
"url": "https://git.kernel.org/stable/c/3b249546f59c3d6d3592c10657f82bc3f1faa07c"
},
{
"url": "https://git.kernel.org/stable/c/40480eee361ed9676b3f844d532ac28b47251634"
}
],
"title": "libceph: Reject monmaps advertising zero monitors",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68155",
"datePublished": "2026-08-10T11:59:21.200Z",
"dateReserved": "2026-07-30T09:28:09.371Z",
"dateUpdated": "2026-08-19T16:30:22.933Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64584 (GCVE-0-2026-64584)
Vulnerability from cvelistv5
Published
2026-08-06 07:06
Modified
2026-08-19 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: f_midi: cancel pending IN work before freeing the midi object
The f_midi driver embeds a work item (midi->work) whose handler,
f_midi_in_work(), dereferences the enclosing struct f_midi through
container_of(). This work is armed from two sites: f_midi_complete(),
on a normal IN-endpoint completion, and f_midi_in_trigger(), on an ALSA
rawmidi output-stream start.
Neither f_midi_disable() nor f_midi_unbind() cancels midi->work.
f_midi_disable() only disables the endpoints and drains the in_req_fifo;
it does not synchronize the work item, and the sound card is released
asynchronously to the final free of the midi object.
The midi object is reference-counted (midi->free_ref) and is freed in
f_midi_free() only once both the usb_function reference and the rawmidi
private_data reference have been dropped. In f_midi_unbind(),
f_midi_disable() runs before the sound card is released, so while the
USB endpoints are already disabled the rawmidi device is still usable by
an open substream. A concurrent userspace write on such a substream can
reach f_midi_in_trigger() and queue midi->work again after
f_midi_disable() has returned. A work item armed this way may still be
pending when the last reference drops and f_midi_free() proceeds to
kfree(midi), letting f_midi_in_work() dereference the struct after it
has been freed, a use-after-free.
For this reason cancelling midi->work in f_midi_disable() would not be
sufficient: the ALSA trigger path can rearm the work after disable()
returns. Cancelling at the refcount-zero free site is the boundary
after which neither arming source can survive, because by then both
references that keep the midi object alive have been dropped: the USB
endpoints are already disabled and the rawmidi device has been released.
Fix this by calling cancel_work_sync(&midi->work) in the refcount-zero
block of f_midi_free(), before the embedded work_struct is freed along
with the rest of the structure. opts->lock is a sleeping mutex, so
calling cancel_work_sync() under it is permitted, and the handler takes
midi->transmit_lock rather than opts->lock, so no self-deadlock can
occur while it waits for a running instance of the work to finish.
This issue was found by an in-house static analysis tool.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 3635523e9b96213969693c320302d536774d8e9b Version: 8653d71ce3763aedcf3d2331f59beda3fecd79e4 Version: 8653d71ce3763aedcf3d2331f59beda3fecd79e4 Version: 8653d71ce3763aedcf3d2331f59beda3fecd79e4 Version: 8653d71ce3763aedcf3d2331f59beda3fecd79e4 Version: 8653d71ce3763aedcf3d2331f59beda3fecd79e4 Version: 8653d71ce3763aedcf3d2331f59beda3fecd79e4 Version: 8653d71ce3763aedcf3d2331f59beda3fecd79e4 Version: 89019ab7a64fcdf98a2ba7799e5c6aff58d4a05d Version: 5.10.235 ≤ Version: 5.4.291 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/gadget/function/f_midi.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "f3c6f2c38062703d3dc7f86958bb0790c6959add",
"status": "affected",
"version": "3635523e9b96213969693c320302d536774d8e9b",
"versionType": "git"
},
{
"lessThan": "df18150126f66817e4d3f79f309e9c92d6ff384e",
"status": "affected",
"version": "8653d71ce3763aedcf3d2331f59beda3fecd79e4",
"versionType": "git"
},
{
"lessThan": "620955b222c47332297d6bf38f78541aa699238a",
"status": "affected",
"version": "8653d71ce3763aedcf3d2331f59beda3fecd79e4",
"versionType": "git"
},
{
"lessThan": "380b4bef46c2eb260c7a9c6bb2c5be33ce5a38f9",
"status": "affected",
"version": "8653d71ce3763aedcf3d2331f59beda3fecd79e4",
"versionType": "git"
},
{
"lessThan": "87bc316dd6fc90072297c635e10b9aa6075ecda1",
"status": "affected",
"version": "8653d71ce3763aedcf3d2331f59beda3fecd79e4",
"versionType": "git"
},
{
"lessThan": "f45089eaad0a083d71d84ff175741d7e157d9b69",
"status": "affected",
"version": "8653d71ce3763aedcf3d2331f59beda3fecd79e4",
"versionType": "git"
},
{
"lessThan": "ac9a51d910bb7465c554c45320cb6c09f3d0b49d",
"status": "affected",
"version": "8653d71ce3763aedcf3d2331f59beda3fecd79e4",
"versionType": "git"
},
{
"lessThan": "5650c18d93a1db7e27cb5a40b394747eb4686d5b",
"status": "affected",
"version": "8653d71ce3763aedcf3d2331f59beda3fecd79e4",
"versionType": "git"
},
{
"status": "affected",
"version": "89019ab7a64fcdf98a2ba7799e5c6aff58d4a05d",
"versionType": "git"
},
{
"lessThan": "5.10.265",
"status": "affected",
"version": "5.10.235",
"versionType": "semver"
},
{
"lessThan": "5.5",
"status": "affected",
"version": "5.4.291",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/usb/gadget/function/f_midi.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.12"
},
{
"lessThan": "5.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.10.235",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.4.291",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: f_midi: cancel pending IN work before freeing the midi object\n\nThe f_midi driver embeds a work item (midi-\u003ework) whose handler,\nf_midi_in_work(), dereferences the enclosing struct f_midi through\ncontainer_of(). This work is armed from two sites: f_midi_complete(),\non a normal IN-endpoint completion, and f_midi_in_trigger(), on an ALSA\nrawmidi output-stream start.\n\nNeither f_midi_disable() nor f_midi_unbind() cancels midi-\u003ework.\nf_midi_disable() only disables the endpoints and drains the in_req_fifo;\nit does not synchronize the work item, and the sound card is released\nasynchronously to the final free of the midi object.\n\nThe midi object is reference-counted (midi-\u003efree_ref) and is freed in\nf_midi_free() only once both the usb_function reference and the rawmidi\nprivate_data reference have been dropped. In f_midi_unbind(),\nf_midi_disable() runs before the sound card is released, so while the\nUSB endpoints are already disabled the rawmidi device is still usable by\nan open substream. A concurrent userspace write on such a substream can\nreach f_midi_in_trigger() and queue midi-\u003ework again after\nf_midi_disable() has returned. A work item armed this way may still be\npending when the last reference drops and f_midi_free() proceeds to\nkfree(midi), letting f_midi_in_work() dereference the struct after it\nhas been freed, a use-after-free.\n\nFor this reason cancelling midi-\u003ework in f_midi_disable() would not be\nsufficient: the ALSA trigger path can rearm the work after disable()\nreturns. Cancelling at the refcount-zero free site is the boundary\nafter which neither arming source can survive, because by then both\nreferences that keep the midi object alive have been dropped: the USB\nendpoints are already disabled and the rawmidi device has been released.\n\nFix this by calling cancel_work_sync(\u0026midi-\u003ework) in the refcount-zero\nblock of f_midi_free(), before the embedded work_struct is freed along\nwith the rest of the structure. opts-\u003elock is a sleeping mutex, so\ncalling cancel_work_sync() under it is permitted, and the handler takes\nmidi-\u003etransmit_lock rather than opts-\u003elock, so no self-deadlock can\noccur while it waits for a running instance of the work to finish.\n\nThis issue was found by an in-house static analysis tool."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The UAF is reached by local configfs UDC clear or function unlink (unregister_gadget \u2192 f_midi_unbind/disable) plus ALSA rawmidi write/close on /dev/snd/midi*; no USB host traffic or cable access is required, and dummy_hcd suffices, matching other gadget teardown UAFs scored AV:L.\nAC:L - The attacker controls both sides of the race: opening/writing the rawmidi substream to queue midi-\u003ework via f_midi_in_trigger after disable, and forcing unbind plus dropping the last free_ref via configfs unlink/close, so the window is freely repeatable.\nPR:L - Exploitation needs access to the gadget configfs tree and/or the ALSA MIDI node; both are routinely delegated to non-root system/audio accounts on Android and embedded MIDI gadgets, with no capability check on the rawmidi write or UDC store path itself.\nUI:N - The attacker performs the full sequence\u2014configfs unbind/unlink, rawmidi write to rearm work, and close to free the midi object\u2014without any action by another user or administrator.\nS:U - The use-after-free corrupts kernel heap within the same kernel security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - f_midi_in_work() container_of()s the freed embedded work_struct and then reads midi-\u003ein_ep, fifo, and port/substream fields; reclaiming the freed f_midi slab yields a classic UAF read/disclosure primitive.\nI:H - Post-free f_midi_transmit()/f_midi_drop_out_substreams() write through the reclaimed object (port state, kfifo, snd_rawmidi_drop_output), giving a heap write-after-free primitive suitable for control-flow hijack.\nA:H - Dereferencing the freed f_midi from system_highpri_wq reliably produces KASAN reports, oops, or kernel panic even without full exploitation."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:29:12.890Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/f3c6f2c38062703d3dc7f86958bb0790c6959add"
},
{
"url": "https://git.kernel.org/stable/c/df18150126f66817e4d3f79f309e9c92d6ff384e"
},
{
"url": "https://git.kernel.org/stable/c/620955b222c47332297d6bf38f78541aa699238a"
},
{
"url": "https://git.kernel.org/stable/c/380b4bef46c2eb260c7a9c6bb2c5be33ce5a38f9"
},
{
"url": "https://git.kernel.org/stable/c/87bc316dd6fc90072297c635e10b9aa6075ecda1"
},
{
"url": "https://git.kernel.org/stable/c/f45089eaad0a083d71d84ff175741d7e157d9b69"
},
{
"url": "https://git.kernel.org/stable/c/ac9a51d910bb7465c554c45320cb6c09f3d0b49d"
},
{
"url": "https://git.kernel.org/stable/c/5650c18d93a1db7e27cb5a40b394747eb4686d5b"
}
],
"title": "usb: gadget: f_midi: cancel pending IN work before freeing the midi object",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64584",
"datePublished": "2026-08-06T07:06:25.953Z",
"dateReserved": "2026-07-19T15:36:31.798Z",
"dateUpdated": "2026-08-19T16:29:12.890Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68398 (GCVE-0-2026-68398)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF
pppol2tp_recv() runs in the L2TP UDP-encap softirq RX path:
l2tp_udp_encap_recv() -> l2tp_recv_common() -> pppol2tp_recv()
-> ppp_input(&po->chan)
It runs under rcu_read_lock() holding only an l2tp_session reference and
takes NO reference on the internal PPP channel (struct channel,
chan->ppp) that ppp_input() dereferences.
The pppox socket is SOCK_RCU_FREE, so 'po' and the embedded ppp_channel
are RCU-safe. But the internal struct channel is a separate allocation
that ppp_release_channel() frees with a plain kfree():
close(data socket) -> pppol2tp_release() -> pppox_unbind_sock()
-> ppp_unregister_channel() -> ppp_release_channel() -> kfree(pch)
For a channel that is bound (PPPIOCGCHAN) but not attached to a ppp unit
(no PPPIOCCONNECT, pch->ppp == NULL) and not bridged, teardown skips
both ppp_disconnect_channel()'s synchronize_net() and
ppp_unbridge_channels()'s synchronize_rcu(), so the kfree() has no grace
period. rcu_read_lock() in pppol2tp_recv() does not protect against a
plain kfree(), so an in-flight ppp_input() on one CPU can dereference
the channel just freed by close() on another CPU.
The bug is reachable by an unprivileged user.
Defer the channel free to an RCU callback via call_rcu() so the grace
period fences any in-flight ppp_input(). The disconnect and unbridge
teardown paths already fence with synchronize_net()/synchronize_rcu();
call_rcu() does the same here without stalling the close() path.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ee40fb2e1eb5bc0ddd3f2f83c6e39a454ef5a741 Version: ee40fb2e1eb5bc0ddd3f2f83c6e39a454ef5a741 Version: ee40fb2e1eb5bc0ddd3f2f83c6e39a454ef5a741 Version: ee40fb2e1eb5bc0ddd3f2f83c6e39a454ef5a741 Version: ee40fb2e1eb5bc0ddd3f2f83c6e39a454ef5a741 Version: ee40fb2e1eb5bc0ddd3f2f83c6e39a454ef5a741 Version: ee40fb2e1eb5bc0ddd3f2f83c6e39a454ef5a741 Version: d36e5ba7bbed5d7bd26e8609ffed503c2def401b Version: 9bcc0508576b2d50efd958f2ea1c5906749c2c89 Version: c2984681fe15cfb803a9132aaaf1140ab20a72c1 Version: 5803ecd7f6ac6f747582e775caa62ac9d0489261 Version: 26f8819ddd10141ebe7bbce700fbab36bfa5f478 Version: 3.2.99 ≤ Version: 3.16.54 ≤ Version: 4.4.225 ≤ Version: 4.9.225 ≤ Version: 4.14.182 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ppp/ppp_generic.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "4e47f1ac188ece11d6fdabe44166a2776cc5bd4e",
"status": "affected",
"version": "ee40fb2e1eb5bc0ddd3f2f83c6e39a454ef5a741",
"versionType": "git"
},
{
"lessThan": "110b765744b147c63882f5e9cb12931c5dc8d85f",
"status": "affected",
"version": "ee40fb2e1eb5bc0ddd3f2f83c6e39a454ef5a741",
"versionType": "git"
},
{
"lessThan": "4bb84e964ff0fe0a171c965362de72f9820dbce9",
"status": "affected",
"version": "ee40fb2e1eb5bc0ddd3f2f83c6e39a454ef5a741",
"versionType": "git"
},
{
"lessThan": "3ab32218d7182705dae5c86f13925f458072da2c",
"status": "affected",
"version": "ee40fb2e1eb5bc0ddd3f2f83c6e39a454ef5a741",
"versionType": "git"
},
{
"lessThan": "c9574b8a8edeb4edd3ac6472c27ef7184bdb2baa",
"status": "affected",
"version": "ee40fb2e1eb5bc0ddd3f2f83c6e39a454ef5a741",
"versionType": "git"
},
{
"lessThan": "06213c85d8c0994f786c093b8b2a517987943ca6",
"status": "affected",
"version": "ee40fb2e1eb5bc0ddd3f2f83c6e39a454ef5a741",
"versionType": "git"
},
{
"lessThan": "ec4215683e47424c9c4762fd3c60f552a3119142",
"status": "affected",
"version": "ee40fb2e1eb5bc0ddd3f2f83c6e39a454ef5a741",
"versionType": "git"
},
{
"status": "affected",
"version": "d36e5ba7bbed5d7bd26e8609ffed503c2def401b",
"versionType": "git"
},
{
"status": "affected",
"version": "9bcc0508576b2d50efd958f2ea1c5906749c2c89",
"versionType": "git"
},
{
"status": "affected",
"version": "c2984681fe15cfb803a9132aaaf1140ab20a72c1",
"versionType": "git"
},
{
"status": "affected",
"version": "5803ecd7f6ac6f747582e775caa62ac9d0489261",
"versionType": "git"
},
{
"status": "affected",
"version": "26f8819ddd10141ebe7bbce700fbab36bfa5f478",
"versionType": "git"
},
{
"lessThan": "3.3",
"status": "affected",
"version": "3.2.99",
"versionType": "semver"
},
{
"lessThan": "3.17",
"status": "affected",
"version": "3.16.54",
"versionType": "semver"
},
{
"lessThan": "4.5",
"status": "affected",
"version": "4.4.225",
"versionType": "semver"
},
{
"lessThan": "4.10",
"status": "affected",
"version": "4.9.225",
"versionType": "semver"
},
{
"lessThan": "4.15",
"status": "affected",
"version": "4.14.182",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ppp/ppp_generic.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.15"
},
{
"lessThan": "4.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.2.99",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.16.54",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.4.225",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.9.225",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.14.182",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF\n\npppol2tp_recv() runs in the L2TP UDP-encap softirq RX path:\n\n l2tp_udp_encap_recv() -\u003e l2tp_recv_common() -\u003e pppol2tp_recv()\n -\u003e ppp_input(\u0026po-\u003echan)\n\nIt runs under rcu_read_lock() holding only an l2tp_session reference and\ntakes NO reference on the internal PPP channel (struct channel,\nchan-\u003eppp) that ppp_input() dereferences.\n\nThe pppox socket is SOCK_RCU_FREE, so \u0027po\u0027 and the embedded ppp_channel\nare RCU-safe. But the internal struct channel is a separate allocation\nthat ppp_release_channel() frees with a plain kfree():\n\n close(data socket) -\u003e pppol2tp_release() -\u003e pppox_unbind_sock()\n -\u003e ppp_unregister_channel() -\u003e ppp_release_channel() -\u003e kfree(pch)\n\nFor a channel that is bound (PPPIOCGCHAN) but not attached to a ppp unit\n(no PPPIOCCONNECT, pch-\u003eppp == NULL) and not bridged, teardown skips\nboth ppp_disconnect_channel()\u0027s synchronize_net() and\nppp_unbridge_channels()\u0027s synchronize_rcu(), so the kfree() has no grace\nperiod. rcu_read_lock() in pppol2tp_recv() does not protect against a\nplain kfree(), so an in-flight ppp_input() on one CPU can dereference\nthe channel just freed by close() on another CPU.\n\nThe bug is reachable by an unprivileged user.\n\nDefer the channel free to an RCU callback via call_rcu() so the grace\nperiod fences any in-flight ppp_input(). The disconnect and unbridge\nteardown paths already fence with synchronize_net()/synchronize_rcu();\ncall_rcu() does the same here without stalling the close() path."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The free side of the race is a local close() of the pppol2tp socket, which no remote peer can invoke; the full attack (create tunnel/session via AF_PPPOX socket, drive RX with loopback UDP datagrams, close concurrently) is performed entirely through local syscalls.\nAC:L - The attacker controls both sides of the race, feeding the UDP-encap RX softirq from one thread while closing the pppox socket on another, and can retry the loop indefinitely until the window is hit.\nPR:L - No capability check exists on this path: pppox_create()/pppol2tp_connect() and ppp_register_net_channel() need no CAP_NET_ADMIN, and PPPIOCGCHAN is handled by pppox_ioctl() on the socket itself, so /dev/ppp access is not required; the fix commit states the bug is reachable by an unprivileged user.\nUI:N - The attacker performs every step \u2014 socket creation, session setup, packet injection and close() \u2014 with no action by any other user or administrator.\nS:U - The use-after-free corrupts kernel slab memory within the same kernel security authority; no VM, IOMMU or sandbox boundary is crossed.\nC:H - After the channel is freed and its slab object reallocated, ppp_input() reads pch-\u003ebridge and pch-\u003eppp from attacker-groomed memory and can route received frames to an arbitrary attacker-chosen structure, giving a path to disclosing kernel memory.\nI:H - skb_queue_tail(\u0026pch-\u003efile.rq, skb) writes a linked-list insertion into the freed object and wake_up_interruptible(\u0026pch-\u003efile.rwait) traverses a freed waitqueue, so heap grooming yields controlled writes and function-pointer traversal usable for privilege escalation.\nA:H - Dereferencing and writing to the kfree()d struct channel from softirq context reliably corrupts the slab and panics or oopses the kernel, and the race can be re-triggered at will."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:49.839Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/4e47f1ac188ece11d6fdabe44166a2776cc5bd4e"
},
{
"url": "https://git.kernel.org/stable/c/110b765744b147c63882f5e9cb12931c5dc8d85f"
},
{
"url": "https://git.kernel.org/stable/c/4bb84e964ff0fe0a171c965362de72f9820dbce9"
},
{
"url": "https://git.kernel.org/stable/c/3ab32218d7182705dae5c86f13925f458072da2c"
},
{
"url": "https://git.kernel.org/stable/c/c9574b8a8edeb4edd3ac6472c27ef7184bdb2baa"
},
{
"url": "https://git.kernel.org/stable/c/06213c85d8c0994f786c093b8b2a517987943ca6"
},
{
"url": "https://git.kernel.org/stable/c/ec4215683e47424c9c4762fd3c60f552a3119142"
}
],
"title": "ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68398",
"datePublished": "2026-08-10T12:04:17.771Z",
"dateReserved": "2026-07-30T09:28:09.389Z",
"dateUpdated": "2026-08-19T16:34:49.839Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68128 (GCVE-0-2026-68128)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-17 04:59
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ice: reject out-of-range ptype in ice_parser_profile_init
set_bit(rslt->ptype, prof->ptypes) operates on a DECLARE_BITMAP of
ICE_FLOW_PTYPE_MAX (1024) bits. Nothing prevents a malicious VF from
providing ptype >= 1024 through VIRTCHNL, resulting in a write past
the end of the bitmap and a kernel page fault.
Reproduced with a custom kernel module injecting a crafted
VIRTCHNL_OP_ADD_RSS_CFG on E810-C QSFP (8086:1592),
FW 4.91 0x800214af 1.3909.0, ICE COMMS DDP 1.3.53.0,
kernel 7.1.0-rc1.
crash_parser: ice_parser_profile_init @ ffffffffc0d61b60
crash_parser: setting ptype=0xffff (max valid=1023)
crash_parser: calling ice_parser_profile_init -- expect OOB crash!
BUG: kernel NULL pointer dereference, address: 0000000000000000
Oops: Oops: 0002 [#1] SMP NOPTI
CPU: 56 UID: 0 PID: 165011 Comm: insmod Kdump: loaded Tainted: G S U OE 7.1.0-rc1 #1
Hardware name: Intel Corporation S2600BPB/S2600BPB
RIP: 0010:ice_parser_profile_init+0x2d/0x1d0 [ice]
Call Trace:
<TASK>
? __pfx_ice_parser_profile_init+0x10/0x10 [ice]
crash_init+0x127/0xff0 [crash_parser]
do_one_initcall+0x45/0x310
do_init_module+0x64/0x270
init_module_from_file+0xcc/0xf0
idempotent_init_module+0x17b/0x280
__x64_sys_finit_module+0x6e/0xe0
Bail out early with -EINVAL when ptype is out of range.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/intel/ice/ice_parser.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "fe2f8d5a77adea38e889fe3d6cde1b76d4a635bf",
"status": "affected",
"version": "e312b3a1e2092f612914dbc4fa5d96b4d8ff94ef",
"versionType": "git"
},
{
"lessThan": "5e496f2b615cec4b45537cfb5b54f36a51dc8753",
"status": "affected",
"version": "e312b3a1e2092f612914dbc4fa5d96b4d8ff94ef",
"versionType": "git"
},
{
"lessThan": "33cc15aaf2491166dddc018b24b3b7db53ec01b2",
"status": "affected",
"version": "e312b3a1e2092f612914dbc4fa5d96b4d8ff94ef",
"versionType": "git"
},
{
"lessThan": "59abb87159c53605c063f6e2ceb215b5eba43ee6",
"status": "affected",
"version": "e312b3a1e2092f612914dbc4fa5d96b4d8ff94ef",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/intel/ice/ice_parser.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.12"
},
{
"lessThan": "6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nice: reject out-of-range ptype in ice_parser_profile_init\n\nset_bit(rslt-\u003eptype, prof-\u003eptypes) operates on a DECLARE_BITMAP of\nICE_FLOW_PTYPE_MAX (1024) bits. Nothing prevents a malicious VF from\nproviding ptype \u003e= 1024 through VIRTCHNL, resulting in a write past\nthe end of the bitmap and a kernel page fault.\n\nReproduced with a custom kernel module injecting a crafted\nVIRTCHNL_OP_ADD_RSS_CFG on E810-C QSFP (8086:1592),\nFW 4.91 0x800214af 1.3909.0, ICE COMMS DDP 1.3.53.0,\nkernel 7.1.0-rc1.\n\ncrash_parser: ice_parser_profile_init @ ffffffffc0d61b60\ncrash_parser: setting ptype=0xffff (max valid=1023)\ncrash_parser: calling ice_parser_profile_init -- expect OOB crash!\nBUG: kernel NULL pointer dereference, address: 0000000000000000\nOops: Oops: 0002 [#1] SMP NOPTI\nCPU: 56 UID: 0 PID: 165011 Comm: insmod Kdump: loaded Tainted: G S U OE 7.1.0-rc1 #1\nHardware name: Intel Corporation S2600BPB/S2600BPB\nRIP: 0010:ice_parser_profile_init+0x2d/0x1d0 [ice]\nCall Trace:\n \u003cTASK\u003e\n ? __pfx_ice_parser_profile_init+0x10/0x10 [ice]\n crash_init+0x127/0xff0 [crash_parser]\n do_one_initcall+0x45/0x310\n do_init_module+0x64/0x270\n init_module_from_file+0xcc/0xf0\n idempotent_init_module+0x17b/0x280\n __x64_sys_finit_module+0x6e/0xe0\n\nBail out early with -EINVAL when ptype is out of range."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires a malicious SR-IOV VF (or guest with VF passthrough) to send VIRTCHNL_OP_ADD_RSS_CFG/ADD_FDIR_FILTER mailbox messages to the host PF driver; this is local device/mailbox access, not remote network packet processing.\nAC:L - A VF can craft a raw RSS/FDIR packet pattern that leaves ice_ptype_resolve() returning U16_MAX (0xFFFF); set_bit() then deterministically indexes far past the 1024-bit prof-\u003eptypes bitmap with no attacker-uncontrollable race or layout dependency.\nPR:L - Attack requires control of an assigned E810 VF, typically as a cloud tenant VM with netdev admin capability or a VFIO-delegated process; this is low privilege relative to the host (not init-namespace root), mirroring similar SR-IOV VF bugs.\nUI:N - The attacker sends their own VIRTCHNL configuration message (or loads a guest kernel module to do so); no separate victim-user interaction is required beyond routine VF assignment already present in SR-IOV deployments.\nS:C - In virtualized/cloud deployments (the primary E810 use case), a malicious guest VF corrupts host kernel stack memory in the PF driver, crossing the guest-to-host isolation boundary analogous to KVM/SR-IOV escape class bugs.\nC:H - The out-of-bounds set_bit() stack write corrupts kernel memory far beyond the 128-byte ptypes bitmap; such uncontrolled memory corruption is leverageable for kernel information disclosure in an exploit chain.\nI:H - set_bit(0xFFFF, prof-\u003eptypes) performs an arbitrary out-of-bounds stack write (~8 KB past the bitmap on x86_64), providing memory corruption primitives potentially usable for host kernel code execution.\nA:H - The bug was reproduced causing a NULL-pointer kernel oops/page fault in ice_parser_profile_init(); reliable triggering from a malicious VF can panic or lock up the host PF kernel."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:59:19.746Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/fe2f8d5a77adea38e889fe3d6cde1b76d4a635bf"
},
{
"url": "https://git.kernel.org/stable/c/5e496f2b615cec4b45537cfb5b54f36a51dc8753"
},
{
"url": "https://git.kernel.org/stable/c/33cc15aaf2491166dddc018b24b3b7db53ec01b2"
},
{
"url": "https://git.kernel.org/stable/c/59abb87159c53605c063f6e2ceb215b5eba43ee6"
}
],
"title": "ice: reject out-of-range ptype in ice_parser_profile_init",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68128",
"datePublished": "2026-08-10T11:58:50.013Z",
"dateReserved": "2026-07-30T09:28:09.370Z",
"dateUpdated": "2026-08-17T04:59:19.746Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68419 (GCVE-0-2026-68419)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-17 05:05
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
RDMA/irdma: Prevent rereg_mr for non-mem regions
When a QP/CQ/SRQ is created, a two step process is used
where the buffer is allocated in userspace and explicitly
registered with the normal reg_mr mechanism prior to creating
the actual QP/CQ/SRQ object.
These special registrations are indicated via an ABI field
so the driver knows that they do not have a valid mkey and
to skip the actual CQP command submission.
Since these are real MR objects from the core's perspective,
it is possible for a user application to invoke rereg_mr on them
and cause a real CQP op to be emitted with the zero-initialized
mkey value of 0.
Fix this by preventing rereg_mr on these special regions.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 715fdb3b30541cc8180b7cdc6aa9f8c307afdf25 Version: 5ac388db27c443dadfbb0b8b23fa7ccf429d901a Version: 5ac388db27c443dadfbb0b8b23fa7ccf429d901a Version: 5ac388db27c443dadfbb0b8b23fa7ccf429d901a Version: 5ac388db27c443dadfbb0b8b23fa7ccf429d901a Version: 6.6.120 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/hw/irdma/verbs.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "fb46d134e1b8690bed2da9005b36d32d2efd34ac",
"status": "affected",
"version": "715fdb3b30541cc8180b7cdc6aa9f8c307afdf25",
"versionType": "git"
},
{
"lessThan": "b5029e91c63406e4f4c8d58161048b41b6f0bd8c",
"status": "affected",
"version": "5ac388db27c443dadfbb0b8b23fa7ccf429d901a",
"versionType": "git"
},
{
"lessThan": "ca1c29f05274b737dc964e28b97803750d7cf7ec",
"status": "affected",
"version": "5ac388db27c443dadfbb0b8b23fa7ccf429d901a",
"versionType": "git"
},
{
"lessThan": "dbaa37e060918c45517786e37ecab0f300b48fa9",
"status": "affected",
"version": "5ac388db27c443dadfbb0b8b23fa7ccf429d901a",
"versionType": "git"
},
{
"lessThan": "a846aecb931b4d65d5eafa92a0623545af46d4f2",
"status": "affected",
"version": "5ac388db27c443dadfbb0b8b23fa7ccf429d901a",
"versionType": "git"
},
{
"lessThan": "6.6.148",
"status": "affected",
"version": "6.6.120",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/hw/irdma/verbs.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.7"
},
{
"lessThan": "6.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.6.120",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/irdma: Prevent rereg_mr for non-mem regions\n\nWhen a QP/CQ/SRQ is created, a two step process is used\nwhere the buffer is allocated in userspace and explicitly\nregistered with the normal reg_mr mechanism prior to creating\nthe actual QP/CQ/SRQ object.\n\nThese special registrations are indicated via an ABI field\nso the driver knows that they do not have a valid mkey and\nto skip the actual CQP command submission.\n\nSince these are real MR objects from the core\u0027s perspective,\nit is possible for a user application to invoke rereg_mr on them\nand cause a real CQP op to be emitted with the zero-initialized\nmkey value of 0.\n\nFix this by preventing rereg_mr on these special regions."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerability is reached through the ib_uverbs REREG_MR command on /dev/infiniband/uverbs*, a local character device; no network input reaches irdma_rereg_user_mr(). The resulting corrupt hardware STAG can later be abused over RDMA, but initial access is local.\nAC:L - The attacker fully controls every precondition: register a buffer with reg_type IRDMA_MEMREG_TYPE_QP/CQ/SRQ, then call rereg_mr on that handle. There is no race, no timing dependency and no reliance on memory layout the attacker cannot influence.\nPR:L - Only an open file descriptor on /dev/infiniband/uverbsN is needed; rdma-core udev rules ship these nodes world-accessible (0666) and they are routinely exposed to containers. ib_uverbs_rereg_mr() performs no capability check, only uobject ownership of the caller\u0027s own MR.\nUI:N - The attacker performs the entire sequence (reg_mr with a non-MEM reg_type, then rereg_mr) from its own process. No action by any other user or administrator is required.\nS:U - The corruption stays within the kernel/RDMA-device security authority managed by the same OS instance; there is no VM, IOMMU or hypervisor boundary crossed by the erroneous CQP command.\nC:H - Programming HW STAG index 0 with attacker-chosen remote-read rights, combined with dereg_mr never invalidating it, leaves a live hardware mapping over PBLEs and umem pages that are freed and reused, giving RDMA-read access to recycled kernel/other-process memory; it can also collide with another process\u0027s MR at stag index 0.\nI:H - The same stale/hijacked STAG can carry IB_ACCESS_REMOTE_WRITE, and the IB_MR_REREG_TRANS path frees the PBLEs and releases the umem of a live QP/CQ/SRQ while hardware keeps DMAing into those pages, yielding device-driven writes into freed and reallocated kernel memory.\nA:H - Issuing a CQP op with a zero mkey corrupts device state and can fail the CQP op, triggering the driver\u0027s reset path; the DMA-after-free into recycled pages and the clobbering of another region\u0027s STAG readily produce kernel memory corruption, oops or full RDMA device reset."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:05:14.336Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/fb46d134e1b8690bed2da9005b36d32d2efd34ac"
},
{
"url": "https://git.kernel.org/stable/c/b5029e91c63406e4f4c8d58161048b41b6f0bd8c"
},
{
"url": "https://git.kernel.org/stable/c/ca1c29f05274b737dc964e28b97803750d7cf7ec"
},
{
"url": "https://git.kernel.org/stable/c/dbaa37e060918c45517786e37ecab0f300b48fa9"
},
{
"url": "https://git.kernel.org/stable/c/a846aecb931b4d65d5eafa92a0623545af46d4f2"
}
],
"title": "RDMA/irdma: Prevent rereg_mr for non-mem regions",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68419",
"datePublished": "2026-08-10T12:04:39.912Z",
"dateReserved": "2026-07-30T09:28:09.391Z",
"dateUpdated": "2026-08-17T05:05:14.336Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68369 (GCVE-0-2026-68369)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: printer: fix infinite loop in printer_read()
printer_read() uses the same variable for the requested copy size and
the number of bytes actually copied to user space. copy_to_user()
returns the number of bytes not copied, so when it fails to copy
anything, the computed copied length becomes zero.
In that case len, buf, current_rx_bytes and current_rx_buf are left
unchanged. If RX data is available and the user buffer remains
unwritable, the read loop can repeat indefinitely.
Track the copied length separately and return -EFAULT, or the number of
bytes already copied, if an iteration makes no progress.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: b185f01a9ab7af586133be2555298e960237359b Version: b185f01a9ab7af586133be2555298e960237359b Version: b185f01a9ab7af586133be2555298e960237359b Version: b185f01a9ab7af586133be2555298e960237359b Version: b185f01a9ab7af586133be2555298e960237359b Version: b185f01a9ab7af586133be2555298e960237359b Version: b185f01a9ab7af586133be2555298e960237359b Version: b185f01a9ab7af586133be2555298e960237359b |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/gadget/function/f_printer.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "3f81197364b57e5318620c75f3bd63f405f60552",
"status": "affected",
"version": "b185f01a9ab7af586133be2555298e960237359b",
"versionType": "git"
},
{
"lessThan": "e225e2998e5a9b83c838dbbe4511fb0d63f88daf",
"status": "affected",
"version": "b185f01a9ab7af586133be2555298e960237359b",
"versionType": "git"
},
{
"lessThan": "3081b0e187065c3b9577e393ad664b12854aeaf3",
"status": "affected",
"version": "b185f01a9ab7af586133be2555298e960237359b",
"versionType": "git"
},
{
"lessThan": "994afccfdcceb73be33f69a8a8ea71e260c9eca5",
"status": "affected",
"version": "b185f01a9ab7af586133be2555298e960237359b",
"versionType": "git"
},
{
"lessThan": "e03597ad9494b500344076589aeaa6c6d2d381d3",
"status": "affected",
"version": "b185f01a9ab7af586133be2555298e960237359b",
"versionType": "git"
},
{
"lessThan": "4cde0b38cc0cb8b7dc17295801015148de37d1d2",
"status": "affected",
"version": "b185f01a9ab7af586133be2555298e960237359b",
"versionType": "git"
},
{
"lessThan": "e41bbbbb1740ce4d7270ab1cdeca13892d6a8d2e",
"status": "affected",
"version": "b185f01a9ab7af586133be2555298e960237359b",
"versionType": "git"
},
{
"lessThan": "c2e819be6a5c7f34344926b4bd7e3dfca58cf48a",
"status": "affected",
"version": "b185f01a9ab7af586133be2555298e960237359b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/usb/gadget/function/f_printer.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.1"
},
{
"lessThan": "4.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: printer: fix infinite loop in printer_read()\n\nprinter_read() uses the same variable for the requested copy size and\nthe number of bytes actually copied to user space. copy_to_user()\nreturns the number of bytes not copied, so when it fails to copy\nanything, the computed copied length becomes zero.\n\nIn that case len, buf, current_rx_bytes and current_rx_buf are left\nunchanged. If RX data is available and the user buffer remains\nunwritable, the read loop can repeat indefinitely.\n\nTrack the copied length separately and return -EFAULT, or the number of\nbytes already copied, if an iteration makes no progress."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:28.812Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/3f81197364b57e5318620c75f3bd63f405f60552"
},
{
"url": "https://git.kernel.org/stable/c/e225e2998e5a9b83c838dbbe4511fb0d63f88daf"
},
{
"url": "https://git.kernel.org/stable/c/3081b0e187065c3b9577e393ad664b12854aeaf3"
},
{
"url": "https://git.kernel.org/stable/c/994afccfdcceb73be33f69a8a8ea71e260c9eca5"
},
{
"url": "https://git.kernel.org/stable/c/e03597ad9494b500344076589aeaa6c6d2d381d3"
},
{
"url": "https://git.kernel.org/stable/c/4cde0b38cc0cb8b7dc17295801015148de37d1d2"
},
{
"url": "https://git.kernel.org/stable/c/e41bbbbb1740ce4d7270ab1cdeca13892d6a8d2e"
},
{
"url": "https://git.kernel.org/stable/c/c2e819be6a5c7f34344926b4bd7e3dfca58cf48a"
}
],
"title": "usb: gadget: printer: fix infinite loop in printer_read()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68369",
"datePublished": "2026-08-10T12:03:46.845Z",
"dateReserved": "2026-07-30T09:28:09.386Z",
"dateUpdated": "2026-08-19T16:34:28.812Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68120 (GCVE-0-2026-68120)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-17 04:59
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
rtase: Workaround for TX hang caused by hardware packet parsing
The hardware performs packet parsing before packet transmission.
Parsing incomplete IPv4, IPv6, TCP, or UDP headers may trigger a TX
hang because the hardware parser expects additional protocol header
data that is not present in the packet.
The hardware performs additional PTP parsing on UDP packets identified
by destination ports 319/320 at the expected UDP destination port
offset.
If such a packet has transport data smaller than RTASE_MIN_PAD_LEN,
the hardware parser expects additional packet data and may trigger a
TX hang.
To avoid these hardware issues, the driver applies the following
workarounds.
Drop malformed packets that may trigger this hardware issue before
transmission.
