Action not permitted
Modal body text goes here.
Modal Title
Modal Body
CERTFR-2026-AVI-1163
Vulnerability from certfr_avis
De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges, une atteinte à la confidentialité des données et un déni de service.
Solutions
Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).
Impacted products
References
| Title | Publication Time | Tags | |||
|---|---|---|---|---|---|
|
|||||
{
"$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
"affected_systems": [
{
"description": "Debian LTS 12 bookworm versions ant\u00e9rieures \u00e0 6.1.187-1",
"product": {
"name": "Debian",
"vendor": {
"name": "Debian",
"scada": false
}
}
}
],
"affected_systems_content": "",
"content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
"cves": [
{
"name": "CVE-2026-80547",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80547"
},
{
"name": "CVE-2026-74632",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74632"
},
{
"name": "CVE-2026-74649",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74649"
},
{
"name": "CVE-2026-72157",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72157"
},
{
"name": "CVE-2026-72392",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72392"
},
{
"name": "CVE-2026-72252",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72252"
},
{
"name": "CVE-2025-40064",
"url": "https://www.cve.org/CVERecord?id=CVE-2025-40064"
},
{
"name": "CVE-2026-68147",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68147"
},
{
"name": "CVE-2026-64590",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64590"
},
{
"name": "CVE-2026-68343",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68343"
},
{
"name": "CVE-2026-64270",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64270"
},
{
"name": "CVE-2026-74441",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74441"
},
{
"name": "CVE-2026-68450",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68450"
},
{
"name": "CVE-2026-68480",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68480"
},
{
"name": "CVE-2026-80716",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80716"
},
{
"name": "CVE-2026-64561",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64561"
},
{
"name": "CVE-2026-72051",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72051"
},
{
"name": "CVE-2026-80846",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80846"
},
{
"name": "CVE-2026-74450",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74450"
},
{
"name": "CVE-2026-80744",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80744"
},
{
"name": "CVE-2026-74481",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74481"
},
{
"name": "CVE-2026-68138",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68138"
},
{
"name": "CVE-2026-64192",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64192"
},
{
"name": "CVE-2026-74597",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74597"
},
{
"name": "CVE-2026-68388",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68388"
},
{
"name": "CVE-2026-68204",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68204"
},
{
"name": "CVE-2026-74669",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74669"
},
{
"name": "CVE-2026-68302",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68302"
},
{
"name": "CVE-2026-68141",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68141"
},
{
"name": "CVE-2026-74482",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74482"
},
{
"name": "CVE-2024-58094",
"url": "https://www.cve.org/CVERecord?id=CVE-2024-58094"
},
{
"name": "CVE-2026-80803",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80803"
},
{
"name": "CVE-2026-80808",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80808"
},
{
"name": "CVE-2026-74598",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74598"
},
{
"name": "CVE-2026-64542",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64542"
},
{
"name": "CVE-2026-53090",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-53090"
},
{
"name": "CVE-2026-72216",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72216"
},
{
"name": "CVE-2026-74540",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74540"
},
{
"name": "CVE-2026-74737",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74737"
},
{
"name": "CVE-2026-80718",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80718"
},
{
"name": "CVE-2026-68218",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68218"
},
{
"name": "CVE-2026-68129",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68129"
},
{
"name": "CVE-2026-80715",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80715"
},
{
"name": "CVE-2026-80733",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80733"
},
{
"name": "CVE-2026-80891",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80891"
},
{
"name": "CVE-2026-68428",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68428"
},
{
"name": "CVE-2026-80793",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80793"
},
{
"name": "CVE-2026-74569",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74569"
},
{
"name": "CVE-2026-74581",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74581"
},
{
"name": "CVE-2026-74696",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74696"
},
{
"name": "CVE-2026-74697",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74697"
},
{
"name": "CVE-2026-68313",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68313"
},
{
"name": "CVE-2026-80829",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80829"
},
{
"name": "CVE-2026-68326",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68326"
},
{
"name": "CVE-2026-68184",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68184"
},
{
"name": "CVE-2026-80848",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80848"
},
{
"name": "CVE-2026-74746",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74746"
},
{
"name": "CVE-2026-72125",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72125"
},
{
"name": "CVE-2026-68417",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68417"
},
{
"name": "CVE-2026-74612",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74612"
},
{
"name": "CVE-2026-68338",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68338"
},
{
"name": "CVE-2026-80754",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80754"
},
{
"name": "CVE-2026-74563",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74563"
},
{
"name": "CVE-2026-74457",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74457"
},
{
"name": "CVE-2026-68248",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68248"
},
{
"name": "CVE-2026-74505",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74505"
},
{
"name": "CVE-2026-68165",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68165"
},
{
"name": "CVE-2026-74523",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74523"
},
{
"name": "CVE-2026-68277",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68277"
},
{
"name": "CVE-2026-74626",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74626"
},
{
"name": "CVE-2026-74453",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74453"
},
{
"name": "CVE-2026-46170",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-46170"
},
{
"name": "CVE-2026-80843",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80843"
},
{
"name": "CVE-2026-74693",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74693"
},
{
"name": "CVE-2026-72015",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72015"
},
{
"name": "CVE-2026-74557",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74557"
},
{
"name": "CVE-2026-68410",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68410"
},
{
"name": "CVE-2026-74607",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74607"
},
{
"name": "CVE-2026-80552",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80552"
},
{
"name": "CVE-2026-74461",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74461"
},
{
"name": "CVE-2026-80678",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80678"
},
{
"name": "CVE-2026-74514",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74514"
},
{
"name": "CVE-2026-68164",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68164"
},
{
"name": "CVE-2026-80909",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80909"
},
{
"name": "CVE-2026-68304",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68304"
},
{
"name": "CVE-2026-68155",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68155"
},
{
"name": "CVE-2026-80726",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80726"
},
{
"name": "CVE-2026-68132",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68132"
},
{
"name": "CVE-2026-68294",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68294"
},
{
"name": "CVE-2026-80765",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80765"
},
{
"name": "CVE-2026-74465",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74465"
},
{
"name": "CVE-2025-39925",
"url": "https://www.cve.org/CVERecord?id=CVE-2025-39925"
},
{
"name": "CVE-2026-74630",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74630"
},
{
"name": "CVE-2026-74682",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74682"
},
{
"name": "CVE-2025-40139",
"url": "https://www.cve.org/CVERecord?id=CVE-2025-40139"
},
{
"name": "CVE-2026-74488",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74488"
},
{
"name": "CVE-2025-68794",
"url": "https://www.cve.org/CVERecord?id=CVE-2025-68794"
},
{
"name": "CVE-2026-68446",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68446"
},
{
"name": "CVE-2026-68226",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68226"
},
{
"name": "CVE-2023-53706",
"url": "https://www.cve.org/CVERecord?id=CVE-2023-53706"
},
{
"name": "CVE-2026-68350",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68350"
},
{
"name": "CVE-2026-64082",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64082"
},
{
"name": "CVE-2026-80830",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80830"
},
{
"name": "CVE-2026-80562",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80562"
},
{
"name": "CVE-2026-74683",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74683"
},
{
"name": "CVE-2026-80752",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80752"
},
{
"name": "CVE-2026-68297",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68297"
},
{
"name": "CVE-2026-68199",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68199"
},
{
"name": "CVE-2026-68425",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68425"
},
{
"name": "CVE-2026-80852",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80852"
},
{
"name": "CVE-2026-80707",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80707"
},
{
"name": "CVE-2025-40054",
"url": "https://www.cve.org/CVERecord?id=CVE-2025-40054"
},
{
"name": "CVE-2026-74444",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74444"
},
{
"name": "CVE-2026-74724",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74724"
},
{
"name": "CVE-2026-80795",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80795"
},
{
"name": "CVE-2024-46754",
"url": "https://www.cve.org/CVERecord?id=CVE-2024-46754"
},
{
"name": "CVE-2026-74657",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74657"
},
{
"name": "CVE-2026-80534",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80534"
},
{
"name": "CVE-2026-80548",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80548"
},
{
"name": "CVE-2026-80794",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80794"
},
{
"name": "CVE-2026-74676",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74676"
},
{
"name": "CVE-2025-38203",
"url": "https://www.cve.org/CVERecord?id=CVE-2025-38203"
},
{
"name": "CVE-2026-68365",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68365"
},
{
"name": "CVE-2026-74460",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74460"
},
{
"name": "CVE-2026-74586",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74586"
},
{
"name": "CVE-2026-68320",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68320"
},
{
"name": "CVE-2026-68176",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68176"
},
{
"name": "CVE-2026-68280",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68280"
},
{
"name": "CVE-2026-68362",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68362"
},
{
"name": "CVE-2026-68430",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68430"
},
{
"name": "CVE-2026-68427",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68427"
},
{
"name": "CVE-2026-46158",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-46158"
},
{
"name": "CVE-2026-68324",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68324"
},
{
"name": "CVE-2026-74688",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74688"
},
{
"name": "CVE-2026-80828",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80828"
},
{
"name": "CVE-2026-80788",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80788"
},
{
"name": "CVE-2026-74726",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74726"
},
{
"name": "CVE-2026-64508",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64508"
},
{
"name": "CVE-2026-74549",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74549"
},
{
"name": "CVE-2026-72260",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72260"
},
{
"name": "CVE-2026-72170",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72170"
},
{
"name": "CVE-2026-68210",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68210"
},
{
"name": "CVE-2026-80731",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80731"
},
{
"name": "CVE-2026-80561",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80561"
},
{
"name": "CVE-2026-74470",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74470"
},
{
"name": "CVE-2026-68309",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68309"
},
{
"name": "CVE-2026-68096",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68096"
},
{
"name": "CVE-2026-68403",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68403"
},
{
"name": "CVE-2026-74478",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74478"
},
{
"name": "CVE-2026-74566",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74566"
},
{
"name": "CVE-2026-80714",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80714"
},
{
"name": "CVE-2026-68093",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68093"
},
{
"name": "CVE-2026-72262",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72262"
},
{
"name": "CVE-2026-80901",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80901"
},
{
"name": "CVE-2026-64584",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64584"
},
{
"name": "CVE-2026-74748",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74748"
},
{
"name": "CVE-2026-72299",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72299"
},
{
"name": "CVE-2026-74473",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74473"
},
{
"name": "CVE-2026-68310",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68310"
},
{
"name": "CVE-2026-80574",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80574"
},
{
"name": "CVE-2026-64272",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64272"
},
{
"name": "CVE-2026-68115",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68115"
},
{
"name": "CVE-2026-80824",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80824"
},
{
"name": "CVE-2026-68246",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68246"
},
{
"name": "CVE-2026-64563",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64563"
},
{
"name": "CVE-2026-68476",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68476"
},
{
"name": "CVE-2026-74467",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74467"
},
{
"name": "CVE-2026-68405",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68405"
},
{
"name": "CVE-2026-68216",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68216"
},
{
"name": "CVE-2026-72237",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72237"
},
{
"name": "CVE-2026-80856",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80856"
},
{
"name": "CVE-2026-64580",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64580"
},
{
"name": "CVE-2026-74476",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74476"
},
{
"name": "CVE-2026-68328",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68328"
},
{
"name": "CVE-2026-74691",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74691"
},
{
"name": "CVE-2026-74490",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74490"
},
{
"name": "CVE-2026-68196",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68196"
},
{
"name": "CVE-2026-64280",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64280"
},
{
"name": "CVE-2026-80589",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80589"
},
{
"name": "CVE-2026-68269",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68269"
},
{
"name": "CVE-2026-68255",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68255"
},
{
"name": "CVE-2026-74730",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74730"
},
{
"name": "CVE-2026-68169",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68169"
},
{
"name": "CVE-2026-72017",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72017"
},
{
"name": "CVE-2026-80767",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80767"
},
{
"name": "CVE-2026-68363",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68363"
},
{
"name": "CVE-2026-74580",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74580"
},
{
"name": "CVE-2026-68213",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68213"
},
{
"name": "CVE-2026-68278",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68278"
},
{
"name": "CVE-2026-72236",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72236"
},
{
"name": "CVE-2026-74660",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74660"
},
{
"name": "CVE-2026-80783",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80783"
},
{
"name": "CVE-2026-74454",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74454"
},
{
"name": "CVE-2026-72012",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72012"
},
{
"name": "CVE-2026-80541",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80541"
},
{
"name": "CVE-2026-72113",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72113"
},
{
"name": "CVE-2026-74493",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74493"
},
{
"name": "CVE-2026-74463",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74463"
},
{
"name": "CVE-2026-74583",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74583"
},
{
"name": "CVE-2026-68361",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68361"
},
{
"name": "CVE-2026-68181",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68181"
},
{
"name": "CVE-2026-74464",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74464"
},
{
"name": "CVE-2026-74636",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74636"
},
{
"name": "CVE-2026-74522",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74522"
},
{
"name": "CVE-2026-74704",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74704"
},
{
"name": "CVE-2026-74689",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74689"
},
{
"name": "CVE-2026-68160",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68160"
},
{
"name": "CVE-2024-58095",
"url": "https://www.cve.org/CVERecord?id=CVE-2024-58095"
},
{
"name": "CVE-2026-68100",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68100"
},
{
"name": "CVE-2026-80888",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80888"
},
{
"name": "CVE-2026-68157",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68157"
},
{
"name": "CVE-2026-74662",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74662"
},
{
"name": "CVE-2026-74622",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74622"
},
{
"name": "CVE-2026-80766",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80766"
},
{
"name": "CVE-2026-68368",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68368"
},
{
"name": "CVE-2026-68335",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68335"
},
{
"name": "CVE-2026-80819",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80819"
},
{
"name": "CVE-2026-68189",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68189"
},
{
"name": "CVE-2026-80680",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80680"
},
{
"name": "CVE-2026-68212",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68212"
},
{
"name": "CVE-2026-80784",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80784"
},
{
"name": "CVE-2026-80893",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80893"
},
{
"name": "CVE-2026-74604",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74604"
},
{
"name": "CVE-2026-72057",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72057"
},
{
"name": "CVE-2026-80792",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80792"
},
{
"name": "CVE-2026-80763",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80763"
},
{
"name": "CVE-2026-80722",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80722"
},
{
"name": "CVE-2026-80906",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80906"
},
{
"name": "CVE-2026-74555",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74555"
},
{
"name": "CVE-2026-74623",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74623"
},
{
"name": "CVE-2026-74456",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74456"
},
{
"name": "CVE-2026-80806",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80806"
},
{
"name": "CVE-2026-68215",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68215"
},
{
"name": "CVE-2026-74552",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74552"
},
{
"name": "CVE-2026-72096",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72096"
},
{
"name": "CVE-2026-74714",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74714"
},
{
"name": "CVE-2026-68099",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68099"
},
{
"name": "CVE-2026-74664",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74664"
},
{
"name": "CVE-2026-68369",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68369"
},
{
"name": "CVE-2026-74620",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74620"
},
{
"name": "CVE-2026-80559",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80559"
},
{
"name": "CVE-2026-72172",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72172"
},
{
"name": "CVE-2026-80706",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80706"
},
{
"name": "CVE-2026-80908",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80908"
},
{
"name": "CVE-2026-72253",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72253"
},
{
"name": "CVE-2026-74739",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74739"
},
{
"name": "CVE-2026-74499",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74499"
},
{
"name": "CVE-2026-68340",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68340"
},
{
"name": "CVE-2026-68352",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68352"
},
{
"name": "CVE-2026-68106",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68106"
},
{
"name": "CVE-2026-80831",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80831"
},
{
"name": "CVE-2026-43491",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-43491"
},
{
"name": "CVE-2026-74675",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74675"
},
{
"name": "CVE-2026-68197",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68197"
},
{
"name": "CVE-2026-45963",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-45963"
},
{
"name": "CVE-2026-74701",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74701"
},
{
"name": "CVE-2026-72040",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72040"
},
{
"name": "CVE-2026-80892",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80892"
},
{
"name": "CVE-2026-68315",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68315"
},
{
"name": "CVE-2026-68377",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68377"
},
{
"name": "CVE-2025-40206",
"url": "https://www.cve.org/CVERecord?id=CVE-2025-40206"
},
{
"name": "CVE-2026-72114",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72114"
},
{
"name": "CVE-2026-53361",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-53361"
},
{
"name": "CVE-2026-74637",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74637"
},
{
"name": "CVE-2026-68175",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68175"
},
{
"name": "CVE-2026-68413",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68413"
},
{
"name": "CVE-2026-68357",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68357"
},
{
"name": "CVE-2026-68376",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68376"
},
{
"name": "CVE-2026-80567",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80567"
},
{
"name": "CVE-2026-64583",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64583"
},
{
"name": "CVE-2026-80807",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80807"
},
{
"name": "CVE-2026-80529",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80529"
},
{
"name": "CVE-2026-68194",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68194"
},
{
"name": "CVE-2026-74589",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74589"
},
{
"name": "CVE-2026-74479",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74479"
},
{
"name": "CVE-2025-38616",
"url": "https://www.cve.org/CVERecord?id=CVE-2025-38616"
},
{
"name": "CVE-2026-80762",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80762"
},
{
"name": "CVE-2026-68127",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68127"
},
{
"name": "CVE-2026-74492",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74492"
},
{
"name": "CVE-2026-80798",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80798"
},
{
"name": "CVE-2026-74641",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74641"
},
{
"name": "CVE-2026-72142",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72142"
},
{
"name": "CVE-2026-80789",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80789"
},
{
"name": "CVE-2026-80797",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80797"
},
{
"name": "CVE-2026-68159",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68159"
},
{
"name": "CVE-2026-74694",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74694"
},
{
"name": "CVE-2026-80569",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80569"
},
{
"name": "CVE-2026-72062",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72062"
},
{
"name": "CVE-2026-68367",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68367"
},
{
"name": "CVE-2026-68146",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68146"
},
{
"name": "CVE-2026-80586",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80586"
},
{
"name": "CVE-2026-68202",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68202"
},
{
"name": "CVE-2026-74614",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74614"
},
{
"name": "CVE-2026-80679",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80679"
},
{
"name": "CVE-2026-68104",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68104"
},
{
"name": "CVE-2026-72323",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72323"
},
{
"name": "CVE-2026-72065",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72065"
},
{
"name": "CVE-2026-68137",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68137"
},
{
"name": "CVE-2026-80584",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80584"
},
{
"name": "CVE-2026-68143",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68143"
},
{
"name": "CVE-2025-38237",
"url": "https://www.cve.org/CVERecord?id=CVE-2025-38237"
},
{
"name": "CVE-2026-74608",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74608"
},
{
"name": "CVE-2026-68349",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68349"
},
{
"name": "CVE-2026-80550",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80550"
},
{
"name": "CVE-2026-74459",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74459"
},
{
"name": "CVE-2026-74471",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74471"
},
{
"name": "CVE-2026-74553",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74553"
},
{
"name": "CVE-2026-74671",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74671"
},
{
"name": "CVE-2026-80772",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80772"
},
{
"name": "CVE-2026-72070",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72070"
},
{
"name": "CVE-2026-68351",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68351"
},
{
"name": "CVE-2026-74515",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74515"
},
{
"name": "CVE-2026-68301",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68301"
},
{
"name": "CVE-2026-68402",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68402"
},
{
"name": "CVE-2023-54141",
"url": "https://www.cve.org/CVERecord?id=CVE-2023-54141"
},
{
"name": "CVE-2025-38206",
"url": "https://www.cve.org/CVERecord?id=CVE-2025-38206"
},
{
"name": "CVE-2025-22104",
"url": "https://www.cve.org/CVERecord?id=CVE-2025-22104"
},
{
"name": "CVE-2026-68117",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68117"
},
{
"name": "CVE-2026-68333",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68333"
},
{
"name": "CVE-2026-68386",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68386"
},
{
"name": "CVE-2023-54263",
"url": "https://www.cve.org/CVERecord?id=CVE-2023-54263"
},
{
"name": "CVE-2025-39901",
"url": "https://www.cve.org/CVERecord?id=CVE-2025-39901"
},
{
"name": "CVE-2026-68111",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68111"
},
{
"name": "CVE-2026-64577",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64577"
},
{
"name": "CVE-2026-80840",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80840"
},
{
"name": "CVE-2026-64586",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64586"
},
{
"name": "CVE-2026-72308",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72308"
},
{
"name": "CVE-2026-80809",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80809"
},
{
"name": "CVE-2026-68142",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68142"
},
{
"name": "CVE-2026-68243",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68243"
},
{
"name": "CVE-2026-74609",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74609"
},
{
"name": "CVE-2026-74487",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74487"
},
{
"name": "CVE-2026-46266",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-46266"
},
{
"name": "CVE-2026-74744",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74744"
},
{
"name": "CVE-2026-68209",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68209"
},
{
"name": "CVE-2026-68207",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68207"
},
{
"name": "CVE-2026-46111",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-46111"
},
{
"name": "CVE-2026-80863",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80863"
},
{
"name": "CVE-2026-80527",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80527"
},
{
"name": "CVE-2026-74668",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74668"
},
{
"name": "CVE-2026-72041",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72041"
},
{
"name": "CVE-2026-74498",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74498"
},
{
"name": "CVE-2026-74615",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74615"
},
{
"name": "CVE-2026-68373",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68373"
},
{
"name": "CVE-2026-72077",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72077"
},
{
"name": "CVE-2026-80549",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80549"
},
{
"name": "CVE-2026-74625",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74625"
},
{
"name": "CVE-2026-80708",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80708"
},
{
"name": "CVE-2026-74446",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74446"
},
{
"name": "CVE-2026-68206",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68206"
},
{
"name": "CVE-2026-74577",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74577"
},
{
"name": "CVE-2026-74516",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74516"
},
{
"name": "CVE-2026-72117",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72117"
},
{
"name": "CVE-2026-64581",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64581"
},
{
"name": "CVE-2025-40168",
"url": "https://www.cve.org/CVERecord?id=CVE-2025-40168"
},
{
"name": "CVE-2026-80791",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80791"
},
{
"name": "CVE-2026-68227",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68227"
},
{
"name": "CVE-2026-80801",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80801"
},
{
"name": "CVE-2026-68331",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68331"
},
{
"name": "CVE-2026-74567",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74567"
},
{
"name": "CVE-2026-80796",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80796"
},
{
"name": "CVE-2025-38117",
"url": "https://www.cve.org/CVERecord?id=CVE-2025-38117"
},
{
"name": "CVE-2026-80781",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80781"
},
{
"name": "CVE-2026-64139",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64139"
},
{
"name": "CVE-2026-80539",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80539"
},
{
"name": "CVE-2026-80572",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80572"
},
{
"name": "CVE-2026-74582",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74582"
},
{
"name": "CVE-2026-80890",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80890"
},
{
"name": "CVE-2026-80757",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80757"
},
{
"name": "CVE-2026-72030",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72030"
},
{
"name": "CVE-2026-68432",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68432"
},
{
"name": "CVE-2026-74519",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74519"
},
{
"name": "CVE-2026-74548",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74548"
},
{
"name": "CVE-2026-68186",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68186"
},
{
"name": "CVE-2026-80800",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80800"
},
{
"name": "CVE-2026-68148",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68148"
},
{
"name": "CVE-2026-74518",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74518"
},
{
"name": "CVE-2026-68344",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68344"
},
{
"name": "CVE-2026-72242",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72242"
},
{
"name": "CVE-2026-80590",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80590"
},
{
"name": "CVE-2026-80826",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80826"
},
{
"name": "CVE-2026-64578",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64578"
},
{
"name": "CVE-2026-80732",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80732"
},
{
"name": "CVE-2026-68398",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68398"
},
{
"name": "CVE-2026-68322",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68322"
},
{
"name": "CVE-2026-80832",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80832"
},
{
"name": "CVE-2026-74603",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74603"
},
{
"name": "CVE-2026-68136",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68136"
},
{
"name": "CVE-2026-74587",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74587"
},
{
"name": "CVE-2026-72099",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72099"
},
{
"name": "CVE-2026-80842",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80842"
},
{
"name": "CVE-2026-74663",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74663"
},
{
"name": "CVE-2026-68395",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68395"
},
{
"name": "CVE-2026-74472",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74472"
},
{
"name": "CVE-2026-68144",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68144"
},
{
"name": "CVE-2026-68299",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68299"
},
{
"name": "CVE-2026-68082",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68082"
},
{
"name": "CVE-2026-68366",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68366"
},
{
"name": "CVE-2026-74494",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74494"
},
{
"name": "CVE-2026-74508",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74508"
},
{
"name": "CVE-2026-68156",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68156"
},
{
"name": "CVE-2026-68187",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68187"
},
{
"name": "CVE-2026-74672",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74672"
},
{
"name": "CVE-2026-74469",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74469"
},
{
"name": "CVE-2026-74679",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74679"
},
{
"name": "CVE-2026-68121",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68121"
},
{
"name": "CVE-2026-80570",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80570"
},
{
"name": "CVE-2026-68231",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68231"
},
{
"name": "CVE-2026-68182",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68182"
},
{
"name": "CVE-2026-72063",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72063"
},
{
"name": "CVE-2026-68451",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68451"
},
{
"name": "CVE-2026-74717",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74717"
},
{
"name": "CVE-2026-80768",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80768"
},
{
"name": "CVE-2026-68422",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68422"
},
{
"name": "CVE-2026-68327",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68327"
},
{
"name": "CVE-2026-80684",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80684"
},
{
"name": "CVE-2026-64582",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64582"
},
{
"name": "CVE-2026-80553",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80553"
},
{
"name": "CVE-2026-68433",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68433"
},
{
"name": "CVE-2026-68190",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68190"
},
{
"name": "CVE-2026-31419",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-31419"
},
{
"name": "CVE-2026-68195",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68195"
},
{
"name": "CVE-2026-80910",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80910"
},
{
"name": "CVE-2026-74654",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74654"
},
{
"name": "CVE-2026-80560",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80560"
},
{
"name": "CVE-2026-80823",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80823"
},
{
"name": "CVE-2026-74658",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74658"
},
{
"name": "CVE-2026-68279",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68279"
},
{
"name": "CVE-2026-80558",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80558"
},
{
"name": "CVE-2026-68234",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68234"
},
{
"name": "CVE-2026-80802",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80802"
},
{
"name": "CVE-2026-74546",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74546"
},
{
"name": "CVE-2026-74680",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74680"
},
{
"name": "CVE-2026-74497",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74497"
},
{
"name": "CVE-2026-74510",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74510"
},
{
"name": "CVE-2026-68140",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68140"
},
{
"name": "CVE-2026-74455",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74455"
},
{
"name": "CVE-2026-74512",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74512"
},
{
"name": "CVE-2026-64434",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64434"
},
{
"name": "CVE-2026-80573",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80573"
},
{
"name": "CVE-2026-80904",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80904"
},
{
"name": "CVE-2026-64562",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64562"
},
{
"name": "CVE-2026-72023",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72023"
},
{
"name": "CVE-2026-68434",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68434"
},
{
"name": "CVE-2026-68444",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68444"
},
{
"name": "CVE-2026-72035",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72035"
},
{
"name": "CVE-2026-74588",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74588"
},
{
"name": "CVE-2026-68153",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68153"
},
{
"name": "CVE-2026-64571",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64571"
},
{
"name": "CVE-2026-53089",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-53089"
},
{
"name": "CVE-2026-68188",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68188"
},
{
"name": "CVE-2026-80814",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80814"
},
{
"name": "CVE-2026-80742",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80742"
},
{
"name": "CVE-2026-68259",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68259"
},
{
"name": "CVE-2026-68223",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68223"
},
{
"name": "CVE-2026-72116",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72116"
},
{
"name": "CVE-2026-74556",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74556"
},
{
"name": "CVE-2025-40102",
"url": "https://www.cve.org/CVERecord?id=CVE-2025-40102"
},
{
"name": "CVE-2026-68414",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68414"
},
{
"name": "CVE-2026-74595",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74595"
},
{
"name": "CVE-2026-68411",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68411"
},
{
"name": "CVE-2026-68131",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68131"
},
{
"name": "CVE-2026-68214",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68214"
},
{
"name": "CVE-2026-68217",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68217"
},
{
"name": "CVE-2026-68452",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68452"
},
{
"name": "CVE-2026-68222",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68222"
},
{
"name": "CVE-2026-74692",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74692"
},
{
"name": "CVE-2026-72045",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72045"
},
{
"name": "CVE-2026-68124",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68124"
},
{
"name": "CVE-2026-80790",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80790"
},
{
"name": "CVE-2026-72305",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72305"
},
{
"name": "CVE-2026-68250",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68250"
},
{
"name": "CVE-2026-68371",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68371"
},
{
"name": "CVE-2025-40307",
"url": "https://www.cve.org/CVERecord?id=CVE-2025-40307"
},
{
"name": "CVE-2026-80686",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80686"
},
{
"name": "CVE-2026-74719",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74719"
},
{
"name": "CVE-2026-80583",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80583"
},
{
"name": "CVE-2026-68397",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68397"
},
{
"name": "CVE-2026-64572",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64572"
},
{
"name": "CVE-2026-80805",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80805"
},
{
"name": "CVE-2026-80557",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80557"
},
{
"name": "CVE-2026-74585",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74585"
},
{
"name": "CVE-2026-74651",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74651"
},
{
"name": "CVE-2026-74551",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74551"
},
{
"name": "CVE-2026-74666",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74666"
},
{
"name": "CVE-2026-80770",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80770"
},
{
"name": "CVE-2026-74705",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74705"
},
{
"name": "CVE-2026-68431",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68431"
},
{
"name": "CVE-2026-80854",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80854"
},
{
"name": "CVE-2026-74495",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74495"
},
{
"name": "CVE-2026-80827",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80827"
},
{
"name": "CVE-2026-68125",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68125"
},
{
"name": "CVE-2026-68135",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68135"
},
{
"name": "CVE-2026-72121",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72121"
},
{
"name": "CVE-2026-68254",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68254"
},
{
"name": "CVE-2026-68360",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68360"
},
{
"name": "CVE-2026-80844",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80844"
},
{
"name": "CVE-2026-74720",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74720"
},
{
"name": "CVE-2026-68244",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68244"
},
{
"name": "CVE-2026-64579",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64579"
},
{
"name": "CVE-2026-74547",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74547"
},
{
"name": "CVE-2026-68249",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68249"
},
{
"name": "CVE-2026-72146",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72146"
},
{
"name": "CVE-2026-74579",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74579"
},
{
"name": "CVE-2026-68300",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68300"
},
{
"name": "CVE-2026-23394",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-23394"
},
{
"name": "CVE-2026-68229",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68229"
},
{
"name": "CVE-2026-68284",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68284"
},
{
"name": "CVE-2026-80756",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80756"
},
{
"name": "CVE-2026-74458",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74458"
},
{
"name": "CVE-2026-74647",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74647"
},
{
"name": "CVE-2026-74613",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74613"
},
{
"name": "CVE-2026-68353",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68353"
},
{
"name": "CVE-2026-74743",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74743"
},
{
"name": "CVE-2026-80913",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80913"
},
{
"name": "CVE-2026-74525",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74525"
},
{
"name": "CVE-2026-72110",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72110"
},
{
"name": "CVE-2026-68108",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68108"
},
{
"name": "CVE-2026-74594",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74594"
},
{
"name": "CVE-2026-74475",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74475"
},
{
"name": "CVE-2026-80717",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80717"
},
{
"name": "CVE-2026-64565",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64565"
},
{
"name": "CVE-2026-68158",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68158"
},
{
"name": "CVE-2026-64543",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64543"
},
{
"name": "CVE-2026-64573",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64573"
},
{
"name": "CVE-2026-74659",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74659"
},
{
"name": "CVE-2026-68325",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68325"
},
{
"name": "CVE-2026-68253",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68253"
},
{
"name": "CVE-2026-74621",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74621"
},
{
"name": "CVE-2026-74507",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74507"
},
{
"name": "CVE-2026-68355",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68355"
},
{
"name": "CVE-2026-80764",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80764"
},
{
"name": "CVE-2026-80568",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80568"
},
{
"name": "CVE-2026-64294",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64294"
},
{
"name": "CVE-2026-80855",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80855"
},
{
"name": "CVE-2026-74628",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74628"
},
{
"name": "CVE-2026-80528",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80528"
},
{
"name": "CVE-2026-74667",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74667"
},
{
"name": "CVE-2026-74601",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74601"
},
{
"name": "CVE-2026-74436",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74436"
},
{
"name": "CVE-2026-74673",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74673"
},
{
"name": "CVE-2026-68180",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68180"
},
{
"name": "CVE-2026-80709",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80709"
},
{
"name": "CVE-2026-80681",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80681"
},
{
"name": "CVE-2026-80725",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80725"
},
{
"name": "CVE-2026-74722",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74722"
},
{
"name": "CVE-2026-68198",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68198"
},
{
"name": "CVE-2024-38620",
"url": "https://www.cve.org/CVERecord?id=CVE-2024-38620"
},
{
"name": "CVE-2026-68407",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68407"
},
{
"name": "CVE-2026-74635",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74635"
},
{
"name": "CVE-2026-68123",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68123"
},
{
"name": "CVE-2026-74624",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74624"
},
{
"name": "CVE-2026-68162",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68162"
},
{
"name": "CVE-2026-80555",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80555"
},
{
"name": "CVE-2026-80782",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80782"
},
{
"name": "CVE-2026-74678",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74678"
},
{
"name": "CVE-2026-68354",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68354"
},
{
"name": "CVE-2026-80743",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80743"
},
{
"name": "CVE-2026-74575",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74575"
},
{
"name": "CVE-2026-74480",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74480"
},
{
"name": "CVE-2026-64507",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64507"
},
{
"name": "CVE-2026-80730",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80730"
},
{
"name": "CVE-2026-68183",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68183"
},
{
"name": "CVE-2025-39833",
"url": "https://www.cve.org/CVERecord?id=CVE-2025-39833"
},
{
"name": "CVE-2026-74468",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74468"
},
{
"name": "CVE-2026-74631",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74631"
},
{
"name": "CVE-2026-68251",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68251"
},
{
"name": "CVE-2026-68151",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68151"
},
{
"name": "CVE-2026-80565",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80565"
},
{
"name": "CVE-2026-72069",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72069"
},
{
"name": "CVE-2026-68359",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68359"
},
{
"name": "CVE-2026-80737",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80737"
},
{
"name": "CVE-2026-68370",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68370"
},
{
"name": "CVE-2026-64567",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64567"
},
{
"name": "CVE-2026-74485",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74485"
},
{
"name": "CVE-2026-80536",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80536"
},
{
"name": "CVE-2026-72191",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72191"
},
{
"name": "CVE-2026-74564",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74564"
},
{
"name": "CVE-2026-80540",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80540"
},
{
"name": "CVE-2026-64576",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64576"
},
{
"name": "CVE-2026-68192",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68192"
},
{
"name": "CVE-2026-74616",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74616"
},
{
"name": "CVE-2026-74550",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74550"
},
{
"name": "CVE-2026-80902",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80902"
},
{
"name": "CVE-2026-80812",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80812"
},
{
"name": "CVE-2026-74509",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74509"
},
{
"name": "CVE-2026-72124",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72124"
},
{
"name": "CVE-2026-74656",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74656"
},
{
"name": "CVE-2026-64564",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64564"
},
{
"name": "CVE-2026-74648",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74648"
},
{
"name": "CVE-2026-74650",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74650"
},
{
"name": "CVE-2026-74443",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-74443"
},
{
"name": "CVE-2026-72119",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72119"
},
{
"name": "CVE-2026-68406",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68406"
},
{
"name": "CVE-2026-72115",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72115"
},
{
"name": "CVE-2026-68130",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68130"
},
{
"name": "CVE-2026-72118",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72118"
},
{
"name": "CVE-2026-68336",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68336"
},
{
"name": "CVE-2026-64569",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-64569"
},
{
"name": "CVE-2026-68154",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-68154"
},
{
"name": "CVE-2026-80799",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-80799"
}
],
"initial_release_date": "2026-09-11T00:00:00",
"last_revision_date": "2026-09-11T00:00:00",
"links": [],
"reference": "CERTFR-2026-AVI-1163",
"revisions": [
{
"description": "Version initiale",
"revision_date": "2026-09-11T00:00:00.000000"
}
],
"risks": [
{
"description": "Non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur"
},
{
"description": "D\u00e9ni de service"
},
{
"description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
},
{
"description": "\u00c9l\u00e9vation de privil\u00e8ges"
}
],
"summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans le noyau Linux de Debian LTS. Certaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer une \u00e9l\u00e9vation de privil\u00e8ges, une atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es et un d\u00e9ni de service.",
"title": "Multiples vuln\u00e9rabilit\u00e9s dans le noyau Linux de Debian LTS",
"vendor_advisories": [
{
"published_at": "2026-09-08",
"title": "Bulletin de s\u00e9curit\u00e9 Debian LTS msg00012",
"url": "https://lists.debian.org/debian-lts-announce/2026/09/msg00012.html"
}
]
}
CVE-2026-68254 (GCVE-0-2026-68254)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/i915/vrr: require valid min/max vfreq for VRR
Ensure the EDID provided min/max vfreq are valid. Most scenarios are
already covered (by coincidence) through the checks in
intel_vrr_is_capable() and intel_vrr_is_in_range(), but be more explicit
about it. At worst, a zero min_vfreq could lead to a division by zero in
intel_vrr_compute_vmax().
Discovered using AI-assisted static analysis confirmed by Intel Product
Security.
(cherry picked from commit 1765cf59f517b02f3b0591fe5120930d08bddeb6)
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 117cd09ba52857a60dc5d7f61941046625d8ff5a Version: 117cd09ba52857a60dc5d7f61941046625d8ff5a Version: 117cd09ba52857a60dc5d7f61941046625d8ff5a Version: 117cd09ba52857a60dc5d7f61941046625d8ff5a Version: 117cd09ba52857a60dc5d7f61941046625d8ff5a Version: 117cd09ba52857a60dc5d7f61941046625d8ff5a Version: 117cd09ba52857a60dc5d7f61941046625d8ff5a |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/i915/display/intel_vrr.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "2f9aa8d42b7fc17621894456433ac07689fb4a21",
"status": "affected",
"version": "117cd09ba52857a60dc5d7f61941046625d8ff5a",
"versionType": "git"
},
{
"lessThan": "5225122b9cad6b0c61e767fb2adea8c07da925be",
"status": "affected",
"version": "117cd09ba52857a60dc5d7f61941046625d8ff5a",
"versionType": "git"
},
{
"lessThan": "6598ac1721c3a5543efdbcab579a8561268d7ce1",
"status": "affected",
"version": "117cd09ba52857a60dc5d7f61941046625d8ff5a",
"versionType": "git"
},
{
"lessThan": "f16218689b41efcbc491207cd7716477b1223879",
"status": "affected",
"version": "117cd09ba52857a60dc5d7f61941046625d8ff5a",
"versionType": "git"
},
{
"lessThan": "df1582c0a101e2e2f133dd331d2a3258bb6a7518",
"status": "affected",
"version": "117cd09ba52857a60dc5d7f61941046625d8ff5a",
"versionType": "git"
},
{
"lessThan": "c726c8bbee5115dad37fa7867136ebaa50690331",
"status": "affected",
"version": "117cd09ba52857a60dc5d7f61941046625d8ff5a",
"versionType": "git"
},
{
"lessThan": "f8a9262c7a6fc2de9802e14b0228114f0333869e",
"status": "affected",
"version": "117cd09ba52857a60dc5d7f61941046625d8ff5a",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/i915/display/intel_vrr.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.12"
},
{
"lessThan": "5.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/i915/vrr: require valid min/max vfreq for VRR\n\nEnsure the EDID provided min/max vfreq are valid. Most scenarios are\nalready covered (by coincidence) through the checks in\nintel_vrr_is_capable() and intel_vrr_is_in_range(), but be more explicit\nabout it. At worst, a zero min_vfreq could lead to a division by zero in\nintel_vrr_compute_vmax().\n\nDiscovered using AI-assisted static analysis confirmed by Intel Product\nSecurity.\n\n(cherry picked from commit 1765cf59f517b02f3b0591fe5120930d08bddeb6)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:12.167Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/2f9aa8d42b7fc17621894456433ac07689fb4a21"
},
{
"url": "https://git.kernel.org/stable/c/5225122b9cad6b0c61e767fb2adea8c07da925be"
},
{
"url": "https://git.kernel.org/stable/c/6598ac1721c3a5543efdbcab579a8561268d7ce1"
},
{
"url": "https://git.kernel.org/stable/c/f16218689b41efcbc491207cd7716477b1223879"
},
{
"url": "https://git.kernel.org/stable/c/df1582c0a101e2e2f133dd331d2a3258bb6a7518"
},
{
"url": "https://git.kernel.org/stable/c/c726c8bbee5115dad37fa7867136ebaa50690331"
},
{
"url": "https://git.kernel.org/stable/c/f8a9262c7a6fc2de9802e14b0228114f0333869e"
}
],
"title": "drm/i915/vrr: require valid min/max vfreq for VRR",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68254",
"datePublished": "2026-08-10T12:01:20.400Z",
"dateReserved": "2026-07-30T09:28:09.377Z",
"dateUpdated": "2026-08-23T12:46:12.167Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74613 (GCVE-0-2026-74613)
Vulnerability from cvelistv5
Published
2026-08-22 15:31
Modified
2026-08-25 05:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
vsock/virtio: avoid refilling the RX queue after teardown
Commit b917507e5ad9 ("vsock/virtio: stop workers during the .remove()")
made the RX worker jump to its common exit when rx_run is clear. That
exit still refills the RX queue when the buffer count is low, so work
queued across virtio_vsock_vqs_del() can add buffers after the virtqueues
have been deleted.
BUG: KASAN: slab-use-after-free in virtqueue_add_sgs
Read of size 4 by task kworker/0:1
Workqueue: virtio_vsock virtio_transport_rx_work
Call Trace:
virtqueue_add_sgs (drivers/virtio/virtio_ring.c:2796)
virtio_vsock_rx_fill (net/vmw_vsock/virtio_transport.c:332)
virtio_transport_rx_work (net/vmw_vsock/virtio_transport.c:701)
process_one_work (kernel/workqueue.c:3314)
worker_thread (kernel/workqueue.c:3478)
kthread (kernel/kthread.c:436)
ret_from_fork (arch/x86/kernel/process.c:158)
ret_from_fork_asm (arch/x86/entry/entry_64.S:245)
...
Freed by task 141:
kfree (mm/slub.c:6566)
vp_del_vq (drivers/virtio/virtio_pci_common.c:259)
vp_del_vqs (drivers/virtio/virtio_pci_common.c:285)
virtio_vsock_freeze (net/vmw_vsock/virtio_transport.c:912)
virtio_device_freeze (drivers/virtio/virtio.c:658)
virtio_pci_freeze (drivers/virtio/virtio_pci_common.c:601)
pci_pm_freeze (drivers/pci/pci-driver.c:1098)
device_suspend (drivers/base/power/main.c:1968)
Kernel panic - not syncing: KASAN: panic_on_warn set ...
Jump to a no-refill exit when rx_run is clear, leaving the normal exit
to replenish a running queue.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: b917507e5ad983085d29069369778b16aa03a0a8 Version: b917507e5ad983085d29069369778b16aa03a0a8 Version: b917507e5ad983085d29069369778b16aa03a0a8 Version: b917507e5ad983085d29069369778b16aa03a0a8 Version: b917507e5ad983085d29069369778b16aa03a0a8 Version: b917507e5ad983085d29069369778b16aa03a0a8 Version: b917507e5ad983085d29069369778b16aa03a0a8 Version: b917507e5ad983085d29069369778b16aa03a0a8 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/vmw_vsock/virtio_transport.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a7658508f5fe8f1077a65e8cb9535d3426f37a2f",
"status": "affected",
"version": "b917507e5ad983085d29069369778b16aa03a0a8",
"versionType": "git"
},
{
"lessThan": "1aa21e7c8702a7c37cd7d3cace1a652cfa5e8171",
"status": "affected",
"version": "b917507e5ad983085d29069369778b16aa03a0a8",
"versionType": "git"
},
{
"lessThan": "4d37e3525cc346a1421c1bdeaad5848e249fc60c",
"status": "affected",
"version": "b917507e5ad983085d29069369778b16aa03a0a8",
"versionType": "git"
},
{
"lessThan": "9d80a04129a6c27a690cb69de3fe3f50be5aa8b9",
"status": "affected",
"version": "b917507e5ad983085d29069369778b16aa03a0a8",
"versionType": "git"
},
{
"lessThan": "a309b74e3fc052352ab778500449cb9c3853c363",
"status": "affected",
"version": "b917507e5ad983085d29069369778b16aa03a0a8",
"versionType": "git"
},
{
"lessThan": "38c7763fdc533edb34dc8f4489c260e8ba2ccae9",
"status": "affected",
"version": "b917507e5ad983085d29069369778b16aa03a0a8",
"versionType": "git"
},
{
"lessThan": "e82a5faea2e3886dfb2a65ce092a132e7e896915",
"status": "affected",
"version": "b917507e5ad983085d29069369778b16aa03a0a8",
"versionType": "git"
},
{
"lessThan": "a31e0ad444698d8aa7534a0f89fda543730f97a5",
"status": "affected",
"version": "b917507e5ad983085d29069369778b16aa03a0a8",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/vmw_vsock/virtio_transport.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.3"
},
{
"lessThan": "5.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nvsock/virtio: avoid refilling the RX queue after teardown\n\nCommit b917507e5ad9 (\"vsock/virtio: stop workers during the .remove()\")\nmade the RX worker jump to its common exit when rx_run is clear. That\nexit still refills the RX queue when the buffer count is low, so work\nqueued across virtio_vsock_vqs_del() can add buffers after the virtqueues\nhave been deleted.\n\nBUG: KASAN: slab-use-after-free in virtqueue_add_sgs\nRead of size 4 by task kworker/0:1\nWorkqueue: virtio_vsock virtio_transport_rx_work\nCall Trace:\n virtqueue_add_sgs (drivers/virtio/virtio_ring.c:2796)\n virtio_vsock_rx_fill (net/vmw_vsock/virtio_transport.c:332)\n virtio_transport_rx_work (net/vmw_vsock/virtio_transport.c:701)\n process_one_work (kernel/workqueue.c:3314)\n worker_thread (kernel/workqueue.c:3478)\n kthread (kernel/kthread.c:436)\n ret_from_fork (arch/x86/kernel/process.c:158)\n ret_from_fork_asm (arch/x86/entry/entry_64.S:245)\n...\nFreed by task 141:\n kfree (mm/slub.c:6566)\n vp_del_vq (drivers/virtio/virtio_pci_common.c:259)\n vp_del_vqs (drivers/virtio/virtio_pci_common.c:285)\n virtio_vsock_freeze (net/vmw_vsock/virtio_transport.c:912)\n virtio_device_freeze (drivers/virtio/virtio.c:658)\n virtio_pci_freeze (drivers/virtio/virtio_pci_common.c:601)\n pci_pm_freeze (drivers/pci/pci-driver.c:1098)\n device_suspend (drivers/base/power/main.c:1968)\nKernel panic - not syncing: KASAN: panic_on_warn set ...\n\nJump to a no-refill exit when rx_run is clear, leaving the normal exit\nto replenish a running queue."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is in the virtio-vsock guest driver reached via AF_VSOCK sockets and virtio virtqueue callbacks, not via remote network packets; kernel guidance classifies vsock as Local attack vector.\nAC:L - An attacker can reliably queue virtio_transport_rx_work by maintaining active vsock traffic while virtqueues are torn down; this slab UAF race is attacker-influenced and does not depend on uncontrollable memory layout.\nPR:L - Triggering the vulnerable RX refill path requires only normal unprivileged AF_VSOCK use to drive virtio RX work; teardown can coincide with host-driven suspend, migration, or device removal without guest root.\nUI:N - Exploitation requires no victim interaction beyond the attacker opening and using vsock sockets to generate virtio RX work during device teardown.\nS:U - The use-after-free corrupts guest-kernel virtio state and can panic the guest kernel; it does not directly cross a VM/host security boundary or enable guest-to-host escape.\nC:H - KASAN reports a slab use-after-free read in virtqueue_add_sgs on freed virtqueue metadata; UAF of kernel heap objects can be leveraged for arbitrary kernel memory disclosure.\nI:H - Use-after-free of virtqueue structures during virtio_vsock_rx_fill enables heap corruption and can be developed into arbitrary kernel writes or control-flow hijack, not merely a benign read.\nA:H - The reported reproducer triggers KASAN slab-use-after-free and kernel panic during virtio_vsock freeze/teardown; UAF in kernel workqueue context causes high availability impact."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:40:39.724Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a7658508f5fe8f1077a65e8cb9535d3426f37a2f"
},
{
"url": "https://git.kernel.org/stable/c/1aa21e7c8702a7c37cd7d3cace1a652cfa5e8171"
},
{
"url": "https://git.kernel.org/stable/c/4d37e3525cc346a1421c1bdeaad5848e249fc60c"
},
{
"url": "https://git.kernel.org/stable/c/9d80a04129a6c27a690cb69de3fe3f50be5aa8b9"
},
{
"url": "https://git.kernel.org/stable/c/a309b74e3fc052352ab778500449cb9c3853c363"
},
{
"url": "https://git.kernel.org/stable/c/38c7763fdc533edb34dc8f4489c260e8ba2ccae9"
},
{
"url": "https://git.kernel.org/stable/c/e82a5faea2e3886dfb2a65ce092a132e7e896915"
},
{
"url": "https://git.kernel.org/stable/c/a31e0ad444698d8aa7534a0f89fda543730f97a5"
}
],
"title": "vsock/virtio: avoid refilling the RX queue after teardown",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74613",
"datePublished": "2026-08-22T15:31:59.062Z",
"dateReserved": "2026-08-15T05:44:03.920Z",
"dateUpdated": "2026-08-25T05:40:39.724Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74744 (GCVE-0-2026-74744)
Vulnerability from cvelistv5
Published
2026-08-26 14:36
Modified
2026-08-27 05:01
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ipvlan: inherit needed_headroom and needed_tailroom from phy_dev
ipvlan devices inherit hard_header_len from phy_dev during ipvlan_init(),
but leave needed_headroom and needed_tailroom set to 0.
When the underlying phy_dev (or stacked lower device) requires extra headroom
or tailroom for headers/trailers (e.g. macsec, ipsec, wireguard, tunnels, or
veth with rx headroom), upper layers calculating packet headroom and tailroom
fail to reserve sufficient space.
This can result in reallocation overhead, skb headroom underflows, or KASAN
slab-use-after-free crashes when dev_hard_header() / ipvlan_hard_header()
prepends header data or when lower devices append tailroom.
Fix this by:
1. Inheriting needed_headroom and needed_tailroom from phy_dev in ipvlan_init().
2. Propagating needed_headroom and needed_tailroom updates to attached ipvlans
in ipvlan_device_event() when receiving NETDEV_FEAT_CHANGE events.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 2ad7bf3638411cb547f2823df08166c13ab04269 Version: 2ad7bf3638411cb547f2823df08166c13ab04269 Version: 2ad7bf3638411cb547f2823df08166c13ab04269 Version: 2ad7bf3638411cb547f2823df08166c13ab04269 Version: 2ad7bf3638411cb547f2823df08166c13ab04269 Version: 2ad7bf3638411cb547f2823df08166c13ab04269 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ipvlan/ipvlan_main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "af602c4d0ee548da18e2409b4b4da1079625a372",
"status": "affected",
"version": "2ad7bf3638411cb547f2823df08166c13ab04269",
"versionType": "git"
},
{
"lessThan": "f3c17ff65f54781cde696e16a6c577615ed735aa",
"status": "affected",
"version": "2ad7bf3638411cb547f2823df08166c13ab04269",
"versionType": "git"
},
{
"lessThan": "c0fbe31f6b20ade0465130685859faa5c86fda59",
"status": "affected",
"version": "2ad7bf3638411cb547f2823df08166c13ab04269",
"versionType": "git"
},
{
"lessThan": "5f33188457bbcc1b11ca87084037963c516ed3d9",
"status": "affected",
"version": "2ad7bf3638411cb547f2823df08166c13ab04269",
"versionType": "git"
},
{
"lessThan": "5c2ca77212eb38559b0353b8363b7a84f4b019dd",
"status": "affected",
"version": "2ad7bf3638411cb547f2823df08166c13ab04269",
"versionType": "git"
},
{
"lessThan": "e16e960d55a40d36bd7c2494cc005e757dc9a1ef",
"status": "affected",
"version": "2ad7bf3638411cb547f2823df08166c13ab04269",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ipvlan/ipvlan_main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.19"
},
{
"lessThan": "3.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.46",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.10",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nipvlan: inherit needed_headroom and needed_tailroom from phy_dev\n\nipvlan devices inherit hard_header_len from phy_dev during ipvlan_init(),\nbut leave needed_headroom and needed_tailroom set to 0.\n\nWhen the underlying phy_dev (or stacked lower device) requires extra headroom\nor tailroom for headers/trailers (e.g. macsec, ipsec, wireguard, tunnels, or\nveth with rx headroom), upper layers calculating packet headroom and tailroom\nfail to reserve sufficient space.\n\nThis can result in reallocation overhead, skb headroom underflows, or KASAN\nslab-use-after-free crashes when dev_hard_header() / ipvlan_hard_header()\nprepends header data or when lower devices append tailroom.\n\nFix this by:\n1. Inheriting needed_headroom and needed_tailroom from phy_dev in ipvlan_init().\n2. Propagating needed_headroom and needed_tailroom updates to attached ipvlans\n in ipvlan_device_event() when receiving NETDEV_FEAT_CHANGE events."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - On hosts where admins deployed ipvlan over phy_dev with non-zero headroom (WireGuard/IPsec/macsec/tunnels/veth-XDP), remote packets that trigger egress through the ipvlan netdev (TCP/UDP/ICMP responses, forwarded traffic) reach ipvlan_hard_header/dev_hard_header without local syscalls.\nAC:L - Once the stacked netdev exists, the attacker controls packet sizes and connection patterns to deterministically undersize skb headroom/tailroom; syzbot reproduced KASAN slab-UAF without races or uncontrollable memory layout.\nPR:N - Remote exploitation on pre-deployed ipvlan-over-encrypted/tunneled container or VPN hosts requires no credentials\u2014only network reachability to services using that netdev; CAP_NET_ADMIN is only needed for the alternate local user-namespace setup path.\nUI:N - No victim interaction is required; the attacker either sends crafted network traffic to trigger kernel TX through ipvlan or self-configures the netdev stack via rtnetlink inside a user namespace.\nS:U - Impact is kernel slab skb/net_device memory corruption and local privilege escalation within the same kernel security authority, not a VM escape, IOMMU bypass, or other cross-boundary scope change.\nC:H - Insufficient LL_RESERVED_SPACE causes pskb_expand_head to free still-referenced skb data and dev_hard_header skb_push to access memory outside the buffer; the fix cites KASAN slab-use-after-free, enabling arbitrary kernel memory disclosure.\nI:H - Slab UAF and skb headroom underflow during header prepend give heap-grooming and controlled overwrite primitives on attacker-influenced TX paths, suitable for kernel control-flow hijacking and code execution.\nA:H - Undersized headroom triggers skb_under_panic BUG and KASAN-reported slab-use-after-free oops/panic from softirq/TX paths; remote or local attackers can retrigger repeatedly for reliable kernel denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T05:01:05.284Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/af602c4d0ee548da18e2409b4b4da1079625a372"
},
{
"url": "https://git.kernel.org/stable/c/f3c17ff65f54781cde696e16a6c577615ed735aa"
},
{
"url": "https://git.kernel.org/stable/c/c0fbe31f6b20ade0465130685859faa5c86fda59"
},
{
"url": "https://git.kernel.org/stable/c/5f33188457bbcc1b11ca87084037963c516ed3d9"
},
{
"url": "https://git.kernel.org/stable/c/5c2ca77212eb38559b0353b8363b7a84f4b019dd"
},
{
"url": "https://git.kernel.org/stable/c/e16e960d55a40d36bd7c2494cc005e757dc9a1ef"
}
],
"title": "ipvlan: inherit needed_headroom and needed_tailroom from phy_dev",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74744",
"datePublished": "2026-08-26T14:36:54.773Z",
"dateReserved": "2026-08-15T05:44:03.931Z",
"dateUpdated": "2026-08-27T05:01:05.284Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80686 (GCVE-0-2026-80686)
Vulnerability from cvelistv5
Published
2026-08-28 06:52
Modified
2026-08-28 06:52
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
mm: migrate_device: fix pte_pfn/pte_dirty called on non-present PTE
pte_pfn() and pte_dirty() have undefined behaviour when called on a
non-present PTE. In migrate_vma_collect_pmd(), these functions may be
invoked on non-present entries (e.g., device-private entries), leading
to potential crashes from pte_pfn() or incorrect dirty folio accounting
from pte_dirty(). Fix both by guarding with pte_present() checks.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 6c287605fd56466e645693eff3ae7c08fba56e0a Version: 6c287605fd56466e645693eff3ae7c08fba56e0a Version: 6c287605fd56466e645693eff3ae7c08fba56e0a Version: 6c287605fd56466e645693eff3ae7c08fba56e0a Version: 6c287605fd56466e645693eff3ae7c08fba56e0a Version: 6c287605fd56466e645693eff3ae7c08fba56e0a |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"mm/migrate_device.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "26f9ca8ed42cba25d2c75daff13561cce6019395",
"status": "affected",
"version": "6c287605fd56466e645693eff3ae7c08fba56e0a",
"versionType": "git"
},
{
"lessThan": "5b948706f11a950bc73c5304630d0a7eafc40daf",
"status": "affected",
"version": "6c287605fd56466e645693eff3ae7c08fba56e0a",
"versionType": "git"
},
{
"lessThan": "86d55447de3738620b9a8272ff167ce97e7f7203",
"status": "affected",
"version": "6c287605fd56466e645693eff3ae7c08fba56e0a",
"versionType": "git"
},
{
"lessThan": "2be94d6b20789b8865b1864dae5fe458ca85e019",
"status": "affected",
"version": "6c287605fd56466e645693eff3ae7c08fba56e0a",
"versionType": "git"
},
{
"lessThan": "42f30fa5481a1f90571ccdfbb20d2e25e47ae76e",
"status": "affected",
"version": "6c287605fd56466e645693eff3ae7c08fba56e0a",
"versionType": "git"
},
{
"lessThan": "63867c82d0c0c2d182016a32b1cc0103116b0ea5",
"status": "affected",
"version": "6c287605fd56466e645693eff3ae7c08fba56e0a",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"mm/migrate_device.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.19"
},
{
"lessThan": "5.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm: migrate_device: fix pte_pfn/pte_dirty called on non-present PTE\n\npte_pfn() and pte_dirty() have undefined behaviour when called on a\nnon-present PTE. In migrate_vma_collect_pmd(), these functions may be\ninvoked on non-present entries (e.g., device-private entries), leading\nto potential crashes from pte_pfn() or incorrect dirty folio accounting\nfrom pte_dirty(). Fix both by guarding with pte_present() checks."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-28T06:52:51.924Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/26f9ca8ed42cba25d2c75daff13561cce6019395"
},
{
"url": "https://git.kernel.org/stable/c/5b948706f11a950bc73c5304630d0a7eafc40daf"
},
{
"url": "https://git.kernel.org/stable/c/86d55447de3738620b9a8272ff167ce97e7f7203"
},
{
"url": "https://git.kernel.org/stable/c/2be94d6b20789b8865b1864dae5fe458ca85e019"
},
{
"url": "https://git.kernel.org/stable/c/42f30fa5481a1f90571ccdfbb20d2e25e47ae76e"
},
{
"url": "https://git.kernel.org/stable/c/63867c82d0c0c2d182016a32b1cc0103116b0ea5"
}
],
"title": "mm: migrate_device: fix pte_pfn/pte_dirty called on non-present PTE",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80686",
"datePublished": "2026-08-28T06:52:51.924Z",
"dateReserved": "2026-08-26T14:34:25.784Z",
"dateUpdated": "2026-08-28T06:52:51.924Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74555 (GCVE-0-2026-74555)
Vulnerability from cvelistv5
Published
2026-08-15 12:28
Modified
2026-08-19 16:38
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
scsi: libsas: Fix HA resume deadlock and hisi_sas disk-wake race
Commit fbefe22811c3 ("scsi: libsas: Don't always drain event workqueue
for HA resume") introduced sas_resume_ha_no_sync() to avoid a deadlock:
the PHYE_RESUME_TIMEOUT handler, running on the HA event workqueue,
calls sas_deform_port() -> sas_destruct_devices(), which removes SCSI
devices and waits for the host to become runtime-active. But the host
cannot resume until sas_resume_ha() -> sas_drain_work() returns, and the
drain is blocked on that very handler.
However skipping the drain reintroduces a race: hisi_sas returns from
resume before all PHY UP work and libsas discovery work finish. The
controller may then autosuspend while disks are still waking up. The
disks issue IO to a suspended controller, the IO fails, and the disks
get disabled.
Fix the deadlock at its source by moving the PHYE_RESUME_TIMEOUT
notification to after sas_drain_work(). By then the host resume is about
to complete, so device removal through device_link no longer blocks on
the resume and the cycle is broken.
With the deadlock gone, restore sas_resume_ha() (the draining variant)
in hisi_sas and remove sas_resume_ha_no_sync().
The reorder is safe for the other libsas consumers (isci, pm8001,
aic94xx, mvsas). During suspend, sas_suspend_devices() calls
sas_notify_lldd_dev_gone() for each device, which sets dev->lldd_dev to
NULL. When scsi_unblock_requests re-enables I/O in resume, any I/O to a
timed-out phy's disk is immediately rejected by the LLDD before reaching
hardware: isci returns SAS_DEVICE_UNKNOWN (mapped to DID_BAD_TARGET),
and pm8001 returns SAS_PHY_DOWN (mapped to DID_NO_CONNECT). Both
complete directly via scsi_done() without entering SCSI EH. This is
identical in both the old and new ordering since lldd_dev_gone runs
during suspend, before resume. The reorder only affects when the
PHYE_RESUME_TIMEOUT handler runs (synchronized by sas_drain_work()
vs. asynchronous after resume returns), not whether I/O can reach the
device. aic94xx and mvsas do not register any PM ops and never reach
this code path.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: fbefe22811c3140a686e407e114789ebf328a9a2 Version: fbefe22811c3140a686e407e114789ebf328a9a2 Version: fbefe22811c3140a686e407e114789ebf328a9a2 Version: fbefe22811c3140a686e407e114789ebf328a9a2 Version: fbefe22811c3140a686e407e114789ebf328a9a2 Version: fbefe22811c3140a686e407e114789ebf328a9a2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/scsi/hisi_sas/hisi_sas_v3_hw.c",
"drivers/scsi/libsas/sas_init.c",
"include/scsi/libsas.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "09357f067122e2e28ec52e27013a1660a1571618",
"status": "affected",
"version": "fbefe22811c3140a686e407e114789ebf328a9a2",
"versionType": "git"
},
{
"lessThan": "e50a6523a603594a6d92cdecfe11997d639410a3",
"status": "affected",
"version": "fbefe22811c3140a686e407e114789ebf328a9a2",
"versionType": "git"
},
{
"lessThan": "c391b5899dd46485a5893696c12ae3e95a3a7325",
"status": "affected",
"version": "fbefe22811c3140a686e407e114789ebf328a9a2",
"versionType": "git"
},
{
"lessThan": "9e24b47ef81d43b3fb1b14294f09991640c79fcc",
"status": "affected",
"version": "fbefe22811c3140a686e407e114789ebf328a9a2",
"versionType": "git"
},
{
"lessThan": "b9c44a14062093e9fc2d6bddc696cfceadb482d7",
"status": "affected",
"version": "fbefe22811c3140a686e407e114789ebf328a9a2",
"versionType": "git"
},
{
"lessThan": "3dbbbf656b850c9c8de05df6ad4a1dfc6ff02845",
"status": "affected",
"version": "fbefe22811c3140a686e407e114789ebf328a9a2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/scsi/hisi_sas/hisi_sas_v3_hw.c",
"drivers/scsi/libsas/sas_init.c",
"include/scsi/libsas.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.17"
},
{
"lessThan": "5.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.17",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: libsas: Fix HA resume deadlock and hisi_sas disk-wake race\n\nCommit fbefe22811c3 (\"scsi: libsas: Don\u0027t always drain event workqueue\nfor HA resume\") introduced sas_resume_ha_no_sync() to avoid a deadlock:\nthe PHYE_RESUME_TIMEOUT handler, running on the HA event workqueue,\ncalls sas_deform_port() -\u003e sas_destruct_devices(), which removes SCSI\ndevices and waits for the host to become runtime-active. But the host\ncannot resume until sas_resume_ha() -\u003e sas_drain_work() returns, and the\ndrain is blocked on that very handler.\n\nHowever skipping the drain reintroduces a race: hisi_sas returns from\nresume before all PHY UP work and libsas discovery work finish. The\ncontroller may then autosuspend while disks are still waking up. The\ndisks issue IO to a suspended controller, the IO fails, and the disks\nget disabled.\n\nFix the deadlock at its source by moving the PHYE_RESUME_TIMEOUT\nnotification to after sas_drain_work(). By then the host resume is about\nto complete, so device removal through device_link no longer blocks on\nthe resume and the cycle is broken.\n\nWith the deadlock gone, restore sas_resume_ha() (the draining variant)\nin hisi_sas and remove sas_resume_ha_no_sync().\n\nThe reorder is safe for the other libsas consumers (isci, pm8001,\naic94xx, mvsas). During suspend, sas_suspend_devices() calls\nsas_notify_lldd_dev_gone() for each device, which sets dev-\u003elldd_dev to\nNULL. When scsi_unblock_requests re-enables I/O in resume, any I/O to a\ntimed-out phy\u0027s disk is immediately rejected by the LLDD before reaching\nhardware: isci returns SAS_DEVICE_UNKNOWN (mapped to DID_BAD_TARGET),\nand pm8001 returns SAS_PHY_DOWN (mapped to DID_NO_CONNECT). Both\ncomplete directly via scsi_done() without entering SCSI EH. This is\nidentical in both the old and new ordering since lldd_dev_gone runs\nduring suspend, before resume. The reorder only affects when the\nPHYE_RESUME_TIMEOUT handler runs (synchronized by sas_drain_work()\nvs. asynchronous after resume returns), not whether I/O can reach the\ndevice. aic94xx and mvsas do not register any PM ops and never reach\nthis code path."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:38:54.912Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/09357f067122e2e28ec52e27013a1660a1571618"
},
{
"url": "https://git.kernel.org/stable/c/e50a6523a603594a6d92cdecfe11997d639410a3"
},
{
"url": "https://git.kernel.org/stable/c/c391b5899dd46485a5893696c12ae3e95a3a7325"
},
{
"url": "https://git.kernel.org/stable/c/9e24b47ef81d43b3fb1b14294f09991640c79fcc"
},
{
"url": "https://git.kernel.org/stable/c/b9c44a14062093e9fc2d6bddc696cfceadb482d7"
},
{
"url": "https://git.kernel.org/stable/c/3dbbbf656b850c9c8de05df6ad4a1dfc6ff02845"
}
],
"title": "scsi: libsas: Fix HA resume deadlock and hisi_sas disk-wake race",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74555",
"datePublished": "2026-08-15T12:28:00.729Z",
"dateReserved": "2026-08-15T05:44:03.916Z",
"dateUpdated": "2026-08-19T16:38:54.912Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68309 (GCVE-0-2026-68309)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: mt76: connac: fix possible NULL-pointer deref in mt76_connac_mcu_uni_bss_he_tlv()
mt76_connac_get_he_phy_cap routine can theoretically return NULL so
check cap pointer before dereferencing it.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d0e274af2f2e44b9d496f5d2c0431fdd2ea76fb8 Version: d0e274af2f2e44b9d496f5d2c0431fdd2ea76fb8 Version: d0e274af2f2e44b9d496f5d2c0431fdd2ea76fb8 Version: d0e274af2f2e44b9d496f5d2c0431fdd2ea76fb8 Version: d0e274af2f2e44b9d496f5d2c0431fdd2ea76fb8 Version: d0e274af2f2e44b9d496f5d2c0431fdd2ea76fb8 Version: d0e274af2f2e44b9d496f5d2c0431fdd2ea76fb8 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/mediatek/mt76/mt76_connac_mcu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "d1f8705d6545d20950991785306d08884b0056fc",
"status": "affected",
"version": "d0e274af2f2e44b9d496f5d2c0431fdd2ea76fb8",
"versionType": "git"
},
{
"lessThan": "91eb15c026debd8b7bfbd83f062e6245a4e69964",
"status": "affected",
"version": "d0e274af2f2e44b9d496f5d2c0431fdd2ea76fb8",
"versionType": "git"
},
{
"lessThan": "b09508dd7bc4a8948ea00603041a918c09788502",
"status": "affected",
"version": "d0e274af2f2e44b9d496f5d2c0431fdd2ea76fb8",
"versionType": "git"
},
{
"lessThan": "2afc2d5098866518a5c446a2e647b1b3f43daaf4",
"status": "affected",
"version": "d0e274af2f2e44b9d496f5d2c0431fdd2ea76fb8",
"versionType": "git"
},
{
"lessThan": "c058786b09cfab080125bc3ee7928a181dcbd37a",
"status": "affected",
"version": "d0e274af2f2e44b9d496f5d2c0431fdd2ea76fb8",
"versionType": "git"
},
{
"lessThan": "8709c66e665a2a09192853d4f3d0fb4bd0f76403",
"status": "affected",
"version": "d0e274af2f2e44b9d496f5d2c0431fdd2ea76fb8",
"versionType": "git"
},
{
"lessThan": "2c1fb2335f5e3afb34f91bc07ecb63517c328090",
"status": "affected",
"version": "d0e274af2f2e44b9d496f5d2c0431fdd2ea76fb8",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/mediatek/mt76/mt76_connac_mcu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.12"
},
{
"lessThan": "5.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: connac: fix possible NULL-pointer deref in mt76_connac_mcu_uni_bss_he_tlv()\n\nmt76_connac_get_he_phy_cap routine can theoretically return NULL so\ncheck cap pointer before dereferencing it."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:00.744Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/d1f8705d6545d20950991785306d08884b0056fc"
},
{
"url": "https://git.kernel.org/stable/c/91eb15c026debd8b7bfbd83f062e6245a4e69964"
},
{
"url": "https://git.kernel.org/stable/c/b09508dd7bc4a8948ea00603041a918c09788502"
},
{
"url": "https://git.kernel.org/stable/c/2afc2d5098866518a5c446a2e647b1b3f43daaf4"
},
{
"url": "https://git.kernel.org/stable/c/c058786b09cfab080125bc3ee7928a181dcbd37a"
},
{
"url": "https://git.kernel.org/stable/c/8709c66e665a2a09192853d4f3d0fb4bd0f76403"
},
{
"url": "https://git.kernel.org/stable/c/2c1fb2335f5e3afb34f91bc07ecb63517c328090"
}
],
"title": "wifi: mt76: connac: fix possible NULL-pointer deref in mt76_connac_mcu_uni_bss_he_tlv()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68309",
"datePublished": "2026-08-10T12:02:43.950Z",
"dateReserved": "2026-07-30T09:28:09.381Z",
"dateUpdated": "2026-08-19T16:33:00.744Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68175 (GCVE-0-2026-68175)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
tracing: Fix resource leak on mmiotrace trace_pipe close
The mmiotrace tracer was added May 12th 2008. At that time, resources
created in pipe_open() could not be freed because there was not
pipe_close function pointer of the tracer. The pipe_close function pointer
was added in December 7th, 2009, but the mmiotrace tracer was not updated.
mmio_pipe_open() allocates a header_iter and takes a pci_dev reference
when trace_pipe is opened. mmio_close() frees them, but it was only
wired to the tracer's .close callback.
tracing_release_pipe() invokes .pipe_close, not .close, when the
trace_pipe file is released. As a result, closing trace_pipe with the
mmiotrace tracer active leaked the header_iter allocation and left a
stale pci_dev reference.
Set .pipe_close to mmio_close, matching how function_graph wires both
callbacks to the same handler.
Note, if the trace_pipe is read to completion, it will clean up the
resources, but if one were to run:
# head -n 1 /sys/kernel/tracing/trace_pipe
VERSION 20070824
Over and over again, it would trigger a massive leak.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: c521efd1700a8c0f7ce26f011f5eaecca17fabfa Version: c521efd1700a8c0f7ce26f011f5eaecca17fabfa Version: c521efd1700a8c0f7ce26f011f5eaecca17fabfa Version: c521efd1700a8c0f7ce26f011f5eaecca17fabfa Version: c521efd1700a8c0f7ce26f011f5eaecca17fabfa Version: c521efd1700a8c0f7ce26f011f5eaecca17fabfa Version: c521efd1700a8c0f7ce26f011f5eaecca17fabfa Version: c521efd1700a8c0f7ce26f011f5eaecca17fabfa |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"kernel/trace/trace_mmiotrace.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "7871128ea41217fa6a58bbbcb44cb0d2e9e60966",
"status": "affected",
"version": "c521efd1700a8c0f7ce26f011f5eaecca17fabfa",
"versionType": "git"
},
{
"lessThan": "1d0b59e2b203c02149d8f63607329debe36b3ec5",
"status": "affected",
"version": "c521efd1700a8c0f7ce26f011f5eaecca17fabfa",
"versionType": "git"
},
{
"lessThan": "581ac13e12e77d6c64f8719083bdf95209308919",
"status": "affected",
"version": "c521efd1700a8c0f7ce26f011f5eaecca17fabfa",
"versionType": "git"
},
{
"lessThan": "f9e6dfe341fb31c95b9655eb6b1db8b3ae090817",
"status": "affected",
"version": "c521efd1700a8c0f7ce26f011f5eaecca17fabfa",
"versionType": "git"
},
{
"lessThan": "594e1cf3f736779a535873fd5988162d827bfe4f",
"status": "affected",
"version": "c521efd1700a8c0f7ce26f011f5eaecca17fabfa",
"versionType": "git"
},
{
"lessThan": "cf5a82bef623b969a609f2b7e392d06dbae34aa6",
"status": "affected",
"version": "c521efd1700a8c0f7ce26f011f5eaecca17fabfa",
"versionType": "git"
},
{
"lessThan": "cb459fec4f7b13caf646101ff076e94ef38434d8",
"status": "affected",
"version": "c521efd1700a8c0f7ce26f011f5eaecca17fabfa",
"versionType": "git"
},
{
"lessThan": "c1d87e724ae55e781b7cc7ccafb34d9e668582b2",
"status": "affected",
"version": "c521efd1700a8c0f7ce26f011f5eaecca17fabfa",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"kernel/trace/trace_mmiotrace.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.33"
},
{
"lessThan": "2.6.33",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.33",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.33",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.33",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.33",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.33",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.33",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.33",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.33",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Fix resource leak on mmiotrace trace_pipe close\n\nThe mmiotrace tracer was added May 12th 2008. At that time, resources\ncreated in pipe_open() could not be freed because there was not\npipe_close function pointer of the tracer. The pipe_close function pointer\nwas added in December 7th, 2009, but the mmiotrace tracer was not updated.\n\nmmio_pipe_open() allocates a header_iter and takes a pci_dev reference\nwhen trace_pipe is opened. mmio_close() frees them, but it was only\nwired to the tracer\u0027s .close callback.\n\ntracing_release_pipe() invokes .pipe_close, not .close, when the\ntrace_pipe file is released. As a result, closing trace_pipe with the\nmmiotrace tracer active leaked the header_iter allocation and left a\nstale pci_dev reference.\n\nSet .pipe_close to mmio_close, matching how function_graph wires both\ncallbacks to the same handler.\n\nNote, if the trace_pipe is read to completion, it will clean up the\nresources, but if one were to run:\n\n # head -n 1 /sys/kernel/tracing/trace_pipe\n VERSION 20070824\n\nOver and over again, it would trigger a massive leak."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:30:39.826Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/7871128ea41217fa6a58bbbcb44cb0d2e9e60966"
},
{
"url": "https://git.kernel.org/stable/c/1d0b59e2b203c02149d8f63607329debe36b3ec5"
},
{
"url": "https://git.kernel.org/stable/c/581ac13e12e77d6c64f8719083bdf95209308919"
},
{
"url": "https://git.kernel.org/stable/c/f9e6dfe341fb31c95b9655eb6b1db8b3ae090817"
},
{
"url": "https://git.kernel.org/stable/c/594e1cf3f736779a535873fd5988162d827bfe4f"
},
{
"url": "https://git.kernel.org/stable/c/cf5a82bef623b969a609f2b7e392d06dbae34aa6"
},
{
"url": "https://git.kernel.org/stable/c/cb459fec4f7b13caf646101ff076e94ef38434d8"
},
{
"url": "https://git.kernel.org/stable/c/c1d87e724ae55e781b7cc7ccafb34d9e668582b2"
}
],
"title": "tracing: Fix resource leak on mmiotrace trace_pipe close",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68175",
"datePublished": "2026-08-10T11:59:45.965Z",
"dateReserved": "2026-07-30T09:28:09.372Z",
"dateUpdated": "2026-08-19T16:30:39.826Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68153 (GCVE-0-2026-68153)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
libceph: remove debugfs files before client teardown
ceph_destroy_client() tears down the monitor client before removing
the per-client debugfs files. A concurrent read of the monmap debugfs
file can enter monmap_show() after ceph_monc_stop() has freed
monc->monmap, triggering a use-after-free.
Remove the debugfs files before stopping the OSD and monitor clients.
debugfs_remove() drains active handlers and prevents new accesses, so
the debugfs callbacks can no longer race the rest of client teardown.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 76aa844d5b2fb8c839180d3f5874e333b297e5fd Version: 76aa844d5b2fb8c839180d3f5874e333b297e5fd Version: 76aa844d5b2fb8c839180d3f5874e333b297e5fd Version: 76aa844d5b2fb8c839180d3f5874e333b297e5fd Version: 76aa844d5b2fb8c839180d3f5874e333b297e5fd Version: 76aa844d5b2fb8c839180d3f5874e333b297e5fd Version: 76aa844d5b2fb8c839180d3f5874e333b297e5fd Version: 76aa844d5b2fb8c839180d3f5874e333b297e5fd |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ceph/ceph_common.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ac78549d186090ee7125d28c3a8c376573b36194",
"status": "affected",
"version": "76aa844d5b2fb8c839180d3f5874e333b297e5fd",
"versionType": "git"
},
{
"lessThan": "463a264e9094384112a5c8b46f0a9ddaf8566904",
"status": "affected",
"version": "76aa844d5b2fb8c839180d3f5874e333b297e5fd",
"versionType": "git"
},
{
"lessThan": "fe46b7e06f14f6f94766832df309b249cb689d27",
"status": "affected",
"version": "76aa844d5b2fb8c839180d3f5874e333b297e5fd",
"versionType": "git"
},
{
"lessThan": "fc1010e7e0204ece6cc0f9af4f473e9553535eab",
"status": "affected",
"version": "76aa844d5b2fb8c839180d3f5874e333b297e5fd",
"versionType": "git"
},
{
"lessThan": "d3dc8889d39a676bf840132bd5c5c48cb0daba23",
"status": "affected",
"version": "76aa844d5b2fb8c839180d3f5874e333b297e5fd",
"versionType": "git"
},
{
"lessThan": "8f5a3abc54ba24dbceb14cc3a719908c4f688091",
"status": "affected",
"version": "76aa844d5b2fb8c839180d3f5874e333b297e5fd",
"versionType": "git"
},
{
"lessThan": "b9fedda2f628e030384228de0dafc574b7fb0c2f",
"status": "affected",
"version": "76aa844d5b2fb8c839180d3f5874e333b297e5fd",
"versionType": "git"
},
{
"lessThan": "e4c804726c4afce3ba648b982d564f6af2cfa328",
"status": "affected",
"version": "76aa844d5b2fb8c839180d3f5874e333b297e5fd",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ceph/ceph_common.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.34"
},
{
"lessThan": "2.6.34",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.34",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: remove debugfs files before client teardown\n\nceph_destroy_client() tears down the monitor client before removing\nthe per-client debugfs files. A concurrent read of the monmap debugfs\nfile can enter monmap_show() after ceph_monc_stop() has freed\nmonc-\u003emonmap, triggering a use-after-free.\n\nRemove the debugfs files before stopping the OSD and monitor clients.\ndebugfs_remove() drains active handlers and prevents new accesses, so\nthe debugfs callbacks can no longer race the rest of client teardown."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires local access to debugfs via read() on /sys/kernel/debug/ceph/client*/monmap concurrent with local ceph client teardown via umount or rbd unmap; the bug is not reachable through Ceph network protocol handlers.\nAC:L - The attacker controls both sides of the race by concurrently reading the monmap debugfs file while triggering ceph_destroy_client() via umount/rbd teardown, and can retry until the window between ceph_monc_stop() and debugfs removal is hit.\nPR:L - An unprivileged local user can use user-namespace capabilities (CAP_DAC_READ_SEARCH) to read root-owned debugfs files and race reads against libceph client teardown during automated volume detach or service restarts on Ceph storage nodes.\nUI:N - No victim user interaction is required; a local attacker can independently issue debugfs reads and trigger or time against client teardown without requiring another user to click, open files, or mount filesystems.\nS:U - The use-after-free corrupts kernel heap memory within the same kernel security domain and does not cross VM, container, or IOMMU boundaries; impact is standard kernel privilege escalation or crash.\nC:H - The use-after-free on monc-\u003emonmap permits reading freed heap memory containing monitor addresses and entity metadata, and UAF primitives are routinely leveraged for arbitrary kernel memory disclosure.\nI:H - Heap use-after-free on the variable-length ceph_monmap structure enables memory corruption that can be groomed into arbitrary kernel write primitives and local privilege escalation via control-flow hijacking.\nA:H - Concurrent access to freed monmap memory during debugfs iteration can cause kernel oops, BUG, or panic, and UAF corruption reliably threatens system availability even when full exploitation is not attempted."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:30:18.048Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ac78549d186090ee7125d28c3a8c376573b36194"
},
{
"url": "https://git.kernel.org/stable/c/463a264e9094384112a5c8b46f0a9ddaf8566904"
},
{
"url": "https://git.kernel.org/stable/c/fe46b7e06f14f6f94766832df309b249cb689d27"
},
{
"url": "https://git.kernel.org/stable/c/fc1010e7e0204ece6cc0f9af4f473e9553535eab"
},
{
"url": "https://git.kernel.org/stable/c/d3dc8889d39a676bf840132bd5c5c48cb0daba23"
},
{
"url": "https://git.kernel.org/stable/c/8f5a3abc54ba24dbceb14cc3a719908c4f688091"
},
{
"url": "https://git.kernel.org/stable/c/b9fedda2f628e030384228de0dafc574b7fb0c2f"
},
{
"url": "https://git.kernel.org/stable/c/e4c804726c4afce3ba648b982d564f6af2cfa328"
}
],
"title": "libceph: remove debugfs files before client teardown",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68153",
"datePublished": "2026-08-10T11:59:19.302Z",
"dateReserved": "2026-07-30T09:28:09.371Z",
"dateUpdated": "2026-08-19T16:30:18.048Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74682 (GCVE-0-2026-74682)
Vulnerability from cvelistv5
Published
2026-08-22 15:32
Modified
2026-08-22 15:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ALSA: usb-audio: fix OOB write on Type II inbound URBs
data_ep_set_params() sizes each URB transfer buffer before it adds the
Format Type II transfer delimiter:
u->packets = urb_packs;
u->buffer_size = maxsize * u->packets;
if (fmt->fmt_type == UAC_FORMAT_TYPE_II)
u->packets++; /* for transfer delimiter */
u->urb = usb_alloc_urb(u->packets, GFP_KERNEL);
buffer_size is computed from the pre-increment packet count and never
recomputed, so for a Type II endpoint the buffer is one packet short of
the packet count the URB is built with.
prepare_inbound_urb() then lays out one iso frame per packet and never
consults buffer_size:
offs = 0;
for (i = 0; i < urb_ctx->packets; i++) {
urb->iso_frame_desc[i].offset = offs;
urb->iso_frame_desc[i].length = ep->curpacksize;
offs += ep->curpacksize;
}
urb->transfer_buffer_length = offs;
urb->number_of_packets = urb_ctx->packets;
The last descriptor therefore points one packet past the end of the
transfer buffer, where the host controller writes device data on every
inbound transfer. prepare_silent_urb() and prepare_playback_urb() bound
their fill loops by ctx->buffer_size, so only capture is affected.
fmt_type comes from the device's audio streaming descriptors, so any
device advertising a Type II capture format hits this once userspace sets
hw_params on the stream.
KASAN on 7.2.0-rc5 (arm64) with a dummy_hcd/raw-gadget device, one report
per inbound transfer:
BUG: KASAN: slab-out-of-bounds in dummy_timer
Write of size 64 at addr ffff0000186171c0 by task cons02/166
__asan_memcpy
dummy_timer
hrtimer_run_softirq
Allocated by task 166:
usb_alloc_coherent
snd_usb_endpoint_set_params
The buggy address is located 0 bytes to the right of
allocated 64-byte region [ffff000018617180, ffff0000186171c0)
Compute buffer_size after the delimiter packet has been accounted for,
and bound the fill loop by buffer_size, as prepare_silent_urb() already
does on the outbound side. This grows every Type II URB allocation by
one maxsize packet.
Discovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 8fdff6a319e7dac757c558bd283dc4577e68cde7 Version: 8fdff6a319e7dac757c558bd283dc4577e68cde7 Version: 8fdff6a319e7dac757c558bd283dc4577e68cde7 Version: 8fdff6a319e7dac757c558bd283dc4577e68cde7 Version: 8fdff6a319e7dac757c558bd283dc4577e68cde7 Version: 8fdff6a319e7dac757c558bd283dc4577e68cde7 Version: 8fdff6a319e7dac757c558bd283dc4577e68cde7 Version: 8fdff6a319e7dac757c558bd283dc4577e68cde7 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"sound/usb/endpoint.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "6af5f29af7711233ae68d3b25c15d67478468900",
"status": "affected",
"version": "8fdff6a319e7dac757c558bd283dc4577e68cde7",
"versionType": "git"
},
{
"lessThan": "f1fbb50b99311b35c2e85cc70341d62082dca4b5",
"status": "affected",
"version": "8fdff6a319e7dac757c558bd283dc4577e68cde7",
"versionType": "git"
},
{
"lessThan": "137bf034740e5a2734794908d0aff1e0bd7cee6e",
"status": "affected",
"version": "8fdff6a319e7dac757c558bd283dc4577e68cde7",
"versionType": "git"
},
{
"lessThan": "6607f85242577f33d4540a0d1f4a6137f5367058",
"status": "affected",
"version": "8fdff6a319e7dac757c558bd283dc4577e68cde7",
"versionType": "git"
},
{
"lessThan": "ca22c94bdfc22c564ca2e11c87ba4d17ebeaaa9a",
"status": "affected",
"version": "8fdff6a319e7dac757c558bd283dc4577e68cde7",
"versionType": "git"
},
{
"lessThan": "0a235379825e1a6194e43861ee6658e5fc35686d",
"status": "affected",
"version": "8fdff6a319e7dac757c558bd283dc4577e68cde7",
"versionType": "git"
},
{
"lessThan": "d3ed4e6321bb453757044cb9e5ecb30a33f04903",
"status": "affected",
"version": "8fdff6a319e7dac757c558bd283dc4577e68cde7",
"versionType": "git"
},
{
"lessThan": "69ee44e1a23be62318189dc4b37fa4ad94053269",
"status": "affected",
"version": "8fdff6a319e7dac757c558bd283dc4577e68cde7",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"sound/usb/endpoint.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.5"
},
{
"lessThan": "3.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: usb-audio: fix OOB write on Type II inbound URBs\n\ndata_ep_set_params() sizes each URB transfer buffer before it adds the\nFormat Type II transfer delimiter:\n\n\tu-\u003epackets = urb_packs;\n\tu-\u003ebuffer_size = maxsize * u-\u003epackets;\n\n\tif (fmt-\u003efmt_type == UAC_FORMAT_TYPE_II)\n\t\tu-\u003epackets++; /* for transfer delimiter */\n\tu-\u003eurb = usb_alloc_urb(u-\u003epackets, GFP_KERNEL);\n\nbuffer_size is computed from the pre-increment packet count and never\nrecomputed, so for a Type II endpoint the buffer is one packet short of\nthe packet count the URB is built with.\n\nprepare_inbound_urb() then lays out one iso frame per packet and never\nconsults buffer_size:\n\n\toffs = 0;\n\tfor (i = 0; i \u003c urb_ctx-\u003epackets; i++) {\n\t\turb-\u003eiso_frame_desc[i].offset = offs;\n\t\turb-\u003eiso_frame_desc[i].length = ep-\u003ecurpacksize;\n\t\toffs += ep-\u003ecurpacksize;\n\t}\n\n\turb-\u003etransfer_buffer_length = offs;\n\turb-\u003enumber_of_packets = urb_ctx-\u003epackets;\n\nThe last descriptor therefore points one packet past the end of the\ntransfer buffer, where the host controller writes device data on every\ninbound transfer. prepare_silent_urb() and prepare_playback_urb() bound\ntheir fill loops by ctx-\u003ebuffer_size, so only capture is affected.\n\nfmt_type comes from the device\u0027s audio streaming descriptors, so any\ndevice advertising a Type II capture format hits this once userspace sets\nhw_params on the stream.\n\nKASAN on 7.2.0-rc5 (arm64) with a dummy_hcd/raw-gadget device, one report\nper inbound transfer:\n\n BUG: KASAN: slab-out-of-bounds in dummy_timer\n Write of size 64 at addr ffff0000186171c0 by task cons02/166\n __asan_memcpy\n dummy_timer\n hrtimer_run_softirq\n Allocated by task 166:\n usb_alloc_coherent\n snd_usb_endpoint_set_params\n The buggy address is located 0 bytes to the right of\n allocated 64-byte region [ffff000018617180, ffff0000186171c0)\n\nCompute buffer_size after the delimiter packet has been accounted for,\nand bound the fill loop by buffer_size, as prepare_silent_urb() already\ndoes on the outbound side. This grows every Type II URB allocation by\none maxsize packet.\n\nDiscovered by XBOW, triaged by Baul Lee \u003cbaul.lee@xbow.com\u003e"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-22T15:32:49.527Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/6af5f29af7711233ae68d3b25c15d67478468900"
},
{
"url": "https://git.kernel.org/stable/c/f1fbb50b99311b35c2e85cc70341d62082dca4b5"
},
{
"url": "https://git.kernel.org/stable/c/137bf034740e5a2734794908d0aff1e0bd7cee6e"
},
{
"url": "https://git.kernel.org/stable/c/6607f85242577f33d4540a0d1f4a6137f5367058"
},
{
"url": "https://git.kernel.org/stable/c/ca22c94bdfc22c564ca2e11c87ba4d17ebeaaa9a"
},
{
"url": "https://git.kernel.org/stable/c/0a235379825e1a6194e43861ee6658e5fc35686d"
},
{
"url": "https://git.kernel.org/stable/c/d3ed4e6321bb453757044cb9e5ecb30a33f04903"
},
{
"url": "https://git.kernel.org/stable/c/69ee44e1a23be62318189dc4b37fa4ad94053269"
}
],
"title": "ALSA: usb-audio: fix OOB write on Type II inbound URBs",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74682",
"datePublished": "2026-08-22T15:32:49.527Z",
"dateReserved": "2026-08-15T05:44:03.925Z",
"dateUpdated": "2026-08-22T15:32:49.527Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80772 (GCVE-0-2026-80772)
Vulnerability from cvelistv5
Published
2026-09-04 15:12
Modified
2026-09-04 15:12
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
HID: nintendo: fix out-of-bounds read in joycon_ctlr_read_handler()
joycon_ctlr_read_handler() casts an incoming HID input report to
struct joycon_input_report and parses it, guarding the cast only with a
12-byte length check:
if (size >= 12) /* make sure it contains the input report */
joycon_parse_report(ctlr, (struct joycon_input_report *)data);
struct joycon_input_report is 49 bytes: a 13-byte header followed by a
union whose IMU arm is 36 bytes. For an IMU report joycon_parse_report()
-> joycon_parse_imu_report() walks that union (struct offsets 13..48),
so a report of exactly 12 bytes with data[0] == JC_INPUT_IMU_DATA passes
the guard yet is read up to 37 bytes past its declared length. The
over-read bytes are decoded into accelerometer/gyroscope values and
forwarded to userspace through the "(IMU)" input device, leaking
driver-internal memory. data[0] and size are fully controlled by a
malicious or spoofed Joy-Con/Pro Controller.
Receive buffers are sized to the maximum report length, so this is an
over-read within the allocation rather than a slab OOB, but the decoded
bytes still reach userspace.
The sibling subcmd path in joycon_ctlr_handle_event() already bounds the
same cast correctly:
if (size < sizeof(struct joycon_input_report) ||
data[0] != JC_INPUT_SUBCMD_REPLY)
break;
Use the same sizeof(struct joycon_input_report) bound here.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 2af16c1f846bd60240745bbd3afa13d5f040c61a Version: 2af16c1f846bd60240745bbd3afa13d5f040c61a Version: 2af16c1f846bd60240745bbd3afa13d5f040c61a Version: 2af16c1f846bd60240745bbd3afa13d5f040c61a Version: 2af16c1f846bd60240745bbd3afa13d5f040c61a Version: 2af16c1f846bd60240745bbd3afa13d5f040c61a Version: 2af16c1f846bd60240745bbd3afa13d5f040c61a |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/hid/hid-nintendo.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "33ea29f8b6141f2d265de807e110a6435b355cb0",
"status": "affected",
"version": "2af16c1f846bd60240745bbd3afa13d5f040c61a",
"versionType": "git"
},
{
"lessThan": "bd397c4123a4bc084913d8c7fdb40ef94e9f8172",
"status": "affected",
"version": "2af16c1f846bd60240745bbd3afa13d5f040c61a",
"versionType": "git"
},
{
"lessThan": "addca61f9a23c0d20a387c2040e70479f54518e1",
"status": "affected",
"version": "2af16c1f846bd60240745bbd3afa13d5f040c61a",
"versionType": "git"
},
{
"lessThan": "51cfd1adbe7a46bb08af162abb3ab3b6820e2d15",
"status": "affected",
"version": "2af16c1f846bd60240745bbd3afa13d5f040c61a",
"versionType": "git"
},
{
"lessThan": "d4cabd4089adb59cf7974915737c52cc47a9bb1b",
"status": "affected",
"version": "2af16c1f846bd60240745bbd3afa13d5f040c61a",
"versionType": "git"
},
{
"lessThan": "34725ed4719da424113db8449fb5485aaf71a913",
"status": "affected",
"version": "2af16c1f846bd60240745bbd3afa13d5f040c61a",
"versionType": "git"
},
{
"lessThan": "27b376b945c0aac46fcdfcc950b14a85b874b557",
"status": "affected",
"version": "2af16c1f846bd60240745bbd3afa13d5f040c61a",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/hid/hid-nintendo.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.16"
},
{
"lessThan": "5.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.185",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.154",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.106",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.47",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.1",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.185",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.154",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.106",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.47",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.11",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.1",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "5.16",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: nintendo: fix out-of-bounds read in joycon_ctlr_read_handler()\n\njoycon_ctlr_read_handler() casts an incoming HID input report to\nstruct joycon_input_report and parses it, guarding the cast only with a\n12-byte length check:\n\n\tif (size \u003e= 12) /* make sure it contains the input report */\n\t\tjoycon_parse_report(ctlr, (struct joycon_input_report *)data);\n\nstruct joycon_input_report is 49 bytes: a 13-byte header followed by a\nunion whose IMU arm is 36 bytes. For an IMU report joycon_parse_report()\n-\u003e joycon_parse_imu_report() walks that union (struct offsets 13..48),\nso a report of exactly 12 bytes with data[0] == JC_INPUT_IMU_DATA passes\nthe guard yet is read up to 37 bytes past its declared length. The\nover-read bytes are decoded into accelerometer/gyroscope values and\nforwarded to userspace through the \"(IMU)\" input device, leaking\ndriver-internal memory. data[0] and size are fully controlled by a\nmalicious or spoofed Joy-Con/Pro Controller.\n\nReceive buffers are sized to the maximum report length, so this is an\nover-read within the allocation rather than a slab OOB, but the decoded\nbytes still reach userspace.\n\nThe sibling subcmd path in joycon_ctlr_handle_event() already bounds the\nsame cast correctly:\n\n\tif (size \u003c sizeof(struct joycon_input_report) ||\n\t data[0] != JC_INPUT_SUBCMD_REPLY)\n\t\tbreak;\n\nUse the same sizeof(struct joycon_input_report) bound here."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T15:12:44.445Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/33ea29f8b6141f2d265de807e110a6435b355cb0"
},
{
"url": "https://git.kernel.org/stable/c/bd397c4123a4bc084913d8c7fdb40ef94e9f8172"
},
{
"url": "https://git.kernel.org/stable/c/addca61f9a23c0d20a387c2040e70479f54518e1"
},
{
"url": "https://git.kernel.org/stable/c/51cfd1adbe7a46bb08af162abb3ab3b6820e2d15"
},
{
"url": "https://git.kernel.org/stable/c/d4cabd4089adb59cf7974915737c52cc47a9bb1b"
},
{
"url": "https://git.kernel.org/stable/c/34725ed4719da424113db8449fb5485aaf71a913"
},
{
"url": "https://git.kernel.org/stable/c/27b376b945c0aac46fcdfcc950b14a85b874b557"
}
],
"title": "HID: nintendo: fix out-of-bounds read in joycon_ctlr_read_handler()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80772",
"datePublished": "2026-09-04T15:12:44.445Z",
"dateReserved": "2026-08-26T14:34:25.792Z",
"dateUpdated": "2026-09-04T15:12:44.445Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80913 (GCVE-0-2026-80913)
Vulnerability from cvelistv5
Published
2026-09-04 17:19
Modified
2026-09-04 17:19
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
selinux: require every boolean value to be defined
p_bools.nprim comes from the policy image independently of how many
booleans follow it, and cond_index_bool() fills bool_val_to_struct[] at
value - 1, so a count larger than the values present leaves NULL entries.
Every user of that array then walks it by index and dereferences each
entry: cond_evaluate_expr() on the access-vector path,
security_get_bools() and security_get_bool_value() behind selinuxfs, and
security_set_bools(). A sparse class value is absorbed by
policydb_class_isvalid() and its siblings; booleans have no such
predicate, and no consumer that could use one.
Reject a boolean value that no boolean defines, once, where the array is
built. Conforming policies define every boolean they declare and are
unaffected.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"security/selinux/ss/policydb.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "4d0ece18e648bd4362704fd087249ac697f2b7fb",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "3938c8494d3c5d84a53fd7d1966ae9dde46cb5f8",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "4dfb997c60f7951011d3dcbee926e3a7f80d8a76",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "3161daa3f1e3ca68f8b2b8fa01720b5a8dcc6b40",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "740012aebdb8311332bf66e2aabf453ba73c2c45",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "42a7107f99d86a7524c37f108047dfa3db096ab5",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "ed901e88aa3fb3d5d7b0b52c2ee3073209df9bec",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "a93d37a09b863810653f93d371fb197457d59deb",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"security/selinux/ss/policydb.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.46",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.10",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nselinux: require every boolean value to be defined\n\np_bools.nprim comes from the policy image independently of how many\nbooleans follow it, and cond_index_bool() fills bool_val_to_struct[] at\nvalue - 1, so a count larger than the values present leaves NULL entries.\nEvery user of that array then walks it by index and dereferences each\nentry: cond_evaluate_expr() on the access-vector path,\nsecurity_get_bools() and security_get_bool_value() behind selinuxfs, and\nsecurity_set_bools(). A sparse class value is absorbed by\npolicydb_class_isvalid() and its siblings; booleans have no such\npredicate, and no consumer that could use one.\n\nReject a boolean value that no boolean defines, once, where the array is\nbuilt. Conforming policies define every boolean they declare and are\nunaffected."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T17:19:23.975Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/4d0ece18e648bd4362704fd087249ac697f2b7fb"
},
{
"url": "https://git.kernel.org/stable/c/3938c8494d3c5d84a53fd7d1966ae9dde46cb5f8"
},
{
"url": "https://git.kernel.org/stable/c/4dfb997c60f7951011d3dcbee926e3a7f80d8a76"
},
{
"url": "https://git.kernel.org/stable/c/3161daa3f1e3ca68f8b2b8fa01720b5a8dcc6b40"
},
{
"url": "https://git.kernel.org/stable/c/740012aebdb8311332bf66e2aabf453ba73c2c45"
},
{
"url": "https://git.kernel.org/stable/c/42a7107f99d86a7524c37f108047dfa3db096ab5"
},
{
"url": "https://git.kernel.org/stable/c/ed901e88aa3fb3d5d7b0b52c2ee3073209df9bec"
},
{
"url": "https://git.kernel.org/stable/c/a93d37a09b863810653f93d371fb197457d59deb"
}
],
"title": "selinux: require every boolean value to be defined",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80913",
"datePublished": "2026-09-04T17:19:23.975Z",
"dateReserved": "2026-08-26T14:34:25.801Z",
"dateUpdated": "2026-09-04T17:19:23.975Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68202 (GCVE-0-2026-68202)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ALSA: seq: close a re-opened queue timer in the destructor
queue_delete() closes the queue timer, then frees it. snd_seq_timer_close()
clears q->timer->timeri. snd_use_lock_sync() then drains borrowers, and
snd_seq_timer_delete() frees q->timer.
A borrower can re-open the timer inside that window. A SET_QUEUE_CLIENT
that took a queueptr() use_lock reference before the queue was unlinked
runs snd_seq_timer_open() after the close. Open refuses re-open only while
timeri is set, and the close just cleared it, so it re-opens timeri.
snd_seq_timer_delete() does not close that instance. Its snd_seq_timer_stop()
is a no-op, because running was cleared first. So it frees q->timer with the
instance still live. The queue is freed next.
The instance stays on the global timer with callback_data pointing at the
freed queue. A non-owner START on the unlocked queue arms it. The next tick
derefs the freed queue in snd_seq_timer_interrupt().
Reachable by an unprivileged user with access to /dev/snd/seq. No CAP and
no queue ownership required.
Close any lingering instance in the destructor. There, ->timeri can no
longer change: the queue is unlinked and all use_lock borrowers have
drained, so no snd_seq_queue_use() can re-open it. Close it before clearing
q->timer. snd_timer_close() waits for any in-flight snd_seq_timer_interrupt()
to finish, and that callback still reads q->timer (via snd_seq_check_queue()),
so q->timer must stay valid until it drains.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"sound/core/seq/seq_timer.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b7feeaca1f53b10df9b4de9eaf611767ca70dc92",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "7478ef94b49bc9789cf1a003deec58b42283dde4",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "9d9be6fc30f384f92c4e1b8ed40bd9d4796b7833",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "fb40d03ed792a8a8bf77aa0ee15df57b0ff78b07",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "24f0cabf173539f048946c8fc221131dc221f277",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "6a10025c7fd09a7d2af37a3ae1da188569fce470",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "31a6163e301d832060f8236f1ed17cbc1ca198df",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "2c4dc0ed50b05cd847a4b34b8cebf0775f19aeb9",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"sound/core/seq/seq_timer.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: seq: close a re-opened queue timer in the destructor\n\nqueue_delete() closes the queue timer, then frees it. snd_seq_timer_close()\nclears q-\u003etimer-\u003etimeri. snd_use_lock_sync() then drains borrowers, and\nsnd_seq_timer_delete() frees q-\u003etimer.\n\nA borrower can re-open the timer inside that window. A SET_QUEUE_CLIENT\nthat took a queueptr() use_lock reference before the queue was unlinked\nruns snd_seq_timer_open() after the close. Open refuses re-open only while\ntimeri is set, and the close just cleared it, so it re-opens timeri.\n\nsnd_seq_timer_delete() does not close that instance. Its snd_seq_timer_stop()\nis a no-op, because running was cleared first. So it frees q-\u003etimer with the\ninstance still live. The queue is freed next.\n\nThe instance stays on the global timer with callback_data pointing at the\nfreed queue. A non-owner START on the unlocked queue arms it. The next tick\nderefs the freed queue in snd_seq_timer_interrupt().\n\nReachable by an unprivileged user with access to /dev/snd/seq. No CAP and\nno queue ownership required.\n\nClose any lingering instance in the destructor. There, -\u003etimeri can no\nlonger change: the queue is unlinked and all use_lock borrowers have\ndrained, so no snd_seq_queue_use() can re-open it. Close it before clearing\nq-\u003etimer. snd_timer_close() waits for any in-flight snd_seq_timer_interrupt()\nto finish, and that callback still reads q-\u003etimer (via snd_seq_check_queue()),\nso q-\u003etimer must stay valid until it drains."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached through ioctls on the local character device /dev/snd/seq (SNDRV_SEQ_IOCTL_CREATE_QUEUE/DELETE_QUEUE/SET_QUEUE_CLIENT); no network or adjacent-network path exists to the ALSA sequencer.\nAC:L - The attacker controls both sides of the race \u2014 one thread deletes the queue while another spins on SET_QUEUE_CLIENT holding a queueptr() reference \u2014 and can retry the loop indefinitely on a default kernel with CONFIG_SND_SEQUENCER, so the window is reliably hit.\nPR:L - Only an unprivileged local user able to open /dev/snd/seq is needed; snd_seq_queue_use() performs no owner or access check and no capability is required, as the fix commit states explicitly.\nUI:N - The attacker\u0027s own threads create, delete and re-use the queue and the global system timer fires on its own; no victim action is involved.\nS:U - The use-after-free corrupts kernel heap objects within the same kernel security authority, giving at most kernel privilege escalation rather than crossing a VM, IOMMU or sandbox boundary.\nC:H - The stale timer instance dereferences the freed snd_seq_queue and snd_seq_timer, reading tick/time fields and freed prioq pointers that can be reclaimed by attacker-sprayed objects, giving a route to disclose arbitrary kernel memory.\nI:H - snd_seq_timer_interrupt() writes cur_time, tick and last_update into the freed snd_seq_timer slab and snd_seq_check_queue() dispatches events through freed queue pointers, yielding a controllable write primitive on reclaimed heap memory suitable for privilege escalation.\nA:H - Even unexploited, the timer callback derefs freed memory and takes a spinlock in a freed object from interrupt context, causing oops, lock corruption or panic \u2014 a repeatable denial of service for any local user."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:08.116Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b7feeaca1f53b10df9b4de9eaf611767ca70dc92"
},
{
"url": "https://git.kernel.org/stable/c/7478ef94b49bc9789cf1a003deec58b42283dde4"
},
{
"url": "https://git.kernel.org/stable/c/9d9be6fc30f384f92c4e1b8ed40bd9d4796b7833"
},
{
"url": "https://git.kernel.org/stable/c/fb40d03ed792a8a8bf77aa0ee15df57b0ff78b07"
},
{
"url": "https://git.kernel.org/stable/c/24f0cabf173539f048946c8fc221131dc221f277"
},
{
"url": "https://git.kernel.org/stable/c/6a10025c7fd09a7d2af37a3ae1da188569fce470"
},
{
"url": "https://git.kernel.org/stable/c/31a6163e301d832060f8236f1ed17cbc1ca198df"
},
{
"url": "https://git.kernel.org/stable/c/2c4dc0ed50b05cd847a4b34b8cebf0775f19aeb9"
}
],
"title": "ALSA: seq: close a re-opened queue timer in the destructor",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68202",
"datePublished": "2026-08-10T12:00:21.279Z",
"dateReserved": "2026-07-30T09:28:09.374Z",
"dateUpdated": "2026-08-23T12:46:08.116Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80808 (GCVE-0-2026-80808)
Vulnerability from cvelistv5
Published
2026-09-04 15:13
Modified
2026-09-04 15:13
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ext4: stop retrying saturated xattr cache entries
ext4_xattr_block_set() retries when a cache entry selected for reuse
has a saturated reference count after taking the buffer lock. The retry
returns to the mbcache lookup without making that entry ineligible, so
it can select the same unusable entry indefinitely. A task spinning
there can hold the parent directory's i_rwsem and leave concurrent
rmdir callers blocked.
Normally a reusable entry has a reference count below
EXT4_XATTR_REFCOUNT_MAX because the count and MBE_REUSABLE_B are
updated under the same buffer lock. A corrupted filesystem can violate
that invariant. The syzbot reproducer reports allocator and xattr
corruption before triggering this retry loop.
Check the untrusted on-disk count before incrementing it, avoiding
overflow, and clear MBE_REUSABLE_B when it is already saturated. The
next lookup then skips the entry that was just proven unusable. This
mirrors the normal transition at EXT4_XATTR_REFCOUNT_MAX; the release
path marks the entry reusable again on the exact 1024-to-1023
transition.
Using the same QEMU harness and guest parameters, current unpatched
Linux hung in 6 of 8 420-second trials with the do_rmdir signature;
representative NMI backtraces caught the owner spinning in
ext4_xattr_block_set(). The patched kernel completed 28 of 28 trials
without a hung-task report; the final twelve trials exercised the
reviewed overflow-safe form of the change. syzbot's patch testing also
completed without reproducing the hang.
References
| URL | Tags | ||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1a56cd972ce121b6cf2517a47a578782bbd2ec95 Version: 1be97463696c7291a3e1547614e96432b0bd3add Version: 65f8b80053a1b2fd602daa6814e62d6fa90e5e9b Version: 65f8b80053a1b2fd602daa6814e62d6fa90e5e9b Version: 65f8b80053a1b2fd602daa6814e62d6fa90e5e9b Version: 65f8b80053a1b2fd602daa6814e62d6fa90e5e9b Version: 65f8b80053a1b2fd602daa6814e62d6fa90e5e9b Version: 65f8b80053a1b2fd602daa6814e62d6fa90e5e9b Version: 65f8b80053a1b2fd602daa6814e62d6fa90e5e9b Version: 98953044b3cdb2cb7d82e7365b659e2ed4f4ca4d Version: af8ecc8d20e72130771cc076bce7fcf17ccda6c4 Version: c6fac5cf5a5098732623bcd00a8a3eb9f5465144 Version: 96fa141fa295ae9428da73c56c9852053b575c04 Version: 5.10.163 ≤ Version: 5.15.61 ≤ Version: 4.19.270 ≤ Version: 5.4.229 ≤ Version: 5.18.18 ≤ Version: 5.19.2 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/ext4/xattr.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "119a2f053242ed75bdd2ebc95baf3ae7db6ccacf",
"status": "affected",
"version": "1a56cd972ce121b6cf2517a47a578782bbd2ec95",
"versionType": "git"
},
{
"lessThan": "61631352a5b405c89be579de00903b72e6888aa4",
"status": "affected",
"version": "1be97463696c7291a3e1547614e96432b0bd3add",
"versionType": "git"
},
{
"lessThan": "8865cd664484517703df5c18a965dc3227572b87",
"status": "affected",
"version": "65f8b80053a1b2fd602daa6814e62d6fa90e5e9b",
"versionType": "git"
},
{
"lessThan": "a40c45268f4358207aa9c53764fed2e05f62986a",
"status": "affected",
"version": "65f8b80053a1b2fd602daa6814e62d6fa90e5e9b",
"versionType": "git"
},
{
"lessThan": "889ec86464d261f026f6c334040cfc6c58c99d58",
"status": "affected",
"version": "65f8b80053a1b2fd602daa6814e62d6fa90e5e9b",
"versionType": "git"
},
{
"lessThan": "4902a5cba21aeaf91e6b29e20e0967a5f6abdcd9",
"status": "affected",
"version": "65f8b80053a1b2fd602daa6814e62d6fa90e5e9b",
"versionType": "git"
},
{
"lessThan": "55ee6533c1db7f7656fa8dd19637f3f8b8c08dc5",
"status": "affected",
"version": "65f8b80053a1b2fd602daa6814e62d6fa90e5e9b",
"versionType": "git"
},
{
"lessThan": "dbd4aea175ad3c46436acb251e817b4374628072",
"status": "affected",
"version": "65f8b80053a1b2fd602daa6814e62d6fa90e5e9b",
"versionType": "git"
},
{
"lessThan": "54b6bd40898de7906acb2bccc9a96d1b8e6b4323",
"status": "affected",
"version": "65f8b80053a1b2fd602daa6814e62d6fa90e5e9b",
"versionType": "git"
},
{
"status": "affected",
"version": "98953044b3cdb2cb7d82e7365b659e2ed4f4ca4d",
"versionType": "git"
},
{
"status": "affected",
"version": "af8ecc8d20e72130771cc076bce7fcf17ccda6c4",
"versionType": "git"
},
{
"status": "affected",
"version": "c6fac5cf5a5098732623bcd00a8a3eb9f5465144",
"versionType": "git"
},
{
"status": "affected",
"version": "96fa141fa295ae9428da73c56c9852053b575c04",
"versionType": "git"
},
{
"lessThan": "5.10.267",
"status": "affected",
"version": "5.10.163",
"versionType": "semver"
},
{
"lessThan": "5.15.218",
"status": "affected",
"version": "5.15.61",
"versionType": "semver"
},
{
"lessThan": "4.20",
"status": "affected",
"version": "4.19.270",
"versionType": "semver"
},
{
"lessThan": "5.5",
"status": "affected",
"version": "5.4.229",
"versionType": "semver"
},
{
"lessThan": "5.19",
"status": "affected",
"version": "5.18.18",
"versionType": "semver"
},
{
"lessThan": "5.20",
"status": "affected",
"version": "5.19.2",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/ext4/xattr.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.0"
},
{
"lessThan": "6.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.267",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.218",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.185",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.154",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.106",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.47",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.1",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.267",
"versionStartIncluding": "5.10.163",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.218",
"versionStartIncluding": "5.15.61",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.185",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.154",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.106",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.47",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.11",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.1",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.19.270",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.4.229",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.18.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.19.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: stop retrying saturated xattr cache entries\n\next4_xattr_block_set() retries when a cache entry selected for reuse\nhas a saturated reference count after taking the buffer lock. The retry\nreturns to the mbcache lookup without making that entry ineligible, so\nit can select the same unusable entry indefinitely. A task spinning\nthere can hold the parent directory\u0027s i_rwsem and leave concurrent\nrmdir callers blocked.\n\nNormally a reusable entry has a reference count below\nEXT4_XATTR_REFCOUNT_MAX because the count and MBE_REUSABLE_B are\nupdated under the same buffer lock. A corrupted filesystem can violate\nthat invariant. The syzbot reproducer reports allocator and xattr\ncorruption before triggering this retry loop.\n\nCheck the untrusted on-disk count before incrementing it, avoiding\noverflow, and clear MBE_REUSABLE_B when it is already saturated. The\nnext lookup then skips the entry that was just proven unusable. This\nmirrors the normal transition at EXT4_XATTR_REFCOUNT_MAX; the release\npath marks the entry reusable again on the exact 1024-to-1023\ntransition.\n\nUsing the same QEMU harness and guest parameters, current unpatched\nLinux hung in 6 of 8 420-second trials with the do_rmdir signature;\nrepresentative NMI backtraces caught the owner spinning in\next4_xattr_block_set(). The patched kernel completed 28 of 28 trials\nwithout a hung-task report; the final twelve trials exercised the\nreviewed overflow-safe form of the change. syzbot\u0027s patch testing also\ncompleted without reproducing the hang."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T15:13:28.562Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/119a2f053242ed75bdd2ebc95baf3ae7db6ccacf"
},
{
"url": "https://git.kernel.org/stable/c/61631352a5b405c89be579de00903b72e6888aa4"
},
{
"url": "https://git.kernel.org/stable/c/8865cd664484517703df5c18a965dc3227572b87"
},
{
"url": "https://git.kernel.org/stable/c/a40c45268f4358207aa9c53764fed2e05f62986a"
},
{
"url": "https://git.kernel.org/stable/c/889ec86464d261f026f6c334040cfc6c58c99d58"
},
{
"url": "https://git.kernel.org/stable/c/4902a5cba21aeaf91e6b29e20e0967a5f6abdcd9"
},
{
"url": "https://git.kernel.org/stable/c/55ee6533c1db7f7656fa8dd19637f3f8b8c08dc5"
},
{
"url": "https://git.kernel.org/stable/c/dbd4aea175ad3c46436acb251e817b4374628072"
},
{
"url": "https://git.kernel.org/stable/c/54b6bd40898de7906acb2bccc9a96d1b8e6b4323"
}
],
"title": "ext4: stop retrying saturated xattr cache entries",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80808",
"datePublished": "2026-09-04T15:13:28.562Z",
"dateReserved": "2026-08-26T14:34:25.794Z",
"dateUpdated": "2026-09-04T15:13:28.562Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68259 (GCVE-0-2026-68259)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-19 16:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdkfd: Check bounds in allocate_event_notification_slot
The valid event ids go from 0 to KFD_SIGNAL_EVENT_LIMIT
allocate_event_notification_slot has an option to specify
an event id to allocate at, used by CRIU. We weren't checking
the bounds on that value.
Check them.
v2: Lower bounds check is unecessary because of idr_alloc
already rejecting negative numbers. Upper bounds check should
be KFD_SIGNAL_EVENT_LIMIT since the signal mode mappings might
not yet exist
(cherry picked from commit 6853f1f6cbbeb3f53ebbbd7286536aeb2c5d5f50)
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 40e8a766a761f7fdc8530347527b344fddf6f1a8 Version: 40e8a766a761f7fdc8530347527b344fddf6f1a8 Version: 40e8a766a761f7fdc8530347527b344fddf6f1a8 Version: 40e8a766a761f7fdc8530347527b344fddf6f1a8 Version: 40e8a766a761f7fdc8530347527b344fddf6f1a8 Version: 40e8a766a761f7fdc8530347527b344fddf6f1a8 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdkfd/kfd_events.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "6884fc142b17f456caac50c14505f509bfbcd012",
"status": "affected",
"version": "40e8a766a761f7fdc8530347527b344fddf6f1a8",
"versionType": "git"
},
{
"lessThan": "85eedff5f0c4aba5a66bc37a1bd6bcecd0d77b53",
"status": "affected",
"version": "40e8a766a761f7fdc8530347527b344fddf6f1a8",
"versionType": "git"
},
{
"lessThan": "4622214f0542f64b02c250db0f9c677eeb032d9b",
"status": "affected",
"version": "40e8a766a761f7fdc8530347527b344fddf6f1a8",
"versionType": "git"
},
{
"lessThan": "50319efb865f72db45f191c8709511746d58ee0a",
"status": "affected",
"version": "40e8a766a761f7fdc8530347527b344fddf6f1a8",
"versionType": "git"
},
{
"lessThan": "abeeb1947d81610c65349db4d89c6151f270e136",
"status": "affected",
"version": "40e8a766a761f7fdc8530347527b344fddf6f1a8",
"versionType": "git"
},
{
"lessThan": "bb52249fbbe948875155ccd45cd8d74bf4ae747b",
"status": "affected",
"version": "40e8a766a761f7fdc8530347527b344fddf6f1a8",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdkfd/kfd_events.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.18"
},
{
"lessThan": "5.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.18",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdkfd: Check bounds in allocate_event_notification_slot\n\nThe valid event ids go from 0 to KFD_SIGNAL_EVENT_LIMIT\n\nallocate_event_notification_slot has an option to specify\nan event id to allocate at, used by CRIU. We weren\u0027t checking\nthe bounds on that value.\n\nCheck them.\n\nv2: Lower bounds check is unecessary because of idr_alloc\nalready rejecting negative numbers. Upper bounds check should\nbe KFD_SIGNAL_EVENT_LIMIT since the signal mode mappings might\nnot yet exist\n\n(cherry picked from commit 6853f1f6cbbeb3f53ebbbd7286536aeb2c5d5f50)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:32:28.586Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/6884fc142b17f456caac50c14505f509bfbcd012"
},
{
"url": "https://git.kernel.org/stable/c/85eedff5f0c4aba5a66bc37a1bd6bcecd0d77b53"
},
{
"url": "https://git.kernel.org/stable/c/4622214f0542f64b02c250db0f9c677eeb032d9b"
},
{
"url": "https://git.kernel.org/stable/c/50319efb865f72db45f191c8709511746d58ee0a"
},
{
"url": "https://git.kernel.org/stable/c/abeeb1947d81610c65349db4d89c6151f270e136"
},
{
"url": "https://git.kernel.org/stable/c/bb52249fbbe948875155ccd45cd8d74bf4ae747b"
}
],
"title": "drm/amdkfd: Check bounds in allocate_event_notification_slot",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68259",
"datePublished": "2026-08-10T12:01:33.110Z",
"dateReserved": "2026-07-30T09:28:09.378Z",
"dateUpdated": "2026-08-19T16:32:28.586Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72115 (GCVE-0-2026-72115)
Vulnerability from cvelistv5
Published
2026-08-15 05:52
Modified
2026-08-19 16:36
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
can: bcm: track a single source interface for ANYDEV timeout/throttle ops
An ANYDEV rx op (ifindex == 0) with an active RX timeout and/or
throttle timer has no defined semantics when matching frames arrive
from several interfaces: bcm_rx_handler() can run concurrently for
the same op on different CPUs, racing hrtimer_cancel()/
bcm_rx_starttimer() against bcm_rx_timeout_handler() and causing
spurious RX_TIMEOUT notifications and last_frames corruption. The
same concurrency lets throttled multiplex frames from different
interfaces clobber the single rx_ifindex/rx_stamp fields shared by
the op.
Add op->if_detected to track the first interface that delivers a
matching frame while a timeout/throttle timer is configured, and
reject frames from any other interface for that op. The claim is
decided in bcm_rx_handler() before hrtimer_cancel() touches
op->timer, so a rejected frame can never disturb the claimed
interface's watchdog. RTR-mode ops are excluded via RX_RTR_FRAME,
independent of kt_ival1/kt_ival2, since those may briefly hold a
stale value from an earlier non-RTR configuration.
The claim is released in bcm_notify() on NETDEV_UNREGISTER and in
bcm_rx_setup() when SETTIMER reconfigures the timer values.
A (re-)claim is only possible on CAN devices in NETREG_REGISTERED
dev->reg_state to cover the release in bcm_notify() where reg_state
becomes NETREG_UNREGISTERING until synchronize_net().
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/can/bcm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "f147f48837cb1426521f5b3c3b3134c71128a25d",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "57cf104da4cf450ae9c16801a3164604b801d2cc",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "03dfe347c398fa41a7e30e8dc538f12568c183e6",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "18b45251e74e35668f0dd0c470549384ae191ecf",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "3ff8c24b421070a2db99a5cdb86edc9ff339418e",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "eca8b44d51fc6ab61022258ec968e55e3073b79e",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "b6317022b685a430a3ae420456716e3c0c02ef4b",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "2f5976f54a04e9f18b25283036ac3136be453b17",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/can/bcm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.25"
},
{
"lessThan": "2.6.25",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.25",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: bcm: track a single source interface for ANYDEV timeout/throttle ops\n\nAn ANYDEV rx op (ifindex == 0) with an active RX timeout and/or\nthrottle timer has no defined semantics when matching frames arrive\nfrom several interfaces: bcm_rx_handler() can run concurrently for\nthe same op on different CPUs, racing hrtimer_cancel()/\nbcm_rx_starttimer() against bcm_rx_timeout_handler() and causing\nspurious RX_TIMEOUT notifications and last_frames corruption. The\nsame concurrency lets throttled multiplex frames from different\ninterfaces clobber the single rx_ifindex/rx_stamp fields shared by\nthe op.\n\nAdd op-\u003eif_detected to track the first interface that delivers a\nmatching frame while a timeout/throttle timer is configured, and\nreject frames from any other interface for that op. The claim is\ndecided in bcm_rx_handler() before hrtimer_cancel() touches\nop-\u003etimer, so a rejected frame can never disturb the claimed\ninterface\u0027s watchdog. RTR-mode ops are excluded via RX_RTR_FRAME,\nindependent of kt_ival1/kt_ival2, since those may briefly hold a\nstale value from an earlier non-RTR configuration.\n\nThe claim is released in bcm_notify() on NETDEV_UNREGISTER and in\nbcm_rx_setup() when SETTIMER reconfigures the timer values.\n\nA (re-)claim is only possible on CAN devices in NETREG_REGISTERED\ndev-\u003ereg_state to cover the release in bcm_notify() where reg_state\nbecomes NETREG_UNREGISTERING until synchronize_net()."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - bcm_rx_handler() is reached from the CAN driver RX path when matching frames arrive on multiple interfaces; on automotive/industrial systems an attacker on shared CAN segment(s) can inject concurrent frames without host shell access once an ANYDEV BCM RX op with active timeout/throttle timers exists.\nAC:L - The attacker controls both sides of the race by flooding matching frames on multiple CAN interfaces (or paired vcan devices) to run bcm_rx_handler() concurrently on different CPUs, racing hrtimer_cancel/bcm_rx_starttimer against bcm_rx_timeout_handler and interleaved last_frames writers.\nPR:N - No Linux capability or account is required to deliver triggering CAN traffic on multiple interfaces; bcm_rx_handler() runs from the unauthenticated netdev RX path once any ANYDEV BCM RX op with active kt_ival1/kt_ival2 timers exists, as commonly configured by telematics/diagnostic daemons.\nUI:N - Exploitation requires no victim interaction beyond normal system operation; malicious or concurrent CAN frames are processed automatically in softirq without mounts, file opens, or user prompts.\nS:U - Impact is confined to corrupted BCM state and incorrect CAN notifications delivered to the subscribing userspace process within the same kernel/host security boundary; no VM, container, or IOMMU escape is involved.\nC:H - Concurrent bcm_rx_handler() and bcm_rx_timeout_handler() races corrupt op-\u003elast_frames heap buffers via unsynchronized memcpy/memset, mixing attacker-controlled CAN payloads from different interfaces and leaking cross-bus frame content through bcm_send_to_user().\nI:H - last_frames corruption lets attacker-controlled frames from one interface overwrite or interleave with another\u0027s stored/throttled state, misattributing RX_CHANGED/RX_TIMEOUT notifications and corrupting safety- or security-relevant CAN monitoring and control decisions.\nA:N - The race corrupts per-op BCM buffers and emits spurious RX_TIMEOUT events but does not dereference freed objects, overrun buffer bounds, or fault the kernel; no oops, panic, hang, or sustained kernel denial of service is indicated."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:36:03.316Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/f147f48837cb1426521f5b3c3b3134c71128a25d"
},
{
"url": "https://git.kernel.org/stable/c/57cf104da4cf450ae9c16801a3164604b801d2cc"
},
{
"url": "https://git.kernel.org/stable/c/03dfe347c398fa41a7e30e8dc538f12568c183e6"
},
{
"url": "https://git.kernel.org/stable/c/18b45251e74e35668f0dd0c470549384ae191ecf"
},
{
"url": "https://git.kernel.org/stable/c/3ff8c24b421070a2db99a5cdb86edc9ff339418e"
},
{
"url": "https://git.kernel.org/stable/c/eca8b44d51fc6ab61022258ec968e55e3073b79e"
},
{
"url": "https://git.kernel.org/stable/c/b6317022b685a430a3ae420456716e3c0c02ef4b"
},
{
"url": "https://git.kernel.org/stable/c/2f5976f54a04e9f18b25283036ac3136be453b17"
}
],
"title": "can: bcm: track a single source interface for ANYDEV timeout/throttle ops",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72115",
"datePublished": "2026-08-15T05:52:55.524Z",
"dateReserved": "2026-08-09T03:40:39.906Z",
"dateUpdated": "2026-08-19T16:36:03.316Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68210 (GCVE-0-2026-68210)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: stm32: dcmi: unregister notifier on probe failure
dcmi_graph_init() registers the async notifier before dcmi_probe() toggles
the reset line. If reset_control_assert() or reset_control_deassert()
fails afterwards, probe returns through err_cleanup and the driver core
will not call dcmi_remove().
Unregister the notifier before cleaning it up on that error path,
matching the successful remove path and the V4L2 async notifier lifetime
rules.
[hverkuil: added Fixes tag]
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d079f94c90469f413920b9f2b201537fac2ceb06 Version: d079f94c90469f413920b9f2b201537fac2ceb06 Version: d079f94c90469f413920b9f2b201537fac2ceb06 Version: d079f94c90469f413920b9f2b201537fac2ceb06 Version: d079f94c90469f413920b9f2b201537fac2ceb06 Version: d079f94c90469f413920b9f2b201537fac2ceb06 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/platform/st/stm32/stm32-dcmi.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "222a9301b086852b90d3b092fef436c3f4e927c4",
"status": "affected",
"version": "d079f94c90469f413920b9f2b201537fac2ceb06",
"versionType": "git"
},
{
"lessThan": "37ff63c5d7119cbc5c6bacdcc658add6008a8e1f",
"status": "affected",
"version": "d079f94c90469f413920b9f2b201537fac2ceb06",
"versionType": "git"
},
{
"lessThan": "6c6f22b7e6cbc4e8c1e359fc9b190419391c3db7",
"status": "affected",
"version": "d079f94c90469f413920b9f2b201537fac2ceb06",
"versionType": "git"
},
{
"lessThan": "931abe1deb65b919d23fa203d7f6d6fbd4fccd8e",
"status": "affected",
"version": "d079f94c90469f413920b9f2b201537fac2ceb06",
"versionType": "git"
},
{
"lessThan": "4b7ee504969e074725e439c949f2483e5fa5572a",
"status": "affected",
"version": "d079f94c90469f413920b9f2b201537fac2ceb06",
"versionType": "git"
},
{
"lessThan": "084973ebd67b28f0945c5d45408f86c58b540110",
"status": "affected",
"version": "d079f94c90469f413920b9f2b201537fac2ceb06",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/platform/st/stm32/stm32-dcmi.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.20"
},
{
"lessThan": "4.20",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.20",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: stm32: dcmi: unregister notifier on probe failure\n\ndcmi_graph_init() registers the async notifier before dcmi_probe() toggles\nthe reset line. If reset_control_assert() or reset_control_deassert()\nfails afterwards, probe returns through err_cleanup and the driver core\nwill not call dcmi_remove().\n\nUnregister the notifier before cleaning it up on that error path,\nmatching the successful remove path and the V4L2 async notifier lifetime\nrules.\n\n[hverkuil: added Fixes tag]"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The affected code is a platform camera-interface driver probe path on STM32 SoCs; it is reached only through local device/driver binding on the machine itself, with the resulting dangling notifier consumed by in-kernel V4L2 subdev registration. No network or remote data path reaches this code.\nAC:L - Once the driver has probe-failed on the reset line, the stale notifier remains on the global v4l2 notifier_list indefinitely, and any subsequent subdev registration deterministically walks the freed object; no race or unpredictable memory layout must be won to reach the freed dereference.\nPR:L - A local user account on the device is sufficient to interact with the media/V4L2 stack and trigger subdev registration paths that walk the corrupted global notifier list; no root or administrative capability is needed to consume the dangling pointer.\nUI:N - The stale notifier is left behind automatically by the failing probe path and is dereferenced by kernel-internal V4L2 async registration; no victim action such as opening a file or mounting a filesystem is required.\nS:U - The freed memory, the corrupted list, and the resulting impact are all within the kernel\u0027s own security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - The devm-allocated stm32_dcmi object containing the notifier is freed while still linked into the global notifier_list, so reallocated heap contents are read back as notifier state and traversed as list pointers, which can be leveraged to disclose kernel memory.\nI:H - Traversal and eventual list_del of the freed notifier_entry performs writes through attacker-influenceable heap contents, giving a use-after-free list-corruption primitive that can be shaped into an arbitrary write and control-flow hijack.\nA:H - Dereferencing and unlinking a freed notifier from the global list reliably produces list corruption and an oops or panic in the V4L2 async core, taking down the kernel."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:34.517Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/222a9301b086852b90d3b092fef436c3f4e927c4"
},
{
"url": "https://git.kernel.org/stable/c/37ff63c5d7119cbc5c6bacdcc658add6008a8e1f"
},
{
"url": "https://git.kernel.org/stable/c/6c6f22b7e6cbc4e8c1e359fc9b190419391c3db7"
},
{
"url": "https://git.kernel.org/stable/c/931abe1deb65b919d23fa203d7f6d6fbd4fccd8e"
},
{
"url": "https://git.kernel.org/stable/c/4b7ee504969e074725e439c949f2483e5fa5572a"
},
{
"url": "https://git.kernel.org/stable/c/084973ebd67b28f0945c5d45408f86c58b540110"
}
],
"title": "media: stm32: dcmi: unregister notifier on probe failure",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68210",
"datePublished": "2026-08-10T12:00:29.515Z",
"dateReserved": "2026-07-30T09:28:09.375Z",
"dateUpdated": "2026-08-19T16:31:34.517Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68176 (GCVE-0-2026-68176)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
tracing: Fix mmiotrace possible NULL dereferencing of hiter->dev
If the mmio_pipe_open() fails to find a PCI device, the hiter->dev
will be assigned to NULL. The mmiotrace read() function dereferences the
hiter->dev if hiter exists.
Change the test of the read to not only check hiter being NULL, but also
the hiter->dev before dereferencing it.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: f984b51e0779a6dd30feedc41404013ca54e5d05 Version: f984b51e0779a6dd30feedc41404013ca54e5d05 Version: f984b51e0779a6dd30feedc41404013ca54e5d05 Version: f984b51e0779a6dd30feedc41404013ca54e5d05 Version: f984b51e0779a6dd30feedc41404013ca54e5d05 Version: f984b51e0779a6dd30feedc41404013ca54e5d05 Version: f984b51e0779a6dd30feedc41404013ca54e5d05 Version: f984b51e0779a6dd30feedc41404013ca54e5d05 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"kernel/trace/trace_mmiotrace.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c06470320f8156306986a831010cdc9f9f87cb50",
"status": "affected",
"version": "f984b51e0779a6dd30feedc41404013ca54e5d05",
"versionType": "git"
},
{
"lessThan": "0d5aaf91a3d05f7f993401af27872a5fc0f26edc",
"status": "affected",
"version": "f984b51e0779a6dd30feedc41404013ca54e5d05",
"versionType": "git"
},
{
"lessThan": "3635a9e8b453e658a49b39d025f35bbc6e58d0e2",
"status": "affected",
"version": "f984b51e0779a6dd30feedc41404013ca54e5d05",
"versionType": "git"
},
{
"lessThan": "faaf95135184208ee3ac6f33175c8d1800669dfc",
"status": "affected",
"version": "f984b51e0779a6dd30feedc41404013ca54e5d05",
"versionType": "git"
},
{
"lessThan": "201a01102c529772168181190cb084471082cf5c",
"status": "affected",
"version": "f984b51e0779a6dd30feedc41404013ca54e5d05",
"versionType": "git"
},
{
"lessThan": "8464427e1c177809a9488a97dfa2807d9dcf323b",
"status": "affected",
"version": "f984b51e0779a6dd30feedc41404013ca54e5d05",
"versionType": "git"
},
{
"lessThan": "724cd84b0546c07806840fa658714488553d13a2",
"status": "affected",
"version": "f984b51e0779a6dd30feedc41404013ca54e5d05",
"versionType": "git"
},
{
"lessThan": "144f29e85702234b23d2a62abf723e6a17eb5427",
"status": "affected",
"version": "f984b51e0779a6dd30feedc41404013ca54e5d05",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"kernel/trace/trace_mmiotrace.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.27"
},
{
"lessThan": "2.6.27",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.27",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.27",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.27",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.27",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.27",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.27",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.27",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.27",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Fix mmiotrace possible NULL dereferencing of hiter-\u003edev\n\nIf the mmio_pipe_open() fails to find a PCI device, the hiter-\u003edev\nwill be assigned to NULL. The mmiotrace read() function dereferences the\nhiter-\u003edev if hiter exists.\n\nChange the test of the read to not only check hiter being NULL, but also\nthe hiter-\u003edev before dereferencing it."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:30:41.982Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c06470320f8156306986a831010cdc9f9f87cb50"
},
{
"url": "https://git.kernel.org/stable/c/0d5aaf91a3d05f7f993401af27872a5fc0f26edc"
},
{
"url": "https://git.kernel.org/stable/c/3635a9e8b453e658a49b39d025f35bbc6e58d0e2"
},
{
"url": "https://git.kernel.org/stable/c/faaf95135184208ee3ac6f33175c8d1800669dfc"
},
{
"url": "https://git.kernel.org/stable/c/201a01102c529772168181190cb084471082cf5c"
},
{
"url": "https://git.kernel.org/stable/c/8464427e1c177809a9488a97dfa2807d9dcf323b"
},
{
"url": "https://git.kernel.org/stable/c/724cd84b0546c07806840fa658714488553d13a2"
},
{
"url": "https://git.kernel.org/stable/c/144f29e85702234b23d2a62abf723e6a17eb5427"
}
],
"title": "tracing: Fix mmiotrace possible NULL dereferencing of hiter-\u003edev",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68176",
"datePublished": "2026-08-10T11:59:47.298Z",
"dateReserved": "2026-07-30T09:28:09.372Z",
"dateUpdated": "2026-08-19T16:30:41.982Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74465 (GCVE-0-2026-74465)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-19 16:37
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: openvswitch: fix potential UAF on meter attach failure
While attaching a newly created meter attach_meter() function makes
the new meter visible to other CPUs but can still fail afterwards.
On failure, it detaches the meter back and returns an error.
However, this is an unexpected behavior for the ovs_meter_cmd_set()
that uses a plain kfree(meter) on attach failure without waiting for
RCU readers to stop using it, assuming it was never visible.
This is never a problem for ovs-vswitchd as it always creates meters
before creating any flows that use them. But the UAF can be triggered
with a custom application using uAPI:
BUG: KASAN: slab-use-after-free in ovs_meter_execute (net/openvswitch/meter.c:653)
Read of size 8 at addr ffff88810d152650 by task meter/2508
Call Trace:
ovs_meter_execute (net/openvswitch/meter.c:653)
do_execute_actions (net/openvswitch/actions.c:1407)
ovs_execute_actions (net/openvswitch/actions.c:1584)
ovs_packet_cmd_execute (net/openvswitch/datapath.c:703)
...
netlink_sendmsg (af_netlink.c:1900)
Allocated by task 2519:
__kasan_kmalloc (mm/kasan/common.c:398 mm/kasan/common.c:415)
ovs_meter_cmd_set (net/openvswitch/meter.c:422)
...
netlink_sendmsg (af_netlink.c:1900)
Freed by task 2519:
kfree (mm/slub.c:2705 mm/slub.c:6405 mm/slub.c:6720)
ovs_meter_cmd_set (net/openvswitch/meter.c:479)
...
netlink_sendmsg (af_netlink.c:1900)
Fix that by making sure attach_meter() doesn't make the meter visible
until all the checks are done and the function can't fail anymore.
This also makes sure the "hash" value is calculated after the potential
re-sizing of the table.
Reported by Trend Micro's Zero Day Initiative as ZDI-CAN-31642.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: c7c4c44c9a95d87e50ced38f7480e779cb472174 Version: c7c4c44c9a95d87e50ced38f7480e779cb472174 Version: c7c4c44c9a95d87e50ced38f7480e779cb472174 Version: c7c4c44c9a95d87e50ced38f7480e779cb472174 Version: c7c4c44c9a95d87e50ced38f7480e779cb472174 Version: c7c4c44c9a95d87e50ced38f7480e779cb472174 Version: c7c4c44c9a95d87e50ced38f7480e779cb472174 Version: c7c4c44c9a95d87e50ced38f7480e779cb472174 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/openvswitch/meter.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "496f3013c6ff759249abcfb2da2361c1a3e2e66d",
"status": "affected",
"version": "c7c4c44c9a95d87e50ced38f7480e779cb472174",
"versionType": "git"
},
{
"lessThan": "ddc0ef4217cc697c6ba1a295cc1ea42423ec68ac",
"status": "affected",
"version": "c7c4c44c9a95d87e50ced38f7480e779cb472174",
"versionType": "git"
},
{
"lessThan": "b0de3b58dac3b02b528f72ee0397728aed11f993",
"status": "affected",
"version": "c7c4c44c9a95d87e50ced38f7480e779cb472174",
"versionType": "git"
},
{
"lessThan": "0310d1fa7f9debd0d89629e9f14c7975a47eaa9a",
"status": "affected",
"version": "c7c4c44c9a95d87e50ced38f7480e779cb472174",
"versionType": "git"
},
{
"lessThan": "4d03e5fa3fbb1df15258a1eb3d6963f0d65659b3",
"status": "affected",
"version": "c7c4c44c9a95d87e50ced38f7480e779cb472174",
"versionType": "git"
},
{
"lessThan": "90623c9499627803ef3f04fa25a3199402d4fb95",
"status": "affected",
"version": "c7c4c44c9a95d87e50ced38f7480e779cb472174",
"versionType": "git"
},
{
"lessThan": "431a295d93f76fbdb6a7cfce92a9e3dfee1e5d61",
"status": "affected",
"version": "c7c4c44c9a95d87e50ced38f7480e779cb472174",
"versionType": "git"
},
{
"lessThan": "a58a2b0ce354df531ebc71fc870058c2feb59f6b",
"status": "affected",
"version": "c7c4c44c9a95d87e50ced38f7480e779cb472174",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/openvswitch/meter.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.8"
},
{
"lessThan": "5.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: openvswitch: fix potential UAF on meter attach failure\n\nWhile attaching a newly created meter attach_meter() function makes\nthe new meter visible to other CPUs but can still fail afterwards.\nOn failure, it detaches the meter back and returns an error.\n\nHowever, this is an unexpected behavior for the ovs_meter_cmd_set()\nthat uses a plain kfree(meter) on attach failure without waiting for\nRCU readers to stop using it, assuming it was never visible.\n\nThis is never a problem for ovs-vswitchd as it always creates meters\nbefore creating any flows that use them. But the UAF can be triggered\nwith a custom application using uAPI:\n\n BUG: KASAN: slab-use-after-free in ovs_meter_execute (net/openvswitch/meter.c:653)\n Read of size 8 at addr ffff88810d152650 by task meter/2508\n\n Call Trace:\n ovs_meter_execute (net/openvswitch/meter.c:653)\n do_execute_actions (net/openvswitch/actions.c:1407)\n ovs_execute_actions (net/openvswitch/actions.c:1584)\n ovs_packet_cmd_execute (net/openvswitch/datapath.c:703)\n ...\n netlink_sendmsg (af_netlink.c:1900)\n\n Allocated by task 2519:\n __kasan_kmalloc (mm/kasan/common.c:398 mm/kasan/common.c:415)\n ovs_meter_cmd_set (net/openvswitch/meter.c:422)\n ...\n netlink_sendmsg (af_netlink.c:1900)\n\n Freed by task 2519:\n kfree (mm/slub.c:2705 mm/slub.c:6405 mm/slub.c:6720)\n ovs_meter_cmd_set (net/openvswitch/meter.c:479)\n ...\n netlink_sendmsg (af_netlink.c:1900)\n\nFix that by making sure attach_meter() doesn\u0027t make the meter visible\nuntil all the checks are done and the function can\u0027t fail anymore.\n\nThis also makes sure the \"hash\" value is calculated after the potential\nre-sizing of the table.\n\nReported by Trend Micro\u0027s Zero Day Initiative as ZDI-CAN-31642."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The UAF is triggered when ovs_meter_cmd_set() fails attach_meter() and kfree()s the meter without an RCU grace period; that path is only reachable via the ovs_meter genetlink uAPI (netlink_sendmsg), not by remote packet reception alone.\nAC:L - The attacker controls both sides of the race by concurrently issuing OVS_METER_CMD_SET (forcing post-insert attach failure at max_meters or ENOMEM) and OVS_PACKET_CMD_EXECUTE or traffic on flows with OVS_ACTION_ATTR_METER while parallel_ops allows overlapping handlers.\nPR:L - OVS_METER_CMD_SET and OVS_PACKET_CMD_EXECUTE require CAP_NET_ADMIN checked with netlink_ns_capable() against the socket network namespace; unprivileged users can obtain CAP_NET_ADMIN in a user namespace (unshare -Urn) and the genl family is netnsok.\nUI:N - Exploitation requires only programmatic netlink API calls from the attacker; no victim user action such as opening files, mounting filesystems, or clicking prompts is needed.\nS:U - Successful exploitation compromises kernel memory and privileges on the same host/kernel security authority; it does not inherently cross a VM hypervisor, IOMMU, or hardware isolation boundary.\nC:H - This is a slab use-after-free: concurrent ovs_meter_execute() reads freed dp_meter fields (bands, stats, lock) via RCU lookup, enabling heap spraying and arbitrary kernel memory disclosure primitives.\nI:H - The UAF write path updates freed meter and band statistics, bucket counters, and takes a spinlock on freed memory, providing memory corruption primitives that can be developed into arbitrary kernel writes or code execution.\nA:H - KASAN reproduces slab-use-after-free in ovs_meter_execute during concurrent meter attach failure; UAF on the datapath fast path can cause kernel oops/panic or be abused for repeatable denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:37:07.822Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/496f3013c6ff759249abcfb2da2361c1a3e2e66d"
},
{
"url": "https://git.kernel.org/stable/c/ddc0ef4217cc697c6ba1a295cc1ea42423ec68ac"
},
{
"url": "https://git.kernel.org/stable/c/b0de3b58dac3b02b528f72ee0397728aed11f993"
},
{
"url": "https://git.kernel.org/stable/c/0310d1fa7f9debd0d89629e9f14c7975a47eaa9a"
},
{
"url": "https://git.kernel.org/stable/c/4d03e5fa3fbb1df15258a1eb3d6963f0d65659b3"
},
{
"url": "https://git.kernel.org/stable/c/90623c9499627803ef3f04fa25a3199402d4fb95"
},
{
"url": "https://git.kernel.org/stable/c/431a295d93f76fbdb6a7cfce92a9e3dfee1e5d61"
},
{
"url": "https://git.kernel.org/stable/c/a58a2b0ce354df531ebc71fc870058c2feb59f6b"
}
],
"title": "net: openvswitch: fix potential UAF on meter attach failure",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74465",
"datePublished": "2026-08-15T12:27:04.403Z",
"dateReserved": "2026-08-15T05:44:03.901Z",
"dateUpdated": "2026-08-19T16:37:07.822Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80909 (GCVE-0-2026-80909)
Vulnerability from cvelistv5
Published
2026-09-04 17:19
Modified
2026-09-07 14:21
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: Reject UVD message with invalid number of h265 refs
Same change as for h264, avoids overflow later when calculating
min dpb size.
(cherry picked from commit a4b0720e4f1601f97f59a2be9c1b4b94fa6527d5)
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 86fa0bdc6fd7b2debc07ce86f1bcd5fb254822e3 Version: 86fa0bdc6fd7b2debc07ce86f1bcd5fb254822e3 Version: 86fa0bdc6fd7b2debc07ce86f1bcd5fb254822e3 Version: 86fa0bdc6fd7b2debc07ce86f1bcd5fb254822e3 Version: 86fa0bdc6fd7b2debc07ce86f1bcd5fb254822e3 Version: 86fa0bdc6fd7b2debc07ce86f1bcd5fb254822e3 Version: 86fa0bdc6fd7b2debc07ce86f1bcd5fb254822e3 Version: 86fa0bdc6fd7b2debc07ce86f1bcd5fb254822e3 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/amdgpu_uvd.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "1facad2a78c1a8aeecc36eb4d560c7f1e10ce198",
"status": "affected",
"version": "86fa0bdc6fd7b2debc07ce86f1bcd5fb254822e3",
"versionType": "git"
},
{
"lessThan": "499907e5d46e575e96967c0230a0a6af980a17ab",
"status": "affected",
"version": "86fa0bdc6fd7b2debc07ce86f1bcd5fb254822e3",
"versionType": "git"
},
{
"lessThan": "cbf1c84bf5cac2b3742ea3d2085fa713424465cc",
"status": "affected",
"version": "86fa0bdc6fd7b2debc07ce86f1bcd5fb254822e3",
"versionType": "git"
},
{
"lessThan": "a930c54cb67200de8bc0de87480d09ece7dcd85d",
"status": "affected",
"version": "86fa0bdc6fd7b2debc07ce86f1bcd5fb254822e3",
"versionType": "git"
},
{
"lessThan": "2abcdc5f738574e7fcdd9417575dffb877fdc26f",
"status": "affected",
"version": "86fa0bdc6fd7b2debc07ce86f1bcd5fb254822e3",
"versionType": "git"
},
{
"lessThan": "e304c3e0d9ce251887be1f274aa0ed52219d5fd7",
"status": "affected",
"version": "86fa0bdc6fd7b2debc07ce86f1bcd5fb254822e3",
"versionType": "git"
},
{
"lessThan": "0acdf1a575f59bd46717d5c487d84575af5bee8f",
"status": "affected",
"version": "86fa0bdc6fd7b2debc07ce86f1bcd5fb254822e3",
"versionType": "git"
},
{
"lessThan": "9fca434208f1f9ab977feac62df8ebb1cc7ce893",
"status": "affected",
"version": "86fa0bdc6fd7b2debc07ce86f1bcd5fb254822e3",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/amdgpu_uvd.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.2"
},
{
"lessThan": "4.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.46",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.10",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Reject UVD message with invalid number of h265 refs\n\nSame change as for h264, avoids overflow later when calculating\nmin dpb size.\n\n(cherry picked from commit a4b0720e4f1601f97f59a2be9c1b4b94fa6527d5)"
}
],
"providerMetadata": {
"dateUpdated": "2026-09-07T14:21:32.011Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/1facad2a78c1a8aeecc36eb4d560c7f1e10ce198"
},
{
"url": "https://git.kernel.org/stable/c/499907e5d46e575e96967c0230a0a6af980a17ab"
},
{
"url": "https://git.kernel.org/stable/c/cbf1c84bf5cac2b3742ea3d2085fa713424465cc"
},
{
"url": "https://git.kernel.org/stable/c/a930c54cb67200de8bc0de87480d09ece7dcd85d"
},
{
"url": "https://git.kernel.org/stable/c/2abcdc5f738574e7fcdd9417575dffb877fdc26f"
},
{
"url": "https://git.kernel.org/stable/c/e304c3e0d9ce251887be1f274aa0ed52219d5fd7"
},
{
"url": "https://git.kernel.org/stable/c/0acdf1a575f59bd46717d5c487d84575af5bee8f"
},
{
"url": "https://git.kernel.org/stable/c/9fca434208f1f9ab977feac62df8ebb1cc7ce893"
}
],
"title": "drm/amdgpu: Reject UVD message with invalid number of h265 refs",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80909",
"datePublished": "2026-09-04T17:19:20.085Z",
"dateReserved": "2026-08-26T14:34:25.801Z",
"dateUpdated": "2026-09-07T14:21:32.011Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64082 (GCVE-0-2026-64082)
Vulnerability from cvelistv5
Published
2026-07-19 15:39
Modified
2026-09-02 12:49
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
riscv: Fix register corruption from uninitialized cregs on error
compat_riscv_gpr_set() calls cregs_to_regs() unconditionally, even when
user_regset_copyin() fails. Since cregs is an uninitialized stack
variable, a copyin failure causes uninitialized stack data to be written
into the target task's pt_regs, corrupting its register state and
potentially leaking kernel stack contents.
compat_restore_sigcontext() has the same issue: it calls cregs_to_regs()
even when __copy_from_user() fails, leading to the same corruption of
the signal-returning task's register state on error.
Only call cregs_to_regs() when the user copy succeeds.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 7383ee05314be58f8f9f018ee0ac53bef3808aea Version: 7383ee05314be58f8f9f018ee0ac53bef3808aea Version: 7383ee05314be58f8f9f018ee0ac53bef3808aea Version: 7383ee05314be58f8f9f018ee0ac53bef3808aea Version: 7383ee05314be58f8f9f018ee0ac53bef3808aea Version: 7383ee05314be58f8f9f018ee0ac53bef3808aea |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"arch/riscv/kernel/compat_signal.c",
"arch/riscv/kernel/ptrace.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "f2d88b0d7aebfa4643fc58bbae57210c6daff9c6",
"status": "affected",
"version": "7383ee05314be58f8f9f018ee0ac53bef3808aea",
"versionType": "git"
},
{
"lessThan": "66dedb6028c3df6c6a3372dd935b823917e150d5",
"status": "affected",
"version": "7383ee05314be58f8f9f018ee0ac53bef3808aea",
"versionType": "git"
},
{
"lessThan": "2a7d1daf2674fe7d5b1cc99a4e3b5f0f72d5958f",
"status": "affected",
"version": "7383ee05314be58f8f9f018ee0ac53bef3808aea",
"versionType": "git"
},
{
"lessThan": "0599aa23734c48de9bce36d043a9ec90c23945a1",
"status": "affected",
"version": "7383ee05314be58f8f9f018ee0ac53bef3808aea",
"versionType": "git"
},
{
"lessThan": "9e020156833f1ad0d425a1e3d85b65639f1c1c50",
"status": "affected",
"version": "7383ee05314be58f8f9f018ee0ac53bef3808aea",
"versionType": "git"
},
{
"lessThan": "6ebcbb53fc9bc30843054ed99fd60b8e542628f4",
"status": "affected",
"version": "7383ee05314be58f8f9f018ee0ac53bef3808aea",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"arch/riscv/kernel/compat_signal.c",
"arch/riscv/kernel/ptrace.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.19"
},
{
"lessThan": "5.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.187",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.156",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.108",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.49",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.187",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.156",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.108",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.49",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "5.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nriscv: Fix register corruption from uninitialized cregs on error\n\ncompat_riscv_gpr_set() calls cregs_to_regs() unconditionally, even when\nuser_regset_copyin() fails. Since cregs is an uninitialized stack\nvariable, a copyin failure causes uninitialized stack data to be written\ninto the target task\u0027s pt_regs, corrupting its register state and\npotentially leaking kernel stack contents.\n\ncompat_restore_sigcontext() has the same issue: it calls cregs_to_regs()\neven when __copy_from_user() fails, leading to the same corruption of\nthe signal-returning task\u0027s register state on error.\n\nOnly call cregs_to_regs() when the user copy succeeds."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is only reachable through local kernel interfaces\u2014compat_rt_sigreturn and ptrace(PTRACE_SETREGSET)\u2014with no network, adjacent-radio, or physical-device code path involved.\nAC:L - An attacker can reliably force the user copy to fail by racing munmap/mprotect against sigreturn or ptrace SETREGSET after access_ok, controlling both sides of the TOCTOU window.\nPR:L - The lowest-privilege path is compat_rt_sigreturn, callable by any unprivileged 32-bit compat process on a CONFIG_COMPAT RISC-V system without capabilities or root.\nUI:N - Exploitation requires no victim interaction; a local attacker corrupts their own task\u2019s registers via rt_sigreturn or a tracee they already control as parent/tracer.\nS:U - Impact is confined to kernel register-state corruption and information disclosure within the same OS security boundary, not a VM escape or cross-authority sandbox breakout.\nC:H - On copy failure, uninitialized kernel stack data (up to the full compat_user_regs_struct) is written into pt_regs, leaking kernel memory contents into user-observable registers.\nI:H - The corruption overwrites all general-purpose registers in pt_regs\u2014including program counter, stack pointer, and return address\u2014constituting memory corruption exploitable for control-flow hijacking.\nA:H - Corrupted pt_regs reliably cause faults, SIGSEGV delivery, or erratic kernel/user execution, and the condition is repeatable for persistent denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-02T12:49:41.782Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/f2d88b0d7aebfa4643fc58bbae57210c6daff9c6"
},
{
"url": "https://git.kernel.org/stable/c/66dedb6028c3df6c6a3372dd935b823917e150d5"
},
{
"url": "https://git.kernel.org/stable/c/2a7d1daf2674fe7d5b1cc99a4e3b5f0f72d5958f"
},
{
"url": "https://git.kernel.org/stable/c/0599aa23734c48de9bce36d043a9ec90c23945a1"
},
{
"url": "https://git.kernel.org/stable/c/9e020156833f1ad0d425a1e3d85b65639f1c1c50"
},
{
"url": "https://git.kernel.org/stable/c/6ebcbb53fc9bc30843054ed99fd60b8e542628f4"
}
],
"title": "riscv: Fix register corruption from uninitialized cregs on error",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64082",
"datePublished": "2026-07-19T15:39:54.074Z",
"dateReserved": "2026-07-19T07:54:57.031Z",
"dateUpdated": "2026-09-02T12:49:41.782Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74498 (GCVE-0-2026-74498)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-19 16:37
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ALSA: usb-audio: Fix DMA buffer out-of-bounds write when fill_max is set
When a USB audio endpoint requests full packet transfers via the fill_max
descriptor flag, data_ep_set_params() promotes ep->curpacksize to
ep->maxpacksize. However, maxsize is left at the original sample-rate
derived value.
Since u->buffer_size is allocated as maxsize * packets, the resulting
DMA buffer is far too small for the requested transfer length. When the
USB host controller streams up to curpacksize bytes per packet, it writes
past the end of the buffer via DMA, corrupting kernel heap memory.
Update maxsize to curpacksize when fill_max is set so that the allocated
DMA buffer size matches the actual transfer request size.
[ changed to reassign maxsize only when ep->fill_max is set -- tiwai ]
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 8fdff6a319e7dac757c558bd283dc4577e68cde7 Version: 8fdff6a319e7dac757c558bd283dc4577e68cde7 Version: 8fdff6a319e7dac757c558bd283dc4577e68cde7 Version: 8fdff6a319e7dac757c558bd283dc4577e68cde7 Version: 8fdff6a319e7dac757c558bd283dc4577e68cde7 Version: 8fdff6a319e7dac757c558bd283dc4577e68cde7 Version: 8fdff6a319e7dac757c558bd283dc4577e68cde7 Version: 8fdff6a319e7dac757c558bd283dc4577e68cde7 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"sound/usb/endpoint.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "10c24e6fddf4bdff0b6b05a47a4347b38e6960e8",
"status": "affected",
"version": "8fdff6a319e7dac757c558bd283dc4577e68cde7",
"versionType": "git"
},
{
"lessThan": "b1770f9ac35c0ffc34914d52347c65dcd5ac049b",
"status": "affected",
"version": "8fdff6a319e7dac757c558bd283dc4577e68cde7",
"versionType": "git"
},
{
"lessThan": "6cbdd11f9b05b92f4aa29f09a66e19ed0e25e66c",
"status": "affected",
"version": "8fdff6a319e7dac757c558bd283dc4577e68cde7",
"versionType": "git"
},
{
"lessThan": "3852974608f53e530e27c21d0c6c7d79c17b3f5a",
"status": "affected",
"version": "8fdff6a319e7dac757c558bd283dc4577e68cde7",
"versionType": "git"
},
{
"lessThan": "f9b6c9576568169139ac151f7881474f384659fd",
"status": "affected",
"version": "8fdff6a319e7dac757c558bd283dc4577e68cde7",
"versionType": "git"
},
{
"lessThan": "04595233e5606d452f9f47e6989fc7ae7440fd40",
"status": "affected",
"version": "8fdff6a319e7dac757c558bd283dc4577e68cde7",
"versionType": "git"
},
{
"lessThan": "bd65b7191683bebd9923904f0558b9211b9129da",
"status": "affected",
"version": "8fdff6a319e7dac757c558bd283dc4577e68cde7",
"versionType": "git"
},
{
"lessThan": "d0199ae1666ff9ae2d1d568d64c3430d4c47f0e5",
"status": "affected",
"version": "8fdff6a319e7dac757c558bd283dc4577e68cde7",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"sound/usb/endpoint.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.5"
},
{
"lessThan": "3.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: usb-audio: Fix DMA buffer out-of-bounds write when fill_max is set\n\nWhen a USB audio endpoint requests full packet transfers via the fill_max\ndescriptor flag, data_ep_set_params() promotes ep-\u003ecurpacksize to\nep-\u003emaxpacksize. However, maxsize is left at the original sample-rate\nderived value.\n\nSince u-\u003ebuffer_size is allocated as maxsize * packets, the resulting\nDMA buffer is far too small for the requested transfer length. When the\nUSB host controller streams up to curpacksize bytes per packet, it writes\npast the end of the buffer via DMA, corrupting kernel heap memory.\n\nUpdate maxsize to curpacksize when fill_max is set so that the allocated\nDMA buffer size matches the actual transfer request size.\n\n[ changed to reassign maxsize only when ep-\u003efill_max is set -- tiwai ]"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:37:57.897Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/10c24e6fddf4bdff0b6b05a47a4347b38e6960e8"
},
{
"url": "https://git.kernel.org/stable/c/b1770f9ac35c0ffc34914d52347c65dcd5ac049b"
},
{
"url": "https://git.kernel.org/stable/c/6cbdd11f9b05b92f4aa29f09a66e19ed0e25e66c"
},
{
"url": "https://git.kernel.org/stable/c/3852974608f53e530e27c21d0c6c7d79c17b3f5a"
},
{
"url": "https://git.kernel.org/stable/c/f9b6c9576568169139ac151f7881474f384659fd"
},
{
"url": "https://git.kernel.org/stable/c/04595233e5606d452f9f47e6989fc7ae7440fd40"
},
{
"url": "https://git.kernel.org/stable/c/bd65b7191683bebd9923904f0558b9211b9129da"
},
{
"url": "https://git.kernel.org/stable/c/d0199ae1666ff9ae2d1d568d64c3430d4c47f0e5"
}
],
"title": "ALSA: usb-audio: Fix DMA buffer out-of-bounds write when fill_max is set",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74498",
"datePublished": "2026-08-15T12:27:25.123Z",
"dateReserved": "2026-08-15T05:44:03.907Z",
"dateUpdated": "2026-08-19T16:37:57.897Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68428 (GCVE-0-2026-68428)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-19 16:35
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
KVM: x86/mmu: Fix use-after-free on vendor module reload
mmu_destroy_caches() destroys pte_list_desc_cache and
mmu_page_header_cache, but leaves both pointers unchanged. The pointers
live in kvm.ko, and therefore survive when a vendor module is unloaded
while kvm.ko remains loaded.
If creation of pte_list_desc_cache fails during a subsequent vendor
module load, its assignment sets pte_list_desc_cache to NULL and the
error path calls mmu_destroy_caches(). mmu_page_header_cache still
points to the cache destroyed during the preceding vendor module
unload. Passing that stale pointer to kmem_cache_destroy() causes a
slab use-after-free.
Reproduce the issue on a v7.1.3 kernel with CONFIG_KASAN=y,
CONFIG_KASAN_GENERIC=y, CONFIG_KVM=m, and CONFIG_KVM_INTEL=m. A
one-shot test hook forces pte_list_desc_cache to NULL on the second
invocation of kvm_mmu_vendor_module_init():
1. Load kvm.ko and kvm-intel.ko, creating both caches.
2. Unload only kvm_intel, leaving kvm.ko loaded.
3. Reload kvm_intel and force initialization through the -ENOMEM path.
KASAN reports:
BUG: KASAN: slab-use-after-free in
kvm_mmu_vendor_module_init+0x5b/0x170 [kvm]
...
kmem_cache_destroy+0x21/0x1d0
kvm_mmu_vendor_module_init+0x5b/0x170 [kvm]
...
Allocated by task 16817:
__kmem_cache_create_args+0x12c/0x3b0
__kmem_cache_create.constprop.0+0xb6/0xf0 [kvm]
kvm_mmu_vendor_module_init+0x13b/0x170 [kvm]
...
Freed by task 16820:
kmem_cache_destroy+0x117/0x1d0
kvm_mmu_vendor_module_exit+0x21/0x30 [kvm]
Clear both pointers immediately after destroying their caches so that
the stored state reflects the caches' lifetime and repeated cleanup is
safe.
With the fix applied, the same injected vendor module reload fails with
-ENOMEM as expected and produces no KASAN report.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: cb498ea2ce1d3f3c0bc0a2522241dca10263e437 Version: cb498ea2ce1d3f3c0bc0a2522241dca10263e437 Version: cb498ea2ce1d3f3c0bc0a2522241dca10263e437 Version: cb498ea2ce1d3f3c0bc0a2522241dca10263e437 Version: cb498ea2ce1d3f3c0bc0a2522241dca10263e437 Version: cb498ea2ce1d3f3c0bc0a2522241dca10263e437 Version: cb498ea2ce1d3f3c0bc0a2522241dca10263e437 Version: cb498ea2ce1d3f3c0bc0a2522241dca10263e437 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"arch/x86/kvm/mmu/mmu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "034b7fa1f5846d69eb51f12ce6d1c71871e83c2d",
"status": "affected",
"version": "cb498ea2ce1d3f3c0bc0a2522241dca10263e437",
"versionType": "git"
},
{
"lessThan": "42272b0f239f3a89f9c26a01cc37aee06138b1b7",
"status": "affected",
"version": "cb498ea2ce1d3f3c0bc0a2522241dca10263e437",
"versionType": "git"
},
{
"lessThan": "940950d5cd86f250dca578279ad5ca63b4e0986b",
"status": "affected",
"version": "cb498ea2ce1d3f3c0bc0a2522241dca10263e437",
"versionType": "git"
},
{
"lessThan": "6f4be73880302d5642c83a0813fdfe1f5fd4b6e3",
"status": "affected",
"version": "cb498ea2ce1d3f3c0bc0a2522241dca10263e437",
"versionType": "git"
},
{
"lessThan": "32b9f89ed9e6d7a45075d64089c254a7f6e13695",
"status": "affected",
"version": "cb498ea2ce1d3f3c0bc0a2522241dca10263e437",
"versionType": "git"
},
{
"lessThan": "ec9daa8fd1b6f45545c9839dca55bd867fad9e13",
"status": "affected",
"version": "cb498ea2ce1d3f3c0bc0a2522241dca10263e437",
"versionType": "git"
},
{
"lessThan": "43cfb20d62ffe49626d62beecfc32eb6f262191c",
"status": "affected",
"version": "cb498ea2ce1d3f3c0bc0a2522241dca10263e437",
"versionType": "git"
},
{
"lessThan": "52f2f7c30126037975389aa04d24c506a5177c35",
"status": "affected",
"version": "cb498ea2ce1d3f3c0bc0a2522241dca10263e437",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"arch/x86/kvm/mmu/mmu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.25"
},
{
"lessThan": "2.6.25",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.25",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: x86/mmu: Fix use-after-free on vendor module reload\n\nmmu_destroy_caches() destroys pte_list_desc_cache and\nmmu_page_header_cache, but leaves both pointers unchanged. The pointers\nlive in kvm.ko, and therefore survive when a vendor module is unloaded\nwhile kvm.ko remains loaded.\n\nIf creation of pte_list_desc_cache fails during a subsequent vendor\nmodule load, its assignment sets pte_list_desc_cache to NULL and the\nerror path calls mmu_destroy_caches(). mmu_page_header_cache still\npoints to the cache destroyed during the preceding vendor module\nunload. Passing that stale pointer to kmem_cache_destroy() causes a\nslab use-after-free.\n\nReproduce the issue on a v7.1.3 kernel with CONFIG_KASAN=y,\nCONFIG_KASAN_GENERIC=y, CONFIG_KVM=m, and CONFIG_KVM_INTEL=m. A\none-shot test hook forces pte_list_desc_cache to NULL on the second\ninvocation of kvm_mmu_vendor_module_init():\n\n 1. Load kvm.ko and kvm-intel.ko, creating both caches.\n 2. Unload only kvm_intel, leaving kvm.ko loaded.\n 3. Reload kvm_intel and force initialization through the -ENOMEM path.\n\nKASAN reports:\n\n BUG: KASAN: slab-use-after-free in\n kvm_mmu_vendor_module_init+0x5b/0x170 [kvm]\n ...\n kmem_cache_destroy+0x21/0x1d0\n kvm_mmu_vendor_module_init+0x5b/0x170 [kvm]\n ...\n Allocated by task 16817:\n __kmem_cache_create_args+0x12c/0x3b0\n __kmem_cache_create.constprop.0+0xb6/0xf0 [kvm]\n kvm_mmu_vendor_module_init+0x13b/0x170 [kvm]\n ...\n Freed by task 16820:\n kmem_cache_destroy+0x117/0x1d0\n kvm_mmu_vendor_module_exit+0x21/0x30 [kvm]\n\nClear both pointers immediately after destroying their caches so that\nthe stored state reflects the caches\u0027 lifetime and repeated cleanup is\nsafe.\n\nWith the fix applied, the same injected vendor module reload fails with\n-ENOMEM as expected and produces no KASAN report."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:35:25.214Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/034b7fa1f5846d69eb51f12ce6d1c71871e83c2d"
},
{
"url": "https://git.kernel.org/stable/c/42272b0f239f3a89f9c26a01cc37aee06138b1b7"
},
{
"url": "https://git.kernel.org/stable/c/940950d5cd86f250dca578279ad5ca63b4e0986b"
},
{
"url": "https://git.kernel.org/stable/c/6f4be73880302d5642c83a0813fdfe1f5fd4b6e3"
},
{
"url": "https://git.kernel.org/stable/c/32b9f89ed9e6d7a45075d64089c254a7f6e13695"
},
{
"url": "https://git.kernel.org/stable/c/ec9daa8fd1b6f45545c9839dca55bd867fad9e13"
},
{
"url": "https://git.kernel.org/stable/c/43cfb20d62ffe49626d62beecfc32eb6f262191c"
},
{
"url": "https://git.kernel.org/stable/c/52f2f7c30126037975389aa04d24c506a5177c35"
}
],
"title": "KVM: x86/mmu: Fix use-after-free on vendor module reload",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68428",
"datePublished": "2026-08-10T12:04:48.905Z",
"dateReserved": "2026-07-30T09:28:09.393Z",
"dateUpdated": "2026-08-19T16:35:25.214Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80527 (GCVE-0-2026-80527)
Vulnerability from cvelistv5
Published
2026-08-26 14:37
Modified
2026-08-27 05:01
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ceph: fix hanging __ceph_get_caps() with stale mds_wanted
A reader can hang forever in __ceph_get_caps() when the client no
longer holds `FILE_RD`, but local cap state still says that the
capability is already wanted (via `mds_wanted`).
One way to trigger this is through MDS cap revocation. If another
client performs a conflicting operation, the MDS can revoke `FILE_RD`
from the reader; the next read then has to reacquire `FILE_RD`. If
the cap update that should request `FILE_RD` never reaches the MDS
after `cap->mds_wanted` was raised, the reader is left holding only
non-file caps while local `mds_wanted` still includes the file read
caps.
In that state, try_get_cap_refs() sees `need <= mds_wanted` and
returns 0, so __ceph_get_caps() just waits on `i_cap_wq`. If the cap
update that was supposed to request `FILE_RD never reaches the MDS
after `cap->mds_wanted was` raised, no further request is sent and the
waiter can sleep indefinitely until unrelated cap traffic happens to
wake it up.
The ordering issue is that `cap->mds_wanted` is updated in
__prep_cap() before the `CEPH_MSG_CLIENT_CAPS message` is actually
queued for send. That makes one field serve two different meanings at
once: what this client wants, and what the client believes the MDS
already knows it wants.
A proper fix would be to split those states and track whether a cap
update is actually in flight or has been observed by the MDS.
However, simply moving the `cap->mds_wanted assignment` later would
not be sufficient: queueing the message in the messenger does not
guarantee that the MDS processed that specific wanted set, and
reconnect or message loss can still invalidate that assumption.
Fixing that properly would require a larger rework of the cap state
machine.
To allow simpler backports to stable kernels, this patch implements a
simpler workaround:
- stop waiting forever in __ceph_get_caps(); after a bounded wait,
fall back to the renew path
- make ceph_renew_caps() issue a synchronous `OPEN` request whenever
the inode still does not actually hold the wanted caps, instead of
only calling ceph_check_caps()
The extra issued-vs-wanted check in ceph_renew_caps() is necessary
because the previous test only checked whether the inode still had any
real caps at all. That is not enough after revocation: the client can
still hold something like `pLs` and yet be missing `FILE_RD`
completely. In that case, falling back to ceph_check_caps() is not
sufficient, because it still trusts `cap->mds_wanted` and may resend
nothing. By requiring `(issued & wanted) == wanted` before taking the
asynchronous path, the code only uses ceph_check_caps() when the
`wanted caps` are already actually issued. Otherwise, it sends the
synchronous `OPEN` renew.
This preserves the existing asynchronous fast path when the wanted
caps are already issued, avoids changing cap-state semantics, and
fixes the hang by guaranteeing that a stalled waiter eventually
retries through a path that does not rely on the stale `mds_wanted`
state.
[ idryomov: move CEPH_GET_CAPS_WAIT_TIMEOUT from libceph.h to
mds_client.h, formatting ]
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 0a454bdd501ad1aa30bb72e9581efa338ad6ce5c Version: 0a454bdd501ad1aa30bb72e9581efa338ad6ce5c Version: 0a454bdd501ad1aa30bb72e9581efa338ad6ce5c Version: 0a454bdd501ad1aa30bb72e9581efa338ad6ce5c Version: 0a454bdd501ad1aa30bb72e9581efa338ad6ce5c Version: 0a454bdd501ad1aa30bb72e9581efa338ad6ce5c Version: 0a454bdd501ad1aa30bb72e9581efa338ad6ce5c Version: 0a454bdd501ad1aa30bb72e9581efa338ad6ce5c |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/ceph/caps.c",
"fs/ceph/file.c",
"fs/ceph/mds_client.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b5661524c5a45085a866864ca9b8ae2513dfd67a",
"status": "affected",
"version": "0a454bdd501ad1aa30bb72e9581efa338ad6ce5c",
"versionType": "git"
},
{
"lessThan": "5e84bc6f67e19fdd192d8b215de728acbfc12572",
"status": "affected",
"version": "0a454bdd501ad1aa30bb72e9581efa338ad6ce5c",
"versionType": "git"
},
{
"lessThan": "5fedf279a1ea369d39c8b06dd4547cdc576065d0",
"status": "affected",
"version": "0a454bdd501ad1aa30bb72e9581efa338ad6ce5c",
"versionType": "git"
},
{
"lessThan": "e05c315b4da0c16ea800ee4b2cb6c617f586d1b5",
"status": "affected",
"version": "0a454bdd501ad1aa30bb72e9581efa338ad6ce5c",
"versionType": "git"
},
{
"lessThan": "fcce1b3be6d286aa80831e730289f4c062053ae6",
"status": "affected",
"version": "0a454bdd501ad1aa30bb72e9581efa338ad6ce5c",
"versionType": "git"
},
{
"lessThan": "a3bc6b3e9ef3f5f5cb85a902a30a090c7931127c",
"status": "affected",
"version": "0a454bdd501ad1aa30bb72e9581efa338ad6ce5c",
"versionType": "git"
},
{
"lessThan": "9e55fe24c548ad3163903eb58bb002d28d32a630",
"status": "affected",
"version": "0a454bdd501ad1aa30bb72e9581efa338ad6ce5c",
"versionType": "git"
},
{
"lessThan": "50958bb928bad3bdba9e5d1b7ff4bbadcf6951e6",
"status": "affected",
"version": "0a454bdd501ad1aa30bb72e9581efa338ad6ce5c",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/ceph/caps.c",
"fs/ceph/file.c",
"fs/ceph/mds_client.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.8"
},
{
"lessThan": "5.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.46",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.10",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nceph: fix hanging __ceph_get_caps() with stale mds_wanted\n\nA reader can hang forever in __ceph_get_caps() when the client no\nlonger holds `FILE_RD`, but local cap state still says that the\ncapability is already wanted (via `mds_wanted`).\n\nOne way to trigger this is through MDS cap revocation. If another\nclient performs a conflicting operation, the MDS can revoke `FILE_RD`\nfrom the reader; the next read then has to reacquire `FILE_RD`. If\nthe cap update that should request `FILE_RD` never reaches the MDS\nafter `cap-\u003emds_wanted` was raised, the reader is left holding only\nnon-file caps while local `mds_wanted` still includes the file read\ncaps.\n\nIn that state, try_get_cap_refs() sees `need \u003c= mds_wanted` and\nreturns 0, so __ceph_get_caps() just waits on `i_cap_wq`. If the cap\nupdate that was supposed to request `FILE_RD never reaches the MDS\nafter `cap-\u003emds_wanted was` raised, no further request is sent and the\nwaiter can sleep indefinitely until unrelated cap traffic happens to\nwake it up.\n\nThe ordering issue is that `cap-\u003emds_wanted` is updated in\n__prep_cap() before the `CEPH_MSG_CLIENT_CAPS message` is actually\nqueued for send. That makes one field serve two different meanings at\nonce: what this client wants, and what the client believes the MDS\nalready knows it wants.\n\nA proper fix would be to split those states and track whether a cap\nupdate is actually in flight or has been observed by the MDS.\nHowever, simply moving the `cap-\u003emds_wanted assignment` later would\nnot be sufficient: queueing the message in the messenger does not\nguarantee that the MDS processed that specific wanted set, and\nreconnect or message loss can still invalidate that assumption.\nFixing that properly would require a larger rework of the cap state\nmachine.\n\nTo allow simpler backports to stable kernels, this patch implements a\nsimpler workaround:\n\n- stop waiting forever in __ceph_get_caps(); after a bounded wait,\n fall back to the renew path\n\n- make ceph_renew_caps() issue a synchronous `OPEN` request whenever\n the inode still does not actually hold the wanted caps, instead of\n only calling ceph_check_caps()\n\nThe extra issued-vs-wanted check in ceph_renew_caps() is necessary\nbecause the previous test only checked whether the inode still had any\nreal caps at all. That is not enough after revocation: the client can\nstill hold something like `pLs` and yet be missing `FILE_RD`\ncompletely. In that case, falling back to ceph_check_caps() is not\nsufficient, because it still trusts `cap-\u003emds_wanted` and may resend\nnothing. By requiring `(issued \u0026 wanted) == wanted` before taking the\nasynchronous path, the code only uses ceph_check_caps() when the\n`wanted caps` are already actually issued. Otherwise, it sends the\nsynchronous `OPEN` renew.\n\nThis preserves the existing asynchronous fast path when the wanted\ncaps are already issued, avoids changing cap-state semantics, and\nfixes the hang by guaranteeing that a stalled waiter eventually\nretries through a path that does not rely on the stale `mds_wanted`\nstate.\n\n[ idryomov: move CEPH_GET_CAPS_WAIT_TIMEOUT from libceph.h to\n mds_client.h, formatting ]"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - On nodes with cephfs mounted (common in Ceph/Rook/Kubernetes), a remote Ceph client can perform conflicting writes so the MDS revokes FILE_RD via CEPH_MSG_CLIENT_CAPS over the network; the victim kernel then hits the stale mds_wanted hang on the next VFS read/mmap/ioctl path into __ceph_get_caps().\nAC:L - The fix commit documents MDS cap revocation from another client as a reliable trigger; an attacker controls both sides by holding a second Ceph client session and driving conflicting I/O and reconnect/message-loss timing, without depending on uncontrollable victim heap layout or rare kernel configs.\nPR:N - Exploitation requires no Linux account, capability, or init-namespace root on the victim host; any remote (or co-tenant) Ceph client with write access to the shared file can induce revocation and the hang while victims only perform normal reads on an already-mounted cephfs export.\nUI:N - No interactive victim action is needed beyond routine automated reads on cephfs-backed workloads; the attacker does not require the victim to mount media, click a link, or perform a one-off administrative step at exploitation time.\nS:U - Impact is confined to threads blocked in __ceph_get_caps() on the same host kernel security domain; it does not cross VM, container, or IOMMU boundaries or grant elevated privileges beyond availability loss on the affected client.\nC:N - This is a capability wait-loop logic error with no out-of-bounds access, use-after-free, or information disclosure; stale mds_wanted only prevents cap reacquisition and does not read or leak kernel or file data to an attacker.\nI:N - The bug does not modify inode data, kernel memory, or capabilities; it causes indefinite sleeping in cap acquisition with no path to arbitrary write, metadata corruption, or code execution.\nA:H - Before the fix, __ceph_get_caps() could wait forever on i_cap_wq when mds_wanted falsely indicated FILE_RD was already requested but not issued, hanging the reader thread (read/write/mmap/getattr) until unrelated cap traffic; repeated exploitation can deny service to cephfs-backed applications."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T05:01:22.018Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b5661524c5a45085a866864ca9b8ae2513dfd67a"
},
{
"url": "https://git.kernel.org/stable/c/5e84bc6f67e19fdd192d8b215de728acbfc12572"
},
{
"url": "https://git.kernel.org/stable/c/5fedf279a1ea369d39c8b06dd4547cdc576065d0"
},
{
"url": "https://git.kernel.org/stable/c/e05c315b4da0c16ea800ee4b2cb6c617f586d1b5"
},
{
"url": "https://git.kernel.org/stable/c/fcce1b3be6d286aa80831e730289f4c062053ae6"
},
{
"url": "https://git.kernel.org/stable/c/a3bc6b3e9ef3f5f5cb85a902a30a090c7931127c"
},
{
"url": "https://git.kernel.org/stable/c/9e55fe24c548ad3163903eb58bb002d28d32a630"
},
{
"url": "https://git.kernel.org/stable/c/50958bb928bad3bdba9e5d1b7ff4bbadcf6951e6"
}
],
"title": "ceph: fix hanging __ceph_get_caps() with stale mds_wanted",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80527",
"datePublished": "2026-08-26T14:37:06.178Z",
"dateReserved": "2026-08-26T14:34:25.764Z",
"dateUpdated": "2026-08-27T05:01:22.018Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74519 (GCVE-0-2026-74519)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-19 16:38
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
pinctrl: devicetree: don't free uninitialized dev_name on error path
dt_remember_or_free_map() duplicates dev_name for each map entry. If
kstrdup_const() fails, dt_free_map() frees dev_name in all num_maps
entries, including entries that have not been initialized.
Some pinctrl drivers, including pinctrl-imx, allocate the map with
kmalloc() and leave dev_name for the core to initialize. The untouched
entries therefore contain uninitialized data which is passed to
kfree_const().
Reproduced on qemu's mcimx6ul-evk (pinctrl-imx) with failslab injection
while binding the pinctrl-consuming device, under KASAN:
BUG: KASAN: double-free in dt_free_map+0x34/0xa4
Free of addr c425a900 by task init/1
kfree from dt_free_map+0x34/0xa4
dt_free_map from dt_remember_or_free_map+0x184/0x198
dt_remember_or_free_map from pinctrl_dt_to_map+0x33c/0x4c8
pinctrl_dt_to_map from create_pinctrl+0x9c/0x5c0
Initialize all dev_name fields to NULL before duplicating the device
name, making the full-map cleanup safe after a partial failure.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: be4c60b563edee3712d392aaeb0943a768df7023 Version: be4c60b563edee3712d392aaeb0943a768df7023 Version: be4c60b563edee3712d392aaeb0943a768df7023 Version: be4c60b563edee3712d392aaeb0943a768df7023 Version: be4c60b563edee3712d392aaeb0943a768df7023 Version: be4c60b563edee3712d392aaeb0943a768df7023 Version: be4c60b563edee3712d392aaeb0943a768df7023 Version: be4c60b563edee3712d392aaeb0943a768df7023 Version: 03f69244302d7954f42f528ea2d45903ebbf59f3 Version: 77440c3a37203e3f4667d06e37f76ef3968d2d8c Version: 679c4f27b8958b65bb51d1c3dfdbf3befe4a33a3 Version: f88ac1330779c5bfdd79f7d7f7d4d3343c782f92 Version: f739a699db7d5a5cf39ca3ce2c84e4fe4a8f4c5d Version: 4.4.244 ≤ Version: 4.9.244 ≤ Version: 4.14.161 ≤ Version: 4.19.92 ≤ Version: 5.4.7 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/pinctrl/devicetree.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "e3cfb22bad363bebcfd55d909e12d499cb8c5490",
"status": "affected",
"version": "be4c60b563edee3712d392aaeb0943a768df7023",
"versionType": "git"
},
{
"lessThan": "1586423da2739a80871ef6240016fcb9c7339bfb",
"status": "affected",
"version": "be4c60b563edee3712d392aaeb0943a768df7023",
"versionType": "git"
},
{
"lessThan": "dec5f0a8080502908dec5e35597c7ae07d533a3b",
"status": "affected",
"version": "be4c60b563edee3712d392aaeb0943a768df7023",
"versionType": "git"
},
{
"lessThan": "929f6396baade89999ec8a1281232c101cbc727d",
"status": "affected",
"version": "be4c60b563edee3712d392aaeb0943a768df7023",
"versionType": "git"
},
{
"lessThan": "321fe3584a8298386938130d138191aa35040b75",
"status": "affected",
"version": "be4c60b563edee3712d392aaeb0943a768df7023",
"versionType": "git"
},
{
"lessThan": "ad0ad3c228b6f76fde10f32047e0ec5fbc109dc8",
"status": "affected",
"version": "be4c60b563edee3712d392aaeb0943a768df7023",
"versionType": "git"
},
{
"lessThan": "9d00a5ac7cd3d32ae61140f4b8a62f136de84e7d",
"status": "affected",
"version": "be4c60b563edee3712d392aaeb0943a768df7023",
"versionType": "git"
},
{
"lessThan": "015b5bcbcb622b32317642be91a7f79aa5413649",
"status": "affected",
"version": "be4c60b563edee3712d392aaeb0943a768df7023",
"versionType": "git"
},
{
"status": "affected",
"version": "03f69244302d7954f42f528ea2d45903ebbf59f3",
"versionType": "git"
},
{
"status": "affected",
"version": "77440c3a37203e3f4667d06e37f76ef3968d2d8c",
"versionType": "git"
},
{
"status": "affected",
"version": "679c4f27b8958b65bb51d1c3dfdbf3befe4a33a3",
"versionType": "git"
},
{
"status": "affected",
"version": "f88ac1330779c5bfdd79f7d7f7d4d3343c782f92",
"versionType": "git"
},
{
"status": "affected",
"version": "f739a699db7d5a5cf39ca3ce2c84e4fe4a8f4c5d",
"versionType": "git"
},
{
"lessThan": "4.5",
"status": "affected",
"version": "4.4.244",
"versionType": "semver"
},
{
"lessThan": "4.10",
"status": "affected",
"version": "4.9.244",
"versionType": "semver"
},
{
"lessThan": "4.15",
"status": "affected",
"version": "4.14.161",
"versionType": "semver"
},
{
"lessThan": "4.20",
"status": "affected",
"version": "4.19.92",
"versionType": "semver"
},
{
"lessThan": "5.5",
"status": "affected",
"version": "5.4.7",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/pinctrl/devicetree.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.5"
},
{
"lessThan": "5.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.4.244",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.9.244",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.14.161",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.19.92",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.4.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\npinctrl: devicetree: don\u0027t free uninitialized dev_name on error path\n\ndt_remember_or_free_map() duplicates dev_name for each map entry. If\nkstrdup_const() fails, dt_free_map() frees dev_name in all num_maps\nentries, including entries that have not been initialized.\n\nSome pinctrl drivers, including pinctrl-imx, allocate the map with\nkmalloc() and leave dev_name for the core to initialize. The untouched\nentries therefore contain uninitialized data which is passed to\nkfree_const().\n\nReproduced on qemu\u0027s mcimx6ul-evk (pinctrl-imx) with failslab injection\nwhile binding the pinctrl-consuming device, under KASAN:\n\n BUG: KASAN: double-free in dt_free_map+0x34/0xa4\n Free of addr c425a900 by task init/1\n kfree from dt_free_map+0x34/0xa4\n dt_free_map from dt_remember_or_free_map+0x184/0x198\n dt_remember_or_free_map from pinctrl_dt_to_map+0x33c/0x4c8\n pinctrl_dt_to_map from create_pinctrl+0x9c/0x5c0\n\nInitialize all dev_name fields to NULL before duplicating the device\nname, making the full-map cleanup safe after a partial failure."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached only through local device driver probe/binding (really_probe -\u003e pinctrl_bind_pins -\u003e devm_pinctrl_get -\u003e create_pinctrl -\u003e pinctrl_dt_to_map -\u003e dt_remember_or_free_map); no network, Bluetooth, or remote protocol handler is on this path.\nAC:L - Once a pinctrl-consuming imx/sunxi device probes or re-probes, an attacker can reliably force kstrdup_const() to fail with sustained memory pressure; the partial-init error path then deterministically calls dt_free_map() on all entries, as confirmed by failslab/KASAN reproduction.\nPR:L - A local unprivileged account suffices to exhaust kernel memory during probe or deferred-probe retry; no CAP_SYS_ADMIN, module load, or DT overlay is strictly required beyond having affected OF hardware that binds pinctrl at boot or on automatic reprobe.\nUI:N - Exploitation executes autonomously during kernel driver initialization when allocation fails; no victim mount, file open, or other interactive action is needed.\nS:U - Double-free and heap corruption remain within kernel slab memory in the same security authority; this is a standard local kernel compromise path without VM escape, IOMMU bypass, or sandbox boundary crossing.\nC:H - kfree_const() on uninitialized kmalloc map[i].dev_name values causes invalid or duplicate frees; KASAN reports double-free, and corrupted freelist/overlapping slab objects can be groomed into arbitrary kernel memory disclosure.\nI:H - Double-free and invalid kfree corrupt the SLUB freelist; attacker-controlled heap grooming can yield overlapping allocations and write primitives enabling control-flow hijack and arbitrary kernel code execution.\nA:H - KASAN-confirmed double-free in dt_free_map during device bind causes kernel oops/panic; even without full exploitation the invalid kmem_cache_free reliably crashes the system on affected embedded imx/sunxi platforms."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:38:21.855Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/e3cfb22bad363bebcfd55d909e12d499cb8c5490"
},
{
"url": "https://git.kernel.org/stable/c/1586423da2739a80871ef6240016fcb9c7339bfb"
},
{
"url": "https://git.kernel.org/stable/c/dec5f0a8080502908dec5e35597c7ae07d533a3b"
},
{
"url": "https://git.kernel.org/stable/c/929f6396baade89999ec8a1281232c101cbc727d"
},
{
"url": "https://git.kernel.org/stable/c/321fe3584a8298386938130d138191aa35040b75"
},
{
"url": "https://git.kernel.org/stable/c/ad0ad3c228b6f76fde10f32047e0ec5fbc109dc8"
},
{
"url": "https://git.kernel.org/stable/c/9d00a5ac7cd3d32ae61140f4b8a62f136de84e7d"
},
{
"url": "https://git.kernel.org/stable/c/015b5bcbcb622b32317642be91a7f79aa5413649"
}
],
"title": "pinctrl: devicetree: don\u0027t free uninitialized dev_name on error path",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74519",
"datePublished": "2026-08-15T12:27:38.101Z",
"dateReserved": "2026-08-15T05:44:03.910Z",
"dateUpdated": "2026-08-19T16:38:21.855Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68280 (GCVE-0-2026-68280)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS()
The deprecated UNIVERSAL_DEV_PM_OPS() macro uses the provided callbacks
for both runtime PM and system sleep. This causes the DSI clocks to be
disabled twice: once during runtime suspend and again during system
suspend, resulting in a WARN message from the clock framework when
attempting to disable already-disabled clocks.
[ 84.384540] clk:231:5 already disabled
[ 84.388314] WARNING: CPU: 2 PID: 531 at /drivers/clk/clk.c:1181 clk_core_disable+0xa4/0xac
...
[ 84.579183] Call trace:
[ 84.581624] clk_core_disable+0xa4/0xac
[ 84.585457] clk_disable+0x30/0x4c
[ 84.588857] cdns_dsi_suspend+0x20/0x58 [cdns_dsi]
[ 84.593651] pm_generic_suspend+0x2c/0x44
[ 84.597661] ti_sci_pd_suspend+0xbc/0x15c
[ 84.601670] dpm_run_callback+0x8c/0x14c
[ 84.605588] __device_suspend+0x1a0/0x56c
[ 84.609594] dpm_suspend+0x17c/0x21c
[ 84.613165] dpm_suspend_start+0xa0/0xa8
[ 84.617083] suspend_devices_and_enter+0x12c/0x634
[ 84.621872] pm_suspend+0x1fc/0x368
To address this issue, replace UNIVERSAL_DEV_PM_OPS() with
RUNTIME_PM_OPS(). Bridge and panel drivers should only deal with runtime
PM, as the DRM framework manages system-wide power transitions through
the bridge enable() and disable() hooks.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: e19233955d9e9a9ae202723b9a38ef38e755b5c0 Version: e19233955d9e9a9ae202723b9a38ef38e755b5c0 Version: e19233955d9e9a9ae202723b9a38ef38e755b5c0 Version: e19233955d9e9a9ae202723b9a38ef38e755b5c0 Version: e19233955d9e9a9ae202723b9a38ef38e755b5c0 Version: e19233955d9e9a9ae202723b9a38ef38e755b5c0 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/bridge/cadence/cdns-dsi-core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "1014b279264c0fc9f56324608754e36d33b7b5ae",
"status": "affected",
"version": "e19233955d9e9a9ae202723b9a38ef38e755b5c0",
"versionType": "git"
},
{
"lessThan": "c18d46d9830c29677be5213a067daafe1ac80e43",
"status": "affected",
"version": "e19233955d9e9a9ae202723b9a38ef38e755b5c0",
"versionType": "git"
},
{
"lessThan": "347bc3a6a4d968c403d2292e5ad986294d919dfc",
"status": "affected",
"version": "e19233955d9e9a9ae202723b9a38ef38e755b5c0",
"versionType": "git"
},
{
"lessThan": "c0384d6872f4dc2701960048a0be1a12a8d2dc6e",
"status": "affected",
"version": "e19233955d9e9a9ae202723b9a38ef38e755b5c0",
"versionType": "git"
},
{
"lessThan": "1f9c6b74e79639179e90ad0c0fbeae26e31e044b",
"status": "affected",
"version": "e19233955d9e9a9ae202723b9a38ef38e755b5c0",
"versionType": "git"
},
{
"lessThan": "2d8b08844c0ecc6f2002fa68711e779aa18c8585",
"status": "affected",
"version": "e19233955d9e9a9ae202723b9a38ef38e755b5c0",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/bridge/cadence/cdns-dsi-core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.18"
},
{
"lessThan": "4.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.18",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS()\n\nThe deprecated UNIVERSAL_DEV_PM_OPS() macro uses the provided callbacks\nfor both runtime PM and system sleep. This causes the DSI clocks to be\ndisabled twice: once during runtime suspend and again during system\nsuspend, resulting in a WARN message from the clock framework when\nattempting to disable already-disabled clocks.\n\n[ 84.384540] clk:231:5 already disabled\n[ 84.388314] WARNING: CPU: 2 PID: 531 at /drivers/clk/clk.c:1181 clk_core_disable+0xa4/0xac\n...\n[ 84.579183] Call trace:\n[ 84.581624] clk_core_disable+0xa4/0xac\n[ 84.585457] clk_disable+0x30/0x4c\n[ 84.588857] cdns_dsi_suspend+0x20/0x58 [cdns_dsi]\n[ 84.593651] pm_generic_suspend+0x2c/0x44\n[ 84.597661] ti_sci_pd_suspend+0xbc/0x15c\n[ 84.601670] dpm_run_callback+0x8c/0x14c\n[ 84.605588] __device_suspend+0x1a0/0x56c\n[ 84.609594] dpm_suspend+0x17c/0x21c\n[ 84.613165] dpm_suspend_start+0xa0/0xa8\n[ 84.617083] suspend_devices_and_enter+0x12c/0x634\n[ 84.621872] pm_suspend+0x1fc/0x368\n\nTo address this issue, replace UNIVERSAL_DEV_PM_OPS() with\nRUNTIME_PM_OPS(). Bridge and panel drivers should only deal with runtime\nPM, as the DRM framework manages system-wide power transitions through\nthe bridge enable() and disable() hooks."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:17.699Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/1014b279264c0fc9f56324608754e36d33b7b5ae"
},
{
"url": "https://git.kernel.org/stable/c/c18d46d9830c29677be5213a067daafe1ac80e43"
},
{
"url": "https://git.kernel.org/stable/c/347bc3a6a4d968c403d2292e5ad986294d919dfc"
},
{
"url": "https://git.kernel.org/stable/c/c0384d6872f4dc2701960048a0be1a12a8d2dc6e"
},
{
"url": "https://git.kernel.org/stable/c/1f9c6b74e79639179e90ad0c0fbeae26e31e044b"
},
{
"url": "https://git.kernel.org/stable/c/2d8b08844c0ecc6f2002fa68711e779aa18c8585"
}
],
"title": "drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68280",
"datePublished": "2026-08-10T12:02:11.434Z",
"dateReserved": "2026-07-30T09:28:09.379Z",
"dateUpdated": "2026-08-23T12:46:17.699Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68187 (GCVE-0-2026-68187)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
exec: fix unsigned loop counter wrap in transfer_args_to_stack()
The stop value is derived from bprm->p >> PAGE_SHIFT. The index variable
is an unsigned long. If bprm->p drops below PAGE_SIZE and stop becomes
zero the loop condition index >= stop is always true.
After the index == 0 iteration the decrement wraps to ULONG_MAX and
bprm->page[ULONG_MAX] reads sizeof(void *) bytes in front of the array.
The pointer has wrapped to -1. That garbage pointer is then passed to
kmap_local_page() and PAGE_SIZE bytes are copied from wherever that
lands into the stack of the process being created. And the loop doesn't
terminate either...
Getting there only requires bprm->p < PAGE_SIZE. On !MMU
bprm_set_stack_limit() and bprm_hit_stack_limit() are empty. So the only
constraint on how far bprm->p is pushed down is valid_arg_len(), i.e.
that each individual string still fits in what is left.
bprm->p starts at PAGE_SIZE * MAX_ARG_PAGES - sizeof(void *) so a
single argument or environment string of a little over 31 pages leaves
it in the first page:
Oops - load access fault [#1]
CPU: 0 UID: 0 PID: 1 Comm: victim Not tainted 7.2.0-rc4 #1
epc : __memcpy+0xd4/0xf8
ra : transfer_args_to_stack+0xaa/0xae
s4 : ffffffffffffffff s2 : 0000000000000000
a1 : ffffffdc98000000 a2 : 0000000000001000
status: 0000000a00001880 badaddr: ffffffdc98000000 cause: 0000000000000005
[<801a5324>] __memcpy+0xd4/0xf8
[<800d5f6a>] load_flat_binary+0x43a/0x65e
[<800a2de4>] bprm_execve+0x1d4/0x316
[<800a351a>] do_execveat_common+0x12e/0x138
[<800a3d44>] __riscv_sys_execve+0x38/0x4e
Kernel panic - not syncing: Fatal exception in interrupt
This is an arcane bug but we should still fix it.
Count down from MAX_ARG_PAGES so the loop ends when index reaches stop,
stop == 0 included. The iterations performed are unchanged for every
other value of stop.
Only CONFIG_MMU=n builds are affected, transfer_args_to_stack() is used
by binfmt_flat and binfmt_elf_fdpic on nommu only.
The loop predates git history. commit 7e7ec6a93434
("elf_fdpic_transfer_args_to_stack(): make it generic") only moved it
from binfmt_elf_fdpic.c into fs/exec.c and narrowed the copy to the used
part of the first page. The condition and the decrement are unchanged
from 2.6.12-rc2.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/exec.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a9eb5c4949008034909bc34ecfa0843ecc1d0ab3",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "67cf5cdad823afb0530d6d0341fbf4ca07e93a09",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "66e20942890a383eb39b2009a2ceb4c2ebec37ef",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "c62bb00caba66e01fb578d5f0302f247dc64930a",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "dfc2a00742af4cb7251c1a8fbce4fbae3cc0de4e",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "2bc6bf70d41055377f390d06f0f3521deb62fd3b",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "55fa2c7f2b15583d1a2fe1b5abcc24377359339f",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "16cc4f5c1c4b9e45eca7f7deefa5410a292db599",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/exec.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nexec: fix unsigned loop counter wrap in transfer_args_to_stack()\n\nThe stop value is derived from bprm-\u003ep \u003e\u003e PAGE_SHIFT. The index variable\nis an unsigned long. If bprm-\u003ep drops below PAGE_SIZE and stop becomes\nzero the loop condition index \u003e= stop is always true.\n\nAfter the index == 0 iteration the decrement wraps to ULONG_MAX and\nbprm-\u003epage[ULONG_MAX] reads sizeof(void *) bytes in front of the array.\nThe pointer has wrapped to -1. That garbage pointer is then passed to\nkmap_local_page() and PAGE_SIZE bytes are copied from wherever that\nlands into the stack of the process being created. And the loop doesn\u0027t\nterminate either...\n\nGetting there only requires bprm-\u003ep \u003c PAGE_SIZE. On !MMU\nbprm_set_stack_limit() and bprm_hit_stack_limit() are empty. So the only\nconstraint on how far bprm-\u003ep is pushed down is valid_arg_len(), i.e.\nthat each individual string still fits in what is left.\n\nbprm-\u003ep starts at PAGE_SIZE * MAX_ARG_PAGES - sizeof(void *) so a\nsingle argument or environment string of a little over 31 pages leaves\nit in the first page:\n\n Oops - load access fault [#1]\n CPU: 0 UID: 0 PID: 1 Comm: victim Not tainted 7.2.0-rc4 #1\n epc : __memcpy+0xd4/0xf8\n ra : transfer_args_to_stack+0xaa/0xae\n s4 : ffffffffffffffff s2 : 0000000000000000\n a1 : ffffffdc98000000 a2 : 0000000000001000\n status: 0000000a00001880 badaddr: ffffffdc98000000 cause: 0000000000000005\n [\u003c801a5324\u003e] __memcpy+0xd4/0xf8\n [\u003c800d5f6a\u003e] load_flat_binary+0x43a/0x65e\n [\u003c800a2de4\u003e] bprm_execve+0x1d4/0x316\n [\u003c800a351a\u003e] do_execveat_common+0x12e/0x138\n [\u003c800a3d44\u003e] __riscv_sys_execve+0x38/0x4e\n Kernel panic - not syncing: Fatal exception in interrupt\n\nThis is an arcane bug but we should still fix it.\n\nCount down from MAX_ARG_PAGES so the loop ends when index reaches stop,\nstop == 0 included. The iterations performed are unchanged for every\nother value of stop.\n\nOnly CONFIG_MMU=n builds are affected, transfer_args_to_stack() is used\nby binfmt_flat and binfmt_elf_fdpic on nommu only.\n\nThe loop predates git history. commit 7e7ec6a93434\n(\"elf_fdpic_transfer_args_to_stack(): make it generic\") only moved it\nfrom binfmt_elf_fdpic.c into fs/exec.c and narrowed the copy to the used\npart of the first page. The condition and the decrement are unchanged\nfrom 2.6.12-rc2."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:30:56.724Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a9eb5c4949008034909bc34ecfa0843ecc1d0ab3"
},
{
"url": "https://git.kernel.org/stable/c/67cf5cdad823afb0530d6d0341fbf4ca07e93a09"
},
{
"url": "https://git.kernel.org/stable/c/66e20942890a383eb39b2009a2ceb4c2ebec37ef"
},
{
"url": "https://git.kernel.org/stable/c/c62bb00caba66e01fb578d5f0302f247dc64930a"
},
{
"url": "https://git.kernel.org/stable/c/dfc2a00742af4cb7251c1a8fbce4fbae3cc0de4e"
},
{
"url": "https://git.kernel.org/stable/c/2bc6bf70d41055377f390d06f0f3521deb62fd3b"
},
{
"url": "https://git.kernel.org/stable/c/55fa2c7f2b15583d1a2fe1b5abcc24377359339f"
},
{
"url": "https://git.kernel.org/stable/c/16cc4f5c1c4b9e45eca7f7deefa5410a292db599"
}
],
"title": "exec: fix unsigned loop counter wrap in transfer_args_to_stack()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68187",
"datePublished": "2026-08-10T11:59:59.303Z",
"dateReserved": "2026-07-30T09:28:09.373Z",
"dateUpdated": "2026-08-19T16:30:56.724Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68279 (GCVE-0-2026-68279)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers
drm_dp_sideband_parse_remote_dpcd_read() reads num_bytes from the raw
message and then unconditionally does:
memcpy(bytes, &raw->msg[idx], num_bytes);
without checking that idx + num_bytes <= raw->curlen. raw->msg[] is
256 bytes; if a malicious or misbehaving MST hub sets num_bytes larger
than the remaining payload, the memcpy reads past the received data
into whatever follows in raw->msg[].
drm_dp_sideband_parse_remote_i2c_read_ack() has the same flaw (noted
with a /* TODO check */ comment since the code was introduced).
Fix both functions by using a single combined check
(idx + num_bytes > curlen) before each memcpy. Since num_bytes is u8,
it is always >= 0, so this strictly subsumes the simpler idx > curlen
form and no separate step is needed.
[added missing fixes tag]
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/display/drm_dp_mst_topology.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "185de1d74e658e2edb723ba76fa61903f77d8a68",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "d7b9b1e33b4ed8c48d4db6e6e21c257ebbbb2586",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "c2fbda0fe0163c55ba3820ee6cea0c6b43622eda",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "22d9f7fc1aaabaf73d5f30e8b0c9aa814ecd6ed2",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "04d953f50d61e542e94a5977822cc53735f8c0ce",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "533d9e2bede4aeefdc2a0561d7071cfede95958f",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "e6ef5455b06cb4e5d181aabcd723791587c79f12",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "1a8f537f5a1eeac941f262fe73078d6b08ba83c0",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/display/drm_dp_mst_topology.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.17"
},
{
"lessThan": "3.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.17",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers\n\ndrm_dp_sideband_parse_remote_dpcd_read() reads num_bytes from the raw\nmessage and then unconditionally does:\n\n memcpy(bytes, \u0026raw-\u003emsg[idx], num_bytes);\n\nwithout checking that idx + num_bytes \u003c= raw-\u003ecurlen. raw-\u003emsg[] is\n256 bytes; if a malicious or misbehaving MST hub sets num_bytes larger\nthan the remaining payload, the memcpy reads past the received data\ninto whatever follows in raw-\u003emsg[].\n\ndrm_dp_sideband_parse_remote_i2c_read_ack() has the same flaw (noted\nwith a /* TODO check */ comment since the code was introduced).\n\nFix both functions by using a single combined check\n(idx + num_bytes \u003e curlen) before each memcpy. Since num_bytes is u8,\nit is always \u003e= 0, so this strictly subsumes the simpler idx \u003e curlen\nform and no separate step is needed.\n\n[added missing fixes tag]"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:16.563Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/185de1d74e658e2edb723ba76fa61903f77d8a68"
},
{
"url": "https://git.kernel.org/stable/c/d7b9b1e33b4ed8c48d4db6e6e21c257ebbbb2586"
},
{
"url": "https://git.kernel.org/stable/c/c2fbda0fe0163c55ba3820ee6cea0c6b43622eda"
},
{
"url": "https://git.kernel.org/stable/c/22d9f7fc1aaabaf73d5f30e8b0c9aa814ecd6ed2"
},
{
"url": "https://git.kernel.org/stable/c/04d953f50d61e542e94a5977822cc53735f8c0ce"
},
{
"url": "https://git.kernel.org/stable/c/533d9e2bede4aeefdc2a0561d7071cfede95958f"
},
{
"url": "https://git.kernel.org/stable/c/e6ef5455b06cb4e5d181aabcd723791587c79f12"
},
{
"url": "https://git.kernel.org/stable/c/1a8f537f5a1eeac941f262fe73078d6b08ba83c0"
}
],
"title": "drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68279",
"datePublished": "2026-08-10T12:02:09.423Z",
"dateReserved": "2026-07-30T09:28:09.379Z",
"dateUpdated": "2026-08-23T12:46:16.563Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64573 (GCVE-0-2026-64573)
Vulnerability from cvelistv5
Published
2026-08-05 08:08
Modified
2026-08-19 16:28
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: qca: fix NVM tag length underflow in TLV parser
In the TLV_TYPE_NVM branch of qca_tlv_check_data() the tag loop bound is
"while (idx < length - sizeof(struct tlv_type_nvm))". "length" is a signed
int from the firmware TLV header and sizeof(struct tlv_type_nvm) is a
size_t (12), so "length" is converted to size_t and any firmware-supplied
"length" < 12 makes the subtraction wrap to a huge value. The loop body
then reads a 12-byte struct tlv_type_nvm past the end of the short
vmalloc'd firmware buffer (and the EDL_TAG_ID_* handlers can write past it).
Rewrite the bound as "idx + sizeof(struct tlv_type_nvm) <= length"; both
operands are non-negative, so it no longer underflows and a "length" too
small for one record correctly skips the loop.
BUG: KASAN: vmalloc-out-of-bounds in qca_download_firmware.isra.0 (drivers/bluetooth/btqca.c:421)
Read of size 2 at addr ffffc900000e5004 by task kworker/u9:0/52
Workqueue: hci0 hci_power_on
Call Trace:
...
kasan_report (mm/kasan/report.c:595)
qca_download_firmware.isra.0 (drivers/bluetooth/btqca.c:421 drivers/bluetooth/btqca.c:617)
qca_uart_setup (drivers/bluetooth/btqca.c:948)
qca_setup (drivers/bluetooth/hci_qca.c:2029)
hci_uart_setup (drivers/bluetooth/hci_ldisc.c:438)
hci_dev_open_sync (net/bluetooth/hci_sync.c:5227)
hci_power_on (net/bluetooth/hci_core.c:920)
process_one_work (kernel/workqueue.c:3322)
worker_thread (kernel/workqueue.c:3486)
kthread (kernel/kthread.c:436)
ret_from_fork (arch/x86/kernel/process.c:158)
ret_from_fork_asm (arch/x86/entry/entry_64.S:245)
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ed53949cc92e28aaa3463d246942bda1fbb7f307 Version: 1caceadfb50432dbf6d808796cb6c34ebb6d662c Version: 427281f9498ed614f9aabc80e46ec077c487da6d Version: 2e4edfa1e2bd821a317e7d006517dcf2f3fac68d Version: 2e4edfa1e2bd821a317e7d006517dcf2f3fac68d Version: 2e4edfa1e2bd821a317e7d006517dcf2f3fac68d Version: 2e4edfa1e2bd821a317e7d006517dcf2f3fac68d Version: 02f05ed44b71152d5e11d29be28aed91c0489b4e Version: 5.15.159 ≤ Version: 6.1.91 ≤ Version: 6.6.31 ≤ Version: 6.8.10 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/bluetooth/btqca.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a7ee11441d71ab036a705d110a415421f5a4a898",
"status": "affected",
"version": "ed53949cc92e28aaa3463d246942bda1fbb7f307",
"versionType": "git"
},
{
"lessThan": "5d34e537755d2f9eba2d4e54d70126f987ef20b4",
"status": "affected",
"version": "1caceadfb50432dbf6d808796cb6c34ebb6d662c",
"versionType": "git"
},
{
"lessThan": "70354dbb5f72d9a76da7b031de3cbaf6c7d8fc24",
"status": "affected",
"version": "427281f9498ed614f9aabc80e46ec077c487da6d",
"versionType": "git"
},
{
"lessThan": "59fd2f075bca94f030c7c78e94878ea0803d7690",
"status": "affected",
"version": "2e4edfa1e2bd821a317e7d006517dcf2f3fac68d",
"versionType": "git"
},
{
"lessThan": "a087ed960fce54e9302796229e9d545bbc9bcd4a",
"status": "affected",
"version": "2e4edfa1e2bd821a317e7d006517dcf2f3fac68d",
"versionType": "git"
},
{
"lessThan": "4fcfb5b2c736785464ff9745f94c6726c5ee2d85",
"status": "affected",
"version": "2e4edfa1e2bd821a317e7d006517dcf2f3fac68d",
"versionType": "git"
},
{
"lessThan": "c90164ca0f7036942ba088eb7ea8d3f6c2352020",
"status": "affected",
"version": "2e4edfa1e2bd821a317e7d006517dcf2f3fac68d",
"versionType": "git"
},
{
"status": "affected",
"version": "02f05ed44b71152d5e11d29be28aed91c0489b4e",
"versionType": "git"
},
{
"lessThan": "5.15.216",
"status": "affected",
"version": "5.15.159",
"versionType": "semver"
},
{
"lessThan": "6.1.183",
"status": "affected",
"version": "6.1.91",
"versionType": "semver"
},
{
"lessThan": "6.6.148",
"status": "affected",
"version": "6.6.31",
"versionType": "semver"
},
{
"lessThan": "6.9",
"status": "affected",
"version": "6.8.10",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/bluetooth/btqca.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.9"
},
{
"lessThan": "6.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.15.159",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "6.1.91",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.6.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.8.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: qca: fix NVM tag length underflow in TLV parser\n\nIn the TLV_TYPE_NVM branch of qca_tlv_check_data() the tag loop bound is\n\"while (idx \u003c length - sizeof(struct tlv_type_nvm))\". \"length\" is a signed\nint from the firmware TLV header and sizeof(struct tlv_type_nvm) is a\nsize_t (12), so \"length\" is converted to size_t and any firmware-supplied\n\"length\" \u003c 12 makes the subtraction wrap to a huge value. The loop body\nthen reads a 12-byte struct tlv_type_nvm past the end of the short\nvmalloc\u0027d firmware buffer (and the EDL_TAG_ID_* handlers can write past it).\n\nRewrite the bound as \"idx + sizeof(struct tlv_type_nvm) \u003c= length\"; both\noperands are non-negative, so it no longer underflows and a \"length\" too\nsmall for one record correctly skips the loop.\n\n BUG: KASAN: vmalloc-out-of-bounds in qca_download_firmware.isra.0 (drivers/bluetooth/btqca.c:421)\n Read of size 2 at addr ffffc900000e5004 by task kworker/u9:0/52\n Workqueue: hci0 hci_power_on\n Call Trace:\n ...\n kasan_report (mm/kasan/report.c:595)\n qca_download_firmware.isra.0 (drivers/bluetooth/btqca.c:421 drivers/bluetooth/btqca.c:617)\n qca_uart_setup (drivers/bluetooth/btqca.c:948)\n qca_setup (drivers/bluetooth/hci_qca.c:2029)\n hci_uart_setup (drivers/bluetooth/hci_ldisc.c:438)\n hci_dev_open_sync (net/bluetooth/hci_sync.c:5227)\n hci_power_on (net/bluetooth/hci_core.c:920)\n process_one_work (kernel/workqueue.c:3322)\n worker_thread (kernel/workqueue.c:3486)\n kthread (kernel/kthread.c:436)\n ret_from_fork (arch/x86/kernel/process.c:158)\n ret_from_fork_asm (arch/x86/entry/entry_64.S:245)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:28:52.002Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a7ee11441d71ab036a705d110a415421f5a4a898"
},
{
"url": "https://git.kernel.org/stable/c/5d34e537755d2f9eba2d4e54d70126f987ef20b4"
},
{
"url": "https://git.kernel.org/stable/c/70354dbb5f72d9a76da7b031de3cbaf6c7d8fc24"
},
{
"url": "https://git.kernel.org/stable/c/59fd2f075bca94f030c7c78e94878ea0803d7690"
},
{
"url": "https://git.kernel.org/stable/c/a087ed960fce54e9302796229e9d545bbc9bcd4a"
},
{
"url": "https://git.kernel.org/stable/c/4fcfb5b2c736785464ff9745f94c6726c5ee2d85"
},
{
"url": "https://git.kernel.org/stable/c/c90164ca0f7036942ba088eb7ea8d3f6c2352020"
}
],
"title": "Bluetooth: qca: fix NVM tag length underflow in TLV parser",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64573",
"datePublished": "2026-08-05T08:08:09.669Z",
"dateReserved": "2026-07-19T15:36:31.797Z",
"dateUpdated": "2026-08-19T16:28:52.002Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74589 (GCVE-0-2026-74589)
Vulnerability from cvelistv5
Published
2026-08-22 15:31
Modified
2026-08-25 05:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
bpf, sockmap: Fix sk_redir use-after-free in send verdict
sk_psock_msg_verdict() takes a socket reference for psock->sk_redir.
tcp_bpf_send_verdict() copies that pointer while holding the source socket
lock, but does not take a reference for the local copy before dropping the
lock around tcp_bpf_sendmsg_redir().
When apply_bytes keeps the cached verdict active, another sendmsg() on the
same source socket can consume the remaining bytes and release the cached
reference while the first thread still holds only the raw local pointer:
CPU 0 CPU 1
sk_redir = psock->sk_redir
apply_bytes remains nonzero
release_sock(sk)
lock_sock(sk)
apply_bytes reaches zero
psock->sk_redir = NULL
release_sock(sk)
tcp_bpf_sendmsg_redir(sk_redir)
sock_put(sk_redir)
tcp_bpf_sendmsg_redir(sk_redir)
The final sock_put() can free sk_redir before CPU 0 dereferences it.
KASAN reported:
BUG: KASAN: slab-use-after-free in tcp_bpf_sendmsg_redir+0xf39/0x1020
Read of size 8 at addr ffff888108537090 by task poc/87
Call Trace:
tcp_bpf_sendmsg_redir+0xf39/0x1020
tcp_bpf_sendmsg+0x977/0x1a50
__sys_sendto+0x32c/0x3a0
__x64_sys_sendto+0xdb/0x1b0
Allocated by task 85:
sk_prot_alloc+0x56/0x210
sk_clone+0x6f/0x14b0
inet_csk_clone_lock+0x24/0x740
tcp_create_openreq_child+0x25/0x2710
tcp_v4_syn_recv_sock+0x10a/0xe00
Freed by task 0:
__kasan_slab_free+0x43/0x70
slab_free_after_rcu_debug+0xa6/0x1e0
rcu_core+0x50a/0x1850
Last potentially related work creation:
__sk_destruct+0x3da/0x540
sk_psock_destroy+0x81e/0xab0
process_one_work+0x63a/0x1070
Take a temporary socket reference while the source socket lock still
protects psock->sk_redir, and drop it after tcp_bpf_sendmsg_redir()
returns. This keeps each unlocked use independent of cached-verdict
ownership.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 604326b41a6fb9b4a78b6179335decee0365cd8c Version: 604326b41a6fb9b4a78b6179335decee0365cd8c Version: 604326b41a6fb9b4a78b6179335decee0365cd8c Version: 604326b41a6fb9b4a78b6179335decee0365cd8c Version: 604326b41a6fb9b4a78b6179335decee0365cd8c Version: 604326b41a6fb9b4a78b6179335decee0365cd8c Version: 604326b41a6fb9b4a78b6179335decee0365cd8c Version: 604326b41a6fb9b4a78b6179335decee0365cd8c |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ipv4/tcp_bpf.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "41b7da0cb72ca5aa1e62b68dab323d0791fc6bdf",
"status": "affected",
"version": "604326b41a6fb9b4a78b6179335decee0365cd8c",
"versionType": "git"
},
{
"lessThan": "9b4fbc371a6ecf1b4e43b5a629015cc0830d8de3",
"status": "affected",
"version": "604326b41a6fb9b4a78b6179335decee0365cd8c",
"versionType": "git"
},
{
"lessThan": "90a19b0894ba79a699b48cf44421b36fbd566e99",
"status": "affected",
"version": "604326b41a6fb9b4a78b6179335decee0365cd8c",
"versionType": "git"
},
{
"lessThan": "d192cff2a37d59206dabe6ec2e60ceac6271f274",
"status": "affected",
"version": "604326b41a6fb9b4a78b6179335decee0365cd8c",
"versionType": "git"
},
{
"lessThan": "4c9d9aa809c261dc0490a0e19d675f7e8e4c85bf",
"status": "affected",
"version": "604326b41a6fb9b4a78b6179335decee0365cd8c",
"versionType": "git"
},
{
"lessThan": "a14e4ef1d90c3418f01b3b6b8fd3a40a0a208a10",
"status": "affected",
"version": "604326b41a6fb9b4a78b6179335decee0365cd8c",
"versionType": "git"
},
{
"lessThan": "1cec526cf0a2227395f2c2f4b671cb052ff0b00e",
"status": "affected",
"version": "604326b41a6fb9b4a78b6179335decee0365cd8c",
"versionType": "git"
},
{
"lessThan": "a76624733730e541e4955fdecf506af2f6b20558",
"status": "affected",
"version": "604326b41a6fb9b4a78b6179335decee0365cd8c",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ipv4/tcp_bpf.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.20"
},
{
"lessThan": "4.20",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.20",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf, sockmap: Fix sk_redir use-after-free in send verdict\n\nsk_psock_msg_verdict() takes a socket reference for psock-\u003esk_redir.\ntcp_bpf_send_verdict() copies that pointer while holding the source socket\nlock, but does not take a reference for the local copy before dropping the\nlock around tcp_bpf_sendmsg_redir().\n\nWhen apply_bytes keeps the cached verdict active, another sendmsg() on the\nsame source socket can consume the remaining bytes and release the cached\nreference while the first thread still holds only the raw local pointer:\n\n CPU 0 CPU 1\n sk_redir = psock-\u003esk_redir\n apply_bytes remains nonzero\n release_sock(sk)\n lock_sock(sk)\n apply_bytes reaches zero\n psock-\u003esk_redir = NULL\n release_sock(sk)\n tcp_bpf_sendmsg_redir(sk_redir)\n sock_put(sk_redir)\n tcp_bpf_sendmsg_redir(sk_redir)\n\nThe final sock_put() can free sk_redir before CPU 0 dereferences it.\n\nKASAN reported:\n\n BUG: KASAN: slab-use-after-free in tcp_bpf_sendmsg_redir+0xf39/0x1020\n Read of size 8 at addr ffff888108537090 by task poc/87\n Call Trace:\n tcp_bpf_sendmsg_redir+0xf39/0x1020\n tcp_bpf_sendmsg+0x977/0x1a50\n __sys_sendto+0x32c/0x3a0\n __x64_sys_sendto+0xdb/0x1b0\n Allocated by task 85:\n sk_prot_alloc+0x56/0x210\n sk_clone+0x6f/0x14b0\n inet_csk_clone_lock+0x24/0x740\n tcp_create_openreq_child+0x25/0x2710\n tcp_v4_syn_recv_sock+0x10a/0xe00\n Freed by task 0:\n __kasan_slab_free+0x43/0x70\n slab_free_after_rcu_debug+0xa6/0x1e0\n rcu_core+0x50a/0x1850\n Last potentially related work creation:\n __sk_destruct+0x3da/0x540\n sk_psock_destroy+0x81e/0xab0\n process_one_work+0x63a/0x1070\n\nTake a temporary socket reference while the source socket lock still\nprotects psock-\u003esk_redir, and drop it after tcp_bpf_sendmsg_redir()\nreturns. This keeps each unlocked use independent of cached-verdict\nownership."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.4,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The UAF is reached via local sendmsg/sendto on a TCP socket whose -\u003esendmsg was replaced by tcp_bpf_sendmsg() after BPF sockmap SK_MSG verdict attachment; per kernel CNA BPF/sockmap guidance this path is Local even when remote peers drive outbound traffic on internet-facing eBPF proxies.\nAC:L - The race needs two concurrent sendmsg() calls on the same sockmap-attached source socket while a cached __SK_REDIRECT verdict still has nonzero apply_bytes; the attacker controls both racing threads locally or can reliably create them on a multi-threaded server with concurrent client requests.\nPR:N - The highest-impact reasonable deployment is an internet-facing Cilium/service-mesh node with pre-installed sockmap SK_MSG redirect programs; an unauthenticated remote client can trigger concurrent outbound sends on enrolled sockets without any privileges on the victim host, while self-setup only raises the bar to CAP_NET_ADMIN in a user namespace.\nUI:N - Exploitation requires only network traffic to a vulnerable proxy or the attacker\u0027s own concurrent sendmsg threads; no victim user action such as mounting filesystems, opening files, or clicking links is needed.\nS:U - The slab use-after-free corrupts a struct sock in the host kernel security authority and enables standard kernel memory corruption or privilege escalation; it does not by itself cross VM, IOMMU, or container sandbox boundaries.\nC:H - KASAN reported slab-use-after-free in tcp_bpf_sendmsg_redir() with an 8-byte read through a freed struct sock; reclaiming that socket object enables attacker-controlled contents and arbitrary kernel memory disclosure via subsequent dereferences.\nI:H - Use-after-free on struct sock provides groomable heap control over sk_prot and callback pointers in tcp_bpf_sendmsg_redir(), yielding standard kernel UAF write primitives usable for arbitrary modification and privilege escalation.\nA:H - The published KASAN trace shows deterministic slab-use-after-free during send verdict redirect processing; UAF on struct sock can oops or panic the kernel during dereference even when full exploitation is not attempted."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:40:16.327Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/41b7da0cb72ca5aa1e62b68dab323d0791fc6bdf"
},
{
"url": "https://git.kernel.org/stable/c/9b4fbc371a6ecf1b4e43b5a629015cc0830d8de3"
},
{
"url": "https://git.kernel.org/stable/c/90a19b0894ba79a699b48cf44421b36fbd566e99"
},
{
"url": "https://git.kernel.org/stable/c/d192cff2a37d59206dabe6ec2e60ceac6271f274"
},
{
"url": "https://git.kernel.org/stable/c/4c9d9aa809c261dc0490a0e19d675f7e8e4c85bf"
},
{
"url": "https://git.kernel.org/stable/c/a14e4ef1d90c3418f01b3b6b8fd3a40a0a208a10"
},
{
"url": "https://git.kernel.org/stable/c/1cec526cf0a2227395f2c2f4b671cb052ff0b00e"
},
{
"url": "https://git.kernel.org/stable/c/a76624733730e541e4955fdecf506af2f6b20558"
}
],
"title": "bpf, sockmap: Fix sk_redir use-after-free in send verdict",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74589",
"datePublished": "2026-08-22T15:31:41.177Z",
"dateReserved": "2026-08-15T05:44:03.918Z",
"dateUpdated": "2026-08-25T05:40:16.327Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74694 (GCVE-0-2026-74694)
Vulnerability from cvelistv5
Published
2026-08-22 15:32
Modified
2026-08-22 15:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/ncsi: fix heap OOB read in NCSI_CMD_SEND_CMD payload length
ncsi_send_cmd_nl() takes the number of bytes to copy from the
attacker-controlled ncsi_pkt_hdr.length field of the in-band packet
header, while the source buffer is the NCSI_ATTR_DATA netlink
attribute whose readable size is nla_len() - sizeof(ncsi_pkt_hdr).
The two length sources are never cross-checked: only
nla_len() >= sizeof(struct ncsi_pkt_hdr) is enforced.
With hdr->length set larger than the attribute payload (up to 65535
against at most 2032 readable bytes), ncsi_cmd_handler_oem() copies
past the end of the netlink attribute buffer with unsafe_memcpy(),
leaking up to ~64KB of kernel heap memory into the transmitted NCSI
command packet. The destination skb is sized by the declared payload,
so the write side does not overflow - this is a pure OOB read /
information leak, reachable with CAP_NET_ADMIN on systems with a
registered NCSI device (e.g. OpenBMC on Aspeed BMC SoCs, where
NET_NCSI=y is standard).
Reject commands whose declared payload extends past the end of the
data attribute.
The issue was found by the autokbug dynamic kernel fuzzer at Tencent
Yunding Lab.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 9771b8ccdfa6dcb1ac5128ca7fe8649f3092d392 Version: 9771b8ccdfa6dcb1ac5128ca7fe8649f3092d392 Version: 9771b8ccdfa6dcb1ac5128ca7fe8649f3092d392 Version: 9771b8ccdfa6dcb1ac5128ca7fe8649f3092d392 Version: 9771b8ccdfa6dcb1ac5128ca7fe8649f3092d392 Version: 9771b8ccdfa6dcb1ac5128ca7fe8649f3092d392 Version: 9771b8ccdfa6dcb1ac5128ca7fe8649f3092d392 Version: 9771b8ccdfa6dcb1ac5128ca7fe8649f3092d392 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ncsi/ncsi-netlink.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "e60afa01d35f8b2671b27ca93309921427144cce",
"status": "affected",
"version": "9771b8ccdfa6dcb1ac5128ca7fe8649f3092d392",
"versionType": "git"
},
{
"lessThan": "67c72b8ef63d9d9a610546fda30b116638f39745",
"status": "affected",
"version": "9771b8ccdfa6dcb1ac5128ca7fe8649f3092d392",
"versionType": "git"
},
{
"lessThan": "4489b4a17892750131e4bef4bc1d3d703c8fb5ba",
"status": "affected",
"version": "9771b8ccdfa6dcb1ac5128ca7fe8649f3092d392",
"versionType": "git"
},
{
"lessThan": "43c7d0a6917751ea898ae584d00f24f5deac46d4",
"status": "affected",
"version": "9771b8ccdfa6dcb1ac5128ca7fe8649f3092d392",
"versionType": "git"
},
{
"lessThan": "b5231ad0b376b801ab8cf2962b182cc29deaedb3",
"status": "affected",
"version": "9771b8ccdfa6dcb1ac5128ca7fe8649f3092d392",
"versionType": "git"
},
{
"lessThan": "02226af69362758046822840fc6a497f5de33f00",
"status": "affected",
"version": "9771b8ccdfa6dcb1ac5128ca7fe8649f3092d392",
"versionType": "git"
},
{
"lessThan": "3a60b5af75abe8e3494ccd074fb4ae6e601a3e55",
"status": "affected",
"version": "9771b8ccdfa6dcb1ac5128ca7fe8649f3092d392",
"versionType": "git"
},
{
"lessThan": "afa58b7384913c8773d837acdb07b035690ec5d2",
"status": "affected",
"version": "9771b8ccdfa6dcb1ac5128ca7fe8649f3092d392",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ncsi/ncsi-netlink.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.20"
},
{
"lessThan": "4.20",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.20",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/ncsi: fix heap OOB read in NCSI_CMD_SEND_CMD payload length\n\nncsi_send_cmd_nl() takes the number of bytes to copy from the\nattacker-controlled ncsi_pkt_hdr.length field of the in-band packet\nheader, while the source buffer is the NCSI_ATTR_DATA netlink\nattribute whose readable size is nla_len() - sizeof(ncsi_pkt_hdr).\nThe two length sources are never cross-checked: only\nnla_len() \u003e= sizeof(struct ncsi_pkt_hdr) is enforced.\n\nWith hdr-\u003elength set larger than the attribute payload (up to 65535\nagainst at most 2032 readable bytes), ncsi_cmd_handler_oem() copies\npast the end of the netlink attribute buffer with unsafe_memcpy(),\nleaking up to ~64KB of kernel heap memory into the transmitted NCSI\ncommand packet. The destination skb is sized by the declared payload,\nso the write side does not overflow - this is a pure OOB read /\ninformation leak, reachable with CAP_NET_ADMIN on systems with a\nregistered NCSI device (e.g. OpenBMC on Aspeed BMC SoCs, where\nNET_NCSI=y is standard).\n\nReject commands whose declared payload extends past the end of the\ndata attribute.\n\nThe issue was found by the autokbug dynamic kernel fuzzer at Tencent\nYunding Lab."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-22T15:32:57.113Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/e60afa01d35f8b2671b27ca93309921427144cce"
},
{
"url": "https://git.kernel.org/stable/c/67c72b8ef63d9d9a610546fda30b116638f39745"
},
{
"url": "https://git.kernel.org/stable/c/4489b4a17892750131e4bef4bc1d3d703c8fb5ba"
},
{
"url": "https://git.kernel.org/stable/c/43c7d0a6917751ea898ae584d00f24f5deac46d4"
},
{
"url": "https://git.kernel.org/stable/c/b5231ad0b376b801ab8cf2962b182cc29deaedb3"
},
{
"url": "https://git.kernel.org/stable/c/02226af69362758046822840fc6a497f5de33f00"
},
{
"url": "https://git.kernel.org/stable/c/3a60b5af75abe8e3494ccd074fb4ae6e601a3e55"
},
{
"url": "https://git.kernel.org/stable/c/afa58b7384913c8773d837acdb07b035690ec5d2"
}
],
"title": "net/ncsi: fix heap OOB read in NCSI_CMD_SEND_CMD payload length",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74694",
"datePublished": "2026-08-22T15:32:57.113Z",
"dateReserved": "2026-08-15T05:44:03.926Z",
"dateUpdated": "2026-08-22T15:32:57.113Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80855 (GCVE-0-2026-80855)
Vulnerability from cvelistv5
Published
2026-09-04 15:55
Modified
2026-09-04 15:55
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
fuse: fix invalidate lock leak on open O_TRUNC DAX failure
fuse_open() takes filemap_invalidate_lock() for a DAX truncate
(dax_truncate = true) and releases it before the out_inode_unlock
label. But when fuse_dax_break_layouts() fails, the goto
out_inode_unlock skips the unlock and leaks the rwsem, so any later
fault or truncate on the file stalls on the stale lock.
fuse_dax_break_layouts() can fail with -ERESTARTSYS when a signal
interrupts the wait for busy DAX pages to drain:
open("file", O_RDWR | O_TRUNC)
└─ fuse_open()
├─ filemap_invalidate_lock() # dax_truncate
└─ fuse_dax_break_layouts()
└─ dax_break_layout()
└─ wait_page_idle() # TASK_INTERRUPTIBLE
└─ fuse_wait_dax_page() # unlock, schedule, re-lock
└─ signal → -ERESTARTSYS
goto out_inode_unlock # <- lock leaked
Fix this by moving filemap_invalidate_unlock() below the label so
that all error paths release the lock, and rename the label to
out_unlock as it now covers more than just the inode lock.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d58366aab86854217b81679d1a9dcd54a2edfc2a Version: 2fdbb8dd01556e1501132b5ad3826e8f71e24a8b Version: 2fdbb8dd01556e1501132b5ad3826e8f71e24a8b Version: 2fdbb8dd01556e1501132b5ad3826e8f71e24a8b Version: 2fdbb8dd01556e1501132b5ad3826e8f71e24a8b Version: 2fdbb8dd01556e1501132b5ad3826e8f71e24a8b Version: 2fdbb8dd01556e1501132b5ad3826e8f71e24a8b Version: 2fdbb8dd01556e1501132b5ad3826e8f71e24a8b Version: 81775ab858b4236c52c5da7e25cec6e49dd91b46 Version: b57e150ac2eac791d5d187923b73dc2dafaf67fa Version: 1fdbbe246daf348adaa0739463384b16ceba1fc0 Version: 5.15.109 ≤ Version: 5.10.179 ≤ Version: 5.18.18 ≤ Version: 5.19.2 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/fuse/file.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "1b04d80a27d317064cce2307472f5bef9975bc50",
"status": "affected",
"version": "d58366aab86854217b81679d1a9dcd54a2edfc2a",
"versionType": "git"
},
{
"lessThan": "a61524da59a2f5ac9c8de23ff98b30da769ab144",
"status": "affected",
"version": "2fdbb8dd01556e1501132b5ad3826e8f71e24a8b",
"versionType": "git"
},
{
"lessThan": "dcf30a56624c2a0cfab1bada5b1ca8cc0c02f010",
"status": "affected",
"version": "2fdbb8dd01556e1501132b5ad3826e8f71e24a8b",
"versionType": "git"
},
{
"lessThan": "7288c279ddbd654a06c82118c1a3f5570c1807f0",
"status": "affected",
"version": "2fdbb8dd01556e1501132b5ad3826e8f71e24a8b",
"versionType": "git"
},
{
"lessThan": "776e85fda752f9a15e0f82dec42ecacd12a9bd94",
"status": "affected",
"version": "2fdbb8dd01556e1501132b5ad3826e8f71e24a8b",
"versionType": "git"
},
{
"lessThan": "1d3e701cda2f41d48aa721b3ebefbe0fbf8d74da",
"status": "affected",
"version": "2fdbb8dd01556e1501132b5ad3826e8f71e24a8b",
"versionType": "git"
},
{
"lessThan": "e981474d7bf1457da12404e169ea147d2c8ecea7",
"status": "affected",
"version": "2fdbb8dd01556e1501132b5ad3826e8f71e24a8b",
"versionType": "git"
},
{
"lessThan": "a927f1867e61b78f39f9da0bbba3c98c2ca151fe",
"status": "affected",
"version": "2fdbb8dd01556e1501132b5ad3826e8f71e24a8b",
"versionType": "git"
},
{
"status": "affected",
"version": "81775ab858b4236c52c5da7e25cec6e49dd91b46",
"versionType": "git"
},
{
"status": "affected",
"version": "b57e150ac2eac791d5d187923b73dc2dafaf67fa",
"versionType": "git"
},
{
"status": "affected",
"version": "1fdbbe246daf348adaa0739463384b16ceba1fc0",
"versionType": "git"
},
{
"lessThan": "5.15.220",
"status": "affected",
"version": "5.15.109",
"versionType": "semver"
},
{
"lessThan": "5.11",
"status": "affected",
"version": "5.10.179",
"versionType": "semver"
},
{
"lessThan": "5.19",
"status": "affected",
"version": "5.18.18",
"versionType": "semver"
},
{
"lessThan": "5.20",
"status": "affected",
"version": "5.19.2",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/fuse/file.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.0"
},
{
"lessThan": "6.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.220",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.187",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.156",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.108",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.49",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.13",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.3",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.220",
"versionStartIncluding": "5.15.109",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.187",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.156",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.108",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.49",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.13",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.3",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.10.179",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.18.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.19.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfuse: fix invalidate lock leak on open O_TRUNC DAX failure\n\nfuse_open() takes filemap_invalidate_lock() for a DAX truncate\n(dax_truncate = true) and releases it before the out_inode_unlock\nlabel. But when fuse_dax_break_layouts() fails, the goto\nout_inode_unlock skips the unlock and leaks the rwsem, so any later\nfault or truncate on the file stalls on the stale lock.\n\nfuse_dax_break_layouts() can fail with -ERESTARTSYS when a signal\ninterrupts the wait for busy DAX pages to drain:\n\n open(\"file\", O_RDWR | O_TRUNC)\n \u2514\u2500 fuse_open()\n \u251c\u2500 filemap_invalidate_lock() # dax_truncate\n \u2514\u2500 fuse_dax_break_layouts()\n \u2514\u2500 dax_break_layout()\n \u2514\u2500 wait_page_idle() # TASK_INTERRUPTIBLE\n \u2514\u2500 fuse_wait_dax_page() # unlock, schedule, re-lock\n \u2514\u2500 signal \u2192 -ERESTARTSYS\n goto out_inode_unlock # \u003c- lock leaked\n\nFix this by moving filemap_invalidate_unlock() below the label so\nthat all error paths release the lock, and rename the label to\nout_unlock as it now covers more than just the inode lock."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T15:55:07.864Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/1b04d80a27d317064cce2307472f5bef9975bc50"
},
{
"url": "https://git.kernel.org/stable/c/a61524da59a2f5ac9c8de23ff98b30da769ab144"
},
{
"url": "https://git.kernel.org/stable/c/dcf30a56624c2a0cfab1bada5b1ca8cc0c02f010"
},
{
"url": "https://git.kernel.org/stable/c/7288c279ddbd654a06c82118c1a3f5570c1807f0"
},
{
"url": "https://git.kernel.org/stable/c/776e85fda752f9a15e0f82dec42ecacd12a9bd94"
},
{
"url": "https://git.kernel.org/stable/c/1d3e701cda2f41d48aa721b3ebefbe0fbf8d74da"
},
{
"url": "https://git.kernel.org/stable/c/e981474d7bf1457da12404e169ea147d2c8ecea7"
},
{
"url": "https://git.kernel.org/stable/c/a927f1867e61b78f39f9da0bbba3c98c2ca151fe"
}
],
"title": "fuse: fix invalidate lock leak on open O_TRUNC DAX failure",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80855",
"datePublished": "2026-09-04T15:55:07.864Z",
"dateReserved": "2026-08-26T14:34:25.797Z",
"dateUpdated": "2026-09-04T15:55:07.864Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68386 (GCVE-0-2026-68386)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
bpf, sockmap: Reject unhashed UDP sockets on sockmap update
UDP sockets get SOCK_RCU_FREE set when (auto-)bound. This means
sk_is_refcounted(unbound) = true, while sk_is_refcounted(bound) = false.
Because sockmap accepts unbound UDP sockets, a BPF program can increment a
socket's refcount via lookup. If the socket is subsequently bound, the
transition from unbound to bound causes bpf_sk_release() to skip the
decrement of the refcount, causing a memory leak.
unreferenced object 0xffff88810bc2eb40 (size 1984):
comm "test_progs", pid 2451, jiffies 4295320596
hex dump (first 32 bytes):
7f 00 00 01 7f 00 00 01 d2 04 1b b7 04 d2 00 00 ................
02 00 01 40 00 00 00 00 00 00 00 00 00 00 00 00 ...@............
backtrace (crc bdee079d):
kmem_cache_alloc_noprof+0x557/0x660
sk_prot_alloc+0x69/0x240
sk_alloc+0x30/0x460
inet_create+0x2ce/0xf80
__sock_create+0x25b/0x5c0
__sys_socket+0x119/0x1d0
__x64_sys_socket+0x72/0xd0
do_syscall_64+0xa1/0x5f0
entry_SYSCALL_64_after_hwframe+0x76/0x7e
Instead of special-casing for refcounted sockets, reject unhashed UDP
sockets during sockmap updates, as there is no benefit to supporting those.
This effectively reverts the commit under Fixes, with two exceptions:
1. sock_map_sk_state_allowed() maintains a fall-through `return true`.
2. In the spirit of commit b8b8315e39ff ("bpf, sockmap: Remove unhash
handler for BPF sockmap usage"), the proto::unhash BPF handler is not
reintroduced.
Historical note: this issue is related to commit 67312adc96b5 ("bpf: reject
unhashed sockets in bpf_sk_assign").
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 0c48eefae712c2fd91480346a07a1a9cd0f9470b Version: 0c48eefae712c2fd91480346a07a1a9cd0f9470b Version: 0c48eefae712c2fd91480346a07a1a9cd0f9470b Version: 0c48eefae712c2fd91480346a07a1a9cd0f9470b Version: 0c48eefae712c2fd91480346a07a1a9cd0f9470b Version: 0c48eefae712c2fd91480346a07a1a9cd0f9470b |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/core/sock_map.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "2271276ac5279d2d204be7739a1a28d4ef6cf608",
"status": "affected",
"version": "0c48eefae712c2fd91480346a07a1a9cd0f9470b",
"versionType": "git"
},
{
"lessThan": "7ffe529e7127411806c8692fb1490f552c629dc2",
"status": "affected",
"version": "0c48eefae712c2fd91480346a07a1a9cd0f9470b",
"versionType": "git"
},
{
"lessThan": "17b7ef6b86112a4e61cee1e9009a4b318e3225c5",
"status": "affected",
"version": "0c48eefae712c2fd91480346a07a1a9cd0f9470b",
"versionType": "git"
},
{
"lessThan": "250474c69bc3fc48a5fc21d7c349f279caad947a",
"status": "affected",
"version": "0c48eefae712c2fd91480346a07a1a9cd0f9470b",
"versionType": "git"
},
{
"lessThan": "8692655da369961128658cf8539334b6a960ecb0",
"status": "affected",
"version": "0c48eefae712c2fd91480346a07a1a9cd0f9470b",
"versionType": "git"
},
{
"lessThan": "66efd3368ae10d05e08fbe6425b50fdec7186ac7",
"status": "affected",
"version": "0c48eefae712c2fd91480346a07a1a9cd0f9470b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/core/sock_map.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.15"
},
{
"lessThan": "5.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf, sockmap: Reject unhashed UDP sockets on sockmap update\n\nUDP sockets get SOCK_RCU_FREE set when (auto-)bound. This means\nsk_is_refcounted(unbound) = true, while sk_is_refcounted(bound) = false.\n\nBecause sockmap accepts unbound UDP sockets, a BPF program can increment a\nsocket\u0027s refcount via lookup. If the socket is subsequently bound, the\ntransition from unbound to bound causes bpf_sk_release() to skip the\ndecrement of the refcount, causing a memory leak.\n\nunreferenced object 0xffff88810bc2eb40 (size 1984):\n comm \"test_progs\", pid 2451, jiffies 4295320596\n hex dump (first 32 bytes):\n 7f 00 00 01 7f 00 00 01 d2 04 1b b7 04 d2 00 00 ................\n 02 00 01 40 00 00 00 00 00 00 00 00 00 00 00 00 ...@............\n backtrace (crc bdee079d):\n kmem_cache_alloc_noprof+0x557/0x660\n sk_prot_alloc+0x69/0x240\n sk_alloc+0x30/0x460\n inet_create+0x2ce/0xf80\n __sock_create+0x25b/0x5c0\n __sys_socket+0x119/0x1d0\n __x64_sys_socket+0x72/0xd0\n do_syscall_64+0xa1/0x5f0\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nInstead of special-casing for refcounted sockets, reject unhashed UDP\nsockets during sockmap updates, as there is no benefit to supporting those.\nThis effectively reverts the commit under Fixes, with two exceptions:\n\n1. sock_map_sk_state_allowed() maintains a fall-through `return true`.\n2. In the spirit of commit b8b8315e39ff (\"bpf, sockmap: Remove unhash\n handler for BPF sockmap usage\"), the proto::unhash BPF handler is not\n reintroduced.\n\nHistorical note: this issue is related to commit 67312adc96b5 (\"bpf: reject\nunhashed sockets in bpf_sk_assign\")."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:40.363Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/2271276ac5279d2d204be7739a1a28d4ef6cf608"
},
{
"url": "https://git.kernel.org/stable/c/7ffe529e7127411806c8692fb1490f552c629dc2"
},
{
"url": "https://git.kernel.org/stable/c/17b7ef6b86112a4e61cee1e9009a4b318e3225c5"
},
{
"url": "https://git.kernel.org/stable/c/250474c69bc3fc48a5fc21d7c349f279caad947a"
},
{
"url": "https://git.kernel.org/stable/c/8692655da369961128658cf8539334b6a960ecb0"
},
{
"url": "https://git.kernel.org/stable/c/66efd3368ae10d05e08fbe6425b50fdec7186ac7"
}
],
"title": "bpf, sockmap: Reject unhashed UDP sockets on sockmap update",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68386",
"datePublished": "2026-08-10T12:04:05.306Z",
"dateReserved": "2026-07-30T09:28:09.388Z",
"dateUpdated": "2026-08-19T16:34:40.363Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74717 (GCVE-0-2026-74717)
Vulnerability from cvelistv5
Published
2026-08-22 15:33
Modified
2026-08-25 05:41
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/mlx5: fw_tracer, return NULL on create error
Tracer creation can fail by returning either NULL or ERR_PTR.
The return value is stored without a check on the device, and users
treat ERR_PTR and NULL the same way.
This also causes a crash in the core dump logic, which is missing the
ERR_PTR check and ends up dereferencing it, as shown in the trace below.
Switch tracer creation to return NULL on failure only, so callers only
need a single NULL check.
Internal error: Oops: 0000000096000006 [#1] SMP
Modules linked in: mlx5_ib ib_uverbs ib_core ipv6 mlx5_core
CPU: 1 UID: 0 PID: 12 Comm: kworker/u16:0 Not tainted 6.19.7 #1 PREEMPT(none)
Workqueue: mlx5_health0001:01:00.0 mlx5_fw_reporter_err_work [mlx5_core]
pstate: a3400009 (NzCv daif +PAN -UAO +TCO +DIT -SSBS BTYPE=--)
pc : mlx5_fw_tracer_trigger_core_dump_general+0x58/0xe0 [mlx5_core]
lr : mlx5_fw_tracer_trigger_core_dump_general+0x40/0xe0 [mlx5_core]
sp : ffff800081cf3c40
x29: ffff800081cf3c90 x28: 0000000000000000 x27: 0000000000000000
x26: ffff000080018828 x25: 0000000000000000 x24: ffff000080304a05
x23: ffff800081cf3d80 x22: ffff0000847e01a0 x21: 0000000000000000
x20: ffff0000847e01a0 x19: ffffffffffffffa1 x18: ffff80008310bbf0
x17: ffff800080119650 x16: ffff80008010df54 x15: ffff80008010d4ac
x14: ffff800079c202e4 x13: ffff80008002fe60 x12: ffff800080119650
x11: ffff80008010df54 x10: ffff80008010d4ac x9 : ffff800079c203d8
x8 : ffff800081cf3c88 x7 : 0000000000000000 x6 : 0000000000000000
x5 : 0000000000000000 x4 : 0000000000000008 x3 : 0000000000000030
x2 : 0000000000000008 x1 : 0000000000000000 x0 : 00000000c5c4000e
Call trace:
mlx5_fw_tracer_trigger_core_dump_general+0x58/0xe0 [mlx5_core] (P)
mlx5_fw_reporter_dump+0x30/0x2e0 [mlx5_core]
devlink_health_do_dump+0x9c/0x160
devlink_health_report+0x1c0/0x288
mlx5_fw_reporter_err_work+0xac/0xc0 [mlx5_core]
process_one_work+0x15c/0x3d8
worker_thread+0x18c/0x320
kthread+0x148/0x228
ret_from_fork+0x10/0x20
Code: b9400000 5ac00800 7a401800 540003ca (3940a260)
---[ end trace 0000000000000000 ]---
Kernel panic - not syncing: Oops: Fatal exception
SMP: stopping secondary CPUs
Kernel Offset: disabled
CPU features: 0x000000,00078031,75fce5a1,35fffe67
Memory Limit: none
---[ end Kernel panic - not syncing: Oops: Fatal exception ]---
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: fd1483fe1f9fd45fe312adffb0faffa57446690d Version: fd1483fe1f9fd45fe312adffb0faffa57446690d Version: fd1483fe1f9fd45fe312adffb0faffa57446690d Version: fd1483fe1f9fd45fe312adffb0faffa57446690d Version: fd1483fe1f9fd45fe312adffb0faffa57446690d Version: fd1483fe1f9fd45fe312adffb0faffa57446690d Version: fd1483fe1f9fd45fe312adffb0faffa57446690d Version: fd1483fe1f9fd45fe312adffb0faffa57446690d |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/mellanox/mlx5/core/diag/fw_tracer.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "47fe0d2571e5b446a0f0b0c1d6b99f55e51f5cc0",
"status": "affected",
"version": "fd1483fe1f9fd45fe312adffb0faffa57446690d",
"versionType": "git"
},
{
"lessThan": "ee41ea49c4ab0e4015919f52ad23ec251d3b39d3",
"status": "affected",
"version": "fd1483fe1f9fd45fe312adffb0faffa57446690d",
"versionType": "git"
},
{
"lessThan": "04599570c3a18f9ae7aad36825eb46f3dcd2c4e3",
"status": "affected",
"version": "fd1483fe1f9fd45fe312adffb0faffa57446690d",
"versionType": "git"
},
{
"lessThan": "9a416f000285a94c1b723877547981dec8132434",
"status": "affected",
"version": "fd1483fe1f9fd45fe312adffb0faffa57446690d",
"versionType": "git"
},
{
"lessThan": "b1d6375b9a63c9dc7e5e780d3ea9b126fe30d6cb",
"status": "affected",
"version": "fd1483fe1f9fd45fe312adffb0faffa57446690d",
"versionType": "git"
},
{
"lessThan": "80094352bd40ba54a33731f9c22872493983ed6d",
"status": "affected",
"version": "fd1483fe1f9fd45fe312adffb0faffa57446690d",
"versionType": "git"
},
{
"lessThan": "4aafa600d93e9551c1f24e785d57cbd4adf021d5",
"status": "affected",
"version": "fd1483fe1f9fd45fe312adffb0faffa57446690d",
"versionType": "git"
},
{
"lessThan": "af39eb111ce6b5eba9c08513b62c4868eb7e7fd5",
"status": "affected",
"version": "fd1483fe1f9fd45fe312adffb0faffa57446690d",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/mellanox/mlx5/core/diag/fw_tracer.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.3"
},
{
"lessThan": "5.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: fw_tracer, return NULL on create error\n\nTracer creation can fail by returning either NULL or ERR_PTR.\nThe return value is stored without a check on the device, and users\ntreat ERR_PTR and NULL the same way.\nThis also causes a crash in the core dump logic, which is missing the\nERR_PTR check and ends up dereferencing it, as shown in the trace below.\n\nSwitch tracer creation to return NULL on failure only, so callers only\nneed a single NULL check.\n\n Internal error: Oops: 0000000096000006 [#1] SMP\n Modules linked in: mlx5_ib ib_uverbs ib_core ipv6 mlx5_core\n CPU: 1 UID: 0 PID: 12 Comm: kworker/u16:0 Not tainted 6.19.7 #1 PREEMPT(none)\n Workqueue: mlx5_health0001:01:00.0 mlx5_fw_reporter_err_work [mlx5_core]\n pstate: a3400009 (NzCv daif +PAN -UAO +TCO +DIT -SSBS BTYPE=--)\n pc : mlx5_fw_tracer_trigger_core_dump_general+0x58/0xe0 [mlx5_core]\n lr : mlx5_fw_tracer_trigger_core_dump_general+0x40/0xe0 [mlx5_core]\n sp : ffff800081cf3c40\n x29: ffff800081cf3c90 x28: 0000000000000000 x27: 0000000000000000\n x26: ffff000080018828 x25: 0000000000000000 x24: ffff000080304a05\n x23: ffff800081cf3d80 x22: ffff0000847e01a0 x21: 0000000000000000\n x20: ffff0000847e01a0 x19: ffffffffffffffa1 x18: ffff80008310bbf0\n x17: ffff800080119650 x16: ffff80008010df54 x15: ffff80008010d4ac\n x14: ffff800079c202e4 x13: ffff80008002fe60 x12: ffff800080119650\n x11: ffff80008010df54 x10: ffff80008010d4ac x9 : ffff800079c203d8\n x8 : ffff800081cf3c88 x7 : 0000000000000000 x6 : 0000000000000000\n x5 : 0000000000000000 x4 : 0000000000000008 x3 : 0000000000000030\n x2 : 0000000000000008 x1 : 0000000000000000 x0 : 00000000c5c4000e\n Call trace:\n mlx5_fw_tracer_trigger_core_dump_general+0x58/0xe0 [mlx5_core] (P)\n mlx5_fw_reporter_dump+0x30/0x2e0 [mlx5_core]\n devlink_health_do_dump+0x9c/0x160\n devlink_health_report+0x1c0/0x288\n mlx5_fw_reporter_err_work+0xac/0xc0 [mlx5_core]\n process_one_work+0x15c/0x3d8\n worker_thread+0x18c/0x320\n kthread+0x148/0x228\n ret_from_fork+0x10/0x20\n Code: b9400000 5ac00800 7a401800 540003ca (3940a260)\n ---[ end trace 0000000000000000 ]---\n Kernel panic - not syncing: Oops: Fatal exception\n SMP: stopping secondary CPUs\n Kernel Offset: disabled\n CPU features: 0x000000,00078031,75fce5a1,35fffe67\n Memory Limit: none\n ---[ end Kernel panic - not syncing: Oops: Fatal exception ]---"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - On internet-facing cloud/HPC hosts with mlx5 PF NICs, a remote attacker can induce ConnectX firmware syndrome via crafted network/RDMA traffic; the kernel health poller then auto-invokes mlx5_fw_reporter_dump without any local syscall.\nAC:L - On affected hardware, mlx5_fw_tracer_create leaves ERR_PTR in dev-\u003etracer at probe (e.g. -EOPNOTSUPP when trace_to_memory is unset); once present, any FW syndrome or health miss counter event reliably queues the dump workqueue that dereferences the bad pointer.\nPR:N - The crash path shown in the fix oops is triggered automatically by mlx5_fw_reporter_err_work from the health poller with no userspace action; inducing FW syndrome over the network requires no host credentials, unlike the optional devlink dump path that needs CAP_NET_ADMIN.\nUI:N - Exploitation requires no victim interaction; the devlink health auto_dump fires from kernel workqueues when firmware reports a syndrome or miss-count threshold, independent of user actions such as mounts or file opens.\nS:U - Impact is confined to kernel crash/panic on the host running mlx5_core; there is no VM escape, IOMMU bypass, or crossing from guest VF context into a separate security authority beyond standard host kernel failure.\nC:N - The bug is an ERR_PTR mishandled as a valid mlx5_fw_tracer pointer; mlx5_fw_tracer_trigger_core_dump_general dereferences tracer-\u003eowner and faults immediately, producing an oops with no out-of-bounds read, UAF, or information disclosure primitive.\nI:N - Faulting on an ERR_PTR-encoded address does not corrupt adjacent memory or provide a controllable write primitive; the only outcome is an unrecoverable kernel oops/panic, not arbitrary modification or code execution.\nA:H - The fix commit documents a fatal kernel Oops in mlx5_fw_tracer_trigger_core_dump_general followed by \u0027Kernel panic - not syncing\u0027, causing complete loss of host availability on affected mlx5 PF systems when the FW reporter dump path runs."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:41:59.788Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/47fe0d2571e5b446a0f0b0c1d6b99f55e51f5cc0"
},
{
"url": "https://git.kernel.org/stable/c/ee41ea49c4ab0e4015919f52ad23ec251d3b39d3"
},
{
"url": "https://git.kernel.org/stable/c/04599570c3a18f9ae7aad36825eb46f3dcd2c4e3"
},
{
"url": "https://git.kernel.org/stable/c/9a416f000285a94c1b723877547981dec8132434"
},
{
"url": "https://git.kernel.org/stable/c/b1d6375b9a63c9dc7e5e780d3ea9b126fe30d6cb"
},
{
"url": "https://git.kernel.org/stable/c/80094352bd40ba54a33731f9c22872493983ed6d"
},
{
"url": "https://git.kernel.org/stable/c/4aafa600d93e9551c1f24e785d57cbd4adf021d5"
},
{
"url": "https://git.kernel.org/stable/c/af39eb111ce6b5eba9c08513b62c4868eb7e7fd5"
}
],
"title": "net/mlx5: fw_tracer, return NULL on create error",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74717",
"datePublished": "2026-08-22T15:33:11.488Z",
"dateReserved": "2026-08-15T05:44:03.928Z",
"dateUpdated": "2026-08-25T05:41:59.788Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68411 (GCVE-0-2026-68411)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-19 16:35
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211_hwsim: clamp virtio RX length before skb_put
hwsim_virtio_rx_work() passes the virtqueue used-ring length reported by
the device straight to skb_put() on a fixed-size receive skb. A backend
reporting a length larger than the skb tailroom drives skb_put() past the
buffer end and hits skb_over_panic() -- a host-triggerable guest panic
(denial of service).
Clamp the length to the skb's available room before skb_put(). A
conforming device never reports more than the posted buffer size, so valid
frames are unaffected; a truncated over-report then fails the
length/header checks in hwsim_virtio_handle_cmd() and is dropped, so
truncating rather than dropping here cannot be turned into a parsing
problem.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 5d44fe7c9808c56e136e59147bd932f5491520f1 Version: 5d44fe7c9808c56e136e59147bd932f5491520f1 Version: 5d44fe7c9808c56e136e59147bd932f5491520f1 Version: 5d44fe7c9808c56e136e59147bd932f5491520f1 Version: 5d44fe7c9808c56e136e59147bd932f5491520f1 Version: 5d44fe7c9808c56e136e59147bd932f5491520f1 Version: 5d44fe7c9808c56e136e59147bd932f5491520f1 Version: 5d44fe7c9808c56e136e59147bd932f5491520f1 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/virtual/mac80211_hwsim_main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "7f9d678b870fca8eaf1d46fa915cba0b1d5b387a",
"status": "affected",
"version": "5d44fe7c9808c56e136e59147bd932f5491520f1",
"versionType": "git"
},
{
"lessThan": "909573d6a9b67354fc0515952574564e7c909c62",
"status": "affected",
"version": "5d44fe7c9808c56e136e59147bd932f5491520f1",
"versionType": "git"
},
{
"lessThan": "5779e4a33e1666ddfeba43e96e29c4a9e5254ff0",
"status": "affected",
"version": "5d44fe7c9808c56e136e59147bd932f5491520f1",
"versionType": "git"
},
{
"lessThan": "82c5a30a66e2a7337d99476c67d6fc1a99c4250e",
"status": "affected",
"version": "5d44fe7c9808c56e136e59147bd932f5491520f1",
"versionType": "git"
},
{
"lessThan": "fade308845c89f784da8a6780c1e77258488f1b6",
"status": "affected",
"version": "5d44fe7c9808c56e136e59147bd932f5491520f1",
"versionType": "git"
},
{
"lessThan": "6dc76371a9a360c29de00df5b11563102d9d675a",
"status": "affected",
"version": "5d44fe7c9808c56e136e59147bd932f5491520f1",
"versionType": "git"
},
{
"lessThan": "99dc05c75acc3c8cde8d89c5371f4b569de5ac62",
"status": "affected",
"version": "5d44fe7c9808c56e136e59147bd932f5491520f1",
"versionType": "git"
},
{
"lessThan": "10a2b430f8f06ae14b9590b6f6faa6b588ef0654",
"status": "affected",
"version": "5d44fe7c9808c56e136e59147bd932f5491520f1",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/virtual/mac80211_hwsim_main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.7"
},
{
"lessThan": "5.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211_hwsim: clamp virtio RX length before skb_put\n\nhwsim_virtio_rx_work() passes the virtqueue used-ring length reported by\nthe device straight to skb_put() on a fixed-size receive skb. A backend\nreporting a length larger than the skb tailroom drives skb_put() past the\nbuffer end and hits skb_over_panic() -- a host-triggerable guest panic\n(denial of service).\n\nClamp the length to the skb\u0027s available room before skb_put(). A\nconforming device never reports more than the posted buffer size, so valid\nframes are unaffected; a truncated over-report then fails the\nlength/header checks in hwsim_virtio_handle_cmd() and is dropped, so\ntruncating rather than dropping here cannot be turned into a parsing\nproblem."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:35:07.403Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/7f9d678b870fca8eaf1d46fa915cba0b1d5b387a"
},
{
"url": "https://git.kernel.org/stable/c/909573d6a9b67354fc0515952574564e7c909c62"
},
{
"url": "https://git.kernel.org/stable/c/5779e4a33e1666ddfeba43e96e29c4a9e5254ff0"
},
{
"url": "https://git.kernel.org/stable/c/82c5a30a66e2a7337d99476c67d6fc1a99c4250e"
},
{
"url": "https://git.kernel.org/stable/c/fade308845c89f784da8a6780c1e77258488f1b6"
},
{
"url": "https://git.kernel.org/stable/c/6dc76371a9a360c29de00df5b11563102d9d675a"
},
{
"url": "https://git.kernel.org/stable/c/99dc05c75acc3c8cde8d89c5371f4b569de5ac62"
},
{
"url": "https://git.kernel.org/stable/c/10a2b430f8f06ae14b9590b6f6faa6b588ef0654"
}
],
"title": "wifi: mac80211_hwsim: clamp virtio RX length before skb_put",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68411",
"datePublished": "2026-08-10T12:04:31.532Z",
"dateReserved": "2026-07-30T09:28:09.391Z",
"dateUpdated": "2026-08-19T16:35:07.403Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64562 (GCVE-0-2026-64562)
Vulnerability from cvelistv5
Published
2026-08-04 06:23
Modified
2026-08-19 16:28
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
KVM: nVMX: Hide shadow VMCS right after VMCLEAR
free_nested() frees the shadow VMCS while vmcs01 still points to it. But
because it is asynchronous with respect to loaded_vmcs_clear(), the vCPU
might migrate before the pointer is cleared and __loaded_vmcs_clear()
may then execute VMCLEAR.
The VMCS needs to stay attached until its explicit VMCLEAR completes, but
then it can be hidden and the page safely freed.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 355f4fb1405ec29d0fac49b4d41fcd78cbd455d5 Version: 355f4fb1405ec29d0fac49b4d41fcd78cbd455d5 Version: 355f4fb1405ec29d0fac49b4d41fcd78cbd455d5 Version: 355f4fb1405ec29d0fac49b4d41fcd78cbd455d5 Version: 355f4fb1405ec29d0fac49b4d41fcd78cbd455d5 Version: 355f4fb1405ec29d0fac49b4d41fcd78cbd455d5 Version: 355f4fb1405ec29d0fac49b4d41fcd78cbd455d5 Version: 355f4fb1405ec29d0fac49b4d41fcd78cbd455d5 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"arch/x86/kvm/vmx/nested.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b82c3144d8264265448292ca406f60bafeba3b6f",
"status": "affected",
"version": "355f4fb1405ec29d0fac49b4d41fcd78cbd455d5",
"versionType": "git"
},
{
"lessThan": "4f50e6aec16f69627dbad5704d1e90a255d766a7",
"status": "affected",
"version": "355f4fb1405ec29d0fac49b4d41fcd78cbd455d5",
"versionType": "git"
},
{
"lessThan": "dc3eecfa219ebc9d01eaf7d1abd1441efe884dab",
"status": "affected",
"version": "355f4fb1405ec29d0fac49b4d41fcd78cbd455d5",
"versionType": "git"
},
{
"lessThan": "af56298e9d86e6098cd1d2e155cb2949b7c45412",
"status": "affected",
"version": "355f4fb1405ec29d0fac49b4d41fcd78cbd455d5",
"versionType": "git"
},
{
"lessThan": "589419470030a89f16cf19300658b6dc644ca946",
"status": "affected",
"version": "355f4fb1405ec29d0fac49b4d41fcd78cbd455d5",
"versionType": "git"
},
{
"lessThan": "8001d2ce9d9bd09118ce523aef595aa094573ae3",
"status": "affected",
"version": "355f4fb1405ec29d0fac49b4d41fcd78cbd455d5",
"versionType": "git"
},
{
"lessThan": "1dabef6e206568bf9d9ade74f6e56a48ea35695d",
"status": "affected",
"version": "355f4fb1405ec29d0fac49b4d41fcd78cbd455d5",
"versionType": "git"
},
{
"lessThan": "622ebfac01ba4f9c0060cebd41257fe46fc4a0b3",
"status": "affected",
"version": "355f4fb1405ec29d0fac49b4d41fcd78cbd455d5",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"arch/x86/kvm/vmx/nested.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.9"
},
{
"lessThan": "4.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: nVMX: Hide shadow VMCS right after VMCLEAR\n\nfree_nested() frees the shadow VMCS while vmcs01 still points to it. But\nbecause it is asynchronous with respect to loaded_vmcs_clear(), the vCPU\nmight migrate before the pointer is cleared and __loaded_vmcs_clear()\nmay then execute VMCLEAR.\n\nThe VMCS needs to stay attached until its explicit VMCLEAR completes, but\nthen it can be hidden and the page safely freed."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached through local KVM nested VMX: open /dev/kvm, run a nested guest, then tear down nested state (VMXOFF/handle_vmxoff or vmx_leave_nested). It is not reachable via network or adjacent-radio packets.\nAC:L - A KVM VMM attacker controls both sides of the race by driving nested teardown (VMXOFF/vcpu destroy) while forcing vCPU migration via thread affinity/scheduling so __loaded_vmcs_clear() VMCLEARs the dangling shadow VMCS pointer.\nPR:L - Exploitation needs permission to use /dev/kvm and nested VMX (commonly kvm-group or equivalent), not real init-namespace root; KVM create/run ioctls have no CAP_SYS_ADMIN gate on this path.\nUI:N - After the attacker has KVM/nested access, they trigger free_nested and migration themselves; no separate victim action is required.\nS:C - free_nested runs in host KVM while handling L1 nested VMX teardown, and the UAF corrupts host kernel memory, crossing the guest/hypervisor isolation boundary (guest-to-host escape class).\nC:H - The dangling shadow VMCS pointer lets VMCLEAR operate on a freed page that may be reused, yielding a host kernel use-after-free that can be leveraged for arbitrary information disclosure.\nI:H - VMCLEAR writes VMCS state into the freed page; with page reuse this is host heap corruption enabling write primitives and potential host code execution, consistent with UAF guidance.\nA:H - Use-after-free of the shadow VMCS page can oops/panic the host kernel when VMCLEAR or later accessors touch reallocated memory, fully denying host availability."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:28:32.954Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b82c3144d8264265448292ca406f60bafeba3b6f"
},
{
"url": "https://git.kernel.org/stable/c/4f50e6aec16f69627dbad5704d1e90a255d766a7"
},
{
"url": "https://git.kernel.org/stable/c/dc3eecfa219ebc9d01eaf7d1abd1441efe884dab"
},
{
"url": "https://git.kernel.org/stable/c/af56298e9d86e6098cd1d2e155cb2949b7c45412"
},
{
"url": "https://git.kernel.org/stable/c/589419470030a89f16cf19300658b6dc644ca946"
},
{
"url": "https://git.kernel.org/stable/c/8001d2ce9d9bd09118ce523aef595aa094573ae3"
},
{
"url": "https://git.kernel.org/stable/c/1dabef6e206568bf9d9ade74f6e56a48ea35695d"
},
{
"url": "https://git.kernel.org/stable/c/622ebfac01ba4f9c0060cebd41257fe46fc4a0b3"
}
],
"title": "KVM: nVMX: Hide shadow VMCS right after VMCLEAR",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64562",
"datePublished": "2026-08-04T06:23:21.855Z",
"dateReserved": "2026-07-19T15:36:31.796Z",
"dateUpdated": "2026-08-19T16:28:32.954Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74678 (GCVE-0-2026-74678)
Vulnerability from cvelistv5
Published
2026-08-22 15:32
Modified
2026-08-25 05:41
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: usb: ax88179_178a: fix skb leak in ax88179_tx_fixup()
When the interface has NETIF_F_SG enabled and skb_linearize() fails in
ax88179_tx_fixup(), the function returns NULL without freeing the skb.
usbnet_start_xmit() treats a NULL return from tx_fixup() as a drop
(info->flags does not set FLAG_MULTI_PACKET for this driver), jumping
to the "drop" label where it does `if (skb) dev_kfree_skb_any(skb)`.
Because tx_fixup() returned NULL, the local skb variable in
usbnet_start_xmit() is NULL, so the original skb is never freed — a
memory leak on every TX frame whose linearization fails (i.e. under
memory pressure).
Free the skb before returning, matching the error handling already used
for the pskb_expand_head() failure path in the same function.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 16b1c4e01c89ba07367461e0bc4cb84993c2d027 Version: 16b1c4e01c89ba07367461e0bc4cb84993c2d027 Version: 16b1c4e01c89ba07367461e0bc4cb84993c2d027 Version: 16b1c4e01c89ba07367461e0bc4cb84993c2d027 Version: 16b1c4e01c89ba07367461e0bc4cb84993c2d027 Version: 16b1c4e01c89ba07367461e0bc4cb84993c2d027 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/usb/ax88179_178a.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "83a765cbd7b4d11b0b9fa1bb9d941ae911a2159b",
"status": "affected",
"version": "16b1c4e01c89ba07367461e0bc4cb84993c2d027",
"versionType": "git"
},
{
"lessThan": "1c63303659a2264bd55d9813df74cb4caeed5922",
"status": "affected",
"version": "16b1c4e01c89ba07367461e0bc4cb84993c2d027",
"versionType": "git"
},
{
"lessThan": "2be5091fa693b9119ad25a8bb8c149d236a23ade",
"status": "affected",
"version": "16b1c4e01c89ba07367461e0bc4cb84993c2d027",
"versionType": "git"
},
{
"lessThan": "58733b1dd46bb231d9d279c132a20ee46da1b664",
"status": "affected",
"version": "16b1c4e01c89ba07367461e0bc4cb84993c2d027",
"versionType": "git"
},
{
"lessThan": "4039cd807a5a46dc5f7618fffae926b8ad8455eb",
"status": "affected",
"version": "16b1c4e01c89ba07367461e0bc4cb84993c2d027",
"versionType": "git"
},
{
"lessThan": "1f428e30947395d9b9aacee03e25a4e6cfcad7a4",
"status": "affected",
"version": "16b1c4e01c89ba07367461e0bc4cb84993c2d027",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/usb/ax88179_178a.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.17"
},
{
"lessThan": "5.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.17",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: usb: ax88179_178a: fix skb leak in ax88179_tx_fixup()\n\nWhen the interface has NETIF_F_SG enabled and skb_linearize() fails in\nax88179_tx_fixup(), the function returns NULL without freeing the skb.\n\nusbnet_start_xmit() treats a NULL return from tx_fixup() as a drop\n(info-\u003eflags does not set FLAG_MULTI_PACKET for this driver), jumping\nto the \"drop\" label where it does `if (skb) dev_kfree_skb_any(skb)`.\nBecause tx_fixup() returned NULL, the local skb variable in\nusbnet_start_xmit() is NULL, so the original skb is never freed \u2014 a\nmemory leak on every TX frame whose linearization fails (i.e. under\nmemory pressure).\n\nFree the skb before returning, matching the error handling already used\nfor the pskb_expand_head() failure path in the same function."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - On systems using the common ASIX AX88179/AX88178A USB 3.0 GbE adapter as their uplink, remote peers induce outbound TSO/GSO traffic that reaches ax88179_tx_fixup() via __dev_queue_xmit\u2192netdev_start_xmit\u2192usbnet_start_xmit; attacker-supplied or reply traffic over the bound NIC is standard network reachability.\nAC:L - NETIF_F_SG and NETIF_F_TSO are always enabled at bind; an attacker can send non-linear egress skbs and deliberately exhaust GFP_ATOMIC/slab memory so skb_linearize() fails on demand\u2014both prerequisites are fully under attacker control without races or rare layout.\nPR:N - No capability or authentication gates the netdev TX path; any remote host exchanging IP traffic with a victim whose ax88179 interface is up can trigger usbnet_start_xmit without local shell access, credentials, or init-namespace privileges.\nUI:N - Exploitation needs only that the adapter is plugged in and carrying traffic\u2014the normal always-on state for USB-Ethernet docks, kiosks, and laptops\u2014not any one-time victim action such as mounting media or opening a file.\nS:U - Leaked sk_buff objects remain in kernel SLAB caches within the same kernel security authority; there is no VM escape, container breakout, IOMMU bypass, or cross-boundary corruption.\nC:N - Orphaned skbs are not freed but are not exposed to userspace or adjacent objects; there is no out-of-bounds read, use-after-free, or other disclosure primitive\u2014only silent kernel heap consumption.\nI:N - The defect drops an skb reference on an error return without corrupting heap metadata, overwriting kernel objects, or enabling arbitrary writes or control-flow hijacking.\nA:H - Each skb_linearize() failure permanently leaks one skb; under attacker-driven memory pressure an unauthenticated remote peer can repeat TSO egress to exhaust kernel memory, provoking OOM-killer thrashing and denial of service on the host."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:41:29.048Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/83a765cbd7b4d11b0b9fa1bb9d941ae911a2159b"
},
{
"url": "https://git.kernel.org/stable/c/1c63303659a2264bd55d9813df74cb4caeed5922"
},
{
"url": "https://git.kernel.org/stable/c/2be5091fa693b9119ad25a8bb8c149d236a23ade"
},
{
"url": "https://git.kernel.org/stable/c/58733b1dd46bb231d9d279c132a20ee46da1b664"
},
{
"url": "https://git.kernel.org/stable/c/4039cd807a5a46dc5f7618fffae926b8ad8455eb"
},
{
"url": "https://git.kernel.org/stable/c/1f428e30947395d9b9aacee03e25a4e6cfcad7a4"
}
],
"title": "net: usb: ax88179_178a: fix skb leak in ax88179_tx_fixup()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74678",
"datePublished": "2026-08-22T15:32:46.765Z",
"dateReserved": "2026-08-15T05:44:03.925Z",
"dateUpdated": "2026-08-25T05:41:29.048Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74514 (GCVE-0-2026-74514)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-23 12:47
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
KVM: s390: pci: Fix memory accounting for pinned/unpinned pages
The account_mem() and unaccount_mem() functions call get_uid() which
increments the reference count of struct user_struct on every invocation.
But we don't decrement the count by calling free_uid(). It also
accounted/unaccounted the pages against the current->mm. But its possible
the unaccount_mem() can be called from a different process context than the
one that originally pinned the pages.
Let's fix this by storing the pinning process user_struct and mm_struct
when accounting for pinned pages, and subsequently free these resources
when the pages are unpinned.
[borntraeger@linux.ibm.com: Fixed whitespace]
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc Version: 3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc Version: 3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc Version: 3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc Version: 3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc Version: 3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"arch/s390/kvm/pci.c",
"arch/s390/kvm/pci.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ad1c2ac7f15b224cf9ab26b593caa9bd1a4be72e",
"status": "affected",
"version": "3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc",
"versionType": "git"
},
{
"lessThan": "dc7465a364104526c56b922c9de9dfcc08a7d5f7",
"status": "affected",
"version": "3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc",
"versionType": "git"
},
{
"lessThan": "47cfd75d9df7c8f425b0d769328fe43a8a8e606e",
"status": "affected",
"version": "3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc",
"versionType": "git"
},
{
"lessThan": "70871b121f81d08879363cb1238a4c85c5c2800c",
"status": "affected",
"version": "3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc",
"versionType": "git"
},
{
"lessThan": "e3f732e086e438c52c7400bd2734bb166aa4752c",
"status": "affected",
"version": "3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc",
"versionType": "git"
},
{
"lessThan": "36f6999ecde3976731a8bfc0b8e667da6f593069",
"status": "affected",
"version": "3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"arch/s390/kvm/pci.c",
"arch/s390/kvm/pci.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.0"
},
{
"lessThan": "6.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: s390: pci: Fix memory accounting for pinned/unpinned pages\n\nThe account_mem() and unaccount_mem() functions call get_uid() which\nincrements the reference count of struct user_struct on every invocation.\nBut we don\u0027t decrement the count by calling free_uid(). It also\naccounted/unaccounted the pages against the current-\u003emm. But its possible\nthe unaccount_mem() can be called from a different process context than the\none that originally pinned the pages.\n\nLet\u0027s fix this by storing the pinning process user_struct and mm_struct\nwhen accounting for pinned pages, and subsequently free these resources\nwhen the pages are unpinned.\n\n[borntraeger@linux.ibm.com: Fixed whitespace]"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:47:32.122Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ad1c2ac7f15b224cf9ab26b593caa9bd1a4be72e"
},
{
"url": "https://git.kernel.org/stable/c/dc7465a364104526c56b922c9de9dfcc08a7d5f7"
},
{
"url": "https://git.kernel.org/stable/c/47cfd75d9df7c8f425b0d769328fe43a8a8e606e"
},
{
"url": "https://git.kernel.org/stable/c/70871b121f81d08879363cb1238a4c85c5c2800c"
},
{
"url": "https://git.kernel.org/stable/c/e3f732e086e438c52c7400bd2734bb166aa4752c"
},
{
"url": "https://git.kernel.org/stable/c/36f6999ecde3976731a8bfc0b8e667da6f593069"
}
],
"title": "KVM: s390: pci: Fix memory accounting for pinned/unpinned pages",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74514",
"datePublished": "2026-08-15T12:27:34.947Z",
"dateReserved": "2026-08-15T05:44:03.909Z",
"dateUpdated": "2026-08-23T12:47:32.122Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2025-40307 (GCVE-0-2025-40307)
Vulnerability from cvelistv5
Published
2025-12-08 00:46
Modified
2026-08-19 16:27
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
exfat: validate cluster allocation bits of the allocation bitmap
syzbot created an exfat image with cluster bits not set for the allocation
bitmap. exfat-fs reads and uses the allocation bitmap without checking
this. The problem is that if the start cluster of the allocation bitmap
is 6, cluster 6 can be allocated when creating a directory with mkdir.
exfat zeros out this cluster in exfat_mkdir, which can delete existing
entries. This can reallocate the allocated entries. In addition,
the allocation bitmap is also zeroed out, so cluster 6 can be reallocated.
This patch adds exfat_test_bitmap_range to validate that clusters used for
the allocation bitmap are correctly marked as in-use.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/exfat/balloc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "87f827d53bd0688597bda63ae95908e2ad39bac0",
"status": "affected",
"version": "1acf1a564b6034b5af1e7fb23cb98cb3bb4f6003",
"versionType": "git"
},
{
"lessThan": "67ce8034dc0278ddd88cad93d4218a945180dddd",
"status": "affected",
"version": "1acf1a564b6034b5af1e7fb23cb98cb3bb4f6003",
"versionType": "git"
},
{
"lessThan": "6bc58b4c53795ab5fe00648344aa7d9d61175f90",
"status": "affected",
"version": "1acf1a564b6034b5af1e7fb23cb98cb3bb4f6003",
"versionType": "git"
},
{
"lessThan": "13c1d24803d5b0446b3f6f0fdd67e07ac1fdc7bf",
"status": "affected",
"version": "1acf1a564b6034b5af1e7fb23cb98cb3bb4f6003",
"versionType": "git"
},
{
"lessThan": "79c1587b6cda74deb0c86fc7ba194b92958c793c",
"status": "affected",
"version": "1acf1a564b6034b5af1e7fb23cb98cb3bb4f6003",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/exfat/balloc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.7"
},
{
"lessThan": "5.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.58",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.17.*",
"status": "unaffected",
"version": "6.17.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "6.18",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.58",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.17.8",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18",
"versionStartIncluding": "5.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nexfat: validate cluster allocation bits of the allocation bitmap\n\nsyzbot created an exfat image with cluster bits not set for the allocation\nbitmap. exfat-fs reads and uses the allocation bitmap without checking\nthis. The problem is that if the start cluster of the allocation bitmap\nis 6, cluster 6 can be allocated when creating a directory with mkdir.\nexfat zeros out this cluster in exfat_mkdir, which can delete existing\nentries. This can reallocate the allocated entries. In addition,\nthe allocation bitmap is also zeroed out, so cluster 6 can be reallocated.\nThis patch adds exfat_test_bitmap_range to validate that clusters used for\nthe allocation bitmap are correctly marked as in-use."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable code is reached by getting a crafted exFAT image mounted from a local block device, loop file, or removable medium and then issuing a local `mkdir()`; there is no network consumer of `exfat_allocate_bitmap()`.\nAC:L - The attacker fully controls the image: clearing the bitmap\u0027s own allocation bit and pointing `start_clu` at a low cluster makes `exfat_find_free_bitmap()` deterministically return that cluster on the very first allocation, so a single `mkdir` reliably zeroes the live bitmap with no race, heap shaping, or memory-layout dependency.\nPR:L - Direct `mount()` needs CAP_SYS_ADMIN, but ubiquitous privileged mount brokers (udisks2, systemd-mount, autofs, Android vold) let an unprivileged local user get an attacker-supplied exFAT volume or loop image mounted rw, after which any user with write access to the mount can run the triggering `mkdir`.\nUI:N - The attacker requests the mount through the automount broker and runs `mkdir` themselves; on a kiosk or shared workstation inserting their own exFAT stick achieves the same, with no action required from any other user or administrator.\nS:U - The corruption and its consequences are confined to the kernel and filesystem that own the mount; no VM, IOMMU, container, or other security-authority boundary is crossed.\nC:H - Once the bitmap is zeroed the allocator re-hands out clusters that are still live, so a newly created file is backed by clusters holding the root directory, other files\u0027 data, and the allocation bitmap itself \u2014 reading that file discloses their full contents, an unbounded read of co-resident data on the shared volume rather than a small bounded leak.\nI:H - This is the core defect: the kernel zeroes and overwrites in-use on-disk metadata (\"can delete existing entries\") and reallocates already-allocated clusters, so attacker-controlled file writes land directly in directory entries and in the live in-kernel allocation bitmap, giving unbounded modification of structures the filesystem subsequently trusts.\nA:H - The zeroed bitmap makes every `exfat_clear_bitmap()` fail with `-EIO`, desyncs `used_clusters` into `exfat_fs_error_ratelimit()`, and produces aliased/looping cluster chains that yield task hangs and the syzbot-reported deadlock WARNING; with `errors=panic`, `panic_on_warn`, or `panic_on_oops` this is a full panic, and the volume is left permanently unusable."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:27:52.404Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/87f827d53bd0688597bda63ae95908e2ad39bac0"
},
{
"url": "https://git.kernel.org/stable/c/67ce8034dc0278ddd88cad93d4218a945180dddd"
},
{
"url": "https://git.kernel.org/stable/c/6bc58b4c53795ab5fe00648344aa7d9d61175f90"
},
{
"url": "https://git.kernel.org/stable/c/13c1d24803d5b0446b3f6f0fdd67e07ac1fdc7bf"
},
{
"url": "https://git.kernel.org/stable/c/79c1587b6cda74deb0c86fc7ba194b92958c793c"
}
],
"title": "exfat: validate cluster allocation bits of the allocation bitmap",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2025-40307",
"datePublished": "2025-12-08T00:46:32.659Z",
"dateReserved": "2025-04-16T07:20:57.185Z",
"dateUpdated": "2026-08-19T16:27:52.404Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80725 (GCVE-0-2026-80725)
Vulnerability from cvelistv5
Published
2026-08-29 06:39
Modified
2026-09-04 04:58
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: gro: properly validate BIG TCP aggregation criteria
When GRO attempts to aggregate packets beyond GRO_LEGACY_MAX_SIZE (64KB),
BIG TCP should only be permitted for plain IPv4 TCP and plain IPv6 TCP
(with sufficient MAC header room to insert the temporary HBH jumbo header).
However, commit b1a78b9b9886 ("net: add support for ipv4 big tcp")
loosened the check in skb_gro_receive(), leading to several issues:
1. skb_gro_receive() checked skb_headroom(p) instead of the actual space
before the MAC header (p->mac_header). Because skb_headroom(p) includes
mac_len, crafted frames (e.g. injected via AF_PACKET) can pass the check
with p->mac_header < 8 bytes. When ipv6_gro_complete() inserts the
temporary HBH jumbo header, the memmove() starts before skb->head,
causing an out-of-bounds write and wrapping skb->mac_header.
2. It allowed non-IP protocols such as software VLAN (ETH_P_8021Q /
ETH_P_8021AD) to aggregate beyond 64KB because
p->protocol != ETH_P_IPV6 was true.
3. It checked p->encapsulation instead of NAPI_GRO_CB(skb)->encap_mark,
allowing encapsulated flows (e.g. SIT / IPv6-in-IPv4) to aggregate
beyond 64KB.
Fix skb_gro_receive() to strictly enforce:
- NAPI_GRO_CB(skb)->proto == IPPROTO_TCP
- Not encapsulated (!NAPI_GRO_CB(skb)->encap_mark && !p->encapsulation)
- Protocol must be either ETH_P_IP or ETH_P_IPV6
- If ETH_P_IPV6, p->mac_header must be at least
sizeof(struct hop_jumbo_hdr)
Returning -E2BIG from skb_gro_receive() ensures that packets which cannot
become BIG TCP are cleanly flushed at <= 64KB and delivered intact without
dropping.
This issue does not exist in mainline (7.0+) because the subsystem was
rewritten in commit 81be30c1f5f2 ("net/ipv6: Drop HBH for BIG TCP on RX
side"), making this fix relevant only for older stable branches like
6.18.y.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/core/gro.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "37a5dcd6837fc2afc44a7bc3ed8af4e983783d46",
"status": "affected",
"version": "0fe79f28bfaf73b66b7b1562d2468f94aa03bd12",
"versionType": "git"
},
{
"lessThan": "e907bf694ed55bdfe421be99dba35751a655df25",
"status": "affected",
"version": "0fe79f28bfaf73b66b7b1562d2468f94aa03bd12",
"versionType": "git"
},
{
"lessThan": "03cb8cc2961f5f781d12e903782cb3815ed84b1c",
"status": "affected",
"version": "0fe79f28bfaf73b66b7b1562d2468f94aa03bd12",
"versionType": "git"
},
{
"lessThan": "3ce832e2bd431d0c12ba525ed73ad8fbc4191da5",
"status": "affected",
"version": "0fe79f28bfaf73b66b7b1562d2468f94aa03bd12",
"versionType": "git"
},
{
"lessThan": "81be30c1f5f2bffda1f04c0efd0746af10b9643a",
"status": "affected",
"version": "0fe79f28bfaf73b66b7b1562d2468f94aa03bd12",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/core/gro.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.19"
},
{
"lessThan": "5.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.185",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.154",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.106",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.47",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.0",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.185",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.154",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.106",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.47",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0",
"versionStartIncluding": "5.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: gro: properly validate BIG TCP aggregation criteria\n\nWhen GRO attempts to aggregate packets beyond GRO_LEGACY_MAX_SIZE (64KB),\nBIG TCP should only be permitted for plain IPv4 TCP and plain IPv6 TCP\n(with sufficient MAC header room to insert the temporary HBH jumbo header).\n\nHowever, commit b1a78b9b9886 (\"net: add support for ipv4 big tcp\")\nloosened the check in skb_gro_receive(), leading to several issues:\n\n1. skb_gro_receive() checked skb_headroom(p) instead of the actual space\n before the MAC header (p-\u003emac_header). Because skb_headroom(p) includes\n mac_len, crafted frames (e.g. injected via AF_PACKET) can pass the check\n with p-\u003emac_header \u003c 8 bytes. When ipv6_gro_complete() inserts the\n temporary HBH jumbo header, the memmove() starts before skb-\u003ehead,\n causing an out-of-bounds write and wrapping skb-\u003emac_header.\n2. It allowed non-IP protocols such as software VLAN (ETH_P_8021Q /\n ETH_P_8021AD) to aggregate beyond 64KB because\n p-\u003eprotocol != ETH_P_IPV6 was true.\n3. It checked p-\u003eencapsulation instead of NAPI_GRO_CB(skb)-\u003eencap_mark,\n allowing encapsulated flows (e.g. SIT / IPv6-in-IPv4) to aggregate\n beyond 64KB.\n\nFix skb_gro_receive() to strictly enforce:\n- NAPI_GRO_CB(skb)-\u003eproto == IPPROTO_TCP\n- Not encapsulated (!NAPI_GRO_CB(skb)-\u003eencap_mark \u0026\u0026 !p-\u003eencapsulation)\n- Protocol must be either ETH_P_IP or ETH_P_IPV6\n- If ETH_P_IPV6, p-\u003emac_header must be at least\n sizeof(struct hop_jumbo_hdr)\n\nReturning -E2BIG from skb_gro_receive() ensures that packets which cannot\nbecome BIG TCP are cleanly flushed at \u003c= 64KB and delivered intact without\ndropping.\n\nThis issue does not exist in mainline (7.0+) because the subsystem was\nrewritten in commit 81be30c1f5f2 (\"net/ipv6: Drop HBH for BIG TCP on RX\nside\"), making this fix relevant only for older stable branches like\n6.18.y."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The flaw is in skb_gro_receive() on the netdev NAPI GRO ingress path (netif_receive_skb\u2192napi_gro_receive\u2192dev_gro_receive\u2192tcp/ipv6 gro handlers); remote peers can deliver crafted in-flow TCP streams to internet-facing interfaces without local access.\nAC:L - On Big TCP deployments with gro_max_size\u003e64KB, an attacker reliably coalesces past GRO_LEGACY_MAX_SIZE by sending many same-flow TCP segments; AF_PACKET injection also gives deterministic header layout control without races or victim-dependent heap layout.\nPR:N - RX GRO runs in softirq on all received packets before socket authentication; no target credentials or capabilities are required. Elevated gro_max_size is an admin tuning prerequisite of the Big TCP server class, not an attacker privilege.\nUI:N - Packet reception and GRO aggregation are automatic kernel network-stack processing triggered solely by attacker-sent traffic; no victim mount, file open, or other interaction is required.\nS:U - Impact is kernel skb/heap memory corruption within the host kernel security authority; exploitation does not cross VM, container, or IOMMU boundaries that would warrant scope-changed scoring.\nC:H - When undersized mac_header room passes the broken skb_headroom check, ipv6_gro_complete() memmove() for the temporary HBH jumbo header writes before skb-\u003ehead, corrupting adjacent kernel memory and enabling information disclosure from attacker-influenced out-of-bounds writes.\nI:H - The same invalid BIG TCP aggregation drives attacker-controlled memmove/header corruption that wraps skb-\u003emac_header, yielding an out-of-bounds write primitive suitable for heap object corruption, control-flow hijacking, and local privilege escalation.\nA:H - The defective memmove or invalid \u003e64KB aggregation on disallowed VLAN, encapsulated, or malformed flows can oops or panic the kernel during GRO completion, and a remote attacker can trigger this repeatedly to deny service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T04:58:15.396Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/37a5dcd6837fc2afc44a7bc3ed8af4e983783d46"
},
{
"url": "https://git.kernel.org/stable/c/e907bf694ed55bdfe421be99dba35751a655df25"
},
{
"url": "https://git.kernel.org/stable/c/03cb8cc2961f5f781d12e903782cb3815ed84b1c"
},
{
"url": "https://git.kernel.org/stable/c/3ce832e2bd431d0c12ba525ed73ad8fbc4191da5"
},
{
"url": "https://git.kernel.org/stable/c/81be30c1f5f2bffda1f04c0efd0746af10b9643a"
}
],
"title": "net: gro: properly validate BIG TCP aggregation criteria",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80725",
"datePublished": "2026-08-29T06:39:35.212Z",
"dateReserved": "2026-08-26T14:34:25.789Z",
"dateUpdated": "2026-09-04T04:58:15.396Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64272 (GCVE-0-2026-64272)
Vulnerability from cvelistv5
Published
2026-07-25 08:49
Modified
2026-08-23 12:45
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Input: mms114 - fix touch indexing for MMS134S and MMS136
The MMS134S and MMS136 touch controllers have an event size of 6 bytes
rather than 8 bytes. When __mms114_read_reg() reads the touch data
packet from the device into the touch buffer, the events are packed
tightly at 6-byte intervals. However, the driver iterates through the
events using standard C array indexing (touch[index]), where each
element is sizeof(struct mms114_touch) (8 bytes) apart. As a result, any
touch events beyond the first one are read from incorrect offsets and
parsed improperly.
Fix this by explicitly calculating the byte offset for each touch event
based on the device's specific event size.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 53fefdd1d3a3403d8c44e28898d1031d8763b913 Version: 53fefdd1d3a3403d8c44e28898d1031d8763b913 Version: 53fefdd1d3a3403d8c44e28898d1031d8763b913 Version: 53fefdd1d3a3403d8c44e28898d1031d8763b913 Version: 53fefdd1d3a3403d8c44e28898d1031d8763b913 Version: 53fefdd1d3a3403d8c44e28898d1031d8763b913 Version: 53fefdd1d3a3403d8c44e28898d1031d8763b913 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/input/touchscreen/mms114.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "062bbe55a1f6d77b89d07135ba3b09f97bfac1cb",
"status": "affected",
"version": "53fefdd1d3a3403d8c44e28898d1031d8763b913",
"versionType": "git"
},
{
"lessThan": "38de2979d90d8cd94f18e0567be4c8342d0e0410",
"status": "affected",
"version": "53fefdd1d3a3403d8c44e28898d1031d8763b913",
"versionType": "git"
},
{
"lessThan": "112666835071d935fef764aab590339e97216d4a",
"status": "affected",
"version": "53fefdd1d3a3403d8c44e28898d1031d8763b913",
"versionType": "git"
},
{
"lessThan": "7c00a0787af7164438bdbc97fcae9733cfc58d21",
"status": "affected",
"version": "53fefdd1d3a3403d8c44e28898d1031d8763b913",
"versionType": "git"
},
{
"lessThan": "75b12874b4172533b9efc349db328cb1a59c3981",
"status": "affected",
"version": "53fefdd1d3a3403d8c44e28898d1031d8763b913",
"versionType": "git"
},
{
"lessThan": "a747c4eb02656afdbd92eea83b88e92715a23977",
"status": "affected",
"version": "53fefdd1d3a3403d8c44e28898d1031d8763b913",
"versionType": "git"
},
{
"lessThan": "a6ac4e24c1a8a533bb61035184fdcc7eede4cc8d",
"status": "affected",
"version": "53fefdd1d3a3403d8c44e28898d1031d8763b913",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/input/touchscreen/mms114.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.13"
},
{
"lessThan": "5.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nInput: mms114 - fix touch indexing for MMS134S and MMS136\n\nThe MMS134S and MMS136 touch controllers have an event size of 6 bytes\nrather than 8 bytes. When __mms114_read_reg() reads the touch data\npacket from the device into the touch buffer, the events are packed\ntightly at 6-byte intervals. However, the driver iterates through the\nevents using standard C array indexing (touch[index]), where each\nelement is sizeof(struct mms114_touch) (8 bytes) apart. As a result, any\ntouch events beyond the first one are read from incorrect offsets and\nparsed improperly.\n\nFix this by explicitly calculating the byte offset for each touch event\nbased on the device\u0027s specific event size."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:45:38.059Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/062bbe55a1f6d77b89d07135ba3b09f97bfac1cb"
},
{
"url": "https://git.kernel.org/stable/c/38de2979d90d8cd94f18e0567be4c8342d0e0410"
},
{
"url": "https://git.kernel.org/stable/c/112666835071d935fef764aab590339e97216d4a"
},
{
"url": "https://git.kernel.org/stable/c/7c00a0787af7164438bdbc97fcae9733cfc58d21"
},
{
"url": "https://git.kernel.org/stable/c/75b12874b4172533b9efc349db328cb1a59c3981"
},
{
"url": "https://git.kernel.org/stable/c/a747c4eb02656afdbd92eea83b88e92715a23977"
},
{
"url": "https://git.kernel.org/stable/c/a6ac4e24c1a8a533bb61035184fdcc7eede4cc8d"
}
],
"title": "Input: mms114 - fix touch indexing for MMS134S and MMS136",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64272",
"datePublished": "2026-07-25T08:49:18.766Z",
"dateReserved": "2026-07-19T15:36:31.775Z",
"dateUpdated": "2026-08-23T12:45:38.059Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80684 (GCVE-0-2026-80684)
Vulnerability from cvelistv5
Published
2026-08-28 06:52
Modified
2026-08-29 06:22
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
KVM: s390: pci: Fix NULL dereference on AIBV allocation failure
The airq_iv_create() can return NULL on failure, but the return value was
never checked. If it fails, zdev->aibv will be NULL and fail when
dereferenced in kvm_zpci_set_airq(). Add a NULL check and free the
previously allocated AISB bit and zdev->aisb on failure.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc Version: 3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc Version: 3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc Version: 3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc Version: 3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc Version: 3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"arch/s390/kvm/pci.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "96099486b63985801c9c6ef22505e9aa635b2d20",
"status": "affected",
"version": "3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc",
"versionType": "git"
},
{
"lessThan": "0a95abe964400771ad82b027d7b84a0d183cd0db",
"status": "affected",
"version": "3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc",
"versionType": "git"
},
{
"lessThan": "df947d85e164a50a29d43a96e814f69ab1d0f7ed",
"status": "affected",
"version": "3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc",
"versionType": "git"
},
{
"lessThan": "e137d082325bbcae780087b57501d38585e625d9",
"status": "affected",
"version": "3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc",
"versionType": "git"
},
{
"lessThan": "d1a103dc9016c25e7423ce5841a5cc2df76d59f3",
"status": "affected",
"version": "3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc",
"versionType": "git"
},
{
"lessThan": "8bf09b9b7d3232806df95f409581f8a9fd99a3fa",
"status": "affected",
"version": "3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"arch/s390/kvm/pci.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.0"
},
{
"lessThan": "6.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: s390: pci: Fix NULL dereference on AIBV allocation failure\n\nThe airq_iv_create() can return NULL on failure, but the return value was\nnever checked. If it fails, zdev-\u003eaibv will be NULL and fail when\ndereferenced in kvm_zpci_set_airq(). Add a NULL check and free the\npreviously allocated AISB bit and zdev-\u003eaisb on failure."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.3,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached through the KVM_S390_ZPCI_OP VM ioctl (kvm_arch_vm_ioctl -\u003e kvm_s390_pci_zpci_op -\u003e kvm_s390_pci_aif_enable), a local syscall on the s390 hypervisor host, not via any network-facing kernel service.\nAC:L - An attacker can reliably trigger airq_iv_create() failure and the subsequent NULL dereference by issuing KVM_S390_ZPCIOP_REG_AEN under controlled host memory pressure or repeated registration attempts while holding a valid passthrough zPCI device context.\nPR:N - A malicious KVM guest with an assigned VFIO zPCI passthrough device can cause QEMU to issue KVM_S390_ZPCIOP_REG_AEN during normal adapter-event setup without possessing any host-root or init-namespace administrative credentials.\nUI:N - Exploitation requires no action by a separate victim user; triggering occurs through the attacker\u0027s own guest workload or VMM issuing the REG_AEN ioctl during standard zPCI passthrough interrupt-forwarding registration.\nS:C - The vulnerable KVM host code executes on behalf of a guest\u0027s passthrough device setup, and the resulting host kernel crash or corrupted global AIFT/GAIT interrupt-forwarding state impacts the hypervisor and resources outside the attacking guest\u0027s security boundary.\nC:H - Before the NULL dereference, unchecked allocation failure still populates host GAIT/summary-bit tables with attacker-influenced interrupt-routing fields, enabling misdelivery or exposure of adapter events intended for other guests or host contexts.\nI:H - Failed AIBV allocation leaves partially written host kernel interrupt-forwarding metadata (GAIT entries, kzdev pointers, summary-bit assignments) under attacker-controlled ioctl parameters, constituting exploitable kernel memory corruption prior to the crash.\nA:H - When zdev-\u003eaibv is NULL, kvm_zpci_set_airq() dereferences zdev-\u003eaibv-\u003evector and airq_iv_end(zdev-\u003eaibv), causing a host kernel oops/panic that denies availability to all VMs on the system."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-29T06:22:11.509Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/96099486b63985801c9c6ef22505e9aa635b2d20"
},
{
"url": "https://git.kernel.org/stable/c/0a95abe964400771ad82b027d7b84a0d183cd0db"
},
{
"url": "https://git.kernel.org/stable/c/df947d85e164a50a29d43a96e814f69ab1d0f7ed"
},
{
"url": "https://git.kernel.org/stable/c/e137d082325bbcae780087b57501d38585e625d9"
},
{
"url": "https://git.kernel.org/stable/c/d1a103dc9016c25e7423ce5841a5cc2df76d59f3"
},
{
"url": "https://git.kernel.org/stable/c/8bf09b9b7d3232806df95f409581f8a9fd99a3fa"
}
],
"title": "KVM: s390: pci: Fix NULL dereference on AIBV allocation failure",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80684",
"datePublished": "2026-08-28T06:52:50.703Z",
"dateReserved": "2026-08-26T14:34:25.784Z",
"dateUpdated": "2026-08-29T06:22:11.509Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72172 (GCVE-0-2026-72172)
Vulnerability from cvelistv5
Published
2026-08-15 05:53
Modified
2026-08-23 12:47
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
mm/mm_init: fix uninitialized struct pages for ZONE_DEVICE
If DAX memory is hotplugged into an unoccupied subsection of an early
section, section_activate() reuses the unoptimized boot memmap. However,
compound_nr_pages() still assumes that vmemmap optimization is in effect
and initializes only the reduced number of struct pages. As a result, the
remaining tail struct pages are left uninitialized, which can later lead
to unexpected behavior or crashes.
Fix this by treating early sections as unoptimized when calculating how
many struct pages to initialize.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 6fd3620b342861de9547ea01d28f664892ef51a1 Version: 6fd3620b342861de9547ea01d28f664892ef51a1 Version: 6fd3620b342861de9547ea01d28f664892ef51a1 Version: 6fd3620b342861de9547ea01d28f664892ef51a1 Version: 6fd3620b342861de9547ea01d28f664892ef51a1 Version: 6fd3620b342861de9547ea01d28f664892ef51a1 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"mm/mm_init.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c5ef574d57e4a701485c13f26822328c91f05413",
"status": "affected",
"version": "6fd3620b342861de9547ea01d28f664892ef51a1",
"versionType": "git"
},
{
"lessThan": "511a60e71aec308b24722cffc1912bf6befb87bf",
"status": "affected",
"version": "6fd3620b342861de9547ea01d28f664892ef51a1",
"versionType": "git"
},
{
"lessThan": "11f2826e9ee6f24aaa774e3dcd75abbe4b3091b6",
"status": "affected",
"version": "6fd3620b342861de9547ea01d28f664892ef51a1",
"versionType": "git"
},
{
"lessThan": "da5234df0941665f3a3f5b80f3dab94046537be0",
"status": "affected",
"version": "6fd3620b342861de9547ea01d28f664892ef51a1",
"versionType": "git"
},
{
"lessThan": "b91e27bce37cab9f35de0059278ebe457ca9878b",
"status": "affected",
"version": "6fd3620b342861de9547ea01d28f664892ef51a1",
"versionType": "git"
},
{
"lessThan": "cd681403a87085562499d60325b7b45d3be11217",
"status": "affected",
"version": "6fd3620b342861de9547ea01d28f664892ef51a1",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"mm/mm_init.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.19"
},
{
"lessThan": "5.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/mm_init: fix uninitialized struct pages for ZONE_DEVICE\n\nIf DAX memory is hotplugged into an unoccupied subsection of an early\nsection, section_activate() reuses the unoptimized boot memmap. However,\ncompound_nr_pages() still assumes that vmemmap optimization is in effect\nand initializes only the reduced number of struct pages. As a result, the\nremaining tail struct pages are left uninitialized, which can later lead\nto unexpected behavior or crashes.\n\nFix this by treating early sections as unoptimized when calculating how\nmany struct pages to initialize."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The flaw is in memmap_init_zone_device() reached via memremap_pages()/devm_memremap_pages() during device-DAX driver probe or ZONE_DEVICE hotplug (e.g., dev_dax_probe, Hyper-V VTL), not via network protocols; subsequent impact is triggered by local mmap/page-fault/get_user_pages activity on the DAX device.\nAC:L - After device-DAX with compound vmemmap (vmemmap_shift\u003e0) is hotplugged into an unoccupied early-section subsection, uninitialized tail struct pages remain indefinitely; an attacker only needs to access that memory (e.g., mmap /dev/dax) to invoke kernel page-metadata operations, without races or uncontrollable victim state.\nPR:L - While initial ZONE_DEVICE hotplug requires administrator device-DAX configuration (daxctl/ndctl, driver bind), on a configured persistent-memory or cloud server unprivileged local users with /dev/dax access can trigger kernel use of the corrupt struct pages via mmap and page faults without CAP_SYS_ADMIN in the init namespace.\nUI:N - Exploitation requires no victim interaction beyond the attacker (or any local user) running programs that mmap or access the already-provisioned DAX device; no mount, click, or plug/unplug action by another user is needed at exploit time.\nS:U - Impact is kernel memory corruption, information disclosure, and denial of service within the host kernel security boundary; it does not inherently cross VM/host, IOMMU, or sandbox isolation even though cloud persistent-memory deployments are a plausible high-impact scenario.\nC:H - Uninitialized tail struct page metadata (flags, refcount, pgmap/lru fields) is later interpreted as valid by the MM subsystem; garbage contents can be read through page-table walks, refcount checks, and folio lookups, yielding kernel memory disclosure comparable to other uninitialized-page corruption bugs.\nI:H - Corrupt struct page fields can drive incorrect refcounting, compound-head/tail linkage, and ZONE_DEVICE pgmap handling, enabling heap-style memory corruption and potential arbitrary kernel write or control-flow hijack, not merely bounded data modification.\nA:H - The fix commit and call path explicitly warn of unexpected behavior and crashes; operations on uninitialized struct pages can provoke kernel oops, BUG_ON, use-after-free, or panic during page allocation, migration, or DAX fault handling, giving reliable denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:47:00.343Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c5ef574d57e4a701485c13f26822328c91f05413"
},
{
"url": "https://git.kernel.org/stable/c/511a60e71aec308b24722cffc1912bf6befb87bf"
},
{
"url": "https://git.kernel.org/stable/c/11f2826e9ee6f24aaa774e3dcd75abbe4b3091b6"
},
{
"url": "https://git.kernel.org/stable/c/da5234df0941665f3a3f5b80f3dab94046537be0"
},
{
"url": "https://git.kernel.org/stable/c/b91e27bce37cab9f35de0059278ebe457ca9878b"
},
{
"url": "https://git.kernel.org/stable/c/cd681403a87085562499d60325b7b45d3be11217"
}
],
"title": "mm/mm_init: fix uninitialized struct pages for ZONE_DEVICE",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72172",
"datePublished": "2026-08-15T05:53:37.795Z",
"dateReserved": "2026-08-09T03:40:39.910Z",
"dateUpdated": "2026-08-23T12:47:00.343Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74441 (GCVE-0-2026-74441)
Vulnerability from cvelistv5
Published
2026-08-15 12:26
Modified
2026-08-23 12:47
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
usb: typec: ucsi: Fix race condition and ordering in port unregistration
A synchronization issue exists during port unregistration where pending
partner work items can race against workqueue destruction, leading to
use-after-free conditions:
cros_ec_ucsi cros_ec_ucsi.3.auto: error -ETIMEDOUT: PPM init failed
BUG: kernel NULL pointer dereference, address: 0000000000000000
RIP: 0010:__queue_work+0x83/0x4a0
Call Trace:
<IRQ>
__cfi_delayed_work_timer_fn+0x10/0x10
run_timer_softirq+0x3b6/0xbd0
sched_clock_cpu+0xc/0x110
irq_exit_rcu+0x18d/0x330
fred_sysvec_apic_timer_interrupt+0x5e/0x80
Fix this by ensuring strict ordering and proper serialization during
teardown:
1. Move ucsi_unregister_partner() to the beginning of the teardown
sequence and protect it under the connector mutex lock.
2. Ensure all pending partner tasks are explicitly flushed and finished
before the workqueue is destroyed.
3. Switch from mod_delayed_work() to a cancel_delayed_work() and
queue_delayed_work() sequence. This guarantees that items currently marked
as pending won't be scheduled an additional time, preventing a double
release of resources which leads to the following crash:
Oops: general protection fault, probably for non-canonical address
0xdead000000000122: 0000 [#1] SMP NOPTI
Workqueue: cros_ec_ucsi.3.auto-con2 ucsi_poll_worker
RIP: 0010:ucsi_poll_worker+0x65/0x1e0
Call Trace:
<TASK>
process_scheduled_works+0x218/0x6d0
worker_thread+0x188/0x3f0
__cfi_worker_thread+0x10/0x10
kthread+0x226/0x2a0
To ensure these rules are applied identically across both the normal
teardown and the ucsi_init() error paths, consolidate the cleanup logic
into a new helper, ucsi_unregister_port().
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: b9aa02ca39a49740926c2c450a1505a4a0f8954a Version: b9aa02ca39a49740926c2c450a1505a4a0f8954a Version: b9aa02ca39a49740926c2c450a1505a4a0f8954a Version: b9aa02ca39a49740926c2c450a1505a4a0f8954a Version: b9aa02ca39a49740926c2c450a1505a4a0f8954a Version: b9aa02ca39a49740926c2c450a1505a4a0f8954a |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/typec/ucsi/ucsi.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "7b63c680ff605f60f056e5f2c323f1a602aee182",
"status": "affected",
"version": "b9aa02ca39a49740926c2c450a1505a4a0f8954a",
"versionType": "git"
},
{
"lessThan": "07f8aaffee705e552c1f723ac8bf7eb137ad59c2",
"status": "affected",
"version": "b9aa02ca39a49740926c2c450a1505a4a0f8954a",
"versionType": "git"
},
{
"lessThan": "11483d80267db97fbe49f2df66385434256cc3b0",
"status": "affected",
"version": "b9aa02ca39a49740926c2c450a1505a4a0f8954a",
"versionType": "git"
},
{
"lessThan": "3f7b3728dd9011c915cbeaea77274ebe8366550d",
"status": "affected",
"version": "b9aa02ca39a49740926c2c450a1505a4a0f8954a",
"versionType": "git"
},
{
"lessThan": "bc7a0f721123ea260a42f1ded06dab844ba49434",
"status": "affected",
"version": "b9aa02ca39a49740926c2c450a1505a4a0f8954a",
"versionType": "git"
},
{
"lessThan": "7aa7d4bf9d3fa9a6a47b640ad103ab433b7ff261",
"status": "affected",
"version": "b9aa02ca39a49740926c2c450a1505a4a0f8954a",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/usb/typec/ucsi/ucsi.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.16"
},
{
"lessThan": "5.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.16",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: ucsi: Fix race condition and ordering in port unregistration\n\nA synchronization issue exists during port unregistration where pending\npartner work items can race against workqueue destruction, leading to\nuse-after-free conditions:\n\n cros_ec_ucsi cros_ec_ucsi.3.auto: error -ETIMEDOUT: PPM init failed\n BUG: kernel NULL pointer dereference, address: 0000000000000000\n RIP: 0010:__queue_work+0x83/0x4a0\n Call Trace:\n \u003cIRQ\u003e\n __cfi_delayed_work_timer_fn+0x10/0x10\n run_timer_softirq+0x3b6/0xbd0\n sched_clock_cpu+0xc/0x110\n irq_exit_rcu+0x18d/0x330\n fred_sysvec_apic_timer_interrupt+0x5e/0x80\n\nFix this by ensuring strict ordering and proper serialization during\nteardown:\n\n1. Move ucsi_unregister_partner() to the beginning of the teardown\nsequence and protect it under the connector mutex lock.\n2. Ensure all pending partner tasks are explicitly flushed and finished\nbefore the workqueue is destroyed.\n3. Switch from mod_delayed_work() to a cancel_delayed_work() and\nqueue_delayed_work() sequence. This guarantees that items currently marked\nas pending won\u0027t be scheduled an additional time, preventing a double\nrelease of resources which leads to the following crash:\n\n Oops: general protection fault, probably for non-canonical address\n 0xdead000000000122: 0000 [#1] SMP NOPTI\n Workqueue: cros_ec_ucsi.3.auto-con2 ucsi_poll_worker\n RIP: 0010:ucsi_poll_worker+0x65/0x1e0\n Call Trace:\n \u003cTASK\u003e\n process_scheduled_works+0x218/0x6d0\n worker_thread+0x188/0x3f0\n __cfi_worker_thread+0x10/0x10\n kthread+0x226/0x2a0\n\nTo ensure these rules are applied identically across both the normal\nteardown and the ucsi_init() error paths, consolidate the cleanup logic\ninto a new helper, ucsi_unregister_port()."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:47:17.900Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/7b63c680ff605f60f056e5f2c323f1a602aee182"
},
{
"url": "https://git.kernel.org/stable/c/07f8aaffee705e552c1f723ac8bf7eb137ad59c2"
},
{
"url": "https://git.kernel.org/stable/c/11483d80267db97fbe49f2df66385434256cc3b0"
},
{
"url": "https://git.kernel.org/stable/c/3f7b3728dd9011c915cbeaea77274ebe8366550d"
},
{
"url": "https://git.kernel.org/stable/c/bc7a0f721123ea260a42f1ded06dab844ba49434"
},
{
"url": "https://git.kernel.org/stable/c/7aa7d4bf9d3fa9a6a47b640ad103ab433b7ff261"
}
],
"title": "usb: typec: ucsi: Fix race condition and ordering in port unregistration",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74441",
"datePublished": "2026-08-15T12:26:49.359Z",
"dateReserved": "2026-08-15T05:44:03.897Z",
"dateUpdated": "2026-08-23T12:47:17.900Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80795 (GCVE-0-2026-80795)
Vulnerability from cvelistv5
Published
2026-09-04 15:13
Modified
2026-09-04 15:13
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
nfc: nci: fix out-of-bounds write in nci_target_auto_activated()
nci_target_auto_activated() appends a target to the fixed-size array
ndev->targets[NCI_MAX_DISCOVERED_TARGETS] and increments ndev->n_targets
without first checking the array is full; unlike its sibling
nci_add_new_target(), which bails out when n_targets already equals
NCI_MAX_DISCOVERED_TARGETS.
ndev->n_targets is only cleared by nci_clear_target_list(), so an NFCC
that repeatedly re-runs discovery (RF_DISCOVER_RSP, which re-enters
NCI_DISCOVERY without clearing the target list) and reports an
auto-activated target (RF_INTF_ACTIVATED_NTF) drives n_targets past the
limit. The append then writes a struct nfc_target past the end of the
array (a slab out-of-bounds write), and nfc_targets_found() goes on to
walk the array with the inflated count:
BUG: KASAN: slab-out-of-bounds in nci_add_new_protocol+0x94/0x2ac [nci]
Write of size 2 at addr ffff0000c7299a18 by task kworker/u8:0/12
Workqueue: nfc0_nci_rx_wq nci_rx_work [nci]
Call trace:
nci_add_new_protocol+0x94/0x2ac [nci]
nci_ntf_packet+0xddc/0x11a0 [nci]
nci_rx_work+0x15c/0x1e0 [nci]
process_one_work+0x2dc/0x500
worker_thread+0x240/0x460
kthread+0x1c0/0x1d0
ret_from_fork+0x10/0x20
The buggy address belongs to the cache kmalloc-2k of size 2048
The buggy address is located 1024 bytes to the right of
allocated 1560-byte region [ffff0000c7299000, ffff0000c7299618)
Guard nci_target_auto_activated() with the same check used by
nci_add_new_target().
References
| URL | Tags | ||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 019c4fbaa790e2b3f11dab0c8b7d9896d77db3e5 Version: 019c4fbaa790e2b3f11dab0c8b7d9896d77db3e5 Version: 019c4fbaa790e2b3f11dab0c8b7d9896d77db3e5 Version: 019c4fbaa790e2b3f11dab0c8b7d9896d77db3e5 Version: 019c4fbaa790e2b3f11dab0c8b7d9896d77db3e5 Version: 019c4fbaa790e2b3f11dab0c8b7d9896d77db3e5 Version: 019c4fbaa790e2b3f11dab0c8b7d9896d77db3e5 Version: 019c4fbaa790e2b3f11dab0c8b7d9896d77db3e5 Version: 019c4fbaa790e2b3f11dab0c8b7d9896d77db3e5 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/nfc/nci/ntf.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "0dc59de0075f88404a0f4a2b5233104ef459fbb2",
"status": "affected",
"version": "019c4fbaa790e2b3f11dab0c8b7d9896d77db3e5",
"versionType": "git"
},
{
"lessThan": "94530ffabfca57e9bff1d207106010014cc84032",
"status": "affected",
"version": "019c4fbaa790e2b3f11dab0c8b7d9896d77db3e5",
"versionType": "git"
},
{
"lessThan": "afd8605fb43becb892311102844955c3b127fc7e",
"status": "affected",
"version": "019c4fbaa790e2b3f11dab0c8b7d9896d77db3e5",
"versionType": "git"
},
{
"lessThan": "24761d3a5f692df5f7d848caeabcb2afd10917aa",
"status": "affected",
"version": "019c4fbaa790e2b3f11dab0c8b7d9896d77db3e5",
"versionType": "git"
},
{
"lessThan": "50e87e1c0e18d791dcd7dccf30f9a2f3e2cf3951",
"status": "affected",
"version": "019c4fbaa790e2b3f11dab0c8b7d9896d77db3e5",
"versionType": "git"
},
{
"lessThan": "2f08dbce3b37624ec6b424d759336a99586170ec",
"status": "affected",
"version": "019c4fbaa790e2b3f11dab0c8b7d9896d77db3e5",
"versionType": "git"
},
{
"lessThan": "d7083f41c21b30582e91b2e6de4d54dce74f6f9c",
"status": "affected",
"version": "019c4fbaa790e2b3f11dab0c8b7d9896d77db3e5",
"versionType": "git"
},
{
"lessThan": "129032c0616d83a5e3e304f6ebf88f14ba01e5f7",
"status": "affected",
"version": "019c4fbaa790e2b3f11dab0c8b7d9896d77db3e5",
"versionType": "git"
},
{
"lessThan": "ac200079db50af81e6b04d058b33ec92901d8edd",
"status": "affected",
"version": "019c4fbaa790e2b3f11dab0c8b7d9896d77db3e5",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/nfc/nci/ntf.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.4"
},
{
"lessThan": "3.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.267",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.218",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.185",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.154",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.106",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.47",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.1",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.267",
"versionStartIncluding": "3.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.218",
"versionStartIncluding": "3.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.185",
"versionStartIncluding": "3.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.154",
"versionStartIncluding": "3.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.106",
"versionStartIncluding": "3.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.47",
"versionStartIncluding": "3.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.11",
"versionStartIncluding": "3.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.1",
"versionStartIncluding": "3.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "3.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: nci: fix out-of-bounds write in nci_target_auto_activated()\n\nnci_target_auto_activated() appends a target to the fixed-size array\nndev-\u003etargets[NCI_MAX_DISCOVERED_TARGETS] and increments ndev-\u003en_targets\nwithout first checking the array is full; unlike its sibling\nnci_add_new_target(), which bails out when n_targets already equals\nNCI_MAX_DISCOVERED_TARGETS.\n\nndev-\u003en_targets is only cleared by nci_clear_target_list(), so an NFCC\nthat repeatedly re-runs discovery (RF_DISCOVER_RSP, which re-enters\nNCI_DISCOVERY without clearing the target list) and reports an\nauto-activated target (RF_INTF_ACTIVATED_NTF) drives n_targets past the\nlimit. The append then writes a struct nfc_target past the end of the\narray (a slab out-of-bounds write), and nfc_targets_found() goes on to\nwalk the array with the inflated count:\n\n BUG: KASAN: slab-out-of-bounds in nci_add_new_protocol+0x94/0x2ac [nci]\n Write of size 2 at addr ffff0000c7299a18 by task kworker/u8:0/12\n Workqueue: nfc0_nci_rx_wq nci_rx_work [nci]\n Call trace:\n nci_add_new_protocol+0x94/0x2ac [nci]\n nci_ntf_packet+0xddc/0x11a0 [nci]\n nci_rx_work+0x15c/0x1e0 [nci]\n process_one_work+0x2dc/0x500\n worker_thread+0x240/0x460\n kthread+0x1c0/0x1d0\n ret_from_fork+0x10/0x20\n\n The buggy address belongs to the cache kmalloc-2k of size 2048\n The buggy address is located 1024 bytes to the right of\n allocated 1560-byte region [ffff0000c7299000, ffff0000c7299618)\n\nGuard nci_target_auto_activated() with the same check used by\nnci_add_new_target()."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T15:13:08.640Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/0dc59de0075f88404a0f4a2b5233104ef459fbb2"
},
{
"url": "https://git.kernel.org/stable/c/94530ffabfca57e9bff1d207106010014cc84032"
},
{
"url": "https://git.kernel.org/stable/c/afd8605fb43becb892311102844955c3b127fc7e"
},
{
"url": "https://git.kernel.org/stable/c/24761d3a5f692df5f7d848caeabcb2afd10917aa"
},
{
"url": "https://git.kernel.org/stable/c/50e87e1c0e18d791dcd7dccf30f9a2f3e2cf3951"
},
{
"url": "https://git.kernel.org/stable/c/2f08dbce3b37624ec6b424d759336a99586170ec"
},
{
"url": "https://git.kernel.org/stable/c/d7083f41c21b30582e91b2e6de4d54dce74f6f9c"
},
{
"url": "https://git.kernel.org/stable/c/129032c0616d83a5e3e304f6ebf88f14ba01e5f7"
},
{
"url": "https://git.kernel.org/stable/c/ac200079db50af81e6b04d058b33ec92901d8edd"
}
],
"title": "nfc: nci: fix out-of-bounds write in nci_target_auto_activated()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80795",
"datePublished": "2026-09-04T15:13:08.640Z",
"dateReserved": "2026-08-26T14:34:25.793Z",
"dateUpdated": "2026-09-04T15:13:08.640Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74647 (GCVE-0-2026-74647)
Vulnerability from cvelistv5
Published
2026-08-22 15:32
Modified
2026-08-27 12:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
misc: fastrpc: Remove buffer from list prior to unmap operation
fastrpc_req_munmap_impl() is called to unmap any buffer. The buffer is
getting removed from the list after it is unmapped from DSP. This can
create potential race conditions if multiple threads invoke unmap
concurrently, where one thread may remove the entry from the list while
another thread's unmap operation is still ongoing.
Fix this by removing the buffer entry from the list before calling the
unmap operation. If the unmap fails, the entry is re-added to the list
so that userspace can retry the unmap, or alternatively, the buffer
will be cleaned up during device release when the DSP process is torn
down and all DSP-side mappings are freed along with remaining buffers
in the list.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 2419e55e532de14fdf336e09e453aa2831c73a25 Version: 2419e55e532de14fdf336e09e453aa2831c73a25 Version: 2419e55e532de14fdf336e09e453aa2831c73a25 Version: 2419e55e532de14fdf336e09e453aa2831c73a25 Version: 2419e55e532de14fdf336e09e453aa2831c73a25 Version: 2419e55e532de14fdf336e09e453aa2831c73a25 Version: 2419e55e532de14fdf336e09e453aa2831c73a25 Version: 2419e55e532de14fdf336e09e453aa2831c73a25 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/misc/fastrpc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "1edb654b2b41baee2ab5cf418baaf6e57dfbd802",
"status": "affected",
"version": "2419e55e532de14fdf336e09e453aa2831c73a25",
"versionType": "git"
},
{
"lessThan": "4716c23c206a2f99ca54ebfdd8b5ba9dd0102240",
"status": "affected",
"version": "2419e55e532de14fdf336e09e453aa2831c73a25",
"versionType": "git"
},
{
"lessThan": "99f8de36c84cb9b872157aa6c3578c2480cee4b8",
"status": "affected",
"version": "2419e55e532de14fdf336e09e453aa2831c73a25",
"versionType": "git"
},
{
"lessThan": "97273624f7b356eaf8261609a75cfcb8738a165a",
"status": "affected",
"version": "2419e55e532de14fdf336e09e453aa2831c73a25",
"versionType": "git"
},
{
"lessThan": "fe70329055977fc1e8dc6291318d0dd75470795a",
"status": "affected",
"version": "2419e55e532de14fdf336e09e453aa2831c73a25",
"versionType": "git"
},
{
"lessThan": "9bf22a7d950cec2d1efeca7f16bb20fcca84c36a",
"status": "affected",
"version": "2419e55e532de14fdf336e09e453aa2831c73a25",
"versionType": "git"
},
{
"lessThan": "0beaa9bd7eb10d9b5e6352ed5161f3f3bbd4c3c5",
"status": "affected",
"version": "2419e55e532de14fdf336e09e453aa2831c73a25",
"versionType": "git"
},
{
"lessThan": "6102ceb4eab845743ee57acd3863fbd06e93c927",
"status": "affected",
"version": "2419e55e532de14fdf336e09e453aa2831c73a25",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/misc/fastrpc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.5"
},
{
"lessThan": "5.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.267",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.218",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.185",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.267",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.218",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.185",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmisc: fastrpc: Remove buffer from list prior to unmap operation\n\nfastrpc_req_munmap_impl() is called to unmap any buffer. The buffer is\ngetting removed from the list after it is unmapped from DSP. This can\ncreate potential race conditions if multiple threads invoke unmap\nconcurrently, where one thread may remove the entry from the list while\nanother thread\u0027s unmap operation is still ongoing.\n\nFix this by removing the buffer entry from the list before calling the\nunmap operation. If the unmap fails, the entry is re-added to the list\nso that userspace can retry the unmap, or alternatively, the buffer\nwill be cleaned up during device release when the DSP process is torn\ndown and all DSP-side mappings are freed along with remaining buffers\nin the list."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The flaw is reachable only through local ioctl on a FastRPC misc device (/dev/fastrpc-*); entry is open() plus FASTRPC_IOCTL_MUNMAP after mmap, not via network, Bluetooth, WiFi, or physical buses.\nAC:L - An attacker controls both racing threads and can repeatedly issue concurrent MUNMAP ioctls for the same mapped buffer; the pre-fix window spans the full DSP unmap in fastrpc_req_munmap_impl(), so no attacker-uncontrollable timing is required.\nPR:L - The MMAP/MUNMAP ioctl path has no capable() or init-namespace root check; on Qualcomm/Android phones an unprivileged app that can open the non-secure FastRPC node and create an unsigned user PD can reach this code.\nUI:N - Exploitation needs only attacker-controlled open/ioctl and pthread scheduling against a buffer it already mapped; no separate victim action such as mounting a filesystem or opening a file is required.\nS:U - The race corrupts kernel list/slab state and double-frees struct fastrpc_buf inside the host kernel driver, matching other FastRPC kernel memory-safety CVEs rather than an inherent VM escape or IOMMU boundary bypass.\nC:H - Concurrent unmap can UAF the list node and double-free a fastrpc_buf slab object holding DMA mapping metadata, a classic kernel primitive that can be groomed into arbitrary kernel memory disclosure.\nI:H - Double kfree of fastrpc_buf plus repeated dma_free_coherent on the same coherent mapping enables heap corruption and plausible control-flow or arbitrary-write exploitation in kernel context.\nA:H - Winning the race can trigger list_del on freed memory, slab double-free, or DMA allocator corruption, producing kernel warnings, oopses, or panics that are repeatable via local ioctl flooding."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T12:39:52.927Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/1edb654b2b41baee2ab5cf418baaf6e57dfbd802"
},
{
"url": "https://git.kernel.org/stable/c/4716c23c206a2f99ca54ebfdd8b5ba9dd0102240"
},
{
"url": "https://git.kernel.org/stable/c/99f8de36c84cb9b872157aa6c3578c2480cee4b8"
},
{
"url": "https://git.kernel.org/stable/c/97273624f7b356eaf8261609a75cfcb8738a165a"
},
{
"url": "https://git.kernel.org/stable/c/fe70329055977fc1e8dc6291318d0dd75470795a"
},
{
"url": "https://git.kernel.org/stable/c/9bf22a7d950cec2d1efeca7f16bb20fcca84c36a"
},
{
"url": "https://git.kernel.org/stable/c/0beaa9bd7eb10d9b5e6352ed5161f3f3bbd4c3c5"
},
{
"url": "https://git.kernel.org/stable/c/6102ceb4eab845743ee57acd3863fbd06e93c927"
}
],
"title": "misc: fastrpc: Remove buffer from list prior to unmap operation",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74647",
"datePublished": "2026-08-22T15:32:24.127Z",
"dateReserved": "2026-08-15T05:44:03.923Z",
"dateUpdated": "2026-08-27T12:39:52.927Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68340 (GCVE-0-2026-68340)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
hwmon: occ: validate poll response sensor blocks
The OCC poll response parser walks a counted list of sensor data blocks.
It used the static backing-array capacity as the parse boundary, but a
transport response makes only data_length bytes current and valid. A
truncated response can therefore make the parser consume a block header or
block extent outside the current response.
Use data_length as the parent boundary, prove the fixed poll header and
each current block header before reading them, and prove the complete block
before advancing. Keep parsed sensor metadata local until the complete
response has passed validation, then publish it. Propagate
malformed-response errors before publishing the OCC as active.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: aa195fe49b033db545ad986cdb2c431c37bea557 Version: aa195fe49b033db545ad986cdb2c431c37bea557 Version: aa195fe49b033db545ad986cdb2c431c37bea557 Version: aa195fe49b033db545ad986cdb2c431c37bea557 Version: aa195fe49b033db545ad986cdb2c431c37bea557 Version: aa195fe49b033db545ad986cdb2c431c37bea557 Version: aa195fe49b033db545ad986cdb2c431c37bea557 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/hwmon/occ/common.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "6e6c72c37433640514db325408bd6913ad28fe69",
"status": "affected",
"version": "aa195fe49b033db545ad986cdb2c431c37bea557",
"versionType": "git"
},
{
"lessThan": "1902e9572901d37901e3db1f3f6b0885f4e49a66",
"status": "affected",
"version": "aa195fe49b033db545ad986cdb2c431c37bea557",
"versionType": "git"
},
{
"lessThan": "112525534ab5cff482d35897ca4ca11fd3a76f46",
"status": "affected",
"version": "aa195fe49b033db545ad986cdb2c431c37bea557",
"versionType": "git"
},
{
"lessThan": "54cb78eceb4e286ccd5a5c01a4632157860d47f0",
"status": "affected",
"version": "aa195fe49b033db545ad986cdb2c431c37bea557",
"versionType": "git"
},
{
"lessThan": "538d862cc0dbd5c732fe26d5aad98eae039e6676",
"status": "affected",
"version": "aa195fe49b033db545ad986cdb2c431c37bea557",
"versionType": "git"
},
{
"lessThan": "b042e538e98b939fccfffc464e2c34c29f0e96ef",
"status": "affected",
"version": "aa195fe49b033db545ad986cdb2c431c37bea557",
"versionType": "git"
},
{
"lessThan": "70e76e700fc6c46afb4e17aec099a1ea089b4a22",
"status": "affected",
"version": "aa195fe49b033db545ad986cdb2c431c37bea557",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/hwmon/occ/common.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.0"
},
{
"lessThan": "5.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: occ: validate poll response sensor blocks\n\nThe OCC poll response parser walks a counted list of sensor data blocks.\nIt used the static backing-array capacity as the parse boundary, but a\ntransport response makes only data_length bytes current and valid. A\ntruncated response can therefore make the parser consume a block header or\nblock extent outside the current response.\n\nUse data_length as the parent boundary, prove the fixed poll header and\neach current block header before reading them, and prove the complete block\nbefore advancing. Keep parsed sensor metadata local until the complete\nresponse has passed validation, then publish it. Propagate\nmalformed-response errors before publishing the OCC as active."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.7,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The malformed poll response reaches the BMC kernel over the local FSI/SBE or I2C link to the attached POWER OCC (drivers/hwmon/occ/p9_sbe.c, p8_i2c.c); there is no network protocol involved, but no physical access is needed either since a bare-metal host-side attacker can drive OCC firmware in software.\nAC:L - The attacker fully controls the response contents and its data_length, so simply returning a truncated poll response with a large num_sensor_data_blocks deterministically drives the parser past the valid data. No race, memory-layout guess, or uncontrolled precondition is involved.\nPR:N - occ_setup() calls occ_active(occ, true) during driver probe unless ibm,no-poll-on-init is set, so the malformed response is parsed automatically at bind with no credentials on the affected BMC system; the OCC-side attacker holds no privileges in the victim kernel\u0027s authority.\nUI:N - Parsing happens automatically during driver probe, or from the management daemon\u0027s periodic occ_active write; no victim action such as mounting or opening a file is required.\nS:U - The out-of-bounds reads and corrupted sensor metadata are confined to the kernel that parses the response; no IOMMU, hypervisor, or sandbox boundary is crossed by the impact itself.\nC:H - Sensor metadata (data pointer, num_sensors, version) is taken from bytes outside the valid response, and consumers index it with fixed per-version struct sizes in occ_setup_sensor_attrs() and every occ_show_* handler, reading far past the devm-allocated occ object and exposing kernel heap contents through world-readable hwmon sysfs attributes.\nI:N - The parse path only reads; the unvalidated lengths yield out-of-bounds loads and bogus metadata, but no attacker-controlled data is written outside any object and no control-flow-hijack primitive is created.\nA:H - Out-of-bounds reads of up to a couple of kilobytes past the allocation can hit unmapped memory or trip KASAN/BUG and oops the kernel, and pre-fix the OCC was marked active with invalid sensor state, leaving the hwmon device in an inconsistent, unusable condition."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:40.900Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/6e6c72c37433640514db325408bd6913ad28fe69"
},
{
"url": "https://git.kernel.org/stable/c/1902e9572901d37901e3db1f3f6b0885f4e49a66"
},
{
"url": "https://git.kernel.org/stable/c/112525534ab5cff482d35897ca4ca11fd3a76f46"
},
{
"url": "https://git.kernel.org/stable/c/54cb78eceb4e286ccd5a5c01a4632157860d47f0"
},
{
"url": "https://git.kernel.org/stable/c/538d862cc0dbd5c732fe26d5aad98eae039e6676"
},
{
"url": "https://git.kernel.org/stable/c/b042e538e98b939fccfffc464e2c34c29f0e96ef"
},
{
"url": "https://git.kernel.org/stable/c/70e76e700fc6c46afb4e17aec099a1ea089b4a22"
}
],
"title": "hwmon: occ: validate poll response sensor blocks",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68340",
"datePublished": "2026-08-10T12:03:16.552Z",
"dateReserved": "2026-07-30T09:28:09.384Z",
"dateUpdated": "2026-08-19T16:33:40.900Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68313 (GCVE-0-2026-68313)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
tipc: fix infinite loop in __tipc_nl_compat_dumpit
cmd->dumpit callback can return a negative errno, causing an infinite
loop due to the while(len) condition. As the loop never terminates,
genl_mutex is never released, and other tasks waiting on it starve in D
state.
Check dumpit's return value, propagate it and jump to err_out on error.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d0796d1ef63deb38147729664691ba3090930b26 Version: d0796d1ef63deb38147729664691ba3090930b26 Version: d0796d1ef63deb38147729664691ba3090930b26 Version: d0796d1ef63deb38147729664691ba3090930b26 Version: d0796d1ef63deb38147729664691ba3090930b26 Version: d0796d1ef63deb38147729664691ba3090930b26 Version: d0796d1ef63deb38147729664691ba3090930b26 Version: d0796d1ef63deb38147729664691ba3090930b26 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/tipc/netlink_compat.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "2a1c1397275f27e33b6a2a565d81cfef0deb6656",
"status": "affected",
"version": "d0796d1ef63deb38147729664691ba3090930b26",
"versionType": "git"
},
{
"lessThan": "98d09766cee3182aae292886e2fef0cbe8dba537",
"status": "affected",
"version": "d0796d1ef63deb38147729664691ba3090930b26",
"versionType": "git"
},
{
"lessThan": "9cd8c88e1336ec0fbe02af1ddf2b52838d30fae4",
"status": "affected",
"version": "d0796d1ef63deb38147729664691ba3090930b26",
"versionType": "git"
},
{
"lessThan": "f9c669d9f4cac832fe31193cdbc24c6a9d99398b",
"status": "affected",
"version": "d0796d1ef63deb38147729664691ba3090930b26",
"versionType": "git"
},
{
"lessThan": "1ab78af2140189b735b8d3b889b0284128cb2013",
"status": "affected",
"version": "d0796d1ef63deb38147729664691ba3090930b26",
"versionType": "git"
},
{
"lessThan": "e740e90ca8e7f70d9eac1aa31a8b3e0e4d32b2ef",
"status": "affected",
"version": "d0796d1ef63deb38147729664691ba3090930b26",
"versionType": "git"
},
{
"lessThan": "b8f3b8efa5f99081b14de1a7ffa68a81bf01bd48",
"status": "affected",
"version": "d0796d1ef63deb38147729664691ba3090930b26",
"versionType": "git"
},
{
"lessThan": "22f8aa35964e8f2ab026578f45befc9605fd1b28",
"status": "affected",
"version": "d0796d1ef63deb38147729664691ba3090930b26",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/tipc/netlink_compat.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.0"
},
{
"lessThan": "4.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: fix infinite loop in __tipc_nl_compat_dumpit\n\ncmd-\u003edumpit callback can return a negative errno, causing an infinite\nloop due to the while(len) condition. As the loop never terminates,\ngenl_mutex is never released, and other tasks waiting on it starve in D\nstate.\n\nCheck dumpit\u0027s return value, propagate it and jump to err_out on error."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:05.750Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/2a1c1397275f27e33b6a2a565d81cfef0deb6656"
},
{
"url": "https://git.kernel.org/stable/c/98d09766cee3182aae292886e2fef0cbe8dba537"
},
{
"url": "https://git.kernel.org/stable/c/9cd8c88e1336ec0fbe02af1ddf2b52838d30fae4"
},
{
"url": "https://git.kernel.org/stable/c/f9c669d9f4cac832fe31193cdbc24c6a9d99398b"
},
{
"url": "https://git.kernel.org/stable/c/1ab78af2140189b735b8d3b889b0284128cb2013"
},
{
"url": "https://git.kernel.org/stable/c/e740e90ca8e7f70d9eac1aa31a8b3e0e4d32b2ef"
},
{
"url": "https://git.kernel.org/stable/c/b8f3b8efa5f99081b14de1a7ffa68a81bf01bd48"
},
{
"url": "https://git.kernel.org/stable/c/22f8aa35964e8f2ab026578f45befc9605fd1b28"
}
],
"title": "tipc: fix infinite loop in __tipc_nl_compat_dumpit",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68313",
"datePublished": "2026-08-10T12:02:48.120Z",
"dateReserved": "2026-07-30T09:28:09.381Z",
"dateUpdated": "2026-08-19T16:33:05.750Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68370 (GCVE-0-2026-68370)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback
dummy_hcd embeds a single shared usb_request (dum->fifo_req) that the
"emulated single-request FIFO" fast-path in dummy_queue() reuses for
small IN transfers: it copies the caller's request into it
(req->req = *_req) and queues it, treating list_empty(&fifo_req.queue)
as "the slot is free".
The completion side (dummy_timer/transfer/nuke/dummy_dequeue) follows
the standard pattern: list_del_init(&req->queue) unlinks the request,
then the lock is dropped and usb_gadget_giveback_request() invokes
req->complete(). But list_del_init() makes fifo_req.queue look empty
*before* the completion callback returns, so a concurrent dummy_queue()
on another CPU sees the slot as free, reuses fifo_req and runs
req->req = *_req -- overwriting req->complete while dummy_timer is
mid-calling it. The indirect call then jumps to a clobbered pointer,
causing a general protection fault / page fault in dummy_timer
(syzkaller extid faf3a6cf579fc65591ca). The clobbering write is an
in-bounds memcpy on a live shared object, so KASAN cannot flag it.
Add a fifo_req_busy bit covering the shared request's whole lifetime:
set it in dummy_queue() when the FIFO fast-path takes fifo_req (making
it the fast-path guard, replacing the list_empty(&fifo_req.queue)
test), and clear it after the completion callback has returned, via a
dummy_giveback() helper used at all four gadget-request giveback
sites. The shared slot can no longer be reused until its completion
callback has finished.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/gadget/udc/dummy_hcd.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "16a685172abc9233728830e27d26ffa778975b51",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "95f30a21612cc65761c58ba044b1767699437317",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "3cab0e5498d0fbb21fe1a9181f7bda9a844a697e",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "e2b2740f1242bc70b5b46da2cdbbaa419f490e59",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "67b589d09a96882d56842dced5698ed8dd06ce45",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "e239ea91b48180ed48a86ac25643832a02c88456",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "e24b33618231034bf01dfaff4fd3409d4b4d5b2e",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "d5e5cd3654d2b5359a12ea6586120f05b28634ee",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/usb/gadget/udc/dummy_hcd.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: dummy_hcd: prevent fifo_req reuse during giveback\n\ndummy_hcd embeds a single shared usb_request (dum-\u003efifo_req) that the\n\"emulated single-request FIFO\" fast-path in dummy_queue() reuses for\nsmall IN transfers: it copies the caller\u0027s request into it\n(req-\u003ereq = *_req) and queues it, treating list_empty(\u0026fifo_req.queue)\nas \"the slot is free\".\n\nThe completion side (dummy_timer/transfer/nuke/dummy_dequeue) follows\nthe standard pattern: list_del_init(\u0026req-\u003equeue) unlinks the request,\nthen the lock is dropped and usb_gadget_giveback_request() invokes\nreq-\u003ecomplete(). But list_del_init() makes fifo_req.queue look empty\n*before* the completion callback returns, so a concurrent dummy_queue()\non another CPU sees the slot as free, reuses fifo_req and runs\nreq-\u003ereq = *_req -- overwriting req-\u003ecomplete while dummy_timer is\nmid-calling it. The indirect call then jumps to a clobbered pointer,\ncausing a general protection fault / page fault in dummy_timer\n(syzkaller extid faf3a6cf579fc65591ca). The clobbering write is an\nin-bounds memcpy on a live shared object, so KASAN cannot flag it.\n\nAdd a fifo_req_busy bit covering the shared request\u0027s whole lifetime:\nset it in dummy_queue() when the FIFO fast-path takes fifo_req (making\nit the fast-path guard, replacing the list_empty(\u0026fifo_req.queue)\ntest), and clear it after the completion callback has returned, via a\ndummy_giveback() helper used at all four gadget-request giveback\nsites. The shared slot can no longer be reused until its completion\ncallback has finished."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - dummy_hcd is a purely virtual UDC/HCD pair with no physical port; both sides of the race are driven locally \u2014 gadget-side `usb_ep_queue()` via raw-gadget ioctls, gadgetfs/functionfs endpoint writes or configfs function traffic, and the host side by the in-software `dummy_timer`/URB path. No cable, hardware, or network access is involved, matching the AV:L used for other dummy_hcd/gadget bugs.\nAC:L - The attacker controls both sides of the race: it queues small IN requests on one CPU in a tight loop while the periodic 1 ms `dummy_timer` frame processing performs giveback on another, and the fast-path guard (`list_empty(\u0026fifo_req.queue)`) is cleared before the callback returns, so the window is entered on essentially every iteration and can be retried indefinitely.\nPR:L - No capability check exists anywhere on the path \u2014 `dummy_queue()` and the giveback sites perform none; reachability is gated only by node/mount permissions on /dev/raw-gadget, gadgetfs or the gadget configfs/functionfs tree, which on Android and embedded/industrial systems are routinely delegated to non-root system accounts, so basic local access suffices.\nUI:N - The attacker performs every step itself \u2014 enabling the gadget, queueing the IN transfers, and letting the emulated frame timer run \u2014 with no action required from any other user or victim.\nS:U - The corrupted object and the resulting control-flow hijack are entirely within the kernel\u0027s own security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - The in-flight copy overwrites `fifo_req.req.buf`, `length`, `actual` and `context` of the live shared request, so the completion path and the host-side `transfer()` memcpy operate with mismatched buffer/length/context pairs, letting an attacker steer reads out of unintended kernel memory and surface them through the emulated host transfer \u2014 a kernel memory disclosure primitive.\nI:H - `req-\u003ereq = *_req` clobbers the `complete` function pointer while `usb_gadget_giveback_request()` is dereferencing it, giving a torn/stale indirect call plus a `context` mismatch (type confusion) that is a direct control-flow hijack primitive; the same race also lets the shared `fifo_buf` be written under a stale length, yielding controllable kernel writes.\nA:H - The reported effect is a general protection fault / kernel page fault in `dummy_timer` (syzbot faf3a6cf579fc65591ca) from calling through the clobbered pointer, i.e. a kernel oops that an unprivileged local attacker can trigger repeatedly."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:31.156Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/16a685172abc9233728830e27d26ffa778975b51"
},
{
"url": "https://git.kernel.org/stable/c/95f30a21612cc65761c58ba044b1767699437317"
},
{
"url": "https://git.kernel.org/stable/c/3cab0e5498d0fbb21fe1a9181f7bda9a844a697e"
},
{
"url": "https://git.kernel.org/stable/c/e2b2740f1242bc70b5b46da2cdbbaa419f490e59"
},
{
"url": "https://git.kernel.org/stable/c/67b589d09a96882d56842dced5698ed8dd06ce45"
},
{
"url": "https://git.kernel.org/stable/c/e239ea91b48180ed48a86ac25643832a02c88456"
},
{
"url": "https://git.kernel.org/stable/c/e24b33618231034bf01dfaff4fd3409d4b4d5b2e"
},
{
"url": "https://git.kernel.org/stable/c/d5e5cd3654d2b5359a12ea6586120f05b28634ee"
}
],
"title": "usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68370",
"datePublished": "2026-08-10T12:03:48.320Z",
"dateReserved": "2026-07-30T09:28:09.386Z",
"dateUpdated": "2026-08-19T16:34:31.156Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74479 (GCVE-0-2026-74479)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-23 12:47
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: pktgen: fix proc entry use-after-free
pktgen_change_name() replaces pkt_dev->entry while holding t->if_lock.
pktgen_remove_device() removes the same entry before
_rem_dev_from_if_list() takes that lock.
This allows the following interleaving:
CPU 0 (NETDEV_CHANGENAME) CPU 1 (kpktgend)
if_lock(t)
proc_remove(pkt_dev->entry)
proc_remove(pkt_dev->entry)
pkt_dev->entry = proc_create_data(...)
if_unlock(t)
The kthread can pass the stale proc_dir_entry to proc_remove() after the
rename path has freed it. A reproducer with a widened race window reports:
BUG: KASAN: slab-use-after-free in proc_remove+0x78/0x80
Read of size 8 at addr ffff8881478fea70 by task kpktgend_0/67
Call Trace:
proc_remove+0x78/0x80
pktgen_remove_device.isra.0+0x11c/0x4c0
pktgen_thread_worker+0x1214/0x6bc0
kthread+0x2c6/0x3b0
Allocated by task 95:
__proc_create+0x204/0x790
proc_create_data+0x72/0xe0
pktgen_thread_write+0xd61/0x1510
Freed by task 28:
kmem_cache_free+0xcb/0x3d0
proc_free_inode+0x5b/0x80
rcu_core+0x50a/0x1850
The buggy address belongs to the object at ffff8881478fea00
which belongs to the cache proc_dir_entry of size 192
Move proc_remove() into the if_lock-protected list removal helper. Keep it
before list_del_rcu() to preserve the ordering required by add_device().
The rename path must then finish replacing the entry before removal, or
it observes that the device is no longer on the list.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 39df232f1a9ba48d41c68ee7d4046756e709cf91 Version: 39df232f1a9ba48d41c68ee7d4046756e709cf91 Version: 39df232f1a9ba48d41c68ee7d4046756e709cf91 Version: 39df232f1a9ba48d41c68ee7d4046756e709cf91 Version: 39df232f1a9ba48d41c68ee7d4046756e709cf91 Version: 39df232f1a9ba48d41c68ee7d4046756e709cf91 Version: 39df232f1a9ba48d41c68ee7d4046756e709cf91 Version: 39df232f1a9ba48d41c68ee7d4046756e709cf91 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/core/pktgen.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "82ed3db9269cb61e3c15bad2f6e221efce90e1e0",
"status": "affected",
"version": "39df232f1a9ba48d41c68ee7d4046756e709cf91",
"versionType": "git"
},
{
"lessThan": "d1cc9797cf8f7aeb87e7ad01b748c6a960a819e4",
"status": "affected",
"version": "39df232f1a9ba48d41c68ee7d4046756e709cf91",
"versionType": "git"
},
{
"lessThan": "7991c7cff8b8622cddb3d8dee07dbe74aa4cbec4",
"status": "affected",
"version": "39df232f1a9ba48d41c68ee7d4046756e709cf91",
"versionType": "git"
},
{
"lessThan": "577443530cb592d5782a1f79847411a9363a65c8",
"status": "affected",
"version": "39df232f1a9ba48d41c68ee7d4046756e709cf91",
"versionType": "git"
},
{
"lessThan": "f85a58340b91f225de3299dfa782c6414098077c",
"status": "affected",
"version": "39df232f1a9ba48d41c68ee7d4046756e709cf91",
"versionType": "git"
},
{
"lessThan": "4ef801b838d85c0ea5852c50667f7344ce3b6cd0",
"status": "affected",
"version": "39df232f1a9ba48d41c68ee7d4046756e709cf91",
"versionType": "git"
},
{
"lessThan": "b006a5404470bd3eb2aa0425fc447183032047ef",
"status": "affected",
"version": "39df232f1a9ba48d41c68ee7d4046756e709cf91",
"versionType": "git"
},
{
"lessThan": "817ff6efdb7f484ea547218e11e17d8e43daa3b4",
"status": "affected",
"version": "39df232f1a9ba48d41c68ee7d4046756e709cf91",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/core/pktgen.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.22"
},
{
"lessThan": "2.6.22",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "2.6.22",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "2.6.22",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "2.6.22",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "2.6.22",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "2.6.22",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "2.6.22",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "2.6.22",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.22",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: pktgen: fix proc entry use-after-free\n\npktgen_change_name() replaces pkt_dev-\u003eentry while holding t-\u003eif_lock.\npktgen_remove_device() removes the same entry before\n_rem_dev_from_if_list() takes that lock.\n\nThis allows the following interleaving:\n\n CPU 0 (NETDEV_CHANGENAME) CPU 1 (kpktgend)\n if_lock(t)\n proc_remove(pkt_dev-\u003eentry)\n proc_remove(pkt_dev-\u003eentry)\n pkt_dev-\u003eentry = proc_create_data(...)\n if_unlock(t)\n\nThe kthread can pass the stale proc_dir_entry to proc_remove() after the\nrename path has freed it. A reproducer with a widened race window reports:\n\n BUG: KASAN: slab-use-after-free in proc_remove+0x78/0x80\n Read of size 8 at addr ffff8881478fea70 by task kpktgend_0/67\n Call Trace:\n proc_remove+0x78/0x80\n pktgen_remove_device.isra.0+0x11c/0x4c0\n pktgen_thread_worker+0x1214/0x6bc0\n kthread+0x2c6/0x3b0\n Allocated by task 95:\n __proc_create+0x204/0x790\n proc_create_data+0x72/0xe0\n pktgen_thread_write+0xd61/0x1510\n Freed by task 28:\n kmem_cache_free+0xcb/0x3d0\n proc_free_inode+0x5b/0x80\n rcu_core+0x50a/0x1850\n The buggy address belongs to the object at ffff8881478fea00\n which belongs to the cache proc_dir_entry of size 192\n\nMove proc_remove() into the if_lock-protected list removal helper. Keep it\nbefore list_del_rcu() to preserve the ordering required by add_device().\nThe rename path must then finish replacing the entry before removal, or\nit observes that the device is no longer on the list."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires local access to /proc/net/pktgen procfs writes and a SIOCSIFNAME/ip-link rename of a pktgen-bound netdev; pktgen is configured only via local proc and ioctl paths, not via remote network packets.\nAC:L - The UAF is a race between pktgen_change_name() on NETDEV_CHANGENAME and pktgen_remove_device() in kpktgend; an attacker controls both sides concurrently via rem_device_all/unregister and interface rename, so success does not depend on uncontrollable timing.\nPR:L - Triggering rename needs ns_capable(CAP_NET_ADMIN) and pktgen proc writes are mode 0600; CAP_NET_ADMIN is obtainable by an unprivileged user via user/network namespaces (unshare -Urn), so real init-namespace root is not required.\nUI:N - No victim interaction is required; the attacker drives pktgen device add/remove and netdev rename/unregister directly through local proc writes and netlink/ioctl without needing another user to act.\nS:U - Impact is kernel slab corruption and potential privilege escalation within the same kernel security domain; it does not inherently cross VM, container, or IOMMU boundaries without additional unrelated primitives.\nC:H - The bug is a slab use-after-free of a proc_dir_entry in proc_remove(); KASAN shows reads of freed 192-byte objects, and UAF on proc metadata can be turned into arbitrary kernel memory disclosure via heap grooming.\nI:H - Corrupting or reusing the freed proc_dir_entry during proc_remove()/procfs teardown can enable attacker-controlled writes and control-flow hijack in kernel context, not merely a benign NULL dereference crash.\nA:H - Concurrent rename and removal causes proc_remove() to dereference a freed proc_dir_entry, producing KASAN slab-use-after-free and kernel oops/panic; even without full exploit development, the UAF reliably threatens system availability."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:47:23.408Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/82ed3db9269cb61e3c15bad2f6e221efce90e1e0"
},
{
"url": "https://git.kernel.org/stable/c/d1cc9797cf8f7aeb87e7ad01b748c6a960a819e4"
},
{
"url": "https://git.kernel.org/stable/c/7991c7cff8b8622cddb3d8dee07dbe74aa4cbec4"
},
{
"url": "https://git.kernel.org/stable/c/577443530cb592d5782a1f79847411a9363a65c8"
},
{
"url": "https://git.kernel.org/stable/c/f85a58340b91f225de3299dfa782c6414098077c"
},
{
"url": "https://git.kernel.org/stable/c/4ef801b838d85c0ea5852c50667f7344ce3b6cd0"
},
{
"url": "https://git.kernel.org/stable/c/b006a5404470bd3eb2aa0425fc447183032047ef"
},
{
"url": "https://git.kernel.org/stable/c/817ff6efdb7f484ea547218e11e17d8e43daa3b4"
}
],
"title": "net: pktgen: fix proc entry use-after-free",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74479",
"datePublished": "2026-08-15T12:27:13.172Z",
"dateReserved": "2026-08-15T05:44:03.904Z",
"dateUpdated": "2026-08-23T12:47:23.408Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80832 (GCVE-0-2026-80832)
Vulnerability from cvelistv5
Published
2026-09-04 15:54
Modified
2026-09-04 15:54
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
crypto: qce - fix CCM AAD buffer underallocation
The AAD buffer allocated in qce_aead_ccm_prepare_buf_assoclen()
can be smaller than the length later programmed into the DMA
scatterlist.
The allocation size is currently calculated as:
ALIGN(assoclen, 16) + MAX_CCM_ADATA_HEADER_LEN
while the DMA length is set to:
ALIGN(assoclen + adata_header_len, 16)
Since ALIGN() does not distribute over addition, the allocation
can be smaller than the DMA length. For example, when
assoclen = 32 and adata_header_len = 2:
allocation = ALIGN(32, 16) + 6 = 38
DMA length = ALIGN(32 + 2, 16) = 48
As a result, the QCE hardware can read beyond the allocated
buffer while computing the CBC-MAC over the associated data.
The extra bytes are folded into the authentication tag,
resulting in an incorrect tag and causing CCM self-test
failures such as:
alg: aead: ccm-aes-qce encryption test failed (wrong result)
on test vector 8
Fix the allocation by adding the maximum possible AAD header
length before alignment:
ALIGN(assoclen + MAX_CCM_ADATA_HEADER_LEN, 16)
This guarantees that the allocated buffer is large enough
for the fully padded AAD data for all supported header sizes.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 9363efb4181c5e0fbf86bdfa759262aa29f0eb50 Version: 9363efb4181c5e0fbf86bdfa759262aa29f0eb50 Version: 9363efb4181c5e0fbf86bdfa759262aa29f0eb50 Version: 9363efb4181c5e0fbf86bdfa759262aa29f0eb50 Version: 9363efb4181c5e0fbf86bdfa759262aa29f0eb50 Version: 9363efb4181c5e0fbf86bdfa759262aa29f0eb50 Version: 9363efb4181c5e0fbf86bdfa759262aa29f0eb50 Version: 9363efb4181c5e0fbf86bdfa759262aa29f0eb50 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/crypto/qce/aead.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "11775b35ce9f27e73d62188d7d38aa0dc0a219aa",
"status": "affected",
"version": "9363efb4181c5e0fbf86bdfa759262aa29f0eb50",
"versionType": "git"
},
{
"lessThan": "c9e0f06a023107694698a7930616aeb460d91816",
"status": "affected",
"version": "9363efb4181c5e0fbf86bdfa759262aa29f0eb50",
"versionType": "git"
},
{
"lessThan": "cc56d2b0d77cfeea061e98114992ee687d5eb4dd",
"status": "affected",
"version": "9363efb4181c5e0fbf86bdfa759262aa29f0eb50",
"versionType": "git"
},
{
"lessThan": "002f1f99aef7ea631cb687fc17bce64e4963f6aa",
"status": "affected",
"version": "9363efb4181c5e0fbf86bdfa759262aa29f0eb50",
"versionType": "git"
},
{
"lessThan": "2f65718b9c1095eef1ae9b374aa0384b1b083f3c",
"status": "affected",
"version": "9363efb4181c5e0fbf86bdfa759262aa29f0eb50",
"versionType": "git"
},
{
"lessThan": "46a84efe2dbaddde89073a3c00c694486937c34b",
"status": "affected",
"version": "9363efb4181c5e0fbf86bdfa759262aa29f0eb50",
"versionType": "git"
},
{
"lessThan": "4839f4c21f9c577eedef2919ced878a3057c7fc3",
"status": "affected",
"version": "9363efb4181c5e0fbf86bdfa759262aa29f0eb50",
"versionType": "git"
},
{
"lessThan": "7f2345f47dd189625f657cd72437179ab4170ee1",
"status": "affected",
"version": "9363efb4181c5e0fbf86bdfa759262aa29f0eb50",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/crypto/qce/aead.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.14"
},
{
"lessThan": "5.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.220",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.187",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.156",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.108",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.49",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.13",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.3",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.220",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.187",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.156",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.108",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.49",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.13",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.3",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "5.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: qce - fix CCM AAD buffer underallocation\n\nThe AAD buffer allocated in qce_aead_ccm_prepare_buf_assoclen()\ncan be smaller than the length later programmed into the DMA\nscatterlist.\n\nThe allocation size is currently calculated as:\n\n ALIGN(assoclen, 16) + MAX_CCM_ADATA_HEADER_LEN\n\nwhile the DMA length is set to:\n\n ALIGN(assoclen + adata_header_len, 16)\n\nSince ALIGN() does not distribute over addition, the allocation\ncan be smaller than the DMA length. For example, when\nassoclen = 32 and adata_header_len = 2:\n\n allocation = ALIGN(32, 16) + 6 = 38\n DMA length = ALIGN(32 + 2, 16) = 48\n\nAs a result, the QCE hardware can read beyond the allocated\nbuffer while computing the CBC-MAC over the associated data.\nThe extra bytes are folded into the authentication tag,\nresulting in an incorrect tag and causing CCM self-test\nfailures such as:\n\n alg: aead: ccm-aes-qce encryption test failed (wrong result)\n on test vector 8\n\nFix the allocation by adding the maximum possible AAD header\nlength before alignment:\n\n ALIGN(assoclen + MAX_CCM_ADATA_HEADER_LEN, 16)\n\nThis guarantees that the allocated buffer is large enough\nfor the fully padded AAD data for all supported header sizes."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T15:54:40.017Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/11775b35ce9f27e73d62188d7d38aa0dc0a219aa"
},
{
"url": "https://git.kernel.org/stable/c/c9e0f06a023107694698a7930616aeb460d91816"
},
{
"url": "https://git.kernel.org/stable/c/cc56d2b0d77cfeea061e98114992ee687d5eb4dd"
},
{
"url": "https://git.kernel.org/stable/c/002f1f99aef7ea631cb687fc17bce64e4963f6aa"
},
{
"url": "https://git.kernel.org/stable/c/2f65718b9c1095eef1ae9b374aa0384b1b083f3c"
},
{
"url": "https://git.kernel.org/stable/c/46a84efe2dbaddde89073a3c00c694486937c34b"
},
{
"url": "https://git.kernel.org/stable/c/4839f4c21f9c577eedef2919ced878a3057c7fc3"
},
{
"url": "https://git.kernel.org/stable/c/7f2345f47dd189625f657cd72437179ab4170ee1"
}
],
"title": "crypto: qce - fix CCM AAD buffer underallocation",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80832",
"datePublished": "2026-09-04T15:54:40.017Z",
"dateReserved": "2026-08-26T14:34:25.796Z",
"dateUpdated": "2026-09-04T15:54:40.017Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2025-38203 (GCVE-0-2025-38203)
Vulnerability from cvelistv5
Published
2025-07-04 13:37
Modified
2026-09-02 12:49
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
jfs: Fix null-ptr-deref in jfs_ioc_trim
[ Syzkaller Report ]
Oops: general protection fault, probably for non-canonical address
0xdffffc0000000087: 0000 [#1
KASAN: null-ptr-deref in range [0x0000000000000438-0x000000000000043f]
CPU: 2 UID: 0 PID: 10614 Comm: syz-executor.0 Not tainted
6.13.0-rc6-gfbfd64d25c7a-dirty #1
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014
Sched_ext: serialise (enabled+all), task: runnable_at=-30ms
RIP: 0010:jfs_ioc_trim+0x34b/0x8f0
Code: e7 e8 59 a4 87 fe 4d 8b 24 24 4d 8d bc 24 38 04 00 00 48 8d 93
90 82 fe ff 4c 89 ff 31 f6
RSP: 0018:ffffc900055f7cd0 EFLAGS: 00010206
RAX: 0000000000000087 RBX: 00005866a9e67ff8 RCX: 000000000000000a
RDX: 0000000000000001 RSI: 0000000000000004 RDI: 0000000000000001
RBP: dffffc0000000000 R08: ffff88807c180003 R09: 1ffff1100f830000
R10: dffffc0000000000 R11: ffffed100f830001 R12: 0000000000000000
R13: 0000000000000000 R14: 0000000000000001 R15: 0000000000000438
FS: 00007fe520225640(0000) GS:ffff8880b7e80000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00005593c91b2c88 CR3: 000000014927c000 CR4: 00000000000006f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
<TASK>
? __die_body+0x61/0xb0
? die_addr+0xb1/0xe0
? exc_general_protection+0x333/0x510
? asm_exc_general_protection+0x26/0x30
? jfs_ioc_trim+0x34b/0x8f0
jfs_ioctl+0x3c8/0x4f0
? __pfx_jfs_ioctl+0x10/0x10
? __pfx_jfs_ioctl+0x10/0x10
__se_sys_ioctl+0x269/0x350
? __pfx___se_sys_ioctl+0x10/0x10
? do_syscall_64+0xfb/0x210
do_syscall_64+0xee/0x210
? syscall_exit_to_user_mode+0x1e0/0x330
entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7fe51f4903ad
Code: c3 e8 a7 2b 00 00 0f 1f 80 00 00 00 00 f3 0f 1e fa 48 89 f8 48
89 f7 48 89 d6 48 89 ca 4d
RSP: 002b:00007fe5202250c8 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 00007fe51f5cbf80 RCX: 00007fe51f4903ad
RDX: 0000000020000680 RSI: 00000000c0185879 RDI: 0000000000000005
RBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 00007fe520225640
R13: 000000000000000e R14: 00007fe51f44fca0 R15: 00007fe52021d000
</TASK>
Modules linked in:
---[ end trace 0000000000000000 ]---
RIP: 0010:jfs_ioc_trim+0x34b/0x8f0
Code: e7 e8 59 a4 87 fe 4d 8b 24 24 4d 8d bc 24 38 04 00 00 48 8d 93
90 82 fe ff 4c 89 ff 31 f6
RSP: 0018:ffffc900055f7cd0 EFLAGS: 00010206
RAX: 0000000000000087 RBX: 00005866a9e67ff8 RCX: 000000000000000a
RDX: 0000000000000001 RSI: 0000000000000004 RDI: 0000000000000001
RBP: dffffc0000000000 R08: ffff88807c180003 R09: 1ffff1100f830000
R10: dffffc0000000000 R11: ffffed100f830001 R12: 0000000000000000
R13: 0000000000000000 R14: 0000000000000001 R15: 0000000000000438
FS: 00007fe520225640(0000) GS:ffff8880b7e80000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00005593c91b2c88 CR3: 000000014927c000 CR4: 00000000000006f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Kernel panic - not syncing: Fatal exception
[ Analysis ]
We believe that we have found a concurrency bug in the `fs/jfs` module
that results in a null pointer dereference. There is a closely related
issue which has been fixed:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=d6c1b3599b2feb5c7291f5ac3a36e5fa7cedb234
... but, unfortunately, the accepted patch appears to still be
susceptible to a null pointer dereference under some interleavings.
To trigger the bug, we think that `JFS_SBI(ipbmap->i_sb)->bmap` is set
to NULL in `dbFreeBits` and then dereferenced in `jfs_ioc_trim`. This
bug manifests quite rarely under normal circumstances, but is
triggereable from a syz-program.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: b40c2e665cd552eae5fbdbb878bc29a34357668e Version: b40c2e665cd552eae5fbdbb878bc29a34357668e Version: b40c2e665cd552eae5fbdbb878bc29a34357668e Version: b40c2e665cd552eae5fbdbb878bc29a34357668e Version: b40c2e665cd552eae5fbdbb878bc29a34357668e Version: b40c2e665cd552eae5fbdbb878bc29a34357668e Version: b40c2e665cd552eae5fbdbb878bc29a34357668e Version: b40c2e665cd552eae5fbdbb878bc29a34357668e |
||
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2025-11-03T17:35:25.733Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"url": "https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/jfs/jfs_discard.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "0d50231d473f89024158dc62624930de45d13718",
"status": "affected",
"version": "b40c2e665cd552eae5fbdbb878bc29a34357668e",
"versionType": "git"
},
{
"lessThan": "a9d41c925069c950e18160e12a7e10e0f58c56fb",
"status": "affected",
"version": "b40c2e665cd552eae5fbdbb878bc29a34357668e",
"versionType": "git"
},
{
"lessThan": "4a8cb9908b51500a76f5156423bd295df53bff89",
"status": "affected",
"version": "b40c2e665cd552eae5fbdbb878bc29a34357668e",
"versionType": "git"
},
{
"lessThan": "4a2de0f5b8d7f218bea5bd43d30b466e8b272b8d",
"status": "affected",
"version": "b40c2e665cd552eae5fbdbb878bc29a34357668e",
"versionType": "git"
},
{
"lessThan": "a39f811a9f5edb6d97bede8e6fe730393d3c8537",
"status": "affected",
"version": "b40c2e665cd552eae5fbdbb878bc29a34357668e",
"versionType": "git"
},
{
"lessThan": "233340626cf1b1887dca181f9f811db60c73f802",
"status": "affected",
"version": "b40c2e665cd552eae5fbdbb878bc29a34357668e",
"versionType": "git"
},
{
"lessThan": "9806ae34d7d661c372247cd36f83bfa0523d60ed",
"status": "affected",
"version": "b40c2e665cd552eae5fbdbb878bc29a34357668e",
"versionType": "git"
},
{
"lessThan": "a4685408ff6c3e2af366ad9a7274f45ff3f394ee",
"status": "affected",
"version": "b40c2e665cd552eae5fbdbb878bc29a34357668e",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/jfs/jfs_discard.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.7"
},
{
"lessThan": "3.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.4.*",
"status": "unaffected",
"version": "5.4.295",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.239",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.186",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.187",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.156",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.108",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.15.*",
"status": "unaffected",
"version": "6.15.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "6.16",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.4.295",
"versionStartIncluding": "3.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.239",
"versionStartIncluding": "3.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.186",
"versionStartIncluding": "3.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.187",
"versionStartIncluding": "3.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.156",
"versionStartIncluding": "3.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.108",
"versionStartIncluding": "3.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.15.4",
"versionStartIncluding": "3.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.16",
"versionStartIncluding": "3.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\njfs: Fix null-ptr-deref in jfs_ioc_trim\n\n[ Syzkaller Report ]\n\nOops: general protection fault, probably for non-canonical address\n0xdffffc0000000087: 0000 [#1\nKASAN: null-ptr-deref in range [0x0000000000000438-0x000000000000043f]\nCPU: 2 UID: 0 PID: 10614 Comm: syz-executor.0 Not tainted\n6.13.0-rc6-gfbfd64d25c7a-dirty #1\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014\nSched_ext: serialise (enabled+all), task: runnable_at=-30ms\nRIP: 0010:jfs_ioc_trim+0x34b/0x8f0\nCode: e7 e8 59 a4 87 fe 4d 8b 24 24 4d 8d bc 24 38 04 00 00 48 8d 93\n90 82 fe ff 4c 89 ff 31 f6\nRSP: 0018:ffffc900055f7cd0 EFLAGS: 00010206\nRAX: 0000000000000087 RBX: 00005866a9e67ff8 RCX: 000000000000000a\nRDX: 0000000000000001 RSI: 0000000000000004 RDI: 0000000000000001\nRBP: dffffc0000000000 R08: ffff88807c180003 R09: 1ffff1100f830000\nR10: dffffc0000000000 R11: ffffed100f830001 R12: 0000000000000000\nR13: 0000000000000000 R14: 0000000000000001 R15: 0000000000000438\nFS: 00007fe520225640(0000) GS:ffff8880b7e80000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00005593c91b2c88 CR3: 000000014927c000 CR4: 00000000000006f0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\n\u003cTASK\u003e\n? __die_body+0x61/0xb0\n? die_addr+0xb1/0xe0\n? exc_general_protection+0x333/0x510\n? asm_exc_general_protection+0x26/0x30\n? jfs_ioc_trim+0x34b/0x8f0\njfs_ioctl+0x3c8/0x4f0\n? __pfx_jfs_ioctl+0x10/0x10\n? __pfx_jfs_ioctl+0x10/0x10\n__se_sys_ioctl+0x269/0x350\n? __pfx___se_sys_ioctl+0x10/0x10\n? do_syscall_64+0xfb/0x210\ndo_syscall_64+0xee/0x210\n? syscall_exit_to_user_mode+0x1e0/0x330\nentry_SYSCALL_64_after_hwframe+0x77/0x7f\nRIP: 0033:0x7fe51f4903ad\nCode: c3 e8 a7 2b 00 00 0f 1f 80 00 00 00 00 f3 0f 1e fa 48 89 f8 48\n89 f7 48 89 d6 48 89 ca 4d\nRSP: 002b:00007fe5202250c8 EFLAGS: 00000246 ORIG_RAX: 0000000000000010\nRAX: ffffffffffffffda RBX: 00007fe51f5cbf80 RCX: 00007fe51f4903ad\nRDX: 0000000020000680 RSI: 00000000c0185879 RDI: 0000000000000005\nRBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000000\nR10: 0000000000000000 R11: 0000000000000246 R12: 00007fe520225640\nR13: 000000000000000e R14: 00007fe51f44fca0 R15: 00007fe52021d000\n\u003c/TASK\u003e\nModules linked in:\n---[ end trace 0000000000000000 ]---\nRIP: 0010:jfs_ioc_trim+0x34b/0x8f0\nCode: e7 e8 59 a4 87 fe 4d 8b 24 24 4d 8d bc 24 38 04 00 00 48 8d 93\n90 82 fe ff 4c 89 ff 31 f6\nRSP: 0018:ffffc900055f7cd0 EFLAGS: 00010206\nRAX: 0000000000000087 RBX: 00005866a9e67ff8 RCX: 000000000000000a\nRDX: 0000000000000001 RSI: 0000000000000004 RDI: 0000000000000001\nRBP: dffffc0000000000 R08: ffff88807c180003 R09: 1ffff1100f830000\nR10: dffffc0000000000 R11: ffffed100f830001 R12: 0000000000000000\nR13: 0000000000000000 R14: 0000000000000001 R15: 0000000000000438\nFS: 00007fe520225640(0000) GS:ffff8880b7e80000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00005593c91b2c88 CR3: 000000014927c000 CR4: 00000000000006f0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nKernel panic - not syncing: Fatal exception\n\n[ Analysis ]\n\nWe believe that we have found a concurrency bug in the `fs/jfs` module\nthat results in a null pointer dereference. There is a closely related\nissue which has been fixed:\n\nhttps://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=d6c1b3599b2feb5c7291f5ac3a36e5fa7cedb234\n\n... but, unfortunately, the accepted patch appears to still be\nsusceptible to a null pointer dereference under some interleavings.\n\nTo trigger the bug, we think that `JFS_SBI(ipbmap-\u003ei_sb)-\u003ebmap` is set\nto NULL in `dbFreeBits` and then dereferenced in `jfs_ioc_trim`. This\nbug manifests quite rarely under normal circumstances, but is\ntriggereable from a syz-program."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-02T12:49:17.628Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/0d50231d473f89024158dc62624930de45d13718"
},
{
"url": "https://git.kernel.org/stable/c/a9d41c925069c950e18160e12a7e10e0f58c56fb"
},
{
"url": "https://git.kernel.org/stable/c/4a8cb9908b51500a76f5156423bd295df53bff89"
},
{
"url": "https://git.kernel.org/stable/c/4a2de0f5b8d7f218bea5bd43d30b466e8b272b8d"
},
{
"url": "https://git.kernel.org/stable/c/a39f811a9f5edb6d97bede8e6fe730393d3c8537"
},
{
"url": "https://git.kernel.org/stable/c/233340626cf1b1887dca181f9f811db60c73f802"
},
{
"url": "https://git.kernel.org/stable/c/9806ae34d7d661c372247cd36f83bfa0523d60ed"
},
{
"url": "https://git.kernel.org/stable/c/a4685408ff6c3e2af366ad9a7274f45ff3f394ee"
}
],
"title": "jfs: Fix null-ptr-deref in jfs_ioc_trim",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2025-38203",
"datePublished": "2025-07-04T13:37:23.975Z",
"dateReserved": "2025-04-16T04:51:23.994Z",
"dateUpdated": "2026-09-02T12:49:17.628Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74746 (GCVE-0-2026-74746)
Vulnerability from cvelistv5
Published
2026-08-26 14:36
Modified
2026-08-27 05:01
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
netfilter: flowtable: publish GC-visible tuple last
nf_flow_table_iterate() only treats original-direction tuple nodes as
owning entries. Publishing the original node first lets GC observe and
free a flow while flow_offload_add() is still inserting the reply node.
Publish the reply node first and the original node last so GC never
sees a partially installed flow.
KASAN can trigger slab-use-after-free read and write reports in the
flowtable/rhashtable path (rht_deferred_worker, jhash, flow_offload_del,
flow_offload_lookup, etc.).
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ac2a66665e231847cab11b8c8e844ce43207dd2e Version: ac2a66665e231847cab11b8c8e844ce43207dd2e Version: ac2a66665e231847cab11b8c8e844ce43207dd2e Version: ac2a66665e231847cab11b8c8e844ce43207dd2e Version: ac2a66665e231847cab11b8c8e844ce43207dd2e Version: ac2a66665e231847cab11b8c8e844ce43207dd2e Version: ac2a66665e231847cab11b8c8e844ce43207dd2e Version: ac2a66665e231847cab11b8c8e844ce43207dd2e |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/netfilter/nf_flow_table_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "0a00254585827f1695aa2700114af622ea754cfa",
"status": "affected",
"version": "ac2a66665e231847cab11b8c8e844ce43207dd2e",
"versionType": "git"
},
{
"lessThan": "be345dcbddb4643a54252b954af974b16eda8f91",
"status": "affected",
"version": "ac2a66665e231847cab11b8c8e844ce43207dd2e",
"versionType": "git"
},
{
"lessThan": "211ee5d998d92a7d548811939c65942d06c146e4",
"status": "affected",
"version": "ac2a66665e231847cab11b8c8e844ce43207dd2e",
"versionType": "git"
},
{
"lessThan": "d37917e7bebe078f3c17e47fd6fc1c9f6e8497b2",
"status": "affected",
"version": "ac2a66665e231847cab11b8c8e844ce43207dd2e",
"versionType": "git"
},
{
"lessThan": "972fdf7c4f5c282a239c88fea614b056c33dc025",
"status": "affected",
"version": "ac2a66665e231847cab11b8c8e844ce43207dd2e",
"versionType": "git"
},
{
"lessThan": "d9d3050a70efe217e73a0751e55fdae6a7092620",
"status": "affected",
"version": "ac2a66665e231847cab11b8c8e844ce43207dd2e",
"versionType": "git"
},
{
"lessThan": "d16b71231e65cb05daea2b45701fcf09cef041e7",
"status": "affected",
"version": "ac2a66665e231847cab11b8c8e844ce43207dd2e",
"versionType": "git"
},
{
"lessThan": "2014ac62df9d45bb9a004a043e85df7be09ed780",
"status": "affected",
"version": "ac2a66665e231847cab11b8c8e844ce43207dd2e",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/netfilter/nf_flow_table_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.16"
},
{
"lessThan": "4.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "4.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "4.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "4.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "4.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "4.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.46",
"versionStartIncluding": "4.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.10",
"versionStartIncluding": "4.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.16",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: flowtable: publish GC-visible tuple last\n\nnf_flow_table_iterate() only treats original-direction tuple nodes as\nowning entries. Publishing the original node first lets GC observe and\nfree a flow while flow_offload_add() is still inserting the reply node.\nPublish the reply node first and the original node last so GC never\nsees a partially installed flow.\n\nKASAN can trigger slab-use-after-free read and write reports in the\nflowtable/rhashtable path (rht_deferred_worker, jhash, flow_offload_del,\nflow_offload_lookup, etc.)."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - flow_offload_add runs from nft_flow_offload_eval on the FORWARD hook and from tc act_ct during softirq packet processing when remote TCP/UDP traffic creates new offloaded conntrack flows on nftables flowtable routers/gateways, not through netlink configuration APIs.\nAC:L - The attacker controls when flows are offloaded (packet rate/timing) and can race connection teardown so nf_flow_table_gc_run observes a partially installed original tuple while reply insertion is still in progress; both the insert and GC sides of the race are attacker-driven.\nPR:N - On the intended edge-router/OpenWrt deployment, nftables flow offload is an administrator prerequisite; a remote sender needs no local account, authentication, or CAP_NET_ADMIN on the victim to trigger flow_offload_add while forwarding traffic.\nUI:N - Exploitation requires only sending network packets processed automatically on the forwarding or ingress path; no victim must open files, mount filesystems, or take any interactive action beyond normal traffic through the router.\nS:U - Slab use-after-free in the flowtable rhashtable/GC path affects only in-kernel memory on the affected host; this is standard kernel compromise within one security authority, not a VM escape, IOMMU bypass, or cross-boundary sandbox break.\nC:H - The fix commit documents KASAN slab-use-after-free read and write reports in rht_deferred_worker, jhash, flow_offload_del, and flow_offload_lookup; UAF on flow_offload kmem-cache objects enables arbitrary kernel memory disclosure via heap grooming.\nI:H - Freed flow_offload structures remain reachable during concurrent rhashtable insert/remove and deferred worker operations, providing attacker-influenceable heap corruption that can be groomed into arbitrary kernel writes and control-flow hijack.\nA:H - Concurrent GC freeing of a partially inserted flow while flow_offload_add or rhashtable workers still access it causes kernel oops/panic and reliable denial of service; UAF on the flow offload path can crash forwarding routers under sustained malicious traffic."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T05:01:07.405Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/0a00254585827f1695aa2700114af622ea754cfa"
},
{
"url": "https://git.kernel.org/stable/c/be345dcbddb4643a54252b954af974b16eda8f91"
},
{
"url": "https://git.kernel.org/stable/c/211ee5d998d92a7d548811939c65942d06c146e4"
},
{
"url": "https://git.kernel.org/stable/c/d37917e7bebe078f3c17e47fd6fc1c9f6e8497b2"
},
{
"url": "https://git.kernel.org/stable/c/972fdf7c4f5c282a239c88fea614b056c33dc025"
},
{
"url": "https://git.kernel.org/stable/c/d9d3050a70efe217e73a0751e55fdae6a7092620"
},
{
"url": "https://git.kernel.org/stable/c/d16b71231e65cb05daea2b45701fcf09cef041e7"
},
{
"url": "https://git.kernel.org/stable/c/2014ac62df9d45bb9a004a043e85df7be09ed780"
}
],
"title": "netfilter: flowtable: publish GC-visible tuple last",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74746",
"datePublished": "2026-08-26T14:36:55.963Z",
"dateReserved": "2026-08-15T05:44:03.931Z",
"dateUpdated": "2026-08-27T05:01:07.405Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68165 (GCVE-0-2026-68165)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
mm/damon/core: validate ranges in damon_set_regions()
DAMON core logic assumes zero length regions don't exist. However, a few
DAMON API callers including DAMON_SYSFS, DAMON_RECLAIM and DAMON_LRU_SORT
allow users to set empty monitoring target regions. This could result in
WARN_ONCE() on CONFIG_DAMON_DEBUG_SANITY enabled kernel, and
divide-by-zero from damon_merge_two_regions().
For example, the WANR_ONCE() can be triggered like below.
# grep DAMON_DEBUG_SANITY /boot/config-$(uname -r)
# CONFIG_DAMON_DEBUG_SANITY=y
# damo start
# cd /sys/kernel/mm/damon/admin/kdamonds/0
# echo 0 > contexts/0/targets/0/regions/0/start
# echo 0 > contexts/0/targets/0/regions/0/end
# echo commit > state
# dmesg
[....]
[ 73.705780] ------------[ cut here ]------------
[ 73.707552] start 0 >= end 0
[ 73.708452] WARNING: mm/damon/core.c:359 at damon_new_region+0x6e/0x80, CPU#1: kdamond.0/758
[...]
All DAMON API callers eventually use damon_set_regions() to setup the
regions. Add the validation logic in the function.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 43b0536cb4710e7bb591edfda7e68a1c327a3409 Version: 43b0536cb4710e7bb591edfda7e68a1c327a3409 Version: 43b0536cb4710e7bb591edfda7e68a1c327a3409 Version: 43b0536cb4710e7bb591edfda7e68a1c327a3409 Version: 43b0536cb4710e7bb591edfda7e68a1c327a3409 Version: 43b0536cb4710e7bb591edfda7e68a1c327a3409 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"mm/damon/core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "71cf8a3ee1c18cfa8b88cc14bac9c2f43dd29f9b",
"status": "affected",
"version": "43b0536cb4710e7bb591edfda7e68a1c327a3409",
"versionType": "git"
},
{
"lessThan": "b585facbafbb5cf117b37b1c75819ac046646c27",
"status": "affected",
"version": "43b0536cb4710e7bb591edfda7e68a1c327a3409",
"versionType": "git"
},
{
"lessThan": "c927b73a5694c735314ea10e7c81c07f9bd51ad7",
"status": "affected",
"version": "43b0536cb4710e7bb591edfda7e68a1c327a3409",
"versionType": "git"
},
{
"lessThan": "4b6f1d6d5d07855bd1bb9e64922b049062138bfa",
"status": "affected",
"version": "43b0536cb4710e7bb591edfda7e68a1c327a3409",
"versionType": "git"
},
{
"lessThan": "43aaddd0fa92010a68adeda7744c7cf497a1c8e9",
"status": "affected",
"version": "43b0536cb4710e7bb591edfda7e68a1c327a3409",
"versionType": "git"
},
{
"lessThan": "1292c0ecb1caefb8ca064a3639d5673991e8810c",
"status": "affected",
"version": "43b0536cb4710e7bb591edfda7e68a1c327a3409",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"mm/damon/core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.16"
},
{
"lessThan": "5.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.16",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/damon/core: validate ranges in damon_set_regions()\n\nDAMON core logic assumes zero length regions don\u0027t exist. However, a few\nDAMON API callers including DAMON_SYSFS, DAMON_RECLAIM and DAMON_LRU_SORT\nallow users to set empty monitoring target regions. This could result in\nWARN_ONCE() on CONFIG_DAMON_DEBUG_SANITY enabled kernel, and\ndivide-by-zero from damon_merge_two_regions().\n\nFor example, the WANR_ONCE() can be triggered like below.\n\n # grep DAMON_DEBUG_SANITY /boot/config-$(uname -r)\n # CONFIG_DAMON_DEBUG_SANITY=y\n # damo start\n # cd /sys/kernel/mm/damon/admin/kdamonds/0\n # echo 0 \u003e contexts/0/targets/0/regions/0/start\n # echo 0 \u003e contexts/0/targets/0/regions/0/end\n # echo commit \u003e state\n # dmesg\n [....]\n [ 73.705780] ------------[ cut here ]------------\n [ 73.707552] start 0 \u003e= end 0\n [ 73.708452] WARNING: mm/damon/core.c:359 at damon_new_region+0x6e/0x80, CPU#1: kdamond.0/758\n [...]\n\nAll DAMON API callers eventually use damon_set_regions() to setup the\nregions. Add the validation logic in the function."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:30:37.581Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/71cf8a3ee1c18cfa8b88cc14bac9c2f43dd29f9b"
},
{
"url": "https://git.kernel.org/stable/c/b585facbafbb5cf117b37b1c75819ac046646c27"
},
{
"url": "https://git.kernel.org/stable/c/c927b73a5694c735314ea10e7c81c07f9bd51ad7"
},
{
"url": "https://git.kernel.org/stable/c/4b6f1d6d5d07855bd1bb9e64922b049062138bfa"
},
{
"url": "https://git.kernel.org/stable/c/43aaddd0fa92010a68adeda7744c7cf497a1c8e9"
},
{
"url": "https://git.kernel.org/stable/c/1292c0ecb1caefb8ca064a3639d5673991e8810c"
}
],
"title": "mm/damon/core: validate ranges in damon_set_regions()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68165",
"datePublished": "2026-08-10T11:59:33.152Z",
"dateReserved": "2026-07-30T09:28:09.372Z",
"dateUpdated": "2026-08-19T16:30:37.581Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68197 (GCVE-0-2026-68197)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper
mwifiex_tdls_add_ht_oper() gates its follow-the-AP-bandwidth path on
bss_desc->bcn_ht_cap being present, but then dereferences a different
pointer, bss_desc->bcn_ht_oper:
if (ISSUPP_CHANWIDTH40(priv->adapter->hw_dot_11n_dev_cap) &&
bss_desc->bcn_ht_cap &&
ISALLOWED_CHANWIDTH40(bss_desc->bcn_ht_oper->ht_param))
bcn_ht_cap and bcn_ht_oper are populated independently while parsing the
associated AP's beacon in mwifiex_update_bss_desc_with_ie(): an AP that
advertises an HT Capabilities element but no HT Operation element leaves
bcn_ht_cap non-NULL and bcn_ht_oper NULL. Setting up a TDLS link to a
peer while associated to such an AP then dereferences the NULL
bcn_ht_oper and crashes the kernel. Every other bcn_ht_oper user in the
driver NULL-checks it first.
Guard on the pointer that is actually dereferenced.
Found by 0sec automated security-research tooling (https://0sec.ai).
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 396939f94084d5923d558e9f22db48bc51156e47 Version: 396939f94084d5923d558e9f22db48bc51156e47 Version: 396939f94084d5923d558e9f22db48bc51156e47 Version: 396939f94084d5923d558e9f22db48bc51156e47 Version: 396939f94084d5923d558e9f22db48bc51156e47 Version: 396939f94084d5923d558e9f22db48bc51156e47 Version: 396939f94084d5923d558e9f22db48bc51156e47 Version: 396939f94084d5923d558e9f22db48bc51156e47 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/marvell/mwifiex/tdls.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "e1770f7410b4232a0267924f99751dc9c5ca31af",
"status": "affected",
"version": "396939f94084d5923d558e9f22db48bc51156e47",
"versionType": "git"
},
{
"lessThan": "8c2058717fd06f05d421c2d3adf1dff3c3abcda1",
"status": "affected",
"version": "396939f94084d5923d558e9f22db48bc51156e47",
"versionType": "git"
},
{
"lessThan": "fba7eb7b248ea0618235f504158b685d752a153a",
"status": "affected",
"version": "396939f94084d5923d558e9f22db48bc51156e47",
"versionType": "git"
},
{
"lessThan": "eb42c3c8fd479166c42984728754cd779c71fd60",
"status": "affected",
"version": "396939f94084d5923d558e9f22db48bc51156e47",
"versionType": "git"
},
{
"lessThan": "45011e4d9ba3f2182e5df64be65888044fa20771",
"status": "affected",
"version": "396939f94084d5923d558e9f22db48bc51156e47",
"versionType": "git"
},
{
"lessThan": "9375a4ea4121625ef27a46b74781cda66a5cc61b",
"status": "affected",
"version": "396939f94084d5923d558e9f22db48bc51156e47",
"versionType": "git"
},
{
"lessThan": "cca4398aa305c22016d1714f388e2fa6ea4e5ad4",
"status": "affected",
"version": "396939f94084d5923d558e9f22db48bc51156e47",
"versionType": "git"
},
{
"lessThan": "c3d68e294cbb6a4090bb219d3dcaca85a011809b",
"status": "affected",
"version": "396939f94084d5923d558e9f22db48bc51156e47",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/marvell/mwifiex/tdls.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.16"
},
{
"lessThan": "3.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.16",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper\n\nmwifiex_tdls_add_ht_oper() gates its follow-the-AP-bandwidth path on\nbss_desc-\u003ebcn_ht_cap being present, but then dereferences a different\npointer, bss_desc-\u003ebcn_ht_oper:\n\n\tif (ISSUPP_CHANWIDTH40(priv-\u003eadapter-\u003ehw_dot_11n_dev_cap) \u0026\u0026\n\t bss_desc-\u003ebcn_ht_cap \u0026\u0026\n\t ISALLOWED_CHANWIDTH40(bss_desc-\u003ebcn_ht_oper-\u003eht_param))\n\nbcn_ht_cap and bcn_ht_oper are populated independently while parsing the\nassociated AP\u0027s beacon in mwifiex_update_bss_desc_with_ie(): an AP that\nadvertises an HT Capabilities element but no HT Operation element leaves\nbcn_ht_cap non-NULL and bcn_ht_oper NULL. Setting up a TDLS link to a\npeer while associated to such an AP then dereferences the NULL\nbcn_ht_oper and crashes the kernel. Every other bcn_ht_oper user in the\ndriver NULL-checks it first.\n\nGuard on the pointer that is actually dereferenced.\n\nFound by 0sec automated security-research tooling (https://0sec.ai)."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:16.085Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/e1770f7410b4232a0267924f99751dc9c5ca31af"
},
{
"url": "https://git.kernel.org/stable/c/8c2058717fd06f05d421c2d3adf1dff3c3abcda1"
},
{
"url": "https://git.kernel.org/stable/c/fba7eb7b248ea0618235f504158b685d752a153a"
},
{
"url": "https://git.kernel.org/stable/c/eb42c3c8fd479166c42984728754cd779c71fd60"
},
{
"url": "https://git.kernel.org/stable/c/45011e4d9ba3f2182e5df64be65888044fa20771"
},
{
"url": "https://git.kernel.org/stable/c/9375a4ea4121625ef27a46b74781cda66a5cc61b"
},
{
"url": "https://git.kernel.org/stable/c/cca4398aa305c22016d1714f388e2fa6ea4e5ad4"
},
{
"url": "https://git.kernel.org/stable/c/c3d68e294cbb6a4090bb219d3dcaca85a011809b"
}
],
"title": "wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68197",
"datePublished": "2026-08-10T12:00:15.750Z",
"dateReserved": "2026-07-30T09:28:09.374Z",
"dateUpdated": "2026-08-19T16:31:16.085Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68117 (GCVE-0-2026-68117)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-19 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
tipc: clear sock->sk on the failed-insert path in tipc_sk_create()
When tipc_sk_create() fails to insert the new socket (tipc_sk_insert()
returns non-zero), its error path frees the sk with sk_free() but leaves
sock->sk pointing at the freed object:
if (tipc_sk_insert(tsk)) {
sk_free(sk);
pr_warn("Socket create failed; port number exhausted\n");
return -EINVAL;
}
This is harmless for plain socket(): the syscall layer clears sock->ops
before releasing, so tipc_release() is never called. It is not harmless
on the accept() path. tipc_accept() creates the pre-allocated child
socket with tipc_sk_create(net, new_sock, 0, kern); on failure it leaves
new_sock->sk dangling and new_sock->ops non-NULL, and do_accept() then
fput()s the new file, so __sock_release() -> tipc_release() runs
lock_sock(new_sock->sk) on the freed sk -- a use-after-free write of the
sk_lock spinlock.
tipc_release() already guards this exact "failed accept() releases a
pre-allocated child" case with "if (sk == NULL) return 0;", but the
guard is bypassed because tipc_sk_create() left sock->sk non-NULL
(dangling) rather than NULL.
Clear sock->sk on the failed-insert path so the existing tipc_release()
NULL check fires and the use-after-free is avoided.
The tipc_sk_insert() failure is reached when the per-netns socket
rhashtable hits its max_size (tsk_rht_params.max_size = 1048576, ~2M
elements) -- i.e. once a netns holds ~2M TIPC sockets every insert
returns -E2BIG.
BUG: KASAN: slab-use-after-free in lock_sock_nested (net/core/sock.c:3839)
Write of size 8 at addr ffff8880047cdc38 by task init/1
lock_sock_nested (net/core/sock.c:3839)
tipc_release (net/tipc/socket.c:638)
__sock_release (net/socket.c:710)
sock_close (net/socket.c:1501)
__fput (fs/file_table.c:512)
Allocated by task 1:
sk_alloc (net/core/sock.c:2308)
tipc_sk_create (net/tipc/socket.c:487)
tipc_accept (net/tipc/socket.c:2744)
do_accept (net/socket.c:2034)
Freed by task 1:
__sk_destruct (net/core/sock.c:2391)
tipc_sk_create (net/tipc/socket.c:504)
tipc_accept (net/tipc/socket.c:2744)
do_accept (net/socket.c:2034)
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: efa78f2ae363428525fb4981bb63c555ee79f3c7 Version: 833ecd0eae76eadf81d6d747bb5bc992d1151867 Version: 00aff3590fc0a73bddd3b743863c14e76fd35c0c Version: 00aff3590fc0a73bddd3b743863c14e76fd35c0c Version: 00aff3590fc0a73bddd3b743863c14e76fd35c0c Version: 00aff3590fc0a73bddd3b743863c14e76fd35c0c Version: 00aff3590fc0a73bddd3b743863c14e76fd35c0c Version: 00aff3590fc0a73bddd3b743863c14e76fd35c0c Version: 638fa20b618b2bbcf86da71231624cc82121a036 Version: 7bc9e7f70bc57d8f02ffea2a42094281effb15ef Version: ef488669b2652bde5b6ee5a409a5b048a2a50db4 Version: 4919d82f7041157a421ca9bf39a78551d5ad8a1b Version: 3b2957fc09fe1ac7f07f40dd50dd5f93e3f3a7a2 Version: 5.10.132 ≤ Version: 5.15.56 ≤ Version: 4.9.324 ≤ Version: 4.14.289 ≤ Version: 4.19.253 ≤ Version: 5.4.207 ≤ Version: 5.18.13 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/tipc/socket.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "efebc23e9b29e3e5a9e2127dd066929f7f0d315e",
"status": "affected",
"version": "efa78f2ae363428525fb4981bb63c555ee79f3c7",
"versionType": "git"
},
{
"lessThan": "8d6f26d48e61ef34f1921289401dbf36b10816af",
"status": "affected",
"version": "833ecd0eae76eadf81d6d747bb5bc992d1151867",
"versionType": "git"
},
{
"lessThan": "82f59aa27f33bd014a7d8739371ab5712d15e33b",
"status": "affected",
"version": "00aff3590fc0a73bddd3b743863c14e76fd35c0c",
"versionType": "git"
},
{
"lessThan": "b07d87b31631edb6529e6cdcca790a7489d1250d",
"status": "affected",
"version": "00aff3590fc0a73bddd3b743863c14e76fd35c0c",
"versionType": "git"
},
{
"lessThan": "dd29891ed840f6b8d020b759d0dc4a00b1d6e4ea",
"status": "affected",
"version": "00aff3590fc0a73bddd3b743863c14e76fd35c0c",
"versionType": "git"
},
{
"lessThan": "5f5a41a48dbf9eda57b67ce23e548602cf7195a6",
"status": "affected",
"version": "00aff3590fc0a73bddd3b743863c14e76fd35c0c",
"versionType": "git"
},
{
"lessThan": "f9596b1566616a8be0592dbceccb6344a7c6f6bb",
"status": "affected",
"version": "00aff3590fc0a73bddd3b743863c14e76fd35c0c",
"versionType": "git"
},
{
"lessThan": "ba0533fc163f905fe817cfabdf8ed4058da44800",
"status": "affected",
"version": "00aff3590fc0a73bddd3b743863c14e76fd35c0c",
"versionType": "git"
},
{
"status": "affected",
"version": "638fa20b618b2bbcf86da71231624cc82121a036",
"versionType": "git"
},
{
"status": "affected",
"version": "7bc9e7f70bc57d8f02ffea2a42094281effb15ef",
"versionType": "git"
},
{
"status": "affected",
"version": "ef488669b2652bde5b6ee5a409a5b048a2a50db4",
"versionType": "git"
},
{
"status": "affected",
"version": "4919d82f7041157a421ca9bf39a78551d5ad8a1b",
"versionType": "git"
},
{
"status": "affected",
"version": "3b2957fc09fe1ac7f07f40dd50dd5f93e3f3a7a2",
"versionType": "git"
},
{
"lessThan": "5.10.265",
"status": "affected",
"version": "5.10.132",
"versionType": "semver"
},
{
"lessThan": "5.15.216",
"status": "affected",
"version": "5.15.56",
"versionType": "semver"
},
{
"lessThan": "4.10",
"status": "affected",
"version": "4.9.324",
"versionType": "semver"
},
{
"lessThan": "4.15",
"status": "affected",
"version": "4.14.289",
"versionType": "semver"
},
{
"lessThan": "4.20",
"status": "affected",
"version": "4.19.253",
"versionType": "semver"
},
{
"lessThan": "5.5",
"status": "affected",
"version": "5.4.207",
"versionType": "semver"
},
{
"lessThan": "5.19",
"status": "affected",
"version": "5.18.13",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/tipc/socket.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.19"
},
{
"lessThan": "5.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.10.132",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.15.56",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.9.324",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.14.289",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.19.253",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.4.207",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.18.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: clear sock-\u003esk on the failed-insert path in tipc_sk_create()\n\nWhen tipc_sk_create() fails to insert the new socket (tipc_sk_insert()\nreturns non-zero), its error path frees the sk with sk_free() but leaves\nsock-\u003esk pointing at the freed object:\n\n\tif (tipc_sk_insert(tsk)) {\n\t\tsk_free(sk);\n\t\tpr_warn(\"Socket create failed; port number exhausted\\n\");\n\t\treturn -EINVAL;\n\t}\n\nThis is harmless for plain socket(): the syscall layer clears sock-\u003eops\nbefore releasing, so tipc_release() is never called. It is not harmless\non the accept() path. tipc_accept() creates the pre-allocated child\nsocket with tipc_sk_create(net, new_sock, 0, kern); on failure it leaves\nnew_sock-\u003esk dangling and new_sock-\u003eops non-NULL, and do_accept() then\nfput()s the new file, so __sock_release() -\u003e tipc_release() runs\nlock_sock(new_sock-\u003esk) on the freed sk -- a use-after-free write of the\nsk_lock spinlock.\n\ntipc_release() already guards this exact \"failed accept() releases a\npre-allocated child\" case with \"if (sk == NULL) return 0;\", but the\nguard is bypassed because tipc_sk_create() left sock-\u003esk non-NULL\n(dangling) rather than NULL.\n\nClear sock-\u003esk on the failed-insert path so the existing tipc_release()\nNULL check fires and the use-after-free is avoided.\n\nThe tipc_sk_insert() failure is reached when the per-netns socket\nrhashtable hits its max_size (tsk_rht_params.max_size = 1048576, ~2M\nelements) -- i.e. once a netns holds ~2M TIPC sockets every insert\nreturns -E2BIG.\n\n BUG: KASAN: slab-use-after-free in lock_sock_nested (net/core/sock.c:3839)\n Write of size 8 at addr ffff8880047cdc38 by task init/1\n lock_sock_nested (net/core/sock.c:3839)\n tipc_release (net/tipc/socket.c:638)\n __sock_release (net/socket.c:710)\n sock_close (net/socket.c:1501)\n __fput (fs/file_table.c:512)\n Allocated by task 1:\n sk_alloc (net/core/sock.c:2308)\n tipc_sk_create (net/tipc/socket.c:487)\n tipc_accept (net/tipc/socket.c:2744)\n do_accept (net/socket.c:2034)\n Freed by task 1:\n __sk_destruct (net/core/sock.c:2391)\n tipc_sk_create (net/tipc/socket.c:504)\n tipc_accept (net/tipc/socket.c:2744)\n do_accept (net/socket.c:2034)"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug is hit in tipc_accept() when a listening SOCK_STREAM/SOCK_SEQPACKET socket accepts an incoming TIPC connection; peers reach this path over default UDP/Ethernet bearers (e.g. UDP/6118) without local syscall access.\nAC:L - An attacker can deterministically fill the per-netns TIPC socket rhashtable (~2M entries) by opening many sockets or connections, then trigger the failed-insert accept() cleanup path that performs lock_sock() on the freed sk.\nPR:N - No elevated Linux capabilities are required to create AF_TIPC stream/seqpacket sockets or send unauthenticated TIPC SYN traffic to a listening cluster service; only LSM policy may restrict access.\nUI:N - Exploitation needs no end-user action beyond a server\u2019s normal accept() loop processing inbound TIPC connection requests queued by the network stack.\nS:U - The use-after-free corrupts kernel heap memory within the same kernel security domain; impact is kernel privilege escalation or crash, not a VM/hypervisor or IOMMU boundary crossing.\nC:H - tipc_release() calls lock_sock() on a freed struct sock, a slab use-after-free that can be groomed for arbitrary kernel memory disclosure via controlled reuse of the freed socket object.\nI:H - The UAF performs an 8-byte write to sk_lock on freed memory during socket teardown, enabling heap corruption and potential arbitrary kernel write or code execution primitives.\nA:H - KASAN reports slab-use-after-free in lock_sock_nested during tipc_release on the failed accept() path, causing kernel oops/panic and denial of service even without full exploitation."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:29:29.277Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/efebc23e9b29e3e5a9e2127dd066929f7f0d315e"
},
{
"url": "https://git.kernel.org/stable/c/8d6f26d48e61ef34f1921289401dbf36b10816af"
},
{
"url": "https://git.kernel.org/stable/c/82f59aa27f33bd014a7d8739371ab5712d15e33b"
},
{
"url": "https://git.kernel.org/stable/c/b07d87b31631edb6529e6cdcca790a7489d1250d"
},
{
"url": "https://git.kernel.org/stable/c/dd29891ed840f6b8d020b759d0dc4a00b1d6e4ea"
},
{
"url": "https://git.kernel.org/stable/c/5f5a41a48dbf9eda57b67ce23e548602cf7195a6"
},
{
"url": "https://git.kernel.org/stable/c/f9596b1566616a8be0592dbceccb6344a7c6f6bb"
},
{
"url": "https://git.kernel.org/stable/c/ba0533fc163f905fe817cfabdf8ed4058da44800"
}
],
"title": "tipc: clear sock-\u003esk on the failed-insert path in tipc_sk_create()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68117",
"datePublished": "2026-08-10T11:58:36.675Z",
"dateReserved": "2026-07-30T09:28:09.369Z",
"dateUpdated": "2026-08-19T16:29:29.277Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74621 (GCVE-0-2026-74621)
Vulnerability from cvelistv5
Published
2026-08-22 15:32
Modified
2026-08-25 05:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/sched: act_ct: fix sk_buff leak when the header checks reject a packet
tcf_ct_handle_fragments() runs its header sanity checks before handing
anything to the defragmentation engine:
if (family == NFPROTO_IPV4)
err = tcf_ct_ipv4_is_fragment(skb, &frag);
else
err = tcf_ct_ipv6_is_fragment(skb, &frag);
if (err || !frag)
return err;
tcf_ct_ipv4_is_fragment() returns -EINVAL or -ENOMEM;
tcf_ct_ipv6_is_fragment() adds -EPROTO when ipv6_find_hdr() fails. None of
them frees or queues the skb, so on that path the caller still owns it.
tcf_ct_act() however funnels every non-zero return into the
ownership-transfer exit:
err = tcf_ct_handle_fragments(net, skb, family, p->zone, &defrag);
if (err)
goto out_frag;
...
out_frag:
if (err != -EINPROGRESS)
tcf_action_inc_drop_qstats(&c->common);
return TC_ACT_CONSUMED;
TC_ACT_CONSUMED means the action took ownership of the skb, so no caller
frees it - sch_handle_ingress(), sch_handle_egress() and
tcf_qevent_handle() all deliberately skip the free for that verdict. The
skb is therefore orphaned: one sk_buff plus its data buffer is leaked per
malformed packet, unbounded. Note the drop counter is already incremented
for these errors, so the statistics claim a drop that never happens.
Three different ownership states reach out_frag: today - the skb may be
queued by the defrag engine (-EINPROGRESS), already freed by
nf_ct_handle_fragments(), or still owned by us. Tell the caller which of
those it is, and free the packet ourselves in the last case, which
restores the TC_ACT_SHOT behaviour that predated the Fixes: commit.
Reproduced on v7.2-rc6 with a 54-byte frame carrying a 40-byte IPv6
header with nexthdr = 0 (hop-by-hop) and nothing after it, on a
clsact ingress chain with "action ct". kmemleak reports one leaked
232-byte skbuff_head_cache object plus its 704-byte data buffer per
packet; with this patch it reports none.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 172ba7d46c202e679f3ccb10264c67416aaeb1c4 Version: 0b5b831122fc3789fff75be433ba3e4dd7b779d4 Version: 73f7da5fd124f2cda9161e2e46114915e6e82e97 Version: 3f14b377d01d8357eba032b4cabc8c1149b458b6 Version: 3f14b377d01d8357eba032b4cabc8c1149b458b6 Version: 3f14b377d01d8357eba032b4cabc8c1149b458b6 Version: 3f14b377d01d8357eba032b4cabc8c1149b458b6 Version: f5346df0591d10bc948761ca854b1fae6d2ef441 Version: 5.15.148 ≤ Version: 6.1.75 ≤ Version: 6.6.14 ≤ Version: 6.7.2 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/sched/act_ct.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b5dbecc2016e1692fd1c2532af9c41ba729cb747",
"status": "affected",
"version": "172ba7d46c202e679f3ccb10264c67416aaeb1c4",
"versionType": "git"
},
{
"lessThan": "23e97d594ddd0153020c506d5041048fbde1beb4",
"status": "affected",
"version": "0b5b831122fc3789fff75be433ba3e4dd7b779d4",
"versionType": "git"
},
{
"lessThan": "737873a59905a54ca0d2d127ef882f3f88bf4379",
"status": "affected",
"version": "73f7da5fd124f2cda9161e2e46114915e6e82e97",
"versionType": "git"
},
{
"lessThan": "47d99828591d0fe8be4b9c8992ff3b8e47968db9",
"status": "affected",
"version": "3f14b377d01d8357eba032b4cabc8c1149b458b6",
"versionType": "git"
},
{
"lessThan": "b47bb899e04b5407c5a63fe88d4b6676586a6e84",
"status": "affected",
"version": "3f14b377d01d8357eba032b4cabc8c1149b458b6",
"versionType": "git"
},
{
"lessThan": "439d3e404f9d5e515911cc8132cde198b337c19e",
"status": "affected",
"version": "3f14b377d01d8357eba032b4cabc8c1149b458b6",
"versionType": "git"
},
{
"lessThan": "8a7ed561671aa6a911a2de99e59ef670a4d0b1df",
"status": "affected",
"version": "3f14b377d01d8357eba032b4cabc8c1149b458b6",
"versionType": "git"
},
{
"status": "affected",
"version": "f5346df0591d10bc948761ca854b1fae6d2ef441",
"versionType": "git"
},
{
"lessThan": "5.15.217",
"status": "affected",
"version": "5.15.148",
"versionType": "semver"
},
{
"lessThan": "6.1.184",
"status": "affected",
"version": "6.1.75",
"versionType": "semver"
},
{
"lessThan": "6.6.152",
"status": "affected",
"version": "6.6.14",
"versionType": "semver"
},
{
"lessThan": "6.8",
"status": "affected",
"version": "6.7.2",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/sched/act_ct.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.8"
},
{
"lessThan": "6.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.15.148",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "6.1.75",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "6.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.7.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: act_ct: fix sk_buff leak when the header checks reject a packet\n\ntcf_ct_handle_fragments() runs its header sanity checks before handing\nanything to the defragmentation engine:\n\n\tif (family == NFPROTO_IPV4)\n\t\terr = tcf_ct_ipv4_is_fragment(skb, \u0026frag);\n\telse\n\t\terr = tcf_ct_ipv6_is_fragment(skb, \u0026frag);\n\tif (err || !frag)\n\t\treturn err;\n\ntcf_ct_ipv4_is_fragment() returns -EINVAL or -ENOMEM;\ntcf_ct_ipv6_is_fragment() adds -EPROTO when ipv6_find_hdr() fails. None of\nthem frees or queues the skb, so on that path the caller still owns it.\n\ntcf_ct_act() however funnels every non-zero return into the\nownership-transfer exit:\n\n\terr = tcf_ct_handle_fragments(net, skb, family, p-\u003ezone, \u0026defrag);\n\tif (err)\n\t\tgoto out_frag;\n\t...\nout_frag:\n\tif (err != -EINPROGRESS)\n\t\ttcf_action_inc_drop_qstats(\u0026c-\u003ecommon);\n\treturn TC_ACT_CONSUMED;\n\nTC_ACT_CONSUMED means the action took ownership of the skb, so no caller\nfrees it - sch_handle_ingress(), sch_handle_egress() and\ntcf_qevent_handle() all deliberately skip the free for that verdict. The\nskb is therefore orphaned: one sk_buff plus its data buffer is leaked per\nmalformed packet, unbounded. Note the drop counter is already incremented\nfor these errors, so the statistics claim a drop that never happens.\n\nThree different ownership states reach out_frag: today - the skb may be\nqueued by the defrag engine (-EINPROGRESS), already freed by\nnf_ct_handle_fragments(), or still owned by us. Tell the caller which of\nthose it is, and free the packet ourselves in the last case, which\nrestores the TC_ACT_SHOT behaviour that predated the Fixes: commit.\n\nReproduced on v7.2-rc6 with a 54-byte frame carrying a 40-byte IPv6\nheader with nexthdr = 0 (hop-by-hop) and nothing after it, on a\nclsact ingress chain with \"action ct\". kmemleak reports one leaked\n232-byte skbuff_head_cache object plus its 704-byte data buffer per\npacket; with this patch it reports none."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The leak is triggered in tcf_ct_act() on the packet datapath (netif_receive_skb \u2192 sch_handle_ingress/egress \u2192 tc_run \u2192 tcf_classify); on OVN/Kubernetes/SDN gateways and mlx5-offload nodes with act_ct on clsact, a remote peer sends malformed IP packets with no local access required.\nAC:L - The attacker fully controls packet contents; a 54-byte IPv6 frame with nexthdr=0 (hop-by-hop) and no trailing data deterministically makes ipv6_find_hdr() return -EPROTO, leaking one skb per packet without races or uncontrollable layout dependencies.\nPR:N - Installing act_ct requires CAP_NET_ADMIN, but triggering the leak on an already-configured internet-facing or tenant-facing gateway needs no target credentials; a remote attacker only sends crafted malformed IP packets, matching CNA precedent for packet-driven act_ct issues (e.g., CVE-2026-72057).\nUI:N - Exploitation requires only attacker-generated malformed packets reaching a host with act_ct on clsact/ingress or egress; no victim login, mount, or other interactive action is needed beyond normal network traffic processing.\nS:U - The leaked sk_buff objects remain within the host kernel memory domain; this is not a VM escape, sandbox breakout, or IOMMU boundary bypass, only unbounded kernel heap consumption on the affected node.\nC:N - This is a pure sk_buff ownership leak on an error path; skb memory is orphaned, not exposed to the attacker, with no out-of-bounds read, use-after-free, or other disclosure primitive.\nI:N - The flaw only fails to kfree_skb() when header validation rejects a packet; it does not corrupt, overwrite, or modify any memory contents and provides no write or code-execution primitive.\nA:H - Each malformed packet leaks one sk_buff plus its data buffer (~936 bytes); sustained remote flooding causes unbounded kernel memory exhaustion and OOM denial of service, matching CNA precedent for repeatable network-triggered skb leaks (e.g., CVE-2026-52974)."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:40:45.894Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b5dbecc2016e1692fd1c2532af9c41ba729cb747"
},
{
"url": "https://git.kernel.org/stable/c/23e97d594ddd0153020c506d5041048fbde1beb4"
},
{
"url": "https://git.kernel.org/stable/c/737873a59905a54ca0d2d127ef882f3f88bf4379"
},
{
"url": "https://git.kernel.org/stable/c/47d99828591d0fe8be4b9c8992ff3b8e47968db9"
},
{
"url": "https://git.kernel.org/stable/c/b47bb899e04b5407c5a63fe88d4b6676586a6e84"
},
{
"url": "https://git.kernel.org/stable/c/439d3e404f9d5e515911cc8132cde198b337c19e"
},
{
"url": "https://git.kernel.org/stable/c/8a7ed561671aa6a911a2de99e59ef670a4d0b1df"
}
],
"title": "net/sched: act_ct: fix sk_buff leak when the header checks reject a packet",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74621",
"datePublished": "2026-08-22T15:32:04.990Z",
"dateReserved": "2026-08-15T05:44:03.921Z",
"dateUpdated": "2026-08-25T05:40:45.894Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74730 (GCVE-0-2026-74730)
Vulnerability from cvelistv5
Published
2026-08-22 15:33
Modified
2026-08-25 05:42
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
NFS: Pin the 'struct nfs_server' during a FREE_STATEID call
Dan Aloni reports that he was able to hit a use-after-free bug if a
FREE_STATEID operation gets delayed for whatever reason. Fix this by
bumping the refcount of the 'struct nfs_server' object for the duration
of the FREE_STATEID so it doesn't get cleaned up from underneath us
while operations are still in flight.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 7c1d5fae4a87d3cf3e9ffd68bcdbaf6529013009 Version: 7c1d5fae4a87d3cf3e9ffd68bcdbaf6529013009 Version: 7c1d5fae4a87d3cf3e9ffd68bcdbaf6529013009 Version: 7c1d5fae4a87d3cf3e9ffd68bcdbaf6529013009 Version: 7c1d5fae4a87d3cf3e9ffd68bcdbaf6529013009 Version: 7c1d5fae4a87d3cf3e9ffd68bcdbaf6529013009 Version: 7c1d5fae4a87d3cf3e9ffd68bcdbaf6529013009 Version: 7c1d5fae4a87d3cf3e9ffd68bcdbaf6529013009 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/nfs/nfs4proc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ed2f92ce2fc48463c41e0e540b9a3454889e8af8",
"status": "affected",
"version": "7c1d5fae4a87d3cf3e9ffd68bcdbaf6529013009",
"versionType": "git"
},
{
"lessThan": "d858ab09e787106432d4d9830bad9dfedf02f890",
"status": "affected",
"version": "7c1d5fae4a87d3cf3e9ffd68bcdbaf6529013009",
"versionType": "git"
},
{
"lessThan": "af62f1af182d33a0de38308c012841885d8ab92e",
"status": "affected",
"version": "7c1d5fae4a87d3cf3e9ffd68bcdbaf6529013009",
"versionType": "git"
},
{
"lessThan": "caee6a68ffaa5016dfc01cd0b3dc1896a32e3abd",
"status": "affected",
"version": "7c1d5fae4a87d3cf3e9ffd68bcdbaf6529013009",
"versionType": "git"
},
{
"lessThan": "ed1161ab6239761958b38d5667225634fc2be894",
"status": "affected",
"version": "7c1d5fae4a87d3cf3e9ffd68bcdbaf6529013009",
"versionType": "git"
},
{
"lessThan": "d71dfffa512e71b166a889484e4c3b148a9a3af2",
"status": "affected",
"version": "7c1d5fae4a87d3cf3e9ffd68bcdbaf6529013009",
"versionType": "git"
},
{
"lessThan": "80ed3d762628b36c9e4b22fac7c65b72ef3b13dd",
"status": "affected",
"version": "7c1d5fae4a87d3cf3e9ffd68bcdbaf6529013009",
"versionType": "git"
},
{
"lessThan": "cf616096a0f3a2b60f7d68b6b39674a6867ded9c",
"status": "affected",
"version": "7c1d5fae4a87d3cf3e9ffd68bcdbaf6529013009",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/nfs/nfs4proc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.10"
},
{
"lessThan": "3.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nNFS: Pin the \u0027struct nfs_server\u0027 during a FREE_STATEID call\n\nDan Aloni reports that he was able to hit a use-after-free bug if a\nFREE_STATEID operation gets delayed for whatever reason. Fix this by\nbumping the refcount of the \u0027struct nfs_server\u0027 object for the duration\nof the FREE_STATEID so it doesn\u0027t get cleaned up from underneath us\nwhile operations are still in flight."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug is in the NFSv4 client FREE_STATEID path: nfs41_free_stateid_prepare/done/release use a freed struct nfs_server while handling async RPC completions driven by NFSv4 replies from the mounted server and by server-initiated CB_RECALL/CB_RECALLANY callbacks on the NFS backchannel.\nAC:L - The attacker controls both sides of the race: they provoke FREE_STATEID via revocation responses or callbacks, keep it in flight with NFS4ERR_DELAY, and time nfs_server teardown via user-mount umount, automount idle expiry, or the concurrent stateid cleanup that runs during umount itself.\nPR:N - A malicious or compromised NFSv4 server needs no account or elevated capability on the victim client once an NFSv4.1+ mount exists; FREE_STATEID is issued automatically during server-driven stateid revocation handling without any client-side privileges at exploit time.\nUI:N - After an NFS mount exists (boot-time, autofs, or Kubernetes volumes are common), no further victim action is needed: the attacker drives recall/revocation on the wire and mount teardown follows from automated autofs expiry or attacker-controlled umount on a user-mounted export.\nS:U - The use-after-free corrupts kernel heap within the NFS client on the same host; it is a standard kernel memory-safety bug, not a VM escape, container breakout, or IOMMU/DMA boundary crossing.\nC:H - Freed struct nfs_server objects are kmalloc\u0027d and callbacks dereference nfs_client, rpc_clnt, and super_block fields after nfs_free_server/call_rcu, giving a classic UAF read primitive over attacker-influenced heap contents including function pointers.\nI:H - UAF on struct nfs_server exposes destroy hooks, RPC client handles, and client/session state pointers that an attacker can reschedule via heap grooming, yielding write and control-flow primitives typical of NFS client heap corruption bugs.\nA:H - Use of a freed nfs_server in RPC prepare/done/release paths causes kernel oops or panic; Dan Aloni demonstrated reliable reproduction, and UAFs in this path crash hosts even when not fully weaponized."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:42:09.527Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ed2f92ce2fc48463c41e0e540b9a3454889e8af8"
},
{
"url": "https://git.kernel.org/stable/c/d858ab09e787106432d4d9830bad9dfedf02f890"
},
{
"url": "https://git.kernel.org/stable/c/af62f1af182d33a0de38308c012841885d8ab92e"
},
{
"url": "https://git.kernel.org/stable/c/caee6a68ffaa5016dfc01cd0b3dc1896a32e3abd"
},
{
"url": "https://git.kernel.org/stable/c/ed1161ab6239761958b38d5667225634fc2be894"
},
{
"url": "https://git.kernel.org/stable/c/d71dfffa512e71b166a889484e4c3b148a9a3af2"
},
{
"url": "https://git.kernel.org/stable/c/80ed3d762628b36c9e4b22fac7c65b72ef3b13dd"
},
{
"url": "https://git.kernel.org/stable/c/cf616096a0f3a2b60f7d68b6b39674a6867ded9c"
}
],
"title": "NFS: Pin the \u0027struct nfs_server\u0027 during a FREE_STATEID call",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74730",
"datePublished": "2026-08-22T15:33:19.659Z",
"dateReserved": "2026-08-15T05:44:03.930Z",
"dateUpdated": "2026-08-25T05:42:09.527Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74659 (GCVE-0-2026-74659)
Vulnerability from cvelistv5
Published
2026-08-22 15:32
Modified
2026-08-22 15:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: bridge: mrp: fix uninitialised bytes on the wire
br_mrp_alloc_test_skb() builds MRP test frames on an skb from
dev_alloc_skb(), which does not clear the linear data area. On the MRA
ring-role branch the sub-option TLV header is appended with
sub_tlv = skb_put(skb, sizeof(*sub_tlv));
sub_tlv->type = BR_MRP_SUB_TLV_HEADER_TEST_AUTO_MGR;
so sub_tlv->length is never written, and the two trailing alignment bytes
are appended with a bare skb_put() that does not clear them either. The
neighbouring oui and sub_opt regions are explicitly zeroed, so three
uninitialised bytes are left in every MRA MRP_Test frame that goes out.
Put the sub-option TLV header and the alignment padding in a single
skb_put_zero(), which clears both. The AUTO_MGR sub-TLV carries no
payload, so the zeroed length field is already the value it should have.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: f7458934b0791c39a001e4d902fc3bf697b439b5 Version: f7458934b0791c39a001e4d902fc3bf697b439b5 Version: f7458934b0791c39a001e4d902fc3bf697b439b5 Version: f7458934b0791c39a001e4d902fc3bf697b439b5 Version: f7458934b0791c39a001e4d902fc3bf697b439b5 Version: f7458934b0791c39a001e4d902fc3bf697b439b5 Version: f7458934b0791c39a001e4d902fc3bf697b439b5 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/bridge/br_mrp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "014c062d23c63ec77ef2cf17a0d9363c7441cc94",
"status": "affected",
"version": "f7458934b0791c39a001e4d902fc3bf697b439b5",
"versionType": "git"
},
{
"lessThan": "7ebc23ff03668042e0b0e4034bb1518d36198d9e",
"status": "affected",
"version": "f7458934b0791c39a001e4d902fc3bf697b439b5",
"versionType": "git"
},
{
"lessThan": "06d58b8d2f053ced82e01efaeb6e7c82891eed58",
"status": "affected",
"version": "f7458934b0791c39a001e4d902fc3bf697b439b5",
"versionType": "git"
},
{
"lessThan": "a5e385eeb2d6dbbbdebfa050e67c34734ae12693",
"status": "affected",
"version": "f7458934b0791c39a001e4d902fc3bf697b439b5",
"versionType": "git"
},
{
"lessThan": "5912cf1822fbe53ae275c147868740eb384a5d3e",
"status": "affected",
"version": "f7458934b0791c39a001e4d902fc3bf697b439b5",
"versionType": "git"
},
{
"lessThan": "e08665218040f8e312abe40f74543186f3c2c941",
"status": "affected",
"version": "f7458934b0791c39a001e4d902fc3bf697b439b5",
"versionType": "git"
},
{
"lessThan": "63488dba65ef91373ef616575b32eb0eb21459f4",
"status": "affected",
"version": "f7458934b0791c39a001e4d902fc3bf697b439b5",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/bridge/br_mrp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.14"
},
{
"lessThan": "5.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: bridge: mrp: fix uninitialised bytes on the wire\n\nbr_mrp_alloc_test_skb() builds MRP test frames on an skb from\ndev_alloc_skb(), which does not clear the linear data area. On the MRA\nring-role branch the sub-option TLV header is appended with\n\n\tsub_tlv = skb_put(skb, sizeof(*sub_tlv));\n\tsub_tlv-\u003etype = BR_MRP_SUB_TLV_HEADER_TEST_AUTO_MGR;\n\nso sub_tlv-\u003elength is never written, and the two trailing alignment bytes\nare appended with a bare skb_put() that does not clear them either. The\nneighbouring oui and sub_opt regions are explicitly zeroed, so three\nuninitialised bytes are left in every MRA MRP_Test frame that goes out.\n\nPut the sub-option TLV header and the alignment padding in a single\nskb_put_zero(), which clears both. The AUTO_MGR sub-TLV carries no\npayload, so the zeroed length field is already the value it should have."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-22T15:32:32.926Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/014c062d23c63ec77ef2cf17a0d9363c7441cc94"
},
{
"url": "https://git.kernel.org/stable/c/7ebc23ff03668042e0b0e4034bb1518d36198d9e"
},
{
"url": "https://git.kernel.org/stable/c/06d58b8d2f053ced82e01efaeb6e7c82891eed58"
},
{
"url": "https://git.kernel.org/stable/c/a5e385eeb2d6dbbbdebfa050e67c34734ae12693"
},
{
"url": "https://git.kernel.org/stable/c/5912cf1822fbe53ae275c147868740eb384a5d3e"
},
{
"url": "https://git.kernel.org/stable/c/e08665218040f8e312abe40f74543186f3c2c941"
},
{
"url": "https://git.kernel.org/stable/c/63488dba65ef91373ef616575b32eb0eb21459f4"
}
],
"title": "net: bridge: mrp: fix uninitialised bytes on the wire",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74659",
"datePublished": "2026-08-22T15:32:32.926Z",
"dateReserved": "2026-08-15T05:44:03.924Z",
"dateUpdated": "2026-08-22T15:32:32.926Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74598 (GCVE-0-2026-74598)
Vulnerability from cvelistv5
Published
2026-08-22 15:31
Modified
2026-08-25 05:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ipv6: fix Route Information option length validation
rt6_route_rcv() validates the Route Information option (RFC 4191) length
against the prefix length, but both checks are off by one.
rinfo->length is the ND option length in units of 8 octets and it
*includes* the 8-byte option header, so an option carrying N bytes of
prefix has length == 1 + N/8. RFC 4191 section 2.3 requires length 3
when Prefix Length is greater than 64, and 2 or 3 when it is greater
than 0. The code accepts length >= 2 and length >= 1 respectively.
ipv6_addr_prefix() then copies prefix_len/8 bytes out of rinfo->prefix,
so a Router Advertisement with (prefix_len=128, length=2) or
(prefix_len=64, length=1) makes the kernel read up to 8 bytes past the
end of the option. Those bytes end up in the prefix of the route that
gets installed, so they are visible to userspace:
# RA with a Route Information option (prefix_len=128, length=2)
# followed by a source link-layer address option, 01 01 de ad be ef ca fe
$ ip -6 route show
2001:db8:dead:beef:101:dead:beef:cafe via fe80::1234 dev veth0 proto ra
^^^^^^^^^^^^^^^^^^ the next option, read out of bounds
When the Route Information option is the last one in the packet, those
eight bytes come from the skb tail room instead.
Reject the option lengths RFC 4191 does not allow.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 70ceb4f53929f73746be72f73707cd9f8753e2fc Version: 70ceb4f53929f73746be72f73707cd9f8753e2fc Version: 70ceb4f53929f73746be72f73707cd9f8753e2fc Version: 70ceb4f53929f73746be72f73707cd9f8753e2fc Version: 70ceb4f53929f73746be72f73707cd9f8753e2fc Version: 70ceb4f53929f73746be72f73707cd9f8753e2fc Version: 70ceb4f53929f73746be72f73707cd9f8753e2fc Version: 70ceb4f53929f73746be72f73707cd9f8753e2fc |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ipv6/route.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "2f6f94eda12430fb41b24b44a71e2ea4e93561d7",
"status": "affected",
"version": "70ceb4f53929f73746be72f73707cd9f8753e2fc",
"versionType": "git"
},
{
"lessThan": "7eac87396c44a312be457ef41d4c5687883be9a2",
"status": "affected",
"version": "70ceb4f53929f73746be72f73707cd9f8753e2fc",
"versionType": "git"
},
{
"lessThan": "7309529f257ae18e72112ef9f614edfd6df229bb",
"status": "affected",
"version": "70ceb4f53929f73746be72f73707cd9f8753e2fc",
"versionType": "git"
},
{
"lessThan": "0b9e02f3bd31c888f2ccdc0ca08e546d6abe9c4d",
"status": "affected",
"version": "70ceb4f53929f73746be72f73707cd9f8753e2fc",
"versionType": "git"
},
{
"lessThan": "ff3cb05289b8a4ef95fa7ea14c7d34818359edbb",
"status": "affected",
"version": "70ceb4f53929f73746be72f73707cd9f8753e2fc",
"versionType": "git"
},
{
"lessThan": "3b2231e358d26e3aec5d8040b1fb777af03c5f05",
"status": "affected",
"version": "70ceb4f53929f73746be72f73707cd9f8753e2fc",
"versionType": "git"
},
{
"lessThan": "da64ed1f346ba84df574d6469fa2e422b2511719",
"status": "affected",
"version": "70ceb4f53929f73746be72f73707cd9f8753e2fc",
"versionType": "git"
},
{
"lessThan": "d1ad8fb2ac6a1afb71dc22d9ae8efb4dda96c824",
"status": "affected",
"version": "70ceb4f53929f73746be72f73707cd9f8753e2fc",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ipv6/route.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.17"
},
{
"lessThan": "2.6.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "2.6.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "2.6.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "2.6.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "2.6.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.17",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: fix Route Information option length validation\n\nrt6_route_rcv() validates the Route Information option (RFC 4191) length\nagainst the prefix length, but both checks are off by one.\n\nrinfo-\u003elength is the ND option length in units of 8 octets and it\n*includes* the 8-byte option header, so an option carrying N bytes of\nprefix has length == 1 + N/8. RFC 4191 section 2.3 requires length 3\nwhen Prefix Length is greater than 64, and 2 or 3 when it is greater\nthan 0. The code accepts length \u003e= 2 and length \u003e= 1 respectively.\n\nipv6_addr_prefix() then copies prefix_len/8 bytes out of rinfo-\u003eprefix,\nso a Router Advertisement with (prefix_len=128, length=2) or\n(prefix_len=64, length=1) makes the kernel read up to 8 bytes past the\nend of the option. Those bytes end up in the prefix of the route that\ngets installed, so they are visible to userspace:\n\n # RA with a Route Information option (prefix_len=128, length=2)\n # followed by a source link-layer address option, 01 01 de ad be ef ca fe\n $ ip -6 route show\n 2001:db8:dead:beef:101:dead:beef:cafe via fe80::1234 dev veth0 proto ra\n ^^^^^^^^^^^^^^^^^^ the next option, read out of bounds\n\nWhen the Route Information option is the last one in the packet, those\neight bytes come from the skb tail room instead.\n\nReject the option lengths RFC 4191 does not allow."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The flaw is reached from inbound ICMPv6 Router Advertisements on the standard IPv6 receive path (ip6_input\u2192icmpv6_rcv\u2192ndisc_rcv\u2192ndisc_router_discovery\u2192rt6_route_rcv), so a network peer can trigger it on hosts accepting RAs (phones, laptops, IoT, containers on shared L2).\nAC:L - Once the victim accepts non-zero Route Information prefixes, an attacker fully controls prefix_len and option length in forged RAs and can deterministically trigger the out-of-bounds read (up to 8 bytes) without races or uncontrollable memory layout.\nPR:N - Exploitation requires only sending crafted ICMPv6 RAs on the victim\u0027s link; the attacker needs no account, capabilities, or init-namespace root on the target, only the ability to inject ND traffic the host will process.\nUI:N - No victim user action is required beyond normal IPv6 connectivity; RA/Route Information processing runs automatically in the kernel when accept_ra and related sysctls permit it.\nS:U - Impact is confined to kernel IPv6 routing state leaking into the same host\u0027s userspace route table; it does not cross VM, container, or IOMMU security boundaries into a separate authority.\nC:H - ipv6_addr_prefix() performs an out-of-bounds read of up to eight bytes past the Route Information option (from following ND options or skb tailroom), and those kernel bytes are stored in the installed route prefix visible to userspace via netlink or ip -6 route.\nI:N - The bug is a bounded out-of-bounds read into a stack buffer followed by route installation; it does not corrupt kernel memory, enable arbitrary writes, or provide a demonstrated control-flow hijack primitive.\nA:N - The vulnerable path only mis-handles prefix extraction and installs a route with leaked bytes; it does not cause kernel oops, panic, hang, or demonstrated denial of service beyond incorrect route data."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:40:24.953Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/2f6f94eda12430fb41b24b44a71e2ea4e93561d7"
},
{
"url": "https://git.kernel.org/stable/c/7eac87396c44a312be457ef41d4c5687883be9a2"
},
{
"url": "https://git.kernel.org/stable/c/7309529f257ae18e72112ef9f614edfd6df229bb"
},
{
"url": "https://git.kernel.org/stable/c/0b9e02f3bd31c888f2ccdc0ca08e546d6abe9c4d"
},
{
"url": "https://git.kernel.org/stable/c/ff3cb05289b8a4ef95fa7ea14c7d34818359edbb"
},
{
"url": "https://git.kernel.org/stable/c/3b2231e358d26e3aec5d8040b1fb777af03c5f05"
},
{
"url": "https://git.kernel.org/stable/c/da64ed1f346ba84df574d6469fa2e422b2511719"
},
{
"url": "https://git.kernel.org/stable/c/d1ad8fb2ac6a1afb71dc22d9ae8efb4dda96c824"
}
],
"title": "ipv6: fix Route Information option length validation",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74598",
"datePublished": "2026-08-22T15:31:47.859Z",
"dateReserved": "2026-08-15T05:44:03.919Z",
"dateUpdated": "2026-08-25T05:40:24.953Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74693 (GCVE-0-2026-74693)
Vulnerability from cvelistv5
Published
2026-08-22 15:32
Modified
2026-08-22 15:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: prestera: validate firmware header length
prestera_fw_hdr_parse() reads the firmware header before checking
that the firmware image contains that header.
Reject images shorter than struct prestera_fw_header before decoding the
magic and version fields.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 4c2703dfd7fabb0824b3bc345f9fa47e33248c14 Version: 4c2703dfd7fabb0824b3bc345f9fa47e33248c14 Version: 4c2703dfd7fabb0824b3bc345f9fa47e33248c14 Version: 4c2703dfd7fabb0824b3bc345f9fa47e33248c14 Version: 4c2703dfd7fabb0824b3bc345f9fa47e33248c14 Version: 4c2703dfd7fabb0824b3bc345f9fa47e33248c14 Version: 4c2703dfd7fabb0824b3bc345f9fa47e33248c14 Version: 4c2703dfd7fabb0824b3bc345f9fa47e33248c14 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/marvell/prestera/prestera_pci.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "38a3afbf9fd8a2e8c47fa3ca47b425a8a9623240",
"status": "affected",
"version": "4c2703dfd7fabb0824b3bc345f9fa47e33248c14",
"versionType": "git"
},
{
"lessThan": "0fbcceb9d19f2d1dcdf099aee590f2517cb718bb",
"status": "affected",
"version": "4c2703dfd7fabb0824b3bc345f9fa47e33248c14",
"versionType": "git"
},
{
"lessThan": "e0f382e8084117f0b11ffb070fe1079e38c0d7f9",
"status": "affected",
"version": "4c2703dfd7fabb0824b3bc345f9fa47e33248c14",
"versionType": "git"
},
{
"lessThan": "6fad06bb793d7089ae05b9fcf46e11be2dfe4850",
"status": "affected",
"version": "4c2703dfd7fabb0824b3bc345f9fa47e33248c14",
"versionType": "git"
},
{
"lessThan": "470ac9cce7308e60cf2dceb448749cdd006e73de",
"status": "affected",
"version": "4c2703dfd7fabb0824b3bc345f9fa47e33248c14",
"versionType": "git"
},
{
"lessThan": "363e048a9d0a6c245cbc348c8a220170afed046a",
"status": "affected",
"version": "4c2703dfd7fabb0824b3bc345f9fa47e33248c14",
"versionType": "git"
},
{
"lessThan": "7fa8a12296d8d5aa4b1c3904f0b354d81124cf29",
"status": "affected",
"version": "4c2703dfd7fabb0824b3bc345f9fa47e33248c14",
"versionType": "git"
},
{
"lessThan": "8ae344eb540af3f457179b52bc6061416752485c",
"status": "affected",
"version": "4c2703dfd7fabb0824b3bc345f9fa47e33248c14",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/marvell/prestera/prestera_pci.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.10"
},
{
"lessThan": "5.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: prestera: validate firmware header length\n\nprestera_fw_hdr_parse() reads the firmware header before checking\nthat the firmware image contains that header.\n\nReject images shorter than struct prestera_fw_header before decoding the\nmagic and version fields."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-22T15:32:56.491Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/38a3afbf9fd8a2e8c47fa3ca47b425a8a9623240"
},
{
"url": "https://git.kernel.org/stable/c/0fbcceb9d19f2d1dcdf099aee590f2517cb718bb"
},
{
"url": "https://git.kernel.org/stable/c/e0f382e8084117f0b11ffb070fe1079e38c0d7f9"
},
{
"url": "https://git.kernel.org/stable/c/6fad06bb793d7089ae05b9fcf46e11be2dfe4850"
},
{
"url": "https://git.kernel.org/stable/c/470ac9cce7308e60cf2dceb448749cdd006e73de"
},
{
"url": "https://git.kernel.org/stable/c/363e048a9d0a6c245cbc348c8a220170afed046a"
},
{
"url": "https://git.kernel.org/stable/c/7fa8a12296d8d5aa4b1c3904f0b354d81124cf29"
},
{
"url": "https://git.kernel.org/stable/c/8ae344eb540af3f457179b52bc6061416752485c"
}
],
"title": "net: prestera: validate firmware header length",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74693",
"datePublished": "2026-08-22T15:32:56.491Z",
"dateReserved": "2026-08-15T05:44:03.926Z",
"dateUpdated": "2026-08-22T15:32:56.491Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68124 (GCVE-0-2026-68124)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-19 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
mctp: serial: handle zero-length frames to prevent rx buffer overflow
The MCTP serial receive state machine reads a frame length byte in
mctp_serial_push_header() case 2 and validates it upper-bound-only:
if (c > MCTP_SERIAL_FRAME_MTU) {
dev->rxstate = STATE_ERR;
} else {
dev->rxlen = c;
dev->rxpos = 0;
dev->rxstate = STATE_DATA;
...
}
A length of zero passes this check, so rxlen is set to 0 and the state
machine advances to STATE_DATA. In mctp_serial_push() STATE_DATA, the
incoming byte is stored and rxpos incremented before the terminator is
dev->rxbuf[dev->rxpos] = c;
dev->rxpos++;
dev->rxstate = STATE_DATA;
if (dev->rxpos == dev->rxlen) {
dev->rxpos = 0;
dev->rxstate = STATE_TRAILER;
}
With rxlen == 0 the "rxpos == rxlen" terminator can never fire (rxpos is
already 1 on the first data byte), so subsequent bytes are written past
the end of the fixed 74-byte rxbuf, which is the last member of the
netdev private area. Every following data byte is an attacker-controlled
1-byte out-of-bounds heap write, and the overflow continues until a
frame (0x7e) or escape byte resets the parser -- effectively unbounded.
Reaching this requires CAP_NET_ADMIN to attach the N_MCTP line
discipline and bring the resulting mctpserialN netdev up, after which
the bytes arrive via the tty receive path.
Route a zero-length frame straight to STATE_TRAILER instead of
STATE_DATA. The trailer/framing bytes are still consumed, and the frame
resolves to a zero-length skb that the MCTP core rejects; the parser
never enters STATE_DATA with rxlen == 0, so the out-of-bounds write can
no longer occur.
KASAN, on a frame of 0x7e 0x01 0x00 followed by data bytes (before this
change):
UBSAN: array-index-out-of-bounds in drivers/net/mctp/mctp-serial.c:370
index 74 is out of range for type 'u8 [74]'
BUG: KASAN: slab-out-of-bounds in mctp_serial_tty_receive_buf
Write of size 1 at addr ... by task kworker/u16:0
mctp_serial_tty_receive_buf
tty_ldisc_receive_buf
flush_to_ldisc
Allocated by task 152:
alloc_netdev_mqs
mctp_serial_open
v2: route zero-length frames to STATE_TRAILER instead of STATE_ERR so
the trailer/framing bytes are still consumed (Jeremy Kerr).
Found by 0sec automated security-research tooling (https://0sec.ai).
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: a0c2ccd9b5ad0a9e838158404e041b5a8ff762dd Version: a0c2ccd9b5ad0a9e838158404e041b5a8ff762dd Version: a0c2ccd9b5ad0a9e838158404e041b5a8ff762dd Version: a0c2ccd9b5ad0a9e838158404e041b5a8ff762dd Version: a0c2ccd9b5ad0a9e838158404e041b5a8ff762dd Version: a0c2ccd9b5ad0a9e838158404e041b5a8ff762dd |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/mctp/mctp-serial.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "64b96ae7912244d55257aa330d9569ee0a8f8d99",
"status": "affected",
"version": "a0c2ccd9b5ad0a9e838158404e041b5a8ff762dd",
"versionType": "git"
},
{
"lessThan": "36dc6d6964a3b90411cc7944cd9b8b6f67b9807b",
"status": "affected",
"version": "a0c2ccd9b5ad0a9e838158404e041b5a8ff762dd",
"versionType": "git"
},
{
"lessThan": "68819427bc07eca7963a9e8be19e5272cc29186c",
"status": "affected",
"version": "a0c2ccd9b5ad0a9e838158404e041b5a8ff762dd",
"versionType": "git"
},
{
"lessThan": "f80ba170d7b3a44e3d244a2c8e06031d61bf3b23",
"status": "affected",
"version": "a0c2ccd9b5ad0a9e838158404e041b5a8ff762dd",
"versionType": "git"
},
{
"lessThan": "06a6b606129c8a25cd457760f5370f3ff01fe05d",
"status": "affected",
"version": "a0c2ccd9b5ad0a9e838158404e041b5a8ff762dd",
"versionType": "git"
},
{
"lessThan": "793b9b729f1e8de57be8c8daf1a9838be96cabed",
"status": "affected",
"version": "a0c2ccd9b5ad0a9e838158404e041b5a8ff762dd",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/mctp/mctp-serial.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.17"
},
{
"lessThan": "5.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.17",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmctp: serial: handle zero-length frames to prevent rx buffer overflow\n\nThe MCTP serial receive state machine reads a frame length byte in\nmctp_serial_push_header() case 2 and validates it upper-bound-only:\n\n\tif (c \u003e MCTP_SERIAL_FRAME_MTU) {\n\t\tdev-\u003erxstate = STATE_ERR;\n\t} else {\n\t\tdev-\u003erxlen = c;\n\t\tdev-\u003erxpos = 0;\n\t\tdev-\u003erxstate = STATE_DATA;\n\t\t...\n\t}\n\nA length of zero passes this check, so rxlen is set to 0 and the state\nmachine advances to STATE_DATA. In mctp_serial_push() STATE_DATA, the\nincoming byte is stored and rxpos incremented before the terminator is\n\n\tdev-\u003erxbuf[dev-\u003erxpos] = c;\n\tdev-\u003erxpos++;\n\tdev-\u003erxstate = STATE_DATA;\n\tif (dev-\u003erxpos == dev-\u003erxlen) {\n\t\tdev-\u003erxpos = 0;\n\t\tdev-\u003erxstate = STATE_TRAILER;\n\t}\n\nWith rxlen == 0 the \"rxpos == rxlen\" terminator can never fire (rxpos is\nalready 1 on the first data byte), so subsequent bytes are written past\nthe end of the fixed 74-byte rxbuf, which is the last member of the\nnetdev private area. Every following data byte is an attacker-controlled\n1-byte out-of-bounds heap write, and the overflow continues until a\nframe (0x7e) or escape byte resets the parser -- effectively unbounded.\n\nReaching this requires CAP_NET_ADMIN to attach the N_MCTP line\ndiscipline and bring the resulting mctpserialN netdev up, after which\nthe bytes arrive via the tty receive path.\n\nRoute a zero-length frame straight to STATE_TRAILER instead of\nSTATE_DATA. The trailer/framing bytes are still consumed, and the frame\nresolves to a zero-length skb that the MCTP core rejects; the parser\nnever enters STATE_DATA with rxlen == 0, so the out-of-bounds write can\nno longer occur.\n\nKASAN, on a frame of 0x7e 0x01 0x00 followed by data bytes (before this\nchange):\n\n UBSAN: array-index-out-of-bounds in drivers/net/mctp/mctp-serial.c:370\n index 74 is out of range for type \u0027u8 [74]\u0027\n BUG: KASAN: slab-out-of-bounds in mctp_serial_tty_receive_buf\n Write of size 1 at addr ... by task kworker/u16:0\n mctp_serial_tty_receive_buf\n tty_ldisc_receive_buf\n flush_to_ldisc\n Allocated by task 152:\n alloc_netdev_mqs\n mctp_serial_open\n\nv2: route zero-length frames to STATE_TRAILER instead of STATE_ERR so\n the trailer/framing bytes are still consumed (Jeremy Kerr).\n\nFound by 0sec automated security-research tooling (https://0sec.ai)."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.6,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The bug is triggered in mctp_serial_tty_receive_buf() by crafted DSP0253 serial frames; on BMC/datacenter systems MCTP-over-serial links management controllers on a shared management LAN, letting an adjacent unauthenticated peer inject 0x7e/0x01/0x00 frames without using host syscalls.\nAC:L - Exploitation is deterministic: a zero-length length byte bypasses the upper-bound check, then each following serial byte is a controlled 1-byte heap OOB write until 0x7e/0x7d resets the parser; no races or attacker-uncontrollable memory layout are required.\nPR:N - Triggering the overflow only requires delivering malicious serial bytes to an already-configured, running mctpserial netdev; a remote/adjacent MCTP peer or compromised management controller needs no Linux host credentials, CAP_NET_ADMIN, or root on the victim.\nUI:N - No victim user action is required at exploit time; administrative enablement of MCTP serial is deployment configuration, not end-user interaction under CVSS.\nS:C - Kconfig documents virtio-serial VM interconnect for MCTP serial; a malicious guest sending crafted frames to the host-side mctpserial binding can corrupt host kernel heap memory, crossing the guest/host virtualization security boundary.\nC:H - Each overflow byte is attacker-controlled and the write stream is effectively unbounded past the 74-byte rxbuf (last netdev private field), enabling slab-out-of-bounds corruption that can be leveraged for arbitrary kernel memory disclosure.\nI:H - Sustained attacker-controlled out-of-bounds heap writes can corrupt adjacent kmalloc objects, function pointers, and netdev state, providing a standard path to arbitrary kernel write and privilege-escalating code execution.\nA:H - KASAN/UBSAN report slab-out-of-bounds and array-index-out-of-bounds in mctp_serial_tty_receive_buf via flush_to_ldisc; continued overflow reliably causes kernel oops/panic or hang during tty receive processing."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:29:36.851Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/64b96ae7912244d55257aa330d9569ee0a8f8d99"
},
{
"url": "https://git.kernel.org/stable/c/36dc6d6964a3b90411cc7944cd9b8b6f67b9807b"
},
{
"url": "https://git.kernel.org/stable/c/68819427bc07eca7963a9e8be19e5272cc29186c"
},
{
"url": "https://git.kernel.org/stable/c/f80ba170d7b3a44e3d244a2c8e06031d61bf3b23"
},
{
"url": "https://git.kernel.org/stable/c/06a6b606129c8a25cd457760f5370f3ff01fe05d"
},
{
"url": "https://git.kernel.org/stable/c/793b9b729f1e8de57be8c8daf1a9838be96cabed"
}
],
"title": "mctp: serial: handle zero-length frames to prevent rx buffer overflow",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68124",
"datePublished": "2026-08-10T11:58:44.997Z",
"dateReserved": "2026-07-30T09:28:09.369Z",
"dateUpdated": "2026-08-19T16:29:36.851Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74567 (GCVE-0-2026-74567)
Vulnerability from cvelistv5
Published
2026-08-15 12:28
Modified
2026-08-19 16:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
keys: fix out-of-bounds read in keyring_get_key_chunk()
For description-level chunks keyring_get_key_chunk() advances the read
pointer by level * sizeof(long) past the inline prefix but only
bounds-checks the prefix, so a long enough key description is read past
its kmemdup(desc, desc_len + 1) allocation. Compute the full byte
offset and bounds-check the description against it before reading.
The walk only reaches a description-level chunk when two keys collide
through the hash, x, type and domain_tag chunks, so this is reached from
an unprivileged add_key(2) with a crafted pair of same-type keys whose
index hashes collide; KASAN reports a slab-out-of-bounds read.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: f771fde82051976a6fc0fd570f8b86de4a92124b Version: f771fde82051976a6fc0fd570f8b86de4a92124b Version: f771fde82051976a6fc0fd570f8b86de4a92124b Version: f771fde82051976a6fc0fd570f8b86de4a92124b Version: f771fde82051976a6fc0fd570f8b86de4a92124b Version: f771fde82051976a6fc0fd570f8b86de4a92124b Version: f771fde82051976a6fc0fd570f8b86de4a92124b Version: f771fde82051976a6fc0fd570f8b86de4a92124b |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"security/keys/keyring.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "4c0c26f751e50d3027eacc4d7d0fabc31f1d7e6b",
"status": "affected",
"version": "f771fde82051976a6fc0fd570f8b86de4a92124b",
"versionType": "git"
},
{
"lessThan": "79916f40d4ab1b4ae694d8c024fd179454bfe46e",
"status": "affected",
"version": "f771fde82051976a6fc0fd570f8b86de4a92124b",
"versionType": "git"
},
{
"lessThan": "e5b01998cef8d7f613200230ccaadebe5de9135c",
"status": "affected",
"version": "f771fde82051976a6fc0fd570f8b86de4a92124b",
"versionType": "git"
},
{
"lessThan": "d1933e03e8c74a018550c31a393b79c4d95bff40",
"status": "affected",
"version": "f771fde82051976a6fc0fd570f8b86de4a92124b",
"versionType": "git"
},
{
"lessThan": "3a744838453fb9309ce5a5526d3252e211d60152",
"status": "affected",
"version": "f771fde82051976a6fc0fd570f8b86de4a92124b",
"versionType": "git"
},
{
"lessThan": "e9417d21a22ad2ec398e78fcf084b717ce92cf2f",
"status": "affected",
"version": "f771fde82051976a6fc0fd570f8b86de4a92124b",
"versionType": "git"
},
{
"lessThan": "8dba33c1e779d0fb9a2acb31e354cf0fc0229111",
"status": "affected",
"version": "f771fde82051976a6fc0fd570f8b86de4a92124b",
"versionType": "git"
},
{
"lessThan": "63918731f9ae25b5deb022f118e941e6dddfcef4",
"status": "affected",
"version": "f771fde82051976a6fc0fd570f8b86de4a92124b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"security/keys/keyring.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.3"
},
{
"lessThan": "5.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nkeys: fix out-of-bounds read in keyring_get_key_chunk()\n\nFor description-level chunks keyring_get_key_chunk() advances the read\npointer by level * sizeof(long) past the inline prefix but only\nbounds-checks the prefix, so a long enough key description is read past\nits kmemdup(desc, desc_len + 1) allocation. Compute the full byte\noffset and bounds-check the description against it before reading.\n\nThe walk only reaches a description-level chunk when two keys collide\nthrough the hash, x, type and domain_tag chunks, so this is reached from\nan unprivileged add_key(2) with a crafted pair of same-type keys whose\nindex hashes collide; KASAN reports a slab-out-of-bounds read."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The flaw is reached only through local key-management syscalls (add_key, keyctl link/search) that walk the keyring assoc_array in security/keys/keyring.c; the keys subsystem has no network-facing handler or remote packet path.\nAC:L - An attacker fully controls both key descriptions and can offline-compute a same-type pair whose index collides through hash, x, type and domain_tag yet differs later, deterministically forcing description-level chunks without races or uncontrollable layout.\nPR:L - The fix commit and add_key path confirm any unprivileged local user can add crafted keys to their own session/user keyring (lookup_user_key with KEY_NEED_WRITE); no real-root capability or init-namespace privilege is required.\nUI:N - Exploitation is self-contained: the attacker issues add_key twice with crafted colliding descriptions into a writable keyring they own; no action by another user or administrator is required.\nS:U - The out-of-bounds slab read and any disclosed data remain within the host kernel\u0027s security authority; this is standard local kernel memory access, not a VM escape, IOMMU bypass, or sandbox boundary crossing.\nC:H - keyring_get_key_chunk() reads up to a word past the kmemdup(desc,desc_len+1) allocation when the offset includes level*sizeof(long), yielding an adjacent-heap read primitive that can disclose kernel pointers and other sensitive slab contents.\nI:N - This is a read-only out-of-bounds access with no kernel memory write, type confusion, or control-flow hijack; the bug discloses data but does not directly modify kernel or victim integrity.\nA:H - KASAN reports slab-out-of-bounds on trigger, and reading beyond the description allocation can fault at slab/page boundaries; the add_key insertion path is trivially repeatable for denial-of-service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:39:09.169Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/4c0c26f751e50d3027eacc4d7d0fabc31f1d7e6b"
},
{
"url": "https://git.kernel.org/stable/c/79916f40d4ab1b4ae694d8c024fd179454bfe46e"
},
{
"url": "https://git.kernel.org/stable/c/e5b01998cef8d7f613200230ccaadebe5de9135c"
},
{
"url": "https://git.kernel.org/stable/c/d1933e03e8c74a018550c31a393b79c4d95bff40"
},
{
"url": "https://git.kernel.org/stable/c/3a744838453fb9309ce5a5526d3252e211d60152"
},
{
"url": "https://git.kernel.org/stable/c/e9417d21a22ad2ec398e78fcf084b717ce92cf2f"
},
{
"url": "https://git.kernel.org/stable/c/8dba33c1e779d0fb9a2acb31e354cf0fc0229111"
},
{
"url": "https://git.kernel.org/stable/c/63918731f9ae25b5deb022f118e941e6dddfcef4"
}
],
"title": "keys: fix out-of-bounds read in keyring_get_key_chunk()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74567",
"datePublished": "2026-08-15T12:28:08.240Z",
"dateReserved": "2026-08-15T05:44:03.917Z",
"dateUpdated": "2026-08-19T16:39:09.169Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80902 (GCVE-0-2026-80902)
Vulnerability from cvelistv5
Published
2026-09-04 17:11
Modified
2026-09-04 17:11
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
dmaengine: sun6i-dma: Fix reclaim descriptors while terminating DMA
When terminating DMA transfers, active descriptors are not properly
reclaimed. Only cyclic descriptors were handled, leaving non-cyclic
descriptors and their LLI chains to be permanently leaked.
Fix by using vchan_terminate_vdesc() which handles both cyclic and
non-cyclic descriptors by adding them to desc_terminated queue for
proper cleanup.
Add pchan->desc != pchan->done check to prevent double-adding completed
descriptors, which would corrupt the list.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 555859308723d8d5b828304f5eb9281143fd86b5 Version: 555859308723d8d5b828304f5eb9281143fd86b5 Version: 555859308723d8d5b828304f5eb9281143fd86b5 Version: 555859308723d8d5b828304f5eb9281143fd86b5 Version: 555859308723d8d5b828304f5eb9281143fd86b5 Version: 555859308723d8d5b828304f5eb9281143fd86b5 Version: 555859308723d8d5b828304f5eb9281143fd86b5 Version: 555859308723d8d5b828304f5eb9281143fd86b5 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/dma/sun6i-dma.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "bb87440561eb72b47a2b848b5373b86433b247e6",
"status": "affected",
"version": "555859308723d8d5b828304f5eb9281143fd86b5",
"versionType": "git"
},
{
"lessThan": "004a7a02982bed0a727a4ac7be400f00f353e7a2",
"status": "affected",
"version": "555859308723d8d5b828304f5eb9281143fd86b5",
"versionType": "git"
},
{
"lessThan": "b150f603083cc8b72b0cbf13ec3e91f85b4390a0",
"status": "affected",
"version": "555859308723d8d5b828304f5eb9281143fd86b5",
"versionType": "git"
},
{
"lessThan": "27806fe7b9701af0963dcd510e30e7d0cc314c43",
"status": "affected",
"version": "555859308723d8d5b828304f5eb9281143fd86b5",
"versionType": "git"
},
{
"lessThan": "1ccc5c059d067c5358682ad5352e7d7e9239ed9b",
"status": "affected",
"version": "555859308723d8d5b828304f5eb9281143fd86b5",
"versionType": "git"
},
{
"lessThan": "9086b488f2737d5dcee86852b83f2059f1cdfabf",
"status": "affected",
"version": "555859308723d8d5b828304f5eb9281143fd86b5",
"versionType": "git"
},
{
"lessThan": "d4ba6aa65fcd797152d3aebd428a7b2da49cd5eb",
"status": "affected",
"version": "555859308723d8d5b828304f5eb9281143fd86b5",
"versionType": "git"
},
{
"lessThan": "ab1150115e68a46b687eb38c1ab92782018c9f2c",
"status": "affected",
"version": "555859308723d8d5b828304f5eb9281143fd86b5",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/dma/sun6i-dma.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.17"
},
{
"lessThan": "3.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.17",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: sun6i-dma: Fix reclaim descriptors while terminating DMA\n\nWhen terminating DMA transfers, active descriptors are not properly\nreclaimed. Only cyclic descriptors were handled, leaving non-cyclic\ndescriptors and their LLI chains to be permanently leaked.\n\nFix by using vchan_terminate_vdesc() which handles both cyclic and\nnon-cyclic descriptors by adding them to desc_terminated queue for\nproper cleanup.\n\nAdd pchan-\u003edesc != pchan-\u003edone check to prevent double-adding completed\ndescriptors, which would corrupt the list."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T17:11:17.510Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/bb87440561eb72b47a2b848b5373b86433b247e6"
},
{
"url": "https://git.kernel.org/stable/c/004a7a02982bed0a727a4ac7be400f00f353e7a2"
},
{
"url": "https://git.kernel.org/stable/c/b150f603083cc8b72b0cbf13ec3e91f85b4390a0"
},
{
"url": "https://git.kernel.org/stable/c/27806fe7b9701af0963dcd510e30e7d0cc314c43"
},
{
"url": "https://git.kernel.org/stable/c/1ccc5c059d067c5358682ad5352e7d7e9239ed9b"
},
{
"url": "https://git.kernel.org/stable/c/9086b488f2737d5dcee86852b83f2059f1cdfabf"
},
{
"url": "https://git.kernel.org/stable/c/d4ba6aa65fcd797152d3aebd428a7b2da49cd5eb"
},
{
"url": "https://git.kernel.org/stable/c/ab1150115e68a46b687eb38c1ab92782018c9f2c"
}
],
"title": "dmaengine: sun6i-dma: Fix reclaim descriptors while terminating DMA",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80902",
"datePublished": "2026-09-04T17:11:17.510Z",
"dateReserved": "2026-08-26T14:34:25.800Z",
"dateUpdated": "2026-09-04T17:11:17.510Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74552 (GCVE-0-2026-74552)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-19 16:38
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
hwmon: (lm90) Only report alarms if driver is ready
Userspace can read sysfs attributes before driver registration is complete,
immediately after devm_hwmon_device_register_with_info() has been called.
At that time, data->hwmon_dev is not yet initialized. This can trigger
a NULL pointer access since lm90_update_device() and with it
lm90_update_alarms_locked() will be called. This call schedules
report_work and lm90_report_alarms(), which passes the still-NULL
data->hwmon_dev to hwmon_notify_event() and triggers a NULL pointer
dereference.
Fix the problem by only scheduling the report and alert workers
data->hwmon_dev is set.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: f6d0775119fb905fb02eafa98d575cf8ee792d46 Version: f6d0775119fb905fb02eafa98d575cf8ee792d46 Version: f6d0775119fb905fb02eafa98d575cf8ee792d46 Version: f6d0775119fb905fb02eafa98d575cf8ee792d46 Version: f6d0775119fb905fb02eafa98d575cf8ee792d46 Version: f6d0775119fb905fb02eafa98d575cf8ee792d46 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/hwmon/lm90.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "31ce62d36d859423dc39f9902f7c4c307b2e00e3",
"status": "affected",
"version": "f6d0775119fb905fb02eafa98d575cf8ee792d46",
"versionType": "git"
},
{
"lessThan": "4eed33c7db5c0c573928d28d8a2c003642c679b8",
"status": "affected",
"version": "f6d0775119fb905fb02eafa98d575cf8ee792d46",
"versionType": "git"
},
{
"lessThan": "70d9a71aa407044d70b50d356b6decf6659c4d56",
"status": "affected",
"version": "f6d0775119fb905fb02eafa98d575cf8ee792d46",
"versionType": "git"
},
{
"lessThan": "075fce376cf852db9293481edce07c181a9b1f46",
"status": "affected",
"version": "f6d0775119fb905fb02eafa98d575cf8ee792d46",
"versionType": "git"
},
{
"lessThan": "f0b791a006512a48b6348494cb6960598fa99a58",
"status": "affected",
"version": "f6d0775119fb905fb02eafa98d575cf8ee792d46",
"versionType": "git"
},
{
"lessThan": "aa9429edf9fc0e90d6f4da19ea4b5495a54ab117",
"status": "affected",
"version": "f6d0775119fb905fb02eafa98d575cf8ee792d46",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/hwmon/lm90.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.0"
},
{
"lessThan": "6.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (lm90) Only report alarms if driver is ready\n\nUserspace can read sysfs attributes before driver registration is complete,\nimmediately after devm_hwmon_device_register_with_info() has been called.\nAt that time, data-\u003ehwmon_dev is not yet initialized. This can trigger\na NULL pointer access since lm90_update_device() and with it\nlm90_update_alarms_locked() will be called. This call schedules\nreport_work and lm90_report_alarms(), which passes the still-NULL\ndata-\u003ehwmon_dev to hwmon_notify_event() and triggers a NULL pointer\ndereference.\n\nFix the problem by only scheduling the report and alert workers\ndata-\u003ehwmon_dev is set."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:38:49.811Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/31ce62d36d859423dc39f9902f7c4c307b2e00e3"
},
{
"url": "https://git.kernel.org/stable/c/4eed33c7db5c0c573928d28d8a2c003642c679b8"
},
{
"url": "https://git.kernel.org/stable/c/70d9a71aa407044d70b50d356b6decf6659c4d56"
},
{
"url": "https://git.kernel.org/stable/c/075fce376cf852db9293481edce07c181a9b1f46"
},
{
"url": "https://git.kernel.org/stable/c/f0b791a006512a48b6348494cb6960598fa99a58"
},
{
"url": "https://git.kernel.org/stable/c/aa9429edf9fc0e90d6f4da19ea4b5495a54ab117"
}
],
"title": "hwmon: (lm90) Only report alarms if driver is ready",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74552",
"datePublished": "2026-08-15T12:27:58.829Z",
"dateReserved": "2026-08-15T05:44:03.915Z",
"dateUpdated": "2026-08-19T16:38:49.811Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74595 (GCVE-0-2026-74595)
Vulnerability from cvelistv5
Published
2026-08-22 15:31
Modified
2026-08-25 05:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
fscrypt: use the mount idmap for the owner check in fscrypt_ioctl_set_policy()
fscrypt_ioctl_set_policy() calls inode_owner_or_capable() with
&nop_mnt_idmap before allowing an encryption policy to be set, instead
of the idmap of the mount the ioctl was issued on.
fscrypt is used by filesystems that support idmapped mounts (e.g. ext4,
f2fs), so on such a mount this compares the caller's fsuid against the
unmapped on-disk owner rather than the mapped owner: the actual owner
can be wrongly denied with -EACCES and an unrelated caller wrongly
allowed. Use file_mnt_idmap(filp) instead.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 14f3db5542e62bcf6fe088a09760ac52d55306c5 Version: 14f3db5542e62bcf6fe088a09760ac52d55306c5 Version: 14f3db5542e62bcf6fe088a09760ac52d55306c5 Version: 14f3db5542e62bcf6fe088a09760ac52d55306c5 Version: 14f3db5542e62bcf6fe088a09760ac52d55306c5 Version: 14f3db5542e62bcf6fe088a09760ac52d55306c5 Version: 14f3db5542e62bcf6fe088a09760ac52d55306c5 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/crypto/policy.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "174633a468817a49bd474bcfc9067c84e54efe68",
"status": "affected",
"version": "14f3db5542e62bcf6fe088a09760ac52d55306c5",
"versionType": "git"
},
{
"lessThan": "0baeb730044981f5ec5fb7d62a3763835ea606f6",
"status": "affected",
"version": "14f3db5542e62bcf6fe088a09760ac52d55306c5",
"versionType": "git"
},
{
"lessThan": "33b7e810ce09955aa02f3b632455cf5e7ac990a9",
"status": "affected",
"version": "14f3db5542e62bcf6fe088a09760ac52d55306c5",
"versionType": "git"
},
{
"lessThan": "6a67c460b12315033268dce597546984fe5739e7",
"status": "affected",
"version": "14f3db5542e62bcf6fe088a09760ac52d55306c5",
"versionType": "git"
},
{
"lessThan": "653e888a24c87b8bbeab44d7e558a1c1a3641088",
"status": "affected",
"version": "14f3db5542e62bcf6fe088a09760ac52d55306c5",
"versionType": "git"
},
{
"lessThan": "98516ba8b817f34e86bdd7a5b7a383cff75c3ddf",
"status": "affected",
"version": "14f3db5542e62bcf6fe088a09760ac52d55306c5",
"versionType": "git"
},
{
"lessThan": "cf6c993c0feca7984797e634deba3c80342e199a",
"status": "affected",
"version": "14f3db5542e62bcf6fe088a09760ac52d55306c5",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/crypto/policy.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.12"
},
{
"lessThan": "5.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfscrypt: use the mount idmap for the owner check in fscrypt_ioctl_set_policy()\n\nfscrypt_ioctl_set_policy() calls inode_owner_or_capable() with\n\u0026nop_mnt_idmap before allowing an encryption policy to be set, instead\nof the idmap of the mount the ioctl was issued on.\n\nfscrypt is used by filesystems that support idmapped mounts (e.g. ext4,\nf2fs), so on such a mount this compares the caller\u0027s fsuid against the\nunmapped on-disk owner rather than the mapped owner: the actual owner\ncan be wrongly denied with -EACCES and an unrelated caller wrongly\nallowed. Use file_mnt_idmap(filp) instead."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires a local process to open a directory on an idmapped ext4/f2fs filesystem and issue FS_IOC_SET_ENCRYPTION_POLICY via ioctl(); there is no network, adjacent-radio, or physical-device attack path to the vulnerable fscrypt_ioctl_set_policy() check.\nAC:L - On idmapped mounts the UID mismatch is structural, not random: any local user whose fsuid equals the inode\u0027s unmapped on-disk owner can open an empty victim directory, add their own fscrypt key, and trigger the ioctl without races or attacker-uncontrollable memory layout.\nPR:L - Only basic local user privileges are needed; the attacker must be able to open the target directory and call FS_IOC_ADD_ENCRYPTION_KEY plus FS_IOC_SET_ENCRYPTION_POLICY, with no real-root or init-namespace capability required beyond normal DAC permissions on the path.\nUI:N - Exploitation requires no action by the victim; the attacker alone issues the ioctl on an empty directory they can open, and the authorization bypass occurs entirely within the attacker\u0027s own syscall sequence.\nS:U - This is an incorrect inode_owner_or_capable() authorization check in the kernel fscrypt ioctl path on idmapped mounts; impact stays within the same kernel security authority and does not constitute VM escape, hypervisor bypass, or IOMMU boundary crossing.\nC:H - A wrongly authorized attacker can bind a victim\u0027s empty directory to an attacker-controlled fscrypt master key, then decrypt any sensitive files the victim later creates there, giving broad read access to victim data rather than a small bounded leak.\nI:H - The ioctl persistently modifies filesystem encryption policy and on-disk fscrypt context for a directory the attacker does not own, granting unauthorized control over a critical security property of victim data at rest.\nA:H - The bug both wrongly denies legitimate directory owners with -EACCES and lets attackers encrypt a victim\u0027s empty directory with an attacker-held key, preventing the real owner from using or recovering that directory and its future contents."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:40:22.483Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/174633a468817a49bd474bcfc9067c84e54efe68"
},
{
"url": "https://git.kernel.org/stable/c/0baeb730044981f5ec5fb7d62a3763835ea606f6"
},
{
"url": "https://git.kernel.org/stable/c/33b7e810ce09955aa02f3b632455cf5e7ac990a9"
},
{
"url": "https://git.kernel.org/stable/c/6a67c460b12315033268dce597546984fe5739e7"
},
{
"url": "https://git.kernel.org/stable/c/653e888a24c87b8bbeab44d7e558a1c1a3641088"
},
{
"url": "https://git.kernel.org/stable/c/98516ba8b817f34e86bdd7a5b7a383cff75c3ddf"
},
{
"url": "https://git.kernel.org/stable/c/cf6c993c0feca7984797e634deba3c80342e199a"
}
],
"title": "fscrypt: use the mount idmap for the owner check in fscrypt_ioctl_set_policy()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74595",
"datePublished": "2026-08-22T15:31:45.649Z",
"dateReserved": "2026-08-15T05:44:03.919Z",
"dateUpdated": "2026-08-25T05:40:22.483Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72242 (GCVE-0-2026-72242)
Vulnerability from cvelistv5
Published
2026-08-15 05:54
Modified
2026-08-23 12:47
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
selinux: avoid sk_socket dereference in selinux_sctp_bind_connect()
selinux_sctp_bind_connect() dereferences sk->sk_socket to pass a
struct socket * to selinux_socket_bind() and
selinux_socket_connect_helper(). However, when the hook is invoked
from the ASCONF softirq path (sctp_process_asconf), there is no file
reference guaranteeing that sk->sk_socket is non-NULL. The setsockopt
callers (bindx, connectx, set_primary, sendmsg connect) hold a file
reference and are not affected.
Both selinux_socket_bind() and selinux_socket_connect_helper()
immediately resolve sock->sk, never using the struct socket * for
anything else. Refactor the inner logic into helpers that take a
struct sock * directly so that selinux_sctp_bind_connect() never needs
to touch sk->sk_socket at all.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d452930fd3b9031e59abfeddb2fa383f1403d61a Version: d452930fd3b9031e59abfeddb2fa383f1403d61a Version: d452930fd3b9031e59abfeddb2fa383f1403d61a Version: d452930fd3b9031e59abfeddb2fa383f1403d61a Version: d452930fd3b9031e59abfeddb2fa383f1403d61a Version: d452930fd3b9031e59abfeddb2fa383f1403d61a Version: d452930fd3b9031e59abfeddb2fa383f1403d61a Version: d452930fd3b9031e59abfeddb2fa383f1403d61a |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"security/selinux/hooks.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "e4f3b8db1b0c5e9f6374b8996d9e1888d1042b55",
"status": "affected",
"version": "d452930fd3b9031e59abfeddb2fa383f1403d61a",
"versionType": "git"
},
{
"lessThan": "2fcaf133a8fd88b69f32ebaecad93fd302da828f",
"status": "affected",
"version": "d452930fd3b9031e59abfeddb2fa383f1403d61a",
"versionType": "git"
},
{
"lessThan": "a4bc2fb8536488b37680c0b66c59434a4b7f8c2f",
"status": "affected",
"version": "d452930fd3b9031e59abfeddb2fa383f1403d61a",
"versionType": "git"
},
{
"lessThan": "5d4d93f9bfbc997ffbb03cd6107e8f6979dbb9b4",
"status": "affected",
"version": "d452930fd3b9031e59abfeddb2fa383f1403d61a",
"versionType": "git"
},
{
"lessThan": "cc8bd47b35eca82393cbad08b1cc86f02e034439",
"status": "affected",
"version": "d452930fd3b9031e59abfeddb2fa383f1403d61a",
"versionType": "git"
},
{
"lessThan": "d61a80b17254be7230bc5544f8e62ddf21ab38e2",
"status": "affected",
"version": "d452930fd3b9031e59abfeddb2fa383f1403d61a",
"versionType": "git"
},
{
"lessThan": "37d642b37ccdc31e1947c2ebc8dc38f03d4a0ceb",
"status": "affected",
"version": "d452930fd3b9031e59abfeddb2fa383f1403d61a",
"versionType": "git"
},
{
"lessThan": "56acfeb10019e200ab6787d01f8d7cbe0f01526f",
"status": "affected",
"version": "d452930fd3b9031e59abfeddb2fa383f1403d61a",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"security/selinux/hooks.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.17"
},
{
"lessThan": "4.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.17",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nselinux: avoid sk_socket dereference in selinux_sctp_bind_connect()\n\nselinux_sctp_bind_connect() dereferences sk-\u003esk_socket to pass a\nstruct socket * to selinux_socket_bind() and\nselinux_socket_connect_helper(). However, when the hook is invoked\nfrom the ASCONF softirq path (sctp_process_asconf), there is no file\nreference guaranteeing that sk-\u003esk_socket is non-NULL. The setsockopt\ncallers (bindx, connectx, set_primary, sendmsg connect) hold a file\nreference and are not affected.\n\nBoth selinux_socket_bind() and selinux_socket_connect_helper()\nimmediately resolve sock-\u003esk, never using the struct socket * for\nanything else. Refactor the inner logic into helpers that take a\nstruct sock * directly so that selinux_sctp_bind_connect() never needs\nto touch sk-\u003esk_socket at all."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The vulnerable code runs in the SCTP receive softirq path when a remote peer sends an authenticated ASCONF chunk (ADD_IP/SET_PRIMARY) on an existing association; packets enter via sctp_rcv() from the network stack, not local syscalls.\nAC:L - An attacker with an established SCTP association controls ASCONF timing and can flood ADD_IP/SET_PRIMARY during the documented post-close() teardown window when sk_socket is NULL but associations still process shutdown-state packets.\nPR:N - Exploitation requires only the ability to complete a normal SCTP association handshake with a SELinux-protected peer; no Linux capabilities, root, or local shell access are needed to send the triggering ASCONF packets over the network.\nUI:N - No victim user action is required beyond normal server operation; the crash is triggered by attacker-sent ASCONF traffic arriving while the kernel processes socket teardown after application close(), not by opening files or clicking links.\nS:U - Impact is a kernel NULL pointer dereference panic/oops within the same kernel security domain; it does not cross VM, container, or IOMMU boundaries and is a standard remote denial-of-service against the host kernel.\nC:N - The failure mode is a direct NULL pointer dereference of sk-\u003esk_socket before reading sock-\u003esk; there is no use-after-free, out-of-bounds access, or memory corruption that could yield information disclosure.\nI:N - The bug does not write or corrupt memory; selinux_socket_bind()/connect_helper() crash immediately on the NULL socket pointer without modifying kernel data structures or achieving code execution.\nA:H - Dereferencing a NULL sk_socket in softirq causes a kernel oops/panic, crashing the entire system; this is repeatable whenever ASCONF arrives during the post-close() window on SCTP associations in shutdown states."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:47:05.827Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/e4f3b8db1b0c5e9f6374b8996d9e1888d1042b55"
},
{
"url": "https://git.kernel.org/stable/c/2fcaf133a8fd88b69f32ebaecad93fd302da828f"
},
{
"url": "https://git.kernel.org/stable/c/a4bc2fb8536488b37680c0b66c59434a4b7f8c2f"
},
{
"url": "https://git.kernel.org/stable/c/5d4d93f9bfbc997ffbb03cd6107e8f6979dbb9b4"
},
{
"url": "https://git.kernel.org/stable/c/cc8bd47b35eca82393cbad08b1cc86f02e034439"
},
{
"url": "https://git.kernel.org/stable/c/d61a80b17254be7230bc5544f8e62ddf21ab38e2"
},
{
"url": "https://git.kernel.org/stable/c/37d642b37ccdc31e1947c2ebc8dc38f03d4a0ceb"
},
{
"url": "https://git.kernel.org/stable/c/56acfeb10019e200ab6787d01f8d7cbe0f01526f"
}
],
"title": "selinux: avoid sk_socket dereference in selinux_sctp_bind_connect()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72242",
"datePublished": "2026-08-15T05:54:30.378Z",
"dateReserved": "2026-08-09T03:40:39.914Z",
"dateUpdated": "2026-08-23T12:47:05.827Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72065 (GCVE-0-2026-72065)
Vulnerability from cvelistv5
Published
2026-08-15 05:52
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: mana: Validate the packet length reported by the NIC
Validate the packet length reported in the RX CQE before passing it
to skb processing. The CQE is supplied by the NIC device and should
not be blindly trusted.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f Version: ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f Version: ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f Version: ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f Version: ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f Version: ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f Version: ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/microsoft/mana/mana_en.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a631f82f89c76084ad5b2b9c043d3b391ffa56d8",
"status": "affected",
"version": "ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f",
"versionType": "git"
},
{
"lessThan": "d2568e64d01f480200063fadd67d6938f676c66f",
"status": "affected",
"version": "ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f",
"versionType": "git"
},
{
"lessThan": "2e276b14b6d378372bf0152df89286cbe7632fb0",
"status": "affected",
"version": "ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f",
"versionType": "git"
},
{
"lessThan": "6080189291d958604dcefe513a13900835ac982f",
"status": "affected",
"version": "ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f",
"versionType": "git"
},
{
"lessThan": "6d13eaa13341a8f80aaf86f78591e1b1d393711d",
"status": "affected",
"version": "ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f",
"versionType": "git"
},
{
"lessThan": "282c5214ca4eb3799158c76782646e86d2945d1b",
"status": "affected",
"version": "ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f",
"versionType": "git"
},
{
"lessThan": "2e2a83b4998af4384e677d3b2ac08565274279bf",
"status": "affected",
"version": "ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/microsoft/mana/mana_en.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.13"
},
{
"lessThan": "5.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mana: Validate the packet length reported by the NIC\n\nValidate the packet length reported in the RX CQE before passing it\nto skb processing. The CQE is supplied by the NIC device and should\nnot be blindly trusted."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - On internet-facing Azure VMs, remote packets drive MANA RX through IRQ/NAPI into mana_poll_rx_cq()/mana_process_rx_cqe(), where device-written RX CQE pkt_len is trusted and passed to skb/XDP processing without bounds checks against rxq-\u003edatasize.\nAC:L - The attacker can repeatedly send traffic to trigger RX completions until the MANA backend reports pkt_len above rxq-\u003edatasize; once that CQE arrives, mana_refill_rx_oob() and mana_rx_skb() misuse the length deterministically with no race or special memory layout.\nPR:N - The vulnerable path is the netdev NAPI receive handler before any socket or credential checks; an unauthenticated remote sender only needs packets routed to the VM\u0027s MANA interface, with no local account or capability on the victim.\nUI:N - RX CQEs are handled automatically from hardware interrupts and NAPI polling once the interface is up; no victim mount, ioctl, or other interactive action is required beyond normal network reception.\nS:U - Out-of-bounds access and crashes occur in the guest kernel processing MANA RX buffers; impact stays within that kernel security authority and does not by itself cross a VM/host or IOMMU boundary.\nC:H - Unchecked pkt_len is used in page_pool_dma_sync_for_cpu(), xdp_prepare_buff()/bpf_prog_run_xdp(), and skb_put()/eth_type_trans(), enabling reads well past the DMA-mapped rxq-\u003edatasize region and leaking adjacent kernel heap/page memory.\nI:H - Oversized pkt_len expands skb and XDP data bounds beyond the posted RX buffer, corrupting adjacent kernel memory and providing attacker-influenced metadata/control corruption primitives consistent with high integrity impact for OOB memory corruption.\nA:H - Processing an oversized pkt_len can kernel oops/panic from skb_put bounds failures or unmapped reads in softirq/NAPI context, and the remote attacker can retrigger the condition for sustained denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:40.741Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a631f82f89c76084ad5b2b9c043d3b391ffa56d8"
},
{
"url": "https://git.kernel.org/stable/c/d2568e64d01f480200063fadd67d6938f676c66f"
},
{
"url": "https://git.kernel.org/stable/c/2e276b14b6d378372bf0152df89286cbe7632fb0"
},
{
"url": "https://git.kernel.org/stable/c/6080189291d958604dcefe513a13900835ac982f"
},
{
"url": "https://git.kernel.org/stable/c/6d13eaa13341a8f80aaf86f78591e1b1d393711d"
},
{
"url": "https://git.kernel.org/stable/c/282c5214ca4eb3799158c76782646e86d2945d1b"
},
{
"url": "https://git.kernel.org/stable/c/2e2a83b4998af4384e677d3b2ac08565274279bf"
}
],
"title": "net: mana: Validate the packet length reported by the NIC",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72065",
"datePublished": "2026-08-15T05:52:18.801Z",
"dateReserved": "2026-08-09T03:40:39.903Z",
"dateUpdated": "2026-08-23T12:46:40.741Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74724 (GCVE-0-2026-74724)
Vulnerability from cvelistv5
Published
2026-08-22 15:33
Modified
2026-08-25 05:42
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ipvs: avoid out-of-bounds write in ip_vs_nat_icmp
Sashiko warns that local attacker can modify the packet
while it is processed by IPVS. Some places read the
IP ihl field multiple times which can cause out-of-bounds
access. One such place is ip_vs_nat_icmp where we
can write after the validated area.
Fix it by providing ciph argument just like it is done for
IPv6 and use ciph->len as offset to the embedded transport
header.
Modify some IPv4 header checks by reading the ihl field
only once.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"include/net/ip_vs.h",
"net/netfilter/ipvs/ip_vs_core.c",
"net/netfilter/ipvs/ip_vs_xmit.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "3b8f79af0e98f27b932b0b416e9c52b692d31ff9",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "3c779b258c9c3c3567af68d4f45c2f751f35bd0e",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "be65fa324640c7a95e30b146159a2be5cc73f22e",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "a69a4b3fff5814d079beff9a1e9d369994b2ed47",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "243d0187ec4c3837b9b0004f18d1068e46115760",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "646922a0379496154e8c8faca4f8e2fd9100cacc",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"include/net/ip_vs.h",
"net/netfilter/ipvs/ip_vs_core.c",
"net/netfilter/ipvs/ip_vs_xmit.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nipvs: avoid out-of-bounds write in ip_vs_nat_icmp\n\nSashiko warns that local attacker can modify the packet\nwhile it is processed by IPVS. Some places read the\nIP ihl field multiple times which can cause out-of-bounds\naccess. One such place is ip_vs_nat_icmp where we\ncan write after the validated area.\n\nFix it by providing ciph argument just like it is done for\nIPv6 and use ciph-\u003elen as offset to the embedded transport\nheader.\n\nModify some IPv4 header checks by reading the ihl field\nonly once."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The OOB write in ip_vs_nat_icmp() requires a local process to change the embedded IPv4 ihl in skb frags between ip_vs_fill_iph_skb_icmp() validation and the NAT write; remote-only ICMP to IPVS netfilter hooks cannot perform that TOCTOU without local access to the packet buffer.\nAC:L - A local attacker controls both sides of the race by concurrently injecting ICMP errors with TCP/UDP/SCTP payloads matching an IPVS NAT connection and modifying the embedded header ihl in skb frags during softirq processing; no victim-specific state or uncontrollable heap layout is required.\nPR:L - Triggering requires a local account able to race skb frag modification (e.g., via raw/packet sockets with CAP_NET_RAW, obtainable in a user namespace) against IPVS ICMP NAT handling on a host where IPVS is already configured; no init-namespace root is needed.\nUI:N - No victim user interaction is required; exploitation is driven entirely by attacker-controlled local packet injection and concurrent frag modification while IPVS processes ICMP errors on NAT-mode connections through LOCAL_IN, LOCAL_OUT, or FORWARD hooks.\nS:U - The out-of-bounds write corrupts kernel skb memory on the IPVS load-balancer host within the same kernel security authority; it does not cross VM, container, or IOMMU boundaries into a separate security scope.\nC:H - Writing TCP/UDP/SCTP port fields and running ip_send_check() using a re-read inflated ihl corrupts skb data beyond the validated region; out-of-bounds kernel memory corruption is exploitable for information disclosure and heap layout control.\nI:H - The bug is an out-of-bounds write of 16-bit port values (and checksum updates over an attacker-inflated header length) past skb_ensure_writable()\u0027s bound, enabling adjacent kernel memory corruption and potential control-flow hijacking on internet-facing IPVS NAT nodes.\nA:H - Corrupting skb header memory beyond the ensured writable area can cause kernel oops or panic during ICMP NAT mangling; a local attacker can repeatedly trigger the race on kube-proxy IPVS nodes and hardware load balancers running IPVS NAT mode."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:42:04.705Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/3b8f79af0e98f27b932b0b416e9c52b692d31ff9"
},
{
"url": "https://git.kernel.org/stable/c/3c779b258c9c3c3567af68d4f45c2f751f35bd0e"
},
{
"url": "https://git.kernel.org/stable/c/be65fa324640c7a95e30b146159a2be5cc73f22e"
},
{
"url": "https://git.kernel.org/stable/c/a69a4b3fff5814d079beff9a1e9d369994b2ed47"
},
{
"url": "https://git.kernel.org/stable/c/243d0187ec4c3837b9b0004f18d1068e46115760"
},
{
"url": "https://git.kernel.org/stable/c/646922a0379496154e8c8faca4f8e2fd9100cacc"
}
],
"title": "ipvs: avoid out-of-bounds write in ip_vs_nat_icmp",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74724",
"datePublished": "2026-08-22T15:33:15.832Z",
"dateReserved": "2026-08-15T05:44:03.929Z",
"dateUpdated": "2026-08-25T05:42:04.705Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68250 (GCVE-0-2026-68250)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-19 16:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON()
There's no need to crash the kernel for these cases.
(cherry picked from commit ae658afc7f47f6147371ec42cc6b1a793dfdb5af)
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 157e72e831cb8f323108b5df6d0b148aef9507fb Version: 157e72e831cb8f323108b5df6d0b148aef9507fb Version: 157e72e831cb8f323108b5df6d0b148aef9507fb Version: 157e72e831cb8f323108b5df6d0b148aef9507fb Version: 157e72e831cb8f323108b5df6d0b148aef9507fb Version: 157e72e831cb8f323108b5df6d0b148aef9507fb Version: 157e72e831cb8f323108b5df6d0b148aef9507fb Version: 157e72e831cb8f323108b5df6d0b148aef9507fb |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/sdma_v5_2.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "55995d8da162acbadfd5fb0f08675e8e1c0bdb63",
"status": "affected",
"version": "157e72e831cb8f323108b5df6d0b148aef9507fb",
"versionType": "git"
},
{
"lessThan": "f718334e4aa3768f6e68d235945eca2987c6687c",
"status": "affected",
"version": "157e72e831cb8f323108b5df6d0b148aef9507fb",
"versionType": "git"
},
{
"lessThan": "6d27435df2a4ca4945f4313344a5da5bc6b54075",
"status": "affected",
"version": "157e72e831cb8f323108b5df6d0b148aef9507fb",
"versionType": "git"
},
{
"lessThan": "01dfea84df919cfbec4064151d327480ae5c120d",
"status": "affected",
"version": "157e72e831cb8f323108b5df6d0b148aef9507fb",
"versionType": "git"
},
{
"lessThan": "b665c1845488c6cd869da3d31b5978015977f898",
"status": "affected",
"version": "157e72e831cb8f323108b5df6d0b148aef9507fb",
"versionType": "git"
},
{
"lessThan": "09da54636bac146c1a3c461c4e7eb08d355bb86e",
"status": "affected",
"version": "157e72e831cb8f323108b5df6d0b148aef9507fb",
"versionType": "git"
},
{
"lessThan": "2051bbbfbd44ff51637b01a5a3dbee6630f90d57",
"status": "affected",
"version": "157e72e831cb8f323108b5df6d0b148aef9507fb",
"versionType": "git"
},
{
"lessThan": "b9dd618a635d39fbb211454b6e8837b2a7f10fb0",
"status": "affected",
"version": "157e72e831cb8f323108b5df6d0b148aef9507fb",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/sdma_v5_2.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.9"
},
{
"lessThan": "5.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON()\n\nThere\u0027s no need to crash the kernel for these cases.\n\n(cherry picked from commit ae658afc7f47f6147371ec42cc6b1a793dfdb5af)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:32:21.015Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/55995d8da162acbadfd5fb0f08675e8e1c0bdb63"
},
{
"url": "https://git.kernel.org/stable/c/f718334e4aa3768f6e68d235945eca2987c6687c"
},
{
"url": "https://git.kernel.org/stable/c/6d27435df2a4ca4945f4313344a5da5bc6b54075"
},
{
"url": "https://git.kernel.org/stable/c/01dfea84df919cfbec4064151d327480ae5c120d"
},
{
"url": "https://git.kernel.org/stable/c/b665c1845488c6cd869da3d31b5978015977f898"
},
{
"url": "https://git.kernel.org/stable/c/09da54636bac146c1a3c461c4e7eb08d355bb86e"
},
{
"url": "https://git.kernel.org/stable/c/2051bbbfbd44ff51637b01a5a3dbee6630f90d57"
},
{
"url": "https://git.kernel.org/stable/c/b9dd618a635d39fbb211454b6e8837b2a7f10fb0"
}
],
"title": "drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68250",
"datePublished": "2026-08-10T12:01:16.435Z",
"dateReserved": "2026-07-30T09:28:09.377Z",
"dateUpdated": "2026-08-19T16:32:21.015Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74582 (GCVE-0-2026-74582)
Vulnerability from cvelistv5
Published
2026-08-21 16:31
Modified
2026-08-27 12:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
packet: use consistent hard_header_len in non-ring send paths
packet_snd() reads dev->hard_header_len multiple times while allocating
and constructing an skb. Device reconfiguration can change this value
concurrently, for example through bonding device type changes.
For SOCK_RAW, packet_snd() can save a larger value in reserve and later
allocate headroom using a smaller value. Moving skb->data back by reserve
then places it before skb->head, and the following copy from userspace can
attempt an out-of-bounds write.
packet_sendmsg_spkt() has the same issue because it calculates its
reservation and header offset from separate reads before dropping the RCU
read lock to allocate the skb.
Add LL_RESERVED_SPACE_EX() for callers that already saved a header length.
Read hard_header_len once in packet_snd() and use it for allocation and
construction. In packet_sendmsg_spkt(), preserve the allocation-time value
through the device lookup retry.
The separate SOCK_DGRAM consistency problem between hard_header_len and
header_ops->create is not addressed here.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: b84bbaf7a6c8cca24f8acf25a2c8e46913a947ba Version: b84bbaf7a6c8cca24f8acf25a2c8e46913a947ba Version: b84bbaf7a6c8cca24f8acf25a2c8e46913a947ba Version: b84bbaf7a6c8cca24f8acf25a2c8e46913a947ba Version: b84bbaf7a6c8cca24f8acf25a2c8e46913a947ba Version: b84bbaf7a6c8cca24f8acf25a2c8e46913a947ba Version: b84bbaf7a6c8cca24f8acf25a2c8e46913a947ba Version: b84bbaf7a6c8cca24f8acf25a2c8e46913a947ba Version: d9fb8cc230b2a4757e9fe4f81468f81212d4deaa Version: 6190cce26e40bf71c4d375b21eea74bb07b6a0f3 Version: 01a658c1b9d4b5393c38d5a92d9112ab1425382a Version: 8809ae6747e760e6f1d2453ceb08c9bcc4939766 Version: 4.4.133 ≤ Version: 4.9.103 ≤ Version: 4.14.44 ≤ Version: 4.16.12 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"include/linux/netdevice.h",
"net/packet/af_packet.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "bcd4df60ac9481b1ceffdfe5ec38fe51dcaae812",
"status": "affected",
"version": "b84bbaf7a6c8cca24f8acf25a2c8e46913a947ba",
"versionType": "git"
},
{
"lessThan": "78a47127e33c340bc6d38dcc4552a094b4f5cc77",
"status": "affected",
"version": "b84bbaf7a6c8cca24f8acf25a2c8e46913a947ba",
"versionType": "git"
},
{
"lessThan": "142e287b3a25cfe909215177c23243e7fc5ae2b1",
"status": "affected",
"version": "b84bbaf7a6c8cca24f8acf25a2c8e46913a947ba",
"versionType": "git"
},
{
"lessThan": "91f041451f967cd87ed722a8f43c0b767a64f1a0",
"status": "affected",
"version": "b84bbaf7a6c8cca24f8acf25a2c8e46913a947ba",
"versionType": "git"
},
{
"lessThan": "9052756290962ffb9a661bcf319e92dedaaedfed",
"status": "affected",
"version": "b84bbaf7a6c8cca24f8acf25a2c8e46913a947ba",
"versionType": "git"
},
{
"lessThan": "5bb10753d428aadfc356a2bfe9acea09c82a62ec",
"status": "affected",
"version": "b84bbaf7a6c8cca24f8acf25a2c8e46913a947ba",
"versionType": "git"
},
{
"lessThan": "b06b6fce6d7deaf7238e09b48ce3b1125ff41acd",
"status": "affected",
"version": "b84bbaf7a6c8cca24f8acf25a2c8e46913a947ba",
"versionType": "git"
},
{
"lessThan": "03390aa32e669cc4ecd7d34108e2e1afc13d689d",
"status": "affected",
"version": "b84bbaf7a6c8cca24f8acf25a2c8e46913a947ba",
"versionType": "git"
},
{
"status": "affected",
"version": "d9fb8cc230b2a4757e9fe4f81468f81212d4deaa",
"versionType": "git"
},
{
"status": "affected",
"version": "6190cce26e40bf71c4d375b21eea74bb07b6a0f3",
"versionType": "git"
},
{
"status": "affected",
"version": "01a658c1b9d4b5393c38d5a92d9112ab1425382a",
"versionType": "git"
},
{
"status": "affected",
"version": "8809ae6747e760e6f1d2453ceb08c9bcc4939766",
"versionType": "git"
},
{
"lessThan": "4.5",
"status": "affected",
"version": "4.4.133",
"versionType": "semver"
},
{
"lessThan": "4.10",
"status": "affected",
"version": "4.9.103",
"versionType": "semver"
},
{
"lessThan": "4.15",
"status": "affected",
"version": "4.14.44",
"versionType": "semver"
},
{
"lessThan": "4.17",
"status": "affected",
"version": "4.16.12",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"include/linux/netdevice.h",
"net/packet/af_packet.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.17"
},
{
"lessThan": "4.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.267",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.218",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.185",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.267",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.218",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.185",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.4.133",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.9.103",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.14.44",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.16.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\npacket: use consistent hard_header_len in non-ring send paths\n\npacket_snd() reads dev-\u003ehard_header_len multiple times while allocating\nand constructing an skb. Device reconfiguration can change this value\nconcurrently, for example through bonding device type changes.\n\nFor SOCK_RAW, packet_snd() can save a larger value in reserve and later\nallocate headroom using a smaller value. Moving skb-\u003edata back by reserve\nthen places it before skb-\u003ehead, and the following copy from userspace can\nattempt an out-of-bounds write.\n\npacket_sendmsg_spkt() has the same issue because it calculates its\nreservation and header offset from separate reads before dropping the RCU\nread lock to allocate the skb.\n\nAdd LL_RESERVED_SPACE_EX() for callers that already saved a header length.\nRead hard_header_len once in packet_snd() and use it for allocation and\nconstruction. In packet_sendmsg_spkt(), preserve the allocation-time value\nthrough the device lookup retry.\n\nThe separate SOCK_DGRAM consistency problem between hard_header_len and\nheader_ops-\u003ecreate is not addressed here."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The flaw is in packet_snd() and packet_sendmsg_spkt() on the local AF_PACKET sendmsg() transmit path; it is not triggered by processing remotely received network traffic or pre-authentication network services.\nAC:L - An attacker in a user+network namespace can open an AF_PACKET SOCK_RAW socket and concurrently reconfigure the bound netdev (bonding/VLAN/macvlan/team) to change hard_header_len, controlling both sides of the race without external timing.\nPR:L - Exploitation requires CAP_NET_RAW to create AF_PACKET sockets and CAP_NET_ADMIN to change netdev hard_header_len; both are obtainable by an unprivileged user inside a user namespace without init-namespace root.\nUI:N - No victim interaction is required; the attacker triggers the bug using their own packet socket sendmsg calls and concurrent netdev reconfiguration threads.\nS:U - Impact is kernel heap corruption and local privilege escalation within the same kernel security domain; it does not constitute a VM escape, sandbox breakout, or IOMMU boundary bypass.\nC:H - Racing hard_header_len can place skb-\u003edata before skb-\u003ehead, and skb_copy_datagram_from_iter/memcpy_from_msg then writes attacker-controlled data outside the skb buffer, corrupting adjacent slab objects and enabling kernel memory disclosure.\nI:H - Inconsistent hard_header_len between skb allocation and header adjustment causes out-of-bounds kernel heap writes of attacker-controlled packet data, yielding corruption primitives suitable for control-flow hijacking and local privilege escalation.\nA:H - Out-of-bounds skb buffer writes corrupt kmalloc metadata and can trigger kernel oops/panic, causing reliable denial of service even when full exploitation is not completed."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T12:39:47.499Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/bcd4df60ac9481b1ceffdfe5ec38fe51dcaae812"
},
{
"url": "https://git.kernel.org/stable/c/78a47127e33c340bc6d38dcc4552a094b4f5cc77"
},
{
"url": "https://git.kernel.org/stable/c/142e287b3a25cfe909215177c23243e7fc5ae2b1"
},
{
"url": "https://git.kernel.org/stable/c/91f041451f967cd87ed722a8f43c0b767a64f1a0"
},
{
"url": "https://git.kernel.org/stable/c/9052756290962ffb9a661bcf319e92dedaaedfed"
},
{
"url": "https://git.kernel.org/stable/c/5bb10753d428aadfc356a2bfe9acea09c82a62ec"
},
{
"url": "https://git.kernel.org/stable/c/b06b6fce6d7deaf7238e09b48ce3b1125ff41acd"
},
{
"url": "https://git.kernel.org/stable/c/03390aa32e669cc4ecd7d34108e2e1afc13d689d"
}
],
"title": "packet: use consistent hard_header_len in non-ring send paths",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74582",
"datePublished": "2026-08-21T16:31:55.283Z",
"dateReserved": "2026-08-15T05:44:03.918Z",
"dateUpdated": "2026-08-27T12:39:47.499Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74620 (GCVE-0-2026-74620)
Vulnerability from cvelistv5
Published
2026-08-22 15:32
Modified
2026-08-23 12:47
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/sched: act_gact, act_police: range check the fallback control action
tcf_action_check_ctrlact() range checks the primary control action:
if (!opcode)
ret = action > TC_ACT_VALUE_MAX ? -EINVAL : 0;
TC_ACT_VALUE_MAX is TC_ACT_TRAP, so kernel-internal verdicts above it
cannot be set that way. But act_gact and act_police each carry a second,
independent control action supplied by user space that never reaches that
helper - TCA_GACT_PROB.paction and TCA_POLICE_RESULT. Both only reject
TC_ACT_GOTO_CHAIN, so any other value is stored verbatim and returned
verbatim from the action.
In particular user space can store TC_ACT_CONSUMED, which is
TC_ACT_VALUE_MAX + 1 and is deliberately not part of the UAPI value
range. That verdict tells every caller the action took ownership of the
skb, so nobody frees it: sch_handle_ingress(), sch_handle_egress() and
tcf_qevent_handle() all deliberately skip the free for it. The result is
one leaked sk_buff plus its data buffer per packet traversing the filter,
unbounded, for all traffic on the chain including kernel-generated
packets.
Both are trivially deterministic. act_gact clamps tcfg_pval to >= 1, so
with pval = 1 gact_determ() returns the fallback for every packet.
act_police has no mandatory rate, so rate = 0 leaves tcfp_mtu = ~0 and
tcf_police_mtu_check() always passes.
TC_ACT_CONSUMED was added by commit 720f22fed81b ("net: sched: refactor
reinsert action"), after both goto-chain guards were written:
commit 9469f375ab09 ("net/sched: act_gact: disallow 'goto chain' on
fallback control action") and
commit c08f5ed5d625 ("net/sched: act_police: disallow 'goto chain' on
fallback control action"). Neither guard was widened when the new
verdict appeared.
Factor the existing range test out of tcf_action_check_ctrlact() as
tcf_action_valid() and apply it to both fallbacks. The helper cannot call
tcf_action_check_ctrlact() directly because that also allocates a
goto_chain, which is exactly what these two sites must not do.
Reproduced on v7.2-rc6: kmemleak reports one leaked 232-byte
skbuff_head_cache object plus its 704-byte data buffer per packet. With
this patch both configurations are rejected with -EINVAL and kmemleak
reports none.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 720f22fed81bc6fd1765db7014651b6718887bea Version: 720f22fed81bc6fd1765db7014651b6718887bea Version: 720f22fed81bc6fd1765db7014651b6718887bea Version: 720f22fed81bc6fd1765db7014651b6718887bea Version: 720f22fed81bc6fd1765db7014651b6718887bea Version: 720f22fed81bc6fd1765db7014651b6718887bea Version: 720f22fed81bc6fd1765db7014651b6718887bea Version: 720f22fed81bc6fd1765db7014651b6718887bea |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"include/net/act_api.h",
"net/sched/act_gact.c",
"net/sched/act_police.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "5f038affdacaffedf6a85a06cf59ec0a852d36a7",
"status": "affected",
"version": "720f22fed81bc6fd1765db7014651b6718887bea",
"versionType": "git"
},
{
"lessThan": "efa58aeb6a99028b1fbc3ab2f31ba3a881211ad4",
"status": "affected",
"version": "720f22fed81bc6fd1765db7014651b6718887bea",
"versionType": "git"
},
{
"lessThan": "725efc2ab4a40affc4e285a2dc4896d103948a6c",
"status": "affected",
"version": "720f22fed81bc6fd1765db7014651b6718887bea",
"versionType": "git"
},
{
"lessThan": "6bcb8839aa2d686964a4154650afc4db91e1c514",
"status": "affected",
"version": "720f22fed81bc6fd1765db7014651b6718887bea",
"versionType": "git"
},
{
"lessThan": "5344e01179baa37547ab29fd7b8614f83faa190c",
"status": "affected",
"version": "720f22fed81bc6fd1765db7014651b6718887bea",
"versionType": "git"
},
{
"lessThan": "92f00f1d4d204a428b38e26fce3baee144b6955d",
"status": "affected",
"version": "720f22fed81bc6fd1765db7014651b6718887bea",
"versionType": "git"
},
{
"lessThan": "2e8df8c9190335475a3b64a159d3efd8cdd1cb73",
"status": "affected",
"version": "720f22fed81bc6fd1765db7014651b6718887bea",
"versionType": "git"
},
{
"lessThan": "883b56ae58fe657d8497806c7059646e9ba6dbd0",
"status": "affected",
"version": "720f22fed81bc6fd1765db7014651b6718887bea",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"include/net/act_api.h",
"net/sched/act_gact.c",
"net/sched/act_police.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.3"
},
{
"lessThan": "5.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: act_gact, act_police: range check the fallback control action\n\ntcf_action_check_ctrlact() range checks the primary control action:\n\n\tif (!opcode)\n\t\tret = action \u003e TC_ACT_VALUE_MAX ? -EINVAL : 0;\n\nTC_ACT_VALUE_MAX is TC_ACT_TRAP, so kernel-internal verdicts above it\ncannot be set that way. But act_gact and act_police each carry a second,\nindependent control action supplied by user space that never reaches that\nhelper - TCA_GACT_PROB.paction and TCA_POLICE_RESULT. Both only reject\nTC_ACT_GOTO_CHAIN, so any other value is stored verbatim and returned\nverbatim from the action.\n\nIn particular user space can store TC_ACT_CONSUMED, which is\nTC_ACT_VALUE_MAX + 1 and is deliberately not part of the UAPI value\nrange. That verdict tells every caller the action took ownership of the\nskb, so nobody frees it: sch_handle_ingress(), sch_handle_egress() and\ntcf_qevent_handle() all deliberately skip the free for it. The result is\none leaked sk_buff plus its data buffer per packet traversing the filter,\nunbounded, for all traffic on the chain including kernel-generated\npackets.\n\nBoth are trivially deterministic. act_gact clamps tcfg_pval to \u003e= 1, so\nwith pval = 1 gact_determ() returns the fallback for every packet.\nact_police has no mandatory rate, so rate = 0 leaves tcfp_mtu = ~0 and\ntcf_police_mtu_check() always passes.\n\nTC_ACT_CONSUMED was added by commit 720f22fed81b (\"net: sched: refactor\nreinsert action\"), after both goto-chain guards were written:\ncommit 9469f375ab09 (\"net/sched: act_gact: disallow \u0027goto chain\u0027 on\nfallback control action\") and\ncommit c08f5ed5d625 (\"net/sched: act_police: disallow \u0027goto chain\u0027 on\nfallback control action\"). Neither guard was widened when the new\nverdict appeared.\n\nFactor the existing range test out of tcf_action_check_ctrlact() as\ntcf_action_valid() and apply it to both fallbacks. The helper cannot call\ntcf_action_check_ctrlact() directly because that also allocates a\ngoto_chain, which is exactly what these two sites must not do.\n\nReproduced on v7.2-rc6: kmemleak reports one leaked 232-byte\nskbuff_head_cache object plus its 704-byte data buffer per packet. With\nthis patch both configurations are rejected with -EINVAL and kmemleak\nreports none."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:47:46.379Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/5f038affdacaffedf6a85a06cf59ec0a852d36a7"
},
{
"url": "https://git.kernel.org/stable/c/efa58aeb6a99028b1fbc3ab2f31ba3a881211ad4"
},
{
"url": "https://git.kernel.org/stable/c/725efc2ab4a40affc4e285a2dc4896d103948a6c"
},
{
"url": "https://git.kernel.org/stable/c/6bcb8839aa2d686964a4154650afc4db91e1c514"
},
{
"url": "https://git.kernel.org/stable/c/5344e01179baa37547ab29fd7b8614f83faa190c"
},
{
"url": "https://git.kernel.org/stable/c/92f00f1d4d204a428b38e26fce3baee144b6955d"
},
{
"url": "https://git.kernel.org/stable/c/2e8df8c9190335475a3b64a159d3efd8cdd1cb73"
},
{
"url": "https://git.kernel.org/stable/c/883b56ae58fe657d8497806c7059646e9ba6dbd0"
}
],
"title": "net/sched: act_gact, act_police: range check the fallback control action",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74620",
"datePublished": "2026-08-22T15:32:04.254Z",
"dateReserved": "2026-08-15T05:44:03.921Z",
"dateUpdated": "2026-08-23T12:47:46.379Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64561 (GCVE-0-2026-64561)
Vulnerability from cvelistv5
Published
2026-08-04 06:23
Modified
2026-08-27 12:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
KVM: x86: Check for invalid/obsolete root *after* making MMU pages available
Check for a "stale" page fault, i.e. for an invalid and/or obsolete root,
after making MMU pages available for the shadow MMU. If reclaiming shadow
pages zaps an in-use root, i.e. marks it invalid, then KVM will attempt to
map memory into an invalid root. On its own, populating an invalid root is
"fine", but because child shadow pages inherit their parent's role, any
children created during the map/fetch will be created as invalid pages,
thus violating KVM's invariant that invalid pages are never on the list of
active MMU pages.
Note, the underlying flaw has existed since KVM first started tracking
invalid roots in 2008 (commit 2e53d63acba7, "KVM: MMU: ignore zapped root
pagetables"), but the true badness only came along in 2020 (Linux 5.9)
with the invariant that invalid shadow pages can't be on the list of
active pages.
Note #2, inheriting role.invalid when creating child shadow pages is also
far from ideal; that flaw will be addressed separately.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: f95eec9bed76d42194c23153cb1cc8f186bf91cb Version: f95eec9bed76d42194c23153cb1cc8f186bf91cb Version: f95eec9bed76d42194c23153cb1cc8f186bf91cb Version: f95eec9bed76d42194c23153cb1cc8f186bf91cb Version: f95eec9bed76d42194c23153cb1cc8f186bf91cb Version: f95eec9bed76d42194c23153cb1cc8f186bf91cb Version: f95eec9bed76d42194c23153cb1cc8f186bf91cb |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"arch/x86/kvm/mmu/mmu.c",
"arch/x86/kvm/mmu/paging_tmpl.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "62ef67af1878fa2cd066642f2f59e33ade95f637",
"status": "affected",
"version": "f95eec9bed76d42194c23153cb1cc8f186bf91cb",
"versionType": "git"
},
{
"lessThan": "65c4f7a1028cf01a93a2762d679c289810ede990",
"status": "affected",
"version": "f95eec9bed76d42194c23153cb1cc8f186bf91cb",
"versionType": "git"
},
{
"lessThan": "35e77467610c4a37cb0ff54ee56b85f73b1f5700",
"status": "affected",
"version": "f95eec9bed76d42194c23153cb1cc8f186bf91cb",
"versionType": "git"
},
{
"lessThan": "0026dbb7de8ea76e97d6edf42fc3cc084564e2bf",
"status": "affected",
"version": "f95eec9bed76d42194c23153cb1cc8f186bf91cb",
"versionType": "git"
},
{
"lessThan": "f3477a6a4164f15287444eda685b5f6405dbd1e5",
"status": "affected",
"version": "f95eec9bed76d42194c23153cb1cc8f186bf91cb",
"versionType": "git"
},
{
"lessThan": "bce0d3c26e2c761a4bf43c8949f333fc7374eb2d",
"status": "affected",
"version": "f95eec9bed76d42194c23153cb1cc8f186bf91cb",
"versionType": "git"
},
{
"lessThan": "2abd5287f08319fa35764566b15c6e22cb1068db",
"status": "affected",
"version": "f95eec9bed76d42194c23153cb1cc8f186bf91cb",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"arch/x86/kvm/mmu/mmu.c",
"arch/x86/kvm/mmu/paging_tmpl.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.9"
},
{
"lessThan": "5.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.218",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.218",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: x86: Check for invalid/obsolete root *after* making MMU pages available\n\nCheck for a \"stale\" page fault, i.e. for an invalid and/or obsolete root,\nafter making MMU pages available for the shadow MMU. If reclaiming shadow\npages zaps an in-use root, i.e. marks it invalid, then KVM will attempt to\nmap memory into an invalid root. On its own, populating an invalid root is\n\"fine\", but because child shadow pages inherit their parent\u0027s role, any\nchildren created during the map/fetch will be created as invalid pages,\nthus violating KVM\u0027s invariant that invalid pages are never on the list of\nactive MMU pages.\n\nNote, the underlying flaw has existed since KVM first started tracking\ninvalid roots in 2008 (commit 2e53d63acba7, \"KVM: MMU: ignore zapped root\npagetables\"), but the true badness only came along in 2020 (Linux 5.9)\nwith the invariant that invalid shadow pages can\u0027t be on the list of\nactive pages.\n\nNote #2, inheriting role.invalid when creating child shadow pages is also\nfar from ideal; that flaw will be addressed separately."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable shadow-MMU page-fault path is reached via local KVM_RUN handling of guest EPT/shadow faults (and nested EPT via paging_tmpl), not by network or adjacent-radio packets.\nAC:L - An attacker who can run nested or shadow-MMU guests controls MMU pressure (heavy nested mappings and/or KVM_SET_NR_MMU_PAGES) and concurrent faults so reclaim zaps an in-use root during make_mmu_pages_available; no attacker-uncontrollable condition is required.\nPR:L - Exploitation needs /dev/kvm access or a nested-capable guest on the host, privileges commonly available to kvm-group users or cloud tenants, not real init-namespace root or CAP_SYS_ADMIN on the create/run path.\nUI:N - Once the attacker can run the guest, they trigger reclaim and page faults entirely through their own vCPU activity with no action by another user.\nS:C - Guest-controlled faults corrupt host KVM MMU state (invalid shadow pages on active_mmu_pages and subsequent list handling), crossing the guest-to-host virtualization boundary into the host kernel authority.\nC:H - Invalid children on active_mmu_pages break zap accounting assumptions so later prepare_zap list_add on still-linked entries corrupts kernel lists, a memory-corruption primitive that can be leveraged for arbitrary host reads.\nI:H - The same active-list invariant break and linked-list corruption in host MMU teardown/reclaim paths yield writable host corruption suitable for control-flow or structure hijacking, not merely a benign accounting glitch.\nA:H - WARN_ON_ONCE skips, infinite zap loops, list corruption, and host oops/hangs are reachable when invalid shadow pages remain on active_mmu_pages, causing host and co-located VM denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T12:39:43.193Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/62ef67af1878fa2cd066642f2f59e33ade95f637"
},
{
"url": "https://git.kernel.org/stable/c/65c4f7a1028cf01a93a2762d679c289810ede990"
},
{
"url": "https://git.kernel.org/stable/c/35e77467610c4a37cb0ff54ee56b85f73b1f5700"
},
{
"url": "https://git.kernel.org/stable/c/0026dbb7de8ea76e97d6edf42fc3cc084564e2bf"
},
{
"url": "https://git.kernel.org/stable/c/f3477a6a4164f15287444eda685b5f6405dbd1e5"
},
{
"url": "https://git.kernel.org/stable/c/bce0d3c26e2c761a4bf43c8949f333fc7374eb2d"
},
{
"url": "https://git.kernel.org/stable/c/2abd5287f08319fa35764566b15c6e22cb1068db"
},
{
"url": "https://github.com/V4bel/Zapscape"
}
],
"title": "KVM: x86: Check for invalid/obsolete root *after* making MMU pages available",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64561",
"datePublished": "2026-08-04T06:23:21.094Z",
"dateReserved": "2026-07-19T15:36:31.796Z",
"dateUpdated": "2026-08-27T12:39:43.193Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64571 (GCVE-0-2026-64571)
Vulnerability from cvelistv5
Published
2026-08-05 08:08
Modified
2026-08-19 16:28
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: p54: validate RX frame length in p54_rx_eeprom_readback()
p54_rx_eeprom_readback() copies the requested EEPROM slice out of a
device-supplied readback frame without checking that the skb actually holds
that many bytes. Commit da1b9a55ff11 ("wifi: p54: prevent buffer-overflow in
p54_rx_eeprom_readback()") closed the destination overflow by copying a
fixed priv->eeprom_slice_size (and rejecting a mismatched advertised len),
but the source side is still unbounded: nothing verifies the frame is long
enough to supply that many bytes.
A malicious USB device can send a short frame whose advertised len matches
priv->eeprom_slice_size while the payload is truncated. The equality check
passes and memcpy() reads past the end of the skb, leaking adjacent heap:
BUG: KASAN: slab-out-of-bounds in p54_rx (drivers/net/wireless/intersil/p54/txrx.c:507)
Read of size 1016 at addr ffff88800f077114 by task swapper/0/0
Call Trace:
<IRQ>
...
__asan_memcpy (mm/kasan/shadow.c:105)
p54_rx (drivers/net/wireless/intersil/p54/txrx.c:507)
p54u_rx_cb (drivers/net/wireless/intersil/p54/p54usb.c:163)
__usb_hcd_giveback_urb (drivers/usb/core/hcd.c:1657)
dummy_timer (drivers/usb/gadget/udc/dummy_hcd.c:2005)
...
</IRQ>
The buggy address belongs to the object at ffff88800f0770c0
which belongs to the cache skbuff_small_head of size 704
The buggy address is located 84 bytes inside of
allocated 704-byte region [ffff88800f0770c0, ffff88800f077380)
Check that the slice fits in the skb before copying.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 7cb770729ba895f73253dfcd46c3fcba45d896f9 Version: 7cb770729ba895f73253dfcd46c3fcba45d896f9 Version: 7cb770729ba895f73253dfcd46c3fcba45d896f9 Version: 7cb770729ba895f73253dfcd46c3fcba45d896f9 Version: 7cb770729ba895f73253dfcd46c3fcba45d896f9 Version: 7cb770729ba895f73253dfcd46c3fcba45d896f9 Version: 7cb770729ba895f73253dfcd46c3fcba45d896f9 Version: 7cb770729ba895f73253dfcd46c3fcba45d896f9 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/intersil/p54/txrx.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "7a456ffcd20bd92ad0ef46c1aaa0e39e3be1f7e7",
"status": "affected",
"version": "7cb770729ba895f73253dfcd46c3fcba45d896f9",
"versionType": "git"
},
{
"lessThan": "88f7044f92b8326fbfab26d0d8ed297c367ebb76",
"status": "affected",
"version": "7cb770729ba895f73253dfcd46c3fcba45d896f9",
"versionType": "git"
},
{
"lessThan": "f21b7e096fe5371bf697cd410537fb434a763f5e",
"status": "affected",
"version": "7cb770729ba895f73253dfcd46c3fcba45d896f9",
"versionType": "git"
},
{
"lessThan": "25c3b85af3fc4f8043159b14e65790fc3bbdaf48",
"status": "affected",
"version": "7cb770729ba895f73253dfcd46c3fcba45d896f9",
"versionType": "git"
},
{
"lessThan": "f46f8f9c43fd02f4dd5f716d4bda296a523c04f0",
"status": "affected",
"version": "7cb770729ba895f73253dfcd46c3fcba45d896f9",
"versionType": "git"
},
{
"lessThan": "d38f5d868a0a4770e3bcd0925e16c46acdbc9509",
"status": "affected",
"version": "7cb770729ba895f73253dfcd46c3fcba45d896f9",
"versionType": "git"
},
{
"lessThan": "9096e1f7014174067239a63df18ae5f28301990d",
"status": "affected",
"version": "7cb770729ba895f73253dfcd46c3fcba45d896f9",
"versionType": "git"
},
{
"lessThan": "ebd6d37fa94bee929e0b4c9ca19fdf9b1dcf6cea",
"status": "affected",
"version": "7cb770729ba895f73253dfcd46c3fcba45d896f9",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/intersil/p54/txrx.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.28"
},
{
"lessThan": "2.6.28",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.28",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: p54: validate RX frame length in p54_rx_eeprom_readback()\n\np54_rx_eeprom_readback() copies the requested EEPROM slice out of a\ndevice-supplied readback frame without checking that the skb actually holds\nthat many bytes. Commit da1b9a55ff11 (\"wifi: p54: prevent buffer-overflow in\np54_rx_eeprom_readback()\") closed the destination overflow by copying a\nfixed priv-\u003eeeprom_slice_size (and rejecting a mismatched advertised len),\nbut the source side is still unbounded: nothing verifies the frame is long\nenough to supply that many bytes.\n\nA malicious USB device can send a short frame whose advertised len matches\npriv-\u003eeeprom_slice_size while the payload is truncated. The equality check\npasses and memcpy() reads past the end of the skb, leaking adjacent heap:\n\n BUG: KASAN: slab-out-of-bounds in p54_rx (drivers/net/wireless/intersil/p54/txrx.c:507)\n Read of size 1016 at addr ffff88800f077114 by task swapper/0/0\n Call Trace:\n \u003cIRQ\u003e\n ...\n __asan_memcpy (mm/kasan/shadow.c:105)\n p54_rx (drivers/net/wireless/intersil/p54/txrx.c:507)\n p54u_rx_cb (drivers/net/wireless/intersil/p54/p54usb.c:163)\n __usb_hcd_giveback_urb (drivers/usb/core/hcd.c:1657)\n dummy_timer (drivers/usb/gadget/udc/dummy_hcd.c:2005)\n ...\n \u003c/IRQ\u003e\n\n The buggy address belongs to the object at ffff88800f0770c0\n which belongs to the cache skbuff_small_head of size 704\n The buggy address is located 84 bytes inside of\n allocated 704-byte region [ffff88800f0770c0, ffff88800f077380)\n\nCheck that the slice fits in the skb before copying."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:28:46.775Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/7a456ffcd20bd92ad0ef46c1aaa0e39e3be1f7e7"
},
{
"url": "https://git.kernel.org/stable/c/88f7044f92b8326fbfab26d0d8ed297c367ebb76"
},
{
"url": "https://git.kernel.org/stable/c/f21b7e096fe5371bf697cd410537fb434a763f5e"
},
{
"url": "https://git.kernel.org/stable/c/25c3b85af3fc4f8043159b14e65790fc3bbdaf48"
},
{
"url": "https://git.kernel.org/stable/c/f46f8f9c43fd02f4dd5f716d4bda296a523c04f0"
},
{
"url": "https://git.kernel.org/stable/c/d38f5d868a0a4770e3bcd0925e16c46acdbc9509"
},
{
"url": "https://git.kernel.org/stable/c/9096e1f7014174067239a63df18ae5f28301990d"
},
{
"url": "https://git.kernel.org/stable/c/ebd6d37fa94bee929e0b4c9ca19fdf9b1dcf6cea"
}
],
"title": "wifi: p54: validate RX frame length in p54_rx_eeprom_readback()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64571",
"datePublished": "2026-08-05T08:08:08.466Z",
"dateReserved": "2026-07-19T15:36:31.797Z",
"dateUpdated": "2026-08-19T16:28:46.775Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74603 (GCVE-0-2026-74603)
Vulnerability from cvelistv5
Published
2026-08-22 15:31
Modified
2026-08-25 05:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ptp: ocp: Fix board ID over-read
The EEPROM board ID is a fixed 13-byte field and is not guaranteed to
contain a NUL terminator. Passing it directly to
devlink_info_version_fixed_put() treats it as a C string and may read
beyond the field.
Format at most OCP_BOARD_ID_LEN bytes into the existing local buffer
before reporting the ID. Use a precision limit because the snprintf()
output size alone does not bound the source string scan.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 0cfcdd1ebcfe1a9b262f6ad8419580720dc843c4 Version: 0cfcdd1ebcfe1a9b262f6ad8419580720dc843c4 Version: 0cfcdd1ebcfe1a9b262f6ad8419580720dc843c4 Version: 0cfcdd1ebcfe1a9b262f6ad8419580720dc843c4 Version: 0cfcdd1ebcfe1a9b262f6ad8419580720dc843c4 Version: 0cfcdd1ebcfe1a9b262f6ad8419580720dc843c4 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/ptp/ptp_ocp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "72ef3ce80078199bfad32f98d055f44ba7cd0c3d",
"status": "affected",
"version": "0cfcdd1ebcfe1a9b262f6ad8419580720dc843c4",
"versionType": "git"
},
{
"lessThan": "3d965811be78473654e6e8cc8e4fb7b6b87aa6c1",
"status": "affected",
"version": "0cfcdd1ebcfe1a9b262f6ad8419580720dc843c4",
"versionType": "git"
},
{
"lessThan": "f92558bbe78d6284fedd053900f82a70f0aa8707",
"status": "affected",
"version": "0cfcdd1ebcfe1a9b262f6ad8419580720dc843c4",
"versionType": "git"
},
{
"lessThan": "5fd91dd4a143479b0575fb1f202ec1c501e71fd5",
"status": "affected",
"version": "0cfcdd1ebcfe1a9b262f6ad8419580720dc843c4",
"versionType": "git"
},
{
"lessThan": "f8d7e5751267637190eff887c971d5b468106213",
"status": "affected",
"version": "0cfcdd1ebcfe1a9b262f6ad8419580720dc843c4",
"versionType": "git"
},
{
"lessThan": "6b69f2ef10cdb018c0b127a7cab88e590bbddba4",
"status": "affected",
"version": "0cfcdd1ebcfe1a9b262f6ad8419580720dc843c4",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/ptp/ptp_ocp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.18"
},
{
"lessThan": "5.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.18",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nptp: ocp: Fix board ID over-read\n\nThe EEPROM board ID is a fixed 13-byte field and is not guaranteed to\ncontain a NUL terminator. Passing it directly to\ndevlink_info_version_fixed_put() treats it as a C string and may read\nbeyond the field.\n\nFormat at most OCP_BOARD_ID_LEN bytes into the existing local buffer\nbefore reporting the ID. Use a precision limit because the snprintf()\noutput size alone does not bound the source string scan."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable code is reached only through the devlink generic-netlink interface (DEVLINK_CMD_INFO_GET) via a local socket; ptp_ocp is a PCI PTP timecard driver with no network, Bluetooth, or physical-device input path to ptp_ocp_devlink_info_get().\nAC:L - On a system with a probed OCP timecard, issuing devlink info deterministically calls ptp_ocp_devlink_info_get() and passes the 13-byte EEPROM board_id that is not guaranteed to be NUL-terminated, so the over-read is reliably triggered without races or attacker-uncontrollable layout.\nPR:L - DEVLINK_CMD_INFO_GET is registered with only GENL_CMD_CAP_DO/GENL_CMD_CAP_DUMP and no GENL_ADMIN_PERM, and devlink_nl_pre_doit() adds no capability check, so any unprivileged local user with generic netlink access can invoke the vulnerable handler.\nUI:N - Exploitation requires only the attacker issuing a devlink info netlink request; no administrator or other user action is needed beyond the attacker having local access to the host.\nS:U - Kernel memory disclosure and any resulting crash are confined to the same host kernel; the bug does not cross VM, IOMMU, or sandbox security boundaries.\nC:H - Passing the non-NUL-terminated board_id to devlink_info_version_fixed_put() makes devlink_info_version_put() and nla_put_string() use strlen(), reading past the 13-byte field through adjacent ptp_ocp/devlink private memory and returning leaked bytes in the netlink reply to the caller.\nI:N - The defect is purely an out-of-bounds kernel read with no write, heap corruption, or control-flow hijack primitive; only kernel memory is scanned and copied into the netlink response.\nA:H - strlen() on the unterminated board_id can walk through subsequent kmalloc-backed struct fields and potentially past the devlink private allocation, touching unmapped pages and oopsing/panicking the kernel; an unprivileged user can repeat the devlink info query to retrigger it."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:40:27.399Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/72ef3ce80078199bfad32f98d055f44ba7cd0c3d"
},
{
"url": "https://git.kernel.org/stable/c/3d965811be78473654e6e8cc8e4fb7b6b87aa6c1"
},
{
"url": "https://git.kernel.org/stable/c/f92558bbe78d6284fedd053900f82a70f0aa8707"
},
{
"url": "https://git.kernel.org/stable/c/5fd91dd4a143479b0575fb1f202ec1c501e71fd5"
},
{
"url": "https://git.kernel.org/stable/c/f8d7e5751267637190eff887c971d5b468106213"
},
{
"url": "https://git.kernel.org/stable/c/6b69f2ef10cdb018c0b127a7cab88e590bbddba4"
}
],
"title": "ptp: ocp: Fix board ID over-read",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74603",
"datePublished": "2026-08-22T15:31:51.544Z",
"dateReserved": "2026-08-15T05:44:03.919Z",
"dateUpdated": "2026-08-25T05:40:27.399Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64578 (GCVE-0-2026-64578)
Vulnerability from cvelistv5
Published
2026-08-05 08:09
Modified
2026-08-19 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: validate compound request size before reading StructureSize2
When ksmbd validates a compound (chained) SMB2 request,
ksmbd_smb2_check_message() reads pdu->StructureSize2 without first
checking that the compound element is large enough to contain it.
StructureSize2 is a 2-byte field at offset 64
(__SMB2_HEADER_STRUCTURE_SIZE) from the start of each element.
The compound-walking logic only guarantees that a full 64-byte SMB2
header is present for the trailing element: when NextCommand is 0, len is
reduced to the number of bytes remaining after next_smb2_rcv_hdr_off. A
remote client can craft a compound request whose last element has exactly
64 bytes, so the 2-byte StructureSize2 read at offset 64 extends one byte
past the receive buffer, producing a slab-out-of-bounds read.
BUG: KASAN: slab-out-of-bounds in ksmbd_smb2_check_message (fs/smb/server/smb2misc.c:402)
Read of size 2 at addr ffff888012ae31ac by task kworker/0:1/14
The buggy address is located 172 bytes inside of allocated 173-byte region
Workqueue: ksmbd-io handle_ksmbd_work
Call Trace:
...
kasan_report (mm/kasan/report.c:595)
ksmbd_smb2_check_message (fs/smb/server/smb2misc.c:402)
handle_ksmbd_work (fs/smb/server/server.c:119)
process_one_work (kernel/workqueue.c:3314)
worker_thread (kernel/workqueue.c:3397)
kthread (kernel/kthread.c:436)
ret_from_fork (arch/x86/kernel/process.c:158)
ret_from_fork_asm (arch/x86/entry/entry_64.S:245)
Reject any compound element that is too small to hold StructureSize2
before dereferencing it.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 Version: e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 Version: e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 Version: e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 Version: e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 Version: e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 Version: e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/smb/server/smb2misc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "415d0fff0451ad7ad4caa910f2bb0f562f0fd60f",
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"versionType": "git"
},
{
"lessThan": "1b6740525f5af90868d557c31b496ae689c8c549",
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"versionType": "git"
},
{
"lessThan": "2c307126ed8e7adddab82b8e31d962d3a2156ab1",
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"versionType": "git"
},
{
"lessThan": "f7550a91ab211726f59cb137523b7a9eae1ac6eb",
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"versionType": "git"
},
{
"lessThan": "f0e337e7db67cc1c832958bbb6c4026bdceacfdb",
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"versionType": "git"
},
{
"lessThan": "ea128f06d2fb2186f0cac0c9f3e953e4d1f5c29a",
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"versionType": "git"
},
{
"lessThan": "15b38176fd1530372905c602fde51fe89ec8c877",
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/smb/server/smb2misc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.15"
},
{
"lessThan": "5.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: validate compound request size before reading StructureSize2\n\nWhen ksmbd validates a compound (chained) SMB2 request,\nksmbd_smb2_check_message() reads pdu-\u003eStructureSize2 without first\nchecking that the compound element is large enough to contain it.\nStructureSize2 is a 2-byte field at offset 64\n(__SMB2_HEADER_STRUCTURE_SIZE) from the start of each element.\n\nThe compound-walking logic only guarantees that a full 64-byte SMB2\nheader is present for the trailing element: when NextCommand is 0, len is\nreduced to the number of bytes remaining after next_smb2_rcv_hdr_off. A\nremote client can craft a compound request whose last element has exactly\n64 bytes, so the 2-byte StructureSize2 read at offset 64 extends one byte\npast the receive buffer, producing a slab-out-of-bounds read.\n\n BUG: KASAN: slab-out-of-bounds in ksmbd_smb2_check_message (fs/smb/server/smb2misc.c:402)\n Read of size 2 at addr ffff888012ae31ac by task kworker/0:1/14\n The buggy address is located 172 bytes inside of allocated 173-byte region\n Workqueue: ksmbd-io handle_ksmbd_work\n Call Trace:\n ...\n kasan_report (mm/kasan/report.c:595)\n ksmbd_smb2_check_message (fs/smb/server/smb2misc.c:402)\n handle_ksmbd_work (fs/smb/server/server.c:119)\n process_one_work (kernel/workqueue.c:3314)\n worker_thread (kernel/workqueue.c:3397)\n kthread (kernel/kthread.c:436)\n ret_from_fork (arch/x86/kernel/process.c:158)\n ret_from_fork_asm (arch/x86/entry/entry_64.S:245)\n\nReject any compound element that is too small to hold StructureSize2\nbefore dereferencing it."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.2,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - ksmbd is an in-kernel SMB server reached over TCP/445; a remote client triggers the bug by sending a crafted compound SMB2 request that is processed in handle_ksmbd_work() \u2192 ksmbd_verify_smb_message() \u2192 ksmbd_smb2_check_message().\nAC:L - The attacker fully controls compound layout and can set the trailing element\u0027s remaining length to exactly 64 bytes so StructureSize2 is read one byte past the receive buffer; no race or attacker-uncontrollable condition is required.\nPR:N - On affected kernels before the compound SESSION_VALID check, a compound NtLmNegotiate SESSION_SETUP (pre-auth, no credentials) sets work-\u003esess and the trailing element still reaches ksmbd_smb2_check_message(); guest/anonymous SESSION_SETUP likewise needs no host privileges.\nUI:N - Exploitation requires only attacker-sent SMB2 protocol traffic to a listening ksmbd service; no victim user action is needed.\nS:U - The out-of-bounds read and any resulting kernel impact occur in the host ksmbd/workqueue context and do not cross a VM, IOMMU, or other security-authority boundary.\nC:L - The flaw is a strictly bounded slab out-of-bounds read of one byte past the receive buffer (2-byte StructureSize2 at offset 64 when only 64 bytes remain); it may disclose adjacent slab contents but not an arbitrary read primitive.\nI:N - The bug only reads past the buffer for a StructureSize2 comparison; for a 64-byte trailing element every valid command size is then rejected, and there is no out-of-bounds write or other modification primitive.\nA:H - KASAN reports a slab-out-of-bounds BUG in ksmbd_smb2_check_message(), and the same access can oops/panic hardened or redzone-enabled kernels; a remote peer can retrigger it with further crafted compound requests."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:29:02.136Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/415d0fff0451ad7ad4caa910f2bb0f562f0fd60f"
},
{
"url": "https://git.kernel.org/stable/c/1b6740525f5af90868d557c31b496ae689c8c549"
},
{
"url": "https://git.kernel.org/stable/c/2c307126ed8e7adddab82b8e31d962d3a2156ab1"
},
{
"url": "https://git.kernel.org/stable/c/f7550a91ab211726f59cb137523b7a9eae1ac6eb"
},
{
"url": "https://git.kernel.org/stable/c/f0e337e7db67cc1c832958bbb6c4026bdceacfdb"
},
{
"url": "https://git.kernel.org/stable/c/ea128f06d2fb2186f0cac0c9f3e953e4d1f5c29a"
},
{
"url": "https://git.kernel.org/stable/c/15b38176fd1530372905c602fde51fe89ec8c877"
}
],
"title": "ksmbd: validate compound request size before reading StructureSize2",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64578",
"datePublished": "2026-08-05T08:09:33.740Z",
"dateReserved": "2026-07-19T15:36:31.798Z",
"dateUpdated": "2026-08-19T16:29:02.136Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68184 (GCVE-0-2026-68184)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
cdrom: fix stack out-of-bounds read in CDROMVOLCTRL
mmc_ioctl_cdrom_volume() first reads the audio control mode page into a
32-byte stack buffer with cgc->buflen set to 24. If the device reports a
block descriptor, the function increases cgc->buflen to include that
descriptor and reads the page again.
For CDROMVOLCTRL, the function then builds a MODE SELECT parameter list
by moving cgc->buffer forward by offset - 8 bytes. This drops the block
descriptor from the outgoing payload and leaves a new 8-byte mode
parameter header in front of the audio control page. However, cgc->buflen
is left unchanged.
With a standard 8-byte block descriptor, cgc->buffer points at buffer + 8
but cgc->buflen remains 32. cdrom_mode_select() therefore asks the low
level packet path to write 32 bytes from that adjusted pointer, reading 8
bytes past the end of the 32-byte stack buffer.
This is not hit by CDROMVOLREAD, and CDROMVOLCTRL only triggers it on
drives that return a non-zero block descriptor length, which helps explain
why it has gone unnoticed. The overread is also sent to the device as
extra MODE SELECT payload, so it may not produce an obvious local failure.
Reduce cgc->buflen by the same amount as the buffer pointer adjustment so
the MODE SELECT transfer covers only the intended parameter list.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/cdrom/cdrom.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "45c65df5339deea3cf204902aac383fe995941a7",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "0329b661349f42f9616f2733da67edffbbb8455d",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "e150c9a10baee55d3bfbc96dbe66b205e8b4fd44",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "7344c84e32413e5c8832f74b8a612b0194e5c051",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "35b68e24c5a69fa4545f46f05f6c849223034cb6",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "d43c5c0c935522deae7339e0c2399365f3bf0016",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "f3e2715a150066f09aa82c30fa983fb184ad6dd5",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "b27e195d4db8dea263050bdbeb11881b2999c9c6",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/cdrom/cdrom.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncdrom: fix stack out-of-bounds read in CDROMVOLCTRL\n\nmmc_ioctl_cdrom_volume() first reads the audio control mode page into a\n32-byte stack buffer with cgc-\u003ebuflen set to 24. If the device reports a\nblock descriptor, the function increases cgc-\u003ebuflen to include that\ndescriptor and reads the page again.\n\nFor CDROMVOLCTRL, the function then builds a MODE SELECT parameter list\nby moving cgc-\u003ebuffer forward by offset - 8 bytes. This drops the block\ndescriptor from the outgoing payload and leaves a new 8-byte mode\nparameter header in front of the audio control page. However, cgc-\u003ebuflen\nis left unchanged.\n\nWith a standard 8-byte block descriptor, cgc-\u003ebuffer points at buffer + 8\nbut cgc-\u003ebuflen remains 32. cdrom_mode_select() therefore asks the low\nlevel packet path to write 32 bytes from that adjusted pointer, reading 8\nbytes past the end of the 32-byte stack buffer.\n\nThis is not hit by CDROMVOLREAD, and CDROMVOLCTRL only triggers it on\ndrives that return a non-zero block descriptor length, which helps explain\nwhy it has gone unnoticed. The overread is also sent to the device as\nextra MODE SELECT payload, so it may not produce an obvious local failure.\n\nReduce cgc-\u003ebuflen by the same amount as the buffer pointer adjustment so\nthe MODE SELECT transfer covers only the intended parameter list."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:30:51.908Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/45c65df5339deea3cf204902aac383fe995941a7"
},
{
"url": "https://git.kernel.org/stable/c/0329b661349f42f9616f2733da67edffbbb8455d"
},
{
"url": "https://git.kernel.org/stable/c/e150c9a10baee55d3bfbc96dbe66b205e8b4fd44"
},
{
"url": "https://git.kernel.org/stable/c/7344c84e32413e5c8832f74b8a612b0194e5c051"
},
{
"url": "https://git.kernel.org/stable/c/35b68e24c5a69fa4545f46f05f6c849223034cb6"
},
{
"url": "https://git.kernel.org/stable/c/d43c5c0c935522deae7339e0c2399365f3bf0016"
},
{
"url": "https://git.kernel.org/stable/c/f3e2715a150066f09aa82c30fa983fb184ad6dd5"
},
{
"url": "https://git.kernel.org/stable/c/b27e195d4db8dea263050bdbeb11881b2999c9c6"
}
],
"title": "cdrom: fix stack out-of-bounds read in CDROMVOLCTRL",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68184",
"datePublished": "2026-08-10T11:59:56.319Z",
"dateReserved": "2026-07-30T09:28:09.373Z",
"dateUpdated": "2026-08-19T16:30:51.908Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74490 (GCVE-0-2026-74490)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-19 16:37
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
tipc: avoid use-after-free in poll trace queue dumps
TIPC socket tracepoints dump queue state through tipc_sk_dump(). Most
queue-dump callsites already serialize that walk under the socket lock or
sk->sk_lock.slock, but tipc_poll() calls trace_tipc_sk_poll(...,
TIPC_DUMP_ALL, ...) without holding either lock.
That lets the poll trace path reach tipc_list_dump() and backlog head/tail
dumping while another context dequeues and frees an skb, leaving the trace
helper dereferencing a stale queue entry.
Stop the unlocked poll trace site from requesting queue dumps. Other queue
dump trace callsites keep their existing output under the locking they
already provide, while poll still emits the event itself without walking
live queue members from an unlocked context.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: b4b9771bcbbd5839b0f77aba55e2f85989ed6779 Version: b4b9771bcbbd5839b0f77aba55e2f85989ed6779 Version: b4b9771bcbbd5839b0f77aba55e2f85989ed6779 Version: b4b9771bcbbd5839b0f77aba55e2f85989ed6779 Version: b4b9771bcbbd5839b0f77aba55e2f85989ed6779 Version: b4b9771bcbbd5839b0f77aba55e2f85989ed6779 Version: b4b9771bcbbd5839b0f77aba55e2f85989ed6779 Version: b4b9771bcbbd5839b0f77aba55e2f85989ed6779 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/tipc/socket.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "3cd57c6b210d50fd1f7ac1720442ba5be5dc94f8",
"status": "affected",
"version": "b4b9771bcbbd5839b0f77aba55e2f85989ed6779",
"versionType": "git"
},
{
"lessThan": "ae7fc824970888b4fdaa076819c9a6f2fcede275",
"status": "affected",
"version": "b4b9771bcbbd5839b0f77aba55e2f85989ed6779",
"versionType": "git"
},
{
"lessThan": "78706367fe1b98aee0a6de27c62b7f1e3035f38d",
"status": "affected",
"version": "b4b9771bcbbd5839b0f77aba55e2f85989ed6779",
"versionType": "git"
},
{
"lessThan": "d7940bb6a8e7ab28f972c2875cb05783216312dc",
"status": "affected",
"version": "b4b9771bcbbd5839b0f77aba55e2f85989ed6779",
"versionType": "git"
},
{
"lessThan": "5e82beba4bc1f91d0e64c9c43f2b2fa9cd1c2a7d",
"status": "affected",
"version": "b4b9771bcbbd5839b0f77aba55e2f85989ed6779",
"versionType": "git"
},
{
"lessThan": "bed792737b5f1ba773054dbe984502958bdfe6ce",
"status": "affected",
"version": "b4b9771bcbbd5839b0f77aba55e2f85989ed6779",
"versionType": "git"
},
{
"lessThan": "ac2f787980fdf4364cd5651a4c8128e59b8de3aa",
"status": "affected",
"version": "b4b9771bcbbd5839b0f77aba55e2f85989ed6779",
"versionType": "git"
},
{
"lessThan": "b4f1719dfea023220e0e6bd892b087d76b2a6a49",
"status": "affected",
"version": "b4b9771bcbbd5839b0f77aba55e2f85989ed6779",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/tipc/socket.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.0"
},
{
"lessThan": "5.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: avoid use-after-free in poll trace queue dumps\n\nTIPC socket tracepoints dump queue state through tipc_sk_dump(). Most\nqueue-dump callsites already serialize that walk under the socket lock or\nsk-\u003esk_lock.slock, but tipc_poll() calls trace_tipc_sk_poll(...,\nTIPC_DUMP_ALL, ...) without holding either lock.\n\nThat lets the poll trace path reach tipc_list_dump() and backlog head/tail\ndumping while another context dequeues and frees an skb, leaving the trace\nhelper dereferencing a stale queue entry.\n\nStop the unlocked poll trace site from requesting queue dumps. Other queue\ndump trace callsites keep their existing output under the locking they\nalready provide, while poll still emits the event itself without walking\nlive queue members from an unlocked context."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The UAF is a race between tipc_poll()\u0027s unlocked trace queue walk and concurrent skb dequeue/free on the TIPC receive path; on cluster nodes a remote TIPC peer can supply the freeing side while poll/epoll runs on the victim socket processing that network traffic.\nAC:L - The attacker controls both sides of the race by concurrently polling/epolling a TIPC socket while sending/receiving TIPC traffic (or having a remote peer deliver packets), and can repeat attempts until the unlocked head/tail dump overlaps skb free.\nPR:L - Exploitation requires only an unprivileged local process with an AF_TIPC socket calling poll/epoll while TIPC traffic is processed; no real-root capability is needed beyond participation in an operational TIPC cluster where tracing may be enabled for diagnostics.\nUI:N - No end-user interaction is required; the race is triggered by normal daemon poll/epoll loops and incoming TIPC packet processing on cluster nodes.\nS:U - Impact is confined to kernel memory corruption and privilege boundaries within the host kernel; this is not a cross-VM or cross-container sandbox escape scenario.\nC:H - The bug is a use-after-free where tipc_list_dump()/tipc_skb_dump() dereference head/tail skbs after concurrent dequeue/kfree, enabling reads of freed skb and message memory usable for kernel information disclosure.\nI:H - UAF on skb queue entries can be leveraged with heap grooming for arbitrary kernel writes and control-flow hijack, not merely a benign crash, because freed skbs can be reallocated under attacker-influenced TIPC traffic.\nA:H - Accessing freed skbs from the poll trace path can cause kernel oops/panic or hang during tipc_skb_dump(), and repeated triggering yields reliable denial of service on affected cluster nodes."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:37:45.610Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/3cd57c6b210d50fd1f7ac1720442ba5be5dc94f8"
},
{
"url": "https://git.kernel.org/stable/c/ae7fc824970888b4fdaa076819c9a6f2fcede275"
},
{
"url": "https://git.kernel.org/stable/c/78706367fe1b98aee0a6de27c62b7f1e3035f38d"
},
{
"url": "https://git.kernel.org/stable/c/d7940bb6a8e7ab28f972c2875cb05783216312dc"
},
{
"url": "https://git.kernel.org/stable/c/5e82beba4bc1f91d0e64c9c43f2b2fa9cd1c2a7d"
},
{
"url": "https://git.kernel.org/stable/c/bed792737b5f1ba773054dbe984502958bdfe6ce"
},
{
"url": "https://git.kernel.org/stable/c/ac2f787980fdf4364cd5651a4c8128e59b8de3aa"
},
{
"url": "https://git.kernel.org/stable/c/b4f1719dfea023220e0e6bd892b087d76b2a6a49"
}
],
"title": "tipc: avoid use-after-free in poll trace queue dumps",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74490",
"datePublished": "2026-08-15T12:27:20.107Z",
"dateReserved": "2026-08-15T05:44:03.905Z",
"dateUpdated": "2026-08-19T16:37:45.610Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80797 (GCVE-0-2026-80797)
Vulnerability from cvelistv5
Published
2026-09-04 15:13
Modified
2026-09-04 15:13
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
nfc: pn533: purge fragmented skbs during cleanup
pn53x_common_clean() purges resp_q before freeing the common PN533 state,
but it leaves fragment_skb untouched. The fragmentation helpers queue
transmit fragments there while sending large initiator or target-mode
frames, and those skbs remain owned by the driver until they are sent or
discarded.
If the device is removed while fragments are still queued, the common
cleanup path frees the PN533 state without releasing the queued fragment
skbs, leaking them.
Purge fragment_skb during cleanup alongside resp_q.
References
| URL | Tags | ||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 963a82e07d4e1f95fc423d53912ac0a7fe643b1c Version: 963a82e07d4e1f95fc423d53912ac0a7fe643b1c Version: 963a82e07d4e1f95fc423d53912ac0a7fe643b1c Version: 963a82e07d4e1f95fc423d53912ac0a7fe643b1c Version: 963a82e07d4e1f95fc423d53912ac0a7fe643b1c Version: 963a82e07d4e1f95fc423d53912ac0a7fe643b1c Version: 963a82e07d4e1f95fc423d53912ac0a7fe643b1c Version: 963a82e07d4e1f95fc423d53912ac0a7fe643b1c Version: 963a82e07d4e1f95fc423d53912ac0a7fe643b1c |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/nfc/pn533/pn533.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "130b5ad4492f8e53d0398ee3af2b0e2388504d11",
"status": "affected",
"version": "963a82e07d4e1f95fc423d53912ac0a7fe643b1c",
"versionType": "git"
},
{
"lessThan": "9319c3c4962efc8697246b563ea31c6d47f085aa",
"status": "affected",
"version": "963a82e07d4e1f95fc423d53912ac0a7fe643b1c",
"versionType": "git"
},
{
"lessThan": "d63e85c5d5555fe6aa65155d3a09452597e163c3",
"status": "affected",
"version": "963a82e07d4e1f95fc423d53912ac0a7fe643b1c",
"versionType": "git"
},
{
"lessThan": "4a52ec2457ff8c26206fcc20fa1972cc35a678c4",
"status": "affected",
"version": "963a82e07d4e1f95fc423d53912ac0a7fe643b1c",
"versionType": "git"
},
{
"lessThan": "e169277281373818ae1cedf976aa1e99118fb77d",
"status": "affected",
"version": "963a82e07d4e1f95fc423d53912ac0a7fe643b1c",
"versionType": "git"
},
{
"lessThan": "2f5d093194ec24d7c29b91bf7df014924e0f4ea1",
"status": "affected",
"version": "963a82e07d4e1f95fc423d53912ac0a7fe643b1c",
"versionType": "git"
},
{
"lessThan": "e7ed2ea5590fbe2d3be39ee4fb0c758a12e31d0c",
"status": "affected",
"version": "963a82e07d4e1f95fc423d53912ac0a7fe643b1c",
"versionType": "git"
},
{
"lessThan": "e95beff58b38c871c557bf84e528408283c2c0ad",
"status": "affected",
"version": "963a82e07d4e1f95fc423d53912ac0a7fe643b1c",
"versionType": "git"
},
{
"lessThan": "5718fc62198c38c2de5316020a90506f9e75e0bb",
"status": "affected",
"version": "963a82e07d4e1f95fc423d53912ac0a7fe643b1c",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/nfc/pn533/pn533.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.12"
},
{
"lessThan": "3.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.267",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.218",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.185",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.154",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.106",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.47",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.1",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.267",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.218",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.185",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.154",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.106",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.47",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.11",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.1",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "3.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: pn533: purge fragmented skbs during cleanup\n\npn53x_common_clean() purges resp_q before freeing the common PN533 state,\nbut it leaves fragment_skb untouched. The fragmentation helpers queue\ntransmit fragments there while sending large initiator or target-mode\nframes, and those skbs remain owned by the driver until they are sent or\ndiscarded.\n\nIf the device is removed while fragments are still queued, the common\ncleanup path frees the PN533 state without releasing the queued fragment\nskbs, leaking them.\n\nPurge fragment_skb during cleanup alongside resp_q."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T15:13:10.911Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/130b5ad4492f8e53d0398ee3af2b0e2388504d11"
},
{
"url": "https://git.kernel.org/stable/c/9319c3c4962efc8697246b563ea31c6d47f085aa"
},
{
"url": "https://git.kernel.org/stable/c/d63e85c5d5555fe6aa65155d3a09452597e163c3"
},
{
"url": "https://git.kernel.org/stable/c/4a52ec2457ff8c26206fcc20fa1972cc35a678c4"
},
{
"url": "https://git.kernel.org/stable/c/e169277281373818ae1cedf976aa1e99118fb77d"
},
{
"url": "https://git.kernel.org/stable/c/2f5d093194ec24d7c29b91bf7df014924e0f4ea1"
},
{
"url": "https://git.kernel.org/stable/c/e7ed2ea5590fbe2d3be39ee4fb0c758a12e31d0c"
},
{
"url": "https://git.kernel.org/stable/c/e95beff58b38c871c557bf84e528408283c2c0ad"
},
{
"url": "https://git.kernel.org/stable/c/5718fc62198c38c2de5316020a90506f9e75e0bb"
}
],
"title": "nfc: pn533: purge fragmented skbs during cleanup",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80797",
"datePublished": "2026-09-04T15:13:10.911Z",
"dateReserved": "2026-08-26T14:34:25.793Z",
"dateUpdated": "2026-09-04T15:13:10.911Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-53090 (GCVE-0-2026-53090)
Vulnerability from cvelistv5
Published
2026-06-24 16:30
Modified
2026-08-19 16:28
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
bpf: Fix ld_{abs,ind} failure path analysis in subprogs
Usage of ld_{abs,ind} instructions got extended into subprogs some time
ago via commit 09b28d76eac4 ("bpf: Add abnormal return checks."). These
are only allowed in subprograms when the latter are BTF annotated and
have scalar return types.
The code generator in bpf_gen_ld_abs() has an abnormal exit path (r0=0 +
exit) from legacy cBPF times. While the enforcement is on scalar return
types, the verifier must also simulate the path of abnormal exit if the
packet data load via ld_{abs,ind} failed.
This is currently not the case. Fix it by having the verifier simulate
both success and failure paths, and extend it in similar ways as we do
for tail calls. The success path (r0=unknown, continue to next insn) is
pushed onto stack for later validation and the r0=0 and return to the
caller is done on the fall-through side.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 09b28d76eac48e922dc293da1aa2b2b85c32aeee Version: 09b28d76eac48e922dc293da1aa2b2b85c32aeee Version: 09b28d76eac48e922dc293da1aa2b2b85c32aeee Version: 09b28d76eac48e922dc293da1aa2b2b85c32aeee Version: 09b28d76eac48e922dc293da1aa2b2b85c32aeee Version: 09b28d76eac48e922dc293da1aa2b2b85c32aeee Version: 09b28d76eac48e922dc293da1aa2b2b85c32aeee Version: 09b28d76eac48e922dc293da1aa2b2b85c32aeee |
||
{
"containers": {
"adp": [
{
"affected": [
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:10"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 10",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:6"
],
"defaultStatus": "unaffected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 6",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:7"
],
"defaultStatus": "unaffected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 7",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:7"
],
"defaultStatus": "unaffected",
"packageName": "kernel-rt",
"product": "Red Hat Enterprise Linux 7",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:8"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 8",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:8"
],
"defaultStatus": "affected",
"packageName": "kernel-rt",
"product": "Red Hat Enterprise Linux 8",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:9"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 9",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:9"
],
"defaultStatus": "affected",
"packageName": "kernel-rt",
"product": "Red Hat Enterprise Linux 9",
"vendor": "Red Hat"
}
],
"datePublic": "2026-06-24T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "A flaw was found in the Linux kernel\u0027s Berkeley Packet Filter (BPF) verifier. When `ld_{abs,ind}` instructions are used in BPF subprograms, the verifier fails to correctly simulate the abnormal exit path if packet data loading fails. This oversight could lead to unexpected behavior or bypass of security checks within the BPF execution environment."
}
],
"metrics": [
{
"other": {
"content": {
"namespace": "https://access.redhat.com/security/updates/classification/",
"value": "Moderate"
},
"type": "Red Hat severity rating"
}
},
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 6.4,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "HIGH",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-253",
"description": "Incorrect Check of Function Return Value",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-07-15T00:45:02.069Z",
"orgId": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
"shortName": "redhat-SADP"
},
"references": [
{
"tags": [
"vdb-entry",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/security/cve/CVE-2026-53090"
},
{
"name": "RHBZ#2492305",
"tags": [
"issue-tracking",
"x_refsource_REDHAT"
],
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492305"
},
{
"tags": [
"x_sadp-csaf-vex"
],
"url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53090.json"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-06-24T00:00:00.000Z",
"value": "Reported to Red Hat."
},
{
"lang": "en",
"time": "2026-06-24T00:00:00.000Z",
"value": "Made public."
}
],
"title": "kernel: bpf: Fix ld_{abs,ind} failure path analysis in subprogs",
"x_adpType": "supplier",
"x_generator": {
"engine": "sadp-cli 1.0.0"
}
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"kernel/bpf/verifier.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "928d354ae3557e8f755a227e67be88034eb3cd7f",
"status": "affected",
"version": "09b28d76eac48e922dc293da1aa2b2b85c32aeee",
"versionType": "git"
},
{
"lessThan": "8a800497d9f6c2ec9c2c1ba7b71d0ac2ea7f7bbe",
"status": "affected",
"version": "09b28d76eac48e922dc293da1aa2b2b85c32aeee",
"versionType": "git"
},
{
"lessThan": "de1055e7f9e67af32b1f3376066272b04e5223c0",
"status": "affected",
"version": "09b28d76eac48e922dc293da1aa2b2b85c32aeee",
"versionType": "git"
},
{
"lessThan": "37ad2bb11e9de92cb7b94548705eeedd87f7d392",
"status": "affected",
"version": "09b28d76eac48e922dc293da1aa2b2b85c32aeee",
"versionType": "git"
},
{
"lessThan": "8674e2db06cff6b50f2216eed9a761d15425bb34",
"status": "affected",
"version": "09b28d76eac48e922dc293da1aa2b2b85c32aeee",
"versionType": "git"
},
{
"lessThan": "ce01a4e5cfac7adbe0be565f90cd32ecbb2f8337",
"status": "affected",
"version": "09b28d76eac48e922dc293da1aa2b2b85c32aeee",
"versionType": "git"
},
{
"lessThan": "d846d83bdacbd8f14fc45c63b8c1d22608452e1c",
"status": "affected",
"version": "09b28d76eac48e922dc293da1aa2b2b85c32aeee",
"versionType": "git"
},
{
"lessThan": "ee861486e377edc55361c08dcbceab3f6b6577bd",
"status": "affected",
"version": "09b28d76eac48e922dc293da1aa2b2b85c32aeee",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"kernel/bpf/verifier.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.10"
},
{
"lessThan": "5.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.10",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "5.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix ld_{abs,ind} failure path analysis in subprogs\n\nUsage of ld_{abs,ind} instructions got extended into subprogs some time\nago via commit 09b28d76eac4 (\"bpf: Add abnormal return checks.\"). These\nare only allowed in subprograms when the latter are BTF annotated and\nhave scalar return types.\n\nThe code generator in bpf_gen_ld_abs() has an abnormal exit path (r0=0 +\nexit) from legacy cBPF times. While the enforcement is on scalar return\ntypes, the verifier must also simulate the path of abnormal exit if the\npacket data load via ld_{abs,ind} failed.\n\nThis is currently not the case. Fix it by having the verifier simulate\nboth success and failure paths, and extend it in similar ways as we do\nfor tail calls. The success path (r0=unknown, continue to next insn) is\npushed onto stack for later validation and the r0=0 and return to the\ncaller is done on the fall-through side."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The attacker must locally invoke the bpf() syscall to load a crafted BPF program; packets only trigger the already-loaded malicious program path.\nAC:L - The attacker controls the BPF bytecode, BTF annotations, and packet length needed to force the ld_abs/ld_ind failure path, with no race or external timing dependency.\nPR:L - The needed subprogram/BTF path requires CAP_BPF-equivalent BPF loading privileges, but BPF tokens can delegate these checks into a user namespace. Under the higher-severity rule, this is Low rather than High.\nUI:N - No victim action is required after the local attacker loads and triggers the crafted BPF program.\nS:U - The vulnerability compromises kernel execution within the same host security authority; it is standard local kernel privilege escalation, not a VM or hardware boundary escape.\nC:H - This is a verifier bypass where an unmodeled runtime path can execute code the verifier considered unreachable, enabling unsafe register and pointer use. Such BPF verifier bypasses can be developed into arbitrary kernel memory disclosure.\nI:H - The same unverified runtime path can be shaped into unsafe memory operations, making arbitrary kernel memory write or code execution defensible.\nA:H - Even without full exploitation, executing verifier-unchecked BPF operations can crash or panic the kernel, and the attacker can repeatedly trigger the path."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:28:06.530Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/928d354ae3557e8f755a227e67be88034eb3cd7f"
},
{
"url": "https://git.kernel.org/stable/c/8a800497d9f6c2ec9c2c1ba7b71d0ac2ea7f7bbe"
},
{
"url": "https://git.kernel.org/stable/c/de1055e7f9e67af32b1f3376066272b04e5223c0"
},
{
"url": "https://git.kernel.org/stable/c/37ad2bb11e9de92cb7b94548705eeedd87f7d392"
},
{
"url": "https://git.kernel.org/stable/c/8674e2db06cff6b50f2216eed9a761d15425bb34"
},
{
"url": "https://git.kernel.org/stable/c/ce01a4e5cfac7adbe0be565f90cd32ecbb2f8337"
},
{
"url": "https://git.kernel.org/stable/c/d846d83bdacbd8f14fc45c63b8c1d22608452e1c"
},
{
"url": "https://git.kernel.org/stable/c/ee861486e377edc55361c08dcbceab3f6b6577bd"
}
],
"title": "bpf: Fix ld_{abs,ind} failure path analysis in subprogs",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-53090",
"datePublished": "2026-06-24T16:30:29.413Z",
"dateReserved": "2026-06-09T07:44:35.384Z",
"dateUpdated": "2026-08-19T16:28:06.530Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72119 (GCVE-0-2026-72119)
Vulnerability from cvelistv5
Published
2026-08-15 05:52
Modified
2026-08-19 16:36
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
can: bcm: extend bcm_tx_lock usage for data and timer updates
Stage new CAN frame content for an existing tx op into a kmalloc()'d
buffer and validate it there, mirroring the approach already used in
bcm_rx_setup(). Only copy the validated data into op->frames while
holding op->bcm_tx_lock, so bcm_can_tx() and bcm_tx_timeout_handler()
can no longer observe a partially updated or unvalidated frame.
Add a missing error path for memcpy_from_msg() when copying CAN frame
data from userspace.
Also move the kt_ival1/kt_ival2/ival1/ival2 updates in bcm_tx_setup()
under op->bcm_tx_lock, and read kt_ival1/kt_ival2/count under the same
lock in bcm_tx_set_expiry() and bcm_tx_timeout_handler(), closing the
torn 64-bit ktime_t read on 32-bit platforms.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 7595de7bc56e0e52b74e56c90f7e247bf626d628 Version: fbd8fdc2b218e979cfe422b139b8f74c12419d1f Version: 2a437b86ac5a9893c902f30ef66815bf13587bf6 Version: 76c84c3728178b2d38d5604e399dfe8b0752645e Version: cc55dd28c20a6611e30596019b3b2f636819a4c0 Version: c2aba69d0c36a496ab4f2e81e9c2b271f2693fd7 Version: c2aba69d0c36a496ab4f2e81e9c2b271f2693fd7 Version: c2aba69d0c36a496ab4f2e81e9c2b271f2693fd7 Version: 8f1c022541bf5a923c8d6fa483112c15250f30a4 Version: c4e8a172501e677ebd8ea9d9161d97dc4df56fbd Version: 5.10.238 ≤ Version: 5.15.185 ≤ Version: 6.1.141 ≤ Version: 6.6.93 ≤ Version: 6.12.31 ≤ Version: 5.4.294 ≤ Version: 6.14.9 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/can/bcm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a538b072ee074c9b41b9d9c15a6861a963e30755",
"status": "affected",
"version": "7595de7bc56e0e52b74e56c90f7e247bf626d628",
"versionType": "git"
},
{
"lessThan": "63422347b4c782f429748b2a09cd3cf3b77e6abd",
"status": "affected",
"version": "fbd8fdc2b218e979cfe422b139b8f74c12419d1f",
"versionType": "git"
},
{
"lessThan": "37917e432e50b7de2b64230974380132a30f7270",
"status": "affected",
"version": "2a437b86ac5a9893c902f30ef66815bf13587bf6",
"versionType": "git"
},
{
"lessThan": "52f06e7603780de100233713ddaf971d422e10ef",
"status": "affected",
"version": "76c84c3728178b2d38d5604e399dfe8b0752645e",
"versionType": "git"
},
{
"lessThan": "972fd66bb08fdef1090abe43196ca8da07216d13",
"status": "affected",
"version": "cc55dd28c20a6611e30596019b3b2f636819a4c0",
"versionType": "git"
},
{
"lessThan": "bd46f55dec608daa44b45dcf3328517630ad8e40",
"status": "affected",
"version": "c2aba69d0c36a496ab4f2e81e9c2b271f2693fd7",
"versionType": "git"
},
{
"lessThan": "337f966c00662d81ad82cf5a4bbb150b2e32c0d4",
"status": "affected",
"version": "c2aba69d0c36a496ab4f2e81e9c2b271f2693fd7",
"versionType": "git"
},
{
"lessThan": "12ce799f7ab1e05bd8fbf79e46f403bfe5597ebc",
"status": "affected",
"version": "c2aba69d0c36a496ab4f2e81e9c2b271f2693fd7",
"versionType": "git"
},
{
"status": "affected",
"version": "8f1c022541bf5a923c8d6fa483112c15250f30a4",
"versionType": "git"
},
{
"status": "affected",
"version": "c4e8a172501e677ebd8ea9d9161d97dc4df56fbd",
"versionType": "git"
},
{
"lessThan": "5.10.265",
"status": "affected",
"version": "5.10.238",
"versionType": "semver"
},
{
"lessThan": "5.15.216",
"status": "affected",
"version": "5.15.185",
"versionType": "semver"
},
{
"lessThan": "6.1.183",
"status": "affected",
"version": "6.1.141",
"versionType": "semver"
},
{
"lessThan": "6.6.148",
"status": "affected",
"version": "6.6.93",
"versionType": "semver"
},
{
"lessThan": "6.12.101",
"status": "affected",
"version": "6.12.31",
"versionType": "semver"
},
{
"lessThan": "5.5",
"status": "affected",
"version": "5.4.294",
"versionType": "semver"
},
{
"lessThan": "6.15",
"status": "affected",
"version": "6.14.9",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/can/bcm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.15"
},
{
"lessThan": "6.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.10.238",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.15.185",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "6.1.141",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.6.93",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.12.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "6.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.4.294",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.14.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: bcm: extend bcm_tx_lock usage for data and timer updates\n\nStage new CAN frame content for an existing tx op into a kmalloc()\u0027d\nbuffer and validate it there, mirroring the approach already used in\nbcm_rx_setup(). Only copy the validated data into op-\u003eframes while\nholding op-\u003ebcm_tx_lock, so bcm_can_tx() and bcm_tx_timeout_handler()\ncan no longer observe a partially updated or unvalidated frame.\n\nAdd a missing error path for memcpy_from_msg() when copying CAN frame\ndata from userspace.\n\nAlso move the kt_ival1/kt_ival2/ival1/ival2 updates in bcm_tx_setup()\nunder op-\u003ebcm_tx_lock, and read kt_ival1/kt_ival2/count under the same\nlock in bcm_tx_set_expiry() and bcm_tx_timeout_handler(), closing the\ntorn 64-bit ktime_t read on 32-bit platforms."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached only through PF_CAN/CAN_BCM socket sendmsg() TX_SETUP updates racing hrtimer-driven bcm_can_tx(); it is not triggered by remote network services or CAN bus traffic alone.\nAC:L - The attacker controls both sides of the race by creating cyclic TX ops with STARTTIMER/SETTIMER and repeatedly issuing TX_SETUP while the softirq hrtimer fires, making the window reliably winnable without external timing luck.\nPR:L - bcm_sendmsg()/bcm_connect() enforce no capability checks; any local user with access to a CAN interface (including vcan created with CAP_NET_ADMIN inside an unprivileged user namespace) can open BCM sockets and drive TX_SETUP.\nUI:N - Exploitation requires only the attacker opening a BCM socket and sending TX_SETUP messages; no victim interaction such as mounting filesystems or opening files is needed.\nS:U - Impact is confined to kernel memory/state corruption and local privilege effects on the host running CAN BCM; it does not cross a VM, container, or IOMMU security boundary by itself.\nC:H - Racing updates can let bcm_can_tx() transmit partially updated or unvalidated frames (e.g., len\u003e64) before bcm_tx_setup() rejects them, and many CAN driver xmit paths memcpy(cf-\u003edata, cf-\u003elen) trusting len, causing kernel out-of-bounds reads.\nI:H - Concurrent unsynchronized writes to op-\u003eframes, flags, count, and ktime_t timer fields corrupt shared in-kernel BCM state that directly feeds skb construction and driver transmission, providing attacker-influenced memory corruption primitives.\nA:H - Observing torn/unvalidated frames in bcm_can_tx() during active timers can trigger kernel WARN/Oops/panic via out-of-bounds accesses in CAN drivers, and torn ktime_t/count reads can disrupt cyclic transmission causing denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:36:13.917Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a538b072ee074c9b41b9d9c15a6861a963e30755"
},
{
"url": "https://git.kernel.org/stable/c/63422347b4c782f429748b2a09cd3cf3b77e6abd"
},
{
"url": "https://git.kernel.org/stable/c/37917e432e50b7de2b64230974380132a30f7270"
},
{
"url": "https://git.kernel.org/stable/c/52f06e7603780de100233713ddaf971d422e10ef"
},
{
"url": "https://git.kernel.org/stable/c/972fd66bb08fdef1090abe43196ca8da07216d13"
},
{
"url": "https://git.kernel.org/stable/c/bd46f55dec608daa44b45dcf3328517630ad8e40"
},
{
"url": "https://git.kernel.org/stable/c/337f966c00662d81ad82cf5a4bbb150b2e32c0d4"
},
{
"url": "https://git.kernel.org/stable/c/12ce799f7ab1e05bd8fbf79e46f403bfe5597ebc"
}
],
"title": "can: bcm: extend bcm_tx_lock usage for data and timer updates",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72119",
"datePublished": "2026-08-15T05:52:58.479Z",
"dateReserved": "2026-08-09T03:40:39.906Z",
"dateUpdated": "2026-08-19T16:36:13.917Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64565 (GCVE-0-2026-64565)
Vulnerability from cvelistv5
Published
2026-08-04 06:23
Modified
2026-08-19 16:28
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data()
The `ims_pcu_process_data()` processes incoming URB data byte by byte.
However, it fails to check if the `read_pos` index exceeds
IMS_PCU_BUF_SIZE.
If a malicious USB device sends a packet larger than IMS_PCU_BUF_SIZE,
`read_pos` will increment indefinitely. Moreover, since `read_pos` is
located immediately after `read_buf`, the attacker can overwrite
`read_pos` itself to arbitrarily control the index.
This manipulated `read_pos` is subsequently used in
`ims_pcu_handle_response()` to copy data into `cmd_buf`, leading to a
heap buffer overflow.
Specifically, an attacker can overwrite the `cmd_done.wait.head` located
at offset 136 relative to `cmd_buf` in the `ims_pcu_handle_response()`.
Consequently, when the driver calls `complete(&pcu->cmd_done)`, it
triggers a control flow hijack by using the manipulated pointer.
Fix this by adding a bounds check for `read_pos` before writing to
`read_buf`. If the packet is too long, discard it, log a warning,
and reset the parser state.
[dtor: factor out resetting packet state, reset checksum as well]
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 628329d52474323938a03826941e166bc7c8eff4 Version: 628329d52474323938a03826941e166bc7c8eff4 Version: 628329d52474323938a03826941e166bc7c8eff4 Version: 628329d52474323938a03826941e166bc7c8eff4 Version: 628329d52474323938a03826941e166bc7c8eff4 Version: 628329d52474323938a03826941e166bc7c8eff4 Version: 628329d52474323938a03826941e166bc7c8eff4 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/input/misc/ims-pcu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "06cfff93fd40441292567b999091beab11c74504",
"status": "affected",
"version": "628329d52474323938a03826941e166bc7c8eff4",
"versionType": "git"
},
{
"lessThan": "992a7173364dcf63e30012af43da3c2f279839f9",
"status": "affected",
"version": "628329d52474323938a03826941e166bc7c8eff4",
"versionType": "git"
},
{
"lessThan": "3a801bc75ba1d121d0ed60e7234f93ba5651d87d",
"status": "affected",
"version": "628329d52474323938a03826941e166bc7c8eff4",
"versionType": "git"
},
{
"lessThan": "40bbbf2e91fd60715525bf0405c67876af817edf",
"status": "affected",
"version": "628329d52474323938a03826941e166bc7c8eff4",
"versionType": "git"
},
{
"lessThan": "ca9f8c09845fb8c51b6d447f6428eecd1b8b0a49",
"status": "affected",
"version": "628329d52474323938a03826941e166bc7c8eff4",
"versionType": "git"
},
{
"lessThan": "d03a740e087de7dcb2a26dc1123377bd3d1d84ca",
"status": "affected",
"version": "628329d52474323938a03826941e166bc7c8eff4",
"versionType": "git"
},
{
"lessThan": "875115b82c295277b81b6dfee7debc725f44e854",
"status": "affected",
"version": "628329d52474323938a03826941e166bc7c8eff4",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/input/misc/ims-pcu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.10"
},
{
"lessThan": "3.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "3.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nInput: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data()\n\nThe `ims_pcu_process_data()` processes incoming URB data byte by byte.\nHowever, it fails to check if the `read_pos` index exceeds\nIMS_PCU_BUF_SIZE.\n\nIf a malicious USB device sends a packet larger than IMS_PCU_BUF_SIZE,\n`read_pos` will increment indefinitely. Moreover, since `read_pos` is\nlocated immediately after `read_buf`, the attacker can overwrite\n`read_pos` itself to arbitrarily control the index.\n\nThis manipulated `read_pos` is subsequently used in\n`ims_pcu_handle_response()` to copy data into `cmd_buf`, leading to a\nheap buffer overflow.\n\nSpecifically, an attacker can overwrite the `cmd_done.wait.head` located\nat offset 136 relative to `cmd_buf` in the `ims_pcu_handle_response()`.\nConsequently, when the driver calls `complete(\u0026pcu-\u003ecmd_done)`, it\ntriggers a control flow hijack by using the manipulated pointer.\n\nFix this by adding a bounds check for `read_pos` before writing to\n`read_buf`. If the packet is too long, discard it, log a warning,\nand reset the parser state.\n\n[dtor: factor out resetting packet state, reset checksum as well]"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:28:39.404Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/06cfff93fd40441292567b999091beab11c74504"
},
{
"url": "https://git.kernel.org/stable/c/992a7173364dcf63e30012af43da3c2f279839f9"
},
{
"url": "https://git.kernel.org/stable/c/3a801bc75ba1d121d0ed60e7234f93ba5651d87d"
},
{
"url": "https://git.kernel.org/stable/c/40bbbf2e91fd60715525bf0405c67876af817edf"
},
{
"url": "https://git.kernel.org/stable/c/ca9f8c09845fb8c51b6d447f6428eecd1b8b0a49"
},
{
"url": "https://git.kernel.org/stable/c/d03a740e087de7dcb2a26dc1123377bd3d1d84ca"
},
{
"url": "https://git.kernel.org/stable/c/875115b82c295277b81b6dfee7debc725f44e854"
}
],
"title": "Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64565",
"datePublished": "2026-08-04T06:23:24.089Z",
"dateReserved": "2026-07-19T15:36:31.797Z",
"dateUpdated": "2026-08-19T16:28:39.404Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80717 (GCVE-0-2026-80717)
Vulnerability from cvelistv5
Published
2026-08-28 06:53
Modified
2026-08-29 06:22
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
sctp: validate Adaptation Indication parameter length
The Adaptation Layer Indication parameter contains a fixed 32-bit
Adaptation Code Point after its parameter header. However,
sctp_verify_param() accepts a header-only parameter because the generic
parameter walker only requires the header to be present.
sctp_process_param() then reads adaptation_ind beyond the declared
parameter. When the malformed parameter is last in an INIT, the read
starts at the receive skb tail, and the value is copied into the state
cookie returned in the INIT ACK. This may disclose four receive-buffer
tail bytes.
Require the declared parameter length to match the fixed structure size
and abort the association through the existing invalid parameter length
path otherwise.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/sctp/sm_make_chunk.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "fa7861ddbe3b525b5d541c15c3953d3569e6eb0e",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "4c92c601c061e5602db2edeea54fef74aa304027",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "7b7e4e3640d57bd8857f0052c8b0d8ed4e5e954a",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "93942b5772e0eee4147d4799cc1b936ae12fa615",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "5fd7cfc708dfc988ae9920c21075e6121bc89926",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "17b412468c7a44f66a385bda48cdc1e94e39bd6d",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "bfa28cf99eb4d096c87da939f54233444d209ca5",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "74b21f52c5c5a71a05c0ff70e513f4f04ff28b17",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/sctp/sm_make_chunk.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: validate Adaptation Indication parameter length\n\nThe Adaptation Layer Indication parameter contains a fixed 32-bit\nAdaptation Code Point after its parameter header. However,\nsctp_verify_param() accepts a header-only parameter because the generic\nparameter walker only requires the header to be present.\n\nsctp_process_param() then reads adaptation_ind beyond the declared\nparameter. When the malformed parameter is last in an INIT, the read\nstarts at the receive skb tail, and the value is copied into the state\ncookie returned in the INIT ACK. This may disclose four receive-buffer\ntail bytes.\n\nRequire the declared parameter length to match the fixed structure size\nand abort the association through the existing invalid parameter length\npath otherwise."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The flaw is reached when a remote peer sends a crafted SCTP INIT to a listening endpoint; packets enter sctp_rcv() and sctp_sf_do_5_1B_init(), which calls sctp_verify_init() and sctp_process_init() before any association authentication.\nAC:L - Exploitation is deterministic SCTP packet crafting: place SCTP_PARAM_ADAPTATION_LAYER_IND last in INIT with a 4-byte header-only length so sctp_process_param() reads past the TLV into skb tail memory; no race, memory-layout lottery, or rare victim state is required beyond SCTP being enabled.\nPR:N - INIT processing is pre-authentication SCTP handshake handling on a listening server; the attacker needs only network reachability to the SCTP port and no local account, Linux capabilities, or init-namespace privileges on the target host.\nUI:N - No victim user action such as opening files or clicking links is required; exploitation needs only that an SCTP listener is reachable and automatically processes inbound INIT chunks during normal server operation.\nS:U - Impact is a bounded kernel skb out-of-bounds read whose contents are returned to the remote peer in the INIT-ACK state cookie; it does not cross VM, container, or IOMMU security boundaries.\nC:H - sctp_process_param() performs an out-of-bounds read of four kernel receive-buffer tail bytes when adaptation_ind is accessed beyond a header-only parameter; those bytes are copied into the state cookie and disclosed to the attacker in INIT-ACK.\nI:N - The defect is an out-of-bounds read only; no kernel memory is written, no association structures are corrupted, and the fix does not address any write primitive or control-flow hijacking.\nA:N - The out-of-bounds read copies four skb tail bytes into the association cookie and INIT-ACK without dereferencing unmapped memory; the commit describes information disclosure only and no kernel oops, panic, or hang."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-29T06:22:33.315Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/fa7861ddbe3b525b5d541c15c3953d3569e6eb0e"
},
{
"url": "https://git.kernel.org/stable/c/4c92c601c061e5602db2edeea54fef74aa304027"
},
{
"url": "https://git.kernel.org/stable/c/7b7e4e3640d57bd8857f0052c8b0d8ed4e5e954a"
},
{
"url": "https://git.kernel.org/stable/c/93942b5772e0eee4147d4799cc1b936ae12fa615"
},
{
"url": "https://git.kernel.org/stable/c/5fd7cfc708dfc988ae9920c21075e6121bc89926"
},
{
"url": "https://git.kernel.org/stable/c/17b412468c7a44f66a385bda48cdc1e94e39bd6d"
},
{
"url": "https://git.kernel.org/stable/c/bfa28cf99eb4d096c87da939f54233444d209ca5"
},
{
"url": "https://git.kernel.org/stable/c/74b21f52c5c5a71a05c0ff70e513f4f04ff28b17"
}
],
"title": "sctp: validate Adaptation Indication parameter length",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80717",
"datePublished": "2026-08-28T06:53:14.886Z",
"dateReserved": "2026-08-26T14:34:25.788Z",
"dateUpdated": "2026-08-29T06:22:33.315Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72096 (GCVE-0-2026-72096)
Vulnerability from cvelistv5
Published
2026-08-15 05:52
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
dm-verity: make error counter atomic
The error counter "v->corrupted_errs" was not atomic, thus it could be
subject to race conditions. The call to
dm_audit_log_target("max-corrupted-errors") may be skipped due to the
races.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 65ff5b7ddf0541f2b6e5cc59c47bfbf6cbcd91b8 Version: 65ff5b7ddf0541f2b6e5cc59c47bfbf6cbcd91b8 Version: 65ff5b7ddf0541f2b6e5cc59c47bfbf6cbcd91b8 Version: 65ff5b7ddf0541f2b6e5cc59c47bfbf6cbcd91b8 Version: 65ff5b7ddf0541f2b6e5cc59c47bfbf6cbcd91b8 Version: 65ff5b7ddf0541f2b6e5cc59c47bfbf6cbcd91b8 Version: 65ff5b7ddf0541f2b6e5cc59c47bfbf6cbcd91b8 Version: 65ff5b7ddf0541f2b6e5cc59c47bfbf6cbcd91b8 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/md/dm-verity-target.c",
"drivers/md/dm-verity.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b8eddcb1bf72199451950aff9087bd76da80635d",
"status": "affected",
"version": "65ff5b7ddf0541f2b6e5cc59c47bfbf6cbcd91b8",
"versionType": "git"
},
{
"lessThan": "aab5cb8a40e82bd33d0f3ae3c73041848b18bfd2",
"status": "affected",
"version": "65ff5b7ddf0541f2b6e5cc59c47bfbf6cbcd91b8",
"versionType": "git"
},
{
"lessThan": "a7df22c4e0e9110f0be577919d3cb9389b2aba65",
"status": "affected",
"version": "65ff5b7ddf0541f2b6e5cc59c47bfbf6cbcd91b8",
"versionType": "git"
},
{
"lessThan": "ac99781115d37d10894653b47941d9d8fc26fa64",
"status": "affected",
"version": "65ff5b7ddf0541f2b6e5cc59c47bfbf6cbcd91b8",
"versionType": "git"
},
{
"lessThan": "3303e5c6501e3638ded8e9402d703805b00ce64e",
"status": "affected",
"version": "65ff5b7ddf0541f2b6e5cc59c47bfbf6cbcd91b8",
"versionType": "git"
},
{
"lessThan": "089e05b644d5aa786c21af467c80b24d691becb1",
"status": "affected",
"version": "65ff5b7ddf0541f2b6e5cc59c47bfbf6cbcd91b8",
"versionType": "git"
},
{
"lessThan": "752e214b2c6f15b40b0d873a2ce27733ce0884c6",
"status": "affected",
"version": "65ff5b7ddf0541f2b6e5cc59c47bfbf6cbcd91b8",
"versionType": "git"
},
{
"lessThan": "8ec4d9c5a5cf4b61fc087f871465b1f79b393325",
"status": "affected",
"version": "65ff5b7ddf0541f2b6e5cc59c47bfbf6cbcd91b8",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/md/dm-verity-target.c",
"drivers/md/dm-verity.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.1"
},
{
"lessThan": "4.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndm-verity: make error counter atomic\n\nThe error counter \"v-\u003ecorrupted_errs\" was not atomic, thus it could be\nsubject to race conditions. The call to\ndm_audit_log_target(\"max-corrupted-errors\") may be skipped due to the\nraces."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:48.390Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b8eddcb1bf72199451950aff9087bd76da80635d"
},
{
"url": "https://git.kernel.org/stable/c/aab5cb8a40e82bd33d0f3ae3c73041848b18bfd2"
},
{
"url": "https://git.kernel.org/stable/c/a7df22c4e0e9110f0be577919d3cb9389b2aba65"
},
{
"url": "https://git.kernel.org/stable/c/ac99781115d37d10894653b47941d9d8fc26fa64"
},
{
"url": "https://git.kernel.org/stable/c/3303e5c6501e3638ded8e9402d703805b00ce64e"
},
{
"url": "https://git.kernel.org/stable/c/089e05b644d5aa786c21af467c80b24d691becb1"
},
{
"url": "https://git.kernel.org/stable/c/752e214b2c6f15b40b0d873a2ce27733ce0884c6"
},
{
"url": "https://git.kernel.org/stable/c/8ec4d9c5a5cf4b61fc087f871465b1f79b393325"
}
],
"title": "dm-verity: make error counter atomic",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72096",
"datePublished": "2026-08-15T05:52:42.208Z",
"dateReserved": "2026-08-09T03:40:39.905Z",
"dateUpdated": "2026-08-23T12:46:48.390Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74588 (GCVE-0-2026-74588)
Vulnerability from cvelistv5
Published
2026-08-22 15:31
Modified
2026-08-25 05:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
sctp: keep chunk->transport in step with the list it is queued on
__sctp_outq_flush_rtx() moves a gap-acked chunk onto another transport's
transmitted list without updating chunk->transport:
if (chunk->tsn_gap_acked) {
list_move_tail(&chunk->transmitted_list,
&transport->transmitted);
continue;
}
The chunk then sits on a live transport's list while chunk->transport still
names a different one. If that transport is removed - sctp_assoc_rm_peer()
from an ASCONF Delete-IP - sctp_transport_free() RCU-frees it and the chunk
is left with a dangling pointer. sctp_assoc_rm_peer() scrubs
peer->transmitted and asoc->outqueue.out_chunk_list, but the chunk is on
neither.
The pointer is not followed while tsn_gap_acked is set. A SACK that
reneges on the TSN clears the flag, and the next SACK reaches
tchunk->transport->flight_size -= sctp_data_size(tchunk);
inside the freed transport. KASAN reports a slab-use-after-free read in
sctp_check_transmitted(), freed from sctp_assoc_rm_peer(). Both the
removal and the SACKs come from the association peer.
Set chunk->transport at the move. The ordinary resend path needs nothing:
it reaches its list_move_tail() only after sctp_packet_append_chunk()
returned SCTP_XMIT_OK, and __sctp_packet_append_chunk() has rebound the
chunk by then.
Discovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/sctp/outqueue.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "6575fb17230814b48b471727c8410c0aadff9274",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "6b9e2ea2057113f3393990ba646d2d97c719a80d",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "874a7c2b5e184f06134fdfde27e9ce9271bafe58",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "1adf929121e13e0b19200bb9fef715b918d483fe",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "e2e7c1de0e226ca1b7fea2de57a6c9bca408709b",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "2b3b5eec8b2c30ee237e3c31a6a38de9c39d804d",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "5ccf35ef0ed6059cdf8b1f4606a6584d5b67166b",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "9f2cf069a9a72a2d6b97ca8b4c70e714aac99749",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/sctp/outqueue.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: keep chunk-\u003etransport in step with the list it is queued on\n\n__sctp_outq_flush_rtx() moves a gap-acked chunk onto another transport\u0027s\ntransmitted list without updating chunk-\u003etransport:\n\n\tif (chunk-\u003etsn_gap_acked) {\n\t\tlist_move_tail(\u0026chunk-\u003etransmitted_list,\n\t\t\t \u0026transport-\u003etransmitted);\n\t\tcontinue;\n\t}\n\nThe chunk then sits on a live transport\u0027s list while chunk-\u003etransport still\nnames a different one. If that transport is removed - sctp_assoc_rm_peer()\nfrom an ASCONF Delete-IP - sctp_transport_free() RCU-frees it and the chunk\nis left with a dangling pointer. sctp_assoc_rm_peer() scrubs\npeer-\u003etransmitted and asoc-\u003eoutqueue.out_chunk_list, but the chunk is on\nneither.\n\nThe pointer is not followed while tsn_gap_acked is set. A SACK that\nreneges on the TSN clears the flag, and the next SACK reaches\n\n\ttchunk-\u003etransport-\u003eflight_size -= sctp_data_size(tchunk);\n\ninside the freed transport. KASAN reports a slab-use-after-free read in\nsctp_check_transmitted(), freed from sctp_assoc_rm_peer(). Both the\nremoval and the SACKs come from the association peer.\n\nSet chunk-\u003etransport at the move. The ordinary resend path needs nothing:\nit reaches its list_move_tail() only after sctp_packet_append_chunk()\nreturned SCTP_XMIT_OK, and __sctp_packet_append_chunk() has rebound the\nchunk by then.\n\nDiscovered by XBOW, triaged by Baul Lee \u003cbaul.lee@xbow.com\u003e"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug is reached when the kernel SCTP stack processes inbound SACK and ASCONF chunks from a remote association peer via sctp_rcv()/sctp_inq_push(), with no local syscall or ioctl required on the victim.\nAC:L - The remote peer controls the SCTP protocol sequence (gap SACKs, ADDIP multihoming, ASCONF Delete-IP, and SACK reneging) needed to strand a chunk and free its transport; no attacker-uncontrollable race or rare memory layout is required.\nPR:N - Exploitation requires only network access as an established SCTP association peer sending authenticated protocol traffic; no local Linux account, capability, or namespace privilege is needed on the victim host.\nUI:N - No victim user action is required beyond normal automated SCTP server/client operation; the attacker drives the entire trigger sequence with crafted SACK and ASCONF packets on the existing association.\nS:U - Impact is confined to kernel memory corruption and potential privilege escalation within the host kernel; it does not cross a VM, container, or IOMMU security boundary.\nC:H - KASAN reports a slab use-after-free read through dangling chunk-\u003etransport in sctp_check_transmitted(); UAF on sctp_transport objects can be groomed for arbitrary kernel memory disclosure.\nI:H - The UAF dereference performs flight_size arithmetic on a freed sctp_transport slab object, enabling heap grooming and arbitrary kernel write or control-flow hijack primitives typical of SCTP transport UAFs.\nA:H - Accessing freed transport memory during SACK processing can cause kernel oops/panic and repeatable remote denial of service against any SCTP endpoint handling the malicious peer traffic."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:40:15.097Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/6575fb17230814b48b471727c8410c0aadff9274"
},
{
"url": "https://git.kernel.org/stable/c/6b9e2ea2057113f3393990ba646d2d97c719a80d"
},
{
"url": "https://git.kernel.org/stable/c/874a7c2b5e184f06134fdfde27e9ce9271bafe58"
},
{
"url": "https://git.kernel.org/stable/c/1adf929121e13e0b19200bb9fef715b918d483fe"
},
{
"url": "https://git.kernel.org/stable/c/e2e7c1de0e226ca1b7fea2de57a6c9bca408709b"
},
{
"url": "https://git.kernel.org/stable/c/2b3b5eec8b2c30ee237e3c31a6a38de9c39d804d"
},
{
"url": "https://git.kernel.org/stable/c/5ccf35ef0ed6059cdf8b1f4606a6584d5b67166b"
},
{
"url": "https://git.kernel.org/stable/c/9f2cf069a9a72a2d6b97ca8b4c70e714aac99749"
}
],
"title": "sctp: keep chunk-\u003etransport in step with the list it is queued on",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74588",
"datePublished": "2026-08-22T15:31:40.466Z",
"dateReserved": "2026-08-15T05:44:03.918Z",
"dateUpdated": "2026-08-25T05:40:15.097Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74579 (GCVE-0-2026-74579)
Vulnerability from cvelistv5
Published
2026-08-17 05:28
Modified
2026-08-25 05:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nft_payload: fix mask build for partial field offload
nft_payload_offload_mask() builds the offload match mask for a payload
expression that covers only part of a header field. For a partial IPv6
address match (field_len = 16, priv_len = 1) that shift is 1 << 120, which
is undefined on the 32-bit int operand. It also trims only one word, so
the remaining words stay 0xffffffff (and when priv_len is a multiple of 4
the trim is skipped entirely), leaving the mask covering more bytes than
the rule matches.
UBSAN: shift-out-of-bounds in net/netfilter/nft_payload.c:278:20
shift exponent 120 is too large for 32-bit type 'int'
...
The match is byte-granular and struct nft_data is zero-initialised, so the
correct mask is simply the first priv_len bytes set to 0xff. Set those
bytes directly and drop the word/shift trimming; this removes the undefined
shift and no longer over-masks the trailing bytes.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: a5d45bc0dc50f9dd83703510e9804d813a9cac32 Version: a5d45bc0dc50f9dd83703510e9804d813a9cac32 Version: a5d45bc0dc50f9dd83703510e9804d813a9cac32 Version: a5d45bc0dc50f9dd83703510e9804d813a9cac32 Version: a5d45bc0dc50f9dd83703510e9804d813a9cac32 Version: a5d45bc0dc50f9dd83703510e9804d813a9cac32 Version: a5d45bc0dc50f9dd83703510e9804d813a9cac32 Version: a5d45bc0dc50f9dd83703510e9804d813a9cac32 Version: 5c2b4b4f9fa5b765b927e361e3d310bcb5773015 Version: 5.9.14 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/netfilter/nft_payload.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "3ee7b3f813b11f28cd6efdf7f24d64b5a7fd4dc7",
"status": "affected",
"version": "a5d45bc0dc50f9dd83703510e9804d813a9cac32",
"versionType": "git"
},
{
"lessThan": "8720df4504e0ed1781a702f65251bd47b3534d5e",
"status": "affected",
"version": "a5d45bc0dc50f9dd83703510e9804d813a9cac32",
"versionType": "git"
},
{
"lessThan": "363c3a84a946d53e5e121c9f47c7c2b7d228c46b",
"status": "affected",
"version": "a5d45bc0dc50f9dd83703510e9804d813a9cac32",
"versionType": "git"
},
{
"lessThan": "b19b5d2e042c294e2cc1c908dc598f9d64015396",
"status": "affected",
"version": "a5d45bc0dc50f9dd83703510e9804d813a9cac32",
"versionType": "git"
},
{
"lessThan": "a375d8ace807767f29f276b681b6324c74929b1d",
"status": "affected",
"version": "a5d45bc0dc50f9dd83703510e9804d813a9cac32",
"versionType": "git"
},
{
"lessThan": "16b553c46e347bc9de9946c4960654d5884a86de",
"status": "affected",
"version": "a5d45bc0dc50f9dd83703510e9804d813a9cac32",
"versionType": "git"
},
{
"lessThan": "630295d5bba1d0e0f494cc459452eb0a0058c545",
"status": "affected",
"version": "a5d45bc0dc50f9dd83703510e9804d813a9cac32",
"versionType": "git"
},
{
"lessThan": "39e88f28fb32bf02bd4b525c24c842c9cff5663d",
"status": "affected",
"version": "a5d45bc0dc50f9dd83703510e9804d813a9cac32",
"versionType": "git"
},
{
"status": "affected",
"version": "5c2b4b4f9fa5b765b927e361e3d310bcb5773015",
"versionType": "git"
},
{
"lessThan": "5.10",
"status": "affected",
"version": "5.9.14",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/netfilter/nft_payload.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.10"
},
{
"lessThan": "5.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.9.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_payload: fix mask build for partial field offload\n\nnft_payload_offload_mask() builds the offload match mask for a payload\nexpression that covers only part of a header field. For a partial IPv6\naddress match (field_len = 16, priv_len = 1) that shift is 1 \u003c\u003c 120, which\nis undefined on the 32-bit int operand. It also trims only one word, so\nthe remaining words stay 0xffffffff (and when priv_len is a multiple of 4\nthe trim is skipped entirely), leaving the mask covering more bytes than\nthe rule matches.\n\n UBSAN: shift-out-of-bounds in net/netfilter/nft_payload.c:278:20\n shift exponent 120 is too large for 32-bit type \u0027int\u0027\n ...\n\nThe match is byte-granular and struct nft_data is zero-initialised, so the\ncorrect mask is simply the first priv_len bytes set to 0xff. Set those\nbytes directly and drop the word/shift trimming; this removes the undefined\nshift and no longer over-masks the trailing bytes."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The flaw is reached only when installing nftables rules via NETLINK_NETFILTER (NFT_MSG_NEWRULE) on NFT_CHAIN_HW_OFFLOAD netdev ingress chains; nft_flow_rule_create() calls nft_payload_offload_mask() during expr offload setup, which is a local netlink syscall path per kernel CNA guidance for nftables/netfilter.\nAC:L - An attacker with CAP_NET_ADMIN can deterministically craft a partial-field payload match (e.g., priv_len=1 on IPv6 saddr with field_len=16) on an HW-offload chain; no race, memory layout, or other conditions outside attacker control are required to hit the undefined shift and incorrect mask build.\nPR:L - All nf_tables netlink operations are gated by netlink_net_capable(skb, CAP_NET_ADMIN) in nfnetlink_rcv(), checked against the socket network namespace user_ns; unprivileged local users routinely obtain CAP_NET_ADMIN via user+network namespaces (unshare -Urn) on cloud hosts and containers.\nUI:N - No victim interaction is required; the attacker installs the malformed HW-offload nftables rule through their own netlink socket and triggers the bug during rule commit without needing another user to mount filesystems, open files, or take any action.\nS:U - Impact is confined to the host kernel and its hardware-offloaded netdev ingress filtering policy (incorrect TC flower masks, potential kernel crash); this is standard kernel/network-authority impact, not a VM escape, IOMMU bypass, or cross-security-boundary scope change.\nC:N - The bug corrupts on-stack bitmask construction during rule installation and does not perform out-of-bounds reads, use-after-free, or other memory-disclosure primitives; no attacker-influenced kernel memory read path exists beyond incorrect mask values.\nI:H - Incorrect or UB-corrupted HW flower match masks misprogram NIC ingress ACLs on hardware-offloaded edge firewalls, causing accept/drop/redirect actions to apply to traffic contrary to administrator intent; this is exploitable integrity compromise of enforced network policy on internet-facing offload deployments.\nA:H - The undefined shift (1\u003c\u003c120) triggers documented UBSAN shift-out-of-bounds at rule install and can panic/oops on UBSAN/trap kernels; misprogrammed HW offload masks can also blackhole or mis-drop production ingress traffic on netdev-offloaded chains, satisfying CNA high availability guidance."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:40:05.144Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/3ee7b3f813b11f28cd6efdf7f24d64b5a7fd4dc7"
},
{
"url": "https://git.kernel.org/stable/c/8720df4504e0ed1781a702f65251bd47b3534d5e"
},
{
"url": "https://git.kernel.org/stable/c/363c3a84a946d53e5e121c9f47c7c2b7d228c46b"
},
{
"url": "https://git.kernel.org/stable/c/b19b5d2e042c294e2cc1c908dc598f9d64015396"
},
{
"url": "https://git.kernel.org/stable/c/a375d8ace807767f29f276b681b6324c74929b1d"
},
{
"url": "https://git.kernel.org/stable/c/16b553c46e347bc9de9946c4960654d5884a86de"
},
{
"url": "https://git.kernel.org/stable/c/630295d5bba1d0e0f494cc459452eb0a0058c545"
},
{
"url": "https://git.kernel.org/stable/c/39e88f28fb32bf02bd4b525c24c842c9cff5663d"
}
],
"title": "netfilter: nft_payload: fix mask build for partial field offload",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74579",
"datePublished": "2026-08-17T05:28:27.768Z",
"dateReserved": "2026-08-15T05:44:03.917Z",
"dateUpdated": "2026-08-25T05:40:05.144Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72323 (GCVE-0-2026-72323)
Vulnerability from cvelistv5
Published
2026-08-15 05:55
Modified
2026-09-02 12:49
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ipv4: igmp: Fix potential UAF in igmp_gq_start_timer()
A race condition exists between device teardown (inetdev_destroy) and
incoming IGMP query processing (igmp_rcv), leading to a Use-After-Free
in the IGMP timer callback.
During device destruction, inetdev_destroy() drops the primary reference
to in_device, which can drop its refcount to 0. The actual freeing of
in_device memory is deferred via RCU (using call_rcu()).
Concurrently, igmp_rcv() runs under RCU read lock and obtains the
in_device pointer. Because the memory is RCU-protected, CPU-0 can safely
dereference in_device even if its refcount has hit 0.
However, if CPU-0 calls igmp_gq_start_timer() and re-arms the timer, it
attempts to acquire a reference using in_dev_hold(). This increments the
refcount from 0 to 1, triggering a "refcount_t: addition on 0" warning.
Since the in_device memory is still scheduled to be freed after the RCU
grace period (as the free callback does not check the refcount again),
the device is freed while the timer is still armed. When the timer
expires, it accesses the freed memory, causing a kernel panic.
Fix this by using refcount_inc_not_zero() (via a new helper
in_dev_hold_safe()) to prevent acquiring a reference if the device is
already being destroyed. If the refcount is 0, we do not arm the timer.
A similar issue in IPv6 MLD is fixed in a subsequent patch.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"include/linux/inetdevice.h",
"net/ipv4/igmp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "7265c747eec415ca3109a6a14a419f7ae433b780",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "d107b4c4f8274763b7ea5ab05d45cef78e4b81ba",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "74b301f7f197517016befb5f5dfab01f7bc64be5",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "40a1e998cb266ed4cb529a0bb4fee2b0ba732702",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "165258303357e54b75fc19b341ae2a2b7c9e3910",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "75e984fe0cb9e7fbde0c8ee838c61ce8573d3ea3",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "8d4394ffa40508e0de72f464af351f6ca6a6cdc3",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "7b19c0f81ed1fdaec6bc522569be367199a9edf3",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"include/linux/inetdevice.h",
"net/ipv4/igmp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.269",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.220",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.187",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.269",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.220",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.187",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: igmp: Fix potential UAF in igmp_gq_start_timer()\n\nA race condition exists between device teardown (inetdev_destroy) and\nincoming IGMP query processing (igmp_rcv), leading to a Use-After-Free\nin the IGMP timer callback.\n\nDuring device destruction, inetdev_destroy() drops the primary reference\nto in_device, which can drop its refcount to 0. The actual freeing of\nin_device memory is deferred via RCU (using call_rcu()).\n\nConcurrently, igmp_rcv() runs under RCU read lock and obtains the\nin_device pointer. Because the memory is RCU-protected, CPU-0 can safely\ndereference in_device even if its refcount has hit 0.\n\nHowever, if CPU-0 calls igmp_gq_start_timer() and re-arms the timer, it\nattempts to acquire a reference using in_dev_hold(). This increments the\nrefcount from 0 to 1, triggering a \"refcount_t: addition on 0\" warning.\nSince the in_device memory is still scheduled to be freed after the RCU\ngrace period (as the free callback does not check the refcount again),\nthe device is freed while the timer is still armed. When the timer\nexpires, it accesses the freed memory, causing a kernel panic.\n\nFix this by using refcount_inc_not_zero() (via a new helper\nin_dev_hold_safe()) to prevent acquiring a reference if the device is\nalready being destroyed. If the refcount is 0, we do not arm the timer.\n\nA similar issue in IPv6 MLD is fixed in a subsequent patch."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug is reached from igmp_rcv(), registered as the IPPROTO_IGMP handler and invoked via ip_rcv \u2192 ip_local_deliver \u2192 ip_protocol_deliver_rcu() on received IPv4 packets; per kernel guidance, net/ stack flaws triggered by inbound packets are scored Network even when practical reachability is typically same-subnet.\nAC:L - An attacker controls both race sides: flooding IGMP general membership queries while concurrently deleting/tearing down the target netdev (e.g., veth in a user/net namespace, container CNI teardown, or parallel RTNETLINK unregister), and can retry until the timer is re-armed after ip_mc_down() during inetdev_destroy().\nPR:N - IGMP query processing has no authentication or capability checks on the receive path; any host that can deliver IPPROTO_IGMP packets to the interface can trigger igmp_heard_query() \u2192 igmp_gq_start_timer(), and concurrent interface destruction is normal system/orchestrator activity rather than attacker privilege on the victim.\nUI:N - Exploitation requires only attacker-sent IGMP packets timed against interface teardown; no victim must open files, click links, mount filesystems, or take any deliberate action beyond routine network interface lifecycle events.\nS:U - The use-after-free corrupts kernel heap memory within the same host kernel security authority; it is a standard in-kernel memory corruption issue, not a VM escape, IOMMU bypass, or other cross-boundary scope change.\nC:H - This is a use-after-free of struct in_device: igmp_gq_timer_expire() dereferences freed memory and calls igmpv3_send_report(), enabling disclosure of reallocated slab contents and arbitrary kernel memory read primitives via heap grooming.\nI:H - The UAF arms mr_gq_timer on a freed in_device and the expiry handler writes through dangling pointers (mr_gq_running, igmpv3_send_report paths), providing attacker-influenced heap corruption that can be developed into arbitrary kernel write and privilege escalation.\nA:H - The fix commit states the timer callback accesses freed in_device memory and causes kernel panic; UAF on a timer-armed netdev structure is a reliable oops/panic and repeatable DoS, and can be retriggered by continued IGMP query flooding during interface churn."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-02T12:49:45.779Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/7265c747eec415ca3109a6a14a419f7ae433b780"
},
{
"url": "https://git.kernel.org/stable/c/d107b4c4f8274763b7ea5ab05d45cef78e4b81ba"
},
{
"url": "https://git.kernel.org/stable/c/74b301f7f197517016befb5f5dfab01f7bc64be5"
},
{
"url": "https://git.kernel.org/stable/c/40a1e998cb266ed4cb529a0bb4fee2b0ba732702"
},
{
"url": "https://git.kernel.org/stable/c/165258303357e54b75fc19b341ae2a2b7c9e3910"
},
{
"url": "https://git.kernel.org/stable/c/75e984fe0cb9e7fbde0c8ee838c61ce8573d3ea3"
},
{
"url": "https://git.kernel.org/stable/c/8d4394ffa40508e0de72f464af351f6ca6a6cdc3"
},
{
"url": "https://git.kernel.org/stable/c/7b19c0f81ed1fdaec6bc522569be367199a9edf3"
}
],
"title": "ipv4: igmp: Fix potential UAF in igmp_gq_start_timer()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72323",
"datePublished": "2026-08-15T05:55:34.828Z",
"dateReserved": "2026-08-09T03:40:39.919Z",
"dateUpdated": "2026-09-02T12:49:45.779Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74616 (GCVE-0-2026-74616)
Vulnerability from cvelistv5
Published
2026-08-22 15:32
Modified
2026-08-25 05:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
xdp: reject clones that overrun skb_shared_info tailroom
xdpf_clone() clones broadcast copies into a single page and sets
frame_sz to PAGE_SIZE. __xdp_build_skb_from_frame() later treats that
page like a normal XDP frame and expects the usual skb_shared_info
tailroom at the end of the buffer.
The current check only rejects frames whose linear xdp_frame header,
headroom, and packet data exceed PAGE_SIZE. A source frame backed by a
larger allocation can still satisfy that check while extending into the
clone's required shared-info area. When such a clone is converted back
into an skb, build_skb_around() places skb_shared_info over live packet
bytes and later writes can corrupt XDP return metadata.
Reject clones unless their linear area fits inside
SKB_WITH_OVERHEAD(PAGE_SIZE), matching the tailroom requirement already
enforced by the XDP-to-skb conversion path.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: e624d4ed4aa8cc3c69d1359b0aaea539203ed266 Version: e624d4ed4aa8cc3c69d1359b0aaea539203ed266 Version: e624d4ed4aa8cc3c69d1359b0aaea539203ed266 Version: e624d4ed4aa8cc3c69d1359b0aaea539203ed266 Version: e624d4ed4aa8cc3c69d1359b0aaea539203ed266 Version: e624d4ed4aa8cc3c69d1359b0aaea539203ed266 Version: e624d4ed4aa8cc3c69d1359b0aaea539203ed266 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/core/xdp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "58408982fa39f9758124cec169f42854d6f98f35",
"status": "affected",
"version": "e624d4ed4aa8cc3c69d1359b0aaea539203ed266",
"versionType": "git"
},
{
"lessThan": "685edea27ac68d08fe4dbd3de74b858d2ad8e830",
"status": "affected",
"version": "e624d4ed4aa8cc3c69d1359b0aaea539203ed266",
"versionType": "git"
},
{
"lessThan": "ba13763d667e008e185fedf592d53846a5b457d1",
"status": "affected",
"version": "e624d4ed4aa8cc3c69d1359b0aaea539203ed266",
"versionType": "git"
},
{
"lessThan": "ef4b7c7046d29a67090de15af0da0d1ae8d1b192",
"status": "affected",
"version": "e624d4ed4aa8cc3c69d1359b0aaea539203ed266",
"versionType": "git"
},
{
"lessThan": "fab820f1691a9e26d9031f18aae1e9ce09078f92",
"status": "affected",
"version": "e624d4ed4aa8cc3c69d1359b0aaea539203ed266",
"versionType": "git"
},
{
"lessThan": "f463b6f4957c9c3fd1c75f8d3e5af4879fa609c0",
"status": "affected",
"version": "e624d4ed4aa8cc3c69d1359b0aaea539203ed266",
"versionType": "git"
},
{
"lessThan": "e48e8edbef2eb824201495daa5234560f632b23c",
"status": "affected",
"version": "e624d4ed4aa8cc3c69d1359b0aaea539203ed266",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/core/xdp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.14"
},
{
"lessThan": "5.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nxdp: reject clones that overrun skb_shared_info tailroom\n\nxdpf_clone() clones broadcast copies into a single page and sets\nframe_sz to PAGE_SIZE. __xdp_build_skb_from_frame() later treats that\npage like a normal XDP frame and expects the usual skb_shared_info\ntailroom at the end of the buffer.\n\nThe current check only rejects frames whose linear xdp_frame header,\nheadroom, and packet data exceed PAGE_SIZE. A source frame backed by a\nlarger allocation can still satisfy that check while extending into the\nclone\u0027s required shared-info area. When such a clone is converted back\ninto an skb, build_skb_around() places skb_shared_info over live packet\nbytes and later writes can corrupt XDP return metadata.\n\nReject clones unless their linear area fits inside\nSKB_WITH_OVERHEAD(PAGE_SIZE), matching the tailroom requirement already\nenforced by the XDP-to-skb conversion path."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - Remote packets on an XDP ingress netdev whose program calls bpf_xdp_redirect_map() with BPF_F_BROADCAST reach xdpf_clone() through dev_map_enqueue_multi(); edge L4 load balancers and container fan-out to veth peers are common deployments where cloned frames later hit __xdp_build_skb_from_frame() without any local attacker access.\nAC:L - Once broadcast devmap redirect is deployed, an attacker can reliably craft linear frames whose headroom plus payload fall in the SKB_WITH_OVERHEAD(PAGE_SIZE)..PAGE_SIZE window; no race, timing luck, or uncontrollable memory layout is required and the condition can be retried with each packet.\nPR:N - Loading/attaching the XDP program and populating the devmap requires CAP_BPF and CAP_NET_ADMIN on the host, but an unauthenticated remote sender on the already-configured datapath needs no privileges on the victim system, matching the CNA pattern used for the related devmap broadcast clone issue CVE-2026-64355.\nUI:N - Exploitation is driven entirely by network traffic processed in NAPI/softirq after XDP redirect; no victim mount, file open, or other interactive action is required beyond packets reaching the configured interface.\nS:U - The flaw corrupts skb_shared_info placement and metadata within the host kernel address space during skb construction; it does not inherently cross VM, hypervisor, or IOMMU security boundaries.\nC:H - build_skb_around() places skb_shared_info over live packet bytes and memset initializes it there; subsequent skb/shinfo access can read kernel metadata and adjacent buffer contents beyond intended bounds, constituting exploitable out-of-bounds memory disclosure.\nI:H - Overlapping skb_shared_info tailroom lets kernel writes corrupt packet data and lets attacker-influenced bytes corrupt shinfo fields used by later stack, GRO, and transmit paths, giving an out-of-bounds write primitive over frame metadata.\nA:H - Tailroom overlap during __xdp_build_skb_from_frame() can fault or corrupt state during skb construction and downstream processing, producing kernel oops/panic; an attacker can trigger this repeatedly with crafted packets on the broadcast redirect path."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:40:43.432Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/58408982fa39f9758124cec169f42854d6f98f35"
},
{
"url": "https://git.kernel.org/stable/c/685edea27ac68d08fe4dbd3de74b858d2ad8e830"
},
{
"url": "https://git.kernel.org/stable/c/ba13763d667e008e185fedf592d53846a5b457d1"
},
{
"url": "https://git.kernel.org/stable/c/ef4b7c7046d29a67090de15af0da0d1ae8d1b192"
},
{
"url": "https://git.kernel.org/stable/c/fab820f1691a9e26d9031f18aae1e9ce09078f92"
},
{
"url": "https://git.kernel.org/stable/c/f463b6f4957c9c3fd1c75f8d3e5af4879fa609c0"
},
{
"url": "https://git.kernel.org/stable/c/e48e8edbef2eb824201495daa5234560f632b23c"
}
],
"title": "xdp: reject clones that overrun skb_shared_info tailroom",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74616",
"datePublished": "2026-08-22T15:32:01.313Z",
"dateReserved": "2026-08-15T05:44:03.920Z",
"dateUpdated": "2026-08-25T05:40:43.432Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74459 (GCVE-0-2026-74459)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-19 16:36
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
can: etas_es58x: es58x_read_bulk_callback(): fix RX buffer leak on URB resubmit failure
es58x_read_bulk_callback() resubmits the RX URB after processing a received
packet. If the resubmit succeeds, the URB remains anchored and will be
handled by the normal RX path or by teardown.
However, if usb_submit_urb() fails, the callback unanchors the URB and then
returns directly. This skips the existing free_urb path, so the coherent
transfer buffer allocated with usb_alloc_coherent() is not released.
Reuse the existing free_urb path after a resubmit failure so that the RX
coherent buffer is freed before leaving the callback.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 7a0171b4921ad443fee5ed4fcb9d99fa4776edac Version: 2185ea6e4ebcb61d1224dc7d187c59723cb5ad59 Version: f6e90c113c92e83fc0963d5e60e16b0e8a268981 Version: b878444519fa03a3edd287d1963cf79ef78be2f1 Version: 18eee279e9b5bff0db1aca9475ae4bc12804f05c Version: 5eaad4f768266f1f17e01232ffe2ef009f8129b7 Version: 5eaad4f768266f1f17e01232ffe2ef009f8129b7 Version: b8f9ca88253574638bcff38900a4c28d570b1919 Version: 5.15.203 ≤ Version: 6.1.167 ≤ Version: 6.6.130 ≤ Version: 6.12.77 ≤ Version: 6.18.17 ≤ Version: 6.19.7 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/can/usb/etas_es58x/es58x_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c7ddf119544eea2d8409e12471c3f9f36ca02e3f",
"status": "affected",
"version": "7a0171b4921ad443fee5ed4fcb9d99fa4776edac",
"versionType": "git"
},
{
"lessThan": "21da1a374769751546cc131e58a4d8bd968f57b2",
"status": "affected",
"version": "2185ea6e4ebcb61d1224dc7d187c59723cb5ad59",
"versionType": "git"
},
{
"lessThan": "0ef136ba052101243ba117a1aca6f4a4c3a81142",
"status": "affected",
"version": "f6e90c113c92e83fc0963d5e60e16b0e8a268981",
"versionType": "git"
},
{
"lessThan": "b85e5c310382803d27adf6fe6554d4208bc8951c",
"status": "affected",
"version": "b878444519fa03a3edd287d1963cf79ef78be2f1",
"versionType": "git"
},
{
"lessThan": "c311f17c261fd375ddf5755f2ebe1f022c19c5b0",
"status": "affected",
"version": "18eee279e9b5bff0db1aca9475ae4bc12804f05c",
"versionType": "git"
},
{
"lessThan": "19c6c8c6cd5dd14fab5fcd744584812a57cbb78d",
"status": "affected",
"version": "5eaad4f768266f1f17e01232ffe2ef009f8129b7",
"versionType": "git"
},
{
"lessThan": "7a0cf2b2497c757c3cb1286eddf2986abb0d387b",
"status": "affected",
"version": "5eaad4f768266f1f17e01232ffe2ef009f8129b7",
"versionType": "git"
},
{
"status": "affected",
"version": "b8f9ca88253574638bcff38900a4c28d570b1919",
"versionType": "git"
},
{
"lessThan": "5.15.216",
"status": "affected",
"version": "5.15.203",
"versionType": "semver"
},
{
"lessThan": "6.1.183",
"status": "affected",
"version": "6.1.167",
"versionType": "semver"
},
{
"lessThan": "6.6.151",
"status": "affected",
"version": "6.6.130",
"versionType": "semver"
},
{
"lessThan": "6.12.103",
"status": "affected",
"version": "6.12.77",
"versionType": "semver"
},
{
"lessThan": "6.18.44",
"status": "affected",
"version": "6.18.17",
"versionType": "semver"
},
{
"lessThan": "6.20",
"status": "affected",
"version": "6.19.7",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/can/usb/etas_es58x/es58x_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "7.0"
},
{
"lessThan": "7.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.15.203",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "6.1.167",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "6.6.130",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "6.12.77",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "6.18.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "7.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "7.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.19.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: etas_es58x: es58x_read_bulk_callback(): fix RX buffer leak on URB resubmit failure\n\nes58x_read_bulk_callback() resubmits the RX URB after processing a received\npacket. If the resubmit succeeds, the URB remains anchored and will be\nhandled by the normal RX path or by teardown.\n\nHowever, if usb_submit_urb() fails, the callback unanchors the URB and then\nreturns directly. This skips the existing free_urb path, so the coherent\ntransfer buffer allocated with usb_alloc_coherent() is not released.\n\nReuse the existing free_urb path after a resubmit failure so that the RX\ncoherent buffer is freed before leaving the callback."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:36:55.813Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c7ddf119544eea2d8409e12471c3f9f36ca02e3f"
},
{
"url": "https://git.kernel.org/stable/c/21da1a374769751546cc131e58a4d8bd968f57b2"
},
{
"url": "https://git.kernel.org/stable/c/0ef136ba052101243ba117a1aca6f4a4c3a81142"
},
{
"url": "https://git.kernel.org/stable/c/b85e5c310382803d27adf6fe6554d4208bc8951c"
},
{
"url": "https://git.kernel.org/stable/c/c311f17c261fd375ddf5755f2ebe1f022c19c5b0"
},
{
"url": "https://git.kernel.org/stable/c/19c6c8c6cd5dd14fab5fcd744584812a57cbb78d"
},
{
"url": "https://git.kernel.org/stable/c/7a0cf2b2497c757c3cb1286eddf2986abb0d387b"
}
],
"title": "can: etas_es58x: es58x_read_bulk_callback(): fix RX buffer leak on URB resubmit failure",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74459",
"datePublished": "2026-08-15T12:27:00.653Z",
"dateReserved": "2026-08-15T05:44:03.900Z",
"dateUpdated": "2026-08-19T16:36:55.813Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74614 (GCVE-0-2026-74614)
Vulnerability from cvelistv5
Published
2026-08-22 15:31
Modified
2026-08-25 05:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
vsock/virtio: read virtqueues under worker locks
Commit bd50c5dc182b ("vsock/virtio: add support for device
suspend/resume") made the *_run flags transition from false to true when
restore installs replacement virtqueues. The RX, TX and event workers
read their virtqueue before locking and checking the corresponding flag,
so a worker delayed across freeze and restore can observe the replacement
queue's running state while retaining a pointer to the deleted queue.
Read each virtqueue under its mutex after checking the run flag, keeping
the pointer and state in the same queue generation.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 762c251c7f5c4ee5bef71460c6e822ed293fd69f Version: bd50c5dc182b0a52599f87b429f9a5a9cbfc9b1c Version: bd50c5dc182b0a52599f87b429f9a5a9cbfc9b1c Version: bd50c5dc182b0a52599f87b429f9a5a9cbfc9b1c Version: bd50c5dc182b0a52599f87b429f9a5a9cbfc9b1c Version: bd50c5dc182b0a52599f87b429f9a5a9cbfc9b1c Version: bd50c5dc182b0a52599f87b429f9a5a9cbfc9b1c Version: 5.15.138 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/vmw_vsock/virtio_transport.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "941329ce14c5f481223a10d1d4c8b57ea7f3048a",
"status": "affected",
"version": "762c251c7f5c4ee5bef71460c6e822ed293fd69f",
"versionType": "git"
},
{
"lessThan": "29dd10583bf9d2744cd84b862e4257c0a5699570",
"status": "affected",
"version": "bd50c5dc182b0a52599f87b429f9a5a9cbfc9b1c",
"versionType": "git"
},
{
"lessThan": "a1fb0c5b8a7c2753758aeced40971f99449dde0c",
"status": "affected",
"version": "bd50c5dc182b0a52599f87b429f9a5a9cbfc9b1c",
"versionType": "git"
},
{
"lessThan": "eae099c764c7ebdb842eb1f638913e310bdd6513",
"status": "affected",
"version": "bd50c5dc182b0a52599f87b429f9a5a9cbfc9b1c",
"versionType": "git"
},
{
"lessThan": "bd43a7ec668be428265b3209eb43647aedcf720a",
"status": "affected",
"version": "bd50c5dc182b0a52599f87b429f9a5a9cbfc9b1c",
"versionType": "git"
},
{
"lessThan": "1cecb4202afdbeddcf29d59baf596ac6ab753f7f",
"status": "affected",
"version": "bd50c5dc182b0a52599f87b429f9a5a9cbfc9b1c",
"versionType": "git"
},
{
"lessThan": "ebac8f6b1ef0e9278afe204b8692a7479988dace",
"status": "affected",
"version": "bd50c5dc182b0a52599f87b429f9a5a9cbfc9b1c",
"versionType": "git"
},
{
"lessThan": "5.15.216",
"status": "affected",
"version": "5.15.138",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/vmw_vsock/virtio_transport.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.19"
},
{
"lessThan": "5.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.15.138",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nvsock/virtio: read virtqueues under worker locks\n\nCommit bd50c5dc182b (\"vsock/virtio: add support for device\nsuspend/resume\") made the *_run flags transition from false to true when\nrestore installs replacement virtqueues. The RX, TX and event workers\nread their virtqueue before locking and checking the corresponding flag,\nso a worker delayed across freeze and restore can observe the replacement\nqueue\u0027s running state while retaining a pointer to the deleted queue.\n\nRead each virtqueue under its mutex after checking the run flag, keeping\nthe pointer and state in the same queue generation."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.4,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is in the guest virtio-vsock driver reached via AF_VSOCK sockets and virtio virtqueue completions, not via routable network protocols; per kernel CNA guidance vsock and virtio guest-driver bugs are scored Local even when the hypervisor is the peer.\nAC:L - An attacker or malicious host controls both sides of the race by flooding vsock/virtqueue traffic to queue RX/TX/event workers while virtio_vsock_freeze/restore deletes and replaces virtqueues, making the stale pre-lock virtqueue pointer race reliable and repeatable.\nPR:N - No guest privileges are required in the highest-impact scenario: a malicious hypervisor or host-initiated suspend/migrate triggers freeze/restore while virtio completions queue workers, matching confidential-computing models where the host is untrusted and holds no guest credentials.\nUI:N - Vulnerable RX/TX/event workers run automatically from virtqueue IRQ callbacks on a dedicated workqueue; no victim must mount filesystems, open files, or take deliberate action beyond normal virtio-vsock device operation and VM lifecycle events.\nS:U - Corruption is confined to the guest kernel virtio-vsock driver; exploited impact stays within the guest security boundary and does not cross to the hypervisor (guest-to-host escape would involve vhost-vsock on the host, not this guest-side driver).\nC:H - Use-after-free of a deleted virtqueue: virtqueue_disable_cb, virtqueue_get_buf, and virtqueue_enable_cb dereference freed vring_virtqueue slab memory, enabling attacker-controlled reuse and arbitrary kernel memory disclosure typical of virtio UAF bugs.\nI:H - Corrupted virtqueue metadata permits out-of-bounds ring/index manipulation and further virtqueue operations, furnishing heap corruption and arbitrary-write primitives suitable for guest ring-0 code execution and privilege escalation.\nA:H - Operating on freed virtqueues triggers KASAN slab-use-after-free and kernel BUG/oops/panic (as in the related virtio-vsock freeze bug CVE-2026-74613), fully denying guest availability even when full exploitation is not attempted."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:40:40.984Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/941329ce14c5f481223a10d1d4c8b57ea7f3048a"
},
{
"url": "https://git.kernel.org/stable/c/29dd10583bf9d2744cd84b862e4257c0a5699570"
},
{
"url": "https://git.kernel.org/stable/c/a1fb0c5b8a7c2753758aeced40971f99449dde0c"
},
{
"url": "https://git.kernel.org/stable/c/eae099c764c7ebdb842eb1f638913e310bdd6513"
},
{
"url": "https://git.kernel.org/stable/c/bd43a7ec668be428265b3209eb43647aedcf720a"
},
{
"url": "https://git.kernel.org/stable/c/1cecb4202afdbeddcf29d59baf596ac6ab753f7f"
},
{
"url": "https://git.kernel.org/stable/c/ebac8f6b1ef0e9278afe204b8692a7479988dace"
}
],
"title": "vsock/virtio: read virtqueues under worker locks",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74614",
"datePublished": "2026-08-22T15:31:59.800Z",
"dateReserved": "2026-08-15T05:44:03.920Z",
"dateUpdated": "2026-08-25T05:40:40.984Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68190 (GCVE-0-2026-68190)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
staging: rtl8723bs: fix OOB reads in rtw_get_wps_ie()
rtw_get_wps_ie() iterates over IE data from network frames without
validating that the IE header and payload fit within the remaining
buffer before reading them. Specifically:
- in_ie[cnt + 1] is read without checking cnt + 1 < in_len
- memcmp(&in_ie[cnt + 2], ...) accesses cnt + 2 without bounds check
- in_ie[cnt + 1] is used as length without verifying payload fits
Add bounds checks at the top of the loop body to break early if fewer
than 2 bytes remain for the IE header, or if the declared payload
extends past the end of the buffer. Also require at least 4 bytes of
payload before comparing the WPS OUI.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/staging/rtl8723bs/core/rtw_ieee80211.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c670efe69ec8a3360bfa596436f0250a3bf15d42",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "23b630e334f7e8f76bb22a18aca350da995af905",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "b9d9a4cd2e59df7281992a076464d2536e80c674",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "630fdca3f2437fee3ffd437c4b646ccf84c7be87",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "875479f18835ac11e21a83e88f3d4dc7ccdcd0c4",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "23c31f107b4f8f420a754a45d12599bdb78f9bb8",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "0e95ff792ae0aa6fbad9455943e9e1e4062670e9",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/staging/rtl8723bs/core/rtw_ieee80211.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.12"
},
{
"lessThan": "4.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: rtl8723bs: fix OOB reads in rtw_get_wps_ie()\n\nrtw_get_wps_ie() iterates over IE data from network frames without\nvalidating that the IE header and payload fit within the remaining\nbuffer before reading them. Specifically:\n\n- in_ie[cnt + 1] is read without checking cnt + 1 \u003c in_len\n- memcmp(\u0026in_ie[cnt + 2], ...) accesses cnt + 2 without bounds check\n- in_ie[cnt + 1] is used as length without verifying payload fits\n\nAdd bounds checks at the top of the loop body to break early if fewer\nthan 2 bytes remain for the IE header, or if the declared payload\nextends past the end of the buffer. Also require at least 4 bytes of\npayload before comparing the WPS OUI."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:04.402Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c670efe69ec8a3360bfa596436f0250a3bf15d42"
},
{
"url": "https://git.kernel.org/stable/c/23b630e334f7e8f76bb22a18aca350da995af905"
},
{
"url": "https://git.kernel.org/stable/c/b9d9a4cd2e59df7281992a076464d2536e80c674"
},
{
"url": "https://git.kernel.org/stable/c/630fdca3f2437fee3ffd437c4b646ccf84c7be87"
},
{
"url": "https://git.kernel.org/stable/c/875479f18835ac11e21a83e88f3d4dc7ccdcd0c4"
},
{
"url": "https://git.kernel.org/stable/c/23c31f107b4f8f420a754a45d12599bdb78f9bb8"
},
{
"url": "https://git.kernel.org/stable/c/0e95ff792ae0aa6fbad9455943e9e1e4062670e9"
}
],
"title": "staging: rtl8723bs: fix OOB reads in rtw_get_wps_ie()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68190",
"datePublished": "2026-08-10T12:00:07.764Z",
"dateReserved": "2026-07-30T09:28:09.373Z",
"dateUpdated": "2026-08-19T16:31:04.402Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74697 (GCVE-0-2026-74697)
Vulnerability from cvelistv5
Published
2026-08-22 15:32
Modified
2026-08-25 05:41
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
bnxt_en: Disable EOP for TPA on all chips to prevent data corruption
EOP (End of frame padding) on the AGG ring may cause overlapping of
zero padding at the end of one segment with the next segment's data.
If Relaxed Ordering (RO) is enabled, the zero padding may overwrite
valid data in the next segment and corrupt the data. Older chips
(P5 and older) do not automatically disable RO when EOP is enabled.
On some ARM systems, data corruption was reported on 57508 (P5)
chips with RO enabled.
Always disable EOP on all chips on the AGG rings when TPA is enabled
to fix the data corruption.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: bfcd8d791ec18496772d117774398e336917f56e Version: bfcd8d791ec18496772d117774398e336917f56e Version: bfcd8d791ec18496772d117774398e336917f56e Version: bfcd8d791ec18496772d117774398e336917f56e Version: bfcd8d791ec18496772d117774398e336917f56e Version: bfcd8d791ec18496772d117774398e336917f56e Version: bfcd8d791ec18496772d117774398e336917f56e |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/broadcom/bnxt/bnxt.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "68c181af7cd1ca9cbf29acd95911073bfd3c6397",
"status": "affected",
"version": "bfcd8d791ec18496772d117774398e336917f56e",
"versionType": "git"
},
{
"lessThan": "7aee22a35978b44784612c156e358e375ddf5d16",
"status": "affected",
"version": "bfcd8d791ec18496772d117774398e336917f56e",
"versionType": "git"
},
{
"lessThan": "410da4428b1f47bf9a84bdc0bcaa089d73ba2048",
"status": "affected",
"version": "bfcd8d791ec18496772d117774398e336917f56e",
"versionType": "git"
},
{
"lessThan": "b61c4911204a0a2f900e538d64ceb608f6c9614d",
"status": "affected",
"version": "bfcd8d791ec18496772d117774398e336917f56e",
"versionType": "git"
},
{
"lessThan": "aab3b5f4d8ec8598606ee011e219ef824ae25ca0",
"status": "affected",
"version": "bfcd8d791ec18496772d117774398e336917f56e",
"versionType": "git"
},
{
"lessThan": "c1962ab4645a914a91ff492735881150ddc8a79e",
"status": "affected",
"version": "bfcd8d791ec18496772d117774398e336917f56e",
"versionType": "git"
},
{
"lessThan": "c3faf548a00f4c17100cc9204746975fa46a73b9",
"status": "affected",
"version": "bfcd8d791ec18496772d117774398e336917f56e",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/broadcom/bnxt/bnxt.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.4"
},
{
"lessThan": "5.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbnxt_en: Disable EOP for TPA on all chips to prevent data corruption\n\nEOP (End of frame padding) on the AGG ring may cause overlapping of\nzero padding at the end of one segment with the next segment\u0027s data.\nIf Relaxed Ordering (RO) is enabled, the zero padding may overwrite\nvalid data in the next segment and corrupt the data. Older chips\n(P5 and older) do not automatically disable RO when EOP is enabled.\nOn some ARM systems, data corruption was reported on 57508 (P5)\nchips with RO enabled.\n\nAlways disable EOP on all chips on the AGG rings when TPA is enabled\nto fix the data corruption."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.2,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug is in bnxt_en hardware RX/TPA aggregation on incoming packets; remote TCP traffic reaches bnxt_msix\u2192napi\u2192bnxt_rx_pkt\u2192bnxt_tpa_end without local syscalls, matching network-reachable net driver guidance for internet-facing cloud servers with Broadcom NICs.\nAC:L - An attacker controls TCP segment sizes, timing, and retry volume to drive TPA aggregation on default NETIF_F_GRO_HW interfaces; the fix documents reproducible corruption on 57508/P5 ARM hosts with PCIe Relaxed Ordering, the scored deployment scenario.\nPR:N - The vulnerable receive fast path performs no authentication or capability checks on incoming frames; any remote peer sending TCP traffic to a host with an affected P5-or-older bnxt_en NIC can trigger hardware TPA aggregation and AGG-ring DMA corruption.\nUI:N - Hardware GRO/TPA is enabled by default on bnxt_en netdevs; exploitation requires only normal network exposure and attacker-sent traffic, with no victim mount, file open, or administrative action.\nS:U - Impact is corrupted RX skb payload data processed within the host kernel and network stack; it does not cross VM, container-host, or IOMMU security boundaries into a separate authority.\nC:N - EOP zero-padding overwrites valid segment bytes with zeros in page-pool RX buffers; there is no out-of-bounds read, UAF, or kernel-memory disclosure\u2014only destruction of receive-buffer contents.\nI:H - Hardware DMA corruption of TPA aggregation buffers modifies delivered skb payload bytes before napi_gro_receive, enabling remote integrity corruption of TCP/application data processed by the kernel and upper-layer services on affected hosts.\nA:L - No kernel oops or panic is documented, but repeated remote triggering can persistently corrupt received payloads, provoking TCP/application errors and degrading availability of correct network processing on affected Broadcom P5 NICs."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:41:41.297Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/68c181af7cd1ca9cbf29acd95911073bfd3c6397"
},
{
"url": "https://git.kernel.org/stable/c/7aee22a35978b44784612c156e358e375ddf5d16"
},
{
"url": "https://git.kernel.org/stable/c/410da4428b1f47bf9a84bdc0bcaa089d73ba2048"
},
{
"url": "https://git.kernel.org/stable/c/b61c4911204a0a2f900e538d64ceb608f6c9614d"
},
{
"url": "https://git.kernel.org/stable/c/aab3b5f4d8ec8598606ee011e219ef824ae25ca0"
},
{
"url": "https://git.kernel.org/stable/c/c1962ab4645a914a91ff492735881150ddc8a79e"
},
{
"url": "https://git.kernel.org/stable/c/c3faf548a00f4c17100cc9204746975fa46a73b9"
}
],
"title": "bnxt_en: Disable EOP for TPA on all chips to prevent data corruption",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74697",
"datePublished": "2026-08-22T15:32:59.073Z",
"dateReserved": "2026-08-15T05:44:03.927Z",
"dateUpdated": "2026-08-25T05:41:41.297Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64576 (GCVE-0-2026-64576)
Vulnerability from cvelistv5
Published
2026-08-05 08:09
Modified
2026-08-19 16:28
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
nexthop: initialize extack in nh_res_bucket_migrate()
nh_res_bucket_migrate() passes an uninitialized netlink_ext_ack to
call_nexthop_res_bucket_notifiers(). When
nh_notifier_res_bucket_info_init() fails (e.g. the kzalloc returns
-ENOMEM), the error is propagated back before any notifier sets
extack._msg, and the error path formats the stale pointer with
pr_err_ratelimited("%s\n", extack._msg). With CONFIG_INIT_STACK_NONE
this dereferences uninitialized stack memory:
Oops: general protection fault, probably for non-canonical address ...
KASAN: maybe wild-memory-access in range [...]
RIP: 0010:string (lib/vsprintf.c:730)
vsnprintf (lib/vsprintf.c:2945)
_printk (kernel/printk/printk.c:2504)
nh_res_bucket_migrate (net/ipv4/nexthop.c:1816)
nh_res_table_upkeep (net/ipv4/nexthop.c:1866)
rtm_new_nexthop (net/ipv4/nexthop.c:3323)
rtnetlink_rcv_msg (net/core/rtnetlink.c:7076)
netlink_sendmsg (net/netlink/af_netlink.c:1900)
Kernel panic - not syncing: Fatal exception
Zero-initialize extack so _msg is NULL on error paths that never set it.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 7c37c7e00411b3d1e0c5292368317aca69d1f324 Version: 7c37c7e00411b3d1e0c5292368317aca69d1f324 Version: 7c37c7e00411b3d1e0c5292368317aca69d1f324 Version: 7c37c7e00411b3d1e0c5292368317aca69d1f324 Version: 7c37c7e00411b3d1e0c5292368317aca69d1f324 Version: 7c37c7e00411b3d1e0c5292368317aca69d1f324 Version: 7c37c7e00411b3d1e0c5292368317aca69d1f324 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ipv4/nexthop.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "eacd2e2117e8682f937967fda1022e7f1c22d91a",
"status": "affected",
"version": "7c37c7e00411b3d1e0c5292368317aca69d1f324",
"versionType": "git"
},
{
"lessThan": "37bbd7e1d8df0bec3d187e961783e20c30533d2c",
"status": "affected",
"version": "7c37c7e00411b3d1e0c5292368317aca69d1f324",
"versionType": "git"
},
{
"lessThan": "c0936c131a71657afc635d0db2ab096d15d473e1",
"status": "affected",
"version": "7c37c7e00411b3d1e0c5292368317aca69d1f324",
"versionType": "git"
},
{
"lessThan": "3081702ea5aca0aeed9c1ade8eadf6cde8db6b7d",
"status": "affected",
"version": "7c37c7e00411b3d1e0c5292368317aca69d1f324",
"versionType": "git"
},
{
"lessThan": "d536bf205c71f700f6de2086038c3e1d77724715",
"status": "affected",
"version": "7c37c7e00411b3d1e0c5292368317aca69d1f324",
"versionType": "git"
},
{
"lessThan": "18506d7263768d76ac8e057ba55a4d9da50aad66",
"status": "affected",
"version": "7c37c7e00411b3d1e0c5292368317aca69d1f324",
"versionType": "git"
},
{
"lessThan": "6347c5314cee49f364aaf2e40ff15415a57a116e",
"status": "affected",
"version": "7c37c7e00411b3d1e0c5292368317aca69d1f324",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ipv4/nexthop.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.13"
},
{
"lessThan": "5.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnexthop: initialize extack in nh_res_bucket_migrate()\n\nnh_res_bucket_migrate() passes an uninitialized netlink_ext_ack to\ncall_nexthop_res_bucket_notifiers(). When\nnh_notifier_res_bucket_info_init() fails (e.g. the kzalloc returns\n-ENOMEM), the error is propagated back before any notifier sets\nextack._msg, and the error path formats the stale pointer with\npr_err_ratelimited(\"%s\\n\", extack._msg). With CONFIG_INIT_STACK_NONE\nthis dereferences uninitialized stack memory:\n\n Oops: general protection fault, probably for non-canonical address ...\n KASAN: maybe wild-memory-access in range [...]\n RIP: 0010:string (lib/vsprintf.c:730)\n vsnprintf (lib/vsprintf.c:2945)\n _printk (kernel/printk/printk.c:2504)\n nh_res_bucket_migrate (net/ipv4/nexthop.c:1816)\n nh_res_table_upkeep (net/ipv4/nexthop.c:1866)\n rtm_new_nexthop (net/ipv4/nexthop.c:3323)\n rtnetlink_rcv_msg (net/core/rtnetlink.c:7076)\n netlink_sendmsg (net/netlink/af_netlink.c:1900)\n Kernel panic - not syncing: Fatal exception\n\nZero-initialize extack so _msg is NULL on error paths that never set it."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Triggered via local RTM_NEWNEXTHOP over rtnetlink (sendmsg \u2192 rtnetlink_rcv_msg \u2192 rtm_new_nexthop \u2192 nh_res_table_upkeep \u2192 nh_res_bucket_migrate), not by processing remote packets.\nAC:L - An attacker can create resilient nexthop groups, ensure notifiers are registered (e.g. VXLAN pernet init), force bucket migration, and induce the kzalloc -ENOMEM path; stack contents are groomable, with no attacker-independent condition required.\nPR:L - rtnetlink_rcv_msg requires CAP_NET_ADMIN via netlink_net_capable() against the socket netns user_ns, which an unprivileged user obtains with unshare -Urn, so privileges are Low not High.\nUI:N - The attacker issues the netlink nexthop configuration and triggers migration themselves; no victim action is required.\nS:U - Impact stays within the host kernel networking authority; this is a local DoS/disclosure bug, not a VM escape, IOMMU bypass, or other cross-boundary scope change.\nC:H - pr_err_ratelimited(\"%s\") dereferences an uninitialized extack._msg pointer as a C string, enabling an attacker-groomable wild kernel read into the log, consistent with treating unbounded wild/OOB reads as Confidentiality High.\nI:N - The defect only reads through the stale _msg pointer for printing; there is no write, free, or other memory-corruption integrity primitive.\nA:H - The wild %s dereference causes a general protection fault / KASAN wild-memory-access and kernel panic, as shown in the fix commit report, so Availability is High."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:28:57.222Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/eacd2e2117e8682f937967fda1022e7f1c22d91a"
},
{
"url": "https://git.kernel.org/stable/c/37bbd7e1d8df0bec3d187e961783e20c30533d2c"
},
{
"url": "https://git.kernel.org/stable/c/c0936c131a71657afc635d0db2ab096d15d473e1"
},
{
"url": "https://git.kernel.org/stable/c/3081702ea5aca0aeed9c1ade8eadf6cde8db6b7d"
},
{
"url": "https://git.kernel.org/stable/c/d536bf205c71f700f6de2086038c3e1d77724715"
},
{
"url": "https://git.kernel.org/stable/c/18506d7263768d76ac8e057ba55a4d9da50aad66"
},
{
"url": "https://git.kernel.org/stable/c/6347c5314cee49f364aaf2e40ff15415a57a116e"
}
],
"title": "nexthop: initialize extack in nh_res_bucket_migrate()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64576",
"datePublished": "2026-08-05T08:09:32.529Z",
"dateReserved": "2026-07-19T15:36:31.798Z",
"dateUpdated": "2026-08-19T16:28:57.222Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74497 (GCVE-0-2026-74497)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-19 16:37
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ALSA: usb-audio: Clamp frame size in implicit-feedback mode
snd_usb_handle_sync_urb() scales received sync packet sizes by the sender's
stride and stores the result directly in out_packet->packet_size[i]. If a
connected USB device sends an oversized sync packet, this frame count can
exceed ep->maxframesize.
The un-clamped frame count then propagates to the playback endpoint queue,
potentially driving packet transfers beyond the endpoint's hardware frame
limits.
Cap the calculated frame count against ep->maxframesize in
snd_usb_handle_sync_urb() to prevent oversized packets from entering the
playback queue.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 28acb12014fb0c3e1edfdab1b1e3e266cf651550 Version: 28acb12014fb0c3e1edfdab1b1e3e266cf651550 Version: 28acb12014fb0c3e1edfdab1b1e3e266cf651550 Version: 28acb12014fb0c3e1edfdab1b1e3e266cf651550 Version: 28acb12014fb0c3e1edfdab1b1e3e266cf651550 Version: 28acb12014fb0c3e1edfdab1b1e3e266cf651550 Version: 28acb12014fb0c3e1edfdab1b1e3e266cf651550 Version: 28acb12014fb0c3e1edfdab1b1e3e266cf651550 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"sound/usb/endpoint.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "2d39fea6d3c19a2f5811d123114d92e3d0115fd1",
"status": "affected",
"version": "28acb12014fb0c3e1edfdab1b1e3e266cf651550",
"versionType": "git"
},
{
"lessThan": "09cf3dbbb4256a43feb91d2f51f274510a9ada47",
"status": "affected",
"version": "28acb12014fb0c3e1edfdab1b1e3e266cf651550",
"versionType": "git"
},
{
"lessThan": "cfa8d3e0e8b812c4db4d5241f62b6bdbab2bd7be",
"status": "affected",
"version": "28acb12014fb0c3e1edfdab1b1e3e266cf651550",
"versionType": "git"
},
{
"lessThan": "56ac3e7c90f6b45969c3fd07a98fad760ffd6901",
"status": "affected",
"version": "28acb12014fb0c3e1edfdab1b1e3e266cf651550",
"versionType": "git"
},
{
"lessThan": "be97fea7451d758881b95af78e900dd0d58a382a",
"status": "affected",
"version": "28acb12014fb0c3e1edfdab1b1e3e266cf651550",
"versionType": "git"
},
{
"lessThan": "2db4535d6af79276a64449201c5be5feffb31c64",
"status": "affected",
"version": "28acb12014fb0c3e1edfdab1b1e3e266cf651550",
"versionType": "git"
},
{
"lessThan": "53f0aa37eb945f3c983f61d12fc35eb33debb8a9",
"status": "affected",
"version": "28acb12014fb0c3e1edfdab1b1e3e266cf651550",
"versionType": "git"
},
{
"lessThan": "8d7a30c50c2e58a6839634ed0acde14466d1dc61",
"status": "affected",
"version": "28acb12014fb0c3e1edfdab1b1e3e266cf651550",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"sound/usb/endpoint.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.8"
},
{
"lessThan": "3.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "3.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "3.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "3.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "3.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: usb-audio: Clamp frame size in implicit-feedback mode\n\nsnd_usb_handle_sync_urb() scales received sync packet sizes by the sender\u0027s\nstride and stores the result directly in out_packet-\u003epacket_size[i]. If a\nconnected USB device sends an oversized sync packet, this frame count can\nexceed ep-\u003emaxframesize.\n\nThe un-clamped frame count then propagates to the playback endpoint queue,\npotentially driving packet transfers beyond the endpoint\u0027s hardware frame\nlimits.\n\nCap the calculated frame count against ep-\u003emaxframesize in\nsnd_usb_handle_sync_urb() to prevent oversized packets from entering the\nplayback queue."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.4,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached via local ALSA USB-audio PCM syscalls (open/hw_params/prepare/trigger) that start isochronous streaming; once implicit-feedback playback is active, malicious inbound USB sync URB completions invoke snd_usb_handle_sync_urb() without any network path.\nAC:L - A malicious USB audio gadget can deterministically send oversized implicit-feedback sync isochronous packets during active playback; the attacker controls both the device firmware and timing, with no race or uncontrollable memory-layout dependency required.\nPR:N - Exploitation is driven by a connected malicious USB audio device sending crafted isochronous IN packets; the attacker needs no host account, kernel capability, or user-namespace privilege on the victim system once playback is running.\nUI:N - After implicit-feedback USB audio playback is started, the malicious device can continuously inject oversized sync packets without further victim interaction; no additional discretionary user actions are needed beyond normal streaming operation.\nS:U - Impact is confined to host-kernel USB-audio transfer-buffer corruption and crashes within the same kernel security authority; it does not constitute a VM escape, IOMMU bypass, or other cross-scope boundary violation.\nC:H - Uncapped frame counts stored in the playback queue propagate into URB preparation, causing out-of-bounds access against kernel-coherent USB DMA transfer buffers and adjacent heap memory, enabling information disclosure from corrupted kernel memory.\nI:H - Oversized packet_size values drive memset/copy and iso_frame_desc lengths beyond allocated URB buffer bounds in prepare_silent_urb() and prepare_playback_urb(), yielding controllable out-of-bounds kernel memory writes and heap corruption.\nA:H - The resulting kernel memory corruption and invalid oversized URB transfers trigger kernel oops/panic and repeatable audio-pipeline failure; related mitigations for this implicit-feedback packet-size mismatch explicitly document crash behavior from the same root cause."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:37:55.435Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/2d39fea6d3c19a2f5811d123114d92e3d0115fd1"
},
{
"url": "https://git.kernel.org/stable/c/09cf3dbbb4256a43feb91d2f51f274510a9ada47"
},
{
"url": "https://git.kernel.org/stable/c/cfa8d3e0e8b812c4db4d5241f62b6bdbab2bd7be"
},
{
"url": "https://git.kernel.org/stable/c/56ac3e7c90f6b45969c3fd07a98fad760ffd6901"
},
{
"url": "https://git.kernel.org/stable/c/be97fea7451d758881b95af78e900dd0d58a382a"
},
{
"url": "https://git.kernel.org/stable/c/2db4535d6af79276a64449201c5be5feffb31c64"
},
{
"url": "https://git.kernel.org/stable/c/53f0aa37eb945f3c983f61d12fc35eb33debb8a9"
},
{
"url": "https://git.kernel.org/stable/c/8d7a30c50c2e58a6839634ed0acde14466d1dc61"
}
],
"title": "ALSA: usb-audio: Clamp frame size in implicit-feedback mode",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74497",
"datePublished": "2026-08-15T12:27:24.494Z",
"dateReserved": "2026-08-15T05:44:03.907Z",
"dateUpdated": "2026-08-19T16:37:55.435Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74651 (GCVE-0-2026-74651)
Vulnerability from cvelistv5
Published
2026-08-22 15:32
Modified
2026-08-25 05:41
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
staging: rtl8723bs: fix OOB read in rtw_get_wpa_ie()
rtw_get_wpa_ie() reads bytes at fixed offsets into a vendor-specific
information element without checking that the element is long enough,
causing an out-of-bounds read for a short trailing IE.
The function locates a vendor-specific IE (EID 221) with rtw_get_ie()
and then compares a 4-byte OUI+type at pbuf + 2 and reads a 2-byte
version word at pbuf + 6. Those accesses require the IE body to be at
least 6 bytes, but rtw_get_ie() only guarantees that the element fits
within the buffer; it does not enforce a minimum body length. A
vendor-specific IE whose length byte is 0 to 5, placed at the end of
the buffer, therefore makes these reads run past the end of the IE and
past the end of the buffer itself.
The buffer holds information elements taken from received management
frames and from the IE blob passed to rtw_cfg80211_set_wpa_ie(), which
is kmemdup'd to its exact length, so the read can run off the end of
the allocation.
The sibling helpers rtw_get_sec_ie(), rtw_get_wapi_ie() and
rtw_get_wps_ie() in this file already reject too-short vendor-specific
IEs before their OUI memcmp(); rtw_get_wpa_ie() was never brought in
line with them, and needs a minimum of 6 rather than 4 bytes because
of the version word. Add the missing length check.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/staging/rtl8723bs/core/rtw_ieee80211.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "4fc459c5cd8767ca4d9bf2f7becbd562639ba4d9",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "b45be82387bf759931acdd21ca7dfe740f16eb97",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "c9068f82a0906b29c905e8788edb62c3208c7c8a",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "0d19f0600fbb610c42f2a86f95c35706dc04691b",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "42c5a0d454aa5b54fec17162d9a1f8c30f8af45a",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "e167a38a8a8f50f137721fef1a1fbba0f4588b5d",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "01ab275f8f3e497a13ebbe4ded44ec0623bccde3",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "1c3e23e78862493e8cf1adad02b10ffcb8b9921c",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/staging/rtl8723bs/core/rtw_ieee80211.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.12"
},
{
"lessThan": "4.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: rtl8723bs: fix OOB read in rtw_get_wpa_ie()\n\nrtw_get_wpa_ie() reads bytes at fixed offsets into a vendor-specific\ninformation element without checking that the element is long enough,\ncausing an out-of-bounds read for a short trailing IE.\n\nThe function locates a vendor-specific IE (EID 221) with rtw_get_ie()\nand then compares a 4-byte OUI+type at pbuf + 2 and reads a 2-byte\nversion word at pbuf + 6. Those accesses require the IE body to be at\nleast 6 bytes, but rtw_get_ie() only guarantees that the element fits\nwithin the buffer; it does not enforce a minimum body length. A\nvendor-specific IE whose length byte is 0 to 5, placed at the end of\nthe buffer, therefore makes these reads run past the end of the IE and\npast the end of the buffer itself.\n\nThe buffer holds information elements taken from received management\nframes and from the IE blob passed to rtw_cfg80211_set_wpa_ie(), which\nis kmemdup\u0027d to its exact length, so the read can run off the end of\nthe allocation.\n\nThe sibling helpers rtw_get_sec_ie(), rtw_get_wapi_ie() and\nrtw_get_wps_ie() in this file already reject too-short vendor-specific\nIEs before their OUI memcmp(); rtw_get_wpa_ie() was never brought in\nline with them, and needs a minimum of 6 rather than 4 bytes because\nof the version word. Add the missing length check."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - rtw_get_wpa_ie() is reached when rtl8723bs parses attacker-controlled 802.11 management IEs from received beacons during client auth/association (OnBeacon\u2192rtw_get_bcn_info/rtw_check_bcn_info); per kernel guidance WiFi frame delivery requires an adjacent wireless attacker.\nAC:L - An adjacent attacker fully controls beacon/probe-response IE layout; placing a trailing vendor-specific IE (EID 221) with length 0\u20135 and a matching WPA OUI reliably triggers the missing minimum-length check without races or uncontrollable victim state.\nPR:N - Exploitation via malicious or spoofed over-the-air beacons requires no account, capabilities, or WPA credentials on the victim; the vulnerable parsing runs on pre-authentication and periodic beacon paths before any verified association secrets.\nUI:N - An evil-twin or rogue AP can deliver malformed beacons matching a victim\u0027s connected BSSID during automatic beacon processing without requiring new user clicks, mounts, or connect actions beyond routine WiFi operation.\nS:U - Impact is confined to kernel memory reads/crashes inside the rtl8723bs WiFi driver on the same host; there is no demonstrated VM escape, container breakout, or IOMMU boundary crossing.\nC:H - The bug performs unchecked memcmp()/memcpy() up to six bytes past the end of a kmemdup\u0027d IE buffer or declared IE length, reading adjacent kernel/heap memory; under the conservative OOB-read rule this is high confidentiality impact.\nI:N - The flaw is a read-only out-of-bounds access with no memory write, structure corruption, or demonstrated control-flow hijack primitive; it cannot modify kernel data or achieve code execution on its own.\nA:H - Reading past a kmemdup allocation or declared IE boundary can fault on unmapped pages or provoke a kernel oops during beacon/auth processing; an adjacent attacker can repeat crafted management frames to deny availability."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:41:09.288Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/4fc459c5cd8767ca4d9bf2f7becbd562639ba4d9"
},
{
"url": "https://git.kernel.org/stable/c/b45be82387bf759931acdd21ca7dfe740f16eb97"
},
{
"url": "https://git.kernel.org/stable/c/c9068f82a0906b29c905e8788edb62c3208c7c8a"
},
{
"url": "https://git.kernel.org/stable/c/0d19f0600fbb610c42f2a86f95c35706dc04691b"
},
{
"url": "https://git.kernel.org/stable/c/42c5a0d454aa5b54fec17162d9a1f8c30f8af45a"
},
{
"url": "https://git.kernel.org/stable/c/e167a38a8a8f50f137721fef1a1fbba0f4588b5d"
},
{
"url": "https://git.kernel.org/stable/c/01ab275f8f3e497a13ebbe4ded44ec0623bccde3"
},
{
"url": "https://git.kernel.org/stable/c/1c3e23e78862493e8cf1adad02b10ffcb8b9921c"
}
],
"title": "staging: rtl8723bs: fix OOB read in rtw_get_wpa_ie()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74651",
"datePublished": "2026-08-22T15:32:27.073Z",
"dateReserved": "2026-08-15T05:44:03.923Z",
"dateUpdated": "2026-08-25T05:41:09.288Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74488 (GCVE-0-2026-74488)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-19 16:37
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames
mwifiex_11n_dispatch_amsdu_pkt() splits an A-MSDU with
ieee80211_amsdu_to_8023s() and walks the resulting subframes. For each
subframe it passes the subframe data pointer to
mwifiex_process_tdls_action_frame(), but pairs it with skb->len, the
length of the A-MSDU parent, instead of rx_skb->len:
rx_skb = __skb_dequeue(&list);
rx_hdr = (struct rx_packet_hdr *)rx_skb->data;
if (ISSUPP_TDLS_ENABLED(priv->adapter->fw_cap_info) &&
ntohs(rx_hdr->eth803_hdr.h_proto) == ETH_P_TDLS) {
mwifiex_process_tdls_action_frame(priv, (u8 *)rx_hdr,
skb->len);
}
The parent is not a valid description of that buffer, and may not be
valid memory at all. ieee80211_amsdu_to_8023s() ends with
if (!reuse_skb)
dev_kfree_skb(skb);
and it only sets reuse_skb when the parent is linear, is not a
head_frag, and is being consumed as the *last* subframe. So when the
parent does not qualify for reuse it has already been freed, and the
read of skb->len is a use-after-free. When it is reused, skb->len is
the length of the last subframe, applied to every earlier subframe,
which over-states the buffer whenever an earlier subframe is shorter.
The callee cannot absorb a wrong length, because it derives its own
ceiling from the value it is given. Each frame type computes
ies_len = len - sizeof(struct ethhdr) - TDLS_*_FIX_LEN;
and the element walk is then bounded entirely against that ceiling,
for (end = pos + ies_len; pos + 1 < end; pos += 2 + pos[1]) {
u8 ie_len = pos[1];
if (pos + 2 + ie_len > end)
break;
so a too-large len moves end past the end of the subframe and the walk
reads and copies beyond it. The A-MSDU layout is chosen by the sender,
which makes the difference between the last subframe and a shorter
earlier one remotely selectable. Reaching this requires TDLS support in
firmware and the TDLS ethertype on the subframe.
The other caller, mwifiex_process_rx_packet(), is correct: it passes a
pointer and a length that describe the same region of the RX buffer.
Pass rx_skb->len, the length of the subframe actually being parsed.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 776f742040ca5eb6242c60f29ac73d5752a5b621 Version: 776f742040ca5eb6242c60f29ac73d5752a5b621 Version: 776f742040ca5eb6242c60f29ac73d5752a5b621 Version: 776f742040ca5eb6242c60f29ac73d5752a5b621 Version: 776f742040ca5eb6242c60f29ac73d5752a5b621 Version: 776f742040ca5eb6242c60f29ac73d5752a5b621 Version: 776f742040ca5eb6242c60f29ac73d5752a5b621 Version: 776f742040ca5eb6242c60f29ac73d5752a5b621 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/marvell/mwifiex/11n_rxreorder.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "707664027bb9307f7268eda403af7c4ccd9b8644",
"status": "affected",
"version": "776f742040ca5eb6242c60f29ac73d5752a5b621",
"versionType": "git"
},
{
"lessThan": "3b02275833a0d3e6583627995d614fa99bdf364f",
"status": "affected",
"version": "776f742040ca5eb6242c60f29ac73d5752a5b621",
"versionType": "git"
},
{
"lessThan": "a1f0f7dc7eb15754e6931b433edb7beb754c996a",
"status": "affected",
"version": "776f742040ca5eb6242c60f29ac73d5752a5b621",
"versionType": "git"
},
{
"lessThan": "25e5a3fe4f15e30f74eca42cbf3bcc3a3fbeda79",
"status": "affected",
"version": "776f742040ca5eb6242c60f29ac73d5752a5b621",
"versionType": "git"
},
{
"lessThan": "ece2ebb34247d573142617dfc534a9dc11ba59be",
"status": "affected",
"version": "776f742040ca5eb6242c60f29ac73d5752a5b621",
"versionType": "git"
},
{
"lessThan": "c9dcfe6b8b71369e1d732e2ff622c3696a2f032c",
"status": "affected",
"version": "776f742040ca5eb6242c60f29ac73d5752a5b621",
"versionType": "git"
},
{
"lessThan": "5a21ab03829cb6d2682c127f22e2b9cd63b4393f",
"status": "affected",
"version": "776f742040ca5eb6242c60f29ac73d5752a5b621",
"versionType": "git"
},
{
"lessThan": "99a948382af8a225e2d5e54a7052158cd6281cc6",
"status": "affected",
"version": "776f742040ca5eb6242c60f29ac73d5752a5b621",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/marvell/mwifiex/11n_rxreorder.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.5"
},
{
"lessThan": "4.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames\n\nmwifiex_11n_dispatch_amsdu_pkt() splits an A-MSDU with\nieee80211_amsdu_to_8023s() and walks the resulting subframes. For each\nsubframe it passes the subframe data pointer to\nmwifiex_process_tdls_action_frame(), but pairs it with skb-\u003elen, the\nlength of the A-MSDU parent, instead of rx_skb-\u003elen:\n\n\trx_skb = __skb_dequeue(\u0026list);\n\trx_hdr = (struct rx_packet_hdr *)rx_skb-\u003edata;\n\tif (ISSUPP_TDLS_ENABLED(priv-\u003eadapter-\u003efw_cap_info) \u0026\u0026\n\t ntohs(rx_hdr-\u003eeth803_hdr.h_proto) == ETH_P_TDLS) {\n\t\tmwifiex_process_tdls_action_frame(priv, (u8 *)rx_hdr,\n\t\t\t\t\t\t skb-\u003elen);\n\t}\n\nThe parent is not a valid description of that buffer, and may not be\nvalid memory at all. ieee80211_amsdu_to_8023s() ends with\n\n\tif (!reuse_skb)\n\t\tdev_kfree_skb(skb);\n\nand it only sets reuse_skb when the parent is linear, is not a\nhead_frag, and is being consumed as the *last* subframe. So when the\nparent does not qualify for reuse it has already been freed, and the\nread of skb-\u003elen is a use-after-free. When it is reused, skb-\u003elen is\nthe length of the last subframe, applied to every earlier subframe,\nwhich over-states the buffer whenever an earlier subframe is shorter.\n\nThe callee cannot absorb a wrong length, because it derives its own\nceiling from the value it is given. Each frame type computes\n\n\ties_len = len - sizeof(struct ethhdr) - TDLS_*_FIX_LEN;\n\nand the element walk is then bounded entirely against that ceiling,\n\n\tfor (end = pos + ies_len; pos + 1 \u003c end; pos += 2 + pos[1]) {\n\t\tu8 ie_len = pos[1];\n\n\t\tif (pos + 2 + ie_len \u003e end)\n\t\t\tbreak;\n\nso a too-large len moves end past the end of the subframe and the walk\nreads and copies beyond it. The A-MSDU layout is chosen by the sender,\nwhich makes the difference between the last subframe and a shorter\nearlier one remotely selectable. Reaching this requires TDLS support in\nfirmware and the TDLS ethertype on the subframe.\n\nThe other caller, mwifiex_process_rx_packet(), is correct: it passes a\npointer and a length that describe the same region of the RX buffer.\n\nPass rx_skb-\u003elen, the length of the subframe actually being parsed."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The bug is reached when the mwifiex driver processes attacker-supplied A-MSDU TDLS frames received over WiFi from a nearby peer, AP, or injector on the same wireless segment, which is an adjacent RF attack vector rather than remote Internet or local syscall access.\nAC:L - Once TDLS-capable mwifiex firmware receives an A-MSDU, the attacker fully controls subframe sizes and TDLS content to trigger either the skb use-after-free or the overstated-length out-of-bounds parse reliably without depending on uncontrollable timing or memory layout.\nPR:N - Exploitation requires only the ability to deliver crafted 802.11 data frames to the victim radio; it does not require any local account, capability, or root access on the Linux host and is not gated by user-namespace privilege boundaries.\nUI:N - No victim user action beyond normal wireless operation is required; the driver parses malicious TDLS subframes automatically during receive and A-MSDU decomposition before forwarding traffic to the network stack.\nS:U - Impact is confined to kernel memory corruption and driver state within the host kernel security authority; it does not by itself cross a VM, container, or IOMMU boundary to affect a separate security domain.\nC:H - The skb use-after-free reads freed sk_buff metadata and the inflated length drives an out-of-bounds IE walk that reads kernel memory beyond the subframe, including attacker-positioned bytes from subsequent A-MSDU subframes, enabling substantial information disclosure.\nI:H - The same out-of-bounds parse copies attacker-controlled IE data from beyond the subframe into heap-allocated sta_node/tdls_cap structures via memcpy, providing a memory-corruption primitive that can be developed into arbitrary kernel write or code execution.\nA:H - Reading skb-\u003elen after the parent A-MSDU skb may already be freed can immediately fault or corrupt memory, and the out-of-bounds TDLS element parsing can provoke kernel oopses or panics even when full exploitation is not attempted."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:37:43.361Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/707664027bb9307f7268eda403af7c4ccd9b8644"
},
{
"url": "https://git.kernel.org/stable/c/3b02275833a0d3e6583627995d614fa99bdf364f"
},
{
"url": "https://git.kernel.org/stable/c/a1f0f7dc7eb15754e6931b433edb7beb754c996a"
},
{
"url": "https://git.kernel.org/stable/c/25e5a3fe4f15e30f74eca42cbf3bcc3a3fbeda79"
},
{
"url": "https://git.kernel.org/stable/c/ece2ebb34247d573142617dfc534a9dc11ba59be"
},
{
"url": "https://git.kernel.org/stable/c/c9dcfe6b8b71369e1d732e2ff622c3696a2f032c"
},
{
"url": "https://git.kernel.org/stable/c/5a21ab03829cb6d2682c127f22e2b9cd63b4393f"
},
{
"url": "https://git.kernel.org/stable/c/99a948382af8a225e2d5e54a7052158cd6281cc6"
}
],
"title": "wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74488",
"datePublished": "2026-08-15T12:27:18.867Z",
"dateReserved": "2026-08-15T05:44:03.905Z",
"dateUpdated": "2026-08-19T16:37:43.361Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68414 (GCVE-0-2026-68414)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-19 16:35
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: cfg80211: cancel sched scan results work on unregister
cfg80211_sched_scan_results() can queue rdev->sched_scan_res_wk from a
driver result notification while a scheduled scan request is present. The
work callback recovers the containing cfg80211_registered_device and then
locks the wiphy and walks the scheduled-scan request list.
wiphy_unregister() already makes the wiphy unreachable and drains rdev work
items before cfg80211_dev_free() can release the object, but it does not
drain sched_scan_res_wk. A queued or running result work item can therefore
cross the unregister/free boundary and access freed rdev state.
The buggy scenario involves two paths, with each column showing the order
within that path:
scheduled-scan result path: unregister/free path:
1. cfg80211_sched_scan_results() 1. interface teardown stops and
queues rdev->sched_scan_res_wk. removes the scheduled scan request.
2. cfg80211_wq starts the work 2. wiphy_unregister() drains other
item and recovers rdev. rdev work items.
3. The worker locks rdev->wiphy 3. cfg80211_dev_free() destroys and
and walks rdev state. frees rdev.
Cancel sched_scan_res_wk in wiphy_unregister() alongside the other rdev
work items. cancel_work_sync() removes a pending result notification and
waits for an already running callback, so cfg80211_dev_free() cannot free
rdev while this work item is still active.
Validation reproduced this kernel report:
BUG: KASAN: use-after-free in cfg80211_sched_scan_results_wk+0x4a6/0x530
Workqueue: cfg80211 cfg80211_sched_scan_results_wk [cfg80211]
Read of size 8
Call trace:
dump_stack_lvl+0x66/0xa0
print_report+0xce/0x630
cfg80211_sched_scan_results_wk+0x4a6/0x530
srso_alias_return_thunk+0x5/0xfbef5
__virt_addr_valid+0x224/0x430
kasan_report+0xac/0xe0
lockdep_hardirqs_on_prepare+0xea/0x1a0
process_one_work+0x8d0/0x18f0 (kernel/workqueue.c:3212)
lock_is_held_type+0x8f/0x100
worker_thread+0x5ad/0xfd0
__kthread_parkme+0xc6/0x200
kthread+0x31e/0x410
trace_hardirqs_on+0x1a/0x170
ret_from_fork+0x576/0x810
__switch_to+0x57e/0xe20
__switch_to_asm+0x33/0x70
ret_from_fork_asm+0x1a/0x30
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 807f8a8c300435d5483e8d78df9dcdbc27333166 Version: 807f8a8c300435d5483e8d78df9dcdbc27333166 Version: 807f8a8c300435d5483e8d78df9dcdbc27333166 Version: 807f8a8c300435d5483e8d78df9dcdbc27333166 Version: 807f8a8c300435d5483e8d78df9dcdbc27333166 Version: 807f8a8c300435d5483e8d78df9dcdbc27333166 Version: 807f8a8c300435d5483e8d78df9dcdbc27333166 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/wireless/core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c0fa1f3a4b021a5c6373169fd6c9bb4261d676a0",
"status": "affected",
"version": "807f8a8c300435d5483e8d78df9dcdbc27333166",
"versionType": "git"
},
{
"lessThan": "b51b42b974461fd0f688baad85f10e2b8ab215c5",
"status": "affected",
"version": "807f8a8c300435d5483e8d78df9dcdbc27333166",
"versionType": "git"
},
{
"lessThan": "3368457b4871ae8f0f88d19c9a3e6270e850ede6",
"status": "affected",
"version": "807f8a8c300435d5483e8d78df9dcdbc27333166",
"versionType": "git"
},
{
"lessThan": "308ffdf575560d7e7b8b21f1e3ca6276630f73bf",
"status": "affected",
"version": "807f8a8c300435d5483e8d78df9dcdbc27333166",
"versionType": "git"
},
{
"lessThan": "9293574ac208d18c11073538851fb69355beb3b5",
"status": "affected",
"version": "807f8a8c300435d5483e8d78df9dcdbc27333166",
"versionType": "git"
},
{
"lessThan": "b119c70b24776c8ab2a2c0515397b3b0ad4e66cd",
"status": "affected",
"version": "807f8a8c300435d5483e8d78df9dcdbc27333166",
"versionType": "git"
},
{
"lessThan": "edf0730be33696a1bd142792830d392129e495cc",
"status": "affected",
"version": "807f8a8c300435d5483e8d78df9dcdbc27333166",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/wireless/core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.0"
},
{
"lessThan": "3.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: cfg80211: cancel sched scan results work on unregister\n\ncfg80211_sched_scan_results() can queue rdev-\u003esched_scan_res_wk from a\ndriver result notification while a scheduled scan request is present. The\nwork callback recovers the containing cfg80211_registered_device and then\nlocks the wiphy and walks the scheduled-scan request list.\n\nwiphy_unregister() already makes the wiphy unreachable and drains rdev work\nitems before cfg80211_dev_free() can release the object, but it does not\ndrain sched_scan_res_wk. A queued or running result work item can therefore\ncross the unregister/free boundary and access freed rdev state.\n\nThe buggy scenario involves two paths, with each column showing the order\nwithin that path:\n\nscheduled-scan result path: unregister/free path:\n1. cfg80211_sched_scan_results() 1. interface teardown stops and\n queues rdev-\u003esched_scan_res_wk. removes the scheduled scan request.\n2. cfg80211_wq starts the work 2. wiphy_unregister() drains other\n item and recovers rdev. rdev work items.\n3. The worker locks rdev-\u003ewiphy 3. cfg80211_dev_free() destroys and\n and walks rdev state. frees rdev.\n\nCancel sched_scan_res_wk in wiphy_unregister() alongside the other rdev\nwork items. cancel_work_sync() removes a pending result notification and\nwaits for an already running callback, so cfg80211_dev_free() cannot free\nrdev while this work item is still active.\n\nValidation reproduced this kernel report:\nBUG: KASAN: use-after-free in cfg80211_sched_scan_results_wk+0x4a6/0x530\nWorkqueue: cfg80211 cfg80211_sched_scan_results_wk [cfg80211]\nRead of size 8\nCall trace:\n dump_stack_lvl+0x66/0xa0\n print_report+0xce/0x630\n cfg80211_sched_scan_results_wk+0x4a6/0x530\n srso_alias_return_thunk+0x5/0xfbef5\n __virt_addr_valid+0x224/0x430\n kasan_report+0xac/0xe0\n lockdep_hardirqs_on_prepare+0xea/0x1a0\n process_one_work+0x8d0/0x18f0 (kernel/workqueue.c:3212)\n lock_is_held_type+0x8f/0x100\n worker_thread+0x5ad/0xfd0\n __kthread_parkme+0xc6/0x200\n kthread+0x31e/0x410\n trace_hardirqs_on+0x1a/0x170\n ret_from_fork+0x576/0x810\n __switch_to+0x57e/0xe20\n __switch_to_asm+0x33/0x70\n ret_from_fork_asm+0x1a/0x30"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The work item is queued from driver PNO/background-scan match notifications that are produced by received 802.11 frames, so an attacker within WiFi range can drive cfg80211_sched_scan_results() by beaconing SSIDs matching the device\u0027s scheduled-scan match set. This is 802.11 frame injection, i.e. adjacent network reach.\nAC:H - The UAF requires the result-notification work to be queued or running exactly while wiphy_unregister()/cfg80211_dev_free() tears the rdev down; the attacker can drive and time the result notifications but cannot force the device-removal/module-unload half of the race, which is a condition outside their control.\nPR:N - No credentials or association are needed \u2014 an unauthenticated attacker in range simply transmits beacons/probe responses matching the scheduled scan already running on the victim (started by the system\u0027s normal wpa_supplicant/NetworkManager PNO), and the driver notifies cfg80211 unconditionally.\nUI:N - Scheduled scan runs continuously in the background on typical laptop, phone and embedded WiFi deployments, and the unregister side is a system/device event; no victim action such as opening a file or mounting anything is required.\nS:U - The freed object and all corrupted state are cfg80211 kernel structures, so the impact stays within the kernel\u0027s own security authority with no crossing of a VM, IOMMU or sandbox boundary.\nC:H - The worker reads freed rdev memory and then feeds freed scheduled-scan request contents into nl80211_send_sched_scan(), leaking reclaimed slab data to userspace netlink listeners; a controlled reallocation of the freed rdev gives an arbitrary-read style disclosure primitive.\nI:H - After the free the worker performs writes into the freed object \u2014 mutex_lock on rdev-\u003ewiphy.mtx, spin_lock on rdev-\u003ebss_lock, clearing req-\u003ereport_results, and list/refcount manipulation in __cfg80211_bss_expire() \u2014 which corrupts whatever object reclaims the slab and is leverageable for control-flow hijack via heap spraying.\nA:H - The confirmed KASAN use-after-free in cfg80211_sched_scan_results_wk() corrupts and dereferences freed memory from a workqueue context, reliably producing an oops/panic and taking down the system."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:35:12.312Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c0fa1f3a4b021a5c6373169fd6c9bb4261d676a0"
},
{
"url": "https://git.kernel.org/stable/c/b51b42b974461fd0f688baad85f10e2b8ab215c5"
},
{
"url": "https://git.kernel.org/stable/c/3368457b4871ae8f0f88d19c9a3e6270e850ede6"
},
{
"url": "https://git.kernel.org/stable/c/308ffdf575560d7e7b8b21f1e3ca6276630f73bf"
},
{
"url": "https://git.kernel.org/stable/c/9293574ac208d18c11073538851fb69355beb3b5"
},
{
"url": "https://git.kernel.org/stable/c/b119c70b24776c8ab2a2c0515397b3b0ad4e66cd"
},
{
"url": "https://git.kernel.org/stable/c/edf0730be33696a1bd142792830d392129e495cc"
}
],
"title": "wifi: cfg80211: cancel sched scan results work on unregister",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68414",
"datePublished": "2026-08-10T12:04:34.459Z",
"dateReserved": "2026-07-30T09:28:09.391Z",
"dateUpdated": "2026-08-19T16:35:12.312Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80798 (GCVE-0-2026-80798)
Vulnerability from cvelistv5
Published
2026-09-04 15:13
Modified
2026-09-04 15:13
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
nfc: llcp: reject PDUs shorter than the LLCP header
Every LLCP PDU begins with a two-byte header (DSAP/SSAP + PTYPE), but the
receive path never checked that a frame is at least LLCP_HEADER_SIZE bytes
before parsing it.
nfc_llcp_rx_skb() reads the header via nfc_llcp_ptype()/nfc_llcp_dsap()/
nfc_llcp_ssap(), which dereference pdu->data[0] and pdu->data[1], and a
CONNECT or CC PDU then computes
tlv_array_len = skb->len - LLCP_HEADER_SIZE;
as a size_t and hands it to the TLV walk. When the frame is shorter than
the header the subtraction wraps to a huge value and the walk runs far
past the buffer, an out-of-bounds read.
A nearby NFC device can reach this without authentication; LLCP link
activation happens automatically after NFC-DEP.
Guard the common receive choke point __nfc_llcp_recv(), shared by both the
target (nfc_llcp_data_received()) and initiator (nfc_llcp_recv()) paths, so
a short skb is dropped before the rx_work worker parses it. Use
pskb_may_pull() rather than a skb->len test so the two header bytes are
guaranteed to sit in the skb linear area even for a non-linear skb,
matching how the sibling NCI and HCI receive paths validate their headers.
Reproduced with a KFENCE out-of-bounds read via /dev/virtual_nci on
linux-next.
Found by 0sec automated security-research tooling (https://0sec.ai).
References
| URL | Tags | ||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d646960f7986fefb460a2b062d5ccc8ccfeacc3a Version: d646960f7986fefb460a2b062d5ccc8ccfeacc3a Version: d646960f7986fefb460a2b062d5ccc8ccfeacc3a Version: d646960f7986fefb460a2b062d5ccc8ccfeacc3a Version: d646960f7986fefb460a2b062d5ccc8ccfeacc3a Version: d646960f7986fefb460a2b062d5ccc8ccfeacc3a Version: d646960f7986fefb460a2b062d5ccc8ccfeacc3a Version: d646960f7986fefb460a2b062d5ccc8ccfeacc3a Version: d646960f7986fefb460a2b062d5ccc8ccfeacc3a |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/nfc/llcp_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "e6ec76a68dce04884dfeccfe5a5f0e9f67c0ec82",
"status": "affected",
"version": "d646960f7986fefb460a2b062d5ccc8ccfeacc3a",
"versionType": "git"
},
{
"lessThan": "f36cffea24bf3e2cc29a00d4b51dbcadc087d810",
"status": "affected",
"version": "d646960f7986fefb460a2b062d5ccc8ccfeacc3a",
"versionType": "git"
},
{
"lessThan": "a7b9b449f5a5132221fff6adc11a9431ab8cd914",
"status": "affected",
"version": "d646960f7986fefb460a2b062d5ccc8ccfeacc3a",
"versionType": "git"
},
{
"lessThan": "3793d768b40f38bb97265dd5b9a8b8655c4e1b1d",
"status": "affected",
"version": "d646960f7986fefb460a2b062d5ccc8ccfeacc3a",
"versionType": "git"
},
{
"lessThan": "eab47618e282602197db287ecbd1b09d356a2515",
"status": "affected",
"version": "d646960f7986fefb460a2b062d5ccc8ccfeacc3a",
"versionType": "git"
},
{
"lessThan": "e969e98410051b1ef8cc318bfe0c7e3f24ec766d",
"status": "affected",
"version": "d646960f7986fefb460a2b062d5ccc8ccfeacc3a",
"versionType": "git"
},
{
"lessThan": "ae5f20f5842f440b72d030e3a34fe182dd8eae42",
"status": "affected",
"version": "d646960f7986fefb460a2b062d5ccc8ccfeacc3a",
"versionType": "git"
},
{
"lessThan": "d3d90243393c48146911c67fd3792b549d21d9e6",
"status": "affected",
"version": "d646960f7986fefb460a2b062d5ccc8ccfeacc3a",
"versionType": "git"
},
{
"lessThan": "95674f506c6376d6722a23144c9acd26609771ed",
"status": "affected",
"version": "d646960f7986fefb460a2b062d5ccc8ccfeacc3a",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/nfc/llcp_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.3"
},
{
"lessThan": "3.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.267",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.218",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.185",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.154",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.106",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.47",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.1",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.267",
"versionStartIncluding": "3.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.218",
"versionStartIncluding": "3.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.185",
"versionStartIncluding": "3.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.154",
"versionStartIncluding": "3.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.106",
"versionStartIncluding": "3.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.47",
"versionStartIncluding": "3.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.11",
"versionStartIncluding": "3.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.1",
"versionStartIncluding": "3.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "3.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: llcp: reject PDUs shorter than the LLCP header\n\nEvery LLCP PDU begins with a two-byte header (DSAP/SSAP + PTYPE), but the\nreceive path never checked that a frame is at least LLCP_HEADER_SIZE bytes\nbefore parsing it.\n\nnfc_llcp_rx_skb() reads the header via nfc_llcp_ptype()/nfc_llcp_dsap()/\nnfc_llcp_ssap(), which dereference pdu-\u003edata[0] and pdu-\u003edata[1], and a\nCONNECT or CC PDU then computes\n\n\ttlv_array_len = skb-\u003elen - LLCP_HEADER_SIZE;\n\nas a size_t and hands it to the TLV walk. When the frame is shorter than\nthe header the subtraction wraps to a huge value and the walk runs far\npast the buffer, an out-of-bounds read.\n\nA nearby NFC device can reach this without authentication; LLCP link\nactivation happens automatically after NFC-DEP.\n\nGuard the common receive choke point __nfc_llcp_recv(), shared by both the\ntarget (nfc_llcp_data_received()) and initiator (nfc_llcp_recv()) paths, so\na short skb is dropped before the rx_work worker parses it. Use\npskb_may_pull() rather than a skb-\u003elen test so the two header bytes are\nguaranteed to sit in the skb linear area even for a non-linear skb,\nmatching how the sibling NCI and HCI receive paths validate their headers.\n\nReproduced with a KFENCE out-of-bounds read via /dev/virtual_nci on\nlinux-next.\n\nFound by 0sec automated security-research tooling (https://0sec.ai)."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T15:13:12.282Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/e6ec76a68dce04884dfeccfe5a5f0e9f67c0ec82"
},
{
"url": "https://git.kernel.org/stable/c/f36cffea24bf3e2cc29a00d4b51dbcadc087d810"
},
{
"url": "https://git.kernel.org/stable/c/a7b9b449f5a5132221fff6adc11a9431ab8cd914"
},
{
"url": "https://git.kernel.org/stable/c/3793d768b40f38bb97265dd5b9a8b8655c4e1b1d"
},
{
"url": "https://git.kernel.org/stable/c/eab47618e282602197db287ecbd1b09d356a2515"
},
{
"url": "https://git.kernel.org/stable/c/e969e98410051b1ef8cc318bfe0c7e3f24ec766d"
},
{
"url": "https://git.kernel.org/stable/c/ae5f20f5842f440b72d030e3a34fe182dd8eae42"
},
{
"url": "https://git.kernel.org/stable/c/d3d90243393c48146911c67fd3792b549d21d9e6"
},
{
"url": "https://git.kernel.org/stable/c/95674f506c6376d6722a23144c9acd26609771ed"
}
],
"title": "nfc: llcp: reject PDUs shorter than the LLCP header",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80798",
"datePublished": "2026-09-04T15:13:12.282Z",
"dateReserved": "2026-08-26T14:34:25.793Z",
"dateUpdated": "2026-09-04T15:13:12.282Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80840 (GCVE-0-2026-80840)
Vulnerability from cvelistv5
Published
2026-09-04 15:54
Modified
2026-09-04 15:54
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ipv6: seg6: clear IPv4 control block on IPIP decapsulation
End.DX4 and End.DT4 decapsulate an IPv4 packet through
decap_and_validate() and send it directly to IPv4 routing. The inner
packet therefore bypasses ip_rcv_core(), which normally clears IPCB
before IPv4 interprets skb->cb.
The skb instead retains IP6CB data from the outer packet. IP6CB and
IPCB use the same skb->cb storage, so IP6CB(skb)->lastopt overlaps
IPCB(skb)->opt.optlen and srr, while IP6CB(skb)->nhoff overlaps rr and
ts.
The sender can make the stale optlen byte nonzero with a valid outer
extension-header chain. The reproducers put an eight-byte Destination
Options header immediately after the 40-byte IPv6 header and before the
Segment Routing Header. ipv6_destopt_rcv() records the sender-controlled
Destination Options offset in both lastopt and nhoff, setting them to
40. On the reproduced little-endian x86-64 kernel, IPv4 therefore sees
optlen = 40 and rr = 40.
Both tcp_v4_save_options() and __ip_options_echo() skip option copying
when optlen is zero. Here optlen is 40, so the TCP SYN path allocates
room for 40 bytes of option data and calls __ip_options_echo(). The
stale rr value makes that function read inner packet byte 41 as the
Record Route option length. The reproducers set that sender-controlled
byte to 255, so __ip_options_echo() copies 255 bytes into the 40-byte
option-data area.
Separate End.DX4 and End.DT4 reproducers on the unpatched v7.2-rc5
kernel both produced:
BUG: KASAN: slab-out-of-bounds in __ip_options_echo()
Write of size 255
The relevant End.DX4 call path is:
__ip_options_echo
tcp_v4_route_req
tcp_conn_request
tcp_v4_conn_request
tcp_rcv_state_process
tcp_v4_do_rcv
tcp_v4_rcv
ip_protocol_deliver_rcu
ip_local_deliver_finish
ip_local_deliver
input_action_end_dx4_finish
input_action_end_dx4
The relevant End.DT4 call path is:
__ip_options_echo
tcp_v4_route_req
tcp_conn_request
tcp_v4_conn_request
tcp_rcv_state_process
tcp_v4_do_rcv
tcp_v4_rcv
ip_protocol_deliver_rcu
ip_local_deliver_finish
ip_local_deliver
input_action_end_dt4
tcp_v4_save_options() is inlined into the tcp_v4_route_req() path, so
it does not appear as a separate frame.
When decap_and_validate() handles IPPROTO_IPIP, save the ingress
interface from IP6CB, clear IPCB, and restore the saved value. Doing
this in the common decapsulation path covers End.DX4, End.DT4, and
End.DT46's IPv4 arm.
Use IP6CB(skb)->iif rather than skb->skb_iif. These actions run after
l3mdev processing, which can replace skb_iif with the L3 master;
IP6CB iif still records the receiving interface set at IPv6 ingress.
References
| URL | Tags | ||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 891ef8dd2a8d14e4e73a81dcdb135b574c57f556 Version: 891ef8dd2a8d14e4e73a81dcdb135b574c57f556 Version: 891ef8dd2a8d14e4e73a81dcdb135b574c57f556 Version: 891ef8dd2a8d14e4e73a81dcdb135b574c57f556 Version: 891ef8dd2a8d14e4e73a81dcdb135b574c57f556 Version: 891ef8dd2a8d14e4e73a81dcdb135b574c57f556 Version: 891ef8dd2a8d14e4e73a81dcdb135b574c57f556 Version: 891ef8dd2a8d14e4e73a81dcdb135b574c57f556 Version: 891ef8dd2a8d14e4e73a81dcdb135b574c57f556 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ipv6/seg6_local.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "10fd1a8f58ac619a9e251f2858e2e2c8fd6cd667",
"status": "affected",
"version": "891ef8dd2a8d14e4e73a81dcdb135b574c57f556",
"versionType": "git"
},
{
"lessThan": "eb0f422487228e140f3d609b032ac61aedcab8fa",
"status": "affected",
"version": "891ef8dd2a8d14e4e73a81dcdb135b574c57f556",
"versionType": "git"
},
{
"lessThan": "9039e4f3e1c0ffe2b575b655b3f58fdd10f7e40c",
"status": "affected",
"version": "891ef8dd2a8d14e4e73a81dcdb135b574c57f556",
"versionType": "git"
},
{
"lessThan": "f52f1e75716d2ee49e013edf204ac92337c72fd8",
"status": "affected",
"version": "891ef8dd2a8d14e4e73a81dcdb135b574c57f556",
"versionType": "git"
},
{
"lessThan": "0e3f01fe2e704e76af4385b8a1742641885a191c",
"status": "affected",
"version": "891ef8dd2a8d14e4e73a81dcdb135b574c57f556",
"versionType": "git"
},
{
"lessThan": "3e4476e58343fb8f2fffced9e22d935376b17aaf",
"status": "affected",
"version": "891ef8dd2a8d14e4e73a81dcdb135b574c57f556",
"versionType": "git"
},
{
"lessThan": "bf1c1151560d11036a144d917fa4c131831342d7",
"status": "affected",
"version": "891ef8dd2a8d14e4e73a81dcdb135b574c57f556",
"versionType": "git"
},
{
"lessThan": "f4be3b391265e24c7720fc867c50062b436acf33",
"status": "affected",
"version": "891ef8dd2a8d14e4e73a81dcdb135b574c57f556",
"versionType": "git"
},
{
"lessThan": "44930446dde45a7a90fe1446fa38eb0e2c561646",
"status": "affected",
"version": "891ef8dd2a8d14e4e73a81dcdb135b574c57f556",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ipv6/seg6_local.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.14"
},
{
"lessThan": "4.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.269",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.220",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.187",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.156",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.108",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.49",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.13",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.3",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.269",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.220",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.187",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.156",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.108",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.49",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.13",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.3",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "4.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: seg6: clear IPv4 control block on IPIP decapsulation\n\nEnd.DX4 and End.DT4 decapsulate an IPv4 packet through\ndecap_and_validate() and send it directly to IPv4 routing. The inner\npacket therefore bypasses ip_rcv_core(), which normally clears IPCB\nbefore IPv4 interprets skb-\u003ecb.\n\nThe skb instead retains IP6CB data from the outer packet. IP6CB and\nIPCB use the same skb-\u003ecb storage, so IP6CB(skb)-\u003elastopt overlaps\nIPCB(skb)-\u003eopt.optlen and srr, while IP6CB(skb)-\u003enhoff overlaps rr and\nts.\n\nThe sender can make the stale optlen byte nonzero with a valid outer\nextension-header chain. The reproducers put an eight-byte Destination\nOptions header immediately after the 40-byte IPv6 header and before the\nSegment Routing Header. ipv6_destopt_rcv() records the sender-controlled\nDestination Options offset in both lastopt and nhoff, setting them to\n40. On the reproduced little-endian x86-64 kernel, IPv4 therefore sees\noptlen = 40 and rr = 40.\n\nBoth tcp_v4_save_options() and __ip_options_echo() skip option copying\nwhen optlen is zero. Here optlen is 40, so the TCP SYN path allocates\nroom for 40 bytes of option data and calls __ip_options_echo(). The\nstale rr value makes that function read inner packet byte 41 as the\nRecord Route option length. The reproducers set that sender-controlled\nbyte to 255, so __ip_options_echo() copies 255 bytes into the 40-byte\noption-data area.\n\nSeparate End.DX4 and End.DT4 reproducers on the unpatched v7.2-rc5\nkernel both produced:\n\n BUG: KASAN: slab-out-of-bounds in __ip_options_echo()\n Write of size 255\n\nThe relevant End.DX4 call path is:\n\n __ip_options_echo\n tcp_v4_route_req\n tcp_conn_request\n tcp_v4_conn_request\n tcp_rcv_state_process\n tcp_v4_do_rcv\n tcp_v4_rcv\n ip_protocol_deliver_rcu\n ip_local_deliver_finish\n ip_local_deliver\n input_action_end_dx4_finish\n input_action_end_dx4\n\nThe relevant End.DT4 call path is:\n\n __ip_options_echo\n tcp_v4_route_req\n tcp_conn_request\n tcp_v4_conn_request\n tcp_rcv_state_process\n tcp_v4_do_rcv\n tcp_v4_rcv\n ip_protocol_deliver_rcu\n ip_local_deliver_finish\n ip_local_deliver\n input_action_end_dt4\n\ntcp_v4_save_options() is inlined into the tcp_v4_route_req() path, so\nit does not appear as a separate frame.\n\nWhen decap_and_validate() handles IPPROTO_IPIP, save the ingress\ninterface from IP6CB, clear IPCB, and restore the saved value. Doing\nthis in the common decapsulation path covers End.DX4, End.DT4, and\nEnd.DT46\u0027s IPv4 arm.\n\nUse IP6CB(skb)-\u003eiif rather than skb-\u003eskb_iif. These actions run after\nl3mdev processing, which can replace skb_iif with the L3 master;\nIP6CB iif still records the receiving interface set at IPv6 ingress."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T15:54:50.403Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/10fd1a8f58ac619a9e251f2858e2e2c8fd6cd667"
},
{
"url": "https://git.kernel.org/stable/c/eb0f422487228e140f3d609b032ac61aedcab8fa"
},
{
"url": "https://git.kernel.org/stable/c/9039e4f3e1c0ffe2b575b655b3f58fdd10f7e40c"
},
{
"url": "https://git.kernel.org/stable/c/f52f1e75716d2ee49e013edf204ac92337c72fd8"
},
{
"url": "https://git.kernel.org/stable/c/0e3f01fe2e704e76af4385b8a1742641885a191c"
},
{
"url": "https://git.kernel.org/stable/c/3e4476e58343fb8f2fffced9e22d935376b17aaf"
},
{
"url": "https://git.kernel.org/stable/c/bf1c1151560d11036a144d917fa4c131831342d7"
},
{
"url": "https://git.kernel.org/stable/c/f4be3b391265e24c7720fc867c50062b436acf33"
},
{
"url": "https://git.kernel.org/stable/c/44930446dde45a7a90fe1446fa38eb0e2c561646"
}
],
"title": "ipv6: seg6: clear IPv4 control block on IPIP decapsulation",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80840",
"datePublished": "2026-09-04T15:54:50.403Z",
"dateReserved": "2026-08-26T14:34:25.796Z",
"dateUpdated": "2026-09-04T15:54:50.403Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72117 (GCVE-0-2026-72117)
Vulnerability from cvelistv5
Published
2026-08-15 05:52
Modified
2026-08-19 16:36
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
can: bcm: fix data race on rx_stamp/rx_ifindex in bcm_rx_handler()
For an rx op subscribed on all interfaces (ifindex == 0), the same op
is registered once in the shared per-netns wildcard filter list, so
bcm_rx_handler() can run concurrently on different CPUs for frames
arriving on different net devices.
op->rx_stamp and op->rx_ifindex were written before bcm_rx_update_lock was
taken, allowing concurrent writers to race each other - including a torn
store of the 64-bit rx_stamp on 32-bit platforms.
Beyond a torn store bcm_send_to_user() must report the timestamp/ifindex
of the very same frame whose content it is delivering. So the assignment
is placed in the same unbroken bcm_rx_update_lock section as the content
comparison.
As a side effect, the RTR-request frame feature (which never reach
bcm_send_to_user()) no longer updates rx_stamp/rx_ifindex, since only
the notification path needs them.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/can/bcm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b64f60c468d149aca22ea56bb842b9730215aaa5",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "c8a5d7cb095d3b12bd9dcf752d6ca0ff50872ac5",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "4b97410f4bba18d2ee2784c8e089104f387bc27c",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "5f246b96ab47523ec9b8ea870b5c567a3cb1eb1c",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "656ff69ef235699035e57d9e1ae417e62a38aa7f",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "136de17f38630307991c59aa7080012a99451783",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "c312b750bb5ac3348cfc85dab25e90937bd4d251",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "58fd6cbc8541216af1d7ed272ea7ac2b66d50fd8",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/can/bcm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.25"
},
{
"lessThan": "2.6.25",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.25",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: bcm: fix data race on rx_stamp/rx_ifindex in bcm_rx_handler()\n\nFor an rx op subscribed on all interfaces (ifindex == 0), the same op\nis registered once in the shared per-netns wildcard filter list, so\nbcm_rx_handler() can run concurrently on different CPUs for frames\narriving on different net devices.\n\nop-\u003erx_stamp and op-\u003erx_ifindex were written before bcm_rx_update_lock was\ntaken, allowing concurrent writers to race each other - including a torn\nstore of the 64-bit rx_stamp on 32-bit platforms.\n\nBeyond a torn store bcm_send_to_user() must report the timestamp/ifindex\nof the very same frame whose content it is delivering. So the assignment\nis placed in the same unbroken bcm_rx_update_lock section as the content\ncomparison.\n\nAs a side effect, the RTR-request frame feature (which never reach\nbcm_send_to_user()) no longer updates rx_stamp/rx_ifindex, since only\nthe notification path needs them."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:36:08.847Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b64f60c468d149aca22ea56bb842b9730215aaa5"
},
{
"url": "https://git.kernel.org/stable/c/c8a5d7cb095d3b12bd9dcf752d6ca0ff50872ac5"
},
{
"url": "https://git.kernel.org/stable/c/4b97410f4bba18d2ee2784c8e089104f387bc27c"
},
{
"url": "https://git.kernel.org/stable/c/5f246b96ab47523ec9b8ea870b5c567a3cb1eb1c"
},
{
"url": "https://git.kernel.org/stable/c/656ff69ef235699035e57d9e1ae417e62a38aa7f"
},
{
"url": "https://git.kernel.org/stable/c/136de17f38630307991c59aa7080012a99451783"
},
{
"url": "https://git.kernel.org/stable/c/c312b750bb5ac3348cfc85dab25e90937bd4d251"
},
{
"url": "https://git.kernel.org/stable/c/58fd6cbc8541216af1d7ed272ea7ac2b66d50fd8"
}
],
"title": "can: bcm: fix data race on rx_stamp/rx_ifindex in bcm_rx_handler()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72117",
"datePublished": "2026-08-15T05:52:56.991Z",
"dateReserved": "2026-08-09T03:40:39.906Z",
"dateUpdated": "2026-08-19T16:36:08.847Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68249 (GCVE-0-2026-68249)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-19 16:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON()
There's no need to crash the kernel for these cases.
(cherry picked from commit 8d144a0eb09537055841af48c9e7c2d4cd48e84d)
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: fef6e24c8b0243c3c43723949091cf999bb39c56 Version: fef6e24c8b0243c3c43723949091cf999bb39c56 Version: fef6e24c8b0243c3c43723949091cf999bb39c56 Version: fef6e24c8b0243c3c43723949091cf999bb39c56 Version: fef6e24c8b0243c3c43723949091cf999bb39c56 Version: fef6e24c8b0243c3c43723949091cf999bb39c56 Version: fef6e24c8b0243c3c43723949091cf999bb39c56 Version: fef6e24c8b0243c3c43723949091cf999bb39c56 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/sdma_v5_0.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "5960a8b54a19367540d93980a4d0e9edbb8acf4e",
"status": "affected",
"version": "fef6e24c8b0243c3c43723949091cf999bb39c56",
"versionType": "git"
},
{
"lessThan": "0c0dcc146f0c3091a9ef416cb8bbfdf5b5e169d5",
"status": "affected",
"version": "fef6e24c8b0243c3c43723949091cf999bb39c56",
"versionType": "git"
},
{
"lessThan": "84254337df02406996068315c2b6f06d8cc64452",
"status": "affected",
"version": "fef6e24c8b0243c3c43723949091cf999bb39c56",
"versionType": "git"
},
{
"lessThan": "f6212bc1bbd936fd9f7d77168b0c8b0019477b64",
"status": "affected",
"version": "fef6e24c8b0243c3c43723949091cf999bb39c56",
"versionType": "git"
},
{
"lessThan": "28337e5d7df429bac7de64b17f1a595147778caa",
"status": "affected",
"version": "fef6e24c8b0243c3c43723949091cf999bb39c56",
"versionType": "git"
},
{
"lessThan": "d20b5c139b2906bcd8ab4bfe5b8be500318161d1",
"status": "affected",
"version": "fef6e24c8b0243c3c43723949091cf999bb39c56",
"versionType": "git"
},
{
"lessThan": "0027cb19b0449ad6babedb1af285a713ab05c97f",
"status": "affected",
"version": "fef6e24c8b0243c3c43723949091cf999bb39c56",
"versionType": "git"
},
{
"lessThan": "9e98ed3113943257ad6e5c1e6beddbdb482a70ad",
"status": "affected",
"version": "fef6e24c8b0243c3c43723949091cf999bb39c56",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/sdma_v5_0.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.3"
},
{
"lessThan": "5.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON()\n\nThere\u0027s no need to crash the kernel for these cases.\n\n(cherry picked from commit 8d144a0eb09537055841af48c9e7c2d4cd48e84d)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:32:18.750Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/5960a8b54a19367540d93980a4d0e9edbb8acf4e"
},
{
"url": "https://git.kernel.org/stable/c/0c0dcc146f0c3091a9ef416cb8bbfdf5b5e169d5"
},
{
"url": "https://git.kernel.org/stable/c/84254337df02406996068315c2b6f06d8cc64452"
},
{
"url": "https://git.kernel.org/stable/c/f6212bc1bbd936fd9f7d77168b0c8b0019477b64"
},
{
"url": "https://git.kernel.org/stable/c/28337e5d7df429bac7de64b17f1a595147778caa"
},
{
"url": "https://git.kernel.org/stable/c/d20b5c139b2906bcd8ab4bfe5b8be500318161d1"
},
{
"url": "https://git.kernel.org/stable/c/0027cb19b0449ad6babedb1af285a713ab05c97f"
},
{
"url": "https://git.kernel.org/stable/c/9e98ed3113943257ad6e5c1e6beddbdb482a70ad"
}
],
"title": "drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68249",
"datePublished": "2026-08-10T12:01:15.453Z",
"dateReserved": "2026-07-30T09:28:09.377Z",
"dateUpdated": "2026-08-19T16:32:18.750Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68300 (GCVE-0-2026-68300)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-19 16:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
sctp: auth: verify auth requirement when auth_chunk is NULL
sctp_auth_chunk_verify() returns true unconditionally when
chunk->auth_chunk is NULL, silently skipping authentication.
This is incorrect when:
1. skb_clone() failed in the BH receive path, leaving auth_chunk
NULL. In sctp_endpoint_bh_rcv() asoc is NULL for new
connections, so the early sctp_auth_recv_cid() check cannot
catch this.
2. No AUTH chunk precedes COOKIE-ECHO, so skb_clone() is never
called and auth_chunk remains NULL.
Fix by checking sctp_auth_recv_cid() when auth_chunk is NULL:
if authentication is required, return false to drop the chunk;
otherwise continue normally.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: bbd0d59809f923ea2b540cbd781b32110e249f6e Version: bbd0d59809f923ea2b540cbd781b32110e249f6e Version: bbd0d59809f923ea2b540cbd781b32110e249f6e Version: bbd0d59809f923ea2b540cbd781b32110e249f6e Version: bbd0d59809f923ea2b540cbd781b32110e249f6e Version: bbd0d59809f923ea2b540cbd781b32110e249f6e Version: bbd0d59809f923ea2b540cbd781b32110e249f6e Version: bbd0d59809f923ea2b540cbd781b32110e249f6e |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/sctp/sm_statefuns.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a129792b3aef15002746c13522781d92ed3522c3",
"status": "affected",
"version": "bbd0d59809f923ea2b540cbd781b32110e249f6e",
"versionType": "git"
},
{
"lessThan": "5a022ac51ad83b4ce6c898f4b9eefc65bd26b247",
"status": "affected",
"version": "bbd0d59809f923ea2b540cbd781b32110e249f6e",
"versionType": "git"
},
{
"lessThan": "6caf0e8590c0bf05a76b0d387726adf3a6f3725c",
"status": "affected",
"version": "bbd0d59809f923ea2b540cbd781b32110e249f6e",
"versionType": "git"
},
{
"lessThan": "ec2e157fc9678a9bc411305a25aec3fd337d7efb",
"status": "affected",
"version": "bbd0d59809f923ea2b540cbd781b32110e249f6e",
"versionType": "git"
},
{
"lessThan": "28c5fdce9dd955d2baf5e28987819b6d7cfaf646",
"status": "affected",
"version": "bbd0d59809f923ea2b540cbd781b32110e249f6e",
"versionType": "git"
},
{
"lessThan": "18957373920caf5cdaf5cf32e5d1d7a99ca7700a",
"status": "affected",
"version": "bbd0d59809f923ea2b540cbd781b32110e249f6e",
"versionType": "git"
},
{
"lessThan": "83f5031f2a6a49d696eb4cc0898345d12f9c6451",
"status": "affected",
"version": "bbd0d59809f923ea2b540cbd781b32110e249f6e",
"versionType": "git"
},
{
"lessThan": "8e04823c120b376ef7dab14b60ebf6823aa16c14",
"status": "affected",
"version": "bbd0d59809f923ea2b540cbd781b32110e249f6e",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/sctp/sm_statefuns.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.24"
},
{
"lessThan": "2.6.24",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.24",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: auth: verify auth requirement when auth_chunk is NULL\n\nsctp_auth_chunk_verify() returns true unconditionally when\nchunk-\u003eauth_chunk is NULL, silently skipping authentication.\nThis is incorrect when:\n\n1. skb_clone() failed in the BH receive path, leaving auth_chunk\n NULL. In sctp_endpoint_bh_rcv() asoc is NULL for new\n connections, so the early sctp_auth_recv_cid() check cannot\n catch this.\n\n2. No AUTH chunk precedes COOKIE-ECHO, so skb_clone() is never\n called and auth_chunk remains NULL.\n\nFix by checking sctp_auth_recv_cid() when auth_chunk is NULL:\nif authentication is required, return false to drop the chunk;\notherwise continue normally."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The vulnerable code is SCTP COOKIE-ECHO chunk processing in the kernel\u0027s SCTP state machine, reached directly from packets received on the network from any remote peer over an arbitrarily routed SCTP connection.\nAC:L - The attacker deterministically triggers the bypass by completing a normal INIT/INIT-ACK exchange with the AUTH extension advertised and then sending COOKIE-ECHO with no preceding AUTH chunk; no race, no memory-layout dependency, and every step is under the attacker\u0027s control.\nPR:N - This is the pre-authentication association-establishment path itself; the attacker needs no credentials, no shared SCTP-AUTH key, and no account, since the bug is precisely that the required authentication is skipped.\nUI:N - The listening SCTP endpoint processes the crafted COOKIE-ECHO automatically in the receive path; no action by any local user or administrator is needed.\nS:U - The bypass affects the SCTP association and the application relying on it within the same host security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - An unauthenticated peer is admitted as an apparently authenticated one, and because peer.auth_capable is set the SCTP_AUTH_NO_AUTH notification is suppressed so the application cannot detect it, giving the attacker full read access to all data the service sends on that association.\nI:H - The attacker can inject arbitrary SCTP data and control chunks into the service as a trusted, supposedly key-verified peer, and can use the dupcook restart path to update or replace an existing association\u0027s state without authentication.\nA:H - Authenticating COOKIE-ECHO is the RFC 4895 defense against unauthorized association restart; bypassing it lets an attacker reset/take over an established association, dropping its queued state and denying service to the legitimate peer, and lets unauthorized peers consume association and accept-queue resources on an endpoint meant to admit only key-holding peers."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:32:51.209Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a129792b3aef15002746c13522781d92ed3522c3"
},
{
"url": "https://git.kernel.org/stable/c/5a022ac51ad83b4ce6c898f4b9eefc65bd26b247"
},
{
"url": "https://git.kernel.org/stable/c/6caf0e8590c0bf05a76b0d387726adf3a6f3725c"
},
{
"url": "https://git.kernel.org/stable/c/ec2e157fc9678a9bc411305a25aec3fd337d7efb"
},
{
"url": "https://git.kernel.org/stable/c/28c5fdce9dd955d2baf5e28987819b6d7cfaf646"
},
{
"url": "https://git.kernel.org/stable/c/18957373920caf5cdaf5cf32e5d1d7a99ca7700a"
},
{
"url": "https://git.kernel.org/stable/c/83f5031f2a6a49d696eb4cc0898345d12f9c6451"
},
{
"url": "https://git.kernel.org/stable/c/8e04823c120b376ef7dab14b60ebf6823aa16c14"
}
],
"title": "sctp: auth: verify auth requirement when auth_chunk is NULL",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68300",
"datePublished": "2026-08-10T12:02:34.168Z",
"dateReserved": "2026-07-30T09:28:09.380Z",
"dateUpdated": "2026-08-19T16:32:51.209Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68434 (GCVE-0-2026-68434)
Vulnerability from cvelistv5
Published
2026-08-12 00:07
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
serial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms
Commit b1b4efea05a5 ("serial: 8250_mid: Disable DMA for selected
platforms") replaced the dnv_board setup and exit callbacks with
PTR_IF(false, ...), which evaluates to NULL. However, the three call
sites in mid8250_probe() and mid8250_remove() unconditionally
dereference these function pointers without NULL checks, causing a NULL
pointer dereference (kernel oops) on any Denverton (DNV), Ice Lake Xeon
D (ICX-D/CDF), or Snowridge (SNR) platform.
Fix this by adding the missing NULL checks before calling the setup and
exit callbacks.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 763d61ded752fbb3116efc951eff4363f237b7e0 Version: c7d190bb07bf4e3b217c69370e94d1b4c80a40ad Version: 0b3ed3fa227ba778cabed96e7f8d84addb8bdf9c Version: 587afb06a5d1dc5092d3d9e9ac3ccf22094d50c6 Version: 977855894bca4b87afa50d21e3f3e85a5a0e901f Version: 1cd54e217c6e2cdb794a897b2f855e13ffcee586 Version: 9690e8a342632344984af72bc56b7a1fba61e6cb Version: b1b4efea05a56c0995e4702a86d6624b4fdff32f |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/tty/serial/8250/8250_mid.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "bdaa8871b53fe9b1730ef64dda2fcd662fd83339",
"status": "affected",
"version": "763d61ded752fbb3116efc951eff4363f237b7e0",
"versionType": "git"
},
{
"lessThan": "f85a42fb90399dedcf81c146d09c07e4548b1e8c",
"status": "affected",
"version": "c7d190bb07bf4e3b217c69370e94d1b4c80a40ad",
"versionType": "git"
},
{
"lessThan": "4ea933a36a14bec19b71025cdd8407bafbd67ec1",
"status": "affected",
"version": "0b3ed3fa227ba778cabed96e7f8d84addb8bdf9c",
"versionType": "git"
},
{
"lessThan": "1096397c31f6bffa95e77bdd18fbca085be83e10",
"status": "affected",
"version": "587afb06a5d1dc5092d3d9e9ac3ccf22094d50c6",
"versionType": "git"
},
{
"lessThan": "600dcd548fb2b00a69f447684f52ba45d5a3540e",
"status": "affected",
"version": "977855894bca4b87afa50d21e3f3e85a5a0e901f",
"versionType": "git"
},
{
"lessThan": "b2a3eeb57ba24f8a0e34a69d40adcc63e5b9ca56",
"status": "affected",
"version": "1cd54e217c6e2cdb794a897b2f855e13ffcee586",
"versionType": "git"
},
{
"lessThan": "8cbad52ccfa6a7f089cfab34979bc6cc3bff25be",
"status": "affected",
"version": "9690e8a342632344984af72bc56b7a1fba61e6cb",
"versionType": "git"
},
{
"lessThan": "7fb13fd7e9a59a37cd911efff83abe19e3ee029d",
"status": "affected",
"version": "b1b4efea05a56c0995e4702a86d6624b4fdff32f",
"versionType": "git"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/tty/serial/8250/8250_mid.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "5.10.266",
"status": "affected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThan": "5.15.217",
"status": "affected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThan": "6.1.183",
"status": "affected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThan": "6.6.148",
"status": "affected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThan": "6.12.101",
"status": "affected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThan": "6.18.42",
"status": "affected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThan": "7.1.6",
"status": "affected",
"version": "7.1.4",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "5.10.261",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.15.212",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "6.1.178",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.6.145",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.12.96",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.18.39",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "7.1.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nserial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms\n\nCommit b1b4efea05a5 (\"serial: 8250_mid: Disable DMA for selected\nplatforms\") replaced the dnv_board setup and exit callbacks with\nPTR_IF(false, ...), which evaluates to NULL. However, the three call\nsites in mid8250_probe() and mid8250_remove() unconditionally\ndereference these function pointers without NULL checks, causing a NULL\npointer dereference (kernel oops) on any Denverton (DNV), Ice Lake Xeon\nD (ICX-D/CDF), or Snowridge (SNR) platform.\n\nFix this by adding the missing NULL checks before calling the setup and\nexit callbacks."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:23.299Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/bdaa8871b53fe9b1730ef64dda2fcd662fd83339"
},
{
"url": "https://git.kernel.org/stable/c/f85a42fb90399dedcf81c146d09c07e4548b1e8c"
},
{
"url": "https://git.kernel.org/stable/c/4ea933a36a14bec19b71025cdd8407bafbd67ec1"
},
{
"url": "https://git.kernel.org/stable/c/1096397c31f6bffa95e77bdd18fbca085be83e10"
},
{
"url": "https://git.kernel.org/stable/c/600dcd548fb2b00a69f447684f52ba45d5a3540e"
},
{
"url": "https://git.kernel.org/stable/c/b2a3eeb57ba24f8a0e34a69d40adcc63e5b9ca56"
},
{
"url": "https://git.kernel.org/stable/c/8cbad52ccfa6a7f089cfab34979bc6cc3bff25be"
},
{
"url": "https://git.kernel.org/stable/c/7fb13fd7e9a59a37cd911efff83abe19e3ee029d"
}
],
"title": "serial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68434",
"datePublished": "2026-08-12T00:07:21.897Z",
"dateReserved": "2026-07-30T09:28:09.393Z",
"dateUpdated": "2026-08-23T12:46:23.299Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68127 (GCVE-0-2026-68127)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-19 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ila: reload IPv6 header after pskb_may_pull in checksum adjust
ila_csum_adjust_transport() caches ip6h = ipv6_hdr(skb) before calling
pskb_may_pull(). On a non-linear skb whose transport header sits in a page
fragment, pskb_may_pull() can call __pskb_pull_tail() / pskb_expand_head()
and free the old skb head, leaving ip6h dangling; the following
get_csum_diff(ip6h, p) then reads freed memory. ila_update_ipv6_locator()
uses ip6h (and the iaddr derived from it) again after the csum-adjust
call and additionally writes the new locator through that pointer.
Impact: a remote IPv6 packet routed through a configured ILA
csum-adjust-transport route or receive-side mapping triggers a
slab-use-after-free in ila_update_ipv6_locator() (KASAN). The route or
mapping requires CAP_NET_ADMIN to configure, but trigger packets are
unauthenticated once it exists.
Reload ip6h after each pskb_may_pull() in ila_csum_adjust_transport()
before the csum-diff read. In ila_update_ipv6_locator() only the
ILA_CSUM_ADJUST_TRANSPORT case pulls the skb, so reload ip6h and iaddr in
that case alone before the destination-address write; the neutral-map
modes never pull and keep their cached pointers.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 33f11d16142b06588eedfc1dd8cf93790979a712 Version: 33f11d16142b06588eedfc1dd8cf93790979a712 Version: 33f11d16142b06588eedfc1dd8cf93790979a712 Version: 33f11d16142b06588eedfc1dd8cf93790979a712 Version: 33f11d16142b06588eedfc1dd8cf93790979a712 Version: 33f11d16142b06588eedfc1dd8cf93790979a712 Version: 33f11d16142b06588eedfc1dd8cf93790979a712 Version: 33f11d16142b06588eedfc1dd8cf93790979a712 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ipv6/ila/ila_common.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "e451a904606c571f731ef7a06b3398619dce5300",
"status": "affected",
"version": "33f11d16142b06588eedfc1dd8cf93790979a712",
"versionType": "git"
},
{
"lessThan": "1eadcb43893b897ade85ac5bf5c618054bc3c655",
"status": "affected",
"version": "33f11d16142b06588eedfc1dd8cf93790979a712",
"versionType": "git"
},
{
"lessThan": "ba353caafb06ccee57b78d3254e3cebf1dea4a93",
"status": "affected",
"version": "33f11d16142b06588eedfc1dd8cf93790979a712",
"versionType": "git"
},
{
"lessThan": "896a9512d0d83c2a4b357e5585b7b62a8e3f95c1",
"status": "affected",
"version": "33f11d16142b06588eedfc1dd8cf93790979a712",
"versionType": "git"
},
{
"lessThan": "7097a0280b178237265681be66d1bef11d15894b",
"status": "affected",
"version": "33f11d16142b06588eedfc1dd8cf93790979a712",
"versionType": "git"
},
{
"lessThan": "472aba2603ca74c4f7722cb0c0296942b0776b8d",
"status": "affected",
"version": "33f11d16142b06588eedfc1dd8cf93790979a712",
"versionType": "git"
},
{
"lessThan": "c6a13ae00dab3a1a8c7cf2f843f0fc9e8d4b0ccc",
"status": "affected",
"version": "33f11d16142b06588eedfc1dd8cf93790979a712",
"versionType": "git"
},
{
"lessThan": "92d3817649df2b0b6a008a686c8275c88d7ef594",
"status": "affected",
"version": "33f11d16142b06588eedfc1dd8cf93790979a712",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ipv6/ila/ila_common.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.5"
},
{
"lessThan": "4.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nila: reload IPv6 header after pskb_may_pull in checksum adjust\n\nila_csum_adjust_transport() caches ip6h = ipv6_hdr(skb) before calling\npskb_may_pull(). On a non-linear skb whose transport header sits in a page\nfragment, pskb_may_pull() can call __pskb_pull_tail() / pskb_expand_head()\nand free the old skb head, leaving ip6h dangling; the following\nget_csum_diff(ip6h, p) then reads freed memory. ila_update_ipv6_locator()\nuses ip6h (and the iaddr derived from it) again after the csum-adjust\ncall and additionally writes the new locator through that pointer.\n\nImpact: a remote IPv6 packet routed through a configured ILA\ncsum-adjust-transport route or receive-side mapping triggers a\nslab-use-after-free in ila_update_ipv6_locator() (KASAN). The route or\nmapping requires CAP_NET_ADMIN to configure, but trigger packets are\nunauthenticated once it exists.\n\nReload ip6h after each pskb_may_pull() in ila_csum_adjust_transport()\nbefore the csum-diff read. In ila_update_ipv6_locator() only the\nILA_CSUM_ADJUST_TRANSPORT case pulls the skb, so reload ip6h and iaddr in\nthat case alone before the destination-address write; the neutral-map\nmodes never pull and keep their cached pointers."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug is reached from ipv6_rcv() through NF_INET_PRE_ROUTING (ila_nf_input) or IPv6 routing/LWT input/output when remote IPv6 packets matching a configured ILA csum-adjust-transport mapping or route are processed; no local syscall is required on internet-facing routers, gateways, or NVO3/overlay hosts.\nAC:L - Once ILA csum-adjust-transport is configured, a remote attacker can reliably send IPv6 TCP/UDP/ICMPv6 packets whose transport headers live in skb page fragments so pskb_may_pull() reallocates the head; they control packet layout and can retry without races or uncontrollable memory layout.\nPR:N - Trigger packets are processed unauthenticated on the network datapath; although ILA routes/mappings require CAP_NET_ADMIN to install, that is operator infrastructure (also obtainable in a user netns), not a privilege the remote attacker needs to send the malformed IPv6 packets that hit ila_update_ipv6_locator().\nUI:N - No victim user action is required beyond normal IPv6 packet delivery; exploitation is fully automated once the affected ILA configuration exists and the attacker sends crafted packets to the host.\nS:U - The slab use-after-free corrupts kernel packet-processing memory within the host kernel security authority; it is not a VM escape, container breakout, or IOMMU/DMA boundary bypass.\nC:H - ila_csum_adjust_transport() reads the cached IPv6 header via get_csum_diff(ip6h, p) after pskb_may_pull() frees the old skb head, causing a slab use-after-free read of freed memory that can disclose kernel heap contents.\nI:H - ila_update_ipv6_locator() then writes iaddr-\u003eloc = p-\u003elocator through the same stale iaddr pointer derived from the freed header, giving a slab use-after-free write primitive that can be leveraged for arbitrary memory corruption and control-flow hijacking.\nA:H - The freed skb-head slab use-after-free was reproduced under KASAN and can cause kernel oops/panic during IPv6 receive/forwarding; even unsuccessful exploitation typically crashes or destabilizes the host."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:29:41.771Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/e451a904606c571f731ef7a06b3398619dce5300"
},
{
"url": "https://git.kernel.org/stable/c/1eadcb43893b897ade85ac5bf5c618054bc3c655"
},
{
"url": "https://git.kernel.org/stable/c/ba353caafb06ccee57b78d3254e3cebf1dea4a93"
},
{
"url": "https://git.kernel.org/stable/c/896a9512d0d83c2a4b357e5585b7b62a8e3f95c1"
},
{
"url": "https://git.kernel.org/stable/c/7097a0280b178237265681be66d1bef11d15894b"
},
{
"url": "https://git.kernel.org/stable/c/472aba2603ca74c4f7722cb0c0296942b0776b8d"
},
{
"url": "https://git.kernel.org/stable/c/c6a13ae00dab3a1a8c7cf2f843f0fc9e8d4b0ccc"
},
{
"url": "https://git.kernel.org/stable/c/92d3817649df2b0b6a008a686c8275c88d7ef594"
}
],
"title": "ila: reload IPv6 header after pskb_may_pull in checksum adjust",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68127",
"datePublished": "2026-08-10T11:58:48.489Z",
"dateReserved": "2026-07-30T09:28:09.369Z",
"dateUpdated": "2026-08-19T16:29:41.771Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80680 (GCVE-0-2026-80680)
Vulnerability from cvelistv5
Published
2026-08-28 06:52
Modified
2026-08-29 06:22
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
i2c: amd-mp2: Unregister callback on adapter add failure
amd_mp2_register_cb() stores the platform I2C context in the MP2 PCI
driver's callback table before the adapter is registered. If
i2c_add_adapter() fails, probe returns and devres frees the context,
but the PCI driver can still dereference the stale pointer from its IRQ
and system-sleep callbacks.
Unregister the callback before returning the adapter registration error.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 529766e0a0114438887382a68d97341fbf8349fb Version: 529766e0a0114438887382a68d97341fbf8349fb Version: 529766e0a0114438887382a68d97341fbf8349fb Version: 529766e0a0114438887382a68d97341fbf8349fb Version: 529766e0a0114438887382a68d97341fbf8349fb Version: 529766e0a0114438887382a68d97341fbf8349fb Version: 529766e0a0114438887382a68d97341fbf8349fb Version: 529766e0a0114438887382a68d97341fbf8349fb |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/i2c/busses/i2c-amd-mp2-plat.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "9142a3dcff0d80a3a24ce159aee19ddc869d9784",
"status": "affected",
"version": "529766e0a0114438887382a68d97341fbf8349fb",
"versionType": "git"
},
{
"lessThan": "2f7789b3a9628819ebf90bcba8f9da3c139f8687",
"status": "affected",
"version": "529766e0a0114438887382a68d97341fbf8349fb",
"versionType": "git"
},
{
"lessThan": "4786d4d70dcd1e6b7e044f2348e00f201947b69c",
"status": "affected",
"version": "529766e0a0114438887382a68d97341fbf8349fb",
"versionType": "git"
},
{
"lessThan": "b7c2c5c8868737926410b93d1223ada17625ead3",
"status": "affected",
"version": "529766e0a0114438887382a68d97341fbf8349fb",
"versionType": "git"
},
{
"lessThan": "cf107c5983dc70fcf932a305581a5f976d908ff1",
"status": "affected",
"version": "529766e0a0114438887382a68d97341fbf8349fb",
"versionType": "git"
},
{
"lessThan": "1883a09a37fed497b9efacf736c23624a472246b",
"status": "affected",
"version": "529766e0a0114438887382a68d97341fbf8349fb",
"versionType": "git"
},
{
"lessThan": "8bf719659406e4a1b56d441e0c7da2085d891d96",
"status": "affected",
"version": "529766e0a0114438887382a68d97341fbf8349fb",
"versionType": "git"
},
{
"lessThan": "82048795242f04275a3f49ffc66ad851b6120954",
"status": "affected",
"version": "529766e0a0114438887382a68d97341fbf8349fb",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/i2c/busses/i2c-amd-mp2-plat.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.2"
},
{
"lessThan": "5.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: amd-mp2: Unregister callback on adapter add failure\n\namd_mp2_register_cb() stores the platform I2C context in the MP2 PCI\ndriver\u0027s callback table before the adapter is registered. If\ni2c_add_adapter() fails, probe returns and devres frees the context,\nbut the PCI driver can still dereference the stale pointer from its IRQ\nand system-sleep callbacks.\n\nUnregister the callback before returning the adapter registration error."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The flaw is in AMD MP2 platform-driver probe teardown and PCI IRQ/system-sleep callbacks, reachable only via local suspend/resume or MP2 hardware interrupts on affected Ryzen laptops; there is no network, Bluetooth, or userspace I2C ioctl path to the stale callback table.\nAC:L - Once i2c_add_adapter() fails the dangling busses[] pointer is deterministic; an attacker can force that registration failure with memory pressure or driver rebind on modular builds, then reliably trigger the UAF through system suspend or MP2 IRQ without uncontrollable races.\nPR:L - After the flawed probe error path leaves the stale callback registered, local users can invoke system suspend via logind/systemctl without init-namespace root, and MP2 IRQs can fire from the already-enabled bus; per CNA guidance Low is used when probe/bind privilege gating is ambiguous.\nUI:N - Exploitation requires no separate victim action; the attacker triggers suspend themselves or relies on automatic MP2 hardware interrupts from an enabled bus, without needing another user to mount filesystems or open files.\nS:U - Impact is host-kernel heap corruption and privilege escalation from stale callback dereference; it does not cross VM, IOMMU, or sandbox security boundaries.\nC:H - The IRQ handler writes into freed amd_i2c_common memory and invokes cmd_completion from the stale object; this UAF provides attacker-influenced heap reuse and arbitrary kernel read primitives per kernel CNA UAF guidance.\nI:H - Suspend/resume and IRQ paths call function pointers through the freed amd_i2c_common structure, enabling control-flow hijack and heap corruption consistent with exploitable UAF write primitives.\nA:H - Stale callback dereference in IRQ or system-sleep paths causes kernel oops/panic and loss of availability; UAF heap corruption can also hang or crash affected AMD MP2 systems on every suspend or interrupt."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-29T06:22:06.613Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/9142a3dcff0d80a3a24ce159aee19ddc869d9784"
},
{
"url": "https://git.kernel.org/stable/c/2f7789b3a9628819ebf90bcba8f9da3c139f8687"
},
{
"url": "https://git.kernel.org/stable/c/4786d4d70dcd1e6b7e044f2348e00f201947b69c"
},
{
"url": "https://git.kernel.org/stable/c/b7c2c5c8868737926410b93d1223ada17625ead3"
},
{
"url": "https://git.kernel.org/stable/c/cf107c5983dc70fcf932a305581a5f976d908ff1"
},
{
"url": "https://git.kernel.org/stable/c/1883a09a37fed497b9efacf736c23624a472246b"
},
{
"url": "https://git.kernel.org/stable/c/8bf719659406e4a1b56d441e0c7da2085d891d96"
},
{
"url": "https://git.kernel.org/stable/c/82048795242f04275a3f49ffc66ad851b6120954"
}
],
"title": "i2c: amd-mp2: Unregister callback on adapter add failure",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80680",
"datePublished": "2026-08-28T06:52:48.300Z",
"dateReserved": "2026-08-26T14:34:25.783Z",
"dateUpdated": "2026-08-29T06:22:06.613Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74547 (GCVE-0-2026-74547)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-19 16:38
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
hwmon: (adt7470) Fix busy-loop and I2C flooding in update thread
When userspace configures 'auto_update_interval' to 0 via sysfs, the
background kthread executes schedule_timeout_interruptible(0), which
returns immediately.
If 'num_temp_sensors' is concurrently or previously set to 0, the
msleep_interruptible() delay inside adt7470_read_temperatures() also
becomes 0. This combination forces the background thread into a tight,
unbounded busy-loop, hogging the CPU and flooding the I2C bus with a
continuous stream of transactions.
Fix this vulnerability by raising the lower limit of the clamp_val in
auto_update_interval_store() from 0 to 500 milliseconds. This guarantees
a reasonable minimum sleep window between sensor updates, protecting the
system from intentional or accidental I2C bus denial of service.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 89fac11cb3e7c5860c425dba14845c09ccede39d Version: 89fac11cb3e7c5860c425dba14845c09ccede39d Version: 89fac11cb3e7c5860c425dba14845c09ccede39d Version: 89fac11cb3e7c5860c425dba14845c09ccede39d Version: 89fac11cb3e7c5860c425dba14845c09ccede39d Version: 89fac11cb3e7c5860c425dba14845c09ccede39d Version: 89fac11cb3e7c5860c425dba14845c09ccede39d Version: 89fac11cb3e7c5860c425dba14845c09ccede39d |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/hwmon/adt7470.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "2c4c4d7cadd10b50b5489183bbbb9eb95f6f8344",
"status": "affected",
"version": "89fac11cb3e7c5860c425dba14845c09ccede39d",
"versionType": "git"
},
{
"lessThan": "4dc1518f9cc57c6db99514cafeb02dd7117d5bda",
"status": "affected",
"version": "89fac11cb3e7c5860c425dba14845c09ccede39d",
"versionType": "git"
},
{
"lessThan": "1325975a2eab265510e6036d8bf0c0068373d332",
"status": "affected",
"version": "89fac11cb3e7c5860c425dba14845c09ccede39d",
"versionType": "git"
},
{
"lessThan": "1a42bd72a66205e439db1d1142442b62d393408a",
"status": "affected",
"version": "89fac11cb3e7c5860c425dba14845c09ccede39d",
"versionType": "git"
},
{
"lessThan": "38e6b5ce5794ff09442231cc171c2be5e900bab3",
"status": "affected",
"version": "89fac11cb3e7c5860c425dba14845c09ccede39d",
"versionType": "git"
},
{
"lessThan": "82d65f7ef11edcea0228745440b8b4b1f222c34c",
"status": "affected",
"version": "89fac11cb3e7c5860c425dba14845c09ccede39d",
"versionType": "git"
},
{
"lessThan": "5ea299c3aa42a827f6a863eeead6de3525bbb17a",
"status": "affected",
"version": "89fac11cb3e7c5860c425dba14845c09ccede39d",
"versionType": "git"
},
{
"lessThan": "cb0b7f9c43b0abbd422a7e4c2c85e91db429207c",
"status": "affected",
"version": "89fac11cb3e7c5860c425dba14845c09ccede39d",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/hwmon/adt7470.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.29"
},
{
"lessThan": "2.6.29",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.29",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.29",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.29",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "2.6.29",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "2.6.29",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "2.6.29",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "2.6.29",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.29",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (adt7470) Fix busy-loop and I2C flooding in update thread\n\nWhen userspace configures \u0027auto_update_interval\u0027 to 0 via sysfs, the\nbackground kthread executes schedule_timeout_interruptible(0), which\nreturns immediately.\n\nIf \u0027num_temp_sensors\u0027 is concurrently or previously set to 0, the\nmsleep_interruptible() delay inside adt7470_read_temperatures() also\nbecomes 0. This combination forces the background thread into a tight,\nunbounded busy-loop, hogging the CPU and flooding the I2C bus with a\ncontinuous stream of transactions.\n\nFix this vulnerability by raising the lower limit of the clamp_val in\nauto_update_interval_store() from 0 to 500 milliseconds. This guarantees\na reasonable minimum sleep window between sensor updates, protecting the\nsystem from intentional or accidental I2C bus denial of service."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:38:37.219Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/2c4c4d7cadd10b50b5489183bbbb9eb95f6f8344"
},
{
"url": "https://git.kernel.org/stable/c/4dc1518f9cc57c6db99514cafeb02dd7117d5bda"
},
{
"url": "https://git.kernel.org/stable/c/1325975a2eab265510e6036d8bf0c0068373d332"
},
{
"url": "https://git.kernel.org/stable/c/1a42bd72a66205e439db1d1142442b62d393408a"
},
{
"url": "https://git.kernel.org/stable/c/38e6b5ce5794ff09442231cc171c2be5e900bab3"
},
{
"url": "https://git.kernel.org/stable/c/82d65f7ef11edcea0228745440b8b4b1f222c34c"
},
{
"url": "https://git.kernel.org/stable/c/5ea299c3aa42a827f6a863eeead6de3525bbb17a"
},
{
"url": "https://git.kernel.org/stable/c/cb0b7f9c43b0abbd422a7e4c2c85e91db429207c"
}
],
"title": "hwmon: (adt7470) Fix busy-loop and I2C flooding in update thread",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74547",
"datePublished": "2026-08-15T12:27:55.777Z",
"dateReserved": "2026-08-15T05:44:03.915Z",
"dateUpdated": "2026-08-19T16:38:37.219Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68216 (GCVE-0-2026-68216)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: pwc: Return queued buffers on start_streaming() failure
The vb2 framework hands buffers to the driver via buf_queue() before
calling start_streaming(). If start_streaming() returns an error
without first returning those buffers via vb2_buffer_done(),
vb2_start_streaming() fires WARN_ON(owned_by_drv_count) and the queued
buffers leak.
pwc's start_streaming() had two early returns that hit this trap:
-ENODEV when the USB device was already disconnected, and -ERESTARTSYS
when mutex_lock_interruptible() was interrupted by a signal. Call the
existing pwc_cleanup_queued_bufs() helper with VB2_BUF_STATE_QUEUED
before returning (matching the state already used by the
pwc_isoc_init() error path in the same function).
This mirrors the uvcvideo fix in commit 4cf3b6fd54eb ("media: uvcvideo:
Return queued buffers on start_streaming() failure").
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ceede9fa8939e40ad0ddb4ad1355f45c6f1d3478 Version: ceede9fa8939e40ad0ddb4ad1355f45c6f1d3478 Version: ceede9fa8939e40ad0ddb4ad1355f45c6f1d3478 Version: ceede9fa8939e40ad0ddb4ad1355f45c6f1d3478 Version: ceede9fa8939e40ad0ddb4ad1355f45c6f1d3478 Version: ceede9fa8939e40ad0ddb4ad1355f45c6f1d3478 Version: ceede9fa8939e40ad0ddb4ad1355f45c6f1d3478 Version: ceede9fa8939e40ad0ddb4ad1355f45c6f1d3478 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/usb/pwc/pwc-if.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "d552852bf76b7dfb35b4593fc874d8dd2f1b1bf3",
"status": "affected",
"version": "ceede9fa8939e40ad0ddb4ad1355f45c6f1d3478",
"versionType": "git"
},
{
"lessThan": "0362ae30b61b3053ee3095c1b8f179197ec4f539",
"status": "affected",
"version": "ceede9fa8939e40ad0ddb4ad1355f45c6f1d3478",
"versionType": "git"
},
{
"lessThan": "fa78e590852751d3ad32f33f6b4e210fe6ccbe9b",
"status": "affected",
"version": "ceede9fa8939e40ad0ddb4ad1355f45c6f1d3478",
"versionType": "git"
},
{
"lessThan": "f2f9fcacd81953dde6cb86312ab13ca13e689664",
"status": "affected",
"version": "ceede9fa8939e40ad0ddb4ad1355f45c6f1d3478",
"versionType": "git"
},
{
"lessThan": "5d7cc2634c3843a1414a0f6407aa17f1f91dee60",
"status": "affected",
"version": "ceede9fa8939e40ad0ddb4ad1355f45c6f1d3478",
"versionType": "git"
},
{
"lessThan": "cb16b79a2be2cec9c3ebe4147490817c4d8b1de3",
"status": "affected",
"version": "ceede9fa8939e40ad0ddb4ad1355f45c6f1d3478",
"versionType": "git"
},
{
"lessThan": "a4f8f629983f643333e49df90557805469bcbb25",
"status": "affected",
"version": "ceede9fa8939e40ad0ddb4ad1355f45c6f1d3478",
"versionType": "git"
},
{
"lessThan": "975b2ee20e569d47821e4f6c9761b4664d48a6a4",
"status": "affected",
"version": "ceede9fa8939e40ad0ddb4ad1355f45c6f1d3478",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/usb/pwc/pwc-if.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.5"
},
{
"lessThan": "3.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: pwc: Return queued buffers on start_streaming() failure\n\nThe vb2 framework hands buffers to the driver via buf_queue() before\ncalling start_streaming(). If start_streaming() returns an error\nwithout first returning those buffers via vb2_buffer_done(),\nvb2_start_streaming() fires WARN_ON(owned_by_drv_count) and the queued\nbuffers leak.\n\npwc\u0027s start_streaming() had two early returns that hit this trap:\n-ENODEV when the USB device was already disconnected, and -ERESTARTSYS\nwhen mutex_lock_interruptible() was interrupted by a signal. Call the\nexisting pwc_cleanup_queued_bufs() helper with VB2_BUF_STATE_QUEUED\nbefore returning (matching the state already used by the\npwc_isoc_init() error path in the same function).\n\nThis mirrors the uvcvideo fix in commit 4cf3b6fd54eb (\"media: uvcvideo:\nReturn queued buffers on start_streaming() failure\")."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached through the VIDIOC_STREAMON ioctl on a local V4L2 device node (/dev/videoN) exposed by the pwc USB webcam driver, so the attacker needs local access to the system rather than network reachability.\nAC:L - The -ERESTARTSYS path is triggered deterministically by the attacker: hold pdev-\u003ev4l2_lock from a second thread/fd and send a signal to the thread blocked in mutex_lock_interruptible() inside start_streaming(), so both sides of the timing window are attacker-controlled and repeatable.\nPR:L - Only an unprivileged local account with access to the video device node (typical for desktop, kiosk and embedded video appliances, where the video group or logind ACLs grant it) is needed; no capabilities or root are required.\nUI:N - The attacker performs the entire sequence (REQBUFS, QBUF, STREAMON, signal delivery) from its own process; no action by any other user is needed.\nS:U - The buffer-accounting breakage and the resulting list corruption stay within the kernel\u0027s own security authority; no VM, IOMMU or sandbox boundary is crossed.\nC:H - Buffers left on pdev-\u003equeued_bufs after vb2 has already reclaimed them to QUEUED are re-linked on the next STREAMON, so the same pwc_frame_buf can be filled and completed while vb2 considers it userspace-owned, allowing an attacker to read kernel-managed frame data through stale mmap\u0027ed buffers.\nI:H - The double list_add_tail() of an already-linked buf-\u003elist node corrupts the driver\u0027s queued-buffer list and desynchronizes vb2\u0027s owned_by_drv_count, giving overlapping kernel/userspace ownership of buffer objects that can be leveraged for controlled modification of kernel-side state.\nA:H - Each attempt fires WARN_ON(owned_by_drv_count) in vb2_start_streaming(), which panics the machine on panic_on_warn kernels, and the leaked/corrupted buffer list additionally leads to lost buffers and unstable streaming state on subsequent STREAMON/STREAMOFF cycles."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:47.114Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/d552852bf76b7dfb35b4593fc874d8dd2f1b1bf3"
},
{
"url": "https://git.kernel.org/stable/c/0362ae30b61b3053ee3095c1b8f179197ec4f539"
},
{
"url": "https://git.kernel.org/stable/c/fa78e590852751d3ad32f33f6b4e210fe6ccbe9b"
},
{
"url": "https://git.kernel.org/stable/c/f2f9fcacd81953dde6cb86312ab13ca13e689664"
},
{
"url": "https://git.kernel.org/stable/c/5d7cc2634c3843a1414a0f6407aa17f1f91dee60"
},
{
"url": "https://git.kernel.org/stable/c/cb16b79a2be2cec9c3ebe4147490817c4d8b1de3"
},
{
"url": "https://git.kernel.org/stable/c/a4f8f629983f643333e49df90557805469bcbb25"
},
{
"url": "https://git.kernel.org/stable/c/975b2ee20e569d47821e4f6c9761b4664d48a6a4"
}
],
"title": "media: pwc: Return queued buffers on start_streaming() failure",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68216",
"datePublished": "2026-08-10T12:00:35.592Z",
"dateReserved": "2026-07-30T09:28:09.375Z",
"dateUpdated": "2026-08-19T16:31:47.114Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80540 (GCVE-0-2026-80540)
Vulnerability from cvelistv5
Published
2026-08-26 14:37
Modified
2026-08-27 05:01
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: Fix UVD decode image min size calculation
This needs to use pitch instead of width. Also reject pitch
over 4096 to avoid overflow.
(cherry picked from commit b41c8cb12e202b220353332ab87dc01a11f69304)
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d38ceaf99ed015f2a0b9af3499791bd3a3daae21 Version: d38ceaf99ed015f2a0b9af3499791bd3a3daae21 Version: d38ceaf99ed015f2a0b9af3499791bd3a3daae21 Version: d38ceaf99ed015f2a0b9af3499791bd3a3daae21 Version: d38ceaf99ed015f2a0b9af3499791bd3a3daae21 Version: d38ceaf99ed015f2a0b9af3499791bd3a3daae21 Version: d38ceaf99ed015f2a0b9af3499791bd3a3daae21 Version: d38ceaf99ed015f2a0b9af3499791bd3a3daae21 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/amdgpu_uvd.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "bc7397a033ac52f6d8c9bb6510d61694b2a3fce7",
"status": "affected",
"version": "d38ceaf99ed015f2a0b9af3499791bd3a3daae21",
"versionType": "git"
},
{
"lessThan": "d058f7a6709441afe1784eecd8c0643dd84750bc",
"status": "affected",
"version": "d38ceaf99ed015f2a0b9af3499791bd3a3daae21",
"versionType": "git"
},
{
"lessThan": "b7549e3f96c78921751c4b3e69af729662130d83",
"status": "affected",
"version": "d38ceaf99ed015f2a0b9af3499791bd3a3daae21",
"versionType": "git"
},
{
"lessThan": "60539d517e8439621532d8c01091ac049c596b4b",
"status": "affected",
"version": "d38ceaf99ed015f2a0b9af3499791bd3a3daae21",
"versionType": "git"
},
{
"lessThan": "271a7da84a6262a09de549912dcf6a749d169cb6",
"status": "affected",
"version": "d38ceaf99ed015f2a0b9af3499791bd3a3daae21",
"versionType": "git"
},
{
"lessThan": "25ee120f3803ad9e416ef9f76f4c3234cc4d645b",
"status": "affected",
"version": "d38ceaf99ed015f2a0b9af3499791bd3a3daae21",
"versionType": "git"
},
{
"lessThan": "5cbd8af02b0b9c8723fa30edcf6fccab5170af8d",
"status": "affected",
"version": "d38ceaf99ed015f2a0b9af3499791bd3a3daae21",
"versionType": "git"
},
{
"lessThan": "b8bb9ba3f101a1b0011f785a577a4a0a38371174",
"status": "affected",
"version": "d38ceaf99ed015f2a0b9af3499791bd3a3daae21",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/amdgpu_uvd.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.2"
},
{
"lessThan": "4.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.46",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.10",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Fix UVD decode image min size calculation\n\nThis needs to use pitch instead of width. Also reject pitch\nover 4096 to avoid overflow.\n\n(cherry picked from commit b41c8cb12e202b220353332ab87dc01a11f69304)"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Reachable only via AMDGPU_CS ioctl on a local DRM render node (/dev/dri/renderD*), through amdgpu_cs_ioctl \u2192 amdgpu_cs_patch_ibs \u2192 amdgpu_uvd_ring_parse_cs \u2192 amdgpu_uvd_cs_pass2 \u2192 amdgpu_uvd_cs_msg \u2192 amdgpu_uvd_cs_msg_decode; not reachable from any network-facing kernel service.\nAC:L - An attacker with render-node access fully controls UVD decode message fields (width, height, pitch in msg[28], stream_type) in their own BO and can reliably set pitch \u003e width (only width \u003e pitch was rejected) to force an underestimated buf_sizes[0x2] check.\nPR:L - Exploitation requires only standard unprivileged local access to the AMDGPU DRM render node (DRM_AUTH|DRM_RENDER_ALLOW on AMDGPU_CS ioctl), not real root; user namespaces alone do not grant render-node access.\nUI:N - No victim interaction is required; a local attacker can directly craft and submit a UVD command stream with a decode message via AMDGPU_CS ioctl after creating a valid UVD session handle.\nS:U - Impact is confined to the kernel/GPU driver on the local host (GPU out-of-bounds access within the attacker\u0027s DRM client address space); it does not cross VM, IOMMU, or sandbox boundaries to a different security authority.\nC:H - Underestimating the decode image minimum size lets undersized buffers pass amdgpu_uvd_cs_pass2 validation while the UVD engine decodes using pitch stride, enabling out-of-bounds reads of adjacent GPU-mapped memory that may contain sensitive data.\nI:H - Using image_size (width-based) instead of (pitch*height)*3/2 for buf_sizes[0x2] allows the UVD hardware to perform large out-of-bounds writes past the validated buffer when pitch exceeds width, corrupting adjacent GPU-mapped memory.\nA:H - Large GPU out-of-bounds writes from the UVD decode engine can hang or reset the GPU driver and may trigger kernel oops/panic; unbounded pitch before the fix also risked integer overflow wrapping the minimum size to near-zero, amplifying corruption."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T05:01:29.500Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/bc7397a033ac52f6d8c9bb6510d61694b2a3fce7"
},
{
"url": "https://git.kernel.org/stable/c/d058f7a6709441afe1784eecd8c0643dd84750bc"
},
{
"url": "https://git.kernel.org/stable/c/b7549e3f96c78921751c4b3e69af729662130d83"
},
{
"url": "https://git.kernel.org/stable/c/60539d517e8439621532d8c01091ac049c596b4b"
},
{
"url": "https://git.kernel.org/stable/c/271a7da84a6262a09de549912dcf6a749d169cb6"
},
{
"url": "https://git.kernel.org/stable/c/25ee120f3803ad9e416ef9f76f4c3234cc4d645b"
},
{
"url": "https://git.kernel.org/stable/c/5cbd8af02b0b9c8723fa30edcf6fccab5170af8d"
},
{
"url": "https://git.kernel.org/stable/c/b8bb9ba3f101a1b0011f785a577a4a0a38371174"
}
],
"title": "drm/amdgpu: Fix UVD decode image min size calculation",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80540",
"datePublished": "2026-08-26T14:37:13.966Z",
"dateReserved": "2026-08-26T14:34:25.765Z",
"dateUpdated": "2026-08-27T05:01:29.500Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64563 (GCVE-0-2026-64563)
Vulnerability from cvelistv5
Published
2026-08-04 06:23
Modified
2026-08-19 16:28
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
rhashtable: clear stale iter->p on table restart
rhashtable_walk_start_check() has two restart paths when resuming a walk.
When iter->walker.tbl is valid, it re-validates iter->p against the table
and sets iter->p = NULL if the object is gone. When iter->walker.tbl is
NULL (table was freed during resize), it resets slot and skip but forgets
to clear iter->p.
rhashtable_walk_next() then dereferences the stale iter->p, reading
freed memory. This is a use-after-free.
Any caller that does multi-fragment rhashtable walks across
walk_stop/walk_start boundaries is affected. Concrete cases include
netlink_diag (__netlink_diag_dump in net/netlink/diag.c) and TIPC
(tipc_nl_sk_walk in net/tipc/socket.c).
Crash stack (netlink_diag):
BUG: KASAN: slab-use-after-free in rhashtable_walk_next+0x365/0x3c0
Read of size 8 at addr ffff88801a9d2438 (freed kmalloc-2k, offset 1080)
Call Trace:
rhashtable_walk_next+0x365/0x3c0 (lib/rhashtable.c:1016)
__netlink_diag_dump+0x160/0x760 (net/netlink/diag.c:122)
netlink_diag_dump+0xc2/0x240
netlink_dump+0x5bc/0x1270
netlink_recvmsg+0x7a3/0x980
sock_recvmsg+0x1bc/0x200
__sys_recvfrom+0x1d4/0x2c0
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 5d240a8936f6a1d3ece06701e8c4d830a2eca8a8 Version: 5d240a8936f6a1d3ece06701e8c4d830a2eca8a8 Version: 5d240a8936f6a1d3ece06701e8c4d830a2eca8a8 Version: 5d240a8936f6a1d3ece06701e8c4d830a2eca8a8 Version: 5d240a8936f6a1d3ece06701e8c4d830a2eca8a8 Version: 5d240a8936f6a1d3ece06701e8c4d830a2eca8a8 Version: 5d240a8936f6a1d3ece06701e8c4d830a2eca8a8 Version: 5d240a8936f6a1d3ece06701e8c4d830a2eca8a8 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"lib/rhashtable.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ba510b5e9fe396497d31162acb579f210adfe6c8",
"status": "affected",
"version": "5d240a8936f6a1d3ece06701e8c4d830a2eca8a8",
"versionType": "git"
},
{
"lessThan": "a0406c40c6638c5ae50257db6297b2fba6c9ba16",
"status": "affected",
"version": "5d240a8936f6a1d3ece06701e8c4d830a2eca8a8",
"versionType": "git"
},
{
"lessThan": "0955b65c2b47c30b439e2cf1b1e375073aa0413a",
"status": "affected",
"version": "5d240a8936f6a1d3ece06701e8c4d830a2eca8a8",
"versionType": "git"
},
{
"lessThan": "c39643ad99fea749be50615550e8f0e6d6e60694",
"status": "affected",
"version": "5d240a8936f6a1d3ece06701e8c4d830a2eca8a8",
"versionType": "git"
},
{
"lessThan": "042fda5c088015f18838e5c692659a7be60aeb26",
"status": "affected",
"version": "5d240a8936f6a1d3ece06701e8c4d830a2eca8a8",
"versionType": "git"
},
{
"lessThan": "3ff7c1dbf722cf3fa538672452ba182318e0fcc3",
"status": "affected",
"version": "5d240a8936f6a1d3ece06701e8c4d830a2eca8a8",
"versionType": "git"
},
{
"lessThan": "4169d9fb92f313ff8e7e83d733c1ecdcc93eebd3",
"status": "affected",
"version": "5d240a8936f6a1d3ece06701e8c4d830a2eca8a8",
"versionType": "git"
},
{
"lessThan": "8173f7e2ce67e6ca1d4763f3da14e5b01ce77456",
"status": "affected",
"version": "5d240a8936f6a1d3ece06701e8c4d830a2eca8a8",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"lib/rhashtable.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.18"
},
{
"lessThan": "4.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.18",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nrhashtable: clear stale iter-\u003ep on table restart\n\nrhashtable_walk_start_check() has two restart paths when resuming a walk.\nWhen iter-\u003ewalker.tbl is valid, it re-validates iter-\u003ep against the table\nand sets iter-\u003ep = NULL if the object is gone. When iter-\u003ewalker.tbl is\nNULL (table was freed during resize), it resets slot and skip but forgets\nto clear iter-\u003ep.\n\nrhashtable_walk_next() then dereferences the stale iter-\u003ep, reading\nfreed memory. This is a use-after-free.\n\nAny caller that does multi-fragment rhashtable walks across\nwalk_stop/walk_start boundaries is affected. Concrete cases include\nnetlink_diag (__netlink_diag_dump in net/netlink/diag.c) and TIPC\n(tipc_nl_sk_walk in net/tipc/socket.c).\n\nCrash stack (netlink_diag):\n BUG: KASAN: slab-use-after-free in rhashtable_walk_next+0x365/0x3c0\n Read of size 8 at addr ffff88801a9d2438 (freed kmalloc-2k, offset 1080)\n Call Trace:\n rhashtable_walk_next+0x365/0x3c0 (lib/rhashtable.c:1016)\n __netlink_diag_dump+0x160/0x760 (net/netlink/diag.c:122)\n netlink_diag_dump+0xc2/0x240\n netlink_dump+0x5bc/0x1270\n netlink_recvmsg+0x7a3/0x980\n sock_recvmsg+0x1bc/0x200\n __sys_recvfrom+0x1d4/0x2c0"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Triggered via local netlink sock_diag dumps (e.g. netlink_diag over NETLINK_SOCK_DIAG) and similar local dump walkers such as TIPC_NL_SOCK_GET; not reachable from remote packet processing.\nAC:L - Attacker controls both sides of the race by running a multi-fragment rhashtable dump while concurrently creating/destroying netlink (or TIPC) sockets to force table resize and free the walked object.\nPR:L - An unprivileged local user can open NETLINK_SOCK_DIAG and dump without CAP_NET_ADMIN; CAP_NET_ADMIN is only required for SOCK_DESTROY, and TIPC_NL_SOCK_GET likewise has no admin permission flag.\nUI:N - Exploitation requires only attacker-issued syscalls (netlink dump plus concurrent socket churn); no victim action is needed.\nS:U - Impact is memory corruption within the host kernel authority (local privilege escalation/crash), not a cross-boundary escape such as guest-to-host or IOMMU bypass.\nC:H - Use-after-free read of a freed hashed object (e.g. netlink_sock) can be reclaimed via heap spray, yielding an arbitrary read primitive through subsequent walk/diag use of the corrupted pointer.\nI:H - UAF on a reclaimable slab object enables heap spraying and fake-object injection into the walk path, which can be leveraged for arbitrary write or control-flow hijacking.\nA:H - The demonstrated KASAN slab-use-after-free in rhashtable_walk_next can oops/panic the kernel, and UAFs remain crashable even when not fully exploited."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:28:34.797Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ba510b5e9fe396497d31162acb579f210adfe6c8"
},
{
"url": "https://git.kernel.org/stable/c/a0406c40c6638c5ae50257db6297b2fba6c9ba16"
},
{
"url": "https://git.kernel.org/stable/c/0955b65c2b47c30b439e2cf1b1e375073aa0413a"
},
{
"url": "https://git.kernel.org/stable/c/c39643ad99fea749be50615550e8f0e6d6e60694"
},
{
"url": "https://git.kernel.org/stable/c/042fda5c088015f18838e5c692659a7be60aeb26"
},
{
"url": "https://git.kernel.org/stable/c/3ff7c1dbf722cf3fa538672452ba182318e0fcc3"
},
{
"url": "https://git.kernel.org/stable/c/4169d9fb92f313ff8e7e83d733c1ecdcc93eebd3"
},
{
"url": "https://git.kernel.org/stable/c/8173f7e2ce67e6ca1d4763f3da14e5b01ce77456"
}
],
"title": "rhashtable: clear stale iter-\u003ep on table restart",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64563",
"datePublished": "2026-08-04T06:23:22.601Z",
"dateReserved": "2026-07-19T15:36:31.797Z",
"dateUpdated": "2026-08-19T16:28:34.797Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74523 (GCVE-0-2026-74523)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-19 16:38
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
qede: sync udp_tunnel ports outside qede_lock in the recovery path
A TX timeout on a qede NIC that has VXLAN/GENEVE tunnel ports
configured wedges the rtnetlink control plane of the whole machine:
NETDEV WATCHDOG: ens6f1 (qede): transmit queue 2 timed out 10226 ms
[qede_tx_timeout:586(ens6f1)]TX timeout on queue 2!
[qede_recovery_handler:2665(ens6f0)]Starting a recovery process
The recovery path deadlocks on the driver's own mutex:
qede_sp_task
rtnl_lock()
mutex_lock(&edev->qede_lock) <- taken
qede_recovery_handler
qede_load
udp_tunnel_nic_reset_ntf
__udp_tunnel_nic_device_sync
info->sync_table == qede_udp_tunnel_sync
mutex_lock(&edev->qede_lock) <- same task: deadlock
The mutex is not recursive, so the kworker blocks on itself with
rtnl_lock held, and neither lock is ever released. Every task that
calls rtnl_lock() afterwards (ip, ovs-vswitchd, lldpad, IPv6
addrconf, sshd) blocks forever while the node still answers ping.
In a vmcore from an affected production node rtnl_mutex.owner
decodes to the very kworker blocked at the innermost mutex_lock()
above.
Re-sync the tunnel ports from qede_sp_task() after the internal lock
is dropped, still under rtnl_lock as the udp_tunnel API requires.
This mirrors qede_open(), which calls udp_tunnel_nic_reset_ntf()
under rtnl without the internal lock.
qede_recovery_handler() now returns whether it has successfully
reloaded an open device, and the caller re-syncs the ports only in
that case. This keeps the old gating exactly: a device that was down
or a failed recovery returns false, as those paths never reached the
udp_tunnel_nic_reset_ntf() call before either.
This was the only user of the qede_lock()/qede_unlock() helpers, so
remove them.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 8cd160a29415f1789d473b1dc07fcc9d02a02b87 Version: 8cd160a29415f1789d473b1dc07fcc9d02a02b87 Version: 8cd160a29415f1789d473b1dc07fcc9d02a02b87 Version: 8cd160a29415f1789d473b1dc07fcc9d02a02b87 Version: 8cd160a29415f1789d473b1dc07fcc9d02a02b87 Version: 8cd160a29415f1789d473b1dc07fcc9d02a02b87 Version: 8cd160a29415f1789d473b1dc07fcc9d02a02b87 Version: 8cd160a29415f1789d473b1dc07fcc9d02a02b87 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/qlogic/qede/qede_main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "19e505ee8bb9e0f0355eda9e9f614fb25fed0070",
"status": "affected",
"version": "8cd160a29415f1789d473b1dc07fcc9d02a02b87",
"versionType": "git"
},
{
"lessThan": "c4c1e5d6bc2b900b2328d6fff93dc8146b858d69",
"status": "affected",
"version": "8cd160a29415f1789d473b1dc07fcc9d02a02b87",
"versionType": "git"
},
{
"lessThan": "8e1bdf57de91247e57816482966265ada573cc74",
"status": "affected",
"version": "8cd160a29415f1789d473b1dc07fcc9d02a02b87",
"versionType": "git"
},
{
"lessThan": "e382a4efeeae6555b95d9ff336cf3094ee7d336b",
"status": "affected",
"version": "8cd160a29415f1789d473b1dc07fcc9d02a02b87",
"versionType": "git"
},
{
"lessThan": "4626df3f63c9185efba5750fe76ac01ab3351bae",
"status": "affected",
"version": "8cd160a29415f1789d473b1dc07fcc9d02a02b87",
"versionType": "git"
},
{
"lessThan": "e51becb8f3377a377171ed5bf0082b96e22e6292",
"status": "affected",
"version": "8cd160a29415f1789d473b1dc07fcc9d02a02b87",
"versionType": "git"
},
{
"lessThan": "6f1ef8170d3d8ad9319aa01347945dcdf5cc4f27",
"status": "affected",
"version": "8cd160a29415f1789d473b1dc07fcc9d02a02b87",
"versionType": "git"
},
{
"lessThan": "451c9075d6c53f2438d110addbeeeea6fac18567",
"status": "affected",
"version": "8cd160a29415f1789d473b1dc07fcc9d02a02b87",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/qlogic/qede/qede_main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.9"
},
{
"lessThan": "5.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nqede: sync udp_tunnel ports outside qede_lock in the recovery path\n\nA TX timeout on a qede NIC that has VXLAN/GENEVE tunnel ports\nconfigured wedges the rtnetlink control plane of the whole machine:\n\n NETDEV WATCHDOG: ens6f1 (qede): transmit queue 2 timed out 10226 ms\n [qede_tx_timeout:586(ens6f1)]TX timeout on queue 2!\n [qede_recovery_handler:2665(ens6f0)]Starting a recovery process\n\nThe recovery path deadlocks on the driver\u0027s own mutex:\n\n qede_sp_task\n rtnl_lock()\n mutex_lock(\u0026edev-\u003eqede_lock) \u003c- taken\n qede_recovery_handler\n qede_load\n udp_tunnel_nic_reset_ntf\n __udp_tunnel_nic_device_sync\n info-\u003esync_table == qede_udp_tunnel_sync\n mutex_lock(\u0026edev-\u003eqede_lock) \u003c- same task: deadlock\n\nThe mutex is not recursive, so the kworker blocks on itself with\nrtnl_lock held, and neither lock is ever released. Every task that\ncalls rtnl_lock() afterwards (ip, ovs-vswitchd, lldpad, IPv6\naddrconf, sshd) blocks forever while the node still answers ping.\nIn a vmcore from an affected production node rtnl_mutex.owner\ndecodes to the very kworker blocked at the innermost mutex_lock()\nabove.\n\nRe-sync the tunnel ports from qede_sp_task() after the internal lock\nis dropped, still under rtnl_lock as the udp_tunnel API requires.\nThis mirrors qede_open(), which calls udp_tunnel_nic_reset_ntf()\nunder rtnl without the internal lock.\n\nqede_recovery_handler() now returns whether it has successfully\nreloaded an open device, and the caller re-syncs the ports only in\nthat case. This keeps the old gating exactly: a device that was down\nor a failed recovery returns false, as those paths never reached the\nudp_tunnel_nic_reset_ntf() call before either.\n\nThis was the only user of the qede_lock()/qede_unlock() helpers, so\nremove them."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug is reached from the qede NIC firmware error-recovery path triggered by network-driven faults (e.g., TX queue watchdog timeout on traffic-bearing queues); remote packets to an internet-facing qede host can induce recovery without local syscall access.\nAC:L - Once qede recovery runs on an interface with VXLAN/GENEVE ports registered, the nested qede_lock while rtnl_lock is held deadlocks deterministically; attackers can repeatedly apply traffic/load patterns to provoke TX timeout and firmware ERROR_RECOVERY.\nPR:N - Exploitation requires only the ability to send network traffic that provokes NIC recovery on a target that already has VXLAN/GENEVE offloads configured (normal on cloud/DC qede nodes); no attacker privileges or rtnetlink configuration are needed.\nUI:N - No victim interaction is required beyond routine use of a server whose qede uplink already runs overlay networking; the attacker does not need the victim to mount, open, or approve anything at exploit time.\nS:U - Impact is a kernel networking control-plane deadlock within the same host/kernel trust boundary; it does not cross VM, container, or IOMMU security domains to affect other authorities.\nC:N - This is a locking deadlock with no memory corruption, out-of-bounds access, use-after-free, or information disclosure; only mutex/RTNL state is wedged.\nI:N - The flaw does not modify data or achieve code execution; it only blocks threads waiting on rtnl_lock/qede_lock without altering memory contents or kernel objects beyond stalled lock state.\nA:H - The deadlock holds rtnl_lock indefinitely, freezing system-wide network reconfiguration and management (ip, ovs-vswitchd, sshd addr setup) until reboot; per CVSS guidance, kernel deadlocks that deny critical availability are rated High."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:38:27.388Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/19e505ee8bb9e0f0355eda9e9f614fb25fed0070"
},
{
"url": "https://git.kernel.org/stable/c/c4c1e5d6bc2b900b2328d6fff93dc8146b858d69"
},
{
"url": "https://git.kernel.org/stable/c/8e1bdf57de91247e57816482966265ada573cc74"
},
{
"url": "https://git.kernel.org/stable/c/e382a4efeeae6555b95d9ff336cf3094ee7d336b"
},
{
"url": "https://git.kernel.org/stable/c/4626df3f63c9185efba5750fe76ac01ab3351bae"
},
{
"url": "https://git.kernel.org/stable/c/e51becb8f3377a377171ed5bf0082b96e22e6292"
},
{
"url": "https://git.kernel.org/stable/c/6f1ef8170d3d8ad9319aa01347945dcdf5cc4f27"
},
{
"url": "https://git.kernel.org/stable/c/451c9075d6c53f2438d110addbeeeea6fac18567"
}
],
"title": "qede: sync udp_tunnel ports outside qede_lock in the recovery path",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74523",
"datePublished": "2026-08-15T12:27:40.575Z",
"dateReserved": "2026-08-15T05:44:03.911Z",
"dateUpdated": "2026-08-19T16:38:27.388Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74548 (GCVE-0-2026-74548)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-19 16:38
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
forcedeth: fix UAF of txrx_stats in nv_remove
nv_remove() frees the per-CPU txrx_stats before unregister_netdev().
Until unregister completes, ndo_get_stats64, the NAPI/xmit data path,
and nv_close()/drain may still access txrx_stats, leading to a
use-after-free.
Free the stats only after unregister_netdev().
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: f4b633b911fd3b4cbe1dc065e8fb064078d0889d Version: f4b633b911fd3b4cbe1dc065e8fb064078d0889d Version: f4b633b911fd3b4cbe1dc065e8fb064078d0889d Version: f4b633b911fd3b4cbe1dc065e8fb064078d0889d Version: f4b633b911fd3b4cbe1dc065e8fb064078d0889d Version: f4b633b911fd3b4cbe1dc065e8fb064078d0889d Version: f4b633b911fd3b4cbe1dc065e8fb064078d0889d Version: f4b633b911fd3b4cbe1dc065e8fb064078d0889d |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/nvidia/forcedeth.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "cdf864d5d3c813ae1876f2bacc1cf3ac3c66dfc9",
"status": "affected",
"version": "f4b633b911fd3b4cbe1dc065e8fb064078d0889d",
"versionType": "git"
},
{
"lessThan": "7c22b4ee0bd003cecfc14ca28981cb213e201f70",
"status": "affected",
"version": "f4b633b911fd3b4cbe1dc065e8fb064078d0889d",
"versionType": "git"
},
{
"lessThan": "d51ce7a63b76eda02cabfed1b0cc277b2f5c9bcc",
"status": "affected",
"version": "f4b633b911fd3b4cbe1dc065e8fb064078d0889d",
"versionType": "git"
},
{
"lessThan": "cf2dcde2284562ff87830ca0b7fa2b06e95aef1e",
"status": "affected",
"version": "f4b633b911fd3b4cbe1dc065e8fb064078d0889d",
"versionType": "git"
},
{
"lessThan": "c9d24a205fd508b9999fcab6aca4c590490a12cf",
"status": "affected",
"version": "f4b633b911fd3b4cbe1dc065e8fb064078d0889d",
"versionType": "git"
},
{
"lessThan": "ae20a8a4de06a289d40b0a0633d8d573f1fcb049",
"status": "affected",
"version": "f4b633b911fd3b4cbe1dc065e8fb064078d0889d",
"versionType": "git"
},
{
"lessThan": "201e05aa531eba0dfe2ee05b4e178f6ffa12c8b1",
"status": "affected",
"version": "f4b633b911fd3b4cbe1dc065e8fb064078d0889d",
"versionType": "git"
},
{
"lessThan": "22666ba1420164753d7b0f5a841986b25ace5435",
"status": "affected",
"version": "f4b633b911fd3b4cbe1dc065e8fb064078d0889d",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/nvidia/forcedeth.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.3"
},
{
"lessThan": "5.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nforcedeth: fix UAF of txrx_stats in nv_remove\n\nnv_remove() frees the per-CPU txrx_stats before unregister_netdev().\nUntil unregister completes, ndo_get_stats64, the NAPI/xmit data path,\nand nv_close()/drain may still access txrx_stats, leading to a\nuse-after-free.\n\nFree the stats only after unregister_netdev()."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The UAF is opened in nv_remove() during local PCI/driver teardown (sysfs unbind, module unload, or hot-unplug); although NAPI/xmit and stats readers can run concurrently on still-registered netdev traffic, there is no standalone remote path into nv_remove itself.\nAC:L - Once teardown starts, unregister_netdev() deterministically calls nv_close()\u2192nv_drain_tx(), which increments freed txrx_stats when TX skbs remain, and an attacker can also drive the race by timing unbind against stats polling or packet I/O they control.\nPR:L - Privileged teardown opens the window, but unprivileged peers can supply the concurrent netdev access (rtnetlink/sysfs stats via nv_get_stats64, and RX/TX on the still-up interface) that performs the UAF; per CNA driver-removal UAF precedent and the higher-severity tiebreak, PR:L.\nUI:N - No separate victim action is required beyond routine driver removal or module unload on a live interface; monitoring daemons and network traffic can hit the freed stats automatically during the unregister window without user cooperation.\nS:U - Impact is kernel heap corruption and crash/privilege escalation within the host kernel security authority; it does not cross VM, hypervisor, IOMMU, or container sandbox boundaries.\nC:H - The bug is a kmalloc-backed per-CPU UAF: nv_get_stats64 reads freed nv_txrx_stats counters via per_cpu_ptr(), and once the slab is reallocated an attacker can obtain arbitrary kernel memory disclosure.\nI:H - Freed txrx_stats are updated from NAPI/xmit and nv_drain_tx() via __this_cpu_inc/add on attacker-influenced traffic, enabling heap grooming and controlled writes through the dangling per-CPU pointer for code execution.\nA:H - Use-after-free dereferences of txrx_stats during netdev teardown reliably cause kernel oops/panic (as in the fix description), and even unsuccessful exploitation still crashes the system when concurrent RX/TX or drain paths touch freed memory."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:38:39.684Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/cdf864d5d3c813ae1876f2bacc1cf3ac3c66dfc9"
},
{
"url": "https://git.kernel.org/stable/c/7c22b4ee0bd003cecfc14ca28981cb213e201f70"
},
{
"url": "https://git.kernel.org/stable/c/d51ce7a63b76eda02cabfed1b0cc277b2f5c9bcc"
},
{
"url": "https://git.kernel.org/stable/c/cf2dcde2284562ff87830ca0b7fa2b06e95aef1e"
},
{
"url": "https://git.kernel.org/stable/c/c9d24a205fd508b9999fcab6aca4c590490a12cf"
},
{
"url": "https://git.kernel.org/stable/c/ae20a8a4de06a289d40b0a0633d8d573f1fcb049"
},
{
"url": "https://git.kernel.org/stable/c/201e05aa531eba0dfe2ee05b4e178f6ffa12c8b1"
},
{
"url": "https://git.kernel.org/stable/c/22666ba1420164753d7b0f5a841986b25ace5435"
}
],
"title": "forcedeth: fix UAF of txrx_stats in nv_remove",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74548",
"datePublished": "2026-08-15T12:27:56.387Z",
"dateReserved": "2026-08-15T05:44:03.915Z",
"dateUpdated": "2026-08-19T16:38:39.684Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80732 (GCVE-0-2026-80732)
Vulnerability from cvelistv5
Published
2026-09-03 08:21
Modified
2026-09-04 04:58
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ata: pata_sl82c105: fix bridge revision use-after-free
pci_get_slot() returns a referenced PCI device. Commit 44c10138fd4b
("PCI: Change all drivers to use pci_device->revision") replaced a
configuration-space read with direct access to the cached revision field,
but left that access after pci_dev_put(). The bridge may therefore be freed
before its revision is read.
Read the revision before dropping the reference.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 44c10138fd4bbc4b6d6bff0873c24902f2a9da65 Version: 44c10138fd4bbc4b6d6bff0873c24902f2a9da65 Version: 44c10138fd4bbc4b6d6bff0873c24902f2a9da65 Version: 44c10138fd4bbc4b6d6bff0873c24902f2a9da65 Version: 44c10138fd4bbc4b6d6bff0873c24902f2a9da65 Version: 44c10138fd4bbc4b6d6bff0873c24902f2a9da65 Version: 44c10138fd4bbc4b6d6bff0873c24902f2a9da65 Version: 44c10138fd4bbc4b6d6bff0873c24902f2a9da65 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/ata/pata_sl82c105.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "1268ca9418e2217f2b60705cf4a280b689b26678",
"status": "affected",
"version": "44c10138fd4bbc4b6d6bff0873c24902f2a9da65",
"versionType": "git"
},
{
"lessThan": "a626dfca96041842053cf2d1efceb436c4cd8dcf",
"status": "affected",
"version": "44c10138fd4bbc4b6d6bff0873c24902f2a9da65",
"versionType": "git"
},
{
"lessThan": "5ef87b1b4656d675440ceab32a56e69ad958d3a1",
"status": "affected",
"version": "44c10138fd4bbc4b6d6bff0873c24902f2a9da65",
"versionType": "git"
},
{
"lessThan": "fa0dca89b4fb0909ffda7b9ab6051af33270f95e",
"status": "affected",
"version": "44c10138fd4bbc4b6d6bff0873c24902f2a9da65",
"versionType": "git"
},
{
"lessThan": "dc711fb137b33c12e6ca22b6a9c9b9f21d49e4de",
"status": "affected",
"version": "44c10138fd4bbc4b6d6bff0873c24902f2a9da65",
"versionType": "git"
},
{
"lessThan": "a837deeaa37cc3f0e8c4e5c096787047f272c956",
"status": "affected",
"version": "44c10138fd4bbc4b6d6bff0873c24902f2a9da65",
"versionType": "git"
},
{
"lessThan": "56fd78c8c820f527f8003e379ab71004b2e79a44",
"status": "affected",
"version": "44c10138fd4bbc4b6d6bff0873c24902f2a9da65",
"versionType": "git"
},
{
"lessThan": "7700a31039cdc6715cb6cce7e7a664ee4e945f67",
"status": "affected",
"version": "44c10138fd4bbc4b6d6bff0873c24902f2a9da65",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/ata/pata_sl82c105.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.23"
},
{
"lessThan": "2.6.23",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.23",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.23",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.23",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "2.6.23",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "2.6.23",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "2.6.23",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "2.6.23",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.23",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nata: pata_sl82c105: fix bridge revision use-after-free\n\npci_get_slot() returns a referenced PCI device. Commit 44c10138fd4b\n(\"PCI: Change all drivers to use pci_device-\u003erevision\") replaced a\nconfiguration-space read with direct access to the cached revision field,\nbut left that access after pci_dev_put(). The bridge may therefore be freed\nbefore its revision is read.\n\nRead the revision before dropping the reference."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - sl82c105_bridge_revision() is only reached from sl82c105_init_one() during PCI driver probe of onboard SL82C105 hardware, triggered by boot enumeration, udev, or local module/sysfs bind; no network or adjacent protocol path exists.\nAC:L - Once CONFIG_PATA_WINBOND and matching Winbond W83C553 bridge hardware are present, the UAF is a deterministic, synchronous read after pci_dev_put() on every successful probe path\u2014no race, layout dependency, or victim state beyond standard probe.\nPR:L - Probe is initiated automatically by kernel PCI enumeration and udev during boot or hotplug on systems with SL82C105 storage (Netwinder, briq, legacy embedded), so reaching the bug does not require admin action; only local presence on such a host is needed.\nUI:N - Driver probe runs automatically during boot enumeration or udev module load when matching PCI hardware is present; no administrator or victim must mount media, open files, or perform any interactive action.\nS:U - Corrupting or reading freed pci_dev memory affects only the host kernel address space, yielding a standard local kernel compromise or panic rather than crossing a VM, hypervisor, or IOMMU boundary.\nC:H - Reading bridge-\u003erevision after pci_dev_put() is a use-after-free of struct pci_dev; if the allocation is reused, the attacker obtains a kernel memory disclosure primitive and can read adjacent freed data.\nI:H - UAF of struct pci_dev enables heap-spray reclamation of the freed object, giving attacker-controlled contents for subsequent kernel dereferences and a well-established path to arbitrary write and privilege escalation.\nA:H - Dereferencing a potentially freed pci_dev during probe can immediately oops or panic the kernel; even without full exploitation, UAF corruption commonly crashes the system on affected legacy embedded hosts."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T04:58:18.567Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/1268ca9418e2217f2b60705cf4a280b689b26678"
},
{
"url": "https://git.kernel.org/stable/c/a626dfca96041842053cf2d1efceb436c4cd8dcf"
},
{
"url": "https://git.kernel.org/stable/c/5ef87b1b4656d675440ceab32a56e69ad958d3a1"
},
{
"url": "https://git.kernel.org/stable/c/fa0dca89b4fb0909ffda7b9ab6051af33270f95e"
},
{
"url": "https://git.kernel.org/stable/c/dc711fb137b33c12e6ca22b6a9c9b9f21d49e4de"
},
{
"url": "https://git.kernel.org/stable/c/a837deeaa37cc3f0e8c4e5c096787047f272c956"
},
{
"url": "https://git.kernel.org/stable/c/56fd78c8c820f527f8003e379ab71004b2e79a44"
},
{
"url": "https://git.kernel.org/stable/c/7700a31039cdc6715cb6cce7e7a664ee4e945f67"
}
],
"title": "ata: pata_sl82c105: fix bridge revision use-after-free",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80732",
"datePublished": "2026-09-03T08:21:49.526Z",
"dateReserved": "2026-08-26T14:34:25.789Z",
"dateUpdated": "2026-09-04T04:58:18.567Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74458 (GCVE-0-2026-74458)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-19 16:36
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
can: kvaser_usb_leaf: kvaser_usb_leaf_wait_cmd(): validate received command extents
The wait and bulk receive paths walk variable-length commands from a
USB buffer. A nonzero command shorter than CMD_HEADER_LEN can still be
dispatched, and the wait path copies a matching command into a fixed
caller-owned struct kvaser_cmd using the device-provided length.
Reject nonzero commands that do not contain the fixed header or that
extend beyond the current USB buffer item. In the wait path, also reject
a matching command that exceeds the destination before copying it.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 080f40a6fa28dab299da7a652e444b1e2d9231e7 Version: 080f40a6fa28dab299da7a652e444b1e2d9231e7 Version: 080f40a6fa28dab299da7a652e444b1e2d9231e7 Version: 080f40a6fa28dab299da7a652e444b1e2d9231e7 Version: 080f40a6fa28dab299da7a652e444b1e2d9231e7 Version: 080f40a6fa28dab299da7a652e444b1e2d9231e7 Version: 080f40a6fa28dab299da7a652e444b1e2d9231e7 Version: 080f40a6fa28dab299da7a652e444b1e2d9231e7 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/can/usb/kvaser_usb/kvaser_usb_leaf.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c00ec53d7dec08134e97071850cc00ef000c5b77",
"status": "affected",
"version": "080f40a6fa28dab299da7a652e444b1e2d9231e7",
"versionType": "git"
},
{
"lessThan": "d9e91672526ffa279709b15490118aea1bdee714",
"status": "affected",
"version": "080f40a6fa28dab299da7a652e444b1e2d9231e7",
"versionType": "git"
},
{
"lessThan": "72f96c2942f11a0ae8663adcb3d9ee986e07d4fa",
"status": "affected",
"version": "080f40a6fa28dab299da7a652e444b1e2d9231e7",
"versionType": "git"
},
{
"lessThan": "695aea154bb2d453e6daada1510972fafd075285",
"status": "affected",
"version": "080f40a6fa28dab299da7a652e444b1e2d9231e7",
"versionType": "git"
},
{
"lessThan": "3d0897ec623e422695d70d80ae456f89476c5328",
"status": "affected",
"version": "080f40a6fa28dab299da7a652e444b1e2d9231e7",
"versionType": "git"
},
{
"lessThan": "185cb1fa38142a3cbf223dd8b3abb24217f330d3",
"status": "affected",
"version": "080f40a6fa28dab299da7a652e444b1e2d9231e7",
"versionType": "git"
},
{
"lessThan": "21f0465fd86d77794aaed8e05f833634f68d178d",
"status": "affected",
"version": "080f40a6fa28dab299da7a652e444b1e2d9231e7",
"versionType": "git"
},
{
"lessThan": "0293dd153f9dbc1ddf5dacdccc76b363bce4a8ee",
"status": "affected",
"version": "080f40a6fa28dab299da7a652e444b1e2d9231e7",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/can/usb/kvaser_usb/kvaser_usb_leaf.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.8"
},
{
"lessThan": "3.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "3.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "3.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "3.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "3.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: kvaser_usb_leaf: kvaser_usb_leaf_wait_cmd(): validate received command extents\n\nThe wait and bulk receive paths walk variable-length commands from a\nUSB buffer. A nonzero command shorter than CMD_HEADER_LEN can still be\ndispatched, and the wait path copies a matching command into a fixed\ncaller-owned struct kvaser_cmd using the device-provided length.\n\nReject nonzero commands that do not contain the fixed header or that\nextend beyond the current USB buffer item. In the wait path, also reject\na matching command that exceeds the destination before copying it."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:36:54.341Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c00ec53d7dec08134e97071850cc00ef000c5b77"
},
{
"url": "https://git.kernel.org/stable/c/d9e91672526ffa279709b15490118aea1bdee714"
},
{
"url": "https://git.kernel.org/stable/c/72f96c2942f11a0ae8663adcb3d9ee986e07d4fa"
},
{
"url": "https://git.kernel.org/stable/c/695aea154bb2d453e6daada1510972fafd075285"
},
{
"url": "https://git.kernel.org/stable/c/3d0897ec623e422695d70d80ae456f89476c5328"
},
{
"url": "https://git.kernel.org/stable/c/185cb1fa38142a3cbf223dd8b3abb24217f330d3"
},
{
"url": "https://git.kernel.org/stable/c/21f0465fd86d77794aaed8e05f833634f68d178d"
},
{
"url": "https://git.kernel.org/stable/c/0293dd153f9dbc1ddf5dacdccc76b363bce4a8ee"
}
],
"title": "can: kvaser_usb_leaf: kvaser_usb_leaf_wait_cmd(): validate received command extents",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74458",
"datePublished": "2026-08-15T12:27:00.053Z",
"dateReserved": "2026-08-15T05:44:03.900Z",
"dateUpdated": "2026-08-19T16:36:54.341Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72051 (GCVE-0-2026-72051)
Vulnerability from cvelistv5
Published
2026-08-15 05:52
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: ip6_tunnel: require CAP_NET_ADMIN in the device netns for changelink
ip6_tnl_changelink() operates on at most two netns, dev_net(dev) and the
tunnel link netns t->net. They differ once the device is created in or
moved to a netns other than the one the request runs in. The rtnl
changelink path checks CAP_NET_ADMIN only against dev_net(dev), so a
caller privileged there but not in t->net can rewrite a tunnel that
lives in t->net.