For IPv4 non-initial fragments, the hardware does not check the
fragment offset before parsing the expected transport header location.
As a result, these packets are still subject to transport header
parsing even though they do not contain a transport header. If the
transport data is shorter than the minimum transport header required
by the hardware parser, pad the transport data to the minimum
transport header length required by the hardware parser. Packets that
also match the hardware PTP parsing conditions continue to follow the
corresponding workaround.
For IPv6 fragmented packets, neither of the above hardware issues
occurs because the hardware only continues packet parsing when the
IPv6 Base Header Next Header field directly indicates UDP. Packets
carrying a Fragment Header do not continue through the subsequent
packet parsing stages.
For packets identified for hardware PTP parsing, pad the transport
data so it reaches RTASE_MIN_PAD_LEN before transmission.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/realtek/rtase/rtase.h",
"drivers/net/ethernet/realtek/rtase/rtase_main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "fe3a7320711eec6537e4890892f7ab9776d8618f",
"status": "affected",
"version": "d6e882b89fdf80be0ab4f914ec10f75215e49495",
"versionType": "git"
},
{
"lessThan": "4a4f3aa6af205bee539b5670afa2cd4e4953750e",
"status": "affected",
"version": "d6e882b89fdf80be0ab4f914ec10f75215e49495",
"versionType": "git"
},
{
"lessThan": "0f54f5048615e4e2802697855ea6374613548301",
"status": "affected",
"version": "d6e882b89fdf80be0ab4f914ec10f75215e49495",
"versionType": "git"
},
{
"lessThan": "1c50efa1faf3a1a96e100b07ec7a2f3164d90bee",
"status": "affected",
"version": "d6e882b89fdf80be0ab4f914ec10f75215e49495",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/realtek/rtase/rtase.h",
"drivers/net/ethernet/realtek/rtase/rtase_main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.12"
},
{
"lessThan": "6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nrtase: Workaround for TX hang caused by hardware packet parsing\n\nThe hardware performs packet parsing before packet transmission.\nParsing incomplete IPv4, IPv6, TCP, or UDP headers may trigger a TX\nhang because the hardware parser expects additional protocol header\ndata that is not present in the packet.\n\nThe hardware performs additional PTP parsing on UDP packets identified\nby destination ports 319/320 at the expected UDP destination port\noffset.\n\nIf such a packet has transport data smaller than RTASE_MIN_PAD_LEN,\nthe hardware parser expects additional packet data and may trigger a\nTX hang.\n\nTo avoid these hardware issues, the driver applies the following\nworkarounds.\n\nDrop malformed packets that may trigger this hardware issue before\ntransmission.\n\nFor IPv4 non-initial fragments, the hardware does not check the\nfragment offset before parsing the expected transport header location.\nAs a result, these packets are still subject to transport header\nparsing even though they do not contain a transport header. If the\ntransport data is shorter than the minimum transport header required\nby the hardware parser, pad the transport data to the minimum\ntransport header length required by the hardware parser. Packets that\nalso match the hardware PTP parsing conditions continue to follow the\ncorresponding workaround.\n\nFor IPv6 fragmented packets, neither of the above hardware issues\noccurs because the hardware only continues packet parsing when the\nIPv6 Base Header Next Header field directly indicates UDP. Packets\ncarrying a Fragment Header do not continue through the subsequent\npacket parsing stages.\n\nFor packets identified for hardware PTP parsing, pad the transport\ndata so it reaches RTASE_MIN_PAD_LEN before transmission."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug is in netdev TX; a remote attacker can send crafted IPv4 fragments or short PTP UDP (ports 319/320) that are forwarded/bridged out the rtase interface on automotive gateways and industrial routers, reaching rtase_start_xmit without local access.\nAC:L - Trigger packets have well-defined shapes (non-initial IPv4 frags with short payload, malformed L3/L4 headers, or PTP UDP under 47 bytes) and the attacker controls generation, timing, and retries; no race or rare layout is required on affected hardware.\nPR:N - Exploitation requires only the ability to inject network traffic that the host forwards or transmits via the rtase netdev; no target credentials, capabilities, or local shell access are needed on forwarding automotive/industrial gateways.\nUI:N - No victim interaction is required; the hang is triggered automatically when the kernel queues the crafted packet for transmission through the vulnerable NIC.\nS:U - Impact is confined to kernel/network availability on the host running the rtase driver; it does not cross VM, container, or IOMMU security boundaries.\nC:N - The failure mode is a hardware TX parser hang with no memory corruption, out-of-bounds access, use-after-free, or information disclosure primitive.\nI:N - The vulnerability does not modify arbitrary data or enable code execution; it only stalls transmission until the netdev watchdog resets the interface.\nA:H - Malformed TX packets can hang the NIC hardware transmit path, stopping egress and disrupting connectivity until rtase_tx_timeout invokes software reset; repeated injection enables sustained denial of service on safety-critical automotive networks."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:59:10.871Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/fe3a7320711eec6537e4890892f7ab9776d8618f"
},
{
"url": "https://git.kernel.org/stable/c/4a4f3aa6af205bee539b5670afa2cd4e4953750e"
},
{
"url": "https://git.kernel.org/stable/c/0f54f5048615e4e2802697855ea6374613548301"
},
{
"url": "https://git.kernel.org/stable/c/1c50efa1faf3a1a96e100b07ec7a2f3164d90bee"
}
],
"title": "rtase: Workaround for TX hang caused by hardware packet parsing",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68120",
"datePublished": "2026-08-10T11:58:40.224Z",
"dateReserved": "2026-07-30T09:28:09.369Z",
"dateUpdated": "2026-08-17T04:59:10.871Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68141 (GCVE-0-2026-68141)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/af_iucv: fix NULL deref in afiucv_hs_callback_syn()
afiucv_hs_callback_syn() allocates the child socket with GFP_ATOMIC.
If the allocation fails, nsk is NULL.
The connection-refused path is entered when the listen state check
fails, the accept backlog is full, or nsk is NULL. The code
unconditionally calls iucv_sock_kill(nsk) in that path.
iucv_sock_kill() does not accept a NULL socket pointer and immediately
dereferences sk via sock_flag(sk, SOCK_ZAPPED). When nsk is NULL,
calling iucv_sock_kill(nsk) results in a NULL pointer dereference.
Only call iucv_sock_kill() when a child socket was successfully
allocated.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 3881ac441f642d56503818123446f7298442236b Version: 3881ac441f642d56503818123446f7298442236b Version: 3881ac441f642d56503818123446f7298442236b Version: 3881ac441f642d56503818123446f7298442236b Version: 3881ac441f642d56503818123446f7298442236b Version: 3881ac441f642d56503818123446f7298442236b Version: 3881ac441f642d56503818123446f7298442236b Version: 3881ac441f642d56503818123446f7298442236b |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/iucv/af_iucv.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "6a1eb5b46c19073f8153b7e2c19b408cf353aaf1",
"status": "affected",
"version": "3881ac441f642d56503818123446f7298442236b",
"versionType": "git"
},
{
"lessThan": "c0b6e2ae90613c2fea7eaf3faa20985c6c2a1953",
"status": "affected",
"version": "3881ac441f642d56503818123446f7298442236b",
"versionType": "git"
},
{
"lessThan": "07e21deb3664001995e0a456dd627ab7dbe127ec",
"status": "affected",
"version": "3881ac441f642d56503818123446f7298442236b",
"versionType": "git"
},
{
"lessThan": "8bb111f87ded6acb9837ec9b45d6f02cda94c51f",
"status": "affected",
"version": "3881ac441f642d56503818123446f7298442236b",
"versionType": "git"
},
{
"lessThan": "46453b16f38ec7147351f7447e2aec6ea330f7b3",
"status": "affected",
"version": "3881ac441f642d56503818123446f7298442236b",
"versionType": "git"
},
{
"lessThan": "33736ff5e7c97d3348ce812e8bd2e125d840743c",
"status": "affected",
"version": "3881ac441f642d56503818123446f7298442236b",
"versionType": "git"
},
{
"lessThan": "0e857185591fe79934427c9c0c1c31dc776be134",
"status": "affected",
"version": "3881ac441f642d56503818123446f7298442236b",
"versionType": "git"
},
{
"lessThan": "47a5116e56a6b6fe1e909f244e39cd0fc26ceee4",
"status": "affected",
"version": "3881ac441f642d56503818123446f7298442236b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/iucv/af_iucv.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.2"
},
{
"lessThan": "3.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/af_iucv: fix NULL deref in afiucv_hs_callback_syn()\n\nafiucv_hs_callback_syn() allocates the child socket with GFP_ATOMIC.\nIf the allocation fails, nsk is NULL.\n\nThe connection-refused path is entered when the listen state check\nfails, the accept backlog is full, or nsk is NULL. The code\nunconditionally calls iucv_sock_kill(nsk) in that path.\n\niucv_sock_kill() does not accept a NULL socket pointer and immediately\ndereferences sk via sock_flag(sk, SOCK_ZAPPED). When nsk is NULL,\ncalling iucv_sock_kill(nsk) results in a NULL pointer dereference.\n\nOnly call iucv_sock_kill() when a child socket was successfully\nallocated."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The flaw is reached from afiucv_hs_rcv() via dev_add_pack() when ETH_P_AF_IUCV SYN frames arrive on a HiperSockets netdev in netif RX softirq; a remote LPAR/guest on the IBM Z HiperSockets fabric can send these connection requests without local access.\nAC:L - An attacker can repeatedly send SYN packets to a listening AF_IUCV service to pressure GFP_ATOMIC socket allocations until iucv_sock_alloc() fails and the broken connection-refused path runs; no timing race or victim-specific state beyond routine memory pressure is required.\nPR:N - Exploitation requires only sending unauthenticated HiperSockets SYN traffic to a bound/listening AF_IUCV socket; the handshake path has no credential checks and the af_iucv code performs no capability or permission validation before reaching afiucv_hs_callback_syn().\nUI:N - Triggering the NULL dereference needs no action from an end user beyond a service already listening on HiperSockets; the attacker can initiate SYN packets remotely without victim interaction.\nS:U - Impact is a kernel NULL pointer dereference and likely oops/panic in the victim LPAR kernel; it does not cross a VM/host, IOMMU, or sandbox boundary to compromise a different security authority.\nC:N - The failure is an immediate NULL pointer dereference in sock_flag() inside iucv_sock_kill(); there is no memory corruption, out-of-bounds access, or use-after-free that could yield information disclosure.\nI:N - The bug does not write attacker-controlled data or corrupt kernel structures; it only dereferences a NULL socket pointer during cleanup, so no integrity impact or code-execution primitive is created.\nA:H - A NULL dereference in afiucv_hs_callback_syn() during softirq packet processing can cause a kernel oops or panic, denying all service on the affected IBM Z LPAR until reboot."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:29:59.584Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/6a1eb5b46c19073f8153b7e2c19b408cf353aaf1"
},
{
"url": "https://git.kernel.org/stable/c/c0b6e2ae90613c2fea7eaf3faa20985c6c2a1953"
},
{
"url": "https://git.kernel.org/stable/c/07e21deb3664001995e0a456dd627ab7dbe127ec"
},
{
"url": "https://git.kernel.org/stable/c/8bb111f87ded6acb9837ec9b45d6f02cda94c51f"
},
{
"url": "https://git.kernel.org/stable/c/46453b16f38ec7147351f7447e2aec6ea330f7b3"
},
{
"url": "https://git.kernel.org/stable/c/33736ff5e7c97d3348ce812e8bd2e125d840743c"
},
{
"url": "https://git.kernel.org/stable/c/0e857185591fe79934427c9c0c1c31dc776be134"
},
{
"url": "https://git.kernel.org/stable/c/47a5116e56a6b6fe1e909f244e39cd0fc26ceee4"
}
],
"title": "net/af_iucv: fix NULL deref in afiucv_hs_callback_syn()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68141",
"datePublished": "2026-08-10T11:59:05.051Z",
"dateReserved": "2026-07-30T09:28:09.370Z",
"dateUpdated": "2026-08-19T16:29:59.584Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68331 (GCVE-0-2026-68331)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
dpaa2-eth: put MAC endpoint device on disconnect
fsl_mc_get_endpoint() returns the MAC endpoint device with a reference
taken through device_find_child(). The Ethernet connect path stores that
device in mac->mc_dev and keeps it for the lifetime of the connected MAC
object.
However, the disconnect path only disconnects and closes the MAC before
freeing the dpaa2_mac object. It does not drop the endpoint device
reference stored in mac->mc_dev, so every successful connect leaks that
device reference when the MAC is later disconnected.
Drop the endpoint device reference after closing the MAC and before
freeing the dpaa2_mac object.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 71947923089353f23f4f210864903c4dcf2c1696 Version: 71947923089353f23f4f210864903c4dcf2c1696 Version: 71947923089353f23f4f210864903c4dcf2c1696 Version: 71947923089353f23f4f210864903c4dcf2c1696 Version: 71947923089353f23f4f210864903c4dcf2c1696 Version: 71947923089353f23f4f210864903c4dcf2c1696 Version: 71947923089353f23f4f210864903c4dcf2c1696 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/freescale/dpaa2/dpaa2-eth.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "6b6ffdb9ca4547a3c4c274aa3e25b6c68dbc62e1",
"status": "affected",
"version": "71947923089353f23f4f210864903c4dcf2c1696",
"versionType": "git"
},
{
"lessThan": "1974127776da46a000c61f36d4946799ea6d4f51",
"status": "affected",
"version": "71947923089353f23f4f210864903c4dcf2c1696",
"versionType": "git"
},
{
"lessThan": "915012e923316b8b5d5bf8fc771617b47bd7572d",
"status": "affected",
"version": "71947923089353f23f4f210864903c4dcf2c1696",
"versionType": "git"
},
{
"lessThan": "e23e4a3b9dfd893469c731318d409cdf04fb1ddf",
"status": "affected",
"version": "71947923089353f23f4f210864903c4dcf2c1696",
"versionType": "git"
},
{
"lessThan": "f112df0744e2d77baa68eeebb860021bbaaa022a",
"status": "affected",
"version": "71947923089353f23f4f210864903c4dcf2c1696",
"versionType": "git"
},
{
"lessThan": "a3cecf169cc652b558d08661bb6ce55e4c933ec0",
"status": "affected",
"version": "71947923089353f23f4f210864903c4dcf2c1696",
"versionType": "git"
},
{
"lessThan": "b4b201cc93ff70150853aba03e14d314d1980ca0",
"status": "affected",
"version": "71947923089353f23f4f210864903c4dcf2c1696",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/freescale/dpaa2/dpaa2-eth.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.5"
},
{
"lessThan": "5.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndpaa2-eth: put MAC endpoint device on disconnect\n\nfsl_mc_get_endpoint() returns the MAC endpoint device with a reference\ntaken through device_find_child(). The Ethernet connect path stores that\ndevice in mac-\u003emc_dev and keeps it for the lifetime of the connected MAC\nobject.\n\nHowever, the disconnect path only disconnects and closes the MAC before\nfreeing the dpaa2_mac object. It does not drop the endpoint device\nreference stored in mac-\u003emc_dev, so every successful connect leaks that\ndevice reference when the MAC is later disconnected.\n\nDrop the endpoint device reference after closing the MAC and before\nfreeing the dpaa2_mac object."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:28.174Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/6b6ffdb9ca4547a3c4c274aa3e25b6c68dbc62e1"
},
{
"url": "https://git.kernel.org/stable/c/1974127776da46a000c61f36d4946799ea6d4f51"
},
{
"url": "https://git.kernel.org/stable/c/915012e923316b8b5d5bf8fc771617b47bd7572d"
},
{
"url": "https://git.kernel.org/stable/c/e23e4a3b9dfd893469c731318d409cdf04fb1ddf"
},
{
"url": "https://git.kernel.org/stable/c/f112df0744e2d77baa68eeebb860021bbaaa022a"
},
{
"url": "https://git.kernel.org/stable/c/a3cecf169cc652b558d08661bb6ce55e4c933ec0"
},
{
"url": "https://git.kernel.org/stable/c/b4b201cc93ff70150853aba03e14d314d1980ca0"
}
],
"title": "dpaa2-eth: put MAC endpoint device on disconnect",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68331",
"datePublished": "2026-08-10T12:03:07.529Z",
"dateReserved": "2026-07-30T09:28:09.383Z",
"dateUpdated": "2026-08-19T16:33:28.174Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64572 (GCVE-0-2026-64572)
Vulnerability from cvelistv5
Published
2026-08-05 08:08
Modified
2026-08-19 16:28
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ipv4: fib: free fib_alias with kfree_rcu() on insert error path
fib_table_insert() publishes new_fa into the leaf's fa_list with
fib_insert_alias() before calling the fib entry notifiers. When a
notifier fails, the error path removes new_fa with fib_remove_alias()
(hlist_del_rcu) and frees it right away with kmem_cache_free().
fib_table_lookup() walks that list under rcu_read_lock() only, so a
concurrent lookup that already reached new_fa keeps reading it after the
free:
BUG: KASAN: slab-use-after-free in fib_table_lookup (net/ipv4/fib_trie.c:1601)
Read of size 1 at addr ffff88810676d4eb by task exploit/297
Call Trace:
fib_table_lookup (net/ipv4/fib_trie.c:1601)
ip_route_output_key_hash_rcu (net/ipv4/route.c:2814)
ip_route_output_key_hash (net/ipv4/route.c:2705)
__ip4_datagram_connect (net/ipv4/datagram.c:49)
udp_connect (net/ipv4/udp.c:2144)
__sys_connect (net/socket.c:2167)
__x64_sys_connect (net/socket.c:2173)
do_syscall_64
entry_SYSCALL_64_after_hwframe
which belongs to the cache ip_fib_alias of size 56
Triggering the error path needs CAP_NET_ADMIN and a registered fib
notifier that can reject a route; a netdevsim device whose IPv4 FIB
resource is exhausted is enough.
Free new_fa with alias_free_mem_rcu(), as fib_table_delete() already
does for a fib_alias removed from the trie.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: a6c76c17df021b141b0d306828c9fe4ba2d2717c Version: a6c76c17df021b141b0d306828c9fe4ba2d2717c Version: a6c76c17df021b141b0d306828c9fe4ba2d2717c Version: a6c76c17df021b141b0d306828c9fe4ba2d2717c Version: a6c76c17df021b141b0d306828c9fe4ba2d2717c Version: a6c76c17df021b141b0d306828c9fe4ba2d2717c Version: a6c76c17df021b141b0d306828c9fe4ba2d2717c Version: a6c76c17df021b141b0d306828c9fe4ba2d2717c |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ipv4/fib_trie.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "9d0778571def598c31e84a38ae5a7ebc6f65e6d8",
"status": "affected",
"version": "a6c76c17df021b141b0d306828c9fe4ba2d2717c",
"versionType": "git"
},
{
"lessThan": "bb03350f974aec352b660d032a1d283eb462165a",
"status": "affected",
"version": "a6c76c17df021b141b0d306828c9fe4ba2d2717c",
"versionType": "git"
},
{
"lessThan": "6429c9cfd941e62acd7bb0bc64d631574d4c3b2a",
"status": "affected",
"version": "a6c76c17df021b141b0d306828c9fe4ba2d2717c",
"versionType": "git"
},
{
"lessThan": "8150b5365f026e72250cacc527ea00be30f40105",
"status": "affected",
"version": "a6c76c17df021b141b0d306828c9fe4ba2d2717c",
"versionType": "git"
},
{
"lessThan": "d007056868723de9c0cc3f5ffaad47a8d468b9a4",
"status": "affected",
"version": "a6c76c17df021b141b0d306828c9fe4ba2d2717c",
"versionType": "git"
},
{
"lessThan": "cb8be318b4432abd88d3172ec157330f27a5f7a7",
"status": "affected",
"version": "a6c76c17df021b141b0d306828c9fe4ba2d2717c",
"versionType": "git"
},
{
"lessThan": "b8d2ea75c76abcd0d72679c2f488271f573e32fb",
"status": "affected",
"version": "a6c76c17df021b141b0d306828c9fe4ba2d2717c",
"versionType": "git"
},
{
"lessThan": "f2f152e94a67bc746afaf05a1b2702c195553112",
"status": "affected",
"version": "a6c76c17df021b141b0d306828c9fe4ba2d2717c",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ipv4/fib_trie.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.6"
},
{
"lessThan": "5.6",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: fib: free fib_alias with kfree_rcu() on insert error path\n\nfib_table_insert() publishes new_fa into the leaf\u0027s fa_list with\nfib_insert_alias() before calling the fib entry notifiers. When a\nnotifier fails, the error path removes new_fa with fib_remove_alias()\n(hlist_del_rcu) and frees it right away with kmem_cache_free().\n\nfib_table_lookup() walks that list under rcu_read_lock() only, so a\nconcurrent lookup that already reached new_fa keeps reading it after the\nfree:\n\n BUG: KASAN: slab-use-after-free in fib_table_lookup (net/ipv4/fib_trie.c:1601)\n Read of size 1 at addr ffff88810676d4eb by task exploit/297\n Call Trace:\n fib_table_lookup (net/ipv4/fib_trie.c:1601)\n ip_route_output_key_hash_rcu (net/ipv4/route.c:2814)\n ip_route_output_key_hash (net/ipv4/route.c:2705)\n __ip4_datagram_connect (net/ipv4/datagram.c:49)\n udp_connect (net/ipv4/udp.c:2144)\n __sys_connect (net/socket.c:2167)\n __x64_sys_connect (net/socket.c:2173)\n do_syscall_64\n entry_SYSCALL_64_after_hwframe\n which belongs to the cache ip_fib_alias of size 56\n\nTriggering the error path needs CAP_NET_ADMIN and a registered fib\nnotifier that can reject a route; a netdevsim device whose IPv4 FIB\nresource is exhausted is enough.\n\nFree new_fa with alias_free_mem_rcu(), as fib_table_delete() already\ndoes for a fib_alias removed from the trie."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:28:49.541Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/9d0778571def598c31e84a38ae5a7ebc6f65e6d8"
},
{
"url": "https://git.kernel.org/stable/c/bb03350f974aec352b660d032a1d283eb462165a"
},
{
"url": "https://git.kernel.org/stable/c/6429c9cfd941e62acd7bb0bc64d631574d4c3b2a"
},
{
"url": "https://git.kernel.org/stable/c/8150b5365f026e72250cacc527ea00be30f40105"
},
{
"url": "https://git.kernel.org/stable/c/d007056868723de9c0cc3f5ffaad47a8d468b9a4"
},
{
"url": "https://git.kernel.org/stable/c/cb8be318b4432abd88d3172ec157330f27a5f7a7"
},
{
"url": "https://git.kernel.org/stable/c/b8d2ea75c76abcd0d72679c2f488271f573e32fb"
},
{
"url": "https://git.kernel.org/stable/c/f2f152e94a67bc746afaf05a1b2702c195553112"
}
],
"title": "ipv4: fib: free fib_alias with kfree_rcu() on insert error path",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64572",
"datePublished": "2026-08-05T08:08:09.068Z",
"dateReserved": "2026-07-19T15:36:31.797Z",
"dateUpdated": "2026-08-19T16:28:49.541Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68197 (GCVE-0-2026-68197)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper
mwifiex_tdls_add_ht_oper() gates its follow-the-AP-bandwidth path on
bss_desc->bcn_ht_cap being present, but then dereferences a different
pointer, bss_desc->bcn_ht_oper:
if (ISSUPP_CHANWIDTH40(priv->adapter->hw_dot_11n_dev_cap) &&
bss_desc->bcn_ht_cap &&
ISALLOWED_CHANWIDTH40(bss_desc->bcn_ht_oper->ht_param))
bcn_ht_cap and bcn_ht_oper are populated independently while parsing the
associated AP's beacon in mwifiex_update_bss_desc_with_ie(): an AP that
advertises an HT Capabilities element but no HT Operation element leaves
bcn_ht_cap non-NULL and bcn_ht_oper NULL. Setting up a TDLS link to a
peer while associated to such an AP then dereferences the NULL
bcn_ht_oper and crashes the kernel. Every other bcn_ht_oper user in the
driver NULL-checks it first.
Guard on the pointer that is actually dereferenced.
Found by 0sec automated security-research tooling (https://0sec.ai).
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 396939f94084d5923d558e9f22db48bc51156e47 Version: 396939f94084d5923d558e9f22db48bc51156e47 Version: 396939f94084d5923d558e9f22db48bc51156e47 Version: 396939f94084d5923d558e9f22db48bc51156e47 Version: 396939f94084d5923d558e9f22db48bc51156e47 Version: 396939f94084d5923d558e9f22db48bc51156e47 Version: 396939f94084d5923d558e9f22db48bc51156e47 Version: 396939f94084d5923d558e9f22db48bc51156e47 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/marvell/mwifiex/tdls.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "e1770f7410b4232a0267924f99751dc9c5ca31af",
"status": "affected",
"version": "396939f94084d5923d558e9f22db48bc51156e47",
"versionType": "git"
},
{
"lessThan": "8c2058717fd06f05d421c2d3adf1dff3c3abcda1",
"status": "affected",
"version": "396939f94084d5923d558e9f22db48bc51156e47",
"versionType": "git"
},
{
"lessThan": "fba7eb7b248ea0618235f504158b685d752a153a",
"status": "affected",
"version": "396939f94084d5923d558e9f22db48bc51156e47",
"versionType": "git"
},
{
"lessThan": "eb42c3c8fd479166c42984728754cd779c71fd60",
"status": "affected",
"version": "396939f94084d5923d558e9f22db48bc51156e47",
"versionType": "git"
},
{
"lessThan": "45011e4d9ba3f2182e5df64be65888044fa20771",
"status": "affected",
"version": "396939f94084d5923d558e9f22db48bc51156e47",
"versionType": "git"
},
{
"lessThan": "9375a4ea4121625ef27a46b74781cda66a5cc61b",
"status": "affected",
"version": "396939f94084d5923d558e9f22db48bc51156e47",
"versionType": "git"
},
{
"lessThan": "cca4398aa305c22016d1714f388e2fa6ea4e5ad4",
"status": "affected",
"version": "396939f94084d5923d558e9f22db48bc51156e47",
"versionType": "git"
},
{
"lessThan": "c3d68e294cbb6a4090bb219d3dcaca85a011809b",
"status": "affected",
"version": "396939f94084d5923d558e9f22db48bc51156e47",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/marvell/mwifiex/tdls.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.16"
},
{
"lessThan": "3.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.16",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper\n\nmwifiex_tdls_add_ht_oper() gates its follow-the-AP-bandwidth path on\nbss_desc-\u003ebcn_ht_cap being present, but then dereferences a different\npointer, bss_desc-\u003ebcn_ht_oper:\n\n\tif (ISSUPP_CHANWIDTH40(priv-\u003eadapter-\u003ehw_dot_11n_dev_cap) \u0026\u0026\n\t bss_desc-\u003ebcn_ht_cap \u0026\u0026\n\t ISALLOWED_CHANWIDTH40(bss_desc-\u003ebcn_ht_oper-\u003eht_param))\n\nbcn_ht_cap and bcn_ht_oper are populated independently while parsing the\nassociated AP\u0027s beacon in mwifiex_update_bss_desc_with_ie(): an AP that\nadvertises an HT Capabilities element but no HT Operation element leaves\nbcn_ht_cap non-NULL and bcn_ht_oper NULL. Setting up a TDLS link to a\npeer while associated to such an AP then dereferences the NULL\nbcn_ht_oper and crashes the kernel. Every other bcn_ht_oper user in the\ndriver NULL-checks it first.\n\nGuard on the pointer that is actually dereferenced.\n\nFound by 0sec automated security-research tooling (https://0sec.ai)."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:16.085Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/e1770f7410b4232a0267924f99751dc9c5ca31af"
},
{
"url": "https://git.kernel.org/stable/c/8c2058717fd06f05d421c2d3adf1dff3c3abcda1"
},
{
"url": "https://git.kernel.org/stable/c/fba7eb7b248ea0618235f504158b685d752a153a"
},
{
"url": "https://git.kernel.org/stable/c/eb42c3c8fd479166c42984728754cd779c71fd60"
},
{
"url": "https://git.kernel.org/stable/c/45011e4d9ba3f2182e5df64be65888044fa20771"
},
{
"url": "https://git.kernel.org/stable/c/9375a4ea4121625ef27a46b74781cda66a5cc61b"
},
{
"url": "https://git.kernel.org/stable/c/cca4398aa305c22016d1714f388e2fa6ea4e5ad4"
},
{
"url": "https://git.kernel.org/stable/c/c3d68e294cbb6a4090bb219d3dcaca85a011809b"
}
],
"title": "wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68197",
"datePublished": "2026-08-10T12:00:15.750Z",
"dateReserved": "2026-07-30T09:28:09.374Z",
"dateUpdated": "2026-08-19T16:31:16.085Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68357 (GCVE-0-2026-68357)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
watchdog: pretimeout: Fix UAF in watchdog_unregister_governor()
When a watchdog governor is unregistered, it updates existing watchdog
devices that were using this governor by falling back to `default_gov`.
If the governor being unregistered is currently set as `default_gov`,
the `default_gov` is never cleared. This leads to 2 use-after-free
issues:
1. New watchdog devices registered after this point will inherit the
dangling `default_gov`.
2. Existing watchdog devices using the unregistered governor will have
their `wdd->gov` reassigned to the dangling `default_gov`.
Fix the UAF by clearing `default_gov` if it matches the governor being
unregistered.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: da0d12ff2b829a35e9921918e925d79497b82bef Version: da0d12ff2b829a35e9921918e925d79497b82bef Version: da0d12ff2b829a35e9921918e925d79497b82bef Version: da0d12ff2b829a35e9921918e925d79497b82bef Version: da0d12ff2b829a35e9921918e925d79497b82bef Version: da0d12ff2b829a35e9921918e925d79497b82bef Version: da0d12ff2b829a35e9921918e925d79497b82bef Version: da0d12ff2b829a35e9921918e925d79497b82bef |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/watchdog/watchdog_pretimeout.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b9ae33faa96bdec6bc60e4c5f8f53786182e4207",
"status": "affected",
"version": "da0d12ff2b829a35e9921918e925d79497b82bef",
"versionType": "git"
},
{
"lessThan": "472ec1e34ff0bb26379805cae808f658cce58c35",
"status": "affected",
"version": "da0d12ff2b829a35e9921918e925d79497b82bef",
"versionType": "git"
},
{
"lessThan": "7a2ee3ec6f208307eca1119a343c7b5d39c03708",
"status": "affected",
"version": "da0d12ff2b829a35e9921918e925d79497b82bef",
"versionType": "git"
},
{
"lessThan": "2e47b91b9b4020fcc01def14d6b6556d66074cf4",
"status": "affected",
"version": "da0d12ff2b829a35e9921918e925d79497b82bef",
"versionType": "git"
},
{
"lessThan": "0ca252720f0e38411cfec3431db9bb1aed0a412c",
"status": "affected",
"version": "da0d12ff2b829a35e9921918e925d79497b82bef",
"versionType": "git"
},
{
"lessThan": "7d1658b066de30f4b23afc14814d22416a971e6e",
"status": "affected",
"version": "da0d12ff2b829a35e9921918e925d79497b82bef",
"versionType": "git"
},
{
"lessThan": "7993d626983cc58fbde9607333cfd2d57725c197",
"status": "affected",
"version": "da0d12ff2b829a35e9921918e925d79497b82bef",
"versionType": "git"
},
{
"lessThan": "7362ba0f9c96ac3ad6a2ca3995bd9fc9a28a8661",
"status": "affected",
"version": "da0d12ff2b829a35e9921918e925d79497b82bef",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/watchdog/watchdog_pretimeout.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.9"
},
{
"lessThan": "4.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwatchdog: pretimeout: Fix UAF in watchdog_unregister_governor()\n\nWhen a watchdog governor is unregistered, it updates existing watchdog\ndevices that were using this governor by falling back to `default_gov`.\n\nIf the governor being unregistered is currently set as `default_gov`,\nthe `default_gov` is never cleared. This leads to 2 use-after-free\nissues:\n1. New watchdog devices registered after this point will inherit the\n dangling `default_gov`.\n2. Existing watchdog devices using the unregistered governor will have\n their `wdd-\u003egov` reassigned to the dangling `default_gov`.\n\nFix the UAF by clearing `default_gov` if it matches the governor being\nunregistered."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:05.347Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b9ae33faa96bdec6bc60e4c5f8f53786182e4207"
},
{
"url": "https://git.kernel.org/stable/c/472ec1e34ff0bb26379805cae808f658cce58c35"
},
{
"url": "https://git.kernel.org/stable/c/7a2ee3ec6f208307eca1119a343c7b5d39c03708"
},
{
"url": "https://git.kernel.org/stable/c/2e47b91b9b4020fcc01def14d6b6556d66074cf4"
},
{
"url": "https://git.kernel.org/stable/c/0ca252720f0e38411cfec3431db9bb1aed0a412c"
},
{
"url": "https://git.kernel.org/stable/c/7d1658b066de30f4b23afc14814d22416a971e6e"
},
{
"url": "https://git.kernel.org/stable/c/7993d626983cc58fbde9607333cfd2d57725c197"
},
{
"url": "https://git.kernel.org/stable/c/7362ba0f9c96ac3ad6a2ca3995bd9fc9a28a8661"
}
],
"title": "watchdog: pretimeout: Fix UAF in watchdog_unregister_governor()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68357",
"datePublished": "2026-08-10T12:03:34.241Z",
"dateReserved": "2026-07-30T09:28:09.385Z",
"dateUpdated": "2026-08-19T16:34:05.347Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72213 (GCVE-0-2026-72213)
Vulnerability from cvelistv5
Published
2026-08-15 05:54
Modified
2026-08-17 05:41
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
mm/hugetlb: fix hugetlb cgroup rsvd charge/uncharge mismatch
In alloc_hugetlb_folio(), a single h_cg pointer is used for both the rsvd
and non-rsvd hugetlb cgroup charges. When map_chg is set,
hugetlb_cgroup_charge_cgroup_rsvd() stores the charged cgroup in h_cg, but
the immediately following hugetlb_cgroup_charge_cgroup() overwrites h_cg
with the non-rsvd cgroup pointer.
As a result, hugetlb_cgroup_commit_charge_rsvd() stores the wrong
(non-rsvd) cgroup pointer into the folio's rsvd slot.
When the folio is later freed, free_huge_folio() unconditionally calls
both hugetlb_cgroup_uncharge_folio() and
hugetlb_cgroup_uncharge_folio_rsvd(). The rsvd uncharge reads back the
wrong cgroup from the folio and decrements a counter that was never
charged for that cgroup, causing a page_counter underflow:
page_counter underflow: -512 nr_pages=512
WARNING: mm/page_counter.c:61 at page_counter_cancel
Fix this by introducing a separate h_cg_rsvd pointer exclusively for the
rsvd charge path, keeping the rsvd and non-rsvd charges fully independent
through their charge, commit, and error uncharge paths.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"mm/hugetlb.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "5c32ae4a91fb5f4941328e0c1720a7fa4189c3bd",
"status": "affected",
"version": "08cf9faf7558020aed6a0da5810b824b07139dfa",
"versionType": "git"
},
{
"lessThan": "1697d253f51cf5e3825a3423ff49e128a3502ab2",
"status": "affected",
"version": "08cf9faf7558020aed6a0da5810b824b07139dfa",
"versionType": "git"
},
{
"lessThan": "b785f2bd9496facedc0a031be09cddcd1d3c84d3",
"status": "affected",
"version": "08cf9faf7558020aed6a0da5810b824b07139dfa",
"versionType": "git"
},
{
"lessThan": "15807d0ddde37407af72859426b654f3d1972b00",
"status": "affected",
"version": "08cf9faf7558020aed6a0da5810b824b07139dfa",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"mm/hugetlb.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.7"
},
{
"lessThan": "5.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/hugetlb: fix hugetlb cgroup rsvd charge/uncharge mismatch\n\nIn alloc_hugetlb_folio(), a single h_cg pointer is used for both the rsvd\nand non-rsvd hugetlb cgroup charges. When map_chg is set,\nhugetlb_cgroup_charge_cgroup_rsvd() stores the charged cgroup in h_cg, but\nthe immediately following hugetlb_cgroup_charge_cgroup() overwrites h_cg\nwith the non-rsvd cgroup pointer.\n\nAs a result, hugetlb_cgroup_commit_charge_rsvd() stores the wrong\n(non-rsvd) cgroup pointer into the folio\u0027s rsvd slot.\n\nWhen the folio is later freed, free_huge_folio() unconditionally calls\nboth hugetlb_cgroup_uncharge_folio() and\nhugetlb_cgroup_uncharge_folio_rsvd(). The rsvd uncharge reads back the\nwrong cgroup from the folio and decrements a counter that was never\ncharged for that cgroup, causing a page_counter underflow:\n\n page_counter underflow: -512 nr_pages=512\n WARNING: mm/page_counter.c:61 at page_counter_cancel\n\nFix this by introducing a separate h_cg_rsvd pointer exclusively for the\nrsvd charge path, keeping the rsvd and non-rsvd charges fully independent\nthrough their charge, commit, and error uncharge paths."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is in alloc_hugetlb_folio()/free_huge_folio() and is reached only via local MM paths (mmap/munmap, hugetlb page faults, fallocate, memfd MFD_HUGETLB, MAP_HUGETLB) that syzbot triggered through hugetlbfs inode eviction, not via any network-facing kernel service.\nAC:L - An unprivileged attacker can reliably trigger the mismatch by creating hugetlbfs mappings without reservations (MAP_NORESERVE or fault-before-reserve), faulting in huge pages to run alloc_hugetlb_folio() with map_chg set, then closing/unmapping to free folios and hit the bad rsvd uncharge.\nPR:L - Triggering requires only an unprivileged local process that can use hugetlb memory (hugetlbfs/MAP_HUGETLB/memfd) under a hugetlb cgroup; no init-namespace root or special driver capabilities are needed, and cgroup hugetlb limits are controllable from user namespaces.\nUI:N - Exploitation is fully attacker-driven through normal syscalls (mmap, write/fault, close/unlink) and does not require any victim user action beyond the attacker operating on their own mappings.\nS:U - Impact is confined to kernel hugetlb/cgroup page_counter accounting within the same host kernel security domain; it does not cross VM, container runtime, or IOMMU boundaries.\nC:N - The flaw corrupts hugetlb cgroup reservation counters and emits a WARN on underflow; it does not read or disclose kernel memory, pointers, or other confidential data to the attacker.\nI:H - page_counter underflow forcibly resets hugetlb cgroup reservation usage to zero, corrupting kernel accounting so an attacker can bypass hugetlb.rsvd cgroup limits and consume hugepage resources beyond enforced quotas in multi-tenant/container deployments.\nA:H - free_huge_folio() unconditionally hits the bad rsvd uncharge and triggers a kernel WARNING/page_counter underflow during hugepage teardown; syzbot classified this as DoS and repeated alloc/free cycles can disrupt hugetlb availability for other workloads when limits are bypassed."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:41:39.361Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/5c32ae4a91fb5f4941328e0c1720a7fa4189c3bd"
},
{
"url": "https://git.kernel.org/stable/c/1697d253f51cf5e3825a3423ff49e128a3502ab2"
},
{
"url": "https://git.kernel.org/stable/c/b785f2bd9496facedc0a031be09cddcd1d3c84d3"
},
{
"url": "https://git.kernel.org/stable/c/15807d0ddde37407af72859426b654f3d1972b00"
}
],
"title": "mm/hugetlb: fix hugetlb cgroup rsvd charge/uncharge mismatch",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72213",
"datePublished": "2026-08-15T05:54:07.854Z",
"dateReserved": "2026-08-09T03:40:39.912Z",
"dateUpdated": "2026-08-17T05:41:39.361Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68196 (GCVE-0-2026-68196)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: wilc1000: validate assoc response length before subtracting header
wilc_parse_assoc_resp_info() computes the trailing IE length as
ies_len = buffer_len - sizeof(*res);
without first checking that buffer_len is at least sizeof(struct
wilc_assoc_resp) (6 bytes). buffer_len is the length reported for a
received association response (host_int_parse_assoc_resp_info() passes
hif_drv->assoc_resp / assoc_resp_info_len straight in) and must be
validated before the driver accesses the fixed header.
For a frame shorter than the 6-byte fixed header, the subtraction wraps.
For a four-byte response the result is truncated to a u16 ies_len of
65534, so kmemdup() then attempts to copy 65534 bytes starting at
buffer + sizeof(*res), beyond the valid association-response data
(CWE-125). A response shorter than four bytes can also cause an
out-of-bounds read of res->status_code at offsets 2 and 3.
Reject frames too short to hold the fixed header before touching the
header or computing ies_len. Also set the connection status to a failure
on this path: the caller falls through to a
"conn_info->status == WLAN_STATUS_SUCCESS" check after the parser
returns, so leaving the status untouched could let a malformed short
response be treated as a successful association.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: c5c77ba18ea66aa05441c71e38473efb787705a4 Version: c5c77ba18ea66aa05441c71e38473efb787705a4 Version: c5c77ba18ea66aa05441c71e38473efb787705a4 Version: c5c77ba18ea66aa05441c71e38473efb787705a4 Version: c5c77ba18ea66aa05441c71e38473efb787705a4 Version: c5c77ba18ea66aa05441c71e38473efb787705a4 Version: c5c77ba18ea66aa05441c71e38473efb787705a4 Version: c5c77ba18ea66aa05441c71e38473efb787705a4 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/microchip/wilc1000/hif.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "d79b92417f33424ff23dad76716ed8f2cefb1083",
"status": "affected",
"version": "c5c77ba18ea66aa05441c71e38473efb787705a4",
"versionType": "git"
},
{
"lessThan": "b81d0ea9e1daa215b3da68c1f4f6fb07940c2f6a",
"status": "affected",
"version": "c5c77ba18ea66aa05441c71e38473efb787705a4",
"versionType": "git"
},
{
"lessThan": "8d50acf5420de0c4da99c2d634731c9d3164a755",
"status": "affected",
"version": "c5c77ba18ea66aa05441c71e38473efb787705a4",
"versionType": "git"
},
{
"lessThan": "584c8954ad55f8b09b475be6db710fe40ceb988c",
"status": "affected",
"version": "c5c77ba18ea66aa05441c71e38473efb787705a4",
"versionType": "git"
},
{
"lessThan": "4d410320e8ae5933e651660c9fadc1d380309e23",
"status": "affected",
"version": "c5c77ba18ea66aa05441c71e38473efb787705a4",
"versionType": "git"
},
{
"lessThan": "e511e93abd6eeedcd5b3c55516241f414fbde64a",
"status": "affected",
"version": "c5c77ba18ea66aa05441c71e38473efb787705a4",
"versionType": "git"
},
{
"lessThan": "8ccdf8c8de87a9580df37c3c1ec53ba88cedef65",
"status": "affected",
"version": "c5c77ba18ea66aa05441c71e38473efb787705a4",
"versionType": "git"
},
{
"lessThan": "4c4c97b60a5e978121d9ee8cb0ab3916e5d6a8de",
"status": "affected",
"version": "c5c77ba18ea66aa05441c71e38473efb787705a4",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/microchip/wilc1000/hif.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.2"
},
{
"lessThan": "4.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: wilc1000: validate assoc response length before subtracting header\n\nwilc_parse_assoc_resp_info() computes the trailing IE length as\n\n\ties_len = buffer_len - sizeof(*res);\n\nwithout first checking that buffer_len is at least sizeof(struct\nwilc_assoc_resp) (6 bytes). buffer_len is the length reported for a\nreceived association response (host_int_parse_assoc_resp_info() passes\nhif_drv-\u003eassoc_resp / assoc_resp_info_len straight in) and must be\nvalidated before the driver accesses the fixed header.\n\nFor a frame shorter than the 6-byte fixed header, the subtraction wraps.\nFor a four-byte response the result is truncated to a u16 ies_len of\n65534, so kmemdup() then attempts to copy 65534 bytes starting at\nbuffer + sizeof(*res), beyond the valid association-response data\n(CWE-125). A response shorter than four bytes can also cause an\nout-of-bounds read of res-\u003estatus_code at offsets 2 and 3.\n\nReject frames too short to hold the fixed header before touching the\nheader or computing ies_len. Also set the connection status to a failure\non this path: the caller falls through to a\n\"conn_info-\u003estatus == WLAN_STATUS_SUCCESS\" check after the parser\nreturns, so leaving the status untouched could let a malformed short\nresponse be treated as a successful association."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - Exploitation requires a rogue WiFi AP to send a malformed 802.11 Association Response over the air during STA join; per kernel guidance WiFi frame injection is Adjacent, not routable Network.\nAC:L - The attacker fully controls the rogue AP and can craft sub-6-byte association responses with SUCCESS status; once the victim initiates or auto-rejoins association, the malformed frame reliably reaches the parser.\nPR:N - No privileges on the victim are required; a remote attacker operating a rogue AP triggers the bug during the standard pre-authentication WiFi association handshake without local access or credentials.\nUI:N - Exploitation does not require per-attempt user action when devices auto-reconnect to a saved SSID or join an evil-twin AP broadcasting a known network name, which is common on embedded/IoT WILC1000 deployments.\nS:U - The vulnerability is confined to kernel memory and driver state on the affected host; impact does not cross a security boundary such as VM escape, sandbox escape, or IOMMU/DMA isolation bypass.\nC:H - Integer underflow drives kmemdup() to copy up to ~65534 bytes past the 512-byte assoc_resp buffer, leaking adjacent kernel heap data that is forwarded to userspace via cfg80211_connect_bss() response IEs.\nI:L - Beyond the OOB read, a malformed short response can leave conn_info-\u003estatus as WLAN_STATUS_SUCCESS and report a bogus successful association, corrupting the device\u0027s connection integrity without granting arbitrary kernel write.\nA:H - The oversized kmemdup() memcpy reads far beyond the kmalloc-backed assoc_resp array, which can fault on unmapped memory and cause a kernel oops or panic; repeated triggers also impose severe memory pressure."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:13.791Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/d79b92417f33424ff23dad76716ed8f2cefb1083"
},
{
"url": "https://git.kernel.org/stable/c/b81d0ea9e1daa215b3da68c1f4f6fb07940c2f6a"
},
{
"url": "https://git.kernel.org/stable/c/8d50acf5420de0c4da99c2d634731c9d3164a755"
},
{
"url": "https://git.kernel.org/stable/c/584c8954ad55f8b09b475be6db710fe40ceb988c"
},
{
"url": "https://git.kernel.org/stable/c/4d410320e8ae5933e651660c9fadc1d380309e23"
},
{
"url": "https://git.kernel.org/stable/c/e511e93abd6eeedcd5b3c55516241f414fbde64a"
},
{
"url": "https://git.kernel.org/stable/c/8ccdf8c8de87a9580df37c3c1ec53ba88cedef65"
},
{
"url": "https://git.kernel.org/stable/c/4c4c97b60a5e978121d9ee8cb0ab3916e5d6a8de"
}
],
"title": "wifi: wilc1000: validate assoc response length before subtracting header",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68196",
"datePublished": "2026-08-10T12:00:14.686Z",
"dateReserved": "2026-07-30T09:28:09.374Z",
"dateUpdated": "2026-08-19T16:31:13.791Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64562 (GCVE-0-2026-64562)
Vulnerability from cvelistv5
Published
2026-08-04 06:23
Modified
2026-08-19 16:28
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
KVM: nVMX: Hide shadow VMCS right after VMCLEAR
free_nested() frees the shadow VMCS while vmcs01 still points to it. But
because it is asynchronous with respect to loaded_vmcs_clear(), the vCPU
might migrate before the pointer is cleared and __loaded_vmcs_clear()
may then execute VMCLEAR.
The VMCS needs to stay attached until its explicit VMCLEAR completes, but
then it can be hidden and the page safely freed.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 355f4fb1405ec29d0fac49b4d41fcd78cbd455d5 Version: 355f4fb1405ec29d0fac49b4d41fcd78cbd455d5 Version: 355f4fb1405ec29d0fac49b4d41fcd78cbd455d5 Version: 355f4fb1405ec29d0fac49b4d41fcd78cbd455d5 Version: 355f4fb1405ec29d0fac49b4d41fcd78cbd455d5 Version: 355f4fb1405ec29d0fac49b4d41fcd78cbd455d5 Version: 355f4fb1405ec29d0fac49b4d41fcd78cbd455d5 Version: 355f4fb1405ec29d0fac49b4d41fcd78cbd455d5 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"arch/x86/kvm/vmx/nested.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b82c3144d8264265448292ca406f60bafeba3b6f",
"status": "affected",
"version": "355f4fb1405ec29d0fac49b4d41fcd78cbd455d5",
"versionType": "git"
},
{
"lessThan": "4f50e6aec16f69627dbad5704d1e90a255d766a7",
"status": "affected",
"version": "355f4fb1405ec29d0fac49b4d41fcd78cbd455d5",
"versionType": "git"
},
{
"lessThan": "dc3eecfa219ebc9d01eaf7d1abd1441efe884dab",
"status": "affected",
"version": "355f4fb1405ec29d0fac49b4d41fcd78cbd455d5",
"versionType": "git"
},
{
"lessThan": "af56298e9d86e6098cd1d2e155cb2949b7c45412",
"status": "affected",
"version": "355f4fb1405ec29d0fac49b4d41fcd78cbd455d5",
"versionType": "git"
},
{
"lessThan": "589419470030a89f16cf19300658b6dc644ca946",
"status": "affected",
"version": "355f4fb1405ec29d0fac49b4d41fcd78cbd455d5",
"versionType": "git"
},
{
"lessThan": "8001d2ce9d9bd09118ce523aef595aa094573ae3",
"status": "affected",
"version": "355f4fb1405ec29d0fac49b4d41fcd78cbd455d5",
"versionType": "git"
},
{
"lessThan": "1dabef6e206568bf9d9ade74f6e56a48ea35695d",
"status": "affected",
"version": "355f4fb1405ec29d0fac49b4d41fcd78cbd455d5",
"versionType": "git"
},
{
"lessThan": "622ebfac01ba4f9c0060cebd41257fe46fc4a0b3",
"status": "affected",
"version": "355f4fb1405ec29d0fac49b4d41fcd78cbd455d5",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"arch/x86/kvm/vmx/nested.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.9"
},
{
"lessThan": "4.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: nVMX: Hide shadow VMCS right after VMCLEAR\n\nfree_nested() frees the shadow VMCS while vmcs01 still points to it. But\nbecause it is asynchronous with respect to loaded_vmcs_clear(), the vCPU\nmight migrate before the pointer is cleared and __loaded_vmcs_clear()\nmay then execute VMCLEAR.\n\nThe VMCS needs to stay attached until its explicit VMCLEAR completes, but\nthen it can be hidden and the page safely freed."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached through local KVM nested VMX: open /dev/kvm, run a nested guest, then tear down nested state (VMXOFF/handle_vmxoff or vmx_leave_nested). It is not reachable via network or adjacent-radio packets.\nAC:L - A KVM VMM attacker controls both sides of the race by driving nested teardown (VMXOFF/vcpu destroy) while forcing vCPU migration via thread affinity/scheduling so __loaded_vmcs_clear() VMCLEARs the dangling shadow VMCS pointer.\nPR:L - Exploitation needs permission to use /dev/kvm and nested VMX (commonly kvm-group or equivalent), not real init-namespace root; KVM create/run ioctls have no CAP_SYS_ADMIN gate on this path.\nUI:N - After the attacker has KVM/nested access, they trigger free_nested and migration themselves; no separate victim action is required.\nS:C - free_nested runs in host KVM while handling L1 nested VMX teardown, and the UAF corrupts host kernel memory, crossing the guest/hypervisor isolation boundary (guest-to-host escape class).\nC:H - The dangling shadow VMCS pointer lets VMCLEAR operate on a freed page that may be reused, yielding a host kernel use-after-free that can be leveraged for arbitrary information disclosure.\nI:H - VMCLEAR writes VMCS state into the freed page; with page reuse this is host heap corruption enabling write primitives and potential host code execution, consistent with UAF guidance.\nA:H - Use-after-free of the shadow VMCS page can oops/panic the host kernel when VMCLEAR or later accessors touch reallocated memory, fully denying host availability."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:28:32.954Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b82c3144d8264265448292ca406f60bafeba3b6f"
},
{
"url": "https://git.kernel.org/stable/c/4f50e6aec16f69627dbad5704d1e90a255d766a7"
},
{
"url": "https://git.kernel.org/stable/c/dc3eecfa219ebc9d01eaf7d1abd1441efe884dab"
},
{
"url": "https://git.kernel.org/stable/c/af56298e9d86e6098cd1d2e155cb2949b7c45412"
},
{
"url": "https://git.kernel.org/stable/c/589419470030a89f16cf19300658b6dc644ca946"
},
{
"url": "https://git.kernel.org/stable/c/8001d2ce9d9bd09118ce523aef595aa094573ae3"
},
{
"url": "https://git.kernel.org/stable/c/1dabef6e206568bf9d9ade74f6e56a48ea35695d"
},
{
"url": "https://git.kernel.org/stable/c/622ebfac01ba4f9c0060cebd41257fe46fc4a0b3"
}
],
"title": "KVM: nVMX: Hide shadow VMCS right after VMCLEAR",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64562",
"datePublished": "2026-08-04T06:23:21.855Z",
"dateReserved": "2026-07-19T15:36:31.796Z",
"dateUpdated": "2026-08-19T16:28:32.954Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68246 (GCVE-0-2026-68246)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-19 16:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu/gfx11: replace BUG_ON() with WARN_ON()
There's no need to crash the kernel for these cases.
(cherry picked from commit daa62107452d2451787c4248ca38fa2d1a0cbefd)
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 3d879e81f0f9ed5d33b5eda0fe5226c884bb8073 Version: 3d879e81f0f9ed5d33b5eda0fe5226c884bb8073 Version: 3d879e81f0f9ed5d33b5eda0fe5226c884bb8073 Version: 3d879e81f0f9ed5d33b5eda0fe5226c884bb8073 Version: 3d879e81f0f9ed5d33b5eda0fe5226c884bb8073 Version: 3d879e81f0f9ed5d33b5eda0fe5226c884bb8073 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/gfx_v11_0.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "cac8002c675eda7d0d567871287201932857576c",
"status": "affected",
"version": "3d879e81f0f9ed5d33b5eda0fe5226c884bb8073",
"versionType": "git"
},
{
"lessThan": "96b6d68f2b5a208e4d8f1e4a932ec424655e1267",
"status": "affected",
"version": "3d879e81f0f9ed5d33b5eda0fe5226c884bb8073",
"versionType": "git"
},
{
"lessThan": "7aeef42b657d930f3b639220e62120ac1bf058a1",
"status": "affected",
"version": "3d879e81f0f9ed5d33b5eda0fe5226c884bb8073",
"versionType": "git"
},
{
"lessThan": "dfd9bf09fd8fe81f113a5c7e88bfd99f2499542f",
"status": "affected",
"version": "3d879e81f0f9ed5d33b5eda0fe5226c884bb8073",
"versionType": "git"
},
{
"lessThan": "625f301e01bf89694466fdaa1f9904e2c62eb8f2",
"status": "affected",
"version": "3d879e81f0f9ed5d33b5eda0fe5226c884bb8073",
"versionType": "git"
},
{
"lessThan": "0eebcab1ea2a77f086a04108f386f82ee3496022",
"status": "affected",
"version": "3d879e81f0f9ed5d33b5eda0fe5226c884bb8073",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/gfx_v11_0.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.19"
},
{
"lessThan": "5.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/gfx11: replace BUG_ON() with WARN_ON()\n\nThere\u0027s no need to crash the kernel for these cases.\n\n(cherry picked from commit daa62107452d2451787c4248ca38fa2d1a0cbefd)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:32:13.526Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/cac8002c675eda7d0d567871287201932857576c"
},
{
"url": "https://git.kernel.org/stable/c/96b6d68f2b5a208e4d8f1e4a932ec424655e1267"
},
{
"url": "https://git.kernel.org/stable/c/7aeef42b657d930f3b639220e62120ac1bf058a1"
},
{
"url": "https://git.kernel.org/stable/c/dfd9bf09fd8fe81f113a5c7e88bfd99f2499542f"
},
{
"url": "https://git.kernel.org/stable/c/625f301e01bf89694466fdaa1f9904e2c62eb8f2"
},
{
"url": "https://git.kernel.org/stable/c/0eebcab1ea2a77f086a04108f386f82ee3496022"
}
],
"title": "drm/amdgpu/gfx11: replace BUG_ON() with WARN_ON()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68246",
"datePublished": "2026-08-10T12:01:12.489Z",
"dateReserved": "2026-07-30T09:28:09.377Z",
"dateUpdated": "2026-08-19T16:32:13.526Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68361 (GCVE-0-2026-68361)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
hwmon: (corsair-psu) Stop device IO before calling hid_hw_stop
hid_hw_stop() does not stop the device IO.
This results in a race condition between hid_input_report() and the point
immediately following the execution of hid_device_io_start() within
corsairpsu_probe(). If the probe operation fails after "io start" has
been initiated, this race condition will result in a uaf vulnerability
[1].
CPU0 CPU1
==== ====
corsairpsu_probe()
hid_device_io_start()
... unlock driver_input_lock
hid_hw_stop()
kfree(hidraw) __hid_input_report()
... acquire driver_input_lock
hid_report_raw_event()
hidraw_report_event()
... access hidraw's list_lock // trigger uaf
Consequently, when corsairpsu_probe() fails and hid_hw_stop() needs to
be executed, the io_started flag is first cleared while holding the
driver_input_lock to prevent potential race conditions involving input
reports.
[1]
BUG: KASAN: slab-use-after-free in rt_spin_lock+0x83/0x400 kernel/locking/spinlock_rt.c:56
Call Trace:
hidraw_report_event+0x5d/0x3a0 drivers/hid/hidraw.c:577
hid_report_raw_event+0x311/0x1730 drivers/hid/hid-core.c:2076
__hid_input_report drivers/hid/hid-core.c:2152 [inline]
hid_input_report+0x44e/0x580 drivers/hid/hid-core.c:2174
hid_irq_in+0x47e/0x6d0 drivers/hid/usbhid/hid-core.c:286
__usb_hcd_giveback_urb+0x3b3/0x5e0 drivers/usb/core/hcd.c:1657
dummy_timer+0x8a9/0x47d0 drivers/usb/gadget/udc/dummy_hcd.c:2005
Allocated by task 10:
hidraw_connect+0x57/0x430 drivers/hid/hidraw.c:606
hid_connect+0x5bf/0x19d0 drivers/hid/hid-core.c:2277
hid_hw_start+0xa8/0x120 drivers/hid/hid-core.c:2387
corsairpsu_probe+0xd9/0x3c0 drivers/hwmon/corsair-psu.c:782
Freed by task 10:
hidraw_disconnect+0x4f/0x60 drivers/hid/hidraw.c:662
hid_disconnect drivers/hid/hid-core.c:2362 [inline]
hid_hw_stop+0x101/0x1e0 drivers/hid/hid-core.c:2407
corsairpsu_probe+0x327/0x3c0 drivers/hwmon/corsair-psu.c:826
Fix the problem by calling hid_device_io_stop() before calling
hid_hw_stop().
[groeck: Updated subject and description;
call hid_device_io_stop() only if IO has been started]
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d115b51e0e567199c821fc39e13b6af7e78f247d Version: d115b51e0e567199c821fc39e13b6af7e78f247d Version: d115b51e0e567199c821fc39e13b6af7e78f247d Version: d115b51e0e567199c821fc39e13b6af7e78f247d Version: d115b51e0e567199c821fc39e13b6af7e78f247d Version: d115b51e0e567199c821fc39e13b6af7e78f247d Version: d115b51e0e567199c821fc39e13b6af7e78f247d |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/hwmon/corsair-psu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "45dcd8a63069197f64dbda30509b9e224b74c0d8",
"status": "affected",
"version": "d115b51e0e567199c821fc39e13b6af7e78f247d",
"versionType": "git"
},
{
"lessThan": "c80ed058f31bb0251a748034d69feb376741dcb2",
"status": "affected",
"version": "d115b51e0e567199c821fc39e13b6af7e78f247d",
"versionType": "git"
},
{
"lessThan": "e6e1e0f3050d1a1a3ea1c9d6253363e87fdad67a",
"status": "affected",
"version": "d115b51e0e567199c821fc39e13b6af7e78f247d",
"versionType": "git"
},
{
"lessThan": "c0aae8d24f5e52d6910f97d59bc624e131f3ae1a",
"status": "affected",
"version": "d115b51e0e567199c821fc39e13b6af7e78f247d",
"versionType": "git"
},
{
"lessThan": "ec477af3a7e8d3964e62fd24ef01cdebb96b8e4e",
"status": "affected",
"version": "d115b51e0e567199c821fc39e13b6af7e78f247d",
"versionType": "git"
},
{
"lessThan": "bb25bd980f2d9bd34558e1b1d16636e4945baf14",
"status": "affected",
"version": "d115b51e0e567199c821fc39e13b6af7e78f247d",
"versionType": "git"
},
{
"lessThan": "9ab8656548cd737b98d0b19c4253aff8d68e97f4",
"status": "affected",
"version": "d115b51e0e567199c821fc39e13b6af7e78f247d",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/hwmon/corsair-psu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.11"
},
{
"lessThan": "5.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (corsair-psu) Stop device IO before calling hid_hw_stop\n\nhid_hw_stop() does not stop the device IO.\n\nThis results in a race condition between hid_input_report() and the point\nimmediately following the execution of hid_device_io_start() within\ncorsairpsu_probe(). If the probe operation fails after \"io start\" has\nbeen initiated, this race condition will result in a uaf vulnerability\n[1].\n\nCPU0\t\t\t\tCPU1\n====\t\t\t\t====\ncorsairpsu_probe()\n hid_device_io_start()\n ... unlock driver_input_lock\n hid_hw_stop()\n kfree(hidraw)\t\t\t__hid_input_report()\n\t\t\t\t ... acquire driver_input_lock\n\t\t\t\t hid_report_raw_event()\n\t\t\t\t hidraw_report_event()\n\t\t\t\t ... access hidraw\u0027s list_lock // trigger uaf\n\nConsequently, when corsairpsu_probe() fails and hid_hw_stop() needs to\nbe executed, the io_started flag is first cleared while holding the\ndriver_input_lock to prevent potential race conditions involving input\nreports.\n\n[1]\nBUG: KASAN: slab-use-after-free in rt_spin_lock+0x83/0x400 kernel/locking/spinlock_rt.c:56\nCall Trace:\n hidraw_report_event+0x5d/0x3a0 drivers/hid/hidraw.c:577\n hid_report_raw_event+0x311/0x1730 drivers/hid/hid-core.c:2076\n __hid_input_report drivers/hid/hid-core.c:2152 [inline]\n hid_input_report+0x44e/0x580 drivers/hid/hid-core.c:2174\n hid_irq_in+0x47e/0x6d0 drivers/hid/usbhid/hid-core.c:286\n __usb_hcd_giveback_urb+0x3b3/0x5e0 drivers/usb/core/hcd.c:1657\n dummy_timer+0x8a9/0x47d0 drivers/usb/gadget/udc/dummy_hcd.c:2005\n\nAllocated by task 10:\n hidraw_connect+0x57/0x430 drivers/hid/hidraw.c:606\n hid_connect+0x5bf/0x19d0 drivers/hid/hid-core.c:2277\n hid_hw_start+0xa8/0x120 drivers/hid/hid-core.c:2387\n corsairpsu_probe+0xd9/0x3c0 drivers/hwmon/corsair-psu.c:782\n\nFreed by task 10:\n hidraw_disconnect+0x4f/0x60 drivers/hid/hidraw.c:662\n hid_disconnect drivers/hid/hid-core.c:2362 [inline]\n hid_hw_stop+0x101/0x1e0 drivers/hid/hid-core.c:2407\n corsairpsu_probe+0x327/0x3c0 drivers/hwmon/corsair-psu.c:826\n\nFix the problem by calling hid_device_io_stop() before calling\nhid_hw_stop().\n\n[groeck: Updated subject and description;\n call hid_device_io_stop() only if IO has been started]"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:13.231Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/45dcd8a63069197f64dbda30509b9e224b74c0d8"
},
{
"url": "https://git.kernel.org/stable/c/c80ed058f31bb0251a748034d69feb376741dcb2"
},
{
"url": "https://git.kernel.org/stable/c/e6e1e0f3050d1a1a3ea1c9d6253363e87fdad67a"
},
{
"url": "https://git.kernel.org/stable/c/c0aae8d24f5e52d6910f97d59bc624e131f3ae1a"
},
{
"url": "https://git.kernel.org/stable/c/ec477af3a7e8d3964e62fd24ef01cdebb96b8e4e"
},
{
"url": "https://git.kernel.org/stable/c/bb25bd980f2d9bd34558e1b1d16636e4945baf14"
},
{
"url": "https://git.kernel.org/stable/c/9ab8656548cd737b98d0b19c4253aff8d68e97f4"
}
],
"title": "hwmon: (corsair-psu) Stop device IO before calling hid_hw_stop",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68361",
"datePublished": "2026-08-10T12:03:38.332Z",
"dateReserved": "2026-07-30T09:28:09.385Z",
"dateUpdated": "2026-08-19T16:34:13.231Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68093 (GCVE-0-2026-68093)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-19 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after hotplug
If a vCPU stays scheduled out (or blocked) while the last pCPU it ran
on goes through a hotplug cycle (online->offline->online), and the vCPU
then resumes execution on the same pCPU, then it is possible for it to
run with an ASID that has now been assigned to a different vCPU,
resulting in stale TLB translations being used.
svm_enable_virtualization_cpu() resets asid_generation to 1 and sets
next_asid to max_asid + 1 on every CPU online event, including hotplug
cycles. Because next_asid starts beyond the pool boundary, the first
call to new_asid() after an online event always wraps the pool,
incrementing asid_generation to 2 and assigning ASIDs starting from
min_asid.
Consider two vCPUs from different VMs, vCPU-A pinned to CPU-X holding
asid_generation=2 and ASID=N from before the hotplug event:
1. CPU-X goes offline and back online: asid_generation resets to 1,
next_asid = max_asid + 1.
2. One or more vCPUs migrate to CPU-X and call new_asid(), wrapping
the pool and consuming ASIDs starting from min_asid. Eventually
vCPU-B from a different VM is assigned asid_generation=2, ASID=N
— the same ASID that vCPU-A held before the hotplug.
3. vCPU-A enters pre_svm_run() on CPU-X: current_vmcb->cpu is
unchanged so the migration branch is skipped. Its saved
asid_generation=2 matches sd->asid_generation=2, so the generation
check silently passes and vCPU-A continues running with ASID=N —
the same ASID just freshly assigned to vCPU-B.
Both vCPUs from different VMs now run on CPU-X with the same ASID,
causing them to share NPT TLB entries and producing stale translations.
The collision manifests as a KVM internal error (Suberror: 1, emulation
failure). The NPT page fault reports a faulting GPA far outside the
VM's physical memory range — a sign of stale TLB translations being
used. KVM falls back to instruction emulation, which fails on
FPU/XSave instructions (XRSTOR, STMXCSR) that the emulator does not
implement.
Fix this by incrementing asid_generation instead of resetting it to 1
in svm_enable_virtualization_cpu(). On module load, asid_generation
starts at 0 (memset) and the increment produces 1, identical to the
old behaviour. On subsequent hotplug cycles the generation advances
beyond any value a vCPU previously observed on this CPU, so the
generation check in pre_svm_run() reliably forces new_asid() on every
vCPU after every hotplug cycle.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 774c47f1d78e373a6bd2964f4e278d1ce26c21cb Version: 774c47f1d78e373a6bd2964f4e278d1ce26c21cb Version: 774c47f1d78e373a6bd2964f4e278d1ce26c21cb Version: 774c47f1d78e373a6bd2964f4e278d1ce26c21cb Version: 774c47f1d78e373a6bd2964f4e278d1ce26c21cb Version: 774c47f1d78e373a6bd2964f4e278d1ce26c21cb |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"arch/x86/kvm/svm/svm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "2028b81321dc757b6875b99c10d908e349c141e2",
"status": "affected",
"version": "774c47f1d78e373a6bd2964f4e278d1ce26c21cb",
"versionType": "git"
},
{
"lessThan": "60283726f2845bd78b95efbd0e50b93944780477",
"status": "affected",
"version": "774c47f1d78e373a6bd2964f4e278d1ce26c21cb",
"versionType": "git"
},
{
"lessThan": "7508916b4b55d6f5ecc68cd09774dabd3a6b4440",
"status": "affected",
"version": "774c47f1d78e373a6bd2964f4e278d1ce26c21cb",
"versionType": "git"
},
{
"lessThan": "0f33b1c457c2199ed130b92cc2ff363a3f7b9415",
"status": "affected",
"version": "774c47f1d78e373a6bd2964f4e278d1ce26c21cb",
"versionType": "git"
},
{
"lessThan": "6b542d116acecb83a1ca34e8eace304cff6a4ec9",
"status": "affected",
"version": "774c47f1d78e373a6bd2964f4e278d1ce26c21cb",
"versionType": "git"
},
{
"lessThan": "25f744ffa0c8e799e06250ce2e618367b166b0d4",
"status": "affected",
"version": "774c47f1d78e373a6bd2964f4e278d1ce26c21cb",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"arch/x86/kvm/svm/svm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.21"
},
{
"lessThan": "2.6.21",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.21",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.21",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.21",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.21",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.21",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.21",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after hotplug\n\nIf a vCPU stays scheduled out (or blocked) while the last pCPU it ran\non goes through a hotplug cycle (online-\u003eoffline-\u003eonline), and the vCPU\nthen resumes execution on the same pCPU, then it is possible for it to\nrun with an ASID that has now been assigned to a different vCPU,\nresulting in stale TLB translations being used.\n\nsvm_enable_virtualization_cpu() resets asid_generation to 1 and sets\nnext_asid to max_asid + 1 on every CPU online event, including hotplug\ncycles. Because next_asid starts beyond the pool boundary, the first\ncall to new_asid() after an online event always wraps the pool,\nincrementing asid_generation to 2 and assigning ASIDs starting from\nmin_asid.\n\nConsider two vCPUs from different VMs, vCPU-A pinned to CPU-X holding\nasid_generation=2 and ASID=N from before the hotplug event:\n\n 1. CPU-X goes offline and back online: asid_generation resets to 1,\n next_asid = max_asid + 1.\n\n 2. One or more vCPUs migrate to CPU-X and call new_asid(), wrapping\n the pool and consuming ASIDs starting from min_asid. Eventually\n vCPU-B from a different VM is assigned asid_generation=2, ASID=N\n \u2014 the same ASID that vCPU-A held before the hotplug.\n\n 3. vCPU-A enters pre_svm_run() on CPU-X: current_vmcb-\u003ecpu is\n unchanged so the migration branch is skipped. Its saved\n asid_generation=2 matches sd-\u003easid_generation=2, so the generation\n check silently passes and vCPU-A continues running with ASID=N \u2014\n the same ASID just freshly assigned to vCPU-B.\n\nBoth vCPUs from different VMs now run on CPU-X with the same ASID,\ncausing them to share NPT TLB entries and producing stale translations.\n\nThe collision manifests as a KVM internal error (Suberror: 1, emulation\nfailure). The NPT page fault reports a faulting GPA far outside the\nVM\u0027s physical memory range \u2014 a sign of stale TLB translations being\nused. KVM falls back to instruction emulation, which fails on\nFPU/XSave instructions (XRSTOR, STMXCSR) that the emulator does not\nimplement.\n\nFix this by incrementing asid_generation instead of resetting it to 1\nin svm_enable_virtualization_cpu(). On module load, asid_generation\nstarts at 0 (memset) and the increment produces 1, identical to the\nold behaviour. On subsequent hotplug cycles the generation advances\nbeyond any value a vCPU previously observed on this CPU, so the\ngeneration check in pre_svm_run() reliably forces new_asid() on every\nvCPU after every hotplug cycle."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:29:15.060Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/2028b81321dc757b6875b99c10d908e349c141e2"
},
{
"url": "https://git.kernel.org/stable/c/60283726f2845bd78b95efbd0e50b93944780477"
},
{
"url": "https://git.kernel.org/stable/c/7508916b4b55d6f5ecc68cd09774dabd3a6b4440"
},
{
"url": "https://git.kernel.org/stable/c/0f33b1c457c2199ed130b92cc2ff363a3f7b9415"
},
{
"url": "https://git.kernel.org/stable/c/6b542d116acecb83a1ca34e8eace304cff6a4ec9"
},
{
"url": "https://git.kernel.org/stable/c/25f744ffa0c8e799e06250ce2e618367b166b0d4"
}
],
"title": "KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after hotplug",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68093",
"datePublished": "2026-08-10T11:58:05.933Z",
"dateReserved": "2026-07-30T09:28:09.367Z",
"dateUpdated": "2026-08-19T16:29:15.060Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68329 (GCVE-0-2026-68329)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-17 05:03
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
iommu/amd: Wait for completion instead of returning early in iommu_completion_wait()
need_sync is a per-IOMMU flag shared by all domains and devices behind
that IOMMU. It is set whenever a command is queued with sync == true and
cleared when a completion-wait (CWAIT) command is queued. However, a
cleared need_sync only means that a covering CWAIT has been queued, not
that all previously queued commands have actually completed in hardware.
iommu_completion_wait() read need_sync locklessly and returned early
when it was false. This breaks the "block until all previously queued
commands have completed" contract in a multi-CPU scenario:
CPU2: queue inv-B => need_sync = true
CPU1: queue CWAIT(N); need_sync = false; then wait_on_sem(N)
CPU2: read need_sync == false => return 0 (no wait!)
CPU2 returns without waiting for any sequence number even though its
inv-B may not have completed yet (CWAIT(N), queued after inv-B, has not
been signaled). CPU2 then proceeds to, for example, free page-table
pages while the IOMMU can still walk stale translations, opening a
use-after-free window. This is a logical race in the meaning of the
flag, not a memory-visibility issue, so barriers alone do not help.