Gate ip6_tnl_changelink() on rtnl_dev_link_net_capable() at its top,
before any attribute is parsed.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 0bd8762824e73a3cce7b7560a97463301764b616 Version: 0bd8762824e73a3cce7b7560a97463301764b616 Version: 0bd8762824e73a3cce7b7560a97463301764b616 Version: 0bd8762824e73a3cce7b7560a97463301764b616 Version: 0bd8762824e73a3cce7b7560a97463301764b616 Version: 0bd8762824e73a3cce7b7560a97463301764b616 Version: 0bd8762824e73a3cce7b7560a97463301764b616 Version: 0bd8762824e73a3cce7b7560a97463301764b616 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ipv6/ip6_tunnel.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "2d53ee7daabe733deb81f51d2cc90188f8ad59a1",
"status": "affected",
"version": "0bd8762824e73a3cce7b7560a97463301764b616",
"versionType": "git"
},
{
"lessThan": "82e53e7281c71e174f9f5877c566a623c637b406",
"status": "affected",
"version": "0bd8762824e73a3cce7b7560a97463301764b616",
"versionType": "git"
},
{
"lessThan": "5252db8fb604321133138c7069d6fc3fcd89cdee",
"status": "affected",
"version": "0bd8762824e73a3cce7b7560a97463301764b616",
"versionType": "git"
},
{
"lessThan": "2636d061bc237a2446a146e42dcc6563acfa7432",
"status": "affected",
"version": "0bd8762824e73a3cce7b7560a97463301764b616",
"versionType": "git"
},
{
"lessThan": "7f68f7928484f463a5bc0d50e6fdd8d16f55a5aa",
"status": "affected",
"version": "0bd8762824e73a3cce7b7560a97463301764b616",
"versionType": "git"
},
{
"lessThan": "234cd54fc500f69db43e37de38603da617fbbeea",
"status": "affected",
"version": "0bd8762824e73a3cce7b7560a97463301764b616",
"versionType": "git"
},
{
"lessThan": "d4bcc202a3530c856e1cb183384bc9cc8fddab22",
"status": "affected",
"version": "0bd8762824e73a3cce7b7560a97463301764b616",
"versionType": "git"
},
{
"lessThan": "2496fa0b7d180b3ad356b514e7ff93bb14e6140a",
"status": "affected",
"version": "0bd8762824e73a3cce7b7560a97463301764b616",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ipv6/ip6_tunnel.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.12"
},
{
"lessThan": "3.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ip6_tunnel: require CAP_NET_ADMIN in the device netns for changelink\n\nip6_tnl_changelink() operates on at most two netns, dev_net(dev) and the\ntunnel link netns t-\u003enet. They differ once the device is created in or\nmoved to a netns other than the one the request runs in. The rtnl\nchangelink path checks CAP_NET_ADMIN only against dev_net(dev), so a\ncaller privileged there but not in t-\u003enet can rewrite a tunnel that\nlives in t-\u003enet.\n\nGate ip6_tnl_changelink() on rtnl_dev_link_net_capable() at its top,\nbefore any attribute is parsed."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires RTM_NEWLINK changelink over a local rtnetlink socket; ip6_tnl_changelink is only reachable from rtnl configuration, not from received IPv6 packets processed by ip6_tnl_rcv.\nAC:L - Once an ip6tnl device exists with t-\u003enet differing from dev_net(dev) (IFLA_LINK_NETNSID newlink or IFLA_NET_NS_FD migration), a single deterministic netlink changelink bypasses the missing check with no race or memory-layout dependency.\nPR:L - The rtnl entry path requires CAP_NET_ADMIN only in dev_net(dev), obtainable by an unprivileged local user via unshare --user --map-root-user --net; no CAP_NET_ADMIN in the sticky link netns t-\u003enet is required.\nUI:N - The attack is fully programmatic through netlink from the attacker\u0027s own process; no victim action such as mounting a filesystem, opening a file, or clicking is required.\nS:C - Authorization is checked against dev_net(dev) while ip6_tnl_changelink mutates tunnel state in t-\u003enet via ip6_tnl_update, crossing from the attacker\u0027s net/user namespace into another tenant\u0027s or the host\u0027s network namespace.\nC:H - An attacker can rewrite IFLA_IPTUN_LOCAL/REMOTE, link, fwmark, and encap parameters to redirect IPv6/IPv4-over-IPv6 tunnel traffic to an attacker-controlled endpoint and read all tunneled payloads in the victim link netns.\nI:H - Unauthorized changelink updates live tunnel endpoints, underlay link, encap ports, and flowinfo/fwmark in t-\u003enet, enabling redirection and injection of traffic carried over the ip6tnl tunnel.\nA:H - Rewriting tunnel remote/local addresses, underlay device, or encap parameters breaks cross-netns IPv6 tunnel connectivity, causing sustained loss of service for every workload depending on the affected ip6tnl tunnel."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:34.252Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/2d53ee7daabe733deb81f51d2cc90188f8ad59a1"
},
{
"url": "https://git.kernel.org/stable/c/82e53e7281c71e174f9f5877c566a623c637b406"
},
{
"url": "https://git.kernel.org/stable/c/5252db8fb604321133138c7069d6fc3fcd89cdee"
},
{
"url": "https://git.kernel.org/stable/c/2636d061bc237a2446a146e42dcc6563acfa7432"
},
{
"url": "https://git.kernel.org/stable/c/7f68f7928484f463a5bc0d50e6fdd8d16f55a5aa"
},
{
"url": "https://git.kernel.org/stable/c/234cd54fc500f69db43e37de38603da617fbbeea"
},
{
"url": "https://git.kernel.org/stable/c/d4bcc202a3530c856e1cb183384bc9cc8fddab22"
},
{
"url": "https://git.kernel.org/stable/c/2496fa0b7d180b3ad356b514e7ff93bb14e6140a"
}
],
"title": "net: ip6_tunnel: require CAP_NET_ADMIN in the device netns for changelink",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72051",
"datePublished": "2026-08-15T05:52:08.445Z",
"dateReserved": "2026-08-09T03:40:39.902Z",
"dateUpdated": "2026-08-23T12:46:34.252Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80790 (GCVE-0-2026-80790)
Vulnerability from cvelistv5
Published
2026-09-04 15:13
Modified
2026-09-04 15:13
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
nvmet-fc: fix invalid free in LS IOD error path
nvmet_fc_alloc_ls_iodlist() advances iod while initializing the LS IOD
array. If an rqstbuf allocation or response buffer DMA mapping fails,
the unwind loop decrements iod past the start of the array. The final
kfree(iod) therefore frees an address before the allocated object.
This can be reproduced with nvme-fcloop and failslab by setting
fail-nth to 6 before creating a target port. KASAN reports:
BUG: KASAN: invalid-free in nvmet_fc_register_targetport
Free of addr ffff88816cf8ff48 by task nvmet_fail_nth/9552
Free the original allocation base stored in tgtport->iod instead. With
this fix applied, the same sysfs write with fail-nth=6 returns -ENOMEM
without any KASAN report.
References
| URL | Tags | ||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: c53432030d86429dc9fe5adc3d68cb9d1343b0b2 Version: c53432030d86429dc9fe5adc3d68cb9d1343b0b2 Version: c53432030d86429dc9fe5adc3d68cb9d1343b0b2 Version: c53432030d86429dc9fe5adc3d68cb9d1343b0b2 Version: c53432030d86429dc9fe5adc3d68cb9d1343b0b2 Version: c53432030d86429dc9fe5adc3d68cb9d1343b0b2 Version: c53432030d86429dc9fe5adc3d68cb9d1343b0b2 Version: c53432030d86429dc9fe5adc3d68cb9d1343b0b2 Version: c53432030d86429dc9fe5adc3d68cb9d1343b0b2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/nvme/target/fc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b189c6e408896ccc23d2e76d7738847cdebf1532",
"status": "affected",
"version": "c53432030d86429dc9fe5adc3d68cb9d1343b0b2",
"versionType": "git"
},
{
"lessThan": "449e9c4f8db84ad9d9bb288029b230bcf590faa2",
"status": "affected",
"version": "c53432030d86429dc9fe5adc3d68cb9d1343b0b2",
"versionType": "git"
},
{
"lessThan": "1a8f007faefe8c226ec65896589f8d59b0a8d5a5",
"status": "affected",
"version": "c53432030d86429dc9fe5adc3d68cb9d1343b0b2",
"versionType": "git"
},
{
"lessThan": "d094582cce9c08516d714e7436a8f3b9211dda90",
"status": "affected",
"version": "c53432030d86429dc9fe5adc3d68cb9d1343b0b2",
"versionType": "git"
},
{
"lessThan": "371fb1bf902adaa59be32bd7e904a5317e604fd0",
"status": "affected",
"version": "c53432030d86429dc9fe5adc3d68cb9d1343b0b2",
"versionType": "git"
},
{
"lessThan": "8bce9cd08aae4283badf8ddc11fbb6f57b75a81e",
"status": "affected",
"version": "c53432030d86429dc9fe5adc3d68cb9d1343b0b2",
"versionType": "git"
},
{
"lessThan": "bb9489f0dce58da730d3479588d6710d7a2c1b45",
"status": "affected",
"version": "c53432030d86429dc9fe5adc3d68cb9d1343b0b2",
"versionType": "git"
},
{
"lessThan": "94334ea92f4d7535f66f86e33681efa94827eddc",
"status": "affected",
"version": "c53432030d86429dc9fe5adc3d68cb9d1343b0b2",
"versionType": "git"
},
{
"lessThan": "ba98d6796d12258e837ece065d2ecb59d76ce4ff",
"status": "affected",
"version": "c53432030d86429dc9fe5adc3d68cb9d1343b0b2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/nvme/target/fc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.10"
},
{
"lessThan": "4.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.267",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.218",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.185",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.154",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.106",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.47",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.1",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.267",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.218",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.185",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.154",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.106",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.47",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.11",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.1",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "4.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet-fc: fix invalid free in LS IOD error path\n\nnvmet_fc_alloc_ls_iodlist() advances iod while initializing the LS IOD\narray. If an rqstbuf allocation or response buffer DMA mapping fails,\nthe unwind loop decrements iod past the start of the array. The final\nkfree(iod) therefore frees an address before the allocated object.\n\nThis can be reproduced with nvme-fcloop and failslab by setting\nfail-nth to 6 before creating a target port. KASAN reports:\n\n BUG: KASAN: invalid-free in nvmet_fc_register_targetport\n Free of addr ffff88816cf8ff48 by task nvmet_fail_nth/9552\n\nFree the original allocation base stored in tgtport-\u003eiod instead. With\nthis fix applied, the same sysfs write with fail-nth=6 returns -ENOMEM\nwithout any KASAN report."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T15:13:02.193Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b189c6e408896ccc23d2e76d7738847cdebf1532"
},
{
"url": "https://git.kernel.org/stable/c/449e9c4f8db84ad9d9bb288029b230bcf590faa2"
},
{
"url": "https://git.kernel.org/stable/c/1a8f007faefe8c226ec65896589f8d59b0a8d5a5"
},
{
"url": "https://git.kernel.org/stable/c/d094582cce9c08516d714e7436a8f3b9211dda90"
},
{
"url": "https://git.kernel.org/stable/c/371fb1bf902adaa59be32bd7e904a5317e604fd0"
},
{
"url": "https://git.kernel.org/stable/c/8bce9cd08aae4283badf8ddc11fbb6f57b75a81e"
},
{
"url": "https://git.kernel.org/stable/c/bb9489f0dce58da730d3479588d6710d7a2c1b45"
},
{
"url": "https://git.kernel.org/stable/c/94334ea92f4d7535f66f86e33681efa94827eddc"
},
{
"url": "https://git.kernel.org/stable/c/ba98d6796d12258e837ece065d2ecb59d76ce4ff"
}
],
"title": "nvmet-fc: fix invalid free in LS IOD error path",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80790",
"datePublished": "2026-09-04T15:13:02.193Z",
"dateReserved": "2026-08-26T14:34:25.793Z",
"dateUpdated": "2026-09-04T15:13:02.193Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80768 (GCVE-0-2026-80768)
Vulnerability from cvelistv5
Published
2026-09-04 15:12
Modified
2026-09-04 15:12
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
HID: ft260: fix stack-use-after-return write in I2C read race
ft260_i2c_read() points dev->read_buf at a caller-supplied buffer
(often an on-stack variable), arms a completion and waits up to five
seconds for the device to return the data. The HID input callback
ft260_raw_event() runs in the input/IRQ path, independent of the
dev->lock mutex held by the read path, and copies the device-supplied
payload into dev->read_buf after a plain NULL check.
These two paths share read_buf, read_idx and read_len with no
serialization. If the device delays its response until the read
times out, ft260_i2c_read() resets the controller, clears read_buf
and returns, unwinding the stack frame the buffer lived in. A
response that arrives at that moment lets ft260_raw_event() pass the
NULL check and then memcpy() the device-controlled payload into the
now-freed stack location, a bounded but attacker-influenced
stack-use-after-return write triggerable by malicious or
malfunctioning hardware.
Add a dedicated spinlock that serializes every access to read_buf,
read_idx and read_len. ft260_raw_event() now holds it across the
NULL check, the memcpy and the index update, while the read path
takes it when arming and when clearing the buffer, so the teardown
can no longer slip between the check and the copy.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 6a82582d9fa438045191074856f47165334f2777 Version: 6a82582d9fa438045191074856f47165334f2777 Version: 6a82582d9fa438045191074856f47165334f2777 Version: 6a82582d9fa438045191074856f47165334f2777 Version: 6a82582d9fa438045191074856f47165334f2777 Version: 6a82582d9fa438045191074856f47165334f2777 Version: 6a82582d9fa438045191074856f47165334f2777 Version: 6a82582d9fa438045191074856f47165334f2777 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/hid/hid-ft260.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "2b907001e8a83cdb71e899fd3d77ab51e2c03f10",
"status": "affected",
"version": "6a82582d9fa438045191074856f47165334f2777",
"versionType": "git"
},
{
"lessThan": "90e9298f2e4336a0e1ca7eeb173403df78056164",
"status": "affected",
"version": "6a82582d9fa438045191074856f47165334f2777",
"versionType": "git"
},
{
"lessThan": "460514d46e8892189fc933a1b4433811cfa5c309",
"status": "affected",
"version": "6a82582d9fa438045191074856f47165334f2777",
"versionType": "git"
},
{
"lessThan": "5aa5a1b7cc4b4bec5497ad9ef113fdfe37b232f3",
"status": "affected",
"version": "6a82582d9fa438045191074856f47165334f2777",
"versionType": "git"
},
{
"lessThan": "a8e1f970f9040294cfd9100c681c32af6c2aeec0",
"status": "affected",
"version": "6a82582d9fa438045191074856f47165334f2777",
"versionType": "git"
},
{
"lessThan": "d7ffbdc076675c84128d5b904e4d5167fe9f3a7f",
"status": "affected",
"version": "6a82582d9fa438045191074856f47165334f2777",
"versionType": "git"
},
{
"lessThan": "77832d8f1c81d9f84b6b54807fb278586001d754",
"status": "affected",
"version": "6a82582d9fa438045191074856f47165334f2777",
"versionType": "git"
},
{
"lessThan": "bf3e39df3a397fd82967a31d17c4e02c7feab221",
"status": "affected",
"version": "6a82582d9fa438045191074856f47165334f2777",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/hid/hid-ft260.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.13"
},
{
"lessThan": "5.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.220",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.187",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.156",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.108",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.49",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.1",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.220",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.187",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.156",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.108",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.49",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.11",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.1",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "5.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: ft260: fix stack-use-after-return write in I2C read race\n\nft260_i2c_read() points dev-\u003eread_buf at a caller-supplied buffer\n(often an on-stack variable), arms a completion and waits up to five\nseconds for the device to return the data. The HID input callback\nft260_raw_event() runs in the input/IRQ path, independent of the\ndev-\u003elock mutex held by the read path, and copies the device-supplied\npayload into dev-\u003eread_buf after a plain NULL check.\n\nThese two paths share read_buf, read_idx and read_len with no\nserialization. If the device delays its response until the read\ntimes out, ft260_i2c_read() resets the controller, clears read_buf\nand returns, unwinding the stack frame the buffer lived in. A\nresponse that arrives at that moment lets ft260_raw_event() pass the\nNULL check and then memcpy() the device-controlled payload into the\nnow-freed stack location, a bounded but attacker-influenced\nstack-use-after-return write triggerable by malicious or\nmalfunctioning hardware.\n\nAdd a dedicated spinlock that serializes every access to read_buf,\nread_idx and read_len. ft260_raw_event() now holds it across the\nNULL check, the memcpy and the index update, while the read path\ntakes it when arming and when clearing the buffer, so the teardown\ncan no longer slip between the check and the copy."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T15:12:40.374Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/2b907001e8a83cdb71e899fd3d77ab51e2c03f10"
},
{
"url": "https://git.kernel.org/stable/c/90e9298f2e4336a0e1ca7eeb173403df78056164"
},
{
"url": "https://git.kernel.org/stable/c/460514d46e8892189fc933a1b4433811cfa5c309"
},
{
"url": "https://git.kernel.org/stable/c/5aa5a1b7cc4b4bec5497ad9ef113fdfe37b232f3"
},
{
"url": "https://git.kernel.org/stable/c/a8e1f970f9040294cfd9100c681c32af6c2aeec0"
},
{
"url": "https://git.kernel.org/stable/c/d7ffbdc076675c84128d5b904e4d5167fe9f3a7f"
},
{
"url": "https://git.kernel.org/stable/c/77832d8f1c81d9f84b6b54807fb278586001d754"
},
{
"url": "https://git.kernel.org/stable/c/bf3e39df3a397fd82967a31d17c4e02c7feab221"
}
],
"title": "HID: ft260: fix stack-use-after-return write in I2C read race",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80768",
"datePublished": "2026-09-04T15:12:40.374Z",
"dateReserved": "2026-08-26T14:34:25.791Z",
"dateUpdated": "2026-09-04T15:12:40.374Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80844 (GCVE-0-2026-80844)
Vulnerability from cvelistv5
Published
2026-09-04 15:54
Modified
2026-09-04 15:54
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
xfrm: ah6: validate routing header segments_left
AH6 rearranges routing-header addresses before computing or verifying the
ICV. ipv6_rearrange_rthdr() assumes that segments_left is not larger than
the number of addresses described by the routing header's hdrlen field.
That assumption does not hold for raw IPv6 HDRINCL packets. A packet with
hdrlen equal to 2 describes one address, but can carry an arbitrary
segments_left value. With segments_left equal to 255, the function moves
its address pointer 4,064 bytes backwards and passes a 4,064-byte length to
memmove(), resulting in an out-of-bounds access.
Validate the invariant locally before modifying the routing header or
performing any address-pointer arithmetic, and propagate malformed-header
errors to the existing AH6 input and output error paths.
References
| URL | Tags | ||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ipv6/ah6.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "2dc650956e4e163b879b3fb1027f9557abc5c985",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "48b0e36cf54358276ee7aa897034c973097d2bc9",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "1b7e066eabcc7d6d8f476c34739b45932f2f4c31",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "f00df8500e5a36ba70d336fd34bd2152ea074e5f",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "1516e31ac458a738be485620579d8f7fb2700fcb",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "6733ae71268a27d598cfb3f3339a3c950b9b656d",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "0bf11081ad3753938a2b48723ce6298dbac743a1",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "46640c814f25f096b0b0045ca50e1b7030cd8a30",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "7bad4bda74dc4713f398d3b7624ff05478e3a568",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ipv6/ah6.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.269",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.220",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.187",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.156",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.108",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.49",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.13",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.3",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.269",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.220",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.187",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.156",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.108",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.49",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.13",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.3",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: ah6: validate routing header segments_left\n\nAH6 rearranges routing-header addresses before computing or verifying the\nICV. ipv6_rearrange_rthdr() assumes that segments_left is not larger than\nthe number of addresses described by the routing header\u0027s hdrlen field.\n\nThat assumption does not hold for raw IPv6 HDRINCL packets. A packet with\nhdrlen equal to 2 describes one address, but can carry an arbitrary\nsegments_left value. With segments_left equal to 255, the function moves\nits address pointer 4,064 bytes backwards and passes a 4,064-byte length to\nmemmove(), resulting in an out-of-bounds access.\n\nValidate the invariant locally before modifying the routing header or\nperforming any address-pointer arithmetic, and propagate malformed-header\nerrors to the existing AH6 input and output error paths."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T15:54:54.295Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/2dc650956e4e163b879b3fb1027f9557abc5c985"
},
{
"url": "https://git.kernel.org/stable/c/48b0e36cf54358276ee7aa897034c973097d2bc9"
},
{
"url": "https://git.kernel.org/stable/c/1b7e066eabcc7d6d8f476c34739b45932f2f4c31"
},
{
"url": "https://git.kernel.org/stable/c/f00df8500e5a36ba70d336fd34bd2152ea074e5f"
},
{
"url": "https://git.kernel.org/stable/c/1516e31ac458a738be485620579d8f7fb2700fcb"
},
{
"url": "https://git.kernel.org/stable/c/6733ae71268a27d598cfb3f3339a3c950b9b656d"
},
{
"url": "https://git.kernel.org/stable/c/0bf11081ad3753938a2b48723ce6298dbac743a1"
},
{
"url": "https://git.kernel.org/stable/c/46640c814f25f096b0b0045ca50e1b7030cd8a30"
},
{
"url": "https://git.kernel.org/stable/c/7bad4bda74dc4713f398d3b7624ff05478e3a568"
}
],
"title": "xfrm: ah6: validate routing header segments_left",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80844",
"datePublished": "2026-09-04T15:54:54.295Z",
"dateReserved": "2026-08-26T14:34:25.796Z",
"dateUpdated": "2026-09-04T15:54:54.295Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2023-54263 (GCVE-0-2023-54263)
Vulnerability from cvelistv5
Published
2025-12-30 12:15
Modified
2026-09-02 12:49
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/nouveau/kms/nv50-: init hpd_irq_lock for PIOR DP
Fixes OOPS on boards with ANX9805 DP encoders.
References
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/nouveau/dispnv50/disp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a63fa556ac5772d004025c1164b7bd5a8b95eaef",
"status": "affected",
"version": "a0922278f83eae085fdf73d06f71bbdfb9d6789e",
"versionType": "git"
},
{
"lessThan": "92d48ce21645267c574268678131cd2b648dad0f",
"status": "affected",
"version": "a0922278f83eae085fdf73d06f71bbdfb9d6789e",
"versionType": "git"
},
{
"lessThan": "ea293f823a8805735d9e00124df81a8f448ed1ae",
"status": "affected",
"version": "a0922278f83eae085fdf73d06f71bbdfb9d6789e",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/nouveau/dispnv50/disp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.10"
},
{
"lessThan": "5.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.187",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.4.*",
"status": "unaffected",
"version": "6.4.7",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "6.5",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.187",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.4.7",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.5",
"versionStartIncluding": "5.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/nouveau/kms/nv50-: init hpd_irq_lock for PIOR DP\n\nFixes OOPS on boards with ANX9805 DP encoders."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-02T12:49:09.821Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a63fa556ac5772d004025c1164b7bd5a8b95eaef"
},
{
"url": "https://git.kernel.org/stable/c/92d48ce21645267c574268678131cd2b648dad0f"
},
{
"url": "https://git.kernel.org/stable/c/ea293f823a8805735d9e00124df81a8f448ed1ae"
}
],
"title": "drm/nouveau/kms/nv50-: init hpd_irq_lock for PIOR DP",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2023-54263",
"datePublished": "2025-12-30T12:15:56.231Z",
"dateReserved": "2025-12-30T12:06:44.517Z",
"dateUpdated": "2026-09-02T12:49:09.821Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72041 (GCVE-0-2026-72041)
Vulnerability from cvelistv5
Published
2026-08-15 05:52
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
espintcp: use sk_msg_free_partial to fix partial send
sk_msg_free_partial() ensures consistency of the skmsg at every
iteration, without having to manually handle uncharges and offsets.
This simplifies the code, and fixes some bugs in skmsg accounting when
we don't send the full contents.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: e27cca96cd68fa2c6814c90f9a1cfd36bb68c593 Version: e27cca96cd68fa2c6814c90f9a1cfd36bb68c593 Version: e27cca96cd68fa2c6814c90f9a1cfd36bb68c593 Version: e27cca96cd68fa2c6814c90f9a1cfd36bb68c593 Version: e27cca96cd68fa2c6814c90f9a1cfd36bb68c593 Version: e27cca96cd68fa2c6814c90f9a1cfd36bb68c593 Version: e27cca96cd68fa2c6814c90f9a1cfd36bb68c593 Version: e27cca96cd68fa2c6814c90f9a1cfd36bb68c593 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/xfrm/espintcp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "518dcb84b997dff461800b079e5f2596389f766a",
"status": "affected",
"version": "e27cca96cd68fa2c6814c90f9a1cfd36bb68c593",
"versionType": "git"
},
{
"lessThan": "4ea8c051b4bd7feec7749a980f2f70e1782b84d7",
"status": "affected",
"version": "e27cca96cd68fa2c6814c90f9a1cfd36bb68c593",
"versionType": "git"
},
{
"lessThan": "a977f78adce40b39d90d9567e7987bb110102810",
"status": "affected",
"version": "e27cca96cd68fa2c6814c90f9a1cfd36bb68c593",
"versionType": "git"
},
{
"lessThan": "54d73f18f8919735f4d04d6f43374f75756c0180",
"status": "affected",
"version": "e27cca96cd68fa2c6814c90f9a1cfd36bb68c593",
"versionType": "git"
},
{
"lessThan": "14c0b42c8a2cd9b5361bbff45b52f69c62c6a286",
"status": "affected",
"version": "e27cca96cd68fa2c6814c90f9a1cfd36bb68c593",
"versionType": "git"
},
{
"lessThan": "a66d45e0ce6d73cd79962d422388e61bfaf0cb50",
"status": "affected",
"version": "e27cca96cd68fa2c6814c90f9a1cfd36bb68c593",
"versionType": "git"
},
{
"lessThan": "a338ce41bc933d8f74c39d9b3b6f1d8ca53d9714",
"status": "affected",
"version": "e27cca96cd68fa2c6814c90f9a1cfd36bb68c593",
"versionType": "git"
},
{
"lessThan": "007800408002d871f5699bdb944f985896730b8f",
"status": "affected",
"version": "e27cca96cd68fa2c6814c90f9a1cfd36bb68c593",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/xfrm/espintcp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.6"
},
{
"lessThan": "5.6",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nespintcp: use sk_msg_free_partial to fix partial send\n\nsk_msg_free_partial() ensures consistency of the skmsg at every\niteration, without having to manually handle uncharges and offsets.\nThis simplifies the code, and fixes some bugs in skmsg accounting when\nwe don\u0027t send the full contents."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - espintcp carries IKE/IPsec over TCP (RFC 8229) on internet-facing VPN gateways; a remote TCP peer can induce partial sends during server outbound IKE responses by shrinking/draining the receive window, corrupting skmsg state without local access.\nAC:L - The attacker controls both sides of the TCP connection and can reliably force partial sends by not reading, advertising a zero window, or resetting mid-transfer; no race or memory-layout conditions outside attacker control are required.\nPR:N - Exploitation needs no credentials on the target\u2014an unauthenticated remote peer during pre-auth IKE-over-TCP can trigger server sends; locally any user can set TCP_ULP to espintcp and sendmsg without CAP_NET_ADMIN or XFRM configuration.\nUI:N - No victim user action is required; once an espintcp TCP endpoint exists, the remote peer alone drives the partial-send condition through normal TCP flow control during server transmission.\nS:U - Impact is kernel heap corruption and privilege escalation within the host kernel; it does not cross VM, IOMMU, or sandbox security boundaries.\nC:H - Incorrect skmsg/page accounting on partial sends causes use-after-free and double-free of scatterlist pages; freed objects can be reallocated and read for arbitrary kernel memory disclosure.\nI:H - Corrupted scatterlist offsets and page refcount errors yield exploitable kernel memory corruption primitives that can enable arbitrary writes and local privilege escalation.\nA:H - Double-free and invalid page references in the send/resume path can oops or panic the kernel; a remote or local attacker can repeat the trigger via sustained partial-send pressure."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:32.051Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/518dcb84b997dff461800b079e5f2596389f766a"
},
{
"url": "https://git.kernel.org/stable/c/4ea8c051b4bd7feec7749a980f2f70e1782b84d7"
},
{
"url": "https://git.kernel.org/stable/c/a977f78adce40b39d90d9567e7987bb110102810"
},
{
"url": "https://git.kernel.org/stable/c/54d73f18f8919735f4d04d6f43374f75756c0180"
},
{
"url": "https://git.kernel.org/stable/c/14c0b42c8a2cd9b5361bbff45b52f69c62c6a286"
},
{
"url": "https://git.kernel.org/stable/c/a66d45e0ce6d73cd79962d422388e61bfaf0cb50"
},
{
"url": "https://git.kernel.org/stable/c/a338ce41bc933d8f74c39d9b3b6f1d8ca53d9714"
},
{
"url": "https://git.kernel.org/stable/c/007800408002d871f5699bdb944f985896730b8f"
}
],
"title": "espintcp: use sk_msg_free_partial to fix partial send",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72041",
"datePublished": "2026-08-15T05:52:00.721Z",
"dateReserved": "2026-08-09T03:40:39.901Z",
"dateUpdated": "2026-08-23T12:46:32.051Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68344 (GCVE-0-2026-68344)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
usb: atm: ueagle-atm: reject descriptors that confuse probe and disconnect
uea_probe() distinguishes a pre-firmware device from a post-firmware one
using the USB id (UEA_IS_PREFIRM()), and stores a different object as the
interface data in each case: a 'struct completion' for a pre-firmware
device (to be waited on in .disconnect()), or a 'struct usbatm_data' for a
post-firmware one.
uea_disconnect() instead tells the two apart by the number of interfaces
of the active configuration (a pre-firmware device exposes a single
interface, ADI930 has 2 and eagle has 3), and casts the interface data
accordingly.
Because the two handlers use different criteria, a crafted device that
advertises a pre-firmware id together with a multi-interface descriptor
(or a post-firmware id with a single interface) makes them disagree: the
small 'struct completion' stored by uea_probe() is then passed to
usbatm_usb_disconnect(), which casts it to 'struct usbatm_data' and takes
instance->serialize, reading past the end of the allocation:
BUG: KASAN: slab-out-of-bounds in __mutex_lock+0x152a/0x1b80
Read of size 8 at addr ffff8880470e2c60 by task kworker/1:2/982
...
__mutex_lock+0x152a/0x1b80
usbatm_usb_disconnect+0x70/0x820
uea_disconnect+0x133/0x2c0
usb_unbind_interface+0x1dd/0x9e0
...
which belongs to the cache kmalloc-96 of size 96
The buggy address is located 0 bytes to the right of
allocated 96-byte region [ffff8880470e2c00, ffff8880470e2c60)
Reject such inconsistent descriptors in uea_probe() so that both handlers
always make the same pre/post-firmware decision.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d85f19aaef42a03e3e4765d659c761c8750a7f23 Version: 76861031b43a18065d13f9ffb8595d25c7576005 Version: bbfedc84714064ea4845e6b76f96316eb5bb65d8 Version: f2a6abc670104fc3e383ee3b1cf35c070485e3df Version: c581e30ae5b332d8acef64475a211b3f82099941 Version: 509b51327320bdeaef1969248177a446ded073ab Version: ddcdac47e1f2651c7be60e299f98faf981522797 Version: e2674dfbed8a30d57e2bc872c4bfa6c3eec918bf |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/atm/ueagle-atm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "9e7312844429379108ea9523a5ed934f142bb177",
"status": "affected",
"version": "d85f19aaef42a03e3e4765d659c761c8750a7f23",
"versionType": "git"
},
{
"lessThan": "f92832262718443feb4e5df2bf70424ba842629e",
"status": "affected",
"version": "76861031b43a18065d13f9ffb8595d25c7576005",
"versionType": "git"
},
{
"lessThan": "e814ae925f6f575325124c29dde518b92c822b83",
"status": "affected",
"version": "bbfedc84714064ea4845e6b76f96316eb5bb65d8",
"versionType": "git"
},
{
"lessThan": "c035b1198906dd5bd3df9a3045b59254bad1ea7a",
"status": "affected",
"version": "f2a6abc670104fc3e383ee3b1cf35c070485e3df",
"versionType": "git"
},
{
"lessThan": "9904a46401198872ab3de34fd11f383831ef3428",
"status": "affected",
"version": "c581e30ae5b332d8acef64475a211b3f82099941",
"versionType": "git"
},
{
"lessThan": "d0a57f19fe2865b9747484f5f9c631f944ed9a0f",
"status": "affected",
"version": "509b51327320bdeaef1969248177a446ded073ab",
"versionType": "git"
},
{
"lessThan": "0cc0c4c14150bb5a16b88dd61368f96cd4caa9ce",
"status": "affected",
"version": "ddcdac47e1f2651c7be60e299f98faf981522797",
"versionType": "git"
},
{
"lessThan": "71132cedd1ecbc4032d76e9928c18a10f7e39b80",
"status": "affected",
"version": "e2674dfbed8a30d57e2bc872c4bfa6c3eec918bf",
"versionType": "git"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/atm/ueagle-atm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "5.10.265",
"status": "affected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThan": "5.15.216",
"status": "affected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThan": "6.1.183",
"status": "affected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThan": "6.6.148",
"status": "affected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThan": "6.12.101",
"status": "affected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThan": "6.18.42",
"status": "affected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThan": "7.1.6",
"status": "affected",
"version": "7.1.5",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.10.261",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.15.212",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "6.1.178",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.6.145",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.12.97",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.18.40",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "7.1.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: atm: ueagle-atm: reject descriptors that confuse probe and disconnect\n\nuea_probe() distinguishes a pre-firmware device from a post-firmware one\nusing the USB id (UEA_IS_PREFIRM()), and stores a different object as the\ninterface data in each case: a \u0027struct completion\u0027 for a pre-firmware\ndevice (to be waited on in .disconnect()), or a \u0027struct usbatm_data\u0027 for a\npost-firmware one.\n\nuea_disconnect() instead tells the two apart by the number of interfaces\nof the active configuration (a pre-firmware device exposes a single\ninterface, ADI930 has 2 and eagle has 3), and casts the interface data\naccordingly.\n\nBecause the two handlers use different criteria, a crafted device that\nadvertises a pre-firmware id together with a multi-interface descriptor\n(or a post-firmware id with a single interface) makes them disagree: the\nsmall \u0027struct completion\u0027 stored by uea_probe() is then passed to\nusbatm_usb_disconnect(), which casts it to \u0027struct usbatm_data\u0027 and takes\ninstance-\u003eserialize, reading past the end of the allocation:\n\n BUG: KASAN: slab-out-of-bounds in __mutex_lock+0x152a/0x1b80\n Read of size 8 at addr ffff8880470e2c60 by task kworker/1:2/982\n ...\n __mutex_lock+0x152a/0x1b80\n usbatm_usb_disconnect+0x70/0x820\n uea_disconnect+0x133/0x2c0\n usb_unbind_interface+0x1dd/0x9e0\n ...\n which belongs to the cache kmalloc-96 of size 96\n The buggy address is located 0 bytes to the right of\n allocated 96-byte region [ffff8880470e2c00, ffff8880470e2c60)\n\nReject such inconsistent descriptors in uea_probe() so that both handlers\nalways make the same pre/post-firmware decision."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:45.376Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/9e7312844429379108ea9523a5ed934f142bb177"
},
{
"url": "https://git.kernel.org/stable/c/f92832262718443feb4e5df2bf70424ba842629e"
},
{
"url": "https://git.kernel.org/stable/c/e814ae925f6f575325124c29dde518b92c822b83"
},
{
"url": "https://git.kernel.org/stable/c/c035b1198906dd5bd3df9a3045b59254bad1ea7a"
},
{
"url": "https://git.kernel.org/stable/c/9904a46401198872ab3de34fd11f383831ef3428"
},
{
"url": "https://git.kernel.org/stable/c/d0a57f19fe2865b9747484f5f9c631f944ed9a0f"
},
{
"url": "https://git.kernel.org/stable/c/0cc0c4c14150bb5a16b88dd61368f96cd4caa9ce"
},
{
"url": "https://git.kernel.org/stable/c/71132cedd1ecbc4032d76e9928c18a10f7e39b80"
}
],
"title": "usb: atm: ueagle-atm: reject descriptors that confuse probe and disconnect",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68344",
"datePublished": "2026-08-10T12:03:20.917Z",
"dateReserved": "2026-07-30T09:28:09.384Z",
"dateUpdated": "2026-08-19T16:33:45.376Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74436 (GCVE-0-2026-74436)
Vulnerability from cvelistv5
Published
2026-08-15 05:59
Modified
2026-08-23 12:47
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
rxrpc: serialize kernel accept preallocation with socket teardown
rxrpc_kernel_charge_accept() reads rx->backlog without any
socket/backlog synchronization and passes that raw pointer into
rxrpc_service_prealloc_one(). A concurrent rxrpc_discard_prealloc()
sets rx->backlog = NULL and frees the backlog rings, so a kernel
preallocation worker can keep using a freed struct rxrpc_backlog
while updating *_backlog_head/tail and array slots.
Serialize the state check and backlog lookup with the socket lock,
and reject kernel preallocation once teardown has disabled
listening or discarded the service backlog.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 00e907127e6f86d0f9b122d9b4347a8aa09a8b61 Version: 00e907127e6f86d0f9b122d9b4347a8aa09a8b61 Version: 00e907127e6f86d0f9b122d9b4347a8aa09a8b61 Version: 00e907127e6f86d0f9b122d9b4347a8aa09a8b61 Version: 00e907127e6f86d0f9b122d9b4347a8aa09a8b61 Version: 00e907127e6f86d0f9b122d9b4347a8aa09a8b61 Version: 00e907127e6f86d0f9b122d9b4347a8aa09a8b61 Version: 00e907127e6f86d0f9b122d9b4347a8aa09a8b61 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/rxrpc/call_accept.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "d6207326b4ca0ae1041281b6af9df53f8080669a",
"status": "affected",
"version": "00e907127e6f86d0f9b122d9b4347a8aa09a8b61",
"versionType": "git"
},
{
"lessThan": "11b429b84c87cb5a0152f14e7d6cb649ed363901",
"status": "affected",
"version": "00e907127e6f86d0f9b122d9b4347a8aa09a8b61",
"versionType": "git"
},
{
"lessThan": "c20d983968f239574290cf804a58cde18ad1c559",
"status": "affected",
"version": "00e907127e6f86d0f9b122d9b4347a8aa09a8b61",
"versionType": "git"
},
{
"lessThan": "0337cdba0c477f176c0459bed012109453184573",
"status": "affected",
"version": "00e907127e6f86d0f9b122d9b4347a8aa09a8b61",
"versionType": "git"
},
{
"lessThan": "dfa0b2bbc5e50119f89c6b5407faa5ed86dfa7c5",
"status": "affected",
"version": "00e907127e6f86d0f9b122d9b4347a8aa09a8b61",
"versionType": "git"
},
{
"lessThan": "35a967ff8b24db09ee429c39c5b5e6571639997d",
"status": "affected",
"version": "00e907127e6f86d0f9b122d9b4347a8aa09a8b61",
"versionType": "git"
},
{
"lessThan": "1741378a7a83dfd8e53a9196730df709b903cd33",
"status": "affected",
"version": "00e907127e6f86d0f9b122d9b4347a8aa09a8b61",
"versionType": "git"
},
{
"lessThan": "dc175389b18c29a5303ee83169ec653adfae3e17",
"status": "affected",
"version": "00e907127e6f86d0f9b122d9b4347a8aa09a8b61",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/rxrpc/call_accept.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.9"
},
{
"lessThan": "4.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nrxrpc: serialize kernel accept preallocation with socket teardown\n\nrxrpc_kernel_charge_accept() reads rx-\u003ebacklog without any\nsocket/backlog synchronization and passes that raw pointer into\nrxrpc_service_prealloc_one(). A concurrent rxrpc_discard_prealloc()\nsets rx-\u003ebacklog = NULL and frees the backlog rings, so a kernel\npreallocation worker can keep using a freed struct rxrpc_backlog\nwhile updating *_backlog_head/tail and array slots.\n\nSerialize the state check and backlog lookup with the socket lock,\nand reject kernel preallocation once teardown has disabled\nlistening or discarded the service backlog."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - RxRPC is a UDP network protocol; remote peers can send packets to AFS callback-manager listeners (port 7001) that instantiate incoming calls and queue kernel preallocation work reaching rxrpc_kernel_charge_accept().\nAC:L - The attacker controls the preallocation side by flooding concurrent rxrpc/AFS callback traffic while a peer thread tears down the same socket via listen(0), shutdown, or close during AFS netns exit, creating a winnable race.\nPR:N - No local account, capability, or authentication is required to reach the vulnerable preallocation path; any remote host that can deliver rxrpc/UDP packets to a listening AFS callback manager can drive the charge_accept worker.\nUI:N - Exploitation requires no victim interaction beyond normal background AFS service operation; the attacker triggers the bug purely through network traffic timed against automatic or administrative socket teardown.\nS:U - The use-after-free corrupts kernel heap metadata and rxrpc backlog structures within kernel memory, enabling local privilege escalation but not crossing a VM, container, or IOMMU security boundary by itself.\nC:H - Concurrent use of a freed struct rxrpc_backlog allows reads and corruption of recycled slab memory, providing a standard kmalloc UAF primitive that can leak kernel pointers and sensitive data.\nI:H - The race writes peer, connection, and call pointers plus head/tail indices into freed backlog ring slots, enabling heap grooming and arbitrary kernel memory corruption exploitable for code execution.\nA:H - Use-after-free on the backlog structure during concurrent head/tail and pointer-array updates can cause kernel oops, panic, or hang, and repeated triggering enables sustained denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:47:16.782Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/d6207326b4ca0ae1041281b6af9df53f8080669a"
},
{
"url": "https://git.kernel.org/stable/c/11b429b84c87cb5a0152f14e7d6cb649ed363901"
},
{
"url": "https://git.kernel.org/stable/c/c20d983968f239574290cf804a58cde18ad1c559"
},
{
"url": "https://git.kernel.org/stable/c/0337cdba0c477f176c0459bed012109453184573"
},
{
"url": "https://git.kernel.org/stable/c/dfa0b2bbc5e50119f89c6b5407faa5ed86dfa7c5"
},
{
"url": "https://git.kernel.org/stable/c/35a967ff8b24db09ee429c39c5b5e6571639997d"
},
{
"url": "https://git.kernel.org/stable/c/1741378a7a83dfd8e53a9196730df709b903cd33"
},
{
"url": "https://git.kernel.org/stable/c/dc175389b18c29a5303ee83169ec653adfae3e17"
}
],
"title": "rxrpc: serialize kernel accept preallocation with socket teardown",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74436",
"datePublished": "2026-08-15T05:59:34.687Z",
"dateReserved": "2026-08-15T05:44:03.896Z",
"dateUpdated": "2026-08-23T12:47:16.782Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72191 (GCVE-0-2026-72191)
Vulnerability from cvelistv5
Published
2026-08-15 05:53
Modified
2026-08-23 12:47
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ntfs3: validate split-point offset in indx_insert_into_buffer
indx_insert_into_buffer() computes
used = used1 - to_copy - sp_size;
memmove(de_t, Add2Ptr(sp, sp_size), used - le32_to_cpu(hdr1->de_off));
where sp and sp_size come from hdr_find_split(). hdr_find_split()
walks entries by le16_to_cpu(e->size) without validating that each
step stays within hdr->used or that the size field is at least
sizeof(struct NTFS_DE). index_hdr_check(), the on-load gatekeeper,
only validates header-level fields (used, total, de_off) and does
not walk per-entry sizes.
A crafted NTFS image whose leaf INDEX_HDR reports used == total but
contains one interior NTFS_DE with size = 0xFFF0 therefore passes
validation, descends to indx_insert_into_buffer() through the
ntfs_create() -> indx_insert_entry() path, and makes hdr_find_split()
return an sp whose sp_size (0xFFF0) greatly exceeds the remaining
bytes in the buffer. The u32 subtraction underflows and the memmove
count becomes a near-4-GiB value, producing an out-of-bounds kernel
write that corrupts adjacent allocations and panics the kernel.
Reproduced on 7.0.0-rc7 with UML + KASAN via a crafted image and a
single 'touch' inside the mounted directory; crash site resolves to
fs/ntfs3/index.c at the memmove. Trigger requires only local mount
of an attacker-supplied filesystem image (USB, loopback, or removable
media auto-mount).
Reject the split whenever the chosen sp plus its declared size
already extends past hdr1->used. This is the minimal fix; it
preserves the existing hdr_find_split() contract and relies on the
same out: cleanup path as the pre-existing error returns.
A prior OOB read in the very same indx_insert_into_buffer() memmove
was fixed in commit b8c44949044e ("fs/ntfs3: Fix OOB read in
indx_insert_into_buffer") by tightening hdr_find_e(), but that fix
does not cover the split-point size field path addressed here: sp is
returned by hdr_find_split(), not hdr_find_e(), and the underflow is
driven by sp->size rather than hdr->used exceeding hdr->total.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 82cae269cfa953032fbb8980a7d554d60fb00b17 Version: 82cae269cfa953032fbb8980a7d554d60fb00b17 Version: 82cae269cfa953032fbb8980a7d554d60fb00b17 Version: 82cae269cfa953032fbb8980a7d554d60fb00b17 Version: 82cae269cfa953032fbb8980a7d554d60fb00b17 Version: 82cae269cfa953032fbb8980a7d554d60fb00b17 Version: 82cae269cfa953032fbb8980a7d554d60fb00b17 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/ntfs3/index.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "8e4ba5a38c155bb3c1c11e63cd285b178cdb099e",
"status": "affected",
"version": "82cae269cfa953032fbb8980a7d554d60fb00b17",
"versionType": "git"
},
{
"lessThan": "4c2f648139a0a86f4486170f72e24fedd4fae74e",
"status": "affected",
"version": "82cae269cfa953032fbb8980a7d554d60fb00b17",
"versionType": "git"
},
{
"lessThan": "b232eb5c9fe11ec2368e9b565db69c724c35fbd2",
"status": "affected",
"version": "82cae269cfa953032fbb8980a7d554d60fb00b17",
"versionType": "git"
},
{
"lessThan": "7bf74e6baf810fe325f111996496c678fc6e244f",
"status": "affected",
"version": "82cae269cfa953032fbb8980a7d554d60fb00b17",
"versionType": "git"
},
{
"lessThan": "f3624cc069195001c88df7a291af215f2133ff2c",
"status": "affected",
"version": "82cae269cfa953032fbb8980a7d554d60fb00b17",
"versionType": "git"
},
{
"lessThan": "1758a564b6ebe7f4a82f23c9851d1cae15549457",
"status": "affected",
"version": "82cae269cfa953032fbb8980a7d554d60fb00b17",
"versionType": "git"
},
{
"lessThan": "f1df9d771df47aa40de6d70949c28720ae1e430d",
"status": "affected",
"version": "82cae269cfa953032fbb8980a7d554d60fb00b17",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/ntfs3/index.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.15"
},
{
"lessThan": "5.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nntfs3: validate split-point offset in indx_insert_into_buffer\n\nindx_insert_into_buffer() computes\n\n used = used1 - to_copy - sp_size;\n memmove(de_t, Add2Ptr(sp, sp_size), used - le32_to_cpu(hdr1-\u003ede_off));\n\nwhere sp and sp_size come from hdr_find_split(). hdr_find_split()\nwalks entries by le16_to_cpu(e-\u003esize) without validating that each\nstep stays within hdr-\u003eused or that the size field is at least\nsizeof(struct NTFS_DE). index_hdr_check(), the on-load gatekeeper,\nonly validates header-level fields (used, total, de_off) and does\nnot walk per-entry sizes.\n\nA crafted NTFS image whose leaf INDEX_HDR reports used == total but\ncontains one interior NTFS_DE with size = 0xFFF0 therefore passes\nvalidation, descends to indx_insert_into_buffer() through the\nntfs_create() -\u003e indx_insert_entry() path, and makes hdr_find_split()\nreturn an sp whose sp_size (0xFFF0) greatly exceeds the remaining\nbytes in the buffer. The u32 subtraction underflows and the memmove\ncount becomes a near-4-GiB value, producing an out-of-bounds kernel\nwrite that corrupts adjacent allocations and panics the kernel.\n\nReproduced on 7.0.0-rc7 with UML + KASAN via a crafted image and a\nsingle \u0027touch\u0027 inside the mounted directory; crash site resolves to\nfs/ntfs3/index.c at the memmove. Trigger requires only local mount\nof an attacker-supplied filesystem image (USB, loopback, or removable\nmedia auto-mount).\n\nReject the split whenever the chosen sp plus its declared size\nalready extends past hdr1-\u003eused. This is the minimal fix; it\npreserves the existing hdr_find_split() contract and relies on the\nsame out: cleanup path as the pre-existing error returns.\n\nA prior OOB read in the very same indx_insert_into_buffer() memmove\nwas fixed in commit b8c44949044e (\"fs/ntfs3: Fix OOB read in\nindx_insert_into_buffer\") by tightening hdr_find_e(), but that fix\ndoes not cover the split-point size field path addressed here: sp is\nreturned by hdr_find_split(), not hdr_find_e(), and the underflow is\ndriven by sp-\u003esize rather than hdr-\u003eused exceeding hdr-\u003etotal."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - Remote SMB CREATE via ksmbd vfs_create on an ntfs3-exported share reaches ntfs_create_inode\u2192indx_insert_entry\u2192indx_insert_into_buffer; the same memmove path is also reachable locally via open(O_CREAT)/touch on a mounted crafted image.\nAC:L - The attacker fully controls the on-disk leaf INDEX_HDR and NTFS_DE size (e.g. 0xFFF0); once the buffer is full and a create forces a split, hdr_find_split() deterministically selects the bad entry and the u32 underflow yields a reliable near-4GiB OOB memmove with no race.\nPR:N - Exploitation requires only a crafted NTFS image and a create in the malicious directory\u2014no root on the target\u2014via udisks2/systemd automount of attacker USB media, or a remote ksmbd client with guest/anonymous write access to an already-mounted ntfs3 export.\nUI:N - After the crafted volume is mounted (automounter or admin), a single attacker-initiated touch/create or remote SMB CREATE in the prepared full directory triggers the split and OOB memmove without any further victim clicks, prompts, or confirmation.\nS:U - The OOB memmove corrupts kernel heap memory within the same host OS security domain as ntfs3; it can enable local privilege escalation but does not cross a VM/hypervisor, IOMMU, or container sandbox boundary.\nC:H - The underflowed memmove length reads far beyond the kmalloc\u0027d index buffer from attacker-controlled on-disk bytes, giving a large out-of-bounds kernel heap read and disclosure/corruption primitive in addition to the write side.\nI:H - The same memmove performs a massive out-of-bounds kernel heap write of adjacent slab objects with attacker-influenced source data, enabling arbitrary memory corruption and potential control-flow hijack beyond a simple denial of service.\nA:H - Reproduced on 7.0.0-rc7 with KASAN: the oversized memmove corrupts adjacent allocations and panics the kernel at fs/ntfs3/index.c; even failed exploitation attempts typically cause oops or hard lockup from the unbounded copy."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:47:01.444Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/8e4ba5a38c155bb3c1c11e63cd285b178cdb099e"
},
{
"url": "https://git.kernel.org/stable/c/4c2f648139a0a86f4486170f72e24fedd4fae74e"
},
{
"url": "https://git.kernel.org/stable/c/b232eb5c9fe11ec2368e9b565db69c724c35fbd2"
},
{
"url": "https://git.kernel.org/stable/c/7bf74e6baf810fe325f111996496c678fc6e244f"
},
{
"url": "https://git.kernel.org/stable/c/f3624cc069195001c88df7a291af215f2133ff2c"
},
{
"url": "https://git.kernel.org/stable/c/1758a564b6ebe7f4a82f23c9851d1cae15549457"
},
{
"url": "https://git.kernel.org/stable/c/f1df9d771df47aa40de6d70949c28720ae1e430d"
}
],
"title": "ntfs3: validate split-point offset in indx_insert_into_buffer",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72191",
"datePublished": "2026-08-15T05:53:51.893Z",
"dateReserved": "2026-08-09T03:40:39.911Z",
"dateUpdated": "2026-08-23T12:47:01.444Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74472 (GCVE-0-2026-74472)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-19 16:37
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ublk: reset kernel-owned dev_info fields in ublk_ctrl_add_dev()
ublk_ctrl_add_dev() memcpy()s the userspace ublksrv_ctrl_dev_info into
ub->dev_info and then fixes up the fields the driver owns, but misses
->state and ->ublksrv_pid.
A device added with ->state = UBLK_S_DEV_LIVE passes the
"->state != UBLK_S_DEV_DEAD" test that ublk_stop_dev_unlocked() uses as its
proxy for "a disk is attached", while ->ub_disk is still NULL, so DEL_DEV
right after ADD_DEV oopses in del_gendisk(). UBLK_S_DEV_QUIESCED plus
UBLK_F_USER_RECOVERY dies one step earlier, in ublk_force_abort_dev(). A
poisoned ->state also gets START_USER_RECOVERY and the char device
read/write path onto a device that was never started, and wedges START_DEV
at -EEXIST. A poisoned ->ublksrv_pid just makes GET_DEV_INFO report an
unrelated task as the ublk server.
Reset both after the memcpy(), as ublk_detach_disk() does. Userspace only
ever reads these back, so correcting them silently breaks nothing.
ADD_DEV has copied ->state in unsanitized since ublk was merged, but back
then it was harmless: the gendisk was allocated during ADD_DEV, and both
teardown and the START_DEV -EEXIST check keyed off disk_live() rather than
->state. The oops became reachable once the disk allocation moved to
START_DEV and those checks switched to ->state.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 6d9e6dfdf3b207701471f364121c67eefb000682 Version: 6d9e6dfdf3b207701471f364121c67eefb000682 Version: 6d9e6dfdf3b207701471f364121c67eefb000682 Version: 6d9e6dfdf3b207701471f364121c67eefb000682 Version: 6d9e6dfdf3b207701471f364121c67eefb000682 Version: 6d9e6dfdf3b207701471f364121c67eefb000682 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/block/ublk_drv.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "787c944502e7e63d20a9201bada77e0dd924f458",
"status": "affected",
"version": "6d9e6dfdf3b207701471f364121c67eefb000682",
"versionType": "git"
},
{
"lessThan": "ee41b00858ca65b4428e99efe39a4277c1f043d2",
"status": "affected",
"version": "6d9e6dfdf3b207701471f364121c67eefb000682",
"versionType": "git"
},
{
"lessThan": "b67ce16b26ad0f14cfd6071013840aa95f823bea",
"status": "affected",
"version": "6d9e6dfdf3b207701471f364121c67eefb000682",
"versionType": "git"
},
{
"lessThan": "205feb72e5beb3140e4e1403b6cff30cf739bab9",
"status": "affected",
"version": "6d9e6dfdf3b207701471f364121c67eefb000682",
"versionType": "git"
},
{
"lessThan": "127033b79383a3e78361d7e971588aa8849f5124",
"status": "affected",
"version": "6d9e6dfdf3b207701471f364121c67eefb000682",
"versionType": "git"
},
{
"lessThan": "e65848e4ce352bac9e3465099354c8b8f845391f",
"status": "affected",
"version": "6d9e6dfdf3b207701471f364121c67eefb000682",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/block/ublk_drv.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.0"
},
{
"lessThan": "6.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nublk: reset kernel-owned dev_info fields in ublk_ctrl_add_dev()\n\nublk_ctrl_add_dev() memcpy()s the userspace ublksrv_ctrl_dev_info into\nub-\u003edev_info and then fixes up the fields the driver owns, but misses\n-\u003estate and -\u003eublksrv_pid.\n\nA device added with -\u003estate = UBLK_S_DEV_LIVE passes the\n\"-\u003estate != UBLK_S_DEV_DEAD\" test that ublk_stop_dev_unlocked() uses as its\nproxy for \"a disk is attached\", while -\u003eub_disk is still NULL, so DEL_DEV\nright after ADD_DEV oopses in del_gendisk(). UBLK_S_DEV_QUIESCED plus\nUBLK_F_USER_RECOVERY dies one step earlier, in ublk_force_abort_dev(). A\npoisoned -\u003estate also gets START_USER_RECOVERY and the char device\nread/write path onto a device that was never started, and wedges START_DEV\nat -EEXIST. A poisoned -\u003eublksrv_pid just makes GET_DEV_INFO report an\nunrelated task as the ublk server.\n\nReset both after the memcpy(), as ublk_detach_disk() does. Userspace only\never reads these back, so correcting them silently breaks nothing.\n\nADD_DEV has copied -\u003estate in unsanitized since ublk was merged, but back\nthen it was harmless: the gendisk was allocated during ADD_DEV, and both\nteardown and the START_DEV -EEXIST check keyed off disk_live() rather than\n-\u003estate. The oops became reachable once the disk allocation moved to\nSTART_DEV and those checks switched to -\u003estate."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:37:23.182Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/787c944502e7e63d20a9201bada77e0dd924f458"
},
{
"url": "https://git.kernel.org/stable/c/ee41b00858ca65b4428e99efe39a4277c1f043d2"
},
{
"url": "https://git.kernel.org/stable/c/b67ce16b26ad0f14cfd6071013840aa95f823bea"
},
{
"url": "https://git.kernel.org/stable/c/205feb72e5beb3140e4e1403b6cff30cf739bab9"
},
{
"url": "https://git.kernel.org/stable/c/127033b79383a3e78361d7e971588aa8849f5124"
},
{
"url": "https://git.kernel.org/stable/c/e65848e4ce352bac9e3465099354c8b8f845391f"
}
],
"title": "ublk: reset kernel-owned dev_info fields in ublk_ctrl_add_dev()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74472",
"datePublished": "2026-08-15T12:27:08.759Z",
"dateReserved": "2026-08-15T05:44:03.902Z",
"dateUpdated": "2026-08-19T16:37:23.182Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72040 (GCVE-0-2026-72040)
Vulnerability from cvelistv5
Published
2026-08-15 05:51
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ipmi: fix refcount leak in i_ipmi_request()
When a caller provides a `supplied_recv` message to i_ipmi_request(),
the function increments the user's `nr_msgs` reference count. If an
error occurs later, the out_err cleanup path only frees the recv_msg
if the function allocated it itself (i.e., !supplied_recv). In the
supplied_recv case the cleanup is skipped, leaving the reference count
elevated. The caller ipmi_request_supply_msgs() does not release the
supplied_recv on error, so the reference is permanently leaked.
Fix this by explicitly reverting the reference count operations when a
supplied recv_msg with a valid user pointer is present in the error
path: decrement nr_msgs and drop the user's kref.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: f63723ca7d7623f9dae1990973cd158671f03c56 Version: 348121b29594d42d1635648fd3ed31dfa25351d5 Version: 53d6e403affbf6df2c859a0ea00ccfc1e72090ca Version: b52da4054ee0bf9ecb44996f2c83236ff50b3812 Version: b52da4054ee0bf9ecb44996f2c83236ff50b3812 Version: b52da4054ee0bf9ecb44996f2c83236ff50b3812 Version: 0ed73be9a2547ffb9b5c1d879ad9bfab73d920b5 Version: 6.1.157 ≤ Version: 6.6.113 ≤ Version: 6.12.54 ≤ Version: 6.17.4 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/char/ipmi/ipmi_msghandler.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "122ca6b2af714e114c9b872a48372ace31a9ab1f",
"status": "affected",
"version": "f63723ca7d7623f9dae1990973cd158671f03c56",
"versionType": "git"
},
{
"lessThan": "9409e18ffe7378d202efe1cf69989df9f67b0369",
"status": "affected",
"version": "348121b29594d42d1635648fd3ed31dfa25351d5",
"versionType": "git"
},
{
"lessThan": "e2a3b77df6aef031455dd83ea8ed4344b7dca1f9",
"status": "affected",
"version": "53d6e403affbf6df2c859a0ea00ccfc1e72090ca",
"versionType": "git"
},
{
"lessThan": "f5c5065963024390ddad51bd455d1adc710de575",
"status": "affected",
"version": "b52da4054ee0bf9ecb44996f2c83236ff50b3812",
"versionType": "git"
},
{
"lessThan": "0fd23994ec8c5436d9f0b50848deb87ed933e6b3",
"status": "affected",
"version": "b52da4054ee0bf9ecb44996f2c83236ff50b3812",
"versionType": "git"
},
{
"lessThan": "a3f3859cecacb64f18fd446271ece9a3b3f2d4de",
"status": "affected",
"version": "b52da4054ee0bf9ecb44996f2c83236ff50b3812",
"versionType": "git"
},
{
"status": "affected",
"version": "0ed73be9a2547ffb9b5c1d879ad9bfab73d920b5",
"versionType": "git"
},
{
"lessThan": "6.1.184",
"status": "affected",
"version": "6.1.157",
"versionType": "semver"
},
{
"lessThan": "6.6.148",
"status": "affected",
"version": "6.6.113",
"versionType": "semver"
},
{
"lessThan": "6.12.101",
"status": "affected",
"version": "6.12.54",
"versionType": "semver"
},
{
"lessThan": "6.18",
"status": "affected",
"version": "6.17.4",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/char/ipmi/ipmi_msghandler.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.18"
},
{
"lessThan": "6.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "6.1.157",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.6.113",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.12.54",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "6.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "6.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.17.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nipmi: fix refcount leak in i_ipmi_request()\n\nWhen a caller provides a `supplied_recv` message to i_ipmi_request(),\nthe function increments the user\u0027s `nr_msgs` reference count. If an\nerror occurs later, the out_err cleanup path only frees the recv_msg\nif the function allocated it itself (i.e., !supplied_recv). In the\nsupplied_recv case the cleanup is skipped, leaving the reference count\nelevated. The caller ipmi_request_supply_msgs() does not release the\nsupplied_recv on error, so the reference is permanently leaked.\n\nFix this by explicitly reverting the reference count operations when a\nsupplied recv_msg with a valid user pointer is present in the error\npath: decrement nr_msgs and drop the user\u0027s kref."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:30.954Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/122ca6b2af714e114c9b872a48372ace31a9ab1f"
},
{
"url": "https://git.kernel.org/stable/c/9409e18ffe7378d202efe1cf69989df9f67b0369"
},
{
"url": "https://git.kernel.org/stable/c/e2a3b77df6aef031455dd83ea8ed4344b7dca1f9"
},
{
"url": "https://git.kernel.org/stable/c/f5c5065963024390ddad51bd455d1adc710de575"
},
{
"url": "https://git.kernel.org/stable/c/0fd23994ec8c5436d9f0b50848deb87ed933e6b3"
},
{
"url": "https://git.kernel.org/stable/c/a3f3859cecacb64f18fd446271ece9a3b3f2d4de"
}
],
"title": "ipmi: fix refcount leak in i_ipmi_request()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72040",
"datePublished": "2026-08-15T05:51:59.975Z",
"dateReserved": "2026-08-09T03:40:39.901Z",
"dateUpdated": "2026-08-23T12:46:30.954Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68406 (GCVE-0-2026-68406)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: cfg80211: validate PMSR FTM preamble range
PMSR FTM request parsing accepts preamble values outside the
enumerated nl80211 preamble range.
Reject out-of-range values before using them in the parser capability
bit test using the policy.
[drop unnecessary check]
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 9bb7e0f24e7e7d00daa1219b14539e2e602649b2 Version: 9bb7e0f24e7e7d00daa1219b14539e2e602649b2 Version: 9bb7e0f24e7e7d00daa1219b14539e2e602649b2 Version: 9bb7e0f24e7e7d00daa1219b14539e2e602649b2 Version: 9bb7e0f24e7e7d00daa1219b14539e2e602649b2 Version: 9bb7e0f24e7e7d00daa1219b14539e2e602649b2 Version: 9bb7e0f24e7e7d00daa1219b14539e2e602649b2 Version: 9bb7e0f24e7e7d00daa1219b14539e2e602649b2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/wireless/nl80211.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "73ada9f23c2c7fac74474ea2a38ceb265bae17f1",
"status": "affected",
"version": "9bb7e0f24e7e7d00daa1219b14539e2e602649b2",
"versionType": "git"
},
{
"lessThan": "2b97fa1bce7731f6a244f3d4407c61858f09b93f",
"status": "affected",
"version": "9bb7e0f24e7e7d00daa1219b14539e2e602649b2",
"versionType": "git"
},
{
"lessThan": "9b33f260db3971f572dda0b45dd28d477cf51ed1",
"status": "affected",
"version": "9bb7e0f24e7e7d00daa1219b14539e2e602649b2",
"versionType": "git"
},
{
"lessThan": "44ea65d779e2d23b2264fea6af2d0c666a3ec9fb",
"status": "affected",
"version": "9bb7e0f24e7e7d00daa1219b14539e2e602649b2",
"versionType": "git"
},
{
"lessThan": "922d71fbaf99c1d5318151a0cb0a42ad448d07d9",
"status": "affected",
"version": "9bb7e0f24e7e7d00daa1219b14539e2e602649b2",
"versionType": "git"
},
{
"lessThan": "cfbda103aeae61071a122a6fc2bfe98cffbd7165",
"status": "affected",
"version": "9bb7e0f24e7e7d00daa1219b14539e2e602649b2",
"versionType": "git"
},
{
"lessThan": "58320cb47df2accc7a20bb72c0150280732fa58f",
"status": "affected",
"version": "9bb7e0f24e7e7d00daa1219b14539e2e602649b2",
"versionType": "git"
},
{
"lessThan": "36230936468f0ba4930e94aef496fc229d4bb951",
"status": "affected",
"version": "9bb7e0f24e7e7d00daa1219b14539e2e602649b2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/wireless/nl80211.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.0"
},
{
"lessThan": "5.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: cfg80211: validate PMSR FTM preamble range\n\nPMSR FTM request parsing accepts preamble values outside the\nenumerated nl80211 preamble range.\n\nReject out-of-range values before using them in the parser capability\nbit test using the policy.\n\n[drop unnecessary check]"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:59.823Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/73ada9f23c2c7fac74474ea2a38ceb265bae17f1"
},
{
"url": "https://git.kernel.org/stable/c/2b97fa1bce7731f6a244f3d4407c61858f09b93f"
},
{
"url": "https://git.kernel.org/stable/c/9b33f260db3971f572dda0b45dd28d477cf51ed1"
},
{
"url": "https://git.kernel.org/stable/c/44ea65d779e2d23b2264fea6af2d0c666a3ec9fb"
},
{
"url": "https://git.kernel.org/stable/c/922d71fbaf99c1d5318151a0cb0a42ad448d07d9"
},
{
"url": "https://git.kernel.org/stable/c/cfbda103aeae61071a122a6fc2bfe98cffbd7165"
},
{
"url": "https://git.kernel.org/stable/c/58320cb47df2accc7a20bb72c0150280732fa58f"
},
{
"url": "https://git.kernel.org/stable/c/36230936468f0ba4930e94aef496fc229d4bb951"
}
],
"title": "wifi: cfg80211: validate PMSR FTM preamble range",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68406",
"datePublished": "2026-08-10T12:04:26.251Z",
"dateReserved": "2026-07-30T09:28:09.390Z",
"dateUpdated": "2026-08-19T16:34:59.823Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68427 (GCVE-0-2026-68427)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-19 16:35
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings
__host1x_bo_unpin() drops the last reference to the mapping and frees
it, so we can't dereference mapping afterwards. The cache itself
outlives the mapping, so use the cache local variable instead.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: af755456299d44e4ed6af3b7c70a7f03ea37fdf1 Version: 71c017b3f83ff72638f2a1b1d6d4e7bc61d30231 Version: 0e9dd7cfb9986b78cc81eca126ccfbf57f4c0602 Version: 8c0d3cf0d5108c96317e0eca92b60dd368867cef Version: df63c76f9c8d881ca7bce1aecfba512328d0527d Version: 3cbf5e3c46e66d9b3b6b91099bb720c6cb1be3bc |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/host1x/bus.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "86a9bd8c8f422d5f3079da31e151868902fcc702",
"status": "affected",
"version": "af755456299d44e4ed6af3b7c70a7f03ea37fdf1",
"versionType": "git"
},
{
"lessThan": "abeff53233b984571b87582bb588b4b38ef4ea50",
"status": "affected",
"version": "71c017b3f83ff72638f2a1b1d6d4e7bc61d30231",
"versionType": "git"
},
{
"lessThan": "5b7e5f84d3d4cea10c3764d2da274810a7934228",
"status": "affected",
"version": "0e9dd7cfb9986b78cc81eca126ccfbf57f4c0602",
"versionType": "git"
},
{
"lessThan": "5f4de3c717d34a24d555af581947742980778c02",
"status": "affected",
"version": "8c0d3cf0d5108c96317e0eca92b60dd368867cef",
"versionType": "git"
},
{
"lessThan": "b773faa32b0a98c3eb2b50d96de631681e5d1157",
"status": "affected",
"version": "df63c76f9c8d881ca7bce1aecfba512328d0527d",
"versionType": "git"
},
{
"lessThan": "266cddf7bd0f6c79b6c0633aef742a22bf70265b",
"status": "affected",
"version": "3cbf5e3c46e66d9b3b6b91099bb720c6cb1be3bc",
"versionType": "git"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/host1x/bus.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "6.1.183",
"status": "affected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThan": "6.6.148",
"status": "affected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThan": "6.12.101",
"status": "affected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThan": "6.18.42",
"status": "affected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThan": "7.1.6",
"status": "affected",
"version": "7.1.5",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "6.1.178",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.6.145",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.12.97",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.18.40",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "7.1.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ngpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings\n\n__host1x_bo_unpin() drops the last reference to the mapping and frees\nit, so we can\u0027t dereference mapping afterwards. The cache itself\noutlives the mapping, so use the cache local variable instead."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable path is reached only through the Tegra DRM/KMS device node (/dev/dri/card0): a local process pins a GEM buffer as a scanout framebuffer via an atomic commit and then destroys the handle, invoking tegra_bo_free_object() -\u003e host1x_bo_clear_cached_mappings(). No network or remote input reaches this code.\nAC:L - The use-after-free is unconditional and deterministic \u2014 every cached mapping freed by host1x_bo_clear_cached_mappings() is dereferenced again for the mutex_unlock. No race must be won and no special memory layout is needed; the attacker fully controls buffer creation, scanout pinning, and the destroy that triggers the free.\nPR:L - An unprivileged local user with access to the Tegra DRM device (video/graphics group, the logged-in console/compositor user on Android, automotive and embedded Tegra systems) can create GEM buffers, present them on a plane and free them. No root or CAP_SYS_ADMIN is required.\nUI:N - The attacking process performs the whole sequence itself \u2014 GEM allocation, atomic plane commit, and handle destruction \u2014 with no action by any other user or victim process.\nS:U - The corruption stays within the kernel\u0027s own memory and security authority; there is no crossing into another VM, IOMMU domain, or sandbox boundary.\nC:H - The freed host1x_bo_mapping is read after kfree() to obtain the cache pointer; with slab reuse the attacker can groom the freed object so the read returns attacker-influenced data, and the resulting UAF primitive can be leveraged to disclose kernel memory contents.\nI:H - mutex_unlock() writes to the lock word at the address read from freed memory, so a reallocated/poisoned mapping object yields a write through an attacker-influenceable pointer \u2014 a classic UAF write primitive usable for heap corruption and control-flow hijacking.\nA:H - Dereferencing the freed mapping reliably oopses under slab poisoning/KASAN, and unlocking a bogus mutex address corrupts kernel state, causing a panic or hang; the sequence can be repeated at will to keep the system down."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:35:22.452Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/86a9bd8c8f422d5f3079da31e151868902fcc702"
},
{
"url": "https://git.kernel.org/stable/c/abeff53233b984571b87582bb588b4b38ef4ea50"
},
{
"url": "https://git.kernel.org/stable/c/5b7e5f84d3d4cea10c3764d2da274810a7934228"
},
{
"url": "https://git.kernel.org/stable/c/5f4de3c717d34a24d555af581947742980778c02"
},
{
"url": "https://git.kernel.org/stable/c/b773faa32b0a98c3eb2b50d96de631681e5d1157"
},
{
"url": "https://git.kernel.org/stable/c/266cddf7bd0f6c79b6c0633aef742a22bf70265b"
}
],
"title": "gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68427",
"datePublished": "2026-08-10T12:04:47.915Z",
"dateReserved": "2026-07-30T09:28:09.392Z",
"dateUpdated": "2026-08-19T16:35:22.452Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74704 (GCVE-0-2026-74704)
Vulnerability from cvelistv5
Published
2026-08-22 15:33
Modified
2026-08-25 05:41
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/sched: sch_cake: drop WARN_ON(1) for malformed packets in ACK filter
The sch_cake ACK filter parses packets to find the TCP header and filter
duplicated ACKs if the flow is backlogged. The parsing code contains a
WARN_ON(1) which can be triggered by a malformed IP header in certain
cases. Depending on the system configuration, this leads either to
either spamming dmesg with warnings, or a panic if panic_on_warn is set.
The code already correctly skips the offending packet in the branch that
triggers the warning, so the WARN_ON itself doesn't really serve any
purpose. So just drop it altogether to avoid the inconvenient side
effects.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 8b7138814f29933898ecd31dfc83e35a30ee69f5 Version: 8b7138814f29933898ecd31dfc83e35a30ee69f5 Version: 8b7138814f29933898ecd31dfc83e35a30ee69f5 Version: 8b7138814f29933898ecd31dfc83e35a30ee69f5 Version: 8b7138814f29933898ecd31dfc83e35a30ee69f5 Version: 8b7138814f29933898ecd31dfc83e35a30ee69f5 Version: 8b7138814f29933898ecd31dfc83e35a30ee69f5 Version: 8b7138814f29933898ecd31dfc83e35a30ee69f5 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/sched/sch_cake.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c1693b7844a6c06d31a565e5a494948034dfd235",
"status": "affected",
"version": "8b7138814f29933898ecd31dfc83e35a30ee69f5",
"versionType": "git"
},
{
"lessThan": "a4b52612004a5639c4bfc30ba93ba414b8326e2a",
"status": "affected",
"version": "8b7138814f29933898ecd31dfc83e35a30ee69f5",
"versionType": "git"
},
{
"lessThan": "ae1b2f8e21a41e7c7e75511bea0c4ccc59ec1bd3",
"status": "affected",
"version": "8b7138814f29933898ecd31dfc83e35a30ee69f5",
"versionType": "git"
},
{
"lessThan": "0c4882bff34558d8d53fb04c3e96da5c327c7dc8",
"status": "affected",
"version": "8b7138814f29933898ecd31dfc83e35a30ee69f5",
"versionType": "git"
},
{
"lessThan": "2504a76e5c0694e14e15562730e1339f2d9f9458",
"status": "affected",
"version": "8b7138814f29933898ecd31dfc83e35a30ee69f5",
"versionType": "git"
},
{
"lessThan": "cd2f1d9fe8a507c2dc86ad326fe221f121c47734",
"status": "affected",
"version": "8b7138814f29933898ecd31dfc83e35a30ee69f5",
"versionType": "git"
},
{
"lessThan": "a1ae353d8355407c1bea971d1c1af5e7f242bb7d",
"status": "affected",
"version": "8b7138814f29933898ecd31dfc83e35a30ee69f5",
"versionType": "git"
},
{
"lessThan": "2a33516f9ef59ad11844d4fc152f889449b5daf3",
"status": "affected",
"version": "8b7138814f29933898ecd31dfc83e35a30ee69f5",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/sched/sch_cake.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.19"
},
{
"lessThan": "4.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: sch_cake: drop WARN_ON(1) for malformed packets in ACK filter\n\nThe sch_cake ACK filter parses packets to find the TCP header and filter\nduplicated ACKs if the flow is backlogged. The parsing code contains a\nWARN_ON(1) which can be triggered by a malformed IP header in certain\ncases. Depending on the system configuration, this leads either to\neither spamming dmesg with warnings, or a panic if panic_on_warn is set.\n\nThe code already correctly skips the offending packet in the branch that\ntriggers the warning, so the WARN_ON itself doesn\u0027t really serve any\npurpose. So just drop it altogether to avoid the inconvenient side\neffects."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.2,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug fires in cake_ack_filter() during cake_enqueue() on the packet datapath; remotely sourced traffic through an internet-facing SQM/OpenWrt gateway with CAKE ingress/egress and ack-filter enabled reaches the vulnerable ACK-filter parsing loop without any local syscall or netlink operation by the attacker.\nAC:L - Once CAKE ack-filter is configured, an attacker reliably crafts malformed encapsulated IP headers (e.g., IPv4 carrying an inner header with invalid version) and floods matching TCP ACKs to keep the flow backlogged, deterministically hitting the unsupported-version branch on each qualifying enqueue.\nPR:N - Installing CAKE with ack-filter requires CAP_NET_ADMIN, but triggering the bug on a preconfigured edge router or gateway needs no credentials on the target; an unauthenticated remote peer only sends crafted packets, consistent with CNA precedent for packet-driven tc issues (e.g., CVE-2026-72256).\nUI:N - Exploitation requires only attacker-generated packets delivered through the shaped interface; no victim login, file open, mount, or other interactive action is needed beyond normal network traffic reaching the CAKE-managed path.\nS:U - Impact is confined to kernel traffic-shaping code and warning/panic handling within the affected host; it does not cross VM, container, IOMMU, or other security-authority boundaries.\nC:L - Each WARN_ON(1) emits a kernel backtrace that can disclose kernel text and module pointers via dmesg/syslog to the attacker, constituting limited information disclosure even though no out-of-bounds read or use-after-free occurs.\nI:N - The failure path only executes continue and skips the malformed queued packet; there is no memory corruption, type confusion, or attacker-controlled modification of kernel or network data beyond normal ACK-filter drop behavior.\nA:H - Each matching malformed packet triggers WARN_ON(1) in cake_ack_filter(), flooding kernel warnings and, when panic_on_warn is enabled, invoking check_panic_on_warn() to kernel panic, yielding repeatable denial of service on CAKE-managed router and gateway paths."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:41:47.538Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c1693b7844a6c06d31a565e5a494948034dfd235"
},
{
"url": "https://git.kernel.org/stable/c/a4b52612004a5639c4bfc30ba93ba414b8326e2a"
},
{
"url": "https://git.kernel.org/stable/c/ae1b2f8e21a41e7c7e75511bea0c4ccc59ec1bd3"
},
{
"url": "https://git.kernel.org/stable/c/0c4882bff34558d8d53fb04c3e96da5c327c7dc8"
},
{
"url": "https://git.kernel.org/stable/c/2504a76e5c0694e14e15562730e1339f2d9f9458"
},
{
"url": "https://git.kernel.org/stable/c/cd2f1d9fe8a507c2dc86ad326fe221f121c47734"
},
{
"url": "https://git.kernel.org/stable/c/a1ae353d8355407c1bea971d1c1af5e7f242bb7d"
},
{
"url": "https://git.kernel.org/stable/c/2a33516f9ef59ad11844d4fc152f889449b5daf3"
}
],
"title": "net/sched: sch_cake: drop WARN_ON(1) for malformed packets in ACK filter",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74704",
"datePublished": "2026-08-22T15:33:03.491Z",
"dateReserved": "2026-08-15T05:44:03.927Z",
"dateUpdated": "2026-08-25T05:41:47.538Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74583 (GCVE-0-2026-74583)
Vulnerability from cvelistv5
Published
2026-08-21 16:31
Modified
2026-08-25 05:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/sched: cls_route: fix fastmap use-after-free on filter
The route4 classifier maintains a 16-slot fastmap cache that stores raw
struct route4_filter pointers indexed by (id, iif). The reader
(route4_classify) populates this cache via route4_set_fastmap() for every
classified packet that hits a filter. The writer (route4_delete,
route4_change) clears the cache via route4_reset_fastmap() before
RCU-deferred kfree of the filter.
This creates a UAF race:
1. Reader walks the RCU-protected bucket chain, finds filter f
2. Writer unlinks f, calls route4_reset_fastmap(), then tcf_queue_work()
3. Reader calls route4_set_fastmap() and writes f into the cache
*after* the writer's reset, caching a pointer about to be freed
4. After the RCU grace period, kfree(f) executes
5. Next classified packet on the same (id, iif) tuple hits the stale
fastmap entry and reads f->res from freed memory
Reproduced with an mdelay(100) accelerator in route4_set_fastmap() and a
concurrent add/delete stress test (provided by both zdi and Santosh).
Both triggered KASAN slab-use-after-free reports in the route4 fastmap
paths.
Fix:
Introduce a per-filter boolean dying flag to suppress stale fastmap
republishing by in-flight readers.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1109c00547fc66df45b9ff923544be4c1e1bec13 Version: 1109c00547fc66df45b9ff923544be4c1e1bec13 Version: 1109c00547fc66df45b9ff923544be4c1e1bec13 Version: 1109c00547fc66df45b9ff923544be4c1e1bec13 Version: 1109c00547fc66df45b9ff923544be4c1e1bec13 Version: 1109c00547fc66df45b9ff923544be4c1e1bec13 Version: 1109c00547fc66df45b9ff923544be4c1e1bec13 Version: 1109c00547fc66df45b9ff923544be4c1e1bec13 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/sched/cls_route.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "7897198b26445b4009a057bda1986b94a99e5d5f",
"status": "affected",
"version": "1109c00547fc66df45b9ff923544be4c1e1bec13",
"versionType": "git"
},
{
"lessThan": "820f083c294ad6d319c02a7d43294f2ed2565139",
"status": "affected",
"version": "1109c00547fc66df45b9ff923544be4c1e1bec13",
"versionType": "git"
},
{
"lessThan": "5ec9001be6d0eb527251125632ec8fe88278897f",
"status": "affected",
"version": "1109c00547fc66df45b9ff923544be4c1e1bec13",
"versionType": "git"
},
{
"lessThan": "b969984b2bdc85d721ce4047cd270cd37ec705a2",
"status": "affected",
"version": "1109c00547fc66df45b9ff923544be4c1e1bec13",
"versionType": "git"
},
{
"lessThan": "a17f636c9330eac879822ce29f998e5abd1b72c1",
"status": "affected",
"version": "1109c00547fc66df45b9ff923544be4c1e1bec13",
"versionType": "git"
},
{
"lessThan": "0e7a8cf8895b06d07c7311f028eba16ad742b9bc",
"status": "affected",
"version": "1109c00547fc66df45b9ff923544be4c1e1bec13",
"versionType": "git"
},
{
"lessThan": "ae9aff87025219005a2d16b4fe83d6f24643e50d",
"status": "affected",
"version": "1109c00547fc66df45b9ff923544be4c1e1bec13",
"versionType": "git"
},
{
"lessThan": "47d7f7051253bdc02b1d245d87e38f16d31a74df",
"status": "affected",
"version": "1109c00547fc66df45b9ff923544be4c1e1bec13",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/sched/cls_route.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.18"
},
{
"lessThan": "3.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "3.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "3.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "3.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "3.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.18",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: cls_route: fix fastmap use-after-free on filter\n\nThe route4 classifier maintains a 16-slot fastmap cache that stores raw\nstruct route4_filter pointers indexed by (id, iif). The reader\n(route4_classify) populates this cache via route4_set_fastmap() for every\nclassified packet that hits a filter. The writer (route4_delete,\nroute4_change) clears the cache via route4_reset_fastmap() before\nRCU-deferred kfree of the filter.\n\nThis creates a UAF race:\n 1. Reader walks the RCU-protected bucket chain, finds filter f\n 2. Writer unlinks f, calls route4_reset_fastmap(), then tcf_queue_work()\n 3. Reader calls route4_set_fastmap() and writes f into the cache\n *after* the writer\u0027s reset, caching a pointer about to be freed\n 4. After the RCU grace period, kfree(f) executes\n 5. Next classified packet on the same (id, iif) tuple hits the stale\n fastmap entry and reads f-\u003eres from freed memory\n\nReproduced with an mdelay(100) accelerator in route4_set_fastmap() and a\nconcurrent add/delete stress test (provided by both zdi and Santosh).\nBoth triggered KASAN slab-use-after-free reports in the route4 fastmap\npaths.\n\nFix:\nIntroduce a per-filter boolean dying flag to suppress stale fastmap\nrepublishing by in-flight readers."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires local rtnetlink RTM_NEWTFILTER/RTM_DELTFILTER (tc filter add/change/del route) through sendmsg\u2192rtnetlink_rcv_msg\u2192tc_new_tfilter/tc_del_tfilter\u2192route4_change/route4_delete; remote packets alone cannot trigger the filter-deletion side of the race.\nAC:L - The attacker controls both race sides\u2014concurrent route filter add/change/delete via netlink plus traffic through route4_classify on clsact/ingress/egress qdiscs; ZDI and independent reporter stress tests reproduced KASAN slab-use-after-free without uncontrollable prerequisites.\nPR:L - Non-GET rtnetlink handlers require netlink_net_capable(CAP_NET_ADMIN), evaluated against the target network namespace user_ns; an unprivileged local user obtains CAP_NET_ADMIN via user+network namespaces (unshare -Urn) and configures clsact with route filters.\nUI:N - No victim interaction is needed; the attacker configures the route classifier, drives concurrent filter churn, and generates matching traffic from their own processes.\nS:U - Impact is kernel memory corruption within the same kernel security boundary (local privilege escalation/DoS); it does not cross VM, hypervisor, or IOMMU boundaries.\nC:H - Slab use-after-free: a stale fastmap entry retains a freed route4_filter pointer and route4_classify dereferences f-\u003eres from freed kmalloc memory; KASAN confirmed slab-use-after-free, enabling arbitrary kernel read via heap reclaim/spray.\nI:H - UAF of the kmalloc route4_filter object allows attacker-controlled heap spraying to reclaim the freed slot and obtain write/control-flow hijacking primitives; memory corruption is exploitable beyond a simple crash.\nA:H - UAF on the fastmap hot path causes kernel oops/panic under concurrent filter churn; KASAN slab-use-after-free was confirmed during add/delete stress testing, providing reliable denial of service even without full exploitation."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:40:10.077Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/7897198b26445b4009a057bda1986b94a99e5d5f"
},
{
"url": "https://git.kernel.org/stable/c/820f083c294ad6d319c02a7d43294f2ed2565139"
},
{
"url": "https://git.kernel.org/stable/c/5ec9001be6d0eb527251125632ec8fe88278897f"
},
{
"url": "https://git.kernel.org/stable/c/b969984b2bdc85d721ce4047cd270cd37ec705a2"
},
{
"url": "https://git.kernel.org/stable/c/a17f636c9330eac879822ce29f998e5abd1b72c1"
},
{
"url": "https://git.kernel.org/stable/c/0e7a8cf8895b06d07c7311f028eba16ad742b9bc"
},
{
"url": "https://git.kernel.org/stable/c/ae9aff87025219005a2d16b4fe83d6f24643e50d"
},
{
"url": "https://git.kernel.org/stable/c/47d7f7051253bdc02b1d245d87e38f16d31a74df"
}
],
"title": "net/sched: cls_route: fix fastmap use-after-free on filter",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74583",
"datePublished": "2026-08-21T16:31:55.886Z",
"dateReserved": "2026-08-15T05:44:03.918Z",
"dateUpdated": "2026-08-25T05:40:10.077Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74649 (GCVE-0-2026-74649)
Vulnerability from cvelistv5
Published
2026-08-22 15:32
Modified
2026-08-25 05:41
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
staging: rtl8723bs: fix missing shared-key auth challenge length check
The WEP shared-key authentication handler uses the challenge-text
element's attacker-controlled length without checking it against the
fixed 128-byte chg_txt buffer.
In OnAuthClient() the length from rtw_get_ie() - up to 255 - is used
to perform memcpy() into the 128-byte pmlmeinfo->chg_txt, so a
malicious AP sending a malformed WLAN_EID_CHALLENGE element can
overflow/underfill chg_txt by up to 127 bytes. It is reachable over the
air, before association, during shared-key authentication. In the case
of an overflow, the driver can write out of bounds. In the case of an
underfill, the driver can echo stale buffer memory.
The challenge text is defined to be exactly 128 octets, which is
already provided as the WLAN_AUTH_CHALLENGE_LEN define; require the
element to be exactly that length before use.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/staging/rtl8723bs/core/rtw_mlme_ext.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "39ae1033071001af9bb4573ebdbb43bbbe88f749",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "4d018e7d7d908bdfcb5ecfa922b1d5cb9ddb3722",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "4ba402fd47009d20e51dbfc934abb562098ea35b",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "87c2f073d2aaea041d531b8e579c47570b54b3b7",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "a28a4b0592e4a37ea471bc0d308513a93133ce7e",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "6235b5156b48ed5d1ce3410d8f0b2fd67d30d944",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "2c56ef658ac8c6bca36bc5574715e8f717207c6c",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/staging/rtl8723bs/core/rtw_mlme_ext.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.12"
},
{
"lessThan": "4.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: rtl8723bs: fix missing shared-key auth challenge length check\n\nThe WEP shared-key authentication handler uses the challenge-text\nelement\u0027s attacker-controlled length without checking it against the\nfixed 128-byte chg_txt buffer.\n\nIn OnAuthClient() the length from rtw_get_ie() - up to 255 - is used\nto perform memcpy() into the 128-byte pmlmeinfo-\u003echg_txt, so a\nmalicious AP sending a malformed WLAN_EID_CHALLENGE element can\noverflow/underfill chg_txt by up to 127 bytes. It is reachable over the\nair, before association, during shared-key authentication. In the case\nof an overflow, the driver can write out of bounds. In the case of an\nunderfill, the driver can echo stale buffer memory.\n\nThe challenge text is defined to be exactly 128 octets, which is\nalready provided as the WLAN_AUTH_CHALLENGE_LEN define; require the\nelement to be exactly that length before use."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - A malicious AP on the same WiFi radio segment sends a crafted 802.11 authentication management frame; rtl8723bs receives it from the air via SDIO and dispatches it through mgt_dispatcher() to OnAuthClient() before association completes.\nAC:L - The rogue AP fully controls the malformed auth seq-2 response and its timing; once the client enters WEP shared-key authentication the attacker can reliably supply any challenge IE length up to 255 without races or conditions outside attacker control.\nPR:N - Exploitation requires no privileges on the victim host; a nearby attacker operating a malicious AP triggers the pre-association shared-key authentication handler without authenticating to the client or needing local shell or capability access.\nUI:N - No fresh victim interaction is needed at exploit time; evil-twin APs can invoke auto-connect to saved WEP profiles, and auth-algorithm auto-fallback from failed open auth can reach shared-key auth without a new user action during the attack.\nS:U - The overflow corrupts driver-private mlme_ext_info fields within the kernel WiFi driver context; impact remains within kernel/driver authority and does not cross a VM, container, or IOMMU security boundary.\nC:H - Underfill leaves stale data in the 128-byte chg_txt buffer that issue_auth() later transmits back to the attacker in auth seq 3, disclosing prior kernel memory; overflow also enables memory corruption paths that can yield further information disclosure.\nI:H - memcpy() uses attacker-controlled len (up to 255) into the fixed 128-byte chg_txt array, writing up to 127 bytes past the buffer into adjacent mlme_ext_info fields (aid, capability, HT/WMM structs, network IEs), enabling exploitable kernel memory corruption.\nA:H - Out-of-bounds writes into critical mlme_ext_info state in kernel context can corrupt driver data structures and trigger kernel oops, panic, or hang, causing complete loss of availability on affected embedded/mobile devices using this driver."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:41:08.071Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/39ae1033071001af9bb4573ebdbb43bbbe88f749"
},
{
"url": "https://git.kernel.org/stable/c/4d018e7d7d908bdfcb5ecfa922b1d5cb9ddb3722"
},
{
"url": "https://git.kernel.org/stable/c/4ba402fd47009d20e51dbfc934abb562098ea35b"
},
{
"url": "https://git.kernel.org/stable/c/87c2f073d2aaea041d531b8e579c47570b54b3b7"
},
{
"url": "https://git.kernel.org/stable/c/a28a4b0592e4a37ea471bc0d308513a93133ce7e"
},
{
"url": "https://git.kernel.org/stable/c/6235b5156b48ed5d1ce3410d8f0b2fd67d30d944"
},
{
"url": "https://git.kernel.org/stable/c/2c56ef658ac8c6bca36bc5574715e8f717207c6c"
}
],
"title": "staging: rtl8723bs: fix missing shared-key auth challenge length check",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74649",
"datePublished": "2026-08-22T15:32:25.601Z",
"dateReserved": "2026-08-15T05:44:03.923Z",
"dateUpdated": "2026-08-25T05:41:08.071Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64567 (GCVE-0-2026-64567)
Vulnerability from cvelistv5
Published
2026-08-05 08:08
Modified
2026-08-19 16:28
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
btrfs: reject free space cache with more entries than pages
When loading a v1 free space cache, __load_free_space_cache() takes
num_entries and num_bitmaps straight from the on-disk
btrfs_free_space_header. That header is stored in the tree_root under a key
with type 0, which the tree-checker has no case for, so neither count is
validated before the load trusts it.
The load loops num_entries times and maps the next page whenever the current
one runs out, going through io_ctl_check_crc() -> io_ctl_map_page(), which
does io_ctl->pages[io_ctl->index++]. But pages[] is allocated in
io_ctl_init() from the cache inode's i_size, not from num_entries:
num_pages = DIV_ROUND_UP(i_size_read(inode), PAGE_SIZE);
io_ctl->pages = kcalloc(num_pages, sizeof(struct page *), GFP_NOFS);
So if num_entries claims more records than the pages can hold, io_ctl->index
runs off the end of pages[]. The write side never hits this because
io_ctl_add_entry() and io_ctl_add_bitmap() both stop once
io_ctl->index >= io_ctl->num_pages; the read side just never had the same
check.
To trigger it, take a clean cache (num_entries = <N> here), set num_entries
in the header to 0x10000, and fix up the leaf checksum so it still passes
the tree-checker. The cache inode has i_size = 65536, so num_pages is 16 and
pages[] is a 16-pointer (kmalloc-128) array. The load now tries to read
65536 entries, io_ctl->index walks up to 16, and pages[16] is read past the
array:
BUG: KASAN: slab-out-of-bounds in io_ctl_check_crc (fs/btrfs/free-space-cache.c:420 fs/btrfs/free-space-cache.c:565)
Read of size 8 at addr ffff88800c833a80 by task kworker/u8:3/58
io_ctl_check_crc (fs/btrfs/free-space-cache.c:420 fs/btrfs/free-space-cache.c:565)
__load_free_space_cache (fs/btrfs/free-space-cache.c:655 fs/btrfs/free-space-cache.c:820)
load_free_space_cache (fs/btrfs/free-space-cache.c:1017)
caching_thread (fs/btrfs/block-group.c:880)
btrfs_work_helper (fs/btrfs/async-thread.c:312)
process_one_work
worker_thread
kthread
ret_from_fork
free-space-cache.c:420 is io_ctl_map_page(), inlined into io_ctl_check_crc()
at line 565, which is why that is the frame KASAN names. The out-of-bounds
slot is then treated as a struct page and handed to crc32c(), so the bad
read turns into a GP fault.
Add the missing check to io_ctl_check_crc(), which is where both the entry
loop and the bitmap loop end up. When num_entries is too large the load now
fails like any corrupt cache: __load_free_space_cache() drops it and rebuilds
the free space from the extent tree, so a valid cache is never rejected.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 5b0e95bf607ddd59b39f52d3d55e6581c817b530 Version: 5b0e95bf607ddd59b39f52d3d55e6581c817b530 Version: 5b0e95bf607ddd59b39f52d3d55e6581c817b530 Version: 5b0e95bf607ddd59b39f52d3d55e6581c817b530 Version: 5b0e95bf607ddd59b39f52d3d55e6581c817b530 Version: 5b0e95bf607ddd59b39f52d3d55e6581c817b530 Version: 5b0e95bf607ddd59b39f52d3d55e6581c817b530 Version: 5b0e95bf607ddd59b39f52d3d55e6581c817b530 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/btrfs/free-space-cache.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "8ded74c654a982dc8581a17b0caa7fcedb20de69",
"status": "affected",
"version": "5b0e95bf607ddd59b39f52d3d55e6581c817b530",
"versionType": "git"
},
{
"lessThan": "c9c38066b6446e83668c041702bb639b0ca49363",
"status": "affected",
"version": "5b0e95bf607ddd59b39f52d3d55e6581c817b530",
"versionType": "git"
},
{
"lessThan": "094734c7aaa2b36751dc32480a680a4952685e78",
"status": "affected",
"version": "5b0e95bf607ddd59b39f52d3d55e6581c817b530",
"versionType": "git"
},
{
"lessThan": "33878ba25e2638bc0c61623d7a05c9ca2b74c039",
"status": "affected",
"version": "5b0e95bf607ddd59b39f52d3d55e6581c817b530",
"versionType": "git"
},
{
"lessThan": "404a0b986e0b6e79738fdf1f0ebbbc43b9acd2a2",
"status": "affected",
"version": "5b0e95bf607ddd59b39f52d3d55e6581c817b530",
"versionType": "git"
},
{
"lessThan": "5e1b2ca6b34939e70fb0785e8222b53cf060016f",
"status": "affected",
"version": "5b0e95bf607ddd59b39f52d3d55e6581c817b530",
"versionType": "git"
},
{
"lessThan": "f9fef131fa3f59b857217f522fa5ea430d1b707c",
"status": "affected",
"version": "5b0e95bf607ddd59b39f52d3d55e6581c817b530",
"versionType": "git"
},
{
"lessThan": "a2d8d5647ed854e38f941741aea45b9eb15a6350",
"status": "affected",
"version": "5b0e95bf607ddd59b39f52d3d55e6581c817b530",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/btrfs/free-space-cache.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.2"
},
{
"lessThan": "3.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: reject free space cache with more entries than pages\n\nWhen loading a v1 free space cache, __load_free_space_cache() takes\nnum_entries and num_bitmaps straight from the on-disk\nbtrfs_free_space_header. That header is stored in the tree_root under a key\nwith type 0, which the tree-checker has no case for, so neither count is\nvalidated before the load trusts it.\n\nThe load loops num_entries times and maps the next page whenever the current\none runs out, going through io_ctl_check_crc() -\u003e io_ctl_map_page(), which\ndoes io_ctl-\u003epages[io_ctl-\u003eindex++]. But pages[] is allocated in\nio_ctl_init() from the cache inode\u0027s i_size, not from num_entries:\n\n\tnum_pages = DIV_ROUND_UP(i_size_read(inode), PAGE_SIZE);\n\tio_ctl-\u003epages = kcalloc(num_pages, sizeof(struct page *), GFP_NOFS);\n\nSo if num_entries claims more records than the pages can hold, io_ctl-\u003eindex\nruns off the end of pages[]. The write side never hits this because\nio_ctl_add_entry() and io_ctl_add_bitmap() both stop once\nio_ctl-\u003eindex \u003e= io_ctl-\u003enum_pages; the read side just never had the same\ncheck.\n\nTo trigger it, take a clean cache (num_entries = \u003cN\u003e here), set num_entries\nin the header to 0x10000, and fix up the leaf checksum so it still passes\nthe tree-checker. The cache inode has i_size = 65536, so num_pages is 16 and\npages[] is a 16-pointer (kmalloc-128) array. The load now tries to read\n65536 entries, io_ctl-\u003eindex walks up to 16, and pages[16] is read past the\narray:\n\n BUG: KASAN: slab-out-of-bounds in io_ctl_check_crc (fs/btrfs/free-space-cache.c:420 fs/btrfs/free-space-cache.c:565)\n Read of size 8 at addr ffff88800c833a80 by task kworker/u8:3/58\n io_ctl_check_crc (fs/btrfs/free-space-cache.c:420 fs/btrfs/free-space-cache.c:565)\n __load_free_space_cache (fs/btrfs/free-space-cache.c:655 fs/btrfs/free-space-cache.c:820)\n load_free_space_cache (fs/btrfs/free-space-cache.c:1017)\n caching_thread (fs/btrfs/block-group.c:880)\n btrfs_work_helper (fs/btrfs/async-thread.c:312)\n process_one_work\n worker_thread\n kthread\n ret_from_fork\n\nfree-space-cache.c:420 is io_ctl_map_page(), inlined into io_ctl_check_crc()\nat line 565, which is why that is the frame KASAN names. The out-of-bounds\nslot is then treated as a struct page and handed to crc32c(), so the bad\nread turns into a GP fault.\n\nAdd the missing check to io_ctl_check_crc(), which is where both the entry\nloop and the bitmap loop end up. When num_entries is too large the load now\nfails like any corrupt cache: __load_free_space_cache() drops it and rebuilds\nthe free space from the extent tree, so a valid cache is never rejected."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached only by mounting a crafted btrfs image so caching_thread \u2192 load_free_space_cache \u2192 __load_free_space_cache runs; there is no network or adjacent protocol path into v1 free-space cache loading.\nAC:L - The attacker authors a v1 cache with inflated num_entries (and a matching leaf checksum); cache_generation auto-enables SPACE_CACHE on mount, and the OOB in io_ctl_check_crc/io_ctl_map_page is deterministic with no race or uncontrolled condition.\nPR:L - btrfs lacks FS_USERNS_MOUNT, but an unprivileged local user can loop-setup and mount a crafted image via udisks2/polkit on typical desktops/kiosks; real init-namespace root is not required.\nUI:N - In the loop/udisks mount scenario the attacker mounts the image themselves; no separate victim must open a file, click through a prompt, or otherwise interact.\nS:U - The slab OOB and resulting kernel memory misuse stay inside the host kernel\u0027s authority; no VM escape, IOMMU bypass, or sandbox boundary is crossed.\nC:H - An out-of-bounds pages[] read yields a forged struct page pointer that is passed to page_address/crc32c and then used as the source for further cache parsing, giving an arbitrary kernel-memory read primitive once adjacent slab contents are groomed.\nI:H - The forged page pointer continues into entry/bitmap load paths (including copy_page into kernel bitmaps and linking attacker-controlled free-space records), a memory-corruption primitive exploitable for arbitrary write and control-flow hijack.\nA:H - Without a valid page pointer the OOB dereference reliably faults (KASAN slab-OOB then GP fault on crc32c as in the report), crashing or oopsing the kernel."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:28:41.793Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/8ded74c654a982dc8581a17b0caa7fcedb20de69"
},
{
"url": "https://git.kernel.org/stable/c/c9c38066b6446e83668c041702bb639b0ca49363"
},
{
"url": "https://git.kernel.org/stable/c/094734c7aaa2b36751dc32480a680a4952685e78"
},
{
"url": "https://git.kernel.org/stable/c/33878ba25e2638bc0c61623d7a05c9ca2b74c039"
},
{
"url": "https://git.kernel.org/stable/c/404a0b986e0b6e79738fdf1f0ebbbc43b9acd2a2"
},
{
"url": "https://git.kernel.org/stable/c/5e1b2ca6b34939e70fb0785e8222b53cf060016f"
},
{
"url": "https://git.kernel.org/stable/c/f9fef131fa3f59b857217f522fa5ea430d1b707c"
},
{
"url": "https://git.kernel.org/stable/c/a2d8d5647ed854e38f941741aea45b9eb15a6350"
}
],
"title": "btrfs: reject free space cache with more entries than pages",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64567",
"datePublished": "2026-08-05T08:08:06.015Z",
"dateReserved": "2026-07-19T15:36:31.797Z",
"dateUpdated": "2026-08-19T16:28:41.793Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68131 (GCVE-0-2026-68131)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-19 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
rbd: Reset positive result codes to zero in object map update path
In a reply message to an RBD request, a positive result code indicates
a data payload, which is not allowed for writes. While
rbd_osd_req_callback() already resets a positive result code for writes
to zero, rbd_object_map_callback() does not. This allows a corrupted
reply to an object map update to trigger the rbd_assert(*result < 0) in
__rbd_obj_handle_request(). This happens, because
rbd_object_map_callback() calls rbd_obj_handle_request() ->
__rbd_obj_handle_request() and passes this positive result code. From
__rbd_obj_handle_request(), rbd_obj_advance_write() is called, which
leaves the positive result code unchanged and returns true. Therefore,
the if(done && *result) branch is executed in __rbd_obj_handle_request()
and the assertion triggers.
This patch fixes the issue by adjusting the logic in the
rbd_object_map_callback() path. A positive result code for an object map
update is now reset to zero (similar to rbd_osd_req_callback()), and the
message is subsequently handled the same way as if the result code was
zero from the beginning. Additionally, a WARN_ON_ONCE() is added for
this case.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 22e8bd51bb0469d1a524130a057f894ff632376a Version: 22e8bd51bb0469d1a524130a057f894ff632376a Version: 22e8bd51bb0469d1a524130a057f894ff632376a Version: 22e8bd51bb0469d1a524130a057f894ff632376a Version: 22e8bd51bb0469d1a524130a057f894ff632376a Version: 22e8bd51bb0469d1a524130a057f894ff632376a Version: 22e8bd51bb0469d1a524130a057f894ff632376a Version: 22e8bd51bb0469d1a524130a057f894ff632376a |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/block/rbd.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "cf1167292f606deaddac35ec384eba48f08a68d2",
"status": "affected",
"version": "22e8bd51bb0469d1a524130a057f894ff632376a",
"versionType": "git"
},
{
"lessThan": "da926959bf791441ba06a80571708c3d0d3cc08f",
"status": "affected",
"version": "22e8bd51bb0469d1a524130a057f894ff632376a",
"versionType": "git"
},
{
"lessThan": "6f33d9d539fb94e5a17589c2dfe271ff9bb64904",
"status": "affected",
"version": "22e8bd51bb0469d1a524130a057f894ff632376a",
"versionType": "git"
},
{
"lessThan": "14995c4250f04b58bf6fc00e0e973a2e1b3cfb9b",
"status": "affected",
"version": "22e8bd51bb0469d1a524130a057f894ff632376a",
"versionType": "git"
},
{
"lessThan": "2419aa74081007dc4d14ff5640659052dfdfd69a",
"status": "affected",
"version": "22e8bd51bb0469d1a524130a057f894ff632376a",
"versionType": "git"
},
{
"lessThan": "34f2a2f32af570dfcc532ad70c080629ee1c32b0",
"status": "affected",
"version": "22e8bd51bb0469d1a524130a057f894ff632376a",
"versionType": "git"
},
{
"lessThan": "b1a61366933224b3ad80975c4d01ac2cc6931ecf",
"status": "affected",
"version": "22e8bd51bb0469d1a524130a057f894ff632376a",
"versionType": "git"
},
{
"lessThan": "a6c4250b81bd30beae94e1b7a4b26fa1193ad2e4",
"status": "affected",
"version": "22e8bd51bb0469d1a524130a057f894ff632376a",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/block/rbd.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.3"
},
{
"lessThan": "5.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nrbd: Reset positive result codes to zero in object map update path\n\nIn a reply message to an RBD request, a positive result code indicates\na data payload, which is not allowed for writes. While\nrbd_osd_req_callback() already resets a positive result code for writes\nto zero, rbd_object_map_callback() does not. This allows a corrupted\nreply to an object map update to trigger the rbd_assert(*result \u003c 0) in\n__rbd_obj_handle_request(). This happens, because\nrbd_object_map_callback() calls rbd_obj_handle_request() -\u003e\n__rbd_obj_handle_request() and passes this positive result code. From\n__rbd_obj_handle_request(), rbd_obj_advance_write() is called, which\nleaves the positive result code unchanged and returns true. Therefore,\nthe if(done \u0026\u0026 *result) branch is executed in __rbd_obj_handle_request()\nand the assertion triggers.\n\nThis patch fixes the issue by adjusting the logic in the\nrbd_object_map_callback() path. A positive result code for an object map\nupdate is now reset to zero (similar to rbd_osd_req_callback()), and the\nmessage is subsequently handled the same way as if the result code was\nzero from the beginning. Additionally, a WARN_ON_ONCE() is added for\nthis case."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The crash is triggered when libceph processes a crafted MOSDOpReply over the Ceph TCP connection and passes a positive r_result into rbd_object_map_callback(); a compromised or malicious OSD/monitor peer can deliver this without any local syscall on the victim.\nAC:L - An attacker controlling the Ceph OSD can deterministically reply to any object-map update request with a positive result code whenever the mapped image has RBD_FEATURE_OBJECT_MAP and write I/O is in flight, with no race or victim-specific memory layout required.\nPR:N - No privileges on the victim host are needed; exploitation only requires the kernel RBD client to be connected to an attacker-controlled or compromised Ceph cluster, consistent with other libceph client CVE scoring where the remote storage peer drives the bug.\nUI:N - After RBD is mapped, object-map updates are driven automatically by block-layer write I/O; no further interactive user action is required at exploit time beyond normal background storage activity on the mapped device.\nS:U - The BUG() panic affects only the kernel on the host running the RBD client and does not cross VM, container, or IOMMU security boundaries to another authority.\nC:N - The vulnerable path returns immediately on a positive result without decoding reply payload or corrupting memory; impact is limited to an assertion failure with no information disclosure primitive.\nI:N - No kernel or user data is modified; the positive result code is mishandled and triggers rbd_assert(*result \u003c 0) leading to BUG(), not an arbitrary write or code-execution primitive.\nA:H - RBD_DEBUG is unconditionally defined so rbd_assert() invokes BUG(), causing a kernel panic that fully denies availability on any host with an affected RBD mapping when a malicious OSD reply is received."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:29:49.752Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/cf1167292f606deaddac35ec384eba48f08a68d2"
},
{
"url": "https://git.kernel.org/stable/c/da926959bf791441ba06a80571708c3d0d3cc08f"
},
{
"url": "https://git.kernel.org/stable/c/6f33d9d539fb94e5a17589c2dfe271ff9bb64904"
},
{
"url": "https://git.kernel.org/stable/c/14995c4250f04b58bf6fc00e0e973a2e1b3cfb9b"
},
{
"url": "https://git.kernel.org/stable/c/2419aa74081007dc4d14ff5640659052dfdfd69a"
},
{
"url": "https://git.kernel.org/stable/c/34f2a2f32af570dfcc532ad70c080629ee1c32b0"
},
{
"url": "https://git.kernel.org/stable/c/b1a61366933224b3ad80975c4d01ac2cc6931ecf"
},
{
"url": "https://git.kernel.org/stable/c/a6c4250b81bd30beae94e1b7a4b26fa1193ad2e4"
}
],
"title": "rbd: Reset positive result codes to zero in object map update path",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68131",
"datePublished": "2026-08-10T11:58:54.155Z",
"dateReserved": "2026-07-30T09:28:09.370Z",
"dateUpdated": "2026-08-19T16:29:49.752Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74608 (GCVE-0-2026-74608)
Vulnerability from cvelistv5
Published
2026-08-22 15:31
Modified
2026-08-25 05:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
smb: client: Fix use-after-free in cifs_try_adding_channels()
cifs_try_adding_channels() takes a temporary reference to an interface
before dropping iface_lock. If cifs_ses_add_channel() fails, it drops
that reference and then increments iface->weight_fulfilled.
A concurrent interface list refresh can remove the list reference while
channel creation is in progress. In that case, the failure-path
kref_put() releases the last reference and frees iface. Updating
weight_fulfilled afterward then accesses freed memory.
Increment weight_fulfilled before dropping the temporary reference,
keeping iface alive for the final access.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: cbc53148cc0946b72d62a3c53870cb22ce4ec284 Version: cff97d683a083b862a8bb24309e0f4d2d928128a Version: 6aac002bcfd554aff6d3ebb55e1660d078d70ab0 Version: 6aac002bcfd554aff6d3ebb55e1660d078d70ab0 Version: 6aac002bcfd554aff6d3ebb55e1660d078d70ab0 Version: 6aac002bcfd554aff6d3ebb55e1660d078d70ab0 Version: 22a6c5b3425f327e7f4c3606a72277dce82c7d83 Version: 6.1.78 ≤ Version: 6.6.17 ≤ Version: 6.7.5 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/smb/client/sess.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "64d7584e62ac8cdc750455c5fdc6008fc2de4f06",
"status": "affected",
"version": "cbc53148cc0946b72d62a3c53870cb22ce4ec284",
"versionType": "git"
},
{
"lessThan": "c292d4686f717c03e5022fc4ae7c782f39a94915",
"status": "affected",
"version": "cff97d683a083b862a8bb24309e0f4d2d928128a",
"versionType": "git"
},
{
"lessThan": "47dfac48bce7198ad4f1a388fc8c9491f878ac3b",
"status": "affected",
"version": "6aac002bcfd554aff6d3ebb55e1660d078d70ab0",
"versionType": "git"
},
{
"lessThan": "1ffacbadc14530e55b8d86f7b917524f6a0fb891",
"status": "affected",
"version": "6aac002bcfd554aff6d3ebb55e1660d078d70ab0",
"versionType": "git"
},
{
"lessThan": "1305eadc6a7d78a8d0a52eee29ddd2d9e8a27805",
"status": "affected",
"version": "6aac002bcfd554aff6d3ebb55e1660d078d70ab0",
"versionType": "git"
},
{
"lessThan": "4986410316b1ae0e63c6ce418e4eb196723626e7",
"status": "affected",
"version": "6aac002bcfd554aff6d3ebb55e1660d078d70ab0",
"versionType": "git"
},
{
"status": "affected",
"version": "22a6c5b3425f327e7f4c3606a72277dce82c7d83",
"versionType": "git"
},
{
"lessThan": "6.1.183",
"status": "affected",
"version": "6.1.78",
"versionType": "semver"
},
{
"lessThan": "6.6.152",
"status": "affected",
"version": "6.6.17",
"versionType": "semver"
},
{
"lessThan": "6.8",
"status": "affected",
"version": "6.7.5",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/smb/client/sess.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.8"
},
{
"lessThan": "6.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "6.1.78",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "6.6.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.7.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: Fix use-after-free in cifs_try_adding_channels()\n\ncifs_try_adding_channels() takes a temporary reference to an interface\nbefore dropping iface_lock. If cifs_ses_add_channel() fails, it drops\nthat reference and then increments iface-\u003eweight_fulfilled.\n\nA concurrent interface list refresh can remove the list reference while\nchannel creation is in progress. In that case, the failure-path\nkref_put() releases the last reference and frees iface. Updating\nweight_fulfilled afterward then accesses freed memory.\n\nIncrement weight_fulfilled before dropping the temporary reference,\nkeeping iface alive for the final access."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The flaw is in the kernel SMB3 client multichannel path reached while handling remote SMB/CIFS server traffic (channel setup, reconnect, and FSCTL_QUERY_NETWORK_INTERFACE_INFO responses) over TCP, so a malicious or compromised SMB server can trigger it from the network.\nAC:L - A hostile SMB server can force cifs_ses_add_channel() to fail and concurrently drive interface-list refresh during the unlocked window; the attacker controls both sides of the race via reconnects, binding failures, and crafted interface responses with retries.\nPR:N - The attacker only needs to operate the malicious SMB server peer; no credentials, local shell access, or privileges on the victim host are required once the client has an SMB3 multichannel session to that server.\nUI:N - After an SMB3 multichannel mount exists, kernel delayed query_interfaces work, automatic reconnect on dropped TCP, and post-mount channel scaling invoke cifs_try_adding_channels() without further user action, letting the server trigger exploitation repeatedly.\nS:U - The UAF corrupts client kernel heap state within the same host kernel security authority and does not inherently cross a VM, container, or IOMMU security boundary.\nC:H - Writing to a freed cifs_server_iface slab object is a use-after-free; attacker-influenced heap grooming can reclaim the object and enable arbitrary kernel memory disclosure via corrupted or overlapping live allocations.\nI:H - The post-free weight_fulfilled increment is a kernel heap write after free that can corrupt adjacent slab objects and be leveraged into arbitrary write or control-flow hijacking through heap shaping.\nA:H - The use-after-free can cause KASAN-detectable slab corruption, kernel oops, or panic, and a malicious server can retrigger it by repeating failed channel opens with concurrent interface-list refresh on reconnect."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:40:33.533Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/64d7584e62ac8cdc750455c5fdc6008fc2de4f06"
},
{
"url": "https://git.kernel.org/stable/c/c292d4686f717c03e5022fc4ae7c782f39a94915"
},
{
"url": "https://git.kernel.org/stable/c/47dfac48bce7198ad4f1a388fc8c9491f878ac3b"
},
{
"url": "https://git.kernel.org/stable/c/1ffacbadc14530e55b8d86f7b917524f6a0fb891"
},
{
"url": "https://git.kernel.org/stable/c/1305eadc6a7d78a8d0a52eee29ddd2d9e8a27805"
},
{
"url": "https://git.kernel.org/stable/c/4986410316b1ae0e63c6ce418e4eb196723626e7"
}
],
"title": "smb: client: Fix use-after-free in cifs_try_adding_channels()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74608",
"datePublished": "2026-08-22T15:31:55.298Z",
"dateReserved": "2026-08-15T05:44:03.920Z",
"dateUpdated": "2026-08-25T05:40:33.533Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68204 (GCVE-0-2026-68204)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: vivid: check for vb2_is_busy() when toggling caps
The vivid_update_format_cap/out() functions must only be called if the
capture/output queue are not busy. But for the controls that select
the CROP/COMPOSE/SCALE capability that is not checked.
Only when streaming starts will they be set to 'grabbed' and it is
impossible to change the control, but between REQBUFS and STREAMON you
are still allowed to set these controls. Since vivid_update_format_cap/out
will change the format, this can cause unexpected results.
Besides adding these checks, also add a WARN_ON in
vivid_update_format_cap/out() if the queue is busy.
I'm 90% certain that this is the cause of this syzbot bug:
https://syzkaller.appspot.com/bug?extid=dac8f5eaa46837e97b89
But since we never have reproducers, it is hard to be certain. In any case,
these checks are needed regardless.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 73c3f48230cda01402ae189b05d56f1f7e0d53c9 Version: 73c3f48230cda01402ae189b05d56f1f7e0d53c9 Version: 73c3f48230cda01402ae189b05d56f1f7e0d53c9 Version: 73c3f48230cda01402ae189b05d56f1f7e0d53c9 Version: 73c3f48230cda01402ae189b05d56f1f7e0d53c9 Version: 73c3f48230cda01402ae189b05d56f1f7e0d53c9 Version: 73c3f48230cda01402ae189b05d56f1f7e0d53c9 Version: 73c3f48230cda01402ae189b05d56f1f7e0d53c9 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/test-drivers/vivid/vivid-ctrls.c",
"drivers/media/test-drivers/vivid/vivid-vid-cap.c",
"drivers/media/test-drivers/vivid/vivid-vid-out.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "0a820f03727b509b887f3216a574062948761f34",
"status": "affected",
"version": "73c3f48230cda01402ae189b05d56f1f7e0d53c9",
"versionType": "git"
},
{
"lessThan": "bbc96bc75de0fcd9bb6ac48798b206e3b09ec865",
"status": "affected",
"version": "73c3f48230cda01402ae189b05d56f1f7e0d53c9",
"versionType": "git"
},
{
"lessThan": "6a5bc8aea111ccbca71ef2b9c868d5c81f2e89de",
"status": "affected",
"version": "73c3f48230cda01402ae189b05d56f1f7e0d53c9",
"versionType": "git"
},
{
"lessThan": "a9cd0e8fb0b21faaa71199d9d3feb305c18ff576",
"status": "affected",
"version": "73c3f48230cda01402ae189b05d56f1f7e0d53c9",
"versionType": "git"
},
{
"lessThan": "abaec6747304581f8d4a9936352fa10e13325f07",
"status": "affected",
"version": "73c3f48230cda01402ae189b05d56f1f7e0d53c9",
"versionType": "git"
},
{
"lessThan": "492c97cb50feaa60ccd7792d3d6b904ed8ec61bf",
"status": "affected",
"version": "73c3f48230cda01402ae189b05d56f1f7e0d53c9",
"versionType": "git"
},
{
"lessThan": "daf2d92669b4a659d805d88d811161c70cd325ee",
"status": "affected",
"version": "73c3f48230cda01402ae189b05d56f1f7e0d53c9",
"versionType": "git"
},
{
"lessThan": "c2d1a2130c93f6d758af58590b86b2254c7a1dec",
"status": "affected",
"version": "73c3f48230cda01402ae189b05d56f1f7e0d53c9",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/test-drivers/vivid/vivid-ctrls.c",
"drivers/media/test-drivers/vivid/vivid-vid-cap.c",
"drivers/media/test-drivers/vivid/vivid-vid-out.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.18"
},
{
"lessThan": "3.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.18",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: vivid: check for vb2_is_busy() when toggling caps\n\nThe vivid_update_format_cap/out() functions must only be called if the\ncapture/output queue are not busy. But for the controls that select\nthe CROP/COMPOSE/SCALE capability that is not checked.\n\nOnly when streaming starts will they be set to \u0027grabbed\u0027 and it is\nimpossible to change the control, but between REQBUFS and STREAMON you\nare still allowed to set these controls. Since vivid_update_format_cap/out\nwill change the format, this can cause unexpected results.\n\nBesides adding these checks, also add a WARN_ON in\nvivid_update_format_cap/out() if the queue is busy.\n\nI\u0027m 90% certain that this is the cause of this syzbot bug:\n\nhttps://syzkaller.appspot.com/bug?extid=dac8f5eaa46837e97b89\n\nBut since we never have reproducers, it is hard to be certain. In any case,\nthese checks are needed regardless."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached purely through local ioctls (VIDIOC_REQBUFS/PREPARE_BUF/S_EXT_CTRLS/STREAMON) on the /dev/videoN character device exposed by the vivid driver. There is no remote or network component.\nAC:L - The attacker fully controls both the initial buffer allocation size and the later geometry change, so the undersized-buffer overflow is produced deterministically by a fixed ioctl sequence with no race or memory-layout precondition.\nPR:L - No capability check exists on the V4L2 control or buffer ioctls; any process able to open /dev/videoN can trigger it, which on desktops/Android and container images with video devices bind-mounted means an ordinary unprivileged user (video group / logind ACL).\nUI:N - The entire sequence is performed by the attacking process itself against a device node it opens; no victim action or cooperation is needed.\nS:U - The corruption stays within the kernel\u0027s own memory and security authority; no VM, IOMMU or sandbox boundary is crossed by the overflow itself.\nC:H - The stale-geometry mismatch also drives out-of-bounds reads on the output path and lets adjacent kernel allocations be read back through the mmap\u0027ed plane, and the resulting heap corruption can be shaped into a broader kernel-memory disclosure primitive.\nI:H - The capture kthread writes a full frame using the enlarged geometry into a plane allocated for the smaller format, giving an out-of-bounds kernel write of attacker-chosen length and largely attacker-influenced (test-pattern) content, which is exploitable for kernel memory corruption.\nA:H - Overwriting memory past the vb2 plane reliably corrupts neighbouring allocations or hits a vmalloc guard page, producing KASAN splats, oopses and kernel panics; the post-fix WARN_ON also panics on panic_on_warn systems."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:23.943Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/0a820f03727b509b887f3216a574062948761f34"
},
{
"url": "https://git.kernel.org/stable/c/bbc96bc75de0fcd9bb6ac48798b206e3b09ec865"
},
{
"url": "https://git.kernel.org/stable/c/6a5bc8aea111ccbca71ef2b9c868d5c81f2e89de"
},
{
"url": "https://git.kernel.org/stable/c/a9cd0e8fb0b21faaa71199d9d3feb305c18ff576"
},
{
"url": "https://git.kernel.org/stable/c/abaec6747304581f8d4a9936352fa10e13325f07"
},
{
"url": "https://git.kernel.org/stable/c/492c97cb50feaa60ccd7792d3d6b904ed8ec61bf"
},
{
"url": "https://git.kernel.org/stable/c/daf2d92669b4a659d805d88d811161c70cd325ee"
},
{
"url": "https://git.kernel.org/stable/c/c2d1a2130c93f6d758af58590b86b2254c7a1dec"
}
],
"title": "media: vivid: check for vb2_is_busy() when toggling caps",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68204",
"datePublished": "2026-08-10T12:00:23.311Z",
"dateReserved": "2026-07-30T09:28:09.374Z",
"dateUpdated": "2026-08-19T16:31:23.943Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68215 (GCVE-0-2026-68215)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: radio-si476x: Unregister v4l2_device on probe failure
si476x_radio_probe() registers radio->v4l2dev before allocating the V4L2
controls and before registering the video device. If any of those later
steps fails, probe returns through the exit label after freeing only the
control handler.
A failed probe does not call si476x_radio_remove(), so the
v4l2_device_unregister() there is not reached. This leaves the parent
device reference taken by v4l2_device_register() behind on the error path.
Unregister the V4L2 device in the probe error path after freeing the
controls.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: b879a9c2a755d4ddf9e685258de6435710fd2f03 Version: b879a9c2a755d4ddf9e685258de6435710fd2f03 Version: b879a9c2a755d4ddf9e685258de6435710fd2f03 Version: b879a9c2a755d4ddf9e685258de6435710fd2f03 Version: b879a9c2a755d4ddf9e685258de6435710fd2f03 Version: b879a9c2a755d4ddf9e685258de6435710fd2f03 Version: b879a9c2a755d4ddf9e685258de6435710fd2f03 Version: b879a9c2a755d4ddf9e685258de6435710fd2f03 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/radio/radio-si476x.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "828f8d2181aa09ff3d8b67e1d9c92d0dfc81026f",
"status": "affected",
"version": "b879a9c2a755d4ddf9e685258de6435710fd2f03",
"versionType": "git"
},
{
"lessThan": "cac1c4f08cb2d8beaad16f7ddc7911f3711daa9f",
"status": "affected",
"version": "b879a9c2a755d4ddf9e685258de6435710fd2f03",
"versionType": "git"
},
{
"lessThan": "7cf393f176317a126d71e88e4b6e25e83499b465",
"status": "affected",
"version": "b879a9c2a755d4ddf9e685258de6435710fd2f03",
"versionType": "git"
},
{
"lessThan": "4ca9c9f12b1bc341a0a3bbbd2090fd182db53771",
"status": "affected",
"version": "b879a9c2a755d4ddf9e685258de6435710fd2f03",
"versionType": "git"
},
{
"lessThan": "7ef9f1659404544a8dddd68842bafcb4a38197af",
"status": "affected",
"version": "b879a9c2a755d4ddf9e685258de6435710fd2f03",
"versionType": "git"
},
{
"lessThan": "64cb15878b35e5574ff4f80a0b613a79e47867ba",
"status": "affected",
"version": "b879a9c2a755d4ddf9e685258de6435710fd2f03",
"versionType": "git"
},
{
"lessThan": "730c235d7d2c80a401dac56b0f5066c889aa442d",
"status": "affected",
"version": "b879a9c2a755d4ddf9e685258de6435710fd2f03",
"versionType": "git"
},
{
"lessThan": "436a693af04ffb889aaf87cb69ec1f2b21d3569c",
"status": "affected",
"version": "b879a9c2a755d4ddf9e685258de6435710fd2f03",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/radio/radio-si476x.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.10"
},
{
"lessThan": "3.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: radio-si476x: Unregister v4l2_device on probe failure\n\nsi476x_radio_probe() registers radio-\u003ev4l2dev before allocating the V4L2\ncontrols and before registering the video device. If any of those later\nsteps fails, probe returns through the exit label after freeing only the\ncontrol handler.\n\nA failed probe does not call si476x_radio_remove(), so the\nv4l2_device_unregister() there is not reached. This leaves the parent\ndevice reference taken by v4l2_device_register() behind on the error path.\n\nUnregister the V4L2 device in the probe error path after freeing the\ncontrols."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:44.648Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/828f8d2181aa09ff3d8b67e1d9c92d0dfc81026f"
},
{
"url": "https://git.kernel.org/stable/c/cac1c4f08cb2d8beaad16f7ddc7911f3711daa9f"
},
{
"url": "https://git.kernel.org/stable/c/7cf393f176317a126d71e88e4b6e25e83499b465"
},
{
"url": "https://git.kernel.org/stable/c/4ca9c9f12b1bc341a0a3bbbd2090fd182db53771"
},
{
"url": "https://git.kernel.org/stable/c/7ef9f1659404544a8dddd68842bafcb4a38197af"
},
{
"url": "https://git.kernel.org/stable/c/64cb15878b35e5574ff4f80a0b613a79e47867ba"
},
{
"url": "https://git.kernel.org/stable/c/730c235d7d2c80a401dac56b0f5066c889aa442d"
},
{
"url": "https://git.kernel.org/stable/c/436a693af04ffb889aaf87cb69ec1f2b21d3569c"
}
],
"title": "media: radio-si476x: Unregister v4l2_device on probe failure",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68215",
"datePublished": "2026-08-10T12:00:34.560Z",
"dateReserved": "2026-07-30T09:28:09.375Z",
"dateUpdated": "2026-08-19T16:31:44.648Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68444 (GCVE-0-2026-68444)
Vulnerability from cvelistv5
Published
2026-08-12 00:07
Modified
2026-08-19 16:35
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
firmware: arm_ffa: Fix NULL dereference in ffa_partition_info_get()
ffa_partition_info_get() passes uuid_str directly to uuid_parse()
without a NULL check. When a caller passes NULL, uuid_parse() ->
__uuid_parse() -> uuid_is_valid() dereferences the pointer, causing
a kernel panic:
| Unable to handle kernel NULL pointer dereference at virtual address
| 0000000000000040
| pc : uuid_parse+0x40/0xac
| lr : ffa_partition_info_get+0x1c/0x94 [arm_ffa]
Add a NULL guard before uuid_parse() so a NULL argument returns
-ENODEV instead of crashing. Callers are expected to always supply
a valid partition UUID, so NULL is not a supported input.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d0c0bce831223b08e5bade2cefc93c3ddb790796 Version: d0c0bce831223b08e5bade2cefc93c3ddb790796 Version: d0c0bce831223b08e5bade2cefc93c3ddb790796 Version: d0c0bce831223b08e5bade2cefc93c3ddb790796 Version: d0c0bce831223b08e5bade2cefc93c3ddb790796 Version: d0c0bce831223b08e5bade2cefc93c3ddb790796 Version: d0c0bce831223b08e5bade2cefc93c3ddb790796 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/firmware/arm_ffa/driver.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "7dfb020e3048411fbca91e9ad6174da9a2d3e2b3",
"status": "affected",
"version": "d0c0bce831223b08e5bade2cefc93c3ddb790796",
"versionType": "git"
},
{
"lessThan": "ddf85f0c32e05baafbd9c3a44859858db90eec48",
"status": "affected",
"version": "d0c0bce831223b08e5bade2cefc93c3ddb790796",
"versionType": "git"
},
{
"lessThan": "86f5ea90f73bb7154593bb96f3411e197f3d4fbe",
"status": "affected",
"version": "d0c0bce831223b08e5bade2cefc93c3ddb790796",
"versionType": "git"
},
{
"lessThan": "7201e56e52d18abf4cd0a2fee45daf9dc08b5b97",
"status": "affected",
"version": "d0c0bce831223b08e5bade2cefc93c3ddb790796",
"versionType": "git"
},
{
"lessThan": "996c5c19d5b5ac5b98a7b5a406b548305841c301",
"status": "affected",
"version": "d0c0bce831223b08e5bade2cefc93c3ddb790796",
"versionType": "git"
},
{
"lessThan": "12a42c610e4432e7708cc48d607e5903fffe0aad",
"status": "affected",
"version": "d0c0bce831223b08e5bade2cefc93c3ddb790796",
"versionType": "git"
},
{
"lessThan": "8ae5f8e4836667fcaffdf2e3c6068b0a8b364dd8",
"status": "affected",
"version": "d0c0bce831223b08e5bade2cefc93c3ddb790796",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/firmware/arm_ffa/driver.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.14"
},
{
"lessThan": "5.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: arm_ffa: Fix NULL dereference in ffa_partition_info_get()\n\nffa_partition_info_get() passes uuid_str directly to uuid_parse()\nwithout a NULL check. When a caller passes NULL, uuid_parse() -\u003e\n__uuid_parse() -\u003e uuid_is_valid() dereferences the pointer, causing\na kernel panic:\n\n | Unable to handle kernel NULL pointer dereference at virtual address\n | 0000000000000040\n | pc : uuid_parse+0x40/0xac\n | lr : ffa_partition_info_get+0x1c/0x94 [arm_ffa]\n\nAdd a NULL guard before uuid_parse() so a NULL argument returns\n-ENODEV instead of crashing. Callers are expected to always supply\na valid partition UUID, so NULL is not a supported input."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:35:38.125Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/7dfb020e3048411fbca91e9ad6174da9a2d3e2b3"
},
{
"url": "https://git.kernel.org/stable/c/ddf85f0c32e05baafbd9c3a44859858db90eec48"
},
{
"url": "https://git.kernel.org/stable/c/86f5ea90f73bb7154593bb96f3411e197f3d4fbe"
},
{
"url": "https://git.kernel.org/stable/c/7201e56e52d18abf4cd0a2fee45daf9dc08b5b97"
},
{
"url": "https://git.kernel.org/stable/c/996c5c19d5b5ac5b98a7b5a406b548305841c301"
},
{
"url": "https://git.kernel.org/stable/c/12a42c610e4432e7708cc48d607e5903fffe0aad"
},
{
"url": "https://git.kernel.org/stable/c/8ae5f8e4836667fcaffdf2e3c6068b0a8b364dd8"
}
],
"title": "firmware: arm_ffa: Fix NULL dereference in ffa_partition_info_get()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68444",
"datePublished": "2026-08-12T00:07:34.609Z",
"dateReserved": "2026-07-30T09:28:09.394Z",
"dateUpdated": "2026-08-19T16:35:38.125Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72308 (GCVE-0-2026-72308)
Vulnerability from cvelistv5
Published
2026-08-15 05:55
Modified
2026-08-23 12:47
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
mlxsw: fix refcount leak in mlxsw_sp_port_lag_join()
When mlxsw_sp_port_lag_index_get() fails, mlxsw_sp_port_lag_join()
returns an error without releasing the lag reference obtained by
the earlier mlxsw_sp_lag_get(). All other error paths in the
function jump to the cleanup label that ends with
mlxsw_sp_lag_put(), so this is a single missed release.
Fix the leak by replacing the bare 'return err' with a goto to the
existing error cleanup label, which will drop the reference safely.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 0d65fc13042fce6a2d6de58ff0dc9531e8523c07 Version: 0d65fc13042fce6a2d6de58ff0dc9531e8523c07 Version: 0d65fc13042fce6a2d6de58ff0dc9531e8523c07 Version: 0d65fc13042fce6a2d6de58ff0dc9531e8523c07 Version: 0d65fc13042fce6a2d6de58ff0dc9531e8523c07 Version: 0d65fc13042fce6a2d6de58ff0dc9531e8523c07 Version: 0d65fc13042fce6a2d6de58ff0dc9531e8523c07 Version: 0d65fc13042fce6a2d6de58ff0dc9531e8523c07 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/mellanox/mlxsw/spectrum.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "3fbeaa8ecd144ad593f9fa1ab4b40a780ad3700b",
"status": "affected",
"version": "0d65fc13042fce6a2d6de58ff0dc9531e8523c07",
"versionType": "git"
},
{
"lessThan": "99ff5b0083eae6f774360c4ea6874604e6c9b553",
"status": "affected",
"version": "0d65fc13042fce6a2d6de58ff0dc9531e8523c07",
"versionType": "git"
},
{
"lessThan": "9bf2d6eea26a226f8ebab7baea6f2b018f914560",
"status": "affected",
"version": "0d65fc13042fce6a2d6de58ff0dc9531e8523c07",
"versionType": "git"
},
{
"lessThan": "8b3350eacd9df0597bfe36a594df7b9def0b3edf",
"status": "affected",
"version": "0d65fc13042fce6a2d6de58ff0dc9531e8523c07",
"versionType": "git"
},
{
"lessThan": "1cf8a1af42b1f12a30b7abd34fe4fc23b3170e7e",
"status": "affected",
"version": "0d65fc13042fce6a2d6de58ff0dc9531e8523c07",
"versionType": "git"
},
{
"lessThan": "2d8b3c3e129973a51ae924bdcf6993a76b828814",
"status": "affected",
"version": "0d65fc13042fce6a2d6de58ff0dc9531e8523c07",
"versionType": "git"
},
{
"lessThan": "cab468c3c03f4bcd7530ce2783a4140da14efb7b",
"status": "affected",
"version": "0d65fc13042fce6a2d6de58ff0dc9531e8523c07",
"versionType": "git"
},
{
"lessThan": "41c8c1d65b32beacd8d916a22457b4f6e47f45af",
"status": "affected",
"version": "0d65fc13042fce6a2d6de58ff0dc9531e8523c07",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/mellanox/mlxsw/spectrum.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.5"
},
{
"lessThan": "4.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmlxsw: fix refcount leak in mlxsw_sp_port_lag_join()\n\nWhen mlxsw_sp_port_lag_index_get() fails, mlxsw_sp_port_lag_join()\nreturns an error without releasing the lag reference obtained by\nthe earlier mlxsw_sp_lag_get(). All other error paths in the\nfunction jump to the cleanup label that ends with\nmlxsw_sp_lag_put(), so this is a single missed release.\n\nFix the leak by replacing the bare \u0027return err\u0027 with a goto to the\nexisting error cleanup label, which will drop the reference safely."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:47:14.564Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/3fbeaa8ecd144ad593f9fa1ab4b40a780ad3700b"
},
{
"url": "https://git.kernel.org/stable/c/99ff5b0083eae6f774360c4ea6874604e6c9b553"
},
{
"url": "https://git.kernel.org/stable/c/9bf2d6eea26a226f8ebab7baea6f2b018f914560"
},
{
"url": "https://git.kernel.org/stable/c/8b3350eacd9df0597bfe36a594df7b9def0b3edf"
},
{
"url": "https://git.kernel.org/stable/c/1cf8a1af42b1f12a30b7abd34fe4fc23b3170e7e"
},
{
"url": "https://git.kernel.org/stable/c/2d8b3c3e129973a51ae924bdcf6993a76b828814"
},
{
"url": "https://git.kernel.org/stable/c/cab468c3c03f4bcd7530ce2783a4140da14efb7b"
},
{
"url": "https://git.kernel.org/stable/c/41c8c1d65b32beacd8d916a22457b4f6e47f45af"
}
],
"title": "mlxsw: fix refcount leak in mlxsw_sp_port_lag_join()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72308",
"datePublished": "2026-08-15T05:55:25.260Z",
"dateReserved": "2026-08-09T03:40:39.918Z",
"dateUpdated": "2026-08-23T12:47:14.564Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68104 (GCVE-0-2026-68104)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-19 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: invoke pm_genpd_remove() before freeing genpd
Call pm_genpd_remove() to unregister from global list prior to releasing
acp_genpd memory, and clear the pointer after free.
(cherry picked from commit cd8650d7a91ee8b768e202354672553faa5cc1f2)
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 25030321ba2860c56651429a4f28d94a6483d952 Version: 25030321ba2860c56651429a4f28d94a6483d952 Version: 25030321ba2860c56651429a4f28d94a6483d952 Version: 25030321ba2860c56651429a4f28d94a6483d952 Version: 25030321ba2860c56651429a4f28d94a6483d952 Version: 25030321ba2860c56651429a4f28d94a6483d952 Version: 25030321ba2860c56651429a4f28d94a6483d952 Version: 25030321ba2860c56651429a4f28d94a6483d952 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/amdgpu_acp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "4d7c10b0bf09d90c81818752decbdb1966b62702",
"status": "affected",
"version": "25030321ba2860c56651429a4f28d94a6483d952",
"versionType": "git"
},
{
"lessThan": "493adf29d66f23888f0e29888b6bc9512acd0825",
"status": "affected",
"version": "25030321ba2860c56651429a4f28d94a6483d952",
"versionType": "git"
},
{
"lessThan": "2e406b86144c1f732eb344f1f1e09043856cfc33",
"status": "affected",
"version": "25030321ba2860c56651429a4f28d94a6483d952",
"versionType": "git"
},
{
"lessThan": "bdfc7f1e0900ef1361b828c4f69b72701f8a0a86",
"status": "affected",
"version": "25030321ba2860c56651429a4f28d94a6483d952",
"versionType": "git"
},
{
"lessThan": "5c0a82283271759fff445ac27182072f200a888c",
"status": "affected",
"version": "25030321ba2860c56651429a4f28d94a6483d952",
"versionType": "git"
},
{
"lessThan": "08fee493e0261f9e4120a5c8e7e42e8a723574e8",
"status": "affected",
"version": "25030321ba2860c56651429a4f28d94a6483d952",
"versionType": "git"
},
{
"lessThan": "930a5dc3df4aa5e10393134bd5313d616dbebaf6",
"status": "affected",
"version": "25030321ba2860c56651429a4f28d94a6483d952",
"versionType": "git"
},
{
"lessThan": "28c9b3c5dc35cc790d11e26ca3fc6e068be63998",
"status": "affected",
"version": "25030321ba2860c56651429a4f28d94a6483d952",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/amdgpu_acp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.6"
},
{
"lessThan": "4.6",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: invoke pm_genpd_remove() before freeing genpd\n\nCall pm_genpd_remove() to unregister from global list prior to releasing\nacp_genpd memory, and clear the pointer after free.\n\n(cherry picked from commit cd8650d7a91ee8b768e202354672553faa5cc1f2)"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is in acp_hw_fini during amdgpu driver teardown (amdgpu_pci_remove/amdgpu_driver_unload_kms), reachable via local PCI unbind/module unload or a failed amdgpu init cleanup after opening a DRM render node; there is no network-facing entry point.\nAC:L - Once the AMDGPU ACP block has been initialized, calling acp_hw_fini deterministically frees acp_genpd without unregistering it from the global genpd list; no race or special memory layout is required to leave a dangling list entry.\nPR:L - Unprivileged users with access to /dev/dri/renderD* can autoload amdgpu and trigger the fini path if initialization fails after ACP setup; the same bug also fires on privileged driver unload/hot-unplug teardown of AMDGPU on ACP-capable APUs (Carrizo/Stoney).\nUI:N - Exploitation does not require any victim interaction such as clicking links or mounting filesystems; triggering driver teardown or a failed init cleanup is sufficient once the attacker can open the DRM device or unload the driver.\nS:U - The use-after-free corrupts kernel heap metadata/objects in the same kernel security domain during AMDGPU/ACP teardown; it does not by itself cross VM, container, or IOMMU boundaries to impact a separate authority.\nC:H - Freeing the generic_pm_domain while it remains linked on the global gpd_list is a kernel use-after-free; subsequent genpd list walks can read attacker-influenced freed memory, enabling information disclosure and kernel pointer leaks.\nI:H - The dangling genpd entry allows the power-domain core to perform reads/writes through a freed acp_pm_domain/generic_pm_domain object, providing a standard heap UAF primitive that can be developed into arbitrary kernel memory corruption or code execution.\nA:H - Dereferencing the freed genpd from the global list during later power-management operations can cause kernel oops/panic or hang, and the UAF can be leveraged for a reliable denial-of-service even when full exploitation is not attempted."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:29:17.502Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/4d7c10b0bf09d90c81818752decbdb1966b62702"
},
{
"url": "https://git.kernel.org/stable/c/493adf29d66f23888f0e29888b6bc9512acd0825"
},
{
"url": "https://git.kernel.org/stable/c/2e406b86144c1f732eb344f1f1e09043856cfc33"
},
{
"url": "https://git.kernel.org/stable/c/bdfc7f1e0900ef1361b828c4f69b72701f8a0a86"
},
{
"url": "https://git.kernel.org/stable/c/5c0a82283271759fff445ac27182072f200a888c"
},
{
"url": "https://git.kernel.org/stable/c/08fee493e0261f9e4120a5c8e7e42e8a723574e8"
},
{
"url": "https://git.kernel.org/stable/c/930a5dc3df4aa5e10393134bd5313d616dbebaf6"
},
{
"url": "https://git.kernel.org/stable/c/28c9b3c5dc35cc790d11e26ca3fc6e068be63998"
}
],
"title": "drm/amdgpu: invoke pm_genpd_remove() before freeing genpd",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68104",
"datePublished": "2026-08-10T11:58:20.614Z",
"dateReserved": "2026-07-30T09:28:09.368Z",
"dateUpdated": "2026-08-19T16:29:17.502Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2025-40064 (GCVE-0-2025-40064)
Vulnerability from cvelistv5
Published
2025-10-28 11:48
Modified
2026-09-02 12:49
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
smc: Fix use-after-free in __pnet_find_base_ndev().
syzbot reported use-after-free of net_device in __pnet_find_base_ndev(),
which was called during connect(). [0]
smc_pnet_find_ism_resource() fetches sk_dst_get(sk)->dev and passes
down to pnet_find_base_ndev(), where RTNL is held. Then, UAF happened
at __pnet_find_base_ndev() when the dev is first used.
This means dev had already been freed before acquiring RTNL in
pnet_find_base_ndev().
While dev is going away, dst->dev could be swapped with blackhole_netdev,
and the dev's refcnt by dst will be released.
We must hold dev's refcnt before calling smc_pnet_find_ism_resource().
Also, smc_pnet_find_roce_resource() has the same problem.
Let's use __sk_dst_get() and dst_dev_rcu() in the two functions.
[0]:
BUG: KASAN: use-after-free in __pnet_find_base_ndev+0x1b1/0x1c0 net/smc/smc_pnet.c:926
Read of size 1 at addr ffff888036bac33a by task syz.0.3632/18609
CPU: 1 UID: 0 PID: 18609 Comm: syz.0.3632 Not tainted syzkaller #0 PREEMPT(full)
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/18/2025
Call Trace:
<TASK>
dump_stack_lvl+0x189/0x250 lib/dump_stack.c:120
print_address_description mm/kasan/report.c:378 [inline]
print_report+0xca/0x240 mm/kasan/report.c:482
kasan_report+0x118/0x150 mm/kasan/report.c:595
__pnet_find_base_ndev+0x1b1/0x1c0 net/smc/smc_pnet.c:926
pnet_find_base_ndev net/smc/smc_pnet.c:946 [inline]
smc_pnet_find_ism_by_pnetid net/smc/smc_pnet.c:1103 [inline]
smc_pnet_find_ism_resource+0xef/0x390 net/smc/smc_pnet.c:1154
smc_find_ism_device net/smc/af_smc.c:1030 [inline]
smc_find_proposal_devices net/smc/af_smc.c:1115 [inline]
__smc_connect+0x372/0x1890 net/smc/af_smc.c:1545
smc_connect+0x877/0xd90 net/smc/af_smc.c:1715
__sys_connect_file net/socket.c:2086 [inline]
__sys_connect+0x313/0x440 net/socket.c:2105
__do_sys_connect net/socket.c:2111 [inline]
__se_sys_connect net/socket.c:2108 [inline]
__x64_sys_connect+0x7a/0x90 net/socket.c:2108
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0xfa/0x3b0 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7f47cbf8eba9
Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007f47ccdb1038 EFLAGS: 00000246 ORIG_RAX: 000000000000002a
RAX: ffffffffffffffda RBX: 00007f47cc1d5fa0 RCX: 00007f47cbf8eba9
RDX: 0000000000000010 RSI: 0000200000000280 RDI: 000000000000000b
RBP: 00007f47cc011e19 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 00007f47cc1d6038 R14: 00007f47cc1d5fa0 R15: 00007ffc512f8aa8
</TASK>
The buggy address belongs to the physical page:
page: refcount:0 mapcount:0 mapping:0000000000000000 index:0xffff888036bacd00 pfn:0x36bac
flags: 0xfff00000000000(node=0|zone=1|lastcpupid=0x7ff)
raw: 00fff00000000000 ffffea0001243d08 ffff8880b863fdc0 0000000000000000
raw: ffff888036bacd00 0000000000000000 00000000ffffffff 0000000000000000
page dumped because: kasan: bad access detected
page_owner tracks the page as freed
page last allocated via order 2, migratetype Unmovable, gfp_mask 0x446dc0(GFP_KERNEL_ACCOUNT|__GFP_ZERO|__GFP_NOWARN|__GFP_RETRY_MAYFAIL|__GFP_COMP), pid 16741, tgid 16741 (syz-executor), ts 343313197788, free_ts 380670750466
set_page_owner include/linux/page_owner.h:32 [inline]
post_alloc_hook+0x240/0x2a0 mm/page_alloc.c:1851
prep_new_page mm/page_alloc.c:1859 [inline]
get_page_from_freelist+0x21e4/0x22c0 mm/page_alloc.c:3858
__alloc_frozen_pages_noprof+0x181/0x370 mm/page_alloc.c:5148
alloc_pages_mpol+0x232/0x4a0 mm/mempolicy.c:2416
___kmalloc_large_node+0x5f/0x1b0 mm/slub.c:4317
__kmalloc_large_node_noprof+0x18/0x90 mm/slub.c:4348
__do_kmalloc_node mm/slub.c:4364 [inline]
__kvmalloc_node
---truncated---
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2025-40064",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-06-16T19:39:09.971835Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-06-16T19:40:55.918Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/smc/smc_pnet.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "005a7173d8e4710646043a681af36f79ce05a29b",
"status": "affected",
"version": "0afff91c6f5ecef27715ea71e34dc2baacba1060",
"versionType": "git"
},
{
"lessThan": "302dbed4760bcd19a661cc1c282d91bb7481307e",
"status": "affected",
"version": "0afff91c6f5ecef27715ea71e34dc2baacba1060",
"versionType": "git"
},
{
"lessThan": "08aca586482e88aab9616a3e81bc36cad22674a5",
"status": "affected",
"version": "0afff91c6f5ecef27715ea71e34dc2baacba1060",
"versionType": "git"
},
{
"lessThan": "233927b645cb7a14bb98d23ac72e4c7243a9f0d9",
"status": "affected",
"version": "0afff91c6f5ecef27715ea71e34dc2baacba1060",
"versionType": "git"
},
{
"lessThan": "3d3466878afd8d43ec0ca2facfbc7f03e40d0f79",
"status": "affected",
"version": "0afff91c6f5ecef27715ea71e34dc2baacba1060",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/smc/smc_pnet.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.19"
},
{
"lessThan": "4.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.187",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.156",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.108",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.17.*",
"status": "unaffected",
"version": "6.17.3",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "6.18",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.187",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.156",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.108",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.17.3",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18",
"versionStartIncluding": "4.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmc: Fix use-after-free in __pnet_find_base_ndev().\n\nsyzbot reported use-after-free of net_device in __pnet_find_base_ndev(),\nwhich was called during connect(). [0]\n\nsmc_pnet_find_ism_resource() fetches sk_dst_get(sk)-\u003edev and passes\ndown to pnet_find_base_ndev(), where RTNL is held. Then, UAF happened\nat __pnet_find_base_ndev() when the dev is first used.\n\nThis means dev had already been freed before acquiring RTNL in\npnet_find_base_ndev().\n\nWhile dev is going away, dst-\u003edev could be swapped with blackhole_netdev,\nand the dev\u0027s refcnt by dst will be released.\n\nWe must hold dev\u0027s refcnt before calling smc_pnet_find_ism_resource().\n\nAlso, smc_pnet_find_roce_resource() has the same problem.\n\nLet\u0027s use __sk_dst_get() and dst_dev_rcu() in the two functions.\n\n[0]:\nBUG: KASAN: use-after-free in __pnet_find_base_ndev+0x1b1/0x1c0 net/smc/smc_pnet.c:926\nRead of size 1 at addr ffff888036bac33a by task syz.0.3632/18609\n\nCPU: 1 UID: 0 PID: 18609 Comm: syz.0.3632 Not tainted syzkaller #0 PREEMPT(full)\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/18/2025\nCall Trace:\n \u003cTASK\u003e\n dump_stack_lvl+0x189/0x250 lib/dump_stack.c:120\n print_address_description mm/kasan/report.c:378 [inline]\n print_report+0xca/0x240 mm/kasan/report.c:482\n kasan_report+0x118/0x150 mm/kasan/report.c:595\n __pnet_find_base_ndev+0x1b1/0x1c0 net/smc/smc_pnet.c:926\n pnet_find_base_ndev net/smc/smc_pnet.c:946 [inline]\n smc_pnet_find_ism_by_pnetid net/smc/smc_pnet.c:1103 [inline]\n smc_pnet_find_ism_resource+0xef/0x390 net/smc/smc_pnet.c:1154\n smc_find_ism_device net/smc/af_smc.c:1030 [inline]\n smc_find_proposal_devices net/smc/af_smc.c:1115 [inline]\n __smc_connect+0x372/0x1890 net/smc/af_smc.c:1545\n smc_connect+0x877/0xd90 net/smc/af_smc.c:1715\n __sys_connect_file net/socket.c:2086 [inline]\n __sys_connect+0x313/0x440 net/socket.c:2105\n __do_sys_connect net/socket.c:2111 [inline]\n __se_sys_connect net/socket.c:2108 [inline]\n __x64_sys_connect+0x7a/0x90 net/socket.c:2108\n do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]\n do_syscall_64+0xfa/0x3b0 arch/x86/entry/syscall_64.c:94\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\nRIP: 0033:0x7f47cbf8eba9\nCode: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 \u003c48\u003e 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48\nRSP: 002b:00007f47ccdb1038 EFLAGS: 00000246 ORIG_RAX: 000000000000002a\nRAX: ffffffffffffffda RBX: 00007f47cc1d5fa0 RCX: 00007f47cbf8eba9\nRDX: 0000000000000010 RSI: 0000200000000280 RDI: 000000000000000b\nRBP: 00007f47cc011e19 R08: 0000000000000000 R09: 0000000000000000\nR10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000\nR13: 00007f47cc1d6038 R14: 00007f47cc1d5fa0 R15: 00007ffc512f8aa8\n \u003c/TASK\u003e\n\nThe buggy address belongs to the physical page:\npage: refcount:0 mapcount:0 mapping:0000000000000000 index:0xffff888036bacd00 pfn:0x36bac\nflags: 0xfff00000000000(node=0|zone=1|lastcpupid=0x7ff)\nraw: 00fff00000000000 ffffea0001243d08 ffff8880b863fdc0 0000000000000000\nraw: ffff888036bacd00 0000000000000000 00000000ffffffff 0000000000000000\npage dumped because: kasan: bad access detected\npage_owner tracks the page as freed\npage last allocated via order 2, migratetype Unmovable, gfp_mask 0x446dc0(GFP_KERNEL_ACCOUNT|__GFP_ZERO|__GFP_NOWARN|__GFP_RETRY_MAYFAIL|__GFP_COMP), pid 16741, tgid 16741 (syz-executor), ts 343313197788, free_ts 380670750466\n set_page_owner include/linux/page_owner.h:32 [inline]\n post_alloc_hook+0x240/0x2a0 mm/page_alloc.c:1851\n prep_new_page mm/page_alloc.c:1859 [inline]\n get_page_from_freelist+0x21e4/0x22c0 mm/page_alloc.c:3858\n __alloc_frozen_pages_noprof+0x181/0x370 mm/page_alloc.c:5148\n alloc_pages_mpol+0x232/0x4a0 mm/mempolicy.c:2416\n ___kmalloc_large_node+0x5f/0x1b0 mm/slub.c:4317\n __kmalloc_large_node_noprof+0x18/0x90 mm/slub.c:4348\n __do_kmalloc_node mm/slub.c:4364 [inline]\n __kvmalloc_node\n---truncated---"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerability is triggered through the connect() syscall on a locally created AF_SMC socket, combined with locally driven netdev teardown (rtnl_dellink) to free the device. Although the same helpers are also reached from the server-side listen path, the freeing side of the race is not remotely controllable, so local access is the realistic delivery vector.\nAC:L - The attacker controls both sides of the race: they create the netdev and route in their own network namespace, initiate the SMC connect that caches the dst, and delete the device concurrently; the reader blocks on rtnl_lock held by the deleting task and dereferences the device immediately after netdev_run_todo() frees it, making the window wide and the trigger reliably repeatable in a loop.\nPR:L - No capability check exists on AF_SMC socket creation and the module autoloads via net-pf-43 for unprivileged users; the netdev create/delete side needs only CAP_NET_ADMIN inside a user+network namespace obtainable with unshare -Urn by any unprivileged local user.\nUI:N - The attacker performs every step \u2014 socket creation, local SMC listener, connect, and device deletion \u2014 with no action required from any other user or administrator.\nS:U - The use-after-free corrupts kernel memory within the same kernel security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - The freed net_device is read and its adj_list is walked, yielding an attacker-influenceable pointer that is further dereferenced (dev.parent, dev_port, dev_net()-\u003enet_generic()); with a page-level heap spray of the freed kvmalloc allocation this provides an arbitrary-read oriented primitive over kernel memory.\nI:H - Controlling the freed net_device contents lets the attacker steer base_ndev to a crafted address that is then used for mutex_lock(\u0026pnettable-\u003elock) and list traversal, giving a controlled write/corruption primitive suitable for privilege escalation.\nA:H - The use-after-free reliably produces a KASAN-detected invalid access and, on production kernels, wild-pointer dereferences leading to kernel oops or panic, and it can be re-triggered at will."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-02T12:49:24.811Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/005a7173d8e4710646043a681af36f79ce05a29b"
},
{
"url": "https://git.kernel.org/stable/c/302dbed4760bcd19a661cc1c282d91bb7481307e"
},
{
"url": "https://git.kernel.org/stable/c/08aca586482e88aab9616a3e81bc36cad22674a5"
},
{
"url": "https://git.kernel.org/stable/c/233927b645cb7a14bb98d23ac72e4c7243a9f0d9"
},
{
"url": "https://git.kernel.org/stable/c/3d3466878afd8d43ec0ca2facfbc7f03e40d0f79"
}
],
"title": "smc: Fix use-after-free in __pnet_find_base_ndev().",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2025-40064",
"datePublished": "2025-10-28T11:48:35.155Z",
"dateReserved": "2025-04-16T07:20:57.159Z",
"dateUpdated": "2026-09-02T12:49:24.811Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2025-68794 (GCVE-0-2025-68794)
Vulnerability from cvelistv5
Published
2026-01-13 15:29
Modified
2026-08-27 12:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
iomap: adjust read range correctly for non-block-aligned positions
iomap_adjust_read_range() assumes that the position and length passed in
are block-aligned. This is not always the case however, as shown in the
syzbot generated case for erofs. This causes too many bytes to be
skipped for uptodate blocks, which results in returning the incorrect
position and length to read in. If all the blocks are uptodate, this
underflows length and returns a position beyond the folio.
Fix the calculation to also take into account the block offset when
calculating how many bytes can be skipped for uptodate blocks.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 9dc55f1389f9569acf9659e58dd836a9c70df217 Version: 9dc55f1389f9569acf9659e58dd836a9c70df217 Version: 9dc55f1389f9569acf9659e58dd836a9c70df217 Version: 9dc55f1389f9569acf9659e58dd836a9c70df217 Version: 9dc55f1389f9569acf9659e58dd836a9c70df217 Version: 9dc55f1389f9569acf9659e58dd836a9c70df217 Version: 9dc55f1389f9569acf9659e58dd836a9c70df217 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/iomap/buffered-io.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ce20f49ac9194cf81a77f01d1c316d7c17ae753c",
"status": "affected",
"version": "9dc55f1389f9569acf9659e58dd836a9c70df217",
"versionType": "git"
},
{
"lessThan": "275b37a1e5c2c8abd313e8075f6aec9a349f291b",
"status": "affected",
"version": "9dc55f1389f9569acf9659e58dd836a9c70df217",
"versionType": "git"
},
{
"lessThan": "b8c9f25fd84328c5fcc4f70c6d1e8f1d4787eaac",
"status": "affected",
"version": "9dc55f1389f9569acf9659e58dd836a9c70df217",
"versionType": "git"
},
{
"lessThan": "82b60ffbb532d919959702768dca04c3c0500ae5",
"status": "affected",
"version": "9dc55f1389f9569acf9659e58dd836a9c70df217",
"versionType": "git"
},
{
"lessThan": "12053695c8ef5410e8cc6c9ed4c0db9cd9c82b3e",
"status": "affected",
"version": "9dc55f1389f9569acf9659e58dd836a9c70df217",
"versionType": "git"
},
{
"lessThan": "142194fb21afe964d2d194cab1fc357cbf87e899",
"status": "affected",
"version": "9dc55f1389f9569acf9659e58dd836a9c70df217",
"versionType": "git"
},
{
"lessThan": "7aa6bc3e8766990824f66ca76c19596ce10daf3e",
"status": "affected",
"version": "9dc55f1389f9569acf9659e58dd836a9c70df217",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/iomap/buffered-io.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.19"
},
{
"lessThan": "4.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.267",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.218",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.185",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.120",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.64",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.3",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "6.19",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.267",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.218",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.185",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.120",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.64",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.3",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.19",
"versionStartIncluding": "4.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\niomap: adjust read range correctly for non-block-aligned positions\n\niomap_adjust_read_range() assumes that the position and length passed in\nare block-aligned. This is not always the case however, as shown in the\nsyzbot generated case for erofs. This causes too many bytes to be\nskipped for uptodate blocks, which results in returning the incorrect\nposition and length to read in. If all the blocks are uptodate, this\nunderflows length and returns a position beyond the folio.\n\nFix the calculation to also take into account the block offset when\ncalculating how many bytes can be skipped for uptodate blocks."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - EROFS supports NFS export, allowing a remote NFS READ request to reach nfsd, filemap, erofs_read_folio or erofs_readahead, and the vulnerable iomap function.\nAC:L - The underflow is deterministic once a non-block-aligned range intersects leading uptodate blocks; no race or condition outside the attacker\u2019s control is required.\nPR:N - A public NFS export can accept RPC_AUTH_NULL, map the requester to the anonymous identity, and permit access to a world-readable trigger file without authentication.\nUI:N - The remote attacker directly triggers the vulnerable reads, including any repetitions needed to establish partial-uptodate state, without victim action.\nS:U - The corruption compromises the kernel and resources governed by the same host security authority, without inherently crossing a VM, IOMMU, or other scope boundary.\nC:H - The underflow can create an almost-4-GiB BIO vector spanning unrelated physical pages; the resulting kernel memory corruption can support code execution and arbitrary information disclosure.\nI:H - Attacker-controlled filesystem data can be read through the malformed BIO into unrelated kernel memory, providing a powerful corruption primitive capable of control-flow hijacking.\nA:H - Hole or post-EOF paths reach bounds BUG_ON checks, while mapped paths can corrupt extensive kernel memory, either of which can panic or otherwise crash the system."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T12:39:37.848Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ce20f49ac9194cf81a77f01d1c316d7c17ae753c"
},
{
"url": "https://git.kernel.org/stable/c/275b37a1e5c2c8abd313e8075f6aec9a349f291b"
},
{
"url": "https://git.kernel.org/stable/c/b8c9f25fd84328c5fcc4f70c6d1e8f1d4787eaac"
},
{
"url": "https://git.kernel.org/stable/c/82b60ffbb532d919959702768dca04c3c0500ae5"
},
{
"url": "https://git.kernel.org/stable/c/12053695c8ef5410e8cc6c9ed4c0db9cd9c82b3e"
},
{
"url": "https://git.kernel.org/stable/c/142194fb21afe964d2d194cab1fc357cbf87e899"
},
{
"url": "https://git.kernel.org/stable/c/7aa6bc3e8766990824f66ca76c19596ce10daf3e"
}
],
"title": "iomap: adjust read range correctly for non-block-aligned positions",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2025-68794",
"datePublished": "2026-01-13T15:29:05.553Z",
"dateReserved": "2025-12-24T10:30:51.037Z",
"dateUpdated": "2026-08-27T12:39:37.848Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74612 (GCVE-0-2026-74612)
Vulnerability from cvelistv5
Published
2026-08-22 15:31
Modified
2026-08-25 05:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
veth: fix skb length accounting after XDP frag adjustment
veth exposes non-linear skb fragments through an xdp_buff. If an XDP
program adjusts the fragment area, veth_xdp_rcv_skb() copies
xdp_frags_size back to skb->data_len but leaves skb->len containing the
old fragment contribution.
After a fragment shrink, this makes skb_headlen() larger than the actual
linear area. In the reproduced UDP receive path, __skb_datagram_iter()
copied 1024 bytes past the actual linear tail to userspace, starting at
struct skb_shared_info. The copied bytes included the affected skb's
nr_frags, xdp_frags_size, and a kernel pointer from
skb_shinfo(skb)->frags[0]. Real packet data was displaced by the same
amount and truncated at the end.
Subtract the old data_len before replacing it and add the new data_len
afterwards, keeping skb->len and skb->data_len synchronized.
Additionally, bpf_xdp_pull_data() can advance data_end while leaving
frags present. The skb is then still non-linear, so the old
__skb_put(skb, off) triggers SKB_LINEAR_ASSERT().
Use skb_set_tail_pointer() and update skb->len explicitly instead,
following bpf_prog_run_generic_xdp(). Unlike __skb_put(),
skb_set_tail_pointer() does not require a linear skb.
A 60000-byte UDP datagram on a veth pair with MTU 64000 was shortened by
1024 bytes from its fragment area. Before the fix, all 10 runs produced
corrupted payloads. After the fix, all 10 runs matched the expected
payload exactly. A forced-tailroom reproducer also exercises
bpf_xdp_pull_data() with frags still present; the old code triggers
SKB_LINEAR_ASSERT(), while this fix passes 10/10 runs.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 718a18a0c8a67f97781e40bdef7cdd055c430996 Version: 718a18a0c8a67f97781e40bdef7cdd055c430996 Version: 718a18a0c8a67f97781e40bdef7cdd055c430996 Version: 718a18a0c8a67f97781e40bdef7cdd055c430996 Version: 718a18a0c8a67f97781e40bdef7cdd055c430996 Version: 718a18a0c8a67f97781e40bdef7cdd055c430996 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/veth.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "0c3024afabb8064b141f3cedcb1ddd6ab05ad9d5",
"status": "affected",
"version": "718a18a0c8a67f97781e40bdef7cdd055c430996",
"versionType": "git"
},
{
"lessThan": "2f2a7f3f8b9f1bffc9b0488aa02b6951b2aec139",
"status": "affected",
"version": "718a18a0c8a67f97781e40bdef7cdd055c430996",
"versionType": "git"
},
{
"lessThan": "41b96667d42b74bb4b137f1bb78b611a953c5943",
"status": "affected",
"version": "718a18a0c8a67f97781e40bdef7cdd055c430996",
"versionType": "git"
},
{
"lessThan": "cdf745b7a777f87f51666e5d8f4c6fc279bcf54d",
"status": "affected",
"version": "718a18a0c8a67f97781e40bdef7cdd055c430996",
"versionType": "git"
},
{
"lessThan": "3205b0652a37255dbb7ca8f3d942c8d8aa677c21",
"status": "affected",
"version": "718a18a0c8a67f97781e40bdef7cdd055c430996",
"versionType": "git"
},
{
"lessThan": "cb6379feaaff11c4e1e79c26c745ffa23182768a",
"status": "affected",
"version": "718a18a0c8a67f97781e40bdef7cdd055c430996",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/veth.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.18"
},
{
"lessThan": "5.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.18",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nveth: fix skb length accounting after XDP frag adjustment\n\nveth exposes non-linear skb fragments through an xdp_buff. If an XDP\nprogram adjusts the fragment area, veth_xdp_rcv_skb() copies\nxdp_frags_size back to skb-\u003edata_len but leaves skb-\u003elen containing the\nold fragment contribution.\n\nAfter a fragment shrink, this makes skb_headlen() larger than the actual\nlinear area. In the reproduced UDP receive path, __skb_datagram_iter()\ncopied 1024 bytes past the actual linear tail to userspace, starting at\nstruct skb_shared_info. The copied bytes included the affected skb\u0027s\nnr_frags, xdp_frags_size, and a kernel pointer from\nskb_shinfo(skb)-\u003efrags[0]. Real packet data was displaced by the same\namount and truncated at the end.\n\nSubtract the old data_len before replacing it and add the new data_len\nafterwards, keeping skb-\u003elen and skb-\u003edata_len synchronized.\n\nAdditionally, bpf_xdp_pull_data() can advance data_end while leaving\nfrags present. The skb is then still non-linear, so the old\n__skb_put(skb, off) triggers SKB_LINEAR_ASSERT().\n\nUse skb_set_tail_pointer() and update skb-\u003elen explicitly instead,\nfollowing bpf_prog_run_generic_xdp(). Unlike __skb_put(),\nskb_set_tail_pointer() does not require a linear skb.\n\nA 60000-byte UDP datagram on a veth pair with MTU 64000 was shortened by\n1024 bytes from its fragment area. Before the fix, all 10 runs produced\ncorrupted payloads. After the fix, all 10 runs matched the expected\npayload exactly. A forced-tailroom reproducer also exercises\nbpf_xdp_pull_data() with frags still present; the old code triggers\nSKB_LINEAR_ASSERT(), while this fix passes 10/10 runs."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 10,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - Remote packets routed through container/host veth pairs reach veth_xdp_rcv_skb() after veth_xmit on the peer; cloud and edge nodes routinely forward Internet traffic across veth links with XDP attached, matching the reproduced UDP receive path.\nAC:L - The fix commit shows 10/10 reliable reproduction with a 60000-byte UDP datagram and XDP bpf_xdp_adjust_tail()/bpf_xdp_pull_data() fragment shrink; the attacker controls packet size, timing, and both veth ends without races or uncontrollable kernel state.\nPR:N - Exploitation only requires an XDP program using bpf_xdp_adjust_tail or bpf_xdp_pull_data to already be attached on a reachable veth peer; the remote packet sender needs no local account, capabilities, or authentication to trigger the bad skb length accounting.\nUI:N - No victim interaction is needed beyond normal always-on packet reception and socket delivery; corrupted payloads and leaked kernel metadata are produced automatically when a userspace process reads the affected datagram.\nS:C - veth links intentionally cross container/host network namespaces on multi-tenant servers, and skb_shared_info metadata plus kernel pointers leaked into a tenant userspace recv buffer exceed that tenant\u0027s authorized security boundary.\nC:H - Desynchronized skb-\u003elen makes skb_headlen() exceed the real linear tail, so __skb_datagram_iter() copies up to 1024 bytes past the skb into userspace, exposing nr_frags, xdp_frags_size, and a kernel pointer from skb_shinfo(skb)-\u003efrags[0].\nI:H - The same length mismatch inflates the linear region, displacing and truncating real datagram bytes in the delivered UDP buffer and corrupting application-visible data beyond intended packet bounds while compounding misuse of leaked kernel metadata.\nA:H - bpf_xdp_pull_data() can leave frags present while the old __skb_put() path hits SKB_LINEAR_ASSERT()/BUG_ON on nonlinear skbs; the commit reports deterministic kernel asserts and crashes in addition to datagram corruption."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:40:38.488Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/0c3024afabb8064b141f3cedcb1ddd6ab05ad9d5"
},
{
"url": "https://git.kernel.org/stable/c/2f2a7f3f8b9f1bffc9b0488aa02b6951b2aec139"
},
{
"url": "https://git.kernel.org/stable/c/41b96667d42b74bb4b137f1bb78b611a953c5943"
},
{
"url": "https://git.kernel.org/stable/c/cdf745b7a777f87f51666e5d8f4c6fc279bcf54d"
},
{
"url": "https://git.kernel.org/stable/c/3205b0652a37255dbb7ca8f3d942c8d8aa677c21"
},
{
"url": "https://git.kernel.org/stable/c/cb6379feaaff11c4e1e79c26c745ffa23182768a"
}
],
"title": "veth: fix skb length accounting after XDP frag adjustment",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74612",
"datePublished": "2026-08-22T15:31:58.295Z",
"dateReserved": "2026-08-15T05:44:03.920Z",
"dateUpdated": "2026-08-25T05:40:38.488Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74671 (GCVE-0-2026-74671)
Vulnerability from cvelistv5
Published
2026-08-22 15:32
Modified
2026-08-22 15:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ima: fix out-of-bounds read in xattr_verify()
The digest-length check in xattr_verify() mixes int and size_t:
if (xattr_len - sizeof(xattr_value->type) - hash_start >=
iint->ima_hash->length)
sizeof() yields size_t, so the usual arithmetic conversions promote
the whole left-hand side to unsigned 64-bit before the subtraction
runs. For a truncated xattr this underflows instead of going negative:
a 1-byte IMA_XATTR_DIGEST_NG xattr (xattr_len == 1, hash_start == 1)
turns "1 - 1 - 1" into SIZE_MAX, which is trivially >= ima_hash->length.
The check then passes and the following memcmp() reads
iint->ima_hash->length bytes starting past the end of the buffer
vfs_getxattr_alloc() allocated for it.
Nothing upstream clamps xattr_len back into a safe range first:
ima_get_hash_algo() only special-cases xattr_len < 2 to pick a default
algorithm, and evm_verifyxattr() returns INTEGRITY_UNKNOWN rather than
failing when no HMAC key is loaded, so a truncated security.ima value
reaches the length check as-is.
Rewrite the comparison so every operand stays a signed int and no
implicit conversion to size_t can occur.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 3ea7a56067e663278470c04fd655adf809e72d4d Version: 3ea7a56067e663278470c04fd655adf809e72d4d Version: 3ea7a56067e663278470c04fd655adf809e72d4d Version: 3ea7a56067e663278470c04fd655adf809e72d4d Version: 3ea7a56067e663278470c04fd655adf809e72d4d Version: 3ea7a56067e663278470c04fd655adf809e72d4d Version: 3ea7a56067e663278470c04fd655adf809e72d4d Version: 3ea7a56067e663278470c04fd655adf809e72d4d |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"security/integrity/ima/ima_appraise.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "d823b5f4557083d1dd92096f796a78a2b1b06d10",
"status": "affected",
"version": "3ea7a56067e663278470c04fd655adf809e72d4d",
"versionType": "git"
},
{
"lessThan": "caeb105c15ea2431fa8da7ecfa242d0c68272426",
"status": "affected",
"version": "3ea7a56067e663278470c04fd655adf809e72d4d",
"versionType": "git"
},
{
"lessThan": "a784b4732ac7e51862b9b210c2d8b2ab9e83568c",
"status": "affected",
"version": "3ea7a56067e663278470c04fd655adf809e72d4d",
"versionType": "git"
},
{
"lessThan": "b6cb134707a2127d90a58d69dd818679cae8033c",
"status": "affected",
"version": "3ea7a56067e663278470c04fd655adf809e72d4d",
"versionType": "git"
},
{
"lessThan": "7e515b6c9aab452a4f0734bd7208e4e780e164ca",
"status": "affected",
"version": "3ea7a56067e663278470c04fd655adf809e72d4d",
"versionType": "git"
},
{
"lessThan": "27f3924061592d0ef6b04e16f48754b6cb6adf27",
"status": "affected",
"version": "3ea7a56067e663278470c04fd655adf809e72d4d",
"versionType": "git"
},
{
"lessThan": "dd04114af0d451091f7b8cbd26d9e37d011e9131",
"status": "affected",
"version": "3ea7a56067e663278470c04fd655adf809e72d4d",
"versionType": "git"
},
{
"lessThan": "5ff232d31106f45ac87c3b64e1d35a0667777797",
"status": "affected",
"version": "3ea7a56067e663278470c04fd655adf809e72d4d",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"security/integrity/ima/ima_appraise.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.13"
},
{
"lessThan": "3.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "3.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "3.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "3.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "3.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nima: fix out-of-bounds read in xattr_verify()\n\nThe digest-length check in xattr_verify() mixes int and size_t:\n\n\tif (xattr_len - sizeof(xattr_value-\u003etype) - hash_start \u003e=\n\t\t\tiint-\u003eima_hash-\u003elength)\n\nsizeof() yields size_t, so the usual arithmetic conversions promote\nthe whole left-hand side to unsigned 64-bit before the subtraction\nruns. For a truncated xattr this underflows instead of going negative:\na 1-byte IMA_XATTR_DIGEST_NG xattr (xattr_len == 1, hash_start == 1)\nturns \"1 - 1 - 1\" into SIZE_MAX, which is trivially \u003e= ima_hash-\u003elength.\nThe check then passes and the following memcmp() reads\niint-\u003eima_hash-\u003elength bytes starting past the end of the buffer\nvfs_getxattr_alloc() allocated for it.\n\nNothing upstream clamps xattr_len back into a safe range first:\nima_get_hash_algo() only special-cases xattr_len \u003c 2 to pick a default\nalgorithm, and evm_verifyxattr() returns INTEGRITY_UNKNOWN rather than\nfailing when no HMAC key is loaded, so a truncated security.ima value\nreaches the length check as-is.\n\nRewrite the comparison so every operand stays a signed int and no\nimplicit conversion to size_t can occur."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-22T15:32:41.480Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/d823b5f4557083d1dd92096f796a78a2b1b06d10"
},
{
"url": "https://git.kernel.org/stable/c/caeb105c15ea2431fa8da7ecfa242d0c68272426"
},
{
"url": "https://git.kernel.org/stable/c/a784b4732ac7e51862b9b210c2d8b2ab9e83568c"
},
{
"url": "https://git.kernel.org/stable/c/b6cb134707a2127d90a58d69dd818679cae8033c"
},
{
"url": "https://git.kernel.org/stable/c/7e515b6c9aab452a4f0734bd7208e4e780e164ca"
},
{
"url": "https://git.kernel.org/stable/c/27f3924061592d0ef6b04e16f48754b6cb6adf27"
},
{
"url": "https://git.kernel.org/stable/c/dd04114af0d451091f7b8cbd26d9e37d011e9131"
},
{
"url": "https://git.kernel.org/stable/c/5ff232d31106f45ac87c3b64e1d35a0667777797"
}
],
"title": "ima: fix out-of-bounds read in xattr_verify()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74671",
"datePublished": "2026-08-22T15:32:41.480Z",
"dateReserved": "2026-08-15T05:44:03.925Z",
"dateUpdated": "2026-08-22T15:32:41.480Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74468 (GCVE-0-2026-74468)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-19 16:37
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
gpio: pch: use raw_spinlock_t for the register lock
pch_irq_type() is registered as the irq_chip .irq_set_type callback and
takes chip->spinlock with spin_lock_irqsave(). This callback is reached
from __setup_irq() -> __irq_set_trigger() -> chip->irq_set_type() while
the caller holds desc->lock, a raw_spinlock_t, with hardirqs disabled.
That context is not sleepable, but on PREEMPT_RT a regular spinlock_t is
an rtmutex-backed sleeping lock, so acquiring it there is invalid.
This was confirmed on a PREEMPT_RT kernel with lockdep
(PROVE_RAW_LOCK_NESTING and DEBUG_ATOMIC_SLEEP). A grounded PoC mirrored
pch_irq_type()'s locking and drove it through the real genirq carrier
irq_set_irq_type() -> __irq_set_trigger() -> chip->irq_set_type(), i.e.
the same __irq_set_trigger() edge that __setup_irq() takes for a
requested IRQ. With the original spin_lock_irqsave() edge lockdep
reported an invalid wait context, immediately followed by:
BUG: sleeping function called from invalid context at kernel/locking/spinlock_rt.c:48
in_atomic(): 1, irqs_disabled(): 1, non_block: 0, pid: 95, name: insmod
hardirqs last disabled at (3784): _raw_spin_lock_irqsave+0x4f/0x60
rt_spin_lock+0x3a/0x1c0
repro_irq_set_type+0x64/0xa0 [pch_repro]
__irq_set_trigger+0x69/0x140
irq_set_irq_type+0x78/0xd0
Switching the mirrored lock to raw_spinlock_t made both splats go away.
Convert the register lock to raw_spinlock_t. The same lock also
serializes the GPIO direction/value callbacks and the suspend/resume
register save/restore, but all of those critical sections only perform
MMIO register accesses (ioread32()/iowrite32()) and
irq_set_handler_locked(); none of them contain sleepable operations.
Keeping this register lock non-sleeping is therefore appropriate for the
irqchip callbacks and does not change the GPIO-side locking contract.
This is the same class of issue and fix as recently addressed for other
GPIO controllers, e.g. commit 286533cb14a3 ("gpio: sch: use raw_spinlock_t
in the irq startup path") and commit 90f0109019e6 ("gpio: eic-sprd: use
raw_spinlock_t in the irq startup path").
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 38eb18a6f92da886fc1af509d25e8f7a49e23d9a Version: 38eb18a6f92da886fc1af509d25e8f7a49e23d9a Version: 38eb18a6f92da886fc1af509d25e8f7a49e23d9a Version: 38eb18a6f92da886fc1af509d25e8f7a49e23d9a Version: 38eb18a6f92da886fc1af509d25e8f7a49e23d9a Version: 38eb18a6f92da886fc1af509d25e8f7a49e23d9a Version: 38eb18a6f92da886fc1af509d25e8f7a49e23d9a Version: 38eb18a6f92da886fc1af509d25e8f7a49e23d9a |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpio/gpio-pch.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "efc76a3f5353dd33a2e2ad48200cd4a18de30a0d",
"status": "affected",
"version": "38eb18a6f92da886fc1af509d25e8f7a49e23d9a",
"versionType": "git"
},
{
"lessThan": "935e6872db7faecfbe1a10b3f5d97a62fdff5ec9",
"status": "affected",
"version": "38eb18a6f92da886fc1af509d25e8f7a49e23d9a",
"versionType": "git"
},
{
"lessThan": "98f292cb6d01487d17988d9fd4e19c13e7adb156",
"status": "affected",
"version": "38eb18a6f92da886fc1af509d25e8f7a49e23d9a",
"versionType": "git"
},
{
"lessThan": "16da33cb36e663b6967112185e11d00ce8ff957c",
"status": "affected",
"version": "38eb18a6f92da886fc1af509d25e8f7a49e23d9a",
"versionType": "git"
},
{
"lessThan": "ff050589a21967883bb55f6dba42568f8367ad4a",
"status": "affected",
"version": "38eb18a6f92da886fc1af509d25e8f7a49e23d9a",
"versionType": "git"
},
{
"lessThan": "466ab0c41d5f54f71cee60619d07c4abd0ffd2cd",
"status": "affected",
"version": "38eb18a6f92da886fc1af509d25e8f7a49e23d9a",
"versionType": "git"
},
{
"lessThan": "c0a4ec89fc26e4b679b04f1002c503cb2529acdc",
"status": "affected",
"version": "38eb18a6f92da886fc1af509d25e8f7a49e23d9a",
"versionType": "git"
},
{
"lessThan": "a02b8950d619123da64f69b70fe1dadef217dfe4",
"status": "affected",
"version": "38eb18a6f92da886fc1af509d25e8f7a49e23d9a",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpio/gpio-pch.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.2"
},
{
"lessThan": "3.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ngpio: pch: use raw_spinlock_t for the register lock\n\npch_irq_type() is registered as the irq_chip .irq_set_type callback and\ntakes chip-\u003espinlock with spin_lock_irqsave(). This callback is reached\nfrom __setup_irq() -\u003e __irq_set_trigger() -\u003e chip-\u003eirq_set_type() while\nthe caller holds desc-\u003elock, a raw_spinlock_t, with hardirqs disabled.\nThat context is not sleepable, but on PREEMPT_RT a regular spinlock_t is\nan rtmutex-backed sleeping lock, so acquiring it there is invalid.\n\nThis was confirmed on a PREEMPT_RT kernel with lockdep\n(PROVE_RAW_LOCK_NESTING and DEBUG_ATOMIC_SLEEP). A grounded PoC mirrored\npch_irq_type()\u0027s locking and drove it through the real genirq carrier\nirq_set_irq_type() -\u003e __irq_set_trigger() -\u003e chip-\u003eirq_set_type(), i.e.\nthe same __irq_set_trigger() edge that __setup_irq() takes for a\nrequested IRQ. With the original spin_lock_irqsave() edge lockdep\nreported an invalid wait context, immediately followed by:\n\n BUG: sleeping function called from invalid context at kernel/locking/spinlock_rt.c:48\n in_atomic(): 1, irqs_disabled(): 1, non_block: 0, pid: 95, name: insmod\n hardirqs last disabled at (3784): _raw_spin_lock_irqsave+0x4f/0x60\n rt_spin_lock+0x3a/0x1c0\n repro_irq_set_type+0x64/0xa0 [pch_repro]\n __irq_set_trigger+0x69/0x140\n irq_set_irq_type+0x78/0xd0\n\nSwitching the mirrored lock to raw_spinlock_t made both splats go away.\n\nConvert the register lock to raw_spinlock_t. The same lock also\nserializes the GPIO direction/value callbacks and the suspend/resume\nregister save/restore, but all of those critical sections only perform\nMMIO register accesses (ioread32()/iowrite32()) and\nirq_set_handler_locked(); none of them contain sleepable operations.\nKeeping this register lock non-sleeping is therefore appropriate for the\nirqchip callbacks and does not change the GPIO-side locking contract.\n\nThis is the same class of issue and fix as recently addressed for other\nGPIO controllers, e.g. commit 286533cb14a3 (\"gpio: sch: use raw_spinlock_t\nin the irq startup path\") and commit 90f0109019e6 (\"gpio: eic-sprd: use\nraw_spinlock_t in the irq startup path\")."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:37:12.926Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/efc76a3f5353dd33a2e2ad48200cd4a18de30a0d"
},
{
"url": "https://git.kernel.org/stable/c/935e6872db7faecfbe1a10b3f5d97a62fdff5ec9"
},
{
"url": "https://git.kernel.org/stable/c/98f292cb6d01487d17988d9fd4e19c13e7adb156"
},
{
"url": "https://git.kernel.org/stable/c/16da33cb36e663b6967112185e11d00ce8ff957c"
},
{
"url": "https://git.kernel.org/stable/c/ff050589a21967883bb55f6dba42568f8367ad4a"
},
{
"url": "https://git.kernel.org/stable/c/466ab0c41d5f54f71cee60619d07c4abd0ffd2cd"
},
{
"url": "https://git.kernel.org/stable/c/c0a4ec89fc26e4b679b04f1002c503cb2529acdc"
},
{
"url": "https://git.kernel.org/stable/c/a02b8950d619123da64f69b70fe1dadef217dfe4"
}
],
"title": "gpio: pch: use raw_spinlock_t for the register lock",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74468",
"datePublished": "2026-08-15T12:27:06.250Z",
"dateReserved": "2026-08-15T05:44:03.902Z",
"dateUpdated": "2026-08-19T16:37:12.926Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68322 (GCVE-0-2026-68322)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
rds: Fix inet6_addr_lst NULL dereference when IPv6 is disabled
When booting with the 'ipv6.disable=1' parameter, inet6_addr_lst
is never initialized because inet6_init() exits before addrconf_init()
is called to initialize it. An attempt to bind an RDS socket to
an ipv6 address results in a crash in __ipv6_chk_addr_and_flags()
KASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f]
RIP: 0010:__ipv6_chk_addr_and_flags+0x1df/0x7e0
Call Trace:
<TASK>
ipv6_chk_addr+0x3b/0x50
rds_tcp_laddr_check+0x155/0x3b0 [rds_tcp]
rds_trans_get_preferred+0x15d/0x2d0 [rds]
? trace_hardirqs_on+0x2d/0x110
rds_bind+0x1433/0x1d60 [rds]
? rds_remove_bound+0xd50/0xd50 [rds]
? aa_af_perm+0x250/0x250
? __might_fault+0xde/0x190
? __sys_bind+0x1dc/0x210
__sys_bind+0x1dc/0x210
? __ia32_sys_socketpair+0x100/0x100
? restore_fpregs_from_fpstate+0x53/0x100
__x64_sys_bind+0x73/0xb0
? syscall_enter_from_user_mode+0x1c/0x50
do_syscall_64+0x34/0x80
entry_SYSCALL_64_after_hwframe+0x6e/0xd8
RIP: 0033:0x7f47f8269ea9
</TASK>
The following code reproduces the issue:
struct sockaddr_in6 addr;
s = socket(PF_RDS, SOCK_SEQPACKET, 0);
memset(&addr, 0, sizeof(addr));
inet_pton(AF_INET6, ADDRESS, &addr.sin6_addr);
addr.sin6_family = AF_INET6;
addr.sin6_port = htons(PORT);
bind(s, &addr, sizeof(addr));
Found by InfoTeCS on behalf of Linux Verification Center
(linuxtesting.org) with Syzkaller.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: eee2fa6ab3225192d6d894c54a6fb02ac9efdff6 Version: eee2fa6ab3225192d6d894c54a6fb02ac9efdff6 Version: eee2fa6ab3225192d6d894c54a6fb02ac9efdff6 Version: eee2fa6ab3225192d6d894c54a6fb02ac9efdff6 Version: eee2fa6ab3225192d6d894c54a6fb02ac9efdff6 Version: eee2fa6ab3225192d6d894c54a6fb02ac9efdff6 Version: eee2fa6ab3225192d6d894c54a6fb02ac9efdff6 Version: eee2fa6ab3225192d6d894c54a6fb02ac9efdff6 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/rds/ib.c",
"net/rds/ib_cm.c",
"net/rds/tcp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "7809344be3f0c1bbfdfdde1cefafeec14bf52d51",
"status": "affected",
"version": "eee2fa6ab3225192d6d894c54a6fb02ac9efdff6",
"versionType": "git"
},
{
"lessThan": "438dec9b0a06bd1f8db8c58539c655e735e17367",
"status": "affected",
"version": "eee2fa6ab3225192d6d894c54a6fb02ac9efdff6",
"versionType": "git"
},
{
"lessThan": "b61c9eb5931bb7389bc104faacd8c17d910da65d",
"status": "affected",
"version": "eee2fa6ab3225192d6d894c54a6fb02ac9efdff6",
"versionType": "git"
},
{
"lessThan": "8e48d7ab1e01936a172ff31531904b003895fd8c",
"status": "affected",
"version": "eee2fa6ab3225192d6d894c54a6fb02ac9efdff6",
"versionType": "git"
},
{
"lessThan": "a8302e758050e6a922765aee8d220a4fd350f52d",
"status": "affected",
"version": "eee2fa6ab3225192d6d894c54a6fb02ac9efdff6",
"versionType": "git"
},
{
"lessThan": "f6787fdffcae5490c779f0f3f33b11597525d1ae",
"status": "affected",
"version": "eee2fa6ab3225192d6d894c54a6fb02ac9efdff6",
"versionType": "git"
},
{
"lessThan": "00d5707217b5972554898ff734ae7b71bce704e6",
"status": "affected",
"version": "eee2fa6ab3225192d6d894c54a6fb02ac9efdff6",
"versionType": "git"
},
{
"lessThan": "9c805e592a29be9e4e61ff1bd567da04aa8fd6f9",
"status": "affected",
"version": "eee2fa6ab3225192d6d894c54a6fb02ac9efdff6",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/rds/ib.c",
"net/rds/ib_cm.c",
"net/rds/tcp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.19"
},
{
"lessThan": "4.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nrds: Fix inet6_addr_lst NULL dereference when IPv6 is disabled\n\nWhen booting with the \u0027ipv6.disable=1\u0027 parameter, inet6_addr_lst\nis never initialized because inet6_init() exits before addrconf_init()\nis called to initialize it. An attempt to bind an RDS socket to\nan ipv6 address results in a crash in __ipv6_chk_addr_and_flags()\n\nKASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f]\nRIP: 0010:__ipv6_chk_addr_and_flags+0x1df/0x7e0\nCall Trace:\n \u003cTASK\u003e\n ipv6_chk_addr+0x3b/0x50\n rds_tcp_laddr_check+0x155/0x3b0 [rds_tcp]\n rds_trans_get_preferred+0x15d/0x2d0 [rds]\n ? trace_hardirqs_on+0x2d/0x110\n rds_bind+0x1433/0x1d60 [rds]\n ? rds_remove_bound+0xd50/0xd50 [rds]\n ? aa_af_perm+0x250/0x250\n ? __might_fault+0xde/0x190\n ? __sys_bind+0x1dc/0x210\n __sys_bind+0x1dc/0x210\n ? __ia32_sys_socketpair+0x100/0x100\n ? restore_fpregs_from_fpstate+0x53/0x100\n __x64_sys_bind+0x73/0xb0\n ? syscall_enter_from_user_mode+0x1c/0x50\n do_syscall_64+0x34/0x80\n entry_SYSCALL_64_after_hwframe+0x6e/0xd8\nRIP: 0033:0x7f47f8269ea9\n \u003c/TASK\u003e\n\nThe following code reproduces the issue:\n\nstruct sockaddr_in6 addr;\ns = socket(PF_RDS, SOCK_SEQPACKET, 0);\n\nmemset(\u0026addr, 0, sizeof(addr));\ninet_pton(AF_INET6, ADDRESS, \u0026addr.sin6_addr);\naddr.sin6_family = AF_INET6;\naddr.sin6_port = htons(PORT);\n\nbind(s, \u0026addr, sizeof(addr));\n\nFound by InfoTeCS on behalf of Linux Verification Center\n(linuxtesting.org) with Syzkaller."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:12.816Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/7809344be3f0c1bbfdfdde1cefafeec14bf52d51"
},
{
"url": "https://git.kernel.org/stable/c/438dec9b0a06bd1f8db8c58539c655e735e17367"
},
{
"url": "https://git.kernel.org/stable/c/b61c9eb5931bb7389bc104faacd8c17d910da65d"
},
{
"url": "https://git.kernel.org/stable/c/8e48d7ab1e01936a172ff31531904b003895fd8c"
},
{
"url": "https://git.kernel.org/stable/c/a8302e758050e6a922765aee8d220a4fd350f52d"
},
{
"url": "https://git.kernel.org/stable/c/f6787fdffcae5490c779f0f3f33b11597525d1ae"
},
{
"url": "https://git.kernel.org/stable/c/00d5707217b5972554898ff734ae7b71bce704e6"
},
{
"url": "https://git.kernel.org/stable/c/9c805e592a29be9e4e61ff1bd567da04aa8fd6f9"
}
],
"title": "rds: Fix inet6_addr_lst NULL dereference when IPv6 is disabled",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68322",
"datePublished": "2026-08-10T12:02:57.499Z",
"dateReserved": "2026-07-30T09:28:09.382Z",
"dateUpdated": "2026-08-19T16:33:12.816Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74516 (GCVE-0-2026-74516)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-19 16:38
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active
Always update x2APIC MSR intercepts for L1 when AVIC is deactivated, even
if L2 is active and KVM is using a separate MSR bitmap to run L2. If AVIC
is fully enabled prior to running L2, and is then inhibited while L2 is
active (for a VM-scoped inhibit), then KVM will run L1 with AVIC disabled,
but with x2APIC MSR intercepts disabled, i.e. will allow L1 to read most of
the host's APIC state, send arbitrary interrupts, change task priority, and
ultimately trivially DoS the host.
E.g. sending a self-IPI in L1 on HYPERV_REENLIGHTENMENT_VECTOR, 0xee, with
CONFIG_HYPERV=n in the host kernel as a "safe" PoC, yields:
Spurious interrupt (vector 0xee) on CPU#425. Acked
And hacking KVM to abuse kvm_set_posted_intr_wakeup_handler() to register a
handler and WARN on POSTED_INTR_WAKEUP_VECTOR yields:
------------[ cut here ]------------
WARNING: arch/x86/kvm/svm/svm.c:5594 at pi_wakeup_handler+0x9/0x10 [kvm_amd], CPU#156: nested_x2apic_t/316940
CPU: 156 UID: 0 PID: 316940 Comm: nested_x2apic_t Tainted: G S U
Tainted: [S]=CPU_OUT_OF_SPEC, [U]=USER
Hardware name: Google Astoria-Turin/astoria, BIOS 0.20260209.0-0 02/09/2026
RIP: 0010:pi_wakeup_handler+0x9/0x10 [kvm_amd]
Call Trace:
<IRQ>
sysvec_kvm_posted_intr_wakeup_ipi+0x64/0x80
</IRQ>
<TASK>
asm_sysvec_kvm_posted_intr_wakeup_ipi+0x1a/0x20
RIP: 0010:vcpu_run+0x1430/0x1e40 [kvm]
kvm_arch_vcpu_ioctl_run+0x2c1/0x600 [kvm]
kvm_vcpu_ioctl+0x580/0x6b0 [kvm]
__se_sys_ioctl+0x6d/0xb0
do_syscall_64+0x10a/0x480
entry_SYSCALL_64_after_hwframe+0x4b/0x53
RIP: 0033:0x46ff4b
</TASK>
---[ end trace 0000000000000000 ]---
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 091abbf578f926e763adc0f577baeb7f405b4bdc Version: 091abbf578f926e763adc0f577baeb7f405b4bdc Version: 091abbf578f926e763adc0f577baeb7f405b4bdc Version: 091abbf578f926e763adc0f577baeb7f405b4bdc Version: 091abbf578f926e763adc0f577baeb7f405b4bdc Version: 091abbf578f926e763adc0f577baeb7f405b4bdc |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"arch/x86/kvm/svm/avic.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "4ca05385b3ddbd463be17c6d69ec76fca657081d",
"status": "affected",
"version": "091abbf578f926e763adc0f577baeb7f405b4bdc",
"versionType": "git"
},
{
"lessThan": "6664a5aea45318f4ec156a729949b474dd6e3159",
"status": "affected",
"version": "091abbf578f926e763adc0f577baeb7f405b4bdc",
"versionType": "git"
},
{
"lessThan": "f12373625b4dc9bcc89c41872648878c73bb9272",
"status": "affected",
"version": "091abbf578f926e763adc0f577baeb7f405b4bdc",
"versionType": "git"
},
{
"lessThan": "7668c58dcf465559dc7a0d2e95e9cb79cf47454b",
"status": "affected",
"version": "091abbf578f926e763adc0f577baeb7f405b4bdc",
"versionType": "git"
},
{
"lessThan": "89f9e8398e79c49886766fc24a84c37726231104",
"status": "affected",
"version": "091abbf578f926e763adc0f577baeb7f405b4bdc",
"versionType": "git"
},
{
"lessThan": "7d3aae206663c4e006b25a1c7a20a4029e67da76",
"status": "affected",
"version": "091abbf578f926e763adc0f577baeb7f405b4bdc",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"arch/x86/kvm/svm/avic.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.0"
},
{
"lessThan": "6.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active\n\nAlways update x2APIC MSR intercepts for L1 when AVIC is deactivated, even\nif L2 is active and KVM is using a separate MSR bitmap to run L2. If AVIC\nis fully enabled prior to running L2, and is then inhibited while L2 is\nactive (for a VM-scoped inhibit), then KVM will run L1 with AVIC disabled,\nbut with x2APIC MSR intercepts disabled, i.e. will allow L1 to read most of\nthe host\u0027s APIC state, send arbitrary interrupts, change task priority, and\nultimately trivially DoS the host.\n\nE.g. sending a self-IPI in L1 on HYPERV_REENLIGHTENMENT_VECTOR, 0xee, with\nCONFIG_HYPERV=n in the host kernel as a \"safe\" PoC, yields:\n\n Spurious interrupt (vector 0xee) on CPU#425. Acked\n\nAnd hacking KVM to abuse kvm_set_posted_intr_wakeup_handler() to register a\nhandler and WARN on POSTED_INTR_WAKEUP_VECTOR yields:\n\n ------------[ cut here ]------------\n WARNING: arch/x86/kvm/svm/svm.c:5594 at pi_wakeup_handler+0x9/0x10 [kvm_amd], CPU#156: nested_x2apic_t/316940\n CPU: 156 UID: 0 PID: 316940 Comm: nested_x2apic_t Tainted: G S U\n Tainted: [S]=CPU_OUT_OF_SPEC, [U]=USER\n Hardware name: Google Astoria-Turin/astoria, BIOS 0.20260209.0-0 02/09/2026\n RIP: 0010:pi_wakeup_handler+0x9/0x10 [kvm_amd]\n Call Trace:\n \u003cIRQ\u003e\n sysvec_kvm_posted_intr_wakeup_ipi+0x64/0x80\n \u003c/IRQ\u003e\n \u003cTASK\u003e\n asm_sysvec_kvm_posted_intr_wakeup_ipi+0x1a/0x20\n RIP: 0010:vcpu_run+0x1430/0x1e40 [kvm]\n kvm_arch_vcpu_ioctl_run+0x2c1/0x600 [kvm]\n kvm_vcpu_ioctl+0x580/0x6b0 [kvm]\n __se_sys_ioctl+0x6d/0xb0\n do_syscall_64+0x10a/0x480\n entry_SYSCALL_64_after_hwframe+0x4b/0x53\n RIP: 0033:0x46ff4b\n \u003c/TASK\u003e\n ---[ end trace 0000000000000000 ]---"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.2,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires triggering KVM nested SVM/AVIC paths via local /dev/kvm ioctls (KVM_CREATE_VM, KVM_CREATE_VCPU, KVM_RUN) from L1; there is no network, adjacent, or physical packet/device path to the vulnerable code.\nAC:L - An L1 attacker fully controls nested VM configuration (x2APIC, AVIC, L2 MSR bitmap, IRQ-window/ExtINT conditions) and can reliably reproduce AVIC inhibition while L2 is active without races or uncontrollable host state.\nPR:H - Reaching the bug requires running nested AMD KVM as L1 (nested virtualization enabled and control of a guest hypervisor), which is not available to an unprivileged host user or via user-namespace capabilities alone without delegated /dev/kvm access.\nUI:N - No victim interaction is required; exploitation is driven entirely by the attacker\u2019s nested hypervisor configuration and KVM_RUN operations once nested virtualization is available.\nS:C - The flaw lets an L1 nested guest hypervisor access the host\u2019s physical x2APIC MSRs, crossing the VM/host security boundary rather than staying within the guest\u2019s own security scope.\nC:H - With x2APIC MSR intercepts left disabled, L1 can read most of the host APIC state (IDs, IRR/ISR, timers, ICR), leaking sensitive host interrupt-controller information beyond the guest boundary.\nI:H - L1 can write host x2APIC MSRs to send arbitrary IPIs, change task priority, and invoke host interrupt vectors (e.g. posted-interrupt wakeup), enabling host integrity compromise beyond mere guest-local effects.\nA:H - Host availability is trivially impacted by injecting spurious or high-priority interrupts to host CPUs; the fix commit demonstrates host kernel warnings and spurious interrupt storms causing denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:38:16.902Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/4ca05385b3ddbd463be17c6d69ec76fca657081d"
},
{
"url": "https://git.kernel.org/stable/c/6664a5aea45318f4ec156a729949b474dd6e3159"
},
{
"url": "https://git.kernel.org/stable/c/f12373625b4dc9bcc89c41872648878c73bb9272"
},
{
"url": "https://git.kernel.org/stable/c/7668c58dcf465559dc7a0d2e95e9cb79cf47454b"
},
{
"url": "https://git.kernel.org/stable/c/89f9e8398e79c49886766fc24a84c37726231104"
},
{
"url": "https://git.kernel.org/stable/c/7d3aae206663c4e006b25a1c7a20a4029e67da76"
}
],
"title": "KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74516",
"datePublished": "2026-08-15T12:27:36.200Z",
"dateReserved": "2026-08-15T05:44:03.910Z",
"dateUpdated": "2026-08-19T16:38:16.902Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74444 (GCVE-0-2026-74444)
Vulnerability from cvelistv5
Published
2026-08-15 12:26
Modified
2026-08-19 16:36
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/vmwgfx: validate DRAW_PRIMITIVES header size before division
vmw_cmd_draw() computes
maxnum = (header->size - sizeof(cmd->body)) / sizeof(*decl);
where header->size is u32 and is taken straight from the user-supplied
command stream. When header->size is less than sizeof(cmd->body) the
unsigned subtraction wraps to nearly 4 GiB, producing a huge maxnum.
Any user-controlled cmd->body.numVertexDecls then passes the bound and
the loop dereferences decl[i] far past the end of the kernel command
bounce buffer, producing an out-of-bounds read of kernel memory.
Reject undersized headers up front.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 7a73ba7469cbea631050094fd14f73acebb97cf9 Version: 7a73ba7469cbea631050094fd14f73acebb97cf9 Version: 7a73ba7469cbea631050094fd14f73acebb97cf9 Version: 7a73ba7469cbea631050094fd14f73acebb97cf9 Version: 7a73ba7469cbea631050094fd14f73acebb97cf9 Version: 7a73ba7469cbea631050094fd14f73acebb97cf9 Version: 7a73ba7469cbea631050094fd14f73acebb97cf9 Version: 7a73ba7469cbea631050094fd14f73acebb97cf9 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/vmwgfx/vmwgfx_execbuf.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b89ca4bba820f79dde52af15ee139fe6e8bbc314",
"status": "affected",
"version": "7a73ba7469cbea631050094fd14f73acebb97cf9",
"versionType": "git"
},
{
"lessThan": "bef30317fcb4c838a37bceb2fc76256eb6b975c1",
"status": "affected",
"version": "7a73ba7469cbea631050094fd14f73acebb97cf9",
"versionType": "git"
},
{
"lessThan": "112c6ff29a56f3a22db4d5af869697aa07035ad6",
"status": "affected",
"version": "7a73ba7469cbea631050094fd14f73acebb97cf9",
"versionType": "git"
},
{
"lessThan": "2666cddf0dd218aa9bd1f99db688d1b532eac21a",
"status": "affected",
"version": "7a73ba7469cbea631050094fd14f73acebb97cf9",
"versionType": "git"
},
{
"lessThan": "fc0c02f510e41650df3479f96e257acf87d8a20a",
"status": "affected",
"version": "7a73ba7469cbea631050094fd14f73acebb97cf9",
"versionType": "git"
},
{
"lessThan": "dc0be7662b7b0ce28cb5eea864737793ed7b9e70",
"status": "affected",
"version": "7a73ba7469cbea631050094fd14f73acebb97cf9",
"versionType": "git"
},
{
"lessThan": "c77cf8edae2bd3a1599115301cc7c98d0c78e731",
"status": "affected",
"version": "7a73ba7469cbea631050094fd14f73acebb97cf9",
"versionType": "git"
},
{
"lessThan": "85891d174707d8bddcec7a888fb4e1d17def34f3",
"status": "affected",
"version": "7a73ba7469cbea631050094fd14f73acebb97cf9",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/vmwgfx/vmwgfx_execbuf.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.33"
},
{
"lessThan": "2.6.33",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.33",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.33",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.33",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "2.6.33",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "2.6.33",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "2.6.33",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "2.6.33",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.33",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vmwgfx: validate DRAW_PRIMITIVES header size before division\n\nvmw_cmd_draw() computes\n\n\tmaxnum = (header-\u003esize - sizeof(cmd-\u003ebody)) / sizeof(*decl);\n\nwhere header-\u003esize is u32 and is taken straight from the user-supplied\ncommand stream. When header-\u003esize is less than sizeof(cmd-\u003ebody) the\nunsigned subtraction wraps to nearly 4 GiB, producing a huge maxnum.\nAny user-controlled cmd-\u003ebody.numVertexDecls then passes the bound and\nthe loop dereferences decl[i] far past the end of the kernel command\nbounce buffer, producing an out-of-bounds read of kernel memory.\n\nReject undersized headers up front."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached only through the local DRM_IOCTL_VMW_EXECBUF ioctl (vmw_execbuf_ioctl -\u003e vmw_execbuf_process -\u003e vmw_cmd_check_all -\u003e vmw_cmd_draw); it is not reachable from network, adjacent wireless, or physical buses.\nAC:L - An attacker fully controls the user command stream and can set header-\u003esize below sizeof(cmd-\u003ebody) to underflow maxnum and bypass numVertexDecls bounds; no races or victim-dependent timing are required.\nPR:L - VMW_EXECBUF is registered with DRM_RENDER_ALLOW, so any local process with access to the vmwgfx render node (/dev/dri/renderD*) and a user-created 3D context can submit the malicious DRAW_PRIMITIVES command without real root.\nUI:N - Exploitation requires only the attacker opening the render device and issuing crafted execbuf ioctls; no additional actions by another user or administrator are needed.\nS:U - Impact is confined to the guest kernel address space running vmwgfx (VMware SVGA virtual GPU); successful exploitation yields guest-kernel memory disclosure/corruption and privilege escalation, not a direct hypervisor/host escape.\nC:H - Unsigned underflow makes maxnum enormous, so the vertex-declaration loop dereferences decl[i] far beyond the vmalloc command bounce buffer and reads adjacent kernel heap memory (e.g., decl-\u003earray.surfaceId) into validation paths.\nI:H - Beyond disclosure, leaked/adjacent surfaceId values can satisfy vmw_user_resource_lookup_handle and vmw_resource_relocations_apply then writes resource IDs to offsets past the bounce buffer, giving an out-of-bounds kernel write primitive.\nA:H - Setting a large numVertexDecls after the bound bypass can walk far past the vmalloc allocation and fault on unmapped pages, and extensive heap corruption from relocation writes can also trigger kernel oops/panic."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:36:38.535Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b89ca4bba820f79dde52af15ee139fe6e8bbc314"
},
{
"url": "https://git.kernel.org/stable/c/bef30317fcb4c838a37bceb2fc76256eb6b975c1"
},
{
"url": "https://git.kernel.org/stable/c/112c6ff29a56f3a22db4d5af869697aa07035ad6"
},
{
"url": "https://git.kernel.org/stable/c/2666cddf0dd218aa9bd1f99db688d1b532eac21a"
},
{
"url": "https://git.kernel.org/stable/c/fc0c02f510e41650df3479f96e257acf87d8a20a"
},
{
"url": "https://git.kernel.org/stable/c/dc0be7662b7b0ce28cb5eea864737793ed7b9e70"
},
{
"url": "https://git.kernel.org/stable/c/c77cf8edae2bd3a1599115301cc7c98d0c78e731"
},
{
"url": "https://git.kernel.org/stable/c/85891d174707d8bddcec7a888fb4e1d17def34f3"
}
],
"title": "drm/vmwgfx: validate DRAW_PRIMITIVES header size before division",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74444",
"datePublished": "2026-08-15T12:26:51.443Z",
"dateReserved": "2026-08-15T05:44:03.898Z",
"dateUpdated": "2026-08-19T16:36:38.535Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72099 (GCVE-0-2026-72099)
Vulnerability from cvelistv5
Published
2026-08-15 05:52
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
dm-integrity: don't increment hash_offset twice
hash_offset is already incremented in the loop "for (i = 0; i < to_copy;
i++, ts--)". Do not increment it again.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 84597a44a9d86ac949900441cea7da0af0f2f473 Version: 84597a44a9d86ac949900441cea7da0af0f2f473 Version: 84597a44a9d86ac949900441cea7da0af0f2f473 Version: 84597a44a9d86ac949900441cea7da0af0f2f473 Version: 84597a44a9d86ac949900441cea7da0af0f2f473 Version: 84597a44a9d86ac949900441cea7da0af0f2f473 Version: 84597a44a9d86ac949900441cea7da0af0f2f473 Version: 84597a44a9d86ac949900441cea7da0af0f2f473 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/md/dm-integrity.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c66b1781a54984227e94b862be9328d81d81e51c",
"status": "affected",
"version": "84597a44a9d86ac949900441cea7da0af0f2f473",
"versionType": "git"
},
{
"lessThan": "39697e2759ac23e65361fe61482f8174cad8a752",
"status": "affected",
"version": "84597a44a9d86ac949900441cea7da0af0f2f473",
"versionType": "git"
},
{
"lessThan": "e6646f4d711d74930d39cce6fb7bfcae4cbee5fd",
"status": "affected",
"version": "84597a44a9d86ac949900441cea7da0af0f2f473",
"versionType": "git"
},
{
"lessThan": "cf9feed8c131e303ecf2afebe6f791be018818ad",
"status": "affected",
"version": "84597a44a9d86ac949900441cea7da0af0f2f473",
"versionType": "git"
},
{
"lessThan": "4f4e43337e9ef322595201cfc24def50fd624219",
"status": "affected",
"version": "84597a44a9d86ac949900441cea7da0af0f2f473",
"versionType": "git"
},
{
"lessThan": "5dfd8042635278613da3b88553e25ade2103cd58",
"status": "affected",
"version": "84597a44a9d86ac949900441cea7da0af0f2f473",
"versionType": "git"
},
{
"lessThan": "829476c06496aab018f14127c055adb164d1a750",
"status": "affected",
"version": "84597a44a9d86ac949900441cea7da0af0f2f473",
"versionType": "git"
},
{
"lessThan": "edf025f083854f80032b73a1aad69a3c90db236f",
"status": "affected",
"version": "84597a44a9d86ac949900441cea7da0af0f2f473",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/md/dm-integrity.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.7"
},
{
"lessThan": "5.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndm-integrity: don\u0027t increment hash_offset twice\n\nhash_offset is already incremented in the loop \"for (i = 0; i \u003c to_copy;\ni++, ts--)\". Do not increment it again."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The flaw is reached via block I/O on dm-integrity journal/bitmap targets; in enterprise/cloud deployments those volumes are commonly accessed remotely through NFS/ksmbd file exports or iSCSI/NVMe-oF/NBD block protocols, letting a remote client drive the vulnerable TAG_CMP path.\nAC:L - An attacker with read access can reliably trigger TAG_CMP by issuing ordinary multi-sector reads; when metadata tag comparisons span dm-bufio buffer boundaries the double-incremented hash_offset mispredicts tag boundaries without races or uncontrollable layout.\nPR:L - Table creation needs CAP_SYS_ADMIN (obtainable in a user namespace), but exploitation only requires read/write access to the mapped block device or an exported filesystem backed by it, not init-namespace root.\nUI:N - Exploitation requires only attacker-initiated reads or writes against the dm-integrity-backed storage; no additional victim actions such as mounting a filesystem or opening files beyond the attacker\u0027s own I/O are needed.\nS:U - Impact is incorrect integrity-tag verification within the host kernel\u0027s device-mapper layer, enabling undetected data tampering or spurious verification failures on the same host; it does not cross VM, container, or IOMMU security boundaries.\nC:N - The bug corrupts tag-boundary state during comparison but does not cause kernel memory disclosure, out-of-bounds reads, or use-after-free; any wrong data returned is attacker-supplied disk content, not leakage of unrelated kernel or user secrets.\nI:H - Misaligned hash_offset can accept integrity tags that should fail verification (including mixed hash/discard-filler boundaries), defeating dm-integrity\u0027s tamper detection and allowing undetected modification of protected block data.\nA:L - The same logic error can spuriously fail checksum verification on legitimate reads, returning I/O errors and denying access to protected data without kernel panic, though repeated reads can sustain a denial-of-service against the volume."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:49.483Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c66b1781a54984227e94b862be9328d81d81e51c"
},
{
"url": "https://git.kernel.org/stable/c/39697e2759ac23e65361fe61482f8174cad8a752"
},
{
"url": "https://git.kernel.org/stable/c/e6646f4d711d74930d39cce6fb7bfcae4cbee5fd"
},
{
"url": "https://git.kernel.org/stable/c/cf9feed8c131e303ecf2afebe6f791be018818ad"
},
{
"url": "https://git.kernel.org/stable/c/4f4e43337e9ef322595201cfc24def50fd624219"
},
{
"url": "https://git.kernel.org/stable/c/5dfd8042635278613da3b88553e25ade2103cd58"
},
{
"url": "https://git.kernel.org/stable/c/829476c06496aab018f14127c055adb164d1a750"
},
{
"url": "https://git.kernel.org/stable/c/edf025f083854f80032b73a1aad69a3c90db236f"
}
],
"title": "dm-integrity: don\u0027t increment hash_offset twice",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72099",
"datePublished": "2026-08-15T05:52:44.292Z",
"dateReserved": "2026-08-09T03:40:39.905Z",
"dateUpdated": "2026-08-23T12:46:49.483Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72392 (GCVE-0-2026-72392)
Vulnerability from cvelistv5
Published
2026-08-15 05:56
Modified
2026-08-19 16:36
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ipv6: fib6: fix NULL deref in fib6_walk_continue() on multi-batch dump
inet6_dump_fib() saves its progress in cb->args[1] as a positional
index within the current hash chain. Between batches, a concurrent
fib6_new_table() can insert a new table at the chain head, shifting
all existing entries. The saved index then lands on a different
table, causing fib6_dump_table() to set w->root to the wrong table
while w->node still points into the previous one.
fib6_walk_continue() dereferences w->node->parent (NULL) and panics:
BUG: kernel NULL pointer dereference, address: 0000000000000008
RIP: 0010:fib6_walk_continue+0x6e/0x170
Call Trace:
<TASK>
fib6_dump_table.isra.0+0xc5/0x240
inet6_dump_fib+0xf6/0x420
rtnl_dumpit+0x30/0xa0
netlink_dump+0x15b/0x460
netlink_recvmsg+0x1d6/0x2a0
____sys_recvmsg+0x17a/0x190
Fix by storing tb->tb6_id in cb->args[1] instead of a positional
index. On resume, skip entries until the id matches; a concurrent
head-insert can never match the saved id, so the walker always
resumes on the correct table.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1b43af5480c351dbcb2eef478bafe179cbeb6e83 Version: 1b43af5480c351dbcb2eef478bafe179cbeb6e83 Version: 1b43af5480c351dbcb2eef478bafe179cbeb6e83 Version: 1b43af5480c351dbcb2eef478bafe179cbeb6e83 Version: 1b43af5480c351dbcb2eef478bafe179cbeb6e83 Version: 1b43af5480c351dbcb2eef478bafe179cbeb6e83 Version: 1b43af5480c351dbcb2eef478bafe179cbeb6e83 Version: 1b43af5480c351dbcb2eef478bafe179cbeb6e83 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ipv6/ip6_fib.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ee73a32dd258d4af66831ff006b771e19812b322",
"status": "affected",
"version": "1b43af5480c351dbcb2eef478bafe179cbeb6e83",
"versionType": "git"
},
{
"lessThan": "89f9c5fee3c64c5cabc34e65599308fd3c879cf9",
"status": "affected",
"version": "1b43af5480c351dbcb2eef478bafe179cbeb6e83",
"versionType": "git"
},
{
"lessThan": "cb90a774a9c6c46961a44949a246fbb61f5f934c",
"status": "affected",
"version": "1b43af5480c351dbcb2eef478bafe179cbeb6e83",
"versionType": "git"
},
{
"lessThan": "27210d433a8c5fe6bf7278a04bbaeb49a81d0290",
"status": "affected",
"version": "1b43af5480c351dbcb2eef478bafe179cbeb6e83",
"versionType": "git"
},
{
"lessThan": "059efb48dd746518898faaa9b965511009b59639",
"status": "affected",
"version": "1b43af5480c351dbcb2eef478bafe179cbeb6e83",
"versionType": "git"
},
{
"lessThan": "d8a01d27873e04bebd357dc87859aa756e0b28b2",
"status": "affected",
"version": "1b43af5480c351dbcb2eef478bafe179cbeb6e83",
"versionType": "git"
},
{
"lessThan": "110ccbd28c9444866fcc84ba96a2ad64fa6e95ae",
"status": "affected",
"version": "1b43af5480c351dbcb2eef478bafe179cbeb6e83",
"versionType": "git"
},
{
"lessThan": "9facb861dc6b9b9ea9793ef5032a9a826f7a4229",
"status": "affected",
"version": "1b43af5480c351dbcb2eef478bafe179cbeb6e83",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ipv6/ip6_fib.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.19"
},
{
"lessThan": "2.6.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "2.6.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "2.6.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "2.6.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "2.6.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "2.6.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: fib6: fix NULL deref in fib6_walk_continue() on multi-batch dump\n\ninet6_dump_fib() saves its progress in cb-\u003eargs[1] as a positional\nindex within the current hash chain. Between batches, a concurrent\nfib6_new_table() can insert a new table at the chain head, shifting\nall existing entries. The saved index then lands on a different\ntable, causing fib6_dump_table() to set w-\u003eroot to the wrong table\nwhile w-\u003enode still points into the previous one.\nfib6_walk_continue() dereferences w-\u003enode-\u003eparent (NULL) and panics:\n\n BUG: kernel NULL pointer dereference, address: 0000000000000008\n RIP: 0010:fib6_walk_continue+0x6e/0x170\n Call Trace:\n \u003cTASK\u003e\n fib6_dump_table.isra.0+0xc5/0x240\n inet6_dump_fib+0xf6/0x420\n rtnl_dumpit+0x30/0xa0\n netlink_dump+0x15b/0x460\n netlink_recvmsg+0x1d6/0x2a0\n ____sys_recvmsg+0x17a/0x190\n\nFix by storing tb-\u003etb6_id in cb-\u003eargs[1] instead of a positional\nindex. On resume, skip entries until the id matches; a concurrent\nhead-insert can never match the saved id, so the walker always\nresumes on the correct table."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:36:33.417Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ee73a32dd258d4af66831ff006b771e19812b322"
},
{
"url": "https://git.kernel.org/stable/c/89f9c5fee3c64c5cabc34e65599308fd3c879cf9"
},
{
"url": "https://git.kernel.org/stable/c/cb90a774a9c6c46961a44949a246fbb61f5f934c"
},
{
"url": "https://git.kernel.org/stable/c/27210d433a8c5fe6bf7278a04bbaeb49a81d0290"
},
{
"url": "https://git.kernel.org/stable/c/059efb48dd746518898faaa9b965511009b59639"
},
{
"url": "https://git.kernel.org/stable/c/d8a01d27873e04bebd357dc87859aa756e0b28b2"
},
{
"url": "https://git.kernel.org/stable/c/110ccbd28c9444866fcc84ba96a2ad64fa6e95ae"
},
{
"url": "https://git.kernel.org/stable/c/9facb861dc6b9b9ea9793ef5032a9a826f7a4229"
}
],
"title": "ipv6: fib6: fix NULL deref in fib6_walk_continue() on multi-batch dump",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72392",
"datePublished": "2026-08-15T05:56:20.463Z",
"dateReserved": "2026-08-09T03:40:39.924Z",
"dateUpdated": "2026-08-19T16:36:33.417Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74689 (GCVE-0-2026-74689)
Vulnerability from cvelistv5
Published
2026-08-22 15:32
Modified
2026-08-25 05:41
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/atm: fix slab-out-of-bounds read in vcc_setsockopt()
vcc_setsockopt() contained an ineffective optlen check:
if (__SO_LEVEL_MATCH(optname, level) && optlen != __SO_SIZE(optname))
return -EINVAL;
If __SO_LEVEL_MATCH(optname, level) evaluated to false (e.g. if the caller
passed a mismatched level), the length check optlen != __SO_SIZE(optname)
was short-circuited and bypassed. Execution then fell through to switch(optname),
calling copy_from_sockptr() assuming optval contained sufficient space.
Furthermore, even if level matched, a cgroup BPF setsockopt filter could shrink
optlen after entry. Because copy_from_sockptr() on kernel pointers uses memcpy(),
this leads to a KASAN slab-out-of-bounds read when optlen is smaller than the
expected structure size.
Fix this by using copy_safe_from_sockptr(), which unconditionally validates
that optlen is at least the expected size before copying. Also change the local
'value' variable type from 'unsigned long' to 'int' so that SO_SETCLP matches
its sizeof(int) ABI encoding on 64-bit systems.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/atm/common.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b3bcd5d65ac03c15787b2a5b36c718e26a689336",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "35f258fee9ed358c6d0f57f91c30bf029c3724af",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "6eb6af88710977eb529b558a07294874d8c40c4d",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "9f77c1ab382188f5b51982fab6d913443b6dc59f",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "2c5988c7349c0b64a7e0441bfc6e1dca54f7116a",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "d0c80dbb970439bd2eeb0e5effff8c16a5f4e1e3",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/atm/common.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/atm: fix slab-out-of-bounds read in vcc_setsockopt()\n\nvcc_setsockopt() contained an ineffective optlen check:\n if (__SO_LEVEL_MATCH(optname, level) \u0026\u0026 optlen != __SO_SIZE(optname))\n return -EINVAL;\n\nIf __SO_LEVEL_MATCH(optname, level) evaluated to false (e.g. if the caller\npassed a mismatched level), the length check optlen != __SO_SIZE(optname)\nwas short-circuited and bypassed. Execution then fell through to switch(optname),\ncalling copy_from_sockptr() assuming optval contained sufficient space.\n\nFurthermore, even if level matched, a cgroup BPF setsockopt filter could shrink\noptlen after entry. Because copy_from_sockptr() on kernel pointers uses memcpy(),\nthis leads to a KASAN slab-out-of-bounds read when optlen is smaller than the\nexpected structure size.\n\nFix this by using copy_safe_from_sockptr(), which unconditionally validates\nthat optlen is at least the expected size before copying. Also change the local\n\u0027value\u0027 variable type from \u0027unsigned long\u0027 to \u0027int\u0027 so that SO_SETCLP matches\nits sizeof(int) ABI encoding on 64-bit systems."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached only via the local setsockopt(2) syscall on an AF_ATMPVC/AF_ATMSVC socket (do_sock_setsockopt -\u003e pvc_setsockopt/svc_setsockopt -\u003e vcc_setsockopt); no remote ATM packet or network-facing handler invokes this path.\nAC:L - The attacker fully controls level, optname, and optlen; passing a mismatched level bypasses the short-circuited length check, and cgroup BPF setsockopt can shrink optlen after entry, deterministically triggering a full-size memcpy past a small kmalloc buffer with no race.\nPR:L - No capability check guards SO_ATMQOS or SO_SETCLP on unconnected ATM sockets; any unprivileged local user in init_net (required because ATM socket creation rejects non-init network namespaces) can open AF_ATMPVC sockets and issue the crafted setsockopt without CAP_NET_ADMIN.\nUI:N - The attacker triggers the out-of-bounds read entirely from their own process with a single crafted setsockopt call; no victim interaction or cooperation is required.\nS:U - Impact is kernel heap memory disclosure and potential crash within the host kernel security boundary; no VM escape, IOMMU bypass, or cross-sandbox boundary crossing occurs.\nC:H - copy_from_sockptr() performs a slab-out-of-bounds read of up to 92 bytes (struct atm_qos) or 8 bytes (SO_SETCLP) past a kmalloc buffer into kernel stack memory; adjacent slab contents can populate vcc-\u003eqos and be retrieved via subsequent SO_ATMQOS getsockopt.\nI:N - The defect is a pure out-of-bounds read with no arbitrary kernel write, heap corruption, or control-flow hijack primitive; although leaked bytes may influence vcc-\u003eqos if validation passes, no attacker-controlled data modification occurs.\nA:H - The KASAN-reported slab-out-of-bounds read triggers kernel oops on hardened kernels, and reading past a small kmalloc object into adjacent slab memory on production kernels risks faulting on unmapped redzone pages or corrupting adjacent objects leading to panic."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:41:33.932Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b3bcd5d65ac03c15787b2a5b36c718e26a689336"
},
{
"url": "https://git.kernel.org/stable/c/35f258fee9ed358c6d0f57f91c30bf029c3724af"
},
{
"url": "https://git.kernel.org/stable/c/6eb6af88710977eb529b558a07294874d8c40c4d"
},
{
"url": "https://git.kernel.org/stable/c/9f77c1ab382188f5b51982fab6d913443b6dc59f"
},
{
"url": "https://git.kernel.org/stable/c/2c5988c7349c0b64a7e0441bfc6e1dca54f7116a"
},
{
"url": "https://git.kernel.org/stable/c/d0c80dbb970439bd2eeb0e5effff8c16a5f4e1e3"
}
],
"title": "net/atm: fix slab-out-of-bounds read in vcc_setsockopt()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74689",
"datePublished": "2026-08-22T15:32:54.034Z",
"dateReserved": "2026-08-15T05:44:03.926Z",
"dateUpdated": "2026-08-25T05:41:33.932Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80707 (GCVE-0-2026-80707)
Vulnerability from cvelistv5
Published
2026-08-28 06:53
Modified
2026-08-29 06:22
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
can: j1939: transport: j1939_session_fresh_new(): initialize receive buffer
Zero the allocated buffer in j1939_session_fresh_new() to ensure it
contains no residual data.
While there is a potential performance impact if users allocate maximum
sized ETP buffers, most real-world use cases are not noticeably affected
since the maximum known buffer size is typically around 65K.
[mkl: add Message-ID]
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 9d71dd0c70099914fcd063135da3c580865e924c Version: 9d71dd0c70099914fcd063135da3c580865e924c Version: 9d71dd0c70099914fcd063135da3c580865e924c Version: 9d71dd0c70099914fcd063135da3c580865e924c Version: 9d71dd0c70099914fcd063135da3c580865e924c Version: 9d71dd0c70099914fcd063135da3c580865e924c Version: 9d71dd0c70099914fcd063135da3c580865e924c Version: 9d71dd0c70099914fcd063135da3c580865e924c |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/can/j1939/transport.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "348818277a3646d5b9fa60c9d20c00dc4bc86832",
"status": "affected",
"version": "9d71dd0c70099914fcd063135da3c580865e924c",
"versionType": "git"
},
{
"lessThan": "f3e120a34b336079479fa10f706f0636eaa6e751",
"status": "affected",
"version": "9d71dd0c70099914fcd063135da3c580865e924c",
"versionType": "git"
},
{
"lessThan": "bbfa49d1e287de44994955b44d19281be3195b44",
"status": "affected",
"version": "9d71dd0c70099914fcd063135da3c580865e924c",
"versionType": "git"
},
{
"lessThan": "194d67e92197eb820f4c2c6605d9721333b3eba0",
"status": "affected",
"version": "9d71dd0c70099914fcd063135da3c580865e924c",
"versionType": "git"
},
{
"lessThan": "038bad8e16c2e28acf31f0b527a816fb23a57269",
"status": "affected",
"version": "9d71dd0c70099914fcd063135da3c580865e924c",
"versionType": "git"
},
{
"lessThan": "8604a3b81b9d0ceaf04fee5f52e701f623a179f9",
"status": "affected",
"version": "9d71dd0c70099914fcd063135da3c580865e924c",
"versionType": "git"
},
{
"lessThan": "d5b3613c7d69d8dcb4dd6704f1f463198ce9f6cf",
"status": "affected",
"version": "9d71dd0c70099914fcd063135da3c580865e924c",
"versionType": "git"
},
{
"lessThan": "eb96c58907922546e415e545fe9a14ea63b02719",
"status": "affected",
"version": "9d71dd0c70099914fcd063135da3c580865e924c",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/can/j1939/transport.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.4"
},
{
"lessThan": "5.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: j1939: transport: j1939_session_fresh_new(): initialize receive buffer\n\nZero the allocated buffer in j1939_session_fresh_new() to ensure it\ncontains no residual data.\n\nWhile there is a potential performance impact if users allocate maximum\nsized ETP buffers, most real-world use cases are not noticeably affected\nsince the maximum known buffer size is typically around 65K.\n\n[mkl: add Message-ID]"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - Received J1939 TP/ETP RTS frames enter j1939_can_recv()\u2192j1939_tp_recv()\u2192j1939_xtp_rx_rts_session_new()\u2192j1939_session_fresh_new() from the CAN receive path with no local syscall; telematics/CAN gateways routinely expose J1939 to remote peers, consistent with prior kernel CNA scores for the same subsystem (e.g. CVE-2023-52887, CVE-2026-22997).\nAC:L - The attacker controls RTS-declared message size, DATA/EOMA sequencing, and timing; skb_put() leaves the entire allocation uninitialized, j1939_xtp_rx_eoma_one() completes without verifying all data packets arrived, and recvmsg returns the full skb length\u2014reliably mixing attacker data with residual heap bytes (including trailing padding).\nPR:N - J1939 receive processing has no authentication gate; an unauthenticated CAN/J1939 peer can send crafted transport-control frames to a victim ECU that already runs a bound J1939 socket (normal automotive, trucking, and industrial deployments) without any Linux account or capability on the target.\nUI:N - No victim interaction is required beyond the target already operating the J1939 stack with a bound socket; the attacker only transmits crafted frames on the bus to trigger session allocation and completion.\nS:U - Uninitialized kernel heap contents are disclosed to matching local J1939 socket owners via recvmsg; impact remains within the same kernel security authority and does not cross VM, IOMMU, or sandbox boundaries.\nC:H - j1939_session_fresh_new() allocates the receive buffer with skb_put() instead of skb_put_zero(), so unfilled bytes retain prior slab contents; on completion j1939_session_completed() delivers the full total_message_size buffer (up to tp_max_packet_size, commonly ~65K) to userspace, disclosing kernel pointers and heap data.\nI:N - The bug only omits zero-initialization of the receive skb; there is no out-of-bounds write, use-after-free, or other memory-corruption primitive enabling integrity impact.\nA:N - Sessions complete or abort normally without kernel panic, oops, hang, or resource exhaustion; the vulnerability is an information-disclosure defect with no availability impact."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-29T06:22:24.493Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/348818277a3646d5b9fa60c9d20c00dc4bc86832"
},
{
"url": "https://git.kernel.org/stable/c/f3e120a34b336079479fa10f706f0636eaa6e751"
},
{
"url": "https://git.kernel.org/stable/c/bbfa49d1e287de44994955b44d19281be3195b44"
},
{
"url": "https://git.kernel.org/stable/c/194d67e92197eb820f4c2c6605d9721333b3eba0"
},
{
"url": "https://git.kernel.org/stable/c/038bad8e16c2e28acf31f0b527a816fb23a57269"
},
{
"url": "https://git.kernel.org/stable/c/8604a3b81b9d0ceaf04fee5f52e701f623a179f9"
},
{
"url": "https://git.kernel.org/stable/c/d5b3613c7d69d8dcb4dd6704f1f463198ce9f6cf"
},
{
"url": "https://git.kernel.org/stable/c/eb96c58907922546e415e545fe9a14ea63b02719"
}
],
"title": "can: j1939: transport: j1939_session_fresh_new(): initialize receive buffer",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80707",
"datePublished": "2026-08-28T06:53:08.244Z",
"dateReserved": "2026-08-26T14:34:25.787Z",
"dateUpdated": "2026-08-29T06:22:24.493Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74454 (GCVE-0-2026-74454)
Vulnerability from cvelistv5
Published
2026-08-15 12:26
Modified
2026-08-19 16:36
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO size
vc4_overflow_mem_work() points BPOA at a 512KB slot inside the 16MB
binner BO, but writes the size of the whole BO to BPOS. On every binner
out-of-memory event the PTB is therefore authorized to write tile lists
across all the other slots (which may hold the tile state, tile alloc and
overflow memory of in-flight jobs) and, for any slot but the first, past
the end of the binner BO into unrelated CMA memory.
Since CMA pages are recycled into page cache and user allocations, this
is arbitrary memory corruption by GPU DMA. In practice it shows up as GPU
hangs with corrupted control list pointers, userspace heap corruption, a
GPU that stays permanently wedged after the first hang, and occasional
full system crashes, whenever a job overflows the initial binner slot.
The bug dates back to the conversion from a dedicated overflow BO (where
writing the full BO size was correct) to the slotted binner BO.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 553c942f8b2cbc7394b4d4fa2f848b23a8f07451 Version: 553c942f8b2cbc7394b4d4fa2f848b23a8f07451 Version: 553c942f8b2cbc7394b4d4fa2f848b23a8f07451 Version: 553c942f8b2cbc7394b4d4fa2f848b23a8f07451 Version: 553c942f8b2cbc7394b4d4fa2f848b23a8f07451 Version: 553c942f8b2cbc7394b4d4fa2f848b23a8f07451 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/vc4/vc4_irq.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "bb5656ae063f2711f56438cf2f1f5b613aea5f12",
"status": "affected",
"version": "553c942f8b2cbc7394b4d4fa2f848b23a8f07451",
"versionType": "git"
},
{
"lessThan": "2f2291a119e9a8b696ae8bb36e86b75d272ceaea",
"status": "affected",
"version": "553c942f8b2cbc7394b4d4fa2f848b23a8f07451",
"versionType": "git"
},
{
"lessThan": "0badb30871004d34df87be33e853536f0b69885f",
"status": "affected",
"version": "553c942f8b2cbc7394b4d4fa2f848b23a8f07451",
"versionType": "git"
},
{
"lessThan": "6cd5acf6f87c073622bd61e38fe99c47365cda9c",
"status": "affected",
"version": "553c942f8b2cbc7394b4d4fa2f848b23a8f07451",
"versionType": "git"
},
{
"lessThan": "1e33ca7f44be64beed2735bb76b86eb65ba8c05b",
"status": "affected",
"version": "553c942f8b2cbc7394b4d4fa2f848b23a8f07451",
"versionType": "git"
},
{
"lessThan": "6395789e4739aa5177bbec0fa0f07ccc38d249b0",
"status": "affected",
"version": "553c942f8b2cbc7394b4d4fa2f848b23a8f07451",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/vc4/vc4_irq.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.13"
},
{
"lessThan": "4.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO size\n\nvc4_overflow_mem_work() points BPOA at a 512KB slot inside the 16MB\nbinner BO, but writes the size of the whole BO to BPOS. On every binner\nout-of-memory event the PTB is therefore authorized to write tile lists\nacross all the other slots (which may hold the tile state, tile alloc and\noverflow memory of in-flight jobs) and, for any slot but the first, past\nthe end of the binner BO into unrelated CMA memory.\n\nSince CMA pages are recycled into page cache and user allocations, this\nis arbitrary memory corruption by GPU DMA. In practice it shows up as GPU\nhangs with corrupted control list pointers, userspace heap corruption, a\nGPU that stays permanently wedged after the first hang, and occasional\nfull system crashes, whenever a job overflows the initial binner slot.\n\nThe bug dates back to the conversion from a dedicated overflow BO (where\nwriting the full BO size was correct) to the slotted binner BO."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires submitting crafted GPU jobs through the VC4 DRM render node via DRM_IOCTL_VC4_SUBMIT_CL; the bug is reached in vc4_overflow_mem_work() after hardware raises V3D_INT_OUTOMEM, which is a local ioctl/syscall path, not a network protocol.\nAC:L - An attacker with render-node access can reliably trigger binner out-of-memory by submitting dense geometry that exhausts the 32-byte initial per-bin allocation, and can run concurrent jobs to force non-zero overflow slots; no race or rare layout conditions beyond attacker-controlled GPU workloads are required.\nPR:L - VC4_SUBMIT_CL is permitted on DRM render nodes (DRM_RENDER_ALLOW, no DRM_AUTH) and vc4_open() performs no extra capability checks; on Raspberry Pi and similar VC4 deployments, unprivileged users in the render/video group routinely have /dev/dri/renderD* access to reach this path.\nUI:N - No victim interaction is required when the attacker is a local unprivileged user with render-node access who directly opens /dev/dri/renderD* and submits a malicious binning command list designed to overflow the initial binner slot.\nS:U - The flaw causes GPU DMA to corrupt CMA memory used by the kernel and userspace, enabling standard local privilege escalation; it does not cross a VM, IOMMU, or hypervisor security boundary and stays within the kernel\u0027s security authority.\nC:H - On OUTOMEM, the driver programs BPOA to a 512KB slot but BPOS to the full 16MB BO, authorizing the PTB to DMA-write far beyond the slot into adjacent in-flight job data and unrelated CMA pages recycled into page cache and user allocations, enabling arbitrary kernel memory disclosure.\nI:H - The oversized BPOS grants the GPU PTB an out-of-bounds DMA write primitive across other binner slots and past the 16MB BO boundary into unrelated CMA memory, corrupting kernel structures and userspace heaps in ways suitable for arbitrary code execution and privilege escalation.\nA:H - The commit reports that triggering binner overflow causes GPU hangs with corrupted control-list pointers, permanently wedged GPUs after the first hang, userspace heap corruption, and occasional full system crashes, satisfying high availability impact from repeatable kernel/GPU failure."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:36:46.319Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/bb5656ae063f2711f56438cf2f1f5b613aea5f12"
},
{
"url": "https://git.kernel.org/stable/c/2f2291a119e9a8b696ae8bb36e86b75d272ceaea"
},
{
"url": "https://git.kernel.org/stable/c/0badb30871004d34df87be33e853536f0b69885f"
},
{
"url": "https://git.kernel.org/stable/c/6cd5acf6f87c073622bd61e38fe99c47365cda9c"
},
{
"url": "https://git.kernel.org/stable/c/1e33ca7f44be64beed2735bb76b86eb65ba8c05b"
},
{
"url": "https://git.kernel.org/stable/c/6395789e4739aa5177bbec0fa0f07ccc38d249b0"
}
],
"title": "drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO size",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74454",
"datePublished": "2026-08-15T12:26:57.565Z",
"dateReserved": "2026-08-15T05:44:03.900Z",
"dateUpdated": "2026-08-19T16:36:46.319Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72124 (GCVE-0-2026-72124)
Vulnerability from cvelistv5
Published
2026-08-15 05:53
Modified
2026-08-19 16:36
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
can: isotp: serialize TX state transitions under so->rx_lock
The TX state machine (so->tx.state) is driven from three contexts:
sendmsg() claiming and progressing a transfer, the RX path consuming
Flow Control/echo frames, and two hrtimers timing out a stalled
transfer. Mixing a lock-free cmpxchg() claim in sendmsg() with
hrtimer_cancel() calls made under so->rx_lock elsewhere left windows
where a frame or timer callback could act on a state that had already
moved on, corrupting an unrelated transfer.
so->rx_lock now covers the full lifecycle of a TX claim: sendmsg()
takes it to check so->tx.state is ISOTP_IDLE, switch it to
ISOTP_SENDING, bump so->tx_gen and drain the previous transfer's
timers - all as one critical section. isotp_rcv_fc()/isotp_rcv_cf()
already run under this lock via isotp_rcv(), and isotp_rcv_echo() now
takes it itself, so none of them can ever observe a transfer mid-claim.
This also means a transfer can no longer be handed to sendmsg()'s
cleanup paths (signal or send error) while another thread is
concurrently claiming or finishing it, so those paths can cancel
timers and reset the state unconditionally.
isotp_release() claims the socket the same way, so a racing sendmsg()
sees a consistent ISOTP_SHUTDOWN and skips arming its timer or sending.
Only the hrtimer callbacks stay outside so->rx_lock, since they run
under so->rx_lock's cancellation elsewhere and taking it themselves
would deadlock. so->tx_gen lets them recognize whether the transfer
they timed out is still the one currently active, so they don't
report an error against a transfer that has since completed or been
superseded.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: e057dd3fc20ffb3d7f150af46542a51b59b90127 Version: e057dd3fc20ffb3d7f150af46542a51b59b90127 Version: e057dd3fc20ffb3d7f150af46542a51b59b90127 Version: e057dd3fc20ffb3d7f150af46542a51b59b90127 Version: e057dd3fc20ffb3d7f150af46542a51b59b90127 Version: e057dd3fc20ffb3d7f150af46542a51b59b90127 Version: e057dd3fc20ffb3d7f150af46542a51b59b90127 Version: e057dd3fc20ffb3d7f150af46542a51b59b90127 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/can/isotp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "bbedeb67a9a684f2fb78c55bd3662c400526715e",
"status": "affected",
"version": "e057dd3fc20ffb3d7f150af46542a51b59b90127",
"versionType": "git"
},
{
"lessThan": "377a8f500704da42ed86a4541ed930e9dcfdb2ea",
"status": "affected",
"version": "e057dd3fc20ffb3d7f150af46542a51b59b90127",
"versionType": "git"
},
{
"lessThan": "6da8119e8dd542194103139812d1a4b7dcd1aedd",
"status": "affected",
"version": "e057dd3fc20ffb3d7f150af46542a51b59b90127",
"versionType": "git"
},
{
"lessThan": "0b05eca9589f609e2491b528dccf683168a4cda8",
"status": "affected",
"version": "e057dd3fc20ffb3d7f150af46542a51b59b90127",
"versionType": "git"
},
{
"lessThan": "a7d90e7b5e75d7406c889fe36e9a61ee364a00cb",
"status": "affected",
"version": "e057dd3fc20ffb3d7f150af46542a51b59b90127",
"versionType": "git"
},
{
"lessThan": "37beb16e08cae94cc05840c7274225e3b0b38ae7",
"status": "affected",
"version": "e057dd3fc20ffb3d7f150af46542a51b59b90127",
"versionType": "git"
},
{
"lessThan": "4f1fdf1a1c317bcac0c6b6c8e12642c9983de1ca",
"status": "affected",
"version": "e057dd3fc20ffb3d7f150af46542a51b59b90127",
"versionType": "git"
},
{
"lessThan": "cf070fe33bfbd1a4c21236078fadb35dd223a157",
"status": "affected",
"version": "e057dd3fc20ffb3d7f150af46542a51b59b90127",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/can/isotp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.10"
},
{
"lessThan": "5.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: isotp: serialize TX state transitions under so-\u003erx_lock\n\nThe TX state machine (so-\u003etx.state) is driven from three contexts:\nsendmsg() claiming and progressing a transfer, the RX path consuming\nFlow Control/echo frames, and two hrtimers timing out a stalled\ntransfer. Mixing a lock-free cmpxchg() claim in sendmsg() with\nhrtimer_cancel() calls made under so-\u003erx_lock elsewhere left windows\nwhere a frame or timer callback could act on a state that had already\nmoved on, corrupting an unrelated transfer.\n\nso-\u003erx_lock now covers the full lifecycle of a TX claim: sendmsg()\ntakes it to check so-\u003etx.state is ISOTP_IDLE, switch it to\nISOTP_SENDING, bump so-\u003etx_gen and drain the previous transfer\u0027s\ntimers - all as one critical section. isotp_rcv_fc()/isotp_rcv_cf()\nalready run under this lock via isotp_rcv(), and isotp_rcv_echo() now\ntakes it itself, so none of them can ever observe a transfer mid-claim.\nThis also means a transfer can no longer be handed to sendmsg()\u0027s\ncleanup paths (signal or send error) while another thread is\nconcurrently claiming or finishing it, so those paths can cancel\ntimers and reset the state unconditionally.\n\nisotp_release() claims the socket the same way, so a racing sendmsg()\nsees a consistent ISOTP_SHUTDOWN and skips arming its timer or sending.\n\nOnly the hrtimer callbacks stay outside so-\u003erx_lock, since they run\nunder so-\u003erx_lock\u0027s cancellation elsewhere and taking it themselves\nwould deadlock. so-\u003etx_gen lets them recognize whether the transfer\nthey timed out is still the one currently active, so they don\u0027t\nreport an error against a transfer that has since completed or been\nsuperseded."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The bug is hit on the SocketCAN receive path (can_rcv\u2192isotp_rcv/isotp_rcv_echo for FC/echo frames) racing sendmsg() and hrtimers; in automotive/industrial ISO-TP (UDS) deployments an attacker on the same CAN segment can inject timed FC/echo frames without host shell access.\nAC:L - The attacker controls both sides of the race via concurrent sendmsg()/close() threads plus crafted FC/echo traffic and timer timing; sashiko-bot/syzkaller reproduces it reliably with no conditions outside attacker influence.\nPR:N - Once a victim ISO-TP socket is bound and transmitting (normal diagnostic behavior), an unauthenticated CAN bus peer needs no Linux credentials; CAN_ISOTP socket create/bind/sendmsg paths impose no capability checks.\nUI:N - No victim interaction beyond routine background ISO-TP traffic on an already-bound socket; the attacker drives concurrent transfers and FC/echo timing to hit the unsynchronized TX state transitions.\nS:U - Impact is kernel ISO-TP/socket heap corruption within the same OS security authority, without inherent VM escape, container breakout, or IOMMU boundary crossing.\nC:H - Mis-serialized so-\u003etx.state, tx.idx, and rx reassembly state lets stale echo/FC/timer handlers operate on the wrong transfer, enabling out-of-bounds reads from tpcon tx/rx buffers and adjacent kernel heap disclosure.\nI:H - The same cross-transfer corruption writes through tpcon buffers and socket state (indices, sequence numbers, timers), yielding attacker-influenced kernel heap corruption rather than a benign protocol error.\nA:H - Stale timers and handlers acting on superseded transfers can provoke sk_err storms, skb/state corruption, and kernel oops/panic in softirq/timer context, matching prior isotp timer race failures and repeatable DoS."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:36:21.129Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/bbedeb67a9a684f2fb78c55bd3662c400526715e"
},
{
"url": "https://git.kernel.org/stable/c/377a8f500704da42ed86a4541ed930e9dcfdb2ea"
},
{
"url": "https://git.kernel.org/stable/c/6da8119e8dd542194103139812d1a4b7dcd1aedd"
},
{
"url": "https://git.kernel.org/stable/c/0b05eca9589f609e2491b528dccf683168a4cda8"
},
{
"url": "https://git.kernel.org/stable/c/a7d90e7b5e75d7406c889fe36e9a61ee364a00cb"
},
{
"url": "https://git.kernel.org/stable/c/37beb16e08cae94cc05840c7274225e3b0b38ae7"
},
{
"url": "https://git.kernel.org/stable/c/4f1fdf1a1c317bcac0c6b6c8e12642c9983de1ca"
},
{
"url": "https://git.kernel.org/stable/c/cf070fe33bfbd1a4c21236078fadb35dd223a157"
}
],
"title": "can: isotp: serialize TX state transitions under so-\u003erx_lock",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72124",
"datePublished": "2026-08-15T05:53:02.172Z",
"dateReserved": "2026-08-09T03:40:39.907Z",
"dateUpdated": "2026-08-19T16:36:21.129Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2025-40168 (GCVE-0-2025-40168)
Vulnerability from cvelistv5
Published
2025-11-12 10:46
Modified
2026-09-02 12:49
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
smc: Use __sk_dst_get() and dst_dev_rcu() in smc_clc_prfx_match().
smc_clc_prfx_match() is called from smc_listen_work() and
not under RCU nor RTNL.
Using sk_dst_get(sk)->dev could trigger UAF.
Let's use __sk_dst_get() and dst_dev_rcu().
Note that the returned value of smc_clc_prfx_match() is not
used in the caller.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2025-40168",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-06-16T19:59:59.004592Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-06-16T20:00:14.873Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/smc/smc_clc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "3f119c37aa293af41400cccb3d89fab8dcf774b0",
"status": "affected",
"version": "a046d57da19f812216f393e7c535f5858f793ac3",
"versionType": "git"
},
{
"lessThan": "4f5f52a5842937f945582a93cb9daed9ea526fee",
"status": "affected",
"version": "a046d57da19f812216f393e7c535f5858f793ac3",
"versionType": "git"
},
{
"lessThan": "326e5cf301d0bec0a672aa834d8254c4f9df6255",
"status": "affected",
"version": "a046d57da19f812216f393e7c535f5858f793ac3",
"versionType": "git"
},
{
"lessThan": "d26e80f7fb62d77757b67a1b94e4ac756bc9c658",
"status": "affected",
"version": "a046d57da19f812216f393e7c535f5858f793ac3",
"versionType": "git"
},
{
"lessThan": "235f81045c008169cc4e1955b4a64e118eebe61b",
"status": "affected",
"version": "a046d57da19f812216f393e7c535f5858f793ac3",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/smc/smc_clc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.11"
},
{
"lessThan": "4.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.187",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.156",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.108",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.17.*",
"status": "unaffected",
"version": "6.17.3",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "6.18",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.187",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.156",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.108",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.17.3",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18",
"versionStartIncluding": "4.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmc: Use __sk_dst_get() and dst_dev_rcu() in smc_clc_prfx_match().\n\nsmc_clc_prfx_match() is called from smc_listen_work() and\nnot under RCU nor RTNL.\n\nUsing sk_dst_get(sk)-\u003edev could trigger UAF.\n\nLet\u0027s use __sk_dst_get() and dst_dev_rcu().\n\nNote that the returned value of smc_clc_prfx_match() is not\nused in the caller."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The vulnerable read is performed by the SMC listen worker while parsing a CLC Proposal message received over TCP from a remote peer (smc_listen_work \u2192 smc_listen_find_device \u2192 smc_listen_prfx_check \u2192 smc_clc_prfx_match), and the peer controls the fields that select and drive the code path. Any host running an AF_SMC listener is exposed to unauthenticated remote connections.\nAC:H - The attacker fully controls one side of the race (when the CLC Proposal arrives and thus when the stale dst-\u003edev is dereferenced), but the other side requires the route\u0027s net_device to be concurrently torn down via dst_dev_put()/free_netdev(), which a remote attacker cannot induce or time.\nPR:N - The CLC handshake is the first exchange on the connection and SMC performs no authentication before smc_clc_prfx_match() runs, so an unauthenticated remote attacker reaches the bug with no credentials of any kind.\nUI:N - Triggering requires only that the attacker complete a TCP handshake with the SMC option and send a CLC Proposal; no action by any local user or administrator is needed.\nS:U - The use-after-free is confined to kernel memory (the net_device slab and the in_dev/inet6_dev structures it points at) within the kernel\u0027s own security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - The freed net_device is dereferenced and its ifa_list/addr_list walked, and since a reclaimed slab can be groomed with attacker-controlled data this yields an arbitrary kernel-memory read primitive; the match/no-match outcome is additionally returned to the peer as SMC_CLC_DECL_DIFFPREFIX, forming a remotely observable oracle on freed memory contents.\nI:H - A use-after-free of a net_device is a heap-corruption primitive: the reclaimed object\u0027s contents are attacker-influencable via heap spraying and the code follows pointers out of it, which can be groomed into an arbitrary write and control-flow hijack.\nA:H - Dereferencing the freed net_device and walking a bogus in_dev/inet6_dev address list reliably produces a kernel oops, panic, or an unbounded list walk, crashing the system."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-02T12:49:28.040Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/3f119c37aa293af41400cccb3d89fab8dcf774b0"
},
{
"url": "https://git.kernel.org/stable/c/4f5f52a5842937f945582a93cb9daed9ea526fee"
},
{
"url": "https://git.kernel.org/stable/c/326e5cf301d0bec0a672aa834d8254c4f9df6255"
},
{
"url": "https://git.kernel.org/stable/c/d26e80f7fb62d77757b67a1b94e4ac756bc9c658"
},
{
"url": "https://git.kernel.org/stable/c/235f81045c008169cc4e1955b4a64e118eebe61b"
}
],
"title": "smc: Use __sk_dst_get() and dst_dev_rcu() in smc_clc_prfx_match().",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2025-40168",
"datePublished": "2025-11-12T10:46:51.422Z",
"dateReserved": "2025-04-16T07:20:57.176Z",
"dateUpdated": "2026-09-02T12:49:28.040Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72260 (GCVE-0-2026-72260)
Vulnerability from cvelistv5
Published
2026-08-15 05:54
Modified
2026-08-23 12:47
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ASoC: mediatek: mt8192: Check runtime resume during probe
The MT8192 AFE probe enables runtime PM temporarily while reinitializing
the regmap cache from hardware, but it uses pm_runtime_get_sync()
without checking the return value. If runtime resume fails, probe keeps
going without the device necessarily being accessible, and
pm_runtime_get_sync() may leave the PM usage count incremented.
The regmap_reinit_cache() failure path also returns before dropping the
temporary PM reference and before clearing pm_runtime_bypass_reg_ctl.
Use pm_runtime_resume_and_get() so resume failures do not leak a usage
count, and clear the temporary bypass flag after dropping the probe PM
reference on all regmap_reinit_cache() outcomes.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 125ab5d588b0b3b842064c4d53a666ca74521ae8 Version: 125ab5d588b0b3b842064c4d53a666ca74521ae8 Version: 125ab5d588b0b3b842064c4d53a666ca74521ae8 Version: 125ab5d588b0b3b842064c4d53a666ca74521ae8 Version: 125ab5d588b0b3b842064c4d53a666ca74521ae8 Version: 125ab5d588b0b3b842064c4d53a666ca74521ae8 Version: 125ab5d588b0b3b842064c4d53a666ca74521ae8 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"sound/soc/mediatek/mt8192/mt8192-afe-pcm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "9339266a8a720889d0385cfd78ba6652fe7bb1a8",
"status": "affected",
"version": "125ab5d588b0b3b842064c4d53a666ca74521ae8",
"versionType": "git"
},
{
"lessThan": "91b20e8c9b64042056d14394c89c81fc16a1c327",
"status": "affected",
"version": "125ab5d588b0b3b842064c4d53a666ca74521ae8",
"versionType": "git"
},
{
"lessThan": "6e2ee6eacc3ec7b339753abcf33812d27e03efe5",
"status": "affected",
"version": "125ab5d588b0b3b842064c4d53a666ca74521ae8",
"versionType": "git"
},
{
"lessThan": "faa97a1a6cab01cd3e2055deb4db4e57efc43ff2",
"status": "affected",
"version": "125ab5d588b0b3b842064c4d53a666ca74521ae8",
"versionType": "git"
},
{
"lessThan": "e0f276f1918a202e9c3ac72baffd311cecb6b8db",
"status": "affected",
"version": "125ab5d588b0b3b842064c4d53a666ca74521ae8",
"versionType": "git"
},
{
"lessThan": "f6e424835cc05d215c57b6370b2c1e353dd02915",
"status": "affected",
"version": "125ab5d588b0b3b842064c4d53a666ca74521ae8",
"versionType": "git"
},
{
"lessThan": "e24d5dde56a50946020b134fa8448869093db76a",
"status": "affected",
"version": "125ab5d588b0b3b842064c4d53a666ca74521ae8",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"sound/soc/mediatek/mt8192/mt8192-afe-pcm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.11"
},
{
"lessThan": "5.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: mediatek: mt8192: Check runtime resume during probe\n\nThe MT8192 AFE probe enables runtime PM temporarily while reinitializing\nthe regmap cache from hardware, but it uses pm_runtime_get_sync()\nwithout checking the return value. If runtime resume fails, probe keeps\ngoing without the device necessarily being accessible, and\npm_runtime_get_sync() may leave the PM usage count incremented.\n\nThe regmap_reinit_cache() failure path also returns before dropping the\ntemporary PM reference and before clearing pm_runtime_bypass_reg_ctl.\n\nUse pm_runtime_resume_and_get() so resume failures do not leak a usage\ncount, and clear the temporary bypass flag after dropping the probe PM\nreference on all regmap_reinit_cache() outcomes."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:47:10.221Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/9339266a8a720889d0385cfd78ba6652fe7bb1a8"
},
{
"url": "https://git.kernel.org/stable/c/91b20e8c9b64042056d14394c89c81fc16a1c327"
},
{
"url": "https://git.kernel.org/stable/c/6e2ee6eacc3ec7b339753abcf33812d27e03efe5"
},
{
"url": "https://git.kernel.org/stable/c/faa97a1a6cab01cd3e2055deb4db4e57efc43ff2"
},
{
"url": "https://git.kernel.org/stable/c/e0f276f1918a202e9c3ac72baffd311cecb6b8db"
},
{
"url": "https://git.kernel.org/stable/c/f6e424835cc05d215c57b6370b2c1e353dd02915"
},
{
"url": "https://git.kernel.org/stable/c/e24d5dde56a50946020b134fa8448869093db76a"
}
],
"title": "ASoC: mediatek: mt8192: Check runtime resume during probe",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72260",
"datePublished": "2026-08-15T05:54:48.409Z",
"dateReserved": "2026-08-09T03:40:39.915Z",
"dateUpdated": "2026-08-23T12:47:10.221Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74453 (GCVE-0-2026-74453)
Vulnerability from cvelistv5
Published
2026-08-15 12:26
Modified
2026-08-19 16:36
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/vc4: Zero the tile state data array before each BIN job
The binner BO is a single 16MB buffer split into 512KB slots that are
handed out to jobs at submission time and recycled as jobs complete,
without ever being cleared. Each slot holds the job's Tile State Data
Array (TSDA) at its start, followed by the tile allocation pool.
While the tile allocation pool is only walked by the render thread
through branches the binner generated during the current job, the
TSDA is the PTB's own per-tile bookkeeping and is consumed by the
hardware itself. Although the kernel sets the "Auto-initialise Tile
State Data Array" flag in the tile binning mode configuration, the
PTB demonstrably still acts on stale tile state left by the slot's
previous user: the binner ends up creating invalid command streams
with invalid primitive streams and branches, which can cause GPU hangs
as observed in [1][2].
Zero the TSDA when the job's binning slot is configured. This clears
48 bytes per tile (~24KB for a 1080p frame) in the submission path, and
guarantees the PTB never sees another job's tile state.
The tile count is only checked for being non-zero today, so the 8-bit
fields it comes from can describe a tile state array almost six times
larger than the slot it has to live in. Bound it before the slot is
handed out, since such size decides how much of the slot is left for
the tile alloc pool.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 553c942f8b2cbc7394b4d4fa2f848b23a8f07451 Version: 553c942f8b2cbc7394b4d4fa2f848b23a8f07451 Version: 553c942f8b2cbc7394b4d4fa2f848b23a8f07451 Version: 553c942f8b2cbc7394b4d4fa2f848b23a8f07451 Version: 553c942f8b2cbc7394b4d4fa2f848b23a8f07451 Version: 553c942f8b2cbc7394b4d4fa2f848b23a8f07451 Version: 553c942f8b2cbc7394b4d4fa2f848b23a8f07451 Version: 553c942f8b2cbc7394b4d4fa2f848b23a8f07451 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/vc4/vc4_validate.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c5d8e8e1a8e3b4e464683c5a8a869c16a6382fea",
"status": "affected",
"version": "553c942f8b2cbc7394b4d4fa2f848b23a8f07451",
"versionType": "git"
},
{
"lessThan": "d3677372e0275e139f0efd2872c5a524b5d12868",
"status": "affected",
"version": "553c942f8b2cbc7394b4d4fa2f848b23a8f07451",
"versionType": "git"
},
{
"lessThan": "c8dea7e7c6098e383e44f21a64d0431da5480e3f",
"status": "affected",
"version": "553c942f8b2cbc7394b4d4fa2f848b23a8f07451",
"versionType": "git"
},
{
"lessThan": "f5802be65535f8818af7191159cf8c11f48ab2a2",
"status": "affected",
"version": "553c942f8b2cbc7394b4d4fa2f848b23a8f07451",
"versionType": "git"
},
{
"lessThan": "0e858422df2334165293ea742da9fbb2e51f2739",
"status": "affected",
"version": "553c942f8b2cbc7394b4d4fa2f848b23a8f07451",
"versionType": "git"
},
{
"lessThan": "57667eb7548faaac396c6e39f3b4444dab5b097c",
"status": "affected",
"version": "553c942f8b2cbc7394b4d4fa2f848b23a8f07451",
"versionType": "git"
},
{
"lessThan": "a75c8f365e209aa9bb927b0942a7840152d44892",
"status": "affected",
"version": "553c942f8b2cbc7394b4d4fa2f848b23a8f07451",
"versionType": "git"
},
{
"lessThan": "48a570c964d8e37d353381e4195106277e17f5cb",
"status": "affected",
"version": "553c942f8b2cbc7394b4d4fa2f848b23a8f07451",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/vc4/vc4_validate.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.13"
},
{
"lessThan": "4.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vc4: Zero the tile state data array before each BIN job\n\nThe binner BO is a single 16MB buffer split into 512KB slots that are\nhanded out to jobs at submission time and recycled as jobs complete,\nwithout ever being cleared. Each slot holds the job\u0027s Tile State Data\nArray (TSDA) at its start, followed by the tile allocation pool.\n\nWhile the tile allocation pool is only walked by the render thread\nthrough branches the binner generated during the current job, the\nTSDA is the PTB\u0027s own per-tile bookkeeping and is consumed by the\nhardware itself. Although the kernel sets the \"Auto-initialise Tile\nState Data Array\" flag in the tile binning mode configuration, the\nPTB demonstrably still acts on stale tile state left by the slot\u0027s\nprevious user: the binner ends up creating invalid command streams\nwith invalid primitive streams and branches, which can cause GPU hangs\nas observed in [1][2].\n\nZero the TSDA when the job\u0027s binning slot is configured. This clears\n48 bytes per tile (~24KB for a 1080p frame) in the submission path, and\nguarantees the PTB never sees another job\u0027s tile state.\n\nThe tile count is only checked for being non-zero today, so the 8-bit\nfields it comes from can describe a tile state array almost six times\nlarger than the slot it has to live in. Bound it before the slot is\nhanded out, since such size decides how much of the slot is left for\nthe tile alloc pool."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The flaw is reached in validate_tile_binning_config() while validating a user bin command list during DRM_IOCTL_VC4_SUBMIT_CL on the VC4 DRM render node (/dev/dri/renderD*), a local ioctl path rather than any network-facing protocol.\nAC:L - An attacker with render-node access controls TILE_BINNING_MODE_CONFIG tile dimensions and can submit concurrent or back-to-back bin jobs to obtain recycled 512KB binner slots carrying stale TSDA; no uncontrollable races or rare kernel config are required.\nPR:L - VC4_SUBMIT_CL is registered with DRM_RENDER_ALLOW only (no DRM_AUTH) and vc4_open() performs no capability checks; unprivileged users in the render/video group on Raspberry Pi and other VC4 deployments routinely open /dev/dri/renderD*.\nUI:N - No victim interaction is needed when a local attacker with render-node access crafts and submits a malicious bin command list via DRM_IOCTL_VC4_SUBMIT_CL to trigger recycled-slot stale tile state or oversized tile counts.\nS:U - Impact is stale-state and GPU PTB misbehavior corrupting shared CMA binner memory for local privilege escalation; it does not cross VM, hypervisor, or IOMMU boundaries and remains within the kernel security authority.\nC:H - Recycled 512KB slots retain prior jobs\u0027 48-byte-per-tile TSDA in the shared 16MB CMA binner BO (cross-process GPU address/metadata leak); missing tile-count bounds let the PTB consume up to ~3MB TSDA spanning multiple slots and stale pointers misdirect PTB reads.\nI:H - Stale TSDA drives the PTB to build invalid primitive streams and branches with out-of-slot GPU DMA across the shared binner BO; unbounded 8-bit tile counts also make tile_alloc_size wrap to ~4GB while tile_alloc_offset points past the 512KB slot, enabling arbitrary CMA corruption.\nA:H - The fix commit and linked Raspberry Pi issues document GPU hangs, repeated \"[drm] Resetting GPU\", permanently wedged GPUs after invalid bin streams, display corruption, and full system lockups requiring power-cycle or reboot."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:36:43.715Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c5d8e8e1a8e3b4e464683c5a8a869c16a6382fea"
},
{
"url": "https://git.kernel.org/stable/c/d3677372e0275e139f0efd2872c5a524b5d12868"
},
{
"url": "https://git.kernel.org/stable/c/c8dea7e7c6098e383e44f21a64d0431da5480e3f"
},
{
"url": "https://git.kernel.org/stable/c/f5802be65535f8818af7191159cf8c11f48ab2a2"
},
{
"url": "https://git.kernel.org/stable/c/0e858422df2334165293ea742da9fbb2e51f2739"
},
{
"url": "https://git.kernel.org/stable/c/57667eb7548faaac396c6e39f3b4444dab5b097c"
},
{
"url": "https://git.kernel.org/stable/c/a75c8f365e209aa9bb927b0942a7840152d44892"
},
{
"url": "https://git.kernel.org/stable/c/48a570c964d8e37d353381e4195106277e17f5cb"
}
],
"title": "drm/vc4: Zero the tile state data array before each BIN job",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74453",
"datePublished": "2026-08-15T12:26:56.949Z",
"dateReserved": "2026-08-15T05:44:03.899Z",
"dateUpdated": "2026-08-19T16:36:43.715Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80764 (GCVE-0-2026-80764)
Vulnerability from cvelistv5
Published
2026-09-04 15:12
Modified
2026-09-04 15:12
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci_event: fix LE list UAF on reset
hci_cc_reset() clears the LE accept and resolving lists without taking
hdev->lock. Other command-complete handlers serialize updates to these
lists with that lock, and the debugfs readers hold it while walking them.
This permits the reset completion and a debugfs read to interleave as
follows:
hci_rx_work debugfs reader
----------- --------------
lock hdev->lock
fetch current entry
list_del(entry)
kfree(entry)
read entry fields
The reader then dereferences a freed list entry and may follow its stale
next pointer.
KASAN reported:
BUG: KASAN: slab-use-after-free in white_list_show+0x15f/0x180
Read of size 1 at addr ffff8881015dab16 by task poc/95
Call Trace:
white_list_show+0x15f/0x180
seq_read_iter+0x3ff/0x1190
seq_read+0x267/0x3d0
vfs_read+0x177/0xa20
ksys_read+0xf7/0x1c0
Allocated by task 91:
hci_bdaddr_list_add+0x1a6/0x3a0
hci_cc_le_add_to_accept_list+0xab/0x140
hci_cmd_complete_evt+0x26c/0x9a0
hci_event_packet+0x454/0xb20
hci_rx_work+0x293/0x730
Freed by task 90:
kfree+0x131/0x3c0
hci_bdaddr_list_clear+0xd8/0x160
hci_cc_reset+0x28a/0x370
hci_cmd_complete_evt+0x26c/0x9a0
hci_event_packet+0x454/0xb20
hci_rx_work+0x293/0x730
Take hdev->lock around both list clears. This matches the existing
mutation and traversal locking convention.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: a4d5504d5c39cc84f1f828e19967595597a8136e Version: a4d5504d5c39cc84f1f828e19967595597a8136e Version: a4d5504d5c39cc84f1f828e19967595597a8136e Version: a4d5504d5c39cc84f1f828e19967595597a8136e Version: a4d5504d5c39cc84f1f828e19967595597a8136e Version: a4d5504d5c39cc84f1f828e19967595597a8136e Version: a4d5504d5c39cc84f1f828e19967595597a8136e Version: 0de8cd646b0152c9ddd10257d8284938d0df0181 Version: 3.18.3 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/bluetooth/hci_event.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "8e68c380290b1dd64a0a512ce66d0264130c46ed",
"status": "affected",
"version": "a4d5504d5c39cc84f1f828e19967595597a8136e",
"versionType": "git"
},
{
"lessThan": "0628cc9b2fa29985a7b8c774741f8a736b0f5e7c",
"status": "affected",
"version": "a4d5504d5c39cc84f1f828e19967595597a8136e",
"versionType": "git"
},
{
"lessThan": "d57702d4c55633c243da5a2fec37ae2ad4adb621",
"status": "affected",
"version": "a4d5504d5c39cc84f1f828e19967595597a8136e",
"versionType": "git"
},
{
"lessThan": "39a3afb91be3cb465f46ce7a8e5696d9e33edf93",
"status": "affected",
"version": "a4d5504d5c39cc84f1f828e19967595597a8136e",
"versionType": "git"
},
{
"lessThan": "b55e83a4ba31d40deae22d4e4dc8c84083e953c6",
"status": "affected",
"version": "a4d5504d5c39cc84f1f828e19967595597a8136e",
"versionType": "git"
},
{
"lessThan": "25b05e3ce31d954540e99954bcc66cbceb27ab35",
"status": "affected",
"version": "a4d5504d5c39cc84f1f828e19967595597a8136e",
"versionType": "git"
},
{
"lessThan": "33af47e847fe4a28b109673affb5874015d54f5a",
"status": "affected",
"version": "a4d5504d5c39cc84f1f828e19967595597a8136e",
"versionType": "git"
},
{
"status": "affected",
"version": "0de8cd646b0152c9ddd10257d8284938d0df0181",
"versionType": "git"
},
{
"lessThan": "3.19",
"status": "affected",
"version": "3.18.3",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/bluetooth/hci_event.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.19"
},
{
"lessThan": "3.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.185",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.154",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.106",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.47",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.1",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.185",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.154",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.106",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.47",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.11",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.1",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.18.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_event: fix LE list UAF on reset\n\nhci_cc_reset() clears the LE accept and resolving lists without taking\nhdev-\u003elock. Other command-complete handlers serialize updates to these\nlists with that lock, and the debugfs readers hold it while walking them.\n\nThis permits the reset completion and a debugfs read to interleave as\nfollows:\n\n hci_rx_work debugfs reader\n ----------- --------------\n lock hdev-\u003elock\n fetch current entry\n list_del(entry)\n kfree(entry)\n read entry fields\n\nThe reader then dereferences a freed list entry and may follow its stale\nnext pointer.\n\nKASAN reported:\n\n BUG: KASAN: slab-use-after-free in white_list_show+0x15f/0x180\n Read of size 1 at addr ffff8881015dab16 by task poc/95\n\n Call Trace:\n white_list_show+0x15f/0x180\n seq_read_iter+0x3ff/0x1190\n seq_read+0x267/0x3d0\n vfs_read+0x177/0xa20\n ksys_read+0xf7/0x1c0\n\n Allocated by task 91:\n hci_bdaddr_list_add+0x1a6/0x3a0\n hci_cc_le_add_to_accept_list+0xab/0x140\n hci_cmd_complete_evt+0x26c/0x9a0\n hci_event_packet+0x454/0xb20\n hci_rx_work+0x293/0x730\n\n Freed by task 90:\n kfree+0x131/0x3c0\n hci_bdaddr_list_clear+0xd8/0x160\n hci_cc_reset+0x28a/0x370\n hci_cmd_complete_evt+0x26c/0x9a0\n hci_event_packet+0x454/0xb20\n hci_rx_work+0x293/0x730\n\nTake hdev-\u003elock around both list clears. This matches the existing\nmutation and traversal locking convention."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T15:12:36.599Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/8e68c380290b1dd64a0a512ce66d0264130c46ed"
},
{
"url": "https://git.kernel.org/stable/c/0628cc9b2fa29985a7b8c774741f8a736b0f5e7c"
},
{
"url": "https://git.kernel.org/stable/c/d57702d4c55633c243da5a2fec37ae2ad4adb621"
},
{
"url": "https://git.kernel.org/stable/c/39a3afb91be3cb465f46ce7a8e5696d9e33edf93"
},
{
"url": "https://git.kernel.org/stable/c/b55e83a4ba31d40deae22d4e4dc8c84083e953c6"
},
{
"url": "https://git.kernel.org/stable/c/25b05e3ce31d954540e99954bcc66cbceb27ab35"
},
{
"url": "https://git.kernel.org/stable/c/33af47e847fe4a28b109673affb5874015d54f5a"
}
],
"title": "Bluetooth: hci_event: fix LE list UAF on reset",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80764",
"datePublished": "2026-09-04T15:12:36.599Z",
"dateReserved": "2026-08-26T14:34:25.791Z",
"dateUpdated": "2026-09-04T15:12:36.599Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74481 (GCVE-0-2026-74481)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-19 16:37
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
mm/page_reporting: use system_freezable_wq to fix UAF during suspend
During PM freeze (e.g. S3 suspend or S4 hibernation), device drivers like
virtio_balloon reset their underlying virtio devices and delete their
virtqueues via vdev->config->del_vqs().
However, page reporting work (page_reporting_process) was scheduled on the
global system_wq. Because system_wq lacks the WQ_FREEZABLE flag, the PM
freezer skips it, leaving page_reporting_process active during suspend.
If pages are freed into the buddy allocator while suspending (for example,
when core MM invokes the balloon shrinker during S4 hibernation image
saving), page reporting triggers virtballoon_free_page_report() on deleted
virtqueues, resulting in a Use-After-Free / General Protection Fault:
[ 196.795226] general protection fault, probably for non-canonical address 0xaa1436fe70dae6df: 0000 [#1] SMP NOPTI
[ 196.825967] Workqueue: events page_reporting_process
[ 196.831038] RIP: 0010:virtqueue_add_split+0x233/0x4c0 [virtio_ring]
[ 196.927073] virtballoon_free_page_report+0x3a/0xe0 [virtio_balloon]
[ 196.946943] page_reporting_process+0x370/0x4f0
Fix this by switching page reporting work to system_freezable_wq. This
ensures that the PM freezer pauses page_reporting_process before device
drivers destroy their reporting virtqueues. Because the reporting worker
is frozen, memory reclamation/freeing (e.g. via shrinker execution) can
safely return pages to MM during freeze without triggering unfrozen
reporting work on deleted virtqueues.
This aligns with the driver's existing design. The comment in
virtballoon_freeze() states:
/*
* The workqueue is already frozen by the PM core before this
* function is called.
*/
Testing:
I have verified these fixes using Google’s virtualization infrastructure
by running continuous suspend/resume iterations (40+ cycles) while
churning memory using stress-ng (`stress-ng --vm 4 --vm-bytes 60%
--timeout 1`) to constantly create free pages for the buddy allocator. We
also set the `page_reporting_order` parameter to 0 to make the page
reporting worker highly sensitive, forcing it to pick up any 4K free
pages. This confirmed that the UAF crashes are no longer reproducible.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 36e66c554b5c6a9d17a229faca7a61693527b0bd Version: 36e66c554b5c6a9d17a229faca7a61693527b0bd Version: 36e66c554b5c6a9d17a229faca7a61693527b0bd Version: 36e66c554b5c6a9d17a229faca7a61693527b0bd Version: 36e66c554b5c6a9d17a229faca7a61693527b0bd Version: 36e66c554b5c6a9d17a229faca7a61693527b0bd Version: 36e66c554b5c6a9d17a229faca7a61693527b0bd Version: 36e66c554b5c6a9d17a229faca7a61693527b0bd |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"mm/page_reporting.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a4c60046052777ca1dcc83fe3ece2a5136b301f1",
"status": "affected",
"version": "36e66c554b5c6a9d17a229faca7a61693527b0bd",
"versionType": "git"
},
{
"lessThan": "b2c094e98f8bb823b3ae475f7169fe2091c40c6d",
"status": "affected",
"version": "36e66c554b5c6a9d17a229faca7a61693527b0bd",
"versionType": "git"
},
{
"lessThan": "992f270fd808338fbae1f498a5e325e7e2e20368",
"status": "affected",
"version": "36e66c554b5c6a9d17a229faca7a61693527b0bd",
"versionType": "git"
},
{
"lessThan": "f978048326570047e8216e81a67f9c71ef2bb1b1",
"status": "affected",
"version": "36e66c554b5c6a9d17a229faca7a61693527b0bd",
"versionType": "git"
},
{
"lessThan": "450f35f4d5a682a0796757e52295df58ddb63bc9",
"status": "affected",
"version": "36e66c554b5c6a9d17a229faca7a61693527b0bd",
"versionType": "git"
},
{
"lessThan": "b11907c905fa08eda925395f0724b7a409870f65",
"status": "affected",
"version": "36e66c554b5c6a9d17a229faca7a61693527b0bd",
"versionType": "git"
},
{
"lessThan": "faf439b5fa7b231120eac4f7a617e0bfd4f6f5c7",
"status": "affected",
"version": "36e66c554b5c6a9d17a229faca7a61693527b0bd",
"versionType": "git"
},
{
"lessThan": "0b45f6927a14914ff685fe0e6f9d11232a1e03df",
"status": "affected",
"version": "36e66c554b5c6a9d17a229faca7a61693527b0bd",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"mm/page_reporting.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.7"
},
{
"lessThan": "5.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/page_reporting: use system_freezable_wq to fix UAF during suspend\n\nDuring PM freeze (e.g. S3 suspend or S4 hibernation), device drivers like\nvirtio_balloon reset their underlying virtio devices and delete their\nvirtqueues via vdev-\u003econfig-\u003edel_vqs().\n\nHowever, page reporting work (page_reporting_process) was scheduled on the\nglobal system_wq. Because system_wq lacks the WQ_FREEZABLE flag, the PM\nfreezer skips it, leaving page_reporting_process active during suspend.\n\nIf pages are freed into the buddy allocator while suspending (for example,\nwhen core MM invokes the balloon shrinker during S4 hibernation image\nsaving), page reporting triggers virtballoon_free_page_report() on deleted\nvirtqueues, resulting in a Use-After-Free / General Protection Fault:\n\n [ 196.795226] general protection fault, probably for non-canonical address 0xaa1436fe70dae6df: 0000 [#1] SMP NOPTI\n [ 196.825967] Workqueue: events page_reporting_process\n [ 196.831038] RIP: 0010:virtqueue_add_split+0x233/0x4c0 [virtio_ring]\n [ 196.927073] virtballoon_free_page_report+0x3a/0xe0 [virtio_balloon]\n [ 196.946943] page_reporting_process+0x370/0x4f0\n\nFix this by switching page reporting work to system_freezable_wq. This\nensures that the PM freezer pauses page_reporting_process before device\ndrivers destroy their reporting virtqueues. Because the reporting worker\nis frozen, memory reclamation/freeing (e.g. via shrinker execution) can\nsafely return pages to MM during freeze without triggering unfrozen\nreporting work on deleted virtqueues.\n\nThis aligns with the driver\u0027s existing design. The comment in\nvirtballoon_freeze() states:\n /*\n * The workqueue is already frozen by the PM core before this\n * function is called.\n */\n\nTesting:\nI have verified these fixes using Google\u2019s virtualization infrastructure\nby running continuous suspend/resume iterations (40+ cycles) while\nchurning memory using stress-ng (`stress-ng --vm 4 --vm-bytes 60%\n--timeout 1`) to constantly create free pages for the buddy allocator. We\nalso set the `page_reporting_order` parameter to 0 to make the page\nreporting worker highly sensitive, forcing it to pick up any 4K free\npages. This confirmed that the UAF crashes are no longer reproducible."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The UAF is reached only through local PM suspend/hibernation and guest memory-free paths (__free_one_page -\u003e page_reporting_notify_free -\u003e page_reporting_process -\u003e virtballoon_free_page_report); it is not reachable via network protocols or remote packet handling.\nAC:L - An attacker with local access can reliably drive the race by churning memory (e.g. stress-ng) to flood page-reporting work while triggering or awaiting S3/S4 suspend, as demonstrated in the fix commit\u0027s reproduction on virtio-balloon VMs.\nPR:L - No real-root capability is required to exercise the memory-free entry path (normal unprivileged mmap/malloc/free syscalls), and many desktop deployments allow session users to initiate suspend via logind/polkit without full init-namespace root.\nUI:N - Exploitation does not require a separate victim action beyond the attacker (or system policy) initiating suspend/hibernation; automated cloud/VM suspend-resume cycles and scripted PM transitions suffice without interactive victim cooperation.\nS:U - Impact is confined to guest kernel memory corruption and crash inside the virtio-balloon/page-reporting subsystem; it does not cross a VM/host, IOMMU, or sandbox security boundary to affect resources outside the kernel\u0027s own authority.\nC:H - This is a kernel heap use-after-free on freed virtqueue metadata accessed through virtqueue_add_split; UAF of kernel objects can be leveraged for arbitrary kernel memory read/info disclosure beyond the observed GPF crash.\nI:H - UAF on virtqueue/vring kernel structures during virtqueue_add_split provides a memory-corruption primitive that can be developed into controlled kernel writes or code execution, not merely a benign crash.\nA:H - The bug provably causes a kernel general protection fault/oops in page_reporting_process during suspend (Workqueue: events), crashing or destabilizing the system and denying availability on every affected suspend/hibernation cycle."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:37:36.090Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a4c60046052777ca1dcc83fe3ece2a5136b301f1"
},
{
"url": "https://git.kernel.org/stable/c/b2c094e98f8bb823b3ae475f7169fe2091c40c6d"
},
{
"url": "https://git.kernel.org/stable/c/992f270fd808338fbae1f498a5e325e7e2e20368"
},
{
"url": "https://git.kernel.org/stable/c/f978048326570047e8216e81a67f9c71ef2bb1b1"
},
{
"url": "https://git.kernel.org/stable/c/450f35f4d5a682a0796757e52295df58ddb63bc9"
},
{
"url": "https://git.kernel.org/stable/c/b11907c905fa08eda925395f0724b7a409870f65"
},
{
"url": "https://git.kernel.org/stable/c/faf439b5fa7b231120eac4f7a617e0bfd4f6f5c7"
},
{
"url": "https://git.kernel.org/stable/c/0b45f6927a14914ff685fe0e6f9d11232a1e03df"
}
],
"title": "mm/page_reporting: use system_freezable_wq to fix UAF during suspend",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74481",
"datePublished": "2026-08-15T12:27:14.441Z",
"dateReserved": "2026-08-15T05:44:03.904Z",
"dateUpdated": "2026-08-19T16:37:36.090Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72299 (GCVE-0-2026-72299)
Vulnerability from cvelistv5
Published
2026-08-15 05:55
Modified
2026-08-23 12:47
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
tipc: restrict socket queue dumps in enqueue tracepoints
tipc_sk_enqueue() runs with sk->sk_lock.slock held while the socket is
owned by user context. The spinlock protects the backlog queue in this
path, but it does not serialize against the socket owner consuming or
purging sk_receive_queue.
KASAN reported:
CPU: 14 UID: 0 PID: 1050 Comm: tipc3 Not tainted 7.1.0-rc6+ #126 PREEMPT(lazy)
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014
Call Trace:
<TASK>
dump_stack_lvl+0x76/0xa0 lib/dump_stack.c:123
print_report+0xce/0x5b0 mm/kasan/report.c:482
kasan_report+0xc6/0x100 mm/kasan/report.c:597
__asan_report_load4_noabort+0x14/0x30 mm/kasan/report_generic.c:380
tipc_skb_dump+0x1327/0x16f0 net/tipc/trace.c:73
tipc_list_dump+0x208/0x2e0 net/tipc/trace.c:187
tipc_sk_dump+0xaf6/0xd60 net/tipc/socket.c:3996
trace_event_raw_event_tipc_sk_class+0x312/0x5a0 net/tipc/trace.h:188
tipc_sk_rcv+0xb1d/0x1d50 net/tipc/socket.c:2497
tipc_node_xmit+0x1c3/0x1440 net/tipc/node.c:1689
__tipc_sendmsg+0x97a/0x1440 net/tipc/socket.c:1512
tipc_sendmsg+0x52/0x80 net/tipc/socket.c:1400
sock_sendmsg+0x2f6/0x3e0 net/socket.c:825
splice_to_socket+0x7f9/0x1010 fs/splice.c:884
do_splice+0xe21/0x2330 fs/splice.c:936
__do_splice+0x153/0x260 fs/splice.c:1431
__x64_sys_splice+0x150/0x230 fs/splice.c:1616
x64_sys_call+0xeb5/0x2790 arch/x86/entry/syscall_64.c:41
do_syscall_64+0xf3/0x620 arch/x86/entry/syscall_64.c:63
entry_SYSCALL_64_after_hwframe+0x76/0x7e arch/x86/entry/entry_64.S:130
RIP: 0033:0x71624e8aafe2
Code: 08 0f 85 71 3a ff ff 49 89 fb 48 89 f0 48 89 d7 48 89 ce 4c 89 c2 4d 89 ca 4c 8b 44 24 08 4c 8b 4c 24 10 4c 89 5c 24 08 0f 05 <c3> 66 2e 0f 1f 84 00 00 00 00 00 66 2e 0f 1f 84 00 00 00 00 00 66
RSP: 002b:0000716157ffed68 EFLAGS: 00000246 ORIG_RAX: 0000000000000113
RAX: ffffffffffffffda RBX: 0000716157fff6c0 RCX: 000071624e8aafe2
RDX: 000000000000005f RSI: 0000000000000000 RDI: 0000000000000066
RBP: 0000716157ffed90 R08: 0000000000008000 R09: 0000000000000001
R10: 0000000000000000 R11: 0000000000000246 R12: ffffffffffffff00
R13: 0000000000000021 R14: 0000000000000000 R15: 00007fff89799c40
</TASK>
The TIPC_DUMP_ALL tracepoints in tipc_sk_enqueue() also dump
sk_receive_queue and can therefore dereference skbs that the socket
owner has already dequeued or freed. Restrict these dumps to
TIPC_DUMP_SK_BKLGQ, which matches the queue protected by the held
spinlock.
Keep the change limited to the enqueue path, where the unsafe queue dump
is reachable while the socket is owned by user context.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 01e661ebfbad40e6280fb8ec25f2861d39ba4387 Version: 01e661ebfbad40e6280fb8ec25f2861d39ba4387 Version: 01e661ebfbad40e6280fb8ec25f2861d39ba4387 Version: 01e661ebfbad40e6280fb8ec25f2861d39ba4387 Version: 01e661ebfbad40e6280fb8ec25f2861d39ba4387 Version: 01e661ebfbad40e6280fb8ec25f2861d39ba4387 Version: 01e661ebfbad40e6280fb8ec25f2861d39ba4387 Version: 01e661ebfbad40e6280fb8ec25f2861d39ba4387 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/tipc/socket.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ae5d0d9ce767b20a5580bb6dc5e06f3e1b8a0fb0",
"status": "affected",
"version": "01e661ebfbad40e6280fb8ec25f2861d39ba4387",
"versionType": "git"
},
{
"lessThan": "273ff83c49b82e4267373adbe629e6ee8aeaa16c",
"status": "affected",
"version": "01e661ebfbad40e6280fb8ec25f2861d39ba4387",
"versionType": "git"
},
{
"lessThan": "258fb15b30db4f3941ab335d5e02f744baf1da54",
"status": "affected",
"version": "01e661ebfbad40e6280fb8ec25f2861d39ba4387",
"versionType": "git"
},
{
"lessThan": "12876864f9de5fa6f611a30c6c17e405a773bf0a",
"status": "affected",
"version": "01e661ebfbad40e6280fb8ec25f2861d39ba4387",
"versionType": "git"
},
{
"lessThan": "b9e100815f4b55e9ccaf6af9a3aba173eb13d381",
"status": "affected",
"version": "01e661ebfbad40e6280fb8ec25f2861d39ba4387",
"versionType": "git"
},
{
"lessThan": "61a55fa24a5d737436018764a647fe5b6cb36371",
"status": "affected",
"version": "01e661ebfbad40e6280fb8ec25f2861d39ba4387",
"versionType": "git"
},
{
"lessThan": "6acbbe54215d5f4251593000cff2bf51d6748713",
"status": "affected",
"version": "01e661ebfbad40e6280fb8ec25f2861d39ba4387",
"versionType": "git"
},
{
"lessThan": "acd7df8d955480a6f6e5bb809da67b1500cc3cf4",
"status": "affected",
"version": "01e661ebfbad40e6280fb8ec25f2861d39ba4387",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/tipc/socket.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.0"
},
{
"lessThan": "5.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: restrict socket queue dumps in enqueue tracepoints\n\ntipc_sk_enqueue() runs with sk-\u003esk_lock.slock held while the socket is\nowned by user context. The spinlock protects the backlog queue in this\npath, but it does not serialize against the socket owner consuming or\npurging sk_receive_queue.\n\nKASAN reported:\n\n CPU: 14 UID: 0 PID: 1050 Comm: tipc3 Not tainted 7.1.0-rc6+ #126 PREEMPT(lazy)\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014\n Call Trace:\n \u003cTASK\u003e\n dump_stack_lvl+0x76/0xa0 lib/dump_stack.c:123\n print_report+0xce/0x5b0 mm/kasan/report.c:482\n kasan_report+0xc6/0x100 mm/kasan/report.c:597\n __asan_report_load4_noabort+0x14/0x30 mm/kasan/report_generic.c:380\n tipc_skb_dump+0x1327/0x16f0 net/tipc/trace.c:73\n tipc_list_dump+0x208/0x2e0 net/tipc/trace.c:187\n tipc_sk_dump+0xaf6/0xd60 net/tipc/socket.c:3996\n trace_event_raw_event_tipc_sk_class+0x312/0x5a0 net/tipc/trace.h:188\n tipc_sk_rcv+0xb1d/0x1d50 net/tipc/socket.c:2497\n tipc_node_xmit+0x1c3/0x1440 net/tipc/node.c:1689\n __tipc_sendmsg+0x97a/0x1440 net/tipc/socket.c:1512\n tipc_sendmsg+0x52/0x80 net/tipc/socket.c:1400\n sock_sendmsg+0x2f6/0x3e0 net/socket.c:825\n splice_to_socket+0x7f9/0x1010 fs/splice.c:884\n do_splice+0xe21/0x2330 fs/splice.c:936\n __do_splice+0x153/0x260 fs/splice.c:1431\n __x64_sys_splice+0x150/0x230 fs/splice.c:1616\n x64_sys_call+0xeb5/0x2790 arch/x86/entry/syscall_64.c:41\n do_syscall_64+0xf3/0x620 arch/x86/entry/syscall_64.c:63\n entry_SYSCALL_64_after_hwframe+0x76/0x7e arch/x86/entry/entry_64.S:130\n RIP: 0033:0x71624e8aafe2\n Code: 08 0f 85 71 3a ff ff 49 89 fb 48 89 f0 48 89 d7 48 89 ce 4c 89 c2 4d 89 ca 4c 8b 44 24 08 4c 8b 4c 24 10 4c 89 5c 24 08 0f 05 \u003cc3\u003e 66 2e 0f 1f 84 00 00 00 00 00 66 2e 0f 1f 84 00 00 00 00 00 66\n RSP: 002b:0000716157ffed68 EFLAGS: 00000246 ORIG_RAX: 0000000000000113\n RAX: ffffffffffffffda RBX: 0000716157fff6c0 RCX: 000071624e8aafe2\n RDX: 000000000000005f RSI: 0000000000000000 RDI: 0000000000000066\n RBP: 0000716157ffed90 R08: 0000000000008000 R09: 0000000000000001\n R10: 0000000000000000 R11: 0000000000000246 R12: ffffffffffffff00\n R13: 0000000000000021 R14: 0000000000000000 R15: 00007fff89799c40\n \u003c/TASK\u003e\n\nThe TIPC_DUMP_ALL tracepoints in tipc_sk_enqueue() also dump\nsk_receive_queue and can therefore dereference skbs that the socket\nowner has already dequeued or freed. Restrict these dumps to\nTIPC_DUMP_SK_BKLGQ, which matches the queue protected by the held\nspinlock.\n\nKeep the change limited to the enqueue path, where the unsafe queue dump\nis reachable while the socket is owned by user context."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - tipc_sk_enqueue() is invoked from tipc_sk_rcv() on inbound TIPC traffic (tipc_rcv()/tipc_link_rcv() from UDP/Ethernet bearers) and on loopback xmit; a remote cluster peer can deliver packets that hit the enqueue trace path while the destination socket is user-owned.\nAC:L - This is a controllable race between enqueue-time TIPC_DUMP_ALL trace dumps of sk_receive_queue and the socket owner dequeuing/freeing those skbs; the attacker drives both sides via concurrent recvmsg/splice/sendmsg threads or by flooding TIPC messages while a receiver holds lock_sock().\nPR:N - TIPC data-plane delivery to an existing socket/port needs no authentication or victim credentials; any local user may open AF_TIPC sockets (including via user namespaces with CAP_NET_ADMIN), and default sk_filter sysctl matches all sockets once trace events are enabled.\nUI:N - Exploitation needs no victim interaction beyond normal socket/cluster I/O; the attacker controls message injection and thread timing without requiring mounts, prompts, or other deliberate user actions.\nS:U - The flaw is a kernel sk_buff use-after-free in the TIPC socket path and its impact stays within the kernel security authority; it does not by itself cross VM, IOMMU, or hypervisor isolation boundaries.\nC:H - KASAN reported __asan_report_load4 in tipc_skb_dump() reading freed skb/message fields from sk_receive_queue; this UAF read of attacker-influenced heap objects can disclose kernel memory and supports further info-leak exploitation.\nI:H - Concurrent enqueue tracing walks queue pointers while skbs are freed by the socket owner, creating a classic UAF on sk_buff slabs that can be groomed for arbitrary kernel memory corruption and privilege escalation.\nA:H - Dereferencing freed skbs during tipc_list_dump()/tipc_skb_dump() can oops or panic the kernel; UAF in the TIPC receive/enqueue path is a high-availability risk even when not fully weaponized for code execution."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:47:12.393Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ae5d0d9ce767b20a5580bb6dc5e06f3e1b8a0fb0"
},
{
"url": "https://git.kernel.org/stable/c/273ff83c49b82e4267373adbe629e6ee8aeaa16c"
},
{
"url": "https://git.kernel.org/stable/c/258fb15b30db4f3941ab335d5e02f744baf1da54"
},
{
"url": "https://git.kernel.org/stable/c/12876864f9de5fa6f611a30c6c17e405a773bf0a"
},
{
"url": "https://git.kernel.org/stable/c/b9e100815f4b55e9ccaf6af9a3aba173eb13d381"
},
{
"url": "https://git.kernel.org/stable/c/61a55fa24a5d737436018764a647fe5b6cb36371"
},
{
"url": "https://git.kernel.org/stable/c/6acbbe54215d5f4251593000cff2bf51d6748713"
},
{
"url": "https://git.kernel.org/stable/c/acd7df8d955480a6f6e5bb809da67b1500cc3cf4"
}
],
"title": "tipc: restrict socket queue dumps in enqueue tracepoints",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72299",
"datePublished": "2026-08-15T05:55:19.147Z",
"dateReserved": "2026-08-09T03:40:39.918Z",
"dateUpdated": "2026-08-23T12:47:12.393Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74551 (GCVE-0-2026-74551)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-19 16:38
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
hwmon: (nzxt-smart2) DMA-align output buffer
Sashiko reports:
When send_output_report() calls hid_hw_output_report(), the underlying USB
HID core calls usb_interrupt_msg() which maps this buffer directly for DMA.
When the DMA mapping flushes or invalidates the cacheline, it will corrupt
the adjacent variables (mutex, update_interval) that were modified
concurrently by the CPU. This causes memory corruption due to cacheline
sharing on non-coherent CPU architectures (such as ARM or MIPS). The DMA
API debugging tool (CONFIG_DMA_API_DEBUG) will trigger runtime warnings
for this violation.
Any operation that triggers send_output_report() (like setting a fan speed
or updating the interval) causes the USB DMA mapping. On systems with
non-coherent caches, this structural bug causes immediate and deterministic
memory corruption.
Align the output buffer to ARCH_DMA_MINALIGN to fix the problem.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 53e68c20aeb1e23419bed811aa3a309ceda200f9 Version: 53e68c20aeb1e23419bed811aa3a309ceda200f9 Version: 53e68c20aeb1e23419bed811aa3a309ceda200f9 Version: 53e68c20aeb1e23419bed811aa3a309ceda200f9 Version: 53e68c20aeb1e23419bed811aa3a309ceda200f9 Version: 53e68c20aeb1e23419bed811aa3a309ceda200f9 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/hwmon/nzxt-smart2.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "81a6593b1c8dfb2694cd0ce39be01212d2b8436c",
"status": "affected",
"version": "53e68c20aeb1e23419bed811aa3a309ceda200f9",
"versionType": "git"
},
{
"lessThan": "70ad543ce81f368411b6c721265a3b2d7ab4fda4",
"status": "affected",
"version": "53e68c20aeb1e23419bed811aa3a309ceda200f9",
"versionType": "git"
},
{
"lessThan": "51a76bc1b8e717ee3fc0d84f15ac51490ca5f76f",
"status": "affected",
"version": "53e68c20aeb1e23419bed811aa3a309ceda200f9",
"versionType": "git"
},
{
"lessThan": "2332d35aaf206c17acf848522817252732596676",
"status": "affected",
"version": "53e68c20aeb1e23419bed811aa3a309ceda200f9",
"versionType": "git"
},
{
"lessThan": "6a2dbce5da2d2163a5b684acf68a0e54582ff0fa",
"status": "affected",
"version": "53e68c20aeb1e23419bed811aa3a309ceda200f9",
"versionType": "git"
},
{
"lessThan": "080bbf42faf77e6489ab30d5114c5f8f6ccbb1b8",
"status": "affected",
"version": "53e68c20aeb1e23419bed811aa3a309ceda200f9",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/hwmon/nzxt-smart2.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.17"
},
{
"lessThan": "5.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.17",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (nzxt-smart2) DMA-align output buffer\n\nSashiko reports:\n\nWhen send_output_report() calls hid_hw_output_report(), the underlying USB\nHID core calls usb_interrupt_msg() which maps this buffer directly for DMA.\n\nWhen the DMA mapping flushes or invalidates the cacheline, it will corrupt\nthe adjacent variables (mutex, update_interval) that were modified\nconcurrently by the CPU. This causes memory corruption due to cacheline\nsharing on non-coherent CPU architectures (such as ARM or MIPS). The DMA\nAPI debugging tool (CONFIG_DMA_API_DEBUG) will trigger runtime warnings\nfor this violation.\n\nAny operation that triggers send_output_report() (like setting a fan speed\nor updating the interval) causes the USB DMA mapping. On systems with\nnon-coherent caches, this structural bug causes immediate and deterministic\nmemory corruption.\n\nAlign the output buffer to ARCH_DMA_MINALIGN to fix the problem."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable send_output_report() path is reached by writing hwmon sysfs attributes (pwm*, update_interval) under /sys/class/hwmon/, a local interface. The USB stack only performs internal DMA mapping; the attacker does not need network, adjacent-network, or direct USB bus manipulation to trigger the bug.\nAC:L - On non-coherent ARM/MIPS systems, each sysfs write that triggers send_output_report() deterministically causes DMA cache-line operations that corrupt the adjacent mutex and update_interval; the attacker controls when writes occur and can repeat them at will with no race or grooming required.\nPR:L - The driver exposes pwm* and update_interval hwmon attributes with mode 0644 and performs no capability or credential checks on the write path; any unprivileged local user account can trigger send_output_report() without real root or init-namespace capabilities.\nUI:N - Exploitation requires only the attacker writing to hwmon sysfs on a system where the NZXT device is already present and bound; no victim action such as opening a file, clicking a prompt, or mounting a filesystem is needed beyond normal device presence at boot.\nS:U - Corruption is confined to kernel driver private data (mutex, update_interval) within the host kernel heap; impact is standard kernel memory corruption and potential privilege escalation, not crossing VM, container, or IOMMU security boundaries.\nC:H - DMA cache-line invalidation corrupts adjacent kernel structures including struct mutex while concurrently modified by the CPU; this class of heap-adjacent memory corruption is a general primitive that can be leveraged for arbitrary kernel memory disclosure.\nI:H - Corrupting an actively held struct mutex in kernel driver private data enables control of synchronization state and adjacent heap contents, providing an exploitable kernel memory corruption primitive suitable for arbitrary write and control-flow hijacking.\nA:H - Corrupted mutex and driver state cause immediate kernel instability including possible deadlock, oops, or panic on every triggering sysfs write on affected non-coherent architectures; the fix commit describes immediate and deterministic memory corruption."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:38:47.362Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/81a6593b1c8dfb2694cd0ce39be01212d2b8436c"
},
{
"url": "https://git.kernel.org/stable/c/70ad543ce81f368411b6c721265a3b2d7ab4fda4"
},
{
"url": "https://git.kernel.org/stable/c/51a76bc1b8e717ee3fc0d84f15ac51490ca5f76f"
},
{
"url": "https://git.kernel.org/stable/c/2332d35aaf206c17acf848522817252732596676"
},
{
"url": "https://git.kernel.org/stable/c/6a2dbce5da2d2163a5b684acf68a0e54582ff0fa"
},
{
"url": "https://git.kernel.org/stable/c/080bbf42faf77e6489ab30d5114c5f8f6ccbb1b8"
}
],
"title": "hwmon: (nzxt-smart2) DMA-align output buffer",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74551",
"datePublished": "2026-08-15T12:27:58.237Z",
"dateReserved": "2026-08-15T05:44:03.915Z",
"dateUpdated": "2026-08-19T16:38:47.362Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68331 (GCVE-0-2026-68331)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
dpaa2-eth: put MAC endpoint device on disconnect
fsl_mc_get_endpoint() returns the MAC endpoint device with a reference
taken through device_find_child(). The Ethernet connect path stores that
device in mac->mc_dev and keeps it for the lifetime of the connected MAC
object.
However, the disconnect path only disconnects and closes the MAC before
freeing the dpaa2_mac object. It does not drop the endpoint device
reference stored in mac->mc_dev, so every successful connect leaks that
device reference when the MAC is later disconnected.
Drop the endpoint device reference after closing the MAC and before
freeing the dpaa2_mac object.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 71947923089353f23f4f210864903c4dcf2c1696 Version: 71947923089353f23f4f210864903c4dcf2c1696 Version: 71947923089353f23f4f210864903c4dcf2c1696 Version: 71947923089353f23f4f210864903c4dcf2c1696 Version: 71947923089353f23f4f210864903c4dcf2c1696 Version: 71947923089353f23f4f210864903c4dcf2c1696 Version: 71947923089353f23f4f210864903c4dcf2c1696 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/freescale/dpaa2/dpaa2-eth.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "6b6ffdb9ca4547a3c4c274aa3e25b6c68dbc62e1",
"status": "affected",
"version": "71947923089353f23f4f210864903c4dcf2c1696",
"versionType": "git"
},
{
"lessThan": "1974127776da46a000c61f36d4946799ea6d4f51",
"status": "affected",
"version": "71947923089353f23f4f210864903c4dcf2c1696",
"versionType": "git"
},
{
"lessThan": "915012e923316b8b5d5bf8fc771617b47bd7572d",
"status": "affected",
"version": "71947923089353f23f4f210864903c4dcf2c1696",
"versionType": "git"
},
{
"lessThan": "e23e4a3b9dfd893469c731318d409cdf04fb1ddf",
"status": "affected",
"version": "71947923089353f23f4f210864903c4dcf2c1696",
"versionType": "git"
},
{
"lessThan": "f112df0744e2d77baa68eeebb860021bbaaa022a",
"status": "affected",
"version": "71947923089353f23f4f210864903c4dcf2c1696",
"versionType": "git"
},
{
"lessThan": "a3cecf169cc652b558d08661bb6ce55e4c933ec0",
"status": "affected",
"version": "71947923089353f23f4f210864903c4dcf2c1696",
"versionType": "git"
},
{
"lessThan": "b4b201cc93ff70150853aba03e14d314d1980ca0",
"status": "affected",
"version": "71947923089353f23f4f210864903c4dcf2c1696",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/freescale/dpaa2/dpaa2-eth.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.5"
},
{
"lessThan": "5.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndpaa2-eth: put MAC endpoint device on disconnect\n\nfsl_mc_get_endpoint() returns the MAC endpoint device with a reference\ntaken through device_find_child(). The Ethernet connect path stores that\ndevice in mac-\u003emc_dev and keeps it for the lifetime of the connected MAC\nobject.\n\nHowever, the disconnect path only disconnects and closes the MAC before\nfreeing the dpaa2_mac object. It does not drop the endpoint device\nreference stored in mac-\u003emc_dev, so every successful connect leaks that\ndevice reference when the MAC is later disconnected.\n\nDrop the endpoint device reference after closing the MAC and before\nfreeing the dpaa2_mac object."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:28.174Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/6b6ffdb9ca4547a3c4c274aa3e25b6c68dbc62e1"
},
{
"url": "https://git.kernel.org/stable/c/1974127776da46a000c61f36d4946799ea6d4f51"
},
{
"url": "https://git.kernel.org/stable/c/915012e923316b8b5d5bf8fc771617b47bd7572d"
},
{
"url": "https://git.kernel.org/stable/c/e23e4a3b9dfd893469c731318d409cdf04fb1ddf"
},
{
"url": "https://git.kernel.org/stable/c/f112df0744e2d77baa68eeebb860021bbaaa022a"
},
{
"url": "https://git.kernel.org/stable/c/a3cecf169cc652b558d08661bb6ce55e4c933ec0"
},
{
"url": "https://git.kernel.org/stable/c/b4b201cc93ff70150853aba03e14d314d1980ca0"
}
],
"title": "dpaa2-eth: put MAC endpoint device on disconnect",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68331",
"datePublished": "2026-08-10T12:03:07.529Z",
"dateReserved": "2026-07-30T09:28:09.383Z",
"dateUpdated": "2026-08-19T16:33:28.174Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68141 (GCVE-0-2026-68141)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/af_iucv: fix NULL deref in afiucv_hs_callback_syn()
afiucv_hs_callback_syn() allocates the child socket with GFP_ATOMIC.
If the allocation fails, nsk is NULL.
The connection-refused path is entered when the listen state check
fails, the accept backlog is full, or nsk is NULL. The code
unconditionally calls iucv_sock_kill(nsk) in that path.
iucv_sock_kill() does not accept a NULL socket pointer and immediately
dereferences sk via sock_flag(sk, SOCK_ZAPPED). When nsk is NULL,
calling iucv_sock_kill(nsk) results in a NULL pointer dereference.
Only call iucv_sock_kill() when a child socket was successfully
allocated.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 3881ac441f642d56503818123446f7298442236b Version: 3881ac441f642d56503818123446f7298442236b Version: 3881ac441f642d56503818123446f7298442236b Version: 3881ac441f642d56503818123446f7298442236b Version: 3881ac441f642d56503818123446f7298442236b Version: 3881ac441f642d56503818123446f7298442236b Version: 3881ac441f642d56503818123446f7298442236b Version: 3881ac441f642d56503818123446f7298442236b |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/iucv/af_iucv.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "6a1eb5b46c19073f8153b7e2c19b408cf353aaf1",
"status": "affected",
"version": "3881ac441f642d56503818123446f7298442236b",
"versionType": "git"
},
{
"lessThan": "c0b6e2ae90613c2fea7eaf3faa20985c6c2a1953",
"status": "affected",
"version": "3881ac441f642d56503818123446f7298442236b",
"versionType": "git"
},
{
"lessThan": "07e21deb3664001995e0a456dd627ab7dbe127ec",
"status": "affected",
"version": "3881ac441f642d56503818123446f7298442236b",
"versionType": "git"
},
{
"lessThan": "8bb111f87ded6acb9837ec9b45d6f02cda94c51f",
"status": "affected",
"version": "3881ac441f642d56503818123446f7298442236b",
"versionType": "git"
},
{
"lessThan": "46453b16f38ec7147351f7447e2aec6ea330f7b3",
"status": "affected",
"version": "3881ac441f642d56503818123446f7298442236b",
"versionType": "git"
},
{
"lessThan": "33736ff5e7c97d3348ce812e8bd2e125d840743c",
"status": "affected",
"version": "3881ac441f642d56503818123446f7298442236b",
"versionType": "git"
},
{
"lessThan": "0e857185591fe79934427c9c0c1c31dc776be134",
"status": "affected",
"version": "3881ac441f642d56503818123446f7298442236b",
"versionType": "git"
},
{
"lessThan": "47a5116e56a6b6fe1e909f244e39cd0fc26ceee4",
"status": "affected",
"version": "3881ac441f642d56503818123446f7298442236b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/iucv/af_iucv.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.2"
},
{
"lessThan": "3.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/af_iucv: fix NULL deref in afiucv_hs_callback_syn()\n\nafiucv_hs_callback_syn() allocates the child socket with GFP_ATOMIC.\nIf the allocation fails, nsk is NULL.\n\nThe connection-refused path is entered when the listen state check\nfails, the accept backlog is full, or nsk is NULL. The code\nunconditionally calls iucv_sock_kill(nsk) in that path.\n\niucv_sock_kill() does not accept a NULL socket pointer and immediately\ndereferences sk via sock_flag(sk, SOCK_ZAPPED). When nsk is NULL,\ncalling iucv_sock_kill(nsk) results in a NULL pointer dereference.\n\nOnly call iucv_sock_kill() when a child socket was successfully\nallocated."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The flaw is reached from afiucv_hs_rcv() via dev_add_pack() when ETH_P_AF_IUCV SYN frames arrive on a HiperSockets netdev in netif RX softirq; a remote LPAR/guest on the IBM Z HiperSockets fabric can send these connection requests without local access.\nAC:L - An attacker can repeatedly send SYN packets to a listening AF_IUCV service to pressure GFP_ATOMIC socket allocations until iucv_sock_alloc() fails and the broken connection-refused path runs; no timing race or victim-specific state beyond routine memory pressure is required.\nPR:N - Exploitation requires only sending unauthenticated HiperSockets SYN traffic to a bound/listening AF_IUCV socket; the handshake path has no credential checks and the af_iucv code performs no capability or permission validation before reaching afiucv_hs_callback_syn().\nUI:N - Triggering the NULL dereference needs no action from an end user beyond a service already listening on HiperSockets; the attacker can initiate SYN packets remotely without victim interaction.\nS:U - Impact is a kernel NULL pointer dereference and likely oops/panic in the victim LPAR kernel; it does not cross a VM/host, IOMMU, or sandbox boundary to compromise a different security authority.\nC:N - The failure is an immediate NULL pointer dereference in sock_flag() inside iucv_sock_kill(); there is no memory corruption, out-of-bounds access, or use-after-free that could yield information disclosure.\nI:N - The bug does not write attacker-controlled data or corrupt kernel structures; it only dereferences a NULL socket pointer during cleanup, so no integrity impact or code-execution primitive is created.\nA:H - A NULL dereference in afiucv_hs_callback_syn() during softirq packet processing can cause a kernel oops or panic, denying all service on the affected IBM Z LPAR until reboot."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:29:59.584Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/6a1eb5b46c19073f8153b7e2c19b408cf353aaf1"
},
{
"url": "https://git.kernel.org/stable/c/c0b6e2ae90613c2fea7eaf3faa20985c6c2a1953"
},
{
"url": "https://git.kernel.org/stable/c/07e21deb3664001995e0a456dd627ab7dbe127ec"
},
{
"url": "https://git.kernel.org/stable/c/8bb111f87ded6acb9837ec9b45d6f02cda94c51f"
},
{
"url": "https://git.kernel.org/stable/c/46453b16f38ec7147351f7447e2aec6ea330f7b3"
},
{
"url": "https://git.kernel.org/stable/c/33736ff5e7c97d3348ce812e8bd2e125d840743c"
},
{
"url": "https://git.kernel.org/stable/c/0e857185591fe79934427c9c0c1c31dc776be134"
},
{
"url": "https://git.kernel.org/stable/c/47a5116e56a6b6fe1e909f244e39cd0fc26ceee4"
}
],
"title": "net/af_iucv: fix NULL deref in afiucv_hs_callback_syn()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68141",
"datePublished": "2026-08-10T11:59:05.051Z",
"dateReserved": "2026-07-30T09:28:09.370Z",
"dateUpdated": "2026-08-19T16:29:59.584Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68251 (GCVE-0-2026-68251)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-19 16:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu/sdma6.0: replace BUG_ON() with WARN_ON()
There's no need to crash the kernel for these cases.
(cherry picked from commit c17a508a7d652da3728f8bbc481bfffe96d65a87)
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 61a039d1757b148717b9e10ea0cd30e5da6cf919 Version: 61a039d1757b148717b9e10ea0cd30e5da6cf919 Version: 61a039d1757b148717b9e10ea0cd30e5da6cf919 Version: 61a039d1757b148717b9e10ea0cd30e5da6cf919 Version: 61a039d1757b148717b9e10ea0cd30e5da6cf919 Version: 61a039d1757b148717b9e10ea0cd30e5da6cf919 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/sdma_v6_0.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "e7575e1e654a7ec8cc5e170f6dc30c81c708ddda",
"status": "affected",
"version": "61a039d1757b148717b9e10ea0cd30e5da6cf919",
"versionType": "git"
},
{
"lessThan": "2eb06c88426b6c8de602c608959f3a56ac51861e",
"status": "affected",
"version": "61a039d1757b148717b9e10ea0cd30e5da6cf919",
"versionType": "git"
},
{
"lessThan": "e7f31c9a61533062a704f90b9f63064045249693",
"status": "affected",
"version": "61a039d1757b148717b9e10ea0cd30e5da6cf919",
"versionType": "git"
},
{
"lessThan": "51fd52087165180967cf7d5ee99badee7e172ea0",
"status": "affected",
"version": "61a039d1757b148717b9e10ea0cd30e5da6cf919",
"versionType": "git"
},
{
"lessThan": "9df8a7f09e305249872b536555793b28e77b7de9",
"status": "affected",
"version": "61a039d1757b148717b9e10ea0cd30e5da6cf919",
"versionType": "git"
},
{
"lessThan": "ec42c96c322e5cc48099ab5e67b5cbe236cb1949",
"status": "affected",
"version": "61a039d1757b148717b9e10ea0cd30e5da6cf919",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/sdma_v6_0.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.19"
},
{
"lessThan": "5.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/sdma6.0: replace BUG_ON() with WARN_ON()\n\nThere\u0027s no need to crash the kernel for these cases.\n\n(cherry picked from commit c17a508a7d652da3728f8bbc481bfffe96d65a87)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:32:23.355Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/e7575e1e654a7ec8cc5e170f6dc30c81c708ddda"
},
{
"url": "https://git.kernel.org/stable/c/2eb06c88426b6c8de602c608959f3a56ac51861e"
},
{
"url": "https://git.kernel.org/stable/c/e7f31c9a61533062a704f90b9f63064045249693"
},
{
"url": "https://git.kernel.org/stable/c/51fd52087165180967cf7d5ee99badee7e172ea0"
},
{
"url": "https://git.kernel.org/stable/c/9df8a7f09e305249872b536555793b28e77b7de9"
},
{
"url": "https://git.kernel.org/stable/c/ec42c96c322e5cc48099ab5e67b5cbe236cb1949"
}
],
"title": "drm/amdgpu/sdma6.0: replace BUG_ON() with WARN_ON()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68251",
"datePublished": "2026-08-10T12:01:17.402Z",
"dateReserved": "2026-07-30T09:28:09.377Z",
"dateUpdated": "2026-08-19T16:32:23.355Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72236 (GCVE-0-2026-72236)
Vulnerability from cvelistv5
Published
2026-08-15 05:54
Modified
2026-08-23 12:47
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
s390/perf_cpum_cf: Add missing array_index_nospec() to __hw_perf_event_init()
ev variable is userspace controlled via event->attr.config and used
as an array index after bounds checking, but without speculation
barriers.
Add the missing array_index_nospec() call to prevent speculative
execution.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 212188a596d17d519842ef2173150315735b54e1 Version: 212188a596d17d519842ef2173150315735b54e1 Version: 212188a596d17d519842ef2173150315735b54e1 Version: 212188a596d17d519842ef2173150315735b54e1 Version: 212188a596d17d519842ef2173150315735b54e1 Version: 212188a596d17d519842ef2173150315735b54e1 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"arch/s390/kernel/perf_cpum_cf.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "4c249b214c686f9a1c4cf4f32893b59b189e897a",
"status": "affected",
"version": "212188a596d17d519842ef2173150315735b54e1",
"versionType": "git"
},
{
"lessThan": "27206bb57c47bdbe33bccc78fa7f7e2a719a06b9",
"status": "affected",
"version": "212188a596d17d519842ef2173150315735b54e1",
"versionType": "git"
},
{
"lessThan": "a21f3615c88421df81060b6ff89220fd34094c4d",
"status": "affected",
"version": "212188a596d17d519842ef2173150315735b54e1",
"versionType": "git"
},
{
"lessThan": "fa1ebae4206e6afc8caa642e9eb1bbe39a9a724f",
"status": "affected",
"version": "212188a596d17d519842ef2173150315735b54e1",
"versionType": "git"
},
{
"lessThan": "f79dff8c721bbb1f3fc312ea55e0551c2cc28801",
"status": "affected",
"version": "212188a596d17d519842ef2173150315735b54e1",
"versionType": "git"
},
{
"lessThan": "49145bce539117db4b6e9e83c0e5ef528e361050",
"status": "affected",
"version": "212188a596d17d519842ef2173150315735b54e1",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"arch/s390/kernel/perf_cpum_cf.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.4"
},
{
"lessThan": "3.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "3.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "3.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "3.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "3.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "3.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/perf_cpum_cf: Add missing array_index_nospec() to __hw_perf_event_init()\n\nev variable is userspace controlled via event-\u003eattr.config and used\nas an array index after bounds checking, but without speculation\nbarriers.\n\nAdd the missing array_index_nospec() call to prevent speculative\nexecution."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:47:04.750Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/4c249b214c686f9a1c4cf4f32893b59b189e897a"
},
{
"url": "https://git.kernel.org/stable/c/27206bb57c47bdbe33bccc78fa7f7e2a719a06b9"
},
{
"url": "https://git.kernel.org/stable/c/a21f3615c88421df81060b6ff89220fd34094c4d"
},
{
"url": "https://git.kernel.org/stable/c/fa1ebae4206e6afc8caa642e9eb1bbe39a9a724f"
},
{
"url": "https://git.kernel.org/stable/c/f79dff8c721bbb1f3fc312ea55e0551c2cc28801"
},
{
"url": "https://git.kernel.org/stable/c/49145bce539117db4b6e9e83c0e5ef528e361050"
}
],
"title": "s390/perf_cpum_cf: Add missing array_index_nospec() to __hw_perf_event_init()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72236",
"datePublished": "2026-08-15T05:54:25.891Z",
"dateReserved": "2026-08-09T03:40:39.914Z",
"dateUpdated": "2026-08-23T12:47:04.750Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74654 (GCVE-0-2026-74654)
Vulnerability from cvelistv5
Published
2026-08-22 15:32
Modified
2026-08-22 15:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
serial: 8250_dma: Clear stale RX state on shutdown
serial8250_release_dma() terminates RX DMA and releases the channel, but
leaves rx_running set. If the port is closed while an RX transfer is
active, the stale state remains while rxchan is NULL until the channel is
requested again on the next open.
The DesignWare BUSY workaround added by commit a7b9ce39fbe4
("serial: 8250_dw: Ensure BUSY is deasserted") calls
serial8250_rx_dma_flush() from the LCR write path during startup. This
happens before serial8250_request_dma() obtains a new RX channel. On
reopen, the stale rx_running state therefore makes the flush path pass a
NULL channel to dmaengine_pause(), causing a kernel Oops.
Clear rx_running after terminating RX DMA, matching the TX cleanup. Also
make the flush helper return if the DMA object or RX channel is not
available so startup and teardown paths cannot pass a NULL channel to the
DMAengine API.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 0fcb7901f9d61a325b4c5b88c600383bcbeb97fe Version: 0fcb7901f9d61a325b4c5b88c600383bcbeb97fe Version: 0fcb7901f9d61a325b4c5b88c600383bcbeb97fe Version: 0fcb7901f9d61a325b4c5b88c600383bcbeb97fe Version: 0fcb7901f9d61a325b4c5b88c600383bcbeb97fe Version: 0fcb7901f9d61a325b4c5b88c600383bcbeb97fe Version: 0fcb7901f9d61a325b4c5b88c600383bcbeb97fe Version: 0fcb7901f9d61a325b4c5b88c600383bcbeb97fe |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/tty/serial/8250/8250_dma.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "bf4fb620e02962b2b52500a4b3d8420f351eb46a",
"status": "affected",
"version": "0fcb7901f9d61a325b4c5b88c600383bcbeb97fe",
"versionType": "git"
},
{
"lessThan": "e10f06ee050a08930e2339b6fec7148fd0b2a8f6",
"status": "affected",
"version": "0fcb7901f9d61a325b4c5b88c600383bcbeb97fe",
"versionType": "git"
},
{
"lessThan": "d06cfb1add4a2d5b393e9e31f49ebbd168beea49",
"status": "affected",
"version": "0fcb7901f9d61a325b4c5b88c600383bcbeb97fe",
"versionType": "git"
},
{
"lessThan": "e7a5d792cf64a2096e18f1d573cc3d01cba15e92",
"status": "affected",
"version": "0fcb7901f9d61a325b4c5b88c600383bcbeb97fe",
"versionType": "git"
},
{
"lessThan": "9f2444f4c0e4b06f61bae38da87c9c94c78efa86",
"status": "affected",
"version": "0fcb7901f9d61a325b4c5b88c600383bcbeb97fe",
"versionType": "git"
},
{
"lessThan": "ae05d9e50b6b9f246c110b3bdc03676145c2d0d4",
"status": "affected",
"version": "0fcb7901f9d61a325b4c5b88c600383bcbeb97fe",
"versionType": "git"
},
{
"lessThan": "e7e3cc6709caa49d1d6ce6c1f7cb305e38675cc9",
"status": "affected",
"version": "0fcb7901f9d61a325b4c5b88c600383bcbeb97fe",
"versionType": "git"
},
{
"lessThan": "e2fe6a0efecbef00e3ecc2db64dd5afa8c212b41",
"status": "affected",
"version": "0fcb7901f9d61a325b4c5b88c600383bcbeb97fe",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/tty/serial/8250/8250_dma.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.19"
},
{
"lessThan": "3.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nserial: 8250_dma: Clear stale RX state on shutdown\n\nserial8250_release_dma() terminates RX DMA and releases the channel, but\nleaves rx_running set. If the port is closed while an RX transfer is\nactive, the stale state remains while rxchan is NULL until the channel is\nrequested again on the next open.\n\nThe DesignWare BUSY workaround added by commit a7b9ce39fbe4\n(\"serial: 8250_dw: Ensure BUSY is deasserted\") calls\nserial8250_rx_dma_flush() from the LCR write path during startup. This\nhappens before serial8250_request_dma() obtains a new RX channel. On\nreopen, the stale rx_running state therefore makes the flush path pass a\nNULL channel to dmaengine_pause(), causing a kernel Oops.\n\nClear rx_running after terminating RX DMA, matching the TX cleanup. Also\nmake the flush helper return if the DMA object or RX channel is not\navailable so startup and teardown paths cannot pass a NULL channel to the\nDMAengine API."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-22T15:32:29.263Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/bf4fb620e02962b2b52500a4b3d8420f351eb46a"
},
{
"url": "https://git.kernel.org/stable/c/e10f06ee050a08930e2339b6fec7148fd0b2a8f6"
},
{
"url": "https://git.kernel.org/stable/c/d06cfb1add4a2d5b393e9e31f49ebbd168beea49"
},
{
"url": "https://git.kernel.org/stable/c/e7a5d792cf64a2096e18f1d573cc3d01cba15e92"
},
{
"url": "https://git.kernel.org/stable/c/9f2444f4c0e4b06f61bae38da87c9c94c78efa86"
},
{
"url": "https://git.kernel.org/stable/c/ae05d9e50b6b9f246c110b3bdc03676145c2d0d4"
},
{
"url": "https://git.kernel.org/stable/c/e7e3cc6709caa49d1d6ce6c1f7cb305e38675cc9"
},
{
"url": "https://git.kernel.org/stable/c/e2fe6a0efecbef00e3ecc2db64dd5afa8c212b41"
}
],
"title": "serial: 8250_dma: Clear stale RX state on shutdown",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74654",
"datePublished": "2026-08-22T15:32:29.263Z",
"dateReserved": "2026-08-15T05:44:03.923Z",
"dateUpdated": "2026-08-22T15:32:29.263Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80848 (GCVE-0-2026-80848)
Vulnerability from cvelistv5
Published
2026-09-04 15:54
Modified
2026-09-04 15:54
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
xfrm: espintcp: fix UAF during close
ZDI reported and analyzed a race condition during close for espintcp
sockets:
espintcp_close() frees emsg->skb via kfree_skb() without holding
any socket lock. Concurrently, the xfrm_trans_reinject work queue
invokes esp_output_tcp_finish() -> espintcp_push_skb() ->
espintcp_push_msgs() -> skb_send_sock_locked(), which reads the
same skb as a data source.
Fix this by adding a synchronize_rcu() call after resetting sk_prot,
since esp_output_tcp_finish() runs under RCU and won't use a socket
with sk_prot == &tcp_prot. Simply taking the socket lock in
espintcp_close() could lead to leaks, if esp_output_tcp_finish()
re-adds an skb in the slot we just freed. After this, the existing
barrier() is no longer needed.
References
| URL | Tags | ||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: e27cca96cd68fa2c6814c90f9a1cfd36bb68c593 Version: e27cca96cd68fa2c6814c90f9a1cfd36bb68c593 Version: e27cca96cd68fa2c6814c90f9a1cfd36bb68c593 Version: e27cca96cd68fa2c6814c90f9a1cfd36bb68c593 Version: e27cca96cd68fa2c6814c90f9a1cfd36bb68c593 Version: e27cca96cd68fa2c6814c90f9a1cfd36bb68c593 Version: e27cca96cd68fa2c6814c90f9a1cfd36bb68c593 Version: e27cca96cd68fa2c6814c90f9a1cfd36bb68c593 Version: e27cca96cd68fa2c6814c90f9a1cfd36bb68c593 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/xfrm/espintcp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "29121c5e6591da527e8e36ddac7120dc527f574d",
"status": "affected",
"version": "e27cca96cd68fa2c6814c90f9a1cfd36bb68c593",
"versionType": "git"
},
{
"lessThan": "ed5d9102190c45fc70121c036b0626b740040b75",
"status": "affected",
"version": "e27cca96cd68fa2c6814c90f9a1cfd36bb68c593",
"versionType": "git"
},
{
"lessThan": "4bc0dfa28dca6fc0084203732695968049c44072",
"status": "affected",
"version": "e27cca96cd68fa2c6814c90f9a1cfd36bb68c593",
"versionType": "git"
},
{
"lessThan": "ff8dd7a932f34409a56e1b91a1219340f17457e9",
"status": "affected",
"version": "e27cca96cd68fa2c6814c90f9a1cfd36bb68c593",
"versionType": "git"
},
{
"lessThan": "4b31a875693c480c611519faca46216514e3e052",
"status": "affected",
"version": "e27cca96cd68fa2c6814c90f9a1cfd36bb68c593",
"versionType": "git"
},
{
"lessThan": "24efebecf415ba264adba0f0491cec436463a14f",
"status": "affected",
"version": "e27cca96cd68fa2c6814c90f9a1cfd36bb68c593",
"versionType": "git"
},
{
"lessThan": "eb3bbf29c723fe75c0eb92be14f0ec92971fe272",
"status": "affected",
"version": "e27cca96cd68fa2c6814c90f9a1cfd36bb68c593",
"versionType": "git"
},
{
"lessThan": "54b41ad14da9a981131ab6e4d3f79321a503ea5d",
"status": "affected",
"version": "e27cca96cd68fa2c6814c90f9a1cfd36bb68c593",
"versionType": "git"
},
{
"lessThan": "deb232e884877bf10b4ce2580909eedec986c284",
"status": "affected",
"version": "e27cca96cd68fa2c6814c90f9a1cfd36bb68c593",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/xfrm/espintcp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.6"
},
{
"lessThan": "5.6",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.269",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.220",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.187",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.156",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.108",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.49",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.13",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.3",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.269",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.220",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.187",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.156",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.108",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.49",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.13",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.3",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "5.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: espintcp: fix UAF during close\n\nZDI reported and analyzed a race condition during close for espintcp\nsockets:\n\n espintcp_close() frees emsg-\u003eskb via kfree_skb() without holding\n any socket lock. Concurrently, the xfrm_trans_reinject work queue\n invokes esp_output_tcp_finish() -\u003e espintcp_push_skb() -\u003e\n espintcp_push_msgs() -\u003e skb_send_sock_locked(), which reads the\n same skb as a data source.\n\nFix this by adding a synchronize_rcu() call after resetting sk_prot,\nsince esp_output_tcp_finish() runs under RCU and won\u0027t use a socket\nwith sk_prot == \u0026tcp_prot. Simply taking the socket lock in\nespintcp_close() could lead to leaks, if esp_output_tcp_finish()\nre-adds an skb in the slot we just freed. After this, the existing\nbarrier() is no longer needed."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T15:54:58.427Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/29121c5e6591da527e8e36ddac7120dc527f574d"
},
{
"url": "https://git.kernel.org/stable/c/ed5d9102190c45fc70121c036b0626b740040b75"
},
{
"url": "https://git.kernel.org/stable/c/4bc0dfa28dca6fc0084203732695968049c44072"
},
{
"url": "https://git.kernel.org/stable/c/ff8dd7a932f34409a56e1b91a1219340f17457e9"
},
{
"url": "https://git.kernel.org/stable/c/4b31a875693c480c611519faca46216514e3e052"
},
{
"url": "https://git.kernel.org/stable/c/24efebecf415ba264adba0f0491cec436463a14f"
},
{
"url": "https://git.kernel.org/stable/c/eb3bbf29c723fe75c0eb92be14f0ec92971fe272"
},
{
"url": "https://git.kernel.org/stable/c/54b41ad14da9a981131ab6e4d3f79321a503ea5d"
},
{
"url": "https://git.kernel.org/stable/c/deb232e884877bf10b4ce2580909eedec986c284"
}
],
"title": "xfrm: espintcp: fix UAF during close",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80848",
"datePublished": "2026-09-04T15:54:58.427Z",
"dateReserved": "2026-08-26T14:34:25.797Z",
"dateUpdated": "2026-09-04T15:54:58.427Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80762 (GCVE-0-2026-80762)
Vulnerability from cvelistv5
Published
2026-09-04 15:12
Modified
2026-09-04 15:12
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci_sync: Fix accept list UAF during suspend
hci_update_event_filter_sync() walks hdev->accept_list while sending a
synchronous HCI command for each remote-wakeup device. The suspend path
holds hdev->req_lock, but accept-list updates are serialized by hdev->lock.
Consequently, remove_device() can free the current list entry during the
controller wait.
The following interleaving causes the use-after-free:
hci_update_event_filter_sync() remove_device()
fetch accept-list entry
hci_set_event_filter_sync()
wait for controller response hci_dev_lock()
list_del()
kfree()
hci_dev_unlock()
read the freed list.next
KASAN reported:
BUG: KASAN: slab-use-after-free in hci_suspend_sync+0x835/0x910
Read of size 8 at addr ffff88810bec8440 by task kworker/0:1/10
Workqueue: events vhci_suspend_work
Call Trace:
hci_suspend_sync+0x835/0x910
hci_suspend_dev+0x182/0x450
process_one_work+0x661/0x1090
worker_thread+0x45b/0xd10
Allocated by task 86:
hci_bdaddr_list_add_with_flags+0x1a8/0x400
add_device+0x381/0x820
hci_sock_sendmsg+0x1033/0x1ea0
Freed by task 91:
kfree+0x131/0x3c0
remove_device+0x429/0xb70
hci_sock_sendmsg+0x1033/0x1ea0
Snapshot the remote-wakeup addresses under hdev->lock. Release the lock
before sending HCI commands. Clear the controller event filter before
building the snapshot, and skip allocation and the second list traversal
when there are no matching entries. This preserves the original filter
and scan-state updates without retaining an accept-list node across a
controller wait.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 182ee45da083db4e3e621541ccf255bfa9652214 Version: 182ee45da083db4e3e621541ccf255bfa9652214 Version: 182ee45da083db4e3e621541ccf255bfa9652214 Version: 182ee45da083db4e3e621541ccf255bfa9652214 Version: 182ee45da083db4e3e621541ccf255bfa9652214 Version: 182ee45da083db4e3e621541ccf255bfa9652214 Version: 182ee45da083db4e3e621541ccf255bfa9652214 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/bluetooth/hci_sync.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "bb5f5414d1a6272a16f68684e998f4063dd19f57",
"status": "affected",
"version": "182ee45da083db4e3e621541ccf255bfa9652214",
"versionType": "git"
},
{
"lessThan": "b5181516a9f5c2fdb3271cdad72a5b16c6963a44",
"status": "affected",
"version": "182ee45da083db4e3e621541ccf255bfa9652214",
"versionType": "git"
},
{
"lessThan": "87ad116ac3abc6f2ce2b5b6c488f633003581eee",
"status": "affected",
"version": "182ee45da083db4e3e621541ccf255bfa9652214",
"versionType": "git"
},
{
"lessThan": "fe93a697a7a92fa9adf78c9ff67a10db3193290c",
"status": "affected",
"version": "182ee45da083db4e3e621541ccf255bfa9652214",
"versionType": "git"
},
{
"lessThan": "95bb57bc11a91caf042ad00fca85e480d3fda37f",
"status": "affected",
"version": "182ee45da083db4e3e621541ccf255bfa9652214",
"versionType": "git"
},
{
"lessThan": "29c59212a507804d7616b8abf491d30b4ab8e75f",
"status": "affected",
"version": "182ee45da083db4e3e621541ccf255bfa9652214",
"versionType": "git"
},
{
"lessThan": "f57b399c4fa1501b2d5451f52d861ece86bcf3db",
"status": "affected",
"version": "182ee45da083db4e3e621541ccf255bfa9652214",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/bluetooth/hci_sync.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.17"
},
{
"lessThan": "5.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.187",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.156",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.108",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.47",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.1",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.187",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.156",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.108",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.47",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.11",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.1",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "5.17",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_sync: Fix accept list UAF during suspend\n\nhci_update_event_filter_sync() walks hdev-\u003eaccept_list while sending a\nsynchronous HCI command for each remote-wakeup device. The suspend path\nholds hdev-\u003ereq_lock, but accept-list updates are serialized by hdev-\u003elock.\nConsequently, remove_device() can free the current list entry during the\ncontroller wait.\n\nThe following interleaving causes the use-after-free:\n\n hci_update_event_filter_sync() remove_device()\n fetch accept-list entry\n hci_set_event_filter_sync()\n wait for controller response hci_dev_lock()\n list_del()\n kfree()\n hci_dev_unlock()\n read the freed list.next\n\nKASAN reported:\n\n BUG: KASAN: slab-use-after-free in hci_suspend_sync+0x835/0x910\n Read of size 8 at addr ffff88810bec8440 by task kworker/0:1/10\n Workqueue: events vhci_suspend_work\n Call Trace:\n hci_suspend_sync+0x835/0x910\n hci_suspend_dev+0x182/0x450\n process_one_work+0x661/0x1090\n worker_thread+0x45b/0xd10\n\n Allocated by task 86:\n hci_bdaddr_list_add_with_flags+0x1a8/0x400\n add_device+0x381/0x820\n hci_sock_sendmsg+0x1033/0x1ea0\n\n Freed by task 91:\n kfree+0x131/0x3c0\n remove_device+0x429/0xb70\n hci_sock_sendmsg+0x1033/0x1ea0\n\nSnapshot the remote-wakeup addresses under hdev-\u003elock. Release the lock\nbefore sending HCI commands. Clear the controller event filter before\nbuilding the snapshot, and skip allocation and the second list traversal\nwhen there are no matching entries. This preserves the original filter\nand scan-state updates without retaining an accept-list node across a\ncontroller wait."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T15:12:34.354Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/bb5f5414d1a6272a16f68684e998f4063dd19f57"
},
{
"url": "https://git.kernel.org/stable/c/b5181516a9f5c2fdb3271cdad72a5b16c6963a44"
},
{
"url": "https://git.kernel.org/stable/c/87ad116ac3abc6f2ce2b5b6c488f633003581eee"
},
{
"url": "https://git.kernel.org/stable/c/fe93a697a7a92fa9adf78c9ff67a10db3193290c"
},
{
"url": "https://git.kernel.org/stable/c/95bb57bc11a91caf042ad00fca85e480d3fda37f"
},
{
"url": "https://git.kernel.org/stable/c/29c59212a507804d7616b8abf491d30b4ab8e75f"
},
{
"url": "https://git.kernel.org/stable/c/f57b399c4fa1501b2d5451f52d861ece86bcf3db"
}
],
"title": "Bluetooth: hci_sync: Fix accept list UAF during suspend",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80762",
"datePublished": "2026-09-04T15:12:34.354Z",
"dateReserved": "2026-08-26T14:34:25.791Z",
"dateUpdated": "2026-09-04T15:12:34.354Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80555 (GCVE-0-2026-80555)
Vulnerability from cvelistv5
Published
2026-08-26 14:37
Modified
2026-08-27 12:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
s390/vfio_ccw: Free all memory if cp_init() fails
The routine cp_free() is called to unpin/free any memory once an I/O
is completed successfully, or if cp_prefetch() fails. But if cp_init()
fails, and cp->initialized is not enabled, the same routine cannot be
used to free all the memory.
An attempt to address this exists in ccwchain_handle_ccw(), where a
single call to ccwchain_free() is made for the currently-processed
CCW segment. But this will leak other segments (created as a result
of a Transfer in Channel) that had been allocated as part of the same
channel program.
Address this by performing the cleanup outside of the recursive
ccwchain_handle_ccw()/ccwchain_loop_tic() logic.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 8b515be512a2435bb8aedc6390cbe140167f9eb9 Version: 8b515be512a2435bb8aedc6390cbe140167f9eb9 Version: 8b515be512a2435bb8aedc6390cbe140167f9eb9 Version: 8b515be512a2435bb8aedc6390cbe140167f9eb9 Version: 8b515be512a2435bb8aedc6390cbe140167f9eb9 Version: 8b515be512a2435bb8aedc6390cbe140167f9eb9 Version: 8b515be512a2435bb8aedc6390cbe140167f9eb9 Version: 8b515be512a2435bb8aedc6390cbe140167f9eb9 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/s390/cio/vfio_ccw_cp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "276bd7ed34d56c48c65c43c0b08f2ee77029b2fa",
"status": "affected",
"version": "8b515be512a2435bb8aedc6390cbe140167f9eb9",
"versionType": "git"
},
{
"lessThan": "f9bcff265556796834122f95de16d52a8375206c",
"status": "affected",
"version": "8b515be512a2435bb8aedc6390cbe140167f9eb9",
"versionType": "git"
},
{
"lessThan": "17e01e342af74de12899c206dcc9ec90684703aa",
"status": "affected",
"version": "8b515be512a2435bb8aedc6390cbe140167f9eb9",
"versionType": "git"
},
{
"lessThan": "152fcb74a26804b70909381c6acc90595a0ae1c1",
"status": "affected",
"version": "8b515be512a2435bb8aedc6390cbe140167f9eb9",
"versionType": "git"
},
{
"lessThan": "6a917199aaf97904f5619afe3dfdacb155b03e8c",
"status": "affected",
"version": "8b515be512a2435bb8aedc6390cbe140167f9eb9",
"versionType": "git"
},
{
"lessThan": "32e3d364a7b8295120d37e6a6bd433d2de26f748",
"status": "affected",
"version": "8b515be512a2435bb8aedc6390cbe140167f9eb9",
"versionType": "git"
},
{
"lessThan": "4699b54fada156534cbb39834d47fc9374d7a1f5",
"status": "affected",
"version": "8b515be512a2435bb8aedc6390cbe140167f9eb9",
"versionType": "git"
},
{
"lessThan": "74186c2968f8f756ac3226b545b598457c910c75",
"status": "affected",
"version": "8b515be512a2435bb8aedc6390cbe140167f9eb9",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/s390/cio/vfio_ccw_cp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.3"
},
{
"lessThan": "5.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.267",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.218",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.185",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.154",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.267",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.218",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.185",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.154",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.46",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.10",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/vfio_ccw: Free all memory if cp_init() fails\n\nThe routine cp_free() is called to unpin/free any memory once an I/O\nis completed successfully, or if cp_prefetch() fails. But if cp_init()\nfails, and cp-\u003einitialized is not enabled, the same routine cannot be\nused to free all the memory.\n\nAn attempt to address this exists in ccwchain_handle_ccw(), where a\nsingle call to ccwchain_free() is made for the currently-processed\nCCW segment. But this will leak other segments (created as a result\nof a Transfer in Channel) that had been allocated as part of the same\nchannel program.\n\nAddress this by performing the cleanup outside of the recursive\nccwchain_handle_ccw()/ccwchain_loop_tic() logic."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached when userspace writes the vfio-ccw io_region (VFIO device mmap/write), triggering fsm_io_request() -\u003e cp_init(); on s390 KVM this is driven by QEMU forwarding guest channel-I/O channel programs, requiring local VFIO/device interaction rather than any network protocol.\nAC:L - An attacker can deterministically fail cp_init() after allocating multiple TIC-linked ccwchain segments by crafting a channel program whose early TIC targets succeed and a later one fails (invalid CPA, chain-length/count limit, or dma_rw error), leaking prior segments on every attempt without races.\nPR:N - On s390 KVM with CCW passthrough, a malicious guest can submit crafted multi-TIC channel programs through normal guest I/O; QEMU forwards them to vfio-ccw without the attacker holding host CAP_SYS_ADMIN, root, or other real init-namespace privileges beyond the assigned device.\nUI:N - No victim interaction is required beyond the attacker (or their guest) issuing channel-I/O start requests with a malicious channel program; exploitation does not depend on another user mounting media, accepting prompts, or performing administrative actions at trigger time.\nS:C - The leaked ccwchain, CCW, and page_array allocations are host kernel slab memory; a guest VM triggering this through passthrough crosses the guest-host virtualization boundary by consuming host resources the guest security domain should not affect.\nC:N - This is a kernel memory leak on the cp_init() error path, not a use-after-free, out-of-bounds read, or other memory corruption; leaked objects are orphaned in kernel heap and are not returned to userspace or the guest, so no information disclosure occurs.\nI:N - The flaw only fails to free kernel allocations when cp_init() errors; it does not corrupt memory, modify guest or host data, or provide write or control-flow primitives, and cp-\u003einitialized stays false so cp_free() never runs on the error or close paths.\nA:H - Each failed cp_init() permanently orphans up to CCWCHAIN_COUNT_MAX ccwchain segments (large GFP_DMA allocations), and subsequent cp_init() calls INIT_LIST_HEAD without freeing prior leaks; repeated guest or VFIO I/O requests can exhaust host memory and cause system-wide OOM or severe denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T12:40:15.211Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/276bd7ed34d56c48c65c43c0b08f2ee77029b2fa"
},
{
"url": "https://git.kernel.org/stable/c/f9bcff265556796834122f95de16d52a8375206c"
},
{
"url": "https://git.kernel.org/stable/c/17e01e342af74de12899c206dcc9ec90684703aa"
},
{
"url": "https://git.kernel.org/stable/c/152fcb74a26804b70909381c6acc90595a0ae1c1"
},
{
"url": "https://git.kernel.org/stable/c/6a917199aaf97904f5619afe3dfdacb155b03e8c"
},
{
"url": "https://git.kernel.org/stable/c/32e3d364a7b8295120d37e6a6bd433d2de26f748"
},
{
"url": "https://git.kernel.org/stable/c/4699b54fada156534cbb39834d47fc9374d7a1f5"
},
{
"url": "https://git.kernel.org/stable/c/74186c2968f8f756ac3226b545b598457c910c75"
}
],
"title": "s390/vfio_ccw: Free all memory if cp_init() fails",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80555",
"datePublished": "2026-08-26T14:37:22.969Z",
"dateReserved": "2026-08-26T14:34:25.766Z",
"dateUpdated": "2026-08-27T12:40:15.211Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2023-54141 (GCVE-0-2023-54141)
Vulnerability from cvelistv5
Published
2025-12-24 13:06
Modified
2026-09-02 12:49
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: ath11k: Add missing hw_ops->get_ring_selector() for IPQ5018
During sending data after clients connected, hw_ops->get_ring_selector()
will be called. But for IPQ5018, this member isn't set, and the
following NULL pointer exception will be occurred:
[ 38.840478] 8<--- cut here ---
[ 38.840517] Unable to handle kernel NULL pointer dereference at virtual address 00000000
...
[ 38.923161] PC is at 0x0
[ 38.927930] LR is at ath11k_dp_tx+0x70/0x730 [ath11k]
...
[ 39.063264] Process hostapd (pid: 1034, stack limit = 0x801ceb3d)
[ 39.068994] Stack: (0x856a9a68 to 0x856aa000)
...
[ 39.438467] [<7f323804>] (ath11k_dp_tx [ath11k]) from [<7f314e6c>] (ath11k_mac_op_tx+0x80/0x190 [ath11k])
[ 39.446607] [<7f314e6c>] (ath11k_mac_op_tx [ath11k]) from [<7f17dbe0>] (ieee80211_handle_wake_tx_queue+0x7c/0xc0 [mac80211])
[ 39.456162] [<7f17dbe0>] (ieee80211_handle_wake_tx_queue [mac80211]) from [<7f174450>] (ieee80211_probereq_get+0x584/0x704 [mac80211])
[ 39.467443] [<7f174450>] (ieee80211_probereq_get [mac80211]) from [<7f178c40>] (ieee80211_tx_prepare_skb+0x1f8/0x248 [mac80211])
[ 39.479334] [<7f178c40>] (ieee80211_tx_prepare_skb [mac80211]) from [<7f179e28>] (__ieee80211_subif_start_xmit+0x32c/0x3d4 [mac80211])
[ 39.491053] [<7f179e28>] (__ieee80211_subif_start_xmit [mac80211]) from [<7f17af08>] (ieee80211_tx_control_port+0x19c/0x288 [mac80211])
[ 39.502946] [<7f17af08>] (ieee80211_tx_control_port [mac80211]) from [<7f0fc704>] (nl80211_tx_control_port+0x174/0x1d4 [cfg80211])
[ 39.515017] [<7f0fc704>] (nl80211_tx_control_port [cfg80211]) from [<808ceac4>] (genl_rcv_msg+0x154/0x340)
[ 39.526814] [<808ceac4>] (genl_rcv_msg) from [<808cdb74>] (netlink_rcv_skb+0xb8/0x11c)
[ 39.536446] [<808cdb74>] (netlink_rcv_skb) from [<808ce1d0>] (genl_rcv+0x28/0x34)
[ 39.544344] [<808ce1d0>] (genl_rcv) from [<808cd234>] (netlink_unicast+0x174/0x274)
[ 39.551895] [<808cd234>] (netlink_unicast) from [<808cd510>] (netlink_sendmsg+0x1dc/0x440)
[ 39.559362] [<808cd510>] (netlink_sendmsg) from [<808596e0>] (____sys_sendmsg+0x1a8/0x1fc)
[ 39.567697] [<808596e0>] (____sys_sendmsg) from [<8085b1a8>] (___sys_sendmsg+0xa4/0xdc)
[ 39.575941] [<8085b1a8>] (___sys_sendmsg) from [<8085b310>] (sys_sendmsg+0x44/0x74)
[ 39.583841] [<8085b310>] (sys_sendmsg) from [<80300060>] (ret_fast_syscall+0x0/0x40)
...
[ 39.620734] Code: bad PC value
[ 39.625869] ---[ end trace 8aef983ad3cbc032 ]---
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/ath/ath11k/hw.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "d49d420e4833fdf6d7c506de23884a0cb9b08e0a",
"status": "affected",
"version": "d0ca5aa0fe7e3a43797ed1bf8b144c59863fd65c",
"versionType": "git"
},
{
"lessThan": "d1992d72a359732f143cc962917104d193705da7",
"status": "affected",
"version": "ba60f2793d3a37a00da14bb56a26558a902d2831",
"versionType": "git"
},
{
"lessThan": "c36289e3c5e83286974ef68c20c821fd5b63801c",
"status": "affected",
"version": "ba60f2793d3a37a00da14bb56a26558a902d2831",
"versionType": "git"
},
{
"lessThan": "ce282d8de71f07f0056ea319541141152c65f552",
"status": "affected",
"version": "ba60f2793d3a37a00da14bb56a26558a902d2831",
"versionType": "git"
},
{
"lessThan": "6.1.187",
"status": "affected",
"version": "6.1.175",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/ath/ath11k/hw.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.3"
},
{
"lessThan": "6.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.187",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.3.*",
"status": "unaffected",
"version": "6.3.13",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.4.*",
"status": "unaffected",
"version": "6.4.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "6.5",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.187",
"versionStartIncluding": "6.1.175",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.3.13",
"versionStartIncluding": "6.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.4.4",
"versionStartIncluding": "6.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.5",
"versionStartIncluding": "6.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath11k: Add missing hw_ops-\u003eget_ring_selector() for IPQ5018\n\nDuring sending data after clients connected, hw_ops-\u003eget_ring_selector()\nwill be called. But for IPQ5018, this member isn\u0027t set, and the\nfollowing NULL pointer exception will be occurred:\n\n\t[ 38.840478] 8\u003c--- cut here ---\n\t[ 38.840517] Unable to handle kernel NULL pointer dereference at virtual address 00000000\n\t...\n\t[ 38.923161] PC is at 0x0\n\t[ 38.927930] LR is at ath11k_dp_tx+0x70/0x730 [ath11k]\n\t...\n\t[ 39.063264] Process hostapd (pid: 1034, stack limit = 0x801ceb3d)\n\t[ 39.068994] Stack: (0x856a9a68 to 0x856aa000)\n\t...\n\t[ 39.438467] [\u003c7f323804\u003e] (ath11k_dp_tx [ath11k]) from [\u003c7f314e6c\u003e] (ath11k_mac_op_tx+0x80/0x190 [ath11k])\n\t[ 39.446607] [\u003c7f314e6c\u003e] (ath11k_mac_op_tx [ath11k]) from [\u003c7f17dbe0\u003e] (ieee80211_handle_wake_tx_queue+0x7c/0xc0 [mac80211])\n\t[ 39.456162] [\u003c7f17dbe0\u003e] (ieee80211_handle_wake_tx_queue [mac80211]) from [\u003c7f174450\u003e] (ieee80211_probereq_get+0x584/0x704 [mac80211])\n\t[ 39.467443] [\u003c7f174450\u003e] (ieee80211_probereq_get [mac80211]) from [\u003c7f178c40\u003e] (ieee80211_tx_prepare_skb+0x1f8/0x248 [mac80211])\n\t[ 39.479334] [\u003c7f178c40\u003e] (ieee80211_tx_prepare_skb [mac80211]) from [\u003c7f179e28\u003e] (__ieee80211_subif_start_xmit+0x32c/0x3d4 [mac80211])\n\t[ 39.491053] [\u003c7f179e28\u003e] (__ieee80211_subif_start_xmit [mac80211]) from [\u003c7f17af08\u003e] (ieee80211_tx_control_port+0x19c/0x288 [mac80211])\n\t[ 39.502946] [\u003c7f17af08\u003e] (ieee80211_tx_control_port [mac80211]) from [\u003c7f0fc704\u003e] (nl80211_tx_control_port+0x174/0x1d4 [cfg80211])\n\t[ 39.515017] [\u003c7f0fc704\u003e] (nl80211_tx_control_port [cfg80211]) from [\u003c808ceac4\u003e] (genl_rcv_msg+0x154/0x340)\n\t[ 39.526814] [\u003c808ceac4\u003e] (genl_rcv_msg) from [\u003c808cdb74\u003e] (netlink_rcv_skb+0xb8/0x11c)\n\t[ 39.536446] [\u003c808cdb74\u003e] (netlink_rcv_skb) from [\u003c808ce1d0\u003e] (genl_rcv+0x28/0x34)\n\t[ 39.544344] [\u003c808ce1d0\u003e] (genl_rcv) from [\u003c808cd234\u003e] (netlink_unicast+0x174/0x274)\n\t[ 39.551895] [\u003c808cd234\u003e] (netlink_unicast) from [\u003c808cd510\u003e] (netlink_sendmsg+0x1dc/0x440)\n\t[ 39.559362] [\u003c808cd510\u003e] (netlink_sendmsg) from [\u003c808596e0\u003e] (____sys_sendmsg+0x1a8/0x1fc)\n\t[ 39.567697] [\u003c808596e0\u003e] (____sys_sendmsg) from [\u003c8085b1a8\u003e] (___sys_sendmsg+0xa4/0xdc)\n\t[ 39.575941] [\u003c8085b1a8\u003e] (___sys_sendmsg) from [\u003c8085b310\u003e] (sys_sendmsg+0x44/0x74)\n\t[ 39.583841] [\u003c8085b310\u003e] (sys_sendmsg) from [\u003c80300060\u003e] (ret_fast_syscall+0x0/0x40)\n\t...\n\t[ 39.620734] Code: bad PC value\n\t[ 39.625869] ---[ end trace 8aef983ad3cbc032 ]---"
}
],
"providerMetadata": {
"dateUpdated": "2026-09-02T12:49:08.767Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/d49d420e4833fdf6d7c506de23884a0cb9b08e0a"
},
{
"url": "https://git.kernel.org/stable/c/d1992d72a359732f143cc962917104d193705da7"
},
{
"url": "https://git.kernel.org/stable/c/c36289e3c5e83286974ef68c20c821fd5b63801c"
},
{
"url": "https://git.kernel.org/stable/c/ce282d8de71f07f0056ea319541141152c65f552"
}
],
"title": "wifi: ath11k: Add missing hw_ops-\u003eget_ring_selector() for IPQ5018",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2023-54141",
"datePublished": "2025-12-24T13:06:55.468Z",
"dateReserved": "2025-12-24T13:02:52.523Z",
"dateUpdated": "2026-09-02T12:49:08.767Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68349 (GCVE-0-2026-68349)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: carl9170: fix buffer overflow in rx_stream failover path
The failover continuation in carl9170_rx_stream() copies the full tlen
from the second USB transfer instead of capping at rx_failover_missing
bytes. When both transfers are near maximum size, the total exceeds the
65535-byte failover SKB, triggering skb_over_panic.
Limit the copy size to the missing byte count.
[Fix checkpatch CHECK:PARENTHESIS_ALIGNMENT]
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/ath/carl9170/rx.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "5fb00a09e9b0375e1ad9d4fefc4a62a67e7ea658",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "48c81fb523ecdc6a4b8654944ff32e499f21e6d0",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "a1ce01764a812c22a47d30aea78e347aebd3eea1",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "5acfa18de66b6089b81c1c0bf1a3ae3c940ec39e",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "b9dfee5e63ee9b5c47be9e344ebc5bd3f43fca78",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "4503829843353dbb18b879c35be1cdfc9af677b7",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "21f59906ea75618fdd46a7e32754d54fbee083ea",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "a1a21995c2e1cc2ca6b2226cfe4f5f018370182a",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/ath/carl9170/rx.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.37"
},
{
"lessThan": "2.6.37",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.37",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: carl9170: fix buffer overflow in rx_stream failover path\n\nThe failover continuation in carl9170_rx_stream() copies the full tlen\nfrom the second USB transfer instead of capping at rx_failover_missing\nbytes. When both transfers are near maximum size, the total exceeds the\n65535-byte failover SKB, triggering skb_over_panic.\n\nLimit the copy size to the missing byte count.\n\n[Fix checkpatch CHECK:PARENTHESIS_ALIGNMENT]"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:47.832Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/5fb00a09e9b0375e1ad9d4fefc4a62a67e7ea658"
},
{
"url": "https://git.kernel.org/stable/c/48c81fb523ecdc6a4b8654944ff32e499f21e6d0"
},
{
"url": "https://git.kernel.org/stable/c/a1ce01764a812c22a47d30aea78e347aebd3eea1"
},
{
"url": "https://git.kernel.org/stable/c/5acfa18de66b6089b81c1c0bf1a3ae3c940ec39e"
},
{
"url": "https://git.kernel.org/stable/c/b9dfee5e63ee9b5c47be9e344ebc5bd3f43fca78"
},
{
"url": "https://git.kernel.org/stable/c/4503829843353dbb18b879c35be1cdfc9af677b7"
},
{
"url": "https://git.kernel.org/stable/c/21f59906ea75618fdd46a7e32754d54fbee083ea"
},
{
"url": "https://git.kernel.org/stable/c/a1a21995c2e1cc2ca6b2226cfe4f5f018370182a"
}
],
"title": "wifi: carl9170: fix buffer overflow in rx_stream failover path",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68349",
"datePublished": "2026-08-10T12:03:26.166Z",
"dateReserved": "2026-07-30T09:28:09.384Z",
"dateUpdated": "2026-08-19T16:33:47.832Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64542 (GCVE-0-2026-64542)
Vulnerability from cvelistv5
Published
2026-07-27 20:10
Modified
2026-08-19 16:28
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ipv6: ndisc: fix NULL deref in accept_untracked_na()
accept_untracked_na() re-fetches the inet6_dev with __in6_dev_get(dev)
and dereferences idev->cnf.accept_untracked_na without a NULL check,
even though its only caller ndisc_recv_na() already fetched and
NULL-checked idev for the same device.
Both reads of dev->ip6_ptr run in the same RCU read-side critical
section, but a concurrent addrconf_ifdown() can clear dev->ip6_ptr
between them: lowering the MTU below IPV6_MIN_MTU calls addrconf_ifdown()
without the synchronize_net() that orders the unregister path, so the
re-fetch returns NULL and oopses:
BUG: KASAN: null-ptr-deref in ndisc_recv_na (net/ipv6/ndisc.c:974)
Read of size 4 at addr 0000000000000364
Call Trace:
<IRQ>
ndisc_recv_na (net/ipv6/ndisc.c:974)
icmpv6_rcv (net/ipv6/icmp.c:1193)
ip6_protocol_deliver_rcu (net/ipv6/ip6_input.c:479)
ip6_input_finish (net/ipv6/ip6_input.c:534)
ip6_input (net/ipv6/ip6_input.c:545)
ip6_mc_input (net/ipv6/ip6_input.c:635)
ipv6_rcv (net/ipv6/ip6_input.c:351)
</IRQ>
It is reachable by an unprivileged user via a network namespace.
Pass the caller's already validated idev instead of re-fetching it; the
idev stays alive for the whole RCU critical section, so it is safe even
after dev->ip6_ptr has been cleared.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: aaa5f515b16b6b3e137779ffb4c9558bb58c1e75 Version: aaa5f515b16b6b3e137779ffb4c9558bb58c1e75 Version: aaa5f515b16b6b3e137779ffb4c9558bb58c1e75 Version: aaa5f515b16b6b3e137779ffb4c9558bb58c1e75 Version: aaa5f515b16b6b3e137779ffb4c9558bb58c1e75 Version: aaa5f515b16b6b3e137779ffb4c9558bb58c1e75 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ipv6/ndisc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "e5ba3017e46f275ad347e762e8eecacec5efa41d",
"status": "affected",
"version": "aaa5f515b16b6b3e137779ffb4c9558bb58c1e75",
"versionType": "git"
},
{
"lessThan": "160d3f0d7a556ceae505dcab521a37057b4ce28f",
"status": "affected",
"version": "aaa5f515b16b6b3e137779ffb4c9558bb58c1e75",
"versionType": "git"
},
{
"lessThan": "62c719203cb521b64fab74da94a81bdde5c18808",
"status": "affected",
"version": "aaa5f515b16b6b3e137779ffb4c9558bb58c1e75",
"versionType": "git"
},
{
"lessThan": "a6450f7cfae57b382cbaf66a577765c9a88b3c58",
"status": "affected",
"version": "aaa5f515b16b6b3e137779ffb4c9558bb58c1e75",
"versionType": "git"
},
{
"lessThan": "63d1c23764de2309cedbb779c75188d257a09d9b",
"status": "affected",
"version": "aaa5f515b16b6b3e137779ffb4c9558bb58c1e75",
"versionType": "git"
},
{
"lessThan": "d186e942365acece7c56d39da05dd63bf95b280a",
"status": "affected",
"version": "aaa5f515b16b6b3e137779ffb4c9558bb58c1e75",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ipv6/ndisc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.0"
},
{
"lessThan": "6.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: ndisc: fix NULL deref in accept_untracked_na()\n\naccept_untracked_na() re-fetches the inet6_dev with __in6_dev_get(dev)\nand dereferences idev-\u003ecnf.accept_untracked_na without a NULL check,\neven though its only caller ndisc_recv_na() already fetched and\nNULL-checked idev for the same device.\n\nBoth reads of dev-\u003eip6_ptr run in the same RCU read-side critical\nsection, but a concurrent addrconf_ifdown() can clear dev-\u003eip6_ptr\nbetween them: lowering the MTU below IPV6_MIN_MTU calls addrconf_ifdown()\nwithout the synchronize_net() that orders the unregister path, so the\nre-fetch returns NULL and oopses:\n\n BUG: KASAN: null-ptr-deref in ndisc_recv_na (net/ipv6/ndisc.c:974)\n Read of size 4 at addr 0000000000000364\n Call Trace:\n \u003cIRQ\u003e\n ndisc_recv_na (net/ipv6/ndisc.c:974)\n icmpv6_rcv (net/ipv6/icmp.c:1193)\n ip6_protocol_deliver_rcu (net/ipv6/ip6_input.c:479)\n ip6_input_finish (net/ipv6/ip6_input.c:534)\n ip6_input (net/ipv6/ip6_input.c:545)\n ip6_mc_input (net/ipv6/ip6_input.c:635)\n ipv6_rcv (net/ipv6/ip6_input.c:351)\n \u003c/IRQ\u003e\n\nIt is reachable by an unprivileged user via a network namespace.\n\nPass the caller\u0027s already validated idev instead of re-fetching it; the\nidev stays alive for the whole RCU critical section, so it is safe even\nafter dev-\u003eip6_ptr has been cleared."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:28:25.885Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/e5ba3017e46f275ad347e762e8eecacec5efa41d"
},
{
"url": "https://git.kernel.org/stable/c/160d3f0d7a556ceae505dcab521a37057b4ce28f"
},
{
"url": "https://git.kernel.org/stable/c/62c719203cb521b64fab74da94a81bdde5c18808"
},
{
"url": "https://git.kernel.org/stable/c/a6450f7cfae57b382cbaf66a577765c9a88b3c58"
},
{
"url": "https://git.kernel.org/stable/c/63d1c23764de2309cedbb779c75188d257a09d9b"
},
{
"url": "https://git.kernel.org/stable/c/d186e942365acece7c56d39da05dd63bf95b280a"
}
],
"title": "ipv6: ndisc: fix NULL deref in accept_untracked_na()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64542",
"datePublished": "2026-07-27T20:10:34.994Z",
"dateReserved": "2026-07-19T15:36:31.795Z",
"dateUpdated": "2026-08-19T16:28:25.885Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68325 (GCVE-0-2026-68325)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
iommu/amd: Bound the early ACPI HID map
The ivrs_acpihid command-line parser appends entries to a fixed
four-element early_acpihid_map array. Unlike the sibling IOAPIC and HPET
parsers, it does not reject a fifth entry before incrementing the map size.
Check the capacity at the common found label before parsing the HID and
UID or writing the entry.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ca3bf5d47cec8b7614bcb2e9132c40081d6d81db Version: ca3bf5d47cec8b7614bcb2e9132c40081d6d81db Version: ca3bf5d47cec8b7614bcb2e9132c40081d6d81db Version: ca3bf5d47cec8b7614bcb2e9132c40081d6d81db Version: ca3bf5d47cec8b7614bcb2e9132c40081d6d81db Version: ca3bf5d47cec8b7614bcb2e9132c40081d6d81db Version: ca3bf5d47cec8b7614bcb2e9132c40081d6d81db Version: ca3bf5d47cec8b7614bcb2e9132c40081d6d81db |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/iommu/amd/init.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "9ae6b1b972ce01d3316c8a5f7f58c8b3668cc6bb",
"status": "affected",
"version": "ca3bf5d47cec8b7614bcb2e9132c40081d6d81db",
"versionType": "git"
},
{
"lessThan": "e5e0098f8cd82f8b3c8687a8f686309565d51745",
"status": "affected",
"version": "ca3bf5d47cec8b7614bcb2e9132c40081d6d81db",
"versionType": "git"
},
{
"lessThan": "afe7ea0520c49586703f210865ace2d70b017e48",
"status": "affected",
"version": "ca3bf5d47cec8b7614bcb2e9132c40081d6d81db",
"versionType": "git"
},
{
"lessThan": "1e31d2394e0db69541b1591d46c5ad6431c81db3",
"status": "affected",
"version": "ca3bf5d47cec8b7614bcb2e9132c40081d6d81db",
"versionType": "git"
},
{
"lessThan": "abe5d7962f09adada9c4fb25b816dddd3f97c55d",
"status": "affected",
"version": "ca3bf5d47cec8b7614bcb2e9132c40081d6d81db",
"versionType": "git"
},
{
"lessThan": "e5ebe8544df1a1c3611739a8622156094fe470df",
"status": "affected",
"version": "ca3bf5d47cec8b7614bcb2e9132c40081d6d81db",
"versionType": "git"
},
{
"lessThan": "030a8e84f8f1b6e96f469c84a13a225c3699910b",
"status": "affected",
"version": "ca3bf5d47cec8b7614bcb2e9132c40081d6d81db",
"versionType": "git"
},
{
"lessThan": "fb80117fddb5b477218dc99bb53911b72c3847f8",
"status": "affected",
"version": "ca3bf5d47cec8b7614bcb2e9132c40081d6d81db",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/iommu/amd/init.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.7"
},
{
"lessThan": "4.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\niommu/amd: Bound the early ACPI HID map\n\nThe ivrs_acpihid command-line parser appends entries to a fixed\nfour-element early_acpihid_map array. Unlike the sibling IOAPIC and HPET\nparsers, it does not reject a fifth entry before incrementing the map size.\n\nCheck the capacity at the common found label before parsing the HID and\nUID or writing the entry."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:18.080Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/9ae6b1b972ce01d3316c8a5f7f58c8b3668cc6bb"
},
{
"url": "https://git.kernel.org/stable/c/e5e0098f8cd82f8b3c8687a8f686309565d51745"
},
{
"url": "https://git.kernel.org/stable/c/afe7ea0520c49586703f210865ace2d70b017e48"
},
{
"url": "https://git.kernel.org/stable/c/1e31d2394e0db69541b1591d46c5ad6431c81db3"
},
{
"url": "https://git.kernel.org/stable/c/abe5d7962f09adada9c4fb25b816dddd3f97c55d"
},
{
"url": "https://git.kernel.org/stable/c/e5ebe8544df1a1c3611739a8622156094fe470df"
},
{
"url": "https://git.kernel.org/stable/c/030a8e84f8f1b6e96f469c84a13a225c3699910b"
},
{
"url": "https://git.kernel.org/stable/c/fb80117fddb5b477218dc99bb53911b72c3847f8"
}
],
"title": "iommu/amd: Bound the early ACPI HID map",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68325",
"datePublished": "2026-08-10T12:03:01.384Z",
"dateReserved": "2026-07-30T09:28:09.382Z",
"dateUpdated": "2026-08-19T16:33:18.080Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74615 (GCVE-0-2026-74615)
Vulnerability from cvelistv5
Published
2026-08-22 15:32
Modified
2026-08-25 05:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
vxlan: do not arm the ageing timer on a device that is down
vxlan_changelink() arms vxlan->age_timer whenever the requested ageing
interval differs from the configured one:
if (conf.age_interval != vxlan->cfg.age_interval)
mod_timer(&vxlan->age_timer, jiffies);
There is no netif_running() test, so the timer is armed even on a device
that was never brought up. The only synchronous cancel in the driver is
the timer_delete_sync() in vxlan_stop(), which is .ndo_stop.
netif_close_many() drops devices without IFF_UP before
__dev_close_many() runs, so that cancel is skipped for such a device.
vxlan_setup() sets dev->needs_free_netdev = true and age_timer is a
member of struct vxlan_dev, so free_netdev() releases the allocation the
timer lives in while it is still queued on a timer_base.
expire_timers() unlinks the entry before it loads timer->function, so
the timer core writes through the freed object's list pointers:
BUG: KASAN: slab-use-after-free in __run_timers+0x208/0x654
Write of size 8 at addr ffff00001adace68 by task true/192
__asan_store8+0x84/0xac
__run_timers+0x208/0x654
run_timer_softirq+0x154/0x18c
Allocated by task 189:
alloc_netdev_mqs+0x64/0x720
rtnl_create_link+0x4ac/0x520
rtnl_newlink+0x758/0xd00
Freed by task 191:
netdev_release+0x40/0x58
netdev_run_todo+0x4a4/0x8c0
rtnl_dellink+0x200/0x4e8
The rtnl operations involved are netns-scoped, so an unprivileged user
can perform them in a new user and network namespace.
Arming the timer on a down device never had an effect: vxlan_cleanup()
returns early on !netif_running(), and vxlan_open() arms the timer for
any non-zero interval once the device is brought up. Add the missing
test.
Discovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 40051c4dcad5b374156ad9cceae8d15c0ef1cb95 Version: 40051c4dcad5b374156ad9cceae8d15c0ef1cb95 Version: 40051c4dcad5b374156ad9cceae8d15c0ef1cb95 Version: 40051c4dcad5b374156ad9cceae8d15c0ef1cb95 Version: 40051c4dcad5b374156ad9cceae8d15c0ef1cb95 Version: 40051c4dcad5b374156ad9cceae8d15c0ef1cb95 Version: 40051c4dcad5b374156ad9cceae8d15c0ef1cb95 Version: 40051c4dcad5b374156ad9cceae8d15c0ef1cb95 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/vxlan/vxlan_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "be44d79d14d7f9ae7c8ffb7272142005341b5123",
"status": "affected",
"version": "40051c4dcad5b374156ad9cceae8d15c0ef1cb95",
"versionType": "git"
},
{
"lessThan": "26c179d47403d2f919ee914cc02c31d896b59fee",
"status": "affected",
"version": "40051c4dcad5b374156ad9cceae8d15c0ef1cb95",
"versionType": "git"
},
{
"lessThan": "9dc561f0522c35bdd66e0646a748814a138ec4ca",
"status": "affected",
"version": "40051c4dcad5b374156ad9cceae8d15c0ef1cb95",
"versionType": "git"
},
{
"lessThan": "619dd29045e439d0b0f8c6d4fec1af447a050680",
"status": "affected",
"version": "40051c4dcad5b374156ad9cceae8d15c0ef1cb95",
"versionType": "git"
},
{
"lessThan": "6b095e99b9e67ea31f0c4b00260e010898253519",
"status": "affected",
"version": "40051c4dcad5b374156ad9cceae8d15c0ef1cb95",
"versionType": "git"
},
{
"lessThan": "46bb297ad77680e009244f067f27d51cf5b8c7cf",
"status": "affected",
"version": "40051c4dcad5b374156ad9cceae8d15c0ef1cb95",
"versionType": "git"
},
{
"lessThan": "6b4119af544996a545cf84b16f1dbce829ba0de8",
"status": "affected",
"version": "40051c4dcad5b374156ad9cceae8d15c0ef1cb95",
"versionType": "git"
},
{
"lessThan": "b37971686ec59fb027fa4910ba16805e68fddb97",
"status": "affected",
"version": "40051c4dcad5b374156ad9cceae8d15c0ef1cb95",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/vxlan/vxlan_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.0"
},
{
"lessThan": "5.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nvxlan: do not arm the ageing timer on a device that is down\n\nvxlan_changelink() arms vxlan-\u003eage_timer whenever the requested ageing\ninterval differs from the configured one:\n\n\tif (conf.age_interval != vxlan-\u003ecfg.age_interval)\n\t\tmod_timer(\u0026vxlan-\u003eage_timer, jiffies);\n\nThere is no netif_running() test, so the timer is armed even on a device\nthat was never brought up. The only synchronous cancel in the driver is\nthe timer_delete_sync() in vxlan_stop(), which is .ndo_stop.\nnetif_close_many() drops devices without IFF_UP before\n__dev_close_many() runs, so that cancel is skipped for such a device.\n\nvxlan_setup() sets dev-\u003eneeds_free_netdev = true and age_timer is a\nmember of struct vxlan_dev, so free_netdev() releases the allocation the\ntimer lives in while it is still queued on a timer_base.\nexpire_timers() unlinks the entry before it loads timer-\u003efunction, so\nthe timer core writes through the freed object\u0027s list pointers:\n\n BUG: KASAN: slab-use-after-free in __run_timers+0x208/0x654\n Write of size 8 at addr ffff00001adace68 by task true/192\n __asan_store8+0x84/0xac\n __run_timers+0x208/0x654\n run_timer_softirq+0x154/0x18c\n Allocated by task 189:\n alloc_netdev_mqs+0x64/0x720\n rtnl_create_link+0x4ac/0x520\n rtnl_newlink+0x758/0xd00\n Freed by task 191:\n netdev_release+0x40/0x58\n netdev_run_todo+0x4a4/0x8c0\n rtnl_dellink+0x200/0x4e8\n\nThe rtnl operations involved are netns-scoped, so an unprivileged user\ncan perform them in a new user and network namespace.\n\nArming the timer on a down device never had an effect: vxlan_cleanup()\nreturns early on !netif_running(), and vxlan_open() arms the timer for\nany non-zero interval once the device is brought up. Add the missing\ntest.\n\nDiscovered by XBOW, triaged by Baul Lee \u003cbaul.lee@xbow.com\u003e"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached only via local RTNETLINK on AF_NETLINK: RTM_NEWLINK creates a vxlan netdev, changelink with IFLA_VXLAN_AGEING arms age_timer, and RTM_DELLINK frees it; remote VXLAN encapsulation/packet receive is not involved.\nAC:L - The attacker fully controls a deterministic sequence on a never-up device: changelink calls mod_timer(jiffies) and dellink frees netdev while the timer stays queued because netif_close_many skips IFF_UP-less devices so vxlan_stop/timer_delete_sync never runs.\nPR:L - rtnetlink_rcv_msg requires CAP_NET_ADMIN for RTM_NEWLINK, RTM_SETLINK, and RTM_DELLINK; unprivileged local users obtain this capability inside a new user and network namespace (unshare -Urn), as stated in the fix commit.\nUI:N - No victim interaction is required; the attacker alone issues netlink create/changelink/delete operations on their own down vxlan interface without bringing the device up or requiring mounts or file access.\nS:C - Slab UAF corruption triggered from CAP_NET_ADMIN inside an unprivileged user/network namespace affects host kernel timer-list memory outside the namespace sandbox, crossing the container-to-host security boundary.\nC:H - KASAN reports slab-use-after-free with an 8-byte write through freed vxlan_dev-\u003eage_timer list pointers in __run_timers; UAF on kernel timer structures enables arbitrary kernel memory disclosure via slab heap reuse.\nI:H - expire_timers() writes to freed timer_list entry fields before loading the callback, providing controlled slab corruption; UAF on embedded vxlan_dev timers is exploitable for arbitrary kernel writes and privilege escalation.\nA:H - Confirmed KASAN slab-use-after-free in run_timer_softirq can kernel oops/panic; the dangling timer remains armed after rtnl_dellink and the sequence can be repeated for reliable denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:40:42.219Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/be44d79d14d7f9ae7c8ffb7272142005341b5123"
},
{
"url": "https://git.kernel.org/stable/c/26c179d47403d2f919ee914cc02c31d896b59fee"
},
{
"url": "https://git.kernel.org/stable/c/9dc561f0522c35bdd66e0646a748814a138ec4ca"
},
{
"url": "https://git.kernel.org/stable/c/619dd29045e439d0b0f8c6d4fec1af447a050680"
},
{
"url": "https://git.kernel.org/stable/c/6b095e99b9e67ea31f0c4b00260e010898253519"
},
{
"url": "https://git.kernel.org/stable/c/46bb297ad77680e009244f067f27d51cf5b8c7cf"
},
{
"url": "https://git.kernel.org/stable/c/6b4119af544996a545cf84b16f1dbce829ba0de8"
},
{
"url": "https://git.kernel.org/stable/c/b37971686ec59fb027fa4910ba16805e68fddb97"
}
],
"title": "vxlan: do not arm the ageing timer on a device that is down",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74615",
"datePublished": "2026-08-22T15:32:00.588Z",
"dateReserved": "2026-08-15T05:44:03.920Z",
"dateUpdated": "2026-08-25T05:40:42.219Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74662 (GCVE-0-2026-74662)
Vulnerability from cvelistv5
Published
2026-08-22 15:32
Modified
2026-08-27 12:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
inet: frags: publish queues before arming timer
inet_frag_create() arms the fragment queue timer before inserting the
queue into the fqdir rhashtable. If the namespace fragment timeout is
zero or negative, the timer can run before the queue is published.
The timer callback then marks the queue complete, tries to remove a node
that is not in the hash table yet, and drops the anticipated hash
reference. Creation can subsequently publish the completed queue without
restoring that reference, leaving a stale hash node after the caller drops
the remaining reference.
Publish the queue first and arm the timer while holding the queue lock.
This makes timer expiry wait until the queue is visible in the hash table,
so inet_frag_kill() can remove the node and balance the hash reference.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 648700f76b03b7e8149d13cc2bdb3355035258a9 Version: 648700f76b03b7e8149d13cc2bdb3355035258a9 Version: 648700f76b03b7e8149d13cc2bdb3355035258a9 Version: 648700f76b03b7e8149d13cc2bdb3355035258a9 Version: 648700f76b03b7e8149d13cc2bdb3355035258a9 Version: 648700f76b03b7e8149d13cc2bdb3355035258a9 Version: 648700f76b03b7e8149d13cc2bdb3355035258a9 Version: 648700f76b03b7e8149d13cc2bdb3355035258a9 Version: 493107105843f299662b3b664a83804645564f12 Version: 4.4.174 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ipv4/inet_fragment.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "f4e4dab62181b7fe7c011bed6fbef9fc3d48c769",
"status": "affected",
"version": "648700f76b03b7e8149d13cc2bdb3355035258a9",
"versionType": "git"
},
{
"lessThan": "4ed0681dc2c1e0538b79d2fc56190ffcb369dacd",
"status": "affected",
"version": "648700f76b03b7e8149d13cc2bdb3355035258a9",
"versionType": "git"
},
{
"lessThan": "08a04d7bfb9c103432561aff8a62b6872e694a6a",
"status": "affected",
"version": "648700f76b03b7e8149d13cc2bdb3355035258a9",
"versionType": "git"
},
{
"lessThan": "d3ffb89b2944672cf7bdd8e9ee577d2043b4a956",
"status": "affected",
"version": "648700f76b03b7e8149d13cc2bdb3355035258a9",
"versionType": "git"
},
{
"lessThan": "39c6c4b267b65f00e0b0335a2ae00cbe9e3174f0",
"status": "affected",
"version": "648700f76b03b7e8149d13cc2bdb3355035258a9",
"versionType": "git"
},
{
"lessThan": "9f904dd3e455750e5d4ec9b2f134835811b85a2f",
"status": "affected",
"version": "648700f76b03b7e8149d13cc2bdb3355035258a9",
"versionType": "git"
},
{
"lessThan": "928128865e43b197e30688dc1bc991592c97edcf",
"status": "affected",
"version": "648700f76b03b7e8149d13cc2bdb3355035258a9",
"versionType": "git"
},
{
"lessThan": "653d7ddf6cba867777a3d14c4f83ace008c5ad13",
"status": "affected",
"version": "648700f76b03b7e8149d13cc2bdb3355035258a9",
"versionType": "git"
},
{
"status": "affected",
"version": "493107105843f299662b3b664a83804645564f12",
"versionType": "git"
},
{
"lessThan": "4.5",
"status": "affected",
"version": "4.4.174",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ipv4/inet_fragment.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.17"
},
{
"lessThan": "4.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.267",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.218",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.185",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.154",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.106",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.267",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.218",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.185",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.154",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.106",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.4.174",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ninet: frags: publish queues before arming timer\n\ninet_frag_create() arms the fragment queue timer before inserting the\nqueue into the fqdir rhashtable. If the namespace fragment timeout is\nzero or negative, the timer can run before the queue is published.\n\nThe timer callback then marks the queue complete, tries to remove a node\nthat is not in the hash table yet, and drops the anticipated hash\nreference. Creation can subsequently publish the completed queue without\nrestoring that reference, leaving a stale hash node after the caller drops\nthe remaining reference.\n\nPublish the queue first and arm the timer while holding the queue lock.\nThis makes timer expiry wait until the queue is visible in the hash table,\nso inet_frag_kill() can remove the node and balance the hash reference."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - IPv4/IPv6 fragments reach inet_frag_create() via remote receive paths (ip_defrag, ipv6_frag_rcv, nf_conntrack reassembly) on any Internet-facing host performing normal fragment reassembly before transport delivery.\nAC:L - Requires per-netns fragment timeout \u22640 so the armed timer expires during queue creation; attacker-settable with CAP_NET_ADMIN in user/net namespaces, and the timer/hash race is fully attacker-controlled and repeatable via crafted fragments.\nPR:N - No authentication or capability check gates IPv4/IPv6 fragment receive/reassembly before inet_frag_find(); remote peers can deliver the triggering fragmented traffic pre-authentication to hosts processing fragments.\nUI:N - Exploitation needs only crafted fragmented packet delivery; no victim action such as opening files, clicking links, or mounting filesystems is required.\nS:U - Corruption is confined to the kernel network stack in the same security authority; this is standard kernel memory corruption/privilege escalation, not a VM escape or IOMMU boundary bypass.\nC:H - Incorrect refcounting leaves a stale rhashtable entry pointing at a freed inet_frag_queue; subsequent fragment lookups dereference freed slab memory, enabling kernel information disclosure primitives.\nI:H - Follow-on fragment handling on the stale queue writes through freed inet_frag_queue and skb linkage fields, yielding kernel heap corruption exploitable for arbitrary modification or code execution.\nA:H - Freed-queue dereferences during reassembly can kernel oops or panic; attackers can retrigger the condition repeatedly by sending additional fragmented datagrams matching the same fragment key."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T12:39:58.332Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/f4e4dab62181b7fe7c011bed6fbef9fc3d48c769"
},
{
"url": "https://git.kernel.org/stable/c/4ed0681dc2c1e0538b79d2fc56190ffcb369dacd"
},
{
"url": "https://git.kernel.org/stable/c/08a04d7bfb9c103432561aff8a62b6872e694a6a"
},
{
"url": "https://git.kernel.org/stable/c/d3ffb89b2944672cf7bdd8e9ee577d2043b4a956"
},
{
"url": "https://git.kernel.org/stable/c/39c6c4b267b65f00e0b0335a2ae00cbe9e3174f0"
},
{
"url": "https://git.kernel.org/stable/c/9f904dd3e455750e5d4ec9b2f134835811b85a2f"
},
{
"url": "https://git.kernel.org/stable/c/928128865e43b197e30688dc1bc991592c97edcf"
},
{
"url": "https://git.kernel.org/stable/c/653d7ddf6cba867777a3d14c4f83ace008c5ad13"
}
],
"title": "inet: frags: publish queues before arming timer",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74662",
"datePublished": "2026-08-22T15:32:35.151Z",
"dateReserved": "2026-08-15T05:44:03.924Z",
"dateUpdated": "2026-08-27T12:39:58.332Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64577 (GCVE-0-2026-64577)
Vulnerability from cvelistv5
Published
2026-08-05 08:09
Modified
2026-08-19 16:28
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
gtp: check skb_pull_data() return in gtp1u_send_echo_resp()
gtp1u_send_echo_resp() ignores skb_pull_data()'s return value. Its
caller gtp1u_udp_encap_recv() only guarantees 16 bytes (udphdr +
gtp1_header), but the pull requests 20 (gtp1_header_long + udphdr). For
a 16-19 byte echo request the pull fails and returns NULL without
advancing skb->data; execution continues, and the following skb_push()
plus the IP header pushed by iptunnel_xmit() move skb->data below
skb->head, tripping skb_under_panic().
Fix it by dropping the packet when skb_pull_data() fails.
skbuff: skb_under_panic: ...
kernel BUG at net/core/skbuff.c:214!
Call Trace:
skb_push (net/core/skbuff.c:2648)
iptunnel_xmit (net/ipv4/ip_tunnel_core.c:82)
gtp_encap_recv (drivers/net/gtp.c:701 drivers/net/gtp.c:808 drivers/net/gtp.c:920)
udp_queue_rcv_one_skb (net/ipv4/udp.c:2388)
...
Kernel panic - not syncing: Fatal exception in interrupt
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 9af41cc33471ea1efa6f77e188f055cc77d0a5c5 Version: 9af41cc33471ea1efa6f77e188f055cc77d0a5c5 Version: 9af41cc33471ea1efa6f77e188f055cc77d0a5c5 Version: 9af41cc33471ea1efa6f77e188f055cc77d0a5c5 Version: 9af41cc33471ea1efa6f77e188f055cc77d0a5c5 Version: 9af41cc33471ea1efa6f77e188f055cc77d0a5c5 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/gtp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "9033fe49926f0e7421fefee922dc086417e905cf",
"status": "affected",
"version": "9af41cc33471ea1efa6f77e188f055cc77d0a5c5",
"versionType": "git"
},
{
"lessThan": "b3c733eaae7f362601c28ac1533d47a961cd3e1c",
"status": "affected",
"version": "9af41cc33471ea1efa6f77e188f055cc77d0a5c5",
"versionType": "git"
},
{
"lessThan": "4fc7923871d176ce0e5fecf4a9b7bb915af790ed",
"status": "affected",
"version": "9af41cc33471ea1efa6f77e188f055cc77d0a5c5",
"versionType": "git"
},
{
"lessThan": "961e9b1e33445f8e42859ecc020c9f60d8b69a8b",
"status": "affected",
"version": "9af41cc33471ea1efa6f77e188f055cc77d0a5c5",
"versionType": "git"
},
{
"lessThan": "cf45d748e437b8dd2dd987f27ee79c8c86f95c88",
"status": "affected",
"version": "9af41cc33471ea1efa6f77e188f055cc77d0a5c5",
"versionType": "git"
},
{
"lessThan": "cd170f051dba9ac146fabcd1b91726487c0cb9fa",
"status": "affected",
"version": "9af41cc33471ea1efa6f77e188f055cc77d0a5c5",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/gtp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.18"
},
{
"lessThan": "5.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.18",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ngtp: check skb_pull_data() return in gtp1u_send_echo_resp()\n\ngtp1u_send_echo_resp() ignores skb_pull_data()\u0027s return value. Its\ncaller gtp1u_udp_encap_recv() only guarantees 16 bytes (udphdr +\ngtp1_header), but the pull requests 20 (gtp1_header_long + udphdr). For\na 16-19 byte echo request the pull fails and returns NULL without\nadvancing skb-\u003edata; execution continues, and the following skb_push()\nplus the IP header pushed by iptunnel_xmit() move skb-\u003edata below\nskb-\u003ehead, tripping skb_under_panic().\n\nFix it by dropping the packet when skb_pull_data() fails.\n\n skbuff: skb_under_panic: ...\n kernel BUG at net/core/skbuff.c:214!\n Call Trace:\n skb_push (net/core/skbuff.c:2648)\n iptunnel_xmit (net/ipv4/ip_tunnel_core.c:82)\n gtp_encap_recv (drivers/net/gtp.c:701 drivers/net/gtp.c:808 drivers/net/gtp.c:920)\n udp_queue_rcv_one_skb (net/ipv4/udp.c:2388)\n ...\n Kernel panic - not syncing: Fatal exception in interrupt"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - A crafted GTP-U Echo Request to UDP port 2152 reaches gtp_encap_recv \u2192 gtp1u_udp_encap_recv \u2192 gtp1u_send_echo_resp via the in-kernel UDP encap receive path, so a remote IP peer can trigger the bug without local access.\nAC:L - The attacker fully controls the packet: a 16\u201319 byte GTP-U Echo Request with the S flag set and TEID 0 reliably fails the unchecked 20-byte pull and drives the subsequent skb_push path into skb_under_panic with no race or external condition required.\nPR:N - GTP-U echo handling runs on unauthenticated received UDP datagrams once a GTP device with kernel-created sockets exists; the attacker needs no credentials or local privileges on the target.\nUI:N - No victim action is required; packet delivery to the GTP-U encap socket alone invokes the vulnerable echo-response path.\nS:U - Impact is a kernel BUG/panic in the host GTP/network stack within the same security authority; it does not cross a VM, IOMMU, or other separate boundary.\nC:N - The failure is a deterministic skb headroom underflow caught by skb_under_panic/BUG with no out-of-bounds read, UAF, or other information-disclosure primitive identified.\nI:N - skb_push detects data \u003c head and BUG()s before further attacker-controlled writes; this is an availability crash, not an exploitable write or control-flow hijack primitive.\nA:H - The commit-reproduced path hits skb_under_panic and a fatal kernel BUG in interrupt context, causing kernel panic and full denial of service that can be retriggered by further crafted echo requests."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:28:59.684Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/9033fe49926f0e7421fefee922dc086417e905cf"
},
{
"url": "https://git.kernel.org/stable/c/b3c733eaae7f362601c28ac1533d47a961cd3e1c"
},
{
"url": "https://git.kernel.org/stable/c/4fc7923871d176ce0e5fecf4a9b7bb915af790ed"
},
{
"url": "https://git.kernel.org/stable/c/961e9b1e33445f8e42859ecc020c9f60d8b69a8b"
},
{
"url": "https://git.kernel.org/stable/c/cf45d748e437b8dd2dd987f27ee79c8c86f95c88"
},
{
"url": "https://git.kernel.org/stable/c/cd170f051dba9ac146fabcd1b91726487c0cb9fa"
}
],
"title": "gtp: check skb_pull_data() return in gtp1u_send_echo_resp()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64577",
"datePublished": "2026-08-05T08:09:33.135Z",
"dateReserved": "2026-07-19T15:36:31.798Z",
"dateUpdated": "2026-08-19T16:28:59.684Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68336 (GCVE-0-2026-68336)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
bonding: fix devconf_all NULL dereference when IPv6 is disabled
When booting with the 'ipv6.disable=1' parameter, the devconf_all is
never initialized because inet6_init() exits before addrconf_init() is
called which initializes it. bond_send_validate(), however, will still
call bond_ns_send_all() even ipv6 is indeed disabled. It will lead to
NULL derefence of net->ipv6.devconf_all in ip6_pol_route().
BUG: kernel NULL pointer dereference, address: 000000000000000c
[...]
Workqueue: bond0 bond_arp_monitor [bonding]
RIP: 0010:ip6_pol_route+0x69/0x480
[...]