Fix it without losing the optimization of avoiding redundant CWAIT
commands: take iommu->lock before testing need_sync, and when it is
false do not return early but wait for the last allocated sequence
number (cmd_sem_val). Since need_sync == false implies no sync command
was queued after the last CWAIT, that CWAIT is FIFO-ordered after every
not-yet-completed command, so waiting for its sequence number guarantees
all prior commands (possibly queued by another CPU) have completed. The
common path with pending work is unchanged and no extra hardware command
is issued.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/iommu/amd/iommu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ab7faf5a172ebfdc423ebb3eea4d472740de82f9",
"status": "affected",
"version": "815b33fdc279d34ab40a8bfe1866623a4cc5669b",
"versionType": "git"
},
{
"lessThan": "93494bd446396c257fb589f59894577e96e406e2",
"status": "affected",
"version": "815b33fdc279d34ab40a8bfe1866623a4cc5669b",
"versionType": "git"
},
{
"lessThan": "d053eb7e09e10cbdca3fca8b35c1017d438091b2",
"status": "affected",
"version": "815b33fdc279d34ab40a8bfe1866623a4cc5669b",
"versionType": "git"
},
{
"lessThan": "02f8cefa2ad95ea3754f0cfd6fbae7f866202ccb",
"status": "affected",
"version": "815b33fdc279d34ab40a8bfe1866623a4cc5669b",
"versionType": "git"
},
{
"lessThan": "1e75a8255f11c81fb07e81e5029cfd75804350a0",
"status": "affected",
"version": "815b33fdc279d34ab40a8bfe1866623a4cc5669b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/iommu/amd/iommu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.0"
},
{
"lessThan": "3.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\niommu/amd: Wait for completion instead of returning early in iommu_completion_wait()\n\nneed_sync is a per-IOMMU flag shared by all domains and devices behind\nthat IOMMU. It is set whenever a command is queued with sync == true and\ncleared when a completion-wait (CWAIT) command is queued. However, a\ncleared need_sync only means that a covering CWAIT has been queued, not\nthat all previously queued commands have actually completed in hardware.\n\niommu_completion_wait() read need_sync locklessly and returned early\nwhen it was false. This breaks the \"block until all previously queued\ncommands have completed\" contract in a multi-CPU scenario:\n\n CPU2: queue inv-B =\u003e need_sync = true\n CPU1: queue CWAIT(N); need_sync = false; then wait_on_sem(N)\n CPU2: read need_sync == false =\u003e return 0 (no wait!)\n\nCPU2 returns without waiting for any sequence number even though its\ninv-B may not have completed yet (CWAIT(N), queued after inv-B, has not\nbeen signaled). CPU2 then proceeds to, for example, free page-table\npages while the IOMMU can still walk stale translations, opening a\nuse-after-free window. This is a logical race in the meaning of the\nflag, not a memory-visibility issue, so barriers alone do not help.\n\nFix it without losing the optimization of avoiding redundant CWAIT\ncommands: take iommu-\u003elock before testing need_sync, and when it is\nfalse do not return early but wait for the last allocated sequence\nnumber (cmd_sem_val). Since need_sync == false implies no sync command\nwas queued after the last CWAIT, that CWAIT is FIFO-ordered after every\nnot-yet-completed command, so waiting for its sequence number guarantees\nall prior commands (possibly queued by another CPU) have completed. The\ncommon path with pending work is unchanged and no extra hardware command\nis issued."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The racy `iommu_completion_wait()` is reached through local DMA map/unmap activity \u2014 iommu-dma unmap paths, VFIO/IOMMUFD unmap ioctls, and domain attach/detach \u2014 all driven from the local system rather than from network input.\nAC:L - The attacker drives both sides of the race by issuing concurrent unmap/flush operations on multiple CPUs against the same IOMMU, and can retry indefinitely; each hit frees page-table pages while translations are still live, so no condition outside the attacker\u0027s influence is required.\nPR:L - An unprivileged local user can generate the concurrent IOMMU invalidation traffic needed via ordinary parallel I/O through DMA-API device paths; no root or capability in the init namespace is required, and privileged VFIO users are only one of several entry points.\nUI:N - The race is triggered purely by the attacker\u0027s own concurrent unmap/flush workload; no victim action such as mounting a filesystem or opening a file is needed.\nS:C - The failure defeats IOMMU isolation itself: page-table pages are freed and reused while the IOMMU can still walk them and stale IOTLB entries persist, so a device (including one assigned to a guest or an external peripheral) retains DMA access to host memory outside its domain, crossing the DMA/IOMMU security boundary.\nC:H - Stale translations and use-after-free page tables let a device read host memory that was unmapped, freed, and reallocated to unrelated kernel or user data, yielding effectively arbitrary memory disclosure across the IOMMU boundary.\nI:H - The same stale translations permit device DMA writes into freed and reallocated pages, including page-table pages the IOMMU still walks, giving an arbitrary kernel-memory write primitive usable for control-flow hijacking and privilege escalation.\nA:H - Use-after-free of page-table pages and DMA into reallocated memory corrupt kernel structures and generate IOMMU I/O page faults, leading to oops or panic and full loss of availability."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:03:27.689Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ab7faf5a172ebfdc423ebb3eea4d472740de82f9"
},
{
"url": "https://git.kernel.org/stable/c/93494bd446396c257fb589f59894577e96e406e2"
},
{
"url": "https://git.kernel.org/stable/c/d053eb7e09e10cbdca3fca8b35c1017d438091b2"
},
{
"url": "https://git.kernel.org/stable/c/02f8cefa2ad95ea3754f0cfd6fbae7f866202ccb"
},
{
"url": "https://git.kernel.org/stable/c/1e75a8255f11c81fb07e81e5029cfd75804350a0"
}
],
"title": "iommu/amd: Wait for completion instead of returning early in iommu_completion_wait()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68329",
"datePublished": "2026-08-10T12:03:05.526Z",
"dateReserved": "2026-07-30T09:28:09.383Z",
"dateUpdated": "2026-08-17T05:03:27.689Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72142 (GCVE-0-2026-72142)
Vulnerability from cvelistv5
Published
2026-08-15 05:53
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
i2c: imx: fix locked bus on SMBus block-read of 0 (atomic)
SMBus 3.1 6.5.7 allows a Block Read byte count of 0, but the atomic
(polling) path rejects it as -EPROTO. Worse, it returns without a
NACK+STOP: the next receive cycle has already started, so the target
keeps holding SDA and the bus stays stuck until a power cycle for
this i2c controller.
Reading I2DR to obtain the count likewise arms the next byte on the
count > I2C_SMBUS_BLOCK_MAX path, which also returned -EPROTO directly
and left the bus held.
Handle both: NACK the in-flight dummy byte (TXAK) and extend msgs->len so
the existing last-byte handling emits STOP; the dummy byte is discarded.
A count of 0 is a valid empty block read; a count above
I2C_SMBUS_BLOCK_MAX is still reported as -EPROTO, but only after the bus
has been released.
The interrupt-driven path has the same flaw from a later commit and is
fixed separately, as it carries a different Fixes: tag and stable range.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 8e8782c71595a5ad29e234ce6b3d2fce787fb07a Version: 8e8782c71595a5ad29e234ce6b3d2fce787fb07a Version: 8e8782c71595a5ad29e234ce6b3d2fce787fb07a Version: 8e8782c71595a5ad29e234ce6b3d2fce787fb07a Version: 8e8782c71595a5ad29e234ce6b3d2fce787fb07a Version: 8e8782c71595a5ad29e234ce6b3d2fce787fb07a Version: 8e8782c71595a5ad29e234ce6b3d2fce787fb07a Version: 8e8782c71595a5ad29e234ce6b3d2fce787fb07a |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/i2c/busses/i2c-imx.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "0f29df3c3d607a9dbc14aed0e45504ced4d2e7ec",
"status": "affected",
"version": "8e8782c71595a5ad29e234ce6b3d2fce787fb07a",
"versionType": "git"
},
{
"lessThan": "38d4947431b2410850409fda016b2ac9f640a4dd",
"status": "affected",
"version": "8e8782c71595a5ad29e234ce6b3d2fce787fb07a",
"versionType": "git"
},
{
"lessThan": "e3e8b02d4773cfc5ad561d2e5505efde36c6927a",
"status": "affected",
"version": "8e8782c71595a5ad29e234ce6b3d2fce787fb07a",
"versionType": "git"
},
{
"lessThan": "016ef0f6ca4bc9bf0330ac41bd2ea349759643e3",
"status": "affected",
"version": "8e8782c71595a5ad29e234ce6b3d2fce787fb07a",
"versionType": "git"
},
{
"lessThan": "c882e8cc68fb993700dc21fd6e754001e6297934",
"status": "affected",
"version": "8e8782c71595a5ad29e234ce6b3d2fce787fb07a",
"versionType": "git"
},
{
"lessThan": "6d2c973926d0612360693bc559be2ffde836151b",
"status": "affected",
"version": "8e8782c71595a5ad29e234ce6b3d2fce787fb07a",
"versionType": "git"
},
{
"lessThan": "60ed00d46616a9232e42ea7a3e3c0273d7cf7543",
"status": "affected",
"version": "8e8782c71595a5ad29e234ce6b3d2fce787fb07a",
"versionType": "git"
},
{
"lessThan": "cb2fc37857693b55909fb77dc2c87cfbc1cdc476",
"status": "affected",
"version": "8e8782c71595a5ad29e234ce6b3d2fce787fb07a",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/i2c/busses/i2c-imx.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.16"
},
{
"lessThan": "3.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.16",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: imx: fix locked bus on SMBus block-read of 0 (atomic)\n\nSMBus 3.1 6.5.7 allows a Block Read byte count of 0, but the atomic\n(polling) path rejects it as -EPROTO. Worse, it returns without a\nNACK+STOP: the next receive cycle has already started, so the target\nkeeps holding SDA and the bus stays stuck until a power cycle for\nthis i2c controller.\n\nReading I2DR to obtain the count likewise arms the next byte on the\ncount \u003e I2C_SMBUS_BLOCK_MAX path, which also returned -EPROTO directly\nand left the bus held.\n\nHandle both: NACK the in-flight dummy byte (TXAK) and extend msgs-\u003elen so\nthe existing last-byte handling emits STOP; the dummy byte is discarded.\nA count of 0 is a valid empty block read; a count above\nI2C_SMBUS_BLOCK_MAX is still reported as -EPROTO, but only after the bus\nhas been released.\n\nThe interrupt-driven path has the same flaw from a later commit and is\nfixed separately, as it carries a different Fixes: tag and stable range."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:51.665Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/0f29df3c3d607a9dbc14aed0e45504ced4d2e7ec"
},
{
"url": "https://git.kernel.org/stable/c/38d4947431b2410850409fda016b2ac9f640a4dd"
},
{
"url": "https://git.kernel.org/stable/c/e3e8b02d4773cfc5ad561d2e5505efde36c6927a"
},
{
"url": "https://git.kernel.org/stable/c/016ef0f6ca4bc9bf0330ac41bd2ea349759643e3"
},
{
"url": "https://git.kernel.org/stable/c/c882e8cc68fb993700dc21fd6e754001e6297934"
},
{
"url": "https://git.kernel.org/stable/c/6d2c973926d0612360693bc559be2ffde836151b"
},
{
"url": "https://git.kernel.org/stable/c/60ed00d46616a9232e42ea7a3e3c0273d7cf7543"
},
{
"url": "https://git.kernel.org/stable/c/cb2fc37857693b55909fb77dc2c87cfbc1cdc476"
}
],
"title": "i2c: imx: fix locked bus on SMBus block-read of 0 (atomic)",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72142",
"datePublished": "2026-08-15T05:53:15.489Z",
"dateReserved": "2026-08-09T03:40:39.908Z",
"dateUpdated": "2026-08-23T12:46:51.665Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68425 (GCVE-0-2026-68425)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-19 16:35
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
IB/mad: Drop unmatched RMPP responses before reassembly
Kernel-handled RMPP receive processing starts reassembly for active
DATA responses before the response is matched to an outstanding send.
The normal match happens later, after ib_process_rmpp_recv_wc() has
either assembled a complete message or consumed the segment.
That ordering lets an unsolicited response that routes to a kernel
RMPP agent by the high TID bits allocate or extend RMPP receive state
before the full TID and source address are checked against a real
request. A reordered burst can therefore reach the receive-side
insertion path even though the response would not match any send.
For kernel-handled RMPP DATA responses, require the existing
ib_find_send_mad() match before entering RMPP reassembly. The matcher
already checks the full TID, management class and source address/GID
against the agent wait, backlog and in-flight send lists. If there is
no match, drop the response without creating RMPP state.
This leaves the RMPP window behavior unchanged and only rejects
responses that have no corresponding request.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: fa619a77046bef30478697aba0553991033afb8e Version: fa619a77046bef30478697aba0553991033afb8e Version: fa619a77046bef30478697aba0553991033afb8e Version: fa619a77046bef30478697aba0553991033afb8e Version: fa619a77046bef30478697aba0553991033afb8e Version: fa619a77046bef30478697aba0553991033afb8e Version: fa619a77046bef30478697aba0553991033afb8e Version: fa619a77046bef30478697aba0553991033afb8e |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/core/mad.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "45416c87ebcece1e90f3bc5bc172d106b77c6b69",
"status": "affected",
"version": "fa619a77046bef30478697aba0553991033afb8e",
"versionType": "git"
},
{
"lessThan": "9634fb1f4d404f36a20ffbcb8797369db69b06bb",
"status": "affected",
"version": "fa619a77046bef30478697aba0553991033afb8e",
"versionType": "git"
},
{
"lessThan": "bfb9e8243fd2099d1080d09222964d988f991d9b",
"status": "affected",
"version": "fa619a77046bef30478697aba0553991033afb8e",
"versionType": "git"
},
{
"lessThan": "dfa535c94406c03d3f0c869ef3ba5528e395737c",
"status": "affected",
"version": "fa619a77046bef30478697aba0553991033afb8e",
"versionType": "git"
},
{
"lessThan": "6e1bd7f590b0ccfee07f7fe1d48b92059bd37d72",
"status": "affected",
"version": "fa619a77046bef30478697aba0553991033afb8e",
"versionType": "git"
},
{
"lessThan": "98d2d468b4faa1fdc68c0c6c238389906ee3490c",
"status": "affected",
"version": "fa619a77046bef30478697aba0553991033afb8e",
"versionType": "git"
},
{
"lessThan": "ad9c9ad3204f63a46f0f7de29687a8e512f05e29",
"status": "affected",
"version": "fa619a77046bef30478697aba0553991033afb8e",
"versionType": "git"
},
{
"lessThan": "d2e52d610b9b09694261632340b801a421e0b0c5",
"status": "affected",
"version": "fa619a77046bef30478697aba0553991033afb8e",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/core/mad.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.13"
},
{
"lessThan": "2.6.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nIB/mad: Drop unmatched RMPP responses before reassembly\n\nKernel-handled RMPP receive processing starts reassembly for active\nDATA responses before the response is matched to an outstanding send.\nThe normal match happens later, after ib_process_rmpp_recv_wc() has\neither assembled a complete message or consumed the segment.\n\nThat ordering lets an unsolicited response that routes to a kernel\nRMPP agent by the high TID bits allocate or extend RMPP receive state\nbefore the full TID and source address are checked against a real\nrequest. A reordered burst can therefore reach the receive-side\ninsertion path even though the response would not match any send.\n\nFor kernel-handled RMPP DATA responses, require the existing\nib_find_send_mad() match before entering RMPP reassembly. The matcher\nalready checks the full TID, management class and source address/GID\nagainst the agent wait, backlog and in-flight send lists. If there is\nno match, drop the response without creating RMPP state.\n\nThis leaves the RMPP window behavior unchanged and only rejects\nresponses that have no corresponding request."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The attacker must be a node on the same InfiniBand fabric, sending unsolicited GSI (QP1) management datagrams to the victim port; MAD/SA traffic is subnet-local, matching the CVSS \"shared physical or logical network\" definition rather than routable network reach.\nAC:L - No race or unusual precondition is needed: the attacker just sends active RMPP DATA response MADs whose high TID bits name a kernel RMPP agent, and hi_tid is a small cyclic xarray index in [0,2^24) that is trivially enumerated or brute-forced.\nPR:N - The MAD receive path accepts unsolicited datagrams from any fabric peer with no authentication; the only gate is ib_mad_enforce_security() P_Key membership, which the default partition typically grants to every node on the subnet.\nUI:N - Reassembly state is created entirely from attacker-sent packets in the completion handler; no action by a local user or administrator is needed, and the always-registered ib_sa kernel agent is the target.\nS:U - The injected RMPP state, allocations and AH objects all live inside the kernel\u0027s own IB MAD layer on the same host, so the impact stays within a single security authority.\nC:N - The flaw creates unmatched reassembly state; it provides no out-of-bounds read, no kernel memory disclosure, and the ACKs the kernel emits echo only attacker-supplied header fields.\nI:L - An unauthenticated fabric peer can insert arbitrary unsolicited entries into the kernel agent\u0027s RMPP reassembly lists and make the kernel emit ACKs, and a colliding entry (SA TIDs come from a predictable tid++ counter) diverts and drops a legitimate SA response\u0027s segments \u2014 limited, bounded modification of kernel protocol state.\nA:H - Each unmatched segment allocates a mad_rmpp_recv, an AH and a retained ~1-2 KB MAD buffer held for 40 seconds with no matching request, so a burst causes unbounded memory/resource exhaustion, while the O(N) rmpp_list walks under an IRQ-disabled spinlock stall MAD processing and break SA/path resolution for the node."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:35:19.996Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/45416c87ebcece1e90f3bc5bc172d106b77c6b69"
},
{
"url": "https://git.kernel.org/stable/c/9634fb1f4d404f36a20ffbcb8797369db69b06bb"
},
{
"url": "https://git.kernel.org/stable/c/bfb9e8243fd2099d1080d09222964d988f991d9b"
},
{
"url": "https://git.kernel.org/stable/c/dfa535c94406c03d3f0c869ef3ba5528e395737c"
},
{
"url": "https://git.kernel.org/stable/c/6e1bd7f590b0ccfee07f7fe1d48b92059bd37d72"
},
{
"url": "https://git.kernel.org/stable/c/98d2d468b4faa1fdc68c0c6c238389906ee3490c"
},
{
"url": "https://git.kernel.org/stable/c/ad9c9ad3204f63a46f0f7de29687a8e512f05e29"
},
{
"url": "https://git.kernel.org/stable/c/d2e52d610b9b09694261632340b801a421e0b0c5"
}
],
"title": "IB/mad: Drop unmatched RMPP responses before reassembly",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68425",
"datePublished": "2026-08-10T12:04:45.947Z",
"dateReserved": "2026-07-30T09:28:09.392Z",
"dateUpdated": "2026-08-19T16:35:19.996Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-53078 (GCVE-0-2026-53078)
Vulnerability from cvelistv5
Published
2026-06-24 16:30
Modified
2026-08-05 12:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
bpf: Fix same-register dst/src OOB read and pointer leak in sock_ops
When a BPF sock_ops program accesses ctx fields with dst_reg == src_reg,
the SOCK_OPS_GET_SK() and SOCK_OPS_GET_FIELD() macros fail to zero the
destination register in the !fullsock / !locked_tcp_sock path.
Both macros borrow a temporary register to check is_fullsock /
is_locked_tcp_sock when dst_reg == src_reg, because dst_reg holds the
ctx pointer. When the check is false (e.g., TCP_NEW_SYN_RECV state with
a request_sock), dst_reg should be zeroed but is not, leaving the stale
ctx pointer:
- SOCK_OPS_GET_SK: dst_reg retains the ctx pointer, passes NULL checks
as PTR_TO_SOCKET_OR_NULL, and can be used as a bogus socket pointer,
leading to stack-out-of-bounds access in helpers like
bpf_skc_to_tcp6_sock().
- SOCK_OPS_GET_FIELD: dst_reg retains the ctx pointer which the
verifier believes is a SCALAR_VALUE, leaking a kernel pointer.
Fix both macros by:
- Changing JMP_A(1) to JMP_A(2) in the fullsock path to skip the
added instruction.
- Adding BPF_MOV64_IMM(si->dst_reg, 0) after the temp register
restore in the !fullsock path, placed after the restore because
dst_reg == src_reg means we need src_reg intact to read ctx->temp.
References
| URL | Tags | |
|---|---|---|
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: fd09af010788a884de1c39537c288830c3d305db Version: fd09af010788a884de1c39537c288830c3d305db Version: fd09af010788a884de1c39537c288830c3d305db Version: fd09af010788a884de1c39537c288830c3d305db Version: 48be3df15aa19c04eadf156c9129293c9a10389f Version: cd4644d904e1d153d516e73e2e127e7a2fe687e1 Version: 6e0bc946cbeec538322820786b5fb5200a2216ab Version: a7e52f7f675046d9ffc5692d815fa67c82fcdbf5 Version: db7f8c57dbdd31f7e59f8dc8d1e1b38607a320ef Version: 5.7.18 ≤ Version: 5.8.4 ≤ Version: 5.4.61 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/core/filter.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "2a2c98141e0a75f2d4a7d78b0316c88b3da784ac",
"status": "affected",
"version": "fd09af010788a884de1c39537c288830c3d305db",
"versionType": "git"
},
{
"lessThan": "22400725de070b787cd6d806c5795370ab46d269",
"status": "affected",
"version": "fd09af010788a884de1c39537c288830c3d305db",
"versionType": "git"
},
{
"lessThan": "18e3ffde1822f0b48b1753bf34aa97ce839df1d8",
"status": "affected",
"version": "fd09af010788a884de1c39537c288830c3d305db",
"versionType": "git"
},
{
"lessThan": "10f86a2a5c91fc4c4d001960f1c21abe52545ef6",
"status": "affected",
"version": "fd09af010788a884de1c39537c288830c3d305db",
"versionType": "git"
},
{
"status": "affected",
"version": "48be3df15aa19c04eadf156c9129293c9a10389f",
"versionType": "git"
},
{
"status": "affected",
"version": "cd4644d904e1d153d516e73e2e127e7a2fe687e1",
"versionType": "git"
},
{
"status": "affected",
"version": "6e0bc946cbeec538322820786b5fb5200a2216ab",
"versionType": "git"
},
{
"status": "affected",
"version": "a7e52f7f675046d9ffc5692d815fa67c82fcdbf5",
"versionType": "git"
},
{
"status": "affected",
"version": "db7f8c57dbdd31f7e59f8dc8d1e1b38607a320ef",
"versionType": "git"
},
{
"lessThan": "5.8",
"status": "affected",
"version": "5.7.18",
"versionType": "semver"
},
{
"lessThan": "5.9",
"status": "affected",
"version": "5.8.4",
"versionType": "semver"
},
{
"lessThan": "5.5",
"status": "affected",
"version": "5.4.61",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/core/filter.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.9"
},
{
"lessThan": "5.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.10",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.7.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.8.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.4.61",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.7.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.8.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix same-register dst/src OOB read and pointer leak in sock_ops\n\nWhen a BPF sock_ops program accesses ctx fields with dst_reg == src_reg,\nthe SOCK_OPS_GET_SK() and SOCK_OPS_GET_FIELD() macros fail to zero the\ndestination register in the !fullsock / !locked_tcp_sock path.\n\nBoth macros borrow a temporary register to check is_fullsock /\nis_locked_tcp_sock when dst_reg == src_reg, because dst_reg holds the\nctx pointer. When the check is false (e.g., TCP_NEW_SYN_RECV state with\na request_sock), dst_reg should be zeroed but is not, leaving the stale\nctx pointer:\n\n - SOCK_OPS_GET_SK: dst_reg retains the ctx pointer, passes NULL checks\n as PTR_TO_SOCKET_OR_NULL, and can be used as a bogus socket pointer,\n leading to stack-out-of-bounds access in helpers like\n bpf_skc_to_tcp6_sock().\n\n - SOCK_OPS_GET_FIELD: dst_reg retains the ctx pointer which the\n verifier believes is a SCALAR_VALUE, leaking a kernel pointer.\n\nFix both macros by:\n - Changing JMP_A(1) to JMP_A(2) in the fullsock path to skip the\n added instruction.\n - Adding BPF_MOV64_IMM(si-\u003edst_reg, 0) after the temp register\n restore in the !fullsock path, placed after the restore because\n dst_reg == src_reg means we need src_reg intact to read ctx-\u003etemp."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires loading and attaching a crafted BPF_PROG_TYPE_SOCK_OPS program through the local bpf() interface. Remote TCP traffic can trigger an attached program, but cannot by itself create the malicious program.\nAC:L - The attacker controls the BPF bytecode pattern and can reliably trigger non-fullsock/request_sock sock_ops callbacks with local TCP activity. No uncontrolled race or rare runtime condition is required.\nPR:L - Loading/attaching sock_ops BPF requires BPF and net-admin style privileges, but these can be available to a local user through user-namespace/BPF-token delegation in plausible deployments. Under the required overestimate rule this is Low rather than High.\nUI:N - No victim action is needed after the attacker loads and attaches the crafted sock_ops program. The attacker can trigger the callback path directly.\nS:U - The impact is within the same kernel security authority. This is not a VM escape, IOMMU bypass, or cross-scope boundary violation.\nC:H - The bug leaks a kernel context pointer as a scalar and lets it be used as a bogus socket pointer. Helper dereferences can perform kernel stack out-of-bounds reads, so confidentiality impact is High.\nI:H - The bogus verifier-approved socket pointer can reach helpers that mutate socket-associated state, creating plausible kernel memory corruption from a misinterpreted stack object. With uncertainty required to resolve upward, integrity impact is High.\nA:H - The same bogus pointer path can cause kernel stack out-of-bounds accesses and invalid helper dereferences. These can crash or panic the kernel, so availability impact is High."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T12:33:11.207Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/2a2c98141e0a75f2d4a7d78b0316c88b3da784ac"
},
{
"url": "https://git.kernel.org/stable/c/22400725de070b787cd6d806c5795370ab46d269"
},
{
"url": "https://git.kernel.org/stable/c/18e3ffde1822f0b48b1753bf34aa97ce839df1d8"
},
{
"url": "https://git.kernel.org/stable/c/10f86a2a5c91fc4c4d001960f1c21abe52545ef6"
}
],
"title": "bpf: Fix same-register dst/src OOB read and pointer leak in sock_ops",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-53078",
"datePublished": "2026-06-24T16:30:18.858Z",
"dateReserved": "2026-06-09T07:44:35.383Z",
"dateUpdated": "2026-08-05T12:33:11.207Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68358 (GCVE-0-2026-68358)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-17 05:04
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
hwmon: (nzxt-kraken3) Stop device IO before calling hid_hw_stop
Calling hid_hw_stop() does not stop the device IO.
This results in a race condition between hid_input_report() and the point
immediately following the execution of hid_device_io_start() within
the driver probe function. If the probe operation fails after "io start"
has been initiated, this race condition will result in a UAF vulnerability.
Fix the problem by calling hid_device_io_stop() before calling
hid_hw_stop().
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/hwmon/nzxt-kraken3.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "8cb282c34d582afcca7b1bae7c7bcd5204fd03d6",
"status": "affected",
"version": "f3b4b146eb107bda47ee4a8b0927699f962e8a2f",
"versionType": "git"
},
{
"lessThan": "305c23993e43db9a3681978691b1f9f2a1b26299",
"status": "affected",
"version": "f3b4b146eb107bda47ee4a8b0927699f962e8a2f",
"versionType": "git"
},
{
"lessThan": "dc73b0dfeab8dc0fe73e29c4401d032279e23efd",
"status": "affected",
"version": "f3b4b146eb107bda47ee4a8b0927699f962e8a2f",
"versionType": "git"
},
{
"lessThan": "f151d0143ac4e086f92f52328ebdbdc50933d8ef",
"status": "affected",
"version": "f3b4b146eb107bda47ee4a8b0927699f962e8a2f",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/hwmon/nzxt-kraken3.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.9"
},
{
"lessThan": "6.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (nzxt-kraken3) Stop device IO before calling hid_hw_stop\n\nCalling hid_hw_stop() does not stop the device IO.\nThis results in a race condition between hid_input_report() and the point\nimmediately following the execution of hid_device_io_start() within\nthe driver probe function. If the probe operation fails after \"io start\"\nhas been initiated, this race condition will result in a UAF vulnerability.\n\nFix the problem by calling hid_device_io_stop() before calling\nhid_hw_stop()."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:04:01.579Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/8cb282c34d582afcca7b1bae7c7bcd5204fd03d6"
},
{
"url": "https://git.kernel.org/stable/c/305c23993e43db9a3681978691b1f9f2a1b26299"
},
{
"url": "https://git.kernel.org/stable/c/dc73b0dfeab8dc0fe73e29c4401d032279e23efd"
},
{
"url": "https://git.kernel.org/stable/c/f151d0143ac4e086f92f52328ebdbdc50933d8ef"
}
],
"title": "hwmon: (nzxt-kraken3) Stop device IO before calling hid_hw_stop",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68358",
"datePublished": "2026-08-10T12:03:35.247Z",
"dateReserved": "2026-07-30T09:28:09.385Z",
"dateUpdated": "2026-08-17T05:04:01.579Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68262 (GCVE-0-2026-68262)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-17 05:01
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/imagination: Fix user array stride in pvr_set_uobj_array()
pvr_set_uobj_array() copies an array of kernel objects to a userspace
array whose element size is described by out->stride. When out->stride
is different from the kernel object size, the slow path advances the
userspace pointer by the kernel object size and the kernel pointer by the
userspace stride.
This reverses the intended layout. For larger userspace strides, later
copies read from the wrong kernel addresses. For smaller userspace
strides, later copies are written at the wrong userspace offsets. The
padding clear is also done only for the first element instead of the
padding area for each element.
Advance the userspace pointer by out->stride and the kernel pointer by
obj_size, and clear per-element padding while the current userspace
pointer is still available.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/imagination/pvr_drv.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "bbebc39a70f6fc9b02637c8624349e30325873cb",
"status": "affected",
"version": "f99f5f3ea7efd54ba0529c4f2d7c72712918a522",
"versionType": "git"
},
{
"lessThan": "b983a35dad3701399c692d7c6eb57d8b6ffc0929",
"status": "affected",
"version": "f99f5f3ea7efd54ba0529c4f2d7c72712918a522",
"versionType": "git"
},
{
"lessThan": "09beaf4aec05b0525f2153dce693f3eb3166697a",
"status": "affected",
"version": "f99f5f3ea7efd54ba0529c4f2d7c72712918a522",
"versionType": "git"
},
{
"lessThan": "8dc8f3f4c2382fb7d1b1986ba8f33a2466cd3d7a",
"status": "affected",
"version": "f99f5f3ea7efd54ba0529c4f2d7c72712918a522",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/imagination/pvr_drv.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.8"
},
{
"lessThan": "6.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/imagination: Fix user array stride in pvr_set_uobj_array()\n\npvr_set_uobj_array() copies an array of kernel objects to a userspace\narray whose element size is described by out-\u003estride. When out-\u003estride\nis different from the kernel object size, the slow path advances the\nuserspace pointer by the kernel object size and the kernel pointer by the\nuserspace stride.\n\nThis reverses the intended layout. For larger userspace strides, later\ncopies read from the wrong kernel addresses. For smaller userspace\nstrides, later copies are written at the wrong userspace offsets. The\npadding clear is also done only for the first element instead of the\npadding area for each element.\n\nAdvance the userspace pointer by out-\u003estride and the kernel pointer by\nobj_size, and clear per-element padding while the current userspace\npointer is still available."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached through the DRM_IOCTL_PVR_DEV_QUERY ioctl on the Imagination PowerVR render node (/dev/dri/renderD*), requiring local access to the device file; there is no remote or adjacent path.\nAC:L - The attacker fully controls the drm_pvr_obj_array stride and count fields passed to the ioctl, so the mis-advanced kernel pointer and the resulting out-of-bounds read occur deterministically on every call, with no race or unpredictable precondition.\nPR:L - The DEV_QUERY ioctl is marked DRM_RENDER_ALLOW, so it needs neither DRM master nor authentication - any unprivileged local user or sandboxed app that can open the render node (standard for GUI/Android/embedded graphics clients) can invoke it.\nUI:N - The attacking process triggers the flaw entirely on its own by issuing a single ioctl; no action by another user or victim process is needed.\nS:U - The out-of-bounds read and the disclosure occur within the kernel and are delivered to the calling process; no other security authority (VM, IOMMU domain) is crossed.\nC:H - With stride \u003e obj_size the kernel source pointer advances by the attacker-chosen stride (up to ~4 GiB) past the static_data_areas array, and copy_to_user hands 16 bytes per element back to userspace; repeating the ioctl with varying strides yields a repeatable read of arbitrary kernel memory at chosen offsets from a known symbol, leaking pointers, keys and other kernel data.\nI:N - Because min_stride equals the object size, only the stride \u003e obj_size case is reachable, so all userspace writes stay inside the caller\u0027s own count*stride buffer and no kernel memory is written; the only integrity effect is misplaced/uncleared data in the caller\u0027s own buffer.\nA:H - The kernel-side reads walk far outside the static array into unmapped, text or slab memory; with hardened usercopy or KASAN enabled this triggers usercopy_abort()/BUG and a KASAN out-of-bounds report, killing the task or panicking the system, and the fault is trivially repeatable."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:01:54.563Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/bbebc39a70f6fc9b02637c8624349e30325873cb"
},
{
"url": "https://git.kernel.org/stable/c/b983a35dad3701399c692d7c6eb57d8b6ffc0929"
},
{
"url": "https://git.kernel.org/stable/c/09beaf4aec05b0525f2153dce693f3eb3166697a"
},
{
"url": "https://git.kernel.org/stable/c/8dc8f3f4c2382fb7d1b1986ba8f33a2466cd3d7a"
}
],
"title": "drm/imagination: Fix user array stride in pvr_set_uobj_array()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68262",
"datePublished": "2026-08-10T12:01:36.582Z",
"dateReserved": "2026-07-30T09:28:09.378Z",
"dateUpdated": "2026-08-17T05:01:54.563Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68222 (GCVE-0-2026-68222)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: msi2500: Return queued buffers on start_streaming() failure
The vb2 framework hands buffers to the driver via buf_queue() before
calling start_streaming(). If start_streaming() returns an error
without first returning those buffers via vb2_buffer_done(),
vb2_start_streaming() fires WARN_ON(owned_by_drv_count) and the queued
buffers leak.
msi2500_start_streaming() had five error paths that all hit this trap
and were further tangled by ret-overwriting between calls:
- -ENODEV when the USB device was already disconnected
- -ERESTARTSYS when mutex_lock_interruptible() was interrupted
- msi2500_set_usb_adc() failure: ret was silently overwritten by
the next call (msi2500_isoc_init), so the error was lost entirely
- msi2500_isoc_init() failure: cleanup_queued_bufs was called, but
the function then fell through to msi2500_ctrl_msg() and again
masked the original error by overwriting ret
- msi2500_ctrl_msg(CMD_START_STREAMING) failure: no cleanup at all,
leaving isoc URBs submitted with no way for the driver to consume
them
Consolidate the error paths into a small goto chain. Every failure
now stops the function, drains the queued-buffer list, and returns
the real error code. The ctrl_msg failure path also rolls back the
preceding msi2500_isoc_init() via msi2500_isoc_cleanup() before
unlocking and draining.
The cleanup helper takes a vb2_buffer_state argument so that the
start_streaming error paths can pass VB2_BUF_STATE_QUEUED (as
expected by userspace on start_streaming failure) while stop_streaming
keeps its existing VB2_BUF_STATE_ERROR semantics.
This mirrors the uvcvideo fix in commit 4cf3b6fd54eb ("media: uvcvideo:
Return queued buffers on start_streaming() failure").
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 977e444f59ad16eedf66acae4f357011c74da291 Version: 977e444f59ad16eedf66acae4f357011c74da291 Version: 977e444f59ad16eedf66acae4f357011c74da291 Version: 977e444f59ad16eedf66acae4f357011c74da291 Version: 977e444f59ad16eedf66acae4f357011c74da291 Version: 977e444f59ad16eedf66acae4f357011c74da291 Version: 977e444f59ad16eedf66acae4f357011c74da291 Version: 977e444f59ad16eedf66acae4f357011c74da291 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/usb/msi2500/msi2500.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c74b680704baecea4620c0774de473069e0bc4e8",
"status": "affected",
"version": "977e444f59ad16eedf66acae4f357011c74da291",
"versionType": "git"
},
{
"lessThan": "2d10eedb786a13f91d76e11320fabb0bf712519f",
"status": "affected",
"version": "977e444f59ad16eedf66acae4f357011c74da291",
"versionType": "git"
},
{
"lessThan": "2de14ddb4fea04ca616403a6ba81c5e8099e9b9e",
"status": "affected",
"version": "977e444f59ad16eedf66acae4f357011c74da291",
"versionType": "git"
},
{
"lessThan": "1d58229b330b7f67fbfa07e0f2a8a51fbeafaa9a",
"status": "affected",
"version": "977e444f59ad16eedf66acae4f357011c74da291",
"versionType": "git"
},
{
"lessThan": "bab9d5a67d4db96ae8c187b92b37979911302a10",
"status": "affected",
"version": "977e444f59ad16eedf66acae4f357011c74da291",
"versionType": "git"
},
{
"lessThan": "264b5380c4f8aa92dbc2983ecd2b627f1d5e0061",
"status": "affected",
"version": "977e444f59ad16eedf66acae4f357011c74da291",
"versionType": "git"
},
{
"lessThan": "3673cb0a5711e910074d69201da9e1535c03f97a",
"status": "affected",
"version": "977e444f59ad16eedf66acae4f357011c74da291",
"versionType": "git"
},
{
"lessThan": "7201c17786a498497bca57752883b90914d405ac",
"status": "affected",
"version": "977e444f59ad16eedf66acae4f357011c74da291",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/usb/msi2500/msi2500.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.12"
},
{
"lessThan": "3.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: msi2500: Return queued buffers on start_streaming() failure\n\nThe vb2 framework hands buffers to the driver via buf_queue() before\ncalling start_streaming(). If start_streaming() returns an error\nwithout first returning those buffers via vb2_buffer_done(),\nvb2_start_streaming() fires WARN_ON(owned_by_drv_count) and the queued\nbuffers leak.\n\nmsi2500_start_streaming() had five error paths that all hit this trap\nand were further tangled by ret-overwriting between calls:\n\n - -ENODEV when the USB device was already disconnected\n - -ERESTARTSYS when mutex_lock_interruptible() was interrupted\n - msi2500_set_usb_adc() failure: ret was silently overwritten by\n the next call (msi2500_isoc_init), so the error was lost entirely\n - msi2500_isoc_init() failure: cleanup_queued_bufs was called, but\n the function then fell through to msi2500_ctrl_msg() and again\n masked the original error by overwriting ret\n - msi2500_ctrl_msg(CMD_START_STREAMING) failure: no cleanup at all,\n leaving isoc URBs submitted with no way for the driver to consume\n them\n\nConsolidate the error paths into a small goto chain. Every failure\nnow stops the function, drains the queued-buffer list, and returns\nthe real error code. The ctrl_msg failure path also rolls back the\npreceding msi2500_isoc_init() via msi2500_isoc_cleanup() before\nunlocking and draining.\n\nThe cleanup helper takes a vb2_buffer_state argument so that the\nstart_streaming error paths can pass VB2_BUF_STATE_QUEUED (as\nexpected by userspace on start_streaming failure) while stop_streaming\nkeeps its existing VB2_BUF_STATE_ERROR semantics.\n\nThis mirrors the uvcvideo fix in commit 4cf3b6fd54eb (\"media: uvcvideo:\nReturn queued buffers on start_streaming() failure\")."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable code is reached only through a local VIDIOC_STREAMON ioctl on the msi2500 SDR character device /dev/swradioN; no network or remote input is involved, and the failure paths are driven from a local process\u0027s syscalls.\nAC:L - The attacker controls both sides of the trigger: hold dev-\u003ev4l2_lock from a second thread and send a signal to the STREAMON thread so mutex_lock_interruptible() returns -ERESTARTSYS, hitting the leaking error path deterministically and repeatably.\nPR:L - Only an unprivileged local user with access to the V4L2/SDR device node is needed; on desktop, Android and embedded systems these nodes are granted to the logged-in seat or a device group, and no capability check guards STREAMON.\nUI:N - The whole sequence (REQBUFS, QBUF, STREAMON, signal, repeat) is performed by the attacker\u0027s own process; no victim action such as plugging in hardware or opening a file is required.\nS:U - The corruption is confined to kernel memory managed by the same kernel security authority; no VM, IOMMU or sandbox boundary is crossed.\nC:H - Buffers left on dev-\u003equeued_bufs after the vb2 core reclaims and later frees them become dangling pointers reused by cleanup_queued_bufs()/get_next_fill_buf(), giving a use-after-free that can be groomed to read reclaimed kernel heap contents back into userspace buffers.\nI:H - The stale list entries permit list_add_tail() on an already-linked node (list corruption) and vb2_buffer_done()/isoc-handler writes into freed objects, yielding attacker-influenced kernel heap writes exploitable for control-flow hijacking.\nA:H - At minimum the missing buffer return trips WARN_ON(owned_by_drv_count) (fatal with panic_on_warn) and leaks buffers; the resulting list corruption and use-after-free reliably oops or hang the kernel."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:51.745Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c74b680704baecea4620c0774de473069e0bc4e8"
},
{
"url": "https://git.kernel.org/stable/c/2d10eedb786a13f91d76e11320fabb0bf712519f"
},
{
"url": "https://git.kernel.org/stable/c/2de14ddb4fea04ca616403a6ba81c5e8099e9b9e"
},
{
"url": "https://git.kernel.org/stable/c/1d58229b330b7f67fbfa07e0f2a8a51fbeafaa9a"
},
{
"url": "https://git.kernel.org/stable/c/bab9d5a67d4db96ae8c187b92b37979911302a10"
},
{
"url": "https://git.kernel.org/stable/c/264b5380c4f8aa92dbc2983ecd2b627f1d5e0061"
},
{
"url": "https://git.kernel.org/stable/c/3673cb0a5711e910074d69201da9e1535c03f97a"
},
{
"url": "https://git.kernel.org/stable/c/7201c17786a498497bca57752883b90914d405ac"
}
],
"title": "media: msi2500: Return queued buffers on start_streaming() failure",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68222",
"datePublished": "2026-08-10T12:00:42.687Z",
"dateReserved": "2026-07-30T09:28:09.375Z",
"dateUpdated": "2026-08-19T16:31:51.745Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68099 (GCVE-0-2026-68099)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-23 12:45
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: restore DACL size on check_add_overflow() to avoid malformed ACL
check_add_overflow() unconditionally writes the truncated sum into *d
even on overflow, per its contract in include/linux/overflow.h.
The four check_add_overflow() guards in set_posix_acl_entries_dacl()
and set_ntacl_dacl() break out of the ACE-building loops on overflow,
but the truncated *size is then consumed downstream at the end of
set_ntacl_dacl():
pndacl->size = cpu_to_le16(le16_to_cpu(pndacl->size) + size);
This produces an on-wire NT ACL whose pndacl->size under-reports the
bytes actually written by the preceding fill_ace_for_sid()/memcpy()
calls, yielding a malformed ACL that can trigger out-of-bounds reads
when re-parsed by clients or ksmbd itself.
Restore *size to its pre-addition value on each overflow branch (via
`*size -= ace_sz` / `size -= nt_ace_size`) so that after the break,
*size once again holds the cumulative size of the successfully-written
ACEs. The committed ACL is then truncated-but-self-consistent rather
than malformed.
The ksmbd DACL builders are the only check_add_overflow() sites found
where an overflow path breaks out of a loop and the destination value
is consumed afterward. The other nearby break-style cases either
return -EINVAL on overflow (transport_ipc.c) or break without
consuming the overflowed destination value afterward (buildid.c).
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 41e53a773db6342ac9a689ee5ba635c31744c9f0 Version: 8d5729350b236896f51379588d9a690b7fafb8db Version: e1955a94b6f17f4b058afa955a6f187eb3ed7615 Version: 5e7b8f3c539d69b2ed5f2408e2f75e68ce7eef43 Version: 299f962c0b02d048fb45d248b4da493d03f3175d Version: 299f962c0b02d048fb45d248b4da493d03f3175d Version: ef7902be3f215b6bf7babe4dc9dd9a7d57dad7a7 Version: 6.1.175 ≤ Version: 6.6.136 ≤ Version: 6.12.84 ≤ Version: 6.18.25 ≤ Version: 7.0.2 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/smb/server/smbacl.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "8f3a7a499a7d9bb1c0f33fe78c4a4594d7e307f4",
"status": "affected",
"version": "41e53a773db6342ac9a689ee5ba635c31744c9f0",
"versionType": "git"
},
{
"lessThan": "f4fcd0c1a243d449307b887fafee23921e9db5ab",
"status": "affected",
"version": "8d5729350b236896f51379588d9a690b7fafb8db",
"versionType": "git"
},
{
"lessThan": "0bf38372821b1526f31538a7d9811844c55c7f38",
"status": "affected",
"version": "e1955a94b6f17f4b058afa955a6f187eb3ed7615",
"versionType": "git"
},
{
"lessThan": "847ecd4eb3c117c3d2f13f1e7ab506543aad8183",
"status": "affected",
"version": "5e7b8f3c539d69b2ed5f2408e2f75e68ce7eef43",
"versionType": "git"
},
{
"lessThan": "bc90144ce8bb7fcf05ad9417c7adb4e9509d9e13",
"status": "affected",
"version": "299f962c0b02d048fb45d248b4da493d03f3175d",
"versionType": "git"
},
{
"lessThan": "bbf0a8e931204ecdab494a88d43b0a24a04285c5",
"status": "affected",
"version": "299f962c0b02d048fb45d248b4da493d03f3175d",
"versionType": "git"
},
{
"status": "affected",
"version": "ef7902be3f215b6bf7babe4dc9dd9a7d57dad7a7",
"versionType": "git"
},
{
"lessThan": "6.1.184",
"status": "affected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThan": "6.6.148",
"status": "affected",
"version": "6.6.136",
"versionType": "semver"
},
{
"lessThan": "6.12.101",
"status": "affected",
"version": "6.12.84",
"versionType": "semver"
},
{
"lessThan": "6.18.42",
"status": "affected",
"version": "6.18.25",
"versionType": "semver"
},
{
"lessThan": "7.1",
"status": "affected",
"version": "7.0.2",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/smb/server/smbacl.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "7.1"
},
{
"lessThan": "7.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "6.1.175",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.6.136",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.12.84",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.18.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "7.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "7.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "7.0.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: restore DACL size on check_add_overflow() to avoid malformed ACL\n\ncheck_add_overflow() unconditionally writes the truncated sum into *d\neven on overflow, per its contract in include/linux/overflow.h.\nThe four check_add_overflow() guards in set_posix_acl_entries_dacl()\nand set_ntacl_dacl() break out of the ACE-building loops on overflow,\nbut the truncated *size is then consumed downstream at the end of\nset_ntacl_dacl():\n\n pndacl-\u003esize = cpu_to_le16(le16_to_cpu(pndacl-\u003esize) + size);\n\nThis produces an on-wire NT ACL whose pndacl-\u003esize under-reports the\nbytes actually written by the preceding fill_ace_for_sid()/memcpy()\ncalls, yielding a malformed ACL that can trigger out-of-bounds reads\nwhen re-parsed by clients or ksmbd itself.\n\nRestore *size to its pre-addition value on each overflow branch (via\n`*size -= ace_sz` / `size -= nt_ace_size`) so that after the break,\n*size once again holds the cumulative size of the successfully-written\nACEs. The committed ACL is then truncated-but-self-consistent rather\nthan malformed.\n\nThe ksmbd DACL builders are the only check_add_overflow() sites found\nwhere an overflow path breaks out of a loop and the destination value\nis consumed afterward. The other nearby break-style cases either\nreturn -EINVAL on overflow (transport_ipc.c) or break without\nconsuming the overflowed destination value afterward (buildid.c)."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:45:49.075Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/8f3a7a499a7d9bb1c0f33fe78c4a4594d7e307f4"
},
{
"url": "https://git.kernel.org/stable/c/f4fcd0c1a243d449307b887fafee23921e9db5ab"
},
{
"url": "https://git.kernel.org/stable/c/0bf38372821b1526f31538a7d9811844c55c7f38"
},
{
"url": "https://git.kernel.org/stable/c/847ecd4eb3c117c3d2f13f1e7ab506543aad8183"
},
{
"url": "https://git.kernel.org/stable/c/bc90144ce8bb7fcf05ad9417c7adb4e9509d9e13"
},
{
"url": "https://git.kernel.org/stable/c/bbf0a8e931204ecdab494a88d43b0a24a04285c5"
}
],
"title": "ksmbd: restore DACL size on check_add_overflow() to avoid malformed ACL",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68099",
"datePublished": "2026-08-10T11:58:13.940Z",
"dateReserved": "2026-07-30T09:28:09.368Z",
"dateUpdated": "2026-08-23T12:45:49.075Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68434 (GCVE-0-2026-68434)
Vulnerability from cvelistv5
Published
2026-08-12 00:07
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
serial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms
Commit b1b4efea05a5 ("serial: 8250_mid: Disable DMA for selected
platforms") replaced the dnv_board setup and exit callbacks with
PTR_IF(false, ...), which evaluates to NULL. However, the three call
sites in mid8250_probe() and mid8250_remove() unconditionally
dereference these function pointers without NULL checks, causing a NULL
pointer dereference (kernel oops) on any Denverton (DNV), Ice Lake Xeon
D (ICX-D/CDF), or Snowridge (SNR) platform.
Fix this by adding the missing NULL checks before calling the setup and
exit callbacks.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 763d61ded752fbb3116efc951eff4363f237b7e0 Version: c7d190bb07bf4e3b217c69370e94d1b4c80a40ad Version: 0b3ed3fa227ba778cabed96e7f8d84addb8bdf9c Version: 587afb06a5d1dc5092d3d9e9ac3ccf22094d50c6 Version: 977855894bca4b87afa50d21e3f3e85a5a0e901f Version: 1cd54e217c6e2cdb794a897b2f855e13ffcee586 Version: 9690e8a342632344984af72bc56b7a1fba61e6cb Version: b1b4efea05a56c0995e4702a86d6624b4fdff32f |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/tty/serial/8250/8250_mid.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "bdaa8871b53fe9b1730ef64dda2fcd662fd83339",
"status": "affected",
"version": "763d61ded752fbb3116efc951eff4363f237b7e0",
"versionType": "git"
},
{
"lessThan": "f85a42fb90399dedcf81c146d09c07e4548b1e8c",
"status": "affected",
"version": "c7d190bb07bf4e3b217c69370e94d1b4c80a40ad",
"versionType": "git"
},
{
"lessThan": "4ea933a36a14bec19b71025cdd8407bafbd67ec1",
"status": "affected",
"version": "0b3ed3fa227ba778cabed96e7f8d84addb8bdf9c",
"versionType": "git"
},
{
"lessThan": "1096397c31f6bffa95e77bdd18fbca085be83e10",
"status": "affected",
"version": "587afb06a5d1dc5092d3d9e9ac3ccf22094d50c6",
"versionType": "git"
},
{
"lessThan": "600dcd548fb2b00a69f447684f52ba45d5a3540e",
"status": "affected",
"version": "977855894bca4b87afa50d21e3f3e85a5a0e901f",
"versionType": "git"
},
{
"lessThan": "b2a3eeb57ba24f8a0e34a69d40adcc63e5b9ca56",
"status": "affected",
"version": "1cd54e217c6e2cdb794a897b2f855e13ffcee586",
"versionType": "git"
},
{
"lessThan": "8cbad52ccfa6a7f089cfab34979bc6cc3bff25be",
"status": "affected",
"version": "9690e8a342632344984af72bc56b7a1fba61e6cb",
"versionType": "git"
},
{
"lessThan": "7fb13fd7e9a59a37cd911efff83abe19e3ee029d",
"status": "affected",
"version": "b1b4efea05a56c0995e4702a86d6624b4fdff32f",
"versionType": "git"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/tty/serial/8250/8250_mid.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "5.10.266",
"status": "affected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThan": "5.15.217",
"status": "affected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThan": "6.1.183",
"status": "affected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThan": "6.6.148",
"status": "affected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThan": "6.12.101",
"status": "affected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThan": "6.18.42",
"status": "affected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThan": "7.1.6",
"status": "affected",
"version": "7.1.4",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "5.10.261",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.15.212",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "6.1.178",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.6.145",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.12.96",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.18.39",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "7.1.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nserial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms\n\nCommit b1b4efea05a5 (\"serial: 8250_mid: Disable DMA for selected\nplatforms\") replaced the dnv_board setup and exit callbacks with\nPTR_IF(false, ...), which evaluates to NULL. However, the three call\nsites in mid8250_probe() and mid8250_remove() unconditionally\ndereference these function pointers without NULL checks, causing a NULL\npointer dereference (kernel oops) on any Denverton (DNV), Ice Lake Xeon\nD (ICX-D/CDF), or Snowridge (SNR) platform.\n\nFix this by adding the missing NULL checks before calling the setup and\nexit callbacks."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:23.299Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/bdaa8871b53fe9b1730ef64dda2fcd662fd83339"
},
{
"url": "https://git.kernel.org/stable/c/f85a42fb90399dedcf81c146d09c07e4548b1e8c"
},
{
"url": "https://git.kernel.org/stable/c/4ea933a36a14bec19b71025cdd8407bafbd67ec1"
},
{
"url": "https://git.kernel.org/stable/c/1096397c31f6bffa95e77bdd18fbca085be83e10"
},
{
"url": "https://git.kernel.org/stable/c/600dcd548fb2b00a69f447684f52ba45d5a3540e"
},
{
"url": "https://git.kernel.org/stable/c/b2a3eeb57ba24f8a0e34a69d40adcc63e5b9ca56"
},
{
"url": "https://git.kernel.org/stable/c/8cbad52ccfa6a7f089cfab34979bc6cc3bff25be"
},
{
"url": "https://git.kernel.org/stable/c/7fb13fd7e9a59a37cd911efff83abe19e3ee029d"
}
],
"title": "serial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68434",
"datePublished": "2026-08-12T00:07:21.897Z",
"dateReserved": "2026-07-30T09:28:09.393Z",
"dateUpdated": "2026-08-23T12:46:23.299Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68098 (GCVE-0-2026-68098)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-17 04:58
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: bound DACL dedup walk to copied ACEs
set_ntacl_dacl() can stop copying ACEs before consuming the full input
DACL when size accounting overflows.
When that happens, num_aces reflects only the ACEs that were actually
copied into the output DACL, but set_posix_acl_entries_dacl() still
receives nt_num_aces and uses it to walk the existing ACE array during
dedup.
That makes the dedup walk scan past the copied ACE array and inspect
buffer tail that does not contain valid ACEs.
Split the two meanings currently carried by the NT ACE count. Pass the
number of copied NT ACEs to bound the dedup walk, and preserve the
original "input DACL had NT ACEs" state separately for the
Everyone/default ACL fallback.
This keeps the dedup walk aligned with the ACEs that are actually
present in the rebuilt DACL.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/smb/server/smbacl.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "6d9d7aa4a2c99c31acfa28921c30b684110cf66c",
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"versionType": "git"
},
{
"lessThan": "b057a851129c6a084e7e393b62ca3abf6c2660bc",
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"versionType": "git"
},
{
"lessThan": "f1eba60db813ec28732bf18b5f0a67ebac9c3100",
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"versionType": "git"
},
{
"lessThan": "a0ebdaa79e10210d4e8ed9fe138e8f4d569719e3",
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"versionType": "git"
},
{
"lessThan": "58d97fcd0bf1aee694e244cc28635b9df95b543b",
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/smb/server/smbacl.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.15"
},
{
"lessThan": "5.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: bound DACL dedup walk to copied ACEs\n\nset_ntacl_dacl() can stop copying ACEs before consuming the full input\nDACL when size accounting overflows.\n\nWhen that happens, num_aces reflects only the ACEs that were actually\ncopied into the output DACL, but set_posix_acl_entries_dacl() still\nreceives nt_num_aces and uses it to walk the existing ACE array during\ndedup.\n\nThat makes the dedup walk scan past the copied ACE array and inspect\nbuffer tail that does not contain valid ACEs.\n\nSplit the two meanings currently carried by the NT ACE count. Pass the\nnumber of copied NT ACEs to bound the dedup walk, and preserve the\noriginal \"input DACL had NT ACEs\" state separately for the\nEveryone/default ACL fallback.\n\nThis keeps the dedup walk aligned with the ACEs that are actually\npresent in the rebuilt DACL."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The flaw is in ksmbd\u0027s in-kernel SMB server (fs/smb/server/smbacl.c), triggered when a remote client sends SMB2 QUERY_INFO (security descriptor) over TCP/445; build_sec_desc() reads the attacker\u0027s stored NTACL xattr and calls set_ntacl_dacl().\nAC:L - An authenticated attacker fully controls the crafted DACL planted via SMB2 SET_INFO and can deterministically trigger partial ACE copy (size overflow) then QUERY_INFO; no race or victim-dependent state is required beyond a file with POSIX ACLs on an ACL-xattr-enabled share.\nPR:L - Exploitation requires a completed SMB2 session and tree connect; planting the malicious security.NTACL xattr needs FILE_WRITE_DAC via SMB2 SET_INFO, and triggering needs an open file handle for QUERY_INFO\u2014standard low-privileged share access, not host root.\nUI:N - The server processes the attacker\u0027s SMB2 SET_INFO and QUERY_INFO requests automatically in ksmbd worker threads; no separate local user or administrator action is required beyond normal server operation.\nS:U - Impact is confined to kernel heap memory corruption and ACL processing within the ksmbd server context; it does not cross VM, container, or IOMMU security boundaries.\nC:H - The dedup walk scans past copied ACEs into buffer tail without valid ACE structures, performing out-of-bounds reads including ntace-\u003esid.sub_auth[ntace-\u003esid.num_subauth-1] on attacker-influenced data; per kernel guidance OOB reads score High.\nI:H - Out-of-bounds kernel heap access during the unbounded ACE walk is a memory corruption primitive; incorrect dedup can also append extra ACEs to the rebuilt security descriptor, enabling integrity impact beyond a simple crash.\nA:H - Walking invalid ACE headers (e.g., zero size fields) can hang the dedup loop, and out-of-bounds reads of invalid sid fields can kernel oops/panic, denying SMB service on the affected host."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:58:46.978Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/6d9d7aa4a2c99c31acfa28921c30b684110cf66c"
},
{
"url": "https://git.kernel.org/stable/c/b057a851129c6a084e7e393b62ca3abf6c2660bc"
},
{
"url": "https://git.kernel.org/stable/c/f1eba60db813ec28732bf18b5f0a67ebac9c3100"
},
{
"url": "https://git.kernel.org/stable/c/a0ebdaa79e10210d4e8ed9fe138e8f4d569719e3"
},
{
"url": "https://git.kernel.org/stable/c/58d97fcd0bf1aee694e244cc28635b9df95b543b"
}
],
"title": "ksmbd: bound DACL dedup walk to copied ACEs",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68098",
"datePublished": "2026-08-10T11:58:12.768Z",
"dateReserved": "2026-07-30T09:28:09.368Z",
"dateUpdated": "2026-08-17T04:58:46.978Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64205 (GCVE-0-2026-64205)
Vulnerability from cvelistv5
Published
2026-07-20 16:27
Modified
2026-08-17 04:51
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
i2c: i801: fix hardware state machine corruption in error path
A severe livelock and subsequent Hung Task panic were observed in the
i2c-i801 driver during concurrent Fuzzing. The crash is caused by an
unconditional hardware register cleanup in the error handling path of
i801_access().
When i801_check_pre() fails (e.g., returning -EBUSY because the SMBus
controller is actively used by BIOS/ACPI), the kernel does not actually
acquire the hardware ownership. However, the code jumps to the 'out'
label and executes:
iowrite8(SMBHSTSTS_INUSE_STS | STATUS_FLAGS, SMBHSTSTS(priv));
This forcefully clears the INUSE_STS lock and resets the hardware status
flags without owning the controller. Doing so interrupts ongoing BIOS/ACPI
transactions and totally corrupts the SMBus hardware state machine.
Consequently, all subsequent i801_access() calls fail at the pre-check
stage, triggering an endless stream of "SMBus is busy, can't use it!"
error logs. Over a slow serial console, this printk flood monopolizes
the CPU (Console Livelock), starving other processes trying to acquire
the mmap_lock down_read semaphore, ultimately triggering the hung task
watchdog.
Fix this by moving the 'out' label below the hardware register cleanup.
If i801_check_pre() fails, we safely bypass the iowrite8() and only
release the software locks (pm_runtime and mutex), strictly adhering to
the rule of not releasing resources that were never acquired.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/i2c/busses/i2c-i801.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "2ef69871b313aa0f02182795f5e0f5aa455f203c",
"status": "affected",
"version": "1f760b87e54cf56a25ab68f8dc625e339f6e46d5",
"versionType": "git"
},
{
"lessThan": "ef5a347532932f58748dad485c15039f5168c377",
"status": "affected",
"version": "1f760b87e54cf56a25ab68f8dc625e339f6e46d5",
"versionType": "git"
},
{
"lessThan": "bb5133a7d5f3fe5c387770e25f2e00e682ce11ed",
"status": "affected",
"version": "1f760b87e54cf56a25ab68f8dc625e339f6e46d5",
"versionType": "git"
},
{
"lessThan": "00904687b9c5527d569d9a1ca72119823e735a61",
"status": "affected",
"version": "1f760b87e54cf56a25ab68f8dc625e339f6e46d5",
"versionType": "git"
},
{
"lessThan": "10dd1a736d557e310a77117832874729a0175d57",
"status": "affected",
"version": "1f760b87e54cf56a25ab68f8dc625e339f6e46d5",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/i2c/busses/i2c-i801.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.3"
},
{
"lessThan": "6.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "6.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "6.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: i801: fix hardware state machine corruption in error path\n\nA severe livelock and subsequent Hung Task panic were observed in the\ni2c-i801 driver during concurrent Fuzzing. The crash is caused by an\nunconditional hardware register cleanup in the error handling path of\ni801_access().\n\nWhen i801_check_pre() fails (e.g., returning -EBUSY because the SMBus\ncontroller is actively used by BIOS/ACPI), the kernel does not actually\nacquire the hardware ownership. However, the code jumps to the \u0027out\u0027\nlabel and executes:\n\n iowrite8(SMBHSTSTS_INUSE_STS | STATUS_FLAGS, SMBHSTSTS(priv));\n\nThis forcefully clears the INUSE_STS lock and resets the hardware status\nflags without owning the controller. Doing so interrupts ongoing BIOS/ACPI\ntransactions and totally corrupts the SMBus hardware state machine.\n\nConsequently, all subsequent i801_access() calls fail at the pre-check\nstage, triggering an endless stream of \"SMBus is busy, can\u0027t use it!\"\nerror logs. Over a slow serial console, this printk flood monopolizes\nthe CPU (Console Livelock), starving other processes trying to acquire\nthe mmap_lock down_read semaphore, ultimately triggering the hung task\nwatchdog.\n\nFix this by moving the \u0027out\u0027 label below the hardware register cleanup.\nIf i801_check_pre() fails, we safely bypass the iowrite8() and only\nrelease the software locks (pm_runtime and mutex), strictly adhering to\nthe rule of not releasing resources that were never acquired."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:51:51.900Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/2ef69871b313aa0f02182795f5e0f5aa455f203c"
},
{
"url": "https://git.kernel.org/stable/c/ef5a347532932f58748dad485c15039f5168c377"
},
{
"url": "https://git.kernel.org/stable/c/bb5133a7d5f3fe5c387770e25f2e00e682ce11ed"
},
{
"url": "https://git.kernel.org/stable/c/00904687b9c5527d569d9a1ca72119823e735a61"
},
{
"url": "https://git.kernel.org/stable/c/10dd1a736d557e310a77117832874729a0175d57"
}
],
"title": "i2c: i801: fix hardware state machine corruption in error path",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64205",
"datePublished": "2026-07-20T16:27:53.310Z",
"dateReserved": "2026-07-19T15:36:31.769Z",
"dateUpdated": "2026-08-17T04:51:51.900Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68199 (GCVE-0-2026-68199)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: ath6kl: fix OOB access from firmware ADDBA window size
aggr_recv_addba_req_evt() logs a debug message when the firmware-supplied
win_sz is outside [AGGR_WIN_SZ_MIN, AGGR_WIN_SZ_MAX] but does not
return. The out-of-range win_sz is then used in TID_WINDOW_SZ() to
compute a kzalloc size and stored in rxtid->hold_q_sz, leading to
zero-size or overflowed allocations and subsequent out-of-bounds access.
Clean up any previously active aggregation session for the TID first,
then return early when win_sz is out of the valid range, instead of
proceeding with a broken allocation size.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/ath/ath6kl/txrx.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c8e3ca7954d8233fbc54bd370c1827670f43c538",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "f480d9910fcfe326db3a6281df80e83af347193e",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "67bc9af4f41f2bdba20404fbd753b2a1bd6dd352",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "d4558c140782180e2c80a7588a4af9f8675adfc4",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "5a65fd4722416061698b0a3277222381efbc4882",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "58c6c8dc2e022e1b4f3dc58725a1ca49ff470f9c",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "cec0a487cf38ac1f9bca240ffe8a94c5014b72f2",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "44126b6994eeb28f2103b638e698f40a1244f327",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/ath/ath6kl/txrx.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.2"
},
{
"lessThan": "3.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath6kl: fix OOB access from firmware ADDBA window size\n\naggr_recv_addba_req_evt() logs a debug message when the firmware-supplied\nwin_sz is outside [AGGR_WIN_SZ_MIN, AGGR_WIN_SZ_MAX] but does not\nreturn. The out-of-range win_sz is then used in TID_WINDOW_SZ() to\ncompute a kzalloc size and stored in rxtid-\u003ehold_q_sz, leading to\nzero-size or overflowed allocations and subsequent out-of-bounds access.\n\nClean up any previously active aggregation session for the TID first,\nthen return early when win_sz is out of the valid range, instead of\nproceeding with a broken allocation size."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - Exploitation requires a malicious WiFi peer (rogue AP or associated client) to trigger ADDBA handling; firmware passes WMI_ADDBA_REQ_EVENTID over the radio link to the ath6kl driver, placing the attacker on the same wireless segment rather than a remote IP network path.\nAC:L - An adjacent attacker can reliably send crafted 802.11 ADDBA requests with out-of-range buffer/window sizes to firmware, which forwards the invalid win_sz to the host; no special memory layout, race, or rare timing is required beyond normal WiFi association.\nPR:N - No local Linux privileges are needed; any associated WiFi peer can induce the malformed ADDBA event. The bug is not reachable via user namespaces or unprivileged local syscalls without controlling the WiFi link/firmware messages.\nUI:N - Once the victim device is associated to WiFi (common on phones, embedded, and IoT), the attacker can send ADDBA and follow-up data frames without any additional victim action beyond routine wireless connectivity.\nS:U - Heap corruption and kernel privilege escalation occur within the same kernel security domain; this is not a VM escape, IOMMU bypass, or cross-authority sandbox breakout.\nC:H - Out-of-bounds access to hold_q allows reading/writing adjacent kernel heap memory (e.g., skb pointers and metadata); OOB kernel heap access is treated as arbitrary memory disclosure potential per kernel CVSS guidance.\nI:H - OOB writes to hold_q entries (struct sk_buff pointers, is_amsdu, seq_no) corrupt kernel heap state and can be leveraged for control-flow hijacking and local privilege escalation, not merely a bounded modification.\nA:H - Invalid win_sz can yield zero-size allocations and hold_q_sz=0 (divide-by-zero in AGGR_WIN_IDX) or inconsistent buffers, causing kernel oops/panic or persistent disruption when aggregation receives subsequent frames."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:18.842Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c8e3ca7954d8233fbc54bd370c1827670f43c538"
},
{
"url": "https://git.kernel.org/stable/c/f480d9910fcfe326db3a6281df80e83af347193e"
},
{
"url": "https://git.kernel.org/stable/c/67bc9af4f41f2bdba20404fbd753b2a1bd6dd352"
},
{
"url": "https://git.kernel.org/stable/c/d4558c140782180e2c80a7588a4af9f8675adfc4"
},
{
"url": "https://git.kernel.org/stable/c/5a65fd4722416061698b0a3277222381efbc4882"
},
{
"url": "https://git.kernel.org/stable/c/58c6c8dc2e022e1b4f3dc58725a1ca49ff470f9c"
},
{
"url": "https://git.kernel.org/stable/c/cec0a487cf38ac1f9bca240ffe8a94c5014b72f2"
},
{
"url": "https://git.kernel.org/stable/c/44126b6994eeb28f2103b638e698f40a1244f327"
}
],
"title": "wifi: ath6kl: fix OOB access from firmware ADDBA window size",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68199",
"datePublished": "2026-08-10T12:00:18.278Z",
"dateReserved": "2026-07-30T09:28:09.374Z",
"dateUpdated": "2026-08-19T16:31:18.842Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68394 (GCVE-0-2026-68394)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-17 05:04
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: MGMT: revalidate LOAD_CONN_PARAM queued update
MGMT_OP_LOAD_CONN_PARAM queues conn_update_sync() when a single parameter
update changes an existing LE central connection. The queued work currently
stores a borrowed hci_conn_params entry from hdev->le_conn_params. A later
LOAD_CONN_PARAM request can clear disabled parameters and free that entry
before hci_cmd_sync_work() runs the queued callback.
Do not keep the borrowed hci_conn_params pointer in queued work. Queue the
hci_conn instead and hold a reference until the queued callback completes.
When the work runs, revalidate that the connection is still present, look
up the current hci_conn_params entry, and cancel the update if userspace
removed that entry while the work was pending.
Copy the interval values from the current params entry under hdev->lock,
then drop the lock and keep using hci_le_conn_update_sync() to issue the
update.
Validation reproduced this kernel report:
BUG: KASAN: slab-use-after-free in conn_update_sync+0x2a/0xf0 [bluetooth]
Read of size 1 at addr ffff88810c697126 by task kworker/u17:0/377
Workqueue: hci0 hci_cmd_sync_work [bluetooth]
Call Trace:
<TASK>
dump_stack_lvl+0x66/0xa0
print_report+0xce/0x5f0
kasan_report+0xe0/0x110
conn_update_sync+0x2a/0xf0 [bluetooth]
hci_cmd_sync_work+0x187/0x210 [bluetooth]
process_one_work+0x4fd/0xbc0
worker_thread+0x2d8/0x570
kthread+0x1ad/0x1f0
ret_from_fork+0x3c9/0x540
ret_from_fork_asm+0x1a/0x30
Allocated by task 466:
hci_conn_params_add+0xa6/0x240 [bluetooth]
load_conn_param+0x4e1/0x850 [bluetooth]
hci_sock_sendmsg+0x96b/0xf80 [bluetooth]
Freed by task 474:
kfree+0x313/0x590
hci_conn_params_clear_disabled+0x9b/0xc0 [bluetooth]
load_conn_param+0x4bf/0x850 [bluetooth]
hci_sock_sendmsg+0x96b/0xf80 [bluetooth]
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/bluetooth/mgmt.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "65ce6fe1b92112ba9064ded932c03180da3dd230",
"status": "affected",
"version": "0ece498c27d8cd2fdad6f49a6abc34b8badd8fbc",
"versionType": "git"
},
{
"lessThan": "57059ff14d81df4a970b2ea8d8f54431bb91a025",
"status": "affected",
"version": "0ece498c27d8cd2fdad6f49a6abc34b8badd8fbc",
"versionType": "git"
},
{
"lessThan": "b82802b5ab26a7c69fc2e7a0f2baa3c13a6c21aa",
"status": "affected",
"version": "0ece498c27d8cd2fdad6f49a6abc34b8badd8fbc",
"versionType": "git"
},
{
"lessThan": "2bf282f8f715f5d05d6f4c49ffb3bd241c5e667e",
"status": "affected",
"version": "0ece498c27d8cd2fdad6f49a6abc34b8badd8fbc",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/bluetooth/mgmt.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.11"
},
{
"lessThan": "6.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: MGMT: revalidate LOAD_CONN_PARAM queued update\n\nMGMT_OP_LOAD_CONN_PARAM queues conn_update_sync() when a single parameter\nupdate changes an existing LE central connection. The queued work currently\nstores a borrowed hci_conn_params entry from hdev-\u003ele_conn_params. A later\nLOAD_CONN_PARAM request can clear disabled parameters and free that entry\nbefore hci_cmd_sync_work() runs the queued callback.\n\nDo not keep the borrowed hci_conn_params pointer in queued work. Queue the\nhci_conn instead and hold a reference until the queued callback completes.\nWhen the work runs, revalidate that the connection is still present, look\nup the current hci_conn_params entry, and cancel the update if userspace\nremoved that entry while the work was pending.\n\nCopy the interval values from the current params entry under hdev-\u003elock,\nthen drop the lock and keep using hci_le_conn_update_sync() to issue the\nupdate.\n\nValidation reproduced this kernel report:\nBUG: KASAN: slab-use-after-free in conn_update_sync+0x2a/0xf0 [bluetooth]\nRead of size 1 at addr ffff88810c697126 by task kworker/u17:0/377\nWorkqueue: hci0 hci_cmd_sync_work [bluetooth]\n\nCall Trace:\n \u003cTASK\u003e\n dump_stack_lvl+0x66/0xa0\n print_report+0xce/0x5f0\n kasan_report+0xe0/0x110\n conn_update_sync+0x2a/0xf0 [bluetooth]\n hci_cmd_sync_work+0x187/0x210 [bluetooth]\n process_one_work+0x4fd/0xbc0\n worker_thread+0x2d8/0x570\n kthread+0x1ad/0x1f0\n ret_from_fork+0x3c9/0x540\n ret_from_fork_asm+0x1a/0x30\n\nAllocated by task 466:\n hci_conn_params_add+0xa6/0x240 [bluetooth]\n load_conn_param+0x4e1/0x850 [bluetooth]\n hci_sock_sendmsg+0x96b/0xf80 [bluetooth]\n\nFreed by task 474:\n kfree+0x313/0x590\n hci_conn_params_clear_disabled+0x9b/0xc0 [bluetooth]\n load_conn_param+0x4bf/0x850 [bluetooth]\n hci_sock_sendmsg+0x96b/0xf80 [bluetooth]"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerability is triggered entirely through local interfaces \u2014 two MGMT_OP_LOAD_CONN_PARAM commands written to a local AF_BLUETOOTH/BTPROTO_HCI socket bound to HCI_CHANNEL_CONTROL, reaching load_conn_param() via hci_sock_sendmsg()/hci_mgmt_cmd(). No over-the-air interaction from a remote Bluetooth peer is required.\nAC:L - The attacker controls both sides of the race: it issues the LOAD_CONN_PARAM that queues conn_update_sync() and then immediately issues a second LOAD_CONN_PARAM whose hci_conn_params_clear_disabled() frees the borrowed entry before hci_cmd_sync_work() dequeues it, and it can grool the slab by repeated hci_conn_params_add() calls.\nPR:L - Reaching load_conn_param() needs a trusted MGMT socket (CAP_NET_ADMIN at bind), which is exactly the privilege held by the unprivileged Bluetooth service account on Android and desktop Linux (bluetoothd / com.android.bluetooth) \u2014 a low-privilege, externally exposed daemon, not real root, and the standard scoring for MGMT-socket flaws.\nUI:N - Exploitation requires only that the attacker send its own MGMT commands over an existing LE central connection it can itself establish; no action by any other user or victim application is needed.\nS:U - The use-after-free corrupts kernel slab memory and its impact stays within the kernel\u0027s own security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - This is a slab use-after-free read: conn_update_sync() reads addr/addr_type and the four interval fields from a freed hci_conn_params and places them into the HCI_OP_LE_CONN_UPDATE command, leaking reallocated heap contents; more generally a UAF gives the attacker control over freed-object contents and can be leveraged into arbitrary kernel memory disclosure.\nI:H - The attacker grooms the freed hci_conn_params slot with controlled data, so freed memory dictates which connection is looked up and what parameters are programmed into the controller; a use-after-free of this kind is a standard primitive for heap manipulation and control-flow/data corruption in the kernel.\nA:H - The bug is a confirmed KASAN slab-use-after-free (BUG: KASAN: slab-use-after-free in conn_update_sync+0x2a/0xf0) in a workqueue context, which panics on KASAN/panic_on_warn kernels and readily causes oopses or unpredictable Bluetooth-stack state otherwise."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:04:42.328Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/65ce6fe1b92112ba9064ded932c03180da3dd230"
},
{
"url": "https://git.kernel.org/stable/c/57059ff14d81df4a970b2ea8d8f54431bb91a025"
},
{
"url": "https://git.kernel.org/stable/c/b82802b5ab26a7c69fc2e7a0f2baa3c13a6c21aa"
},
{
"url": "https://git.kernel.org/stable/c/2bf282f8f715f5d05d6f4c49ffb3bd241c5e667e"
}
],
"title": "Bluetooth: MGMT: revalidate LOAD_CONN_PARAM queued update",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68394",
"datePublished": "2026-08-10T12:04:13.562Z",
"dateReserved": "2026-07-30T09:28:09.389Z",
"dateUpdated": "2026-08-17T05:04:42.328Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68156 (GCVE-0-2026-68156)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
libceph: refresh auth->authorizer_buf{,_len} after authorizer update
ceph_x_create_authorizer() caches au->buf->vec.iov_base and
au->buf->vec.iov_len in struct ceph_auth_handshake. These
cached values are then used by the messenger connect code when
sending the authorizer.
ceph_x_update_authorizer() can rebuild the authorizer when a newer
service ticket is available. If the rebuilt authorizer no longer
fits in the existing buffer, ceph_x_build_authorizer() drops its
reference to au->buf and allocates a new one. If this is the final
reference, ceph_buffer_put() frees the old ceph_buffer and its
vec.iov_base, but auth->authorizer_buf still points at that freed
memory.
A subsequent msgr1 reconnect can therefore queue the stale pointer
and trigger a KASAN slab-use-after-free in _copy_from_iter() while
tcp_sendmsg() copies the authorizer.