Call Trace:
<TASK>
? srso_return_thunk+0x5/0x5f
? __pfx_ip6_pol_route_output+0x10/0x10
fib6_rule_lookup+0xfe/0x260
? wakeup_preempt+0x8a/0x90
? srso_return_thunk+0x5/0x5f
? srso_return_thunk+0x5/0x5f
? sched_balance_rq+0x369/0x810
ip6_route_output_flags+0xd7/0x170
bond_ns_send_all+0xde/0x280 [bonding]
bond_ab_arp_probe+0x296/0x320 [bonding]
? srso_return_thunk+0x5/0x5f
bond_activebackup_arp_mon+0xb4/0x2c0 [bonding]
process_one_work+0x196/0x370
worker_thread+0x1af/0x320
? srso_return_thunk+0x5/0x5f
? __pfx_worker_thread+0x10/0x10
kthread+0xe3/0x120
? __pfx_kthread+0x10/0x10
ret_from_fork+0x199/0x260
? __pfx_kthread+0x10/0x10
ret_from_fork_asm+0x1a/0x30
</TASK>
Fix this by adding ipv6_mod_enabled() condition check in the caller.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 4e24be018eb9dbcefa4b01c07e298b147dc1a4d7 Version: 4e24be018eb9dbcefa4b01c07e298b147dc1a4d7 Version: 4e24be018eb9dbcefa4b01c07e298b147dc1a4d7 Version: 4e24be018eb9dbcefa4b01c07e298b147dc1a4d7 Version: 4e24be018eb9dbcefa4b01c07e298b147dc1a4d7 Version: 4e24be018eb9dbcefa4b01c07e298b147dc1a4d7 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/bonding/bond_main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "451c2d5422a309393aa8ae161fc1a527c2f19ab2",
"status": "affected",
"version": "4e24be018eb9dbcefa4b01c07e298b147dc1a4d7",
"versionType": "git"
},
{
"lessThan": "2a4bad24ac5296b262ad821aa5e08bb265e6b154",
"status": "affected",
"version": "4e24be018eb9dbcefa4b01c07e298b147dc1a4d7",
"versionType": "git"
},
{
"lessThan": "690ce66782778e8c4b1fdd79c0b0890a100e9522",
"status": "affected",
"version": "4e24be018eb9dbcefa4b01c07e298b147dc1a4d7",
"versionType": "git"
},
{
"lessThan": "992dce02bdabbd9883255ea9b36494e34a7821d7",
"status": "affected",
"version": "4e24be018eb9dbcefa4b01c07e298b147dc1a4d7",
"versionType": "git"
},
{
"lessThan": "738039ad21e20ca2c5bbde2f5a4f5ad5fb718038",
"status": "affected",
"version": "4e24be018eb9dbcefa4b01c07e298b147dc1a4d7",
"versionType": "git"
},
{
"lessThan": "1c975de3343cdef506f2eecc833cc1f14b0401c4",
"status": "affected",
"version": "4e24be018eb9dbcefa4b01c07e298b147dc1a4d7",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/bonding/bond_main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.18"
},
{
"lessThan": "5.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.18",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbonding: fix devconf_all NULL dereference when IPv6 is disabled\n\nWhen booting with the \u0027ipv6.disable=1\u0027 parameter, the devconf_all is\nnever initialized because inet6_init() exits before addrconf_init() is\ncalled which initializes it. bond_send_validate(), however, will still\ncall bond_ns_send_all() even ipv6 is indeed disabled. It will lead to\nNULL derefence of net-\u003eipv6.devconf_all in ip6_pol_route().\n\n BUG: kernel NULL pointer dereference, address: 000000000000000c\n [...]\n Workqueue: bond0 bond_arp_monitor [bonding]\n RIP: 0010:ip6_pol_route+0x69/0x480\n [...]\n Call Trace:\n \u003cTASK\u003e\n ? srso_return_thunk+0x5/0x5f\n ? __pfx_ip6_pol_route_output+0x10/0x10\n fib6_rule_lookup+0xfe/0x260\n ? wakeup_preempt+0x8a/0x90\n ? srso_return_thunk+0x5/0x5f\n ? srso_return_thunk+0x5/0x5f\n ? sched_balance_rq+0x369/0x810\n ip6_route_output_flags+0xd7/0x170\n bond_ns_send_all+0xde/0x280 [bonding]\n bond_ab_arp_probe+0x296/0x320 [bonding]\n ? srso_return_thunk+0x5/0x5f\n bond_activebackup_arp_mon+0xb4/0x2c0 [bonding]\n process_one_work+0x196/0x370\n worker_thread+0x1af/0x320\n ? srso_return_thunk+0x5/0x5f\n ? __pfx_worker_thread+0x10/0x10\n kthread+0xe3/0x120\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x199/0x260\n ? __pfx_kthread+0x10/0x10\n ret_from_fork_asm+0x1a/0x30\n \u003c/TASK\u003e\n\nFix this by adding ipv6_mod_enabled() condition check in the caller."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:35.547Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/451c2d5422a309393aa8ae161fc1a527c2f19ab2"
},
{
"url": "https://git.kernel.org/stable/c/2a4bad24ac5296b262ad821aa5e08bb265e6b154"
},
{
"url": "https://git.kernel.org/stable/c/690ce66782778e8c4b1fdd79c0b0890a100e9522"
},
{
"url": "https://git.kernel.org/stable/c/992dce02bdabbd9883255ea9b36494e34a7821d7"
},
{
"url": "https://git.kernel.org/stable/c/738039ad21e20ca2c5bbde2f5a4f5ad5fb718038"
},
{
"url": "https://git.kernel.org/stable/c/1c975de3343cdef506f2eecc833cc1f14b0401c4"
}
],
"title": "bonding: fix devconf_all NULL dereference when IPv6 is disabled",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68336",
"datePublished": "2026-08-10T12:03:12.592Z",
"dateReserved": "2026-07-30T09:28:09.383Z",
"dateUpdated": "2026-08-19T16:33:35.547Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80789 (GCVE-0-2026-80789)
Vulnerability from cvelistv5
Published
2026-09-04 15:13
Modified
2026-09-04 15:13
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
nvmet-tcp: bound SGL data length before allocating command buffers
nvmet_tcp_map_data() reads the host-controlled 32-bit sgl->length
and, for the in-capsule offset descriptor (type 0x01), checks it
against port->inline_data_size before use. Any other SGL descriptor
type -- including the non-inline transport SGL data-block descriptor
(type (NVME_TRANSPORT_SGL_DATA_DESC << 4) | NVME_SGL_FMT_TRANSPORT_A,
the type a real host uses for out-of-capsule writes) skips that check
entirely and falls straight through to:
cmd->req.sg = sgl_alloc(len, GFP_KERNEL, &cmd->req.sg_cnt);
with len taken directly from the wire, unbounded up to 4 GiB.
nvmet_req_init() only parses the command and never inspects
sgl->length, and nvmet_check_transfer_len() -- the only other place
transfer_len is validated -- runs later, from req->execute(), after
the allocation has already happened. For a write command the target
responds with an R2T and parks the command waiting for the host to
send the data; if the host (or an unauthenticated peer that simply
never follows up) never does, the sgl_alloc() buffer stays resident
for the life of the command. NVMe/TCP has no mandatory authentication
in the default configuration, so any peer able to reach the target
portal and complete a Fabrics connect can drive this with a single
crafted command, repeatable across queues and connections for
amplification. This is unbounded kernel memory allocation
triggered by a remote, effectively unauthenticated peer.
Validate len against the same NVMET_TCP_MAXH2CDATA ceiling this file
already uses to bound per-PDU H2C data, for every SGL descriptor type,
before doing any allocation. This closes the gap for the non-inline
descriptor while leaving the existing, tighter inline_data_size check
in place for the in-capsule case.
Runtime-verified on a v6.19 KASAN stand: with this bound in place, a
crafted write command carrying an oversized non-inline SGL length is
rejected before sgl_alloc() runs, where the same request previously
drove an unbounded ~256 MiB kernel allocation (up to 4 GiB) that
stayed resident pending an R2T the host never satisfies.
References
| URL | Tags | ||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 872d26a391da92ed8f0c0f5cb5fef428067b7f30 Version: 872d26a391da92ed8f0c0f5cb5fef428067b7f30 Version: 872d26a391da92ed8f0c0f5cb5fef428067b7f30 Version: 872d26a391da92ed8f0c0f5cb5fef428067b7f30 Version: 872d26a391da92ed8f0c0f5cb5fef428067b7f30 Version: 872d26a391da92ed8f0c0f5cb5fef428067b7f30 Version: 872d26a391da92ed8f0c0f5cb5fef428067b7f30 Version: 872d26a391da92ed8f0c0f5cb5fef428067b7f30 Version: 872d26a391da92ed8f0c0f5cb5fef428067b7f30 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/nvme/target/tcp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "f6e51b09cbaa5f6f6e6a3a9dafa666f76c37aab5",
"status": "affected",
"version": "872d26a391da92ed8f0c0f5cb5fef428067b7f30",
"versionType": "git"
},
{
"lessThan": "f63e89a0310264264923f84406dea05fe752de62",
"status": "affected",
"version": "872d26a391da92ed8f0c0f5cb5fef428067b7f30",
"versionType": "git"
},
{
"lessThan": "0952541b153e258b99d39cdb03ea6919fdeb41d0",
"status": "affected",
"version": "872d26a391da92ed8f0c0f5cb5fef428067b7f30",
"versionType": "git"
},
{
"lessThan": "25ad03d5c0e858c4b63f1e4b6d461d2af1b30b22",
"status": "affected",
"version": "872d26a391da92ed8f0c0f5cb5fef428067b7f30",
"versionType": "git"
},
{
"lessThan": "d2acc96c528d589f5827cfb90e8e9229dd9d8cb4",
"status": "affected",
"version": "872d26a391da92ed8f0c0f5cb5fef428067b7f30",
"versionType": "git"
},
{
"lessThan": "6d27199ebe8cb223022150f74be13f154a964474",
"status": "affected",
"version": "872d26a391da92ed8f0c0f5cb5fef428067b7f30",
"versionType": "git"
},
{
"lessThan": "14dbe37681a6a7e346fc147bb363ec7cca3180a0",
"status": "affected",
"version": "872d26a391da92ed8f0c0f5cb5fef428067b7f30",
"versionType": "git"
},
{
"lessThan": "d895e66628f939edbb98608f6e033d3d39e6e546",
"status": "affected",
"version": "872d26a391da92ed8f0c0f5cb5fef428067b7f30",
"versionType": "git"
},
{
"lessThan": "4a3f00262a044e8e15064b1a6860968bf0500bf4",
"status": "affected",
"version": "872d26a391da92ed8f0c0f5cb5fef428067b7f30",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/nvme/target/tcp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.0"
},
{
"lessThan": "5.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.269",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.220",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.187",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.156",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.106",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.47",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.1",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.269",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.220",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.187",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.156",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.106",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.47",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.11",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.1",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "5.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet-tcp: bound SGL data length before allocating command buffers\n\nnvmet_tcp_map_data() reads the host-controlled 32-bit sgl-\u003elength\nand, for the in-capsule offset descriptor (type 0x01), checks it\nagainst port-\u003einline_data_size before use. Any other SGL descriptor\ntype -- including the non-inline transport SGL data-block descriptor\n(type (NVME_TRANSPORT_SGL_DATA_DESC \u003c\u003c 4) | NVME_SGL_FMT_TRANSPORT_A,\nthe type a real host uses for out-of-capsule writes) skips that check\nentirely and falls straight through to:\n\n\tcmd-\u003ereq.sg = sgl_alloc(len, GFP_KERNEL, \u0026cmd-\u003ereq.sg_cnt);\n\nwith len taken directly from the wire, unbounded up to 4 GiB.\n\nnvmet_req_init() only parses the command and never inspects\nsgl-\u003elength, and nvmet_check_transfer_len() -- the only other place\ntransfer_len is validated -- runs later, from req-\u003eexecute(), after\nthe allocation has already happened. For a write command the target\nresponds with an R2T and parks the command waiting for the host to\nsend the data; if the host (or an unauthenticated peer that simply\nnever follows up) never does, the sgl_alloc() buffer stays resident\nfor the life of the command. NVMe/TCP has no mandatory authentication\nin the default configuration, so any peer able to reach the target\nportal and complete a Fabrics connect can drive this with a single\ncrafted command, repeatable across queues and connections for\namplification. This is unbounded kernel memory allocation\ntriggered by a remote, effectively unauthenticated peer.\n\nValidate len against the same NVMET_TCP_MAXH2CDATA ceiling this file\nalready uses to bound per-PDU H2C data, for every SGL descriptor type,\nbefore doing any allocation. This closes the gap for the non-inline\ndescriptor while leaving the existing, tighter inline_data_size check\nin place for the in-capsule case.\n\nRuntime-verified on a v6.19 KASAN stand: with this bound in place, a\ncrafted write command carrying an oversized non-inline SGL length is\nrejected before sgl_alloc() runs, where the same request previously\ndrove an unbounded ~256 MiB kernel allocation (up to 4 GiB) that\nstayed resident pending an R2T the host never satisfies."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T15:13:01.161Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/f6e51b09cbaa5f6f6e6a3a9dafa666f76c37aab5"
},
{
"url": "https://git.kernel.org/stable/c/f63e89a0310264264923f84406dea05fe752de62"
},
{
"url": "https://git.kernel.org/stable/c/0952541b153e258b99d39cdb03ea6919fdeb41d0"
},
{
"url": "https://git.kernel.org/stable/c/25ad03d5c0e858c4b63f1e4b6d461d2af1b30b22"
},
{
"url": "https://git.kernel.org/stable/c/d2acc96c528d589f5827cfb90e8e9229dd9d8cb4"
},
{
"url": "https://git.kernel.org/stable/c/6d27199ebe8cb223022150f74be13f154a964474"
},
{
"url": "https://git.kernel.org/stable/c/14dbe37681a6a7e346fc147bb363ec7cca3180a0"
},
{
"url": "https://git.kernel.org/stable/c/d895e66628f939edbb98608f6e033d3d39e6e546"
},
{
"url": "https://git.kernel.org/stable/c/4a3f00262a044e8e15064b1a6860968bf0500bf4"
}
],
"title": "nvmet-tcp: bound SGL data length before allocating command buffers",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80789",
"datePublished": "2026-09-04T15:13:01.161Z",
"dateReserved": "2026-08-26T14:34:25.793Z",
"dateUpdated": "2026-09-04T15:13:01.161Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74624 (GCVE-0-2026-74624)
Vulnerability from cvelistv5
Published
2026-08-22 15:32
Modified
2026-08-25 05:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_conntrack: defer invalid log until after unlock
TCP and SCTP conntrack paths can emit invalid-packet logs while ct->lock
is still held.
When invalid logging is routed to nfnetlink_log and conntrack export is
enabled, the log path can re-enter conntrack netlink glue and dump the
same conntrack again. Protocol attribute dumping may take ct->lock, so
logging while holding that lock can deadlock.
Defer the TCP invalid logs by storing only the minimal log context while
ct->lock is held and emitting the log after unlocking. Also make the TCP
timeout-lowering invalid path return whether a log is needed, then emit
that log after unlocking.
Do the same for the SCTP invalid state-transition log that can be reached
while ct->lock is held.
Add a lockdep assertion to nf_ct_l4proto_log_invalid() so future callers
that log invalid conntracks while holding ct->lock are caught outside TCP
and SCTP as well.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d9a6f0d0df1899ff9086a57abc600e414f4b8cdd Version: d9a6f0d0df1899ff9086a57abc600e414f4b8cdd Version: d9a6f0d0df1899ff9086a57abc600e414f4b8cdd Version: d9a6f0d0df1899ff9086a57abc600e414f4b8cdd Version: d9a6f0d0df1899ff9086a57abc600e414f4b8cdd Version: d9a6f0d0df1899ff9086a57abc600e414f4b8cdd |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/netfilter/nf_conntrack_proto.c",
"net/netfilter/nf_conntrack_proto_sctp.c",
"net/netfilter/nf_conntrack_proto_tcp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ca97360eba4b3dc67f1804625542f4ccc774242a",
"status": "affected",
"version": "d9a6f0d0df1899ff9086a57abc600e414f4b8cdd",
"versionType": "git"
},
{
"lessThan": "63853eb20bba4e00b7cd0b8cfc19337bbaaf5037",
"status": "affected",
"version": "d9a6f0d0df1899ff9086a57abc600e414f4b8cdd",
"versionType": "git"
},
{
"lessThan": "9480fcf70a5aa9d320088a01c95df0e5e6391f4a",
"status": "affected",
"version": "d9a6f0d0df1899ff9086a57abc600e414f4b8cdd",
"versionType": "git"
},
{
"lessThan": "0424186d570aa4d1ad17f516afb86bd9eaa4f42e",
"status": "affected",
"version": "d9a6f0d0df1899ff9086a57abc600e414f4b8cdd",
"versionType": "git"
},
{
"lessThan": "c0224327b7cbed9d3198e8dbec847281053dcd06",
"status": "affected",
"version": "d9a6f0d0df1899ff9086a57abc600e414f4b8cdd",
"versionType": "git"
},
{
"lessThan": "2d19b95c9723001f214f7a47d67b09f46238f200",
"status": "affected",
"version": "d9a6f0d0df1899ff9086a57abc600e414f4b8cdd",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/netfilter/nf_conntrack_proto.c",
"net/netfilter/nf_conntrack_proto_sctp.c",
"net/netfilter/nf_conntrack_proto_tcp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.1"
},
{
"lessThan": "6.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "6.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "6.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "6.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "6.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "6.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_conntrack: defer invalid log until after unlock\n\nTCP and SCTP conntrack paths can emit invalid-packet logs while ct-\u003elock\nis still held.\n\nWhen invalid logging is routed to nfnetlink_log and conntrack export is\nenabled, the log path can re-enter conntrack netlink glue and dump the\nsame conntrack again. Protocol attribute dumping may take ct-\u003elock, so\nlogging while holding that lock can deadlock.\n\nDefer the TCP invalid logs by storing only the minimal log context while\nct-\u003elock is held and emitting the log after unlocking. Also make the TCP\ntimeout-lowering invalid path return whether a log is needed, then emit\nthat log after unlocking.\n\nDo the same for the SCTP invalid state-transition log that can be reached\nwhile ct-\u003elock is held.\n\nAdd a lockdep assertion to nf_ct_l4proto_log_invalid() so future callers\nthat log invalid conntracks while holding ct-\u003elock are caught outside TCP\nand SCTP as well."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The flaw is hit in nf_conntrack_tcp_packet()/nf_conntrack_sctp_packet() from the NF_INET_PRE_ROUTING and LOCAL_OUT netfilter hooks on received or forwarded TCP/SCTP traffic, so a remote peer can trigger invalid conntrack handling with crafted packets to internet-facing NAT gateways, routers, and servers.\nAC:L - Once nf_conntrack_log_invalid, nflog binding, and NFULNL_CFG_F_CONNTRACK are enabled (the CVE-scoped configuration on monitored firewalls), an attacker deterministically deadlocks by sending invalid-sequence TCP or invalid-state SCTP packets on tracked flows without races or special memory layout.\nPR:N - Triggering the vulnerable conntrack path requires only the ability to send TCP/SCTP packets to a host already running connection tracking with invalid logging; no local account, CAP_NET_ADMIN, or netlink configuration privileges are needed on the attacker side.\nUI:N - Exploitation is driven entirely by network packet delivery and softirq packet processing; no victim must open files, mount filesystems, or perform any interactive action beyond normal network connectivity to the target.\nS:U - The deadlock confines impact to the same kernel networking authority processing the packet; it does not cross VM, container, or IOMMU boundaries to compromise a separate security domain.\nC:N - This is a recursive spinlock deadlock in conntrack invalid logging with no memory corruption, out-of-bounds access, use-after-free, or information-disclosure primitive.\nI:N - The bug causes a lock re-entry hang during logging only; it does not modify kernel or user data, provide arbitrary write primitives, or enable code execution.\nA:H - Re-acquiring ct-\u003elock while it is held deadlocks packet processing on the affected CPU in softirq context, can stall networking on that core, and may escalate to soft lockup or watchdog-induced kernel panic under sustained attack."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:40:47.114Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ca97360eba4b3dc67f1804625542f4ccc774242a"
},
{
"url": "https://git.kernel.org/stable/c/63853eb20bba4e00b7cd0b8cfc19337bbaaf5037"
},
{
"url": "https://git.kernel.org/stable/c/9480fcf70a5aa9d320088a01c95df0e5e6391f4a"
},
{
"url": "https://git.kernel.org/stable/c/0424186d570aa4d1ad17f516afb86bd9eaa4f42e"
},
{
"url": "https://git.kernel.org/stable/c/c0224327b7cbed9d3198e8dbec847281053dcd06"
},
{
"url": "https://git.kernel.org/stable/c/2d19b95c9723001f214f7a47d67b09f46238f200"
}
],
"title": "netfilter: nf_conntrack: defer invalid log until after unlock",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74624",
"datePublished": "2026-08-22T15:32:07.193Z",
"dateReserved": "2026-08-15T05:44:03.921Z",
"dateUpdated": "2026-08-25T05:40:47.114Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68129 (GCVE-0-2026-68129)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-19 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
gve: fix Rx queue stall on alloc failure
When the system is under extreme memory pressure, page allocations can
fail during the Rx buffer refill loop. If the number of buffers posted
to hardware falls below a critical low threshold and the refill loop
exits due to allocation failures, the queue can stall:
1. The device drops incoming packets because there are no descriptors.
2. Since no packets are processed, no Rx completions are generated.
3. Because no completions occur, NAPI is never scheduled, preventing
the refill loop from running again even after memory is freed.
This results in a permanent queue stall.
Resolve this by introducing a starvation recovery timer for each Rx queue.
If the number of buffers posted to hardware falls below a critical low
threshold, start a timer to periodically reschedule NAPI. Once NAPI runs
and successfully refills the queue above the threshold, the timer is
not rescheduled.
The threshold is set to 32 because a single maximum-sized Receive Segment
Coalescing (RSC) packet can consume up to 19 descriptors in the Rx path.
Lower thresholds (such as 8 or 16) would be insufficient to process a
complete maximum-sized RSC packet, risking packet drops or unexpected
hardware behavior under memory pressure. Setting the threshold to 32
guarantees a safe margin to handle at least one full RSC packet.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 9b8dd5e5ea48bbb7532d20c4093a79d8283e4029 Version: 9b8dd5e5ea48bbb7532d20c4093a79d8283e4029 Version: 9b8dd5e5ea48bbb7532d20c4093a79d8283e4029 Version: 9b8dd5e5ea48bbb7532d20c4093a79d8283e4029 Version: 9b8dd5e5ea48bbb7532d20c4093a79d8283e4029 Version: 9b8dd5e5ea48bbb7532d20c4093a79d8283e4029 Version: 9b8dd5e5ea48bbb7532d20c4093a79d8283e4029 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/google/gve/gve.h",
"drivers/net/ethernet/google/gve/gve_rx_dqo.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "9db46e19e5d6bdcd4bf811284a5b0df1b984ef80",
"status": "affected",
"version": "9b8dd5e5ea48bbb7532d20c4093a79d8283e4029",
"versionType": "git"
},
{
"lessThan": "42d525e751c61b876b2b0ae4e71ba7a8ab0c2777",
"status": "affected",
"version": "9b8dd5e5ea48bbb7532d20c4093a79d8283e4029",
"versionType": "git"
},
{
"lessThan": "299d5728a7312fdd02059b074aebbe4ebbd391e4",
"status": "affected",
"version": "9b8dd5e5ea48bbb7532d20c4093a79d8283e4029",
"versionType": "git"
},
{
"lessThan": "0c317349b4baa5038d1fc373bf46d5a2419d1710",
"status": "affected",
"version": "9b8dd5e5ea48bbb7532d20c4093a79d8283e4029",
"versionType": "git"
},
{
"lessThan": "91e0249f3ef62b75fe8c9c9372eaba32876e4b3a",
"status": "affected",
"version": "9b8dd5e5ea48bbb7532d20c4093a79d8283e4029",
"versionType": "git"
},
{
"lessThan": "689b9f588d2d7323dc66293fe594a68d030f400f",
"status": "affected",
"version": "9b8dd5e5ea48bbb7532d20c4093a79d8283e4029",
"versionType": "git"
},
{
"lessThan": "b65352a1bac64442ad95e64f385b40ccb9f1b0db",
"status": "affected",
"version": "9b8dd5e5ea48bbb7532d20c4093a79d8283e4029",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/google/gve/gve.h",
"drivers/net/ethernet/google/gve/gve_rx_dqo.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.14"
},
{
"lessThan": "5.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ngve: fix Rx queue stall on alloc failure\n\nWhen the system is under extreme memory pressure, page allocations can\nfail during the Rx buffer refill loop. If the number of buffers posted\nto hardware falls below a critical low threshold and the refill loop\nexits due to allocation failures, the queue can stall:\n\n1. The device drops incoming packets because there are no descriptors.\n2. Since no packets are processed, no Rx completions are generated.\n3. Because no completions occur, NAPI is never scheduled, preventing\n the refill loop from running again even after memory is freed.\n\nThis results in a permanent queue stall.\n\nResolve this by introducing a starvation recovery timer for each Rx queue.\nIf the number of buffers posted to hardware falls below a critical low\nthreshold, start a timer to periodically reschedule NAPI. Once NAPI runs\nand successfully refills the queue above the threshold, the timer is\nnot rescheduled.\n\nThe threshold is set to 32 because a single maximum-sized Receive Segment\nCoalescing (RSC) packet can consume up to 19 descriptors in the Rx path.\nLower thresholds (such as 8 or 16) would be insufficient to process a\ncomplete maximum-sized RSC packet, risking packet drops or unexpected\nhardware behavior under memory pressure. Setting the threshold to 32\nguarantees a safe margin to handle at least one full RSC packet."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The flaw is in the gVNIC receive/refill path driven by incoming network traffic on internet-facing Google Cloud VMs; remote packets trigger NAPI polling that reaches gve_rx_post_buffers_dqo() where the stall occurs.\nAC:L - An attacker can reliably drive the vulnerable refill loop by sending high-volume traffic to exhaust RX page-pool buffers and pressure GFP_ATOMIC allocations; no race or rare layout is required beyond sustained network load.\nPR:N - Exploitation requires only the ability to send packets to the VM\u0027s gVNIC interface; no local account, capabilities, or authentication is needed on internet-reachable cloud instances.\nUI:N - No victim interaction is required; the permanent RX queue stall is triggered automatically during kernel packet receive processing under memory pressure.\nS:U - Impact is confined to the affected guest\u0027s network stack and does not cross VM, container, or IOMMU security boundaries; it is a guest-local denial of service, not an escape.\nC:N - This is a resource-management logic bug causing queue starvation with no out-of-bounds access, use-after-free, or information disclosure; no kernel or user memory is read by the attacker.\nI:N - The bug causes a permanent receive-queue stall without modifying kernel data structures, user data, or enabling code execution; there is no integrity impact beyond loss of connectivity.\nA:H - A failed refill below the 32-descriptor threshold permanently stalls the RX queue because no completions schedule NAPI again, causing lasting loss of network receive capability until reboot."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:29:44.226Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/9db46e19e5d6bdcd4bf811284a5b0df1b984ef80"
},
{
"url": "https://git.kernel.org/stable/c/42d525e751c61b876b2b0ae4e71ba7a8ab0c2777"
},
{
"url": "https://git.kernel.org/stable/c/299d5728a7312fdd02059b074aebbe4ebbd391e4"
},
{
"url": "https://git.kernel.org/stable/c/0c317349b4baa5038d1fc373bf46d5a2419d1710"
},
{
"url": "https://git.kernel.org/stable/c/91e0249f3ef62b75fe8c9c9372eaba32876e4b3a"
},
{
"url": "https://git.kernel.org/stable/c/689b9f588d2d7323dc66293fe594a68d030f400f"
},
{
"url": "https://git.kernel.org/stable/c/b65352a1bac64442ad95e64f385b40ccb9f1b0db"
}
],
"title": "gve: fix Rx queue stall on alloc failure",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68129",
"datePublished": "2026-08-10T11:58:51.406Z",
"dateReserved": "2026-07-30T09:28:09.370Z",
"dateUpdated": "2026-08-19T16:29:44.226Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74679 (GCVE-0-2026-74679)
Vulnerability from cvelistv5
Published
2026-08-22 15:32
Modified
2026-08-22 15:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: f_ncm: Use unsigned int for ndp_index
The variable ndp_index is declared as a signed integer, but it stores
the return value of get_ncm(), which is unsigned.
A malicious host can supply a large offset that overflows the signed
ndp_index, making it negative. Because ndp_index is compared against
unsigned bounds, this negative value bypasses sanity checks and leads
to an out-of-bounds read when calculating the address of the NDP
block (ntb_ptr + ndp_index).
Fix this by changing ndp_index to unsigned int to ensure consistent
unsigned comparisons throughout the function.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 370af734dfaf8336b496b386e194648e097e248a Version: 370af734dfaf8336b496b386e194648e097e248a Version: 370af734dfaf8336b496b386e194648e097e248a Version: 370af734dfaf8336b496b386e194648e097e248a Version: 370af734dfaf8336b496b386e194648e097e248a Version: 370af734dfaf8336b496b386e194648e097e248a Version: 370af734dfaf8336b496b386e194648e097e248a Version: 370af734dfaf8336b496b386e194648e097e248a |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/gadget/function/f_ncm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "9c8c6825a750fcd3efbe922847ca70ccd5a66857",
"status": "affected",
"version": "370af734dfaf8336b496b386e194648e097e248a",
"versionType": "git"
},
{
"lessThan": "a1c0deeba4a46481543d6b09c665f758c54c3a1a",
"status": "affected",
"version": "370af734dfaf8336b496b386e194648e097e248a",
"versionType": "git"
},
{
"lessThan": "d13f650a3485b58c124b3cda45597e8002c9c833",
"status": "affected",
"version": "370af734dfaf8336b496b386e194648e097e248a",
"versionType": "git"
},
{
"lessThan": "11413d7ed42174b8f5d8d0b6a25d10dc88239b21",
"status": "affected",
"version": "370af734dfaf8336b496b386e194648e097e248a",
"versionType": "git"
},
{
"lessThan": "5b2b3a3229a3f4c493ffdee53aee2f173b6f13b3",
"status": "affected",
"version": "370af734dfaf8336b496b386e194648e097e248a",
"versionType": "git"
},
{
"lessThan": "d328fdc607fa1bb668ad512e1c918a120f78f337",
"status": "affected",
"version": "370af734dfaf8336b496b386e194648e097e248a",
"versionType": "git"
},
{
"lessThan": "fc9e54e22845c4da29588ca0986cb7c795b5a262",
"status": "affected",
"version": "370af734dfaf8336b496b386e194648e097e248a",
"versionType": "git"
},
{
"lessThan": "6b1c8a9403a26cb0fed7a648916c74dc236da591",
"status": "affected",
"version": "370af734dfaf8336b496b386e194648e097e248a",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/usb/gadget/function/f_ncm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.17"
},
{
"lessThan": "3.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.17",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: f_ncm: Use unsigned int for ndp_index\n\nThe variable ndp_index is declared as a signed integer, but it stores\nthe return value of get_ncm(), which is unsigned.\n\nA malicious host can supply a large offset that overflows the signed\nndp_index, making it negative. Because ndp_index is compared against\nunsigned bounds, this negative value bypasses sanity checks and leads\nto an out-of-bounds read when calculating the address of the NDP\nblock (ntb_ptr + ndp_index).\n\nFix this by changing ndp_index to unsigned int to ensure consistent\nunsigned comparisons throughout the function."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-22T15:32:47.499Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/9c8c6825a750fcd3efbe922847ca70ccd5a66857"
},
{
"url": "https://git.kernel.org/stable/c/a1c0deeba4a46481543d6b09c665f758c54c3a1a"
},
{
"url": "https://git.kernel.org/stable/c/d13f650a3485b58c124b3cda45597e8002c9c833"
},
{
"url": "https://git.kernel.org/stable/c/11413d7ed42174b8f5d8d0b6a25d10dc88239b21"
},
{
"url": "https://git.kernel.org/stable/c/5b2b3a3229a3f4c493ffdee53aee2f173b6f13b3"
},
{
"url": "https://git.kernel.org/stable/c/d328fdc607fa1bb668ad512e1c918a120f78f337"
},
{
"url": "https://git.kernel.org/stable/c/fc9e54e22845c4da29588ca0986cb7c795b5a262"
},
{
"url": "https://git.kernel.org/stable/c/6b1c8a9403a26cb0fed7a648916c74dc236da591"
}
],
"title": "usb: gadget: f_ncm: Use unsigned int for ndp_index",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74679",
"datePublished": "2026-08-22T15:32:47.499Z",
"dateReserved": "2026-08-15T05:44:03.925Z",
"dateUpdated": "2026-08-22T15:32:47.499Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74635 (GCVE-0-2026-74635)
Vulnerability from cvelistv5
Published
2026-08-22 15:32
Modified
2026-08-25 05:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
fbdev: bitblit: bound-check glyph index in bit_cursor()
bit_cursor() fetches the glyph under the cursor with
c = scr_readw(vc_pos);
src = vc_font.data + ((c & charmask) * w * height);
where charmask is 0x1ff when vc_hi_font_mask is set. The screen buffer
value comes directly from scr_readw() and may be larger than the current
font's glyph count.
Syzkaller triggers this via vcs_write(). The Call Trace shows
vcs_write() in vc_screen.c writing an arbitrary 16-bit value with
writev() to /dev/vcsa, which vcs_write_buf() in vc_screen.c stores via
vcs_scr_writew() without checking charcount. The stored value is later
read in bit_cursor() in bitblit.c.
When the font is changed from a font with 512 glyphs to a font with
256 glyphs, the screen buffer can retain characters with the high
bit set from the previous mode, which could also produce the same
out-of-bounds access.
BUG: KASAN: global-out-of-bounds in soft_cursor+0x378/0x6bc drivers/video/fbdev/core/softcursor.c:70
Read of size 16 at addr ffff800086c57970
Call Trace:
soft_cursor+0x378/0x6bc drivers/video/fbdev/core/softcursor.c:70
bit_cursor+0xa90/0x1108 drivers/video/fbdev/core/bitblit.c:365
fbcon_cursor+0x344/0x498 drivers/video/fbdev/core/fbcon.c:1427
hide_cursor+0xdc/0x2d0 drivers/tty/vt/vt.c:883
update_region+0x100/0x18c drivers/tty/vt/vt.c:669
vcs_write+0x8ec/0xaf0 drivers/tty/vt/vc_screen.c:685
bit_putcs_aligned() and bit_putcs_unaligned() already clamp the glyph
index to vc_font.charcount. Apply the same clamp in bit_cursor() after
extracting the attribute and masking, before indexing fontdata.
The fix completes the bounds checking started in commit 18c4ef4e765a
("fbdev: bitblit: bound-check glyph index in bit_putcs*"), which missed
the cursor path.
This change should be safe because the clamp reuses the existing
contract from fbcon: charcount is maintained under console_lock in
con_font_set() and fbcon_font_set(), and hi_font_mask is cleared when
switching from 512 to 256 glyphs. When stale screen data with high bits
remains after a font switch, or when vcs_write() stores an arbitrary
value, clamping the index to 0 prevents the out-of-bounds read without
changing cursor semantics — the same fallback bit_putcs uses.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 0998a6cb232674408a03e8561dc15aa266b2f53b Version: db5c9a162d2f42bcc842b76b3d935dcc050a0eec Version: c12003bf91fdff381c55ef54fef3e961a5af2545 Version: 9ba1a7802ca9a2590cef95b253e6526f4364477f Version: 901f44227072be60812fe8083e83e1533c04eed1 Version: 18c4ef4e765a798b47980555ed665d78b71aeadf Version: 18c4ef4e765a798b47980555ed665d78b71aeadf Version: 18c4ef4e765a798b47980555ed665d78b71aeadf Version: a10cede006f9614b465cf25609a8753efbfd45cc Version: efaf89a75a29b2d179bf4fe63ca62852e93ad620 Version: 5.10.247 ≤ Version: 5.15.197 ≤ Version: 6.1.159 ≤ Version: 6.6.117 ≤ Version: 6.12.58 ≤ Version: 5.4.302 ≤ Version: 6.17.8 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/video/fbdev/core/bitblit.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "250159ace2dc53c1bdad267aa8da51b638748700",
"status": "affected",
"version": "0998a6cb232674408a03e8561dc15aa266b2f53b",
"versionType": "git"
},
{
"lessThan": "46336f476484f36145e5117e72d7b590f47433ee",
"status": "affected",
"version": "db5c9a162d2f42bcc842b76b3d935dcc050a0eec",
"versionType": "git"
},
{
"lessThan": "bf750cfeacf4e47ac72dadc7f05839696efb8576",
"status": "affected",
"version": "c12003bf91fdff381c55ef54fef3e961a5af2545",
"versionType": "git"
},
{
"lessThan": "94134d70abf9273b70499d97d0adc9185ef21091",
"status": "affected",
"version": "9ba1a7802ca9a2590cef95b253e6526f4364477f",
"versionType": "git"
},
{
"lessThan": "c1e7351767dd30fc574395c82121e4c67b882da3",
"status": "affected",
"version": "901f44227072be60812fe8083e83e1533c04eed1",
"versionType": "git"
},
{
"lessThan": "bc9db0d879c655d5dfd8add32fd60f13e65d132c",
"status": "affected",
"version": "18c4ef4e765a798b47980555ed665d78b71aeadf",
"versionType": "git"
},
{
"lessThan": "9ea879862e66e354e616028c31b39aa3eb6d35d8",
"status": "affected",
"version": "18c4ef4e765a798b47980555ed665d78b71aeadf",
"versionType": "git"
},
{
"lessThan": "e033cbf3975a8465f879ebd5989dc35b04423a4d",
"status": "affected",
"version": "18c4ef4e765a798b47980555ed665d78b71aeadf",
"versionType": "git"
},
{
"status": "affected",
"version": "a10cede006f9614b465cf25609a8753efbfd45cc",
"versionType": "git"
},
{
"status": "affected",
"version": "efaf89a75a29b2d179bf4fe63ca62852e93ad620",
"versionType": "git"
},
{
"lessThan": "5.10.265",
"status": "affected",
"version": "5.10.247",
"versionType": "semver"
},
{
"lessThan": "5.15.216",
"status": "affected",
"version": "5.15.197",
"versionType": "semver"
},
{
"lessThan": "6.1.183",
"status": "affected",
"version": "6.1.159",
"versionType": "semver"
},
{
"lessThan": "6.6.152",
"status": "affected",
"version": "6.6.117",
"versionType": "semver"
},
{
"lessThan": "6.12.104",
"status": "affected",
"version": "6.12.58",
"versionType": "semver"
},
{
"lessThan": "5.5",
"status": "affected",
"version": "5.4.302",
"versionType": "semver"
},
{
"lessThan": "6.18",
"status": "affected",
"version": "6.17.8",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/video/fbdev/core/bitblit.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.18"
},
{
"lessThan": "6.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.10.247",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.15.197",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "6.1.159",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "6.6.117",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "6.12.58",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "6.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "6.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.4.302",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.17.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: bitblit: bound-check glyph index in bit_cursor()\n\nbit_cursor() fetches the glyph under the cursor with\n\n\tc = scr_readw(vc_pos);\n\tsrc = vc_font.data + ((c \u0026 charmask) * w * height);\n\nwhere charmask is 0x1ff when vc_hi_font_mask is set. The screen buffer\nvalue comes directly from scr_readw() and may be larger than the current\nfont\u0027s glyph count.\n\nSyzkaller triggers this via vcs_write(). The Call Trace shows\nvcs_write() in vc_screen.c writing an arbitrary 16-bit value with\nwritev() to /dev/vcsa, which vcs_write_buf() in vc_screen.c stores via\nvcs_scr_writew() without checking charcount. The stored value is later\nread in bit_cursor() in bitblit.c.\n\nWhen the font is changed from a font with 512 glyphs to a font with\n256 glyphs, the screen buffer can retain characters with the high\nbit set from the previous mode, which could also produce the same\nout-of-bounds access.\n\n BUG: KASAN: global-out-of-bounds in soft_cursor+0x378/0x6bc drivers/video/fbdev/core/softcursor.c:70\n Read of size 16 at addr ffff800086c57970\n\n Call Trace:\n soft_cursor+0x378/0x6bc drivers/video/fbdev/core/softcursor.c:70\n bit_cursor+0xa90/0x1108 drivers/video/fbdev/core/bitblit.c:365\n fbcon_cursor+0x344/0x498 drivers/video/fbdev/core/fbcon.c:1427\n hide_cursor+0xdc/0x2d0 drivers/tty/vt/vt.c:883\n update_region+0x100/0x18c drivers/tty/vt/vt.c:669\n vcs_write+0x8ec/0xaf0 drivers/tty/vt/vc_screen.c:685\n\nbit_putcs_aligned() and bit_putcs_unaligned() already clamp the glyph\nindex to vc_font.charcount. Apply the same clamp in bit_cursor() after\nextracting the attribute and masking, before indexing fontdata.\n\nThe fix completes the bounds checking started in commit 18c4ef4e765a\n(\"fbdev: bitblit: bound-check glyph index in bit_putcs*\"), which missed\nthe cursor path.\n\nThis change should be safe because the clamp reuses the existing\ncontract from fbcon: charcount is maintained under console_lock in\ncon_font_set() and fbcon_font_set(), and hi_font_mask is cleared when\nswitching from 512 to 256 glyphs. When stale screen data with high bits\nremains after a font switch, or when vcs_write() stores an arbitrary\nvalue, clamping the index to 0 prevents the out-of-bounds read without\nchanging cursor semantics \u2014 the same fallback bit_putcs uses."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires local write() to /dev/vcsa (or ioctl on an owned virtual console) to poison the VT screen buffer; the bug is in fbcon cursor rendering, not in any network-facing protocol handler.\nAC:L - Syzkaller reproduces the fault reliably by writing arbitrary screen-buffer values to /dev/vcsa; the attacker fully controls the glyph index and can repeat the trigger on every console refresh without races or victim-specific timing.\nPR:L - Triggering needs only a local account with write access to /dev/vcsa* (typically membership in the tty group) or a session owning the target console for KDFONTOP/font-switch paths; no CAP_SYS_ADMIN or init-namespace root is required.\nUI:N - Once the attacker has the needed local device access, exploitation is fully self-contained and does not require any additional action from another user or administrator.\nS:U - Impact is confined to kernel framebuffer-console memory within the same kernel security domain; it does not cross VM, container, or IOMMU boundaries to affect a separate authority.\nC:H - An out-of-bounds read past the font glyph table copies adjacent kernel memory (global or heap font data) into cursor buffers and framebuffer blit paths, disclosing more than a few bytes per trigger.\nI:H - The out-of-bounds glyph pointer feeds update_attr() and soft_cursor() memcpy paths that copy attacker-influenced kernel memory into kmalloc cursor buffers and framebuffer state, constituting kernel memory corruption with integrity impact.\nA:H - KASAN reports a kernel BUG on the out-of-bounds read in soft_cursor(), and repeated malicious /dev/vcsa writes force console refresh through hide_cursor(), enabling kernel oops/panic and console denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:40:59.420Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/250159ace2dc53c1bdad267aa8da51b638748700"
},
{
"url": "https://git.kernel.org/stable/c/46336f476484f36145e5117e72d7b590f47433ee"
},
{
"url": "https://git.kernel.org/stable/c/bf750cfeacf4e47ac72dadc7f05839696efb8576"
},
{
"url": "https://git.kernel.org/stable/c/94134d70abf9273b70499d97d0adc9185ef21091"
},
{
"url": "https://git.kernel.org/stable/c/c1e7351767dd30fc574395c82121e4c67b882da3"
},
{
"url": "https://git.kernel.org/stable/c/bc9db0d879c655d5dfd8add32fd60f13e65d132c"
},
{
"url": "https://git.kernel.org/stable/c/9ea879862e66e354e616028c31b39aa3eb6d35d8"
},
{
"url": "https://git.kernel.org/stable/c/e033cbf3975a8465f879ebd5989dc35b04423a4d"
}
],
"title": "fbdev: bitblit: bound-check glyph index in bit_cursor()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74635",
"datePublished": "2026-08-22T15:32:15.280Z",
"dateReserved": "2026-08-15T05:44:03.922Z",
"dateUpdated": "2026-08-25T05:40:59.420Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74623 (GCVE-0-2026-74623)
Vulnerability from cvelistv5
Published
2026-08-22 15:32
Modified
2026-08-23 12:47
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: atlantic: free stranded TX buffers on ring deinit
aq_vec_deinit() drains the TX rings with a single aq_ring_tx_clean()
call, which frees at most AQ_CFG_TX_CLEAN_BUDGET (256) descriptors and
stops at hw_head, which no longer moves once aq_vec_stop() has stopped
the hardware and NAPI. Completed descriptors beyond the budget and
everything still posted in [hw_head, sw_tail) keep their skb or
xdp_frame when the interface goes down: aq_vec_ring_free() then frees
the buffer ring and the references are lost for good.
Today this is a silent memory leak on every interface down under
TX/XDP_TX load. With the conversion of the RX path to page_pool posted
for net-next it becomes much more visible: XDP_TX frames carry fragment
references on the RX ring's page_pool, so a single stranded frame keeps
the pool's inflight count above zero forever. page_pool_destroy() then
never completes, the pool is leaked together with its pages, and
"page_pool_release_retry() stalled pool shutdown" is warned every 60
seconds from that point on, on every ifdown, XDP detach or ring resize
under XDP_TX load.
Bring back aq_ring_tx_deinit() as it was before the removal and use it
for teardown again, with one extension: TX rings can hold xdp_frames
nowadays, so release those too. They are returned with
xdp_return_frame() since this runs in process context.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: eb36bedf28be6d986bdbcfa375bab08ffa45efd8 Version: eb36bedf28be6d986bdbcfa375bab08ffa45efd8 Version: eb36bedf28be6d986bdbcfa375bab08ffa45efd8 Version: eb36bedf28be6d986bdbcfa375bab08ffa45efd8 Version: eb36bedf28be6d986bdbcfa375bab08ffa45efd8 Version: eb36bedf28be6d986bdbcfa375bab08ffa45efd8 Version: eb36bedf28be6d986bdbcfa375bab08ffa45efd8 Version: eb36bedf28be6d986bdbcfa375bab08ffa45efd8 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/aquantia/atlantic/aq_ring.c",
"drivers/net/ethernet/aquantia/atlantic/aq_ring.h",
"drivers/net/ethernet/aquantia/atlantic/aq_vec.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a14ceebd13bf857bfca052bc5a6bd49e737912be",
"status": "affected",
"version": "eb36bedf28be6d986bdbcfa375bab08ffa45efd8",
"versionType": "git"
},
{
"lessThan": "4f1c20873f70b4b22ef86dc38dad1fda8e169bcd",
"status": "affected",
"version": "eb36bedf28be6d986bdbcfa375bab08ffa45efd8",
"versionType": "git"
},
{
"lessThan": "307d80193b4a4a75b8dc4e0d3162be3755abbed7",
"status": "affected",
"version": "eb36bedf28be6d986bdbcfa375bab08ffa45efd8",
"versionType": "git"
},
{
"lessThan": "7a3e1481f4ee6c581bccc6bfc6c970aac5be7b0c",
"status": "affected",
"version": "eb36bedf28be6d986bdbcfa375bab08ffa45efd8",
"versionType": "git"
},
{
"lessThan": "3447641d361dcc5511841d986ad4d849b2900d9b",
"status": "affected",
"version": "eb36bedf28be6d986bdbcfa375bab08ffa45efd8",
"versionType": "git"
},
{
"lessThan": "b13202d401e1a20fec89b0cda733dcbaf279f79d",
"status": "affected",
"version": "eb36bedf28be6d986bdbcfa375bab08ffa45efd8",
"versionType": "git"
},
{
"lessThan": "dd633280de7fdfd60dc4fcf63d04e2ad95b43269",
"status": "affected",
"version": "eb36bedf28be6d986bdbcfa375bab08ffa45efd8",
"versionType": "git"
},
{
"lessThan": "452636ea5410a96e02ebaaf80b21e3620b98e0dd",
"status": "affected",
"version": "eb36bedf28be6d986bdbcfa375bab08ffa45efd8",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/aquantia/atlantic/aq_ring.c",
"drivers/net/ethernet/aquantia/atlantic/aq_ring.h",
"drivers/net/ethernet/aquantia/atlantic/aq_vec.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.11"
},
{
"lessThan": "4.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: atlantic: free stranded TX buffers on ring deinit\n\naq_vec_deinit() drains the TX rings with a single aq_ring_tx_clean()\ncall, which frees at most AQ_CFG_TX_CLEAN_BUDGET (256) descriptors and\nstops at hw_head, which no longer moves once aq_vec_stop() has stopped\nthe hardware and NAPI. Completed descriptors beyond the budget and\neverything still posted in [hw_head, sw_tail) keep their skb or\nxdp_frame when the interface goes down: aq_vec_ring_free() then frees\nthe buffer ring and the references are lost for good.\n\nToday this is a silent memory leak on every interface down under\nTX/XDP_TX load. With the conversion of the RX path to page_pool posted\nfor net-next it becomes much more visible: XDP_TX frames carry fragment\nreferences on the RX ring\u0027s page_pool, so a single stranded frame keeps\nthe pool\u0027s inflight count above zero forever. page_pool_destroy() then\nnever completes, the pool is leaked together with its pages, and\n\"page_pool_release_retry() stalled pool shutdown\" is warned every 60\nseconds from that point on, on every ifdown, XDP detach or ring resize\nunder XDP_TX load.\n\nBring back aq_ring_tx_deinit() as it was before the removal and use it\nfor teardown again, with one extension: TX rings can hold xdp_frames\nnowadays, so release those too. They are returned with\nxdp_return_frame() since this runs in process context."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:47:48.573Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a14ceebd13bf857bfca052bc5a6bd49e737912be"
},
{
"url": "https://git.kernel.org/stable/c/4f1c20873f70b4b22ef86dc38dad1fda8e169bcd"
},
{
"url": "https://git.kernel.org/stable/c/307d80193b4a4a75b8dc4e0d3162be3755abbed7"
},
{
"url": "https://git.kernel.org/stable/c/7a3e1481f4ee6c581bccc6bfc6c970aac5be7b0c"
},
{
"url": "https://git.kernel.org/stable/c/3447641d361dcc5511841d986ad4d849b2900d9b"
},
{
"url": "https://git.kernel.org/stable/c/b13202d401e1a20fec89b0cda733dcbaf279f79d"
},
{
"url": "https://git.kernel.org/stable/c/dd633280de7fdfd60dc4fcf63d04e2ad95b43269"
},
{
"url": "https://git.kernel.org/stable/c/452636ea5410a96e02ebaaf80b21e3620b98e0dd"
}
],
"title": "net: atlantic: free stranded TX buffers on ring deinit",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74623",
"datePublished": "2026-08-22T15:32:06.467Z",
"dateReserved": "2026-08-15T05:44:03.921Z",
"dateUpdated": "2026-08-23T12:47:48.573Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74636 (GCVE-0-2026-74636)
Vulnerability from cvelistv5
Published
2026-08-22 15:32
Modified
2026-08-22 15:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
tracing: Fix race between update_event_fields and, event_define_fields
The following sequence may leads race between event_define_fields()
and update_event_fields():
CPU0 (loads module A) CPU1 (loads module B)
=============================== ===============================
load_module(A) load_module(B)
notifier_call_chain notifier_call_chain
trace_module_notify trace_module_notify
mutex_lock(&event_mutex) trace_event_update_all()
trace_module_add_events(A) down_write(&trace_event_sem)
__register_event(call_A)
__add_event_to_tracers(call_A)
event_define_fields(call_A)
for each f: list_for_each_entry(field,
list_add(&f->link, &class->fields, link)
&class->fields) field = class->fields->next;
Where access to the class->fields is not protected by the event_mutex in
trace_event_update_all().
This produces the following panic:
Unable to handle kernel access ... at virtual address 0000000000000018
pc : update_event_fields+0xf8/0x368
Call trace:
update_event_fields+0xf8/0x368
trace_event_update_all+0x7c/0x2b4
trace_module_notify+0x4c/0x1dc
notifier_call_chain+0x84/0x168
blocking_notifier_call_chain_robust+0x64/0xd4
load_module+0x10c8/0x123c
__arm64_sys_finit_module+0x230/0x31c
Fix by taking event_mutex in trace_event_update_all() before
trace_event_sem.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 7c6bd60999f32138e3b73fd97ea11ef47a94de25 Version: b3bc8547d3be60898818885f5bf22d0a62e2eb48 Version: b3bc8547d3be60898818885f5bf22d0a62e2eb48 Version: b3bc8547d3be60898818885f5bf22d0a62e2eb48 Version: b3bc8547d3be60898818885f5bf22d0a62e2eb48 Version: b3bc8547d3be60898818885f5bf22d0a62e2eb48 Version: b3bc8547d3be60898818885f5bf22d0a62e2eb48 Version: 55defdf935fab9f2989a197aae1042c082d9a343 Version: 0c53a5c80e6e286733381a1d9f255ba4039e2e45 Version: 5.15.33 ≤ Version: 5.16.19 ≤ Version: 5.17.2 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"kernel/trace/trace_events.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "4e39f7b4d9d36508c53e89e6cbc640728df870b5",
"status": "affected",
"version": "7c6bd60999f32138e3b73fd97ea11ef47a94de25",
"versionType": "git"
},
{
"lessThan": "a30d421468300b1e7b2f233136aeb2db8013f555",
"status": "affected",
"version": "b3bc8547d3be60898818885f5bf22d0a62e2eb48",
"versionType": "git"
},
{
"lessThan": "e5f1d301b4bdaa4206db251fdc691f623162b0a8",
"status": "affected",
"version": "b3bc8547d3be60898818885f5bf22d0a62e2eb48",
"versionType": "git"
},
{
"lessThan": "fdeb190b0905a6aaed1e5d6adfb8613214748d7d",
"status": "affected",
"version": "b3bc8547d3be60898818885f5bf22d0a62e2eb48",
"versionType": "git"
},
{
"lessThan": "ed49684e69f846bf50b5050651ccdb87cfd152c0",
"status": "affected",
"version": "b3bc8547d3be60898818885f5bf22d0a62e2eb48",
"versionType": "git"
},
{
"lessThan": "f128740f39ab28d1f4ad5bdd10f3e117eec0c374",
"status": "affected",
"version": "b3bc8547d3be60898818885f5bf22d0a62e2eb48",
"versionType": "git"
},
{
"lessThan": "c3730b8373bb5059d735509b9e6a00d7eb337d7c",
"status": "affected",
"version": "b3bc8547d3be60898818885f5bf22d0a62e2eb48",
"versionType": "git"
},
{
"status": "affected",
"version": "55defdf935fab9f2989a197aae1042c082d9a343",
"versionType": "git"
},
{
"status": "affected",
"version": "0c53a5c80e6e286733381a1d9f255ba4039e2e45",
"versionType": "git"
},
{
"lessThan": "5.15.216",
"status": "affected",
"version": "5.15.33",
"versionType": "semver"
},
{
"lessThan": "5.17",
"status": "affected",
"version": "5.16.19",
"versionType": "semver"
},
{
"lessThan": "5.18",
"status": "affected",
"version": "5.17.2",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"kernel/trace/trace_events.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.18"
},
{
"lessThan": "5.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.15.33",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.16.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.17.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Fix race between update_event_fields and, event_define_fields\n\nThe following sequence may leads race between event_define_fields()\nand update_event_fields():\n\n CPU0 (loads module A) CPU1 (loads module B)\n =============================== ===============================\n load_module(A) load_module(B)\n notifier_call_chain notifier_call_chain\n trace_module_notify trace_module_notify\n mutex_lock(\u0026event_mutex) trace_event_update_all()\n trace_module_add_events(A) down_write(\u0026trace_event_sem)\n __register_event(call_A)\n __add_event_to_tracers(call_A)\n event_define_fields(call_A)\n for each f: list_for_each_entry(field,\n list_add(\u0026f-\u003elink, \u0026class-\u003efields, link)\n \u0026class-\u003efields) field = class-\u003efields-\u003enext;\n\nWhere access to the class-\u003efields is not protected by the event_mutex in\ntrace_event_update_all().\n\nThis produces the following panic:\n Unable to handle kernel access ... at virtual address 0000000000000018\n pc : update_event_fields+0xf8/0x368\n Call trace:\n update_event_fields+0xf8/0x368\n trace_event_update_all+0x7c/0x2b4\n trace_module_notify+0x4c/0x1dc\n notifier_call_chain+0x84/0x168\n blocking_notifier_call_chain_robust+0x64/0xd4\n load_module+0x10c8/0x123c\n __arm64_sys_finit_module+0x230/0x31c\n\nFix by taking event_mutex in trace_event_update_all() before\ntrace_event_sem."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-22T15:32:16.026Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/4e39f7b4d9d36508c53e89e6cbc640728df870b5"
},
{
"url": "https://git.kernel.org/stable/c/a30d421468300b1e7b2f233136aeb2db8013f555"
},
{
"url": "https://git.kernel.org/stable/c/e5f1d301b4bdaa4206db251fdc691f623162b0a8"
},
{
"url": "https://git.kernel.org/stable/c/fdeb190b0905a6aaed1e5d6adfb8613214748d7d"
},
{
"url": "https://git.kernel.org/stable/c/ed49684e69f846bf50b5050651ccdb87cfd152c0"
},
{
"url": "https://git.kernel.org/stable/c/f128740f39ab28d1f4ad5bdd10f3e117eec0c374"
},
{
"url": "https://git.kernel.org/stable/c/c3730b8373bb5059d735509b9e6a00d7eb337d7c"
}
],
"title": "tracing: Fix race between update_event_fields and, event_define_fields",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74636",
"datePublished": "2026-08-22T15:32:16.026Z",
"dateReserved": "2026-08-15T05:44:03.922Z",
"dateUpdated": "2026-08-22T15:32:16.026Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80842 (GCVE-0-2026-80842)
Vulnerability from cvelistv5
Published
2026-09-04 15:54
Modified
2026-09-04 15:54
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: bridge: mcast: fix use-after-free of a master VLAN's multicast context
br_multicast_toggle_one_vlan() clears BR_VLFLAG_MCAST_ENABLED under
br->multicast_lock before stopping a VLAN's multicast context. That is
the teardown handshake: lockless readers gate on the flag through
br_multicast_ctx_should_use() -> br_multicast_ctx_vlan_disabled(), so
once it is cleared under the lock no reader can arm the context again.
For a master VLAN the handshake never runs. __vlan_del() clears
BRIDGE_VLAN_INFO_BRENTRY before calling br_vlan_put_master(), so
br_multicast_toggle_one_vlan(masterv, false) returns early on
!br_vlan_is_brentry(vlan): the flag stays set and br->multicast_lock is
never taken. br_vlan_put_master() then drains the context in
br_multicast_ctx_deinit() and frees the VLAN through call_rcu(), while a
reader still inside rcu_read_lock() sees the context as enabled and
re-arms it. The port and port-VLAN branch of the function has no
br_vlan_is_brentry() test and flips the flag under br->multicast_lock,
so it is not affected.
The reader is the bridge transmit path. For a master VLAN
br_multicast_rcv() selects brmctx = &vlan->br_mcast_ctx with
pmctx = NULL, so IGMP sent to the bridge device re-arms the context's
timers after br_multicast_ctx_deinit() has already stopped them.
BUG: KASAN: slab-use-after-free in detach_if_pending+0x412/0x4a0
Write of size 8 at addr ffff88810ac39918 by task brmc/601
__mod_timer+0x51a/0xc50
br_multicast_host_join+0x25b/0x390
__br_multicast_add_group+0x468/0x530
br_ip4_multicast_add_group+0x1a0/0x260
br_multicast_rcv+0x2cda/0x61e0
br_dev_xmit+0x6c4/0x1540
Allocated by task 610:
br_vlan_add+0x111/0xb40
br_vlan_info+0x370/0x3e0
Freed by task 0:
kfree+0x1a7/0x4f0
rcu_core+0x7dc/0x10a0
Only test br_vlan_is_brentry() when enabling, like the
br_multicast_ctx_vlan_global_disabled() test next to it. Disabling then
always clears BR_VLFLAG_MCAST_ENABLED under br->multicast_lock before
br_multicast_ctx_deinit() drains the context.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 7b54aaaf53cb784411426c64482af0435f7c845e Version: 7b54aaaf53cb784411426c64482af0435f7c845e Version: 7b54aaaf53cb784411426c64482af0435f7c845e Version: 7b54aaaf53cb784411426c64482af0435f7c845e Version: 7b54aaaf53cb784411426c64482af0435f7c845e Version: 7b54aaaf53cb784411426c64482af0435f7c845e Version: 7b54aaaf53cb784411426c64482af0435f7c845e Version: 7b54aaaf53cb784411426c64482af0435f7c845e |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/bridge/br_multicast.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "3afaaee2f972aec9059110953adb62fa3cf5c4bd",
"status": "affected",
"version": "7b54aaaf53cb784411426c64482af0435f7c845e",
"versionType": "git"
},
{
"lessThan": "22226a2c3b90f15b0925f1464470d3baa6c5677e",
"status": "affected",
"version": "7b54aaaf53cb784411426c64482af0435f7c845e",
"versionType": "git"
},
{
"lessThan": "7c54fd8cfbcf371a5ef50db5c53fe6e85fb76686",
"status": "affected",
"version": "7b54aaaf53cb784411426c64482af0435f7c845e",
"versionType": "git"
},
{
"lessThan": "3a0ad4fcdfa0b7dba1876de14a12cb65c8b5ca50",
"status": "affected",
"version": "7b54aaaf53cb784411426c64482af0435f7c845e",
"versionType": "git"
},
{
"lessThan": "c069f29da72324697aa4b7cab5b3647a7d24a575",
"status": "affected",
"version": "7b54aaaf53cb784411426c64482af0435f7c845e",
"versionType": "git"
},
{
"lessThan": "3f4752996735e0628af559aa8da1d872c2fac13b",
"status": "affected",
"version": "7b54aaaf53cb784411426c64482af0435f7c845e",
"versionType": "git"
},
{
"lessThan": "57f94d3f4dee8b54d63cefddf1112be4656ef9e6",
"status": "affected",
"version": "7b54aaaf53cb784411426c64482af0435f7c845e",
"versionType": "git"
},
{
"lessThan": "50e5c6605cc9c2dd57bd2d1b3459674d19738983",
"status": "affected",
"version": "7b54aaaf53cb784411426c64482af0435f7c845e",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/bridge/br_multicast.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.15"
},
{
"lessThan": "5.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.220",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.187",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.156",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.108",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.49",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.13",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.3",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.220",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.187",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.156",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.108",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.49",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.13",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.3",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "5.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: bridge: mcast: fix use-after-free of a master VLAN\u0027s multicast context\n\nbr_multicast_toggle_one_vlan() clears BR_VLFLAG_MCAST_ENABLED under\nbr-\u003emulticast_lock before stopping a VLAN\u0027s multicast context. That is\nthe teardown handshake: lockless readers gate on the flag through\nbr_multicast_ctx_should_use() -\u003e br_multicast_ctx_vlan_disabled(), so\nonce it is cleared under the lock no reader can arm the context again.\n\nFor a master VLAN the handshake never runs. __vlan_del() clears\nBRIDGE_VLAN_INFO_BRENTRY before calling br_vlan_put_master(), so\nbr_multicast_toggle_one_vlan(masterv, false) returns early on\n!br_vlan_is_brentry(vlan): the flag stays set and br-\u003emulticast_lock is\nnever taken. br_vlan_put_master() then drains the context in\nbr_multicast_ctx_deinit() and frees the VLAN through call_rcu(), while a\nreader still inside rcu_read_lock() sees the context as enabled and\nre-arms it. The port and port-VLAN branch of the function has no\nbr_vlan_is_brentry() test and flips the flag under br-\u003emulticast_lock,\nso it is not affected.\n\nThe reader is the bridge transmit path. For a master VLAN\nbr_multicast_rcv() selects brmctx = \u0026vlan-\u003ebr_mcast_ctx with\npmctx = NULL, so IGMP sent to the bridge device re-arms the context\u0027s\ntimers after br_multicast_ctx_deinit() has already stopped them.\n\n BUG: KASAN: slab-use-after-free in detach_if_pending+0x412/0x4a0\n Write of size 8 at addr ffff88810ac39918 by task brmc/601\n __mod_timer+0x51a/0xc50\n br_multicast_host_join+0x25b/0x390\n __br_multicast_add_group+0x468/0x530\n br_ip4_multicast_add_group+0x1a0/0x260\n br_multicast_rcv+0x2cda/0x61e0\n br_dev_xmit+0x6c4/0x1540\n Allocated by task 610:\n br_vlan_add+0x111/0xb40\n br_vlan_info+0x370/0x3e0\n Freed by task 0:\n kfree+0x1a7/0x4f0\n rcu_core+0x7dc/0x10a0\n\nOnly test br_vlan_is_brentry() when enabling, like the\nbr_multicast_ctx_vlan_global_disabled() test next to it. Disabling then\nalways clears BR_VLFLAG_MCAST_ENABLED under br-\u003emulticast_lock before\nbr_multicast_ctx_deinit() drains the context."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T15:54:52.459Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/3afaaee2f972aec9059110953adb62fa3cf5c4bd"
},
{
"url": "https://git.kernel.org/stable/c/22226a2c3b90f15b0925f1464470d3baa6c5677e"
},
{
"url": "https://git.kernel.org/stable/c/7c54fd8cfbcf371a5ef50db5c53fe6e85fb76686"
},
{
"url": "https://git.kernel.org/stable/c/3a0ad4fcdfa0b7dba1876de14a12cb65c8b5ca50"
},
{
"url": "https://git.kernel.org/stable/c/c069f29da72324697aa4b7cab5b3647a7d24a575"
},
{
"url": "https://git.kernel.org/stable/c/3f4752996735e0628af559aa8da1d872c2fac13b"
},
{
"url": "https://git.kernel.org/stable/c/57f94d3f4dee8b54d63cefddf1112be4656ef9e6"
},
{
"url": "https://git.kernel.org/stable/c/50e5c6605cc9c2dd57bd2d1b3459674d19738983"
}
],
"title": "net: bridge: mcast: fix use-after-free of a master VLAN\u0027s multicast context",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80842",
"datePublished": "2026-09-04T15:54:52.459Z",
"dateReserved": "2026-08-26T14:34:25.796Z",
"dateUpdated": "2026-09-04T15:54:52.459Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68198 (GCVE-0-2026-68198)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: ath6kl: fix use-after-free in aggr_reset_state()
The aggr_reset_state() function uses timer_delete() (non-synchronous)
for the aggregation timer before proceeding to delete TID state and
before the structure is freed by callers like aggr_module_destroy().
If the timer callback (aggr_timeout) is executing when aggr_reset_state()
is called, the callback will continue to access aggr_conn fields like
rx_tid[] and stat[] which may be freed immediately after by
kfree(aggr_info->aggr_conn) in aggr_module_destroy().
Additionally, the timer callback can re-arm itself via mod_timer() while
aggr_reset_state() is running, creating a more complex race condition.
Use timer_delete_sync() instead to ensure any running timer callback
has completed before returning.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/ath/ath6kl/txrx.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a1bac650b2d6b1baab1f3e78e2e007a6e2948dde",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "2132a6db05846dd2318857d00e0c1291f9e41b29",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "17ff29cd8dbc977c97788a5f7c011ec807b58242",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "64af6534a085f49d6ed33338a19ab9cf0d0523c9",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "b5d618fd61b9069b4c0a6b487022dd3117ad5acc",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "18965470d41e69d3fc10eb62afae29d10f4cdfd1",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "a3313111b5d9046af60b370c93eec105b27380c1",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "ba7debb4dd6427386862220e8335a53a4bfc235d",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/ath/ath6kl/txrx.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.2"
},
{
"lessThan": "3.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath6kl: fix use-after-free in aggr_reset_state()\n\nThe aggr_reset_state() function uses timer_delete() (non-synchronous)\nfor the aggregation timer before proceeding to delete TID state and\nbefore the structure is freed by callers like aggr_module_destroy().\n\nIf the timer callback (aggr_timeout) is executing when aggr_reset_state()\nis called, the callback will continue to access aggr_conn fields like\nrx_tid[] and stat[] which may be freed immediately after by\nkfree(aggr_info-\u003eaggr_conn) in aggr_module_destroy().\n\nAdditionally, the timer callback can re-arm itself via mod_timer() while\naggr_reset_state() is running, creating a more complex race condition.\n\nUse timer_delete_sync() instead to ensure any running timer callback\nhas completed before returning."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - ath6kl is a WiFi driver; the race is driven by 802.11 frames from an adjacent attacker \u2014 a gapped A-MPDU sequence arms the reorder timer and a deauth/disassoc or connect/disconnect event drives aggr_reset_state() via ath6kl_disconnect_event()/ath6kl_connect_event()/ath6kl_sta_cleanup(). This requires radio proximity, not routable network access.\nAC:L - The attacker controls both sides of the race: transmitting out-of-order aggregated frames arms aggr_conn-\u003etimer, and a deauth/disassoc or reconnect immediately invokes aggr_reset_state(), which frees rx_tid[].hold_q and (via aggr_module_destroy) aggr_conn itself while aggr_timeout() may be running or re-arming via mod_timer(). The sequence can be repeated indefinitely until the window is hit.\nPR:N - No privileges or account on the target system are required; a rogue AP the client associates with, or an attacker injecting unprotected deauth/disassoc frames at a station with an active block-ack session, is sufficient. In AP mode, a station joining an open network can trigger the same path on disconnect.\nUI:N - The station already associated and receiving aggregated traffic is enough; deauth/disassoc handling and the resulting aggr_reset_state() run automatically in the driver with no action by the device owner.\nS:U - The use-after-free is on kernel heap memory owned by the ath6kl driver and stays within the kernel\u0027s own security authority; no hypervisor, IOMMU, or sandbox boundary is crossed.\nC:H - The freed aggr_info_conn and hold_q allocations can be reclaimed and refilled with attacker-influenced data (e.g. sk_buff payloads from injected frames), so the concurrent callback reading rx_tid[]/stat[]/hold_q[] yields a controllable read primitive that can leak kernel memory contents.\nI:H - aggr_timeout() writes through the freed object \u2014 setting timer_scheduled, rxtid-\u003etimer_mon, dequeuing skbs from hold_q[] and calling mod_timer() on a freed timer_list \u2014 giving arbitrary writes into reclaimed heap objects and list corruption that is a classic path to control-flow hijack.\nA:H - Even without successful heap grooming, the use-after-free and the double-free/dangling-skb access in aggr_deque_frms() reliably produce slab corruption and a kernel oops or panic, and the attacker can repeat the trigger at will."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:06.548Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a1bac650b2d6b1baab1f3e78e2e007a6e2948dde"
},
{
"url": "https://git.kernel.org/stable/c/2132a6db05846dd2318857d00e0c1291f9e41b29"
},
{
"url": "https://git.kernel.org/stable/c/17ff29cd8dbc977c97788a5f7c011ec807b58242"
},
{
"url": "https://git.kernel.org/stable/c/64af6534a085f49d6ed33338a19ab9cf0d0523c9"
},
{
"url": "https://git.kernel.org/stable/c/b5d618fd61b9069b4c0a6b487022dd3117ad5acc"
},
{
"url": "https://git.kernel.org/stable/c/18965470d41e69d3fc10eb62afae29d10f4cdfd1"
},
{
"url": "https://git.kernel.org/stable/c/a3313111b5d9046af60b370c93eec105b27380c1"
},
{
"url": "https://git.kernel.org/stable/c/ba7debb4dd6427386862220e8335a53a4bfc235d"
}
],
"title": "wifi: ath6kl: fix use-after-free in aggr_reset_state()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68198",
"datePublished": "2026-08-10T12:00:16.718Z",
"dateReserved": "2026-07-30T09:28:09.374Z",
"dateUpdated": "2026-08-23T12:46:06.548Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68199 (GCVE-0-2026-68199)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: ath6kl: fix OOB access from firmware ADDBA window size
aggr_recv_addba_req_evt() logs a debug message when the firmware-supplied
win_sz is outside [AGGR_WIN_SZ_MIN, AGGR_WIN_SZ_MAX] but does not
return. The out-of-range win_sz is then used in TID_WINDOW_SZ() to
compute a kzalloc size and stored in rxtid->hold_q_sz, leading to
zero-size or overflowed allocations and subsequent out-of-bounds access.
Clean up any previously active aggregation session for the TID first,
then return early when win_sz is out of the valid range, instead of
proceeding with a broken allocation size.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/ath/ath6kl/txrx.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c8e3ca7954d8233fbc54bd370c1827670f43c538",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "f480d9910fcfe326db3a6281df80e83af347193e",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "67bc9af4f41f2bdba20404fbd753b2a1bd6dd352",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "d4558c140782180e2c80a7588a4af9f8675adfc4",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "5a65fd4722416061698b0a3277222381efbc4882",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "58c6c8dc2e022e1b4f3dc58725a1ca49ff470f9c",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "cec0a487cf38ac1f9bca240ffe8a94c5014b72f2",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "44126b6994eeb28f2103b638e698f40a1244f327",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/ath/ath6kl/txrx.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.2"
},
{
"lessThan": "3.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath6kl: fix OOB access from firmware ADDBA window size\n\naggr_recv_addba_req_evt() logs a debug message when the firmware-supplied\nwin_sz is outside [AGGR_WIN_SZ_MIN, AGGR_WIN_SZ_MAX] but does not\nreturn. The out-of-range win_sz is then used in TID_WINDOW_SZ() to\ncompute a kzalloc size and stored in rxtid-\u003ehold_q_sz, leading to\nzero-size or overflowed allocations and subsequent out-of-bounds access.\n\nClean up any previously active aggregation session for the TID first,\nthen return early when win_sz is out of the valid range, instead of\nproceeding with a broken allocation size."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - Exploitation requires a malicious WiFi peer (rogue AP or associated client) to trigger ADDBA handling; firmware passes WMI_ADDBA_REQ_EVENTID over the radio link to the ath6kl driver, placing the attacker on the same wireless segment rather than a remote IP network path.\nAC:L - An adjacent attacker can reliably send crafted 802.11 ADDBA requests with out-of-range buffer/window sizes to firmware, which forwards the invalid win_sz to the host; no special memory layout, race, or rare timing is required beyond normal WiFi association.\nPR:N - No local Linux privileges are needed; any associated WiFi peer can induce the malformed ADDBA event. The bug is not reachable via user namespaces or unprivileged local syscalls without controlling the WiFi link/firmware messages.\nUI:N - Once the victim device is associated to WiFi (common on phones, embedded, and IoT), the attacker can send ADDBA and follow-up data frames without any additional victim action beyond routine wireless connectivity.\nS:U - Heap corruption and kernel privilege escalation occur within the same kernel security domain; this is not a VM escape, IOMMU bypass, or cross-authority sandbox breakout.\nC:H - Out-of-bounds access to hold_q allows reading/writing adjacent kernel heap memory (e.g., skb pointers and metadata); OOB kernel heap access is treated as arbitrary memory disclosure potential per kernel CVSS guidance.\nI:H - OOB writes to hold_q entries (struct sk_buff pointers, is_amsdu, seq_no) corrupt kernel heap state and can be leveraged for control-flow hijacking and local privilege escalation, not merely a bounded modification.\nA:H - Invalid win_sz can yield zero-size allocations and hold_q_sz=0 (divide-by-zero in AGGR_WIN_IDX) or inconsistent buffers, causing kernel oops/panic or persistent disruption when aggregation receives subsequent frames."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:18.842Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c8e3ca7954d8233fbc54bd370c1827670f43c538"
},
{
"url": "https://git.kernel.org/stable/c/f480d9910fcfe326db3a6281df80e83af347193e"
},
{
"url": "https://git.kernel.org/stable/c/67bc9af4f41f2bdba20404fbd753b2a1bd6dd352"
},
{
"url": "https://git.kernel.org/stable/c/d4558c140782180e2c80a7588a4af9f8675adfc4"
},
{
"url": "https://git.kernel.org/stable/c/5a65fd4722416061698b0a3277222381efbc4882"
},
{
"url": "https://git.kernel.org/stable/c/58c6c8dc2e022e1b4f3dc58725a1ca49ff470f9c"
},
{
"url": "https://git.kernel.org/stable/c/cec0a487cf38ac1f9bca240ffe8a94c5014b72f2"
},
{
"url": "https://git.kernel.org/stable/c/44126b6994eeb28f2103b638e698f40a1244f327"
}
],
"title": "wifi: ath6kl: fix OOB access from firmware ADDBA window size",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68199",
"datePublished": "2026-08-10T12:00:18.278Z",
"dateReserved": "2026-07-30T09:28:09.374Z",
"dateUpdated": "2026-08-19T16:31:18.842Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74597 (GCVE-0-2026-74597)
Vulnerability from cvelistv5
Published
2026-08-22 15:31
Modified
2026-08-25 05:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ip6_tunnel: clear skb2->cb[] in ip6ip6_err()
ip6ip6_err() clones an outer IPv6 ICMP error skb, pulls it to the
quoted inner IPv6 packet, and then passes the clone to icmpv6_send().
The clone still carries the outer packet's inet6_skb_parm in skb->cb.
If the outer packet had a Home Address Option, IP6CB(skb2)->dsthao
remains non-zero after skb_pull(). icmpv6_send() later calls
mip6_addr_swap(), which uses that stale dsthao offset against the quoted
inner packet. A malformed inner destination-options header can then make
the HAO lookup and address swap run past the end of the quoted packet
and corrupt skb_shared_info.
Clear skb2->cb[] before pulling the quoted inner IPv6 packet so the
reply path does not reuse metadata left by the outer IPv6 stack.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: e490d1d85cf5e191791979e5f260d32eb4f703a8 Version: e490d1d85cf5e191791979e5f260d32eb4f703a8 Version: e490d1d85cf5e191791979e5f260d32eb4f703a8 Version: e490d1d85cf5e191791979e5f260d32eb4f703a8 Version: e490d1d85cf5e191791979e5f260d32eb4f703a8 Version: e490d1d85cf5e191791979e5f260d32eb4f703a8 Version: e490d1d85cf5e191791979e5f260d32eb4f703a8 Version: e490d1d85cf5e191791979e5f260d32eb4f703a8 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ipv6/ip6_tunnel.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "44fe898df302e91c5ee5acbc71ffa74e78e6c183",
"status": "affected",
"version": "e490d1d85cf5e191791979e5f260d32eb4f703a8",
"versionType": "git"
},
{
"lessThan": "0dadb0620ab65949a8bc2439dd28ea3c942fe87d",
"status": "affected",
"version": "e490d1d85cf5e191791979e5f260d32eb4f703a8",
"versionType": "git"
},
{
"lessThan": "b6816536a2990c0db44a26130a03e40b441e829b",
"status": "affected",
"version": "e490d1d85cf5e191791979e5f260d32eb4f703a8",
"versionType": "git"
},
{
"lessThan": "64e41736a26f37ab6215bc2e6df125df05aceb08",
"status": "affected",
"version": "e490d1d85cf5e191791979e5f260d32eb4f703a8",
"versionType": "git"
},
{
"lessThan": "484134e1eb07d700a73b1e4bbf3fb503e299be60",
"status": "affected",
"version": "e490d1d85cf5e191791979e5f260d32eb4f703a8",
"versionType": "git"
},
{
"lessThan": "4eb15c465337b18f44716c499cd6ad63eee0ad54",
"status": "affected",
"version": "e490d1d85cf5e191791979e5f260d32eb4f703a8",
"versionType": "git"
},
{
"lessThan": "fbf40faa0414b753212494ad197542002e66ed9e",
"status": "affected",
"version": "e490d1d85cf5e191791979e5f260d32eb4f703a8",
"versionType": "git"
},
{
"lessThan": "f803c086399da277b5d0ff36a107d0f162751800",
"status": "affected",
"version": "e490d1d85cf5e191791979e5f260d32eb4f703a8",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ipv6/ip6_tunnel.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.22"
},
{
"lessThan": "2.6.22",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.22",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.22",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.22",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "2.6.22",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "2.6.22",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "2.6.22",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "2.6.22",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.22",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nip6_tunnel: clear skb2-\u003ecb[] in ip6ip6_err()\n\nip6ip6_err() clones an outer IPv6 ICMP error skb, pulls it to the\nquoted inner IPv6 packet, and then passes the clone to icmpv6_send().\nThe clone still carries the outer packet\u0027s inet6_skb_parm in skb-\u003ecb.\n\nIf the outer packet had a Home Address Option, IP6CB(skb2)-\u003edsthao\nremains non-zero after skb_pull(). icmpv6_send() later calls\nmip6_addr_swap(), which uses that stale dsthao offset against the quoted\ninner packet. A malformed inner destination-options header can then make\nthe HAO lookup and address swap run past the end of the quoted packet\nand corrupt skb_shared_info.\n\nClear skb2-\u003ecb[] before pulling the quoted inner IPv6 packet so the\nreply path does not reuse metadata left by the outer IPv6 stack."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug is reached when a remote peer sends a forged ICMPv6 error whose quoted payload is an IPv6-in-IPv6 tunnel datagram; processing follows the normal IPv6 receive path (ipv6_rcv -\u003e icmpv6_notify -\u003e tunnel6_err -\u003e ip6ip6_err) with no local access required.\nAC:L - The attacker controls the carrier IPv6 Home Address Option, quoted tunnel/inner headers, and ICMP error type; once an ip6tnl endpoint exists (normal for this subsystem), triggering the stale-dsthao path is reliable and needs no races or victim interaction.\nPR:N - No authentication or capabilities are required on the target; unprivileged remote senders can deliver crafted ICMPv6 errors that the kernel processes on the standard pre-auth receive path (INET6_PROTO_NOPOLICY).\nUI:N - Exploitation requires only delivering a malicious network packet; no victim must open files, click links, or perform any other action.\nS:U - Impact is in-kernel memory corruption on the receiving host within the same security authority; it does not by itself cross VM, container, or IOMMU boundaries.\nC:H - With CONFIG_IPV6_MIP6, mip6_addr_swap() uses the stale dsthao offset to scan the quoted inner packet and can read attacker-controlled bytes past the skb tail while resolving a fake HAO TLV before swapping addresses.\nI:H - The resulting 16-byte swap(iph-\u003esaddr, hao-\u003eaddr) can write beyond the quoted packet into skb_shared_info, giving attacker-influenced heap corruption suitable for further control-flow or data manipulation.\nA:H - Corrupting skb_shared_info from the network input path can cause kernel oops/panic or otherwise deny service on IPv6 tunnel endpoints, and the condition is repeatable with crafted packets."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:40:23.709Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/44fe898df302e91c5ee5acbc71ffa74e78e6c183"
},
{
"url": "https://git.kernel.org/stable/c/0dadb0620ab65949a8bc2439dd28ea3c942fe87d"
},
{
"url": "https://git.kernel.org/stable/c/b6816536a2990c0db44a26130a03e40b441e829b"
},
{
"url": "https://git.kernel.org/stable/c/64e41736a26f37ab6215bc2e6df125df05aceb08"
},
{
"url": "https://git.kernel.org/stable/c/484134e1eb07d700a73b1e4bbf3fb503e299be60"
},
{
"url": "https://git.kernel.org/stable/c/4eb15c465337b18f44716c499cd6ad63eee0ad54"
},
{
"url": "https://git.kernel.org/stable/c/fbf40faa0414b753212494ad197542002e66ed9e"
},
{
"url": "https://git.kernel.org/stable/c/f803c086399da277b5d0ff36a107d0f162751800"
}
],
"title": "ip6_tunnel: clear skb2-\u003ecb[] in ip6ip6_err()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74597",
"datePublished": "2026-08-22T15:31:47.120Z",
"dateReserved": "2026-08-15T05:44:03.919Z",
"dateUpdated": "2026-08-25T05:40:23.709Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80589 (GCVE-0-2026-80589)
Vulnerability from cvelistv5
Published
2026-08-26 14:37
Modified
2026-08-27 05:02
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
block: stop the timeout timer when releasing a never added disk
disk_release() undoes blk_mq_init_allocated_queue() for a disk whose
probe failed before add_disk(), but it only calls blk_mq_exit_queue().
Nothing there stops q->timeout, and that timer rolls forward: it stays
pending until it next expires, not until the last request completes.
So if the driver issued any I/O before adding the disk, the
request_queue is freed while still linked into a timer wheel bucket.
Commit 6f8191fdf41d ("block: simplify disk shutdown") dropped the
blk_cleanup_queue() call that used to stop it. __del_gendisk() and
blk_mq_destroy_queue() still do; only the probe failure path lost it.
nvme gets there because nvme_update_ns_info() submits Report Zones or
FDP io-mgmt-recv on ns->queue before the disk is added, so a later
failure - a concurrent reset setting NVME_CTRL_FROZEN, or
device_add_disk() failing - lands in put_disk() with the timer armed:
BUG: KASAN: slab-use-after-free in detach_if_pending+0x30c/0x340
Write of size 8 at addr ffff888004d71310 by task kworker/u8:2/37
__timer_delete_sync+0x156/0x240 kernel/time/timer.c:1621
blk_sync_queue+0x22/0x40 block/blk-core.c:222
nvme_sync_queues+0x100/0x150 drivers/nvme/host/core.c:5362
nvme_reset_work+0x138/0x930 drivers/nvme/host/pci.c:3264
Allocated by task 34:
__blk_mq_alloc_disk+0x33/0x100 block/blk-mq.c:4462
nvme_alloc_ns+0x290/0x3870 drivers/nvme/host/core.c:4146
Freed by task 0:
blk_free_queue_rcu+0x3a/0x50 block/blk-core.c:254
rcu_core+0xc10/0x1730 kernel/rcu/tree.c:2857
The queue being synced there is ctrl->admin_q, only a victim sharing a
timer wheel bucket with the freed queue's dangling entry; other runs
tripped in enqueue_timer(), __run_timers() or blk_mq_timeout_work().
Failing nvme_alloc_ns() with a debug patch makes it deterministic: one
leaked timer trips KASAN within seconds, while 1987 patched releases
produced no splat.
Stop the timer and the queue work items before blk_mq_exit_queue(), like
blk_mq_destroy_queue() does.
Found by FuzzNvme.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 6f8191fdf41d3a53cc1d63fe2234e812c55a0092 Version: 6f8191fdf41d3a53cc1d63fe2234e812c55a0092 Version: 6f8191fdf41d3a53cc1d63fe2234e812c55a0092 Version: 6f8191fdf41d3a53cc1d63fe2234e812c55a0092 Version: 6f8191fdf41d3a53cc1d63fe2234e812c55a0092 Version: 6f8191fdf41d3a53cc1d63fe2234e812c55a0092 Version: d27b66257db183fe11c10f31246ae965adb005d3 Version: 5.19.12 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"block/genhd.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "6ae7364f68e6c7af6b6df4bbb14040b89e5975d0",
"status": "affected",
"version": "6f8191fdf41d3a53cc1d63fe2234e812c55a0092",
"versionType": "git"
},
{
"lessThan": "6f06dbe5012c160e0dba418a5a9cb16c456ad46a",
"status": "affected",
"version": "6f8191fdf41d3a53cc1d63fe2234e812c55a0092",
"versionType": "git"
},
{
"lessThan": "1a0ae4d502062a2759f2a92d12bdeab3c64c7372",
"status": "affected",
"version": "6f8191fdf41d3a53cc1d63fe2234e812c55a0092",
"versionType": "git"
},
{
"lessThan": "bb03b56d1d754908a37a160603be21769da423cf",
"status": "affected",
"version": "6f8191fdf41d3a53cc1d63fe2234e812c55a0092",
"versionType": "git"
},
{
"lessThan": "93d620519d71dfc6ee64b5baea74f1d85d4439fb",
"status": "affected",
"version": "6f8191fdf41d3a53cc1d63fe2234e812c55a0092",
"versionType": "git"
},
{
"lessThan": "26cb8ebbfaf713c82e142d08828d4d765057633b",
"status": "affected",
"version": "6f8191fdf41d3a53cc1d63fe2234e812c55a0092",
"versionType": "git"
},
{
"status": "affected",
"version": "d27b66257db183fe11c10f31246ae965adb005d3",
"versionType": "git"
},
{
"lessThan": "5.20",
"status": "affected",
"version": "5.19.12",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"block/genhd.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.0"
},
{
"lessThan": "6.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.46",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.10",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.19.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nblock: stop the timeout timer when releasing a never added disk\n\ndisk_release() undoes blk_mq_init_allocated_queue() for a disk whose\nprobe failed before add_disk(), but it only calls blk_mq_exit_queue().\nNothing there stops q-\u003etimeout, and that timer rolls forward: it stays\npending until it next expires, not until the last request completes.\nSo if the driver issued any I/O before adding the disk, the\nrequest_queue is freed while still linked into a timer wheel bucket.\n\nCommit 6f8191fdf41d (\"block: simplify disk shutdown\") dropped the\nblk_cleanup_queue() call that used to stop it. __del_gendisk() and\nblk_mq_destroy_queue() still do; only the probe failure path lost it.\n\nnvme gets there because nvme_update_ns_info() submits Report Zones or\nFDP io-mgmt-recv on ns-\u003equeue before the disk is added, so a later\nfailure - a concurrent reset setting NVME_CTRL_FROZEN, or\ndevice_add_disk() failing - lands in put_disk() with the timer armed:\n\n BUG: KASAN: slab-use-after-free in detach_if_pending+0x30c/0x340\n Write of size 8 at addr ffff888004d71310 by task kworker/u8:2/37\n __timer_delete_sync+0x156/0x240 kernel/time/timer.c:1621\n blk_sync_queue+0x22/0x40 block/blk-core.c:222\n nvme_sync_queues+0x100/0x150 drivers/nvme/host/core.c:5362\n nvme_reset_work+0x138/0x930 drivers/nvme/host/pci.c:3264\n\n Allocated by task 34:\n __blk_mq_alloc_disk+0x33/0x100 block/blk-mq.c:4462\n nvme_alloc_ns+0x290/0x3870 drivers/nvme/host/core.c:4146\n\n Freed by task 0:\n blk_free_queue_rcu+0x3a/0x50 block/blk-core.c:254\n rcu_core+0xc10/0x1730 kernel/rcu/tree.c:2857\n\nThe queue being synced there is ctrl-\u003eadmin_q, only a victim sharing a\ntimer wheel bucket with the freed queue\u0027s dangling entry; other runs\ntripped in enqueue_timer(), __run_timers() or blk_mq_timeout_work().\nFailing nvme_alloc_ns() with a debug patch makes it deterministic: one\nleaked timer trips KASAN within seconds, while 1987 patched releases\nproduced no splat.\n\nStop the timer and the queue work items before blk_mq_exit_queue(), like\nblk_mq_destroy_queue() does.\n\nFound by FuzzNvme."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - Exploitation reaches disk_release() via NVMe namespace probing that issues pre-add_disk I/O (FDP io-mgmt-recv, Report Zones) over NVMe-oF TCP/RDMA; a remote or storage-network peer can supply crafted responses during automatic scan/reconnect on cloud/datacenter initiators.\nAC:L - An attacker controlling the NVMe endpoint can reliably time namespace enumeration I/O (arming q-\u003etimeout) with a concurrent probe failure (controller reset/NVME_CTRL_FROZEN or device_add_disk failure); FuzzNvme made this deterministic, and the attacker controls both sides of the race.\nPR:N - No local account or capability is required on the victim host at exploitation time; once an NVMe fabric path exists, a remote/compromised target or storage-network attacker can trigger the probe-failure teardown without CAP_SYS_ADMIN, ioctl, or sysfs access.\nUI:N - The bug fires during automatic kernel namespace scan/reconnect and queue teardown on probe failure; no victim mount, login, or manual device interaction is required beyond normal background storage enumeration.\nS:U - Impact is kernel slab corruption and crashes within the host kernel block layer; it does not cross a VM, container, or IOMMU security boundary even though virtio_blk shares the same pre-add_disk probe pattern.\nC:H - KASAN reports slab use-after-free with an 8-byte write in detach_if_pending on a freed request_queue whose timeout timer remains on the timer wheel; UAF of queue/timer structures enables arbitrary kernel memory disclosure primitives.\nI:H - The dangling timer wheel entry corrupts kernel heap metadata and can affect unrelated queues (e.g., ctrl-\u003eadmin_q in the reported stack); UAF on request_queue/timer state is exploitable for arbitrary write and control-flow hijacking, not merely a crash.\nA:H - Observed impact includes KASAN BUG/oops from timer deletion and queue sync on freed memory; leaked timers also trip in enqueue_timer(), __run_timers(), and blk_mq_timeout_work(), causing kernel panics and denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T05:02:10.391Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/6ae7364f68e6c7af6b6df4bbb14040b89e5975d0"
},
{
"url": "https://git.kernel.org/stable/c/6f06dbe5012c160e0dba418a5a9cb16c456ad46a"
},
{
"url": "https://git.kernel.org/stable/c/1a0ae4d502062a2759f2a92d12bdeab3c64c7372"
},
{
"url": "https://git.kernel.org/stable/c/bb03b56d1d754908a37a160603be21769da423cf"
},
{
"url": "https://git.kernel.org/stable/c/93d620519d71dfc6ee64b5baea74f1d85d4439fb"
},
{
"url": "https://git.kernel.org/stable/c/26cb8ebbfaf713c82e142d08828d4d765057633b"
}
],
"title": "block: stop the timeout timer when releasing a never added disk",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80589",
"datePublished": "2026-08-26T14:37:43.293Z",
"dateReserved": "2026-08-26T14:34:25.770Z",
"dateUpdated": "2026-08-27T05:02:10.391Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80553 (GCVE-0-2026-80553)
Vulnerability from cvelistv5
Published
2026-08-26 14:37
Modified
2026-08-27 12:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
s390/vfio_ccw: Cancel existing workqueues
The initialization of the io_work and crw_work workqueues begs the
question of whether they should be un-initialized. Add the corresponding
cleanup tags in _release_dev to ensure work isn't dispatched after
the private struct is free'd.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: e5f84dbaea59b4f712dac428c337528b70e1c533 Version: e5f84dbaea59b4f712dac428c337528b70e1c533 Version: e5f84dbaea59b4f712dac428c337528b70e1c533 Version: e5f84dbaea59b4f712dac428c337528b70e1c533 Version: e5f84dbaea59b4f712dac428c337528b70e1c533 Version: e5f84dbaea59b4f712dac428c337528b70e1c533 Version: e5f84dbaea59b4f712dac428c337528b70e1c533 Version: e5f84dbaea59b4f712dac428c337528b70e1c533 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/s390/cio/vfio_ccw_ops.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "87d569cb35a541b31a184faf982540694d4c9a89",
"status": "affected",
"version": "e5f84dbaea59b4f712dac428c337528b70e1c533",
"versionType": "git"
},
{
"lessThan": "7492ca2d0c5d59add01e267be9f5a6eeb8076fd7",
"status": "affected",
"version": "e5f84dbaea59b4f712dac428c337528b70e1c533",
"versionType": "git"
},
{
"lessThan": "b94b28c1f0fae53b2f2d6180ae6442c9a1558f67",
"status": "affected",
"version": "e5f84dbaea59b4f712dac428c337528b70e1c533",
"versionType": "git"
},
{
"lessThan": "e868ea8be0bc88c6982f48ecf3259d98afd884ae",
"status": "affected",
"version": "e5f84dbaea59b4f712dac428c337528b70e1c533",
"versionType": "git"
},
{
"lessThan": "dc47a98abe6714577a25224534dbd356051097a3",
"status": "affected",
"version": "e5f84dbaea59b4f712dac428c337528b70e1c533",
"versionType": "git"
},
{
"lessThan": "b7ae0f7993867d009a4b554fc1d6d451c10580a0",
"status": "affected",
"version": "e5f84dbaea59b4f712dac428c337528b70e1c533",
"versionType": "git"
},
{
"lessThan": "77f5e888d2e607a0b3141fb95091ad6ef1cca9a2",
"status": "affected",
"version": "e5f84dbaea59b4f712dac428c337528b70e1c533",
"versionType": "git"
},
{
"lessThan": "79c60b2c61105368dcc8444eb45847e21734f7c4",
"status": "affected",
"version": "e5f84dbaea59b4f712dac428c337528b70e1c533",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/s390/cio/vfio_ccw_ops.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.12"
},
{
"lessThan": "4.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.267",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.218",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.185",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.267",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.218",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.185",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.46",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.10",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/vfio_ccw: Cancel existing workqueues\n\nThe initialization of the io_work and crw_work workqueues begs the\nquestion of whether they should be un-initialized. Add the corresponding\ncleanup tags in _release_dev to ensure work isn\u0027t dispatched after\nthe private struct is free\u0027d."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached only through local VFIO mediated-device syscalls (read/write/ioctl on /dev/vfio/* and device fds) that start channel I/O or receive CRW events; vfio-ccw has no network, Bluetooth, or physical-bus packet entry point.\nAC:L - This is a close/teardown versus workqueue race where the VFIO client controls both sides: it can submit I/O that queues io_work/crw_work via interrupts or path events, then close or release the device while work is still pending, and retry to win reliably.\nPR:L - Exploitation requires access to an opened vfio-ccw mdev (typical QEMU/libvirt VM operator or delegated /dev/vfio holder on an IBM Z passthrough host), not init-namespace root; mdev creation is admin setup, but triggering the UAF needs only the delegated VFIO fd.\nUI:N - No separate victim action is required; once vfio-ccw passthrough is configured, the attacker issues channel I/O and coordinates device close/release (e.g., hot-unplug or fd teardown) without needing another user to mount media or click anything.\nS:C - On IBM Z/LinuxONE, vfio-ccw exists to pass DASD subchannels into KVM guests; guest-driven channel I/O causes host interrupt/workqueue activity and host-side teardown UAF corrupts hypervisor kernel memory outside the VM security boundary.\nC:H - vfio_ccw_sch_io_todo() and vfio_ccw_crw_todo() dereference freed vfio_ccw_private fields (io_mutex, cp, io_region, crw list, eventfd pointers); per kernel UAF guidance this enables attacker-influenced reuse and arbitrary kernel read primitives.\nI:H - The UAF handlers perform mutex operations, cp_free(), memcpy into io_region, and eventfd_signal() on freed memory, giving heap-sprayable arbitrary write and control-flow hijack potential beyond a simple crash.\nA:H - Use-after-free in deferred I/O/CRW work during device close or release can immediately oops or panic the host kernel from invalid mutex/structure access, and successful exploitation can hang or crash the system even when not leveraged for code execution."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T12:40:13.853Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/87d569cb35a541b31a184faf982540694d4c9a89"
},
{
"url": "https://git.kernel.org/stable/c/7492ca2d0c5d59add01e267be9f5a6eeb8076fd7"
},
{
"url": "https://git.kernel.org/stable/c/b94b28c1f0fae53b2f2d6180ae6442c9a1558f67"
},
{
"url": "https://git.kernel.org/stable/c/e868ea8be0bc88c6982f48ecf3259d98afd884ae"
},
{
"url": "https://git.kernel.org/stable/c/dc47a98abe6714577a25224534dbd356051097a3"
},
{
"url": "https://git.kernel.org/stable/c/b7ae0f7993867d009a4b554fc1d6d451c10580a0"
},
{
"url": "https://git.kernel.org/stable/c/77f5e888d2e607a0b3141fb95091ad6ef1cca9a2"
},
{
"url": "https://git.kernel.org/stable/c/79c60b2c61105368dcc8444eb45847e21734f7c4"
}
],
"title": "s390/vfio_ccw: Cancel existing workqueues",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80553",
"datePublished": "2026-08-26T14:37:21.774Z",
"dateReserved": "2026-08-26T14:34:25.766Z",
"dateUpdated": "2026-08-27T12:40:13.853Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74668 (GCVE-0-2026-74668)
Vulnerability from cvelistv5
Published
2026-08-22 15:32
Modified
2026-08-27 12:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
packet: use consistent hard_header_len in TX_RING send path
tpacket_snd() reads dev->hard_header_len independently for skb
allocation and header construction in tpacket_fill_skb(). Concurrent
netdevice reconfiguration can therefore make the reserved headroom
smaller than the amount later pushed, or make copylen - hard_header_len
negative.
Snapshot hard_header_len once before processing ring frames and use it
for the frame limit, headroom allocation, copy length, and skb
construction. Pass the snapshot to tpacket_fill_skb().
The separate SOCK_DGRAM consistency problem between hard_header_len and
header_ops->create is not addressed here.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 69e3c75f4d541a6eb151b3ef91f34033cb3ad6e1 Version: 69e3c75f4d541a6eb151b3ef91f34033cb3ad6e1 Version: 69e3c75f4d541a6eb151b3ef91f34033cb3ad6e1 Version: 69e3c75f4d541a6eb151b3ef91f34033cb3ad6e1 Version: 69e3c75f4d541a6eb151b3ef91f34033cb3ad6e1 Version: 69e3c75f4d541a6eb151b3ef91f34033cb3ad6e1 Version: 69e3c75f4d541a6eb151b3ef91f34033cb3ad6e1 Version: 69e3c75f4d541a6eb151b3ef91f34033cb3ad6e1 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/packet/af_packet.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "9c7e8ff48c377bef18c3d178748aea0575b69ede",
"status": "affected",
"version": "69e3c75f4d541a6eb151b3ef91f34033cb3ad6e1",
"versionType": "git"
},
{
"lessThan": "2a73b2c37ee3060a880b53cd24783d93fc7be5f8",
"status": "affected",
"version": "69e3c75f4d541a6eb151b3ef91f34033cb3ad6e1",
"versionType": "git"
},
{
"lessThan": "e79f59a8527a49078cfaf8fe8fb5fcefc20c76d2",
"status": "affected",
"version": "69e3c75f4d541a6eb151b3ef91f34033cb3ad6e1",
"versionType": "git"
},
{
"lessThan": "d85d2fd54e901637c81d847811e03c662aee13cd",
"status": "affected",
"version": "69e3c75f4d541a6eb151b3ef91f34033cb3ad6e1",
"versionType": "git"
},
{
"lessThan": "016763e829cac37b3234eace86fd0a4c560de4a7",
"status": "affected",
"version": "69e3c75f4d541a6eb151b3ef91f34033cb3ad6e1",
"versionType": "git"
},
{
"lessThan": "27e068d1b35dbec10a3cf268887c94407be4badc",
"status": "affected",
"version": "69e3c75f4d541a6eb151b3ef91f34033cb3ad6e1",
"versionType": "git"
},
{
"lessThan": "d48ea5c9c4c34dc0df621f0e39ed3a16b644621a",
"status": "affected",
"version": "69e3c75f4d541a6eb151b3ef91f34033cb3ad6e1",
"versionType": "git"
},
{
"lessThan": "21b5953e7494c16a42e6cd8cf110e18d13ae4a6b",
"status": "affected",
"version": "69e3c75f4d541a6eb151b3ef91f34033cb3ad6e1",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/packet/af_packet.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.31"
},
{
"lessThan": "2.6.31",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.267",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.218",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.185",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.267",
"versionStartIncluding": "2.6.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.218",
"versionStartIncluding": "2.6.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.185",
"versionStartIncluding": "2.6.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "2.6.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "2.6.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "2.6.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "2.6.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.31",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\npacket: use consistent hard_header_len in TX_RING send path\n\ntpacket_snd() reads dev-\u003ehard_header_len independently for skb\nallocation and header construction in tpacket_fill_skb(). Concurrent\nnetdevice reconfiguration can therefore make the reserved headroom\nsmaller than the amount later pushed, or make copylen - hard_header_len\nnegative.\n\nSnapshot hard_header_len once before processing ring frames and use it\nfor the frame limit, headroom allocation, copy length, and skb\nconstruction. Pass the snapshot to tpacket_fill_skb().\n\nThe separate SOCK_DGRAM consistency problem between hard_header_len and\nheader_ops-\u003ecreate is not addressed here."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The flaw is reached only via local syscalls on an AF_PACKET socket with PACKET_TX_RING configured (sendmsg on mmap ring frames); it is not triggered by processing remotely received network traffic.\nAC:L - An attacker can open the TX_RING socket and concurrently reconfigure the bound netdev (e.g., VLAN/bonding/macvlan changes) in a user+network namespace, controlling both sides of the hard_header_len race without depending on external timing.\nPR:L - Exploitation requires CAP_NET_RAW to create AF_PACKET sockets and CAP_NET_ADMIN to change netdev hard_header_len; both are obtainable by an unprivileged user inside a user namespace without init-namespace root.\nUI:N - No victim interaction is required; the attacker triggers the bug using their own packet socket, TX_RING, and netdev reconfiguration threads.\nS:U - Impact is kernel heap corruption and local privilege escalation within the same kernel security domain; it does not constitute a VM escape, sandbox breakout, or IOMMU boundary bypass.\nC:H - Racing hard_header_len can make skb_push exceed reserved headroom or skb_put use a negative length (huge unsigned), and subsequent skb_store_bits writes before skb-\u003ehead or far past skb-\u003etail, corrupting adjacent slab objects and enabling kernel memory disclosure.\nI:H - Inconsistent hard_header_len between skb allocation and tpacket_fill_skb causes out-of-bounds linear expansion and data writes in the skb buffer, yielding heap corruption primitives suitable for control-flow hijacking and local privilege escalation.\nA:H - Corrupted skb_push/put operations invoke skb_under_panic or skb_over_panic (BUG), causing kernel oops/panic and reliable denial of service even when exploitation is not completed."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T12:40:01.903Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/9c7e8ff48c377bef18c3d178748aea0575b69ede"
},
{
"url": "https://git.kernel.org/stable/c/2a73b2c37ee3060a880b53cd24783d93fc7be5f8"
},
{
"url": "https://git.kernel.org/stable/c/e79f59a8527a49078cfaf8fe8fb5fcefc20c76d2"
},
{
"url": "https://git.kernel.org/stable/c/d85d2fd54e901637c81d847811e03c662aee13cd"
},
{
"url": "https://git.kernel.org/stable/c/016763e829cac37b3234eace86fd0a4c560de4a7"
},
{
"url": "https://git.kernel.org/stable/c/27e068d1b35dbec10a3cf268887c94407be4badc"
},
{
"url": "https://git.kernel.org/stable/c/d48ea5c9c4c34dc0df621f0e39ed3a16b644621a"
},
{
"url": "https://git.kernel.org/stable/c/21b5953e7494c16a42e6cd8cf110e18d13ae4a6b"
}
],
"title": "packet: use consistent hard_header_len in TX_RING send path",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74668",
"datePublished": "2026-08-22T15:32:39.583Z",
"dateReserved": "2026-08-15T05:44:03.924Z",
"dateUpdated": "2026-08-27T12:40:01.903Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72070 (GCVE-0-2026-72070)
Vulnerability from cvelistv5
Published
2026-08-15 05:52
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: libertas_tf: fix use-after-free in lbtf_free_adapter()
lbtf_free_adapter() calls timer_delete(&priv->command_timer), which does
not wait for a running command_timer_fn() callback. lbtf_free_adapter()
runs on the teardown path right before ieee80211_free_hw() frees priv,
both in lbtf_remove_card() and in the probe error path. command_timer is
armed by mod_timer() in lbtf_cmd() whenever a firmware command is sent.
command_timer_fn() dereferences priv. If a command times out as the
device is removed, command_timer_fn() runs concurrently with teardown and
dereferences priv after it has been freed.
This is the same use-after-free that commit 03cc8f90d053 ("wifi: libertas:
fix use-after-free in lbs_free_adapter()") fixed in the sibling libertas
driver. The libertas_tf variant has the identical pattern and was left
unchanged. Use timer_delete_sync() so any in-flight callback completes
before priv is freed.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 06b16ae5319251c26377afcb401e46056d5673f4 Version: 06b16ae5319251c26377afcb401e46056d5673f4 Version: 06b16ae5319251c26377afcb401e46056d5673f4 Version: 06b16ae5319251c26377afcb401e46056d5673f4 Version: 06b16ae5319251c26377afcb401e46056d5673f4 Version: 06b16ae5319251c26377afcb401e46056d5673f4 Version: 06b16ae5319251c26377afcb401e46056d5673f4 Version: 06b16ae5319251c26377afcb401e46056d5673f4 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/marvell/libertas_tf/main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "bd75636681588c67006279abdb9a76a708b3ce29",
"status": "affected",
"version": "06b16ae5319251c26377afcb401e46056d5673f4",
"versionType": "git"
},
{
"lessThan": "2fba1d3b2f031a2c68e566a6d45cc5b7a8d6683d",
"status": "affected",
"version": "06b16ae5319251c26377afcb401e46056d5673f4",
"versionType": "git"
},
{
"lessThan": "9392fd5de555272449d3d8c63410ea00f8ec853a",
"status": "affected",
"version": "06b16ae5319251c26377afcb401e46056d5673f4",
"versionType": "git"
},
{
"lessThan": "4714e95f5d61cb9c5c7c6c4e68b618f37bc6ffcf",
"status": "affected",
"version": "06b16ae5319251c26377afcb401e46056d5673f4",
"versionType": "git"
},
{
"lessThan": "066b59e84f90d270cc15f0370166155aca507630",
"status": "affected",
"version": "06b16ae5319251c26377afcb401e46056d5673f4",
"versionType": "git"
},
{
"lessThan": "fcff712d0e3d183843ec3916470ee6cc3455baad",
"status": "affected",
"version": "06b16ae5319251c26377afcb401e46056d5673f4",
"versionType": "git"
},
{
"lessThan": "bcf7968cb97ce4312588042cf2712f04caff6d8f",
"status": "affected",
"version": "06b16ae5319251c26377afcb401e46056d5673f4",
"versionType": "git"
},
{
"lessThan": "aa6dcd5c8dd9ba1d7d0f60093bcda41c0d6d438d",
"status": "affected",
"version": "06b16ae5319251c26377afcb401e46056d5673f4",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/marvell/libertas_tf/main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.28"
},
{
"lessThan": "2.6.28",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.28",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: libertas_tf: fix use-after-free in lbtf_free_adapter()\n\nlbtf_free_adapter() calls timer_delete(\u0026priv-\u003ecommand_timer), which does\nnot wait for a running command_timer_fn() callback. lbtf_free_adapter()\nruns on the teardown path right before ieee80211_free_hw() frees priv,\nboth in lbtf_remove_card() and in the probe error path. command_timer is\narmed by mod_timer() in lbtf_cmd() whenever a firmware command is sent.\ncommand_timer_fn() dereferences priv. If a command times out as the\ndevice is removed, command_timer_fn() runs concurrently with teardown and\ndereferences priv after it has been freed.\n\nThis is the same use-after-free that commit 03cc8f90d053 (\"wifi: libertas:\nfix use-after-free in lbs_free_adapter()\") fixed in the sibling libertas\ndriver. The libertas_tf variant has the identical pattern and was left\nunchanged. Use timer_delete_sync() so any in-flight callback completes\nbefore priv is freed."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:42.921Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/bd75636681588c67006279abdb9a76a708b3ce29"
},
{
"url": "https://git.kernel.org/stable/c/2fba1d3b2f031a2c68e566a6d45cc5b7a8d6683d"
},
{
"url": "https://git.kernel.org/stable/c/9392fd5de555272449d3d8c63410ea00f8ec853a"
},
{
"url": "https://git.kernel.org/stable/c/4714e95f5d61cb9c5c7c6c4e68b618f37bc6ffcf"
},
{
"url": "https://git.kernel.org/stable/c/066b59e84f90d270cc15f0370166155aca507630"
},
{
"url": "https://git.kernel.org/stable/c/fcff712d0e3d183843ec3916470ee6cc3455baad"
},
{
"url": "https://git.kernel.org/stable/c/bcf7968cb97ce4312588042cf2712f04caff6d8f"
},
{
"url": "https://git.kernel.org/stable/c/aa6dcd5c8dd9ba1d7d0f60093bcda41c0d6d438d"
}
],
"title": "wifi: libertas_tf: fix use-after-free in lbtf_free_adapter()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72070",
"datePublished": "2026-08-15T05:52:22.486Z",
"dateReserved": "2026-08-09T03:40:39.904Z",
"dateUpdated": "2026-08-23T12:46:42.921Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74673 (GCVE-0-2026-74673)
Vulnerability from cvelistv5
Published
2026-08-22 15:32
Modified
2026-08-25 05:23
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Input: evdev - fix information leak in evdev_pass_values()
In evdev_pass_values(), the input_event structure is allocated on the
kernel stack and populated field-by-field. However, it is never fully
initialized. On architectures where struct input_event contains explicit
or implicit padding (such as the 32-bit __pad field on SPARC64), these
padding bytes are left uninitialized.
When this event structure is subsequently passed to the client buffer
and later copied to userspace, the uninitialized padding bytes leak
kernel stack memory, potentially exposing sensitive information.
Similar issues exist in __evdev_queue_syn_dropped and __pass_event.
Fix this by explicitly zeroing the entire event structure with memset()
before populating its fields. This ensures all padding bytes are cleared
before the data crosses the security boundary.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 6addb1d6de1968b84852f54561cc9a999909b5a9 Version: 6addb1d6de1968b84852f54561cc9a999909b5a9 Version: 6addb1d6de1968b84852f54561cc9a999909b5a9 Version: 6addb1d6de1968b84852f54561cc9a999909b5a9 Version: 6addb1d6de1968b84852f54561cc9a999909b5a9 Version: 6addb1d6de1968b84852f54561cc9a999909b5a9 Version: 6addb1d6de1968b84852f54561cc9a999909b5a9 Version: 6addb1d6de1968b84852f54561cc9a999909b5a9 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/input/evdev.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "d2e3839419ac4047835762c4d7712bda1101b57e",
"status": "affected",
"version": "6addb1d6de1968b84852f54561cc9a999909b5a9",
"versionType": "git"
},
{
"lessThan": "c6d5fa46c1ee25d068fc730fd377f0f54188d290",
"status": "affected",
"version": "6addb1d6de1968b84852f54561cc9a999909b5a9",
"versionType": "git"
},
{
"lessThan": "e748811d9b80a3e101110ff4b3c612e5fca54d98",
"status": "affected",
"version": "6addb1d6de1968b84852f54561cc9a999909b5a9",
"versionType": "git"
},
{
"lessThan": "06a286b320236508d02ab2ccc9496352748652a8",
"status": "affected",
"version": "6addb1d6de1968b84852f54561cc9a999909b5a9",
"versionType": "git"
},
{
"lessThan": "7d17e9454a9af3ec7aebb88b41a9deedd5b19a6b",
"status": "affected",
"version": "6addb1d6de1968b84852f54561cc9a999909b5a9",
"versionType": "git"
},
{
"lessThan": "bd3c4108a56de34380edab670065e86283cb3029",
"status": "affected",
"version": "6addb1d6de1968b84852f54561cc9a999909b5a9",
"versionType": "git"
},
{
"lessThan": "7e55ca1080f09d9f7112c7f20ac31f682c1f2374",
"status": "affected",
"version": "6addb1d6de1968b84852f54561cc9a999909b5a9",
"versionType": "git"
},
{
"lessThan": "90f305f2c7a30257c683e13f4bf7c798eea992a0",
"status": "affected",
"version": "6addb1d6de1968b84852f54561cc9a999909b5a9",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/input/evdev.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.24"
},
{
"lessThan": "2.6.24",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.24",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nInput: evdev - fix information leak in evdev_pass_values()\n\nIn evdev_pass_values(), the input_event structure is allocated on the\nkernel stack and populated field-by-field. However, it is never fully\ninitialized. On architectures where struct input_event contains explicit\nor implicit padding (such as the 32-bit __pad field on SPARC64), these\npadding bytes are left uninitialized.\n\nWhen this event structure is subsequently passed to the client buffer\nand later copied to userspace, the uninitialized padding bytes leak\nkernel stack memory, potentially exposing sensitive information.\n\nSimilar issues exist in __evdev_queue_syn_dropped and __pass_event.\n\nFix this by explicitly zeroing the entire event structure with memset()\nbefore populating its fields. This ensures all padding bytes are cleared\nbefore the data crosses the security boundary."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:23:15.607Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/d2e3839419ac4047835762c4d7712bda1101b57e"
},
{
"url": "https://git.kernel.org/stable/c/c6d5fa46c1ee25d068fc730fd377f0f54188d290"
},
{
"url": "https://git.kernel.org/stable/c/e748811d9b80a3e101110ff4b3c612e5fca54d98"
},
{
"url": "https://git.kernel.org/stable/c/06a286b320236508d02ab2ccc9496352748652a8"
},
{
"url": "https://git.kernel.org/stable/c/7d17e9454a9af3ec7aebb88b41a9deedd5b19a6b"
},
{
"url": "https://git.kernel.org/stable/c/bd3c4108a56de34380edab670065e86283cb3029"
},
{
"url": "https://git.kernel.org/stable/c/7e55ca1080f09d9f7112c7f20ac31f682c1f2374"
},
{
"url": "https://git.kernel.org/stable/c/90f305f2c7a30257c683e13f4bf7c798eea992a0"
}
],
"title": "Input: evdev - fix information leak in evdev_pass_values()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74673",
"datePublished": "2026-08-22T15:32:42.941Z",
"dateReserved": "2026-08-15T05:44:03.925Z",
"dateUpdated": "2026-08-25T05:23:15.607Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72057 (GCVE-0-2026-72057)
Vulnerability from cvelistv5
Published
2026-08-15 05:52
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/sched: act_ct: preserve tc_skb_cb across defragmentation
tcf_ct_handle_fragments() calls nf_ct_handle_fragments() without saving
and restoring skb->cb. The defrag helper clears IPCB/IP6CB, which aliases
the tc_skb_cb/qdisc_skb_cb control buffer. Fragmented traffic through
act_ct therefore loses qdisc metadata such as pkt_segs and can trigger
WARN_ON_ONCE() in qdisc_pkt_segs() when panic_on_warn is enabled.
Save and restore the full tc_skb_cb around nf_ct_handle_fragments(),
matching the pattern used by ovs_ct_handle_fragments().
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 0d76daf2013ce1da20eab5e26bd81d983e1c18fb Version: ec624fe740b416fb68d536b37fb8eef46f90b5c2 Version: ec624fe740b416fb68d536b37fb8eef46f90b5c2 Version: ec624fe740b416fb68d536b37fb8eef46f90b5c2 Version: ec624fe740b416fb68d536b37fb8eef46f90b5c2 Version: ec624fe740b416fb68d536b37fb8eef46f90b5c2 Version: ec624fe740b416fb68d536b37fb8eef46f90b5c2 Version: 5.15.13 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/sched/act_ct.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "fb080b6f54835d5d4d11ce3122800e6f0f6689e6",
"status": "affected",
"version": "0d76daf2013ce1da20eab5e26bd81d983e1c18fb",
"versionType": "git"
},
{
"lessThan": "67d6b00a54446c008f52cf70fc0c2ad0c712f85d",
"status": "affected",
"version": "ec624fe740b416fb68d536b37fb8eef46f90b5c2",
"versionType": "git"
},
{
"lessThan": "2400c4b05d58834b994500a9eec90a37db44187c",
"status": "affected",
"version": "ec624fe740b416fb68d536b37fb8eef46f90b5c2",
"versionType": "git"
},
{
"lessThan": "5c3ae5f6c7c6de73ea9b6a75154fe4ed343e1bac",
"status": "affected",
"version": "ec624fe740b416fb68d536b37fb8eef46f90b5c2",
"versionType": "git"
},
{
"lessThan": "b3d835407846134b0d54637c0281b39bebef831d",
"status": "affected",
"version": "ec624fe740b416fb68d536b37fb8eef46f90b5c2",
"versionType": "git"
},
{
"lessThan": "f7f45ceb855d9ba1cba594fb3f383255f7013fad",
"status": "affected",
"version": "ec624fe740b416fb68d536b37fb8eef46f90b5c2",
"versionType": "git"
},
{
"lessThan": "9092e15defbe6c7bc241c306093ca9d358a578e7",
"status": "affected",
"version": "ec624fe740b416fb68d536b37fb8eef46f90b5c2",
"versionType": "git"
},
{
"lessThan": "5.15.217",
"status": "affected",
"version": "5.15.13",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/sched/act_ct.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.16"
},
{
"lessThan": "5.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.15.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.16",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: act_ct: preserve tc_skb_cb across defragmentation\n\ntcf_ct_handle_fragments() calls nf_ct_handle_fragments() without saving\nand restoring skb-\u003ecb. The defrag helper clears IPCB/IP6CB, which aliases\nthe tc_skb_cb/qdisc_skb_cb control buffer. Fragmented traffic through\nact_ct therefore loses qdisc metadata such as pkt_segs and can trigger\nWARN_ON_ONCE() in qdisc_pkt_segs() when panic_on_warn is enabled.\n\nSave and restore the full tc_skb_cb around nf_ct_handle_fragments(),\nmatching the pattern used by ovs_ct_handle_fragments()."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.2,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug fires in tcf_ct_act() on the packet datapath (sch_handle_ingress/egress \u2192 tc_run \u2192 tcf_classify) when IP fragments arrive; on OVN/Kubernetes/SDN gateways and mlx5 offload nodes with act_ct already installed, a remote peer triggers it by sending fragmented traffic with no local access.\nAC:L - The attacker fully controls fragment boundaries and ordering; nf_ct_handle_fragments() memset of IPCB/IP6CB that aliases tc_skb_cb runs deterministically on each matching fragment through the configured ct action without races or memory-layout dependencies.\nPR:N - Installing act_ct requires CAP_NET_ADMIN, but triggering the bug on an already-configured internet-facing or tenant-facing gateway needs no target credentials; a remote attacker only sends crafted IP fragments, matching CNA precedent for packet-driven act_ct issues (e.g., CVE-2023-52610).\nUI:N - Exploitation requires only attacker-generated fragmented packets reaching a host with act_ct on clsact/ingress; no victim login, mount, or other interactive action is needed.\nS:U - WARN/panic and corrupted qdisc/tc metadata occur entirely within the host kernel security domain; this is not a VM escape, sandbox breakout, or IOMMU boundary bypass.\nC:N - memset(IPCB/IP6CB) zeroes tc_skb_cb/qdisc_skb_cb fields in place without out-of-bounds read or use-after-free; no kernel memory contents are disclosed to the attacker, only skb control-block metadata is clobbered.\nI:L - Clearing pkt_segs, pkt_len, post_ct, and zone corrupts tc/qdisc state consumed by bstats_update, sch_cake/sch_qfq, and cls_flower zone matching, enabling attacker-driven mis-accounting and mis-handling of packets on the affected path.\nA:H - Zeroed pkt_segs makes qdisc_pkt_segs() hit DEBUG_NET_WARN_ON_ONCE when it disagrees with GSO segment count; with panic_on_warn enabled this kernel-panics the host, and the condition is repeatable with sustained fragmented traffic."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:36.427Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/fb080b6f54835d5d4d11ce3122800e6f0f6689e6"
},
{
"url": "https://git.kernel.org/stable/c/67d6b00a54446c008f52cf70fc0c2ad0c712f85d"
},
{
"url": "https://git.kernel.org/stable/c/2400c4b05d58834b994500a9eec90a37db44187c"
},
{
"url": "https://git.kernel.org/stable/c/5c3ae5f6c7c6de73ea9b6a75154fe4ed343e1bac"
},
{
"url": "https://git.kernel.org/stable/c/b3d835407846134b0d54637c0281b39bebef831d"
},
{
"url": "https://git.kernel.org/stable/c/f7f45ceb855d9ba1cba594fb3f383255f7013fad"
},
{
"url": "https://git.kernel.org/stable/c/9092e15defbe6c7bc241c306093ca9d358a578e7"
}
],
"title": "net/sched: act_ct: preserve tc_skb_cb across defragmentation",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72057",
"datePublished": "2026-08-15T05:52:12.873Z",
"dateReserved": "2026-08-09T03:40:39.903Z",
"dateUpdated": "2026-08-23T12:46:36.427Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68366 (GCVE-0-2026-68366)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer
uvc_send_response() builds the UVC control response from a user-supplied
struct uvc_request_data:
req->length = min_t(unsigned int, uvc->event_length, data->length);
...
memcpy(req->buf, data->data, req->length);
req->length is clamped to uvc->event_length, which is taken from the
host control request wLength (up to UVC_MAX_REQUEST_SIZE, 64), and to
data->length, which comes from the UVCIOC_SEND_RESPONSE ioctl and is
only checked for being negative. The source buffer data->data is only
60 bytes, so a response with uvc->event_length and data->length both
greater than 60 makes memcpy() read past the end of data->data.
Clamp req->length to sizeof(data->data) as well.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: a5eaaa1f33e771fa1651a4a7652b8a5f9fa7f6c1 Version: a5eaaa1f33e771fa1651a4a7652b8a5f9fa7f6c1 Version: a5eaaa1f33e771fa1651a4a7652b8a5f9fa7f6c1 Version: a5eaaa1f33e771fa1651a4a7652b8a5f9fa7f6c1 Version: a5eaaa1f33e771fa1651a4a7652b8a5f9fa7f6c1 Version: a5eaaa1f33e771fa1651a4a7652b8a5f9fa7f6c1 Version: a5eaaa1f33e771fa1651a4a7652b8a5f9fa7f6c1 Version: a5eaaa1f33e771fa1651a4a7652b8a5f9fa7f6c1 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/gadget/function/uvc_v4l2.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "eaf783c005299a702f2cc96b08cd21ede081f098",
"status": "affected",
"version": "a5eaaa1f33e771fa1651a4a7652b8a5f9fa7f6c1",
"versionType": "git"
},
{
"lessThan": "568e68d8f80395a64848aa2946af8ade72da0ffb",
"status": "affected",
"version": "a5eaaa1f33e771fa1651a4a7652b8a5f9fa7f6c1",
"versionType": "git"
},
{
"lessThan": "82ec2c1e456b17451f0736c3983402642f961733",
"status": "affected",
"version": "a5eaaa1f33e771fa1651a4a7652b8a5f9fa7f6c1",
"versionType": "git"
},
{
"lessThan": "4e116372b7a4f87df0dc0ed4b0ab5b0bb0cc5796",
"status": "affected",
"version": "a5eaaa1f33e771fa1651a4a7652b8a5f9fa7f6c1",
"versionType": "git"
},
{
"lessThan": "662f6c6c6ff8a6c508e1646c09cae74e28f3cca6",
"status": "affected",
"version": "a5eaaa1f33e771fa1651a4a7652b8a5f9fa7f6c1",
"versionType": "git"
},
{
"lessThan": "1f03658f3e9b2f8fd1d1003ba389a0390b49a350",
"status": "affected",
"version": "a5eaaa1f33e771fa1651a4a7652b8a5f9fa7f6c1",
"versionType": "git"
},
{
"lessThan": "c8510fbbea09ef0170b56b14dc2b5890dc75be07",
"status": "affected",
"version": "a5eaaa1f33e771fa1651a4a7652b8a5f9fa7f6c1",
"versionType": "git"
},
{
"lessThan": "b70dc75e85ba968b7b76eebfe5d63000080b875b",
"status": "affected",
"version": "a5eaaa1f33e771fa1651a4a7652b8a5f9fa7f6c1",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/usb/gadget/function/uvc_v4l2.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.10"
},
{
"lessThan": "3.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer\n\nuvc_send_response() builds the UVC control response from a user-supplied\nstruct uvc_request_data:\n\n\treq-\u003elength = min_t(unsigned int, uvc-\u003eevent_length, data-\u003elength);\n\t...\n\tmemcpy(req-\u003ebuf, data-\u003edata, req-\u003elength);\n\nreq-\u003elength is clamped to uvc-\u003eevent_length, which is taken from the\nhost control request wLength (up to UVC_MAX_REQUEST_SIZE, 64), and to\ndata-\u003elength, which comes from the UVCIOC_SEND_RESPONSE ioctl and is\nonly checked for being negative. The source buffer data-\u003edata is only\n60 bytes, so a response with uvc-\u003eevent_length and data-\u003elength both\ngreater than 60 makes memcpy() read past the end of data-\u003edata.\n\nClamp req-\u003elength to sizeof(data-\u003edata) as well."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:23.776Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/eaf783c005299a702f2cc96b08cd21ede081f098"
},
{
"url": "https://git.kernel.org/stable/c/568e68d8f80395a64848aa2946af8ade72da0ffb"
},
{
"url": "https://git.kernel.org/stable/c/82ec2c1e456b17451f0736c3983402642f961733"
},
{
"url": "https://git.kernel.org/stable/c/4e116372b7a4f87df0dc0ed4b0ab5b0bb0cc5796"
},
{
"url": "https://git.kernel.org/stable/c/662f6c6c6ff8a6c508e1646c09cae74e28f3cca6"
},
{
"url": "https://git.kernel.org/stable/c/1f03658f3e9b2f8fd1d1003ba389a0390b49a350"
},
{
"url": "https://git.kernel.org/stable/c/c8510fbbea09ef0170b56b14dc2b5890dc75be07"
},
{
"url": "https://git.kernel.org/stable/c/b70dc75e85ba968b7b76eebfe5d63000080b875b"
}
],
"title": "usb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68366",
"datePublished": "2026-08-10T12:03:43.304Z",
"dateReserved": "2026-07-30T09:28:09.385Z",
"dateUpdated": "2026-08-19T16:34:23.776Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74563 (GCVE-0-2026-74563)
Vulnerability from cvelistv5
Published
2026-08-15 12:28
Modified
2026-08-19 16:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
rds: tcp: hold the RCU lock across ipv6_chk_addr() in rds_tcp_laddr_check()
rds_tcp_laddr_check() looks up a scoped IPv6 interface with
dev_get_by_index_rcu(), drops the RCU read-side lock, and only then
passes the bare struct net_device * into ipv6_chk_addr().
dev_get_by_index_rcu() only keeps the device alive within the same RCU
read-side section. After rcu_read_unlock(), a concurrent RTM_DELLINK can
free the net_device; ipv6_chk_addr() then dereferences the stale pointer
in __ipv6_chk_addr_and_flags() (e.g. l3mdev_master_dev_rcu(dev)), reading
freed memory.
Keep the RCU read-side lock held across the ipv6_chk_addr() call instead
of dropping it right after the lookup, so the device cannot be freed
while it is in use.
BUG: KASAN: slab-use-after-free in __ipv6_chk_addr_and_flags (... net/ipv6/addrconf.c:1998)
Read of size 8 at addr ffff8880106ec000 by task exploit/153
Call Trace:
...
kasan_report (mm/kasan/report.c:595)
__ipv6_chk_addr_and_flags (... net/ipv6/addrconf.c:1998)
ipv6_chk_addr (net/ipv6/addrconf.c:2031 net/ipv6/addrconf.c:1972)
rds_tcp_laddr_check (net/rds/tcp.c:370)
rds_bind (net/rds/bind.c:248)
__sys_bind (net/socket.c:1920)
__x64_sys_bind (net/socket.c:1956)
do_syscall_64 (arch/x86/entry/syscall_64.c:63)
entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: eee2fa6ab3225192d6d894c54a6fb02ac9efdff6 Version: eee2fa6ab3225192d6d894c54a6fb02ac9efdff6 Version: eee2fa6ab3225192d6d894c54a6fb02ac9efdff6 Version: eee2fa6ab3225192d6d894c54a6fb02ac9efdff6 Version: eee2fa6ab3225192d6d894c54a6fb02ac9efdff6 Version: eee2fa6ab3225192d6d894c54a6fb02ac9efdff6 Version: eee2fa6ab3225192d6d894c54a6fb02ac9efdff6 Version: eee2fa6ab3225192d6d894c54a6fb02ac9efdff6 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/rds/tcp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "f8a8977af2134a1d91e5f9773cb7d9d53278c830",
"status": "affected",
"version": "eee2fa6ab3225192d6d894c54a6fb02ac9efdff6",
"versionType": "git"
},
{
"lessThan": "ba95bce5dfe6e2ef602a87e0557225f2934ccb5c",
"status": "affected",
"version": "eee2fa6ab3225192d6d894c54a6fb02ac9efdff6",
"versionType": "git"
},
{
"lessThan": "c4933624a6f416ecfcc31ab58d585da1207a0597",
"status": "affected",
"version": "eee2fa6ab3225192d6d894c54a6fb02ac9efdff6",
"versionType": "git"
},
{
"lessThan": "76dd48886eeeb5fcf2b837d2f4c3d17eebeac9ef",
"status": "affected",
"version": "eee2fa6ab3225192d6d894c54a6fb02ac9efdff6",
"versionType": "git"
},
{
"lessThan": "f0d1fb05d70c8a561cd8d0473bcacafa2fc137ff",
"status": "affected",
"version": "eee2fa6ab3225192d6d894c54a6fb02ac9efdff6",
"versionType": "git"
},
{
"lessThan": "b1d480fce05f857dc438080cd8c9244b84a83494",
"status": "affected",
"version": "eee2fa6ab3225192d6d894c54a6fb02ac9efdff6",
"versionType": "git"
},
{
"lessThan": "8398bc477d3cb3e2b018a5aaac2bec0f69acda30",
"status": "affected",
"version": "eee2fa6ab3225192d6d894c54a6fb02ac9efdff6",
"versionType": "git"
},
{
"lessThan": "78f75d632f74b8de0f081a128588f7c37d0d1164",
"status": "affected",
"version": "eee2fa6ab3225192d6d894c54a6fb02ac9efdff6",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/rds/tcp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.19"
},
{
"lessThan": "4.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nrds: tcp: hold the RCU lock across ipv6_chk_addr() in rds_tcp_laddr_check()\n\nrds_tcp_laddr_check() looks up a scoped IPv6 interface with\ndev_get_by_index_rcu(), drops the RCU read-side lock, and only then\npasses the bare struct net_device * into ipv6_chk_addr().\n\ndev_get_by_index_rcu() only keeps the device alive within the same RCU\nread-side section. After rcu_read_unlock(), a concurrent RTM_DELLINK can\nfree the net_device; ipv6_chk_addr() then dereferences the stale pointer\nin __ipv6_chk_addr_and_flags() (e.g. l3mdev_master_dev_rcu(dev)), reading\nfreed memory.\n\nKeep the RCU read-side lock held across the ipv6_chk_addr() call instead\nof dropping it right after the lookup, so the device cannot be freed\nwhile it is in use.\n\n BUG: KASAN: slab-use-after-free in __ipv6_chk_addr_and_flags (... net/ipv6/addrconf.c:1998)\n Read of size 8 at addr ffff8880106ec000 by task exploit/153\n Call Trace:\n ...\n kasan_report (mm/kasan/report.c:595)\n __ipv6_chk_addr_and_flags (... net/ipv6/addrconf.c:1998)\n ipv6_chk_addr (net/ipv6/addrconf.c:2031 net/ipv6/addrconf.c:1972)\n rds_tcp_laddr_check (net/rds/tcp.c:370)\n rds_bind (net/rds/bind.c:248)\n __sys_bind (net/socket.c:1920)\n __x64_sys_bind (net/socket.c:1956)\n do_syscall_64 (arch/x86/entry/syscall_64.c:63)\n entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The slab use-after-free is reached via the bind(2) syscall on an AF_RDS socket with a link-local IPv6 address and non-zero scope_id; the KASAN reproducer follows bind()-\u003erds_bind()-\u003erds_tcp_laddr_check(), requiring on-host access to race bind against RTM_DELLINK netlink deletion of the referenced netdev.\nAC:L - Exploitation requires racing rds_tcp_laddr_check() against RTM_DELLINK freeing the netdev; the attacker controls both sides by concurrently calling bind() and deleting the interface via netlink (e.g., a veth in a user namespace) and can retry until the race succeeds.\nPR:L - An unprivileged local user can create AF_RDS sockets and call bind(); the RTM_DELLINK race is achievable with CAP_NET_ADMIN obtainable inside an unprivileged user+network namespace (unshare -Urn), not requiring init-namespace root.\nUI:N - No victim interaction is required; exploitation is fully attacker-driven through bind/netlink syscalls without needing another user to mount a filesystem, click, or open a file.\nS:U - Impact is confined to kernel memory corruption and potential privilege escalation within the same kernel/host security boundary; this is not a VM-guest-to-host escape, sandbox escape, or cross-authority boundary crossing.\nC:H - The bug is a slab use-after-free read of a freed struct net_device in __ipv6_chk_addr_and_flags() via a stale pointer passed to ipv6_chk_addr(); UAF reads of kernel heap objects can disclose sensitive memory and enable further exploitation.\nI:H - Use-after-free on struct net_device heap memory provides memory corruption primitives that can be groomed for arbitrary kernel writes, control-flow hijacking, and local privilege escalation, not merely a bounded or transient error.\nA:H - The reported KASAN slab-use-after-free causes kernel oops/panic during the stale dereference in the IPv6 address-check path; UAF conditions are inherently crash-prone even when not fully weaponized for code execution."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:39:02.416Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/f8a8977af2134a1d91e5f9773cb7d9d53278c830"
},
{
"url": "https://git.kernel.org/stable/c/ba95bce5dfe6e2ef602a87e0557225f2934ccb5c"
},
{
"url": "https://git.kernel.org/stable/c/c4933624a6f416ecfcc31ab58d585da1207a0597"
},
{
"url": "https://git.kernel.org/stable/c/76dd48886eeeb5fcf2b837d2f4c3d17eebeac9ef"
},
{
"url": "https://git.kernel.org/stable/c/f0d1fb05d70c8a561cd8d0473bcacafa2fc137ff"
},
{
"url": "https://git.kernel.org/stable/c/b1d480fce05f857dc438080cd8c9244b84a83494"
},
{
"url": "https://git.kernel.org/stable/c/8398bc477d3cb3e2b018a5aaac2bec0f69acda30"
},
{
"url": "https://git.kernel.org/stable/c/78f75d632f74b8de0f081a128588f7c37d0d1164"
}
],
"title": "rds: tcp: hold the RCU lock across ipv6_chk_addr() in rds_tcp_laddr_check()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74563",
"datePublished": "2026-08-15T12:28:05.768Z",
"dateReserved": "2026-08-15T05:44:03.916Z",
"dateUpdated": "2026-08-19T16:39:02.416Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80568 (GCVE-0-2026-80568)
Vulnerability from cvelistv5
Published
2026-08-26 14:37
Modified
2026-08-27 05:01
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Input: synaptics-rmi4 - block s_input when F54 queue is busy
Changing the input (diagnostic report type) mid-stream changes the
report size. Since V4L2 buffers are allocated based on the size at
stream start, changing the input while streaming could lead to a
heap buffer overflow if the new size is larger than the allocated
buffers.
Prevent this by blocking VIDIOC_S_INPUT with -EBUSY if the V4L2 queue
is busy (streaming).
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d Version: 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d Version: 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d Version: 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d Version: 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d Version: 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d Version: 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d Version: 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/input/rmi4/rmi_f54.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "7e994a9ecc0b49ad2fe63da9c92a8aca8a6614af",
"status": "affected",
"version": "3a762dbd5347514c3cb2ac756a92a3d1c7646a2d",
"versionType": "git"
},
{
"lessThan": "fa69f93015becf3729716de2199b58540aa99672",
"status": "affected",
"version": "3a762dbd5347514c3cb2ac756a92a3d1c7646a2d",
"versionType": "git"
},
{
"lessThan": "493ba8e794729649689438edba72337111303cc4",
"status": "affected",
"version": "3a762dbd5347514c3cb2ac756a92a3d1c7646a2d",
"versionType": "git"
},
{
"lessThan": "1d718f1461766e9f00a8dbeb4f13f1b1c19d90ac",
"status": "affected",
"version": "3a762dbd5347514c3cb2ac756a92a3d1c7646a2d",
"versionType": "git"
},
{
"lessThan": "cae79513f9115c350561b16f36adcb47c9bfff12",
"status": "affected",
"version": "3a762dbd5347514c3cb2ac756a92a3d1c7646a2d",
"versionType": "git"
},
{
"lessThan": "ff0849705d29277fd1f6fc6596674b9308724fb2",
"status": "affected",
"version": "3a762dbd5347514c3cb2ac756a92a3d1c7646a2d",
"versionType": "git"
},
{
"lessThan": "ddd9a53faf3b65e5920cb802cb1db6f4615bdfef",
"status": "affected",
"version": "3a762dbd5347514c3cb2ac756a92a3d1c7646a2d",
"versionType": "git"
},
{
"lessThan": "fbfd76746adc16d64be29ff113f673b70bc3f5c2",
"status": "affected",
"version": "3a762dbd5347514c3cb2ac756a92a3d1c7646a2d",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/input/rmi4/rmi_f54.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.9"
},
{
"lessThan": "4.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.46",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.10",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nInput: synaptics-rmi4 - block s_input when F54 queue is busy\n\nChanging the input (diagnostic report type) mid-stream changes the\nreport size. Since V4L2 buffers are allocated based on the size at\nstream start, changing the input while streaming could lead to a\nheap buffer overflow if the new size is larger than the allocated\nbuffers.\n\nPrevent this by blocking VIDIOC_S_INPUT with -EBUSY if the V4L2 queue\nis busy (streaming)."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires issuing V4L2 ioctls (VIDIOC_S_INPUT, VIDIOC_STREAMON, VIDIOC_QBUF) on the /dev/v4l-touch* node created by the synaptics-rmi4 F54 diagnostics driver; reachable only from a local process with permission to open that character device, not over the network.\nAC:L - An attacker can deterministically start streaming with a smaller F54 report type, switch to a larger type via VIDIOC_S_INPUT while the vb2 queue is busy, then queue buffers to trigger the overflow; no winning of uncontrollable races or rare layout-dependent conditions is required.\nPR:L - The vulnerable path has no capability checks beyond standard DAC on /dev/v4l-touch*; on typical laptop/kiosk/Android deployments any unprivileged local user or app granted access to the V4L2 touch diagnostics node (commonly via the video group) can invoke the bug without real root in the init namespace.\nUI:N - No victim interaction is required beyond the attacker opening the device and issuing ioctl sequences; exploitation does not depend on another user plugging hardware, mounting filesystems, or performing GUI actions.\nS:U - The flaw corrupts kernel heap memory within the same host via vb2 vmalloc buffers in the F54 V4L2 driver; impact stays in the kernel security authority and does not by itself cross VM, IOMMU, or sandbox boundaries.\nC:H - Changing the diagnostic input mid-stream makes rmi_f54_buffer_queue() memcpy() up to twice the originally allocated report size into undersized vmalloc-backed V4L2 buffers, a kernel heap out-of-bounds write that can expose or corrupt adjacent kernel memory.\nI:H - The oversized memcpy is a controlled kernel heap buffer overflow in rmi_f54_buffer_queue() that can corrupt adjacent vmalloc objects and be developed into arbitrary memory write or code-execution primitives, not merely a bounded data change.\nA:H - Writing far beyond the allocated V4L2 capture buffer can corrupt critical kernel heap metadata or adjacent structures, causing kernel oops/panic or denial of service on affected laptops, kiosks, and embedded touch systems even without full exploit development."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T05:01:52.050Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/7e994a9ecc0b49ad2fe63da9c92a8aca8a6614af"
},
{
"url": "https://git.kernel.org/stable/c/fa69f93015becf3729716de2199b58540aa99672"
},
{
"url": "https://git.kernel.org/stable/c/493ba8e794729649689438edba72337111303cc4"
},
{
"url": "https://git.kernel.org/stable/c/1d718f1461766e9f00a8dbeb4f13f1b1c19d90ac"
},
{
"url": "https://git.kernel.org/stable/c/cae79513f9115c350561b16f36adcb47c9bfff12"
},
{
"url": "https://git.kernel.org/stable/c/ff0849705d29277fd1f6fc6596674b9308724fb2"
},
{
"url": "https://git.kernel.org/stable/c/ddd9a53faf3b65e5920cb802cb1db6f4615bdfef"
},
{
"url": "https://git.kernel.org/stable/c/fbfd76746adc16d64be29ff113f673b70bc3f5c2"
}
],
"title": "Input: synaptics-rmi4 - block s_input when F54 queue is busy",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80568",
"datePublished": "2026-08-26T14:37:30.740Z",
"dateReserved": "2026-08-26T14:34:25.768Z",
"dateUpdated": "2026-08-27T05:01:52.050Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74722 (GCVE-0-2026-74722)
Vulnerability from cvelistv5
Published
2026-08-22 15:33
Modified
2026-08-22 15:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
btrfs: fix memory leak in btrfs_do_encoded_write()
Local fuzzing of 6.12.94 has found the following memory leak:
Unreferenced object 0xffff888018050a80 (size 64):
comm "syz.0.17", pid 10297, jiffies 4294953601
hex dump (first 32 bytes):
00 10 00 00 00 00 00 00 01 00 00 00 00 00 00 00 ................
10 0a 05 18 80 88 ff ff 10 0a 05 18 80 88 ff ff ................
backtrace (crc a8a6fc29):
kmemleak_alloc_recursive include/linux/kmemleak.h:42 [inline]
slab_post_alloc_hook mm/slub.c:4152 [inline]
slab_alloc_node mm/slub.c:4197 [inline]
__kmalloc_cache_noprof+0x168/0x2c0 mm/slub.c:4358
kmalloc_noprof include/linux/slab.h:878 [inline]
extent_changeset_alloc fs/btrfs/extent_io.h:207 [inline]
qgroup_reserve_data+0x1c5/0x7d0 fs/btrfs/qgroup.c:4305
btrfs_qgroup_reserve_data+0x2e/0xb0 fs/btrfs/qgroup.c:4355
btrfs_do_encoded_write+0x92e/0x1040 fs/btrfs/inode.c:9746
btrfs_encoded_write fs/btrfs/file.c:1482 [inline]
btrfs_do_write_iter+0x280/0x610 fs/btrfs/file.c:1507
btrfs_ioctl_encoded_write+0x3d6/0x490 fs/btrfs/ioctl.c:4738
btrfs_ioctl+0x6f9/0xc90 fs/btrfs/ioctl.c:-1
vfs_ioctl fs/ioctl.c:51 [inline]
__do_sys_ioctl fs/ioctl.c:906 [inline]
__se_sys_ioctl+0xf9/0x170 fs/ioctl.c:892
do_syscall_x64 arch/x86/entry/common.c:47 [inline]
do_syscall_64+0xbe/0x1a0 arch/x86/entry/common.c:78
entry_SYSCALL_64_after_hwframe+0x77/0x7f
Unreferenced object 0xffff888018050a00 (size 64):
comm "syz.0.17", pid 10297, jiffies 4294953601
hex dump (first 32 bytes):
00 00 00 00 00 00 00 00 ff 0f 00 00 00 00 00 00 ................
90 0a 05 18 80 88 ff ff 90 0a 05 18 80 88 ff ff ................
backtrace (crc cb5c9580):
kmemleak_alloc_recursive include/linux/kmemleak.h:42 [inline]
slab_post_alloc_hook mm/slub.c:4152 [inline]
slab_alloc_node mm/slub.c:4197 [inline]
__kmalloc_cache_noprof+0x168/0x2c0 mm/slub.c:4358
kmalloc_noprof include/linux/slab.h:878 [inline]
kzalloc_noprof include/linux/slab.h:1014 [inline]
ulist_prealloc+0x9c/0x110 fs/btrfs/ulist.c:114
extent_changeset_prealloc fs/btrfs/extent_io.h:217 [inline]
__set_extent_bit+0x16b/0x1a70 fs/btrfs/extent-io-tree.c:1086
set_record_extent_bits+0x50/0x90 fs/btrfs/extent-io-tree.c:1821
qgroup_reserve_data+0x274/0x7d0 fs/btrfs/qgroup.c:4312
btrfs_qgroup_reserve_data+0x2e/0xb0 fs/btrfs/qgroup.c:4355
btrfs_do_encoded_write+0x92e/0x1040 fs/btrfs/inode.c:9746
btrfs_encoded_write fs/btrfs/file.c:1482 [inline]
btrfs_do_write_iter+0x280/0x610 fs/btrfs/file.c:1507
btrfs_ioctl_encoded_write+0x3d6/0x490 fs/btrfs/ioctl.c:4738
btrfs_ioctl+0x6f9/0xc90 fs/btrfs/ioctl.c:-1
vfs_ioctl fs/ioctl.c:51 [inline]
__do_sys_ioctl fs/ioctl.c:906 [inline]
__se_sys_ioctl+0xf9/0x170 fs/ioctl.c:892
do_syscall_x64 arch/x86/entry/common.c:47 [inline]
do_syscall_64+0xbe/0x1a0 arch/x86/entry/common.c:78
entry_SYSCALL_64_after_hwframe+0x77/0x7f
Fix this by freeing an extent changeset before returning from
btrfs_do_encoded_write().
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 7c0c7269f7b508ba6e4b063a9314d6bd1fb6db22 Version: 7c0c7269f7b508ba6e4b063a9314d6bd1fb6db22 Version: 7c0c7269f7b508ba6e4b063a9314d6bd1fb6db22 Version: 7c0c7269f7b508ba6e4b063a9314d6bd1fb6db22 Version: 7c0c7269f7b508ba6e4b063a9314d6bd1fb6db22 Version: 7c0c7269f7b508ba6e4b063a9314d6bd1fb6db22 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/btrfs/inode.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "0f0da96ccb1b9f35f4d3d4540dcaab0969d9d6b0",
"status": "affected",
"version": "7c0c7269f7b508ba6e4b063a9314d6bd1fb6db22",
"versionType": "git"
},
{
"lessThan": "e2c7e88815edd5ecfb88e7660ab9fd42bda6bc47",
"status": "affected",
"version": "7c0c7269f7b508ba6e4b063a9314d6bd1fb6db22",
"versionType": "git"
},
{
"lessThan": "20c0eeb4313f9f89d47b80b672b5846f9827cb31",
"status": "affected",
"version": "7c0c7269f7b508ba6e4b063a9314d6bd1fb6db22",
"versionType": "git"
},
{
"lessThan": "24a8f2c29aebb753ccb962fbb25bae18d7978f6e",
"status": "affected",
"version": "7c0c7269f7b508ba6e4b063a9314d6bd1fb6db22",
"versionType": "git"
},
{
"lessThan": "60b50ceba6243802f8d2c0a9a7c2d549a93b1d64",
"status": "affected",
"version": "7c0c7269f7b508ba6e4b063a9314d6bd1fb6db22",
"versionType": "git"
},
{
"lessThan": "d2a4e4e626b2f4670b69b430c357f03f53eb6632",
"status": "affected",
"version": "7c0c7269f7b508ba6e4b063a9314d6bd1fb6db22",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/btrfs/inode.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.18"
},
{
"lessThan": "5.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.18",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix memory leak in btrfs_do_encoded_write()\n\nLocal fuzzing of 6.12.94 has found the following memory leak:\n\nUnreferenced object 0xffff888018050a80 (size 64):\n comm \"syz.0.17\", pid 10297, jiffies 4294953601\n hex dump (first 32 bytes):\n 00 10 00 00 00 00 00 00 01 00 00 00 00 00 00 00 ................\n 10 0a 05 18 80 88 ff ff 10 0a 05 18 80 88 ff ff ................\n backtrace (crc a8a6fc29):\n kmemleak_alloc_recursive include/linux/kmemleak.h:42 [inline]\n slab_post_alloc_hook mm/slub.c:4152 [inline]\n slab_alloc_node mm/slub.c:4197 [inline]\n __kmalloc_cache_noprof+0x168/0x2c0 mm/slub.c:4358\n kmalloc_noprof include/linux/slab.h:878 [inline]\n extent_changeset_alloc fs/btrfs/extent_io.h:207 [inline]\n qgroup_reserve_data+0x1c5/0x7d0 fs/btrfs/qgroup.c:4305\n btrfs_qgroup_reserve_data+0x2e/0xb0 fs/btrfs/qgroup.c:4355\n btrfs_do_encoded_write+0x92e/0x1040 fs/btrfs/inode.c:9746\n btrfs_encoded_write fs/btrfs/file.c:1482 [inline]\n btrfs_do_write_iter+0x280/0x610 fs/btrfs/file.c:1507\n btrfs_ioctl_encoded_write+0x3d6/0x490 fs/btrfs/ioctl.c:4738\n btrfs_ioctl+0x6f9/0xc90 fs/btrfs/ioctl.c:-1\n vfs_ioctl fs/ioctl.c:51 [inline]\n __do_sys_ioctl fs/ioctl.c:906 [inline]\n __se_sys_ioctl+0xf9/0x170 fs/ioctl.c:892\n do_syscall_x64 arch/x86/entry/common.c:47 [inline]\n do_syscall_64+0xbe/0x1a0 arch/x86/entry/common.c:78\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nUnreferenced object 0xffff888018050a00 (size 64):\n comm \"syz.0.17\", pid 10297, jiffies 4294953601\n hex dump (first 32 bytes):\n 00 00 00 00 00 00 00 00 ff 0f 00 00 00 00 00 00 ................\n 90 0a 05 18 80 88 ff ff 90 0a 05 18 80 88 ff ff ................\n backtrace (crc cb5c9580):\n kmemleak_alloc_recursive include/linux/kmemleak.h:42 [inline]\n slab_post_alloc_hook mm/slub.c:4152 [inline]\n slab_alloc_node mm/slub.c:4197 [inline]\n __kmalloc_cache_noprof+0x168/0x2c0 mm/slub.c:4358\n kmalloc_noprof include/linux/slab.h:878 [inline]\n kzalloc_noprof include/linux/slab.h:1014 [inline]\n ulist_prealloc+0x9c/0x110 fs/btrfs/ulist.c:114\n extent_changeset_prealloc fs/btrfs/extent_io.h:217 [inline]\n __set_extent_bit+0x16b/0x1a70 fs/btrfs/extent-io-tree.c:1086\n set_record_extent_bits+0x50/0x90 fs/btrfs/extent-io-tree.c:1821\n qgroup_reserve_data+0x274/0x7d0 fs/btrfs/qgroup.c:4312\n btrfs_qgroup_reserve_data+0x2e/0xb0 fs/btrfs/qgroup.c:4355\n btrfs_do_encoded_write+0x92e/0x1040 fs/btrfs/inode.c:9746\n btrfs_encoded_write fs/btrfs/file.c:1482 [inline]\n btrfs_do_write_iter+0x280/0x610 fs/btrfs/file.c:1507\n btrfs_ioctl_encoded_write+0x3d6/0x490 fs/btrfs/ioctl.c:4738\n btrfs_ioctl+0x6f9/0xc90 fs/btrfs/ioctl.c:-1\n vfs_ioctl fs/ioctl.c:51 [inline]\n __do_sys_ioctl fs/ioctl.c:906 [inline]\n __se_sys_ioctl+0xf9/0x170 fs/ioctl.c:892\n do_syscall_x64 arch/x86/entry/common.c:47 [inline]\n do_syscall_64+0xbe/0x1a0 arch/x86/entry/common.c:78\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nFix this by freeing an extent changeset before returning from\nbtrfs_do_encoded_write()."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-22T15:33:14.582Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/0f0da96ccb1b9f35f4d3d4540dcaab0969d9d6b0"
},
{
"url": "https://git.kernel.org/stable/c/e2c7e88815edd5ecfb88e7660ab9fd42bda6bc47"
},
{
"url": "https://git.kernel.org/stable/c/20c0eeb4313f9f89d47b80b672b5846f9827cb31"
},
{
"url": "https://git.kernel.org/stable/c/24a8f2c29aebb753ccb962fbb25bae18d7978f6e"
},
{
"url": "https://git.kernel.org/stable/c/60b50ceba6243802f8d2c0a9a7c2d549a93b1d64"
},
{
"url": "https://git.kernel.org/stable/c/d2a4e4e626b2f4670b69b430c357f03f53eb6632"
}
],
"title": "btrfs: fix memory leak in btrfs_do_encoded_write()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74722",
"datePublished": "2026-08-22T15:33:14.582Z",
"dateReserved": "2026-08-15T05:44:03.929Z",
"dateUpdated": "2026-08-22T15:33:14.582Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68106 (GCVE-0-2026-68106)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-19 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: fix division by zero with invalid uvd dimensions
When width or height is less than 16, width_in_mb or height_in_mb
becomes 0, leading to fs_in_mb being 0. This causes a division by
zero when calculating num_dpb_buffer in H264 and H264 Perf decode
paths.
Add validation to reject frames with width < 16 or height < 16
before performing any calculations that depend on these values.
V2: Format change - move up all vaiable definitions.
V3: Use warn_once to avoid spam.
(cherry picked from commit 3e41d26c70b0a459d041cc19482a226c4b7423cb)
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d38ceaf99ed015f2a0b9af3499791bd3a3daae21 Version: d38ceaf99ed015f2a0b9af3499791bd3a3daae21 Version: d38ceaf99ed015f2a0b9af3499791bd3a3daae21 Version: d38ceaf99ed015f2a0b9af3499791bd3a3daae21 Version: d38ceaf99ed015f2a0b9af3499791bd3a3daae21 Version: d38ceaf99ed015f2a0b9af3499791bd3a3daae21 Version: d38ceaf99ed015f2a0b9af3499791bd3a3daae21 Version: d38ceaf99ed015f2a0b9af3499791bd3a3daae21 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/amdgpu_uvd.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "004d0453cfef16f056cb7b8bc04f69f19cf9df32",
"status": "affected",
"version": "d38ceaf99ed015f2a0b9af3499791bd3a3daae21",
"versionType": "git"
},
{
"lessThan": "00ee64910ecf748cc15b23bbcbea472c203ec1e8",
"status": "affected",
"version": "d38ceaf99ed015f2a0b9af3499791bd3a3daae21",
"versionType": "git"
},
{
"lessThan": "81c9b4921f62d1642b9d775524ae9240e521a5ed",
"status": "affected",
"version": "d38ceaf99ed015f2a0b9af3499791bd3a3daae21",
"versionType": "git"
},
{
"lessThan": "52f9a588296432accf2982f7d258192a37562f4f",
"status": "affected",
"version": "d38ceaf99ed015f2a0b9af3499791bd3a3daae21",
"versionType": "git"
},
{
"lessThan": "a00946b5ab7c25da5685ca9c58f50ff6f43c0fdf",
"status": "affected",
"version": "d38ceaf99ed015f2a0b9af3499791bd3a3daae21",
"versionType": "git"
},
{
"lessThan": "ffb33d466a68cea3e8a3dbed04d79037a3cbabd1",
"status": "affected",
"version": "d38ceaf99ed015f2a0b9af3499791bd3a3daae21",
"versionType": "git"
},
{
"lessThan": "be725ab23aa45c11a5afef3e2a9f6d8c084ae5dc",
"status": "affected",
"version": "d38ceaf99ed015f2a0b9af3499791bd3a3daae21",
"versionType": "git"
},
{
"lessThan": "0c01c811be47e6b146552dd59bfedbea8f09b8f4",
"status": "affected",
"version": "d38ceaf99ed015f2a0b9af3499791bd3a3daae21",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/amdgpu_uvd.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.2"
},
{
"lessThan": "4.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: fix division by zero with invalid uvd dimensions\n\nWhen width or height is less than 16, width_in_mb or height_in_mb\nbecomes 0, leading to fs_in_mb being 0. This causes a division by\nzero when calculating num_dpb_buffer in H264 and H264 Perf decode\npaths.\n\nAdd validation to reject frames with width \u003c 16 or height \u003c 16\nbefore performing any calculations that depend on these values.\n\nV2: Format change - move up all vaiable definitions.\nV3: Use warn_once to avoid spam.\n\n(cherry picked from commit 3e41d26c70b0a459d041cc19482a226c4b7423cb)"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The flaw is reached only via the AMDGPU_CS DRM ioctl on a local render node (/dev/dri/renderD*), traversing amdgpu_cs_ioctl, amdgpu_cs_patch_ibs, amdgpu_uvd_ring_parse_cs, and amdgpu_uvd_cs_msg_decode; it is not reachable from any network-facing kernel service.\nAC:L - An attacker with render-node access fully controls the UVD decode message fields (stream_type H264/H264 Perf, width, height, level) in their own BO and can reliably trigger width or height \u003c 16 after creating a valid UVD session handle.\nPR:L - Exploitation requires only standard unprivileged local access to the AMDGPU DRM render node (DRM_AUTH|DRM_RENDER_ALLOW on AMDGPU_CS), not root or capabilities outside the render/video group; user namespaces do not grant this access by themselves.\nUI:N - No victim interaction is required; a local attacker can directly submit a crafted UVD command stream through AMDGPU_CS ioctl without needing another user to open media, mount a filesystem, or take any other action.\nS:U - Impact is confined to the kernel/GPU driver security domain on the local host (kernel oops or GPU memory corruption within the attacker\u0027s DRM client); it does not cross VM, IOMMU, or sandbox boundaries to affect a different security authority.\nC:H - On x86, kernel-mode divide-by-zero causes a fatal trap; on architectures where unsigned division by zero returns zero, underestimated DPB buffer sizes can pass validation, enabling GPU out-of-bounds reads of adjacent mapped buffers that may hold sensitive data.\nI:H - Underestimated buffer-size calculations from zero macroblock counts can let undersized DPB buffers pass kernel validation, permitting the UVD engine to perform out-of-bounds writes into adjacent GPU-mapped memory that could be leveraged for further memory corruption.\nA:H - Triggering the divide-by-zero in kernel context during CS parsing causes an x86 divide-error exception leading to die()/kernel oops, crashing or hanging the system; repeated submissions can deny GPU/video availability on affected UVD hardware (v3.1-v6.0)."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:29:19.954Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/004d0453cfef16f056cb7b8bc04f69f19cf9df32"
},
{
"url": "https://git.kernel.org/stable/c/00ee64910ecf748cc15b23bbcbea472c203ec1e8"
},
{
"url": "https://git.kernel.org/stable/c/81c9b4921f62d1642b9d775524ae9240e521a5ed"
},
{
"url": "https://git.kernel.org/stable/c/52f9a588296432accf2982f7d258192a37562f4f"
},
{
"url": "https://git.kernel.org/stable/c/a00946b5ab7c25da5685ca9c58f50ff6f43c0fdf"
},
{
"url": "https://git.kernel.org/stable/c/ffb33d466a68cea3e8a3dbed04d79037a3cbabd1"
},
{
"url": "https://git.kernel.org/stable/c/be725ab23aa45c11a5afef3e2a9f6d8c084ae5dc"
},
{
"url": "https://git.kernel.org/stable/c/0c01c811be47e6b146552dd59bfedbea8f09b8f4"
}
],
"title": "drm/amdgpu: fix division by zero with invalid uvd dimensions",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68106",
"datePublished": "2026-08-10T11:58:23.108Z",
"dateReserved": "2026-07-30T09:28:09.368Z",
"dateUpdated": "2026-08-19T16:29:19.954Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68151 (GCVE-0-2026-68151)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
binfmt_elf_fdpic: only honour the first PT_INTERP
The program header scan handles PT_INTERP from a switch nested in the
scan loop, so its break leaves the switch and not the loop. A binary
carrying more than one PT_INTERP runs the case again and overwrites both
interpreter_name and interpreter. The previous name allocation leaks and
so does the previous interpreter reference, along with the write denial
open_exec() took on it. The denial is never released, so the file stays
unwritable for as long as the system runs.
An unprivileged caller reaches this with a crafted binary and repeats it
at will. binfmt_elf stops at the first PT_INTERP. Do the same here.
The flaw dates back to the driver's introduction in the pre-git history
tree introduced in v2.6.11 by 91808d6ebe39 ("[PATCH] FRV: Add FDPIC ELF
binary format driver").
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/binfmt_elf_fdpic.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "9854538349aaf6fb88ed33b56987954ac1716151",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "3c31397b0a75310217f1f2f3c7bdfd8af67aec4c",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "849a7bd9d266e43a457db5c6b322600f916a2127",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "e4563e07ef5c938d5332c5c44721db976f214bc6",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "21eaf5594a33d16343a011c752624099c30e918f",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "89b9121c3b0162655fc2f190b714ae64f1aa8cae",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "69ecc199880bf7e8d06224c82dc411d18f9285f8",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "3349ef6a366a61d631f6a263d12cea240957719d",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/binfmt_elf_fdpic.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbinfmt_elf_fdpic: only honour the first PT_INTERP\n\nThe program header scan handles PT_INTERP from a switch nested in the\nscan loop, so its break leaves the switch and not the loop. A binary\ncarrying more than one PT_INTERP runs the case again and overwrites both\ninterpreter_name and interpreter. The previous name allocation leaks and\nso does the previous interpreter reference, along with the write denial\nopen_exec() took on it. The denial is never released, so the file stays\nunwritable for as long as the system runs.\n\nAn unprivileged caller reaches this with a crafted binary and repeats it\nat will. binfmt_elf stops at the first PT_INTERP. Do the same here.\n\nThe flaw dates back to the driver\u0027s introduction in the pre-git history\ntree introduced in v2.6.11 by 91808d6ebe39 (\"[PATCH] FRV: Add FDPIC ELF\nbinary format driver\")."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:30:15.558Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/9854538349aaf6fb88ed33b56987954ac1716151"
},
{
"url": "https://git.kernel.org/stable/c/3c31397b0a75310217f1f2f3c7bdfd8af67aec4c"
},
{
"url": "https://git.kernel.org/stable/c/849a7bd9d266e43a457db5c6b322600f916a2127"
},
{
"url": "https://git.kernel.org/stable/c/e4563e07ef5c938d5332c5c44721db976f214bc6"
},
{
"url": "https://git.kernel.org/stable/c/21eaf5594a33d16343a011c752624099c30e918f"
},
{
"url": "https://git.kernel.org/stable/c/89b9121c3b0162655fc2f190b714ae64f1aa8cae"
},
{
"url": "https://git.kernel.org/stable/c/69ecc199880bf7e8d06224c82dc411d18f9285f8"
},
{
"url": "https://git.kernel.org/stable/c/3349ef6a366a61d631f6a263d12cea240957719d"
}
],
"title": "binfmt_elf_fdpic: only honour the first PT_INTERP",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68151",
"datePublished": "2026-08-10T11:59:16.878Z",
"dateReserved": "2026-07-30T09:28:09.371Z",
"dateUpdated": "2026-08-19T16:30:15.558Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68310 (GCVE-0-2026-68310)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: mt76: mt7915: guard HE capability lookups
mt7915_mcu_bss_he_tlv() and mt7915_mcu_sta_bfer_tlv() both run after
checking HE support, then dereference the HE PHY capability returned by
mt76_connac_get_he_phy_cap(). That helper can return NULL when no
capability entry matches the vif type.
Fetch the capability before appending the TLV and skip the HE-specific
setup when no matching capability is available.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: e6d557a78b6016eee7b9cd6832343efd32cc0b27 Version: e6d557a78b6016eee7b9cd6832343efd32cc0b27 Version: e6d557a78b6016eee7b9cd6832343efd32cc0b27 Version: e6d557a78b6016eee7b9cd6832343efd32cc0b27 Version: e6d557a78b6016eee7b9cd6832343efd32cc0b27 Version: e6d557a78b6016eee7b9cd6832343efd32cc0b27 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/mediatek/mt76/mt7915/mcu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "8d5f1f4d2ea2c9d626ccc28dba7ea0df862acc67",
"status": "affected",
"version": "e6d557a78b6016eee7b9cd6832343efd32cc0b27",
"versionType": "git"
},
{
"lessThan": "23a2b98e754da04e0e90314d5fa8ca44349590fb",
"status": "affected",
"version": "e6d557a78b6016eee7b9cd6832343efd32cc0b27",
"versionType": "git"
},
{
"lessThan": "a031f454f14e3e76ad03bcb23918e1a82b4b0869",
"status": "affected",
"version": "e6d557a78b6016eee7b9cd6832343efd32cc0b27",
"versionType": "git"
},
{
"lessThan": "871549814eb4da081f1e93cc0c7ea626a310a966",
"status": "affected",
"version": "e6d557a78b6016eee7b9cd6832343efd32cc0b27",
"versionType": "git"
},
{
"lessThan": "6f99a5667c6c7c3e0da1d3c4dc8dfb103042609e",
"status": "affected",
"version": "e6d557a78b6016eee7b9cd6832343efd32cc0b27",
"versionType": "git"
},
{
"lessThan": "8e9db062654a388d0fa587acbeeae68dd33eba41",
"status": "affected",
"version": "e6d557a78b6016eee7b9cd6832343efd32cc0b27",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/mediatek/mt76/mt7915/mcu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.18"
},
{
"lessThan": "5.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.18",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7915: guard HE capability lookups\n\nmt7915_mcu_bss_he_tlv() and mt7915_mcu_sta_bfer_tlv() both run after\nchecking HE support, then dereference the HE PHY capability returned by\nmt76_connac_get_he_phy_cap(). That helper can return NULL when no\ncapability entry matches the vif type.\n\nFetch the capability before appending the TLV and skip the HE-specific\nsetup when no matching capability is available."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:03.090Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/8d5f1f4d2ea2c9d626ccc28dba7ea0df862acc67"
},
{
"url": "https://git.kernel.org/stable/c/23a2b98e754da04e0e90314d5fa8ca44349590fb"
},
{
"url": "https://git.kernel.org/stable/c/a031f454f14e3e76ad03bcb23918e1a82b4b0869"
},
{
"url": "https://git.kernel.org/stable/c/871549814eb4da081f1e93cc0c7ea626a310a966"
},
{
"url": "https://git.kernel.org/stable/c/6f99a5667c6c7c3e0da1d3c4dc8dfb103042609e"
},
{
"url": "https://git.kernel.org/stable/c/8e9db062654a388d0fa587acbeeae68dd33eba41"
}
],
"title": "wifi: mt76: mt7915: guard HE capability lookups",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68310",
"datePublished": "2026-08-10T12:02:44.917Z",
"dateReserved": "2026-07-30T09:28:09.381Z",
"dateUpdated": "2026-08-19T16:33:03.090Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80744 (GCVE-0-2026-80744)
Vulnerability from cvelistv5
Published
2026-09-03 08:26
Modified
2026-09-03 08:26
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_tables_offload: suppress WARN_ON_ONCE for ENOMEM in abort path
In nft_flow_rule_offload_abort(), WARN_ON_ONCE(err) is triggered on every
error during rollback, including -ENOMEM. Memory allocation failures are
expected under low-memory conditions and do not indicate a kernel bug.
Trace for example:
nft_flow_offload_chain() // FLOW_BLOCK_BIND
nft_flow_block_chain()
nft_chain_offload_cmd()
nft_block_offload_cmd()
->ndo_setup_tc()
nsim_setup_tc()
flow_block_cb_setup_simple()
flow_block_cb_alloc() // fails to -ENOMEM
The warning was reproduced on the 5.10 stable kernel under memory pressure
via fault injection, but the underlying bug exists in mainline as well,
as demonstrated by the ENOMEM trace above. The following splat was
triggered during nf_tables transaction processing:
WARNING: CPU: 0 PID: 8567 at net/netfilter/nf_tables_offload.c:532 nft_flow_rule_offload_abort net/netfilter/nf_tables_offload.c:532 [inline]
WARNING: CPU: 0 PID: 8567 at net/netfilter/nf_tables_offload.c:532 nft_flow_rule_offload_commit+0x971/0xcd0 net/netfilter/nf_tables_offload.c:591
Modules linked in:
CPU: 0 PID: 8567 Comm: syz-executor.0 Not tainted 5.10.260-syzkaller #0
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.12.0-1 04/01/2014
RIP: 0010:nft_flow_rule_offload_abort net/netfilter/nf_tables_offload.c:532 [inline]
RIP: 0010:nft_flow_rule_offload_commit+0x971/0xcd0 net/netfilter/nf_tables_offload.c:591
Call Trace:
nf_tables_commit+0x3bd/0x4bd0 net/netfilter/nf_tables_api.c:8604
nfnetlink_rcv_batch+0xb1e/0x1f20 net/netfilter/nfnetlink.c:509
nfnetlink_rcv_skb_batch net/netfilter/nfnetlink.c:579 [inline]
nfnetlink_rcv+0x3b3/0x420 net/netfilter/nfnetlink.c:597
netlink_unicast_kernel net/netlink/af_netlink.c:1314 [inline]
netlink_unicast+0x6cd/0xa00 net/netfilter/af_netlink.c:1340
netlink_sendmsg+0x906/0xe10 net/netfilter/af_netlink.c:1919
sock_sendmsg_nosec net/socket.c:651 [inline]
__sock_sendmsg+0x155/0x190 net/socket.c:663
____sys_sendmsg+0x705/0x870 net/socket.c:2379
___sys_sendmsg+0x100/0x170 net/socket.c:2433
__sys_sendmsg+0xe9/0x1c0 net/socket.c:2462
do_syscall_64+0x33/0x40 arch/x86/entry/common.c:46
entry_SYSCALL_64_after_hwframe+0x67/0xd1
Change the condition to WARN_ON_ONCE(err && err != -ENOMEM) so that
warnings are only emitted for unexpected errors. This aligns with the
common kernel practice of not warning on -ENOMEM.
Found by Linux Verification Center (linuxtesting.org) with Syzkaller.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 63b48c73ff567bbab1f940d6e8f3f48607077a13 Version: 63b48c73ff567bbab1f940d6e8f3f48607077a13 Version: 63b48c73ff567bbab1f940d6e8f3f48607077a13 Version: 63b48c73ff567bbab1f940d6e8f3f48607077a13 Version: 63b48c73ff567bbab1f940d6e8f3f48607077a13 Version: 63b48c73ff567bbab1f940d6e8f3f48607077a13 Version: 63b48c73ff567bbab1f940d6e8f3f48607077a13 Version: 63b48c73ff567bbab1f940d6e8f3f48607077a13 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/netfilter/nf_tables_offload.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "2319033c4bf8bdb275a9e4e1f7af9bf8a457ad79",
"status": "affected",
"version": "63b48c73ff567bbab1f940d6e8f3f48607077a13",
"versionType": "git"
},
{
"lessThan": "6ee3803c22b72508c5baf1e5aecb21301b714be0",
"status": "affected",
"version": "63b48c73ff567bbab1f940d6e8f3f48607077a13",
"versionType": "git"
},
{
"lessThan": "09bda4b6df222fd1819e8f188c3a6e90caf546d3",
"status": "affected",
"version": "63b48c73ff567bbab1f940d6e8f3f48607077a13",
"versionType": "git"
},
{
"lessThan": "17c132e18ca5d1641ddbaed8d0e6ecfd1d38fa0b",
"status": "affected",
"version": "63b48c73ff567bbab1f940d6e8f3f48607077a13",
"versionType": "git"
},
{
"lessThan": "7ce9851be6f2b019e96e105a9de99715aec6deb4",
"status": "affected",
"version": "63b48c73ff567bbab1f940d6e8f3f48607077a13",
"versionType": "git"
},
{
"lessThan": "4a923fe60939a194777bc605036ce2147ab00c9d",
"status": "affected",
"version": "63b48c73ff567bbab1f940d6e8f3f48607077a13",
"versionType": "git"
},
{
"lessThan": "c23620a0fa5b1d80399f894c41a9f78bc29d6235",
"status": "affected",
"version": "63b48c73ff567bbab1f940d6e8f3f48607077a13",
"versionType": "git"
},
{
"lessThan": "d02f592064347e0c1e0d84f24941ad338838cc48",
"status": "affected",
"version": "63b48c73ff567bbab1f940d6e8f3f48607077a13",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/netfilter/nf_tables_offload.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.5"
},
{
"lessThan": "5.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.46",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.10",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables_offload: suppress WARN_ON_ONCE for ENOMEM in abort path\n\nIn nft_flow_rule_offload_abort(), WARN_ON_ONCE(err) is triggered on every\nerror during rollback, including -ENOMEM. Memory allocation failures are\nexpected under low-memory conditions and do not indicate a kernel bug.\n\nTrace for example:\nnft_flow_offload_chain() // FLOW_BLOCK_BIND\n nft_flow_block_chain()\n nft_chain_offload_cmd()\n nft_block_offload_cmd()\n -\u003endo_setup_tc()\n nsim_setup_tc()\n flow_block_cb_setup_simple()\n flow_block_cb_alloc() // fails to -ENOMEM\n\nThe warning was reproduced on the 5.10 stable kernel under memory pressure\nvia fault injection, but the underlying bug exists in mainline as well,\nas demonstrated by the ENOMEM trace above. The following splat was\ntriggered during nf_tables transaction processing:\n\nWARNING: CPU: 0 PID: 8567 at net/netfilter/nf_tables_offload.c:532 nft_flow_rule_offload_abort net/netfilter/nf_tables_offload.c:532 [inline]\nWARNING: CPU: 0 PID: 8567 at net/netfilter/nf_tables_offload.c:532 nft_flow_rule_offload_commit+0x971/0xcd0 net/netfilter/nf_tables_offload.c:591\nModules linked in:\nCPU: 0 PID: 8567 Comm: syz-executor.0 Not tainted 5.10.260-syzkaller #0\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.12.0-1 04/01/2014\nRIP: 0010:nft_flow_rule_offload_abort net/netfilter/nf_tables_offload.c:532 [inline]\nRIP: 0010:nft_flow_rule_offload_commit+0x971/0xcd0 net/netfilter/nf_tables_offload.c:591\nCall Trace:\n nf_tables_commit+0x3bd/0x4bd0 net/netfilter/nf_tables_api.c:8604\n nfnetlink_rcv_batch+0xb1e/0x1f20 net/netfilter/nfnetlink.c:509\n nfnetlink_rcv_skb_batch net/netfilter/nfnetlink.c:579 [inline]\n nfnetlink_rcv+0x3b3/0x420 net/netfilter/nfnetlink.c:597\n netlink_unicast_kernel net/netlink/af_netlink.c:1314 [inline]\n netlink_unicast+0x6cd/0xa00 net/netfilter/af_netlink.c:1340\n netlink_sendmsg+0x906/0xe10 net/netfilter/af_netlink.c:1919\n sock_sendmsg_nosec net/socket.c:651 [inline]\n __sock_sendmsg+0x155/0x190 net/socket.c:663\n ____sys_sendmsg+0x705/0x870 net/socket.c:2379\n ___sys_sendmsg+0x100/0x170 net/socket.c:2433\n __sys_sendmsg+0xe9/0x1c0 net/socket.c:2462\n do_syscall_64+0x33/0x40 arch/x86/entry/common.c:46\n entry_SYSCALL_64_after_hwframe+0x67/0xd1\n\nChange the condition to WARN_ON_ONCE(err \u0026\u0026 err != -ENOMEM) so that\nwarnings are only emitted for unexpected errors. This aligns with the\ncommon kernel practice of not warning on -ENOMEM.\n\nFound by Linux Verification Center (linuxtesting.org) with Syzkaller."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-03T08:26:27.137Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/2319033c4bf8bdb275a9e4e1f7af9bf8a457ad79"
},
{
"url": "https://git.kernel.org/stable/c/6ee3803c22b72508c5baf1e5aecb21301b714be0"
},
{
"url": "https://git.kernel.org/stable/c/09bda4b6df222fd1819e8f188c3a6e90caf546d3"
},
{
"url": "https://git.kernel.org/stable/c/17c132e18ca5d1641ddbaed8d0e6ecfd1d38fa0b"
},
{
"url": "https://git.kernel.org/stable/c/7ce9851be6f2b019e96e105a9de99715aec6deb4"
},
{
"url": "https://git.kernel.org/stable/c/4a923fe60939a194777bc605036ce2147ab00c9d"
},
{
"url": "https://git.kernel.org/stable/c/c23620a0fa5b1d80399f894c41a9f78bc29d6235"
},
{
"url": "https://git.kernel.org/stable/c/d02f592064347e0c1e0d84f24941ad338838cc48"
}
],
"title": "netfilter: nf_tables_offload: suppress WARN_ON_ONCE for ENOMEM in abort path",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80744",
"datePublished": "2026-09-03T08:26:27.137Z",
"dateReserved": "2026-08-26T14:34:25.790Z",
"dateUpdated": "2026-09-03T08:26:27.137Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80806 (GCVE-0-2026-80806)
Vulnerability from cvelistv5
Published
2026-09-04 15:13
Modified
2026-09-04 15:13
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ext4: don't enable DAX on new encrypted files
Currently, when a new encrypted regular file is created, the call to
ext4_set_inode_flags(inode, init=true) in __ext4_new_inode() is made
before EXT4_INODE_ENCRYPT is set. As a result, it can set S_DAX if the
filesystem is mounted with "-o dax=always".
EXT4_INODE_ENCRYPT then actually gets set a bit later in
__ext4_new_inode(), when it calls fscrypt_set_context() which calls
ext4_set_context(). ext4_set_context() sets EXT4_INODE_ENCRYPT and
calls ext4_set_inode_flags(inode, init=false) to set S_ENCRYPTED too.
This was intended to clear S_DAX as well. However, this was broken by
commit 043546e46dc7 ("fs/ext4: Only change S_DAX on inode load"). This
causes data written to the file to bypass encryption, also causing
xfstests failures such as generic/548 (when "-o dax=always" is used).
Fix this by simplifying the flow by making __ext4_new_inode() set
EXT4_INODE_ENCRYPT earlier. This makes it take effect in
ext4_set_inode_flags(inode, init=true), making S_DAX never be set.
Similarly, make EXT4_STATE_MAY_INLINE_DATA never be set in the first
place on new encrypted inodes. Then it doesn't need to be cleared.
As a result of these simplifications, ext4_set_context() no longer needs
to change inode flags or state when 'handle != NULL'. Remove that too.
References
| URL | Tags | ||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 043546e46dc70c25ff7e2cf6d09cbb0424fc9978 Version: 043546e46dc70c25ff7e2cf6d09cbb0424fc9978 Version: 043546e46dc70c25ff7e2cf6d09cbb0424fc9978 Version: 043546e46dc70c25ff7e2cf6d09cbb0424fc9978 Version: 043546e46dc70c25ff7e2cf6d09cbb0424fc9978 Version: 043546e46dc70c25ff7e2cf6d09cbb0424fc9978 Version: 043546e46dc70c25ff7e2cf6d09cbb0424fc9978 Version: 043546e46dc70c25ff7e2cf6d09cbb0424fc9978 Version: 043546e46dc70c25ff7e2cf6d09cbb0424fc9978 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/ext4/crypto.c",
"fs/ext4/ialloc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "add98959b220935b243170214c787bc03044a44d",
"status": "affected",
"version": "043546e46dc70c25ff7e2cf6d09cbb0424fc9978",
"versionType": "git"
},
{
"lessThan": "f53b325068bca0b238c3e0d2eb7de9b1f2268cab",
"status": "affected",
"version": "043546e46dc70c25ff7e2cf6d09cbb0424fc9978",
"versionType": "git"
},
{
"lessThan": "5959cad3cfa852ec07bbdaf9c17f4838a94a8e6c",
"status": "affected",
"version": "043546e46dc70c25ff7e2cf6d09cbb0424fc9978",
"versionType": "git"
},
{
"lessThan": "a13f61ba9b2a7a4ff1f140949ccfad23c5313757",
"status": "affected",
"version": "043546e46dc70c25ff7e2cf6d09cbb0424fc9978",
"versionType": "git"
},
{
"lessThan": "ed1cd834da65db127f1c30ff67e78f14825a06c1",
"status": "affected",
"version": "043546e46dc70c25ff7e2cf6d09cbb0424fc9978",
"versionType": "git"
},
{
"lessThan": "458776af0061afec1014cb3cd0061e282e482e83",
"status": "affected",
"version": "043546e46dc70c25ff7e2cf6d09cbb0424fc9978",
"versionType": "git"
},
{
"lessThan": "3392391b363a63ebb531d45318a729b1c998565b",
"status": "affected",
"version": "043546e46dc70c25ff7e2cf6d09cbb0424fc9978",
"versionType": "git"
},
{
"lessThan": "e27bae352158c007143d5bb50f3af33a177c0a37",
"status": "affected",
"version": "043546e46dc70c25ff7e2cf6d09cbb0424fc9978",
"versionType": "git"
},
{
"lessThan": "da32af420d6d466e247c43ac0b829edeac7ae0ad",
"status": "affected",
"version": "043546e46dc70c25ff7e2cf6d09cbb0424fc9978",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/ext4/crypto.c",
"fs/ext4/ialloc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.8"
},
{
"lessThan": "5.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.269",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.220",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.187",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.156",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.108",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.47",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.1",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.269",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.220",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.187",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.156",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.108",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.47",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.11",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.1",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "5.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: don\u0027t enable DAX on new encrypted files\n\nCurrently, when a new encrypted regular file is created, the call to\next4_set_inode_flags(inode, init=true) in __ext4_new_inode() is made\nbefore EXT4_INODE_ENCRYPT is set. As a result, it can set S_DAX if the\nfilesystem is mounted with \"-o dax=always\".\n\nEXT4_INODE_ENCRYPT then actually gets set a bit later in\n__ext4_new_inode(), when it calls fscrypt_set_context() which calls\next4_set_context(). ext4_set_context() sets EXT4_INODE_ENCRYPT and\ncalls ext4_set_inode_flags(inode, init=false) to set S_ENCRYPTED too.\n\nThis was intended to clear S_DAX as well. However, this was broken by\ncommit 043546e46dc7 (\"fs/ext4: Only change S_DAX on inode load\"). This\ncauses data written to the file to bypass encryption, also causing\nxfstests failures such as generic/548 (when \"-o dax=always\" is used).\n\nFix this by simplifying the flow by making __ext4_new_inode() set\nEXT4_INODE_ENCRYPT earlier. This makes it take effect in\next4_set_inode_flags(inode, init=true), making S_DAX never be set.\n\nSimilarly, make EXT4_STATE_MAY_INLINE_DATA never be set in the first\nplace on new encrypted inodes. Then it doesn\u0027t need to be cleared.\n\nAs a result of these simplifications, ext4_set_context() no longer needs\nto change inode flags or state when \u0027handle != NULL\u0027. Remove that too."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T15:13:20.282Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/add98959b220935b243170214c787bc03044a44d"
},
{
"url": "https://git.kernel.org/stable/c/f53b325068bca0b238c3e0d2eb7de9b1f2268cab"
},
{
"url": "https://git.kernel.org/stable/c/5959cad3cfa852ec07bbdaf9c17f4838a94a8e6c"
},
{
"url": "https://git.kernel.org/stable/c/a13f61ba9b2a7a4ff1f140949ccfad23c5313757"
},
{
"url": "https://git.kernel.org/stable/c/ed1cd834da65db127f1c30ff67e78f14825a06c1"
},
{
"url": "https://git.kernel.org/stable/c/458776af0061afec1014cb3cd0061e282e482e83"
},
{
"url": "https://git.kernel.org/stable/c/3392391b363a63ebb531d45318a729b1c998565b"
},
{
"url": "https://git.kernel.org/stable/c/e27bae352158c007143d5bb50f3af33a177c0a37"
},
{
"url": "https://git.kernel.org/stable/c/da32af420d6d466e247c43ac0b829edeac7ae0ad"
}
],
"title": "ext4: don\u0027t enable DAX on new encrypted files",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80806",
"datePublished": "2026-09-04T15:13:20.282Z",
"dateReserved": "2026-08-26T14:34:25.794Z",
"dateUpdated": "2026-09-04T15:13:20.282Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68333 (GCVE-0-2026-68333)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
dpaa2-switch: put MAC endpoint device on disconnect
fsl_mc_get_endpoint() returns the MAC endpoint device with a reference
taken through device_find_child(). The switch port connect path stores
that device in mac->mc_dev and keeps it for the lifetime of the connected
MAC object.
However, the disconnect path only closes the MAC and frees the dpaa2_mac
object. It does not drop the endpoint device reference stored in
mac->mc_dev, so every successful connect leaks that device reference when
the MAC is later disconnected.
Drop the endpoint device reference before freeing the dpaa2_mac object.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 84cba72956fddf29ba666f885c39ed147024c125 Version: 84cba72956fddf29ba666f885c39ed147024c125 Version: 84cba72956fddf29ba666f885c39ed147024c125 Version: 84cba72956fddf29ba666f885c39ed147024c125 Version: 84cba72956fddf29ba666f885c39ed147024c125 Version: 84cba72956fddf29ba666f885c39ed147024c125 Version: 84cba72956fddf29ba666f885c39ed147024c125 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/freescale/dpaa2/dpaa2-switch.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "196f7301537814bef0f5915f87cd73d6d1235c19",
"status": "affected",
"version": "84cba72956fddf29ba666f885c39ed147024c125",
"versionType": "git"
},
{
"lessThan": "0e9a6811eb6198ab17538cd01fa155d133b238ed",
"status": "affected",
"version": "84cba72956fddf29ba666f885c39ed147024c125",
"versionType": "git"
},
{
"lessThan": "1f4ca61b7a93de3dfa5161bcd38ecb99bb091c38",
"status": "affected",
"version": "84cba72956fddf29ba666f885c39ed147024c125",
"versionType": "git"
},
{
"lessThan": "680eecc850d36a280df9780496bc603fec17b2d6",
"status": "affected",
"version": "84cba72956fddf29ba666f885c39ed147024c125",
"versionType": "git"
},
{
"lessThan": "26ac2d3602347f0377fbcd5214bc28a9d735ae68",
"status": "affected",
"version": "84cba72956fddf29ba666f885c39ed147024c125",
"versionType": "git"
},
{
"lessThan": "c27694ff6748e08fcd2fdba89018439d75b8198f",
"status": "affected",
"version": "84cba72956fddf29ba666f885c39ed147024c125",
"versionType": "git"
},
{
"lessThan": "4c1eabbef7a1707635652e956e39db1269c3af2b",
"status": "affected",
"version": "84cba72956fddf29ba666f885c39ed147024c125",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/freescale/dpaa2/dpaa2-switch.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.15"
},
{
"lessThan": "5.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndpaa2-switch: put MAC endpoint device on disconnect\n\nfsl_mc_get_endpoint() returns the MAC endpoint device with a reference\ntaken through device_find_child(). The switch port connect path stores\nthat device in mac-\u003emc_dev and keeps it for the lifetime of the connected\nMAC object.\n\nHowever, the disconnect path only closes the MAC and frees the dpaa2_mac\nobject. It does not drop the endpoint device reference stored in\nmac-\u003emc_dev, so every successful connect leaks that device reference when\nthe MAC is later disconnected.\n\nDrop the endpoint device reference before freeing the dpaa2_mac object."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:30.627Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/196f7301537814bef0f5915f87cd73d6d1235c19"
},
{
"url": "https://git.kernel.org/stable/c/0e9a6811eb6198ab17538cd01fa155d133b238ed"
},
{
"url": "https://git.kernel.org/stable/c/1f4ca61b7a93de3dfa5161bcd38ecb99bb091c38"
},
{
"url": "https://git.kernel.org/stable/c/680eecc850d36a280df9780496bc603fec17b2d6"
},
{
"url": "https://git.kernel.org/stable/c/26ac2d3602347f0377fbcd5214bc28a9d735ae68"
},
{
"url": "https://git.kernel.org/stable/c/c27694ff6748e08fcd2fdba89018439d75b8198f"
},
{
"url": "https://git.kernel.org/stable/c/4c1eabbef7a1707635652e956e39db1269c3af2b"
}
],
"title": "dpaa2-switch: put MAC endpoint device on disconnect",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68333",
"datePublished": "2026-08-10T12:03:09.524Z",
"dateReserved": "2026-07-30T09:28:09.383Z",
"dateUpdated": "2026-08-19T16:33:30.627Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72305 (GCVE-0-2026-72305)
Vulnerability from cvelistv5
Published
2026-08-15 05:55
Modified
2026-08-23 12:47
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
VDUSE: avoid leaking information to userspace
The bounceing is not necessarily page aligned, so current VDUSE can
leak kernel information through mapping bounce pages to
userspace. Allocate bounce pages with __GFP_ZERO to avoid leaking
information to userspace.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 8c773d53fb7b64267b0f55c1d3517cb8c5e29b3c Version: 8c773d53fb7b64267b0f55c1d3517cb8c5e29b3c Version: 8c773d53fb7b64267b0f55c1d3517cb8c5e29b3c Version: 8c773d53fb7b64267b0f55c1d3517cb8c5e29b3c Version: 8c773d53fb7b64267b0f55c1d3517cb8c5e29b3c Version: 8c773d53fb7b64267b0f55c1d3517cb8c5e29b3c Version: 8c773d53fb7b64267b0f55c1d3517cb8c5e29b3c |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/vdpa/vdpa_user/iova_domain.c",
"drivers/vdpa/vdpa_user/vduse_dev.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "41e27a6aca608c9e04f091c29c420d03fafe0313",
"status": "affected",
"version": "8c773d53fb7b64267b0f55c1d3517cb8c5e29b3c",
"versionType": "git"
},
{
"lessThan": "3ae878f262bd1445c8c31511856a99962a05fe16",
"status": "affected",
"version": "8c773d53fb7b64267b0f55c1d3517cb8c5e29b3c",
"versionType": "git"
},
{
"lessThan": "fde25641cbddd0c084e3320d08f755e7e6acfae5",
"status": "affected",
"version": "8c773d53fb7b64267b0f55c1d3517cb8c5e29b3c",
"versionType": "git"
},
{
"lessThan": "5e88c1bc3a41d9a260dd42bae8ad18fd4f35bbe1",
"status": "affected",
"version": "8c773d53fb7b64267b0f55c1d3517cb8c5e29b3c",
"versionType": "git"
},
{
"lessThan": "690fb82c4122f8c2656fa4f842275132771b68b9",
"status": "affected",
"version": "8c773d53fb7b64267b0f55c1d3517cb8c5e29b3c",
"versionType": "git"
},
{
"lessThan": "00335df9da2011e095f846d645cc2e9fd2907659",
"status": "affected",
"version": "8c773d53fb7b64267b0f55c1d3517cb8c5e29b3c",
"versionType": "git"
},
{
"lessThan": "9c1523803445ee0348f62b77793266dd981596e0",
"status": "affected",
"version": "8c773d53fb7b64267b0f55c1d3517cb8c5e29b3c",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/vdpa/vdpa_user/iova_domain.c",
"drivers/vdpa/vdpa_user/vduse_dev.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.15"
},
{
"lessThan": "5.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nVDUSE: avoid leaking information to userspace\n\nThe bounceing is not necessarily page aligned, so current VDUSE can\nleak kernel information through mapping bounce pages to\nuserspace. Allocate bounce pages with __GFP_ZERO to avoid leaking\ninformation to userspace."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:47:13.473Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/41e27a6aca608c9e04f091c29c420d03fafe0313"
},
{
"url": "https://git.kernel.org/stable/c/3ae878f262bd1445c8c31511856a99962a05fe16"
},
{
"url": "https://git.kernel.org/stable/c/fde25641cbddd0c084e3320d08f755e7e6acfae5"
},
{
"url": "https://git.kernel.org/stable/c/5e88c1bc3a41d9a260dd42bae8ad18fd4f35bbe1"
},
{
"url": "https://git.kernel.org/stable/c/690fb82c4122f8c2656fa4f842275132771b68b9"
},
{
"url": "https://git.kernel.org/stable/c/00335df9da2011e095f846d645cc2e9fd2907659"
},
{
"url": "https://git.kernel.org/stable/c/9c1523803445ee0348f62b77793266dd981596e0"
}
],
"title": "VDUSE: avoid leaking information to userspace",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72305",
"datePublished": "2026-08-15T05:55:22.914Z",
"dateReserved": "2026-08-09T03:40:39.918Z",
"dateUpdated": "2026-08-23T12:47:13.473Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68218 (GCVE-0-2026-68218)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: pci: dm1105: Free allocated workqueue
Destroy allocated workqueue in remove() callback to free its resources,
thus fixing memory leak.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 519a4bdcf8221c6b2d129b3c720761b7cab7f2c1 Version: 519a4bdcf8221c6b2d129b3c720761b7cab7f2c1 Version: 519a4bdcf8221c6b2d129b3c720761b7cab7f2c1 Version: 519a4bdcf8221c6b2d129b3c720761b7cab7f2c1 Version: 519a4bdcf8221c6b2d129b3c720761b7cab7f2c1 Version: 519a4bdcf8221c6b2d129b3c720761b7cab7f2c1 Version: 519a4bdcf8221c6b2d129b3c720761b7cab7f2c1 Version: 519a4bdcf8221c6b2d129b3c720761b7cab7f2c1 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/pci/dm1105/dm1105.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "078e0750b5e60277e44d780d70c6997c46569df2",
"status": "affected",
"version": "519a4bdcf8221c6b2d129b3c720761b7cab7f2c1",
"versionType": "git"
},
{
"lessThan": "d97f2e37516aa151582c8b2296021332db6da906",
"status": "affected",
"version": "519a4bdcf8221c6b2d129b3c720761b7cab7f2c1",
"versionType": "git"
},
{
"lessThan": "df5cd8b30c750f4edd0766982437d3472a0dbbd4",
"status": "affected",
"version": "519a4bdcf8221c6b2d129b3c720761b7cab7f2c1",
"versionType": "git"
},
{
"lessThan": "46715fecc38a2d341c3ff680f295de6e8aec72c0",
"status": "affected",
"version": "519a4bdcf8221c6b2d129b3c720761b7cab7f2c1",
"versionType": "git"
},
{
"lessThan": "8d753c8c37afc0910ed5ddc014645b05d6266add",
"status": "affected",
"version": "519a4bdcf8221c6b2d129b3c720761b7cab7f2c1",
"versionType": "git"
},
{
"lessThan": "08ddfd628a2dbd9d385da677afccd893d0ab37e1",
"status": "affected",
"version": "519a4bdcf8221c6b2d129b3c720761b7cab7f2c1",
"versionType": "git"
},
{
"lessThan": "0c2b4c45fce012e88904b8c66b5cd786535c0b8c",
"status": "affected",
"version": "519a4bdcf8221c6b2d129b3c720761b7cab7f2c1",
"versionType": "git"
},
{
"lessThan": "1a65db225b25bb8c8febf16974c060e0cc242eb9",
"status": "affected",
"version": "519a4bdcf8221c6b2d129b3c720761b7cab7f2c1",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/pci/dm1105/dm1105.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.31"
},
{
"lessThan": "2.6.31",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.31",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: pci: dm1105: Free allocated workqueue\n\nDestroy allocated workqueue in remove() callback to free its resources,\nthus fixing memory leak."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:50.280Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/078e0750b5e60277e44d780d70c6997c46569df2"
},
{
"url": "https://git.kernel.org/stable/c/d97f2e37516aa151582c8b2296021332db6da906"
},
{
"url": "https://git.kernel.org/stable/c/df5cd8b30c750f4edd0766982437d3472a0dbbd4"
},
{
"url": "https://git.kernel.org/stable/c/46715fecc38a2d341c3ff680f295de6e8aec72c0"
},
{
"url": "https://git.kernel.org/stable/c/8d753c8c37afc0910ed5ddc014645b05d6266add"
},
{
"url": "https://git.kernel.org/stable/c/08ddfd628a2dbd9d385da677afccd893d0ab37e1"
},
{
"url": "https://git.kernel.org/stable/c/0c2b4c45fce012e88904b8c66b5cd786535c0b8c"
},
{
"url": "https://git.kernel.org/stable/c/1a65db225b25bb8c8febf16974c060e0cc242eb9"
}
],
"title": "media: pci: dm1105: Free allocated workqueue",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68218",
"datePublished": "2026-08-10T12:00:38.175Z",
"dateReserved": "2026-07-30T09:28:09.375Z",
"dateUpdated": "2026-08-19T16:31:50.280Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80586 (GCVE-0-2026-80586)
Vulnerability from cvelistv5
Published
2026-08-26 14:37
Modified
2026-08-27 05:02
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
mptcp: options: reset DSS fields in case of unexpected size
A remote peer could send a malformed DSS with a wrong size, followed by
another DSS or MPC + Data. In this case, the first suboption will be
ignored, but leaving some fields written, which could lead to
inconsistency or access uninitialized data.
Explicitly reset the fields that could have been modified in case of
unexpected size.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 648ef4b88673dadb8463bf0d4b10fbf33d55def8 Version: 648ef4b88673dadb8463bf0d4b10fbf33d55def8 Version: 648ef4b88673dadb8463bf0d4b10fbf33d55def8 Version: 648ef4b88673dadb8463bf0d4b10fbf33d55def8 Version: 648ef4b88673dadb8463bf0d4b10fbf33d55def8 Version: 648ef4b88673dadb8463bf0d4b10fbf33d55def8 Version: 648ef4b88673dadb8463bf0d4b10fbf33d55def8 Version: 648ef4b88673dadb8463bf0d4b10fbf33d55def8 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/mptcp/options.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "15e35fdad7a5576bf3f1c8d688877aeb5d1b506b",
"status": "affected",
"version": "648ef4b88673dadb8463bf0d4b10fbf33d55def8",
"versionType": "git"
},
{
"lessThan": "b1256090816ec46011601e084be580731df58fc7",
"status": "affected",
"version": "648ef4b88673dadb8463bf0d4b10fbf33d55def8",
"versionType": "git"
},
{
"lessThan": "192878df582c51d440bf7b91a15f297f29f2b596",
"status": "affected",
"version": "648ef4b88673dadb8463bf0d4b10fbf33d55def8",
"versionType": "git"
},
{
"lessThan": "26dac5c9ffb20812b475fdf253eb04fab99cff3b",
"status": "affected",
"version": "648ef4b88673dadb8463bf0d4b10fbf33d55def8",
"versionType": "git"
},
{
"lessThan": "4e80eff5c1c893aca2ac1d202f0b256d2e52ecde",
"status": "affected",
"version": "648ef4b88673dadb8463bf0d4b10fbf33d55def8",
"versionType": "git"
},
{
"lessThan": "1fade1b2ac5b1a4948e538fae7313bea57b5ac36",
"status": "affected",
"version": "648ef4b88673dadb8463bf0d4b10fbf33d55def8",
"versionType": "git"
},
{
"lessThan": "27ed642a4e7e4b5df4b8522c72c457a67e052493",
"status": "affected",
"version": "648ef4b88673dadb8463bf0d4b10fbf33d55def8",
"versionType": "git"
},
{
"lessThan": "35772b4981f38ba8059372cde8753e8e477e98ec",
"status": "affected",
"version": "648ef4b88673dadb8463bf0d4b10fbf33d55def8",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/mptcp/options.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.6"
},
{
"lessThan": "5.6",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.46",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.10",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: options: reset DSS fields in case of unexpected size\n\nA remote peer could send a malformed DSS with a wrong size, followed by\nanother DSS or MPC + Data. In this case, the first suboption will be\nignored, but leaving some fields written, which could lead to\ninconsistency or access uninitialized data.\n\nExplicitly reset the fields that could have been modified in case of\nunexpected size."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - Remote attacker sends crafted TCP segments with malformed MPTCP options that are parsed in the softirq receive path (tcp_v4_rcv/tcp_rcv_established/tcp_data_queue/mptcp_incoming_options/mptcp_get_options), requiring only network reachability to an MPTCP-enabled peer.\nAC:L - Attacker fully controls TCP option bytes on an established MPTCP connection and can deterministically send a size-invalid DSS (setting use_ack/use_map flags) immediately followed by MPC+Data or another DSS in the same header; no race or victim-specific state is required.\nPR:N - Only requires the attacker to be the remote MPTCP/TCP peer of a host with CONFIG_MPTCP enabled; no local account, capabilities, or authenticated access on the victim is needed to reach the vulnerable parser.\nUI:N - Exploitation is fully automated over the network once an MPTCP session exists; the kernel processes malicious segments in softirq without any victim user action beyond ordinary connectivity.\nS:U - Impact is limited to kernel networking/MPTCP connection state on the affected host and does not cross VM, container, or IOMMU security boundaries.\nC:H - Malformed DSS leaves use_ack/use_map/dsn64/data_fin set while data_ack and map fields are never read, so ack_update_msk() and DSS handling consume uninitialized stack values and corrupt metadata that can leak kernel memory contents.\nI:H - Stale DSS flag bits cause forged ack advancement of msk-\u003esnd_una/wnd_end/bytes_acked and bogus DATA_FIN/DSN mapping in skb extensions, corrupting rtx queues and silently altering or truncating application data delivery.\nA:H - Bogus ack state triggers __mptcp_clean_una() WARN_ON_ONCE paths outside recovery, can abort or hang MPTCP connections, and may kernel-panic systems built with panic_on_warn."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T05:02:07.204Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/15e35fdad7a5576bf3f1c8d688877aeb5d1b506b"
},
{
"url": "https://git.kernel.org/stable/c/b1256090816ec46011601e084be580731df58fc7"
},
{
"url": "https://git.kernel.org/stable/c/192878df582c51d440bf7b91a15f297f29f2b596"
},
{
"url": "https://git.kernel.org/stable/c/26dac5c9ffb20812b475fdf253eb04fab99cff3b"
},
{
"url": "https://git.kernel.org/stable/c/4e80eff5c1c893aca2ac1d202f0b256d2e52ecde"
},
{
"url": "https://git.kernel.org/stable/c/1fade1b2ac5b1a4948e538fae7313bea57b5ac36"
},
{
"url": "https://git.kernel.org/stable/c/27ed642a4e7e4b5df4b8522c72c457a67e052493"
},
{
"url": "https://git.kernel.org/stable/c/35772b4981f38ba8059372cde8753e8e477e98ec"
}
],
"title": "mptcp: options: reset DSS fields in case of unexpected size",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80586",
"datePublished": "2026-08-26T14:37:41.493Z",
"dateReserved": "2026-08-26T14:34:25.769Z",
"dateUpdated": "2026-08-27T05:02:07.204Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80888 (GCVE-0-2026-80888)
Vulnerability from cvelistv5
Published
2026-09-04 17:11
Modified
2026-09-04 17:11
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/vmwgfx: drop dma_buf reference on foreign-fd prime import
ttm_prime_fd_to_handle() returns -ENOSYS when the imported fd's
dma_buf->ops do not match the ttm_object_device's ops, but does so
without releasing the reference acquired by dma_buf_get(). Any
unprivileged renderD client passing a non-vmwgfx prime fd through the
DRM_VMW_GB_SURFACE_REF{,_EXT} path leaks one dma_buf reference per
call and indefinitely pins the foreign exporter's GEM resources.
Funnel the error path through the existing dma_buf_put() so the
reference is always dropped.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 65981f7681abdf92b25942222b629b9c512d0705 Version: 65981f7681abdf92b25942222b629b9c512d0705 Version: 65981f7681abdf92b25942222b629b9c512d0705 Version: 65981f7681abdf92b25942222b629b9c512d0705 Version: 65981f7681abdf92b25942222b629b9c512d0705 Version: 65981f7681abdf92b25942222b629b9c512d0705 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/vmwgfx/ttm_object.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "619c3cfa88e09603a13d918f754808db2dda7057",
"status": "affected",
"version": "65981f7681abdf92b25942222b629b9c512d0705",
"versionType": "git"
},
{
"lessThan": "c1c22fca0a0896a452a7cb92422d67babd65b4be",
"status": "affected",
"version": "65981f7681abdf92b25942222b629b9c512d0705",
"versionType": "git"
},
{
"lessThan": "a1e972fa94c3a8069e022c67b9d97c7aa7b05293",
"status": "affected",
"version": "65981f7681abdf92b25942222b629b9c512d0705",
"versionType": "git"
},
{
"lessThan": "a8434b145b1e467940334c58c00af241e9494c5f",
"status": "affected",
"version": "65981f7681abdf92b25942222b629b9c512d0705",
"versionType": "git"
},
{
"lessThan": "4df39eb99bb47d1f24d1952c23b21b10988356bf",
"status": "affected",
"version": "65981f7681abdf92b25942222b629b9c512d0705",
"versionType": "git"
},
{
"lessThan": "f739416dc555fa205a785e5135d73fa39b26f35d",
"status": "affected",
"version": "65981f7681abdf92b25942222b629b9c512d0705",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/vmwgfx/ttm_object.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.13"
},
{
"lessThan": "3.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "3.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "3.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "3.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "3.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vmwgfx: drop dma_buf reference on foreign-fd prime import\n\nttm_prime_fd_to_handle() returns -ENOSYS when the imported fd\u0027s\ndma_buf-\u003eops do not match the ttm_object_device\u0027s ops, but does so\nwithout releasing the reference acquired by dma_buf_get(). Any\nunprivileged renderD client passing a non-vmwgfx prime fd through the\nDRM_VMW_GB_SURFACE_REF{,_EXT} path leaks one dma_buf reference per\ncall and indefinitely pins the foreign exporter\u0027s GEM resources.\n\nFunnel the error path through the existing dma_buf_put() so the\nreference is always dropped."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T17:11:04.975Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/619c3cfa88e09603a13d918f754808db2dda7057"
},
{
"url": "https://git.kernel.org/stable/c/c1c22fca0a0896a452a7cb92422d67babd65b4be"
},
{
"url": "https://git.kernel.org/stable/c/a1e972fa94c3a8069e022c67b9d97c7aa7b05293"
},
{
"url": "https://git.kernel.org/stable/c/a8434b145b1e467940334c58c00af241e9494c5f"
},
{
"url": "https://git.kernel.org/stable/c/4df39eb99bb47d1f24d1952c23b21b10988356bf"
},
{
"url": "https://git.kernel.org/stable/c/f739416dc555fa205a785e5135d73fa39b26f35d"
}
],
"title": "drm/vmwgfx: drop dma_buf reference on foreign-fd prime import",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80888",
"datePublished": "2026-09-04T17:11:04.975Z",
"dateReserved": "2026-08-26T14:34:25.799Z",
"dateUpdated": "2026-09-04T17:11:04.975Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80558 (GCVE-0-2026-80558)
Vulnerability from cvelistv5
Published
2026-08-26 14:37
Modified
2026-08-27 05:01
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
libceph: Avoid using invalid osd indices from primary_temp
A corrupted osdmap received from a Ceph monitor or OSD may contain osd
indices in its pg_temp, primary_temp, pg_upmap, and pg_upmap_items parts
that don't exist, i.e., that are greater than max_osd or smaller than
CEPH_HOMELESS_OSD (-1). These indices are used to create the up and
acting set in ceph_pg_to_up_acting_osds(), called from calc_target().
While most of these osd indices are checked, the one from primary_temp
is not. Subsequently, this may lead to calc_target() returning this
(potentially invalid) index as target osd for a (linger) request.
Because the osd_state, osd_weight, and osd_addr arrays only contain
max_osd entries (with indices 0 to max_osd -1), this leads to
out-of-bounds accesses when trying to read values from these arrays.
This patch fixes the issue by adding a check to get_temp_osds(), so that
only valid osd indices from primary_temp are used, and it falls back to
using the primary from pg_temp or the up set if it is invalid.
[ idryomov: changelog ]
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 5e8d4d36bf23bb7baf027c479d54395840219928 Version: 5e8d4d36bf23bb7baf027c479d54395840219928 Version: 5e8d4d36bf23bb7baf027c479d54395840219928 Version: 5e8d4d36bf23bb7baf027c479d54395840219928 Version: 5e8d4d36bf23bb7baf027c479d54395840219928 Version: 5e8d4d36bf23bb7baf027c479d54395840219928 Version: 5e8d4d36bf23bb7baf027c479d54395840219928 Version: 5e8d4d36bf23bb7baf027c479d54395840219928 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ceph/osdmap.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "505fc50b8ff8e687b7e3ef6866269dea27366224",
"status": "affected",
"version": "5e8d4d36bf23bb7baf027c479d54395840219928",
"versionType": "git"
},
{
"lessThan": "1c705fe8e59c6b16f48964973fb23c8ec4735b73",
"status": "affected",
"version": "5e8d4d36bf23bb7baf027c479d54395840219928",
"versionType": "git"
},
{
"lessThan": "dfe1877d351b99eb1b1a62a3fc2d174220e88e20",
"status": "affected",
"version": "5e8d4d36bf23bb7baf027c479d54395840219928",
"versionType": "git"
},
{
"lessThan": "e2ffeec85201b2bb748e99e12539ee1b92f62796",
"status": "affected",
"version": "5e8d4d36bf23bb7baf027c479d54395840219928",
"versionType": "git"
},
{
"lessThan": "6799d4a916ffcb3d450d8440f9fe0f0862f768d6",
"status": "affected",
"version": "5e8d4d36bf23bb7baf027c479d54395840219928",
"versionType": "git"
},
{
"lessThan": "4f392fec075562dc93bb0c69f37423ca2af9b48f",
"status": "affected",
"version": "5e8d4d36bf23bb7baf027c479d54395840219928",
"versionType": "git"
},
{
"lessThan": "e009c5f0ad634c62f5c48a41f1f3c019ecf52555",
"status": "affected",
"version": "5e8d4d36bf23bb7baf027c479d54395840219928",
"versionType": "git"
},
{
"lessThan": "3660b98d1204b419f6a77e9a295f148dcf38d042",
"status": "affected",
"version": "5e8d4d36bf23bb7baf027c479d54395840219928",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ceph/osdmap.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.15"
},
{
"lessThan": "3.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "3.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "3.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "3.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "3.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "3.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.46",
"versionStartIncluding": "3.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.10",
"versionStartIncluding": "3.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: Avoid using invalid osd indices from primary_temp\n\nA corrupted osdmap received from a Ceph monitor or OSD may contain osd\nindices in its pg_temp, primary_temp, pg_upmap, and pg_upmap_items parts\nthat don\u0027t exist, i.e., that are greater than max_osd or smaller than\nCEPH_HOMELESS_OSD (-1). These indices are used to create the up and\nacting set in ceph_pg_to_up_acting_osds(), called from calc_target().\nWhile most of these osd indices are checked, the one from primary_temp\nis not. Subsequently, this may lead to calc_target() returning this\n(potentially invalid) index as target osd for a (linger) request.\nBecause the osd_state, osd_weight, and osd_addr arrays only contain\nmax_osd entries (with indices 0 to max_osd -1), this leads to\nout-of-bounds accesses when trying to read values from these arrays.\n\nThis patch fixes the issue by adding a check to get_temp_osds(), so that\nonly valid osd indices from primary_temp are used, and it falls back to\nusing the primary from pg_temp or the up set if it is invalid.\n\n[ idryomov: changelog ]"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - Malformed primary_temp data arrives in CEPH_MSG_OSD_MAP over TCP from a Ceph monitor (mon_dispatch) or OSD (osd_dispatch); calc_target() then uses the bogus osd index in lookup_create_osd()/reopen_osd() to index osd_addr/osd_state/osd_weight without any local syscall.\nAC:L - A compromised or malicious monitor/OSD can publish an incremental osdmap whose primary_temp sets an osd index \u003e= max_osd for a victim PG; once applied, calc_target() on pending I/O, linger requests, or map-driven resends deterministically uses that invalid index.\nPR:N - The attacker acts as the remote Ceph cluster peer delivering forged osdmaps to an already-connected kernel CephFS/RBD client and needs no local account, capabilities, or user-namespace privileges on the victim host.\nUI:N - Once a kernel Ceph client session exists, osdmap updates are applied automatically and scan_requests/kick_requests recalculate targets without any mount, open, or other victim interaction at exploit time.\nS:U - Impact is confined to kernel libceph client memory and state on the Ceph client host (heap disclosure, misrouted connections, crash); it does not cross VM, IOMMU, or container sandbox boundaries to another security authority.\nC:H - Invalid acting.primary indexes past the end of kmalloc-backed osd_addr, osd_state, and osd_weight arrays, performing out-of-bounds reads of adjacent kernel heap memory that can disclose pointers and other sensitive data.\nI:H - Attacker-chosen osd indices drive out-of-bounds reads whose results are treated as authoritative OSD addresses and state for ceph_con_open() and request routing, corrupting kernel client connection targeting in ways usable for further exploitation.\nA:H - Out-of-bounds reads with large crafted osd indices can fault on unmapped kmalloc slack and trigger kernel oops or panic; misrouted linger and I/O requests also cause persistent, repeatable client failure on each malicious osdmap update."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T05:01:46.707Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/505fc50b8ff8e687b7e3ef6866269dea27366224"
},
{
"url": "https://git.kernel.org/stable/c/1c705fe8e59c6b16f48964973fb23c8ec4735b73"
},
{
"url": "https://git.kernel.org/stable/c/dfe1877d351b99eb1b1a62a3fc2d174220e88e20"
},
{
"url": "https://git.kernel.org/stable/c/e2ffeec85201b2bb748e99e12539ee1b92f62796"
},
{
"url": "https://git.kernel.org/stable/c/6799d4a916ffcb3d450d8440f9fe0f0862f768d6"
},
{
"url": "https://git.kernel.org/stable/c/4f392fec075562dc93bb0c69f37423ca2af9b48f"
},
{
"url": "https://git.kernel.org/stable/c/e009c5f0ad634c62f5c48a41f1f3c019ecf52555"
},
{
"url": "https://git.kernel.org/stable/c/3660b98d1204b419f6a77e9a295f148dcf38d042"
}
],
"title": "libceph: Avoid using invalid osd indices from primary_temp",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80558",
"datePublished": "2026-08-26T14:37:24.768Z",
"dateReserved": "2026-08-26T14:34:25.767Z",
"dateUpdated": "2026-08-27T05:01:46.707Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64584 (GCVE-0-2026-64584)
Vulnerability from cvelistv5
Published
2026-08-06 07:06
Modified
2026-08-19 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: f_midi: cancel pending IN work before freeing the midi object
The f_midi driver embeds a work item (midi->work) whose handler,
f_midi_in_work(), dereferences the enclosing struct f_midi through
container_of(). This work is armed from two sites: f_midi_complete(),
on a normal IN-endpoint completion, and f_midi_in_trigger(), on an ALSA
rawmidi output-stream start.
Neither f_midi_disable() nor f_midi_unbind() cancels midi->work.
f_midi_disable() only disables the endpoints and drains the in_req_fifo;
it does not synchronize the work item, and the sound card is released
asynchronously to the final free of the midi object.
The midi object is reference-counted (midi->free_ref) and is freed in
f_midi_free() only once both the usb_function reference and the rawmidi
private_data reference have been dropped. In f_midi_unbind(),
f_midi_disable() runs before the sound card is released, so while the
USB endpoints are already disabled the rawmidi device is still usable by
an open substream. A concurrent userspace write on such a substream can
reach f_midi_in_trigger() and queue midi->work again after
f_midi_disable() has returned. A work item armed this way may still be
pending when the last reference drops and f_midi_free() proceeds to
kfree(midi), letting f_midi_in_work() dereference the struct after it
has been freed, a use-after-free.
For this reason cancelling midi->work in f_midi_disable() would not be
sufficient: the ALSA trigger path can rearm the work after disable()
returns. Cancelling at the refcount-zero free site is the boundary
after which neither arming source can survive, because by then both
references that keep the midi object alive have been dropped: the USB
endpoints are already disabled and the rawmidi device has been released.
Fix this by calling cancel_work_sync(&midi->work) in the refcount-zero
block of f_midi_free(), before the embedded work_struct is freed along
with the rest of the structure. opts->lock is a sleeping mutex, so
calling cancel_work_sync() under it is permitted, and the handler takes
midi->transmit_lock rather than opts->lock, so no self-deadlock can
occur while it waits for a running instance of the work to finish.
This issue was found by an in-house static analysis tool.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 3635523e9b96213969693c320302d536774d8e9b Version: 8653d71ce3763aedcf3d2331f59beda3fecd79e4 Version: 8653d71ce3763aedcf3d2331f59beda3fecd79e4 Version: 8653d71ce3763aedcf3d2331f59beda3fecd79e4 Version: 8653d71ce3763aedcf3d2331f59beda3fecd79e4 Version: 8653d71ce3763aedcf3d2331f59beda3fecd79e4 Version: 8653d71ce3763aedcf3d2331f59beda3fecd79e4 Version: 8653d71ce3763aedcf3d2331f59beda3fecd79e4 Version: 89019ab7a64fcdf98a2ba7799e5c6aff58d4a05d Version: 5.10.235 ≤ Version: 5.4.291 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/gadget/function/f_midi.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "f3c6f2c38062703d3dc7f86958bb0790c6959add",
"status": "affected",
"version": "3635523e9b96213969693c320302d536774d8e9b",
"versionType": "git"
},
{
"lessThan": "df18150126f66817e4d3f79f309e9c92d6ff384e",
"status": "affected",
"version": "8653d71ce3763aedcf3d2331f59beda3fecd79e4",
"versionType": "git"
},
{
"lessThan": "620955b222c47332297d6bf38f78541aa699238a",
"status": "affected",
"version": "8653d71ce3763aedcf3d2331f59beda3fecd79e4",
"versionType": "git"
},
{
"lessThan": "380b4bef46c2eb260c7a9c6bb2c5be33ce5a38f9",
"status": "affected",
"version": "8653d71ce3763aedcf3d2331f59beda3fecd79e4",
"versionType": "git"
},
{
"lessThan": "87bc316dd6fc90072297c635e10b9aa6075ecda1",
"status": "affected",
"version": "8653d71ce3763aedcf3d2331f59beda3fecd79e4",
"versionType": "git"
},
{
"lessThan": "f45089eaad0a083d71d84ff175741d7e157d9b69",
"status": "affected",
"version": "8653d71ce3763aedcf3d2331f59beda3fecd79e4",
"versionType": "git"
},
{
"lessThan": "ac9a51d910bb7465c554c45320cb6c09f3d0b49d",
"status": "affected",
"version": "8653d71ce3763aedcf3d2331f59beda3fecd79e4",
"versionType": "git"
},
{
"lessThan": "5650c18d93a1db7e27cb5a40b394747eb4686d5b",
"status": "affected",
"version": "8653d71ce3763aedcf3d2331f59beda3fecd79e4",
"versionType": "git"
},
{
"status": "affected",
"version": "89019ab7a64fcdf98a2ba7799e5c6aff58d4a05d",
"versionType": "git"
},
{
"lessThan": "5.10.265",
"status": "affected",
"version": "5.10.235",
"versionType": "semver"
},
{
"lessThan": "5.5",
"status": "affected",
"version": "5.4.291",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/usb/gadget/function/f_midi.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.12"
},
{
"lessThan": "5.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.10.235",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.4.291",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: f_midi: cancel pending IN work before freeing the midi object\n\nThe f_midi driver embeds a work item (midi-\u003ework) whose handler,\nf_midi_in_work(), dereferences the enclosing struct f_midi through\ncontainer_of(). This work is armed from two sites: f_midi_complete(),\non a normal IN-endpoint completion, and f_midi_in_trigger(), on an ALSA\nrawmidi output-stream start.\n\nNeither f_midi_disable() nor f_midi_unbind() cancels midi-\u003ework.\nf_midi_disable() only disables the endpoints and drains the in_req_fifo;\nit does not synchronize the work item, and the sound card is released\nasynchronously to the final free of the midi object.\n\nThe midi object is reference-counted (midi-\u003efree_ref) and is freed in\nf_midi_free() only once both the usb_function reference and the rawmidi\nprivate_data reference have been dropped. In f_midi_unbind(),\nf_midi_disable() runs before the sound card is released, so while the\nUSB endpoints are already disabled the rawmidi device is still usable by\nan open substream. A concurrent userspace write on such a substream can\nreach f_midi_in_trigger() and queue midi-\u003ework again after\nf_midi_disable() has returned. A work item armed this way may still be\npending when the last reference drops and f_midi_free() proceeds to\nkfree(midi), letting f_midi_in_work() dereference the struct after it\nhas been freed, a use-after-free.\n\nFor this reason cancelling midi-\u003ework in f_midi_disable() would not be\nsufficient: the ALSA trigger path can rearm the work after disable()\nreturns. Cancelling at the refcount-zero free site is the boundary\nafter which neither arming source can survive, because by then both\nreferences that keep the midi object alive have been dropped: the USB\nendpoints are already disabled and the rawmidi device has been released.\n\nFix this by calling cancel_work_sync(\u0026midi-\u003ework) in the refcount-zero\nblock of f_midi_free(), before the embedded work_struct is freed along\nwith the rest of the structure. opts-\u003elock is a sleeping mutex, so\ncalling cancel_work_sync() under it is permitted, and the handler takes\nmidi-\u003etransmit_lock rather than opts-\u003elock, so no self-deadlock can\noccur while it waits for a running instance of the work to finish.\n\nThis issue was found by an in-house static analysis tool."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The UAF is reached by local configfs UDC clear or function unlink (unregister_gadget \u2192 f_midi_unbind/disable) plus ALSA rawmidi write/close on /dev/snd/midi*; no USB host traffic or cable access is required, and dummy_hcd suffices, matching other gadget teardown UAFs scored AV:L.\nAC:L - The attacker controls both sides of the race: opening/writing the rawmidi substream to queue midi-\u003ework via f_midi_in_trigger after disable, and forcing unbind plus dropping the last free_ref via configfs unlink/close, so the window is freely repeatable.\nPR:L - Exploitation needs access to the gadget configfs tree and/or the ALSA MIDI node; both are routinely delegated to non-root system/audio accounts on Android and embedded MIDI gadgets, with no capability check on the rawmidi write or UDC store path itself.\nUI:N - The attacker performs the full sequence\u2014configfs unbind/unlink, rawmidi write to rearm work, and close to free the midi object\u2014without any action by another user or administrator.\nS:U - The use-after-free corrupts kernel heap within the same kernel security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - f_midi_in_work() container_of()s the freed embedded work_struct and then reads midi-\u003ein_ep, fifo, and port/substream fields; reclaiming the freed f_midi slab yields a classic UAF read/disclosure primitive.\nI:H - Post-free f_midi_transmit()/f_midi_drop_out_substreams() write through the reclaimed object (port state, kfifo, snd_rawmidi_drop_output), giving a heap write-after-free primitive suitable for control-flow hijack.\nA:H - Dereferencing the freed f_midi from system_highpri_wq reliably produces KASAN reports, oops, or kernel panic even without full exploitation."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:29:12.890Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/f3c6f2c38062703d3dc7f86958bb0790c6959add"
},
{
"url": "https://git.kernel.org/stable/c/df18150126f66817e4d3f79f309e9c92d6ff384e"
},
{
"url": "https://git.kernel.org/stable/c/620955b222c47332297d6bf38f78541aa699238a"
},
{
"url": "https://git.kernel.org/stable/c/380b4bef46c2eb260c7a9c6bb2c5be33ce5a38f9"
},
{
"url": "https://git.kernel.org/stable/c/87bc316dd6fc90072297c635e10b9aa6075ecda1"
},
{
"url": "https://git.kernel.org/stable/c/f45089eaad0a083d71d84ff175741d7e157d9b69"
},
{
"url": "https://git.kernel.org/stable/c/ac9a51d910bb7465c554c45320cb6c09f3d0b49d"
},
{
"url": "https://git.kernel.org/stable/c/5650c18d93a1db7e27cb5a40b394747eb4686d5b"
}
],
"title": "usb: gadget: f_midi: cancel pending IN work before freeing the midi object",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64584",
"datePublished": "2026-08-06T07:06:25.953Z",
"dateReserved": "2026-07-19T15:36:31.798Z",
"dateUpdated": "2026-08-19T16:29:12.890Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80819 (GCVE-0-2026-80819)
Vulnerability from cvelistv5
Published
2026-09-04 15:13
Modified
2026-09-04 15:13
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept
rfcomm_sock_recvmsg() completes a deferred setup by calling
rfcomm_dlc_accept() without holding any RFCOMM lock:
if (test_and_clear_bit(RFCOMM_DEFER_SETUP, &d->flags)) {
rfcomm_dlc_accept(d);
return 0;
}
and rfcomm_dlc_accept() dereferences the session on its first line:
struct sock *sk = d->session->sock->sk;
Every other path that touches d->session runs under rfcomm_mutex:
rfcomm_dlc_open(), rfcomm_dlc_close(), rfcomm_dlc_exists(),
rfcomm_dlc_send_rpn(), and the RFCOMM thread through
rfcomm_process_sessions(). rfcomm_connect_ind() is even documented as
"called under rfcomm_lock()". This call site is the only one that skips
it.
The RFCOMM_DEFER_SETUP bit looks like it serialises the accept against
teardown, since __rfcomm_dlc_close() returns early when it wins the
test_and_clear. But rfcomm_recv_disc() forces the state first:
d->state = BT_CLOSED;
__rfcomm_dlc_close(d, err);
and the early return only covers BT_CONNECT, BT_CONFIG, BT_OPEN and
BT_CONNECT2. With the state already BT_CLOSED that switch does not
match, the bit is never consulted, and __rfcomm_dlc_close() falls
through to rfcomm_dlc_unlink(), which sets d->session = NULL.
So a remote DISC on a deferred dlc clears the session while leaving
RFCOMM_DEFER_SETUP set. The next recvmsg() then passes the
test_and_clear and dereferences a NULL session. No timing window is
needed: once the DISC has been processed, the dereference is
unconditional.
Give rfcomm_dlc_accept() the same shape as rfcomm_dlc_open() and
rfcomm_dlc_close(): an exported wrapper that takes rfcomm_mutex and
re-checks the session, around a __rfcomm_dlc_accept() that the two
in-core callers, which already hold the mutex, keep using.
Reproduced on a KASAN + PROVE_LOCKING kernel with a BR/EDR peer emulated
over /dev/vhci: the peer brings up an ACL link, opens L2CAP on the
RFCOMM PSM, starts a session, opens a dlc on a channel bound with
BT_DEFER_SETUP, and sends DISC after the socket is accepted. recv() on
the accepted socket then hits:
Oops: general protection fault
KASAN: null-ptr-deref in range [0x0000000000000010-0x0000000000000017]
RIP: 0010:rfcomm_dlc_accept+0x54/0x350
Call Trace:
rfcomm_sock_recvmsg+0x1cd/0x230
sock_recvmsg+0x166/0x1c0
__sys_recvfrom+0x20d/0x300
0x10 is the offset of sock in struct rfcomm_session. With this patch the
same run completes with recv() returning 0 and no report, and lockdep
stays quiet, confirming rfcomm_mutex is still taken before lock_sock on
this path as it is on the thread side.
References
| URL | Tags | ||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: bb23c0ab824653be4aa7dfca15b07b3059717004 Version: bb23c0ab824653be4aa7dfca15b07b3059717004 Version: bb23c0ab824653be4aa7dfca15b07b3059717004 Version: bb23c0ab824653be4aa7dfca15b07b3059717004 Version: bb23c0ab824653be4aa7dfca15b07b3059717004 Version: bb23c0ab824653be4aa7dfca15b07b3059717004 Version: bb23c0ab824653be4aa7dfca15b07b3059717004 Version: bb23c0ab824653be4aa7dfca15b07b3059717004 Version: bb23c0ab824653be4aa7dfca15b07b3059717004 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/bluetooth/rfcomm/core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "d8d686dd5662a7c4745e4515f1237a9f3b7df181",
"status": "affected",
"version": "bb23c0ab824653be4aa7dfca15b07b3059717004",
"versionType": "git"
},
{
"lessThan": "eb71d5a1ea8ff2683e394b48ae3cd676037ab4c2",
"status": "affected",
"version": "bb23c0ab824653be4aa7dfca15b07b3059717004",
"versionType": "git"
},
{
"lessThan": "56f0aa75c7640e46397ef73bea251fcbef9150c0",
"status": "affected",
"version": "bb23c0ab824653be4aa7dfca15b07b3059717004",
"versionType": "git"
},
{
"lessThan": "362726c9c6e56eea4262109183e49868c39ccd3a",
"status": "affected",
"version": "bb23c0ab824653be4aa7dfca15b07b3059717004",
"versionType": "git"
},
{
"lessThan": "825b95561d7b7c393df9e7bc295451aaeadc3d18",
"status": "affected",
"version": "bb23c0ab824653be4aa7dfca15b07b3059717004",
"versionType": "git"
},
{
"lessThan": "d4b1a13b1eff2e80925c7368ffdeaaa50cba93df",
"status": "affected",
"version": "bb23c0ab824653be4aa7dfca15b07b3059717004",
"versionType": "git"
},
{
"lessThan": "355bfd57ca4ca881c6eb03ca813b440a094b1f44",
"status": "affected",
"version": "bb23c0ab824653be4aa7dfca15b07b3059717004",
"versionType": "git"
},
{
"lessThan": "b405c2f96ae2e37375105881890f7738833b1d62",
"status": "affected",
"version": "bb23c0ab824653be4aa7dfca15b07b3059717004",
"versionType": "git"
},
{
"lessThan": "43a556b2fd43f2df6dded59c2e26560a27874c24",
"status": "affected",
"version": "bb23c0ab824653be4aa7dfca15b07b3059717004",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/bluetooth/rfcomm/core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.30"
},
{
"lessThan": "2.6.30",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.267",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.218",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.185",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.154",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.106",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.47",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.1",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.267",
"versionStartIncluding": "2.6.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.218",
"versionStartIncluding": "2.6.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.185",
"versionStartIncluding": "2.6.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.154",
"versionStartIncluding": "2.6.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.106",
"versionStartIncluding": "2.6.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.47",
"versionStartIncluding": "2.6.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.11",
"versionStartIncluding": "2.6.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.1",
"versionStartIncluding": "2.6.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "2.6.30",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept\n\nrfcomm_sock_recvmsg() completes a deferred setup by calling\nrfcomm_dlc_accept() without holding any RFCOMM lock:\n\n\tif (test_and_clear_bit(RFCOMM_DEFER_SETUP, \u0026d-\u003eflags)) {\n\t\trfcomm_dlc_accept(d);\n\t\treturn 0;\n\t}\n\nand rfcomm_dlc_accept() dereferences the session on its first line:\n\n\tstruct sock *sk = d-\u003esession-\u003esock-\u003esk;\n\nEvery other path that touches d-\u003esession runs under rfcomm_mutex:\nrfcomm_dlc_open(), rfcomm_dlc_close(), rfcomm_dlc_exists(),\nrfcomm_dlc_send_rpn(), and the RFCOMM thread through\nrfcomm_process_sessions(). rfcomm_connect_ind() is even documented as\n\"called under rfcomm_lock()\". This call site is the only one that skips\nit.\n\nThe RFCOMM_DEFER_SETUP bit looks like it serialises the accept against\nteardown, since __rfcomm_dlc_close() returns early when it wins the\ntest_and_clear. But rfcomm_recv_disc() forces the state first:\n\n\td-\u003estate = BT_CLOSED;\n\t__rfcomm_dlc_close(d, err);\n\nand the early return only covers BT_CONNECT, BT_CONFIG, BT_OPEN and\nBT_CONNECT2. With the state already BT_CLOSED that switch does not\nmatch, the bit is never consulted, and __rfcomm_dlc_close() falls\nthrough to rfcomm_dlc_unlink(), which sets d-\u003esession = NULL.\n\nSo a remote DISC on a deferred dlc clears the session while leaving\nRFCOMM_DEFER_SETUP set. The next recvmsg() then passes the\ntest_and_clear and dereferences a NULL session. No timing window is\nneeded: once the DISC has been processed, the dereference is\nunconditional.\n\nGive rfcomm_dlc_accept() the same shape as rfcomm_dlc_open() and\nrfcomm_dlc_close(): an exported wrapper that takes rfcomm_mutex and\nre-checks the session, around a __rfcomm_dlc_accept() that the two\nin-core callers, which already hold the mutex, keep using.\n\nReproduced on a KASAN + PROVE_LOCKING kernel with a BR/EDR peer emulated\nover /dev/vhci: the peer brings up an ACL link, opens L2CAP on the\nRFCOMM PSM, starts a session, opens a dlc on a channel bound with\nBT_DEFER_SETUP, and sends DISC after the socket is accepted. recv() on\nthe accepted socket then hits:\n\n Oops: general protection fault\n KASAN: null-ptr-deref in range [0x0000000000000010-0x0000000000000017]\n RIP: 0010:rfcomm_dlc_accept+0x54/0x350\n Call Trace:\n rfcomm_sock_recvmsg+0x1cd/0x230\n sock_recvmsg+0x166/0x1c0\n __sys_recvfrom+0x20d/0x300\n\n0x10 is the offset of sock in struct rfcomm_session. With this patch the\nsame run completes with recv() returning 0 and no report, and lockdep\nstays quiet, confirming rfcomm_mutex is still taken before lock_sock on\nthis path as it is on the thread side."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T15:13:40.309Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/d8d686dd5662a7c4745e4515f1237a9f3b7df181"
},
{
"url": "https://git.kernel.org/stable/c/eb71d5a1ea8ff2683e394b48ae3cd676037ab4c2"
},
{
"url": "https://git.kernel.org/stable/c/56f0aa75c7640e46397ef73bea251fcbef9150c0"
},
{
"url": "https://git.kernel.org/stable/c/362726c9c6e56eea4262109183e49868c39ccd3a"
},
{
"url": "https://git.kernel.org/stable/c/825b95561d7b7c393df9e7bc295451aaeadc3d18"
},
{
"url": "https://git.kernel.org/stable/c/d4b1a13b1eff2e80925c7368ffdeaaa50cba93df"
},
{
"url": "https://git.kernel.org/stable/c/355bfd57ca4ca881c6eb03ca813b440a094b1f44"
},
{
"url": "https://git.kernel.org/stable/c/b405c2f96ae2e37375105881890f7738833b1d62"
},
{
"url": "https://git.kernel.org/stable/c/43a556b2fd43f2df6dded59c2e26560a27874c24"
}
],
"title": "Bluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80819",
"datePublished": "2026-09-04T15:13:40.309Z",
"dateReserved": "2026-08-26T14:34:25.795Z",
"dateUpdated": "2026-09-04T15:13:40.309Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68422 (GCVE-0-2026-68422)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-19 16:35
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots()
If we have an unexpected reloc_root for our root, we jump to the out label
but never drop the reference we obtained for root, resulting in a leak.
Add a missing btrfs_put_root() call.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 24213fa46c7080c31d79aa2e3e2f0d9480cab700 Version: 24213fa46c7080c31d79aa2e3e2f0d9480cab700 Version: 24213fa46c7080c31d79aa2e3e2f0d9480cab700 Version: 24213fa46c7080c31d79aa2e3e2f0d9480cab700 Version: 24213fa46c7080c31d79aa2e3e2f0d9480cab700 Version: 24213fa46c7080c31d79aa2e3e2f0d9480cab700 Version: 24213fa46c7080c31d79aa2e3e2f0d9480cab700 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/btrfs/relocation.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "f89df93e8aefa4c1c813f835559f2ac727f79766",
"status": "affected",
"version": "24213fa46c7080c31d79aa2e3e2f0d9480cab700",
"versionType": "git"
},
{
"lessThan": "3f586b4c92e4272fcd01bf0db0590b63acf3e85b",
"status": "affected",
"version": "24213fa46c7080c31d79aa2e3e2f0d9480cab700",
"versionType": "git"
},
{
"lessThan": "b3d39b03799600c76c33486e2d29b73a771023db",
"status": "affected",
"version": "24213fa46c7080c31d79aa2e3e2f0d9480cab700",
"versionType": "git"
},
{
"lessThan": "72f673d1c1deb819554d3e7e154f6d84301eb735",
"status": "affected",
"version": "24213fa46c7080c31d79aa2e3e2f0d9480cab700",
"versionType": "git"
},
{
"lessThan": "60a23d4ea169e27403f3bb023bb98036797c0206",
"status": "affected",
"version": "24213fa46c7080c31d79aa2e3e2f0d9480cab700",
"versionType": "git"
},
{
"lessThan": "7591d1727067d6063247901ad25c4bdc4e5695c4",
"status": "affected",
"version": "24213fa46c7080c31d79aa2e3e2f0d9480cab700",
"versionType": "git"
},
{
"lessThan": "ce6050bafb4e33377dc17fcc357736bfc351180c",
"status": "affected",
"version": "24213fa46c7080c31d79aa2e3e2f0d9480cab700",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/btrfs/relocation.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.13"
},
{
"lessThan": "5.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots()\n\nIf we have an unexpected reloc_root for our root, we jump to the out label\nbut never drop the reference we obtained for root, resulting in a leak.\nAdd a missing btrfs_put_root() call."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:35:17.540Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/f89df93e8aefa4c1c813f835559f2ac727f79766"
},
{
"url": "https://git.kernel.org/stable/c/3f586b4c92e4272fcd01bf0db0590b63acf3e85b"
},
{
"url": "https://git.kernel.org/stable/c/b3d39b03799600c76c33486e2d29b73a771023db"
},
{
"url": "https://git.kernel.org/stable/c/72f673d1c1deb819554d3e7e154f6d84301eb735"
},
{
"url": "https://git.kernel.org/stable/c/60a23d4ea169e27403f3bb023bb98036797c0206"
},
{
"url": "https://git.kernel.org/stable/c/7591d1727067d6063247901ad25c4bdc4e5695c4"
},
{
"url": "https://git.kernel.org/stable/c/ce6050bafb4e33377dc17fcc357736bfc351180c"
}
],
"title": "btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68422",
"datePublished": "2026-08-10T12:04:42.949Z",
"dateReserved": "2026-07-30T09:28:09.392Z",
"dateUpdated": "2026-08-19T16:35:17.540Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68217 (GCVE-0-2026-68217)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: pwc: Drain fill_buf on start_streaming() failure
pwc_isoc_init() submits its isochronous URBs with
usb_submit_urb(.., GFP_KERNEL) in a loop. After the first URB is
submitted, its completion handler pwc_isoc_handler() can run on another
CPU before the loop finishes:
start_streaming()
pwc_isoc_init()
usb_submit_urb(urbs[0], GFP_KERNEL)
pwc_isoc_handler(urbs[0])
pdev->fill_buf =
pwc_get_next_fill_buf(pdev)
usb_submit_urb(urbs[i>0], ..) -> fails
pwc_isoc_cleanup(pdev) /* kills URBs */
return ret;
pwc_cleanup_queued_bufs(pdev, VB2_BUF_STATE_QUEUED)
pwc_get_next_fill_buf() detaches a buffer from pdev->queued_bufs and
stores it in pdev->fill_buf. The error path in start_streaming() only
drains pdev->queued_bufs, so the buffer parked in pdev->fill_buf is
leaked. vb2_start_streaming() then triggers
WARN_ON(owned_by_drv_count).
stop_streaming() already handles this since commit 80b0963e1698
("[media] pwc: fix WARN_ON"), which added the fill_buf drain in the
teardown path but not in the start_streaming() error path. Mirror that
handling on failure so start_streaming() returns with no buffer owned
by the driver.
Issue identified by automated review of the INV-003 series at
https://sashiko.dev/
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 885fe18f5542fe283a17f70583383c6cadcba1c3 Version: 885fe18f5542fe283a17f70583383c6cadcba1c3 Version: 885fe18f5542fe283a17f70583383c6cadcba1c3 Version: 885fe18f5542fe283a17f70583383c6cadcba1c3 Version: 885fe18f5542fe283a17f70583383c6cadcba1c3 Version: 885fe18f5542fe283a17f70583383c6cadcba1c3 Version: 885fe18f5542fe283a17f70583383c6cadcba1c3 Version: 885fe18f5542fe283a17f70583383c6cadcba1c3 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/usb/pwc/pwc-if.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "97f3c15957ec7e6d249f05407ad947c0644df24d",
"status": "affected",
"version": "885fe18f5542fe283a17f70583383c6cadcba1c3",
"versionType": "git"
},
{
"lessThan": "a4afffd148991a826e8995362fb10cf8705c1130",
"status": "affected",
"version": "885fe18f5542fe283a17f70583383c6cadcba1c3",
"versionType": "git"
},
{
"lessThan": "eabe9a59640698137d7382d5b549e95dc37f7565",
"status": "affected",
"version": "885fe18f5542fe283a17f70583383c6cadcba1c3",
"versionType": "git"
},
{
"lessThan": "a56e7641e09bd80b976e944ae759109b86fd5b38",
"status": "affected",
"version": "885fe18f5542fe283a17f70583383c6cadcba1c3",
"versionType": "git"
},
{
"lessThan": "acc789b2173070638cad89c2b61d33ed338be0dd",
"status": "affected",
"version": "885fe18f5542fe283a17f70583383c6cadcba1c3",
"versionType": "git"
},
{
"lessThan": "9afd605dcd96c7a45f338eded1de16679b30e1df",
"status": "affected",
"version": "885fe18f5542fe283a17f70583383c6cadcba1c3",
"versionType": "git"
},
{
"lessThan": "5d4812668b03f823b5044789d6aa77fe56b42587",
"status": "affected",
"version": "885fe18f5542fe283a17f70583383c6cadcba1c3",
"versionType": "git"
},
{
"lessThan": "906e410dcffbbd99fb4081abab817a830033aa28",
"status": "affected",
"version": "885fe18f5542fe283a17f70583383c6cadcba1c3",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/usb/pwc/pwc-if.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.1"
},
{
"lessThan": "3.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: pwc: Drain fill_buf on start_streaming() failure\n\npwc_isoc_init() submits its isochronous URBs with\nusb_submit_urb(.., GFP_KERNEL) in a loop. After the first URB is\nsubmitted, its completion handler pwc_isoc_handler() can run on another\nCPU before the loop finishes:\n\n start_streaming()\n pwc_isoc_init()\n usb_submit_urb(urbs[0], GFP_KERNEL)\n pwc_isoc_handler(urbs[0])\n pdev-\u003efill_buf =\n pwc_get_next_fill_buf(pdev)\n usb_submit_urb(urbs[i\u003e0], ..) -\u003e fails\n pwc_isoc_cleanup(pdev) /* kills URBs */\n return ret;\n pwc_cleanup_queued_bufs(pdev, VB2_BUF_STATE_QUEUED)\n\npwc_get_next_fill_buf() detaches a buffer from pdev-\u003equeued_bufs and\nstores it in pdev-\u003efill_buf. The error path in start_streaming() only\ndrains pdev-\u003equeued_bufs, so the buffer parked in pdev-\u003efill_buf is\nleaked. vb2_start_streaming() then triggers\nWARN_ON(owned_by_drv_count).\n\nstop_streaming() already handles this since commit 80b0963e1698\n(\"[media] pwc: fix WARN_ON\"), which added the fill_buf drain in the\nteardown path but not in the start_streaming() error path. Mirror that\nhandling on failure so start_streaming() returns with no buffer owned\nby the driver.\n\nIssue identified by automated review of the INV-003 series at\nhttps://sashiko.dev/"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:48.858Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/97f3c15957ec7e6d249f05407ad947c0644df24d"
},
{
"url": "https://git.kernel.org/stable/c/a4afffd148991a826e8995362fb10cf8705c1130"
},
{
"url": "https://git.kernel.org/stable/c/eabe9a59640698137d7382d5b549e95dc37f7565"
},
{
"url": "https://git.kernel.org/stable/c/a56e7641e09bd80b976e944ae759109b86fd5b38"
},
{
"url": "https://git.kernel.org/stable/c/acc789b2173070638cad89c2b61d33ed338be0dd"
},
{
"url": "https://git.kernel.org/stable/c/9afd605dcd96c7a45f338eded1de16679b30e1df"
},
{
"url": "https://git.kernel.org/stable/c/5d4812668b03f823b5044789d6aa77fe56b42587"
},
{
"url": "https://git.kernel.org/stable/c/906e410dcffbbd99fb4081abab817a830033aa28"
}
],
"title": "media: pwc: Drain fill_buf on start_streaming() failure",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68217",
"datePublished": "2026-08-10T12:00:36.773Z",
"dateReserved": "2026-07-30T09:28:09.375Z",
"dateUpdated": "2026-08-19T16:31:48.858Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74626 (GCVE-0-2026-74626)
Vulnerability from cvelistv5
Published
2026-08-22 15:32
Modified
2026-08-27 12:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
NTB: ntb_netdev: Preserve RX queue depth on allocation failure
ntb_netdev_rx_handler() hands the received skb to the network stack
before allocating its replacement. If the allocation fails, nothing is
reposted. Every failure therefore takes one buffer out of the RX queue
while the interface remains up, and enough failures eventually stall
reception.
A retry path could refill the queue later, but ntb_netdev has none.
Allocate the replacement first instead. If that fails, drop the packet
and repost the same skb. This keeps the queue full and lets packet
delivery resume as soon as memory is available again.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 548c237c0a9972df5d1afaca38aa733ee577128d Version: 548c237c0a9972df5d1afaca38aa733ee577128d Version: 548c237c0a9972df5d1afaca38aa733ee577128d Version: 548c237c0a9972df5d1afaca38aa733ee577128d Version: 548c237c0a9972df5d1afaca38aa733ee577128d Version: 548c237c0a9972df5d1afaca38aa733ee577128d Version: 548c237c0a9972df5d1afaca38aa733ee577128d Version: 548c237c0a9972df5d1afaca38aa733ee577128d |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ntb_netdev.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "6d7f8a23c130d768c0976c2578b214353674e18f",
"status": "affected",
"version": "548c237c0a9972df5d1afaca38aa733ee577128d",
"versionType": "git"
},
{
"lessThan": "18781cc0bfb5c7f2a51ac6d678a28f101b7c35c5",
"status": "affected",
"version": "548c237c0a9972df5d1afaca38aa733ee577128d",
"versionType": "git"
},
{
"lessThan": "272df0fbe6f3e04e22bc67fbdd9ac24586b942f4",
"status": "affected",
"version": "548c237c0a9972df5d1afaca38aa733ee577128d",
"versionType": "git"
},
{
"lessThan": "fcaf8ba7e56bb73319ac107a63b907d59536192c",
"status": "affected",
"version": "548c237c0a9972df5d1afaca38aa733ee577128d",
"versionType": "git"
},
{
"lessThan": "3f2a15f33f86f7bd5b920669fd40c06725d72a1e",
"status": "affected",
"version": "548c237c0a9972df5d1afaca38aa733ee577128d",
"versionType": "git"
},
{
"lessThan": "a4e340971fe8ccd245d206db4d43b2a0eec240bd",
"status": "affected",
"version": "548c237c0a9972df5d1afaca38aa733ee577128d",
"versionType": "git"
},
{
"lessThan": "755fd7843f300d724caceabdf9bb13adc8701540",
"status": "affected",
"version": "548c237c0a9972df5d1afaca38aa733ee577128d",
"versionType": "git"
},
{
"lessThan": "d2121faf133ac3bf9531b53a7e21273649a08517",
"status": "affected",
"version": "548c237c0a9972df5d1afaca38aa733ee577128d",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ntb_netdev.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.9"
},
{
"lessThan": "3.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.267",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.218",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.185",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.154",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.106",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.267",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.218",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.185",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.154",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.106",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.46",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nNTB: ntb_netdev: Preserve RX queue depth on allocation failure\n\nntb_netdev_rx_handler() hands the received skb to the network stack\nbefore allocating its replacement. If the allocation fails, nothing is\nreposted. Every failure therefore takes one buffer out of the RX queue\nwhile the interface remains up, and enough failures eventually stall\nreception.\n\nA retry path could refill the queue later, but ntb_netdev has none.\nAllocate the replacement first instead. If that fails, drop the packet\nand repost the same skb. This keeps the queue full and lets packet\ndelivery resume as soon as memory is available again."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug is triggered in ntb_netdev_rx_handler() on every Ethernet frame received on the NTB virtual netdev; in dual-controller storage and cluster deployments the NTB interconnect carries bridged or routed IP traffic, so a remote peer can deliver packets that reach this handler without local access to the victim.\nAC:L - An attacker can reliably trigger the failure by flooding the NTB link with packets while inducing GFP_ATOMIC allocation pressure through sustained traffic and/or local memory exhaustion; each failed netdev_alloc_skb permanently consumes one of the 100 RX slots with no recovery path until the interface is restarted.\nPR:N - Reception is driven by raw Ethernet frames from the NTB peer with no authentication, capability checks, or application-layer credentials on the receive path; any host that can send traffic over the established NTB link can reach ntb_netdev_rx_handler().\nUI:N - Exploitation requires only that the NTB netdev link already be up in its normal deployment configuration; no victim login, mount, file open, or other interactive action is needed beyond the attacker sending packets over the interconnect.\nS:U - The impact is permanent loss of receive capability on the NTB netdev within the same kernel security domain; it does not cross a VM, hypervisor, IOMMU, or other security-authority boundary.\nC:N - The defect only leaks RX queue entries on allocation failure and does not involve out-of-bounds access, use-after-free, or any memory read primitive that could disclose kernel data to the attacker.\nI:N - No kernel or user data is modified; the bug only fails to repost a receive buffer, causing progressive RX queue depletion rather than arbitrary memory writes or code execution.\nA:H - Each allocation failure permanently removes one RX buffer with no refill mechanism, and after NTB_RXQ_SIZE (100) failures reception on the NTB netdev stalls completely while the interface remains up, causing a persistent denial of service on a critical cluster interconnect until manual intervention."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T12:39:48.605Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/6d7f8a23c130d768c0976c2578b214353674e18f"
},
{
"url": "https://git.kernel.org/stable/c/18781cc0bfb5c7f2a51ac6d678a28f101b7c35c5"
},
{
"url": "https://git.kernel.org/stable/c/272df0fbe6f3e04e22bc67fbdd9ac24586b942f4"
},
{
"url": "https://git.kernel.org/stable/c/fcaf8ba7e56bb73319ac107a63b907d59536192c"
},
{
"url": "https://git.kernel.org/stable/c/3f2a15f33f86f7bd5b920669fd40c06725d72a1e"
},
{
"url": "https://git.kernel.org/stable/c/a4e340971fe8ccd245d206db4d43b2a0eec240bd"
},
{
"url": "https://git.kernel.org/stable/c/755fd7843f300d724caceabdf9bb13adc8701540"
},
{
"url": "https://git.kernel.org/stable/c/d2121faf133ac3bf9531b53a7e21273649a08517"
}
],
"title": "NTB: ntb_netdev: Preserve RX queue depth on allocation failure",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74626",
"datePublished": "2026-08-22T15:32:08.687Z",
"dateReserved": "2026-08-15T05:44:03.921Z",
"dateUpdated": "2026-08-27T12:39:48.605Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68222 (GCVE-0-2026-68222)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: msi2500: Return queued buffers on start_streaming() failure
The vb2 framework hands buffers to the driver via buf_queue() before
calling start_streaming(). If start_streaming() returns an error
without first returning those buffers via vb2_buffer_done(),
vb2_start_streaming() fires WARN_ON(owned_by_drv_count) and the queued
buffers leak.
msi2500_start_streaming() had five error paths that all hit this trap
and were further tangled by ret-overwriting between calls:
- -ENODEV when the USB device was already disconnected
- -ERESTARTSYS when mutex_lock_interruptible() was interrupted
- msi2500_set_usb_adc() failure: ret was silently overwritten by
the next call (msi2500_isoc_init), so the error was lost entirely
- msi2500_isoc_init() failure: cleanup_queued_bufs was called, but
the function then fell through to msi2500_ctrl_msg() and again
masked the original error by overwriting ret
- msi2500_ctrl_msg(CMD_START_STREAMING) failure: no cleanup at all,
leaving isoc URBs submitted with no way for the driver to consume
them
Consolidate the error paths into a small goto chain. Every failure
now stops the function, drains the queued-buffer list, and returns
the real error code. The ctrl_msg failure path also rolls back the
preceding msi2500_isoc_init() via msi2500_isoc_cleanup() before
unlocking and draining.
The cleanup helper takes a vb2_buffer_state argument so that the
start_streaming error paths can pass VB2_BUF_STATE_QUEUED (as
expected by userspace on start_streaming failure) while stop_streaming
keeps its existing VB2_BUF_STATE_ERROR semantics.
This mirrors the uvcvideo fix in commit 4cf3b6fd54eb ("media: uvcvideo:
Return queued buffers on start_streaming() failure").
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 977e444f59ad16eedf66acae4f357011c74da291 Version: 977e444f59ad16eedf66acae4f357011c74da291 Version: 977e444f59ad16eedf66acae4f357011c74da291 Version: 977e444f59ad16eedf66acae4f357011c74da291 Version: 977e444f59ad16eedf66acae4f357011c74da291 Version: 977e444f59ad16eedf66acae4f357011c74da291 Version: 977e444f59ad16eedf66acae4f357011c74da291 Version: 977e444f59ad16eedf66acae4f357011c74da291 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/usb/msi2500/msi2500.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c74b680704baecea4620c0774de473069e0bc4e8",
"status": "affected",
"version": "977e444f59ad16eedf66acae4f357011c74da291",
"versionType": "git"
},
{
"lessThan": "2d10eedb786a13f91d76e11320fabb0bf712519f",
"status": "affected",
"version": "977e444f59ad16eedf66acae4f357011c74da291",
"versionType": "git"
},
{
"lessThan": "2de14ddb4fea04ca616403a6ba81c5e8099e9b9e",
"status": "affected",
"version": "977e444f59ad16eedf66acae4f357011c74da291",
"versionType": "git"
},
{
"lessThan": "1d58229b330b7f67fbfa07e0f2a8a51fbeafaa9a",
"status": "affected",
"version": "977e444f59ad16eedf66acae4f357011c74da291",
"versionType": "git"
},
{
"lessThan": "bab9d5a67d4db96ae8c187b92b37979911302a10",
"status": "affected",
"version": "977e444f59ad16eedf66acae4f357011c74da291",
"versionType": "git"
},
{
"lessThan": "264b5380c4f8aa92dbc2983ecd2b627f1d5e0061",
"status": "affected",
"version": "977e444f59ad16eedf66acae4f357011c74da291",
"versionType": "git"
},
{
"lessThan": "3673cb0a5711e910074d69201da9e1535c03f97a",
"status": "affected",
"version": "977e444f59ad16eedf66acae4f357011c74da291",
"versionType": "git"
},
{
"lessThan": "7201c17786a498497bca57752883b90914d405ac",
"status": "affected",
"version": "977e444f59ad16eedf66acae4f357011c74da291",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/usb/msi2500/msi2500.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.12"
},
{
"lessThan": "3.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: msi2500: Return queued buffers on start_streaming() failure\n\nThe vb2 framework hands buffers to the driver via buf_queue() before\ncalling start_streaming(). If start_streaming() returns an error\nwithout first returning those buffers via vb2_buffer_done(),\nvb2_start_streaming() fires WARN_ON(owned_by_drv_count) and the queued\nbuffers leak.\n\nmsi2500_start_streaming() had five error paths that all hit this trap\nand were further tangled by ret-overwriting between calls:\n\n - -ENODEV when the USB device was already disconnected\n - -ERESTARTSYS when mutex_lock_interruptible() was interrupted\n - msi2500_set_usb_adc() failure: ret was silently overwritten by\n the next call (msi2500_isoc_init), so the error was lost entirely\n - msi2500_isoc_init() failure: cleanup_queued_bufs was called, but\n the function then fell through to msi2500_ctrl_msg() and again\n masked the original error by overwriting ret\n - msi2500_ctrl_msg(CMD_START_STREAMING) failure: no cleanup at all,\n leaving isoc URBs submitted with no way for the driver to consume\n them\n\nConsolidate the error paths into a small goto chain. Every failure\nnow stops the function, drains the queued-buffer list, and returns\nthe real error code. The ctrl_msg failure path also rolls back the\npreceding msi2500_isoc_init() via msi2500_isoc_cleanup() before\nunlocking and draining.\n\nThe cleanup helper takes a vb2_buffer_state argument so that the\nstart_streaming error paths can pass VB2_BUF_STATE_QUEUED (as\nexpected by userspace on start_streaming failure) while stop_streaming\nkeeps its existing VB2_BUF_STATE_ERROR semantics.\n\nThis mirrors the uvcvideo fix in commit 4cf3b6fd54eb (\"media: uvcvideo:\nReturn queued buffers on start_streaming() failure\")."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable code is reached only through a local VIDIOC_STREAMON ioctl on the msi2500 SDR character device /dev/swradioN; no network or remote input is involved, and the failure paths are driven from a local process\u0027s syscalls.\nAC:L - The attacker controls both sides of the trigger: hold dev-\u003ev4l2_lock from a second thread and send a signal to the STREAMON thread so mutex_lock_interruptible() returns -ERESTARTSYS, hitting the leaking error path deterministically and repeatably.\nPR:L - Only an unprivileged local user with access to the V4L2/SDR device node is needed; on desktop, Android and embedded systems these nodes are granted to the logged-in seat or a device group, and no capability check guards STREAMON.\nUI:N - The whole sequence (REQBUFS, QBUF, STREAMON, signal, repeat) is performed by the attacker\u0027s own process; no victim action such as plugging in hardware or opening a file is required.\nS:U - The corruption is confined to kernel memory managed by the same kernel security authority; no VM, IOMMU or sandbox boundary is crossed.\nC:H - Buffers left on dev-\u003equeued_bufs after the vb2 core reclaims and later frees them become dangling pointers reused by cleanup_queued_bufs()/get_next_fill_buf(), giving a use-after-free that can be groomed to read reclaimed kernel heap contents back into userspace buffers.\nI:H - The stale list entries permit list_add_tail() on an already-linked node (list corruption) and vb2_buffer_done()/isoc-handler writes into freed objects, yielding attacker-influenced kernel heap writes exploitable for control-flow hijacking.\nA:H - At minimum the missing buffer return trips WARN_ON(owned_by_drv_count) (fatal with panic_on_warn) and leaks buffers; the resulting list corruption and use-after-free reliably oops or hang the kernel."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:51.745Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c74b680704baecea4620c0774de473069e0bc4e8"
},
{
"url": "https://git.kernel.org/stable/c/2d10eedb786a13f91d76e11320fabb0bf712519f"
},
{
"url": "https://git.kernel.org/stable/c/2de14ddb4fea04ca616403a6ba81c5e8099e9b9e"
},
{
"url": "https://git.kernel.org/stable/c/1d58229b330b7f67fbfa07e0f2a8a51fbeafaa9a"
},
{
"url": "https://git.kernel.org/stable/c/bab9d5a67d4db96ae8c187b92b37979911302a10"
},
{
"url": "https://git.kernel.org/stable/c/264b5380c4f8aa92dbc2983ecd2b627f1d5e0061"
},
{
"url": "https://git.kernel.org/stable/c/3673cb0a5711e910074d69201da9e1535c03f97a"
},
{
"url": "https://git.kernel.org/stable/c/7201c17786a498497bca57752883b90914d405ac"
}
],
"title": "media: msi2500: Return queued buffers on start_streaming() failure",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68222",
"datePublished": "2026-08-10T12:00:42.687Z",
"dateReserved": "2026-07-30T09:28:09.375Z",
"dateUpdated": "2026-08-19T16:31:51.745Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68244 (GCVE-0-2026-68244)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-19 16:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/i915/gem: Do not leak siblings[] on proto context error
After a successful BALANCE/PARALLEL_SUBMIT extension on context
creation, error during processing of next user extension leaks
the siblings[] array. Fix that.
Discovered using AI-assisted static analysis confirmed by
Intel Product Security.
(cherry picked from commit aa65e0a4b51b3b54b53e4142aaa2d997aa1061ff)
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d4433c7600f794623d6802395542cf4ca4f1b1f9 Version: d4433c7600f794623d6802395542cf4ca4f1b1f9 Version: d4433c7600f794623d6802395542cf4ca4f1b1f9 Version: d4433c7600f794623d6802395542cf4ca4f1b1f9 Version: d4433c7600f794623d6802395542cf4ca4f1b1f9 Version: d4433c7600f794623d6802395542cf4ca4f1b1f9 Version: d4433c7600f794623d6802395542cf4ca4f1b1f9 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/i915/gem/i915_gem_context.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "60b7d701ffae0c3a69e838f984cc80d8ca929f5d",
"status": "affected",
"version": "d4433c7600f794623d6802395542cf4ca4f1b1f9",
"versionType": "git"
},
{
"lessThan": "e600672f11a1d9215f5432ca58f0b9823917a292",
"status": "affected",
"version": "d4433c7600f794623d6802395542cf4ca4f1b1f9",
"versionType": "git"
},
{
"lessThan": "f014702fbd48d06a3d7a06e4bb4075d406376cf0",
"status": "affected",
"version": "d4433c7600f794623d6802395542cf4ca4f1b1f9",
"versionType": "git"
},
{
"lessThan": "8431a4d7ff95c7f9c6fb1dbbbc9cdadf29d4f6d5",
"status": "affected",
"version": "d4433c7600f794623d6802395542cf4ca4f1b1f9",
"versionType": "git"
},
{
"lessThan": "37951ce1567ccf8c86c7a1b8fb7d55a32c821b87",
"status": "affected",
"version": "d4433c7600f794623d6802395542cf4ca4f1b1f9",
"versionType": "git"
},
{
"lessThan": "6cdbef8f60f313684e641628d64aa85960080d3f",
"status": "affected",
"version": "d4433c7600f794623d6802395542cf4ca4f1b1f9",
"versionType": "git"
},
{
"lessThan": "eed3de2acf6aa5154d49098b026710b646db67ee",
"status": "affected",
"version": "d4433c7600f794623d6802395542cf4ca4f1b1f9",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/i915/gem/i915_gem_context.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.15"
},
{
"lessThan": "5.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/i915/gem: Do not leak siblings[] on proto context error\n\nAfter a successful BALANCE/PARALLEL_SUBMIT extension on context\ncreation, error during processing of next user extension leaks\nthe siblings[] array. Fix that.\n\nDiscovered using AI-assisted static analysis confirmed by\nIntel Product Security.\n\n(cherry picked from commit aa65e0a4b51b3b54b53e4142aaa2d997aa1061ff)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:32:11.063Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/60b7d701ffae0c3a69e838f984cc80d8ca929f5d"
},
{
"url": "https://git.kernel.org/stable/c/e600672f11a1d9215f5432ca58f0b9823917a292"
},
{
"url": "https://git.kernel.org/stable/c/f014702fbd48d06a3d7a06e4bb4075d406376cf0"
},
{
"url": "https://git.kernel.org/stable/c/8431a4d7ff95c7f9c6fb1dbbbc9cdadf29d4f6d5"
},
{
"url": "https://git.kernel.org/stable/c/37951ce1567ccf8c86c7a1b8fb7d55a32c821b87"
},
{
"url": "https://git.kernel.org/stable/c/6cdbef8f60f313684e641628d64aa85960080d3f"
},
{
"url": "https://git.kernel.org/stable/c/eed3de2acf6aa5154d49098b026710b646db67ee"
}
],
"title": "drm/i915/gem: Do not leak siblings[] on proto context error",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68244",
"datePublished": "2026-08-10T12:01:10.469Z",
"dateReserved": "2026-07-30T09:28:09.377Z",
"dateUpdated": "2026-08-19T16:32:11.063Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68253 (GCVE-0-2026-68253)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/i915/hdcp: check streams[] bounds before overflow
The data->streams[] overflow check is done after the buffer overflow has
already happened. Move the overflow check before the write.
Side note, emitting a warning splat with a backtrace might be overkill
here, but prefer not changing the behaviour other than not doing the
overrun.
Discovered using AI-assisted static analysis confirmed by Intel Product
Security.
(cherry picked from commit 9284ab3b6e776c315883ac2611283d263c9460fd)
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: e03187e12cae57c09b521b6f7dd7c7f9aa2b62e9 Version: e03187e12cae57c09b521b6f7dd7c7f9aa2b62e9 Version: e03187e12cae57c09b521b6f7dd7c7f9aa2b62e9 Version: e03187e12cae57c09b521b6f7dd7c7f9aa2b62e9 Version: e03187e12cae57c09b521b6f7dd7c7f9aa2b62e9 Version: e03187e12cae57c09b521b6f7dd7c7f9aa2b62e9 Version: e03187e12cae57c09b521b6f7dd7c7f9aa2b62e9 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/i915/display/intel_hdcp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "336cf6d80d41457442b659e7ba7a7badc0ffe79d",
"status": "affected",
"version": "e03187e12cae57c09b521b6f7dd7c7f9aa2b62e9",
"versionType": "git"
},
{
"lessThan": "389079bf04e6f0c6f10f5b879f6d7a9cf80f0567",
"status": "affected",
"version": "e03187e12cae57c09b521b6f7dd7c7f9aa2b62e9",
"versionType": "git"
},
{
"lessThan": "84351f12390349ba010920fc247e1a0b12e41eb3",
"status": "affected",
"version": "e03187e12cae57c09b521b6f7dd7c7f9aa2b62e9",
"versionType": "git"
},
{
"lessThan": "2106fb490b2c6003e23ad6ff36ce823a2170e138",
"status": "affected",
"version": "e03187e12cae57c09b521b6f7dd7c7f9aa2b62e9",
"versionType": "git"
},
{
"lessThan": "3d2ef8d389495e7889c6062d8bddc46d2a5fbdef",
"status": "affected",
"version": "e03187e12cae57c09b521b6f7dd7c7f9aa2b62e9",
"versionType": "git"
},
{
"lessThan": "984085c5b53572e2e03fd5fc4817e86ef1effc6e",
"status": "affected",
"version": "e03187e12cae57c09b521b6f7dd7c7f9aa2b62e9",
"versionType": "git"
},
{
"lessThan": "bbb15a6b042d02e5508a02b4847e02d2579ee7bc",
"status": "affected",
"version": "e03187e12cae57c09b521b6f7dd7c7f9aa2b62e9",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/i915/display/intel_hdcp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.12"
},
{
"lessThan": "5.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/i915/hdcp: check streams[] bounds before overflow\n\nThe data-\u003estreams[] overflow check is done after the buffer overflow has\nalready happened. Move the overflow check before the write.\n\nSide note, emitting a warning splat with a backtrace might be overkill\nhere, but prefer not changing the behaviour other than not doing the\noverrun.\n\nDiscovered using AI-assisted static analysis confirmed by Intel Product\nSecurity.\n\n(cherry picked from commit 9284ab3b6e776c315883ac2611283d263c9460fd)"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The overflow is reached through a local DRM atomic modeset ioctl on /dev/dri/cardN that sets the \"Content Protection\" connector property, driving intel_hdcp_enable() -\u003e intel_hdcp_prepare_streams(); no network or remote path exists to the i915 display HDCP code.\nAC:L - Any DP MST topology with more connected MST connectors on one digital port than the device has pipes (a common dock/hub/daisy-chain setup, and easily arranged by anyone with access to the machine\u0027s display outputs) makes every HDCP enable request overflow the buffer deterministically, with no race or memory-layout condition to win.\nPR:L - The attacker only needs access to the DRM device node as DRM master, which an ordinary user in a local graphical session (video/render group, logind seat) has; no CAP_SYS_ADMIN or root is required to request HDCP content protection on an MST connector.\nUI:N - The attacker performs the atomic commit that requests content protection themselves; no action by another user is needed, and on a system already running a compositor with HDCP desired the overflow occurs automatically on the modeset.\nS:U - The corruption is confined to kernel heap memory within the same kernel security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - The out-of-bounds write corrupts adjacent objects in a small kmalloc slab, and such heap corruption is a standard primitive for pivoting to arbitrary kernel memory disclosure by overwriting neighbouring pointers or length fields.\nI:H - This is a heap out-of-bounds write past a kzalloc\u0027d streams[] buffer sized to INTEL_NUM_PIPES, with attacker-influenced VCPI values and an attacker-controlled overflow length determined by the MST topology, giving corruption of adjacent slab objects that can be leveraged for control-flow hijack.\nA:H - Overwriting adjacent slab allocations reliably produces slab corruption, oops, or panic, and the path can be re-triggered on every HDCP enable/modeset, so the system can be crashed repeatedly."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:11.002Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/336cf6d80d41457442b659e7ba7a7badc0ffe79d"
},
{
"url": "https://git.kernel.org/stable/c/389079bf04e6f0c6f10f5b879f6d7a9cf80f0567"
},
{
"url": "https://git.kernel.org/stable/c/84351f12390349ba010920fc247e1a0b12e41eb3"
},
{
"url": "https://git.kernel.org/stable/c/2106fb490b2c6003e23ad6ff36ce823a2170e138"
},
{
"url": "https://git.kernel.org/stable/c/3d2ef8d389495e7889c6062d8bddc46d2a5fbdef"
},
{
"url": "https://git.kernel.org/stable/c/984085c5b53572e2e03fd5fc4817e86ef1effc6e"
},
{
"url": "https://git.kernel.org/stable/c/bbb15a6b042d02e5508a02b4847e02d2579ee7bc"
}
],
"title": "drm/i915/hdcp: check streams[] bounds before overflow",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68253",
"datePublished": "2026-08-10T12:01:19.402Z",
"dateReserved": "2026-07-30T09:28:09.377Z",
"dateUpdated": "2026-08-23T12:46:11.002Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74743 (GCVE-0-2026-74743)
Vulnerability from cvelistv5
Published
2026-08-26 14:36
Modified
2026-08-27 05:01
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
macvlan: inherit needed_headroom and needed_tailroom from lowerdev
macvlan devices inherit hard_header_len from lowerdev during macvlan_init(),
but leave needed_headroom and needed_tailroom set to 0.
When the underlying lowerdev requires extra headroom or tailroom for
headers/trailers (e.g. macsec, ipsec, wireguard, tunnels, or veth with rx
headroom), upper layers calculating packet headroom and tailroom fail to
reserve sufficient space.
This can result in reallocation overhead, skb headroom underflows, or KASAN
slab-use-after-free crashes when dev_hard_header() / macvlan_hard_header()
prepends header data or when lower devices append tailroom.
Fix this by:
1. Inheriting needed_headroom and needed_tailroom from lowerdev in macvlan_init().
2. Propagating needed_headroom and needed_tailroom updates to attached macvlans
in macvlan_device_event() when receiving NETDEV_FEAT_CHANGE events.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: b863ceb7ddcea8c55fcf1d7b2ac591d50aa7ed53 Version: b863ceb7ddcea8c55fcf1d7b2ac591d50aa7ed53 Version: b863ceb7ddcea8c55fcf1d7b2ac591d50aa7ed53 Version: b863ceb7ddcea8c55fcf1d7b2ac591d50aa7ed53 Version: b863ceb7ddcea8c55fcf1d7b2ac591d50aa7ed53 Version: b863ceb7ddcea8c55fcf1d7b2ac591d50aa7ed53 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/macvlan.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "8cd90e850e434577bf6774778657d26d6995e53f",
"status": "affected",
"version": "b863ceb7ddcea8c55fcf1d7b2ac591d50aa7ed53",
"versionType": "git"
},
{
"lessThan": "28afc87bd8da0b3348bbbd834c8a89e83712cf5e",
"status": "affected",
"version": "b863ceb7ddcea8c55fcf1d7b2ac591d50aa7ed53",
"versionType": "git"
},
{
"lessThan": "8f6a05dbac05725e0786701eb04778c5bdbe4eaa",
"status": "affected",
"version": "b863ceb7ddcea8c55fcf1d7b2ac591d50aa7ed53",
"versionType": "git"
},
{
"lessThan": "96fa90b74385b7f2b0d97251dd43d5ee6ca44668",
"status": "affected",
"version": "b863ceb7ddcea8c55fcf1d7b2ac591d50aa7ed53",
"versionType": "git"
},
{
"lessThan": "bc9a00fb78e32bccc39d763bfd13a450705bac5d",
"status": "affected",
"version": "b863ceb7ddcea8c55fcf1d7b2ac591d50aa7ed53",
"versionType": "git"
},
{
"lessThan": "cef51860becd9700217c81732ca1eb1ea6ed6fe1",
"status": "affected",
"version": "b863ceb7ddcea8c55fcf1d7b2ac591d50aa7ed53",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/macvlan.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.23"
},
{
"lessThan": "2.6.23",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "2.6.23",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "2.6.23",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "2.6.23",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.46",
"versionStartIncluding": "2.6.23",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.10",
"versionStartIncluding": "2.6.23",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.23",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmacvlan: inherit needed_headroom and needed_tailroom from lowerdev\n\nmacvlan devices inherit hard_header_len from lowerdev during macvlan_init(),\nbut leave needed_headroom and needed_tailroom set to 0.\n\nWhen the underlying lowerdev requires extra headroom or tailroom for\nheaders/trailers (e.g. macsec, ipsec, wireguard, tunnels, or veth with rx\nheadroom), upper layers calculating packet headroom and tailroom fail to\nreserve sufficient space.\n\nThis can result in reallocation overhead, skb headroom underflows, or KASAN\nslab-use-after-free crashes when dev_hard_header() / macvlan_hard_header()\nprepends header data or when lower devices append tailroom.\n\nFix this by:\n1. Inheriting needed_headroom and needed_tailroom from lowerdev in macvlan_init().\n2. Propagating needed_headroom and needed_tailroom updates to attached macvlans\n in macvlan_device_event() when receiving NETDEV_FEAT_CHANGE events."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug fires on the macvlan transmit path (ip_finish_output2/neigh_resolve_output/macvlan_hard_header) when kernel-generated replies or forwarded traffic egress a macvlan netdev; remote peers trigger this by sending TCP/UDP/ICMP to an address on a pre-configured macvlan interface.\nAC:L - Once macvlan is stacked on a lowerdev with nonzero needed_headroom (WireGuard, MACsec, IPsec, tunnels, veth RX headroom), ordinary packets reliably hit under-reserved skb headroom/tailroom during dev_hard_header() without races or uncontrollable timing.\nPR:N - A remote attacker needs no local account or capabilities; sending routable traffic to a macvlan address suffices. Administrative macvlan setup is environmental (like other netdev CVEs), not an attacker privilege requirement.\nUI:N - Exploitation requires only normal network delivery to a reachable macvlan address; no victim must open files, mount filesystems, or perform any interactive action beyond existing connectivity.\nS:U - Impact is kernel skb heap corruption, slab-use-after-free, or panic within the host network stack; it does not cross VM, IOMMU, or container security boundaries into a separate authority.\nC:H - The fix commit documents KASAN slab-use-after-free from skb headroom underflow during header prepending; this class of kernel heap corruption is exploitable for arbitrary memory disclosure beyond a bounded leak.\nI:H - Insufficient headroom causes skb_push underflows and slab UAF during pskb_expand_head/reallocation, providing kernel heap write primitives that can be leveraged for control-flow hijacking and privilege escalation.\nA:H - The failure mode includes skb_under_panic (kernel BUG/panic) and KASAN-detected slab UAF crashes, causing immediate host kernel denial of service on affected transmit paths."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T05:01:04.222Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/8cd90e850e434577bf6774778657d26d6995e53f"
},
{
"url": "https://git.kernel.org/stable/c/28afc87bd8da0b3348bbbd834c8a89e83712cf5e"
},
{
"url": "https://git.kernel.org/stable/c/8f6a05dbac05725e0786701eb04778c5bdbe4eaa"
},
{
"url": "https://git.kernel.org/stable/c/96fa90b74385b7f2b0d97251dd43d5ee6ca44668"
},
{
"url": "https://git.kernel.org/stable/c/bc9a00fb78e32bccc39d763bfd13a450705bac5d"
},
{
"url": "https://git.kernel.org/stable/c/cef51860becd9700217c81732ca1eb1ea6ed6fe1"
}
],
"title": "macvlan: inherit needed_headroom and needed_tailroom from lowerdev",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74743",
"datePublished": "2026-08-26T14:36:54.175Z",
"dateReserved": "2026-08-15T05:44:03.930Z",
"dateUpdated": "2026-08-27T05:01:04.222Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68195 (GCVE-0-2026-68195)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses
PKT_TYPE_TXRX_NOTIFY is an mmio-only event, but mt7615_rx_check() and
mt7615_queue_rx_skb() dispatch it to mt7615_mac_tx_free() on every bus.
mt7615_mac_tx_free() cleans the DMA tx queues with
mt76_queue_tx_cleanup(), which calls queue_ops->tx_cleanup(). Only the
mmio queue ops implement that callback; on the mt7663 USB and SDIO
buses it is NULL, so a TXRX_NOTIFY there calls a NULL pointer in the RX
worker. Same defect as the mt7921 and mt7925 patches in this series.
Drop the event on non-mmio buses via mt76_is_mmio(), as in
commit 5683e1488aa9 ("wifi: mt76: connac: do not check WED status for
non-mmio devices").
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: eb99cc95c3b6513b495c4839ac4917206705f657 Version: eb99cc95c3b6513b495c4839ac4917206705f657 Version: eb99cc95c3b6513b495c4839ac4917206705f657 Version: eb99cc95c3b6513b495c4839ac4917206705f657 Version: eb99cc95c3b6513b495c4839ac4917206705f657 Version: eb99cc95c3b6513b495c4839ac4917206705f657 Version: eb99cc95c3b6513b495c4839ac4917206705f657 Version: eb99cc95c3b6513b495c4839ac4917206705f657 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/mediatek/mt76/mt7615/mac.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "664f8bbc61e45e062679da512bf12f8f6fb26a1b",
"status": "affected",
"version": "eb99cc95c3b6513b495c4839ac4917206705f657",
"versionType": "git"
},
{
"lessThan": "1a099d630b8667fa622662b85e35a0ef659fb343",
"status": "affected",
"version": "eb99cc95c3b6513b495c4839ac4917206705f657",
"versionType": "git"
},
{
"lessThan": "a0b3e8d8726c3830102a18946c766c94c953c7f2",
"status": "affected",
"version": "eb99cc95c3b6513b495c4839ac4917206705f657",
"versionType": "git"
},
{
"lessThan": "f2a72f47c5fb4ba6887e85bbe809d7e5b318d9d5",
"status": "affected",
"version": "eb99cc95c3b6513b495c4839ac4917206705f657",
"versionType": "git"
},
{
"lessThan": "88c98ef247a3126fea9bbbda953a18a2f36c3ea7",
"status": "affected",
"version": "eb99cc95c3b6513b495c4839ac4917206705f657",
"versionType": "git"
},
{
"lessThan": "ab4d213393e846baa6437497f94dda7553cbeda7",
"status": "affected",
"version": "eb99cc95c3b6513b495c4839ac4917206705f657",
"versionType": "git"
},
{
"lessThan": "b2ab73b8123ce6cf2bc32634bfee4928676ffa66",
"status": "affected",
"version": "eb99cc95c3b6513b495c4839ac4917206705f657",
"versionType": "git"
},
{
"lessThan": "39afc46c0243d10b7795e6e6cf4ae91f41732120",
"status": "affected",
"version": "eb99cc95c3b6513b495c4839ac4917206705f657",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/mediatek/mt76/mt7615/mac.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.8"
},
{
"lessThan": "5.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses\n\nPKT_TYPE_TXRX_NOTIFY is an mmio-only event, but mt7615_rx_check() and\nmt7615_queue_rx_skb() dispatch it to mt7615_mac_tx_free() on every bus.\nmt7615_mac_tx_free() cleans the DMA tx queues with\nmt76_queue_tx_cleanup(), which calls queue_ops-\u003etx_cleanup(). Only the\nmmio queue ops implement that callback; on the mt7663 USB and SDIO\nbuses it is NULL, so a TXRX_NOTIFY there calls a NULL pointer in the RX\nworker. Same defect as the mt7921 and mt7925 patches in this series.\n\nDrop the event on non-mmio buses via mt76_is_mmio(), as in\ncommit 5683e1488aa9 (\"wifi: mt76: connac: do not check WED status for\nnon-mmio devices\")."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:11.475Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/664f8bbc61e45e062679da512bf12f8f6fb26a1b"
},
{
"url": "https://git.kernel.org/stable/c/1a099d630b8667fa622662b85e35a0ef659fb343"
},
{
"url": "https://git.kernel.org/stable/c/a0b3e8d8726c3830102a18946c766c94c953c7f2"
},
{
"url": "https://git.kernel.org/stable/c/f2a72f47c5fb4ba6887e85bbe809d7e5b318d9d5"
},
{
"url": "https://git.kernel.org/stable/c/88c98ef247a3126fea9bbbda953a18a2f36c3ea7"
},
{
"url": "https://git.kernel.org/stable/c/ab4d213393e846baa6437497f94dda7553cbeda7"
},
{
"url": "https://git.kernel.org/stable/c/b2ab73b8123ce6cf2bc32634bfee4928676ffa66"
},
{
"url": "https://git.kernel.org/stable/c/39afc46c0243d10b7795e6e6cf4ae91f41732120"
}
],
"title": "wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68195",
"datePublished": "2026-08-10T12:00:13.627Z",
"dateReserved": "2026-07-30T09:28:09.374Z",
"dateUpdated": "2026-08-19T16:31:11.475Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74667 (GCVE-0-2026-74667)
Vulnerability from cvelistv5
Published
2026-08-22 15:32
Modified
2026-08-25 05:41
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/packet: reset the MAC header on the packet-socket transmit path
packet_parse_headers() resets the MAC header only for a SOCK_RAW frame
whose socket did not bind a protocol. A protocol-bound SOCK_RAW socket,
any SOCK_DGRAM frame, and the legacy SOCK_PACKET path therefore leave
skb->mac_header unset here.
For frames sent via __dev_queue_xmit() this is harmless: it resets the
MAC header unconditionally. But the packet-socket PACKET_QDISC_BYPASS
path uses dev_direct_xmit(), which does not, so the frame reaches
ndo_start_xmit() with the MAC header unset. A driver that reads
eth_hdr(skb) on transmit then dereferences skb->head + (u16)~0, an
out-of-bounds access ~64 KiB past the head -- the same class fixed for
one consumer in commit f5089008f90c ("macsec: do not read an unset MAC
header in macsec_encrypt()").
packet_parse_headers() runs only on the transmit path, where skb->data
points at the start of the L2 header for every packet-socket type
regardless of its length: SOCK_RAW and SOCK_PACKET carry a user-supplied
header and SOCK_DGRAM has one built by dev_hard_header(). Reset the MAC
header unconditionally, mirroring __dev_queue_xmit(), so the frame is
anchored on the bypass path too.
Found by 0sec (https://0sec.ai) using automated source analysis;
verified against source and matched to the macsec KASAN report in
f5089008f90c. Compile-tested.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 75c65772c3d18447d62d3aca5f91b06c16cc25e4 Version: 75c65772c3d18447d62d3aca5f91b06c16cc25e4 Version: 75c65772c3d18447d62d3aca5f91b06c16cc25e4 Version: 75c65772c3d18447d62d3aca5f91b06c16cc25e4 Version: 75c65772c3d18447d62d3aca5f91b06c16cc25e4 Version: 75c65772c3d18447d62d3aca5f91b06c16cc25e4 Version: 75c65772c3d18447d62d3aca5f91b06c16cc25e4 Version: 75c65772c3d18447d62d3aca5f91b06c16cc25e4 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/packet/af_packet.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "1e43a1d66615f411d427f9df1f46dd049d9e3681",
"status": "affected",
"version": "75c65772c3d18447d62d3aca5f91b06c16cc25e4",
"versionType": "git"
},
{
"lessThan": "4057853a91fb796c4f47c7d1baf1aa085394148e",
"status": "affected",
"version": "75c65772c3d18447d62d3aca5f91b06c16cc25e4",
"versionType": "git"
},
{
"lessThan": "2610ed4e86a4590234a9d70518c469751c5af231",
"status": "affected",
"version": "75c65772c3d18447d62d3aca5f91b06c16cc25e4",
"versionType": "git"
},
{
"lessThan": "b47ba8fe6e1d2df8c92048de5afafd059447dc30",
"status": "affected",
"version": "75c65772c3d18447d62d3aca5f91b06c16cc25e4",
"versionType": "git"
},
{
"lessThan": "284f3e7a3f1a743fdf89e304fd1f19d5ffcff46d",
"status": "affected",
"version": "75c65772c3d18447d62d3aca5f91b06c16cc25e4",
"versionType": "git"
},
{
"lessThan": "971aa7d99242bbf09513e27b7a243f0b29ff23ae",
"status": "affected",
"version": "75c65772c3d18447d62d3aca5f91b06c16cc25e4",
"versionType": "git"
},
{
"lessThan": "fdd4d7d52358a58e351dd9d82530c04eba8ccd7a",
"status": "affected",
"version": "75c65772c3d18447d62d3aca5f91b06c16cc25e4",
"versionType": "git"
},
{
"lessThan": "c2707480cfbf19c7619acc9c089d17f20869821f",
"status": "affected",
"version": "75c65772c3d18447d62d3aca5f91b06c16cc25e4",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/packet/af_packet.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.1"
},
{
"lessThan": "5.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/packet: reset the MAC header on the packet-socket transmit path\n\npacket_parse_headers() resets the MAC header only for a SOCK_RAW frame\nwhose socket did not bind a protocol. A protocol-bound SOCK_RAW socket,\nany SOCK_DGRAM frame, and the legacy SOCK_PACKET path therefore leave\nskb-\u003emac_header unset here.\n\nFor frames sent via __dev_queue_xmit() this is harmless: it resets the\nMAC header unconditionally. But the packet-socket PACKET_QDISC_BYPASS\npath uses dev_direct_xmit(), which does not, so the frame reaches\nndo_start_xmit() with the MAC header unset. A driver that reads\neth_hdr(skb) on transmit then dereferences skb-\u003ehead + (u16)~0, an\nout-of-bounds access ~64 KiB past the head -- the same class fixed for\none consumer in commit f5089008f90c (\"macsec: do not read an unset MAC\nheader in macsec_encrypt()\").\n\npacket_parse_headers() runs only on the transmit path, where skb-\u003edata\npoints at the start of the L2 header for every packet-socket type\nregardless of its length: SOCK_RAW and SOCK_PACKET carry a user-supplied\nheader and SOCK_DGRAM has one built by dev_hard_header(). Reset the MAC\nheader unconditionally, mirroring __dev_queue_xmit(), so the frame is\nanchored on the bypass path too.\n\nFound by 0sec (https://0sec.ai) using automated source analysis;\nverified against source and matched to the macsec KASAN report in\nf5089008f90c. Compile-tested."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The flaw is reached only via local AF_PACKET transmit syscalls (sendmsg on SOCK_DGRAM/bound SOCK_RAW with PACKET_QDISC_BYPASS); remote network input cannot trigger packet_parse_headers() on this TX path.\nAC:L - The attacker controls socket type, enables PACKET_QDISC_BYPASS via setsockopt, selects a vulnerable netdev (macsec/macvlan/tap), and sends frames to reliably hit dev_direct_xmit() without races or external victim state.\nPR:L - packet_create() requires CAP_NET_RAW, which unprivileged users commonly obtain inside user+network namespaces (unshare -Urn) per kernel capability rules, not solely real root in the init namespace.\nUI:N - Exploitation requires only the attacker opening a packet socket, enabling bypass, and transmitting; no victim user action such as opening files or mounting filesystems is needed.\nS:U - Impact is kernel heap/slab disclosure and transmit-time corruption within the same kernel security authority; it is not a VM escape, IOMMU bypass, or other cross-boundary scope change.\nC:H - Unset mac_header makes eth_hdr(skb) a large out-of-bounds kernel memory read (~64 KiB past skb-\u003ehead); macsec KASAN confirmed slab data leakage and bytes can be emitted on the wire in the frame.\nI:H - Affected TX drivers consume the bogus eth_hdr() pointer to modify skbs (e.g., macsec memmove of OOB MAC bytes into the frame, vxlan header rewrites), giving attacker-influenced corruption beyond a pure read.\nA:H - The invalid mac_header dereference can fault or trigger KASAN/driver failures during ndo_start_xmit(), causing kernel oops/panic or repeated transmit failure on the bypass path."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:41:21.641Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/1e43a1d66615f411d427f9df1f46dd049d9e3681"
},
{
"url": "https://git.kernel.org/stable/c/4057853a91fb796c4f47c7d1baf1aa085394148e"
},
{
"url": "https://git.kernel.org/stable/c/2610ed4e86a4590234a9d70518c469751c5af231"
},
{
"url": "https://git.kernel.org/stable/c/b47ba8fe6e1d2df8c92048de5afafd059447dc30"
},
{
"url": "https://git.kernel.org/stable/c/284f3e7a3f1a743fdf89e304fd1f19d5ffcff46d"
},
{
"url": "https://git.kernel.org/stable/c/971aa7d99242bbf09513e27b7a243f0b29ff23ae"
},
{
"url": "https://git.kernel.org/stable/c/fdd4d7d52358a58e351dd9d82530c04eba8ccd7a"
},
{
"url": "https://git.kernel.org/stable/c/c2707480cfbf19c7619acc9c089d17f20869821f"
}
],
"title": "net/packet: reset the MAC header on the packet-socket transmit path",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74667",
"datePublished": "2026-08-22T15:32:38.862Z",
"dateReserved": "2026-08-15T05:44:03.924Z",
"dateUpdated": "2026-08-25T05:41:21.641Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74594 (GCVE-0-2026-74594)
Vulnerability from cvelistv5
Published
2026-08-22 15:31
Modified
2026-08-25 05:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
sched/psi: Shut down rtpoll_timer in psi_cgroup_free()
psi_schedule_rtpoll_work() is called locklessly from the scheduler hotpath
and can race psi_trigger_destroy() taking down the last rtpoll trigger under
rtpoll_trigger_lock:
psi_schedule_rtpoll_work() psi_trigger_destroy()
rcu_read_lock();
task = rcu_dereference(rtpoll_task);
rcu_assign_pointer(rtpoll_task, NULL);
timer_delete(&rtpoll_timer);
mod_timer(&rtpoll_timer, ...);
rcu_read_unlock();
synchronize_rcu();
kthread_stop(task_to_destroy);
The group can then be freed with the re-armed timer still pending, and
poll_timer_fn() runs on freed memory.
461daba06bdc ("psi: eliminate kthread_worker from psi trigger scheduling
mechanism") deleted the timer synchronously after the synchronize_rcu(),
which prevented this but raced trigger creation instead: the deletion could
cancel the timer that a new trigger set armed during the grace period and,
as creation also reinitialized the timer at the time, corrupt it.
8f91efd870ea ("psi: Fix race between psi_trigger_create/destroy") moved the
initialization into group_init() and the deletion into the locked section,
trading the creation races for the window above.
Neither placement in the destruction path works. A pending timer firing
while the group is alive is harmless though. poll_timer_fn() just wakes the
rtpoll waitqueue and doesn't re-arm itself. Bind the timer to the group's
lifetime instead and shut it down in psi_cgroup_free(). Nothing can arm it
by then. timer_shutdown_sync() because the timer is never armed again.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 6bfcb6178925b1fd28c102e53d403091b8f49396 Version: 8f91efd870ea5d8bc10b0fcc9740db51cd4c0c83 Version: 8f91efd870ea5d8bc10b0fcc9740db51cd4c0c83 Version: 8f91efd870ea5d8bc10b0fcc9740db51cd4c0c83 Version: 8f91efd870ea5d8bc10b0fcc9740db51cd4c0c83 Version: 8f91efd870ea5d8bc10b0fcc9740db51cd4c0c83 Version: 8f91efd870ea5d8bc10b0fcc9740db51cd4c0c83 Version: 8f91efd870ea5d8bc10b0fcc9740db51cd4c0c83 Version: e1e5e263bbe0e6e9c3db36aa48a3c8acf546fa49 Version: 979965c33f734a1666af67900408f997ac669c23 Version: 5.10.50 ≤ Version: 5.12.17 ≤ Version: 5.13.2 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"kernel/sched/psi.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "4addb102154b7cf6e2310ccbe20c3c08619e520d",
"status": "affected",
"version": "6bfcb6178925b1fd28c102e53d403091b8f49396",
"versionType": "git"
},
{
"lessThan": "894a9300d7fb2e2951da92e565ae6de7ddfb0a69",
"status": "affected",
"version": "8f91efd870ea5d8bc10b0fcc9740db51cd4c0c83",
"versionType": "git"
},
{
"lessThan": "1e5ca82eee59caca6988f9d6e859786aab8a5fa0",
"status": "affected",
"version": "8f91efd870ea5d8bc10b0fcc9740db51cd4c0c83",
"versionType": "git"
},
{
"lessThan": "310b5a537a78c358a4cd244bd767c1a517a05459",
"status": "affected",
"version": "8f91efd870ea5d8bc10b0fcc9740db51cd4c0c83",
"versionType": "git"
},
{
"lessThan": "806fcff98c1d7cb3c1dc0015e55ebdbe819e6b08",
"status": "affected",
"version": "8f91efd870ea5d8bc10b0fcc9740db51cd4c0c83",
"versionType": "git"
},
{
"lessThan": "8037c5b2b2a447df52542f4d8535895d837bdcbd",
"status": "affected",
"version": "8f91efd870ea5d8bc10b0fcc9740db51cd4c0c83",
"versionType": "git"
},
{
"lessThan": "611e7821c4f83a671455658797336faecc3a5196",
"status": "affected",
"version": "8f91efd870ea5d8bc10b0fcc9740db51cd4c0c83",
"versionType": "git"
},
{
"lessThan": "5457025fa8ca3c0d2732109513de839e3e797190",
"status": "affected",
"version": "8f91efd870ea5d8bc10b0fcc9740db51cd4c0c83",
"versionType": "git"
},
{
"status": "affected",
"version": "e1e5e263bbe0e6e9c3db36aa48a3c8acf546fa49",
"versionType": "git"
},
{
"status": "affected",
"version": "979965c33f734a1666af67900408f997ac669c23",
"versionType": "git"
},
{
"lessThan": "5.10.266",
"status": "affected",
"version": "5.10.50",
"versionType": "semver"
},
{
"lessThan": "5.13",
"status": "affected",
"version": "5.12.17",
"versionType": "semver"
},
{
"lessThan": "5.14",
"status": "affected",
"version": "5.13.2",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"kernel/sched/psi.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.14"
},
{
"lessThan": "5.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "5.10.50",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.12.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.13.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsched/psi: Shut down rtpoll_timer in psi_cgroup_free()\n\npsi_schedule_rtpoll_work() is called locklessly from the scheduler hotpath\nand can race psi_trigger_destroy() taking down the last rtpoll trigger under\nrtpoll_trigger_lock:\n\n psi_schedule_rtpoll_work() psi_trigger_destroy()\n\n rcu_read_lock();\n task = rcu_dereference(rtpoll_task);\n rcu_assign_pointer(rtpoll_task, NULL);\n timer_delete(\u0026rtpoll_timer);\n mod_timer(\u0026rtpoll_timer, ...);\n rcu_read_unlock();\n synchronize_rcu();\n kthread_stop(task_to_destroy);\n\nThe group can then be freed with the re-armed timer still pending, and\npoll_timer_fn() runs on freed memory.\n\n461daba06bdc (\"psi: eliminate kthread_worker from psi trigger scheduling\nmechanism\") deleted the timer synchronously after the synchronize_rcu(),\nwhich prevented this but raced trigger creation instead: the deletion could\ncancel the timer that a new trigger set armed during the grace period and,\nas creation also reinitialized the timer at the time, corrupt it.\n8f91efd870ea (\"psi: Fix race between psi_trigger_create/destroy\") moved the\ninitialization into group_init() and the deletion into the locked section,\ntrading the creation races for the window above.\n\nNeither placement in the destruction path works. A pending timer firing\nwhile the group is alive is harmless though. poll_timer_fn() just wakes the\nrtpoll waitqueue and doesn\u0027t re-arm itself. Bind the timer to the group\u0027s\nlifetime instead and shut it down in psi_cgroup_free(). Nothing can arm it\nby then. timer_shutdown_sync() because the timer is never armed again."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Reachable only via local kernel interfaces: writing cgroup *.pressure or /proc/pressure/*, closing the trigger fd, and removing the cgroup; the race involves scheduler hotpath callbacks, not any network protocol.\nAC:L - The attacker controls both race participants\u2014closing/destroying the last privileged PSI trigger while concurrently driving psi_schedule_rtpoll_work() via cgroup task scheduling or the psimon worker\u2014so the mod_timer-after-timer_delete window is reliably winnable.\nPR:L - The vulnerable rtpoll path requires CAP_SYS_RESOURCE (non-2s PSI windows); that capability is available to an unprivileged user who creates a user namespace, and cgroup pressure files are writable under delegated cgroup v2 hierarchies in that namespace.\nUI:N - Exploitation is fully self-driven: the attacker creates the trigger, races its teardown against scheduler activity, and deletes the cgroup; no separate victim action such as mounting a filesystem or opening a file is required.\nS:U - Impact is confined to kernel memory corruption and potential local privilege escalation within the same kernel security authority; it does not cross a VM, container runtime, or IOMMU trust boundary.\nC:H - After psi_cgroup_free() the pending rtpoll_timer fires poll_timer_fn() on a freed psi_group, a classic use-after-free that can expose or corrupt adjacent slab contents and be developed into arbitrary kernel memory read primitives.\nI:H - poll_timer_fn() performs atomic_set() on group-\u003ertpoll_wakeup and wake_up_interruptible() on group-\u003ertpoll_wait after the psi_group is freed, giving attacker-influenced writes into a recycled kmem object suitable for control-flow hijacking.\nA:H - Timer execution on freed psi_group memory can cause immediate kernel oops/panic from invalid pointer dereferences or list corruption, and the race can be retriggered for sustained denial of service on shared cloud/container hosts."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:40:21.246Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/4addb102154b7cf6e2310ccbe20c3c08619e520d"
},
{
"url": "https://git.kernel.org/stable/c/894a9300d7fb2e2951da92e565ae6de7ddfb0a69"
},
{
"url": "https://git.kernel.org/stable/c/1e5ca82eee59caca6988f9d6e859786aab8a5fa0"
},
{
"url": "https://git.kernel.org/stable/c/310b5a537a78c358a4cd244bd767c1a517a05459"
},
{
"url": "https://git.kernel.org/stable/c/806fcff98c1d7cb3c1dc0015e55ebdbe819e6b08"
},
{
"url": "https://git.kernel.org/stable/c/8037c5b2b2a447df52542f4d8535895d837bdcbd"
},
{
"url": "https://git.kernel.org/stable/c/611e7821c4f83a671455658797336faecc3a5196"
},
{
"url": "https://git.kernel.org/stable/c/5457025fa8ca3c0d2732109513de839e3e797190"
}
],
"title": "sched/psi: Shut down rtpoll_timer in psi_cgroup_free()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74594",
"datePublished": "2026-08-22T15:31:44.894Z",
"dateReserved": "2026-08-15T05:44:03.919Z",
"dateUpdated": "2026-08-25T05:40:21.246Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72121 (GCVE-0-2026-72121)
Vulnerability from cvelistv5
Published
2026-08-15 05:52
Modified
2026-08-19 16:36
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
can: bcm: add locking when updating filter and timer values
KCSAN detected a simultaneous access to timer values that can be
overwritten in bcm_rx_setup() when updating timer and filter content
while bcm_rx_handler(), bcm_rx_timeout_handler() or bcm_rx_thr_handler()
run concurrently on incoming CAN traffic.
Protect the timer (ival1/ival2/kt_ival1/kt_ival2/kt_lastmsg) and filter
(nframes/flags/frames/last_frames) updates in bcm_rx_setup() with a new
per-op bcm_rx_update_lock, taken with the matching scope in the RX
handlers. memcpy_from_msg() is staged into a temporary buffer before the
lock is taken, since it can sleep and must not run under a spinlock.
hrtimer_cancel() is always called without bcm_rx_update_lock held, since
bcm_rx_timeout_handler()/bcm_rx_thr_handler() take the same lock and a
running callback would otherwise deadlock against the canceller.
Also close a related race: bcm_rx_setup() cleared the RTR flag in the
stored reply frame's can_id as a separate, unprotected step after the
frame content was already installed, so a concurrent bcm_rx_handler()
could transmit a stale reply with CAN_RTR_FLAG still set. Fold that
normalization into the initial frame preparation instead (on the staged
buffer for updates, directly on op->frames pre-registration for new
ops), so the installed frame is always atomically self-consistent.
bcm_rx_handler()'s RX_RTR_FRAME check now takes a lock-protected
snapshot of op->flags before deciding whether to call bcm_can_tx(),
but does not hold the lock across that call.
Also take a lock-protected snapshot of the currframe in bcm_can_tx()
to avoid partly overwrites by content updates in bcm_tx_setup().
Finally check if a TX_RESET_MULTI_IDX/SETTIMER might have reset
op->currframe between the two locked sections in bcm_can_tx().
Omit calling hrtimer_forward() with zero interval in bcm_rx_thr_handler().
kt_ival2 may have been concurrently cleared by bcm_rx_setup() before it
cancels this timer, so check kt_ival2 inside the bcm_rx_update_lock.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 7595de7bc56e0e52b74e56c90f7e247bf626d628 Version: fbd8fdc2b218e979cfe422b139b8f74c12419d1f Version: 2a437b86ac5a9893c902f30ef66815bf13587bf6 Version: 76c84c3728178b2d38d5604e399dfe8b0752645e Version: cc55dd28c20a6611e30596019b3b2f636819a4c0 Version: c2aba69d0c36a496ab4f2e81e9c2b271f2693fd7 Version: c2aba69d0c36a496ab4f2e81e9c2b271f2693fd7 Version: c2aba69d0c36a496ab4f2e81e9c2b271f2693fd7 Version: 8f1c022541bf5a923c8d6fa483112c15250f30a4 Version: c4e8a172501e677ebd8ea9d9161d97dc4df56fbd Version: 5.10.238 ≤ Version: 5.15.185 ≤ Version: 6.1.141 ≤ Version: 6.6.93 ≤ Version: 6.12.31 ≤ Version: 5.4.294 ≤ Version: 6.14.9 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/can/bcm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "96994180bd7b248b0cc698afe926e23fc1bda59b",
"status": "affected",
"version": "7595de7bc56e0e52b74e56c90f7e247bf626d628",
"versionType": "git"
},
{
"lessThan": "caa8704a7f3cb7806331596195385437126ecb3a",
"status": "affected",
"version": "fbd8fdc2b218e979cfe422b139b8f74c12419d1f",
"versionType": "git"
},
{
"lessThan": "a7c369e7da8203e2b5be12bbcac7b9ab2ed5b658",
"status": "affected",
"version": "2a437b86ac5a9893c902f30ef66815bf13587bf6",
"versionType": "git"
},
{
"lessThan": "a7eb6db1cd3f7b556a301dc1265945ad112089f7",
"status": "affected",
"version": "76c84c3728178b2d38d5604e399dfe8b0752645e",
"versionType": "git"
},
{
"lessThan": "834cbca3b12e46887f7a9b35f1981a888360ea4c",
"status": "affected",
"version": "cc55dd28c20a6611e30596019b3b2f636819a4c0",
"versionType": "git"
},
{
"lessThan": "19b1994069dd29478ba767de1f98f14a088198dc",
"status": "affected",
"version": "c2aba69d0c36a496ab4f2e81e9c2b271f2693fd7",
"versionType": "git"
},
{
"lessThan": "fc9f5ee1b073bd233d9c604e338af4ebb42cbc33",
"status": "affected",
"version": "c2aba69d0c36a496ab4f2e81e9c2b271f2693fd7",
"versionType": "git"
},
{
"lessThan": "749179c2e25b95d22499ed29096b3e02d6dfd2b4",
"status": "affected",
"version": "c2aba69d0c36a496ab4f2e81e9c2b271f2693fd7",
"versionType": "git"
},
{
"status": "affected",
"version": "8f1c022541bf5a923c8d6fa483112c15250f30a4",
"versionType": "git"
},
{
"status": "affected",
"version": "c4e8a172501e677ebd8ea9d9161d97dc4df56fbd",
"versionType": "git"
},
{
"lessThan": "5.10.265",
"status": "affected",
"version": "5.10.238",
"versionType": "semver"
},
{
"lessThan": "5.15.216",
"status": "affected",
"version": "5.15.185",
"versionType": "semver"
},
{
"lessThan": "6.1.183",
"status": "affected",
"version": "6.1.141",
"versionType": "semver"
},
{
"lessThan": "6.6.148",
"status": "affected",
"version": "6.6.93",
"versionType": "semver"
},
{
"lessThan": "6.12.101",
"status": "affected",
"version": "6.12.31",
"versionType": "semver"
},
{
"lessThan": "5.5",
"status": "affected",
"version": "5.4.294",
"versionType": "semver"
},
{
"lessThan": "6.15",
"status": "affected",
"version": "6.14.9",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/can/bcm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.15"
},
{
"lessThan": "6.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.10.238",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.15.185",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "6.1.141",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.6.93",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.12.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "6.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.4.294",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.14.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: bcm: add locking when updating filter and timer values\n\nKCSAN detected a simultaneous access to timer values that can be\noverwritten in bcm_rx_setup() when updating timer and filter content\nwhile bcm_rx_handler(), bcm_rx_timeout_handler() or bcm_rx_thr_handler()\nrun concurrently on incoming CAN traffic.\n\nProtect the timer (ival1/ival2/kt_ival1/kt_ival2/kt_lastmsg) and filter\n(nframes/flags/frames/last_frames) updates in bcm_rx_setup() with a new\nper-op bcm_rx_update_lock, taken with the matching scope in the RX\nhandlers. memcpy_from_msg() is staged into a temporary buffer before the\nlock is taken, since it can sleep and must not run under a spinlock.\n\nhrtimer_cancel() is always called without bcm_rx_update_lock held, since\nbcm_rx_timeout_handler()/bcm_rx_thr_handler() take the same lock and a\nrunning callback would otherwise deadlock against the canceller.\n\nAlso close a related race: bcm_rx_setup() cleared the RTR flag in the\nstored reply frame\u0027s can_id as a separate, unprotected step after the\nframe content was already installed, so a concurrent bcm_rx_handler()\ncould transmit a stale reply with CAN_RTR_FLAG still set. Fold that\nnormalization into the initial frame preparation instead (on the staged\nbuffer for updates, directly on op-\u003eframes pre-registration for new\nops), so the installed frame is always atomically self-consistent.\n\nbcm_rx_handler()\u0027s RX_RTR_FRAME check now takes a lock-protected\nsnapshot of op-\u003eflags before deciding whether to call bcm_can_tx(),\nbut does not hold the lock across that call.\n\nAlso take a lock-protected snapshot of the currframe in bcm_can_tx()\nto avoid partly overwrites by content updates in bcm_tx_setup().\nFinally check if a TX_RESET_MULTI_IDX/SETTIMER might have reset\nop-\u003ecurrframe between the two locked sections in bcm_can_tx().\n\nOmit calling hrtimer_forward() with zero interval in bcm_rx_thr_handler().\nkt_ival2 may have been concurrently cleared by bcm_rx_setup() before it\ncancels this timer, so check kt_ival2 inside the bcm_rx_update_lock."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The race is driven by concurrent CAN frame reception in bcm_rx_handler()/timer callbacks on a shared CAN segment (automotive OBD/ECU bus, factory controllers, CAN-USB adapters), an adjacent broadcast medium comparable to Bluetooth/WiFi segment access.\nAC:L - An attacker controls both race sides by flooding RX_SETUP via sendmsg while concurrently injecting matching CAN frames or armed timers; syzbot reliably reproduced the KCSAN race without timing conditions beyond attacker control.\nPR:N - CAN_BCM sockets impose no capability checks in can_create()/bcm_sendmsg(), and a bus participant can trigger the RX handler path without any Linux credentials while racing BCM configuration updates from local services.\nUI:N - Exploitation requires no victim interaction beyond normal background CAN/BCM activity on systems that already use the Broadcast Manager for monitoring or diagnostics.\nS:U - Impact is confined to kernel memory corruption and privilege boundaries within the same host; this is not a VM escape, IOMMU bypass, or cross-authority sandbox breakout.\nC:H - Unlocked concurrent updates to nframes/flags/frames/last_frames permit torn reads and out-of-bounds accesses in handler loops and timeout memset, matching the prior BCM race class that produced KASAN slab-out-of-bounds reads.\nI:H - Partial overwrites of op-\u003eframes during bcm_can_tx(), stale RTR replies transmitted on the bus, and size-mismatched memset/memcpy against concurrently shrinking buffers enable arbitrary CAN injection and kernel heap corruption.\nA:H - Concurrent timer corruption (hrtimer_forward with zero kt_ival2), torn structure fields, and heap corruption from racing memset/copy operations can cause kernel oops, panic, or sustained denial of service on CAN-equipped systems."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:36:16.520Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/96994180bd7b248b0cc698afe926e23fc1bda59b"
},
{
"url": "https://git.kernel.org/stable/c/caa8704a7f3cb7806331596195385437126ecb3a"
},
{
"url": "https://git.kernel.org/stable/c/a7c369e7da8203e2b5be12bbcac7b9ab2ed5b658"
},
{
"url": "https://git.kernel.org/stable/c/a7eb6db1cd3f7b556a301dc1265945ad112089f7"
},
{
"url": "https://git.kernel.org/stable/c/834cbca3b12e46887f7a9b35f1981a888360ea4c"
},
{
"url": "https://git.kernel.org/stable/c/19b1994069dd29478ba767de1f98f14a088198dc"
},
{
"url": "https://git.kernel.org/stable/c/fc9f5ee1b073bd233d9c604e338af4ebb42cbc33"
},
{
"url": "https://git.kernel.org/stable/c/749179c2e25b95d22499ed29096b3e02d6dfd2b4"
}
],
"title": "can: bcm: add locking when updating filter and timer values",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72121",
"datePublished": "2026-08-15T05:52:59.959Z",
"dateReserved": "2026-08-09T03:40:39.907Z",
"dateUpdated": "2026-08-19T16:36:16.520Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68207 (GCVE-0-2026-68207)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: ti: vpe: unwind v4l2 device registration on probe error
If the vpe_top resource is missing, vpe_probe() returns -ENODEV after
v4l2_device_register() has succeeded. Probe failures do not call the
driver's remove callback, so the v4l2 device remains registered on that
error path.
Route that failure through the existing v4l2_device_unregister() unwind
label, matching the other errors after v4l2_device_register().
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 4d59c7d455853edca990848b1cb7c482b4628f32 Version: 4d59c7d455853edca990848b1cb7c482b4628f32 Version: 4d59c7d455853edca990848b1cb7c482b4628f32 Version: 4d59c7d455853edca990848b1cb7c482b4628f32 Version: 4d59c7d455853edca990848b1cb7c482b4628f32 Version: 4d59c7d455853edca990848b1cb7c482b4628f32 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/platform/ti/vpe/vpe.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "0f0a60c000876bcd808a70d602c758c2e64c77d8",
"status": "affected",
"version": "4d59c7d455853edca990848b1cb7c482b4628f32",
"versionType": "git"
},
{
"lessThan": "4ecf0cc0cf59032a89bcdf36fbbb03bff5455fd9",
"status": "affected",
"version": "4d59c7d455853edca990848b1cb7c482b4628f32",
"versionType": "git"
},
{
"lessThan": "7d383357905de975e1dbde639e5fa7477075d104",
"status": "affected",
"version": "4d59c7d455853edca990848b1cb7c482b4628f32",
"versionType": "git"
},
{
"lessThan": "7e6521dd747eca3cb3d4cd3ddcf20f266494f63d",
"status": "affected",
"version": "4d59c7d455853edca990848b1cb7c482b4628f32",
"versionType": "git"
},
{
"lessThan": "fcbbaf9cb9722a82f0221c56114037fc537f4ada",
"status": "affected",
"version": "4d59c7d455853edca990848b1cb7c482b4628f32",
"versionType": "git"
},
{
"lessThan": "e0f1c9a90ef665f2587c274a8fed59f2dfc575a6",
"status": "affected",
"version": "4d59c7d455853edca990848b1cb7c482b4628f32",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/platform/ti/vpe/vpe.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.5"
},
{
"lessThan": "5.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: ti: vpe: unwind v4l2 device registration on probe error\n\nIf the vpe_top resource is missing, vpe_probe() returns -ENODEV after\nv4l2_device_register() has succeeded. Probe failures do not call the\ndriver\u0027s remove callback, so the v4l2 device remains registered on that\nerror path.\n\nRoute that failure through the existing v4l2_device_unregister() unwind\nlabel, matching the other errors after v4l2_device_register()."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:29.282Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/0f0a60c000876bcd808a70d602c758c2e64c77d8"
},
{
"url": "https://git.kernel.org/stable/c/4ecf0cc0cf59032a89bcdf36fbbb03bff5455fd9"
},
{
"url": "https://git.kernel.org/stable/c/7d383357905de975e1dbde639e5fa7477075d104"
},
{
"url": "https://git.kernel.org/stable/c/7e6521dd747eca3cb3d4cd3ddcf20f266494f63d"
},
{
"url": "https://git.kernel.org/stable/c/fcbbaf9cb9722a82f0221c56114037fc537f4ada"
},
{
"url": "https://git.kernel.org/stable/c/e0f1c9a90ef665f2587c274a8fed59f2dfc575a6"
}
],
"title": "media: ti: vpe: unwind v4l2 device registration on probe error",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68207",
"datePublished": "2026-08-10T12:00:26.322Z",
"dateReserved": "2026-07-30T09:28:09.374Z",
"dateUpdated": "2026-08-19T16:31:29.282Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68432 (GCVE-0-2026-68432)
Vulnerability from cvelistv5
Published
2026-08-12 00:07
Modified
2026-08-19 16:35
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
vxlan: require CAP_NET_ADMIN in the device netns for changelink
A tunnel changelink() operates on at most two netns, dev_net(dev) and
the sticky underlay netns vxlan->net. They differ once the device is
created in or moved to a netns other than the one the request runs in.
The rtnl changelink path checks CAP_NET_ADMIN only against dev_net(dev),
so a caller privileged there but not in vxlan->net can rewrite a vxlan
device whose underlay lives in vxlan->net.
vxlan_changelink() validates and applies the new configuration against
vxlan->net (vxlan_config_validate(vxlan->net, ...)) and can reopen the
underlay socket in that netns, so the same reasoning as the tunnel
changelink series applies here.
Gate vxlan_changelink() with rtnl_dev_link_net_capable(), at the top of
the op before any attribute is parsed, matching ipgre_changelink() and
the rest of the "require CAP_NET_ADMIN in the device netns for
changelink" series.
Found by 0sec automated security-research tooling (https://0sec.ai).
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 8bcdc4f3a20be949df54b67e5ae2734daabb5792 Version: 8bcdc4f3a20be949df54b67e5ae2734daabb5792 Version: 8bcdc4f3a20be949df54b67e5ae2734daabb5792 Version: 8bcdc4f3a20be949df54b67e5ae2734daabb5792 Version: 8bcdc4f3a20be949df54b67e5ae2734daabb5792 Version: 8bcdc4f3a20be949df54b67e5ae2734daabb5792 Version: 8bcdc4f3a20be949df54b67e5ae2734daabb5792 Version: 8bcdc4f3a20be949df54b67e5ae2734daabb5792 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/vxlan/vxlan_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b95a8743e58f7efed5ddc4cb73829b66f17feab0",
"status": "affected",
"version": "8bcdc4f3a20be949df54b67e5ae2734daabb5792",
"versionType": "git"
},
{
"lessThan": "7465ade989ba84adc2bfa58bad3ca25d249f0f7a",
"status": "affected",
"version": "8bcdc4f3a20be949df54b67e5ae2734daabb5792",
"versionType": "git"
},
{
"lessThan": "0aa580a8bbbed2507b4582a1f0ef581d480d06ed",
"status": "affected",
"version": "8bcdc4f3a20be949df54b67e5ae2734daabb5792",
"versionType": "git"
},
{
"lessThan": "b3793d7dccb192ffff29894d11824db6251acdd5",
"status": "affected",
"version": "8bcdc4f3a20be949df54b67e5ae2734daabb5792",
"versionType": "git"
},
{
"lessThan": "32d10c46bfde3e9b274e9e1bd6399d0ebea8f60f",
"status": "affected",
"version": "8bcdc4f3a20be949df54b67e5ae2734daabb5792",
"versionType": "git"
},
{
"lessThan": "730c7e5fea7f06e0cdf21c547222ec93234fd1d6",
"status": "affected",
"version": "8bcdc4f3a20be949df54b67e5ae2734daabb5792",
"versionType": "git"
},
{
"lessThan": "e8ad0d311e225939a9a6c745d6cc384c7364ec87",
"status": "affected",
"version": "8bcdc4f3a20be949df54b67e5ae2734daabb5792",
"versionType": "git"
},
{
"lessThan": "3a61bd9637f3d929aa846e4eb3d98b48c26fcb0e",
"status": "affected",
"version": "8bcdc4f3a20be949df54b67e5ae2734daabb5792",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/vxlan/vxlan_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.11"
},
{
"lessThan": "4.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nvxlan: require CAP_NET_ADMIN in the device netns for changelink\n\nA tunnel changelink() operates on at most two netns, dev_net(dev) and\nthe sticky underlay netns vxlan-\u003enet. They differ once the device is\ncreated in or moved to a netns other than the one the request runs in.\nThe rtnl changelink path checks CAP_NET_ADMIN only against dev_net(dev),\nso a caller privileged there but not in vxlan-\u003enet can rewrite a vxlan\ndevice whose underlay lives in vxlan-\u003enet.\n\nvxlan_changelink() validates and applies the new configuration against\nvxlan-\u003enet (vxlan_config_validate(vxlan-\u003enet, ...)) and can reopen the\nunderlay socket in that netns, so the same reasoning as the tunnel\nchangelink series applies here.\n\nGate vxlan_changelink() with rtnl_dev_link_net_capable(), at the top of\nthe op before any attribute is parsed, matching ipgre_changelink() and\nthe rest of the \"require CAP_NET_ADMIN in the device netns for\nchangelink\" series.\n\nFound by 0sec automated security-research tooling (https://0sec.ai)."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires issuing an RTM_NEWLINK changelink request over an rtnetlink socket on the local system, matching the kernel guidance that netlink configuration paths are Local.\nAC:L - Once a cross-namespace vxlan device is present in the caller\u0027s netns, the missing check is bypassed by a single deterministic netlink changelink call with no race, timing, or memory-layout dependency.\nPR:L - The rtnl entry path only requires CAP_NET_ADMIN in dev_net(dev), which an unprivileged user obtains inside a user namespace via unshare --user --map-root-user --net; no privilege in the underlay netns vxlan-\u003enet is needed.\nUI:N - The attack is fully programmatic through netlink from the attacker\u0027s own process; no victim action such as mounting, opening a file, or clicking is required.\nS:C - Authorization is evaluated against dev_net(dev) while the configuration is validated and applied against vxlan-\u003enet, so the impact crosses from the attacker\u0027s net/user namespace into another tenant\u0027s or the host\u0027s network namespace.\nC:H - The attacker can rewrite IFLA_VXLAN_GROUP/LOCAL and the underlay IFLA_VXLAN_LINK so encapsulated overlay traffic in the victim netns is sent to an attacker-controlled endpoint, exposing tunneled payloads.\nI:H - Unauthorized changelink mutates live tunnel state in the victim underlay netns (remote/local addresses, lower device, TOS/TTL/label, learning and proxy/RSC flags, default-remote FDB entries), enabling redirection and injection of overlay traffic.\nA:H - Rewriting the remote group, source address, or lower device tears down and re-establishes multicast group membership and forwarding state, causing sustained loss of connectivity for every service riding the affected VXLAN overlay."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:35:30.743Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b95a8743e58f7efed5ddc4cb73829b66f17feab0"
},
{
"url": "https://git.kernel.org/stable/c/7465ade989ba84adc2bfa58bad3ca25d249f0f7a"
},
{
"url": "https://git.kernel.org/stable/c/0aa580a8bbbed2507b4582a1f0ef581d480d06ed"
},
{
"url": "https://git.kernel.org/stable/c/b3793d7dccb192ffff29894d11824db6251acdd5"
},
{
"url": "https://git.kernel.org/stable/c/32d10c46bfde3e9b274e9e1bd6399d0ebea8f60f"
},
{
"url": "https://git.kernel.org/stable/c/730c7e5fea7f06e0cdf21c547222ec93234fd1d6"
},
{
"url": "https://git.kernel.org/stable/c/e8ad0d311e225939a9a6c745d6cc384c7364ec87"
},
{
"url": "https://git.kernel.org/stable/c/3a61bd9637f3d929aa846e4eb3d98b48c26fcb0e"
}
],
"title": "vxlan: require CAP_NET_ADMIN in the device netns for changelink",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68432",
"datePublished": "2026-08-12T00:07:18.806Z",
"dateReserved": "2026-07-30T09:28:09.393Z",
"dateUpdated": "2026-08-19T16:35:30.743Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74485 (GCVE-0-2026-74485)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-19 16:37
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
binfmt_misc: reject a flag character as the field delimiter
The registration string starts with a user chosen delimiter that
separates the individual fields. So that the field parsers terminate
even on a truncated string create_entry() pads the buffer with that
same delimiter:
memset(buf + count, del, 8);
Most fields are scanned for the delimiter with strchr()/scanarg() and
happily stop on the padding. The flags field is different: instead of
scanning for the delimiter check_special_flags() consumes the flag
characters 'P', 'O', 'C' and 'F' and stops at the first byte that is
none of them, relying on the trailing delimiter to end the scan.
If the delimiter is itself a flag character the padding no longer acts
as a terminator. The scan swallows all eight padding bytes and keeps
reading past the end of the allocation until it hits a byte that is
not a flag character. For example registering
PaPEPPxPPiP
with 'P' as the delimiter (name "a", type extension, magic "x",
interpreter "i", empty flags) leaves the flag scan running off the end
of the buffer. The registration is rejected in the end because the
parser does not stop exactly at buf + count, but only after the out of
bounds read has already happened. With an unlucky allocation layout the
scan can walk into an unmapped page; under KASAN it is reported as a
slab out of bounds read. binfmt_misc mounts are available to
unprivileged users in a user namespace so the read is reachable without
privileges.
Reject a delimiter that is one of the flag characters up front. Such a
registration was always rejected anyway, only after the out of bounds
read, so no valid registration string changes meaning.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/binfmt_misc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "96bd5d4fea2970b9b08265293ca7a10b9b27c0fd",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "9970e094e5d60f0d66914bf9a97d1ef19107ebf5",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "b29e3c1f375c1296362d219ff38bceddf2d2a88a",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "1819f82dee766c58295ecaacdac02cdf6837d7a4",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "1853e95c9bfe69ef1dd862b3f551e68f4a1b76cc",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "840bb9c49c3e75fb32b593d67ab32f6b77122262",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "9a2d87db3898b5993b64fd258d0334e0eba9ee0d",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "8e85d50ba1117fd446bf9a250bd8a97d48384bdc",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/binfmt_misc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbinfmt_misc: reject a flag character as the field delimiter\n\nThe registration string starts with a user chosen delimiter that\nseparates the individual fields. So that the field parsers terminate\neven on a truncated string create_entry() pads the buffer with that\nsame delimiter:\n\n\tmemset(buf + count, del, 8);\n\nMost fields are scanned for the delimiter with strchr()/scanarg() and\nhappily stop on the padding. The flags field is different: instead of\nscanning for the delimiter check_special_flags() consumes the flag\ncharacters \u0027P\u0027, \u0027O\u0027, \u0027C\u0027 and \u0027F\u0027 and stops at the first byte that is\nnone of them, relying on the trailing delimiter to end the scan.\n\nIf the delimiter is itself a flag character the padding no longer acts\nas a terminator. The scan swallows all eight padding bytes and keeps\nreading past the end of the allocation until it hits a byte that is\nnot a flag character. For example registering\n\n\tPaPEPPxPPiP\n\nwith \u0027P\u0027 as the delimiter (name \"a\", type extension, magic \"x\",\ninterpreter \"i\", empty flags) leaves the flag scan running off the end\nof the buffer. The registration is rejected in the end because the\nparser does not stop exactly at buf + count, but only after the out of\nbounds read has already happened. With an unlucky allocation layout the\nscan can walk into an unmapped page; under KASAN it is reported as a\nslab out of bounds read. binfmt_misc mounts are available to\nunprivileged users in a user namespace so the read is reachable without\nprivileges.\n\nReject a delimiter that is one of the flag characters up front. Such a\nregistration was always rejected anyway, only after the out of bounds\nread, so no valid registration string changes meaning."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires a local write() to binfmt_misc/register via bm_register_write()-\u003ecreate_entry(); the path is a VFS syscall on a mounted filesystem, not any network protocol or remote packet handler.\nAC:L - An attacker fully controls the registration string and can deterministically choose delimiter P/O/C/F with empty flags so check_special_flags() consumes padding and reads past the kmalloc buffer on every attempt; no race or victim-specific state is required.\nPR:L - binfmt_misc has FS_USERNS_MOUNT; an unprivileged local user can unshare a user namespace, mount binfmt_misc, and write register without init-namespace root, matching the fix commit\u0027s stated unprivileged reachability.\nUI:N - Triggering is entirely attacker-driven through mounting binfmt_misc and writing a crafted registration string; no victim must open files, click links, or perform any interactive action beyond the attacker\u0027s own syscalls.\nS:U - The slab out-of-bounds read and any disclosed kernel data remain within the host kernel security authority; this is standard local kernel memory access, not a VM escape, IOMMU bypass, or sandbox boundary crossing.\nC:H - check_special_flags() scans past buf+count+8 through adjacent kmalloc/slab memory until a non-P/O/C/F byte, a classic out-of-bounds read that can disclose kernel pointers and other sensitive heap contents for KASLR defeat.\nI:N - The defect is read-only: check_special_flags() only dereferences bytes beyond the allocation and sets flags on the soon-freed Node; it performs no out-of-bounds write, metadata corruption, or control-flow hijack primitive.\nA:H - The unbounded flag scan can walk into an unmapped page and fault the kernel; KASAN reports slab-out-of-bounds, and the single write() to register is trivially repeatable for denial-of-service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:37:40.898Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/96bd5d4fea2970b9b08265293ca7a10b9b27c0fd"
},
{
"url": "https://git.kernel.org/stable/c/9970e094e5d60f0d66914bf9a97d1ef19107ebf5"
},
{
"url": "https://git.kernel.org/stable/c/b29e3c1f375c1296362d219ff38bceddf2d2a88a"
},
{
"url": "https://git.kernel.org/stable/c/1819f82dee766c58295ecaacdac02cdf6837d7a4"
},
{
"url": "https://git.kernel.org/stable/c/1853e95c9bfe69ef1dd862b3f551e68f4a1b76cc"
},
{
"url": "https://git.kernel.org/stable/c/840bb9c49c3e75fb32b593d67ab32f6b77122262"
},
{
"url": "https://git.kernel.org/stable/c/9a2d87db3898b5993b64fd258d0334e0eba9ee0d"
},
{
"url": "https://git.kernel.org/stable/c/8e85d50ba1117fd446bf9a250bd8a97d48384bdc"
}
],
"title": "binfmt_misc: reject a flag character as the field delimiter",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74485",
"datePublished": "2026-08-15T12:27:16.980Z",
"dateReserved": "2026-08-15T05:44:03.905Z",
"dateUpdated": "2026-08-19T16:37:40.898Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74475 (GCVE-0-2026-74475)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-19 16:37
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
vxlan: use neigh_ha_snapshot() in route_shortcircuit()
The neighbour hardware address n->ha can be updated asynchronously by the
neighbour subsystem, protected by n->ha_lock seqlock. Reading n->ha without
holding the seqlock loop can lead to torn reads or reading a partially updated
MAC address.
Use neigh_ha_snapshot() in route_shortcircuit() to safely copy n->ha under
read_seqbegin()/read_seqretry() lock protection before using it.
Note that arp_reduce() and neigh_reduce() seem to have the same issue
left for future patches.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: e4f67addf158f98f8197e08974966b18480dc751 Version: e4f67addf158f98f8197e08974966b18480dc751 Version: e4f67addf158f98f8197e08974966b18480dc751 Version: e4f67addf158f98f8197e08974966b18480dc751 Version: e4f67addf158f98f8197e08974966b18480dc751 Version: e4f67addf158f98f8197e08974966b18480dc751 Version: e4f67addf158f98f8197e08974966b18480dc751 Version: e4f67addf158f98f8197e08974966b18480dc751 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/vxlan/vxlan_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "32a9590a8d30426e3db63e6b20893e47e02576c0",
"status": "affected",
"version": "e4f67addf158f98f8197e08974966b18480dc751",
"versionType": "git"
},
{
"lessThan": "d0993fc053f29e15cc7c9fe2029df3882a2ab5ab",
"status": "affected",
"version": "e4f67addf158f98f8197e08974966b18480dc751",
"versionType": "git"
},
{
"lessThan": "87210054bad82bbae6f483a742dc45722fb47a6b",
"status": "affected",
"version": "e4f67addf158f98f8197e08974966b18480dc751",
"versionType": "git"
},
{
"lessThan": "d08e8ac13f2e228cc7fc3c70b5ebe71557b624a0",
"status": "affected",
"version": "e4f67addf158f98f8197e08974966b18480dc751",
"versionType": "git"
},
{
"lessThan": "ec341bb76d77b4c2948764375ee6bfeef4bb41c3",
"status": "affected",
"version": "e4f67addf158f98f8197e08974966b18480dc751",
"versionType": "git"
},
{
"lessThan": "ff89415d34c3ab9f5312316423122e664ed3524f",
"status": "affected",
"version": "e4f67addf158f98f8197e08974966b18480dc751",
"versionType": "git"
},
{
"lessThan": "05f2987f73daa05333fd713d05546142f9f7c5f0",
"status": "affected",
"version": "e4f67addf158f98f8197e08974966b18480dc751",
"versionType": "git"
},
{
"lessThan": "8eca411347e1d38964f9ed2c8d3b6ab0e7e4473d",
"status": "affected",
"version": "e4f67addf158f98f8197e08974966b18480dc751",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/vxlan/vxlan_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.8"
},
{
"lessThan": "3.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "3.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "3.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "3.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "3.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nvxlan: use neigh_ha_snapshot() in route_shortcircuit()\n\nThe neighbour hardware address n-\u003eha can be updated asynchronously by the\nneighbour subsystem, protected by n-\u003eha_lock seqlock. Reading n-\u003eha without\nholding the seqlock loop can lead to torn reads or reading a partially updated\nMAC address.\n\nUse neigh_ha_snapshot() in route_shortcircuit() to safely copy n-\u003eha under\nread_seqbegin()/read_seqretry() lock protection before using it.\n\nNote that arp_reduce() and neigh_reduce() seem to have the same issue\nleft for future patches."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 10,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - route_shortcircuit() runs on the vxlan_xmit() transmit path when overlay IP/IPv6 traffic is encapsulated; in cloud/SDN VTEP deployments a remote tenant can drive dev_queue_xmit() through bridge/IP forwarding without any local syscall or netlink access.\nAC:L - The attacker controls both sides of the race by concurrently sending overlay traffic that hits route_shortcircuit() and generating neighbour ha updates (ARP/NDP churn); repeated attempts do not depend on victim state or uncontrollable memory layout.\nPR:N - Exploitation requires only the ability to send overlay/underlay packets to a VTEP that already has VXLAN_F_RSC and router FDB entries configured by infrastructure; no CAP_NET_ADMIN, root, or host credentials are needed on the victim.\nUI:N - Triggering is automatic during kernel packet forwarding and VXLAN encapsulation once matching traffic flows; no mount, file open, or other victim action is required beyond normal overlay operation.\nS:C - A torn n-\u003eha read can rewrite the skb Ethernet destination and reselect a different FDB remote, mis-encapsulating traffic to an unintended VXLAN peer and crossing intended multi-tenant overlay segmentation boundaries beyond the local VTEP authority.\nC:H - Unsynchronized reads of neighbour ha during concurrent updates yield torn MAC values that drive post-rewrite FDB lookup and encapsulation, potentially delivering other tenants\u0027 overlay frames to an attacker-controlled remote endpoint or leaking mixed neighbour state.\nI:H - The corrupted hardware address is copied into the skb Ethernet header and steers subsequent vxlan_find_mac_tx()/vxlan_xmit_one() encapsulation, enabling deterministic overlay traffic redirection or injection toward an attacker-chosen VTEP rather than the intended router destination.\nA:L - While the host kernel does not panic, torn MAC rewriting can cause mis-encapsulation, FDB misses, and dropped or misdelivered overlay packets, producing intermittent connectivity loss and performance degradation on affected VTEP nodes under sustained attack."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:37:28.096Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/32a9590a8d30426e3db63e6b20893e47e02576c0"
},
{
"url": "https://git.kernel.org/stable/c/d0993fc053f29e15cc7c9fe2029df3882a2ab5ab"
},
{
"url": "https://git.kernel.org/stable/c/87210054bad82bbae6f483a742dc45722fb47a6b"
},
{
"url": "https://git.kernel.org/stable/c/d08e8ac13f2e228cc7fc3c70b5ebe71557b624a0"
},
{
"url": "https://git.kernel.org/stable/c/ec341bb76d77b4c2948764375ee6bfeef4bb41c3"
},
{
"url": "https://git.kernel.org/stable/c/ff89415d34c3ab9f5312316423122e664ed3524f"
},
{
"url": "https://git.kernel.org/stable/c/05f2987f73daa05333fd713d05546142f9f7c5f0"
},
{
"url": "https://git.kernel.org/stable/c/8eca411347e1d38964f9ed2c8d3b6ab0e7e4473d"
}
],
"title": "vxlan: use neigh_ha_snapshot() in route_shortcircuit()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74475",
"datePublished": "2026-08-15T12:27:10.685Z",
"dateReserved": "2026-08-15T05:44:03.903Z",
"dateUpdated": "2026-08-19T16:37:28.096Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68398 (GCVE-0-2026-68398)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF
pppol2tp_recv() runs in the L2TP UDP-encap softirq RX path:
l2tp_udp_encap_recv() -> l2tp_recv_common() -> pppol2tp_recv()
-> ppp_input(&po->chan)
It runs under rcu_read_lock() holding only an l2tp_session reference and
takes NO reference on the internal PPP channel (struct channel,
chan->ppp) that ppp_input() dereferences.
The pppox socket is SOCK_RCU_FREE, so 'po' and the embedded ppp_channel
are RCU-safe. But the internal struct channel is a separate allocation
that ppp_release_channel() frees with a plain kfree():
close(data socket) -> pppol2tp_release() -> pppox_unbind_sock()
-> ppp_unregister_channel() -> ppp_release_channel() -> kfree(pch)
For a channel that is bound (PPPIOCGCHAN) but not attached to a ppp unit
(no PPPIOCCONNECT, pch->ppp == NULL) and not bridged, teardown skips
both ppp_disconnect_channel()'s synchronize_net() and
ppp_unbridge_channels()'s synchronize_rcu(), so the kfree() has no grace
period. rcu_read_lock() in pppol2tp_recv() does not protect against a
plain kfree(), so an in-flight ppp_input() on one CPU can dereference
the channel just freed by close() on another CPU.
The bug is reachable by an unprivileged user.
Defer the channel free to an RCU callback via call_rcu() so the grace
period fences any in-flight ppp_input(). The disconnect and unbridge
teardown paths already fence with synchronize_net()/synchronize_rcu();
call_rcu() does the same here without stalling the close() path.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ee40fb2e1eb5bc0ddd3f2f83c6e39a454ef5a741 Version: ee40fb2e1eb5bc0ddd3f2f83c6e39a454ef5a741 Version: ee40fb2e1eb5bc0ddd3f2f83c6e39a454ef5a741 Version: ee40fb2e1eb5bc0ddd3f2f83c6e39a454ef5a741 Version: ee40fb2e1eb5bc0ddd3f2f83c6e39a454ef5a741 Version: ee40fb2e1eb5bc0ddd3f2f83c6e39a454ef5a741 Version: ee40fb2e1eb5bc0ddd3f2f83c6e39a454ef5a741 Version: d36e5ba7bbed5d7bd26e8609ffed503c2def401b Version: 9bcc0508576b2d50efd958f2ea1c5906749c2c89 Version: c2984681fe15cfb803a9132aaaf1140ab20a72c1 Version: 5803ecd7f6ac6f747582e775caa62ac9d0489261 Version: 26f8819ddd10141ebe7bbce700fbab36bfa5f478 Version: 3.2.99 ≤ Version: 3.16.54 ≤ Version: 4.4.225 ≤ Version: 4.9.225 ≤ Version: 4.14.182 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ppp/ppp_generic.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "4e47f1ac188ece11d6fdabe44166a2776cc5bd4e",
"status": "affected",
"version": "ee40fb2e1eb5bc0ddd3f2f83c6e39a454ef5a741",
"versionType": "git"
},
{
"lessThan": "110b765744b147c63882f5e9cb12931c5dc8d85f",
"status": "affected",
"version": "ee40fb2e1eb5bc0ddd3f2f83c6e39a454ef5a741",
"versionType": "git"
},
{
"lessThan": "4bb84e964ff0fe0a171c965362de72f9820dbce9",
"status": "affected",
"version": "ee40fb2e1eb5bc0ddd3f2f83c6e39a454ef5a741",
"versionType": "git"
},
{
"lessThan": "3ab32218d7182705dae5c86f13925f458072da2c",
"status": "affected",
"version": "ee40fb2e1eb5bc0ddd3f2f83c6e39a454ef5a741",
"versionType": "git"
},
{
"lessThan": "c9574b8a8edeb4edd3ac6472c27ef7184bdb2baa",
"status": "affected",
"version": "ee40fb2e1eb5bc0ddd3f2f83c6e39a454ef5a741",
"versionType": "git"
},
{
"lessThan": "06213c85d8c0994f786c093b8b2a517987943ca6",
"status": "affected",
"version": "ee40fb2e1eb5bc0ddd3f2f83c6e39a454ef5a741",
"versionType": "git"
},
{
"lessThan": "ec4215683e47424c9c4762fd3c60f552a3119142",
"status": "affected",
"version": "ee40fb2e1eb5bc0ddd3f2f83c6e39a454ef5a741",
"versionType": "git"
},
{
"status": "affected",
"version": "d36e5ba7bbed5d7bd26e8609ffed503c2def401b",
"versionType": "git"
},
{
"status": "affected",
"version": "9bcc0508576b2d50efd958f2ea1c5906749c2c89",
"versionType": "git"
},
{
"status": "affected",
"version": "c2984681fe15cfb803a9132aaaf1140ab20a72c1",
"versionType": "git"
},
{
"status": "affected",
"version": "5803ecd7f6ac6f747582e775caa62ac9d0489261",
"versionType": "git"
},
{
"status": "affected",
"version": "26f8819ddd10141ebe7bbce700fbab36bfa5f478",
"versionType": "git"
},
{
"lessThan": "3.3",
"status": "affected",
"version": "3.2.99",
"versionType": "semver"
},
{
"lessThan": "3.17",
"status": "affected",
"version": "3.16.54",
"versionType": "semver"
},
{
"lessThan": "4.5",
"status": "affected",
"version": "4.4.225",
"versionType": "semver"
},
{
"lessThan": "4.10",
"status": "affected",
"version": "4.9.225",
"versionType": "semver"
},
{
"lessThan": "4.15",
"status": "affected",
"version": "4.14.182",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ppp/ppp_generic.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.15"
},
{
"lessThan": "4.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.2.99",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.16.54",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.4.225",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.9.225",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.14.182",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF\n\npppol2tp_recv() runs in the L2TP UDP-encap softirq RX path:\n\n l2tp_udp_encap_recv() -\u003e l2tp_recv_common() -\u003e pppol2tp_recv()\n -\u003e ppp_input(\u0026po-\u003echan)\n\nIt runs under rcu_read_lock() holding only an l2tp_session reference and\ntakes NO reference on the internal PPP channel (struct channel,\nchan-\u003eppp) that ppp_input() dereferences.\n\nThe pppox socket is SOCK_RCU_FREE, so \u0027po\u0027 and the embedded ppp_channel\nare RCU-safe. But the internal struct channel is a separate allocation\nthat ppp_release_channel() frees with a plain kfree():\n\n close(data socket) -\u003e pppol2tp_release() -\u003e pppox_unbind_sock()\n -\u003e ppp_unregister_channel() -\u003e ppp_release_channel() -\u003e kfree(pch)\n\nFor a channel that is bound (PPPIOCGCHAN) but not attached to a ppp unit\n(no PPPIOCCONNECT, pch-\u003eppp == NULL) and not bridged, teardown skips\nboth ppp_disconnect_channel()\u0027s synchronize_net() and\nppp_unbridge_channels()\u0027s synchronize_rcu(), so the kfree() has no grace\nperiod. rcu_read_lock() in pppol2tp_recv() does not protect against a\nplain kfree(), so an in-flight ppp_input() on one CPU can dereference\nthe channel just freed by close() on another CPU.\n\nThe bug is reachable by an unprivileged user.\n\nDefer the channel free to an RCU callback via call_rcu() so the grace\nperiod fences any in-flight ppp_input(). The disconnect and unbridge\nteardown paths already fence with synchronize_net()/synchronize_rcu();\ncall_rcu() does the same here without stalling the close() path."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The free side of the race is a local close() of the pppol2tp socket, which no remote peer can invoke; the full attack (create tunnel/session via AF_PPPOX socket, drive RX with loopback UDP datagrams, close concurrently) is performed entirely through local syscalls.\nAC:L - The attacker controls both sides of the race, feeding the UDP-encap RX softirq from one thread while closing the pppox socket on another, and can retry the loop indefinitely until the window is hit.\nPR:L - No capability check exists on this path: pppox_create()/pppol2tp_connect() and ppp_register_net_channel() need no CAP_NET_ADMIN, and PPPIOCGCHAN is handled by pppox_ioctl() on the socket itself, so /dev/ppp access is not required; the fix commit states the bug is reachable by an unprivileged user.\nUI:N - The attacker performs every step \u2014 socket creation, session setup, packet injection and close() \u2014 with no action by any other user or administrator.\nS:U - The use-after-free corrupts kernel slab memory within the same kernel security authority; no VM, IOMMU or sandbox boundary is crossed.\nC:H - After the channel is freed and its slab object reallocated, ppp_input() reads pch-\u003ebridge and pch-\u003eppp from attacker-groomed memory and can route received frames to an arbitrary attacker-chosen structure, giving a path to disclosing kernel memory.\nI:H - skb_queue_tail(\u0026pch-\u003efile.rq, skb) writes a linked-list insertion into the freed object and wake_up_interruptible(\u0026pch-\u003efile.rwait) traverses a freed waitqueue, so heap grooming yields controlled writes and function-pointer traversal usable for privilege escalation.\nA:H - Dereferencing and writing to the kfree()d struct channel from softirq context reliably corrupts the slab and panics or oopses the kernel, and the race can be re-triggered at will."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:49.839Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/4e47f1ac188ece11d6fdabe44166a2776cc5bd4e"
},
{
"url": "https://git.kernel.org/stable/c/110b765744b147c63882f5e9cb12931c5dc8d85f"
},
{
"url": "https://git.kernel.org/stable/c/4bb84e964ff0fe0a171c965362de72f9820dbce9"
},
{
"url": "https://git.kernel.org/stable/c/3ab32218d7182705dae5c86f13925f458072da2c"
},
{
"url": "https://git.kernel.org/stable/c/c9574b8a8edeb4edd3ac6472c27ef7184bdb2baa"
},
{
"url": "https://git.kernel.org/stable/c/06213c85d8c0994f786c093b8b2a517987943ca6"
},
{
"url": "https://git.kernel.org/stable/c/ec4215683e47424c9c4762fd3c60f552a3119142"
}
],
"title": "ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68398",
"datePublished": "2026-08-10T12:04:17.771Z",
"dateReserved": "2026-07-30T09:28:09.389Z",
"dateUpdated": "2026-08-19T16:34:49.839Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80770 (GCVE-0-2026-80770)
Vulnerability from cvelistv5
Published
2026-09-04 15:12
Modified
2026-09-04 15:12
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
HID: nintendo: stop device IO before hid_hw_stop on probe failure
nintendo_hid_probe() calls hid_device_io_start() before joycon_init()
and joycon_leds_create(). If either fails, the error path jumps to
err_close which calls hid_hw_close()/hid_hw_stop() without first calling
hid_device_io_stop().
hid_hw_stop() does not stop device IO, so hid_input_report() may still
run and access driver data that is being torn down, resulting in a
use-after-free.
Add an err_io_stop label that calls hid_device_io_stop() before
hid_hw_close(), and point the two post-io_start error paths at it.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 2af16c1f846bd60240745bbd3afa13d5f040c61a Version: 2af16c1f846bd60240745bbd3afa13d5f040c61a Version: 2af16c1f846bd60240745bbd3afa13d5f040c61a Version: 2af16c1f846bd60240745bbd3afa13d5f040c61a Version: 2af16c1f846bd60240745bbd3afa13d5f040c61a Version: 2af16c1f846bd60240745bbd3afa13d5f040c61a Version: 2af16c1f846bd60240745bbd3afa13d5f040c61a |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/hid/hid-nintendo.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c2f3d51c7f5222f5b51e0c90f02258d82e1b44dd",
"status": "affected",
"version": "2af16c1f846bd60240745bbd3afa13d5f040c61a",
"versionType": "git"
},
{
"lessThan": "c023443f0e6cfd257846b6515c93c1ea08026593",
"status": "affected",
"version": "2af16c1f846bd60240745bbd3afa13d5f040c61a",
"versionType": "git"
},
{
"lessThan": "03a84f9f88b42cd49752ec0259922b67e4b88598",
"status": "affected",
"version": "2af16c1f846bd60240745bbd3afa13d5f040c61a",
"versionType": "git"
},
{
"lessThan": "5efcd7bbfaaec67d137c99aa0940fa34375db27f",
"status": "affected",
"version": "2af16c1f846bd60240745bbd3afa13d5f040c61a",
"versionType": "git"
},
{
"lessThan": "13a3edf96568a0b7aacadea07c2adec53ac8f630",
"status": "affected",
"version": "2af16c1f846bd60240745bbd3afa13d5f040c61a",
"versionType": "git"
},
{
"lessThan": "2e0d98dc8a6dea5fc2b72bf66e0dcbd5488644b4",
"status": "affected",
"version": "2af16c1f846bd60240745bbd3afa13d5f040c61a",
"versionType": "git"
},
{
"lessThan": "1f74d3bff6fe04a64e02ab3661d2e0d554565aa6",
"status": "affected",
"version": "2af16c1f846bd60240745bbd3afa13d5f040c61a",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/hid/hid-nintendo.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.16"
},
{
"lessThan": "5.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.187",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.156",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.106",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.47",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.1",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.187",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.156",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.106",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.47",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.11",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.1",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "5.16",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: nintendo: stop device IO before hid_hw_stop on probe failure\n\nnintendo_hid_probe() calls hid_device_io_start() before joycon_init()\nand joycon_leds_create(). If either fails, the error path jumps to\nerr_close which calls hid_hw_close()/hid_hw_stop() without first calling\nhid_device_io_stop().\n\nhid_hw_stop() does not stop device IO, so hid_input_report() may still\nrun and access driver data that is being torn down, resulting in a\nuse-after-free.\n\nAdd an err_io_stop label that calls hid_device_io_stop() before\nhid_hw_close(), and point the two post-io_start error paths at it."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T15:12:42.327Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c2f3d51c7f5222f5b51e0c90f02258d82e1b44dd"
},
{
"url": "https://git.kernel.org/stable/c/c023443f0e6cfd257846b6515c93c1ea08026593"
},
{
"url": "https://git.kernel.org/stable/c/03a84f9f88b42cd49752ec0259922b67e4b88598"
},
{
"url": "https://git.kernel.org/stable/c/5efcd7bbfaaec67d137c99aa0940fa34375db27f"
},
{
"url": "https://git.kernel.org/stable/c/13a3edf96568a0b7aacadea07c2adec53ac8f630"
},
{
"url": "https://git.kernel.org/stable/c/2e0d98dc8a6dea5fc2b72bf66e0dcbd5488644b4"
},
{
"url": "https://git.kernel.org/stable/c/1f74d3bff6fe04a64e02ab3661d2e0d554565aa6"
}
],
"title": "HID: nintendo: stop device IO before hid_hw_stop on probe failure",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80770",
"datePublished": "2026-09-04T15:12:42.327Z",
"dateReserved": "2026-08-26T14:34:25.792Z",
"dateUpdated": "2026-09-04T15:12:42.327Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80856 (GCVE-0-2026-80856)
Vulnerability from cvelistv5
Published
2026-09-04 15:55
Modified
2026-09-04 15:55
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
fuse: fix invalidate lock leak on setattr writeback failure
fuse_do_setattr() takes filemap_invalidate_lock() for a DAX truncate
(fault_blocked = true) and releases it at the out:/error: labels. But
when a writeback flush is also needed, a write_inode_now() failure
returns directly and leaks the lock, so any later fault or truncate on
the file stalls on the stale rwsem.
For example, truncate(2) on a setuid file reaches fuse_do_setattr()
with both ATTR_SIZE and ATTR_MODE set:
truncate(2)
└─ do_truncate()
├─ dentry_needs_remove_privs() # S_ISUID
└─ notify_change() # KILL_SUID -> ATTR_MODE
└─ fuse_setattr() # no killpriv:
│ # ia_valid |= ATTR_MODE
└─ fuse_do_setattr()
├─ filemap_invalidate_lock() # IS_DAX && is_truncate
└─ write_inode_now() # is_wb && ATTR_MODE
└─ if (err) # e.g. daemon -> -EIO
return err # <- lock leaked
Fix this by adding an unlock label that releases the lock before
returning the error, and use it for the fuse_dax_break_layouts()
failure path as well.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 6ae330cad6ef22ab8347ea9e0707dc56a7c7363f Version: 6ae330cad6ef22ab8347ea9e0707dc56a7c7363f Version: 6ae330cad6ef22ab8347ea9e0707dc56a7c7363f Version: 6ae330cad6ef22ab8347ea9e0707dc56a7c7363f Version: 6ae330cad6ef22ab8347ea9e0707dc56a7c7363f Version: 6ae330cad6ef22ab8347ea9e0707dc56a7c7363f Version: 6ae330cad6ef22ab8347ea9e0707dc56a7c7363f Version: 6ae330cad6ef22ab8347ea9e0707dc56a7c7363f |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/fuse/dir.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "8f14906ce9103ab8f2f1ebda45935a0d61b9d763",
"status": "affected",
"version": "6ae330cad6ef22ab8347ea9e0707dc56a7c7363f",
"versionType": "git"
},
{
"lessThan": "03cfeeb135428fa83f0791d3f8f94d9298cae695",
"status": "affected",
"version": "6ae330cad6ef22ab8347ea9e0707dc56a7c7363f",
"versionType": "git"
},
{
"lessThan": "92588d187ba4697a322e7aefe5d9e538a87d1cd2",
"status": "affected",
"version": "6ae330cad6ef22ab8347ea9e0707dc56a7c7363f",
"versionType": "git"
},
{
"lessThan": "ea9fea370b8de4ffd72e0ef89550415c15637787",
"status": "affected",
"version": "6ae330cad6ef22ab8347ea9e0707dc56a7c7363f",
"versionType": "git"
},
{
"lessThan": "1758730d9eaa3c06cf415c3446d9f6eed9ed3eed",
"status": "affected",
"version": "6ae330cad6ef22ab8347ea9e0707dc56a7c7363f",
"versionType": "git"
},
{
"lessThan": "dd278d954c0e96a9cbd3cc491e07b8267d25f8d5",
"status": "affected",
"version": "6ae330cad6ef22ab8347ea9e0707dc56a7c7363f",
"versionType": "git"
},
{
"lessThan": "e8457ebfd77a46e8d1210e8888ea914ad064558e",
"status": "affected",
"version": "6ae330cad6ef22ab8347ea9e0707dc56a7c7363f",
"versionType": "git"
},
{
"lessThan": "9afeca0d569c9fc89d758fe7a9339d1e8afb1546",
"status": "affected",
"version": "6ae330cad6ef22ab8347ea9e0707dc56a7c7363f",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/fuse/dir.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.10"
},
{
"lessThan": "5.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.220",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.187",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.156",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.108",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.49",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.13",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.3",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.220",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.187",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.156",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.108",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.49",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.13",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.3",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "5.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfuse: fix invalidate lock leak on setattr writeback failure\n\nfuse_do_setattr() takes filemap_invalidate_lock() for a DAX truncate\n(fault_blocked = true) and releases it at the out:/error: labels. But\nwhen a writeback flush is also needed, a write_inode_now() failure\nreturns directly and leaks the lock, so any later fault or truncate on\nthe file stalls on the stale rwsem.\n\nFor example, truncate(2) on a setuid file reaches fuse_do_setattr()\nwith both ATTR_SIZE and ATTR_MODE set:\n\n truncate(2)\n \u2514\u2500 do_truncate()\n \u251c\u2500 dentry_needs_remove_privs() # S_ISUID\n \u2514\u2500 notify_change() # KILL_SUID -\u003e ATTR_MODE\n \u2514\u2500 fuse_setattr() # no killpriv:\n \u2502 # ia_valid |= ATTR_MODE\n \u2514\u2500 fuse_do_setattr()\n \u251c\u2500 filemap_invalidate_lock() # IS_DAX \u0026\u0026 is_truncate\n \u2514\u2500 write_inode_now() # is_wb \u0026\u0026 ATTR_MODE\n \u2514\u2500 if (err) # e.g. daemon -\u003e -EIO\n return err # \u003c- lock leaked\n\nFix this by adding an unlock label that releases the lock before\nreturning the error, and use it for the fuse_dax_break_layouts()\nfailure path as well."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T15:55:09.250Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/8f14906ce9103ab8f2f1ebda45935a0d61b9d763"
},
{
"url": "https://git.kernel.org/stable/c/03cfeeb135428fa83f0791d3f8f94d9298cae695"
},
{
"url": "https://git.kernel.org/stable/c/92588d187ba4697a322e7aefe5d9e538a87d1cd2"
},
{
"url": "https://git.kernel.org/stable/c/ea9fea370b8de4ffd72e0ef89550415c15637787"
},
{
"url": "https://git.kernel.org/stable/c/1758730d9eaa3c06cf415c3446d9f6eed9ed3eed"
},
{
"url": "https://git.kernel.org/stable/c/dd278d954c0e96a9cbd3cc491e07b8267d25f8d5"
},
{
"url": "https://git.kernel.org/stable/c/e8457ebfd77a46e8d1210e8888ea914ad064558e"
},
{
"url": "https://git.kernel.org/stable/c/9afeca0d569c9fc89d758fe7a9339d1e8afb1546"
}
],
"title": "fuse: fix invalidate lock leak on setattr writeback failure",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80856",
"datePublished": "2026-09-04T15:55:09.250Z",
"dateReserved": "2026-08-26T14:34:25.797Z",
"dateUpdated": "2026-09-04T15:55:09.250Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74705 (GCVE-0-2026-74705)
Vulnerability from cvelistv5
Published
2026-08-22 15:33
Modified
2026-08-25 05:41
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
udp: fix potential use-after-free in tunnel segmentation
__skb_udp_tunnel_segment() gets the UDP header before ensuring the
tunnel header is in the skb head. If the pull reallocates skb->head,
the saved UDP header pointer is no longer valid.
Get the UDP header after the pull to avoid a potential use-after-free.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: dbef491ebe7f3a4fb1b9111878b86a426fd540b7 Version: dbef491ebe7f3a4fb1b9111878b86a426fd540b7 Version: dbef491ebe7f3a4fb1b9111878b86a426fd540b7 Version: dbef491ebe7f3a4fb1b9111878b86a426fd540b7 Version: dbef491ebe7f3a4fb1b9111878b86a426fd540b7 Version: dbef491ebe7f3a4fb1b9111878b86a426fd540b7 Version: dbef491ebe7f3a4fb1b9111878b86a426fd540b7 Version: dbef491ebe7f3a4fb1b9111878b86a426fd540b7 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ipv4/udp_offload.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "6a733a38b983d8c2e222f13968209010cf44de87",
"status": "affected",
"version": "dbef491ebe7f3a4fb1b9111878b86a426fd540b7",
"versionType": "git"
},
{
"lessThan": "19d89b13a43640b2da2f277ee462d919d988cb6f",
"status": "affected",
"version": "dbef491ebe7f3a4fb1b9111878b86a426fd540b7",
"versionType": "git"
},
{
"lessThan": "b3df61bb745eb5201eac22679a2839d4ccbf3442",
"status": "affected",
"version": "dbef491ebe7f3a4fb1b9111878b86a426fd540b7",
"versionType": "git"
},
{
"lessThan": "1ae134c012e10384cdac420b5cc6e0615cde0b55",
"status": "affected",
"version": "dbef491ebe7f3a4fb1b9111878b86a426fd540b7",
"versionType": "git"
},
{
"lessThan": "5161e67c561c4f28a5d9335a6e859b02511de92b",
"status": "affected",
"version": "dbef491ebe7f3a4fb1b9111878b86a426fd540b7",
"versionType": "git"
},
{
"lessThan": "64d322c288577793eedd352b96ef75234ed380fe",
"status": "affected",
"version": "dbef491ebe7f3a4fb1b9111878b86a426fd540b7",
"versionType": "git"
},
{
"lessThan": "588d4a6795d99d080f74ef0b5f391ea8c453ae5d",
"status": "affected",
"version": "dbef491ebe7f3a4fb1b9111878b86a426fd540b7",
"versionType": "git"
},
{
"lessThan": "d0f86fb36eb260abd10007b62c9dcc1028e03e61",
"status": "affected",
"version": "dbef491ebe7f3a4fb1b9111878b86a426fd540b7",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ipv4/udp_offload.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.6"
},
{
"lessThan": "4.6",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nudp: fix potential use-after-free in tunnel segmentation\n\n__skb_udp_tunnel_segment() gets the UDP header before ensuring the\ntunnel header is in the skb head. If the pull reallocates skb-\u003ehead,\nthe saved UDP header pointer is no longer valid.\n\nGet the UDP header after the pull to avoid a potential use-after-free."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 10,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - Remote peers reach __skb_udp_tunnel_segment on egress when GRO-coalesced VXLAN/Geneve/FOU GSO superpackets are forwarded or re-encapsulated through dev_queue_xmit, and malicious virtio-net/cloud tenants can inject VIRTIO_NET_HDR_GSO_UDP_TUNNEL frames the host later segments on physical or overlay NICs.\nAC:L - Triggering is deterministic once a GSO UDP-tunnel skb has tunnel headers beyond skb_headlen so pskb_may_pull reallocates skb-\u003ehead; attackers control that layout via fragmented or GRO-built outer/encap headers and can repeat crafted sends until segmentation dereferences the stale UDP pointer.\nPR:N - No host authentication or credentials are required to send UDP tunnel traffic to listening overlay ports on cloud/DC nodes, and co-resident virtio-net guests or tenant VMs can emit GSO UDP-tunnel frames into the host datapath without CAP_NET_ADMIN on the victim host.\nUI:N - Exploitation needs only crafted encapsulated GSO traffic into an already-running overlay, bridge, IPVS, OVS, or virtio forwarding path; no victim file open, mount, link click, or other interactive action beyond normal network or VM I/O.\nS:C - In cloud/Kubernetes and virtio-net multitenant deployments, remote or guest/tenant senders can corrupt hypervisor kernel heap during host-side UDP-tunnel GSO segmentation on egress, crossing the VM/container-to-host security boundary rather than staying within the attacker\u0027s own namespace.\nC:H - After pskb_may_pull reallocates skb-\u003ehead, the pre-pull udp_hdr pointer is stale yet uh-\u003elen and uh-\u003echeck are read for checksum adjustment, yielding a classic heap use-after-free read primitive that can disclose kernel memory and support further exploitation.\nI:H - UAF on the UDP header allows attacker-influenced heap reuse and corruption of header fields and checksum state during tunnel GSO segmentation, providing a write/control primitive suitable for kernel code execution rather than a benign checksum miscalculation.\nA:H - Dereferencing the freed UDP header during GSO segmentation can immediately oops or panic the kernel, and repeated exploitation attempts against this UAF commonly crash or hang the host even when full control is not achieved."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:41:48.767Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/6a733a38b983d8c2e222f13968209010cf44de87"
},
{
"url": "https://git.kernel.org/stable/c/19d89b13a43640b2da2f277ee462d919d988cb6f"
},
{
"url": "https://git.kernel.org/stable/c/b3df61bb745eb5201eac22679a2839d4ccbf3442"
},
{
"url": "https://git.kernel.org/stable/c/1ae134c012e10384cdac420b5cc6e0615cde0b55"
},
{
"url": "https://git.kernel.org/stable/c/5161e67c561c4f28a5d9335a6e859b02511de92b"
},
{
"url": "https://git.kernel.org/stable/c/64d322c288577793eedd352b96ef75234ed380fe"
},
{
"url": "https://git.kernel.org/stable/c/588d4a6795d99d080f74ef0b5f391ea8c453ae5d"
},
{
"url": "https://git.kernel.org/stable/c/d0f86fb36eb260abd10007b62c9dcc1028e03e61"
}
],
"title": "udp: fix potential use-after-free in tunnel segmentation",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74705",
"datePublished": "2026-08-22T15:33:04.110Z",
"dateReserved": "2026-08-15T05:44:03.927Z",
"dateUpdated": "2026-08-25T05:41:48.767Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68169 (GCVE-0-2026-68169)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
mptcp: pm: userspace: fix use-after-free in get_local_id
In mptcp_pm_userspace_get_local_id(), the address entry is looked up under
spinlock, but its id is read after dropping the lock. A concurrent deletion
can free the entry between the unlock and the read, leading to UAF.
The race window is narrow. It was reproduced only with a locally
constructed stress test that repeatedly overlaps an MP_JOIN SYN with a
MPTCP_PM_CMD_SUBFLOW_DESTROY request.
However, the KASAN report below confirms that the race is reachable:
[ 666.319376] BUG: KASAN: slab-use-after-free in mptcp_userspace_pm_get_local_id+0x1dc/0x1f0
[ 666.319386] Read of size 1 at addr ffff888124845610 by task swapper/0/0
...
[ 666.319401] Call Trace:
[ 666.319405] <IRQ>
[ 666.319408] dump_stack_lvl+0x53/0x70
[ 666.319412] print_address_description.constprop.0+0x2c/0x3b0
[ 666.319418] print_report+0xbe/0x2b0
[ 666.319421] ? mptcp_userspace_pm_get_local_id+0x1dc/0x1f0
[ 666.319423] kasan_report+0xce/0x100
[ 666.319426] ? mptcp_userspace_pm_get_local_id+0x1dc/0x1f0
[ 666.319429] mptcp_userspace_pm_get_local_id+0x1dc/0x1f0
[ 666.319433] mptcp_pm_get_local_id+0x371/0x440
...
[ 666.319821] Allocated by task 45539:
[ 666.319844] kasan_save_stack+0x33/0x60
[ 666.319855] kasan_save_track+0x14/0x30
[ 666.319858] __kasan_kmalloc+0x8f/0xa0
[ 666.319863] __kmalloc_noprof+0x1e7/0x520
[ 666.319867] sock_kmalloc+0xdf/0x130
[ 666.319885] sock_kmemdup+0x1b/0x40
[ 666.319888] mptcp_userspace_pm_append_new_local_addr+0x261/0x500
[ 666.319910] mptcp_pm_nl_announce_doit+0x16a/0x610
...
[ 666.319967] Freed by task 45560:
[ 666.319988] kasan_save_stack+0x33/0x60
[ 666.319991] kasan_save_track+0x14/0x30
[ 666.319994] kasan_save_free_info+0x3b/0x60
[ 666.319998] __kasan_slab_free+0x43/0x70
[ 666.320000] kfree+0x166/0x440
[ 666.320003] sock_kfree_s+0x1d/0x50
[ 666.320007] mptcp_userspace_pm_delete_local_addr.isra.0+0x157/0x200
[ 666.320011] mptcp_pm_nl_subflow_destroy_doit+0x51d/0xea0
Fix by copying the id into a local variable while still holding the lock,
and use -1 as a "not found" sentinel.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: e373bfc8ec3d6496ec7e11dd7f4d087a44b1009a Version: ed34dfa19ddbd1e4c85a73636f8cba0211025ea4 Version: f012d796a6de662692159c539689e47e662853a8 Version: f012d796a6de662692159c539689e47e662853a8 Version: f012d796a6de662692159c539689e47e662853a8 Version: f012d796a6de662692159c539689e47e662853a8 Version: 005a3ad289eb604216dcaa03646de36cb08624a0 Version: 6.1.79 ≤ Version: 6.6.18 ≤ Version: 6.7.6 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/mptcp/pm_userspace.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "8ce48d2879aafc0e7a6f8bfc3613c0ba979ec6f5",
"status": "affected",
"version": "e373bfc8ec3d6496ec7e11dd7f4d087a44b1009a",
"versionType": "git"
},
{
"lessThan": "d2c3760b45f2f481a4dd4c5adef4a29dfabd948f",
"status": "affected",
"version": "ed34dfa19ddbd1e4c85a73636f8cba0211025ea4",
"versionType": "git"
},
{
"lessThan": "31ce5af66891f79998fb2e8b8df08e3c98fd72e3",
"status": "affected",
"version": "f012d796a6de662692159c539689e47e662853a8",
"versionType": "git"
},
{
"lessThan": "d64f6c02495f3fad674038cfa7ec049671b59e7b",
"status": "affected",
"version": "f012d796a6de662692159c539689e47e662853a8",
"versionType": "git"
},
{
"lessThan": "40dde4b5d98279471a70e5c8bb713182738c00d9",
"status": "affected",
"version": "f012d796a6de662692159c539689e47e662853a8",
"versionType": "git"
},
{
"lessThan": "9bc6d5e4ca9f3cbb41d43400b3a31cb0403796c9",
"status": "affected",
"version": "f012d796a6de662692159c539689e47e662853a8",
"versionType": "git"
},
{
"status": "affected",
"version": "005a3ad289eb604216dcaa03646de36cb08624a0",
"versionType": "git"
},
{
"lessThan": "6.1.184",
"status": "affected",
"version": "6.1.79",
"versionType": "semver"
},
{
"lessThan": "6.6.151",
"status": "affected",
"version": "6.6.18",
"versionType": "semver"
},
{
"lessThan": "6.8",
"status": "affected",
"version": "6.7.6",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/mptcp/pm_userspace.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.8"
},
{
"lessThan": "6.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "6.1.79",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "6.6.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.7.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: pm: userspace: fix use-after-free in get_local_id\n\nIn mptcp_pm_userspace_get_local_id(), the address entry is looked up under\nspinlock, but its id is read after dropping the lock. A concurrent deletion\ncan free the entry between the unlock and the read, leading to UAF.\n\nThe race window is narrow. It was reproduced only with a locally\nconstructed stress test that repeatedly overlaps an MP_JOIN SYN with a\nMPTCP_PM_CMD_SUBFLOW_DESTROY request.\n\nHowever, the KASAN report below confirms that the race is reachable:\n\n [ 666.319376] BUG: KASAN: slab-use-after-free in mptcp_userspace_pm_get_local_id+0x1dc/0x1f0\n [ 666.319386] Read of size 1 at addr ffff888124845610 by task swapper/0/0\n ...\n [ 666.319401] Call Trace:\n [ 666.319405] \u003cIRQ\u003e\n [ 666.319408] dump_stack_lvl+0x53/0x70\n [ 666.319412] print_address_description.constprop.0+0x2c/0x3b0\n [ 666.319418] print_report+0xbe/0x2b0\n [ 666.319421] ? mptcp_userspace_pm_get_local_id+0x1dc/0x1f0\n [ 666.319423] kasan_report+0xce/0x100\n [ 666.319426] ? mptcp_userspace_pm_get_local_id+0x1dc/0x1f0\n [ 666.319429] mptcp_userspace_pm_get_local_id+0x1dc/0x1f0\n [ 666.319433] mptcp_pm_get_local_id+0x371/0x440\n ...\n [ 666.319821] Allocated by task 45539:\n [ 666.319844] kasan_save_stack+0x33/0x60\n [ 666.319855] kasan_save_track+0x14/0x30\n [ 666.319858] __kasan_kmalloc+0x8f/0xa0\n [ 666.319863] __kmalloc_noprof+0x1e7/0x520\n [ 666.319867] sock_kmalloc+0xdf/0x130\n [ 666.319885] sock_kmemdup+0x1b/0x40\n [ 666.319888] mptcp_userspace_pm_append_new_local_addr+0x261/0x500\n [ 666.319910] mptcp_pm_nl_announce_doit+0x16a/0x610\n ...\n [ 666.319967] Freed by task 45560:\n [ 666.319988] kasan_save_stack+0x33/0x60\n [ 666.319991] kasan_save_track+0x14/0x30\n [ 666.319994] kasan_save_free_info+0x3b/0x60\n [ 666.319998] __kasan_slab_free+0x43/0x70\n [ 666.320000] kfree+0x166/0x440\n [ 666.320003] sock_kfree_s+0x1d/0x50\n [ 666.320007] mptcp_userspace_pm_delete_local_addr.isra.0+0x157/0x200\n [ 666.320011] mptcp_pm_nl_subflow_destroy_doit+0x51d/0xea0\n\nFix by copying the id into a local variable while still holding the lock,\nand use -1 as a \"not found\" sentinel."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:03.401Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/8ce48d2879aafc0e7a6f8bfc3613c0ba979ec6f5"
},
{
"url": "https://git.kernel.org/stable/c/d2c3760b45f2f481a4dd4c5adef4a29dfabd948f"
},
{
"url": "https://git.kernel.org/stable/c/31ce5af66891f79998fb2e8b8df08e3c98fd72e3"
},
{
"url": "https://git.kernel.org/stable/c/d64f6c02495f3fad674038cfa7ec049671b59e7b"
},
{
"url": "https://git.kernel.org/stable/c/40dde4b5d98279471a70e5c8bb713182738c00d9"
},
{
"url": "https://git.kernel.org/stable/c/9bc6d5e4ca9f3cbb41d43400b3a31cb0403796c9"
}
],
"title": "mptcp: pm: userspace: fix use-after-free in get_local_id",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68169",
"datePublished": "2026-08-10T11:59:38.177Z",
"dateReserved": "2026-07-30T09:28:09.372Z",
"dateUpdated": "2026-08-23T12:46:03.401Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64508 (GCVE-0-2026-64508)
Vulnerability from cvelistv5
Published
2026-07-25 08:52
Modified
2026-08-19 16:28
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
bpf: Support for hardening against JIT spraying
The BPF JIT allocator packs many small programs into larger executable
allocations and reuses space within those allocations as programs are
loaded and freed. When fresh code is written into space that a previous
program occupied, an indirect jump into the new program can reuse a branch
prediction left behind by the old one.
Flush the indirect branch predictors before reusing JIT memory so that
indirect jumps into a newly written program don't reuse predictions from an
old program that occupied the same space.
Introduce bpf_arch_pred_flush_enabled static key and bpf_arch_pred_flush
static call for flushing the branch predictors on JIT memory reuse.
Architectures that need a flush, can update it to a predictor flush
function. By default, its a NOP and does not emit any CALL.
Allocations larger than a pack are not covered by this flush. That is safe
because cBPF programs (the unprivileged attack surface) are bounded well
below a pack size. Issue a warning if this assumption is ever violated
while the flush is active.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 57631054fae6dcc9c892ae6310b58bbb6f6e5048 Version: 57631054fae6dcc9c892ae6310b58bbb6f6e5048 Version: 57631054fae6dcc9c892ae6310b58bbb6f6e5048 Version: 57631054fae6dcc9c892ae6310b58bbb6f6e5048 Version: 57631054fae6dcc9c892ae6310b58bbb6f6e5048 Version: 57631054fae6dcc9c892ae6310b58bbb6f6e5048 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"include/linux/filter.h",
"kernel/bpf/core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "1fbafd5235ca897b322161659ebe8ba651b00b3b",
"status": "affected",
"version": "57631054fae6dcc9c892ae6310b58bbb6f6e5048",
"versionType": "git"
},
{
"lessThan": "6e52c240c43a601b681e3a4e58fc5685114d4726",
"status": "affected",
"version": "57631054fae6dcc9c892ae6310b58bbb6f6e5048",
"versionType": "git"
},
{
"lessThan": "eed774da601268dae674e14d54a15e3624691f52",
"status": "affected",
"version": "57631054fae6dcc9c892ae6310b58bbb6f6e5048",
"versionType": "git"
},
{
"lessThan": "8ff183ee4d8c452960df58175a094828c0513b2e",
"status": "affected",
"version": "57631054fae6dcc9c892ae6310b58bbb6f6e5048",
"versionType": "git"
},
{
"lessThan": "7a6c171c6a1ac6d1509752dac131d941a3de0b37",
"status": "affected",
"version": "57631054fae6dcc9c892ae6310b58bbb6f6e5048",
"versionType": "git"
},
{
"lessThan": "96cce16e26dd02a8678f1e87f88a4b5cdb63b995",
"status": "affected",
"version": "57631054fae6dcc9c892ae6310b58bbb6f6e5048",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"include/linux/filter.h",
"kernel/bpf/core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.18"
},
{
"lessThan": "5.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.18",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Support for hardening against JIT spraying\n\nThe BPF JIT allocator packs many small programs into larger executable\nallocations and reuses space within those allocations as programs are\nloaded and freed. When fresh code is written into space that a previous\nprogram occupied, an indirect jump into the new program can reuse a branch\nprediction left behind by the old one.\n\nFlush the indirect branch predictors before reusing JIT memory so that\nindirect jumps into a newly written program don\u0027t reuse predictions from an\nold program that occupied the same space.\n\nIntroduce bpf_arch_pred_flush_enabled static key and bpf_arch_pred_flush\nstatic call for flushing the branch predictors on JIT memory reuse.\nArchitectures that need a flush, can update it to a predictor flush\nfunction. By default, its a NOP and does not emit any CALL.\n\nAllocations larger than a pack are not covered by this flush. That is safe\nbecause cBPF programs (the unprivileged attack surface) are bounded well\nbelow a pack size. Issue a warning if this assumption is ever violated\nwhile the flush is active."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:28:20.972Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/1fbafd5235ca897b322161659ebe8ba651b00b3b"
},
{
"url": "https://git.kernel.org/stable/c/6e52c240c43a601b681e3a4e58fc5685114d4726"
},
{
"url": "https://git.kernel.org/stable/c/eed774da601268dae674e14d54a15e3624691f52"
},
{
"url": "https://git.kernel.org/stable/c/8ff183ee4d8c452960df58175a094828c0513b2e"
},
{
"url": "https://git.kernel.org/stable/c/7a6c171c6a1ac6d1509752dac131d941a3de0b37"
},
{
"url": "https://git.kernel.org/stable/c/96cce16e26dd02a8678f1e87f88a4b5cdb63b995"
}
],
"title": "bpf: Support for hardening against JIT spraying",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64508",
"datePublished": "2026-07-25T08:52:01.732Z",
"dateReserved": "2026-07-19T15:36:31.793Z",
"dateUpdated": "2026-08-19T16:28:20.972Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64579 (GCVE-0-2026-64579)
Vulnerability from cvelistv5
Published
2026-08-05 08:09
Modified
2026-08-19 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert
xfrm_hash_rebuild()'s first loop preallocates the bins/chains the reinsert
loop needs, so the reinsert (after hlist_del_rcu()) cannot allocate or
fail. But its guard is inverted: it skips policies with prefixlen <
threshold and preallocates for the rest.
prefixlen < threshold is exactly when policy_hash_bysel() returns NULL and
the reinsert takes the allocating xfrm_policy_inexact_insert() path. So the
loop preallocates for the exact policies (which never allocate) and skips
the inexact ones, whose bin/node is then allocated GFP_ATOMIC during
reinsert. On failure the error path only WARN_ONCE()s and continues,
leaving a poisoned bydst node; the next rebuild's hlist_del_rcu()
dereferences LIST_POISON2 and takes a GPF. Reachable under memory pressure,
deterministic via failslab.
Invert the guard so preallocation covers exactly the reinserted policies;
the reinsert then allocates nothing and cannot fail.
Crash:
Oops: general protection fault, probably for non-canonical address
0xfbd59c0000000024: 0000 [#1] SMP KASAN NOPTI
KASAN: maybe wild-memory-access in range [0xdead...]
...
Workqueue: events xfrm_hash_rebuild
RIP: 0010:xfrm_hash_rebuild+0x5b3/0x1190
RAX: dead000000000122 (LIST_POISON2 + offset)
...
Call Trace:
hlist_del_rcu (include/linux/rculist.h:599)
xfrm_hash_rebuild (net/xfrm/xfrm_policy.c:1365)
process_one_work (kernel/workqueue.c:3322)
worker_thread (kernel/workqueue.c:3486)
kthread (kernel/kthread.c:436)
ret_from_fork (arch/x86/kernel/process.c:158)
ret_from_fork_asm (arch/x86/entry/entry_64.S:245)
...
Kernel panic - not syncing: Fatal exception in interrupt
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 24969facd704a5f0dd8e08da86bf32a9ce972bee Version: 24969facd704a5f0dd8e08da86bf32a9ce972bee Version: 24969facd704a5f0dd8e08da86bf32a9ce972bee Version: 24969facd704a5f0dd8e08da86bf32a9ce972bee Version: 24969facd704a5f0dd8e08da86bf32a9ce972bee Version: 24969facd704a5f0dd8e08da86bf32a9ce972bee Version: 24969facd704a5f0dd8e08da86bf32a9ce972bee Version: 24969facd704a5f0dd8e08da86bf32a9ce972bee |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/xfrm/xfrm_policy.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "e48f4c3e3df35b34be719d72d737bbeaca77cf0c",
"status": "affected",
"version": "24969facd704a5f0dd8e08da86bf32a9ce972bee",
"versionType": "git"
},
{
"lessThan": "1cdeed9df1306f1a277e715600772640d63defa9",
"status": "affected",
"version": "24969facd704a5f0dd8e08da86bf32a9ce972bee",
"versionType": "git"
},
{
"lessThan": "43a4d510523779891cf8eca7ffb4a086b0b5d8bf",
"status": "affected",
"version": "24969facd704a5f0dd8e08da86bf32a9ce972bee",
"versionType": "git"
},
{
"lessThan": "d9d9cc21cc90014724a14c447e3d587be9447107",
"status": "affected",
"version": "24969facd704a5f0dd8e08da86bf32a9ce972bee",
"versionType": "git"
},
{
"lessThan": "94c00391a5117530188334f740ce26d3f1256190",
"status": "affected",
"version": "24969facd704a5f0dd8e08da86bf32a9ce972bee",
"versionType": "git"
},
{
"lessThan": "7acc5ed2f33608a3d83b64f50a5766843b6e2485",
"status": "affected",
"version": "24969facd704a5f0dd8e08da86bf32a9ce972bee",
"versionType": "git"
},
{
"lessThan": "6aa3796d18a9fda953ad76a62b57bf6c145cb9ef",
"status": "affected",
"version": "24969facd704a5f0dd8e08da86bf32a9ce972bee",
"versionType": "git"
},
{
"lessThan": "f38f8cce2f7e79775b3db7e8a5eacda04ac908e4",
"status": "affected",
"version": "24969facd704a5f0dd8e08da86bf32a9ce972bee",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/xfrm/xfrm_policy.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.0"
},
{
"lessThan": "5.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert\n\nxfrm_hash_rebuild()\u0027s first loop preallocates the bins/chains the reinsert\nloop needs, so the reinsert (after hlist_del_rcu()) cannot allocate or\nfail. But its guard is inverted: it skips policies with prefixlen \u003c\nthreshold and preallocates for the rest.\n\nprefixlen \u003c threshold is exactly when policy_hash_bysel() returns NULL and\nthe reinsert takes the allocating xfrm_policy_inexact_insert() path. So the\nloop preallocates for the exact policies (which never allocate) and skips\nthe inexact ones, whose bin/node is then allocated GFP_ATOMIC during\nreinsert. On failure the error path only WARN_ONCE()s and continues,\nleaving a poisoned bydst node; the next rebuild\u0027s hlist_del_rcu()\ndereferences LIST_POISON2 and takes a GPF. Reachable under memory pressure,\ndeterministic via failslab.\n\nInvert the guard so preallocation covers exactly the reinserted policies;\nthe reinsert then allocates nothing and cannot fail.\n\nCrash:\n Oops: general protection fault, probably for non-canonical address\n 0xfbd59c0000000024: 0000 [#1] SMP KASAN NOPTI\n KASAN: maybe wild-memory-access in range [0xdead...]\n ...\n Workqueue: events xfrm_hash_rebuild\n RIP: 0010:xfrm_hash_rebuild+0x5b3/0x1190\n RAX: dead000000000122 (LIST_POISON2 + offset)\n ...\n Call Trace:\n hlist_del_rcu (include/linux/rculist.h:599)\n xfrm_hash_rebuild (net/xfrm/xfrm_policy.c:1365)\n process_one_work (kernel/workqueue.c:3322)\n worker_thread (kernel/workqueue.c:3486)\n kthread (kernel/kthread.c:436)\n ret_from_fork (arch/x86/kernel/process.c:158)\n ret_from_fork_asm (arch/x86/entry/entry_64.S:245)\n ...\n Kernel panic - not syncing: Fatal exception in interrupt"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:29:04.594Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/e48f4c3e3df35b34be719d72d737bbeaca77cf0c"
},
{
"url": "https://git.kernel.org/stable/c/1cdeed9df1306f1a277e715600772640d63defa9"
},
{
"url": "https://git.kernel.org/stable/c/43a4d510523779891cf8eca7ffb4a086b0b5d8bf"
},
{
"url": "https://git.kernel.org/stable/c/d9d9cc21cc90014724a14c447e3d587be9447107"
},
{
"url": "https://git.kernel.org/stable/c/94c00391a5117530188334f740ce26d3f1256190"
},
{
"url": "https://git.kernel.org/stable/c/7acc5ed2f33608a3d83b64f50a5766843b6e2485"
},
{
"url": "https://git.kernel.org/stable/c/6aa3796d18a9fda953ad76a62b57bf6c145cb9ef"
},
{
"url": "https://git.kernel.org/stable/c/f38f8cce2f7e79775b3db7e8a5eacda04ac908e4"
}
],
"title": "xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64579",
"datePublished": "2026-08-05T08:09:34.346Z",
"dateReserved": "2026-07-19T15:36:31.798Z",
"dateUpdated": "2026-08-19T16:29:04.594Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74499 (GCVE-0-2026-74499)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-19 16:38
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output()
snd_usbmidi_akai_output() computes its fill-loop bound
buf_end = ep->max_transfer - MAX_AKAI_SYSEX_LEN - 1;
as a signed int, so a small device-advertised bulk-OUT max_transfer
makes buf_end negative. The loop guard then compares the u32
urb->transfer_buffer_length against that negative int: the usual
arithmetic conversion turns buf_end into a large unsigned value, so the
guard stays true and each iteration keeps appending SysEx framing and
payload bytes past the end of the URB transfer buffer, which is only
max_transfer bytes long.
A USB device that advertises a tiny bulk-OUT endpoint can therefore
trigger an attacker-length- and content-controlled heap out-of-bounds
write when a process writes to the created /dev/snd/midiC*D* node.
Return early when there is no room for even one SysEx, so the loop is
never entered with a bound that would wrap. The loop is the last
statement of the function, so bailing out is equivalent to it not
running.
Discovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 4434ade8c9334a3ab975d8993de456f06841899e Version: 4434ade8c9334a3ab975d8993de456f06841899e Version: 4434ade8c9334a3ab975d8993de456f06841899e Version: 4434ade8c9334a3ab975d8993de456f06841899e Version: 4434ade8c9334a3ab975d8993de456f06841899e Version: 4434ade8c9334a3ab975d8993de456f06841899e Version: 4434ade8c9334a3ab975d8993de456f06841899e Version: 4434ade8c9334a3ab975d8993de456f06841899e |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"sound/usb/midi.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "78dfdeb8d2065524ed5928d6470bf3d3244d1009",
"status": "affected",
"version": "4434ade8c9334a3ab975d8993de456f06841899e",
"versionType": "git"
},
{
"lessThan": "00cc659a42ac4e94ec880fae2c9bf22fce69c2e8",
"status": "affected",
"version": "4434ade8c9334a3ab975d8993de456f06841899e",
"versionType": "git"
},
{
"lessThan": "ce949d66607cfb000b8d8d84f80f35a886e72683",
"status": "affected",
"version": "4434ade8c9334a3ab975d8993de456f06841899e",
"versionType": "git"
},
{
"lessThan": "29a4c29943631301e85f5e9d10f25741bd78e7ba",
"status": "affected",
"version": "4434ade8c9334a3ab975d8993de456f06841899e",
"versionType": "git"
},
{
"lessThan": "9b22a5c8310b0d55d04f5f0159b913a2fb8b444f",
"status": "affected",
"version": "4434ade8c9334a3ab975d8993de456f06841899e",
"versionType": "git"
},
{
"lessThan": "b5305a0d0bb8e90a6fc9f88270d5f6c9b8c40081",
"status": "affected",
"version": "4434ade8c9334a3ab975d8993de456f06841899e",
"versionType": "git"
},
{
"lessThan": "2b7a0f330dd90dd1a7657cec0db019ee1efa4372",
"status": "affected",
"version": "4434ade8c9334a3ab975d8993de456f06841899e",
"versionType": "git"
},
{
"lessThan": "0970274613fb463d376211450cab066d34ebfe6a",
"status": "affected",
"version": "4434ade8c9334a3ab975d8993de456f06841899e",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"sound/usb/midi.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.35"
},
{
"lessThan": "2.6.35",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.35",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.35",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.35",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "2.6.35",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "2.6.35",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "2.6.35",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "2.6.35",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.35",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output()\n\nsnd_usbmidi_akai_output() computes its fill-loop bound\n\n\tbuf_end = ep-\u003emax_transfer - MAX_AKAI_SYSEX_LEN - 1;\n\nas a signed int, so a small device-advertised bulk-OUT max_transfer\nmakes buf_end negative. The loop guard then compares the u32\nurb-\u003etransfer_buffer_length against that negative int: the usual\narithmetic conversion turns buf_end into a large unsigned value, so the\nguard stays true and each iteration keeps appending SysEx framing and\npayload bytes past the end of the URB transfer buffer, which is only\nmax_transfer bytes long.\n\nA USB device that advertises a tiny bulk-OUT endpoint can therefore\ntrigger an attacker-length- and content-controlled heap out-of-bounds\nwrite when a process writes to the created /dev/snd/midiC*D* node.\n\nReturn early when there is no room for even one SysEx, so the loop is\nnever entered with a bound that would wrap. The loop is the last\nstatement of the function, so bailing out is equivalent to it not\nrunning.\n\nDiscovered by XBOW, triaged by Baul Lee \u003cbaul.lee@xbow.com\u003e"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:38:00.351Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/78dfdeb8d2065524ed5928d6470bf3d3244d1009"
},
{
"url": "https://git.kernel.org/stable/c/00cc659a42ac4e94ec880fae2c9bf22fce69c2e8"
},
{
"url": "https://git.kernel.org/stable/c/ce949d66607cfb000b8d8d84f80f35a886e72683"
},
{
"url": "https://git.kernel.org/stable/c/29a4c29943631301e85f5e9d10f25741bd78e7ba"
},
{
"url": "https://git.kernel.org/stable/c/9b22a5c8310b0d55d04f5f0159b913a2fb8b444f"
},
{
"url": "https://git.kernel.org/stable/c/b5305a0d0bb8e90a6fc9f88270d5f6c9b8c40081"
},
{
"url": "https://git.kernel.org/stable/c/2b7a0f330dd90dd1a7657cec0db019ee1efa4372"
},
{
"url": "https://git.kernel.org/stable/c/0970274613fb463d376211450cab066d34ebfe6a"
}
],
"title": "ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74499",
"datePublished": "2026-08-15T12:27:25.728Z",
"dateReserved": "2026-08-15T05:44:03.907Z",
"dateUpdated": "2026-08-19T16:38:00.351Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80904 (GCVE-0-2026-80904)
Vulnerability from cvelistv5
Published
2026-09-04 17:19
Modified
2026-09-04 17:19
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/tls: Fail tls_sw_splice_read() after a failed async decrypt
When an async decrypt fails, tls_decrypt_done() records the error in
ctx->async_wait.err and calls tls_err_abort(), which stores it in
sk_err. tls_sw_recvmsg() and tls_sw_read_sock() each read
async_wait.err once they hold the reader lock and fail the call: a
record that did not authenticate breaks the connection.
tls_sw_splice_read() has no such check, and sk_err does not stand in
for one. tls_rx_rec_wait() tests sk_err only inside the loop it
skips whenever a record is already parsed, and the first reader to
reach sock_error() clears it, while async_wait.err persists. A
splice therefore keeps delivering records on a connection that
recvmsg() and read_sock() refuse to read.