Refresh auth->authorizer_buf and auth->authorizer_buf_len after a
successful authorizer rebuild so the messenger sends the current
buffer.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 0bed9b5c523d577378b6f83eab5835fe30c27208 Version: 0bed9b5c523d577378b6f83eab5835fe30c27208 Version: 0bed9b5c523d577378b6f83eab5835fe30c27208 Version: 0bed9b5c523d577378b6f83eab5835fe30c27208 Version: 0bed9b5c523d577378b6f83eab5835fe30c27208 Version: 0bed9b5c523d577378b6f83eab5835fe30c27208 Version: 0bed9b5c523d577378b6f83eab5835fe30c27208 Version: 0bed9b5c523d577378b6f83eab5835fe30c27208 Version: 29c65a277a64645af853e8c9a9b3dda0ddc421e0 Version: d2c7223497cf8228416c70e3f4238ddd6c5bdf3c Version: 3.4.50 ≤ Version: 3.9.7 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ceph/auth_x.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "2334e9997308305ee4fd508fdfe6086c4150ed60",
"status": "affected",
"version": "0bed9b5c523d577378b6f83eab5835fe30c27208",
"versionType": "git"
},
{
"lessThan": "79a273df64238a4ade8b709689a78589f755b8ef",
"status": "affected",
"version": "0bed9b5c523d577378b6f83eab5835fe30c27208",
"versionType": "git"
},
{
"lessThan": "26f814187abceee90dbb29a02133adb4786fbb13",
"status": "affected",
"version": "0bed9b5c523d577378b6f83eab5835fe30c27208",
"versionType": "git"
},
{
"lessThan": "9d37aec9ffe4e743dabc3f84502e9723e17a30d4",
"status": "affected",
"version": "0bed9b5c523d577378b6f83eab5835fe30c27208",
"versionType": "git"
},
{
"lessThan": "75e82e8944ac1efe9fdb88bd2f14d9a031282bdf",
"status": "affected",
"version": "0bed9b5c523d577378b6f83eab5835fe30c27208",
"versionType": "git"
},
{
"lessThan": "0060ec912292a550198d8d18ac95b433c92a7091",
"status": "affected",
"version": "0bed9b5c523d577378b6f83eab5835fe30c27208",
"versionType": "git"
},
{
"lessThan": "5ecfcd5c05866f185357700b81b461dae4f5ebb2",
"status": "affected",
"version": "0bed9b5c523d577378b6f83eab5835fe30c27208",
"versionType": "git"
},
{
"lessThan": "937d61f86d377a3aa578adae7a3dfcecdddf9d89",
"status": "affected",
"version": "0bed9b5c523d577378b6f83eab5835fe30c27208",
"versionType": "git"
},
{
"status": "affected",
"version": "29c65a277a64645af853e8c9a9b3dda0ddc421e0",
"versionType": "git"
},
{
"status": "affected",
"version": "d2c7223497cf8228416c70e3f4238ddd6c5bdf3c",
"versionType": "git"
},
{
"lessThan": "3.5",
"status": "affected",
"version": "3.4.50",
"versionType": "semver"
},
{
"lessThan": "3.10",
"status": "affected",
"version": "3.9.7",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ceph/auth_x.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.10"
},
{
"lessThan": "3.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.4.50",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.9.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: refresh auth-\u003eauthorizer_buf{,_len} after authorizer update\n\nceph_x_create_authorizer() caches au-\u003ebuf-\u003evec.iov_base and\nau-\u003ebuf-\u003evec.iov_len in struct ceph_auth_handshake. These\ncached values are then used by the messenger connect code when\nsending the authorizer.\n\nceph_x_update_authorizer() can rebuild the authorizer when a newer\nservice ticket is available. If the rebuilt authorizer no longer\nfits in the existing buffer, ceph_x_build_authorizer() drops its\nreference to au-\u003ebuf and allocates a new one. If this is the final\nreference, ceph_buffer_put() frees the old ceph_buffer and its\nvec.iov_base, but auth-\u003eauthorizer_buf still points at that freed\nmemory.\n\nA subsequent msgr1 reconnect can therefore queue the stale pointer\nand trigger a KASAN slab-use-after-free in _copy_from_iter() while\ntcp_sendmsg() copies the authorizer.\n\nRefresh auth-\u003eauthorizer_buf and auth-\u003eauthorizer_buf_len after a\nsuccessful authorizer rebuild so the messenger sends the current\nbuffer."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - A compromised or malicious Ceph monitor/OSD delivers rotated cephx service tickets over TCP that increase secret_id and can enlarge the authorizer; on subsequent msgr1 reconnect the stale authorizer_buf is copied in tcp_sendmsg, so the UAF is reachable from the network peer without local syscall access.\nAC:L - An attacker controlling the Ceph cluster can deterministically issue a larger rotated ticket to force ceph_buffer realloc in ceph_x_update_authorizer, then trigger an msgr1 OSD/MDS/MON reconnect; no victim-specific memory layout or uncontrollable race is required.\nPR:N - Exploitation requires no privileges on the victim host; any kernel Ceph/RBD/CephFS client already connected to an attacker-controlled or compromised cluster is sufficient, matching other libceph client CVEs where the remote peer drives the bug.\nUI:N - After initial Ceph client setup, service-ticket rotation and messenger reconnects occur automatically; no further interactive user action is needed to reach the stale-buffer send path.\nS:U - The slab UAF corrupts kernel heap memory on the Ceph client host for local privilege escalation or crash, but does not cross VM, IOMMU, or container sandbox boundaries to another security authority.\nC:H - KASAN-confirmed slab use-after-free in _copy_from_iter during authorizer transmission reads freed kmalloc memory, which can disclose adjacent kernel pointers and is classed as exploitable arbitrary read per kernel UAF guidance.\nI:H - Freed authorizer buffers can be reclaimed with attacker-controlled data before reconnect, enabling heap corruption and control-flow hijack during the stale-pointer copy, consistent with kernel UAF write primitive scoring.\nA:H - The reported KASAN slab-use-after-free in tcp_sendmsg while copying the authorizer reliably causes kernel oops or panic on Ceph client reconnect, and remains repeatable whenever tickets are rotated and msgr1 reconnects."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:30:25.089Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/2334e9997308305ee4fd508fdfe6086c4150ed60"
},
{
"url": "https://git.kernel.org/stable/c/79a273df64238a4ade8b709689a78589f755b8ef"
},
{
"url": "https://git.kernel.org/stable/c/26f814187abceee90dbb29a02133adb4786fbb13"
},
{
"url": "https://git.kernel.org/stable/c/9d37aec9ffe4e743dabc3f84502e9723e17a30d4"
},
{
"url": "https://git.kernel.org/stable/c/75e82e8944ac1efe9fdb88bd2f14d9a031282bdf"
},
{
"url": "https://git.kernel.org/stable/c/0060ec912292a550198d8d18ac95b433c92a7091"
},
{
"url": "https://git.kernel.org/stable/c/5ecfcd5c05866f185357700b81b461dae4f5ebb2"
},
{
"url": "https://git.kernel.org/stable/c/937d61f86d377a3aa578adae7a3dfcecdddf9d89"
}
],
"title": "libceph: refresh auth-\u003eauthorizer_buf{,_len} after authorizer update",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68156",
"datePublished": "2026-08-10T11:59:22.514Z",
"dateReserved": "2026-07-30T09:28:09.371Z",
"dateUpdated": "2026-08-19T16:30:25.089Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68261 (GCVE-0-2026-68261)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-17 05:01
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/imagination: fix error checking of pvr_vm_context_lookup()
Since pvr_vm_context_lookup() returns either NULL or a pointer, then stop
using IS_ERR() for checking the return value.
Using IS_ERR() leads to the kernel oops reported below. It can be
reproduced by passing an invalid VM context handle from userspace to the
DRM_IOCTL_PVR_CREATE_CONTEXT ioctl.
[ 92.733119] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000148
[ 92.742042] Mem abort info:
[ 92.744890] ESR = 0x0000000096000004
[ 92.748686] EC = 0x25: DABT (current EL), IL = 32 bits
[ 92.754020] SET = 0, FnV = 0
[ 92.757154] EA = 0, S1PTW = 0
[ 92.760337] FSC = 0x04: level 0 translation fault
[ 92.765243] Data abort info:
[ 92.768129] ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000
[ 92.773626] CM = 0, WnR = 0, TnD = 0, TagAccess = 0
[ 92.778763] GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0
[ 92.784098] user pgtable: 4k pages, 48-bit VAs, pgdp=000000088ed23000
[ 92.790550] [0000000000000148] pgd=0000000000000000, p4d=0000000000000000
[ 92.797381] Internal error: Oops: 0000000096000004 [#1] SMP
[ 92.803027] Modules linked in: powervr
[ 92.852533] CPU: 0 UID: 0 PID: 409 Comm: triangle Not tainted 7.1.0-rc5-g98b46e693b91 #1 PREEMPT
[ 92.861385] Hardware name: Texas Instruments AM68 SK (DT)
[ 92.866766] pstate: 60000005 (nZCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)
[ 92.873709] pc : pvr_vm_get_fw_mem_context+0x0/0xc [powervr]
[ 92.879376] lr : pvr_queue_create+0x26c/0x440 [powervr]
[ 92.884595] sp : ffff8000837fbb00
[ 92.887895] x29: ffff8000837fbb60 x28: 0000000000000000 x27: ffff8000837fbce8
[ 92.895015] x26: ffff000807f61a40 x25: ffff000807f61a00 x24: ffff000807f64400
[ 92.902135] x23: ffff00080a5ab000 x22: ffff800079b24730 x21: ffff000807f61800
[ 92.909254] x20: ffff00080999e680 x19: 0000000000000000 x18: 0000000000000000
[ 92.916373] x17: 0000000000000000 x16: 0000000000000000 x15: 0000000000000001
[ 92.923492] x14: 0000000000000000 x13: 0000000000000002 x12: ffff80008145b298
[ 92.930611] x11: ffff8000844e5000 x10: ffff80008165a130 x9 : 0000000000000100
[ 92.937730] x8 : 0000000000000001 x7 : ffff0008076b27e0 x6 : ffff00080ec43b7c
[ 92.944850] x5 : ffff00080ec43b78 x4 : 0000000000000000 x3 : ffff00080999e680
[ 92.951968] x2 : 0000000000000000 x1 : 0000000000000000 x0 : 0000000000000000
[ 92.959088] Call trace:
[ 92.961521] pvr_vm_get_fw_mem_context+0x0/0xc [powervr] (P)
[ 92.967173] pvr_context_create+0x190/0x410 [powervr]
[ 92.972218] pvr_ioctl_create_context+0x44/0x8c [powervr]
[ 92.977608] drm_ioctl_kernel+0xbc/0x124 [drm]
[ 92.982127] drm_ioctl+0x1f8/0x4dc [drm]
[ 92.986098] __arm64_sys_ioctl+0xac/0x104
[ 92.990102] invoke_syscall+0x54/0x10c
[ 92.993842] el0_svc_common.constprop.0+0x40/0xe0
[ 92.998532] do_el0_svc+0x1c/0x28
[ 93.001835] el0_svc+0x38/0x11c
[ 93.004969] el0t_64_sync_handler+0xa0/0xe4
[ 93.009139] el0t_64_sync+0x198/0x19c
[ 93.012792] Code: aa1703e0 d2800014 95cb0ba4 17ffffe8 (f940a400)
[ 93.018869] ---[ end trace 0000000000000000 ]---
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/imagination/pvr_context.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ce97192087c659f2e0c0c2a627330c7edcc9eeb3",
"status": "affected",
"version": "d2d79d29bb98a32c511f7339a8e93b47544fdeac",
"versionType": "git"
},
{
"lessThan": "c45fafa69fe3f79e319369cf665da89868e3ef98",
"status": "affected",
"version": "d2d79d29bb98a32c511f7339a8e93b47544fdeac",
"versionType": "git"
},
{
"lessThan": "401fbe3b6bbb6c94c24ee8843b7beed5111491ac",
"status": "affected",
"version": "d2d79d29bb98a32c511f7339a8e93b47544fdeac",
"versionType": "git"
},
{
"lessThan": "cf385cf6e713eba0720651174dac0b2d2f5bb8f8",
"status": "affected",
"version": "d2d79d29bb98a32c511f7339a8e93b47544fdeac",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/imagination/pvr_context.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.8"
},
{
"lessThan": "6.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/imagination: fix error checking of pvr_vm_context_lookup()\n\nSince pvr_vm_context_lookup() returns either NULL or a pointer, then stop\nusing IS_ERR() for checking the return value.\n\nUsing IS_ERR() leads to the kernel oops reported below. It can be\nreproduced by passing an invalid VM context handle from userspace to the\nDRM_IOCTL_PVR_CREATE_CONTEXT ioctl.\n\n[ 92.733119] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000148\n[ 92.742042] Mem abort info:\n[ 92.744890] ESR = 0x0000000096000004\n[ 92.748686] EC = 0x25: DABT (current EL), IL = 32 bits\n[ 92.754020] SET = 0, FnV = 0\n[ 92.757154] EA = 0, S1PTW = 0\n[ 92.760337] FSC = 0x04: level 0 translation fault\n[ 92.765243] Data abort info:\n[ 92.768129] ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000\n[ 92.773626] CM = 0, WnR = 0, TnD = 0, TagAccess = 0\n[ 92.778763] GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0\n[ 92.784098] user pgtable: 4k pages, 48-bit VAs, pgdp=000000088ed23000\n[ 92.790550] [0000000000000148] pgd=0000000000000000, p4d=0000000000000000\n[ 92.797381] Internal error: Oops: 0000000096000004 [#1] SMP\n[ 92.803027] Modules linked in: powervr\n[ 92.852533] CPU: 0 UID: 0 PID: 409 Comm: triangle Not tainted 7.1.0-rc5-g98b46e693b91 #1 PREEMPT\n[ 92.861385] Hardware name: Texas Instruments AM68 SK (DT)\n[ 92.866766] pstate: 60000005 (nZCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n[ 92.873709] pc : pvr_vm_get_fw_mem_context+0x0/0xc [powervr]\n[ 92.879376] lr : pvr_queue_create+0x26c/0x440 [powervr]\n[ 92.884595] sp : ffff8000837fbb00\n[ 92.887895] x29: ffff8000837fbb60 x28: 0000000000000000 x27: ffff8000837fbce8\n[ 92.895015] x26: ffff000807f61a40 x25: ffff000807f61a00 x24: ffff000807f64400\n[ 92.902135] x23: ffff00080a5ab000 x22: ffff800079b24730 x21: ffff000807f61800\n[ 92.909254] x20: ffff00080999e680 x19: 0000000000000000 x18: 0000000000000000\n[ 92.916373] x17: 0000000000000000 x16: 0000000000000000 x15: 0000000000000001\n[ 92.923492] x14: 0000000000000000 x13: 0000000000000002 x12: ffff80008145b298\n[ 92.930611] x11: ffff8000844e5000 x10: ffff80008165a130 x9 : 0000000000000100\n[ 92.937730] x8 : 0000000000000001 x7 : ffff0008076b27e0 x6 : ffff00080ec43b7c\n[ 92.944850] x5 : ffff00080ec43b78 x4 : 0000000000000000 x3 : ffff00080999e680\n[ 92.951968] x2 : 0000000000000000 x1 : 0000000000000000 x0 : 0000000000000000\n[ 92.959088] Call trace:\n[ 92.961521] pvr_vm_get_fw_mem_context+0x0/0xc [powervr] (P)\n[ 92.967173] pvr_context_create+0x190/0x410 [powervr]\n[ 92.972218] pvr_ioctl_create_context+0x44/0x8c [powervr]\n[ 92.977608] drm_ioctl_kernel+0xbc/0x124 [drm]\n[ 92.982127] drm_ioctl+0x1f8/0x4dc [drm]\n[ 92.986098] __arm64_sys_ioctl+0xac/0x104\n[ 92.990102] invoke_syscall+0x54/0x10c\n[ 92.993842] el0_svc_common.constprop.0+0x40/0xe0\n[ 92.998532] do_el0_svc+0x1c/0x28\n[ 93.001835] el0_svc+0x38/0x11c\n[ 93.004969] el0t_64_sync_handler+0xa0/0xe4\n[ 93.009139] el0t_64_sync+0x198/0x19c\n[ 93.012792] Code: aa1703e0 d2800014 95cb0ba4 17ffffe8 (f940a400)\n[ 93.018869] ---[ end trace 0000000000000000 ]---"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:01:53.453Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ce97192087c659f2e0c0c2a627330c7edcc9eeb3"
},
{
"url": "https://git.kernel.org/stable/c/c45fafa69fe3f79e319369cf665da89868e3ef98"
},
{
"url": "https://git.kernel.org/stable/c/401fbe3b6bbb6c94c24ee8843b7beed5111491ac"
},
{
"url": "https://git.kernel.org/stable/c/cf385cf6e713eba0720651174dac0b2d2f5bb8f8"
}
],
"title": "drm/imagination: fix error checking of pvr_vm_context_lookup()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68261",
"datePublished": "2026-08-10T12:01:35.600Z",
"dateReserved": "2026-07-30T09:28:09.378Z",
"dateUpdated": "2026-08-17T05:01:53.453Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68176 (GCVE-0-2026-68176)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
tracing: Fix mmiotrace possible NULL dereferencing of hiter->dev
If the mmio_pipe_open() fails to find a PCI device, the hiter->dev
will be assigned to NULL. The mmiotrace read() function dereferences the
hiter->dev if hiter exists.
Change the test of the read to not only check hiter being NULL, but also
the hiter->dev before dereferencing it.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: f984b51e0779a6dd30feedc41404013ca54e5d05 Version: f984b51e0779a6dd30feedc41404013ca54e5d05 Version: f984b51e0779a6dd30feedc41404013ca54e5d05 Version: f984b51e0779a6dd30feedc41404013ca54e5d05 Version: f984b51e0779a6dd30feedc41404013ca54e5d05 Version: f984b51e0779a6dd30feedc41404013ca54e5d05 Version: f984b51e0779a6dd30feedc41404013ca54e5d05 Version: f984b51e0779a6dd30feedc41404013ca54e5d05 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"kernel/trace/trace_mmiotrace.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c06470320f8156306986a831010cdc9f9f87cb50",
"status": "affected",
"version": "f984b51e0779a6dd30feedc41404013ca54e5d05",
"versionType": "git"
},
{
"lessThan": "0d5aaf91a3d05f7f993401af27872a5fc0f26edc",
"status": "affected",
"version": "f984b51e0779a6dd30feedc41404013ca54e5d05",
"versionType": "git"
},
{
"lessThan": "3635a9e8b453e658a49b39d025f35bbc6e58d0e2",
"status": "affected",
"version": "f984b51e0779a6dd30feedc41404013ca54e5d05",
"versionType": "git"
},
{
"lessThan": "faaf95135184208ee3ac6f33175c8d1800669dfc",
"status": "affected",
"version": "f984b51e0779a6dd30feedc41404013ca54e5d05",
"versionType": "git"
},
{
"lessThan": "201a01102c529772168181190cb084471082cf5c",
"status": "affected",
"version": "f984b51e0779a6dd30feedc41404013ca54e5d05",
"versionType": "git"
},
{
"lessThan": "8464427e1c177809a9488a97dfa2807d9dcf323b",
"status": "affected",
"version": "f984b51e0779a6dd30feedc41404013ca54e5d05",
"versionType": "git"
},
{
"lessThan": "724cd84b0546c07806840fa658714488553d13a2",
"status": "affected",
"version": "f984b51e0779a6dd30feedc41404013ca54e5d05",
"versionType": "git"
},
{
"lessThan": "144f29e85702234b23d2a62abf723e6a17eb5427",
"status": "affected",
"version": "f984b51e0779a6dd30feedc41404013ca54e5d05",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"kernel/trace/trace_mmiotrace.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.27"
},
{
"lessThan": "2.6.27",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.27",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.27",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.27",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.27",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.27",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.27",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.27",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.27",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Fix mmiotrace possible NULL dereferencing of hiter-\u003edev\n\nIf the mmio_pipe_open() fails to find a PCI device, the hiter-\u003edev\nwill be assigned to NULL. The mmiotrace read() function dereferences the\nhiter-\u003edev if hiter exists.\n\nChange the test of the read to not only check hiter being NULL, but also\nthe hiter-\u003edev before dereferencing it."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:30:41.982Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c06470320f8156306986a831010cdc9f9f87cb50"
},
{
"url": "https://git.kernel.org/stable/c/0d5aaf91a3d05f7f993401af27872a5fc0f26edc"
},
{
"url": "https://git.kernel.org/stable/c/3635a9e8b453e658a49b39d025f35bbc6e58d0e2"
},
{
"url": "https://git.kernel.org/stable/c/faaf95135184208ee3ac6f33175c8d1800669dfc"
},
{
"url": "https://git.kernel.org/stable/c/201a01102c529772168181190cb084471082cf5c"
},
{
"url": "https://git.kernel.org/stable/c/8464427e1c177809a9488a97dfa2807d9dcf323b"
},
{
"url": "https://git.kernel.org/stable/c/724cd84b0546c07806840fa658714488553d13a2"
},
{
"url": "https://git.kernel.org/stable/c/144f29e85702234b23d2a62abf723e6a17eb5427"
}
],
"title": "tracing: Fix mmiotrace possible NULL dereferencing of hiter-\u003edev",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68176",
"datePublished": "2026-08-10T11:59:47.298Z",
"dateReserved": "2026-07-30T09:28:09.372Z",
"dateUpdated": "2026-08-19T16:30:41.982Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72130 (GCVE-0-2026-72130)
Vulnerability from cvelistv5
Published
2026-08-15 05:53
Modified
2026-08-17 05:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
nvmet-auth: reject short AUTH_RECEIVE buffers
nvmet_execute_auth_receive() trusts the AUTH_RECEIVE allocation length
after checking only that it is nonzero and matches the transfer length.
In the SUCCESS1 and FAILURE1/default states, that lets a remote NVMe-oF
initiator reach the fixed-size DH-HMAC-CHAP response builders with a
kmalloc() buffer shorter than the response, so nvmet_auth_success1() and
nvmet_auth_failure1() write past the allocation; both only WARN_ON the
short length and then format the message anyway.
Impact: A remote NVMe-oF initiator with access to an auth-enabled target
can trigger a 16-byte heap out-of-bounds write via a one-byte
AUTH_RECEIVE allocation length.
Compute the minimum response length for the current DH-HMAC-CHAP step in
nvmet_auth_receive_data_len() and report a zero data length when the
host-supplied allocation length is shorter, so the existing zero-length
check in nvmet_execute_auth_receive() rejects the command before any
builder runs. The SUCCESS1 minimum is sizeof(struct
nvmf_auth_dhchap_success1_data) plus the HMAC hash length, because the
response hash is written into the rval[] flexible-array tail, so the
minimum is state dependent rather than a flat sizeof. CHALLENGE keeps its
existing variable-length guard in nvmet_auth_challenge().
This is reachable only when in-band DH-HMAC-CHAP authentication is
configured on the target.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/nvme/target/fabrics-cmd-auth.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "80bf7b7f676e3987bbe06af3c359bd56ac91a5a9",
"status": "affected",
"version": "db1312dd95488b5e6ff362ff66fcf953a46b1821",
"versionType": "git"
},
{
"lessThan": "2eaa3ad450141cfcf187bb43cb8335eb336b5f87",
"status": "affected",
"version": "db1312dd95488b5e6ff362ff66fcf953a46b1821",
"versionType": "git"
},
{
"lessThan": "bc111698b46e43eddd8664cceaa621cd559e99a0",
"status": "affected",
"version": "db1312dd95488b5e6ff362ff66fcf953a46b1821",
"versionType": "git"
},
{
"lessThan": "779575bc35c687697ba69e904f2cd22e60112534",
"status": "affected",
"version": "db1312dd95488b5e6ff362ff66fcf953a46b1821",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/nvme/target/fabrics-cmd-auth.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.0"
},
{
"lessThan": "6.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet-auth: reject short AUTH_RECEIVE buffers\n\nnvmet_execute_auth_receive() trusts the AUTH_RECEIVE allocation length\nafter checking only that it is nonzero and matches the transfer length.\nIn the SUCCESS1 and FAILURE1/default states, that lets a remote NVMe-oF\ninitiator reach the fixed-size DH-HMAC-CHAP response builders with a\nkmalloc() buffer shorter than the response, so nvmet_auth_success1() and\nnvmet_auth_failure1() write past the allocation; both only WARN_ON the\nshort length and then format the message anyway.\n\nImpact: A remote NVMe-oF initiator with access to an auth-enabled target\ncan trigger a 16-byte heap out-of-bounds write via a one-byte\nAUTH_RECEIVE allocation length.\n\nCompute the minimum response length for the current DH-HMAC-CHAP step in\nnvmet_auth_receive_data_len() and report a zero data length when the\nhost-supplied allocation length is shorter, so the existing zero-length\ncheck in nvmet_execute_auth_receive() rejects the command before any\nbuilder runs. The SUCCESS1 minimum is sizeof(struct\nnvmf_auth_dhchap_success1_data) plus the HMAC hash length, because the\nresponse hash is written into the rval[] flexible-array tail, so the\nminimum is state dependent rather than a flat sizeof. CHALLENGE keeps its\nexisting variable-length guard in nvmet_auth_challenge().\n\nThis is reachable only when in-band DH-HMAC-CHAP authentication is\nconfigured on the target."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug is in nvmet DH-HMAC-CHAP AUTH_RECEIVE handling reached by remote NVMe-oF initiators over network transports (nvmet-tcp/RDMA/FC); malicious allocation length arrives in a Fabrics command capsule from the network.\nAC:L - Once an auth-enabled target is reachable, the attacker fully controls AUTH_RECEIVE allocation length and can reliably reach vulnerable states (e.g. default NEGOTIATE branch or FAILURE1) without conditions beyond their control.\nPR:N - Exploitation occurs on the pre-authentication DH-HMAC-CHAP handshake before credentials are verified; no Linux privileges on the target are required, only network access to an auth-configured NVMe-oF target port.\nUI:N - No victim user action is required beyond the administrator having already deployed an NVMe-oF target; exploitation is driven entirely by attacker-sent Fabrics authentication commands.\nS:U - Impact is kernel heap memory corruption within the NVMe target subsystem on the same host; it does not cross a VM/hypervisor or IOMMU security boundary by itself.\nC:H - A controlled heap out-of-bounds write (up to 16 bytes plus optional HMAC tail in SUCCESS1) can corrupt adjacent kmalloc objects and be leveraged for kernel information disclosure, per memory-corruption guidance.\nI:H - The vulnerability is a heap out-of-bounds write in kernel context; such corruption is exploitable for arbitrary memory modification and potential code execution, not merely a bounded logic error.\nA:H - Heap corruption can cause kernel oops/panic, and the FAILURE1 AUTH_RECEIVE completion path calls nvmet_ctrl_fatal_error(), taking down the NVMe controller and denying service to connected initiators."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:40:42.219Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/80bf7b7f676e3987bbe06af3c359bd56ac91a5a9"
},
{
"url": "https://git.kernel.org/stable/c/2eaa3ad450141cfcf187bb43cb8335eb336b5f87"
},
{
"url": "https://git.kernel.org/stable/c/bc111698b46e43eddd8664cceaa621cd559e99a0"
},
{
"url": "https://git.kernel.org/stable/c/779575bc35c687697ba69e904f2cd22e60112534"
}
],
"title": "nvmet-auth: reject short AUTH_RECEIVE buffers",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72130",
"datePublished": "2026-08-15T05:53:06.604Z",
"dateReserved": "2026-08-09T03:40:39.907Z",
"dateUpdated": "2026-08-17T05:40:42.219Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68263 (GCVE-0-2026-68263)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-17 05:01
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/imagination: Fix double call to drm_sched_entity_fini()
Call sequence of double call:
pvr_context_destroy
pvr_context_kill_queues
pvr_queue_kill
drm_sched_entity_destroy
drm_sched_entity_fini // here
pvr_context_put
kref_put(..., pvr_context_release)
pvr_context_destroy_queues
pvr_queue_destroy
drm_sched_entity_fini // here
Call to drm_sched_entity_destroy() from pvr_context_kill_queues() calls
drm_sched_entity_flush() + drm_sched_entity_fini().
drm_sched_entity_flush() ensures all pending jobs are completed and
drm_sched_entity_fini() ensures no further submission is allowed as
per expectation from pvr_context_kill_queues(). Double call to
drm_sched_entity_fini() is misuse of the API so keep call only in
pvr_context_create() failure path.
Stack trace for issue with addition of refcounting for DRM entity
stats in commit fd177135f0e6 ("drm/sched: Account entity GPU time"):
[ 789.490527] ------------[ cut here ]------------
[ 789.490559] refcount_t: underflow; use-after-free.
[ 789.490657] WARNING: lib/refcount.c:28 at refcount_warn_saturate+0xf4/0x144, CPU#0: kworker/u16:1/440
[ 789.490695] Modules linked in: powervr drm_gpuvm drm_exec gpu_sched drm_shmem_helper xhci_plat_hcd xhci_hcd dwc3 usbcore usb_common snd_soc_simple_card snd_soc_simple_card_utils sa2ul sha512 sha256 dwc3_am62 sha1 authenc rti_wdt libsha512 at24 sch_fq_codel fuse dm_mod ipv6
[ 789.490798] CPU: 0 UID: 0 PID: 440 Comm: kworker/u16:1 Not tainted 7.0.0-rc7-02049-g5e2c0700091b #22 PREEMPT
[ 789.490809] Hardware name: Texas Instruments AM625 SK (DT)
[ 789.490815] Workqueue: powervr-sched pvr_queue_fence_release_work [powervr]
[ 789.490868] pstate: 60000005 (nZCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)
[ 789.490876] pc : refcount_warn_saturate+0xf4/0x144
[ 789.490884] lr : refcount_warn_saturate+0xf4/0x144
[ 789.490892] sp : ffff8000822cbcc0
[ 789.490895] x29: ffff8000822cbcc0 x28: 0000000000000000 x27: 0000000000000000
[ 789.490909] x26: 0000000000000000 x25: ffff800081b1e338 x24: ffff000004541405
[ 789.490922] x23: ffff000004bea950 x22: ffff00000042e400 x21: ffff000007123e30
[ 789.490935] x20: ffff000007123000 x19: ffff000007a80d50 x18: fffffffffffe7768
[ 789.490948] x17: 74736574202c6e6f x16: 697461746e656d65 x15: ffff800081b269f0
[ 789.490962] x14: 0000000000000030 x13: ffff800081b26a70 x12: 0000000000000211
[ 789.490975] x11: 00000000000000c0 x10: 0000000000000b50 x9 : ffff8000822cbb30
[ 789.490988] x8 : ffff0000014e7bb0 x7 : ffff00007725e780 x6 : 0000000372a05f49
[ 789.491001] x5 : 0000000000000000 x4 : 0000000000000001 x3 : 0000000000000010
[ 789.491013] x2 : 0000000000000000 x1 : 0000000000000000 x0 : ffff0000014e7000
[ 789.491027] Call trace:
[ 789.491032] refcount_warn_saturate+0xf4/0x144 (P)
[ 789.491043] drm_sched_entity_fini+0x164/0x18c [gpu_sched]
[ 789.491081] pvr_queue_destroy+0x64/0x134 [powervr]
[ 789.491110] pvr_context_destroy_queues+0x34/0x64 [powervr]
[ 789.491138] pvr_context_release+0x70/0xac [powervr]
[ 789.491166] pvr_context_put.part.0+0x5c/0x7c [powervr]
[ 789.491193] pvr_context_put+0x14/0x24 [powervr]
[ 789.491221] pvr_queue_fence_release_work+0x20/0x38 [powervr]
[ 789.491249] process_one_work+0x160/0x4c4
[ 789.491264] worker_thread+0x188/0x310
[ 789.491276] kthread+0x130/0x13c
[ 789.491287] ret_from_fork+0x10/0x20
[ 789.491300] ---[ end trace 0000000000000000 ]---
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/imagination/pvr_context.c",
"drivers/gpu/drm/imagination/pvr_queue.c",
"drivers/gpu/drm/imagination/pvr_queue.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "9be3f4bd6f514f69c51a8c77ea64fce2729dc7f4",
"status": "affected",
"version": "eaf01ee5ba28b97f96a3d3eec4c5fbfb37ee4cde",
"versionType": "git"
},
{
"lessThan": "c88fdbf3da26e0179629530cae7768cd3d4ead85",
"status": "affected",
"version": "eaf01ee5ba28b97f96a3d3eec4c5fbfb37ee4cde",
"versionType": "git"
},
{
"lessThan": "c1136d907fd04ca5c62ba11c1159b5fe65a1760c",
"status": "affected",
"version": "eaf01ee5ba28b97f96a3d3eec4c5fbfb37ee4cde",
"versionType": "git"
},
{
"lessThan": "4af24c27a39ba147a613a09e10b9e0f7294524c0",
"status": "affected",
"version": "eaf01ee5ba28b97f96a3d3eec4c5fbfb37ee4cde",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/imagination/pvr_context.c",
"drivers/gpu/drm/imagination/pvr_queue.c",
"drivers/gpu/drm/imagination/pvr_queue.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.8"
},
{
"lessThan": "6.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/imagination: Fix double call to drm_sched_entity_fini()\n\nCall sequence of double call:\npvr_context_destroy\n\u2003\u2003pvr_context_kill_queues\n\u2003\u2003\u2003\u2003pvr_queue_kill\n\u2003\u2003\u2003\u2003\u2003\u2003drm_sched_entity_destroy\n\u2003\u2003\u2003\u2003\u2003\u2003\u2003\u2003drm_sched_entity_fini // here\n\u2003\u2003pvr_context_put\n\u2003\u2003\u2003\u2003kref_put(..., pvr_context_release)\n\u2003\u2003\u2003\u2003\u2003\u2003pvr_context_destroy_queues\n\u2003\u2003\u2003\u2003\u2003\u2003\u2003\u2003pvr_queue_destroy\n\u2003\u2003\u2003\u2003\u2003\u2003\u2003\u2003\u2003\u2003drm_sched_entity_fini // here\n\nCall to drm_sched_entity_destroy() from pvr_context_kill_queues() calls\ndrm_sched_entity_flush() + drm_sched_entity_fini().\ndrm_sched_entity_flush() ensures all pending jobs are completed and\ndrm_sched_entity_fini() ensures no further submission is allowed as\nper expectation from pvr_context_kill_queues(). Double call to\ndrm_sched_entity_fini() is misuse of the API so keep call only in\npvr_context_create() failure path.\n\nStack trace for issue with addition of refcounting for DRM entity\nstats in commit fd177135f0e6 (\"drm/sched: Account entity GPU time\"):\n\n[ 789.490527] ------------[ cut here ]------------\n[ 789.490559] refcount_t: underflow; use-after-free.\n[ 789.490657] WARNING: lib/refcount.c:28 at refcount_warn_saturate+0xf4/0x144, CPU#0: kworker/u16:1/440\n[ 789.490695] Modules linked in: powervr drm_gpuvm drm_exec gpu_sched drm_shmem_helper xhci_plat_hcd xhci_hcd dwc3 usbcore usb_common snd_soc_simple_card snd_soc_simple_card_utils sa2ul sha512 sha256 dwc3_am62 sha1 authenc rti_wdt libsha512 at24 sch_fq_codel fuse dm_mod ipv6\n[ 789.490798] CPU: 0 UID: 0 PID: 440 Comm: kworker/u16:1 Not tainted 7.0.0-rc7-02049-g5e2c0700091b #22 PREEMPT\n[ 789.490809] Hardware name: Texas Instruments AM625 SK (DT)\n[ 789.490815] Workqueue: powervr-sched pvr_queue_fence_release_work [powervr]\n[ 789.490868] pstate: 60000005 (nZCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n[ 789.490876] pc : refcount_warn_saturate+0xf4/0x144\n[ 789.490884] lr : refcount_warn_saturate+0xf4/0x144\n[ 789.490892] sp : ffff8000822cbcc0\n[ 789.490895] x29: ffff8000822cbcc0 x28: 0000000000000000 x27: 0000000000000000\n[ 789.490909] x26: 0000000000000000 x25: ffff800081b1e338 x24: ffff000004541405\n[ 789.490922] x23: ffff000004bea950 x22: ffff00000042e400 x21: ffff000007123e30\n[ 789.490935] x20: ffff000007123000 x19: ffff000007a80d50 x18: fffffffffffe7768\n[ 789.490948] x17: 74736574202c6e6f x16: 697461746e656d65 x15: ffff800081b269f0\n[ 789.490962] x14: 0000000000000030 x13: ffff800081b26a70 x12: 0000000000000211\n[ 789.490975] x11: 00000000000000c0 x10: 0000000000000b50 x9 : ffff8000822cbb30\n[ 789.490988] x8 : ffff0000014e7bb0 x7 : ffff00007725e780 x6 : 0000000372a05f49\n[ 789.491001] x5 : 0000000000000000 x4 : 0000000000000001 x3 : 0000000000000010\n[ 789.491013] x2 : 0000000000000000 x1 : 0000000000000000 x0 : ffff0000014e7000\n[ 789.491027] Call trace:\n[ 789.491032] refcount_warn_saturate+0xf4/0x144 (P)\n[ 789.491043] drm_sched_entity_fini+0x164/0x18c [gpu_sched]\n[ 789.491081] pvr_queue_destroy+0x64/0x134 [powervr]\n[ 789.491110] pvr_context_destroy_queues+0x34/0x64 [powervr]\n[ 789.491138] pvr_context_release+0x70/0xac [powervr]\n[ 789.491166] pvr_context_put.part.0+0x5c/0x7c [powervr]\n[ 789.491193] pvr_context_put+0x14/0x24 [powervr]\n[ 789.491221] pvr_queue_fence_release_work+0x20/0x38 [powervr]\n[ 789.491249] process_one_work+0x160/0x4c4\n[ 789.491264] worker_thread+0x188/0x310\n[ 789.491276] kthread+0x130/0x13c\n[ 789.491287] ret_from_fork+0x10/0x20\n[ 789.491300] ---[ end trace 0000000000000000 ]---"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached only through the PowerVR DRM render node (/dev/dri/renderD*) via the DRM_IOCTL_PVR_CREATE_CONTEXT / SUBMIT_JOBS / DESTROY_CONTEXT ioctls or by closing the DRM file descriptor, which requires local access to the device.\nAC:L - pvr_context_destroy() unconditionally calls drm_sched_entity_destroy() (fini #1) and pvr_context_release() then calls drm_sched_entity_fini() again, so the extra stats kref put happens deterministically on every context teardown; the attacker also controls job submission, so keeping a job reference alive over the free window is trivially arranged.\nPR:L - All involved ioctls are marked DRM_RENDER_ALLOW, so any unprivileged local user (or sandboxed app on Android/embedded systems) that can open the render node \u2014 the normal configuration for graphics clients \u2014 can drive the path; no capability is required.\nUI:N - The attacker performs the whole sequence itself with open(), a few ioctls and close(); no action by another user or administrator is needed.\nS:U - The corruption stays within kernel memory managed by the same kernel security authority; no VM, IOMMU or sandbox boundary is crossed.\nC:H - The duplicate drm_sched_entity_stats_put() frees the kref\u0027d drm_sched_entity_stats slab object while in-flight jobs still hold pointers to it, so subsequent scheduler accesses read freed memory that an unprivileged process can reallocate and spray, allowing disclosure of arbitrary kernel data.\nI:H - After the premature free, drm_sched_entity_stats_job_add_gpu_time() takes stats-\u003elock and writes stats-\u003eruntime into reclaimed memory, giving a use-after-free write into an attacker-groomable kmalloc object that can be leveraged for privilege escalation.\nA:H - The refcount underflow triggers a WARNING splat and the resulting use-after-free on the entity stats object corrupts kernel heap state from the scheduler workqueue, readily causing an oops or panic."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:01:55.726Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/9be3f4bd6f514f69c51a8c77ea64fce2729dc7f4"
},
{
"url": "https://git.kernel.org/stable/c/c88fdbf3da26e0179629530cae7768cd3d4ead85"
},
{
"url": "https://git.kernel.org/stable/c/c1136d907fd04ca5c62ba11c1159b5fe65a1760c"
},
{
"url": "https://git.kernel.org/stable/c/4af24c27a39ba147a613a09e10b9e0f7294524c0"
}
],
"title": "drm/imagination: Fix double call to drm_sched_entity_fini()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68263",
"datePublished": "2026-08-10T12:01:37.571Z",
"dateReserved": "2026-07-30T09:28:09.378Z",
"dateUpdated": "2026-08-17T05:01:55.726Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68397 (GCVE-0-2026-68397)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/iucv: take a reference on the socket found in afiucv_hs_rcv()
afiucv_hs_rcv() looks up the destination socket under iucv_sk_list.lock,
drops the lock, and then passes the socket to the afiucv_hs_callback_*()
handlers without holding a reference. AF_IUCV sockets are not
RCU-protected and are freed synchronously by iucv_sock_kill() ->
sock_put(), so a concurrent close can free the socket in the window
between read_unlock() and the handler, which then dereferences freed
memory (for example sk->sk_data_ready() in afiucv_hs_callback_syn()).