Read async_wait.err in tls_sw_splice_read() as the other two readers
do.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: f314bfee81b1bf8e01168177b2f65f24eb8da63a Version: f314bfee81b1bf8e01168177b2f65f24eb8da63a Version: f314bfee81b1bf8e01168177b2f65f24eb8da63a Version: f314bfee81b1bf8e01168177b2f65f24eb8da63a Version: f314bfee81b1bf8e01168177b2f65f24eb8da63a Version: f314bfee81b1bf8e01168177b2f65f24eb8da63a |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/tls/tls_sw.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a808aadff634c7a408b2ab84d5919e9a741fdb5b",
"status": "affected",
"version": "f314bfee81b1bf8e01168177b2f65f24eb8da63a",
"versionType": "git"
},
{
"lessThan": "06c2a53604fa1dc4820063828d7dadb3675b7af8",
"status": "affected",
"version": "f314bfee81b1bf8e01168177b2f65f24eb8da63a",
"versionType": "git"
},
{
"lessThan": "18ae1e95f20867106a28820c208a9cec99dda861",
"status": "affected",
"version": "f314bfee81b1bf8e01168177b2f65f24eb8da63a",
"versionType": "git"
},
{
"lessThan": "82d9269f01ebfd835b6256aa17016a974cbbc647",
"status": "affected",
"version": "f314bfee81b1bf8e01168177b2f65f24eb8da63a",
"versionType": "git"
},
{
"lessThan": "4b177911eb9f799e9841c2f87c75b08cb112757a",
"status": "affected",
"version": "f314bfee81b1bf8e01168177b2f65f24eb8da63a",
"versionType": "git"
},
{
"lessThan": "976df67f463db1fddaf2a32fb04f57ad2891a23d",
"status": "affected",
"version": "f314bfee81b1bf8e01168177b2f65f24eb8da63a",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/tls/tls_sw.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.19"
},
{
"lessThan": "5.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.46",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.10",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/tls: Fail tls_sw_splice_read() after a failed async decrypt\n\nWhen an async decrypt fails, tls_decrypt_done() records the error in\nctx-\u003easync_wait.err and calls tls_err_abort(), which stores it in\nsk_err. tls_sw_recvmsg() and tls_sw_read_sock() each read\nasync_wait.err once they hold the reader lock and fail the call: a\nrecord that did not authenticate breaks the connection.\n\ntls_sw_splice_read() has no such check, and sk_err does not stand in\nfor one. tls_rx_rec_wait() tests sk_err only inside the loop it\nskips whenever a record is already parsed, and the first reader to\nreach sock_error() clears it, while async_wait.err persists. A\nsplice therefore keeps delivering records on a connection that\nrecvmsg() and read_sock() refuse to read.\n\nRead async_wait.err in tls_sw_splice_read() as the other two readers\ndo."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T17:19:14.391Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a808aadff634c7a408b2ab84d5919e9a741fdb5b"
},
{
"url": "https://git.kernel.org/stable/c/06c2a53604fa1dc4820063828d7dadb3675b7af8"
},
{
"url": "https://git.kernel.org/stable/c/18ae1e95f20867106a28820c208a9cec99dda861"
},
{
"url": "https://git.kernel.org/stable/c/82d9269f01ebfd835b6256aa17016a974cbbc647"
},
{
"url": "https://git.kernel.org/stable/c/4b177911eb9f799e9841c2f87c75b08cb112757a"
},
{
"url": "https://git.kernel.org/stable/c/976df67f463db1fddaf2a32fb04f57ad2891a23d"
}
],
"title": "net/tls: Fail tls_sw_splice_read() after a failed async decrypt",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80904",
"datePublished": "2026-09-04T17:19:14.391Z",
"dateReserved": "2026-08-26T14:34:25.800Z",
"dateUpdated": "2026-09-04T17:19:14.391Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68096 (GCVE-0-2026-68096)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-23 12:45
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
audit: fix recursive locking deadlock in audit_dupe_exe()
A deadlock occurs in the audit subsystem when duplicating
executable-related rules.
When a file is moved (e.g., via do_renameat2()), the VFS layer locks
the parent directory (I_MUTEX_PARENT), which synchronously triggers an
fsnotify_move event. If an existing executable audit rule matches the
file being moved, the audit subsystem catches this event and calls
audit_dupe_exe() to duplicate the watch and update the rule. Then,
audit_alloc_mark() would call kern_path_parent() to resolve the path,
leading to a blind attempt to acquire the exact same I_MUTEX_PARENT lock
already held by the task, resulting in the following recursive locking
deadlock:
============================================
WARNING: possible recursive locking detected
6.12.0-55.27.1.el10_0.x86_64+debug #1 Not tainted
--------------------------------------------
mv/5099 is trying to acquire lock:
ffff888132845358 (&inode->i_sb->s_type->i_mutex_dir_key/1){+.+.}-{3:3},
at: __kern_path_locked+0x10a/0x2f0
but task is already holding lock:
ffff888132846b58 (&inode->i_sb->s_type->i_mutex_dir_key/1){+.+.}-{3:3},
at: lock_two_directories+0x13f/0x2b0
other info that might help us debug this:
Possible unsafe locking scenario:
CPU0
----
lock(&inode->i_sb->s_type->i_mutex_dir_key/1);
lock(&inode->i_sb->s_type->i_mutex_dir_key/1);
*** DEADLOCK ***
May be due to missing lock nesting notation
6 locks held by mv/5099:
#0: ffff888112a9c440 (sb_writers#13)
at: do_renameat2+0x34c/0xbc0
#1: ffff888112a9c790 (&type->s_vfs_rename_key#3)
at: do_renameat2+0x415/0xbc0
#2: ffff888132846b58 (&inode->i_sb->s_type->i_mutex_dir_key/1)
at: lock_two_directories+0x13f/0x2b0
#3: ffff888132845358 (&inode->i_sb->s_type->i_mutex_dir_key/5)
at: lock_two_directories+0x175/0x2b0
#4: ffffffffb3a1fb10 (&fsnotify_mark_srcu)
at: fsnotify+0x454/0x28a0
#5: ffffffffaf886230 (audit_filter_mutex)
at: audit_update_watch+0x36/0x11e0
stack backtrace:
Call Trace:
<TASK>
dump_stack_lvl+0x6f/0xb0
print_deadlock_bug.cold+0xbd/0xca
validate_chain+0x83a/0xf00
__lock_acquire+0xcac/0x1d20
lock_acquire.part.0+0x11b/0x360
down_write_nested+0x9f/0x230
__kern_path_locked+0x10a/0x2f0
kern_path_locked+0x26/0x40
audit_alloc_mark+0xfb/0x4f0
audit_dupe_exe+0x6c/0xe0
audit_dupe_rule+0x6c2/0xc00
audit_update_watch+0x4cc/0x11e0
audit_watch_handle_event+0x12c/0x1b0
send_to_group+0x5d0/0x8b0
fsnotify+0x615/0x28a0
fsnotify_move+0x1d8/0x630
vfs_rename+0xdcd/0x1df0
do_renameat2+0x9d4/0xbc0
__x64_sys_renameat+0x192/0x260
do_syscall_64+0x92/0x180
entry_SYSCALL_64_after_hwframe+0x76/0x7e
RIP: 0033:0x7f0491fe8c4e
Code: 0f 1f 40 00 48 8b 15 c1 e1 16 00 f7 d8 64 89 02 b8 ff ff ff ff
c3 66 0f 1f 44 00 00 f3 0f 1e fa 49 89 ca b8 08 01 00 00 0f 05 <48>
3d 00 f0 ff ff 77 0a c3 66 0f 1f 84 00 00 00 00 00 48 8b 15 89
RSP: 002b:00007ffc7210bf38 EFLAGS: 00000246 ORIG_RAX: 0000000000000108
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f0491fe8c4e
RDX: 0000000000000003 RSI: 00007ffc7210e6c8 RDI: 00000000ffffff9c
RBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000001
R10: 00005575eb2dae2a R11: 0000000000000246 R12: 00005575eb2dae2a
R13: 00007ffc7210e6c8 R14: 0000000000000003 R15: 00000000ffffff9c
</TASK>
The aforementioned deadlock can be consistently reproduced by running
the script below:
audit-dupe-exe-deadlock.sh
--------------------------
#!/bin/bash
auditctl -D
mkdir -p /tmp/foo
touch /tmp/file
auditctl -a always,exit -F exe=/tmp/file -F path=/tmp/file -S all -k dr
mv /tmp/file /tmp/foo/file
rm -Rf /tmp/foo
This patch fixes the issue by introducing struct audit_watch_ctx to pass
the fsnotify event context down to audit_alloc_mark(). By utilizing the
already-resolved directory inode provided by the event, we bypass the
kern_path_parent() path resol
---truncated---
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 34d99af52ad40bd498ba66970579a5bc1fb1a3bc Version: 34d99af52ad40bd498ba66970579a5bc1fb1a3bc Version: 34d99af52ad40bd498ba66970579a5bc1fb1a3bc Version: 34d99af52ad40bd498ba66970579a5bc1fb1a3bc Version: 34d99af52ad40bd498ba66970579a5bc1fb1a3bc Version: 34d99af52ad40bd498ba66970579a5bc1fb1a3bc Version: 34d99af52ad40bd498ba66970579a5bc1fb1a3bc Version: 34d99af52ad40bd498ba66970579a5bc1fb1a3bc |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"kernel/audit.h",
"kernel/audit_fsnotify.c",
"kernel/audit_watch.c",
"kernel/auditfilter.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "6114c3f21eb2ae175401736da744b684705e7ed9",
"status": "affected",
"version": "34d99af52ad40bd498ba66970579a5bc1fb1a3bc",
"versionType": "git"
},
{
"lessThan": "f6fda0ac6661c23b8356dfb1cc423960cc6f0593",
"status": "affected",
"version": "34d99af52ad40bd498ba66970579a5bc1fb1a3bc",
"versionType": "git"
},
{
"lessThan": "3bbb4931f7cd84cecf29ec222c0732bf9ad4da9f",
"status": "affected",
"version": "34d99af52ad40bd498ba66970579a5bc1fb1a3bc",
"versionType": "git"
},
{
"lessThan": "36eb77f14b4e6f2dc1008c1fabe31236397be27a",
"status": "affected",
"version": "34d99af52ad40bd498ba66970579a5bc1fb1a3bc",
"versionType": "git"
},
{
"lessThan": "7d1f66c69898ffb1a718926c32a777ecc471caca",
"status": "affected",
"version": "34d99af52ad40bd498ba66970579a5bc1fb1a3bc",
"versionType": "git"
},
{
"lessThan": "40879c39d6740f3dddfb52b5d6ba7fb8cceb84d8",
"status": "affected",
"version": "34d99af52ad40bd498ba66970579a5bc1fb1a3bc",
"versionType": "git"
},
{
"lessThan": "3b601938314c24fcd1afb6659cad92fe96c9c2f8",
"status": "affected",
"version": "34d99af52ad40bd498ba66970579a5bc1fb1a3bc",
"versionType": "git"
},
{
"lessThan": "81905b5acbe77284734438df3fbec1158e6429a3",
"status": "affected",
"version": "34d99af52ad40bd498ba66970579a5bc1fb1a3bc",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"kernel/audit.h",
"kernel/audit_fsnotify.c",
"kernel/audit_watch.c",
"kernel/auditfilter.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.3"
},
{
"lessThan": "4.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\naudit: fix recursive locking deadlock in audit_dupe_exe()\n\nA deadlock occurs in the audit subsystem when duplicating\nexecutable-related rules.\n\nWhen a file is moved (e.g., via do_renameat2()), the VFS layer locks\nthe parent directory (I_MUTEX_PARENT), which synchronously triggers an\nfsnotify_move event. If an existing executable audit rule matches the\nfile being moved, the audit subsystem catches this event and calls\naudit_dupe_exe() to duplicate the watch and update the rule. Then,\naudit_alloc_mark() would call kern_path_parent() to resolve the path,\nleading to a blind attempt to acquire the exact same I_MUTEX_PARENT lock\nalready held by the task, resulting in the following recursive locking\ndeadlock:\n\n ============================================\n WARNING: possible recursive locking detected\n 6.12.0-55.27.1.el10_0.x86_64+debug #1 Not tainted\n --------------------------------------------\n mv/5099 is trying to acquire lock:\n ffff888132845358 (\u0026inode-\u003ei_sb-\u003es_type-\u003ei_mutex_dir_key/1){+.+.}-{3:3},\n at: __kern_path_locked+0x10a/0x2f0\n\n but task is already holding lock:\n ffff888132846b58 (\u0026inode-\u003ei_sb-\u003es_type-\u003ei_mutex_dir_key/1){+.+.}-{3:3},\n at: lock_two_directories+0x13f/0x2b0\n\n other info that might help us debug this:\n Possible unsafe locking scenario:\n\n CPU0\n ----\n lock(\u0026inode-\u003ei_sb-\u003es_type-\u003ei_mutex_dir_key/1);\n lock(\u0026inode-\u003ei_sb-\u003es_type-\u003ei_mutex_dir_key/1);\n\n *** DEADLOCK ***\n\n May be due to missing lock nesting notation\n\n 6 locks held by mv/5099:\n #0: ffff888112a9c440 (sb_writers#13)\n at: do_renameat2+0x34c/0xbc0\n #1: ffff888112a9c790 (\u0026type-\u003es_vfs_rename_key#3)\n at: do_renameat2+0x415/0xbc0\n #2: ffff888132846b58 (\u0026inode-\u003ei_sb-\u003es_type-\u003ei_mutex_dir_key/1)\n at: lock_two_directories+0x13f/0x2b0\n #3: ffff888132845358 (\u0026inode-\u003ei_sb-\u003es_type-\u003ei_mutex_dir_key/5)\n at: lock_two_directories+0x175/0x2b0\n #4: ffffffffb3a1fb10 (\u0026fsnotify_mark_srcu)\n at: fsnotify+0x454/0x28a0\n #5: ffffffffaf886230 (audit_filter_mutex)\n at: audit_update_watch+0x36/0x11e0\n\n stack backtrace:\n Call Trace:\n \u003cTASK\u003e\n dump_stack_lvl+0x6f/0xb0\n print_deadlock_bug.cold+0xbd/0xca\n validate_chain+0x83a/0xf00\n __lock_acquire+0xcac/0x1d20\n lock_acquire.part.0+0x11b/0x360\n down_write_nested+0x9f/0x230\n __kern_path_locked+0x10a/0x2f0\n kern_path_locked+0x26/0x40\n audit_alloc_mark+0xfb/0x4f0\n audit_dupe_exe+0x6c/0xe0\n audit_dupe_rule+0x6c2/0xc00\n audit_update_watch+0x4cc/0x11e0\n audit_watch_handle_event+0x12c/0x1b0\n send_to_group+0x5d0/0x8b0\n fsnotify+0x615/0x28a0\n fsnotify_move+0x1d8/0x630\n vfs_rename+0xdcd/0x1df0\n do_renameat2+0x9d4/0xbc0\n __x64_sys_renameat+0x192/0x260\n do_syscall_64+0x92/0x180\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n RIP: 0033:0x7f0491fe8c4e\n Code: 0f 1f 40 00 48 8b 15 c1 e1 16 00 f7 d8 64 89 02 b8 ff ff ff ff\n c3 66 0f 1f 44 00 00 f3 0f 1e fa 49 89 ca b8 08 01 00 00 0f 05 \u003c48\u003e\n 3d 00 f0 ff ff 77 0a c3 66 0f 1f 84 00 00 00 00 00 48 8b 15 89\n RSP: 002b:00007ffc7210bf38 EFLAGS: 00000246 ORIG_RAX: 0000000000000108\n RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f0491fe8c4e\n RDX: 0000000000000003 RSI: 00007ffc7210e6c8 RDI: 00000000ffffff9c\n RBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000001\n R10: 00005575eb2dae2a R11: 0000000000000246 R12: 00005575eb2dae2a\n R13: 00007ffc7210e6c8 R14: 0000000000000003 R15: 00000000ffffff9c\n \u003c/TASK\u003e\n\nThe aforementioned deadlock can be consistently reproduced by running\nthe script below:\n\n audit-dupe-exe-deadlock.sh\n --------------------------\n #!/bin/bash\n auditctl -D\n mkdir -p /tmp/foo\n touch /tmp/file\n auditctl -a always,exit -F exe=/tmp/file -F path=/tmp/file -S all -k dr\n mv /tmp/file /tmp/foo/file\n rm -Rf /tmp/foo\n\nThis patch fixes the issue by introducing struct audit_watch_ctx to pass\nthe fsnotify event context down to audit_alloc_mark(). By utilizing the\nalready-resolved directory inode provided by the event, we bypass the\nkern_path_parent() path resol\n---truncated---"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The deadlock is triggered when vfs_rename() emits fsnotify_move() during rename processing; on NFS (nfsd) and SMB (ksmbd) servers a remote client rename request reaches this same synchronous audit_update_watch()-\u003eaudit_dupe_exe()-\u003eaudit_alloc_mark()-\u003ekern_path_parent() path, not only local renameat().\nAC:L - Once an audit rule combining exe= and path= watches exists, the fix commit shows the recursive directory-lock deadlock is consistently reproduced by a simple rename/move; the attacker controls when the rename occurs and no race or special memory layout is required.\nPR:N - Triggering requires only the ability to rename the watched file on a local or network-exported path; a remote NFS/SMB client can issue that rename without local shell access, CAP_AUDIT_CONTROL, or other elevated server-side Unix privileges beyond export write access.\nUI:N - No victim interaction is required; the attacker or any client performing the rename directly invokes the vulnerable fsnotify/audit path without needing another user to open files, click links, or mount filesystems.\nS:U - Impact is confined to the vulnerable kernel host where the rename is processed (task hang/deadlock during audit rule update); it does not cross VM, IOMMU, or sandbox security boundaries.\nC:N - This is a recursive mutex deadlock with no memory corruption, out-of-bounds access, or use-after-free; no attacker-controlled information disclosure occurs beyond optional lockdep diagnostics on debug kernels.\nI:N - The bug does not modify kernel or user data and provides no write primitive or code-execution path; it only deadlocks the calling context while holding VFS directory locks and audit_filter_mutex.\nA:H - The vulnerability causes a deterministic recursive locking deadlock that permanently hangs the rename task while holding directory inode locks and audit_filter_mutex, denying that operation and potentially blocking audit processing and directory operations system-wide."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:45:47.969Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/6114c3f21eb2ae175401736da744b684705e7ed9"
},
{
"url": "https://git.kernel.org/stable/c/f6fda0ac6661c23b8356dfb1cc423960cc6f0593"
},
{
"url": "https://git.kernel.org/stable/c/3bbb4931f7cd84cecf29ec222c0732bf9ad4da9f"
},
{
"url": "https://git.kernel.org/stable/c/36eb77f14b4e6f2dc1008c1fabe31236397be27a"
},
{
"url": "https://git.kernel.org/stable/c/7d1f66c69898ffb1a718926c32a777ecc471caca"
},
{
"url": "https://git.kernel.org/stable/c/40879c39d6740f3dddfb52b5d6ba7fb8cceb84d8"
},
{
"url": "https://git.kernel.org/stable/c/3b601938314c24fcd1afb6659cad92fe96c9c2f8"
},
{
"url": "https://git.kernel.org/stable/c/81905b5acbe77284734438df3fbec1158e6429a3"
}
],
"title": "audit: fix recursive locking deadlock in audit_dupe_exe()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68096",
"datePublished": "2026-08-10T11:58:09.951Z",
"dateReserved": "2026-07-30T09:28:09.368Z",
"dateUpdated": "2026-08-23T12:45:47.969Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80557 (GCVE-0-2026-80557)
Vulnerability from cvelistv5
Published
2026-08-26 14:37
Modified
2026-08-27 12:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
libceph: fix OOB read in decode_watchers() via missing bounds check
ceph_start_decoding() validates that struct_len bytes remain in the
buffer after the encoding header, but accepts struct_len=0 as valid:
ceph_decode_need(p, end, 0, bad) always passes. When a malicious or
compromised OSD sends an obj_list_watch_response_t reply with
struct_len=0, ceph_start_decoding() returns success with p == end,
leaving zero bytes guaranteed for subsequent reads.
The immediately following ceph_decode_32(p) in decode_watchers() has
no preceding bounds check. With p == end this is a 4-byte read past
the validated buffer boundary. The garbage value is then passed
directly to kzalloc_objs() as the watcher count.
The sibling function decode_watcher() already uses the safe variants
(ceph_decode_copy_safe, ceph_decode_64_safe, ceph_decode_skip_32)
after its own ceph_start_decoding() call. decode_watchers() is the
only site that uses the bare variant, confirming an oversight.
Fix by replacing ceph_decode_32(p) with ceph_decode_32_safe(p, end,
*num_watchers, bad), consistent with the established pattern.
Attacker model: a malicious or compromised OSD in a multi-tenant Ceph
deployment (e.g. cloud) can trigger this against any kernel client
that calls CEPH_OSD_OP_LIST_WATCHERS, without any further privileges
beyond OSD session establishment.
[ idryomov: trim changelog ]
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: a4ed38d7a180f184a6e7aedd09db9ca4b1e6a71c Version: a4ed38d7a180f184a6e7aedd09db9ca4b1e6a71c Version: a4ed38d7a180f184a6e7aedd09db9ca4b1e6a71c Version: a4ed38d7a180f184a6e7aedd09db9ca4b1e6a71c Version: a4ed38d7a180f184a6e7aedd09db9ca4b1e6a71c Version: a4ed38d7a180f184a6e7aedd09db9ca4b1e6a71c Version: a4ed38d7a180f184a6e7aedd09db9ca4b1e6a71c Version: a4ed38d7a180f184a6e7aedd09db9ca4b1e6a71c |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ceph/osd_client.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "85479b7d65b4ebcb07fbbe57230976793974ab4a",
"status": "affected",
"version": "a4ed38d7a180f184a6e7aedd09db9ca4b1e6a71c",
"versionType": "git"
},
{
"lessThan": "1c824e7c75bb4adf19553dd4ea944a5d83096be8",
"status": "affected",
"version": "a4ed38d7a180f184a6e7aedd09db9ca4b1e6a71c",
"versionType": "git"
},
{
"lessThan": "f161be39201eb5f9b1f58fb8f90b8a9cd3931eb6",
"status": "affected",
"version": "a4ed38d7a180f184a6e7aedd09db9ca4b1e6a71c",
"versionType": "git"
},
{
"lessThan": "eab3eeb68bfc639d74f27256f05546af5c4f787d",
"status": "affected",
"version": "a4ed38d7a180f184a6e7aedd09db9ca4b1e6a71c",
"versionType": "git"
},
{
"lessThan": "c59219a6b62d74936963983e5815524c3de8dd79",
"status": "affected",
"version": "a4ed38d7a180f184a6e7aedd09db9ca4b1e6a71c",
"versionType": "git"
},
{
"lessThan": "cb8246e5846dbbe34930903a90c7a90dd8e5910b",
"status": "affected",
"version": "a4ed38d7a180f184a6e7aedd09db9ca4b1e6a71c",
"versionType": "git"
},
{
"lessThan": "7130d94846dadbb97b6b7f4d78a3a7bba6e3daa1",
"status": "affected",
"version": "a4ed38d7a180f184a6e7aedd09db9ca4b1e6a71c",
"versionType": "git"
},
{
"lessThan": "00ead17c7de137a692edee59f2772e6af687e8eb",
"status": "affected",
"version": "a4ed38d7a180f184a6e7aedd09db9ca4b1e6a71c",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ceph/osd_client.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.9"
},
{
"lessThan": "4.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.267",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.218",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.185",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.154",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.106",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.47",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.267",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.218",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.185",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.154",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.106",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.47",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.10",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: fix OOB read in decode_watchers() via missing bounds check\n\nceph_start_decoding() validates that struct_len bytes remain in the\nbuffer after the encoding header, but accepts struct_len=0 as valid:\nceph_decode_need(p, end, 0, bad) always passes. When a malicious or\ncompromised OSD sends an obj_list_watch_response_t reply with\nstruct_len=0, ceph_start_decoding() returns success with p == end,\nleaving zero bytes guaranteed for subsequent reads.\n\nThe immediately following ceph_decode_32(p) in decode_watchers() has\nno preceding bounds check. With p == end this is a 4-byte read past\nthe validated buffer boundary. The garbage value is then passed\ndirectly to kzalloc_objs() as the watcher count.\n\nThe sibling function decode_watcher() already uses the safe variants\n(ceph_decode_copy_safe, ceph_decode_64_safe, ceph_decode_skip_32)\nafter its own ceph_start_decoding() call. decode_watchers() is the\nonly site that uses the bare variant, confirming an oversight.\n\nFix by replacing ceph_decode_32(p) with ceph_decode_32_safe(p, end,\n*num_watchers, bad), consistent with the established pattern.\n\nAttacker model: a malicious or compromised OSD in a multi-tenant Ceph\ndeployment (e.g. cloud) can trigger this against any kernel client\nthat calls CEPH_OSD_OP_LIST_WATCHERS, without any further privileges\nbeyond OSD session establishment.\n\n[ idryomov: trim changelog ]"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug is triggered when libceph decodes a crafted MOSDOpReply for CEPH_OSD_OP_LIST_WATCHERS received over the Ceph messenger TCP session from a compromised or malicious OSD; exploitation requires no local syscall, ioctl, or device access on the victim.\nAC:L - A malicious OSD fully controls the reply encoding and can set struct_len=0 with a chosen outdata_len so ceph_start_decoding() leaves p at end and the following ceph_decode_32() deterministically reads attacker-chosen bytes as num_watchers without races or victim-specific memory layout.\nPR:N - The attacker acts as the remote Ceph OSD peer and needs no account, capabilities, or privileges on the victim Linux host; any kernel RBD client connected to a multi-tenant or attacker-controlled cluster is exposed when exclusive-lock recovery issues LIST_WATCHERS.\nUI:N - Once an RBD image with exclusive-lock is mapped, ceph_osdc_list_watchers() is invoked automatically during rbd_try_lock() lock-contention recovery; no additional victim user or administrator action is required at exploit time beyond the existing client session.\nS:U - The out-of-bounds read, attacker-sized heap allocation, and any resulting kernel memory corruption all occur within the victim host kernel Ceph client; the flaw does not cross VM, container, or IOMMU security boundaries.\nC:H - The missing bounds check causes a 4-byte out-of-bounds kernel memory read via ceph_decode_32() when p equals end; per kernel guidance any out-of-bounds read is rated High, and the attacker can place controlled bytes immediately past the validated boundary via outdata_len.\nI:H - The out-of-bounds or attacker-supplied num_watchers value is passed directly to kzalloc_objs(), giving the remote peer control over kernel heap allocation size and subsequent decode_watchers() processing of watcher structures in the RBD exclusive-lock path.\nA:H - The slab out-of-bounds read can trigger KASAN faults or kernel oops on instrumented builds, and a large attacker-chosen num_watchers can cause ENOMEM/OOM or stall the RBD lock worker during repeated decode_watcher() attempts, producing severe repeatable availability loss."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T12:40:16.573Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/85479b7d65b4ebcb07fbbe57230976793974ab4a"
},
{
"url": "https://git.kernel.org/stable/c/1c824e7c75bb4adf19553dd4ea944a5d83096be8"
},
{
"url": "https://git.kernel.org/stable/c/f161be39201eb5f9b1f58fb8f90b8a9cd3931eb6"
},
{
"url": "https://git.kernel.org/stable/c/eab3eeb68bfc639d74f27256f05546af5c4f787d"
},
{
"url": "https://git.kernel.org/stable/c/c59219a6b62d74936963983e5815524c3de8dd79"
},
{
"url": "https://git.kernel.org/stable/c/cb8246e5846dbbe34930903a90c7a90dd8e5910b"
},
{
"url": "https://git.kernel.org/stable/c/7130d94846dadbb97b6b7f4d78a3a7bba6e3daa1"
},
{
"url": "https://git.kernel.org/stable/c/00ead17c7de137a692edee59f2772e6af687e8eb"
}
],
"title": "libceph: fix OOB read in decode_watchers() via missing bounds check",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80557",
"datePublished": "2026-08-26T14:37:24.178Z",
"dateReserved": "2026-08-26T14:34:25.767Z",
"dateUpdated": "2026-08-27T12:40:16.573Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68111 (GCVE-0-2026-68111)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-19 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON()
There's no need to crash the kernel for these cases.
(cherry picked from commit b71604f8685b0eba07866f4e8dc30f93e1931054)
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: b1023571479020e9e9c15a51b43bf8e15406952b Version: b1023571479020e9e9c15a51b43bf8e15406952b Version: b1023571479020e9e9c15a51b43bf8e15406952b Version: b1023571479020e9e9c15a51b43bf8e15406952b Version: b1023571479020e9e9c15a51b43bf8e15406952b Version: b1023571479020e9e9c15a51b43bf8e15406952b Version: b1023571479020e9e9c15a51b43bf8e15406952b Version: b1023571479020e9e9c15a51b43bf8e15406952b |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/gfx_v9_0.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "67965f576f9337e387dc8efaf9a46cb6b7ea12cb",
"status": "affected",
"version": "b1023571479020e9e9c15a51b43bf8e15406952b",
"versionType": "git"
},
{
"lessThan": "9b5e4fa18fea1e7f6017e1af02fa10276628d9a0",
"status": "affected",
"version": "b1023571479020e9e9c15a51b43bf8e15406952b",
"versionType": "git"
},
{
"lessThan": "6978b10861850b93292fcd6b22a5495d69fce276",
"status": "affected",
"version": "b1023571479020e9e9c15a51b43bf8e15406952b",
"versionType": "git"
},
{
"lessThan": "6c8b9c1f03c7169c9577098b0c3035617606f8d4",
"status": "affected",
"version": "b1023571479020e9e9c15a51b43bf8e15406952b",
"versionType": "git"
},
{
"lessThan": "d74a6351d3f64e1f8a0fba28b369c0eeecf517f1",
"status": "affected",
"version": "b1023571479020e9e9c15a51b43bf8e15406952b",
"versionType": "git"
},
{
"lessThan": "042c047e8bc9c9ada7574028a8e4592102e2e1fd",
"status": "affected",
"version": "b1023571479020e9e9c15a51b43bf8e15406952b",
"versionType": "git"
},
{
"lessThan": "43768ad42b8f1a91652b86e0731ac14d6853cebb",
"status": "affected",
"version": "b1023571479020e9e9c15a51b43bf8e15406952b",
"versionType": "git"
},
{
"lessThan": "6302be10b521f5106ce01eb5a724b9e7945a5061",
"status": "affected",
"version": "b1023571479020e9e9c15a51b43bf8e15406952b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/gfx_v9_0.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.12"
},
{
"lessThan": "4.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/gfx9: replace BUG_ON() with WARN_ON()\n\nThere\u0027s no need to crash the kernel for these cases.\n\n(cherry picked from commit b71604f8685b0eba07866f4e8dc30f93e1931054)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:29:24.565Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/67965f576f9337e387dc8efaf9a46cb6b7ea12cb"
},
{
"url": "https://git.kernel.org/stable/c/9b5e4fa18fea1e7f6017e1af02fa10276628d9a0"
},
{
"url": "https://git.kernel.org/stable/c/6978b10861850b93292fcd6b22a5495d69fce276"
},
{
"url": "https://git.kernel.org/stable/c/6c8b9c1f03c7169c9577098b0c3035617606f8d4"
},
{
"url": "https://git.kernel.org/stable/c/d74a6351d3f64e1f8a0fba28b369c0eeecf517f1"
},
{
"url": "https://git.kernel.org/stable/c/042c047e8bc9c9ada7574028a8e4592102e2e1fd"
},
{
"url": "https://git.kernel.org/stable/c/43768ad42b8f1a91652b86e0731ac14d6853cebb"
},
{
"url": "https://git.kernel.org/stable/c/6302be10b521f5106ce01eb5a724b9e7945a5061"
}
],
"title": "drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68111",
"datePublished": "2026-08-10T11:58:28.489Z",
"dateReserved": "2026-07-30T09:28:09.368Z",
"dateUpdated": "2026-08-19T16:29:24.565Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80547 (GCVE-0-2026-80547)
Vulnerability from cvelistv5
Published
2026-08-26 14:37
Modified
2026-08-27 12:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
s390/vfio_ccw: Implement a crw lock
Unlike the channel_program struct, which covers synchronous I/O
submissions and asynchronous interrupts, the CRW region relies
exclusively on asynchronous events coming from hardware.
Implement a lock to manage the list of those payloads, to ensure
they are read cohesively.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 3f02cb2fd9d2d9e8762102886e3e4b51285797ee Version: 3f02cb2fd9d2d9e8762102886e3e4b51285797ee Version: 3f02cb2fd9d2d9e8762102886e3e4b51285797ee Version: 3f02cb2fd9d2d9e8762102886e3e4b51285797ee Version: 3f02cb2fd9d2d9e8762102886e3e4b51285797ee Version: 3f02cb2fd9d2d9e8762102886e3e4b51285797ee Version: 3f02cb2fd9d2d9e8762102886e3e4b51285797ee |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/s390/cio/vfio_ccw_chp.c",
"drivers/s390/cio/vfio_ccw_drv.c",
"drivers/s390/cio/vfio_ccw_ops.c",
"drivers/s390/cio/vfio_ccw_private.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "3c94d4179bcc19e01b28db634c07a58b28116209",
"status": "affected",
"version": "3f02cb2fd9d2d9e8762102886e3e4b51285797ee",
"versionType": "git"
},
{
"lessThan": "0edd222730a9d7ec98368aaf1d40ee2d8d862e61",
"status": "affected",
"version": "3f02cb2fd9d2d9e8762102886e3e4b51285797ee",
"versionType": "git"
},
{
"lessThan": "a3d60ae24183eee352c8e87a0ff94c97cd87f156",
"status": "affected",
"version": "3f02cb2fd9d2d9e8762102886e3e4b51285797ee",
"versionType": "git"
},
{
"lessThan": "49fa26b0df009dc1f420980bd71780e70615b83b",
"status": "affected",
"version": "3f02cb2fd9d2d9e8762102886e3e4b51285797ee",
"versionType": "git"
},
{
"lessThan": "7902be374cbfc11c3435e1e87bf22195bf06a558",
"status": "affected",
"version": "3f02cb2fd9d2d9e8762102886e3e4b51285797ee",
"versionType": "git"
},
{
"lessThan": "c76c4ee72bfc3824f4f491f18ed0323bf2e2daf9",
"status": "affected",
"version": "3f02cb2fd9d2d9e8762102886e3e4b51285797ee",
"versionType": "git"
},
{
"lessThan": "16b0798024c0e9117e395829ddbbe70981c79d9c",
"status": "affected",
"version": "3f02cb2fd9d2d9e8762102886e3e4b51285797ee",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/s390/cio/vfio_ccw_chp.c",
"drivers/s390/cio/vfio_ccw_drv.c",
"drivers/s390/cio/vfio_ccw_ops.c",
"drivers/s390/cio/vfio_ccw_private.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.8"
},
{
"lessThan": "5.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.218",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.185",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.154",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.218",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.185",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.154",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.46",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.10",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/vfio_ccw: Implement a crw lock\n\nUnlike the channel_program struct, which covers synchronous I/O\nsubmissions and asynchronous interrupts, the CRW region relies\nexclusively on asynchronous events coming from hardware.\n\nImplement a lock to manage the list of those payloads, to ensure\nthey are read cohesively."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The flaw is reached only via local VFIO mediated-device access (read/ioctl on /dev/vfio/* device fds) to the CCW CRW region; vfio-ccw has no network, Bluetooth, or physical-bus packet entry point.\nAC:L - The attacker controls CRW region reads and can retry concurrently while channel-path events queue CRWs via vfio_ccw_chp_event(); this user-versus-hardware/workqueue list race is winnable without conditions outside attacker influence.\nPR:L - Triggering requires an opened vfio-ccw mdev fd (typical QEMU/libvirt VM operator or delegated /dev/vfio holder on IBM Z passthrough hosts), not init-namespace root; admin creates the mdev but exploitation needs only that VFIO client access.\nUI:N - No separate victim action is required; once vfio-ccw passthrough is configured, the attacker repeatedly reads the CRW region while guest/channel I/O generates asynchronous path events without needing another user to interact.\nS:C - On IBM Z/LinuxONE, vfio-ccw passes DASD subchannels into KVM guests; guest-driven channel activity causes host-side CRW queuing while the VFIO client reads the CRW region, corrupting hypervisor kernel memory outside the VM security boundary.\nC:H - Unsynchronized list_del/list_add/kfree on kmalloc vfio_ccw_crw objects is a use-after-free/list-corruption primitive; per kernel guidance this enables attacker-influenced heap reuse and arbitrary kernel memory disclosure.\nI:H - Corrupted list pointers and freed CRW entries allow heap-sprayable arbitrary writes and control-flow hijack beyond a simple crash, matching kernel guidance for use-after-free and memory corruption bugs.\nA:H - Concurrent unsynchronized list manipulation can immediately oops or panic the host kernel via invalid list operations or double-free, and successful exploitation can hang or crash the entire system."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T12:40:07.162Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/3c94d4179bcc19e01b28db634c07a58b28116209"
},
{
"url": "https://git.kernel.org/stable/c/0edd222730a9d7ec98368aaf1d40ee2d8d862e61"
},
{
"url": "https://git.kernel.org/stable/c/a3d60ae24183eee352c8e87a0ff94c97cd87f156"
},
{
"url": "https://git.kernel.org/stable/c/49fa26b0df009dc1f420980bd71780e70615b83b"
},
{
"url": "https://git.kernel.org/stable/c/7902be374cbfc11c3435e1e87bf22195bf06a558"
},
{
"url": "https://git.kernel.org/stable/c/c76c4ee72bfc3824f4f491f18ed0323bf2e2daf9"
},
{
"url": "https://git.kernel.org/stable/c/16b0798024c0e9117e395829ddbbe70981c79d9c"
}
],
"title": "s390/vfio_ccw: Implement a crw lock",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80547",
"datePublished": "2026-08-26T14:37:18.159Z",
"dateReserved": "2026-08-26T14:34:25.766Z",
"dateUpdated": "2026-08-27T12:40:07.162Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64569 (GCVE-0-2026-64569)
Vulnerability from cvelistv5
Published
2026-08-05 08:08
Modified
2026-08-19 16:28
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n
On CONFIG_INET=n builds, mpls_valid_fib_dump_req() walks the parsed
attribute table itself instead of calling ip_valid_fib_dump_req(). The
RTA_OIF arm passes tb[RTA_OIF] to nla_get_u32() without checking it is
present, so an RTM_GETROUTE dump for AF_MPLS with strict checking and no
RTA_OIF hits a NULL dereference.
RTM_GETROUTE is RTNL_KIND_GET, which rtnetlink_rcv_msg() permits without
CAP_NET_ADMIN, so an unprivileged user can trigger it.
Oops: general protection fault, probably for non-canonical address
0xdffffc0000000000: 0000 [#1] SMP KASAN NOPTI
KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]
RIP: 0010:mpls_valid_fib_dump_req (net/mpls/af_mpls.c:2189)
Call Trace:
mpls_dump_routes (net/mpls/af_mpls.c:2236)
netlink_dump (net/netlink/af_netlink.c:2331)
__netlink_dump_start (net/netlink/af_netlink.c:2446)
rtnetlink_rcv_msg (net/core/rtnetlink.c:7033)
netlink_rcv_skb (net/netlink/af_netlink.c:2556)
netlink_unicast (net/netlink/af_netlink.c:1345)
netlink_sendmsg (net/netlink/af_netlink.c:1900)
__sock_sendmsg (net/socket.c:790)
____sys_sendmsg (net/socket.c:2684)
___sys_sendmsg (net/socket.c:2738)
__sys_sendmsg (net/socket.c:2770)
do_syscall_64 (arch/x86/entry/syscall_64.c:94)
entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)
Skip unset attributes, as ip_valid_fib_dump_req() does.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 196cfebf897266c3450519e916bab9daff74e52c Version: 196cfebf897266c3450519e916bab9daff74e52c Version: 196cfebf897266c3450519e916bab9daff74e52c Version: 196cfebf897266c3450519e916bab9daff74e52c Version: 196cfebf897266c3450519e916bab9daff74e52c Version: 196cfebf897266c3450519e916bab9daff74e52c Version: 196cfebf897266c3450519e916bab9daff74e52c Version: 196cfebf897266c3450519e916bab9daff74e52c |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/mpls/af_mpls.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "bfc1cb5d6a8308e493e307f1c823d2107abc0a47",
"status": "affected",
"version": "196cfebf897266c3450519e916bab9daff74e52c",
"versionType": "git"
},
{
"lessThan": "03b5a2c29afc8e634924c75d6ee94140e70de88d",
"status": "affected",
"version": "196cfebf897266c3450519e916bab9daff74e52c",
"versionType": "git"
},
{
"lessThan": "e796ce9ef4356dc7cbbaa8373843f77852f2814d",
"status": "affected",
"version": "196cfebf897266c3450519e916bab9daff74e52c",
"versionType": "git"
},
{
"lessThan": "d6eee7cd078aaf9dd75efc801f6c9b608a37cd71",
"status": "affected",
"version": "196cfebf897266c3450519e916bab9daff74e52c",
"versionType": "git"
},
{
"lessThan": "ad6284ced6a15e4abd57ca4d0793b7bd15ca52ce",
"status": "affected",
"version": "196cfebf897266c3450519e916bab9daff74e52c",
"versionType": "git"
},
{
"lessThan": "5f6e7b32bd1fbde10fd31a4143260735ea535b8a",
"status": "affected",
"version": "196cfebf897266c3450519e916bab9daff74e52c",
"versionType": "git"
},
{
"lessThan": "06db79411a280707c7e4bf4b221ff4e664b51502",
"status": "affected",
"version": "196cfebf897266c3450519e916bab9daff74e52c",
"versionType": "git"
},
{
"lessThan": "56d96fededd61192cd7cc8d2b0f36adfd59036c3",
"status": "affected",
"version": "196cfebf897266c3450519e916bab9daff74e52c",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/mpls/af_mpls.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.20"
},
{
"lessThan": "4.20",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.20",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n\n\nOn CONFIG_INET=n builds, mpls_valid_fib_dump_req() walks the parsed\nattribute table itself instead of calling ip_valid_fib_dump_req(). The\nRTA_OIF arm passes tb[RTA_OIF] to nla_get_u32() without checking it is\npresent, so an RTM_GETROUTE dump for AF_MPLS with strict checking and no\nRTA_OIF hits a NULL dereference.\n\nRTM_GETROUTE is RTNL_KIND_GET, which rtnetlink_rcv_msg() permits without\nCAP_NET_ADMIN, so an unprivileged user can trigger it.\n\n Oops: general protection fault, probably for non-canonical address\n 0xdffffc0000000000: 0000 [#1] SMP KASAN NOPTI\n KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]\n RIP: 0010:mpls_valid_fib_dump_req (net/mpls/af_mpls.c:2189)\n Call Trace:\n mpls_dump_routes (net/mpls/af_mpls.c:2236)\n netlink_dump (net/netlink/af_netlink.c:2331)\n __netlink_dump_start (net/netlink/af_netlink.c:2446)\n rtnetlink_rcv_msg (net/core/rtnetlink.c:7033)\n netlink_rcv_skb (net/netlink/af_netlink.c:2556)\n netlink_unicast (net/netlink/af_netlink.c:1345)\n netlink_sendmsg (net/netlink/af_netlink.c:1900)\n __sock_sendmsg (net/socket.c:790)\n ____sys_sendmsg (net/socket.c:2684)\n ___sys_sendmsg (net/socket.c:2738)\n __sys_sendmsg (net/socket.c:2770)\n do_syscall_64 (arch/x86/entry/syscall_64.c:94)\n entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)\n\nSkip unset attributes, as ip_valid_fib_dump_req() does."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:28:44.216Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/bfc1cb5d6a8308e493e307f1c823d2107abc0a47"
},
{
"url": "https://git.kernel.org/stable/c/03b5a2c29afc8e634924c75d6ee94140e70de88d"
},
{
"url": "https://git.kernel.org/stable/c/e796ce9ef4356dc7cbbaa8373843f77852f2814d"
},
{
"url": "https://git.kernel.org/stable/c/d6eee7cd078aaf9dd75efc801f6c9b608a37cd71"
},
{
"url": "https://git.kernel.org/stable/c/ad6284ced6a15e4abd57ca4d0793b7bd15ca52ce"
},
{
"url": "https://git.kernel.org/stable/c/5f6e7b32bd1fbde10fd31a4143260735ea535b8a"
},
{
"url": "https://git.kernel.org/stable/c/06db79411a280707c7e4bf4b221ff4e664b51502"
},
{
"url": "https://git.kernel.org/stable/c/56d96fededd61192cd7cc8d2b0f36adfd59036c3"
}
],
"title": "mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64569",
"datePublished": "2026-08-05T08:08:07.233Z",
"dateReserved": "2026-07-19T15:36:31.797Z",
"dateUpdated": "2026-08-19T16:28:44.216Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80824 (GCVE-0-2026-80824)
Vulnerability from cvelistv5
Published
2026-09-04 15:54
Modified
2026-09-04 15:54
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
usb: usbfs: fix use-after-free of usb_device in usbdev_release()
usbdev_release() drops its reference to the struct usb_device before
draining the list of completed async URBs, but that drain path reads back
through the same object: free_async() calls dec_usb_memory_use_count()
for any URB whose buffer came from the usbfs mmap() region, and its first
statement is bus_to_hcd(ps->dev->bus).
After a disconnect the usbfs reference can be the last one, in which case
usb_put_dev() frees the device and the subsequent loop reads offset 80 of
freed memory and uses the result as a struct usb_hcd *, which
hcd_buffer_free_pages() then dereferences.
This is reachable by an unprivileged process that has read/write access to
a /dev/bus/usb node: mmap() the fd, submit one URB with a buffer inside the
mapping, wait for the device to be unplugged, then munmap() and close().
It reproduces on every attempt rather than being a race, because a live
MAP_SHARED vma holds a reference on the struct file, so usbdev_release()
cannot run until the last vma is gone and the freeing branch of
dec_usb_memory_use_count() is always taken.
BUG: KASAN: slab-use-after-free in dec_usb_memory_use_count+0x3ae/0x410
Read of size 8 at addr ffff8880122ee050 by task poc/769
CPU: 1 UID: 1000 PID: 769 Comm: poc Tainted: G B 6.12.94 #3
Call Trace:
dec_usb_memory_use_count+0x3ae/0x410
free_async+0x2aa/0x4f0
usbdev_release+0x375/0x460
__fput+0x3ea/0xb50
__x64_sys_close+0x86/0x100
Allocated by task 11:
usb_alloc_dev+0x55/0xd90
hub_event+0x2524/0x43d0
Freed by task 769:
kfree+0x121/0x360
device_release+0xd2/0x280
usb_put_dev+0x23/0x30
usbdev_release+0x2d8/0x460
Release the device reference after the drain loop instead. Nothing between
the two points requires it to have been dropped.
References
| URL | Tags | ||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: f7d34b445abc00e979b7cf36b9580ac3d1a47cd8 Version: f7d34b445abc00e979b7cf36b9580ac3d1a47cd8 Version: f7d34b445abc00e979b7cf36b9580ac3d1a47cd8 Version: f7d34b445abc00e979b7cf36b9580ac3d1a47cd8 Version: f7d34b445abc00e979b7cf36b9580ac3d1a47cd8 Version: f7d34b445abc00e979b7cf36b9580ac3d1a47cd8 Version: f7d34b445abc00e979b7cf36b9580ac3d1a47cd8 Version: f7d34b445abc00e979b7cf36b9580ac3d1a47cd8 Version: f7d34b445abc00e979b7cf36b9580ac3d1a47cd8 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/core/devio.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "0a960b88c5979f853019d4dc4957dfbeeb193440",
"status": "affected",
"version": "f7d34b445abc00e979b7cf36b9580ac3d1a47cd8",
"versionType": "git"
},
{
"lessThan": "96f5520fc9a5e4bbf77ac93c9d5ce502f597e6cf",
"status": "affected",
"version": "f7d34b445abc00e979b7cf36b9580ac3d1a47cd8",
"versionType": "git"
},
{
"lessThan": "bd4bffc621a8cb2f4d9ed9b6447415de524a3bef",
"status": "affected",
"version": "f7d34b445abc00e979b7cf36b9580ac3d1a47cd8",
"versionType": "git"
},
{
"lessThan": "65879e0a452ca2a234b9475e0c11aff7a4343738",
"status": "affected",
"version": "f7d34b445abc00e979b7cf36b9580ac3d1a47cd8",
"versionType": "git"
},
{
"lessThan": "b3cde26a66b04f1d90ed0b675899c88b4e49d424",
"status": "affected",
"version": "f7d34b445abc00e979b7cf36b9580ac3d1a47cd8",
"versionType": "git"
},
{
"lessThan": "5f08c45bdcfd28d1171de38c5ef29fc89a76eedc",
"status": "affected",
"version": "f7d34b445abc00e979b7cf36b9580ac3d1a47cd8",
"versionType": "git"
},
{
"lessThan": "7f0278e474c4d1c4457974ff1137cc385c944ab3",
"status": "affected",
"version": "f7d34b445abc00e979b7cf36b9580ac3d1a47cd8",
"versionType": "git"
},
{
"lessThan": "47a7f98fbb5006d46d15a3a210ffdc61448a4f19",
"status": "affected",
"version": "f7d34b445abc00e979b7cf36b9580ac3d1a47cd8",
"versionType": "git"
},
{
"lessThan": "0dd68b5d01d022fc9c5e71c82a82b0a94d3d0671",
"status": "affected",
"version": "f7d34b445abc00e979b7cf36b9580ac3d1a47cd8",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/usb/core/devio.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.6"
},
{
"lessThan": "4.6",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.269",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.220",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.187",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.156",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.108",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.49",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.13",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.3",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.269",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.220",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.187",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.156",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.108",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.49",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.13",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.3",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "4.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: usbfs: fix use-after-free of usb_device in usbdev_release()\n\nusbdev_release() drops its reference to the struct usb_device before\ndraining the list of completed async URBs, but that drain path reads back\nthrough the same object: free_async() calls dec_usb_memory_use_count()\nfor any URB whose buffer came from the usbfs mmap() region, and its first\nstatement is bus_to_hcd(ps-\u003edev-\u003ebus).\n\nAfter a disconnect the usbfs reference can be the last one, in which case\nusb_put_dev() frees the device and the subsequent loop reads offset 80 of\nfreed memory and uses the result as a struct usb_hcd *, which\nhcd_buffer_free_pages() then dereferences.\n\nThis is reachable by an unprivileged process that has read/write access to\na /dev/bus/usb node: mmap() the fd, submit one URB with a buffer inside the\nmapping, wait for the device to be unplugged, then munmap() and close().\nIt reproduces on every attempt rather than being a race, because a live\nMAP_SHARED vma holds a reference on the struct file, so usbdev_release()\ncannot run until the last vma is gone and the freeing branch of\ndec_usb_memory_use_count() is always taken.\n\n BUG: KASAN: slab-use-after-free in dec_usb_memory_use_count+0x3ae/0x410\n Read of size 8 at addr ffff8880122ee050 by task poc/769\n CPU: 1 UID: 1000 PID: 769 Comm: poc Tainted: G B 6.12.94 #3\n\n Call Trace:\n dec_usb_memory_use_count+0x3ae/0x410\n free_async+0x2aa/0x4f0\n usbdev_release+0x375/0x460\n __fput+0x3ea/0xb50\n __x64_sys_close+0x86/0x100\n\n Allocated by task 11:\n usb_alloc_dev+0x55/0xd90\n hub_event+0x2524/0x43d0\n\n Freed by task 769:\n kfree+0x121/0x360\n device_release+0xd2/0x280\n usb_put_dev+0x23/0x30\n usbdev_release+0x2d8/0x460\n\nRelease the device reference after the drain loop instead. Nothing between\nthe two points requires it to have been dropped."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T15:54:28.038Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/0a960b88c5979f853019d4dc4957dfbeeb193440"
},
{
"url": "https://git.kernel.org/stable/c/96f5520fc9a5e4bbf77ac93c9d5ce502f597e6cf"
},
{
"url": "https://git.kernel.org/stable/c/bd4bffc621a8cb2f4d9ed9b6447415de524a3bef"
},
{
"url": "https://git.kernel.org/stable/c/65879e0a452ca2a234b9475e0c11aff7a4343738"
},
{
"url": "https://git.kernel.org/stable/c/b3cde26a66b04f1d90ed0b675899c88b4e49d424"
},
{
"url": "https://git.kernel.org/stable/c/5f08c45bdcfd28d1171de38c5ef29fc89a76eedc"
},
{
"url": "https://git.kernel.org/stable/c/7f0278e474c4d1c4457974ff1137cc385c944ab3"
},
{
"url": "https://git.kernel.org/stable/c/47a7f98fbb5006d46d15a3a210ffdc61448a4f19"
},
{
"url": "https://git.kernel.org/stable/c/0dd68b5d01d022fc9c5e71c82a82b0a94d3d0671"
}
],
"title": "usb: usbfs: fix use-after-free of usb_device in usbdev_release()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80824",
"datePublished": "2026-09-04T15:54:28.038Z",
"dateReserved": "2026-08-26T14:34:25.795Z",
"dateUpdated": "2026-09-04T15:54:28.038Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-53089 (GCVE-0-2026-53089)
Vulnerability from cvelistv5
Published
2026-06-24 16:30
Modified
2026-09-02 12:49
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
bpf: Fix use-after-free in offloaded map/prog info fill
When querying info for an offloaded BPF map or program,
bpf_map_offload_info_fill_ns() and bpf_prog_offload_info_fill_ns()
obtain the network namespace with get_net(dev_net(offmap->netdev)).
However, the associated netdev's netns may be racing with teardown
during netns destruction. If the netns refcount has already reached 0,
get_net() performs a refcount_t increment on 0, triggering:
refcount_t: addition on 0; use-after-free.
Although rtnl_lock and bpf_devs_lock ensure the netdev pointer remains
valid, they cannot prevent the netns refcount from reaching zero.
Fix this by using maybe_get_net() instead of get_net(). maybe_get_net()
uses refcount_inc_not_zero() and returns NULL if the refcount is already
zero, which causes ns_get_path_cb() to fail and the caller to return
-ENOENT -- the correct behavior when the netns is being destroyed.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 675fc275a3a2d905535207237402c6d8dcb5fa4b Version: 675fc275a3a2d905535207237402c6d8dcb5fa4b Version: 675fc275a3a2d905535207237402c6d8dcb5fa4b Version: 675fc275a3a2d905535207237402c6d8dcb5fa4b Version: 675fc275a3a2d905535207237402c6d8dcb5fa4b Version: 675fc275a3a2d905535207237402c6d8dcb5fa4b Version: 675fc275a3a2d905535207237402c6d8dcb5fa4b Version: 675fc275a3a2d905535207237402c6d8dcb5fa4b |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"kernel/bpf/offload.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "43d6848a2a6c92ccfd614d9f0bb6fd85b95dfa9d",
"status": "affected",
"version": "675fc275a3a2d905535207237402c6d8dcb5fa4b",
"versionType": "git"
},
{
"lessThan": "642943ae5bdacabc8109dc4a5e0ebb4a6b99ef3e",
"status": "affected",
"version": "675fc275a3a2d905535207237402c6d8dcb5fa4b",
"versionType": "git"
},
{
"lessThan": "fea55b034328feaafef75aee252f305e6f85a991",
"status": "affected",
"version": "675fc275a3a2d905535207237402c6d8dcb5fa4b",
"versionType": "git"
},
{
"lessThan": "5662dac41a3442aa378d7c405164903eb109fc05",
"status": "affected",
"version": "675fc275a3a2d905535207237402c6d8dcb5fa4b",
"versionType": "git"
},
{
"lessThan": "1a2dc103e16448d022a77ad5fc3234641436c4b7",
"status": "affected",
"version": "675fc275a3a2d905535207237402c6d8dcb5fa4b",
"versionType": "git"
},
{
"lessThan": "85dc711f742b192eb97c0e00b521312f5a7a415e",
"status": "affected",
"version": "675fc275a3a2d905535207237402c6d8dcb5fa4b",
"versionType": "git"
},
{
"lessThan": "a51e7fbe94a87e236631a83973d4f558310b2cd2",
"status": "affected",
"version": "675fc275a3a2d905535207237402c6d8dcb5fa4b",
"versionType": "git"
},
{
"lessThan": "a0c584fc18056709c8e047a82a6045d6c209f4ce",
"status": "affected",
"version": "675fc275a3a2d905535207237402c6d8dcb5fa4b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"kernel/bpf/offload.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.16"
},
{
"lessThan": "4.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.269",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.220",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.187",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.156",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.108",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.49",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.269",
"versionStartIncluding": "4.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.220",
"versionStartIncluding": "4.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.187",
"versionStartIncluding": "4.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.156",
"versionStartIncluding": "4.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.108",
"versionStartIncluding": "4.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.49",
"versionStartIncluding": "4.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.10",
"versionStartIncluding": "4.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "4.16",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix use-after-free in offloaded map/prog info fill\n\nWhen querying info for an offloaded BPF map or program,\nbpf_map_offload_info_fill_ns() and bpf_prog_offload_info_fill_ns()\nobtain the network namespace with get_net(dev_net(offmap-\u003enetdev)).\nHowever, the associated netdev\u0027s netns may be racing with teardown\nduring netns destruction. If the netns refcount has already reached 0,\nget_net() performs a refcount_t increment on 0, triggering:\n\n refcount_t: addition on 0; use-after-free.\n\nAlthough rtnl_lock and bpf_devs_lock ensure the netdev pointer remains\nvalid, they cannot prevent the netns refcount from reaching zero.\n\nFix this by using maybe_get_net() instead of get_net(). maybe_get_net()\nuses refcount_inc_not_zero() and returns NULL if the refcount is already\nzero, which causes ns_get_path_cb() to fail and the caller to return\n-ENOENT -- the correct behavior when the netns is being destroyed."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-02T12:49:34.606Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/43d6848a2a6c92ccfd614d9f0bb6fd85b95dfa9d"
},
{
"url": "https://git.kernel.org/stable/c/642943ae5bdacabc8109dc4a5e0ebb4a6b99ef3e"
},
{
"url": "https://git.kernel.org/stable/c/fea55b034328feaafef75aee252f305e6f85a991"
},
{
"url": "https://git.kernel.org/stable/c/5662dac41a3442aa378d7c405164903eb109fc05"
},
{
"url": "https://git.kernel.org/stable/c/1a2dc103e16448d022a77ad5fc3234641436c4b7"
},
{
"url": "https://git.kernel.org/stable/c/85dc711f742b192eb97c0e00b521312f5a7a415e"
},
{
"url": "https://git.kernel.org/stable/c/a51e7fbe94a87e236631a83973d4f558310b2cd2"
},
{
"url": "https://git.kernel.org/stable/c/a0c584fc18056709c8e047a82a6045d6c209f4ce"
}
],
"title": "bpf: Fix use-after-free in offloaded map/prog info fill",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-53089",
"datePublished": "2026-06-24T16:30:28.531Z",
"dateReserved": "2026-06-09T07:44:35.384Z",
"dateUpdated": "2026-09-02T12:49:34.606Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68135 (GCVE-0-2026-68135)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-19 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: hip04: fix RX buffer leak on build_skb failure
When build_skb() fails in hip04_rx_poll(), the driver jumps to the
refill path without releasing the current RX buffer and its DMA mapping.
Installing a replacement buffer then overwrites the slot references and
leaks both resources.
Keep the current slot intact and return budget so NAPI retries the same
buffer. Also free a newly allocated RX fragment when dma_map_single()
fails.
This issue was found by an in-house static analysis tool.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 701a0fd5231866db08cebcd502894699f49cb960 Version: 701a0fd5231866db08cebcd502894699f49cb960 Version: 701a0fd5231866db08cebcd502894699f49cb960 Version: 701a0fd5231866db08cebcd502894699f49cb960 Version: 701a0fd5231866db08cebcd502894699f49cb960 Version: 701a0fd5231866db08cebcd502894699f49cb960 Version: 701a0fd5231866db08cebcd502894699f49cb960 Version: 701a0fd5231866db08cebcd502894699f49cb960 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/hisilicon/hip04_eth.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "690ecc13a4032e5cae1dc6659512f32b033533b0",
"status": "affected",
"version": "701a0fd5231866db08cebcd502894699f49cb960",
"versionType": "git"
},
{
"lessThan": "2b19fe277645fd1aeb18fd4ecdcf31966080dee7",
"status": "affected",
"version": "701a0fd5231866db08cebcd502894699f49cb960",
"versionType": "git"
},
{
"lessThan": "bcd43ee1f25b682151df213c06a99b2e1c1cf2e5",
"status": "affected",
"version": "701a0fd5231866db08cebcd502894699f49cb960",
"versionType": "git"
},
{
"lessThan": "e054dcd990d8180cde529ea28ce0838e76a5ad5e",
"status": "affected",
"version": "701a0fd5231866db08cebcd502894699f49cb960",
"versionType": "git"
},
{
"lessThan": "67a7614bde310da006ab259f4f163d3fb0f9e253",
"status": "affected",
"version": "701a0fd5231866db08cebcd502894699f49cb960",
"versionType": "git"
},
{
"lessThan": "80d977f280b4eccd4ac5369871d0ecb2b9c9a49d",
"status": "affected",
"version": "701a0fd5231866db08cebcd502894699f49cb960",
"versionType": "git"
},
{
"lessThan": "a0f247d63489a107bbc3b712a77b302af2a2a173",
"status": "affected",
"version": "701a0fd5231866db08cebcd502894699f49cb960",
"versionType": "git"
},
{
"lessThan": "14fa65d10f5696b063a7d8d26e8291ea84a2c6ed",
"status": "affected",
"version": "701a0fd5231866db08cebcd502894699f49cb960",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/hisilicon/hip04_eth.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.5"
},
{
"lessThan": "4.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: hip04: fix RX buffer leak on build_skb failure\n\nWhen build_skb() fails in hip04_rx_poll(), the driver jumps to the\nrefill path without releasing the current RX buffer and its DMA mapping.\nInstalling a replacement buffer then overwrites the slot references and\nleaks both resources.\n\nKeep the current slot intact and return budget so NAPI retries the same\nbuffer. Also free a newly allocated RX fragment when dma_map_single()\nfails.\n\nThis issue was found by an in-house static analysis tool."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:29:52.114Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/690ecc13a4032e5cae1dc6659512f32b033533b0"
},
{
"url": "https://git.kernel.org/stable/c/2b19fe277645fd1aeb18fd4ecdcf31966080dee7"
},
{
"url": "https://git.kernel.org/stable/c/bcd43ee1f25b682151df213c06a99b2e1c1cf2e5"
},
{
"url": "https://git.kernel.org/stable/c/e054dcd990d8180cde529ea28ce0838e76a5ad5e"
},
{
"url": "https://git.kernel.org/stable/c/67a7614bde310da006ab259f4f163d3fb0f9e253"
},
{
"url": "https://git.kernel.org/stable/c/80d977f280b4eccd4ac5369871d0ecb2b9c9a49d"
},
{
"url": "https://git.kernel.org/stable/c/a0f247d63489a107bbc3b712a77b302af2a2a173"
},
{
"url": "https://git.kernel.org/stable/c/14fa65d10f5696b063a7d8d26e8291ea84a2c6ed"
}
],
"title": "net: hip04: fix RX buffer leak on build_skb failure",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68135",
"datePublished": "2026-08-10T11:58:58.463Z",
"dateReserved": "2026-07-30T09:28:09.370Z",
"dateUpdated": "2026-08-19T16:29:52.114Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74566 (GCVE-0-2026-74566)
Vulnerability from cvelistv5
Published
2026-08-15 12:28
Modified
2026-08-19 16:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
keys: make keyring key-chunk byte order agree with keyring_diff_objects()
keyring_get_key_chunk() loads description bytes into the index chunk low
address first, while keyring_diff_objects() numbers the first differing
bit from the low end and folds the absolute byte index into the level
without removing the inline-prefix offset the level already carries.
The two disagree on byte order and bit position, so the array can be
told two keys first differ at a bit that does not differ in the chunk
the walker uses, letting crafted descriptions collide into one node.
Load the chunk in the order keyring_diff_objects() assumes and drop the
inline-prefix length when folding the byte index into the level. This
only changes the in-memory ordering used to place keys within a keyring;
add, search and read of non-colliding keys are unaffected.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: f771fde82051976a6fc0fd570f8b86de4a92124b Version: f771fde82051976a6fc0fd570f8b86de4a92124b Version: f771fde82051976a6fc0fd570f8b86de4a92124b Version: f771fde82051976a6fc0fd570f8b86de4a92124b Version: f771fde82051976a6fc0fd570f8b86de4a92124b Version: f771fde82051976a6fc0fd570f8b86de4a92124b Version: f771fde82051976a6fc0fd570f8b86de4a92124b Version: f771fde82051976a6fc0fd570f8b86de4a92124b |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"security/keys/keyring.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "414bcf37d81ce9b3823aabc06b04c97fdcbe489b",
"status": "affected",
"version": "f771fde82051976a6fc0fd570f8b86de4a92124b",
"versionType": "git"
},
{
"lessThan": "abe43c661efb753d5ee35ad8ace4bbb16fa9afd0",
"status": "affected",
"version": "f771fde82051976a6fc0fd570f8b86de4a92124b",
"versionType": "git"
},
{
"lessThan": "f81920917074e3c4ad4fba06fe8c56738d010606",
"status": "affected",
"version": "f771fde82051976a6fc0fd570f8b86de4a92124b",
"versionType": "git"
},
{
"lessThan": "bd0f976ef89dce6db458bf75bc2cf51127becc41",
"status": "affected",
"version": "f771fde82051976a6fc0fd570f8b86de4a92124b",
"versionType": "git"
},
{
"lessThan": "7269df3e7fcfa308e6a456305162f7788747bdbd",
"status": "affected",
"version": "f771fde82051976a6fc0fd570f8b86de4a92124b",
"versionType": "git"
},
{
"lessThan": "3d9f16c0b643ceac305526b2e2fe25c2c6166926",
"status": "affected",
"version": "f771fde82051976a6fc0fd570f8b86de4a92124b",
"versionType": "git"
},
{
"lessThan": "7e5397a3fed0dee7779bd084bec3c0584db3c930",
"status": "affected",
"version": "f771fde82051976a6fc0fd570f8b86de4a92124b",
"versionType": "git"
},
{
"lessThan": "58565eef0f8d861aae92abfb7658458d661cee17",
"status": "affected",
"version": "f771fde82051976a6fc0fd570f8b86de4a92124b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"security/keys/keyring.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.3"
},
{
"lessThan": "5.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nkeys: make keyring key-chunk byte order agree with keyring_diff_objects()\n\nkeyring_get_key_chunk() loads description bytes into the index chunk low\naddress first, while keyring_diff_objects() numbers the first differing\nbit from the low end and folds the absolute byte index into the level\nwithout removing the inline-prefix offset the level already carries.\nThe two disagree on byte order and bit position, so the array can be\ntold two keys first differ at a bit that does not differ in the chunk\nthe walker uses, letting crafted descriptions collide into one node.\n\nLoad the chunk in the order keyring_diff_objects() assumes and drop the\ninline-prefix length when folding the byte index into the level. This\nonly changes the in-memory ordering used to place keys within a keyring;\nadd, search and read of non-colliding keys are unaffected."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:39:06.890Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/414bcf37d81ce9b3823aabc06b04c97fdcbe489b"
},
{
"url": "https://git.kernel.org/stable/c/abe43c661efb753d5ee35ad8ace4bbb16fa9afd0"
},
{
"url": "https://git.kernel.org/stable/c/f81920917074e3c4ad4fba06fe8c56738d010606"
},
{
"url": "https://git.kernel.org/stable/c/bd0f976ef89dce6db458bf75bc2cf51127becc41"
},
{
"url": "https://git.kernel.org/stable/c/7269df3e7fcfa308e6a456305162f7788747bdbd"
},
{
"url": "https://git.kernel.org/stable/c/3d9f16c0b643ceac305526b2e2fe25c2c6166926"
},
{
"url": "https://git.kernel.org/stable/c/7e5397a3fed0dee7779bd084bec3c0584db3c930"
},
{
"url": "https://git.kernel.org/stable/c/58565eef0f8d861aae92abfb7658458d661cee17"
}
],
"title": "keys: make keyring key-chunk byte order agree with keyring_diff_objects()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74566",
"datePublished": "2026-08-15T12:28:07.628Z",
"dateReserved": "2026-08-15T05:44:03.917Z",
"dateUpdated": "2026-08-19T16:39:06.890Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72015 (GCVE-0-2026-72015)
Vulnerability from cvelistv5
Published
2026-08-15 05:51
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
fs/resctrl: Fix double-add of pseudo-locked region's RMID to free list
A pseudo-locked group's RMID is freed when it is created. On unmount
rmdir_all_sub() unconditionally frees all RMID of all groups, resulting
in a double-free of the pseudo-locked group's RMID. The consequence of this
is that the original free results in the pseudo-locked group's RMID being
added to the rmid_free_lru linked list and the second free then attempts
to add the same RMID entry to the rmid_free_lru again.
Do not double-free a pseudo-locked group's RMID.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: e0bdfe8e36f3fbbdc91e70bf927f743ca23917b0 Version: e0bdfe8e36f3fbbdc91e70bf927f743ca23917b0 Version: e0bdfe8e36f3fbbdc91e70bf927f743ca23917b0 Version: e0bdfe8e36f3fbbdc91e70bf927f743ca23917b0 Version: e0bdfe8e36f3fbbdc91e70bf927f743ca23917b0 Version: e0bdfe8e36f3fbbdc91e70bf927f743ca23917b0 Version: e0bdfe8e36f3fbbdc91e70bf927f743ca23917b0 Version: e0bdfe8e36f3fbbdc91e70bf927f743ca23917b0 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/resctrl/rdtgroup.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "bab7dbba38ed3011972c3d9be2dcdca7575cbe32",
"status": "affected",
"version": "e0bdfe8e36f3fbbdc91e70bf927f743ca23917b0",
"versionType": "git"
},
{
"lessThan": "ad12e70d7dc3c94a05efc61d1e4861078e0e162b",
"status": "affected",
"version": "e0bdfe8e36f3fbbdc91e70bf927f743ca23917b0",
"versionType": "git"
},
{
"lessThan": "52b769165f20b38092f28ce064b4b143471540a7",
"status": "affected",
"version": "e0bdfe8e36f3fbbdc91e70bf927f743ca23917b0",
"versionType": "git"
},
{
"lessThan": "9168176894332312c12ef052e784735dbf4ffe3f",
"status": "affected",
"version": "e0bdfe8e36f3fbbdc91e70bf927f743ca23917b0",
"versionType": "git"
},
{
"lessThan": "b2fe9e140aa94b2816aab7ebc692b543e418f5e3",
"status": "affected",
"version": "e0bdfe8e36f3fbbdc91e70bf927f743ca23917b0",
"versionType": "git"
},
{
"lessThan": "52007bfdce5310e8c8a29849bfbfb188a1e50ca0",
"status": "affected",
"version": "e0bdfe8e36f3fbbdc91e70bf927f743ca23917b0",
"versionType": "git"
},
{
"lessThan": "f7628eea9212e185a09df3aea603ca8580b8678d",
"status": "affected",
"version": "e0bdfe8e36f3fbbdc91e70bf927f743ca23917b0",
"versionType": "git"
},
{
"lessThan": "b9f089723aee892efc77c349ae47a6b452b293c4",
"status": "affected",
"version": "e0bdfe8e36f3fbbdc91e70bf927f743ca23917b0",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/resctrl/rdtgroup.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.19"
},
{
"lessThan": "4.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs/resctrl: Fix double-add of pseudo-locked region\u0027s RMID to free list\n\nA pseudo-locked group\u0027s RMID is freed when it is created. On unmount\nrmdir_all_sub() unconditionally frees all RMID of all groups, resulting\nin a double-free of the pseudo-locked group\u0027s RMID. The consequence of this\nis that the original free results in the pseudo-locked group\u0027s RMID being\nadded to the rmid_free_lru linked list and the second free then attempts\nto add the same RMID entry to the rmid_free_lru again.\n\nDo not double-free a pseudo-locked group\u0027s RMID."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:25.496Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/bab7dbba38ed3011972c3d9be2dcdca7575cbe32"
},
{
"url": "https://git.kernel.org/stable/c/ad12e70d7dc3c94a05efc61d1e4861078e0e162b"
},
{
"url": "https://git.kernel.org/stable/c/52b769165f20b38092f28ce064b4b143471540a7"
},
{
"url": "https://git.kernel.org/stable/c/9168176894332312c12ef052e784735dbf4ffe3f"
},
{
"url": "https://git.kernel.org/stable/c/b2fe9e140aa94b2816aab7ebc692b543e418f5e3"
},
{
"url": "https://git.kernel.org/stable/c/52007bfdce5310e8c8a29849bfbfb188a1e50ca0"
},
{
"url": "https://git.kernel.org/stable/c/f7628eea9212e185a09df3aea603ca8580b8678d"
},
{
"url": "https://git.kernel.org/stable/c/b9f089723aee892efc77c349ae47a6b452b293c4"
}
],
"title": "fs/resctrl: Fix double-add of pseudo-locked region\u0027s RMID to free list",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72015",
"datePublished": "2026-08-15T05:51:43.390Z",
"dateReserved": "2026-08-09T03:40:39.900Z",
"dateUpdated": "2026-08-23T12:46:25.496Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74580 (GCVE-0-2026-74580)
Vulnerability from cvelistv5
Published
2026-08-21 16:31
Modified
2026-08-25 05:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
vhost: reset the vring metadata cache on vring reconfiguration
vq->meta_iotlb[] caches the vhost_iotlb_map that backs each vring
metadata region, and iotlb_access_ok() returns early on a cache hit,
taking the hit as proof that the region has already been validated:
if (vhost_vq_meta_fetch(vq, addr, len, type))
return true;
The cache is reset on VHOST_IOTLB_UPDATE and VHOST_IOTLB_INVALIDATE, on
device IOTLB (re)initialisation and on vq reset, but not when
VHOST_SET_VRING_ADDR replaces vq->desc, vq->avail and vq->used, nor when
VHOST_SET_VRING_NUM changes the region sizes.
With a device IOTLB attached both ioctls are accepted while the vq is
live, and neither validates the addresses at ioctl time: vq_access_ok()
and vq_log_used_access_ok() return true early because the addresses are
GIOVAs, deferring validation to prefetch time. Once the cache has been
populated that deferred validation no longer runs -- vq_meta_prefetch()
hits the stale entry and returns true -- and vhost_vq_meta_fetch() keeps
translating through the old mapping as
map->addr + addr - map->start
for an address the mapping no longer covers. vhost_copy_to_user() and
vhost_copy_from_user() consume the result with __copy_to_user() and
__copy_from_user(), which do not check it either, so a subsequent used
ring update or descriptor fetch accesses memory outside the region the
IOTLB actually maps.
Reset the metadata cache whenever the vring is reconfigured, so the new
addresses are pushed back through iotlb_access_ok()'s slow path.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: f889491380582b4ba2981cf0b0d7d6a40fb30ab7 Version: f889491380582b4ba2981cf0b0d7d6a40fb30ab7 Version: f889491380582b4ba2981cf0b0d7d6a40fb30ab7 Version: f889491380582b4ba2981cf0b0d7d6a40fb30ab7 Version: f889491380582b4ba2981cf0b0d7d6a40fb30ab7 Version: f889491380582b4ba2981cf0b0d7d6a40fb30ab7 Version: f889491380582b4ba2981cf0b0d7d6a40fb30ab7 Version: f889491380582b4ba2981cf0b0d7d6a40fb30ab7 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/vhost/vhost.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "5224bd37e37d36076a550d99b2aebba33939fd95",
"status": "affected",
"version": "f889491380582b4ba2981cf0b0d7d6a40fb30ab7",
"versionType": "git"
},
{
"lessThan": "54617e9119be2eb728ecdd8d977b99c99d4c498a",
"status": "affected",
"version": "f889491380582b4ba2981cf0b0d7d6a40fb30ab7",
"versionType": "git"
},
{
"lessThan": "13fa6f32a56a386a82bd7451644c494beed034af",
"status": "affected",
"version": "f889491380582b4ba2981cf0b0d7d6a40fb30ab7",
"versionType": "git"
},
{
"lessThan": "cf363a7a02ce132ef1f58084fdb13e1a3b7da7e7",
"status": "affected",
"version": "f889491380582b4ba2981cf0b0d7d6a40fb30ab7",
"versionType": "git"
},
{
"lessThan": "6fa3e9b1fe856259555a7e22f3f3082e7827fd9b",
"status": "affected",
"version": "f889491380582b4ba2981cf0b0d7d6a40fb30ab7",
"versionType": "git"
},
{
"lessThan": "f1e21108e3ddfcce62f6cad4ebd7b5674543c9e6",
"status": "affected",
"version": "f889491380582b4ba2981cf0b0d7d6a40fb30ab7",
"versionType": "git"
},
{
"lessThan": "b70ebe0bba254e093dd5fd4c0c170941ce83eb85",
"status": "affected",
"version": "f889491380582b4ba2981cf0b0d7d6a40fb30ab7",
"versionType": "git"
},
{
"lessThan": "de845981da67a6b049080c87e605130b0c30adc5",
"status": "affected",
"version": "f889491380582b4ba2981cf0b0d7d6a40fb30ab7",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/vhost/vhost.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.11"
},
{
"lessThan": "4.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nvhost: reset the vring metadata cache on vring reconfiguration\n\nvq-\u003emeta_iotlb[] caches the vhost_iotlb_map that backs each vring\nmetadata region, and iotlb_access_ok() returns early on a cache hit,\ntaking the hit as proof that the region has already been validated:\n\n\tif (vhost_vq_meta_fetch(vq, addr, len, type))\n\t\treturn true;\n\nThe cache is reset on VHOST_IOTLB_UPDATE and VHOST_IOTLB_INVALIDATE, on\ndevice IOTLB (re)initialisation and on vq reset, but not when\nVHOST_SET_VRING_ADDR replaces vq-\u003edesc, vq-\u003eavail and vq-\u003eused, nor when\nVHOST_SET_VRING_NUM changes the region sizes.\n\nWith a device IOTLB attached both ioctls are accepted while the vq is\nlive, and neither validates the addresses at ioctl time: vq_access_ok()\nand vq_log_used_access_ok() return true early because the addresses are\nGIOVAs, deferring validation to prefetch time. Once the cache has been\npopulated that deferred validation no longer runs -- vq_meta_prefetch()\nhits the stale entry and returns true -- and vhost_vq_meta_fetch() keeps\ntranslating through the old mapping as\n\n\tmap-\u003eaddr + addr - map-\u003estart\n\nfor an address the mapping no longer covers. vhost_copy_to_user() and\nvhost_copy_from_user() consume the result with __copy_to_user() and\n__copy_from_user(), which do not check it either, so a subsequent used\nring update or descriptor fetch accesses memory outside the region the\nIOTLB actually maps.\n\nReset the metadata cache whenever the vring is reconfigured, so the new\naddresses are pushed back through iotlb_access_ok()\u0027s slow path."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires ioctl on /dev/vhost-net or /dev/vhost-vsock (VHOST_SET_OWNER, VHOST_SET_FEATURES with VIRTIO_F_ACCESS_PLATFORM, VHOST_SET_VRING_ADDR, IOTLB updates); although virtio kicks and network I/O trigger the corrupting copies, the stale-cache state is created only through local vhost character-device syscalls, not remote packets.\nAC:L - An attacker who controls the vhost owner process can deterministically populate meta_iotlb via normal virtqueue traffic, issue VHOST_SET_VRING_ADDR with new GIOVAs while the backend is live, then trigger descriptor/used-ring access; no races, special heap layout, or victim timing are required.\nPR:L - No host root is needed: exploitation is performed by the vhost device owner (standard libvirt/QEMU kvm-group account) or, in the highest-impact cloud scenario, an authorized malicious VM tenant whose virtio traffic drives vhost workers after QEMU updates live vring addresses under VIRTIO_F_ACCESS_PLATFORM.\nUI:N - No end-user or administrator action is required beyond routine automated VM operation (virtio I/O, vhost backend attachment, and vring setup) that the attacker or tenant controls directly.\nS:C - Stale IOTLB metadata translation makes the host kernel read/write outside the mapped vring regions in the VMM userspace address space (QEMU), crossing the guest-to-host virtualization boundary\u2014the same escape class as CVE-2025-38074, not mere in-guest kernel impact.\nC:H - vhost_copy_from_user and __vhost_get_user use vhost_vq_meta_fetch\u0027s stale map-\u003eaddr+addr-map-\u003estart translation without bounds checks, enabling out-of-bounds reads of adjacent VMM memory during descriptor and avail-ring fetches (arbitrary misdirected kernel reads from host userspace).\nI:H - vhost_copy_to_user and vhost_put_user write used-ring entries through the same stale translation, giving controlled out-of-bounds writes into the VMM process that can corrupt QEMU heap, IOTLB tables, or migration metadata for code-execution primitives.\nA:H - Misdirected __copy_to_user/__copy_from_user against unmapped or invalid VMM addresses can fault the vhost worker (host kernel oops/panic), and corrupting VMM control structures reliably crashes or kills the hypervisor process, terminating the VM."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:40:06.380Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/5224bd37e37d36076a550d99b2aebba33939fd95"
},
{
"url": "https://git.kernel.org/stable/c/54617e9119be2eb728ecdd8d977b99c99d4c498a"
},
{
"url": "https://git.kernel.org/stable/c/13fa6f32a56a386a82bd7451644c494beed034af"
},
{
"url": "https://git.kernel.org/stable/c/cf363a7a02ce132ef1f58084fdb13e1a3b7da7e7"
},
{
"url": "https://git.kernel.org/stable/c/6fa3e9b1fe856259555a7e22f3f3082e7827fd9b"
},
{
"url": "https://git.kernel.org/stable/c/f1e21108e3ddfcce62f6cad4ebd7b5674543c9e6"
},
{
"url": "https://git.kernel.org/stable/c/b70ebe0bba254e093dd5fd4c0c170941ce83eb85"
},
{
"url": "https://git.kernel.org/stable/c/de845981da67a6b049080c87e605130b0c30adc5"
}
],
"title": "vhost: reset the vring metadata cache on vring reconfiguration",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74580",
"datePublished": "2026-08-21T16:31:54.076Z",
"dateReserved": "2026-08-15T05:44:03.918Z",
"dateUpdated": "2026-08-25T05:40:06.380Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80765 (GCVE-0-2026-80765)
Vulnerability from cvelistv5
Published
2026-09-04 15:12
Modified
2026-09-04 15:12
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
HID: hyperv: validate initial device info bounds
The Hyper-V synthetic HID host supplies SYNTH_HID_INITIAL_DEVICE_INFO
messages that contain a HID descriptor followed by the report descriptor
bytes. mousevsc_on_receive_device_info() trusts bLength and
wDescriptorLength without checking that the received packet contains both
byte ranges.
A malformed host or backend message can therefore make the guest read
past the received VMBus packet while copying the report descriptor. Pass
the received initial-device-info size into the parser and reject
descriptor lengths that exceed the packet.
Impact: A malicious Hyper-V host or backend can crash a guest by sending
a short initial device-info message with an oversized HID report
descriptor length.
References
| URL | Tags | ||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: b95f5bcb811e3905b5376f87789da8d097fee682 Version: b95f5bcb811e3905b5376f87789da8d097fee682 Version: b95f5bcb811e3905b5376f87789da8d097fee682 Version: b95f5bcb811e3905b5376f87789da8d097fee682 Version: b95f5bcb811e3905b5376f87789da8d097fee682 Version: b95f5bcb811e3905b5376f87789da8d097fee682 Version: b95f5bcb811e3905b5376f87789da8d097fee682 Version: b95f5bcb811e3905b5376f87789da8d097fee682 Version: b95f5bcb811e3905b5376f87789da8d097fee682 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/hid/hid-hyperv.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "e0d5d3e45e142b7ef7525654aaa54d3e986002a6",
"status": "affected",
"version": "b95f5bcb811e3905b5376f87789da8d097fee682",
"versionType": "git"
},
{
"lessThan": "390d3d9c52a710fdc9de95a537747397c0c671d1",
"status": "affected",
"version": "b95f5bcb811e3905b5376f87789da8d097fee682",
"versionType": "git"
},
{
"lessThan": "8614c043b11cc35ffebd35542ab4da275f8f923d",
"status": "affected",
"version": "b95f5bcb811e3905b5376f87789da8d097fee682",
"versionType": "git"
},
{
"lessThan": "334271d3812ab3197c95b4593bc6745f8d189114",
"status": "affected",
"version": "b95f5bcb811e3905b5376f87789da8d097fee682",
"versionType": "git"
},
{
"lessThan": "f84d777574b748b1a488723ca7be9d87a301a872",
"status": "affected",
"version": "b95f5bcb811e3905b5376f87789da8d097fee682",
"versionType": "git"
},
{
"lessThan": "608f8fd8c0f7b6268da43509447802955f210aac",
"status": "affected",
"version": "b95f5bcb811e3905b5376f87789da8d097fee682",
"versionType": "git"
},
{
"lessThan": "2529737763cb4bcfcaf397beeea2664656c865b4",
"status": "affected",
"version": "b95f5bcb811e3905b5376f87789da8d097fee682",
"versionType": "git"
},
{
"lessThan": "c894143c508a7e063aab9f73c9e835ab40121283",
"status": "affected",
"version": "b95f5bcb811e3905b5376f87789da8d097fee682",
"versionType": "git"
},
{
"lessThan": "934b7778aa7b7c8f6bb073d2a73ba3674885bae0",
"status": "affected",
"version": "b95f5bcb811e3905b5376f87789da8d097fee682",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/hid/hid-hyperv.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.3"
},
{
"lessThan": "3.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.267",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.218",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.185",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.154",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.106",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.47",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.1",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.267",
"versionStartIncluding": "3.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.218",
"versionStartIncluding": "3.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.185",
"versionStartIncluding": "3.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.154",
"versionStartIncluding": "3.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.106",
"versionStartIncluding": "3.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.47",
"versionStartIncluding": "3.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.11",
"versionStartIncluding": "3.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.1",
"versionStartIncluding": "3.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "3.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: hyperv: validate initial device info bounds\n\nThe Hyper-V synthetic HID host supplies SYNTH_HID_INITIAL_DEVICE_INFO\nmessages that contain a HID descriptor followed by the report descriptor\nbytes. mousevsc_on_receive_device_info() trusts bLength and\nwDescriptorLength without checking that the received packet contains both\nbyte ranges.\n\nA malformed host or backend message can therefore make the guest read\npast the received VMBus packet while copying the report descriptor. Pass\nthe received initial-device-info size into the parser and reject\ndescriptor lengths that exceed the packet.\n\nImpact: A malicious Hyper-V host or backend can crash a guest by sending\na short initial device-info message with an oversized HID report\ndescriptor length."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T15:12:37.639Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/e0d5d3e45e142b7ef7525654aaa54d3e986002a6"
},
{
"url": "https://git.kernel.org/stable/c/390d3d9c52a710fdc9de95a537747397c0c671d1"
},
{
"url": "https://git.kernel.org/stable/c/8614c043b11cc35ffebd35542ab4da275f8f923d"
},
{
"url": "https://git.kernel.org/stable/c/334271d3812ab3197c95b4593bc6745f8d189114"
},
{
"url": "https://git.kernel.org/stable/c/f84d777574b748b1a488723ca7be9d87a301a872"
},
{
"url": "https://git.kernel.org/stable/c/608f8fd8c0f7b6268da43509447802955f210aac"
},
{
"url": "https://git.kernel.org/stable/c/2529737763cb4bcfcaf397beeea2664656c865b4"
},
{
"url": "https://git.kernel.org/stable/c/c894143c508a7e063aab9f73c9e835ab40121283"
},
{
"url": "https://git.kernel.org/stable/c/934b7778aa7b7c8f6bb073d2a73ba3674885bae0"
}
],
"title": "HID: hyperv: validate initial device info bounds",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80765",
"datePublished": "2026-09-04T15:12:37.639Z",
"dateReserved": "2026-08-26T14:34:25.791Z",
"dateUpdated": "2026-09-04T15:12:37.639Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68144 (GCVE-0-2026-68144)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
phonet: pep: fix use-after-free in pep_get_sb()
pep_get_sb() doesn't consider that pskb_may_pull() might have relocated
the skb data, and continue to access the older pointer, causing UAF.
Reproduced under KASAN:
BUG: KASAN: slab-use-after-free in pep_get_sb+0x234/0x3b0
Read of size 1 at addr ff11000105510f50 by task repro/157
pep_get_sb+0x234/0x3b0
pipe_handler_do_rcv+0x5f7/0xa10
pep_do_rcv+0x203/0x410
__sk_receive_skb+0x471/0x4a0
phonet_rcv+0x5b3/0x6c0
__netif_receive_skb+0xcc/0x1d0
Refetch the header with skb_header_pointer() after pskb_may_pull(), so
the possibly stale pointer is no longer dereferenced. There are better
ways to solve this, but, this is the less instrusive one.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 9641458d3ec42def729fde64669abf07f3220cd5 Version: 9641458d3ec42def729fde64669abf07f3220cd5 Version: 9641458d3ec42def729fde64669abf07f3220cd5 Version: 9641458d3ec42def729fde64669abf07f3220cd5 Version: 9641458d3ec42def729fde64669abf07f3220cd5 Version: 9641458d3ec42def729fde64669abf07f3220cd5 Version: 9641458d3ec42def729fde64669abf07f3220cd5 Version: 9641458d3ec42def729fde64669abf07f3220cd5 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/phonet/pep.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c4a52cb4da8d57d060b1d52085d25147a238dac2",
"status": "affected",
"version": "9641458d3ec42def729fde64669abf07f3220cd5",
"versionType": "git"
},
{
"lessThan": "df198743859fefba2f824115f8151dd62d7ad6d8",
"status": "affected",
"version": "9641458d3ec42def729fde64669abf07f3220cd5",
"versionType": "git"
},
{
"lessThan": "1d81e19fc57a5ee55b4497d01bc0510d76fb9578",
"status": "affected",
"version": "9641458d3ec42def729fde64669abf07f3220cd5",
"versionType": "git"
},
{
"lessThan": "8d931a75a38b9bb584a4071f5ebbd52755fc35ee",
"status": "affected",
"version": "9641458d3ec42def729fde64669abf07f3220cd5",
"versionType": "git"
},
{
"lessThan": "17f78c0c0d41d738ee236eb6e841e39395188054",
"status": "affected",
"version": "9641458d3ec42def729fde64669abf07f3220cd5",
"versionType": "git"
},
{
"lessThan": "a48a889b60f73edb0399a8b08284a2ab0bd0295f",
"status": "affected",
"version": "9641458d3ec42def729fde64669abf07f3220cd5",
"versionType": "git"
},
{
"lessThan": "25e3641beb51333bfbb155af2fd2573a61113af2",
"status": "affected",
"version": "9641458d3ec42def729fde64669abf07f3220cd5",
"versionType": "git"
},
{
"lessThan": "0f71f852a96af9685858ce59fda34ecbf85c283d",
"status": "affected",
"version": "9641458d3ec42def729fde64669abf07f3220cd5",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/phonet/pep.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.28"
},
{
"lessThan": "2.6.28",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.28",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nphonet: pep: fix use-after-free in pep_get_sb()\n\npep_get_sb() doesn\u0027t consider that pskb_may_pull() might have relocated\nthe skb data, and continue to access the older pointer, causing UAF.\n\nReproduced under KASAN:\n\n BUG: KASAN: slab-use-after-free in pep_get_sb+0x234/0x3b0\n Read of size 1 at addr ff11000105510f50 by task repro/157\n pep_get_sb+0x234/0x3b0\n pipe_handler_do_rcv+0x5f7/0xa10\n pep_do_rcv+0x203/0x410\n __sk_receive_skb+0x471/0x4a0\n phonet_rcv+0x5b3/0x6c0\n __netif_receive_skb+0xcc/0x1d0\n\nRefetch the header with skb_header_pointer() after pskb_may_pull(), so\nthe possibly stale pointer is no longer dereferenced. There are better\nways to solve this, but, this is the less instrusive one."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug is hit in phonet_rcv() via __netif_receive_skb() when processing inbound Phonet pipe packets on a netdev; on modem-equipped phones this path is reachable from the cellular/BT-facing modem link without local access.\nAC:L - The attacker fully controls crafted TLV sb_len values in Phonet pipe messages to deterministically force pskb_may_pull() skb head reallocation; no race or victim-specific state beyond an existing/connecting pipe socket is required.\nPR:N - Exploitation requires only delivering a malformed Phonet packet to a listening/connecting pipe endpoint; phonet_rcv() performs no authentication or capability checks before delivering to pep_do_rcv() and pep_get_sb().\nUI:N - No end-user action is needed; triggering only requires a background phonet pipe listener or an in-progress connect/accept on affected Nokia/modem platforms where phonet daemons run continuously.\nS:U - Impact is confined to kernel memory/process integrity on the affected host; successful exploitation yields local privilege escalation within the same kernel security domain, not a cross-VM or cross-container boundary escape.\nC:H - Confirmed slab use-after-free read in pep_get_sb(); stale post-realloc pointer dereference can leak adjacent heap contents and is a standard primitive for arbitrary kernel memory disclosure.\nI:H - Use-after-free on skb header memory enables heap grooming and control of freed object contents, providing a well-established path to arbitrary kernel writes and code execution beyond the immediate one-byte read.\nA:H - KASAN reproduced a slab use-after-free oops in pep_get_sb() during packet receive; even without full exploit development, malformed Phonet pipe packets can reliably panic or hang the kernel on affected systems."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:30:06.882Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c4a52cb4da8d57d060b1d52085d25147a238dac2"
},
{
"url": "https://git.kernel.org/stable/c/df198743859fefba2f824115f8151dd62d7ad6d8"
},
{
"url": "https://git.kernel.org/stable/c/1d81e19fc57a5ee55b4497d01bc0510d76fb9578"
},
{
"url": "https://git.kernel.org/stable/c/8d931a75a38b9bb584a4071f5ebbd52755fc35ee"
},
{
"url": "https://git.kernel.org/stable/c/17f78c0c0d41d738ee236eb6e841e39395188054"
},
{
"url": "https://git.kernel.org/stable/c/a48a889b60f73edb0399a8b08284a2ab0bd0295f"
},
{
"url": "https://git.kernel.org/stable/c/25e3641beb51333bfbb155af2fd2573a61113af2"
},
{
"url": "https://git.kernel.org/stable/c/0f71f852a96af9685858ce59fda34ecbf85c283d"
}
],
"title": "phonet: pep: fix use-after-free in pep_get_sb()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68144",
"datePublished": "2026-08-10T11:59:08.437Z",
"dateReserved": "2026-07-30T09:28:09.370Z",
"dateUpdated": "2026-08-19T16:30:06.882Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68192 (GCVE-0-2026-68192)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: brcmfmac: make release_scratchbuffers idempotent
brcmf_pcie_release_scratchbuffers() frees the shared.scratch and
shared.ringupd DMA buffers with dma_free_coherent() but does not clear
the pointers afterwards, unlike the sibling release_ringbuffers() which
NULLs commonrings/flowrings/idxbuf on release.
Both the bus_reset .reset callback (brcmf_pcie_reset) and
brcmf_pcie_remove() call release_scratchbuffers. When reset teardown
has run before removal, remove's own teardown would call
dma_free_coherent() a second time on the already-freed DMA allocation.
NULL the pointers after free, matching release_ringbuffers(), so a later
release observes that the allocation has already been released. This
patch makes repeated sequential release safe; the reset-work lifetime is
handled separately by the following patch.
This issue was found by an in-house static analysis tool.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 4684997d9eea29380000e062755aa6d368d789a3 Version: 4684997d9eea29380000e062755aa6d368d789a3 Version: 4684997d9eea29380000e062755aa6d368d789a3 Version: 4684997d9eea29380000e062755aa6d368d789a3 Version: 4684997d9eea29380000e062755aa6d368d789a3 Version: 4684997d9eea29380000e062755aa6d368d789a3 Version: 4684997d9eea29380000e062755aa6d368d789a3 Version: 4684997d9eea29380000e062755aa6d368d789a3 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/broadcom/brcm80211/brcmfmac/pcie.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "81c58a206d1deee01f4c29236d4154c0872f2a38",
"status": "affected",
"version": "4684997d9eea29380000e062755aa6d368d789a3",
"versionType": "git"
},
{
"lessThan": "382ee00b2d1e31869ae576a60d3fbe7a2153512f",
"status": "affected",
"version": "4684997d9eea29380000e062755aa6d368d789a3",
"versionType": "git"
},
{
"lessThan": "739b686aecdb14a6065300ea53401f043e51fd22",
"status": "affected",
"version": "4684997d9eea29380000e062755aa6d368d789a3",
"versionType": "git"
},
{
"lessThan": "b7d1d8cb1bdca56aecebacd2896615da0acc126a",
"status": "affected",
"version": "4684997d9eea29380000e062755aa6d368d789a3",
"versionType": "git"
},
{
"lessThan": "5a045c2f0fbf029873d2295178fa0785ade35af0",
"status": "affected",
"version": "4684997d9eea29380000e062755aa6d368d789a3",
"versionType": "git"
},
{
"lessThan": "044fca8f45ba9ab6ca526163155234cf88287ff5",
"status": "affected",
"version": "4684997d9eea29380000e062755aa6d368d789a3",
"versionType": "git"
},
{
"lessThan": "0ca80328df23f851c86866720d4977783c919ee6",
"status": "affected",
"version": "4684997d9eea29380000e062755aa6d368d789a3",
"versionType": "git"
},
{
"lessThan": "538c51e9d124cf656f2dd0c0394a8545efc7102d",
"status": "affected",
"version": "4684997d9eea29380000e062755aa6d368d789a3",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/broadcom/brcm80211/brcmfmac/pcie.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.2"
},
{
"lessThan": "5.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: brcmfmac: make release_scratchbuffers idempotent\n\nbrcmf_pcie_release_scratchbuffers() frees the shared.scratch and\nshared.ringupd DMA buffers with dma_free_coherent() but does not clear\nthe pointers afterwards, unlike the sibling release_ringbuffers() which\nNULLs commonrings/flowrings/idxbuf on release.\n\nBoth the bus_reset .reset callback (brcmf_pcie_reset) and\nbrcmf_pcie_remove() call release_scratchbuffers. When reset teardown\nhas run before removal, remove\u0027s own teardown would call\ndma_free_coherent() a second time on the already-freed DMA allocation.\n\nNULL the pointers after free, matching release_ringbuffers(), so a later\nrelease observes that the allocation has already been released. This\npatch makes repeated sequential release safe; the reset-work lifetime is\nhandled separately by the following patch.\n\nThis issue was found by an in-house static analysis tool."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The flaw is reached during brcmfmac PCIe bus reset/teardown after firmware halt; brcmf_fw_crashed() is invoked from the threaded IRQ handler on BRCMF_D2H_DEV_FWHALT mailbox data from the WiFi firmware, which an adjacent attacker can trigger with crafted over-the-air WiFi traffic to crash the dongle.\nAC:L - An attacker who induces firmware halt controls the reset sequence; brcmf_pcie_reset() always frees scratch buffers first and a later brcmf_pcie_remove() or failed brcmf_pcie_setup() teardown calls release_scratchbuffers() again on the same stale pointers, making the double-free deterministic without races they cannot influence.\nPR:N - No host privileges are required because crashing Broadcom FullMAC firmware via adjacent WiFi frames reaches brcmf_fw_crashed() without authentication, CAP_NET_ADMIN, or local access; the debugfs reset path is root-only but is not needed for the highest-impact attack scenario.\nUI:N - Exploitation only requires a victim with an active brcmfmac PCIe WiFi interface within RF range; no victim click, file open, driver unload, or other explicit user action is needed beyond normal always-on WiFi operation on laptops and embedded hosts using Broadcom PCIe FullMAC chips.\nS:U - The vulnerability corrupts kernel DMA/page-allocator state and enables host kernel privilege escalation within the same security authority; it does not cross VM, container, or IOMMU boundaries, so scope remains unchanged.\nC:H - Calling dma_free_coherent() twice on the same scratch and ringupd DMA allocations is a double-free of kernel coherent memory; this allocator-metadata corruption can be leveraged for arbitrary kernel memory disclosure even when full exploitation is not attempted, per kernel CVSS guidance for memory corruption.\nI:H - Double-free of dma_alloc_coherent buffers corrupts the kernel DMA/page heap freelist, enabling attacker-controlled reallocation and arbitrary kernel writes or control-flow hijack on systems with BRCMFMAC_PCIE enabled and a reachable Broadcom PCIe FullMAC wireless device.\nA:H - Re-freeing already released DMA-coherent allocations during driver reset or removal typically causes immediate kernel BUG/oops/panic or fatal allocator corruption during teardown, guaranteeing severe host availability loss on affected Broadcom PCIe WiFi systems even when code execution is not achieved."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:06.873Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/81c58a206d1deee01f4c29236d4154c0872f2a38"
},
{
"url": "https://git.kernel.org/stable/c/382ee00b2d1e31869ae576a60d3fbe7a2153512f"
},
{
"url": "https://git.kernel.org/stable/c/739b686aecdb14a6065300ea53401f043e51fd22"
},
{
"url": "https://git.kernel.org/stable/c/b7d1d8cb1bdca56aecebacd2896615da0acc126a"
},
{
"url": "https://git.kernel.org/stable/c/5a045c2f0fbf029873d2295178fa0785ade35af0"
},
{
"url": "https://git.kernel.org/stable/c/044fca8f45ba9ab6ca526163155234cf88287ff5"
},
{
"url": "https://git.kernel.org/stable/c/0ca80328df23f851c86866720d4977783c919ee6"
},
{
"url": "https://git.kernel.org/stable/c/538c51e9d124cf656f2dd0c0394a8545efc7102d"
}
],
"title": "wifi: brcmfmac: make release_scratchbuffers idempotent",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68192",
"datePublished": "2026-08-10T12:00:10.041Z",
"dateReserved": "2026-07-30T09:28:09.373Z",
"dateUpdated": "2026-08-19T16:31:06.873Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68369 (GCVE-0-2026-68369)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: printer: fix infinite loop in printer_read()
printer_read() uses the same variable for the requested copy size and
the number of bytes actually copied to user space. copy_to_user()
returns the number of bytes not copied, so when it fails to copy
anything, the computed copied length becomes zero.
In that case len, buf, current_rx_bytes and current_rx_buf are left
unchanged. If RX data is available and the user buffer remains
unwritable, the read loop can repeat indefinitely.
Track the copied length separately and return -EFAULT, or the number of
bytes already copied, if an iteration makes no progress.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: b185f01a9ab7af586133be2555298e960237359b Version: b185f01a9ab7af586133be2555298e960237359b Version: b185f01a9ab7af586133be2555298e960237359b Version: b185f01a9ab7af586133be2555298e960237359b Version: b185f01a9ab7af586133be2555298e960237359b Version: b185f01a9ab7af586133be2555298e960237359b Version: b185f01a9ab7af586133be2555298e960237359b Version: b185f01a9ab7af586133be2555298e960237359b |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/gadget/function/f_printer.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "3f81197364b57e5318620c75f3bd63f405f60552",
"status": "affected",
"version": "b185f01a9ab7af586133be2555298e960237359b",
"versionType": "git"
},
{
"lessThan": "e225e2998e5a9b83c838dbbe4511fb0d63f88daf",
"status": "affected",
"version": "b185f01a9ab7af586133be2555298e960237359b",
"versionType": "git"
},
{
"lessThan": "3081b0e187065c3b9577e393ad664b12854aeaf3",
"status": "affected",
"version": "b185f01a9ab7af586133be2555298e960237359b",
"versionType": "git"
},
{
"lessThan": "994afccfdcceb73be33f69a8a8ea71e260c9eca5",
"status": "affected",
"version": "b185f01a9ab7af586133be2555298e960237359b",
"versionType": "git"
},
{
"lessThan": "e03597ad9494b500344076589aeaa6c6d2d381d3",
"status": "affected",
"version": "b185f01a9ab7af586133be2555298e960237359b",
"versionType": "git"
},
{
"lessThan": "4cde0b38cc0cb8b7dc17295801015148de37d1d2",
"status": "affected",
"version": "b185f01a9ab7af586133be2555298e960237359b",
"versionType": "git"
},
{
"lessThan": "e41bbbbb1740ce4d7270ab1cdeca13892d6a8d2e",
"status": "affected",
"version": "b185f01a9ab7af586133be2555298e960237359b",
"versionType": "git"
},
{
"lessThan": "c2e819be6a5c7f34344926b4bd7e3dfca58cf48a",
"status": "affected",
"version": "b185f01a9ab7af586133be2555298e960237359b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/usb/gadget/function/f_printer.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.1"
},
{
"lessThan": "4.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: printer: fix infinite loop in printer_read()\n\nprinter_read() uses the same variable for the requested copy size and\nthe number of bytes actually copied to user space. copy_to_user()\nreturns the number of bytes not copied, so when it fails to copy\nanything, the computed copied length becomes zero.\n\nIn that case len, buf, current_rx_bytes and current_rx_buf are left\nunchanged. If RX data is available and the user buffer remains\nunwritable, the read loop can repeat indefinitely.\n\nTrack the copied length separately and return -EFAULT, or the number of\nbytes already copied, if an iteration makes no progress."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:28.812Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/3f81197364b57e5318620c75f3bd63f405f60552"
},
{
"url": "https://git.kernel.org/stable/c/e225e2998e5a9b83c838dbbe4511fb0d63f88daf"
},
{
"url": "https://git.kernel.org/stable/c/3081b0e187065c3b9577e393ad664b12854aeaf3"
},
{
"url": "https://git.kernel.org/stable/c/994afccfdcceb73be33f69a8a8ea71e260c9eca5"
},
{
"url": "https://git.kernel.org/stable/c/e03597ad9494b500344076589aeaa6c6d2d381d3"
},
{
"url": "https://git.kernel.org/stable/c/4cde0b38cc0cb8b7dc17295801015148de37d1d2"
},
{
"url": "https://git.kernel.org/stable/c/e41bbbbb1740ce4d7270ab1cdeca13892d6a8d2e"
},
{
"url": "https://git.kernel.org/stable/c/c2e819be6a5c7f34344926b4bd7e3dfca58cf48a"
}
],
"title": "usb: gadget: printer: fix infinite loop in printer_read()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68369",
"datePublished": "2026-08-10T12:03:46.845Z",
"dateReserved": "2026-07-30T09:28:09.386Z",
"dateUpdated": "2026-08-19T16:34:28.812Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68357 (GCVE-0-2026-68357)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
watchdog: pretimeout: Fix UAF in watchdog_unregister_governor()
When a watchdog governor is unregistered, it updates existing watchdog
devices that were using this governor by falling back to `default_gov`.
If the governor being unregistered is currently set as `default_gov`,
the `default_gov` is never cleared. This leads to 2 use-after-free
issues:
1. New watchdog devices registered after this point will inherit the
dangling `default_gov`.
2. Existing watchdog devices using the unregistered governor will have
their `wdd->gov` reassigned to the dangling `default_gov`.
Fix the UAF by clearing `default_gov` if it matches the governor being
unregistered.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: da0d12ff2b829a35e9921918e925d79497b82bef Version: da0d12ff2b829a35e9921918e925d79497b82bef Version: da0d12ff2b829a35e9921918e925d79497b82bef Version: da0d12ff2b829a35e9921918e925d79497b82bef Version: da0d12ff2b829a35e9921918e925d79497b82bef Version: da0d12ff2b829a35e9921918e925d79497b82bef Version: da0d12ff2b829a35e9921918e925d79497b82bef Version: da0d12ff2b829a35e9921918e925d79497b82bef |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/watchdog/watchdog_pretimeout.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b9ae33faa96bdec6bc60e4c5f8f53786182e4207",
"status": "affected",
"version": "da0d12ff2b829a35e9921918e925d79497b82bef",
"versionType": "git"
},
{
"lessThan": "472ec1e34ff0bb26379805cae808f658cce58c35",
"status": "affected",
"version": "da0d12ff2b829a35e9921918e925d79497b82bef",
"versionType": "git"
},
{
"lessThan": "7a2ee3ec6f208307eca1119a343c7b5d39c03708",
"status": "affected",
"version": "da0d12ff2b829a35e9921918e925d79497b82bef",
"versionType": "git"
},
{
"lessThan": "2e47b91b9b4020fcc01def14d6b6556d66074cf4",
"status": "affected",
"version": "da0d12ff2b829a35e9921918e925d79497b82bef",
"versionType": "git"
},
{
"lessThan": "0ca252720f0e38411cfec3431db9bb1aed0a412c",
"status": "affected",
"version": "da0d12ff2b829a35e9921918e925d79497b82bef",
"versionType": "git"
},
{
"lessThan": "7d1658b066de30f4b23afc14814d22416a971e6e",
"status": "affected",
"version": "da0d12ff2b829a35e9921918e925d79497b82bef",
"versionType": "git"
},
{
"lessThan": "7993d626983cc58fbde9607333cfd2d57725c197",
"status": "affected",
"version": "da0d12ff2b829a35e9921918e925d79497b82bef",
"versionType": "git"
},
{
"lessThan": "7362ba0f9c96ac3ad6a2ca3995bd9fc9a28a8661",
"status": "affected",
"version": "da0d12ff2b829a35e9921918e925d79497b82bef",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/watchdog/watchdog_pretimeout.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.9"
},
{
"lessThan": "4.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwatchdog: pretimeout: Fix UAF in watchdog_unregister_governor()\n\nWhen a watchdog governor is unregistered, it updates existing watchdog\ndevices that were using this governor by falling back to `default_gov`.\n\nIf the governor being unregistered is currently set as `default_gov`,\nthe `default_gov` is never cleared. This leads to 2 use-after-free\nissues:\n1. New watchdog devices registered after this point will inherit the\n dangling `default_gov`.\n2. Existing watchdog devices using the unregistered governor will have\n their `wdd-\u003egov` reassigned to the dangling `default_gov`.\n\nFix the UAF by clearing `default_gov` if it matches the governor being\nunregistered."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:05.347Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b9ae33faa96bdec6bc60e4c5f8f53786182e4207"
},
{
"url": "https://git.kernel.org/stable/c/472ec1e34ff0bb26379805cae808f658cce58c35"
},
{
"url": "https://git.kernel.org/stable/c/7a2ee3ec6f208307eca1119a343c7b5d39c03708"
},
{
"url": "https://git.kernel.org/stable/c/2e47b91b9b4020fcc01def14d6b6556d66074cf4"
},
{
"url": "https://git.kernel.org/stable/c/0ca252720f0e38411cfec3431db9bb1aed0a412c"
},
{
"url": "https://git.kernel.org/stable/c/7d1658b066de30f4b23afc14814d22416a971e6e"
},
{
"url": "https://git.kernel.org/stable/c/7993d626983cc58fbde9607333cfd2d57725c197"
},
{
"url": "https://git.kernel.org/stable/c/7362ba0f9c96ac3ad6a2ca3995bd9fc9a28a8661"
}
],
"title": "watchdog: pretimeout: Fix UAF in watchdog_unregister_governor()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68357",
"datePublished": "2026-08-10T12:03:34.241Z",
"dateReserved": "2026-07-30T09:28:09.385Z",
"dateUpdated": "2026-08-19T16:34:05.347Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80854 (GCVE-0-2026-80854)
Vulnerability from cvelistv5
Published
2026-09-04 15:55
Modified
2026-09-04 15:55
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: f_tcm: keep port count until LUN teardown completes
tcm_usbg_drop_nexus() permits session removal once tpg_port_count
reaches zero. However, usbg_port_unlink() currently decrements that
count from the fabric_pre_unlink() callback, before core_dev_del_lun()
waits for active se_lun references to drain.
If removal of the last LUN races a nexus removal, the latter can observe
a zero port count and call target_remove_session(). This frees
sess_cmd_map while an in-flight struct usbg_cmd, including its work item,
can still be accessed.
Overlapping the last-LUN unlink with nexus removal reproduces this
lifetime violation as a DEBUG_OBJECTS "free active" warning for
usbg_cmd_work, followed by a target-core BUG/Oops.
The generic target-core unlink path has no callback after
core_dev_del_lun() completes. Add an optional fabric_post_unlink()
callback and use it for the f_tcm port count. The count now remains
nonzero until core_dev_del_lun() has finished draining active LUN
references, preventing nexus removal from freeing the session during
command completion.
References
| URL | Tags | ||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: c52661d60f636d17e26ad834457db333bd1df494 Version: c52661d60f636d17e26ad834457db333bd1df494 Version: c52661d60f636d17e26ad834457db333bd1df494 Version: c52661d60f636d17e26ad834457db333bd1df494 Version: c52661d60f636d17e26ad834457db333bd1df494 Version: c52661d60f636d17e26ad834457db333bd1df494 Version: c52661d60f636d17e26ad834457db333bd1df494 Version: c52661d60f636d17e26ad834457db333bd1df494 Version: c52661d60f636d17e26ad834457db333bd1df494 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/target/target_core_fabric_configfs.c",
"drivers/usb/gadget/function/f_tcm.c",
"include/target/target_core_fabric.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c494c5562ca69b61a82f566e3b87a445d2c28929",
"status": "affected",
"version": "c52661d60f636d17e26ad834457db333bd1df494",
"versionType": "git"
},
{
"lessThan": "c1f359d9a5efed458946063de65ddbeaacc4f165",
"status": "affected",
"version": "c52661d60f636d17e26ad834457db333bd1df494",
"versionType": "git"
},
{
"lessThan": "178f59a0bccd3f66cdfa5184310f31a58b7257c4",
"status": "affected",
"version": "c52661d60f636d17e26ad834457db333bd1df494",
"versionType": "git"
},
{
"lessThan": "ad6f0375d2e93a1d8c015463e5e92dfcb26e311b",
"status": "affected",
"version": "c52661d60f636d17e26ad834457db333bd1df494",
"versionType": "git"
},
{
"lessThan": "2efbfd42441d3ef8137aff2d59e9835e1d5ae780",
"status": "affected",
"version": "c52661d60f636d17e26ad834457db333bd1df494",
"versionType": "git"
},
{
"lessThan": "85aa61fedcb4eb13f3dc5db73f6dc359f41f5d95",
"status": "affected",
"version": "c52661d60f636d17e26ad834457db333bd1df494",
"versionType": "git"
},
{
"lessThan": "bbd6aa311a9f4dd17822c7557451458d3d2e980b",
"status": "affected",
"version": "c52661d60f636d17e26ad834457db333bd1df494",
"versionType": "git"
},
{
"lessThan": "eaa96a8458f54d6cf0954242ab8b1df2a6fccafa",
"status": "affected",
"version": "c52661d60f636d17e26ad834457db333bd1df494",
"versionType": "git"
},
{
"lessThan": "c39d0916da47d94909391876c9e5bd429ea7b1b9",
"status": "affected",
"version": "c52661d60f636d17e26ad834457db333bd1df494",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/target/target_core_fabric_configfs.c",
"drivers/usb/gadget/function/f_tcm.c",
"include/target/target_core_fabric.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.5"
},
{
"lessThan": "3.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.269",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.220",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.187",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.156",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.108",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.49",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.13",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.3",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.269",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.220",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.187",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.156",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.108",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.49",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.13",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.3",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "3.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: f_tcm: keep port count until LUN teardown completes\n\ntcm_usbg_drop_nexus() permits session removal once tpg_port_count\nreaches zero. However, usbg_port_unlink() currently decrements that\ncount from the fabric_pre_unlink() callback, before core_dev_del_lun()\nwaits for active se_lun references to drain.\n\nIf removal of the last LUN races a nexus removal, the latter can observe\na zero port count and call target_remove_session(). This frees\nsess_cmd_map while an in-flight struct usbg_cmd, including its work item,\ncan still be accessed.\n\nOverlapping the last-LUN unlink with nexus removal reproduces this\nlifetime violation as a DEBUG_OBJECTS \"free active\" warning for\nusbg_cmd_work, followed by a target-core BUG/Oops.\n\nThe generic target-core unlink path has no callback after\ncore_dev_del_lun() completes. Add an optional fabric_post_unlink()\ncallback and use it for the f_tcm port count. The count now remains\nnonzero until core_dev_del_lun() has finished draining active LUN\nreferences, preventing nexus removal from freeing the session during\ncommand completion."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T15:55:06.478Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c494c5562ca69b61a82f566e3b87a445d2c28929"
},
{
"url": "https://git.kernel.org/stable/c/c1f359d9a5efed458946063de65ddbeaacc4f165"
},
{
"url": "https://git.kernel.org/stable/c/178f59a0bccd3f66cdfa5184310f31a58b7257c4"
},
{
"url": "https://git.kernel.org/stable/c/ad6f0375d2e93a1d8c015463e5e92dfcb26e311b"
},
{
"url": "https://git.kernel.org/stable/c/2efbfd42441d3ef8137aff2d59e9835e1d5ae780"
},
{
"url": "https://git.kernel.org/stable/c/85aa61fedcb4eb13f3dc5db73f6dc359f41f5d95"
},
{
"url": "https://git.kernel.org/stable/c/bbd6aa311a9f4dd17822c7557451458d3d2e980b"
},
{
"url": "https://git.kernel.org/stable/c/eaa96a8458f54d6cf0954242ab8b1df2a6fccafa"
},
{
"url": "https://git.kernel.org/stable/c/c39d0916da47d94909391876c9e5bd429ea7b1b9"
}
],
"title": "usb: gadget: f_tcm: keep port count until LUN teardown completes",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80854",
"datePublished": "2026-09-04T15:55:06.478Z",
"dateReserved": "2026-08-26T14:34:25.797Z",
"dateUpdated": "2026-09-04T15:55:06.478Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80536 (GCVE-0-2026-80536)
Vulnerability from cvelistv5
Published
2026-08-26 14:37
Modified
2026-08-27 12:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
xfs: bounds-check buffer log item's dirty bitmap
xlog_recover_do_reg_buffer() replays each dirty region described by a
buffer log item's bitmap into the buffer read for that item:
memcpy(xfs_buf_offset(bp, (uint)bit << XFS_BLF_SHIFT),
item->ri_buf[i].iov_base,
nbits << XFS_BLF_SHIFT);
The destination offset (bit/nbits, from the logged dirty bitmap) and the
buffer size (from the logged blf_len) are both attacker-controlled and
otherwise unrelated, yet the only thing bounding the copy is an ASSERT(),
which compiles away on production kernels. A crafted image logging a
small blf_len together with a bitmap bit past the end of that buffer
drives the memcpy() past the buffer's allocation, corrupting adjacent
kernel heap during mount-time log recovery. This is reachable by anyone
who can get a crafted image mounted -- the malicious-filesystem threat
model XFS already guards against elsewhere.
Turn the ASSERT() into a real XFS_IS_CORRUPT() check that aborts recovery
of the buffer with -EFSCORRUPTED, consistent with the validate-and-fail
idiom already used in xlog_recover_do_inode_buffer() and
xfs_dquot_item_recover.c. xlog_recover_do_reg_buffer() therefore becomes
STATIC int and its three callers propagate the error.
Found and confirmed with KASAN on a CONFIG_XFS_DEBUG=n build: the crafted
image trips a slab-out-of-bounds write before this change and fails
recovery cleanly with -EFSCORRUPTED after it.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/xfs/xfs_buf_item_recover.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "acb4e26295e7f0e685815a3fd3d70bd8329cefa1",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "f3859c35a4fbc1c1c58431f684f808e43696891d",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "f7b5fa83e2c192be922121b764415fa8c7549ea1",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "b7528b42813f02724a78fce1da24d69d1bfc4d38",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "7e32d4eebae6ca24f8a673c107fd7eca1f47afc2",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "f8288214459ead7e87d26e5822f62c14a4f2ed6b",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "edaf5b6bd625356893da20d69a259b34a9de2694",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "813f8136a2ce1fee266d02a7df73db6e8a541604",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/xfs/xfs_buf_item_recover.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.267",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.218",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.185",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.154",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.106",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.267",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.218",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.185",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.154",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.106",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.46",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.10",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nxfs: bounds-check buffer log item\u0027s dirty bitmap\n\nxlog_recover_do_reg_buffer() replays each dirty region described by a\nbuffer log item\u0027s bitmap into the buffer read for that item:\n\n\tmemcpy(xfs_buf_offset(bp, (uint)bit \u003c\u003c XFS_BLF_SHIFT),\n\t\titem-\u003eri_buf[i].iov_base,\n\t\tnbits \u003c\u003c XFS_BLF_SHIFT);\n\nThe destination offset (bit/nbits, from the logged dirty bitmap) and the\nbuffer size (from the logged blf_len) are both attacker-controlled and\notherwise unrelated, yet the only thing bounding the copy is an ASSERT(),\nwhich compiles away on production kernels. A crafted image logging a\nsmall blf_len together with a bitmap bit past the end of that buffer\ndrives the memcpy() past the buffer\u0027s allocation, corrupting adjacent\nkernel heap during mount-time log recovery. This is reachable by anyone\nwho can get a crafted image mounted -- the malicious-filesystem threat\nmodel XFS already guards against elsewhere.\n\nTurn the ASSERT() into a real XFS_IS_CORRUPT() check that aborts recovery\nof the buffer with -EFSCORRUPTED, consistent with the validate-and-fail\nidiom already used in xlog_recover_do_inode_buffer() and\nxfs_dquot_item_recover.c. xlog_recover_do_reg_buffer() therefore becomes\nSTATIC int and its three callers propagate the error.\n\nFound and confirmed with KASAN on a CONFIG_XFS_DEBUG=n build: the crafted\nimage trips a slab-out-of-bounds write before this change and fails\nrecovery cleanly with -EFSCORRUPTED after it."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.4,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The OOB write is only reachable during XFS log recovery at mount time (mount\u2192xfs_mountfs\u2192xfs_log_mount\u2192xlog_recover\u2192xlog_do_recovery_pass pass2\u2192xlog_recover_buf_commit_pass2\u2192xlog_recover_do_reg_buffer); attacker data comes from a local block/loop device image, not from any network protocol handler.\nAC:L - All trigger fields (blf_len, blf_data_map bit/nbits, and logged source bytes in ri_buf) are attacker-authored on-disk log metadata; pairing a small blf_len with a bitmap region past the buffer end deterministically drives memcpy() past the xfs_buf allocation on every mount with no race or uncontrollable layout.\nPR:N - Mounting the crafted image requires no account or capability on the victim host in the malicious-filesystem threat model: an external attacker only supplies removable media or a disk image and desktop/kiosk udisks2 or systemd automount performs the privileged mount on device insertion without attacker credentials.\nUI:N - Once the crafted XFS volume is presented to the host, log recovery in xlog_recover_do_reg_buffer() runs automatically during mount (including read-only mounts) before any file access; the attacker needs no separate victim to open files, click links, or perform additional actions beyond presenting the image.\nS:U - Heap corruption occurs entirely within the mounting host kernel during log replay; impact is confined to the same kernel security authority and does not cross VM, IOMMU, or container sandbox boundaries.\nC:H - KASAN-confirmed slab-out-of-bounds write corrupts adjacent kernel heap objects; such controlled memory corruption is routinely weaponized for arbitrary kernel read primitives and pointer disclosure, not merely a crash.\nI:H - memcpy() writes attacker-controlled bytes from logged ri_buf regions to attacker-chosen offsets beyond the buffer end, giving a controllable out-of-bounds kernel heap write primitive suitable for control-flow hijacking and privilege escalation.\nA:H - The unchecked memcpy() causes slab-out-of-bounds writes during mount-time recovery (KASAN-verified on CONFIG_XFS_DEBUG=n), reliably corrupting kernel heap and capable of provoking kernel oops/panic or persistent denial of service on repeated mount attempts."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T12:40:04.524Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/acb4e26295e7f0e685815a3fd3d70bd8329cefa1"
},
{
"url": "https://git.kernel.org/stable/c/f3859c35a4fbc1c1c58431f684f808e43696891d"
},
{
"url": "https://git.kernel.org/stable/c/f7b5fa83e2c192be922121b764415fa8c7549ea1"
},
{
"url": "https://git.kernel.org/stable/c/b7528b42813f02724a78fce1da24d69d1bfc4d38"
},
{
"url": "https://git.kernel.org/stable/c/7e32d4eebae6ca24f8a673c107fd7eca1f47afc2"
},
{
"url": "https://git.kernel.org/stable/c/f8288214459ead7e87d26e5822f62c14a4f2ed6b"
},
{
"url": "https://git.kernel.org/stable/c/edaf5b6bd625356893da20d69a259b34a9de2694"
},
{
"url": "https://git.kernel.org/stable/c/813f8136a2ce1fee266d02a7df73db6e8a541604"
}
],
"title": "xfs: bounds-check buffer log item\u0027s dirty bitmap",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80536",
"datePublished": "2026-08-26T14:37:11.584Z",
"dateReserved": "2026-08-26T14:34:25.765Z",
"dateUpdated": "2026-08-27T12:40:04.524Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68397 (GCVE-0-2026-68397)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/iucv: take a reference on the socket found in afiucv_hs_rcv()
afiucv_hs_rcv() looks up the destination socket under iucv_sk_list.lock,
drops the lock, and then passes the socket to the afiucv_hs_callback_*()
handlers without holding a reference. AF_IUCV sockets are not
RCU-protected and are freed synchronously by iucv_sock_kill() ->
sock_put(), so a concurrent close can free the socket in the window
between read_unlock() and the handler, which then dereferences freed
memory (for example sk->sk_data_ready() in afiucv_hs_callback_syn()).
Take a reference with sock_hold() while the socket is still on the list
and release it with sock_put() once the handler has run.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 3881ac441f642d56503818123446f7298442236b Version: 3881ac441f642d56503818123446f7298442236b Version: 3881ac441f642d56503818123446f7298442236b Version: 3881ac441f642d56503818123446f7298442236b Version: 3881ac441f642d56503818123446f7298442236b Version: 3881ac441f642d56503818123446f7298442236b Version: 3881ac441f642d56503818123446f7298442236b Version: 3881ac441f642d56503818123446f7298442236b |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/iucv/af_iucv.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "5739be5c19495d709d902a2912c9102ce78740d5",
"status": "affected",
"version": "3881ac441f642d56503818123446f7298442236b",
"versionType": "git"
},
{
"lessThan": "bc6c6e546ffff8865daaeb622ef348c2d481e80f",
"status": "affected",
"version": "3881ac441f642d56503818123446f7298442236b",
"versionType": "git"
},
{
"lessThan": "e3e0679fc950191aff8f27fa78abcfc2462cff4a",
"status": "affected",
"version": "3881ac441f642d56503818123446f7298442236b",
"versionType": "git"
},
{
"lessThan": "4dc0e63abf8bc7ba8892e617c1fb8b204361e022",
"status": "affected",
"version": "3881ac441f642d56503818123446f7298442236b",
"versionType": "git"
},
{
"lessThan": "1801cb20a5025a787d6853e19c38db138344b4b4",
"status": "affected",
"version": "3881ac441f642d56503818123446f7298442236b",
"versionType": "git"
},
{
"lessThan": "c75a950e77356e526672cba4584080c6c8b793b6",
"status": "affected",
"version": "3881ac441f642d56503818123446f7298442236b",
"versionType": "git"
},
{
"lessThan": "5595ea59cdf29182cf6a270cacc1426c57b603de",
"status": "affected",
"version": "3881ac441f642d56503818123446f7298442236b",
"versionType": "git"
},
{
"lessThan": "4fa349156043dc119721d067329714179f501749",
"status": "affected",
"version": "3881ac441f642d56503818123446f7298442236b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/iucv/af_iucv.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.2"
},
{
"lessThan": "3.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/iucv: take a reference on the socket found in afiucv_hs_rcv()\n\nafiucv_hs_rcv() looks up the destination socket under iucv_sk_list.lock,\ndrops the lock, and then passes the socket to the afiucv_hs_callback_*()\nhandlers without holding a reference. AF_IUCV sockets are not\nRCU-protected and are freed synchronously by iucv_sock_kill() -\u003e\nsock_put(), so a concurrent close can free the socket in the window\nbetween read_unlock() and the handler, which then dereferences freed\nmemory (for example sk-\u003esk_data_ready() in afiucv_hs_callback_syn()).\n\nTake a reference with sock_hold() while the socket is still on the list\nand release it with sock_put() once the handler has run."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The vulnerable handler is registered via dev_add_pack() for ethertype ETH_P_AF_IUCV (0xFBFB) on every netdevice, so any peer LPAR/guest on the same HiperSockets internal LAN or any host on an attached Ethernet segment can drive afiucv_hs_rcv() with crafted frames; the frames are raw L2 and cannot be routed across an IP hop, so the vector is adjacent rather than network.\nAC:L - The attacker controls the packet side of the race outright (flooding 0xFBFB frames) and can drive the freeing side too, since SYN frames make a listener spawn and enqueue child sockets while FIN/SYN|FIN frames push sockets to IUCV_DISCONN and wake the application into close(), so the read_unlock()-to-handler window can be retried indefinitely until won.\nPR:N - afiucv_hs_rcv() runs from the netif RX softirq and processes any matching frame with no authentication, credential check, or capability test anywhere on the path; the attacker needs no account or privilege on the target s390 system.\nUI:N - No victim action is required: the attacker\u0027s own frames both create the AF_IUCV child sockets and trigger the state changes that lead to their teardown, and the packet handler runs unconditionally in softirq context.\nS:U - The freed struct sock and the resulting corruption stay inside the kernel of the affected LPAR or z/VM guest; no hypervisor, IOMMU, or container boundary is crossed.\nC:H - This is a use-after-free on a socket allocated from a generic kmalloc cache (iucv_proto is registered without its own slab), so an attacker who reclaims the object has the kernel read attacker-influenced or stale heap contents through sk fields, sk_filter()\u0027s BPF program pointer, and the iucv backlog queues, yielding kernel memory disclosure.\nI:H - After the free the handlers perform indirect calls through the freed object (sk-\u003esk_data_ready(), sk-\u003esk_state_change(), sk_filter()) and writes into it (sk_state, atomic_sub on iucv-\u003emsg_sent, skb_queue_tail() list-pointer updates), giving control-flow hijack and write primitives once the slab object is reclaimed with attacker-controlled data.\nA:H - Dereferencing the freed socket from softirq context reliably produces an oops or \"Fatal exception in interrupt\" panic, and the attacker can repeat the frame flood at will, causing complete loss of availability of the IBM Z LPAR or guest."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:47.433Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/5739be5c19495d709d902a2912c9102ce78740d5"
},
{
"url": "https://git.kernel.org/stable/c/bc6c6e546ffff8865daaeb622ef348c2d481e80f"
},
{
"url": "https://git.kernel.org/stable/c/e3e0679fc950191aff8f27fa78abcfc2462cff4a"
},
{
"url": "https://git.kernel.org/stable/c/4dc0e63abf8bc7ba8892e617c1fb8b204361e022"
},
{
"url": "https://git.kernel.org/stable/c/1801cb20a5025a787d6853e19c38db138344b4b4"
},
{
"url": "https://git.kernel.org/stable/c/c75a950e77356e526672cba4584080c6c8b793b6"
},
{
"url": "https://git.kernel.org/stable/c/5595ea59cdf29182cf6a270cacc1426c57b603de"
},
{
"url": "https://git.kernel.org/stable/c/4fa349156043dc119721d067329714179f501749"
}
],
"title": "net/iucv: take a reference on the socket found in afiucv_hs_rcv()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68397",
"datePublished": "2026-08-10T12:04:16.772Z",
"dateReserved": "2026-07-30T09:28:09.389Z",
"dateUpdated": "2026-08-19T16:34:47.433Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68365 (GCVE-0-2026-68365)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
USB: serial: io_edgeport: cap received transmit credits
The interrupt-status packet reports transmit credits returned by the
device. edge_interrupt_callback() adds the 16-bit value to txCredits
without checking maxTxCredits.
edge_write() uses txCredits minus the software FIFO count as the amount
of data that fits. Since the FIFO is allocated with maxTxCredits bytes,
txCredits exceeding maxTxCredits can cause OOB write in ring buffer.
Cap accumulated credits at maxTxCredits. Conforming devices should never
hit the cap.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/serial/io_edgeport.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "d9dd87bc1d7e8476d29d68883542ec6198d385c6",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "5b39d3da15344b87ef54a0a04f65b52622747e99",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "63c4e55d0741cfaf00515e807cad9293445cd348",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "ee57992c053a6d395e98ced2d4c9cc3b42d8c27a",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "64b687f9694777754285d489abbefa3784bc78da",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "cbe00048b69d67c8a78293cb7681b4c9963b26c7",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "1e47d8228b8767c8ac722aedb388f70adeeda43d",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "faaddd811c5099f11a5f52e68a6b31a5898cda4f",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/usb/serial/io_edgeport.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: serial: io_edgeport: cap received transmit credits\n\nThe interrupt-status packet reports transmit credits returned by the\ndevice. edge_interrupt_callback() adds the 16-bit value to txCredits\nwithout checking maxTxCredits.\n\nedge_write() uses txCredits minus the software FIFO count as the amount\nof data that fits. Since the FIFO is allocated with maxTxCredits bytes,\ntxCredits exceeding maxTxCredits can cause OOB write in ring buffer.\n\nCap accumulated credits at maxTxCredits. Conforming devices should never\nhit the cap."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:21.018Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/d9dd87bc1d7e8476d29d68883542ec6198d385c6"
},
{
"url": "https://git.kernel.org/stable/c/5b39d3da15344b87ef54a0a04f65b52622747e99"
},
{
"url": "https://git.kernel.org/stable/c/63c4e55d0741cfaf00515e807cad9293445cd348"
},
{
"url": "https://git.kernel.org/stable/c/ee57992c053a6d395e98ced2d4c9cc3b42d8c27a"
},
{
"url": "https://git.kernel.org/stable/c/64b687f9694777754285d489abbefa3784bc78da"
},
{
"url": "https://git.kernel.org/stable/c/cbe00048b69d67c8a78293cb7681b4c9963b26c7"
},
{
"url": "https://git.kernel.org/stable/c/1e47d8228b8767c8ac722aedb388f70adeeda43d"
},
{
"url": "https://git.kernel.org/stable/c/faaddd811c5099f11a5f52e68a6b31a5898cda4f"
}
],
"title": "USB: serial: io_edgeport: cap received transmit credits",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68365",
"datePublished": "2026-08-10T12:03:42.358Z",
"dateReserved": "2026-07-30T09:28:09.385Z",
"dateUpdated": "2026-08-19T16:34:21.018Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72012 (GCVE-0-2026-72012)
Vulnerability from cvelistv5
Published
2026-08-15 05:51
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
tracing/osnoise: Call synchronize_rcu() when unregistering
This ensures that any RCU readers traversing the instance list
have finished, before releasing the reference on the tracer that
the instance points to.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: a6ed2aee54644cfa2d04ca86308767f5c3a087e8 Version: a6ed2aee54644cfa2d04ca86308767f5c3a087e8 Version: a6ed2aee54644cfa2d04ca86308767f5c3a087e8 Version: a6ed2aee54644cfa2d04ca86308767f5c3a087e8 Version: a6ed2aee54644cfa2d04ca86308767f5c3a087e8 Version: a6ed2aee54644cfa2d04ca86308767f5c3a087e8 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"kernel/trace/trace_osnoise.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "428cedade9b2cc8e48f00742df0cfd770e77a803",
"status": "affected",
"version": "a6ed2aee54644cfa2d04ca86308767f5c3a087e8",
"versionType": "git"
},
{
"lessThan": "3c693635bb7b3a9b6645831a84fed2af46cdf249",
"status": "affected",
"version": "a6ed2aee54644cfa2d04ca86308767f5c3a087e8",
"versionType": "git"
},
{
"lessThan": "38366140dc8ee3568c7f0191d517e117963bd580",
"status": "affected",
"version": "a6ed2aee54644cfa2d04ca86308767f5c3a087e8",
"versionType": "git"
},
{
"lessThan": "fad36954b29592ce463254179c3043697678481f",
"status": "affected",
"version": "a6ed2aee54644cfa2d04ca86308767f5c3a087e8",
"versionType": "git"
},
{
"lessThan": "dd0160a0842337f12e7694d68b184050afc6d3a4",
"status": "affected",
"version": "a6ed2aee54644cfa2d04ca86308767f5c3a087e8",
"versionType": "git"
},
{
"lessThan": "fe58f457ad8d0a2bef4e053cfecca4b5cd266b1a",
"status": "affected",
"version": "a6ed2aee54644cfa2d04ca86308767f5c3a087e8",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"kernel/trace/trace_osnoise.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.17"
},
{
"lessThan": "5.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.17",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntracing/osnoise: Call synchronize_rcu() when unregistering\n\nThis ensures that any RCU readers traversing the instance list\nhave finished, before releasing the reference on the tracer that\nthe instance points to."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires writing tracefs (e.g. enabling osnoise/timerlat via current_tracer and deleting a tracing instance); there is no network, adjacent, or physical entry path to osnoise_unregister_instance().\nAC:L - An attacker who can configure tracing controls both teardown and sampling; deleting a trace instance while osnoise/timerlat is active races RCU readers that still dereference inst-\u003etr, and this race is reliably attacker-driven.\nPR:L - Triggering requires tracefs write access to configure/destroy tracing instances; this is not init-namespace root on every system (tracing group/remounted tracefs or CAP_SYS_ADMIN in a container with tracefs mounted suffices).\nUI:N - No victim interaction is required; exploitation is achieved entirely by the attacker\u0027s tracing configuration and concurrent instance teardown.\nS:U - The use-after-free corrupts kernel memory within the same kernel security domain; it does not cross VM, IOMMU, or sandbox boundaries by itself.\nC:H - Deferred kvfree_rcu_mightsleep() lets __remove_instance() free the trace_array while RCU readers in IRQ/NMI/timerlat paths still dereference inst-\u003etr, a classic UAF enabling arbitrary kernel memory disclosure.\nI:H - The dangling trace_array pointer can be leveraged for heap corruption and control-flow hijack; UAF of kernel heap objects is scored as high integrity impact even when the immediate failure mode is a crash.\nA:H - Concurrent access to a freed trace_array causes kernel oops/panic from RCU list walkers and buffer operations; UAF in interrupt context can crash or hang the system even without full exploitation."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:24.402Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/428cedade9b2cc8e48f00742df0cfd770e77a803"
},
{
"url": "https://git.kernel.org/stable/c/3c693635bb7b3a9b6645831a84fed2af46cdf249"
},
{
"url": "https://git.kernel.org/stable/c/38366140dc8ee3568c7f0191d517e117963bd580"
},
{
"url": "https://git.kernel.org/stable/c/fad36954b29592ce463254179c3043697678481f"
},
{
"url": "https://git.kernel.org/stable/c/dd0160a0842337f12e7694d68b184050afc6d3a4"
},
{
"url": "https://git.kernel.org/stable/c/fe58f457ad8d0a2bef4e053cfecca4b5cd266b1a"
}
],
"title": "tracing/osnoise: Call synchronize_rcu() when unregistering",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72012",
"datePublished": "2026-08-15T05:51:41.222Z",
"dateReserved": "2026-08-09T03:40:39.899Z",
"dateUpdated": "2026-08-23T12:46:24.402Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68212 (GCVE-0-2026-68212)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: saa7134: Fix a possible memory leak in saa7134_video_init1
In saa7134_video_init1(), the return value of the first
saa7134_pgtable_alloc() is not checked. If it fails, the function
continues as if successful, leaving the driver with an invalid page
table. Additionally, if vb2_queue_init() for the VBI queue fails after
the video queue page table has been allocated, the allocated memory is
not freed before returning. The second saa7134_pgtable_alloc() also
lacks a return value check. Errors occur during device probing before
the device is fully registered, the normal cleanup path in
saa7134_finidev() is not executed, leading to memory leaks and
potential use of uninitialized DMA resources.
Check the return value of both saa7134_pgtable_alloc() calls and
propagate errors. On failure of any later step, free allocated page
tables to avoid memory leaks. Ensure control handlers are also
released on error to prevent further resource leakage.
Found by code review.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: a00e68888d5d2b583b13d7d58204a27207af95fd Version: a00e68888d5d2b583b13d7d58204a27207af95fd Version: a00e68888d5d2b583b13d7d58204a27207af95fd Version: a00e68888d5d2b583b13d7d58204a27207af95fd Version: a00e68888d5d2b583b13d7d58204a27207af95fd Version: a00e68888d5d2b583b13d7d58204a27207af95fd Version: a00e68888d5d2b583b13d7d58204a27207af95fd Version: a00e68888d5d2b583b13d7d58204a27207af95fd |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/pci/saa7134/saa7134-video.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "e773b1d4bd191e7520bf9e02cb676d62c1b20556",
"status": "affected",
"version": "a00e68888d5d2b583b13d7d58204a27207af95fd",
"versionType": "git"
},
{
"lessThan": "44e16e3e022bf4a26adf03bc05a6dd5ffc34ef6d",
"status": "affected",
"version": "a00e68888d5d2b583b13d7d58204a27207af95fd",
"versionType": "git"
},
{
"lessThan": "34082a48376fd225a5c3d971c8962eb1320a54e0",
"status": "affected",
"version": "a00e68888d5d2b583b13d7d58204a27207af95fd",
"versionType": "git"
},
{
"lessThan": "134c979dd721e22f196d71026432ee37d1f5cc38",
"status": "affected",
"version": "a00e68888d5d2b583b13d7d58204a27207af95fd",
"versionType": "git"
},
{
"lessThan": "e1ef361ee31d1dba5dcae2cdd50f9c1352df0c23",
"status": "affected",
"version": "a00e68888d5d2b583b13d7d58204a27207af95fd",
"versionType": "git"
},
{
"lessThan": "b7936e8cbec1b96b126058eeb005e5b9111df38e",
"status": "affected",
"version": "a00e68888d5d2b583b13d7d58204a27207af95fd",
"versionType": "git"
},
{
"lessThan": "1731dd61b6c0b7435c139951d2b7eada6c9667a8",
"status": "affected",
"version": "a00e68888d5d2b583b13d7d58204a27207af95fd",
"versionType": "git"
},
{
"lessThan": "f86ed548386e3050e5f8f25b450d09dc009d9a88",
"status": "affected",
"version": "a00e68888d5d2b583b13d7d58204a27207af95fd",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/pci/saa7134/saa7134-video.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.16"
},
{
"lessThan": "3.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.16",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: saa7134: Fix a possible memory leak in saa7134_video_init1\n\nIn saa7134_video_init1(), the return value of the first\nsaa7134_pgtable_alloc() is not checked. If it fails, the function\ncontinues as if successful, leaving the driver with an invalid page\ntable. Additionally, if vb2_queue_init() for the VBI queue fails after\nthe video queue page table has been allocated, the allocated memory is\nnot freed before returning. The second saa7134_pgtable_alloc() also\nlacks a return value check. Errors occur during device probing before\nthe device is fully registered, the normal cleanup path in\nsaa7134_finidev() is not executed, leading to memory leaks and\npotential use of uninitialized DMA resources.\n\nCheck the return value of both saa7134_pgtable_alloc() calls and\npropagate errors. On failure of any later step, free allocated page\ntables to avoid memory leaks. Ensure control handlers are also\nreleased on error to prevent further resource leakage.\n\nFound by code review."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:37.074Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/e773b1d4bd191e7520bf9e02cb676d62c1b20556"
},
{
"url": "https://git.kernel.org/stable/c/44e16e3e022bf4a26adf03bc05a6dd5ffc34ef6d"
},
{
"url": "https://git.kernel.org/stable/c/34082a48376fd225a5c3d971c8962eb1320a54e0"
},
{
"url": "https://git.kernel.org/stable/c/134c979dd721e22f196d71026432ee37d1f5cc38"
},
{
"url": "https://git.kernel.org/stable/c/e1ef361ee31d1dba5dcae2cdd50f9c1352df0c23"
},
{
"url": "https://git.kernel.org/stable/c/b7936e8cbec1b96b126058eeb005e5b9111df38e"
},
{
"url": "https://git.kernel.org/stable/c/1731dd61b6c0b7435c139951d2b7eada6c9667a8"
},
{
"url": "https://git.kernel.org/stable/c/f86ed548386e3050e5f8f25b450d09dc009d9a88"
}
],
"title": "media: saa7134: Fix a possible memory leak in saa7134_video_init1",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68212",
"datePublished": "2026-08-10T12:00:31.498Z",
"dateReserved": "2026-07-30T09:28:09.375Z",
"dateUpdated": "2026-08-19T16:31:37.074Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74656 (GCVE-0-2026-74656)
Vulnerability from cvelistv5
Published
2026-08-22 15:32
Modified
2026-08-25 05:41
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ipv4: fix use-after-free in fib_nhc_update_mtu()
fib_nhc_update_mtu() walks the nexthop exception table under RTNL, but
RTNL does not serialize this walk with PMTU exception updates. The walk
uses rcu_dereference_protected() with a constant true condition without
holding fnhe_lock.
The following interleaving can therefore occur:
CPU 0 CPU 1
fib_nhc_update_mtu() update_or_create_fnhe()
load fnhe spin_lock_bh(&fnhe_lock)
fnhe_remove_oldest()
unlink fnhe
kfree_rcu(fnhe, rcu)
<quiescent state>
access fnhe after grace period
KASAN reported:
BUG: KASAN: slab-use-after-free in fib_nhc_update_mtu+0x3df/0x410
Read of size 8 at addr ffff888107d49000 by task poc/90
Call Trace:
fib_nhc_update_mtu+0x3df/0x410
fib_sync_mtu+0x7a/0xd0
fib_netdev_event+0x229/0x3f0
netif_set_mtu_ext+0x33a/0x570
dev_set_mtu+0x88/0x120
The same walk updates fnhe_pmtu and fnhe_mtu_locked. These fields form a
pair and other writers serialize them with fnhe_lock. RCU alone prevents
reclamation, but would still allow concurrent writers to leave a mixed
pair.
Walk the table under RCU and acquire fnhe_lock only while updating each
exception. RCU keeps the current entry alive while the short critical
section serializes its paired PMTU fields. This avoids holding the global
lock while scanning all 2048 buckets for every nexthop.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: af7d6cce53694a88d6a1bb60c9a239a6a5144459 Version: af7d6cce53694a88d6a1bb60c9a239a6a5144459 Version: af7d6cce53694a88d6a1bb60c9a239a6a5144459 Version: af7d6cce53694a88d6a1bb60c9a239a6a5144459 Version: af7d6cce53694a88d6a1bb60c9a239a6a5144459 Version: af7d6cce53694a88d6a1bb60c9a239a6a5144459 Version: af7d6cce53694a88d6a1bb60c9a239a6a5144459 Version: af7d6cce53694a88d6a1bb60c9a239a6a5144459 Version: b427832009b97a3ee412ef643a80b15372a7754d Version: 2b7e4c735933be79882aba2bed9afa789e03c62f Version: 8d59c3a6376bbc6dd3f7303968a719ffba75a4f1 Version: 9b4869cf385aa16f89c0f019eed4ec4e36aa441c Version: ff34695ced21e2dfa04d0fa1c5f6c35011fa8117 Version: 3.16.62 ≤ Version: 4.4.162 ≤ Version: 4.9.134 ≤ Version: 4.14.77 ≤ Version: 4.18.15 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"include/net/route.h",
"net/ipv4/fib_semantics.c",
"net/ipv4/route.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "fd39e711866498ae94fcf9acf6f422a4f045b681",
"status": "affected",
"version": "af7d6cce53694a88d6a1bb60c9a239a6a5144459",
"versionType": "git"
},
{
"lessThan": "e1e602d6b22d5cb1641c4459c487eb18bf569e0a",
"status": "affected",
"version": "af7d6cce53694a88d6a1bb60c9a239a6a5144459",
"versionType": "git"
},
{
"lessThan": "e00f7d2b5f2540a3415a229c982af7a25ff6362e",
"status": "affected",
"version": "af7d6cce53694a88d6a1bb60c9a239a6a5144459",
"versionType": "git"
},
{
"lessThan": "dfe388da13aa784851e5ebbea90afbb099075761",
"status": "affected",
"version": "af7d6cce53694a88d6a1bb60c9a239a6a5144459",
"versionType": "git"
},
{
"lessThan": "5a28a4b22dde92f9d293b94236314b8d6181dc4a",
"status": "affected",
"version": "af7d6cce53694a88d6a1bb60c9a239a6a5144459",
"versionType": "git"
},
{
"lessThan": "63996ffc594d128ccec8fc0983f91effd2d3adc4",
"status": "affected",
"version": "af7d6cce53694a88d6a1bb60c9a239a6a5144459",
"versionType": "git"
},
{
"lessThan": "ed503eaad62f20cdd5122d7c3078a648a99c8f16",
"status": "affected",
"version": "af7d6cce53694a88d6a1bb60c9a239a6a5144459",
"versionType": "git"
},
{
"lessThan": "bc5bde9ce3cc36502839dfe98e068f7303a50982",
"status": "affected",
"version": "af7d6cce53694a88d6a1bb60c9a239a6a5144459",
"versionType": "git"
},
{
"status": "affected",
"version": "b427832009b97a3ee412ef643a80b15372a7754d",
"versionType": "git"
},
{
"status": "affected",
"version": "2b7e4c735933be79882aba2bed9afa789e03c62f",
"versionType": "git"
},
{
"status": "affected",
"version": "8d59c3a6376bbc6dd3f7303968a719ffba75a4f1",
"versionType": "git"
},
{
"status": "affected",
"version": "9b4869cf385aa16f89c0f019eed4ec4e36aa441c",
"versionType": "git"
},
{
"status": "affected",
"version": "ff34695ced21e2dfa04d0fa1c5f6c35011fa8117",
"versionType": "git"
},
{
"lessThan": "3.17",
"status": "affected",
"version": "3.16.62",
"versionType": "semver"
},
{
"lessThan": "4.5",
"status": "affected",
"version": "4.4.162",
"versionType": "semver"
},
{
"lessThan": "4.10",
"status": "affected",
"version": "4.9.134",
"versionType": "semver"
},
{
"lessThan": "4.15",
"status": "affected",
"version": "4.14.77",
"versionType": "semver"
},
{
"lessThan": "4.19",
"status": "affected",
"version": "4.18.15",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"include/net/route.h",
"net/ipv4/fib_semantics.c",
"net/ipv4/route.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.19"
},
{
"lessThan": "4.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.16.62",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.4.162",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.9.134",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.14.77",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.18.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: fix use-after-free in fib_nhc_update_mtu()\n\nfib_nhc_update_mtu() walks the nexthop exception table under RTNL, but\nRTNL does not serialize this walk with PMTU exception updates. The walk\nuses rcu_dereference_protected() with a constant true condition without\nholding fnhe_lock.\n\nThe following interleaving can therefore occur:\n\n CPU 0 CPU 1\n fib_nhc_update_mtu() update_or_create_fnhe()\n load fnhe spin_lock_bh(\u0026fnhe_lock)\n fnhe_remove_oldest()\n unlink fnhe\n kfree_rcu(fnhe, rcu)\n \u003cquiescent state\u003e\n access fnhe after grace period\n\nKASAN reported:\n\n BUG: KASAN: slab-use-after-free in fib_nhc_update_mtu+0x3df/0x410\n Read of size 8 at addr ffff888107d49000 by task poc/90\n Call Trace:\n fib_nhc_update_mtu+0x3df/0x410\n fib_sync_mtu+0x7a/0xd0\n fib_netdev_event+0x229/0x3f0\n netif_set_mtu_ext+0x33a/0x570\n dev_set_mtu+0x88/0x120\n\nThe same walk updates fnhe_pmtu and fnhe_mtu_locked. These fields form a\npair and other writers serialize them with fnhe_lock. RCU alone prevents\nreclamation, but would still allow concurrent writers to leave a mixed\npair.\n\nWalk the table under RCU and acquire fnhe_lock only while updating each\nexception. RCU keeps the current entry alive while the short critical\nsection serializes its paired PMTU fields. This avoids holding the global\nlock while scanning all 2048 buckets for every nexthop."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The UAF is hit in fib_nhc_update_mtu(), entered only via NETDEV_CHANGEMTU from dev_set_mtu()/netif_set_mtu_ext() (SIOCSIFMTU or RTM_NEWLINK IFLA_MTU); per kernel CNA guidance this administrative netdev path is Local even though the racing update_or_create_fnhe() leg is driven by received ICMP PMTU packets.\nAC:L - KASAN reproduced this from task poc/90 by racing dev_set_mtu() against concurrent PMTU exception creation/eviction; an attacker controls both CPUs by running an MTU-change thread alongside ICMP or socket traffic that floods update_or_create_fnhe() and fnhe_remove_oldest(), without depending on uncontrollable victim state.\nPR:L - Changing interface MTU requires CAP_NET_ADMIN checked via ns_capable(net-\u003euser_ns, CAP_NET_ADMIN) on SIOCSIFMTU and RTM_SETLINK; unprivileged local users obtain this in a user+network namespace (unshare -Urn) and can then race MTU changes against PMTU exception updates on the same host.\nUI:N - Exploitation requires only the attacker\u0027s own MTU ioctl/netlink operations and concurrent network or socket traffic to populate/evict fib_nh_exception entries; no victim mount, click, or other voluntary action is needed beyond normal host networking.\nS:U - The slab use-after-free corrupts host kernel IPv4 routing state within the same kernel security authority; it is not a VM escape, IOMMU bypass, or other cross-boundary scope change.\nC:H - KASAN reported a slab use-after-free read of 8 bytes in fib_nhc_update_mtu() on a fib_nh_exception freed by kfree_rcu() from fnhe_remove_oldest(); UAF on this kmalloc object enables heap grooming for arbitrary kernel memory disclosure.\nI:H - The buggy walk both reads and writes fnhe_pmtu and fnhe_mtu_locked on potentially freed fib_nh_exception objects without fnhe_lock, providing standard slab reuse primitives for attacker-controlled kernel writes and potential control-flow hijack.\nA:H - The confirmed KASAN slab-use-after-free in fib_nhc_update_mtu() can immediately BUG/oops the kernel; the attacker can retrigger the race by repeating MTU toggles concurrent with PMTU exception flooding for persistent denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:41:13.058Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/fd39e711866498ae94fcf9acf6f422a4f045b681"
},
{
"url": "https://git.kernel.org/stable/c/e1e602d6b22d5cb1641c4459c487eb18bf569e0a"
},
{
"url": "https://git.kernel.org/stable/c/e00f7d2b5f2540a3415a229c982af7a25ff6362e"
},
{
"url": "https://git.kernel.org/stable/c/dfe388da13aa784851e5ebbea90afbb099075761"
},
{
"url": "https://git.kernel.org/stable/c/5a28a4b22dde92f9d293b94236314b8d6181dc4a"
},
{
"url": "https://git.kernel.org/stable/c/63996ffc594d128ccec8fc0983f91effd2d3adc4"
},
{
"url": "https://git.kernel.org/stable/c/ed503eaad62f20cdd5122d7c3078a648a99c8f16"
},
{
"url": "https://git.kernel.org/stable/c/bc5bde9ce3cc36502839dfe98e068f7303a50982"
}
],
"title": "ipv4: fix use-after-free in fib_nhc_update_mtu()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74656",
"datePublished": "2026-08-22T15:32:30.729Z",
"dateReserved": "2026-08-15T05:44:03.923Z",
"dateUpdated": "2026-08-25T05:41:13.058Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68213 (GCVE-0-2026-68213)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: rtl2832_sdr: Return queued buffers on start_streaming() failure
The vb2 framework hands buffers to the driver via buf_queue() before
calling start_streaming(). If start_streaming() returns an error
without first returning those buffers via vb2_buffer_done(),
vb2_start_streaming() fires WARN_ON(owned_by_drv_count) and the queued
buffers leak.
rtl2832_sdr_start_streaming() had multiple error paths that hit this
trap: two direct early returns (-ENODEV, -ERESTARTSYS), plus six
`goto err` paths covering subdev s_power, tuner setup, ADC setup,
stream-buffer allocation, urb allocation, and urb submission failures.
None of them returned the queued buffers.
The original function had no distinct success exit and fell straight
through into the err label, which previously only did mutex_unlock and
"return ret". Adding queued-buffer cleanup at err must therefore be
paired with an explicit success return; otherwise every successful
start would also drain the buffer queue and kill streaming. Add that
success return, then add rtl2832_sdr_cleanup_queued_bufs() at the err
label and before each early return.
The cleanup helper takes a vb2_buffer_state argument so that the
start_streaming error paths can pass VB2_BUF_STATE_QUEUED (as
expected by userspace on start_streaming failure) while stop_streaming
keeps its existing VB2_BUF_STATE_ERROR semantics.
This mirrors the uvcvideo fix in commit 4cf3b6fd54eb ("media: uvcvideo:
Return queued buffers on start_streaming() failure").
The err label still does not roll back power_ctrl(), frontend_ctrl(),
the POWER_ON flag, or stream/URB allocations that may have happened
before the failing step. Those are pre-existing leaks of a different
class and are not addressed here.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 771138920eafa399f68d3492c8a75dfeea23474b Version: 771138920eafa399f68d3492c8a75dfeea23474b Version: 771138920eafa399f68d3492c8a75dfeea23474b Version: 771138920eafa399f68d3492c8a75dfeea23474b Version: 771138920eafa399f68d3492c8a75dfeea23474b Version: 771138920eafa399f68d3492c8a75dfeea23474b Version: 771138920eafa399f68d3492c8a75dfeea23474b Version: 771138920eafa399f68d3492c8a75dfeea23474b |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/dvb-frontends/rtl2832_sdr.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "fd1e11fc3849169285e48b2d4ec441614ad2ea74",
"status": "affected",
"version": "771138920eafa399f68d3492c8a75dfeea23474b",
"versionType": "git"
},
{
"lessThan": "772f2550fe32357557d3b2f88e02f7cf477f0789",
"status": "affected",
"version": "771138920eafa399f68d3492c8a75dfeea23474b",
"versionType": "git"
},
{
"lessThan": "a248273f8af6e630a03e823274385725974009b5",
"status": "affected",
"version": "771138920eafa399f68d3492c8a75dfeea23474b",
"versionType": "git"
},
{
"lessThan": "465dc8e71d2db2ed603e749fa71392bcdccf07eb",
"status": "affected",
"version": "771138920eafa399f68d3492c8a75dfeea23474b",
"versionType": "git"
},
{
"lessThan": "0b08c0403cf672a121ace4eff647a9b240bd4e1b",
"status": "affected",
"version": "771138920eafa399f68d3492c8a75dfeea23474b",
"versionType": "git"
},
{
"lessThan": "894e83509c66910112b9eaeaa8cd66cd9806db91",
"status": "affected",
"version": "771138920eafa399f68d3492c8a75dfeea23474b",
"versionType": "git"
},
{
"lessThan": "fc0b18782aab4e35078efe72863df8eab46560a8",
"status": "affected",
"version": "771138920eafa399f68d3492c8a75dfeea23474b",
"versionType": "git"
},
{
"lessThan": "33ca0aab6f4bd90921fc1395478f38f72c4d19af",
"status": "affected",
"version": "771138920eafa399f68d3492c8a75dfeea23474b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/dvb-frontends/rtl2832_sdr.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.15"
},
{
"lessThan": "3.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: rtl2832_sdr: Return queued buffers on start_streaming() failure\n\nThe vb2 framework hands buffers to the driver via buf_queue() before\ncalling start_streaming(). If start_streaming() returns an error\nwithout first returning those buffers via vb2_buffer_done(),\nvb2_start_streaming() fires WARN_ON(owned_by_drv_count) and the queued\nbuffers leak.\n\nrtl2832_sdr_start_streaming() had multiple error paths that hit this\ntrap: two direct early returns (-ENODEV, -ERESTARTSYS), plus six\n`goto err` paths covering subdev s_power, tuner setup, ADC setup,\nstream-buffer allocation, urb allocation, and urb submission failures.\nNone of them returned the queued buffers.\n\nThe original function had no distinct success exit and fell straight\nthrough into the err label, which previously only did mutex_unlock and\n\"return ret\". Adding queued-buffer cleanup at err must therefore be\npaired with an explicit success return; otherwise every successful\nstart would also drain the buffer queue and kill streaming. Add that\nsuccess return, then add rtl2832_sdr_cleanup_queued_bufs() at the err\nlabel and before each early return.\n\nThe cleanup helper takes a vb2_buffer_state argument so that the\nstart_streaming error paths can pass VB2_BUF_STATE_QUEUED (as\nexpected by userspace on start_streaming failure) while stop_streaming\nkeeps its existing VB2_BUF_STATE_ERROR semantics.\n\nThis mirrors the uvcvideo fix in commit 4cf3b6fd54eb (\"media: uvcvideo:\nReturn queued buffers on start_streaming() failure\").\n\nThe err label still does not roll back power_ctrl(), frontend_ctrl(),\nthe POWER_ON flag, or stream/URB allocations that may have happened\nbefore the failing step. Those are pre-existing leaks of a different\nclass and are not addressed here."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Triggered entirely through ioctls on the V4L2 SDR device node /dev/swradio0 (VIDIOC_REQBUFS/QBUF/STREAMON); no network or physical interaction is required, since the failure path is reached via lock contention and signal delivery from local threads.\nAC:L - The attacker controls both sides: one thread holds dev-\u003ev4l2_lock via slow USB-backed ioctls while another calls STREAMON and a third signals it, forcing the -ERESTARTSYS path deterministically and retryably; no condition lies outside attacker influence.\nPR:L - Requires only an unprivileged local account with access to the SDR video node, which is customarily group-video readable/writable on desktop, embedded and Android-style deployments; no CAP_SYS_ADMIN or root is needed.\nUI:N - The full sequence (REQBUFS, QBUF, STREAMON, close, reopen) is performed by the attacker\u0027s own process; no victim action or cooperation is involved at any point.\nS:U - The corruption is confined to kernel heap objects owned by the same kernel security authority; no VM, IOMMU or sandbox boundary is crossed.\nC:H - The stale dev-\u003equeued_bufs entries point at freed vb2 buffer objects that the attacker can reclaim via heap spraying, and the URB completion handler dereferences them, yielding a use-after-free read primitive over kernel memory.\nI:H - A later buf_queue() performs list_add_tail() through the dangling list head, writing kernel pointers into freed, attacker-reclaimed memory, and vb2_buffer_done() operates on a forged buffer \u2014 a classic UAF write primitive usable for control-flow hijack.\nA:H - The immediate effect is WARN_ON(owned_by_drv_count) in vb2_start_streaming() (a panic under panic_on_warn) plus list corruption; the resulting use-after-free reliably oopses the kernel and can be repeated at will."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:39.730Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/fd1e11fc3849169285e48b2d4ec441614ad2ea74"
},
{
"url": "https://git.kernel.org/stable/c/772f2550fe32357557d3b2f88e02f7cf477f0789"
},
{
"url": "https://git.kernel.org/stable/c/a248273f8af6e630a03e823274385725974009b5"
},
{
"url": "https://git.kernel.org/stable/c/465dc8e71d2db2ed603e749fa71392bcdccf07eb"
},
{
"url": "https://git.kernel.org/stable/c/0b08c0403cf672a121ace4eff647a9b240bd4e1b"
},
{
"url": "https://git.kernel.org/stable/c/894e83509c66910112b9eaeaa8cd66cd9806db91"
},
{
"url": "https://git.kernel.org/stable/c/fc0b18782aab4e35078efe72863df8eab46560a8"
},
{
"url": "https://git.kernel.org/stable/c/33ca0aab6f4bd90921fc1395478f38f72c4d19af"
}
],
"title": "media: rtl2832_sdr: Return queued buffers on start_streaming() failure",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68213",
"datePublished": "2026-08-10T12:00:32.514Z",
"dateReserved": "2026-07-30T09:28:09.375Z",
"dateUpdated": "2026-08-19T16:31:39.730Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74487 (GCVE-0-2026-74487)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-23 12:47
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
binfmt_misc: restore write access when removing an entry
Registering an entry with the MISC_FMT_OPEN_FILE flag opens the
interpreter via open_exec() which denies write access to it for as
long as the entry exists. Removing the entry closes the interpreter
file via filp_close() but never restores write access, leaving the
inode's i_writecount permanently negative. Opening the interpreter
for writing keeps failing with ETXTBSY long after the entry is gone
until the inode is evicted from the inode cache.
Commit 90f601b497d7 ("binfmt_misc: restore write access before
closing files opened by open_exec()") fixed the same imbalance in the
error path of bm_register_write() but the actual removal path has
been leaking the write denial since the introduction of the flag.
Restore write access in put_binfmt_handler() before closing the
interpreter file.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 948b701a607f123df92ed29084413e5dd8cda2ed Version: 948b701a607f123df92ed29084413e5dd8cda2ed Version: 948b701a607f123df92ed29084413e5dd8cda2ed Version: 948b701a607f123df92ed29084413e5dd8cda2ed Version: 948b701a607f123df92ed29084413e5dd8cda2ed Version: 948b701a607f123df92ed29084413e5dd8cda2ed Version: 948b701a607f123df92ed29084413e5dd8cda2ed Version: 948b701a607f123df92ed29084413e5dd8cda2ed |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/binfmt_misc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "7873f987213695e3564c8c259e6db283e4739472",
"status": "affected",
"version": "948b701a607f123df92ed29084413e5dd8cda2ed",
"versionType": "git"
},
{
"lessThan": "13efc628fdf641d901bdba07caa1c558e1bed046",
"status": "affected",
"version": "948b701a607f123df92ed29084413e5dd8cda2ed",
"versionType": "git"
},
{
"lessThan": "f1cf67f6be0babc73afa4ee0e27bdedffeeeb095",
"status": "affected",
"version": "948b701a607f123df92ed29084413e5dd8cda2ed",
"versionType": "git"
},
{
"lessThan": "dd9ba32169e73a3c3ba595cf1de1f4c69ceafb3c",
"status": "affected",
"version": "948b701a607f123df92ed29084413e5dd8cda2ed",
"versionType": "git"
},
{
"lessThan": "a50296cca2a1db9d8d21051e7d50f0cf3a4b7ec8",
"status": "affected",
"version": "948b701a607f123df92ed29084413e5dd8cda2ed",
"versionType": "git"
},
{
"lessThan": "fdc1d702bf3001586221fa07e598e876a0a854c5",
"status": "affected",
"version": "948b701a607f123df92ed29084413e5dd8cda2ed",
"versionType": "git"
},
{
"lessThan": "3b522487a3a9162b1b519eefde7998d103e3e07b",
"status": "affected",
"version": "948b701a607f123df92ed29084413e5dd8cda2ed",
"versionType": "git"
},
{
"lessThan": "db1856ea9196cf6e015d12199a34c0b9313c7bfa",
"status": "affected",
"version": "948b701a607f123df92ed29084413e5dd8cda2ed",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/binfmt_misc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.8"
},
{
"lessThan": "4.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbinfmt_misc: restore write access when removing an entry\n\nRegistering an entry with the MISC_FMT_OPEN_FILE flag opens the\ninterpreter via open_exec() which denies write access to it for as\nlong as the entry exists. Removing the entry closes the interpreter\nfile via filp_close() but never restores write access, leaving the\ninode\u0027s i_writecount permanently negative. Opening the interpreter\nfor writing keeps failing with ETXTBSY long after the entry is gone\nuntil the inode is evicted from the inode cache.\n\nCommit 90f601b497d7 (\"binfmt_misc: restore write access before\nclosing files opened by open_exec()\") fixed the same imbalance in the\nerror path of bm_register_write() but the actual removal path has\nbeen leaking the write denial since the introduction of the flag.\n\nRestore write access in put_binfmt_handler() before closing the\ninterpreter file."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:47:26.657Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/7873f987213695e3564c8c259e6db283e4739472"
},
{
"url": "https://git.kernel.org/stable/c/13efc628fdf641d901bdba07caa1c558e1bed046"
},
{
"url": "https://git.kernel.org/stable/c/f1cf67f6be0babc73afa4ee0e27bdedffeeeb095"
},
{
"url": "https://git.kernel.org/stable/c/dd9ba32169e73a3c3ba595cf1de1f4c69ceafb3c"
},
{
"url": "https://git.kernel.org/stable/c/a50296cca2a1db9d8d21051e7d50f0cf3a4b7ec8"
},
{
"url": "https://git.kernel.org/stable/c/fdc1d702bf3001586221fa07e598e876a0a854c5"
},
{
"url": "https://git.kernel.org/stable/c/3b522487a3a9162b1b519eefde7998d103e3e07b"
},
{
"url": "https://git.kernel.org/stable/c/db1856ea9196cf6e015d12199a34c0b9313c7bfa"
}
],
"title": "binfmt_misc: restore write access when removing an entry",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74487",
"datePublished": "2026-08-15T12:27:18.236Z",
"dateReserved": "2026-08-15T05:44:03.905Z",
"dateUpdated": "2026-08-23T12:47:26.657Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80846 (GCVE-0-2026-80846)
Vulnerability from cvelistv5
Published
2026-09-04 15:54
Modified
2026-09-04 15:54
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
xfrm: drop ESP-in-TCP packets with no ingress device
ESP-in-TCP receives records through the TCP strparser. handle_esp()
restores skb->dev from the saved skb_iif before passing the packet into
the XFRM input path.
Queued TCP data can be processed after the original ingress device has
been removed, for example during veth or net namespace teardown. In that
case dev_get_by_index_rcu() returns NULL. The XFRM IPv4 and IPv6 input
paths both expect skb->dev to be valid while building the route lookup,
so queued ESP-in-TCP data can dereference a NULL device.
Drop the packet if the saved ingress device can no longer be resolved.
Such a packet can no longer be routed through the normal XFRM receive
path, and this preserves the existing behaviour for packets whose ingress
device still exists.
References
| URL | Tags | ||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: e27cca96cd68fa2c6814c90f9a1cfd36bb68c593 Version: e27cca96cd68fa2c6814c90f9a1cfd36bb68c593 Version: e27cca96cd68fa2c6814c90f9a1cfd36bb68c593 Version: e27cca96cd68fa2c6814c90f9a1cfd36bb68c593 Version: e27cca96cd68fa2c6814c90f9a1cfd36bb68c593 Version: e27cca96cd68fa2c6814c90f9a1cfd36bb68c593 Version: e27cca96cd68fa2c6814c90f9a1cfd36bb68c593 Version: e27cca96cd68fa2c6814c90f9a1cfd36bb68c593 Version: e27cca96cd68fa2c6814c90f9a1cfd36bb68c593 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/xfrm/espintcp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "239d0f71af09dc2029fd4d730cb24b8c83aaa43a",
"status": "affected",
"version": "e27cca96cd68fa2c6814c90f9a1cfd36bb68c593",
"versionType": "git"
},
{
"lessThan": "f00235f9d12301183d61f75fbe4105506f3e5140",
"status": "affected",
"version": "e27cca96cd68fa2c6814c90f9a1cfd36bb68c593",
"versionType": "git"
},
{
"lessThan": "6af5cdb03819a5ce6e945992635c6c5e91045367",
"status": "affected",
"version": "e27cca96cd68fa2c6814c90f9a1cfd36bb68c593",
"versionType": "git"
},
{
"lessThan": "2dd1609cadff46c4b20ce53b91ab9cce1380456a",
"status": "affected",
"version": "e27cca96cd68fa2c6814c90f9a1cfd36bb68c593",
"versionType": "git"
},
{
"lessThan": "c296d25efbc840be24de83f56d43bc47e714ace9",
"status": "affected",
"version": "e27cca96cd68fa2c6814c90f9a1cfd36bb68c593",
"versionType": "git"
},
{
"lessThan": "328e40aa774b446969c69b654c52a051a95af8a1",
"status": "affected",
"version": "e27cca96cd68fa2c6814c90f9a1cfd36bb68c593",
"versionType": "git"
},
{
"lessThan": "7911e0236616487b89db6bd3ba3f408abd10eb23",
"status": "affected",
"version": "e27cca96cd68fa2c6814c90f9a1cfd36bb68c593",
"versionType": "git"
},
{
"lessThan": "943d95233b8b4a88994e244fcf466f8c403d63f1",
"status": "affected",
"version": "e27cca96cd68fa2c6814c90f9a1cfd36bb68c593",
"versionType": "git"
},
{
"lessThan": "e1d7c5ac1c246ce5775f604515de0a59fbf2116e",
"status": "affected",
"version": "e27cca96cd68fa2c6814c90f9a1cfd36bb68c593",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/xfrm/espintcp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.6"
},
{
"lessThan": "5.6",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.269",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.220",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.187",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.156",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.108",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.49",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.13",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.3",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.269",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.220",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.187",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.156",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.108",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.49",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.13",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.3",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "5.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: drop ESP-in-TCP packets with no ingress device\n\nESP-in-TCP receives records through the TCP strparser. handle_esp()\nrestores skb-\u003edev from the saved skb_iif before passing the packet into\nthe XFRM input path.\n\nQueued TCP data can be processed after the original ingress device has\nbeen removed, for example during veth or net namespace teardown. In that\ncase dev_get_by_index_rcu() returns NULL. The XFRM IPv4 and IPv6 input\npaths both expect skb-\u003edev to be valid while building the route lookup,\nso queued ESP-in-TCP data can dereference a NULL device.\n\nDrop the packet if the saved ingress device can no longer be resolved.\nSuch a packet can no longer be routed through the normal XFRM receive\npath, and this preserves the existing behaviour for packets whose ingress\ndevice still exists."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T15:54:56.492Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/239d0f71af09dc2029fd4d730cb24b8c83aaa43a"
},
{
"url": "https://git.kernel.org/stable/c/f00235f9d12301183d61f75fbe4105506f3e5140"
},
{
"url": "https://git.kernel.org/stable/c/6af5cdb03819a5ce6e945992635c6c5e91045367"
},
{
"url": "https://git.kernel.org/stable/c/2dd1609cadff46c4b20ce53b91ab9cce1380456a"
},
{
"url": "https://git.kernel.org/stable/c/c296d25efbc840be24de83f56d43bc47e714ace9"
},
{
"url": "https://git.kernel.org/stable/c/328e40aa774b446969c69b654c52a051a95af8a1"
},
{
"url": "https://git.kernel.org/stable/c/7911e0236616487b89db6bd3ba3f408abd10eb23"
},
{
"url": "https://git.kernel.org/stable/c/943d95233b8b4a88994e244fcf466f8c403d63f1"
},
{
"url": "https://git.kernel.org/stable/c/e1d7c5ac1c246ce5775f604515de0a59fbf2116e"
}
],
"title": "xfrm: drop ESP-in-TCP packets with no ingress device",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80846",
"datePublished": "2026-09-04T15:54:56.492Z",
"dateReserved": "2026-08-26T14:34:25.797Z",
"dateUpdated": "2026-09-04T15:54:56.492Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68410 (GCVE-0-2026-68410)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-19 16:35
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: libertas: fix memory leak in helper_firmware_cb()
helper_firmware_cb() neglects to free the single-stage firmware image
after a successful async load, leading to a memory leak in the USB
firmware-download path.
Fix this memory leak by calling release_firmware() immediately after
lbs_fw_loaded() returns.
The bug was first flagged by an experimental analysis tool we are
developing for kernel memory-management bugs while analyzing
v6.13-rc1. The tool is still under development and is not yet publicly
available. Manual inspection confirms that the bug is still present in
the current wireless tree.
An x86_64 allyesconfig build showed no new warnings. As we do not have
compatible Libertas USB hardware for exercising this firmware-download
path, no runtime testing was able to be performed.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1dfba3060fe7ee03ccec25a91d35085142dfc295 Version: 1dfba3060fe7ee03ccec25a91d35085142dfc295 Version: 1dfba3060fe7ee03ccec25a91d35085142dfc295 Version: 1dfba3060fe7ee03ccec25a91d35085142dfc295 Version: 1dfba3060fe7ee03ccec25a91d35085142dfc295 Version: 1dfba3060fe7ee03ccec25a91d35085142dfc295 Version: 1dfba3060fe7ee03ccec25a91d35085142dfc295 Version: 1dfba3060fe7ee03ccec25a91d35085142dfc295 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/marvell/libertas/firmware.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "6c1f54a04813676c5a2150d99331c8d21f199374",
"status": "affected",
"version": "1dfba3060fe7ee03ccec25a91d35085142dfc295",
"versionType": "git"
},
{
"lessThan": "7f28722b3e4e0c8d49c859fea4a9b1fa13b5ae06",
"status": "affected",
"version": "1dfba3060fe7ee03ccec25a91d35085142dfc295",
"versionType": "git"
},
{
"lessThan": "ce829286f4935f1eb6b5dcb64da02910ce149c76",
"status": "affected",
"version": "1dfba3060fe7ee03ccec25a91d35085142dfc295",
"versionType": "git"
},
{
"lessThan": "d497b7566e74920acfe283dd6b2cbf1682890796",
"status": "affected",
"version": "1dfba3060fe7ee03ccec25a91d35085142dfc295",
"versionType": "git"
},
{
"lessThan": "eaeb1d74a47fc4864f2c754c0b9d654a9b7dc55c",
"status": "affected",
"version": "1dfba3060fe7ee03ccec25a91d35085142dfc295",
"versionType": "git"
},
{
"lessThan": "6cda91bbb8dc3d22ef0323008a12dcf73a5129da",
"status": "affected",
"version": "1dfba3060fe7ee03ccec25a91d35085142dfc295",
"versionType": "git"
},
{
"lessThan": "644640cde2fb216e6567de5eee780a38dbc95928",
"status": "affected",
"version": "1dfba3060fe7ee03ccec25a91d35085142dfc295",
"versionType": "git"
},
{
"lessThan": "63c2391deefb31e1b801b7f32bd502ca4808639b",
"status": "affected",
"version": "1dfba3060fe7ee03ccec25a91d35085142dfc295",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/marvell/libertas/firmware.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.13"
},
{
"lessThan": "3.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: libertas: fix memory leak in helper_firmware_cb()\n\nhelper_firmware_cb() neglects to free the single-stage firmware image\nafter a successful async load, leading to a memory leak in the USB\nfirmware-download path.\n\nFix this memory leak by calling release_firmware() immediately after\nlbs_fw_loaded() returns.\n\nThe bug was first flagged by an experimental analysis tool we are\ndeveloping for kernel memory-management bugs while analyzing\nv6.13-rc1. The tool is still under development and is not yet publicly\navailable. Manual inspection confirms that the bug is still present in\nthe current wireless tree.\n\nAn x86_64 allyesconfig build showed no new warnings. As we do not have\ncompatible Libertas USB hardware for exercising this firmware-download\npath, no runtime testing was able to be performed."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:35:04.634Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/6c1f54a04813676c5a2150d99331c8d21f199374"
},
{
"url": "https://git.kernel.org/stable/c/7f28722b3e4e0c8d49c859fea4a9b1fa13b5ae06"
},
{
"url": "https://git.kernel.org/stable/c/ce829286f4935f1eb6b5dcb64da02910ce149c76"
},
{
"url": "https://git.kernel.org/stable/c/d497b7566e74920acfe283dd6b2cbf1682890796"
},
{
"url": "https://git.kernel.org/stable/c/eaeb1d74a47fc4864f2c754c0b9d654a9b7dc55c"
},
{
"url": "https://git.kernel.org/stable/c/6cda91bbb8dc3d22ef0323008a12dcf73a5129da"
},
{
"url": "https://git.kernel.org/stable/c/644640cde2fb216e6567de5eee780a38dbc95928"
},
{
"url": "https://git.kernel.org/stable/c/63c2391deefb31e1b801b7f32bd502ca4808639b"
}
],
"title": "wifi: libertas: fix memory leak in helper_firmware_cb()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68410",
"datePublished": "2026-08-10T12:04:30.194Z",
"dateReserved": "2026-07-30T09:28:09.390Z",
"dateUpdated": "2026-08-19T16:35:04.634Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68452 (GCVE-0-2026-68452)
Vulnerability from cvelistv5
Published
2026-08-13 13:59
Modified
2026-08-19 16:35
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
s390/zcrypt: Validate length for CCA AES cipher key requests
cca_cipher2protkey() derives the copy length for the CPRB parameter
block directly from the length field in the key token. Reject the
request early if the token length exceeds the available space in the
parameter block.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 4bc123b18ce6ae6c42c69d0456b5acbd2f7bc8bd Version: 4bc123b18ce6ae6c42c69d0456b5acbd2f7bc8bd Version: 4bc123b18ce6ae6c42c69d0456b5acbd2f7bc8bd Version: 4bc123b18ce6ae6c42c69d0456b5acbd2f7bc8bd Version: 4bc123b18ce6ae6c42c69d0456b5acbd2f7bc8bd Version: 4bc123b18ce6ae6c42c69d0456b5acbd2f7bc8bd Version: 4bc123b18ce6ae6c42c69d0456b5acbd2f7bc8bd Version: 4bc123b18ce6ae6c42c69d0456b5acbd2f7bc8bd |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/s390/crypto/zcrypt_ccamisc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "be037204e4f595e4bd2159acda146677a1dc6342",
"status": "affected",
"version": "4bc123b18ce6ae6c42c69d0456b5acbd2f7bc8bd",
"versionType": "git"
},
{
"lessThan": "4e500ecb6704d879f9c2417c2ed6faba595015ca",
"status": "affected",
"version": "4bc123b18ce6ae6c42c69d0456b5acbd2f7bc8bd",
"versionType": "git"
},
{
"lessThan": "7f9e5a3dbb14a9b321a1dfa30390402c673f82dc",
"status": "affected",
"version": "4bc123b18ce6ae6c42c69d0456b5acbd2f7bc8bd",
"versionType": "git"
},
{
"lessThan": "406b317ea2b501f6f5eca1264293c9399a73a778",
"status": "affected",
"version": "4bc123b18ce6ae6c42c69d0456b5acbd2f7bc8bd",
"versionType": "git"
},
{
"lessThan": "4fc46deceda076d429ef3fab2ccf8d96629ebd23",
"status": "affected",
"version": "4bc123b18ce6ae6c42c69d0456b5acbd2f7bc8bd",
"versionType": "git"
},
{
"lessThan": "ad93a1f1a45652478c0cf4eb029114e03af57f3b",
"status": "affected",
"version": "4bc123b18ce6ae6c42c69d0456b5acbd2f7bc8bd",
"versionType": "git"
},
{
"lessThan": "3859f630b674801a00bca39bc451f52288591f65",
"status": "affected",
"version": "4bc123b18ce6ae6c42c69d0456b5acbd2f7bc8bd",
"versionType": "git"
},
{
"lessThan": "06afe425d5283b9764303de47f554da5a808ce8a",
"status": "affected",
"version": "4bc123b18ce6ae6c42c69d0456b5acbd2f7bc8bd",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/s390/crypto/zcrypt_ccamisc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.4"
},
{
"lessThan": "5.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/zcrypt: Validate length for CCA AES cipher key requests\n\ncca_cipher2protkey() derives the copy length for the CPRB parameter\nblock directly from the length field in the key token. Reject the\nrequest early if the token length exceeds the available space in the\nparameter block."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached through an ioctl (PKEY_KBLOB2PROTK2/3) on the /dev/pkey character device, requiring local access to the s390 system; there is no remote or adjacent-network path to cca_cipher2protkey().\nAC:L - The overflow is fully deterministic: the attacker sets the token\u0027s len field to any value up to the 8192-byte ioctl limit and the memcpy into the 512-byte parameter block happens unconditionally, before any crypto card interaction, with no race or unknown state involved.\nPR:L - The pkey misc device is registered with .mode = 0666 and neither pkey_api.c, pkey_base.c nor pkey_cca.c performs any capable()/CAP_* check, so any unprivileged local user can open it and issue the key-to-protkey ioctl.\nUI:N - The attacker triggers the overflow entirely on its own by issuing the ioctl with a crafted CCA AES cipher key token; no victim action or cooperation is needed.\nS:U - The heap corruption occurs in kernel slab memory managed by the same kernel security authority as the calling process; no VM, IOMMU or sandbox boundary is crossed.\nC:H - The controlled slab overflow (up to ~7.6 KB past a kmalloc-2k object) lets the attacker overwrite adjacent kernel objects, and the corrupted CPRB/reply buffer is subsequently parsed and partially copied back to userspace, giving a path to disclosing arbitrary kernel memory.\nI:H - memcpy() writes attacker-chosen token bytes far beyond the 512-byte parameter block, an out-of-bounds heap write with attacker-controlled length and contents, which is a classic primitive for corrupting neighbouring slab objects and hijacking control flow.\nA:H - Overwriting several kilobytes of adjacent slab memory reliably corrupts unrelated kernel objects and slab metadata, causing oopses or a panic; the ioctl can be repeated at will by any local user."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:35:50.661Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/be037204e4f595e4bd2159acda146677a1dc6342"
},
{
"url": "https://git.kernel.org/stable/c/4e500ecb6704d879f9c2417c2ed6faba595015ca"
},
{
"url": "https://git.kernel.org/stable/c/7f9e5a3dbb14a9b321a1dfa30390402c673f82dc"
},
{
"url": "https://git.kernel.org/stable/c/406b317ea2b501f6f5eca1264293c9399a73a778"
},
{
"url": "https://git.kernel.org/stable/c/4fc46deceda076d429ef3fab2ccf8d96629ebd23"
},
{
"url": "https://git.kernel.org/stable/c/ad93a1f1a45652478c0cf4eb029114e03af57f3b"
},
{
"url": "https://git.kernel.org/stable/c/3859f630b674801a00bca39bc451f52288591f65"
},
{
"url": "https://git.kernel.org/stable/c/06afe425d5283b9764303de47f554da5a808ce8a"
}
],
"title": "s390/zcrypt: Validate length for CCA AES cipher key requests",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68452",
"datePublished": "2026-08-13T13:59:54.840Z",
"dateReserved": "2026-07-30T09:28:09.395Z",
"dateUpdated": "2026-08-19T16:35:50.661Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68373 (GCVE-0-2026-68373)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: at76c50x-usb: avoid length underflow in at76_guess_freq()
at76_guess_freq() checks only that the received frame is at least a bare
802.11 header (24 bytes) before subtracting the fixed management-body
offset:
len -= el_off;
For both beacon and probe response frames, el_off is 36. If the frame is
shorter than el_off, subtracting it causes the calculated IE length to
wrap. The length is eventually passed to cfg80211_find_elem_match() as a
very large unsigned value, so the element walk runs beyond the RX skb.
This path is reached from at76_rx_tasklet() while scanning. If the device
delivers a truncated beacon or probe response, the oversized IE length
causes an out-of-bounds read during scanning.
Skip the IE lookup if the frame does not reach the variable elements,
before subtracting el_off.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1264b951463a00efebe1bb596499aaad620ec8af Version: 1264b951463a00efebe1bb596499aaad620ec8af Version: 1264b951463a00efebe1bb596499aaad620ec8af Version: 1264b951463a00efebe1bb596499aaad620ec8af Version: 1264b951463a00efebe1bb596499aaad620ec8af Version: 1264b951463a00efebe1bb596499aaad620ec8af Version: 1264b951463a00efebe1bb596499aaad620ec8af Version: 1264b951463a00efebe1bb596499aaad620ec8af |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/atmel/at76c50x-usb.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "cb831aff2f850f72bc5ff5ad77d0a70bb5a84061",
"status": "affected",
"version": "1264b951463a00efebe1bb596499aaad620ec8af",
"versionType": "git"
},
{
"lessThan": "4875680d1703f56afa6257ba30244f2fb44ed205",
"status": "affected",
"version": "1264b951463a00efebe1bb596499aaad620ec8af",
"versionType": "git"
},
{
"lessThan": "b406f33d234f98c8b310fdab5cbb492d85e98e49",
"status": "affected",
"version": "1264b951463a00efebe1bb596499aaad620ec8af",
"versionType": "git"
},
{
"lessThan": "e165a1d295e7e814e13b0f92c86e5d48309509ce",
"status": "affected",
"version": "1264b951463a00efebe1bb596499aaad620ec8af",
"versionType": "git"
},
{
"lessThan": "bcde7249d45f52f994a9872bedf45994472ade77",
"status": "affected",
"version": "1264b951463a00efebe1bb596499aaad620ec8af",
"versionType": "git"
},
{
"lessThan": "fb1b50ab699211e777dca5ccfb648788b6a6e519",
"status": "affected",
"version": "1264b951463a00efebe1bb596499aaad620ec8af",
"versionType": "git"
},
{
"lessThan": "f742d9c98b5c504fc9e6744eef13a721c2aea486",
"status": "affected",
"version": "1264b951463a00efebe1bb596499aaad620ec8af",
"versionType": "git"
},
{
"lessThan": "61a799ffd1e5a4fd3702d547828b7ff3d161468e",
"status": "affected",
"version": "1264b951463a00efebe1bb596499aaad620ec8af",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/atmel/at76c50x-usb.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.30"
},
{
"lessThan": "2.6.30",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.30",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: at76c50x-usb: avoid length underflow in at76_guess_freq()\n\nat76_guess_freq() checks only that the received frame is at least a bare\n802.11 header (24 bytes) before subtracting the fixed management-body\noffset:\n\n\tlen -= el_off;\n\nFor both beacon and probe response frames, el_off is 36. If the frame is\nshorter than el_off, subtracting it causes the calculated IE length to\nwrap. The length is eventually passed to cfg80211_find_elem_match() as a\nvery large unsigned value, so the element walk runs beyond the RX skb.\n\nThis path is reached from at76_rx_tasklet() while scanning. If the device\ndelivers a truncated beacon or probe response, the oversized IE length\ncauses an out-of-bounds read during scanning.\n\nSkip the IE lookup if the frame does not reach the variable elements,\nbefore subtracting el_off."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The malformed frame is an over-the-air 802.11 beacon or probe response received by the at76c50x USB WLAN dongle and parsed in at76_rx_tasklet(); an attacker only needs to be within radio range of the victim, which is the adjacent-network (WiFi frame injection) case.\nAC:L - The attacker simply transmits a beacon/probe response whose body is shorter than the 36-byte fixed management offset with a valid FCS, and can repeat it continuously or answer the victim\u0027s probe requests during the routine scans that set priv-\u003escanning, so triggering is reliable and fully attacker-timed.\nPR:N - No authentication, association, or any local privilege is required; the frame is parsed during scanning before any association or key exchange, so an entirely unauthenticated radio-range attacker reaches the bug.\nUI:N - Background and periodic scans are issued automatically by wpa_supplicant/NetworkManager without any user action, so no victim interaction is needed for the vulnerable path to run.\nS:U - The out-of-bounds read stays within the kernel\u0027s own memory and security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - The underflowed length becomes ~4GB when widened to unsigned int, so the element walk reads far past the ~2.5KB RX skb slab object, and the out-of-bounds byte taken as el[2] is turned into rx_status.freq that userspace observes in scan results, allowing repeated frames to leak adjacent kernel heap contents.\nI:N - The defect is purely a read overrun; nothing outside the skb is written and the only attacker-influenced value is the reported channel/frequency, giving no memory-corruption or control-flow primitive.\nA:H - The unbounded element walk runs off the slab and can dereference unmapped memory while executing in tasklet/softirq context, producing a kernel oops or panic that the attacker can trigger repeatedly with injected frames."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:33.308Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/cb831aff2f850f72bc5ff5ad77d0a70bb5a84061"
},
{
"url": "https://git.kernel.org/stable/c/4875680d1703f56afa6257ba30244f2fb44ed205"
},
{
"url": "https://git.kernel.org/stable/c/b406f33d234f98c8b310fdab5cbb492d85e98e49"
},
{
"url": "https://git.kernel.org/stable/c/e165a1d295e7e814e13b0f92c86e5d48309509ce"
},
{
"url": "https://git.kernel.org/stable/c/bcde7249d45f52f994a9872bedf45994472ade77"
},
{
"url": "https://git.kernel.org/stable/c/fb1b50ab699211e777dca5ccfb648788b6a6e519"
},
{
"url": "https://git.kernel.org/stable/c/f742d9c98b5c504fc9e6744eef13a721c2aea486"
},
{
"url": "https://git.kernel.org/stable/c/61a799ffd1e5a4fd3702d547828b7ff3d161468e"
}
],
"title": "wifi: at76c50x-usb: avoid length underflow in at76_guess_freq()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68373",
"datePublished": "2026-08-10T12:03:51.663Z",
"dateReserved": "2026-07-30T09:28:09.386Z",
"dateUpdated": "2026-08-19T16:34:33.308Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74691 (GCVE-0-2026-74691)
Vulnerability from cvelistv5
Published
2026-08-22 15:32
Modified
2026-08-25 05:41
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: thunderbolt: Tear down DMA paths before stopping the rings
tbnet_tear_down() stops both rings and frees their frame buffers before
calling tb_xdomain_disable_paths(). tb_ring_stop() zeroes the ring's
descriptor base and tbnet_free_buffers() unmaps and frees the pages the
frames sit in, so by the time __tb_path_deactivate_hop() polls the hop's
'pending' bit, anything still in flight has nowhere to drain to.
The teardown sequence has been in this order since the driver was added.
The setup path has not: commit ff7cd07f3064 ("net: thunderbolt: Enable
DMA paths only after rings are enabled") moved the path enable to the end
of tbnet_connected_work() and documented why:
/* Both logins successful so enable the rings, high-speed DMA
* paths and start the network device queue.
*
* Note we enable the DMA paths last to make sure we have primed
* the Rx ring before any incoming packets are allowed to
* arrive.
*/
Teardown was never updated to match, so the rings and the paths now come
down in the same order they go up instead of in reverse.
On an ASMedia ASM4242 host router the 'pending' bit then never clears:
every teardown burns the full 500 ms timeout and
__tb_path_deactivate_hop() returns -ETIMEDOUT. Raising the timeout to
5 s does not help, so the hop is not slow to drain, it never drains
at all.
The failure is invisible above the thunderbolt core.
__tb_path_deactivate_hops() is void and only calls tb_port_warn();
tb_path_deactivate(), tb_tunnel_deactivate() and
__tb_disconnect_xdomain_paths() are void as well, and
tb_disconnect_xdomain_paths() ends in an unconditional "return 0". So
tb_xdomain_disable_paths() reports success and the netdev_warn() below
it never fires. Repeated teardowns eventually take the XDomain control
channel down, after which the peer node is gone and only a power cycle
brings the controller back.
Deactivating the paths first fixes it. Measured with kretprobes on a
stock v6.17 tree with no other patches applied, on a link that was up
and had just carried traffic:
before: __tb_path_deactivate_hop() returns 0 for the first hop, then
-ETIMEDOUT for the second 500335 us later
after: 0 for both, 525 us apart
Alternating the two orderings ABBA over three load levels, four
teardowns per arm: every teardown failed before the change (21 of 21
that ran), none failed after (0 of 24). The before arms ran short
because the link died partway through. The same split shows up when
the interface is enslaved to a bond instead of just brought down, which
is how I ran into this in the first place. Throughput and latency after
the change are unchanged.
Hosts whose routers drain the hop despite the stale descriptor base see
no functional difference, since the paths end up deactivated either way.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: e69b6c02b4c3b8d03be7136f90dd9551ad5a5a5e Version: e69b6c02b4c3b8d03be7136f90dd9551ad5a5a5e Version: e69b6c02b4c3b8d03be7136f90dd9551ad5a5a5e Version: e69b6c02b4c3b8d03be7136f90dd9551ad5a5a5e Version: e69b6c02b4c3b8d03be7136f90dd9551ad5a5a5e Version: e69b6c02b4c3b8d03be7136f90dd9551ad5a5a5e Version: e69b6c02b4c3b8d03be7136f90dd9551ad5a5a5e |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/thunderbolt/main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "7cce39109206bc5497e0953806563644b88bfc44",
"status": "affected",
"version": "e69b6c02b4c3b8d03be7136f90dd9551ad5a5a5e",
"versionType": "git"
},
{
"lessThan": "0da9a6d27155ad072dd76db8cd637feead99a0e0",
"status": "affected",
"version": "e69b6c02b4c3b8d03be7136f90dd9551ad5a5a5e",
"versionType": "git"
},
{
"lessThan": "b5a21615f627c48dafaa6ef82a34a5b97a4352aa",
"status": "affected",
"version": "e69b6c02b4c3b8d03be7136f90dd9551ad5a5a5e",
"versionType": "git"
},
{
"lessThan": "103a9b663ac1cacb8465aeff18f84a247154a562",
"status": "affected",
"version": "e69b6c02b4c3b8d03be7136f90dd9551ad5a5a5e",
"versionType": "git"
},
{
"lessThan": "4dd71cb0d23d40cb58fe4261c7bd183dca66caa0",
"status": "affected",
"version": "e69b6c02b4c3b8d03be7136f90dd9551ad5a5a5e",
"versionType": "git"
},
{
"lessThan": "9a482b2b117e5fa656b6d24fc01799e8ac2d4368",
"status": "affected",
"version": "e69b6c02b4c3b8d03be7136f90dd9551ad5a5a5e",
"versionType": "git"
},
{
"lessThan": "68bf02b6b4ad3f748c6db71fd77b6c0402d252f4",
"status": "affected",
"version": "e69b6c02b4c3b8d03be7136f90dd9551ad5a5a5e",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/thunderbolt/main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.15"
},
{
"lessThan": "4.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: thunderbolt: Tear down DMA paths before stopping the rings\n\ntbnet_tear_down() stops both rings and frees their frame buffers before\ncalling tb_xdomain_disable_paths(). tb_ring_stop() zeroes the ring\u0027s\ndescriptor base and tbnet_free_buffers() unmaps and frees the pages the\nframes sit in, so by the time __tb_path_deactivate_hop() polls the hop\u0027s\n\u0027pending\u0027 bit, anything still in flight has nowhere to drain to.\n\nThe teardown sequence has been in this order since the driver was added.\nThe setup path has not: commit ff7cd07f3064 (\"net: thunderbolt: Enable\nDMA paths only after rings are enabled\") moved the path enable to the end\nof tbnet_connected_work() and documented why:\n\n\t/* Both logins successful so enable the rings, high-speed DMA\n\t * paths and start the network device queue.\n\t *\n\t * Note we enable the DMA paths last to make sure we have primed\n\t * the Rx ring before any incoming packets are allowed to\n\t * arrive.\n\t */\n\nTeardown was never updated to match, so the rings and the paths now come\ndown in the same order they go up instead of in reverse.\n\nOn an ASMedia ASM4242 host router the \u0027pending\u0027 bit then never clears:\nevery teardown burns the full 500 ms timeout and\n__tb_path_deactivate_hop() returns -ETIMEDOUT. Raising the timeout to\n5 s does not help, so the hop is not slow to drain, it never drains\nat all.\n\nThe failure is invisible above the thunderbolt core.\n__tb_path_deactivate_hops() is void and only calls tb_port_warn();\ntb_path_deactivate(), tb_tunnel_deactivate() and\n__tb_disconnect_xdomain_paths() are void as well, and\ntb_disconnect_xdomain_paths() ends in an unconditional \"return 0\". So\ntb_xdomain_disable_paths() reports success and the netdev_warn() below\nit never fires. Repeated teardowns eventually take the XDomain control\nchannel down, after which the peer node is gone and only a power cycle\nbrings the controller back.\n\nDeactivating the paths first fixes it. Measured with kretprobes on a\nstock v6.17 tree with no other patches applied, on a link that was up\nand had just carried traffic:\n\n before: __tb_path_deactivate_hop() returns 0 for the first hop, then\n -ETIMEDOUT for the second 500335 us later\n after: 0 for both, 525 us apart\n\nAlternating the two orderings ABBA over three load levels, four\nteardowns per arm: every teardown failed before the change (21 of 21\nthat ran), none failed after (0 of 24). The before arms ran short\nbecause the link died partway through. The same split shows up when\nthe interface is enslaved to a bond instead of just brought down, which\nis how I ran into this in the first place. Throughput and latency after\nthe change are unchanged.\n\nHosts whose routers drain the hop despite the stale descriptor base see\nno functional difference, since the paths end up deactivated either way."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The bug is reached when tbnet_tear_down() runs during ThunderboltIP session teardown; a malicious peer on the same direct Thunderbolt/USB4 link can send TBIP_LOGOUT over XDomain to queue disconnect_work without any local syscall, matching the adjacent-peer model used for other tbnet CVEs.\nAC:L - On affected host routers (e.g. ASMedia ASM4242) the reporter measured 21/21 failed teardowns versus 0/24 after the fix; an adjacent peer can reliably trigger teardown during active traffic by sending logout or forcing reconnect cycles without races or layout dependencies.\nPR:N - No Linux account, capability, or init-namespace privilege is required on the victim; any Thunderbolt/USB4 peer that completes the automatic ThunderboltIP login handshake can send TBIP_LOGOUT to invoke tbnet_handle_packet() and reach the vulnerable teardown path.\nUI:N - Once a ThunderboltIP session is established, which is typical for docks, direct laptop links, and bonded interfaces, the peer can trigger the faulty teardown repeatedly without further victim interaction beyond the existing cable connection.\nS:U - Impact is confined to the host kernel Thunderbolt controller and XDomain networking stack (hop drain failure, control-channel loss, power-cycle recovery) and does not cross VM, container, or IOMMU isolation boundaries.\nC:H - Stopping rings and calling tbnet_free_buffers() unmaps and frees RX/TX frame pages before tb_xdomain_disable_paths() drains hops; with pending in-flight Thunderbolt DMA this teardown race can expose or corrupt repurposed kernel memory, satisfying the higher-severity memory-corruption class when impact is uncertain.\nI:H - The same premature buffer unmap/free while DMA paths remain active can let in-flight NHI DMA target freed frame pages, enabling attacker-influenced kernel memory writes or control-flow corruption beyond the observed controller hang.\nA:H - Repeated teardowns leave hops stuck pending, eventually kill the XDomain control channel, and strand the peer until a full power cycle; bond enslavement and interface down paths also reliably trigger this denial of service on vulnerable hardware."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:41:36.384Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/7cce39109206bc5497e0953806563644b88bfc44"
},
{
"url": "https://git.kernel.org/stable/c/0da9a6d27155ad072dd76db8cd637feead99a0e0"
},
{
"url": "https://git.kernel.org/stable/c/b5a21615f627c48dafaa6ef82a34a5b97a4352aa"
},
{
"url": "https://git.kernel.org/stable/c/103a9b663ac1cacb8465aeff18f84a247154a562"
},
{
"url": "https://git.kernel.org/stable/c/4dd71cb0d23d40cb58fe4261c7bd183dca66caa0"
},
{
"url": "https://git.kernel.org/stable/c/9a482b2b117e5fa656b6d24fc01799e8ac2d4368"
},
{
"url": "https://git.kernel.org/stable/c/68bf02b6b4ad3f748c6db71fd77b6c0402d252f4"
}
],
"title": "net: thunderbolt: Tear down DMA paths before stopping the rings",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74691",
"datePublished": "2026-08-22T15:32:55.258Z",
"dateReserved": "2026-08-15T05:44:03.926Z",
"dateUpdated": "2026-08-25T05:41:36.384Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72017 (GCVE-0-2026-72017)
Vulnerability from cvelistv5
Published
2026-08-15 05:51
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: macb: drop in-flight Tx SKBs on close
The MACB driver has since forever leaked the outgoing SKBs that
have not yet been marked as completed. They live in queue->tx_skb
which gets freed without remorse nor checking.
macb_free_consistent() gets called in a few codepaths, but only close will
trigger the added expressions. In macb_open() and macb_alloc_consistent()
failure cases, queues' tx_skb just got allocated and are empty.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 89e5785fc8a6b9eafd37f2318a9a76d479c796be Version: 89e5785fc8a6b9eafd37f2318a9a76d479c796be Version: 89e5785fc8a6b9eafd37f2318a9a76d479c796be Version: 89e5785fc8a6b9eafd37f2318a9a76d479c796be Version: 89e5785fc8a6b9eafd37f2318a9a76d479c796be Version: 89e5785fc8a6b9eafd37f2318a9a76d479c796be |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/cadence/macb_main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "0e9797dc4ebdefe1b7f931b1f92d5e98e5dbf655",
"status": "affected",
"version": "89e5785fc8a6b9eafd37f2318a9a76d479c796be",
"versionType": "git"
},
{
"lessThan": "6124bd785073659c99385094657b77382ebce11b",
"status": "affected",
"version": "89e5785fc8a6b9eafd37f2318a9a76d479c796be",
"versionType": "git"
},
{
"lessThan": "2143fdc0ce27adbb1caaa1a97e0bfb9f3750aef4",
"status": "affected",
"version": "89e5785fc8a6b9eafd37f2318a9a76d479c796be",
"versionType": "git"
},
{
"lessThan": "26b131b2d5b55a81ef6182769d28105a870c0eb2",
"status": "affected",
"version": "89e5785fc8a6b9eafd37f2318a9a76d479c796be",
"versionType": "git"
},
{
"lessThan": "109241d9880488aafd8e104832b4d4859ad57244",
"status": "affected",
"version": "89e5785fc8a6b9eafd37f2318a9a76d479c796be",
"versionType": "git"
},
{
"lessThan": "27f575836cfebbf872dec020428742b10650a955",
"status": "affected",
"version": "89e5785fc8a6b9eafd37f2318a9a76d479c796be",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/cadence/macb_main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.20"
},
{
"lessThan": "2.6.20",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "2.6.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "2.6.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "2.6.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.20",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: macb: drop in-flight Tx SKBs on close\n\nThe MACB driver has since forever leaked the outgoing SKBs that\nhave not yet been marked as completed. They live in queue-\u003etx_skb\nwhich gets freed without remorse nor checking.\n\nmacb_free_consistent() gets called in a few codepaths, but only close will\ntrigger the added expressions. In macb_open() and macb_alloc_consistent()\nfailure cases, queues\u0027 tx_skb just got allocated and are empty."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:26.593Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/0e9797dc4ebdefe1b7f931b1f92d5e98e5dbf655"
},
{
"url": "https://git.kernel.org/stable/c/6124bd785073659c99385094657b77382ebce11b"
},
{
"url": "https://git.kernel.org/stable/c/2143fdc0ce27adbb1caaa1a97e0bfb9f3750aef4"
},
{
"url": "https://git.kernel.org/stable/c/26b131b2d5b55a81ef6182769d28105a870c0eb2"
},
{
"url": "https://git.kernel.org/stable/c/109241d9880488aafd8e104832b4d4859ad57244"
},
{
"url": "https://git.kernel.org/stable/c/27f575836cfebbf872dec020428742b10650a955"
}
],
"title": "net: macb: drop in-flight Tx SKBs on close",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72017",
"datePublished": "2026-08-15T05:51:44.698Z",
"dateReserved": "2026-08-09T03:40:39.900Z",
"dateUpdated": "2026-08-23T12:46:26.593Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74739 (GCVE-0-2026-74739)
Vulnerability from cvelistv5
Published
2026-08-26 14:36
Modified
2026-08-27 05:01
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/sched: cls_u32: skip hash tables in u32_bind_class()
u32_walk() enumerates both struct tc_u_hnode and struct tc_u_knode
through the walker callback. u32_bind_class() unconditionally casts the
passed fh to tc_u_knode and accesses &n->res, so when fh is actually a
tc_u_hnode, which has no tcf_result member, this results in a
slab-out-of-bounds read of res->classid in tc_cls_bind_class().
The issue can be reproduced with the following commands:
tc qdisc add dev lo root handle 1: hfsc
tc class add dev lo parent 1: classid 1:1 hfsc sc rate 1000kbit
tc filter add dev lo parent 1:1 protocol ip prio 1 u32 match u32 0 0 flowid 1:1
tc class add dev lo parent 1: classid 1:2 hfsc sc rate 2000kbit
Fix this by skipping hash tables via the TC_U32_KEY(handle) check.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 07d79fc7d94e3f884b8b1c95aa615b202bb5e4c1 Version: 07d79fc7d94e3f884b8b1c95aa615b202bb5e4c1 Version: 07d79fc7d94e3f884b8b1c95aa615b202bb5e4c1 Version: 07d79fc7d94e3f884b8b1c95aa615b202bb5e4c1 Version: 07d79fc7d94e3f884b8b1c95aa615b202bb5e4c1 Version: 07d79fc7d94e3f884b8b1c95aa615b202bb5e4c1 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/sched/cls_u32.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ec5f3005586a785689fd568361b0c5925cb1548b",
"status": "affected",
"version": "07d79fc7d94e3f884b8b1c95aa615b202bb5e4c1",
"versionType": "git"
},
{
"lessThan": "19d114b93c94bdef70496f26685c2a6b242f41b3",
"status": "affected",
"version": "07d79fc7d94e3f884b8b1c95aa615b202bb5e4c1",
"versionType": "git"
},
{
"lessThan": "594a064d603202b9ee21e07679d854e5c1750cc4",
"status": "affected",
"version": "07d79fc7d94e3f884b8b1c95aa615b202bb5e4c1",
"versionType": "git"
},
{
"lessThan": "31f26a95eeee926946809ac456c61a3217936a62",
"status": "affected",
"version": "07d79fc7d94e3f884b8b1c95aa615b202bb5e4c1",
"versionType": "git"
},
{
"lessThan": "e71f8e9ed6f311410b14741f6012afe01869c0fa",
"status": "affected",
"version": "07d79fc7d94e3f884b8b1c95aa615b202bb5e4c1",
"versionType": "git"
},
{
"lessThan": "6d3724e616faf952c3adcf8414fc21a828ef3709",
"status": "affected",
"version": "07d79fc7d94e3f884b8b1c95aa615b202bb5e4c1",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/sched/cls_u32.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.14"
},
{
"lessThan": "4.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.46",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.10",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: cls_u32: skip hash tables in u32_bind_class()\n\nu32_walk() enumerates both struct tc_u_hnode and struct tc_u_knode\nthrough the walker callback. u32_bind_class() unconditionally casts the\npassed fh to tc_u_knode and accesses \u0026n-\u003eres, so when fh is actually a\ntc_u_hnode, which has no tcf_result member, this results in a\nslab-out-of-bounds read of res-\u003eclassid in tc_cls_bind_class().\n\nThe issue can be reproduced with the following commands:\n\n tc qdisc add dev lo root handle 1: hfsc\n tc class add dev lo parent 1: classid 1:1 hfsc sc rate 1000kbit\n tc filter add dev lo parent 1:1 protocol ip prio 1 u32 match u32 0 0 flowid 1:1\n tc class add dev lo parent 1: classid 1:2 hfsc sc rate 2000kbit\n\nFix this by skipping hash tables via the TC_U32_KEY(handle) check."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached only via RTM_NEWTCLASS rtnetlink (tc class add) in __tc_ctl_tclass(), which calls tc_bind_tclass() to walk u32 filters; per kernel CNA guidance, tc/qdisc/netlink classifier configuration is Local, not remotely reachable by packets.\nAC:L - The reproducer is deterministic: install a u32 filter with flowid, then add another tc class so reverse binding walks hash nodes; the attacker controls every netlink step and needs no race or uncontrollable victim state.\nPR:L - RTM_NEWTCLASS requires CAP_NET_ADMIN enforced by netlink_net_capable() in rtnetlink; this capability is obtainable by unprivileged users in a user+network namespace (unshare -Urn) or containers granted NET_ADMIN, not init-namespace root only.\nUI:N - Exploitation requires only the attacker\u0027s own tc/netlink operations (qdisc, filter, class add) inside a namespace they control; no separate victim action such as opening files or mounting media is needed.\nS:U - Impact is kernel slab memory read and possible adjacent-slab corruption during tc class binding within the same host kernel; this is standard local kernel compromise, not VM escape, IOMMU bypass, or another cross-authority boundary.\nC:H - u32_bind_class() casts tc_u_hnode to tc_u_knode and reads \u0026n-\u003eres.classid past the hnode allocation in tc_cls_bind_class(); per CNA guidance, slab out-of-bounds reads of kernel memory warrant High confidentiality impact.\nI:H - If the out-of-bounds classid read matches the newly created class, tc_cls_bind_class() calls __tcf_bind_filter(), which xchg-writes to \u0026r-\u003eclass at the bogus offset, enabling adjacent slab corruption and potential control-flow hijack per memory-corruption guidance.\nA:H - The slab out-of-bounds access is reported as a KASAN violation on trigger, and mistaken reverse binding can corrupt adjacent kernel objects leading to oops/panic during later tc operations; per CNA guidance, kernel crashes and memory corruption score Availability High."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T05:01:00.695Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ec5f3005586a785689fd568361b0c5925cb1548b"
},
{
"url": "https://git.kernel.org/stable/c/19d114b93c94bdef70496f26685c2a6b242f41b3"
},
{
"url": "https://git.kernel.org/stable/c/594a064d603202b9ee21e07679d854e5c1750cc4"
},
{
"url": "https://git.kernel.org/stable/c/31f26a95eeee926946809ac456c61a3217936a62"
},
{
"url": "https://git.kernel.org/stable/c/e71f8e9ed6f311410b14741f6012afe01869c0fa"
},
{
"url": "https://git.kernel.org/stable/c/6d3724e616faf952c3adcf8414fc21a828ef3709"
}
],
"title": "net/sched: cls_u32: skip hash tables in u32_bind_class()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74739",
"datePublished": "2026-08-26T14:36:51.746Z",
"dateReserved": "2026-08-15T05:44:03.930Z",
"dateUpdated": "2026-08-27T05:01:00.695Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80562 (GCVE-0-2026-80562)
Vulnerability from cvelistv5
Published
2026-08-26 14:37
Modified
2026-08-27 12:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
gpio: ml-ioh: use raw_spinlock_t for the register lock
ioh_irq_type() is registered as the irq_chip .irq_set_type callback and
takes chip->spinlock with spin_lock_irqsave(). This callback is reached
from __setup_irq() -> __irq_set_trigger() -> chip->irq_set_type() while
the caller holds desc->lock, a raw_spinlock_t, with hardirqs disabled.
That context is not sleepable, but on PREEMPT_RT a regular spinlock_t is
an rtmutex-backed sleeping lock, so acquiring it there is invalid.
ioh_irq_enable() and ioh_irq_disable() take the same lock from the
.irq_enable/.irq_disable callbacks, which are likewise invoked with
desc->lock held.
Convert the register lock to raw_spinlock_t. The same lock also
serializes the GPIO direction/value callbacks and the suspend/resume
register save/restore, and those critical sections only perform short
sequences of MMIO register accesses (ioread32()/iowrite32()); the
.irq_set_type callback additionally emits a dev_warn() on an unsupported
type. None of these are sleepable operations, so keeping this register
lock non-sleeping is appropriate for the irqchip callbacks and does not
change the GPIO-side locking contract.
This is the same fix as commit a02b8950d619 ("gpio: pch: use
raw_spinlock_t for the register lock"); this driver shares the same
structure as gpio-pch.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 54be566317b6aece2389a95bb19ea209af9359be Version: 54be566317b6aece2389a95bb19ea209af9359be Version: 54be566317b6aece2389a95bb19ea209af9359be Version: 54be566317b6aece2389a95bb19ea209af9359be Version: 54be566317b6aece2389a95bb19ea209af9359be Version: 54be566317b6aece2389a95bb19ea209af9359be Version: 54be566317b6aece2389a95bb19ea209af9359be Version: 54be566317b6aece2389a95bb19ea209af9359be |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpio/gpio-ml-ioh.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "431b10133113537660a6090a2856b0d74d1b06de",
"status": "affected",
"version": "54be566317b6aece2389a95bb19ea209af9359be",
"versionType": "git"
},
{
"lessThan": "359e6b1168c9a62a7bd214ace476aaa2d57eebe8",
"status": "affected",
"version": "54be566317b6aece2389a95bb19ea209af9359be",
"versionType": "git"
},
{
"lessThan": "63d2230e5076c12f93d2a1d1bff2fbbf6cf32f3c",
"status": "affected",
"version": "54be566317b6aece2389a95bb19ea209af9359be",
"versionType": "git"
},
{
"lessThan": "b6505a4cea45dd92eb753581b1ad9b524b5fcc34",
"status": "affected",
"version": "54be566317b6aece2389a95bb19ea209af9359be",
"versionType": "git"
},
{
"lessThan": "84be002b40d30c56a91873b236e2d9001bbee363",
"status": "affected",
"version": "54be566317b6aece2389a95bb19ea209af9359be",
"versionType": "git"
},
{
"lessThan": "bc7934d0acd4fc1c7e5b7c68debdb4a991121628",
"status": "affected",
"version": "54be566317b6aece2389a95bb19ea209af9359be",
"versionType": "git"
},
{
"lessThan": "0559b86611c35d342dd48542ea26a9e437046bf6",
"status": "affected",
"version": "54be566317b6aece2389a95bb19ea209af9359be",
"versionType": "git"
},
{
"lessThan": "600411ea1f2443fdf5b1af9b6480f616d7aff9d0",
"status": "affected",
"version": "54be566317b6aece2389a95bb19ea209af9359be",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpio/gpio-ml-ioh.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.2"
},
{
"lessThan": "3.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.267",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.218",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.185",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.154",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.106",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.267",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.218",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.185",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.154",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.106",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.46",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.10",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ngpio: ml-ioh: use raw_spinlock_t for the register lock\n\nioh_irq_type() is registered as the irq_chip .irq_set_type callback and\ntakes chip-\u003espinlock with spin_lock_irqsave(). This callback is reached\nfrom __setup_irq() -\u003e __irq_set_trigger() -\u003e chip-\u003eirq_set_type() while\nthe caller holds desc-\u003elock, a raw_spinlock_t, with hardirqs disabled.\nThat context is not sleepable, but on PREEMPT_RT a regular spinlock_t is\nan rtmutex-backed sleeping lock, so acquiring it there is invalid.\nioh_irq_enable() and ioh_irq_disable() take the same lock from the\n.irq_enable/.irq_disable callbacks, which are likewise invoked with\ndesc-\u003elock held.\n\nConvert the register lock to raw_spinlock_t. The same lock also\nserializes the GPIO direction/value callbacks and the suspend/resume\nregister save/restore, and those critical sections only perform short\nsequences of MMIO register accesses (ioread32()/iowrite32()); the\n.irq_set_type callback additionally emits a dev_warn() on an unsupported\ntype. None of these are sleepable operations, so keeping this register\nlock non-sleeping is appropriate for the irqchip callbacks and does not\nchange the GPIO-side locking contract.\n\nThis is the same fix as commit a02b8950d619 (\"gpio: pch: use\nraw_spinlock_t for the register lock\"); this driver shares the same\nstructure as gpio-pch."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T12:40:17.967Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/431b10133113537660a6090a2856b0d74d1b06de"
},
{
"url": "https://git.kernel.org/stable/c/359e6b1168c9a62a7bd214ace476aaa2d57eebe8"
},
{
"url": "https://git.kernel.org/stable/c/63d2230e5076c12f93d2a1d1bff2fbbf6cf32f3c"
},
{
"url": "https://git.kernel.org/stable/c/b6505a4cea45dd92eb753581b1ad9b524b5fcc34"
},
{
"url": "https://git.kernel.org/stable/c/84be002b40d30c56a91873b236e2d9001bbee363"
},
{
"url": "https://git.kernel.org/stable/c/bc7934d0acd4fc1c7e5b7c68debdb4a991121628"
},
{
"url": "https://git.kernel.org/stable/c/0559b86611c35d342dd48542ea26a9e437046bf6"
},
{
"url": "https://git.kernel.org/stable/c/600411ea1f2443fdf5b1af9b6480f616d7aff9d0"
}
],
"title": "gpio: ml-ioh: use raw_spinlock_t for the register lock",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80562",
"datePublished": "2026-08-26T14:37:27.171Z",
"dateReserved": "2026-08-26T14:34:25.767Z",
"dateUpdated": "2026-08-27T12:40:17.967Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68371 (GCVE-0-2026-68371)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
usb: musb: omap2430: Do not put borrowed of_node in probe
omap2430_probe() stores pdev->dev.of_node in a local np variable. This is
a borrowed pointer and the probe function does not take a reference to
it.
The success and error paths nevertheless call of_node_put(np). This drops
a reference that is owned by the platform device, and can leave
pdev->dev.of_node with an unbalanced reference count.
Do not put the borrowed platform device node from omap2430_probe().
References taken for the child MUSB device are handled by the device core,
and the ctrl-module phandle reference is still released separately.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 22b60658a90260e3fbd57824e3afe5682c6afcf5 Version: ffbe2feac59b37c8dc536727552b4f375e1b9aec Version: ffbe2feac59b37c8dc536727552b4f375e1b9aec Version: ffbe2feac59b37c8dc536727552b4f375e1b9aec Version: ffbe2feac59b37c8dc536727552b4f375e1b9aec Version: ffbe2feac59b37c8dc536727552b4f375e1b9aec Version: fed43efc00ba6ac8c6b95828cd5acfa3d45eca4d Version: 6.1.2 ≤ Version: 6.0.16 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/musb/omap2430.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "f0e68402d13cd9ffb289da50e65d4429d0002174",
"status": "affected",
"version": "22b60658a90260e3fbd57824e3afe5682c6afcf5",
"versionType": "git"
},
{
"lessThan": "eed56f105a7f70cbcfceb4df6deb6870fc58214d",
"status": "affected",
"version": "ffbe2feac59b37c8dc536727552b4f375e1b9aec",
"versionType": "git"
},
{
"lessThan": "58d1c81c0b54a0b9aa6d6af077b09aa2f1bd2193",
"status": "affected",
"version": "ffbe2feac59b37c8dc536727552b4f375e1b9aec",
"versionType": "git"
},
{
"lessThan": "0950ac52426b0ab32d3b8cf4afe1711668b19cb8",
"status": "affected",
"version": "ffbe2feac59b37c8dc536727552b4f375e1b9aec",
"versionType": "git"
},
{
"lessThan": "6c525c851e5912b9753622d796f2bc55c4913b04",
"status": "affected",
"version": "ffbe2feac59b37c8dc536727552b4f375e1b9aec",
"versionType": "git"
},
{
"lessThan": "c947360ae63eee1c9eacc030dd6f5a53f717addf",
"status": "affected",
"version": "ffbe2feac59b37c8dc536727552b4f375e1b9aec",
"versionType": "git"
},
{
"status": "affected",
"version": "fed43efc00ba6ac8c6b95828cd5acfa3d45eca4d",
"versionType": "git"
},
{
"lessThan": "6.1.184",
"status": "affected",
"version": "6.1.2",
"versionType": "semver"
},
{
"lessThan": "6.1",
"status": "affected",
"version": "6.0.16",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/usb/musb/omap2430.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.2"
},
{
"lessThan": "6.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "6.1.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "6.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.0.16",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: musb: omap2430: Do not put borrowed of_node in probe\n\nomap2430_probe() stores pdev-\u003edev.of_node in a local np variable. This is\na borrowed pointer and the probe function does not take a reference to\nit.\n\nThe success and error paths nevertheless call of_node_put(np). This drops\na reference that is owned by the platform device, and can leave\npdev-\u003edev.of_node with an unbalanced reference count.\n\nDo not put the borrowed platform device node from omap2430_probe().\nReferences taken for the child MUSB device are handled by the device core,\nand the ctrl-module phandle reference is still released separately."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.4,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - omap2430_probe() is reached only via the local driver model - boot-time platform bus match on the OMAP MUSB device-tree node, deferred-probe retries, sysfs bind/unbind of musb-omap2430, or module load/unload. There is no network, adjacent-network, or remote path, and leveraging the prematurely released kobject name/OF node requires local heap manipulation in the same kmalloc cache.\nAC:L - The stray of_node_put(np) is unconditional on both the success return and the err_put_musb error path, so every probe invocation drops a reference the driver never took. There is no race to win, no timing window, and no memory-layout precondition; the imbalance occurs deterministically on each probe and reproduces at will through bind/unbind cycles.\nPR:N - No credential, capability, or namespace check exists on the path - the platform bus binds the OMAP MUSB node and drops the reference during kernel boot, before any user session exists, so the underflowed device_node state arises with zero privileges. Deliberate re-triggering via sysfs unbind would need root, but that is not needed for the vulnerable condition to occur.\nUI:N - The musb-omap2430 platform driver binds automatically when the device-tree node is populated, and deferred-probe retries run unattended during boot; no administrator action, victim interaction, mount, or file open is required for the unbalanced of_node_put() to execute.\nS:U - The corrupted struct device_node, its embedded kobject, and the OF tree all belong to the kernel\u0027s own security authority, and the faulting code runs in that same kernel context. No hypervisor, IOMMU, or sandbox boundary is crossed.\nC:H - The premature release drives kobject_cleanup(), which kfree_const()s kobj-\u003ename while the device_node stays reachable via pdev-\u003edev.of_node, the OF tree, and phandle lookups, so later kobject_name()/sysfs/%pOF accesses read back reclaimed heap contents an attacker can spray. The bad of_node_put() splat with dump_stack() additionally leaks kernel pointers and a full stack trace.\nI:H - A device_node whose backing kobject has been released and whose slab-allocated name has been freed yields write primitives once the memory is reclaimed: the embedded fwnode_handle.ops table is dereferenced by fwnode_call_int_op(), kobj.ktype-\u003erelease is invoked on the next put, and the parent/child/sibling and device-link list heads permit list-manipulation writes during OF tree operations.\nA:H - Reaching zero produces \"ERROR: of_node_release() detected bad of_node_put()\" with dump_stack(), and the next get/put triggers a refcount_t underflow; use-after-free WARN - an outright panic under panic_on_warn. __kobject_del() also tears down the node\u0027s /sys/firmware/devicetree entries and cascades puts onto the parent node, and dereferencing the released node oopses the kernel."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:19.885Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/f0e68402d13cd9ffb289da50e65d4429d0002174"
},
{
"url": "https://git.kernel.org/stable/c/eed56f105a7f70cbcfceb4df6deb6870fc58214d"
},
{
"url": "https://git.kernel.org/stable/c/58d1c81c0b54a0b9aa6d6af077b09aa2f1bd2193"
},
{
"url": "https://git.kernel.org/stable/c/0950ac52426b0ab32d3b8cf4afe1711668b19cb8"
},
{
"url": "https://git.kernel.org/stable/c/6c525c851e5912b9753622d796f2bc55c4913b04"
},
{
"url": "https://git.kernel.org/stable/c/c947360ae63eee1c9eacc030dd6f5a53f717addf"
}
],
"title": "usb: musb: omap2430: Do not put borrowed of_node in probe",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68371",
"datePublished": "2026-08-10T12:03:49.287Z",
"dateReserved": "2026-07-30T09:28:09.386Z",
"dateUpdated": "2026-08-23T12:46:19.885Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74622 (GCVE-0-2026-74622)
Vulnerability from cvelistv5
Published
2026-08-22 15:32
Modified
2026-08-22 15:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: atlantic: free RX pages of consumed but not refilled buffers
aq_ring_rx_deinit() only walks [sw_head, sw_tail), the region posted to
hardware. Since the page reuse strategy was added, a cleaned RX buffer
keeps its page (and its DMA mapping) in the ring for reuse, and refill
is batched: aq_ring_rx_fill() returns early until AQ_CFG_RX_REFILL_THRES
slots are free. Slots that were consumed but not yet reposted therefore
sit in the complementary [sw_tail, sw_head) gap with a live page, and
the deinit walk never visits them: up to a refill batch worth of pages
and DMA mappings leak on every interface down.
Walk the whole ring instead and release whatever is still there. Also
bail out if the buffer ring is already gone: a partial
aq_ptp_ring_alloc() failure frees the ring but leaves aq_nic set, so
aq_ptp_ring_deinit() still gets here on the unwind path.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 46f4c29d9de6e4a9d4ed7de9a37dd42501d89f86 Version: 46f4c29d9de6e4a9d4ed7de9a37dd42501d89f86 Version: 46f4c29d9de6e4a9d4ed7de9a37dd42501d89f86 Version: 46f4c29d9de6e4a9d4ed7de9a37dd42501d89f86 Version: 46f4c29d9de6e4a9d4ed7de9a37dd42501d89f86 Version: 46f4c29d9de6e4a9d4ed7de9a37dd42501d89f86 Version: 46f4c29d9de6e4a9d4ed7de9a37dd42501d89f86 Version: 46f4c29d9de6e4a9d4ed7de9a37dd42501d89f86 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/aquantia/atlantic/aq_ring.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "1e58b0bab40dcbdfc04acaba6a221d40801c3770",
"status": "affected",
"version": "46f4c29d9de6e4a9d4ed7de9a37dd42501d89f86",
"versionType": "git"
},
{
"lessThan": "30c473ea097ef0c93b064281b3e295c97d17e28b",
"status": "affected",
"version": "46f4c29d9de6e4a9d4ed7de9a37dd42501d89f86",
"versionType": "git"
},
{
"lessThan": "17c99dd86f169c7a3e73d6778e79ef5b1ed3ceac",
"status": "affected",
"version": "46f4c29d9de6e4a9d4ed7de9a37dd42501d89f86",
"versionType": "git"
},
{
"lessThan": "ff451bc4290b79c04f1c5cfa928d448f9d47ecf5",
"status": "affected",
"version": "46f4c29d9de6e4a9d4ed7de9a37dd42501d89f86",
"versionType": "git"
},
{
"lessThan": "64e1346bc66b947eb80b848e4c8d9828ba50e0fe",
"status": "affected",
"version": "46f4c29d9de6e4a9d4ed7de9a37dd42501d89f86",
"versionType": "git"
},
{
"lessThan": "782cc40b7ade4614a8aec0b948b8cf95c69f8d4b",
"status": "affected",
"version": "46f4c29d9de6e4a9d4ed7de9a37dd42501d89f86",
"versionType": "git"
},
{
"lessThan": "24d87dc28ddd3771dd0e88719209811809729439",
"status": "affected",
"version": "46f4c29d9de6e4a9d4ed7de9a37dd42501d89f86",
"versionType": "git"
},
{
"lessThan": "e8e7471ef686b6c002218fee9671cc61992ae01a",
"status": "affected",
"version": "46f4c29d9de6e4a9d4ed7de9a37dd42501d89f86",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/aquantia/atlantic/aq_ring.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.2"
},
{
"lessThan": "5.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: atlantic: free RX pages of consumed but not refilled buffers\n\naq_ring_rx_deinit() only walks [sw_head, sw_tail), the region posted to\nhardware. Since the page reuse strategy was added, a cleaned RX buffer\nkeeps its page (and its DMA mapping) in the ring for reuse, and refill\nis batched: aq_ring_rx_fill() returns early until AQ_CFG_RX_REFILL_THRES\nslots are free. Slots that were consumed but not yet reposted therefore\nsit in the complementary [sw_tail, sw_head) gap with a live page, and\nthe deinit walk never visits them: up to a refill batch worth of pages\nand DMA mappings leak on every interface down.\n\nWalk the whole ring instead and release whatever is still there. Also\nbail out if the buffer ring is already gone: a partial\naq_ptp_ring_alloc() failure frees the ring but leaves aq_nic set, so\naq_ptp_ring_deinit() still gets here on the unwind path."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-22T15:32:05.719Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/1e58b0bab40dcbdfc04acaba6a221d40801c3770"
},
{
"url": "https://git.kernel.org/stable/c/30c473ea097ef0c93b064281b3e295c97d17e28b"
},
{
"url": "https://git.kernel.org/stable/c/17c99dd86f169c7a3e73d6778e79ef5b1ed3ceac"
},
{
"url": "https://git.kernel.org/stable/c/ff451bc4290b79c04f1c5cfa928d448f9d47ecf5"
},
{
"url": "https://git.kernel.org/stable/c/64e1346bc66b947eb80b848e4c8d9828ba50e0fe"
},
{
"url": "https://git.kernel.org/stable/c/782cc40b7ade4614a8aec0b948b8cf95c69f8d4b"
},
{
"url": "https://git.kernel.org/stable/c/24d87dc28ddd3771dd0e88719209811809729439"
},
{
"url": "https://git.kernel.org/stable/c/e8e7471ef686b6c002218fee9671cc61992ae01a"
}
],
"title": "net: atlantic: free RX pages of consumed but not refilled buffers",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74622",
"datePublished": "2026-08-22T15:32:05.719Z",
"dateReserved": "2026-08-15T05:44:03.921Z",
"dateUpdated": "2026-08-22T15:32:05.719Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64280 (GCVE-0-2026-64280)
Vulnerability from cvelistv5
Published
2026-07-25 08:49
Modified
2026-08-23 12:45
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region()
afu_ioctl_dma_map() accepts a 64-bit length from userspace via
DFL_FPGA_PORT_DMA_MAP ioctl without an upper bound check. The value
is passed to afu_dma_pin_pages() where npages is derived as
length >> PAGE_SHIFT and passed to pin_user_pages_fast() which takes
int nr_pages, causing implicit truncation if length is very large.
Validate map.length at the ioctl entry point before calling
afu_dma_map_region(), rejecting values whose page count exceeds
INT_MAX.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: fa8dda1edef9ebc3af467c644c5533ac97171e12 Version: fa8dda1edef9ebc3af467c644c5533ac97171e12 Version: fa8dda1edef9ebc3af467c644c5533ac97171e12 Version: fa8dda1edef9ebc3af467c644c5533ac97171e12 Version: fa8dda1edef9ebc3af467c644c5533ac97171e12 Version: fa8dda1edef9ebc3af467c644c5533ac97171e12 Version: fa8dda1edef9ebc3af467c644c5533ac97171e12 Version: fa8dda1edef9ebc3af467c644c5533ac97171e12 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/fpga/dfl-afu-main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "5352d488ce4ae5e8c68c080ad4c3a5f084ad5fbc",
"status": "affected",
"version": "fa8dda1edef9ebc3af467c644c5533ac97171e12",
"versionType": "git"
},
{
"lessThan": "d7e787eee2ea619b6dbb98890472ee73daf2e7fd",
"status": "affected",
"version": "fa8dda1edef9ebc3af467c644c5533ac97171e12",
"versionType": "git"
},
{
"lessThan": "a6a3884ff500f04f3088d6d09eec803cd35331a2",
"status": "affected",
"version": "fa8dda1edef9ebc3af467c644c5533ac97171e12",
"versionType": "git"
},
{
"lessThan": "16381bda90b261a656ded0568630c1b857b2ebc8",
"status": "affected",
"version": "fa8dda1edef9ebc3af467c644c5533ac97171e12",
"versionType": "git"
},
{
"lessThan": "b50e6cd2395cde615f59b624819998d28c0668d6",
"status": "affected",
"version": "fa8dda1edef9ebc3af467c644c5533ac97171e12",
"versionType": "git"
},
{
"lessThan": "59070040fd12e0b78d7b4d341d9f9a183237c5ff",
"status": "affected",
"version": "fa8dda1edef9ebc3af467c644c5533ac97171e12",
"versionType": "git"
},
{
"lessThan": "fb2c0eab51ae5b02d2bae7d67c2cfbec39b57231",
"status": "affected",
"version": "fa8dda1edef9ebc3af467c644c5533ac97171e12",
"versionType": "git"
},
{
"lessThan": "fc3b071a7c8dc0f5d56defddf6e6fd5aaa3e1e27",
"status": "affected",
"version": "fa8dda1edef9ebc3af467c644c5533ac97171e12",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/fpga/dfl-afu-main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.19"
},
{
"lessThan": "4.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfpga: dfl-afu: validate DMA mapping length in afu_dma_map_region()\n\nafu_ioctl_dma_map() accepts a 64-bit length from userspace via\nDFL_FPGA_PORT_DMA_MAP ioctl without an upper bound check. The value\nis passed to afu_dma_pin_pages() where npages is derived as\nlength \u003e\u003e PAGE_SHIFT and passed to pin_user_pages_fast() which takes\nint nr_pages, causing implicit truncation if length is very large.\n\nValidate map.length at the ioctl entry point before calling\nafu_dma_map_region(), rejecting values whose page count exceeds\nINT_MAX."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable path is reached locally through DFL_FPGA_PORT_DMA_MAP on a /dev/dfl-port.* character device.\nAC:L - A page-aligned length whose page count wraps to zero or a small positive integer deterministically triggers the mismatch; no race or condition outside the attacker\u2019s control is required.\nPR:L - The ioctl contains no capability or namespace privilege check, so any unprivileged user granted access to the port device can trigger it.\nUI:N - The attacker independently opens the device and submits the malicious ioctl without any victim action.\nS:C - The oversized DMA mapping can cross the IOMMU-enforced boundary between the assigned user buffer and host physical memory, affecting kernel and other-user resources.\nC:H - A small positive page-count wrap can create an enormous DMA-readable mapping after pinning only a few pages, exposing host memory beyond the authorized buffer; teardown also performs unbounded out-of-bounds pointer reads.\nI:H - The mapping is DMA_BIDIRECTIONAL, permitting writes beyond the pinned buffer, while the oversized unpin operation can corrupt unrelated page reference counts through out-of-bounds page pointers.\nA:H - A zero page-count wrap causes a deterministic pages[0] dereference from a zero-sized allocation, while other wrapped counts can produce an unbounded unpin traversal and kernel crash."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:45:39.157Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/5352d488ce4ae5e8c68c080ad4c3a5f084ad5fbc"
},
{
"url": "https://git.kernel.org/stable/c/d7e787eee2ea619b6dbb98890472ee73daf2e7fd"
},
{
"url": "https://git.kernel.org/stable/c/a6a3884ff500f04f3088d6d09eec803cd35331a2"
},
{
"url": "https://git.kernel.org/stable/c/16381bda90b261a656ded0568630c1b857b2ebc8"
},
{
"url": "https://git.kernel.org/stable/c/b50e6cd2395cde615f59b624819998d28c0668d6"
},
{
"url": "https://git.kernel.org/stable/c/59070040fd12e0b78d7b4d341d9f9a183237c5ff"
},
{
"url": "https://git.kernel.org/stable/c/fb2c0eab51ae5b02d2bae7d67c2cfbec39b57231"
},
{
"url": "https://git.kernel.org/stable/c/fc3b071a7c8dc0f5d56defddf6e6fd5aaa3e1e27"
}
],
"title": "fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64280",
"datePublished": "2026-07-25T08:49:23.753Z",
"dateReserved": "2026-07-19T15:36:31.777Z",
"dateUpdated": "2026-08-23T12:45:39.157Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74676 (GCVE-0-2026-74676)
Vulnerability from cvelistv5
Published
2026-08-22 15:32
Modified
2026-08-25 05:23
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
vt: add permission check for KDSKBMETA ioctl
KDSKBMETA modifies keyboard meta mode but lacks the !perm check that all
other keyboard setter ioctls in vt_k_ioctl() enforce, allowing a process
to change meta mode on a non-controlling console without authorization.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/tty/vt/vt_ioctl.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "9f8cbaf4b774694dcc292e60509762483ebfd9ae",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "ddc4a8303347114e945b9e6e81b81d77855f7358",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "1c5b67a1e2cb7d78dab321280f330b056e3bf437",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "d8ead5083b203d12b8319e7cb29cc6b8836e813f",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "4671c3b79e337bbae28c2d79023dc642df012bde",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "a1c31e026c93e378e297a8df8328983d3013a59f",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "7bf32337a7103ccb686cbd240324bf26225ef2d6",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "a7ad0034453ba4c353f9b8f810ee2569de33d283",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/tty/vt/vt_ioctl.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nvt: add permission check for KDSKBMETA ioctl\n\nKDSKBMETA modifies keyboard meta mode but lacks the !perm check that all\nother keyboard setter ioctls in vt_k_ioctl() enforce, allowing a process\nto change meta mode on a non-controlling console without authorization."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:23:18.083Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/9f8cbaf4b774694dcc292e60509762483ebfd9ae"
},
{
"url": "https://git.kernel.org/stable/c/ddc4a8303347114e945b9e6e81b81d77855f7358"
},
{
"url": "https://git.kernel.org/stable/c/1c5b67a1e2cb7d78dab321280f330b056e3bf437"
},
{
"url": "https://git.kernel.org/stable/c/d8ead5083b203d12b8319e7cb29cc6b8836e813f"
},
{
"url": "https://git.kernel.org/stable/c/4671c3b79e337bbae28c2d79023dc642df012bde"
},
{
"url": "https://git.kernel.org/stable/c/a1c31e026c93e378e297a8df8328983d3013a59f"
},
{
"url": "https://git.kernel.org/stable/c/7bf32337a7103ccb686cbd240324bf26225ef2d6"
},
{
"url": "https://git.kernel.org/stable/c/a7ad0034453ba4c353f9b8f810ee2569de33d283"
}
],
"title": "vt: add permission check for KDSKBMETA ioctl",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74676",
"datePublished": "2026-08-22T15:32:45.256Z",
"dateReserved": "2026-08-15T05:44:03.925Z",
"dateUpdated": "2026-08-25T05:23:18.083Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74540 (GCVE-0-2026-74540)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-19 16:38
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: L2CAP: fix UAF in l2cap_le_connect_rsp
l2cap_le_connect_rsp() obtains a channel via
__l2cap_get_chan_by_ident() but neither holds a reference nor uses
l2cap_chan_hold_unless_zero() before locking and operating on it.
A concurrent l2cap_chan_del() triggered by a remote disconnect can
free the channel between the lookup and l2cap_chan_lock(), causing
a use-after-free.
The BR/EDR counterpart l2cap_connect_rsp() and the sibling handler
l2cap_le_command_rej() already use l2cap_chan_hold_unless_zero()
to safely hold a reference, but l2cap_le_connect_rsp() was left
unprotected.
Fix by adding l2cap_chan_hold_unless_zero() after the ident lookup
and l2cap_chan_put() on the exit path, consistent with other L2CAP
response handlers.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: f1496dee9cbde2a62821f4441dadb0d3360f60c3 Version: f1496dee9cbde2a62821f4441dadb0d3360f60c3 Version: f1496dee9cbde2a62821f4441dadb0d3360f60c3 Version: f1496dee9cbde2a62821f4441dadb0d3360f60c3 Version: f1496dee9cbde2a62821f4441dadb0d3360f60c3 Version: f1496dee9cbde2a62821f4441dadb0d3360f60c3 Version: f1496dee9cbde2a62821f4441dadb0d3360f60c3 Version: f1496dee9cbde2a62821f4441dadb0d3360f60c3 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/bluetooth/l2cap_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "15d6c2367217a6a20b1abae9f38ded716bf620f1",
"status": "affected",
"version": "f1496dee9cbde2a62821f4441dadb0d3360f60c3",
"versionType": "git"
},
{
"lessThan": "1818180fe12d6cec7a437bc59cde8efdf6b10250",
"status": "affected",
"version": "f1496dee9cbde2a62821f4441dadb0d3360f60c3",
"versionType": "git"
},
{
"lessThan": "8325eafb38c3dee5af329266393763693d17381b",
"status": "affected",
"version": "f1496dee9cbde2a62821f4441dadb0d3360f60c3",
"versionType": "git"
},
{
"lessThan": "fd4c1e301bdec60a40728ea37de531cbccda501a",
"status": "affected",
"version": "f1496dee9cbde2a62821f4441dadb0d3360f60c3",
"versionType": "git"
},
{
"lessThan": "522b730c62c53a1981604fd73524697fd347830d",
"status": "affected",
"version": "f1496dee9cbde2a62821f4441dadb0d3360f60c3",
"versionType": "git"
},
{
"lessThan": "58e3c5289ad230a7e24ae4b0c7b43f5ee6e32136",
"status": "affected",
"version": "f1496dee9cbde2a62821f4441dadb0d3360f60c3",
"versionType": "git"
},
{
"lessThan": "09f447accc2570751e7d17f0dc0788b40d3edade",
"status": "affected",
"version": "f1496dee9cbde2a62821f4441dadb0d3360f60c3",
"versionType": "git"
},
{
"lessThan": "c4740e7f23ff9a8210198d8b4703259e21b9f69d",
"status": "affected",
"version": "f1496dee9cbde2a62821f4441dadb0d3360f60c3",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/bluetooth/l2cap_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.14"
},
{
"lessThan": "3.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "3.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "3.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "3.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "3.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: fix UAF in l2cap_le_connect_rsp\n\nl2cap_le_connect_rsp() obtains a channel via\n__l2cap_get_chan_by_ident() but neither holds a reference nor uses\nl2cap_chan_hold_unless_zero() before locking and operating on it.\nA concurrent l2cap_chan_del() triggered by a remote disconnect can\nfree the channel between the lookup and l2cap_chan_lock(), causing\na use-after-free.\n\nThe BR/EDR counterpart l2cap_connect_rsp() and the sibling handler\nl2cap_le_command_rej() already use l2cap_chan_hold_unless_zero()\nto safely hold a reference, but l2cap_le_connect_rsp() was left\nunprotected.\n\nFix by adding l2cap_chan_hold_unless_zero() after the ident lookup\nand l2cap_chan_put() on the exit path, consistent with other L2CAP\nresponse handlers."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The vulnerability is reached when the kernel processes an incoming L2CAP LE Connect Response over an established Bluetooth LE ACL link (HCI ACL receive \u2192 l2cap_recv_acldata \u2192 l2cap_le_sig_channel \u2192 l2cap_le_connect_rsp), requiring radio proximity rather than routable Internet access.\nAC:L - The remote Bluetooth peer controls both sides of the race by sending L2CAP_LE_CONN_RSP while concurrently triggering channel teardown via L2CAP DISCONN_REQ or HCI disconnect, freeing the channel between __l2cap_get_chan_by_ident() and l2cap_chan_lock() without attacker-uncontrollable timing.\nPR:N - No local privileges on the victim are required; exploitation needs only a nearby attacker with an established LE Bluetooth connection sending crafted L2CAP signaling packets, with no root, CAP_NET_ADMIN, or user-namespace capability on the target host.\nUI:N - On phones, wearables, automotive, and IoT deployments, paired or background Bluetooth clients routinely auto-initiate L2CAP credit-based connections without per-attack user confirmation once an LE link is up, enabling trigger of the pending outgoing connect path.\nS:U - Impact is confined to kernel memory and privileges on the Bluetooth-connected host; there is no VM guest-to-host escape, sandbox breakout, or IOMMU/DMA boundary crossing, so security scope remains unchanged per kernel CVSS guidance.\nC:H - Use-after-free of heap-allocated struct l2cap_chan allows attacker-controlled reuse of freed slab memory, enabling disclosure of kernel heap contents and pointers through corrupted channel fields accessed after premature free.\nI:H - The UAF window writes channel state (ident, dcid, mtu, credits) and invokes chan-\u003eops function pointers (ready, teardown) on freed memory, enabling heap spraying and control-flow hijack for arbitrary kernel code execution.\nA:H - Operating on a freed l2cap_chan can immediately kernel-oops or panic from corrupt mutex/state during lock/unlock and callback dispatch; UAF in softirq L2CAP processing inherently threatens full system availability."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:38:32.306Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/15d6c2367217a6a20b1abae9f38ded716bf620f1"
},
{
"url": "https://git.kernel.org/stable/c/1818180fe12d6cec7a437bc59cde8efdf6b10250"
},
{
"url": "https://git.kernel.org/stable/c/8325eafb38c3dee5af329266393763693d17381b"
},
{
"url": "https://git.kernel.org/stable/c/fd4c1e301bdec60a40728ea37de531cbccda501a"
},
{
"url": "https://git.kernel.org/stable/c/522b730c62c53a1981604fd73524697fd347830d"
},
{
"url": "https://git.kernel.org/stable/c/58e3c5289ad230a7e24ae4b0c7b43f5ee6e32136"
},
{
"url": "https://git.kernel.org/stable/c/09f447accc2570751e7d17f0dc0788b40d3edade"
},
{
"url": "https://git.kernel.org/stable/c/c4740e7f23ff9a8210198d8b4703259e21b9f69d"
}
],
"title": "Bluetooth: L2CAP: fix UAF in l2cap_le_connect_rsp",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74540",
"datePublished": "2026-08-15T12:27:51.522Z",
"dateReserved": "2026-08-15T05:44:03.913Z",
"dateUpdated": "2026-08-19T16:38:32.306Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80678 (GCVE-0-2026-80678)
Vulnerability from cvelistv5
Published
2026-08-28 06:52
Modified
2026-08-29 06:22
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
i2c: imx: Fix slave registration race and error handling
In i2c_imx_reg_slave(), the slave pointer was assigned before
pm_runtime_resume_and_get(). If pm_runtime_resume_and_get() failed,
the error path returned without clearing i2c_imx->slave, leaving it
non-NULL and causing all subsequent registration attempts to fail
with -EBUSY.
Additionally, because this driver uses a shared IRQ, the interrupt
handler i2c_imx_isr() can execute concurrently and, after acquiring
slave_lock, dereference i2c_imx->slave. The previous fix attempt
added a lockless i2c_imx->slave = NULL on the error path, but that
could race with the ISR under the lock and still cause a NULL pointer
dereference.
Fix both issues by deferring the assignment of i2c_imx->slave and
i2c_imx->last_slave_event to after a successful resume, and by
performing the assignment inside the slave_lock critical section.
This guarantees that the slave pointer is never left stale on the
error path and is always valid when observed by the interrupt handler.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: f7414cd6923fd7f78e57086fc964ba2dc25db5c1 Version: f7414cd6923fd7f78e57086fc964ba2dc25db5c1 Version: f7414cd6923fd7f78e57086fc964ba2dc25db5c1 Version: f7414cd6923fd7f78e57086fc964ba2dc25db5c1 Version: f7414cd6923fd7f78e57086fc964ba2dc25db5c1 Version: f7414cd6923fd7f78e57086fc964ba2dc25db5c1 Version: f7414cd6923fd7f78e57086fc964ba2dc25db5c1 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/i2c/busses/i2c-imx.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "754bc62f72fd64b202462367134ac8ce95b005de",
"status": "affected",
"version": "f7414cd6923fd7f78e57086fc964ba2dc25db5c1",
"versionType": "git"
},
{
"lessThan": "cfdf6e13518589f911b7eace6ccb788e4ed87397",
"status": "affected",
"version": "f7414cd6923fd7f78e57086fc964ba2dc25db5c1",
"versionType": "git"
},
{
"lessThan": "b9f6f4883b9ac86654e75899d0dbf8a7a96ad5d8",
"status": "affected",
"version": "f7414cd6923fd7f78e57086fc964ba2dc25db5c1",
"versionType": "git"
},
{
"lessThan": "d6748f6802f3eebafaa16a5e5dcfbfb9b3bc173f",
"status": "affected",
"version": "f7414cd6923fd7f78e57086fc964ba2dc25db5c1",
"versionType": "git"
},
{
"lessThan": "12a4f0950a158d98552cbaeacc35edccd8d975fa",
"status": "affected",
"version": "f7414cd6923fd7f78e57086fc964ba2dc25db5c1",
"versionType": "git"
},
{
"lessThan": "614ca6594e301ff682999797c2216e9685558a2b",
"status": "affected",
"version": "f7414cd6923fd7f78e57086fc964ba2dc25db5c1",
"versionType": "git"
},
{
"lessThan": "d64ec362c369bbc33833f7936d5f3a706b0d5c45",
"status": "affected",
"version": "f7414cd6923fd7f78e57086fc964ba2dc25db5c1",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/i2c/busses/i2c-imx.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.11"
},
{
"lessThan": "5.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: imx: Fix slave registration race and error handling\n\nIn i2c_imx_reg_slave(), the slave pointer was assigned before\npm_runtime_resume_and_get(). If pm_runtime_resume_and_get() failed,\nthe error path returned without clearing i2c_imx-\u003eslave, leaving it\nnon-NULL and causing all subsequent registration attempts to fail\nwith -EBUSY.\n\nAdditionally, because this driver uses a shared IRQ, the interrupt\nhandler i2c_imx_isr() can execute concurrently and, after acquiring\nslave_lock, dereference i2c_imx-\u003eslave. The previous fix attempt\nadded a lockless i2c_imx-\u003eslave = NULL on the error path, but that\ncould race with the ISR under the lock and still cause a NULL pointer\ndereference.\n\nFix both issues by deferring the assignment of i2c_imx-\u003eslave and\ni2c_imx-\u003elast_slave_event to after a successful resume, and by\nperforming the assignment inside the slave_lock critical section.\nThis guarantees that the slave pointer is never left stale on the\nerror path and is always valid when observed by the interrupt handler."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.4,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is in i2c_imx_reg_slave() reached from kernel i2c_slave_register() during driver probe/module bind on embedded i.MX platforms; concurrent exploitation requires local I2C bus activity on the same adapter to fire the shared IRQ handler during registration.\nAC:L - The attacker controls the race by driving I2C slave traffic to trigger i2c_imx_isr() while registration runs, and can retry across reboots, OTA reprobes, or pm_runtime resume cycles until the unprotected slave-pointer window is hit.\nPR:N - No Linux credentials are needed when a physically proximate attacker races automated boot-time or service-driven i2c_slave_register() calls (DT probe, IPMI SSIF/MCTP backends) on imx I2C slave-capable controllers.\nUI:N - Exploitation requires no victim interaction; automated driver probe, suspend/resume, or maintenance-triggered slave registration provides the registration side of the race without user action.\nS:U - Impact is confined to kernel memory safety violations and crash on the same host; this is not a VM escape, IOMMU bypass, or other cross-security-authority boundary.\nC:H - The ISR can dereference a NULL or stale i2c_imx-\u003eslave under slave_lock when the error path races registration, violating memory safety and enabling arbitrary kernel read primitives per CVSS race/UAF guidance.\nI:H - Concurrent ISR handling during partial slave registration can corrupt driver state and invoke slave callbacks with inconsistent pointers, enabling heap manipulation and arbitrary kernel write or control-flow hijack beyond a simple crash.\nA:H - NULL or stale slave dereference in i2c_imx_isr()/i2c_imx_slave_event() causes kernel oops/panic; leaving slave non-NULL after failed pm_runtime_resume_and_get() also blocks all subsequent slave registration (-EBUSY) on affected controllers."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-29T06:22:05.188Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/754bc62f72fd64b202462367134ac8ce95b005de"
},
{
"url": "https://git.kernel.org/stable/c/cfdf6e13518589f911b7eace6ccb788e4ed87397"
},
{
"url": "https://git.kernel.org/stable/c/b9f6f4883b9ac86654e75899d0dbf8a7a96ad5d8"
},
{
"url": "https://git.kernel.org/stable/c/d6748f6802f3eebafaa16a5e5dcfbfb9b3bc173f"
},
{
"url": "https://git.kernel.org/stable/c/12a4f0950a158d98552cbaeacc35edccd8d975fa"
},
{
"url": "https://git.kernel.org/stable/c/614ca6594e301ff682999797c2216e9685558a2b"
},
{
"url": "https://git.kernel.org/stable/c/d64ec362c369bbc33833f7936d5f3a706b0d5c45"
}
],
"title": "i2c: imx: Fix slave registration race and error handling",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80678",
"datePublished": "2026-08-28T06:52:47.077Z",
"dateReserved": "2026-08-26T14:34:25.783Z",
"dateUpdated": "2026-08-29T06:22:05.188Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68413 (GCVE-0-2026-68413)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-19 16:35
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one()
The memory allocated in the ipw2100_alloc_device() function is not freed
in some of the error paths in ipw2100_pci_init_one(). Fix that by
converting the direct return into a goto to the error path return.
The error path when pci_enable_device() fails cannot jump to fail, since
at this point priv is not set, so perform error handling inline.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 2c86c275015c880e810830304a3a4ab94803b38b Version: 2c86c275015c880e810830304a3a4ab94803b38b Version: 2c86c275015c880e810830304a3a4ab94803b38b Version: 2c86c275015c880e810830304a3a4ab94803b38b Version: 2c86c275015c880e810830304a3a4ab94803b38b Version: 2c86c275015c880e810830304a3a4ab94803b38b Version: 2c86c275015c880e810830304a3a4ab94803b38b Version: 2c86c275015c880e810830304a3a4ab94803b38b |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/intel/ipw2x00/ipw2100.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "71614326ab43e8b8f392ba865aeb6d7e327dff7d",
"status": "affected",
"version": "2c86c275015c880e810830304a3a4ab94803b38b",
"versionType": "git"
},
{
"lessThan": "9b080198a22fd809c4e7f6793eafab53ac2643fd",
"status": "affected",
"version": "2c86c275015c880e810830304a3a4ab94803b38b",
"versionType": "git"
},
{
"lessThan": "768a701362a8f77b62c14f8202ad559b7ecbb0c6",
"status": "affected",
"version": "2c86c275015c880e810830304a3a4ab94803b38b",
"versionType": "git"
},
{
"lessThan": "f75b9a2a9d8334ae0f9c5e47df7b31f7aeb1fdbe",
"status": "affected",
"version": "2c86c275015c880e810830304a3a4ab94803b38b",
"versionType": "git"
},
{
"lessThan": "836a19c654dcb1b01878a70090af016fbd0fd7e5",
"status": "affected",
"version": "2c86c275015c880e810830304a3a4ab94803b38b",
"versionType": "git"
},
{
"lessThan": "f442e581a88937671a22ceb3806c186265ef6254",
"status": "affected",
"version": "2c86c275015c880e810830304a3a4ab94803b38b",
"versionType": "git"
},
{
"lessThan": "7cbda50eebcd9aa00b0de382f776287cf7a36cf8",
"status": "affected",
"version": "2c86c275015c880e810830304a3a4ab94803b38b",
"versionType": "git"
},
{
"lessThan": "0d388f62031dbabcba0f44bb91b59f10e88cac17",
"status": "affected",
"version": "2c86c275015c880e810830304a3a4ab94803b38b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/intel/ipw2x00/ipw2100.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.14"
},
{
"lessThan": "2.6.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one()\n\nThe memory allocated in the ipw2100_alloc_device() function is not freed\nin some of the error paths in ipw2100_pci_init_one(). Fix that by\nconverting the direct return into a goto to the error path return.\n\nThe error path when pci_enable_device() fails cannot jump to fail, since\nat this point priv is not set, so perform error handling inline."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:35:10.167Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/71614326ab43e8b8f392ba865aeb6d7e327dff7d"
},
{
"url": "https://git.kernel.org/stable/c/9b080198a22fd809c4e7f6793eafab53ac2643fd"
},
{
"url": "https://git.kernel.org/stable/c/768a701362a8f77b62c14f8202ad559b7ecbb0c6"
},
{
"url": "https://git.kernel.org/stable/c/f75b9a2a9d8334ae0f9c5e47df7b31f7aeb1fdbe"
},
{
"url": "https://git.kernel.org/stable/c/836a19c654dcb1b01878a70090af016fbd0fd7e5"
},
{
"url": "https://git.kernel.org/stable/c/f442e581a88937671a22ceb3806c186265ef6254"
},
{
"url": "https://git.kernel.org/stable/c/7cbda50eebcd9aa00b0de382f776287cf7a36cf8"
},
{
"url": "https://git.kernel.org/stable/c/0d388f62031dbabcba0f44bb91b59f10e88cac17"
}
],
"title": "wifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68413",
"datePublished": "2026-08-10T12:04:33.525Z",
"dateReserved": "2026-07-30T09:28:09.391Z",
"dateUpdated": "2026-08-19T16:35:10.167Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74512 (GCVE-0-2026-74512)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-19 16:38
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
audit: fix potential use-after-free in audit_del_rule()
`audit_del_rule()` destroys `e->rule.exe` via `audit_remove_mark_rule()`
before unlinking the rule from RCU-visible filter lists and waiting for a
grace period. Concurrent readers in `audit_filter()` and
`audit_filter_rules()` still dereference `e->rule.exe`, while the fsnotify
mark can be freed on an independent lifetime path. This creates a
use-after-free window during rule deletion.
Fix this by unlinking the rule from the RCU-visible lists and invoking
`synchronize_rcu()` before calling `audit_remove_mark_rule()` (and other
rule removal helpers). This ensures that all existing RCU readers have
exited the critical section before any underlying resources are destroyed.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 34d99af52ad40bd498ba66970579a5bc1fb1a3bc Version: 34d99af52ad40bd498ba66970579a5bc1fb1a3bc Version: 34d99af52ad40bd498ba66970579a5bc1fb1a3bc Version: 34d99af52ad40bd498ba66970579a5bc1fb1a3bc Version: 34d99af52ad40bd498ba66970579a5bc1fb1a3bc Version: 34d99af52ad40bd498ba66970579a5bc1fb1a3bc Version: 34d99af52ad40bd498ba66970579a5bc1fb1a3bc Version: 34d99af52ad40bd498ba66970579a5bc1fb1a3bc |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"kernel/auditfilter.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "93616c567469510b7bba55b2674e0c4523fd7e64",
"status": "affected",
"version": "34d99af52ad40bd498ba66970579a5bc1fb1a3bc",
"versionType": "git"
},
{
"lessThan": "3f82927b399d7a276c0c12b6ff4424b747a0c9a7",
"status": "affected",
"version": "34d99af52ad40bd498ba66970579a5bc1fb1a3bc",
"versionType": "git"
},
{
"lessThan": "8ae135a8962be9d4e8a131eb18eb06cdf02a47ce",
"status": "affected",
"version": "34d99af52ad40bd498ba66970579a5bc1fb1a3bc",
"versionType": "git"
},
{
"lessThan": "45bf3df5b32e5a49953e7ceabc55f7dd85380e46",
"status": "affected",
"version": "34d99af52ad40bd498ba66970579a5bc1fb1a3bc",
"versionType": "git"
},
{
"lessThan": "78bde7e9bd36eaae1b8e8cfcd47f12a34f301dbf",
"status": "affected",
"version": "34d99af52ad40bd498ba66970579a5bc1fb1a3bc",
"versionType": "git"
},
{
"lessThan": "cae0dfed5d307b240bff71c3cf206652d1b6f215",
"status": "affected",
"version": "34d99af52ad40bd498ba66970579a5bc1fb1a3bc",
"versionType": "git"
},
{
"lessThan": "5b8f46864f06d6dbacb7dcea52bc084dfd122638",
"status": "affected",
"version": "34d99af52ad40bd498ba66970579a5bc1fb1a3bc",
"versionType": "git"
},
{
"lessThan": "246df90b5f1a8a6e6abbd2f058b029558720adec",
"status": "affected",
"version": "34d99af52ad40bd498ba66970579a5bc1fb1a3bc",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"kernel/auditfilter.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.3"
},
{
"lessThan": "4.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\naudit: fix potential use-after-free in audit_del_rule()\n\n`audit_del_rule()` destroys `e-\u003erule.exe` via `audit_remove_mark_rule()`\nbefore unlinking the rule from RCU-visible filter lists and waiting for a\ngrace period. Concurrent readers in `audit_filter()` and\n`audit_filter_rules()` still dereference `e-\u003erule.exe`, while the fsnotify\nmark can be freed on an independent lifetime path. This creates a\nuse-after-free window during rule deletion.\n\nFix this by unlinking the rule from the RCU-visible lists and invoking\n`synchronize_rcu()` before calling `audit_remove_mark_rule()` (and other\nrule removal helpers). This ensures that all existing RCU readers have\nexited the critical section before any underlying resources are destroyed."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Reachable only via local NETLINK_AUDIT (AUDIT_DEL_RULE) or filesystem events that autoremove AUDIT_EXE rules; concurrent UAF readers run in syscall/io_uring exit audit filtering on the local host, not from remote network input.\nAC:L - The attacker controls both sides of the race by deleting an AUDIT_EXE rule (auditctl or deleting/moving the audited executable) while driving concurrent syscall/io_uring activity to keep RCU readers in audit_filter()/audit_filter_rules().\nPR:L - Besides CAP_AUDIT_CONTROL netlink deletion, unprivileged local users can trigger audit_del_rule() via fsnotify autoremove when deleting/moving an admin-configured audited executable they can write, without init-namespace root.\nUI:N - Exploitation requires no victim interaction; the attacker schedules rule deletion and concurrent audited syscalls/io_uring exits to hit the UAF window.\nS:U - Impact is kernel heap memory corruption and local privilege escalation within the host kernel security domain, not a documented cross-VM or IOMMU boundary escape.\nC:H - Use-after-free of audit_fsnotify_mark while audit_exe_compare()/audit_mark_compare() dereference mark-\u003eino/dev enables arbitrary kernel memory reads and info disclosure primitives.\nI:H - Freed fsnotify mark objects can be reallocated and corrupted to obtain arbitrary kernel writes, control-flow hijack, and local root code execution beyond audit rule deletion.\nA:H - Concurrent dereference of a freed audit_fsnotify_mark during audit filtering can immediately oops/panic the kernel; repeated triggering yields reliable denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:38:09.879Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/93616c567469510b7bba55b2674e0c4523fd7e64"
},
{
"url": "https://git.kernel.org/stable/c/3f82927b399d7a276c0c12b6ff4424b747a0c9a7"
},
{
"url": "https://git.kernel.org/stable/c/8ae135a8962be9d4e8a131eb18eb06cdf02a47ce"
},
{
"url": "https://git.kernel.org/stable/c/45bf3df5b32e5a49953e7ceabc55f7dd85380e46"
},
{
"url": "https://git.kernel.org/stable/c/78bde7e9bd36eaae1b8e8cfcd47f12a34f301dbf"
},
{
"url": "https://git.kernel.org/stable/c/cae0dfed5d307b240bff71c3cf206652d1b6f215"
},
{
"url": "https://git.kernel.org/stable/c/5b8f46864f06d6dbacb7dcea52bc084dfd122638"
},
{
"url": "https://git.kernel.org/stable/c/246df90b5f1a8a6e6abbd2f058b029558720adec"
}
],
"title": "audit: fix potential use-after-free in audit_del_rule()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74512",
"datePublished": "2026-08-15T12:27:33.736Z",
"dateReserved": "2026-08-15T05:44:03.909Z",
"dateUpdated": "2026-08-19T16:38:09.879Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68162 (GCVE-0-2026-68162)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
sctp: avoid auth_enable sysctl UAF during netns teardown
proc_sctp_do_auth() updates the SCTP control socket after changing
net.sctp.auth_enable. The handler gets the per-net SCTP state from
ctl->data, so an already opened sysctl file can still target a network
namespace while that namespace is being torn down.
SCTP previously registered its per-net sysctls from sctp_defaults_init(),
while the control socket is created later from sctp_ctrlsock_init(). This
exposed a window during initialization where auth_enable was writable
before net->sctp.ctl_sock existed, and a teardown window where auth_enable
stayed writable after inet_ctl_sock_destroy() had released the control
socket.
Move the per-net SCTP sysctl registration into sctp_ctrlsock_init() after
sctp_ctl_sock_init() succeeds, and unregister the sysctl table before
destroying the control socket in sctp_ctrlsock_exit(). If sysctl
registration fails after the control socket was created, destroy the
control socket in the same init path.
Make sctp_sysctl_net_unregister() tolerate a missing header and clear the
saved pointer so init-error and exit paths can safely share the unregister
helper.
References
| URL | Tags | ||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 10c869a52f266e40f548cc3c565d14930a5edafc Version: dc583e7e5f8515ca489c0df28e4362a70eade382 Version: bd2a2939423566c654545fa3e96a656662a0af9e Version: 1b67030d39f2b00f94ac1f0af11ba6657589e4d3 Version: 7ec30c54f339c640aa7e49d7e9f7bbed6bd42bf6 Version: c184bc621e3cef03ac9ba81a50dda2dae6a21d36 Version: 15649fd5415eda664ef35780c2013adeb5d9c695 Version: 15649fd5415eda664ef35780c2013adeb5d9c695 Version: 15649fd5415eda664ef35780c2013adeb5d9c695 Version: 5.4.290 ≤ Version: 5.10.234 ≤ Version: 5.15.177 ≤ Version: 6.1.125 ≤ Version: 6.6.72 ≤ Version: 6.12.10 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/sctp/protocol.c",
"net/sctp/sysctl.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "19573dcddb8819fd68d6cd1f916c1c99c3fa4ff4",
"status": "affected",
"version": "10c869a52f266e40f548cc3c565d14930a5edafc",
"versionType": "git"
},
{
"lessThan": "ceb7190b5c873d4a1267a1600c5aa52c600e929f",
"status": "affected",
"version": "dc583e7e5f8515ca489c0df28e4362a70eade382",
"versionType": "git"
},
{
"lessThan": "fd66854a22661929245f3d2b244c432bc8b1a150",
"status": "affected",
"version": "bd2a2939423566c654545fa3e96a656662a0af9e",
"versionType": "git"
},
{
"lessThan": "158f3cc332dc53f43ec20060233d7c3cecd6d912",
"status": "affected",
"version": "1b67030d39f2b00f94ac1f0af11ba6657589e4d3",
"versionType": "git"
},
{
"lessThan": "66700c0719675e0e118ae83b2d7168dacd69dd3d",
"status": "affected",
"version": "7ec30c54f339c640aa7e49d7e9f7bbed6bd42bf6",
"versionType": "git"
},
{
"lessThan": "626bda8cfe43dff19a9833ff6ba055a817b5455c",
"status": "affected",
"version": "c184bc621e3cef03ac9ba81a50dda2dae6a21d36",
"versionType": "git"
},
{
"lessThan": "be6aae9d1b91c603adb35872d37d40e83daf8758",
"status": "affected",
"version": "15649fd5415eda664ef35780c2013adeb5d9c695",
"versionType": "git"
},
{
"lessThan": "a50e73488e0bbdd262b3be3c9a1d8dd078382381",
"status": "affected",
"version": "15649fd5415eda664ef35780c2013adeb5d9c695",
"versionType": "git"
},
{
"lessThan": "f8d5e7846025f4ab15a461235f8ebae9094a361a",
"status": "affected",
"version": "15649fd5415eda664ef35780c2013adeb5d9c695",
"versionType": "git"
},
{
"lessThan": "5.4.292",
"status": "affected",
"version": "5.4.290",
"versionType": "semver"
},
{
"lessThan": "5.10.266",
"status": "affected",
"version": "5.10.234",
"versionType": "semver"
},
{
"lessThan": "5.15.217",
"status": "affected",
"version": "5.15.177",
"versionType": "semver"
},
{
"lessThan": "6.1.184",
"status": "affected",
"version": "6.1.125",
"versionType": "semver"
},
{
"lessThan": "6.6.151",
"status": "affected",
"version": "6.6.72",
"versionType": "semver"
},
{
"lessThan": "6.12.101",
"status": "affected",
"version": "6.12.10",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/sctp/protocol.c",
"net/sctp/sysctl.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.13"
},
{
"lessThan": "6.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.4.*",
"status": "unaffected",
"version": "5.4.292",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.4.292",
"versionStartIncluding": "5.4.290",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "5.10.234",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.15.177",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "6.1.125",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "6.6.72",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.12.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: avoid auth_enable sysctl UAF during netns teardown\n\nproc_sctp_do_auth() updates the SCTP control socket after changing\nnet.sctp.auth_enable. The handler gets the per-net SCTP state from\nctl-\u003edata, so an already opened sysctl file can still target a network\nnamespace while that namespace is being torn down.\n\nSCTP previously registered its per-net sysctls from sctp_defaults_init(),\nwhile the control socket is created later from sctp_ctrlsock_init(). This\nexposed a window during initialization where auth_enable was writable\nbefore net-\u003esctp.ctl_sock existed, and a teardown window where auth_enable\nstayed writable after inet_ctl_sock_destroy() had released the control\nsocket.\n\nMove the per-net SCTP sysctl registration into sctp_ctrlsock_init() after\nsctp_ctl_sock_init() succeeds, and unregister the sysctl table before\ndestroying the control socket in sctp_ctrlsock_exit(). If sysctl\nregistration fails after the control socket was created, destroy the\ncontrol socket in the same init path.\n\nMake sctp_sysctl_net_unregister() tolerate a missing header and clear the\nsaved pointer so init-error and exit paths can safely share the unregister\nhelper."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is triggered only by writing the per-net sysctl net.sctp.auth_enable via /proc/sys (proc_sctp_do_auth); it is not reachable from SCTP packet receive, sockets, or other remote protocol paths.\nAC:L - An attacker can open the sysctl file, concurrently destroy the target network namespace, and repeatedly write during teardown; pernet exit destroys ctl_sock before unregistering sysctls, and the attacker controls both sides of that race.\nPR:L - Exploitation requires writing a mode 0644 sysctl in a network namespace; an unprivileged host user with CAP_NET_ADMIN via user namespaces can create a netns, become namespace root, and write net/sctp/auth_enable without init-namespace privileges.\nUI:N - No victim interaction is required beyond the attacker opening the sysctl and triggering namespace teardown in their own threads or processes.\nS:U - Impact is confined to kernel memory corruption and privilege escalation within the same host/kernel security domain; it does not cross VM, container, or IOMMU boundaries by itself.\nC:H - proc_sctp_do_auth dereferences net-\u003esctp.ctl_sock after inet_ctl_sock_destroy; lock_sock and sctp_sk(sk)-\u003eep access freed socket/endpoint memory, a use-after-free that can disclose or infer heap contents.\nI:H - On a successful write, the handler sets sctp_sk(sk)-\u003eep-\u003eauth_enable on a freed endpoint object, giving a controlled heap write primitive that can be developed into arbitrary kernel modification or code execution.\nA:H - Use-after-free on the SCTP control socket/endpoint during sysctl processing can cause kernel oops/panic from lock_sock or ep access on freed memory, even when full exploitation is not attempted."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:01.222Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/19573dcddb8819fd68d6cd1f916c1c99c3fa4ff4"
},
{
"url": "https://git.kernel.org/stable/c/ceb7190b5c873d4a1267a1600c5aa52c600e929f"
},
{
"url": "https://git.kernel.org/stable/c/fd66854a22661929245f3d2b244c432bc8b1a150"
},
{
"url": "https://git.kernel.org/stable/c/158f3cc332dc53f43ec20060233d7c3cecd6d912"
},
{
"url": "https://git.kernel.org/stable/c/66700c0719675e0e118ae83b2d7168dacd69dd3d"
},
{
"url": "https://git.kernel.org/stable/c/626bda8cfe43dff19a9833ff6ba055a817b5455c"
},
{
"url": "https://git.kernel.org/stable/c/be6aae9d1b91c603adb35872d37d40e83daf8758"
},
{
"url": "https://git.kernel.org/stable/c/a50e73488e0bbdd262b3be3c9a1d8dd078382381"
},
{
"url": "https://git.kernel.org/stable/c/f8d5e7846025f4ab15a461235f8ebae9094a361a"
}
],
"title": "sctp: avoid auth_enable sysctl UAF during netns teardown",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68162",
"datePublished": "2026-08-10T11:59:29.099Z",
"dateReserved": "2026-07-30T09:28:09.372Z",
"dateUpdated": "2026-08-23T12:46:01.222Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80892 (GCVE-0-2026-80892)
Vulnerability from cvelistv5
Published
2026-09-04 17:11
Modified
2026-09-04 17:11
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
erofs: cap LZMA stream pool size
fs/erofs/decompressor_lzma.c sizes the module-global MicroLZMA stream
pool from num_possible_cpus() when the lzma_streams module parameter is
unset, then z_erofs_load_lzma_config() preallocates one image-supplied
dictionary per stream, accepting dictionaries up to 8 MiB. On high-CPU
systems, a small EROFS image can pin hundreds of MiB of vmalloc-backed
decoder state until the erofs module is unloaded.
Impact: An EROFS image mounted by the system can pin up to 8 MiB of
vmalloc memory per LZMA stream, either as intended or unexpectedly.
Bound the default stream count by a new
CONFIG_EROFS_FS_ZIP_LZMA_DEFAULT_MAX_STREAMS option, default 16, so the
worst-case default preallocation is 128 MiB if the number of CPUs is no
less than 16 while preserving the existing per-image dictionary limit.
An explicit lzma_streams module parameter is still honoured as-is, so
administrators who deliberately size the pool are not affected.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 622ceaddb7649ca328832f50ba1400af778d75fa Version: 622ceaddb7649ca328832f50ba1400af778d75fa Version: 622ceaddb7649ca328832f50ba1400af778d75fa Version: 622ceaddb7649ca328832f50ba1400af778d75fa Version: 622ceaddb7649ca328832f50ba1400af778d75fa Version: 622ceaddb7649ca328832f50ba1400af778d75fa |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/erofs/Kconfig",
"fs/erofs/decompressor_lzma.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "682cb3ece37fc5141e73bc726ccf4adb833e5189",
"status": "affected",
"version": "622ceaddb7649ca328832f50ba1400af778d75fa",
"versionType": "git"
},
{
"lessThan": "e8b3d09aa8889dda9be9cbb3d2f0218c4b9acde4",
"status": "affected",
"version": "622ceaddb7649ca328832f50ba1400af778d75fa",
"versionType": "git"
},
{
"lessThan": "0c676903cb2a61992ded8e7907609cc6b0f11744",
"status": "affected",
"version": "622ceaddb7649ca328832f50ba1400af778d75fa",
"versionType": "git"
},
{
"lessThan": "5aaa06dfc10f8398c8807453dbec738ea9af10e4",
"status": "affected",
"version": "622ceaddb7649ca328832f50ba1400af778d75fa",
"versionType": "git"
},
{
"lessThan": "e52da169b8c0d19bb2d803f2a07fe0e5a00462d6",
"status": "affected",
"version": "622ceaddb7649ca328832f50ba1400af778d75fa",
"versionType": "git"
},
{
"lessThan": "c9b47e6b23114e939b17f818471c7a46e59006e7",
"status": "affected",
"version": "622ceaddb7649ca328832f50ba1400af778d75fa",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/erofs/Kconfig",
"fs/erofs/decompressor_lzma.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.16"
},
{
"lessThan": "5.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.16",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nerofs: cap LZMA stream pool size\n\nfs/erofs/decompressor_lzma.c sizes the module-global MicroLZMA stream\npool from num_possible_cpus() when the lzma_streams module parameter is\nunset, then z_erofs_load_lzma_config() preallocates one image-supplied\ndictionary per stream, accepting dictionaries up to 8 MiB. On high-CPU\nsystems, a small EROFS image can pin hundreds of MiB of vmalloc-backed\ndecoder state until the erofs module is unloaded.\n\nImpact: An EROFS image mounted by the system can pin up to 8 MiB of\nvmalloc memory per LZMA stream, either as intended or unexpectedly.\n\nBound the default stream count by a new\nCONFIG_EROFS_FS_ZIP_LZMA_DEFAULT_MAX_STREAMS option, default 16, so the\nworst-case default preallocation is 128 MiB if the number of CPUs is no\nless than 16 while preserving the existing per-image dictionary limit.\nAn explicit lzma_streams module parameter is still honoured as-is, so\nadministrators who deliberately size the pool are not affected."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T17:11:08.391Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/682cb3ece37fc5141e73bc726ccf4adb833e5189"
},
{
"url": "https://git.kernel.org/stable/c/e8b3d09aa8889dda9be9cbb3d2f0218c4b9acde4"
},
{
"url": "https://git.kernel.org/stable/c/0c676903cb2a61992ded8e7907609cc6b0f11744"
},
{
"url": "https://git.kernel.org/stable/c/5aaa06dfc10f8398c8807453dbec738ea9af10e4"
},
{
"url": "https://git.kernel.org/stable/c/e52da169b8c0d19bb2d803f2a07fe0e5a00462d6"
},
{
"url": "https://git.kernel.org/stable/c/c9b47e6b23114e939b17f818471c7a46e59006e7"
}
],
"title": "erofs: cap LZMA stream pool size",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80892",
"datePublished": "2026-09-04T17:11:08.391Z",
"dateReserved": "2026-08-26T14:34:25.800Z",
"dateUpdated": "2026-09-04T17:11:08.391Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68146 (GCVE-0-2026-68146)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-23 12:45
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ftrace: Add global mutex to serialize trace_parser access
In ftrace, the trace_parser structure is allocated and initialized when
a trace file is opened, and is subsequently used across write and release
handlers to parse user input.
The affected handler paths and their specific functions are:
- Open paths: ftrace_regex_open(), ftrace_graph_open()
- Write paths: ftrace_regex_write(), ftrace_graph_write()
- Release paths: ftrace_regex_release(), ftrace_graph_release()
If userspace opens a trace file descriptor and shares it across multiple
threads, concurrent write calls will race on the parser's internal state,
specifically the 'idx', 'cont', and 'buffer' fields, leading to corrupted
input or undefined behavior.
Fix this by adding a global mutex, parser_lock, to serialize all access
to trace_parser across write and release paths, preventing concurrent
corruption of parser state.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 689fd8b65d669b96d612ccc37d6fb87bf7ed6907 Version: 689fd8b65d669b96d612ccc37d6fb87bf7ed6907 Version: 689fd8b65d669b96d612ccc37d6fb87bf7ed6907 Version: 689fd8b65d669b96d612ccc37d6fb87bf7ed6907 Version: 689fd8b65d669b96d612ccc37d6fb87bf7ed6907 Version: 689fd8b65d669b96d612ccc37d6fb87bf7ed6907 Version: 689fd8b65d669b96d612ccc37d6fb87bf7ed6907 Version: 689fd8b65d669b96d612ccc37d6fb87bf7ed6907 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"kernel/trace/ftrace.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a29bc20ea5f0cb79c6287f2c6182c5eeb8e6c01f",
"status": "affected",
"version": "689fd8b65d669b96d612ccc37d6fb87bf7ed6907",
"versionType": "git"
},
{
"lessThan": "db76744d588086695371ecdd982694395628ba48",
"status": "affected",
"version": "689fd8b65d669b96d612ccc37d6fb87bf7ed6907",
"versionType": "git"
},
{
"lessThan": "1474fe4453505b6be720b5bb94be1c927de3314a",
"status": "affected",
"version": "689fd8b65d669b96d612ccc37d6fb87bf7ed6907",
"versionType": "git"
},
{
"lessThan": "3d0dd138a06c782f8b755cd1b6f9909494514ce1",
"status": "affected",
"version": "689fd8b65d669b96d612ccc37d6fb87bf7ed6907",
"versionType": "git"
},
{
"lessThan": "90be137813e1a5bdfd671e40fe28004fb959d3e4",
"status": "affected",
"version": "689fd8b65d669b96d612ccc37d6fb87bf7ed6907",
"versionType": "git"
},
{
"lessThan": "65bf73bee1a4f3722208ae46afc0fa5de76b9a0a",
"status": "affected",
"version": "689fd8b65d669b96d612ccc37d6fb87bf7ed6907",
"versionType": "git"
},
{
"lessThan": "e807c9193d9493c7a0d039158ebb955050a76df1",
"status": "affected",
"version": "689fd8b65d669b96d612ccc37d6fb87bf7ed6907",
"versionType": "git"
},
{
"lessThan": "7720b63bcef3f54c7fe288774b720a227d54a306",
"status": "affected",
"version": "689fd8b65d669b96d612ccc37d6fb87bf7ed6907",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"kernel/trace/ftrace.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.32"
},
{
"lessThan": "2.6.32",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "2.6.32",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "2.6.32",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.32",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.32",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.32",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.32",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.32",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.32",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nftrace: Add global mutex to serialize trace_parser access\n\nIn ftrace, the trace_parser structure is allocated and initialized when\na trace file is opened, and is subsequently used across write and release\nhandlers to parse user input.\n\nThe affected handler paths and their specific functions are:\n - Open paths: ftrace_regex_open(), ftrace_graph_open()\n - Write paths: ftrace_regex_write(), ftrace_graph_write()\n - Release paths: ftrace_regex_release(), ftrace_graph_release()\n\nIf userspace opens a trace file descriptor and shares it across multiple\nthreads, concurrent write calls will race on the parser\u0027s internal state,\nspecifically the \u0027idx\u0027, \u0027cont\u0027, and \u0027buffer\u0027 fields, leading to corrupted\ninput or undefined behavior.\n\nFix this by adding a global mutex, parser_lock, to serialize all access\nto trace_parser across write and release paths, preventing concurrent\ncorruption of parser state."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:45:57.951Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a29bc20ea5f0cb79c6287f2c6182c5eeb8e6c01f"
},
{
"url": "https://git.kernel.org/stable/c/db76744d588086695371ecdd982694395628ba48"
},
{
"url": "https://git.kernel.org/stable/c/1474fe4453505b6be720b5bb94be1c927de3314a"
},
{
"url": "https://git.kernel.org/stable/c/3d0dd138a06c782f8b755cd1b6f9909494514ce1"
},
{
"url": "https://git.kernel.org/stable/c/90be137813e1a5bdfd671e40fe28004fb959d3e4"
},
{
"url": "https://git.kernel.org/stable/c/65bf73bee1a4f3722208ae46afc0fa5de76b9a0a"
},
{
"url": "https://git.kernel.org/stable/c/e807c9193d9493c7a0d039158ebb955050a76df1"
},
{
"url": "https://git.kernel.org/stable/c/7720b63bcef3f54c7fe288774b720a227d54a306"
}
],
"title": "ftrace: Add global mutex to serialize trace_parser access",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68146",
"datePublished": "2026-08-10T11:59:11.273Z",
"dateReserved": "2026-07-30T09:28:09.371Z",
"dateUpdated": "2026-08-23T12:45:57.951Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68143 (GCVE-0-2026-68143)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: slip: serialize receive against buffer reallocation
sl_realloc_bufs() replaces rbuff and updates buffsize while holding
sl->lock. slip_receive_buf() reads those fields and writes through rbuff
without holding the lock.
An MTU change can therefore race with receive processing. An MTU shrink
can expose the new smaller rbuff with the old larger bound, causing an
out-of-bounds write. A receive callback which already loaded the old
rbuff can instead continue writing after that buffer has been freed.
Serialize receive processing with sl_realloc_bufs() by holding sl->lock
while consuming each receive batch.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/slip/slip.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "8180daf2b66155f84ec4f9e3f95488c8a3421716",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "189a550eb7e1dc10018718ddfc46d003ffe58653",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "1be09d175b627fad7f6bec7ad27b8a4a99863912",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "eb3836eab47487823f362e6985e170a1e15f20fd",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "44401f7dd9940ced7098930ef64f5a332f279fc2",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "5d07b178bef511d69558cfc89fe1129258dc39f8",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "0e37bbd6d617eb52bace49390e99eaedc1af73ce",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "ee7f9bb9320add61f7b367d7e6cd55e3a3a4d65d",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/slip/slip.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: slip: serialize receive against buffer reallocation\n\nsl_realloc_bufs() replaces rbuff and updates buffsize while holding\nsl-\u003elock. slip_receive_buf() reads those fields and writes through rbuff\nwithout holding the lock.\n\nAn MTU change can therefore race with receive processing. An MTU shrink\ncan expose the new smaller rbuff with the old larger bound, causing an\nout-of-bounds write. A receive callback which already loaded the old\nrbuff can instead continue writing after that buffer has been freed.\n\nSerialize receive processing with sl_realloc_bufs() by holding sl-\u003elock\nwhile consuming each receive batch."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is in the SLIP TTY line discipline; triggering the MTU shrink/realloc race requires SIOCSIFMTU/RTM_SETLINK (CAP_NET_ADMIN) on the host, so a single attacker must have local access even if SLIP frames arrive over a serial backhaul.\nAC:L - An attacker with CAP_NET_ADMIN can concurrently hammer MTU changes via ioctl/rtnetlink and inject SLIP frames on the bound TTY/PTY, controlling both sides of the race without depending on uncontrollable timing.\nPR:L - SIOCSIFMTU requires CAP_NET_ADMIN in the interface network namespace, obtainable by an unprivileged user via user namespaces; exploitation targets already-active SLIP links and does not repeat slip_open()\u0027s init-namespace check.\nUI:N - No end-user or administrator interaction is required during exploitation once a SLIP interface is active; the attacker drives both MTU reallocation and receive processing directly.\nS:U - Heap corruption is confined to kernel SLIP receive buffers and adjacent kmalloc objects; impact is standard kernel memory corruption and local privilege escalation, not a cross-VM or sandbox boundary escape.\nC:H - The race yields heap out-of-bounds writes and use-after-free writes on freed rbuff kmalloc objects; per kernel guidance, this class of memory corruption enables arbitrary kernel memory disclosure.\nI:H - Writing past the reallocated rbuff boundary or into a freed buffer corrupts adjacent heap metadata/objects, providing primitives for arbitrary kernel writes and control-flow hijacking.\nA:H - Out-of-bounds and use-after-free corruption of kernel heap memory reliably causes kernel oops/panic during the race even when not fully weaponized for code execution."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:30:04.807Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/8180daf2b66155f84ec4f9e3f95488c8a3421716"
},
{
"url": "https://git.kernel.org/stable/c/189a550eb7e1dc10018718ddfc46d003ffe58653"
},
{
"url": "https://git.kernel.org/stable/c/1be09d175b627fad7f6bec7ad27b8a4a99863912"
},
{
"url": "https://git.kernel.org/stable/c/eb3836eab47487823f362e6985e170a1e15f20fd"
},
{
"url": "https://git.kernel.org/stable/c/44401f7dd9940ced7098930ef64f5a332f279fc2"
},
{
"url": "https://git.kernel.org/stable/c/5d07b178bef511d69558cfc89fe1129258dc39f8"
},
{
"url": "https://git.kernel.org/stable/c/0e37bbd6d617eb52bace49390e99eaedc1af73ce"
},
{
"url": "https://git.kernel.org/stable/c/ee7f9bb9320add61f7b367d7e6cd55e3a3a4d65d"
}
],
"title": "net: slip: serialize receive against buffer reallocation",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68143",
"datePublished": "2026-08-10T11:59:07.354Z",
"dateReserved": "2026-07-30T09:28:09.370Z",
"dateUpdated": "2026-08-19T16:30:04.807Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80829 (GCVE-0-2026-80829)
Vulnerability from cvelistv5
Published
2026-09-04 15:54
Modified
2026-09-04 15:54
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output()
snd_usbmidi_novation_output() lays out a two-byte header at
transfer_buffer[0..1] and passes &transfer_buffer[2] together with a
length of ep->max_transfer - 2 to snd_rawmidi_transmit():
count = snd_rawmidi_transmit(ep->ports[0].substream,
&transfer_buffer[2],
ep->max_transfer - 2);
ep->max_transfer comes from the output endpoint's wMaxPacketSize via
usb_maxpacket(). A malformed or malicious device can advertise a bulk
OUT endpoint with a wMaxPacketSize of 1 - the USB core only clamps this
value downwards - so ep->max_transfer becomes 1 and the count argument
becomes -1.
snd_rawmidi_transmit() passes the negative count on to
__snd_rawmidi_transmit_peek(), where "if (count1 > count) count1 = count"
leaves count1 negative; get_aligned_size() keeps it negative for a
byte-stream substream, so the following memcpy(buffer, ..., count1) runs
with a (size_t)-1 length and writes far past the transfer buffer, which
was allocated with usb_alloc_coherent(ep->max_transfer).
This is the same class of bug that was fixed for snd_usbmidi_akai_output()
in commit 0970274613fb ("ALSA: usb-audio: fix OOB write in
snd_usbmidi_akai_output()"); the novation output routine was left
unguarded. Bail out when the endpoint cannot hold the two-byte header
plus at least one payload byte.
References
| URL | Tags | ||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"sound/usb/midi.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "558fc4485ecc704edfe7876d6cebae4738ff7ef8",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "9c8212436631b0063cb021e9f58df438e3db84d0",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "e9c00d7533f99aa9833c4b598f47e3b3202fdb9a",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "94e4562fcc81badd1d467ddfb88c27e4fae974c2",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "7639ec9755d3ec0ec8cd7c0fdd2c3d3997434870",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "91919b3b99ab7ce3d7dbb39fcf7c6c742a663c0c",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "7f00dbddb51f4f74325cdc7c3f6b19fb3392481a",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "1074c2306901b44ebcb83855583c6776e1e392ea",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "1035a8f63bae28e498b0e7b5ac91d749844a7158",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"sound/usb/midi.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.269",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.220",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.187",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.156",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.108",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.49",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.13",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.3",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.269",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.220",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.187",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.156",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.108",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.49",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.13",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.3",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output()\n\nsnd_usbmidi_novation_output() lays out a two-byte header at\ntransfer_buffer[0..1] and passes \u0026transfer_buffer[2] together with a\nlength of ep-\u003emax_transfer - 2 to snd_rawmidi_transmit():\n\n\tcount = snd_rawmidi_transmit(ep-\u003eports[0].substream,\n\t\t\t\t \u0026transfer_buffer[2],\n\t\t\t\t ep-\u003emax_transfer - 2);\n\nep-\u003emax_transfer comes from the output endpoint\u0027s wMaxPacketSize via\nusb_maxpacket(). A malformed or malicious device can advertise a bulk\nOUT endpoint with a wMaxPacketSize of 1 - the USB core only clamps this\nvalue downwards - so ep-\u003emax_transfer becomes 1 and the count argument\nbecomes -1.\n\nsnd_rawmidi_transmit() passes the negative count on to\n__snd_rawmidi_transmit_peek(), where \"if (count1 \u003e count) count1 = count\"\nleaves count1 negative; get_aligned_size() keeps it negative for a\nbyte-stream substream, so the following memcpy(buffer, ..., count1) runs\nwith a (size_t)-1 length and writes far past the transfer buffer, which\nwas allocated with usb_alloc_coherent(ep-\u003emax_transfer).\n\nThis is the same class of bug that was fixed for snd_usbmidi_akai_output()\nin commit 0970274613fb (\"ALSA: usb-audio: fix OOB write in\nsnd_usbmidi_akai_output()\"); the novation output routine was left\nunguarded. Bail out when the endpoint cannot hold the two-byte header\nplus at least one payload byte."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T15:54:33.981Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/558fc4485ecc704edfe7876d6cebae4738ff7ef8"
},
{
"url": "https://git.kernel.org/stable/c/9c8212436631b0063cb021e9f58df438e3db84d0"
},
{
"url": "https://git.kernel.org/stable/c/e9c00d7533f99aa9833c4b598f47e3b3202fdb9a"
},
{
"url": "https://git.kernel.org/stable/c/94e4562fcc81badd1d467ddfb88c27e4fae974c2"
},
{
"url": "https://git.kernel.org/stable/c/7639ec9755d3ec0ec8cd7c0fdd2c3d3997434870"
},
{
"url": "https://git.kernel.org/stable/c/91919b3b99ab7ce3d7dbb39fcf7c6c742a663c0c"
},
{
"url": "https://git.kernel.org/stable/c/7f00dbddb51f4f74325cdc7c3f6b19fb3392481a"
},
{
"url": "https://git.kernel.org/stable/c/1074c2306901b44ebcb83855583c6776e1e392ea"
},
{
"url": "https://git.kernel.org/stable/c/1035a8f63bae28e498b0e7b5ac91d749844a7158"
}
],
"title": "ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80829",
"datePublished": "2026-09-04T15:54:33.981Z",
"dateReserved": "2026-08-26T14:34:25.796Z",
"dateUpdated": "2026-09-04T15:54:33.981Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80756 (GCVE-0-2026-80756)
Vulnerability from cvelistv5
Published
2026-09-03 08:26
Modified
2026-09-03 08:26
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
selinux: do not cancel a policy conversion that never started
sel_write_load() calls selinux_policy_cancel() when sel_make_policy_nodes()
fails, and that helper dereferences the outgoing policy to cancel its
sidtab conversion. On the first policy load there is no outgoing policy:
security_load_policy() returns early for that case, before it converts
anything, and state->policy is still NULL. A first load that fails while
building the selinuxfs tree therefore takes a NULL dereference in
selinux_policy_cancel(), reached from a write(2) to /sys/fs/selinux/load.
Skip the cancel when there is no old policy, mirroring the check
security_load_policy() already makes before it converts.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 02a52c5c8c3b8cbad0f12009cde9f36dbefb6972 Version: 02a52c5c8c3b8cbad0f12009cde9f36dbefb6972 Version: 02a52c5c8c3b8cbad0f12009cde9f36dbefb6972 Version: 02a52c5c8c3b8cbad0f12009cde9f36dbefb6972 Version: 02a52c5c8c3b8cbad0f12009cde9f36dbefb6972 Version: 02a52c5c8c3b8cbad0f12009cde9f36dbefb6972 Version: 02a52c5c8c3b8cbad0f12009cde9f36dbefb6972 Version: 02a52c5c8c3b8cbad0f12009cde9f36dbefb6972 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"security/selinux/ss/services.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "2d29983104f06f5b0babcd5a25a0f0408272cd27",
"status": "affected",
"version": "02a52c5c8c3b8cbad0f12009cde9f36dbefb6972",
"versionType": "git"
},
{
"lessThan": "a4f182f8715cb0819445f0850cd5436828f4bafc",
"status": "affected",
"version": "02a52c5c8c3b8cbad0f12009cde9f36dbefb6972",
"versionType": "git"
},
{
"lessThan": "1059789ae9f99cbbe3a78e361e9c0976beb5958b",
"status": "affected",
"version": "02a52c5c8c3b8cbad0f12009cde9f36dbefb6972",
"versionType": "git"
},
{
"lessThan": "1acc317d67a755a45e32419a15d70e403fa43f0e",
"status": "affected",
"version": "02a52c5c8c3b8cbad0f12009cde9f36dbefb6972",
"versionType": "git"
},
{
"lessThan": "a42932c6aa33d0aac683cacdf1ec7009b955ba5d",
"status": "affected",
"version": "02a52c5c8c3b8cbad0f12009cde9f36dbefb6972",
"versionType": "git"
},
{
"lessThan": "1b4ff94ae7c580c880291519fb0e3e2bd075beef",
"status": "affected",
"version": "02a52c5c8c3b8cbad0f12009cde9f36dbefb6972",
"versionType": "git"
},
{
"lessThan": "219c96de5d9b6b4af7e8576ad897b774cc3ee9a7",
"status": "affected",
"version": "02a52c5c8c3b8cbad0f12009cde9f36dbefb6972",
"versionType": "git"
},
{
"lessThan": "e5c0235a3c4e9eb047a16cd02323fe4ecf2f570e",
"status": "affected",
"version": "02a52c5c8c3b8cbad0f12009cde9f36dbefb6972",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"security/selinux/ss/services.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.10"
},
{
"lessThan": "5.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.46",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.10",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nselinux: do not cancel a policy conversion that never started\n\nsel_write_load() calls selinux_policy_cancel() when sel_make_policy_nodes()\nfails, and that helper dereferences the outgoing policy to cancel its\nsidtab conversion. On the first policy load there is no outgoing policy:\nsecurity_load_policy() returns early for that case, before it converts\nanything, and state-\u003epolicy is still NULL. A first load that fails while\nbuilding the selinuxfs tree therefore takes a NULL dereference in\nselinux_policy_cancel(), reached from a write(2) to /sys/fs/selinux/load.\n\nSkip the cancel when there is no old policy, mirroring the check\nsecurity_load_policy() already makes before it converts."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-03T08:26:34.396Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/2d29983104f06f5b0babcd5a25a0f0408272cd27"
},
{
"url": "https://git.kernel.org/stable/c/a4f182f8715cb0819445f0850cd5436828f4bafc"
},
{
"url": "https://git.kernel.org/stable/c/1059789ae9f99cbbe3a78e361e9c0976beb5958b"
},
{
"url": "https://git.kernel.org/stable/c/1acc317d67a755a45e32419a15d70e403fa43f0e"
},
{
"url": "https://git.kernel.org/stable/c/a42932c6aa33d0aac683cacdf1ec7009b955ba5d"
},
{
"url": "https://git.kernel.org/stable/c/1b4ff94ae7c580c880291519fb0e3e2bd075beef"
},
{
"url": "https://git.kernel.org/stable/c/219c96de5d9b6b4af7e8576ad897b774cc3ee9a7"
},
{
"url": "https://git.kernel.org/stable/c/e5c0235a3c4e9eb047a16cd02323fe4ecf2f570e"
}
],
"title": "selinux: do not cancel a policy conversion that never started",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80756",
"datePublished": "2026-09-03T08:26:34.396Z",
"dateReserved": "2026-08-26T14:34:25.791Z",
"dateUpdated": "2026-09-03T08:26:34.396Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68299 (GCVE-0-2026-68299)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-19 16:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets
vmxnet3_get_hdr_len() assumes gdesc->rcd.v4/v6/tcp always describe the
outer header, but for a Geneve-encapsulated packet the device can set
them based on the inner header instead, signalled by the
VMXNET3_RCD_HDR_INNER_SHIFT bit in the completion descriptor. Since the
function never skips the outer encapsulation, this mismatch triggers:
- BUG_ON(hdr.ipv4->protocol != IPPROTO_TCP), because the outer
protocol is UDP (Geneve), not TCP.
- BUG_ON(hdr.eth->h_proto != ...), when the tunnel's outer and inner
IP versions differ (e.g. outer IPv6/inner IPv4 or vice versa).
Check VMXNET3_RCD_HDR_INNER_SHIFT up front and bail out, since the
function cannot locate the inner header it would need to parse. Also
convert the remaining BUG_ON()s in this function to return 0
defensively.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 45dac1d6ea045ae56e4df8d9c70c92c7412bd4fc Version: 45dac1d6ea045ae56e4df8d9c70c92c7412bd4fc Version: 45dac1d6ea045ae56e4df8d9c70c92c7412bd4fc Version: 45dac1d6ea045ae56e4df8d9c70c92c7412bd4fc Version: 45dac1d6ea045ae56e4df8d9c70c92c7412bd4fc Version: 45dac1d6ea045ae56e4df8d9c70c92c7412bd4fc Version: 45dac1d6ea045ae56e4df8d9c70c92c7412bd4fc Version: 45dac1d6ea045ae56e4df8d9c70c92c7412bd4fc |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/vmxnet3/vmxnet3_drv.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "2ddf51fcb6dd7d55ceef38e2e1a5ab2ab7fd47b0",
"status": "affected",
"version": "45dac1d6ea045ae56e4df8d9c70c92c7412bd4fc",
"versionType": "git"
},
{
"lessThan": "fbab6b73cc086e32698c86e43d1b16bf17d24c36",
"status": "affected",
"version": "45dac1d6ea045ae56e4df8d9c70c92c7412bd4fc",
"versionType": "git"
},
{
"lessThan": "28e382646417c7e2be9c9a7079eddf627ff52b90",
"status": "affected",
"version": "45dac1d6ea045ae56e4df8d9c70c92c7412bd4fc",
"versionType": "git"
},
{
"lessThan": "667b6e52048eaf4dbcf1707ed87ffd44abb9cb38",
"status": "affected",
"version": "45dac1d6ea045ae56e4df8d9c70c92c7412bd4fc",
"versionType": "git"
},
{
"lessThan": "28cb5d8d13b4c1faf3f688f62e5df82fe7b438d8",
"status": "affected",
"version": "45dac1d6ea045ae56e4df8d9c70c92c7412bd4fc",
"versionType": "git"
},
{
"lessThan": "4fdb0f162ccdbe9626863b10003855703253fa29",
"status": "affected",
"version": "45dac1d6ea045ae56e4df8d9c70c92c7412bd4fc",
"versionType": "git"
},
{
"lessThan": "b28596baf87e25a078789f1c05817c8a3bf71257",
"status": "affected",
"version": "45dac1d6ea045ae56e4df8d9c70c92c7412bd4fc",
"versionType": "git"
},
{
"lessThan": "34a71f5361fc3adb5b7138da78750b0d535a8252",
"status": "affected",
"version": "45dac1d6ea045ae56e4df8d9c70c92c7412bd4fc",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/vmxnet3/vmxnet3_drv.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.2"
},
{
"lessThan": "4.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nvmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets\n\nvmxnet3_get_hdr_len() assumes gdesc-\u003ercd.v4/v6/tcp always describe the\nouter header, but for a Geneve-encapsulated packet the device can set\nthem based on the inner header instead, signalled by the\nVMXNET3_RCD_HDR_INNER_SHIFT bit in the completion descriptor. Since the\nfunction never skips the outer encapsulation, this mismatch triggers:\n\n- BUG_ON(hdr.ipv4-\u003eprotocol != IPPROTO_TCP), because the outer\n protocol is UDP (Geneve), not TCP.\n- BUG_ON(hdr.eth-\u003eh_proto != ...), when the tunnel\u0027s outer and inner\n IP versions differ (e.g. outer IPv6/inner IPv4 or vice versa).\n\nCheck VMXNET3_RCD_HDR_INNER_SHIFT up front and bail out, since the\nfunction cannot locate the inner header it would need to parse. Also\nconvert the remaining BUG_ON()s in this function to return 0\ndefensively."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug is triggered purely by a received Geneve-encapsulated packet processed in the vmxnet3 RX completion path (vmxnet3_rq_rx_complete -\u003e vmxnet3_get_hdr_len); any remote host that can deliver such a frame to a VMware guest\u0027s vmxnet3 interface reaches the code, with no local access required.\nAC:L - The attacker only needs to send Geneve-encapsulated TCP traffic larger than the MTU to the target; the device then sets rcd.v4/v6/tcp from the inner header and the outer UDP protocol (or an outer/inner IP version mismatch) deterministically hits the BUG_ON, with no race or memory-layout dependency.\nPR:N - Packet reception and header-length estimation occur in the driver\u0027s NAPI RX path before any socket, credential, or authentication check, so an entirely unauthenticated remote sender triggers it.\nUI:N - The panic happens during normal NAPI RX processing of an incoming packet; no action by any local user or administrator is needed.\nS:U - The BUG_ON crashes the kernel that owns the vmxnet3 interface, and impact stays entirely within that kernel\u0027s security authority with no crossing into the hypervisor or another domain.\nC:N - The header parsing is bounded by the explicit skb_headlen()/maplen checks, so no out-of-bounds read occurs and no kernel memory contents are disclosed to the attacker before the BUG_ON aborts.\nI:N - No out-of-bounds or attacker-controlled write occurs; the mismatch is caught by the BUG_ON assertion, which halts execution rather than corrupting kernel memory or control flow.\nA:H - Hitting BUG_ON() in softirq/NAPI context oopses and panics the kernel, taking down the entire guest; a remote attacker can repeat it with a single crafted Geneve packet stream for a persistent denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:32:48.545Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/2ddf51fcb6dd7d55ceef38e2e1a5ab2ab7fd47b0"
},
{
"url": "https://git.kernel.org/stable/c/fbab6b73cc086e32698c86e43d1b16bf17d24c36"
},
{
"url": "https://git.kernel.org/stable/c/28e382646417c7e2be9c9a7079eddf627ff52b90"
},
{
"url": "https://git.kernel.org/stable/c/667b6e52048eaf4dbcf1707ed87ffd44abb9cb38"
},
{
"url": "https://git.kernel.org/stable/c/28cb5d8d13b4c1faf3f688f62e5df82fe7b438d8"
},
{
"url": "https://git.kernel.org/stable/c/4fdb0f162ccdbe9626863b10003855703253fa29"
},
{
"url": "https://git.kernel.org/stable/c/b28596baf87e25a078789f1c05817c8a3bf71257"
},
{
"url": "https://git.kernel.org/stable/c/34a71f5361fc3adb5b7138da78750b0d535a8252"
}
],
"title": "vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68299",
"datePublished": "2026-08-10T12:02:33.213Z",
"dateReserved": "2026-07-30T09:28:09.380Z",
"dateUpdated": "2026-08-19T16:32:48.545Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68315 (GCVE-0-2026-68315)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
sctp: validate stream count in sctp_process_strreset_inreq()
When processing a RESET_IN_REQUEST from a peer,
sctp_process_strreset_inreq() derives the stream count from the
parameter length but does not check whether the resulting
RESET_OUT_REQUEST would exceed SCTP_MAX_CHUNK_LEN.
The OUT request header (sctp_strreset_outreq, 16 bytes) is 8 bytes
larger than the IN request header (sctp_strreset_inreq, 8 bytes).
Generally, the IP payload is bounded to 65535 bytes, so the stream
list cannot be large enough to trigger the overflow. However, on
interfaces with MTU > 65535 (e.g., loopback with IPv6 jumbograms), a
stream list that fits within the incoming IN parameter can cause a
__u16 overflow in sctp_make_strreset_req() when computing the OUT
request size, leading to an undersized skb allocation and a kernel
BUG:
net/core/skbuff.c:207 skb_panic
net/core/skbuff.c:2625 skb_put
net/sctp/sm_make_chunk.c:1535 sctp_addto_chunk
net/sctp/sm_make_chunk.c:3695 sctp_make_strreset_req
net/sctp/stream.c:655 sctp_process_strreset_inreq
The local setsockopt path validates the generated reset request size.
However, for an incoming-only reset, it accounts for the smaller IN
request even though the peer must generate an OUT request with the same
stream list. Such a request cannot be completed successfully by the
peer.
Reject peer IN requests whose corresponding OUT request would exceed
SCTP_MAX_CHUNK_LEN. Also tighten the local check so it does not send an
IN request that would require an oversized OUT request from the peer.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137 Version: 7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137 Version: 7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137 Version: 7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137 Version: 7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137 Version: 7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137 Version: 7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137 Version: 7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/sctp/stream.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "61327d8e7cfb0259d527be17202630f556213249",
"status": "affected",
"version": "7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137",
"versionType": "git"
},
{
"lessThan": "7cf7439948e3bf639119119922c88ec190874ca3",
"status": "affected",
"version": "7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137",
"versionType": "git"
},
{
"lessThan": "60c47dea5d320d2fc706e9aad1db38a04df0a056",
"status": "affected",
"version": "7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137",
"versionType": "git"
},
{
"lessThan": "b255d8cd6cc68045ae9eecbac3b3c14e1f176c9b",
"status": "affected",
"version": "7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137",
"versionType": "git"
},
{
"lessThan": "6f0e39d180cd7cced647381b6fa14fd83d261047",
"status": "affected",
"version": "7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137",
"versionType": "git"
},
{
"lessThan": "1a10fe1aa9c01f41b389a31906a77d538637c9d9",
"status": "affected",
"version": "7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137",
"versionType": "git"
},
{
"lessThan": "00ae679cb21a035491fdad8d58dc6d79cc68b675",
"status": "affected",
"version": "7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137",
"versionType": "git"
},
{
"lessThan": "18ae07691d43183d270de8be9dc8e027906015d9",
"status": "affected",
"version": "7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/sctp/stream.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.11"
},
{
"lessThan": "4.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: validate stream count in sctp_process_strreset_inreq()\n\nWhen processing a RESET_IN_REQUEST from a peer,\nsctp_process_strreset_inreq() derives the stream count from the\nparameter length but does not check whether the resulting\nRESET_OUT_REQUEST would exceed SCTP_MAX_CHUNK_LEN.\n\nThe OUT request header (sctp_strreset_outreq, 16 bytes) is 8 bytes\nlarger than the IN request header (sctp_strreset_inreq, 8 bytes).\nGenerally, the IP payload is bounded to 65535 bytes, so the stream\nlist cannot be large enough to trigger the overflow. However, on\ninterfaces with MTU \u003e 65535 (e.g., loopback with IPv6 jumbograms), a\nstream list that fits within the incoming IN parameter can cause a\n__u16 overflow in sctp_make_strreset_req() when computing the OUT\nrequest size, leading to an undersized skb allocation and a kernel\nBUG:\n\n net/core/skbuff.c:207 skb_panic\n net/core/skbuff.c:2625 skb_put\n net/sctp/sm_make_chunk.c:1535 sctp_addto_chunk\n net/sctp/sm_make_chunk.c:3695 sctp_make_strreset_req\n net/sctp/stream.c:655 sctp_process_strreset_inreq\n\nThe local setsockopt path validates the generated reset request size.\nHowever, for an incoming-only reset, it accounts for the smaller IN\nrequest even though the peer must generate an OUT request with the same\nstream list. Such a request cannot be completed successfully by the\npeer.\n\nReject peer IN requests whose corresponding OUT request would exceed\nSCTP_MAX_CHUNK_LEN. Also tighten the local check so it does not send an\nIN request that would require an oversized OUT request from the peer."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The vulnerability is triggered by processing an SCTP RECONF chunk (RESET_IN_REQUEST) received from a remote/loopback peer in the in-kernel SCTP stack; per kernel guidance net-stack bugs reachable via received packets are Network.\nAC:L - The attacker fully controls the stream list length in the IN request, and the required MTU\u003e65535 is the default for loopback (65536), so the panic is reliably triggerable; stream-reset must be enabled but that is a deployment condition, not an attacker-uncontrollable one.\nPR:N - Sending the RECONF chunk only requires an established SCTP association, which any peer can set up without authentication or credentials; the bug is reached during normal association-scoped packet processing.\nUI:N - No victim interaction is needed; the attacker simply sends a crafted RECONF chunk to an established association.\nS:U - The crash occurs within the kernel\u0027s own security scope with no crossing of a security boundary such as VM or IOMMU.\nC:N - The bug is a controlled BUG()/skb_over_panic that aborts before any out-of-bounds access, disclosing no memory contents.\nI:N - The panic fires before the oversized copy executes, so no memory is written or modified out of bounds.\nA:H - The undersized skb allocation causes skb_put to invoke skb_over_panic \u2192 BUG(), producing a kernel panic (denial of service)."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:08.206Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/61327d8e7cfb0259d527be17202630f556213249"
},
{
"url": "https://git.kernel.org/stable/c/7cf7439948e3bf639119119922c88ec190874ca3"
},
{
"url": "https://git.kernel.org/stable/c/60c47dea5d320d2fc706e9aad1db38a04df0a056"
},
{
"url": "https://git.kernel.org/stable/c/b255d8cd6cc68045ae9eecbac3b3c14e1f176c9b"
},
{
"url": "https://git.kernel.org/stable/c/6f0e39d180cd7cced647381b6fa14fd83d261047"
},
{
"url": "https://git.kernel.org/stable/c/1a10fe1aa9c01f41b389a31906a77d538637c9d9"
},
{
"url": "https://git.kernel.org/stable/c/00ae679cb21a035491fdad8d58dc6d79cc68b675"
},
{
"url": "https://git.kernel.org/stable/c/18ae07691d43183d270de8be9dc8e027906015d9"
}
],
"title": "sctp: validate stream count in sctp_process_strreset_inreq()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68315",
"datePublished": "2026-08-10T12:02:50.156Z",
"dateReserved": "2026-07-30T09:28:09.382Z",
"dateUpdated": "2026-08-19T16:33:08.206Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68136 (GCVE-0-2026-68136)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-23 12:45
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: gro: fix double aggregation of flush-marked skbs
Commit 0ab03f353d36 ("net-gro: Fix GRO flush when receiving a GSO
packet.") added a flush check to skb_gro_receive(), but
skb_gro_receive_list() lacks the same validation.
As a result, packets marked with NAPI_GRO_CB(skb)->flush may still be
re-aggregated.
This allows already-GRO'd packets with existing frag_list to be
re-aggregated into a new GRO session, corrupting the frag_list chain
structure. When skb_segment() attempts to unpack these malformed packets,
it encounters invalid state and triggers a kernel panic.
Scenario (Tethering/Device forwarding):
1. Driver: Generated aggregated packet P1 via LRO with frag_list
2. Dev A: Receives aggregated fraglist packet and flush flag set
3. Dev A: Re-enters GRO, skb_gro_receive_list() is called
4. Missing flush check allows re-aggregation despite flush flag
5. Frag_list chain becomes corrupted (loops or dangling refs)
6. Dev B: TX path calls skb_segment(), crashes on corrupted frag_list
Root cause in skb_segment():
The check at line ~4891:
if (hsize <= 0 && i >= nfrags && skb_headlen(list_skb) &&
(skb_headlen(list_skb) == len || sg)) {
When frag_list is corrupted by double aggregation, when list_skb is
a NULL pointer from skb->next, skb_headlen(list_skb) dereference
NULL/corrupted pointers occurs.
Call Trace:
skb_headlen(NULL skb)
skb_segment
tcp_gso_segment
tcp4_gso_segment
inet_gso_segment
skb_mac_gso_segment
__skb_gso_segment
skb_gso_segment
validate_xmit_skb
validate_xmit_skb_list
sch_direct_xmit
qdisc_restart
__qdisc_run
qdisc_run
net_tx_action
Fix: Add NAPI_GRO_CB(skb)->flush validation to the early-return check in
skb_gro_receive_list(), matching the defensive programming pattern of
skb_gro_receive().
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 3a1296a38d0cf62bffb9a03c585cbd5dbf15d596 Version: 3a1296a38d0cf62bffb9a03c585cbd5dbf15d596 Version: 3a1296a38d0cf62bffb9a03c585cbd5dbf15d596 Version: 3a1296a38d0cf62bffb9a03c585cbd5dbf15d596 Version: 3a1296a38d0cf62bffb9a03c585cbd5dbf15d596 Version: 3a1296a38d0cf62bffb9a03c585cbd5dbf15d596 Version: 3a1296a38d0cf62bffb9a03c585cbd5dbf15d596 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/core/gro.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "7fc7e35212cf58c134310fb47566a844297ceae9",
"status": "affected",
"version": "3a1296a38d0cf62bffb9a03c585cbd5dbf15d596",
"versionType": "git"
},
{
"lessThan": "d1fb23f8f794ac4683127bd49a6422bd87e0ac02",
"status": "affected",
"version": "3a1296a38d0cf62bffb9a03c585cbd5dbf15d596",
"versionType": "git"
},
{
"lessThan": "db3e82da616f52e2b27e25e7be3fde2f2a5e54d6",
"status": "affected",
"version": "3a1296a38d0cf62bffb9a03c585cbd5dbf15d596",
"versionType": "git"
},
{
"lessThan": "107e1a469f53a2a70874f3f12bf6fcd23925da1d",
"status": "affected",
"version": "3a1296a38d0cf62bffb9a03c585cbd5dbf15d596",
"versionType": "git"
},
{
"lessThan": "a4dfd46cc8f08a29c6183794790547d0945f3d45",
"status": "affected",
"version": "3a1296a38d0cf62bffb9a03c585cbd5dbf15d596",
"versionType": "git"
},
{
"lessThan": "fc0c0f7a207f0cd2d2aa725696c907f7d03af9e0",
"status": "affected",
"version": "3a1296a38d0cf62bffb9a03c585cbd5dbf15d596",
"versionType": "git"
},
{
"lessThan": "e751256486d0ded20f5a9f9863467f1dce65142f",
"status": "affected",
"version": "3a1296a38d0cf62bffb9a03c585cbd5dbf15d596",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/core/gro.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.6"
},
{
"lessThan": "5.6",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: gro: fix double aggregation of flush-marked skbs\n\nCommit 0ab03f353d36 (\"net-gro: Fix GRO flush when receiving a GSO\npacket.\") added a flush check to skb_gro_receive(), but\nskb_gro_receive_list() lacks the same validation.\n\nAs a result, packets marked with NAPI_GRO_CB(skb)-\u003eflush may still be\nre-aggregated.\n\nThis allows already-GRO\u0027d packets with existing frag_list to be\nre-aggregated into a new GRO session, corrupting the frag_list chain\nstructure. When skb_segment() attempts to unpack these malformed packets,\nit encounters invalid state and triggers a kernel panic.\n\nScenario (Tethering/Device forwarding):\n 1. Driver: Generated aggregated packet P1 via LRO with frag_list\n 2. Dev A: Receives aggregated fraglist packet and flush flag set\n 3. Dev A: Re-enters GRO, skb_gro_receive_list() is called\n 4. Missing flush check allows re-aggregation despite flush flag\n 5. Frag_list chain becomes corrupted (loops or dangling refs)\n 6. Dev B: TX path calls skb_segment(), crashes on corrupted frag_list\n\nRoot cause in skb_segment():\n The check at line ~4891:\n if (hsize \u003c= 0 \u0026\u0026 i \u003e= nfrags \u0026\u0026 skb_headlen(list_skb) \u0026\u0026\n (skb_headlen(list_skb) == len || sg)) {\n\n When frag_list is corrupted by double aggregation, when list_skb is\n a NULL pointer from skb-\u003enext, skb_headlen(list_skb) dereference\n NULL/corrupted pointers occurs.\n\nCall Trace:\n skb_headlen(NULL skb)\n skb_segment\n tcp_gso_segment\n tcp4_gso_segment\n inet_gso_segment\n skb_mac_gso_segment\n __skb_gso_segment\n skb_gso_segment\n validate_xmit_skb\n validate_xmit_skb_list\n sch_direct_xmit\n qdisc_restart\n __qdisc_run\n qdisc_run\n net_tx_action\n\nFix: Add NAPI_GRO_CB(skb)-\u003eflush validation to the early-return check in\nskb_gro_receive_list(), matching the defensive programming pattern of\nskb_gro_receive()."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug is reached from the standard NAPI GRO receive path processing remotely originated TCP/IP packets (napi_gro_receive\u2192dev_gro_receive\u2192tcp_gro_receive\u2192skb_gro_receive_list), including tethering/NAT/forwarding scenarios where packets re-enter GRO on a second netdev after driver LRO or prior GRO aggregation.\nAC:L - An attacker can reliably trigger the bug by crafting a TCP stream through a forwarding host with rx-gro-list enabled, without races or victim-specific timing; the commit documents a deterministic tethering/forwarding repro where flush-marked frag_list skbs are re-aggregated and later crash skb_segment.\nPR:N - No local privileges or authentication are required; any remote peer that can send TCP traffic through a vulnerable forwarding/tethering/NAT Linux host can reach the GRO fraglist merge path, which performs no capability or credential checks on the receive path.\nUI:N - Exploitation requires only network-delivered packets and normal kernel forwarding/GRO processing; the victim does not need to open files, mount filesystems, click links, or perform any deliberate action beyond routine network operation.\nS:U - Impact is confined to kernel memory corruption and panic within the same host kernel security domain during packet GRO aggregation and subsequent segmentation on transmit; it does not cross VM, container, or IOMMU boundaries to affect a separate security authority.\nC:H - Double aggregation corrupts the skb frag_list chain (loops, dangling references, NULL/corrupted list_skb pointers), constituting kernel heap memory corruption that can be read during skb_segment processing and is classifiable as a high-impact info-disclosure primitive beyond a simple crash.\nI:H - Re-aggregating flush-marked skbs with existing frag_list corrupts skb linked-list structure and reference relationships in kernel memory, enabling potential control of subsequent skb metadata and write/control-flow primitives during GSO segmentation, not merely integrity-preserving packet drops.\nA:H - Corrupted frag_list state causes skb_segment to dereference a NULL or invalid list_skb via skb_headlen(), producing a kernel panic/oops on the transmit path (sch_direct_xmit/qdisc_run), fully denying availability of the affected system."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:45:54.689Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/7fc7e35212cf58c134310fb47566a844297ceae9"
},
{
"url": "https://git.kernel.org/stable/c/d1fb23f8f794ac4683127bd49a6422bd87e0ac02"
},
{
"url": "https://git.kernel.org/stable/c/db3e82da616f52e2b27e25e7be3fde2f2a5e54d6"
},
{
"url": "https://git.kernel.org/stable/c/107e1a469f53a2a70874f3f12bf6fcd23925da1d"
},
{
"url": "https://git.kernel.org/stable/c/a4dfd46cc8f08a29c6183794790547d0945f3d45"
},
{
"url": "https://git.kernel.org/stable/c/fc0c0f7a207f0cd2d2aa725696c907f7d03af9e0"
},
{
"url": "https://git.kernel.org/stable/c/e751256486d0ded20f5a9f9863467f1dce65142f"
}
],
"title": "net: gro: fix double aggregation of flush-marked skbs",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68136",
"datePublished": "2026-08-10T11:58:59.450Z",
"dateReserved": "2026-07-30T09:28:09.370Z",
"dateUpdated": "2026-08-23T12:45:54.689Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80893 (GCVE-0-2026-80893)
Vulnerability from cvelistv5
Published
2026-09-04 17:11
Modified
2026-09-04 17:11
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
mm/hugetlb: fix swap entry corruption when clearing uffd-wp at fork()
copy_hugetlb_page_range() clears the uffd-wp bit of migration and hwpoison
entries with huge_pte_clear_uffd_wp(), which operates on the present-PTE
bit position. Swap entries keep the uffd-wp state elsewhere -- the
migration branch reads and sets it with pte_swp_uffd_wp() and
pte_swp_mkuffd_wp() -- and the present-PTE position falls into the swap
payload. On x86-64 it lands in the inverted swap offset, where a
naturally-aligned hugetlb PFN always has the affected bit set, so the
clear advances the encoded PFN by two pages.
No userfaultfd needs to be involved: the clear is guarded only by the
child VMA not being uffd-wp registered, so a plain fork() with an
in-flight hugetlb migration entry (or a poisoned hugetlb page) corrupts
the entry copied into the child. Instrumenting the clear and forking
after MADV_HWPOISON on a 2MB anon hugetlb page shows:
offset before=120e00
offset after =120e02
The fallout is mostly latent: rmap walks match migration entries by folio
range and remove_migration_pte() rebuilds the PTE from the folio, so a
within-folio PFN skew heals once migration completes. But any path that
re-encodes the corrupted offset -- e.g. hugetlb_change_protection()
rewriting a writable migration entry via
make_readable_migration_entry(swp_offset(entry)) -- propagates it.
Migration entries legitimately carry uffd-wp, so clear it with
pte_swp_clear_uffd_wp(), matching copy_nonpresent_pte() and
move_huge_pte().
A hwpoison entry, on the other hand, never carries the uffd-wp bit: it is
installed fresh by make_hwpoison_entry() (try_to_unmap_one() does not
preserve uffd-wp on the hwpoison path) and hugetlb_change_protection()
leaves hwpoison entries untouched. There was nothing to clear there, only
the corruption, so drop the clear entirely.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: bc70fbf269fdff410b0b6d75c3770b9f59117b90 Version: bc70fbf269fdff410b0b6d75c3770b9f59117b90 Version: bc70fbf269fdff410b0b6d75c3770b9f59117b90 Version: bc70fbf269fdff410b0b6d75c3770b9f59117b90 Version: bc70fbf269fdff410b0b6d75c3770b9f59117b90 Version: bc70fbf269fdff410b0b6d75c3770b9f59117b90 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"mm/hugetlb.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "f1b1311c0352873137768bac5a126e491271a747",
"status": "affected",
"version": "bc70fbf269fdff410b0b6d75c3770b9f59117b90",
"versionType": "git"
},
{
"lessThan": "69cb5825d9988c7944bc9f1dc08cb233655405a7",
"status": "affected",
"version": "bc70fbf269fdff410b0b6d75c3770b9f59117b90",
"versionType": "git"
},
{
"lessThan": "8b0de7005b148738d79d6c45594d566489948a68",
"status": "affected",
"version": "bc70fbf269fdff410b0b6d75c3770b9f59117b90",
"versionType": "git"
},
{
"lessThan": "2b9a07002c2f296aa6a9c591213933d3492e3089",
"status": "affected",
"version": "bc70fbf269fdff410b0b6d75c3770b9f59117b90",
"versionType": "git"
},
{
"lessThan": "2fa11c60c9c06bafc19cf4d9efdaa36a38079e87",
"status": "affected",
"version": "bc70fbf269fdff410b0b6d75c3770b9f59117b90",
"versionType": "git"
},
{
"lessThan": "83abe2fd5b3aeb3123b5408a5a91709c5538fb23",
"status": "affected",
"version": "bc70fbf269fdff410b0b6d75c3770b9f59117b90",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"mm/hugetlb.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.19"
},
{
"lessThan": "5.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/hugetlb: fix swap entry corruption when clearing uffd-wp at fork()\n\ncopy_hugetlb_page_range() clears the uffd-wp bit of migration and hwpoison\nentries with huge_pte_clear_uffd_wp(), which operates on the present-PTE\nbit position. Swap entries keep the uffd-wp state elsewhere -- the\nmigration branch reads and sets it with pte_swp_uffd_wp() and\npte_swp_mkuffd_wp() -- and the present-PTE position falls into the swap\npayload. On x86-64 it lands in the inverted swap offset, where a\nnaturally-aligned hugetlb PFN always has the affected bit set, so the\nclear advances the encoded PFN by two pages.\n\nNo userfaultfd needs to be involved: the clear is guarded only by the\nchild VMA not being uffd-wp registered, so a plain fork() with an\nin-flight hugetlb migration entry (or a poisoned hugetlb page) corrupts\nthe entry copied into the child. Instrumenting the clear and forking\nafter MADV_HWPOISON on a 2MB anon hugetlb page shows:\n\n offset before=120e00\n offset after =120e02\n\nThe fallout is mostly latent: rmap walks match migration entries by folio\nrange and remove_migration_pte() rebuilds the PTE from the folio, so a\nwithin-folio PFN skew heals once migration completes. But any path that\nre-encodes the corrupted offset -- e.g. hugetlb_change_protection()\nrewriting a writable migration entry via\nmake_readable_migration_entry(swp_offset(entry)) -- propagates it.\n\nMigration entries legitimately carry uffd-wp, so clear it with\npte_swp_clear_uffd_wp(), matching copy_nonpresent_pte() and\nmove_huge_pte().\n\nA hwpoison entry, on the other hand, never carries the uffd-wp bit: it is\ninstalled fresh by make_hwpoison_entry() (try_to_unmap_one() does not\npreserve uffd-wp on the hwpoison path) and hugetlb_change_protection()\nleaves hwpoison entries untouched. There was nothing to clear there, only\nthe corruption, so drop the clear entirely."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T17:11:09.199Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/f1b1311c0352873137768bac5a126e491271a747"
},
{
"url": "https://git.kernel.org/stable/c/69cb5825d9988c7944bc9f1dc08cb233655405a7"
},
{
"url": "https://git.kernel.org/stable/c/8b0de7005b148738d79d6c45594d566489948a68"
},
{
"url": "https://git.kernel.org/stable/c/2b9a07002c2f296aa6a9c591213933d3492e3089"
},
{
"url": "https://git.kernel.org/stable/c/2fa11c60c9c06bafc19cf4d9efdaa36a38079e87"
},
{
"url": "https://git.kernel.org/stable/c/83abe2fd5b3aeb3123b5408a5a91709c5538fb23"
}
],
"title": "mm/hugetlb: fix swap entry corruption when clearing uffd-wp at fork()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80893",
"datePublished": "2026-09-04T17:11:09.199Z",
"dateReserved": "2026-08-26T14:34:25.800Z",
"dateUpdated": "2026-09-04T17:11:09.199Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2024-58094 (GCVE-0-2024-58094)
Vulnerability from cvelistv5
Published
2025-04-16 14:11
Modified
2026-09-02 12:49
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
jfs: add check read-only before truncation in jfs_truncate_nolock()
Added a check for "read-only" mode in the `jfs_truncate_nolock`
function to avoid errors related to writing to a read-only
filesystem.
Call stack:
block_write_begin() {
jfs_write_failed() {
jfs_truncate() {
jfs_truncate_nolock() {
txEnd() {
...
log = JFS_SBI(tblk->sb)->log;
// (log == NULL)
If the `isReadOnly(ip)` condition is triggered in
`jfs_truncate_nolock`, the function execution will stop, and no
further data modification will occur. Instead, the `xtTruncate`
function will be called with the "COMMIT_WMAP" flag, preventing
modifications in "read-only" mode.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/jfs/inode.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b98506e61e1bb6764c6711198cfab826df8ca952",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "1fee021d6cf1d41b3f6e3fd028939be8f5d5c5db",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "b57a8983916fc2cf54fd8de3afc733c6b3d1c0e5",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "41da1715cd24e177678f93ee27f737b095fc838b",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "77038187890ea82d237b05c8a9c4e08a38b1efcb",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "f605bc3e162f5c6faa9bd3602ce496053d06a4bb",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "b5799dd77054c1ec49b0088b006c9908e256843b",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/jfs/inode.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.269",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.220",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.187",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.156",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.108",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.14.*",
"status": "unaffected",
"version": "6.14.2",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "6.15",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.269",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.220",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.187",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.156",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.108",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.14.2",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.15",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\njfs: add check read-only before truncation in jfs_truncate_nolock()\n\nAdded a check for \"read-only\" mode in the `jfs_truncate_nolock`\nfunction to avoid errors related to writing to a read-only\nfilesystem.\n\nCall stack:\n\nblock_write_begin() {\n jfs_write_failed() {\n jfs_truncate() {\n jfs_truncate_nolock() {\n txEnd() {\n ...\n log = JFS_SBI(tblk-\u003esb)-\u003elog;\n // (log == NULL)\n\nIf the `isReadOnly(ip)` condition is triggered in\n`jfs_truncate_nolock`, the function execution will stop, and no\nfurther data modification will occur. Instead, the `xtTruncate`\nfunction will be called with the \"COMMIT_WMAP\" flag, preventing\nmodifications in \"read-only\" mode."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerability is triggered by a local write(2)/truncate on a file residing on a mounted JFS filesystem, reaching jfs_write_begin \u2192 jfs_write_failed \u2192 jfs_truncate_nolock. There is no network-facing consumer of this path.\nAC:L - With an fd held open across a forced remount-ro (mount -o remount,ro,force or SysRq emergency remount) the trigger is deterministic, and the remount,nointegrity path in jfs_reconfigure() tears down the log with no SB_RDONLY set and no writer hold-off, leaving a multi-second window an attacker can hammer with a write loop. No memory-layout or victim-state condition outside the attacker\u0027s influence is needed.\nPR:L - The memory-unsafe operation executes in the context of an ordinary unprivileged process\u0027s buffered write on a JFS file; the read-only/log-teardown transition is a routine system event (shutdown remount, emergency remount, integrity-flag remount, removable-media handling) rather than something the attacker must supply. Basic local user access with a writable fd on a JFS volume suffices.\nUI:N - No victim action is required \u2014 the attacker\u0027s own write(2) call drives the entire path through xtTruncate() and txEnd(0). The filesystem is already mounted in the targeted deployment scenario.\nS:U - The wild-pointer read/write, lock corruption and filesystem metadata damage all occur within the kernel\u0027s own security authority. No VM, IOMMU, or sandbox boundary is crossed.\nC:H - txEnd(0) dereferences TxBlock[0].sb, which is uninitialized vmalloc memory holding stale kernel data, and then chases it a second time (JFS_SBI(tblk-\u003esb)-\u003elog), while TXN_WAKEUP walks an uninitialized wait_queue_head\u0027s garbage list pointers. This uninitialized-memory-driven corruption is groomable and leverageable for kernel memory disclosure.\nI:H - Without the fix, xtTruncate() runs with COMMIT_PWMAP and mutates xtree metadata and the persistent block map of a filesystem that must not be modified \u2014 the fix exists precisely so that \"no further data modification will occur\". Additionally, `--log-\u003eactive` performs a decrement write through a pointer derived from uninitialized memory, and TxAnchor.freetid is corrupted to 0 so later transactions reuse the uninitialized TxBlock[0].\nA:H - The immediate observed result is a kernel oops (\"BUG: unable to handle kernel paging request\"/null-ptr-deref) in txEnd(). It occurs while the global TXN_LOCK spinlock, the inode commit_mutex and IWRITE_LOCK are held, so the locks are never released and every subsequent JFS operation on the system deadlocks."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-02T12:49:14.404Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b98506e61e1bb6764c6711198cfab826df8ca952"
},
{
"url": "https://git.kernel.org/stable/c/1fee021d6cf1d41b3f6e3fd028939be8f5d5c5db"
},
{
"url": "https://git.kernel.org/stable/c/b57a8983916fc2cf54fd8de3afc733c6b3d1c0e5"
},
{
"url": "https://git.kernel.org/stable/c/41da1715cd24e177678f93ee27f737b095fc838b"
},
{
"url": "https://git.kernel.org/stable/c/77038187890ea82d237b05c8a9c4e08a38b1efcb"
},
{
"url": "https://git.kernel.org/stable/c/f605bc3e162f5c6faa9bd3602ce496053d06a4bb"
},
{
"url": "https://git.kernel.org/stable/c/b5799dd77054c1ec49b0088b006c9908e256843b"
}
],
"title": "jfs: add check read-only before truncation in jfs_truncate_nolock()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2024-58094",
"datePublished": "2025-04-16T14:11:43.298Z",
"dateReserved": "2025-03-06T15:52:09.188Z",
"dateUpdated": "2026-09-02T12:49:14.404Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68403 (GCVE-0-2026-68403)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: brcmfmac: initialize SDIO data work before cleanup
brcmf_sdio_probe() stores the newly allocated bus in sdiodev->bus before
allocating the ordered workqueue. If that allocation fails, the function
jumps to fail and calls brcmf_sdio_remove().
brcmf_sdio_remove() unconditionally cancels bus->datawork. Initialize the
work item before the first failure path that can reach brcmf_sdio_remove(),
so the cleanup path always observes a valid work object.
This issue was found by our static analysis tool and then confirmed by
manual review of the probe error path and the remove-time work drain. The
problem pattern is an early setup failure that reaches a cleanup helper
which cancels an embedded work item before its initializer has run.
A QEMU PoC forced alloc_ordered_workqueue() to fail at the same point in
brcmf_sdio_probe(), before INIT_WORK(&bus->datawork) is reached. The
resulting fail path calls brcmf_sdio_remove(), and DEBUG_OBJECTS reports
the invalid work drain with brcmf_sdio_probe() and brcmf_sdio_remove() in
the stack.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 9982464379e81ece51ced03ebecbbcd34ea367a6 Version: 9982464379e81ece51ced03ebecbbcd34ea367a6 Version: 9982464379e81ece51ced03ebecbbcd34ea367a6 Version: 9982464379e81ece51ced03ebecbbcd34ea367a6 Version: 9982464379e81ece51ced03ebecbbcd34ea367a6 Version: 9982464379e81ece51ced03ebecbbcd34ea367a6 Version: 9982464379e81ece51ced03ebecbbcd34ea367a6 Version: 9982464379e81ece51ced03ebecbbcd34ea367a6 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/broadcom/brcm80211/brcmfmac/sdio.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "860887d22890417d43ef8298f0cc4865e29b54de",
"status": "affected",
"version": "9982464379e81ece51ced03ebecbbcd34ea367a6",
"versionType": "git"
},
{
"lessThan": "9a4be91e5bb032b34cb3c962f6d4f82e7ef09364",
"status": "affected",
"version": "9982464379e81ece51ced03ebecbbcd34ea367a6",
"versionType": "git"
},
{
"lessThan": "fb12c87ae855346321af72e57a93c146205f1090",
"status": "affected",
"version": "9982464379e81ece51ced03ebecbbcd34ea367a6",
"versionType": "git"
},
{
"lessThan": "f50a2b9e57a751e70ae9a272875d80d39eaccd6a",
"status": "affected",
"version": "9982464379e81ece51ced03ebecbbcd34ea367a6",
"versionType": "git"
},
{
"lessThan": "6bd21ec8549a5854dd64204a66289952917a924c",
"status": "affected",
"version": "9982464379e81ece51ced03ebecbbcd34ea367a6",
"versionType": "git"
},
{
"lessThan": "5c342437ea44bb829680ca9e4f683dd5b325b219",
"status": "affected",
"version": "9982464379e81ece51ced03ebecbbcd34ea367a6",
"versionType": "git"
},
{
"lessThan": "c73c3fc1c7ca5a927639f0884624cb244ba791e4",
"status": "affected",
"version": "9982464379e81ece51ced03ebecbbcd34ea367a6",
"versionType": "git"
},
{
"lessThan": "2a665946e0407a05a3f81bd56a08553c446498e0",
"status": "affected",
"version": "9982464379e81ece51ced03ebecbbcd34ea367a6",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/broadcom/brcm80211/brcmfmac/sdio.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.1"
},
{
"lessThan": "4.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: brcmfmac: initialize SDIO data work before cleanup\n\nbrcmf_sdio_probe() stores the newly allocated bus in sdiodev-\u003ebus before\nallocating the ordered workqueue. If that allocation fails, the function\njumps to fail and calls brcmf_sdio_remove().\n\nbrcmf_sdio_remove() unconditionally cancels bus-\u003edatawork. Initialize the\nwork item before the first failure path that can reach brcmf_sdio_remove(),\nso the cleanup path always observes a valid work object.\n\nThis issue was found by our static analysis tool and then confirmed by\nmanual review of the probe error path and the remove-time work drain. The\nproblem pattern is an early setup failure that reaches a cleanup helper\nwhich cancels an embedded work item before its initializer has run.\n\nA QEMU PoC forced alloc_ordered_workqueue() to fail at the same point in\nbrcmf_sdio_probe(), before INIT_WORK(\u0026bus-\u003edatawork) is reached. The\nresulting fail path calls brcmf_sdio_remove(), and DEBUG_OBJECTS reports\nthe invalid work drain with brcmf_sdio_probe() and brcmf_sdio_remove() in\nthe stack."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:54.805Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/860887d22890417d43ef8298f0cc4865e29b54de"
},
{
"url": "https://git.kernel.org/stable/c/9a4be91e5bb032b34cb3c962f6d4f82e7ef09364"
},
{
"url": "https://git.kernel.org/stable/c/fb12c87ae855346321af72e57a93c146205f1090"
},
{
"url": "https://git.kernel.org/stable/c/f50a2b9e57a751e70ae9a272875d80d39eaccd6a"
},
{
"url": "https://git.kernel.org/stable/c/6bd21ec8549a5854dd64204a66289952917a924c"
},
{
"url": "https://git.kernel.org/stable/c/5c342437ea44bb829680ca9e4f683dd5b325b219"
},
{
"url": "https://git.kernel.org/stable/c/c73c3fc1c7ca5a927639f0884624cb244ba791e4"
},
{
"url": "https://git.kernel.org/stable/c/2a665946e0407a05a3f81bd56a08553c446498e0"
}
],
"title": "wifi: brcmfmac: initialize SDIO data work before cleanup",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68403",
"datePublished": "2026-08-10T12:04:23.150Z",
"dateReserved": "2026-07-30T09:28:09.390Z",
"dateUpdated": "2026-08-19T16:34:54.805Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72030 (GCVE-0-2026-72030)
Vulnerability from cvelistv5
Published
2026-08-15 05:51
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ata: libata-core: Reject an invalid concurrent positioning ranges count
ata_dev_config_cpr() takes the number of range descriptors from buf[0]
of the concurrent positioning ranges log (up to 255), which the device
reports independently of the log size in the GPL directory. The count is
then walked at a fixed 32-byte stride in two places with no bound: the
log read here, and the INQUIRY VPD page B9h emitter, which writes one
descriptor per range into the fixed 2048-byte ata_scsi_rbuf. A device
reporting a count larger than its own log overflows the read buffer (up
to 7704 bytes past a 512-byte slab), and a count above 62 overflows the
response buffer on the emit side.
Bound the count once, on probe, against both the log the device returned
and the number of descriptors the VPD B9h response buffer can hold
(ATA_DEV_MAX_CPR, derived from the rbuf size). Reject an out-of-range
count with a warning; this keeps the emitter in bounds with no separate
change there.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: fe22e1c2f705676a705d821301fc52eecc2fe055 Version: fe22e1c2f705676a705d821301fc52eecc2fe055 Version: fe22e1c2f705676a705d821301fc52eecc2fe055 Version: fe22e1c2f705676a705d821301fc52eecc2fe055 Version: fe22e1c2f705676a705d821301fc52eecc2fe055 Version: fe22e1c2f705676a705d821301fc52eecc2fe055 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/ata/libata-core.c",
"drivers/ata/libata-scsi.c",
"drivers/ata/libata.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "01d7d321e6046f87ba270aeeffdc5260209bd91e",
"status": "affected",
"version": "fe22e1c2f705676a705d821301fc52eecc2fe055",
"versionType": "git"
},
{
"lessThan": "4cb4b4dd8853c4ab3057efe238b2c34277772176",
"status": "affected",
"version": "fe22e1c2f705676a705d821301fc52eecc2fe055",
"versionType": "git"
},
{
"lessThan": "b1607f0ee5f5e53e0aa66f41794085b7cc98f5d1",
"status": "affected",
"version": "fe22e1c2f705676a705d821301fc52eecc2fe055",
"versionType": "git"
},
{
"lessThan": "4c1e8ccd8655ee8cf1bcb1b7dfee72c9fa941fd4",
"status": "affected",
"version": "fe22e1c2f705676a705d821301fc52eecc2fe055",
"versionType": "git"
},
{
"lessThan": "d43efd1b5d976203e6f1ef26f67e8b1a7bc2751b",
"status": "affected",
"version": "fe22e1c2f705676a705d821301fc52eecc2fe055",
"versionType": "git"
},
{
"lessThan": "533a0b940f901c15e5cbbd4b5d66e871c209e8ce",
"status": "affected",
"version": "fe22e1c2f705676a705d821301fc52eecc2fe055",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/ata/libata-core.c",
"drivers/ata/libata-scsi.c",
"drivers/ata/libata.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.16"
},
{
"lessThan": "5.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.16",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nata: libata-core: Reject an invalid concurrent positioning ranges count\n\nata_dev_config_cpr() takes the number of range descriptors from buf[0]\nof the concurrent positioning ranges log (up to 255), which the device\nreports independently of the log size in the GPL directory. The count is\nthen walked at a fixed 32-byte stride in two places with no bound: the\nlog read here, and the INQUIRY VPD page B9h emitter, which writes one\ndescriptor per range into the fixed 2048-byte ata_scsi_rbuf. A device\nreporting a count larger than its own log overflows the read buffer (up\nto 7704 bytes past a 512-byte slab), and a count above 62 overflows the\nresponse buffer on the emit side.\n\nBound the count once, on probe, against both the log the device returned\nand the number of descriptors the VPD B9h response buffer can hold\n(ATA_DEV_MAX_CPR, derived from the rbuf size). Reject an out-of-range\ncount with a warning; this keeps the emitter in bounds with no separate\nchange there."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:28.762Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/01d7d321e6046f87ba270aeeffdc5260209bd91e"
},
{
"url": "https://git.kernel.org/stable/c/4cb4b4dd8853c4ab3057efe238b2c34277772176"
},
{
"url": "https://git.kernel.org/stable/c/b1607f0ee5f5e53e0aa66f41794085b7cc98f5d1"
},
{
"url": "https://git.kernel.org/stable/c/4c1e8ccd8655ee8cf1bcb1b7dfee72c9fa941fd4"
},
{
"url": "https://git.kernel.org/stable/c/d43efd1b5d976203e6f1ef26f67e8b1a7bc2751b"
},
{
"url": "https://git.kernel.org/stable/c/533a0b940f901c15e5cbbd4b5d66e871c209e8ce"
}
],
"title": "ata: libata-core: Reject an invalid concurrent positioning ranges count",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72030",
"datePublished": "2026-08-15T05:51:53.189Z",
"dateReserved": "2026-08-09T03:40:39.901Z",
"dateUpdated": "2026-08-23T12:46:28.762Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80766 (GCVE-0-2026-80766)
Vulnerability from cvelistv5
Published
2026-09-04 15:12
Modified
2026-09-04 15:12
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
HID: uclogic: fix use-after-free of inrange_timer on remove
uclogic_remove() cancels the pen in-range timer and then stops the
device:
timer_delete_sync(&drvdata->inrange_timer);
hid_hw_stop(hdev);
timer_delete_sync() only guarantees the timer is idle at that instant.
uclogic_raw_event_pen() keeps delivering pen reports until hid_hw_stop()
stops the transport several lines later, and every report with
pen->inrange == UCLOGIC_PARAMS_PEN_INRANGE_NONE re-arms the timer:
mod_timer(&drvdata->inrange_timer, jiffies + msecs_to_jiffies(100));
A report landing between the timer_delete_sync() call and the transport
teardown in hid_hw_stop() re-arms inrange_timer after it was cancelled.
uclogic_remove() then returns and the devm drvdata is freed, while
hid_hw_stop() has already freed the input device drvdata->pen_input
points at, so when the timer fires ~100 ms later
uclogic_inrange_timeout() dereferences freed memory -- a use-after-free
in timer-softirq context.
Swapping the two calls is not a fix: stopping the device first frees
drvdata->pen_input via hidinput_disconnect() while the timer may still
be pending, so a timer already armed before removal fires on the freed
input device in the window before timer_delete_sync() runs.
Use timer_shutdown_sync() before hid_hw_stop() instead. It cancels the
timer, waits for a running callback while pen_input is still valid, and
prevents any further re-arming -- a later mod_timer() from an in-flight
report is silently ignored -- so the timer is provably dead before
hid_hw_stop() frees the inputs. This is the ordering the timer core
documents for this "timer re-armed from another path" teardown case.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 01309e29eb95c16bd48984f2589fad0cbf5e27d1 Version: 01309e29eb95c16bd48984f2589fad0cbf5e27d1 Version: 01309e29eb95c16bd48984f2589fad0cbf5e27d1 Version: 01309e29eb95c16bd48984f2589fad0cbf5e27d1 Version: 01309e29eb95c16bd48984f2589fad0cbf5e27d1 Version: 01309e29eb95c16bd48984f2589fad0cbf5e27d1 Version: 01309e29eb95c16bd48984f2589fad0cbf5e27d1 Version: 01309e29eb95c16bd48984f2589fad0cbf5e27d1 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/hid/hid-uclogic-core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "f40243358b407aec362fe305fabfcdc94a3abd89",
"status": "affected",
"version": "01309e29eb95c16bd48984f2589fad0cbf5e27d1",
"versionType": "git"
},
{
"lessThan": "dc5108f18f58870a8dd4203a02a47e571a2be7f0",
"status": "affected",
"version": "01309e29eb95c16bd48984f2589fad0cbf5e27d1",
"versionType": "git"
},
{
"lessThan": "9d77ac82e57ead056cf3f71d347083ed9244ad90",
"status": "affected",
"version": "01309e29eb95c16bd48984f2589fad0cbf5e27d1",
"versionType": "git"
},
{
"lessThan": "e750cdb6de009aace3c77f37fe2173f96175e8e4",
"status": "affected",
"version": "01309e29eb95c16bd48984f2589fad0cbf5e27d1",
"versionType": "git"
},
{
"lessThan": "849e537160bbb77fe419ecc3944bfe125dcd441b",
"status": "affected",
"version": "01309e29eb95c16bd48984f2589fad0cbf5e27d1",
"versionType": "git"
},
{
"lessThan": "f1b3ca06380531f49f988f4721d3ed30b0d7a5d2",
"status": "affected",
"version": "01309e29eb95c16bd48984f2589fad0cbf5e27d1",
"versionType": "git"
},
{
"lessThan": "f13d0a00204b05e62336da0ab72ea0d87b56690c",
"status": "affected",
"version": "01309e29eb95c16bd48984f2589fad0cbf5e27d1",
"versionType": "git"
},
{
"lessThan": "506fd50a9027340f0e9dcc587d10ccb03312dba6",
"status": "affected",
"version": "01309e29eb95c16bd48984f2589fad0cbf5e27d1",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/hid/hid-uclogic-core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.1"
},
{
"lessThan": "5.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.220",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.187",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.156",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.108",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.47",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.1",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.220",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.187",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.156",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.108",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.47",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.11",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.1",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "5.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: uclogic: fix use-after-free of inrange_timer on remove\n\nuclogic_remove() cancels the pen in-range timer and then stops the\ndevice:\n\n\ttimer_delete_sync(\u0026drvdata-\u003einrange_timer);\n\thid_hw_stop(hdev);\n\ntimer_delete_sync() only guarantees the timer is idle at that instant.\nuclogic_raw_event_pen() keeps delivering pen reports until hid_hw_stop()\nstops the transport several lines later, and every report with\npen-\u003einrange == UCLOGIC_PARAMS_PEN_INRANGE_NONE re-arms the timer:\n\n\tmod_timer(\u0026drvdata-\u003einrange_timer, jiffies + msecs_to_jiffies(100));\n\nA report landing between the timer_delete_sync() call and the transport\nteardown in hid_hw_stop() re-arms inrange_timer after it was cancelled.\nuclogic_remove() then returns and the devm drvdata is freed, while\nhid_hw_stop() has already freed the input device drvdata-\u003epen_input\npoints at, so when the timer fires ~100 ms later\nuclogic_inrange_timeout() dereferences freed memory -- a use-after-free\nin timer-softirq context.\n\nSwapping the two calls is not a fix: stopping the device first frees\ndrvdata-\u003epen_input via hidinput_disconnect() while the timer may still\nbe pending, so a timer already armed before removal fires on the freed\ninput device in the window before timer_delete_sync() runs.\n\nUse timer_shutdown_sync() before hid_hw_stop() instead. It cancels the\ntimer, waits for a running callback while pen_input is still valid, and\nprevents any further re-arming -- a later mod_timer() from an in-flight\nreport is silently ignored -- so the timer is provably dead before\nhid_hw_stop() frees the inputs. This is the ordering the timer core\ndocuments for this \"timer re-armed from another path\" teardown case."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T15:12:38.520Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/f40243358b407aec362fe305fabfcdc94a3abd89"
},
{
"url": "https://git.kernel.org/stable/c/dc5108f18f58870a8dd4203a02a47e571a2be7f0"
},
{
"url": "https://git.kernel.org/stable/c/9d77ac82e57ead056cf3f71d347083ed9244ad90"
},
{
"url": "https://git.kernel.org/stable/c/e750cdb6de009aace3c77f37fe2173f96175e8e4"
},
{
"url": "https://git.kernel.org/stable/c/849e537160bbb77fe419ecc3944bfe125dcd441b"
},
{
"url": "https://git.kernel.org/stable/c/f1b3ca06380531f49f988f4721d3ed30b0d7a5d2"
},
{
"url": "https://git.kernel.org/stable/c/f13d0a00204b05e62336da0ab72ea0d87b56690c"
},
{
"url": "https://git.kernel.org/stable/c/506fd50a9027340f0e9dcc587d10ccb03312dba6"
}
],
"title": "HID: uclogic: fix use-after-free of inrange_timer on remove",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80766",
"datePublished": "2026-09-04T15:12:38.520Z",
"dateReserved": "2026-08-26T14:34:25.791Z",
"dateUpdated": "2026-09-04T15:12:38.520Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80809 (GCVE-0-2026-80809)
Vulnerability from cvelistv5
Published
2026-09-04 15:13
Modified
2026-09-04 15:13
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ocfs2: fix missing metadata reservation for large xattrs
[BUG]
lsetxattr() panics the kernel when setting a large xattr value on a
fragmented filesystem where the file already has an external xattr
block.
[CAUSE]
ocfs2_calc_xattr_set_need() never reserves metadata blocks for a new
xattr value's extent tree when the file already has an external xattr
block. The not_found path leaves meta_add at zero, so meta_ac is NULL
when ocfs2_xattr_extend_allocation() runs.
A new value root has room for a single extent record. On a fragmented
filesystem, the allocator cannot satisfy the xattr value in one
contiguous run, so each non-contiguous run requires its own extent
record. When the value root's extent list is full and meta_ac is NULL,
ocfs2_add_clusters_in_btree() returns RESTART_META, and
ocfs2_xattr_extend_allocation() hits BUG_ON(why == RESTART_META).
[FIX]
The case where no xattr block exists yet already calls
ocfs2_extend_meta_needed(&def_xv.xv.xr_list) to reserve value tree
metadata. Add the same reservation to the case where an xattr block
already exists, making the two cases consistent.
Replace the BUG_ON with a -ENOSPC return so that if RESTART_META is
returned despite the reservation, the error propagates to userspace
instead of panicking the kernel.
References
| URL | Tags | ||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: a78f9f4668949a6588b8872f162e86685c63d023 Version: a78f9f4668949a6588b8872f162e86685c63d023 Version: a78f9f4668949a6588b8872f162e86685c63d023 Version: a78f9f4668949a6588b8872f162e86685c63d023 Version: a78f9f4668949a6588b8872f162e86685c63d023 Version: a78f9f4668949a6588b8872f162e86685c63d023 Version: a78f9f4668949a6588b8872f162e86685c63d023 Version: a78f9f4668949a6588b8872f162e86685c63d023 Version: a78f9f4668949a6588b8872f162e86685c63d023 Version: 92f61d8a31e270f9391e7bcc0ac638bd4262a8e0 Version: 2.6.34.2 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/ocfs2/xattr.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "743ac908282ac97ef6e73ac3a92df2cc8ecb7479",
"status": "affected",
"version": "a78f9f4668949a6588b8872f162e86685c63d023",
"versionType": "git"
},
{
"lessThan": "04ba24bce61c917b5b3009f0db470cbb72e26a0d",
"status": "affected",
"version": "a78f9f4668949a6588b8872f162e86685c63d023",
"versionType": "git"
},
{
"lessThan": "b4663405ae29d36011cd712d243456f3f9ab700d",
"status": "affected",
"version": "a78f9f4668949a6588b8872f162e86685c63d023",
"versionType": "git"
},
{
"lessThan": "6a009f1e61b11d9e23d3c5aa1dacfb010945da45",
"status": "affected",
"version": "a78f9f4668949a6588b8872f162e86685c63d023",
"versionType": "git"
},
{
"lessThan": "b9eb5c9fdd81d82976d4d5be2b2458eb7d7e46ec",
"status": "affected",
"version": "a78f9f4668949a6588b8872f162e86685c63d023",
"versionType": "git"
},
{
"lessThan": "6176313622e34fa3e2b66b9d0682d1e1c6b365c5",
"status": "affected",
"version": "a78f9f4668949a6588b8872f162e86685c63d023",
"versionType": "git"
},
{
"lessThan": "a3ccb57086dd7652d5ecb826486144198a98a8e9",
"status": "affected",
"version": "a78f9f4668949a6588b8872f162e86685c63d023",
"versionType": "git"
},
{
"lessThan": "50f0cbec45b0f3fd7e1263d01916518dbf31eb3f",
"status": "affected",
"version": "a78f9f4668949a6588b8872f162e86685c63d023",
"versionType": "git"
},
{
"lessThan": "0cdc7dde00ec63ac714271fa8b2918d630b8da1a",
"status": "affected",
"version": "a78f9f4668949a6588b8872f162e86685c63d023",
"versionType": "git"
},
{
"status": "affected",
"version": "92f61d8a31e270f9391e7bcc0ac638bd4262a8e0",
"versionType": "git"
},
{
"lessThan": "2.6.35",
"status": "affected",
"version": "2.6.34.2",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/ocfs2/xattr.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.35"
},
{
"lessThan": "2.6.35",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.267",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.218",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.185",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.154",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.106",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.47",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.1",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.267",
"versionStartIncluding": "2.6.35",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.218",
"versionStartIncluding": "2.6.35",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.185",
"versionStartIncluding": "2.6.35",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.154",
"versionStartIncluding": "2.6.35",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.106",
"versionStartIncluding": "2.6.35",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.47",
"versionStartIncluding": "2.6.35",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.11",
"versionStartIncluding": "2.6.35",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.1",
"versionStartIncluding": "2.6.35",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "2.6.35",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "2.6.34.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: fix missing metadata reservation for large xattrs\n\n[BUG]\nlsetxattr() panics the kernel when setting a large xattr value on a\nfragmented filesystem where the file already has an external xattr\nblock.\n\n[CAUSE]\nocfs2_calc_xattr_set_need() never reserves metadata blocks for a new\nxattr value\u0027s extent tree when the file already has an external xattr\nblock. The not_found path leaves meta_add at zero, so meta_ac is NULL\nwhen ocfs2_xattr_extend_allocation() runs.\n\nA new value root has room for a single extent record. On a fragmented\nfilesystem, the allocator cannot satisfy the xattr value in one\ncontiguous run, so each non-contiguous run requires its own extent\nrecord. When the value root\u0027s extent list is full and meta_ac is NULL,\nocfs2_add_clusters_in_btree() returns RESTART_META, and\nocfs2_xattr_extend_allocation() hits BUG_ON(why == RESTART_META).\n\n[FIX]\nThe case where no xattr block exists yet already calls\nocfs2_extend_meta_needed(\u0026def_xv.xv.xr_list) to reserve value tree\nmetadata. Add the same reservation to the case where an xattr block\nalready exists, making the two cases consistent.\n\nReplace the BUG_ON with a -ENOSPC return so that if RESTART_META is\nreturned despite the reservation, the error propagates to userspace\ninstead of panicking the kernel."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T15:13:29.769Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/743ac908282ac97ef6e73ac3a92df2cc8ecb7479"
},
{
"url": "https://git.kernel.org/stable/c/04ba24bce61c917b5b3009f0db470cbb72e26a0d"
},
{
"url": "https://git.kernel.org/stable/c/b4663405ae29d36011cd712d243456f3f9ab700d"
},
{
"url": "https://git.kernel.org/stable/c/6a009f1e61b11d9e23d3c5aa1dacfb010945da45"
},
{
"url": "https://git.kernel.org/stable/c/b9eb5c9fdd81d82976d4d5be2b2458eb7d7e46ec"
},
{
"url": "https://git.kernel.org/stable/c/6176313622e34fa3e2b66b9d0682d1e1c6b365c5"
},
{
"url": "https://git.kernel.org/stable/c/a3ccb57086dd7652d5ecb826486144198a98a8e9"
},
{
"url": "https://git.kernel.org/stable/c/50f0cbec45b0f3fd7e1263d01916518dbf31eb3f"
},
{
"url": "https://git.kernel.org/stable/c/0cdc7dde00ec63ac714271fa8b2918d630b8da1a"
}
],
"title": "ocfs2: fix missing metadata reservation for large xattrs",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80809",
"datePublished": "2026-09-04T15:13:29.769Z",
"dateReserved": "2026-08-26T14:34:25.794Z",
"dateUpdated": "2026-09-04T15:13:29.769Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80784 (GCVE-0-2026-80784)
Vulnerability from cvelistv5
Published
2026-09-04 15:12
Modified
2026-09-04 15:12
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
mptcp: pm: fix memory leak from alloc-during-teardown race
mptcp_pm_destroy() empties msk->pm.anno_list and
msk->pm.userspace_pm_local_addr_list under msk->pm.lock during socket
teardown, dropping the lock between the two.
A concurrent userspace PM genl ANNOUNCE on the same msk holds a sock
reference via mptcp_token_get_sock() and, in
mptcp_pm_nl_announce_doit(), calls
mptcp_userspace_pm_append_new_local_addr() and
mptcp_pm_announced_alloc(). Both take msk->pm.lock briefly to add to
their respective lists. Because the genl handler holds a sock reference,
mptcp_pm_destroy() may run on the same msk via mptcp_disconnect(), which
invokes mptcp_destroy_common() without dropping the sock refcount,
before the handler completes.
If the lock acquisitions interleave such that mptcp_pm_destroy() empties
a list first, the later alloc adds its entry to a list head that nothing
else iterates for this msk, and the entry leaks. kmemleak reports both
mptcp_pm_add_addr objects (from mptcp_pm_announced_alloc()) and
mptcp_pm_addr_entry objects (from
mptcp_userspace_pm_append_new_local_addr()) under sustained concurrent
ANNOUNCE + close load against the userspace PM.
Add an MPTCP_PM_DESTROYING bit in msk->pm.status, set by
mptcp_pm_destroy() under pm.lock before the lists are emptied and
checked under pm.lock by the alloc paths. Either the alloc takes pm.lock
first, in which case its entry is on the list when mptcp_pm_destroy()
frees it; or mptcp_pm_destroy() takes pm.lock first, in which case the
later alloc observes the bit and refuses.
Found by an MPTCP protocol-flow harness extending BRF (arXiv:2305.08782).
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 9ab4807c84a4aacfc9b4f79cc81254035e0ec361 Version: 9ab4807c84a4aacfc9b4f79cc81254035e0ec361 Version: 9ab4807c84a4aacfc9b4f79cc81254035e0ec361 Version: 9ab4807c84a4aacfc9b4f79cc81254035e0ec361 Version: 9ab4807c84a4aacfc9b4f79cc81254035e0ec361 Version: 9ab4807c84a4aacfc9b4f79cc81254035e0ec361 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/mptcp/pm.c",
"net/mptcp/pm_userspace.c",
"net/mptcp/protocol.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "f48341830e4202db3fe884b819b2db6740f0537d",
"status": "affected",
"version": "9ab4807c84a4aacfc9b4f79cc81254035e0ec361",
"versionType": "git"
},
{
"lessThan": "bb32e9a6a9a9f99eeda16c4efe443400f3e43892",
"status": "affected",
"version": "9ab4807c84a4aacfc9b4f79cc81254035e0ec361",
"versionType": "git"
},
{
"lessThan": "b2a0b55bf613bd3e81ed26a847b0f6b8e6b7f804",
"status": "affected",
"version": "9ab4807c84a4aacfc9b4f79cc81254035e0ec361",
"versionType": "git"
},
{
"lessThan": "9fe5eebb664ecdba88f3fde18062d94b1d1c465f",
"status": "affected",
"version": "9ab4807c84a4aacfc9b4f79cc81254035e0ec361",
"versionType": "git"
},
{
"lessThan": "6c290915a03fc8228b473641025cf762b256dbd2",
"status": "affected",
"version": "9ab4807c84a4aacfc9b4f79cc81254035e0ec361",
"versionType": "git"
},
{
"lessThan": "efc33b5102ff859bacd390a5f30112d8e0c084c0",
"status": "affected",
"version": "9ab4807c84a4aacfc9b4f79cc81254035e0ec361",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/mptcp/pm.c",
"net/mptcp/pm_userspace.c",
"net/mptcp/protocol.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.19"
},
{
"lessThan": "5.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.187",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.154",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.106",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.47",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.187",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.154",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.106",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.47",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.11",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: pm: fix memory leak from alloc-during-teardown race\n\nmptcp_pm_destroy() empties msk-\u003epm.anno_list and\nmsk-\u003epm.userspace_pm_local_addr_list under msk-\u003epm.lock during socket\nteardown, dropping the lock between the two.\n\nA concurrent userspace PM genl ANNOUNCE on the same msk holds a sock\nreference via mptcp_token_get_sock() and, in\nmptcp_pm_nl_announce_doit(), calls\nmptcp_userspace_pm_append_new_local_addr() and\nmptcp_pm_announced_alloc(). Both take msk-\u003epm.lock briefly to add to\ntheir respective lists. Because the genl handler holds a sock reference,\nmptcp_pm_destroy() may run on the same msk via mptcp_disconnect(), which\ninvokes mptcp_destroy_common() without dropping the sock refcount,\nbefore the handler completes.\n\nIf the lock acquisitions interleave such that mptcp_pm_destroy() empties\na list first, the later alloc adds its entry to a list head that nothing\nelse iterates for this msk, and the entry leaks. kmemleak reports both\nmptcp_pm_add_addr objects (from mptcp_pm_announced_alloc()) and\nmptcp_pm_addr_entry objects (from\nmptcp_userspace_pm_append_new_local_addr()) under sustained concurrent\nANNOUNCE + close load against the userspace PM.\n\nAdd an MPTCP_PM_DESTROYING bit in msk-\u003epm.status, set by\nmptcp_pm_destroy() under pm.lock before the lists are emptied and\nchecked under pm.lock by the alloc paths. Either the alloc takes pm.lock\nfirst, in which case its entry is on the list when mptcp_pm_destroy()\nfrees it; or mptcp_pm_destroy() takes pm.lock first, in which case the\nlater alloc observes the bit and refuses.\n\nFound by an MPTCP protocol-flow harness extending BRF (arXiv:2305.08782)."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T15:12:56.125Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/f48341830e4202db3fe884b819b2db6740f0537d"
},
{
"url": "https://git.kernel.org/stable/c/bb32e9a6a9a9f99eeda16c4efe443400f3e43892"
},
{
"url": "https://git.kernel.org/stable/c/b2a0b55bf613bd3e81ed26a847b0f6b8e6b7f804"
},
{
"url": "https://git.kernel.org/stable/c/9fe5eebb664ecdba88f3fde18062d94b1d1c465f"
},
{
"url": "https://git.kernel.org/stable/c/6c290915a03fc8228b473641025cf762b256dbd2"
},
{
"url": "https://git.kernel.org/stable/c/efc33b5102ff859bacd390a5f30112d8e0c084c0"
}
],
"title": "mptcp: pm: fix memory leak from alloc-during-teardown race",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80784",
"datePublished": "2026-09-04T15:12:56.125Z",
"dateReserved": "2026-08-26T14:34:25.792Z",
"dateUpdated": "2026-09-04T15:12:56.125Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72118 (GCVE-0-2026-72118)
Vulnerability from cvelistv5
Published
2026-08-15 05:52
Modified
2026-08-19 16:36
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
can: bcm: fix CAN frame rx/tx statistics
KCSAN detected a data race within the bcm_rx_handler() when two CAN frames
have been simultaneously received and processed in a single rx op by two
different CPUs.
Use atomic operations with (signed) long data types to access the
statistics in the hot path to fix the KCSAN complaint.
Additionally simplify the update and check of statistics overflow by
using the atomic operations in separate bcm_update_[rx|tx]_stats()
functions. The rx variant runs under bcm_rx_update_lock to prevent
races when resetting the two rx counters; the tx variant runs under
bcm_tx_lock and only needs to guard its own counter's overflow.
As the rx path resets its values already at LONG_MAX / 100, there is
no conflict between the two locking domains (bcm_rx_update_lock vs.
bcm_tx_lock) even for ops that use both paths.
The rx statistics update and the frames_filtered update in
bcm_rx_changed() were previously performed in two separate
bcm_rx_update_lock sections. For an rx op subscribed on all interfaces
(ifindex == 0), bcm_rx_handler() can run concurrently on different
CPUs, so a counter reset by one CPU between these two sections could
leave frames_filtered larger than frames_abs on another CPU, producing
a bogus (even negative) reduction percentage in procfs. Update the
statistics in the same critical section as bcm_rx_changed() to close
this gap, which also removes the now unneeded extra lock/unlock pair
around the traffic_flags calculation.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/can/bcm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "640acf3566fc897065127001be875ebc5401c218",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "47fca0d1620f2d4fab0677564989ef2b9c225c66",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "fd75884eae40a7be47867cbfc9fc84a80bb8ddb4",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "8b2783172d92edd650de6006ebd1c800937021ab",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "970caff5c1a63702c80e08d920256bcb5f88ecc5",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "8104bcdb2612fdda95169ddc3b49747b2ff98d24",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "df47f07cdc801a6afe05a486b5a343c3e532a93c",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "e6c24ba95fc3f1b5e1dcd28b1c6e59ef61a9daa5",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/can/bcm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.25"
},
{
"lessThan": "2.6.25",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.25",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: bcm: fix CAN frame rx/tx statistics\n\nKCSAN detected a data race within the bcm_rx_handler() when two CAN frames\nhave been simultaneously received and processed in a single rx op by two\ndifferent CPUs.\n\nUse atomic operations with (signed) long data types to access the\nstatistics in the hot path to fix the KCSAN complaint.\n\nAdditionally simplify the update and check of statistics overflow by\nusing the atomic operations in separate bcm_update_[rx|tx]_stats()\nfunctions. The rx variant runs under bcm_rx_update_lock to prevent\nraces when resetting the two rx counters; the tx variant runs under\nbcm_tx_lock and only needs to guard its own counter\u0027s overflow.\n\nAs the rx path resets its values already at LONG_MAX / 100, there is\nno conflict between the two locking domains (bcm_rx_update_lock vs.\nbcm_tx_lock) even for ops that use both paths.\n\nThe rx statistics update and the frames_filtered update in\nbcm_rx_changed() were previously performed in two separate\nbcm_rx_update_lock sections. For an rx op subscribed on all interfaces\n(ifindex == 0), bcm_rx_handler() can run concurrently on different\nCPUs, so a counter reset by one CPU between these two sections could\nleave frames_filtered larger than frames_abs on another CPU, producing\na bogus (even negative) reduction percentage in procfs. Update the\nstatistics in the same critical section as bcm_rx_changed() to close\nthis gap, which also removes the now unneeded extra lock/unlock pair\naround the traffic_flags calculation."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:36:11.603Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/640acf3566fc897065127001be875ebc5401c218"
},
{
"url": "https://git.kernel.org/stable/c/47fca0d1620f2d4fab0677564989ef2b9c225c66"
},
{
"url": "https://git.kernel.org/stable/c/fd75884eae40a7be47867cbfc9fc84a80bb8ddb4"
},
{
"url": "https://git.kernel.org/stable/c/8b2783172d92edd650de6006ebd1c800937021ab"
},
{
"url": "https://git.kernel.org/stable/c/970caff5c1a63702c80e08d920256bcb5f88ecc5"
},
{
"url": "https://git.kernel.org/stable/c/8104bcdb2612fdda95169ddc3b49747b2ff98d24"
},
{
"url": "https://git.kernel.org/stable/c/df47f07cdc801a6afe05a486b5a343c3e532a93c"
},
{
"url": "https://git.kernel.org/stable/c/e6c24ba95fc3f1b5e1dcd28b1c6e59ef61a9daa5"
}
],
"title": "can: bcm: fix CAN frame rx/tx statistics",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72118",
"datePublished": "2026-08-15T05:52:57.734Z",
"dateReserved": "2026-08-09T03:40:39.906Z",
"dateUpdated": "2026-08-19T16:36:11.603Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68142 (GCVE-0-2026-68142)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
geneve: require CAP_NET_ADMIN in the device netns for changelink
A tunnel changelink() operates on at most two netns, dev_net(dev) and
the sticky underlay netns geneve->net. They differ once the device is
created in or moved to a netns other than the one the request runs in.
The rtnl changelink path checks CAP_NET_ADMIN only against dev_net(dev),
so a caller privileged there but not in geneve->net can rewrite a geneve
device whose underlay lives in geneve->net.
geneve_changelink() applies the new configuration against geneve->net:
geneve_link_config() and the geneve_quiesce()/geneve_unquiesce() pair
reopen the underlay sockets in that netns (geneve_sock_add() uses
geneve->net), so the same reasoning as the tunnel changelink series
applies here.
Gate geneve_changelink() with rtnl_dev_link_net_capable(), at the top of
the op before any attribute is parsed, matching ipgre_changelink() and
the rest of the "require CAP_NET_ADMIN in the device netns for
changelink" series.
Found by 0sec automated security-research tooling (https://0sec.ai).
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 5b861f6baa3a22a48d7a4ad0ce38a223d36c978a Version: 5b861f6baa3a22a48d7a4ad0ce38a223d36c978a Version: 5b861f6baa3a22a48d7a4ad0ce38a223d36c978a Version: 5b861f6baa3a22a48d7a4ad0ce38a223d36c978a Version: 5b861f6baa3a22a48d7a4ad0ce38a223d36c978a Version: 5b861f6baa3a22a48d7a4ad0ce38a223d36c978a Version: 5b861f6baa3a22a48d7a4ad0ce38a223d36c978a Version: 5b861f6baa3a22a48d7a4ad0ce38a223d36c978a |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/geneve.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a5522963c57f12df5f9db804ebfc472b58eef0ae",
"status": "affected",
"version": "5b861f6baa3a22a48d7a4ad0ce38a223d36c978a",
"versionType": "git"
},
{
"lessThan": "278c6a31ee27c931c722202c8c06cc3253923254",
"status": "affected",
"version": "5b861f6baa3a22a48d7a4ad0ce38a223d36c978a",
"versionType": "git"
},
{
"lessThan": "11a7d989d00160481a273eb4f7f05f64b5a6ffdf",
"status": "affected",
"version": "5b861f6baa3a22a48d7a4ad0ce38a223d36c978a",
"versionType": "git"
},
{
"lessThan": "2abdacc927c92fa6a9cc8341e8c9b88dcb561553",
"status": "affected",
"version": "5b861f6baa3a22a48d7a4ad0ce38a223d36c978a",
"versionType": "git"
},
{
"lessThan": "9de5518fc1fab583526a8f66b8e505c4864dc60a",
"status": "affected",
"version": "5b861f6baa3a22a48d7a4ad0ce38a223d36c978a",
"versionType": "git"
},
{
"lessThan": "f8c498585d2a08aa623748353c3e61467b7e9fd2",
"status": "affected",
"version": "5b861f6baa3a22a48d7a4ad0ce38a223d36c978a",
"versionType": "git"
},
{
"lessThan": "95f45e20f1b2cec13823f0f68060ab4b2261b2c1",
"status": "affected",
"version": "5b861f6baa3a22a48d7a4ad0ce38a223d36c978a",
"versionType": "git"
},
{
"lessThan": "8efb8f8bbb353b8f2fdf4f37534c6d96c9f69e01",
"status": "affected",
"version": "5b861f6baa3a22a48d7a4ad0ce38a223d36c978a",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/geneve.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.14"
},
{
"lessThan": "4.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ngeneve: require CAP_NET_ADMIN in the device netns for changelink\n\nA tunnel changelink() operates on at most two netns, dev_net(dev) and\nthe sticky underlay netns geneve-\u003enet. They differ once the device is\ncreated in or moved to a netns other than the one the request runs in.\nThe rtnl changelink path checks CAP_NET_ADMIN only against dev_net(dev),\nso a caller privileged there but not in geneve-\u003enet can rewrite a geneve\ndevice whose underlay lives in geneve-\u003enet.\n\ngeneve_changelink() applies the new configuration against geneve-\u003enet:\ngeneve_link_config() and the geneve_quiesce()/geneve_unquiesce() pair\nreopen the underlay sockets in that netns (geneve_sock_add() uses\ngeneve-\u003enet), so the same reasoning as the tunnel changelink series\napplies here.\n\nGate geneve_changelink() with rtnl_dev_link_net_capable(), at the top of\nthe op before any attribute is parsed, matching ipgre_changelink() and\nthe rest of the \"require CAP_NET_ADMIN in the device netns for\nchangelink\" series.\n\nFound by 0sec automated security-research tooling (https://0sec.ai)."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires issuing RTM_NEWLINK changelink over a local rtnetlink socket; geneve_changelink is only reachable from the rtnl configuration path, not from received GENEVE/UDP network packets.\nAC:L - Once a geneve device exists with geneve-\u003enet differing from dev_net(dev) (via IFLA_NET_NS_FD migration or IFLA_LINK_NETNSID newlink), a single deterministic netlink changelink bypasses the missing check with no race or memory-layout dependency.\nPR:L - The rtnl entry path requires CAP_NET_ADMIN in dev_net(dev), obtainable by an unprivileged local user inside a user+network namespace via unshare --user --map-root-user --net; no CAP_NET_ADMIN in the sticky underlay netns geneve-\u003enet is needed.\nUI:N - The attack is fully programmatic through netlink from the attacker\u0027s own process; no victim action such as mounting a filesystem, opening a file, or clicking is required.\nS:C - geneve_changelink applies geneve_link_config() and geneve_quiesce()/geneve_unquiesce() (reopening underlay sockets via geneve_sock_add() in geneve-\u003enet) while authorization is checked only against dev_net(dev), crossing into another tenant\u0027s or the host\u0027s network namespace.\nC:H - An attacker can set IFLA_GENEVE_REMOTE/REMOTE6 to redirect encapsulated overlay traffic to an attacker-controlled endpoint and read tunneled payloads from the victim underlay netns.\nI:H - Unauthorized changelink mutates live tunnel remote endpoint, TTL/TOS/DF/label, and MTU in geneve-\u003enet, enabling redirection and injection of overlay traffic without authorization in that namespace.\nA:H - geneve_quiesce() drops in-flight tunnel traffic and rewriting the remote endpoint or MTU breaks production GENEVE overlays (Kubernetes/OVN/cloud SDN), causing sustained loss of connectivity for dependent services."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:30:02.355Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a5522963c57f12df5f9db804ebfc472b58eef0ae"
},
{
"url": "https://git.kernel.org/stable/c/278c6a31ee27c931c722202c8c06cc3253923254"
},
{
"url": "https://git.kernel.org/stable/c/11a7d989d00160481a273eb4f7f05f64b5a6ffdf"
},
{
"url": "https://git.kernel.org/stable/c/2abdacc927c92fa6a9cc8341e8c9b88dcb561553"
},
{
"url": "https://git.kernel.org/stable/c/9de5518fc1fab583526a8f66b8e505c4864dc60a"
},
{
"url": "https://git.kernel.org/stable/c/f8c498585d2a08aa623748353c3e61467b7e9fd2"
},
{
"url": "https://git.kernel.org/stable/c/95f45e20f1b2cec13823f0f68060ab4b2261b2c1"
},
{
"url": "https://git.kernel.org/stable/c/8efb8f8bbb353b8f2fdf4f37534c6d96c9f69e01"
}
],
"title": "geneve: require CAP_NET_ADMIN in the device netns for changelink",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68142",
"datePublished": "2026-08-10T11:59:06.048Z",
"dateReserved": "2026-07-30T09:28:09.370Z",
"dateUpdated": "2026-08-19T16:30:02.355Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68164 (GCVE-0-2026-68164)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
mm/damon/core: disallow overlapping input ranges for damon_set_regions()
damon_set_regions() assumes the input ranges are sorted by the address and
don't overlap each other. Hence the assumption was initially to be
explicitly validated. But commit 97d482f4592f ("mm/damon/sysfs: reuse
damon_set_regions() for regions setting") has mistakenly removed the
validation.
This can make DAMON behave in unexpected ways. At the best, the
monitoring results snapshot will just look weird since there will be
overlapping regions. DAMOS will also work weirdly, applying the same
action multiple times for overlapping regions, and make DAMOS quota weird.
More seriously, depending on the setup and regions updates sequence,
negative size regions can be made. It will trigger WARN_ONCE() if the
kernel is built with CONFIG_DAMON_DEBUG_SANITY=y. Depending on the
monitoring results, the negative size region can further trigger division
by zero in damon_merge_two_regions().
Note that some of the consequences including the WARN_ONCE() and the
divide by zero depend on commits that were introduced after the root cause
commit 97d482f4592f ("mm/damon/sysfs: reuse damon_set_regions() for
regions setting").
Fix the problems by checking the assumption and returning an error if
the input ranges don't meet the assumption.
The issue was discovered [1] by Sashiko.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 97d482f4592fde2322c319f07bc54f3a0d37861c Version: 97d482f4592fde2322c319f07bc54f3a0d37861c Version: 97d482f4592fde2322c319f07bc54f3a0d37861c Version: 97d482f4592fde2322c319f07bc54f3a0d37861c Version: 97d482f4592fde2322c319f07bc54f3a0d37861c Version: 97d482f4592fde2322c319f07bc54f3a0d37861c |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"mm/damon/core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a5c453fffb6f2ce75fc10b5d8bc475f1758010bd",
"status": "affected",
"version": "97d482f4592fde2322c319f07bc54f3a0d37861c",
"versionType": "git"
},
{
"lessThan": "4b4a3e7ef7bb622237495db9ba4dfd7417d6530e",
"status": "affected",
"version": "97d482f4592fde2322c319f07bc54f3a0d37861c",
"versionType": "git"
},
{
"lessThan": "06a4beeeec8f03f0b3e9c78a98f1ae4f0f18cfbd",
"status": "affected",
"version": "97d482f4592fde2322c319f07bc54f3a0d37861c",
"versionType": "git"
},
{
"lessThan": "6ce0db97fb37ab8cf8596edca0e3de8618ab009a",
"status": "affected",
"version": "97d482f4592fde2322c319f07bc54f3a0d37861c",
"versionType": "git"
},
{
"lessThan": "e33adf96afb5883f84b0d98747976bde293e33cb",
"status": "affected",
"version": "97d482f4592fde2322c319f07bc54f3a0d37861c",
"versionType": "git"
},
{
"lessThan": "954157679ec34661c2e87e7eb796104a797c32db",
"status": "affected",
"version": "97d482f4592fde2322c319f07bc54f3a0d37861c",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"mm/damon/core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.19"
},
{
"lessThan": "5.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/damon/core: disallow overlapping input ranges for damon_set_regions()\n\ndamon_set_regions() assumes the input ranges are sorted by the address and\ndon\u0027t overlap each other. Hence the assumption was initially to be\nexplicitly validated. But commit 97d482f4592f (\"mm/damon/sysfs: reuse\ndamon_set_regions() for regions setting\") has mistakenly removed the\nvalidation.\n\nThis can make DAMON behave in unexpected ways. At the best, the\nmonitoring results snapshot will just look weird since there will be\noverlapping regions. DAMOS will also work weirdly, applying the same\naction multiple times for overlapping regions, and make DAMOS quota weird.\nMore seriously, depending on the setup and regions updates sequence,\nnegative size regions can be made. It will trigger WARN_ONCE() if the\nkernel is built with CONFIG_DAMON_DEBUG_SANITY=y. Depending on the\nmonitoring results, the negative size region can further trigger division\nby zero in damon_merge_two_regions().\n\nNote that some of the consequences including the WARN_ONCE() and the\ndivide by zero depend on commits that were introduced after the root cause\ncommit 97d482f4592f (\"mm/damon/sysfs: reuse damon_set_regions() for\nregions setting\").\n\nFix the problems by checking the assumption and returning an error if\nthe input ranges don\u0027t meet the assumption.\n\nThe issue was discovered [1] by Sashiko."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:30:34.916Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a5c453fffb6f2ce75fc10b5d8bc475f1758010bd"
},
{
"url": "https://git.kernel.org/stable/c/4b4a3e7ef7bb622237495db9ba4dfd7417d6530e"
},
{
"url": "https://git.kernel.org/stable/c/06a4beeeec8f03f0b3e9c78a98f1ae4f0f18cfbd"
},
{
"url": "https://git.kernel.org/stable/c/6ce0db97fb37ab8cf8596edca0e3de8618ab009a"
},
{
"url": "https://git.kernel.org/stable/c/e33adf96afb5883f84b0d98747976bde293e33cb"
},
{
"url": "https://git.kernel.org/stable/c/954157679ec34661c2e87e7eb796104a797c32db"
}
],
"title": "mm/damon/core: disallow overlapping input ranges for damon_set_regions()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68164",
"datePublished": "2026-08-10T11:59:31.670Z",
"dateReserved": "2026-07-30T09:28:09.372Z",
"dateUpdated": "2026-08-19T16:30:34.916Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64294 (GCVE-0-2026-64294)
Vulnerability from cvelistv5
Published
2026-07-25 08:49
Modified
2026-08-23 12:45
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
mm: do file ownership checks with the proper mount idmap
Ever since idmapped mounts were introduced, inode ownership checks (for
side-channel protection) in mincore() and madvise(MADV_PAGEOUT) were done
against the nop_mnt_idmap, which completely ignores the file's mount's
idmap. This results in odd edgecases like:
1) mount/bind-mount with an idmap userA:userB:1
2) userB runs an owner_or_capable() check on file that is owned by userA
on-disk/in-memory, but owned by userB after idmap translation
3) owner_or_capable() mysteriously fails as the correct idmap wasn't supplied
In the case of mincore/madvise MADV_PAGEOUT, this is usually benign,
because file_permission(file, MAY_WRITE) will probably succeed, as it uses
the proper idmap internally, but it does not need to be the case on e.g a
0444 file where even the owner itself doesn't have permissions to write to
it.
Since this is clearly not trivial to get right, introduce a
file_owner_or_capable() that can carry the correct semantics, and switch
the various users in mm to it.
The issue was found by manual code inspection & an off-list discussion
with Jan Kara.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 9caccd41541a6f7d6279928d9f971f6642c361af Version: 9caccd41541a6f7d6279928d9f971f6642c361af Version: 9caccd41541a6f7d6279928d9f971f6642c361af Version: 9caccd41541a6f7d6279928d9f971f6642c361af Version: 9caccd41541a6f7d6279928d9f971f6642c361af Version: 9caccd41541a6f7d6279928d9f971f6642c361af Version: 9caccd41541a6f7d6279928d9f971f6642c361af |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"include/linux/fs.h",
"mm/filemap.c",
"mm/madvise.c",
"mm/mincore.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "7368bec565bac3e536cd43579dbde1e715e6ba61",
"status": "affected",
"version": "9caccd41541a6f7d6279928d9f971f6642c361af",
"versionType": "git"
},
{
"lessThan": "b2f3d94ea310bea9d36d53e9d9b3f45e86c1d893",
"status": "affected",
"version": "9caccd41541a6f7d6279928d9f971f6642c361af",
"versionType": "git"
},
{
"lessThan": "744b23aa430d52f5c8e4dbff7d71496d6643bed2",
"status": "affected",
"version": "9caccd41541a6f7d6279928d9f971f6642c361af",
"versionType": "git"
},
{
"lessThan": "8344bdf0629457e532797b42d9d2bbf2a2900bbf",
"status": "affected",
"version": "9caccd41541a6f7d6279928d9f971f6642c361af",
"versionType": "git"
},
{
"lessThan": "5c942ad7df75925ee166e7f0fb36892d8dde376b",
"status": "affected",
"version": "9caccd41541a6f7d6279928d9f971f6642c361af",
"versionType": "git"
},
{
"lessThan": "04ba248d02d9eaa3d9077b00a6134caa75fa3e90",
"status": "affected",
"version": "9caccd41541a6f7d6279928d9f971f6642c361af",
"versionType": "git"
},
{
"lessThan": "e187bc02f8fa4226d62814592cf064ee4557c470",
"status": "affected",
"version": "9caccd41541a6f7d6279928d9f971f6642c361af",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"include/linux/fs.h",
"mm/filemap.c",
"mm/madvise.c",
"mm/mincore.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.12"
},
{
"lessThan": "5.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm: do file ownership checks with the proper mount idmap\n\nEver since idmapped mounts were introduced, inode ownership checks (for\nside-channel protection) in mincore() and madvise(MADV_PAGEOUT) were done\nagainst the nop_mnt_idmap, which completely ignores the file\u0027s mount\u0027s\nidmap. This results in odd edgecases like:\n\n1) mount/bind-mount with an idmap userA:userB:1\n2) userB runs an owner_or_capable() check on file that is owned by userA\non-disk/in-memory, but owned by userB after idmap translation\n3) owner_or_capable() mysteriously fails as the correct idmap wasn\u0027t supplied\n\nIn the case of mincore/madvise MADV_PAGEOUT, this is usually benign,\nbecause file_permission(file, MAY_WRITE) will probably succeed, as it uses\nthe proper idmap internally, but it does not need to be the case on e.g a\n0444 file where even the owner itself doesn\u0027t have permissions to write to\nit.\n\nSince this is clearly not trivial to get right, introduce a\nfile_owner_or_capable() that can carry the correct semantics, and switch\nthe various users in mm to it.\n\nThe issue was found by manual code inspection \u0026 an off-list discussion\nwith Jan Kara."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:45:40.258Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/7368bec565bac3e536cd43579dbde1e715e6ba61"
},
{
"url": "https://git.kernel.org/stable/c/b2f3d94ea310bea9d36d53e9d9b3f45e86c1d893"
},
{
"url": "https://git.kernel.org/stable/c/744b23aa430d52f5c8e4dbff7d71496d6643bed2"
},
{
"url": "https://git.kernel.org/stable/c/8344bdf0629457e532797b42d9d2bbf2a2900bbf"
},
{
"url": "https://git.kernel.org/stable/c/5c942ad7df75925ee166e7f0fb36892d8dde376b"
},
{
"url": "https://git.kernel.org/stable/c/04ba248d02d9eaa3d9077b00a6134caa75fa3e90"
},
{
"url": "https://git.kernel.org/stable/c/e187bc02f8fa4226d62814592cf064ee4557c470"
}
],
"title": "mm: do file ownership checks with the proper mount idmap",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64294",
"datePublished": "2026-07-25T08:49:32.570Z",
"dateReserved": "2026-07-19T15:36:31.778Z",
"dateUpdated": "2026-08-23T12:45:40.258Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72125 (GCVE-0-2026-72125)
Vulnerability from cvelistv5
Published
2026-08-15 05:53
Modified
2026-08-19 16:36
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
can: isotp: fix use-after-free race with concurrent NETDEV_UNREGISTER
isotp_release() looked up the bound network device via dev_get_by_index()
using the stored ifindex. During device unregistration the device is
unlisted from the ifindex hash before the NETDEV_UNREGISTER notifier
chain runs, so a concurrent isotp_release() could find no device, skip
can_rx_unregister() entirely, and still proceed to free the socket.
Since isotp_release() had already removed itself from the isotp
notifier list at that point, isotp_notify() would never get a chance to
clean up either, leaving a stale CAN filter that keeps pointing at the
freed socket.
Fix this the same way raw.c already does: hold a tracked reference to
the bound net_device in the socket (so->dev/so->dev_tracker) from
bind() onward instead of re-resolving it from the ifindex, and
serialize bind()/release() with rtnl_lock() so that so->dev is always
consistent with what the NETDEV_UNREGISTER notifier sees. so->dev
stays valid regardless of ifindex-hash unlisting, and is only ever
cleared by whichever of isotp_release()/isotp_notify() gets there
first, so the filter is always removed exactly once.
isotp_bind() now rejects a (re)bind with -EAGAIN while so->[tx|rx].state
isn't ISOTP_IDLE yet, so a timer left running by a prior
NETDEV_UNREGISTER can't act on a newly bound so->ifindex. Both checks
share the same lock_sock() section, so there is no window in which a
concurrent isotp_notify() clearing so->bound could be missed.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: e057dd3fc20ffb3d7f150af46542a51b59b90127 Version: e057dd3fc20ffb3d7f150af46542a51b59b90127 Version: e057dd3fc20ffb3d7f150af46542a51b59b90127 Version: e057dd3fc20ffb3d7f150af46542a51b59b90127 Version: e057dd3fc20ffb3d7f150af46542a51b59b90127 Version: e057dd3fc20ffb3d7f150af46542a51b59b90127 Version: e057dd3fc20ffb3d7f150af46542a51b59b90127 Version: e057dd3fc20ffb3d7f150af46542a51b59b90127 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/can/isotp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "f311bbb29bb06aaab69ba45a6e4b11323d20b8f9",
"status": "affected",
"version": "e057dd3fc20ffb3d7f150af46542a51b59b90127",
"versionType": "git"
},
{
"lessThan": "8e018f4335590460ebcf0c2b493ed38ba1a35204",
"status": "affected",
"version": "e057dd3fc20ffb3d7f150af46542a51b59b90127",
"versionType": "git"
},
{
"lessThan": "33b9cd9245e2a4b800f99ed1cc53d64960614152",
"status": "affected",
"version": "e057dd3fc20ffb3d7f150af46542a51b59b90127",
"versionType": "git"
},
{
"lessThan": "0b811c4bbe3ec9ad611e90a540fe8b51b3bb8a96",
"status": "affected",
"version": "e057dd3fc20ffb3d7f150af46542a51b59b90127",
"versionType": "git"
},
{
"lessThan": "43884dc7963beef2328f507f4fe680bdc173eb80",
"status": "affected",
"version": "e057dd3fc20ffb3d7f150af46542a51b59b90127",
"versionType": "git"
},
{
"lessThan": "7bef39ba76eb7307ed22a50329e0f5776dbeda58",
"status": "affected",
"version": "e057dd3fc20ffb3d7f150af46542a51b59b90127",
"versionType": "git"
},
{
"lessThan": "e442b62ba5a7756c17e05a77b32cdd085a2b6138",
"status": "affected",
"version": "e057dd3fc20ffb3d7f150af46542a51b59b90127",
"versionType": "git"
},
{
"lessThan": "20bab8b88baac140ca3701116e1d486c7f51e311",
"status": "affected",
"version": "e057dd3fc20ffb3d7f150af46542a51b59b90127",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/can/isotp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.10"
},
{
"lessThan": "5.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: isotp: fix use-after-free race with concurrent NETDEV_UNREGISTER\n\nisotp_release() looked up the bound network device via dev_get_by_index()\nusing the stored ifindex. During device unregistration the device is\nunlisted from the ifindex hash before the NETDEV_UNREGISTER notifier\nchain runs, so a concurrent isotp_release() could find no device, skip\ncan_rx_unregister() entirely, and still proceed to free the socket.\nSince isotp_release() had already removed itself from the isotp\nnotifier list at that point, isotp_notify() would never get a chance to\nclean up either, leaving a stale CAN filter that keeps pointing at the\nfreed socket.\n\nFix this the same way raw.c already does: hold a tracked reference to\nthe bound net_device in the socket (so-\u003edev/so-\u003edev_tracker) from\nbind() onward instead of re-resolving it from the ifindex, and\nserialize bind()/release() with rtnl_lock() so that so-\u003edev is always\nconsistent with what the NETDEV_UNREGISTER notifier sees. so-\u003edev\nstays valid regardless of ifindex-hash unlisting, and is only ever\ncleared by whichever of isotp_release()/isotp_notify() gets there\nfirst, so the filter is always removed exactly once.\n\nisotp_bind() now rejects a (re)bind with -EAGAIN while so-\u003e[tx|rx].state\nisn\u0027t ISOTP_IDLE yet, so a timer left running by a prior\nNETDEV_UNREGISTER can\u0027t act on a newly bound so-\u003eifindex. Both checks\nshare the same lock_sock() section, so there is no window in which a\nconcurrent isotp_notify() clearing so-\u003ebound could be missed."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires local AF_CAN ISO-TP socket operations (socket/bind/close) racing NETDEV_UNREGISTER on the bound CAN interface; stale-filter UAF is triggered via local frame injection or an existing bound interface, not a remote IP/network service.\nAC:L - The attacker controls both sides of the race by concurrently closing the ISO-TP socket and unregistering the bound CAN device (e.g., vcan create/delete with CAP_NET_ADMIN in a user namespace), and can retry until the stale RX filter is left on a freed socket.\nPR:L - No init-namespace root is required: any local user can open CAN_ISOTP sockets, and CAP_NET_ADMIN obtainable in user namespaces suffices to create/delete vcan and drive the unregister path used in automotive/embedded ISO-TP (UDS) deployments.\nUI:N - No victim interaction is needed; the use-after-free is triggered by the attacker\u0027s own concurrent close()/NETDEV_UNREGISTER operations and subsequent CAN frames sent to the bound IDs.\nS:U - Impact is kernel heap corruption and potential privilege escalation within the same OS security boundary; it does not inherently cross VM, container, or IOMMU isolation boundaries.\nC:H - A stale can_rx filter keeps calling isotp_rcv()/isotp_rcv_echo() with a freed isotp_sock, enabling reads of reallocated slab contents through socket state, sock_queue_rcv_skb(), and protocol parsing on attacker-influenced memory.\nI:H - The UAF path performs extensive writes to freed socket state (RX/TX buffers, timers, generation counters) and can emit CAN traffic, providing primitives for heap shaping and control-flow hijack rather than a crash-only fault.\nA:H - Use-after-free in softirq CAN receive callbacks commonly causes kernel oops/panic from dereferencing or writing freed isotp_sock/timer state, even before reliable exploitation."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:36:23.877Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/f311bbb29bb06aaab69ba45a6e4b11323d20b8f9"
},
{
"url": "https://git.kernel.org/stable/c/8e018f4335590460ebcf0c2b493ed38ba1a35204"
},
{
"url": "https://git.kernel.org/stable/c/33b9cd9245e2a4b800f99ed1cc53d64960614152"
},
{
"url": "https://git.kernel.org/stable/c/0b811c4bbe3ec9ad611e90a540fe8b51b3bb8a96"
},
{
"url": "https://git.kernel.org/stable/c/43884dc7963beef2328f507f4fe680bdc173eb80"
},
{
"url": "https://git.kernel.org/stable/c/7bef39ba76eb7307ed22a50329e0f5776dbeda58"
},
{
"url": "https://git.kernel.org/stable/c/e442b62ba5a7756c17e05a77b32cdd085a2b6138"
},
{
"url": "https://git.kernel.org/stable/c/20bab8b88baac140ca3701116e1d486c7f51e311"
}
],
"title": "can: isotp: fix use-after-free race with concurrent NETDEV_UNREGISTER",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72125",
"datePublished": "2026-08-15T05:53:02.905Z",
"dateReserved": "2026-08-09T03:40:39.907Z",
"dateUpdated": "2026-08-19T16:36:23.877Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68304 (GCVE-0-2026-68304)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-19 16:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: brcmfmac: fix 802.1X-SHA256 call trace warning
Based on wpa_auth as 1x_256 mode, need to set up
"use_fwsup" with BRCMF_PROFILE_FWSUP_1X.
Or it will happen trace warning when call brcmf_cfg80211_set_pmk().
[ 4481.831101] ------------[ cut here ]------------
[ 4481.831102] WARNING: CPU: 1 PID: 2997 at
drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c:7242 brcmf_cfg80211_set_pmk+0x77/0xd0 [brcmfmac]
[...]
[ 4481.831202] Call Trace:
[ 4481.831204] <TASK>
[ 4481.831205] nl80211_set_pmk+0x183/0x250 [cfg80211]
[ 4481.831233] genl_family_rcv_msg_doit+0xea/0x150
[ 4481.831237] genl_rcv_msg+0x104/0x240
[ 4481.831239] ? cfg80211_probe_status+0x2c0/0x2c0 [cfg80211]
[ 4481.831257] ? genl_family_rcv_msg_doit+0x150/0x150
[ 4481.831259] netlink_rcv_skb+0x4e/0x100
[ 4481.831261] genl_rcv+0x24/0x40
[ 4481.831262] netlink_unicast+0x236/0x380
[ 4481.831264] netlink_sendmsg+0x250/0x4b0
[ 4481.831266] sock_sendmsg+0x5c/0x70
[ 4481.831269] ____sys_sendmsg+0x236/0x2b0
[ 4481.831271] ? copy_msghdr_from_user+0x6d/0xa0
[ 4481.831272] ___sys_sendmsg+0x86/0xd0
[ 4481.831274] ? avc_has_perm+0x8c/0x1a0
[ 4481.831276] ? preempt_count_add+0x6a/0xa0
[ 4481.831279] ? sock_has_perm+0x82/0xa0
[ 4481.831280] __sys_sendmsg+0x57/0xa0
[ 4481.831282] do_syscall_64+0x38/0x90
[ 4481.831284] entry_SYSCALL_64_after_hwframe+0x63/0xcd
[ 4481.831286] RIP: 0033:0x7fd270d369b4
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 2526ff21aa77c205f72e8263335f20b7d7e636fc Version: 2526ff21aa77c205f72e8263335f20b7d7e636fc Version: 2526ff21aa77c205f72e8263335f20b7d7e636fc Version: 2526ff21aa77c205f72e8263335f20b7d7e636fc Version: 2526ff21aa77c205f72e8263335f20b7d7e636fc Version: 2526ff21aa77c205f72e8263335f20b7d7e636fc Version: 2526ff21aa77c205f72e8263335f20b7d7e636fc Version: 2526ff21aa77c205f72e8263335f20b7d7e636fc |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "fe27cc1feecde0e6a0a9a04b7ad3262ed5f99252",
"status": "affected",
"version": "2526ff21aa77c205f72e8263335f20b7d7e636fc",
"versionType": "git"
},
{
"lessThan": "47989a233df369c2c2263ab0a5cbd8c8dad253a5",
"status": "affected",
"version": "2526ff21aa77c205f72e8263335f20b7d7e636fc",
"versionType": "git"
},
{
"lessThan": "d0395840e3266397de94ecd3c91e1c188c7667c6",
"status": "affected",
"version": "2526ff21aa77c205f72e8263335f20b7d7e636fc",
"versionType": "git"
},
{
"lessThan": "137e4710da626290495b174e2eb1d5e889a4b165",
"status": "affected",
"version": "2526ff21aa77c205f72e8263335f20b7d7e636fc",
"versionType": "git"
},
{
"lessThan": "d3ac5b35ec85c41ccf8ec524d47b520e72edaca1",
"status": "affected",
"version": "2526ff21aa77c205f72e8263335f20b7d7e636fc",
"versionType": "git"
},
{
"lessThan": "00ebbf030d8c4a1cb89cbbae15e28332373649db",
"status": "affected",
"version": "2526ff21aa77c205f72e8263335f20b7d7e636fc",
"versionType": "git"
},
{
"lessThan": "bd4fac033bb95fcad898cf6734e869991b2561cb",
"status": "affected",
"version": "2526ff21aa77c205f72e8263335f20b7d7e636fc",
"versionType": "git"
},
{
"lessThan": "7cb34f6c4fe8a68af621d870abe63bfca2275dd6",
"status": "affected",
"version": "2526ff21aa77c205f72e8263335f20b7d7e636fc",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.13"
},
{
"lessThan": "4.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: brcmfmac: fix 802.1X-SHA256 call trace warning\n\nBased on wpa_auth as 1x_256 mode, need to set up\n\"use_fwsup\" with BRCMF_PROFILE_FWSUP_1X.\nOr it will happen trace warning when call brcmf_cfg80211_set_pmk().\n\n[ 4481.831101] ------------[ cut here ]------------\n[ 4481.831102] WARNING: CPU: 1 PID: 2997 at\ndrivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c:7242 brcmf_cfg80211_set_pmk+0x77/0xd0 [brcmfmac]\n[...]\n[ 4481.831202] Call Trace:\n[ 4481.831204] \u00a0\u003cTASK\u003e\n[ 4481.831205] \u00a0nl80211_set_pmk+0x183/0x250 [cfg80211]\n[ 4481.831233] \u00a0genl_family_rcv_msg_doit+0xea/0x150\n[ 4481.831237] \u00a0genl_rcv_msg+0x104/0x240\n[ 4481.831239] \u00a0? cfg80211_probe_status+0x2c0/0x2c0 [cfg80211]\n[ 4481.831257] \u00a0? genl_family_rcv_msg_doit+0x150/0x150\n[ 4481.831259] \u00a0netlink_rcv_skb+0x4e/0x100\n[ 4481.831261] \u00a0genl_rcv+0x24/0x40\n[ 4481.831262] \u00a0netlink_unicast+0x236/0x380\n[ 4481.831264] \u00a0netlink_sendmsg+0x250/0x4b0\n[ 4481.831266] \u00a0sock_sendmsg+0x5c/0x70\n[ 4481.831269] \u00a0____sys_sendmsg+0x236/0x2b0\n[ 4481.831271] \u00a0? copy_msghdr_from_user+0x6d/0xa0\n[ 4481.831272] \u00a0___sys_sendmsg+0x86/0xd0\n[ 4481.831274] \u00a0? avc_has_perm+0x8c/0x1a0\n[ 4481.831276] \u00a0? preempt_count_add+0x6a/0xa0\n[ 4481.831279] \u00a0? sock_has_perm+0x82/0xa0\n[ 4481.831280] \u00a0__sys_sendmsg+0x57/0xa0\n[ 4481.831282] \u00a0do_syscall_64+0x38/0x90\n[ 4481.831284] \u00a0entry_SYSCALL_64_after_hwframe+0x63/0xcd\n[ 4481.831286] RIP: 0033:0x7fd270d369b4"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:32:58.379Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/fe27cc1feecde0e6a0a9a04b7ad3262ed5f99252"
},
{
"url": "https://git.kernel.org/stable/c/47989a233df369c2c2263ab0a5cbd8c8dad253a5"
},
{
"url": "https://git.kernel.org/stable/c/d0395840e3266397de94ecd3c91e1c188c7667c6"
},
{
"url": "https://git.kernel.org/stable/c/137e4710da626290495b174e2eb1d5e889a4b165"
},
{
"url": "https://git.kernel.org/stable/c/d3ac5b35ec85c41ccf8ec524d47b520e72edaca1"
},
{
"url": "https://git.kernel.org/stable/c/00ebbf030d8c4a1cb89cbbae15e28332373649db"
},
{
"url": "https://git.kernel.org/stable/c/bd4fac033bb95fcad898cf6734e869991b2561cb"
},
{
"url": "https://git.kernel.org/stable/c/7cb34f6c4fe8a68af621d870abe63bfca2275dd6"
}
],
"title": "wifi: brcmfmac: fix 802.1X-SHA256 call trace warning",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68304",
"datePublished": "2026-08-10T12:02:38.515Z",
"dateReserved": "2026-07-30T09:28:09.381Z",
"dateUpdated": "2026-08-19T16:32:58.379Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2025-40139 (GCVE-0-2025-40139)
Vulnerability from cvelistv5
Published
2025-11-12 10:23
Modified
2026-09-02 12:49
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
smc: Use __sk_dst_get() and dst_dev_rcu() in in smc_clc_prfx_set().
smc_clc_prfx_set() is called during connect() and not under RCU
nor RTNL.
Using sk_dst_get(sk)->dev could trigger UAF.
Let's use __sk_dst_get() and dev_dst_rcu() under rcu_read_lock()
after kernel_getsockname().
Note that the returned value of smc_clc_prfx_set() is not used
in the caller.
While at it, we change the 1st arg of smc_clc_prfx_set[46]_rcu()
not to touch dst there.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/smc/smc_clc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "5a2fccc4b32c13ddde3676f9e15e1a9baa7d6fde",
"status": "affected",
"version": "a046d57da19f812216f393e7c535f5858f793ac3",
"versionType": "git"
},
{
"lessThan": "80d1fd39f4e37d836655e9f7ffccaf78925049bf",
"status": "affected",
"version": "a046d57da19f812216f393e7c535f5858f793ac3",
"versionType": "git"
},
{
"lessThan": "956c57daba55cf9ed25d9f2512883b8a1a927599",
"status": "affected",
"version": "a046d57da19f812216f393e7c535f5858f793ac3",
"versionType": "git"
},
{
"lessThan": "0736993bfe5c7a9c744ae3fac62d769dfdae54e1",
"status": "affected",
"version": "a046d57da19f812216f393e7c535f5858f793ac3",
"versionType": "git"
},
{
"lessThan": "935d783e5de9b64587f3adb25641dd8385e64ddb",
"status": "affected",
"version": "a046d57da19f812216f393e7c535f5858f793ac3",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/smc/smc_clc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.11"
},
{
"lessThan": "4.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.187",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.156",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.108",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.17.*",
"status": "unaffected",
"version": "6.17.3",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "6.18",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.187",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.156",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.108",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.17.3",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18",
"versionStartIncluding": "4.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmc: Use __sk_dst_get() and dst_dev_rcu() in in smc_clc_prfx_set().\n\nsmc_clc_prfx_set() is called during connect() and not under RCU\nnor RTNL.\n\nUsing sk_dst_get(sk)-\u003edev could trigger UAF.\n\nLet\u0027s use __sk_dst_get() and dev_dst_rcu() under rcu_read_lock()\nafter kernel_getsockname().\n\nNote that the returned value of smc_clc_prfx_set() is not used\nin the caller.\n\nWhile at it, we change the 1st arg of smc_clc_prfx_set[46]_rcu()\nnot to touch dst there."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - `smc_clc_prfx_set()` is only reached from the client side of the CLC handshake, via `connect()` on a locally created AF_SMC socket (`smc_connect` \u2192 `__smc_connect` \u2192 `smc_clc_send_proposal`). The attacker must have local code execution to initiate the connection, so the vector is Local even though the leaked bytes are subsequently sent to a remote peer.\nAC:L - The attacker drives both sides of the race \u2014 one thread loops `connect()` on AF_SMC sockets (the stale `dst-\u003edev` dereference), while another repeatedly creates and deletes net_devices to force `dst_dev_put()`/`free_netdev()`, which unprivileged users can do freely inside a user namespace with CAP_NET_ADMIN. No condition depends on state outside the attacker\u0027s influence, and the window is widened at will by using non-blocking connect so the work runs in `smc_connect_work`.\nPR:L - `smc_create()` performs no capability check and `MODULE_ALIAS_NETPROTO(PF_SMC)` lets any unprivileged user autoload the module; the netdev teardown side needs CAP_NET_ADMIN, which is obtainable by an ordinary user via `unshare -Urn` and therefore counts as Low, not High.\nUI:N - The attacker\u0027s own process performs every step \u2014 creating the SMC socket, connecting to a listener it controls, and tearing down the device \u2014 with no action required from any other user or administrator.\nS:U - The use-after-free touches the freed `net_device` slab and the `in_device`/`inet6_dev` structures it points to, all within the kernel\u0027s own security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - The freed `net_device` is dereferenced and its `ifa_list`/`addr_list` walked, and a reclaimed slab can be groomed with attacker-controlled data, yielding an arbitrary kernel-memory read; worse, `smc_clc_prfx_set6_rcu()` copies up to 8 prefixes out of that freed memory into the CLC Proposal that `smc_clc_send_proposal()` transmits, exfiltrating freed kernel bytes onto the wire.\nI:H - A use-after-free on a `net_device` is a heap-corruption primitive \u2014 the reclaimed object\u0027s contents are attacker-influenceable through heap spraying and the code follows pointers out of it (`dev-\u003eip_ptr`, `dev-\u003eip6_ptr`, list heads), which can be groomed into an arbitrary write and control-flow hijack.\nA:H - Dereferencing the freed device and walking a bogus `in_dev`/`inet6_dev` address list reliably produces a kernel oops or panic, or an unbounded list walk that hangs the CPU, and the attacker can repeat the attempt indefinitely."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-02T12:49:26.951Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/5a2fccc4b32c13ddde3676f9e15e1a9baa7d6fde"
},
{
"url": "https://git.kernel.org/stable/c/80d1fd39f4e37d836655e9f7ffccaf78925049bf"
},
{
"url": "https://git.kernel.org/stable/c/956c57daba55cf9ed25d9f2512883b8a1a927599"
},
{
"url": "https://git.kernel.org/stable/c/0736993bfe5c7a9c744ae3fac62d769dfdae54e1"
},
{
"url": "https://git.kernel.org/stable/c/935d783e5de9b64587f3adb25641dd8385e64ddb"
}
],
"title": "smc: Use __sk_dst_get() and dst_dev_rcu() in in smc_clc_prfx_set().",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2025-40139",
"datePublished": "2025-11-12T10:23:24.216Z",
"dateReserved": "2025-04-16T07:20:57.171Z",
"dateUpdated": "2026-09-02T12:49:26.951Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74581 (GCVE-0-2026-74581)
Vulnerability from cvelistv5
Published
2026-08-21 16:31
Modified
2026-08-25 05:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: ipv6: clear suppressed fib6 rule result
fib6_rule_suppress() drops a suppressed route with ip6_rt_put_flags(),
but leaves res->rt6 pointing at the released rt6_info.
If no later rule supplies a replacement, fib6_rule_lookup() still sees
res.rt6 and returns that stale dst to its caller. A suppressing rule can
therefore leak a released route back to rt6_lookup(), and the next put
hits rcuref_put_slowpath() from dst_release().
Clear res->rt6 when suppressing the route so suppressed lookups fall
through to the null dst instead of reusing the released one.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 209d35ee34e25f9668c404350a1c86d914c54ffa Version: 8ef8a76a340ebdb2c2eea3f6fb0ebbed09a16383 Version: cdef485217d30382f3bf6448c54b4401648fe3f1 Version: cdef485217d30382f3bf6448c54b4401648fe3f1 Version: cdef485217d30382f3bf6448c54b4401648fe3f1 Version: cdef485217d30382f3bf6448c54b4401648fe3f1 Version: cdef485217d30382f3bf6448c54b4401648fe3f1 Version: cdef485217d30382f3bf6448c54b4401648fe3f1 Version: ee38eb8cf9a7323884c2b8e0adbbeb2192d31e29 Version: 5.10.84 ≤ Version: 5.15.7 ≤ Version: 5.4.164 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ipv6/fib6_rules.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "90c57310e266eb94e4a80d6b15a9ca131d2e82cb",
"status": "affected",
"version": "209d35ee34e25f9668c404350a1c86d914c54ffa",
"versionType": "git"
},
{
"lessThan": "5d29b286c9de0b309e94b9ed083aa1a2f429434f",
"status": "affected",
"version": "8ef8a76a340ebdb2c2eea3f6fb0ebbed09a16383",
"versionType": "git"
},
{
"lessThan": "354db6243eca59e9d187ffbf8b7955b044ce84dc",
"status": "affected",
"version": "cdef485217d30382f3bf6448c54b4401648fe3f1",
"versionType": "git"
},
{
"lessThan": "6d98c70fe0ba8c7708bfd5b2a5174d2086775daa",
"status": "affected",
"version": "cdef485217d30382f3bf6448c54b4401648fe3f1",
"versionType": "git"
},
{
"lessThan": "9bad152c42b37499162367fe47867411e62fffa3",
"status": "affected",
"version": "cdef485217d30382f3bf6448c54b4401648fe3f1",
"versionType": "git"
},
{
"lessThan": "dc3ab04220667f254f4348572b2a0b3febff89fb",
"status": "affected",
"version": "cdef485217d30382f3bf6448c54b4401648fe3f1",
"versionType": "git"
},
{
"lessThan": "a341c091ca0bfae377747b1b59a3bd8ebe18a937",
"status": "affected",
"version": "cdef485217d30382f3bf6448c54b4401648fe3f1",
"versionType": "git"
},
{
"lessThan": "6aea62e433fe1b586202a5fee8b5807ce635e1d7",
"status": "affected",
"version": "cdef485217d30382f3bf6448c54b4401648fe3f1",
"versionType": "git"
},
{
"status": "affected",
"version": "ee38eb8cf9a7323884c2b8e0adbbeb2192d31e29",
"versionType": "git"
},
{
"lessThan": "5.10.265",
"status": "affected",
"version": "5.10.84",
"versionType": "semver"
},
{
"lessThan": "5.15.216",
"status": "affected",
"version": "5.15.7",
"versionType": "semver"
},
{
"lessThan": "5.5",
"status": "affected",
"version": "5.4.164",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ipv6/fib6_rules.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.16"
},
{
"lessThan": "5.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.10.84",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.15.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.4.164",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ipv6: clear suppressed fib6 rule result\n\nfib6_rule_suppress() drops a suppressed route with ip6_rt_put_flags(),\nbut leaves res-\u003ert6 pointing at the released rt6_info.\n\nIf no later rule supplies a replacement, fib6_rule_lookup() still sees\nres.rt6 and returns that stale dst to its caller. A suppressing rule can\ntherefore leak a released route back to rt6_lookup(), and the next put\nhits rcuref_put_slowpath() from dst_release().\n\nClear res-\u003ert6 when suppressing the route so suppressed lookups fall\nthrough to the null dst instead of reusing the released one."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - fib6_rule_suppress() runs on every IPv6 route lookup via fib6_rule_lookup(), including ip6_route_input() for received packets and icmp6/icmpv6 redirect handlers; WireGuard/VPN servers commonly deploy suppress_prefixlength rules (wg-quick), so remote IPv6 traffic to those hosts reaches the bug.\nAC:L - Once suppress_prefixlength IPv6 policy routing rules exist, any matching packet deterministically triggers fib6_rule_suppress() to release the route while leaving a stale res-\u003ert6 pointer; no race or uncontrollable memory layout is required.\nPR:N - Remote exploitation needs only the ability to send IPv6 packets through a host whose operator already configured suppress rules (e.g., wg-quick); CAP_NET_ADMIN is an admin deployment prerequisite, not attacker privilege on the target.\nUI:N - No victim action is required beyond normal delivery of attacker-generated IPv6 traffic (or ICMPv6 redirect) to a host performing policy-route lookup.\nS:U - The stale rt6_info/dst_entry UAF corrupts kernel heap memory within the same host security boundary; it is not a VM escape or cross-authority sandbox break.\nC:H - Returning a released rt6_info leaves a dangling dst_entry in ip6_dst_cache; subsequent reads through ip6_dst_idev(), dst metrics, or error paths are classic slab UAF with attacker-influencable heap reuse via sustained IPv6 traffic.\nI:H - Double-free/imbalanced rcuref put and post-free use of rt6_info fields give heap corruption primitives; UAF on dst/route cache objects is routinely leveraged for kernel write and control-flow hijack.\nA:H - Commit explicitly reports rcuref_put_slowpath() WARN from dst_release() on the freed route; UAF and refcount corruption can oops/panic the kernel, fully denying availability."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:40:07.594Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/90c57310e266eb94e4a80d6b15a9ca131d2e82cb"
},
{
"url": "https://git.kernel.org/stable/c/5d29b286c9de0b309e94b9ed083aa1a2f429434f"
},
{
"url": "https://git.kernel.org/stable/c/354db6243eca59e9d187ffbf8b7955b044ce84dc"
},
{
"url": "https://git.kernel.org/stable/c/6d98c70fe0ba8c7708bfd5b2a5174d2086775daa"
},
{
"url": "https://git.kernel.org/stable/c/9bad152c42b37499162367fe47867411e62fffa3"
},
{
"url": "https://git.kernel.org/stable/c/dc3ab04220667f254f4348572b2a0b3febff89fb"
},
{
"url": "https://git.kernel.org/stable/c/a341c091ca0bfae377747b1b59a3bd8ebe18a937"
},
{
"url": "https://git.kernel.org/stable/c/6aea62e433fe1b586202a5fee8b5807ce635e1d7"
}
],
"title": "net: ipv6: clear suppressed fib6 rule result",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74581",
"datePublished": "2026-08-21T16:31:54.683Z",
"dateReserved": "2026-08-15T05:44:03.918Z",
"dateUpdated": "2026-08-25T05:40:07.594Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68328 (GCVE-0-2026-68328)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
nfp: Check resource mutex allocation
nfp_cpp_resource_find() allocates a CPP mutex handle for the matching
resource-table entry and then reports success. nfp_resource_try_acquire()
immediately passes that handle to nfp_cpp_mutex_trylock().
However, nfp_cpp_mutex_alloc() returns NULL on failure. If that happens
for a matching table entry, the resource lookup still returns success and
the following trylock dereferences a NULL mutex pointer while opening the
resource.
nfp_resource_acquire() already treats failure to allocate the table mutex
as -ENOMEM. Do the same for the resource mutex and fail the lookup before
publishing the rest of the resource handle.
This issue was found by a static analysis checker and confirmed by
manual source review.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: f01a2161577d31b14581e0db3bbbdfa963f145b6 Version: f01a2161577d31b14581e0db3bbbdfa963f145b6 Version: f01a2161577d31b14581e0db3bbbdfa963f145b6 Version: f01a2161577d31b14581e0db3bbbdfa963f145b6 Version: f01a2161577d31b14581e0db3bbbdfa963f145b6 Version: f01a2161577d31b14581e0db3bbbdfa963f145b6 Version: f01a2161577d31b14581e0db3bbbdfa963f145b6 Version: f01a2161577d31b14581e0db3bbbdfa963f145b6 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/netronome/nfp/nfpcore/nfp_resource.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "18737a48acc87e4cbe41d6fea9a3f44eae490e24",
"status": "affected",
"version": "f01a2161577d31b14581e0db3bbbdfa963f145b6",
"versionType": "git"
},
{
"lessThan": "423523f96a681428ce6e214eaf47f0d8242319de",
"status": "affected",
"version": "f01a2161577d31b14581e0db3bbbdfa963f145b6",
"versionType": "git"
},
{
"lessThan": "0dbd85a8cc35c14bd26e686fa5fae8c64a7958ae",
"status": "affected",
"version": "f01a2161577d31b14581e0db3bbbdfa963f145b6",
"versionType": "git"
},
{
"lessThan": "6dbd428119cb1fd1b73cf6968c711f4ea964dc8b",
"status": "affected",
"version": "f01a2161577d31b14581e0db3bbbdfa963f145b6",
"versionType": "git"
},
{
"lessThan": "cfa119aa781c4044dab5b4c1e5864600f53a26bc",
"status": "affected",
"version": "f01a2161577d31b14581e0db3bbbdfa963f145b6",
"versionType": "git"
},
{
"lessThan": "3b1d4fc3b73ea6faf008a0996ce6190c6e43efc3",
"status": "affected",
"version": "f01a2161577d31b14581e0db3bbbdfa963f145b6",
"versionType": "git"
},
{
"lessThan": "a7dc30b6828c3a30252892827b12b676749f250f",
"status": "affected",
"version": "f01a2161577d31b14581e0db3bbbdfa963f145b6",
"versionType": "git"
},
{
"lessThan": "a61b4db34a753bdf5c9e77a7f3d3dddd41dcfacc",
"status": "affected",
"version": "f01a2161577d31b14581e0db3bbbdfa963f145b6",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/netronome/nfp/nfpcore/nfp_resource.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.11"
},
{
"lessThan": "4.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfp: Check resource mutex allocation\n\nnfp_cpp_resource_find() allocates a CPP mutex handle for the matching\nresource-table entry and then reports success. nfp_resource_try_acquire()\nimmediately passes that handle to nfp_cpp_mutex_trylock().\n\nHowever, nfp_cpp_mutex_alloc() returns NULL on failure. If that happens\nfor a matching table entry, the resource lookup still returns success and\nthe following trylock dereferences a NULL mutex pointer while opening the\nresource.\n\nnfp_resource_acquire() already treats failure to allocate the table mutex\nas -ENOMEM. Do the same for the resource mutex and fail the lookup before\npublishing the rest of the resource handle.\n\nThis issue was found by a static analysis checker and confirmed by\nmanual source review."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:25.716Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/18737a48acc87e4cbe41d6fea9a3f44eae490e24"
},
{
"url": "https://git.kernel.org/stable/c/423523f96a681428ce6e214eaf47f0d8242319de"
},
{
"url": "https://git.kernel.org/stable/c/0dbd85a8cc35c14bd26e686fa5fae8c64a7958ae"
},
{
"url": "https://git.kernel.org/stable/c/6dbd428119cb1fd1b73cf6968c711f4ea964dc8b"
},
{
"url": "https://git.kernel.org/stable/c/cfa119aa781c4044dab5b4c1e5864600f53a26bc"
},
{
"url": "https://git.kernel.org/stable/c/3b1d4fc3b73ea6faf008a0996ce6190c6e43efc3"
},
{
"url": "https://git.kernel.org/stable/c/a7dc30b6828c3a30252892827b12b676749f250f"
},
{
"url": "https://git.kernel.org/stable/c/a61b4db34a753bdf5c9e77a7f3d3dddd41dcfacc"
}
],
"title": "nfp: Check resource mutex allocation",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68328",
"datePublished": "2026-08-10T12:03:04.560Z",
"dateReserved": "2026-07-30T09:28:09.382Z",
"dateUpdated": "2026-08-19T16:33:25.716Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80852 (GCVE-0-2026-80852)
Vulnerability from cvelistv5
Published
2026-09-04 15:55
Modified
2026-09-04 15:55
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
tls: device: fix out-of-bounds write in tls_append_frag()
Found with syzkaller and a local syzbot instance running on top of a
netdevsim TLS offload emulation; tls_device.c is otherwise only reachable
on a machine with a NIC that implements the offload.
tls_push_data() only checks whether the open record still has room for
another frag at the bottom of its loop, and the MSG_MORE early break
skips that check. The record survives to the next syscall with the frag
count it already had, and tls_append_frag() does not check either, so
with TLS_TX_ZEROCOPY_RO every splice(SPLICE_F_MORE) of a byte or two adds
a non-coalescing pipe page and num_frags walks off the end of
tls_record_info.frags[MAX_SKB_FRAGS]. Once the record is pushed,
tls_push_record() runs the same index over sg_tx_data[MAX_SKB_FRAGS] and
the sg_set_page() writes land on the destruct_work that follows it, which
the workqueue then calls.
The byte limit is fine because copy drops to 0 and the loop falls through
to the same check; the frag count has no such feedback.
Push the record rather than keep a full one open, which is what a plain
TCP socket does - tcp_sendmsg_locked() uses tcp_mark_push() and
new_segment in both the copy and the MSG_SPLICE_PAGES paths, and tls_sw
already sets full_record when the sk_msg ring fills up, MSG_MORE or not.
BUG: KASAN: slab-out-of-bounds in tls_append_frag ( net/tls/tls_device.c:269)
Write of size 8 at addr ffff8881104d1530 by task tls_oob/450
CPU: 2 UID: 0 PID: 450 Comm: tls_oob Not tainted 7.2.0-rc7+ #329 PREEMPT
Call Trace:
<TASK>
dump_stack_lvl (lib/dump_stack.c:94 lib/dump_stack.c:120)
print_report (mm/kasan/report.c:378 mm/kasan/report.c:482)
kasan_report (mm/kasan/report.c:595)
tls_append_frag (net/tls/tls_device.c:269)
tls_push_data (net/tls/tls_device.c:518)
tls_device_sendmsg (net/tls/tls_device.c:583)
inet_sendmsg (net/ipv4/af_inet.c:865)
sock_sendmsg (net/socket.c:775 net/socket.c:790 net/socket.c:813)
splice_to_socket (fs/splice.c:884)
do_splice (fs/splice.c:936 fs/splice.c:1349)
__do_splice (fs/splice.c:1431)
__x64_sys_splice (fs/splice.c:1634 fs/splice.c:1616)
do_syscall_64 (arch/x86/entry/syscall_64.c:63 arch/x86/entry/syscall_64.c:94)
entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)
</TASK>
and, once the record is pushed:
UBSAN: array-index-out-of-bounds in net/tls/tls_device.c:300:24
index 18 is out of range for type 'skb_frag_t [17]'
UBSAN: array-index-out-of-bounds in net/tls/tls_device.c:301:41
index 18 is out of range for type 'scatterlist [17]'
UBSAN: array-index-out-of-bounds in net/tls/tls_device.c:302:39
index 18 is out of range for type 'scatterlist [17]'
UBSAN: array-index-out-of-bounds in net/tls/tls_device.c:307:38
index 26 is out of range for type 'scatterlist [17]'
kernel tried to execute NX-protected page - exploit attempt? (uid: 0)
BUG: unable to handle page fault for address: ffffea000411a680
#PF: supervisor instruction fetch in kernel mode
#PF: error_code(0x0011) - permissions violation
Oops: Oops: 0011 [#1] SMP KASAN PTI
Workqueue: ktls_device_destruct 0xffffea000411a680
RIP: 0010:0xffffea000411a680
Call Trace:
<TASK>
worker_thread (kernel/workqueue.c:3405 kernel/workqueue.c:3486)
kthread (kernel/kthread.c:436)
ret_from_fork (arch/x86/kernel/process.c:158)
ret_from_fork_asm (arch/x86/entry/entry_64.S:245)
</TASK>
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: e8f69799810c32dd40c6724d829eccc70baad07f Version: e8f69799810c32dd40c6724d829eccc70baad07f Version: e8f69799810c32dd40c6724d829eccc70baad07f Version: e8f69799810c32dd40c6724d829eccc70baad07f Version: e8f69799810c32dd40c6724d829eccc70baad07f Version: e8f69799810c32dd40c6724d829eccc70baad07f Version: e8f69799810c32dd40c6724d829eccc70baad07f |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/tls/tls_device.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "03ced5da6120965d80ed56dbb7d78fa5c9128906",
"status": "affected",
"version": "e8f69799810c32dd40c6724d829eccc70baad07f",
"versionType": "git"
},
{
"lessThan": "a832d7cb09da2a8e4e9734b4be14d3e76169d805",
"status": "affected",
"version": "e8f69799810c32dd40c6724d829eccc70baad07f",
"versionType": "git"
},
{
"lessThan": "b7f10d4ff987bda038df90052cd4a1434a7412d4",
"status": "affected",
"version": "e8f69799810c32dd40c6724d829eccc70baad07f",
"versionType": "git"
},
{
"lessThan": "fadbc1ed2a872a8649a44cf9e1cf9621fc58cd6e",
"status": "affected",
"version": "e8f69799810c32dd40c6724d829eccc70baad07f",
"versionType": "git"
},
{
"lessThan": "cd7e875b89597f3498917af764758391338d1802",
"status": "affected",
"version": "e8f69799810c32dd40c6724d829eccc70baad07f",
"versionType": "git"
},
{
"lessThan": "7e1208c135618358da5d7d6664874dc6e53c62fc",
"status": "affected",
"version": "e8f69799810c32dd40c6724d829eccc70baad07f",
"versionType": "git"
},
{
"lessThan": "b17cf742eaad70ae29ac558cefb3aa9bbeea03d4",
"status": "affected",
"version": "e8f69799810c32dd40c6724d829eccc70baad07f",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/tls/tls_device.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.18"
},
{
"lessThan": "4.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.187",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.156",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.108",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.49",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.13",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.3",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.187",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.156",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.108",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.49",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.13",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.3",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "4.18",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntls: device: fix out-of-bounds write in tls_append_frag()\n\nFound with syzkaller and a local syzbot instance running on top of a\nnetdevsim TLS offload emulation; tls_device.c is otherwise only reachable\non a machine with a NIC that implements the offload.\n\ntls_push_data() only checks whether the open record still has room for\nanother frag at the bottom of its loop, and the MSG_MORE early break\nskips that check. The record survives to the next syscall with the frag\ncount it already had, and tls_append_frag() does not check either, so\nwith TLS_TX_ZEROCOPY_RO every splice(SPLICE_F_MORE) of a byte or two adds\na non-coalescing pipe page and num_frags walks off the end of\ntls_record_info.frags[MAX_SKB_FRAGS]. Once the record is pushed,\ntls_push_record() runs the same index over sg_tx_data[MAX_SKB_FRAGS] and\nthe sg_set_page() writes land on the destruct_work that follows it, which\nthe workqueue then calls.\n\nThe byte limit is fine because copy drops to 0 and the loop falls through\nto the same check; the frag count has no such feedback.\n\nPush the record rather than keep a full one open, which is what a plain\nTCP socket does - tcp_sendmsg_locked() uses tcp_mark_push() and\nnew_segment in both the copy and the MSG_SPLICE_PAGES paths, and tls_sw\nalready sets full_record when the sk_msg ring fills up, MSG_MORE or not.\n\n BUG: KASAN: slab-out-of-bounds in tls_append_frag ( net/tls/tls_device.c:269)\n Write of size 8 at addr ffff8881104d1530 by task tls_oob/450\n\n CPU: 2 UID: 0 PID: 450 Comm: tls_oob Not tainted 7.2.0-rc7+ #329 PREEMPT\n Call Trace:\n \u003cTASK\u003e\n dump_stack_lvl (lib/dump_stack.c:94 lib/dump_stack.c:120)\n print_report (mm/kasan/report.c:378 mm/kasan/report.c:482)\n kasan_report (mm/kasan/report.c:595)\n tls_append_frag (net/tls/tls_device.c:269)\n tls_push_data (net/tls/tls_device.c:518)\n tls_device_sendmsg (net/tls/tls_device.c:583)\n inet_sendmsg (net/ipv4/af_inet.c:865)\n sock_sendmsg (net/socket.c:775 net/socket.c:790 net/socket.c:813)\n splice_to_socket (fs/splice.c:884)\n do_splice (fs/splice.c:936 fs/splice.c:1349)\n __do_splice (fs/splice.c:1431)\n __x64_sys_splice (fs/splice.c:1634 fs/splice.c:1616)\n do_syscall_64 (arch/x86/entry/syscall_64.c:63 arch/x86/entry/syscall_64.c:94)\n entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)\n \u003c/TASK\u003e\n\nand, once the record is pushed:\n\n UBSAN: array-index-out-of-bounds in net/tls/tls_device.c:300:24\n index 18 is out of range for type \u0027skb_frag_t [17]\u0027\n UBSAN: array-index-out-of-bounds in net/tls/tls_device.c:301:41\n index 18 is out of range for type \u0027scatterlist [17]\u0027\n UBSAN: array-index-out-of-bounds in net/tls/tls_device.c:302:39\n index 18 is out of range for type \u0027scatterlist [17]\u0027\n UBSAN: array-index-out-of-bounds in net/tls/tls_device.c:307:38\n index 26 is out of range for type \u0027scatterlist [17]\u0027\n\n kernel tried to execute NX-protected page - exploit attempt? (uid: 0)\n BUG: unable to handle page fault for address: ffffea000411a680\n #PF: supervisor instruction fetch in kernel mode\n #PF: error_code(0x0011) - permissions violation\n Oops: Oops: 0011 [#1] SMP KASAN PTI\n Workqueue: ktls_device_destruct 0xffffea000411a680\n RIP: 0010:0xffffea000411a680\n Call Trace:\n \u003cTASK\u003e\n worker_thread (kernel/workqueue.c:3405 kernel/workqueue.c:3486)\n kthread (kernel/kthread.c:436)\n ret_from_fork (arch/x86/kernel/process.c:158)\n ret_from_fork_asm (arch/x86/entry/entry_64.S:245)\n \u003c/TASK\u003e"
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T15:55:02.806Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/03ced5da6120965d80ed56dbb7d78fa5c9128906"
},
{
"url": "https://git.kernel.org/stable/c/a832d7cb09da2a8e4e9734b4be14d3e76169d805"
},
{
"url": "https://git.kernel.org/stable/c/b7f10d4ff987bda038df90052cd4a1434a7412d4"
},
{
"url": "https://git.kernel.org/stable/c/fadbc1ed2a872a8649a44cf9e1cf9621fc58cd6e"
},
{
"url": "https://git.kernel.org/stable/c/cd7e875b89597f3498917af764758391338d1802"
},
{
"url": "https://git.kernel.org/stable/c/7e1208c135618358da5d7d6664874dc6e53c62fc"
},
{
"url": "https://git.kernel.org/stable/c/b17cf742eaad70ae29ac558cefb3aa9bbeea03d4"
}
],
"title": "tls: device: fix out-of-bounds write in tls_append_frag()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80852",
"datePublished": "2026-09-04T15:55:02.806Z",
"dateReserved": "2026-08-26T14:34:25.797Z",
"dateUpdated": "2026-09-04T15:55:02.806Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2024-38620 (GCVE-0-2024-38620)
Vulnerability from cvelistv5
Published
2024-06-20 08:03
Modified
2026-08-23 12:45
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: HCI: Remove HCI_AMP support
Since BT_HS has been remove HCI_AMP controllers no longer has any use so
remove it along with the capability of creating AMP controllers.
Since we no longer need to differentiate between AMP and Primary
controllers, as only HCI_PRIMARY is left, this also remove
hdev->dev_type altogether.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2024-38620",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-06-20T16:21:10.645379Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2024-06-20T16:22:30.641Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
},
{
"providerMetadata": {
"dateUpdated": "2024-08-02T04:12:26.064Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_transferred"
],
"url": "https://git.kernel.org/stable/c/5af2e235b0d5b797e9531a00c50058319130e156"
},
{
"tags": [
"x_transferred"
],
"url": "https://git.kernel.org/stable/c/d3c7b012d912b31ad23b9349c0e499d6dddd48ec"
},
{
"tags": [
"x_transferred"
],
"url": "https://git.kernel.org/stable/c/af1d425b6dc67cd67809f835dd7afb6be4d43e03"
},
{
"tags": [
"x_transferred"
],
"url": "https://git.kernel.org/stable/c/84a4bb6548a29326564f0e659fb8064503ecc1c7"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/bluetooth/btmrvl_main.c",
"drivers/bluetooth/btrsi.c",
"drivers/bluetooth/btsdio.c",
"drivers/bluetooth/btusb.c",
"drivers/bluetooth/hci_bcm4377.c",
"drivers/bluetooth/hci_ldisc.c",
"drivers/bluetooth/hci_serdev.c",
"drivers/bluetooth/hci_uart.h",
"drivers/bluetooth/hci_vhci.c",
"drivers/bluetooth/virtio_bt.c",
"include/net/bluetooth/hci.h",
"include/net/bluetooth/hci_core.h",
"include/uapi/linux/virtio_bt.h",
"net/bluetooth/hci_conn.c",
"net/bluetooth/hci_core.c",
"net/bluetooth/hci_event.c",
"net/bluetooth/hci_sock.c",
"net/bluetooth/hci_sync.c",
"net/bluetooth/l2cap_core.c",
"net/bluetooth/mgmt.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "9e6cf0eccfe15b67bf9773ecd101162dfdfed5e2",
"status": "affected",
"version": "244bc377591c3882f454882357bc730c90cbedb5",
"versionType": "git"
},
{
"lessThan": "5af2e235b0d5b797e9531a00c50058319130e156",
"status": "affected",
"version": "244bc377591c3882f454882357bc730c90cbedb5",
"versionType": "git"
},
{
"lessThan": "d3c7b012d912b31ad23b9349c0e499d6dddd48ec",
"status": "affected",
"version": "244bc377591c3882f454882357bc730c90cbedb5",
"versionType": "git"
},
{
"lessThan": "af1d425b6dc67cd67809f835dd7afb6be4d43e03",
"status": "affected",
"version": "244bc377591c3882f454882357bc730c90cbedb5",
"versionType": "git"
},
{
"lessThan": "84a4bb6548a29326564f0e659fb8064503ecc1c7",
"status": "affected",
"version": "244bc377591c3882f454882357bc730c90cbedb5",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/bluetooth/btmrvl_main.c",
"drivers/bluetooth/btrsi.c",
"drivers/bluetooth/btsdio.c",
"drivers/bluetooth/btusb.c",
"drivers/bluetooth/hci_bcm4377.c",
"drivers/bluetooth/hci_ldisc.c",
"drivers/bluetooth/hci_serdev.c",
"drivers/bluetooth/hci_uart.h",
"drivers/bluetooth/hci_vhci.c",
"drivers/bluetooth/virtio_bt.c",
"include/net/bluetooth/hci.h",
"include/net/bluetooth/hci_core.h",
"include/uapi/linux/virtio_bt.h",
"net/bluetooth/hci_conn.c",
"net/bluetooth/hci_core.c",
"net/bluetooth/hci_event.c",
"net/bluetooth/hci_sock.c",
"net/bluetooth/hci_sync.c",
"net/bluetooth/l2cap_core.c",
"net/bluetooth/mgmt.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.3"
},
{
"lessThan": "4.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.33",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.8.*",
"status": "unaffected",
"version": "6.8.12",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.9.*",
"status": "unaffected",
"version": "6.9.3",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "6.10",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.33",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.8.12",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.9.3",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.10",
"versionStartIncluding": "4.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: HCI: Remove HCI_AMP support\n\nSince BT_HS has been remove HCI_AMP controllers no longer has any use so\nremove it along with the capability of creating AMP controllers.\n\nSince we no longer need to differentiate between AMP and Primary\ncontrollers, as only HCI_PRIMARY is left, this also remove\nhdev-\u003edev_type altogether."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The broken paths (`l2cap_recv_acldata`, `l2cap_connect`, `l2cap_connect_cfm`\u2192`l2cap_conn_add`, `hci_queue_acl`, `hci_num_comp_blocks_evt`) all process ACL/L2CAP traffic and link events originating from a remote Bluetooth peer in radio range of an AMP-capable controller, which real hardware ships as (btusb USB class e0/01/04, btmrvl SDIO combo chips, btsdio SDIO_CLASS_BT_AMP, virtio-bt). Bluetooth radio proximity is the adjacent-network vector.\nAC:L - Once an HCI_AMP controller is present \u2014 the default state on affected hardware, requiring no attacker setup \u2014 the inconsistent paths are reached deterministically by initiating an ACL/L2CAP connection and sending data; there is no race and no memory layout the attacker cannot influence.\nPR:N - An adjacent Bluetooth attacker needs no credentials on the target: `hci_conn_request_evt` and `l2cap_connect_cfm`/`l2cap_conn_add` run before any pairing or authorization, and `l2cap_connect` explicitly exempts the SDP PSM from the link-mode security check.\nUI:N - No victim action is required \u2014 inbound connection establishment and ACL data reception are handled autonomously by the kernel once Bluetooth is up.\nS:U - All corruption and crashes stay inside the kernel\u0027s own security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - `hci_queue_acl()` builds ACL headers from `chan-\u003ehandle` rather than `conn-\u003ehandle` on AMP hdevs, so L2CAP payloads can be emitted tagged with the wrong link handle, and the state corruption in the connection/scheduler bookkeeping is of a class leverageable for kernel memory disclosure.\nI:H - `hci_num_comp_blocks_evt` applies an unbounded `conn-\u003esent -= block_count` to a `hci_chan` that should never have existed, underflowing an unsigned counter that drives `hci_quote_sent`/`hci_low_sent` quota arithmetic, and the ACL handle confusion lets frames be attributed to the wrong connection \u2014 kernel state under attacker influence.\nA:H - `__get_blocks()` divides by controller-supplied `hdev-\u003eblock_len` on the block-based path that only AMP controllers select, giving a divide-by-zero kernel oops; separately, `hci_sched_acl()` never drains the AMP queues so `chan-\u003edata_q` grows without bound until memory is exhausted."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:45:18.071Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/9e6cf0eccfe15b67bf9773ecd101162dfdfed5e2"
},
{
"url": "https://git.kernel.org/stable/c/5af2e235b0d5b797e9531a00c50058319130e156"
},
{
"url": "https://git.kernel.org/stable/c/d3c7b012d912b31ad23b9349c0e499d6dddd48ec"
},
{
"url": "https://git.kernel.org/stable/c/af1d425b6dc67cd67809f835dd7afb6be4d43e03"
},
{
"url": "https://git.kernel.org/stable/c/84a4bb6548a29326564f0e659fb8064503ecc1c7"
}
],
"title": "Bluetooth: HCI: Remove HCI_AMP support",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2024-38620",
"datePublished": "2024-06-20T08:03:43.906Z",
"dateReserved": "2024-06-18T19:36:34.945Z",
"dateUpdated": "2026-08-23T12:45:18.071Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68148 (GCVE-0-2026-68148)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
fscrypt: Add missing superblock check in find_or_insert_direct_key()
The legacy 'fscrypt_direct_keys' table caches master keys that are used
by v1 encryption policies that have FSCRYPT_POLICY_FLAG_DIRECT_KEY.
It's just a global table for all filesystems (since the keys can be
provided by the legacy process-subscribed keyrings mechanism, which
makes it difficult to reuse super_block::s_master_keys).
The entries in it ('struct fscrypt_direct_key') do contain a super_block
pointer, though, for passing to fscrypt_destroy_inline_crypt_key() when
the last inode that references the key is evicted.
However, when finding the fscrypt_direct_key for an inode, we weren't
actually comparing the super_block pointer. As a result, inodes with
different super_blocks could point to the same fscrypt_direct_key. That
could extend the lifetime of a fscrypt_direct_key beyond the
super_block it points to, causing a use-after-free later.
Fix this by creating distinct fscrypt_direct_key structs for distinct
super_block structs.
Note that this problem doesn't exist in the v2 policy equivalent
("per-mode keys"), since the data structures there are per super_block.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 22e9947a4b2ba255888541bd0111cf00b9b16586 Version: 22e9947a4b2ba255888541bd0111cf00b9b16586 Version: 22e9947a4b2ba255888541bd0111cf00b9b16586 Version: 22e9947a4b2ba255888541bd0111cf00b9b16586 Version: 22e9947a4b2ba255888541bd0111cf00b9b16586 Version: 22e9947a4b2ba255888541bd0111cf00b9b16586 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/crypto/keysetup_v1.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "965b5bc8cf5031225e057979ce660fec2bd5fbfc",
"status": "affected",
"version": "22e9947a4b2ba255888541bd0111cf00b9b16586",
"versionType": "git"
},
{
"lessThan": "330249609b70778094a7a36f5b6bcfa6362121d4",
"status": "affected",
"version": "22e9947a4b2ba255888541bd0111cf00b9b16586",
"versionType": "git"
},
{
"lessThan": "deff41898a5ae3a47db5fa1896a494aa95efda5d",
"status": "affected",
"version": "22e9947a4b2ba255888541bd0111cf00b9b16586",
"versionType": "git"
},
{
"lessThan": "95376fe9c145be35566991df99c53134943d992f",
"status": "affected",
"version": "22e9947a4b2ba255888541bd0111cf00b9b16586",
"versionType": "git"
},
{
"lessThan": "466f187b501a5ac8e1ea2ccf3ccd5c46108d8830",
"status": "affected",
"version": "22e9947a4b2ba255888541bd0111cf00b9b16586",
"versionType": "git"
},
{
"lessThan": "b5fa40226e71c17847b9ff2816c6ca4133d0d994",
"status": "affected",
"version": "22e9947a4b2ba255888541bd0111cf00b9b16586",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/crypto/keysetup_v1.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.1"
},
{
"lessThan": "6.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "6.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfscrypt: Add missing superblock check in find_or_insert_direct_key()\n\nThe legacy \u0027fscrypt_direct_keys\u0027 table caches master keys that are used\nby v1 encryption policies that have FSCRYPT_POLICY_FLAG_DIRECT_KEY.\nIt\u0027s just a global table for all filesystems (since the keys can be\nprovided by the legacy process-subscribed keyrings mechanism, which\nmakes it difficult to reuse super_block::s_master_keys).\n\nThe entries in it (\u0027struct fscrypt_direct_key\u0027) do contain a super_block\npointer, though, for passing to fscrypt_destroy_inline_crypt_key() when\nthe last inode that references the key is evicted.\n\nHowever, when finding the fscrypt_direct_key for an inode, we weren\u0027t\nactually comparing the super_block pointer. As a result, inodes with\ndifferent super_blocks could point to the same fscrypt_direct_key. That\ncould extend the lifetime of a fscrypt_direct_key beyond the\nsuper_block it points to, causing a use-after-free later.\n\nFix this by creating distinct fscrypt_direct_key structs for distinct\nsuper_block structs.\n\nNote that this problem doesn\u0027t exist in the v2 policy equivalent\n(\"per-mode keys\"), since the data structures there are per super_block."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The flaw is reached only through local syscalls (mount/umount, FS_IOC_SET_ENCRYPTION_POLICY, and file I/O that calls fscrypt_get_encryption_info -\u003e find_or_insert_direct_key); fscrypt is not invoked from network-facing kernel services.\nAC:L - An attacker who can mount two encrypted filesystems with the same v1 DIRECT_KEY master key, share the global cache entry, then unmount the first superblock can deterministically trigger eviction-time cleanup on a freed super_block without races or victim-dependent timing.\nPR:L - Exploitation requires mounting/unmounting filesystems and setting v1 DIRECT_KEY policies (CAP_SYS_ADMIN in a user/mount namespace) or supplying keys via process keyrings; per kernel guidance, CAP_SYS_ADMIN obtainable in user namespaces maps to PR:L.\nUI:N - No separate victim action is required; the attacker sets v1 DIRECT_KEY policies, accesses encrypted inodes on two mounts, and controls unmount/eviction to hit the vulnerable refcount and cleanup path.\nS:U - The use-after-free corrupts kernel heap memory and enables local privilege escalation within the same kernel; it does not cross VM, hypervisor, or IOMMU security boundaries.\nC:H - Extending a fscrypt_direct_key past its super_block lifetime causes cleanup to dereference a freed super_block in fscrypt_destroy_inline_crypt_key(), a use-after-free that can leak kernel memory and support arbitrary-read exploitation primitives.\nI:H - Use-after-free during inline-crypto key destruction on a dangling super_block pointer can be leveraged for heap corruption and arbitrary kernel writes, enabling local privilege escalation rather than only a controlled crash.\nA:H - Evicting the last inode holding the mismatched fscrypt_direct_key dereferences a freed super_block during key teardown, which can cause kernel oops/panic and complete local denial of service on encrypted mobile/embedded and server systems using inline encryption."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:30:13.417Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/965b5bc8cf5031225e057979ce660fec2bd5fbfc"
},
{
"url": "https://git.kernel.org/stable/c/330249609b70778094a7a36f5b6bcfa6362121d4"
},
{
"url": "https://git.kernel.org/stable/c/deff41898a5ae3a47db5fa1896a494aa95efda5d"
},
{
"url": "https://git.kernel.org/stable/c/95376fe9c145be35566991df99c53134943d992f"
},
{
"url": "https://git.kernel.org/stable/c/466f187b501a5ac8e1ea2ccf3ccd5c46108d8830"
},
{
"url": "https://git.kernel.org/stable/c/b5fa40226e71c17847b9ff2816c6ca4133d0d994"
}
],
"title": "fscrypt: Add missing superblock check in find_or_insert_direct_key()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68148",
"datePublished": "2026-08-10T11:59:13.413Z",
"dateReserved": "2026-07-30T09:28:09.371Z",
"dateUpdated": "2026-08-19T16:30:13.417Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68425 (GCVE-0-2026-68425)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-19 16:35
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
IB/mad: Drop unmatched RMPP responses before reassembly
Kernel-handled RMPP receive processing starts reassembly for active
DATA responses before the response is matched to an outstanding send.
The normal match happens later, after ib_process_rmpp_recv_wc() has
either assembled a complete message or consumed the segment.
That ordering lets an unsolicited response that routes to a kernel
RMPP agent by the high TID bits allocate or extend RMPP receive state
before the full TID and source address are checked against a real
request. A reordered burst can therefore reach the receive-side
insertion path even though the response would not match any send.
For kernel-handled RMPP DATA responses, require the existing
ib_find_send_mad() match before entering RMPP reassembly. The matcher
already checks the full TID, management class and source address/GID
against the agent wait, backlog and in-flight send lists. If there is
no match, drop the response without creating RMPP state.
This leaves the RMPP window behavior unchanged and only rejects
responses that have no corresponding request.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: fa619a77046bef30478697aba0553991033afb8e Version: fa619a77046bef30478697aba0553991033afb8e Version: fa619a77046bef30478697aba0553991033afb8e Version: fa619a77046bef30478697aba0553991033afb8e Version: fa619a77046bef30478697aba0553991033afb8e Version: fa619a77046bef30478697aba0553991033afb8e Version: fa619a77046bef30478697aba0553991033afb8e Version: fa619a77046bef30478697aba0553991033afb8e |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/core/mad.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "45416c87ebcece1e90f3bc5bc172d106b77c6b69",
"status": "affected",
"version": "fa619a77046bef30478697aba0553991033afb8e",
"versionType": "git"
},
{
"lessThan": "9634fb1f4d404f36a20ffbcb8797369db69b06bb",
"status": "affected",
"version": "fa619a77046bef30478697aba0553991033afb8e",
"versionType": "git"
},
{
"lessThan": "bfb9e8243fd2099d1080d09222964d988f991d9b",
"status": "affected",
"version": "fa619a77046bef30478697aba0553991033afb8e",
"versionType": "git"
},
{
"lessThan": "dfa535c94406c03d3f0c869ef3ba5528e395737c",
"status": "affected",
"version": "fa619a77046bef30478697aba0553991033afb8e",
"versionType": "git"
},
{
"lessThan": "6e1bd7f590b0ccfee07f7fe1d48b92059bd37d72",
"status": "affected",
"version": "fa619a77046bef30478697aba0553991033afb8e",
"versionType": "git"
},
{
"lessThan": "98d2d468b4faa1fdc68c0c6c238389906ee3490c",
"status": "affected",
"version": "fa619a77046bef30478697aba0553991033afb8e",
"versionType": "git"
},
{
"lessThan": "ad9c9ad3204f63a46f0f7de29687a8e512f05e29",
"status": "affected",
"version": "fa619a77046bef30478697aba0553991033afb8e",
"versionType": "git"
},
{
"lessThan": "d2e52d610b9b09694261632340b801a421e0b0c5",
"status": "affected",
"version": "fa619a77046bef30478697aba0553991033afb8e",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/core/mad.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.13"
},
{
"lessThan": "2.6.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nIB/mad: Drop unmatched RMPP responses before reassembly\n\nKernel-handled RMPP receive processing starts reassembly for active\nDATA responses before the response is matched to an outstanding send.\nThe normal match happens later, after ib_process_rmpp_recv_wc() has\neither assembled a complete message or consumed the segment.\n\nThat ordering lets an unsolicited response that routes to a kernel\nRMPP agent by the high TID bits allocate or extend RMPP receive state\nbefore the full TID and source address are checked against a real\nrequest. A reordered burst can therefore reach the receive-side\ninsertion path even though the response would not match any send.\n\nFor kernel-handled RMPP DATA responses, require the existing\nib_find_send_mad() match before entering RMPP reassembly. The matcher\nalready checks the full TID, management class and source address/GID\nagainst the agent wait, backlog and in-flight send lists. If there is\nno match, drop the response without creating RMPP state.\n\nThis leaves the RMPP window behavior unchanged and only rejects\nresponses that have no corresponding request."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The attacker must be a node on the same InfiniBand fabric, sending unsolicited GSI (QP1) management datagrams to the victim port; MAD/SA traffic is subnet-local, matching the CVSS \"shared physical or logical network\" definition rather than routable network reach.\nAC:L - No race or unusual precondition is needed: the attacker just sends active RMPP DATA response MADs whose high TID bits name a kernel RMPP agent, and hi_tid is a small cyclic xarray index in [0,2^24) that is trivially enumerated or brute-forced.\nPR:N - The MAD receive path accepts unsolicited datagrams from any fabric peer with no authentication; the only gate is ib_mad_enforce_security() P_Key membership, which the default partition typically grants to every node on the subnet.\nUI:N - Reassembly state is created entirely from attacker-sent packets in the completion handler; no action by a local user or administrator is needed, and the always-registered ib_sa kernel agent is the target.\nS:U - The injected RMPP state, allocations and AH objects all live inside the kernel\u0027s own IB MAD layer on the same host, so the impact stays within a single security authority.\nC:N - The flaw creates unmatched reassembly state; it provides no out-of-bounds read, no kernel memory disclosure, and the ACKs the kernel emits echo only attacker-supplied header fields.\nI:L - An unauthenticated fabric peer can insert arbitrary unsolicited entries into the kernel agent\u0027s RMPP reassembly lists and make the kernel emit ACKs, and a colliding entry (SA TIDs come from a predictable tid++ counter) diverts and drops a legitimate SA response\u0027s segments \u2014 limited, bounded modification of kernel protocol state.\nA:H - Each unmatched segment allocates a mad_rmpp_recv, an AH and a retained ~1-2 KB MAD buffer held for 40 seconds with no matching request, so a burst causes unbounded memory/resource exhaustion, while the O(N) rmpp_list walks under an IRQ-disabled spinlock stall MAD processing and break SA/path resolution for the node."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:35:19.996Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/45416c87ebcece1e90f3bc5bc172d106b77c6b69"
},
{
"url": "https://git.kernel.org/stable/c/9634fb1f4d404f36a20ffbcb8797369db69b06bb"
},
{
"url": "https://git.kernel.org/stable/c/bfb9e8243fd2099d1080d09222964d988f991d9b"
},
{
"url": "https://git.kernel.org/stable/c/dfa535c94406c03d3f0c869ef3ba5528e395737c"
},
{
"url": "https://git.kernel.org/stable/c/6e1bd7f590b0ccfee07f7fe1d48b92059bd37d72"
},
{
"url": "https://git.kernel.org/stable/c/98d2d468b4faa1fdc68c0c6c238389906ee3490c"
},
{
"url": "https://git.kernel.org/stable/c/ad9c9ad3204f63a46f0f7de29687a8e512f05e29"
},
{
"url": "https://git.kernel.org/stable/c/d2e52d610b9b09694261632340b801a421e0b0c5"
}
],
"title": "IB/mad: Drop unmatched RMPP responses before reassembly",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68425",
"datePublished": "2026-08-10T12:04:45.947Z",
"dateReserved": "2026-07-30T09:28:09.392Z",
"dateUpdated": "2026-08-19T16:35:19.996Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74480 (GCVE-0-2026-74480)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-19 16:37
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: bridge: stop fast-leave after deleting a port group
br_multicast_leave_group() iterates mp->ports with pp = &p->next in
its fast-leave path. After br_multicast_del_pg() removes p,
continuing the loop advances pp through the deleted entry.
If multicast-to-unicast was enabled, the bridge can hold multiple port
groups for the same port and group with different source MAC
addresses. Once multicast-to-unicast is disabled,
br_port_group_equal() matches those entries by port only. A fast leave
can then delete one entry and continue from its stale next pointer,
leaving mp->ports pointing at a deleted port group.
Fast leave only needs to remove one matching port group. Break after
br_multicast_del_pg() so the loop stops before dereferencing the
removed entry.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 6db6f0eae6052b70885562e1733896647ec1d807 Version: 6db6f0eae6052b70885562e1733896647ec1d807 Version: 6db6f0eae6052b70885562e1733896647ec1d807 Version: 6db6f0eae6052b70885562e1733896647ec1d807 Version: 6db6f0eae6052b70885562e1733896647ec1d807 Version: 6db6f0eae6052b70885562e1733896647ec1d807 Version: 6db6f0eae6052b70885562e1733896647ec1d807 Version: 6db6f0eae6052b70885562e1733896647ec1d807 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/bridge/br_multicast.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "d6c32e2e25a9a06ba021030e26b6d602a277eb72",
"status": "affected",
"version": "6db6f0eae6052b70885562e1733896647ec1d807",
"versionType": "git"
},
{
"lessThan": "482bcb85139addb4e8ac8ed10baeda3e0aad4031",
"status": "affected",
"version": "6db6f0eae6052b70885562e1733896647ec1d807",
"versionType": "git"
},
{
"lessThan": "1a109cc9890d017c41d77e6c82da739579c49f0b",
"status": "affected",
"version": "6db6f0eae6052b70885562e1733896647ec1d807",
"versionType": "git"
},
{
"lessThan": "159ad90cb929c033308bb39a2c5f8fbf393b77aa",
"status": "affected",
"version": "6db6f0eae6052b70885562e1733896647ec1d807",
"versionType": "git"
},
{
"lessThan": "4695430e8132420bf8de94da3eb36a6cf35fde6b",
"status": "affected",
"version": "6db6f0eae6052b70885562e1733896647ec1d807",
"versionType": "git"
},
{
"lessThan": "0309ebbc570000ea0df11c06b69798e5860c5f6f",
"status": "affected",
"version": "6db6f0eae6052b70885562e1733896647ec1d807",
"versionType": "git"
},
{
"lessThan": "4c57056ca6aace2e9f94ae9298bf49ef6b0c95e4",
"status": "affected",
"version": "6db6f0eae6052b70885562e1733896647ec1d807",
"versionType": "git"
},
{
"lessThan": "a39789f211b8a4125f0c70e05b30cf715f4f187d",
"status": "affected",
"version": "6db6f0eae6052b70885562e1733896647ec1d807",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/bridge/br_multicast.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.11"
},
{
"lessThan": "4.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: bridge: stop fast-leave after deleting a port group\n\nbr_multicast_leave_group() iterates mp-\u003eports with pp = \u0026p-\u003enext in\nits fast-leave path. After br_multicast_del_pg() removes p,\ncontinuing the loop advances pp through the deleted entry.\n\nIf multicast-to-unicast was enabled, the bridge can hold multiple port\ngroups for the same port and group with different source MAC\naddresses. Once multicast-to-unicast is disabled,\nbr_port_group_equal() matches those entries by port only. A fast leave\ncan then delete one entry and continue from its stale next pointer,\nleaving mp-\u003eports pointing at a deleted port group.\n\nFast leave only needs to remove one matching port group. Break after\nbr_multicast_del_pg() so the loop stops before dereferencing the\nremoved entry."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug is reached when the bridge network stack processes attacker-supplied IGMP/MLD Leave packets received on a bridge port (br_handle_frame_finish -\u003e br_multicast_rcv -\u003e br_ip4/ip6_multicast_leave_group -\u003e br_multicast_leave_group), requiring no local syscall access.\nAC:L - Once a bridge has IGMP snooping, fast-leave, and leftover duplicate port groups (common on WiFi APs that used multicast-to-unicast), an attacker can reliably trigger the bug by sending IGMP/MLD joins then a Leave; no uncontrollable race or rare timing is required.\nPR:N - No privileges or authentication are required on the target; any host on an attached bridge port can inject IGMP/MLD Leave packets that are processed and reach the vulnerable fast-leave deletion loop.\nUI:N - Exploitation requires only attacker-sent multicast control packets; no victim user action such as opening files, clicking links, or mounting filesystems is needed.\nS:U - Impact is kernel heap corruption and use-after-free within the bridge/multicast subsystem on the same host; it does not cross a VM/hypervisor or IOMMU security boundary by itself.\nC:H - Deleting a port group then continuing the list walk dereferences freed net_bridge_port_group memory and can leave mp-\u003eports dangling, giving a use-after-free read primitive exploitable for arbitrary kernel memory disclosure.\nI:H - Corrupting the mp-\u003eports linked list via stale next pointers after br_multicast_del_pg() enables attacker-influenced kernel heap corruption that can be developed into arbitrary write and privilege escalation.\nA:H - The use-after-free and corrupted multicast database pointers cause kernel oops/panics when subsequent bridge multicast forwarding or MDB operations traverse the broken port-group list, enabling repeatable denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:37:33.031Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/d6c32e2e25a9a06ba021030e26b6d602a277eb72"
},
{
"url": "https://git.kernel.org/stable/c/482bcb85139addb4e8ac8ed10baeda3e0aad4031"
},
{
"url": "https://git.kernel.org/stable/c/1a109cc9890d017c41d77e6c82da739579c49f0b"
},
{
"url": "https://git.kernel.org/stable/c/159ad90cb929c033308bb39a2c5f8fbf393b77aa"
},
{
"url": "https://git.kernel.org/stable/c/4695430e8132420bf8de94da3eb36a6cf35fde6b"
},
{
"url": "https://git.kernel.org/stable/c/0309ebbc570000ea0df11c06b69798e5860c5f6f"
},
{
"url": "https://git.kernel.org/stable/c/4c57056ca6aace2e9f94ae9298bf49ef6b0c95e4"
},
{
"url": "https://git.kernel.org/stable/c/a39789f211b8a4125f0c70e05b30cf715f4f187d"
}
],
"title": "net: bridge: stop fast-leave after deleting a port group",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74480",
"datePublished": "2026-08-15T12:27:13.803Z",
"dateReserved": "2026-08-15T05:44:03.904Z",
"dateUpdated": "2026-08-19T16:37:33.031Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64564 (GCVE-0-2026-64564)
Vulnerability from cvelistv5
Published
2026-08-04 06:23
Modified
2026-08-19 16:28
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
sctp: don't free the ASCONF's own transport in DEL-IP processing
sctp_process_asconf() caches the transport the ASCONF chunk is processed
against in asconf->transport (== chunk->transport, set once in sctp_rcv()).
For an ASCONF located through its Address Parameter by
__sctp_rcv_asconf_lookup(), that cached transport corresponds to the
Address Parameter, which need not be the packet's source address.
sctp_process_asconf_param() rejects a DEL-IP for the packet source address
(ADDIP D8, SCTP_ERROR_DEL_SRC_IP), but nothing protects asconf->transport.
A single ASCONF can therefore carry, in order:
[Address Parameter L] [DEL-IP L] [DEL-IP 0.0.0.0]
where L differs from the source. The DEL-IP for L passes the D8 check and
calls sctp_assoc_rm_peer() on the transport that asconf->transport still
points at, freeing it (RCU-deferred). The following wildcard DEL-IP then
reuses the now-dangling asconf->transport in sctp_assoc_set_primary() and
sctp_assoc_del_nonprimary_peers(): set_primary() dereferences the freed
transport (->ipaddr, ->state) and plants the dangling pointer into
asoc->peer.primary_path / active_path, and del_nonprimary_peers(), keeping
only the pointer that is no longer on the list, removes every real
transport, leaving the association with a transport_count of 0 and
primary_path/active_path pointing at freed memory.
Reject a DEL-IP that targets the transport the ASCONF is being processed
against, mirroring the existing source-address guard, so the wildcard
branch can never reuse a freed transport.
References
| URL | Tags | ||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 42e30bf3463cd37d73839376662cb79b4d5c416c Version: 42e30bf3463cd37d73839376662cb79b4d5c416c Version: 42e30bf3463cd37d73839376662cb79b4d5c416c Version: 42e30bf3463cd37d73839376662cb79b4d5c416c Version: 42e30bf3463cd37d73839376662cb79b4d5c416c Version: 42e30bf3463cd37d73839376662cb79b4d5c416c Version: 42e30bf3463cd37d73839376662cb79b4d5c416c Version: 42e30bf3463cd37d73839376662cb79b4d5c416c |
||
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2026-08-08T01:31:36.501Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"url": "http://www.openwall.com/lists/oss-security/2026/08/06/3"
},
{
"url": "http://www.openwall.com/lists/oss-security/2026/08/06/4"
},
{
"url": "http://www.openwall.com/lists/oss-security/2026/08/06/13"
},
{
"url": "http://www.openwall.com/lists/oss-security/2026/08/07/1"
},
{
"url": "http://www.openwall.com/lists/oss-security/2026/08/07/2"
},
{
"url": "http://www.openwall.com/lists/oss-security/2026/08/07/8"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/sctp/sm_make_chunk.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a9ce31be4cb1a5dd82b3e0a1d0c3e7cbdcd31293",
"status": "affected",
"version": "42e30bf3463cd37d73839376662cb79b4d5c416c",
"versionType": "git"
},
{
"lessThan": "a63afa1f9b12d5293cbe0b77fd45dc0632533a13",
"status": "affected",
"version": "42e30bf3463cd37d73839376662cb79b4d5c416c",
"versionType": "git"
},
{
"lessThan": "2b324ba3494ae958cba16a453e3e71489b4de7fc",
"status": "affected",
"version": "42e30bf3463cd37d73839376662cb79b4d5c416c",
"versionType": "git"
},
{
"lessThan": "fedeb4468987bcaff85fe3061de5ae052d414740",
"status": "affected",
"version": "42e30bf3463cd37d73839376662cb79b4d5c416c",
"versionType": "git"
},
{
"lessThan": "74e8f3e7114f0e26d1b2c4c048044db9fcc27603",
"status": "affected",
"version": "42e30bf3463cd37d73839376662cb79b4d5c416c",
"versionType": "git"
},
{
"lessThan": "85aca407c560aba81b5ce9d3d6cf94c74077d19b",
"status": "affected",
"version": "42e30bf3463cd37d73839376662cb79b4d5c416c",
"versionType": "git"
},
{
"lessThan": "d136b29bf91dd8e3161281b87de597b7311d9462",
"status": "affected",
"version": "42e30bf3463cd37d73839376662cb79b4d5c416c",
"versionType": "git"
},
{
"lessThan": "9b2854f86f0b56e9027d68e7a3fc909d1a9b566f",
"status": "affected",
"version": "42e30bf3463cd37d73839376662cb79b4d5c416c",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/sctp/sm_make_chunk.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.25"
},
{
"lessThan": "2.6.25",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.25",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: don\u0027t free the ASCONF\u0027s own transport in DEL-IP processing\n\nsctp_process_asconf() caches the transport the ASCONF chunk is processed\nagainst in asconf-\u003etransport (== chunk-\u003etransport, set once in sctp_rcv()).\nFor an ASCONF located through its Address Parameter by\n__sctp_rcv_asconf_lookup(), that cached transport corresponds to the\nAddress Parameter, which need not be the packet\u0027s source address.\n\nsctp_process_asconf_param() rejects a DEL-IP for the packet source address\n(ADDIP D8, SCTP_ERROR_DEL_SRC_IP), but nothing protects asconf-\u003etransport.\nA single ASCONF can therefore carry, in order:\n\n [Address Parameter L] [DEL-IP L] [DEL-IP 0.0.0.0]\n\nwhere L differs from the source. The DEL-IP for L passes the D8 check and\ncalls sctp_assoc_rm_peer() on the transport that asconf-\u003etransport still\npoints at, freeing it (RCU-deferred). The following wildcard DEL-IP then\nreuses the now-dangling asconf-\u003etransport in sctp_assoc_set_primary() and\nsctp_assoc_del_nonprimary_peers(): set_primary() dereferences the freed\ntransport (-\u003eipaddr, -\u003estate) and plants the dangling pointer into\nasoc-\u003epeer.primary_path / active_path, and del_nonprimary_peers(), keeping\nonly the pointer that is no longer on the list, removes every real\ntransport, leaving the association with a transport_count of 0 and\nprimary_path/active_path pointing at freed memory.\n\nReject a DEL-IP that targets the transport the ASCONF is being processed\nagainst, mirroring the existing source-address guard, so the wildcard\nbranch can never reuse a freed transport."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug is in SCTP ASCONF receive processing (sctp_rcv \u2192 sctp_sf_do_asconf \u2192 sctp_process_asconf \u2192 sctp_process_asconf_param); a remote peer triggers it by sending a crafted ASCONF over IP/IPv6 on an established association, matching kernel guidance that net/ stack bugs reachable via received packets are Network.\nAC:L - A single attacker-controlled ASCONF with [Address Parameter L][DEL-IP L][DEL-IP 0.0.0.0] reliably frees asconf-\u003etransport then reuses it in the same softirq; the peer fully controls multi-homing, serial, and parameter order, with no race or other condition outside attacker influence.\nPR:N - Any remote SCTP peer that completes a normal association with ADD-IP negotiated can send the ASCONF; SCTP-AUTH keys come from the handshake the peer itself performs (or addip_noauth), and no local credentials or capabilities on the target are required.\nUI:N - Exploitation requires only attacker-sent SCTP packets processed automatically in the receive/state-machine path; no victim user action such as opening a file or mounting a device is needed.\nS:U - Impact is confined to the vulnerable host kernel (sctp_transport UAF / crash or privilege escalation) and does not cross a VM, IOMMU, or other security-authority boundary.\nC:H - This is a heap use-after-free of an sctp_transport planted into primary_path/active_path after RCU-deferred free; freed-object reuse yields arbitrary kernel read primitives, scored High per UAF guidance.\nI:H - The same transport UAF enables heap spraying and write/control-flow hijacking via later dereferences of the dangling primary_path/active_path, so integrity impact is High.\nA:H - set_primary() immediately dereferences the freed transport and leaves the association with transport_count 0 and dangling path pointers, causing a reproducible kernel oops/panic on subsequent use, which is High availability impact."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:28:36.947Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a9ce31be4cb1a5dd82b3e0a1d0c3e7cbdcd31293"
},
{
"url": "https://git.kernel.org/stable/c/a63afa1f9b12d5293cbe0b77fd45dc0632533a13"
},
{
"url": "https://git.kernel.org/stable/c/2b324ba3494ae958cba16a453e3e71489b4de7fc"
},
{
"url": "https://git.kernel.org/stable/c/fedeb4468987bcaff85fe3061de5ae052d414740"
},
{
"url": "https://git.kernel.org/stable/c/74e8f3e7114f0e26d1b2c4c048044db9fcc27603"
},
{
"url": "https://git.kernel.org/stable/c/85aca407c560aba81b5ce9d3d6cf94c74077d19b"
},
{
"url": "https://git.kernel.org/stable/c/d136b29bf91dd8e3161281b87de597b7311d9462"
},
{
"url": "https://git.kernel.org/stable/c/9b2854f86f0b56e9027d68e7a3fc909d1a9b566f"
},
{
"url": "https://matrix.tencent.com/en/2026/08/06/sctphantom-CVE-2026-64564"
}
],
"title": "sctp: don\u0027t free the ASCONF\u0027s own transport in DEL-IP processing",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64564",
"datePublished": "2026-08-04T06:23:23.339Z",
"dateReserved": "2026-07-19T15:36:31.797Z",
"dateUpdated": "2026-08-19T16:28:36.947Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80718 (GCVE-0-2026-80718)
Vulnerability from cvelistv5
Published
2026-08-28 06:53
Modified
2026-08-29 06:22
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
mm/percpu-km: fix bitmap overflow and accounting in pcpu_create_chunk()
In pcpu_create_chunk(), nr_pages is the total contiguous backing
allocation, i.e., nr_units * pcpu_unit_pages, but pcpu_chunk_populated()
uses it to set chunk->populated, whose size is pcpu_unit_pages, bitmap.
Since bit N in chunk->populated means page offset N inside every unit is
backed. When nr_units > 1, the function writes beyond chunk->populated.
Fix it by using chunk->nr_pages.
It also fixes the global pcpu_nr_empty_pop_pages accounting, since
pcpu_balance_free() only iterates up to chunk->nr_pages.
Commit a63d4ac4ab609 ("percpu: make percpu-km set chunk->populated bitmap
properly") introduced the bitmap overflow issue. Later, commit
b539b87fed37f ("percpu: implmeent pcpu_nr_empty_pop_pages and
chunk->nr_populated") added pcpu_nr_empty_pop_pages and caused the
accounting issue.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: a63d4ac4ab6094c051a5a240260d16117a7a2f86 Version: a63d4ac4ab6094c051a5a240260d16117a7a2f86 Version: a63d4ac4ab6094c051a5a240260d16117a7a2f86 Version: a63d4ac4ab6094c051a5a240260d16117a7a2f86 Version: a63d4ac4ab6094c051a5a240260d16117a7a2f86 Version: a63d4ac4ab6094c051a5a240260d16117a7a2f86 Version: a63d4ac4ab6094c051a5a240260d16117a7a2f86 Version: a63d4ac4ab6094c051a5a240260d16117a7a2f86 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"mm/percpu-km.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "5f43d2c1bea280dcdfabaf156c25e7402fb8039f",
"status": "affected",
"version": "a63d4ac4ab6094c051a5a240260d16117a7a2f86",
"versionType": "git"
},
{
"lessThan": "92c43ac3c2b09eb16162e8144e73c00b7c3e29d6",
"status": "affected",
"version": "a63d4ac4ab6094c051a5a240260d16117a7a2f86",
"versionType": "git"
},
{
"lessThan": "6fc7da2a052f2825fff785e860e67183f5acaaba",
"status": "affected",
"version": "a63d4ac4ab6094c051a5a240260d16117a7a2f86",
"versionType": "git"
},
{
"lessThan": "01504da375f5b19df195cb1cb1cf1dd184318f97",
"status": "affected",
"version": "a63d4ac4ab6094c051a5a240260d16117a7a2f86",
"versionType": "git"
},
{
"lessThan": "a6940b84c8c035da465b7165fdfcfb005545724e",
"status": "affected",
"version": "a63d4ac4ab6094c051a5a240260d16117a7a2f86",
"versionType": "git"
},
{
"lessThan": "32134cf9211b83bed9076d0739c5906fbea4c763",
"status": "affected",
"version": "a63d4ac4ab6094c051a5a240260d16117a7a2f86",
"versionType": "git"
},
{
"lessThan": "5c7fc39bf19abb38a996aaad77b3e3a8f48581c3",
"status": "affected",
"version": "a63d4ac4ab6094c051a5a240260d16117a7a2f86",
"versionType": "git"
},
{
"lessThan": "89b1b79c308818a715e75f28744b70d8940a07c9",
"status": "affected",
"version": "a63d4ac4ab6094c051a5a240260d16117a7a2f86",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"mm/percpu-km.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.18"
},
{
"lessThan": "3.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "3.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "3.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "3.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "3.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.18",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/percpu-km: fix bitmap overflow and accounting in pcpu_create_chunk()\n\nIn pcpu_create_chunk(), nr_pages is the total contiguous backing\nallocation, i.e., nr_units * pcpu_unit_pages, but pcpu_chunk_populated()\nuses it to set chunk-\u003epopulated, whose size is pcpu_unit_pages, bitmap. \nSince bit N in chunk-\u003epopulated means page offset N inside every unit is\nbacked. When nr_units \u003e 1, the function writes beyond chunk-\u003epopulated. \nFix it by using chunk-\u003enr_pages.\n\nIt also fixes the global pcpu_nr_empty_pop_pages accounting, since\npcpu_balance_free() only iterates up to chunk-\u003enr_pages.\n\nCommit a63d4ac4ab609 (\"percpu: make percpu-km set chunk-\u003epopulated bitmap\nproperly\") introduced the bitmap overflow issue. Later, commit\nb539b87fed37f (\"percpu: implmeent pcpu_nr_empty_pop_pages and\nchunk-\u003enr_populated\") added pcpu_nr_empty_pop_pages and caused the\naccounting issue."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - pcpu_create_chunk() is reached only when the kernel dynamic percpu allocator creates a new chunk via pcpu_alloc_noprof() or pcpu_balance_populated(); both require local syscalls driving __alloc_percpu() exhaustion, and percpu-km applies only on NOMMU/UP kernels with no remote packet path into this code.\nAC:L - On affected SMP NOMMU builds where nr_units\u003e1, an attacker can deterministically force pcpu_create_chunk() by spraying percpu-consuming allocations (e.g., repeated socket() or BPF percpu map creation) until existing chunks are full; no race or victim state outside attacker control is needed.\nPR:L - Dynamic percpu allocation is reachable with basic local user access; unprivileged attackers can obtain effective capability via user namespaces (unshare -Urn) plus CAP_NET_RAW-class socket paths or CAP_BPF where enabled, matching percpu-spray patterns in similar allocator CVEs.\nUI:N - The attacker drives percpu exhaustion and new-chunk creation entirely from its own processes via repeated local syscalls; no victim mount, file open, or administrator interaction is required.\nS:U - The bitmap overflow corrupts kernel kmalloc slab objects and percpu bookkeeping within the same kernel security domain; this is standard kernel heap corruption, not a VM, IOMMU, or sandbox boundary escape.\nC:H - bitmap_set() writes up to (nr_units*pcpu_unit_pages) bits into chunk-\u003epopulated[] sized for only pcpu_unit_pages, overflowing the kzalloc allocation in pcpu_alloc_chunk() and exposing or corrupting adjacent kernel heap memory.\nI:H - The same out-of-bounds write corrupts neighboring slab objects and inflates nr_populated/nr_empty_pop_pages accounting, providing attacker-influenced heap metadata corruption exploitable for arbitrary kernel writes and privilege escalation.\nA:H - Slab overflow during chunk initialization can immediately oops or panic the kernel and leaves corrupted allocator state that causes subsequent percpu operations to fault, consistent with rubric guidance for heap corruption bugs."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-29T06:22:34.556Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/5f43d2c1bea280dcdfabaf156c25e7402fb8039f"
},
{
"url": "https://git.kernel.org/stable/c/92c43ac3c2b09eb16162e8144e73c00b7c3e29d6"
},
{
"url": "https://git.kernel.org/stable/c/6fc7da2a052f2825fff785e860e67183f5acaaba"
},
{
"url": "https://git.kernel.org/stable/c/01504da375f5b19df195cb1cb1cf1dd184318f97"
},
{
"url": "https://git.kernel.org/stable/c/a6940b84c8c035da465b7165fdfcfb005545724e"
},
{
"url": "https://git.kernel.org/stable/c/32134cf9211b83bed9076d0739c5906fbea4c763"
},
{
"url": "https://git.kernel.org/stable/c/5c7fc39bf19abb38a996aaad77b3e3a8f48581c3"
},
{
"url": "https://git.kernel.org/stable/c/89b1b79c308818a715e75f28744b70d8940a07c9"
}
],
"title": "mm/percpu-km: fix bitmap overflow and accounting in pcpu_create_chunk()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80718",
"datePublished": "2026-08-28T06:53:15.490Z",
"dateReserved": "2026-08-26T14:34:25.788Z",
"dateUpdated": "2026-08-29T06:22:34.556Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74494 (GCVE-0-2026-74494)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-23 12:47
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: reject repeated SMB2 NEGOTIATE requests
Unauthenticated client can send multiple successful SMB2 NEGOTIATE
requests on one connection before SESSION_SETUP. While the connection is
in KSMBD_SESS_NEED_SETUP, smb2_handle_negotiate() accepts another
SMB3.1.1 NEGOTIATE and overwrites conn->preauth_info with a new allocation.
Only the final allocation is freed when the connection is released, leaking
one object for every additional successful request.
A repeated SMB2 NEGOTIATE after a dialect has been selected is a protocol
violation. MS-SMB2 section 3.3.5.4 requires the server to disconnect
without replying in this case. Set the connection exiting when rejecting
the request, in addition to suppressing the response.
Reject SMB2 NEGOTIATE unless the connection is new or is waiting for the
SMB2 NEGOTIATE that follows an SMB1 multi-protocol negotiate. Serialize
both SMB1 and SMB2 negotiation paths under conn->srv_mutex, since they
update connection-wide dialect and negotiation state.
Move the locking contract to ksmbd_smb_negotiate_common(), where the state
and dialect are selected, and add ksmbd_conn_new() for consistent state
access.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 Version: e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 Version: e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 Version: e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 Version: e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 Version: e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 Version: e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/smb/server/connection.h",
"fs/smb/server/smb2pdu.c",
"fs/smb/server/smb_common.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "0b1390cf2b6b91723b37c0909dd123f7a5eba1a7",
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"versionType": "git"
},
{
"lessThan": "fd6a6c43f96b40a08a22ff62f08d194a49741c8a",
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"versionType": "git"
},
{
"lessThan": "81e21cb7bd1479bb5238e0004a7e0110452c610b",
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"versionType": "git"
},
{
"lessThan": "7fb8dbeb3f2868ae836ca12311d89aed16fc2927",
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"versionType": "git"
},
{
"lessThan": "a60b5da05e318d9a364dbac38c347c7f24e625e7",
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"versionType": "git"
},
{
"lessThan": "7e02cb30e8a1f5fc78cb10b220b06020e36d0bbe",
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"versionType": "git"
},
{
"lessThan": "cb469993b3a61a72653770856d37af616d72d05f",
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/smb/server/connection.h",
"fs/smb/server/smb2pdu.c",
"fs/smb/server/smb_common.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.15"
},
{
"lessThan": "5.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: reject repeated SMB2 NEGOTIATE requests\n\nUnauthenticated client can send multiple successful SMB2 NEGOTIATE\nrequests on one connection before SESSION_SETUP. While the connection is\nin KSMBD_SESS_NEED_SETUP, smb2_handle_negotiate() accepts another\nSMB3.1.1 NEGOTIATE and overwrites conn-\u003epreauth_info with a new allocation.\nOnly the final allocation is freed when the connection is released, leaking\none object for every additional successful request.\n\nA repeated SMB2 NEGOTIATE after a dialect has been selected is a protocol\nviolation. MS-SMB2 section 3.3.5.4 requires the server to disconnect\nwithout replying in this case. Set the connection exiting when rejecting\nthe request, in addition to suppressing the response.\n\nReject SMB2 NEGOTIATE unless the connection is new or is waiting for the\nSMB2 NEGOTIATE that follows an SMB1 multi-protocol negotiate. Serialize\nboth SMB1 and SMB2 negotiation paths under conn-\u003esrv_mutex, since they\nupdate connection-wide dialect and negotiation state.\n\nMove the locking contract to ksmbd_smb_negotiate_common(), where the state\nand dialect are selected, and add ksmbd_conn_new() for consistent state\naccess."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:47:27.752Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/0b1390cf2b6b91723b37c0909dd123f7a5eba1a7"
},
{
"url": "https://git.kernel.org/stable/c/fd6a6c43f96b40a08a22ff62f08d194a49741c8a"
},
{
"url": "https://git.kernel.org/stable/c/81e21cb7bd1479bb5238e0004a7e0110452c610b"
},
{
"url": "https://git.kernel.org/stable/c/7fb8dbeb3f2868ae836ca12311d89aed16fc2927"
},
{
"url": "https://git.kernel.org/stable/c/a60b5da05e318d9a364dbac38c347c7f24e625e7"
},
{
"url": "https://git.kernel.org/stable/c/7e02cb30e8a1f5fc78cb10b220b06020e36d0bbe"
},
{
"url": "https://git.kernel.org/stable/c/cb469993b3a61a72653770856d37af616d72d05f"
}
],
"title": "ksmbd: reject repeated SMB2 NEGOTIATE requests",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74494",
"datePublished": "2026-08-15T12:27:22.609Z",
"dateReserved": "2026-08-15T05:44:03.906Z",
"dateUpdated": "2026-08-23T12:47:27.752Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68099 (GCVE-0-2026-68099)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-23 12:45
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: restore DACL size on check_add_overflow() to avoid malformed ACL
check_add_overflow() unconditionally writes the truncated sum into *d
even on overflow, per its contract in include/linux/overflow.h.
The four check_add_overflow() guards in set_posix_acl_entries_dacl()
and set_ntacl_dacl() break out of the ACE-building loops on overflow,
but the truncated *size is then consumed downstream at the end of
set_ntacl_dacl():
pndacl->size = cpu_to_le16(le16_to_cpu(pndacl->size) + size);
This produces an on-wire NT ACL whose pndacl->size under-reports the
bytes actually written by the preceding fill_ace_for_sid()/memcpy()
calls, yielding a malformed ACL that can trigger out-of-bounds reads
when re-parsed by clients or ksmbd itself.
Restore *size to its pre-addition value on each overflow branch (via
`*size -= ace_sz` / `size -= nt_ace_size`) so that after the break,
*size once again holds the cumulative size of the successfully-written
ACEs. The committed ACL is then truncated-but-self-consistent rather
than malformed.
The ksmbd DACL builders are the only check_add_overflow() sites found
where an overflow path breaks out of a loop and the destination value
is consumed afterward. The other nearby break-style cases either
return -EINVAL on overflow (transport_ipc.c) or break without
consuming the overflowed destination value afterward (buildid.c).
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 41e53a773db6342ac9a689ee5ba635c31744c9f0 Version: 8d5729350b236896f51379588d9a690b7fafb8db Version: e1955a94b6f17f4b058afa955a6f187eb3ed7615 Version: 5e7b8f3c539d69b2ed5f2408e2f75e68ce7eef43 Version: 299f962c0b02d048fb45d248b4da493d03f3175d Version: 299f962c0b02d048fb45d248b4da493d03f3175d Version: ef7902be3f215b6bf7babe4dc9dd9a7d57dad7a7 Version: 6.1.175 ≤ Version: 6.6.136 ≤ Version: 6.12.84 ≤ Version: 6.18.25 ≤ Version: 7.0.2 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/smb/server/smbacl.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "8f3a7a499a7d9bb1c0f33fe78c4a4594d7e307f4",
"status": "affected",
"version": "41e53a773db6342ac9a689ee5ba635c31744c9f0",
"versionType": "git"
},
{
"lessThan": "f4fcd0c1a243d449307b887fafee23921e9db5ab",
"status": "affected",
"version": "8d5729350b236896f51379588d9a690b7fafb8db",
"versionType": "git"
},
{
"lessThan": "0bf38372821b1526f31538a7d9811844c55c7f38",
"status": "affected",
"version": "e1955a94b6f17f4b058afa955a6f187eb3ed7615",
"versionType": "git"
},
{
"lessThan": "847ecd4eb3c117c3d2f13f1e7ab506543aad8183",
"status": "affected",
"version": "5e7b8f3c539d69b2ed5f2408e2f75e68ce7eef43",
"versionType": "git"
},
{
"lessThan": "bc90144ce8bb7fcf05ad9417c7adb4e9509d9e13",
"status": "affected",
"version": "299f962c0b02d048fb45d248b4da493d03f3175d",
"versionType": "git"
},
{
"lessThan": "bbf0a8e931204ecdab494a88d43b0a24a04285c5",
"status": "affected",
"version": "299f962c0b02d048fb45d248b4da493d03f3175d",
"versionType": "git"
},
{
"status": "affected",
"version": "ef7902be3f215b6bf7babe4dc9dd9a7d57dad7a7",
"versionType": "git"
},
{
"lessThan": "6.1.184",
"status": "affected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThan": "6.6.148",
"status": "affected",
"version": "6.6.136",
"versionType": "semver"
},
{
"lessThan": "6.12.101",
"status": "affected",
"version": "6.12.84",
"versionType": "semver"
},
{
"lessThan": "6.18.42",
"status": "affected",
"version": "6.18.25",
"versionType": "semver"
},
{
"lessThan": "7.1",
"status": "affected",
"version": "7.0.2",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/smb/server/smbacl.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "7.1"
},
{
"lessThan": "7.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "6.1.175",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.6.136",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.12.84",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.18.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "7.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "7.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "7.0.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: restore DACL size on check_add_overflow() to avoid malformed ACL\n\ncheck_add_overflow() unconditionally writes the truncated sum into *d\neven on overflow, per its contract in include/linux/overflow.h.\nThe four check_add_overflow() guards in set_posix_acl_entries_dacl()\nand set_ntacl_dacl() break out of the ACE-building loops on overflow,\nbut the truncated *size is then consumed downstream at the end of\nset_ntacl_dacl():\n\n pndacl-\u003esize = cpu_to_le16(le16_to_cpu(pndacl-\u003esize) + size);\n\nThis produces an on-wire NT ACL whose pndacl-\u003esize under-reports the\nbytes actually written by the preceding fill_ace_for_sid()/memcpy()\ncalls, yielding a malformed ACL that can trigger out-of-bounds reads\nwhen re-parsed by clients or ksmbd itself.\n\nRestore *size to its pre-addition value on each overflow branch (via\n`*size -= ace_sz` / `size -= nt_ace_size`) so that after the break,\n*size once again holds the cumulative size of the successfully-written\nACEs. The committed ACL is then truncated-but-self-consistent rather\nthan malformed.\n\nThe ksmbd DACL builders are the only check_add_overflow() sites found\nwhere an overflow path breaks out of a loop and the destination value\nis consumed afterward. The other nearby break-style cases either\nreturn -EINVAL on overflow (transport_ipc.c) or break without\nconsuming the overflowed destination value afterward (buildid.c)."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:45:49.075Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/8f3a7a499a7d9bb1c0f33fe78c4a4594d7e307f4"
},
{
"url": "https://git.kernel.org/stable/c/f4fcd0c1a243d449307b887fafee23921e9db5ab"
},
{
"url": "https://git.kernel.org/stable/c/0bf38372821b1526f31538a7d9811844c55c7f38"
},
{
"url": "https://git.kernel.org/stable/c/847ecd4eb3c117c3d2f13f1e7ab506543aad8183"
},
{
"url": "https://git.kernel.org/stable/c/bc90144ce8bb7fcf05ad9417c7adb4e9509d9e13"
},
{
"url": "https://git.kernel.org/stable/c/bbf0a8e931204ecdab494a88d43b0a24a04285c5"
}
],
"title": "ksmbd: restore DACL size on check_add_overflow() to avoid malformed ACL",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68099",
"datePublished": "2026-08-10T11:58:13.940Z",
"dateReserved": "2026-07-30T09:28:09.368Z",
"dateUpdated": "2026-08-23T12:45:49.075Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80782 (GCVE-0-2026-80782)
Vulnerability from cvelistv5
Published
2026-09-04 15:12
Modified
2026-09-04 15:12
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
HID: magicmouse: do not keep a stale msc->input if no input is claimed
magicmouse_input_mapping() caches the first hid_input's input_dev in
msc->input while the report descriptor is parsed, and the rest of the
driver treats a non-NULL msc->input as proof that an input device was
registered.
That does not hold on the hid-input error path. If hidinput_connect()
fails -- for instance because input_register_device() returns an error --
it unwinds through hidinput_disconnect(), which frees every input_dev it
created, including the one cached in msc->input.
The failure does not abort the probe. hid_connect() only skips the claim:
if ((connect_mask & HID_CONNECT_HIDINPUT) && !hidinput_connect(hdev,
connect_mask & HID_CONNECT_HIDINPUT_FORCE))
hdev->claimed |= HID_CLAIMED_INPUT;
and the "device has no listeners" bailout below it does not fire for this
driver, which sets ->raw_event; on the USB Magic Mouse 2 / Magic Trackpad
2 paths hidraw and hiddev are claimed as well. hid_hw_start() therefore
returns 0 and magicmouse_probe() continues with msc->input pointing at
freed memory. Being non-NULL, it passes the "input not registered" check
in probe and the NULL checks in ->raw_event and ->event, so the next
input report dereferences freed memory.
Clear msc->input when the HID core did not claim an input device, so the
existing NULL checks cover this case as well.
References
| URL | Tags | ||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: f1a9a149abc86903e81dd1b2e720f3f89874384b Version: f1a9a149abc86903e81dd1b2e720f3f89874384b Version: f1a9a149abc86903e81dd1b2e720f3f89874384b Version: f1a9a149abc86903e81dd1b2e720f3f89874384b Version: f1a9a149abc86903e81dd1b2e720f3f89874384b Version: f1a9a149abc86903e81dd1b2e720f3f89874384b Version: f1a9a149abc86903e81dd1b2e720f3f89874384b Version: f1a9a149abc86903e81dd1b2e720f3f89874384b Version: f1a9a149abc86903e81dd1b2e720f3f89874384b Version: 0e55072e7c63a6569cab1447e9025d160abd9dd9 Version: 3.8.7 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/hid/hid-magicmouse.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c3597923932bb90d4fc2186aef552f6677175e4a",
"status": "affected",
"version": "f1a9a149abc86903e81dd1b2e720f3f89874384b",
"versionType": "git"
},
{
"lessThan": "e0c224c93d10ee38854fdf24c815108aedd3dcb3",
"status": "affected",
"version": "f1a9a149abc86903e81dd1b2e720f3f89874384b",
"versionType": "git"
},
{
"lessThan": "403cc9bd6ccb9fbe68d501c3236e5a6dd5504e14",
"status": "affected",
"version": "f1a9a149abc86903e81dd1b2e720f3f89874384b",
"versionType": "git"
},
{
"lessThan": "3d7a7bac4c75f25b2513505a0ac5ba909588ed2b",
"status": "affected",
"version": "f1a9a149abc86903e81dd1b2e720f3f89874384b",
"versionType": "git"
},
{
"lessThan": "9bdf8c7bfd79f1090e61d28f969b32880fd77bb3",
"status": "affected",
"version": "f1a9a149abc86903e81dd1b2e720f3f89874384b",
"versionType": "git"
},
{
"lessThan": "15b60ade825c8ce9ec560048a4ae3747e4572be3",
"status": "affected",
"version": "f1a9a149abc86903e81dd1b2e720f3f89874384b",
"versionType": "git"
},
{
"lessThan": "0bf253e9ac994cb5329bc87b00bb4eeca9136791",
"status": "affected",
"version": "f1a9a149abc86903e81dd1b2e720f3f89874384b",
"versionType": "git"
},
{
"lessThan": "2ef16934e069d5f771e989d6ee5c3ece5042f3cd",
"status": "affected",
"version": "f1a9a149abc86903e81dd1b2e720f3f89874384b",
"versionType": "git"
},
{
"lessThan": "0af3b89705688af01aa06025b84fa7a1e06ba6cc",
"status": "affected",
"version": "f1a9a149abc86903e81dd1b2e720f3f89874384b",
"versionType": "git"
},
{
"status": "affected",
"version": "0e55072e7c63a6569cab1447e9025d160abd9dd9",
"versionType": "git"
},
{
"lessThan": "3.9",
"status": "affected",
"version": "3.8.7",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/hid/hid-magicmouse.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.9"
},
{
"lessThan": "3.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.269",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.218",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.185",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.154",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.106",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.47",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.1",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.269",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.218",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.185",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.154",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.106",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.47",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.11",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.1",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.8.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: magicmouse: do not keep a stale msc-\u003einput if no input is claimed\n\nmagicmouse_input_mapping() caches the first hid_input\u0027s input_dev in\nmsc-\u003einput while the report descriptor is parsed, and the rest of the\ndriver treats a non-NULL msc-\u003einput as proof that an input device was\nregistered.\n\nThat does not hold on the hid-input error path. If hidinput_connect()\nfails -- for instance because input_register_device() returns an error --\nit unwinds through hidinput_disconnect(), which frees every input_dev it\ncreated, including the one cached in msc-\u003einput.\n\nThe failure does not abort the probe. hid_connect() only skips the claim:\n\n\tif ((connect_mask \u0026 HID_CONNECT_HIDINPUT) \u0026\u0026 !hidinput_connect(hdev,\n\t\t\t\tconnect_mask \u0026 HID_CONNECT_HIDINPUT_FORCE))\n\t\thdev-\u003eclaimed |= HID_CLAIMED_INPUT;\n\nand the \"device has no listeners\" bailout below it does not fire for this\ndriver, which sets -\u003eraw_event; on the USB Magic Mouse 2 / Magic Trackpad\n2 paths hidraw and hiddev are claimed as well. hid_hw_start() therefore\nreturns 0 and magicmouse_probe() continues with msc-\u003einput pointing at\nfreed memory. Being non-NULL, it passes the \"input not registered\" check\nin probe and the NULL checks in -\u003eraw_event and -\u003eevent, so the next\ninput report dereferences freed memory.\n\nClear msc-\u003einput when the HID core did not claim an input device, so the\nexisting NULL checks cover this case as well."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T15:12:53.933Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c3597923932bb90d4fc2186aef552f6677175e4a"
},
{
"url": "https://git.kernel.org/stable/c/e0c224c93d10ee38854fdf24c815108aedd3dcb3"
},
{
"url": "https://git.kernel.org/stable/c/403cc9bd6ccb9fbe68d501c3236e5a6dd5504e14"
},
{
"url": "https://git.kernel.org/stable/c/3d7a7bac4c75f25b2513505a0ac5ba909588ed2b"
},
{
"url": "https://git.kernel.org/stable/c/9bdf8c7bfd79f1090e61d28f969b32880fd77bb3"
},
{
"url": "https://git.kernel.org/stable/c/15b60ade825c8ce9ec560048a4ae3747e4572be3"
},
{
"url": "https://git.kernel.org/stable/c/0bf253e9ac994cb5329bc87b00bb4eeca9136791"
},
{
"url": "https://git.kernel.org/stable/c/2ef16934e069d5f771e989d6ee5c3ece5042f3cd"
},
{
"url": "https://git.kernel.org/stable/c/0af3b89705688af01aa06025b84fa7a1e06ba6cc"
}
],
"title": "HID: magicmouse: do not keep a stale msc-\u003einput if no input is claimed",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80782",
"datePublished": "2026-09-04T15:12:53.933Z",
"dateReserved": "2026-08-26T14:34:25.792Z",
"dateUpdated": "2026-09-04T15:12:53.933Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64572 (GCVE-0-2026-64572)
Vulnerability from cvelistv5
Published
2026-08-05 08:08
Modified
2026-08-19 16:28
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ipv4: fib: free fib_alias with kfree_rcu() on insert error path
fib_table_insert() publishes new_fa into the leaf's fa_list with
fib_insert_alias() before calling the fib entry notifiers. When a
notifier fails, the error path removes new_fa with fib_remove_alias()
(hlist_del_rcu) and frees it right away with kmem_cache_free().
fib_table_lookup() walks that list under rcu_read_lock() only, so a
concurrent lookup that already reached new_fa keeps reading it after the
free:
BUG: KASAN: slab-use-after-free in fib_table_lookup (net/ipv4/fib_trie.c:1601)
Read of size 1 at addr ffff88810676d4eb by task exploit/297
Call Trace:
fib_table_lookup (net/ipv4/fib_trie.c:1601)
ip_route_output_key_hash_rcu (net/ipv4/route.c:2814)
ip_route_output_key_hash (net/ipv4/route.c:2705)
__ip4_datagram_connect (net/ipv4/datagram.c:49)
udp_connect (net/ipv4/udp.c:2144)
__sys_connect (net/socket.c:2167)
__x64_sys_connect (net/socket.c:2173)
do_syscall_64
entry_SYSCALL_64_after_hwframe
which belongs to the cache ip_fib_alias of size 56
Triggering the error path needs CAP_NET_ADMIN and a registered fib
notifier that can reject a route; a netdevsim device whose IPv4 FIB
resource is exhausted is enough.
Free new_fa with alias_free_mem_rcu(), as fib_table_delete() already
does for a fib_alias removed from the trie.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: a6c76c17df021b141b0d306828c9fe4ba2d2717c Version: a6c76c17df021b141b0d306828c9fe4ba2d2717c Version: a6c76c17df021b141b0d306828c9fe4ba2d2717c Version: a6c76c17df021b141b0d306828c9fe4ba2d2717c Version: a6c76c17df021b141b0d306828c9fe4ba2d2717c Version: a6c76c17df021b141b0d306828c9fe4ba2d2717c Version: a6c76c17df021b141b0d306828c9fe4ba2d2717c Version: a6c76c17df021b141b0d306828c9fe4ba2d2717c |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ipv4/fib_trie.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "9d0778571def598c31e84a38ae5a7ebc6f65e6d8",
"status": "affected",
"version": "a6c76c17df021b141b0d306828c9fe4ba2d2717c",
"versionType": "git"
},
{
"lessThan": "bb03350f974aec352b660d032a1d283eb462165a",
"status": "affected",
"version": "a6c76c17df021b141b0d306828c9fe4ba2d2717c",
"versionType": "git"
},
{
"lessThan": "6429c9cfd941e62acd7bb0bc64d631574d4c3b2a",
"status": "affected",
"version": "a6c76c17df021b141b0d306828c9fe4ba2d2717c",
"versionType": "git"
},
{
"lessThan": "8150b5365f026e72250cacc527ea00be30f40105",
"status": "affected",
"version": "a6c76c17df021b141b0d306828c9fe4ba2d2717c",
"versionType": "git"
},
{
"lessThan": "d007056868723de9c0cc3f5ffaad47a8d468b9a4",
"status": "affected",
"version": "a6c76c17df021b141b0d306828c9fe4ba2d2717c",
"versionType": "git"
},
{
"lessThan": "cb8be318b4432abd88d3172ec157330f27a5f7a7",
"status": "affected",
"version": "a6c76c17df021b141b0d306828c9fe4ba2d2717c",
"versionType": "git"
},
{
"lessThan": "b8d2ea75c76abcd0d72679c2f488271f573e32fb",
"status": "affected",
"version": "a6c76c17df021b141b0d306828c9fe4ba2d2717c",
"versionType": "git"
},
{
"lessThan": "f2f152e94a67bc746afaf05a1b2702c195553112",
"status": "affected",
"version": "a6c76c17df021b141b0d306828c9fe4ba2d2717c",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ipv4/fib_trie.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.6"
},
{
"lessThan": "5.6",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: fib: free fib_alias with kfree_rcu() on insert error path\n\nfib_table_insert() publishes new_fa into the leaf\u0027s fa_list with\nfib_insert_alias() before calling the fib entry notifiers. When a\nnotifier fails, the error path removes new_fa with fib_remove_alias()\n(hlist_del_rcu) and frees it right away with kmem_cache_free().\n\nfib_table_lookup() walks that list under rcu_read_lock() only, so a\nconcurrent lookup that already reached new_fa keeps reading it after the\nfree:\n\n BUG: KASAN: slab-use-after-free in fib_table_lookup (net/ipv4/fib_trie.c:1601)\n Read of size 1 at addr ffff88810676d4eb by task exploit/297\n Call Trace:\n fib_table_lookup (net/ipv4/fib_trie.c:1601)\n ip_route_output_key_hash_rcu (net/ipv4/route.c:2814)\n ip_route_output_key_hash (net/ipv4/route.c:2705)\n __ip4_datagram_connect (net/ipv4/datagram.c:49)\n udp_connect (net/ipv4/udp.c:2144)\n __sys_connect (net/socket.c:2167)\n __x64_sys_connect (net/socket.c:2173)\n do_syscall_64\n entry_SYSCALL_64_after_hwframe\n which belongs to the cache ip_fib_alias of size 56\n\nTriggering the error path needs CAP_NET_ADMIN and a registered fib\nnotifier that can reject a route; a netdevsim device whose IPv4 FIB\nresource is exhausted is enough.\n\nFree new_fa with alias_free_mem_rcu(), as fib_table_delete() already\ndoes for a fib_alias removed from the trie."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:28:49.541Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/9d0778571def598c31e84a38ae5a7ebc6f65e6d8"
},
{
"url": "https://git.kernel.org/stable/c/bb03350f974aec352b660d032a1d283eb462165a"
},
{
"url": "https://git.kernel.org/stable/c/6429c9cfd941e62acd7bb0bc64d631574d4c3b2a"
},
{
"url": "https://git.kernel.org/stable/c/8150b5365f026e72250cacc527ea00be30f40105"
},
{
"url": "https://git.kernel.org/stable/c/d007056868723de9c0cc3f5ffaad47a8d468b9a4"
},
{
"url": "https://git.kernel.org/stable/c/cb8be318b4432abd88d3172ec157330f27a5f7a7"
},
{
"url": "https://git.kernel.org/stable/c/b8d2ea75c76abcd0d72679c2f488271f573e32fb"
},
{
"url": "https://git.kernel.org/stable/c/f2f152e94a67bc746afaf05a1b2702c195553112"
}
],
"title": "ipv4: fib: free fib_alias with kfree_rcu() on insert error path",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64572",
"datePublished": "2026-08-05T08:08:09.068Z",
"dateReserved": "2026-07-19T15:36:31.797Z",
"dateUpdated": "2026-08-19T16:28:49.541Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80573 (GCVE-0-2026-80573)
Vulnerability from cvelistv5
Published
2026-08-26 14:37
Modified
2026-08-27 04:58
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Input: iforce - validate input packet lengths
iforce_process_packet() reads fixed fields from joystick, wheel and
status packets without first checking their lengths. In particular, the
shared hats-and-buttons helper unconditionally reads data[6]. The status
tail is a sequence of 16-bit effect addresses, but an incomplete final
address is also consumed. A successful zero-length USB URB additionally
reads the packet ID before the common parser is called.
Reject the zero-length USB transfer, require the seven-byte joystick and
wheel prefixes and the two-byte status prefix, and consume only complete
status-tail addresses.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/input/joystick/iforce/iforce-packets.c",
"drivers/input/joystick/iforce/iforce-usb.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "0ec411167655ef3ff3e84f6af685e962aff9a75b",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "609be40988898a4d75225ade0ea5c1734757dd33",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "e73d7a7d913d89141321f5f3f16343ecc200d152",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "5232529eaf57f08fe37484e301579a1915b93d14",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "2c083ab16e33fbff3ab8c752fbf8118ed3dd31ce",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "a64a8b6b31cd669f0449138e53cc2592d454ccf1",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "84e5cb517f445dadbd5f8bf4ec513540e51f9c36",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "5751c781d3c97ab6ce0e2a966156ed882152c415",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/input/joystick/iforce/iforce-packets.c",
"drivers/input/joystick/iforce/iforce-usb.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.46",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.10",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nInput: iforce - validate input packet lengths\n\niforce_process_packet() reads fixed fields from joystick, wheel and\nstatus packets without first checking their lengths. In particular, the\nshared hats-and-buttons helper unconditionally reads data[6]. The status\ntail is a sequence of 16-bit effect addresses, but an incomplete final\naddress is also consumed. A successful zero-length USB URB additionally\nreads the packet ID before the common parser is called.\n\nReject the zero-length USB transfer, require the seven-byte joystick and\nwheel prefixes and the two-byte status prefix, and consume only complete\nstatus-tail addresses."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T04:58:55.441Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/0ec411167655ef3ff3e84f6af685e962aff9a75b"
},
{
"url": "https://git.kernel.org/stable/c/609be40988898a4d75225ade0ea5c1734757dd33"
},
{
"url": "https://git.kernel.org/stable/c/e73d7a7d913d89141321f5f3f16343ecc200d152"
},
{
"url": "https://git.kernel.org/stable/c/5232529eaf57f08fe37484e301579a1915b93d14"
},
{
"url": "https://git.kernel.org/stable/c/2c083ab16e33fbff3ab8c752fbf8118ed3dd31ce"
},
{
"url": "https://git.kernel.org/stable/c/a64a8b6b31cd669f0449138e53cc2592d454ccf1"
},
{
"url": "https://git.kernel.org/stable/c/84e5cb517f445dadbd5f8bf4ec513540e51f9c36"
},
{
"url": "https://git.kernel.org/stable/c/5751c781d3c97ab6ce0e2a966156ed882152c415"
}
],
"title": "Input: iforce - validate input packet lengths",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80573",
"datePublished": "2026-08-26T14:37:33.756Z",
"dateReserved": "2026-08-26T14:34:25.768Z",
"dateUpdated": "2026-08-27T04:58:55.441Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74450 (GCVE-0-2026-74450)
Vulnerability from cvelistv5
Published
2026-08-15 12:26
Modified
2026-08-23 12:47
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/pm: fix pptable use-after-free
amdgpu_dpm_get_pp_table() returns a pointer to a driver-owned power table
after dropping adev->pm.mutex. The sysfs path then copies from that pointer.
A concurrent pp_table write can replace and free the allocation during the
copy, causing a use-after-free.
Change the DPM interface to copy into caller-provided storage while the mutex
is held. Keep the size-only query for attribute discovery without exposing
the driver-owned pointer.
(cherry picked from commit f6eed7acfd30099ef7baeb6ba45bb59daad80631)
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1684d3ba488529266ce6f97b88076bd185f4790e Version: 1684d3ba488529266ce6f97b88076bd185f4790e Version: 1684d3ba488529266ce6f97b88076bd185f4790e Version: 1684d3ba488529266ce6f97b88076bd185f4790e Version: 1684d3ba488529266ce6f97b88076bd185f4790e Version: 1684d3ba488529266ce6f97b88076bd185f4790e |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/pm/amdgpu_dpm.c",
"drivers/gpu/drm/amd/pm/amdgpu_pm.c",
"drivers/gpu/drm/amd/pm/inc/amdgpu_dpm.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "3fbb3ac75000e3187f500a91a4099b24206866a1",
"status": "affected",
"version": "1684d3ba488529266ce6f97b88076bd185f4790e",
"versionType": "git"
},
{
"lessThan": "9efc767335234cf7a892e46d45cd453b711421e7",
"status": "affected",
"version": "1684d3ba488529266ce6f97b88076bd185f4790e",
"versionType": "git"
},
{
"lessThan": "81b5af1fb0f14cace6c3b3130a05e5602a597820",
"status": "affected",
"version": "1684d3ba488529266ce6f97b88076bd185f4790e",
"versionType": "git"
},
{
"lessThan": "8c685df5c3b261c42505110965b42f9a754eb9b7",
"status": "affected",
"version": "1684d3ba488529266ce6f97b88076bd185f4790e",
"versionType": "git"
},
{
"lessThan": "b628f2c6feb3a115ea72d3120a2bd94afc5163df",
"status": "affected",
"version": "1684d3ba488529266ce6f97b88076bd185f4790e",
"versionType": "git"
},
{
"lessThan": "bb493058c35c8676e48269ab6732688ea733d23c",
"status": "affected",
"version": "1684d3ba488529266ce6f97b88076bd185f4790e",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/pm/amdgpu_dpm.c",
"drivers/gpu/drm/amd/pm/amdgpu_pm.c",
"drivers/gpu/drm/amd/pm/inc/amdgpu_dpm.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.9"
},
{
"lessThan": "4.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.46",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/pm: fix pptable use-after-free\n\namdgpu_dpm_get_pp_table() returns a pointer to a driver-owned power table\nafter dropping adev-\u003epm.mutex. The sysfs path then copies from that pointer.\nA concurrent pp_table write can replace and free the allocation during the\ncopy, causing a use-after-free.\n\nChange the DPM interface to copy into caller-provided storage while the mutex\nis held. Keep the size-only query for attribute discovery without exposing\nthe driver-owned pointer.\n\n(cherry picked from commit f6eed7acfd30099ef7baeb6ba45bb59daad80631)"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Reached only via local sysfs read/write on /sys/class/drm/cardN/device/pp_table (amdgpu_get_pp_table/amdgpu_set_pp_table); no network, adjacent, or physical-access path exists into amdgpu_dpm_get_pp_table().\nAC:L - A single attacker can drive both sides of the race with concurrent pp_table read and write threads; the write path holds pm.mutex during smu_reset/smu_sys_set_pp_table() while the read copies up to PAGE_SIZE-1 bytes from a pointer obtained after mutex drop.\nPR:L - Triggering the concurrent write/free requires sysfs write access to pp_table; the kernel CNA\u0027s CVE-2025-21780 scored the same attribute PR:L because gaming/handheld udev rules commonly group-write pp_* nodes and the commit describes a concurrent pp_table write.\nUI:N - Exploitation is performed by the attacker\u0027s own concurrent sysfs read/write loops; no action by another user or victim is required.\nS:U - The use-after-free corrupts kernel heap memory during a sysfs memcpy in amdgpu_pm.c; impact stays within the kernel security authority with no VM, IOMMU, or sandbox boundary crossed.\nC:H - Use-after-free on a kmalloc\u0027d pp table during memcpy can return freed/reallocated kernel heap contents up to PAGE_SIZE-1 bytes to userspace and enables arbitrary kernel memory reads via heap grooming.\nI:H - Concurrent pp_table writes control kmalloc size/contents while reads dereference the freed pptable, classic UAF heap corruption that can be weaponized for arbitrary kernel writes and privilege escalation.\nA:H - Reading freed pptable memory during memcpy causes kernel oops/panic and smu_reset() during the concurrent write can wedge discrete AMD GPUs; UAF reliably threatens system/GPU availability."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:47:19.009Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/3fbb3ac75000e3187f500a91a4099b24206866a1"
},
{
"url": "https://git.kernel.org/stable/c/9efc767335234cf7a892e46d45cd453b711421e7"
},
{
"url": "https://git.kernel.org/stable/c/81b5af1fb0f14cace6c3b3130a05e5602a597820"
},
{
"url": "https://git.kernel.org/stable/c/8c685df5c3b261c42505110965b42f9a754eb9b7"
},
{
"url": "https://git.kernel.org/stable/c/b628f2c6feb3a115ea72d3120a2bd94afc5163df"
},
{
"url": "https://git.kernel.org/stable/c/bb493058c35c8676e48269ab6732688ea733d23c"
}
],
"title": "drm/amd/pm: fix pptable use-after-free",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74450",
"datePublished": "2026-08-15T12:26:55.127Z",
"dateReserved": "2026-08-15T05:44:03.899Z",
"dateUpdated": "2026-08-23T12:47:19.009Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74585 (GCVE-0-2026-74585)
Vulnerability from cvelistv5
Published
2026-08-22 15:31
Modified
2026-08-22 15:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
thunderbolt: Bound the DROM dual link port number before indexing sw->ports
tb_drom_parse_entry_port() validates the device-supplied header->index
against sw->config.max_port_number before indexing sw->ports[], but the
sibling field entry->dual_link_port_nr -- a 6-bit value also read from
the DROM -- indexes the same array with no such check. A malicious or
malformed Thunderbolt device can set dual_link_port_nr beyond the
allocated sw->ports[] (max_port_number + 1 entries), producing an
out-of-bounds tb_port pointer that is stored and later dereferenced.
Reject a port entry whose dual_link_port_nr exceeds max_port_number,
the same bound already applied to header->index.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: cd22e73bdf5eff7e68a0f8bdfbce123ad43651f6 Version: cd22e73bdf5eff7e68a0f8bdfbce123ad43651f6 Version: cd22e73bdf5eff7e68a0f8bdfbce123ad43651f6 Version: cd22e73bdf5eff7e68a0f8bdfbce123ad43651f6 Version: cd22e73bdf5eff7e68a0f8bdfbce123ad43651f6 Version: cd22e73bdf5eff7e68a0f8bdfbce123ad43651f6 Version: cd22e73bdf5eff7e68a0f8bdfbce123ad43651f6 Version: cd22e73bdf5eff7e68a0f8bdfbce123ad43651f6 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/thunderbolt/eeprom.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "6c892ed9f4129ae40ef0f92e1bb31aa0b0ddc72c",
"status": "affected",
"version": "cd22e73bdf5eff7e68a0f8bdfbce123ad43651f6",
"versionType": "git"
},
{
"lessThan": "3d3c212b70633332ab71672aa2bc6af257d2ec83",
"status": "affected",
"version": "cd22e73bdf5eff7e68a0f8bdfbce123ad43651f6",
"versionType": "git"
},
{
"lessThan": "b98e1e28bd95b0fa33164eec1e763d26c7058b39",
"status": "affected",
"version": "cd22e73bdf5eff7e68a0f8bdfbce123ad43651f6",
"versionType": "git"
},
{
"lessThan": "50f0c8dd8c3390f851cfb97ca13116f9ee6469d1",
"status": "affected",
"version": "cd22e73bdf5eff7e68a0f8bdfbce123ad43651f6",
"versionType": "git"
},
{
"lessThan": "f28066057134aa9294caa597b670daf505ad9dce",
"status": "affected",
"version": "cd22e73bdf5eff7e68a0f8bdfbce123ad43651f6",
"versionType": "git"
},
{
"lessThan": "40d2ffb74094cf36edbe05855566a4c58b6ce808",
"status": "affected",
"version": "cd22e73bdf5eff7e68a0f8bdfbce123ad43651f6",
"versionType": "git"
},
{
"lessThan": "f32c3a9a77cfb50934a60b05d5407649af062535",
"status": "affected",
"version": "cd22e73bdf5eff7e68a0f8bdfbce123ad43651f6",
"versionType": "git"
},
{
"lessThan": "d6764992f17b23d91ff93ce905ab53c2aa7191f0",
"status": "affected",
"version": "cd22e73bdf5eff7e68a0f8bdfbce123ad43651f6",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/thunderbolt/eeprom.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.17"
},
{
"lessThan": "3.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.17",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nthunderbolt: Bound the DROM dual link port number before indexing sw-\u003eports\n\ntb_drom_parse_entry_port() validates the device-supplied header-\u003eindex\nagainst sw-\u003econfig.max_port_number before indexing sw-\u003eports[], but the\nsibling field entry-\u003edual_link_port_nr -- a 6-bit value also read from\nthe DROM -- indexes the same array with no such check. A malicious or\nmalformed Thunderbolt device can set dual_link_port_nr beyond the\nallocated sw-\u003eports[] (max_port_number + 1 entries), producing an\nout-of-bounds tb_port pointer that is stored and later dereferenced.\n\nReject a port entry whose dual_link_port_nr exceeds max_port_number,\nthe same bound already applied to header-\u003eindex."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-22T15:31:38.339Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/6c892ed9f4129ae40ef0f92e1bb31aa0b0ddc72c"
},
{
"url": "https://git.kernel.org/stable/c/3d3c212b70633332ab71672aa2bc6af257d2ec83"
},
{
"url": "https://git.kernel.org/stable/c/b98e1e28bd95b0fa33164eec1e763d26c7058b39"
},
{
"url": "https://git.kernel.org/stable/c/50f0c8dd8c3390f851cfb97ca13116f9ee6469d1"
},
{
"url": "https://git.kernel.org/stable/c/f28066057134aa9294caa597b670daf505ad9dce"
},
{
"url": "https://git.kernel.org/stable/c/40d2ffb74094cf36edbe05855566a4c58b6ce808"
},
{
"url": "https://git.kernel.org/stable/c/f32c3a9a77cfb50934a60b05d5407649af062535"
},
{
"url": "https://git.kernel.org/stable/c/d6764992f17b23d91ff93ce905ab53c2aa7191f0"
}
],
"title": "thunderbolt: Bound the DROM dual link port number before indexing sw-\u003eports",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74585",
"datePublished": "2026-08-22T15:31:38.339Z",
"dateReserved": "2026-08-15T05:44:03.918Z",
"dateUpdated": "2026-08-22T15:31:38.339Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72110 (GCVE-0-2026-72110)
Vulnerability from cvelistv5
Published
2026-08-15 05:52
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
bpf,fork: wipe ->bpf_storage before bailouts that access it
Currently, copy_process() can bail out to free_task() before p->bpf_storage
has been initialized, with this call graph (shown here for the
!CONFIG_MEMCG case):
copy_process
dup_task_struct
arch_dup_task_struct
[copies the entire task_struct, including ->bpf_storage member]
[RLIMIT_NPROC check fails]
delayed_free_task
free_task
bpf_task_storage_free
rcu_dereference(task->bpf_storage)
bpf_local_storage_destroy
In this case, the nascent task's ->bpf_storage member that
bpf_local_storage_destroy() operates on is a plain copy of the parent's
->bpf_storage pointer, not a real initialized pointer.
This leads to badness (kernel hangs, UAF).
This is reachable as long as the process calling fork() has been inserted
into a task storage map.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: a10787e6d58c24b51e91c19c6d16c5da89fcaa4b Version: a10787e6d58c24b51e91c19c6d16c5da89fcaa4b Version: a10787e6d58c24b51e91c19c6d16c5da89fcaa4b Version: a10787e6d58c24b51e91c19c6d16c5da89fcaa4b Version: a10787e6d58c24b51e91c19c6d16c5da89fcaa4b Version: a10787e6d58c24b51e91c19c6d16c5da89fcaa4b Version: a10787e6d58c24b51e91c19c6d16c5da89fcaa4b |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"kernel/fork.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "7df67a4799067a59e6a2d53f8059a6be6e73e678",
"status": "affected",
"version": "a10787e6d58c24b51e91c19c6d16c5da89fcaa4b",
"versionType": "git"
},
{
"lessThan": "aff686efd38728e06daf12417a0d7ed454ce4cff",
"status": "affected",
"version": "a10787e6d58c24b51e91c19c6d16c5da89fcaa4b",
"versionType": "git"
},
{
"lessThan": "c3fd6f28c7ce1142a3b23dbb840eaa4777de1d74",
"status": "affected",
"version": "a10787e6d58c24b51e91c19c6d16c5da89fcaa4b",
"versionType": "git"
},
{
"lessThan": "9cff220ddb65b022cc668bb652200742476e744c",
"status": "affected",
"version": "a10787e6d58c24b51e91c19c6d16c5da89fcaa4b",
"versionType": "git"
},
{
"lessThan": "c4f626ddf2350652ad2f79daf1f10847f3f6eabd",
"status": "affected",
"version": "a10787e6d58c24b51e91c19c6d16c5da89fcaa4b",
"versionType": "git"
},
{
"lessThan": "43f0005f81b8ce3be962d653cde8db9022f1e9b0",
"status": "affected",
"version": "a10787e6d58c24b51e91c19c6d16c5da89fcaa4b",
"versionType": "git"
},
{
"lessThan": "9b51a6155d14389876916726430da30eabb1d4ed",
"status": "affected",
"version": "a10787e6d58c24b51e91c19c6d16c5da89fcaa4b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"kernel/fork.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.13"
},
{
"lessThan": "5.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf,fork: wipe -\u003ebpf_storage before bailouts that access it\n\nCurrently, copy_process() can bail out to free_task() before p-\u003ebpf_storage\nhas been initialized, with this call graph (shown here for the\n!CONFIG_MEMCG case):\n\ncopy_process\n dup_task_struct\n arch_dup_task_struct\n [copies the entire task_struct, including -\u003ebpf_storage member]\n [RLIMIT_NPROC check fails]\n delayed_free_task\n free_task\n bpf_task_storage_free\n rcu_dereference(task-\u003ebpf_storage)\n bpf_local_storage_destroy\n\nIn this case, the nascent task\u0027s -\u003ebpf_storage member that\nbpf_local_storage_destroy() operates on is a plain copy of the parent\u0027s\n-\u003ebpf_storage pointer, not a real initialized pointer.\nThis leads to badness (kernel hangs, UAF).\n\nThis is reachable as long as the process calling fork() has been inserted\ninto a task storage map."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached via fork()/clone()/clone3() into copy_process() and free_task()-\u003ebpf_task_storage_free(); per kernel guidance BPF/fork paths are Local and no network-facing handler can drive this early-bailout teardown.\nAC:L - The attacker controls all conditions: dup_task_struct copies parent -\u003ebpf_storage, then they can deterministically force early copy_process failure (setrlimit(RLIMIT_NPROC) plus fork, fork-until-EAGAIN, or nr_threads exhaustion) to hit bpf_local_storage_destroy on the copied pointer.\nPR:L - Exploitation needs only a local process already inserted into a BPF task storage map (sched_ext/tracing BPF on servers, or BPF loaded via user-namespace CAP_BPF/unprivileged BPF); fork itself needs no real-root capability, so PR:L per user-namespace guidance.\nUI:N - No victim action is required; the attacker triggers the failed fork on a process they run and control the bailout timing themselves.\nS:U - Impact is in-kernel UAF/heap corruption and denial of service on the parent task\u0027s BPF local storage; this is standard kernel memory corruption without VM, container, or IOMMU boundary crossing.\nC:H - Destroying the parent\u0027s live bpf_local_storage via the child\u0027s stale -\u003ebpf_storage pointer is a use-after-free; freed bpf_local_storage/bpf_local_storage_elem objects can be reclaimed for arbitrary kernel memory disclosure per UAF guidance.\nI:H - bpf_local_storage_destroy() unlinks and frees parent storage still referenced by the live forking task, enabling heap grooming and attacker-controlled writes over freed BPF local storage structures for privilege escalation.\nA:H - The fix commit reports kernel hangs and UAF; tearing down active BPF task local storage during failed fork can oops, panic, or deadlock the system, satisfying High availability impact for kernel crashes/UAF."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:50.580Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/7df67a4799067a59e6a2d53f8059a6be6e73e678"
},
{
"url": "https://git.kernel.org/stable/c/aff686efd38728e06daf12417a0d7ed454ce4cff"
},
{
"url": "https://git.kernel.org/stable/c/c3fd6f28c7ce1142a3b23dbb840eaa4777de1d74"
},
{
"url": "https://git.kernel.org/stable/c/9cff220ddb65b022cc668bb652200742476e744c"
},
{
"url": "https://git.kernel.org/stable/c/c4f626ddf2350652ad2f79daf1f10847f3f6eabd"
},
{
"url": "https://git.kernel.org/stable/c/43f0005f81b8ce3be962d653cde8db9022f1e9b0"
},
{
"url": "https://git.kernel.org/stable/c/9b51a6155d14389876916726430da30eabb1d4ed"
}
],
"title": "bpf,fork: wipe -\u003ebpf_storage before bailouts that access it",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72110",
"datePublished": "2026-08-15T05:52:51.805Z",
"dateReserved": "2026-08-09T03:40:39.906Z",
"dateUpdated": "2026-08-23T12:46:50.580Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80805 (GCVE-0-2026-80805)
Vulnerability from cvelistv5
Published
2026-09-04 15:13
Modified
2026-09-04 15:13
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
xfs: validate attr entry pointer before field access
xfs_attr3_leaf_verify_entry() accesses lentry/rentry fields (namelen,
valuelen) before checking if the entry pointer itself is within bounds.
If nameidx is crafted to point near the end of the buffer, these field
accesses can read out-of-bounds before the bounds check at
name_end > buf_end is performed.
Add explicit bounds checks for entry pointers before accessing their
fields. Use offsetof() to check that the start of the flexible array
member (nameval/name) is within bounds, which ensures all preceding
fields are safe to access.
References
| URL | Tags | ||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: c84760659dcf237902d4cc997cd5f55cb3b2807f Version: c84760659dcf237902d4cc997cd5f55cb3b2807f Version: c84760659dcf237902d4cc997cd5f55cb3b2807f Version: c84760659dcf237902d4cc997cd5f55cb3b2807f Version: c84760659dcf237902d4cc997cd5f55cb3b2807f Version: c84760659dcf237902d4cc997cd5f55cb3b2807f Version: c84760659dcf237902d4cc997cd5f55cb3b2807f Version: c84760659dcf237902d4cc997cd5f55cb3b2807f Version: c84760659dcf237902d4cc997cd5f55cb3b2807f |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/xfs/libxfs/xfs_attr_leaf.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "0f82586741e39926542f621bafa424e237a04fa4",
"status": "affected",
"version": "c84760659dcf237902d4cc997cd5f55cb3b2807f",
"versionType": "git"
},
{
"lessThan": "134d82a2b5e3eba3ebf58753a1387b22f26ca1de",
"status": "affected",
"version": "c84760659dcf237902d4cc997cd5f55cb3b2807f",
"versionType": "git"
},
{
"lessThan": "03a12253dd2a036545bdb0110a4e0b8dc70f8e7c",
"status": "affected",
"version": "c84760659dcf237902d4cc997cd5f55cb3b2807f",
"versionType": "git"
},
{
"lessThan": "e99120b5944a16d0bc27e52b33de78bcdaaabf5c",
"status": "affected",
"version": "c84760659dcf237902d4cc997cd5f55cb3b2807f",
"versionType": "git"
},
{
"lessThan": "98a42bb9d60d42898c3494de351a1bf508348cde",
"status": "affected",
"version": "c84760659dcf237902d4cc997cd5f55cb3b2807f",
"versionType": "git"
},
{
"lessThan": "184c1a80421a5b5ddcd262e47980ce2e67fee211",
"status": "affected",
"version": "c84760659dcf237902d4cc997cd5f55cb3b2807f",
"versionType": "git"
},
{
"lessThan": "9f92e749fc08b7ff3d9da190c4d1b2273745b282",
"status": "affected",
"version": "c84760659dcf237902d4cc997cd5f55cb3b2807f",
"versionType": "git"
},
{
"lessThan": "c35da2bac6f7cb9a9be73f188b4fcc324615c327",
"status": "affected",
"version": "c84760659dcf237902d4cc997cd5f55cb3b2807f",
"versionType": "git"
},
{
"lessThan": "b7eea80be25f3334f131d52982b3131aba77b97d",
"status": "affected",
"version": "c84760659dcf237902d4cc997cd5f55cb3b2807f",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/xfs/libxfs/xfs_attr_leaf.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.5"
},
{
"lessThan": "5.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.267",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.218",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.185",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.154",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.106",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.47",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.1",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.267",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.218",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.185",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.154",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.106",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.47",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.11",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.1",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "5.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nxfs: validate attr entry pointer before field access\n\nxfs_attr3_leaf_verify_entry() accesses lentry/rentry fields (namelen,\nvaluelen) before checking if the entry pointer itself is within bounds.\nIf nameidx is crafted to point near the end of the buffer, these field\naccesses can read out-of-bounds before the bounds check at\nname_end \u003e buf_end is performed.\n\nAdd explicit bounds checks for entry pointers before accessing their\nfields. Use offsetof() to check that the start of the flexible array\nmember (nameval/name) is within bounds, which ensures all preceding\nfields are safe to access."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T15:13:19.239Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/0f82586741e39926542f621bafa424e237a04fa4"
},
{
"url": "https://git.kernel.org/stable/c/134d82a2b5e3eba3ebf58753a1387b22f26ca1de"
},
{
"url": "https://git.kernel.org/stable/c/03a12253dd2a036545bdb0110a4e0b8dc70f8e7c"
},
{
"url": "https://git.kernel.org/stable/c/e99120b5944a16d0bc27e52b33de78bcdaaabf5c"
},
{
"url": "https://git.kernel.org/stable/c/98a42bb9d60d42898c3494de351a1bf508348cde"
},
{
"url": "https://git.kernel.org/stable/c/184c1a80421a5b5ddcd262e47980ce2e67fee211"
},
{
"url": "https://git.kernel.org/stable/c/9f92e749fc08b7ff3d9da190c4d1b2273745b282"
},
{
"url": "https://git.kernel.org/stable/c/c35da2bac6f7cb9a9be73f188b4fcc324615c327"
},
{
"url": "https://git.kernel.org/stable/c/b7eea80be25f3334f131d52982b3131aba77b97d"
}
],
"title": "xfs: validate attr entry pointer before field access",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80805",
"datePublished": "2026-09-04T15:13:19.239Z",
"dateReserved": "2026-08-26T14:34:25.794Z",
"dateUpdated": "2026-09-04T15:13:19.239Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74457 (GCVE-0-2026-74457)
Vulnerability from cvelistv5
Published
2026-08-15 12:26
Modified
2026-08-19 16:36
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
can: peak_usb: add bounds check for USB channel index
The channel control index ctrl_idx is derived from rx->len which comes
directly from a device USB payload. The mask 0x0f allows values 0-15, but
the array size of usb_if->dev[] is only 2. Values 2-15 cause heap
out-of-bounds read, eventually causing kernel panic in the IRQ context.
Add bounds checking for ctrl_idx before the array access in both
pcan_usb_pro_handle_canmsg() and pcan_usb_pro_handle_error().
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d8a199355f8f8a0797c00d98788d7282c9ea38bd Version: d8a199355f8f8a0797c00d98788d7282c9ea38bd Version: d8a199355f8f8a0797c00d98788d7282c9ea38bd Version: d8a199355f8f8a0797c00d98788d7282c9ea38bd Version: d8a199355f8f8a0797c00d98788d7282c9ea38bd Version: d8a199355f8f8a0797c00d98788d7282c9ea38bd Version: d8a199355f8f8a0797c00d98788d7282c9ea38bd Version: d8a199355f8f8a0797c00d98788d7282c9ea38bd |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/can/usb/peak_usb/pcan_usb_pro.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "18b1a868a2cda66fb438007ba47ce5f2484db381",
"status": "affected",
"version": "d8a199355f8f8a0797c00d98788d7282c9ea38bd",
"versionType": "git"
},
{
"lessThan": "0c9268457bd6e4058fe55b4db01b16661c2eacf5",
"status": "affected",
"version": "d8a199355f8f8a0797c00d98788d7282c9ea38bd",
"versionType": "git"
},
{
"lessThan": "94fb6fe83ce152532b11b36730b30f3dc0c94217",
"status": "affected",
"version": "d8a199355f8f8a0797c00d98788d7282c9ea38bd",
"versionType": "git"
},
{
"lessThan": "825c903ca3c98cd0cf0e3de8ab8f2604a5339b3f",
"status": "affected",
"version": "d8a199355f8f8a0797c00d98788d7282c9ea38bd",
"versionType": "git"
},
{
"lessThan": "f97b7e5e1cdaae15cd95b3a360028c7929664969",
"status": "affected",
"version": "d8a199355f8f8a0797c00d98788d7282c9ea38bd",
"versionType": "git"
},
{
"lessThan": "1acab790b7cecd4e144d1d18bdfe549e282f6b0b",
"status": "affected",
"version": "d8a199355f8f8a0797c00d98788d7282c9ea38bd",
"versionType": "git"
},
{
"lessThan": "0149fdb50a30944827acf9600a2cc44de0325a7f",
"status": "affected",
"version": "d8a199355f8f8a0797c00d98788d7282c9ea38bd",
"versionType": "git"
},
{
"lessThan": "39132f166ca8ce00ae60d8a9068e06a60943cc4b",
"status": "affected",
"version": "d8a199355f8f8a0797c00d98788d7282c9ea38bd",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/can/usb/peak_usb/pcan_usb_pro.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.4"
},
{
"lessThan": "3.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "3.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "3.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "3.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "3.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: peak_usb: add bounds check for USB channel index\n\nThe channel control index ctrl_idx is derived from rx-\u003elen which comes\ndirectly from a device USB payload. The mask 0x0f allows values 0-15, but\nthe array size of usb_if-\u003edev[] is only 2. Values 2-15 cause heap\nout-of-bounds read, eventually causing kernel panic in the IRQ context.\n\nAdd bounds checking for ctrl_idx before the array access in both\npcan_usb_pro_handle_canmsg() and pcan_usb_pro_handle_error()."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:36:52.931Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/18b1a868a2cda66fb438007ba47ce5f2484db381"
},
{
"url": "https://git.kernel.org/stable/c/0c9268457bd6e4058fe55b4db01b16661c2eacf5"
},
{
"url": "https://git.kernel.org/stable/c/94fb6fe83ce152532b11b36730b30f3dc0c94217"
},
{
"url": "https://git.kernel.org/stable/c/825c903ca3c98cd0cf0e3de8ab8f2604a5339b3f"
},
{
"url": "https://git.kernel.org/stable/c/f97b7e5e1cdaae15cd95b3a360028c7929664969"
},
{
"url": "https://git.kernel.org/stable/c/1acab790b7cecd4e144d1d18bdfe549e282f6b0b"
},
{
"url": "https://git.kernel.org/stable/c/0149fdb50a30944827acf9600a2cc44de0325a7f"
},
{
"url": "https://git.kernel.org/stable/c/39132f166ca8ce00ae60d8a9068e06a60943cc4b"
}
],
"title": "can: peak_usb: add bounds check for USB channel index",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74457",
"datePublished": "2026-08-15T12:26:59.411Z",
"dateReserved": "2026-08-15T05:44:03.900Z",
"dateUpdated": "2026-08-19T16:36:52.931Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2025-39925 (GCVE-0-2025-39925)
Vulnerability from cvelistv5
Published
2025-10-01 08:07
Modified
2026-09-02 12:49
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
can: j1939: implement NETDEV_UNREGISTER notification handler
syzbot is reporting
unregister_netdevice: waiting for vcan0 to become free. Usage count = 2
problem, for j1939 protocol did not have NETDEV_UNREGISTER notification
handler for undoing changes made by j1939_sk_bind().
Commit 25fe97cb7620 ("can: j1939: move j1939_priv_put() into sk_destruct
callback") expects that a call to j1939_priv_put() can be unconditionally
delayed until j1939_sk_sock_destruct() is called. But we need to call
j1939_priv_put() against an extra ref held by j1939_sk_bind() call
(as a part of undoing changes made by j1939_sk_bind()) as soon as
NETDEV_UNREGISTER notification fires (i.e. before j1939_sk_sock_destruct()
is called via j1939_sk_release()). Otherwise, the extra ref on "struct
j1939_priv" held by j1939_sk_bind() call prevents "struct net_device" from
dropping the usage count to 1; making it impossible for
unregister_netdevice() to continue.
[mkl: remove space in front of label]
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 9d71dd0c70099914fcd063135da3c580865e924c Version: 9d71dd0c70099914fcd063135da3c580865e924c Version: 9d71dd0c70099914fcd063135da3c580865e924c Version: 9d71dd0c70099914fcd063135da3c580865e924c Version: 9d71dd0c70099914fcd063135da3c580865e924c Version: 9d71dd0c70099914fcd063135da3c580865e924c |
||
{
"containers": {
"adp": [
{
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 5.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
}
},
{
"other": {
"content": {
"id": "CVE-2025-39925",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-01-14T17:39:05.628974Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "CWE-noinfo Not enough information",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-01-14T17:42:45.107Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/can/j1939/j1939-priv.h",
"net/can/j1939/main.c",
"net/can/j1939/socket.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "479d8a2aedcc1db16f14c1a8a9c74b5bdf18b9ac",
"status": "affected",
"version": "9d71dd0c70099914fcd063135da3c580865e924c",
"versionType": "git"
},
{
"lessThan": "2c88069fac2c792e228e6a4ae71c9b9b5b9a87a6",
"status": "affected",
"version": "9d71dd0c70099914fcd063135da3c580865e924c",
"versionType": "git"
},
{
"lessThan": "76957b618ce729c3bd1e782fbc9d9991af653925",
"status": "affected",
"version": "9d71dd0c70099914fcd063135da3c580865e924c",
"versionType": "git"
},
{
"lessThan": "4e154cb5e7681c2910e2dfa09f05e3469e333745",
"status": "affected",
"version": "9d71dd0c70099914fcd063135da3c580865e924c",
"versionType": "git"
},
{
"lessThan": "da9e8f429139928570407e8f90559b5d46c20262",
"status": "affected",
"version": "9d71dd0c70099914fcd063135da3c580865e924c",
"versionType": "git"
},
{
"lessThan": "7fcbe5b2c6a4b5407bf2241fdb71e0a390f6ab9a",
"status": "affected",
"version": "9d71dd0c70099914fcd063135da3c580865e924c",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/can/j1939/j1939-priv.h",
"net/can/j1939/main.c",
"net/can/j1939/socket.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.4"
},
{
"lessThan": "5.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.220",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.187",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.156",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.108",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.16.*",
"status": "unaffected",
"version": "6.16.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "6.17",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.220",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.187",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.156",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.108",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.16.8",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.17",
"versionStartIncluding": "5.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: j1939: implement NETDEV_UNREGISTER notification handler\n\nsyzbot is reporting\n\n unregister_netdevice: waiting for vcan0 to become free. Usage count = 2\n\nproblem, for j1939 protocol did not have NETDEV_UNREGISTER notification\nhandler for undoing changes made by j1939_sk_bind().\n\nCommit 25fe97cb7620 (\"can: j1939: move j1939_priv_put() into sk_destruct\ncallback\") expects that a call to j1939_priv_put() can be unconditionally\ndelayed until j1939_sk_sock_destruct() is called. But we need to call\nj1939_priv_put() against an extra ref held by j1939_sk_bind() call\n(as a part of undoing changes made by j1939_sk_bind()) as soon as\nNETDEV_UNREGISTER notification fires (i.e. before j1939_sk_sock_destruct()\nis called via j1939_sk_release()). Otherwise, the extra ref on \"struct\nj1939_priv\" held by j1939_sk_bind() call prevents \"struct net_device\" from\ndropping the usage count to 1; making it impossible for\nunregister_netdevice() to continue.\n\n[mkl: remove space in front of label]"
}
],
"providerMetadata": {
"dateUpdated": "2026-09-02T12:49:23.677Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/479d8a2aedcc1db16f14c1a8a9c74b5bdf18b9ac"
},
{
"url": "https://git.kernel.org/stable/c/2c88069fac2c792e228e6a4ae71c9b9b5b9a87a6"
},
{
"url": "https://git.kernel.org/stable/c/76957b618ce729c3bd1e782fbc9d9991af653925"
},
{
"url": "https://git.kernel.org/stable/c/4e154cb5e7681c2910e2dfa09f05e3469e333745"
},
{
"url": "https://git.kernel.org/stable/c/da9e8f429139928570407e8f90559b5d46c20262"
},
{
"url": "https://git.kernel.org/stable/c/7fcbe5b2c6a4b5407bf2241fdb71e0a390f6ab9a"
}
],
"title": "can: j1939: implement NETDEV_UNREGISTER notification handler",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2025-39925",
"datePublished": "2025-10-01T08:07:13.123Z",
"dateReserved": "2025-04-16T07:20:57.147Z",
"dateUpdated": "2026-09-02T12:49:23.677Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74507 (GCVE-0-2026-74507)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-19 16:38
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: HIDP: validate numbered report payloads
When hidp_get_raw_report() waits for a numbered report,
hidp_process_data() compares the expected report number with skb->data[0].
A connected HIDP peer can reply with only a DATA transaction header,
leaving the skb empty after the header is removed.
KMSAN reports an uninitialized-value use in hidp_session_run(), with the
value originating in __alloc_skb() through vhci_write(). The transaction
header checks remove the empty-frame reports, but this report remains until
the payload check is added.
The comparison can also consume a peer-controlled byte beyond the declared
L2CAP PDU. A DATA | FEATURE response followed by an extra 0x01 byte made
the current code accept that byte as report ID 1 and complete
HIDIOCGFEATURE with a zero-byte result. With this change the malformed
response is rejected with -EIO, while a subsequent valid response still
succeeds.
Require a payload byte before comparing a numbered report ID. Unnumbered
reports continue to accept an empty payload.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 0ff1731a1ae51e8e48cd559d70db536281c47f8e Version: 0ff1731a1ae51e8e48cd559d70db536281c47f8e Version: 0ff1731a1ae51e8e48cd559d70db536281c47f8e Version: 0ff1731a1ae51e8e48cd559d70db536281c47f8e Version: 0ff1731a1ae51e8e48cd559d70db536281c47f8e Version: 0ff1731a1ae51e8e48cd559d70db536281c47f8e Version: 0ff1731a1ae51e8e48cd559d70db536281c47f8e Version: 0ff1731a1ae51e8e48cd559d70db536281c47f8e |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/bluetooth/hidp/core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "011bf4350d941f1995b2bd4b815ee206cacf2b8e",
"status": "affected",
"version": "0ff1731a1ae51e8e48cd559d70db536281c47f8e",
"versionType": "git"
},
{
"lessThan": "689d8bb7fee96b7196b572b015b6055c6616ce0c",
"status": "affected",
"version": "0ff1731a1ae51e8e48cd559d70db536281c47f8e",
"versionType": "git"
},
{
"lessThan": "c73beb320f5705e508bf7d385b8cc5ef8d9c8b69",
"status": "affected",
"version": "0ff1731a1ae51e8e48cd559d70db536281c47f8e",
"versionType": "git"
},
{
"lessThan": "b7ad105d46acd828e424454815e4cd31069e047a",
"status": "affected",
"version": "0ff1731a1ae51e8e48cd559d70db536281c47f8e",
"versionType": "git"
},
{
"lessThan": "7e7162427659b70ea17cd41b1f79e2e64c246690",
"status": "affected",
"version": "0ff1731a1ae51e8e48cd559d70db536281c47f8e",
"versionType": "git"
},
{
"lessThan": "27cc0e603355c585f1e5da8398faa4d36d498188",
"status": "affected",
"version": "0ff1731a1ae51e8e48cd559d70db536281c47f8e",
"versionType": "git"
},
{
"lessThan": "9c841f59e10b5d75c398a3fc6b2da448d2a2276b",
"status": "affected",
"version": "0ff1731a1ae51e8e48cd559d70db536281c47f8e",
"versionType": "git"
},
{
"lessThan": "34f53d27b81a16a02828c8fdfa4e02badc326f17",
"status": "affected",
"version": "0ff1731a1ae51e8e48cd559d70db536281c47f8e",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/bluetooth/hidp/core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.39"
},
{
"lessThan": "2.6.39",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.39",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.39",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.39",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "2.6.39",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "2.6.39",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "2.6.39",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "2.6.39",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.39",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: HIDP: validate numbered report payloads\n\nWhen hidp_get_raw_report() waits for a numbered report,\nhidp_process_data() compares the expected report number with skb-\u003edata[0].\nA connected HIDP peer can reply with only a DATA transaction header,\nleaving the skb empty after the header is removed.\n\nKMSAN reports an uninitialized-value use in hidp_session_run(), with the\nvalue originating in __alloc_skb() through vhci_write(). The transaction\nheader checks remove the empty-frame reports, but this report remains until\nthe payload check is added.\n\nThe comparison can also consume a peer-controlled byte beyond the declared\nL2CAP PDU. A DATA | FEATURE response followed by an extra 0x01 byte made\nthe current code accept that byte as report ID 1 and complete\nHIDIOCGFEATURE with a zero-byte result. With this change the malformed\nresponse is rejected with -EIO, while a subsequent valid response still\nsucceeds.\n\nRequire a payload byte before comparing a numbered report ID. Unnumbered\nreports continue to accept an empty payload."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The flaw is reached when a connected Bluetooth HIDP peer sends crafted DATA frames over the established L2CAP control channel; Bluetooth is an adjacent wireless vector, not local syscall/ioctl or physical USB access.\nAC:L - The malicious peer receives the host GET_REPORT and can deterministically reply with a header-only DATA frame or a malformed numbered-report payload; no race or rare layout conditions beyond an active HIDP session are required.\nPR:N - Exploitation is performed by the remote Bluetooth HIDP peer sending malicious protocol data; the attacker needs no local account, capabilities, or init-namespace root on the victim host.\nUI:N - Once a HIDP session exists, the peer can trigger the bug by answering host-initiated GET_REPORT requests from HIDIOCGFEATURE or kernel HID probe I/O without any additional victim action at exploit time.\nS:U - Impact is confined to kernel Bluetooth HIDP/hidraw handling on the victim host; it does not cross a VM, container, or IOMMU security boundary to affect a separate authority.\nC:H - With numbered reports, hidp_process_data() reads skb-\u003edata[0] when skb-\u003elen is zero or beyond the declared L2CAP PDU, causing an out-of-bounds/uninitialized heap read that may contain stale kernel memory.\nI:L - Accepting malformed numbered-report responses can complete HIDIOCGFEATURE with incorrect zero-length or attacker-chosen report-ID data, causing limited integrity impact on returned HID feature-report contents.\nA:N - The defect is an invalid payload-length check and uninitialized/OOB read during report matching; it does not cause a documented kernel oops, panic, hang, or repeatable denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:38:05.065Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/011bf4350d941f1995b2bd4b815ee206cacf2b8e"
},
{
"url": "https://git.kernel.org/stable/c/689d8bb7fee96b7196b572b015b6055c6616ce0c"
},
{
"url": "https://git.kernel.org/stable/c/c73beb320f5705e508bf7d385b8cc5ef8d9c8b69"
},
{
"url": "https://git.kernel.org/stable/c/b7ad105d46acd828e424454815e4cd31069e047a"
},
{
"url": "https://git.kernel.org/stable/c/7e7162427659b70ea17cd41b1f79e2e64c246690"
},
{
"url": "https://git.kernel.org/stable/c/27cc0e603355c585f1e5da8398faa4d36d498188"
},
{
"url": "https://git.kernel.org/stable/c/9c841f59e10b5d75c398a3fc6b2da448d2a2276b"
},
{
"url": "https://git.kernel.org/stable/c/34f53d27b81a16a02828c8fdfa4e02badc326f17"
}
],
"title": "Bluetooth: HIDP: validate numbered report payloads",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74507",
"datePublished": "2026-08-15T12:27:30.683Z",
"dateReserved": "2026-08-15T05:44:03.908Z",
"dateUpdated": "2026-08-19T16:38:05.065Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74575 (GCVE-0-2026-74575)
Vulnerability from cvelistv5
Published
2026-08-15 12:28
Modified
2026-08-23 12:47
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
thunderbolt: Prevent XDomain delayed work use-after-free on disconnect
tb_xdp_handle_request() runs on system_wq and queues
xd->state_work via queue_delayed_work() in three request handlers:
PROPERTIES_CHANGED_REQUEST, UUID_REQUEST (via start_handshake),
and LINK_STATE_CHANGE_REQUEST. Similarly, update_xdomain() queues
xd->properties_changed_work when local properties change.
Concurrently, tb_xdomain_remove() calls stop_handshake() which does
cancel_delayed_work_sync() on both delayed works. Later,
tb_xdomain_unregister() calls device_unregister() which eventually
frees the xdomain. Since commit 559c1e1e0134 ("thunderbolt: Run
tb_xdp_handle_request() in system workqueue") moved the request
handler off tb->wq, the handler and the remove path are no longer
serialized. If queue_delayed_work() executes after
cancel_delayed_work_sync() but before the xdomain is freed, the
delayed work fires on a freed object.
Add xd->removing that tb_xdomain_remove() sets under xd->lock
before calling stop_handshake(). Each external queue site holds
the same lock and checks removing before calling
queue_delayed_work(). This provides the mutual exclusion needed:
either the queue site acquires the lock first and queues work that
the subsequent cancel will see, or the remove path acquires the
lock first and the queue site observes removing == true and skips
the queue.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 559c1e1e013437bf190469efbcbd8bc803285853 Version: 559c1e1e013437bf190469efbcbd8bc803285853 Version: 559c1e1e013437bf190469efbcbd8bc803285853 Version: 559c1e1e013437bf190469efbcbd8bc803285853 Version: 559c1e1e013437bf190469efbcbd8bc803285853 Version: 559c1e1e013437bf190469efbcbd8bc803285853 Version: 559c1e1e013437bf190469efbcbd8bc803285853 Version: 559c1e1e013437bf190469efbcbd8bc803285853 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/thunderbolt/xdomain.c",
"include/linux/thunderbolt.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "d4fa0d544c04dea636bf821ff5582cd7d63e2c34",
"status": "affected",
"version": "559c1e1e013437bf190469efbcbd8bc803285853",
"versionType": "git"
},
{
"lessThan": "cfbd2dba3d862c9be8c92bea2a357d9ed828a54a",
"status": "affected",
"version": "559c1e1e013437bf190469efbcbd8bc803285853",
"versionType": "git"
},
{
"lessThan": "dc11d5118f9da6ea28487ffe055de5a0d0734125",
"status": "affected",
"version": "559c1e1e013437bf190469efbcbd8bc803285853",
"versionType": "git"
},
{
"lessThan": "91b40862a02000f490b63f1d315be3ee31e83871",
"status": "affected",
"version": "559c1e1e013437bf190469efbcbd8bc803285853",
"versionType": "git"
},
{
"lessThan": "33c0ee18cf8665c974b00f4e0ba769fbc07efe10",
"status": "affected",
"version": "559c1e1e013437bf190469efbcbd8bc803285853",
"versionType": "git"
},
{
"lessThan": "54a62153c765cd24239cde1f2633f2a2fd005368",
"status": "affected",
"version": "559c1e1e013437bf190469efbcbd8bc803285853",
"versionType": "git"
},
{
"lessThan": "2aa2cde2cc79a79d8ea4a15be9f4a67fc528ae91",
"status": "affected",
"version": "559c1e1e013437bf190469efbcbd8bc803285853",
"versionType": "git"
},
{
"lessThan": "2c5d2d3c3f70cde2565d7b279b544893a2035842",
"status": "affected",
"version": "559c1e1e013437bf190469efbcbd8bc803285853",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/thunderbolt/xdomain.c",
"include/linux/thunderbolt.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.2"
},
{
"lessThan": "5.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nthunderbolt: Prevent XDomain delayed work use-after-free on disconnect\n\ntb_xdp_handle_request() runs on system_wq and queues\nxd-\u003estate_work via queue_delayed_work() in three request handlers:\nPROPERTIES_CHANGED_REQUEST, UUID_REQUEST (via start_handshake),\nand LINK_STATE_CHANGE_REQUEST. Similarly, update_xdomain() queues\nxd-\u003eproperties_changed_work when local properties change.\n\nConcurrently, tb_xdomain_remove() calls stop_handshake() which does\ncancel_delayed_work_sync() on both delayed works. Later,\ntb_xdomain_unregister() calls device_unregister() which eventually\nfrees the xdomain. Since commit 559c1e1e0134 (\"thunderbolt: Run\ntb_xdp_handle_request() in system workqueue\") moved the request\nhandler off tb-\u003ewq, the handler and the remove path are no longer\nserialized. If queue_delayed_work() executes after\ncancel_delayed_work_sync() but before the xdomain is freed, the\ndelayed work fires on a freed object.\n\nAdd xd-\u003eremoving that tb_xdomain_remove() sets under xd-\u003elock\nbefore calling stop_handshake(). Each external queue site holds\nthe same lock and checks removing before calling\nqueue_delayed_work(). This provides the mutual exclusion needed:\neither the queue site acquires the lock first and queues work that\nthe subsequent cancel will see, or the remove path acquires the\nlock first and the queue site observes removing == true and skips\nthe queue."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - XDomain discovery packets reach the kernel over the Thunderbolt/USB4 control channel from a connected peer (adjacent host, dock, or inline device) on the shared physical link; no remote IP/network service is involved, but the attacker need not touch the victim chassis if they control the far end of an established TB connection.\nAC:L - The bug is a race between system_wq request handling and disconnect teardown; the peer attacker controls both sides by sending PROPERTIES_CHANGED, UUID, or LINK_STATE_CHANGE requests while forcing unplug/disconnect and can retry timing until delayed work is queued after cancel_delayed_work_sync().\nPR:N - No local account, capability, or root on the victim is required; any malicious or compromised Thunderbolt XDomain peer that can exchange discovery control-plane packets can trigger the vulnerable queue_delayed_work() paths without OS authentication.\nUI:N - During an active XDomain session the peer can send the triggering requests and force link teardown without any further victim action at exploit time; no additional mount, login, or sysfs operation is needed beyond the already-established Thunderbolt link.\nS:U - Impact is kernel heap use-after-free and memory corruption within kernel context; it does not directly cross VM, container, or IOMMU boundaries, though successful exploitation can yield standard local privilege escalation.\nC:H - Use-after-free on struct tb_xdomain lets attacker-influenced delayed work read freed kernel memory, enabling arbitrary kernel information disclosure and kernel pointer leaks that support further exploitation of the corruption primitive.\nI:H - Delayed work on the freed xdomain executes handshake state transitions, property/link updates, and hardware operations on attacker-reclaimed memory, enabling heap grooming and control-flow hijack for arbitrary kernel write/code execution.\nA:H - Accessing freed tb_xdomain via state_work or properties_changed_work causes kernel oops/panic or hang during disconnect, and a peer can repeat disconnect/request storms to deny Thunderbolt/XDomain services."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:47:35.374Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/d4fa0d544c04dea636bf821ff5582cd7d63e2c34"
},
{
"url": "https://git.kernel.org/stable/c/cfbd2dba3d862c9be8c92bea2a357d9ed828a54a"
},
{
"url": "https://git.kernel.org/stable/c/dc11d5118f9da6ea28487ffe055de5a0d0734125"
},
{
"url": "https://git.kernel.org/stable/c/91b40862a02000f490b63f1d315be3ee31e83871"
},
{
"url": "https://git.kernel.org/stable/c/33c0ee18cf8665c974b00f4e0ba769fbc07efe10"
},
{
"url": "https://git.kernel.org/stable/c/54a62153c765cd24239cde1f2633f2a2fd005368"
},
{
"url": "https://git.kernel.org/stable/c/2aa2cde2cc79a79d8ea4a15be9f4a67fc528ae91"
},
{
"url": "https://git.kernel.org/stable/c/2c5d2d3c3f70cde2565d7b279b544893a2035842"
}
],
"title": "thunderbolt: Prevent XDomain delayed work use-after-free on disconnect",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74575",
"datePublished": "2026-08-15T12:28:13.187Z",
"dateReserved": "2026-08-15T05:44:03.917Z",
"dateUpdated": "2026-08-23T12:47:35.374Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68234 (GCVE-0-2026-68234)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: fix bo->pin leaking in amdgpu_bo_create_reserved
amdgpu_bo_create_reserved() only allocates a new BO when
*bo_ptr (struct amdgpu_bo **bo_ptr as input parameter) is
NULL, it simply skips creation when *bo_ptr is non-NULL.
But it unconditionally reserves, pins, gart allocates
and maps the BO afterwards.
When the same non-NULL BO pointer is passed in again,
for example firmware buffers that live in adev and are
re-loaded on every resume / cp_resume / start
under AMDGPU_FW_LOAD_DIRECT, amdgpu_bo_pin() just increases
pin_count unconditionally, however the matching teardown only unpins
once, so pin_count never drops to zero, so TTM is not able
to move, swap or evict a BO, causing BO leaks.
This commit fixes this issue by only pinning the bo
once at creation, and repeated calls no longer
take additional pin references.
(cherry picked from commit 3ddc0ae76202c447b6aec61e907b852bc94671cf)
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 53766e5adac75872e9d413cdbfd0e47ae40701f9 Version: 53766e5adac75872e9d413cdbfd0e47ae40701f9 Version: 53766e5adac75872e9d413cdbfd0e47ae40701f9 Version: 53766e5adac75872e9d413cdbfd0e47ae40701f9 Version: 53766e5adac75872e9d413cdbfd0e47ae40701f9 Version: 53766e5adac75872e9d413cdbfd0e47ae40701f9 Version: 53766e5adac75872e9d413cdbfd0e47ae40701f9 Version: 53766e5adac75872e9d413cdbfd0e47ae40701f9 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/amdgpu_object.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "7aea619d9f186dcf0f1289879e9edb69d2b56639",
"status": "affected",
"version": "53766e5adac75872e9d413cdbfd0e47ae40701f9",
"versionType": "git"
},
{
"lessThan": "b572d0814c1366701ca704286589fab025802566",
"status": "affected",
"version": "53766e5adac75872e9d413cdbfd0e47ae40701f9",
"versionType": "git"
},
{
"lessThan": "e06e0885725a16304b7723aeb478a78cca9dc96a",
"status": "affected",
"version": "53766e5adac75872e9d413cdbfd0e47ae40701f9",
"versionType": "git"
},
{
"lessThan": "51eeef1949c11d3dcb5f422a5d9b3f09ebe8a1bc",
"status": "affected",
"version": "53766e5adac75872e9d413cdbfd0e47ae40701f9",
"versionType": "git"
},
{
"lessThan": "2f390b4c83011452753fd84972f657d2b00a952b",
"status": "affected",
"version": "53766e5adac75872e9d413cdbfd0e47ae40701f9",
"versionType": "git"
},
{
"lessThan": "ba7b6444097a73ccd3d3ac9e2be4ebb73d226460",
"status": "affected",
"version": "53766e5adac75872e9d413cdbfd0e47ae40701f9",
"versionType": "git"
},
{
"lessThan": "9743f60013273987abf415dc47474683d22aaee9",
"status": "affected",
"version": "53766e5adac75872e9d413cdbfd0e47ae40701f9",
"versionType": "git"
},
{
"lessThan": "a2f895f3c852063258d62e9f74b081de07ca95df",
"status": "affected",
"version": "53766e5adac75872e9d413cdbfd0e47ae40701f9",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/amdgpu_object.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.14"
},
{
"lessThan": "4.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: fix bo-\u003epin leaking in amdgpu_bo_create_reserved\n\namdgpu_bo_create_reserved() only allocates a new BO when\n*bo_ptr (struct amdgpu_bo **bo_ptr as input parameter) is\nNULL, it simply skips creation when *bo_ptr is non-NULL.\nBut it unconditionally reserves, pins, gart allocates\nand maps the BO afterwards.\n\nWhen the same non-NULL BO pointer is passed in again,\nfor example firmware buffers that live in adev and are\nre-loaded on every resume / cp_resume / start\nunder AMDGPU_FW_LOAD_DIRECT, amdgpu_bo_pin() just increases\npin_count unconditionally, however the matching teardown only unpins\nonce, so pin_count never drops to zero, so TTM is not able\nto move, swap or evict a BO, causing BO leaks.\n\nThis commit fixes this issue by only pinning the bo\nonce at creation, and repeated calls no longer\ntake additional pin references.\n\n(cherry picked from commit 3ddc0ae76202c447b6aec61e907b852bc94671cf)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:32:06.457Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/7aea619d9f186dcf0f1289879e9edb69d2b56639"
},
{
"url": "https://git.kernel.org/stable/c/b572d0814c1366701ca704286589fab025802566"
},
{
"url": "https://git.kernel.org/stable/c/e06e0885725a16304b7723aeb478a78cca9dc96a"
},
{
"url": "https://git.kernel.org/stable/c/51eeef1949c11d3dcb5f422a5d9b3f09ebe8a1bc"
},
{
"url": "https://git.kernel.org/stable/c/2f390b4c83011452753fd84972f657d2b00a952b"
},
{
"url": "https://git.kernel.org/stable/c/ba7b6444097a73ccd3d3ac9e2be4ebb73d226460"
},
{
"url": "https://git.kernel.org/stable/c/9743f60013273987abf415dc47474683d22aaee9"
},
{
"url": "https://git.kernel.org/stable/c/a2f895f3c852063258d62e9f74b081de07ca95df"
}
],
"title": "drm/amdgpu: fix bo-\u003epin leaking in amdgpu_bo_create_reserved",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68234",
"datePublished": "2026-08-10T12:00:59.074Z",
"dateReserved": "2026-07-30T09:28:09.376Z",
"dateUpdated": "2026-08-19T16:32:06.457Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74470 (GCVE-0-2026-74470)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-23 12:47
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write
resp_report_zones() sizes the reply buffer from the CDB allocation
length. The v3 fix rounds alloc_len up with ALIGN() before deriving the
descriptor count:
rep_max_zones = (ALIGN((u64)alloc_len, RZONES_DESC_HD) -
RZONES_DESC_HD) >> ilog2(RZONES_DESC_HD);
arr_len = (u64)RZONES_DESC_HD * (rep_max_zones + 1);
For alloc_len in 0xFFFFFFC1..0xFFFFFFFF, ALIGN() rounds up to
0x100000000, so arr_len is 4 GB. On 32-bit, kzalloc()'s size_t is 32-bit
and truncates 0x100000000 to 0; kzalloc(0) returns ZERO_SIZE_PTR, which
passes the !arr check, and desc = arr + 64 is then dereferenced in the
loop -> out-of-bounds write / panic.
Clamp rep_max_zones to devip->nr_zones. The loop already stops at
sdebug_capacity (after nr_zones zones), so a report can never hold more
than nr_zones descriptors; the clamp does not change the report, it only
bounds arr_len to (nr_zones + 1) * RZONES_DESC_HD, a real device
property that can never reach 0x100000000.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ebacb44cb2042b90951140eda806bedad23ef554 Version: 7db0e0c8190a086ef92ce5bb960836cde49540aa Version: 7db0e0c8190a086ef92ce5bb960836cde49540aa Version: 7db0e0c8190a086ef92ce5bb960836cde49540aa Version: 7db0e0c8190a086ef92ce5bb960836cde49540aa Version: 7db0e0c8190a086ef92ce5bb960836cde49540aa Version: 7db0e0c8190a086ef92ce5bb960836cde49540aa Version: c4d2d7c935a4ad20e8e726ca10499cefe4537103 Version: 5.15.8 ≤ Version: 5.10.85 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/scsi/scsi_debug.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "7b615fc139e35c81077046df44725c532f7e2404",
"status": "affected",
"version": "ebacb44cb2042b90951140eda806bedad23ef554",
"versionType": "git"
},
{
"lessThan": "5d3e1d006bbb543259f9e31824caadbfff6a5465",
"status": "affected",
"version": "7db0e0c8190a086ef92ce5bb960836cde49540aa",
"versionType": "git"
},
{
"lessThan": "49e5b25a0b74dbac595f122e5608fdce2918cc4e",
"status": "affected",
"version": "7db0e0c8190a086ef92ce5bb960836cde49540aa",
"versionType": "git"
},
{
"lessThan": "495058429ca55ab7fcc21977b63b92907ad68066",
"status": "affected",
"version": "7db0e0c8190a086ef92ce5bb960836cde49540aa",
"versionType": "git"
},
{
"lessThan": "2047ed09bf13453b7d6f9431b112ec07984dd69b",
"status": "affected",
"version": "7db0e0c8190a086ef92ce5bb960836cde49540aa",
"versionType": "git"
},
{
"lessThan": "d6e6da6bc3b53231fac77ffab428da8173ee729c",
"status": "affected",
"version": "7db0e0c8190a086ef92ce5bb960836cde49540aa",
"versionType": "git"
},
{
"lessThan": "93dde0bf2f39a0f9f57fd610aa3201ce5b753433",
"status": "affected",
"version": "7db0e0c8190a086ef92ce5bb960836cde49540aa",
"versionType": "git"
},
{
"status": "affected",
"version": "c4d2d7c935a4ad20e8e726ca10499cefe4537103",
"versionType": "git"
},
{
"lessThan": "5.15.217",
"status": "affected",
"version": "5.15.8",
"versionType": "semver"
},
{
"lessThan": "5.11",
"status": "affected",
"version": "5.10.85",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/scsi/scsi_debug.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.16"
},
{
"lessThan": "5.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.15.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.10.85",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write\n\nresp_report_zones() sizes the reply buffer from the CDB allocation\nlength. The v3 fix rounds alloc_len up with ALIGN() before deriving the\ndescriptor count:\n\n\trep_max_zones = (ALIGN((u64)alloc_len, RZONES_DESC_HD) -\n\t\t\t RZONES_DESC_HD) \u003e\u003e ilog2(RZONES_DESC_HD);\n\tarr_len = (u64)RZONES_DESC_HD * (rep_max_zones + 1);\n\nFor alloc_len in 0xFFFFFFC1..0xFFFFFFFF, ALIGN() rounds up to\n0x100000000, so arr_len is 4 GB. On 32-bit, kzalloc()\u0027s size_t is 32-bit\nand truncates 0x100000000 to 0; kzalloc(0) returns ZERO_SIZE_PTR, which\npasses the !arr check, and desc = arr + 64 is then dereferenced in the\nloop -\u003e out-of-bounds write / panic.\n\nClamp rep_max_zones to devip-\u003enr_zones. The loop already stops at\nsdebug_capacity (after nr_zones zones), so a report can never hold more\nthan nr_zones descriptors; the clamp does not change the report, it only\nbounds arr_len to (nr_zones + 1) * RZONES_DESC_HD, a real device\nproperty that can never reach 0x100000000."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached by sending a crafted ZONE IN REPORT ZONES SCSI CDB through local SG_IO/BSG ioctl on a scsi_debug zoned LUN; scsi_debug is a pseudo host simulator with no native network protocol handler.\nAC:L - Once scsi_debug is loaded in host-managed zoned mode, a single REPORT ZONES command with ALLOCATION LENGTH 1-63 reliably underflows rep_max_zones and forces heap writes past a tiny kzalloc buffer; no races or victim-dependent timing are required.\nPR:L - ZBC_IN is whitelisted in scsi_cmd_allowed() without CAP_SYS_RAWIO, so any local user who can open the scsi_debug /dev/sg or BSG node (e.g., disk group) can issue the malicious CDB; module load and zoned setup are environmental, not exploit-time privileges.\nUI:N - Exploitation requires only the attacker issuing SG_IO/BSG with a malicious REPORT ZONES CDB; no separate victim interaction such as mounting media or clicking a prompt is needed.\nS:U - The out-of-bounds write corrupts kernel heap memory in the same host kernel security authority; it is not a VM escape, IOMMU bypass, or other cross-boundary compromise.\nC:H - The kmalloc heap out-of-bounds write can corrupt adjacent slab objects and be groomed into arbitrary kernel memory disclosure primitives; per kernel guidance, exploitable out-of-bounds writes warrant High confidentiality impact.\nI:H - Attacker-controlled REPORT ZONES allocation length drives rep_max_zones and causes repeated 64-byte descriptor writes far beyond the allocated buffer, providing a kernel heap out-of-bounds write suitable for control-data corruption and privilege escalation.\nA:H - Writing zone descriptors from arr+64 when the buffer is smaller than 64 bytes immediately corrupts out-of-bounds kernel memory and commonly triggers KASAN faults, kernel oops, or panic, satisfying High availability impact."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:47:20.125Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/7b615fc139e35c81077046df44725c532f7e2404"
},
{
"url": "https://git.kernel.org/stable/c/5d3e1d006bbb543259f9e31824caadbfff6a5465"
},
{
"url": "https://git.kernel.org/stable/c/49e5b25a0b74dbac595f122e5608fdce2918cc4e"
},
{
"url": "https://git.kernel.org/stable/c/495058429ca55ab7fcc21977b63b92907ad68066"
},
{
"url": "https://git.kernel.org/stable/c/2047ed09bf13453b7d6f9431b112ec07984dd69b"
},
{
"url": "https://git.kernel.org/stable/c/d6e6da6bc3b53231fac77ffab428da8173ee729c"
},
{
"url": "https://git.kernel.org/stable/c/93dde0bf2f39a0f9f57fd610aa3201ce5b753433"
}
],
"title": "scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74470",
"datePublished": "2026-08-15T12:27:07.504Z",
"dateReserved": "2026-08-15T05:44:03.902Z",
"dateUpdated": "2026-08-23T12:47:20.125Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72146 (GCVE-0-2026-72146)
Vulnerability from cvelistv5
Published
2026-08-15 05:53
Modified
2026-08-19 16:36
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
dmaengine: sh: rz-dmac: Move interrupt request after everything is set up
Once the interrupt is requested, the interrupt handler may run immediately.
Since the IRQ handler can access channel->ch_base, which is initialized
only after requesting the IRQ, this may lead to invalid memory access.
Likewise, the IRQ thread may access uninitialized data (the ld_free,
ld_queue, and ld_active lists), which may also lead to issues.
Request the interrupts only after everything is set up. To keep the error
path simpler, use dmam_alloc_coherent() instead of dma_alloc_coherent().
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 5000d37042a61ca556fde2782ca40dbfa802ea16 Version: 5000d37042a61ca556fde2782ca40dbfa802ea16 Version: 5000d37042a61ca556fde2782ca40dbfa802ea16 Version: 5000d37042a61ca556fde2782ca40dbfa802ea16 Version: 5000d37042a61ca556fde2782ca40dbfa802ea16 Version: 5000d37042a61ca556fde2782ca40dbfa802ea16 Version: 5000d37042a61ca556fde2782ca40dbfa802ea16 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/dma/sh/rz-dmac.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "d24d53323e817d79a4bd111bd10b34dbc96e64a8",
"status": "affected",
"version": "5000d37042a61ca556fde2782ca40dbfa802ea16",
"versionType": "git"
},
{
"lessThan": "0e0c5b3cf374ebf3c589741751e1fbc67f53ec2f",
"status": "affected",
"version": "5000d37042a61ca556fde2782ca40dbfa802ea16",
"versionType": "git"
},
{
"lessThan": "5b12de6229d662864ee22c11d4876652b40120f0",
"status": "affected",
"version": "5000d37042a61ca556fde2782ca40dbfa802ea16",
"versionType": "git"
},
{
"lessThan": "2a4d9e2234c3f817bb0ddbc8680d09ce9be84f93",
"status": "affected",
"version": "5000d37042a61ca556fde2782ca40dbfa802ea16",
"versionType": "git"
},
{
"lessThan": "ec9f66c91bffdb69d309bae6dfb387562db7ebc8",
"status": "affected",
"version": "5000d37042a61ca556fde2782ca40dbfa802ea16",
"versionType": "git"
},
{
"lessThan": "07ae600bd353b22f31a8f1007269744fafc7f123",
"status": "affected",
"version": "5000d37042a61ca556fde2782ca40dbfa802ea16",
"versionType": "git"
},
{
"lessThan": "731712403ddb39d1a76a11abf339a0615bc85de7",
"status": "affected",
"version": "5000d37042a61ca556fde2782ca40dbfa802ea16",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/dma/sh/rz-dmac.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.15"
},
{
"lessThan": "5.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: sh: rz-dmac: Move interrupt request after everything is set up\n\nOnce the interrupt is requested, the interrupt handler may run immediately.\nSince the IRQ handler can access channel-\u003ech_base, which is initialized\nonly after requesting the IRQ, this may lead to invalid memory access.\nLikewise, the IRQ thread may access uninitialized data (the ld_free,\nld_queue, and ld_active lists), which may also lead to issues.\n\nRequest the interrupts only after everything is set up. To keep the error\npath simpler, use dmam_alloc_coherent() instead of dma_alloc_coherent()."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.4,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The flaw triggers in rz_dmac_chan_probe() during Renesas RZ/G2L/V2H/T2H platform DMAC driver initialization at boot or module load; there is no network, Bluetooth, or runtime syscall path to the vulnerable devm_request_threaded_irq() ordering.\nAC:L - Once the DMAC channel IRQ line is asserted when devm_request_threaded_irq() is called after reset_deassert, the hardirq/thread handlers run immediately before ch_base or lists are initialized; stale post-reset interrupt state on these SoCs makes this timing plausible without luck.\nPR:N - rz_dmac_probe() performs no capability or authentication checks before requesting per-channel IRQs; on affected Renesas embedded boards the vulnerable probe sequence runs automatically during kernel boot without the attacker holding Linux privileges.\nUI:N - No victim action is required; pending/latched DMAC channel interrupts during driver probe at boot or reboot can invoke the buggy handlers without anyone opening device nodes or configuring DMA transfers.\nS:U - Impact is kernel NULL dereference, list/spinlock corruption, and MMIO faults within the host kernel; this is not a VM escape, container sandbox breakout, or documented IOMMU security-boundary bypass.\nC:H - The threaded IRQ handler may lock an uninitialized vc.lock and walk uninitialized ld_active/ld_queue/ld_free lists, causing invalid kernel memory reads and list-metadata exposure beyond a pure bounded fault.\nI:H - The hardirq path issues readl/writel through uninitialized ch_base (NULL/low MMIO), and list/spinlock corruption in the IRQ thread can corrupt kernel heap metadata and enable control-flow hijack primitives.\nA:H - Invalid MMIO via NULL ch_base and corrupted IRQ-thread list handling can cause kernel oops/panic during probe on affected embedded systems, causing full loss of availability until reboot."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:36:26.048Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/d24d53323e817d79a4bd111bd10b34dbc96e64a8"
},
{
"url": "https://git.kernel.org/stable/c/0e0c5b3cf374ebf3c589741751e1fbc67f53ec2f"
},
{
"url": "https://git.kernel.org/stable/c/5b12de6229d662864ee22c11d4876652b40120f0"
},
{
"url": "https://git.kernel.org/stable/c/2a4d9e2234c3f817bb0ddbc8680d09ce9be84f93"
},
{
"url": "https://git.kernel.org/stable/c/ec9f66c91bffdb69d309bae6dfb387562db7ebc8"
},
{
"url": "https://git.kernel.org/stable/c/07ae600bd353b22f31a8f1007269744fafc7f123"
},
{
"url": "https://git.kernel.org/stable/c/731712403ddb39d1a76a11abf339a0615bc85de7"
}
],
"title": "dmaengine: sh: rz-dmac: Move interrupt request after everything is set up",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72146",
"datePublished": "2026-08-15T05:53:18.431Z",
"dateReserved": "2026-08-09T03:40:39.908Z",
"dateUpdated": "2026-08-19T16:36:26.048Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80843 (GCVE-0-2026-80843)
Vulnerability from cvelistv5
Published
2026-09-04 15:54
Modified
2026-09-04 15:54
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
xfrm: fix xfrm_state_construct() auth-trunc leak
attach_auth_trunc() can allocate x->aalg while leaving
x->props.aalgo at zero when the selected auth algorithm has no
sadb_alg_id. One real case is cmac(aes).
xfrm_state_construct() then treats !x->props.aalgo as "no auth
algorithm attached yet" and calls attach_auth(). That overwrites
x->aalg and loses the first allocation. Any later failure or teardown
only frees the replacement pointer.
Check whether x->aalg is already attached instead of inferring that
state from x->props.aalgo.
References
| URL | Tags | ||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 4447bb33f09444920a8f1d89e1540137429351b6 Version: 4447bb33f09444920a8f1d89e1540137429351b6 Version: 4447bb33f09444920a8f1d89e1540137429351b6 Version: 4447bb33f09444920a8f1d89e1540137429351b6 Version: 4447bb33f09444920a8f1d89e1540137429351b6 Version: 4447bb33f09444920a8f1d89e1540137429351b6 Version: 4447bb33f09444920a8f1d89e1540137429351b6 Version: 4447bb33f09444920a8f1d89e1540137429351b6 Version: 4447bb33f09444920a8f1d89e1540137429351b6 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/xfrm/xfrm_user.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "958ae9f261319e1cdc44879886bcda2263258cca",
"status": "affected",
"version": "4447bb33f09444920a8f1d89e1540137429351b6",
"versionType": "git"
},
{
"lessThan": "fb7f3e74789a3c89647f4eb768f6dfaf4a751e72",
"status": "affected",
"version": "4447bb33f09444920a8f1d89e1540137429351b6",
"versionType": "git"
},
{
"lessThan": "ba0c110c205855b3f1e3130d8c0fdb484d704c8c",
"status": "affected",
"version": "4447bb33f09444920a8f1d89e1540137429351b6",
"versionType": "git"
},
{
"lessThan": "c8837bbe792257af547fd1c0252553ce13148795",
"status": "affected",
"version": "4447bb33f09444920a8f1d89e1540137429351b6",
"versionType": "git"
},
{
"lessThan": "71d42da01740ec6557837bebec0bc48cfc3b4c39",
"status": "affected",
"version": "4447bb33f09444920a8f1d89e1540137429351b6",
"versionType": "git"
},
{
"lessThan": "cf67361e78dca488d6e4df8396a53e6745a3a80e",
"status": "affected",
"version": "4447bb33f09444920a8f1d89e1540137429351b6",
"versionType": "git"
},
{
"lessThan": "37426395cb90ef217beec8407a14bd82153793d3",
"status": "affected",
"version": "4447bb33f09444920a8f1d89e1540137429351b6",
"versionType": "git"
},
{
"lessThan": "be19d20e53a239572bb2a28efcc1cd2b069b1ef9",
"status": "affected",
"version": "4447bb33f09444920a8f1d89e1540137429351b6",
"versionType": "git"
},
{
"lessThan": "c12cbf56320fb633484ee0ca1fb7d68d6b64b213",
"status": "affected",
"version": "4447bb33f09444920a8f1d89e1540137429351b6",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/xfrm/xfrm_user.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.33"
},
{
"lessThan": "2.6.33",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.269",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.220",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.187",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.156",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.108",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.49",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.13",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.3",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.269",
"versionStartIncluding": "2.6.33",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.220",
"versionStartIncluding": "2.6.33",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.187",
"versionStartIncluding": "2.6.33",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.156",
"versionStartIncluding": "2.6.33",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.108",
"versionStartIncluding": "2.6.33",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.49",
"versionStartIncluding": "2.6.33",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.13",
"versionStartIncluding": "2.6.33",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.3",
"versionStartIncluding": "2.6.33",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "2.6.33",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: fix xfrm_state_construct() auth-trunc leak\n\nattach_auth_trunc() can allocate x-\u003eaalg while leaving\nx-\u003eprops.aalgo at zero when the selected auth algorithm has no\nsadb_alg_id. One real case is cmac(aes).\n\nxfrm_state_construct() then treats !x-\u003eprops.aalgo as \"no auth\nalgorithm attached yet\" and calls attach_auth(). That overwrites\nx-\u003eaalg and loses the first allocation. Any later failure or teardown\nonly frees the replacement pointer.\n\nCheck whether x-\u003eaalg is already attached instead of inferring that\nstate from x-\u003eprops.aalgo."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T15:54:53.328Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/958ae9f261319e1cdc44879886bcda2263258cca"
},
{
"url": "https://git.kernel.org/stable/c/fb7f3e74789a3c89647f4eb768f6dfaf4a751e72"
},
{
"url": "https://git.kernel.org/stable/c/ba0c110c205855b3f1e3130d8c0fdb484d704c8c"
},
{
"url": "https://git.kernel.org/stable/c/c8837bbe792257af547fd1c0252553ce13148795"
},
{
"url": "https://git.kernel.org/stable/c/71d42da01740ec6557837bebec0bc48cfc3b4c39"
},
{
"url": "https://git.kernel.org/stable/c/cf67361e78dca488d6e4df8396a53e6745a3a80e"
},
{
"url": "https://git.kernel.org/stable/c/37426395cb90ef217beec8407a14bd82153793d3"
},
{
"url": "https://git.kernel.org/stable/c/be19d20e53a239572bb2a28efcc1cd2b069b1ef9"
},
{
"url": "https://git.kernel.org/stable/c/c12cbf56320fb633484ee0ca1fb7d68d6b64b213"
}
],
"title": "xfrm: fix xfrm_state_construct() auth-trunc leak",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80843",
"datePublished": "2026-09-04T15:54:53.328Z",
"dateReserved": "2026-08-26T14:34:25.796Z",
"dateUpdated": "2026-09-04T15:54:53.328Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80528 (GCVE-0-2026-80528)
Vulnerability from cvelistv5
Published
2026-08-26 14:37
Modified
2026-08-27 05:01
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ceph: avoid fs reclaim while using current->journal_info
handle_reply() stores a `ceph_mds_request` pointer in
`current->journal_info` while filling the inode and dentry cache from
an MDS reply.
An allocation in this section can enter direct reclaim and prune
dentries from another filesystem. If this dirties an ext4 inode, ext4
starts a JBD2 transaction. JBD2 interprets the Ceph request in
`current->journal_info` as a journal handle and dereferences the
request's `r_tid` as `h_transaction`, causing a kernel crash, e.g.:
Unable to handle kernel paging request at virtual address 00000000077b4818
[...]
Internal error: Oops: 0000000096000004 [#1] SMP
Modules linked in:
CPU: 6 UID: 0 PID: 2699135 Comm: kworker/6:3 Tainted: G W 6.18.38-i3 #1113 NONE
[...]
Workqueue: ceph-msgr ceph_con_workfn
pstate: 80400009 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
pc : jbd2__journal_start+0x2c/0x208
lr : __ext4_journal_start_sb+0x100/0x178
[...]
Call trace:
jbd2__journal_start+0x2c/0x208 (P)
__ext4_journal_start_sb+0x100/0x178
ext4_dirty_inode+0x3c/0x90
__mark_inode_dirty+0x58/0x400
iput.part.0+0x2b0/0x370
iput+0x18/0x30
dentry_unlink_inode+0xc0/0x158
__dentry_kill+0x80/0x250
shrink_dentry_list+0x90/0x130
prune_dcache_sb+0x60/0x98
super_cache_scan+0xe8/0x190
do_shrink_slab+0x174/0x388
shrink_slab+0xd8/0x4c0
shrink_node+0x31c/0x908
do_try_to_free_pages+0xd0/0x508
try_to_free_pages+0x11c/0x238
__alloc_frozen_pages_noprof+0x4d0/0xdd0
__folio_alloc_noprof+0x18/0x70
__filemap_get_folio+0x248/0x440
ceph_readdir_prepopulate+0x570/0x9e8
mds_dispatch+0x1424/0x1ba0
ceph_con_process_message+0x74/0xa0
ceph_con_v1_try_read+0x3a0/0x1510
ceph_con_workfn+0x260/0x460
Enter a scoped NOFS allocation context and leave it after clearing
`journal_info`. This prevents filesystem reclaim from recursing into
another filesystem while the field contains Ceph-private data.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 315f24088048a51eed341c53be66ea477a3c7d16 Version: 315f24088048a51eed341c53be66ea477a3c7d16 Version: 315f24088048a51eed341c53be66ea477a3c7d16 Version: 315f24088048a51eed341c53be66ea477a3c7d16 Version: 315f24088048a51eed341c53be66ea477a3c7d16 Version: 315f24088048a51eed341c53be66ea477a3c7d16 Version: 315f24088048a51eed341c53be66ea477a3c7d16 Version: 315f24088048a51eed341c53be66ea477a3c7d16 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/ceph/mds_client.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ca5fa2380dd90a0adb01580fa6225025351a90f6",
"status": "affected",
"version": "315f24088048a51eed341c53be66ea477a3c7d16",
"versionType": "git"
},
{
"lessThan": "00c12f57a87f537fa8779258fb3a03003a99963e",
"status": "affected",
"version": "315f24088048a51eed341c53be66ea477a3c7d16",
"versionType": "git"
},
{
"lessThan": "4dbb2c02558e71f93510a6461d7e798b67426b49",
"status": "affected",
"version": "315f24088048a51eed341c53be66ea477a3c7d16",
"versionType": "git"
},
{
"lessThan": "c8a21660c3b90864c391164eea5622e7b5b2897c",
"status": "affected",
"version": "315f24088048a51eed341c53be66ea477a3c7d16",
"versionType": "git"
},
{
"lessThan": "47b745747b3aa39064724a642884f9df924ddf20",
"status": "affected",
"version": "315f24088048a51eed341c53be66ea477a3c7d16",
"versionType": "git"
},
{
"lessThan": "79d95b43ca090426399651ed580dd9bf2db36ab8",
"status": "affected",
"version": "315f24088048a51eed341c53be66ea477a3c7d16",
"versionType": "git"
},
{
"lessThan": "b6a0989613072499633e761a1536428a466de7d3",
"status": "affected",
"version": "315f24088048a51eed341c53be66ea477a3c7d16",
"versionType": "git"
},
{
"lessThan": "5b602344a49e039e792ce5a8923bcc61412ee134",
"status": "affected",
"version": "315f24088048a51eed341c53be66ea477a3c7d16",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/ceph/mds_client.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.6"
},
{
"lessThan": "4.6",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.46",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.10",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nceph: avoid fs reclaim while using current-\u003ejournal_info\n\nhandle_reply() stores a `ceph_mds_request` pointer in\n`current-\u003ejournal_info` while filling the inode and dentry cache from\nan MDS reply.\n\nAn allocation in this section can enter direct reclaim and prune\ndentries from another filesystem. If this dirties an ext4 inode, ext4\nstarts a JBD2 transaction. JBD2 interprets the Ceph request in\n`current-\u003ejournal_info` as a journal handle and dereferences the\nrequest\u0027s `r_tid` as `h_transaction`, causing a kernel crash, e.g.:\n\n Unable to handle kernel paging request at virtual address 00000000077b4818\n [...]\n Internal error: Oops: 0000000096000004 [#1] SMP\n Modules linked in:\n CPU: 6 UID: 0 PID: 2699135 Comm: kworker/6:3 Tainted: G W 6.18.38-i3 #1113 NONE\n [...]\n Workqueue: ceph-msgr ceph_con_workfn\n pstate: 80400009 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n pc : jbd2__journal_start+0x2c/0x208\n lr : __ext4_journal_start_sb+0x100/0x178\n [...]\n Call trace:\n jbd2__journal_start+0x2c/0x208 (P)\n __ext4_journal_start_sb+0x100/0x178\n ext4_dirty_inode+0x3c/0x90\n __mark_inode_dirty+0x58/0x400\n iput.part.0+0x2b0/0x370\n iput+0x18/0x30\n dentry_unlink_inode+0xc0/0x158\n __dentry_kill+0x80/0x250\n shrink_dentry_list+0x90/0x130\n prune_dcache_sb+0x60/0x98\n super_cache_scan+0xe8/0x190\n do_shrink_slab+0x174/0x388\n shrink_slab+0xd8/0x4c0\n shrink_node+0x31c/0x908\n do_try_to_free_pages+0xd0/0x508\n try_to_free_pages+0x11c/0x238\n __alloc_frozen_pages_noprof+0x4d0/0xdd0\n __folio_alloc_noprof+0x18/0x70\n __filemap_get_folio+0x248/0x440\n ceph_readdir_prepopulate+0x570/0x9e8\n mds_dispatch+0x1424/0x1ba0\n ceph_con_process_message+0x74/0xa0\n ceph_con_v1_try_read+0x3a0/0x1510\n ceph_con_workfn+0x260/0x460\n\nEnter a scoped NOFS allocation context and leave it after clearing\n`journal_info`. This prevents filesystem reclaim from recursing into\nanother filesystem while the field contains Ceph-private data."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The crash path runs in the ceph-msgr kworker handling CEPH_MSG_CLIENT_REPLY from the MDS over TCP; on Ceph/Rook/Kubernetes nodes with cephfs mounted, a compromised or malicious MDS peer drives handle_reply() remotely without requiring a victim syscall.\nAC:L - A MDS peer can supply large readdir/lookup replies to force GFP_KERNEL allocations in ceph_fill_trace/ceph_readdir_prepopulate while journal_info is set, making direct reclaim into ext4 dentry pruning likely without rare kernel configs or uncontrollable heap layout.\nPR:N - Exploitation requires no Linux UID, capability, or init-namespace root on the victim; any kernel cephfs client already connected to an attacker-controlled or compromised cluster suffices, consistent with other MDS-reply client CVEs (e.g., CVE-2026-80527).\nUI:N - Once cephfs is mounted (standard in Ceph deployments), MDS replies are processed automatically in kworker context; attackers need not induce a victim to mount media or perform a one-off interactive step at exploitation time.\nS:U - Impact is a kernel oops from JBD2 mistyping current-\u003ejournal_info on the same host; it does not cross VM, container, or IOMMU boundaries to another security authority.\nC:H - While journal_info holds a ceph_mds_request pointer, ext4 reclaim invokes jbd2__journal_start(), type-confusing that object as a journal handle and dereferencing r_tid as h_transaction\u2014a cross-subsystem type confusion with kernel-pointer read potential per CNA memory-safety guidance.\nI:H - Type confusion of current-\u003ejournal_info between Ceph and JBD2 misinterprets live ceph_mds_request fields as journal-handle metadata during MDS reply processing; kernel CNA guidance classes type confusion as High integrity impact even when the immediate fault is an oops.\nA:H - The reported ARM64 oops in jbd2__journal_start() from invalid h_transaction dereference reliably crashes the ceph-msgr worker and can panic the node; reclaim during MDS reply handling enables repeated remote-triggered denial-of-service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T05:01:23.093Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ca5fa2380dd90a0adb01580fa6225025351a90f6"
},
{
"url": "https://git.kernel.org/stable/c/00c12f57a87f537fa8779258fb3a03003a99963e"
},
{
"url": "https://git.kernel.org/stable/c/4dbb2c02558e71f93510a6461d7e798b67426b49"
},
{
"url": "https://git.kernel.org/stable/c/c8a21660c3b90864c391164eea5622e7b5b2897c"
},
{
"url": "https://git.kernel.org/stable/c/47b745747b3aa39064724a642884f9df924ddf20"
},
{
"url": "https://git.kernel.org/stable/c/79d95b43ca090426399651ed580dd9bf2db36ab8"
},
{
"url": "https://git.kernel.org/stable/c/b6a0989613072499633e761a1536428a466de7d3"
},
{
"url": "https://git.kernel.org/stable/c/5b602344a49e039e792ce5a8923bcc61412ee134"
}
],
"title": "ceph: avoid fs reclaim while using current-\u003ejournal_info",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80528",
"datePublished": "2026-08-26T14:37:06.781Z",
"dateReserved": "2026-08-26T14:34:25.764Z",
"dateUpdated": "2026-08-27T05:01:23.093Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68121 (GCVE-0-2026-68121)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-19 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
pppoe: reload header pointer after dev_hard_header()
pppoe_sendmsg() saves a pointer to the PPPoE header before calling
dev_hard_header(). Device header callbacks are allowed to reallocate the
skb head, invalidating pointers into it.
This can happen when a send is blocked in copy_from_user() while the first
non-Ethernet port is added to an empty team device. The team's delegated
GRE header callback then expands the skb head. PPPoE subsequently writes
six bytes through the stale pointer into the freed head.
Reload the PPPoE header through the skb's network-header offset after
device header creation. pskb_expand_head() updates that offset when it
relocates the head.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ppp/pppoe.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "7a56e7c9b08e08fd55a1bcada24cf4fe3782b722",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "6eed5ae7887a93160803d2b81ff88e75eefd4a4c",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "ba3409369c5413cdf0dcbf3a928f76b48e8c3e6a",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "e6493a4d1ee17595766165fa446d45b7e0c318d0",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "7e9fbd7f96bcde63a7c798fe16b38cedee7a1501",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "6866abf59976d273164a6624234d96a967280223",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "bed4caecd723693f750e13adbb2c42ca1249a3fd",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "e9c238f6fe42fb1b4dba3a578277de32cb487937",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ppp/pppoe.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\npppoe: reload header pointer after dev_hard_header()\n\npppoe_sendmsg() saves a pointer to the PPPoE header before calling\ndev_hard_header(). Device header callbacks are allowed to reallocate the\nskb head, invalidating pointers into it.\n\nThis can happen when a send is blocked in copy_from_user() while the first\nnon-Ethernet port is added to an empty team device. The team\u0027s delegated\nGRE header callback then expands the skb head. PPPoE subsequently writes\nsix bytes through the stale pointer into the freed head.\n\nReload the PPPoE header through the skb\u0027s network-header offset after\ndevice header creation. pskb_expand_head() updates that offset when it\nrelocates the head."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is in pppoe_sendmsg(), reached only via the local sendmsg() syscall on a PF_PPPOX/PPPoE socket; it is not triggered by remote packet reception or in-kernel PPP transmit paths such as __pppoe_xmit().\nAC:L - Exploitation requires a race between copy_from_user() blocking in sendmsg and changing team header_ops (e.g., adding the first non-Ethernet GRE port), which an attacker can drive with concurrent threads and retries rather than uncontrollable timing.\nPR:L - PPPoE sockets can be created without special privileges, and configuring the team/GRE topology needed to trigger dev_hard_header() head expansion is achievable with CAP_NET_ADMIN inside an unprivileged user/network namespace (unshare -Urn).\nUI:N - No victim interaction is required; exploitation is fully attacker-driven through socket I/O and netlink/rtnl configuration of the team device.\nS:U - Impact is kernel heap corruption and privilege escalation within the same kernel security authority, not a cross-boundary escape such as guest-to-host VM breakout or IOMMU bypass.\nC:H - Writing PPPoE header fields through a stale pointer after pskb_expand_head() frees the old skb head is a slab use-after-free; freed kmalloc objects can be reclaimed for sensitive data, enabling arbitrary kernel memory disclosure.\nI:H - The post-dev_hard_header() memcpy/ph-\u003elength stores up to eight attacker-influenced bytes into freed skb head memory, providing a heap corruption primitive that can be developed into arbitrary kernel writes or code execution.\nA:H - Use-after-free writes into freed slab memory commonly cause kernel oops/panic and can be triggered repeatedly via sendmsg, yielding persistent denial of service even when full exploitation is not attempted."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:29:31.935Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/7a56e7c9b08e08fd55a1bcada24cf4fe3782b722"
},
{
"url": "https://git.kernel.org/stable/c/6eed5ae7887a93160803d2b81ff88e75eefd4a4c"
},
{
"url": "https://git.kernel.org/stable/c/ba3409369c5413cdf0dcbf3a928f76b48e8c3e6a"
},
{
"url": "https://git.kernel.org/stable/c/e6493a4d1ee17595766165fa446d45b7e0c318d0"
},
{
"url": "https://git.kernel.org/stable/c/7e9fbd7f96bcde63a7c798fe16b38cedee7a1501"
},
{
"url": "https://git.kernel.org/stable/c/6866abf59976d273164a6624234d96a967280223"
},
{
"url": "https://git.kernel.org/stable/c/bed4caecd723693f750e13adbb2c42ca1249a3fd"
},
{
"url": "https://git.kernel.org/stable/c/e9c238f6fe42fb1b4dba3a578277de32cb487937"
}
],
"title": "pppoe: reload header pointer after dev_hard_header()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68121",
"datePublished": "2026-08-10T11:58:41.489Z",
"dateReserved": "2026-07-30T09:28:09.369Z",
"dateUpdated": "2026-08-19T16:29:31.935Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74515 (GCVE-0-2026-74515)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-19 16:38
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
KVM: s390: pci: Reject adapter interrupt forwarding if already enabled
The MPCIFC instruction doesn't allow registering adapter interrupts without
first unregistering. So reject any request to enable interrupt forwarding
if its already enabled for the zPCI device. This also fixes overwriting and
thus leaking resources when the ioctl is called multiple times for the same
device.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc Version: 3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc Version: 3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc Version: 3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc Version: 3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc Version: 3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"arch/s390/kvm/pci.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "642d2d1067f7c4d753ae0e3ba5bc98b43cfe3c70",
"status": "affected",
"version": "3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc",
"versionType": "git"
},
{
"lessThan": "78d9648e7e960546d5b72504a0b0358cd8bb1e9d",
"status": "affected",
"version": "3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc",
"versionType": "git"
},
{
"lessThan": "6be1ff49ba81f96a6fa55915e6d920be43ac57cc",
"status": "affected",
"version": "3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc",
"versionType": "git"
},
{
"lessThan": "6837f0ae85fd54cf64c8a0c7c530bba2fae0a207",
"status": "affected",
"version": "3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc",
"versionType": "git"
},
{
"lessThan": "591952b63a9f976da7d49f719f36ec826ee2a575",
"status": "affected",
"version": "3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc",
"versionType": "git"
},
{
"lessThan": "8fa01be5a6149404adb82c0979a78f6347edd3ef",
"status": "affected",
"version": "3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"arch/s390/kvm/pci.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.0"
},
{
"lessThan": "6.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: s390: pci: Reject adapter interrupt forwarding if already enabled\n\nThe MPCIFC instruction doesn\u0027t allow registering adapter interrupts without\nfirst unregistering. So reject any request to enable interrupt forwarding\nif its already enabled for the zPCI device. This also fixes overwriting and\nthus leaking resources when the ioctl is called multiple times for the same\ndevice."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached only through the KVM_S390_ZPCI_OP VM ioctl in arch/s390/kvm/kvm-s390.c; on IBM Z with zPCI passthrough, QEMU forwards guest mpcifc adapter-interrupt registration to this local ioctl path, not over the network.\nAC:L - An attacker with an assigned zPCI device can call KVM_S390_ZPCIOP_REG_AEN twice in a row without racing or special memory layout; each duplicate call deterministically re-enters kvm_s390_pci_aif_enable() and overwrites host bookkeeping.\nPR:L - Exploitation requires a KVM VM file descriptor and a VFIO-assigned zPCI device, i.e. control of the guest/VMM process (typical cloud tenant or qemu user), not init-namespace root; this cannot be reached from an unprivileged user namespace alone.\nUI:N - Once zPCI passthrough is configured, the guest or its VMM can issue duplicate registration on its own; no additional host administrator or victim user action is needed beyond normal device setup.\nS:C - A guest-triggered ioctl corrupts host-owned AIFT/GAITE state outside the VM security boundary, leaving orphaned summary-index entries that the host interrupt path later dereferences in hypervisor context.\nC:H - Duplicate enable overwrites zdev-\u003eaisb and leaks earlier GAITE/AIBV resources; on teardown aift-\u003ekzdev[orphaned_si] still points at freed kvm_zdev/kvm, so aen_host_forward() performs UAF reads of host hypervisor memory.\nI:H - Stale orphaned GAITE entries retain guest-chosen physical addresses and dangling kzdev pointers; aen_host_forward() can execute set_bit_inv() and further host-side writes through those corrupted structures during adapter-event delivery.\nA:H - Each duplicate REG_AEN leaks pinned guest pages, AIBV allocations, and summary bits without rollback when MPCIFC re-registration fails, enabling repeatable host memory exhaustion and kernel oops/panic via IRQ-time UAF dereferences."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:38:14.487Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/642d2d1067f7c4d753ae0e3ba5bc98b43cfe3c70"
},
{
"url": "https://git.kernel.org/stable/c/78d9648e7e960546d5b72504a0b0358cd8bb1e9d"
},
{
"url": "https://git.kernel.org/stable/c/6be1ff49ba81f96a6fa55915e6d920be43ac57cc"
},
{
"url": "https://git.kernel.org/stable/c/6837f0ae85fd54cf64c8a0c7c530bba2fae0a207"
},
{
"url": "https://git.kernel.org/stable/c/591952b63a9f976da7d49f719f36ec826ee2a575"
},
{
"url": "https://git.kernel.org/stable/c/8fa01be5a6149404adb82c0979a78f6347edd3ef"
}
],
"title": "KVM: s390: pci: Reject adapter interrupt forwarding if already enabled",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74515",
"datePublished": "2026-08-15T12:27:35.567Z",
"dateReserved": "2026-08-15T05:44:03.910Z",
"dateUpdated": "2026-08-19T16:38:14.487Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80565 (GCVE-0-2026-80565)
Vulnerability from cvelistv5
Published
2026-08-26 14:37
Modified
2026-08-27 05:01
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
crypto: qce - fix error path in devm_qce_register_algs
If ops->register_algs() fails, the error path repeatedly calls the same
ops->unregister_algs() from the failed registration. Use the loop index
to unregister the previously registered algorithms instead.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 9e403fea74ecbe6b4a4321f13bd4bc929382908d Version: f52f00efd8c0088992ac07ef46af6096e4f0e52e Version: 5d5b673b4dd260226b2202f66a920566c27051f3 Version: e914b2f795b6995bb0e7db45caa4a912dca09e65 Version: 76e6d50fa5a2fb466edcc8b513d7aad372312c2a Version: e80cf84b608725303113d6fe98bb727bf7b7a40d Version: e80cf84b608725303113d6fe98bb727bf7b7a40d Version: e80cf84b608725303113d6fe98bb727bf7b7a40d Version: 8c735ef894dfcca8d0a1cc554f83a82a70fd5b76 Version: 4007883dc7df1dbaeb461b850e0b1b27c057affc Version: 5.10.235 ≤ Version: 5.15.179 ≤ Version: 6.1.129 ≤ Version: 6.6.78 ≤ Version: 6.12.14 ≤ Version: 5.4.291 ≤ Version: 6.13.3 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/crypto/qce/core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "dbca8b798caf47fb2799a26dd09c9ad66305883d",
"status": "affected",
"version": "9e403fea74ecbe6b4a4321f13bd4bc929382908d",
"versionType": "git"
},
{
"lessThan": "fef187c6194d67395182d58169dd14ba631f1b41",
"status": "affected",
"version": "f52f00efd8c0088992ac07ef46af6096e4f0e52e",
"versionType": "git"
},
{
"lessThan": "1ece8e16c085e8cd60ecbdb641269aaa53d31da4",
"status": "affected",
"version": "5d5b673b4dd260226b2202f66a920566c27051f3",
"versionType": "git"
},
{
"lessThan": "de52c713d21806b93b00a6074056b57aec4f8919",
"status": "affected",
"version": "e914b2f795b6995bb0e7db45caa4a912dca09e65",
"versionType": "git"
},
{
"lessThan": "c7dc487aade12c692add3221673c9bdf32dc24f5",
"status": "affected",
"version": "76e6d50fa5a2fb466edcc8b513d7aad372312c2a",
"versionType": "git"
},
{
"lessThan": "a134e4b8102c077286818ee112b9f925db613d4c",
"status": "affected",
"version": "e80cf84b608725303113d6fe98bb727bf7b7a40d",
"versionType": "git"
},
{
"lessThan": "4e88b4fda48282f3fd504b4d4f5d2d4f996b76ce",
"status": "affected",
"version": "e80cf84b608725303113d6fe98bb727bf7b7a40d",
"versionType": "git"
},
{
"lessThan": "9c75402286409f5e1a75e4a445555c84066f89db",
"status": "affected",
"version": "e80cf84b608725303113d6fe98bb727bf7b7a40d",
"versionType": "git"
},
{
"status": "affected",
"version": "8c735ef894dfcca8d0a1cc554f83a82a70fd5b76",
"versionType": "git"
},
{
"status": "affected",
"version": "4007883dc7df1dbaeb461b850e0b1b27c057affc",
"versionType": "git"
},
{
"lessThan": "5.10.266",
"status": "affected",
"version": "5.10.235",
"versionType": "semver"
},
{
"lessThan": "5.15.217",
"status": "affected",
"version": "5.15.179",
"versionType": "semver"
},
{
"lessThan": "6.1.184",
"status": "affected",
"version": "6.1.129",
"versionType": "semver"
},
{
"lessThan": "6.6.153",
"status": "affected",
"version": "6.6.78",
"versionType": "semver"
},
{
"lessThan": "6.12.105",
"status": "affected",
"version": "6.12.14",
"versionType": "semver"
},
{
"lessThan": "5.5",
"status": "affected",
"version": "5.4.291",
"versionType": "semver"
},
{
"lessThan": "6.14",
"status": "affected",
"version": "6.13.3",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/crypto/qce/core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.14"
},
{
"lessThan": "6.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "5.10.235",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.15.179",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "6.1.129",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "6.6.78",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "6.12.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.46",
"versionStartIncluding": "6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.10",
"versionStartIncluding": "6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.4.291",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.13.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: qce - fix error path in devm_qce_register_algs\n\nIf ops-\u003eregister_algs() fails, the error path repeatedly calls the same\nops-\u003eunregister_algs() from the failed registration. Use the loop index\nto unregister the previously registered algorithms instead."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The flaw is in devm_qce_register_algs() called only from qce_crypto_probe() during platform-driver initialization at boot or qcrypto module load, not from any network, ioctl, or AF_ALG userspace path.\nAC:L - On modular builds an attacker can reload qcrypto under memory pressure to force register_algs() failure, and once algorithms leak the UAF is reliably triggered by normal kernel crypto consumers such as fscrypt selecting high-priority QCE transforms.\nPR:L - After the flawed probe error path leaves QCE algorithms registered, unprivileged local processes on Qualcomm phones and embedded targets reach them through routine fscrypt/dm-crypt kernel crypto without capabilities or init-namespace root.\nUI:N - Exploitation requires no victim interaction beyond ordinary encrypted filesystem or storage activity that automatically exercises kernel crypto after the probe failure has occurred.\nS:U - Impact is confined to kernel memory corruption and privilege escalation within the same kernel security domain, not a VM, IOMMU, or sandbox boundary crossing.\nC:H - Leaked algorithm templates retain tmpl-\u003eqce pointers to the devm-freed qce_device, creating a kernel heap use-after-free that can be leveraged for arbitrary kernel memory disclosure.\nI:H - The dangling qce_device UAF corrupts kernel heap objects and control fields (mutex, DMA, MMIO pointers) reachable from crypto request handlers, enabling arbitrary write and potential code execution.\nA:H - Dereferencing the freed qce_device during QCE crypto operations can cause kernel oops, panic, or hang, and UAF corruption inherently threatens system availability."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T05:01:50.972Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/dbca8b798caf47fb2799a26dd09c9ad66305883d"
},
{
"url": "https://git.kernel.org/stable/c/fef187c6194d67395182d58169dd14ba631f1b41"
},
{
"url": "https://git.kernel.org/stable/c/1ece8e16c085e8cd60ecbdb641269aaa53d31da4"
},
{
"url": "https://git.kernel.org/stable/c/de52c713d21806b93b00a6074056b57aec4f8919"
},
{
"url": "https://git.kernel.org/stable/c/c7dc487aade12c692add3221673c9bdf32dc24f5"
},
{
"url": "https://git.kernel.org/stable/c/a134e4b8102c077286818ee112b9f925db613d4c"
},
{
"url": "https://git.kernel.org/stable/c/4e88b4fda48282f3fd504b4d4f5d2d4f996b76ce"
},
{
"url": "https://git.kernel.org/stable/c/9c75402286409f5e1a75e4a445555c84066f89db"
}
],
"title": "crypto: qce - fix error path in devm_qce_register_algs",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80565",
"datePublished": "2026-08-26T14:37:28.953Z",
"dateReserved": "2026-08-26T14:34:25.767Z",
"dateUpdated": "2026-08-27T05:01:50.972Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74650 (GCVE-0-2026-74650)
Vulnerability from cvelistv5
Published
2026-08-22 15:32
Modified
2026-08-27 12:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
staging: rtl8723bs: fix OOB read in WMM_param_handler()
WMM_param_handler() copies a fixed-size WMM parameter element out of a
received information element without checking that the element is long
enough, causing an out-of-bounds read for a short WMM IE.
The handler reads sizeof(struct WMM_para_element) (18) bytes at
pIE->data + 6, so it requires pIE->length to be at least 24
(WLAN_WMM_LEN), but it never validates the length. Two of its three
callers reach it after matching only the WMM OUI: OnAssocRsp() in
rtw_mlme_ext.c matches a 6-byte OUI, and join_cmd_hdl() matches a
4-byte OUI, before calling the handler. A vendor-specific IE carrying
the WMM OUI but a length between 6 and 23, placed in an association
response or in the IE blob handed to join_cmd_hdl(), passes the OUI
check and then makes the memcmp() and memcpy() at pIE->data + 6 read
past the end of the element. OnAssocRsp() parses a frame received from
the AP, so this is reachable from a remote peer.
The remaining caller in rtw_wlan_util.c already guards the handler with
"pIE->length == WLAN_WMM_LEN". Move the equivalent check into the
handler itself so every caller is covered; the sibling IE handlers in
the same parsing loop (HT_caps_handler(), HT_info_handler(),
ERP_IE_handler()) likewise bound their accesses by pIE->length.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/staging/rtl8723bs/core/rtw_wlan_util.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "5df2fd06567df5f178c8faae0bdaefd203618d21",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "6cdca4c8b64c15a3ab9ad7a85f482e9519eadf93",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "2bee6f7a0f0125238951e31da2e96d06fe359043",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "1158b9931207392d6dd136aa0c4be18893b50fa1",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "ce2399717de242344880044b91a20a712644fdfb",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "e5b7610008f4e6a80c8b071aa77ddbd5e17ea472",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "e429c6dfd5d2324cd866daaf4c29d5cfe4dea0e4",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "ae21407350151bddfd4fea7aa39bd0643c0ca9d3",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/staging/rtl8723bs/core/rtw_wlan_util.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.12"
},
{
"lessThan": "4.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.267",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.267",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: rtl8723bs: fix OOB read in WMM_param_handler()\n\nWMM_param_handler() copies a fixed-size WMM parameter element out of a\nreceived information element without checking that the element is long\nenough, causing an out-of-bounds read for a short WMM IE.\n\nThe handler reads sizeof(struct WMM_para_element) (18) bytes at\npIE-\u003edata + 6, so it requires pIE-\u003elength to be at least 24\n(WLAN_WMM_LEN), but it never validates the length. Two of its three\ncallers reach it after matching only the WMM OUI: OnAssocRsp() in\nrtw_mlme_ext.c matches a 6-byte OUI, and join_cmd_hdl() matches a\n4-byte OUI, before calling the handler. A vendor-specific IE carrying\nthe WMM OUI but a length between 6 and 23, placed in an association\nresponse or in the IE blob handed to join_cmd_hdl(), passes the OUI\ncheck and then makes the memcmp() and memcpy() at pIE-\u003edata + 6 read\npast the end of the element. OnAssocRsp() parses a frame received from\nthe AP, so this is reachable from a remote peer.\n\nThe remaining caller in rtw_wlan_util.c already guards the handler with\n\"pIE-\u003elength == WLAN_WMM_LEN\". Move the equivalent check into the\nhandler itself so every caller is covered; the sibling IE handlers in\nthe same parsing loop (HT_caps_handler(), HT_info_handler(),\nERP_IE_handler()) likewise bound their accesses by pIE-\u003elength."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T12:39:54.006Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/5df2fd06567df5f178c8faae0bdaefd203618d21"
},
{
"url": "https://git.kernel.org/stable/c/6cdca4c8b64c15a3ab9ad7a85f482e9519eadf93"
},
{
"url": "https://git.kernel.org/stable/c/2bee6f7a0f0125238951e31da2e96d06fe359043"
},
{
"url": "https://git.kernel.org/stable/c/1158b9931207392d6dd136aa0c4be18893b50fa1"
},
{
"url": "https://git.kernel.org/stable/c/ce2399717de242344880044b91a20a712644fdfb"
},
{
"url": "https://git.kernel.org/stable/c/e5b7610008f4e6a80c8b071aa77ddbd5e17ea472"
},
{
"url": "https://git.kernel.org/stable/c/e429c6dfd5d2324cd866daaf4c29d5cfe4dea0e4"
},
{
"url": "https://git.kernel.org/stable/c/ae21407350151bddfd4fea7aa39bd0643c0ca9d3"
}
],
"title": "staging: rtl8723bs: fix OOB read in WMM_param_handler()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74650",
"datePublished": "2026-08-22T15:32:26.333Z",
"dateReserved": "2026-08-15T05:44:03.923Z",
"dateUpdated": "2026-08-27T12:39:54.006Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74604 (GCVE-0-2026-74604)
Vulnerability from cvelistv5
Published
2026-08-22 15:31
Modified
2026-08-25 05:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Revert "thermal/drivers/hwmon: Cleanup coding style a bit"
Revert commit 030a48b0f6ce ("thermal/drivers/hwmon: Cleanup coding style
a bit") that introduced a use-after-free into the error path of
thermal_add_hwmon_sysfs() by removing a valid check from it.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 030a48b0f6ce393d78b8d33debb1e2043b8cc156 Version: 030a48b0f6ce393d78b8d33debb1e2043b8cc156 Version: 030a48b0f6ce393d78b8d33debb1e2043b8cc156 Version: 030a48b0f6ce393d78b8d33debb1e2043b8cc156 Version: 030a48b0f6ce393d78b8d33debb1e2043b8cc156 Version: 030a48b0f6ce393d78b8d33debb1e2043b8cc156 Version: 030a48b0f6ce393d78b8d33debb1e2043b8cc156 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/thermal/thermal_hwmon.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "2434f4765da8ccd7ef31be88b86f1bfa2e95be11",
"status": "affected",
"version": "030a48b0f6ce393d78b8d33debb1e2043b8cc156",
"versionType": "git"
},
{
"lessThan": "b4c01ae6dd56d9dfd96bd1b29c28afa8fa06b366",
"status": "affected",
"version": "030a48b0f6ce393d78b8d33debb1e2043b8cc156",
"versionType": "git"
},
{
"lessThan": "999e573212d5f1debf073c68be35e55bbfad12fc",
"status": "affected",
"version": "030a48b0f6ce393d78b8d33debb1e2043b8cc156",
"versionType": "git"
},
{
"lessThan": "6a48ee9a5bda0f8ee501f9bef159fb9f39ff519a",
"status": "affected",
"version": "030a48b0f6ce393d78b8d33debb1e2043b8cc156",
"versionType": "git"
},
{
"lessThan": "8d34019d1413629a434a7e8d9f91c76d256196a0",
"status": "affected",
"version": "030a48b0f6ce393d78b8d33debb1e2043b8cc156",
"versionType": "git"
},
{
"lessThan": "6b446d335ba16e93a266dd77adf1ba51abc82df4",
"status": "affected",
"version": "030a48b0f6ce393d78b8d33debb1e2043b8cc156",
"versionType": "git"
},
{
"lessThan": "ff8da20b6f47c48d46e47f93f7a59e2d56ee9107",
"status": "affected",
"version": "030a48b0f6ce393d78b8d33debb1e2043b8cc156",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/thermal/thermal_hwmon.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.11"
},
{
"lessThan": "5.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nRevert \"thermal/drivers/hwmon: Cleanup coding style a bit\"\n\nRevert commit 030a48b0f6ce (\"thermal/drivers/hwmon: Cleanup coding style\na bit\") that introduced a use-after-free into the error path of\nthermal_add_hwmon_sysfs() by removing a valid check from it."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.4,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is in thermal_add_hwmon_sysfs() during thermal zone/hwmon driver registration; it is only reachable from kernel thermal driver probe/init paths, not from network protocols or physical buses.\nAC:L - When a second thermal zone shares an existing hwmon type and registration fails, the error path deterministically kfree()s a still-linked hwmon object, leaving a dangling entry that any later sysfs access can hit without winning a race.\nPR:N - No privileges are needed to exploit the resulting UAF: hwmon temp attributes are world-readable (0444) and unprivileged local processes routinely read /sys/class/hwmon on phones, servers, and embedded devices after latent corruption during multi-sensor thermal probe.\nUI:N - Exploitation requires no victim interaction beyond normal system operation; reading thermal sensors or subsequent kernel hwmon operations can trigger use of the freed object automatically.\nS:U - Impact is confined to kernel memory corruption and privilege escalation within the host kernel; it does not cross VM, container, or IOMMU security boundaries by itself.\nC:H - The use-after-free of struct thermal_hwmon_device leaves a dangling list entry and device pointer; subsequent sysfs reads or thermal hwmon operations can dereference attacker-influencable freed heap memory, enabling arbitrary kernel memory disclosure.\nI:H - Heap UAF on a long-lived thermal_hwmon_device structure adjacent to list pointers and device objects provides standard kernel heap corruption primitives that can be developed into arbitrary write and local privilege escalation.\nA:H - Use-after-free in kernel thermal/hwmon registration can cause immediate kernel oops/panic on access to the freed hwmon device, and repeated or concurrent sysfs access can reliably crash or hang the system."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:40:28.622Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/2434f4765da8ccd7ef31be88b86f1bfa2e95be11"
},
{
"url": "https://git.kernel.org/stable/c/b4c01ae6dd56d9dfd96bd1b29c28afa8fa06b366"
},
{
"url": "https://git.kernel.org/stable/c/999e573212d5f1debf073c68be35e55bbfad12fc"
},
{
"url": "https://git.kernel.org/stable/c/6a48ee9a5bda0f8ee501f9bef159fb9f39ff519a"
},
{
"url": "https://git.kernel.org/stable/c/8d34019d1413629a434a7e8d9f91c76d256196a0"
},
{
"url": "https://git.kernel.org/stable/c/6b446d335ba16e93a266dd77adf1ba51abc82df4"
},
{
"url": "https://git.kernel.org/stable/c/ff8da20b6f47c48d46e47f93f7a59e2d56ee9107"
}
],
"title": "Revert \"thermal/drivers/hwmon: Cleanup coding style a bit\"",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74604",
"datePublished": "2026-08-22T15:31:52.295Z",
"dateReserved": "2026-08-15T05:44:03.919Z",
"dateUpdated": "2026-08-25T05:40:28.622Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80714 (GCVE-0-2026-80714)
Vulnerability from cvelistv5
Published
2026-08-28 06:53
Modified
2026-08-29 06:22
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ipvs: do not propagate one-packet flag to synced conns
Synced connections can be created before their destination exists. When
the destination is later added, ip_vs_bind_dest() copies connection flags
from the destination into cp->flags.
IP_VS_CONN_F_ONE_PACKET connections are not synced. If a synced
connection inherits IP_VS_CONN_F_ONE_PACKET while it is already hashed,
expiry can treat it as a one-packet connection and skip unlinking the
existing conn_tab node, leaving stale hash nodes pointing at a freed
struct ip_vs_conn.
Drop IP_VS_CONN_F_ONE_PACKET from destination flags when binding synced
connections.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 26ec037f9841e49cc5c615deb8e1e73e5beab2ca Version: 26ec037f9841e49cc5c615deb8e1e73e5beab2ca Version: 26ec037f9841e49cc5c615deb8e1e73e5beab2ca Version: 26ec037f9841e49cc5c615deb8e1e73e5beab2ca Version: 26ec037f9841e49cc5c615deb8e1e73e5beab2ca Version: 26ec037f9841e49cc5c615deb8e1e73e5beab2ca Version: 26ec037f9841e49cc5c615deb8e1e73e5beab2ca Version: 26ec037f9841e49cc5c615deb8e1e73e5beab2ca |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/netfilter/ipvs/ip_vs_conn.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "06d1d9b56ef8132fbf85006885eb43d9510b8b02",
"status": "affected",
"version": "26ec037f9841e49cc5c615deb8e1e73e5beab2ca",
"versionType": "git"
},
{
"lessThan": "acbdc276091b308ca7794acb86e761f8203e2f59",
"status": "affected",
"version": "26ec037f9841e49cc5c615deb8e1e73e5beab2ca",
"versionType": "git"
},
{
"lessThan": "300348e3ba1521b003d59825f97e24f9a6859688",
"status": "affected",
"version": "26ec037f9841e49cc5c615deb8e1e73e5beab2ca",
"versionType": "git"
},
{
"lessThan": "44af98cc7d5ef8e730488d5df1eecd5deeaa5947",
"status": "affected",
"version": "26ec037f9841e49cc5c615deb8e1e73e5beab2ca",
"versionType": "git"
},
{
"lessThan": "4649e6faeecdc2d44bfa6ccbe405eef27e55d816",
"status": "affected",
"version": "26ec037f9841e49cc5c615deb8e1e73e5beab2ca",
"versionType": "git"
},
{
"lessThan": "b5ee5b266f833601ac4817f6df0bc496fc376a28",
"status": "affected",
"version": "26ec037f9841e49cc5c615deb8e1e73e5beab2ca",
"versionType": "git"
},
{
"lessThan": "e7acfc990c29890c883d0d0ce3f737d003a43b44",
"status": "affected",
"version": "26ec037f9841e49cc5c615deb8e1e73e5beab2ca",
"versionType": "git"
},
{
"lessThan": "a63d2dbaeb50a85d4c976b15a36e6b0c7113db5b",
"status": "affected",
"version": "26ec037f9841e49cc5c615deb8e1e73e5beab2ca",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/netfilter/ipvs/ip_vs_conn.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.36"
},
{
"lessThan": "2.6.36",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.36",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.36",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.36",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "2.6.36",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "2.6.36",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "2.6.36",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "2.6.36",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.36",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nipvs: do not propagate one-packet flag to synced conns\n\nSynced connections can be created before their destination exists. When\nthe destination is later added, ip_vs_bind_dest() copies connection flags\nfrom the destination into cp-\u003eflags.\n\nIP_VS_CONN_F_ONE_PACKET connections are not synced. If a synced\nconnection inherits IP_VS_CONN_F_ONE_PACKET while it is already hashed,\nexpiry can treat it as a one-packet connection and skip unlinking the\nexisting conn_tab node, leaving stale hash nodes pointing at a freed\nstruct ip_vs_conn.\n\nDrop IP_VS_CONN_F_ONE_PACKET from destination flags when binding synced\nconnections."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug is reached on IPVS backup nodes processing UDP sync datagrams in ip_vs_process_message()/ip_vs_proc_conn() (default multicast 224.0.0.81:8848), and on internet-facing load balancers client UDP traffic drives master sync that creates the hashed backup connection before destination bind.\nAC:L - An attacker can reliably inject or refresh IPVS sync records for UDP connections whose destination is not yet present, then trigger ip_vs_try_bind_dest() once a ONEPACKET destination exists; only optional syncid filtering (often 0) is outside attacker control, and connection expiry is timer-driven without a race.\nPR:N - The backup sync receiver accepts unauthenticated UDP multicast with no capability checks in ip_vs_receive()/ip_vs_process_message(); configuring IPVS/ONEPACKET is an environmental precondition on HA load balancers, not a privilege the remote attacker must hold on the victim host.\nUI:N - Exploitation requires no victim or administrator action at trigger time beyond normal HA IPVS operation; forged or reflected sync traffic and subsequent connection expiry directly invoke the vulnerable bind/unlink path without user interaction.\nS:U - Impact is confined to the kernel IPVS connection table on the affected load-balancer node (stale hash entries to a freed struct ip_vs_conn); it does not cross a VM, container, or IOMMU security boundary.\nC:H - Incorrect ONE_PACKET handling leaves hashed conn_tab nodes pointing at a freed struct ip_vs_conn; subsequent lookups in __ip_vs_conn_in_get() dereference freed slab memory, giving a use-after-free read primitive and potential kernel pointer/data disclosure.\nI:H - The same use-after-free lets attackers influence reuse of the freed ip_vs_conn object and corrupt connection state during later hash-table operations, enabling memory corruption exploitable for arbitrary kernel writes or control-flow hijacking.\nA:H - Dereferencing stale conn_tab entries for a freed connection causes kernel oops/panic; the condition is repeatable by sending additional sync traffic to recreate and expire affected UDP synced connections on the backup node."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-29T06:22:30.808Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/06d1d9b56ef8132fbf85006885eb43d9510b8b02"
},
{
"url": "https://git.kernel.org/stable/c/acbdc276091b308ca7794acb86e761f8203e2f59"
},
{
"url": "https://git.kernel.org/stable/c/300348e3ba1521b003d59825f97e24f9a6859688"
},
{
"url": "https://git.kernel.org/stable/c/44af98cc7d5ef8e730488d5df1eecd5deeaa5947"
},
{
"url": "https://git.kernel.org/stable/c/4649e6faeecdc2d44bfa6ccbe405eef27e55d816"
},
{
"url": "https://git.kernel.org/stable/c/b5ee5b266f833601ac4817f6df0bc496fc376a28"
},
{
"url": "https://git.kernel.org/stable/c/e7acfc990c29890c883d0d0ce3f737d003a43b44"
},
{
"url": "https://git.kernel.org/stable/c/a63d2dbaeb50a85d4c976b15a36e6b0c7113db5b"
}
],
"title": "ipvs: do not propagate one-packet flag to synced conns",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80714",
"datePublished": "2026-08-28T06:53:13.069Z",
"dateReserved": "2026-08-26T14:34:25.788Z",
"dateUpdated": "2026-08-29T06:22:30.808Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68363 (GCVE-0-2026-68363)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request
ath9k_hif_request_firmware() re-arms an asynchronous firmware load via
request_firmware_nowait(), passing hif_dev as the completion context, and
then still dereferences hif_dev:
dev_info(&hif_dev->udev->dev, "ath9k_htc: Firmware %s requested\n",
hif_dev->fw_name);
The re-armed callback ath9k_hif_usb_firmware_cb() runs on the "events"
workqueue and, when the firmware is missing, walks the retry chain into
ath9k_hif_usb_firmware_fail() -> complete_all(&hif_dev->fw_done). That
releases the wait_for_completion(&hif_dev->fw_done) in a concurrent
ath9k_hif_usb_disconnect(), which then kfree()s hif_dev. The trailing
dev_info() in the frame that re-armed the request can therefore read freed
memory (hif_dev->udev, the first field of struct hif_device_usb):
BUG: KASAN: slab-use-after-free in ath9k_hif_request_firmware
Read of size 8 ... by task kworker/...
ath9k_hif_request_firmware
ath9k_hif_usb_firmware_cb drivers/net/wireless/ath/ath9k/hif_usb.c:1247
request_firmware_work_func
Allocated by ...:
ath9k_hif_usb_probe drivers/net/wireless/ath/ath9k/hif_usb.c
Freed by ...:
ath9k_hif_usb_disconnect -> kfree drivers/net/wireless/ath/ath9k/hif_usb.c
The fw_done barrier only makes disconnect wait for the firmware chain to
*terminate*; it does not protect the outer ath9k_hif_request_firmware()
frame that re-armed the request and keeps touching hif_dev afterwards.
Drop the post-request dev_info(): it is the only use of hif_dev after the
async request is armed, and it is purely informational (the dev_err() on the
failure path runs only when request_firmware_nowait() did not arm a callback,
so hif_dev is still alive there).
This was first reported by syzbot as a single, non-reproduced crash that was
later auto-obsoleted, and was independently rediscovered by the reFuzz fuzzer,
which produced a C reproducer (USB-gadget connect/disconnect of an ath9k_htc
device whose firmware download fails). The vulnerable code is unchanged and
still present in v7.1-rc6, where the slab-use-after-free reproduces under KASAN
once the (sub-microsecond) race window is widened.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: e904cf6fe23022cde4e0ea9d41601411a315a3dc Version: e904cf6fe23022cde4e0ea9d41601411a315a3dc Version: e904cf6fe23022cde4e0ea9d41601411a315a3dc Version: e904cf6fe23022cde4e0ea9d41601411a315a3dc Version: e904cf6fe23022cde4e0ea9d41601411a315a3dc Version: e904cf6fe23022cde4e0ea9d41601411a315a3dc Version: e904cf6fe23022cde4e0ea9d41601411a315a3dc Version: e904cf6fe23022cde4e0ea9d41601411a315a3dc |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/ath/ath9k/hif_usb.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "47ed81aaa7f94d9808f4719e78a760c2ec1e6c86",
"status": "affected",
"version": "e904cf6fe23022cde4e0ea9d41601411a315a3dc",
"versionType": "git"
},
{
"lessThan": "48de0c6952192b0771fca468df4364d11ec74ad9",
"status": "affected",
"version": "e904cf6fe23022cde4e0ea9d41601411a315a3dc",
"versionType": "git"
},
{
"lessThan": "063497cc9f320ab71a7a937c3bc0a23e630aefe2",
"status": "affected",
"version": "e904cf6fe23022cde4e0ea9d41601411a315a3dc",
"versionType": "git"
},
{
"lessThan": "7f184ca38a90889f3f6665ff96748b95da39dbee",
"status": "affected",
"version": "e904cf6fe23022cde4e0ea9d41601411a315a3dc",
"versionType": "git"
},
{
"lessThan": "10b0ce629123a3737b4eda50188f73bb7be7b68b",
"status": "affected",
"version": "e904cf6fe23022cde4e0ea9d41601411a315a3dc",
"versionType": "git"
},
{
"lessThan": "48a69cedde7388294e4ea6fd804156cd62bc04fc",
"status": "affected",
"version": "e904cf6fe23022cde4e0ea9d41601411a315a3dc",
"versionType": "git"
},
{
"lessThan": "7c9046d92c4b9789c9d9d775e4fd5f34be64cb0a",
"status": "affected",
"version": "e904cf6fe23022cde4e0ea9d41601411a315a3dc",
"versionType": "git"
},
{
"lessThan": "dad9f96945d77ecd4708f730c06ef54dcd8cc057",
"status": "affected",
"version": "e904cf6fe23022cde4e0ea9d41601411a315a3dc",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/ath/ath9k/hif_usb.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.4"
},
{
"lessThan": "4.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath9k: hif_usb: don\u0027t dereference hif_dev after re-arming firmware request\n\nath9k_hif_request_firmware() re-arms an asynchronous firmware load via\nrequest_firmware_nowait(), passing hif_dev as the completion context, and\nthen still dereferences hif_dev:\n\n\tdev_info(\u0026hif_dev-\u003eudev-\u003edev, \"ath9k_htc: Firmware %s requested\\n\",\n\t\t hif_dev-\u003efw_name);\n\nThe re-armed callback ath9k_hif_usb_firmware_cb() runs on the \"events\"\nworkqueue and, when the firmware is missing, walks the retry chain into\nath9k_hif_usb_firmware_fail() -\u003e complete_all(\u0026hif_dev-\u003efw_done). That\nreleases the wait_for_completion(\u0026hif_dev-\u003efw_done) in a concurrent\nath9k_hif_usb_disconnect(), which then kfree()s hif_dev. The trailing\ndev_info() in the frame that re-armed the request can therefore read freed\nmemory (hif_dev-\u003eudev, the first field of struct hif_device_usb):\n\n BUG: KASAN: slab-use-after-free in ath9k_hif_request_firmware\n Read of size 8 ... by task kworker/...\n ath9k_hif_request_firmware\n ath9k_hif_usb_firmware_cb drivers/net/wireless/ath/ath9k/hif_usb.c:1247\n request_firmware_work_func\n Allocated by ...:\n ath9k_hif_usb_probe drivers/net/wireless/ath/ath9k/hif_usb.c\n Freed by ...:\n ath9k_hif_usb_disconnect -\u003e kfree drivers/net/wireless/ath/ath9k/hif_usb.c\n\nThe fw_done barrier only makes disconnect wait for the firmware chain to\n*terminate*; it does not protect the outer ath9k_hif_request_firmware()\nframe that re-armed the request and keeps touching hif_dev afterwards.\n\nDrop the post-request dev_info(): it is the only use of hif_dev after the\nasync request is armed, and it is purely informational (the dev_err() on the\nfailure path runs only when request_firmware_nowait() did not arm a callback,\nso hif_dev is still alive there).\n\nThis was first reported by syzbot as a single, non-reproduced crash that was\nlater auto-obsoleted, and was independently rediscovered by the reFuzz fuzzer,\nwhich produced a C reproducer (USB-gadget connect/disconnect of an ath9k_htc\ndevice whose firmware download fails). The vulnerable code is unchanged and\nstill present in v7.1-rc6, where the slab-use-after-free reproduces under KASAN\nonce the (sub-microsecond) race window is widened."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:18.694Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/47ed81aaa7f94d9808f4719e78a760c2ec1e6c86"
},
{
"url": "https://git.kernel.org/stable/c/48de0c6952192b0771fca468df4364d11ec74ad9"
},
{
"url": "https://git.kernel.org/stable/c/063497cc9f320ab71a7a937c3bc0a23e630aefe2"
},
{
"url": "https://git.kernel.org/stable/c/7f184ca38a90889f3f6665ff96748b95da39dbee"
},
{
"url": "https://git.kernel.org/stable/c/10b0ce629123a3737b4eda50188f73bb7be7b68b"
},
{
"url": "https://git.kernel.org/stable/c/48a69cedde7388294e4ea6fd804156cd62bc04fc"
},
{
"url": "https://git.kernel.org/stable/c/7c9046d92c4b9789c9d9d775e4fd5f34be64cb0a"
},
{
"url": "https://git.kernel.org/stable/c/dad9f96945d77ecd4708f730c06ef54dcd8cc057"
}
],
"title": "wifi: ath9k: hif_usb: don\u0027t dereference hif_dev after re-arming firmware request",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68363",
"datePublished": "2026-08-10T12:03:40.355Z",
"dateReserved": "2026-07-30T09:28:09.385Z",
"dateUpdated": "2026-08-19T16:34:18.694Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74482 (GCVE-0-2026-74482)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-19 16:37
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
mm/huge_memory: unlock i_mmap_rwsem before releasing after-split folios
__folio_split() keeps dereferencing the mapping after the split:
shmem_uncharge(mapping->host) and remap_page() while the folios are still
frozen/locked, and i_mmap_unlock_read(mapping) at the very end, after the
after-split folios have been unlocked and freed.
Nothing holds an inode reference across that. The split relies on @folio
-- which the beyond-EOF drop loop never removes, as it starts at
folio_next(folio) -- staying locked and in the page cache to hold off
eviction. But the unlock loop unlocks @folio before i_mmap_unlock_read()
runs. If the caller's @lock_at is a tail beyond EOF, as memory_failure()
passes when splitting a poisoned tail of a shmem THP that reaches past
i_size during truncation, it too is gone from the page cache; so once
@folio is unlocked no locked, in-cache folio pins the inode, and a
concurrent final iput() can evict and RCU-free it before
i_mmap_unlock_read() touches i_mmap_rwsem:
BUG: KASAN: slab-use-after-free in __up_read+0x634/0x790
i_mmap_unlock_read include/linux/fs.h:537 [inline]
__folio_split+0x732/0x1640 mm/huge_memory.c:4100
try_to_split_thp_page+0xab/0x390 mm/memory-failure.c:1675
memory_failure+0x1394/0x26e0 mm/memory-failure.c:2470
Freed by task 4601:
shmem_free_in_core_inode+0x54/0xb0 mm/shmem.c:5177
evict+0x57f/0xac0 fs/inode.c:870
Do every mapping dereference while @folio still pins the inode: drop
i_mmap_rwsem right after remap_page(), before the loop that unlocks and
frees the after-split folios, and clear @mapping so the exit path does not
unlock it again. shmem_uncharge() and remap_page() already run before
that point, so after this nothing past the unlock loop touches the inode
or the mapping.
This is now a rule the split depends on, alongside keeping @folio frozen
until the page cache is updated: no inode or mapping dereference once the
after-split folios start being unlocked.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: baa355fd331424526e742d41d9b90d5f9d10f716 Version: baa355fd331424526e742d41d9b90d5f9d10f716 Version: baa355fd331424526e742d41d9b90d5f9d10f716 Version: baa355fd331424526e742d41d9b90d5f9d10f716 Version: baa355fd331424526e742d41d9b90d5f9d10f716 Version: baa355fd331424526e742d41d9b90d5f9d10f716 Version: baa355fd331424526e742d41d9b90d5f9d10f716 Version: baa355fd331424526e742d41d9b90d5f9d10f716 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"mm/huge_memory.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "bc2f5eabaaf60ec18da70b619a8fba1bfb7dea3a",
"status": "affected",
"version": "baa355fd331424526e742d41d9b90d5f9d10f716",
"versionType": "git"
},
{
"lessThan": "f87c08060818ebb19bafed37c38244538da25097",
"status": "affected",
"version": "baa355fd331424526e742d41d9b90d5f9d10f716",
"versionType": "git"
},
{
"lessThan": "6f5c272d71845a669e4c8ee5c72b376e29a0e6e5",
"status": "affected",
"version": "baa355fd331424526e742d41d9b90d5f9d10f716",
"versionType": "git"
},
{
"lessThan": "be106f7855f03d3128ed0ce70ba74b484a90b473",
"status": "affected",
"version": "baa355fd331424526e742d41d9b90d5f9d10f716",
"versionType": "git"
},
{
"lessThan": "e3dd774dbfd0b5bc2dbd0995221751b1234f8205",
"status": "affected",
"version": "baa355fd331424526e742d41d9b90d5f9d10f716",
"versionType": "git"
},
{
"lessThan": "10065fb891651d9541e7a5a2db84c1e656ece4f9",
"status": "affected",
"version": "baa355fd331424526e742d41d9b90d5f9d10f716",
"versionType": "git"
},
{
"lessThan": "d640efe94d86d3be893d4c19220362546a637e90",
"status": "affected",
"version": "baa355fd331424526e742d41d9b90d5f9d10f716",
"versionType": "git"
},
{
"lessThan": "e923bd21058ea02fd0dcd3549d151d143fd036e5",
"status": "affected",
"version": "baa355fd331424526e742d41d9b90d5f9d10f716",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"mm/huge_memory.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.8"
},
{
"lessThan": "4.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/huge_memory: unlock i_mmap_rwsem before releasing after-split folios\n\n__folio_split() keeps dereferencing the mapping after the split:\nshmem_uncharge(mapping-\u003ehost) and remap_page() while the folios are still\nfrozen/locked, and i_mmap_unlock_read(mapping) at the very end, after the\nafter-split folios have been unlocked and freed.\n\nNothing holds an inode reference across that. The split relies on @folio\n-- which the beyond-EOF drop loop never removes, as it starts at\nfolio_next(folio) -- staying locked and in the page cache to hold off\neviction. But the unlock loop unlocks @folio before i_mmap_unlock_read()\nruns. If the caller\u0027s @lock_at is a tail beyond EOF, as memory_failure()\npasses when splitting a poisoned tail of a shmem THP that reaches past\ni_size during truncation, it too is gone from the page cache; so once\n@folio is unlocked no locked, in-cache folio pins the inode, and a\nconcurrent final iput() can evict and RCU-free it before\ni_mmap_unlock_read() touches i_mmap_rwsem:\n\n BUG: KASAN: slab-use-after-free in __up_read+0x634/0x790\n i_mmap_unlock_read include/linux/fs.h:537 [inline]\n __folio_split+0x732/0x1640 mm/huge_memory.c:4100\n try_to_split_thp_page+0xab/0x390 mm/memory-failure.c:1675\n memory_failure+0x1394/0x26e0 mm/memory-failure.c:2470\n\n Freed by task 4601:\n shmem_free_in_core_inode+0x54/0xb0 mm/shmem.c:5177\n evict+0x57f/0xac0 fs/inode.c:870\n\nDo every mapping dereference while @folio still pins the inode: drop\ni_mmap_rwsem right after remap_page(), before the loop that unlocks and\nfrees the after-split folios, and clear @mapping so the exit path does not\nunlock it again. shmem_uncharge() and remap_page() already run before\nthat point, so after this nothing past the unlock loop touches the inode\nor the mapping.\n\nThis is now a rule the split depends on, alongside keeping @folio frozen\nuntil the page cache is updated: no inode or mapping dereference once the\nafter-split folios start being unlocked."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The UAF is in __folio_split() on the memory_failure()-\u003etry_to_split_thp_page() path while splitting file-backed shmem THPs; reachability is via local syscalls (memfd/mmap/madvise/ftruncate) or admin hwpoison injection, not network or physical interfaces.\nAC:L - An attacker can deterministically create a shmem THP with tail pages beyond EOF and race MADV_HWPOISON-driven memory_failure() against concurrent truncate/close(iput) using attacker-controlled threads; both sides of the race are attacker-driven.\nPR:L - Reliable exploitation uses MADV_HWPOISON to invoke memory_failure() on a chosen tail page; CAP_SYS_ADMIN is available to user-namespace/container root, and the shmem THP setup needs only ordinary local mapping and truncation privileges.\nUI:N - No separate victim action is required; the attacker creates, maps, poisons, and truncates their own memfd/shmem/tmpfs object to reach the vulnerable split path.\nS:U - Impact is a kernel slab use-after-free on inode/mapping metadata in core MM within the same kernel security domain, not a VM escape, sandbox breakout, or other cross-authority boundary violation.\nC:H - KASAN reports slab-use-after-free in i_mmap_unlock_read() after shmem_free_in_core_inode() RCU-frees the inode; this inode/mapping UAF can be heap-sprayed into an arbitrary kernel memory read primitive.\nI:H - The same UAF corrupts freed inode slab objects and i_mmap_rwsem state, enabling heap grooming for arbitrary kernel writes and potential privilege escalation via control-flow hijacking per kernel UAF guidance.\nA:H - The use-after-free provokes a KASAN BUG/oops during i_mmap_unlock_read() and corrupts core MM inode state, capable of kernel panic or hang when triggered on production shmem/tmpfs workloads."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:37:38.544Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/bc2f5eabaaf60ec18da70b619a8fba1bfb7dea3a"
},
{
"url": "https://git.kernel.org/stable/c/f87c08060818ebb19bafed37c38244538da25097"
},
{
"url": "https://git.kernel.org/stable/c/6f5c272d71845a669e4c8ee5c72b376e29a0e6e5"
},
{
"url": "https://git.kernel.org/stable/c/be106f7855f03d3128ed0ce70ba74b484a90b473"
},
{
"url": "https://git.kernel.org/stable/c/e3dd774dbfd0b5bc2dbd0995221751b1234f8205"
},
{
"url": "https://git.kernel.org/stable/c/10065fb891651d9541e7a5a2db84c1e656ece4f9"
},
{
"url": "https://git.kernel.org/stable/c/d640efe94d86d3be893d4c19220362546a637e90"
},
{
"url": "https://git.kernel.org/stable/c/e923bd21058ea02fd0dcd3549d151d143fd036e5"
}
],
"title": "mm/huge_memory: unlock i_mmap_rwsem before releasing after-split folios",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74482",
"datePublished": "2026-08-15T12:27:15.083Z",
"dateReserved": "2026-08-15T05:44:03.904Z",
"dateUpdated": "2026-08-19T16:37:38.544Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74680 (GCVE-0-2026-74680)
Vulnerability from cvelistv5
Published
2026-08-22 15:32
Modified
2026-08-22 15:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
usb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm()
If cxacru_cm() encounters an error while submitting or waiting for snd_urb,
it aborts and returns the error without killing the already submitted
rcv_urb. This leaves the rcv_urb active.
When this happens during initialization (e.g., in cxacru_atm_start()), the
driver may ignore the error and proceed to call cxacru_poll_status(), which
invokes cxacru_cm() again. Attempting to submit the still-active rcv_urb
triggers a warning in usb_submit_urb():
cxacru 1-1:1.0: send of cm 0x84 failed (-104)
ATM dev 0: cxacru_atm_start: CHIP_ADSL_LINE_START returned -104
------------[ cut here ]------------
URB ffff88812658d200 submitted while active
WARNING: drivers/usb/core/urb.c:379 at usb_submit_urb+0x79/0x18b0
drivers/usb/core/urb.c:379
...
Call Trace:
<TASK>
cxacru_cm+0x21a/0xf10 drivers/usb/atm/cxacru.c:631
cxacru_cm_get_array drivers/usb/atm/cxacru.c:722 [inline]
cxacru_poll_status+0x178/0x1110 drivers/usb/atm/cxacru.c:828
cxacru_atm_start+0x185/0x360 drivers/usb/atm/cxacru.c:814
usbatm_atm_init+0x144/0x3a0 drivers/usb/atm/usbatm.c:927
usbatm_usb_probe+0x15cb/0x1db0 drivers/usb/atm/usbatm.c:1178
cxacru_usb_probe+0x17f/0x220 drivers/usb/atm/cxacru.c:1370
...
To fix this, ensure that rcv_urb is properly killed if cxacru_cm() aborts
early. We can safely call usb_kill_urb() on rcv_urb in the error path, as
it is safe to call even if the URB is not active (e.g., if it failed to
submit in the first place, or if it already completed).
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1b0e614652344a2d39eb336f3dc07651782883bf Version: 1b0e614652344a2d39eb336f3dc07651782883bf Version: 1b0e614652344a2d39eb336f3dc07651782883bf Version: 1b0e614652344a2d39eb336f3dc07651782883bf Version: 1b0e614652344a2d39eb336f3dc07651782883bf Version: 1b0e614652344a2d39eb336f3dc07651782883bf Version: 1b0e614652344a2d39eb336f3dc07651782883bf Version: 1b0e614652344a2d39eb336f3dc07651782883bf |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/atm/cxacru.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "6133b461058316e3ccba7331f974d110d4c08b23",
"status": "affected",
"version": "1b0e614652344a2d39eb336f3dc07651782883bf",
"versionType": "git"
},
{
"lessThan": "61093d7f1144f6a15bac505df35e5f535ade2ac1",
"status": "affected",
"version": "1b0e614652344a2d39eb336f3dc07651782883bf",
"versionType": "git"
},
{
"lessThan": "645d98dbccdbfdbf0129f48822af7183492de091",
"status": "affected",
"version": "1b0e614652344a2d39eb336f3dc07651782883bf",
"versionType": "git"
},
{
"lessThan": "993f7677949e3d72e360e86eed1f41c2511f75ed",
"status": "affected",
"version": "1b0e614652344a2d39eb336f3dc07651782883bf",
"versionType": "git"
},
{
"lessThan": "939b6a41f681aea52af678053072ee443068e93e",
"status": "affected",
"version": "1b0e614652344a2d39eb336f3dc07651782883bf",
"versionType": "git"
},
{
"lessThan": "2f73a065791d2a8e3f0bdf29248e33600359e865",
"status": "affected",
"version": "1b0e614652344a2d39eb336f3dc07651782883bf",
"versionType": "git"
},
{
"lessThan": "0af047703dbed8224552587ed436f14a24371b46",
"status": "affected",
"version": "1b0e614652344a2d39eb336f3dc07651782883bf",
"versionType": "git"
},
{
"lessThan": "c2f811314be351d86b6ab41e9297ae80d8da6f86",
"status": "affected",
"version": "1b0e614652344a2d39eb336f3dc07651782883bf",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/usb/atm/cxacru.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.13"
},
{
"lessThan": "2.6.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "2.6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "2.6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "2.6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "2.6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm()\n\nIf cxacru_cm() encounters an error while submitting or waiting for snd_urb,\nit aborts and returns the error without killing the already submitted\nrcv_urb. This leaves the rcv_urb active.\n\nWhen this happens during initialization (e.g., in cxacru_atm_start()), the\ndriver may ignore the error and proceed to call cxacru_poll_status(), which\ninvokes cxacru_cm() again. Attempting to submit the still-active rcv_urb\ntriggers a warning in usb_submit_urb():\n\ncxacru 1-1:1.0: send of cm 0x84 failed (-104)\nATM dev 0: cxacru_atm_start: CHIP_ADSL_LINE_START returned -104\n------------[ cut here ]------------\nURB ffff88812658d200 submitted while active\nWARNING: drivers/usb/core/urb.c:379 at usb_submit_urb+0x79/0x18b0\ndrivers/usb/core/urb.c:379\n...\nCall Trace:\n \u003cTASK\u003e\n cxacru_cm+0x21a/0xf10 drivers/usb/atm/cxacru.c:631\n cxacru_cm_get_array drivers/usb/atm/cxacru.c:722 [inline]\n cxacru_poll_status+0x178/0x1110 drivers/usb/atm/cxacru.c:828\n cxacru_atm_start+0x185/0x360 drivers/usb/atm/cxacru.c:814\n usbatm_atm_init+0x144/0x3a0 drivers/usb/atm/usbatm.c:927\n usbatm_usb_probe+0x15cb/0x1db0 drivers/usb/atm/usbatm.c:1178\n cxacru_usb_probe+0x17f/0x220 drivers/usb/atm/cxacru.c:1370\n...\n\nTo fix this, ensure that rcv_urb is properly killed if cxacru_cm() aborts\nearly. We can safely call usb_kill_urb() on rcv_urb in the error path, as\nit is safe to call even if the URB is not active (e.g., if it failed to\nsubmit in the first place, or if it already completed)."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-22T15:32:48.230Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/6133b461058316e3ccba7331f974d110d4c08b23"
},
{
"url": "https://git.kernel.org/stable/c/61093d7f1144f6a15bac505df35e5f535ade2ac1"
},
{
"url": "https://git.kernel.org/stable/c/645d98dbccdbfdbf0129f48822af7183492de091"
},
{
"url": "https://git.kernel.org/stable/c/993f7677949e3d72e360e86eed1f41c2511f75ed"
},
{
"url": "https://git.kernel.org/stable/c/939b6a41f681aea52af678053072ee443068e93e"
},
{
"url": "https://git.kernel.org/stable/c/2f73a065791d2a8e3f0bdf29248e33600359e865"
},
{
"url": "https://git.kernel.org/stable/c/0af047703dbed8224552587ed436f14a24371b46"
},
{
"url": "https://git.kernel.org/stable/c/c2f811314be351d86b6ab41e9297ae80d8da6f86"
}
],
"title": "usb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74680",
"datePublished": "2026-08-22T15:32:48.230Z",
"dateReserved": "2026-08-15T05:44:03.925Z",
"dateUpdated": "2026-08-22T15:32:48.230Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80560 (GCVE-0-2026-80560)
Vulnerability from cvelistv5
Published
2026-08-26 14:37
Modified
2026-08-27 05:01
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
openrisc: signal: do not restore privileged SR bits on sigreturn
restore_sigcontext() copies the whole supervision register (SR) from the
signal frame and only clears SPR_SR_SM before the value is reloaded into
the hardware SR (through ESR and l.rfe) on the return to user space. All
other SR bits are left under user control.
An unprivileged task can thus return from a signal handler through a
crafted sigframe that clears SPR_SR_DME. With the data MMU disabled the
CPU performs no translation or protection on data accesses, so the task
gains read and write access to arbitrary physical memory, a local
privilege escalation. SPR_SR_IME, SPR_SR_SUMRA, SPR_SR_LEE, SPR_SR_EPH
and the cache-enable bits are exposed the same way. The ptrace GPR regset
already refuses any change to SR for exactly this reason.
Restore only the arithmetic flag bits (F, CY, OV) from the signal frame
and take every privileged control bit from the SR the kernel saved on
signal entry.
Verified with qemu-system-or1k -M or1k-sim: before this change an
unprivileged PoC clears SPR_SR_DME in rt_sigreturn and writes a marker to
physical address 0x03000000 (beyond the kernel's mem=32M); afterwards the
same PoC receives SIGSEGV and physical memory is unchanged.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ac689eb7f9d4e270d1365853b82eece669387e2c Version: ac689eb7f9d4e270d1365853b82eece669387e2c Version: ac689eb7f9d4e270d1365853b82eece669387e2c Version: ac689eb7f9d4e270d1365853b82eece669387e2c Version: ac689eb7f9d4e270d1365853b82eece669387e2c Version: ac689eb7f9d4e270d1365853b82eece669387e2c Version: ac689eb7f9d4e270d1365853b82eece669387e2c Version: ac689eb7f9d4e270d1365853b82eece669387e2c |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"arch/openrisc/include/asm/processor.h",
"arch/openrisc/kernel/signal.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "bc2e24ba6e167ccf374a197457aa5640a802f429",
"status": "affected",
"version": "ac689eb7f9d4e270d1365853b82eece669387e2c",
"versionType": "git"
},
{
"lessThan": "cf1b5514ddf9df098ce7e3741fc9679fd85a4ec6",
"status": "affected",
"version": "ac689eb7f9d4e270d1365853b82eece669387e2c",
"versionType": "git"
},
{
"lessThan": "cd8b43a71755c516f5c1f265a103438ae9ab15be",
"status": "affected",
"version": "ac689eb7f9d4e270d1365853b82eece669387e2c",
"versionType": "git"
},
{
"lessThan": "b4d73c3848bae9084fa8b9b2aa76d99a7d8eb17d",
"status": "affected",
"version": "ac689eb7f9d4e270d1365853b82eece669387e2c",
"versionType": "git"
},
{
"lessThan": "89a91b30685c0493b0fa2b47d0ab41061a63069d",
"status": "affected",
"version": "ac689eb7f9d4e270d1365853b82eece669387e2c",
"versionType": "git"
},
{
"lessThan": "a88d688be8d7f03cbf927f2ab454ea9fa58d2979",
"status": "affected",
"version": "ac689eb7f9d4e270d1365853b82eece669387e2c",
"versionType": "git"
},
{
"lessThan": "212fc482ddd7f9ccdd74a05eab1cac849350dcd6",
"status": "affected",
"version": "ac689eb7f9d4e270d1365853b82eece669387e2c",
"versionType": "git"
},
{
"lessThan": "32ef1b30ad736519f7a207bcc2986f3d4129d972",
"status": "affected",
"version": "ac689eb7f9d4e270d1365853b82eece669387e2c",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"arch/openrisc/include/asm/processor.h",
"arch/openrisc/kernel/signal.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.1"
},
{
"lessThan": "3.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.46",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.10",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nopenrisc: signal: do not restore privileged SR bits on sigreturn\n\nrestore_sigcontext() copies the whole supervision register (SR) from the\nsignal frame and only clears SPR_SR_SM before the value is reloaded into\nthe hardware SR (through ESR and l.rfe) on the return to user space. All\nother SR bits are left under user control.\n\nAn unprivileged task can thus return from a signal handler through a\ncrafted sigframe that clears SPR_SR_DME. With the data MMU disabled the\nCPU performs no translation or protection on data accesses, so the task\ngains read and write access to arbitrary physical memory, a local\nprivilege escalation. SPR_SR_IME, SPR_SR_SUMRA, SPR_SR_LEE, SPR_SR_EPH\nand the cache-enable bits are exposed the same way. The ptrace GPR regset\nalready refuses any change to SR for exactly this reason.\n\nRestore only the arithmetic flag bits (F, CY, OV) from the signal frame\nand take every privileged control bit from the SR the kernel saved on\nsignal entry.\n\nVerified with qemu-system-or1k -M or1k-sim: before this change an\nunprivileged PoC clears SPR_SR_DME in rt_sigreturn and writes a marker to\nphysical address 0x03000000 (beyond the kernel\u0027s mem=32M); afterwards the\nsame PoC receives SIGSEGV and physical memory is unchanged."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The flaw is only reachable through the local rt_sigreturn syscall path (userspace trap to _sys_call_handler, sys_rt_sigreturn, restore_sigcontext, then l.rfe); OpenRISC signal handling has no network, adjacent-wireless, or physical-device entry point.\nAC:L - Exploitation is deterministic because the attacker fully controls the rt_sigframe SR field and can invoke rt_sigreturn directly; the fix author verified an unprivileged PoC on qemu-system-or1k that clears SPR_SR_DME and writes arbitrary physical memory.\nPR:L - Any unprivileged local process can call rt_sigreturn with a crafted sigframe on its own stack; the path performs only access_ok/copy_from_user checks and has no capability, authentication, or init-namespace root requirement.\nUI:N - No separate victim interaction is needed; the attacker can self-send a signal or directly syscall rt_sigreturn with a forged stack frame in their own process without requiring another user to mount, plug in, or approve anything.\nS:U - This is standard host-kernel privilege escalation by restoring attacker-controlled CPU privilege bits on sigreturn; it does not cross a VM guest/host, container sandbox, or IOMMU security boundary despite granting direct physical memory access.\nC:H - Clearing SPR_SR_DME disables data MMU translation and protection, allowing an unprivileged task to read arbitrary physical addresses including kernel memory; other exposed SR bits (SPR_SR_IME, SPR_SR_SUMRA, cache enables) further broaden privileged-state disclosure.\nI:H - With SPR_SR_DME cleared the CPU performs unprotected physical data accesses, giving arbitrary read/write to all of RAM; the fix commit PoC writes a marker beyond the kernel mem=32M reservation, demonstrating direct integrity compromise and local root escalation.\nA:H - Arbitrary physical memory writes can corrupt kernel text, data, or device MMIO and trigger oops or panic; manipulating privileged SR and cache-control bits can also destabilize the system even when full exploitation is not attempted."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T05:01:48.838Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/bc2e24ba6e167ccf374a197457aa5640a802f429"
},
{
"url": "https://git.kernel.org/stable/c/cf1b5514ddf9df098ce7e3741fc9679fd85a4ec6"
},
{
"url": "https://git.kernel.org/stable/c/cd8b43a71755c516f5c1f265a103438ae9ab15be"
},
{
"url": "https://git.kernel.org/stable/c/b4d73c3848bae9084fa8b9b2aa76d99a7d8eb17d"
},
{
"url": "https://git.kernel.org/stable/c/89a91b30685c0493b0fa2b47d0ab41061a63069d"
},
{
"url": "https://git.kernel.org/stable/c/a88d688be8d7f03cbf927f2ab454ea9fa58d2979"
},
{
"url": "https://git.kernel.org/stable/c/212fc482ddd7f9ccdd74a05eab1cac849350dcd6"
},
{
"url": "https://git.kernel.org/stable/c/32ef1b30ad736519f7a207bcc2986f3d4129d972"
}
],
"title": "openrisc: signal: do not restore privileged SR bits on sigreturn",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80560",
"datePublished": "2026-08-26T14:37:25.971Z",
"dateReserved": "2026-08-26T14:34:25.767Z",
"dateUpdated": "2026-08-27T05:01:48.838Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2025-40206 (GCVE-0-2025-40206)
Vulnerability from cvelistv5
Published
2025-11-12 21:56
Modified
2026-08-23 12:45
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nft_objref: validate objref and objrefmap expressions
Referencing a synproxy stateful object from OUTPUT hook causes kernel
crash due to infinite recursive calls:
BUG: TASK stack guard page was hit at 000000008bda5b8c (stack is 000000003ab1c4a5..00000000494d8b12)
[...]
Call Trace:
__find_rr_leaf+0x99/0x230
fib6_table_lookup+0x13b/0x2d0
ip6_pol_route+0xa4/0x400
fib6_rule_lookup+0x156/0x240
ip6_route_output_flags+0xc6/0x150
__nf_ip6_route+0x23/0x50
synproxy_send_tcp_ipv6+0x106/0x200
synproxy_send_client_synack_ipv6+0x1aa/0x1f0
nft_synproxy_do_eval+0x263/0x310
nft_do_chain+0x5a8/0x5f0 [nf_tables
nft_do_chain_inet+0x98/0x110
nf_hook_slow+0x43/0xc0
__ip6_local_out+0xf0/0x170
ip6_local_out+0x17/0x70
synproxy_send_tcp_ipv6+0x1a2/0x200
synproxy_send_client_synack_ipv6+0x1aa/0x1f0
[...]
Implement objref and objrefmap expression validate functions.
Currently, only NFT_OBJECT_SYNPROXY object type requires validation.
This will also handle a jump to a chain using a synproxy object from the
OUTPUT hook.
Now when trying to reference a synproxy object in the OUTPUT hook, nft
will produce the following error:
synproxy_crash.nft: Error: Could not process rule: Operation not supported
synproxy name mysynproxy
^^^^^^^^^^^^^^^^^^^^^^^^
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/netfilter/nft_objref.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "f31bcea12222a26d6f151df9c4a6d21f2eec1724",
"status": "affected",
"version": "ee394f96ad7517fbc0de9106dcc7ce9efb14f264",
"versionType": "git"
},
{
"lessThan": "0028e0134c64d9ed21728341a74fcfc59cd0f944",
"status": "affected",
"version": "ee394f96ad7517fbc0de9106dcc7ce9efb14f264",
"versionType": "git"
},
{
"lessThan": "7ea55a44493a5a36c3b3293b88bbe4841f9dbaf0",
"status": "affected",
"version": "ee394f96ad7517fbc0de9106dcc7ce9efb14f264",
"versionType": "git"
},
{
"lessThan": "4c1cf72ec10be5a9ad264650cadffa1fbce6fabd",
"status": "affected",
"version": "ee394f96ad7517fbc0de9106dcc7ce9efb14f264",
"versionType": "git"
},
{
"lessThan": "f359b809d54c6e3dd1d039b97e0b68390b0e53e4",
"status": "affected",
"version": "ee394f96ad7517fbc0de9106dcc7ce9efb14f264",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/netfilter/nft_objref.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.4"
},
{
"lessThan": "5.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.113",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.54",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.17.*",
"status": "unaffected",
"version": "6.17.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "6.18",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.113",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.54",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.17.4",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18",
"versionStartIncluding": "5.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_objref: validate objref and objrefmap expressions\n\nReferencing a synproxy stateful object from OUTPUT hook causes kernel\ncrash due to infinite recursive calls:\n\nBUG: TASK stack guard page was hit at 000000008bda5b8c (stack is 000000003ab1c4a5..00000000494d8b12)\n[...]\nCall Trace:\n __find_rr_leaf+0x99/0x230\n fib6_table_lookup+0x13b/0x2d0\n ip6_pol_route+0xa4/0x400\n fib6_rule_lookup+0x156/0x240\n ip6_route_output_flags+0xc6/0x150\n __nf_ip6_route+0x23/0x50\n synproxy_send_tcp_ipv6+0x106/0x200\n synproxy_send_client_synack_ipv6+0x1aa/0x1f0\n nft_synproxy_do_eval+0x263/0x310\n nft_do_chain+0x5a8/0x5f0 [nf_tables\n nft_do_chain_inet+0x98/0x110\n nf_hook_slow+0x43/0xc0\n __ip6_local_out+0xf0/0x170\n ip6_local_out+0x17/0x70\n synproxy_send_tcp_ipv6+0x1a2/0x200\n synproxy_send_client_synack_ipv6+0x1aa/0x1f0\n[...]\n\nImplement objref and objrefmap expression validate functions.\n\nCurrently, only NFT_OBJECT_SYNPROXY object type requires validation.\nThis will also handle a jump to a chain using a synproxy object from the\nOUTPUT hook.\n\nNow when trying to reference a synproxy object in the OUTPUT hook, nft\nwill produce the following error:\n\nsynproxy_crash.nft: Error: Could not process rule: Operation not supported\n synproxy name mysynproxy\n ^^^^^^^^^^^^^^^^^^^^^^^^"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The flaw is enabled through an nftables ruleset installed over the NFNL_SUBSYS_NFTABLES netlink socket, and triggered by a locally-generated TCP SYN traversing the OUTPUT hook. Per netfilter/nftables convention this is a local attack surface, not a remotely reachable one.\nAC:L - Exploitation is fully deterministic \u2014 add a synproxy object reference to an OUTPUT base chain and emit any TCP SYN; there is no race, no memory-layout dependency, and no bound on the recursion depth. CONFIG_NFT_SYNPROXY is standard and autoloadable on distribution kernels.\nPR:L - nfnetlink_rcv checks netlink_net_capable(skb, CAP_NET_ADMIN), which evaluates against the network namespace\u0027s owning user namespace, so any unprivileged local user obtains it via `unshare -Urn`; nft_synproxy_do_init imposes no init_user_ns requirement. The resulting stack overflow is not confined to the namespace and takes down the host.\nUI:N - The attacker performs both steps \u2014 installing the rule and emitting the triggering SYN \u2014 with no action required from any other user or administrator.\nS:U - The recursion, the stack exhaustion, and the resulting panic all occur within the kernel\u0027s own security authority; no hypervisor, IOMMU, or other trust boundary is crossed.\nC:H - The unbounded recursion exhausts the kernel stack, and on the many embedded/IoT/automotive configurations lacking CONFIG_VMAP_STACK (arm32 without ARM_HAS_GROUP_RELOCS, and architectures with no VMAP_STACK support) it runs past the stack into adjacent kernel pages rather than into a guard page, corrupting neighbouring structures that can be leveraged for kernel memory disclosure.\nI:H - On those same non-VMAP_STACK configurations the overrun writes attacker-influenced frame contents \u2014 struct flowi6 built from the attacker\u0027s SYN addresses/ports, synproxy_options with attacker-chosen MSS/wscale/timestamps, and nft_regs \u2014 into adjacent kernel memory, and on architectures where thread_info sits at the stack base it clobbers that first, yielding an exploitable corruption primitive.\nA:H - The infinite recursion reliably exhausts the kernel stack and hits the guard page, producing an immediate kernel panic as shown in the reporter\u0027s trace. This is a complete denial of service triggerable at will by an unprivileged local user."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:45:25.956Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/f31bcea12222a26d6f151df9c4a6d21f2eec1724"
},
{
"url": "https://git.kernel.org/stable/c/0028e0134c64d9ed21728341a74fcfc59cd0f944"
},
{
"url": "https://git.kernel.org/stable/c/7ea55a44493a5a36c3b3293b88bbe4841f9dbaf0"
},
{
"url": "https://git.kernel.org/stable/c/4c1cf72ec10be5a9ad264650cadffa1fbce6fabd"
},
{
"url": "https://git.kernel.org/stable/c/f359b809d54c6e3dd1d039b97e0b68390b0e53e4"
}
],
"title": "netfilter: nft_objref: validate objref and objrefmap expressions",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2025-40206",
"datePublished": "2025-11-12T21:56:35.675Z",
"dateReserved": "2025-04-16T07:20:57.179Z",
"dateUpdated": "2026-08-23T12:45:25.956Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68430 (GCVE-0-2026-68430)
Vulnerability from cvelistv5
Published
2026-08-12 00:07
Modified
2026-08-19 16:35
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu/gfx8: drop unecessary BUG_ON()
There's no need to crash the kernel for this case.
(cherry picked from commit 4d7c25208ca612b754f3bf39e9f16e725b828891)
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 4e638ae9c1e7a2b85155f2dd91c8105ce109ea7e Version: 4e638ae9c1e7a2b85155f2dd91c8105ce109ea7e Version: 4e638ae9c1e7a2b85155f2dd91c8105ce109ea7e Version: 4e638ae9c1e7a2b85155f2dd91c8105ce109ea7e Version: 4e638ae9c1e7a2b85155f2dd91c8105ce109ea7e Version: 4e638ae9c1e7a2b85155f2dd91c8105ce109ea7e Version: 4e638ae9c1e7a2b85155f2dd91c8105ce109ea7e Version: 4e638ae9c1e7a2b85155f2dd91c8105ce109ea7e |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/gfx_v8_0.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "69004f1f769f7f6e9e34f4390d98a12aa0b4ab98",
"status": "affected",
"version": "4e638ae9c1e7a2b85155f2dd91c8105ce109ea7e",
"versionType": "git"
},
{
"lessThan": "26ad939b402a754b0624840dfaeebd86d7ff2a22",
"status": "affected",
"version": "4e638ae9c1e7a2b85155f2dd91c8105ce109ea7e",
"versionType": "git"
},
{
"lessThan": "0027afe3dc97a4964a9ea0fb5a3457de06d85f5b",
"status": "affected",
"version": "4e638ae9c1e7a2b85155f2dd91c8105ce109ea7e",
"versionType": "git"
},
{
"lessThan": "ab05af6c345bc8460052c60de657ce6d4a2386f7",
"status": "affected",
"version": "4e638ae9c1e7a2b85155f2dd91c8105ce109ea7e",
"versionType": "git"
},
{
"lessThan": "2404600dca5c0979485c6f2d9c62bd356a98870a",
"status": "affected",
"version": "4e638ae9c1e7a2b85155f2dd91c8105ce109ea7e",
"versionType": "git"
},
{
"lessThan": "f70bd5235d9efc2ee2f70293eea51888c5f2a54d",
"status": "affected",
"version": "4e638ae9c1e7a2b85155f2dd91c8105ce109ea7e",
"versionType": "git"
},
{
"lessThan": "db85aa861b8214fa0d1d8405c01488f604a455a0",
"status": "affected",
"version": "4e638ae9c1e7a2b85155f2dd91c8105ce109ea7e",
"versionType": "git"
},
{
"lessThan": "84a1a8a952ab4b8c23c5dd1f2eea4049cb4914f5",
"status": "affected",
"version": "4e638ae9c1e7a2b85155f2dd91c8105ce109ea7e",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/gfx_v8_0.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.11"
},
{
"lessThan": "4.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/gfx8: drop unecessary BUG_ON()\n\nThere\u0027s no need to crash the kernel for this case.\n\n(cherry picked from commit 4d7c25208ca612b754f3bf39e9f16e725b828891)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:35:27.984Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/69004f1f769f7f6e9e34f4390d98a12aa0b4ab98"
},
{
"url": "https://git.kernel.org/stable/c/26ad939b402a754b0624840dfaeebd86d7ff2a22"
},
{
"url": "https://git.kernel.org/stable/c/0027afe3dc97a4964a9ea0fb5a3457de06d85f5b"
},
{
"url": "https://git.kernel.org/stable/c/ab05af6c345bc8460052c60de657ce6d4a2386f7"
},
{
"url": "https://git.kernel.org/stable/c/2404600dca5c0979485c6f2d9c62bd356a98870a"
},
{
"url": "https://git.kernel.org/stable/c/f70bd5235d9efc2ee2f70293eea51888c5f2a54d"
},
{
"url": "https://git.kernel.org/stable/c/db85aa861b8214fa0d1d8405c01488f604a455a0"
},
{
"url": "https://git.kernel.org/stable/c/84a1a8a952ab4b8c23c5dd1f2eea4049cb4914f5"
}
],
"title": "drm/amdgpu/gfx8: drop unecessary BUG_ON()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68430",
"datePublished": "2026-08-12T00:07:15.927Z",
"dateReserved": "2026-07-30T09:28:09.393Z",
"dateUpdated": "2026-08-19T16:35:27.984Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80796 (GCVE-0-2026-80796)
Vulnerability from cvelistv5
Published
2026-09-04 15:13
Modified
2026-09-04 15:13
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
nfc: nci: add data_len bound checks to activation parameter extractors
nci_extract_activation_params_iso_dep() and
nci_extract_activation_params_nfc_dep() read an inner length byte from
the NCI RF_INTF_ACTIVATED_NTF payload and use it to memcpy() into fixed
kernel buffers, but neither function receives the caller-validated
activation_params_len. A crafted NCI notification with
activation_params_len=1 and an inner length byte of up to 20 (NFC-A) or
50 (NFC-B) causes memcpy() to read that many bytes past the one valid
byte in the activation params region -- a slab out-of-bounds read of
kernel memory adjacent to the NCI skb.
The sibling nci_extract_rf_params_*() family was given equivalent
protection by commit 571dcbeb8e63 ("net: nfc: nci: Fix parameter
validation for packet data"), but the two activation parameter
extractors were not updated at that time.
Add a data_len parameter to both functions, guard against an empty
region before consuming the inner length byte, decrement the remaining
count after consuming it, and clamp the copy length to what is actually
available. Update both call sites to pass ntf.activation_params_len,
which is already validated against the skb at ntf.c:801.
References
| URL | Tags | ||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20 Version: e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20 Version: e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20 Version: e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20 Version: e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20 Version: e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20 Version: e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20 Version: e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20 Version: e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/nfc/nci/ntf.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "1168484fe2b3828bf24a46f3c42a8719fade679b",
"status": "affected",
"version": "e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20",
"versionType": "git"
},
{
"lessThan": "be311c0cfeadfbe815ea22d2914a98d06e3fab0e",
"status": "affected",
"version": "e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20",
"versionType": "git"
},
{
"lessThan": "04e51353cb9fa321caaeeed8331d4cd041fbaca7",
"status": "affected",
"version": "e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20",
"versionType": "git"
},
{
"lessThan": "e25b44bd8b8cc666b49a3fe0ef547e64d5b1e300",
"status": "affected",
"version": "e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20",
"versionType": "git"
},
{
"lessThan": "9b01f5af0dc59263b59391b148bc78d83c0354a9",
"status": "affected",
"version": "e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20",
"versionType": "git"
},
{
"lessThan": "9620a91f8d643b680f417a435db399a04d1e06d8",
"status": "affected",
"version": "e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20",
"versionType": "git"
},
{
"lessThan": "cf9d44be50b9074a5abdc301b4a3ba3e283591df",
"status": "affected",
"version": "e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20",
"versionType": "git"
},
{
"lessThan": "f5c534b53f8c424a8e7633c9b585475c4bf4ee18",
"status": "affected",
"version": "e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20",
"versionType": "git"
},
{
"lessThan": "0428fa2c22e2ba0cff766d3b80d461e149102045",
"status": "affected",
"version": "e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/nfc/nci/ntf.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.3"
},
{
"lessThan": "3.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.269",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.220",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.187",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.156",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.108",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.47",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.1",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.269",
"versionStartIncluding": "3.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.220",
"versionStartIncluding": "3.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.187",
"versionStartIncluding": "3.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.156",
"versionStartIncluding": "3.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.108",
"versionStartIncluding": "3.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.47",
"versionStartIncluding": "3.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.11",
"versionStartIncluding": "3.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.1",
"versionStartIncluding": "3.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "3.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: nci: add data_len bound checks to activation parameter extractors\n\nnci_extract_activation_params_iso_dep() and\nnci_extract_activation_params_nfc_dep() read an inner length byte from\nthe NCI RF_INTF_ACTIVATED_NTF payload and use it to memcpy() into fixed\nkernel buffers, but neither function receives the caller-validated\nactivation_params_len. A crafted NCI notification with\nactivation_params_len=1 and an inner length byte of up to 20 (NFC-A) or\n50 (NFC-B) causes memcpy() to read that many bytes past the one valid\nbyte in the activation params region -- a slab out-of-bounds read of\nkernel memory adjacent to the NCI skb.\n\nThe sibling nci_extract_rf_params_*() family was given equivalent\nprotection by commit 571dcbeb8e63 (\"net: nfc: nci: Fix parameter\nvalidation for packet data\"), but the two activation parameter\nextractors were not updated at that time.\n\nAdd a data_len parameter to both functions, guard against an empty\nregion before consuming the inner length byte, decrement the remaining\ncount after consuming it, and clamp the copy length to what is actually\navailable. Update both call sites to pass ntf.activation_params_len,\nwhich is already validated against the skb at ntf.c:801."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T15:13:09.857Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/1168484fe2b3828bf24a46f3c42a8719fade679b"
},
{
"url": "https://git.kernel.org/stable/c/be311c0cfeadfbe815ea22d2914a98d06e3fab0e"
},
{
"url": "https://git.kernel.org/stable/c/04e51353cb9fa321caaeeed8331d4cd041fbaca7"
},
{
"url": "https://git.kernel.org/stable/c/e25b44bd8b8cc666b49a3fe0ef547e64d5b1e300"
},
{
"url": "https://git.kernel.org/stable/c/9b01f5af0dc59263b59391b148bc78d83c0354a9"
},
{
"url": "https://git.kernel.org/stable/c/9620a91f8d643b680f417a435db399a04d1e06d8"
},
{
"url": "https://git.kernel.org/stable/c/cf9d44be50b9074a5abdc301b4a3ba3e283591df"
},
{
"url": "https://git.kernel.org/stable/c/f5c534b53f8c424a8e7633c9b585475c4bf4ee18"
},
{
"url": "https://git.kernel.org/stable/c/0428fa2c22e2ba0cff766d3b80d461e149102045"
}
],
"title": "nfc: nci: add data_len bound checks to activation parameter extractors",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80796",
"datePublished": "2026-09-04T15:13:09.857Z",
"dateReserved": "2026-08-26T14:34:25.793Z",
"dateUpdated": "2026-09-04T15:13:09.857Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74714 (GCVE-0-2026-74714)
Vulnerability from cvelistv5
Published
2026-08-22 15:33
Modified
2026-08-25 05:41
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
bpf: tcp: Fix use-after-free in bpf_iter_tcp_established_batch()
reqsk_queue_hash_req() publishes a TCP_NEW_SYN_RECV request_sock onto
the ehash chain, drops the bucket lock, and only afterwards sets
rsk_refcnt to 3.
Lockless readers such as __inet_lookup_established() handle this with
refcount_inc_not_zero(), but bpf_iter_tcp_established_batch() uses plain
sock_hold() while holding the bucket lock, on the assumption that the
lock guarantees sk_refcnt > 0. That assumption does not hold for
request_sock:
CPU 0 CPU 1
----- -----
tcp_conn_request()
reqsk_queue_hash_req()
inet_ehash_insert(req)
spin_lock(bucket)
__sk_nulls_add_node_rcu(req) // rsk_refcnt == 0
spin_unlock(bucket)
bpf_iter_tcp_established_batch()
spin_lock(bucket)
sock_hold(req) <-- addition on 0
spin_unlock(bucket)
refcount_set(&req->rsk_refcnt, 3) // clobbers saturated value
which surfaces as:
refcount_t: addition on 0; use-after-free.
WARNING: lib/refcount.c:25 at refcount_warn_saturate+0x48/0x90, CPU#1
Call Trace:
bpf_iter_tcp_established_batch+0x14e/0x170
bpf_iter_tcp_batch+0x53/0x200
bpf_iter_tcp_seq_next+0x27/0x70
bpf_seq_read+0x107/0x410
vfs_read+0xb9/0x380
The iterator's stolen reference is lost when the publishing CPU's
refcount_set() overwrites the count, leaving the socket one reference
short. When the last legitimate owner drops its reference the reqsk is
freed while still reachable, leading to use-after-free.
This reproduces in seconds with tcp_syncookies=0, a handful of threads
doing connect()/close() to a local listener while others read an
iter/tcp link in a tight loop.
Use refcount_inc_not_zero() and skip the socket on failure. A skipped
socket is still part of the bucket, so keep counting it in expected.
The reallocations are sized from expected, and a request sock whose
refcount gets published while the lock is held across the last realloc
must already have room.
A skipped socket is counted in expected but never batched, so end_sk
can be short of expected on a batch that is actually complete. Decide
completeness by whether the walk left any socket behind instead. The
WARN after the locked realloc checks the same, replacing an
end_sk == expected check that could not hold on that path since
commit cdec67a489d4 ("bpf: tcp: Make sure iter->batch always
contains a full bucket snapshot").
If every matching socket in a bucket is mid-init (refcount 0), end_sk
stays 0. Advance to the next bucket rather than returning a batch entry
that was never filled this round.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 04c7820b776f1c4b48698574c47de9e940d368e8 Version: 04c7820b776f1c4b48698574c47de9e940d368e8 Version: 04c7820b776f1c4b48698574c47de9e940d368e8 Version: 04c7820b776f1c4b48698574c47de9e940d368e8 Version: 04c7820b776f1c4b48698574c47de9e940d368e8 Version: 04c7820b776f1c4b48698574c47de9e940d368e8 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ipv4/tcp_ipv4.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "cc0295f89296ed351fc4b0b48fee887ba02c5d24",
"status": "affected",
"version": "04c7820b776f1c4b48698574c47de9e940d368e8",
"versionType": "git"
},
{
"lessThan": "ddbe966b5d1fe212ada749bc3d0b410f1a7dea74",
"status": "affected",
"version": "04c7820b776f1c4b48698574c47de9e940d368e8",
"versionType": "git"
},
{
"lessThan": "7d2b60a4bc0499f62ff8520af6309bbe170882fd",
"status": "affected",
"version": "04c7820b776f1c4b48698574c47de9e940d368e8",
"versionType": "git"
},
{
"lessThan": "cefcbbe20846a45f9a7dae868f7ef1000953e2df",
"status": "affected",
"version": "04c7820b776f1c4b48698574c47de9e940d368e8",
"versionType": "git"
},
{
"lessThan": "97e74d3e45d653c07c2d406fc530a9bbe3df8396",
"status": "affected",
"version": "04c7820b776f1c4b48698574c47de9e940d368e8",
"versionType": "git"
},
{
"lessThan": "e5fd3f514e27db1f05fbd72ba615d74941e23c51",
"status": "affected",
"version": "04c7820b776f1c4b48698574c47de9e940d368e8",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ipv4/tcp_ipv4.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.15"
},
{
"lessThan": "5.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: tcp: Fix use-after-free in bpf_iter_tcp_established_batch()\n\nreqsk_queue_hash_req() publishes a TCP_NEW_SYN_RECV request_sock onto\nthe ehash chain, drops the bucket lock, and only afterwards sets\nrsk_refcnt to 3.\n\nLockless readers such as __inet_lookup_established() handle this with\nrefcount_inc_not_zero(), but bpf_iter_tcp_established_batch() uses plain\nsock_hold() while holding the bucket lock, on the assumption that the\nlock guarantees sk_refcnt \u003e 0. That assumption does not hold for\nrequest_sock:\n\n CPU 0 CPU 1\n ----- -----\n tcp_conn_request()\n reqsk_queue_hash_req()\n inet_ehash_insert(req)\n spin_lock(bucket)\n __sk_nulls_add_node_rcu(req) // rsk_refcnt == 0\n spin_unlock(bucket)\n bpf_iter_tcp_established_batch()\n spin_lock(bucket)\n sock_hold(req) \u003c-- addition on 0\n spin_unlock(bucket)\n refcount_set(\u0026req-\u003ersk_refcnt, 3) // clobbers saturated value\n\nwhich surfaces as:\n\n refcount_t: addition on 0; use-after-free.\n WARNING: lib/refcount.c:25 at refcount_warn_saturate+0x48/0x90, CPU#1\n Call Trace:\n bpf_iter_tcp_established_batch+0x14e/0x170\n bpf_iter_tcp_batch+0x53/0x200\n bpf_iter_tcp_seq_next+0x27/0x70\n bpf_seq_read+0x107/0x410\n vfs_read+0xb9/0x380\n\nThe iterator\u0027s stolen reference is lost when the publishing CPU\u0027s\nrefcount_set() overwrites the count, leaving the socket one reference\nshort. When the last legitimate owner drops its reference the reqsk is\nfreed while still reachable, leading to use-after-free.\n\nThis reproduces in seconds with tcp_syncookies=0, a handful of threads\ndoing connect()/close() to a local listener while others read an\niter/tcp link in a tight loop.\n\nUse refcount_inc_not_zero() and skip the socket on failure. A skipped\nsocket is still part of the bucket, so keep counting it in expected.\nThe reallocations are sized from expected, and a request sock whose\nrefcount gets published while the lock is held across the last realloc\nmust already have room.\n\nA skipped socket is counted in expected but never batched, so end_sk\ncan be short of expected on a batch that is actually complete. Decide\ncompleteness by whether the walk left any socket behind instead. The\nWARN after the locked realloc checks the same, replacing an\nend_sk == expected check that could not hold on that path since\ncommit cdec67a489d4 (\"bpf: tcp: Make sure iter-\u003ebatch always\ncontains a full bucket snapshot\").\n\nIf every matching socket in a bucket is mid-init (refcount 0), end_sk\nstays 0. Advance to the next bucket rather than returning a batch entry\nthat was never filled this round."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - bpf_iter_tcp_established_batch() is reached only via local bpf() to load a BPF_TRACE_ITER TCP program, create an iterator link/fd, and read() it (bpf_seq_read-\u003ebpf_iter_tcp_batch); per kernel CNA guidance BPF iterator paths are Local even though concurrent TCP_NEW_SYN_RECV creation can be driven by network SYNs.\nAC:L - The fix commit reproduces in seconds with threads doing connect()/close() while others read iter/tcp in a tight loop; the attacker controls both the BPF iterator and TCP connection churn, so the refcount race between sock_hold() and refcount_set() is reliably winnable without uncontrollable victim state.\nPR:L - Loading BPF_PROG_TYPE_TRACING/BPF_TRACE_ITER requires CAP_BPF and CAP_PERFMON at bpf_prog_load(); per kernel CNA guidance these are Low privileges because BPF tokens and user namespaces can delegate them to non-init-namespace users, not only real root.\nUI:N - No victim interaction is required; the attacker loads their own iter/tcp BPF program and link, then triggers the race with self-generated connect/close traffic or SYN activity to listeners in the iterated network namespace.\nS:U - Impact is a kernel heap use-after-free and memory corruption within the same host kernel security authority; this is standard local kernel compromise/crash, not a VM escape, sandbox boundary cross, or IOMMU bypass.\nC:H - The iterator retains dangling request_sock pointers after refcount_set() clobbers a sock_hold() taken on sk_refcnt==0; subsequent bpf_iter_tcp_seq_show/put_batch dereference freed kernel objects, giving UAF read primitives per kernel CNA UAF guidance.\nI:H - Freed request_sock slabs can be reallocated while the iterator batch still references them; UAF enables corrupted socket metadata, refcount abuse, and control-flow hijacking via heap grooming, meeting High integrity under kernel CNA memory-corruption guidance.\nA:H - The bug surfaces as refcount_warn_saturate and leaves the reqsk one reference short so it is freed while still reachable from the iterator batch, causing kernel oops/panic; the tight-loop repro shows reliable, repeatable host denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:41:57.341Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/cc0295f89296ed351fc4b0b48fee887ba02c5d24"
},
{
"url": "https://git.kernel.org/stable/c/ddbe966b5d1fe212ada749bc3d0b410f1a7dea74"
},
{
"url": "https://git.kernel.org/stable/c/7d2b60a4bc0499f62ff8520af6309bbe170882fd"
},
{
"url": "https://git.kernel.org/stable/c/cefcbbe20846a45f9a7dae868f7ef1000953e2df"
},
{
"url": "https://git.kernel.org/stable/c/97e74d3e45d653c07c2d406fc530a9bbe3df8396"
},
{
"url": "https://git.kernel.org/stable/c/e5fd3f514e27db1f05fbd72ba615d74941e23c51"
}
],
"title": "bpf: tcp: Fix use-after-free in bpf_iter_tcp_established_batch()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74714",
"datePublished": "2026-08-22T15:33:09.643Z",
"dateReserved": "2026-08-15T05:44:03.928Z",
"dateUpdated": "2026-08-25T05:41:57.341Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80561 (GCVE-0-2026-80561)
Vulnerability from cvelistv5
Published
2026-08-26 14:37
Modified
2026-08-27 05:01
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
libceph: fix multiple unsafe decodes in decode_locker()
decode_locker() in cls_lock_client.c contains three unsafe decode
operations that allow a malicious or compromised OSD to trigger
slab-out-of-bounds reads:
1. ceph_decode_copy() at the locker_id_t name field has no preceding
bounds check. With p == end after ceph_start_decoding() accepts
struct_len=0, this reads sizeof(ceph_entity_name) = 9 bytes past
the validated buffer boundary.
2. *p += sizeof(struct ceph_timespec) after the locker_info_t header
is an unchecked pointer advance. A malicious OSD can position p
past end, causing all subsequent _safe checks to pass against a
bogus boundary.
3. len = ceph_decode_32(p) has no preceding bounds check, and the
immediately following *p += len is uncapped. A malicious OSD can
send len=0xffffffff, advancing p gigabytes past end and escaping
the decode window entirely.
Fix all three by replacing bare operations with their safe variants:
ceph_decode_copy -> ceph_decode_copy_safe
*p += sizeof(...) -> ceph_decode_skip_n
ceph_decode_32(p) -> ceph_decode_32_safe
*p += len -> ceph_decode_skip_n
A new label is added to return -EINVAL on any bounds violation.
-EINVAL is appropriate here: the data received from the OSD
is structurally malformed, which is an invalid argument to the decode
contract regardless of whether the caller or the wire is at fault.
Attacker model: a malicious or compromised OSD in a multi-tenant Ceph
deployment can trigger this against any kernel client that issues the
lock.get_info class method (e.g. during RBD exclusive lock acquisition)
without any further privileges beyond OSD session establishment.
[ idryomov: use ceph_decode_skip_string() to skip description, trim
changelog ]
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d4ed4a530562881cc5225050e42d96034f405aae Version: d4ed4a530562881cc5225050e42d96034f405aae Version: d4ed4a530562881cc5225050e42d96034f405aae Version: d4ed4a530562881cc5225050e42d96034f405aae Version: d4ed4a530562881cc5225050e42d96034f405aae Version: d4ed4a530562881cc5225050e42d96034f405aae Version: d4ed4a530562881cc5225050e42d96034f405aae Version: d4ed4a530562881cc5225050e42d96034f405aae |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ceph/cls_lock_client.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "1ed45c8d96498725eb54f740172f9068d8673906",
"status": "affected",
"version": "d4ed4a530562881cc5225050e42d96034f405aae",
"versionType": "git"
},
{
"lessThan": "6265103e78f0ee7e2518de9cf938b94bee9700a0",
"status": "affected",
"version": "d4ed4a530562881cc5225050e42d96034f405aae",
"versionType": "git"
},
{
"lessThan": "3c3716dc06a34e4ca7f743f5fcfa07fbc5a11070",
"status": "affected",
"version": "d4ed4a530562881cc5225050e42d96034f405aae",
"versionType": "git"
},
{
"lessThan": "fa4aa86fff0c56799c2e3f51a88879053285f4a9",
"status": "affected",
"version": "d4ed4a530562881cc5225050e42d96034f405aae",
"versionType": "git"
},
{
"lessThan": "dbfd83f722a78446ec18a476ef7a38e52240b50a",
"status": "affected",
"version": "d4ed4a530562881cc5225050e42d96034f405aae",
"versionType": "git"
},
{
"lessThan": "d1bba38574d095f191557d397d9633f08cd966b1",
"status": "affected",
"version": "d4ed4a530562881cc5225050e42d96034f405aae",
"versionType": "git"
},
{
"lessThan": "51c8d238fe7236de627ab1a1433694552a904136",
"status": "affected",
"version": "d4ed4a530562881cc5225050e42d96034f405aae",
"versionType": "git"
},
{
"lessThan": "437b6551cfcc235eea1d735a874f9d421f555e17",
"status": "affected",
"version": "d4ed4a530562881cc5225050e42d96034f405aae",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ceph/cls_lock_client.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.9"
},
{
"lessThan": "4.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.46",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.10",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: fix multiple unsafe decodes in decode_locker()\n\ndecode_locker() in cls_lock_client.c contains three unsafe decode\noperations that allow a malicious or compromised OSD to trigger\nslab-out-of-bounds reads:\n\n1. ceph_decode_copy() at the locker_id_t name field has no preceding\n bounds check. With p == end after ceph_start_decoding() accepts\n struct_len=0, this reads sizeof(ceph_entity_name) = 9 bytes past\n the validated buffer boundary.\n\n2. *p += sizeof(struct ceph_timespec) after the locker_info_t header\n is an unchecked pointer advance. A malicious OSD can position p\n past end, causing all subsequent _safe checks to pass against a\n bogus boundary.\n\n3. len = ceph_decode_32(p) has no preceding bounds check, and the\n immediately following *p += len is uncapped. A malicious OSD can\n send len=0xffffffff, advancing p gigabytes past end and escaping\n the decode window entirely.\n\nFix all three by replacing bare operations with their safe variants:\n ceph_decode_copy -\u003e ceph_decode_copy_safe\n *p += sizeof(...) -\u003e ceph_decode_skip_n\n ceph_decode_32(p) -\u003e ceph_decode_32_safe\n *p += len -\u003e ceph_decode_skip_n\n\nA new label is added to return -EINVAL on any bounds violation.\n-EINVAL is appropriate here: the data received from the OSD\nis structurally malformed, which is an invalid argument to the decode\ncontract regardless of whether the caller or the wire is at fault.\n\nAttacker model: a malicious or compromised OSD in a multi-tenant Ceph\ndeployment can trigger this against any kernel client that issues the\nlock.get_info class method (e.g. during RBD exclusive lock acquisition)\nwithout any further privileges beyond OSD session establishment.\n\n[ idryomov: use ceph_decode_skip_string() to skip description, trim\n changelog ]"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The flaw is reached when libceph decodes a crafted MOSDOpReply for the lock.get_info class method received over the Ceph messenger TCP session from a compromised or malicious OSD; no local syscall or ioctl is required on the victim.\nAC:L - A malicious OSD fully controls the reply and can set struct_len=0, advance the decode pointer past field boundaries, or send len=0xffffffff to deterministically trigger all three unsafe decodes in decode_locker() without races or special memory layout.\nPR:N - The attacker acts as the remote Ceph OSD peer and needs no account or privileges on the victim Linux host; any kernel RBD client connected to a multi-tenant or attacker-controlled cluster is exposed during automatic exclusive-lock operations.\nUI:N - Once an RBD image is mapped, ceph_cls_lock_info() is invoked automatically during exclusive-lock acquisition and object-map lock recovery; no further victim user or administrator action is required at exploit time.\nS:U - The slab out-of-bounds reads and any resulting kernel memory corruption occur entirely within the victim host kernel running the Ceph client, without crossing VM, container, or IOMMU security boundaries.\nC:H - Unsafe ceph_decode_copy, unchecked pointer advances, and uncapped *p+=len in decode_locker() perform slab out-of-bounds reads; leaked bytes populate ceph_entity_name and influence subsequent ceph_extract_encoded_string() allocation and locker field parsing.\nI:H - Attacker-controlled malformed replies misposition decode pointers so out-of-bounds values and lengths feed heap allocations and locker structure fields in kernel lock-handling paths, providing memory-corruption primitives beyond simple information disclosure.\nA:H - Slab out-of-bounds reads can trigger KASAN faults or kernel oops on instrumented builds, and uncapped pointer advances escaping the decode window can destabilize the RBD lock worker and cause severe availability loss on storage client hosts."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T05:01:49.904Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/1ed45c8d96498725eb54f740172f9068d8673906"
},
{
"url": "https://git.kernel.org/stable/c/6265103e78f0ee7e2518de9cf938b94bee9700a0"
},
{
"url": "https://git.kernel.org/stable/c/3c3716dc06a34e4ca7f743f5fcfa07fbc5a11070"
},
{
"url": "https://git.kernel.org/stable/c/fa4aa86fff0c56799c2e3f51a88879053285f4a9"
},
{
"url": "https://git.kernel.org/stable/c/dbfd83f722a78446ec18a476ef7a38e52240b50a"
},
{
"url": "https://git.kernel.org/stable/c/d1bba38574d095f191557d397d9633f08cd966b1"
},
{
"url": "https://git.kernel.org/stable/c/51c8d238fe7236de627ab1a1433694552a904136"
},
{
"url": "https://git.kernel.org/stable/c/437b6551cfcc235eea1d735a874f9d421f555e17"
}
],
"title": "libceph: fix multiple unsafe decodes in decode_locker()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80561",
"datePublished": "2026-08-26T14:37:26.572Z",
"dateReserved": "2026-08-26T14:34:25.767Z",
"dateUpdated": "2026-08-27T05:01:49.904Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80823 (GCVE-0-2026-80823)
Vulnerability from cvelistv5
Published
2026-09-04 15:27
Modified
2026-09-04 15:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
nfc: st21nfca: validate ATR_REQ length against the received frame
st21nfca_tm_recv_atr_req() checks that the received ATR_REQ frame is at
least ST21NFCA_ATR_REQ_MIN_SIZE and that the self-declared atr_req->length
is at least sizeof(struct st21nfca_atr_req), but never checks that
atr_req->length does not exceed the actual received length (skb->len).
st21nfca_tm_send_atr_res() then trusts the declared length:
gb_len = atr_req->length - sizeof(struct st21nfca_atr_req);
...
memcpy(atr_res->gbi, atr_req->gbi, gb_len);
so an RF peer that sends a short frame but sets atr_req->length larger
than the frame makes gb_len exceed the general bytes actually present,
and the memcpy reads out of bounds past the received skb. Those bytes are
placed in the ATR_RES and sent back to the peer (kernel-memory disclosure
to a proximity attacker); a larger declared length is an out-of-bounds
read (DoS).
Reject frames whose declared length exceeds the received length. The
adjacent nfc_tm_activated() path in the same function already derives its
general-bytes length from skb->len rather than the declared field.
Found by 0sec (https://0sec.ai) using automated source analysis; the
missing bound is evident from source. Compile-tested.
References
| URL | Tags | ||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1892bf844ea0261736bd5e75546fc996e9daeedf Version: 1892bf844ea0261736bd5e75546fc996e9daeedf Version: 1892bf844ea0261736bd5e75546fc996e9daeedf Version: 1892bf844ea0261736bd5e75546fc996e9daeedf Version: 1892bf844ea0261736bd5e75546fc996e9daeedf Version: 1892bf844ea0261736bd5e75546fc996e9daeedf Version: 1892bf844ea0261736bd5e75546fc996e9daeedf Version: 1892bf844ea0261736bd5e75546fc996e9daeedf Version: 1892bf844ea0261736bd5e75546fc996e9daeedf |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/nfc/st21nfca/dep.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "785df00bb3ae3206674a43284eb06dac575b5c64",
"status": "affected",
"version": "1892bf844ea0261736bd5e75546fc996e9daeedf",
"versionType": "git"
},
{
"lessThan": "2c1ad291f4cdc357f9527b688c6fda9c6ffa7890",
"status": "affected",
"version": "1892bf844ea0261736bd5e75546fc996e9daeedf",
"versionType": "git"
},
{
"lessThan": "dd26d30f40c43ad9cfe2f25c6ea0ead1dd51d5aa",
"status": "affected",
"version": "1892bf844ea0261736bd5e75546fc996e9daeedf",
"versionType": "git"
},
{
"lessThan": "9635507fe82949e429b3cd938876a9917125b151",
"status": "affected",
"version": "1892bf844ea0261736bd5e75546fc996e9daeedf",
"versionType": "git"
},
{
"lessThan": "0f344944c506b4f02d2b098489f7268b438c369e",
"status": "affected",
"version": "1892bf844ea0261736bd5e75546fc996e9daeedf",
"versionType": "git"
},
{
"lessThan": "bfcca5f42c9aa4eadef1e5fe7bb23783d7fcc96d",
"status": "affected",
"version": "1892bf844ea0261736bd5e75546fc996e9daeedf",
"versionType": "git"
},
{
"lessThan": "304f5b414f4051d324b8c4a3ab0e79f7dc7e150e",
"status": "affected",
"version": "1892bf844ea0261736bd5e75546fc996e9daeedf",
"versionType": "git"
},
{
"lessThan": "f33cecf69095c43be88567fef92b180b858f7369",
"status": "affected",
"version": "1892bf844ea0261736bd5e75546fc996e9daeedf",
"versionType": "git"
},
{
"lessThan": "5cdcca5d62a66eda6b774110a44cba67bc1a8d1d",
"status": "affected",
"version": "1892bf844ea0261736bd5e75546fc996e9daeedf",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/nfc/st21nfca/dep.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.17"
},
{
"lessThan": "3.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.267",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.218",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.185",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.154",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.106",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.47",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.1",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.267",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.218",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.185",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.154",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.106",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.47",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.11",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.1",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "3.17",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: st21nfca: validate ATR_REQ length against the received frame\n\nst21nfca_tm_recv_atr_req() checks that the received ATR_REQ frame is at\nleast ST21NFCA_ATR_REQ_MIN_SIZE and that the self-declared atr_req-\u003elength\nis at least sizeof(struct st21nfca_atr_req), but never checks that\natr_req-\u003elength does not exceed the actual received length (skb-\u003elen).\n\nst21nfca_tm_send_atr_res() then trusts the declared length:\n\n\tgb_len = atr_req-\u003elength - sizeof(struct st21nfca_atr_req);\n\t...\n\tmemcpy(atr_res-\u003egbi, atr_req-\u003egbi, gb_len);\n\nso an RF peer that sends a short frame but sets atr_req-\u003elength larger\nthan the frame makes gb_len exceed the general bytes actually present,\nand the memcpy reads out of bounds past the received skb. Those bytes are\nplaced in the ATR_RES and sent back to the peer (kernel-memory disclosure\nto a proximity attacker); a larger declared length is an out-of-bounds\nread (DoS).\n\nReject frames whose declared length exceeds the received length. The\nadjacent nfc_tm_activated() path in the same function already derives its\ngeneral-bytes length from skb-\u003elen rather than the declared field.\n\nFound by 0sec (https://0sec.ai) using automated source analysis; the\nmissing bound is evident from source. Compile-tested."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T15:29:25.316Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/785df00bb3ae3206674a43284eb06dac575b5c64"
},
{
"url": "https://git.kernel.org/stable/c/2c1ad291f4cdc357f9527b688c6fda9c6ffa7890"
},
{
"url": "https://git.kernel.org/stable/c/dd26d30f40c43ad9cfe2f25c6ea0ead1dd51d5aa"
},
{
"url": "https://git.kernel.org/stable/c/9635507fe82949e429b3cd938876a9917125b151"
},
{
"url": "https://git.kernel.org/stable/c/0f344944c506b4f02d2b098489f7268b438c369e"
},
{
"url": "https://git.kernel.org/stable/c/bfcca5f42c9aa4eadef1e5fe7bb23783d7fcc96d"
},
{
"url": "https://git.kernel.org/stable/c/304f5b414f4051d324b8c4a3ab0e79f7dc7e150e"
},
{
"url": "https://git.kernel.org/stable/c/f33cecf69095c43be88567fef92b180b858f7369"
},
{
"url": "https://git.kernel.org/stable/c/5cdcca5d62a66eda6b774110a44cba67bc1a8d1d"
}
],
"title": "nfc: st21nfca: validate ATR_REQ length against the received frame",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80823",
"datePublished": "2026-09-04T15:27:46.153Z",
"dateReserved": "2026-08-26T14:34:25.795Z",
"dateUpdated": "2026-09-04T15:29:25.316Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74692 (GCVE-0-2026-74692)
Vulnerability from cvelistv5
Published
2026-08-22 15:32
Modified
2026-08-25 05:41
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/smc: fix TOCTOU race between smc_listen_out() and listener close
smc_listen_out() reads lsmc->sk.sk_state without the listener lock,
then acquires lock_sock_nested() only after the check passes. This
opens a window where smc_close_active() can transition the listener
to SMC_CLOSED, call smc_close_cleanup_listen() to drain the accept
queue, and release the lock, all between the lockless read and the
delayed lock acquisition:
smc_listen_work (smc_hs_wq) smc_close_active()
------------------------------- -------------------------
release_sock(child)
if (sk_state == SMC_LISTEN) TRUE
lock_sock(listener)
sk_state = SMC_CLOSED
smc_close_cleanup_listen()
release_sock(listener)
flush_work(tcp_listen_work)
lock_sock_nested(listener)
smc_accept_enqueue(listener, child) /* child enqueued on dead listener */
smc_close_active() flushes only tcp_listen_work. Work items already
dispatched onto smc_hs_wq for the CLC handshake continue running
unguarded. smc_accept_enqueue() takes a sock_hold() on the child that
is never released, so the child smc_sock, its clcsock, and the
reference all leak. A remote peer that opens TCP connections while the
server calls close() can exhaust kernel memory.
Move lock_sock_nested() to before the sk_state check so that the test
and the enqueue are atomic under the listener lock.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: fd57770dd198f5b2ddd5b9e6bf282cf98d63adb9 Version: fd57770dd198f5b2ddd5b9e6bf282cf98d63adb9 Version: fd57770dd198f5b2ddd5b9e6bf282cf98d63adb9 Version: fd57770dd198f5b2ddd5b9e6bf282cf98d63adb9 Version: fd57770dd198f5b2ddd5b9e6bf282cf98d63adb9 Version: fd57770dd198f5b2ddd5b9e6bf282cf98d63adb9 Version: fd57770dd198f5b2ddd5b9e6bf282cf98d63adb9 Version: d1d004585b40c212b338fc8a40cbaaf230ea4703 Version: 4.19.299 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/smc/af_smc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "53c7938d8bcfde3296ec1a347ba2a9393c1fdcfa",
"status": "affected",
"version": "fd57770dd198f5b2ddd5b9e6bf282cf98d63adb9",
"versionType": "git"
},
{
"lessThan": "feb71634bb1abab3e8fb5cde874b27001cc1282e",
"status": "affected",
"version": "fd57770dd198f5b2ddd5b9e6bf282cf98d63adb9",
"versionType": "git"
},
{
"lessThan": "01865e1ddb126b25ac9eba5cdd7ec49e11183a64",
"status": "affected",
"version": "fd57770dd198f5b2ddd5b9e6bf282cf98d63adb9",
"versionType": "git"
},
{
"lessThan": "00f89433777236ced4771211047fb5d4cd581cea",
"status": "affected",
"version": "fd57770dd198f5b2ddd5b9e6bf282cf98d63adb9",
"versionType": "git"
},
{
"lessThan": "78e5ebcd1c10ed7c8bda0a99e0abd5b62da86d67",
"status": "affected",
"version": "fd57770dd198f5b2ddd5b9e6bf282cf98d63adb9",
"versionType": "git"
},
{
"lessThan": "ff5bcd804b5bc5c64736b7d318c20e12ea9506b8",
"status": "affected",
"version": "fd57770dd198f5b2ddd5b9e6bf282cf98d63adb9",
"versionType": "git"
},
{
"lessThan": "185a4caeecabc150106deda1da170b09f2ad803f",
"status": "affected",
"version": "fd57770dd198f5b2ddd5b9e6bf282cf98d63adb9",
"versionType": "git"
},
{
"status": "affected",
"version": "d1d004585b40c212b338fc8a40cbaaf230ea4703",
"versionType": "git"
},
{
"lessThan": "4.20",
"status": "affected",
"version": "4.19.299",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/smc/af_smc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.1"
},
{
"lessThan": "5.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.19.299",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/smc: fix TOCTOU race between smc_listen_out() and listener close\n\nsmc_listen_out() reads lsmc-\u003esk.sk_state without the listener lock,\nthen acquires lock_sock_nested() only after the check passes. This\nopens a window where smc_close_active() can transition the listener\nto SMC_CLOSED, call smc_close_cleanup_listen() to drain the accept\nqueue, and release the lock, all between the lockless read and the\ndelayed lock acquisition:\n\n smc_listen_work (smc_hs_wq) smc_close_active()\n ------------------------------- -------------------------\n release_sock(child)\n if (sk_state == SMC_LISTEN) TRUE\n lock_sock(listener)\n sk_state = SMC_CLOSED\n smc_close_cleanup_listen()\n release_sock(listener)\n flush_work(tcp_listen_work)\n lock_sock_nested(listener)\n smc_accept_enqueue(listener, child) /* child enqueued on dead listener */\n\nsmc_close_active() flushes only tcp_listen_work. Work items already\ndispatched onto smc_hs_wq for the CLC handshake continue running\nunguarded. smc_accept_enqueue() takes a sock_hold() on the child that\nis never released, so the child smc_sock, its clcsock, and the\nreference all leak. A remote peer that opens TCP connections while the\nserver calls close() can exhaust kernel memory.\n\nMove lock_sock_nested() to before the sk_state check so that the test\nand the enqueue are atomic under the listener lock."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug fires when smc_listen_work() on smc_hs_wq finishes an inbound SMC/TCP handshake queued by smc_tcp_listen_work() for each remote connection to an AF_SMC listener, so any network peer that reaches the listener port drives the full path via SYN and CLC messages.\nAC:L - The attacker controls handshake completions by flooding SMC-capable TCP connections and overlapping them with listener close(), either by timing floods against restarts or locally by running server and client together; smc_close_active() only flushes tcp_listen_work, leaving smc_hs_wq workers racing through the unlocked sk_state check.\nPR:N - SMC performs no authentication; smc_create() and smc_listen() enforce no capabilities, and smc_listen_work() processes the CLC handshake immediately after TCP accept before any credential verification, so an unauthenticated remote peer need only reach the listener port.\nUI:N - Exploitation requires only inbound network connections and kernel handshake/close processing; no end-user action such as opening a file or mounting a filesystem is needed, and listener shutdown during deployments or restarts is routine automated server behavior.\nS:U - The leak accumulates orphaned smc_sock structures and clcsock references within the kernel networking subsystem on the targeted host; it does not cross VM, container, IOMMU, or other security boundaries.\nC:N - The bug is an unreleased sock_hold() leaving child sockets on a closed listener accept queue; objects are never freed prematurely, so there is no out-of-bounds read, use-after-free dereference, or kernel data disclosure to the attacker.\nI:N - Only reference counts are incremented without matching decrements; no memory is written out of bounds, no freed object is reused, and no control-flow or integrity primitive is obtained\u2014only unreclaimable kernel allocations accumulate.\nA:H - Each successful race permanently leaks a child smc_sock, its clcsock, and sock references that smc_close_cleanup_listen() can never drain; a remote peer repeating handshakes during listener close can exhaust kernel memory and cause system-wide denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:41:37.608Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/53c7938d8bcfde3296ec1a347ba2a9393c1fdcfa"
},
{
"url": "https://git.kernel.org/stable/c/feb71634bb1abab3e8fb5cde874b27001cc1282e"
},
{
"url": "https://git.kernel.org/stable/c/01865e1ddb126b25ac9eba5cdd7ec49e11183a64"
},
{
"url": "https://git.kernel.org/stable/c/00f89433777236ced4771211047fb5d4cd581cea"
},
{
"url": "https://git.kernel.org/stable/c/78e5ebcd1c10ed7c8bda0a99e0abd5b62da86d67"
},
{
"url": "https://git.kernel.org/stable/c/ff5bcd804b5bc5c64736b7d318c20e12ea9506b8"
},
{
"url": "https://git.kernel.org/stable/c/185a4caeecabc150106deda1da170b09f2ad803f"
}
],
"title": "net/smc: fix TOCTOU race between smc_listen_out() and listener close",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74692",
"datePublished": "2026-08-22T15:32:55.873Z",
"dateReserved": "2026-08-15T05:44:03.926Z",
"dateUpdated": "2026-08-25T05:41:37.608Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-46158 (GCVE-0-2026-46158)
Vulnerability from cvelistv5
Published
2026-05-28 09:36
Modified
2026-08-27 12:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
mptcp: pm: ADD_ADDR rtx: always decrease sk refcount
When an ADD_ADDR is retransmitted, the sk is held in sk_reset_timer().
It should then be released in all cases at the end.
Some (unlikely) checks were returning directly instead of calling
sock_put() to decrease the refcount. Jump to a new 'exit' label to call
__sock_put() (which will become sock_put() in the next commit) to fix
this potential leak.
While at it, drop the '!msk' check which cannot happen because it is
never reset, and explicitly mark the remaining one as "unlikely".
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 00cfd77b9063dcdf3628a7087faba60de85a9cc8 Version: 00cfd77b9063dcdf3628a7087faba60de85a9cc8 Version: 00cfd77b9063dcdf3628a7087faba60de85a9cc8 Version: 00cfd77b9063dcdf3628a7087faba60de85a9cc8 Version: 00cfd77b9063dcdf3628a7087faba60de85a9cc8 Version: 00cfd77b9063dcdf3628a7087faba60de85a9cc8 Version: 00cfd77b9063dcdf3628a7087faba60de85a9cc8 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/mptcp/pm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "e9ba34301d2e90f63f97c76ad9eb98e5250fe961",
"status": "affected",
"version": "00cfd77b9063dcdf3628a7087faba60de85a9cc8",
"versionType": "git"
},
{
"lessThan": "81d8142148164176385c279c7c1e1d581867423d",
"status": "affected",
"version": "00cfd77b9063dcdf3628a7087faba60de85a9cc8",
"versionType": "git"
},
{
"lessThan": "9426265e157dd77ec237c795901ed4dea6d69b5c",
"status": "affected",
"version": "00cfd77b9063dcdf3628a7087faba60de85a9cc8",
"versionType": "git"
},
{
"lessThan": "b41dd76f3b9735096c21d3e799a2b9fe36498d57",
"status": "affected",
"version": "00cfd77b9063dcdf3628a7087faba60de85a9cc8",
"versionType": "git"
},
{
"lessThan": "acd3d3562315c99f3c0db16f0fcc5f0306638982",
"status": "affected",
"version": "00cfd77b9063dcdf3628a7087faba60de85a9cc8",
"versionType": "git"
},
{
"lessThan": "25e37407442b8766ec2cf52fb4e31b5c3d3aeeae",
"status": "affected",
"version": "00cfd77b9063dcdf3628a7087faba60de85a9cc8",
"versionType": "git"
},
{
"lessThan": "9634cb35af17019baec21ca648516ce376fa10e6",
"status": "affected",
"version": "00cfd77b9063dcdf3628a7087faba60de85a9cc8",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/mptcp/pm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.10"
},
{
"lessThan": "5.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.218",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.185",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.142",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.92",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.30",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.7",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.218",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.185",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.142",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.92",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.30",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.7",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "5.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: pm: ADD_ADDR rtx: always decrease sk refcount\n\nWhen an ADD_ADDR is retransmitted, the sk is held in sk_reset_timer().\nIt should then be released in all cases at the end.\n\nSome (unlikely) checks were returning directly instead of calling\nsock_put() to decrease the refcount. Jump to a new \u0027exit\u0027 label to call\n__sock_put() (which will become sock_put() in the next commit) to fix\nthis potential leak.\n\nWhile at it, drop the \u0027!msk\u0027 check which cannot happen because it is\nnever reset, and explicitly mark the remaining one as \"unlikely\"."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T12:39:39.980Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/e9ba34301d2e90f63f97c76ad9eb98e5250fe961"
},
{
"url": "https://git.kernel.org/stable/c/81d8142148164176385c279c7c1e1d581867423d"
},
{
"url": "https://git.kernel.org/stable/c/9426265e157dd77ec237c795901ed4dea6d69b5c"
},
{
"url": "https://git.kernel.org/stable/c/b41dd76f3b9735096c21d3e799a2b9fe36498d57"
},
{
"url": "https://git.kernel.org/stable/c/acd3d3562315c99f3c0db16f0fcc5f0306638982"
},
{
"url": "https://git.kernel.org/stable/c/25e37407442b8766ec2cf52fb4e31b5c3d3aeeae"
},
{
"url": "https://git.kernel.org/stable/c/9634cb35af17019baec21ca648516ce376fa10e6"
}
],
"title": "mptcp: pm: ADD_ADDR rtx: always decrease sk refcount",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-46158",
"datePublished": "2026-05-28T09:36:13.821Z",
"dateReserved": "2026-05-13T15:03:33.102Z",
"dateUpdated": "2026-08-27T12:39:39.980Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68130 (GCVE-0-2026-68130)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-23 12:45
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: defer destroy_previous_session() until after NTLM authentication
In ntlm_authenticate(), destroy_previous_session() is called using a
user pointer resolved from the client-supplied NTLM blob username field
before the NTLMv2 response is validated. An authenticated attacker can
set the NTLM blob username to match a victim account and set
PreviousSessionId to the victim's session ID; destroy_previous_session()
destroys the victim's session while ksmbd_decode_ntlmssp_auth_blob()
subsequently rejects the request with -EPERM.
Move destroy_previous_session() and the prev_id assignment to after
ksmbd_decode_ntlmssp_auth_blob() returns success and use sess->user
rather than the pre-authentication lookup result. This matches the
ordering already used by krb5_authenticate(), where
destroy_previous_session() is called only after
ksmbd_krb5_authenticate() returns success.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 Version: e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 Version: e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 Version: e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 Version: e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 Version: e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 Version: e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/smb/server/smb2pdu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ab0230257ebdf48b07eaa679a8c92bc842fe3498",
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"versionType": "git"
},
{
"lessThan": "370b0ec8822b69c9073265e16b7daaa8201c9a4f",
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"versionType": "git"
},
{
"lessThan": "5c833074b549e5db125436a6f681af682261f785",
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"versionType": "git"
},
{
"lessThan": "243f1614ef2aca2d62a744575f1c24b07cd42757",
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"versionType": "git"
},
{
"lessThan": "18705cace0619fd2123737dcd028147774f38181",
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"versionType": "git"
},
{
"lessThan": "0ff12308c8a6c16ab68f0a487ffa93d69001dc18",
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"versionType": "git"
},
{
"lessThan": "c74801ee524f477c174a1899782b6c3b6918d407",
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/smb/server/smb2pdu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.15"
},
{
"lessThan": "5.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: defer destroy_previous_session() until after NTLM authentication\n\nIn ntlm_authenticate(), destroy_previous_session() is called using a\nuser pointer resolved from the client-supplied NTLM blob username field\nbefore the NTLMv2 response is validated. An authenticated attacker can\nset the NTLM blob username to match a victim account and set\nPreviousSessionId to the victim\u0027s session ID; destroy_previous_session()\ndestroys the victim\u0027s session while ksmbd_decode_ntlmssp_auth_blob()\nsubsequently rejects the request with -EPERM.\n\nMove destroy_previous_session() and the prev_id assignment to after\nksmbd_decode_ntlmssp_auth_blob() returns success and use sess-\u003euser\nrather than the pre-authentication lookup result. This matches the\nordering already used by krb5_authenticate(), where\ndestroy_previous_session() is called only after\nksmbd_krb5_authenticate() returns success."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:45:52.403Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ab0230257ebdf48b07eaa679a8c92bc842fe3498"
},
{
"url": "https://git.kernel.org/stable/c/370b0ec8822b69c9073265e16b7daaa8201c9a4f"
},
{
"url": "https://git.kernel.org/stable/c/5c833074b549e5db125436a6f681af682261f785"
},
{
"url": "https://git.kernel.org/stable/c/243f1614ef2aca2d62a744575f1c24b07cd42757"
},
{
"url": "https://git.kernel.org/stable/c/18705cace0619fd2123737dcd028147774f38181"
},
{
"url": "https://git.kernel.org/stable/c/0ff12308c8a6c16ab68f0a487ffa93d69001dc18"
},
{
"url": "https://git.kernel.org/stable/c/c74801ee524f477c174a1899782b6c3b6918d407"
}
],
"title": "ksmbd: defer destroy_previous_session() until after NTLM authentication",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68130",
"datePublished": "2026-08-10T11:58:52.653Z",
"dateReserved": "2026-07-30T09:28:09.370Z",
"dateUpdated": "2026-08-23T12:45:52.403Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74460 (GCVE-0-2026-74460)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-19 16:36
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
can: ems_usb: validate CPC message lengths
ems_usb_read_bulk_callback() walks CPC messages packed in one USB
receive buffer.
Check that each declared message fits in the URB payload. Also require the
type-specific payload to cover the fields used by the CAN, state, error and
overrun handlers.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 702171adeed3607ee9603ec30ce081411e36ae42 Version: 702171adeed3607ee9603ec30ce081411e36ae42 Version: 702171adeed3607ee9603ec30ce081411e36ae42 Version: 702171adeed3607ee9603ec30ce081411e36ae42 Version: 702171adeed3607ee9603ec30ce081411e36ae42 Version: 702171adeed3607ee9603ec30ce081411e36ae42 Version: 702171adeed3607ee9603ec30ce081411e36ae42 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/can/usb/ems_usb.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "bb3cc8da8a2967c0f8e83d148fc6870b19fa32c6",
"status": "affected",
"version": "702171adeed3607ee9603ec30ce081411e36ae42",
"versionType": "git"
},
{
"lessThan": "db5655287d78f00daf98888a520bb8da4d30126d",
"status": "affected",
"version": "702171adeed3607ee9603ec30ce081411e36ae42",
"versionType": "git"
},
{
"lessThan": "ce8125566b1d0b0f16449407e014addf451804ea",
"status": "affected",
"version": "702171adeed3607ee9603ec30ce081411e36ae42",
"versionType": "git"
},
{
"lessThan": "0b9090717c7e2184e2c427bbcc752f295116ac1d",
"status": "affected",
"version": "702171adeed3607ee9603ec30ce081411e36ae42",
"versionType": "git"
},
{
"lessThan": "0b23144c59c126beb4a7761a85a194ae0fe668a5",
"status": "affected",
"version": "702171adeed3607ee9603ec30ce081411e36ae42",
"versionType": "git"
},
{
"lessThan": "df3ac2a672a5284441f120d486acabdd6740fc2a",
"status": "affected",
"version": "702171adeed3607ee9603ec30ce081411e36ae42",
"versionType": "git"
},
{
"lessThan": "02925f51377f2a42a6724f00549167499c9302e5",
"status": "affected",
"version": "702171adeed3607ee9603ec30ce081411e36ae42",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/can/usb/ems_usb.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.32"
},
{
"lessThan": "2.6.32",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.32",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.32",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "2.6.32",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "2.6.32",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "2.6.32",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "2.6.32",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.32",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: ems_usb: validate CPC message lengths\n\nems_usb_read_bulk_callback() walks CPC messages packed in one USB\nreceive buffer.\n\nCheck that each declared message fits in the URB payload. Also require the\ntype-specific payload to cover the fields used by the CAN, state, error and\noverrun handlers."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:36:57.996Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/bb3cc8da8a2967c0f8e83d148fc6870b19fa32c6"
},
{
"url": "https://git.kernel.org/stable/c/db5655287d78f00daf98888a520bb8da4d30126d"
},
{
"url": "https://git.kernel.org/stable/c/ce8125566b1d0b0f16449407e014addf451804ea"
},
{
"url": "https://git.kernel.org/stable/c/0b9090717c7e2184e2c427bbcc752f295116ac1d"
},
{
"url": "https://git.kernel.org/stable/c/0b23144c59c126beb4a7761a85a194ae0fe668a5"
},
{
"url": "https://git.kernel.org/stable/c/df3ac2a672a5284441f120d486acabdd6740fc2a"
},
{
"url": "https://git.kernel.org/stable/c/02925f51377f2a42a6724f00549167499c9302e5"
}
],
"title": "can: ems_usb: validate CPC message lengths",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74460",
"datePublished": "2026-08-15T12:27:01.274Z",
"dateReserved": "2026-08-15T05:44:03.901Z",
"dateUpdated": "2026-08-19T16:36:57.996Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74737 (GCVE-0-2026-74737)
Vulnerability from cvelistv5
Published
2026-08-26 14:36
Modified
2026-08-27 05:00
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG
On the packet reception path, the ID of the MAC Port on which the packet
was received, is embedded in the RX DMA Descriptor's metadata. The ID is
extracted using the helper function cppi5_desc_get_tags_ids() which fills
in the 16-bit Source Tag into the 'port_id' variable. However, it is only
the lower 8-bits of the 16-bit Source Tag that represent the MAC Port ID,
while the upper 8-bits are Hardware-Reserved and carry an arbitrary value.
With the existing logic, sporadic kernel crash is observed due to the
subsequent driver code accessing out-of-bound memory because of an invalid
port_id.
Hence, fix the port_id extraction logic to use only the lower 8-bits of the
Source Tag as the MAC Port ID.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 93a76530316a3d8cc2d82c3deca48424fee92100 Version: 93a76530316a3d8cc2d82c3deca48424fee92100 Version: 93a76530316a3d8cc2d82c3deca48424fee92100 Version: 93a76530316a3d8cc2d82c3deca48424fee92100 Version: 93a76530316a3d8cc2d82c3deca48424fee92100 Version: 93a76530316a3d8cc2d82c3deca48424fee92100 Version: 93a76530316a3d8cc2d82c3deca48424fee92100 Version: 93a76530316a3d8cc2d82c3deca48424fee92100 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/ti/am65-cpsw-nuss.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "14fc40bf28390e0ebee6a072457c36b82c614100",
"status": "affected",
"version": "93a76530316a3d8cc2d82c3deca48424fee92100",
"versionType": "git"
},
{
"lessThan": "1c0e35ce761131f82062222779d8574849790892",
"status": "affected",
"version": "93a76530316a3d8cc2d82c3deca48424fee92100",
"versionType": "git"
},
{
"lessThan": "9a220225efd6f58350bbb53fe70bdec08519267f",
"status": "affected",
"version": "93a76530316a3d8cc2d82c3deca48424fee92100",
"versionType": "git"
},
{
"lessThan": "551688b410d3fb0dae7739724422f268cd9446d6",
"status": "affected",
"version": "93a76530316a3d8cc2d82c3deca48424fee92100",
"versionType": "git"
},
{
"lessThan": "46a8e084a159e638ac2728e96980b65d752d65fd",
"status": "affected",
"version": "93a76530316a3d8cc2d82c3deca48424fee92100",
"versionType": "git"
},
{
"lessThan": "72e4e3d7efc3b7d85f86abbe8b94f8e45074abe3",
"status": "affected",
"version": "93a76530316a3d8cc2d82c3deca48424fee92100",
"versionType": "git"
},
{
"lessThan": "914e0100df3435bd14d09f397238e891cf9b7dce",
"status": "affected",
"version": "93a76530316a3d8cc2d82c3deca48424fee92100",
"versionType": "git"
},
{
"lessThan": "36a05d2820077bb3955acb8111e1041d39148037",
"status": "affected",
"version": "93a76530316a3d8cc2d82c3deca48424fee92100",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/ti/am65-cpsw-nuss.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.7"
},
{
"lessThan": "5.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.46",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.10",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG\n\nOn the packet reception path, the ID of the MAC Port on which the packet\nwas received, is embedded in the RX DMA Descriptor\u0027s metadata. The ID is\nextracted using the helper function cppi5_desc_get_tags_ids() which fills\nin the 16-bit Source Tag into the \u0027port_id\u0027 variable. However, it is only\nthe lower 8-bits of the 16-bit Source Tag that represent the MAC Port ID,\nwhile the upper 8-bits are Hardware-Reserved and carry an arbitrary value.\nWith the existing logic, sporadic kernel crash is observed due to the\nsubsequent driver code accessing out-of-bound memory because of an invalid\nport_id.\n\nHence, fix the port_id extraction logic to use only the lower 8-bits of the\nSource Tag as the MAC Port ID."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug is in am65_cpsw_nuss_rx_packets() on the NAPI RX path for TI AM65/J721E CPSW Ethernet; any remote host that can deliver L2 frames to a configured port triggers RX DMA completion and this handler without local access.\nAC:L - An attacker only needs to send Ethernet traffic to drive RX completions; although hardware upper source-tag bits make hits sporadic, sustained transmission reliably provokes the out-of-bounds port lookup without races or victim-specific state.\nPR:N - Exploitation requires no Linux credentials or capabilities\u2014the vulnerable code runs in kernel RX softirq before socket demux or authentication, reachable by any entity that can send frames to the NIC.\nUI:N - Packet reception and NAPI polling are automatic once the interface is up; no victim mount, click, or other local action is needed beyond normal network connectivity to the device.\nS:U - Impact is kernel memory corruption and crash within the host kernel security domain; there is no VM, container, or IOMMU boundary crossover typical of Scope Changed scenarios.\nC:H - Invalid port_id indexes far past the kmalloc\u0027d ports[] array (max eight) via am65_common_get_port(), causing out-of-bounds reads of adjacent kernel objects such as ndev pointers, xdp_prog, and other port fields.\nI:H - The same out-of-bounds port pointer drives writes including ndev stats increments, XDP processing, and skb association on attacker-supplied packet buffers, yielding a memory corruption primitive steerable toward kernel modification.\nA:H - The fix commit documents sporadic kernel oops/panics from out-of-bounds access when hardware source-tag upper bits inflate port_id beyond the small allocated ports array."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T05:00:59.630Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/14fc40bf28390e0ebee6a072457c36b82c614100"
},
{
"url": "https://git.kernel.org/stable/c/1c0e35ce761131f82062222779d8574849790892"
},
{
"url": "https://git.kernel.org/stable/c/9a220225efd6f58350bbb53fe70bdec08519267f"
},
{
"url": "https://git.kernel.org/stable/c/551688b410d3fb0dae7739724422f268cd9446d6"
},
{
"url": "https://git.kernel.org/stable/c/46a8e084a159e638ac2728e96980b65d752d65fd"
},
{
"url": "https://git.kernel.org/stable/c/72e4e3d7efc3b7d85f86abbe8b94f8e45074abe3"
},
{
"url": "https://git.kernel.org/stable/c/914e0100df3435bd14d09f397238e891cf9b7dce"
},
{
"url": "https://git.kernel.org/stable/c/36a05d2820077bb3955acb8111e1041d39148037"
}
],
"title": "net: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74737",
"datePublished": "2026-08-26T14:36:50.544Z",
"dateReserved": "2026-08-15T05:44:03.930Z",
"dateUpdated": "2026-08-27T05:00:59.630Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68354 (GCVE-0-2026-68354)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
firewire: net: Fix fragmented datagram reassembly
fwnet_frag_new() keeps a sorted list of received fragments for a partial
datagram. When a new fragment is adjacent to an existing fragment, the
code checks whether the new fragment also closes the gap to the next or
previous list entry.
Those neighbor lookups currently assume that the current fragment always
has a real next or previous fragment. At a list edge, the next or
previous entry is the list head, not a struct fwnet_fragment_info.
The gap checks also compare against the old edge of the current fragment
instead of the edge after adding the new fragment. As a result, a
fragment that bridges two existing ranges may leave two adjacent ranges
unmerged, so fwnet_pd_is_complete() can miss a complete datagram.
Check for the list head before looking up the neighboring fragment, and
compare the neighbor against the new fragment's far edge when deciding
whether to merge all three ranges.
This issue was found by a static analysis checker and confirmed by
manual source review.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: c76acec6d55107b652a37c90b36c00bc8b04dabb Version: c76acec6d55107b652a37c90b36c00bc8b04dabb Version: c76acec6d55107b652a37c90b36c00bc8b04dabb Version: c76acec6d55107b652a37c90b36c00bc8b04dabb Version: c76acec6d55107b652a37c90b36c00bc8b04dabb Version: c76acec6d55107b652a37c90b36c00bc8b04dabb Version: c76acec6d55107b652a37c90b36c00bc8b04dabb Version: c76acec6d55107b652a37c90b36c00bc8b04dabb |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/firewire/net.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "1aaf16031d65ccd4576451a79f7dabbec994c111",
"status": "affected",
"version": "c76acec6d55107b652a37c90b36c00bc8b04dabb",
"versionType": "git"
},
{
"lessThan": "0a219b2a01b4fe93706717e3bcacf7f62967b26f",
"status": "affected",
"version": "c76acec6d55107b652a37c90b36c00bc8b04dabb",
"versionType": "git"
},
{
"lessThan": "268cea3800eda5fa3ee04a49ee2973b8766a8df3",
"status": "affected",
"version": "c76acec6d55107b652a37c90b36c00bc8b04dabb",
"versionType": "git"
},
{
"lessThan": "b7d633c7c92321be98724b1d365e8ce507f2f349",
"status": "affected",
"version": "c76acec6d55107b652a37c90b36c00bc8b04dabb",
"versionType": "git"
},
{
"lessThan": "22e05b8ddbcf7d22c7f1598786e86635547e554d",
"status": "affected",
"version": "c76acec6d55107b652a37c90b36c00bc8b04dabb",
"versionType": "git"
},
{
"lessThan": "0177e578d7a885037b0fb82286c12e9d0360cc10",
"status": "affected",
"version": "c76acec6d55107b652a37c90b36c00bc8b04dabb",
"versionType": "git"
},
{
"lessThan": "2a5aa4e9b89227d1a1690fb8d5b81e5f3b261999",
"status": "affected",
"version": "c76acec6d55107b652a37c90b36c00bc8b04dabb",
"versionType": "git"
},
{
"lessThan": "d52a13adbb8ccbab99cd3bad36804e87d8b5c052",
"status": "affected",
"version": "c76acec6d55107b652a37c90b36c00bc8b04dabb",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/firewire/net.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.31"
},
{
"lessThan": "2.6.31",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.31",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfirewire: net: Fix fragmented datagram reassembly\n\nfwnet_frag_new() keeps a sorted list of received fragments for a partial\ndatagram. When a new fragment is adjacent to an existing fragment, the\ncode checks whether the new fragment also closes the gap to the next or\nprevious list entry.\n\nThose neighbor lookups currently assume that the current fragment always\nhas a real next or previous fragment. At a list edge, the next or\nprevious entry is the list head, not a struct fwnet_fragment_info.\n\nThe gap checks also compare against the old edge of the current fragment\ninstead of the edge after adding the new fragment. As a result, a\nfragment that bridges two existing ranges may leave two adjacent ranges\nunmerged, so fwnet_pd_is_complete() can miss a complete datagram.\n\nCheck for the list head before looking up the neighboring fragment, and\ncompare the neighbor against the new fragment\u0027s far edge when deciding\nwhether to merge all three ranges.\n\nThis issue was found by a static analysis checker and confirmed by\nmanual source review."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The vulnerable reassembly code processes IP-over-1394 (RFC 2734) fragments arriving from another node on the shared IEEE 1394 bus via fwnet_receive_packet/fwnet_receive_broadcast -\u003e fwnet_incoming_packet -\u003e fwnet_pd_update -\u003e fwnet_frag_new, matching this CNA\u0027s Adjacent shared-physical-segment model for FireWire (CVE-2023-53432, CVE-2024-50113).\nAC:L - The attacker fully controls fg_off, dg_size and fragment ordering (12-bit fields, 0-4095) and can create unlimited fresh partial datagrams, so they can sweep every boundary offset against the aliased pd-\u003eskb bits and groom skb allocation until the type-confused compare matches; once it does, the list-head corruption and misaligned kfree are deterministic, with no attacker-uncontrollable race involved.\nPR:N - fwnet_receive_packet accepts TCODE_WRITE_BLOCK_REQUEST payloads from any bus peer and fwnet_receive_broadcast processes GASP packets automatically, with no credentials, capability check, or authentication anywhere on the path to fwnet_frag_new.\nUI:N - Fragment reassembly runs entirely in FireWire IRQ/softirq context once the firewire-net interface is up; the attacker\u0027s own node supplies the fragments and no victim action such as opening, mounting, or clicking is needed.\nS:U - The corruption is confined to kernel slab objects (fwnet_partial_datagram, sk_buff) under the same kernel security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - list_entry() on the list head reads the low 32 bits of pd-\u003eskb as fragment metadata (a kernel-pointer disclosure primitive), the missed merge lets fwnet_pd_is_complete() hand up an skb whose unwritten gaps contain uninitialized heap data, and the resulting slab freelist corruption from kfree() of an interior pointer yields overlapping objects usable for arbitrary kernel memory read.\nI:H - The prepend branch performs fi2-\u003elen += fi-\u003elen + len directly into bits 16-31 of pd-\u003eskb, giving a partially attacker-influenced write to a kernel pointer that is later passed to dev_kfree_skb_any() (arbitrary free), while the append branch\u0027s kfree() of pd+16 corrupts the SLUB freelist into attacker-groomable overlapping allocations - both classic control-flow-hijack primitives.\nA:H - list_del() on the list head leaves pd-\u003efi_list poisoned, and the immediately following fwnet_pd_is_complete() dereferences LIST_POISON1 in interrupt context while holding dev-\u003elock with IRQs disabled, oopsing or hanging the machine; the misaligned kfree() also trips slab debug BUGs, and a bus peer can repeat the packet flood to crash the system at will."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:00.740Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/1aaf16031d65ccd4576451a79f7dabbec994c111"
},
{
"url": "https://git.kernel.org/stable/c/0a219b2a01b4fe93706717e3bcacf7f62967b26f"
},
{
"url": "https://git.kernel.org/stable/c/268cea3800eda5fa3ee04a49ee2973b8766a8df3"
},
{
"url": "https://git.kernel.org/stable/c/b7d633c7c92321be98724b1d365e8ce507f2f349"
},
{
"url": "https://git.kernel.org/stable/c/22e05b8ddbcf7d22c7f1598786e86635547e554d"
},
{
"url": "https://git.kernel.org/stable/c/0177e578d7a885037b0fb82286c12e9d0360cc10"
},
{
"url": "https://git.kernel.org/stable/c/2a5aa4e9b89227d1a1690fb8d5b81e5f3b261999"
},
{
"url": "https://git.kernel.org/stable/c/d52a13adbb8ccbab99cd3bad36804e87d8b5c052"
}
],
"title": "firewire: net: Fix fragmented datagram reassembly",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68354",
"datePublished": "2026-08-10T12:03:31.348Z",
"dateReserved": "2026-07-30T09:28:09.385Z",
"dateUpdated": "2026-08-19T16:34:00.740Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68407 (GCVE-0-2026-68407)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-19 16:35
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: nl80211: free RNR data on MBSSID mismatch
nl80211_parse_beacon() rejects EMA RNR data when there are fewer RNR
entries than MBSSID entries.
The rejected RNR allocation has not been attached to the beacon data yet,
so free it before returning the error.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 56189d7bc30531def6b999f27940ee43c6ff2569 Version: dbbb27e183b1568d5a907ace1cd144b0709ea52a Version: dbbb27e183b1568d5a907ace1cd144b0709ea52a Version: dbbb27e183b1568d5a907ace1cd144b0709ea52a Version: dbbb27e183b1568d5a907ace1cd144b0709ea52a Version: dbbb27e183b1568d5a907ace1cd144b0709ea52a Version: 6.1.160 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/wireless/nl80211.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "4b76fc30c80b240107a7de3c7560113c9290eafc",
"status": "affected",
"version": "56189d7bc30531def6b999f27940ee43c6ff2569",
"versionType": "git"
},
{
"lessThan": "fa9592ef7de11f8c7042315d9bc20e91a97f679e",
"status": "affected",
"version": "dbbb27e183b1568d5a907ace1cd144b0709ea52a",
"versionType": "git"
},
{
"lessThan": "312c8b9d7836ef58e552619a8c19be08b04032bb",
"status": "affected",
"version": "dbbb27e183b1568d5a907ace1cd144b0709ea52a",
"versionType": "git"
},
{
"lessThan": "fb052a6e2fa866384d8edc237746583ec94c15af",
"status": "affected",
"version": "dbbb27e183b1568d5a907ace1cd144b0709ea52a",
"versionType": "git"
},
{
"lessThan": "6f919f29e9b75793104709987131b8d910d7800a",
"status": "affected",
"version": "dbbb27e183b1568d5a907ace1cd144b0709ea52a",
"versionType": "git"
},
{
"lessThan": "07a95ec2b54774201fdf4ef7ffb0ca2ab19ed29c",
"status": "affected",
"version": "dbbb27e183b1568d5a907ace1cd144b0709ea52a",
"versionType": "git"
},
{
"lessThan": "6.1.183",
"status": "affected",
"version": "6.1.160",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/wireless/nl80211.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.4"
},
{
"lessThan": "6.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "6.1.160",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: nl80211: free RNR data on MBSSID mismatch\n\nnl80211_parse_beacon() rejects EMA RNR data when there are fewer RNR\nentries than MBSSID entries.\n\nThe rejected RNR allocation has not been attached to the beacon data yet,\nso free it before returning the error."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:35:02.178Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/4b76fc30c80b240107a7de3c7560113c9290eafc"
},
{
"url": "https://git.kernel.org/stable/c/fa9592ef7de11f8c7042315d9bc20e91a97f679e"
},
{
"url": "https://git.kernel.org/stable/c/312c8b9d7836ef58e552619a8c19be08b04032bb"
},
{
"url": "https://git.kernel.org/stable/c/fb052a6e2fa866384d8edc237746583ec94c15af"
},
{
"url": "https://git.kernel.org/stable/c/6f919f29e9b75793104709987131b8d910d7800a"
},
{
"url": "https://git.kernel.org/stable/c/07a95ec2b54774201fdf4ef7ffb0ca2ab19ed29c"
}
],
"title": "wifi: nl80211: free RNR data on MBSSID mismatch",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68407",
"datePublished": "2026-08-10T12:04:27.252Z",
"dateReserved": "2026-07-30T09:28:09.390Z",
"dateUpdated": "2026-08-19T16:35:02.178Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74663 (GCVE-0-2026-74663)
Vulnerability from cvelistv5
Published
2026-08-22 15:32
Modified
2026-08-27 12:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/sched: reject overly deep qdisc hierarchies
Deep qdisc hierarchies can lead to excessive recursion in qdisc tree
walkers and exhaust the kernel stack. The existing loop check does not
cover the create-and-graft path, so a hierarchy can still be extended by
creating a new child qdisc below an already deep parent.
Store the hierarchy depth in struct Qdisc and update it when qdiscs are
grafted. Reject new child qdiscs once the parent is already at the maximum
allowed depth.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"include/net/sch_generic.h",
"net/sched/sch_api.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "08dc49df1527b09d9ea225a7265bbf6c237097bf",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "a627d36c2a94e18c8c105ae68008786dfd85592e",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "9f69bb9fdaa2fe64b68bb62fb84d405784bee540",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "8ca8cdb74939581339e1ae370193c0adb5a85336",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "2759acf08a3454866660edcd3ef4e64139f254a6",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "a4b14a4df29d36458a943f9b521ddd0f940363cc",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "e2d658c6427844cee5bc654b436ca68d680b6148",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "dedd34b0f2310e28c5f6d4875cfbf4b7ed821c01",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"include/net/sch_generic.h",
"net/sched/sch_api.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.267",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.218",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.267",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.218",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: reject overly deep qdisc hierarchies\n\nDeep qdisc hierarchies can lead to excessive recursion in qdisc tree\nwalkers and exhaust the kernel stack. The existing loop check does not\ncover the create-and-graft path, so a hierarchy can still be extended by\ncreating a new child qdisc below an already deep parent.\n\nStore the hierarchy depth in struct Qdisc and update it when qdiscs are\ngrafted. Reject new child qdiscs once the parent is already at the maximum\nallowed depth."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached only through RTM_NEWQDISC/tc netlink operations that build or graft qdiscs and invoke recursive qdisc tree walkers such as check_loop(); per kernel CNA guidance, tc/netlink qdisc configuration is Local and is not on any remote packet-receive path.\nAC:L - The create-and-graft path bypasses the existing depth-7 check_loop() guard, so an attacker can deterministically extend a linear classful qdisc chain (e.g., repeated HTB/HFSC grafts) and then trigger check_loop() with a graft/replace to recurse until the kernel stack is exhausted; no race or uncontrollable layout is required.\nPR:L - RTM_NEWQDISC is gated by netlink_net_capable(skb, CAP_NET_ADMIN) in rtnetlink_rcv_msg(), evaluated against the socket netns user_ns; an unprivileged local user routinely obtains CAP_NET_ADMIN via user+network namespaces (unshare -Urn) or containers with NET_ADMIN, not init-namespace root.\nUI:N - Exploitation requires only the attacker\u0027s own tc/netlink qdisc setup and a follow-on graft/replace that walks the deep hierarchy; no victim must open files, mount filesystems, click prompts, or perform any cooperative action.\nS:U - Impact is kernel-stack exhaustion and crash/panic within the same kernel security domain; it does not cross a VM, IOMMU, or sandbox boundary to another security authority such as guest-to-host escape.\nC:H - Unbounded recursion in qdisc tree walkers overflows the kernel task stack and corrupts stack memory before the guard-page fault; under overestimation guidance, such stack corruption is treated as plausibly enabling kernel memory disclosure rather than a pure crash with no data exposure.\nI:H - Recursive stack exhaustion overwrites saved return addresses and adjacent kernel stack frames, providing a plausible path to control-flow hijack or arbitrary kernel modification even though the immediate failure mode is oops/panic, not a bounded integrity change.\nA:H - Excessive recursion in qdisc tree walkers exhausts the kernel stack and causes a kernel oops/panic, denying all system availability on the host until reboot; any kernel stack guard fault or panic from this path scores Availability High."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T12:39:59.404Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/08dc49df1527b09d9ea225a7265bbf6c237097bf"
},
{
"url": "https://git.kernel.org/stable/c/a627d36c2a94e18c8c105ae68008786dfd85592e"
},
{
"url": "https://git.kernel.org/stable/c/9f69bb9fdaa2fe64b68bb62fb84d405784bee540"
},
{
"url": "https://git.kernel.org/stable/c/8ca8cdb74939581339e1ae370193c0adb5a85336"
},
{
"url": "https://git.kernel.org/stable/c/2759acf08a3454866660edcd3ef4e64139f254a6"
},
{
"url": "https://git.kernel.org/stable/c/a4b14a4df29d36458a943f9b521ddd0f940363cc"
},
{
"url": "https://git.kernel.org/stable/c/e2d658c6427844cee5bc654b436ca68d680b6148"
},
{
"url": "https://git.kernel.org/stable/c/dedd34b0f2310e28c5f6d4875cfbf4b7ed821c01"
}
],
"title": "net/sched: reject overly deep qdisc hierarchies",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74663",
"datePublished": "2026-08-22T15:32:35.871Z",
"dateReserved": "2026-08-15T05:44:03.924Z",
"dateUpdated": "2026-08-27T12:39:59.404Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80757 (GCVE-0-2026-80757)
Vulnerability from cvelistv5
Published
2026-09-03 08:26
Modified
2026-09-03 08:26
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
selinux: reject a class permission count below its inherited common
security_get_permissions() maps an inherited common's permissions into
an array sized by the class's own permissions.nprim, but class_read()
takes that nprim verbatim from the policy image and never checks that it
covers the common. A class that inherits a common of N permissions while
declaring a smaller nprim is accepted, and on load the common's
permissions are written past the class-sized array -- an out-of-bounds
heap write.
Reject a class whose permission count is below its inherited common's.
Well-formed policies, where the class count already includes the
inherited permissions, are unaffected.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 55fcf09b3fe4325c9395ebbb0322a547a157ebc7 Version: 55fcf09b3fe4325c9395ebbb0322a547a157ebc7 Version: 55fcf09b3fe4325c9395ebbb0322a547a157ebc7 Version: 55fcf09b3fe4325c9395ebbb0322a547a157ebc7 Version: 55fcf09b3fe4325c9395ebbb0322a547a157ebc7 Version: 55fcf09b3fe4325c9395ebbb0322a547a157ebc7 Version: 55fcf09b3fe4325c9395ebbb0322a547a157ebc7 Version: 55fcf09b3fe4325c9395ebbb0322a547a157ebc7 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"security/selinux/ss/policydb.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "2002ff745db64ac83ee1bb9ff78196d2d68bfdb3",
"status": "affected",
"version": "55fcf09b3fe4325c9395ebbb0322a547a157ebc7",
"versionType": "git"
},
{
"lessThan": "38d91446630a20ce8c2a981810deea81fd61a3b5",
"status": "affected",
"version": "55fcf09b3fe4325c9395ebbb0322a547a157ebc7",
"versionType": "git"
},
{
"lessThan": "638213f2e6ea52c06a25861616781338d154db35",
"status": "affected",
"version": "55fcf09b3fe4325c9395ebbb0322a547a157ebc7",
"versionType": "git"
},
{
"lessThan": "2b7ffd7921fcbfe408fb7b372e47454e45b1e6a7",
"status": "affected",
"version": "55fcf09b3fe4325c9395ebbb0322a547a157ebc7",
"versionType": "git"
},
{
"lessThan": "a63011c009ea79439b800a05602b880eb4adbb05",
"status": "affected",
"version": "55fcf09b3fe4325c9395ebbb0322a547a157ebc7",
"versionType": "git"
},
{
"lessThan": "acd5b09be98fd38b7392307880156fb0452a7276",
"status": "affected",
"version": "55fcf09b3fe4325c9395ebbb0322a547a157ebc7",
"versionType": "git"
},
{
"lessThan": "1b995966c3ae5244751bdaee9bfe7e17567d4fbe",
"status": "affected",
"version": "55fcf09b3fe4325c9395ebbb0322a547a157ebc7",
"versionType": "git"
},
{
"lessThan": "9a82dcd98b6e6e11cfd162410967951f12152528",
"status": "affected",
"version": "55fcf09b3fe4325c9395ebbb0322a547a157ebc7",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"security/selinux/ss/policydb.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.23"
},
{
"lessThan": "2.6.23",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "2.6.23",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "2.6.23",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "2.6.23",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "2.6.23",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "2.6.23",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.46",
"versionStartIncluding": "2.6.23",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.10",
"versionStartIncluding": "2.6.23",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.23",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nselinux: reject a class permission count below its inherited common\n\nsecurity_get_permissions() maps an inherited common\u0027s permissions into\nan array sized by the class\u0027s own permissions.nprim, but class_read()\ntakes that nprim verbatim from the policy image and never checks that it\ncovers the common. A class that inherits a common of N permissions while\ndeclaring a smaller nprim is accepted, and on load the common\u0027s\npermissions are written past the class-sized array -- an out-of-bounds\nheap write.\n\nReject a class whose permission count is below its inherited common\u0027s.\nWell-formed policies, where the class count already includes the\ninherited permissions, are unaffected."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-03T08:26:35.005Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/2002ff745db64ac83ee1bb9ff78196d2d68bfdb3"
},
{
"url": "https://git.kernel.org/stable/c/38d91446630a20ce8c2a981810deea81fd61a3b5"
},
{
"url": "https://git.kernel.org/stable/c/638213f2e6ea52c06a25861616781338d154db35"
},
{
"url": "https://git.kernel.org/stable/c/2b7ffd7921fcbfe408fb7b372e47454e45b1e6a7"
},
{
"url": "https://git.kernel.org/stable/c/a63011c009ea79439b800a05602b880eb4adbb05"
},
{
"url": "https://git.kernel.org/stable/c/acd5b09be98fd38b7392307880156fb0452a7276"
},
{
"url": "https://git.kernel.org/stable/c/1b995966c3ae5244751bdaee9bfe7e17567d4fbe"
},
{
"url": "https://git.kernel.org/stable/c/9a82dcd98b6e6e11cfd162410967951f12152528"
}
],
"title": "selinux: reject a class permission count below its inherited common",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80757",
"datePublished": "2026-09-03T08:26:35.005Z",
"dateReserved": "2026-08-26T14:34:25.791Z",
"dateUpdated": "2026-09-03T08:26:35.005Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80737 (GCVE-0-2026-80737)
Vulnerability from cvelistv5
Published
2026-09-03 08:21
Modified
2026-09-04 04:58
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
serial: amba-pl011: synchronize DMA teardown
dmaengine_terminate_all() does not wait for a running callback, so the TX
callback can still touch the TX buffer after it is freed. The RX poll
timer reads the RX buffers without the port lock.
Switch to dmaengine_terminate_sync() and delete the RX timer before
freeing the buffers.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ead76f329f777c7301e0a5456a0a1c7a081570bd Version: ead76f329f777c7301e0a5456a0a1c7a081570bd Version: ead76f329f777c7301e0a5456a0a1c7a081570bd Version: ead76f329f777c7301e0a5456a0a1c7a081570bd Version: ead76f329f777c7301e0a5456a0a1c7a081570bd Version: ead76f329f777c7301e0a5456a0a1c7a081570bd Version: ead76f329f777c7301e0a5456a0a1c7a081570bd Version: ead76f329f777c7301e0a5456a0a1c7a081570bd |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/tty/serial/amba-pl011.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a38fae9d212e2d3ed5e9ec0ef773f8c0a27fb76e",
"status": "affected",
"version": "ead76f329f777c7301e0a5456a0a1c7a081570bd",
"versionType": "git"
},
{
"lessThan": "44bd0ecc3444882d08ecfbc2b2418d2f463d3186",
"status": "affected",
"version": "ead76f329f777c7301e0a5456a0a1c7a081570bd",
"versionType": "git"
},
{
"lessThan": "f70c9d4fba46463a5b1c7b3ee9ee3b40c90dac03",
"status": "affected",
"version": "ead76f329f777c7301e0a5456a0a1c7a081570bd",
"versionType": "git"
},
{
"lessThan": "c8c8e895f65fbf71ea6224e27cf8dab91b776e0d",
"status": "affected",
"version": "ead76f329f777c7301e0a5456a0a1c7a081570bd",
"versionType": "git"
},
{
"lessThan": "9f6989e477f03a4721d34bb4b09b17accd40283e",
"status": "affected",
"version": "ead76f329f777c7301e0a5456a0a1c7a081570bd",
"versionType": "git"
},
{
"lessThan": "5974cb66681eac367107b05924744d7e3b49d41c",
"status": "affected",
"version": "ead76f329f777c7301e0a5456a0a1c7a081570bd",
"versionType": "git"
},
{
"lessThan": "fdfb46c387241b4eddd36d746793764413285913",
"status": "affected",
"version": "ead76f329f777c7301e0a5456a0a1c7a081570bd",
"versionType": "git"
},
{
"lessThan": "440915499231e9db1c361aa45bb702e8fd3b4a32",
"status": "affected",
"version": "ead76f329f777c7301e0a5456a0a1c7a081570bd",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/tty/serial/amba-pl011.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.39"
},
{
"lessThan": "2.6.39",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.267",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.218",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.185",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.154",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.106",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.267",
"versionStartIncluding": "2.6.39",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.218",
"versionStartIncluding": "2.6.39",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.185",
"versionStartIncluding": "2.6.39",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.154",
"versionStartIncluding": "2.6.39",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.106",
"versionStartIncluding": "2.6.39",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "2.6.39",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "2.6.39",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.39",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nserial: amba-pl011: synchronize DMA teardown\n\ndmaengine_terminate_all() does not wait for a running callback, so the TX\ncallback can still touch the TX buffer after it is freed. The RX poll\ntimer reads the RX buffers without the port lock.\n\nSwitch to dmaengine_terminate_sync() and delete the RX timer before\nfreeing the buffers."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Local tty device access via open/write/close on /dev/ttyAMA* or similar; PL011 DMA teardown runs in pl011_shutdown from uart_close/hangup/suspend, not via network protocols.\nAC:L - Attacker with tty fd controls DMA load (large writes for TX DMA, active RX) and teardown timing via close/hangup; they can repeatedly race shutdown against in-flight DMA callbacks/timers without uncontrollable conditions.\nPR:L - Requires open/write/close on the UART tty node, typically granted via dialout group on embedded ARM systems with PL011 DMA; not via user namespaces alone, but no root required on auxiliary serial ports.\nUI:N - Attacker performs all steps themselves (open port, queue DMA traffic, close); no separate victim action needed.\nS:U - Kernel heap/coherent-buffer UAF during UART driver teardown affects only local kernel resources; no VM escape, IOMMU bypass, or cross-security-authority boundary.\nC:H - TX DMA callback or RX poll timer can access freed TX kmalloc buffer or RX dma coherent pages, yielding UAF read primitives over kernel memory and potential information disclosure.\nI:H - Post-free access via pl011_dma_tx_refill/dma_map or pl011_dma_rx_poll writing into tty flip buffers enables heap corruption and potential kernel code execution or privilege escalation.\nA:H - UAF during DMA teardown can provoke kernel oops/panic from concurrent access to freed buffers, and repeated triggering can deny UART service or crash the host."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T04:58:22.813Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a38fae9d212e2d3ed5e9ec0ef773f8c0a27fb76e"
},
{
"url": "https://git.kernel.org/stable/c/44bd0ecc3444882d08ecfbc2b2418d2f463d3186"
},
{
"url": "https://git.kernel.org/stable/c/f70c9d4fba46463a5b1c7b3ee9ee3b40c90dac03"
},
{
"url": "https://git.kernel.org/stable/c/c8c8e895f65fbf71ea6224e27cf8dab91b776e0d"
},
{
"url": "https://git.kernel.org/stable/c/9f6989e477f03a4721d34bb4b09b17accd40283e"
},
{
"url": "https://git.kernel.org/stable/c/5974cb66681eac367107b05924744d7e3b49d41c"
},
{
"url": "https://git.kernel.org/stable/c/fdfb46c387241b4eddd36d746793764413285913"
},
{
"url": "https://git.kernel.org/stable/c/440915499231e9db1c361aa45bb702e8fd3b4a32"
}
],
"title": "serial: amba-pl011: synchronize DMA teardown",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80737",
"datePublished": "2026-09-03T08:21:52.539Z",
"dateReserved": "2026-08-26T14:34:25.789Z",
"dateUpdated": "2026-09-04T04:58:22.813Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2025-40102 (GCVE-0-2025-40102)
Vulnerability from cvelistv5
Published
2025-10-30 09:48
Modified
2026-09-02 12:49
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
KVM: arm64: Prevent access to vCPU events before init
Another day, another syzkaller bug. KVM erroneously allows userspace to
pend vCPU events for a vCPU that hasn't been initialized yet, leading to
KVM interpreting a bunch of uninitialized garbage for routing /
injecting the exception.
In one case the injection code and the hyp disagree on whether the vCPU
has a 32bit EL1 and put the vCPU into an illegal mode for AArch64,
tripping the BUG() in exception_target_el() during the next injection:
kernel BUG at arch/arm64/kvm/inject_fault.c:40!
Internal error: Oops - BUG: 00000000f2000800 [#1] SMP
CPU: 3 UID: 0 PID: 318 Comm: repro Not tainted 6.17.0-rc4-00104-g10fd0285305d #6 PREEMPT
Hardware name: linux,dummy-virt (DT)
pstate: 21402009 (nzCv daif +PAN -UAO -TCO +DIT -SSBS BTYPE=--)
pc : exception_target_el+0x88/0x8c
lr : pend_serror_exception+0x18/0x13c
sp : ffff800082f03a10
x29: ffff800082f03a10 x28: ffff0000cb132280 x27: 0000000000000000
x26: 0000000000000000 x25: ffff0000c2a99c20 x24: 0000000000000000
x23: 0000000000008000 x22: 0000000000000002 x21: 0000000000000004
x20: 0000000000008000 x19: ffff0000c2a99c20 x18: 0000000000000000
x17: 0000000000000000 x16: 0000000000000000 x15: 00000000200000c0
x14: 0000000000000000 x13: 0000000000000000 x12: 0000000000000000
x11: 0000000000000000 x10: 0000000000000000 x9 : 0000000000000000
x8 : ffff800082f03af8 x7 : 0000000000000000 x6 : 0000000000000000
x5 : ffff800080f621f0 x4 : 0000000000000000 x3 : 0000000000000000
x2 : 000000000040009b x1 : 0000000000000003 x0 : ffff0000c2a99c20
Call trace:
exception_target_el+0x88/0x8c (P)
kvm_inject_serror_esr+0x40/0x3b4
__kvm_arm_vcpu_set_events+0xf0/0x100
kvm_arch_vcpu_ioctl+0x180/0x9d4
kvm_vcpu_ioctl+0x60c/0x9f4
__arm64_sys_ioctl+0xac/0x104
invoke_syscall+0x48/0x110
el0_svc_common.constprop.0+0x40/0xe0
do_el0_svc+0x1c/0x28
el0_svc+0x34/0xf0
el0t_64_sync_handler+0xa0/0xe4
el0t_64_sync+0x198/0x19c
Code: f946bc01 b4fffe61 9101e020 17fffff2 (d4210000)
Reject the ioctls outright as no sane VMM would call these before
KVM_ARM_VCPU_INIT anyway. Even if it did the exception would've been
thrown away by the eventual reset of the vCPU's state.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: b7b27facc7b50a5fce0afaa3df56157136ce181a Version: b7b27facc7b50a5fce0afaa3df56157136ce181a Version: b7b27facc7b50a5fce0afaa3df56157136ce181a Version: b7b27facc7b50a5fce0afaa3df56157136ce181a Version: b7b27facc7b50a5fce0afaa3df56157136ce181a Version: b7b27facc7b50a5fce0afaa3df56157136ce181a Version: b7b27facc7b50a5fce0afaa3df56157136ce181a |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"arch/arm64/kvm/arm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b0ab34a9e4cd5b88b522cc156e792cefe3085334",
"status": "affected",
"version": "b7b27facc7b50a5fce0afaa3df56157136ce181a",
"versionType": "git"
},
{
"lessThan": "d64461d38972302f0243498ff409b0d54e14e106",
"status": "affected",
"version": "b7b27facc7b50a5fce0afaa3df56157136ce181a",
"versionType": "git"
},
{
"lessThan": "b498f0da45a388b40195f7198455c62fe366a372",
"status": "affected",
"version": "b7b27facc7b50a5fce0afaa3df56157136ce181a",
"versionType": "git"
},
{
"lessThan": "7b854e68365a84dfa984ee81268e10b9311ac9d2",
"status": "affected",
"version": "b7b27facc7b50a5fce0afaa3df56157136ce181a",
"versionType": "git"
},
{
"lessThan": "c0fcd72e7eb50205dc20731033b0b1c67ecbe4dc",
"status": "affected",
"version": "b7b27facc7b50a5fce0afaa3df56157136ce181a",
"versionType": "git"
},
{
"lessThan": "64a04e6320fc5affbadc59dc7024d79f909bfe84",
"status": "affected",
"version": "b7b27facc7b50a5fce0afaa3df56157136ce181a",
"versionType": "git"
},
{
"lessThan": "0aa1b76fe1429629215a7c79820e4b96233ac4a3",
"status": "affected",
"version": "b7b27facc7b50a5fce0afaa3df56157136ce181a",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"arch/arm64/kvm/arm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.19"
},
{
"lessThan": "4.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.269",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.220",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.187",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.156",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.108",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.17.*",
"status": "unaffected",
"version": "6.17.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "6.18",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.269",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.220",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.187",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.156",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.108",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.17.5",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18",
"versionStartIncluding": "4.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: arm64: Prevent access to vCPU events before init\n\nAnother day, another syzkaller bug. KVM erroneously allows userspace to\npend vCPU events for a vCPU that hasn\u0027t been initialized yet, leading to\nKVM interpreting a bunch of uninitialized garbage for routing /\ninjecting the exception.\n\nIn one case the injection code and the hyp disagree on whether the vCPU\nhas a 32bit EL1 and put the vCPU into an illegal mode for AArch64,\ntripping the BUG() in exception_target_el() during the next injection:\n\n kernel BUG at arch/arm64/kvm/inject_fault.c:40!\n Internal error: Oops - BUG: 00000000f2000800 [#1] SMP\n CPU: 3 UID: 0 PID: 318 Comm: repro Not tainted 6.17.0-rc4-00104-g10fd0285305d #6 PREEMPT\n Hardware name: linux,dummy-virt (DT)\n pstate: 21402009 (nzCv daif +PAN -UAO -TCO +DIT -SSBS BTYPE=--)\n pc : exception_target_el+0x88/0x8c\n lr : pend_serror_exception+0x18/0x13c\n sp : ffff800082f03a10\n x29: ffff800082f03a10 x28: ffff0000cb132280 x27: 0000000000000000\n x26: 0000000000000000 x25: ffff0000c2a99c20 x24: 0000000000000000\n x23: 0000000000008000 x22: 0000000000000002 x21: 0000000000000004\n x20: 0000000000008000 x19: ffff0000c2a99c20 x18: 0000000000000000\n x17: 0000000000000000 x16: 0000000000000000 x15: 00000000200000c0\n x14: 0000000000000000 x13: 0000000000000000 x12: 0000000000000000\n x11: 0000000000000000 x10: 0000000000000000 x9 : 0000000000000000\n x8 : ffff800082f03af8 x7 : 0000000000000000 x6 : 0000000000000000\n x5 : ffff800080f621f0 x4 : 0000000000000000 x3 : 0000000000000000\n x2 : 000000000040009b x1 : 0000000000000003 x0 : ffff0000c2a99c20\n Call trace:\n exception_target_el+0x88/0x8c (P)\n kvm_inject_serror_esr+0x40/0x3b4\n __kvm_arm_vcpu_set_events+0xf0/0x100\n kvm_arch_vcpu_ioctl+0x180/0x9d4\n kvm_vcpu_ioctl+0x60c/0x9f4\n __arm64_sys_ioctl+0xac/0x104\n invoke_syscall+0x48/0x110\n el0_svc_common.constprop.0+0x40/0xe0\n do_el0_svc+0x1c/0x28\n el0_svc+0x34/0xf0\n el0t_64_sync_handler+0xa0/0xe4\n el0t_64_sync+0x198/0x19c\n Code: f946bc01 b4fffe61 9101e020 17fffff2 (d4210000)\n\nReject the ioctls outright as no sane VMM would call these before\nKVM_ARM_VCPU_INIT anyway. Even if it did the exception would\u0027ve been\nthrown away by the eventual reset of the vCPU\u0027s state."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-02T12:49:25.880Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b0ab34a9e4cd5b88b522cc156e792cefe3085334"
},
{
"url": "https://git.kernel.org/stable/c/d64461d38972302f0243498ff409b0d54e14e106"
},
{
"url": "https://git.kernel.org/stable/c/b498f0da45a388b40195f7198455c62fe366a372"
},
{
"url": "https://git.kernel.org/stable/c/7b854e68365a84dfa984ee81268e10b9311ac9d2"
},
{
"url": "https://git.kernel.org/stable/c/c0fcd72e7eb50205dc20731033b0b1c67ecbe4dc"
},
{
"url": "https://git.kernel.org/stable/c/64a04e6320fc5affbadc59dc7024d79f909bfe84"
},
{
"url": "https://git.kernel.org/stable/c/0aa1b76fe1429629215a7c79820e4b96233ac4a3"
}
],
"title": "KVM: arm64: Prevent access to vCPU events before init",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2025-40102",
"datePublished": "2025-10-30T09:48:07.790Z",
"dateReserved": "2025-04-16T07:20:57.164Z",
"dateUpdated": "2026-09-02T12:49:25.880Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-31419 (GCVE-0-2026-31419)
Vulnerability from cvelistv5
Published
2026-04-13 13:40
Modified
2026-08-23 12:45
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: bonding: fix use-after-free in bond_xmit_broadcast()
bond_xmit_broadcast() reuses the original skb for the last slave
(determined by bond_is_last_slave()) and clones it for others.
Concurrent slave enslave/release can mutate the slave list during
RCU-protected iteration, changing which slave is "last" mid-loop.
This causes the original skb to be double-consumed (double-freed).
Replace the racy bond_is_last_slave() check with a simple index
comparison (i + 1 == slaves_count) against the pre-snapshot slave
count taken via READ_ONCE() before the loop. This preserves the
zero-copy optimization for the last slave while making the "last"
determination stable against concurrent list mutations.
The UAF can trigger the following crash:
==================================================================
BUG: KASAN: slab-use-after-free in skb_clone
Read of size 8 at addr ffff888100ef8d40 by task exploit/147
CPU: 1 UID: 0 PID: 147 Comm: exploit Not tainted 7.0.0-rc3+ #4 PREEMPTLAZY
Call Trace:
<TASK>
dump_stack_lvl (lib/dump_stack.c:123)
print_report (mm/kasan/report.c:379 mm/kasan/report.c:482)
kasan_report (mm/kasan/report.c:597)
skb_clone (include/linux/skbuff.h:1724 include/linux/skbuff.h:1792 include/linux/skbuff.h:3396 net/core/skbuff.c:2108)
bond_xmit_broadcast (drivers/net/bonding/bond_main.c:5334)
bond_start_xmit (drivers/net/bonding/bond_main.c:5567 drivers/net/bonding/bond_main.c:5593)
dev_hard_start_xmit (include/linux/netdevice.h:5325 include/linux/netdevice.h:5334 net/core/dev.c:3871 net/core/dev.c:3887)
__dev_queue_xmit (include/linux/netdevice.h:3601 net/core/dev.c:4838)
ip6_finish_output2 (include/net/neighbour.h:540 include/net/neighbour.h:554 net/ipv6/ip6_output.c:136)
ip6_finish_output (net/ipv6/ip6_output.c:208 net/ipv6/ip6_output.c:219)
ip6_output (net/ipv6/ip6_output.c:250)
ip6_send_skb (net/ipv6/ip6_output.c:1985)
udp_v6_send_skb (net/ipv6/udp.c:1442)
udpv6_sendmsg (net/ipv6/udp.c:1733)
__sys_sendto (net/socket.c:730 net/socket.c:742 net/socket.c:2206)
__x64_sys_sendto (net/socket.c:2209)
do_syscall_64 (arch/x86/entry/syscall_64.c:63 arch/x86/entry/syscall_64.c:94)
entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130)
</TASK>
Allocated by task 147:
Freed by task 147:
The buggy address belongs to the object at ffff888100ef8c80
which belongs to the cache skbuff_head_cache of size 224
The buggy address is located 192 bytes inside of
freed 224-byte region [ffff888100ef8c80, ffff888100ef8d60)
Memory state around the buggy address:
ffff888100ef8c00: fb fb fb fb fc fc fc fc fc fc fc fc fc fc fc fc
ffff888100ef8c80: fa fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
>ffff888100ef8d00: fb fb fb fb fb fb fb fb fb fb fb fb fc fc fc fc
^
ffff888100ef8d80: fc fc fc fc fc fc fc fc fa fb fb fb fb fb fb fb
ffff888100ef8e00: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
==================================================================
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 4e5bd03ae34652cd932ab4c91c71c511793df75c Version: 4e5bd03ae34652cd932ab4c91c71c511793df75c Version: 4e5bd03ae34652cd932ab4c91c71c511793df75c Version: 4e5bd03ae34652cd932ab4c91c71c511793df75c Version: 4e5bd03ae34652cd932ab4c91c71c511793df75c Version: 4e5bd03ae34652cd932ab4c91c71c511793df75c Version: 20949c3816463e97c6f8fe84c0280c7e5ae83a8d Version: f1d206181f19b00b275b258fea1418718a2f4173 Version: c1f1691ef84fa6d38fa5e5148eca073145e97ffa Version: 5.10.94 ≤ Version: 5.15.17 ≤ Version: 5.16.3 ≤ |
||
{
"containers": {
"adp": [
{
"affected": [
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:10.1",
"cpe:/o:redhat:enterprise_linux:10.2"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 10",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:6.12.0-124.55.1.el10_1",
"versionType": "rpm"
},
{
"lessThan": "*",
"status": "unaffected",
"version": "0:6.12.0-211.22.1.el10_2",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:10.2"
],
"defaultStatus": "unaffected",
"packageName": "kpatch-patch",
"product": "Red Hat Enterprise Linux 10",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux_eus:10.0"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 10.0 Extended Update Support",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:6.12.0-55.76.1.el10_0",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/a:redhat:enterprise_linux:8::nfv"
],
"defaultStatus": "affected",
"packageName": "kernel-rt",
"product": "Red Hat Enterprise Linux 8",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:4.18.0-553.136.1.rt7.477.el8_10",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:8"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 8",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:4.18.0-553.136.1.el8_10",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:8"
],
"defaultStatus": "unaffected",
"packageName": "kpatch-patch",
"product": "Red Hat Enterprise Linux 8",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:rhel_tus:8.8"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:4.18.0-477.143.1.el8_8",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:rhel_e4s:8.8"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:4.18.0-477.143.1.el8_8",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:rhel_e4s:8.8"
],
"defaultStatus": "unaffected",
"packageName": "kpatch-patch",
"product": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/a:redhat:enterprise_linux:9",
"cpe:/o:redhat:enterprise_linux:9"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 9",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:5.14.0-687.15.1.el9_8",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:9"
],
"defaultStatus": "unaffected",
"packageName": "kpatch-patch",
"product": "Red Hat Enterprise Linux 9",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/a:redhat:rhel_e4s:9.2"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:5.14.0-284.174.1.el9_2",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/a:redhat:rhel_e4s:9.2::nfv"
],
"defaultStatus": "affected",
"packageName": "kernel-rt",
"product": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:5.14.0-284.174.1.rt14.459.el9_2",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:rhel_e4s:9.2"
],
"defaultStatus": "unaffected",
"packageName": "kpatch-patch",
"product": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/a:redhat:rhel_eus:9.4"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 9.4 Extended Update Support",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:5.14.0-427.127.1.el9_4",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:rhel_e4s:9.4"
],
"defaultStatus": "unaffected",
"packageName": "kpatch-patch",
"product": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/a:redhat:rhel_eus:9.6"
],
"defaultStatus": "affected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 9.6 Extended Update Support",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:5.14.0-570.119.1.el9_6",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:rhel_eus:9.6"
],
"defaultStatus": "unaffected",
"packageName": "kpatch-patch",
"product": "Red Hat Enterprise Linux 9.6 Extended Update Support",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:6"
],
"defaultStatus": "unaffected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 6",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:7"
],
"defaultStatus": "unaffected",
"packageName": "kernel",
"product": "Red Hat Enterprise Linux 7",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:7"
],
"defaultStatus": "unaffected",
"packageName": "kernel-rt",
"product": "Red Hat Enterprise Linux 7",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:9"
],
"defaultStatus": "affected",
"packageName": "kernel-rt",
"product": "Red Hat Enterprise Linux 9",
"vendor": "Red Hat"
}
],
"datePublic": "2026-04-13T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "A flaw was found in the Linux kernel\u0027s bonding driver. A local attacker with low privileges could exploit a use-after-free vulnerability in the `bond_xmit_broadcast()` function. This occurs due to a race condition during concurrent slave enslave/release operations, which can lead to the original socket buffer (skb) being double-freed. Successful exploitation of this flaw can result in a system crash, leading to a denial of service."
}
],
"metrics": [
{
"other": {
"content": {
"namespace": "https://access.redhat.com/security/updates/classification/",
"value": "Important"
},
"type": "Red Hat severity rating"
}
},
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 7,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-416",
"description": "Use After Free",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-07-15T01:09:22.472Z",
"orgId": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
"shortName": "redhat-SADP"
},
"references": [
{
"tags": [
"vdb-entry",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/security/cve/CVE-2026-31419"
},
{
"name": "RHBZ#2457829",
"tags": [
"issue-tracking",
"x_refsource_REDHAT"
],
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457829"
},
{
"tags": [
"x_sadp-csaf-vex"
],
"url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-31419.json"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:22334"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:13566"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:25191"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:22940"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:21209"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:23224"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:25217"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:35870"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:27353"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:36530"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:19521"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:36531"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:36532"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:36533"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:36534"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:36172"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:27354"
},
{
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:22900"
}
],
"solutions": [
{
"lang": "en",
"value": "RHSA-2026:22334: Red Hat Enterprise Linux AppStream EUS (v. 10.0), Red Hat Enterprise Linux BaseOS EUS (v. 10.0), Red Hat Enterprise Linux CodeReady Linux Builder EUS (v. 10.0), Red Hat Enterprise Linux Real Time EUS (v. 10.0), Red Hat Enterprise Linux Real Time for NFV EUS (v. 10.0)"
},
{
"lang": "en",
"value": "RHSA-2026:13566: Red Hat Enterprise Linux AppStream (v. 10), Red Hat Enterprise Linux BaseOS (v. 10), Red Hat Enterprise Linux CodeReady Linux Builder (v. 10), Red Hat Enterprise Linux Real Time (v. 10), Red Hat Enterprise Linux Real Time for NFV (v. 10)"
},
{
"lang": "en",
"value": "RHSA-2026:25191: Red Hat Enterprise Linux AppStream (v. 10), Red Hat Enterprise Linux BaseOS (v. 10), Red Hat Enterprise Linux CodeReady Linux Builder (v. 10), Red Hat Enterprise Linux Real Time (v. 10), Red Hat Enterprise Linux Real Time for NFV (v. 10)"
},
{
"lang": "en",
"value": "RHSA-2026:22940: Red Hat Enterprise Linux AppStream E4S (v.9.2), Red Hat Enterprise Linux BaseOS E4S (v.9.2)"
},
{
"lang": "en",
"value": "RHSA-2026:21209: Red Hat CodeReady Linux Builder EUS (v.9.4), Red Hat Enterprise Linux AppStream EUS (v.9.4), Red Hat Enterprise Linux BaseOS EUS (v.9.4), Red Hat Enterprise Linux Real Time EUS (v.9.4), Red Hat Enterprise Linux Real Time for NFV EUS (v.9.4)"
},
{
"lang": "en",
"value": "RHSA-2026:23224: Red Hat CodeReady Linux Builder EUS (v.9.6), Red Hat Enterprise Linux AppStream EUS (v.9.6), Red Hat Enterprise Linux BaseOS EUS (v.9.6), Red Hat Enterprise Linux Real Time EUS (v.9.6), Red Hat Enterprise Linux Real Time for NFV EUS (v.9.6)"
},
{
"lang": "en",
"value": "RHSA-2026:25217: Red Hat Enterprise Linux AppStream (v. 9), Red Hat Enterprise Linux BaseOS (v. 9), Red Hat Enterprise Linux CodeReady Linux Builder (v. 9), Red Hat Enterprise Linux Real Time (v. 9), Red Hat Enterprise Linux Real Time for NFV (v. 9)"
},
{
"lang": "en",
"value": "RHSA-2026:35870: Red Hat Enterprise Linux BaseOS (v. 10)"
},
{
"lang": "en",
"value": "RHSA-2026:27353: Red Hat Enterprise Linux BaseOS (v. 8), Red Hat Enterprise Linux CRB (v. 8)"
},
{
"lang": "en",
"value": "RHSA-2026:36530: Red Hat Enterprise Linux BaseOS (v. 8)"
},
{
"lang": "en",
"value": "RHSA-2026:19521: Red Hat Enterprise Linux BaseOS E4S (v.8.8), Red Hat Enterprise Linux BaseOS TUS (v.8.8)"
},
{
"lang": "en",
"value": "RHSA-2026:36531: Red Hat Enterprise Linux BaseOS E4S (v.8.8)"
},
{
"lang": "en",
"value": "RHSA-2026:36532: Red Hat Enterprise Linux BaseOS E4S (v.9.2)"
},
{
"lang": "en",
"value": "RHSA-2026:36533: Red Hat Enterprise Linux BaseOS E4S (v.9.4)"
},
{
"lang": "en",
"value": "RHSA-2026:36534: Red Hat Enterprise Linux BaseOS EUS (v.9.6)"
},
{
"lang": "en",
"value": "RHSA-2026:36172: Red Hat Enterprise Linux BaseOS (v. 9)"
},
{
"lang": "en",
"value": "RHSA-2026:27354: Red Hat Enterprise Linux NFV (v. 8), Red Hat Enterprise Linux RT (v. 8)"
},
{
"lang": "en",
"value": "RHSA-2026:22900: Red Hat Enterprise Linux Real Time E4S (v.9.2), Red Hat Enterprise Linux Real Time for NFV E4S (v.9.2)"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-04-13T00:00:00.000Z",
"value": "Reported to Red Hat."
},
{
"lang": "en",
"time": "2026-04-13T00:00:00.000Z",
"value": "Made public."