Take a reference with sock_hold() while the socket is still on the list
and release it with sock_put() once the handler has run.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 3881ac441f642d56503818123446f7298442236b Version: 3881ac441f642d56503818123446f7298442236b Version: 3881ac441f642d56503818123446f7298442236b Version: 3881ac441f642d56503818123446f7298442236b Version: 3881ac441f642d56503818123446f7298442236b Version: 3881ac441f642d56503818123446f7298442236b Version: 3881ac441f642d56503818123446f7298442236b Version: 3881ac441f642d56503818123446f7298442236b |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/iucv/af_iucv.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "5739be5c19495d709d902a2912c9102ce78740d5",
"status": "affected",
"version": "3881ac441f642d56503818123446f7298442236b",
"versionType": "git"
},
{
"lessThan": "bc6c6e546ffff8865daaeb622ef348c2d481e80f",
"status": "affected",
"version": "3881ac441f642d56503818123446f7298442236b",
"versionType": "git"
},
{
"lessThan": "e3e0679fc950191aff8f27fa78abcfc2462cff4a",
"status": "affected",
"version": "3881ac441f642d56503818123446f7298442236b",
"versionType": "git"
},
{
"lessThan": "4dc0e63abf8bc7ba8892e617c1fb8b204361e022",
"status": "affected",
"version": "3881ac441f642d56503818123446f7298442236b",
"versionType": "git"
},
{
"lessThan": "1801cb20a5025a787d6853e19c38db138344b4b4",
"status": "affected",
"version": "3881ac441f642d56503818123446f7298442236b",
"versionType": "git"
},
{
"lessThan": "c75a950e77356e526672cba4584080c6c8b793b6",
"status": "affected",
"version": "3881ac441f642d56503818123446f7298442236b",
"versionType": "git"
},
{
"lessThan": "5595ea59cdf29182cf6a270cacc1426c57b603de",
"status": "affected",
"version": "3881ac441f642d56503818123446f7298442236b",
"versionType": "git"
},
{
"lessThan": "4fa349156043dc119721d067329714179f501749",
"status": "affected",
"version": "3881ac441f642d56503818123446f7298442236b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/iucv/af_iucv.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.2"
},
{
"lessThan": "3.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/iucv: take a reference on the socket found in afiucv_hs_rcv()\n\nafiucv_hs_rcv() looks up the destination socket under iucv_sk_list.lock,\ndrops the lock, and then passes the socket to the afiucv_hs_callback_*()\nhandlers without holding a reference. AF_IUCV sockets are not\nRCU-protected and are freed synchronously by iucv_sock_kill() -\u003e\nsock_put(), so a concurrent close can free the socket in the window\nbetween read_unlock() and the handler, which then dereferences freed\nmemory (for example sk-\u003esk_data_ready() in afiucv_hs_callback_syn()).\n\nTake a reference with sock_hold() while the socket is still on the list\nand release it with sock_put() once the handler has run."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The vulnerable handler is registered via dev_add_pack() for ethertype ETH_P_AF_IUCV (0xFBFB) on every netdevice, so any peer LPAR/guest on the same HiperSockets internal LAN or any host on an attached Ethernet segment can drive afiucv_hs_rcv() with crafted frames; the frames are raw L2 and cannot be routed across an IP hop, so the vector is adjacent rather than network.\nAC:L - The attacker controls the packet side of the race outright (flooding 0xFBFB frames) and can drive the freeing side too, since SYN frames make a listener spawn and enqueue child sockets while FIN/SYN|FIN frames push sockets to IUCV_DISCONN and wake the application into close(), so the read_unlock()-to-handler window can be retried indefinitely until won.\nPR:N - afiucv_hs_rcv() runs from the netif RX softirq and processes any matching frame with no authentication, credential check, or capability test anywhere on the path; the attacker needs no account or privilege on the target s390 system.\nUI:N - No victim action is required: the attacker\u0027s own frames both create the AF_IUCV child sockets and trigger the state changes that lead to their teardown, and the packet handler runs unconditionally in softirq context.\nS:U - The freed struct sock and the resulting corruption stay inside the kernel of the affected LPAR or z/VM guest; no hypervisor, IOMMU, or container boundary is crossed.\nC:H - This is a use-after-free on a socket allocated from a generic kmalloc cache (iucv_proto is registered without its own slab), so an attacker who reclaims the object has the kernel read attacker-influenced or stale heap contents through sk fields, sk_filter()\u0027s BPF program pointer, and the iucv backlog queues, yielding kernel memory disclosure.\nI:H - After the free the handlers perform indirect calls through the freed object (sk-\u003esk_data_ready(), sk-\u003esk_state_change(), sk_filter()) and writes into it (sk_state, atomic_sub on iucv-\u003emsg_sent, skb_queue_tail() list-pointer updates), giving control-flow hijack and write primitives once the slab object is reclaimed with attacker-controlled data.\nA:H - Dereferencing the freed socket from softirq context reliably produces an oops or \"Fatal exception in interrupt\" panic, and the attacker can repeat the frame flood at will, causing complete loss of availability of the IBM Z LPAR or guest."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:47.433Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/5739be5c19495d709d902a2912c9102ce78740d5"
},
{
"url": "https://git.kernel.org/stable/c/bc6c6e546ffff8865daaeb622ef348c2d481e80f"
},
{
"url": "https://git.kernel.org/stable/c/e3e0679fc950191aff8f27fa78abcfc2462cff4a"
},
{
"url": "https://git.kernel.org/stable/c/4dc0e63abf8bc7ba8892e617c1fb8b204361e022"
},
{
"url": "https://git.kernel.org/stable/c/1801cb20a5025a787d6853e19c38db138344b4b4"
},
{
"url": "https://git.kernel.org/stable/c/c75a950e77356e526672cba4584080c6c8b793b6"
},
{
"url": "https://git.kernel.org/stable/c/5595ea59cdf29182cf6a270cacc1426c57b603de"
},
{
"url": "https://git.kernel.org/stable/c/4fa349156043dc119721d067329714179f501749"
}
],
"title": "net/iucv: take a reference on the socket found in afiucv_hs_rcv()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68397",
"datePublished": "2026-08-10T12:04:16.772Z",
"dateReserved": "2026-07-30T09:28:09.389Z",
"dateUpdated": "2026-08-19T16:34:47.433Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-45897 (GCVE-0-2026-45897)
Vulnerability from cvelistv5
Published
2026-05-27 12:17
Modified
2026-08-03 09:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nft_counter: serialize reset with spinlock
Add a global static spinlock to serialize counter fetch+reset
operations, preventing concurrent dump-and-reset from underrunning
values.
The lock is taken before fetching the total so that two parallel
resets cannot both read the same counter values and then both
subtract them.
A global lock is used for simplicity since resets are infrequent.
If this becomes a bottleneck, it can be replaced with a per-net
lock later.
References
| URL | Tags | |
|---|---|---|
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 3cb03edb4de33fd04c4ea55f47397b96a8657c53 Version: 3cb03edb4de33fd04c4ea55f47397b96a8657c53 Version: 3cb03edb4de33fd04c4ea55f47397b96a8657c53 Version: 3cb03edb4de33fd04c4ea55f47397b96a8657c53 Version: fb1adb05ea87b6149e65a31e511756c4f470d0cd Version: f123293db16dcd0cd81b246ae60e6362f0025d0a Version: 6.1.107 ≤ Version: 6.6.48 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/netfilter/nft_counter.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "48cf7918d10c66cb6b05226fa3fa5daf0c891089",
"status": "affected",
"version": "3cb03edb4de33fd04c4ea55f47397b96a8657c53",
"versionType": "git"
},
{
"lessThan": "cd968dcdec6aee79a2d399e4f6e0eca63c3b45e1",
"status": "affected",
"version": "3cb03edb4de33fd04c4ea55f47397b96a8657c53",
"versionType": "git"
},
{
"lessThan": "0cdc6d5a26f2d1f7f15a43526841b679445c32e2",
"status": "affected",
"version": "3cb03edb4de33fd04c4ea55f47397b96a8657c53",
"versionType": "git"
},
{
"lessThan": "779c60a5190c42689534172f4b49e927c9959e4e",
"status": "affected",
"version": "3cb03edb4de33fd04c4ea55f47397b96a8657c53",
"versionType": "git"
},
{
"status": "affected",
"version": "fb1adb05ea87b6149e65a31e511756c4f470d0cd",
"versionType": "git"
},
{
"status": "affected",
"version": "f123293db16dcd0cd81b246ae60e6362f0025d0a",
"versionType": "git"
},
{
"lessThan": "6.2",
"status": "affected",
"version": "6.1.107",
"versionType": "semver"
},
{
"lessThan": "6.7",
"status": "affected",
"version": "6.6.48",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/netfilter/nft_counter.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.7"
},
{
"lessThan": "6.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.19.*",
"status": "unaffected",
"version": "6.19.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.0",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.19.4",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.1.107",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.6.48",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_counter: serialize reset with spinlock\n\nAdd a global static spinlock to serialize counter fetch+reset\noperations, preventing concurrent dump-and-reset from underrunning\nvalues.\n\nThe lock is taken before fetching the total so that two parallel\nresets cannot both read the same counter values and then both\nsubtract them.\n\nA global lock is used for simplicity since resets are infrequent.\nIf this becomes a bottleneck, it can be replaced with a per-net\nlock later."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-03T09:32:30.454Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/48cf7918d10c66cb6b05226fa3fa5daf0c891089"
},
{
"url": "https://git.kernel.org/stable/c/cd968dcdec6aee79a2d399e4f6e0eca63c3b45e1"
},
{
"url": "https://git.kernel.org/stable/c/0cdc6d5a26f2d1f7f15a43526841b679445c32e2"
},
{
"url": "https://git.kernel.org/stable/c/779c60a5190c42689534172f4b49e927c9959e4e"
}
],
"title": "netfilter: nft_counter: serialize reset with spinlock",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-45897",
"datePublished": "2026-05-27T12:17:07.038Z",
"dateReserved": "2026-05-13T15:03:33.083Z",
"dateUpdated": "2026-08-03T09:32:30.454Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68221 (GCVE-0-2026-68221)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-17 05:01
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: nuvoton: npcm-video: fix memory leaks in probe and remove
npcm_video_probe() allocates the npcm_video structure with kzalloc_obj()
but never frees it on any probe error path or in npcm_video_remove(),
leaking the allocation on every failed probe and every normal unbind.
Additionally, when npcm_video_setup_video() fails, the reserved memory
association established by of_reserved_mem_device_init() in
npcm_video_init() is not released, leaking the rmem_assigned_device
entry on the global list.
Fix both by adding kfree(video) to all probe error paths and to
npcm_video_remove(), and adding the missing
of_reserved_mem_device_release() call when npcm_video_setup_video()
fails.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/platform/nuvoton/npcm-video.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b092d690a9b28795ab2db083023e8a5368cddb22",
"status": "affected",
"version": "46c15a4ff1f4fe078c5b250fb2570020211eab38",
"versionType": "git"
},
{
"lessThan": "181a0aeefd56f9285325b84789aa348aba0508bf",
"status": "affected",
"version": "46c15a4ff1f4fe078c5b250fb2570020211eab38",
"versionType": "git"
},
{
"lessThan": "65ddc021d39d6383635ee8b0970b2d1c7947e447",
"status": "affected",
"version": "46c15a4ff1f4fe078c5b250fb2570020211eab38",
"versionType": "git"
},
{
"lessThan": "50cc0e547da50b887e63dfa1ad203cd5b735d01e",
"status": "affected",
"version": "46c15a4ff1f4fe078c5b250fb2570020211eab38",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/platform/nuvoton/npcm-video.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.7"
},
{
"lessThan": "6.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: nuvoton: npcm-video: fix memory leaks in probe and remove\n\nnpcm_video_probe() allocates the npcm_video structure with kzalloc_obj()\nbut never frees it on any probe error path or in npcm_video_remove(),\nleaking the allocation on every failed probe and every normal unbind.\n\nAdditionally, when npcm_video_setup_video() fails, the reserved memory\nassociation established by of_reserved_mem_device_init() in\nnpcm_video_init() is not released, leaking the rmem_assigned_device\nentry on the global list.\n\nFix both by adding kfree(video) to all probe error paths and to\nnpcm_video_remove(), and adding the missing\nof_reserved_mem_device_release() call when npcm_video_setup_video()\nfails."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:01:07.985Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b092d690a9b28795ab2db083023e8a5368cddb22"
},
{
"url": "https://git.kernel.org/stable/c/181a0aeefd56f9285325b84789aa348aba0508bf"
},
{
"url": "https://git.kernel.org/stable/c/65ddc021d39d6383635ee8b0970b2d1c7947e447"
},
{
"url": "https://git.kernel.org/stable/c/50cc0e547da50b887e63dfa1ad203cd5b735d01e"
}
],
"title": "media: nuvoton: npcm-video: fix memory leaks in probe and remove",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68221",
"datePublished": "2026-08-10T12:00:41.392Z",
"dateReserved": "2026-07-30T09:28:09.375Z",
"dateUpdated": "2026-08-17T05:01:07.985Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68290 (GCVE-0-2026-68290)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-17 05:02
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
rds: tcp: unregister sysctl before tearing down listen socket
rds_tcp_exit_net() frees the per-netns RDS TCP listen socket via
rds_tcp_kill_sock() before unregistering the per-netns sysctl table. Since
rds_tcp_skbuf_handler() derives the netns from
rtn->rds_tcp_listen_sock->sk, a concurrent sysctl write can race with
netns teardown and dereference the freed socket/sk.
KASAN reports the race as:
BUG: KASAN: slab-use-after-free in rds_tcp_skbuf_handler+0x2aa/0x2e0
rds_tcp_skbuf_handler net/rds/tcp.c:721
proc_sys_call_handler fs/proc/proc_sysctl.c
vfs_write fs/read_write.c
__x64_sys_pwrite64 fs/read_write.c
Fix this by unregistering the RDS TCP sysctl table before calling
rds_tcp_kill_sock(). unregister_net_sysctl_table() prevents new sysctl
handlers from starting and waits for in-flight handlers to finish, so
the listen socket can then be released safely. The fix was tested
against the linked reproducer.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/rds/tcp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "80fffed08dc1c10e971066941d2daa56253f1552",
"status": "affected",
"version": "de8d6de0ee27be4b2b1e5b06f04aeacbabbba492",
"versionType": "git"
},
{
"lessThan": "16df2d154ec82e2f7e7585b4fa154751ba37729a",
"status": "affected",
"version": "7f5611cbc4871c7fb1ad36c2e5a9edad63dca95c",
"versionType": "git"
},
{
"lessThan": "3aa13fe0c1bb7bc5312f878e61523e5d8cf3f85d",
"status": "affected",
"version": "7f5611cbc4871c7fb1ad36c2e5a9edad63dca95c",
"versionType": "git"
},
{
"lessThan": "167e54c703ccd4fa028feb568b0d1002020cff86",
"status": "affected",
"version": "7f5611cbc4871c7fb1ad36c2e5a9edad63dca95c",
"versionType": "git"
},
{
"lessThan": "6.12.101",
"status": "affected",
"version": "6.12.10",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/rds/tcp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.13"
},
{
"lessThan": "6.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.12.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nrds: tcp: unregister sysctl before tearing down listen socket\n\nrds_tcp_exit_net() frees the per-netns RDS TCP listen socket via\nrds_tcp_kill_sock() before unregistering the per-netns sysctl table. Since\nrds_tcp_skbuf_handler() derives the netns from\nrtn-\u003erds_tcp_listen_sock-\u003esk, a concurrent sysctl write can race with\nnetns teardown and dereference the freed socket/sk.\n\nKASAN reports the race as:\n\n BUG: KASAN: slab-use-after-free in rds_tcp_skbuf_handler+0x2aa/0x2e0\n rds_tcp_skbuf_handler net/rds/tcp.c:721\n proc_sys_call_handler fs/proc/proc_sysctl.c\n vfs_write fs/read_write.c\n __x64_sys_pwrite64 fs/read_write.c\n\nFix this by unregistering the RDS TCP sysctl table before calling\nrds_tcp_kill_sock(). unregister_net_sysctl_table() prevents new sysctl\nhandlers from starting and waits for in-flight handlers to finish, so\nthe listen socket can then be released safely. The fix was tested\nagainst the linked reproducer."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerability is triggered by a local write() /pwrite64() to the per-netns sysctl file /proc/sys/net/rds/tcp/rds_tcp_{snd,rcv}buf racing with network namespace teardown; no network traffic reaches the vulnerable handler, so local syscall access is required.\nAC:L - Although this is a race, the attacker controls both sides: they create the netns, keep the sysctl fd open, choose when the netns is destroyed, and issue the concurrent sysctl write in a tight loop, so the race can be retried indefinitely until won.\nPR:L - Only an unprivileged local account is needed: unshare -Urn yields CAP_NET_ADMIN over the new netns\u0027s user_ns, and net_ctl_permissions()/net_ctl_set_ownership() then grant that user write access to the RDS TCP sysctls, while the rds_tcp module is autoloaded by an unprivileged AF_RDS socket.\nUI:N - The attacker performs every step itself \u2014 namespace creation, opening the sysctl file, triggering teardown and writing \u2014 with no action required from any other user or administrator.\nS:U - The use-after-free occurs on kernel slab objects belonging to the same kernel security authority; there is no crossing of a VM, IOMMU or other security boundary.\nC:H - The handler reads the freed listen socket and then dereferences lsock-\u003esk and sock_net(sk); by spraying the freed socket/sk slabs the attacker can steer these dereferences to chosen addresses, turning the use-after-free read into a kernel memory disclosure primitive.\nI:H - Reallocating the freed struct socket/sk with attacker-controlled data lets the attacker supply a bogus struct net pointer that drives rds_tcp_sysctl_reset()/rds_conn_path_drop() over the global RDS connection list, corrupting kernel state and giving the usual UAF path toward control-flow hijack.\nA:H - The confirmed KASAN slab-use-after-free on the freed listen socket readily oopses or panics the kernel, and the race can be repeated by an unprivileged user until it hits, giving a reliable denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:02:25.806Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/80fffed08dc1c10e971066941d2daa56253f1552"
},
{
"url": "https://git.kernel.org/stable/c/16df2d154ec82e2f7e7585b4fa154751ba37729a"
},
{
"url": "https://git.kernel.org/stable/c/3aa13fe0c1bb7bc5312f878e61523e5d8cf3f85d"
},
{
"url": "https://git.kernel.org/stable/c/167e54c703ccd4fa028feb568b0d1002020cff86"
}
],
"title": "rds: tcp: unregister sysctl before tearing down listen socket",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68290",
"datePublished": "2026-08-10T12:02:23.425Z",
"dateReserved": "2026-07-30T09:28:09.380Z",
"dateUpdated": "2026-08-17T05:02:25.806Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72069 (GCVE-0-2026-72069)
Vulnerability from cvelistv5
Published
2026-08-15 05:52
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
locking/rt: Fix the incorrect RCU protection in rt_spin_unlock()
rt_spin_unlock() releases the RCU protection before unlocking the
lock. That opens the door for the following UAF scenario:
T1 T2
spin_lock(&p->lock); rcu_read_lock();
invalidate(p); p = rcu_dereference(ptr);
rcu_assign_pointer(ptr, NULL); if (!p) return;
spin_unlock(&p->lock); spin_lock(&p->lock)
lock(&lock->lock);
rcu_read_lock();
kfree_rcu(p); rcu_read_unlock();
....
spin_unlock(&p->lock)
rcu_read_unlock(); // Ends grace period
rcu_do_batch()
kfree(p);
UAF -> rt_mutex_cmpxchg_release(&lock->lock...)
Regular spinlocks keep preemption disabled accross the unlock operation,
which provides full RCU protection, but the RT substitution fails to
resemble that. Same applies for the rwlock substitution.
Move the rcu_read_unlock() invocation past the unlock operations to match
the non-RT semantics. This makes it asymmetric vs. rt_xxx_lock(), but
that's harmless as the caller needs to hold RCU read lock across the lock
operation. The migrate_enable() call stays before the unlock operation
because there is no per CPU operation in the unlock path which would
require migration to be kept disabled.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 0f383b6dc96e976dfbf2721b0bf10bd96103b341 Version: 0f383b6dc96e976dfbf2721b0bf10bd96103b341 Version: 0f383b6dc96e976dfbf2721b0bf10bd96103b341 Version: 0f383b6dc96e976dfbf2721b0bf10bd96103b341 Version: 0f383b6dc96e976dfbf2721b0bf10bd96103b341 Version: 0f383b6dc96e976dfbf2721b0bf10bd96103b341 Version: 0f383b6dc96e976dfbf2721b0bf10bd96103b341 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"kernel/locking/spinlock_rt.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "af28d801cd2db4cc7378554499bd4a5d84a5517e",
"status": "affected",
"version": "0f383b6dc96e976dfbf2721b0bf10bd96103b341",
"versionType": "git"
},
{
"lessThan": "9d1fcd64ab81200e02b7a6db5eb1da8e244e8289",
"status": "affected",
"version": "0f383b6dc96e976dfbf2721b0bf10bd96103b341",
"versionType": "git"
},
{
"lessThan": "3cfaac77b3c32ac3940df28866de263c3f45d24c",
"status": "affected",
"version": "0f383b6dc96e976dfbf2721b0bf10bd96103b341",
"versionType": "git"
},
{
"lessThan": "1f0d56d3f1e88f20f6e46109402f8c15d59bac37",
"status": "affected",
"version": "0f383b6dc96e976dfbf2721b0bf10bd96103b341",
"versionType": "git"
},
{
"lessThan": "633cadbc0b8323f5cc140a285d2432089dbb534e",
"status": "affected",
"version": "0f383b6dc96e976dfbf2721b0bf10bd96103b341",
"versionType": "git"
},
{
"lessThan": "83f9fb561c1c3917e19f95523dd933c7d30291aa",
"status": "affected",
"version": "0f383b6dc96e976dfbf2721b0bf10bd96103b341",
"versionType": "git"
},
{
"lessThan": "89038cc87d80c77e7aa6f42a64b2573b74af339f",
"status": "affected",
"version": "0f383b6dc96e976dfbf2721b0bf10bd96103b341",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"kernel/locking/spinlock_rt.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.15"
},
{
"lessThan": "5.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nlocking/rt: Fix the incorrect RCU protection in rt_spin_unlock()\n\nrt_spin_unlock() releases the RCU protection before unlocking the\nlock. That opens the door for the following UAF scenario:\n\n T1\t\t\t\t\tT2\n spin_lock(\u0026p-\u003elock);\t\trcu_read_lock();\n invalidate(p);\t\t\tp = rcu_dereference(ptr);\n rcu_assign_pointer(ptr, NULL);\tif (!p) return;\n spin_unlock(\u0026p-\u003elock);\t\tspin_lock(\u0026p-\u003elock)\n \t\t\t\t lock(\u0026lock-\u003elock);\n\t\t\t\t rcu_read_lock();\n kfree_rcu(p);\t\t\trcu_read_unlock();\n\t\t\t\t....\n\t\t\t\tspin_unlock(\u0026p-\u003elock)\n\t\t\t\t rcu_read_unlock(); // Ends grace period\n rcu_do_batch()\n kfree(p);\n\t\t\t UAF -\u003e\t rt_mutex_cmpxchg_release(\u0026lock-\u003elock...)\n\nRegular spinlocks keep preemption disabled accross the unlock operation,\nwhich provides full RCU protection, but the RT substitution fails to\nresemble that. Same applies for the rwlock substitution.\n\nMove the rcu_read_unlock() invocation past the unlock operations to match\nthe non-RT semantics. This makes it asymmetric vs. rt_xxx_lock(), but\nthat\u0027s harmless as the caller needs to hold RCU read lock across the lock\noperation. The migrate_enable() call stays before the unlock operation\nbecause there is no per CPU operation in the unlock path which would\nrequire migration to be kept disabled."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - On CONFIG_PREEMPT_RT, every spin_unlock() is substituted by rt_spin_unlock(); network subsystems such as netfilter xt_hashlimit process inbound packets through hashlimit_mt_common(), spin_lock/unlock on RCU-protected dsthash_ent objects concurrently freed via call_rcu by GC\u2014the exact embedded-spinlock UAF pattern from the fix.\nAC:L - The bug is a cross-CPU race where rt_spin_unlock() calls rcu_read_unlock() before releasing the rtmutex, ending the RCU grace period while still dereferencing the lock; syzbot triggered this reliably on PREEMPT_RT via concurrent unlinkat and dentry teardown, and attackers control both sides with parallel syscalls or packet/GC load.\nPR:N - Remote attackers need no account, capability, or authentication to send packets that hit deployed hashlimit rules on internet-facing PREEMPT_RT gateways; the proven syzbot unlinkat path needs only directory write permission (PR:L), but PR:N reflects the highest-severity unauthenticated network packet scenario.\nUI:N - No victim interaction is required; the attacker drives the race through their own concurrent filesystem syscalls (syzbot: unlinkat racing __fput/dentry_kill) or sustained inbound traffic overlapping netfilter GC, without needing another user to open files or mount filesystems.\nS:U - The UAF corrupts kernel slab memory containing embedded spinlock/rtmutex fields and enables privilege escalation within the same kernel security authority; it does not inherently cross VM/guest, container sandbox, or IOMMU hardware isolation boundaries.\nC:H - Syzbot reported KASAN slab-use-after-free Read in rt_mutex_slowunlock during spin_unlock on a freed dentry in shrink_dcache_tree; the systemic UAF lets attackers read freed objects (dentry, dsthash_ent, etc.) after premature RCU grace-period completion, enabling kernel pointer and memory disclosure.\nI:H - UAF on embedded rtmutex fields inside freed slab objects (dentry-\u003ed_lock per syzbot) permits heap grooming and reallocation of attacker-controlled data, providing standard kernel heap corruption primitives for arbitrary write and control-flow hijack beyond the immediate crash.\nA:H - Syzbot hit KASAN slab-use-after-free causing kernel fault in shrink_dcache_tree via rt_spin_unlock on PREEMPT_RT; the bug can oops/panic any RT kernel whenever spin_unlock races RCU-deferred free of the containing object, enabling repeatable denial of service via concurrent VFS or netfilter operations."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:41.836Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/af28d801cd2db4cc7378554499bd4a5d84a5517e"
},
{
"url": "https://git.kernel.org/stable/c/9d1fcd64ab81200e02b7a6db5eb1da8e244e8289"
},
{
"url": "https://git.kernel.org/stable/c/3cfaac77b3c32ac3940df28866de263c3f45d24c"
},
{
"url": "https://git.kernel.org/stable/c/1f0d56d3f1e88f20f6e46109402f8c15d59bac37"
},
{
"url": "https://git.kernel.org/stable/c/633cadbc0b8323f5cc140a285d2432089dbb534e"
},
{
"url": "https://git.kernel.org/stable/c/83f9fb561c1c3917e19f95523dd933c7d30291aa"
},
{
"url": "https://git.kernel.org/stable/c/89038cc87d80c77e7aa6f42a64b2573b74af339f"
}
],
"title": "locking/rt: Fix the incorrect RCU protection in rt_spin_unlock()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72069",
"datePublished": "2026-08-15T05:52:21.752Z",
"dateReserved": "2026-08-09T03:40:39.903Z",
"dateUpdated": "2026-08-23T12:46:41.836Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68326 (GCVE-0-2026-68326)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: mwifiex: bound uAP association event IEs to the event buffer
mwifiex_process_uap_event() handles EVENT_UAP_STA_ASSOC by exposing the
(re)association request IEs that the firmware copies into the event:
sinfo->assoc_req_ies = &event->data[len];
len = (u8 *)sinfo->assoc_req_ies - (u8 *)&event->frame_control;
sinfo->assoc_req_ies_len = le16_to_cpu(event->len) - (u16)len;
event->len is supplied by the device firmware and is never validated,
and the subtraction is unchecked. assoc_req_ies points into
adapter->event_body[MAX_EVENT_SIZE], a fixed-size array embedded in the
kmalloc()'d struct mwifiex_adapter.
On the ap_11n_enabled path mwifiex_set_sta_ht_cap() walks these IEs with
cfg80211_find_ie(), whose for_each_element() loop dereferences each
element header. A firmware-reported event->len larger than the bytes
actually received makes assoc_req_ies_len describe IEs that extend past
event_body, so the walk reads out of the adapter slab object, a
slab-out-of-bounds read (KASAN: slab-out-of-bounds in cfg80211_find_ie).
An event->len smaller than the header instead makes the int subtraction
negative, which wraps to a huge size_t when stored in assoc_req_ies_len.
The same length is handed to cfg80211_new_sta(), so a more modest
over-claim can also copy stale event_body bytes into the
NL80211_CMD_NEW_STATION notification.
A malicious or malfunctioning mwifiex device (USB/SDIO/PCIe) can deliver
such an event while the interface is in AP/uAP mode.
Validate event->len before use: reject a length that underflows the
header or that would place the IEs outside the event_body[] buffer the
event was copied into. event->len here is struct mwifiex_assoc_event.len,
a payload field internal to this event, not the transport frame length,
so it is validated in this handler rather than at the generic
MWIFIEX_TYPE_EVENT receive path, which only sees the event cause and the
transport frame length. The bound is against event_body[MAX_EVENT_SIZE]
rather than the actually-received length because the transports store the
event differently (USB and SDIO leave the 4-byte event header in
event_skb, PCIe strips it via skb_pull), whereas event_body is the single
fixed buffer all of them copy the event into. This is the event-path
analogue of the receive-path bounds checks added in commit 119585281617
("wifi: mwifiex: Fix OOB and integer underflow when rx packets").
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: e568634ae7ac379661c90731d480e067929420a1 Version: e568634ae7ac379661c90731d480e067929420a1 Version: e568634ae7ac379661c90731d480e067929420a1 Version: e568634ae7ac379661c90731d480e067929420a1 Version: e568634ae7ac379661c90731d480e067929420a1 Version: e568634ae7ac379661c90731d480e067929420a1 Version: e568634ae7ac379661c90731d480e067929420a1 Version: e568634ae7ac379661c90731d480e067929420a1 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/marvell/mwifiex/uap_event.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a616616b938f7922a93e79bef16b4643c57c0922",
"status": "affected",
"version": "e568634ae7ac379661c90731d480e067929420a1",
"versionType": "git"
},
{
"lessThan": "1ae00b6d9a6c82eb3de151d9b04ed59e06cc100f",
"status": "affected",
"version": "e568634ae7ac379661c90731d480e067929420a1",
"versionType": "git"
},
{
"lessThan": "e7e93d3e8c240bdb70c41e79d169d74dfb442843",
"status": "affected",
"version": "e568634ae7ac379661c90731d480e067929420a1",
"versionType": "git"
},
{
"lessThan": "a3f47d7c75ddad1a14621a309286f9fae3cba191",
"status": "affected",
"version": "e568634ae7ac379661c90731d480e067929420a1",
"versionType": "git"
},
{
"lessThan": "ad26c75ae25749313248f06510ebe43b5bf4adcc",
"status": "affected",
"version": "e568634ae7ac379661c90731d480e067929420a1",
"versionType": "git"
},
{
"lessThan": "d21464d93f8ba464dc3d7b4b31c6e0adcd9f659c",
"status": "affected",
"version": "e568634ae7ac379661c90731d480e067929420a1",
"versionType": "git"
},
{
"lessThan": "b6766d7ea43edf5de9d5a572bc58b631d09efe4b",
"status": "affected",
"version": "e568634ae7ac379661c90731d480e067929420a1",
"versionType": "git"
},
{
"lessThan": "f0858bfc7d3cab411a447b88e3ef970e575032c9",
"status": "affected",
"version": "e568634ae7ac379661c90731d480e067929420a1",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/marvell/mwifiex/uap_event.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.5"
},
{
"lessThan": "3.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mwifiex: bound uAP association event IEs to the event buffer\n\nmwifiex_process_uap_event() handles EVENT_UAP_STA_ASSOC by exposing the\n(re)association request IEs that the firmware copies into the event:\n\n\tsinfo-\u003eassoc_req_ies = \u0026event-\u003edata[len];\n\tlen = (u8 *)sinfo-\u003eassoc_req_ies - (u8 *)\u0026event-\u003eframe_control;\n\tsinfo-\u003eassoc_req_ies_len = le16_to_cpu(event-\u003elen) - (u16)len;\n\nevent-\u003elen is supplied by the device firmware and is never validated,\nand the subtraction is unchecked. assoc_req_ies points into\nadapter-\u003eevent_body[MAX_EVENT_SIZE], a fixed-size array embedded in the\nkmalloc()\u0027d struct mwifiex_adapter.\n\nOn the ap_11n_enabled path mwifiex_set_sta_ht_cap() walks these IEs with\ncfg80211_find_ie(), whose for_each_element() loop dereferences each\nelement header. A firmware-reported event-\u003elen larger than the bytes\nactually received makes assoc_req_ies_len describe IEs that extend past\nevent_body, so the walk reads out of the adapter slab object, a\nslab-out-of-bounds read (KASAN: slab-out-of-bounds in cfg80211_find_ie).\nAn event-\u003elen smaller than the header instead makes the int subtraction\nnegative, which wraps to a huge size_t when stored in assoc_req_ies_len.\nThe same length is handed to cfg80211_new_sta(), so a more modest\nover-claim can also copy stale event_body bytes into the\nNL80211_CMD_NEW_STATION notification.\n\nA malicious or malfunctioning mwifiex device (USB/SDIO/PCIe) can deliver\nsuch an event while the interface is in AP/uAP mode.\n\nValidate event-\u003elen before use: reject a length that underflows the\nheader or that would place the IEs outside the event_body[] buffer the\nevent was copied into. event-\u003elen here is struct mwifiex_assoc_event.len,\na payload field internal to this event, not the transport frame length,\nso it is validated in this handler rather than at the generic\nMWIFIEX_TYPE_EVENT receive path, which only sees the event cause and the\ntransport frame length. The bound is against event_body[MAX_EVENT_SIZE]\nrather than the actually-received length because the transports store the\nevent differently (USB and SDIO leave the 4-byte event header in\nevent_skb, PCIe strips it via skb_pull), whereas event_body is the single\nfixed buffer all of them copy the event into. This is the event-path\nanalogue of the receive-path bounds checks added in commit 119585281617\n(\"wifi: mwifiex: Fix OOB and integer underflow when rx packets\")."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The event payload is the firmware\u0027s rendering of an over-the-air (re)association request received by the mwifiex uAP interface, with event-\u003elen being the TLV length covering that frame, so the triggering input comes from a station within 802.11 radio range. This matches the Adjacent treatment used for other frame/event-driven mwifiex defects (CVE-2024-46755, CVE-2023-53226).\nAC:L - No race or attacker-uncontrollable state is involved: the attacker simply sends a crafted/oversized (re)association request to the AP, and the handler parses the resulting EVENT_UAP_STA_ASSOC unconditionally. The only precondition, an mwifiex interface in AP/uAP mode with ap_11n_enabled, is the normal steady state for tethering, Chromebook SoftAP and embedded AP deployments.\nPR:N - EVENT_UAP_STA_ASSOC is generated at association time, before the WPA/EAPOL handshake, so the attacker needs no credentials on or accepted association with the target host. No host user account or capability is involved anywhere on the path.\nUI:N - The event is consumed autonomously by mwifiex_process_uap_event() in the driver\u0027s main work handler as soon as the firmware delivers it; no local user or administrator action is required beyond the AP already running.\nS:U - The out-of-bounds read, the underflowed length and the resulting corruption are all confined to the host kernel\u0027s own security authority within the mwifiex/cfg80211 code; no hypervisor, IOMMU or sandbox boundary is crossed.\nC:H - An over-claimed event-\u003elen makes assoc_req_ies_len describe memory past adapter-\u003eevent_body[MAX_EVENT_SIZE], producing a slab-out-of-bounds read in cfg80211_find_ie() and, worse, causing nla_put() to copy up to tens of kilobytes of adjacent kernel slab memory into the NL80211_CMD_NEW_STATION notification delivered to userspace \u2014 an unbounded kernel heap disclosure, not a few stray bytes.\nI:H - An event-\u003elen below the header makes the int subtraction negative and wrap in size_t; that value reaches nla_put(), where nla_total_size() of the negative length evaluates to 0 and passes the tailroom check, so __nla_put()\u0027s memcpy() runs with the negative length widened to a huge size_t \u2014 an unbounded out-of-bounds write past the netlink skb. Driver 11n/AMSDU state is also set from out-of-bounds data.\nA:H - The commit documents a reproducible KASAN slab-out-of-bounds in cfg80211_find_ie, and the underflow path drives a memcpy of a near-2^64 length that guarantees an immediate kernel panic. The condition can be re-triggered at will by repeating the association attempt."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:21.015Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a616616b938f7922a93e79bef16b4643c57c0922"
},
{
"url": "https://git.kernel.org/stable/c/1ae00b6d9a6c82eb3de151d9b04ed59e06cc100f"
},
{
"url": "https://git.kernel.org/stable/c/e7e93d3e8c240bdb70c41e79d169d74dfb442843"
},
{
"url": "https://git.kernel.org/stable/c/a3f47d7c75ddad1a14621a309286f9fae3cba191"
},
{
"url": "https://git.kernel.org/stable/c/ad26c75ae25749313248f06510ebe43b5bf4adcc"
},
{
"url": "https://git.kernel.org/stable/c/d21464d93f8ba464dc3d7b4b31c6e0adcd9f659c"
},
{
"url": "https://git.kernel.org/stable/c/b6766d7ea43edf5de9d5a572bc58b631d09efe4b"
},
{
"url": "https://git.kernel.org/stable/c/f0858bfc7d3cab411a447b88e3ef970e575032c9"
}
],
"title": "wifi: mwifiex: bound uAP association event IEs to the event buffer",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68326",
"datePublished": "2026-08-10T12:03:02.372Z",
"dateReserved": "2026-07-30T09:28:09.382Z",
"dateUpdated": "2026-08-19T16:33:21.015Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64570 (GCVE-0-2026-64570)
Vulnerability from cvelistv5
Published
2026-08-05 08:08
Modified
2026-08-17 04:57
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: fix fils_discovery double free on alloc failure
ieee80211_set_fils_discovery() calls kfree_rcu() on the old template
before allocating the replacement. If the kzalloc() then fails, it
returns -ENOMEM while link->u.ap.fils_discovery still points at the
object already queued for freeing. A later update or AP teardown
(ieee80211_stop_ap()) re-queues that same rcu_head; the second free is
caught by KASAN when the RCU sheaf is processed in softirq:
BUG: KASAN: double-free in rcu_free_sheaf (mm/slub.c:5850)
Free of addr ffff88800c065280 by task swapper/0/0
...