}
],
"title": "kernel: Linux kernel: Use-after-free in bonding driver leads to denial of service",
"x_adpType": "supplier",
"x_generator": {
"engine": "sadp-cli 1.0.0"
}
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/bonding/bond_main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "00752893f96b344f258c9c6de18b33171ac4872c",
"status": "affected",
"version": "4e5bd03ae34652cd932ab4c91c71c511793df75c",
"versionType": "git"
},
{
"lessThan": "2de5c8eea0a9db99dae7c36f4b541b74b41d3a04",
"status": "affected",
"version": "4e5bd03ae34652cd932ab4c91c71c511793df75c",
"versionType": "git"
},
{
"lessThan": "a0f661918edc79d7a75e468128af8d41e2a1a83a",
"status": "affected",
"version": "4e5bd03ae34652cd932ab4c91c71c511793df75c",
"versionType": "git"
},
{
"lessThan": "d4cc7e4c80b1634c7b1497574a2fdb18df6c026c",
"status": "affected",
"version": "4e5bd03ae34652cd932ab4c91c71c511793df75c",
"versionType": "git"
},
{
"lessThan": "f5b94654a4a19891a8108d66ef166de6c028c6cd",
"status": "affected",
"version": "4e5bd03ae34652cd932ab4c91c71c511793df75c",
"versionType": "git"
},
{
"lessThan": "2884bf72fb8f03409e423397319205de48adca16",
"status": "affected",
"version": "4e5bd03ae34652cd932ab4c91c71c511793df75c",
"versionType": "git"
},
{
"status": "affected",
"version": "20949c3816463e97c6f8fe84c0280c7e5ae83a8d",
"versionType": "git"
},
{
"status": "affected",
"version": "f1d206181f19b00b275b258fea1418718a2f4173",
"versionType": "git"
},
{
"status": "affected",
"version": "c1f1691ef84fa6d38fa5e5148eca073145e97ffa",
"versionType": "git"
},
{
"lessThan": "5.11",
"status": "affected",
"version": "5.10.94",
"versionType": "semver"
},
{
"lessThan": "5.16",
"status": "affected",
"version": "5.15.17",
"versionType": "semver"
},
{
"lessThan": "5.17",
"status": "affected",
"version": "5.16.3",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/bonding/bond_main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.17"
},
{
"lessThan": "5.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.95",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.22",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.19.*",
"status": "unaffected",
"version": "6.19.12",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.0",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.143",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.95",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.22",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.19.12",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.10.94",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.15.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.16.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: bonding: fix use-after-free in bond_xmit_broadcast()\n\nbond_xmit_broadcast() reuses the original skb for the last slave\n(determined by bond_is_last_slave()) and clones it for others.\nConcurrent slave enslave/release can mutate the slave list during\nRCU-protected iteration, changing which slave is \"last\" mid-loop.\nThis causes the original skb to be double-consumed (double-freed).\n\nReplace the racy bond_is_last_slave() check with a simple index\ncomparison (i + 1 == slaves_count) against the pre-snapshot slave\ncount taken via READ_ONCE() before the loop. This preserves the\nzero-copy optimization for the last slave while making the \"last\"\ndetermination stable against concurrent list mutations.\n\nThe UAF can trigger the following crash:\n\n==================================================================\nBUG: KASAN: slab-use-after-free in skb_clone\nRead of size 8 at addr ffff888100ef8d40 by task exploit/147\n\nCPU: 1 UID: 0 PID: 147 Comm: exploit Not tainted 7.0.0-rc3+ #4 PREEMPTLAZY\nCall Trace:\n \u003cTASK\u003e\n dump_stack_lvl (lib/dump_stack.c:123)\n print_report (mm/kasan/report.c:379 mm/kasan/report.c:482)\n kasan_report (mm/kasan/report.c:597)\n skb_clone (include/linux/skbuff.h:1724 include/linux/skbuff.h:1792 include/linux/skbuff.h:3396 net/core/skbuff.c:2108)\n bond_xmit_broadcast (drivers/net/bonding/bond_main.c:5334)\n bond_start_xmit (drivers/net/bonding/bond_main.c:5567 drivers/net/bonding/bond_main.c:5593)\n dev_hard_start_xmit (include/linux/netdevice.h:5325 include/linux/netdevice.h:5334 net/core/dev.c:3871 net/core/dev.c:3887)\n __dev_queue_xmit (include/linux/netdevice.h:3601 net/core/dev.c:4838)\n ip6_finish_output2 (include/net/neighbour.h:540 include/net/neighbour.h:554 net/ipv6/ip6_output.c:136)\n ip6_finish_output (net/ipv6/ip6_output.c:208 net/ipv6/ip6_output.c:219)\n ip6_output (net/ipv6/ip6_output.c:250)\n ip6_send_skb (net/ipv6/ip6_output.c:1985)\n udp_v6_send_skb (net/ipv6/udp.c:1442)\n udpv6_sendmsg (net/ipv6/udp.c:1733)\n __sys_sendto (net/socket.c:730 net/socket.c:742 net/socket.c:2206)\n __x64_sys_sendto (net/socket.c:2209)\n do_syscall_64 (arch/x86/entry/syscall_64.c:63 arch/x86/entry/syscall_64.c:94)\n entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130)\n \u003c/TASK\u003e\n\nAllocated by task 147:\n\nFreed by task 147:\n\nThe buggy address belongs to the object at ffff888100ef8c80\n which belongs to the cache skbuff_head_cache of size 224\nThe buggy address is located 192 bytes inside of\n freed 224-byte region [ffff888100ef8c80, ffff888100ef8d60)\n\nMemory state around the buggy address:\n ffff888100ef8c00: fb fb fb fb fc fc fc fc fc fc fc fc fc fc fc fc\n ffff888100ef8c80: fa fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb\n\u003effff888100ef8d00: fb fb fb fb fb fb fb fb fb fb fb fb fc fc fc fc\n ^\n ffff888100ef8d80: fc fc fc fc fc fc fc fc fa fb fb fb fb fb fb fb\n ffff888100ef8e00: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb\n=================================================================="
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerability is in the packet transmit path triggered by the sendto() syscall; the race requires concurrent local slave management (enslave/release) via netlink, which a remote attacker cannot perform.\nAC:L - The attacker controls both sides of the race \u2014 one thread sends packets through the bond interface while another concurrently adds/removes slaves \u2014 making the race reliably triggerable.\nPR:L - Requires CAP_NET_ADMIN for bonding device creation and slave management, but this capability is obtainable by any unprivileged user via user namespaces (unshare -Urn).\nUI:N - No user interaction is required; the attacker sets up the bonding interface, sends packets, and triggers the race entirely autonomously.\nS:U - This is a standard kernel vulnerability that does not cross any security boundary such as a VM or sandbox.\nC:H - The use-after-free on a 224-byte sk_buff slab object can be leveraged via heap spraying to achieve arbitrary kernel memory reads.\nI:H - The use-after-free on sk_buff allows heap spray reclamation with attacker-controlled data, enabling arbitrary write primitives and potential code execution.\nA:H - The KASAN report in the commit demonstrates a kernel crash (slab-use-after-free), and any UAF reliably causes kernel oops/panic."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:45:30.305Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/00752893f96b344f258c9c6de18b33171ac4872c"
},
{
"url": "https://git.kernel.org/stable/c/2de5c8eea0a9db99dae7c36f4b541b74b41d3a04"
},
{
"url": "https://git.kernel.org/stable/c/a0f661918edc79d7a75e468128af8d41e2a1a83a"
},
{
"url": "https://git.kernel.org/stable/c/d4cc7e4c80b1634c7b1497574a2fdb18df6c026c"
},
{
"url": "https://git.kernel.org/stable/c/f5b94654a4a19891a8108d66ef166de6c028c6cd"
},
{
"url": "https://git.kernel.org/stable/c/2884bf72fb8f03409e423397319205de48adca16"
}
],
"title": "net: bonding: fix use-after-free in bond_xmit_broadcast()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-31419",
"datePublished": "2026-04-13T13:40:23.279Z",
"dateReserved": "2026-03-09T15:48:24.088Z",
"dateUpdated": "2026-08-23T12:45:30.305Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-46266 (GCVE-0-2026-46266)
Vulnerability from cvelistv5
Published
2026-06-03 15:50
Modified
2026-09-02 12:49
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP
Yizhou Zhao reported that simply having one RAW socket on protocol
IPPROTO_RAW (255) was dangerous.
socket(AF_INET, SOCK_RAW, 255);
A malicious incoming ICMP packet can set the protocol field to 255
and match this socket, leading to FNHE cache changes.
inner = IP(src="192.168.2.1", dst="8.8.8.8", proto=255)/Raw("TEST")
pkt = IP(src="192.168.1.1", dst="192.168.2.1")/ICMP(type=3, code=4, nexthopmtu=576)/inner
"man 7 raw" states:
A protocol of IPPROTO_RAW implies enabled IP_HDRINCL and is able
to send any IP protocol that is specified in the passed header.
Receiving of all IP protocols via IPPROTO_RAW is not possible
using raw sockets.
Make sure we drop these malicious packets.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ipv4/icmp.c",
"net/ipv6/icmp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "47276297140ee6712646f9b19fb04fe26daedd01",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "db76b75ede3810e7cf9cfea5067d4f3e0993768b",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "19e42490c89bac9a388f28179e66bebbef350f99",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "531c1aec81bfe19d00af13da5531fbb8209e4bd2",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "719d3932b8f6e3348ce2f0ac58e278301fc17575",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "c89477ad79446867394360b29bb801010fc3ff22",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ipv4/icmp.c",
"net/ipv6/icmp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.187",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.128",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.75",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.14",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.19.*",
"status": "unaffected",
"version": "6.19.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.0",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.187",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.128",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.75",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.14",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.19.4",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ninet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP\n\nYizhou Zhao reported that simply having one RAW socket on protocol\nIPPROTO_RAW (255) was dangerous.\n\n socket(AF_INET, SOCK_RAW, 255);\n\nA malicious incoming ICMP packet can set the protocol field to 255\nand match this socket, leading to FNHE cache changes.\n\ninner = IP(src=\"192.168.2.1\", dst=\"8.8.8.8\", proto=255)/Raw(\"TEST\")\npkt = IP(src=\"192.168.1.1\", dst=\"192.168.2.1\")/ICMP(type=3, code=4, nexthopmtu=576)/inner\n\n\"man 7 raw\" states:\n\n A protocol of IPPROTO_RAW implies enabled IP_HDRINCL and is able\n to send any IP protocol that is specified in the passed header.\n Receiving of all IP protocols via IPPROTO_RAW is not possible\n using raw sockets.\n\nMake sure we drop these malicious packets."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug is reached when a remotely sourced ICMP error (DEST_UNREACH/FRAG_NEEDED or REDIRECT) is received and processed through icmp_rcv() \u2192 icmp_unreach()/icmp_redirect() \u2192 icmp_socket_deliver(), which is standard internet-facing IPv4 input on any host accepting ICMP.\nAC:L - Exploitation is a single, deterministic crafted ICMP packet (inner IP proto=255, attacker-chosen daddr/PMTU) matching an open IPPROTO_RAW socket; an attacker can reliably create that socket via CAP_NET_RAW in a user+network namespace (unshare -Urn) without winning a race.\nPR:N - The network trigger requires no authentication or victim credentials\u2014only delivery of forged ICMP to the target IP; the remote attacker does not need local privileges even though a local IPPROTO_RAW socket must exist on the victim (typically opened by a daemon or a co-resident userns holder).\nUI:N - No victim user action is required beyond normal network operation; the attacker sends ICMP directly to the host without tricking anyone into clicking, mounting, or opening files.\nS:U - Impact is confined to the kernel IPv4 routing/FNHE cache within the same network namespace; it does not cross a VM/hypervisor or IOMMU security boundary.\nC:N - This is a missing validation/logic bug that poisons route-cache metadata (PMTU/gateway); there is no memory read, pointer leak, or information-disclosure primitive.\nI:H - Before the fix, raw_err() unconditionally calls ipv4_sk_update_pmtu()/ipv4_sk_redirect(), letting a remote attacker inject attacker-controlled PMTU and gateway values into the system-wide FNHE exception cache for arbitrary destination addresses, altering forwarding for all local traffic to those destinations.\nA:H - Repeated forged ICMP FRAG_NEEDED packets can persistently force minimum PMTU entries in FNHE for chosen destinations, causing severe throughput collapse and connectivity failure for affected flows across the entire host or shared network namespace."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-02T12:49:33.535Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/47276297140ee6712646f9b19fb04fe26daedd01"
},
{
"url": "https://git.kernel.org/stable/c/db76b75ede3810e7cf9cfea5067d4f3e0993768b"
},
{
"url": "https://git.kernel.org/stable/c/19e42490c89bac9a388f28179e66bebbef350f99"
},
{
"url": "https://git.kernel.org/stable/c/531c1aec81bfe19d00af13da5531fbb8209e4bd2"
},
{
"url": "https://git.kernel.org/stable/c/719d3932b8f6e3348ce2f0ac58e278301fc17575"
},
{
"url": "https://git.kernel.org/stable/c/c89477ad79446867394360b29bb801010fc3ff22"
}
],
"title": "inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-46266",
"datePublished": "2026-06-03T15:50:07.907Z",
"dateReserved": "2026-05-13T15:03:33.108Z",
"dateUpdated": "2026-09-02T12:49:33.535Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80794 (GCVE-0-2026-80794)
Vulnerability from cvelistv5
Published
2026-09-04 15:13
Modified
2026-09-04 15:13
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
nfc: nci: fix uninit-value in the RF discover/activated NTF handlers
nci_rf_discover_ntf_packet() and nci_rf_intf_activated_ntf_packet() each
parse a notification into an on-stack struct (nci_rf_discover_ntf /
nci_rf_intf_activated_ntf) that is not initialised. The RF
technology-specific parameters are only extracted when
rf_tech_specific_params_len is non-zero, so a notification that reports a
zero length leaves the rf_tech_specific_params union uninitialised - and
both handlers then pass it to nci_add_new_protocol(), which reads it:
- discover: nci_add_new_target() -> nci_add_new_protocol();
- activated: nci_target_auto_activated() -> nci_add_new_protocol().
nci_add_new_protocol() uses nfca_poll->nfcid1_len as both a branch
condition and a memcpy() length and copies nfcid1/sens_res/sel_res into
ndev->targets, which is later exposed to user space via NFC_CMD_GET_TARGET.
BUG: KMSAN: uninit-value in nci_add_new_protocol+0x624/0x6c0
nci_add_new_protocol+0x624/0x6c0
nci_ntf_packet+0x25b2/0x3c30
nci_rx_work+0x318/0x5d0
process_scheduled_works+0x84b/0x17a0
worker_thread+0xc10/0x11b0
kthread+0x376/0x500
Local variable ntf.i created at:
nci_ntf_packet+0xbc2/0x3c30
Zero-initialise both on-stack notifications so the union reads back as
zero when no technology-specific parameters are present.
References
| URL | Tags | ||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20 Version: e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20 Version: e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20 Version: e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20 Version: e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20 Version: e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20 Version: e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20 Version: e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20 Version: e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/nfc/nci/ntf.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "1007a6b429d756513abd25bd00290908f2e89a4a",
"status": "affected",
"version": "e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20",
"versionType": "git"
},
{
"lessThan": "4bda9ef8392710f21e99027467f3f4afdfb5c99a",
"status": "affected",
"version": "e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20",
"versionType": "git"
},
{
"lessThan": "fe69fed3495f676578d49414a069ad7d8468e2ce",
"status": "affected",
"version": "e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20",
"versionType": "git"
},
{
"lessThan": "7489f59d1ea2d3298aa41de7baf193e5e6e132f6",
"status": "affected",
"version": "e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20",
"versionType": "git"
},
{
"lessThan": "7086dab72b3ed95df96842801e10e935cfeb27a3",
"status": "affected",
"version": "e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20",
"versionType": "git"
},
{
"lessThan": "0d4b5cfab6891a5ca0f6aef209beebba4bd7c095",
"status": "affected",
"version": "e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20",
"versionType": "git"
},
{
"lessThan": "5bd00c0e1470d90d77a7c60242854257ddf14e00",
"status": "affected",
"version": "e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20",
"versionType": "git"
},
{
"lessThan": "d6f743d3d388913135681cde051c08823730194f",
"status": "affected",
"version": "e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20",
"versionType": "git"
},
{
"lessThan": "8cbe06c1e699c0a165dae5093a2550e65f914818",
"status": "affected",
"version": "e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/nfc/nci/ntf.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.3"
},
{
"lessThan": "3.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.269",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.218",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.185",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.154",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.106",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.47",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.1",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.269",
"versionStartIncluding": "3.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.218",
"versionStartIncluding": "3.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.185",
"versionStartIncluding": "3.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.154",
"versionStartIncluding": "3.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.106",
"versionStartIncluding": "3.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.47",
"versionStartIncluding": "3.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.11",
"versionStartIncluding": "3.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.1",
"versionStartIncluding": "3.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "3.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: nci: fix uninit-value in the RF discover/activated NTF handlers\n\nnci_rf_discover_ntf_packet() and nci_rf_intf_activated_ntf_packet() each\nparse a notification into an on-stack struct (nci_rf_discover_ntf /\nnci_rf_intf_activated_ntf) that is not initialised. The RF\ntechnology-specific parameters are only extracted when\nrf_tech_specific_params_len is non-zero, so a notification that reports a\nzero length leaves the rf_tech_specific_params union uninitialised - and\nboth handlers then pass it to nci_add_new_protocol(), which reads it:\n\n - discover: nci_add_new_target() -\u003e nci_add_new_protocol();\n - activated: nci_target_auto_activated() -\u003e nci_add_new_protocol().\n\nnci_add_new_protocol() uses nfca_poll-\u003enfcid1_len as both a branch\ncondition and a memcpy() length and copies nfcid1/sens_res/sel_res into\nndev-\u003etargets, which is later exposed to user space via NFC_CMD_GET_TARGET.\n\n BUG: KMSAN: uninit-value in nci_add_new_protocol+0x624/0x6c0\n nci_add_new_protocol+0x624/0x6c0\n nci_ntf_packet+0x25b2/0x3c30\n nci_rx_work+0x318/0x5d0\n process_scheduled_works+0x84b/0x17a0\n worker_thread+0xc10/0x11b0\n kthread+0x376/0x500\n Local variable ntf.i created at:\n nci_ntf_packet+0xbc2/0x3c30\n\nZero-initialise both on-stack notifications so the union reads back as\nzero when no technology-specific parameters are present."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T15:13:07.169Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/1007a6b429d756513abd25bd00290908f2e89a4a"
},
{
"url": "https://git.kernel.org/stable/c/4bda9ef8392710f21e99027467f3f4afdfb5c99a"
},
{
"url": "https://git.kernel.org/stable/c/fe69fed3495f676578d49414a069ad7d8468e2ce"
},
{
"url": "https://git.kernel.org/stable/c/7489f59d1ea2d3298aa41de7baf193e5e6e132f6"
},
{
"url": "https://git.kernel.org/stable/c/7086dab72b3ed95df96842801e10e935cfeb27a3"
},
{
"url": "https://git.kernel.org/stable/c/0d4b5cfab6891a5ca0f6aef209beebba4bd7c095"
},
{
"url": "https://git.kernel.org/stable/c/5bd00c0e1470d90d77a7c60242854257ddf14e00"
},
{
"url": "https://git.kernel.org/stable/c/d6f743d3d388913135681cde051c08823730194f"
},
{
"url": "https://git.kernel.org/stable/c/8cbe06c1e699c0a165dae5093a2550e65f914818"
}
],
"title": "nfc: nci: fix uninit-value in the RF discover/activated NTF handlers",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80794",
"datePublished": "2026-09-04T15:13:07.169Z",
"dateReserved": "2026-08-26T14:34:25.793Z",
"dateUpdated": "2026-09-04T15:13:07.169Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68301 (GCVE-0-2026-68301)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-19 16:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: hsr: fix memory leak on slave unregistration by removing synced VLANs
When an HSR master device is brought UP, it auto-adds VLAN 0 via
vlan_vid0_add(), which propagates VID 0 to its slave devices (slave A and B).
If a slave device is later unregistered while HSR is active (e.g., during
netns cleanup or interface destruction), hsr_del_port() is called to
detach the slave port from the HSR master. However, hsr_del_port() currently
does not delete the VLAN IDs that were synced to the slave device by HSR.
As a result, the slave device retains a refcount on VID 0 (and any other
synced VLANs). When the slave device is destroyed, its vlan_info /
vlan_vid_info structure remains allocated, leading to a memory leak.
Fix this by calling vlan_vids_del_by_dev(port->dev, master->dev) in
hsr_del_port() before unlinking slave A or slave B ports, matching the
propagation logic in hsr_ndo_vlan_rx_add_vid() / hsr_ndo_vlan_rx_kill_vid()
and the cleanup behavior in bonding and team drivers.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1100242709d5644856131a9dd25d32672ebe7357 Version: a2accc07bdcfb0c7ab2cacdca6a1fe8267816efa Version: 72dbae1f2f2159395089405c6c54632f2613f1be Version: c707d2c5541d2bb94131968ad5dfeb06427a1dba Version: 1a8a63a5305e95519de6f941922dfcd8179f82e5 Version: 1a8a63a5305e95519de6f941922dfcd8179f82e5 Version: 1a8a63a5305e95519de6f941922dfcd8179f82e5 Version: 5.15.194 ≤ Version: 6.1.153 ≤ Version: 6.6.107 ≤ Version: 6.12.48 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/hsr/hsr_slave.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ccc822e9e4f09a6c2ca73ad5334570441947f94f",
"status": "affected",
"version": "1100242709d5644856131a9dd25d32672ebe7357",
"versionType": "git"
},
{
"lessThan": "79ff0547676acdeceda445c3fce4071b0a887b70",
"status": "affected",
"version": "a2accc07bdcfb0c7ab2cacdca6a1fe8267816efa",
"versionType": "git"
},
{
"lessThan": "f72c312af6c7897ab0f8a2b5a63f917a207a4143",
"status": "affected",
"version": "72dbae1f2f2159395089405c6c54632f2613f1be",
"versionType": "git"
},
{
"lessThan": "21d48408479a17eb65568a765930adea37e4d804",
"status": "affected",
"version": "c707d2c5541d2bb94131968ad5dfeb06427a1dba",
"versionType": "git"
},
{
"lessThan": "b5ded444621b6180df9f3d4e07045fc1fc1e8cd9",
"status": "affected",
"version": "1a8a63a5305e95519de6f941922dfcd8179f82e5",
"versionType": "git"
},
{
"lessThan": "ae995b8002d3af134560a706c0e111a89e26317c",
"status": "affected",
"version": "1a8a63a5305e95519de6f941922dfcd8179f82e5",
"versionType": "git"
},
{
"lessThan": "dcf15eaf5641812f1cfc5e96537380132a7da89d",
"status": "affected",
"version": "1a8a63a5305e95519de6f941922dfcd8179f82e5",
"versionType": "git"
},
{
"lessThan": "5.15.216",
"status": "affected",
"version": "5.15.194",
"versionType": "semver"
},
{
"lessThan": "6.1.183",
"status": "affected",
"version": "6.1.153",
"versionType": "semver"
},
{
"lessThan": "6.6.148",
"status": "affected",
"version": "6.6.107",
"versionType": "semver"
},
{
"lessThan": "6.12.101",
"status": "affected",
"version": "6.12.48",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/hsr/hsr_slave.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.13"
},
{
"lessThan": "6.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.15.194",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "6.1.153",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.6.107",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.12.48",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: hsr: fix memory leak on slave unregistration by removing synced VLANs\n\nWhen an HSR master device is brought UP, it auto-adds VLAN 0 via\nvlan_vid0_add(), which propagates VID 0 to its slave devices (slave A and B).\n\nIf a slave device is later unregistered while HSR is active (e.g., during\nnetns cleanup or interface destruction), hsr_del_port() is called to\ndetach the slave port from the HSR master. However, hsr_del_port() currently\ndoes not delete the VLAN IDs that were synced to the slave device by HSR.\n\nAs a result, the slave device retains a refcount on VID 0 (and any other\nsynced VLANs). When the slave device is destroyed, its vlan_info /\nvlan_vid_info structure remains allocated, leading to a memory leak.\n\nFix this by calling vlan_vids_del_by_dev(port-\u003edev, master-\u003edev) in\nhsr_del_port() before unlinking slave A or slave B ports, matching the\npropagation logic in hsr_ndo_vlan_rx_add_vid() / hsr_ndo_vlan_rx_kill_vid()\nand the cleanup behavior in bonding and team drivers."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:32:53.463Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ccc822e9e4f09a6c2ca73ad5334570441947f94f"
},
{
"url": "https://git.kernel.org/stable/c/79ff0547676acdeceda445c3fce4071b0a887b70"
},
{
"url": "https://git.kernel.org/stable/c/f72c312af6c7897ab0f8a2b5a63f917a207a4143"
},
{
"url": "https://git.kernel.org/stable/c/21d48408479a17eb65568a765930adea37e4d804"
},
{
"url": "https://git.kernel.org/stable/c/b5ded444621b6180df9f3d4e07045fc1fc1e8cd9"
},
{
"url": "https://git.kernel.org/stable/c/ae995b8002d3af134560a706c0e111a89e26317c"
},
{
"url": "https://git.kernel.org/stable/c/dcf15eaf5641812f1cfc5e96537380132a7da89d"
}
],
"title": "net: hsr: fix memory leak on slave unregistration by removing synced VLANs",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68301",
"datePublished": "2026-08-10T12:02:35.155Z",
"dateReserved": "2026-07-30T09:28:09.380Z",
"dateUpdated": "2026-08-19T16:32:53.463Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80803 (GCVE-0-2026-80803)
Vulnerability from cvelistv5
Published
2026-09-04 15:13
Modified
2026-09-04 15:13
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
nfc: digital: clamp SENSF_RES length to the destination buffer
digital_in_recv_sensf_res() memcpy()s resp->len bytes from a remote
NFC-F device response into the NFC_SENSF_RES_MAXSIZE-byte target.sensf_res
field without an upper-bound check. A nearby malicious NFC-F device can
send an oversized SENSF_RES response to overflow the stack-local struct
nfc_target.
Clamp resp->len to NFC_SENSF_RES_MAXSIZE before the copy.
Found by 0sec automated security-research tooling (https://0sec.ai).
References
| URL | Tags | ||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 8c0695e4998dd268ff2a05951961247b7e015651 Version: 8c0695e4998dd268ff2a05951961247b7e015651 Version: 8c0695e4998dd268ff2a05951961247b7e015651 Version: 8c0695e4998dd268ff2a05951961247b7e015651 Version: 8c0695e4998dd268ff2a05951961247b7e015651 Version: 8c0695e4998dd268ff2a05951961247b7e015651 Version: 8c0695e4998dd268ff2a05951961247b7e015651 Version: 8c0695e4998dd268ff2a05951961247b7e015651 Version: 8c0695e4998dd268ff2a05951961247b7e015651 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/nfc/digital_technology.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "6afb29751ee731e7f7a96feb8a15f91441e552ba",
"status": "affected",
"version": "8c0695e4998dd268ff2a05951961247b7e015651",
"versionType": "git"
},
{
"lessThan": "e886c63d2ca7108826076989103a1ffa8a0bb8f4",
"status": "affected",
"version": "8c0695e4998dd268ff2a05951961247b7e015651",
"versionType": "git"
},
{
"lessThan": "4e942da2869bcd646353eef706b7dd82efeb9db5",
"status": "affected",
"version": "8c0695e4998dd268ff2a05951961247b7e015651",
"versionType": "git"
},
{
"lessThan": "d0756a98277e383c26fead988a96c91f0781cd7f",
"status": "affected",
"version": "8c0695e4998dd268ff2a05951961247b7e015651",
"versionType": "git"
},
{
"lessThan": "af4c0606f743e009254a8d252096855335ade85d",
"status": "affected",
"version": "8c0695e4998dd268ff2a05951961247b7e015651",
"versionType": "git"
},
{
"lessThan": "a56773e649ea99b344d6bbaf90f34c8e3fadef5d",
"status": "affected",
"version": "8c0695e4998dd268ff2a05951961247b7e015651",
"versionType": "git"
},
{
"lessThan": "a1ef9bddfbb3ae42b036c5aa16cf386d78db70b6",
"status": "affected",
"version": "8c0695e4998dd268ff2a05951961247b7e015651",
"versionType": "git"
},
{
"lessThan": "31aa28ed732f66ab83c40ef53d99791be69b85c4",
"status": "affected",
"version": "8c0695e4998dd268ff2a05951961247b7e015651",
"versionType": "git"
},
{
"lessThan": "344a56d7c8e0f3cbaff0bcb1bcd95a1a1db24b16",
"status": "affected",
"version": "8c0695e4998dd268ff2a05951961247b7e015651",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/nfc/digital_technology.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.13"
},
{
"lessThan": "3.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.267",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.218",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.185",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.154",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.106",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.47",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.1",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.267",
"versionStartIncluding": "3.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.218",
"versionStartIncluding": "3.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.185",
"versionStartIncluding": "3.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.154",
"versionStartIncluding": "3.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.106",
"versionStartIncluding": "3.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.47",
"versionStartIncluding": "3.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.11",
"versionStartIncluding": "3.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.1",
"versionStartIncluding": "3.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "3.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: digital: clamp SENSF_RES length to the destination buffer\n\ndigital_in_recv_sensf_res() memcpy()s resp-\u003elen bytes from a remote\nNFC-F device response into the NFC_SENSF_RES_MAXSIZE-byte target.sensf_res\nfield without an upper-bound check. A nearby malicious NFC-F device can\nsend an oversized SENSF_RES response to overflow the stack-local struct\nnfc_target.\n\nClamp resp-\u003elen to NFC_SENSF_RES_MAXSIZE before the copy.\n\nFound by 0sec automated security-research tooling (https://0sec.ai)."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T15:13:17.298Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/6afb29751ee731e7f7a96feb8a15f91441e552ba"
},
{
"url": "https://git.kernel.org/stable/c/e886c63d2ca7108826076989103a1ffa8a0bb8f4"
},
{
"url": "https://git.kernel.org/stable/c/4e942da2869bcd646353eef706b7dd82efeb9db5"
},
{
"url": "https://git.kernel.org/stable/c/d0756a98277e383c26fead988a96c91f0781cd7f"
},
{
"url": "https://git.kernel.org/stable/c/af4c0606f743e009254a8d252096855335ade85d"
},
{
"url": "https://git.kernel.org/stable/c/a56773e649ea99b344d6bbaf90f34c8e3fadef5d"
},
{
"url": "https://git.kernel.org/stable/c/a1ef9bddfbb3ae42b036c5aa16cf386d78db70b6"
},
{
"url": "https://git.kernel.org/stable/c/31aa28ed732f66ab83c40ef53d99791be69b85c4"
},
{
"url": "https://git.kernel.org/stable/c/344a56d7c8e0f3cbaff0bcb1bcd95a1a1db24b16"
}
],
"title": "nfc: digital: clamp SENSF_RES length to the destination buffer",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80803",
"datePublished": "2026-09-04T15:13:17.298Z",
"dateReserved": "2026-08-26T14:34:25.794Z",
"dateUpdated": "2026-09-04T15:13:17.298Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74508 (GCVE-0-2026-74508)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-23 12:47
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: HIDP: reject frames without a transaction header
hidp_recv_ctrl_frame() and hidp_recv_intr_frame() read skb->data[0]
before checking that the L2CAP SDU contains a transaction header. A
connected HIDP peer can send an empty basic-mode SDU and make both paths
use an uninitialized byte from skb tailroom.
KMSAN reports the use in hidp_session_run(), with the uninitialized value
originating in __alloc_skb() through vhci_write(). The control path
produces two reports and the interrupt path produces one.
The byte can also be controlled by a malformed lower-layer packet. If an
HCI ACL packet contains an L2CAP PDU with a declared zero-length payload
followed by an extra 0x15 byte, l2cap_recv_acldata() reduces skb->len to
the declared PDU length before dispatch. The current HIDP path nevertheless
consumes the extra byte as HIDP_TRANS_HID_CONTROL |
HIDP_CTRL_VIRTUAL_CABLE_UNPLUG and terminates the HIDP session. With this
change, the same packet is discarded and a subsequent feature report
request succeeds.
Pull the transaction header with skb_pull_data() and discard frames that
do not contain it.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/bluetooth/hidp/core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "24c64ccd5c1fc9934b427335b0d976c7f2b1a7d8",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "238c333bc4b3f245c626632e8bfa3c9dab97f51b",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "567a2a0a633f2ea5fdccaf3517c09f22c9d860c7",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "46ca5ab39737d7c6f9ca77ecf714cdcfa6caaeec",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "97b61241ab45bfa5b0526cb0f3978942493bc811",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "2ebf63aa557a69990b4e9ea22be224d58aabce96",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "854194494a6f726a60b90b76059148bf08df023d",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "47778d2c2087b5d192398f6fddf692d16a5431cf",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/bluetooth/hidp/core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: HIDP: reject frames without a transaction header\n\nhidp_recv_ctrl_frame() and hidp_recv_intr_frame() read skb-\u003edata[0]\nbefore checking that the L2CAP SDU contains a transaction header. A\nconnected HIDP peer can send an empty basic-mode SDU and make both paths\nuse an uninitialized byte from skb tailroom.\n\nKMSAN reports the use in hidp_session_run(), with the uninitialized value\noriginating in __alloc_skb() through vhci_write(). The control path\nproduces two reports and the interrupt path produces one.\n\nThe byte can also be controlled by a malformed lower-layer packet. If an\nHCI ACL packet contains an L2CAP PDU with a declared zero-length payload\nfollowed by an extra 0x15 byte, l2cap_recv_acldata() reduces skb-\u003elen to\nthe declared PDU length before dispatch. The current HIDP path nevertheless\nconsumes the extra byte as HIDP_TRANS_HID_CONTROL |\nHIDP_CTRL_VIRTUAL_CABLE_UNPLUG and terminates the HIDP session. With this\nchange, the same packet is discarded and a subsequent feature report\nrequest succeeds.\n\nPull the transaction header with skb_pull_data() and discard frames that\ndo not contain it."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - Malicious or malformed Bluetooth L2CAP SDUs reach hidp_recv_ctrl_frame()/hidp_recv_intr_frame() from a radio-adjacent peer via hci_acl_packet() -\u003e l2cap_recv_acldata() -\u003e l2cap_recv_frame() -\u003e l2cap_sock_recv_cb() -\u003e hidp_session_run().\nAC:L - A connected HIDP peer reliably triggers the bug by sending empty basic-mode SDUs or zero-length L2CAP PDUs with trailing bytes; the attacker controls both sides of the malformed-packet condition without races or rare kernel configs.\nPR:N - Exploitation requires only delivering crafted Bluetooth ACL/L2CAP traffic as the connected peer; the victim attacker does not need local accounts, capabilities, or CAP_NET_ADMIN on the target host.\nUI:N - Once a normal Bluetooth HID session is active (typical paired keyboard/mouse/headset use), the attacker can send malicious frames without any additional victim interaction during exploitation.\nS:U - The flaw affects kernel Bluetooth HIDP session handling only and does not cross VM, container, or IOMMU security boundaries; impact stays within the kernel Bluetooth/HID authority.\nC:H - On zero-length SDUs, hidp_recv_*_frame() reads skb-\u003edata[0] from uninitialized skb tailroom (KMSAN via vhci_write/__alloc_skb), leaking kernel heap bytes that drive subsequent protocol parsing.\nI:H - Attacker-controlled header bytes (e.g., malformed PDU trailing 0x15 = HIDP_TRANS_HID_CONTROL|HIDP_CTRL_VIRTUAL_CABLE_UNPLUG) force hidp_process_hid_control() to tear down sessions and can misroute other transaction types through handshake/data handlers.\nA:H - Forged virtual-cable-unplug and related control-path handling forcibly terminates active HIDP sessions, completely denying Bluetooth HID input/output on phones, laptops, kiosks, and embedded systems until reconnect."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:47:28.838Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/24c64ccd5c1fc9934b427335b0d976c7f2b1a7d8"
},
{
"url": "https://git.kernel.org/stable/c/238c333bc4b3f245c626632e8bfa3c9dab97f51b"
},
{
"url": "https://git.kernel.org/stable/c/567a2a0a633f2ea5fdccaf3517c09f22c9d860c7"
},
{
"url": "https://git.kernel.org/stable/c/46ca5ab39737d7c6f9ca77ecf714cdcfa6caaeec"
},
{
"url": "https://git.kernel.org/stable/c/97b61241ab45bfa5b0526cb0f3978942493bc811"
},
{
"url": "https://git.kernel.org/stable/c/2ebf63aa557a69990b4e9ea22be224d58aabce96"
},
{
"url": "https://git.kernel.org/stable/c/854194494a6f726a60b90b76059148bf08df023d"
},
{
"url": "https://git.kernel.org/stable/c/47778d2c2087b5d192398f6fddf692d16a5431cf"
}
],
"title": "Bluetooth: HIDP: reject frames without a transaction header",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74508",
"datePublished": "2026-08-15T12:27:31.288Z",
"dateReserved": "2026-08-15T05:44:03.908Z",
"dateUpdated": "2026-08-23T12:47:28.838Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68277 (GCVE-0-2026-68277)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers
Three sideband reply parsers read 16-bit fields as:
val = (raw->msg[idx] << 8) | (raw->msg[idx+1]);
and check bounds only after the fact. When idx == raw->curlen,
raw->msg[idx+1] reads one byte past the received message data into
the following struct fields (curchunk_len, curchunk_idx, curlen).
Affected functions:
- drm_dp_sideband_parse_enum_path_resources_ack()
full_payload_bw_number and avail_payload_bw_number fields
- drm_dp_sideband_parse_allocate_payload_ack()
allocated_pbn field
- drm_dp_sideband_parse_query_payload_ack()
allocated_pbn field
Fix by using a single combined check (idx + 2 > curlen) before each
2-byte read. Since the check is strictly tighter than idx > curlen,
no separate step is needed.
[added fixes tag]
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/display/drm_dp_mst_topology.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c1f72a13d54ffd16647d3fa540d961f5deba8790",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "192e146c2d57ad033b0d418ec64ee390f8dc074e",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "6e3107e6522109a07fc9bb0fc4ec463f1982e113",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "bdf0508b1e6785d4a8982c637e97e68d60b47d7b",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "0bcd7675c69a2462a8531fcd9e4d096e9c7ec5df",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "d5c70523cafa26ad2c7a37b612849abe2683baa8",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "68a624416d1dd481b3e5b7ea0e8a070a9b8a2c73",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "6b89ba3dba2f583626fb693e47e951ffb8bf591f",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/display/drm_dp_mst_topology.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.17"
},
{
"lessThan": "3.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.17",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers\n\nThree sideband reply parsers read 16-bit fields as:\n\n val = (raw-\u003emsg[idx] \u003c\u003c 8) | (raw-\u003emsg[idx+1]);\n\nand check bounds only after the fact. When idx == raw-\u003ecurlen,\nraw-\u003emsg[idx+1] reads one byte past the received message data into\nthe following struct fields (curchunk_len, curchunk_idx, curlen).\n\nAffected functions:\n - drm_dp_sideband_parse_enum_path_resources_ack()\n full_payload_bw_number and avail_payload_bw_number fields\n - drm_dp_sideband_parse_allocate_payload_ack()\n allocated_pbn field\n - drm_dp_sideband_parse_query_payload_ack()\n allocated_pbn field\n\nFix by using a single combined check (idx + 2 \u003e curlen) before each\n2-byte read. Since the check is strictly tighter than idx \u003e curlen,\nno separate step is needed.\n\n[added fixes tag]"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:14.372Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c1f72a13d54ffd16647d3fa540d961f5deba8790"
},
{
"url": "https://git.kernel.org/stable/c/192e146c2d57ad033b0d418ec64ee390f8dc074e"
},
{
"url": "https://git.kernel.org/stable/c/6e3107e6522109a07fc9bb0fc4ec463f1982e113"
},
{
"url": "https://git.kernel.org/stable/c/bdf0508b1e6785d4a8982c637e97e68d60b47d7b"
},
{
"url": "https://git.kernel.org/stable/c/0bcd7675c69a2462a8531fcd9e4d096e9c7ec5df"
},
{
"url": "https://git.kernel.org/stable/c/d5c70523cafa26ad2c7a37b612849abe2683baa8"
},
{
"url": "https://git.kernel.org/stable/c/68a624416d1dd481b3e5b7ea0e8a070a9b8a2c73"
},
{
"url": "https://git.kernel.org/stable/c/6b89ba3dba2f583626fb693e47e951ffb8bf591f"
}
],
"title": "drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68277",
"datePublished": "2026-08-10T12:01:53.085Z",
"dateReserved": "2026-07-30T09:28:09.379Z",
"dateUpdated": "2026-08-23T12:46:14.372Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68351 (GCVE-0-2026-68351)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read
When the firmware sends a command response with a length mismatch,
carl9170_cmd_callback() logs the mismatch and calls carl9170_restart()
but then falls through to memcpy(ar->readbuf, buffer + 4, len - 4).
Since len comes from the firmware and can exceed ar->readlen, this
copies more data than the readbuf was allocated for.
Bound the memcpy to min(len - 4, ar->readlen) so that the response
is still completed -- avoiding repeated restarts from queued garbage --
while preventing an overread past the response buffer.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/ath/carl9170/rx.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "38e240996a6a78c94ab07d461fd66e361d55c3c4",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "2d05c321d27624c413c950278d2dc8e0f44a8950",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "525036b20ef01d814a7fcd0567d123992e4479fa",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "f74e34e66379e487a09009a4f2d42470051672bd",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "500c36649f270de05a56591fcc1aaaa36687958e",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "9aee949c68dc6dccbc54333537b109c53fe2079f",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "cb7a38810cf25738176dac32dec7a146b3f959cf",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "4cde55b2feff9504d1f993ab80e84e7ccb62791c",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/ath/carl9170/rx.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.37"
},
{
"lessThan": "2.6.37",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.37",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: carl9170: bound memcpy length in cmd callback to prevent OOB read\n\nWhen the firmware sends a command response with a length mismatch,\ncarl9170_cmd_callback() logs the mismatch and calls carl9170_restart()\nbut then falls through to memcpy(ar-\u003ereadbuf, buffer + 4, len - 4).\nSince len comes from the firmware and can exceed ar-\u003ereadlen, this\ncopies more data than the readbuf was allocated for.\n\nBound the memcpy to min(len - 4, ar-\u003ereadlen) so that the response\nis still completed -- avoiding repeated restarts from queued garbage --\nwhile preventing an overread past the response buffer."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:53.098Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/38e240996a6a78c94ab07d461fd66e361d55c3c4"
},
{
"url": "https://git.kernel.org/stable/c/2d05c321d27624c413c950278d2dc8e0f44a8950"
},
{
"url": "https://git.kernel.org/stable/c/525036b20ef01d814a7fcd0567d123992e4479fa"
},
{
"url": "https://git.kernel.org/stable/c/f74e34e66379e487a09009a4f2d42470051672bd"
},
{
"url": "https://git.kernel.org/stable/c/500c36649f270de05a56591fcc1aaaa36687958e"
},
{
"url": "https://git.kernel.org/stable/c/9aee949c68dc6dccbc54333537b109c53fe2079f"
},
{
"url": "https://git.kernel.org/stable/c/cb7a38810cf25738176dac32dec7a146b3f959cf"
},
{
"url": "https://git.kernel.org/stable/c/4cde55b2feff9504d1f993ab80e84e7ccb62791c"
}
],
"title": "wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68351",
"datePublished": "2026-08-10T12:03:28.312Z",
"dateReserved": "2026-07-30T09:28:09.384Z",
"dateUpdated": "2026-08-19T16:33:53.098Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64586 (GCVE-0-2026-64586)
Vulnerability from cvelistv5
Published
2026-08-06 07:06
Modified
2026-08-23 12:45
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: brcmfmac: drain bus_reset work on device removal
brcmf_fw_crashed() and the debugfs "reset" entry both schedule
drvr->bus_reset, whose callback recovers drvr through container_of()
and dereferences it. The removal path frees drvr (brcmf_free ->
wiphy_free) without draining the work, so a bus_reset callback pending
or running during removal can outlive drvr.
Cancellation cannot live in brcmf_detach() or brcmf_free(): the work
callback reaches teardown through the bus .reset op (PCIe
brcmf_pcie_reset -> brcmf_detach; SDIO brcmf_sdio_bus_reset ->
brcmf_sdiod_remove -> brcmf_free), so cancelling there would wait for
the running work and deadlock.
Add a per-bus mutex (bus_reset_lock) and route all arming through
brcmf_bus_schedule_reset(), which under the lock skips when the bus is
marked removing. Each bus remove entry calls
brcmf_bus_cancel_reset_work(), which under the same lock sets removing
and cancels the work. Holding the mutex across cancel_work_sync() makes
the set-removing + drain step atomic. Every producer reaches the arming
path from process context -- the PCIe firmware-halt notification runs in
the threaded IRQ handler (brcmf_pcie_isr_thread) and the SDIO hostmail
path runs from the data workqueue -- so the mutex is taken only in
sleepable contexts. Where applicable the remove entry first stops the
firmware-crash producer: on PCIe mask the mailbox and synchronize_irq;
on SDIO unregister the bus interrupt and cancel the data worker, which
also reports firmware halts through brcmf_fw_crashed(). The mutex is
initialized at bus allocation. The SDIO suspend power-off path frees
drvr through the same brcmf_sdiod_remove() and takes the same lock;
resume re-allows the work only on a successful re-probe.
Also guard brcmf_fw_crashed() against a NULL bus_if/drvr: it can fire
before brcmf_attach() wires up drvr, and it dereferences drvr
(bphy_err/brcmf_dev_coredump) before reaching the arming gate.
The bus_reset work is shared across buses, so the drain is applied to
every remove path: PCIe (the .reset op introduced by the Fixes commit),
SDIO (arms the same work through brcmf_fw_crashed()), and USB (via the
debugfs "reset" entry). cancel_work_sync() drains a running or pending
bus_reset work item before removal frees drvr, and patch 1/2 makes the
scratch-buffer release safe when reset teardown has already released
those DMA buffers.
This patch fixes the lifetime of the bus_reset work item itself. It does
not attempt to address the separate, pre-existing lifetime of the
asynchronous firmware completion started by the PCIe reset path. That
callback needs its own lifetime/ownership protocol and is being tracked
separately.
This issue was found by an in-house static analysis tool.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 4684997d9eea29380000e062755aa6d368d789a3 Version: 4684997d9eea29380000e062755aa6d368d789a3 Version: 4684997d9eea29380000e062755aa6d368d789a3 Version: 4684997d9eea29380000e062755aa6d368d789a3 Version: 4684997d9eea29380000e062755aa6d368d789a3 Version: 4684997d9eea29380000e062755aa6d368d789a3 Version: 4684997d9eea29380000e062755aa6d368d789a3 Version: 4684997d9eea29380000e062755aa6d368d789a3 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/broadcom/brcm80211/brcmfmac/bcmsdh.c",
"drivers/net/wireless/broadcom/brcm80211/brcmfmac/bus.h",
"drivers/net/wireless/broadcom/brcm80211/brcmfmac/core.c",
"drivers/net/wireless/broadcom/brcm80211/brcmfmac/pcie.c",
"drivers/net/wireless/broadcom/brcm80211/brcmfmac/sdio.c",
"drivers/net/wireless/broadcom/brcm80211/brcmfmac/sdio.h",
"drivers/net/wireless/broadcom/brcm80211/brcmfmac/usb.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "9dfb09cb0abbf92a06f93e0715e163aa188a84da",
"status": "affected",
"version": "4684997d9eea29380000e062755aa6d368d789a3",
"versionType": "git"
},
{
"lessThan": "4824e3bcc68f8d678b409039d1bb48c7b5ea73dc",
"status": "affected",
"version": "4684997d9eea29380000e062755aa6d368d789a3",
"versionType": "git"
},
{
"lessThan": "61127dd20920bf28460a1609aabb0dafa2f54fac",
"status": "affected",
"version": "4684997d9eea29380000e062755aa6d368d789a3",
"versionType": "git"
},
{
"lessThan": "c268331845ee00dbdbccb000826bb612dff2bee7",
"status": "affected",
"version": "4684997d9eea29380000e062755aa6d368d789a3",
"versionType": "git"
},
{
"lessThan": "e3815d1ffbb9be4f1605ddc3b427557893461683",
"status": "affected",
"version": "4684997d9eea29380000e062755aa6d368d789a3",
"versionType": "git"
},
{
"lessThan": "02d378828af8bb74f6c2f4d2bee3c77cf16c861e",
"status": "affected",
"version": "4684997d9eea29380000e062755aa6d368d789a3",
"versionType": "git"
},
{
"lessThan": "177a25be1195f8bdc6160ba5f1a5699f7041c985",
"status": "affected",
"version": "4684997d9eea29380000e062755aa6d368d789a3",
"versionType": "git"
},
{
"lessThan": "43b25879f004c98defa2776bedc6ca4763c51945",
"status": "affected",
"version": "4684997d9eea29380000e062755aa6d368d789a3",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/broadcom/brcm80211/brcmfmac/bcmsdh.c",
"drivers/net/wireless/broadcom/brcm80211/brcmfmac/bus.h",
"drivers/net/wireless/broadcom/brcm80211/brcmfmac/core.c",
"drivers/net/wireless/broadcom/brcm80211/brcmfmac/pcie.c",
"drivers/net/wireless/broadcom/brcm80211/brcmfmac/sdio.c",
"drivers/net/wireless/broadcom/brcm80211/brcmfmac/sdio.h",
"drivers/net/wireless/broadcom/brcm80211/brcmfmac/usb.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.2"
},
{
"lessThan": "5.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: brcmfmac: drain bus_reset work on device removal\n\nbrcmf_fw_crashed() and the debugfs \"reset\" entry both schedule\ndrvr-\u003ebus_reset, whose callback recovers drvr through container_of()\nand dereferences it. The removal path frees drvr (brcmf_free -\u003e\nwiphy_free) without draining the work, so a bus_reset callback pending\nor running during removal can outlive drvr.\n\nCancellation cannot live in brcmf_detach() or brcmf_free(): the work\ncallback reaches teardown through the bus .reset op (PCIe\nbrcmf_pcie_reset -\u003e brcmf_detach; SDIO brcmf_sdio_bus_reset -\u003e\nbrcmf_sdiod_remove -\u003e brcmf_free), so cancelling there would wait for\nthe running work and deadlock.\n\nAdd a per-bus mutex (bus_reset_lock) and route all arming through\nbrcmf_bus_schedule_reset(), which under the lock skips when the bus is\nmarked removing. Each bus remove entry calls\nbrcmf_bus_cancel_reset_work(), which under the same lock sets removing\nand cancels the work. Holding the mutex across cancel_work_sync() makes\nthe set-removing + drain step atomic. Every producer reaches the arming\npath from process context -- the PCIe firmware-halt notification runs in\nthe threaded IRQ handler (brcmf_pcie_isr_thread) and the SDIO hostmail\npath runs from the data workqueue -- so the mutex is taken only in\nsleepable contexts. Where applicable the remove entry first stops the\nfirmware-crash producer: on PCIe mask the mailbox and synchronize_irq;\non SDIO unregister the bus interrupt and cancel the data worker, which\nalso reports firmware halts through brcmf_fw_crashed(). The mutex is\ninitialized at bus allocation. The SDIO suspend power-off path frees\ndrvr through the same brcmf_sdiod_remove() and takes the same lock;\nresume re-allows the work only on a successful re-probe.\n\nAlso guard brcmf_fw_crashed() against a NULL bus_if/drvr: it can fire\nbefore brcmf_attach() wires up drvr, and it dereferences drvr\n(bphy_err/brcmf_dev_coredump) before reaching the arming gate.\n\nThe bus_reset work is shared across buses, so the drain is applied to\nevery remove path: PCIe (the .reset op introduced by the Fixes commit),\nSDIO (arms the same work through brcmf_fw_crashed()), and USB (via the\ndebugfs \"reset\" entry). cancel_work_sync() drains a running or pending\nbus_reset work item before removal frees drvr, and patch 1/2 makes the\nscratch-buffer release safe when reset teardown has already released\nthose DMA buffers.\n\nThis patch fixes the lifetime of the bus_reset work item itself. It does\nnot attempt to address the separate, pre-existing lifetime of the\nasynchronous firmware completion started by the PCIe reset path. That\ncallback needs its own lifetime/ownership protocol and is being tracked\nseparately.\n\nThis issue was found by an in-house static analysis tool."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - bus_reset is armed by brcmf_fw_crashed() when Broadcom fullmac signals FWHALT (PCIe mailbox ISR thread / SDIO hostmail). An adjacent 802.11 attacker can induce that halt with malformed frames; the pending work then races device removal (USB hot-unplug, SDIO suspend power-off) that frees drvr without draining the work.\nAC:L - The attacker repeatedly induces firmware halts to schedule bus_reset and can align removal (USB unplug on shared dongles/kiosks, or SDIO suspend) so the work runs after wiphy_free; both sides are attacker-influenced and freely retryable, so success does not depend on uncontrollable timing.\nPR:N - FWHALT delivery and brcmf_fw_crashed() need no host credentials; concurrent free via USB disconnect or automatic SDIO power-cut suspend likewise requires no account or capability. The debugfs reset path is root-only but is not the highest-severity reachability.\nUI:N - Firmware-halt recovery and device removal/suspend paths run in kernel workqueues and bus callbacks without the victim opening a file, mounting media, or otherwise interacting.\nS:U - The UAF corrupts host-kernel heap (struct brcmf_pub embedded in the wiphy) within the same kernel security authority; it is not a VM escape, IOMMU bypass, or sandbox boundary crossing.\nC:H - Use-after-free of drvr via container_of on the freed bus_reset work_struct lets an attacker reallocate the wiphy/drvr slab and observe attacker-controlled object contents through subsequent driver dereferences, yielding an arbitrary kernel read primitive.\nI:H - The recycled work_struct/drvr is dispatched by the workqueue (func pointer / bus_if ops), enabling heap corruption and control-flow hijack when brcmf_core_bus_reset runs on attacker-shaped memory after brcmf_free/wiphy_free.\nA:H - Even without full exploitation, running bus_reset after wiphy_free dereferences freed drvr/bus_if state and reliably causes kernel oops/panic or driver teardown failure, denying availability of the host."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:45:44.685Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/9dfb09cb0abbf92a06f93e0715e163aa188a84da"
},
{
"url": "https://git.kernel.org/stable/c/4824e3bcc68f8d678b409039d1bb48c7b5ea73dc"
},
{
"url": "https://git.kernel.org/stable/c/61127dd20920bf28460a1609aabb0dafa2f54fac"
},
{
"url": "https://git.kernel.org/stable/c/c268331845ee00dbdbccb000826bb612dff2bee7"
},
{
"url": "https://git.kernel.org/stable/c/e3815d1ffbb9be4f1605ddc3b427557893461683"
},
{
"url": "https://git.kernel.org/stable/c/02d378828af8bb74f6c2f4d2bee3c77cf16c861e"
},
{
"url": "https://git.kernel.org/stable/c/177a25be1195f8bdc6160ba5f1a5699f7041c985"
},
{
"url": "https://git.kernel.org/stable/c/43b25879f004c98defa2776bedc6ca4763c51945"
}
],
"title": "wifi: brcmfmac: drain bus_reset work on device removal",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64586",
"datePublished": "2026-08-06T07:06:27.158Z",
"dateReserved": "2026-07-19T15:36:31.798Z",
"dateUpdated": "2026-08-23T12:45:44.685Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80584 (GCVE-0-2026-80584)
Vulnerability from cvelistv5
Published
2026-08-26 14:37
Modified
2026-08-27 05:02
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
s390/qeth: validate user buffer length in SNMP and ARP query ioctls
qeth_snmp_command() and qeth_l3_arp_query() allocate a buffer sized by
a user-supplied length (udata_len) without checking a lower bound, then
set udata_offset to a fixed non-zero value and pass both to a reply
callback. The callback bounds-checks the copy with
if ((udata_len - udata_offset) < len)
Both fields are u32, so a udata_len smaller than udata_offset makes the
subtraction wrap and the check pass, and the following memcpy() writes
past the allocation. A udata_len of 0 also yields ZERO_SIZE_PTR from
kzalloc(), which the existing NULL check does not catch.
Reject buffers smaller than udata_offset before allocating, so the
callback subtraction can no longer underflow.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 4a71df50047f0db65ea09b1be155852e81a45eba Version: 4a71df50047f0db65ea09b1be155852e81a45eba Version: 4a71df50047f0db65ea09b1be155852e81a45eba Version: 4a71df50047f0db65ea09b1be155852e81a45eba Version: 4a71df50047f0db65ea09b1be155852e81a45eba Version: 4a71df50047f0db65ea09b1be155852e81a45eba Version: 4a71df50047f0db65ea09b1be155852e81a45eba Version: 4a71df50047f0db65ea09b1be155852e81a45eba |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/s390/net/qeth_core_main.c",
"drivers/s390/net/qeth_l3_main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "9d00eeb2d27f4cc817c5e408760226d43f811ec6",
"status": "affected",
"version": "4a71df50047f0db65ea09b1be155852e81a45eba",
"versionType": "git"
},
{
"lessThan": "46443eaddebd84c51940857b11787229be169dec",
"status": "affected",
"version": "4a71df50047f0db65ea09b1be155852e81a45eba",
"versionType": "git"
},
{
"lessThan": "91935843f9396a9e45253e2c0d4337ca1371754b",
"status": "affected",
"version": "4a71df50047f0db65ea09b1be155852e81a45eba",
"versionType": "git"
},
{
"lessThan": "cc423f4105fe145b33e1d7cad34245a798358f73",
"status": "affected",
"version": "4a71df50047f0db65ea09b1be155852e81a45eba",
"versionType": "git"
},
{
"lessThan": "3083818e67bcd656965797fbac9a3d6c1d44f78a",
"status": "affected",
"version": "4a71df50047f0db65ea09b1be155852e81a45eba",
"versionType": "git"
},
{
"lessThan": "a3083647747942ea32faf14560d6397ff3068046",
"status": "affected",
"version": "4a71df50047f0db65ea09b1be155852e81a45eba",
"versionType": "git"
},
{
"lessThan": "75fb3151513d7d9f77a8f9545418279b119c06b8",
"status": "affected",
"version": "4a71df50047f0db65ea09b1be155852e81a45eba",
"versionType": "git"
},
{
"lessThan": "d141f087b1af656f055d7c5793a3e87817ba0bbe",
"status": "affected",
"version": "4a71df50047f0db65ea09b1be155852e81a45eba",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/s390/net/qeth_core_main.c",
"drivers/s390/net/qeth_l3_main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.26"
},
{
"lessThan": "2.6.26",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "2.6.26",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "2.6.26",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "2.6.26",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "2.6.26",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "2.6.26",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.46",
"versionStartIncluding": "2.6.26",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.10",
"versionStartIncluding": "2.6.26",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.26",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/qeth: validate user buffer length in SNMP and ARP query ioctls\n\nqeth_snmp_command() and qeth_l3_arp_query() allocate a buffer sized by\na user-supplied length (udata_len) without checking a lower bound, then\nset udata_offset to a fixed non-zero value and pass both to a reply\ncallback. The callback bounds-checks the copy with\n\n if ((udata_len - udata_offset) \u003c len)\n\nBoth fields are u32, so a udata_len smaller than udata_offset makes the\nsubtraction wrap and the check pass, and the following memcpy() writes\npast the allocation. A udata_len of 0 also yields ZERO_SIZE_PTR from\nkzalloc(), which the existing NULL check does not catch.\n\nReject buffers smaller than udata_offset before allocating, so the\ncallback subtraction can no longer underflow."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.4,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires a local ioctl(2) on a qeth netdev (SIOC_QETH_ADP_SET_SNMP_CONTROL or SIOC_QETH_ARP_QUERY_INFO) via socket()-\u003edev_ioctl()-\u003edev_siocdevprivate(); no remote packet or network protocol handler reaches these code paths.\nAC:L - The attacker fully controls udata_len in the ioctl argument; values below the fixed udata_offset (16 for SNMP, 6 for ARP) deterministically underflow the u32 bounds check and cause memcpy() past the kmalloc allocation without races or uncontrollable memory layout.\nPR:N - On affected kernels before CVE-2026-74467, SIOC_QETH_ADP_SET_SNMP_CONTROL had no CAP_NET_ADMIN gate and dev_ioctl() performs no capability check for SIOCDEVPRIVATE, so any unprivileged local user on an IBM Z/LinuxONE LPAR with a qeth interface can reach the overflow.\nUI:N - Exploitation requires only the attacker opening a socket and issuing the crafted ioctl against a qeth interface; no victim login, mount, or other interactive action is needed on a shared mainframe guest.\nS:U - Impact is kernel heap corruption and crash within the local LPAR/kernel security boundary on IBM Z; this does not cross a VM guest-to-host, container, or IOMMU security boundary.\nC:H - The unchecked memcpy() performs a kernel heap out-of-bounds write past a user-sized kmalloc buffer, corrupting adjacent slab objects; per CNA guidance, memory corruption exploitable for information disclosure warrants High confidentiality impact.\nI:H - Integer underflow bypasses the bounds check and memcpy() writes OSA SNMP/ARP response data past the kmalloc allocation end, providing a kernel heap overflow primitive suitable for adjacent-object corruption and privilege escalation.\nA:H - udata_len=0 yields ZERO_SIZE_PTR from kzalloc() (not caught by the NULL check) and memcpy() writes to a fixed low kernel address causing a CPU fault; undersized non-zero lengths corrupt the heap and can trigger kernel oops or panic."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T05:02:04.879Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/9d00eeb2d27f4cc817c5e408760226d43f811ec6"
},
{
"url": "https://git.kernel.org/stable/c/46443eaddebd84c51940857b11787229be169dec"
},
{
"url": "https://git.kernel.org/stable/c/91935843f9396a9e45253e2c0d4337ca1371754b"
},
{
"url": "https://git.kernel.org/stable/c/cc423f4105fe145b33e1d7cad34245a798358f73"
},
{
"url": "https://git.kernel.org/stable/c/3083818e67bcd656965797fbac9a3d6c1d44f78a"
},
{
"url": "https://git.kernel.org/stable/c/a3083647747942ea32faf14560d6397ff3068046"
},
{
"url": "https://git.kernel.org/stable/c/75fb3151513d7d9f77a8f9545418279b119c06b8"
},
{
"url": "https://git.kernel.org/stable/c/d141f087b1af656f055d7c5793a3e87817ba0bbe"
}
],
"title": "s390/qeth: validate user buffer length in SNMP and ARP query ioctls",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80584",
"datePublished": "2026-08-26T14:37:40.302Z",
"dateReserved": "2026-08-26T14:34:25.769Z",
"dateUpdated": "2026-08-27T05:02:04.879Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74569 (GCVE-0-2026-74569)
Vulnerability from cvelistv5
Published
2026-08-15 12:28
Modified
2026-08-19 16:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp()
sip_help_tcp() stores the size change of each NAT-rewritten SIP message
in s16 diff and accumulates it in s16 tdiff, but a single message can
grow by more than S16_MAX while the packet stays under the 65535
enlarge_skb() limit: nf_nat_sip() rewrites every matching URI, and a long
Contact list expands the message by tens of kilobytes. diff then wraps,
and "datalen = datalen + diff - msglen" yields a huge unsigned datalen,
so the next iteration's ct_sip_get_header() reads past the linearized skb
tail.
Widen diff, tdiff and the seq_adjust hook to s32. Both are bounded by the
65535 byte packet limit, and the seqadj core is already s32
(nf_ct_seqadj_set() takes s32), so no previously accepted input is
rejected.
BUG: KASAN: use-after-free in ct_sip_get_header (net/netfilter/nf_conntrack_sip.c:464)
Read of size 1 at addr ffff888010800000 by task ksoftirqd/1/25
ct_sip_get_header (net/netfilter/nf_conntrack_sip.c:464)
sip_help_tcp (net/netfilter/nf_conntrack_sip.c:1694)
nf_confirm (net/netfilter/nf_conntrack_proto.c:183)
nf_hook_slow (net/netfilter/core.c:619)
ip6_output (net/ipv6/ip6_output.c:246)
ip6_forward (net/ipv6/ip6_output.c:690)
ipv6_rcv (net/ipv6/ip6_input.c:351)
__netif_receive_skb_one_core (net/core/dev.c:6212)
process_backlog (net/core/dev.c:6676)
__napi_poll (net/core/dev.c:7735)
net_rx_action (net/core/dev.c:7955)
handle_softirqs (kernel/softirq.c:622)
run_ksoftirqd (kernel/softirq.c:1076)
...
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: f5b321bd37fbec9188feb1f721ab46a5ac0b35da Version: f5b321bd37fbec9188feb1f721ab46a5ac0b35da Version: f5b321bd37fbec9188feb1f721ab46a5ac0b35da Version: f5b321bd37fbec9188feb1f721ab46a5ac0b35da Version: f5b321bd37fbec9188feb1f721ab46a5ac0b35da Version: f5b321bd37fbec9188feb1f721ab46a5ac0b35da Version: f5b321bd37fbec9188feb1f721ab46a5ac0b35da Version: f5b321bd37fbec9188feb1f721ab46a5ac0b35da |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"include/linux/netfilter/nf_conntrack_sip.h",
"net/netfilter/nf_conntrack_sip.c",
"net/netfilter/nf_nat_sip.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ed1f9be6dc8e2e280b8725e44ccdc6e0cd38640d",
"status": "affected",
"version": "f5b321bd37fbec9188feb1f721ab46a5ac0b35da",
"versionType": "git"
},
{
"lessThan": "1b0843f9e9b9b0b9b4b70d143b67e58163c85b2c",
"status": "affected",
"version": "f5b321bd37fbec9188feb1f721ab46a5ac0b35da",
"versionType": "git"
},
{
"lessThan": "32d4abc8923b0d4046fd63ad6e4917872e44eb6d",
"status": "affected",
"version": "f5b321bd37fbec9188feb1f721ab46a5ac0b35da",
"versionType": "git"
},
{
"lessThan": "63eea41759fd682229c14e0a2205802b46d106f3",
"status": "affected",
"version": "f5b321bd37fbec9188feb1f721ab46a5ac0b35da",
"versionType": "git"
},
{
"lessThan": "c97621a110e386b2dd69e276eb699e1d3cec581d",
"status": "affected",
"version": "f5b321bd37fbec9188feb1f721ab46a5ac0b35da",
"versionType": "git"
},
{
"lessThan": "f74554e67ccf04d1fa71069e8c9afa2717e40716",
"status": "affected",
"version": "f5b321bd37fbec9188feb1f721ab46a5ac0b35da",
"versionType": "git"
},
{
"lessThan": "ef5e2c6555d2bb52dfe0e4053a8c6193f9d83b64",
"status": "affected",
"version": "f5b321bd37fbec9188feb1f721ab46a5ac0b35da",
"versionType": "git"
},
{
"lessThan": "db3d0e0e5d4bc5ab4fe445b9f413d1b486508ca5",
"status": "affected",
"version": "f5b321bd37fbec9188feb1f721ab46a5ac0b35da",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"include/linux/netfilter/nf_conntrack_sip.h",
"net/netfilter/nf_conntrack_sip.c",
"net/netfilter/nf_nat_sip.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.34"
},
{
"lessThan": "2.6.34",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.34",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp()\n\nsip_help_tcp() stores the size change of each NAT-rewritten SIP message\nin s16 diff and accumulates it in s16 tdiff, but a single message can\ngrow by more than S16_MAX while the packet stays under the 65535\nenlarge_skb() limit: nf_nat_sip() rewrites every matching URI, and a long\nContact list expands the message by tens of kilobytes. diff then wraps,\nand \"datalen = datalen + diff - msglen\" yields a huge unsigned datalen,\nso the next iteration\u0027s ct_sip_get_header() reads past the linearized skb\ntail.\n\nWiden diff, tdiff and the seq_adjust hook to s32. Both are bounded by the\n65535 byte packet limit, and the seqadj core is already s32\n(nf_ct_seqadj_set() takes s32), so no previously accepted input is\nrejected.\n\n BUG: KASAN: use-after-free in ct_sip_get_header (net/netfilter/nf_conntrack_sip.c:464)\n Read of size 1 at addr ffff888010800000 by task ksoftirqd/1/25\n ct_sip_get_header (net/netfilter/nf_conntrack_sip.c:464)\n sip_help_tcp (net/netfilter/nf_conntrack_sip.c:1694)\n nf_confirm (net/netfilter/nf_conntrack_proto.c:183)\n nf_hook_slow (net/netfilter/core.c:619)\n ip6_output (net/ipv6/ip6_output.c:246)\n ip6_forward (net/ipv6/ip6_output.c:690)\n ipv6_rcv (net/ipv6/ip6_input.c:351)\n __netif_receive_skb_one_core (net/core/dev.c:6212)\n process_backlog (net/core/dev.c:6676)\n __napi_poll (net/core/dev.c:7735)\n net_rx_action (net/core/dev.c:7955)\n handle_softirqs (kernel/softirq.c:622)\n run_ksoftirqd (kernel/softirq.c:1076)\n ..."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - Remote attackers trigger sip_help_tcp() by sending crafted TCP SIP traffic that traverses netfilter nf_confirm() on POST_ROUTING/LOCAL_IN during packet receive/forward (ipv6_rcv\u2192ip6_forward\u2192ip6_output\u2192nf_hook_slow), the standard path for network-facing SIP ALG/NAT gateways.\nAC:L - Once nf_conntrack_sip and nf_nat_sip are active on a NATed SIP flow, the attacker fully controls the TCP SIP payload (Contact list length and private URIs) to force \u003e32KB NAT expansion and deterministic s16 wrap; no race or external timing is required.\nPR:N - Exploitation requires no privileges on the victim kernel; a remote SIP peer only needs to deliver malicious TCP SIP packets through an already-configured SIP conntrack/NAT helper, with no authentication or local access to the target system.\nUI:N - No victim user interaction is required beyond normal automated packet processing; the helper parses and NAT-rewrites attacker-supplied SIP data in softirq during connection tracking confirmation without any user action.\nS:U - Impact is confined to kernel netfilter/conntrack memory on the same security authority (e.g., a NAT firewall or router). This is not a VM escape, sandbox breakout, or cross-tenant boundary violation.\nC:H - Integer overflow yields a huge unsigned datalen, causing ct_sip_get_header() to read past the linearized skb tail; KASAN reports a use-after-free read, and this out-of-bounds/UAF access can disclose adjacent kernel heap memory beyond the packet buffer.\nI:H - Although the immediate fault is a read past skb bounds, KASAN-classified UAF/out-of-bounds kernel heap corruption is exploitable with heap grooming for control of freed/reallocated objects, enabling arbitrary write and potential code execution in kernel context.\nA:H - The corrupted datalen drives out-of-bounds access in softirq packet processing (ksoftirqd), which can cause kernel oops/panic and denial of service on the NAT/firewall handling the SIP flow; the bug is reliably triggerable with crafted packets."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:39:11.673Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ed1f9be6dc8e2e280b8725e44ccdc6e0cd38640d"
},
{
"url": "https://git.kernel.org/stable/c/1b0843f9e9b9b0b9b4b70d143b67e58163c85b2c"
},
{
"url": "https://git.kernel.org/stable/c/32d4abc8923b0d4046fd63ad6e4917872e44eb6d"
},
{
"url": "https://git.kernel.org/stable/c/63eea41759fd682229c14e0a2205802b46d106f3"
},
{
"url": "https://git.kernel.org/stable/c/c97621a110e386b2dd69e276eb699e1d3cec581d"
},
{
"url": "https://git.kernel.org/stable/c/f74554e67ccf04d1fa71069e8c9afa2717e40716"
},
{
"url": "https://git.kernel.org/stable/c/ef5e2c6555d2bb52dfe0e4053a8c6193f9d83b64"
},
{
"url": "https://git.kernel.org/stable/c/db3d0e0e5d4bc5ab4fe445b9f413d1b486508ca5"
}
],
"title": "netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74569",
"datePublished": "2026-08-15T12:28:09.476Z",
"dateReserved": "2026-08-15T05:44:03.917Z",
"dateUpdated": "2026-08-19T16:39:11.673Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68180 (GCVE-0-2026-68180)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
intel_th: fix MSC output device reference leak
intel_th_output_open() looks up the output device with
bus_find_device_by_devt(), which returns the device with a reference that
must be dropped after use.
commit 95fc36a234da ("intel_th: fix device leak on output open()")
attempted to drop the reference from intel_th_output_release(). However,
a successful open replaces file->f_op with the output driver file
operations before returning, so close runs the output driver release
callback instead.
For MSC outputs, close runs intel_th_msc_release(), which only removes
the per-file iterator and does not drop the device reference taken by
intel_th_output_open(). Consequently, every successful MSC output open
leaks one device reference.
Drop the device reference from intel_th_msc_release(), which is the
release path actually used for MSC output files. Remove the now-unused
intel_th_output_release() callback from intel_th_output_fops.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: af4b9467296b9a16ebc008147238070236982b6d Version: 64015cbf06e8bb75b81ae95b997e847b55280f7f Version: b71e64ef7ff9443835d1333e3e80ab1e49e5209f Version: bf7785434b5d05d940d936b78925080950bd54dd Version: 0fca16c5591534cc1fec8b6181277ee3a3d0f26c Version: f9b059bda4276f2bb72cb98ec7875a747f042ea2 Version: 95fc36a234da24bbc5f476f8104a5a15f99ed3e3 Version: 95fc36a234da24bbc5f476f8104a5a15f99ed3e3 Version: 5.10.249 ≤ Version: 5.15.199 ≤ Version: 6.1.162 ≤ Version: 6.6.122 ≤ Version: 6.12.68 ≤ Version: 6.18.8 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/hwtracing/intel_th/core.c",
"drivers/hwtracing/intel_th/msu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "12ad4fad748e6e563ff4480f03b89134a41b5c37",
"status": "affected",
"version": "af4b9467296b9a16ebc008147238070236982b6d",
"versionType": "git"
},
{
"lessThan": "df55842fddbcdb80e6dd16680439c0f780ed592e",
"status": "affected",
"version": "64015cbf06e8bb75b81ae95b997e847b55280f7f",
"versionType": "git"
},
{
"lessThan": "141641a70ed337e54487f766ede745fc2ce44c42",
"status": "affected",
"version": "b71e64ef7ff9443835d1333e3e80ab1e49e5209f",
"versionType": "git"
},
{
"lessThan": "ddcf2064d7ec5a8c9afa7cb74442320e443502bc",
"status": "affected",
"version": "bf7785434b5d05d940d936b78925080950bd54dd",
"versionType": "git"
},
{
"lessThan": "26e27b8dcef1e4df6f30d8f25b3304a506d482b3",
"status": "affected",
"version": "0fca16c5591534cc1fec8b6181277ee3a3d0f26c",
"versionType": "git"
},
{
"lessThan": "caba30eb8bd321c465ecfc7d850ee85f5b353496",
"status": "affected",
"version": "f9b059bda4276f2bb72cb98ec7875a747f042ea2",
"versionType": "git"
},
{
"lessThan": "c3a28f9cb82425fe0835048ed3677f321e780691",
"status": "affected",
"version": "95fc36a234da24bbc5f476f8104a5a15f99ed3e3",
"versionType": "git"
},
{
"lessThan": "761b785a0cfbce43761227bc42a7f984f31f8921",
"status": "affected",
"version": "95fc36a234da24bbc5f476f8104a5a15f99ed3e3",
"versionType": "git"
},
{
"lessThan": "5.10.265",
"status": "affected",
"version": "5.10.249",
"versionType": "semver"
},
{
"lessThan": "5.15.216",
"status": "affected",
"version": "5.15.199",
"versionType": "semver"
},
{
"lessThan": "6.1.183",
"status": "affected",
"version": "6.1.162",
"versionType": "semver"
},
{
"lessThan": "6.6.148",
"status": "affected",
"version": "6.6.122",
"versionType": "semver"
},
{
"lessThan": "6.12.101",
"status": "affected",
"version": "6.12.68",
"versionType": "semver"
},
{
"lessThan": "6.18.42",
"status": "affected",
"version": "6.18.8",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/hwtracing/intel_th/core.c",
"drivers/hwtracing/intel_th/msu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.19"
},
{
"lessThan": "6.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.10.249",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.15.199",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "6.1.162",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.6.122",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.12.68",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.18.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nintel_th: fix MSC output device reference leak\n\nintel_th_output_open() looks up the output device with\nbus_find_device_by_devt(), which returns the device with a reference that\nmust be dropped after use.\n\ncommit 95fc36a234da (\"intel_th: fix device leak on output open()\")\nattempted to drop the reference from intel_th_output_release(). However,\na successful open replaces file-\u003ef_op with the output driver file\noperations before returning, so close runs the output driver release\ncallback instead.\n\nFor MSC outputs, close runs intel_th_msc_release(), which only removes\nthe per-file iterator and does not drop the device reference taken by\nintel_th_output_open(). Consequently, every successful MSC output open\nleaks one device reference.\n\nDrop the device reference from intel_th_msc_release(), which is the\nrelease path actually used for MSC output files. Remove the now-unused\nintel_th_output_release() callback from intel_th_output_fops."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:30:44.755Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/12ad4fad748e6e563ff4480f03b89134a41b5c37"
},
{
"url": "https://git.kernel.org/stable/c/df55842fddbcdb80e6dd16680439c0f780ed592e"
},
{
"url": "https://git.kernel.org/stable/c/141641a70ed337e54487f766ede745fc2ce44c42"
},
{
"url": "https://git.kernel.org/stable/c/ddcf2064d7ec5a8c9afa7cb74442320e443502bc"
},
{
"url": "https://git.kernel.org/stable/c/26e27b8dcef1e4df6f30d8f25b3304a506d482b3"
},
{
"url": "https://git.kernel.org/stable/c/caba30eb8bd321c465ecfc7d850ee85f5b353496"
},
{
"url": "https://git.kernel.org/stable/c/c3a28f9cb82425fe0835048ed3677f321e780691"
},
{
"url": "https://git.kernel.org/stable/c/761b785a0cfbce43761227bc42a7f984f31f8921"
}
],
"title": "intel_th: fix MSC output device reference leak",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68180",
"datePublished": "2026-08-10T11:59:51.694Z",
"dateReserved": "2026-07-30T09:28:09.373Z",
"dateUpdated": "2026-08-19T16:30:44.755Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68154 (GCVE-0-2026-68154)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
libceph: reject zero bucket types in crush_decode
CRUSH bucket type 0 is reserved for devices. The mapper relies on
that invariant and uses type 0 to identify leaf devices.
If crush_decode() accepts a bucket with type 0, a malformed CRUSH map
can make the mapper treat a negative bucket ID as a device and pass it
to is_out(), which then indexes the OSD weight array with a negative
value.
Reject zero bucket types while decoding the CRUSH map so the invalid
state never reaches the mapper.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: f24e9980eb860d8600cbe5ef3d2fd9295320d229 Version: f24e9980eb860d8600cbe5ef3d2fd9295320d229 Version: f24e9980eb860d8600cbe5ef3d2fd9295320d229 Version: f24e9980eb860d8600cbe5ef3d2fd9295320d229 Version: f24e9980eb860d8600cbe5ef3d2fd9295320d229 Version: f24e9980eb860d8600cbe5ef3d2fd9295320d229 Version: f24e9980eb860d8600cbe5ef3d2fd9295320d229 Version: f24e9980eb860d8600cbe5ef3d2fd9295320d229 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ceph/osdmap.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "952ca5dc99913d169263f59fd689f586729a13c1",
"status": "affected",
"version": "f24e9980eb860d8600cbe5ef3d2fd9295320d229",
"versionType": "git"
},
{
"lessThan": "146461f09565afe3665e65b0423d3d6b0fe806c5",
"status": "affected",
"version": "f24e9980eb860d8600cbe5ef3d2fd9295320d229",
"versionType": "git"
},
{
"lessThan": "80fc40e11cda1b5d990a3f69c6efa344fb5cd987",
"status": "affected",
"version": "f24e9980eb860d8600cbe5ef3d2fd9295320d229",
"versionType": "git"
},
{
"lessThan": "b8a9fb6bf806f9c4891e71ae1beab0c07c23a877",
"status": "affected",
"version": "f24e9980eb860d8600cbe5ef3d2fd9295320d229",
"versionType": "git"
},
{
"lessThan": "826cd1de5802fd392922785f9b64d76e65d2a100",
"status": "affected",
"version": "f24e9980eb860d8600cbe5ef3d2fd9295320d229",
"versionType": "git"
},
{
"lessThan": "3b2f1937f5fce8b7dd5432e7693e3cc8b5eece56",
"status": "affected",
"version": "f24e9980eb860d8600cbe5ef3d2fd9295320d229",
"versionType": "git"
},
{
"lessThan": "70998f91030ee083ecb336a1dff0701c20a38081",
"status": "affected",
"version": "f24e9980eb860d8600cbe5ef3d2fd9295320d229",
"versionType": "git"
},
{
"lessThan": "05f90284223381005d6bcddab3fda4a97f9c3401",
"status": "affected",
"version": "f24e9980eb860d8600cbe5ef3d2fd9295320d229",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ceph/osdmap.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.34"
},
{
"lessThan": "2.6.34",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.34",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: reject zero bucket types in crush_decode\n\nCRUSH bucket type 0 is reserved for devices. The mapper relies on\nthat invariant and uses type 0 to identify leaf devices.\n\nIf crush_decode() accepts a bucket with type 0, a malformed CRUSH map\ncan make the mapper treat a negative bucket ID as a device and pass it\nto is_out(), which then indexes the OSD weight array with a negative\nvalue.\n\nReject zero bucket types while decoding the CRUSH map so the invalid\nstate never reaches the mapper."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The flaw is reached when the in-kernel Ceph client decodes a crafted CRUSH map inside CEPH_MSG_OSD_MAP received over TCP from a Ceph monitor or OSD, which is a standard network-delivered cluster control message on connected storage clients.\nAC:L - An attacker can reliably craft a CRUSH map with a bucket whose type field is zero and controlled hierarchy/items so crush_do_rule() later calls is_out() with a negative index, without races, victim-specific memory layout, or rare kernel build options.\nPR:N - No local privileges on the victim host are required; a remote attacker who controls, compromises, or MITMs the authenticated Ceph monitor/OSD peer can deliver the malicious OSD map over the established client cluster connection.\nUI:N - No additional victim action is needed at exploit time because poisoned OSD maps are processed automatically and CRUSH placement is recalculated during routine map updates, request rescanning, and normal Ceph client I/O.\nS:U - The vulnerability corrupts or reads kernel memory on the host running the Ceph client, affecting that kernel security domain rather than crossing a VM, container sandbox, or IOMMU boundary.\nC:H - When a type-0 bucket makes the mapper treat a negative bucket ID as a device, is_out() indexes osd_weight[] with a negative value, causing an out-of-bounds read of adjacent kernel memory beyond the OSD weight array.\nI:H - This out-of-bounds kernel heap access during CRUSH placement is memory corruption in a privileged parser/mapper path that can be leveraged for further kernel memory control and arbitrary code execution, not only information disclosure.\nA:H - The invalid negative indexing during CRUSH mapping can dereference unmapped or non-resident memory and trigger a kernel oops or panic, causing complete loss of availability on affected Ceph client hosts."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:30:20.481Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/952ca5dc99913d169263f59fd689f586729a13c1"
},
{
"url": "https://git.kernel.org/stable/c/146461f09565afe3665e65b0423d3d6b0fe806c5"
},
{
"url": "https://git.kernel.org/stable/c/80fc40e11cda1b5d990a3f69c6efa344fb5cd987"
},
{
"url": "https://git.kernel.org/stable/c/b8a9fb6bf806f9c4891e71ae1beab0c07c23a877"
},
{
"url": "https://git.kernel.org/stable/c/826cd1de5802fd392922785f9b64d76e65d2a100"
},
{
"url": "https://git.kernel.org/stable/c/3b2f1937f5fce8b7dd5432e7693e3cc8b5eece56"
},
{
"url": "https://git.kernel.org/stable/c/70998f91030ee083ecb336a1dff0701c20a38081"
},
{
"url": "https://git.kernel.org/stable/c/05f90284223381005d6bcddab3fda4a97f9c3401"
}
],
"title": "libceph: reject zero bucket types in crush_decode",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68154",
"datePublished": "2026-08-10T11:59:20.250Z",
"dateReserved": "2026-07-30T09:28:09.371Z",
"dateUpdated": "2026-08-19T16:30:20.481Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2025-38237 (GCVE-0-2025-38237)
Vulnerability from cvelistv5
Published
2025-07-08 07:42
Modified
2026-09-02 12:49
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: platform: exynos4-is: Add hardware sync wait to fimc_is_hw_change_mode()
In fimc_is_hw_change_mode(), the function changes camera modes without
waiting for hardware completion, risking corrupted data or system hangs
if subsequent operations proceed before the hardware is ready.
Add fimc_is_hw_wait_intmsr0_intmsd0() after mode configuration, ensuring
hardware state synchronization and stable interrupt handling.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 9a761e436843f228eaa2decda6d2c6dbd5ef1480 Version: 9a761e436843f228eaa2decda6d2c6dbd5ef1480 Version: 9a761e436843f228eaa2decda6d2c6dbd5ef1480 Version: 9a761e436843f228eaa2decda6d2c6dbd5ef1480 Version: 9a761e436843f228eaa2decda6d2c6dbd5ef1480 Version: 9a761e436843f228eaa2decda6d2c6dbd5ef1480 Version: 9a761e436843f228eaa2decda6d2c6dbd5ef1480 Version: 9a761e436843f228eaa2decda6d2c6dbd5ef1480 |
||
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2025-11-03T17:35:52.390Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"url": "https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/platform/samsung/exynos4-is/fimc-is-regs.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b0d92b94278561f43057003a73a17ce13b7c1a1a",
"status": "affected",
"version": "9a761e436843f228eaa2decda6d2c6dbd5ef1480",
"versionType": "git"
},
{
"lessThan": "e4077a10a25560ec0bd0b42322e4ea027d6f76e2",
"status": "affected",
"version": "9a761e436843f228eaa2decda6d2c6dbd5ef1480",
"versionType": "git"
},
{
"lessThan": "bb97dfab7615fea97322b8a6131546e80f878a69",
"status": "affected",
"version": "9a761e436843f228eaa2decda6d2c6dbd5ef1480",
"versionType": "git"
},
{
"lessThan": "9b03c3ce32a685f9cb82d33c63fc18bfcee0ba1b",
"status": "affected",
"version": "9a761e436843f228eaa2decda6d2c6dbd5ef1480",
"versionType": "git"
},
{
"lessThan": "71209954f1e8ff0f0ba944c8d3b64bbed83d400c",
"status": "affected",
"version": "9a761e436843f228eaa2decda6d2c6dbd5ef1480",
"versionType": "git"
},
{
"lessThan": "2fbe83fe23f541798bcdd7d6b56a08d4ac205bad",
"status": "affected",
"version": "9a761e436843f228eaa2decda6d2c6dbd5ef1480",
"versionType": "git"
},
{
"lessThan": "14acbb5af101b7bb58c0952949bba4c5fdf0ee7e",
"status": "affected",
"version": "9a761e436843f228eaa2decda6d2c6dbd5ef1480",
"versionType": "git"
},
{
"lessThan": "bd9f6ce7d512fa21249415c16af801a4ed5d97b6",
"status": "affected",
"version": "9a761e436843f228eaa2decda6d2c6dbd5ef1480",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/platform/samsung/exynos4-is/fimc-is-regs.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.10"
},
{
"lessThan": "3.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.4.*",
"status": "unaffected",
"version": "5.4.295",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.239",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.186",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.187",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.156",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.108",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.15.*",
"status": "unaffected",
"version": "6.15.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "6.16",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.4.295",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.239",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.186",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.187",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.156",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.108",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.15.4",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.16",
"versionStartIncluding": "3.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: platform: exynos4-is: Add hardware sync wait to fimc_is_hw_change_mode()\n\nIn fimc_is_hw_change_mode(), the function changes camera modes without\nwaiting for hardware completion, risking corrupted data or system hangs\nif subsequent operations proceed before the hardware is ready.\n\nAdd fimc_is_hw_wait_intmsr0_intmsd0() after mode configuration, ensuring\nhardware state synchronization and stable interrupt handling."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-02T12:49:21.506Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b0d92b94278561f43057003a73a17ce13b7c1a1a"
},
{
"url": "https://git.kernel.org/stable/c/e4077a10a25560ec0bd0b42322e4ea027d6f76e2"
},
{
"url": "https://git.kernel.org/stable/c/bb97dfab7615fea97322b8a6131546e80f878a69"
},
{
"url": "https://git.kernel.org/stable/c/9b03c3ce32a685f9cb82d33c63fc18bfcee0ba1b"
},
{
"url": "https://git.kernel.org/stable/c/71209954f1e8ff0f0ba944c8d3b64bbed83d400c"
},
{
"url": "https://git.kernel.org/stable/c/2fbe83fe23f541798bcdd7d6b56a08d4ac205bad"
},
{
"url": "https://git.kernel.org/stable/c/14acbb5af101b7bb58c0952949bba4c5fdf0ee7e"
},
{
"url": "https://git.kernel.org/stable/c/bd9f6ce7d512fa21249415c16af801a4ed5d97b6"
}
],
"title": "media: platform: exynos4-is: Add hardware sync wait to fimc_is_hw_change_mode()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2025-38237",
"datePublished": "2025-07-08T07:42:57.527Z",
"dateReserved": "2025-04-16T04:51:23.996Z",
"dateUpdated": "2026-09-02T12:49:21.506Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68147 (GCVE-0-2026-68147)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
fscrypt: Avoid dynamic allocation in fscrypt_get_devices()
When a blk_crypto_key starts being used or is evicted, fs/crypto/ calls
fscrypt_get_devices() to get the filesystem's list of block devices,
then iterates over them and calls blk_crypto_config_supported(),
blk_crypto_start_using_key(), or blk_crypto_evict_key() on each one.
Currently, the block device pointers are placed in a dynamically
allocated array. This dynamic allocation is problematic because:
- It can fail, especially at the fscrypt_destroy_inline_crypt_key() call
site when it's invoked for inode eviction under direct reclaim.
- fscrypt_destroy_inline_crypt_key() doesn't handle the failure. It
just zeroizes and frees the blk_crypto_key without calling
blk_crypto_evict_key(). That causes a use-after-free.
For now, let's fix this in the straightforward and easily-backportable
way by switching to an on-stack array. Currently the fscrypt
multi-device functionality is used only by f2fs, which has a hardcoded
limit of 8 block devices. An on-stack array works fine for that.
(Of course, this solution won't scale up to large number of block
devices. For that we'd need a different solution, like moving the block
device iteration into the filesystem. Or in the case of btrfs, which
will only support blk-crypto-fallback, we should make it just call
blk-crypto-fallback directly, so the block devices won't be needed.)
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 22e9947a4b2ba255888541bd0111cf00b9b16586 Version: 22e9947a4b2ba255888541bd0111cf00b9b16586 Version: 22e9947a4b2ba255888541bd0111cf00b9b16586 Version: 22e9947a4b2ba255888541bd0111cf00b9b16586 Version: 22e9947a4b2ba255888541bd0111cf00b9b16586 Version: 22e9947a4b2ba255888541bd0111cf00b9b16586 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/crypto/inline_crypt.c",
"fs/f2fs/super.c",
"include/linux/fscrypt.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "bab016bb80d74a9d1f7d4121a7fc1cb529b470e0",
"status": "affected",
"version": "22e9947a4b2ba255888541bd0111cf00b9b16586",
"versionType": "git"
},
{
"lessThan": "4462ac3d90e897dda52ce4b6af2d526ddae835a8",
"status": "affected",
"version": "22e9947a4b2ba255888541bd0111cf00b9b16586",
"versionType": "git"
},
{
"lessThan": "97a688563be71ec6fefc071aff69a66c69dbe244",
"status": "affected",
"version": "22e9947a4b2ba255888541bd0111cf00b9b16586",
"versionType": "git"
},
{
"lessThan": "81ea8e8221853950c47dac7164f27c63a96f8f86",
"status": "affected",
"version": "22e9947a4b2ba255888541bd0111cf00b9b16586",
"versionType": "git"
},
{
"lessThan": "bc2d630296e0e049210ec05ff08459a6893ae749",
"status": "affected",
"version": "22e9947a4b2ba255888541bd0111cf00b9b16586",
"versionType": "git"
},
{
"lessThan": "6fe4e4b8259e1330945b5f3c9476e08473b8e0e8",
"status": "affected",
"version": "22e9947a4b2ba255888541bd0111cf00b9b16586",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/crypto/inline_crypt.c",
"fs/f2fs/super.c",
"include/linux/fscrypt.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.1"
},
{
"lessThan": "6.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "6.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfscrypt: Avoid dynamic allocation in fscrypt_get_devices()\n\nWhen a blk_crypto_key starts being used or is evicted, fs/crypto/ calls\nfscrypt_get_devices() to get the filesystem\u0027s list of block devices,\nthen iterates over them and calls blk_crypto_config_supported(),\nblk_crypto_start_using_key(), or blk_crypto_evict_key() on each one.\n\nCurrently, the block device pointers are placed in a dynamically\nallocated array. This dynamic allocation is problematic because:\n\n- It can fail, especially at the fscrypt_destroy_inline_crypt_key() call\n site when it\u0027s invoked for inode eviction under direct reclaim.\n\n- fscrypt_destroy_inline_crypt_key() doesn\u0027t handle the failure. It\n just zeroizes and frees the blk_crypto_key without calling\n blk_crypto_evict_key(). That causes a use-after-free.\n\nFor now, let\u0027s fix this in the straightforward and easily-backportable\nway by switching to an on-stack array. Currently the fscrypt\nmulti-device functionality is used only by f2fs, which has a hardcoded\nlimit of 8 block devices. An on-stack array works fine for that.\n\n(Of course, this solution won\u0027t scale up to large number of block\ndevices. For that we\u0027d need a different solution, like moving the block\ndevice iteration into the filesystem. Or in the case of btrfs, which\nwill only support blk-crypto-fallback, we should make it just call\nblk-crypto-fallback directly, so the block devices won\u0027t be needed.)"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached only via local fscrypt/inline-crypto teardown (fscrypt_destroy_inline_crypt_key) during inode eviction or key removal on ext4/f2fs, triggered by local syscalls/ioctls and file operations, not by any network-facing kernel service.\nAC:L - An attacker can reliably induce the kmalloc failure by creating memory pressure while closing encrypted inodes or removing v2 fscrypt keys, especially under direct reclaim where the commit notes this path fails; both sides of the race are attacker-controlled.\nPR:L - Exploitation requires only a local unprivileged user on an inlinecrypt-mounted filesystem: v2 FS_IOC_ADD/REMOVE_ENCRYPTION_KEY are unprivileged, and the attacker can create/close their own encrypted files to drive fscrypt_put_encryption_info into the buggy destroy path.\nUI:N - No victim interaction is required; the attacker triggers memory pressure and encrypted inode/key teardown themselves through normal local file and fscrypt ioctl operations on systems already mounted with inline encryption.\nS:U - Impact is confined to kernel memory corruption and privilege escalation within the same kernel security domain; this is not a VM escape, IOMMU bypass, or other cross-authority boundary violation.\nC:H - Skipping blk_crypto_evict_key before kfree_sensitive leaves dangling slot-\u003ekey/bio_crypt_ctx pointers to a freed blk_crypto_key (containing raw key bytes), a classic use-after-free that enables arbitrary kernel memory disclosure and heap grooming.\nI:H - The use-after-free of blk_crypto_key structures still registered in blk-crypto keyslot hash tables can be leveraged for heap corruption and control-flow hijacking, yielding arbitrary kernel write or local privilege escalation primitives.\nA:H - Dereferencing the prematurely freed blk_crypto_key during subsequent block I/O or keyslot lookups can cause kernel oops/panic; use-after-free in the block crypto path also inherently threatens system availability even before full exploitation."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:30:11.166Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/bab016bb80d74a9d1f7d4121a7fc1cb529b470e0"
},
{
"url": "https://git.kernel.org/stable/c/4462ac3d90e897dda52ce4b6af2d526ddae835a8"
},
{
"url": "https://git.kernel.org/stable/c/97a688563be71ec6fefc071aff69a66c69dbe244"
},
{
"url": "https://git.kernel.org/stable/c/81ea8e8221853950c47dac7164f27c63a96f8f86"
},
{
"url": "https://git.kernel.org/stable/c/bc2d630296e0e049210ec05ff08459a6893ae749"
},
{
"url": "https://git.kernel.org/stable/c/6fe4e4b8259e1330945b5f3c9476e08473b8e0e8"
}
],
"title": "fscrypt: Avoid dynamic allocation in fscrypt_get_devices()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68147",
"datePublished": "2026-08-10T11:59:12.308Z",
"dateReserved": "2026-07-30T09:28:09.371Z",
"dateUpdated": "2026-08-19T16:30:11.166Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80715 (GCVE-0-2026-80715)
Vulnerability from cvelistv5
Published
2026-08-28 06:53
Modified
2026-08-28 06:53
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
igc: remove napi_synchronize() in igc_down()
When an AF_XDP zero-copy application is killed abruptly, the XSK pool is
torn down but NAPI keeps polling. igc_clean_rx_irq_zc() then returns the
full budget on every poll, so napi_complete_done() never clears
NAPI_STATE_SCHED.
igc_down() calls napi_synchronize() before napi_disable(), so it spins
forever waiting for that bit and the interface never goes down. Drop the
napi_synchronize() and let napi_disable() do the job -- it sets
NAPI_STATE_DISABLE, which forces the stuck poll to complete. Reorder it
ahead of igc_set_queue_napi() so the NAPI mapping is cleared only after
polling has stopped, matching the recent igb fix b1e067240379.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: fc9df2a0b520d7d439ecf464794d53e91be74b93 Version: fc9df2a0b520d7d439ecf464794d53e91be74b93 Version: fc9df2a0b520d7d439ecf464794d53e91be74b93 Version: fc9df2a0b520d7d439ecf464794d53e91be74b93 Version: fc9df2a0b520d7d439ecf464794d53e91be74b93 Version: fc9df2a0b520d7d439ecf464794d53e91be74b93 Version: fc9df2a0b520d7d439ecf464794d53e91be74b93 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/intel/igc/igc_main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ad6e0df267dc96edb7de1fa0a2fb2a70645bff86",
"status": "affected",
"version": "fc9df2a0b520d7d439ecf464794d53e91be74b93",
"versionType": "git"
},
{
"lessThan": "605585a8d89aaeb0122e9016fdaa92376897a705",
"status": "affected",
"version": "fc9df2a0b520d7d439ecf464794d53e91be74b93",
"versionType": "git"
},
{
"lessThan": "a0f16c337691813f8d8f014c01fff5a368e08898",
"status": "affected",
"version": "fc9df2a0b520d7d439ecf464794d53e91be74b93",
"versionType": "git"
},
{
"lessThan": "f929a6fe5b7ae1e72d2c6d18cd69ab90dcf689d2",
"status": "affected",
"version": "fc9df2a0b520d7d439ecf464794d53e91be74b93",
"versionType": "git"
},
{
"lessThan": "3b5aee6fcbf6b58112d40d19c8d31fa3f78ee668",
"status": "affected",
"version": "fc9df2a0b520d7d439ecf464794d53e91be74b93",
"versionType": "git"
},
{
"lessThan": "9a2b637aef4e515c2179774888441d00e8a5ae95",
"status": "affected",
"version": "fc9df2a0b520d7d439ecf464794d53e91be74b93",
"versionType": "git"
},
{
"lessThan": "5ffab5b9589c50e4cfc0cf36ffd76c89422d4019",
"status": "affected",
"version": "fc9df2a0b520d7d439ecf464794d53e91be74b93",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/intel/igc/igc_main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.14"
},
{
"lessThan": "5.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nigc: remove napi_synchronize() in igc_down()\n\nWhen an AF_XDP zero-copy application is killed abruptly, the XSK pool is\ntorn down but NAPI keeps polling. igc_clean_rx_irq_zc() then returns the\nfull budget on every poll, so napi_complete_done() never clears\nNAPI_STATE_SCHED.\n\nigc_down() calls napi_synchronize() before napi_disable(), so it spins\nforever waiting for that bit and the interface never goes down. Drop the\nnapi_synchronize() and let napi_disable() do the job -- it sets\nNAPI_STATE_DISABLE, which forces the stuck poll to complete. Reorder it\nahead of igc_set_queue_napi() so the NAPI mapping is cleared only after\npolling has stopped, matching the recent igb fix b1e067240379."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-28T06:53:13.683Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ad6e0df267dc96edb7de1fa0a2fb2a70645bff86"
},
{
"url": "https://git.kernel.org/stable/c/605585a8d89aaeb0122e9016fdaa92376897a705"
},
{
"url": "https://git.kernel.org/stable/c/a0f16c337691813f8d8f014c01fff5a368e08898"
},
{
"url": "https://git.kernel.org/stable/c/f929a6fe5b7ae1e72d2c6d18cd69ab90dcf689d2"
},
{
"url": "https://git.kernel.org/stable/c/3b5aee6fcbf6b58112d40d19c8d31fa3f78ee668"
},
{
"url": "https://git.kernel.org/stable/c/9a2b637aef4e515c2179774888441d00e8a5ae95"
},
{
"url": "https://git.kernel.org/stable/c/5ffab5b9589c50e4cfc0cf36ffd76c89422d4019"
}
],
"title": "igc: remove napi_synchronize() in igc_down()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80715",
"datePublished": "2026-08-28T06:53:13.683Z",
"dateReserved": "2026-08-26T14:34:25.788Z",
"dateUpdated": "2026-08-28T06:53:13.683Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74546 (GCVE-0-2026-74546)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-19 16:38
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
hwmon: (adt7470) Fix divide-by-zero TOCTOU crash in fan speed read
If the fan data becomes 0 between the FAN_DATA_VALID() check and the
FAN_PERIOD_TO_RPM() conversion, it will result in a divide-by-zero crash
due to a race with a concurrent update of the cached fan value.
Fix a TOCTOU issue by reading fan data once.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: fc958a61ff6d34a0ec42744d3ff524ee202b2e9f Version: fc958a61ff6d34a0ec42744d3ff524ee202b2e9f Version: fc958a61ff6d34a0ec42744d3ff524ee202b2e9f Version: fc958a61ff6d34a0ec42744d3ff524ee202b2e9f Version: fc958a61ff6d34a0ec42744d3ff524ee202b2e9f Version: fc958a61ff6d34a0ec42744d3ff524ee202b2e9f Version: fc958a61ff6d34a0ec42744d3ff524ee202b2e9f |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/hwmon/adt7470.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "689a2ea75434131d0af58aeb7d51fde40e858b4d",
"status": "affected",
"version": "fc958a61ff6d34a0ec42744d3ff524ee202b2e9f",
"versionType": "git"
},
{
"lessThan": "009240d057e26831cc925feaba4c490209c1d0ba",
"status": "affected",
"version": "fc958a61ff6d34a0ec42744d3ff524ee202b2e9f",
"versionType": "git"
},
{
"lessThan": "d328175045176f85c15c369bd21dc551351e7935",
"status": "affected",
"version": "fc958a61ff6d34a0ec42744d3ff524ee202b2e9f",
"versionType": "git"
},
{
"lessThan": "832069bec79cf6f903441c5769d3cdba95d0af33",
"status": "affected",
"version": "fc958a61ff6d34a0ec42744d3ff524ee202b2e9f",
"versionType": "git"
},
{
"lessThan": "96ad57d31763559d376416cdf3bf5ae79bbbebec",
"status": "affected",
"version": "fc958a61ff6d34a0ec42744d3ff524ee202b2e9f",
"versionType": "git"
},
{
"lessThan": "76963b04b2d1c648d69949d8dd521e1ff7f40b51",
"status": "affected",
"version": "fc958a61ff6d34a0ec42744d3ff524ee202b2e9f",
"versionType": "git"
},
{
"lessThan": "1b46fe9dc8f8de59310f37e6c5e5c0e05ded46c3",
"status": "affected",
"version": "fc958a61ff6d34a0ec42744d3ff524ee202b2e9f",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/hwmon/adt7470.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.15"
},
{
"lessThan": "5.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (adt7470) Fix divide-by-zero TOCTOU crash in fan speed read\n\nIf the fan data becomes 0 between the FAN_DATA_VALID() check and the\nFAN_PERIOD_TO_RPM() conversion, it will result in a divide-by-zero crash\ndue to a race with a concurrent update of the cached fan value.\n\nFix a TOCTOU issue by reading fan data once."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:38:34.886Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/689a2ea75434131d0af58aeb7d51fde40e858b4d"
},
{
"url": "https://git.kernel.org/stable/c/009240d057e26831cc925feaba4c490209c1d0ba"
},
{
"url": "https://git.kernel.org/stable/c/d328175045176f85c15c369bd21dc551351e7935"
},
{
"url": "https://git.kernel.org/stable/c/832069bec79cf6f903441c5769d3cdba95d0af33"
},
{
"url": "https://git.kernel.org/stable/c/96ad57d31763559d376416cdf3bf5ae79bbbebec"
},
{
"url": "https://git.kernel.org/stable/c/76963b04b2d1c648d69949d8dd521e1ff7f40b51"
},
{
"url": "https://git.kernel.org/stable/c/1b46fe9dc8f8de59310f37e6c5e5c0e05ded46c3"
}
],
"title": "hwmon: (adt7470) Fix divide-by-zero TOCTOU crash in fan speed read",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74546",
"datePublished": "2026-08-15T12:27:55.147Z",
"dateReserved": "2026-08-15T05:44:03.914Z",
"dateUpdated": "2026-08-19T16:38:34.886Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74446 (GCVE-0-2026-74446)
Vulnerability from cvelistv5
Published
2026-08-15 12:26
Modified
2026-08-19 16:36
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdkfd: hold event_mutex while checkpointing CRIU events
kfd_criu_checkpoint_events() counts the entries in p->event_idr via
kfd_get_num_events(), allocates an array sized to that count, and then
walks the same IDR to fill it. Neither the count nor the walk holds
p->event_mutex.
The CRIU checkpoint caller holds only p->mutex. Event create and destroy
(kfd_event_create()/kfd_event_destroy()) take p->event_mutex and do not
take p->mutex, so a second thread in the same process can insert or remove
events between the count and the walk. If an event is inserted, the walk
iterates more entries than were counted and writes past the end of the
ev_privs allocation; if an event is removed, the walk dereferences an
entry that is being freed.
Hold p->event_mutex across the count and the walk so both observe a
consistent view of p->event_idr. The lock is released before
copy_to_user(), which only touches the local buffer. The caller already
holds p->mutex and the create/destroy paths never take p->mutex, so the
p->mutex -> p->event_mutex order is not inverted and no deadlock is
introduced.
(cherry picked from commit ff57e223ab105795b05d3ef3f3c35a5a441bcbaa)
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 40e8a766a761f7fdc8530347527b344fddf6f1a8 Version: 40e8a766a761f7fdc8530347527b344fddf6f1a8 Version: 40e8a766a761f7fdc8530347527b344fddf6f1a8 Version: 40e8a766a761f7fdc8530347527b344fddf6f1a8 Version: 40e8a766a761f7fdc8530347527b344fddf6f1a8 Version: 40e8a766a761f7fdc8530347527b344fddf6f1a8 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdkfd/kfd_events.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "8f7196f25b14f4290738639a50459b56a5ff2784",
"status": "affected",
"version": "40e8a766a761f7fdc8530347527b344fddf6f1a8",
"versionType": "git"
},
{
"lessThan": "2040b7e39027cb83bb8c7b84a4c95c2f6053c32f",
"status": "affected",
"version": "40e8a766a761f7fdc8530347527b344fddf6f1a8",
"versionType": "git"
},
{
"lessThan": "9a7f765985f64fd4a7a58f7bc9cd80a1f4230628",
"status": "affected",
"version": "40e8a766a761f7fdc8530347527b344fddf6f1a8",
"versionType": "git"
},
{
"lessThan": "6a52f48157fa7fb81e0c146937fd6c8b0c1cfdbd",
"status": "affected",
"version": "40e8a766a761f7fdc8530347527b344fddf6f1a8",
"versionType": "git"
},
{
"lessThan": "bed80be08c0bee47fa242a4256ac873477c815f8",
"status": "affected",
"version": "40e8a766a761f7fdc8530347527b344fddf6f1a8",
"versionType": "git"
},
{
"lessThan": "ff8bc5a68a9a70bdc38d61a72c7a49c56063f9d2",
"status": "affected",
"version": "40e8a766a761f7fdc8530347527b344fddf6f1a8",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdkfd/kfd_events.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.18"
},
{
"lessThan": "5.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.18",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdkfd: hold event_mutex while checkpointing CRIU events\n\nkfd_criu_checkpoint_events() counts the entries in p-\u003eevent_idr via\nkfd_get_num_events(), allocates an array sized to that count, and then\nwalks the same IDR to fill it. Neither the count nor the walk holds\np-\u003eevent_mutex.\n\nThe CRIU checkpoint caller holds only p-\u003emutex. Event create and destroy\n(kfd_event_create()/kfd_event_destroy()) take p-\u003eevent_mutex and do not\ntake p-\u003emutex, so a second thread in the same process can insert or remove\nevents between the count and the walk. If an event is inserted, the walk\niterates more entries than were counted and writes past the end of the\nev_privs allocation; if an event is removed, the walk dereferences an\nentry that is being freed.\n\nHold p-\u003eevent_mutex across the count and the walk so both observe a\nconsistent view of p-\u003eevent_idr. The lock is released before\ncopy_to_user(), which only touches the local buffer. The caller already\nholds p-\u003emutex and the create/destroy paths never take p-\u003emutex, so the\np-\u003emutex -\u003e p-\u003eevent_mutex order is not inverted and no deadlock is\nintroduced.\n\n(cherry picked from commit ff57e223ab105795b05d3ef3f3c35a5a441bcbaa)"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached only through AMDKFD_IOC_CRIU_OP_CHECKPOINT on /dev/kfd, a local character-device ioctl in the amdgpu/amdkfd GPU compute stack, not via any network-facing kernel service.\nAC:L - Exploitation needs a race between CRIU checkpoint and concurrent event create/destroy in the same KFD process; the attacker controls both threads and can repeat the ioctl and event churn until the TOCTOU window is hit reliably.\nPR:L - CRIU checkpoint requires CAP_CHECKPOINT_RESTORE or CAP_SYS_ADMIN, both obtainable by an unprivileged user via a user namespace (same model as other namespace-granted caps); GPU tenant access to /dev/kfd on ROCm/HPC nodes is sufficient.\nUI:N - No victim interaction is required beyond the attacker opening /dev/kfd and driving CRIU checkpoint and event ioctls from their own process threads.\nS:U - Impact is kernel heap corruption and privilege escalation within the host kernel security domain; it does not cross a guest/host or IOMMU/DMA trust boundary on its own.\nC:H - Concurrent event removal causes the checkpoint walk to dereference kfd_event objects being freed (UAF), and OOB writes of 64-byte kfd_criu_event_priv_data entries can corrupt adjacent kernel memory to leak data.\nI:H - If events are inserted between kfd_get_num_events() and the IDR walk, the checkpoint loop writes past the end of the kvzalloc ev_privs buffer, enabling heap overflow and control of freed-object contents for arbitrary write primitives.\nA:H - The UAF and heap out-of-bounds write can trigger kernel oops/panic during checkpoint or corrupt critical kernel structures, causing denial of service or system crash."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:36:41.097Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/8f7196f25b14f4290738639a50459b56a5ff2784"
},
{
"url": "https://git.kernel.org/stable/c/2040b7e39027cb83bb8c7b84a4c95c2f6053c32f"
},
{
"url": "https://git.kernel.org/stable/c/9a7f765985f64fd4a7a58f7bc9cd80a1f4230628"
},
{
"url": "https://git.kernel.org/stable/c/6a52f48157fa7fb81e0c146937fd6c8b0c1cfdbd"
},
{
"url": "https://git.kernel.org/stable/c/bed80be08c0bee47fa242a4256ac873477c815f8"
},
{
"url": "https://git.kernel.org/stable/c/ff8bc5a68a9a70bdc38d61a72c7a49c56063f9d2"
}
],
"title": "drm/amdkfd: hold event_mutex while checkpointing CRIU events",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74446",
"datePublished": "2026-08-15T12:26:52.677Z",
"dateReserved": "2026-08-15T05:44:03.898Z",
"dateUpdated": "2026-08-19T16:36:41.097Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80590 (GCVE-0-2026-80590)
Vulnerability from cvelistv5
Published
2026-08-28 06:35
Modified
2026-08-31 06:12
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
inet: frags: strip GSO state from fragments before reassembly
A virtio_net_hdr (tun/tap, or AF_PACKET with PACKET_VNET_HDR) can mark
an IPv4 or IPv6 fragment as GSO; nothing relates gso_type to frag_off.
inet_frag_reasm_prepare()/inet_frag_reasm_finish() keep the first
fragment's skb as the head of the reassembled datagram, including its
shinfo->gso_size/gso_type/gso_segs, and chain the remaining fragments
on frag_list with whatever linear/paged layout they arrived with.
After ip_defrag() (ip_local_deliver(), nf_defrag_ipv4, ...) the
reassembled skb therefore still claims to be GSO (SKB_GSO_DODGY), and
the next software segmentation point - udp_rcv_segment() on local
delivery, validate_xmit_skb(), or the ip_finish_output_gso() slow
path - hands it to skb_segment(). skb_segment()'s frag_list walk
assumes GRO-shaped input and hits one of its BUG_ON()s. Two writes to
a tap by an unprivileged user in its own userns are enough:
kernel BUG at net/core/skbuff.c:4899!
Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI
CPU: 0 UID: 1000 PID: 82 Comm: poc Not tainted 7.2.0-pentest+ #2
RIP: 0010:skb_segment+0x20ca/0x48b0
Call Trace:
<TASK>
__udp_gso_segment+0x29a/0x27d0
udp4_ufo_fragment+0x458/0x6c0
inet_gso_segment+0x429/0x1340
skb_mac_gso_segment+0x233/0x4f0
__skb_gso_segment+0x308/0x660
udp_queue_rcv_skb+0x440/0xad0
udp_unicast_rcv_skb+0xc7/0x2c0
udp_rcv+0x16ce/0x2260
ip_protocol_deliver_rcu+0x197/0x2d0
ip_local_deliver+0x430/0x690
ip_rcv+0x16f/0x1f0
__netif_receive_skb_one_core+0x15e/0x1c0
__netif_receive_skb+0x1e/0x110
netif_receive_skb+0xf6/0x5c0
tun_rx_batched.isra.0+0x3ab/0x790
tun_get_user+0x17c3/0x3550
tun_chr_write_iter+0xba/0x1b0
vfs_write+0x646/0x1130
</TASK>
Kernel panic - not syncing: Fatal exception in interrupt
This runs with BH disabled, so it is a panic rather than an oops. The
same is reachable with CAP_NET_RAW in a netns where a defrag point
precedes a GSO point, and from a guest whose VMM forwards
virtio_net_hdr to a tap. The SKB_GSO_DODGY frag_list checks added by
commit 3dcbdb134f32 ("net: gso: Fix skb_segment splat when splitting
gso_size mangled skb having linear-headed frag_list") and by
commit 9e4b7a99a03a ("net: gso: fix panic on frag_list with mixed head
alloc types") do not cover it: page-backed heads skip them, and kmalloc
heads skip them when gso_size == skb_headlen(head), which the sender
controls.
An skb entering a frag queue is an IP fragment by definition and
cannot legitimately carry GSO state: GRO does not merge fragments and
the stack segments before it fragments, so only untrusted sources are
affected. This has been reachable since
commit f43798c27684 ("tun: Allow GSO using virtio_net_hdr"), the first
path that let userspace attach GSO metadata to an IP fragment. Reset
the GSO fields of every fragment as it is queued, in
inet_frag_queue_insert(), which IPv4, IPv6, nf_conntrack_reasm and
6lowpan reassembly share; then neither the head nor the frag_list
members of the reassembled skb carry them (the members matter too:
the ip_do_fragment()/ip6_fragment() fast paths send them out as they
are). The head may remain CHECKSUM_PARTIAL; that is already accepted
on receive and resolved by skb_checksum_help() in
ip_do_fragment()/ip6_fragment() on forward.
Tested on top of net.git (dc4b95b8fee9), x86_64: the tap reproducer
above, two further IPv4 frag_list geometries that reach
BUG_ON(i >= nfrags) and BUG_ON(!list_skb->head_frag), and an IPv6
fragment-header variant (udp6_ufo_fragment()) each panic the unpatched
kernel; with this patch all four datagrams are delivered intact and
nothing is logged.
References
| URL | Tags | ||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: f43798c27684ab925adde7d8acc34c78c6e50df8 Version: f43798c27684ab925adde7d8acc34c78c6e50df8 Version: f43798c27684ab925adde7d8acc34c78c6e50df8 Version: f43798c27684ab925adde7d8acc34c78c6e50df8 Version: f43798c27684ab925adde7d8acc34c78c6e50df8 Version: f43798c27684ab925adde7d8acc34c78c6e50df8 Version: f43798c27684ab925adde7d8acc34c78c6e50df8 Version: f43798c27684ab925adde7d8acc34c78c6e50df8 Version: f43798c27684ab925adde7d8acc34c78c6e50df8 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ipv4/inet_fragment.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "cfdbc8c2e6f9ef5d8b8e54859da03dfe682b0bee",
"status": "affected",
"version": "f43798c27684ab925adde7d8acc34c78c6e50df8",
"versionType": "git"
},
{
"lessThan": "29dda278a5ed272f2230ff4eaa23cf403107bba0",
"status": "affected",
"version": "f43798c27684ab925adde7d8acc34c78c6e50df8",
"versionType": "git"
},
{
"lessThan": "14a8f3e10fa9a5abd6cedcdaa0c0b7ea9a09f234",
"status": "affected",
"version": "f43798c27684ab925adde7d8acc34c78c6e50df8",
"versionType": "git"
},
{
"lessThan": "3edf721bb4b99d272c336631b44e3d8ff9a4f31b",
"status": "affected",
"version": "f43798c27684ab925adde7d8acc34c78c6e50df8",
"versionType": "git"
},
{
"lessThan": "dec2edb7aaf12a8878b3a03172ea8fc277b8eaad",
"status": "affected",
"version": "f43798c27684ab925adde7d8acc34c78c6e50df8",
"versionType": "git"
},
{
"lessThan": "c49f04e8d2b94dbb8d9fd99731dd3f00589c8ace",
"status": "affected",
"version": "f43798c27684ab925adde7d8acc34c78c6e50df8",
"versionType": "git"
},
{
"lessThan": "69b73b74d9eb45f5560a8fe4fa406ada580e1340",
"status": "affected",
"version": "f43798c27684ab925adde7d8acc34c78c6e50df8",
"versionType": "git"
},
{
"lessThan": "da857e448322a2e871ce3ecc2900027041160d43",
"status": "affected",
"version": "f43798c27684ab925adde7d8acc34c78c6e50df8",
"versionType": "git"
},
{
"lessThan": "d5dc1e69fd7258ea605c9952e5d5947539159ae3",
"status": "affected",
"version": "f43798c27684ab925adde7d8acc34c78c6e50df8",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ipv4/inet_fragment.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.27"
},
{
"lessThan": "2.6.27",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.268",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.219",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.186",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.155",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.107",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.48",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.12",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.2",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.268",
"versionStartIncluding": "2.6.27",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.219",
"versionStartIncluding": "2.6.27",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.186",
"versionStartIncluding": "2.6.27",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.155",
"versionStartIncluding": "2.6.27",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.107",
"versionStartIncluding": "2.6.27",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.48",
"versionStartIncluding": "2.6.27",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.12",
"versionStartIncluding": "2.6.27",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.2",
"versionStartIncluding": "2.6.27",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "2.6.27",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ninet: frags: strip GSO state from fragments before reassembly\n\nA virtio_net_hdr (tun/tap, or AF_PACKET with PACKET_VNET_HDR) can mark\nan IPv4 or IPv6 fragment as GSO; nothing relates gso_type to frag_off.\ninet_frag_reasm_prepare()/inet_frag_reasm_finish() keep the first\nfragment\u0027s skb as the head of the reassembled datagram, including its\nshinfo-\u003egso_size/gso_type/gso_segs, and chain the remaining fragments\non frag_list with whatever linear/paged layout they arrived with.\n\nAfter ip_defrag() (ip_local_deliver(), nf_defrag_ipv4, ...) the\nreassembled skb therefore still claims to be GSO (SKB_GSO_DODGY), and\nthe next software segmentation point - udp_rcv_segment() on local\ndelivery, validate_xmit_skb(), or the ip_finish_output_gso() slow\npath - hands it to skb_segment(). skb_segment()\u0027s frag_list walk\nassumes GRO-shaped input and hits one of its BUG_ON()s. Two writes to\na tap by an unprivileged user in its own userns are enough:\n\n kernel BUG at net/core/skbuff.c:4899!\n Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI\n CPU: 0 UID: 1000 PID: 82 Comm: poc Not tainted 7.2.0-pentest+ #2\n RIP: 0010:skb_segment+0x20ca/0x48b0\n Call Trace:\n \u003cTASK\u003e\n __udp_gso_segment+0x29a/0x27d0\n udp4_ufo_fragment+0x458/0x6c0\n inet_gso_segment+0x429/0x1340\n skb_mac_gso_segment+0x233/0x4f0\n __skb_gso_segment+0x308/0x660\n udp_queue_rcv_skb+0x440/0xad0\n udp_unicast_rcv_skb+0xc7/0x2c0\n udp_rcv+0x16ce/0x2260\n ip_protocol_deliver_rcu+0x197/0x2d0\n ip_local_deliver+0x430/0x690\n ip_rcv+0x16f/0x1f0\n __netif_receive_skb_one_core+0x15e/0x1c0\n __netif_receive_skb+0x1e/0x110\n netif_receive_skb+0xf6/0x5c0\n tun_rx_batched.isra.0+0x3ab/0x790\n tun_get_user+0x17c3/0x3550\n tun_chr_write_iter+0xba/0x1b0\n vfs_write+0x646/0x1130\n \u003c/TASK\u003e\n Kernel panic - not syncing: Fatal exception in interrupt\n\nThis runs with BH disabled, so it is a panic rather than an oops. The\nsame is reachable with CAP_NET_RAW in a netns where a defrag point\nprecedes a GSO point, and from a guest whose VMM forwards\nvirtio_net_hdr to a tap. The SKB_GSO_DODGY frag_list checks added by\ncommit 3dcbdb134f32 (\"net: gso: Fix skb_segment splat when splitting\ngso_size mangled skb having linear-headed frag_list\") and by\ncommit 9e4b7a99a03a (\"net: gso: fix panic on frag_list with mixed head\nalloc types\") do not cover it: page-backed heads skip them, and kmalloc\nheads skip them when gso_size == skb_headlen(head), which the sender\ncontrols.\n\nAn skb entering a frag queue is an IP fragment by definition and\ncannot legitimately carry GSO state: GRO does not merge fragments and\nthe stack segments before it fragments, so only untrusted sources are\naffected. This has been reachable since\ncommit f43798c27684 (\"tun: Allow GSO using virtio_net_hdr\"), the first\npath that let userspace attach GSO metadata to an IP fragment. Reset\nthe GSO fields of every fragment as it is queued, in\ninet_frag_queue_insert(), which IPv4, IPv6, nf_conntrack_reasm and\n6lowpan reassembly share; then neither the head nor the frag_list\nmembers of the reassembled skb carry them (the members matter too:\nthe ip_do_fragment()/ip6_fragment() fast paths send them out as they\nare). The head may remain CHECKSUM_PARTIAL; that is already accepted\non receive and resolved by skb_checksum_help() in\nip_do_fragment()/ip6_fragment() on forward.\n\nTested on top of net.git (dc4b95b8fee9), x86_64: the tap reproducer\nabove, two further IPv4 frag_list geometries that reach\nBUG_ON(i \u003e= nfrags) and BUG_ON(!list_skb-\u003ehead_frag), and an IPv6\nfragment-header variant (udp6_ufo_fragment()) each panic the unpatched\nkernel; with this patch all four datagrams are delivered intact and\nnothing is logged."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.6,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - A malicious cloud VM guest injects virtio_net_hdr-marked IPv4/IPv6 fragments through virtio-net/vhost-tap into the host ip_rcv() path; the same inet_frag reassembly and skb_segment() crash also fires on validate_xmit_skb()/ip_finish_output_gso() when such skbs traverse forwarding.\nAC:L - The attacker fully controls virtio_net_hdr gso_type/gso_size and fragment geometry; the commit reproduces a host panic from two tap writes with no races, timing, or uncontrollable memory layout required.\nPR:N - On typical KVM/QEMU tap-backed virtio-net deployments a tenant VM needs no host account or capability; exploitation uses only the pre-provisioned virtual NIC, not init-namespace root or CAP_NET_ADMIN on the host.\nUI:N - Packet injection, ip_defrag reassembly, and GSO segmentation run automatically in softirq once crafted virtio fragments are sent; no victim mount, click, or other cooperative action is required.\nS:C - A guest VM tenant can panic the host kernel by crossing the hypervisor virtio/tap boundary, impacting resources outside the guest security authority even though the demonstrated primitive is denial of service rather than full escape.\nC:N - Impact is an intentional BUG_ON in skb_segment() frag_list handling; there is no demonstrated out-of-bounds read, use-after-free, or other information-disclosure primitive before the assertion aborts.\nI:N - The failure aborts in skb_segment() before any out-of-bounds write, page-desc conversion, or control-flow hijack; attacker-controlled metadata only reaches a defensive assertion, not a memory modification primitive.\nA:H - Triggering skb_segment() BUG_ON from tun_rx/tun_get_user runs with BH disabled and causes a fatal kernel panic, fully and repeatedly denying availability of the affected host until reboot."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-31T06:12:21.989Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/cfdbc8c2e6f9ef5d8b8e54859da03dfe682b0bee"
},
{
"url": "https://git.kernel.org/stable/c/29dda278a5ed272f2230ff4eaa23cf403107bba0"
},
{
"url": "https://git.kernel.org/stable/c/14a8f3e10fa9a5abd6cedcdaa0c0b7ea9a09f234"
},
{
"url": "https://git.kernel.org/stable/c/3edf721bb4b99d272c336631b44e3d8ff9a4f31b"
},
{
"url": "https://git.kernel.org/stable/c/dec2edb7aaf12a8878b3a03172ea8fc277b8eaad"
},
{
"url": "https://git.kernel.org/stable/c/c49f04e8d2b94dbb8d9fd99731dd3f00589c8ace"
},
{
"url": "https://git.kernel.org/stable/c/69b73b74d9eb45f5560a8fe4fa406ada580e1340"
},
{
"url": "https://git.kernel.org/stable/c/da857e448322a2e871ce3ecc2900027041160d43"
},
{
"url": "https://git.kernel.org/stable/c/d5dc1e69fd7258ea605c9952e5d5947539159ae3"
}
],
"title": "inet: frags: strip GSO state from fragments before reassembly",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80590",
"datePublished": "2026-08-28T06:35:12.516Z",
"dateReserved": "2026-08-26T14:34:25.770Z",
"dateUpdated": "2026-08-31T06:12:21.989Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74637 (GCVE-0-2026-74637)
Vulnerability from cvelistv5
Published
2026-08-22 15:32
Modified
2026-08-27 12:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
perf/core: Fix group leader use-after-free after sibling detach
perf_group_detach() handles leader and sibling detach differently. When the
group leader is detached, all siblings are promoted to singleton events and
their group_leader pointer is reset to themselves. When a sibling is
detached, it is removed from the leader's sibling_list, but its
group_leader pointer is left pointing at the old leader.
That is harmless when the sibling is being closed and freed immediately, as
in the DETACH_DEAD path. It is not safe when the sibling is detached but
kept alive, such as during CPU hotplug with DETACH_GROUP. In that case the
sibling is removed from the context, while its file descriptor can still
keep it alive.
A typical failing sequence is:
- A group contains leader L and sibling S.
- CPU hot-unplug detaches S with DETACH_GROUP, removing it from
L->sibling_list but leaving S->group_leader == L.
- L is later closed and freed.
- A PERF_IOC_FLAG_GROUP ioctl on S follows S->group_leader and
dereferences the freed leader.
This was reproduced by running the perf event fuzzer, CPU hotplug, and a
stress workload concurrently:
Unable to handle kernel paging request at virtual address 006b6b6b6b6b6cdb
CPU: 2 PID: 12489 Comm: perf_fuzzer 6.18.7 PREEMPT
pc : perf_ioctl+0x34c/0xc68
x20: ffffff89a3fa2c70 x8 : 6b6b6b6b6b6b6b6b
Code: 943c4a0e 340047a0 f9404a94 f9411e88 (f940b908)
Call trace:
perf_ioctl+0x34c/0xc68 (P)
__arm64_sys_ioctl+0xa0/0xf4
invoke_syscall+0x58/0xe4
el0_svc_common+0xa8/0xdc
do_el0_svc+0x1c/0x28
el0_svc+0x40/0xc0
el0t_64_sync_handler+0x68/0xdc
el0t_64_sync+0x1c4/0x1c8
The fault happened in perf_ioctl(), where perf_event_for_each() follows
the stale group_leader pointer and perf_event_for_each_child() then
dereferences the freed leader's context.
Fix the use-after-free by promoting the detached sibling to a singleton.
Also fix __event_disable() cgroup accounting and event state change.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 8a49542c0554af7d0073aac0ee73ee65b807ef34 Version: 8a49542c0554af7d0073aac0ee73ee65b807ef34 Version: 8a49542c0554af7d0073aac0ee73ee65b807ef34 Version: 8a49542c0554af7d0073aac0ee73ee65b807ef34 Version: 8a49542c0554af7d0073aac0ee73ee65b807ef34 Version: 8a49542c0554af7d0073aac0ee73ee65b807ef34 Version: 8a49542c0554af7d0073aac0ee73ee65b807ef34 Version: 8a49542c0554af7d0073aac0ee73ee65b807ef34 Version: e732ebc42aea321ee84514330eb3a675307fcc83 Version: 2.6.34.14 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"kernel/events/core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "8f867c0e8da4c2303d91adf45acb6b1820966c27",
"status": "affected",
"version": "8a49542c0554af7d0073aac0ee73ee65b807ef34",
"versionType": "git"
},
{
"lessThan": "8e92e03984364d93e0d5b0acd81c95eca773f034",
"status": "affected",
"version": "8a49542c0554af7d0073aac0ee73ee65b807ef34",
"versionType": "git"
},
{
"lessThan": "f8a07021679aadfb6d63b209207ccc41f26982d1",
"status": "affected",
"version": "8a49542c0554af7d0073aac0ee73ee65b807ef34",
"versionType": "git"
},
{
"lessThan": "80c6054a4c40a0ffad82acef9f9a0dee108d152a",
"status": "affected",
"version": "8a49542c0554af7d0073aac0ee73ee65b807ef34",
"versionType": "git"
},
{
"lessThan": "b42948f9e0d1ea4dbd5742ce1dfc7688de5d4a35",
"status": "affected",
"version": "8a49542c0554af7d0073aac0ee73ee65b807ef34",
"versionType": "git"
},
{
"lessThan": "a979a642402d0b1f856c7a729b4cb2d92de4cf2f",
"status": "affected",
"version": "8a49542c0554af7d0073aac0ee73ee65b807ef34",
"versionType": "git"
},
{
"lessThan": "1e7abfeb23c12bf46f6457e4a3e1a1a300d50619",
"status": "affected",
"version": "8a49542c0554af7d0073aac0ee73ee65b807ef34",
"versionType": "git"
},
{
"lessThan": "42c5ca1f0a288a52878bd72a5595b08261057438",
"status": "affected",
"version": "8a49542c0554af7d0073aac0ee73ee65b807ef34",
"versionType": "git"
},
{
"status": "affected",
"version": "e732ebc42aea321ee84514330eb3a675307fcc83",
"versionType": "git"
},
{
"lessThan": "2.6.35",
"status": "affected",
"version": "2.6.34.14",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"kernel/events/core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.35"
},
{
"lessThan": "2.6.35",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.267",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.218",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.185",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.154",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.267",
"versionStartIncluding": "2.6.35",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.218",
"versionStartIncluding": "2.6.35",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.185",
"versionStartIncluding": "2.6.35",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.154",
"versionStartIncluding": "2.6.35",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "2.6.35",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "2.6.35",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "2.6.35",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.35",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "2.6.34.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nperf/core: Fix group leader use-after-free after sibling detach\n\nperf_group_detach() handles leader and sibling detach differently. When the\ngroup leader is detached, all siblings are promoted to singleton events and\ntheir group_leader pointer is reset to themselves. When a sibling is\ndetached, it is removed from the leader\u0027s sibling_list, but its\ngroup_leader pointer is left pointing at the old leader.\n\nThat is harmless when the sibling is being closed and freed immediately, as\nin the DETACH_DEAD path. It is not safe when the sibling is detached but\nkept alive, such as during CPU hotplug with DETACH_GROUP. In that case the\nsibling is removed from the context, while its file descriptor can still\nkeep it alive.\n\nA typical failing sequence is:\n\n - A group contains leader L and sibling S.\n - CPU hot-unplug detaches S with DETACH_GROUP, removing it from\n L-\u003esibling_list but leaving S-\u003egroup_leader == L.\n - L is later closed and freed.\n - A PERF_IOC_FLAG_GROUP ioctl on S follows S-\u003egroup_leader and\n dereferences the freed leader.\n\nThis was reproduced by running the perf event fuzzer, CPU hotplug, and a\nstress workload concurrently:\n\n Unable to handle kernel paging request at virtual address 006b6b6b6b6b6cdb\n CPU: 2 PID: 12489 Comm: perf_fuzzer 6.18.7 PREEMPT\n pc : perf_ioctl+0x34c/0xc68\n x20: ffffff89a3fa2c70 x8 : 6b6b6b6b6b6b6b6b\n Code: 943c4a0e 340047a0 f9404a94 f9411e88 (f940b908)\n Call trace:\n perf_ioctl+0x34c/0xc68 (P)\n __arm64_sys_ioctl+0xa0/0xf4\n invoke_syscall+0x58/0xe4\n el0_svc_common+0xa8/0xdc\n do_el0_svc+0x1c/0x28\n el0_svc+0x40/0xc0\n el0t_64_sync_handler+0x68/0xdc\n el0t_64_sync+0x1c4/0x1c8\n\nThe fault happened in perf_ioctl(), where perf_event_for_each() follows\nthe stale group_leader pointer and perf_event_for_each_child() then\ndereferences the freed leader\u0027s context.\n\nFix the use-after-free by promoting the detached sibling to a singleton.\nAlso fix __event_disable() cgroup accounting and event state change."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached only through local perf_event_open(2), ioctl(2) on perf fds (PERF_IOC_FLAG_GROUP), close(2), and execve(2); perf_ioctl() follows the stale group_leader into freed memory. There is no network, adjacent-wireless, or physical device entry path.\nAC:L - An attacker fully controls creation of leader/sibling groups, triggering sibling DETACH_GROUP via remove_on_exec or racing CPU hot-unplug against leader close, then issuing GROUP ioctls on the surviving sibling fd. The reproducer used perf_fuzzer with concurrent hotplug, and the attacker controls both sides of the lifecycle race.\nPR:L - A basic unprivileged local user can open per-task perf event groups on their own process with exclude_kernel=1 under the default sysctl_perf_event_paranoid=2, without CAP_PERFMON or init-namespace root. security_perf_event_open(PERF_SECURITY_OPEN) and perf_check_permission() allow this self-monitoring path.\nUI:N - Exploitation requires no action from another user or administrator beyond the attacker running their own syscalls (open group, exec or wait for hotplug, close leader, ioctl sibling). No victim must mount filesystems, open files, or interact with the system.\nS:U - Impact is confined to kernel perf/core heap corruption and privilege escalation within the same host kernel security authority. This is not a VM escape, IOMMU bypass, or cross-namespace boundary change; it is standard local kernel memory corruption.\nC:H - This is a use-after-free: perf_event_for_each() and perf_event_for_each_child() dereference a freed group leader and its context (repro showed 0x6b6b6b6b6b6b6b poisoned pointers). UAF on attacker-influenceable perf_event objects enables arbitrary kernel memory disclosure via controlled reallocations.\nI:H - Freed perf_event/group_leader structures can be reallocated with attacker-controlled data, providing heap grooming primitives for arbitrary kernel writes and control-flow hijack. Memory corruption from following stale group_leader pointers is exploitable beyond a simple crash.\nA:H - The fix commit documents a reproducible kernel paging fault in perf_ioctl() (\"Unable to handle kernel paging request\"). UAF dereferences reliably cause kernel oops/panic or hang, giving full denial of service and potential system-wide unavailability on affected hosts."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T12:39:51.869Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/8f867c0e8da4c2303d91adf45acb6b1820966c27"
},
{
"url": "https://git.kernel.org/stable/c/8e92e03984364d93e0d5b0acd81c95eca773f034"
},
{
"url": "https://git.kernel.org/stable/c/f8a07021679aadfb6d63b209207ccc41f26982d1"
},
{
"url": "https://git.kernel.org/stable/c/80c6054a4c40a0ffad82acef9f9a0dee108d152a"
},
{
"url": "https://git.kernel.org/stable/c/b42948f9e0d1ea4dbd5742ce1dfc7688de5d4a35"
},
{
"url": "https://git.kernel.org/stable/c/a979a642402d0b1f856c7a729b4cb2d92de4cf2f"
},
{
"url": "https://git.kernel.org/stable/c/1e7abfeb23c12bf46f6457e4a3e1a1a300d50619"
},
{
"url": "https://git.kernel.org/stable/c/42c5ca1f0a288a52878bd72a5595b08261057438"
}
],
"title": "perf/core: Fix group leader use-after-free after sibling detach",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74637",
"datePublished": "2026-08-22T15:32:16.755Z",
"dateReserved": "2026-08-15T05:44:03.922Z",
"dateUpdated": "2026-08-27T12:39:51.869Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80742 (GCVE-0-2026-80742)
Vulnerability from cvelistv5
Published
2026-09-03 08:26
Modified
2026-09-03 08:26
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
af_packet: Don't send zero-byte data in tpacket_snd().
syzbot reported a WARNING in __dev_queue_xmit() triggered via tpacket_snd():
skb_assert_len
WARNING: at include/linux/skbuff.h:2753 skb_assert_len
WARNING: at __dev_queue_xmit+0x21bc/0x4970 net/core/dev.c:4781
Call Trace:
<TASK>
dev_queue_xmit include/linux/netdevice.h:3448 [inline]
packet_xmit+0x243/0x310 net/packet/af_packet.c:276
tpacket_snd net/packet/af_packet.c:2907 [inline]
packet_sendmsg+0x28d6/0x4eb0 net/packet/af_packet.c:3134
When sending 0-byte packets via TPACKET ring buffer on devices with no
hard header (e.g. dev->hard_header_len == 0), tpacket_fill_skb()
populates an skb with skb->len == 0 and returns 0. tpacket_snd() then
forwards this empty skb to packet_xmit(), causing __dev_queue_xmit() to
hit skb_assert_len(skb).
Similar checks exist in packet_snd() via commit dc633700f00f
("net/af_packet: check len when min_header_len equals to 0") and in
packet_sendmsg_spkt() via commit 6a341729fb31 ("af_packet: Don't send
zero-byte data in packet_sendmsg_spkt().").
Return -EINVAL in tpacket_fill_skb() when skb->len is zero to reject
zero-length packets in tpacket_snd().
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/packet/af_packet.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "dde212f8622f5cb36223fff1ebd6e6f2a3dc61fe",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "80a702964467b998d254f16cc61c2c9a20540c9d",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "7521e691c7c4f2231634c95053281ac888d1f452",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "1fc70b3d513bafb16b17540178870ef46e81c0bb",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "3fa110f9e2ea96f567f2194c673c4bc327640111",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "98c5914d6b7bd4b4675535908e57dea31f1efd6a",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "f09ac5682f1bb67981fcb6ead4d3cfe439225876",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "6bcd76c134c55c697148acb5c0194e9666abdf84",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/packet/af_packet.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.46",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.10",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\naf_packet: Don\u0027t send zero-byte data in tpacket_snd().\n\nsyzbot reported a WARNING in __dev_queue_xmit() triggered via tpacket_snd():\n\nskb_assert_len\nWARNING: at include/linux/skbuff.h:2753 skb_assert_len\nWARNING: at __dev_queue_xmit+0x21bc/0x4970 net/core/dev.c:4781\n\nCall Trace:\n \u003cTASK\u003e\n dev_queue_xmit include/linux/netdevice.h:3448 [inline]\n packet_xmit+0x243/0x310 net/packet/af_packet.c:276\n tpacket_snd net/packet/af_packet.c:2907 [inline]\n packet_sendmsg+0x28d6/0x4eb0 net/packet/af_packet.c:3134\n\nWhen sending 0-byte packets via TPACKET ring buffer on devices with no\nhard header (e.g. dev-\u003ehard_header_len == 0), tpacket_fill_skb()\npopulates an skb with skb-\u003elen == 0 and returns 0. tpacket_snd() then\nforwards this empty skb to packet_xmit(), causing __dev_queue_xmit() to\nhit skb_assert_len(skb).\n\nSimilar checks exist in packet_snd() via commit dc633700f00f\n(\"net/af_packet: check len when min_header_len equals to 0\") and in\npacket_sendmsg_spkt() via commit 6a341729fb31 (\"af_packet: Don\u0027t send\nzero-byte data in packet_sendmsg_spkt().\").\n\nReturn -EINVAL in tpacket_fill_skb() when skb-\u003elen is zero to reject\nzero-length packets in tpacket_snd()."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-03T08:26:25.920Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/dde212f8622f5cb36223fff1ebd6e6f2a3dc61fe"
},
{
"url": "https://git.kernel.org/stable/c/80a702964467b998d254f16cc61c2c9a20540c9d"
},
{
"url": "https://git.kernel.org/stable/c/7521e691c7c4f2231634c95053281ac888d1f452"
},
{
"url": "https://git.kernel.org/stable/c/1fc70b3d513bafb16b17540178870ef46e81c0bb"
},
{
"url": "https://git.kernel.org/stable/c/3fa110f9e2ea96f567f2194c673c4bc327640111"
},
{
"url": "https://git.kernel.org/stable/c/98c5914d6b7bd4b4675535908e57dea31f1efd6a"
},
{
"url": "https://git.kernel.org/stable/c/f09ac5682f1bb67981fcb6ead4d3cfe439225876"
},
{
"url": "https://git.kernel.org/stable/c/6bcd76c134c55c697148acb5c0194e9666abdf84"
}
],
"title": "af_packet: Don\u0027t send zero-byte data in tpacket_snd().",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80742",
"datePublished": "2026-09-03T08:26:25.920Z",
"dateReserved": "2026-08-26T14:34:25.790Z",
"dateUpdated": "2026-09-03T08:26:25.920Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80827 (GCVE-0-2026-80827)
Vulnerability from cvelistv5
Published
2026-09-04 15:54
Modified
2026-09-04 15:54
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
USB: serial: option: fix slab OOB read in interrupt URB callback
The interrupt URB buffer is allocated in setup_port_interrupt_in() based
on the endpoint's wMaxPacketSize:
buffer_size = usb_endpoint_maxp(epd);
port->interrupt_in_buffer = kmalloc(buffer_size, GFP_KERNEL);
When a USB device declares wMaxPacketSize = 8 on its interrupt IN
endpoint, the buffer is allocated from kmalloc-8 cache (exactly
8 bytes).
If the device sends a short packet (actual_length < wMaxPacketSize),
the URB completes with status == 0 and the callback proceeds to read:
data[sizeof(struct usb_ctrlrequest)]
which evaluates to data[8], accessing 1 byte beyond the allocated 8-byte
buffer. This results in a slab out-of-bounds read.
Fix this by adding the missing bounds check: first verify that the
actual length is large enough to contain the struct usb_ctrlrequest
header before accessing req_pkt->bRequestType and req_pkt->bRequest,
and then verify that there is an additional byte for the modem signal
state before reading data[sizeof(struct usb_ctrlrequest)] inside the
conditional. Use sizeof(*req_pkt) instead of sizeof(struct
usb_ctrlrequest) for consistency.
[ johan: use dev_err(); split signals declaration and initialisation ]
References
| URL | Tags | ||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 58cfe9113e485f7e04bd0eac4fc4251b330af501 Version: 58cfe9113e485f7e04bd0eac4fc4251b330af501 Version: 58cfe9113e485f7e04bd0eac4fc4251b330af501 Version: 58cfe9113e485f7e04bd0eac4fc4251b330af501 Version: 58cfe9113e485f7e04bd0eac4fc4251b330af501 Version: 58cfe9113e485f7e04bd0eac4fc4251b330af501 Version: 58cfe9113e485f7e04bd0eac4fc4251b330af501 Version: 58cfe9113e485f7e04bd0eac4fc4251b330af501 Version: 58cfe9113e485f7e04bd0eac4fc4251b330af501 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/serial/option.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "fbe60fd2abc8a5561f39719a41ad9a01b5d8e567",
"status": "affected",
"version": "58cfe9113e485f7e04bd0eac4fc4251b330af501",
"versionType": "git"
},
{
"lessThan": "94e5525697b9e91ddc4071129874120a50a4f342",
"status": "affected",
"version": "58cfe9113e485f7e04bd0eac4fc4251b330af501",
"versionType": "git"
},
{
"lessThan": "6b8cf5422c7e96ed5b22a8368eff663f3f98b8ec",
"status": "affected",
"version": "58cfe9113e485f7e04bd0eac4fc4251b330af501",
"versionType": "git"
},
{
"lessThan": "030e3a73d3c3aa67c44454649e984d6383cdb7d3",
"status": "affected",
"version": "58cfe9113e485f7e04bd0eac4fc4251b330af501",
"versionType": "git"
},
{
"lessThan": "060db7d48af1e650643c8b8319111a9ea2ce4486",
"status": "affected",
"version": "58cfe9113e485f7e04bd0eac4fc4251b330af501",
"versionType": "git"
},
{
"lessThan": "2ef5560387f2c0713cee975be2b24b281bd90f3e",
"status": "affected",
"version": "58cfe9113e485f7e04bd0eac4fc4251b330af501",
"versionType": "git"
},
{
"lessThan": "a72a13c83a652516a0e469d275b81d29a7429049",
"status": "affected",
"version": "58cfe9113e485f7e04bd0eac4fc4251b330af501",
"versionType": "git"
},
{
"lessThan": "d762aef4eba354066be21a5d88eb2066e282f4c9",
"status": "affected",
"version": "58cfe9113e485f7e04bd0eac4fc4251b330af501",
"versionType": "git"
},
{
"lessThan": "885d802f544ca7bfa8f3984d94233cce715bb6b3",
"status": "affected",
"version": "58cfe9113e485f7e04bd0eac4fc4251b330af501",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/usb/serial/option.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.269",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.220",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.187",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.156",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.108",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.49",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.13",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.3",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.269",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.220",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.187",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.156",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.108",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.49",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.13",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.3",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: serial: option: fix slab OOB read in interrupt URB callback\n\nThe interrupt URB buffer is allocated in setup_port_interrupt_in() based\non the endpoint\u0027s wMaxPacketSize:\n\n buffer_size = usb_endpoint_maxp(epd);\n port-\u003einterrupt_in_buffer = kmalloc(buffer_size, GFP_KERNEL);\n\nWhen a USB device declares wMaxPacketSize = 8 on its interrupt IN\nendpoint, the buffer is allocated from kmalloc-8 cache (exactly\n8 bytes).\n\nIf the device sends a short packet (actual_length \u003c wMaxPacketSize),\nthe URB completes with status == 0 and the callback proceeds to read:\n\n data[sizeof(struct usb_ctrlrequest)]\n\nwhich evaluates to data[8], accessing 1 byte beyond the allocated 8-byte\nbuffer. This results in a slab out-of-bounds read.\n\nFix this by adding the missing bounds check: first verify that the\nactual length is large enough to contain the struct usb_ctrlrequest\nheader before accessing req_pkt-\u003ebRequestType and req_pkt-\u003ebRequest,\nand then verify that there is an additional byte for the modem signal\nstate before reading data[sizeof(struct usb_ctrlrequest)] inside the\nconditional. Use sizeof(*req_pkt) instead of sizeof(struct\nusb_ctrlrequest) for consistency.\n\n[ johan: use dev_err(); split signals declaration and initialisation ]"
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T15:54:31.111Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/fbe60fd2abc8a5561f39719a41ad9a01b5d8e567"
},
{
"url": "https://git.kernel.org/stable/c/94e5525697b9e91ddc4071129874120a50a4f342"
},
{
"url": "https://git.kernel.org/stable/c/6b8cf5422c7e96ed5b22a8368eff663f3f98b8ec"
},
{
"url": "https://git.kernel.org/stable/c/030e3a73d3c3aa67c44454649e984d6383cdb7d3"
},
{
"url": "https://git.kernel.org/stable/c/060db7d48af1e650643c8b8319111a9ea2ce4486"
},
{
"url": "https://git.kernel.org/stable/c/2ef5560387f2c0713cee975be2b24b281bd90f3e"
},
{
"url": "https://git.kernel.org/stable/c/a72a13c83a652516a0e469d275b81d29a7429049"
},
{
"url": "https://git.kernel.org/stable/c/d762aef4eba354066be21a5d88eb2066e282f4c9"
},
{
"url": "https://git.kernel.org/stable/c/885d802f544ca7bfa8f3984d94233cce715bb6b3"
}
],
"title": "USB: serial: option: fix slab OOB read in interrupt URB callback",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80827",
"datePublished": "2026-09-04T15:54:31.111Z",
"dateReserved": "2026-08-26T14:34:25.795Z",
"dateUpdated": "2026-09-04T15:54:31.111Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80910 (GCVE-0-2026-80910)
Vulnerability from cvelistv5
Published
2026-09-04 17:19
Modified
2026-09-04 17:19
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ASoC: codecs: lpass-wsa-macro: Fix enum kcontrol accesses
EAR SPKR PA Gain" and the four "WSA RX* Mux" controls are enumerated,
but their get and put callbacks access the value through
ucontrol->value.integer.value[0] (a long) instead of
ucontrol->value.enumerated.item[0] (an unsigned int).
This same pattern was fixed in the sibling drivers by
commit bcfe5f76cc40 ("ASoC: codecs: rx-macro: fix accessing array
out of bounds for enum type") and
commit 0ea5eff7c606 ("ASoC: codecs: va-macro: fix accessing array
out of bounds for enum type"), but wsa-macro was missed.
On 64-bit kernels with CONFIG_SND_CTL_DEBUG this trips the elem value
sanity check and every read of these controls fails with -EINVAL.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 809bcbcecebff86003e13f07444d21b9d6652a64 Version: 809bcbcecebff86003e13f07444d21b9d6652a64 Version: 809bcbcecebff86003e13f07444d21b9d6652a64 Version: 809bcbcecebff86003e13f07444d21b9d6652a64 Version: 809bcbcecebff86003e13f07444d21b9d6652a64 Version: 809bcbcecebff86003e13f07444d21b9d6652a64 Version: 809bcbcecebff86003e13f07444d21b9d6652a64 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"sound/soc/codecs/lpass-wsa-macro.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "bd4e5f9c3b764dc0e2a5662f92d63d2f3767a78d",
"status": "affected",
"version": "809bcbcecebff86003e13f07444d21b9d6652a64",
"versionType": "git"
},
{
"lessThan": "4bcac4bf304a3ec746192e49a669c236aaf27dbf",
"status": "affected",
"version": "809bcbcecebff86003e13f07444d21b9d6652a64",
"versionType": "git"
},
{
"lessThan": "891129df5de79cd533ae335c6eab24df2ff2b0fd",
"status": "affected",
"version": "809bcbcecebff86003e13f07444d21b9d6652a64",
"versionType": "git"
},
{
"lessThan": "524aa7b9954b0a43dd13f71ecbbac52a151c326d",
"status": "affected",
"version": "809bcbcecebff86003e13f07444d21b9d6652a64",
"versionType": "git"
},
{
"lessThan": "2fe7a89b2b5b73be35c1e493d0246314ba54e427",
"status": "affected",
"version": "809bcbcecebff86003e13f07444d21b9d6652a64",
"versionType": "git"
},
{
"lessThan": "7bcdde412e6c744f6135e02b12a735e2e37b639f",
"status": "affected",
"version": "809bcbcecebff86003e13f07444d21b9d6652a64",
"versionType": "git"
},
{
"lessThan": "56f24311fd5607588a47e44675195a9efb200f29",
"status": "affected",
"version": "809bcbcecebff86003e13f07444d21b9d6652a64",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"sound/soc/codecs/lpass-wsa-macro.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.11"
},
{
"lessThan": "5.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.46",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.10",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: codecs: lpass-wsa-macro: Fix enum kcontrol accesses\n\nEAR SPKR PA Gain\" and the four \"WSA RX* Mux\" controls are enumerated,\nbut their get and put callbacks access the value through\nucontrol-\u003evalue.integer.value[0] (a long) instead of\nucontrol-\u003evalue.enumerated.item[0] (an unsigned int).\n\nThis same pattern was fixed in the sibling drivers by\ncommit bcfe5f76cc40 (\"ASoC: codecs: rx-macro: fix accessing array\nout of bounds for enum type\") and\ncommit 0ea5eff7c606 (\"ASoC: codecs: va-macro: fix accessing array\nout of bounds for enum type\"), but wsa-macro was missed.\n\nOn 64-bit kernels with CONFIG_SND_CTL_DEBUG this trips the elem value\nsanity check and every read of these controls fails with -EINVAL."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T17:19:21.079Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/bd4e5f9c3b764dc0e2a5662f92d63d2f3767a78d"
},
{
"url": "https://git.kernel.org/stable/c/4bcac4bf304a3ec746192e49a669c236aaf27dbf"
},
{
"url": "https://git.kernel.org/stable/c/891129df5de79cd533ae335c6eab24df2ff2b0fd"
},
{
"url": "https://git.kernel.org/stable/c/524aa7b9954b0a43dd13f71ecbbac52a151c326d"
},
{
"url": "https://git.kernel.org/stable/c/2fe7a89b2b5b73be35c1e493d0246314ba54e427"
},
{
"url": "https://git.kernel.org/stable/c/7bcdde412e6c744f6135e02b12a735e2e37b639f"
},
{
"url": "https://git.kernel.org/stable/c/56f24311fd5607588a47e44675195a9efb200f29"
}
],
"title": "ASoC: codecs: lpass-wsa-macro: Fix enum kcontrol accesses",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80910",
"datePublished": "2026-09-04T17:19:21.079Z",
"dateReserved": "2026-08-26T14:34:25.801Z",
"dateUpdated": "2026-09-04T17:19:21.079Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80801 (GCVE-0-2026-80801)
Vulnerability from cvelistv5
Published
2026-09-04 15:13
Modified
2026-09-04 15:13
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
nfc: microread: validate target discovery payload lengths
microread_target_discovered() parses target discovery payloads from
skb->data according to the HCI gate. The fixed field offsets and UID
copies were checked only against the destination nfc_target buffers, not
against the actual skb length.
Validate that each gate-specific payload contains the fixed fields and
UID bytes before reading or copying them.
References
| URL | Tags | ||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: cfad1ba87150e198be9ea32367a24e500e59de2c Version: cfad1ba87150e198be9ea32367a24e500e59de2c Version: cfad1ba87150e198be9ea32367a24e500e59de2c Version: cfad1ba87150e198be9ea32367a24e500e59de2c Version: cfad1ba87150e198be9ea32367a24e500e59de2c Version: cfad1ba87150e198be9ea32367a24e500e59de2c Version: cfad1ba87150e198be9ea32367a24e500e59de2c Version: cfad1ba87150e198be9ea32367a24e500e59de2c Version: cfad1ba87150e198be9ea32367a24e500e59de2c |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/nfc/microread/microread.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c6de4241f2efbbab286efbb84a9c7190298b3052",
"status": "affected",
"version": "cfad1ba87150e198be9ea32367a24e500e59de2c",
"versionType": "git"
},
{
"lessThan": "92a6f0201bb68391b5eba1b3f330af007d7323b6",
"status": "affected",
"version": "cfad1ba87150e198be9ea32367a24e500e59de2c",
"versionType": "git"
},
{
"lessThan": "cb298672282421159e53ab311fe49d204c8a52da",
"status": "affected",
"version": "cfad1ba87150e198be9ea32367a24e500e59de2c",
"versionType": "git"
},
{
"lessThan": "18f02354ed229b8e4561b580812d026e7eb29c85",
"status": "affected",
"version": "cfad1ba87150e198be9ea32367a24e500e59de2c",
"versionType": "git"
},
{
"lessThan": "e6397fe7b8b5ef18e051f49612d40ff476c5f7d9",
"status": "affected",
"version": "cfad1ba87150e198be9ea32367a24e500e59de2c",
"versionType": "git"
},
{
"lessThan": "d0902a7c454326c6384c614226ab8987f3fd425d",
"status": "affected",
"version": "cfad1ba87150e198be9ea32367a24e500e59de2c",
"versionType": "git"
},
{
"lessThan": "dabfa26a208e56f4d8dbf26fddc48f188bdb0649",
"status": "affected",
"version": "cfad1ba87150e198be9ea32367a24e500e59de2c",
"versionType": "git"
},
{
"lessThan": "953963b9ac5eecbb316617d337bfaa3d731e3c5e",
"status": "affected",
"version": "cfad1ba87150e198be9ea32367a24e500e59de2c",
"versionType": "git"
},
{
"lessThan": "25519469972ef57c3edb1805dabd6c5612b90211",
"status": "affected",
"version": "cfad1ba87150e198be9ea32367a24e500e59de2c",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/nfc/microread/microread.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.9"
},
{
"lessThan": "3.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.267",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.218",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.185",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.154",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.106",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.47",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.1",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.267",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.218",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.185",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.154",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.106",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.47",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.11",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.1",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "3.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: microread: validate target discovery payload lengths\n\nmicroread_target_discovered() parses target discovery payloads from\nskb-\u003edata according to the HCI gate. The fixed field offsets and UID\ncopies were checked only against the destination nfc_target buffers, not\nagainst the actual skb length.\n\nValidate that each gate-specific payload contains the fixed fields and\nUID bytes before reading or copying them."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T15:13:15.263Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c6de4241f2efbbab286efbb84a9c7190298b3052"
},
{
"url": "https://git.kernel.org/stable/c/92a6f0201bb68391b5eba1b3f330af007d7323b6"
},
{
"url": "https://git.kernel.org/stable/c/cb298672282421159e53ab311fe49d204c8a52da"
},
{
"url": "https://git.kernel.org/stable/c/18f02354ed229b8e4561b580812d026e7eb29c85"
},
{
"url": "https://git.kernel.org/stable/c/e6397fe7b8b5ef18e051f49612d40ff476c5f7d9"
},
{
"url": "https://git.kernel.org/stable/c/d0902a7c454326c6384c614226ab8987f3fd425d"
},
{
"url": "https://git.kernel.org/stable/c/dabfa26a208e56f4d8dbf26fddc48f188bdb0649"
},
{
"url": "https://git.kernel.org/stable/c/953963b9ac5eecbb316617d337bfaa3d731e3c5e"
},
{
"url": "https://git.kernel.org/stable/c/25519469972ef57c3edb1805dabd6c5612b90211"
}
],
"title": "nfc: microread: validate target discovery payload lengths",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80801",
"datePublished": "2026-09-04T15:13:15.263Z",
"dateReserved": "2026-08-26T14:34:25.794Z",
"dateUpdated": "2026-09-04T15:13:15.263Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68361 (GCVE-0-2026-68361)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
hwmon: (corsair-psu) Stop device IO before calling hid_hw_stop
hid_hw_stop() does not stop the device IO.
This results in a race condition between hid_input_report() and the point
immediately following the execution of hid_device_io_start() within
corsairpsu_probe(). If the probe operation fails after "io start" has
been initiated, this race condition will result in a uaf vulnerability
[1].
CPU0 CPU1
==== ====
corsairpsu_probe()
hid_device_io_start()
... unlock driver_input_lock
hid_hw_stop()
kfree(hidraw) __hid_input_report()
... acquire driver_input_lock
hid_report_raw_event()
hidraw_report_event()
... access hidraw's list_lock // trigger uaf
Consequently, when corsairpsu_probe() fails and hid_hw_stop() needs to
be executed, the io_started flag is first cleared while holding the
driver_input_lock to prevent potential race conditions involving input
reports.
[1]
BUG: KASAN: slab-use-after-free in rt_spin_lock+0x83/0x400 kernel/locking/spinlock_rt.c:56
Call Trace:
hidraw_report_event+0x5d/0x3a0 drivers/hid/hidraw.c:577
hid_report_raw_event+0x311/0x1730 drivers/hid/hid-core.c:2076
__hid_input_report drivers/hid/hid-core.c:2152 [inline]
hid_input_report+0x44e/0x580 drivers/hid/hid-core.c:2174
hid_irq_in+0x47e/0x6d0 drivers/hid/usbhid/hid-core.c:286
__usb_hcd_giveback_urb+0x3b3/0x5e0 drivers/usb/core/hcd.c:1657
dummy_timer+0x8a9/0x47d0 drivers/usb/gadget/udc/dummy_hcd.c:2005
Allocated by task 10:
hidraw_connect+0x57/0x430 drivers/hid/hidraw.c:606
hid_connect+0x5bf/0x19d0 drivers/hid/hid-core.c:2277
hid_hw_start+0xa8/0x120 drivers/hid/hid-core.c:2387
corsairpsu_probe+0xd9/0x3c0 drivers/hwmon/corsair-psu.c:782
Freed by task 10:
hidraw_disconnect+0x4f/0x60 drivers/hid/hidraw.c:662
hid_disconnect drivers/hid/hid-core.c:2362 [inline]
hid_hw_stop+0x101/0x1e0 drivers/hid/hid-core.c:2407
corsairpsu_probe+0x327/0x3c0 drivers/hwmon/corsair-psu.c:826
Fix the problem by calling hid_device_io_stop() before calling
hid_hw_stop().
[groeck: Updated subject and description;
call hid_device_io_stop() only if IO has been started]
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d115b51e0e567199c821fc39e13b6af7e78f247d Version: d115b51e0e567199c821fc39e13b6af7e78f247d Version: d115b51e0e567199c821fc39e13b6af7e78f247d Version: d115b51e0e567199c821fc39e13b6af7e78f247d Version: d115b51e0e567199c821fc39e13b6af7e78f247d Version: d115b51e0e567199c821fc39e13b6af7e78f247d Version: d115b51e0e567199c821fc39e13b6af7e78f247d |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/hwmon/corsair-psu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "45dcd8a63069197f64dbda30509b9e224b74c0d8",
"status": "affected",
"version": "d115b51e0e567199c821fc39e13b6af7e78f247d",
"versionType": "git"
},
{
"lessThan": "c80ed058f31bb0251a748034d69feb376741dcb2",
"status": "affected",
"version": "d115b51e0e567199c821fc39e13b6af7e78f247d",
"versionType": "git"
},
{
"lessThan": "e6e1e0f3050d1a1a3ea1c9d6253363e87fdad67a",
"status": "affected",
"version": "d115b51e0e567199c821fc39e13b6af7e78f247d",
"versionType": "git"
},
{
"lessThan": "c0aae8d24f5e52d6910f97d59bc624e131f3ae1a",
"status": "affected",
"version": "d115b51e0e567199c821fc39e13b6af7e78f247d",
"versionType": "git"
},
{
"lessThan": "ec477af3a7e8d3964e62fd24ef01cdebb96b8e4e",
"status": "affected",
"version": "d115b51e0e567199c821fc39e13b6af7e78f247d",
"versionType": "git"
},
{
"lessThan": "bb25bd980f2d9bd34558e1b1d16636e4945baf14",
"status": "affected",
"version": "d115b51e0e567199c821fc39e13b6af7e78f247d",
"versionType": "git"
},
{
"lessThan": "9ab8656548cd737b98d0b19c4253aff8d68e97f4",
"status": "affected",
"version": "d115b51e0e567199c821fc39e13b6af7e78f247d",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/hwmon/corsair-psu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.11"
},
{
"lessThan": "5.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (corsair-psu) Stop device IO before calling hid_hw_stop\n\nhid_hw_stop() does not stop the device IO.\n\nThis results in a race condition between hid_input_report() and the point\nimmediately following the execution of hid_device_io_start() within\ncorsairpsu_probe(). If the probe operation fails after \"io start\" has\nbeen initiated, this race condition will result in a uaf vulnerability\n[1].\n\nCPU0\t\t\t\tCPU1\n====\t\t\t\t====\ncorsairpsu_probe()\n hid_device_io_start()\n ... unlock driver_input_lock\n hid_hw_stop()\n kfree(hidraw)\t\t\t__hid_input_report()\n\t\t\t\t ... acquire driver_input_lock\n\t\t\t\t hid_report_raw_event()\n\t\t\t\t hidraw_report_event()\n\t\t\t\t ... access hidraw\u0027s list_lock // trigger uaf\n\nConsequently, when corsairpsu_probe() fails and hid_hw_stop() needs to\nbe executed, the io_started flag is first cleared while holding the\ndriver_input_lock to prevent potential race conditions involving input\nreports.\n\n[1]\nBUG: KASAN: slab-use-after-free in rt_spin_lock+0x83/0x400 kernel/locking/spinlock_rt.c:56\nCall Trace:\n hidraw_report_event+0x5d/0x3a0 drivers/hid/hidraw.c:577\n hid_report_raw_event+0x311/0x1730 drivers/hid/hid-core.c:2076\n __hid_input_report drivers/hid/hid-core.c:2152 [inline]\n hid_input_report+0x44e/0x580 drivers/hid/hid-core.c:2174\n hid_irq_in+0x47e/0x6d0 drivers/hid/usbhid/hid-core.c:286\n __usb_hcd_giveback_urb+0x3b3/0x5e0 drivers/usb/core/hcd.c:1657\n dummy_timer+0x8a9/0x47d0 drivers/usb/gadget/udc/dummy_hcd.c:2005\n\nAllocated by task 10:\n hidraw_connect+0x57/0x430 drivers/hid/hidraw.c:606\n hid_connect+0x5bf/0x19d0 drivers/hid/hid-core.c:2277\n hid_hw_start+0xa8/0x120 drivers/hid/hid-core.c:2387\n corsairpsu_probe+0xd9/0x3c0 drivers/hwmon/corsair-psu.c:782\n\nFreed by task 10:\n hidraw_disconnect+0x4f/0x60 drivers/hid/hidraw.c:662\n hid_disconnect drivers/hid/hid-core.c:2362 [inline]\n hid_hw_stop+0x101/0x1e0 drivers/hid/hid-core.c:2407\n corsairpsu_probe+0x327/0x3c0 drivers/hwmon/corsair-psu.c:826\n\nFix the problem by calling hid_device_io_stop() before calling\nhid_hw_stop().\n\n[groeck: Updated subject and description;\n call hid_device_io_stop() only if IO has been started]"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:13.231Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/45dcd8a63069197f64dbda30509b9e224b74c0d8"
},
{
"url": "https://git.kernel.org/stable/c/c80ed058f31bb0251a748034d69feb376741dcb2"
},
{
"url": "https://git.kernel.org/stable/c/e6e1e0f3050d1a1a3ea1c9d6253363e87fdad67a"
},
{
"url": "https://git.kernel.org/stable/c/c0aae8d24f5e52d6910f97d59bc624e131f3ae1a"
},
{
"url": "https://git.kernel.org/stable/c/ec477af3a7e8d3964e62fd24ef01cdebb96b8e4e"
},
{
"url": "https://git.kernel.org/stable/c/bb25bd980f2d9bd34558e1b1d16636e4945baf14"
},
{
"url": "https://git.kernel.org/stable/c/9ab8656548cd737b98d0b19c4253aff8d68e97f4"
}
],
"title": "hwmon: (corsair-psu) Stop device IO before calling hid_hw_stop",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68361",
"datePublished": "2026-08-10T12:03:38.332Z",
"dateReserved": "2026-07-30T09:28:09.385Z",
"dateUpdated": "2026-08-19T16:34:13.231Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68248 (GCVE-0-2026-68248)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-19 16:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/i915: Return NULL on error in active_instance
Avoid returning &node->base when node is NULL due to OOM
during GFP_ATOMIC allocation.
Discovered using AI-assisted static analysis confirmed by
Intel Product Security.
(cherry picked from commit 6029bc064f0b1bac184203a50fbaaf070fa18832)
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: bfaae47db3c0989c0ca82a1d59ca3088860b1845 Version: bfaae47db3c0989c0ca82a1d59ca3088860b1845 Version: bfaae47db3c0989c0ca82a1d59ca3088860b1845 Version: bfaae47db3c0989c0ca82a1d59ca3088860b1845 Version: bfaae47db3c0989c0ca82a1d59ca3088860b1845 Version: bfaae47db3c0989c0ca82a1d59ca3088860b1845 Version: bfaae47db3c0989c0ca82a1d59ca3088860b1845 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/i915/i915_active.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a727a004d14580b2fc9bec9e1a9ea60a9016cfcf",
"status": "affected",
"version": "bfaae47db3c0989c0ca82a1d59ca3088860b1845",
"versionType": "git"
},
{
"lessThan": "2bc7c50ffca43e1824cf29738d0572f1eb21f261",
"status": "affected",
"version": "bfaae47db3c0989c0ca82a1d59ca3088860b1845",
"versionType": "git"
},
{
"lessThan": "32c1a2afa90dd07df931f0b12578de1dbb751f0c",
"status": "affected",
"version": "bfaae47db3c0989c0ca82a1d59ca3088860b1845",
"versionType": "git"
},
{
"lessThan": "b238d86e7f43afde8e830ef5b8d89ffedbbc7613",
"status": "affected",
"version": "bfaae47db3c0989c0ca82a1d59ca3088860b1845",
"versionType": "git"
},
{
"lessThan": "cbec6a57959ab503e3ad4ad6edd51efb585dce92",
"status": "affected",
"version": "bfaae47db3c0989c0ca82a1d59ca3088860b1845",
"versionType": "git"
},
{
"lessThan": "58b7e63ca0cd964190957ddd169c899256acaee9",
"status": "affected",
"version": "bfaae47db3c0989c0ca82a1d59ca3088860b1845",
"versionType": "git"
},
{
"lessThan": "1e33f0de5fdcd09e51fdec1e5822448970b6420f",
"status": "affected",
"version": "bfaae47db3c0989c0ca82a1d59ca3088860b1845",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/i915/i915_active.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.13"
},
{
"lessThan": "5.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/i915: Return NULL on error in active_instance\n\nAvoid returning \u0026node-\u003ebase when node is NULL due to OOM\nduring GFP_ATOMIC allocation.\n\nDiscovered using AI-assisted static analysis confirmed by\nIntel Product Security.\n\n(cherry picked from commit 6029bc064f0b1bac184203a50fbaaf070fa18832)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:32:15.977Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a727a004d14580b2fc9bec9e1a9ea60a9016cfcf"
},
{
"url": "https://git.kernel.org/stable/c/2bc7c50ffca43e1824cf29738d0572f1eb21f261"
},
{
"url": "https://git.kernel.org/stable/c/32c1a2afa90dd07df931f0b12578de1dbb751f0c"
},
{
"url": "https://git.kernel.org/stable/c/b238d86e7f43afde8e830ef5b8d89ffedbbc7613"
},
{
"url": "https://git.kernel.org/stable/c/cbec6a57959ab503e3ad4ad6edd51efb585dce92"
},
{
"url": "https://git.kernel.org/stable/c/58b7e63ca0cd964190957ddd169c899256acaee9"
},
{
"url": "https://git.kernel.org/stable/c/1e33f0de5fdcd09e51fdec1e5822448970b6420f"
}
],
"title": "drm/i915: Return NULL on error in active_instance",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68248",
"datePublished": "2026-08-10T12:01:14.485Z",
"dateReserved": "2026-07-30T09:28:09.377Z",
"dateUpdated": "2026-08-19T16:32:15.977Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72252 (GCVE-0-2026-72252)
Vulnerability from cvelistv5
Published
2026-08-15 05:54
Modified
2026-08-23 12:47
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nft_set_pipapo: don't leak bad clone into future transaction
On memory allocation failure the cloned nft_pipapo_match can enter a bad
state:
- some fields can have their lookup tables resized while others did
not
- bits might have been toggled
- scratch map can be undersized which also means m->bsize_max can be
lower than what is required
This means that the next insertion in the same batch can trigger
out-of-bounds writes.
Furthermore, a failure in the first can result in the bad clone to
leak into the next transaction because the abort callback is never
executed in this case (the upper layer saw an error and no attempt to
allocate a transactional request was made).
Record a state for the nft_pipapo_match structure:
- NEW (pristine clone)
- MOD (modified clone with good state)
- ERR (potentially bogus content)
Then make it so that deletes and insertions fail when the clone
entered ERR state.
In case the very first insert attempt results in an error, free the
clone right away.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 3c4287f62044a90e73a561aa05fc46e62da173da Version: 3c4287f62044a90e73a561aa05fc46e62da173da Version: 3c4287f62044a90e73a561aa05fc46e62da173da Version: 3c4287f62044a90e73a561aa05fc46e62da173da Version: 3c4287f62044a90e73a561aa05fc46e62da173da Version: 3c4287f62044a90e73a561aa05fc46e62da173da Version: 3c4287f62044a90e73a561aa05fc46e62da173da |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/netfilter/nft_set_pipapo.c",
"net/netfilter/nft_set_pipapo.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "0ab7b1802f63ca5b288ea59acb467830b83abd6b",
"status": "affected",
"version": "3c4287f62044a90e73a561aa05fc46e62da173da",
"versionType": "git"
},
{
"lessThan": "cc53703f48558896295f565cd4f5e956d21b7af4",
"status": "affected",
"version": "3c4287f62044a90e73a561aa05fc46e62da173da",
"versionType": "git"
},
{
"lessThan": "047e813324eac2ac60cddfb58bcdbd0144eadb09",
"status": "affected",
"version": "3c4287f62044a90e73a561aa05fc46e62da173da",
"versionType": "git"
},
{
"lessThan": "610e3b73efaec3dd81a95dcda2421ad7d9795bd0",
"status": "affected",
"version": "3c4287f62044a90e73a561aa05fc46e62da173da",
"versionType": "git"
},
{
"lessThan": "02b6b0e892aea582590671796fd6eff5b93ea93f",
"status": "affected",
"version": "3c4287f62044a90e73a561aa05fc46e62da173da",
"versionType": "git"
},
{
"lessThan": "e74f9680e1b64872a51cc7b5bda1edaaa08aa51f",
"status": "affected",
"version": "3c4287f62044a90e73a561aa05fc46e62da173da",
"versionType": "git"
},
{
"lessThan": "47e65eff50691f0a5b79d325e28d83ec1da43bcf",
"status": "affected",
"version": "3c4287f62044a90e73a561aa05fc46e62da173da",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/netfilter/nft_set_pipapo.c",
"net/netfilter/nft_set_pipapo.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.6"
},
{
"lessThan": "5.6",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_set_pipapo: don\u0027t leak bad clone into future transaction\n\nOn memory allocation failure the cloned nft_pipapo_match can enter a bad\nstate:\n - some fields can have their lookup tables resized while others did\n not\n - bits might have been toggled\n - scratch map can be undersized which also means m-\u003ebsize_max can be\n lower than what is required\n\nThis means that the next insertion in the same batch can trigger\nout-of-bounds writes.\n\nFurthermore, a failure in the first can result in the bad clone to\nleak into the next transaction because the abort callback is never\nexecuted in this case (the upper layer saw an error and no attempt to\nallocate a transactional request was made).\n\nRecord a state for the nft_pipapo_match structure:\n- NEW (pristine clone)\n- MOD (modified clone with good state)\n- ERR (potentially bogus content)\n\nThen make it so that deletes and insertions fail when the clone\nentered ERR state.\n\nIn case the very first insert attempt results in an error, free the\nclone right away."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached only via the nf_tables netlink control path (NFT_MSG_NEWSETELEM into nft_pipapo_insert); it is not triggered by remote packet handling, so attack vector is Local per kernel nftables guidance.\nAC:L - An attacker can reliably induce the needed allocation failure by crafting wide pipapo interval elements and constraining memory (e.g., memcg limits), then retrying until a partial insert leaves a corrupted clone that the next add reuses.\nPR:L - All nf_tables netlink operations require CAP_NET_ADMIN; on systems with unprivileged user namespaces this capability is obtainable by a normal local user via unshare -Urn, so privileges required are Low rather than High.\nUI:N - Exploitation requires only attacker-controlled nftables set element insertions and does not depend on any victim user action such as opening files or mounting filesystems.\nS:U - Impact is kernel heap corruption and potential privilege escalation within the same kernel security domain; it does not inherently cross VM, IOMMU, or other sandbox boundaries without separate exploitation.\nC:H - A partially updated pipapo clone leaves inconsistent lookup/mapping tables and undersized scratch buffers; subsequent inserts or lookups can perform out-of-bounds heap access that is exploitable for arbitrary kernel memory disclosure.\nI:H - The fix commit explicitly states the corrupted clone can cause out-of-bounds writes on the next insertion, enabling heap corruption that can be leveraged for arbitrary kernel writes and local privilege escalation.\nA:H - Out-of-bounds writes into kernel heap structures commonly cause kernel oops/panic or persistent instability; memory corruption from this bug can crash the system even when full exploitation is not attempted."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:47:06.920Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/0ab7b1802f63ca5b288ea59acb467830b83abd6b"
},
{
"url": "https://git.kernel.org/stable/c/cc53703f48558896295f565cd4f5e956d21b7af4"
},
{
"url": "https://git.kernel.org/stable/c/047e813324eac2ac60cddfb58bcdbd0144eadb09"
},
{
"url": "https://git.kernel.org/stable/c/610e3b73efaec3dd81a95dcda2421ad7d9795bd0"
},
{
"url": "https://git.kernel.org/stable/c/02b6b0e892aea582590671796fd6eff5b93ea93f"
},
{
"url": "https://git.kernel.org/stable/c/e74f9680e1b64872a51cc7b5bda1edaaa08aa51f"
},
{
"url": "https://git.kernel.org/stable/c/47e65eff50691f0a5b79d325e28d83ec1da43bcf"
}
],
"title": "netfilter: nft_set_pipapo: don\u0027t leak bad clone into future transaction",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72252",
"datePublished": "2026-08-15T05:54:40.740Z",
"dateReserved": "2026-08-09T03:40:39.915Z",
"dateUpdated": "2026-08-23T12:47:06.920Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74443 (GCVE-0-2026-74443)
Vulnerability from cvelistv5
Published
2026-08-15 12:26
Modified
2026-08-19 16:36
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/vmwgfx: bound DMA command body size against suffix pointer
vmw_cmd_dma() locates the DMA suffix at
(unsigned long) &cmd->body + header->size - sizeof(*suffix)
without checking that header->size is large enough to contain both
cmd->body and the suffix. An undersized header makes the suffix
pointer underflow back into the previous command in the bounce
buffer. The verifier later writes suffix->maximumOffset, clobbering
verified fields of an already-relocated earlier command -- a TOCTOU
on the device-visible command stream that lets one command rewrite
another's GMR id, surface id, or other authenticated fields.
Reject the command if the body is too small for the suffix to fit.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 4e4ddd47774313accc86b233d6ca2c6a9037a671 Version: 4e4ddd47774313accc86b233d6ca2c6a9037a671 Version: 4e4ddd47774313accc86b233d6ca2c6a9037a671 Version: 4e4ddd47774313accc86b233d6ca2c6a9037a671 Version: 4e4ddd47774313accc86b233d6ca2c6a9037a671 Version: 4e4ddd47774313accc86b233d6ca2c6a9037a671 Version: 4e4ddd47774313accc86b233d6ca2c6a9037a671 Version: 4e4ddd47774313accc86b233d6ca2c6a9037a671 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/vmwgfx/vmwgfx_execbuf.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "eb20f418933bea53375843b27b4022c1810be63b",
"status": "affected",
"version": "4e4ddd47774313accc86b233d6ca2c6a9037a671",
"versionType": "git"
},
{
"lessThan": "fcd1e56e7816b31a1050ccc67df722b20f6bb15d",
"status": "affected",
"version": "4e4ddd47774313accc86b233d6ca2c6a9037a671",
"versionType": "git"
},
{
"lessThan": "a4a37080a5ac777b59306cfcdf854cc05d7604d4",
"status": "affected",
"version": "4e4ddd47774313accc86b233d6ca2c6a9037a671",
"versionType": "git"
},
{
"lessThan": "036e16ada95389bdc30f41068af04c1d0872fad0",
"status": "affected",
"version": "4e4ddd47774313accc86b233d6ca2c6a9037a671",
"versionType": "git"
},
{
"lessThan": "d5d7ada4e1296b00d89fe82b2ca850cc7809d6f7",
"status": "affected",
"version": "4e4ddd47774313accc86b233d6ca2c6a9037a671",
"versionType": "git"
},
{
"lessThan": "7e40e6120fb232a10b543ffd994e5c6d8f3a2cc6",
"status": "affected",
"version": "4e4ddd47774313accc86b233d6ca2c6a9037a671",
"versionType": "git"
},
{
"lessThan": "9759da60e38d7b9db44dc92713e4e0391883d221",
"status": "affected",
"version": "4e4ddd47774313accc86b233d6ca2c6a9037a671",
"versionType": "git"
},
{
"lessThan": "f4f1db96bfd68b81053693ba53405b6f510ac16c",
"status": "affected",
"version": "4e4ddd47774313accc86b233d6ca2c6a9037a671",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/vmwgfx/vmwgfx_execbuf.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.33"
},
{
"lessThan": "2.6.33",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.33",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.33",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.33",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "2.6.33",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "2.6.33",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "2.6.33",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "2.6.33",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.33",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vmwgfx: bound DMA command body size against suffix pointer\n\nvmw_cmd_dma() locates the DMA suffix at\n\n\t(unsigned long) \u0026cmd-\u003ebody + header-\u003esize - sizeof(*suffix)\n\nwithout checking that header-\u003esize is large enough to contain both\ncmd-\u003ebody and the suffix. An undersized header makes the suffix\npointer underflow back into the previous command in the bounce\nbuffer. The verifier later writes suffix-\u003emaximumOffset, clobbering\nverified fields of an already-relocated earlier command -- a TOCTOU\non the device-visible command stream that lets one command rewrite\nanother\u0027s GMR id, surface id, or other authenticated fields.\n\nReject the command if the body is too small for the suffix to fit."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires issuing DRM_IOCTL_VMW_EXECBUF with a crafted SVGA command batch via /dev/dri/card* or /dev/dri/renderD*, the standard local DRM render-node path for the vmwgfx driver in VMware virtual machines.\nAC:L - The attacker fully controls execbuf command layout and can set an undersized SVGA_3D_CMD_SURFACE_DMA header-\u003esize so the suffix pointer underflows into the prior command; no races, rare configs, or victim-dependent heap layout are required.\nPR:L - VMW_EXECBUF is registered with DRM_RENDER_ALLOW, so any local user with access to the DRM render node (typically membership in the render/video group on VMware guests) can reach vmw_cmd_dma without real root in the init namespace.\nUI:N - No victim interaction is required beyond the attacker opening the DRM device and submitting a malicious execbuf ioctl; exploitation does not depend on another user mounting filesystems or performing other actions.\nS:C - The bug is a TOCTOU on the device-visible SVGA command stream: verifier writes clobber already-checked fields (GMR id, surface id, DMA bounds) in the bounce buffer before submission to the VMware virtual GPU, bypassing guest/host isolation enforced by command authentication.\nC:H - Rewriting authenticated GMR/surface identifiers or inflating maximumOffset can authorize SVGA surface DMA reads (including SVGA3D_READ_HOST_VRAM) beyond validated guest buffer bounds, yielding arbitrary guest memory disclosure and plausible host VRAM reads via the virtual device backend.\nI:H - Clobbering verified command fields lets a later command rewrite another\u0027s GMR id, surface id, or DMA limit so the hypervisor executes unauthorized SVGA3D_WRITE_HOST_VRAM or guest GMR DMA, enabling arbitrary memory write and code-execution primitives typical of kernel heap corruption.\nA:H - Corrupting the bounce-buffer command stream before FIFO submission can panic the guest kernel (invalid SVGA commands/resources) and enables repeatable denial of service; memory corruption in the verifier path is independently rated High per kernel CVSS guidance."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:36:35.874Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/eb20f418933bea53375843b27b4022c1810be63b"
},
{
"url": "https://git.kernel.org/stable/c/fcd1e56e7816b31a1050ccc67df722b20f6bb15d"
},
{
"url": "https://git.kernel.org/stable/c/a4a37080a5ac777b59306cfcdf854cc05d7604d4"
},
{
"url": "https://git.kernel.org/stable/c/036e16ada95389bdc30f41068af04c1d0872fad0"
},
{
"url": "https://git.kernel.org/stable/c/d5d7ada4e1296b00d89fe82b2ca850cc7809d6f7"
},
{
"url": "https://git.kernel.org/stable/c/7e40e6120fb232a10b543ffd994e5c6d8f3a2cc6"
},
{
"url": "https://git.kernel.org/stable/c/9759da60e38d7b9db44dc92713e4e0391883d221"
},
{
"url": "https://git.kernel.org/stable/c/f4f1db96bfd68b81053693ba53405b6f510ac16c"
}
],
"title": "drm/vmwgfx: bound DMA command body size against suffix pointer",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74443",
"datePublished": "2026-08-15T12:26:50.826Z",
"dateReserved": "2026-08-15T05:44:03.898Z",
"dateUpdated": "2026-08-19T16:36:35.874Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68159 (GCVE-0-2026-68159)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE
__decode_pg_temp() decodes an user-controlled length but only rejects
values large enough to overflow the allocation; it does not bound it to
CEPH_PG_MAX_SIZE. The helper backs both pg_temp and pg_upmap decoding, and
apply_upmap()/get_temp_osds() later copy the decoded list into the fixed-size
on-stack array struct ceph_osds.osds[CEPH_PG_MAX_SIZE]. A monitor that sends
an OSDMap with a pg_temp/pg_upmap entry longer than 32 thus causes a stack
out-of-bounds write.
An OSD set for a single PG can never exceed CEPH_PG_MAX_SIZE, so reject longer
entries at decode time. The bound is well below the old overflow threshold, so
it also covers the allocation-size overflow the previous check guarded against.
BUG: KASAN: stack-out-of-bounds in ceph_pg_to_up_acting_osds
Write of size 4 ... by task exploit
kasan_report (mm/kasan/report.c:595)
ceph_pg_to_up_acting_osds (net/ceph/osdmap.c:2617 net/ceph/osdmap.c:2833)
calc_target (net/ceph/osd_client.c:1638)
__submit_request (net/ceph/osd_client.c:2394)
ceph_osdc_start_request (net/ceph/osd_client.c:2490)
ceph_osdc_call (net/ceph/osd_client.c:5164)
rbd_dev_image_probe (drivers/block/rbd.c:6899)
do_rbd_add (drivers/block/rbd.c:7138)
...
kernel BUG at net/ceph/osdmap.c:2670!
[ idryomov: do the same in __decode_pg_upmap_items() ]
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: a303bb0e58345fe9f7ab2f82b90266f2b5036058 Version: a303bb0e58345fe9f7ab2f82b90266f2b5036058 Version: a303bb0e58345fe9f7ab2f82b90266f2b5036058 Version: a303bb0e58345fe9f7ab2f82b90266f2b5036058 Version: a303bb0e58345fe9f7ab2f82b90266f2b5036058 Version: a303bb0e58345fe9f7ab2f82b90266f2b5036058 Version: a303bb0e58345fe9f7ab2f82b90266f2b5036058 Version: a303bb0e58345fe9f7ab2f82b90266f2b5036058 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ceph/osdmap.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "66eec4af1e080b695229c9a20635648a6d12fedf",
"status": "affected",
"version": "a303bb0e58345fe9f7ab2f82b90266f2b5036058",
"versionType": "git"
},
{
"lessThan": "4daf06456677177f2a6044729abac59c1b49e87b",
"status": "affected",
"version": "a303bb0e58345fe9f7ab2f82b90266f2b5036058",
"versionType": "git"
},
{
"lessThan": "d5650ddbd4d42c1a916c8fe1a4c4cb573ef810a1",
"status": "affected",
"version": "a303bb0e58345fe9f7ab2f82b90266f2b5036058",
"versionType": "git"
},
{
"lessThan": "42bc06c67d94d5f2a6b33294b0c4b07d8a47c515",
"status": "affected",
"version": "a303bb0e58345fe9f7ab2f82b90266f2b5036058",
"versionType": "git"
},
{
"lessThan": "ebdf4b4f3b1474079980a2e5cd79ad65fb54db57",
"status": "affected",
"version": "a303bb0e58345fe9f7ab2f82b90266f2b5036058",
"versionType": "git"
},
{
"lessThan": "590b07ceea138d49c9b64f65d263aa902d3b4730",
"status": "affected",
"version": "a303bb0e58345fe9f7ab2f82b90266f2b5036058",
"versionType": "git"
},
{
"lessThan": "e36663145abd7024f0281dfb22fdef65f185845b",
"status": "affected",
"version": "a303bb0e58345fe9f7ab2f82b90266f2b5036058",
"versionType": "git"
},
{
"lessThan": "9f00f9cf2be293efe899db67dc5272e3a9c62717",
"status": "affected",
"version": "a303bb0e58345fe9f7ab2f82b90266f2b5036058",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ceph/osdmap.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.13"
},
{
"lessThan": "4.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.46",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE\n\n__decode_pg_temp() decodes an user-controlled length but only rejects\nvalues large enough to overflow the allocation; it does not bound it to\nCEPH_PG_MAX_SIZE. The helper backs both pg_temp and pg_upmap decoding, and\napply_upmap()/get_temp_osds() later copy the decoded list into the fixed-size\non-stack array struct ceph_osds.osds[CEPH_PG_MAX_SIZE]. A monitor that sends\nan OSDMap with a pg_temp/pg_upmap entry longer than 32 thus causes a stack\nout-of-bounds write.\n\nAn OSD set for a single PG can never exceed CEPH_PG_MAX_SIZE, so reject longer\nentries at decode time. The bound is well below the old overflow threshold, so\nit also covers the allocation-size overflow the previous check guarded against.\n\n BUG: KASAN: stack-out-of-bounds in ceph_pg_to_up_acting_osds\n Write of size 4 ... by task exploit\n kasan_report (mm/kasan/report.c:595)\n ceph_pg_to_up_acting_osds (net/ceph/osdmap.c:2617 net/ceph/osdmap.c:2833)\n calc_target (net/ceph/osd_client.c:1638)\n __submit_request (net/ceph/osd_client.c:2394)\n ceph_osdc_start_request (net/ceph/osd_client.c:2490)\n ceph_osdc_call (net/ceph/osd_client.c:5164)\n rbd_dev_image_probe (drivers/block/rbd.c:6899)\n do_rbd_add (drivers/block/rbd.c:7138)\n ...\n kernel BUG at net/ceph/osdmap.c:2670!\n\n[ idryomov: do the same in __decode_pg_upmap_items() ]"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - Malicious pg_temp/pg_upmap data arrives in CEPH_MSG_OSD_MAP from a Ceph monitor or OSD over TCP, is decoded in libceph, and later triggers stack corruption in ceph_pg_to_up_acting_osds during RBD/CephFS/libceph client I/O.\nAC:L - A compromised or attacker-controlled monitor can publish osdmap entries with length \u003e32 for chosen PGs; once the client subscribes, kernel I/O paths such as RBD mount/probe via calc_target deterministically invoke apply_upmap/get_temp_osds and overflow the stack buffer.\nPR:N - Exploitation requires no privileges on the victim host; any machine acting as a Ceph client that receives a forged osdmap from a cluster peer over the network can be attacked without local user capabilities or namespace tricks.\nUI:N - No victim user action is needed during exploitation beyond the host already being a Ceph client; forged osdmaps are applied automatically and the overflow fires on subsequent kernel client operations without interactive steps.\nS:U - Impact is confined to kernel memory on the Ceph client host (privilege escalation or crash); it does not cross VM, IOMMU, or sandbox boundaries to other security authorities.\nC:H - KASAN-confirmed stack out-of-bounds write in ceph_pg_to_up_acting_osds corrupts adjacent stack memory and can be leveraged for arbitrary kernel memory disclosure, not merely a bounded leak.\nI:H - Unbounded copy loops in apply_upmap() and get_temp_osds() write attacker-controlled u32 OSD IDs past the fixed osds[CEPH_PG_MAX_SIZE] stack array, enabling control-flow hijack and arbitrary kernel writes.\nA:H - The reported reproducer triggers KASAN stack-out-of-bounds followed by kernel BUG in ceph_pg_to_up_acting_osds, demonstrating a reliable kernel oops or panic from malformed osdmap processing on Ceph clients."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:00.131Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/66eec4af1e080b695229c9a20635648a6d12fedf"
},
{
"url": "https://git.kernel.org/stable/c/4daf06456677177f2a6044729abac59c1b49e87b"
},
{
"url": "https://git.kernel.org/stable/c/d5650ddbd4d42c1a916c8fe1a4c4cb573ef810a1"
},
{
"url": "https://git.kernel.org/stable/c/42bc06c67d94d5f2a6b33294b0c4b07d8a47c515"
},
{
"url": "https://git.kernel.org/stable/c/ebdf4b4f3b1474079980a2e5cd79ad65fb54db57"
},
{
"url": "https://git.kernel.org/stable/c/590b07ceea138d49c9b64f65d263aa902d3b4730"
},
{
"url": "https://git.kernel.org/stable/c/e36663145abd7024f0281dfb22fdef65f185845b"
},
{
"url": "https://git.kernel.org/stable/c/9f00f9cf2be293efe899db67dc5272e3a9c62717"
}
],
"title": "libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68159",
"datePublished": "2026-08-10T11:59:25.697Z",
"dateReserved": "2026-07-30T09:28:09.371Z",
"dateUpdated": "2026-08-23T12:46:00.131Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74720 (GCVE-0-2026-74720)
Vulnerability from cvelistv5
Published
2026-08-22 15:33
Modified
2026-08-25 05:42
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
bpf: Preserve pointer state for commuted arithmetic
When scalar += pointer is handled in adjust_ptr_min_max_vals(), the
destination register inherits the pointer state from the source pointer.
Copying only selected fields is fragile because pointer provenance is
tracked by several bpf_reg_state fields.
Use the caller's temporary offset register to preserve the scalar operand
while replacing the destination with the full pointer state. This preserves
the frame number for PTR_TO_STACK registers and keeps parent identity
fields consistent.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: f4d7e40a5b7157e1329c3c5b10f60d8289fc2941 Version: f4d7e40a5b7157e1329c3c5b10f60d8289fc2941 Version: f4d7e40a5b7157e1329c3c5b10f60d8289fc2941 Version: f4d7e40a5b7157e1329c3c5b10f60d8289fc2941 Version: f4d7e40a5b7157e1329c3c5b10f60d8289fc2941 Version: f4d7e40a5b7157e1329c3c5b10f60d8289fc2941 Version: f4d7e40a5b7157e1329c3c5b10f60d8289fc2941 Version: f4d7e40a5b7157e1329c3c5b10f60d8289fc2941 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"kernel/bpf/verifier.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "86b203aadc2930e0a4f9c6277b5b80ff3664c472",
"status": "affected",
"version": "f4d7e40a5b7157e1329c3c5b10f60d8289fc2941",
"versionType": "git"
},
{
"lessThan": "8109c25e0c41f5f19a1c2380bb49c991a877494e",
"status": "affected",
"version": "f4d7e40a5b7157e1329c3c5b10f60d8289fc2941",
"versionType": "git"
},
{
"lessThan": "d1959028190a7649b926f5867a58de5fe221b23c",
"status": "affected",
"version": "f4d7e40a5b7157e1329c3c5b10f60d8289fc2941",
"versionType": "git"
},
{
"lessThan": "8cb23101a3fcc7432b451ea3d0f14a90711f4acf",
"status": "affected",
"version": "f4d7e40a5b7157e1329c3c5b10f60d8289fc2941",
"versionType": "git"
},
{
"lessThan": "29c239f8dbec5ab33a61796724d189bddee6cd4b",
"status": "affected",
"version": "f4d7e40a5b7157e1329c3c5b10f60d8289fc2941",
"versionType": "git"
},
{
"lessThan": "db6382ed3361bdd8129572a3423956cba1dae829",
"status": "affected",
"version": "f4d7e40a5b7157e1329c3c5b10f60d8289fc2941",
"versionType": "git"
},
{
"lessThan": "eaffa1495e4fe6330aeff9f323ea3d48b01f118a",
"status": "affected",
"version": "f4d7e40a5b7157e1329c3c5b10f60d8289fc2941",
"versionType": "git"
},
{
"lessThan": "a4c6f804b44c5c790269b25e0e61cf4e9f117c86",
"status": "affected",
"version": "f4d7e40a5b7157e1329c3c5b10f60d8289fc2941",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"kernel/bpf/verifier.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.16"
},
{
"lessThan": "4.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "4.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "4.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "4.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "4.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.16",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Preserve pointer state for commuted arithmetic\n\nWhen scalar += pointer is handled in adjust_ptr_min_max_vals(), the\ndestination register inherits the pointer state from the source pointer.\nCopying only selected fields is fragile because pointer provenance is\ntracked by several bpf_reg_state fields.\n\nUse the caller\u0027s temporary offset register to preserve the scalar operand\nwhile replacing the destination with the full pointer state. This preserves\nthe frame number for PTR_TO_STACK registers and keeps parent identity\nfields consistent."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The flaw is in bpf_check()/adjust_ptr_min_max_vals() during bpf(BPF_PROG_LOAD) via the local bpf(2) syscall; per kernel CNA guidance BPF verifier bugs are Local, not reachable from remote network packet handling.\nAC:L - An attacker fully controls BPF bytecode using commuted 64-bit scalar+=pointer ALU and bpf2bpf call chains, deterministically poisoning register state during verification without races or external preconditions.\nPR:L - Exploitation requires loading bpf2bpf programs (CAP_BPF-gated), which is routinely available to unprivileged users via user namespaces/BPF token delegation or unprivileged socket-filter loading when kernel.unprivileged_bpf_disabled=0, not init-namespace root.\nUI:N - The attacker loads and executes their own crafted BPF program through bpf(2); no separate victim action such as mounting filesystems or opening files is required beyond the attacker\u0027s own local access.\nS:U - Impact is a BPF verifier bypass enabling in-kernel out-of-bounds memory access and privilege escalation within the host kernel\u0027s security authority; it does not cross VM, IOMMU, or sandbox boundaries.\nC:H - Copying only type/id on scalar+=pointer leaves stale frameno, var_off, and map/parent metadata, so bpf_func() stack checks validate the wrong frame and approve out-of-bounds reads of adjacent kernel memory.\nI:H - The same incorrect pointer provenance permits verifier-approved out-of-bounds BPF stack/map writes at runtime, a controllable kernel memory corruption primitive leverageable for arbitrary modification and privilege escalation.\nA:H - Out-of-bounds BPF memory accesses from the bypassed verifier state can corrupt critical kernel data or dereference invalid addresses, reliably causing kernel oops/panic and repeatable denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:42:01.009Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/86b203aadc2930e0a4f9c6277b5b80ff3664c472"
},
{
"url": "https://git.kernel.org/stable/c/8109c25e0c41f5f19a1c2380bb49c991a877494e"
},
{
"url": "https://git.kernel.org/stable/c/d1959028190a7649b926f5867a58de5fe221b23c"
},
{
"url": "https://git.kernel.org/stable/c/8cb23101a3fcc7432b451ea3d0f14a90711f4acf"
},
{
"url": "https://git.kernel.org/stable/c/29c239f8dbec5ab33a61796724d189bddee6cd4b"
},
{
"url": "https://git.kernel.org/stable/c/db6382ed3361bdd8129572a3423956cba1dae829"
},
{
"url": "https://git.kernel.org/stable/c/eaffa1495e4fe6330aeff9f323ea3d48b01f118a"
},
{
"url": "https://git.kernel.org/stable/c/a4c6f804b44c5c790269b25e0e61cf4e9f117c86"
}
],
"title": "bpf: Preserve pointer state for commuted arithmetic",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74720",
"datePublished": "2026-08-22T15:33:13.342Z",
"dateReserved": "2026-08-15T05:44:03.929Z",
"dateUpdated": "2026-08-25T05:42:01.009Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74553 (GCVE-0-2026-74553)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-19 16:38
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
hwmon: (nct6775-core) Fix number of temperature registers for NCT6116
Unlike NCT6106, NCT6116 only has three temperature registers, and with
it only three temperature source and temperature source configuration
registers. The register addresses match those of NCT6106 and can be
re-used.
The code used a separate array to list the temperature source registers
for NCT6116, but used the size of the NCT6106 register array to set
the number of registers. The NCT6106 register array provides six addresses,
while the temperature source register array for NCT6116 only provides three
addresses. This causes a KASAN report.
BUG: KASAN: global-out-of-bounds in nct6775_probe+0x936/0x46f0 [nct6775]
Read of size 2 at addr ffffffffc19561a6 by task modprobe/954
...
Call Trace:
dump_stack+0x7d/0xa7
print_address_description.constprop.0+0x1c/0x220
? __kasan_kmalloc.constprop.0+0xc9/0xd0
? __kmalloc_node_track_caller+0x194/0x5b0
? nct6775_probe+0x936/0x46f0 [nct6775]
? nct6775_probe+0x936/0x46f0 [nct6775]
...
Fix the problem by hard-coding the number of temperature and temperature
configuration registers to three for NCT6116. Drop the unnecessary
NCT6116_REG_TEMP_SOURCE array and re-use NCT6106_REG_TEMP_SOURCE.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 29c7cb485b321c024dedc168bcbb04451176b163 Version: 29c7cb485b321c024dedc168bcbb04451176b163 Version: 29c7cb485b321c024dedc168bcbb04451176b163 Version: 29c7cb485b321c024dedc168bcbb04451176b163 Version: 29c7cb485b321c024dedc168bcbb04451176b163 Version: 29c7cb485b321c024dedc168bcbb04451176b163 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/hwmon/nct6775-core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "739d7fc6b6f662c8286912157f0c4912388aa292",
"status": "affected",
"version": "29c7cb485b321c024dedc168bcbb04451176b163",
"versionType": "git"
},
{
"lessThan": "9a87dfaa05c3c9d3a4cdb7eafc1ab4abc84f6eef",
"status": "affected",
"version": "29c7cb485b321c024dedc168bcbb04451176b163",
"versionType": "git"
},
{
"lessThan": "16c45bb3d3434cfb9ea264fa52090d0823240465",
"status": "affected",
"version": "29c7cb485b321c024dedc168bcbb04451176b163",
"versionType": "git"
},
{
"lessThan": "a42d727dae5701deac8bb2a75effadae7d681153",
"status": "affected",
"version": "29c7cb485b321c024dedc168bcbb04451176b163",
"versionType": "git"
},
{
"lessThan": "a7f47f5246cd6c3199e5fb2d4109cc53e766e3f0",
"status": "affected",
"version": "29c7cb485b321c024dedc168bcbb04451176b163",
"versionType": "git"
},
{
"lessThan": "b0e8adb2ccb43009796897ced09f91636685c9d3",
"status": "affected",
"version": "29c7cb485b321c024dedc168bcbb04451176b163",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/hwmon/nct6775-core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.4"
},
{
"lessThan": "5.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (nct6775-core) Fix number of temperature registers for NCT6116\n\nUnlike NCT6106, NCT6116 only has three temperature registers, and with\nit only three temperature source and temperature source configuration\nregisters. The register addresses match those of NCT6106 and can be\nre-used.\n\nThe code used a separate array to list the temperature source registers\nfor NCT6116, but used the size of the NCT6106 register array to set\nthe number of registers. The NCT6106 register array provides six addresses,\nwhile the temperature source register array for NCT6116 only provides three\naddresses. This causes a KASAN report.\n\nBUG: KASAN: global-out-of-bounds in nct6775_probe+0x936/0x46f0 [nct6775]\nRead of size 2 at addr ffffffffc19561a6 by task modprobe/954\n...\nCall Trace:\n dump_stack+0x7d/0xa7\n print_address_description.constprop.0+0x1c/0x220\n ? __kasan_kmalloc.constprop.0+0xc9/0xd0\n ? __kmalloc_node_track_caller+0x194/0x5b0\n ? nct6775_probe+0x936/0x46f0 [nct6775]\n ? nct6775_probe+0x936/0x46f0 [nct6775]\n...\n\nFix the problem by hard-coding the number of temperature and temperature\nconfiguration registers to three for NCT6116. Drop the unnecessary\nNCT6116_REG_TEMP_SOURCE array and re-use NCT6106_REG_TEMP_SOURCE."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:38:52.272Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/739d7fc6b6f662c8286912157f0c4912388aa292"
},
{
"url": "https://git.kernel.org/stable/c/9a87dfaa05c3c9d3a4cdb7eafc1ab4abc84f6eef"
},
{
"url": "https://git.kernel.org/stable/c/16c45bb3d3434cfb9ea264fa52090d0823240465"
},
{
"url": "https://git.kernel.org/stable/c/a42d727dae5701deac8bb2a75effadae7d681153"
},
{
"url": "https://git.kernel.org/stable/c/a7f47f5246cd6c3199e5fb2d4109cc53e766e3f0"
},
{
"url": "https://git.kernel.org/stable/c/b0e8adb2ccb43009796897ced09f91636685c9d3"
}
],
"title": "hwmon: (nct6775-core) Fix number of temperature registers for NCT6116",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74553",
"datePublished": "2026-08-15T12:27:59.472Z",
"dateReserved": "2026-08-15T05:44:03.916Z",
"dateUpdated": "2026-08-19T16:38:52.272Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-53361 (GCVE-0-2026-53361)
Vulnerability from cvelistv5
Published
2026-07-04 11:54
Modified
2026-08-19 16:28
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
af_unix: Set gc_in_progress to true in unix_gc().
Igor Ushakov reported that unix_gc() could run with gc_in_progress
being false if the work is scheduled while running:
Thread 1 Thread 2 Thread 3
-------- -------- --------
unix_schedule_gc() unix_schedule_gc()
`- if (!gc_in_progress) `- if (!gc_in_progress)
|- gc_in_progress = true |
`- queue_work() |
unix_gc() <----------------/ |
| |- gc_in_progress = true
... `- queue_work()
| |
`- gc_in_progress = false |
|
unix_gc() <---------------------------------------------'
|
... /* gc_in_progress == false */
|
`- gc_in_progress = false
unix_peek_fpl() relies on gc_in_progress not to confuse GC
by MSG_PEEK.
Let's set gc_in_progress to true in unix_gc().
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ceb8bd6c69c1680fd9b45e7f16d7170c9c7513a5 Version: 328840c93bd6a4871dd10908d01b41eab83eb8e2 Version: 8b90a9f819dc2a06baae4ec1a64d875e53b824ec Version: 8b90a9f819dc2a06baae4ec1a64d875e53b824ec Version: 8b90a9f819dc2a06baae4ec1a64d875e53b824ec Version: 6.1.141 ≤ Version: 6.6.93 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/unix/garbage.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "20aa894d475bd8086b25c1113ec4ca70f70c7a98",
"status": "affected",
"version": "ceb8bd6c69c1680fd9b45e7f16d7170c9c7513a5",
"versionType": "git"
},
{
"lessThan": "82c17e13d404f686e164590483fd6c1abaa675d0",
"status": "affected",
"version": "328840c93bd6a4871dd10908d01b41eab83eb8e2",
"versionType": "git"
},
{
"lessThan": "591f1ac217428a6d2b32a8ac14aac0fab44f155a",
"status": "affected",
"version": "8b90a9f819dc2a06baae4ec1a64d875e53b824ec",
"versionType": "git"
},
{
"lessThan": "0cfa78c050662784fc8e3ab26dbfd1dc632b2082",
"status": "affected",
"version": "8b90a9f819dc2a06baae4ec1a64d875e53b824ec",
"versionType": "git"
},
{
"lessThan": "d82ba05263c69fa2437fe93e4e561cc40f4c03af",
"status": "affected",
"version": "8b90a9f819dc2a06baae4ec1a64d875e53b824ec",
"versionType": "git"
},
{
"lessThan": "6.1.183",
"status": "affected",
"version": "6.1.141",
"versionType": "semver"
},
{
"lessThan": "6.6.144",
"status": "affected",
"version": "6.6.93",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/unix/garbage.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.9"
},
{
"lessThan": "6.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.144",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.95",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.38",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "6.1.141",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.144",
"versionStartIncluding": "6.6.93",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.95",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.38",
"versionStartIncluding": "6.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "6.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\naf_unix: Set gc_in_progress to true in unix_gc().\n\nIgor Ushakov reported that unix_gc() could run with gc_in_progress\nbeing false if the work is scheduled while running:\n\n Thread 1 Thread 2 Thread 3\n -------- -------- --------\n unix_schedule_gc() unix_schedule_gc()\n `- if (!gc_in_progress) `- if (!gc_in_progress)\n |- gc_in_progress = true |\n `- queue_work() |\n unix_gc() \u003c----------------/ |\n | |- gc_in_progress = true\n ... `- queue_work()\n | |\n `- gc_in_progress = false |\n |\n unix_gc() \u003c---------------------------------------------\u0027\n |\n ... /* gc_in_progress == false */\n |\n `- gc_in_progress = false\n\nunix_peek_fpl() relies on gc_in_progress not to confuse GC\nby MSG_PEEK.\n\nLet\u0027s set gc_in_progress to true in unix_gc()."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable AF_UNIX garbage-collection path is reached through local socket syscalls such as socketpair(), sendmsg() with SCM_RIGHTS, recvmsg(MSG_PEEK), and close(). It is not reachable directly from network packets.\nAC:L - Although this is a race, the attacker can control the relevant operations by creating AF_UNIX FD cycles, issuing concurrent GC-triggering sends, peeking, and closing sockets. No victim timing or external condition is required beyond scheduler interleaving.\nPR:L - The path is available to an unprivileged local user through ordinary AF_UNIX sockets and SCM_RIGHTS; there is no capability check for socket creation, FD passing, or MSG_PEEK. It still requires local code execution, so privileges are Low rather than None.\nUI:N - No victim interaction is required once the local attacker can run code. The attacker can create the sockets, pass FDs, trigger GC, and race MSG_PEEK independently.\nS:U - The impact remains within the kernel/local IPC security authority. This is not a VM escape, IOMMU bypass, or other cross-scope boundary violation.\nC:N - The bug causes stale GC liveness decisions and purging of live AF_UNIX receive queues, but I did not find a new arbitrary read or unintended disclosure primitive. MSG_PEEK-visible descriptors are already exposed to the receiving endpoint by design.\nI:H - The race can make GC incorrectly collect a live AF_UNIX SCC and purge live receive queues, dropping queued data and SCM_RIGHTS file descriptors. That is unauthorized corruption/destruction of kernel-maintained IPC state, so integrity impact is High.\nA:H - The attacker can repeatedly cause live AF_UNIX sockets to lose queued messages and passed FDs, breaking IPC semantics and potentially denying service to affected local components. Under the required higher-severity rule, this supports High availability impact."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:28:08.836Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/20aa894d475bd8086b25c1113ec4ca70f70c7a98"
},
{
"url": "https://git.kernel.org/stable/c/82c17e13d404f686e164590483fd6c1abaa675d0"
},
{
"url": "https://git.kernel.org/stable/c/591f1ac217428a6d2b32a8ac14aac0fab44f155a"
},
{
"url": "https://git.kernel.org/stable/c/0cfa78c050662784fc8e3ab26dbfd1dc632b2082"
},
{
"url": "https://git.kernel.org/stable/c/d82ba05263c69fa2437fe93e4e561cc40f4c03af"
}
],
"title": "af_unix: Set gc_in_progress to true in unix_gc().",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-53361",
"datePublished": "2026-07-04T11:54:52.543Z",
"dateReserved": "2026-06-09T07:44:35.400Z",
"dateUpdated": "2026-08-19T16:28:08.836Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68431 (GCVE-0-2026-68431)
Vulnerability from cvelistv5
Published
2026-08-12 00:07
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: validate minimum PDU size for transform requests
The receive path applies the minimum SMB2 PDU size check only when
ProtocolId is SMB2_PROTO_NUMBER. A packet carrying
SMB2_TRANSFORM_PROTO_NUM bypasses the check even when the negotiated
dialect does not provide transform handling.
On an SMB 2.1 connection, a short transform packet therefore reaches
init_smb2_rsp_hdr(), which interprets the request as a full SMB2 header
and reads beyond the request allocation. The copied fields can then be
returned to the unauthenticated client.
Compression transforms are converted to ordinary SMB2 messages before
protocol validation. After that conversion, validate ordinary SMB2
requests against SMB2_MIN_SUPPORTED_PDU_SIZE and require encryption
transform requests to contain both a transform header and an SMB2
header. This rejects truncated requests before work allocation.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: df3a4518aee64f21bcafa891105b468413f27431 Version: 543c12c2644e772caa6880662c2a852cfdc5a10c Version: 368ba06881c395f1c9a7ba22203cf8d78b4addc0 Version: 368ba06881c395f1c9a7ba22203cf8d78b4addc0 Version: 368ba06881c395f1c9a7ba22203cf8d78b4addc0 Version: 368ba06881c395f1c9a7ba22203cf8d78b4addc0 Version: 368ba06881c395f1c9a7ba22203cf8d78b4addc0 Version: e9cb7be2fcbaee9e808b729e92948d38d52e5add Version: 5.15.145 ≤ Version: 6.1.34 ≤ Version: 6.3.8 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/smb/server/connection.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "22f1aa35b87e471cc31b35b74451f46630863b12",
"status": "affected",
"version": "df3a4518aee64f21bcafa891105b468413f27431",
"versionType": "git"
},
{
"lessThan": "928dda88d0e13fbca381255028f65b244343a4ea",
"status": "affected",
"version": "543c12c2644e772caa6880662c2a852cfdc5a10c",
"versionType": "git"
},
{
"lessThan": "d8e5c5672724b8f3c4c099d2cf60239c996e5424",
"status": "affected",
"version": "368ba06881c395f1c9a7ba22203cf8d78b4addc0",
"versionType": "git"
},
{
"lessThan": "32e486b70c256d5ef4baa5a2936ade2fea50e8eb",
"status": "affected",
"version": "368ba06881c395f1c9a7ba22203cf8d78b4addc0",
"versionType": "git"
},
{
"lessThan": "d9e9753dfd43bd27c956578df7804a3c90b80fdc",
"status": "affected",
"version": "368ba06881c395f1c9a7ba22203cf8d78b4addc0",
"versionType": "git"
},
{
"lessThan": "b62c510f59803f82f9b4c76ead2a56833b2984c7",
"status": "affected",
"version": "368ba06881c395f1c9a7ba22203cf8d78b4addc0",
"versionType": "git"
},
{
"lessThan": "cfc0b8e5080aec87700774e8568765eaa4b7b92b",
"status": "affected",
"version": "368ba06881c395f1c9a7ba22203cf8d78b4addc0",
"versionType": "git"
},
{
"status": "affected",
"version": "e9cb7be2fcbaee9e808b729e92948d38d52e5add",
"versionType": "git"
},
{
"lessThan": "5.15.217",
"status": "affected",
"version": "5.15.145",
"versionType": "semver"
},
{
"lessThan": "6.1.184",
"status": "affected",
"version": "6.1.34",
"versionType": "semver"
},
{
"lessThan": "6.4",
"status": "affected",
"version": "6.3.8",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/smb/server/connection.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.4"
},
{
"lessThan": "6.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.15.145",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "6.1.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.46",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.3.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: validate minimum PDU size for transform requests\n\nThe receive path applies the minimum SMB2 PDU size check only when\nProtocolId is SMB2_PROTO_NUMBER. A packet carrying\nSMB2_TRANSFORM_PROTO_NUM bypasses the check even when the negotiated\ndialect does not provide transform handling.\n\nOn an SMB 2.1 connection, a short transform packet therefore reaches\ninit_smb2_rsp_hdr(), which interprets the request as a full SMB2 header\nand reads beyond the request allocation. The copied fields can then be\nreturned to the unauthenticated client.\n\nCompression transforms are converted to ordinary SMB2 messages before\nprotocol validation. After that conversion, validate ordinary SMB2\nrequests against SMB2_MIN_SUPPORTED_PDU_SIZE and require encryption\ntransform requests to contain both a transform header and an SMB2\nheader. This rejects truncated requests before work allocation."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - ksmbd is the in-kernel SMB server on TCP/445; the malformed short SMB2_TRANSFORM PDU is delivered entirely as remote network data in ksmbd_conn_handler_loop(), and the leaked bytes are returned in the network response. No local access is involved.\nAC:L - The attacker connects, sends a NEGOTIATE selecting dialect 2.1 (permitted by default since ksmbd_min_protocol() is SMB21_PROT), then a 35-byte packet with ProtocolId 0xFD\u0027SMB\u0027; the undersized-buffer header copy happens deterministically with no race, timing, or memory-layout dependency.\nPR:N - Only NEGOTIATE is required to reach the flaw, which precedes SESSION_SETUP; smb2_check_user_session() fails after the out-of-bounds copy has already been made, so the disclosure is delivered to a fully unauthenticated client.\nUI:N - The attacker drives the entire exchange from a single TCP connection; no action by any local user, administrator, or SMB client is needed.\nS:U - The out-of-bounds read and the disclosed data remain within the kernel\u0027s own security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - init_smb2_rsp_hdr() reads a 64-byte smb2_hdr out of a ~40-byte kvmalloc allocation and echoes MessageId, ProcessId, TreeId, SessionId and 16 Signature bytes back to the client, disclosing ~28 bytes of uninitialized and adjacent kmalloc-64 heap contents per request, repeatable at will as a remote heap/KASLR oracle.\nI:N - The defect is a read past the request allocation; no attacker-controlled data is written into kernel memory and no kernel or filesystem state is modified by the truncated transform request.\nA:H - The header copy reads past the end of the slab object; on KASAN, hardware tag-based KASAN (MTE), or slub_debug/hardened builds this is a fatal report, and any such unchecked out-of-bounds kernel access is treated as crash-capable."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:22.134Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/22f1aa35b87e471cc31b35b74451f46630863b12"
},
{
"url": "https://git.kernel.org/stable/c/928dda88d0e13fbca381255028f65b244343a4ea"
},
{
"url": "https://git.kernel.org/stable/c/d8e5c5672724b8f3c4c099d2cf60239c996e5424"
},
{
"url": "https://git.kernel.org/stable/c/32e486b70c256d5ef4baa5a2936ade2fea50e8eb"
},
{
"url": "https://git.kernel.org/stable/c/d9e9753dfd43bd27c956578df7804a3c90b80fdc"
},
{
"url": "https://git.kernel.org/stable/c/b62c510f59803f82f9b4c76ead2a56833b2984c7"
},
{
"url": "https://git.kernel.org/stable/c/cfc0b8e5080aec87700774e8568765eaa4b7b92b"
}
],
"title": "ksmbd: validate minimum PDU size for transform requests",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68431",
"datePublished": "2026-08-12T00:07:17.216Z",
"dateReserved": "2026-07-30T09:28:09.393Z",
"dateUpdated": "2026-08-23T12:46:22.134Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74632 (GCVE-0-2026-74632)
Vulnerability from cvelistv5
Published
2026-08-22 15:32
Modified
2026-08-27 12:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
mm/huge_memory: fix huge_zero_pfn race
Patch series "mm/huge_memory: fix huge_zero_pfn race", v2.
There is a subtle race in the reference-counted huge_zero_folio
implementation.
The fast path atomic logic fails to account for the fact that the shrinker
(which drops the final huge_zero_refcount pin) can overwrite huge_zero_pfn
with the ~0UL sentinel value in shrink_huge_zero_folio_scan() after a
racing get_huge_zero_folio() installed a valid value there.
This results in huge_zero_folio being correctly set but huge_zero_pfn
being set incorrectly and thus is_huge_zero_pfn() and consequently
is_huge_zero_pmd() will misidentify the huge zero folio as being an
ordinary THP folio.
This can result in the huge zero folio being split and otherwise treated
incorrectly.
The solution to this is very subtle as there is an atomic fast path, and
thus ordering in weakly ordered architectures has to be treated very
carefully.
The first commit fixes the issue by introducing a spinlock around
huge_zero_[pfn, folio, refcount] write, with careful consideration paid to
load/store ordering in the fast path. It is placed first and kept as
small as possible so that it can be backported on its own.
The second commit is a pure cleanup which reworks the
CONFIG_PERSISTENT_HUGE_ZERO_FOLIO logic to better separate the persistent
logic from the dynamically allocated one.
This patch (of 2):
If !CONFIG_PERSISTENT_HUGE_ZERO_FOLIO, the huge_zero_folio is refcounted
by huge_zero_refcount and returned by mm_get_huge_zero_folio().
When the caller is done with the huge zero page, its reference count is
decremented. Only a shrinker can set the reference count to zero.
A race can unfortunately occur between a shrinker decrementing the
reference count to zero and a concurrent page fault.
This is because shrink_huge_zero_folio_scan() might, if very unlucky, be
preempted between setting huge_zero_refcount to zero and writing an
invalid value.
During this time get_huge_zero_folio() could write to huge_zero_pfn before
shrink_huge_zero_folio_scan() resumes.
In this event the huge zero folio will be persistently misidentified
causing the THP code path to be entered inappropriately for the huge zero
folio:
CPU 0 CPU 1
=======================================|=================================
shrink_huge_zero_folio_scan() |
atomic_cmpxchg() sets refcount to 0 |
xchg() sets huge_zero_folio to NULL | get_huge_zero_folio()
| | atomic_inc_not_zero() -> zero
preempted for a long time | Allocate new huge zero folio
| | Write valid huge_zero_folio
v | Write valid huge_zero_pfn
Overwrite huge_zero_pfn with ~0UL <--- Invalid overwrite!
This results in is_huge_zero_pfn() and is_huge_zero_pmd() incorrectly
returning false for a huge zero page which could result in issues like the
huge zero folio being incorrectly split.
Note that the issue is with huge_zero_pfn not huge_zero_folio, as
get_huge_zero_folio() uses cmpxchg() gated on huge_zero_folio being NULL
with a retry loop and shrink_huge_zero_folio_scan() uses xchg() to set
huge_zero_folio.
Fix the issue by introducing a spinlock, huge_zero_lock, to prevent
concurrent write of huge_zero_folio, huge_zero_pfn and huge_zero_refcount.
There needs to be significant care taken here to ensure correctness:
The fast path in get_huge_zero_folio() uses atomic_inc_not_zero(), which
is outside of the critical section, and means huge zero allocation is
gated on zero huge_zero_refcount.
The fast path doesn't use huge_zero_lock, so the critical section is
irrelevant to it.
So invariants are required - huge_zero_refcount MUST:
* Only be set in the huge_zero_lock critical section to ensure
serialisation of huge_zero_pfn, huge_zero_folio and
---truncated---
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 6527d8ef68c3ca3c455e38ae2a37cd7810caec73 Version: 3b77e8c8cde581dadab9a0f1543a347e24315f11 Version: 3b77e8c8cde581dadab9a0f1543a347e24315f11 Version: 3b77e8c8cde581dadab9a0f1543a347e24315f11 Version: 3b77e8c8cde581dadab9a0f1543a347e24315f11 Version: 3b77e8c8cde581dadab9a0f1543a347e24315f11 Version: 3b77e8c8cde581dadab9a0f1543a347e24315f11 Version: 3b77e8c8cde581dadab9a0f1543a347e24315f11 Version: fc1fbc5b017b6f5ef24a4a93f33cd022225e01c8 Version: bd092a0f19423d7e9e81182314a96ecd6a14f3b7 Version: b1daf8f862136894a4595770a44e4508808fb806 Version: 5.10.47 ≤ Version: 4.19.197 ≤ Version: 5.4.129 ≤ Version: 5.12.14 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"mm/huge_memory.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "9c0fd1802ce06d7709f0bae4edeb085288f28764",
"status": "affected",
"version": "6527d8ef68c3ca3c455e38ae2a37cd7810caec73",
"versionType": "git"
},
{
"lessThan": "b7041ba61c5da4e0b56f9be58cfb87d7689724e4",
"status": "affected",
"version": "3b77e8c8cde581dadab9a0f1543a347e24315f11",
"versionType": "git"
},
{
"lessThan": "9332b080ad57650d1dc582e54517f9fc78ef89cc",
"status": "affected",
"version": "3b77e8c8cde581dadab9a0f1543a347e24315f11",
"versionType": "git"
},
{
"lessThan": "f3a874a903053c53fb53ba287ea9eacda69c68e8",
"status": "affected",
"version": "3b77e8c8cde581dadab9a0f1543a347e24315f11",
"versionType": "git"
},
{
"lessThan": "6024f6d0d9b9ca5138bfc4ac6f6e4bdf616e42b3",
"status": "affected",
"version": "3b77e8c8cde581dadab9a0f1543a347e24315f11",
"versionType": "git"
},
{
"lessThan": "105d04edbec83010df5728f74d17fd9c108e7553",
"status": "affected",
"version": "3b77e8c8cde581dadab9a0f1543a347e24315f11",
"versionType": "git"
},
{
"lessThan": "ab7e4b407c7f58d1a003134eff3841f303d5ccc2",
"status": "affected",
"version": "3b77e8c8cde581dadab9a0f1543a347e24315f11",
"versionType": "git"
},
{
"lessThan": "33192a26cddea7a7e4ca66e5c3eebd36fa8be2bb",
"status": "affected",
"version": "3b77e8c8cde581dadab9a0f1543a347e24315f11",
"versionType": "git"
},
{
"status": "affected",
"version": "fc1fbc5b017b6f5ef24a4a93f33cd022225e01c8",
"versionType": "git"
},
{
"status": "affected",
"version": "bd092a0f19423d7e9e81182314a96ecd6a14f3b7",
"versionType": "git"
},
{
"status": "affected",
"version": "b1daf8f862136894a4595770a44e4508808fb806",
"versionType": "git"
},
{
"lessThan": "5.10.267",
"status": "affected",
"version": "5.10.47",
"versionType": "semver"
},
{
"lessThan": "4.20",
"status": "affected",
"version": "4.19.197",
"versionType": "semver"
},
{
"lessThan": "5.5",
"status": "affected",
"version": "5.4.129",
"versionType": "semver"
},
{
"lessThan": "5.13",
"status": "affected",
"version": "5.12.14",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"mm/huge_memory.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.13"
},
{
"lessThan": "5.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.267",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.218",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.267",
"versionStartIncluding": "5.10.47",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.218",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.19.197",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.4.129",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.12.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/huge_memory: fix huge_zero_pfn race\n\nPatch series \"mm/huge_memory: fix huge_zero_pfn race\", v2.\n\nThere is a subtle race in the reference-counted huge_zero_folio\nimplementation.\n\nThe fast path atomic logic fails to account for the fact that the shrinker\n(which drops the final huge_zero_refcount pin) can overwrite huge_zero_pfn\nwith the ~0UL sentinel value in shrink_huge_zero_folio_scan() after a\nracing get_huge_zero_folio() installed a valid value there.\n\nThis results in huge_zero_folio being correctly set but huge_zero_pfn\nbeing set incorrectly and thus is_huge_zero_pfn() and consequently\nis_huge_zero_pmd() will misidentify the huge zero folio as being an\nordinary THP folio.\n\nThis can result in the huge zero folio being split and otherwise treated\nincorrectly.\n\nThe solution to this is very subtle as there is an atomic fast path, and\nthus ordering in weakly ordered architectures has to be treated very\ncarefully.\n\nThe first commit fixes the issue by introducing a spinlock around\nhuge_zero_[pfn, folio, refcount] write, with careful consideration paid to\nload/store ordering in the fast path. It is placed first and kept as\nsmall as possible so that it can be backported on its own.\n\nThe second commit is a pure cleanup which reworks the\nCONFIG_PERSISTENT_HUGE_ZERO_FOLIO logic to better separate the persistent\nlogic from the dynamically allocated one.\n\n\nThis patch (of 2):\n\nIf !CONFIG_PERSISTENT_HUGE_ZERO_FOLIO, the huge_zero_folio is refcounted\nby huge_zero_refcount and returned by mm_get_huge_zero_folio().\n\nWhen the caller is done with the huge zero page, its reference count is\ndecremented. Only a shrinker can set the reference count to zero.\n\nA race can unfortunately occur between a shrinker decrementing the\nreference count to zero and a concurrent page fault.\n\nThis is because shrink_huge_zero_folio_scan() might, if very unlucky, be\npreempted between setting huge_zero_refcount to zero and writing an\ninvalid value.\n\nDuring this time get_huge_zero_folio() could write to huge_zero_pfn before\nshrink_huge_zero_folio_scan() resumes.\n\nIn this event the huge zero folio will be persistently misidentified\ncausing the THP code path to be entered inappropriately for the huge zero\nfolio:\n\n CPU 0 CPU 1\n=======================================|=================================\nshrink_huge_zero_folio_scan() |\n atomic_cmpxchg() sets refcount to 0 |\n xchg() sets huge_zero_folio to NULL | get_huge_zero_folio()\n | | atomic_inc_not_zero() -\u003e zero\n preempted for a long time | Allocate new huge zero folio\n | | Write valid huge_zero_folio\n v | Write valid huge_zero_pfn\n Overwrite huge_zero_pfn with ~0UL \u003c--- Invalid overwrite!\n\nThis results in is_huge_zero_pfn() and is_huge_zero_pmd() incorrectly\nreturning false for a huge zero page which could result in issues like the\nhuge zero folio being incorrectly split.\n\nNote that the issue is with huge_zero_pfn not huge_zero_folio, as\nget_huge_zero_folio() uses cmpxchg() gated on huge_zero_folio being NULL\nwith a retry loop and shrink_huge_zero_folio_scan() uses xchg() to set\nhuge_zero_folio.\n\nFix the issue by introducing a spinlock, huge_zero_lock, to prevent\nconcurrent write of huge_zero_folio, huge_zero_pfn and huge_zero_refcount.\n\nThere needs to be significant care taken here to ensure correctness:\n\nThe fast path in get_huge_zero_folio() uses atomic_inc_not_zero(), which\nis outside of the critical section, and means huge zero allocation is\ngated on zero huge_zero_refcount.\n\nThe fast path doesn\u0027t use huge_zero_lock, so the critical section is\nirrelevant to it.\n\nSo invariants are required - huge_zero_refcount MUST:\n\n* Only be set in the huge_zero_lock critical section to ensure\n serialisation of huge_zero_pfn, huge_zero_folio and\n---truncated---"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Reached only through local page faults in handle_mm_fault()-\u003ecreate_huge_pmd()-\u003edo_huge_pmd_anonymous_page()-\u003emm_get_huge_zero_folio() racing shrink_huge_zero_folio_scan(); no network, adjacent, or physical path exists.\nAC:L - Attacker controls both race sides: concurrent anonymous read faults drive get_huge_zero_folio() while memory-pressure reclaim drives shrink_huge_zero_folio_scan(); multi-threaded hammering makes the preemption window reliably winnable.\nPR:L - Any unprivileged local process can mmap anonymous memory and trigger huge-zero PMD installation on typical CONFIG_TRANSPARENT_HUGEPAGE systems with zero-page enabled; no root, capabilities, or authentication is required.\nUI:N - Exploitation is fully attacker-driven via standard syscalls (mmap, madvise, read, munmap) and deliberate memory pressure; no separate victim action beyond the attacker running their own workload is needed.\nS:U - Corrupts kernel-global huge_zero_folio metadata and rmap/RSS accounting within the kernel security boundary; this is not a VM escape, IOMMU bypass, or cross-authority sandbox break.\nC:H - Misidentification routes the shared huge zero folio through normal THP split/teardown (folio_remove_rmap_pmd, incorrect accounting), corrupting global page metadata with plausible arbitrary kernel memory disclosure leverage.\nI:H - Wrong-path splitting manipulates refcount/rmap state on the system-wide huge zero singleton folio, corrupting kernel integrity and enabling memory-write/control-flow primitives from metadata corruption.\nA:H - Mis-split triggers kernel WARN/BUG_ON, bad page state, and bad rss-counter failures during reclaim or teardown, causing kernel oops, panic, or hang on affected THP systems."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T12:39:50.791Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/9c0fd1802ce06d7709f0bae4edeb085288f28764"
},
{
"url": "https://git.kernel.org/stable/c/b7041ba61c5da4e0b56f9be58cfb87d7689724e4"
},
{
"url": "https://git.kernel.org/stable/c/9332b080ad57650d1dc582e54517f9fc78ef89cc"
},
{
"url": "https://git.kernel.org/stable/c/f3a874a903053c53fb53ba287ea9eacda69c68e8"
},
{
"url": "https://git.kernel.org/stable/c/6024f6d0d9b9ca5138bfc4ac6f6e4bdf616e42b3"
},
{
"url": "https://git.kernel.org/stable/c/105d04edbec83010df5728f74d17fd9c108e7553"
},
{
"url": "https://git.kernel.org/stable/c/ab7e4b407c7f58d1a003134eff3841f303d5ccc2"
},
{
"url": "https://git.kernel.org/stable/c/33192a26cddea7a7e4ca66e5c3eebd36fa8be2bb"
}
],
"title": "mm/huge_memory: fix huge_zero_pfn race",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74632",
"datePublished": "2026-08-22T15:32:13.078Z",
"dateReserved": "2026-08-15T05:44:03.922Z",
"dateUpdated": "2026-08-27T12:39:50.791Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74587 (GCVE-0-2026-74587)
Vulnerability from cvelistv5
Published
2026-08-22 15:31
Modified
2026-08-25 05:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
sctp: fix use-after-free of cached ASCONF chunk
addip_last_asconf caches the outstanding outbound ASCONF chunk. The normal
ASCONF-ACK completion path releases the chunk and clears the pointer.
However, sctp_asconf_queue_teardown() releases the cached chunk without
clearing addip_last_asconf. During peer restart handling,
sctp_sf_do_dupcook_a() queues SCTP_CMD_PURGE_ASCONF_QUEUE, which invokes
sctp_asconf_queue_teardown() while the association remains alive and leaves
the pointer dangling.
A delayed authenticated ASCONF-ACK can then reach sctp_sf_do_asconf_ack(),
which accesses the stale chunk and passes it to sctp_process_asconf_ack(),
causing a use-after-free and a second release.
Clearing the pointer exposes a race with T4 expiry. Peer restart handling
queues the timer stop before the purge, but SCTP_CMD_TIMER_STOP uses
timer_delete(), which does not wait for a callback already running on
another CPU. Such a callback can reach sctp_sf_t4_timer_expire() after
the purge and dereference NULL.
Clear addip_last_asconf after releasing the cached chunk, and make
sctp_sf_t4_timer_expire() consume a stale T4 expiry if no outstanding
ASCONF remains.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: a000c01e60e40e15304ffe48fff051d17a7bea91 Version: a000c01e60e40e15304ffe48fff051d17a7bea91 Version: a000c01e60e40e15304ffe48fff051d17a7bea91 Version: a000c01e60e40e15304ffe48fff051d17a7bea91 Version: a000c01e60e40e15304ffe48fff051d17a7bea91 Version: a000c01e60e40e15304ffe48fff051d17a7bea91 Version: a000c01e60e40e15304ffe48fff051d17a7bea91 Version: a000c01e60e40e15304ffe48fff051d17a7bea91 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/sctp/associola.c",
"net/sctp/sm_statefuns.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "10459b03e2d9ee12435e96f587de4d4cacdbf435",
"status": "affected",
"version": "a000c01e60e40e15304ffe48fff051d17a7bea91",
"versionType": "git"
},
{
"lessThan": "e1bb114e09372fd6e03387ced9ef566da336ed6c",
"status": "affected",
"version": "a000c01e60e40e15304ffe48fff051d17a7bea91",
"versionType": "git"
},
{
"lessThan": "179676f0166230c80053a392303485b37c93dd33",
"status": "affected",
"version": "a000c01e60e40e15304ffe48fff051d17a7bea91",
"versionType": "git"
},
{
"lessThan": "dc67d528c2fa939cec7fe3bf7f3089c8d281ca3d",
"status": "affected",
"version": "a000c01e60e40e15304ffe48fff051d17a7bea91",
"versionType": "git"
},
{
"lessThan": "618b5c6d049896fcfabb91afc072954c92cb2693",
"status": "affected",
"version": "a000c01e60e40e15304ffe48fff051d17a7bea91",
"versionType": "git"
},
{
"lessThan": "07daf4f9750104960a1d60831b2353c0d41f35fb",
"status": "affected",
"version": "a000c01e60e40e15304ffe48fff051d17a7bea91",
"versionType": "git"
},
{
"lessThan": "d949992bc3f00027a2c755e860a11950c75f6073",
"status": "affected",
"version": "a000c01e60e40e15304ffe48fff051d17a7bea91",
"versionType": "git"
},
{
"lessThan": "8c283e7b56adce00193837f3311b06662466fb21",
"status": "affected",
"version": "a000c01e60e40e15304ffe48fff051d17a7bea91",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/sctp/associola.c",
"net/sctp/sm_statefuns.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.0"
},
{
"lessThan": "3.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: fix use-after-free of cached ASCONF chunk\n\naddip_last_asconf caches the outstanding outbound ASCONF chunk. The normal\nASCONF-ACK completion path releases the chunk and clears the pointer.\n\nHowever, sctp_asconf_queue_teardown() releases the cached chunk without\nclearing addip_last_asconf. During peer restart handling,\nsctp_sf_do_dupcook_a() queues SCTP_CMD_PURGE_ASCONF_QUEUE, which invokes\nsctp_asconf_queue_teardown() while the association remains alive and leaves\nthe pointer dangling.\n\nA delayed authenticated ASCONF-ACK can then reach sctp_sf_do_asconf_ack(),\nwhich accesses the stale chunk and passes it to sctp_process_asconf_ack(),\ncausing a use-after-free and a second release.\n\nClearing the pointer exposes a race with T4 expiry. Peer restart handling\nqueues the timer stop before the purge, but SCTP_CMD_TIMER_STOP uses\ntimer_delete(), which does not wait for a callback already running on\nanother CPU. Such a callback can reach sctp_sf_t4_timer_expire() after\nthe purge and dereference NULL.\n\nClear addip_last_asconf after releasing the cached chunk, and make\nsctp_sf_t4_timer_expire() consume a stale T4 expiry if no outstanding\nASCONF remains."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The UAF is triggered when the kernel processes inbound SCTP COOKIE-ECHO (peer restart) and ASCONF-ACK chunks from a remote association peer via sctp_rcv()/sctp_inq_push()/sctp_do_sm(), with no local syscall required on the victim.\nAC:L - The remote SCTP peer controls the full protocol sequence\u2014establishing an ADDIP-capable association, waiting for the victim\u0027s outstanding ASCONF, sending COOKIE-ECHO restart to purge queues, then delivering a delayed authenticated ASCONF-ACK\u2014without attacker-uncontrollable races or memory layout.\nPR:N - Exploitation requires only network access as an established SCTP association peer sending authenticated protocol traffic; no local Linux account, capability, or namespace privilege is needed on the victim host.\nUI:N - No victim user action is required beyond normal automated SCTP server/client operation; the attacker drives the entire trigger sequence with crafted COOKIE-ECHO and ASCONF-ACK packets on the existing association.\nS:U - Impact is confined to kernel memory corruption and potential privilege escalation within the host kernel; it does not cross a VM, container, or IOMMU security boundary.\nC:H - sctp_sf_do_asconf_ack() and sctp_process_asconf_ack() dereference the stale addip_last_asconf pointer to read freed sctp_chunk and skb metadata; UAF on slab-allocated chunk objects enables heap grooming for arbitrary kernel memory disclosure.\nI:H - The stale pointer causes sctp_process_asconf_ack() to perform a second sctp_chunk_free() on an already-freed chunk, yielding a kmem_cache double-free that can be leveraged for arbitrary kernel write or control-flow hijack.\nA:H - Dereferencing the freed cached ASCONF chunk during ASCONF-ACK processing can cause kernel oops/panic and repeatable remote denial of service against any SCTP endpoint handling the malicious peer traffic."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:40:13.798Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/10459b03e2d9ee12435e96f587de4d4cacdbf435"
},
{
"url": "https://git.kernel.org/stable/c/e1bb114e09372fd6e03387ced9ef566da336ed6c"
},
{
"url": "https://git.kernel.org/stable/c/179676f0166230c80053a392303485b37c93dd33"
},
{
"url": "https://git.kernel.org/stable/c/dc67d528c2fa939cec7fe3bf7f3089c8d281ca3d"
},
{
"url": "https://git.kernel.org/stable/c/618b5c6d049896fcfabb91afc072954c92cb2693"
},
{
"url": "https://git.kernel.org/stable/c/07daf4f9750104960a1d60831b2353c0d41f35fb"
},
{
"url": "https://git.kernel.org/stable/c/d949992bc3f00027a2c755e860a11950c75f6073"
},
{
"url": "https://git.kernel.org/stable/c/8c283e7b56adce00193837f3311b06662466fb21"
}
],
"title": "sctp: fix use-after-free of cached ASCONF chunk",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74587",
"datePublished": "2026-08-22T15:31:39.810Z",
"dateReserved": "2026-08-15T05:44:03.918Z",
"dateUpdated": "2026-08-25T05:40:13.798Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80826 (GCVE-0-2026-80826)
Vulnerability from cvelistv5
Published
2026-09-04 15:54
Modified
2026-09-04 15:54
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
USB: c67x00: fix use-after-free in c67x00_add_iso_urb()
When TD creation fails for the last packet of an isochronous URB,
c67x00_add_iso_urb() gives the URB back before updating the endpoint
scheduling state.
c67x00_giveback_urb() frees the URB private data, and the completion
callback may release the final URB reference. The following accesses to
urbp->ep_data, urb->interval, and urbp->cnt can therefore use freed
memory.
Update next_frame and cnt before giving back the failed final packet,
making the giveback the last operation that uses the URB and its private
data.
References
| URL | Tags | ||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: e9b29ffc519b9e63d4e1c0b1278bb951bb418a9d Version: e9b29ffc519b9e63d4e1c0b1278bb951bb418a9d Version: e9b29ffc519b9e63d4e1c0b1278bb951bb418a9d Version: e9b29ffc519b9e63d4e1c0b1278bb951bb418a9d Version: e9b29ffc519b9e63d4e1c0b1278bb951bb418a9d Version: e9b29ffc519b9e63d4e1c0b1278bb951bb418a9d Version: e9b29ffc519b9e63d4e1c0b1278bb951bb418a9d Version: e9b29ffc519b9e63d4e1c0b1278bb951bb418a9d Version: e9b29ffc519b9e63d4e1c0b1278bb951bb418a9d |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/c67x00/c67x00-sched.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "e4039e9bebb528dd9cd7ac72aeaec529c26c355a",
"status": "affected",
"version": "e9b29ffc519b9e63d4e1c0b1278bb951bb418a9d",
"versionType": "git"
},
{
"lessThan": "ade18b4ce78a16558f4f435aece80082f6f7b64c",
"status": "affected",
"version": "e9b29ffc519b9e63d4e1c0b1278bb951bb418a9d",
"versionType": "git"
},
{
"lessThan": "bb572801290e25ec1c4753d14af35777303f5d6b",
"status": "affected",
"version": "e9b29ffc519b9e63d4e1c0b1278bb951bb418a9d",
"versionType": "git"
},
{
"lessThan": "62cd519ab74cac499036cd88c11692f8f0d53e14",
"status": "affected",
"version": "e9b29ffc519b9e63d4e1c0b1278bb951bb418a9d",
"versionType": "git"
},
{
"lessThan": "ff172092cba7ec990ecc7b610ce703e19570b8f0",
"status": "affected",
"version": "e9b29ffc519b9e63d4e1c0b1278bb951bb418a9d",
"versionType": "git"
},
{
"lessThan": "b4cb8081cf80f82e48fbe9c021a8f6d0fa2ed421",
"status": "affected",
"version": "e9b29ffc519b9e63d4e1c0b1278bb951bb418a9d",
"versionType": "git"
},
{
"lessThan": "7983daa159981fac125db2457437723f38ea1472",
"status": "affected",
"version": "e9b29ffc519b9e63d4e1c0b1278bb951bb418a9d",
"versionType": "git"
},
{
"lessThan": "f24dcc61bd0ecf7639fac5bf700450b398d793a7",
"status": "affected",
"version": "e9b29ffc519b9e63d4e1c0b1278bb951bb418a9d",
"versionType": "git"
},
{
"lessThan": "b1e24de475bf2d66fffc9103f3444b783527d55a",
"status": "affected",
"version": "e9b29ffc519b9e63d4e1c0b1278bb951bb418a9d",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/usb/c67x00/c67x00-sched.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.26"
},
{
"lessThan": "2.6.26",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.269",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.220",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.187",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.156",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.108",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.49",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.13",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.3",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.269",
"versionStartIncluding": "2.6.26",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.220",
"versionStartIncluding": "2.6.26",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.187",
"versionStartIncluding": "2.6.26",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.156",
"versionStartIncluding": "2.6.26",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.108",
"versionStartIncluding": "2.6.26",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.49",
"versionStartIncluding": "2.6.26",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.13",
"versionStartIncluding": "2.6.26",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.3",
"versionStartIncluding": "2.6.26",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "2.6.26",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: c67x00: fix use-after-free in c67x00_add_iso_urb()\n\nWhen TD creation fails for the last packet of an isochronous URB,\nc67x00_add_iso_urb() gives the URB back before updating the endpoint\nscheduling state.\n\nc67x00_giveback_urb() frees the URB private data, and the completion\ncallback may release the final URB reference. The following accesses to\nurbp-\u003eep_data, urb-\u003einterval, and urbp-\u003ecnt can therefore use freed\nmemory.\n\nUpdate next_frame and cnt before giving back the failed final packet,\nmaking the giveback the last operation that uses the URB and its private\ndata."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T15:54:30.131Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/e4039e9bebb528dd9cd7ac72aeaec529c26c355a"
},
{
"url": "https://git.kernel.org/stable/c/ade18b4ce78a16558f4f435aece80082f6f7b64c"
},
{
"url": "https://git.kernel.org/stable/c/bb572801290e25ec1c4753d14af35777303f5d6b"
},
{
"url": "https://git.kernel.org/stable/c/62cd519ab74cac499036cd88c11692f8f0d53e14"
},
{
"url": "https://git.kernel.org/stable/c/ff172092cba7ec990ecc7b610ce703e19570b8f0"
},
{
"url": "https://git.kernel.org/stable/c/b4cb8081cf80f82e48fbe9c021a8f6d0fa2ed421"
},
{
"url": "https://git.kernel.org/stable/c/7983daa159981fac125db2457437723f38ea1472"
},
{
"url": "https://git.kernel.org/stable/c/f24dcc61bd0ecf7639fac5bf700450b398d793a7"
},
{
"url": "https://git.kernel.org/stable/c/b1e24de475bf2d66fffc9103f3444b783527d55a"
}
],
"title": "USB: c67x00: fix use-after-free in c67x00_add_iso_urb()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80826",
"datePublished": "2026-09-04T15:54:30.131Z",
"dateReserved": "2026-08-26T14:34:25.795Z",
"dateUpdated": "2026-09-04T15:54:30.131Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74607 (GCVE-0-2026-74607)
Vulnerability from cvelistv5
Published
2026-08-22 15:31
Modified
2026-08-25 05:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
KVM: SVM: Serialize accesses to the owner and mirror list with separate lock
Interaction between KVM_CAP_VM_MOVE_ENC_CONTEXT_FROM and
KVM_CAP_VM_COPY_ENC_CONTEXT_FROM can cause two separate issues:
- in sev_migrate_from(), when the destination KVM is a mirror, the mirror
entry is moved from the source's list to the owner's mirror_vms list,
without holding the owner's lock unlike other writers of the owner's
mirror list (sev_vm_copy_enc_context_from(), sev_vm_destroy()).
A concurrent COPY or destroy can race with sev_migrate_from() and
corrupt the list.
- In sev_vm_destroy(), the *owner* is still active and could receive
concurrently a KVM_CAP_VM_MOVE_ENC_CONTEXT_FROM that causes
sev->enc_context_owner to change. In this case the incorrect VM
receives kvm_put_kvm().
The second issue needs particular care because the owner could disappear
altogether (even though the race window is impossibly small) between
reading it and locking it. There is thus no way to perform the checks
under the owner lock without putting struct kvm under SLAB_TYPESAFE_BY_RCU
(which would allow kvm_get_kvm_safe() under RCU critical section).
It is much simpler to just use a global lock, since the critical
sections are so small and the new lock is always a leaf lock.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: b2125513dfc0dd0ec5a9605138a3c356592cfb73 Version: b2125513dfc0dd0ec5a9605138a3c356592cfb73 Version: b2125513dfc0dd0ec5a9605138a3c356592cfb73 Version: b2125513dfc0dd0ec5a9605138a3c356592cfb73 Version: b2125513dfc0dd0ec5a9605138a3c356592cfb73 Version: b2125513dfc0dd0ec5a9605138a3c356592cfb73 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"arch/x86/kvm/svm/sev.c",
"arch/x86/kvm/svm/svm.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "7943ec3a6d0e7e0a2eb4943300bce089ac3e8c3e",
"status": "affected",
"version": "b2125513dfc0dd0ec5a9605138a3c356592cfb73",
"versionType": "git"
},
{
"lessThan": "28afde1edbd8b20058cbf4d75fb57876471ec334",
"status": "affected",
"version": "b2125513dfc0dd0ec5a9605138a3c356592cfb73",
"versionType": "git"
},
{
"lessThan": "328ab4fabe05af004d886659f8744076e320ddce",
"status": "affected",
"version": "b2125513dfc0dd0ec5a9605138a3c356592cfb73",
"versionType": "git"
},
{
"lessThan": "47976eaaf0a4eb46dade48b3246779090db9e3ec",
"status": "affected",
"version": "b2125513dfc0dd0ec5a9605138a3c356592cfb73",
"versionType": "git"
},
{
"lessThan": "d728baba0f20e49439fc7831bf3e4e7dee82161a",
"status": "affected",
"version": "b2125513dfc0dd0ec5a9605138a3c356592cfb73",
"versionType": "git"
},
{
"lessThan": "1d78d33275ef2a16c6d080910b291d0a97a0e613",
"status": "affected",
"version": "b2125513dfc0dd0ec5a9605138a3c356592cfb73",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"arch/x86/kvm/svm/sev.c",
"arch/x86/kvm/svm/svm.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.18"
},
{
"lessThan": "5.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.18",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: SVM: Serialize accesses to the owner and mirror list with separate lock\n\nInteraction between KVM_CAP_VM_MOVE_ENC_CONTEXT_FROM and\nKVM_CAP_VM_COPY_ENC_CONTEXT_FROM can cause two separate issues:\n\n- in sev_migrate_from(), when the destination KVM is a mirror, the mirror\n entry is moved from the source\u0027s list to the owner\u0027s mirror_vms list,\n without holding the owner\u0027s lock unlike other writers of the owner\u0027s\n mirror list (sev_vm_copy_enc_context_from(), sev_vm_destroy()).\n A concurrent COPY or destroy can race with sev_migrate_from() and\n corrupt the list.\n\n- In sev_vm_destroy(), the *owner* is still active and could receive\n concurrently a KVM_CAP_VM_MOVE_ENC_CONTEXT_FROM that causes\n sev-\u003eenc_context_owner to change. In this case the incorrect VM\n receives kvm_put_kvm().\n\nThe second issue needs particular care because the owner could disappear\naltogether (even though the race window is impossibly small) between\nreading it and locking it. There is thus no way to perform the checks\nunder the owner lock without putting struct kvm under SLAB_TYPESAFE_BY_RCU\n(which would allow kvm_get_kvm_safe() under RCU critical section).\n\nIt is much simpler to just use a global lock, since the critical\nsections are so small and the new lock is always a leaf lock."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Reached only via local KVM_ENABLE_CAP ioctl on VM fds (KVM_CAP_VM_MOVE_ENC_CONTEXT_FROM/KVM_CAP_VM_COPY_ENC_CONTEXT_FROM) after opening /dev/kvm; not network, adjacent-wireless, or physical-device reachable.\nAC:L - Attacker with multiple VM fds can concurrently issue MOVE, COPY, and close operations from threads they control to deterministically race sev_migrate_from(), sev_vm_copy_enc_context_from(), and sev_vm_destroy().\nPR:L - Requires /dev/kvm and SEV setup (typically kvm-group or QEMU/container KVM passthrough), not init-namespace root; CAP_SYS_ADMIN-equivalent access is not obtainable via unprivileged user namespaces alone but kvm tenants hold sufficient access.\nUI:N - No victim interaction; the attacker VMM process issues the ioctl sequence and concurrent close/migrate operations directly.\nS:C - Races corrupt SEV mirror/owner linked lists and can misdirect kvm_put_kvm() on the wrong struct kvm, breaking AMD SEV encrypted-memory isolation boundaries and enabling host impact beyond the caller VM scope.\nC:H - Unsynchronized mirror_vms/enc_context_owner updates cause kernel linked-list corruption and kvm refcount UAF, which can disclose kernel memory and confidential SEV guest ciphertext via broken owner/mirror bookkeeping.\nI:H - List corruption and mistaken kvm_put_kvm() on the wrong KVM object provide exploitable heap corruption and control over SEV encryption context lifetime, enabling arbitrary host memory modification.\nA:H - Corrupted mirror lists, use-after-free on struct kvm, or premature destruction of an active SEV owner/mirror reliably triggers kernel oops/panic and denial of host service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:40:32.287Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/7943ec3a6d0e7e0a2eb4943300bce089ac3e8c3e"
},
{
"url": "https://git.kernel.org/stable/c/28afde1edbd8b20058cbf4d75fb57876471ec334"
},
{
"url": "https://git.kernel.org/stable/c/328ab4fabe05af004d886659f8744076e320ddce"
},
{
"url": "https://git.kernel.org/stable/c/47976eaaf0a4eb46dade48b3246779090db9e3ec"
},
{
"url": "https://git.kernel.org/stable/c/d728baba0f20e49439fc7831bf3e4e7dee82161a"
},
{
"url": "https://git.kernel.org/stable/c/1d78d33275ef2a16c6d080910b291d0a97a0e613"
}
],
"title": "KVM: SVM: Serialize accesses to the owner and mirror list with separate lock",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74607",
"datePublished": "2026-08-22T15:31:54.554Z",
"dateReserved": "2026-08-15T05:44:03.920Z",
"dateUpdated": "2026-08-25T05:40:32.287Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68368 (GCVE-0-2026-68368)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb()
When unpacking host-supplied NTBs, ncm_unwrap_ntb() checks datagram length
against frame_max but does not verify that the datagram fits within the
declared block length. Additionally, when decoding multiple NTBs from a
single socket buffer, subsequent block lengths are not checked against the
actual remaining buffer data.
With these checks missing, a malicious USB host can specify datagram
offsets and lengths that point beyond the block, or supply secondary NTB
headers declaring lengths larger than the buffer. skb_put_data() then
copies adjacent kernel memory from skb_shared_info into the network skb.
Fix this by verifying that sufficient buffer space remains for the NTB
header before parsing, handling zero-length block declarations, ensuring
that block lengths never exceed the remaining buffer space, and verifying
that each datagram payload stays strictly within the block boundary.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 2b74b0a04d3e9f9f08ff026e5663dce88ff94e52 Version: 2b74b0a04d3e9f9f08ff026e5663dce88ff94e52 Version: 2b74b0a04d3e9f9f08ff026e5663dce88ff94e52 Version: 2b74b0a04d3e9f9f08ff026e5663dce88ff94e52 Version: 2b74b0a04d3e9f9f08ff026e5663dce88ff94e52 Version: 2b74b0a04d3e9f9f08ff026e5663dce88ff94e52 Version: 2b74b0a04d3e9f9f08ff026e5663dce88ff94e52 Version: 2b74b0a04d3e9f9f08ff026e5663dce88ff94e52 Version: f7e0611e207d8908c4f2858e244370529a76dbf7 Version: b88ad6e714284b33a47834f5f2a294c2b37c66aa Version: 471b23586387a32857778c511be60ab31c98dcfd Version: 4f529c4d1e436230d3af7c09a3239677a14d2b46 Version: ae6a5394d9fbe118bc95cfe376d6a9d91d7547e8 Version: 5bdf93a2f5459f944b416b188178ca4a92fd206f Version: ff3ba016263ee93a1c6209bf5ab1599de7ab1512 Version: e7ca00f35d8a17af1ae19d529193ebc21bfda164 Version: 4.9.235 ≤ Version: 4.14.196 ≤ Version: 4.19.143 ≤ Version: 5.4.62 ≤ Version: 5.8.6 ≤ Version: 4.14.328 ≤ Version: 4.19.297 ≤ Version: 5.4.259 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/gadget/function/f_ncm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "35d15bbaec0557330e774ec31412ef508de6e0e0",
"status": "affected",
"version": "2b74b0a04d3e9f9f08ff026e5663dce88ff94e52",
"versionType": "git"
},
{
"lessThan": "6b2be489eaa6293e60549005d91f15ceb150510f",
"status": "affected",
"version": "2b74b0a04d3e9f9f08ff026e5663dce88ff94e52",
"versionType": "git"
},
{
"lessThan": "f87ed889f0f7417b8938c98d8833f559b755373c",
"status": "affected",
"version": "2b74b0a04d3e9f9f08ff026e5663dce88ff94e52",
"versionType": "git"
},
{
"lessThan": "e07751d0527ccc2a1c32eb0b0b7da3b4b9b5381f",
"status": "affected",
"version": "2b74b0a04d3e9f9f08ff026e5663dce88ff94e52",
"versionType": "git"
},
{
"lessThan": "fff1059d139ef798bab917990524faaf25854ca8",
"status": "affected",
"version": "2b74b0a04d3e9f9f08ff026e5663dce88ff94e52",
"versionType": "git"
},
{
"lessThan": "40c706a0224bde194667e3378c689b542fec4b44",
"status": "affected",
"version": "2b74b0a04d3e9f9f08ff026e5663dce88ff94e52",
"versionType": "git"
},
{
"lessThan": "41fd5f2fb0027d3773ae949e3247c2e0a2a7fe5c",
"status": "affected",
"version": "2b74b0a04d3e9f9f08ff026e5663dce88ff94e52",
"versionType": "git"
},
{
"lessThan": "1febec7e47cdcd01f43fb0211094e3010474666e",
"status": "affected",
"version": "2b74b0a04d3e9f9f08ff026e5663dce88ff94e52",
"versionType": "git"
},
{
"status": "affected",
"version": "f7e0611e207d8908c4f2858e244370529a76dbf7",
"versionType": "git"
},
{
"status": "affected",
"version": "b88ad6e714284b33a47834f5f2a294c2b37c66aa",
"versionType": "git"
},
{
"status": "affected",
"version": "471b23586387a32857778c511be60ab31c98dcfd",
"versionType": "git"
},
{
"status": "affected",
"version": "4f529c4d1e436230d3af7c09a3239677a14d2b46",
"versionType": "git"
},
{
"status": "affected",
"version": "ae6a5394d9fbe118bc95cfe376d6a9d91d7547e8",
"versionType": "git"
},
{
"status": "affected",
"version": "5bdf93a2f5459f944b416b188178ca4a92fd206f",
"versionType": "git"
},
{
"status": "affected",
"version": "ff3ba016263ee93a1c6209bf5ab1599de7ab1512",
"versionType": "git"
},
{
"status": "affected",
"version": "e7ca00f35d8a17af1ae19d529193ebc21bfda164",
"versionType": "git"
},
{
"lessThan": "4.10",
"status": "affected",
"version": "4.9.235",
"versionType": "semver"
},
{
"lessThan": "4.15",
"status": "affected",
"version": "4.14.196",
"versionType": "semver"
},
{
"lessThan": "4.20",
"status": "affected",
"version": "4.19.143",
"versionType": "semver"
},
{
"lessThan": "5.5",
"status": "affected",
"version": "5.4.62",
"versionType": "semver"
},
{
"lessThan": "5.9",
"status": "affected",
"version": "5.8.6",
"versionType": "semver"
},
{
"lessThan": "4.15",
"status": "affected",
"version": "4.14.328",
"versionType": "semver"
},
{
"lessThan": "4.20",
"status": "affected",
"version": "4.19.297",
"versionType": "semver"
},
{
"lessThan": "5.5",
"status": "affected",
"version": "5.4.259",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/usb/gadget/function/f_ncm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.9"
},
{
"lessThan": "5.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.9.235",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.14.196",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.19.143",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.4.62",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.8.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.14.328",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.19.297",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.4.259",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb()\n\nWhen unpacking host-supplied NTBs, ncm_unwrap_ntb() checks datagram length\nagainst frame_max but does not verify that the datagram fits within the\ndeclared block length. Additionally, when decoding multiple NTBs from a\nsingle socket buffer, subsequent block lengths are not checked against the\nactual remaining buffer data.\n\nWith these checks missing, a malicious USB host can specify datagram\noffsets and lengths that point beyond the block, or supply secondary NTB\nheaders declaring lengths larger than the buffer. skb_put_data() then\ncopies adjacent kernel memory from skb_shared_info into the network skb.\n\nFix this by verifying that sufficient buffer space remains for the NTB\nheader before parsing, handling zero-length block declarations, ensuring\nthat block lengths never exceed the remaining buffer space, and verifying\nthat each datagram payload stays strictly within the block boundary."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:26.235Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/35d15bbaec0557330e774ec31412ef508de6e0e0"
},
{
"url": "https://git.kernel.org/stable/c/6b2be489eaa6293e60549005d91f15ceb150510f"
},
{
"url": "https://git.kernel.org/stable/c/f87ed889f0f7417b8938c98d8833f559b755373c"
},
{
"url": "https://git.kernel.org/stable/c/e07751d0527ccc2a1c32eb0b0b7da3b4b9b5381f"
},
{
"url": "https://git.kernel.org/stable/c/fff1059d139ef798bab917990524faaf25854ca8"
},
{
"url": "https://git.kernel.org/stable/c/40c706a0224bde194667e3378c689b542fec4b44"
},
{
"url": "https://git.kernel.org/stable/c/41fd5f2fb0027d3773ae949e3247c2e0a2a7fe5c"
},
{
"url": "https://git.kernel.org/stable/c/1febec7e47cdcd01f43fb0211094e3010474666e"
}
],
"title": "usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68368",
"datePublished": "2026-08-10T12:03:45.579Z",
"dateReserved": "2026-07-30T09:28:09.386Z",
"dateUpdated": "2026-08-19T16:34:26.235Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68353 (GCVE-0-2026-68353)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler
The firmware-controlled num_msg field (u8, 0-255) drives the loop in
ath6kl_wmi_tx_complete_event_rx() without validation against the buffer
length. This allows out-of-bounds reads of up to 1020 bytes past the
WMI event buffer when the firmware sends an inflated num_msg.
Add a check that the buffer is large enough to hold the fixed struct
and the num_msg variable-length entries.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/ath/ath6kl/wmi.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "5297299c3fa6133275db0be99d69cd759b6cbfe9",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "35196a07603f8c94a4943093bc26d5b5826285f8",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "0e0fc04af9b443c6b425f00fb604ff599bc80d1d",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "69ac7ba3a3df6654e7daa82674575a8c4a1a63ea",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "289edc3c71344b89e6522891147cfb8f61b088bb",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "eb636fbc443149b3501c3f97e26225ddcb314a0f",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "c38b0d5c661951b5dd082bdf31f8a57a0ce6e540",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "3a21c89215cc18f1a97c5e5bfd1da6d4f3d44495",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/ath/ath6kl/wmi.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.2"
},
{
"lessThan": "3.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler\n\nThe firmware-controlled num_msg field (u8, 0-255) drives the loop in\nath6kl_wmi_tx_complete_event_rx() without validation against the buffer\nlength. This allows out-of-bounds reads of up to 1020 bytes past the\nWMI event buffer when the firmware sends an inflated num_msg.\n\nAdd a check that the buffer is large enough to hold the fixed struct\nand the num_msg variable-length entries."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The vulnerable handler parses WMI control events delivered by the ath6kl AR600x wireless firmware over SDIO/USB; an attacker on the same wireless segment who subverts or influences the wireless device\u0027s firmware supplies the malformed event, matching the adjacent-network vector used for other ath driver event-parsing flaws.\nAC:L - Triggering requires only a WMI_TX_COMPLETE_EVENTID event whose payload is shorter than num_msg * 4 bytes; the loop bound is taken directly from the event with no validation, so the read happens deterministically every time.\nPR:N - The event is processed in the driver\u0027s asynchronous control-message receive path with no capability check, no syscall entry, and no authentication or association gate; the attacker needs no credentials on the target system.\nUI:N - The WMI event is handled automatically by the driver as soon as the interface is running; no victim action such as opening a file or issuing a command is needed.\nS:U - The out-of-bounds read stays within the kernel\u0027s own memory and security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - Up to 1020 bytes past the event buffer are read and the contents are emitted through ath6kl_dbg() into the kernel log on debug builds, disclosing adjacent kernel heap data well beyond a small bounded read.\nI:N - The loop only reads and prints the out-of-bounds entries; there is no write to kernel memory and no attacker-controlled pointer is dereferenced for modification.\nA:H - The read can walk past the end of the slab allocation into unmapped or redzoned memory, producing an oops or a KASAN panic on hardened/debug kernels and thus a full loss of availability."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:58.283Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/5297299c3fa6133275db0be99d69cd759b6cbfe9"
},
{
"url": "https://git.kernel.org/stable/c/35196a07603f8c94a4943093bc26d5b5826285f8"
},
{
"url": "https://git.kernel.org/stable/c/0e0fc04af9b443c6b425f00fb604ff599bc80d1d"
},
{
"url": "https://git.kernel.org/stable/c/69ac7ba3a3df6654e7daa82674575a8c4a1a63ea"
},
{
"url": "https://git.kernel.org/stable/c/289edc3c71344b89e6522891147cfb8f61b088bb"
},
{
"url": "https://git.kernel.org/stable/c/eb636fbc443149b3501c3f97e26225ddcb314a0f"
},
{
"url": "https://git.kernel.org/stable/c/c38b0d5c661951b5dd082bdf31f8a57a0ce6e540"
},
{
"url": "https://git.kernel.org/stable/c/3a21c89215cc18f1a97c5e5bfd1da6d4f3d44495"
}
],
"title": "wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68353",
"datePublished": "2026-08-10T12:03:30.330Z",
"dateReserved": "2026-07-30T09:28:09.385Z",
"dateUpdated": "2026-08-19T16:33:58.283Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80743 (GCVE-0-2026-80743)
Vulnerability from cvelistv5
Published
2026-09-03 08:26
Modified
2026-09-03 08:26
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ASoC: xilinx: formatter_pcm: pass aud_drv_data to irq handlers
The irq handlers take a struct device pointer and call
dev_get_drvdata() to obtain the driver data. However, the driver
data is only set at the end of probe, after devm_request_irq(),
so an interrupt taken in between causes the handlers to pass a
NULL pointer to readl() and crash.
Pass the private data directly as the devm_request_irq() argument
instead of the device pointer, matching what the handlers expect.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 6f6c3c36f0917be24587eeba818ab4fdfcb5465a Version: 6f6c3c36f0917be24587eeba818ab4fdfcb5465a Version: 6f6c3c36f0917be24587eeba818ab4fdfcb5465a Version: 6f6c3c36f0917be24587eeba818ab4fdfcb5465a Version: 6f6c3c36f0917be24587eeba818ab4fdfcb5465a Version: 6f6c3c36f0917be24587eeba818ab4fdfcb5465a Version: 6f6c3c36f0917be24587eeba818ab4fdfcb5465a Version: 6f6c3c36f0917be24587eeba818ab4fdfcb5465a |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"sound/soc/xilinx/xlnx_formatter_pcm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "7d857aec162fb02d10ce326aecc1ac7509c31f43",
"status": "affected",
"version": "6f6c3c36f0917be24587eeba818ab4fdfcb5465a",
"versionType": "git"
},
{
"lessThan": "a85315f2eb06adc5597a7103e1910fc7d0d35ffd",
"status": "affected",
"version": "6f6c3c36f0917be24587eeba818ab4fdfcb5465a",
"versionType": "git"
},
{
"lessThan": "721cfeb0b9572084435695ae535411b921d1ea68",
"status": "affected",
"version": "6f6c3c36f0917be24587eeba818ab4fdfcb5465a",
"versionType": "git"
},
{
"lessThan": "b4ef887bee4d3c177adac5d1eab8b2de31b08ac3",
"status": "affected",
"version": "6f6c3c36f0917be24587eeba818ab4fdfcb5465a",
"versionType": "git"
},
{
"lessThan": "0d58a70b6dc7b65772e3ef7c43beb91882cf9ed5",
"status": "affected",
"version": "6f6c3c36f0917be24587eeba818ab4fdfcb5465a",
"versionType": "git"
},
{
"lessThan": "f51a540b14eecb8667bbe450192318271b87631e",
"status": "affected",
"version": "6f6c3c36f0917be24587eeba818ab4fdfcb5465a",
"versionType": "git"
},
{
"lessThan": "09e4c486348e176c083f8bee9169ae8f408cf8d1",
"status": "affected",
"version": "6f6c3c36f0917be24587eeba818ab4fdfcb5465a",
"versionType": "git"
},
{
"lessThan": "f12afefb7b01f94d6d66d397f323a9914edbf70e",
"status": "affected",
"version": "6f6c3c36f0917be24587eeba818ab4fdfcb5465a",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"sound/soc/xilinx/xlnx_formatter_pcm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.1"
},
{
"lessThan": "5.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.46",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.10",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: xilinx: formatter_pcm: pass aud_drv_data to irq handlers\n\nThe irq handlers take a struct device pointer and call\ndev_get_drvdata() to obtain the driver data. However, the driver\ndata is only set at the end of probe, after devm_request_irq(),\nso an interrupt taken in between causes the handlers to pass a\nNULL pointer to readl() and crash.\n\nPass the private data directly as the devm_request_irq() argument\ninstead of the device pointer, matching what the handlers expect."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-03T08:26:26.524Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/7d857aec162fb02d10ce326aecc1ac7509c31f43"
},
{
"url": "https://git.kernel.org/stable/c/a85315f2eb06adc5597a7103e1910fc7d0d35ffd"
},
{
"url": "https://git.kernel.org/stable/c/721cfeb0b9572084435695ae535411b921d1ea68"
},
{
"url": "https://git.kernel.org/stable/c/b4ef887bee4d3c177adac5d1eab8b2de31b08ac3"
},
{
"url": "https://git.kernel.org/stable/c/0d58a70b6dc7b65772e3ef7c43beb91882cf9ed5"
},
{
"url": "https://git.kernel.org/stable/c/f51a540b14eecb8667bbe450192318271b87631e"
},
{
"url": "https://git.kernel.org/stable/c/09e4c486348e176c083f8bee9169ae8f408cf8d1"
},
{
"url": "https://git.kernel.org/stable/c/f12afefb7b01f94d6d66d397f323a9914edbf70e"
}
],
"title": "ASoC: xilinx: formatter_pcm: pass aud_drv_data to irq handlers",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80743",
"datePublished": "2026-09-03T08:26:26.524Z",
"dateReserved": "2026-08-26T14:34:25.790Z",
"dateUpdated": "2026-09-03T08:26:26.524Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74625 (GCVE-0-2026-74625)
Vulnerability from cvelistv5
Published
2026-08-22 15:32
Modified
2026-08-25 05:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
netfilter: bridge: release template ct on non-IP path
A bridge nftables ct zone set rule can attach a conntrack template to
an skb before nf_ct_bridge_pre() sees it. For non-IPv4 and non-IPv6
EtherTypes, nf_ct_bridge_pre() currently overwrites skb->_nfct with
IP_CT_UNTRACKED without releasing the existing template reference.
That makes the per-cpu template, and any temporary templates allocated
for concurrent use, unreachable and leaks memory until the host runs out
of slab.
Reset the skb conntrack state before marking the frame untracked so the
existing template reference is dropped on the non-IP path.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 3c171f496ef57774f8e5d509923372549734877f Version: 3c171f496ef57774f8e5d509923372549734877f Version: 3c171f496ef57774f8e5d509923372549734877f Version: 3c171f496ef57774f8e5d509923372549734877f Version: 3c171f496ef57774f8e5d509923372549734877f Version: 3c171f496ef57774f8e5d509923372549734877f Version: 3c171f496ef57774f8e5d509923372549734877f Version: 3c171f496ef57774f8e5d509923372549734877f |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/bridge/netfilter/nf_conntrack_bridge.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "fc90df37540627d092af770215fb4b7befe9409b",
"status": "affected",
"version": "3c171f496ef57774f8e5d509923372549734877f",
"versionType": "git"
},
{
"lessThan": "daa6e070f8e1e7a4dddec8b64ca37663f8cda917",
"status": "affected",
"version": "3c171f496ef57774f8e5d509923372549734877f",
"versionType": "git"
},
{
"lessThan": "bd7b16494dacf87e9336a1dcfdada83b9e40edd6",
"status": "affected",
"version": "3c171f496ef57774f8e5d509923372549734877f",
"versionType": "git"
},
{
"lessThan": "6ea88401e10e04e0b3bb7a7adea54932fb60b93b",
"status": "affected",
"version": "3c171f496ef57774f8e5d509923372549734877f",
"versionType": "git"
},
{
"lessThan": "46d559f00b1ab1d114f92d2f16c5ef0093b3b9dd",
"status": "affected",
"version": "3c171f496ef57774f8e5d509923372549734877f",
"versionType": "git"
},
{
"lessThan": "c58d34fe8b7e47bb0b350a7625023b1261342be5",
"status": "affected",
"version": "3c171f496ef57774f8e5d509923372549734877f",
"versionType": "git"
},
{
"lessThan": "7cff440d702616022769f2643168d7f9820547a0",
"status": "affected",
"version": "3c171f496ef57774f8e5d509923372549734877f",
"versionType": "git"
},
{
"lessThan": "d45cc8020d7c0a9f01dee42ff5c40bc14c9af72f",
"status": "affected",
"version": "3c171f496ef57774f8e5d509923372549734877f",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/bridge/netfilter/nf_conntrack_bridge.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.3"
},
{
"lessThan": "5.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: bridge: release template ct on non-IP path\n\nA bridge nftables ct zone set rule can attach a conntrack template to\nan skb before nf_ct_bridge_pre() sees it. For non-IPv4 and non-IPv6\nEtherTypes, nf_ct_bridge_pre() currently overwrites skb-\u003e_nfct with\nIP_CT_UNTRACKED without releasing the existing template reference.\n\nThat makes the per-cpu template, and any temporary templates allocated\nfor concurrent use, unreachable and leaks memory until the host runs out\nof slab.\n\nReset the skb conntrack state before marking the frame untracked so the\nexisting template reference is dropped on the non-IP path."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - Non-IP L2 frames (ARP/LLDP) injected into a Linux bridge reach NF_BR_PRE_ROUTING via br_handle_frame\u2192nf_hook_bridge_pre; on overlay/container hosts (VXLAN/GRE bridges in Docker/k8s/OpenStack) remote peers can deliver those frames across routed networks to the victim bridge port.\nAC:L - Once a bridge nftables ct zone set rule runs before NF_IP_PRI_CONNTRACK (-200), every non-IPv4/IPv6 EtherType frame deterministically leaks template references; the attacker controls rule priority, zone value, and can flood ARP/LLDP to accelerate the leak without races.\nPR:N - On bridge firewalls/routers with deployed nftables ct zone marking, exploitation needs only unauthenticated L2 packet delivery\u2014no host UID, capability, or namespace privilege; CAP_NET_ADMIN (obtainable via user namespaces) is an alternate Low path for self-setup but not required on pre-configured appliances.\nUI:N - Bridge netfilter processes received frames automatically in softirq; no victim mount, click, or administrative action is required beyond normal bridge forwarding of attacker-supplied non-IP traffic.\nS:U - Impact is unbounded kernel slab consumption from leaked nf_conn template objects within the host kernel; it does not cross VM, container, IOMMU, or hypervisor security boundaries.\nC:N - The bug is a missing nf_conntrack_put()\u2014a reference-count leak\u2014not a use-after-free, out-of-bounds read, or disclosure primitive; orphaned templates are unreachable and their contents are never returned to the attacker.\nI:N - Only template reference counts are leaked via skb-\u003e_nfct overwrite; no heap corruption, type confusion, or attacker-controlled writes occur, so integrity cannot be compromised beyond availability loss from memory pressure.\nA:H - Each leaked per-CPU and temporary conntrack template is never freed; sustained non-IP frame flooding can exhaust kernel slab until OOM, causing severe host unavailability or panic on memory-allocation failure paths."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:40:48.341Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/fc90df37540627d092af770215fb4b7befe9409b"
},
{
"url": "https://git.kernel.org/stable/c/daa6e070f8e1e7a4dddec8b64ca37663f8cda917"
},
{
"url": "https://git.kernel.org/stable/c/bd7b16494dacf87e9336a1dcfdada83b9e40edd6"
},
{
"url": "https://git.kernel.org/stable/c/6ea88401e10e04e0b3bb7a7adea54932fb60b93b"
},
{
"url": "https://git.kernel.org/stable/c/46d559f00b1ab1d114f92d2f16c5ef0093b3b9dd"
},
{
"url": "https://git.kernel.org/stable/c/c58d34fe8b7e47bb0b350a7625023b1261342be5"
},
{
"url": "https://git.kernel.org/stable/c/7cff440d702616022769f2643168d7f9820547a0"
},
{
"url": "https://git.kernel.org/stable/c/d45cc8020d7c0a9f01dee42ff5c40bc14c9af72f"
}
],
"title": "netfilter: bridge: release template ct on non-IP path",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74625",
"datePublished": "2026-08-22T15:32:07.929Z",
"dateReserved": "2026-08-15T05:44:03.921Z",
"dateUpdated": "2026-08-25T05:40:48.341Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80800 (GCVE-0-2026-80800)
Vulnerability from cvelistv5
Published
2026-09-04 15:13
Modified
2026-09-04 15:13
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
nfc: llcp: bound the connect_sn TLV walk to the skb
Commit 27256cdb290e ("nfc: llcp: bound SNL TLV parsing to the skb and
add length checks") fixed the unbounded TLV walk in nfc_llcp_recv_snl(),
and commit d8bd2dedbde5 ("nfc: llcp: fix OOB read and u8 offset wrap in
TLV parsers") subsequently bounded nfc_llcp_parse_gb_tlv() and
nfc_llcp_parse_connection_tlv(). One sibling parser sharing the same
pattern remains unbounded: nfc_llcp_connect_sn().
nfc_llcp_connect_sn() walks a TLV list, reading a two-byte header
(type, length) followed by length bytes of value, without checking that
the two header bytes or the declared length stay within the buffer. It
returns a pointer to a service name of up to 255 bytes that may point
past the end of the skb; it is subsequently consumed by memcmp() in
nfc_llcp_sock_from_sn(). In addition tlv_array_len was computed as
"skb->len - LLCP_HEADER_SIZE" in size_t, so a CONNECT/CC frame shorter
than the LLCP header underflows to a huge length and the walk runs far
past the buffer.
nfc_llcp_connect_sn() is reachable from nfc_llcp_recv_connect() and
nfc_llcp_recv_cc(), i.e. from received CONNECT and CC PDUs. A nearby
NFC device can reach this without authentication; LLCP link activation
happens automatically after NFC-DEP, and the nfc_llcp_rx_skb()
dispatcher applies no minimum-length guard.
Walk the TLV list by pointer, bounded by skb_tail_pointer(skb), and
validate each declared length before use, matching the approach already
used for nfc_llcp_recv_snl(). Starting the walk at
&skb->data[LLCP_HEADER_SIZE] against the tail pointer also removes the
size_t underflow for short frames.
Found by 0sec automated security-research tooling (https://0sec.ai).
References
| URL | Tags | ||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d646960f7986fefb460a2b062d5ccc8ccfeacc3a Version: d646960f7986fefb460a2b062d5ccc8ccfeacc3a Version: d646960f7986fefb460a2b062d5ccc8ccfeacc3a Version: d646960f7986fefb460a2b062d5ccc8ccfeacc3a Version: d646960f7986fefb460a2b062d5ccc8ccfeacc3a Version: d646960f7986fefb460a2b062d5ccc8ccfeacc3a Version: d646960f7986fefb460a2b062d5ccc8ccfeacc3a Version: d646960f7986fefb460a2b062d5ccc8ccfeacc3a Version: d646960f7986fefb460a2b062d5ccc8ccfeacc3a |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/nfc/llcp_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b2ebdfe3d5b76e91f267a61cbc3f9a0e3f77071e",
"status": "affected",
"version": "d646960f7986fefb460a2b062d5ccc8ccfeacc3a",
"versionType": "git"
},
{
"lessThan": "e18d044bab6d3d0280639098c3fe6621692cbfe2",
"status": "affected",
"version": "d646960f7986fefb460a2b062d5ccc8ccfeacc3a",
"versionType": "git"
},
{
"lessThan": "65a0ec7783b06068dda6745dd689bf4a91ee64aa",
"status": "affected",
"version": "d646960f7986fefb460a2b062d5ccc8ccfeacc3a",
"versionType": "git"
},
{
"lessThan": "1964addc8dd535a05d5d3b55b4d1ac19ae31aa65",
"status": "affected",
"version": "d646960f7986fefb460a2b062d5ccc8ccfeacc3a",
"versionType": "git"
},
{
"lessThan": "389986fd79e4d43f971a03b512645a1bb63c982f",
"status": "affected",
"version": "d646960f7986fefb460a2b062d5ccc8ccfeacc3a",
"versionType": "git"
},
{
"lessThan": "e87527b506c40db9af528714b7b1240918eb80fc",
"status": "affected",
"version": "d646960f7986fefb460a2b062d5ccc8ccfeacc3a",
"versionType": "git"
},
{
"lessThan": "22e5177ba1196a0b272a6a46c2575eb940a939c4",
"status": "affected",
"version": "d646960f7986fefb460a2b062d5ccc8ccfeacc3a",
"versionType": "git"
},
{
"lessThan": "0cfbdb0e13ab5b0765d77f96af67eb879cbc9736",
"status": "affected",
"version": "d646960f7986fefb460a2b062d5ccc8ccfeacc3a",
"versionType": "git"
},
{
"lessThan": "55c68ac93e7dacc0f5f608b9c39dd4ff48cf28e8",
"status": "affected",
"version": "d646960f7986fefb460a2b062d5ccc8ccfeacc3a",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/nfc/llcp_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.3"
},
{
"lessThan": "3.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.267",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.218",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.185",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.154",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.106",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.47",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.1",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.267",
"versionStartIncluding": "3.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.218",
"versionStartIncluding": "3.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.185",
"versionStartIncluding": "3.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.154",
"versionStartIncluding": "3.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.106",
"versionStartIncluding": "3.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.47",
"versionStartIncluding": "3.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.11",
"versionStartIncluding": "3.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.1",
"versionStartIncluding": "3.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "3.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: llcp: bound the connect_sn TLV walk to the skb\n\nCommit 27256cdb290e (\"nfc: llcp: bound SNL TLV parsing to the skb and\nadd length checks\") fixed the unbounded TLV walk in nfc_llcp_recv_snl(),\nand commit d8bd2dedbde5 (\"nfc: llcp: fix OOB read and u8 offset wrap in\nTLV parsers\") subsequently bounded nfc_llcp_parse_gb_tlv() and\nnfc_llcp_parse_connection_tlv(). One sibling parser sharing the same\npattern remains unbounded: nfc_llcp_connect_sn().\n\nnfc_llcp_connect_sn() walks a TLV list, reading a two-byte header\n(type, length) followed by length bytes of value, without checking that\nthe two header bytes or the declared length stay within the buffer. It\nreturns a pointer to a service name of up to 255 bytes that may point\npast the end of the skb; it is subsequently consumed by memcmp() in\nnfc_llcp_sock_from_sn(). In addition tlv_array_len was computed as\n\"skb-\u003elen - LLCP_HEADER_SIZE\" in size_t, so a CONNECT/CC frame shorter\nthan the LLCP header underflows to a huge length and the walk runs far\npast the buffer.\n\nnfc_llcp_connect_sn() is reachable from nfc_llcp_recv_connect() and\nnfc_llcp_recv_cc(), i.e. from received CONNECT and CC PDUs. A nearby\nNFC device can reach this without authentication; LLCP link activation\nhappens automatically after NFC-DEP, and the nfc_llcp_rx_skb()\ndispatcher applies no minimum-length guard.\n\nWalk the TLV list by pointer, bounded by skb_tail_pointer(skb), and\nvalidate each declared length before use, matching the approach already\nused for nfc_llcp_recv_snl(). Starting the walk at\n\u0026skb-\u003edata[LLCP_HEADER_SIZE] against the tail pointer also removes the\nsize_t underflow for short frames.\n\nFound by 0sec automated security-research tooling (https://0sec.ai)."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T15:13:14.271Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b2ebdfe3d5b76e91f267a61cbc3f9a0e3f77071e"
},
{
"url": "https://git.kernel.org/stable/c/e18d044bab6d3d0280639098c3fe6621692cbfe2"
},
{
"url": "https://git.kernel.org/stable/c/65a0ec7783b06068dda6745dd689bf4a91ee64aa"
},
{
"url": "https://git.kernel.org/stable/c/1964addc8dd535a05d5d3b55b4d1ac19ae31aa65"
},
{
"url": "https://git.kernel.org/stable/c/389986fd79e4d43f971a03b512645a1bb63c982f"
},
{
"url": "https://git.kernel.org/stable/c/e87527b506c40db9af528714b7b1240918eb80fc"
},
{
"url": "https://git.kernel.org/stable/c/22e5177ba1196a0b272a6a46c2575eb940a939c4"
},
{
"url": "https://git.kernel.org/stable/c/0cfbdb0e13ab5b0765d77f96af67eb879cbc9736"
},
{
"url": "https://git.kernel.org/stable/c/55c68ac93e7dacc0f5f608b9c39dd4ff48cf28e8"
}
],
"title": "nfc: llcp: bound the connect_sn TLV walk to the skb",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80800",
"datePublished": "2026-09-04T15:13:14.271Z",
"dateReserved": "2026-08-26T14:34:25.793Z",
"dateUpdated": "2026-09-04T15:13:14.271Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74510 (GCVE-0-2026-74510)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-23 12:47
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: mgmt: fix UAF in pair command cancellation
The pairing completion and authentication failure callbacks look up the
pending MGMT_OP_PAIR_DEVICE command by walking hdev->mgmt_pending. The
lookup returned a command that was still linked on the shared pending list,
without keeping mgmt_pending_lock held for the later dereference and
removal.
A concurrent MGMT_OP_CANCEL_PAIR_DEVICE request can remove and free the
same pending command before the callback uses it. The reverse race is also
possible when cancel_pair_device() gets a command from pending_find() and a
callback removes it before the cancel path dereferences it. This can lead
to a use-after-free and a second list_del().
Make the pairing lookup helpers transfer ownership of the pending command
by removing it from hdev->mgmt_pending while holding mgmt_pending_lock.
The callbacks and cancel path then complete the command and free it
directly, so racing paths cannot find or free the same command again. Take
a temporary hci_conn reference in cancel_pair_device() because the command
completion drops the reference stored in the pending command.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: e9a416b5ce0c0f93819f55d34cf6882196e9c3b2 Version: e9a416b5ce0c0f93819f55d34cf6882196e9c3b2 Version: e9a416b5ce0c0f93819f55d34cf6882196e9c3b2 Version: e9a416b5ce0c0f93819f55d34cf6882196e9c3b2 Version: e9a416b5ce0c0f93819f55d34cf6882196e9c3b2 Version: e9a416b5ce0c0f93819f55d34cf6882196e9c3b2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/bluetooth/mgmt.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "50af4280a587c9971b5388cbc438f1324e626b7b",
"status": "affected",
"version": "e9a416b5ce0c0f93819f55d34cf6882196e9c3b2",
"versionType": "git"
},
{
"lessThan": "86ed4dd6548ccf277bc691bc912ca06e76b9d80c",
"status": "affected",
"version": "e9a416b5ce0c0f93819f55d34cf6882196e9c3b2",
"versionType": "git"
},
{
"lessThan": "7c2a152a897cd1c184b2051484d4f74d803e7f4a",
"status": "affected",
"version": "e9a416b5ce0c0f93819f55d34cf6882196e9c3b2",
"versionType": "git"
},
{
"lessThan": "c569def320aa8b1fde89227e2ea96606790fd86d",
"status": "affected",
"version": "e9a416b5ce0c0f93819f55d34cf6882196e9c3b2",
"versionType": "git"
},
{
"lessThan": "51be7280980fddc90ebe874a69c2fe8ab02bb46a",
"status": "affected",
"version": "e9a416b5ce0c0f93819f55d34cf6882196e9c3b2",
"versionType": "git"
},
{
"lessThan": "d0a7b48ad0921bd88effaee10bf970ab1d5d0ddd",
"status": "affected",
"version": "e9a416b5ce0c0f93819f55d34cf6882196e9c3b2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/bluetooth/mgmt.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.39"
},
{
"lessThan": "2.6.39",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "2.6.39",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "2.6.39",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "2.6.39",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "2.6.39",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "2.6.39",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.39",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: mgmt: fix UAF in pair command cancellation\n\nThe pairing completion and authentication failure callbacks look up the\npending MGMT_OP_PAIR_DEVICE command by walking hdev-\u003emgmt_pending. The\nlookup returned a command that was still linked on the shared pending list,\nwithout keeping mgmt_pending_lock held for the later dereference and\nremoval.\n\nA concurrent MGMT_OP_CANCEL_PAIR_DEVICE request can remove and free the\nsame pending command before the callback uses it. The reverse race is also\npossible when cancel_pair_device() gets a command from pending_find() and a\ncallback removes it before the cancel path dereferences it. This can lead\nto a use-after-free and a second list_del().\n\nMake the pairing lookup helpers transfer ownership of the pending command\nby removing it from hdev-\u003emgmt_pending while holding mgmt_pending_lock.\nThe callbacks and cancel path then complete the command and free it\ndirectly, so racing paths cannot find or free the same command again. Take\na temporary hci_conn reference in cancel_pair_device() because the command\ncompletion drops the reference stored in the pending command."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The UAF is triggered through local AF_BLUETOOTH HCI_CHANNEL_CONTROL management commands (hci_sock_bind/sendmsg -\u003e hci_mgmt_cmd -\u003e pair_device/cancel_pair_device); remote Bluetooth peers cannot issue MGMT_OP_PAIR_DEVICE or MGMT_OP_CANCEL_PAIR_DEVICE over the air.\nAC:L - An attacker controls the race by concurrently issuing MGMT_OP_PAIR_DEVICE and MGMT_OP_CANCEL_PAIR_DEVICE from threads or sockets they own while pairing HCI callbacks fire, and can retry until cancel and completion/auth/SMP paths interleave on the same pending command.\nPR:L - pair_device and cancel_pair_device lack HCI_MGMT_UNTRUSTED and require HCI_SOCK_TRUSTED (CAP_NET_ADMIN at bind); per kernel CNA guidance CAP_NET_ADMIN reachable via unprivileged user namespaces (unshare -Urn) maps to PR:L, consistent with similar Bluetooth mgmt UAF scores.\nUI:N - No victim interaction is required beyond a powered Bluetooth controller; the attacker directly sends the conflicting PAIR_DEVICE and CANCEL_PAIR_DEVICE management commands that create the pending entry and race the unlocked find_pairing/pending_find paths against completion callbacks.\nS:U - Exploitation corrupts kernel Bluetooth MGMT heap objects (mgmt_pending_cmd) within the same host kernel security authority; this is standard local kernel memory corruption, not a VM, IOMMU, or cross-authority boundary escape.\nC:H - Use-after-free of mgmt_pending_cmd when find_pairing or pending_find returns a still-linked command without holding mgmt_pending_lock through later dereference and mgmt_pending_remove, enabling arbitrary kernel memory disclosure via slab reuse of the freed object.\nI:H - Slab UAF and double list_del on mgmt_pending_cmd during concurrent cancel_pair_device and pairing/auth/SMP completion callbacks provide attacker-influenced heap corruption primitives exploitable for arbitrary kernel writes and control-flow hijacking per kernel UAF guidance.\nA:H - Dereferencing or list_del on a freed mgmt_pending_cmd during the cancel versus callback race causes kernel oops or panic; repeated concurrent PAIR_DEVICE and CANCEL_PAIR_DEVICE commands during active pairing can reliably crash or hang the system."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:47:31.049Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/50af4280a587c9971b5388cbc438f1324e626b7b"
},
{
"url": "https://git.kernel.org/stable/c/86ed4dd6548ccf277bc691bc912ca06e76b9d80c"
},
{
"url": "https://git.kernel.org/stable/c/7c2a152a897cd1c184b2051484d4f74d803e7f4a"
},
{
"url": "https://git.kernel.org/stable/c/c569def320aa8b1fde89227e2ea96606790fd86d"
},
{
"url": "https://git.kernel.org/stable/c/51be7280980fddc90ebe874a69c2fe8ab02bb46a"
},
{
"url": "https://git.kernel.org/stable/c/d0a7b48ad0921bd88effaee10bf970ab1d5d0ddd"
}
],
"title": "Bluetooth: mgmt: fix UAF in pair command cancellation",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74510",
"datePublished": "2026-08-15T12:27:32.503Z",
"dateReserved": "2026-08-15T05:44:03.909Z",
"dateUpdated": "2026-08-23T12:47:31.049Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68255 (GCVE-0-2026-68255)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/virtio: bound EDID block reads to the response buffer
virtio_get_edid_block() validates the read offset only against the
device-supplied resp->size field, never against the fixed-size resp->edid
array. The EDID block index is driven by the device-supplied extension
count, so a malicious virtio-gpu backend can advertise a large size
together with a high block count and read far past the array into adjacent
kernel memory, which is then surfaced in the parsed EDID (an out-of-bounds
read / info leak).
Also reject any read whose end exceeds the size of the edid array.
Conforming EDID responses stay within the array and are unaffected.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: b4b01b4995fb15b55a2d067eb405917f5ab32709 Version: b4b01b4995fb15b55a2d067eb405917f5ab32709 Version: b4b01b4995fb15b55a2d067eb405917f5ab32709 Version: b4b01b4995fb15b55a2d067eb405917f5ab32709 Version: b4b01b4995fb15b55a2d067eb405917f5ab32709 Version: b4b01b4995fb15b55a2d067eb405917f5ab32709 Version: b4b01b4995fb15b55a2d067eb405917f5ab32709 Version: b4b01b4995fb15b55a2d067eb405917f5ab32709 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/virtio/virtgpu_vq.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "65ce911f341ad8ff0c08922eff5bb6db75666eb0",
"status": "affected",
"version": "b4b01b4995fb15b55a2d067eb405917f5ab32709",
"versionType": "git"
},
{
"lessThan": "64bedd2758eccbc74d39f7006a7ec16fa39dc901",
"status": "affected",
"version": "b4b01b4995fb15b55a2d067eb405917f5ab32709",
"versionType": "git"
},
{
"lessThan": "3f506a85a905b080cadc029a1651a310479090a6",
"status": "affected",
"version": "b4b01b4995fb15b55a2d067eb405917f5ab32709",
"versionType": "git"
},
{
"lessThan": "9fc2a017c5d597937e0c28b9a9669844aa796c42",
"status": "affected",
"version": "b4b01b4995fb15b55a2d067eb405917f5ab32709",
"versionType": "git"
},
{
"lessThan": "2757e6e803092cf0aeaf4b735e16b5d3bdc705c5",
"status": "affected",
"version": "b4b01b4995fb15b55a2d067eb405917f5ab32709",
"versionType": "git"
},
{
"lessThan": "35be0e2c6862abcd5e5f5445261f1fd910d4a9b4",
"status": "affected",
"version": "b4b01b4995fb15b55a2d067eb405917f5ab32709",
"versionType": "git"
},
{
"lessThan": "375c1934ef0196d3b6d3a1eae3232bef8dae7bf7",
"status": "affected",
"version": "b4b01b4995fb15b55a2d067eb405917f5ab32709",
"versionType": "git"
},
{
"lessThan": "4e1a53892ba7f8a3e1da6bfc53c83ae7c812dccd",
"status": "affected",
"version": "b4b01b4995fb15b55a2d067eb405917f5ab32709",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/virtio/virtgpu_vq.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.0"
},
{
"lessThan": "5.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/virtio: bound EDID block reads to the response buffer\n\nvirtio_get_edid_block() validates the read offset only against the\ndevice-supplied resp-\u003esize field, never against the fixed-size resp-\u003eedid\narray. The EDID block index is driven by the device-supplied extension\ncount, so a malicious virtio-gpu backend can advertise a large size\ntogether with a high block count and read far past the array into adjacent\nkernel memory, which is then surfaced in the parsed EDID (an out-of-bounds\nread / info leak).\n\nAlso reject any read whose end exceeds the size of the edid array.\nConforming EDID responses stay within the array and are unaffected."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.7,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The attacker is a malicious or compromised virtio-gpu backend (host/hypervisor device emulation or a vhost-user device process) supplying crafted EDID responses over the virtqueue; this is device-to-guest-kernel access, not remote network access.\nAC:L - The device fully controls resp-\u003esize, the EDID extension count and the timing of the read by raising VIRTIO_GPU_EVENT_DISPLAY config-change interrupts, so it can trigger the out-of-bounds read reliably and repeatedly with no conditions outside its control.\nPR:N - No guest credentials are needed at all: the vulnerable path runs in the virtio-gpu probe and the config-changed workqueue in kernel context, driven purely by device responses.\nUI:N - EDID re-reads are initiated automatically at probe and on device-raised display events; no guest user has to open, mount or interact with anything.\nS:U - The out-of-bounds read and the resulting disclosure both occur within the guest kernel\u0027s own security authority; no IOMMU, VM or sandbox boundary is crossed by the impact itself.\nC:H - Block indices up to 255 give start offsets of ~32 KB past the 1024-byte resp-\u003eedid array, reading far beyond the kmalloc\u0027d response object into adjacent kernel heap memory, which is then surfaced as parsed EDID via the connector blob property and world-readable sysfs edid file, and hex-dumped for bad blocks.\nI:N - Destination buffers in _drm_do_get_edid() are allocated from the block count, so the flaw is strictly an over-read of the response buffer with no out-of-bounds write or kernel data modification.\nA:H - The memcpy can walk tens of kilobytes past the slab object into unmapped or guarded memory, causing an oops/panic (and an immediate BUG under KASAN/hardened builds), and the device can repeat it at will."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:13.247Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/65ce911f341ad8ff0c08922eff5bb6db75666eb0"
},
{
"url": "https://git.kernel.org/stable/c/64bedd2758eccbc74d39f7006a7ec16fa39dc901"
},
{
"url": "https://git.kernel.org/stable/c/3f506a85a905b080cadc029a1651a310479090a6"
},
{
"url": "https://git.kernel.org/stable/c/9fc2a017c5d597937e0c28b9a9669844aa796c42"
},
{
"url": "https://git.kernel.org/stable/c/2757e6e803092cf0aeaf4b735e16b5d3bdc705c5"
},
{
"url": "https://git.kernel.org/stable/c/35be0e2c6862abcd5e5f5445261f1fd910d4a9b4"
},
{
"url": "https://git.kernel.org/stable/c/375c1934ef0196d3b6d3a1eae3232bef8dae7bf7"
},
{
"url": "https://git.kernel.org/stable/c/4e1a53892ba7f8a3e1da6bfc53c83ae7c812dccd"
}
],
"title": "drm/virtio: bound EDID block reads to the response buffer",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68255",
"datePublished": "2026-08-10T12:01:24.835Z",
"dateReserved": "2026-07-30T09:28:09.377Z",
"dateUpdated": "2026-08-23T12:46:13.247Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80539 (GCVE-0-2026-80539)
Vulnerability from cvelistv5
Published
2026-08-26 14:37
Modified
2026-08-27 12:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: disallow multiple FENCE chunks in one submit
amdgpu_cs_pass1() dispatches on chunk_id once per chunk without
rejecting repeated ids. p->uf_bo is a single-slot field, so a
submission carrying two AMDGPU_CHUNK_ID_FENCE chunks runs
amdgpu_cs_p1_user_fence() twice, and the second run overwrites
p->uf_bo with a freshly referenced BO without dropping the reference
taken by the first.
amdgpu_cs_parser_fini() only unrefs the final p->uf_bo, so every FENCE
chunk but the last leaks a BO reference. The leaked BO outlives handle
close and process exit.
Reject duplicate FENCE chunks the same way commit fec5f8e8c6bc
("drm/amdgpu: disallow multiple BO_HANDLES chunks in one submit") did
for p->bo_list.
(cherry picked from commit 665b1fc2a1845206408f9a2c6da67101789edb82)
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d38ceaf99ed015f2a0b9af3499791bd3a3daae21 Version: d38ceaf99ed015f2a0b9af3499791bd3a3daae21 Version: d38ceaf99ed015f2a0b9af3499791bd3a3daae21 Version: d38ceaf99ed015f2a0b9af3499791bd3a3daae21 Version: d38ceaf99ed015f2a0b9af3499791bd3a3daae21 Version: d38ceaf99ed015f2a0b9af3499791bd3a3daae21 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/amdgpu_cs.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "7e9954e7212042ec808b06181b365b14f00c6f0a",
"status": "affected",
"version": "d38ceaf99ed015f2a0b9af3499791bd3a3daae21",
"versionType": "git"
},
{
"lessThan": "070229262ede37d17c4ea596650deb6e5eb5d106",
"status": "affected",
"version": "d38ceaf99ed015f2a0b9af3499791bd3a3daae21",
"versionType": "git"
},
{
"lessThan": "5f46322e0b84af29e10eb951ff45bd6ea40640de",
"status": "affected",
"version": "d38ceaf99ed015f2a0b9af3499791bd3a3daae21",
"versionType": "git"
},
{
"lessThan": "71aa45f7bfe46fbc6f51e7832573ff49b6005fea",
"status": "affected",
"version": "d38ceaf99ed015f2a0b9af3499791bd3a3daae21",
"versionType": "git"
},
{
"lessThan": "e3ee74d6dbbe409eb99546a7b0a02b2782f9021d",
"status": "affected",
"version": "d38ceaf99ed015f2a0b9af3499791bd3a3daae21",
"versionType": "git"
},
{
"lessThan": "931cd1d1baeae68e8eb2c23bc1f3d8934dca6241",
"status": "affected",
"version": "d38ceaf99ed015f2a0b9af3499791bd3a3daae21",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/amdgpu_cs.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.2"
},
{
"lessThan": "4.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.185",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.185",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.46",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.10",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: disallow multiple FENCE chunks in one submit\n\namdgpu_cs_pass1() dispatches on chunk_id once per chunk without\nrejecting repeated ids. p-\u003euf_bo is a single-slot field, so a\nsubmission carrying two AMDGPU_CHUNK_ID_FENCE chunks runs\namdgpu_cs_p1_user_fence() twice, and the second run overwrites\np-\u003euf_bo with a freshly referenced BO without dropping the reference\ntaken by the first.\n\namdgpu_cs_parser_fini() only unrefs the final p-\u003euf_bo, so every FENCE\nchunk but the last leaks a BO reference. The leaked BO outlives handle\nclose and process exit.\n\nReject duplicate FENCE chunks the same way commit fec5f8e8c6bc\n(\"drm/amdgpu: disallow multiple BO_HANDLES chunks in one submit\") did\nfor p-\u003ebo_list.\n\n(cherry picked from commit 665b1fc2a1845206408f9a2c6da67101789edb82)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T12:40:05.835Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/7e9954e7212042ec808b06181b365b14f00c6f0a"
},
{
"url": "https://git.kernel.org/stable/c/070229262ede37d17c4ea596650deb6e5eb5d106"
},
{
"url": "https://git.kernel.org/stable/c/5f46322e0b84af29e10eb951ff45bd6ea40640de"
},
{
"url": "https://git.kernel.org/stable/c/71aa45f7bfe46fbc6f51e7832573ff49b6005fea"
},
{
"url": "https://git.kernel.org/stable/c/e3ee74d6dbbe409eb99546a7b0a02b2782f9021d"
},
{
"url": "https://git.kernel.org/stable/c/931cd1d1baeae68e8eb2c23bc1f3d8934dca6241"
}
],
"title": "drm/amdgpu: disallow multiple FENCE chunks in one submit",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80539",
"datePublished": "2026-08-26T14:37:13.367Z",
"dateReserved": "2026-08-26T14:34:25.765Z",
"dateUpdated": "2026-08-27T12:40:05.835Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68326 (GCVE-0-2026-68326)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: mwifiex: bound uAP association event IEs to the event buffer
mwifiex_process_uap_event() handles EVENT_UAP_STA_ASSOC by exposing the
(re)association request IEs that the firmware copies into the event:
sinfo->assoc_req_ies = &event->data[len];
len = (u8 *)sinfo->assoc_req_ies - (u8 *)&event->frame_control;
sinfo->assoc_req_ies_len = le16_to_cpu(event->len) - (u16)len;
event->len is supplied by the device firmware and is never validated,
and the subtraction is unchecked. assoc_req_ies points into
adapter->event_body[MAX_EVENT_SIZE], a fixed-size array embedded in the
kmalloc()'d struct mwifiex_adapter.
On the ap_11n_enabled path mwifiex_set_sta_ht_cap() walks these IEs with
cfg80211_find_ie(), whose for_each_element() loop dereferences each
element header. A firmware-reported event->len larger than the bytes
actually received makes assoc_req_ies_len describe IEs that extend past
event_body, so the walk reads out of the adapter slab object, a
slab-out-of-bounds read (KASAN: slab-out-of-bounds in cfg80211_find_ie).
An event->len smaller than the header instead makes the int subtraction
negative, which wraps to a huge size_t when stored in assoc_req_ies_len.
The same length is handed to cfg80211_new_sta(), so a more modest
over-claim can also copy stale event_body bytes into the
NL80211_CMD_NEW_STATION notification.
A malicious or malfunctioning mwifiex device (USB/SDIO/PCIe) can deliver
such an event while the interface is in AP/uAP mode.
Validate event->len before use: reject a length that underflows the
header or that would place the IEs outside the event_body[] buffer the
event was copied into. event->len here is struct mwifiex_assoc_event.len,
a payload field internal to this event, not the transport frame length,
so it is validated in this handler rather than at the generic
MWIFIEX_TYPE_EVENT receive path, which only sees the event cause and the
transport frame length. The bound is against event_body[MAX_EVENT_SIZE]
rather than the actually-received length because the transports store the
event differently (USB and SDIO leave the 4-byte event header in
event_skb, PCIe strips it via skb_pull), whereas event_body is the single
fixed buffer all of them copy the event into. This is the event-path
analogue of the receive-path bounds checks added in commit 119585281617
("wifi: mwifiex: Fix OOB and integer underflow when rx packets").
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: e568634ae7ac379661c90731d480e067929420a1 Version: e568634ae7ac379661c90731d480e067929420a1 Version: e568634ae7ac379661c90731d480e067929420a1 Version: e568634ae7ac379661c90731d480e067929420a1 Version: e568634ae7ac379661c90731d480e067929420a1 Version: e568634ae7ac379661c90731d480e067929420a1 Version: e568634ae7ac379661c90731d480e067929420a1 Version: e568634ae7ac379661c90731d480e067929420a1 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/marvell/mwifiex/uap_event.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a616616b938f7922a93e79bef16b4643c57c0922",
"status": "affected",
"version": "e568634ae7ac379661c90731d480e067929420a1",
"versionType": "git"
},
{
"lessThan": "1ae00b6d9a6c82eb3de151d9b04ed59e06cc100f",
"status": "affected",
"version": "e568634ae7ac379661c90731d480e067929420a1",
"versionType": "git"
},
{
"lessThan": "e7e93d3e8c240bdb70c41e79d169d74dfb442843",
"status": "affected",
"version": "e568634ae7ac379661c90731d480e067929420a1",
"versionType": "git"
},
{
"lessThan": "a3f47d7c75ddad1a14621a309286f9fae3cba191",
"status": "affected",
"version": "e568634ae7ac379661c90731d480e067929420a1",
"versionType": "git"
},
{
"lessThan": "ad26c75ae25749313248f06510ebe43b5bf4adcc",
"status": "affected",
"version": "e568634ae7ac379661c90731d480e067929420a1",
"versionType": "git"
},
{
"lessThan": "d21464d93f8ba464dc3d7b4b31c6e0adcd9f659c",
"status": "affected",
"version": "e568634ae7ac379661c90731d480e067929420a1",
"versionType": "git"
},
{
"lessThan": "b6766d7ea43edf5de9d5a572bc58b631d09efe4b",
"status": "affected",
"version": "e568634ae7ac379661c90731d480e067929420a1",
"versionType": "git"
},
{
"lessThan": "f0858bfc7d3cab411a447b88e3ef970e575032c9",
"status": "affected",
"version": "e568634ae7ac379661c90731d480e067929420a1",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/marvell/mwifiex/uap_event.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.5"
},
{
"lessThan": "3.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mwifiex: bound uAP association event IEs to the event buffer\n\nmwifiex_process_uap_event() handles EVENT_UAP_STA_ASSOC by exposing the\n(re)association request IEs that the firmware copies into the event:\n\n\tsinfo-\u003eassoc_req_ies = \u0026event-\u003edata[len];\n\tlen = (u8 *)sinfo-\u003eassoc_req_ies - (u8 *)\u0026event-\u003eframe_control;\n\tsinfo-\u003eassoc_req_ies_len = le16_to_cpu(event-\u003elen) - (u16)len;\n\nevent-\u003elen is supplied by the device firmware and is never validated,\nand the subtraction is unchecked. assoc_req_ies points into\nadapter-\u003eevent_body[MAX_EVENT_SIZE], a fixed-size array embedded in the\nkmalloc()\u0027d struct mwifiex_adapter.\n\nOn the ap_11n_enabled path mwifiex_set_sta_ht_cap() walks these IEs with\ncfg80211_find_ie(), whose for_each_element() loop dereferences each\nelement header. A firmware-reported event-\u003elen larger than the bytes\nactually received makes assoc_req_ies_len describe IEs that extend past\nevent_body, so the walk reads out of the adapter slab object, a\nslab-out-of-bounds read (KASAN: slab-out-of-bounds in cfg80211_find_ie).\nAn event-\u003elen smaller than the header instead makes the int subtraction\nnegative, which wraps to a huge size_t when stored in assoc_req_ies_len.\nThe same length is handed to cfg80211_new_sta(), so a more modest\nover-claim can also copy stale event_body bytes into the\nNL80211_CMD_NEW_STATION notification.\n\nA malicious or malfunctioning mwifiex device (USB/SDIO/PCIe) can deliver\nsuch an event while the interface is in AP/uAP mode.\n\nValidate event-\u003elen before use: reject a length that underflows the\nheader or that would place the IEs outside the event_body[] buffer the\nevent was copied into. event-\u003elen here is struct mwifiex_assoc_event.len,\na payload field internal to this event, not the transport frame length,\nso it is validated in this handler rather than at the generic\nMWIFIEX_TYPE_EVENT receive path, which only sees the event cause and the\ntransport frame length. The bound is against event_body[MAX_EVENT_SIZE]\nrather than the actually-received length because the transports store the\nevent differently (USB and SDIO leave the 4-byte event header in\nevent_skb, PCIe strips it via skb_pull), whereas event_body is the single\nfixed buffer all of them copy the event into. This is the event-path\nanalogue of the receive-path bounds checks added in commit 119585281617\n(\"wifi: mwifiex: Fix OOB and integer underflow when rx packets\")."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The event payload is the firmware\u0027s rendering of an over-the-air (re)association request received by the mwifiex uAP interface, with event-\u003elen being the TLV length covering that frame, so the triggering input comes from a station within 802.11 radio range. This matches the Adjacent treatment used for other frame/event-driven mwifiex defects (CVE-2024-46755, CVE-2023-53226).\nAC:L - No race or attacker-uncontrollable state is involved: the attacker simply sends a crafted/oversized (re)association request to the AP, and the handler parses the resulting EVENT_UAP_STA_ASSOC unconditionally. The only precondition, an mwifiex interface in AP/uAP mode with ap_11n_enabled, is the normal steady state for tethering, Chromebook SoftAP and embedded AP deployments.\nPR:N - EVENT_UAP_STA_ASSOC is generated at association time, before the WPA/EAPOL handshake, so the attacker needs no credentials on or accepted association with the target host. No host user account or capability is involved anywhere on the path.\nUI:N - The event is consumed autonomously by mwifiex_process_uap_event() in the driver\u0027s main work handler as soon as the firmware delivers it; no local user or administrator action is required beyond the AP already running.\nS:U - The out-of-bounds read, the underflowed length and the resulting corruption are all confined to the host kernel\u0027s own security authority within the mwifiex/cfg80211 code; no hypervisor, IOMMU or sandbox boundary is crossed.\nC:H - An over-claimed event-\u003elen makes assoc_req_ies_len describe memory past adapter-\u003eevent_body[MAX_EVENT_SIZE], producing a slab-out-of-bounds read in cfg80211_find_ie() and, worse, causing nla_put() to copy up to tens of kilobytes of adjacent kernel slab memory into the NL80211_CMD_NEW_STATION notification delivered to userspace \u2014 an unbounded kernel heap disclosure, not a few stray bytes.\nI:H - An event-\u003elen below the header makes the int subtraction negative and wrap in size_t; that value reaches nla_put(), where nla_total_size() of the negative length evaluates to 0 and passes the tailroom check, so __nla_put()\u0027s memcpy() runs with the negative length widened to a huge size_t \u2014 an unbounded out-of-bounds write past the netlink skb. Driver 11n/AMSDU state is also set from out-of-bounds data.\nA:H - The commit documents a reproducible KASAN slab-out-of-bounds in cfg80211_find_ie, and the underflow path drives a memcpy of a near-2^64 length that guarantees an immediate kernel panic. The condition can be re-triggered at will by repeating the association attempt."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:21.015Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a616616b938f7922a93e79bef16b4643c57c0922"
},
{
"url": "https://git.kernel.org/stable/c/1ae00b6d9a6c82eb3de151d9b04ed59e06cc100f"
},
{
"url": "https://git.kernel.org/stable/c/e7e93d3e8c240bdb70c41e79d169d74dfb442843"
},
{
"url": "https://git.kernel.org/stable/c/a3f47d7c75ddad1a14621a309286f9fae3cba191"
},
{
"url": "https://git.kernel.org/stable/c/ad26c75ae25749313248f06510ebe43b5bf4adcc"
},
{
"url": "https://git.kernel.org/stable/c/d21464d93f8ba464dc3d7b4b31c6e0adcd9f659c"
},
{
"url": "https://git.kernel.org/stable/c/b6766d7ea43edf5de9d5a572bc58b631d09efe4b"
},
{
"url": "https://git.kernel.org/stable/c/f0858bfc7d3cab411a447b88e3ef970e575032c9"
}
],
"title": "wifi: mwifiex: bound uAP association event IEs to the event buffer",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68326",
"datePublished": "2026-08-10T12:03:02.372Z",
"dateReserved": "2026-07-30T09:28:09.382Z",
"dateUpdated": "2026-08-19T16:33:21.015Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74473 (GCVE-0-2026-74473)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-19 16:37
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
vxlan: use pskb_network_may_pull() in route_shortcircuit()
route_shortcircuit() currently calls pskb_may_pull(skb, sizeof(struct iphdr))
(or ipv6hdr), which checks if bytes are available starting from skb->data.
However, in vxlan_xmit(), skb->data points to the MAC header, so
skb_network_offset(skb) is ETH_HLEN (14 bytes). Using pskb_may_pull(skb, 20)
only checks 20 bytes from skb->data (which is 14 bytes MAC header + 6 bytes of
IP header), leaving the rest of the IP header potentially un-pulled in non-linear
frags. Subsequent dereferences of ip_hdr(skb)->daddr can read beyond the pulled
linear buffer length.
Fix this by using pskb_network_may_pull(), which adds skb_network_offset(skb) to
the length check to ensure the full network header is present in the linear buffer.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: e4f67addf158f98f8197e08974966b18480dc751 Version: e4f67addf158f98f8197e08974966b18480dc751 Version: e4f67addf158f98f8197e08974966b18480dc751 Version: e4f67addf158f98f8197e08974966b18480dc751 Version: e4f67addf158f98f8197e08974966b18480dc751 Version: e4f67addf158f98f8197e08974966b18480dc751 Version: e4f67addf158f98f8197e08974966b18480dc751 Version: e4f67addf158f98f8197e08974966b18480dc751 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/vxlan/vxlan_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c419af4924c1593500a40519730ed98575d04a3e",
"status": "affected",
"version": "e4f67addf158f98f8197e08974966b18480dc751",
"versionType": "git"
},
{
"lessThan": "6bd0a3a1b5744166946f0c551a6665c3b46b05e4",
"status": "affected",
"version": "e4f67addf158f98f8197e08974966b18480dc751",
"versionType": "git"
},
{
"lessThan": "214ba43faf106cb06cd3dd30999c5c809c868b53",
"status": "affected",
"version": "e4f67addf158f98f8197e08974966b18480dc751",
"versionType": "git"
},
{
"lessThan": "42887be7c4cf283cce02cd0fb6411221167c8b6c",
"status": "affected",
"version": "e4f67addf158f98f8197e08974966b18480dc751",
"versionType": "git"
},
{
"lessThan": "aa0d31376d574ac858a40078431a77127bf04ee4",
"status": "affected",
"version": "e4f67addf158f98f8197e08974966b18480dc751",
"versionType": "git"
},
{
"lessThan": "ee799977d7941dbfb11049e17edd9eaf4f8820f7",
"status": "affected",
"version": "e4f67addf158f98f8197e08974966b18480dc751",
"versionType": "git"
},
{
"lessThan": "4f3f96e771a20263635bb5e1307c112d613b4bbd",
"status": "affected",
"version": "e4f67addf158f98f8197e08974966b18480dc751",
"versionType": "git"
},
{
"lessThan": "26bb2dd0a8839617e2c79ffbbe1923f8e4bab9fb",
"status": "affected",
"version": "e4f67addf158f98f8197e08974966b18480dc751",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/vxlan/vxlan_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.8"
},
{
"lessThan": "3.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "3.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "3.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "3.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "3.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nvxlan: use pskb_network_may_pull() in route_shortcircuit()\n\nroute_shortcircuit() currently calls pskb_may_pull(skb, sizeof(struct iphdr))\n(or ipv6hdr), which checks if bytes are available starting from skb-\u003edata.\n\nHowever, in vxlan_xmit(), skb-\u003edata points to the MAC header, so\nskb_network_offset(skb) is ETH_HLEN (14 bytes). Using pskb_may_pull(skb, 20)\nonly checks 20 bytes from skb-\u003edata (which is 14 bytes MAC header + 6 bytes of\nIP header), leaving the rest of the IP header potentially un-pulled in non-linear\nfrags. Subsequent dereferences of ip_hdr(skb)-\u003edaddr can read beyond the pulled\nlinear buffer length.\n\nFix this by using pskb_network_may_pull(), which adds skb_network_offset(skb) to\nthe length check to ensure the full network header is present in the linear buffer."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - route_shortcircuit() runs in vxlan_xmit() during overlay transmit; remote packets forwarded or routed onto a VXLAN netdev with route-short-circuit enabled reach this path without local access, matching net-stack guidance for network-reachable packet processing on cloud/SDN nodes.\nAC:L - An attacker can reliably craft non-linear skbs (scatter/gather/frags and size boundaries) and aim traffic at a known router MAC in the VXLAN FDB; no race or uncontrollable memory layout is required beyond targeting an RSC-enabled deployment, which is the scored scenario.\nPR:N - Exploitation needs no credentials or capabilities on the victim when VXLAN RSC is already configured; a remote peer only has to send IPv4/IPv6 frames that traverse the tunnel transmit path, with no netlink setup or CAP_NET_ADMIN in the target namespace.\nUI:N - Triggering the bug requires only attacker-controlled network traffic through the overlay; no victim mount, file open, link click, or other interactive action is needed.\nS:U - Impact is confined to the kernel hosting the VXLAN endpoint (memory disclosure, packet-header corruption, or crash); it does not cross VM, container, or IOMMU security boundaries by itself.\nC:H - The faulty pskb_may_pull() check leaves the IP/IPv6 header in non-linear frags, so ip_hdr(skb)-\u003edaddr/ipv6 daddr is read past the linear head and can disclose adjacent kernel memory per OOB-read guidance.\nI:H - The out-of-bounds destination address feeds neigh_lookup() and may rewrite eth_hdr()-\u003eh_dest before encapsulation, giving attacker-influenced overlay forwarding and a memory-safety primitive in the transmit path.\nA:H - Dereferencing network-header fields beyond the pulled linear buffer can provoke kernel oops/panic on affected skb layouts, and OOB reads in xmit context are treated as high availability impact even when exploitation is not fully weaponized."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:37:25.639Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c419af4924c1593500a40519730ed98575d04a3e"
},
{
"url": "https://git.kernel.org/stable/c/6bd0a3a1b5744166946f0c551a6665c3b46b05e4"
},
{
"url": "https://git.kernel.org/stable/c/214ba43faf106cb06cd3dd30999c5c809c868b53"
},
{
"url": "https://git.kernel.org/stable/c/42887be7c4cf283cce02cd0fb6411221167c8b6c"
},
{
"url": "https://git.kernel.org/stable/c/aa0d31376d574ac858a40078431a77127bf04ee4"
},
{
"url": "https://git.kernel.org/stable/c/ee799977d7941dbfb11049e17edd9eaf4f8820f7"
},
{
"url": "https://git.kernel.org/stable/c/4f3f96e771a20263635bb5e1307c112d613b4bbd"
},
{
"url": "https://git.kernel.org/stable/c/26bb2dd0a8839617e2c79ffbbe1923f8e4bab9fb"
}
],
"title": "vxlan: use pskb_network_may_pull() in route_shortcircuit()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74473",
"datePublished": "2026-08-15T12:27:09.382Z",
"dateReserved": "2026-08-15T05:44:03.903Z",
"dateUpdated": "2026-08-19T16:37:25.639Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72216 (GCVE-0-2026-72216)
Vulnerability from cvelistv5
Published
2026-08-15 05:54
Modified
2026-08-23 12:47
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
remoteproc: qcom: Fix leak when custom dump_segments addition fails
Free allocated minidump_region 'name' in qcom_add_minidump_segments()
when failing before adding the region to 'dump_segments'. Otherwise,
the 'name' is not tracked and is never freed by qcom_minidump_cleanup().
Return error when adding to 'dump_segments' fails.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 8ed8485c4f056d488d17a2b56581c86aeb42955d Version: 8ed8485c4f056d488d17a2b56581c86aeb42955d Version: 8ed8485c4f056d488d17a2b56581c86aeb42955d Version: 8ed8485c4f056d488d17a2b56581c86aeb42955d Version: 8ed8485c4f056d488d17a2b56581c86aeb42955d Version: 8ed8485c4f056d488d17a2b56581c86aeb42955d Version: 8ed8485c4f056d488d17a2b56581c86aeb42955d |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/remoteproc/qcom_common.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "491edca252d1256b57e805c6e3acae320b53f53e",
"status": "affected",
"version": "8ed8485c4f056d488d17a2b56581c86aeb42955d",
"versionType": "git"
},
{
"lessThan": "8bfe7e7729617e73233ab5f1a2edbeee5e75c722",
"status": "affected",
"version": "8ed8485c4f056d488d17a2b56581c86aeb42955d",
"versionType": "git"
},
{
"lessThan": "65104d6eb43f066dcf73ca9ade6478824b17d867",
"status": "affected",
"version": "8ed8485c4f056d488d17a2b56581c86aeb42955d",
"versionType": "git"
},
{
"lessThan": "381c8a7a59da06293951c343857f4a2465b2c655",
"status": "affected",
"version": "8ed8485c4f056d488d17a2b56581c86aeb42955d",
"versionType": "git"
},
{
"lessThan": "51aad3d89a2dd2bd34713785b0f2fd5177eb33b6",
"status": "affected",
"version": "8ed8485c4f056d488d17a2b56581c86aeb42955d",
"versionType": "git"
},
{
"lessThan": "e5b1aaa74118e91f0c0f18b22b6f853199873db4",
"status": "affected",
"version": "8ed8485c4f056d488d17a2b56581c86aeb42955d",
"versionType": "git"
},
{
"lessThan": "ecf9fc18e62c58eae1ceb65dab2bccb8a724de2d",
"status": "affected",
"version": "8ed8485c4f056d488d17a2b56581c86aeb42955d",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/remoteproc/qcom_common.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.11"
},
{
"lessThan": "5.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nremoteproc: qcom: Fix leak when custom dump_segments addition fails\n\nFree allocated minidump_region \u0027name\u0027 in qcom_add_minidump_segments()\nwhen failing before adding the region to \u0027dump_segments\u0027. Otherwise,\nthe \u0027name\u0027 is not tracked and is never freed by qcom_minidump_cleanup().\n\nReturn error when adding to \u0027dump_segments\u0027 fails."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:47:02.553Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/491edca252d1256b57e805c6e3acae320b53f53e"
},
{
"url": "https://git.kernel.org/stable/c/8bfe7e7729617e73233ab5f1a2edbeee5e75c722"
},
{
"url": "https://git.kernel.org/stable/c/65104d6eb43f066dcf73ca9ade6478824b17d867"
},
{
"url": "https://git.kernel.org/stable/c/381c8a7a59da06293951c343857f4a2465b2c655"
},
{
"url": "https://git.kernel.org/stable/c/51aad3d89a2dd2bd34713785b0f2fd5177eb33b6"
},
{
"url": "https://git.kernel.org/stable/c/e5b1aaa74118e91f0c0f18b22b6f853199873db4"
},
{
"url": "https://git.kernel.org/stable/c/ecf9fc18e62c58eae1ceb65dab2bccb8a724de2d"
}
],
"title": "remoteproc: qcom: Fix leak when custom dump_segments addition fails",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72216",
"datePublished": "2026-08-15T05:54:10.106Z",
"dateReserved": "2026-08-09T03:40:39.912Z",
"dateUpdated": "2026-08-23T12:47:02.553Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68082 (GCVE-0-2026-68082)
Vulnerability from cvelistv5
Published
2026-08-08 09:17
Modified
2026-08-23 12:45
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
libceph: fix two unsafe bare decodes in decode_lockers()
decode_lockers() in cls_lock_client.c contains two bare decode operations
that allow a malicious or compromised OSD to trigger slab-out-of-bounds
reads:
1. ceph_decode_32(p) at the num_lockers field has no preceding bounds
check. ceph_start_decoding() accepts struct_len=0 as valid -- the
internal ceph_decode_need(p, end, 0, bad) always passes -- so when an
OSD sends struct_len=0, ceph_start_decoding() returns success with
p == end. The immediately following bare ceph_decode_32(p) then reads
4 bytes past the validated buffer boundary. The garbage value is
passed directly to kzalloc_objs() as the locker count.
The sibling function decode_watchers() in osd_client.c already uses
ceph_decode_32_safe() after its own ceph_start_decoding() call.
decode_lockers() was the only site using the bare variant.
2. ceph_decode_8(p) after the decode_locker() loop has no preceding
bounds check. If an OSD crafts num_lockers such that the loop
advances p exactly to end, the subsequent bare ceph_decode_8(p) reads
one byte past the validated buffer boundary. The result is passed
directly into *type, which is used as a lock type discriminator by
callers, giving an OSD-controlled one-byte OOB read with direct
influence over the lock type field.
Fix both by replacing bare operations with their safe variants:
ceph_decode_32(p) -> ceph_decode_32_safe(p, end, *num_lockers,
err_inval)
ceph_decode_8(p) -> ceph_decode_8_safe(p, end, *type,
err_free_lockers)
The goto targets differ intentionally:
err_inval: is a new label returning -EINVAL directly. It is used for
the pre-allocation failure path where *lockers is not yet allocated
and must not be passed to ceph_free_lockers().
err_free_lockers: is the existing label. It is used for the
post-allocation failure path where *lockers is allocated and must
be freed.
ret is set to -EINVAL before ceph_decode_8_safe() so that
err_free_lockers returns the correct error code on bounds violation.
Without this, err_free_lockers would return a stale ret value (0 from
the successful decode_locker() loop), silently swallowing the error.
-EINVAL is correct for both failure paths. The data received from the
OSD is structurally malformed. -ENOMEM would misrepresent the failure
class to callers and to stable@ backporters triaging error paths.
Attacker model: a malicious or compromised OSD in a multi-tenant Ceph
deployment can trigger this against any kernel client that issues the
lock.get_info class method (e.g. during RBD exclusive lock acquisition).
[ idryomov: trim changelog, formatting ]
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d4ed4a530562881cc5225050e42d96034f405aae Version: d4ed4a530562881cc5225050e42d96034f405aae Version: d4ed4a530562881cc5225050e42d96034f405aae Version: d4ed4a530562881cc5225050e42d96034f405aae Version: d4ed4a530562881cc5225050e42d96034f405aae Version: d4ed4a530562881cc5225050e42d96034f405aae Version: d4ed4a530562881cc5225050e42d96034f405aae Version: d4ed4a530562881cc5225050e42d96034f405aae |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ceph/cls_lock_client.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c8ade01170a27d8ede0d761c255268af81e417f8",
"status": "affected",
"version": "d4ed4a530562881cc5225050e42d96034f405aae",
"versionType": "git"
},
{
"lessThan": "001835c599899ef1bd3506a815110a6374451554",
"status": "affected",
"version": "d4ed4a530562881cc5225050e42d96034f405aae",
"versionType": "git"
},
{
"lessThan": "7c422364acd93d7da1dfc27d6b54635a269653a1",
"status": "affected",
"version": "d4ed4a530562881cc5225050e42d96034f405aae",
"versionType": "git"
},
{
"lessThan": "02430f6f729b297e803d0605871f0a670b4eafd6",
"status": "affected",
"version": "d4ed4a530562881cc5225050e42d96034f405aae",
"versionType": "git"
},
{
"lessThan": "57ba829804fe6d34bbac3b826c4b15c1caa54862",
"status": "affected",
"version": "d4ed4a530562881cc5225050e42d96034f405aae",
"versionType": "git"
},
{
"lessThan": "89df5d71f83f8e2781286798fd8ae5e42cf5f1a7",
"status": "affected",
"version": "d4ed4a530562881cc5225050e42d96034f405aae",
"versionType": "git"
},
{
"lessThan": "a54be593d0b749161b08a1e56189b2cb9114267a",
"status": "affected",
"version": "d4ed4a530562881cc5225050e42d96034f405aae",
"versionType": "git"
},
{
"lessThan": "a109a556115271ca7896dcda7b4b7e45e156c227",
"status": "affected",
"version": "d4ed4a530562881cc5225050e42d96034f405aae",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ceph/cls_lock_client.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.9"
},
{
"lessThan": "4.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.46",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: fix two unsafe bare decodes in decode_lockers()\n\ndecode_lockers() in cls_lock_client.c contains two bare decode operations\nthat allow a malicious or compromised OSD to trigger slab-out-of-bounds\nreads:\n\n1. ceph_decode_32(p) at the num_lockers field has no preceding bounds\n check. ceph_start_decoding() accepts struct_len=0 as valid -- the\n internal ceph_decode_need(p, end, 0, bad) always passes -- so when an\n OSD sends struct_len=0, ceph_start_decoding() returns success with\n p == end. The immediately following bare ceph_decode_32(p) then reads\n 4 bytes past the validated buffer boundary. The garbage value is\n passed directly to kzalloc_objs() as the locker count.\n\n The sibling function decode_watchers() in osd_client.c already uses\n ceph_decode_32_safe() after its own ceph_start_decoding() call.\n decode_lockers() was the only site using the bare variant.\n\n2. ceph_decode_8(p) after the decode_locker() loop has no preceding\n bounds check. If an OSD crafts num_lockers such that the loop\n advances p exactly to end, the subsequent bare ceph_decode_8(p) reads\n one byte past the validated buffer boundary. The result is passed\n directly into *type, which is used as a lock type discriminator by\n callers, giving an OSD-controlled one-byte OOB read with direct\n influence over the lock type field.\n\nFix both by replacing bare operations with their safe variants:\n ceph_decode_32(p) -\u003e ceph_decode_32_safe(p, end, *num_lockers,\n err_inval)\n ceph_decode_8(p) -\u003e ceph_decode_8_safe(p, end, *type,\n err_free_lockers)\n\nThe goto targets differ intentionally:\n err_inval: is a new label returning -EINVAL directly. It is used for\n the pre-allocation failure path where *lockers is not yet allocated\n and must not be passed to ceph_free_lockers().\n\n err_free_lockers: is the existing label. It is used for the\n post-allocation failure path where *lockers is allocated and must\n be freed.\n\nret is set to -EINVAL before ceph_decode_8_safe() so that\nerr_free_lockers returns the correct error code on bounds violation.\nWithout this, err_free_lockers would return a stale ret value (0 from\nthe successful decode_locker() loop), silently swallowing the error.\n\n-EINVAL is correct for both failure paths. The data received from the\nOSD is structurally malformed. -ENOMEM would misrepresent the failure\nclass to callers and to stable@ backporters triaging error paths.\n\nAttacker model: a malicious or compromised OSD in a multi-tenant Ceph\ndeployment can trigger this against any kernel client that issues the\nlock.get_info class method (e.g. during RBD exclusive lock acquisition).\n\n[ idryomov: trim changelog, formatting ]"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The flaw is reached when libceph decodes a crafted MOSDOpReply for the lock.get_info class method received over the Ceph messenger TCP session from a compromised or malicious OSD; no local syscall or ioctl is required on the victim.\nAC:L - A malicious OSD can deterministically send struct_len=0 or craft num_lockers so the decode pointer reaches end, triggering both bare decodes on every attempt without races, special memory layout, or rare kernel configuration.\nPR:N - The attacker acts as the remote Ceph OSD peer and needs no account or privileges on the victim Linux host; any kernel RBD client connected to a multi-tenant or attacker-controlled cluster is exposed during automatic exclusive-lock operations.\nUI:N - Once an RBD image is mapped, ceph_cls_lock_info() is invoked automatically during exclusive-lock acquisition and object-map lock recovery; no further victim user or administrator action is required at exploit time.\nS:U - The slab out-of-bounds reads and any resulting kernel memory corruption occur entirely within the victim host kernel running the Ceph client, without crossing VM, container, or IOMMU security boundaries.\nC:H - Bare ceph_decode_32/8 past the validated reply boundary perform slab out-of-bounds reads of adjacent kernel memory; the leaked u32 can drive kzalloc_objs() sizing and the OOB u8 directly controls the lock-type field consumed by RBD lock logic.\nI:H - Attacker-influenced out-of-bounds values feed heap allocation sizing and lock-type discrimination in kernel lock-handling paths, providing memory-corruption primitives in a privileged parser that can be leveraged beyond simple information disclosure.\nA:H - Slab out-of-bounds reads can trigger KASAN faults or kernel oops on instrumented builds, and attacker-controlled locker counts can force very large kzalloc attempts causing severe memory pressure, OOM conditions, and loss of availability on RBD client hosts."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:45:46.891Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c8ade01170a27d8ede0d761c255268af81e417f8"
},
{
"url": "https://git.kernel.org/stable/c/001835c599899ef1bd3506a815110a6374451554"
},
{
"url": "https://git.kernel.org/stable/c/7c422364acd93d7da1dfc27d6b54635a269653a1"
},
{
"url": "https://git.kernel.org/stable/c/02430f6f729b297e803d0605871f0a670b4eafd6"
},
{
"url": "https://git.kernel.org/stable/c/57ba829804fe6d34bbac3b826c4b15c1caa54862"
},
{
"url": "https://git.kernel.org/stable/c/89df5d71f83f8e2781286798fd8ae5e42cf5f1a7"
},
{
"url": "https://git.kernel.org/stable/c/a54be593d0b749161b08a1e56189b2cb9114267a"
},
{
"url": "https://git.kernel.org/stable/c/a109a556115271ca7896dcda7b4b7e45e156c227"
}
],
"title": "libceph: fix two unsafe bare decodes in decode_lockers()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68082",
"datePublished": "2026-08-08T09:17:45.394Z",
"dateReserved": "2026-07-30T09:28:09.367Z",
"dateUpdated": "2026-08-23T12:45:46.891Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2025-22104 (GCVE-0-2025-22104)
Vulnerability from cvelistv5
Published
2025-04-16 14:12
Modified
2026-09-02 12:49
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ibmvnic: Use kernel helpers for hex dumps
Previously, when the driver was printing hex dumps, the buffer was cast
to an 8 byte long and printed using string formatters. If the buffer
size was not a multiple of 8 then a read buffer overflow was possible.
Therefore, create a new ibmvnic function that loops over a buffer and
calls hex_dump_to_buffer instead.
This patch address KASAN reports like the one below:
ibmvnic 30000003 env3: Login Buffer:
ibmvnic 30000003 env3: 01000000af000000
<...>
ibmvnic 30000003 env3: 2e6d62692e736261
ibmvnic 30000003 env3: 65050003006d6f63
==================================================================
BUG: KASAN: slab-out-of-bounds in ibmvnic_login+0xacc/0xffc [ibmvnic]
Read of size 8 at addr c0000001331a9aa8 by task ip/17681
<...>
Allocated by task 17681:
<...>
ibmvnic_login+0x2f0/0xffc [ibmvnic]
ibmvnic_open+0x148/0x308 [ibmvnic]
__dev_open+0x1ac/0x304
<...>
The buggy address is located 168 bytes inside of
allocated 175-byte region [c0000001331a9a00, c0000001331a9aaf)
<...>
=================================================================
ibmvnic 30000003 env3: 000000000033766e
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/ibm/ibmvnic.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "19efa170e01207c8ada726f3f6c65b31fcba2a73",
"status": "affected",
"version": "032c5e82847a2214c3196a90f0aeba0ce252de58",
"versionType": "git"
},
{
"lessThan": "9bc078818ec76344c2e06b81d7aee2df3adecfbf",
"status": "affected",
"version": "032c5e82847a2214c3196a90f0aeba0ce252de58",
"versionType": "git"
},
{
"lessThan": "005fee039dd845122d313ac8f2122b0d09dc5d7b",
"status": "affected",
"version": "032c5e82847a2214c3196a90f0aeba0ce252de58",
"versionType": "git"
},
{
"lessThan": "ae6b1d6c1acee3a2000394d83ec9f1028321e207",
"status": "affected",
"version": "032c5e82847a2214c3196a90f0aeba0ce252de58",
"versionType": "git"
},
{
"lessThan": "d93a6caab5d7d9b5ce034d75b1e1e993338e3852",
"status": "affected",
"version": "032c5e82847a2214c3196a90f0aeba0ce252de58",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/ibm/ibmvnic.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.5"
},
{
"lessThan": "4.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.187",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.156",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.108",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.14.*",
"status": "unaffected",
"version": "6.14.2",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "6.15",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.187",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.156",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.108",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.14.2",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.15",
"versionStartIncluding": "4.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nibmvnic: Use kernel helpers for hex dumps\n\nPreviously, when the driver was printing hex dumps, the buffer was cast\nto an 8 byte long and printed using string formatters. If the buffer\nsize was not a multiple of 8 then a read buffer overflow was possible.\n\nTherefore, create a new ibmvnic function that loops over a buffer and\ncalls hex_dump_to_buffer instead.\n\nThis patch address KASAN reports like the one below:\n ibmvnic 30000003 env3: Login Buffer:\n ibmvnic 30000003 env3: 01000000af000000\n \u003c...\u003e\n ibmvnic 30000003 env3: 2e6d62692e736261\n ibmvnic 30000003 env3: 65050003006d6f63\n ==================================================================\n BUG: KASAN: slab-out-of-bounds in ibmvnic_login+0xacc/0xffc [ibmvnic]\n Read of size 8 at addr c0000001331a9aa8 by task ip/17681\n \u003c...\u003e\n Allocated by task 17681:\n \u003c...\u003e\n ibmvnic_login+0x2f0/0xffc [ibmvnic]\n ibmvnic_open+0x148/0x308 [ibmvnic]\n __dev_open+0x1ac/0x304\n \u003c...\u003e\n The buggy address is located 168 bytes inside of\n allocated 175-byte region [c0000001331a9a00, c0000001331a9aaf)\n \u003c...\u003e\n =================================================================\n ibmvnic 30000003 env3: 000000000033766e"
}
],
"providerMetadata": {
"dateUpdated": "2026-09-02T12:49:16.565Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/19efa170e01207c8ada726f3f6c65b31fcba2a73"
},
{
"url": "https://git.kernel.org/stable/c/9bc078818ec76344c2e06b81d7aee2df3adecfbf"
},
{
"url": "https://git.kernel.org/stable/c/005fee039dd845122d313ac8f2122b0d09dc5d7b"
},
{
"url": "https://git.kernel.org/stable/c/ae6b1d6c1acee3a2000394d83ec9f1028321e207"
},
{
"url": "https://git.kernel.org/stable/c/d93a6caab5d7d9b5ce034d75b1e1e993338e3852"
}
],
"title": "ibmvnic: Use kernel helpers for hex dumps",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2025-22104",
"datePublished": "2025-04-16T14:12:53.118Z",
"dateReserved": "2024-12-29T08:45:45.819Z",
"dateUpdated": "2026-09-02T12:49:16.565Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74471 (GCVE-0-2026-74471)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-19 16:37
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
tracing: Check return value of __register_event() in trace_module_add_events()
trace_module_add_events() ignores the return value of __register_event()
and unconditionally calls __add_event_to_tracers() for each event.
If __register_event() fails (for example, if event_init() fails), the
trace_event_call is not added to ftrace_events list, but
__add_event_to_tracers() still creates a trace_event_file pointing to it.
If module loading subsequently fails and module memory is freed, tracing
state retains a stale trace_event_call pointer in trace_event_file,
leading to a use-after-free when tracefs or tracing subsystem operations
are later executed.
Fix this by checking the return value of __register_event() and only
calling __add_event_to_tracers() if event registration succeeded.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ae63b31e4d0e2ec09c569306ea46f664508ef717 Version: ae63b31e4d0e2ec09c569306ea46f664508ef717 Version: ae63b31e4d0e2ec09c569306ea46f664508ef717 Version: ae63b31e4d0e2ec09c569306ea46f664508ef717 Version: ae63b31e4d0e2ec09c569306ea46f664508ef717 Version: ae63b31e4d0e2ec09c569306ea46f664508ef717 Version: ae63b31e4d0e2ec09c569306ea46f664508ef717 Version: ae63b31e4d0e2ec09c569306ea46f664508ef717 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"kernel/trace/trace_events.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "3bf965a2827c44f03294107703e7ba53fbd0a69a",
"status": "affected",
"version": "ae63b31e4d0e2ec09c569306ea46f664508ef717",
"versionType": "git"
},
{
"lessThan": "9d6d79744f01eacaf3d5522f4fcd59939581abfd",
"status": "affected",
"version": "ae63b31e4d0e2ec09c569306ea46f664508ef717",
"versionType": "git"
},
{
"lessThan": "54b7a358f6399c1242d2fb7f4f96085af34baa5e",
"status": "affected",
"version": "ae63b31e4d0e2ec09c569306ea46f664508ef717",
"versionType": "git"
},
{
"lessThan": "d61ee2a27dfd5eb43ddc18af40168f5b9eb1cea5",
"status": "affected",
"version": "ae63b31e4d0e2ec09c569306ea46f664508ef717",
"versionType": "git"
},
{
"lessThan": "22f954f7a8afe975e85517aff41b35defe05144b",
"status": "affected",
"version": "ae63b31e4d0e2ec09c569306ea46f664508ef717",
"versionType": "git"
},
{
"lessThan": "cbb5ed3be9cae70e1c12b1991009b4e12bf4a4ca",
"status": "affected",
"version": "ae63b31e4d0e2ec09c569306ea46f664508ef717",
"versionType": "git"
},
{
"lessThan": "000765dcdc3edf128990762790543adc4b868f6c",
"status": "affected",
"version": "ae63b31e4d0e2ec09c569306ea46f664508ef717",
"versionType": "git"
},
{
"lessThan": "ac8719969e6c3c54e939834df812bc41f25453cf",
"status": "affected",
"version": "ae63b31e4d0e2ec09c569306ea46f664508ef717",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"kernel/trace/trace_events.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.10"
},
{
"lessThan": "3.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Check return value of __register_event() in trace_module_add_events()\n\ntrace_module_add_events() ignores the return value of __register_event()\nand unconditionally calls __add_event_to_tracers() for each event.\n\nIf __register_event() fails (for example, if event_init() fails), the\ntrace_event_call is not added to ftrace_events list, but\n__add_event_to_tracers() still creates a trace_event_file pointing to it.\nIf module loading subsequently fails and module memory is freed, tracing\nstate retains a stale trace_event_call pointer in trace_event_file,\nleading to a use-after-free when tracefs or tracing subsystem operations\nare later executed.\n\nFix this by checking the return value of __register_event() and only\ncalling __add_event_to_tracers() if event registration succeeded."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached only via local init_module/finit_module module loading (MODULE_STATE_COMING notifier) and subsequent tracefs/tracing operations on poisoned event files; there is no network, adjacent-wireless, or physical-device input path into trace_module_add_events() or the stale trace_event_file dereferences.\nAC:L - An attacker can deterministically craft a module whose trace events fail event_init()/__register_event() while __add_event_to_tracers() still runs, then force module-load failure or rmmod to free module memory; no uncontrollable race, rare kernel config, or victim-specific memory layout is required.\nPR:L - Triggering the UAF requires only local tracefs/tracing access, which tracing_check_open() gates solely with LOCKDOWN_TRACEFS and DAC (no capable() check), commonly granted to tracing-group/Android/ChromeOS diagnostics users; priming stale pointers via init_module uses capable(CAP_SYS_MODULE) but is achievable on permissive dev/container hosts loading attacker modules.\nUI:N - Once tracefs is accessible, the attacker can read/write event enable/format files or invoke tracing helpers that iterate tr-\u003eevents and dereference the stale trace_event_call without any separate victim user performing mounts, clicks, or configuration changes.\nS:U - The use-after-free corrupts kernel tracing heap/metadata within the same OS security authority and enables local privilege escalation; it does not cross VM, container, IOMMU, or hardware trust boundaries.\nC:H - Stale trace_event_file-\u003eevent_call pointers reference freed module slab memory; subsequent trace_event_name(), call-\u003eclass, and reg/unreg callbacks read attacker-influenced reclaimed heap contents, giving an arbitrary kernel memory read primitive typical of UAF bugs.\nI:H - Operations such as __ftrace_event_enable_disable() invoke call-\u003eclass-\u003ereg() through the dangling trace_event_call and manipulate event flags/filters on reclaimed objects, providing controllable kernel writes and a standard UAF path to code execution.\nA:H - Dereferencing freed module-resident trace_event_call structures from tracefs or tracing subsystem operations readily causes kernel oops/panic; even without full exploitation, the UAF reliably threatens system availability and can be retriggered at will."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:37:20.725Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/3bf965a2827c44f03294107703e7ba53fbd0a69a"
},
{
"url": "https://git.kernel.org/stable/c/9d6d79744f01eacaf3d5522f4fcd59939581abfd"
},
{
"url": "https://git.kernel.org/stable/c/54b7a358f6399c1242d2fb7f4f96085af34baa5e"
},
{
"url": "https://git.kernel.org/stable/c/d61ee2a27dfd5eb43ddc18af40168f5b9eb1cea5"
},
{
"url": "https://git.kernel.org/stable/c/22f954f7a8afe975e85517aff41b35defe05144b"
},
{
"url": "https://git.kernel.org/stable/c/cbb5ed3be9cae70e1c12b1991009b4e12bf4a4ca"
},
{
"url": "https://git.kernel.org/stable/c/000765dcdc3edf128990762790543adc4b868f6c"
},
{
"url": "https://git.kernel.org/stable/c/ac8719969e6c3c54e939834df812bc41f25453cf"
}
],
"title": "tracing: Check return value of __register_event() in trace_module_add_events()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74471",
"datePublished": "2026-08-15T12:27:08.128Z",
"dateReserved": "2026-08-15T05:44:03.902Z",
"dateUpdated": "2026-08-19T16:37:20.725Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80529 (GCVE-0-2026-80529)
Vulnerability from cvelistv5
Published
2026-08-26 14:37
Modified
2026-08-26 14:37
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
xfs: don't swallow dquot recovery verification errors
xlog_recover_dquot_commit_pass2() validates the recovered dquot with
xfs_dqblk_verify() and, on failure, sets error = -EFSCORRUPTED and jumps
to out_release. But out_release unconditionally returns 0, so the
corruption error is discarded: the caller xlog_recover_items_pass2()
sees success, log recovery proceeds as if the dquot were valid, and the
corrupt quota buffer can be written back to disk.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 7880b1f0adef4d363f42d6bb42aab3211291351b Version: 3581868f51a2edb027a898988b5b5a4ba379ee55 Version: 9c235dfc3d3f901fe22acb20f2ab37ff39f2ce02 Version: 9c235dfc3d3f901fe22acb20f2ab37ff39f2ce02 Version: 9c235dfc3d3f901fe22acb20f2ab37ff39f2ce02 Version: 9c235dfc3d3f901fe22acb20f2ab37ff39f2ce02 Version: 6.1.128 ≤ Version: 6.6.17 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/xfs/xfs_dquot_item_recover.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "e506e127fcb4e2bad1045805f1740b395eea9618",
"status": "affected",
"version": "7880b1f0adef4d363f42d6bb42aab3211291351b",
"versionType": "git"
},
{
"lessThan": "5b756fbb60b5d26063f46a11a3c7daa7eb616d79",
"status": "affected",
"version": "3581868f51a2edb027a898988b5b5a4ba379ee55",
"versionType": "git"
},
{
"lessThan": "a233b3362a3c7bf23f5143b4ef4b17ec337fcb4d",
"status": "affected",
"version": "9c235dfc3d3f901fe22acb20f2ab37ff39f2ce02",
"versionType": "git"
},
{
"lessThan": "38a4dbe588bd028a07a77dc5cee62ee3ce21e87d",
"status": "affected",
"version": "9c235dfc3d3f901fe22acb20f2ab37ff39f2ce02",
"versionType": "git"
},
{
"lessThan": "36a31b12540c0a0a3b77a01fda86de646f2961fb",
"status": "affected",
"version": "9c235dfc3d3f901fe22acb20f2ab37ff39f2ce02",
"versionType": "git"
},
{
"lessThan": "e2b4a856085e9bd939bde2dee0d08b1d41babde9",
"status": "affected",
"version": "9c235dfc3d3f901fe22acb20f2ab37ff39f2ce02",
"versionType": "git"
},
{
"lessThan": "6.1.184",
"status": "affected",
"version": "6.1.128",
"versionType": "semver"
},
{
"lessThan": "6.6.153",
"status": "affected",
"version": "6.6.17",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/xfs/xfs_dquot_item_recover.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.7"
},
{
"lessThan": "6.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "6.1.128",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "6.6.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.46",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.10",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nxfs: don\u0027t swallow dquot recovery verification errors\n\nxlog_recover_dquot_commit_pass2() validates the recovered dquot with\nxfs_dqblk_verify() and, on failure, sets error = -EFSCORRUPTED and jumps\nto out_release. But out_release unconditionally returns 0, so the\ncorruption error is discarded: the caller xlog_recover_items_pass2()\nsees success, log recovery proceeds as if the dquot were valid, and the\ncorrupt quota buffer can be written back to disk."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-26T14:37:07.390Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/e506e127fcb4e2bad1045805f1740b395eea9618"
},
{
"url": "https://git.kernel.org/stable/c/5b756fbb60b5d26063f46a11a3c7daa7eb616d79"
},
{
"url": "https://git.kernel.org/stable/c/a233b3362a3c7bf23f5143b4ef4b17ec337fcb4d"
},
{
"url": "https://git.kernel.org/stable/c/38a4dbe588bd028a07a77dc5cee62ee3ce21e87d"
},
{
"url": "https://git.kernel.org/stable/c/36a31b12540c0a0a3b77a01fda86de646f2961fb"
},
{
"url": "https://git.kernel.org/stable/c/e2b4a856085e9bd939bde2dee0d08b1d41babde9"
}
],
"title": "xfs: don\u0027t swallow dquot recovery verification errors",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80529",
"datePublished": "2026-08-26T14:37:07.390Z",
"dateReserved": "2026-08-26T14:34:25.764Z",
"dateUpdated": "2026-08-26T14:37:07.390Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80548 (GCVE-0-2026-80548)
Vulnerability from cvelistv5
Published
2026-08-26 14:37
Modified
2026-08-27 12:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
s390/vfio_ccw: Selectively expand io_mutex
The io_mutex was defined to serialize the io_regions, but then has
also sort of been associated with the I/O themselves because of
the close relationship they share.
With the handful of races that are possible, the choices are either to:
A) expand the scope of io_mutex to close these remaining windows, or
B) reduce the scope of io_mutex to just io_region, and introduce a new
lock mechanism for the remaining I/O resources
This patch implements A, since B brings with it a lot more interactions
that would need to be tracked and kept in a correct hierarchy. It also
takes advantage of the workqueue element for cp_free() that now gets
called out of fsm_notoper(), which could be invoked out of an interrupt
context and thus cannot acquire a mutex itself.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 4f76617378ee97c557b526cb58d3c61eb0a9c963 Version: 4f76617378ee97c557b526cb58d3c61eb0a9c963 Version: 4f76617378ee97c557b526cb58d3c61eb0a9c963 Version: 4f76617378ee97c557b526cb58d3c61eb0a9c963 Version: 4f76617378ee97c557b526cb58d3c61eb0a9c963 Version: 4f76617378ee97c557b526cb58d3c61eb0a9c963 Version: 4f76617378ee97c557b526cb58d3c61eb0a9c963 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/s390/cio/vfio_ccw_chp.c",
"drivers/s390/cio/vfio_ccw_cp.c",
"drivers/s390/cio/vfio_ccw_drv.c",
"drivers/s390/cio/vfio_ccw_fsm.c",
"drivers/s390/cio/vfio_ccw_private.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "dab6a6627b0b0cce23653e99c7b0bf8c6cfd82e0",
"status": "affected",
"version": "4f76617378ee97c557b526cb58d3c61eb0a9c963",
"versionType": "git"
},
{
"lessThan": "56d7488533ceac4e986e96e15c9e487a2245bc01",
"status": "affected",
"version": "4f76617378ee97c557b526cb58d3c61eb0a9c963",
"versionType": "git"
},
{
"lessThan": "f72a51810d49411bd8cad0c2df8592320a2fe5cc",
"status": "affected",
"version": "4f76617378ee97c557b526cb58d3c61eb0a9c963",
"versionType": "git"
},
{
"lessThan": "2ba9efdf9ebedc4e54df4b56aa3b43a65f7967cd",
"status": "affected",
"version": "4f76617378ee97c557b526cb58d3c61eb0a9c963",
"versionType": "git"
},
{
"lessThan": "b6aecea4b2b246f9fbd98a5712daa1193a60818e",
"status": "affected",
"version": "4f76617378ee97c557b526cb58d3c61eb0a9c963",
"versionType": "git"
},
{
"lessThan": "2a5ac0c0f1f7da33929211a2e41911bf72ee35d8",
"status": "affected",
"version": "4f76617378ee97c557b526cb58d3c61eb0a9c963",
"versionType": "git"
},
{
"lessThan": "34f4feff3e90bd09308fad0974e97113b23b812a",
"status": "affected",
"version": "4f76617378ee97c557b526cb58d3c61eb0a9c963",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/s390/cio/vfio_ccw_chp.c",
"drivers/s390/cio/vfio_ccw_cp.c",
"drivers/s390/cio/vfio_ccw_drv.c",
"drivers/s390/cio/vfio_ccw_fsm.c",
"drivers/s390/cio/vfio_ccw_private.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.2"
},
{
"lessThan": "5.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.218",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.185",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.218",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.185",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.46",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.10",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/vfio_ccw: Selectively expand io_mutex\n\nThe io_mutex was defined to serialize the io_regions, but then has\nalso sort of been associated with the I/O themselves because of\nthe close relationship they share.\n\nWith the handful of races that are possible, the choices are either to:\n A) expand the scope of io_mutex to close these remaining windows, or\n B) reduce the scope of io_mutex to just io_region, and introduce a new\n lock mechanism for the remaining I/O resources\n\nThis patch implements A, since B brings with it a lot more interactions\nthat would need to be tracked and kept in a correct hierarchy. It also\ntakes advantage of the workqueue element for cp_free() that now gets\ncalled out of fsm_notoper(), which could be invoked out of an interrupt\ncontext and thus cannot acquire a mutex itself."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached only through local VFIO mediated-device syscalls (read/write/ioctl on vfio-ccw device fds) and deferred work from hardware I/O interrupts and channel-path events; vfio-ccw has no network, Bluetooth, or physical-bus entry point.\nAC:L - The VFIO client controls both sides of each race window: it can submit channel I/O, close or reset the device, and trigger DMA unmap while io_work, notoper_work, or fsm_close concurrently run cp_free, cp_update_scsw, or cp_iova_pinned without full io_mutex protection, and retry to win reliably.\nPR:L - Exploitation requires an opened vfio-ccw mdev device fd (typical QEMU/libvirt VM operator or delegated /dev/vfio holder on IBM Z passthrough hosts), not init-namespace root; mdev creation is admin setup, but triggering the races needs only that delegated VFIO client access.\nUI:N - No separate victim action is required; once vfio-ccw passthrough is configured, the attacker issues concurrent channel I/O, region access, device close/reset, or DMA unmap without needing another user to mount media or interact.\nS:C - On IBM Z/LinuxONE, vfio-ccw passes DASD/CCW subchannels into KVM guests; guest-driven channel I/O and path events trigger host interrupt/workqueue activity concurrent with VFIO client teardown, corrupting hypervisor kernel memory outside the VM security boundary.\nC:H - cp_free racing with cp_update_scsw, cp_iova_pinned, and io_region access without io_mutex causes use-after-free on ccwchain_list and page_array structures; per kernel UAF guidance this enables attacker-influenced heap reuse and arbitrary kernel read primitives.\nI:H - Concurrent cp_free during cp_init, page_array_unpin_free, memcpy into io_region, and mutex operations on freed channel_program memory provides heap-sprayable arbitrary write and control-flow hijack potential beyond a simple crash.\nA:H - Use-after-free and double-free of channel program structures during concurrent I/O completion, not-operational cleanup, or device close can immediately oops or panic the host kernel from invalid list/mutex access, and successful exploitation can crash or hang the system."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T12:40:08.507Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/dab6a6627b0b0cce23653e99c7b0bf8c6cfd82e0"
},
{
"url": "https://git.kernel.org/stable/c/56d7488533ceac4e986e96e15c9e487a2245bc01"
},
{
"url": "https://git.kernel.org/stable/c/f72a51810d49411bd8cad0c2df8592320a2fe5cc"
},
{
"url": "https://git.kernel.org/stable/c/2ba9efdf9ebedc4e54df4b56aa3b43a65f7967cd"
},
{
"url": "https://git.kernel.org/stable/c/b6aecea4b2b246f9fbd98a5712daa1193a60818e"
},
{
"url": "https://git.kernel.org/stable/c/2a5ac0c0f1f7da33929211a2e41911bf72ee35d8"
},
{
"url": "https://git.kernel.org/stable/c/34f4feff3e90bd09308fad0974e97113b23b812a"
}
],
"title": "s390/vfio_ccw: Selectively expand io_mutex",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80548",
"datePublished": "2026-08-26T14:37:18.759Z",
"dateReserved": "2026-08-26T14:34:25.766Z",
"dateUpdated": "2026-08-27T12:40:08.507Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72077 (GCVE-0-2026-72077)
Vulnerability from cvelistv5
Published
2026-08-15 05:52
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Input: ims-pcu - fix firmware leak in async update
The firmware object was not being released if validation failed.
Use __free(firmware) to ensure the firmware is always released.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 628329d52474323938a03826941e166bc7c8eff4 Version: 628329d52474323938a03826941e166bc7c8eff4 Version: 628329d52474323938a03826941e166bc7c8eff4 Version: 628329d52474323938a03826941e166bc7c8eff4 Version: 628329d52474323938a03826941e166bc7c8eff4 Version: 628329d52474323938a03826941e166bc7c8eff4 Version: 628329d52474323938a03826941e166bc7c8eff4 Version: 628329d52474323938a03826941e166bc7c8eff4 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/input/misc/ims-pcu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "f4b8cd2a96b47473e912e8a134f3c59efb81f10f",
"status": "affected",
"version": "628329d52474323938a03826941e166bc7c8eff4",
"versionType": "git"
},
{
"lessThan": "9efba5177a51ed996b0bdc03aa677c08247d5b91",
"status": "affected",
"version": "628329d52474323938a03826941e166bc7c8eff4",
"versionType": "git"
},
{
"lessThan": "af0641337f6584ccbc7a42ce3f4803d8ff9c5a4a",
"status": "affected",
"version": "628329d52474323938a03826941e166bc7c8eff4",
"versionType": "git"
},
{
"lessThan": "a5dd47ea3904dedb1ae7a5fe0e6b44a458f0c5ec",
"status": "affected",
"version": "628329d52474323938a03826941e166bc7c8eff4",
"versionType": "git"
},
{
"lessThan": "1f7bdfbe791aacad77db87f044e78ef60a93ae0d",
"status": "affected",
"version": "628329d52474323938a03826941e166bc7c8eff4",
"versionType": "git"
},
{
"lessThan": "99c428d7ef644d3e394f3072f905040c16dab18d",
"status": "affected",
"version": "628329d52474323938a03826941e166bc7c8eff4",
"versionType": "git"
},
{
"lessThan": "47a9889a9325b87698b6d6eaf3187a9af6e4773d",
"status": "affected",
"version": "628329d52474323938a03826941e166bc7c8eff4",
"versionType": "git"
},
{
"lessThan": "d48795b5cd6828d36b707e8d62fc9e5c90e004ab",
"status": "affected",
"version": "628329d52474323938a03826941e166bc7c8eff4",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/input/misc/ims-pcu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.10"
},
{
"lessThan": "3.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nInput: ims-pcu - fix firmware leak in async update\n\nThe firmware object was not being released if validation failed.\nUse __free(firmware) to ensure the firmware is always released."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:45.145Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/f4b8cd2a96b47473e912e8a134f3c59efb81f10f"
},
{
"url": "https://git.kernel.org/stable/c/9efba5177a51ed996b0bdc03aa677c08247d5b91"
},
{
"url": "https://git.kernel.org/stable/c/af0641337f6584ccbc7a42ce3f4803d8ff9c5a4a"
},
{
"url": "https://git.kernel.org/stable/c/a5dd47ea3904dedb1ae7a5fe0e6b44a458f0c5ec"
},
{
"url": "https://git.kernel.org/stable/c/1f7bdfbe791aacad77db87f044e78ef60a93ae0d"
},
{
"url": "https://git.kernel.org/stable/c/99c428d7ef644d3e394f3072f905040c16dab18d"
},
{
"url": "https://git.kernel.org/stable/c/47a9889a9325b87698b6d6eaf3187a9af6e4773d"
},
{
"url": "https://git.kernel.org/stable/c/d48795b5cd6828d36b707e8d62fc9e5c90e004ab"
}
],
"title": "Input: ims-pcu - fix firmware leak in async update",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72077",
"datePublished": "2026-08-15T05:52:27.612Z",
"dateReserved": "2026-08-09T03:40:39.904Z",
"dateUpdated": "2026-08-23T12:46:45.145Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74586 (GCVE-0-2026-74586)
Vulnerability from cvelistv5
Published
2026-08-22 15:31
Modified
2026-08-25 05:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
sctp: clear new_transport when removing a peer
sctp_process_asconf_param() stores a newly added peer transport in
asoc->new_transport. After all parameters in the ASCONF chunk have been
processed, sctp_sf_do_asconf() uses this pointer to send a HEARTBEAT to the
new transport.
An authenticated ASCONF from a remote SCTP peer can add a transport and
remove it again with a wildcard DEL-IP parameter in the same chunk. The
wildcard deletion preserves the transport on which the ASCONF arrived, but
removes the newly added transport through
sctp_assoc_del_nonprimary_peers(). The removal does not clear
asoc->new_transport, leaving it pointing to the removed transport.
sctp_sf_do_asconf() then creates a HEARTBEAT whose chunk->transport points
to the removed transport without holding a transport reference. During
local address replacement, src_out_of_asoc_ok keeps this HEARTBEAT on
control_chunk_list. After the transport is freed by RCU, a successful
ASCONF_ACK for the replacement address releases the queued HEARTBEAT and
sctp_outq_select_transport() reads the freed transport's state.
The issue was found during a static audit of SCTP objects. With an
authenticated peer, the reproducer triggered the same KASAN report in 2
of 2 unpatched runs on a KASAN-enabled netdev/main kernel:
BUG: KASAN: slab-use-after-free in sctp_outq_select_transport
Read of size 4 at addr ffff88800b9bd95c by task python3/197
Call Trace:
sctp_outq_select_transport+0x549/0x8b0 [sctp]
sctp_outq_flush+0x306/0x2c60 [sctp]
sctp_transport_immediate_rtx+0xaf/0x260 [sctp]
sctp_process_asconf_ack+0xa48/0xf70 [sctp]
Allocated by task 197:
sctp_transport_new+0x68/0x650 [sctp]
sctp_assoc_add_peer+0x258/0x12a0 [sctp]
sctp_process_asconf+0x5e9/0x1090 [sctp]
Last potentially related work creation:
__call_rcu_common.constprop.0+0x77/0xb70
sctp_assoc_del_nonprimary_peers+0x7c/0xd0 [sctp]
sctp_process_asconf+0xd9c/0x1090 [sctp]
The first invalid access was a four-byte read of transport->state at
net/sctp/outqueue.c:833. The same reproducer completed the full
authenticated ASCONF and local-address replacement sequence with this
change without a KASAN report or oops.
Clear new_transport when its peer is removed, before it can be used to
create the HEARTBEAT.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 6af29ccc223b0feb6fc6112281c3fa3cdb1afddf Version: 6af29ccc223b0feb6fc6112281c3fa3cdb1afddf Version: 6af29ccc223b0feb6fc6112281c3fa3cdb1afddf Version: 6af29ccc223b0feb6fc6112281c3fa3cdb1afddf Version: 6af29ccc223b0feb6fc6112281c3fa3cdb1afddf Version: 6af29ccc223b0feb6fc6112281c3fa3cdb1afddf Version: 6af29ccc223b0feb6fc6112281c3fa3cdb1afddf Version: 6af29ccc223b0feb6fc6112281c3fa3cdb1afddf |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/sctp/associola.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c0f973bb5118dd1b146cda3fcc8af6f6057befec",
"status": "affected",
"version": "6af29ccc223b0feb6fc6112281c3fa3cdb1afddf",
"versionType": "git"
},
{
"lessThan": "3b539b317cd052236fed0350364ff1268996ba46",
"status": "affected",
"version": "6af29ccc223b0feb6fc6112281c3fa3cdb1afddf",
"versionType": "git"
},
{
"lessThan": "db9d8e3b670f841755bc2018f178472dc6064d27",
"status": "affected",
"version": "6af29ccc223b0feb6fc6112281c3fa3cdb1afddf",
"versionType": "git"
},
{
"lessThan": "31efa656cf6aface26e88f038c14f22ee6ca1500",
"status": "affected",
"version": "6af29ccc223b0feb6fc6112281c3fa3cdb1afddf",
"versionType": "git"
},
{
"lessThan": "291accf36febce751021888de5f15090f4875b56",
"status": "affected",
"version": "6af29ccc223b0feb6fc6112281c3fa3cdb1afddf",
"versionType": "git"
},
{
"lessThan": "ca33df36aa0143a1d04f57d2086020c12e7eddb7",
"status": "affected",
"version": "6af29ccc223b0feb6fc6112281c3fa3cdb1afddf",
"versionType": "git"
},
{
"lessThan": "163847552a571bd55094291f4ffcdc1de0f14a7b",
"status": "affected",
"version": "6af29ccc223b0feb6fc6112281c3fa3cdb1afddf",
"versionType": "git"
},
{
"lessThan": "beb33f8ee1ca83acddb2a5ae80f3d22ec550b4c3",
"status": "affected",
"version": "6af29ccc223b0feb6fc6112281c3fa3cdb1afddf",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/sctp/associola.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.2"
},
{
"lessThan": "3.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: clear new_transport when removing a peer\n\nsctp_process_asconf_param() stores a newly added peer transport in\nasoc-\u003enew_transport. After all parameters in the ASCONF chunk have been\nprocessed, sctp_sf_do_asconf() uses this pointer to send a HEARTBEAT to the\nnew transport.\n\nAn authenticated ASCONF from a remote SCTP peer can add a transport and\nremove it again with a wildcard DEL-IP parameter in the same chunk. The\nwildcard deletion preserves the transport on which the ASCONF arrived, but\nremoves the newly added transport through\nsctp_assoc_del_nonprimary_peers(). The removal does not clear\nasoc-\u003enew_transport, leaving it pointing to the removed transport.\n\nsctp_sf_do_asconf() then creates a HEARTBEAT whose chunk-\u003etransport points\nto the removed transport without holding a transport reference. During\nlocal address replacement, src_out_of_asoc_ok keeps this HEARTBEAT on\ncontrol_chunk_list. After the transport is freed by RCU, a successful\nASCONF_ACK for the replacement address releases the queued HEARTBEAT and\nsctp_outq_select_transport() reads the freed transport\u0027s state.\n\nThe issue was found during a static audit of SCTP objects. With an\nauthenticated peer, the reproducer triggered the same KASAN report in 2\nof 2 unpatched runs on a KASAN-enabled netdev/main kernel:\n\n BUG: KASAN: slab-use-after-free in sctp_outq_select_transport\n Read of size 4 at addr ffff88800b9bd95c by task python3/197\n\n Call Trace:\n sctp_outq_select_transport+0x549/0x8b0 [sctp]\n sctp_outq_flush+0x306/0x2c60 [sctp]\n sctp_transport_immediate_rtx+0xaf/0x260 [sctp]\n sctp_process_asconf_ack+0xa48/0xf70 [sctp]\n\n Allocated by task 197:\n sctp_transport_new+0x68/0x650 [sctp]\n sctp_assoc_add_peer+0x258/0x12a0 [sctp]\n sctp_process_asconf+0x5e9/0x1090 [sctp]\n\n Last potentially related work creation:\n __call_rcu_common.constprop.0+0x77/0xb70\n sctp_assoc_del_nonprimary_peers+0x7c/0xd0 [sctp]\n sctp_process_asconf+0xd9c/0x1090 [sctp]\n\nThe first invalid access was a four-byte read of transport-\u003estate at\nnet/sctp/outqueue.c:833. The same reproducer completed the full\nauthenticated ASCONF and local-address replacement sequence with this\nchange without a KASAN report or oops.\n\nClear new_transport when its peer is removed, before it can be used to\ncreate the HEARTBEAT."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug is triggered when a remote SCTP peer sends an authenticated ASCONF chunk that is processed via sctp_rcv() through the state machine into sctp_sf_do_asconf() and sctp_process_asconf(); this is standard network packet handling, not a local syscall or ioctl path.\nAC:L - The remote peer fully controls a single ASCONF containing ADD_IP followed by wildcard DEL-IP to add then remove a transport while leaving asoc-\u003enew_transport dangling; combined with routine SCTP local address replacement (src_out_of_asoc_ok), the KASAN reproducer hit the UAF in 2/2 runs.\nPR:N - Exploitation requires only being an established SCTP association peer sending SCTP-AUTH-protected ASCONF traffic negotiated during the normal handshake (or addip_noauth); no Linux account, capability, or init-namespace privilege is needed on the victim host.\nUI:N - No victim user action such as opening a file or mounting a filesystem is required; the kernel automatically processes attacker-crafted ASCONF packets on an existing SCTP association during normal server operation.\nS:U - Impact is confined to kernel heap corruption on the vulnerable host (slab UAF on sctp_transport) and potential privilege escalation within that kernel; it does not cross VM, container, or IOMMU security boundaries.\nC:H - KASAN reports slab-use-after-free with a 4-byte read of freed sctp_transport-\u003estate in sctp_outq_select_transport(); UAF on heap transport objects enables grooming for arbitrary kernel memory disclosure per kernel CVSS guidance.\nI:H - The dangling sctp_transport pointer is embedded in a queued HEARTBEAT control chunk without a reference; UAF on this heap object can be leveraged via heap spraying for arbitrary kernel writes and control-flow hijacking, not merely a bounded corruption.\nA:H - Dereferencing the freed transport during sctp_outq_flush() causes a reproducible kernel UAF/oops; remote peers can repeatedly trigger this against SCTP endpoints handling ADD-IP traffic, yielding denial of service or crash."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:40:12.552Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c0f973bb5118dd1b146cda3fcc8af6f6057befec"
},
{
"url": "https://git.kernel.org/stable/c/3b539b317cd052236fed0350364ff1268996ba46"
},
{
"url": "https://git.kernel.org/stable/c/db9d8e3b670f841755bc2018f178472dc6064d27"
},
{
"url": "https://git.kernel.org/stable/c/31efa656cf6aface26e88f038c14f22ee6ca1500"
},
{
"url": "https://git.kernel.org/stable/c/291accf36febce751021888de5f15090f4875b56"
},
{
"url": "https://git.kernel.org/stable/c/ca33df36aa0143a1d04f57d2086020c12e7eddb7"
},
{
"url": "https://git.kernel.org/stable/c/163847552a571bd55094291f4ffcdc1de0f14a7b"
},
{
"url": "https://git.kernel.org/stable/c/beb33f8ee1ca83acddb2a5ae80f3d22ec550b4c3"
}
],
"title": "sctp: clear new_transport when removing a peer",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74586",
"datePublished": "2026-08-22T15:31:39.094Z",
"dateReserved": "2026-08-15T05:44:03.918Z",
"dateUpdated": "2026-08-25T05:40:12.552Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72023 (GCVE-0-2026-72023)
Vulnerability from cvelistv5
Published
2026-08-15 05:51
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
octeontx2-pf: fix SQB pointer leak on init failure
otx2_init_hw_resources() initializes SQ aura and pool resources before
several later setup steps. On failure, err_free_sq_ptrs only frees SQB
pages, leaving the per-SQ sqb_ptrs arrays behind.
Use otx2_free_sq_res() for the SQ unwind path and let it free sqb_ptrs
even when sq->sqe has not been allocated yet.
The bug was first flagged by an experimental analysis tool we are
developing for kernel memory-management bugs while analyzing
v6.13-rc1. The tool is still under development and is not yet publicly
available. Manual inspection confirms that the bug is still
present in v7.1.1.
An x86_64 allyesconfig build showed no new warnings. As we do not have an
OcteonTX2 PF device and the corresponding AF mailbox setup to test with,
no runtime testing was able to be performed.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: caa2da34fd25a37e9fd43343b6966fb9d730a6d5 Version: caa2da34fd25a37e9fd43343b6966fb9d730a6d5 Version: caa2da34fd25a37e9fd43343b6966fb9d730a6d5 Version: caa2da34fd25a37e9fd43343b6966fb9d730a6d5 Version: caa2da34fd25a37e9fd43343b6966fb9d730a6d5 Version: caa2da34fd25a37e9fd43343b6966fb9d730a6d5 Version: caa2da34fd25a37e9fd43343b6966fb9d730a6d5 Version: caa2da34fd25a37e9fd43343b6966fb9d730a6d5 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/marvell/octeontx2/nic/otx2_pf.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "fca9c22633169a6c5d429a32e439121b6419e2be",
"status": "affected",
"version": "caa2da34fd25a37e9fd43343b6966fb9d730a6d5",
"versionType": "git"
},
{
"lessThan": "42c2836f10ac0427dac9e9a923d6ee2189dec544",
"status": "affected",
"version": "caa2da34fd25a37e9fd43343b6966fb9d730a6d5",
"versionType": "git"
},
{
"lessThan": "2cac2eac935ed7e0a9203204e036a1f6090ebc3d",
"status": "affected",
"version": "caa2da34fd25a37e9fd43343b6966fb9d730a6d5",
"versionType": "git"
},
{
"lessThan": "148d7ec0a3a98839c320e6cdd112e2e88bfb091b",
"status": "affected",
"version": "caa2da34fd25a37e9fd43343b6966fb9d730a6d5",
"versionType": "git"
},
{
"lessThan": "5e023fe2569e630ba23b5558ebe4bf4837af4d16",
"status": "affected",
"version": "caa2da34fd25a37e9fd43343b6966fb9d730a6d5",
"versionType": "git"
},
{
"lessThan": "5df30f05db96552903680a17f858d250dfd9e86e",
"status": "affected",
"version": "caa2da34fd25a37e9fd43343b6966fb9d730a6d5",
"versionType": "git"
},
{
"lessThan": "23d917acd9c9a9fd999688ec3fdde7aa58ab8a14",
"status": "affected",
"version": "caa2da34fd25a37e9fd43343b6966fb9d730a6d5",
"versionType": "git"
},
{
"lessThan": "62e7df6d042aeebd5efb581074e28865c04477be",
"status": "affected",
"version": "caa2da34fd25a37e9fd43343b6966fb9d730a6d5",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/marvell/octeontx2/nic/otx2_pf.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.6"
},
{
"lessThan": "5.6",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nocteontx2-pf: fix SQB pointer leak on init failure\n\notx2_init_hw_resources() initializes SQ aura and pool resources before\nseveral later setup steps. On failure, err_free_sq_ptrs only frees SQB\npages, leaving the per-SQ sqb_ptrs arrays behind.\n\nUse otx2_free_sq_res() for the SQ unwind path and let it free sqb_ptrs\neven when sq-\u003esqe has not been allocated yet.\n\nThe bug was first flagged by an experimental analysis tool we are\ndeveloping for kernel memory-management bugs while analyzing\nv6.13-rc1. The tool is still under development and is not yet publicly\navailable. Manual inspection confirms that the bug is still\npresent in v7.1.1.\n\nAn x86_64 allyesconfig build showed no new warnings. As we do not have an\nOcteonTX2 PF device and the corresponding AF mailbox setup to test with,\nno runtime testing was able to be performed."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:27.683Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/fca9c22633169a6c5d429a32e439121b6419e2be"
},
{
"url": "https://git.kernel.org/stable/c/42c2836f10ac0427dac9e9a923d6ee2189dec544"
},
{
"url": "https://git.kernel.org/stable/c/2cac2eac935ed7e0a9203204e036a1f6090ebc3d"
},
{
"url": "https://git.kernel.org/stable/c/148d7ec0a3a98839c320e6cdd112e2e88bfb091b"
},
{
"url": "https://git.kernel.org/stable/c/5e023fe2569e630ba23b5558ebe4bf4837af4d16"
},
{
"url": "https://git.kernel.org/stable/c/5df30f05db96552903680a17f858d250dfd9e86e"
},
{
"url": "https://git.kernel.org/stable/c/23d917acd9c9a9fd999688ec3fdde7aa58ab8a14"
},
{
"url": "https://git.kernel.org/stable/c/62e7df6d042aeebd5efb581074e28865c04477be"
}
],
"title": "octeontx2-pf: fix SQB pointer leak on init failure",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72023",
"datePublished": "2026-08-15T05:51:48.629Z",
"dateReserved": "2026-08-09T03:40:39.900Z",
"dateUpdated": "2026-08-23T12:46:27.683Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68214 (GCVE-0-2026-68214)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: rtl2832: fix use-after-free in rtl2832_remove()
cancel_delayed_work_sync() is called before i2c_mux_del_adapters()
in rtl2832_remove(). While the cancel waits for any running instance
of i2c_gate_work to finish, it does not prevent the timer from being
rescheduled by a concurrent thread.
During probe, the r820t_attach() call attempts I2C transfers through
the mux adapter. These transfers go through i2c_mux_master_xfer(),
which calls rtl2832_deselect() after the transfer completes,
rescheduling i2c_gate_work via schedule_delayed_work(). If this
transfer is still in flight when rtl2832_remove() runs,
rtl2832_deselect() can reschedule i2c_gate_work after it has been
cancelled, causing a use-after-free when kfree(dev) is called.
Fix this by calling i2c_mux_del_adapters() before
cancel_delayed_work_sync(). Once the mux adapter is unregistered, no
new I2C transfers can go through it, so rtl2832_deselect() can no
longer reschedule i2c_gate_work. The subsequent
cancel_delayed_work_sync() is then guaranteed to be final.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: cddcc40b1b1553010acb89add84c64b5d123ec94 Version: cddcc40b1b1553010acb89add84c64b5d123ec94 Version: cddcc40b1b1553010acb89add84c64b5d123ec94 Version: cddcc40b1b1553010acb89add84c64b5d123ec94 Version: cddcc40b1b1553010acb89add84c64b5d123ec94 Version: cddcc40b1b1553010acb89add84c64b5d123ec94 Version: cddcc40b1b1553010acb89add84c64b5d123ec94 Version: cddcc40b1b1553010acb89add84c64b5d123ec94 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/dvb-frontends/rtl2832.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "1e8a6bc19403661661fed5ae82f6eca6c9cdfad2",
"status": "affected",
"version": "cddcc40b1b1553010acb89add84c64b5d123ec94",
"versionType": "git"
},
{
"lessThan": "68a9c0290897c1436ddceb8cea604c93377a0299",
"status": "affected",
"version": "cddcc40b1b1553010acb89add84c64b5d123ec94",
"versionType": "git"
},
{
"lessThan": "13c06056699e66ff7109ba68658cc6ea4a23f516",
"status": "affected",
"version": "cddcc40b1b1553010acb89add84c64b5d123ec94",
"versionType": "git"
},
{
"lessThan": "9acd5bbbe1df8e487e49488692c224496d4c9e16",
"status": "affected",
"version": "cddcc40b1b1553010acb89add84c64b5d123ec94",
"versionType": "git"
},
{
"lessThan": "24bef237eef8dd1ebcffb129ba21891ddad0d309",
"status": "affected",
"version": "cddcc40b1b1553010acb89add84c64b5d123ec94",
"versionType": "git"
},
{
"lessThan": "2c71bda6edc630a1f8c3c45d8df5fc22d234e042",
"status": "affected",
"version": "cddcc40b1b1553010acb89add84c64b5d123ec94",
"versionType": "git"
},
{
"lessThan": "90d781711418881f8c836c2a859cc2886625d750",
"status": "affected",
"version": "cddcc40b1b1553010acb89add84c64b5d123ec94",
"versionType": "git"
},
{
"lessThan": "680daf40a82d483949f87f0d8f98639dc47e610c",
"status": "affected",
"version": "cddcc40b1b1553010acb89add84c64b5d123ec94",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/dvb-frontends/rtl2832.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.7"
},
{
"lessThan": "4.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: rtl2832: fix use-after-free in rtl2832_remove()\n\ncancel_delayed_work_sync() is called before i2c_mux_del_adapters()\nin rtl2832_remove(). While the cancel waits for any running instance\nof i2c_gate_work to finish, it does not prevent the timer from being\nrescheduled by a concurrent thread.\n\nDuring probe, the r820t_attach() call attempts I2C transfers through\nthe mux adapter. These transfers go through i2c_mux_master_xfer(),\nwhich calls rtl2832_deselect() after the transfer completes,\nrescheduling i2c_gate_work via schedule_delayed_work(). If this\ntransfer is still in flight when rtl2832_remove() runs,\nrtl2832_deselect() can reschedule i2c_gate_work after it has been\ncancelled, causing a use-after-free when kfree(dev) is called.\n\nFix this by calling i2c_mux_del_adapters() before\ncancel_delayed_work_sync(). Once the mux adapter is unregistered, no\nnew I2C transfers can go through it, so rtl2832_deselect() can no\nlonger reschedule i2c_gate_work. The subsequent\ncancel_delayed_work_sync() is then guaranteed to be final."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:42.193Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/1e8a6bc19403661661fed5ae82f6eca6c9cdfad2"
},
{
"url": "https://git.kernel.org/stable/c/68a9c0290897c1436ddceb8cea604c93377a0299"
},
{
"url": "https://git.kernel.org/stable/c/13c06056699e66ff7109ba68658cc6ea4a23f516"
},
{
"url": "https://git.kernel.org/stable/c/9acd5bbbe1df8e487e49488692c224496d4c9e16"
},
{
"url": "https://git.kernel.org/stable/c/24bef237eef8dd1ebcffb129ba21891ddad0d309"
},
{
"url": "https://git.kernel.org/stable/c/2c71bda6edc630a1f8c3c45d8df5fc22d234e042"
},
{
"url": "https://git.kernel.org/stable/c/90d781711418881f8c836c2a859cc2886625d750"
},
{
"url": "https://git.kernel.org/stable/c/680daf40a82d483949f87f0d8f98639dc47e610c"
}
],
"title": "media: rtl2832: fix use-after-free in rtl2832_remove()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68214",
"datePublished": "2026-08-10T12:00:33.539Z",
"dateReserved": "2026-07-30T09:28:09.375Z",
"dateUpdated": "2026-08-19T16:31:42.193Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80793 (GCVE-0-2026-80793)
Vulnerability from cvelistv5
Published
2026-09-04 15:13
Modified
2026-09-04 15:13
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ipv4: reject undersized MTUs in ip_do_fragment()
ip_do_fragment() subtracts the IPv4 header length from the effective
MTU and passes the resulting payload MTU to ip_frag_next().
If the effective MTU is smaller than hlen + 8, ip_frag_next() rounds
the fragment payload length down to zero. The fragmentation state then
never makes forward progress: state->left, state->ptr and state->offset
stay unchanged while ip_do_fragment() keeps allocating and transmitting
header-only fragments until the softlockup detector fires.
This is reproducible with a route installed using "mtu lock 20", but it
is also reproducible without route MTU lock, for example by forwarding a
packet to a device whose MTU is 20.
Fix it in ip_do_fragment() by rejecting mtu < hlen + 8 with -EMSGSIZE,
matching the existing IPv6 fragmentation check.
References
| URL | Tags | ||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ipv4/ip_output.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a716a64a4ba68cd46f2745fba2b1099fe8e0aa59",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "515b6816ba0c12d8415c88e5f41e6ec029e35cfa",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "74ce7389f8f562d39015f59a00ef7ad6acd37803",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "b0ea911453ce7210e8200a07a94d2458bd1e6430",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "36e0741833bd823866f8cb9f112f37cea1a70b60",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "d9d1a676b033acabf8e5645f730486d1f8204a3f",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "3556beb8ca86677af2aca5bfbed6f8e790fccc83",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "c8a74adccaf028223054633b532593101dfcc581",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "c0726f0caf8c6b3208552949e17d23634a2f3129",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ipv4/ip_output.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.267",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.218",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.185",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.154",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.106",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.47",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.1",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.267",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.218",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.185",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.154",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.106",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.47",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.11",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.1",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: reject undersized MTUs in ip_do_fragment()\n\nip_do_fragment() subtracts the IPv4 header length from the effective\nMTU and passes the resulting payload MTU to ip_frag_next().\n\nIf the effective MTU is smaller than hlen + 8, ip_frag_next() rounds\nthe fragment payload length down to zero. The fragmentation state then\nnever makes forward progress: state-\u003eleft, state-\u003eptr and state-\u003eoffset\nstay unchanged while ip_do_fragment() keeps allocating and transmitting\nheader-only fragments until the softlockup detector fires.\n\nThis is reproducible with a route installed using \"mtu lock 20\", but it\nis also reproducible without route MTU lock, for example by forwarding a\npacket to a device whose MTU is 20.\n\nFix it in ip_do_fragment() by rejecting mtu \u003c hlen + 8 with -EMSGSIZE,\nmatching the existing IPv6 fragmentation check."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T15:13:05.814Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a716a64a4ba68cd46f2745fba2b1099fe8e0aa59"
},
{
"url": "https://git.kernel.org/stable/c/515b6816ba0c12d8415c88e5f41e6ec029e35cfa"
},
{
"url": "https://git.kernel.org/stable/c/74ce7389f8f562d39015f59a00ef7ad6acd37803"
},
{
"url": "https://git.kernel.org/stable/c/b0ea911453ce7210e8200a07a94d2458bd1e6430"
},
{
"url": "https://git.kernel.org/stable/c/36e0741833bd823866f8cb9f112f37cea1a70b60"
},
{
"url": "https://git.kernel.org/stable/c/d9d1a676b033acabf8e5645f730486d1f8204a3f"
},
{
"url": "https://git.kernel.org/stable/c/3556beb8ca86677af2aca5bfbed6f8e790fccc83"
},
{
"url": "https://git.kernel.org/stable/c/c8a74adccaf028223054633b532593101dfcc581"
},
{
"url": "https://git.kernel.org/stable/c/c0726f0caf8c6b3208552949e17d23634a2f3129"
}
],
"title": "ipv4: reject undersized MTUs in ip_do_fragment()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80793",
"datePublished": "2026-09-04T15:13:05.814Z",
"dateReserved": "2026-08-26T14:34:25.793Z",
"dateUpdated": "2026-09-04T15:13:05.814Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-46170 (GCVE-0-2026-46170)
Vulnerability from cvelistv5
Published
2026-05-28 09:36
Modified
2026-08-27 12:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
mptcp: pm: ADD_ADDR rtx: free sk if last
When an ADD_ADDR is retransmitted, the sk is held in sk_reset_timer(),
and released at the end.
If at that moment, it was the last reference being held, the sk would
not be freed. sock_put() should then be called instead of __sock_put().
But that's not enough: if it is the last reference, sock_put() will call
sk_free(), which will end up calling sk_stop_timer_sync() on the same
timer, and waiting indefinitely to finish. So it is needed to mark that
the timer is done at the end of the timer handler when it has not been
rescheduled, not to call sk_stop_timer_sync() on "itself".
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 00cfd77b9063dcdf3628a7087faba60de85a9cc8 Version: 00cfd77b9063dcdf3628a7087faba60de85a9cc8 Version: 00cfd77b9063dcdf3628a7087faba60de85a9cc8 Version: 00cfd77b9063dcdf3628a7087faba60de85a9cc8 Version: 00cfd77b9063dcdf3628a7087faba60de85a9cc8 Version: 00cfd77b9063dcdf3628a7087faba60de85a9cc8 Version: 00cfd77b9063dcdf3628a7087faba60de85a9cc8 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/mptcp/pm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "1f26487e83e69462540bb1047139472957c913c6",
"status": "affected",
"version": "00cfd77b9063dcdf3628a7087faba60de85a9cc8",
"versionType": "git"
},
{
"lessThan": "5da972efed3dc7599da6e2b5e8d906d1b7b1a728",
"status": "affected",
"version": "00cfd77b9063dcdf3628a7087faba60de85a9cc8",
"versionType": "git"
},
{
"lessThan": "6a3af482188f6db4186d1605f64d911d7330abb3",
"status": "affected",
"version": "00cfd77b9063dcdf3628a7087faba60de85a9cc8",
"versionType": "git"
},
{
"lessThan": "531c537b8fb620beabccfb1594e8d43cbebbb87a",
"status": "affected",
"version": "00cfd77b9063dcdf3628a7087faba60de85a9cc8",
"versionType": "git"
},
{
"lessThan": "b74ad20198652b6b39a761c277ba65ae82b1e107",
"status": "affected",
"version": "00cfd77b9063dcdf3628a7087faba60de85a9cc8",
"versionType": "git"
},
{
"lessThan": "8143a224785ceaf2b0856e08d4498916f38228fb",
"status": "affected",
"version": "00cfd77b9063dcdf3628a7087faba60de85a9cc8",
"versionType": "git"
},
{
"lessThan": "b7b9a461569734d33d3259d58d2507adfac107ed",
"status": "affected",
"version": "00cfd77b9063dcdf3628a7087faba60de85a9cc8",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/mptcp/pm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.10"
},
{
"lessThan": "5.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.218",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.185",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.142",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.92",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.30",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.7",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.218",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.185",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.142",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.92",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.30",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.7",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "5.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: pm: ADD_ADDR rtx: free sk if last\n\nWhen an ADD_ADDR is retransmitted, the sk is held in sk_reset_timer(),\nand released at the end.\n\nIf at that moment, it was the last reference being held, the sk would\nnot be freed. sock_put() should then be called instead of __sock_put().\n\nBut that\u0027s not enough: if it is the last reference, sock_put() will call\nsk_free(), which will end up calling sk_stop_timer_sync() on the same\ntimer, and waiting indefinitely to finish. So it is needed to mark that\nthe timer is done at the end of the timer handler when it has not been\nrescheduled, not to call sk_stop_timer_sync() on \"itself\"."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T12:39:41.056Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/1f26487e83e69462540bb1047139472957c913c6"
},
{
"url": "https://git.kernel.org/stable/c/5da972efed3dc7599da6e2b5e8d906d1b7b1a728"
},
{
"url": "https://git.kernel.org/stable/c/6a3af482188f6db4186d1605f64d911d7330abb3"
},
{
"url": "https://git.kernel.org/stable/c/531c537b8fb620beabccfb1594e8d43cbebbb87a"
},
{
"url": "https://git.kernel.org/stable/c/b74ad20198652b6b39a761c277ba65ae82b1e107"
},
{
"url": "https://git.kernel.org/stable/c/8143a224785ceaf2b0856e08d4498916f38228fb"
},
{
"url": "https://git.kernel.org/stable/c/b7b9a461569734d33d3259d58d2507adfac107ed"
}
],
"title": "mptcp: pm: ADD_ADDR rtx: free sk if last",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-46170",
"datePublished": "2026-05-28T09:36:25.184Z",
"dateReserved": "2026-05-13T15:03:33.103Z",
"dateUpdated": "2026-08-27T12:39:41.056Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68140 (GCVE-0-2026-68140)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/iucv: fix use-after-free of a severed iucv_path
af_iucv queues not-yet-received message notifications on iucv->message_q,
each holding a raw pointer to the connection's iucv_path. When the peer
severs the connection, iucv_sever_path() frees that path with
iucv_path_free() but leaves the notifications queued. A later recvmsg()
drains message_q via iucv_process_message_q() and hands the stale path to
message_receive() -- a use-after-free of the freed iucv_path.