__rcu_free_sheaf_prepare (mm/slub.c:2634 mm/slub.c:2940)
rcu_free_sheaf (mm/slub.c:5850)
rcu_core (kernel/rcu/tree.c:2617 kernel/rcu/tree.c:2869)
handle_softirqs (kernel/softirq.c:622)
The buggy address belongs to the cache kmalloc-96 of size 96
Queue the old object for kfree_rcu() only after the new one is published,
matching ieee80211_set_probe_resp() and ieee80211_set_s1g_short_beacon().
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/mac80211/cfg.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "e2c55079155a953db669ca1986a985fa286bad95",
"status": "affected",
"version": "3b1c256eb4aedfc71dd97d5951ccff824b41d628",
"versionType": "git"
},
{
"lessThan": "5baaa1042f71dd4b8e418f2cdd516808702d229b",
"status": "affected",
"version": "3b1c256eb4aedfc71dd97d5951ccff824b41d628",
"versionType": "git"
},
{
"lessThan": "1981fba71797ec95e6755fb882cad88899a2a84f",
"status": "affected",
"version": "3b1c256eb4aedfc71dd97d5951ccff824b41d628",
"versionType": "git"
},
{
"lessThan": "286e52a799fa158bdbd77da1426c4d93f9a6e7ad",
"status": "affected",
"version": "3b1c256eb4aedfc71dd97d5951ccff824b41d628",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/mac80211/cfg.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.7"
},
{
"lessThan": "6.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: fix fils_discovery double free on alloc failure\n\nieee80211_set_fils_discovery() calls kfree_rcu() on the old template\nbefore allocating the replacement. If the kzalloc() then fails, it\nreturns -ENOMEM while link-\u003eu.ap.fils_discovery still points at the\nobject already queued for freeing. A later update or AP teardown\n(ieee80211_stop_ap()) re-queues that same rcu_head; the second free is\ncaught by KASAN when the RCU sheaf is processed in softirq:\n\n BUG: KASAN: double-free in rcu_free_sheaf (mm/slub.c:5850)\n Free of addr ffff88800c065280 by task swapper/0/0\n ...\n __rcu_free_sheaf_prepare (mm/slub.c:2634 mm/slub.c:2940)\n rcu_free_sheaf (mm/slub.c:5850)\n rcu_core (kernel/rcu/tree.c:2617 kernel/rcu/tree.c:2869)\n handle_softirqs (kernel/softirq.c:622)\n The buggy address belongs to the cache kmalloc-96 of size 96\n\nQueue the old object for kfree_rcu() only after the new one is published,\nmatching ieee80211_set_probe_resp() and ieee80211_set_s1g_short_beacon()."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Triggered only via local nl80211 SoftAP config (NL80211_CMD_START_AP/SET_BEACON \u2192 ieee80211_set_fils_discovery), not by processing over-the-air WiFi frames or remote packets.\nAC:L - The attacker fully controls the SET_BEACON/STOP_AP sequence and can force the GFP_KERNEL kzalloc failure (e.g. memory pressure/memcg) with an attacker-chosen template size; no race or condition outside attacker influence is required.\nPR:L - START_AP and SET_BEACON use GENL_UNS_ADMIN_PERM (CAP_NET_ADMIN in the wiphy netns user_ns). Per CNA guidance that capability via user namespaces scores Low, not init-namespace root High.\nUI:N - The attacker issues the nl80211 commands to set FILS discovery and later tear down or update the AP; no separate victim action is required.\nS:U - Impact stays inside the host kernel mac80211 heap (local privilege-escalation class) and does not cross a VM, IOMMU, or other separate security authority.\nC:H - After the failed alloc the dangling fils_discovery pointer can be read via ieee80211_get_fils_discovery_tmpl and the object is double-freed; double-free/UAF enables heap reuse and arbitrary kernel memory disclosure.\nI:H - Double-free of the attacker-sized kmalloc FILS template (and subsequent stop_ap/update re-free) is classic heap corruption enabling spray/arbitrary-write and control-flow hijack primitives.\nA:H - The bug is a KASAN-confirmed double-free in rcu_free_sheaf softirq processing and can oops/panic the kernel, fully denying availability."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:57:49.594Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/e2c55079155a953db669ca1986a985fa286bad95"
},
{
"url": "https://git.kernel.org/stable/c/5baaa1042f71dd4b8e418f2cdd516808702d229b"
},
{
"url": "https://git.kernel.org/stable/c/1981fba71797ec95e6755fb882cad88899a2a84f"
},
{
"url": "https://git.kernel.org/stable/c/286e52a799fa158bdbd77da1426c4d93f9a6e7ad"
}
],
"title": "wifi: mac80211: fix fils_discovery double free on alloc failure",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64570",
"datePublished": "2026-08-05T08:08:07.855Z",
"dateReserved": "2026-07-19T15:36:31.797Z",
"dateUpdated": "2026-08-17T04:57:49.594Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64565 (GCVE-0-2026-64565)
Vulnerability from cvelistv5
Published
2026-08-04 06:23
Modified
2026-08-19 16:28
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data()
The `ims_pcu_process_data()` processes incoming URB data byte by byte.
However, it fails to check if the `read_pos` index exceeds
IMS_PCU_BUF_SIZE.
If a malicious USB device sends a packet larger than IMS_PCU_BUF_SIZE,
`read_pos` will increment indefinitely. Moreover, since `read_pos` is
located immediately after `read_buf`, the attacker can overwrite
`read_pos` itself to arbitrarily control the index.
This manipulated `read_pos` is subsequently used in
`ims_pcu_handle_response()` to copy data into `cmd_buf`, leading to a
heap buffer overflow.
Specifically, an attacker can overwrite the `cmd_done.wait.head` located
at offset 136 relative to `cmd_buf` in the `ims_pcu_handle_response()`.
Consequently, when the driver calls `complete(&pcu->cmd_done)`, it
triggers a control flow hijack by using the manipulated pointer.
Fix this by adding a bounds check for `read_pos` before writing to
`read_buf`. If the packet is too long, discard it, log a warning,
and reset the parser state.
[dtor: factor out resetting packet state, reset checksum as well]
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 628329d52474323938a03826941e166bc7c8eff4 Version: 628329d52474323938a03826941e166bc7c8eff4 Version: 628329d52474323938a03826941e166bc7c8eff4 Version: 628329d52474323938a03826941e166bc7c8eff4 Version: 628329d52474323938a03826941e166bc7c8eff4 Version: 628329d52474323938a03826941e166bc7c8eff4 Version: 628329d52474323938a03826941e166bc7c8eff4 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/input/misc/ims-pcu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "06cfff93fd40441292567b999091beab11c74504",
"status": "affected",
"version": "628329d52474323938a03826941e166bc7c8eff4",
"versionType": "git"
},
{
"lessThan": "992a7173364dcf63e30012af43da3c2f279839f9",
"status": "affected",
"version": "628329d52474323938a03826941e166bc7c8eff4",
"versionType": "git"
},
{
"lessThan": "3a801bc75ba1d121d0ed60e7234f93ba5651d87d",
"status": "affected",
"version": "628329d52474323938a03826941e166bc7c8eff4",
"versionType": "git"
},
{
"lessThan": "40bbbf2e91fd60715525bf0405c67876af817edf",
"status": "affected",
"version": "628329d52474323938a03826941e166bc7c8eff4",
"versionType": "git"
},
{
"lessThan": "ca9f8c09845fb8c51b6d447f6428eecd1b8b0a49",
"status": "affected",
"version": "628329d52474323938a03826941e166bc7c8eff4",
"versionType": "git"
},
{
"lessThan": "d03a740e087de7dcb2a26dc1123377bd3d1d84ca",
"status": "affected",
"version": "628329d52474323938a03826941e166bc7c8eff4",
"versionType": "git"
},
{
"lessThan": "875115b82c295277b81b6dfee7debc725f44e854",
"status": "affected",
"version": "628329d52474323938a03826941e166bc7c8eff4",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/input/misc/ims-pcu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.10"
},
{
"lessThan": "3.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "3.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nInput: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data()\n\nThe `ims_pcu_process_data()` processes incoming URB data byte by byte.\nHowever, it fails to check if the `read_pos` index exceeds\nIMS_PCU_BUF_SIZE.\n\nIf a malicious USB device sends a packet larger than IMS_PCU_BUF_SIZE,\n`read_pos` will increment indefinitely. Moreover, since `read_pos` is\nlocated immediately after `read_buf`, the attacker can overwrite\n`read_pos` itself to arbitrarily control the index.\n\nThis manipulated `read_pos` is subsequently used in\n`ims_pcu_handle_response()` to copy data into `cmd_buf`, leading to a\nheap buffer overflow.\n\nSpecifically, an attacker can overwrite the `cmd_done.wait.head` located\nat offset 136 relative to `cmd_buf` in the `ims_pcu_handle_response()`.\nConsequently, when the driver calls `complete(\u0026pcu-\u003ecmd_done)`, it\ntriggers a control flow hijack by using the manipulated pointer.\n\nFix this by adding a bounds check for `read_pos` before writing to\n`read_buf`. If the packet is too long, discard it, log a warning,\nand reset the parser state.\n\n[dtor: factor out resetting packet state, reset checksum as well]"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:28:39.404Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/06cfff93fd40441292567b999091beab11c74504"
},
{
"url": "https://git.kernel.org/stable/c/992a7173364dcf63e30012af43da3c2f279839f9"
},
{
"url": "https://git.kernel.org/stable/c/3a801bc75ba1d121d0ed60e7234f93ba5651d87d"
},
{
"url": "https://git.kernel.org/stable/c/40bbbf2e91fd60715525bf0405c67876af817edf"
},
{
"url": "https://git.kernel.org/stable/c/ca9f8c09845fb8c51b6d447f6428eecd1b8b0a49"
},
{
"url": "https://git.kernel.org/stable/c/d03a740e087de7dcb2a26dc1123377bd3d1d84ca"
},
{
"url": "https://git.kernel.org/stable/c/875115b82c295277b81b6dfee7debc725f44e854"
}
],
"title": "Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64565",
"datePublished": "2026-08-04T06:23:24.089Z",
"dateReserved": "2026-07-19T15:36:31.797Z",
"dateUpdated": "2026-08-19T16:28:39.404Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68280 (GCVE-0-2026-68280)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS()
The deprecated UNIVERSAL_DEV_PM_OPS() macro uses the provided callbacks
for both runtime PM and system sleep. This causes the DSI clocks to be
disabled twice: once during runtime suspend and again during system
suspend, resulting in a WARN message from the clock framework when
attempting to disable already-disabled clocks.
[ 84.384540] clk:231:5 already disabled
[ 84.388314] WARNING: CPU: 2 PID: 531 at /drivers/clk/clk.c:1181 clk_core_disable+0xa4/0xac
...
[ 84.579183] Call trace:
[ 84.581624] clk_core_disable+0xa4/0xac
[ 84.585457] clk_disable+0x30/0x4c
[ 84.588857] cdns_dsi_suspend+0x20/0x58 [cdns_dsi]
[ 84.593651] pm_generic_suspend+0x2c/0x44
[ 84.597661] ti_sci_pd_suspend+0xbc/0x15c
[ 84.601670] dpm_run_callback+0x8c/0x14c
[ 84.605588] __device_suspend+0x1a0/0x56c
[ 84.609594] dpm_suspend+0x17c/0x21c
[ 84.613165] dpm_suspend_start+0xa0/0xa8
[ 84.617083] suspend_devices_and_enter+0x12c/0x634
[ 84.621872] pm_suspend+0x1fc/0x368
To address this issue, replace UNIVERSAL_DEV_PM_OPS() with
RUNTIME_PM_OPS(). Bridge and panel drivers should only deal with runtime
PM, as the DRM framework manages system-wide power transitions through
the bridge enable() and disable() hooks.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: e19233955d9e9a9ae202723b9a38ef38e755b5c0 Version: e19233955d9e9a9ae202723b9a38ef38e755b5c0 Version: e19233955d9e9a9ae202723b9a38ef38e755b5c0 Version: e19233955d9e9a9ae202723b9a38ef38e755b5c0 Version: e19233955d9e9a9ae202723b9a38ef38e755b5c0 Version: e19233955d9e9a9ae202723b9a38ef38e755b5c0 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/bridge/cadence/cdns-dsi-core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "1014b279264c0fc9f56324608754e36d33b7b5ae",
"status": "affected",
"version": "e19233955d9e9a9ae202723b9a38ef38e755b5c0",
"versionType": "git"
},
{
"lessThan": "c18d46d9830c29677be5213a067daafe1ac80e43",
"status": "affected",
"version": "e19233955d9e9a9ae202723b9a38ef38e755b5c0",
"versionType": "git"
},
{
"lessThan": "347bc3a6a4d968c403d2292e5ad986294d919dfc",
"status": "affected",
"version": "e19233955d9e9a9ae202723b9a38ef38e755b5c0",
"versionType": "git"
},
{
"lessThan": "c0384d6872f4dc2701960048a0be1a12a8d2dc6e",
"status": "affected",
"version": "e19233955d9e9a9ae202723b9a38ef38e755b5c0",
"versionType": "git"
},
{
"lessThan": "1f9c6b74e79639179e90ad0c0fbeae26e31e044b",
"status": "affected",
"version": "e19233955d9e9a9ae202723b9a38ef38e755b5c0",
"versionType": "git"
},
{
"lessThan": "2d8b08844c0ecc6f2002fa68711e779aa18c8585",
"status": "affected",
"version": "e19233955d9e9a9ae202723b9a38ef38e755b5c0",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/bridge/cadence/cdns-dsi-core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.18"
},
{
"lessThan": "4.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.18",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS()\n\nThe deprecated UNIVERSAL_DEV_PM_OPS() macro uses the provided callbacks\nfor both runtime PM and system sleep. This causes the DSI clocks to be\ndisabled twice: once during runtime suspend and again during system\nsuspend, resulting in a WARN message from the clock framework when\nattempting to disable already-disabled clocks.\n\n[ 84.384540] clk:231:5 already disabled\n[ 84.388314] WARNING: CPU: 2 PID: 531 at /drivers/clk/clk.c:1181 clk_core_disable+0xa4/0xac\n...\n[ 84.579183] Call trace:\n[ 84.581624] clk_core_disable+0xa4/0xac\n[ 84.585457] clk_disable+0x30/0x4c\n[ 84.588857] cdns_dsi_suspend+0x20/0x58 [cdns_dsi]\n[ 84.593651] pm_generic_suspend+0x2c/0x44\n[ 84.597661] ti_sci_pd_suspend+0xbc/0x15c\n[ 84.601670] dpm_run_callback+0x8c/0x14c\n[ 84.605588] __device_suspend+0x1a0/0x56c\n[ 84.609594] dpm_suspend+0x17c/0x21c\n[ 84.613165] dpm_suspend_start+0xa0/0xa8\n[ 84.617083] suspend_devices_and_enter+0x12c/0x634\n[ 84.621872] pm_suspend+0x1fc/0x368\n\nTo address this issue, replace UNIVERSAL_DEV_PM_OPS() with\nRUNTIME_PM_OPS(). Bridge and panel drivers should only deal with runtime\nPM, as the DRM framework manages system-wide power transitions through\nthe bridge enable() and disable() hooks."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:17.699Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/1014b279264c0fc9f56324608754e36d33b7b5ae"
},
{
"url": "https://git.kernel.org/stable/c/c18d46d9830c29677be5213a067daafe1ac80e43"
},
{
"url": "https://git.kernel.org/stable/c/347bc3a6a4d968c403d2292e5ad986294d919dfc"
},
{
"url": "https://git.kernel.org/stable/c/c0384d6872f4dc2701960048a0be1a12a8d2dc6e"
},
{
"url": "https://git.kernel.org/stable/c/1f9c6b74e79639179e90ad0c0fbeae26e31e044b"
},
{
"url": "https://git.kernel.org/stable/c/2d8b08844c0ecc6f2002fa68711e779aa18c8585"
}
],
"title": "drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68280",
"datePublished": "2026-08-10T12:02:11.434Z",
"dateReserved": "2026-07-30T09:28:09.379Z",
"dateUpdated": "2026-08-23T12:46:17.699Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68408 (GCVE-0-2026-68408)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-17 05:04
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock
When a netlink socket that owns a PMSR session is closed,
cfg80211_release_pmsr() clears the request's nl_portid and queues
pmsr_free_wk to call cfg80211_pmsr_process_abort() asynchronously.
If the interface tears down concurrently, cfg80211_pmsr_wdev_down()
is called under wiphy_lock and calls cancel_work_sync(&pmsr_free_wk)
to wait for any running work. The work function acquires wiphy_lock
via guard(wiphy) before calling process_abort.
This is a deadlock: wdev_down holds wiphy_lock and blocks inside
cancel_work_sync(); pmsr_free_wk blocks trying to acquire that same
wiphy_lock. Neither thread can proceed.
The same deadlock is reachable from cfg80211_leave_locked(), which
calls cfg80211_pmsr_wdev_down() for all interface types under
wiphy_lock.
Fix this by converting pmsr_free_wk from a plain work_struct to a
wiphy_work. The wiphy_work dispatcher holds wiphy_lock when running
work items, so the explicit guard(wiphy) in the work function is no
longer needed. wiphy_work_cancel() can be called safely while holding
wiphy_lock - since wiphy_lock prevents the work from running
concurrently, wiphy_work_cancel() never blocks, eliminating the
deadlock.
Remove the cancel_work_sync() for pmsr_free_wk from the
NETDEV_GOING_DOWN handler. cfg80211_leave(), called unconditionally
just before it, already cancels any pending work under wiphy_lock
via wiphy_work_cancel() inside cfg80211_pmsr_wdev_down().
References
| URL | Tags | |
|---|---|---|
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d32c07ef1880fe20cf4ab223dbfedc9c0b2816aa Version: a1b7a843f12a0c3e9d3a2ca607ce451916ef42cf Version: 6dccbc9f3e1d38565dff7730d2b7d1e8b16c9b09 Version: 6dccbc9f3e1d38565dff7730d2b7d1e8b16c9b09 Version: 28d3551f8d8cb3aec7497894d94150fe84d20e5e Version: 37e776e2e0a523731e2470dce6d563f0e8632a40 Version: 72b7ea786b8e570ae11149e9089859a4a8634a13 Version: 6.12.78 ≤ Version: 6.18.20 ≤ Version: 6.1.167 ≤ Version: 6.6.130 ≤ Version: 6.19.10 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"include/net/cfg80211.h",
"net/wireless/core.c",
"net/wireless/core.h",
"net/wireless/pmsr.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "21512b5f7a74fd18c996c22e6854efe57d570816",
"status": "affected",
"version": "d32c07ef1880fe20cf4ab223dbfedc9c0b2816aa",
"versionType": "git"
},
{
"lessThan": "133684982dd0c24359fcc641d19d89cc17d6e5ef",
"status": "affected",
"version": "a1b7a843f12a0c3e9d3a2ca607ce451916ef42cf",
"versionType": "git"
},
{
"lessThan": "0a77d9fb4d5c0e01306cd406ffdee8f1fe955c0e",
"status": "affected",
"version": "6dccbc9f3e1d38565dff7730d2b7d1e8b16c9b09",
"versionType": "git"
},
{
"lessThan": "2b0eab425e1f658d8fe1df7590e3b9af5959505e",
"status": "affected",
"version": "6dccbc9f3e1d38565dff7730d2b7d1e8b16c9b09",
"versionType": "git"
},
{
"status": "affected",
"version": "28d3551f8d8cb3aec7497894d94150fe84d20e5e",
"versionType": "git"
},
{
"status": "affected",
"version": "37e776e2e0a523731e2470dce6d563f0e8632a40",
"versionType": "git"
},
{
"status": "affected",
"version": "72b7ea786b8e570ae11149e9089859a4a8634a13",
"versionType": "git"
},
{
"lessThan": "6.12.101",
"status": "affected",
"version": "6.12.78",
"versionType": "semver"
},
{
"lessThan": "6.18.42",
"status": "affected",
"version": "6.18.20",
"versionType": "semver"
},
{
"lessThan": "6.2",
"status": "affected",
"version": "6.1.167",
"versionType": "semver"
},
{
"lessThan": "6.7",
"status": "affected",
"version": "6.6.130",
"versionType": "semver"
},
{
"lessThan": "6.20",
"status": "affected",
"version": "6.19.10",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"include/net/cfg80211.h",
"net/wireless/core.c",
"net/wireless/core.h",
"net/wireless/pmsr.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "7.0"
},
{
"lessThan": "7.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.12.78",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.18.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "7.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "7.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.1.167",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.6.130",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.19.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock\n\nWhen a netlink socket that owns a PMSR session is closed,\ncfg80211_release_pmsr() clears the request\u0027s nl_portid and queues\npmsr_free_wk to call cfg80211_pmsr_process_abort() asynchronously.\n\nIf the interface tears down concurrently, cfg80211_pmsr_wdev_down()\nis called under wiphy_lock and calls cancel_work_sync(\u0026pmsr_free_wk)\nto wait for any running work. The work function acquires wiphy_lock\nvia guard(wiphy) before calling process_abort.\n\nThis is a deadlock: wdev_down holds wiphy_lock and blocks inside\ncancel_work_sync(); pmsr_free_wk blocks trying to acquire that same\nwiphy_lock. Neither thread can proceed.\n\nThe same deadlock is reachable from cfg80211_leave_locked(), which\ncalls cfg80211_pmsr_wdev_down() for all interface types under\nwiphy_lock.\n\nFix this by converting pmsr_free_wk from a plain work_struct to a\nwiphy_work. The wiphy_work dispatcher holds wiphy_lock when running\nwork items, so the explicit guard(wiphy) in the work function is no\nlonger needed. wiphy_work_cancel() can be called safely while holding\nwiphy_lock - since wiphy_lock prevents the work from running\nconcurrently, wiphy_work_cancel() never blocks, eliminating the\ndeadlock.\n\nRemove the cancel_work_sync() for pmsr_free_wk from the\nNETDEV_GOING_DOWN handler. cfg80211_leave(), called unconditionally\njust before it, already cancels any pending work under wiphy_lock\nvia wiphy_work_cancel() inside cfg80211_pmsr_wdev_down()."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:04:58.708Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/21512b5f7a74fd18c996c22e6854efe57d570816"
},
{
"url": "https://git.kernel.org/stable/c/133684982dd0c24359fcc641d19d89cc17d6e5ef"
},
{
"url": "https://git.kernel.org/stable/c/0a77d9fb4d5c0e01306cd406ffdee8f1fe955c0e"
},
{
"url": "https://git.kernel.org/stable/c/2b0eab425e1f658d8fe1df7590e3b9af5959505e"
}
],
"title": "wifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68408",
"datePublished": "2026-08-10T12:04:28.172Z",
"dateReserved": "2026-07-30T09:28:09.390Z",
"dateUpdated": "2026-08-17T05:04:58.708Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72253 (GCVE-0-2026-72253)
Vulnerability from cvelistv5
Published
2026-08-15 05:54
Modified
2026-08-23 12:47
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_conntrack_sip: validate skb_dst() before accessing it
tc ingress and openvswitch do not guarantee routing information to be
available. These subsystems use the conntrack helper infrastructure, and
the SIP helper relies on the skb_dst() to be present if
sip_external_media is set to 1 (which is disabled by default as a module
parameter).
This effectively disables the sip_external_media toggle for these
subsystems without resulting in a crash.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: cae3a2627520c3795b54533c5328b77af3405dbe Version: cae3a2627520c3795b54533c5328b77af3405dbe Version: cae3a2627520c3795b54533c5328b77af3405dbe Version: cae3a2627520c3795b54533c5328b77af3405dbe Version: cae3a2627520c3795b54533c5328b77af3405dbe Version: cae3a2627520c3795b54533c5328b77af3405dbe Version: cae3a2627520c3795b54533c5328b77af3405dbe Version: cae3a2627520c3795b54533c5328b77af3405dbe |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/netfilter/nf_conntrack_sip.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "7866116a040b3a23fb094e7d8f7ea3d61b3ac70b",
"status": "affected",
"version": "cae3a2627520c3795b54533c5328b77af3405dbe",
"versionType": "git"
},
{
"lessThan": "c5ef7228be04518d95591fc5369a9c554b19756d",
"status": "affected",
"version": "cae3a2627520c3795b54533c5328b77af3405dbe",
"versionType": "git"
},
{
"lessThan": "0aec339694a56e263d4b22475ff7211d40900830",
"status": "affected",
"version": "cae3a2627520c3795b54533c5328b77af3405dbe",
"versionType": "git"
},
{
"lessThan": "e64a48c50a1ff565a98c6a98d82b5b942868e76e",
"status": "affected",
"version": "cae3a2627520c3795b54533c5328b77af3405dbe",
"versionType": "git"
},
{
"lessThan": "c199ed687c00841daf60e9d131976958583a8c09",
"status": "affected",
"version": "cae3a2627520c3795b54533c5328b77af3405dbe",
"versionType": "git"
},
{
"lessThan": "09755dc62b026076b1d47f83489eb0547c8135e0",
"status": "affected",
"version": "cae3a2627520c3795b54533c5328b77af3405dbe",
"versionType": "git"
},
{
"lessThan": "b843a96252f672332837ea2ecb7c8db0acf68e20",
"status": "affected",
"version": "cae3a2627520c3795b54533c5328b77af3405dbe",
"versionType": "git"
},
{
"lessThan": "e5e24a365a5e024efef63cc49abb345fbd4852c5",
"status": "affected",
"version": "cae3a2627520c3795b54533c5328b77af3405dbe",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/netfilter/nf_conntrack_sip.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.3"
},
{
"lessThan": "4.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_conntrack_sip: validate skb_dst() before accessing it\n\ntc ingress and openvswitch do not guarantee routing information to be\navailable. These subsystems use the conntrack helper infrastructure, and\nthe SIP helper relies on the skb_dst() to be present if\nsip_external_media is set to 1 (which is disabled by default as a module\nparameter).\n\nThis effectively disables the sip_external_media toggle for these\nsubsystems without resulting in a crash."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - Remote attackers reach set_expected_rtp_rtcp() by sending crafted SIP/SDP (e.g., INVITE) through Open vSwitch or tc ingress ct(helper=sip) on internet-facing VoIP SBC/NFV gateways where packets are conntrack-processed before skb_dst routing metadata is attached.\nAC:L - Once sip_external_media=1, sip_direct_media=0, and the SIP helper are configured on OVS/tc ingress, the attacker fully controls SIP/SDP contents to reach the skb_dst(skb)-\u003edev dereference without races or conditions outside their control.\nPR:N - Exploitation requires no privileges on the victim host; a remote SIP peer only needs to deliver malicious signaling to an already-configured OVS/tc SIP ALG with sip_external_media enabled, with no authentication or local access.\nUI:N - No victim user interaction is required; the kernel SIP helper parses attacker-supplied SIP/SDP during conntrack processing in softirq without any user action beyond normal automated packet handling.\nS:U - A NULL pointer dereference in nf_conntrack_sip causes a kernel oops/panic within the same kernel security domain on the gateway; it does not cross VM, IOMMU, or sandbox boundaries.\nC:N - The failure is a direct NULL pointer dereference from skb_dst(skb) being NULL on tc/OVS ingress paths; there is no use-after-free, out-of-bounds read, or other memory disclosure primitive.\nI:N - Accessing skb_dst(skb)-\u003edev when skb_dst is NULL cannot modify memory or hijack control flow beyond the immediate fault; CVSS guidance assigns None for pure NULL-deref crashes without write capability.\nA:H - The invalid skb_dst dereference in set_expected_rtp_rtcp() during SIP SDP processing causes a kernel oops/panic-class fault, denying availability on the VoIP gateway until reboot; the crash is reliably reproducible with crafted SIP traffic."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:47:08.038Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/7866116a040b3a23fb094e7d8f7ea3d61b3ac70b"
},
{
"url": "https://git.kernel.org/stable/c/c5ef7228be04518d95591fc5369a9c554b19756d"
},
{
"url": "https://git.kernel.org/stable/c/0aec339694a56e263d4b22475ff7211d40900830"
},
{
"url": "https://git.kernel.org/stable/c/e64a48c50a1ff565a98c6a98d82b5b942868e76e"
},
{
"url": "https://git.kernel.org/stable/c/c199ed687c00841daf60e9d131976958583a8c09"
},
{
"url": "https://git.kernel.org/stable/c/09755dc62b026076b1d47f83489eb0547c8135e0"
},
{
"url": "https://git.kernel.org/stable/c/b843a96252f672332837ea2ecb7c8db0acf68e20"
},
{
"url": "https://git.kernel.org/stable/c/e5e24a365a5e024efef63cc49abb345fbd4852c5"
}
],
"title": "netfilter: nf_conntrack_sip: validate skb_dst() before accessing it",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72253",
"datePublished": "2026-08-15T05:54:41.490Z",
"dateReserved": "2026-08-09T03:40:39.915Z",
"dateUpdated": "2026-08-23T12:47:08.038Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68413 (GCVE-0-2026-68413)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-19 16:35
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one()
The memory allocated in the ipw2100_alloc_device() function is not freed
in some of the error paths in ipw2100_pci_init_one(). Fix that by
converting the direct return into a goto to the error path return.
The error path when pci_enable_device() fails cannot jump to fail, since
at this point priv is not set, so perform error handling inline.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 2c86c275015c880e810830304a3a4ab94803b38b Version: 2c86c275015c880e810830304a3a4ab94803b38b Version: 2c86c275015c880e810830304a3a4ab94803b38b Version: 2c86c275015c880e810830304a3a4ab94803b38b Version: 2c86c275015c880e810830304a3a4ab94803b38b Version: 2c86c275015c880e810830304a3a4ab94803b38b Version: 2c86c275015c880e810830304a3a4ab94803b38b Version: 2c86c275015c880e810830304a3a4ab94803b38b |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/intel/ipw2x00/ipw2100.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "71614326ab43e8b8f392ba865aeb6d7e327dff7d",
"status": "affected",
"version": "2c86c275015c880e810830304a3a4ab94803b38b",
"versionType": "git"
},
{
"lessThan": "9b080198a22fd809c4e7f6793eafab53ac2643fd",
"status": "affected",
"version": "2c86c275015c880e810830304a3a4ab94803b38b",
"versionType": "git"
},
{
"lessThan": "768a701362a8f77b62c14f8202ad559b7ecbb0c6",
"status": "affected",
"version": "2c86c275015c880e810830304a3a4ab94803b38b",
"versionType": "git"
},
{
"lessThan": "f75b9a2a9d8334ae0f9c5e47df7b31f7aeb1fdbe",
"status": "affected",
"version": "2c86c275015c880e810830304a3a4ab94803b38b",
"versionType": "git"
},
{
"lessThan": "836a19c654dcb1b01878a70090af016fbd0fd7e5",
"status": "affected",
"version": "2c86c275015c880e810830304a3a4ab94803b38b",
"versionType": "git"
},
{
"lessThan": "f442e581a88937671a22ceb3806c186265ef6254",
"status": "affected",
"version": "2c86c275015c880e810830304a3a4ab94803b38b",
"versionType": "git"
},
{
"lessThan": "7cbda50eebcd9aa00b0de382f776287cf7a36cf8",
"status": "affected",
"version": "2c86c275015c880e810830304a3a4ab94803b38b",
"versionType": "git"
},
{
"lessThan": "0d388f62031dbabcba0f44bb91b59f10e88cac17",
"status": "affected",
"version": "2c86c275015c880e810830304a3a4ab94803b38b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/intel/ipw2x00/ipw2100.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.14"
},
{
"lessThan": "2.6.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one()\n\nThe memory allocated in the ipw2100_alloc_device() function is not freed\nin some of the error paths in ipw2100_pci_init_one(). Fix that by\nconverting the direct return into a goto to the error path return.\n\nThe error path when pci_enable_device() fails cannot jump to fail, since\nat this point priv is not set, so perform error handling inline."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:35:10.167Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/71614326ab43e8b8f392ba865aeb6d7e327dff7d"
},
{
"url": "https://git.kernel.org/stable/c/9b080198a22fd809c4e7f6793eafab53ac2643fd"
},
{
"url": "https://git.kernel.org/stable/c/768a701362a8f77b62c14f8202ad559b7ecbb0c6"
},
{
"url": "https://git.kernel.org/stable/c/f75b9a2a9d8334ae0f9c5e47df7b31f7aeb1fdbe"
},
{
"url": "https://git.kernel.org/stable/c/836a19c654dcb1b01878a70090af016fbd0fd7e5"
},
{
"url": "https://git.kernel.org/stable/c/f442e581a88937671a22ceb3806c186265ef6254"
},
{
"url": "https://git.kernel.org/stable/c/7cbda50eebcd9aa00b0de382f776287cf7a36cf8"
},
{
"url": "https://git.kernel.org/stable/c/0d388f62031dbabcba0f44bb91b59f10e88cac17"
}
],
"title": "wifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68413",
"datePublished": "2026-08-10T12:04:33.525Z",
"dateReserved": "2026-07-30T09:28:09.391Z",
"dateUpdated": "2026-08-19T16:35:10.167Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68236 (GCVE-0-2026-68236)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-17 05:01
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: set new_stream to NULL after release
In dm_update_crtc_state(), the skip_modeset path releases new_stream
via dc_stream_release() but does not set the pointer to NULL.
If a later error (e.g., color management failure) triggers the fail
label, the error path calls dc_stream_release() again on the same
dangling pointer, causing a double release and potential use-after-free.
Fix this by setting new_stream to NULL after the initial release.
(cherry picked from commit 99f3af19073b3ddbfd96e789124cce12c4277b28)
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ba8bf1dcbb44773e7a0fd13b42925c644e0d5e76",
"status": "affected",
"version": "9b690ef3c70422cdcd0cf912db33f2c92ef4a53f",
"versionType": "git"
},
{
"lessThan": "5182e442e61397d446c36995b8f5676942d35b82",
"status": "affected",
"version": "9b690ef3c70422cdcd0cf912db33f2c92ef4a53f",
"versionType": "git"
},
{
"lessThan": "679f23f0a3606afcef1ffabd72222f00a54ad9e3",
"status": "affected",
"version": "9b690ef3c70422cdcd0cf912db33f2c92ef4a53f",
"versionType": "git"
},
{
"lessThan": "0676fecbb5242aa22c057e78326d6d6041db034c",
"status": "affected",
"version": "9b690ef3c70422cdcd0cf912db33f2c92ef4a53f",
"versionType": "git"
},
{
"lessThan": "9fa26b9eed6195bf840f39ac183b9a6237548755",
"status": "affected",
"version": "9b690ef3c70422cdcd0cf912db33f2c92ef4a53f",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.15"
},
{
"lessThan": "4.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: set new_stream to NULL after release\n\nIn dm_update_crtc_state(), the skip_modeset path releases new_stream\nvia dc_stream_release() but does not set the pointer to NULL.\n\nIf a later error (e.g., color management failure) triggers the fail\nlabel, the error path calls dc_stream_release() again on the same\ndangling pointer, causing a double release and potential use-after-free.\n\nFix this by setting new_stream to NULL after the initial release.\n\n(cherry picked from commit 99f3af19073b3ddbfd96e789124cce12c4277b28)"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached through the DRM atomic modeset ioctl (DRM_IOCTL_MODE_ATOMIC) on a local /dev/dri/card* node of an AMD GPU; there is no network or remote input path into dm_update_crtc_state().\nAC:L - A single atomic commit that requests a mode change while attaching a wrong-sized DEGAMMA_LUT blob deterministically drives amdgpu_dm_check_crtc_color_mgmt() to -EINVAL and hits the double dc_stream_release(); no race and no uncontrolled precondition, and TEST_ONLY commits let the attacker repeat it freely to groom the heap.\nPR:L - The atomic ioctl is gated only by DRM master on the card node, which any unprivileged local user on a graphical seat or an unused VT can hold; no CAP_SYS_ADMIN or root is needed.\nUI:N - The attacker performs the whole sequence with its own ioctl calls; no action by another user or administrator is required, and TEST_ONLY commits do not even disturb the display.\nS:U - The corrupted dc_stream_state and the resulting freed-memory reuse stay within the kernel\u0027s own security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - The extra kref_put() frees the dc_stream_state while the CRTC state and the DC context still reference it; reading through those dangling pointers after the slab is reallocated leaks adjacent kernel object contents and pointers, and the attacker can spray to control what lands there.\nI:H - The reference-count underflow yields a use-after-free/double-free: subsequent kref_put() writes into reallocated slab memory and dc_stream_free() kfree()s an attacker-influenced update_scratch pointer, giving write and arbitrary-free primitives usable for privilege escalation.\nA:H - Even without exploitation the premature free causes dereference of freed stream/sink/link structures during atomic state unwind, producing a kernel oops or panic and killing the display pipeline; it can be triggered repeatedly."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:01:25.183Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ba8bf1dcbb44773e7a0fd13b42925c644e0d5e76"
},
{
"url": "https://git.kernel.org/stable/c/5182e442e61397d446c36995b8f5676942d35b82"
},
{
"url": "https://git.kernel.org/stable/c/679f23f0a3606afcef1ffabd72222f00a54ad9e3"
},
{
"url": "https://git.kernel.org/stable/c/0676fecbb5242aa22c057e78326d6d6041db034c"
},
{
"url": "https://git.kernel.org/stable/c/9fa26b9eed6195bf840f39ac183b9a6237548755"
}
],
"title": "drm/amd/display: set new_stream to NULL after release",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68236",
"datePublished": "2026-08-10T12:01:01.114Z",
"dateReserved": "2026-07-30T09:28:09.376Z",
"dateUpdated": "2026-08-17T05:01:25.183Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
Loading…
Loading…
Sightings
| Author | Source | Type | Date |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…