Drop the queued notifications when the path is severed; once the path is
gone they can no longer be received. This also frees the notifications
leaked when a socket is closed with messages still queued.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: f0703c80e5156406ad947cb67fe277725b48080f Version: f0703c80e5156406ad947cb67fe277725b48080f Version: f0703c80e5156406ad947cb67fe277725b48080f Version: f0703c80e5156406ad947cb67fe277725b48080f Version: f0703c80e5156406ad947cb67fe277725b48080f Version: f0703c80e5156406ad947cb67fe277725b48080f Version: f0703c80e5156406ad947cb67fe277725b48080f Version: f0703c80e5156406ad947cb67fe277725b48080f |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/iucv/af_iucv.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "5f08c5e50bcb4680069bd3f9edd5728308816ded",
"status": "affected",
"version": "f0703c80e5156406ad947cb67fe277725b48080f",
"versionType": "git"
},
{
"lessThan": "c24faf11bd31bfe0500aca12cbdd5a573a954a5d",
"status": "affected",
"version": "f0703c80e5156406ad947cb67fe277725b48080f",
"versionType": "git"
},
{
"lessThan": "99ddb33748698296a6f17b9b34aa3d16a406bb3c",
"status": "affected",
"version": "f0703c80e5156406ad947cb67fe277725b48080f",
"versionType": "git"
},
{
"lessThan": "23658b350b4107e8292045c2044983fd426fa15d",
"status": "affected",
"version": "f0703c80e5156406ad947cb67fe277725b48080f",
"versionType": "git"
},
{
"lessThan": "a5bbaddf69853117f28173c3f5c8fc14c6b2ec82",
"status": "affected",
"version": "f0703c80e5156406ad947cb67fe277725b48080f",
"versionType": "git"
},
{
"lessThan": "900cd6d8119b7f3ae5c4bf82f922ff5957df43db",
"status": "affected",
"version": "f0703c80e5156406ad947cb67fe277725b48080f",
"versionType": "git"
},
{
"lessThan": "f579582c03ed526281a8450159baf1d35099a85f",
"status": "affected",
"version": "f0703c80e5156406ad947cb67fe277725b48080f",
"versionType": "git"
},
{
"lessThan": "be7cc4656eb1f54029610e82d1f0fdd3f9b5ec0a",
"status": "affected",
"version": "f0703c80e5156406ad947cb67fe277725b48080f",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/iucv/af_iucv.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.24"
},
{
"lessThan": "2.6.24",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.24",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/iucv: fix use-after-free of a severed iucv_path\n\naf_iucv queues not-yet-received message notifications on iucv-\u003emessage_q,\neach holding a raw pointer to the connection\u0027s iucv_path. When the peer\nsevers the connection, iucv_sever_path() frees that path with\niucv_path_free() but leaves the notifications queued. A later recvmsg()\ndrains message_q via iucv_process_message_q() and hands the stale path to\nmessage_receive() -- a use-after-free of the freed iucv_path.\n\nDrop the queued notifications when the path is severed; once the path is\ngone they can no longer be received. This also frees the notifications\nleaked when a socket is closed with messages still queued."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - An adjacent z/VM guest or LPAR peer can establish an AF_IUCV connection and deliver IUCV message_pending and path_severed events to a victim; exploitation requires same-CPC IUCV reachability, not Internet-wide access.\nAC:L - The attacker deterministically floods IUCV messages to fill message_q, severs the connection to free iucv_path, then victim recvmsg() drains the stale queue; no uncontrollable timing or memory-layout luck is required.\nPR:N - On the victim, no local Linux account or capability is needed; any unauthorized adjacent IUCV peer that completes the AF_IUCV handshake can flood messages and sever the path against a listening service.\nUI:N - No special victim action is required beyond normal server recvmsg() on an established IUCV session; the attacker drives connection setup, message flood, and path sever entirely from the peer side.\nS:U - Impact is kernel memory corruption within the victim Linux guest; it does not cross hypervisor, VM-escape, or IOMMU security boundaries.\nC:H - Queued notifications dereference a freed struct iucv_path in message_receive(), passing stale pathid and private fields into CP IUCV RECEIVE calls\u2014a classic UAF enabling attacker-controlled heap reuse and kernel memory disclosure.\nI:H - Use-after-free of iucv_path lets an attacker reclaim the freed object and supply forged pathid and list pointers used by __iucv_message_receive(), providing heap corruption primitives suitable for arbitrary kernel write or code execution.\nA:H - Processing the stale path in iucv_process_message_q() dereferences freed kernel memory during message_receive(), reliably causing kernel oops or panic and total loss of availability even before full exploitation."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:29:57.127Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/5f08c5e50bcb4680069bd3f9edd5728308816ded"
},
{
"url": "https://git.kernel.org/stable/c/c24faf11bd31bfe0500aca12cbdd5a573a954a5d"
},
{
"url": "https://git.kernel.org/stable/c/99ddb33748698296a6f17b9b34aa3d16a406bb3c"
},
{
"url": "https://git.kernel.org/stable/c/23658b350b4107e8292045c2044983fd426fa15d"
},
{
"url": "https://git.kernel.org/stable/c/a5bbaddf69853117f28173c3f5c8fc14c6b2ec82"
},
{
"url": "https://git.kernel.org/stable/c/900cd6d8119b7f3ae5c4bf82f922ff5957df43db"
},
{
"url": "https://git.kernel.org/stable/c/f579582c03ed526281a8450159baf1d35099a85f"
},
{
"url": "https://git.kernel.org/stable/c/be7cc4656eb1f54029610e82d1f0fdd3f9b5ec0a"
}
],
"title": "net/iucv: fix use-after-free of a severed iucv_path",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68140",
"datePublished": "2026-08-10T11:59:03.761Z",
"dateReserved": "2026-07-30T09:28:09.370Z",
"dateUpdated": "2026-08-19T16:29:57.127Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80831 (GCVE-0-2026-80831)
Vulnerability from cvelistv5
Published
2026-09-04 15:54
Modified
2026-09-04 15:54
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
crypto: mxs-dcp - fix source scatterlist length access
mxs_dcp_aes_block_crypt() uses sg_dma_len() without mapping the source
scatterlist with dma_map_sg() first. Therefore, sg_dma_len() is invalid
and could return zero or a stale DMA length, causing encryption and
decryption to process the wrong number of bytes when
CONFIG_NEED_SG_DMA_LENGTH=y.
Use the original scatterlist length instead.
References
| URL | Tags | ||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 15b59e7c3733f90ff1f7dd66ad77ae1c90bcdff5 Version: 15b59e7c3733f90ff1f7dd66ad77ae1c90bcdff5 Version: 15b59e7c3733f90ff1f7dd66ad77ae1c90bcdff5 Version: 15b59e7c3733f90ff1f7dd66ad77ae1c90bcdff5 Version: 15b59e7c3733f90ff1f7dd66ad77ae1c90bcdff5 Version: 15b59e7c3733f90ff1f7dd66ad77ae1c90bcdff5 Version: 15b59e7c3733f90ff1f7dd66ad77ae1c90bcdff5 Version: 15b59e7c3733f90ff1f7dd66ad77ae1c90bcdff5 Version: 15b59e7c3733f90ff1f7dd66ad77ae1c90bcdff5 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/crypto/mxs-dcp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "fd0f211b27a6ec2ebd8c315683401b43adcc5511",
"status": "affected",
"version": "15b59e7c3733f90ff1f7dd66ad77ae1c90bcdff5",
"versionType": "git"
},
{
"lessThan": "04201dcc88b26eac52f736e39727fc5c420b7257",
"status": "affected",
"version": "15b59e7c3733f90ff1f7dd66ad77ae1c90bcdff5",
"versionType": "git"
},
{
"lessThan": "e72a795df521cb65b7c4705cc11078cdacfaa2f4",
"status": "affected",
"version": "15b59e7c3733f90ff1f7dd66ad77ae1c90bcdff5",
"versionType": "git"
},
{
"lessThan": "1537bd55b4f842565068c54b47cd2ae1777d5f8f",
"status": "affected",
"version": "15b59e7c3733f90ff1f7dd66ad77ae1c90bcdff5",
"versionType": "git"
},
{
"lessThan": "da14fae5203b72ca71ccfa9af8de9249e40d533a",
"status": "affected",
"version": "15b59e7c3733f90ff1f7dd66ad77ae1c90bcdff5",
"versionType": "git"
},
{
"lessThan": "182f16a20d329a1c818d51dad57d9bf43d356c7c",
"status": "affected",
"version": "15b59e7c3733f90ff1f7dd66ad77ae1c90bcdff5",
"versionType": "git"
},
{
"lessThan": "0e9edb108a63bbbef952dfcbc597e34ed9c1fb74",
"status": "affected",
"version": "15b59e7c3733f90ff1f7dd66ad77ae1c90bcdff5",
"versionType": "git"
},
{
"lessThan": "6ef9a4afb52cb102ab038cd42352c142d8505d09",
"status": "affected",
"version": "15b59e7c3733f90ff1f7dd66ad77ae1c90bcdff5",
"versionType": "git"
},
{
"lessThan": "c5bcb084a9871e5b62afb5f48b60adfa13b5d9f8",
"status": "affected",
"version": "15b59e7c3733f90ff1f7dd66ad77ae1c90bcdff5",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/crypto/mxs-dcp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.14"
},
{
"lessThan": "3.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.269",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.220",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.187",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.156",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.108",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.49",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.13",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.3",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.269",
"versionStartIncluding": "3.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.220",
"versionStartIncluding": "3.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.187",
"versionStartIncluding": "3.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.156",
"versionStartIncluding": "3.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.108",
"versionStartIncluding": "3.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.49",
"versionStartIncluding": "3.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.13",
"versionStartIncluding": "3.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.3",
"versionStartIncluding": "3.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "3.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: mxs-dcp - fix source scatterlist length access\n\nmxs_dcp_aes_block_crypt() uses sg_dma_len() without mapping the source\nscatterlist with dma_map_sg() first. Therefore, sg_dma_len() is invalid\nand could return zero or a stale DMA length, causing encryption and\ndecryption to process the wrong number of bytes when\nCONFIG_NEED_SG_DMA_LENGTH=y.\n\nUse the original scatterlist length instead."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T15:54:36.250Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/fd0f211b27a6ec2ebd8c315683401b43adcc5511"
},
{
"url": "https://git.kernel.org/stable/c/04201dcc88b26eac52f736e39727fc5c420b7257"
},
{
"url": "https://git.kernel.org/stable/c/e72a795df521cb65b7c4705cc11078cdacfaa2f4"
},
{
"url": "https://git.kernel.org/stable/c/1537bd55b4f842565068c54b47cd2ae1777d5f8f"
},
{
"url": "https://git.kernel.org/stable/c/da14fae5203b72ca71ccfa9af8de9249e40d533a"
},
{
"url": "https://git.kernel.org/stable/c/182f16a20d329a1c818d51dad57d9bf43d356c7c"
},
{
"url": "https://git.kernel.org/stable/c/0e9edb108a63bbbef952dfcbc597e34ed9c1fb74"
},
{
"url": "https://git.kernel.org/stable/c/6ef9a4afb52cb102ab038cd42352c142d8505d09"
},
{
"url": "https://git.kernel.org/stable/c/c5bcb084a9871e5b62afb5f48b60adfa13b5d9f8"
}
],
"title": "crypto: mxs-dcp - fix source scatterlist length access",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80831",
"datePublished": "2026-09-04T15:54:36.250Z",
"dateReserved": "2026-08-26T14:34:25.796Z",
"dateUpdated": "2026-09-04T15:54:36.250Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68226 (GCVE-0-2026-68226)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: cx23885: add ioremap return check and cleanup
Add a check for the return value of pci_ioremap_bar()
in cx23885_dev_setup().
If ioremap for BAR0 fails, release the already allocated
PCI memory region,
decrement the device count, and return -ENODEV.
This prevents a potential null pointer dereference and
ensures proper cleanup
on memory mapping failure.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d19770e5178a4bc49641711246360c25781d20a4 Version: d19770e5178a4bc49641711246360c25781d20a4 Version: d19770e5178a4bc49641711246360c25781d20a4 Version: d19770e5178a4bc49641711246360c25781d20a4 Version: d19770e5178a4bc49641711246360c25781d20a4 Version: d19770e5178a4bc49641711246360c25781d20a4 Version: d19770e5178a4bc49641711246360c25781d20a4 Version: d19770e5178a4bc49641711246360c25781d20a4 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/pci/cx23885/cx23885-core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "f58f4b571bd75c78bbf15441086ba0c2830c1aa5",
"status": "affected",
"version": "d19770e5178a4bc49641711246360c25781d20a4",
"versionType": "git"
},
{
"lessThan": "9052fec0bb84eace81ac7bad071266052870cdf3",
"status": "affected",
"version": "d19770e5178a4bc49641711246360c25781d20a4",
"versionType": "git"
},
{
"lessThan": "6a7636e3d5204fb18fdf1c3f909a3d9d9e24064c",
"status": "affected",
"version": "d19770e5178a4bc49641711246360c25781d20a4",
"versionType": "git"
},
{
"lessThan": "8fbdca4c99f68734e9b6c030973fb61a11bede15",
"status": "affected",
"version": "d19770e5178a4bc49641711246360c25781d20a4",
"versionType": "git"
},
{
"lessThan": "83540d86d717735b52a43e4ba1b784da5cc2310a",
"status": "affected",
"version": "d19770e5178a4bc49641711246360c25781d20a4",
"versionType": "git"
},
{
"lessThan": "c68c4ce72feb6fcccc843eb3baa7af60189ed567",
"status": "affected",
"version": "d19770e5178a4bc49641711246360c25781d20a4",
"versionType": "git"
},
{
"lessThan": "ff3c670a1de3a714f5644e37b9446fe7c3299fd3",
"status": "affected",
"version": "d19770e5178a4bc49641711246360c25781d20a4",
"versionType": "git"
},
{
"lessThan": "a0701e387b46e2481c05b47f1235b954bfc2af3e",
"status": "affected",
"version": "d19770e5178a4bc49641711246360c25781d20a4",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/pci/cx23885/cx23885-core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.24"
},
{
"lessThan": "2.6.24",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.24",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: cx23885: add ioremap return check and cleanup\n\nAdd a check for the return value of pci_ioremap_bar()\nin cx23885_dev_setup().\nIf ioremap for BAR0 fails, release the already allocated\nPCI memory region,\ndecrement the device count, and return -ENODEV.\n\nThis prevents a potential null pointer dereference and\nensures proper cleanup\non memory mapping failure."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:56.630Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/f58f4b571bd75c78bbf15441086ba0c2830c1aa5"
},
{
"url": "https://git.kernel.org/stable/c/9052fec0bb84eace81ac7bad071266052870cdf3"
},
{
"url": "https://git.kernel.org/stable/c/6a7636e3d5204fb18fdf1c3f909a3d9d9e24064c"
},
{
"url": "https://git.kernel.org/stable/c/8fbdca4c99f68734e9b6c030973fb61a11bede15"
},
{
"url": "https://git.kernel.org/stable/c/83540d86d717735b52a43e4ba1b784da5cc2310a"
},
{
"url": "https://git.kernel.org/stable/c/c68c4ce72feb6fcccc843eb3baa7af60189ed567"
},
{
"url": "https://git.kernel.org/stable/c/ff3c670a1de3a714f5644e37b9446fe7c3299fd3"
},
{
"url": "https://git.kernel.org/stable/c/a0701e387b46e2481c05b47f1235b954bfc2af3e"
}
],
"title": "media: cx23885: add ioremap return check and cleanup",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68226",
"datePublished": "2026-08-10T12:00:48.349Z",
"dateReserved": "2026-07-30T09:28:09.376Z",
"dateUpdated": "2026-08-19T16:31:56.630Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68243 (GCVE-0-2026-68243)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-19 16:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU
Setting context engine slot N into I915_ENGINE_CLASS_INVALID /
I915_ENGINE_CLASS_INVALID_NONE and attempting to apply
I915_CONTEXT_PARAM_SSEU to the same slot N will deref NULL.
Fix that.
Discovered using AI-assisted static analysis confirmed by
Intel Product Security.
(cherry picked from commit 36eda5b5c2d40da41cc0a5403c26986237cf9e87)
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d4433c7600f794623d6802395542cf4ca4f1b1f9 Version: d4433c7600f794623d6802395542cf4ca4f1b1f9 Version: d4433c7600f794623d6802395542cf4ca4f1b1f9 Version: d4433c7600f794623d6802395542cf4ca4f1b1f9 Version: d4433c7600f794623d6802395542cf4ca4f1b1f9 Version: d4433c7600f794623d6802395542cf4ca4f1b1f9 Version: d4433c7600f794623d6802395542cf4ca4f1b1f9 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/i915/gem/i915_gem_context.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "97a4872ef927dee301d76085cb19f6e36d4a53a4",
"status": "affected",
"version": "d4433c7600f794623d6802395542cf4ca4f1b1f9",
"versionType": "git"
},
{
"lessThan": "b226dee4ee1fff2909f79e8ad700b7082f8d3569",
"status": "affected",
"version": "d4433c7600f794623d6802395542cf4ca4f1b1f9",
"versionType": "git"
},
{
"lessThan": "edd2edaca52ada833c341c8b264aaea9dd93369c",
"status": "affected",
"version": "d4433c7600f794623d6802395542cf4ca4f1b1f9",
"versionType": "git"
},
{
"lessThan": "9923c223d38fcd9602f41cc31d480e5299d9a38e",
"status": "affected",
"version": "d4433c7600f794623d6802395542cf4ca4f1b1f9",
"versionType": "git"
},
{
"lessThan": "726f27bca93e6c83b263542669132ee1d0eb693e",
"status": "affected",
"version": "d4433c7600f794623d6802395542cf4ca4f1b1f9",
"versionType": "git"
},
{
"lessThan": "97f236379f06a5082d37c6a764edd56bb58a94cd",
"status": "affected",
"version": "d4433c7600f794623d6802395542cf4ca4f1b1f9",
"versionType": "git"
},
{
"lessThan": "2b56757a9a7456825eb668fde92299e01c5e2721",
"status": "affected",
"version": "d4433c7600f794623d6802395542cf4ca4f1b1f9",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/i915/gem/i915_gem_context.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.15"
},
{
"lessThan": "5.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU\n\nSetting context engine slot N into I915_ENGINE_CLASS_INVALID /\nI915_ENGINE_CLASS_INVALID_NONE and attempting to apply\nI915_CONTEXT_PARAM_SSEU to the same slot N will deref NULL.\nFix that.\n\nDiscovered using AI-assisted static analysis confirmed by\nIntel Product Security.\n\n(cherry picked from commit 36eda5b5c2d40da41cc0a5403c26986237cf9e87)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:32:08.740Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/97a4872ef927dee301d76085cb19f6e36d4a53a4"
},
{
"url": "https://git.kernel.org/stable/c/b226dee4ee1fff2909f79e8ad700b7082f8d3569"
},
{
"url": "https://git.kernel.org/stable/c/edd2edaca52ada833c341c8b264aaea9dd93369c"
},
{
"url": "https://git.kernel.org/stable/c/9923c223d38fcd9602f41cc31d480e5299d9a38e"
},
{
"url": "https://git.kernel.org/stable/c/726f27bca93e6c83b263542669132ee1d0eb693e"
},
{
"url": "https://git.kernel.org/stable/c/97f236379f06a5082d37c6a764edd56bb58a94cd"
},
{
"url": "https://git.kernel.org/stable/c/2b56757a9a7456825eb668fde92299e01c5e2721"
}
],
"title": "drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68243",
"datePublished": "2026-08-10T12:01:09.484Z",
"dateReserved": "2026-07-30T09:28:09.377Z",
"dateUpdated": "2026-08-19T16:32:08.740Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72237 (GCVE-0-2026-72237)
Vulnerability from cvelistv5
Published
2026-08-15 05:54
Modified
2026-08-19 16:36
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
perf/x86/amd/brs: Fix kernel address leakage
A user-only branch stack can contain branches that originate from
the kernel. As a result, kernel addresses are exposed to user space
even when PERF_SAMPLE_BRANCH_USER is requested. On AMD processors
supporting X86_FEATURE_BRS (Zen 3 only), perf can still report entries
such as SYSRET/interrupt returns for which the branch-from addresses
are in the kernel.
E.g.
$ perf record -j any,u -c 4000 -e branch-brs -o - -- \
perf bench syscall basic --loop 1000 | \
perf script -i - -F brstack|tr ' ' '\n'| \
grep -E '0x[89a-f][0-9a-f]{15}'
...
0xffffffff810001c4/0x72e2e32955eb/-/-/-/0//-
0xffffffff810001c4/0x72e2d94a9821/-/-/-/0//-
0xffffffff810001c4/0x72e2d94ffa1b/-/-/-/0//-
...
BRS provides no hardware branch filtering, so privilege level
filtering is performed entirely in software. However, amd_brs_match_plm()
only validates the branch-to address against the requested privilege
levels. For branches from the kernel to user space, the branch-from
address is left unchecked and is leaked. Extend the software filter to
also validate the branch-from address, so that any branch record whose
branch-from address is in the kernel is dropped when
PERF_SAMPLE_BRANCH_USER is requested.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 8910075d61a37e5b0d82e6c83ed9a0a31fe9ea08 Version: 8910075d61a37e5b0d82e6c83ed9a0a31fe9ea08 Version: 8910075d61a37e5b0d82e6c83ed9a0a31fe9ea08 Version: 8910075d61a37e5b0d82e6c83ed9a0a31fe9ea08 Version: 8910075d61a37e5b0d82e6c83ed9a0a31fe9ea08 Version: 8910075d61a37e5b0d82e6c83ed9a0a31fe9ea08 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"arch/x86/events/amd/brs.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "4f949bc3913a6e3ce3b8574ac6ed1da8ec7a5ad1",
"status": "affected",
"version": "8910075d61a37e5b0d82e6c83ed9a0a31fe9ea08",
"versionType": "git"
},
{
"lessThan": "ac44b4a3d6137489f8fa2e794b12e849c6b22eaa",
"status": "affected",
"version": "8910075d61a37e5b0d82e6c83ed9a0a31fe9ea08",
"versionType": "git"
},
{
"lessThan": "90843d00dbc61220b66408ea0d8775cae9e51f70",
"status": "affected",
"version": "8910075d61a37e5b0d82e6c83ed9a0a31fe9ea08",
"versionType": "git"
},
{
"lessThan": "046f6244da9b68e463a849b21446b9424e531491",
"status": "affected",
"version": "8910075d61a37e5b0d82e6c83ed9a0a31fe9ea08",
"versionType": "git"
},
{
"lessThan": "2e706be56f418718bb3ae66c0aa94f9b61150e6d",
"status": "affected",
"version": "8910075d61a37e5b0d82e6c83ed9a0a31fe9ea08",
"versionType": "git"
},
{
"lessThan": "47915e855fb38b42133e31ba917d99565f862154",
"status": "affected",
"version": "8910075d61a37e5b0d82e6c83ed9a0a31fe9ea08",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"arch/x86/events/amd/brs.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.19"
},
{
"lessThan": "5.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nperf/x86/amd/brs: Fix kernel address leakage\n\nA user-only branch stack can contain branches that originate from\nthe kernel. As a result, kernel addresses are exposed to user space\neven when PERF_SAMPLE_BRANCH_USER is requested. On AMD processors\nsupporting X86_FEATURE_BRS (Zen 3 only), perf can still report entries\nsuch as SYSRET/interrupt returns for which the branch-from addresses\nare in the kernel.\n\nE.g.\n\n $ perf record -j any,u -c 4000 -e branch-brs -o - -- \\\n perf bench syscall basic --loop 1000 | \\\n perf script -i - -F brstack|tr \u0027 \u0027 \u0027\\n\u0027| \\\n grep -E \u00270x[89a-f][0-9a-f]{15}\u0027\n\n ...\n 0xffffffff810001c4/0x72e2e32955eb/-/-/-/0//-\n 0xffffffff810001c4/0x72e2d94a9821/-/-/-/0//-\n 0xffffffff810001c4/0x72e2d94ffa1b/-/-/-/0//-\n ...\n\nBRS provides no hardware branch filtering, so privilege level\nfiltering is performed entirely in software. However, amd_brs_match_plm()\nonly validates the branch-to address against the requested privilege\nlevels. For branches from the kernel to user space, the branch-from\naddress is left unchecked and is leaked. Extend the software filter to\nalso validate the branch-from address, so that any branch record whose\nbranch-from address is in the kernel is dropped when\nPERF_SAMPLE_BRANCH_USER is requested."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:36:31.271Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/4f949bc3913a6e3ce3b8574ac6ed1da8ec7a5ad1"
},
{
"url": "https://git.kernel.org/stable/c/ac44b4a3d6137489f8fa2e794b12e849c6b22eaa"
},
{
"url": "https://git.kernel.org/stable/c/90843d00dbc61220b66408ea0d8775cae9e51f70"
},
{
"url": "https://git.kernel.org/stable/c/046f6244da9b68e463a849b21446b9424e531491"
},
{
"url": "https://git.kernel.org/stable/c/2e706be56f418718bb3ae66c0aa94f9b61150e6d"
},
{
"url": "https://git.kernel.org/stable/c/47915e855fb38b42133e31ba917d99565f862154"
}
],
"title": "perf/x86/amd/brs: Fix kernel address leakage",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72237",
"datePublished": "2026-08-15T05:54:26.685Z",
"dateReserved": "2026-08-09T03:40:39.914Z",
"dateUpdated": "2026-08-19T16:36:31.271Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68362 (GCVE-0-2026-68362)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: ath11k: fix NULL pointer dereference in ath11k_hal_srng_access_begin
In ATH11K_QMI_EVENT_FW_READY, ATH11K_FLAG_REGISTERED is set
unconditionally even when ath11k_core_qmi_firmware_ready() fails.
This leaves the driver in an inconsistent state where
initialization is considered complete although the firmware ready
handling did not finish successfully. During the subsequent SSR,
the driver enters the restart path based on this incorrect state
and dereferences uninitialized srng members, resulting in a NULL
pointer dereference.
Call trace:
ath11k_hal_srng_access_begin+0xc/0x60 [ath11k] (P)
ath11k_ce_cleanup_pipes+0x17c/0x180 [ath11k]
ath11k_core_restart+0x40/0x168 [ath11k]
Fix this by:
- skipping firmware_ready if ATH11K_FLAG_REGISTERED is already set
- setting ATH11K_FLAG_REGISTERED only when firmware_ready succeeds
- setting ATH11K_FLAG_QMI_FAIL and aborting the FW_READY handling
on error
Tested-on: WCN6750 hw1.0 AHB WLAN.MSL.2.0.c2-00204-QCAMSLSWPLZ-1
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 6fe62a8cec51c756159c71be35a16b2cc8cbd4c0 Version: 6fe62a8cec51c756159c71be35a16b2cc8cbd4c0 Version: 6fe62a8cec51c756159c71be35a16b2cc8cbd4c0 Version: 6fe62a8cec51c756159c71be35a16b2cc8cbd4c0 Version: 6fe62a8cec51c756159c71be35a16b2cc8cbd4c0 Version: 6fe62a8cec51c756159c71be35a16b2cc8cbd4c0 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/ath/ath11k/qmi.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "66bf998b18334ca97321433e4ab783b6ff267e9d",
"status": "affected",
"version": "6fe62a8cec51c756159c71be35a16b2cc8cbd4c0",
"versionType": "git"
},
{
"lessThan": "e517e207300edcf7f3a8f6c45f9155c0e419ffb9",
"status": "affected",
"version": "6fe62a8cec51c756159c71be35a16b2cc8cbd4c0",
"versionType": "git"
},
{
"lessThan": "d6bba659ac30d862ee7bab92862cd6e514f07521",
"status": "affected",
"version": "6fe62a8cec51c756159c71be35a16b2cc8cbd4c0",
"versionType": "git"
},
{
"lessThan": "e5394605f9a985cc3a8263e610ba84b33cbe7b0c",
"status": "affected",
"version": "6fe62a8cec51c756159c71be35a16b2cc8cbd4c0",
"versionType": "git"
},
{
"lessThan": "4abb4e284d8897176e91d7a3168ee29ed876bb41",
"status": "affected",
"version": "6fe62a8cec51c756159c71be35a16b2cc8cbd4c0",
"versionType": "git"
},
{
"lessThan": "e8d85672dd7e2523f774caafba8f858384e18df7",
"status": "affected",
"version": "6fe62a8cec51c756159c71be35a16b2cc8cbd4c0",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/ath/ath11k/qmi.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.1"
},
{
"lessThan": "6.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "6.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath11k: fix NULL pointer dereference in ath11k_hal_srng_access_begin\n\nIn ATH11K_QMI_EVENT_FW_READY, ATH11K_FLAG_REGISTERED is set\nunconditionally even when ath11k_core_qmi_firmware_ready() fails.\nThis leaves the driver in an inconsistent state where\ninitialization is considered complete although the firmware ready\nhandling did not finish successfully. During the subsequent SSR,\nthe driver enters the restart path based on this incorrect state\nand dereferences uninitialized srng members, resulting in a NULL\npointer dereference.\n\nCall trace:\n ath11k_hal_srng_access_begin+0xc/0x60 [ath11k] (P)\n ath11k_ce_cleanup_pipes+0x17c/0x180 [ath11k]\n ath11k_core_restart+0x40/0x168 [ath11k]\n\nFix this by:\n- skipping firmware_ready if ATH11K_FLAG_REGISTERED is already set\n- setting ATH11K_FLAG_REGISTERED only when firmware_ready succeeds\n- setting ATH11K_FLAG_QMI_FAIL and aborting the FW_READY handling\non error\n\nTested-on: WCN6750 hw1.0 AHB WLAN.MSL.2.0.c2-00204-QCAMSLSWPLZ-1"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:15.793Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/66bf998b18334ca97321433e4ab783b6ff267e9d"
},
{
"url": "https://git.kernel.org/stable/c/e517e207300edcf7f3a8f6c45f9155c0e419ffb9"
},
{
"url": "https://git.kernel.org/stable/c/d6bba659ac30d862ee7bab92862cd6e514f07521"
},
{
"url": "https://git.kernel.org/stable/c/e5394605f9a985cc3a8263e610ba84b33cbe7b0c"
},
{
"url": "https://git.kernel.org/stable/c/4abb4e284d8897176e91d7a3168ee29ed876bb41"
},
{
"url": "https://git.kernel.org/stable/c/e8d85672dd7e2523f774caafba8f858384e18df7"
}
],
"title": "wifi: ath11k: fix NULL pointer dereference in ath11k_hal_srng_access_begin",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68362",
"datePublished": "2026-08-10T12:03:39.363Z",
"dateReserved": "2026-07-30T09:28:09.385Z",
"dateUpdated": "2026-08-19T16:34:15.793Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74609 (GCVE-0-2026-74609)
Vulnerability from cvelistv5
Published
2026-08-22 15:31
Modified
2026-08-25 05:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
tipc: read le->link under the node lock in tipc_node_link_down()
tipc_node_link_down() caches the link pointer before taking n->lock:
struct tipc_link *l = le->link; /* unlocked */
if (!l)
return;
tipc_node_write_lock(n);
if (!tipc_link_is_establishing(l)) { /* deref l */
...
tipc_link_reset(l); /* write into l */
if (delete) {
kfree(l);
le->link = NULL;
The delete=true caller frees that very object under n->lock, so the lock
does not protect the cached pointer against it:
- CPU A, delete=false: tipc_rcv() on TIPC_LINK_DOWN_EVT, or the link
supervision timer via tipc_node_timeout(), reads l unlocked and then
dereferences it under n->lock;
- CPU B, delete=true: netlink TIPC_NL_BEARER_DISABLE -> bearer_disable()
-> tipc_node_delete_links() -> tipc_node_link_down(n, bearer_id, true)
-> kfree(l).
The link is freed with plain kfree(), not kfree_rcu(), and for UDP bearers
disable_media() only schedules the asynchronous cleanup_bearer() work, so
its synchronize_net() runs after the links are already gone. An in-flight
CPU A that has read l therefore dereferences freed memory once B frees it:
a use-after-free read in tipc_link_is_establishing(), and a use-after-free
write via tipc_link_reset() on the establishing branch.
The following trace was captured on 7.2.0-rc5-00284-gaf39eb111ce6:
BUG: KASAN: slab-use-after-free in tipc_link_is_establishing (net/tipc/link.c:285)
Read of size 4 at addr ffff88802e2aa068 by task swapper/2/0
tipc_link_is_establishing (net/tipc/link.c:285)
tipc_node_link_down (net/tipc/node.c:1076)
tipc_node_timeout (net/tipc/node.c:843)
Allocated by task 9549:
tipc_link_create (net/tipc/link.c:490)
tipc_node_check_dest (net/tipc/node.c:1279)
tipc_disc_rcv (net/tipc/discover.c:252)
tipc_udp_recv (net/tipc/udp_media.c:389)
Freed by task 9549:
tipc_node_link_down (net/tipc/node.c:1084)
tipc_node_delete_links (net/tipc/node.c:1320)
bearer_disable (net/tipc/bearer.c:414)
__tipc_nl_bearer_disable (net/tipc/bearer.c:992)
Move the le->link read inside tipc_node_write_lock(), so it is serialised
against the kfree() in the delete path. A racing teardown now either has
not run yet, and we see a valid link, or has already run, and we see NULL.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 73f646cec35477b5099d7e952297cb9e1855be45 Version: 73f646cec35477b5099d7e952297cb9e1855be45 Version: 73f646cec35477b5099d7e952297cb9e1855be45 Version: 73f646cec35477b5099d7e952297cb9e1855be45 Version: 73f646cec35477b5099d7e952297cb9e1855be45 Version: 73f646cec35477b5099d7e952297cb9e1855be45 Version: 73f646cec35477b5099d7e952297cb9e1855be45 Version: 73f646cec35477b5099d7e952297cb9e1855be45 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/tipc/node.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "2be741ad565c610871a6a95062c12c39da7168fd",
"status": "affected",
"version": "73f646cec35477b5099d7e952297cb9e1855be45",
"versionType": "git"
},
{
"lessThan": "69d209461c110388710e483a130caf051e4fd09a",
"status": "affected",
"version": "73f646cec35477b5099d7e952297cb9e1855be45",
"versionType": "git"
},
{
"lessThan": "de017c22135f545ca4e65d1eada22887b64958eb",
"status": "affected",
"version": "73f646cec35477b5099d7e952297cb9e1855be45",
"versionType": "git"
},
{
"lessThan": "47ba70891b10b2feb52462086b7fcd2ad75d3ce3",
"status": "affected",
"version": "73f646cec35477b5099d7e952297cb9e1855be45",
"versionType": "git"
},
{
"lessThan": "a714d62513befef37f71f4ae89bb1fe173b65f2e",
"status": "affected",
"version": "73f646cec35477b5099d7e952297cb9e1855be45",
"versionType": "git"
},
{
"lessThan": "c3f2347a47754eac690967cfd82cb6d559817b07",
"status": "affected",
"version": "73f646cec35477b5099d7e952297cb9e1855be45",
"versionType": "git"
},
{
"lessThan": "5558a8312452ddb21eff22b1cbd84302ad951944",
"status": "affected",
"version": "73f646cec35477b5099d7e952297cb9e1855be45",
"versionType": "git"
},
{
"lessThan": "cba9ccb47e9fa4cc77692fb896cc5ab57a667882",
"status": "affected",
"version": "73f646cec35477b5099d7e952297cb9e1855be45",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/tipc/node.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.4"
},
{
"lessThan": "4.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "4.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "4.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "4.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "4.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: read le-\u003elink under the node lock in tipc_node_link_down()\n\ntipc_node_link_down() caches the link pointer before taking n-\u003elock:\n\n\tstruct tipc_link *l = le-\u003elink;\t\t/* unlocked */\n\n\tif (!l)\n\t\treturn;\n\ttipc_node_write_lock(n);\n\tif (!tipc_link_is_establishing(l)) {\t/* deref l */\n\t...\n\t\ttipc_link_reset(l);\t\t/* write into l */\n\tif (delete) {\n\t\tkfree(l);\n\t\tle-\u003elink = NULL;\n\nThe delete=true caller frees that very object under n-\u003elock, so the lock\ndoes not protect the cached pointer against it:\n\n - CPU A, delete=false: tipc_rcv() on TIPC_LINK_DOWN_EVT, or the link\n supervision timer via tipc_node_timeout(), reads l unlocked and then\n dereferences it under n-\u003elock;\n - CPU B, delete=true: netlink TIPC_NL_BEARER_DISABLE -\u003e bearer_disable()\n -\u003e tipc_node_delete_links() -\u003e tipc_node_link_down(n, bearer_id, true)\n -\u003e kfree(l).\n\nThe link is freed with plain kfree(), not kfree_rcu(), and for UDP bearers\ndisable_media() only schedules the asynchronous cleanup_bearer() work, so\nits synchronize_net() runs after the links are already gone. An in-flight\nCPU A that has read l therefore dereferences freed memory once B frees it:\na use-after-free read in tipc_link_is_establishing(), and a use-after-free\nwrite via tipc_link_reset() on the establishing branch.\n\nThe following trace was captured on 7.2.0-rc5-00284-gaf39eb111ce6:\n\n BUG: KASAN: slab-use-after-free in tipc_link_is_establishing (net/tipc/link.c:285)\n Read of size 4 at addr ffff88802e2aa068 by task swapper/2/0\n tipc_link_is_establishing (net/tipc/link.c:285)\n tipc_node_link_down (net/tipc/node.c:1076)\n tipc_node_timeout (net/tipc/node.c:843)\n Allocated by task 9549:\n tipc_link_create (net/tipc/link.c:490)\n tipc_node_check_dest (net/tipc/node.c:1279)\n tipc_disc_rcv (net/tipc/discover.c:252)\n tipc_udp_recv (net/tipc/udp_media.c:389)\n Freed by task 9549:\n tipc_node_link_down (net/tipc/node.c:1084)\n tipc_node_delete_links (net/tipc/node.c:1320)\n bearer_disable (net/tipc/bearer.c:414)\n __tipc_nl_bearer_disable (net/tipc/bearer.c:992)\n\nMove the le-\u003elink read inside tipc_node_write_lock(), so it is serialised\nagainst the kfree() in the delete path. A racing teardown now either has\nnot run yet, and we see a valid link, or has already run, and we see NULL."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The UAF race requires the delete=true path (kfree) via TIPC_NL_BEARER_DISABLE/bearer_disable() or netns teardown, reachable only through local RTNL/genlink with CAP_NET_ADMIN; remote tipc_rcv() packets alone cannot free links and complete the race.\nAC:L - An attacker with CAP_NET_ADMIN controls both CPUs by scripting bearer disable/netns teardown while concurrently driving link-down events via TIPC traffic or link supervision timers; KASAN reproduced this reliably without uncontrollable victim timing.\nPR:L - Bearer disable and link deletion require CAP_NET_ADMIN (GENL_UNS_ADMIN_PERM on TIPC_NL_BEARER_DISABLE); tipc_genl_family is netns-aware, so unprivileged users obtain effective net-admin via user/network namespaces (unshare -Urn).\nUI:N - No victim interaction is required; the attacker scripts bearer teardown and concurrent TIPC link activity from their own processes without needing another user to mount, open files, or perform administrative actions.\nS:U - Slab UAF corrupts host kernel heap memory within the same kernel security authority; impact is kernel crash or local privilege escalation, not a VM, IOMMU, or cross-container sandbox boundary escape.\nC:H - Slab use-after-free read in tipc_link_is_establishing() dereferences freed tipc_link objects (KASAN-confirmed), enabling disclosure of freed kernel memory and supporting further heap exploitation primitives.\nI:H - On the establishing branch tipc_link_reset() performs multiple writes into the freed tipc_link structure, corrupting kernel heap metadata and adjacent objects in ways exploitable for arbitrary write and control-flow hijacking.\nA:H - KASAN-confirmed slab-use-after-free in tipc_node_link_down() causes kernel oops/panic (observed on swapper during tipc_node_timeout), and the race can be retriggered during bearer teardown loops for reliable denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:40:34.778Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/2be741ad565c610871a6a95062c12c39da7168fd"
},
{
"url": "https://git.kernel.org/stable/c/69d209461c110388710e483a130caf051e4fd09a"
},
{
"url": "https://git.kernel.org/stable/c/de017c22135f545ca4e65d1eada22887b64958eb"
},
{
"url": "https://git.kernel.org/stable/c/47ba70891b10b2feb52462086b7fcd2ad75d3ce3"
},
{
"url": "https://git.kernel.org/stable/c/a714d62513befef37f71f4ae89bb1fe173b65f2e"
},
{
"url": "https://git.kernel.org/stable/c/c3f2347a47754eac690967cfd82cb6d559817b07"
},
{
"url": "https://git.kernel.org/stable/c/5558a8312452ddb21eff22b1cbd84302ad951944"
},
{
"url": "https://git.kernel.org/stable/c/cba9ccb47e9fa4cc77692fb896cc5ab57a667882"
}
],
"title": "tipc: read le-\u003elink under the node lock in tipc_node_link_down()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74609",
"datePublished": "2026-08-22T15:31:56.054Z",
"dateReserved": "2026-08-15T05:44:03.920Z",
"dateUpdated": "2026-08-25T05:40:34.778Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80541 (GCVE-0-2026-80541)
Vulnerability from cvelistv5
Published
2026-08-26 14:37
Modified
2026-08-27 05:01
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: validate GEM_CREATE domain combinations
AMDGPU_GEM_CREATE checked domain bits against AMDGPU_GEM_DOMAIN_MASK,
but did not validate domain combinations. Userspace could combine
CPU|GTT|VRAM with DOORBELL, GDS, GWS, or OA, making
amdgpu_bo_placement_from_domain() exceed AMDGPU_BO_MAX_PLACEMENTS and
hit BUG_ON().
Allow combinations only within CPU/GTT/VRAM, and require non-CPU/GTT/
VRAM domains to be specified one at a time. Return -EINVAL for invalid
combinations in amdgpu_gem_create_ioctl().
v2: Rename helper from amdgpu_gem_domain_valid() to
amdgpu_gem_are_domains_valid() (Christian)
(cherry picked from commit db39852d0c39843cb02048dfb47e4b8c703e9080)
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 77a2faa55c1a497f4e7e89eabd11830f0e3cb3dd Version: 77a2faa55c1a497f4e7e89eabd11830f0e3cb3dd Version: 77a2faa55c1a497f4e7e89eabd11830f0e3cb3dd Version: 77a2faa55c1a497f4e7e89eabd11830f0e3cb3dd Version: 77a2faa55c1a497f4e7e89eabd11830f0e3cb3dd Version: 77a2faa55c1a497f4e7e89eabd11830f0e3cb3dd Version: 77a2faa55c1a497f4e7e89eabd11830f0e3cb3dd Version: 77a2faa55c1a497f4e7e89eabd11830f0e3cb3dd |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/amdgpu_gem.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "5c73485af7ad9c3ae592db3481f370bc07705391",
"status": "affected",
"version": "77a2faa55c1a497f4e7e89eabd11830f0e3cb3dd",
"versionType": "git"
},
{
"lessThan": "584e3d47736fe2e7184ef3fc16b00b41485f96c6",
"status": "affected",
"version": "77a2faa55c1a497f4e7e89eabd11830f0e3cb3dd",
"versionType": "git"
},
{
"lessThan": "66133fc05c3af002f45de8a71b833c026ccbfba6",
"status": "affected",
"version": "77a2faa55c1a497f4e7e89eabd11830f0e3cb3dd",
"versionType": "git"
},
{
"lessThan": "ce5da474c3ddf7cccec5dce6aa4296297dd7caff",
"status": "affected",
"version": "77a2faa55c1a497f4e7e89eabd11830f0e3cb3dd",
"versionType": "git"
},
{
"lessThan": "493355096e397f9217b41c8574ed2784c7351443",
"status": "affected",
"version": "77a2faa55c1a497f4e7e89eabd11830f0e3cb3dd",
"versionType": "git"
},
{
"lessThan": "220aa2589d7321fb68d2e8597862711b5f22ae0b",
"status": "affected",
"version": "77a2faa55c1a497f4e7e89eabd11830f0e3cb3dd",
"versionType": "git"
},
{
"lessThan": "80f0b53860d02577709d69a312a29ca674b9297c",
"status": "affected",
"version": "77a2faa55c1a497f4e7e89eabd11830f0e3cb3dd",
"versionType": "git"
},
{
"lessThan": "5e9d136ad74df4edec67e502ce267597064d8f86",
"status": "affected",
"version": "77a2faa55c1a497f4e7e89eabd11830f0e3cb3dd",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/amdgpu_gem.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.20"
},
{
"lessThan": "4.20",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.46",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.10",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.20",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: validate GEM_CREATE domain combinations\n\nAMDGPU_GEM_CREATE checked domain bits against AMDGPU_GEM_DOMAIN_MASK,\nbut did not validate domain combinations. Userspace could combine\nCPU|GTT|VRAM with DOORBELL, GDS, GWS, or OA, making\namdgpu_bo_placement_from_domain() exceed AMDGPU_BO_MAX_PLACEMENTS and\nhit BUG_ON().\n\nAllow combinations only within CPU/GTT/VRAM, and require non-CPU/GTT/\nVRAM domains to be specified one at a time. Return -EINVAL for invalid\ncombinations in amdgpu_gem_create_ioctl().\n\nv2: Rename helper from amdgpu_gem_domain_valid() to\n amdgpu_gem_are_domains_valid() (Christian)\n\n(cherry picked from commit db39852d0c39843cb02048dfb47e4b8c703e9080)"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached only via DRM_IOCTL_AMDGPU_GEM_CREATE on a local amdgpu render node (/dev/dri/renderD*); userspace passes crafted domain flags into amdgpu_gem_create_ioctl(), which calls amdgpu_bo_placement_from_domain() during amdgpu_bo_create(). There is no network, adjacent-radio, or physical-access path to this code.\nAC:L - Triggering is a single deterministic ioctl with an invalid domain bitmask (e.g. CPU|GTT|VRAM|DOORBELL); the attacker fully controls the domains field and needs no race, special memory layout, or victim state. Invalid combinations reliably exceed AMDGPU_BO_MAX_PLACEMENTS (3) and hit BUG_ON() on every attempt.\nPR:L - AMDGPU_GEM_CREATE is registered with DRM_AUTH|DRM_RENDER_ALLOW, so any local unprivileged user who can open the render node (default on desktops, ChromeOS, Steam Deck, and cloud GPU tenants via render/video group or ACL) can invoke it without real root or init-namespace capabilities.\nUI:N - The attacking process performs the GEM_CREATE ioctl itself; no other user must mount a filesystem, open a file, click a link, or take any other action for the invalid domain combination to reach amdgpu_bo_placement_from_domain() and panic the kernel.\nS:U - Impact is confined to host-kernel memory corruption and panic within the amdgpu/TTM driver; it does not cross a VM, IOMMU, or sandbox security boundary, and is standard local kernel privilege-escalation/DoS scope rather than a guest-to-host escape.\nC:H - Before BUG_ON(), amdgpu_bo_placement_from_domain() writes past the fixed placements[AMDGPU_BO_MAX_PLACEMENTS] array into adjacent amdgpu_bo fields (including struct ttm_placement) with attacker-influenced mem_type and flag values; this out-of-bounds write is memory corruption that could be leveraged for kernel info disclosure.\nI:H - The same out-of-bounds placement writes corrupt adjacent kernel heap objects in the amdgpu_bo allocation with partially attacker-controlled ttm_place contents; out-of-bounds writes into kernel structures are classed as high integrity impact and could enable further heap corruption or control-flow hijacking.\nA:H - Once placement count exceeds three the kernel hits BUG_ON(c \u003e AMDGPU_BO_MAX_PLACEMENTS), causing an oops or panic; an unprivileged GPU client on shared AMD hardware (multi-user workstations or cloud GPU nodes) can repeatedly crash the entire host, denying service to all co-tenants."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T05:01:30.566Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/5c73485af7ad9c3ae592db3481f370bc07705391"
},
{
"url": "https://git.kernel.org/stable/c/584e3d47736fe2e7184ef3fc16b00b41485f96c6"
},
{
"url": "https://git.kernel.org/stable/c/66133fc05c3af002f45de8a71b833c026ccbfba6"
},
{
"url": "https://git.kernel.org/stable/c/ce5da474c3ddf7cccec5dce6aa4296297dd7caff"
},
{
"url": "https://git.kernel.org/stable/c/493355096e397f9217b41c8574ed2784c7351443"
},
{
"url": "https://git.kernel.org/stable/c/220aa2589d7321fb68d2e8597862711b5f22ae0b"
},
{
"url": "https://git.kernel.org/stable/c/80f0b53860d02577709d69a312a29ca674b9297c"
},
{
"url": "https://git.kernel.org/stable/c/5e9d136ad74df4edec67e502ce267597064d8f86"
}
],
"title": "drm/amdgpu: validate GEM_CREATE domain combinations",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80541",
"datePublished": "2026-08-26T14:37:14.572Z",
"dateReserved": "2026-08-26T14:34:25.765Z",
"dateUpdated": "2026-08-27T05:01:30.566Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-46111 (GCVE-0-2026-46111)
Vulnerability from cvelistv5
Published
2026-05-28 09:35
Modified
2026-08-19 16:28
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci_conn: fix potential UAF in create_big_sync
Add hci_conn_valid() check in create_big_sync() to detect stale
connections before proceeding with BIG creation. Handle the
resulting -ECANCELED in create_big_complete() and re-validate the
connection under hci_dev_lock() before dereferencing, matching the
pattern used by create_le_conn_complete() and create_pa_complete().
Keep the hci_conn object alive across the async boundary by taking
a reference via hci_conn_get() when queueing create_big_sync(), and
dropping it in the completion callback. The refcount and the lock
are complementary: the refcount keeps the object allocated, while
hci_dev_lock() serializes hci_conn_hash_del()'s list_del_rcu() on
hdev->conn_hash, as required by hci_conn_del().
hci_conn_put() is called outside hci_dev_unlock() so the final put
(which resolves to kfree() via bt_link_release) does not run under
hdev->lock, though the release path would be safe either way.
Without this, create_big_complete() would unconditionally
dereference the conn pointer on error, causing a use-after-free
via hci_connect_cfm() and hci_conn_del().
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: eca0ae4aea66914515e5e3098ea051b518ee5316 Version: eca0ae4aea66914515e5e3098ea051b518ee5316 Version: eca0ae4aea66914515e5e3098ea051b518ee5316 Version: eca0ae4aea66914515e5e3098ea051b518ee5316 Version: eca0ae4aea66914515e5e3098ea051b518ee5316 Version: eca0ae4aea66914515e5e3098ea051b518ee5316 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/bluetooth/hci_conn.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "d41093723e47255d7d74df86e2736711c1b8486e",
"status": "affected",
"version": "eca0ae4aea66914515e5e3098ea051b518ee5316",
"versionType": "git"
},
{
"lessThan": "6823f730bf195fc296d9edd09e2ca94bc1ff5584",
"status": "affected",
"version": "eca0ae4aea66914515e5e3098ea051b518ee5316",
"versionType": "git"
},
{
"lessThan": "1750a2df0eab61dc421a7afae74abdd239a44b85",
"status": "affected",
"version": "eca0ae4aea66914515e5e3098ea051b518ee5316",
"versionType": "git"
},
{
"lessThan": "dc34f8d8240f25dd137dc2758ebbcc75e3779142",
"status": "affected",
"version": "eca0ae4aea66914515e5e3098ea051b518ee5316",
"versionType": "git"
},
{
"lessThan": "f8eaf92c57ad99358dd372580d5ff87623343a72",
"status": "affected",
"version": "eca0ae4aea66914515e5e3098ea051b518ee5316",
"versionType": "git"
},
{
"lessThan": "0beddb0c380bed5f5b8e61ddbe14635bb73d0b41",
"status": "affected",
"version": "eca0ae4aea66914515e5e3098ea051b518ee5316",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/bluetooth/hci_conn.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.0"
},
{
"lessThan": "6.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.140",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.90",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.32",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.7",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.140",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.90",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.32",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.7",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "6.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_conn: fix potential UAF in create_big_sync\n\nAdd hci_conn_valid() check in create_big_sync() to detect stale\nconnections before proceeding with BIG creation. Handle the\nresulting -ECANCELED in create_big_complete() and re-validate the\nconnection under hci_dev_lock() before dereferencing, matching the\npattern used by create_le_conn_complete() and create_pa_complete().\n\nKeep the hci_conn object alive across the async boundary by taking\na reference via hci_conn_get() when queueing create_big_sync(), and\ndropping it in the completion callback. The refcount and the lock\nare complementary: the refcount keeps the object allocated, while\nhci_dev_lock() serializes hci_conn_hash_del()\u0027s list_del_rcu() on\nhdev-\u003econn_hash, as required by hci_conn_del().\n\nhci_conn_put() is called outside hci_dev_unlock() so the final put\n(which resolves to kfree() via bt_link_release) does not run under\nhdev-\u003elock, though the release path would be safe either way.\n\nWithout this, create_big_complete() would unconditionally\ndereference the conn pointer on error, causing a use-after-free\nvia hci_connect_cfm() and hci_conn_del()."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The UAF is reached only through a local ISO socket connect() syscall (BTPROTO_ISO \u2192 iso_connect_bis \u2192 hci_connect_bis); BIG broadcast setup is locally initiated and requires no Bluetooth peer or over-the-air frame, so the attacker needs local system access.\nAC:L - This is a use-after-free where the attacker controls both sides of the race \u2014 initiating the async create_big work via connect() and freeing the conn (e.g., closing the socket) \u2014 and can retry at will, so the condition is within attacker control.\nPR:L - Creating and connecting an ISO socket requires no capability check (iso_sock_create/bt_sock_create perform none), so any unprivileged local user can reach the path on systems where the ISO/BIS feature is enabled.\nUI:N - The attacker performs all steps (open socket, connect, race a teardown); no victim interaction is required.\nS:U - The use-after-free is contained within the kernel\u0027s own memory/security authority and does not cross into another security boundary such as a VM or IOMMU domain.\nC:H - A UAF of the hci_conn object gives the attacker control over the freed object\u0027s contents, enabling kernel-memory disclosure (e.g., leaking pointers/data placed in the reclaimed allocation).\nI:H - The freed hci_conn is dereferenced and written via hci_connect_cfm() and hci_conn_del() (including list_del_rcu on conn_hash), so heap grooming of the freed slab yields an arbitrary-write/control-flow primitive.\nA:H - Dereferencing and deleting a freed hci_conn reliably causes memory corruption leading to a kernel oops/panic."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:28:01.615Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/d41093723e47255d7d74df86e2736711c1b8486e"
},
{
"url": "https://git.kernel.org/stable/c/6823f730bf195fc296d9edd09e2ca94bc1ff5584"
},
{
"url": "https://git.kernel.org/stable/c/1750a2df0eab61dc421a7afae74abdd239a44b85"
},
{
"url": "https://git.kernel.org/stable/c/dc34f8d8240f25dd137dc2758ebbcc75e3779142"
},
{
"url": "https://git.kernel.org/stable/c/f8eaf92c57ad99358dd372580d5ff87623343a72"
},
{
"url": "https://git.kernel.org/stable/c/0beddb0c380bed5f5b8e61ddbe14635bb73d0b41"
}
],
"title": "Bluetooth: hci_conn: fix potential UAF in create_big_sync",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-46111",
"datePublished": "2026-05-28T09:35:19.970Z",
"dateReserved": "2026-05-13T15:03:33.098Z",
"dateUpdated": "2026-08-19T16:28:01.615Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68324 (GCVE-0-2026-68324)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
iommu/intel: Fix out-of-bounds memset in dmar_latency_disable()
dmar_latency_disable() intends to zero out only the single
latency_statistic entry for the given type, but the memset size was
computed as sizeof(*lstat) * DMAR_LATENCY_NUM, which clears the entire
array starting from &lstat[type].
When type > 0, this writes beyond the end of the allocated array,
corrupting adjacent memory.
Fix by using sizeof(*lstat) to clear only the target entry.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 55ee5e67a59a1b6f388d7a1c7b24022145f47a3e Version: 55ee5e67a59a1b6f388d7a1c7b24022145f47a3e Version: 55ee5e67a59a1b6f388d7a1c7b24022145f47a3e Version: 55ee5e67a59a1b6f388d7a1c7b24022145f47a3e Version: 55ee5e67a59a1b6f388d7a1c7b24022145f47a3e Version: 55ee5e67a59a1b6f388d7a1c7b24022145f47a3e Version: 55ee5e67a59a1b6f388d7a1c7b24022145f47a3e |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/iommu/intel/perf.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "80f3605991461679c298ea2045c350ee3cf36de3",
"status": "affected",
"version": "55ee5e67a59a1b6f388d7a1c7b24022145f47a3e",
"versionType": "git"
},
{
"lessThan": "104d89cf5b01cb66ff975d91ed42f61b3904df53",
"status": "affected",
"version": "55ee5e67a59a1b6f388d7a1c7b24022145f47a3e",
"versionType": "git"
},
{
"lessThan": "3078d82e7fe9048a2b90a992e71af7cd7ef881fa",
"status": "affected",
"version": "55ee5e67a59a1b6f388d7a1c7b24022145f47a3e",
"versionType": "git"
},
{
"lessThan": "866a35735e56b9dc81cbc33899255134adf6d8b3",
"status": "affected",
"version": "55ee5e67a59a1b6f388d7a1c7b24022145f47a3e",
"versionType": "git"
},
{
"lessThan": "d06fea9b85f038690f55e72fe0c45e113715a85a",
"status": "affected",
"version": "55ee5e67a59a1b6f388d7a1c7b24022145f47a3e",
"versionType": "git"
},
{
"lessThan": "0e28ca1c3204b51068579defc904a0dfba5e5c57",
"status": "affected",
"version": "55ee5e67a59a1b6f388d7a1c7b24022145f47a3e",
"versionType": "git"
},
{
"lessThan": "754f8efe45f87e3a9c6871b645b2f9d46d1b407b",
"status": "affected",
"version": "55ee5e67a59a1b6f388d7a1c7b24022145f47a3e",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/iommu/intel/perf.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.14"
},
{
"lessThan": "5.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\niommu/intel: Fix out-of-bounds memset in dmar_latency_disable()\n\ndmar_latency_disable() intends to zero out only the single\nlatency_statistic entry for the given type, but the memset size was\ncomputed as sizeof(*lstat) * DMAR_LATENCY_NUM, which clears the entire\narray starting from \u0026lstat[type].\n\nWhen type \u003e 0, this writes beyond the end of the allocated array,\ncorrupting adjacent memory.\n\nFix by using sizeof(*lstat) to clear only the target entry."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:15.575Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/80f3605991461679c298ea2045c350ee3cf36de3"
},
{
"url": "https://git.kernel.org/stable/c/104d89cf5b01cb66ff975d91ed42f61b3904df53"
},
{
"url": "https://git.kernel.org/stable/c/3078d82e7fe9048a2b90a992e71af7cd7ef881fa"
},
{
"url": "https://git.kernel.org/stable/c/866a35735e56b9dc81cbc33899255134adf6d8b3"
},
{
"url": "https://git.kernel.org/stable/c/d06fea9b85f038690f55e72fe0c45e113715a85a"
},
{
"url": "https://git.kernel.org/stable/c/0e28ca1c3204b51068579defc904a0dfba5e5c57"
},
{
"url": "https://git.kernel.org/stable/c/754f8efe45f87e3a9c6871b645b2f9d46d1b407b"
}
],
"title": "iommu/intel: Fix out-of-bounds memset in dmar_latency_disable()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68324",
"datePublished": "2026-08-10T12:03:00.073Z",
"dateReserved": "2026-07-30T09:28:09.382Z",
"dateUpdated": "2026-08-19T16:33:15.575Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74696 (GCVE-0-2026-74696)
Vulnerability from cvelistv5
Published
2026-08-22 15:32
Modified
2026-08-25 05:41
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
tcp: fix TFO max_qlen accounting across reuseport migration
A listener's TCP_FASTOPEN max_qlen stops being accurate and lets through
far more pending Fast Open requests than it was configured for.
This only shows up with SO_REUSEPORT listener migration, where closing a
listener hands its still-pending TFO children over to a surviving one.
fastopenq.qlen is charged in tcp_fastopen_create_child() when the child
is created and uncharged in reqsk_fastopen_remove() when the handshake
completes. The uncharge follows rsk_listener of the request the child
points at, and inet_reqsk_clone() has repointed the child at a new
request owned by the new listener, so the ++ and the -- land on two
different sockets. The new listener's qlen drifts negative and its
limit no longer binds.
Charge the new listener during migration, like reqsk_queue_migrated()
already does for queue->young and queue->qlen.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 54b92e84193749c9968aff2dd46e3b0f42643e18 Version: 54b92e84193749c9968aff2dd46e3b0f42643e18 Version: 54b92e84193749c9968aff2dd46e3b0f42643e18 Version: 54b92e84193749c9968aff2dd46e3b0f42643e18 Version: 54b92e84193749c9968aff2dd46e3b0f42643e18 Version: 54b92e84193749c9968aff2dd46e3b0f42643e18 Version: 54b92e84193749c9968aff2dd46e3b0f42643e18 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ipv4/inet_connection_sock.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "e98f0d80b9cccb5f828425d2004f9686e7d1ae24",
"status": "affected",
"version": "54b92e84193749c9968aff2dd46e3b0f42643e18",
"versionType": "git"
},
{
"lessThan": "b6247e0f96bd825ffb2005257f6177b5e642dee6",
"status": "affected",
"version": "54b92e84193749c9968aff2dd46e3b0f42643e18",
"versionType": "git"
},
{
"lessThan": "585fc5247d14939a561056aa2addd9b7c2b1f670",
"status": "affected",
"version": "54b92e84193749c9968aff2dd46e3b0f42643e18",
"versionType": "git"
},
{
"lessThan": "6e10ee56524a26b250229ad348637825646ddb88",
"status": "affected",
"version": "54b92e84193749c9968aff2dd46e3b0f42643e18",
"versionType": "git"
},
{
"lessThan": "a66e869cf0c90c1e47ae75f72b6482acbfc808ff",
"status": "affected",
"version": "54b92e84193749c9968aff2dd46e3b0f42643e18",
"versionType": "git"
},
{
"lessThan": "d974618b2097453778389d385e3741629c40e0a3",
"status": "affected",
"version": "54b92e84193749c9968aff2dd46e3b0f42643e18",
"versionType": "git"
},
{
"lessThan": "a0ab2ba83e35159d81cec830a92e885ecf8139be",
"status": "affected",
"version": "54b92e84193749c9968aff2dd46e3b0f42643e18",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ipv4/inet_connection_sock.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.14"
},
{
"lessThan": "5.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: fix TFO max_qlen accounting across reuseport migration\n\nA listener\u0027s TCP_FASTOPEN max_qlen stops being accurate and lets through\nfar more pending Fast Open requests than it was configured for.\n\nThis only shows up with SO_REUSEPORT listener migration, where closing a\nlistener hands its still-pending TFO children over to a surviving one.\n\nfastopenq.qlen is charged in tcp_fastopen_create_child() when the child\nis created and uncharged in reqsk_fastopen_remove() when the handshake\ncompletes. The uncharge follows rsk_listener of the request the child\npoints at, and inet_reqsk_clone() has repointed the child at a new\nrequest owned by the new listener, so the ++ and the -- land on two\ndifferent sockets. The new listener\u0027s qlen drifts negative and its\nlimit no longer binds.\n\nCharge the new listener during migration, like reqsk_queue_migrated()\nalready does for queue-\u003eyoung and queue-\u003eqlen."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug is in the inbound TCP SYN/TFO server path (tcp_v4_rcv/tcp_conn_request/tcp_try_fastopen), reachable by sending TCP Fast Open SYN packets to any internet-facing listener with server-side TFO enabled.\nAC:L - An attacker fully controls the TFO SYN flood; once a SO_REUSEPORT worker closes while TFO children are pending (routine nginx/k8s reloads), migration deterministically skews qlen negative with no narrow race or special memory layout required.\nPR:N - Exploitation needs only unauthenticated network reachability to the listening TCP port; no target credentials, capabilities, or local access are required because TFO SYN processing occurs before any application authentication.\nUI:N - No victim user action is needed beyond normal server operation; the remote attacker sends crafted TFO SYN traffic and benefits automatically when reuseport listener migration occurs during ordinary worker shutdown or reload.\nS:U - Impact is confined to the target host kernel TCP stack resource limits and availability; it does not cross VM, container, or IOMMU security boundaries to affect a different authority.\nC:N - The flaw is a signed counter accounting mismatch on fastopenq.qlen; it does not corrupt memory, leak kernel pointers, or provide an out-of-bounds read or use-after-free disclosure primitive.\nI:N - No arbitrary memory write, control-flow hijack, or unauthorized persistent data modification occurs; bypassing max_qlen only relaxes a rate limit while TFO cookie validation and normal TCP semantics still govern accepted data.\nA:H - With max_qlen disabled, a remote attacker can create far more pending TFO child sockets and SYN-carrying skbs than configured, exhausting kernel memory and socket tables and causing severe denial of service or OOM-induced host instability."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:41:40.079Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/e98f0d80b9cccb5f828425d2004f9686e7d1ae24"
},
{
"url": "https://git.kernel.org/stable/c/b6247e0f96bd825ffb2005257f6177b5e642dee6"
},
{
"url": "https://git.kernel.org/stable/c/585fc5247d14939a561056aa2addd9b7c2b1f670"
},
{
"url": "https://git.kernel.org/stable/c/6e10ee56524a26b250229ad348637825646ddb88"
},
{
"url": "https://git.kernel.org/stable/c/a66e869cf0c90c1e47ae75f72b6482acbfc808ff"
},
{
"url": "https://git.kernel.org/stable/c/d974618b2097453778389d385e3741629c40e0a3"
},
{
"url": "https://git.kernel.org/stable/c/a0ab2ba83e35159d81cec830a92e885ecf8139be"
}
],
"title": "tcp: fix TFO max_qlen accounting across reuseport migration",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74696",
"datePublished": "2026-08-22T15:32:58.414Z",
"dateReserved": "2026-08-15T05:44:03.926Z",
"dateUpdated": "2026-08-25T05:41:40.079Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74518 (GCVE-0-2026-74518)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-19 16:38
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
mm/hugetlb: fix list corruption in allocate_file_region_entries()
allocate_file_region_entries() tops up resv->region_cache with freshly
allocated file_region descriptors. The allocation uses GFP_KERNEL, so
resv->lock is dropped around it: the new entries are gathered on a
stack-local list head, allocated_regions, and spliced into
resv->region_cache once the lock is re-acquired.
The splice used list_splice(), which moves the entries but does not
re-initialize the source head, so allocated_regions is left pointing at an
entry that now lives on resv->region_cache. The top-up runs in a while
loop that re-checks the cache deficit after re-acquiring the lock. For a
shared mapping the resv_map is shared by every mapper of the hugetlbfs
inode, so a concurrent region_chg()/region_add()/region_del() on the same
resv_map can consume cache entries during the unlocked window and force a
second iteration. That iteration calls list_add() on the stale head and
corrupts the list; with CONFIG_DEBUG_LIST the __list_add_valid() check
trips:
list_add corruption. next->prev should be prev (ffffc900011ff7f8),
but was ffff88814c281460. (next=ffff88814c545640).
kernel BUG at lib/list_debug.c:31!
allocate_file_region_entries+0x191/0x420
region_chg+0x267/0x300
hugetlb_reserve_pages+0x387/0xc80
hugetlbfs_file_mmap+0x2ce/0x3f0
mmap_region+0x1348/0x1a80
do_mmap+0x85e/0xb90
vm_mmap_pgoff+0x18c/0x330
ksys_mmap_pgoff+0x2a1/0x3e0
do_syscall_64+0xd7/0x420
Without CONFIG_DEBUG_LIST the bad list_add() silently links a kernel-stack
address into resv->region_cache, leading to later use-after-free.
This was observed as a real host panic on a dense KVM host where a QEMU
guest-RAM hugetlbfs file was mapped MAP_SHARED by both QEMU and a separate
SPDK/DPDK vhost-user target, generating concurrent region_* traffic on one
shared resv_map.
Use list_splice_init() so the source head is re-initialized empty after
each splice, making the retry loop safe.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d3ec7b6e09e512ba902b86bcca2c512fb06d492f Version: d3ec7b6e09e512ba902b86bcca2c512fb06d492f Version: d3ec7b6e09e512ba902b86bcca2c512fb06d492f Version: d3ec7b6e09e512ba902b86bcca2c512fb06d492f Version: d3ec7b6e09e512ba902b86bcca2c512fb06d492f Version: d3ec7b6e09e512ba902b86bcca2c512fb06d492f Version: d3ec7b6e09e512ba902b86bcca2c512fb06d492f Version: d3ec7b6e09e512ba902b86bcca2c512fb06d492f |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"mm/hugetlb.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "01b8569233e47693d6ff7efa96d9854c55f936fc",
"status": "affected",
"version": "d3ec7b6e09e512ba902b86bcca2c512fb06d492f",
"versionType": "git"
},
{
"lessThan": "9c5fdffc5e1ce84403c58289ee72697051803bf7",
"status": "affected",
"version": "d3ec7b6e09e512ba902b86bcca2c512fb06d492f",
"versionType": "git"
},
{
"lessThan": "f3e54f6a5e1681f83d13e8716bc92ef5ecf121d3",
"status": "affected",
"version": "d3ec7b6e09e512ba902b86bcca2c512fb06d492f",
"versionType": "git"
},
{
"lessThan": "62e1c2741a4d923d9854efd5927a6212aad7a187",
"status": "affected",
"version": "d3ec7b6e09e512ba902b86bcca2c512fb06d492f",
"versionType": "git"
},
{
"lessThan": "587a0accc2b4fccc5cf7baf0fe34e50efde51f9c",
"status": "affected",
"version": "d3ec7b6e09e512ba902b86bcca2c512fb06d492f",
"versionType": "git"
},
{
"lessThan": "126a70bf1a08ddc9d79c471ebdaa2b08cfbab8df",
"status": "affected",
"version": "d3ec7b6e09e512ba902b86bcca2c512fb06d492f",
"versionType": "git"
},
{
"lessThan": "ac1bb7fd45088d0db57a22ce7729f258ebd63cf5",
"status": "affected",
"version": "d3ec7b6e09e512ba902b86bcca2c512fb06d492f",
"versionType": "git"
},
{
"lessThan": "dd9623f58ec702a07b2d67179d6fcea79c52231a",
"status": "affected",
"version": "d3ec7b6e09e512ba902b86bcca2c512fb06d492f",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"mm/hugetlb.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.10"
},
{
"lessThan": "5.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/hugetlb: fix list corruption in allocate_file_region_entries()\n\nallocate_file_region_entries() tops up resv-\u003eregion_cache with freshly\nallocated file_region descriptors. The allocation uses GFP_KERNEL, so\nresv-\u003elock is dropped around it: the new entries are gathered on a\nstack-local list head, allocated_regions, and spliced into\nresv-\u003eregion_cache once the lock is re-acquired.\n\nThe splice used list_splice(), which moves the entries but does not\nre-initialize the source head, so allocated_regions is left pointing at an\nentry that now lives on resv-\u003eregion_cache. The top-up runs in a while\nloop that re-checks the cache deficit after re-acquiring the lock. For a\nshared mapping the resv_map is shared by every mapper of the hugetlbfs\ninode, so a concurrent region_chg()/region_add()/region_del() on the same\nresv_map can consume cache entries during the unlocked window and force a\nsecond iteration. That iteration calls list_add() on the stale head and\ncorrupts the list; with CONFIG_DEBUG_LIST the __list_add_valid() check\ntrips:\n\n list_add corruption. next-\u003eprev should be prev (ffffc900011ff7f8),\n but was ffff88814c281460. (next=ffff88814c545640).\n kernel BUG at lib/list_debug.c:31!\n allocate_file_region_entries+0x191/0x420\n region_chg+0x267/0x300\n hugetlb_reserve_pages+0x387/0xc80\n hugetlbfs_file_mmap+0x2ce/0x3f0\n mmap_region+0x1348/0x1a80\n do_mmap+0x85e/0xb90\n vm_mmap_pgoff+0x18c/0x330\n ksys_mmap_pgoff+0x2a1/0x3e0\n do_syscall_64+0xd7/0x420\n\nWithout CONFIG_DEBUG_LIST the bad list_add() silently links a kernel-stack\naddress into resv-\u003eregion_cache, leading to later use-after-free.\n\nThis was observed as a real host panic on a dense KVM host where a QEMU\nguest-RAM hugetlbfs file was mapped MAP_SHARED by both QEMU and a separate\nSPDK/DPDK vhost-user target, generating concurrent region_* traffic on one\nshared resv_map.\n\nUse list_splice_init() so the source head is re-initialized empty after\neach splice, making the retry loop safe."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached only through local hugetlb reservation paths (mmap/memfd_create/fault syscalls into region_chg/region_add/region_del); no network protocol or remote packet handler invokes allocate_file_region_entries().\nAC:L - Exploitation needs a race while resv-\u003elock is dropped during GFP_KERNEL allocation, but an attacker can spawn concurrent MAP_SHARED mappers/faulters on one hugetlb inode and controls both sides of that race.\nPR:L - Unprivileged local users can trigger this via memfd_create(MFD_HUGETLB) plus MAP_SHARED mmap/fault activity, or by mapping accessible shared hugetlbfs files, without init-namespace root or special capabilities.\nUI:N - No victim interaction is required; the attacker drives the needed concurrent syscalls and shared hugetlb mappings themselves to hit the corrupted list splice retry path.\nS:U - Impact is kernel hugetlb resv_map list/memory corruption on the host; it does not by itself cross a VM, IOMMU, or separate security-authority boundary even though KVM/DPDK hosts are a prime deployment.\nC:H - Without CONFIG_DEBUG_LIST, stale list_splice leaves a kernel-stack pointer in resv-\u003eregion_cache, producing later use-after-free that can be turned into arbitrary kernel memory read/disclosure primitives.\nI:H - Corrupted region_cache pointers let subsequent region_add/region_del/cache operations write through attacker-influenced list links, enabling heap metadata corruption and potential arbitrary kernel write or code execution.\nA:H - Real host panics were reported on dense KVM hugetlb workloads; DEBUG_LIST kernels BUG on list_add corruption, and default builds can crash from UAF while walking the poisoned region_cache."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:38:19.402Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/01b8569233e47693d6ff7efa96d9854c55f936fc"
},
{
"url": "https://git.kernel.org/stable/c/9c5fdffc5e1ce84403c58289ee72697051803bf7"
},
{
"url": "https://git.kernel.org/stable/c/f3e54f6a5e1681f83d13e8716bc92ef5ecf121d3"
},
{
"url": "https://git.kernel.org/stable/c/62e1c2741a4d923d9854efd5927a6212aad7a187"
},
{
"url": "https://git.kernel.org/stable/c/587a0accc2b4fccc5cf7baf0fe34e50efde51f9c"
},
{
"url": "https://git.kernel.org/stable/c/126a70bf1a08ddc9d79c471ebdaa2b08cfbab8df"
},
{
"url": "https://git.kernel.org/stable/c/ac1bb7fd45088d0db57a22ce7729f258ebd63cf5"
},
{
"url": "https://git.kernel.org/stable/c/dd9623f58ec702a07b2d67179d6fcea79c52231a"
}
],
"title": "mm/hugetlb: fix list corruption in allocate_file_region_entries()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74518",
"datePublished": "2026-08-15T12:27:37.480Z",
"dateReserved": "2026-08-15T05:44:03.910Z",
"dateUpdated": "2026-08-19T16:38:19.402Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80891 (GCVE-0-2026-80891)
Vulnerability from cvelistv5
Published
2026-09-04 17:11
Modified
2026-09-04 17:11
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
KVM: s390: pci: Validate AIBV and AISB before pinning guest pages
The AIBV holds one bit per MSI-X vector for a given function. The size of
the bit vector is derived from the NOI and the AIBVO. If the size of the
AIBV exceeds a single page boundary, then reject the request as we cannot
safely pin the guest AIBV.
Similarly reject the request if the AISB address is not 8-byte aligned as
the architecture requires doubleword alignment for the summary bit address.
Since the AISBO can address up to 64 bits, the size of the AISB can only be
8 bytes for the function. This also ensures the AISB doesn't exceed a
single page boundary.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc Version: 3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc Version: 3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc Version: 3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc Version: 3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc Version: 3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"arch/s390/kvm/pci.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "3a1c64220ede4ac9ef9a3e76f008ff60a34f4c48",
"status": "affected",
"version": "3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc",
"versionType": "git"
},
{
"lessThan": "f00ef8efd41440129ccd88f4a1ebebf8d61d297f",
"status": "affected",
"version": "3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc",
"versionType": "git"
},
{
"lessThan": "15df7700dd99f8a37f5c6ed2dcf1e33009cdba47",
"status": "affected",
"version": "3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc",
"versionType": "git"
},
{
"lessThan": "b878ba7e28144c9a857bc847d31f3c45413450ac",
"status": "affected",
"version": "3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc",
"versionType": "git"
},
{
"lessThan": "fbfe683f8b1ae7e40b56bdd6daf5bd671bc3a528",
"status": "affected",
"version": "3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc",
"versionType": "git"
},
{
"lessThan": "868d32ac72cba21c5c6d8a66a814b7c25a3a5c01",
"status": "affected",
"version": "3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"arch/s390/kvm/pci.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.0"
},
{
"lessThan": "6.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: s390: pci: Validate AIBV and AISB before pinning guest pages\n\nThe AIBV holds one bit per MSI-X vector for a given function. The size of\nthe bit vector is derived from the NOI and the AIBVO. If the size of the\nAIBV exceeds a single page boundary, then reject the request as we cannot\nsafely pin the guest AIBV.\n\nSimilarly reject the request if the AISB address is not 8-byte aligned as\nthe architecture requires doubleword alignment for the summary bit address.\nSince the AISBO can address up to 64 bits, the size of the AISB can only be\n8 bytes for the function. This also ensures the AISB doesn\u0027t exceed a\nsingle page boundary."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T17:11:07.555Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/3a1c64220ede4ac9ef9a3e76f008ff60a34f4c48"
},
{
"url": "https://git.kernel.org/stable/c/f00ef8efd41440129ccd88f4a1ebebf8d61d297f"
},
{
"url": "https://git.kernel.org/stable/c/15df7700dd99f8a37f5c6ed2dcf1e33009cdba47"
},
{
"url": "https://git.kernel.org/stable/c/b878ba7e28144c9a857bc847d31f3c45413450ac"
},
{
"url": "https://git.kernel.org/stable/c/fbfe683f8b1ae7e40b56bdd6daf5bd671bc3a528"
},
{
"url": "https://git.kernel.org/stable/c/868d32ac72cba21c5c6d8a66a814b7c25a3a5c01"
}
],
"title": "KVM: s390: pci: Validate AIBV and AISB before pinning guest pages",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80891",
"datePublished": "2026-09-04T17:11:07.555Z",
"dateReserved": "2026-08-26T14:34:25.799Z",
"dateUpdated": "2026-09-04T17:11:07.555Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80731 (GCVE-0-2026-80731)
Vulnerability from cvelistv5
Published
2026-09-03 08:21
Modified
2026-09-04 04:58
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: remove CAP_SYS_RAWIO zero-padding in dev_validate_header
dev_validate_header() reads dev->hard_header_len directly when
zero-padding short link layer headers for CAP_SYS_RAWIO holders:
if (capable(CAP_SYS_RAWIO)) {
memset(ll_header + len, 0, dev->hard_header_len - len);
return true;
}
Packet send paths call dev_validate_header() on skbs whose headroom was
allocated from an earlier hard_header_len read. If the device is
reconfigured so that dev->hard_header_len increases before validation,
the memset writes past the reserved buffer, an out-of-bounds write.
This out-of-bounds write is masked in some SOCK_RAW paths today because
the same concurrent increase can first make skb_push() exceed the
reserved headroom and trigger skb_under_panic(). Remove the zero-padding
branch before making those hard_header_len reads consistent, so the
snapshot fixes do not turn a loud panic into a silent overwrite.
This path is only reached for variable length L2 protocols, where
len < hard_header_len but len >= min_header_len. No remaining in-tree
variable length L2 protocol implements header_ops->validate, and the
CAP_SYS_RAWIO bypass that zero-pads and accepts short headers has no
real value beyond allowing testing of intentionally malformed input.
Drop the CAP_SYS_RAWIO branch. The remaining reads of
dev->hard_header_len in dev_validate_header() are comparisons only and
have no memory safety impact.
References
| URL | Tags | ||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: b5518429e70cd783b8ca52335456172c1a0589f6 Version: 2793a23aacbd754dbbb5cb75093deb7e4103bace Version: 2793a23aacbd754dbbb5cb75093deb7e4103bace Version: 2793a23aacbd754dbbb5cb75093deb7e4103bace Version: 2793a23aacbd754dbbb5cb75093deb7e4103bace Version: 2793a23aacbd754dbbb5cb75093deb7e4103bace Version: 2793a23aacbd754dbbb5cb75093deb7e4103bace Version: 2793a23aacbd754dbbb5cb75093deb7e4103bace Version: 2793a23aacbd754dbbb5cb75093deb7e4103bace Version: f58a6c08ebdfa978178bbca78c2ba744a2665912 Version: 1df16498dfd0d5a129bdf2982d9a08df73e8923d Version: 8b8d278aa4de9335682bbd4a3bb619af015c859e Version: 6804052fa9d86e9a512c88b24a5debbfc1a490fc Version: 3.2.80 ≤ Version: 3.16.36 ≤ Version: 4.1.28 ≤ Version: 4.4.8 ≤ Version: 4.5.2 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"include/linux/netdevice.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "53fd7f912c0877647d6a1e1877f5ea8535ee0b4a",
"status": "affected",
"version": "b5518429e70cd783b8ca52335456172c1a0589f6",
"versionType": "git"
},
{
"lessThan": "fa6d98dd925e72fc028b26a0cbbff9d2f0601ff6",
"status": "affected",
"version": "2793a23aacbd754dbbb5cb75093deb7e4103bace",
"versionType": "git"
},
{
"lessThan": "8fc9816404166a90ed8d544dc52482fafffb6d9f",
"status": "affected",
"version": "2793a23aacbd754dbbb5cb75093deb7e4103bace",
"versionType": "git"
},
{
"lessThan": "b0f92a5731dc82556a9ae005cc35f71ab136307b",
"status": "affected",
"version": "2793a23aacbd754dbbb5cb75093deb7e4103bace",
"versionType": "git"
},
{
"lessThan": "99df6b7a713f96eda206680d100b76e15f9d9b69",
"status": "affected",
"version": "2793a23aacbd754dbbb5cb75093deb7e4103bace",
"versionType": "git"
},
{
"lessThan": "74e035f07f53feca09e2352e77fccb09cad5e208",
"status": "affected",
"version": "2793a23aacbd754dbbb5cb75093deb7e4103bace",
"versionType": "git"
},
{
"lessThan": "dbb30dc943a93e083f1e531bfdc6779e57de40d0",
"status": "affected",
"version": "2793a23aacbd754dbbb5cb75093deb7e4103bace",
"versionType": "git"
},
{
"lessThan": "fc902f52a02298c7432b2334c0c82a2885a1a8b6",
"status": "affected",
"version": "2793a23aacbd754dbbb5cb75093deb7e4103bace",
"versionType": "git"
},
{
"lessThan": "3b9a324e646d3657a8d9806dfbfe4f3e4066e882",
"status": "affected",
"version": "2793a23aacbd754dbbb5cb75093deb7e4103bace",
"versionType": "git"
},
{
"status": "affected",
"version": "f58a6c08ebdfa978178bbca78c2ba744a2665912",
"versionType": "git"
},
{
"status": "affected",
"version": "1df16498dfd0d5a129bdf2982d9a08df73e8923d",
"versionType": "git"
},
{
"status": "affected",
"version": "8b8d278aa4de9335682bbd4a3bb619af015c859e",
"versionType": "git"
},
{
"status": "affected",
"version": "6804052fa9d86e9a512c88b24a5debbfc1a490fc",
"versionType": "git"
},
{
"lessThan": "3.2.81",
"status": "affected",
"version": "3.2.80",
"versionType": "semver"
},
{
"lessThan": "3.17",
"status": "affected",
"version": "3.16.36",
"versionType": "semver"
},
{
"lessThan": "4.2",
"status": "affected",
"version": "4.1.28",
"versionType": "semver"
},
{
"lessThan": "4.5",
"status": "affected",
"version": "4.4.8",
"versionType": "semver"
},
{
"lessThan": "4.6",
"status": "affected",
"version": "4.5.2",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"include/linux/netdevice.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.6"
},
{
"lessThan": "4.6",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "3.2.*",
"status": "unaffected",
"version": "3.2.81",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "3.2.81",
"versionStartIncluding": "3.2.80",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.16.36",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.1.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.5.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: remove CAP_SYS_RAWIO zero-padding in dev_validate_header\n\ndev_validate_header() reads dev-\u003ehard_header_len directly when\nzero-padding short link layer headers for CAP_SYS_RAWIO holders:\n\n if (capable(CAP_SYS_RAWIO)) {\n memset(ll_header + len, 0, dev-\u003ehard_header_len - len);\n return true;\n }\n\nPacket send paths call dev_validate_header() on skbs whose headroom was\nallocated from an earlier hard_header_len read. If the device is\nreconfigured so that dev-\u003ehard_header_len increases before validation,\nthe memset writes past the reserved buffer, an out-of-bounds write.\n\nThis out-of-bounds write is masked in some SOCK_RAW paths today because\nthe same concurrent increase can first make skb_push() exceed the\nreserved headroom and trigger skb_under_panic(). Remove the zero-padding\nbranch before making those hard_header_len reads consistent, so the\nsnapshot fixes do not turn a loud panic into a silent overwrite.\n\nThis path is only reached for variable length L2 protocols, where\nlen \u003c hard_header_len but len \u003e= min_header_len. No remaining in-tree\nvariable length L2 protocol implements header_ops-\u003evalidate, and the\nCAP_SYS_RAWIO bypass that zero-pads and accepts short headers has no\nreal value beyond allowing testing of intentionally malformed input.\n\nDrop the CAP_SYS_RAWIO branch. The remaining reads of\ndev-\u003ehard_header_len in dev_validate_header() are comparisons only and\nhave no memory safety impact."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires a local sendmsg() on a PF_PACKET SOCK_RAW socket; dev_validate_header() is only reached from af_packet transmit paths (packet_snd, packet_sendmsg_spkt, tpacket_fill_skb), not from remote packet receive.\nAC:L - The attacker can reliably win the TOCTOU race by concurrently sending PF_PACKET frames while changing netdev hard_header_len (e.g., PPP channel attach or bonding slave updates via rtnetlink), controlling both allocation and validation sides.\nPR:L - PF_PACKET creation requires CAP_NET_RAW and the memset bypass requires CAP_SYS_RAWIO; both are granted to user-namespace root (CAP_FULL_SET via unshare -Urn), so a basic unprivileged local user can obtain the needed privileges without init-namespace root.\nUI:N - No victim interaction is required; exploitation is fully attacker-driven through socket creation, concurrent device reconfiguration, and crafted sendmsg() calls.\nS:U - Impact is kernel heap memory corruption and local privilege escalation within the same kernel security domain, not a VM escape, IOMMU bypass, or other cross-authority boundary violation.\nC:H - The bug is an out-of-bounds write via memset() past skb link-layer headroom when hard_header_len grows between allocation and validation; such heap corruption can be groomed into arbitrary kernel memory read primitives.\nI:H - Writing past the reserved skb headroom corrupts adjacent kernel heap objects and is a standard exploitable primitive for arbitrary kernel writes, control-flow hijacking, and privilege escalation.\nA:H - The out-of-bounds memset can corrupt critical kernel structures and trigger oops/panic; the commit notes this can silently overwrite memory where other SOCK_RAW paths would have panicked via skb_under_panic."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T04:58:17.510Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/53fd7f912c0877647d6a1e1877f5ea8535ee0b4a"
},
{
"url": "https://git.kernel.org/stable/c/fa6d98dd925e72fc028b26a0cbbff9d2f0601ff6"
},
{
"url": "https://git.kernel.org/stable/c/8fc9816404166a90ed8d544dc52482fafffb6d9f"
},
{
"url": "https://git.kernel.org/stable/c/b0f92a5731dc82556a9ae005cc35f71ab136307b"
},
{
"url": "https://git.kernel.org/stable/c/99df6b7a713f96eda206680d100b76e15f9d9b69"
},
{
"url": "https://git.kernel.org/stable/c/74e035f07f53feca09e2352e77fccb09cad5e208"
},
{
"url": "https://git.kernel.org/stable/c/dbb30dc943a93e083f1e531bfdc6779e57de40d0"
},
{
"url": "https://git.kernel.org/stable/c/fc902f52a02298c7432b2334c0c82a2885a1a8b6"
},
{
"url": "https://git.kernel.org/stable/c/3b9a324e646d3657a8d9806dfbfe4f3e4066e882"
}
],
"title": "net: remove CAP_SYS_RAWIO zero-padding in dev_validate_header",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80731",
"datePublished": "2026-09-03T08:21:48.924Z",
"dateReserved": "2026-08-26T14:34:25.789Z",
"dateUpdated": "2026-09-04T04:58:17.510Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68108 (GCVE-0-2026-68108)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-19 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu/vce: fix integer overflow in image size
Fix a security vulnerability where malicious VCE command streams
with oversized dimensions (e.g. 65536×65536) cause 32-bit integer
overflow, wrapping the calculated buffer size to 0. This bypasses
validation and allows GPU firmware to perform out-of-bound memory
access.
The fix uses 64-bit arithmetic to detect overflow and rejects
invalid dimensions before they reach the hardware.
V2: remove redundant check
V3: modify max height value
V4: remove size64
(cherry picked from commit cbe408dba581755ad1279a487ec786d8927d778d)
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: f1689ec1b0b1256d0e69653cd4aaeee44aafdf5c Version: f1689ec1b0b1256d0e69653cd4aaeee44aafdf5c Version: f1689ec1b0b1256d0e69653cd4aaeee44aafdf5c Version: f1689ec1b0b1256d0e69653cd4aaeee44aafdf5c Version: f1689ec1b0b1256d0e69653cd4aaeee44aafdf5c Version: f1689ec1b0b1256d0e69653cd4aaeee44aafdf5c |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/amdgpu_vce.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "893db20383800cfe92e638705984eebb13bc81a5",
"status": "affected",
"version": "f1689ec1b0b1256d0e69653cd4aaeee44aafdf5c",
"versionType": "git"
},
{
"lessThan": "a07430abd556de3707adfcadcc60db3fa64e4b2b",
"status": "affected",
"version": "f1689ec1b0b1256d0e69653cd4aaeee44aafdf5c",
"versionType": "git"
},
{
"lessThan": "a6d7065b91a14790980ce6f4960db0ca8c3c9940",
"status": "affected",
"version": "f1689ec1b0b1256d0e69653cd4aaeee44aafdf5c",
"versionType": "git"
},
{
"lessThan": "7eebef042c12dfe0568593ee6a8926d16505925e",
"status": "affected",
"version": "f1689ec1b0b1256d0e69653cd4aaeee44aafdf5c",
"versionType": "git"
},
{
"lessThan": "00c311a13d225266800c712f2b7db2711c6897de",
"status": "affected",
"version": "f1689ec1b0b1256d0e69653cd4aaeee44aafdf5c",
"versionType": "git"
},
{
"lessThan": "186bfdc4e26d019b2e7570cb121964a1d89b2e5b",
"status": "affected",
"version": "f1689ec1b0b1256d0e69653cd4aaeee44aafdf5c",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/amdgpu_vce.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.2"
},
{
"lessThan": "4.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/vce: fix integer overflow in image size\n\nFix a security vulnerability where malicious VCE command streams\nwith oversized dimensions (e.g. 65536\u00d765536) cause 32-bit integer\noverflow, wrapping the calculated buffer size to 0. This bypasses\nvalidation and allows GPU firmware to perform out-of-bound memory\naccess.\n\nThe fix uses 64-bit arithmetic to detect overflow and rejects\ninvalid dimensions before they reach the hardware.\n\nV2: remove redundant check\nV3: modify max height value\nV4: remove size64\n\n(cherry picked from commit cbe408dba581755ad1279a487ec786d8927d778d)"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The flaw is reached only through the AMDGPU_CS DRM ioctl on a local render node (/dev/dri/renderD*); there is no network, adjacent-radio, or physical-device path to the VCE command-stream parser.\nAC:L - On affected AMD GPUs using physical-mode VCE parsing, an attacker fully controls the IB and can set create-command dimensions (e.g., 65536x65536) to deterministically overflow the 32-bit size to zero without races or uncontrollable layout conditions.\nPR:L - Exploitation requires only unprivileged local access to the amdgpu DRM render node; AMDGPU_CS is gated by DRM_AUTH|DRM_RENDER_ALLOW with no root, DRM-master, or non-namespace capability requirement.\nUI:N - No victim interaction is needed beyond the attacker submitting crafted VCE command buffers through their own render-node context; no third party must open files or take other actions.\nS:C - Bypassing size-based BO relocation/validation lets VCE firmware DMA outside the intended buffer boundaries, crossing the GPU memory-isolation boundary that kernel validation is meant to enforce on GART/VRAM mappings.\nC:H - With validation defeated, VCE firmware can read arbitrarily beyond undersized encode/context/MV buffers, exposing other GPU-accessible memory including GTT-mapped system memory and adjacent VRAM allocations.\nI:H - The same out-of-bounds VCE firmware accesses enable arbitrary writes to GPU-mapped memory beyond validated buffers, providing memory-corruption primitives suitable for privilege escalation or control-flow influence.\nA:H - Oversized VCE operations against undersized buffers can trigger GPU page faults, engine hangs, GPU resets, or broader system disruption that the attacker can repeat via further command submissions."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:29:22.109Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/893db20383800cfe92e638705984eebb13bc81a5"
},
{
"url": "https://git.kernel.org/stable/c/a07430abd556de3707adfcadcc60db3fa64e4b2b"
},
{
"url": "https://git.kernel.org/stable/c/a6d7065b91a14790980ce6f4960db0ca8c3c9940"
},
{
"url": "https://git.kernel.org/stable/c/7eebef042c12dfe0568593ee6a8926d16505925e"
},
{
"url": "https://git.kernel.org/stable/c/00c311a13d225266800c712f2b7db2711c6897de"
},
{
"url": "https://git.kernel.org/stable/c/186bfdc4e26d019b2e7570cb121964a1d89b2e5b"
}
],
"title": "drm/amdgpu/vce: fix integer overflow in image size",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68108",
"datePublished": "2026-08-10T11:58:25.241Z",
"dateReserved": "2026-07-30T09:28:09.368Z",
"dateUpdated": "2026-08-19T16:29:22.109Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72062 (GCVE-0-2026-72062)
Vulnerability from cvelistv5
Published
2026-08-15 05:52
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
gpio: mt7621: avoid corruption of shared interrupt trigger state
The bank-shared fields like 'rising' and 'falling' are modified using
non-atomic read-modify-write operations. Since every gpio chip instance
represents an entire bank of 32 pins, if 'mediatek_gpio_irq_type()' is
called concurrently for different IRQs on the same bank a possible overwrite
of each other's configuration is possible. Thus, protect this state with
'gpio_generic_lock_irqsave' lock in the same way it is handled in irp_chip
'mediatek_gpio_irq_mask()' and 'mediatek_gpio_irq_unmask()' callbacks.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 4ba9c3afda41213ec98c30053e32963892e6dc7c Version: 4ba9c3afda41213ec98c30053e32963892e6dc7c Version: 4ba9c3afda41213ec98c30053e32963892e6dc7c Version: 4ba9c3afda41213ec98c30053e32963892e6dc7c Version: 4ba9c3afda41213ec98c30053e32963892e6dc7c Version: 4ba9c3afda41213ec98c30053e32963892e6dc7c |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpio/gpio-mt7621.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "bddf9314a57a243dd11ed945ba11e146e331257e",
"status": "affected",
"version": "4ba9c3afda41213ec98c30053e32963892e6dc7c",
"versionType": "git"
},
{
"lessThan": "207d3ebf36f654a43a934addeb4d6775cb2dd667",
"status": "affected",
"version": "4ba9c3afda41213ec98c30053e32963892e6dc7c",
"versionType": "git"
},
{
"lessThan": "877a243006788aaa586b2d087f27c9f3628071b0",
"status": "affected",
"version": "4ba9c3afda41213ec98c30053e32963892e6dc7c",
"versionType": "git"
},
{
"lessThan": "d3b9026ef78da3018a7d2c5a9c9d611de6d45c47",
"status": "affected",
"version": "4ba9c3afda41213ec98c30053e32963892e6dc7c",
"versionType": "git"
},
{
"lessThan": "a60a40c9ba30edd06d3fb4215fdf430ed968728e",
"status": "affected",
"version": "4ba9c3afda41213ec98c30053e32963892e6dc7c",
"versionType": "git"
},
{
"lessThan": "1781172526d1092323af443fa03f00e6de560401",
"status": "affected",
"version": "4ba9c3afda41213ec98c30053e32963892e6dc7c",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpio/gpio-mt7621.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.19"
},
{
"lessThan": "4.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ngpio: mt7621: avoid corruption of shared interrupt trigger state\n\nThe bank-shared fields like \u0027rising\u0027 and \u0027falling\u0027 are modified using\nnon-atomic read-modify-write operations. Since every gpio chip instance\nrepresents an entire bank of 32 pins, if \u0027mediatek_gpio_irq_type()\u0027 is\ncalled concurrently for different IRQs on the same bank a possible overwrite\nof each other\u0027s configuration is possible. Thus, protect this state with\n\u0027gpio_generic_lock_irqsave\u0027 lock in the same way it is handled in irp_chip\n\u0027mediatek_gpio_irq_mask()\u0027 and \u0027mediatek_gpio_irq_unmask()\u0027 callbacks."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:38.586Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/bddf9314a57a243dd11ed945ba11e146e331257e"
},
{
"url": "https://git.kernel.org/stable/c/207d3ebf36f654a43a934addeb4d6775cb2dd667"
},
{
"url": "https://git.kernel.org/stable/c/877a243006788aaa586b2d087f27c9f3628071b0"
},
{
"url": "https://git.kernel.org/stable/c/d3b9026ef78da3018a7d2c5a9c9d611de6d45c47"
},
{
"url": "https://git.kernel.org/stable/c/a60a40c9ba30edd06d3fb4215fdf430ed968728e"
},
{
"url": "https://git.kernel.org/stable/c/1781172526d1092323af443fa03f00e6de560401"
}
],
"title": "gpio: mt7621: avoid corruption of shared interrupt trigger state",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72062",
"datePublished": "2026-08-15T05:52:16.564Z",
"dateReserved": "2026-08-09T03:40:39.903Z",
"dateUpdated": "2026-08-23T12:46:38.586Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80754 (GCVE-0-2026-80754)
Vulnerability from cvelistv5
Published
2026-09-03 08:26
Modified
2026-09-04 04:58
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Input: synaptics-rmi4 - fix F55 transmitter electrode count typo
During F55 sensor detection, the transmitter (TX) electrode count was
incorrectly assigned the value of the receiver (RX) electrode count
due to copy-paste typos.
This incorrect value was then propagated to the driver data and used
by F54 to determine the diagnostics report size. On devices with more
RX than TX electrodes, this inflated the perceived TX count, leading
to incorrect report size calculations and potential out-of-bounds
buffer accesses.
Fix the typos by correctly assigning the TX electrode counts.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 6adba43fd222ea362c36296d1a6897c2e28fdc8e Version: 6adba43fd222ea362c36296d1a6897c2e28fdc8e Version: 6adba43fd222ea362c36296d1a6897c2e28fdc8e Version: 6adba43fd222ea362c36296d1a6897c2e28fdc8e Version: 6adba43fd222ea362c36296d1a6897c2e28fdc8e Version: 6adba43fd222ea362c36296d1a6897c2e28fdc8e Version: 6adba43fd222ea362c36296d1a6897c2e28fdc8e Version: 6adba43fd222ea362c36296d1a6897c2e28fdc8e |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/input/rmi4/rmi_f55.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "6484e00d6778fdf2209cd75940bc3902b276457f",
"status": "affected",
"version": "6adba43fd222ea362c36296d1a6897c2e28fdc8e",
"versionType": "git"
},
{
"lessThan": "db4e20265ebda729610ca5cf45ca9437462c3f36",
"status": "affected",
"version": "6adba43fd222ea362c36296d1a6897c2e28fdc8e",
"versionType": "git"
},
{
"lessThan": "a6d9646e77da7cab2dff7043a8e9f75e23b836bc",
"status": "affected",
"version": "6adba43fd222ea362c36296d1a6897c2e28fdc8e",
"versionType": "git"
},
{
"lessThan": "0739c65e799d4a93fe573ed23255a71fcfcc5438",
"status": "affected",
"version": "6adba43fd222ea362c36296d1a6897c2e28fdc8e",
"versionType": "git"
},
{
"lessThan": "9759502f5cd71805923457f183ae5b9533e20c7b",
"status": "affected",
"version": "6adba43fd222ea362c36296d1a6897c2e28fdc8e",
"versionType": "git"
},
{
"lessThan": "9b184c8337c6e12df129399007735a7fbcbbcb7b",
"status": "affected",
"version": "6adba43fd222ea362c36296d1a6897c2e28fdc8e",
"versionType": "git"
},
{
"lessThan": "a81cafe3c3c2f8494063385a7b0ea7ff407bf19f",
"status": "affected",
"version": "6adba43fd222ea362c36296d1a6897c2e28fdc8e",
"versionType": "git"
},
{
"lessThan": "6058f0fea10f3caf63a435677358d1b8e9325114",
"status": "affected",
"version": "6adba43fd222ea362c36296d1a6897c2e28fdc8e",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/input/rmi4/rmi_f55.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.10"
},
{
"lessThan": "4.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.46",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.10",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nInput: synaptics-rmi4 - fix F55 transmitter electrode count typo\n\nDuring F55 sensor detection, the transmitter (TX) electrode count was\nincorrectly assigned the value of the receiver (RX) electrode count\ndue to copy-paste typos.\n\nThis incorrect value was then propagated to the driver data and used\nby F54 to determine the diagnostics report size. On devices with more\nRX than TX electrodes, this inflated the perceived TX count, leading\nto incorrect report size calculations and potential out-of-bounds\nbuffer accesses.\n\nFix the typos by correctly assigning the TX electrode counts."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires local V4L2 ioctls (STREAMON/QBUF) on the synaptics-rmi4 F54 diagnostics node (/dev/video* or /dev/v4l-touch*) that drive rmi_f54_buffer_queue() into rmi_f54_work(); the touch controller is on-board I2C/SPI/SMBus, not reachable over a network protocol.\nAC:L - On affected Synaptics hardware with more RX than TX electrodes and CONFIG_RMI4_F54 enabled, the inflated F55 TX count makes rmi_f54_get_report_size() exceed the F54-probe allocation deterministically; an attacker with device access can queue capture buffers without races or layout-dependent conditions.\nPR:L - No kernel capability is required beyond permission to open the registered VFL_TYPE_TOUCH video device and issue standard V4L2 capture ioctls; on typical laptops, kiosks, and Android builds this is granted to unprivileged local users via video/input device policy without init-namespace root.\nUI:N - No cooperative victim action is needed; the attacker opens the diagnostics node, selects a 16-bit F54 report type, and streams capture buffers to trigger the overflow without requiring another user to plug hardware, mount filesystems, or interact with the system.\nS:U - Impact is confined to host kernel heap memory within the same security boundary; this is a kmalloc buffer overflow in the input driver and does not inherently provide VM escape, IOMMU bypass, or cross-sandbox authority change.\nC:H - The inflated report_size causes rmi_f54_work() to read past the end of report_data and rmi_f54_buffer_queue() memcpy() copies that oversized payload into userspace, leaking adjacent kernel heap/slab contents that can include sensitive pointers and kernel memory.\nI:H - The device read loop writes attacker-influenced diagnostic bytes up to tens of kilobytes past the devm-allocated report_data buffer, corrupting adjacent heap objects and enabling control-flow hijacking or privilege-escalation primitives typical of kernel heap overflows.\nA:H - Corrupting adjacent slab objects via the out-of-bounds write can immediately panic or oops the kernel; the overflow is repeatable on each queued V4L2 buffer while the mis-probed F55 electrode counts remain in drv_data on affected hardware."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T04:58:34.715Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/6484e00d6778fdf2209cd75940bc3902b276457f"
},
{
"url": "https://git.kernel.org/stable/c/db4e20265ebda729610ca5cf45ca9437462c3f36"
},
{
"url": "https://git.kernel.org/stable/c/a6d9646e77da7cab2dff7043a8e9f75e23b836bc"
},
{
"url": "https://git.kernel.org/stable/c/0739c65e799d4a93fe573ed23255a71fcfcc5438"
},
{
"url": "https://git.kernel.org/stable/c/9759502f5cd71805923457f183ae5b9533e20c7b"
},
{
"url": "https://git.kernel.org/stable/c/9b184c8337c6e12df129399007735a7fbcbbcb7b"
},
{
"url": "https://git.kernel.org/stable/c/a81cafe3c3c2f8494063385a7b0ea7ff407bf19f"
},
{
"url": "https://git.kernel.org/stable/c/6058f0fea10f3caf63a435677358d1b8e9325114"
}
],
"title": "Input: synaptics-rmi4 - fix F55 transmitter electrode count typo",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80754",
"datePublished": "2026-09-03T08:26:33.180Z",
"dateReserved": "2026-08-26T14:34:25.790Z",
"dateUpdated": "2026-09-04T04:58:34.715Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74726 (GCVE-0-2026-74726)
Vulnerability from cvelistv5
Published
2026-08-22 15:33
Modified
2026-08-25 05:42
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
bonding: alb: re-check primary_is_promisc under RTNL in bond_alb_monitor
bond_alb_monitor() reads primary_is_promisc under RCU, then drops RCU and
takes RTNL via rtnl_trylock() before undoing the promiscuity it set on the
active slave. In that window the active slave can change under RTNL
(RTM_DELLINK -> __bond_release_one() -> bond_alb_handle_active_change()),
which already drops the promiscuity and clears primary_is_promisc. The
monitor still acts on the stale decision: if the slave was removed with no
failover, curr_active_slave is now NULL and the deref faults; if it failed
over, the stale dev_set_promiscuity(-1) underflows the new slave's
promiscuity counter and pins it in IFF_PROMISC.
Oops: general protection fault, probably for non-canonical address ...
KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]
Workqueue: b42 bond_alb_monitor
RIP: 0010:bond_alb_monitor (drivers/net/bonding/bond_alb.c:1600)
process_one_work (kernel/workqueue.c:3322)
worker_thread (kernel/workqueue.c:3486)
kthread (kernel/kthread.c:436)
ret_from_fork (arch/x86/kernel/process.c:158)
Kernel panic - not syncing: Fatal exception
Re-check primary_is_promisc (and curr_active_slave) after taking RTNL so
the monitor only undoes an increment it still owns. The other bonding
monitors already re-read state under RTNL in their commit phase
(bond_miimon_commit/bond_ab_arp_commit); bond_alb_monitor() was the only
one acting on the pre-trylock decision.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d0e81b7e2246a41d068ecaf15aac9de570816d63 Version: d0e81b7e2246a41d068ecaf15aac9de570816d63 Version: d0e81b7e2246a41d068ecaf15aac9de570816d63 Version: d0e81b7e2246a41d068ecaf15aac9de570816d63 Version: d0e81b7e2246a41d068ecaf15aac9de570816d63 Version: d0e81b7e2246a41d068ecaf15aac9de570816d63 Version: d0e81b7e2246a41d068ecaf15aac9de570816d63 Version: d0e81b7e2246a41d068ecaf15aac9de570816d63 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/bonding/bond_alb.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "f7668762bf5fd6db9397de5c0514407489d9d815",
"status": "affected",
"version": "d0e81b7e2246a41d068ecaf15aac9de570816d63",
"versionType": "git"
},
{
"lessThan": "09add8d5cfa9c46828f51eaad162c36e86366b71",
"status": "affected",
"version": "d0e81b7e2246a41d068ecaf15aac9de570816d63",
"versionType": "git"
},
{
"lessThan": "b82f51681a7a88c7d3c865e817a3340d42b5fa2a",
"status": "affected",
"version": "d0e81b7e2246a41d068ecaf15aac9de570816d63",
"versionType": "git"
},
{
"lessThan": "dd148539fb4741d01c06b7d2c8bd84b01920756c",
"status": "affected",
"version": "d0e81b7e2246a41d068ecaf15aac9de570816d63",
"versionType": "git"
},
{
"lessThan": "dccec0227ed8d9e36936d66e256b957dc2858468",
"status": "affected",
"version": "d0e81b7e2246a41d068ecaf15aac9de570816d63",
"versionType": "git"
},
{
"lessThan": "2faf75a8a06504071b4c0aea7e45a9cc49a4e187",
"status": "affected",
"version": "d0e81b7e2246a41d068ecaf15aac9de570816d63",
"versionType": "git"
},
{
"lessThan": "257c4a3a34d8f51efb00f35375a0c6ce3c8f6ce2",
"status": "affected",
"version": "d0e81b7e2246a41d068ecaf15aac9de570816d63",
"versionType": "git"
},
{
"lessThan": "683c6ba6e58e6ed1037831ea97dd58d9c0e76b8d",
"status": "affected",
"version": "d0e81b7e2246a41d068ecaf15aac9de570816d63",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/bonding/bond_alb.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.24"
},
{
"lessThan": "2.6.24",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.24",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbonding: alb: re-check primary_is_promisc under RTNL in bond_alb_monitor\n\nbond_alb_monitor() reads primary_is_promisc under RCU, then drops RCU and\ntakes RTNL via rtnl_trylock() before undoing the promiscuity it set on the\nactive slave. In that window the active slave can change under RTNL\n(RTM_DELLINK -\u003e __bond_release_one() -\u003e bond_alb_handle_active_change()),\nwhich already drops the promiscuity and clears primary_is_promisc. The\nmonitor still acts on the stale decision: if the slave was removed with no\nfailover, curr_active_slave is now NULL and the deref faults; if it failed\nover, the stale dev_set_promiscuity(-1) underflows the new slave\u0027s\npromiscuity counter and pins it in IFF_PROMISC.\n\n Oops: general protection fault, probably for non-canonical address ...\n KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]\n Workqueue: b42 bond_alb_monitor\n RIP: 0010:bond_alb_monitor (drivers/net/bonding/bond_alb.c:1600)\n process_one_work (kernel/workqueue.c:3322)\n worker_thread (kernel/workqueue.c:3486)\n kthread (kernel/kthread.c:436)\n ret_from_fork (arch/x86/kernel/process.c:158)\n Kernel panic - not syncing: Fatal exception\n\nRe-check primary_is_promisc (and curr_active_slave) after taking RTNL so\nthe monitor only undoes an increment it still owns. The other bonding\nmonitors already re-read state under RTNL in their commit phase\n(bond_miimon_commit/bond_ab_arp_commit); bond_alb_monitor() was the only\none acting on the pre-trylock decision."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires local RTNL netlink (RTM_DELLINK) or bonding ioctl (SIOCBONDRELEASE) to remove/reconfigure slaves while bond_alb_monitor runs; the bug is in a delayed workqueue, not in packet receive or any remote network protocol path.\nAC:L - An attacker with CAP_NET_ADMIN controls both race sides\u2014timing slave removal/failover against the periodic ALB monitor after primary_is_promisc is set\u2014and can retry rapidly when rtnl_trylock fails, making NULL deref or promiscuity-counter underflow reliably winnable.\nPR:L - Triggering ALB bond setup and slave release requires CAP_NET_ADMIN, which unprivileged users can obtain inside a user+network namespace (unshare -Urn), enabling host-wide kernel panic without init-namespace root on typical distributions.\nUI:N - No victim interaction is required; the attacker programmatically creates an ALB bond, drives primary_is_promisc via slave disable/removal, and races bond_alb_monitor without any other user or administrator action.\nS:U - Impact is confined to kernel networking state and causes host kernel panic or netdev promiscuity corruption; it does not cross VM, container, or IOMMU security boundaries into another security authority.\nC:H - Beyond the NULL-deref crash path, the failover race underflows dev-\u003epromiscuity and permanently pins IFF_PROMISC on the new active slave, enabling sustained capture of all traffic on that bonded interface/segment\u2014a broad confidentiality impact on server/cloud HA deployments.\nI:L - The stale dev_set_promiscuity(-1) corrupts the netdev promiscuity counter (unsigned underflow to a huge value), improperly modifying kernel network device state even though it does not provide arbitrary memory write or code-execution primitives.\nA:H - If the active slave is removed without failover, the monitor dereferences a NULL curr_active_slave and panics the kernel, as confirmed by KASAN null-ptr-deref and \"Kernel panic - not syncing: Fatal exception\" in the fix commit."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:42:07.173Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/f7668762bf5fd6db9397de5c0514407489d9d815"
},
{
"url": "https://git.kernel.org/stable/c/09add8d5cfa9c46828f51eaad162c36e86366b71"
},
{
"url": "https://git.kernel.org/stable/c/b82f51681a7a88c7d3c865e817a3340d42b5fa2a"
},
{
"url": "https://git.kernel.org/stable/c/dd148539fb4741d01c06b7d2c8bd84b01920756c"
},
{
"url": "https://git.kernel.org/stable/c/dccec0227ed8d9e36936d66e256b957dc2858468"
},
{
"url": "https://git.kernel.org/stable/c/2faf75a8a06504071b4c0aea7e45a9cc49a4e187"
},
{
"url": "https://git.kernel.org/stable/c/257c4a3a34d8f51efb00f35375a0c6ce3c8f6ce2"
},
{
"url": "https://git.kernel.org/stable/c/683c6ba6e58e6ed1037831ea97dd58d9c0e76b8d"
}
],
"title": "bonding: alb: re-check primary_is_promisc under RTNL in bond_alb_monitor",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74726",
"datePublished": "2026-08-22T15:33:17.128Z",
"dateReserved": "2026-08-15T05:44:03.929Z",
"dateUpdated": "2026-08-25T05:42:07.173Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72045 (GCVE-0-2026-72045)
Vulnerability from cvelistv5
Published
2026-08-15 05:52
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
octeontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF
rvu_mbox_handler_lmtst_tbl_setup() uses req->base_pcifunc as a direct
index into the LMT map table to read another function's LMTLINE
physical base address and copy it into the caller's own LMT map table
entry. The mailbox dispatcher authenticates req->hdr.pcifunc from the
IRQ source, but req->base_pcifunc is a separate payload field and is
not sanitized.
Reject the request with -EPERM when a VF caller's base_pcifunc is not a
valid function under its own PF. is_pf_func_valid() bounds the FUNC field
to the PF's configured VF count, keeping the computed index inside the
caller's own slot block.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 893ae97214c385be02f8ec097298cc48c7f0d905 Version: 893ae97214c385be02f8ec097298cc48c7f0d905 Version: 893ae97214c385be02f8ec097298cc48c7f0d905 Version: 893ae97214c385be02f8ec097298cc48c7f0d905 Version: 893ae97214c385be02f8ec097298cc48c7f0d905 Version: 893ae97214c385be02f8ec097298cc48c7f0d905 Version: 893ae97214c385be02f8ec097298cc48c7f0d905 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/marvell/octeontx2/af/rvu_cn10k.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "04c014e49b9f53d58a8f94adece8a0af3ae1b85c",
"status": "affected",
"version": "893ae97214c385be02f8ec097298cc48c7f0d905",
"versionType": "git"
},
{
"lessThan": "6967dd944be2a71eddab3a2ae1a1a4dd9e5f8eed",
"status": "affected",
"version": "893ae97214c385be02f8ec097298cc48c7f0d905",
"versionType": "git"
},
{
"lessThan": "e9c5b03208507dd6d58b0c23a2c60b5c2f4c1b11",
"status": "affected",
"version": "893ae97214c385be02f8ec097298cc48c7f0d905",
"versionType": "git"
},
{
"lessThan": "54535692bec9ef464adc714108eb19e49e38b5a2",
"status": "affected",
"version": "893ae97214c385be02f8ec097298cc48c7f0d905",
"versionType": "git"
},
{
"lessThan": "c73b8795b45f4ad5a95120d2e9b435ea4616e08e",
"status": "affected",
"version": "893ae97214c385be02f8ec097298cc48c7f0d905",
"versionType": "git"
},
{
"lessThan": "59da37fee81a8d76079313348ca13c5bc90dd6ae",
"status": "affected",
"version": "893ae97214c385be02f8ec097298cc48c7f0d905",
"versionType": "git"
},
{
"lessThan": "8cdcf3d2caacdee7ddd363705fb4d93b0c1a0915",
"status": "affected",
"version": "893ae97214c385be02f8ec097298cc48c7f0d905",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/marvell/octeontx2/af/rvu_cn10k.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.14"
},
{
"lessThan": "5.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nocteontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF\n\nrvu_mbox_handler_lmtst_tbl_setup() uses req-\u003ebase_pcifunc as a direct\nindex into the LMT map table to read another function\u0027s LMTLINE\nphysical base address and copy it into the caller\u0027s own LMT map table\nentry. The mailbox dispatcher authenticates req-\u003ehdr.pcifunc from the\nIRQ source, but req-\u003ebase_pcifunc is a separate payload field and is\nnot sanitized.\n\nReject the request with -EPERM when a VF caller\u0027s base_pcifunc is not a\nvalid function under its own PF. is_pf_func_valid() bounds the FUNC field\nto the PF\u0027s configured VF count, keeping the computed index inside the\ncaller\u0027s own slot block."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires local control of an assigned Marvell CN10K/OCTEONTX2 SR-IOV VF and sending a crafted LMTST_TBL_SETUP mailbox message over the PCI VF\u2192AF control path (rvu_afvf_mbox_handler\u2192rvu_mbox_handler_lmtst_tbl_setup); it is not reachable via remote packet delivery.\nAC:L - Once a VF is assigned, the attacker fully controls the unsanitized base_pcifunc payload field and can trigger the flaw deterministically with a single mailbox message; no race, special memory layout, or victim timing is required.\nPR:L - Only control of an assigned VF is needed (typical cloud/tenant VM or container with SR-IOV passthrough, or guest root/CAP_NET_ADMIN managing the VF); host init-namespace root is not required and unprivileged host users cannot reach this hardware mailbox without the VF device.\nUI:N - No victim user action is required; the attacker directly sends the malicious LMTST_TBL_SETUP mailbox request from their VF to the AF handler.\nS:C - A malicious VF tenant can retarget hardware LMTLINE stores to another PF/VF\u0027s memory region, crossing the SR-IOV tenant isolation boundary and enabling guest-to-host or guest-to-guest impact on shared CN10K NIC deployments.\nC:H - Redirecting a VF\u0027s LMT map entry to another function\u0027s LMTLINE region lets the attacker read victim in-flight packet/crypto submission metadata and buffer pointers from shared hardware LMT memory, constituting cross-tenant information disclosure beyond the attacker\u0027s scope.\nI:H - After the map-table redirect, the attacker\u0027s LMTST flush operations (packet TX SQE submission, NPA aura free, CPT enqueue) are hardware-written into the victim\u0027s LMTLINE physical pages, enabling arbitrary cross-tenant memory corruption and potential control of victim I/O submission state.\nA:H - Corrupting another PF/VF\u0027s LMTLINE submission buffers can crash or hang the victim\u0027s networking/crypto stack (guest kernel oops/panic or persistent TX failure) and the attack can be repeated on demand by resending mailbox requests."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:33.156Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/04c014e49b9f53d58a8f94adece8a0af3ae1b85c"
},
{
"url": "https://git.kernel.org/stable/c/6967dd944be2a71eddab3a2ae1a1a4dd9e5f8eed"
},
{
"url": "https://git.kernel.org/stable/c/e9c5b03208507dd6d58b0c23a2c60b5c2f4c1b11"
},
{
"url": "https://git.kernel.org/stable/c/54535692bec9ef464adc714108eb19e49e38b5a2"
},
{
"url": "https://git.kernel.org/stable/c/c73b8795b45f4ad5a95120d2e9b435ea4616e08e"
},
{
"url": "https://git.kernel.org/stable/c/59da37fee81a8d76079313348ca13c5bc90dd6ae"
},
{
"url": "https://git.kernel.org/stable/c/8cdcf3d2caacdee7ddd363705fb4d93b0c1a0915"
}
],
"title": "octeontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72045",
"datePublished": "2026-08-15T05:52:04.038Z",
"dateReserved": "2026-08-09T03:40:39.902Z",
"dateUpdated": "2026-08-23T12:46:33.156Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80781 (GCVE-0-2026-80781)
Vulnerability from cvelistv5
Published
2026-09-04 15:12
Modified
2026-09-04 15:12
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
HID: core: fix OOB read of field->usage in hid_set_field()
hid_set_field() hands field->usage + offset to hid_dump_input() before
the guard that bounds offset:
hid_dump_input(field->report->device, field->usage + offset, value);
if (offset >= field->report_count) {
hid_err(...);
return -1;
}
Under CONFIG_DEBUG_FS hid_dump_input() dereferences that pointer, with
buf = hid_resolv_usage(usage->hid, NULL). The usage[] array is
allocated inline with the hid_field in hid_register_field() and holds
field->maxusage entries, so an offset past it reads off the end of the
kvzalloc()ed allocation and into a neighbouring object. Had the guard
run first, offset < report_count <= maxusage would already have confined
the pointer to the array.
A caller supplies such an offset today. picolcd_fb_send_tile()
validates only report->maxfield before issuing
hid_set_field(report->field[0], 11 + i, ...) for i = 0..31, so its
offsets are fixed at 11..42 and are never checked against the bound
field. When the device registers that field with fewer usages, the
framebuffer deferred-io work drives the read on every tile. KASAN
reports a 4-byte slab-out-of-bounds read in hid_dump_input() below
hid_set_field(), and the same boot logs "offset (1) exceeds
report_count (1)" from the guard that runs only afterwards.
Move the hid_dump_input() call below the guard. Because
field->maxusage >= field->report_count, the guard then establishes that
field->usage + offset lies inside the array before it is dereferenced,
for every caller and without changing behaviour on the valid path.
Discovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>
References
| URL | Tags | ||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/hid/hid-core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "465544b3d6602cfbdc2305d5cbfb7f4954353b63",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "4993e1ab85d7d3f4a40d81852170f9665483bbd8",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "313ead1abed945544703b100a12c5a10fdf78409",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "c1d9c16af51cc6ff92a5a062617d3b022dd01078",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "a38212687519f2a72f43e62dec1348a690412404",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "9a1d7c5f0d82e8665715d5e47c9410c6a97e3748",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "5215ea00a747eca34cb2f603cfef91fef76c2558",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "cbcc0e8dea499e5ca86b583372ccb1815cccc570",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "a13cdb19fcb223ed41bdab3bab42b98dba87e90b",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/hid/hid-core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.267",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.218",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.185",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.154",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.106",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.47",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.1",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.267",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.218",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.185",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.154",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.106",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.47",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.11",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.1",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: core: fix OOB read of field-\u003eusage in hid_set_field()\n\nhid_set_field() hands field-\u003eusage + offset to hid_dump_input() before\nthe guard that bounds offset:\n\n\thid_dump_input(field-\u003ereport-\u003edevice, field-\u003eusage + offset, value);\n\n\tif (offset \u003e= field-\u003ereport_count) {\n\t\thid_err(...);\n\t\treturn -1;\n\t}\n\nUnder CONFIG_DEBUG_FS hid_dump_input() dereferences that pointer, with\nbuf = hid_resolv_usage(usage-\u003ehid, NULL). The usage[] array is\nallocated inline with the hid_field in hid_register_field() and holds\nfield-\u003emaxusage entries, so an offset past it reads off the end of the\nkvzalloc()ed allocation and into a neighbouring object. Had the guard\nrun first, offset \u003c report_count \u003c= maxusage would already have confined\nthe pointer to the array.\n\nA caller supplies such an offset today. picolcd_fb_send_tile()\nvalidates only report-\u003emaxfield before issuing\nhid_set_field(report-\u003efield[0], 11 + i, ...) for i = 0..31, so its\noffsets are fixed at 11..42 and are never checked against the bound\nfield. When the device registers that field with fewer usages, the\nframebuffer deferred-io work drives the read on every tile. KASAN\nreports a 4-byte slab-out-of-bounds read in hid_dump_input() below\nhid_set_field(), and the same boot logs \"offset (1) exceeds\nreport_count (1)\" from the guard that runs only afterwards.\n\nMove the hid_dump_input() call below the guard. Because\nfield-\u003emaxusage \u003e= field-\u003ereport_count, the guard then establishes that\nfield-\u003eusage + offset lies inside the array before it is dereferenced,\nfor every caller and without changing behaviour on the valid path.\n\nDiscovered by XBOW, triaged by Baul Lee \u003cbaul.lee@xbow.com\u003e"
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T15:12:52.980Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/465544b3d6602cfbdc2305d5cbfb7f4954353b63"
},
{
"url": "https://git.kernel.org/stable/c/4993e1ab85d7d3f4a40d81852170f9665483bbd8"
},
{
"url": "https://git.kernel.org/stable/c/313ead1abed945544703b100a12c5a10fdf78409"
},
{
"url": "https://git.kernel.org/stable/c/c1d9c16af51cc6ff92a5a062617d3b022dd01078"
},
{
"url": "https://git.kernel.org/stable/c/a38212687519f2a72f43e62dec1348a690412404"
},
{
"url": "https://git.kernel.org/stable/c/9a1d7c5f0d82e8665715d5e47c9410c6a97e3748"
},
{
"url": "https://git.kernel.org/stable/c/5215ea00a747eca34cb2f603cfef91fef76c2558"
},
{
"url": "https://git.kernel.org/stable/c/cbcc0e8dea499e5ca86b583372ccb1815cccc570"
},
{
"url": "https://git.kernel.org/stable/c/a13cdb19fcb223ed41bdab3bab42b98dba87e90b"
}
],
"title": "HID: core: fix OOB read of field-\u003eusage in hid_set_field()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80781",
"datePublished": "2026-09-04T15:12:52.980Z",
"dateReserved": "2026-08-26T14:34:25.792Z",
"dateUpdated": "2026-09-04T15:12:52.980Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68189 (GCVE-0-2026-68189)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci_sync: Protect UUID list traversal
The hci_sync conversion moved class-of-device and EIR generation from an
HCI request built under hdev->lock to asynchronous command sync work.
The worker holds hdev->req_lock, but that lock does not serialize access
to hdev->uuids against add_uuid() and remove_uuid(), which update the
list under hdev->lock.
The following interleaving can therefore occur:
CPU0 (command sync work) CPU1 (management socket)
fetch uuid from the list
list_del(&uuid->list)
kfree(uuid)
read uuid->size
KASAN reports the resulting use-after-free:
BUG: KASAN: slab-use-after-free in eir_create+0xb8f/0xee0
Read of size 1 at addr ffff88810dbd8620 by task kworker/u17:0/87
Workqueue: hci0 hci_cmd_sync_work
Call Trace:
eir_create+0xb8f/0xee0
hci_update_eir_sync+0x1c0/0x330
hci_cmd_sync_work+0x13c/0x290
process_one_work+0x63a/0x1070
worker_thread+0x45b/0xd10
Allocated by task 86:
__kasan_kmalloc+0x8f/0xa0
add_uuid+0x18a/0x4b0
hci_sock_sendmsg+0x1033/0x1ea0
Freed by task 92:
__kasan_slab_free+0x43/0x70
kfree+0x131/0x3c0
remove_uuid+0x25e/0x560
hci_sock_sendmsg+0x1033/0x1ea0
Hold hdev->lock while generating and committing the class-of-device and
EIR snapshots. Release it before sending an HCI command, so controller
waits do not happen under the device lock. This protects all UUID list
walks in these paths and restores the serialization lost in the command
sync conversion.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 161510ccf91c961638940b03abb1ee804be53a97 Version: 161510ccf91c961638940b03abb1ee804be53a97 Version: 161510ccf91c961638940b03abb1ee804be53a97 Version: 161510ccf91c961638940b03abb1ee804be53a97 Version: 161510ccf91c961638940b03abb1ee804be53a97 Version: 161510ccf91c961638940b03abb1ee804be53a97 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/bluetooth/hci_sync.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "30bc6248f035a792d1b1f4cc761b32fd5827b55f",
"status": "affected",
"version": "161510ccf91c961638940b03abb1ee804be53a97",
"versionType": "git"
},
{
"lessThan": "e4fa2c5c261d736b8e58759fdef3a968d510630c",
"status": "affected",
"version": "161510ccf91c961638940b03abb1ee804be53a97",
"versionType": "git"
},
{
"lessThan": "a351f68fb24828b23a971e00b8238ee0e8a40380",
"status": "affected",
"version": "161510ccf91c961638940b03abb1ee804be53a97",
"versionType": "git"
},
{
"lessThan": "a42f5536ea9c00e13f0c0fbb330feed95e2365ca",
"status": "affected",
"version": "161510ccf91c961638940b03abb1ee804be53a97",
"versionType": "git"
},
{
"lessThan": "fe13adc258df88d95789e5673c7ba5178b5f8b28",
"status": "affected",
"version": "161510ccf91c961638940b03abb1ee804be53a97",
"versionType": "git"
},
{
"lessThan": "e9027ffbf5a0f3c12ca8900822e884eae9f0821b",
"status": "affected",
"version": "161510ccf91c961638940b03abb1ee804be53a97",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/bluetooth/hci_sync.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.17"
},
{
"lessThan": "5.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.17",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_sync: Protect UUID list traversal\n\nThe hci_sync conversion moved class-of-device and EIR generation from an\nHCI request built under hdev-\u003elock to asynchronous command sync work.\nThe worker holds hdev-\u003ereq_lock, but that lock does not serialize access\nto hdev-\u003euuids against add_uuid() and remove_uuid(), which update the\nlist under hdev-\u003elock.\n\nThe following interleaving can therefore occur:\n\n CPU0 (command sync work) CPU1 (management socket)\n fetch uuid from the list\n list_del(\u0026uuid-\u003elist)\n kfree(uuid)\n read uuid-\u003esize\n\nKASAN reports the resulting use-after-free:\n\n BUG: KASAN: slab-use-after-free in eir_create+0xb8f/0xee0\n Read of size 1 at addr ffff88810dbd8620 by task kworker/u17:0/87\n Workqueue: hci0 hci_cmd_sync_work\n Call Trace:\n eir_create+0xb8f/0xee0\n hci_update_eir_sync+0x1c0/0x330\n hci_cmd_sync_work+0x13c/0x290\n process_one_work+0x63a/0x1070\n worker_thread+0x45b/0xd10\n\n Allocated by task 86:\n __kasan_kmalloc+0x8f/0xa0\n add_uuid+0x18a/0x4b0\n hci_sock_sendmsg+0x1033/0x1ea0\n\n Freed by task 92:\n __kasan_slab_free+0x43/0x70\n kfree+0x131/0x3c0\n remove_uuid+0x25e/0x560\n hci_sock_sendmsg+0x1033/0x1ea0\n\nHold hdev-\u003elock while generating and committing the class-of-device and\nEIR snapshots. Release it before sending an HCI command, so controller\nwaits do not happen under the device lock. This protects all UUID list\nwalks in these paths and restores the serialization lost in the command\nsync conversion."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires concurrent MGMT_OP_ADD_UUID/MGMT_REMOVE_UUID commands through a local AF_BLUETOOTH HCI management socket (hci_sock_sendmsg), not reception of over-the-air Bluetooth protocol traffic from a remote peer.\nAC:L - The attacker controls both sides of the race by issuing concurrent management socket commands from threads or processes they own; KASAN shows reliable interleaving between hci_cmd_sync_work and remove_uuid without attacker-uncontrollable timing or memory layout.\nPR:L - MGMT_OP_ADD_UUID and MGMT_OP_REMOVE_UUID require HCI_SOCK_TRUSTED, set only when the socket binder holds CAP_NET_ADMIN; per kernel CNA guidance CAP_NET_ADMIN reachable via user namespaces (unshare -Urn) maps to PR:L, not PR:H.\nUI:N - No victim interaction is required; the attacker directly issues local management commands that queue hci_cmd_sync_work and concurrently modify the UUID list to trigger the use-after-free.\nS:U - The vulnerability causes kernel heap corruption and local privilege escalation within the same host security authority; it does not cross VM, container, or IOMMU security boundaries.\nC:H - KASAN-confirmed slab use-after-free reading freed bt_uuid fields (uuid-\u003esize and uuid data) during eir_create traversal enables arbitrary kernel memory disclosure via heap spraying and reuse of freed kmalloc objects.\nI:H - Slab UAF on bt_uuid during list traversal enables attacker-controlled reallocation of freed objects, providing heap corruption primitives that can be leveraged for arbitrary kernel writes and control-flow hijacking.\nA:H - The confirmed use-after-free in eir_create on the hci_cmd_sync_work path causes kernel oops or panic; repeated concurrent add/remove UUID operations can reliably crash or hang the system."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:01.944Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/30bc6248f035a792d1b1f4cc761b32fd5827b55f"
},
{
"url": "https://git.kernel.org/stable/c/e4fa2c5c261d736b8e58759fdef3a968d510630c"
},
{
"url": "https://git.kernel.org/stable/c/a351f68fb24828b23a971e00b8238ee0e8a40380"
},
{
"url": "https://git.kernel.org/stable/c/a42f5536ea9c00e13f0c0fbb330feed95e2365ca"
},
{
"url": "https://git.kernel.org/stable/c/fe13adc258df88d95789e5673c7ba5178b5f8b28"
},
{
"url": "https://git.kernel.org/stable/c/e9027ffbf5a0f3c12ca8900822e884eae9f0821b"
}
],
"title": "Bluetooth: hci_sync: Protect UUID list traversal",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68189",
"datePublished": "2026-08-10T12:00:01.711Z",
"dateReserved": "2026-07-30T09:28:09.373Z",
"dateUpdated": "2026-08-19T16:31:01.944Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72170 (GCVE-0-2026-72170)
Vulnerability from cvelistv5
Published
2026-08-15 05:53
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
9p: skip nlink update in cacheless mode to fix WARN_ON
v9fs_dec_count() unconditionally calls drop_nlink() on regular files,
even when the inode's nlink is already zero. In cacheless mode the
client refetches inode metadata from the server (the source of truth)
on every operation, so by the time v9fs_remove() returns, the locally
cached nlink may already reflect the post-unlink value:
1. Client initiates unlink, server processes it and sets nlink to 0
2. Client refetches inode metadata (nlink=0) before unlink returns
3. Client's v9fs_remove() completes successfully
4. Client calls v9fs_dec_count() which calls drop_nlink() on nlink=0
This race is easily triggered under heavy unlink workloads, such as
stress-ng's unlink stressor, producing the following warning:
WARNING: fs/inode.c:417 at drop_nlink+0x4c/0xc8
Call trace:
drop_nlink+0x4c/0xc8
v9fs_remove+0x1e0/0x250 [9p]
v9fs_vfs_unlink+0x20/0x38 [9p]
vfs_unlink+0x13c/0x258
...
In cacheless mode the server is authoritative and the inode is on its
way out, so locally adjusting nlink buys nothing. Skip v9fs_dec_count()
entirely when neither CACHE_META nor CACHE_LOOSE is set, which both
avoids the warning and removes a class of nlink races (two concurrent
unlinkers observing nlink > 0 and both calling drop_nlink()) that an
nlink == 0 guard alone would only narrow rather than close.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ac89b2ef9b55924bcf922251f043ba73a32d05bb Version: ac89b2ef9b55924bcf922251f043ba73a32d05bb Version: ac89b2ef9b55924bcf922251f043ba73a32d05bb Version: ac89b2ef9b55924bcf922251f043ba73a32d05bb Version: ac89b2ef9b55924bcf922251f043ba73a32d05bb Version: ac89b2ef9b55924bcf922251f043ba73a32d05bb Version: ac89b2ef9b55924bcf922251f043ba73a32d05bb Version: ac89b2ef9b55924bcf922251f043ba73a32d05bb |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/9p/vfs_inode.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "6086469f7d469549bfd070348b717a6e43736200",
"status": "affected",
"version": "ac89b2ef9b55924bcf922251f043ba73a32d05bb",
"versionType": "git"
},
{
"lessThan": "ab257019cb72f467b55c95384d99c94e3908b928",
"status": "affected",
"version": "ac89b2ef9b55924bcf922251f043ba73a32d05bb",
"versionType": "git"
},
{
"lessThan": "4ec4ebe40c82cb4c60756732f6593055d010c59c",
"status": "affected",
"version": "ac89b2ef9b55924bcf922251f043ba73a32d05bb",
"versionType": "git"
},
{
"lessThan": "a5a682b016ef5b5384e28f6d652d47a8f8e73d37",
"status": "affected",
"version": "ac89b2ef9b55924bcf922251f043ba73a32d05bb",
"versionType": "git"
},
{
"lessThan": "de79c3f3643841b8659a71958df7cf2a66bfd409",
"status": "affected",
"version": "ac89b2ef9b55924bcf922251f043ba73a32d05bb",
"versionType": "git"
},
{
"lessThan": "8d610017c992de705b304d3d727a6e3a86af6149",
"status": "affected",
"version": "ac89b2ef9b55924bcf922251f043ba73a32d05bb",
"versionType": "git"
},
{
"lessThan": "8faccac11e1369adddf5d80f4a45af93f13b2e1a",
"status": "affected",
"version": "ac89b2ef9b55924bcf922251f043ba73a32d05bb",
"versionType": "git"
},
{
"lessThan": "574aa0b4799470ac814479f1138d19efe6262255",
"status": "affected",
"version": "ac89b2ef9b55924bcf922251f043ba73a32d05bb",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/9p/vfs_inode.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.17"
},
{
"lessThan": "4.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.17",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\n9p: skip nlink update in cacheless mode to fix WARN_ON\n\nv9fs_dec_count() unconditionally calls drop_nlink() on regular files,\neven when the inode\u0027s nlink is already zero. In cacheless mode the\nclient refetches inode metadata from the server (the source of truth)\non every operation, so by the time v9fs_remove() returns, the locally\ncached nlink may already reflect the post-unlink value:\n\n 1. Client initiates unlink, server processes it and sets nlink to 0\n 2. Client refetches inode metadata (nlink=0) before unlink returns\n 3. Client\u0027s v9fs_remove() completes successfully\n 4. Client calls v9fs_dec_count() which calls drop_nlink() on nlink=0\n\nThis race is easily triggered under heavy unlink workloads, such as\nstress-ng\u0027s unlink stressor, producing the following warning:\n\n WARNING: fs/inode.c:417 at drop_nlink+0x4c/0xc8\n Call trace:\n drop_nlink+0x4c/0xc8\n v9fs_remove+0x1e0/0x250 [9p]\n v9fs_vfs_unlink+0x20/0x38 [9p]\n vfs_unlink+0x13c/0x258\n ...\n\nIn cacheless mode the server is authoritative and the inode is on its\nway out, so locally adjusting nlink buys nothing. Skip v9fs_dec_count()\nentirely when neither CACHE_META nor CACHE_LOOSE is set, which both\navoids the warning and removes a class of nlink races (two concurrent\nunlinkers observing nlink \u003e 0 and both calling drop_nlink()) that an\nnlink == 0 guard alone would only narrow rather than close."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Triggered via unlink/rmdir/rename syscalls on a mounted 9p client filesystem (default cacheless mode). Common in QEMU/KVM virtio-9p guest shares and TCP-mounted exports; requires code execution on the client host, not direct remote packet delivery to this kernel path.\nAC:L - The fix commit states the race is easily triggered under heavy unlink workloads (e.g., stress-ng). An attacker can drive concurrent unlinks or getattr/unlink on the same inode to refresh server nlink=0 before drop_nlink(), controlling both sides of the race.\nPR:L - Exploitation requires only normal filesystem write permission on the 9p export (may_delete_dentry/inode_permission on the parent directory). Guest users on virtio-9p shares or tenants with write access do not need root/CAP_SYS_ADMIN beyond using an already-mounted filesystem.\nUI:N - No victim interaction is required beyond the attacker (or compromised local process) issuing unlink/rmdir/rename on paths they can already write; mounting 9p is an admin setup step, not per-exploit user action.\nS:U - The bug corrupts inode metadata in the 9p client kernel on the same host as the attacker process. It does not cross VM/host, container/host, or IOMMU security boundaries; virtio-9p guest triggers affect the guest kernel only.\nC:H - drop_nlink() on i_nlink==0 emits WARN_ON then underflows the unsigned link counter to UINT_MAX, corrupting kernel inode metadata. Per kernel CVSS guidance, memory/metadata corruption that could be leveraged for further exploitation warrants High confidentiality.\nI:H - Unsigned i_nlink underflow corrupts inode lifecycle accounting, preventing correct removal tracking (s_remove_count) and desynchronizing dentry unlink from inode state. This class of VFS inode corruption can enable further integrity violations and is scored High when uncertain.\nA:H - Each hit triggers kernel WARN_ON (easily spammed for denial-of-service via log flooding, and fatal where panic_on_warn is enabled) and leaves inodes with bogus nlink values that can provoke subsequent kernel faults during VFS operations on affected files."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:59.271Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/6086469f7d469549bfd070348b717a6e43736200"
},
{
"url": "https://git.kernel.org/stable/c/ab257019cb72f467b55c95384d99c94e3908b928"
},
{
"url": "https://git.kernel.org/stable/c/4ec4ebe40c82cb4c60756732f6593055d010c59c"
},
{
"url": "https://git.kernel.org/stable/c/a5a682b016ef5b5384e28f6d652d47a8f8e73d37"
},
{
"url": "https://git.kernel.org/stable/c/de79c3f3643841b8659a71958df7cf2a66bfd409"
},
{
"url": "https://git.kernel.org/stable/c/8d610017c992de705b304d3d727a6e3a86af6149"
},
{
"url": "https://git.kernel.org/stable/c/8faccac11e1369adddf5d80f4a45af93f13b2e1a"
},
{
"url": "https://git.kernel.org/stable/c/574aa0b4799470ac814479f1138d19efe6262255"
}
],
"title": "9p: skip nlink update in cacheless mode to fix WARN_ON",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72170",
"datePublished": "2026-08-15T05:53:36.332Z",
"dateReserved": "2026-08-09T03:40:39.910Z",
"dateUpdated": "2026-08-23T12:46:59.271Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68388 (GCVE-0-2026-68388)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
smb/client: handle overlapping allocated ranges in fallocate
smb3_simple_fallocate_range() can skip holes when an allocated range
returned by the server starts before the current fallocate offset. The
skipped hole is not zero-filled, but fallocate still returns success. A
later write to that hole may therefore fail with ENOSPC.
The function queries allocated ranges so that it can preserve existing
contents and write zeroes only into holes. However, the server may return
a range that starts before the current fallocate offset.
For example, assume the fallocate request is [100, 400) and the only
allocated range returned by the server is [0, 200):
Request: [100, 400)
Server range: [ 0, 200) allocated
Correct:
[100, 200) allocated data, skip
[200, 400) hole, zero-fill
Current:
[100, 300) skipped
[300, 400) zero-filled afterwards
The current code adds the full server range length, 200, to the current
offset 100 and moves to 300. As a result, the hole in [200, 300) is
skipped without being zero-filled.
Fix this by advancing only over the part of the allocated range that
overlaps the current fallocate offset. Ignore ranges that end before the
current offset and reject ranges whose end offset overflows.
This also prevents a malformed range length from causing an out-of-bounds
zero-buffer read.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: c406bb9ece6ef63721daab106f132ff4b4234e81 Version: 966a3cb7c7db786452a87afdc3b48858fc4d4d6b Version: 966a3cb7c7db786452a87afdc3b48858fc4d4d6b Version: 966a3cb7c7db786452a87afdc3b48858fc4d4d6b Version: 966a3cb7c7db786452a87afdc3b48858fc4d4d6b Version: 966a3cb7c7db786452a87afdc3b48858fc4d4d6b Version: 966a3cb7c7db786452a87afdc3b48858fc4d4d6b Version: 966a3cb7c7db786452a87afdc3b48858fc4d4d6b Version: 2f9f4a2d0e6fcf0673ed51195e06e47abe966900 Version: 5e397c943424de94879830e72c95f2679e297a76 Version: 5.10.50 ≤ Version: 5.12.17 ≤ Version: 5.13.2 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/smb/client/smb2ops.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "aeb58a4eb39a7ff4d7782b4f4ada0fda5e0675d2",
"status": "affected",
"version": "c406bb9ece6ef63721daab106f132ff4b4234e81",
"versionType": "git"
},
{
"lessThan": "01719883235507b1585e4c51e320d9a7113dc698",
"status": "affected",
"version": "966a3cb7c7db786452a87afdc3b48858fc4d4d6b",
"versionType": "git"
},
{
"lessThan": "f47c7277c03a636fcc3a57969f2dc09567b3c050",
"status": "affected",
"version": "966a3cb7c7db786452a87afdc3b48858fc4d4d6b",
"versionType": "git"
},
{
"lessThan": "437637f5ff3f573b2edf8571de91fb00a21eb4e6",
"status": "affected",
"version": "966a3cb7c7db786452a87afdc3b48858fc4d4d6b",
"versionType": "git"
},
{
"lessThan": "377fe3e583e46369ee1004d5cfe12271d6589a68",
"status": "affected",
"version": "966a3cb7c7db786452a87afdc3b48858fc4d4d6b",
"versionType": "git"
},
{
"lessThan": "7e08ab7a061b17ac1989a225c6afb53f44a86808",
"status": "affected",
"version": "966a3cb7c7db786452a87afdc3b48858fc4d4d6b",
"versionType": "git"
},
{
"lessThan": "a4a09e5142835633fffbde68bd0a039ba4d4bf97",
"status": "affected",
"version": "966a3cb7c7db786452a87afdc3b48858fc4d4d6b",
"versionType": "git"
},
{
"lessThan": "b09ae45d85dc816987a71db9eebc54b0ae288e94",
"status": "affected",
"version": "966a3cb7c7db786452a87afdc3b48858fc4d4d6b",
"versionType": "git"
},
{
"status": "affected",
"version": "2f9f4a2d0e6fcf0673ed51195e06e47abe966900",
"versionType": "git"
},
{
"status": "affected",
"version": "5e397c943424de94879830e72c95f2679e297a76",
"versionType": "git"
},
{
"lessThan": "5.10.265",
"status": "affected",
"version": "5.10.50",
"versionType": "semver"
},
{
"lessThan": "5.13",
"status": "affected",
"version": "5.12.17",
"versionType": "semver"
},
{
"lessThan": "5.14",
"status": "affected",
"version": "5.13.2",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/smb/client/smb2ops.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.14"
},
{
"lessThan": "5.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.10.50",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.12.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.13.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb/client: handle overlapping allocated ranges in fallocate\n\nsmb3_simple_fallocate_range() can skip holes when an allocated range\nreturned by the server starts before the current fallocate offset. The\nskipped hole is not zero-filled, but fallocate still returns success. A\nlater write to that hole may therefore fail with ENOSPC.\n\nThe function queries allocated ranges so that it can preserve existing\ncontents and write zeroes only into holes. However, the server may return\na range that starts before the current fallocate offset.\n\nFor example, assume the fallocate request is [100, 400) and the only\nallocated range returned by the server is [0, 200):\n\n Request: [100, 400)\n Server range: [ 0, 200) allocated\n\n Correct:\n [100, 200) allocated data, skip\n [200, 400) hole, zero-fill\n\n Current:\n [100, 300) skipped\n [300, 400) zero-filled afterwards\n\nThe current code adds the full server range length, 200, to the current\noffset 100 and moves to 300. As a result, the hole in [200, 300) is\nskipped without being zero-filled.\n\nFix this by advancing only over the part of the allocated range that\noverlaps the current fallocate offset. Ignore ranges that end before the\ncurrent offset and reject ranges whose end offset overflows.\n\nThis also prevents a malformed range length from causing an out-of-bounds\nzero-buffer read."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The malformed input is the FSCTL_QUERY_ALLOCATED_RANGES response parsed by the SMB client from a remote peer, so a malicious, compromised, or MITM\u0027d SMB server exploits this purely over the network (TCP/445) against the mounted client.\nAC:L - The server fully and deterministically controls the returned range file_offset/length fields; a single record with bit 63 set in length reliably inflates the loop\u0027s len past the 1 MB buffer with no race, timing, or memory-layout precondition.\nPR:N - The attacker is the remote SMB server (or a network MITM) and needs no account, credentials, or privileges on the victim client; only the pre-existing SMB session the client itself established is required.\nUI:N - Against an already-mounted share (fstab/autofs/systemd automount) a compromised or MITM\u0027d server needs no victim action, and fallocate/posix_fallocate is issued routinely by ordinary applications such as databases, VM images, and download managers.\nS:U - The out-of-bounds read, the corrupted write offsets, and the resulting crash all stay within the kernel of the client host; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - Because smb3_simple_fallocate_write_range() advances buf by every 64 KB chunk written, the inflated length walks far past the 1 MB kvzalloc\u0027d zero buffer and transmits adjacent kernel heap memory straight back to the attacker\u0027s server, yielding a large sequential kernel memory disclosure.\nI:H - The negative length drives off backwards and lets attacker-chosen offsets be zero-filled over ranges of the victim\u0027s file that hold real data, and the original defect makes fallocate report success while leaving holes unallocated, silently breaking the allocation guarantee applications rely on.\nA:H - The out-of-bounds read walks potentially gigabytes past the allocation and will fault on unmapped or guard pages, causing a kernel oops/panic, while the inflated length also drives an extremely long 64 KB-at-a-time write loop that stalls the caller."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:42.827Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/aeb58a4eb39a7ff4d7782b4f4ada0fda5e0675d2"
},
{
"url": "https://git.kernel.org/stable/c/01719883235507b1585e4c51e320d9a7113dc698"
},
{
"url": "https://git.kernel.org/stable/c/f47c7277c03a636fcc3a57969f2dc09567b3c050"
},
{
"url": "https://git.kernel.org/stable/c/437637f5ff3f573b2edf8571de91fb00a21eb4e6"
},
{
"url": "https://git.kernel.org/stable/c/377fe3e583e46369ee1004d5cfe12271d6589a68"
},
{
"url": "https://git.kernel.org/stable/c/7e08ab7a061b17ac1989a225c6afb53f44a86808"
},
{
"url": "https://git.kernel.org/stable/c/a4a09e5142835633fffbde68bd0a039ba4d4bf97"
},
{
"url": "https://git.kernel.org/stable/c/b09ae45d85dc816987a71db9eebc54b0ae288e94"
}
],
"title": "smb/client: handle overlapping allocated ranges in fallocate",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68388",
"datePublished": "2026-08-10T12:04:07.304Z",
"dateReserved": "2026-07-30T09:28:09.388Z",
"dateUpdated": "2026-08-19T16:34:42.827Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74522 (GCVE-0-2026-74522)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-19 16:38
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix use-after-free in __close_file_table_ids()
A ksmbd_file can remain alive after logical close while another session
holds a temporary reference obtained through ksmbd_lookup_fd_inode().
ksmbd_close_fd() currently marks the file closed and drops the idr-owned
reference, but leaves the pointer published in the closing session's idr
until the final reference is dropped.
If the foreign holder performs the final ksmbd_fd_put(), __put_fd_final()
supplies the foreign session's file table to __ksmbd_close_fd(). The object
is then freed without being removed from its owner's idr, and the owner
session later dereferences the stale pointer during file-table teardown.
Remove the volatile id from the owner's idr while ksmbd_close_fd() still
holds that table's lock, and clear volatile_id before dropping
the idr-owned reference. A later foreign final put then only performs
physical destruction and cannot remove the object from the wrong table.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 8510a043d334ecdf83d4604782f288db6bf21d60 Version: 8510a043d334ecdf83d4604782f288db6bf21d60 Version: 8510a043d334ecdf83d4604782f288db6bf21d60 Version: 8510a043d334ecdf83d4604782f288db6bf21d60 Version: 8510a043d334ecdf83d4604782f288db6bf21d60 Version: 8510a043d334ecdf83d4604782f288db6bf21d60 Version: df30cbfd3d8a70e61ce59f63ce5ed2261799ac10 Version: aaf1d5ebb358f546414965b39da90107a7ca7ce5 Version: 5.15.38 ≤ Version: 5.17.6 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/smb/server/vfs_cache.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "19bfd90d5aaf63217735d81964585c5306158e5f",
"status": "affected",
"version": "8510a043d334ecdf83d4604782f288db6bf21d60",
"versionType": "git"
},
{
"lessThan": "67aaec2a1fdce3e1dde46c45b5d1ef8cf22f65cd",
"status": "affected",
"version": "8510a043d334ecdf83d4604782f288db6bf21d60",
"versionType": "git"
},
{
"lessThan": "0c3918c2cee62ec6c9de8d5c73ebfe6f833961ac",
"status": "affected",
"version": "8510a043d334ecdf83d4604782f288db6bf21d60",
"versionType": "git"
},
{
"lessThan": "9be4a66f019ea90bd9deca70511f4f9ffebf5c6f",
"status": "affected",
"version": "8510a043d334ecdf83d4604782f288db6bf21d60",
"versionType": "git"
},
{
"lessThan": "cffbdc86393b0235383a20c8c59bc32f16036459",
"status": "affected",
"version": "8510a043d334ecdf83d4604782f288db6bf21d60",
"versionType": "git"
},
{
"lessThan": "e7188199eff46a636f3436356f0aae039be6dd66",
"status": "affected",
"version": "8510a043d334ecdf83d4604782f288db6bf21d60",
"versionType": "git"
},
{
"status": "affected",
"version": "df30cbfd3d8a70e61ce59f63ce5ed2261799ac10",
"versionType": "git"
},
{
"status": "affected",
"version": "aaf1d5ebb358f546414965b39da90107a7ca7ce5",
"versionType": "git"
},
{
"lessThan": "5.16",
"status": "affected",
"version": "5.15.38",
"versionType": "semver"
},
{
"lessThan": "5.18",
"status": "affected",
"version": "5.17.6",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/smb/server/vfs_cache.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.18"
},
{
"lessThan": "5.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.15.38",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.17.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix use-after-free in __close_file_table_ids()\n\nA ksmbd_file can remain alive after logical close while another session\nholds a temporary reference obtained through ksmbd_lookup_fd_inode().\nksmbd_close_fd() currently marks the file closed and drops the idr-owned\nreference, but leaves the pointer published in the closing session\u0027s idr\nuntil the final reference is dropped.\n\nIf the foreign holder performs the final ksmbd_fd_put(), __put_fd_final()\nsupplies the foreign session\u0027s file table to __ksmbd_close_fd(). The object\nis then freed without being removed from its owner\u0027s idr, and the owner\nsession later dereferences the stale pointer during file-table teardown.\n\nRemove the volatile id from the owner\u0027s idr while ksmbd_close_fd() still\nholds that table\u0027s lock, and clear volatile_id before dropping\nthe idr-owned reference. A later foreign final put then only performs\nphysical destruction and cannot remove the object from the wrong table."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug is in ksmbd, the in-kernel SMB server reached remotely over TCP port 445 via SMB2 CREATE/CLOSE/SET_INFO rename and session teardown requests.\nAC:L - An attacker controls both sides of the race by issuing concurrent SMB2 CLOSE and rename operations on the same share, then logoff or disconnect; no victim-dependent timing or memory layout is required.\nPR:L - Exploitation requires a valid authenticated SMB session and share access to open, close, and rename files; it is not reachable on pre-authentication negotiate/echo paths.\nUI:N - No end-user action is required beyond the attacker driving SMB protocol operations on their own client connection(s).\nS:U - Impact is confined to kernel memory corruption and privilege escalation on the SMB server host; it does not cross a VM, container, or IOMMU security boundary.\nC:H - Use-after-free of a freed ksmbd_file slab object during session file-table teardown enables reading attacker-influenced heap contents and building arbitrary kernel memory read primitives.\nI:H - The UAF corrupts kernel heap metadata and ksmbd_file fields (pointers, list heads), enabling heap grooming and arbitrary write or control-flow hijack for code execution as root.\nA:H - The stale IDR entry is dereferenced during __close_file_table_ids() on logoff, tree disconnect, or connection teardown, causing kernel oops/panic and repeatable remote denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:38:25.036Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/19bfd90d5aaf63217735d81964585c5306158e5f"
},
{
"url": "https://git.kernel.org/stable/c/67aaec2a1fdce3e1dde46c45b5d1ef8cf22f65cd"
},
{
"url": "https://git.kernel.org/stable/c/0c3918c2cee62ec6c9de8d5c73ebfe6f833961ac"
},
{
"url": "https://git.kernel.org/stable/c/9be4a66f019ea90bd9deca70511f4f9ffebf5c6f"
},
{
"url": "https://git.kernel.org/stable/c/cffbdc86393b0235383a20c8c59bc32f16036459"
},
{
"url": "https://git.kernel.org/stable/c/e7188199eff46a636f3436356f0aae039be6dd66"
}
],
"title": "ksmbd: fix use-after-free in __close_file_table_ids()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74522",
"datePublished": "2026-08-15T12:27:39.945Z",
"dateReserved": "2026-08-15T05:44:03.911Z",
"dateUpdated": "2026-08-19T16:38:25.036Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74641 (GCVE-0-2026-74641)
Vulnerability from cvelistv5
Published
2026-08-22 15:32
Modified
2026-08-25 05:41
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ALSA: usx2y: bound the hwdep mmap fault offset
snd_us428ctls_vm_fault() turns the faulting page offset into a kernel
address with no bound of any kind:
offset = vmf->pgoff << PAGE_SHIFT;
vaddr = (char *)(...)->us428ctls_sharedmem + offset;
page = virt_to_page(vaddr);
get_page(page);
vmf->page = page;
return 0;
snd_us428ctls_mmap() checks only the length of the mapping, never the
offset, and us428ctls_sharedmem is a single page from
alloc_pages_exact(). For a character device file_mmap_size_max()
returns ULONG_MAX, so the mm layer imposes no ceiling either. Every page
offset above zero resolves to a struct page outside the object, and the
handler installs it into the caller's address space read-write; the vma
is not marked read-only.
The caller picks the page frame with a single mmap() argument and gets
read-write access to a page of kernel memory it does not own; an offset
that lands in an unpopulated vmemmap region oopses instead.
A process that can open the hwdep node of an attached US-X2Y reaches
this after loading the FPGA image through the same node; no capability
check is involved.
On 7.2.0-rc5 (arm64), mmap() with a large offset:
Unable to handle kernel paging request at virtual address fffffdffc45d5ac8
pc : snd_us428ctls_vm_fault+0x68/0x140 [snd_usb_usx2y]
Call trace:
snd_us428ctls_vm_fault+0x68/0x140 [snd_usb_usx2y]
__do_fault
__handle_mm_fault
handle_mm_fault
el0_da
Reject any offset outside the shared region. The pcm hwdep handler in
usx2yhwdeppcm.c computes its address the same way and needs the same
bound.
Discovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"sound/usb/usx2y/usX2Yhwdep.c",
"sound/usb/usx2y/usx2yhwdeppcm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ad6fedea65c6e90eda00d716c8bf20cdc437ed10",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "10a87401fb3148c388e55df0148295b3b137da07",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "34ab56ed854baa73a731cfd99af689f0b1bac444",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "4208db2453e1ea71b8048a5b7802360cb29a53f1",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "f613b4a2d87247b51a1b2b330f2e083a454125f2",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "f75d6f61f0d9c5c1ea725104014e10d26d1e3a00",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "5bf5ccddf00b59f1e3ea7e65d76a5f5b5c21cc2e",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "2ca1eea3cd17930daffe9e429a7c89232036ec24",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"sound/usb/usx2y/usX2Yhwdep.c",
"sound/usb/usx2y/usx2yhwdeppcm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: usx2y: bound the hwdep mmap fault offset\n\nsnd_us428ctls_vm_fault() turns the faulting page offset into a kernel\naddress with no bound of any kind:\n\n\toffset = vmf-\u003epgoff \u003c\u003c PAGE_SHIFT;\n\tvaddr = (char *)(...)-\u003eus428ctls_sharedmem + offset;\n\tpage = virt_to_page(vaddr);\n\tget_page(page);\n\tvmf-\u003epage = page;\n\n\treturn 0;\n\nsnd_us428ctls_mmap() checks only the length of the mapping, never the\noffset, and us428ctls_sharedmem is a single page from\nalloc_pages_exact(). For a character device file_mmap_size_max()\nreturns ULONG_MAX, so the mm layer imposes no ceiling either. Every page\noffset above zero resolves to a struct page outside the object, and the\nhandler installs it into the caller\u0027s address space read-write; the vma\nis not marked read-only.\n\nThe caller picks the page frame with a single mmap() argument and gets\nread-write access to a page of kernel memory it does not own; an offset\nthat lands in an unpopulated vmemmap region oopses instead.\n\nA process that can open the hwdep node of an attached US-X2Y reaches\nthis after loading the FPGA image through the same node; no capability\ncheck is involved.\n\nOn 7.2.0-rc5 (arm64), mmap() with a large offset:\n\n Unable to handle kernel paging request at virtual address fffffdffc45d5ac8\n pc : snd_us428ctls_vm_fault+0x68/0x140 [snd_usb_usx2y]\n Call trace:\n snd_us428ctls_vm_fault+0x68/0x140 [snd_usb_usx2y]\n __do_fault\n __handle_mm_fault\n handle_mm_fault\n el0_da\n\nReject any offset outside the shared region. The pcm hwdep handler in\nusx2yhwdeppcm.c computes its address the same way and needs the same\nbound.\n\nDiscovered by XBOW, triaged by Baul Lee \u003cbaul.lee@xbow.com\u003e"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires local mmap() on the ALSA hwdep character device (/dev/snd/hwC*D*); the path is open\u2192SNDRV_HWDEP_IOCTL_DSP_LOAD\u2192mmap\u2192snd_us428ctls_vm_fault, with no network or remote packet handler involved.\nAC:L - The attacker fully controls the mmap() page offset (vmf-\u003epgoff); any offset beyond the single-page shared buffer deterministically maps an attacker-chosen kernel page read-write or oopses, with no race or uncontrollable memory-layout dependency.\nPR:L - The driver performs no capability checks on hwdep open, ioctl, or mmap; any unprivileged local user who can access the hwdep node (typically via the audio group on desktop distros) can reach the fault handler after loading the FPGA image.\nUI:N - All exploitation steps\u2014opening the hwdep node, loading FPGA firmware via DSP_LOAD ioctl, and mmap with a crafted offset\u2014are performed by the attacker; no discretionary victim action beyond the device being present in the environment is required.\nS:U - Impact is arbitrary read/write of host kernel memory leading to local privilege escalation within the same kernel security authority; it does not cross a VM, container, or IOMMU security boundary.\nC:H - Unbounded pgoff arithmetic maps arbitrary kernel struct pages into the attacker\u0027s address space; the VMA is not read-only, giving attacker-controlled read access to any reachable kernel page selected via the mmap offset.\nI:H - The same unbounded mmap fault path installs attacker-chosen kernel pages into a read-write userspace mapping, enabling arbitrary kernel memory writes and heap corruption primitives suitable for privilege escalation or code execution.\nA:H - Large mmap offsets dereference unpopulated vmemmap regions causing kernel paging faults and oops (demonstrated on arm64); arbitrary kernel page writes can also panic the system or destabilize the kernel."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:41:03.118Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ad6fedea65c6e90eda00d716c8bf20cdc437ed10"
},
{
"url": "https://git.kernel.org/stable/c/10a87401fb3148c388e55df0148295b3b137da07"
},
{
"url": "https://git.kernel.org/stable/c/34ab56ed854baa73a731cfd99af689f0b1bac444"
},
{
"url": "https://git.kernel.org/stable/c/4208db2453e1ea71b8048a5b7802360cb29a53f1"
},
{
"url": "https://git.kernel.org/stable/c/f613b4a2d87247b51a1b2b330f2e083a454125f2"
},
{
"url": "https://git.kernel.org/stable/c/f75d6f61f0d9c5c1ea725104014e10d26d1e3a00"
},
{
"url": "https://git.kernel.org/stable/c/5bf5ccddf00b59f1e3ea7e65d76a5f5b5c21cc2e"
},
{
"url": "https://git.kernel.org/stable/c/2ca1eea3cd17930daffe9e429a7c89232036ec24"
}
],
"title": "ALSA: usx2y: bound the hwdep mmap fault offset",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74641",
"datePublished": "2026-08-22T15:32:19.696Z",
"dateReserved": "2026-08-15T05:44:03.922Z",
"dateUpdated": "2026-08-25T05:41:03.118Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74664 (GCVE-0-2026-74664)
Vulnerability from cvelistv5
Published
2026-08-22 15:32
Modified
2026-08-22 15:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: openvswitch: reallocate update replies for mismatched IDs
ovs_flow_cmd_new() preallocates the optional reply skb before it takes
ovs_mutex and before it knows which existing flow will be updated.
That is normally fine because the skb is sized from the request flow
identifier. That identifier also becomes the inserted flow's identifier.
For updates, however, a request with a UFID may miss the UFID lookup and
then fall back to the flow key lookup. That lookup can legitimately find
an existing key-identified flow. UFIDs are optional and the flow key is
the primary identifier.
For echoed replies, ovs_flow_cmd_fill_info() writes the matched flow's
identifier, not the request identifier used for the preallocation. A short
request UFID can therefore leave too little room for the key identifier.
The fill can then fail with -EMSGSIZE and hit the BUG_ON(error < 0) in the
update path.
Once the update target has been resolved, reallocate the reply skb if the
matched flow needs a larger reply than the request identifier allowed. Do
this before replacing the actions so the request can still fail cleanly if
the rare extra allocation fails.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 74ed7ab9264c54471c7f057409d352052820d750 Version: 74ed7ab9264c54471c7f057409d352052820d750 Version: 74ed7ab9264c54471c7f057409d352052820d750 Version: 74ed7ab9264c54471c7f057409d352052820d750 Version: 74ed7ab9264c54471c7f057409d352052820d750 Version: 74ed7ab9264c54471c7f057409d352052820d750 Version: 74ed7ab9264c54471c7f057409d352052820d750 Version: 74ed7ab9264c54471c7f057409d352052820d750 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/openvswitch/datapath.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "bd8ca84d48cd9a4f6fc63df26512c55e1d339927",
"status": "affected",
"version": "74ed7ab9264c54471c7f057409d352052820d750",
"versionType": "git"
},
{
"lessThan": "00f987f066e802793a37dd2167459e67cf2cf2ec",
"status": "affected",
"version": "74ed7ab9264c54471c7f057409d352052820d750",
"versionType": "git"
},
{
"lessThan": "696a0b9435fce9cf4f1e9ba7f6afa6bee96c97fc",
"status": "affected",
"version": "74ed7ab9264c54471c7f057409d352052820d750",
"versionType": "git"
},
{
"lessThan": "87d0c0040b5d4b61de51ae39132c4c46709f2f77",
"status": "affected",
"version": "74ed7ab9264c54471c7f057409d352052820d750",
"versionType": "git"
},
{
"lessThan": "69f40ccf85074981340847d650a9cbf9adabfbbe",
"status": "affected",
"version": "74ed7ab9264c54471c7f057409d352052820d750",
"versionType": "git"
},
{
"lessThan": "23716dd9d8d46a5908536b73dc085e62f2b5c237",
"status": "affected",
"version": "74ed7ab9264c54471c7f057409d352052820d750",
"versionType": "git"
},
{
"lessThan": "20751193d83be2e9735d4faee71375691c09cd13",
"status": "affected",
"version": "74ed7ab9264c54471c7f057409d352052820d750",
"versionType": "git"
},
{
"lessThan": "5d1c224dd914579524a183a514c12b95095d12ce",
"status": "affected",
"version": "74ed7ab9264c54471c7f057409d352052820d750",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/openvswitch/datapath.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.0"
},
{
"lessThan": "4.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: openvswitch: reallocate update replies for mismatched IDs\n\novs_flow_cmd_new() preallocates the optional reply skb before it takes\novs_mutex and before it knows which existing flow will be updated.\n\nThat is normally fine because the skb is sized from the request flow\nidentifier. That identifier also becomes the inserted flow\u0027s identifier.\nFor updates, however, a request with a UFID may miss the UFID lookup and\nthen fall back to the flow key lookup. That lookup can legitimately find\nan existing key-identified flow. UFIDs are optional and the flow key is\nthe primary identifier.\n\nFor echoed replies, ovs_flow_cmd_fill_info() writes the matched flow\u0027s\nidentifier, not the request identifier used for the preallocation. A short\nrequest UFID can therefore leave too little room for the key identifier.\nThe fill can then fail with -EMSGSIZE and hit the BUG_ON(error \u003c 0) in the\nupdate path.\n\nOnce the update target has been resolved, reallocate the reply skb if the\nmatched flow needs a larger reply than the request identifier allowed. Do\nthis before replacing the actions so the request can still fail cleanly if\nthe rare extra allocation fails."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-22T15:32:36.616Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/bd8ca84d48cd9a4f6fc63df26512c55e1d339927"
},
{
"url": "https://git.kernel.org/stable/c/00f987f066e802793a37dd2167459e67cf2cf2ec"
},
{
"url": "https://git.kernel.org/stable/c/696a0b9435fce9cf4f1e9ba7f6afa6bee96c97fc"
},
{
"url": "https://git.kernel.org/stable/c/87d0c0040b5d4b61de51ae39132c4c46709f2f77"
},
{
"url": "https://git.kernel.org/stable/c/69f40ccf85074981340847d650a9cbf9adabfbbe"
},
{
"url": "https://git.kernel.org/stable/c/23716dd9d8d46a5908536b73dc085e62f2b5c237"
},
{
"url": "https://git.kernel.org/stable/c/20751193d83be2e9735d4faee71375691c09cd13"
},
{
"url": "https://git.kernel.org/stable/c/5d1c224dd914579524a183a514c12b95095d12ce"
}
],
"title": "net: openvswitch: reallocate update replies for mismatched IDs",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74664",
"datePublished": "2026-08-22T15:32:36.616Z",
"dateReserved": "2026-08-15T05:44:03.924Z",
"dateUpdated": "2026-08-22T15:32:36.616Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74455 (GCVE-0-2026-74455)
Vulnerability from cvelistv5
Published
2026-08-15 12:26
Modified
2026-08-19 16:36
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
can: peak_usb: validate uCAN receive record lengths
pcan_usb_fd_decode_buf() walks uCAN records packed in one USB
receive buffer.
Require each record to contain the fixed header for its type, and verify
CAN payload bytes before copying them into the skb.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 0a25e1f4f18566b750ebd3ae995af64e23111e63 Version: 0a25e1f4f18566b750ebd3ae995af64e23111e63 Version: 0a25e1f4f18566b750ebd3ae995af64e23111e63 Version: 0a25e1f4f18566b750ebd3ae995af64e23111e63 Version: 0a25e1f4f18566b750ebd3ae995af64e23111e63 Version: 0a25e1f4f18566b750ebd3ae995af64e23111e63 Version: 0a25e1f4f18566b750ebd3ae995af64e23111e63 Version: 0a25e1f4f18566b750ebd3ae995af64e23111e63 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/can/usb/peak_usb/pcan_usb_fd.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "276d989cd2dd88e2b7ab2c96fd10c86836b12781",
"status": "affected",
"version": "0a25e1f4f18566b750ebd3ae995af64e23111e63",
"versionType": "git"
},
{
"lessThan": "bf9d787b7e1ef59be19b35abca08194772deb97e",
"status": "affected",
"version": "0a25e1f4f18566b750ebd3ae995af64e23111e63",
"versionType": "git"
},
{
"lessThan": "89c92a8052698dbbd3652a77c04d02bbd74a3275",
"status": "affected",
"version": "0a25e1f4f18566b750ebd3ae995af64e23111e63",
"versionType": "git"
},
{
"lessThan": "6067c878e38d02a3d5c43497347e143f85c9064a",
"status": "affected",
"version": "0a25e1f4f18566b750ebd3ae995af64e23111e63",
"versionType": "git"
},
{
"lessThan": "2c8f08f3641a074da40acf05baa5a18ae2739260",
"status": "affected",
"version": "0a25e1f4f18566b750ebd3ae995af64e23111e63",
"versionType": "git"
},
{
"lessThan": "2427ef427bdd78d862c7c76597bfd9eda88b81f1",
"status": "affected",
"version": "0a25e1f4f18566b750ebd3ae995af64e23111e63",
"versionType": "git"
},
{
"lessThan": "d9c115948c3dd5fcc2d0245cec5eb76c098503c8",
"status": "affected",
"version": "0a25e1f4f18566b750ebd3ae995af64e23111e63",
"versionType": "git"
},
{
"lessThan": "93fcab2c6968446316bbb49548848df604d6346f",
"status": "affected",
"version": "0a25e1f4f18566b750ebd3ae995af64e23111e63",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/can/usb/peak_usb/pcan_usb_fd.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.0"
},
{
"lessThan": "4.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: peak_usb: validate uCAN receive record lengths\n\npcan_usb_fd_decode_buf() walks uCAN records packed in one USB\nreceive buffer.\n\nRequire each record to contain the fixed header for its type, and verify\nCAN payload bytes before copying them into the skb."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:36:48.775Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/276d989cd2dd88e2b7ab2c96fd10c86836b12781"
},
{
"url": "https://git.kernel.org/stable/c/bf9d787b7e1ef59be19b35abca08194772deb97e"
},
{
"url": "https://git.kernel.org/stable/c/89c92a8052698dbbd3652a77c04d02bbd74a3275"
},
{
"url": "https://git.kernel.org/stable/c/6067c878e38d02a3d5c43497347e143f85c9064a"
},
{
"url": "https://git.kernel.org/stable/c/2c8f08f3641a074da40acf05baa5a18ae2739260"
},
{
"url": "https://git.kernel.org/stable/c/2427ef427bdd78d862c7c76597bfd9eda88b81f1"
},
{
"url": "https://git.kernel.org/stable/c/d9c115948c3dd5fcc2d0245cec5eb76c098503c8"
},
{
"url": "https://git.kernel.org/stable/c/93fcab2c6968446316bbb49548848df604d6346f"
}
],
"title": "can: peak_usb: validate uCAN receive record lengths",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74455",
"datePublished": "2026-08-15T12:26:58.175Z",
"dateReserved": "2026-08-15T05:44:03.900Z",
"dateUpdated": "2026-08-19T16:36:48.775Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2024-46754 (GCVE-0-2024-46754)
Vulnerability from cvelistv5
Published
2024-09-18 07:12
Modified
2026-09-02 12:49
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
bpf: Remove tst_run from lwt_seg6local_prog_ops.
The syzbot reported that the lwt_seg6 related BPF ops can be invoked
via bpf_test_run() without without entering input_action_end_bpf()
first.
Martin KaFai Lau said that self test for BPF_PROG_TYPE_LWT_SEG6LOCAL
probably didn't work since it was introduced in commit 04d4b274e2a
("ipv6: sr: Add seg6local action End.BPF"). The reason is that the
per-CPU variable seg6_bpf_srh_states::srh is never assigned in the self
test case but each BPF function expects it.
Remove test_run for BPF_PROG_TYPE_LWT_SEG6LOCAL.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 004d4b274e2a1a895a0e5dc66158b90a7d463d44 Version: 004d4b274e2a1a895a0e5dc66158b90a7d463d44 Version: 004d4b274e2a1a895a0e5dc66158b90a7d463d44 Version: 004d4b274e2a1a895a0e5dc66158b90a7d463d44 Version: 004d4b274e2a1a895a0e5dc66158b90a7d463d44 Version: 004d4b274e2a1a895a0e5dc66158b90a7d463d44 |
||
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2024-46754",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-09-29T14:46:48.262114Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2024-09-29T14:47:03.068Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/core/filter.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ea3fae6984ba0f054550e4da22219489c12cd8d4",
"status": "affected",
"version": "004d4b274e2a1a895a0e5dc66158b90a7d463d44",
"versionType": "git"
},
{
"lessThan": "a675524cfbe88fd49c05ff8807a08646983e687c",
"status": "affected",
"version": "004d4b274e2a1a895a0e5dc66158b90a7d463d44",
"versionType": "git"
},
{
"lessThan": "b05c2e25a5c168dbb46b6f7fcb741fd4e4f3b54a",
"status": "affected",
"version": "004d4b274e2a1a895a0e5dc66158b90a7d463d44",
"versionType": "git"
},
{
"lessThan": "e217492f6fa2228ad703ee3006d8fc4e5969fbd4",
"status": "affected",
"version": "004d4b274e2a1a895a0e5dc66158b90a7d463d44",
"versionType": "git"
},
{
"lessThan": "9cd15511de7c619bbd0f54bb3f28e6e720ded5d6",
"status": "affected",
"version": "004d4b274e2a1a895a0e5dc66158b90a7d463d44",
"versionType": "git"
},
{
"lessThan": "c13fda93aca118b8e5cd202e339046728ee7dddb",
"status": "affected",
"version": "004d4b274e2a1a895a0e5dc66158b90a7d463d44",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/core/filter.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.18"
},
{
"lessThan": "4.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.269",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.220",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.187",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.156",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.10.*",
"status": "unaffected",
"version": "6.10.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "6.11",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.269",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.220",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.187",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.156",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.10.10",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.11",
"versionStartIncluding": "4.18",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Remove tst_run from lwt_seg6local_prog_ops.\n\nThe syzbot reported that the lwt_seg6 related BPF ops can be invoked\nvia bpf_test_run() without without entering input_action_end_bpf()\nfirst.\n\nMartin KaFai Lau said that self test for BPF_PROG_TYPE_LWT_SEG6LOCAL\nprobably didn\u0027t work since it was introduced in commit 04d4b274e2a\n(\"ipv6: sr: Add seg6local action End.BPF\"). The reason is that the\nper-CPU variable seg6_bpf_srh_states::srh is never assigned in the self\ntest case but each BPF function expects it.\n\nRemove test_run for BPF_PROG_TYPE_LWT_SEG6LOCAL."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The only entry point is the local `bpf(BPF_PROG_TEST_RUN)` syscall against a `BPF_PROG_TYPE_LWT_SEG6LOCAL` program fd; no packet ever reaches this path from the network, since real SRv6 traffic goes through `input_action_end_bpf()` which initializes the state correctly.\nAC:L - A single `BPF_PROG_TEST_RUN` calling `bpf_lwt_seg6_action(END_B6_ENCAP)` deterministically hits `dev_net(skb_dst(skb)-\u003edev)` with a NULL dst, with no race, no timing window and no layout luck; the UAF variant needs only ordinary heap grooming that the attacker fully drives by choosing `data_size_in` (slab cache), `srhoff` (offset) and CPU affinity.\nPR:L - `bpf_prog_test_run()` itself performs zero capability check \u2014 it only does `bpf_prog_get(attr-\u003etest.prog_fd)` \u2014 so any unprivileged local process that inherits or receives a seg6local program fd (fork/exec, `SCM_RIGHTS`, or a permissively-moded bpffs pin) can trigger it, and BPF tokens in 6.9+ deliberately delegate `CAP_BPF`/`CAP_NET_ADMIN` program loading to unprivileged users inside containers.\nUI:N - The attacker issues the `bpf()` syscalls entirely on their own; no victim action, mount, file open, or administrator step is involved at any point.\nS:U - The NULL dereference, out-of-bounds read and slab use-after-free all occur in kernel context within the same security authority the calling process already interacts with; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - The dangling per-CPU `srh_state-\u003esrh` lets `seg6_validate_srh()` walk TLVs through a freed, attacker-reclaimed slab object, and `seg6_do_srh_inline()`\u0027s `memmove(hdr, oldhdr, 40)` on a short test packet reads up to 40 bytes past `skb-\u003etail` which are then returned to userspace via `bpf_test_finish()`\u0027s `data_out`.\nI:H - `seg6_bpf_has_valid_srh()` executes `srh-\u003ehdrlen = (u8)(srh_state-\u003ehdrlen \u003e\u003e 3)` through the stale pointer, giving an attacker-valued one-byte write at an attacker-chosen offset inside a freed object in an attacker-selected kmalloc cache \u2014 a reclaim primitive suitable for corrupting length/flag fields of a sprayed victim structure and escalating.\nA:H - `bpf_lwt_seg6_action(END_B6_ENCAP)` reliably oopses the kernel on `dev_net(skb_dst(skb)-\u003edev)` because the test skb carries no dst, and post-`d1542d4ae4df` the same path also trips `lockdep_assert_held()`, which is a panic under `panic_on_warn`."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-02T12:49:13.346Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ea3fae6984ba0f054550e4da22219489c12cd8d4"
},
{
"url": "https://git.kernel.org/stable/c/a675524cfbe88fd49c05ff8807a08646983e687c"
},
{
"url": "https://git.kernel.org/stable/c/b05c2e25a5c168dbb46b6f7fcb741fd4e4f3b54a"
},
{
"url": "https://git.kernel.org/stable/c/e217492f6fa2228ad703ee3006d8fc4e5969fbd4"
},
{
"url": "https://git.kernel.org/stable/c/9cd15511de7c619bbd0f54bb3f28e6e720ded5d6"
},
{
"url": "https://git.kernel.org/stable/c/c13fda93aca118b8e5cd202e339046728ee7dddb"
}
],
"title": "bpf: Remove tst_run from lwt_seg6local_prog_ops.",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2024-46754",
"datePublished": "2024-09-18T07:12:13.780Z",
"dateReserved": "2024-09-11T15:12:18.270Z",
"dateUpdated": "2026-09-02T12:49:13.346Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72262 (GCVE-0-2026-72262)
Vulnerability from cvelistv5
Published
2026-08-15 05:54
Modified
2026-08-23 12:47
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get
The ipc_control_data buffer is allocated as kzalloc(max_size), where
max_size covers the entire struct sof_ipc_ctrl_data including its
flexible array payload. However, the bounds checks in bytes_ext_put
and _bytes_ext_get compared user data lengths against max_size
directly, ignoring that cdata->data sits at an offset of
sizeof(struct sof_ipc_ctrl_data) bytes into the allocation.
This allowed writing up to sizeof(struct sof_ipc_ctrl_data) bytes past
the end of the heap buffer from unprivileged userspace via the ALSA TLV
kcontrol interface, and similarly allowed over-reading adjacent heap
data on the get path.
Fix all bounds checks to subtract sizeof(*cdata) from max_size so they
reflect the actual space available at the cdata->data offset. Also fix
the error-path restore in bytes_ext_put which wrote to cdata->data
instead of cdata, causing the same overflow.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 67ec2a091630c28ea8d05db2bd7178a05b04b7e6 Version: 67ec2a091630c28ea8d05db2bd7178a05b04b7e6 Version: 67ec2a091630c28ea8d05db2bd7178a05b04b7e6 Version: 67ec2a091630c28ea8d05db2bd7178a05b04b7e6 Version: 67ec2a091630c28ea8d05db2bd7178a05b04b7e6 Version: 67ec2a091630c28ea8d05db2bd7178a05b04b7e6 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"sound/soc/sof/ipc3-control.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "af4b437a463ac0482ba705434a44da06783778e6",
"status": "affected",
"version": "67ec2a091630c28ea8d05db2bd7178a05b04b7e6",
"versionType": "git"
},
{
"lessThan": "1adde1941bba7b0d7104b86ed819d48d81cb0ad9",
"status": "affected",
"version": "67ec2a091630c28ea8d05db2bd7178a05b04b7e6",
"versionType": "git"
},
{
"lessThan": "eaa67e139c9217099e2a7b717aeeb46c65de3494",
"status": "affected",
"version": "67ec2a091630c28ea8d05db2bd7178a05b04b7e6",
"versionType": "git"
},
{
"lessThan": "121577383b5cf221e86581e0f2bcca4c66f17469",
"status": "affected",
"version": "67ec2a091630c28ea8d05db2bd7178a05b04b7e6",
"versionType": "git"
},
{
"lessThan": "f4933e1d11b97b6a0951648b7c3e53850e1b33a9",
"status": "affected",
"version": "67ec2a091630c28ea8d05db2bd7178a05b04b7e6",
"versionType": "git"
},
{
"lessThan": "fd46668d538993218eea19c6925c868ac0f2630c",
"status": "affected",
"version": "67ec2a091630c28ea8d05db2bd7178a05b04b7e6",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"sound/soc/sof/ipc3-control.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.18"
},
{
"lessThan": "5.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.18",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get\n\nThe ipc_control_data buffer is allocated as kzalloc(max_size), where\nmax_size covers the entire struct sof_ipc_ctrl_data including its\nflexible array payload. However, the bounds checks in bytes_ext_put\nand _bytes_ext_get compared user data lengths against max_size\ndirectly, ignoring that cdata-\u003edata sits at an offset of\nsizeof(struct sof_ipc_ctrl_data) bytes into the allocation.\n\nThis allowed writing up to sizeof(struct sof_ipc_ctrl_data) bytes past\nthe end of the heap buffer from unprivileged userspace via the ALSA TLV\nkcontrol interface, and similarly allowed over-reading adjacent heap\ndata on the get path.\n\nFix all bounds checks to subtract sizeof(*cdata) from max_size so they\nreflect the actual space available at the cdata-\u003edata offset. Also fix\nthe error-path restore in bytes_ext_put which wrote to cdata-\u003edata\ninstead of cdata, causing the same overflow."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires a local ioctl on /dev/snd/controlC* (SNDRV_CTL_IOCTL_TLV_WRITE/READ) through the ALSA control device; there is no network, adjacent-radio, or physical-bus attack surface for this SOF IPC3 kcontrol path.\nAC:L - On affected SOF IPC3 systems with topology bytes_ext controls, an attacker can deterministically trigger the bug by issuing TLV writes with header.length equal to max_size, causing copy_from_user/memcpy to overrun the kzalloc(max_size) buffer by sizeof(struct sof_ipc_ctrl_data).\nPR:L - The fix commit states the overflow is reachable from unprivileged userspace via ALSA TLV kcontrols; any local user who can open the sound control device (typically membership in the audio group on Linux, or an app with audio access on Android/ChromeOS) can reach the vulnerable code without real root.\nUI:N - Exploitation is performed entirely by the attacker issuing ALSA TLV ioctls against an existing bytes_ext kcontrol; no victim click, mount, or other interactive action beyond the attacker\u0027s own access to the sound control interface is required.\nS:U - The vulnerability corrupts kernel heap memory from a local userspace context and enables standard kernel privilege escalation or denial of service; it does not cross a VM, container, or IOMMU security boundary into a separate authority.\nC:H - The get path can copy_to_user up to sizeof(struct sof_ipc_ctrl_data) bytes beyond the allocated ipc_control_data buffer, leaking adjacent kernel heap contents; combined with the controllable overflow, this is an out-of-bounds read/memory corruption primitive consistent with arbitrary disclosure potential.\nI:H - The put path performs an out-of-bounds heap write of up to sizeof(struct sof_ipc_ctrl_data) bytes past the kzalloc(max_size) allocation (including via the err_restore memcpy), enabling heap metadata/object corruption that can be developed into arbitrary kernel write or code execution.\nA:H - Heap out-of-bounds writes of roughly 96 bytes into adjacent slab objects can corrupt kernel structures and trigger oops/panic or wedged audio/subsystem state; repeated TLV operations make denial of service reliably achievable even without full exploitation."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:47:11.302Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/af4b437a463ac0482ba705434a44da06783778e6"
},
{
"url": "https://git.kernel.org/stable/c/1adde1941bba7b0d7104b86ed819d48d81cb0ad9"
},
{
"url": "https://git.kernel.org/stable/c/eaa67e139c9217099e2a7b717aeeb46c65de3494"
},
{
"url": "https://git.kernel.org/stable/c/121577383b5cf221e86581e0f2bcca4c66f17469"
},
{
"url": "https://git.kernel.org/stable/c/f4933e1d11b97b6a0951648b7c3e53850e1b33a9"
},
{
"url": "https://git.kernel.org/stable/c/fd46668d538993218eea19c6925c868ac0f2630c"
}
],
"title": "ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72262",
"datePublished": "2026-08-15T05:54:49.635Z",
"dateReserved": "2026-08-09T03:40:39.915Z",
"dateUpdated": "2026-08-23T12:47:11.302Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72157 (GCVE-0-2026-72157)
Vulnerability from cvelistv5
Published
2026-08-15 05:53
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: thunderbolt: Fix frags[] overflow by bounding frame_count
tbnet_poll() assembles a multi-frame ThunderboltIP packet into one skb. The
first frame goes into the skb linear area and every further frame is added as
a page fragment.
skb_add_rx_frag(skb, skb_shinfo(skb)->nr_frags,
page, hdr_size, frame_size,
TBNET_RX_PAGE_SIZE - hdr_size);
A packet of frame_count frames therefore ends up with frame_count - 1
fragments. tbnet_check_frame() only bounds the peer supplied frame_count to
TBNET_RING_SIZE / 4 (64), which is far above MAX_SKB_FRAGS (17 by default). A
peer that sends a packet of 19 or more small frames pushes nr_frags past
MAX_SKB_FRAGS, so skb_add_rx_frag() writes past skb_shinfo()->frags[] and
corrupts memory after the shared info.
Tighten the start of packet bound to MAX_SKB_FRAGS + 1 so a packet can never
produce more fragments than frags[] can hold. This matches the recent skb
frags overflow fixes in other receive paths, for example f0813bcd2d9d ("net:
wwan: t7xx: fix potential skb->frags overflow in RX path") and 600dc40554dc
("net: usb: cdc-phonet: fix skb frags[] overflow in rx_complete()").
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: e69b6c02b4c3b8d03be7136f90dd9551ad5a5a5e Version: e69b6c02b4c3b8d03be7136f90dd9551ad5a5a5e Version: e69b6c02b4c3b8d03be7136f90dd9551ad5a5a5e Version: e69b6c02b4c3b8d03be7136f90dd9551ad5a5a5e Version: e69b6c02b4c3b8d03be7136f90dd9551ad5a5a5e Version: e69b6c02b4c3b8d03be7136f90dd9551ad5a5a5e Version: e69b6c02b4c3b8d03be7136f90dd9551ad5a5a5e Version: e69b6c02b4c3b8d03be7136f90dd9551ad5a5a5e |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/thunderbolt/main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "f96b3b35c622d565eff2438993e028d280163f5c",
"status": "affected",
"version": "e69b6c02b4c3b8d03be7136f90dd9551ad5a5a5e",
"versionType": "git"
},
{
"lessThan": "6262f51e09d8dc8b07599a9e4f03bd3989d13fff",
"status": "affected",
"version": "e69b6c02b4c3b8d03be7136f90dd9551ad5a5a5e",
"versionType": "git"
},
{
"lessThan": "569ba39b2d12995a29dc158e5b4de6e449278f30",
"status": "affected",
"version": "e69b6c02b4c3b8d03be7136f90dd9551ad5a5a5e",
"versionType": "git"
},
{
"lessThan": "2b3b4e5ff5a58ad32817824b0310e63908b12052",
"status": "affected",
"version": "e69b6c02b4c3b8d03be7136f90dd9551ad5a5a5e",
"versionType": "git"
},
{
"lessThan": "e27beb4536cbf1d59e2d8c2840e87d972aba906f",
"status": "affected",
"version": "e69b6c02b4c3b8d03be7136f90dd9551ad5a5a5e",
"versionType": "git"
},
{
"lessThan": "e5824d5b841d99a2bcdd4e2c256643293bbc22c1",
"status": "affected",
"version": "e69b6c02b4c3b8d03be7136f90dd9551ad5a5a5e",
"versionType": "git"
},
{
"lessThan": "fe6b606fbf0c3beb94ccf17fcf31d8c2138264e3",
"status": "affected",
"version": "e69b6c02b4c3b8d03be7136f90dd9551ad5a5a5e",
"versionType": "git"
},
{
"lessThan": "55d9895f89970501fe126d1026b586b04a224c27",
"status": "affected",
"version": "e69b6c02b4c3b8d03be7136f90dd9551ad5a5a5e",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/thunderbolt/main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.15"
},
{
"lessThan": "4.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "4.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: thunderbolt: Fix frags[] overflow by bounding frame_count\n\ntbnet_poll() assembles a multi-frame ThunderboltIP packet into one skb. The\nfirst frame goes into the skb linear area and every further frame is added as\na page fragment.\n\n\tskb_add_rx_frag(skb, skb_shinfo(skb)-\u003enr_frags,\n\t\t\tpage, hdr_size, frame_size,\n\t\t\tTBNET_RX_PAGE_SIZE - hdr_size);\n\nA packet of frame_count frames therefore ends up with frame_count - 1\nfragments. tbnet_check_frame() only bounds the peer supplied frame_count to\nTBNET_RING_SIZE / 4 (64), which is far above MAX_SKB_FRAGS (17 by default). A\npeer that sends a packet of 19 or more small frames pushes nr_frags past\nMAX_SKB_FRAGS, so skb_add_rx_frag() writes past skb_shinfo()-\u003efrags[] and\ncorrupts memory after the shared info.\n\nTighten the start of packet bound to MAX_SKB_FRAGS + 1 so a packet can never\nproduce more fragments than frags[] can hold. This matches the recent skb\nfrags overflow fixes in other receive paths, for example f0813bcd2d9d (\"net:\nwwan: t7xx: fix potential skb-\u003efrags overflow in RX path\") and 600dc40554dc\n(\"net: usb: cdc-phonet: fix skb frags[] overflow in rx_complete()\")."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The flaw is triggered by malicious ThunderboltIP frames sent from a peer on the same direct Thunderbolt/USB4 link; exploitation is not Internet-routable but is reachable from an adjacent connected host, dock, or peripheral without local syscall access.\nAC:L - An adjacent peer can reliably trigger the overflow by sending a start-of-packet header with frame_count of 19-64 and delivering the matching small frames; no races or attacker-uncontrollable heap layout are required.\nPR:N - The attacker needs no account, capability, or privilege on the victim OS; a malicious Thunderbolt/USB4 peer that completes XDomain ThunderboltIP login can send the crafted RX frames directly over the established DMA path.\nUI:N - Once a ThunderboltIP session is active, which is common with docks, direct laptop-to-laptop links, and shared workstations, triggering the bug requires no further victim action beyond the existing link.\nS:U - Memory corruption occurs in the kernel Thunderbolt network driver during skb reassembly and does not by itself cross a VM, container, or IOMMU security boundary.\nC:H - skb_add_rx_frag() writes past skb_shinfo()-\u003efrags[], corrupting adjacent kernel memory; such out-of-bounds skb metadata corruption is reasonably leverageable for information disclosure as well as further exploitation.\nI:H - The overflow is an attacker-controlled out-of-bounds write of skb fragment descriptors beyond MAX_SKB_FRAGS, which can corrupt heap/skb metadata and be developed into arbitrary kernel memory modification or code execution.\nA:H - Corrupting memory past skb_shared_info can cause kernel oopses, panics, or unstable behavior during RX processing, and repeated malicious packets can deny service on affected systems."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:55.998Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/f96b3b35c622d565eff2438993e028d280163f5c"
},
{
"url": "https://git.kernel.org/stable/c/6262f51e09d8dc8b07599a9e4f03bd3989d13fff"
},
{
"url": "https://git.kernel.org/stable/c/569ba39b2d12995a29dc158e5b4de6e449278f30"
},
{
"url": "https://git.kernel.org/stable/c/2b3b4e5ff5a58ad32817824b0310e63908b12052"
},
{
"url": "https://git.kernel.org/stable/c/e27beb4536cbf1d59e2d8c2840e87d972aba906f"
},
{
"url": "https://git.kernel.org/stable/c/e5824d5b841d99a2bcdd4e2c256643293bbc22c1"
},
{
"url": "https://git.kernel.org/stable/c/fe6b606fbf0c3beb94ccf17fcf31d8c2138264e3"
},
{
"url": "https://git.kernel.org/stable/c/55d9895f89970501fe126d1026b586b04a224c27"
}
],
"title": "net: thunderbolt: Fix frags[] overflow by bounding frame_count",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72157",
"datePublished": "2026-08-15T05:53:26.718Z",
"dateReserved": "2026-08-09T03:40:39.909Z",
"dateUpdated": "2026-08-23T12:46:55.998Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64581 (GCVE-0-2026-64581)
Vulnerability from cvelistv5
Published
2026-08-05 08:09
Modified
2026-08-27 12:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
xfrm: fix sk_dst_cache double-free in xfrm_user_policy()
xfrm_user_policy() clears the socket dst cache with __sk_dst_reset(),
i.e. the non-atomic __sk_dst_set(sk, NULL): it reads sk_dst_cache with
rcu_dereference_protected(), stores NULL and dst_release()s the old dst.
That is only safe if no other thread modifies sk_dst_cache concurrently.
For a connected UDP socket that does not hold: the transmit fast path
(udp_sendmsg -> sk_dst_check -> sk_dst_reset) resets the cache locklessly
with an atomic xchg(). A per-socket policy change racing a send can make
both sides observe the same old dst and each dst_release() it, dropping
the socket's single reference twice and freeing the xfrm_dst bundle while
it is still referenced:
BUG: KASAN: slab-use-after-free in dst_release
Write of size 4 at addr ffff88801897b6c0 by task exploit/155
Call Trace:
...
dst_release (... ./include/linux/rcuref.h:109)
xfrm_user_policy (./include/net/sock.h:2239 ./include/net/sock.h:2256 net/xfrm/xfrm_state.c:3053)
do_ip_setsockopt (net/ipv4/ip_sockglue.c:1347)
ip_setsockopt (net/ipv4/ip_sockglue.c:1417)
do_sock_setsockopt (net/socket.c:2368)
__sys_setsockopt (net/socket.c:2393)
__x64_sys_setsockopt (net/socket.c:2396)
do_syscall_64 (arch/x86/entry/syscall_64.c:94)
entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)
Reachable by an unprivileged user via a user+network namespace.
Use the atomic sk_dst_reset() so the cache is cleared and released with a
single xchg(): whichever side wins releases the dst once, the other sees
NULL and does nothing. Behaviour is otherwise unchanged.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 2b06cdf3e688b98fcc9945873b5d42792bd4eee0 Version: 2b06cdf3e688b98fcc9945873b5d42792bd4eee0 Version: 2b06cdf3e688b98fcc9945873b5d42792bd4eee0 Version: 2b06cdf3e688b98fcc9945873b5d42792bd4eee0 Version: 2b06cdf3e688b98fcc9945873b5d42792bd4eee0 Version: 2b06cdf3e688b98fcc9945873b5d42792bd4eee0 Version: 2b06cdf3e688b98fcc9945873b5d42792bd4eee0 Version: 2b06cdf3e688b98fcc9945873b5d42792bd4eee0 Version: 72f157be2f81910ae759bfe2e5c2256fc4625645 Version: 9e9fe58a92a46c6d154d2901735bf230d91b8507 Version: adc1ec6cdc20d430aa01b86497220709b9149466 Version: b54033eb1cfd77aba471269ddd804ed8d3e35dea Version: c9e82cb34c3c2ee895af01bc899c6ed0bc6eb04a Version: 5eef9b51114fcc65651d671add52f267f91b9451 Version: 3.16.52 ≤ Version: 4.4.163 ≤ Version: 3.18.101 ≤ Version: 4.1.52 ≤ Version: 4.4.123 ≤ Version: 4.9.89 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/xfrm/xfrm_state.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "e8686fd8d18b99f3a9038683045b2f2338a7706d",
"status": "affected",
"version": "2b06cdf3e688b98fcc9945873b5d42792bd4eee0",
"versionType": "git"
},
{
"lessThan": "a9340ebdc13f8bb5063c0bc0b037ee7e640d4ae9",
"status": "affected",
"version": "2b06cdf3e688b98fcc9945873b5d42792bd4eee0",
"versionType": "git"
},
{
"lessThan": "f833821e4b52ab6335d443ede5fb79c38e61d19a",
"status": "affected",
"version": "2b06cdf3e688b98fcc9945873b5d42792bd4eee0",
"versionType": "git"
},
{
"lessThan": "f0ab9a71167bae308e05ab13b65e2007504a603f",
"status": "affected",
"version": "2b06cdf3e688b98fcc9945873b5d42792bd4eee0",
"versionType": "git"
},
{
"lessThan": "8dd8929b71c4f06c614f8f54c2cc070453faae16",
"status": "affected",
"version": "2b06cdf3e688b98fcc9945873b5d42792bd4eee0",
"versionType": "git"
},
{
"lessThan": "0ea8f06454012d9e7f9c6e6253df710949bf6294",
"status": "affected",
"version": "2b06cdf3e688b98fcc9945873b5d42792bd4eee0",
"versionType": "git"
},
{
"lessThan": "96b678d08268b5f5c6fc99d4289d9b7e334fc683",
"status": "affected",
"version": "2b06cdf3e688b98fcc9945873b5d42792bd4eee0",
"versionType": "git"
},
{
"lessThan": "c283e9ada7fcb7dd4b10592623086b2e6d2f9925",
"status": "affected",
"version": "2b06cdf3e688b98fcc9945873b5d42792bd4eee0",
"versionType": "git"
},
{
"status": "affected",
"version": "72f157be2f81910ae759bfe2e5c2256fc4625645",
"versionType": "git"
},
{
"status": "affected",
"version": "9e9fe58a92a46c6d154d2901735bf230d91b8507",
"versionType": "git"
},
{
"status": "affected",
"version": "adc1ec6cdc20d430aa01b86497220709b9149466",
"versionType": "git"
},
{
"status": "affected",
"version": "b54033eb1cfd77aba471269ddd804ed8d3e35dea",
"versionType": "git"
},
{
"status": "affected",
"version": "c9e82cb34c3c2ee895af01bc899c6ed0bc6eb04a",
"versionType": "git"
},
{
"status": "affected",
"version": "5eef9b51114fcc65651d671add52f267f91b9451",
"versionType": "git"
},
{
"lessThan": "3.17",
"status": "affected",
"version": "3.16.52",
"versionType": "semver"
},
{
"lessThan": "4.5",
"status": "affected",
"version": "4.4.163",
"versionType": "semver"
},
{
"lessThan": "3.19",
"status": "affected",
"version": "3.18.101",
"versionType": "semver"
},
{
"lessThan": "4.2",
"status": "affected",
"version": "4.1.52",
"versionType": "semver"
},
{
"lessThan": "4.5",
"status": "affected",
"version": "4.4.123",
"versionType": "semver"
},
{
"lessThan": "4.10",
"status": "affected",
"version": "4.9.89",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/xfrm/xfrm_state.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.14"
},
{
"lessThan": "4.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.267",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.218",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.185",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.154",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.106",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.47",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.267",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.218",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.185",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.154",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.106",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.47",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.16.52",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.4.163",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.18.101",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.1.52",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.4.123",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.9.89",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: fix sk_dst_cache double-free in xfrm_user_policy()\n\nxfrm_user_policy() clears the socket dst cache with __sk_dst_reset(),\ni.e. the non-atomic __sk_dst_set(sk, NULL): it reads sk_dst_cache with\nrcu_dereference_protected(), stores NULL and dst_release()s the old dst.\nThat is only safe if no other thread modifies sk_dst_cache concurrently.\n\nFor a connected UDP socket that does not hold: the transmit fast path\n(udp_sendmsg -\u003e sk_dst_check -\u003e sk_dst_reset) resets the cache locklessly\nwith an atomic xchg(). A per-socket policy change racing a send can make\nboth sides observe the same old dst and each dst_release() it, dropping\nthe socket\u0027s single reference twice and freeing the xfrm_dst bundle while\nit is still referenced:\n\n BUG: KASAN: slab-use-after-free in dst_release\n Write of size 4 at addr ffff88801897b6c0 by task exploit/155\n Call Trace:\n ...\n dst_release (... ./include/linux/rcuref.h:109)\n xfrm_user_policy (./include/net/sock.h:2239 ./include/net/sock.h:2256 net/xfrm/xfrm_state.c:3053)\n do_ip_setsockopt (net/ipv4/ip_sockglue.c:1347)\n ip_setsockopt (net/ipv4/ip_sockglue.c:1417)\n do_sock_setsockopt (net/socket.c:2368)\n __sys_setsockopt (net/socket.c:2393)\n __x64_sys_setsockopt (net/socket.c:2396)\n do_syscall_64 (arch/x86/entry/syscall_64.c:94)\n entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)\n\nReachable by an unprivileged user via a user+network namespace.\n\nUse the atomic sk_dst_reset() so the cache is cleared and released with a\nsingle xchg(): whichever side wins releases the dst once, the other sees\nNULL and does nothing. Behaviour is otherwise unchanged."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Triggered via setsockopt(IP_XFRM_POLICY/IP_IPSEC_POLICY) on a local socket racing concurrent udp_sendmsg; entry is a local syscall path (do_ip_setsockopt -\u003e xfrm_user_policy), not packet processing.\nAC:L - Attacker controls both sides of the race (one thread setsockopt to clear/apply per-socket xfrm policy, another sendmsg on the same connected UDP socket) and can create the obsolete xfrm_dst precondition in their netns, retrying until the double dst_release wins.\nPR:L - Path requires CAP_NET_ADMIN checked with sockopt_ns_capable(sock_net(sk)-\u003euser_ns), which an unprivileged user obtains via user+network namespaces; the fix commit explicitly states this reachability.\nUI:N - Exploitation uses only the attacker\u0027s own socket, threads, and setsockopt/sendmsg loops; no victim action or cooperation is required.\nS:U - Double-free/UAF of the socket\u0027s dst_entry/xfrm_dst is standard local kernel memory corruption within the host kernel authority, not a VM escape or other cross-boundary impact.\nC:H - Double dst_release frees the xfrm_dst slab object while still referenced, yielding a use-after-free that can be reclaimed/sprayed to disclose kernel memory via corrupted dst contents and ops.\nI:H - The UAF targets a dst_entry with function pointers (ops/input/output) used on transmit, enabling heap reuse for arbitrary write and control-flow hijack consistent with comparable sk_dst_cache races.\nA:H - The KASAN slab-use-after-free in dst_release demonstrates kernel memory corruption that can oops/panic, and the attacker can repeat the race freely."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T12:39:44.254Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/e8686fd8d18b99f3a9038683045b2f2338a7706d"
},
{
"url": "https://git.kernel.org/stable/c/a9340ebdc13f8bb5063c0bc0b037ee7e640d4ae9"
},
{
"url": "https://git.kernel.org/stable/c/f833821e4b52ab6335d443ede5fb79c38e61d19a"
},
{
"url": "https://git.kernel.org/stable/c/f0ab9a71167bae308e05ab13b65e2007504a603f"
},
{
"url": "https://git.kernel.org/stable/c/8dd8929b71c4f06c614f8f54c2cc070453faae16"
},
{
"url": "https://git.kernel.org/stable/c/0ea8f06454012d9e7f9c6e6253df710949bf6294"
},
{
"url": "https://git.kernel.org/stable/c/96b678d08268b5f5c6fc99d4289d9b7e334fc683"
},
{
"url": "https://git.kernel.org/stable/c/c283e9ada7fcb7dd4b10592623086b2e6d2f9925"
}
],
"title": "xfrm: fix sk_dst_cache double-free in xfrm_user_policy()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64581",
"datePublished": "2026-08-05T08:09:35.556Z",
"dateReserved": "2026-07-19T15:36:31.798Z",
"dateUpdated": "2026-08-27T12:39:44.254Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80733 (GCVE-0-2026-80733)
Vulnerability from cvelistv5
Published
2026-09-03 08:21
Modified
2026-09-03 08:21
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: remove WARN_ON_ONCE() from sk_mc_loop()
sk_mc_loop() can be called for sockets that are neither AF_INET
nor AF_INET6 (e.g. AF_PACKET sockets when sending packets via raw/packet
socket over virtual devices such as VRF or ipvlan).
In such cases, sk_family is not AF_INET/AF_INET6 and sk_mc_loop() falls
through the switch statement and triggers WARN_ON_ONCE(1).
Non-INET sockets do not support IP_MULTICAST_LOOP or IPV6_MULTICAST_LOOP
options, so loopback should default to true without generating a warning.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: f60e5990d9c1424af9dbca60a23ba2a1c7c1ce90 Version: f60e5990d9c1424af9dbca60a23ba2a1c7c1ce90 Version: f60e5990d9c1424af9dbca60a23ba2a1c7c1ce90 Version: f60e5990d9c1424af9dbca60a23ba2a1c7c1ce90 Version: f60e5990d9c1424af9dbca60a23ba2a1c7c1ce90 Version: f60e5990d9c1424af9dbca60a23ba2a1c7c1ce90 Version: f60e5990d9c1424af9dbca60a23ba2a1c7c1ce90 Version: f60e5990d9c1424af9dbca60a23ba2a1c7c1ce90 Version: c91f81773cd4bbebfe744e9ab30a7ce093f9b930 Version: c8c30b2b17f2133e953850c547e3902c3a3d80e2 Version: 3fe207e4637a2e792c46a08666aa722f77d7f8f7 Version: 3.14.40 ≤ Version: 3.18.13 ≤ Version: 3.19.6 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/core/sock.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "97133c4d42654578fab95abe47359ebe784dde18",
"status": "affected",
"version": "f60e5990d9c1424af9dbca60a23ba2a1c7c1ce90",
"versionType": "git"
},
{
"lessThan": "f625c742b33dc137c209dd13d1c5f12b1c18d71c",
"status": "affected",
"version": "f60e5990d9c1424af9dbca60a23ba2a1c7c1ce90",
"versionType": "git"
},
{
"lessThan": "ad7fa2f411cb30f63d6725f111be134064cdb718",
"status": "affected",
"version": "f60e5990d9c1424af9dbca60a23ba2a1c7c1ce90",
"versionType": "git"
},
{
"lessThan": "d2adc4e80b29e58b5162ae09f0f657a215806c8c",
"status": "affected",
"version": "f60e5990d9c1424af9dbca60a23ba2a1c7c1ce90",
"versionType": "git"
},
{
"lessThan": "ad7dbb1d14b1b4406eca8ef9478e8de312ba0cfe",
"status": "affected",
"version": "f60e5990d9c1424af9dbca60a23ba2a1c7c1ce90",
"versionType": "git"
},
{
"lessThan": "c8f256dc849205ccb2bd78bd99a3497b972b44e0",
"status": "affected",
"version": "f60e5990d9c1424af9dbca60a23ba2a1c7c1ce90",
"versionType": "git"
},
{
"lessThan": "0d75f2c1d0764efa756ad9c1e078d8c09ea8fc1f",
"status": "affected",
"version": "f60e5990d9c1424af9dbca60a23ba2a1c7c1ce90",
"versionType": "git"
},
{
"lessThan": "b8a39a09ae4eaae04309e1e38ed6a1101d967496",
"status": "affected",
"version": "f60e5990d9c1424af9dbca60a23ba2a1c7c1ce90",
"versionType": "git"
},
{
"status": "affected",
"version": "c91f81773cd4bbebfe744e9ab30a7ce093f9b930",
"versionType": "git"
},
{
"status": "affected",
"version": "c8c30b2b17f2133e953850c547e3902c3a3d80e2",
"versionType": "git"
},
{
"status": "affected",
"version": "3fe207e4637a2e792c46a08666aa722f77d7f8f7",
"versionType": "git"
},
{
"lessThan": "3.15",
"status": "affected",
"version": "3.14.40",
"versionType": "semver"
},
{
"lessThan": "3.19",
"status": "affected",
"version": "3.18.13",
"versionType": "semver"
},
{
"lessThan": "3.20",
"status": "affected",
"version": "3.19.6",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/core/sock.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.0"
},
{
"lessThan": "4.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.14.40",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.18.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.19.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: remove WARN_ON_ONCE() from sk_mc_loop()\n\nsk_mc_loop() can be called for sockets that are neither AF_INET\nnor AF_INET6 (e.g. AF_PACKET sockets when sending packets via raw/packet\nsocket over virtual devices such as VRF or ipvlan).\n\nIn such cases, sk_family is not AF_INET/AF_INET6 and sk_mc_loop() falls\nthrough the switch statement and triggers WARN_ON_ONCE(1).\n\nNon-INET sockets do not support IP_MULTICAST_LOOP or IPV6_MULTICAST_LOOP\noptions, so loopback should default to true without generating a warning."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-03T08:21:50.136Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/97133c4d42654578fab95abe47359ebe784dde18"
},
{
"url": "https://git.kernel.org/stable/c/f625c742b33dc137c209dd13d1c5f12b1c18d71c"
},
{
"url": "https://git.kernel.org/stable/c/ad7fa2f411cb30f63d6725f111be134064cdb718"
},
{
"url": "https://git.kernel.org/stable/c/d2adc4e80b29e58b5162ae09f0f657a215806c8c"
},
{
"url": "https://git.kernel.org/stable/c/ad7dbb1d14b1b4406eca8ef9478e8de312ba0cfe"
},
{
"url": "https://git.kernel.org/stable/c/c8f256dc849205ccb2bd78bd99a3497b972b44e0"
},
{
"url": "https://git.kernel.org/stable/c/0d75f2c1d0764efa756ad9c1e078d8c09ea8fc1f"
},
{
"url": "https://git.kernel.org/stable/c/b8a39a09ae4eaae04309e1e38ed6a1101d967496"
}
],
"title": "net: remove WARN_ON_ONCE() from sk_mc_loop()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80733",
"datePublished": "2026-09-03T08:21:50.136Z",
"dateReserved": "2026-08-26T14:34:25.789Z",
"dateUpdated": "2026-09-03T08:21:50.136Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68433 (GCVE-0-2026-68433)
Vulnerability from cvelistv5
Published
2026-08-12 00:07
Modified
2026-08-19 16:35
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
libceph: bound get_version reply decode to front len
handle_get_version_reply() uses msg->front_alloc_len as the decode
boundary for MON_GET_VERSION_REPLY. That is the size of the reused
reply buffer, not the number of bytes actually received.
A truncated reply can therefore pass ceph_decode_need() and decode the
second u64 from stale tail bytes left in the buffer by an earlier
message, causing an uninitialized memory read.
Use msg->front.iov_len as the receive-side decode boundary, matching
other libceph reply handlers and limiting decoding to the bytes that
were actually read from the wire.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 513a8243d67f8e8d27f2883bd2f18bc87c7ca376 Version: 513a8243d67f8e8d27f2883bd2f18bc87c7ca376 Version: 513a8243d67f8e8d27f2883bd2f18bc87c7ca376 Version: 513a8243d67f8e8d27f2883bd2f18bc87c7ca376 Version: 513a8243d67f8e8d27f2883bd2f18bc87c7ca376 Version: 513a8243d67f8e8d27f2883bd2f18bc87c7ca376 Version: 513a8243d67f8e8d27f2883bd2f18bc87c7ca376 Version: 513a8243d67f8e8d27f2883bd2f18bc87c7ca376 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ceph/mon_client.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "1307028f082756bf453e1889aee9983d30643a4b",
"status": "affected",
"version": "513a8243d67f8e8d27f2883bd2f18bc87c7ca376",
"versionType": "git"
},
{
"lessThan": "f6cbf6878f3a1503c872ba8f1e69a58ee68d8b2e",
"status": "affected",
"version": "513a8243d67f8e8d27f2883bd2f18bc87c7ca376",
"versionType": "git"
},
{
"lessThan": "72a35070fcefa229b1b031aa7482ad3788e18f07",
"status": "affected",
"version": "513a8243d67f8e8d27f2883bd2f18bc87c7ca376",
"versionType": "git"
},
{
"lessThan": "340e0386aa39da181015bee38f309018c335ce16",
"status": "affected",
"version": "513a8243d67f8e8d27f2883bd2f18bc87c7ca376",
"versionType": "git"
},
{
"lessThan": "d60de8253c85a02d0e6194b0735e7a562981a04c",
"status": "affected",
"version": "513a8243d67f8e8d27f2883bd2f18bc87c7ca376",
"versionType": "git"
},
{
"lessThan": "4e7ebfaa0d14cf50e44041bfde38070d6dbc019f",
"status": "affected",
"version": "513a8243d67f8e8d27f2883bd2f18bc87c7ca376",
"versionType": "git"
},
{
"lessThan": "0d934c934ec746d53fc7e4f53239792647bbae63",
"status": "affected",
"version": "513a8243d67f8e8d27f2883bd2f18bc87c7ca376",
"versionType": "git"
},
{
"lessThan": "d3c32939fa0e3ee9b883b9a0fd1972c5c444e3d0",
"status": "affected",
"version": "513a8243d67f8e8d27f2883bd2f18bc87c7ca376",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ceph/mon_client.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.16"
},
{
"lessThan": "3.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.16",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: bound get_version reply decode to front len\n\nhandle_get_version_reply() uses msg-\u003efront_alloc_len as the decode\nboundary for MON_GET_VERSION_REPLY. That is the size of the reused\nreply buffer, not the number of bytes actually received.\n\nA truncated reply can therefore pass ceph_decode_need() and decode the\nsecond u64 from stale tail bytes left in the buffer by an earlier\nmessage, causing an uninitialized memory read.\n\nUse msg-\u003efront.iov_len as the receive-side decode boundary, matching\nother libceph reply handlers and limiting decoding to the bytes that\nwere actually read from the wire."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.6,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The malformed MON_GET_VERSION_REPLY arrives over the ceph messenger TCP connection to a monitor; a malicious/compromised ceph-mon or an on-path attacker on the msgr1/crc-mode session triggers the bug purely with received network data.\nAC:L - The attacker fully controls the reply\u0027s hdr.front_len and tid, so truncating the reply to 8 bytes reliably makes the handler decode past the received data every time; no race or memory-layout condition outside attacker control is involved.\nPR:N - The vulnerable decode runs on any reply the client accepts for an outstanding generic request; the attacker acts as the remote server/peer and needs no credentials or account on the victim kernel client.\nUI:N - An already-mounted CephFS/RBD client issues mon_get_version requests automatically (osdmap checks, pool-dne checks, remount/latest-map waits), so no local user action is needed once the client is connected.\nS:U - The uninitialized read and the resulting bogus epoch stay within the kernel\u0027s own libceph client state; no security authority other than the affected kernel is impacted.\nC:L - Eight bytes of uninitialized kvmalloc\u0027d heap (or stale bytes of a prior reply) are consumed as req-\u003eu.newest; the read stays inside the 32-byte allocation and is not copied to userspace, so it is a small bounded uninitialized-memory disclosure that only leaks indirectly through client behaviour.\nI:L - The attacker causes kernel state (req-\u003eu.newest, r_map_dne_bound, linger map_dne_bound) to be populated from uninitialized memory rather than the wire, corrupting osdmap-epoch bookkeeping and leading to wrong pool-does-not-exist decisions, but gives no arbitrary write.\nA:H - A zero stale value trips WARN_ON(greq-\u003eresult || !greq-\u003eu.newest) in map_check_cb()/linger_map_check_cb() (panic with panic_on_warn), while a huge garbage epoch makes ceph_monc_wait_osdmap() block until mount_timeout or indefinitely and makes check_pool_dne() abort in-flight requests with -ENOENT; all repeatable at will."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:35:33.508Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/1307028f082756bf453e1889aee9983d30643a4b"
},
{
"url": "https://git.kernel.org/stable/c/f6cbf6878f3a1503c872ba8f1e69a58ee68d8b2e"
},
{
"url": "https://git.kernel.org/stable/c/72a35070fcefa229b1b031aa7482ad3788e18f07"
},
{
"url": "https://git.kernel.org/stable/c/340e0386aa39da181015bee38f309018c335ce16"
},
{
"url": "https://git.kernel.org/stable/c/d60de8253c85a02d0e6194b0735e7a562981a04c"
},
{
"url": "https://git.kernel.org/stable/c/4e7ebfaa0d14cf50e44041bfde38070d6dbc019f"
},
{
"url": "https://git.kernel.org/stable/c/0d934c934ec746d53fc7e4f53239792647bbae63"
},
{
"url": "https://git.kernel.org/stable/c/d3c32939fa0e3ee9b883b9a0fd1972c5c444e3d0"
}
],
"title": "libceph: bound get_version reply decode to front len",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68433",
"datePublished": "2026-08-12T00:07:20.455Z",
"dateReserved": "2026-07-30T09:28:09.393Z",
"dateUpdated": "2026-08-19T16:35:33.508Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72116 (GCVE-0-2026-72116)
Vulnerability from cvelistv5
Published
2026-08-15 05:52
Modified
2026-08-19 16:36
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
can: bcm: fix stale rx/tx ops after device removal
RX: an RX_SETUP update(!) for an existing op skipped can_rx_register()
unconditionally, even when a concurrent NETDEV_UNREGISTER had already
torn down its registration (op->rx_reg_dev == NULL). This silently
did not re-enable frame delivery for that updated filter. bcm_rx_setup()
now re-registers in that case, while leaving rx_ops with ifindex = 0
(all CAN devices) which never carry a tracked rx_reg_dev registered as-is.
TX: bcm_notify() only handled bo->rx_ops on NETDEV_UNREGISTER, leaving
tx_ops with an active cyclic transmission re-arming its hrtimer
indefinitely to execute bcm_tx_timeout_handler(). Cancelling the hrtimer
prevents the runaway timer and any injection into a later reused ifindex,
since nothing else calls bcm_can_tx() for the op until an explicit
TX_SETUP update re-arms it.
Unlike bcm_rx_unreg(), which clears the tracked rx_reg_dev for rx_ops,
the ifindex is intentionally left unchanged for tx_ops. bcm_tx_setup()
always rejects ifindex 0, so clearing it would strand the op: neither a
later TX_SETUP (bcm_find_op()) nor TX_DELETE (bcm_delete_tx_op()) could
ever find it again, since both require an exact ifindex match.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/can/bcm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "d30a36066ed3abefb72ae18901f71841ba18b350",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "ca829677ffa2de5d79e06366e19ac1e4f5cc78dd",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "9517d8fb0b191398d35b9b7f8c719c1cc7761cb1",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "60d8a7942f4ed2d975207aaeba1adb576707e53d",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "f749e4564952d60e96930c09f2be99955d07c22e",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "6be3e1fedf03eab36a2c09d755d1171287b2014b",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "b31d0933509c5a35c0be5736a2ce8df0d1bf112c",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "3b762c0d950383ab7a002686c9136b9aa55d2d70",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/can/bcm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.25"
},
{
"lessThan": "2.6.25",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.25",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: bcm: fix stale rx/tx ops after device removal\n\nRX: an RX_SETUP update(!) for an existing op skipped can_rx_register()\nunconditionally, even when a concurrent NETDEV_UNREGISTER had already\ntorn down its registration (op-\u003erx_reg_dev == NULL). This silently\ndid not re-enable frame delivery for that updated filter. bcm_rx_setup()\nnow re-registers in that case, while leaving rx_ops with ifindex = 0\n(all CAN devices) which never carry a tracked rx_reg_dev registered as-is.\n\nTX: bcm_notify() only handled bo-\u003erx_ops on NETDEV_UNREGISTER, leaving\ntx_ops with an active cyclic transmission re-arming its hrtimer\nindefinitely to execute bcm_tx_timeout_handler(). Cancelling the hrtimer\nprevents the runaway timer and any injection into a later reused ifindex,\nsince nothing else calls bcm_can_tx() for the op until an explicit\nTX_SETUP update re-arms it.\n\nUnlike bcm_rx_unreg(), which clears the tracked rx_reg_dev for rx_ops,\nthe ifindex is intentionally left unchanged for tx_ops. bcm_tx_setup()\nalways rejects ifindex 0, so clearing it would strand the op: neither a\nlater TX_SETUP (bcm_find_op()) nor TX_DELETE (bcm_delete_tx_op()) could\never find it again, since both require an exact ifindex match."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached only via local PF_CAN/CAN_BCM syscalls (socket/connect/sendmsg TX_SETUP or RX_SETUP); bcm_tx_timeout_handler() is driven by a local hrtimer, not by remote network services or CAN bus frames alone.\nAC:L - An attacker controls both sides by arming cyclic TX with SETTIMER/STARTTIMER, then triggering or waiting for NETDEV_UNREGISTER (e.g., concurrent ip link del in a user namespace) while ifindex reuse is normal kernel behavior, making injection reliably achievable.\nPR:L - can_create(), bcm_connect(), and bcm_sendmsg() perform no capability checks; any local user with CAN access (or CAP_NET_ADMIN in an unprivileged user namespace to create vcan) can open BCM sockets and program cyclic TX/RX ops.\nUI:N - Exploitation requires only the attacker opening a BCM socket and sending TX_SETUP/RX_SETUP messages; no victim action such as mounting media or opening files is needed once local CAN access exists.\nS:U - Impact is unauthorized CAN transmission/monitoring disruption within the same kernel host; it does not cross VM, container, or IOMMU security boundaries even when frames reach an adjacent vehicle or factory CAN segment.\nC:N - The flaw causes stale timer-driven transmission and missed RX re-registration, not kernel memory disclosure; no out-of-bounds read, UAF, or other information-leak primitive is present in this bug.\nI:H - After NETDEV_UNREGISTER, orphaned tx_ops keep bcm_can_tx() running with a stale ifindex, so attacker-crafted cyclic CAN frames can be injected onto any later netdev that reuses that ifindex, including safety-critical automotive or industrial buses.\nA:H - Uncancelled hrtimers on stale tx_ops re-arm bcm_tx_timeout_handler() indefinitely after device removal, causing persistent timer/softirq CPU consumption, and the RX_SETUP path can silently stop frame delivery after unregister races."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:36:05.976Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/d30a36066ed3abefb72ae18901f71841ba18b350"
},
{
"url": "https://git.kernel.org/stable/c/ca829677ffa2de5d79e06366e19ac1e4f5cc78dd"
},
{
"url": "https://git.kernel.org/stable/c/9517d8fb0b191398d35b9b7f8c719c1cc7761cb1"
},
{
"url": "https://git.kernel.org/stable/c/60d8a7942f4ed2d975207aaeba1adb576707e53d"
},
{
"url": "https://git.kernel.org/stable/c/f749e4564952d60e96930c09f2be99955d07c22e"
},
{
"url": "https://git.kernel.org/stable/c/6be3e1fedf03eab36a2c09d755d1171287b2014b"
},
{
"url": "https://git.kernel.org/stable/c/b31d0933509c5a35c0be5736a2ce8df0d1bf112c"
},
{
"url": "https://git.kernel.org/stable/c/3b762c0d950383ab7a002686c9136b9aa55d2d70"
}
],
"title": "can: bcm: fix stale rx/tx ops after device removal",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72116",
"datePublished": "2026-08-15T05:52:56.260Z",
"dateReserved": "2026-08-09T03:40:39.906Z",
"dateUpdated": "2026-08-19T16:36:05.976Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80716 (GCVE-0-2026-80716)
Vulnerability from cvelistv5
Published
2026-08-28 06:53
Modified
2026-08-29 06:22
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ALSA: pcm: wake linked drain waiters on unlink
snd_pcm_drain() on a linked stream parks an on-stack wait entry on the
drained peer's runtime->sleep, and after schedule_timeout() removes it
only if that peer is still found in the caller's group. If group
membership changes during the wait and the sleep ends by signal or
timeout (so autoremove_wake_function() does not run), finish_wait() is
skipped and snd_pcm_drain() returns with the entry still queued on that
stream's sleep list; a later wake_up() then walks a freed stack frame.
This is reachable by unlinking either the drained or the draining stream.
Unlike the close path (snd_pcm_drop() -> snd_pcm_post_stop()),
snd_pcm_unlink() never wakes the sleep queues. Wake every group member
under the group lock before the membership change, so a linked drainer is
released and drops its entry while the streams are still grouped.
The window was opened when snd_pcm_link_rwsem stopped being held across
the wait and the removal became conditional on group membership (see
Fixes). The later switch to finish_wait() kept that conditional removal,
so the signal/timeout case remained.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: f57f3df03a8e6010e321fa0258d3e054713c3cb7 Version: f57f3df03a8e6010e321fa0258d3e054713c3cb7 Version: f57f3df03a8e6010e321fa0258d3e054713c3cb7 Version: f57f3df03a8e6010e321fa0258d3e054713c3cb7 Version: f57f3df03a8e6010e321fa0258d3e054713c3cb7 Version: f57f3df03a8e6010e321fa0258d3e054713c3cb7 Version: f57f3df03a8e6010e321fa0258d3e054713c3cb7 Version: f57f3df03a8e6010e321fa0258d3e054713c3cb7 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"sound/core/pcm_native.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c172e4c53321ee6429955295ea133bc3597a3ca9",
"status": "affected",
"version": "f57f3df03a8e6010e321fa0258d3e054713c3cb7",
"versionType": "git"
},
{
"lessThan": "3035bb784cea3f338934f5042dd3f35225a51b2e",
"status": "affected",
"version": "f57f3df03a8e6010e321fa0258d3e054713c3cb7",
"versionType": "git"
},
{
"lessThan": "1c1b7e8e545ce65e40f65b55c432765e058ea98f",
"status": "affected",
"version": "f57f3df03a8e6010e321fa0258d3e054713c3cb7",
"versionType": "git"
},
{
"lessThan": "e8b784a3f4fba3ea9c4d05138ecfa784a069627f",
"status": "affected",
"version": "f57f3df03a8e6010e321fa0258d3e054713c3cb7",
"versionType": "git"
},
{
"lessThan": "e8315330e4ec09c0cac625515400e13d0ee22b81",
"status": "affected",
"version": "f57f3df03a8e6010e321fa0258d3e054713c3cb7",
"versionType": "git"
},
{
"lessThan": "2940cc3cf43c72126b74ee6376314c195382023a",
"status": "affected",
"version": "f57f3df03a8e6010e321fa0258d3e054713c3cb7",
"versionType": "git"
},
{
"lessThan": "db09bc4ab19ce548a078240d2374792523953500",
"status": "affected",
"version": "f57f3df03a8e6010e321fa0258d3e054713c3cb7",
"versionType": "git"
},
{
"lessThan": "f495b6c4c8594122918552c9be2b51eb71647cd9",
"status": "affected",
"version": "f57f3df03a8e6010e321fa0258d3e054713c3cb7",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"sound/core/pcm_native.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.1"
},
{
"lessThan": "5.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: pcm: wake linked drain waiters on unlink\n\nsnd_pcm_drain() on a linked stream parks an on-stack wait entry on the\ndrained peer\u0027s runtime-\u003esleep, and after schedule_timeout() removes it\nonly if that peer is still found in the caller\u0027s group. If group\nmembership changes during the wait and the sleep ends by signal or\ntimeout (so autoremove_wake_function() does not run), finish_wait() is\nskipped and snd_pcm_drain() returns with the entry still queued on that\nstream\u0027s sleep list; a later wake_up() then walks a freed stack frame.\nThis is reachable by unlinking either the drained or the draining stream.\n\nUnlike the close path (snd_pcm_drop() -\u003e snd_pcm_post_stop()),\nsnd_pcm_unlink() never wakes the sleep queues. Wake every group member\nunder the group lock before the membership change, so a linked drainer is\nreleased and drops its entry while the streams are still grouped.\n\nThe window was opened when snd_pcm_link_rwsem stopped being held across\nthe wait and the removal became conditional on group membership (see\nFixes). The later switch to finish_wait() kept that conditional removal,\nso the signal/timeout case remained."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is triggered only via local ALSA PCM character devices (/dev/snd/pcmC*D*) through open/ioctl syscalls (SNDRV_PCM_IOCTL_LINK, UNLINK, DRAIN); snd_pcm_kernel_ioctl does not expose LINK/UNLINK, and there is no network-facing path to this code.\nAC:L - This is a race, but the attacker controls both sides by opening two PCM fds, linking them, blocking one thread in DRAIN, and concurrently UNLINKing or closing the peer; sending a signal or waiting for timeout forces the path where finish_wait() is skipped.\nPR:L - Exploitation requires only a local process able to open and ioctl ALSA PCM nodes (typical desktop/mobile users via the audio group, session ACLs, or equivalent device permissions); no real root, CAP_SYS_ADMIN, or init-namespace privileges are needed.\nUI:N - The attacker drives the entire sequence programmatically with their own PCM file descriptors and threads; no victim interaction such as opening a file, mounting a filesystem, or plugging in hardware is required.\nS:U - Impact is confined to kernel memory corruption and privilege escalation within the same security authority; this is not a VM escape, IOMMU/DMA boundary bypass, or other cross-scope violation.\nC:H - The orphaned wait_queue_entry_t remains on the sleep list after snd_pcm_drain() returns, and a later wake_up() dereferences a freed on-stack wait entry (use-after-free), which can expose kernel stack/memory contents under attacker-controlled timing.\nI:H - Corrupting the wait-queue list with a stale stack-backed entry gives kernel memory corruption primitives; wake_up() invokes the entry\u0027s function pointer from freed stack memory, enabling plausible control-flow hijack and arbitrary write via further heap/stack grooming.\nA:H - A subsequent wake_up() on the poisoned sleep queue walks a freed stack frame and can oops or panic the kernel; even without full exploitation, the UAF reliably threatens system availability on multimedia desktops, kiosks, and embedded devices with ALSA access."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-29T06:22:32.041Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c172e4c53321ee6429955295ea133bc3597a3ca9"
},
{
"url": "https://git.kernel.org/stable/c/3035bb784cea3f338934f5042dd3f35225a51b2e"
},
{
"url": "https://git.kernel.org/stable/c/1c1b7e8e545ce65e40f65b55c432765e058ea98f"
},
{
"url": "https://git.kernel.org/stable/c/e8b784a3f4fba3ea9c4d05138ecfa784a069627f"
},
{
"url": "https://git.kernel.org/stable/c/e8315330e4ec09c0cac625515400e13d0ee22b81"
},
{
"url": "https://git.kernel.org/stable/c/2940cc3cf43c72126b74ee6376314c195382023a"
},
{
"url": "https://git.kernel.org/stable/c/db09bc4ab19ce548a078240d2374792523953500"
},
{
"url": "https://git.kernel.org/stable/c/f495b6c4c8594122918552c9be2b51eb71647cd9"
}
],
"title": "ALSA: pcm: wake linked drain waiters on unlink",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80716",
"datePublished": "2026-08-28T06:53:14.286Z",
"dateReserved": "2026-08-26T14:34:25.788Z",
"dateUpdated": "2026-08-29T06:22:32.041Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74509 (GCVE-0-2026-74509)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-27 12:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci_sync: Fix advertising data UAFs
hci_find_adv_instance() returns an adv_info pointer that is valid only
while hdev->lock is held. The advertising command-sync paths perform
instance lookups without that lock and, in some cases, retain the pointer
while waiting for a controller response.
An advertising termination event can therefore interleave as follows:
hci_cmd_sync_work hci_rx_work
hci_find_adv_instance()
__hci_cmd_sync_status()
wait for controller reply hci_dev_lock()
hci_remove_adv_instance()
kfree(adv)
adv->scan_rsp_changed = false
KASAN reported:
BUG: KASAN: slab-use-after-free in hci_set_ext_scan_rsp_data_sync+0x2e1/0x300
Write of size 1 at addr ffff88810a45d21d by task kworker/u17:0/88
Workqueue: hci0 hci_cmd_sync_work
Call Trace:
hci_set_ext_scan_rsp_data_sync+0x2e1/0x300
hci_schedule_adv_instance_sync+0x390/0x4c0
hci_cmd_sync_work+0x173/0x300
Allocated by task 87:
hci_add_adv_instance+0x538/0xac0
add_advertising+0x885/0x1160
Freed by task 89:
kfree+0x131/0x3c0
hci_remove_adv_instance+0x1d8/0x3b0
hci_le_ext_adv_term_evt+0x17b/0x730
Protect the instance lookup and payload construction in the extended
advertising, scan response, and periodic advertising data paths. Snapshot
the advertising parameters under hdev->lock, but release the lock before
waiting for the controller.
Clear advertising-data dirty bits before issuing their commands and
restore them after a failure using a fresh lookup. Likewise, update the
reported transmit power through a fresh lookup after the parameter command
completes. No adv_info pointer then survives an HCI command wait.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: cba6b758711cab946c787f7c15be92cc749b8e1f Version: cba6b758711cab946c787f7c15be92cc749b8e1f Version: cba6b758711cab946c787f7c15be92cc749b8e1f Version: cba6b758711cab946c787f7c15be92cc749b8e1f Version: cba6b758711cab946c787f7c15be92cc749b8e1f Version: cba6b758711cab946c787f7c15be92cc749b8e1f Version: 42fe380baaaccbe635c34ca07b29d19b9ec2498d Version: 5.15.210 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/bluetooth/hci_sync.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "565971488191bf54a87a417abafab6ad0de72201",
"status": "affected",
"version": "cba6b758711cab946c787f7c15be92cc749b8e1f",
"versionType": "git"
},
{
"lessThan": "c4cec575a6d6f7c36808a3a0017b0675968bb06b",
"status": "affected",
"version": "cba6b758711cab946c787f7c15be92cc749b8e1f",
"versionType": "git"
},
{
"lessThan": "95cdcd8c82a501931fd3ae9b3811b0b6da167e94",
"status": "affected",
"version": "cba6b758711cab946c787f7c15be92cc749b8e1f",
"versionType": "git"
},
{
"lessThan": "eb1d8318764de7216e6dbba29a24d69f7ce51348",
"status": "affected",
"version": "cba6b758711cab946c787f7c15be92cc749b8e1f",
"versionType": "git"
},
{
"lessThan": "b16ebdbebd2d37f4cdc590bc3e9db71fe90350a3",
"status": "affected",
"version": "cba6b758711cab946c787f7c15be92cc749b8e1f",
"versionType": "git"
},
{
"lessThan": "cdc36db204ffd97b947d64374cf23a210dc74777",
"status": "affected",
"version": "cba6b758711cab946c787f7c15be92cc749b8e1f",
"versionType": "git"
},
{
"status": "affected",
"version": "42fe380baaaccbe635c34ca07b29d19b9ec2498d",
"versionType": "git"
},
{
"lessThan": "5.16",
"status": "affected",
"version": "5.15.210",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/bluetooth/hci_sync.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.17"
},
{
"lessThan": "5.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.154",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.154",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.15.210",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_sync: Fix advertising data UAFs\n\nhci_find_adv_instance() returns an adv_info pointer that is valid only\nwhile hdev-\u003elock is held. The advertising command-sync paths perform\ninstance lookups without that lock and, in some cases, retain the pointer\nwhile waiting for a controller response.\n\nAn advertising termination event can therefore interleave as follows:\n\n hci_cmd_sync_work hci_rx_work\n hci_find_adv_instance()\n __hci_cmd_sync_status()\n wait for controller reply hci_dev_lock()\n hci_remove_adv_instance()\n kfree(adv)\n adv-\u003escan_rsp_changed = false\n\nKASAN reported:\n\n BUG: KASAN: slab-use-after-free in hci_set_ext_scan_rsp_data_sync+0x2e1/0x300\n Write of size 1 at addr ffff88810a45d21d by task kworker/u17:0/88\n Workqueue: hci0 hci_cmd_sync_work\n Call Trace:\n hci_set_ext_scan_rsp_data_sync+0x2e1/0x300\n hci_schedule_adv_instance_sync+0x390/0x4c0\n hci_cmd_sync_work+0x173/0x300\n Allocated by task 87:\n hci_add_adv_instance+0x538/0xac0\n add_advertising+0x885/0x1160\n Freed by task 89:\n kfree+0x131/0x3c0\n hci_remove_adv_instance+0x1d8/0x3b0\n hci_le_ext_adv_term_evt+0x17b/0x730\n\nProtect the instance lookup and payload construction in the extended\nadvertising, scan response, and periodic advertising data paths. Snapshot\nthe advertising parameters under hdev-\u003elock, but release the lock before\nwaiting for the controller.\n\nClear advertising-data dirty bits before issuing their commands and\nrestore them after a failure using a fresh lookup. Likewise, update the\nreported transmit power through a fresh lookup after the parameter command\ncompletes. No adv_info pointer then survives an HCI command wait."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The bug is in the Bluetooth HCI LE extended-advertising path; a remote/adjacent peer can deliver the LE Extended Advertising Set Terminated HCI event that frees adv_info while hci_cmd_sync_work waits on the controller during scan-response/advertising-data updates on phones and other BLE devices.\nAC:L - This is a use-after-free race between hci_cmd_sync_work and hci_rx_work where the attacker controls the terminating side by repeatedly initiating BLE connections/terminations during the up-to-2s HCI command wait, and can also drive the setup side via MGMT advertising commands.\nPR:N - An adjacent Bluetooth attacker needs no account, credentials, or capabilities on the victim; exploitation only requires the victim stack to be configuring BLE advertising (normal on Android phones, laptops, and IoT) while the attacker sends over-the-air BLE traffic to trigger hci_le_ext_adv_term_evt.\nUI:N - No deliberate victim action is required beyond a device running Bluetooth with LE advertising updates (common default behavior); the attacker triggers the race remotely without social engineering, file opens, or mounts.\nS:U - Impact is kernel heap corruption and potential local privilege escalation within the same kernel security domain; it does not cross a VM, container, or IOMMU boundary.\nC:H - Multiple UAF paths read freed adv_info (e.g., eir_create_scan_rsp/adv_data) and retain dangling pointers across __hci_cmd_sync_status waits, enabling slab reuse and arbitrary kernel memory disclosure via heap grooming.\nI:H - KASAN shows a post-free write to adv_info (scan_rsp_changed); similar paths write adv_data_changed and tx_power on freed objects, providing exploitable heap corruption for arbitrary kernel writes and code execution.\nA:H - Use-after-free on adv_info in hci_cmd_sync_work can cause immediate kernel oops/panic or hung BLE subsystem during advertising reconfiguration, and is reachable from unauthenticated adjacent BLE interaction on actively advertising devices."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T12:39:46.394Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/565971488191bf54a87a417abafab6ad0de72201"
},
{
"url": "https://git.kernel.org/stable/c/c4cec575a6d6f7c36808a3a0017b0675968bb06b"
},
{
"url": "https://git.kernel.org/stable/c/95cdcd8c82a501931fd3ae9b3811b0b6da167e94"
},
{
"url": "https://git.kernel.org/stable/c/eb1d8318764de7216e6dbba29a24d69f7ce51348"
},
{
"url": "https://git.kernel.org/stable/c/b16ebdbebd2d37f4cdc590bc3e9db71fe90350a3"
},
{
"url": "https://git.kernel.org/stable/c/cdc36db204ffd97b947d64374cf23a210dc74777"
}
],
"title": "Bluetooth: hci_sync: Fix advertising data UAFs",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74509",
"datePublished": "2026-08-15T12:27:31.896Z",
"dateReserved": "2026-08-15T05:44:03.909Z",
"dateUpdated": "2026-08-27T12:39:46.394Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74493 (GCVE-0-2026-74493)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-19 16:37
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/smc: fix socket use-after-free during link group termination
__smc_lgr_terminate() drops conns_lock after finding a connection in
lgr->conns_all, but before taking a reference on its socket. The connection
is embedded in the socket, and its registration reference protects it only
while the connection remains in the tree.
A concurrent close can unregister the connection and drop that reference,
freeing the socket before the termination worker reaches sock_hold().
The race is reachable when close overlaps link group termination.
Local stress testing reproduced the use-after-free and KASAN reported:
BUG: KASAN: slab-use-after-free in __smc_lgr_terminate.part.0 [smc]
Write of size 4 by task kworker/3:3
Workqueue: events smc_lgr_terminate_work [smc]
__smc_lgr_terminate.part.0 [smc]
The socket was allocated by smc_create(), freed through
slab_free_after_rcu_debug(), and was followed by:
refcount_t: addition on 0; use-after-free.
__smc_lgr_terminate.part.0 [smc]
Take the socket reference while conns_lock still protects the tree entry.
The unregister path then cannot drop the last reference until termination
has finished using the socket.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 69318b5215f2dc32c345a3d65b98b4b1bf29c007 Version: 69318b5215f2dc32c345a3d65b98b4b1bf29c007 Version: 69318b5215f2dc32c345a3d65b98b4b1bf29c007 Version: 69318b5215f2dc32c345a3d65b98b4b1bf29c007 Version: 69318b5215f2dc32c345a3d65b98b4b1bf29c007 Version: 69318b5215f2dc32c345a3d65b98b4b1bf29c007 Version: 69318b5215f2dc32c345a3d65b98b4b1bf29c007 Version: 69318b5215f2dc32c345a3d65b98b4b1bf29c007 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/smc/smc_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ff44f2df57fb5560bdc75eb977867643e764a262",
"status": "affected",
"version": "69318b5215f2dc32c345a3d65b98b4b1bf29c007",
"versionType": "git"
},
{
"lessThan": "9fb17c95b8f0683570fca1fb2792264147af937a",
"status": "affected",
"version": "69318b5215f2dc32c345a3d65b98b4b1bf29c007",
"versionType": "git"
},
{
"lessThan": "bea8dc14de2d56aca749d368563e6888217710a5",
"status": "affected",
"version": "69318b5215f2dc32c345a3d65b98b4b1bf29c007",
"versionType": "git"
},
{
"lessThan": "5a42f162b857019a4c10ff687dc3bcdf51831865",
"status": "affected",
"version": "69318b5215f2dc32c345a3d65b98b4b1bf29c007",
"versionType": "git"
},
{
"lessThan": "281c103a8eaed59001ce952f231df1b07674215a",
"status": "affected",
"version": "69318b5215f2dc32c345a3d65b98b4b1bf29c007",
"versionType": "git"
},
{
"lessThan": "f807a63d0d95680c34f677700da9148a07d7c78f",
"status": "affected",
"version": "69318b5215f2dc32c345a3d65b98b4b1bf29c007",
"versionType": "git"
},
{
"lessThan": "f0541a775d04c88e90ba448e35ce0d743512822a",
"status": "affected",
"version": "69318b5215f2dc32c345a3d65b98b4b1bf29c007",
"versionType": "git"
},
{
"lessThan": "f621d6ebeebb6374342571e4ddf45fdbc420f6cd",
"status": "affected",
"version": "69318b5215f2dc32c345a3d65b98b4b1bf29c007",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/smc/smc_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.5"
},
{
"lessThan": "5.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/smc: fix socket use-after-free during link group termination\n\n__smc_lgr_terminate() drops conns_lock after finding a connection in\nlgr-\u003econns_all, but before taking a reference on its socket. The connection\nis embedded in the socket, and its registration reference protects it only\nwhile the connection remains in the tree.\n\nA concurrent close can unregister the connection and drop that reference,\nfreeing the socket before the termination worker reaches sock_hold().\n\nThe race is reachable when close overlaps link group termination.\nLocal stress testing reproduced the use-after-free and KASAN reported:\n\n BUG: KASAN: slab-use-after-free in __smc_lgr_terminate.part.0 [smc]\n Write of size 4 by task kworker/3:3\n Workqueue: events smc_lgr_terminate_work [smc]\n __smc_lgr_terminate.part.0 [smc]\n\nThe socket was allocated by smc_create(), freed through\nslab_free_after_rcu_debug(), and was followed by:\n\n refcount_t: addition on 0; use-after-free.\n __smc_lgr_terminate.part.0 [smc]\n\nTake the socket reference while conns_lock still protects the tree entry.\nThe unregister path then cannot drop the last reference until termination\nhas finished using the socket."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug is hit in __smc_lgr_terminate() when a link group shuts down; that path is driven by SMC LLC control messages from a remote peer over RoCE/RDMA (smc_llc_rx_handler), including DELETE_LINK_ALL and protocol-violation termination, not only local syscalls.\nAC:L - An SMC peer can overlap link-group termination with connection teardown by sending DELETE_LINK_ALL (or a terminating LLC event) while aborting/closing the same session; the fix report shows reliable stress reproduction, and the attacker controls both sides of the terminate/close race.\nPR:N - Exploitation needs only completing an SMC handshake as a network peer to the victim; no local account, capabilities, or namespace admin rights on the victim host are required beyond normal remote connectivity to the SMC service.\nUI:N - No victim user action is needed; a remote peer can trigger termination and concurrent connection teardown purely through kernel protocol handling, without the user mounting filesystems, opening files, or performing other interactive steps.\nS:U - The impact stays within the host kernel boundary (memory corruption and potential local privilege escalation) and does not cross VM, container, or IOMMU security authorities into another trust domain.\nC:H - KASAN reported slab-use-after-free in __smc_lgr_terminate with refcount_t addition on 0 during sock_hold() on a freed smc_sock; UAF on kernel heap objects can be turned into arbitrary kernel memory disclosure via heap grooming.\nI:H - The UAF is a write of size 4 to freed socket memory during sock_hold(), giving a kernel heap corruption primitive that can be developed into arbitrary write or control-flow hijack for kernel code execution.\nA:H - The reported UAF occurs in the smc_lgr_terminate workqueue and can crash the kernel (oops/panic); repeated remote triggering against SMC/RoCE services can also cause sustained denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:37:50.842Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ff44f2df57fb5560bdc75eb977867643e764a262"
},
{
"url": "https://git.kernel.org/stable/c/9fb17c95b8f0683570fca1fb2792264147af937a"
},
{
"url": "https://git.kernel.org/stable/c/bea8dc14de2d56aca749d368563e6888217710a5"
},
{
"url": "https://git.kernel.org/stable/c/5a42f162b857019a4c10ff687dc3bcdf51831865"
},
{
"url": "https://git.kernel.org/stable/c/281c103a8eaed59001ce952f231df1b07674215a"
},
{
"url": "https://git.kernel.org/stable/c/f807a63d0d95680c34f677700da9148a07d7c78f"
},
{
"url": "https://git.kernel.org/stable/c/f0541a775d04c88e90ba448e35ce0d743512822a"
},
{
"url": "https://git.kernel.org/stable/c/f621d6ebeebb6374342571e4ddf45fdbc420f6cd"
}
],
"title": "net/smc: fix socket use-after-free during link group termination",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74493",
"datePublished": "2026-08-15T12:27:21.980Z",
"dateReserved": "2026-08-15T05:44:03.906Z",
"dateUpdated": "2026-08-19T16:37:50.842Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2025-38616 (GCVE-0-2025-38616)
Vulnerability from cvelistv5
Published
2025-08-22 13:01
Modified
2026-08-27 12:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
tls: handle data disappearing from under the TLS ULP
TLS expects that it owns the receive queue of the TCP socket.
This cannot be guaranteed in case the reader of the TCP socket
entered before the TLS ULP was installed, or uses some non-standard
read API (eg. zerocopy ones). Replace the WARN_ON() and a buggy
early exit (which leaves anchor pointing to a freed skb) with real
error handling. Wipe the parsing state and tell the reader to retry.
We already reload the anchor every time we (re)acquire the socket lock,
so the only condition we need to avoid is an out of bounds read
(not having enough bytes in the socket for previously parsed record len).
If some data was read from under TLS but there's enough in the queue
we'll reload and decrypt what is most likely not a valid TLS record.
Leading to some undefined behavior from TLS perspective (corrupting
a stream? missing an alert? missing an attack?) but no kernel crash
should take place.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 84c61fe1a75b4255df1e1e7c054c9e6d048da417 Version: 84c61fe1a75b4255df1e1e7c054c9e6d048da417 Version: 84c61fe1a75b4255df1e1e7c054c9e6d048da417 Version: 84c61fe1a75b4255df1e1e7c054c9e6d048da417 Version: 84c61fe1a75b4255df1e1e7c054c9e6d048da417 Version: 84c61fe1a75b4255df1e1e7c054c9e6d048da417 |
||
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2025-38616",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-06-10T20:40:59.907591Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-06-11T18:44:07.792Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/tls/tls.h",
"net/tls/tls_strp.c",
"net/tls/tls_sw.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ef50eaab631f9bf519ddbdfa42ccb0528adc1fc8",
"status": "affected",
"version": "84c61fe1a75b4255df1e1e7c054c9e6d048da417",
"versionType": "git"
},
{
"lessThan": "f1fe99919f629f980d0b8a7ff16950bffe06a859",
"status": "affected",
"version": "84c61fe1a75b4255df1e1e7c054c9e6d048da417",
"versionType": "git"
},
{
"lessThan": "eb0336f213fe88bbdb7d2b19c9c9ec19245a3155",
"status": "affected",
"version": "84c61fe1a75b4255df1e1e7c054c9e6d048da417",
"versionType": "git"
},
{
"lessThan": "db3658a12d5ec4db7185ae7476151a50521b7207",
"status": "affected",
"version": "84c61fe1a75b4255df1e1e7c054c9e6d048da417",
"versionType": "git"
},
{
"lessThan": "2fb97ed9e2672b4f6e24ce206ac1a875ce4bcb38",
"status": "affected",
"version": "84c61fe1a75b4255df1e1e7c054c9e6d048da417",
"versionType": "git"
},
{
"lessThan": "6db015fc4b5d5f63a64a193f65d98da3a7fc811d",
"status": "affected",
"version": "84c61fe1a75b4255df1e1e7c054c9e6d048da417",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/tls/tls.h",
"net/tls/tls_strp.c",
"net/tls/tls_sw.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.0"
},
{
"lessThan": "6.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.185",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.43",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.15.*",
"status": "unaffected",
"version": "6.15.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.16.*",
"status": "unaffected",
"version": "6.16.2",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "6.17",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.185",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.103",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.43",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.15.11",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.16.2",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.17",
"versionStartIncluding": "6.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntls: handle data disappearing from under the TLS ULP\n\nTLS expects that it owns the receive queue of the TCP socket.\nThis cannot be guaranteed in case the reader of the TCP socket\nentered before the TLS ULP was installed, or uses some non-standard\nread API (eg. zerocopy ones). Replace the WARN_ON() and a buggy\nearly exit (which leaves anchor pointing to a freed skb) with real\nerror handling. Wipe the parsing state and tell the reader to retry.\n\nWe already reload the anchor every time we (re)acquire the socket lock,\nso the only condition we need to avoid is an out of bounds read\n(not having enough bytes in the socket for previously parsed record len).\n\nIf some data was read from under TLS but there\u0027s enough in the queue\nwe\u0027ll reload and decrypt what is most likely not a valid TLS record.\nLeading to some undefined behavior from TLS perspective (corrupting\na stream? missing an alert? missing an attack?) but no kernel crash\nshould take place."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerability is triggered by a local out-of-band consumer of the TCP receive queue (e.g. TCP_ZEROCOPY_RECEIVE getsockopt or a reader active before the TLS ULP was installed); a remote peer only supplies encrypted bytes and cannot itself make data disappear from under the ULP, so it is reachable only via local syscalls on the attacker\u0027s own socket.\nAC:L - The attacker owns and sequences every step\u2014install kTLS, feed data over loopback, consume the queue via zerocopy receive, then recvmsg\u2014all serialized under their own socket lock, making the UAF/OOB read fire deterministically rather than depending on any uncontrolled condition.\nPR:L - Installing the TLS ULP, setting RX crypto keys, using TCP_ZEROCOPY_RECEIVE, and calling recvmsg require no capability whatsoever (tls_init only needs an ESTABLISHED TCP socket), so any basic unprivileged local user qualifies.\nUI:N - The attacking process performs the entire sequence itself on a socket it controls, requiring no action from any other user or victim.\nS:U - The freed/out-of-bounds skb memory read during decryption stays entirely within the kernel\u0027s own security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - The anchor is left pointing at a freed skb and the decrypt path reads up to a full record length (~16KB) beyond the valid data, a use-after-free/out-of-bounds read over attacker-groomable freed kernel memory that can disclose kernel contents.\nI:H - The use-after-free lets the attacker control the freed skb contents via heap spraying (a classic write-primitive enabler), and TLS can additionally be made to decrypt garbage\u2014corrupting the stream or silently dropping alerts/attacks\u2014so integrity is high.\nA:H - Dereferencing a freed skb\u0027s frag_list and reading past the available bytes readily triggers a kernel oops/panic, the very crash the fix was written to prevent."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T12:39:35.730Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ef50eaab631f9bf519ddbdfa42ccb0528adc1fc8"
},
{
"url": "https://git.kernel.org/stable/c/f1fe99919f629f980d0b8a7ff16950bffe06a859"
},
{
"url": "https://git.kernel.org/stable/c/eb0336f213fe88bbdb7d2b19c9c9ec19245a3155"
},
{
"url": "https://git.kernel.org/stable/c/db3658a12d5ec4db7185ae7476151a50521b7207"
},
{
"url": "https://git.kernel.org/stable/c/2fb97ed9e2672b4f6e24ce206ac1a875ce4bcb38"
},
{
"url": "https://git.kernel.org/stable/c/6db015fc4b5d5f63a64a193f65d98da3a7fc811d"
}
],
"title": "tls: handle data disappearing from under the TLS ULP",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2025-38616",
"datePublished": "2025-08-22T13:01:23.217Z",
"dateReserved": "2025-04-16T04:51:24.029Z",
"dateUpdated": "2026-08-27T12:39:35.730Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80791 (GCVE-0-2026-80791)
Vulnerability from cvelistv5
Published
2026-09-04 15:13
Modified
2026-09-04 15:13
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
nvmet-auth: zero the AUTH_RECEIVE response buffer
nvmet_execute_auth_receive() allocates the response buffer with kmalloc()
sized by the host-supplied AUTH_RECEIVE allocation length, but the
DH-HMAC-CHAP builders write only a fixed-size message into it. The full
allocation length is then copied to the wire by nvmet_copy_to_sgl(), so a
remote initiator receives the bytes past the built message -- up to nearly
a page of uninitialized slab -- during the pre-authentication handshake.
Allocate the buffer with kzalloc() so the unwritten tail is zeroed before
it is sent; conforming responses are unaffected.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: db1312dd95488b5e6ff362ff66fcf953a46b1821 Version: db1312dd95488b5e6ff362ff66fcf953a46b1821 Version: db1312dd95488b5e6ff362ff66fcf953a46b1821 Version: db1312dd95488b5e6ff362ff66fcf953a46b1821 Version: db1312dd95488b5e6ff362ff66fcf953a46b1821 Version: db1312dd95488b5e6ff362ff66fcf953a46b1821 Version: db1312dd95488b5e6ff362ff66fcf953a46b1821 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/nvme/target/fabrics-cmd-auth.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "447b668faa14710f611e714031e3739ac3ec3a4f",
"status": "affected",
"version": "db1312dd95488b5e6ff362ff66fcf953a46b1821",
"versionType": "git"
},
{
"lessThan": "8f6363c8d54dde95982f0ab45e77cf57ec0efd62",
"status": "affected",
"version": "db1312dd95488b5e6ff362ff66fcf953a46b1821",
"versionType": "git"
},
{
"lessThan": "dfcf013f77709ebdb282767edc2795a37cab5b57",
"status": "affected",
"version": "db1312dd95488b5e6ff362ff66fcf953a46b1821",
"versionType": "git"
},
{
"lessThan": "b26189d28442183a8b5edb754f4a6918f77ca84e",
"status": "affected",
"version": "db1312dd95488b5e6ff362ff66fcf953a46b1821",
"versionType": "git"
},
{
"lessThan": "2dcc9226203da7275a9c29d20007da278d73d5e9",
"status": "affected",
"version": "db1312dd95488b5e6ff362ff66fcf953a46b1821",
"versionType": "git"
},
{
"lessThan": "1d6837d98bf966a041af65de5f78de7409ff83bc",
"status": "affected",
"version": "db1312dd95488b5e6ff362ff66fcf953a46b1821",
"versionType": "git"
},
{
"lessThan": "3ddcfb013322aa37eaa7a0d344b73079c38dfa21",
"status": "affected",
"version": "db1312dd95488b5e6ff362ff66fcf953a46b1821",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/nvme/target/fabrics-cmd-auth.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.0"
},
{
"lessThan": "6.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.185",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.154",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.106",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.47",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.1",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.185",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.154",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.106",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.47",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.11",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.1",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "6.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet-auth: zero the AUTH_RECEIVE response buffer\n\nnvmet_execute_auth_receive() allocates the response buffer with kmalloc()\nsized by the host-supplied AUTH_RECEIVE allocation length, but the\nDH-HMAC-CHAP builders write only a fixed-size message into it. The full\nallocation length is then copied to the wire by nvmet_copy_to_sgl(), so a\nremote initiator receives the bytes past the built message -- up to nearly\na page of uninitialized slab -- during the pre-authentication handshake.\n\nAllocate the buffer with kzalloc() so the unwritten tail is zeroed before\nit is sent; conforming responses are unaffected."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T15:13:03.204Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/447b668faa14710f611e714031e3739ac3ec3a4f"
},
{
"url": "https://git.kernel.org/stable/c/8f6363c8d54dde95982f0ab45e77cf57ec0efd62"
},
{
"url": "https://git.kernel.org/stable/c/dfcf013f77709ebdb282767edc2795a37cab5b57"
},
{
"url": "https://git.kernel.org/stable/c/b26189d28442183a8b5edb754f4a6918f77ca84e"
},
{
"url": "https://git.kernel.org/stable/c/2dcc9226203da7275a9c29d20007da278d73d5e9"
},
{
"url": "https://git.kernel.org/stable/c/1d6837d98bf966a041af65de5f78de7409ff83bc"
},
{
"url": "https://git.kernel.org/stable/c/3ddcfb013322aa37eaa7a0d344b73079c38dfa21"
}
],
"title": "nvmet-auth: zero the AUTH_RECEIVE response buffer",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80791",
"datePublished": "2026-09-04T15:13:03.204Z",
"dateReserved": "2026-08-26T14:34:25.793Z",
"dateUpdated": "2026-09-04T15:13:03.204Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68123 (GCVE-0-2026-68123)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-19 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
openvswitch: fix GSO userspace truncation underflow
OVS_ACTION_ATTR_TRUNC currently stores a delta from the original skb
length in OVS_CB(skb)->cutlen. When a later userspace action segments a
GSO skb, queue_gso_packets() reuses that delta for each smaller segment.
A segment can then reach queue_userspace_packet() with cutlen greater
than skb->len, underflowing the length passed to skb_zerocopy().
Store the maximum preserved length instead and bound each consumer
against the current skb length. Use U32_MAX as the no-truncation
sentinel so the value remains valid if skb geometry changes before a
consumer handles it.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: f2a4d086ed4c588d32fe9b7aa67fead7280e7bf1 Version: f2a4d086ed4c588d32fe9b7aa67fead7280e7bf1 Version: f2a4d086ed4c588d32fe9b7aa67fead7280e7bf1 Version: f2a4d086ed4c588d32fe9b7aa67fead7280e7bf1 Version: f2a4d086ed4c588d32fe9b7aa67fead7280e7bf1 Version: f2a4d086ed4c588d32fe9b7aa67fead7280e7bf1 Version: f2a4d086ed4c588d32fe9b7aa67fead7280e7bf1 Version: f2a4d086ed4c588d32fe9b7aa67fead7280e7bf1 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/openvswitch/actions.c",
"net/openvswitch/datapath.c",
"net/openvswitch/datapath.h",
"net/openvswitch/vport.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "50a6a85f3d6b1d22d8436848606cdef5d2c490b4",
"status": "affected",
"version": "f2a4d086ed4c588d32fe9b7aa67fead7280e7bf1",
"versionType": "git"
},
{
"lessThan": "2623c48cc3a8da9a1886fd8f65c0e348f4406fd6",
"status": "affected",
"version": "f2a4d086ed4c588d32fe9b7aa67fead7280e7bf1",
"versionType": "git"
},
{
"lessThan": "e211b081901ffca76674082c73eeaed53524c369",
"status": "affected",
"version": "f2a4d086ed4c588d32fe9b7aa67fead7280e7bf1",
"versionType": "git"
},
{
"lessThan": "a16eaaf7c0b0ccdef6166707d90ffbc6eebf6855",
"status": "affected",
"version": "f2a4d086ed4c588d32fe9b7aa67fead7280e7bf1",
"versionType": "git"
},
{
"lessThan": "fbfa3ad2ad6f3a5624aba5211c46290fb98cc9dc",
"status": "affected",
"version": "f2a4d086ed4c588d32fe9b7aa67fead7280e7bf1",
"versionType": "git"
},
{
"lessThan": "100a23b1613e9218e0af654ef102352c713f0263",
"status": "affected",
"version": "f2a4d086ed4c588d32fe9b7aa67fead7280e7bf1",
"versionType": "git"
},
{
"lessThan": "ea85dbcbe8d4056ecb54352f97743d138ea4c407",
"status": "affected",
"version": "f2a4d086ed4c588d32fe9b7aa67fead7280e7bf1",
"versionType": "git"
},
{
"lessThan": "4032f8ed10fcb84d41c508dfb04be96589f78dfe",
"status": "affected",
"version": "f2a4d086ed4c588d32fe9b7aa67fead7280e7bf1",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/openvswitch/actions.c",
"net/openvswitch/datapath.c",
"net/openvswitch/datapath.h",
"net/openvswitch/vport.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.8"
},
{
"lessThan": "4.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nopenvswitch: fix GSO userspace truncation underflow\n\nOVS_ACTION_ATTR_TRUNC currently stores a delta from the original skb\nlength in OVS_CB(skb)-\u003ecutlen. When a later userspace action segments a\nGSO skb, queue_gso_packets() reuses that delta for each smaller segment.\nA segment can then reach queue_userspace_packet() with cutlen greater\nthan skb-\u003elen, underflowing the length passed to skb_zerocopy().\n\nStore the maximum preserved length instead and bound each consumer\nagainst the current skb length. Use U32_MAX as the no-truncation\nsentinel so the value remains valid if skb geometry changes before a\nconsumer handles it."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - Ingress packets reach ovs_vport_receive() through netdev rx_handlers or tunnel vports; GRO-coalesced GSO skbs from remote senders traverse this path into queue_gso_packets(), so the underflow is reachable from the network without physical access.\nAC:L - The attacker chooses truncation max_len relative to GSO super-skb size and sends traffic that GRO segments predictably; no timing race or fragile heap layout is required to make cutlen exceed a child segment length after __skb_gso_segment().\nPR:N - In multi-tenant cloud/OVN deployments, a remote VM or container can send crafted GSO traffic into the host OVS datapath to hit provider-installed TRUNC+USERSPACE sampling flows without possessing any Linux capabilities on the host.\nUI:N - Triggering the flaw requires only network traffic matching existing OVS flow actions; no victim login, file open, mount, or other interactive step is needed.\nS:U - Impact is kernel memory corruption and crash/escalation within the host kernel security domain; it does not cross a guest-to-hypervisor, VM, or hardware IOMMU trust boundary by itself.\nC:H - Unsigned underflow makes skb-\u003elen-cutlen enormous for skb_zerocopy()/skb_copy_bits(), enabling out-of-bounds reads from the source skb and adjacent slab data, i.e., an exploitable information-disclosure primitive.\nI:H - The same underflowed length can expand destination skbs via skb_len_add()/nlattr sizing, corrupting kernel heap metadata and yielding a write primitive suitable for control-flow hijacking.\nA:H - The miscopied lengths can BUG the skb helpers or cause immediate kernel oops/panic during zerocopy/trim handling, and corrupted metadata can crash the system even if exploitation is not completed."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:29:34.391Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/50a6a85f3d6b1d22d8436848606cdef5d2c490b4"
},
{
"url": "https://git.kernel.org/stable/c/2623c48cc3a8da9a1886fd8f65c0e348f4406fd6"
},
{
"url": "https://git.kernel.org/stable/c/e211b081901ffca76674082c73eeaed53524c369"
},
{
"url": "https://git.kernel.org/stable/c/a16eaaf7c0b0ccdef6166707d90ffbc6eebf6855"
},
{
"url": "https://git.kernel.org/stable/c/fbfa3ad2ad6f3a5624aba5211c46290fb98cc9dc"
},
{
"url": "https://git.kernel.org/stable/c/100a23b1613e9218e0af654ef102352c713f0263"
},
{
"url": "https://git.kernel.org/stable/c/ea85dbcbe8d4056ecb54352f97743d138ea4c407"
},
{
"url": "https://git.kernel.org/stable/c/4032f8ed10fcb84d41c508dfb04be96589f78dfe"
}
],
"title": "openvswitch: fix GSO userspace truncation underflow",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68123",
"datePublished": "2026-08-10T11:58:43.727Z",
"dateReserved": "2026-07-30T09:28:09.369Z",
"dateUpdated": "2026-08-19T16:29:34.391Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74557 (GCVE-0-2026-74557)
Vulnerability from cvelistv5
Published
2026-08-15 12:28
Modified
2026-08-19 16:38
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
scsi: libiscsi: Fix stale-data leak into the SCSI sense buffer
iscsi_scsi_cmd_rsp() copies the sense data of a SCSI Response from the
target-supplied data segment. The segment carries a 2-byte sense length
followed by the sense bytes, so it must hold 2 + senselen bytes, but the
bounds check only requires datalen >= senselen:
senselen = get_unaligned_be16(data);
if (datalen < senselen)
goto invalid_datalen;
memcpy(sc->sense_buffer, data + 2,
min_t(uint16_t, senselen, SCSI_SENSE_BUFFERSIZE));
A target that returns a SCSI Response whose datalen equals senselen
(with senselen <= SCSI_SENSE_BUFFERSIZE) makes the memcpy() from data +
2 read up to two bytes past the received data. Those bytes are stale
conn->data contents and end up in the command's sense buffer, which is
returned to userspace.
Account for the 2-byte sense length prefix in the check.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 7996a778ff8c717cb1a7a294475c59cc8f1e9fb8 Version: 7996a778ff8c717cb1a7a294475c59cc8f1e9fb8 Version: 7996a778ff8c717cb1a7a294475c59cc8f1e9fb8 Version: 7996a778ff8c717cb1a7a294475c59cc8f1e9fb8 Version: 7996a778ff8c717cb1a7a294475c59cc8f1e9fb8 Version: 7996a778ff8c717cb1a7a294475c59cc8f1e9fb8 Version: 7996a778ff8c717cb1a7a294475c59cc8f1e9fb8 Version: 7996a778ff8c717cb1a7a294475c59cc8f1e9fb8 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/scsi/libiscsi.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "812f1ae95b22419422972748f173b0916ee4d621",
"status": "affected",
"version": "7996a778ff8c717cb1a7a294475c59cc8f1e9fb8",
"versionType": "git"
},
{
"lessThan": "fef6167e8149896cd81bea333fd51b1c91239149",
"status": "affected",
"version": "7996a778ff8c717cb1a7a294475c59cc8f1e9fb8",
"versionType": "git"
},
{
"lessThan": "baa04572673125e4d5bc309b4077d1cb46cc78d1",
"status": "affected",
"version": "7996a778ff8c717cb1a7a294475c59cc8f1e9fb8",
"versionType": "git"
},
{
"lessThan": "7567f06abdefb1caf2d836107c4d08c5185c650e",
"status": "affected",
"version": "7996a778ff8c717cb1a7a294475c59cc8f1e9fb8",
"versionType": "git"
},
{
"lessThan": "60499924faf4ef97e84228c20515218ef121facf",
"status": "affected",
"version": "7996a778ff8c717cb1a7a294475c59cc8f1e9fb8",
"versionType": "git"
},
{
"lessThan": "3ef209ca0b4b68c75e9a814d90cc916026b5a6ac",
"status": "affected",
"version": "7996a778ff8c717cb1a7a294475c59cc8f1e9fb8",
"versionType": "git"
},
{
"lessThan": "1f07a897d43c63e6c9458bf77450defef39b5833",
"status": "affected",
"version": "7996a778ff8c717cb1a7a294475c59cc8f1e9fb8",
"versionType": "git"
},
{
"lessThan": "98b87885de4b7f605533a2860685f5689fce8e82",
"status": "affected",
"version": "7996a778ff8c717cb1a7a294475c59cc8f1e9fb8",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/scsi/libiscsi.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.18"
},
{
"lessThan": "2.6.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "2.6.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "2.6.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "2.6.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "2.6.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.18",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: libiscsi: Fix stale-data leak into the SCSI sense buffer\n\niscsi_scsi_cmd_rsp() copies the sense data of a SCSI Response from the\ntarget-supplied data segment. The segment carries a 2-byte sense length\nfollowed by the sense bytes, so it must hold 2 + senselen bytes, but the\nbounds check only requires datalen \u003e= senselen:\n\n\tsenselen = get_unaligned_be16(data);\n\tif (datalen \u003c senselen)\n\t\tgoto invalid_datalen;\n\tmemcpy(sc-\u003esense_buffer, data + 2,\n\t min_t(uint16_t, senselen, SCSI_SENSE_BUFFERSIZE));\n\nA target that returns a SCSI Response whose datalen equals senselen\n(with senselen \u003c= SCSI_SENSE_BUFFERSIZE) makes the memcpy() from data +\n2 read up to two bytes past the received data. Those bytes are stale\nconn-\u003edata contents and end up in the command\u0027s sense buffer, which is\nreturned to userspace.\n\nAccount for the 2-byte sense length prefix in the check."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - A remote malicious or compromised iSCSI target can trigger the bug by sending a crafted SCSI Command Response over the standard iSCSI/TCP session to a Linux kernel initiator, with no local access required on the victim host.\nAC:L - The attacker fully controls the response PDU fields (datalen, sense length, CHECK_CONDITION status) and can reliably set datalen equal to senselen so the flawed bounds check passes and stale conn-\u003edata bytes are copied into the sense buffer.\nPR:N - Exploitation requires only the ability to act as the iSCSI target on the network; the attacker needs no local account, capabilities, or privileges on the victim system initiating the connection.\nUI:N - Once an iSCSI session exists, the leak is triggered automatically on SCSI command responses with no further victim action; the attacker does not rely on a user opening a file, clicking a link, or performing any interactive step at exploit time.\nS:U - The flaw discloses kernel memory contents into a SCSI sense buffer returned within the same host security domain; it does not cross VM, hypervisor, or IOMMU boundaries and is a standard kernel-to-userspace information leak.\nC:H - The out-of-bounds memcpy reads up to two bytes per response from stale conn-\u003edata kernel heap memory into sc-\u003esense_buffer, which is copied to userspace via SCSI completion, ioctl, and BSG paths, enabling repeated kernel information disclosure.\nI:N - The vulnerability is a read-only out-of-bounds memcpy from the receive buffer into the sense buffer; it does not corrupt kernel structures, overwrite memory, or provide a write or code-execution primitive.\nA:N - The bug causes no kernel panic, oops, or hang; invalid responses are handled gracefully and exploitation only leaks data into the sense buffer without disrupting system availability."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:38:59.951Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/812f1ae95b22419422972748f173b0916ee4d621"
},
{
"url": "https://git.kernel.org/stable/c/fef6167e8149896cd81bea333fd51b1c91239149"
},
{
"url": "https://git.kernel.org/stable/c/baa04572673125e4d5bc309b4077d1cb46cc78d1"
},
{
"url": "https://git.kernel.org/stable/c/7567f06abdefb1caf2d836107c4d08c5185c650e"
},
{
"url": "https://git.kernel.org/stable/c/60499924faf4ef97e84228c20515218ef121facf"
},
{
"url": "https://git.kernel.org/stable/c/3ef209ca0b4b68c75e9a814d90cc916026b5a6ac"
},
{
"url": "https://git.kernel.org/stable/c/1f07a897d43c63e6c9458bf77450defef39b5833"
},
{
"url": "https://git.kernel.org/stable/c/98b87885de4b7f605533a2860685f5689fce8e82"
}
],
"title": "scsi: libiscsi: Fix stale-data leak into the SCSI sense buffer",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74557",
"datePublished": "2026-08-15T12:28:01.988Z",
"dateReserved": "2026-08-15T05:44:03.916Z",
"dateUpdated": "2026-08-19T16:38:59.951Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74550 (GCVE-0-2026-74550)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-19 16:38
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: do not send ICMP/NDISC Redirects when peer allocation fails
When inet_getpeer_v4() or inet_getpeer_v6() fails to allocate a peer entry
under memory pressure or tree size caps, redirect handlers previously fell
back to sending un-rate-limited ICMP/NDISC Redirect messages.
In IPv4, ip_rt_send_redirect() called icmp_send() directly when peer == NULL.
In IPv6, ip6_forward() and ndisc_send_redirect() passed a NULL peer into
inet_peer_xrlim_allow(), which returned true when peer == NULL.
Because ICMP/NDISC Redirects are not part of the default global rate limit
mask (sysctl_icmp_ratemask), sending redirects when peer == NULL creates
an un-rate-limited ICMP packet storm.
Fix this by failing closed in ip_rt_send_redirect(), ip6_forward(), and
ndisc_send_redirect() when peer is NULL.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 92d8682926342d2b6aa5b2ecc02221e00e1573a0 Version: 92d8682926342d2b6aa5b2ecc02221e00e1573a0 Version: 92d8682926342d2b6aa5b2ecc02221e00e1573a0 Version: 92d8682926342d2b6aa5b2ecc02221e00e1573a0 Version: 92d8682926342d2b6aa5b2ecc02221e00e1573a0 Version: 92d8682926342d2b6aa5b2ecc02221e00e1573a0 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ipv4/route.c",
"net/ipv6/ip6_output.c",
"net/ipv6/ndisc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c0adf8b4247bcc5a145a25c1929006eb392580bb",
"status": "affected",
"version": "92d8682926342d2b6aa5b2ecc02221e00e1573a0",
"versionType": "git"
},
{
"lessThan": "f5ecaa7ea7686fa7ecdb6affc9d3a9a42e4524b1",
"status": "affected",
"version": "92d8682926342d2b6aa5b2ecc02221e00e1573a0",
"versionType": "git"
},
{
"lessThan": "21666f7af49a90ef44d474916b8ef4402dfd74f5",
"status": "affected",
"version": "92d8682926342d2b6aa5b2ecc02221e00e1573a0",
"versionType": "git"
},
{
"lessThan": "5ec5f00fc606a6df8434948c4552b3cb1176595d",
"status": "affected",
"version": "92d8682926342d2b6aa5b2ecc02221e00e1573a0",
"versionType": "git"
},
{
"lessThan": "828f6670d110ff2bf44c743037b38badc315704c",
"status": "affected",
"version": "92d8682926342d2b6aa5b2ecc02221e00e1573a0",
"versionType": "git"
},
{
"lessThan": "dbc3791e3b2472e1ccc08947e0f83b443470ff4f",
"status": "affected",
"version": "92d8682926342d2b6aa5b2ecc02221e00e1573a0",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ipv4/route.c",
"net/ipv6/ip6_output.c",
"net/ipv6/ndisc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.39"
},
{
"lessThan": "2.6.39",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.39",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "2.6.39",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "2.6.39",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "2.6.39",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "2.6.39",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.39",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: do not send ICMP/NDISC Redirects when peer allocation fails\n\nWhen inet_getpeer_v4() or inet_getpeer_v6() fails to allocate a peer entry\nunder memory pressure or tree size caps, redirect handlers previously fell\nback to sending un-rate-limited ICMP/NDISC Redirect messages.\n\nIn IPv4, ip_rt_send_redirect() called icmp_send() directly when peer == NULL.\nIn IPv6, ip6_forward() and ndisc_send_redirect() passed a NULL peer into\ninet_peer_xrlim_allow(), which returned true when peer == NULL.\n\nBecause ICMP/NDISC Redirects are not part of the default global rate limit\nmask (sysctl_icmp_ratemask), sending redirects when peer == NULL creates\nan un-rate-limited ICMP packet storm.\n\nFix this by failing closed in ip_rt_send_redirect(), ip6_forward(), and\nndisc_send_redirect() when peer is NULL."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The flaw is in IPv4/IPv6 packet forwarding paths (ip_forward/ip6_forward) reached when a remote host sends IP traffic processed by a forwarding router; this is standard net stack input handling, not a local-only API.\nAC:L - An attacker can reliably trigger redirect-eligible forwarded packets, flood unique source/destination addresses to stress inet_peer allocation, and induce memory pressure so peer allocation fails, controlling the conditions needed for the un-rate-limited redirect storm.\nPR:N - Exploitation requires only the ability to send IP packets to a forwarding host; no local account, capabilities, or authentication on the victim is needed.\nUI:N - No victim user action is required; the redirect storm is triggered entirely by attacker-sent network packets processed during kernel forwarding.\nS:U - Impact is confined to the kernel/network stack of the targeted forwarding system and its network availability; it does not cross VM, container, or IOMMU security boundaries.\nC:N - The bug bypasses redirect rate limiting to generate ICMP/NDISC storms; it does not involve memory corruption, out-of-bounds access, or unintended disclosure of sensitive kernel memory.\nI:N - The vulnerability causes excessive transmission of otherwise-valid redirect messages; it does not grant arbitrary data modification, code execution, or attacker-controlled corruption of kernel or application state.\nA:H - When peer allocation fails, ICMP/NDISC Redirects are sent without any rate limit (excluded from sysctl_icmp_ratemask), enabling a sustained packet storm that can exhaust CPU, memory, and bandwidth and deny service to the router and adjacent networks."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:38:44.870Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c0adf8b4247bcc5a145a25c1929006eb392580bb"
},
{
"url": "https://git.kernel.org/stable/c/f5ecaa7ea7686fa7ecdb6affc9d3a9a42e4524b1"
},
{
"url": "https://git.kernel.org/stable/c/21666f7af49a90ef44d474916b8ef4402dfd74f5"
},
{
"url": "https://git.kernel.org/stable/c/5ec5f00fc606a6df8434948c4552b3cb1176595d"
},
{
"url": "https://git.kernel.org/stable/c/828f6670d110ff2bf44c743037b38badc315704c"
},
{
"url": "https://git.kernel.org/stable/c/dbc3791e3b2472e1ccc08947e0f83b443470ff4f"
}
],
"title": "net: do not send ICMP/NDISC Redirects when peer allocation fails",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74550",
"datePublished": "2026-08-15T12:27:57.615Z",
"dateReserved": "2026-08-15T05:44:03.915Z",
"dateUpdated": "2026-08-19T16:38:44.870Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80726 (GCVE-0-2026-80726)
Vulnerability from cvelistv5
Published
2026-09-03 08:21
Modified
2026-09-04 04:58
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page
Explicitly clear role.invalid when deriving a child shadow page's role from
its parent to harden against bugs elsewhere in KVM, as violating KVM's
invariant that invalid pages are NOT on the list of active MMU pages leads
to use-after-free due to __kvm_mmu_prepare_zap_page() using list_add()
instead of list_move() when processing an invalid shadow page, i.e. makes a
bad situation far worse.
Yell loudly if the parent is invalid, as it means KVM has missed a validity
check, i.e. KVM is attempting to map memory using an invalid/obsolete root,
but continue on as the child is otherwise still a valid shadow page.
==================================================================
BUG: KASAN: slab-use-after-free in __kvm_mmu_get_shadow_page+0x1817/0x1860 [kvm]
Write of size 8 at addr ff11000153dd1368 by task repro/853
CPU: 1 UID: 1000 PID: 853 Comm: repro Not tainted 7.2.0-rc2-3aec122bdcaf-next-vm #5 PREEMPT
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 0.0.0 02/06/2015
Call Trace:
<TASK>
dump_stack_lvl+0x4b/0x70
print_report+0x153/0x49c
kasan_report+0xbc/0xf0
__kvm_mmu_get_shadow_page+0x1817/0x1860 [kvm]
mmu_alloc_root+0x141/0x320 [kvm]
kvm_mmu_load+0x612/0x20f0 [kvm]
kvm_arch_vcpu_ioctl_run+0x3dd5/0x6150 [kvm]
kvm_vcpu_ioctl+0x5e4/0x10d0 [kvm]
__x64_sys_ioctl+0x131/0x1b0
do_syscall_64+0x67/0x5f0
entry_SYSCALL_64_after_hwframe+0x4b/0x53
</TASK>
Allocated by task 853:
kasan_save_stack+0x20/0x40
kasan_save_track+0x14/0x30
__kasan_slab_alloc+0x5f/0x70
kmem_cache_alloc_noprof+0xfe/0x2e0
__kvm_mmu_topup_memory_cache+0x135/0x530 [kvm]
paging64_page_fault+0x318/0x1e30 [kvm]
kvm_mmu_do_page_fault+0x21d/0x630 [kvm]
kvm_mmu_page_fault+0x18c/0x17b0 [kvm]
kvm_arch_vcpu_ioctl_run+0x1f35/0x6150 [kvm]
kvm_vcpu_ioctl+0x5e4/0x10d0 [kvm]
__x64_sys_ioctl+0x131/0x1b0
do_syscall_64+0x67/0x5f0
entry_SYSCALL_64_after_hwframe+0x4b/0x53
Freed by task 853:
kasan_save_stack+0x20/0x40
kasan_save_track+0x14/0x30
kasan_save_free_info+0x3b/0x60
__kasan_slab_free+0x43/0x70
kmem_cache_free+0xe2/0x400
kvm_mmu_commit_zap_page.part.0+0x1e2/0x310 [kvm]
kvm_mmu_free_roots+0x283/0x560 [kvm]
kvm_arch_vcpu_ioctl_run+0x33c8/0x6150 [kvm]
kvm_vcpu_ioctl+0x5e4/0x10d0 [kvm]
__x64_sys_ioctl+0x131/0x1b0
do_syscall_64+0x67/0x5f0
entry_SYSCALL_64_after_hwframe+0x4b/0x53
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: a770f6f28b1a9287189f3dc8333eb694d9a2f0ab Version: a770f6f28b1a9287189f3dc8333eb694d9a2f0ab Version: a770f6f28b1a9287189f3dc8333eb694d9a2f0ab Version: a770f6f28b1a9287189f3dc8333eb694d9a2f0ab Version: a770f6f28b1a9287189f3dc8333eb694d9a2f0ab Version: a770f6f28b1a9287189f3dc8333eb694d9a2f0ab |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"arch/x86/kvm/mmu/mmu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "9b7984692c18b22d6d61af3f53887fca7fddb0f1",
"status": "affected",
"version": "a770f6f28b1a9287189f3dc8333eb694d9a2f0ab",
"versionType": "git"
},
{
"lessThan": "f33ecb89d352348ed5e625f6747ac51ede254e1b",
"status": "affected",
"version": "a770f6f28b1a9287189f3dc8333eb694d9a2f0ab",
"versionType": "git"
},
{
"lessThan": "0af4711862c5b818204d40b21f0859ad51c230e9",
"status": "affected",
"version": "a770f6f28b1a9287189f3dc8333eb694d9a2f0ab",
"versionType": "git"
},
{
"lessThan": "66bc868a33cf1de43f22a94acd8857e0fe33393f",
"status": "affected",
"version": "a770f6f28b1a9287189f3dc8333eb694d9a2f0ab",
"versionType": "git"
},
{
"lessThan": "9f7760a2e962cbda0d096a27d394d14ad4d22928",
"status": "affected",
"version": "a770f6f28b1a9287189f3dc8333eb694d9a2f0ab",
"versionType": "git"
},
{
"lessThan": "5ec42d57655c690234c14aece6dd3f209778c1d8",
"status": "affected",
"version": "a770f6f28b1a9287189f3dc8333eb694d9a2f0ab",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"arch/x86/kvm/mmu/mmu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.30"
},
{
"lessThan": "2.6.30",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "2.6.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "2.6.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "2.6.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "2.6.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.30",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page\n\nExplicitly clear role.invalid when deriving a child shadow page\u0027s role from\nits parent to harden against bugs elsewhere in KVM, as violating KVM\u0027s\ninvariant that invalid pages are NOT on the list of active MMU pages leads\nto use-after-free due to __kvm_mmu_prepare_zap_page() using list_add()\ninstead of list_move() when processing an invalid shadow page, i.e. makes a\nbad situation far worse.\n\nYell loudly if the parent is invalid, as it means KVM has missed a validity\ncheck, i.e. KVM is attempting to map memory using an invalid/obsolete root,\nbut continue on as the child is otherwise still a valid shadow page.\n\n ==================================================================\n BUG: KASAN: slab-use-after-free in __kvm_mmu_get_shadow_page+0x1817/0x1860 [kvm]\n Write of size 8 at addr ff11000153dd1368 by task repro/853\n\n CPU: 1 UID: 1000 PID: 853 Comm: repro Not tainted 7.2.0-rc2-3aec122bdcaf-next-vm #5 PREEMPT\n Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 0.0.0 02/06/2015\n Call Trace:\n \u003cTASK\u003e\n dump_stack_lvl+0x4b/0x70\n print_report+0x153/0x49c\n kasan_report+0xbc/0xf0\n __kvm_mmu_get_shadow_page+0x1817/0x1860 [kvm]\n mmu_alloc_root+0x141/0x320 [kvm]\n kvm_mmu_load+0x612/0x20f0 [kvm]\n kvm_arch_vcpu_ioctl_run+0x3dd5/0x6150 [kvm]\n kvm_vcpu_ioctl+0x5e4/0x10d0 [kvm]\n __x64_sys_ioctl+0x131/0x1b0\n do_syscall_64+0x67/0x5f0\n entry_SYSCALL_64_after_hwframe+0x4b/0x53\n \u003c/TASK\u003e\n\n Allocated by task 853:\n kasan_save_stack+0x20/0x40\n kasan_save_track+0x14/0x30\n __kasan_slab_alloc+0x5f/0x70\n kmem_cache_alloc_noprof+0xfe/0x2e0\n __kvm_mmu_topup_memory_cache+0x135/0x530 [kvm]\n paging64_page_fault+0x318/0x1e30 [kvm]\n kvm_mmu_do_page_fault+0x21d/0x630 [kvm]\n kvm_mmu_page_fault+0x18c/0x17b0 [kvm]\n kvm_arch_vcpu_ioctl_run+0x1f35/0x6150 [kvm]\n kvm_vcpu_ioctl+0x5e4/0x10d0 [kvm]\n __x64_sys_ioctl+0x131/0x1b0\n do_syscall_64+0x67/0x5f0\n entry_SYSCALL_64_after_hwframe+0x4b/0x53\n\n Freed by task 853:\n kasan_save_stack+0x20/0x40\n kasan_save_track+0x14/0x30\n kasan_save_free_info+0x3b/0x60\n __kasan_slab_free+0x43/0x70\n kmem_cache_free+0xe2/0x400\n kvm_mmu_commit_zap_page.part.0+0x1e2/0x310 [kvm]\n kvm_mmu_free_roots+0x283/0x560 [kvm]\n kvm_arch_vcpu_ioctl_run+0x33c8/0x6150 [kvm]\n kvm_vcpu_ioctl+0x5e4/0x10d0 [kvm]\n __x64_sys_ioctl+0x131/0x1b0\n do_syscall_64+0x67/0x5f0\n entry_SYSCALL_64_after_hwframe+0x4b/0x53"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.3,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached only through host KVM x86 shadow-MMU handling on the KVM_RUN ioctl path (kvm_arch_vcpu_ioctl_run -\u003e kvm_mmu_page_fault/kvm_mmu_load -\u003e __kvm_mmu_get_shadow_page), driven by guest page faults and root reloads, not by remote network or physical input.\nAC:L - The reproducer (UID 1000) triggers this reliably by combining guest page-table churn with MMU reclaim (make_mmu_pages_available/kvm_mmu_zap_oldest_mmu_pages) so an in-use root is zapped invalid while children are still created; the attacker controls both fault and reclaim sides of the race.\nPR:N - Exploitation requires only code running inside an already-running KVM guest (or equivalent guest-driven KVM_RUN activity); no host root, CAP_SYS_ADMIN, or direct /dev/kvm access is needed beyond what any cloud VM tenant or compromised guest process already has.\nUI:N - Once the attacker can execute in the guest, triggering the fault/reclaim sequence is entirely self-driven through guest memory and paging behavior with no action required from another user or administrator.\nS:C - Corrupting host KVM MMU active_mmu_pages/list state from guest-controlled faults crosses the guest-to-host virtualization boundary and can compromise the host kernel beyond the guest security domain, enabling VM escape-class impact.\nC:H - The demonstrated slab use-after-free and broken active-list invariant (invalid children left linked while __kvm_mmu_prepare_zap_page uses list_add instead of list_move) provide attacker-influenced host heap corruption that can be leveraged for arbitrary kernel memory reads.\nI:H - The same UAF and doubly-linked list corruption on host kvm_mmu_page objects are writable memory-corruption primitives suitable for control-flow or structure hijacking, not merely benign accounting errors.\nA:H - KASAN reports a host slab UAF with an 8-byte write in __kvm_mmu_get_shadow_page, and list corruption on active_mmu_pages can cause host oops, panic, or hang, denying service to the host and co-located VMs."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T04:58:16.442Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/9b7984692c18b22d6d61af3f53887fca7fddb0f1"
},
{
"url": "https://git.kernel.org/stable/c/f33ecb89d352348ed5e625f6747ac51ede254e1b"
},
{
"url": "https://git.kernel.org/stable/c/0af4711862c5b818204d40b21f0859ad51c230e9"
},
{
"url": "https://git.kernel.org/stable/c/66bc868a33cf1de43f22a94acd8857e0fe33393f"
},
{
"url": "https://git.kernel.org/stable/c/9f7760a2e962cbda0d096a27d394d14ad4d22928"
},
{
"url": "https://git.kernel.org/stable/c/5ec42d57655c690234c14aece6dd3f209778c1d8"
}
],
"title": "KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80726",
"datePublished": "2026-09-03T08:21:45.923Z",
"dateReserved": "2026-08-26T14:34:25.789Z",
"dateUpdated": "2026-09-04T04:58:16.442Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68125 (GCVE-0-2026-68125)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-19 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
mac802154: llsec: reject frames shorter than the authentication tag
llsec_do_decrypt_auth() computes the associated-data length for the
AEAD request as
assoclen += datalen - authlen;
where datalen is the number of bytes after the MAC header and authlen
(4, 8 or 16) is the length of the authentication tag. Nothing verifies
that the frame actually carries at least authlen payload bytes. A
secured frame whose payload is shorter than the tag makes
datalen - authlen negative; assoclen is then passed to
aead_request_set_ad() as an unsigned value close to 4 GiB, so
crypto_aead_decrypt() walks far off the end of the scatterlist that
only spans the real frame.
The frame is fully attacker-controlled and reaches this path from any
IEEE 802.15.4 peer in radio range. Reject frames whose payload is
shorter than the authentication tag before the subtraction.
Dynamically reproduced on a KASAN kernel as a general-protection-fault
in the AEAD scatterwalk, and the fix confirmed.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 4c14a2fb5d143e4ed94143be2b8c1961b47df9af Version: 4c14a2fb5d143e4ed94143be2b8c1961b47df9af Version: 4c14a2fb5d143e4ed94143be2b8c1961b47df9af Version: 4c14a2fb5d143e4ed94143be2b8c1961b47df9af Version: 4c14a2fb5d143e4ed94143be2b8c1961b47df9af Version: 4c14a2fb5d143e4ed94143be2b8c1961b47df9af Version: 4c14a2fb5d143e4ed94143be2b8c1961b47df9af Version: 4c14a2fb5d143e4ed94143be2b8c1961b47df9af |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/mac802154/llsec.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "f27ce82eb04960465df71634b196a48a4ecafd50",
"status": "affected",
"version": "4c14a2fb5d143e4ed94143be2b8c1961b47df9af",
"versionType": "git"
},
{
"lessThan": "2d6b42a61373144298070668fddf06efe79cf2ff",
"status": "affected",
"version": "4c14a2fb5d143e4ed94143be2b8c1961b47df9af",
"versionType": "git"
},
{
"lessThan": "ec7e62d77193131227df49d654d118fdf5a59892",
"status": "affected",
"version": "4c14a2fb5d143e4ed94143be2b8c1961b47df9af",
"versionType": "git"
},
{
"lessThan": "5bbf0cd9b6a7076af86c75e87e180099be2e11ae",
"status": "affected",
"version": "4c14a2fb5d143e4ed94143be2b8c1961b47df9af",
"versionType": "git"
},
{
"lessThan": "de80808f37d99c6dc67bb6f97eea00c8f57a8821",
"status": "affected",
"version": "4c14a2fb5d143e4ed94143be2b8c1961b47df9af",
"versionType": "git"
},
{
"lessThan": "f20dedce0429b293d4bad604e0d3f65d8ac96c83",
"status": "affected",
"version": "4c14a2fb5d143e4ed94143be2b8c1961b47df9af",
"versionType": "git"
},
{
"lessThan": "e09e0301d616c1ef38a5e64e8e4326fd39df13cc",
"status": "affected",
"version": "4c14a2fb5d143e4ed94143be2b8c1961b47df9af",
"versionType": "git"
},
{
"lessThan": "fd3a3f28ed60c6af4b2a39933b151d6b27842c3b",
"status": "affected",
"version": "4c14a2fb5d143e4ed94143be2b8c1961b47df9af",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/mac802154/llsec.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.16"
},
{
"lessThan": "3.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.16",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmac802154: llsec: reject frames shorter than the authentication tag\n\nllsec_do_decrypt_auth() computes the associated-data length for the\nAEAD request as\n\n\tassoclen += datalen - authlen;\n\nwhere datalen is the number of bytes after the MAC header and authlen\n(4, 8 or 16) is the length of the authentication tag. Nothing verifies\nthat the frame actually carries at least authlen payload bytes. A\nsecured frame whose payload is shorter than the tag makes\ndatalen - authlen negative; assoclen is then passed to\naead_request_set_ad() as an unsigned value close to 4 GiB, so\ncrypto_aead_decrypt() walks far off the end of the scatterlist that\nonly spans the real frame.\n\nThe frame is fully attacker-controlled and reaches this path from any\nIEEE 802.15.4 peer in radio range. Reject frames whose payload is\nshorter than the authentication tag before the subtraction.\n\nDynamically reproduced on a KASAN kernel as a general-protection-fault\nin the AEAD scatterwalk, and the fix confirmed."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - Exploitation requires sending crafted IEEE 802.15.4 frames over the WPAN radio interface; any peer within RF range can reach mac802154 receive/decrypt without IP routing or local shell access, matching Adjacent wireless attack guidance like Bluetooth.\nAC:L - The attacker fully controls frame length and security header fields; once LLSEC is enabled on the victim, a single undersized MIC-only secured frame reliably triggers the assoclen underflow and was dynamically reproduced as a KASAN GPF.\nPR:N - No Linux credentials or capabilities are required on the target; exploitation is performed by an over-the-air 802.15.4 peer spoofing a known PAN device/key/frame counter, not via local syscalls, ioctl, or netlink.\nUI:N - No victim user action is needed beyond normal operation of an LLSEC-enabled 802.15.4 interface; the malicious frame is processed automatically in the softirq receive path before delivery to userspace.\nS:U - Impact is confined to kernel memory and availability on the attacked host\u0027s WPAN stack; it does not cross a VM, container, or IOMMU security boundary into a separate authority.\nC:H - The wrapped assoclen makes crypto_aead_decrypt() scatterwalk read gigabytes beyond the skb-backed scatterlist, causing out-of-bounds kernel memory reads that can disclose adjacent heap or slab data and enable further exploitation primitives.\nI:H - Kernel memory corruption in the AEAD decrypt scatterwalk path can be leveraged for control-flow hijack or arbitrary write primitives beyond the demonstrated crash, consistent with high integrity impact for exploitable OOB access in crypto handlers.\nA:H - The bug was reproduced on a KASAN kernel as a general-protection fault in the AEAD scatterwalk, and repeated malicious frames can panic or hang the kernel on LLSEC-enabled coordinators, gateways, and IoT border routers."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:29:39.507Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/f27ce82eb04960465df71634b196a48a4ecafd50"
},
{
"url": "https://git.kernel.org/stable/c/2d6b42a61373144298070668fddf06efe79cf2ff"
},
{
"url": "https://git.kernel.org/stable/c/ec7e62d77193131227df49d654d118fdf5a59892"
},
{
"url": "https://git.kernel.org/stable/c/5bbf0cd9b6a7076af86c75e87e180099be2e11ae"
},
{
"url": "https://git.kernel.org/stable/c/de80808f37d99c6dc67bb6f97eea00c8f57a8821"
},
{
"url": "https://git.kernel.org/stable/c/f20dedce0429b293d4bad604e0d3f65d8ac96c83"
},
{
"url": "https://git.kernel.org/stable/c/e09e0301d616c1ef38a5e64e8e4326fd39df13cc"
},
{
"url": "https://git.kernel.org/stable/c/fd3a3f28ed60c6af4b2a39933b151d6b27842c3b"
}
],
"title": "mac802154: llsec: reject frames shorter than the authentication tag",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68125",
"datePublished": "2026-08-10T11:58:46.198Z",
"dateReserved": "2026-07-30T09:28:09.369Z",
"dateUpdated": "2026-08-19T16:29:39.507Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68284 (GCVE-0-2026-68284)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-19 16:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg()
tcp_bpf_sendmsg() keeps msg_tx across sk_stream_wait_memory(), which
drops and reacquires the socket lock. Its error path tries to decide
whether msg_tx names the local temporary message by comparing it with
the current value of psock->cork.
This comparison is unsafe when two threads send on the same socket:
Thread A Thread B
msg_tx = psock->cork
sk_msg_alloc() fails
sk_stream_wait_memory()
releases the socket lock acquires the socket lock
completes the cork
psock->cork = NULL
frees the cork
reacquires the socket lock
msg_tx != psock->cork
sk_msg_free(msg_tx)
The stale cork is therefore mistaken for the local temporary message
and freed again. KASAN reported:
BUG: KASAN: slab-use-after-free in sk_msg_free+0x49/0x50
Read of size 4 at addr ffff88810c908800 by task poc/90
Call Trace:
sk_msg_free+0x49/0x50
tcp_bpf_sendmsg+0x14f5/0x1cc0
__sys_sendto+0x32c/0x3a0
__x64_sys_sendto+0xdb/0x1b0
Allocated by task 89:
__kasan_kmalloc+0x8f/0xa0
tcp_bpf_sendmsg+0x16b3/0x1cc0
Freed by task 91:
__kasan_slab_free+0x43/0x70
kfree+0x131/0x3c0
tcp_bpf_sendmsg+0xec3/0x1cc0
msg_tx can only name the stack-local tmp or the shared cork. Check for
tmp directly so a changed psock->cork cannot turn a shared message into
an apparent local one.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 604326b41a6fb9b4a78b6179335decee0365cd8c Version: 604326b41a6fb9b4a78b6179335decee0365cd8c Version: 604326b41a6fb9b4a78b6179335decee0365cd8c Version: 604326b41a6fb9b4a78b6179335decee0365cd8c Version: 604326b41a6fb9b4a78b6179335decee0365cd8c Version: 604326b41a6fb9b4a78b6179335decee0365cd8c Version: 604326b41a6fb9b4a78b6179335decee0365cd8c Version: 604326b41a6fb9b4a78b6179335decee0365cd8c |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ipv4/tcp_bpf.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "0688e6fe599d2d39147ae9ece97944c6e1815ebf",
"status": "affected",
"version": "604326b41a6fb9b4a78b6179335decee0365cd8c",
"versionType": "git"
},
{
"lessThan": "b2bcbeabfd843d47468fa095b1bd08ddb90cf616",
"status": "affected",
"version": "604326b41a6fb9b4a78b6179335decee0365cd8c",
"versionType": "git"
},
{
"lessThan": "54be47e7cbb936429c3bbdfc526ea943954aaf80",
"status": "affected",
"version": "604326b41a6fb9b4a78b6179335decee0365cd8c",
"versionType": "git"
},
{
"lessThan": "ee762f684eefa59de34d9ed93cab08336e834f47",
"status": "affected",
"version": "604326b41a6fb9b4a78b6179335decee0365cd8c",
"versionType": "git"
},
{
"lessThan": "cde4d6bcd9b73073c66498f6723c7b364c4dbc18",
"status": "affected",
"version": "604326b41a6fb9b4a78b6179335decee0365cd8c",
"versionType": "git"
},
{
"lessThan": "786d690257ec7a0c839f8710456e444ce3f1348b",
"status": "affected",
"version": "604326b41a6fb9b4a78b6179335decee0365cd8c",
"versionType": "git"
},
{
"lessThan": "752b1159ed5d0c48fe169a3721b96660a9822aa1",
"status": "affected",
"version": "604326b41a6fb9b4a78b6179335decee0365cd8c",
"versionType": "git"
},
{
"lessThan": "2d66a033864e27ab8d5e44cb36f31d9d2413bee4",
"status": "affected",
"version": "604326b41a6fb9b4a78b6179335decee0365cd8c",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ipv4/tcp_bpf.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.20"
},
{
"lessThan": "4.20",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.20",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg()\n\ntcp_bpf_sendmsg() keeps msg_tx across sk_stream_wait_memory(), which\ndrops and reacquires the socket lock. Its error path tries to decide\nwhether msg_tx names the local temporary message by comparing it with\nthe current value of psock-\u003ecork.\n\nThis comparison is unsafe when two threads send on the same socket:\n\n Thread A Thread B\n msg_tx = psock-\u003ecork\n sk_msg_alloc() fails\n sk_stream_wait_memory()\n releases the socket lock acquires the socket lock\n completes the cork\n psock-\u003ecork = NULL\n frees the cork\n reacquires the socket lock\n msg_tx != psock-\u003ecork\n sk_msg_free(msg_tx)\n\nThe stale cork is therefore mistaken for the local temporary message\nand freed again. KASAN reported:\n\n BUG: KASAN: slab-use-after-free in sk_msg_free+0x49/0x50\n Read of size 4 at addr ffff88810c908800 by task poc/90\n Call Trace:\n sk_msg_free+0x49/0x50\n tcp_bpf_sendmsg+0x14f5/0x1cc0\n __sys_sendto+0x32c/0x3a0\n __x64_sys_sendto+0xdb/0x1b0\n Allocated by task 89:\n __kasan_kmalloc+0x8f/0xa0\n tcp_bpf_sendmsg+0x16b3/0x1cc0\n Freed by task 91:\n __kasan_slab_free+0x43/0x70\n kfree+0x131/0x3c0\n tcp_bpf_sendmsg+0xec3/0x1cc0\n\nmsg_tx can only name the stack-local tmp or the shared cork. Check for\ntmp directly so a changed psock-\u003ecork cannot turn a shared message into\nan apparent local one."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerability is triggered by local `sendmsg()`/`sendto()` syscalls issued concurrently by two threads on the same TCP socket attached to a BPF sockmap; the remote peer cannot drive the race, so this is a local attack surface.\nAC:L - The attacker controls both sides of the race: it owns both sending threads, can force the `wait_for_memory` path deterministically with a small SO_SNDBUF plus a large blocking send, and can force `sk_stream_wait_memory()` to fail via SO_SNDTIMEO or a socket error, making the stale-cork free reliably reachable.\nPR:L - Once the sockmap and sk_msg verdict/cork program are installed by the platform (a standard deployment such as Cilium/Istio sockops acceleration), an ordinary unprivileged local process owning a socket in the map triggers the bug with plain send syscalls; no capability check guards `tcp_bpf_sendmsg()` itself.\nUI:N - The attacker\u0027s own two threads perform all the required sends; no action by any other user or victim process is needed.\nS:U - The use-after-free corrupts kernel slab and page state within the same kernel security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - `sk_msg_free()` reads the freed `sk_msg` cork object (KASAN slab-use-after-free read), and by reclaiming that slab object with attacker-groomed data the freed scatterlist can be steered to leak or expose arbitrary kernel memory contents.\nI:H - Beyond the stale read, the path re-frees the cork\u0027s scatterlist pages and uncharges socket memory, giving a double-free/page-refcount-underflow primitive on an attacker-groomable slab object, which is classically leveraged into arbitrary kernel write and control-flow hijack.\nA:H - The use-after-free and duplicate page release corrupt slab and page allocator state, reliably producing a kernel oops or panic and taking the whole system down."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:32:41.174Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/0688e6fe599d2d39147ae9ece97944c6e1815ebf"
},
{
"url": "https://git.kernel.org/stable/c/b2bcbeabfd843d47468fa095b1bd08ddb90cf616"
},
{
"url": "https://git.kernel.org/stable/c/54be47e7cbb936429c3bbdfc526ea943954aaf80"
},
{
"url": "https://git.kernel.org/stable/c/ee762f684eefa59de34d9ed93cab08336e834f47"
},
{
"url": "https://git.kernel.org/stable/c/cde4d6bcd9b73073c66498f6723c7b364c4dbc18"
},
{
"url": "https://git.kernel.org/stable/c/786d690257ec7a0c839f8710456e444ce3f1348b"
},
{
"url": "https://git.kernel.org/stable/c/752b1159ed5d0c48fe169a3721b96660a9822aa1"
},
{
"url": "https://git.kernel.org/stable/c/2d66a033864e27ab8d5e44cb36f31d9d2413bee4"
}
],
"title": "bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68284",
"datePublished": "2026-08-10T12:02:16.572Z",
"dateReserved": "2026-07-30T09:28:09.379Z",
"dateUpdated": "2026-08-19T16:32:41.174Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74657 (GCVE-0-2026-74657)
Vulnerability from cvelistv5
Published
2026-08-22 15:32
Modified
2026-08-27 12:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ipv4: Fix fib_nlmsg_size() for RTA_VIA nexthops
fib_nlmsg_size() still estimates nexthop space as if every gateway is
encoded as an IPv4 RTA_GATEWAY attribute. IPv4 routes can also carry an
IPv6 gateway, which fib_nexthop_info() dumps as RTA_VIA.
As a result, route notifications can allocate an skb that is too small.
fib_dump_info() then fails with -EMSGSIZE and rtmsg_fib() hits the
WARN_ON() that marks such failures as a fib_nlmsg_size() bug. With
panic_on_warn set, this becomes a kernel panic.
Mirror the actual nexthop dump layout in fib_nlmsg_size(): account for
IPv6 nexthop gateways dumped as RTA_VIA, for the no-header rtnexthop
layout used inside RTA_MULTIPATH, and for RTA_FLOW only when it is
actually present.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d15662682db232da77136cd348f4c9df312ca6f9 Version: d15662682db232da77136cd348f4c9df312ca6f9 Version: d15662682db232da77136cd348f4c9df312ca6f9 Version: d15662682db232da77136cd348f4c9df312ca6f9 Version: d15662682db232da77136cd348f4c9df312ca6f9 Version: d15662682db232da77136cd348f4c9df312ca6f9 Version: d15662682db232da77136cd348f4c9df312ca6f9 Version: d15662682db232da77136cd348f4c9df312ca6f9 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ipv4/fib_semantics.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "57195f0ab5cfbb5ee0864e5aff15ceb48f5a5e28",
"status": "affected",
"version": "d15662682db232da77136cd348f4c9df312ca6f9",
"versionType": "git"
},
{
"lessThan": "0f0ca602941d0a81ae9514943ca06c55159c6385",
"status": "affected",
"version": "d15662682db232da77136cd348f4c9df312ca6f9",
"versionType": "git"
},
{
"lessThan": "5307a53599fa762c06e475ee4a375252074fd324",
"status": "affected",
"version": "d15662682db232da77136cd348f4c9df312ca6f9",
"versionType": "git"
},
{
"lessThan": "7f80ad373ce4a7af5367ff273cea0f16e91387f3",
"status": "affected",
"version": "d15662682db232da77136cd348f4c9df312ca6f9",
"versionType": "git"
},
{
"lessThan": "4a5dfbae5179f6574695012a980476254df2d295",
"status": "affected",
"version": "d15662682db232da77136cd348f4c9df312ca6f9",
"versionType": "git"
},
{
"lessThan": "a59edda6eda1252340354322d8ab318b2e9052fb",
"status": "affected",
"version": "d15662682db232da77136cd348f4c9df312ca6f9",
"versionType": "git"
},
{
"lessThan": "9b22f13524fa0de0d963bbd3002df6c28bae3395",
"status": "affected",
"version": "d15662682db232da77136cd348f4c9df312ca6f9",
"versionType": "git"
},
{
"lessThan": "4ff9548d84945d2cbf9e4c207288063a200ea397",
"status": "affected",
"version": "d15662682db232da77136cd348f4c9df312ca6f9",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ipv4/fib_semantics.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.2"
},
{
"lessThan": "5.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.267",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.267",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: Fix fib_nlmsg_size() for RTA_VIA nexthops\n\nfib_nlmsg_size() still estimates nexthop space as if every gateway is\nencoded as an IPv4 RTA_GATEWAY attribute. IPv4 routes can also carry an\nIPv6 gateway, which fib_nexthop_info() dumps as RTA_VIA.\n\nAs a result, route notifications can allocate an skb that is too small.\nfib_dump_info() then fails with -EMSGSIZE and rtmsg_fib() hits the\nWARN_ON() that marks such failures as a fib_nlmsg_size() bug. With\npanic_on_warn set, this becomes a kernel panic.\n\nMirror the actual nexthop dump layout in fib_nlmsg_size(): account for\nIPv6 nexthop gateways dumped as RTA_VIA, for the no-header rtnexthop\nlayout used inside RTA_MULTIPATH, and for RTA_FLOW only when it is\nactually present."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T12:39:57.259Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/57195f0ab5cfbb5ee0864e5aff15ceb48f5a5e28"
},
{
"url": "https://git.kernel.org/stable/c/0f0ca602941d0a81ae9514943ca06c55159c6385"
},
{
"url": "https://git.kernel.org/stable/c/5307a53599fa762c06e475ee4a375252074fd324"
},
{
"url": "https://git.kernel.org/stable/c/7f80ad373ce4a7af5367ff273cea0f16e91387f3"
},
{
"url": "https://git.kernel.org/stable/c/4a5dfbae5179f6574695012a980476254df2d295"
},
{
"url": "https://git.kernel.org/stable/c/a59edda6eda1252340354322d8ab318b2e9052fb"
},
{
"url": "https://git.kernel.org/stable/c/9b22f13524fa0de0d963bbd3002df6c28bae3395"
},
{
"url": "https://git.kernel.org/stable/c/4ff9548d84945d2cbf9e4c207288063a200ea397"
}
],
"title": "ipv4: Fix fib_nlmsg_size() for RTA_VIA nexthops",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74657",
"datePublished": "2026-08-22T15:32:31.458Z",
"dateReserved": "2026-08-15T05:44:03.923Z",
"dateUpdated": "2026-08-27T12:39:57.259Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68231 (GCVE-0-2026-68231)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: airspy: Return queued buffers on start_streaming() failure
The vb2 framework hands buffers to the driver via buf_queue() before
calling start_streaming(). If start_streaming() returns an error
without first returning those buffers via vb2_buffer_done(),
vb2_start_streaming() fires WARN_ON(owned_by_drv_count) and the queued
buffers leak.
airspy_start_streaming() returned -ENODEV early when the USB device had
been disconnected (s->udev == NULL) without returning any buffers that
buf_queue() had already accepted. Take v4l2_lock first and jump to the
existing err_clear_bit label, which already drains s->queued_bufs via
vb2_buffer_done(..., VB2_BUF_STATE_QUEUED) before unlocking.
This mirrors the uvcvideo fix in commit 4cf3b6fd54eb ("media: uvcvideo:
Return queued buffers on start_streaming() failure").
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 634fe5033951b80ef4b98d8f047cb1083d29170d Version: 634fe5033951b80ef4b98d8f047cb1083d29170d Version: 634fe5033951b80ef4b98d8f047cb1083d29170d Version: 634fe5033951b80ef4b98d8f047cb1083d29170d Version: 634fe5033951b80ef4b98d8f047cb1083d29170d Version: 634fe5033951b80ef4b98d8f047cb1083d29170d Version: 634fe5033951b80ef4b98d8f047cb1083d29170d Version: 634fe5033951b80ef4b98d8f047cb1083d29170d |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/usb/airspy/airspy.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "badceeb82a9d8d8e98d07859f3c89130ae1998b9",
"status": "affected",
"version": "634fe5033951b80ef4b98d8f047cb1083d29170d",
"versionType": "git"
},
{
"lessThan": "122ce0c0af629a8765ddf1adf6fb85c6db3d47cb",
"status": "affected",
"version": "634fe5033951b80ef4b98d8f047cb1083d29170d",
"versionType": "git"
},
{
"lessThan": "bcdf261c4c29077fc3da6449f7eda77357046205",
"status": "affected",
"version": "634fe5033951b80ef4b98d8f047cb1083d29170d",
"versionType": "git"
},
{
"lessThan": "877686a74ecdc93dcaee09dbac566e819059c9e7",
"status": "affected",
"version": "634fe5033951b80ef4b98d8f047cb1083d29170d",
"versionType": "git"
},
{
"lessThan": "cd42623d698b59f1fe5768f78a4101c28d5feb2e",
"status": "affected",
"version": "634fe5033951b80ef4b98d8f047cb1083d29170d",
"versionType": "git"
},
{
"lessThan": "73bd2779865372b1017d4f555b45270aa2d0d710",
"status": "affected",
"version": "634fe5033951b80ef4b98d8f047cb1083d29170d",
"versionType": "git"
},
{
"lessThan": "170fcc945bc094b1c956bf555c070692826a3eff",
"status": "affected",
"version": "634fe5033951b80ef4b98d8f047cb1083d29170d",
"versionType": "git"
},
{
"lessThan": "04344d0b4929caa94c0df72f767752aa0935ef5d",
"status": "affected",
"version": "634fe5033951b80ef4b98d8f047cb1083d29170d",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/usb/airspy/airspy.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.17"
},
{
"lessThan": "3.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.17",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: airspy: Return queued buffers on start_streaming() failure\n\nThe vb2 framework hands buffers to the driver via buf_queue() before\ncalling start_streaming(). If start_streaming() returns an error\nwithout first returning those buffers via vb2_buffer_done(),\nvb2_start_streaming() fires WARN_ON(owned_by_drv_count) and the queued\nbuffers leak.\n\nairspy_start_streaming() returned -ENODEV early when the USB device had\nbeen disconnected (s-\u003eudev == NULL) without returning any buffers that\nbuf_queue() had already accepted. Take v4l2_lock first and jump to the\nexisting err_clear_bit label, which already drains s-\u003equeued_bufs via\nvb2_buffer_done(..., VB2_BUF_STATE_QUEUED) before unlocking.\n\nThis mirrors the uvcvideo fix in commit 4cf3b6fd54eb (\"media: uvcvideo:\nReturn queued buffers on start_streaming() failure\")."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:32:04.017Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/badceeb82a9d8d8e98d07859f3c89130ae1998b9"
},
{
"url": "https://git.kernel.org/stable/c/122ce0c0af629a8765ddf1adf6fb85c6db3d47cb"
},
{
"url": "https://git.kernel.org/stable/c/bcdf261c4c29077fc3da6449f7eda77357046205"
},
{
"url": "https://git.kernel.org/stable/c/877686a74ecdc93dcaee09dbac566e819059c9e7"
},
{
"url": "https://git.kernel.org/stable/c/cd42623d698b59f1fe5768f78a4101c28d5feb2e"
},
{
"url": "https://git.kernel.org/stable/c/73bd2779865372b1017d4f555b45270aa2d0d710"
},
{
"url": "https://git.kernel.org/stable/c/170fcc945bc094b1c956bf555c070692826a3eff"
},
{
"url": "https://git.kernel.org/stable/c/04344d0b4929caa94c0df72f767752aa0935ef5d"
}
],
"title": "media: airspy: Return queued buffers on start_streaming() failure",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68231",
"datePublished": "2026-08-10T12:00:54.801Z",
"dateReserved": "2026-07-30T09:28:09.376Z",
"dateUpdated": "2026-08-19T16:32:04.017Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68355 (GCVE-0-2026-68355)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: ath11k: fix potential buffer underflow in ath11k_hal_rx_msdu_list_get()
When the first entry in msdu_details has a zero buffer address,
the code accesses msdu_details[i - 1] with i == 0, causing a
buffer underflow.
Fix similarly to ath12k_wifi7_hal_rx_msdu_list_get() by adding
a separate check for i == 0 before the main condition to prevent
the out-of-bounds access.
Found by Linux Verification Center (linuxtesting.org) with SVACE.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d5c65159f2895379e11ca13f62feabe93278985d Version: d5c65159f2895379e11ca13f62feabe93278985d Version: d5c65159f2895379e11ca13f62feabe93278985d Version: d5c65159f2895379e11ca13f62feabe93278985d Version: d5c65159f2895379e11ca13f62feabe93278985d Version: d5c65159f2895379e11ca13f62feabe93278985d Version: d5c65159f2895379e11ca13f62feabe93278985d Version: d5c65159f2895379e11ca13f62feabe93278985d |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/ath/ath11k/dp_rx.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "085a5fde5bac29c01059e69399b417e91c0a6c18",
"status": "affected",
"version": "d5c65159f2895379e11ca13f62feabe93278985d",
"versionType": "git"
},
{
"lessThan": "31ea4b175bc3ab430be15834d9ee8a1ce65bee15",
"status": "affected",
"version": "d5c65159f2895379e11ca13f62feabe93278985d",
"versionType": "git"
},
{
"lessThan": "20d18a5ec6ec364fcaf0d03af6fc43dcc42c6591",
"status": "affected",
"version": "d5c65159f2895379e11ca13f62feabe93278985d",
"versionType": "git"
},
{
"lessThan": "69a6a4f60b2da92c0bdfd9264b8ffe053f51f52a",
"status": "affected",
"version": "d5c65159f2895379e11ca13f62feabe93278985d",
"versionType": "git"
},
{
"lessThan": "904367381a922aa2dc3e8bd2488e6c9180516c7a",
"status": "affected",
"version": "d5c65159f2895379e11ca13f62feabe93278985d",
"versionType": "git"
},
{
"lessThan": "a154ca3c441a67d36b3a9ea63a4f11b06abe6223",
"status": "affected",
"version": "d5c65159f2895379e11ca13f62feabe93278985d",
"versionType": "git"
},
{
"lessThan": "725c1c3a8c5d920a7d3f5887412f2ad8e95a74f5",
"status": "affected",
"version": "d5c65159f2895379e11ca13f62feabe93278985d",
"versionType": "git"
},
{
"lessThan": "7f11e70629650ff6ea140984e5ce188b775b2683",
"status": "affected",
"version": "d5c65159f2895379e11ca13f62feabe93278985d",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/ath/ath11k/dp_rx.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.6"
},
{
"lessThan": "5.6",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath11k: fix potential buffer underflow in ath11k_hal_rx_msdu_list_get()\n\nWhen the first entry in msdu_details has a zero buffer address,\nthe code accesses msdu_details[i - 1] with i == 0, causing a\nbuffer underflow.\n\nFix similarly to ath12k_wifi7_hal_rx_msdu_list_get() by adding\na separate check for i == 0 before the main condition to prevent\nthe out-of-bounds access.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:03.197Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/085a5fde5bac29c01059e69399b417e91c0a6c18"
},
{
"url": "https://git.kernel.org/stable/c/31ea4b175bc3ab430be15834d9ee8a1ce65bee15"
},
{
"url": "https://git.kernel.org/stable/c/20d18a5ec6ec364fcaf0d03af6fc43dcc42c6591"
},
{
"url": "https://git.kernel.org/stable/c/69a6a4f60b2da92c0bdfd9264b8ffe053f51f52a"
},
{
"url": "https://git.kernel.org/stable/c/904367381a922aa2dc3e8bd2488e6c9180516c7a"
},
{
"url": "https://git.kernel.org/stable/c/a154ca3c441a67d36b3a9ea63a4f11b06abe6223"
},
{
"url": "https://git.kernel.org/stable/c/725c1c3a8c5d920a7d3f5887412f2ad8e95a74f5"
},
{
"url": "https://git.kernel.org/stable/c/7f11e70629650ff6ea140984e5ce188b775b2683"
}
],
"title": "wifi: ath11k: fix potential buffer underflow in ath11k_hal_rx_msdu_list_get()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68355",
"datePublished": "2026-08-10T12:03:32.321Z",
"dateReserved": "2026-07-30T09:28:09.385Z",
"dateUpdated": "2026-08-19T16:34:03.197Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68188 (GCVE-0-2026-68188)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: RFCOMM: Fix session UAF in set_termios
rfcomm_tty_set_termios() tests dlc->session without rfcomm_mutex and
later passes the pointer to rfcomm_send_rpn(). The latter dereferences
both session->initiator and session->sock. Meanwhile, krfcommd can
unlink the DLC and free the session while holding rfcomm_mutex.
The race can proceed as follows:
TTY ioctl task krfcommd
-------------- --------
load dlc->session
enter rfcomm_send_rpn()
lock rfcomm_mutex
clear dlc->session
free session
unlock rfcomm_mutex
read session->initiator
KASAN reported:
BUG: KASAN: slab-use-after-free in rfcomm_send_rpn+0x297/0x2a0
Read of size 4 at addr ffff88810012a850 by task poc/92
Call Trace:
rfcomm_send_rpn+0x297/0x2a0
rfcomm_tty_set_termios+0x50d/0x850
tty_set_termios+0x596/0x950
set_termios+0x46a/0x6e0
tty_mode_ioctl+0x152/0xbd0
tty_ioctl+0x915/0x1240
__x64_sys_ioctl+0x134/0x1c0
Allocated by task 92:
rfcomm_session_add+0x9e/0x2e0
rfcomm_dlc_open+0x8b1/0xe00
rfcomm_dev_activate+0x85/0x1a0
rfcomm_tty_open+0x90/0x280
Freed by task 68:
kfree+0x131/0x3c0
rfcomm_session_del+0x119/0x180
rfcomm_run+0x737/0x4710
Add rfcomm_dlc_send_rpn(), which holds rfcomm_mutex while it verifies
that the DLC is still attached and sends the RPN frame. Have the TTY
path use the helper and drop its unlocked session check. This keeps the
session valid through both the frame construction and socket send.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 3a5e903c09aed19ca4a1bb26d87b8d6461a93818 Version: 3a5e903c09aed19ca4a1bb26d87b8d6461a93818 Version: 3a5e903c09aed19ca4a1bb26d87b8d6461a93818 Version: 3a5e903c09aed19ca4a1bb26d87b8d6461a93818 Version: 3a5e903c09aed19ca4a1bb26d87b8d6461a93818 Version: 3a5e903c09aed19ca4a1bb26d87b8d6461a93818 Version: 3a5e903c09aed19ca4a1bb26d87b8d6461a93818 Version: 3a5e903c09aed19ca4a1bb26d87b8d6461a93818 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"include/net/bluetooth/rfcomm.h",
"net/bluetooth/rfcomm/core.c",
"net/bluetooth/rfcomm/tty.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "4eac4576a072084b06459de6c054b4ebc764b4ea",
"status": "affected",
"version": "3a5e903c09aed19ca4a1bb26d87b8d6461a93818",
"versionType": "git"
},
{
"lessThan": "82c383f9031f1ce919ac6c3c06bc5bd492a6b078",
"status": "affected",
"version": "3a5e903c09aed19ca4a1bb26d87b8d6461a93818",
"versionType": "git"
},
{
"lessThan": "c5c060597247131f90f39ea7c8c978fa0c2e79d0",
"status": "affected",
"version": "3a5e903c09aed19ca4a1bb26d87b8d6461a93818",
"versionType": "git"
},
{
"lessThan": "2894bd8c68e97accd758ca6e5fc375d7e9e8882c",
"status": "affected",
"version": "3a5e903c09aed19ca4a1bb26d87b8d6461a93818",
"versionType": "git"
},
{
"lessThan": "a82a9d3891f5607030b0672c255087a12bb9837b",
"status": "affected",
"version": "3a5e903c09aed19ca4a1bb26d87b8d6461a93818",
"versionType": "git"
},
{
"lessThan": "780b04d09c941262ee2a2b4a09906451b69df8a6",
"status": "affected",
"version": "3a5e903c09aed19ca4a1bb26d87b8d6461a93818",
"versionType": "git"
},
{
"lessThan": "98bc68194e37bfa5e8ddc80b5c1eb0be4dc607ea",
"status": "affected",
"version": "3a5e903c09aed19ca4a1bb26d87b8d6461a93818",
"versionType": "git"
},
{
"lessThan": "c783399efc22d035443f1dfbf2a09bf9562aaa5e",
"status": "affected",
"version": "3a5e903c09aed19ca4a1bb26d87b8d6461a93818",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"include/net/bluetooth/rfcomm.h",
"net/bluetooth/rfcomm/core.c",
"net/bluetooth/rfcomm/tty.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.14"
},
{
"lessThan": "2.6.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: RFCOMM: Fix session UAF in set_termios\n\nrfcomm_tty_set_termios() tests dlc-\u003esession without rfcomm_mutex and\nlater passes the pointer to rfcomm_send_rpn(). The latter dereferences\nboth session-\u003einitiator and session-\u003esock. Meanwhile, krfcommd can\nunlink the DLC and free the session while holding rfcomm_mutex.\n\nThe race can proceed as follows:\n\n TTY ioctl task krfcommd\n -------------- --------\n load dlc-\u003esession\n enter rfcomm_send_rpn()\n lock rfcomm_mutex\n clear dlc-\u003esession\n free session\n unlock rfcomm_mutex\n read session-\u003einitiator\n\nKASAN reported:\n\n BUG: KASAN: slab-use-after-free in rfcomm_send_rpn+0x297/0x2a0\n Read of size 4 at addr ffff88810012a850 by task poc/92\n\n Call Trace:\n rfcomm_send_rpn+0x297/0x2a0\n rfcomm_tty_set_termios+0x50d/0x850\n tty_set_termios+0x596/0x950\n set_termios+0x46a/0x6e0\n tty_mode_ioctl+0x152/0xbd0\n tty_ioctl+0x915/0x1240\n __x64_sys_ioctl+0x134/0x1c0\n\n Allocated by task 92:\n rfcomm_session_add+0x9e/0x2e0\n rfcomm_dlc_open+0x8b1/0xe00\n rfcomm_dev_activate+0x85/0x1a0\n rfcomm_tty_open+0x90/0x280\n\n Freed by task 68:\n kfree+0x131/0x3c0\n rfcomm_session_del+0x119/0x180\n rfcomm_run+0x737/0x4710\n\nAdd rfcomm_dlc_send_rpn(), which holds rfcomm_mutex while it verifies\nthat the DLC is still attached and sends the RPN frame. Have the TTY\npath use the helper and drop its unlocked session check. This keeps the\nsession valid through both the frame construction and socket send."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:30:59.491Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/4eac4576a072084b06459de6c054b4ebc764b4ea"
},
{
"url": "https://git.kernel.org/stable/c/82c383f9031f1ce919ac6c3c06bc5bd492a6b078"
},
{
"url": "https://git.kernel.org/stable/c/c5c060597247131f90f39ea7c8c978fa0c2e79d0"
},
{
"url": "https://git.kernel.org/stable/c/2894bd8c68e97accd758ca6e5fc375d7e9e8882c"
},
{
"url": "https://git.kernel.org/stable/c/a82a9d3891f5607030b0672c255087a12bb9837b"
},
{
"url": "https://git.kernel.org/stable/c/780b04d09c941262ee2a2b4a09906451b69df8a6"
},
{
"url": "https://git.kernel.org/stable/c/98bc68194e37bfa5e8ddc80b5c1eb0be4dc607ea"
},
{
"url": "https://git.kernel.org/stable/c/c783399efc22d035443f1dfbf2a09bf9562aaa5e"
}
],
"title": "Bluetooth: RFCOMM: Fix session UAF in set_termios",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68188",
"datePublished": "2026-08-10T12:00:00.521Z",
"dateReserved": "2026-07-30T09:28:09.373Z",
"dateUpdated": "2026-08-19T16:30:59.491Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74630 (GCVE-0-2026-74630)
Vulnerability from cvelistv5
Published
2026-08-22 15:32
Modified
2026-08-25 05:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ipv6: prevent in6_dev_get() from resurrecting inet6_dev
in6_dev_get() reads dev->ip6_ptr under RCU and then unconditionally
increments its refcount. Device teardown can clear the pointer and drop
the last reference between these operations. The increment then
resurrects an object whose RCU free has already been queued, so callers
can use it after it is freed.
Use refcount_inc_not_zero() and return NULL when the object has already
reached zero. RCU keeps the memory accessible through the attempted
reference acquisition, and a successful increment pins the object for
the caller.
An independent run on the exact unpatched 6f5156d7a31a (v7.2-rc3)
kernel reproduced the invalid reference acquisition as UID 1000:
refcount_t: addition on 0; use-after-free.
ip6_mc_source+0xef4/0x17e0
It was followed by the corresponding reference underflow in
ip6_mc_source(). The supplied trace from the same unpatched revision
additionally shows the access after the RCU read-side section ends:
BUG: KASAN: slab-use-after-free in mutex_lock+0x76/0xe0
Write of size 8 at addr ffff888015b50240 by task poc/1219
Bug found and triaged by OpenAI Security Research and
validated by Trail of Bits.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 8814c4b533817df825485ff32ce6ac406c3a54d1 Version: 8814c4b533817df825485ff32ce6ac406c3a54d1 Version: 8814c4b533817df825485ff32ce6ac406c3a54d1 Version: 8814c4b533817df825485ff32ce6ac406c3a54d1 Version: 8814c4b533817df825485ff32ce6ac406c3a54d1 Version: 8814c4b533817df825485ff32ce6ac406c3a54d1 Version: 8814c4b533817df825485ff32ce6ac406c3a54d1 Version: 8814c4b533817df825485ff32ce6ac406c3a54d1 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"include/net/addrconf.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "785d908f8d21c8bc78b6fb2c2932ab662bf6918a",
"status": "affected",
"version": "8814c4b533817df825485ff32ce6ac406c3a54d1",
"versionType": "git"
},
{
"lessThan": "aedcfefdb5b7ed7f8a6196a3e68a25bdbe51d2f8",
"status": "affected",
"version": "8814c4b533817df825485ff32ce6ac406c3a54d1",
"versionType": "git"
},
{
"lessThan": "145812b678de9f3b59780173be3c0d22ed60dd93",
"status": "affected",
"version": "8814c4b533817df825485ff32ce6ac406c3a54d1",
"versionType": "git"
},
{
"lessThan": "cc5bd568f9b7683e60841b6fd02c10d64535bd6e",
"status": "affected",
"version": "8814c4b533817df825485ff32ce6ac406c3a54d1",
"versionType": "git"
},
{
"lessThan": "1c206d461c680c3151daa3c89fc26eaf5bf98a7f",
"status": "affected",
"version": "8814c4b533817df825485ff32ce6ac406c3a54d1",
"versionType": "git"
},
{
"lessThan": "680fbd7942185448eadb990a3d10a53eb946b702",
"status": "affected",
"version": "8814c4b533817df825485ff32ce6ac406c3a54d1",
"versionType": "git"
},
{
"lessThan": "14e812ab41df0cac033479da835ec9a5de633404",
"status": "affected",
"version": "8814c4b533817df825485ff32ce6ac406c3a54d1",
"versionType": "git"
},
{
"lessThan": "0e243671bc7b8eaf00f83dd2f4367436dc0cff98",
"status": "affected",
"version": "8814c4b533817df825485ff32ce6ac406c3a54d1",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"include/net/addrconf.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.19"
},
{
"lessThan": "2.6.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "2.6.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "2.6.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "2.6.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "2.6.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: prevent in6_dev_get() from resurrecting inet6_dev\n\nin6_dev_get() reads dev-\u003eip6_ptr under RCU and then unconditionally\nincrements its refcount. Device teardown can clear the pointer and drop\nthe last reference between these operations. The increment then\nresurrects an object whose RCU free has already been queued, so callers\ncan use it after it is freed.\n\nUse refcount_inc_not_zero() and return NULL when the object has already\nreached zero. RCU keeps the memory accessible through the attempted\nreference acquisition, and a successful increment pins the object for\nthe caller.\n\nAn independent run on the exact unpatched 6f5156d7a31a (v7.2-rc3)\nkernel reproduced the invalid reference acquisition as UID 1000:\n\n refcount_t: addition on 0; use-after-free.\n ip6_mc_source+0xef4/0x17e0\n\nIt was followed by the corresponding reference underflow in\nip6_mc_source(). The supplied trace from the same unpatched revision\nadditionally shows the access after the RCU read-side section ends:\n\n BUG: KASAN: slab-use-after-free in mutex_lock+0x76/0xe0\n Write of size 8 at addr ffff888015b50240 by task poc/1219\n\nBug found and triaged by OpenAI Security Research and\nvalidated by Trail of Bits."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The reliable path is local setsockopt(2) on IPv6 MCAST source-filter options (ipv6_setsockopt \u2192 do_ipv6_mcast_group_source \u2192 ip6_mc_source \u2192 in6_dev_get), reproduced as UID 1000; concurrent netdev unregister is also a local rtnetlink syscall, not remote packet delivery.\nAC:L - An attacker in their own user+network namespace controls both sides of the race\u2014hammering MCAST_JOIN/BLOCK/UNBLOCK_SOURCE setsockopt while deleting the bound veth via RTM_DELLINK\u2014so the ip6_ptr clear and final in6_dev_put window is attacker-driven and retryable.\nPR:L - Multicast setsockopt needs no capability, but hitting the unregister teardown that drops the last inet6_dev reference requires CAP_NET_ADMIN for RTM_DELLINK; that is ns_capable() in the netns user_ns and is obtainable by an unprivileged user via unshare -Urn, not init-namespace root.\nUI:N - Exploitation uses only the attacker\u0027s own IPv6 sockets, setsockopt calls, and netdev create/delete in their namespace; no victim mount, click, or other cooperation is required.\nS:U - The resurrected inet6_dev UAF corrupts kernel heap state within the host kernel authority (mutex_lock on freed mc_lock); it is standard local kernel memory corruption, not a VM escape, IOMMU bypass, or other cross-boundary impact.\nC:H - Resurrecting a zero-refcount inet6_dev whose RCU free is already queued is a slab use-after-free; KASAN reported UAF on freed inet6_dev memory, and such heap UAFs enable disclosure via controlled reuse of the freed object.\nI:H - After resurrection the caller locks idev-\u003emc_lock and mutates multicast state on freed memory (KASAN write in mutex_lock), giving attacker-influenced heap corruption that can be turned into arbitrary write or control-flow hijack.\nA:H - The PoC triggers refcount_t addition-on-0 warnings, refcount underflow, and KASAN slab-use-after-free in mutex_lock, demonstrating immediate kernel memory corruption that can oops/panic and be repeated by re-running the race."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:40:54.475Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/785d908f8d21c8bc78b6fb2c2932ab662bf6918a"
},
{
"url": "https://git.kernel.org/stable/c/aedcfefdb5b7ed7f8a6196a3e68a25bdbe51d2f8"
},
{
"url": "https://git.kernel.org/stable/c/145812b678de9f3b59780173be3c0d22ed60dd93"
},
{
"url": "https://git.kernel.org/stable/c/cc5bd568f9b7683e60841b6fd02c10d64535bd6e"
},
{
"url": "https://git.kernel.org/stable/c/1c206d461c680c3151daa3c89fc26eaf5bf98a7f"
},
{
"url": "https://git.kernel.org/stable/c/680fbd7942185448eadb990a3d10a53eb946b702"
},
{
"url": "https://git.kernel.org/stable/c/14e812ab41df0cac033479da835ec9a5de633404"
},
{
"url": "https://git.kernel.org/stable/c/0e243671bc7b8eaf00f83dd2f4367436dc0cff98"
}
],
"title": "ipv6: prevent in6_dev_get() from resurrecting inet6_dev",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74630",
"datePublished": "2026-08-22T15:32:11.596Z",
"dateReserved": "2026-08-15T05:44:03.921Z",
"dateUpdated": "2026-08-25T05:40:54.475Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80802 (GCVE-0-2026-80802)
Vulnerability from cvelistv5
Published
2026-09-04 15:13
Modified
2026-09-04 15:13
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
nfc: fdp: bound the device-reported read length and fix an skb leak
fdp_nci_i2c_read() takes the next packet length from two device-supplied
bytes and never validates it. The value is a u16 used as the
i2c_master_recv() count into a 261-byte on-stack buffer: a malicious,
counterfeit or malfunctioning controller (or an i2c bus interposer) can
drive it far past the buffer for a stack out-of-bounds write that
clobbers the canary and return address, or below the minimum frame size
(directly, or by truncating the computed sum) so the header/LRC strip
and the next length read run past a short receive. Reject a length
outside [FDP_NCI_I2C_MIN_PAYLOAD, FDP_NCI_I2C_MAX_PAYLOAD], as a
corrupted packet already is, and force resynchronization.
The same loop allocates one data skb per iteration and assumes a length
packet followed by a data packet; a device that sends two data packets
in one call leaks the first skb when the second allocation overwrites
it. Free a previously allocated skb before allocating the next.
References
| URL | Tags | ||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: a06347c04c13e380afce0c9816df51f00b83faf1 Version: a06347c04c13e380afce0c9816df51f00b83faf1 Version: a06347c04c13e380afce0c9816df51f00b83faf1 Version: a06347c04c13e380afce0c9816df51f00b83faf1 Version: a06347c04c13e380afce0c9816df51f00b83faf1 Version: a06347c04c13e380afce0c9816df51f00b83faf1 Version: a06347c04c13e380afce0c9816df51f00b83faf1 Version: a06347c04c13e380afce0c9816df51f00b83faf1 Version: a06347c04c13e380afce0c9816df51f00b83faf1 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/nfc/fdp/i2c.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "d9498ab9a78cb63d78dbe4f221d8cc6c91f285ee",
"status": "affected",
"version": "a06347c04c13e380afce0c9816df51f00b83faf1",
"versionType": "git"
},
{
"lessThan": "1fc32327b927a6e2cde086f82575c29880844228",
"status": "affected",
"version": "a06347c04c13e380afce0c9816df51f00b83faf1",
"versionType": "git"
},
{
"lessThan": "8d2c243b79854628ff076c38748c020042f02f57",
"status": "affected",
"version": "a06347c04c13e380afce0c9816df51f00b83faf1",
"versionType": "git"
},
{
"lessThan": "fc3c2bd5b1ec6c7cbc8a50e32d9bcec114f25463",
"status": "affected",
"version": "a06347c04c13e380afce0c9816df51f00b83faf1",
"versionType": "git"
},
{
"lessThan": "0d723090645b82c1cb27cfd7ebf81f0e7c96bcae",
"status": "affected",
"version": "a06347c04c13e380afce0c9816df51f00b83faf1",
"versionType": "git"
},
{
"lessThan": "db7e464b350969c6ea8340de00d9796e5fd5123b",
"status": "affected",
"version": "a06347c04c13e380afce0c9816df51f00b83faf1",
"versionType": "git"
},
{
"lessThan": "e5eec121f2c3bc4c7022613bedd9121a8aa4c949",
"status": "affected",
"version": "a06347c04c13e380afce0c9816df51f00b83faf1",
"versionType": "git"
},
{
"lessThan": "1aa3fc769b0c45bd19f8dab1697084c2b3f6d706",
"status": "affected",
"version": "a06347c04c13e380afce0c9816df51f00b83faf1",
"versionType": "git"
},
{
"lessThan": "7ad21dcfeb5181af0c3ee2608808c0c0a5283aa1",
"status": "affected",
"version": "a06347c04c13e380afce0c9816df51f00b83faf1",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/nfc/fdp/i2c.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.4"
},
{
"lessThan": "4.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.267",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.218",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.185",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.154",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.106",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.47",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.1",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.267",
"versionStartIncluding": "4.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.218",
"versionStartIncluding": "4.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.185",
"versionStartIncluding": "4.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.154",
"versionStartIncluding": "4.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.106",
"versionStartIncluding": "4.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.47",
"versionStartIncluding": "4.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.11",
"versionStartIncluding": "4.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.1",
"versionStartIncluding": "4.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "4.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: fdp: bound the device-reported read length and fix an skb leak\n\nfdp_nci_i2c_read() takes the next packet length from two device-supplied\nbytes and never validates it. The value is a u16 used as the\ni2c_master_recv() count into a 261-byte on-stack buffer: a malicious,\ncounterfeit or malfunctioning controller (or an i2c bus interposer) can\ndrive it far past the buffer for a stack out-of-bounds write that\nclobbers the canary and return address, or below the minimum frame size\n(directly, or by truncating the computed sum) so the header/LRC strip\nand the next length read run past a short receive. Reject a length\noutside [FDP_NCI_I2C_MIN_PAYLOAD, FDP_NCI_I2C_MAX_PAYLOAD], as a\ncorrupted packet already is, and force resynchronization.\n\nThe same loop allocates one data skb per iteration and assumes a length\npacket followed by a data packet; a device that sends two data packets\nin one call leaks the first skb when the second allocation overwrites\nit. Free a previously allocated skb before allocating the next."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T15:13:16.241Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/d9498ab9a78cb63d78dbe4f221d8cc6c91f285ee"
},
{
"url": "https://git.kernel.org/stable/c/1fc32327b927a6e2cde086f82575c29880844228"
},
{
"url": "https://git.kernel.org/stable/c/8d2c243b79854628ff076c38748c020042f02f57"
},
{
"url": "https://git.kernel.org/stable/c/fc3c2bd5b1ec6c7cbc8a50e32d9bcec114f25463"
},
{
"url": "https://git.kernel.org/stable/c/0d723090645b82c1cb27cfd7ebf81f0e7c96bcae"
},
{
"url": "https://git.kernel.org/stable/c/db7e464b350969c6ea8340de00d9796e5fd5123b"
},
{
"url": "https://git.kernel.org/stable/c/e5eec121f2c3bc4c7022613bedd9121a8aa4c949"
},
{
"url": "https://git.kernel.org/stable/c/1aa3fc769b0c45bd19f8dab1697084c2b3f6d706"
},
{
"url": "https://git.kernel.org/stable/c/7ad21dcfeb5181af0c3ee2608808c0c0a5283aa1"
}
],
"title": "nfc: fdp: bound the device-reported read length and fix an skb leak",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80802",
"datePublished": "2026-09-04T15:13:16.241Z",
"dateReserved": "2026-08-26T14:34:25.794Z",
"dateUpdated": "2026-09-04T15:13:16.241Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72069 (GCVE-0-2026-72069)
Vulnerability from cvelistv5
Published
2026-08-15 05:52
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
locking/rt: Fix the incorrect RCU protection in rt_spin_unlock()
rt_spin_unlock() releases the RCU protection before unlocking the
lock. That opens the door for the following UAF scenario:
T1 T2
spin_lock(&p->lock); rcu_read_lock();
invalidate(p); p = rcu_dereference(ptr);
rcu_assign_pointer(ptr, NULL); if (!p) return;
spin_unlock(&p->lock); spin_lock(&p->lock)
lock(&lock->lock);
rcu_read_lock();
kfree_rcu(p); rcu_read_unlock();
....
spin_unlock(&p->lock)
rcu_read_unlock(); // Ends grace period
rcu_do_batch()
kfree(p);
UAF -> rt_mutex_cmpxchg_release(&lock->lock...)
Regular spinlocks keep preemption disabled accross the unlock operation,
which provides full RCU protection, but the RT substitution fails to
resemble that. Same applies for the rwlock substitution.
Move the rcu_read_unlock() invocation past the unlock operations to match
the non-RT semantics. This makes it asymmetric vs. rt_xxx_lock(), but
that's harmless as the caller needs to hold RCU read lock across the lock
operation. The migrate_enable() call stays before the unlock operation
because there is no per CPU operation in the unlock path which would
require migration to be kept disabled.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 0f383b6dc96e976dfbf2721b0bf10bd96103b341 Version: 0f383b6dc96e976dfbf2721b0bf10bd96103b341 Version: 0f383b6dc96e976dfbf2721b0bf10bd96103b341 Version: 0f383b6dc96e976dfbf2721b0bf10bd96103b341 Version: 0f383b6dc96e976dfbf2721b0bf10bd96103b341 Version: 0f383b6dc96e976dfbf2721b0bf10bd96103b341 Version: 0f383b6dc96e976dfbf2721b0bf10bd96103b341 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"kernel/locking/spinlock_rt.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "af28d801cd2db4cc7378554499bd4a5d84a5517e",
"status": "affected",
"version": "0f383b6dc96e976dfbf2721b0bf10bd96103b341",
"versionType": "git"
},
{
"lessThan": "9d1fcd64ab81200e02b7a6db5eb1da8e244e8289",
"status": "affected",
"version": "0f383b6dc96e976dfbf2721b0bf10bd96103b341",
"versionType": "git"
},
{
"lessThan": "3cfaac77b3c32ac3940df28866de263c3f45d24c",
"status": "affected",
"version": "0f383b6dc96e976dfbf2721b0bf10bd96103b341",
"versionType": "git"
},
{
"lessThan": "1f0d56d3f1e88f20f6e46109402f8c15d59bac37",
"status": "affected",
"version": "0f383b6dc96e976dfbf2721b0bf10bd96103b341",
"versionType": "git"
},
{
"lessThan": "633cadbc0b8323f5cc140a285d2432089dbb534e",
"status": "affected",
"version": "0f383b6dc96e976dfbf2721b0bf10bd96103b341",
"versionType": "git"
},
{
"lessThan": "83f9fb561c1c3917e19f95523dd933c7d30291aa",
"status": "affected",
"version": "0f383b6dc96e976dfbf2721b0bf10bd96103b341",
"versionType": "git"
},
{
"lessThan": "89038cc87d80c77e7aa6f42a64b2573b74af339f",
"status": "affected",
"version": "0f383b6dc96e976dfbf2721b0bf10bd96103b341",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"kernel/locking/spinlock_rt.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.15"
},
{
"lessThan": "5.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nlocking/rt: Fix the incorrect RCU protection in rt_spin_unlock()\n\nrt_spin_unlock() releases the RCU protection before unlocking the\nlock. That opens the door for the following UAF scenario:\n\n T1\t\t\t\t\tT2\n spin_lock(\u0026p-\u003elock);\t\trcu_read_lock();\n invalidate(p);\t\t\tp = rcu_dereference(ptr);\n rcu_assign_pointer(ptr, NULL);\tif (!p) return;\n spin_unlock(\u0026p-\u003elock);\t\tspin_lock(\u0026p-\u003elock)\n \t\t\t\t lock(\u0026lock-\u003elock);\n\t\t\t\t rcu_read_lock();\n kfree_rcu(p);\t\t\trcu_read_unlock();\n\t\t\t\t....\n\t\t\t\tspin_unlock(\u0026p-\u003elock)\n\t\t\t\t rcu_read_unlock(); // Ends grace period\n rcu_do_batch()\n kfree(p);\n\t\t\t UAF -\u003e\t rt_mutex_cmpxchg_release(\u0026lock-\u003elock...)\n\nRegular spinlocks keep preemption disabled accross the unlock operation,\nwhich provides full RCU protection, but the RT substitution fails to\nresemble that. Same applies for the rwlock substitution.\n\nMove the rcu_read_unlock() invocation past the unlock operations to match\nthe non-RT semantics. This makes it asymmetric vs. rt_xxx_lock(), but\nthat\u0027s harmless as the caller needs to hold RCU read lock across the lock\noperation. The migrate_enable() call stays before the unlock operation\nbecause there is no per CPU operation in the unlock path which would\nrequire migration to be kept disabled."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - On CONFIG_PREEMPT_RT, every spin_unlock() is substituted by rt_spin_unlock(); network subsystems such as netfilter xt_hashlimit process inbound packets through hashlimit_mt_common(), spin_lock/unlock on RCU-protected dsthash_ent objects concurrently freed via call_rcu by GC\u2014the exact embedded-spinlock UAF pattern from the fix.\nAC:L - The bug is a cross-CPU race where rt_spin_unlock() calls rcu_read_unlock() before releasing the rtmutex, ending the RCU grace period while still dereferencing the lock; syzbot triggered this reliably on PREEMPT_RT via concurrent unlinkat and dentry teardown, and attackers control both sides with parallel syscalls or packet/GC load.\nPR:N - Remote attackers need no account, capability, or authentication to send packets that hit deployed hashlimit rules on internet-facing PREEMPT_RT gateways; the proven syzbot unlinkat path needs only directory write permission (PR:L), but PR:N reflects the highest-severity unauthenticated network packet scenario.\nUI:N - No victim interaction is required; the attacker drives the race through their own concurrent filesystem syscalls (syzbot: unlinkat racing __fput/dentry_kill) or sustained inbound traffic overlapping netfilter GC, without needing another user to open files or mount filesystems.\nS:U - The UAF corrupts kernel slab memory containing embedded spinlock/rtmutex fields and enables privilege escalation within the same kernel security authority; it does not inherently cross VM/guest, container sandbox, or IOMMU hardware isolation boundaries.\nC:H - Syzbot reported KASAN slab-use-after-free Read in rt_mutex_slowunlock during spin_unlock on a freed dentry in shrink_dcache_tree; the systemic UAF lets attackers read freed objects (dentry, dsthash_ent, etc.) after premature RCU grace-period completion, enabling kernel pointer and memory disclosure.\nI:H - UAF on embedded rtmutex fields inside freed slab objects (dentry-\u003ed_lock per syzbot) permits heap grooming and reallocation of attacker-controlled data, providing standard kernel heap corruption primitives for arbitrary write and control-flow hijack beyond the immediate crash.\nA:H - Syzbot hit KASAN slab-use-after-free causing kernel fault in shrink_dcache_tree via rt_spin_unlock on PREEMPT_RT; the bug can oops/panic any RT kernel whenever spin_unlock races RCU-deferred free of the containing object, enabling repeatable denial of service via concurrent VFS or netfilter operations."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:41.836Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/af28d801cd2db4cc7378554499bd4a5d84a5517e"
},
{
"url": "https://git.kernel.org/stable/c/9d1fcd64ab81200e02b7a6db5eb1da8e244e8289"
},
{
"url": "https://git.kernel.org/stable/c/3cfaac77b3c32ac3940df28866de263c3f45d24c"
},
{
"url": "https://git.kernel.org/stable/c/1f0d56d3f1e88f20f6e46109402f8c15d59bac37"
},
{
"url": "https://git.kernel.org/stable/c/633cadbc0b8323f5cc140a285d2432089dbb534e"
},
{
"url": "https://git.kernel.org/stable/c/83f9fb561c1c3917e19f95523dd933c7d30291aa"
},
{
"url": "https://git.kernel.org/stable/c/89038cc87d80c77e7aa6f42a64b2573b74af339f"
}
],
"title": "locking/rt: Fix the incorrect RCU protection in rt_spin_unlock()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72069",
"datePublished": "2026-08-15T05:52:21.752Z",
"dateReserved": "2026-08-09T03:40:39.903Z",
"dateUpdated": "2026-08-23T12:46:41.836Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64590 (GCVE-0-2026-64590)
Vulnerability from cvelistv5
Published
2026-08-06 07:13
Modified
2026-08-23 12:45
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
dma-buf/udmabuf: skip redundant cpu sync to fix cacheline EEXIST warning
When CONFIG_DMA_API_DEBUG_SG is enabled, importing a udmabuf into a DRM
driver (e.g. amdgpu for video playback in GNOME Videos / Showtime)
triggers a spurious warning:
DMA-API: amdgpu 0000:03:00.0: cacheline tracking EEXIST, \
overlapping mappings aren't supported
WARNING: kernel/dma/debug.c:619 at add_dma_entry+0x473/0x5f0
The call chain is:
amdgpu_cs_ioctl
-> amdgpu_ttm_backend_bind
-> dma_buf_map_attachment
-> [udmabuf] map_udmabuf -> get_sg_table
-> dma_map_sgtable(dev, sg, direction, 0) // attrs=0
-> debug_dma_map_sg -> add_dma_entry -> EEXIST
This happens because udmabuf builds a per-page scatter-gather list via
sg_set_folio(). When begin_cpu_udmabuf() has already created an sg
table mapped for the misc device, and an importer such as amdgpu maps
the same pages for its own device via map_udmabuf(), the DMA debug
infrastructure sees two active mappings whose physical addresses share
cacheline boundaries and warns about the overlap.
The DMA_ATTR_SKIP_CPU_SYNC flag suppresses this check in
add_dma_entry() because it signals that no CPU cache maintenance is
performed at map/unmap time, making the cacheline overlap harmless.
All other major dma-buf exporters already pass this flag:
- drm_gem_map_dma_buf() passes DMA_ATTR_SKIP_CPU_SYNC
- amdgpu_dma_buf_map() passes DMA_ATTR_SKIP_CPU_SYNC
The CPU sync at map/unmap time is also redundant for udmabuf:
begin_cpu_udmabuf() and end_cpu_udmabuf() already perform explicit
cache synchronization via dma_sync_sgtable_for_cpu/device() when CPU
access is requested through the dma-buf interface.
Pass DMA_ATTR_SKIP_CPU_SYNC to dma_map_sgtable() and
dma_unmap_sgtable() in udmabuf to suppress the spurious warning and
skip the redundant sync.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 284562e1f34874e267d4f499362c3816f8f6bc3f Version: 284562e1f34874e267d4f499362c3816f8f6bc3f Version: 284562e1f34874e267d4f499362c3816f8f6bc3f Version: 284562e1f34874e267d4f499362c3816f8f6bc3f Version: 284562e1f34874e267d4f499362c3816f8f6bc3f Version: 284562e1f34874e267d4f499362c3816f8f6bc3f Version: 284562e1f34874e267d4f499362c3816f8f6bc3f Version: 284562e1f34874e267d4f499362c3816f8f6bc3f |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/dma-buf/udmabuf.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "4a7c644e632741c2a3116a0d3da6c11de957a6ba",
"status": "affected",
"version": "284562e1f34874e267d4f499362c3816f8f6bc3f",
"versionType": "git"
},
{
"lessThan": "01126abc11bcc6a45b664293b0b5df715be911d7",
"status": "affected",
"version": "284562e1f34874e267d4f499362c3816f8f6bc3f",
"versionType": "git"
},
{
"lessThan": "dd7f1e572f44d3d039dc77e3989f537196c3bf52",
"status": "affected",
"version": "284562e1f34874e267d4f499362c3816f8f6bc3f",
"versionType": "git"
},
{
"lessThan": "0db56e7eae932f8e2f3eb44ad1a63633d8f504f8",
"status": "affected",
"version": "284562e1f34874e267d4f499362c3816f8f6bc3f",
"versionType": "git"
},
{
"lessThan": "d6552f5cff795d60e629f37513ecf23d88fd2f82",
"status": "affected",
"version": "284562e1f34874e267d4f499362c3816f8f6bc3f",
"versionType": "git"
},
{
"lessThan": "34696563461c9a23177feb6d8aff43f4c0510278",
"status": "affected",
"version": "284562e1f34874e267d4f499362c3816f8f6bc3f",
"versionType": "git"
},
{
"lessThan": "0449a6583c0ee76778d314e4e82f166fc97fa9d8",
"status": "affected",
"version": "284562e1f34874e267d4f499362c3816f8f6bc3f",
"versionType": "git"
},
{
"lessThan": "504e2b4ab97a51d56d966cd36d0997ad30b65b2d",
"status": "affected",
"version": "284562e1f34874e267d4f499362c3816f8f6bc3f",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/dma-buf/udmabuf.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.6"
},
{
"lessThan": "5.6",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndma-buf/udmabuf: skip redundant cpu sync to fix cacheline EEXIST warning\n\nWhen CONFIG_DMA_API_DEBUG_SG is enabled, importing a udmabuf into a DRM\ndriver (e.g. amdgpu for video playback in GNOME Videos / Showtime)\ntriggers a spurious warning:\n\n DMA-API: amdgpu 0000:03:00.0: cacheline tracking EEXIST, \\\n overlapping mappings aren\u0027t supported\n WARNING: kernel/dma/debug.c:619 at add_dma_entry+0x473/0x5f0\n\nThe call chain is:\n\n amdgpu_cs_ioctl\n -\u003e amdgpu_ttm_backend_bind\n -\u003e dma_buf_map_attachment\n -\u003e [udmabuf] map_udmabuf -\u003e get_sg_table\n -\u003e dma_map_sgtable(dev, sg, direction, 0) // attrs=0\n -\u003e debug_dma_map_sg -\u003e add_dma_entry -\u003e EEXIST\n\nThis happens because udmabuf builds a per-page scatter-gather list via\nsg_set_folio(). When begin_cpu_udmabuf() has already created an sg\ntable mapped for the misc device, and an importer such as amdgpu maps\nthe same pages for its own device via map_udmabuf(), the DMA debug\ninfrastructure sees two active mappings whose physical addresses share\ncacheline boundaries and warns about the overlap.\n\nThe DMA_ATTR_SKIP_CPU_SYNC flag suppresses this check in\nadd_dma_entry() because it signals that no CPU cache maintenance is\nperformed at map/unmap time, making the cacheline overlap harmless.\n\nAll other major dma-buf exporters already pass this flag:\n - drm_gem_map_dma_buf() passes DMA_ATTR_SKIP_CPU_SYNC\n - amdgpu_dma_buf_map() passes DMA_ATTR_SKIP_CPU_SYNC\n\nThe CPU sync at map/unmap time is also redundant for udmabuf:\nbegin_cpu_udmabuf() and end_cpu_udmabuf() already perform explicit\ncache synchronization via dma_sync_sgtable_for_cpu/device() when CPU\naccess is requested through the dma-buf interface.\n\nPass DMA_ATTR_SKIP_CPU_SYNC to dma_map_sgtable() and\ndma_unmap_sgtable() in udmabuf to suppress the spurious warning and\nskip the redundant sync."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:45:45.786Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/4a7c644e632741c2a3116a0d3da6c11de957a6ba"
},
{
"url": "https://git.kernel.org/stable/c/01126abc11bcc6a45b664293b0b5df715be911d7"
},
{
"url": "https://git.kernel.org/stable/c/dd7f1e572f44d3d039dc77e3989f537196c3bf52"
},
{
"url": "https://git.kernel.org/stable/c/0db56e7eae932f8e2f3eb44ad1a63633d8f504f8"
},
{
"url": "https://git.kernel.org/stable/c/d6552f5cff795d60e629f37513ecf23d88fd2f82"
},
{
"url": "https://git.kernel.org/stable/c/34696563461c9a23177feb6d8aff43f4c0510278"
},
{
"url": "https://git.kernel.org/stable/c/0449a6583c0ee76778d314e4e82f166fc97fa9d8"
},
{
"url": "https://git.kernel.org/stable/c/504e2b4ab97a51d56d966cd36d0997ad30b65b2d"
}
],
"title": "dma-buf/udmabuf: skip redundant cpu sync to fix cacheline EEXIST warning",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64590",
"datePublished": "2026-08-06T07:13:47.888Z",
"dateReserved": "2026-07-19T15:36:31.798Z",
"dateUpdated": "2026-08-23T12:45:45.786Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80549 (GCVE-0-2026-80549)
Vulnerability from cvelistv5
Published
2026-08-26 14:37
Modified
2026-08-27 12:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
s390/vfio_ccw: Move cp cleanup out of not operational
The fsm_notoper() routine is called when the device has been
lost, and is (by definition) no longer operational. Since this
can happen asynchronously from the normal behavior of the
driver, the cleanup may happen when holding other locks
in the calling sequence (notably, the cio subchannel lock).
Push the cleanup of the private->cp resources to a workqueue,
where it can be done out from under that lock sequence and
a future patch can safely manage the locking requirements.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 204b394a23ad5e30944f23518e21e844614da2ff Version: 204b394a23ad5e30944f23518e21e844614da2ff Version: 204b394a23ad5e30944f23518e21e844614da2ff Version: 204b394a23ad5e30944f23518e21e844614da2ff Version: 204b394a23ad5e30944f23518e21e844614da2ff Version: 204b394a23ad5e30944f23518e21e844614da2ff |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/s390/cio/vfio_ccw_drv.c",
"drivers/s390/cio/vfio_ccw_fsm.c",
"drivers/s390/cio/vfio_ccw_ops.c",
"drivers/s390/cio/vfio_ccw_private.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c9b85aa2cf73ea645e55e2c2670e0ddebfe1589b",
"status": "affected",
"version": "204b394a23ad5e30944f23518e21e844614da2ff",
"versionType": "git"
},
{
"lessThan": "f98a9890ca42f4223d2d4c50e0660af3e012fcb4",
"status": "affected",
"version": "204b394a23ad5e30944f23518e21e844614da2ff",
"versionType": "git"
},
{
"lessThan": "4e3301e2a651d742c05914f6074a25b8e41bce19",
"status": "affected",
"version": "204b394a23ad5e30944f23518e21e844614da2ff",
"versionType": "git"
},
{
"lessThan": "af1759d8e6e6da9ba94f30a2f92546f406899aa7",
"status": "affected",
"version": "204b394a23ad5e30944f23518e21e844614da2ff",
"versionType": "git"
},
{
"lessThan": "56100baa0eb7055b1026dfa73e696e8066ff71fd",
"status": "affected",
"version": "204b394a23ad5e30944f23518e21e844614da2ff",
"versionType": "git"
},
{
"lessThan": "0c11f61a876ed6fcca53d442ed3f33ea8362a0f9",
"status": "affected",
"version": "204b394a23ad5e30944f23518e21e844614da2ff",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/s390/cio/vfio_ccw_drv.c",
"drivers/s390/cio/vfio_ccw_fsm.c",
"drivers/s390/cio/vfio_ccw_ops.c",
"drivers/s390/cio/vfio_ccw_private.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.0"
},
{
"lessThan": "6.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.185",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.185",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.46",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.10",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/vfio_ccw: Move cp cleanup out of not operational\n\nThe fsm_notoper() routine is called when the device has been\nlost, and is (by definition) no longer operational. Since this\ncan happen asynchronously from the normal behavior of the\ndriver, the cleanup may happen when holding other locks\nin the calling sequence (notably, the cio subchannel lock).\n\nPush the cleanup of the private-\u003ecp resources to a workqueue,\nwhere it can be done out from under that lock sequence and\na future patch can safely manage the locking requirements."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.2,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Reachable only via local VFIO/mdev device access (pread/pwrite/ioctl on an opened vfio-ccw mediated device); the vulnerable cp_free() runs from FSM not-operational handling triggered by CIO subchannel events and VFIO I/O, not from any network protocol.\nAC:L - A VFIO client can submit channel programs and concurrently provoke not-operational transitions (device close/reset, in-flight I/O, or subchannel state changes), controlling both sides of the race without rare external timing.\nPR:H - Exploitation requires opening and operating an s390 vfio-ccw passthrough mdev, which needs host administrator setup and CAP_SYS_ADMIN-level VFIO/IOMMU access that cannot be obtained from an unprivileged user namespace.\nUI:N - No victim interaction is required beyond the attacker already having VFIO device access; triggering the bug is fully automated through concurrent I/O submissions and device state transitions.\nS:C - vfio-ccw manages guest DMA page pinning/unpinning through the IOMMU for channel I/O passthrough; unsynchronized cp_free() under the wrong locks can corrupt that isolation boundary between the VFIO guest and the host kernel.\nC:H - Concurrent unsynchronized cp_free() on an active channel_program can double-free or use-after-free kmalloc\u0027d ccwchain/page_array metadata and pinned page state, yielding kernel memory disclosure primitives per UAF guidance.\nI:H - The same race while unpining guest pages and freeing channel-program structures can corrupt heap metadata and IOMMU mappings, enabling arbitrary kernel write or control-flow hijack per memory-corruption guidance.\nA:H - Calling sleeping vfio_unpin_pages()/cp_free() while holding the subchannel spinlock can deadlock the kernel, and the concurrent double-free/UAF reliably causes kernel oops/panic under load."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T12:40:09.822Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c9b85aa2cf73ea645e55e2c2670e0ddebfe1589b"
},
{
"url": "https://git.kernel.org/stable/c/f98a9890ca42f4223d2d4c50e0660af3e012fcb4"
},
{
"url": "https://git.kernel.org/stable/c/4e3301e2a651d742c05914f6074a25b8e41bce19"
},
{
"url": "https://git.kernel.org/stable/c/af1759d8e6e6da9ba94f30a2f92546f406899aa7"
},
{
"url": "https://git.kernel.org/stable/c/56100baa0eb7055b1026dfa73e696e8066ff71fd"
},
{
"url": "https://git.kernel.org/stable/c/0c11f61a876ed6fcca53d442ed3f33ea8362a0f9"
}
],
"title": "s390/vfio_ccw: Move cp cleanup out of not operational",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80549",
"datePublished": "2026-08-26T14:37:19.353Z",
"dateReserved": "2026-08-26T14:34:25.766Z",
"dateUpdated": "2026-08-27T12:40:09.822Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68297 (GCVE-0-2026-68297)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-19 16:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
tipc: fix u16 MTU truncation in media and bearer MTU validation
Both TIPC_NL_MEDIA_SET and TIPC_NL_BEARER_SET accept user-supplied
MTU values but only enforce a minimum bound, not a maximum. When a user
sets the MTU to a value exceeding U16_MAX (65535), it passes validation
but is silently truncated when assigned to u16 fields l->mtu and
l->advertised_mtu in tipc_link_create(). Values like 65536 (0x10000)
truncate to 0, causing a division by zero in tipc_link_set_queue_limits()
which computes TIPC_MAX_PUBL / (l->mtu / ITEM_SIZE). Other overflowing
values (e.g. 65537-131071) produce small incorrect MTU values, resulting
in link malfunction behaviors.
Crash stack (triggered as unprivileged user via user namespace):
tipc_link_set_queue_limits net/tipc/link.c:2531
tipc_link_create net/tipc/link.c:520
tipc_node_check_dest net/tipc/node.c:1279
tipc_disc_rcv net/tipc/discover.c:252
tipc_rcv net/tipc/node.c:2129
tipc_udp_recv net/tipc/udp_media.c:392
Two independent paths lack the upper bound check:
1. tipc_udp_mtu_bad() -- called from __tipc_nl_media_set() (MEDIA_SET)
2. inline check in __tipc_nl_bearer_set() at bearer.c:1160 (BEARER_SET)
Fix both by rejecting MTU values above U16_MAX.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 901271e0403af638c224987c2a4e55cebade7e91 Version: 901271e0403af638c224987c2a4e55cebade7e91 Version: 901271e0403af638c224987c2a4e55cebade7e91 Version: 901271e0403af638c224987c2a4e55cebade7e91 Version: 901271e0403af638c224987c2a4e55cebade7e91 Version: 901271e0403af638c224987c2a4e55cebade7e91 Version: 901271e0403af638c224987c2a4e55cebade7e91 Version: 901271e0403af638c224987c2a4e55cebade7e91 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/tipc/netlink.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "8bfdfe0dbb36a650b7c4dec1aeae078319938a0b",
"status": "affected",
"version": "901271e0403af638c224987c2a4e55cebade7e91",
"versionType": "git"
},
{
"lessThan": "dc4b577a083b361d25e118dc96d8281255ebe22c",
"status": "affected",
"version": "901271e0403af638c224987c2a4e55cebade7e91",
"versionType": "git"
},
{
"lessThan": "dfdfd987f1917c84766e097a6120a1f3f1634940",
"status": "affected",
"version": "901271e0403af638c224987c2a4e55cebade7e91",
"versionType": "git"
},
{
"lessThan": "f02334a9e378f7e07232b26dc3d2ab353339f040",
"status": "affected",
"version": "901271e0403af638c224987c2a4e55cebade7e91",
"versionType": "git"
},
{
"lessThan": "f4013598b69457dbea350df52e52daea6faef8eb",
"status": "affected",
"version": "901271e0403af638c224987c2a4e55cebade7e91",
"versionType": "git"
},
{
"lessThan": "1b8fb5a20508bfb0db854e01214888c761b3a911",
"status": "affected",
"version": "901271e0403af638c224987c2a4e55cebade7e91",
"versionType": "git"
},
{
"lessThan": "c1cda72f6acec02ebd45d913bf8527ff77336ba6",
"status": "affected",
"version": "901271e0403af638c224987c2a4e55cebade7e91",
"versionType": "git"
},
{
"lessThan": "9f29cd8a8e7901a2617c8064ce9f50fc67b97cb8",
"status": "affected",
"version": "901271e0403af638c224987c2a4e55cebade7e91",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/tipc/netlink.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.18"
},
{
"lessThan": "4.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.18",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: fix u16 MTU truncation in media and bearer MTU validation\n\nBoth TIPC_NL_MEDIA_SET and TIPC_NL_BEARER_SET accept user-supplied\nMTU values but only enforce a minimum bound, not a maximum. When a user\nsets the MTU to a value exceeding U16_MAX (65535), it passes validation\nbut is silently truncated when assigned to u16 fields l-\u003emtu and\nl-\u003eadvertised_mtu in tipc_link_create(). Values like 65536 (0x10000)\ntruncate to 0, causing a division by zero in tipc_link_set_queue_limits()\nwhich computes TIPC_MAX_PUBL / (l-\u003emtu / ITEM_SIZE). Other overflowing\nvalues (e.g. 65537-131071) produce small incorrect MTU values, resulting\nin link malfunction behaviors.\n\nCrash stack (triggered as unprivileged user via user namespace):\n\n tipc_link_set_queue_limits net/tipc/link.c:2531\n tipc_link_create net/tipc/link.c:520\n tipc_node_check_dest net/tipc/node.c:1279\n tipc_disc_rcv net/tipc/discover.c:252\n tipc_rcv net/tipc/node.c:2129\n tipc_udp_recv net/tipc/udp_media.c:392\n\nTwo independent paths lack the upper bound check:\n1. tipc_udp_mtu_bad() -- called from __tipc_nl_media_set() (MEDIA_SET)\n2. inline check in __tipc_nl_bearer_set() at bearer.c:1160 (BEARER_SET)\n\nFix both by rejecting MTU values above U16_MAX."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The attack begins with a local TIPC netlink command (TIPC_NL_BEARER_SET/TIPC_NL_MEDIA_SET) setting an out-of-range MTU, with the crash/corruption then triggered by locally generated discovery traffic and sendmsg() in the attacker\u0027s own network namespace.\nAC:L - The attacker fully controls both the bad MTU value and the discovery packet that creates the link, so the truncation and subsequent divide-by-zero or undersized-fragment path trigger deterministically on every attempt.\nPR:L - Both netlink ops are gated by GENL_UNS_ADMIN_PERM, i.e. CAP_NET_ADMIN in the owning user namespace, which any unprivileged user obtains via `unshare -Urn`; the commit message explicitly reports the crash reproduced as an unprivileged user through a user namespace.\nUI:N - The attacker performs every step (bearer setup, MTU configuration, packet injection, sendmsg) with no action from any other user or administrator.\nS:U - The truncated MTU corrupts only kernel state within the same kernel security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - Truncated MTUs below the TIPC header size propagate into tipc_msg_build() as pktmax, driving negative fragment remainders and oversized copies into undersized skbs; the resulting heap corruption and adjacent-object exposure can be leveraged to read kernel memory.\nI:H - The undersized-fragment path writes INT_H_SIZE plus header bytes and then a negative-length (huge unsigned) user copy into a buffer allocated at the truncated MTU size, giving an attacker-controlled linear heap overflow suitable for control-flow hijacking.\nA:H - MTU values truncating to under 20 make tipc_link_set_queue_limits() divide by zero inside tipc_link_create(), which runs in softirq context from tipc_udp_recv()/tipc_disc_rcv(), producing a kernel oops that is typically fatal in interrupt context."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:32:46.091Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/8bfdfe0dbb36a650b7c4dec1aeae078319938a0b"
},
{
"url": "https://git.kernel.org/stable/c/dc4b577a083b361d25e118dc96d8281255ebe22c"
},
{
"url": "https://git.kernel.org/stable/c/dfdfd987f1917c84766e097a6120a1f3f1634940"
},
{
"url": "https://git.kernel.org/stable/c/f02334a9e378f7e07232b26dc3d2ab353339f040"
},
{
"url": "https://git.kernel.org/stable/c/f4013598b69457dbea350df52e52daea6faef8eb"
},
{
"url": "https://git.kernel.org/stable/c/1b8fb5a20508bfb0db854e01214888c761b3a911"
},
{
"url": "https://git.kernel.org/stable/c/c1cda72f6acec02ebd45d913bf8527ff77336ba6"
},
{
"url": "https://git.kernel.org/stable/c/9f29cd8a8e7901a2617c8064ce9f50fc67b97cb8"
}
],
"title": "tipc: fix u16 MTU truncation in media and bearer MTU validation",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68297",
"datePublished": "2026-08-10T12:02:30.721Z",
"dateReserved": "2026-07-30T09:28:09.380Z",
"dateUpdated": "2026-08-19T16:32:46.091Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74748 (GCVE-0-2026-74748)
Vulnerability from cvelistv5
Published
2026-08-26 14:36
Modified
2026-08-27 05:01
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
netfilter: ipset: fix refcount race between list:set GC and swap
__ip_set_put_byindex() resolved the index to a set pointer under RCU,
then took ip_set_ref_lock in __ip_set_put() to decrement set->ref.
ip_set_swap() holds that same lock while swapping both the ip_set_list
slots and the two sets' ref counters, so it can interleave between the
dereference and the lock acquisition, leaving the caller to decrement a
set whose reference already moved to the other index and hit
BUG_ON(set->ref == 0). list_set_gc() reaches this from timer softirq,
which the nfnl mutex does not serialize against swap: an expiring
list:set member calls list_set_del() -> ip_set_put_byindex() while
IPSET_CMD_SWAP runs on the referenced sets.
Resolve the index and decrement under ip_set_ref_lock, as ip_set_swap()
already does, keeping the refcount tied to the index rather than to a
stale set pointer.
kernel BUG at net/netfilter/ipset/ip_set_core.c:685!
Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI
RIP: 0010:ip_set_put_byindex (net/netfilter/ipset/ip_set_core.c:870)
Call Trace:
<IRQ>
list_set_del (net/netfilter/ipset/ip_set_list_set.c:159)
set_cleanup_entries (net/netfilter/ipset/ip_set_list_set.c:181)
list_set_gc (net/netfilter/ipset/ip_set_list_set.c:578)
call_timer_fn (kernel/time/timer.c:1748)
__run_timers (kernel/time/timer.c:1799 kernel/time/timer.c:2374)
run_timer_softirq (kernel/time/timer.c:2405)
</IRQ>
Kernel panic - not syncing: Fatal exception in interrupt
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 9076aea76538556224e7d73ab718f8841330818a Version: 9076aea76538556224e7d73ab718f8841330818a Version: 9076aea76538556224e7d73ab718f8841330818a Version: 9076aea76538556224e7d73ab718f8841330818a Version: 9076aea76538556224e7d73ab718f8841330818a Version: 9076aea76538556224e7d73ab718f8841330818a Version: 9076aea76538556224e7d73ab718f8841330818a Version: 9076aea76538556224e7d73ab718f8841330818a |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/netfilter/ipset/ip_set_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "97a01de0c6321b7210d30d0a4d60f10f561097c7",
"status": "affected",
"version": "9076aea76538556224e7d73ab718f8841330818a",
"versionType": "git"
},
{
"lessThan": "c21afc7c216a4d257a4f3f300e0791890bc846b9",
"status": "affected",
"version": "9076aea76538556224e7d73ab718f8841330818a",
"versionType": "git"
},
{
"lessThan": "b0aab9dd1a348b99d75ff52765719d0cc2050630",
"status": "affected",
"version": "9076aea76538556224e7d73ab718f8841330818a",
"versionType": "git"
},
{
"lessThan": "b891e7a6bb06e0f6560e5932665ac660acd12225",
"status": "affected",
"version": "9076aea76538556224e7d73ab718f8841330818a",
"versionType": "git"
},
{
"lessThan": "20cb13a523f0a05cb2d0a7d72abae687683712e0",
"status": "affected",
"version": "9076aea76538556224e7d73ab718f8841330818a",
"versionType": "git"
},
{
"lessThan": "cb20da33839f28f590c99f16bafaa6151451c0e8",
"status": "affected",
"version": "9076aea76538556224e7d73ab718f8841330818a",
"versionType": "git"
},
{
"lessThan": "24ffcb1e1688c55fd2a505f064295cd28eac546d",
"status": "affected",
"version": "9076aea76538556224e7d73ab718f8841330818a",
"versionType": "git"
},
{
"lessThan": "0c88868271653537ed443272dd8e7d13634d214b",
"status": "affected",
"version": "9076aea76538556224e7d73ab718f8841330818a",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/netfilter/ipset/ip_set_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.8"
},
{
"lessThan": "3.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "3.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "3.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "3.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "3.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "3.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.46",
"versionStartIncluding": "3.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.10",
"versionStartIncluding": "3.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: ipset: fix refcount race between list:set GC and swap\n\n__ip_set_put_byindex() resolved the index to a set pointer under RCU,\nthen took ip_set_ref_lock in __ip_set_put() to decrement set-\u003eref.\nip_set_swap() holds that same lock while swapping both the ip_set_list\nslots and the two sets\u0027 ref counters, so it can interleave between the\ndereference and the lock acquisition, leaving the caller to decrement a\nset whose reference already moved to the other index and hit\nBUG_ON(set-\u003eref == 0). list_set_gc() reaches this from timer softirq,\nwhich the nfnl mutex does not serialize against swap: an expiring\nlist:set member calls list_set_del() -\u003e ip_set_put_byindex() while\nIPSET_CMD_SWAP runs on the referenced sets.\n\nResolve the index and decrement under ip_set_ref_lock, as ip_set_swap()\nalready does, keeping the refcount tied to the index rather than to a\nstale set pointer.\n\n kernel BUG at net/netfilter/ipset/ip_set_core.c:685!\n Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI\n RIP: 0010:ip_set_put_byindex (net/netfilter/ipset/ip_set_core.c:870)\n Call Trace:\n \u003cIRQ\u003e\n list_set_del (net/netfilter/ipset/ip_set_list_set.c:159)\n set_cleanup_entries (net/netfilter/ipset/ip_set_list_set.c:181)\n list_set_gc (net/netfilter/ipset/ip_set_list_set.c:578)\n call_timer_fn (kernel/time/timer.c:1748)\n __run_timers (kernel/time/timer.c:1799 kernel/time/timer.c:2374)\n run_timer_softirq (kernel/time/timer.c:2405)\n \u003c/IRQ\u003e\n Kernel panic - not syncing: Fatal exception in interrupt"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires issuing IPSET_CMD_SWAP over the NETLINK_NETFILTER socket; nfnetlink is a local userspace-to-kernel control interface, not reachable by remote network packets.\nAC:L - An attacker with CAP_NET_ADMIN controls both sides of the race by creating a timeout-enabled list:set, timing member expiry to drive list_set_gc(), and repeatedly issuing IPSET_CMD_SWAP to interleave with the GC softirq.\nPR:L - IPSET_CMD_SWAP is gated by netlink_net_capable(skb, CAP_NET_ADMIN); CAP_NET_ADMIN is obtainable by unprivileged users inside a user namespace (unshare -Urn), so real init-namespace root is not required.\nUI:N - Triggering the refcount race requires only attacker-controlled netlink commands and timer-driven GC; no victim user action such as opening files or mounting filesystems is needed.\nS:U - The impact is a kernel BUG/panic and potential memory-safety corruption within the same kernel security domain; it does not cross a VM, container, or IOMMU boundary to affect a separate security authority.\nC:H - The refcount race between list_set_gc and ip_set_swap can corrupt set lifetime management; stale pointer decrements can leave sets with incorrect refcounts, enabling use-after-free and arbitrary kernel memory disclosure.\nI:H - Incorrect refcount decrements on stale set pointers can free ip_set objects while still referenced in ip_set_list, providing heap reuse primitives that could be leveraged for arbitrary kernel memory corruption or code execution.\nA:H - The demonstrated failure path hits BUG_ON(set-\u003eref == 0) in timer softirq during list_set_gc, producing a fatal kernel oops and panic that crashes the entire system."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T05:01:09.517Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/97a01de0c6321b7210d30d0a4d60f10f561097c7"
},
{
"url": "https://git.kernel.org/stable/c/c21afc7c216a4d257a4f3f300e0791890bc846b9"
},
{
"url": "https://git.kernel.org/stable/c/b0aab9dd1a348b99d75ff52765719d0cc2050630"
},
{
"url": "https://git.kernel.org/stable/c/b891e7a6bb06e0f6560e5932665ac660acd12225"
},
{
"url": "https://git.kernel.org/stable/c/20cb13a523f0a05cb2d0a7d72abae687683712e0"
},
{
"url": "https://git.kernel.org/stable/c/cb20da33839f28f590c99f16bafaa6151451c0e8"
},
{
"url": "https://git.kernel.org/stable/c/24ffcb1e1688c55fd2a505f064295cd28eac546d"
},
{
"url": "https://git.kernel.org/stable/c/0c88868271653537ed443272dd8e7d13634d214b"
}
],
"title": "netfilter: ipset: fix refcount race between list:set GC and swap",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74748",
"datePublished": "2026-08-26T14:36:57.164Z",
"dateReserved": "2026-08-15T05:44:03.931Z",
"dateUpdated": "2026-08-27T05:01:09.517Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68327 (GCVE-0-2026-68327)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wan: wanxl: Only reset hardware after BAR mapping
wanxl_pci_init_one() stores the freshly allocated card in driver data
before the PLX BAR is mapped. Several early probe failures then unwind
through wanxl_pci_remove_one(), including failure to allocate the coherent
status area or to restore the DMA mask.
wanxl_pci_remove_one() unconditionally calls wanxl_reset(), and
wanxl_reset() dereferences card->plx. On those early failures card->plx
is still NULL, so the error path can dereference a NULL MMIO pointer.
Only issue the hardware reset once the BAR mapping exists. The remaining
cleanup in wanxl_pci_remove_one() already checks whether later resources
were allocated.
This issue was found by a static analysis checker and confirmed by
manual source review.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wan/wanxl.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ef394eeb9d5ec6db8d979eec6d27f56c2ebc6523",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "3d9617d856ebddcdddbab0ce877c397420f59f55",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "897e289db1e4d00ca6419cfe733c646492147270",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "f4834132773f15ffb255127499c8443947fa7d0f",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "b9e2ff70e96acf83693b27987e0390bad9f83efa",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "59cbe6cfa0fa23c192351cc284e30707309f6741",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "2fe22d58b3797d741570f9873b26653fd511576c",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "91957b89da995607cb654b1f9a3c126ddbaee10f",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wan/wanxl.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwan: wanxl: Only reset hardware after BAR mapping\n\nwanxl_pci_init_one() stores the freshly allocated card in driver data\nbefore the PLX BAR is mapped. Several early probe failures then unwind\nthrough wanxl_pci_remove_one(), including failure to allocate the coherent\nstatus area or to restore the DMA mask.\n\nwanxl_pci_remove_one() unconditionally calls wanxl_reset(), and\nwanxl_reset() dereferences card-\u003eplx. On those early failures card-\u003eplx\nis still NULL, so the error path can dereference a NULL MMIO pointer.\n\nOnly issue the hardware reset once the BAR mapping exists. The remaining\ncleanup in wanxl_pci_remove_one() already checks whether later resources\nwere allocated.\n\nThis issue was found by a static analysis checker and confirmed by\nmanual source review."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:23.256Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ef394eeb9d5ec6db8d979eec6d27f56c2ebc6523"
},
{
"url": "https://git.kernel.org/stable/c/3d9617d856ebddcdddbab0ce877c397420f59f55"
},
{
"url": "https://git.kernel.org/stable/c/897e289db1e4d00ca6419cfe733c646492147270"
},
{
"url": "https://git.kernel.org/stable/c/f4834132773f15ffb255127499c8443947fa7d0f"
},
{
"url": "https://git.kernel.org/stable/c/b9e2ff70e96acf83693b27987e0390bad9f83efa"
},
{
"url": "https://git.kernel.org/stable/c/59cbe6cfa0fa23c192351cc284e30707309f6741"
},
{
"url": "https://git.kernel.org/stable/c/2fe22d58b3797d741570f9873b26653fd511576c"
},
{
"url": "https://git.kernel.org/stable/c/91957b89da995607cb654b1f9a3c126ddbaee10f"
}
],
"title": "wan: wanxl: Only reset hardware after BAR mapping",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68327",
"datePublished": "2026-08-10T12:03:03.398Z",
"dateReserved": "2026-07-30T09:28:09.382Z",
"dateUpdated": "2026-08-19T16:33:23.256Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74556 (GCVE-0-2026-74556)
Vulnerability from cvelistv5
Published
2026-08-15 12:28
Modified
2026-08-19 16:38
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer
iscsi_tcp_hdr_dissect() receives the data segment of several PDU types
into the fixed-size conn->data buffer, which is allocated for
ISCSI_DEF_MAX_RECV_SEG_LEN (8192) bytes. For the LOGIN_RSP, TEXT_RSP,
REJECT and ASYNC_EVENT opcodes the dissect path already rejects a PDU
whose DataSegmentLength exceeds that buffer.
The SCSI Command Response (ISCSI_OP_SCSI_CMD_RSP) path also copies its
data segment (sense/response data) into conn->data via
iscsi_tcp_data_recv_prep(), but it does so without the same check. The
only upstream bound on in.datalen is conn->max_recv_dlength, the
initiator's advertised MaxRecvDataSegmentLength, which is commonly
negotiated well above 8192 (open-iscsi defaults to 262144). A target
that returns a SCSI Response with a DataSegmentLength between 8193 and
max_recv_dlength therefore overflows the 8192-byte conn->data buffer.
Once the same bound applies, ISCSI_OP_SCSI_CMD_RSP is handled exactly
like those responses: bound the data segment, receive it into conn->data
when present, and otherwise complete the PDU with no data. Fold the
opcode into that case group rather than duplicating the check.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: a081c13e39b5c17052a7b46fafa61019c4c110ff Version: a081c13e39b5c17052a7b46fafa61019c4c110ff Version: a081c13e39b5c17052a7b46fafa61019c4c110ff Version: a081c13e39b5c17052a7b46fafa61019c4c110ff Version: a081c13e39b5c17052a7b46fafa61019c4c110ff Version: a081c13e39b5c17052a7b46fafa61019c4c110ff Version: a081c13e39b5c17052a7b46fafa61019c4c110ff Version: a081c13e39b5c17052a7b46fafa61019c4c110ff |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/scsi/libiscsi_tcp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a51812842084fd390590ab8dc0431f10c73ddc56",
"status": "affected",
"version": "a081c13e39b5c17052a7b46fafa61019c4c110ff",
"versionType": "git"
},
{
"lessThan": "a8f94cc9f0e5759252551be3a172960c57f21f54",
"status": "affected",
"version": "a081c13e39b5c17052a7b46fafa61019c4c110ff",
"versionType": "git"
},
{
"lessThan": "f1a3a51fc5dba0e99532379665069f1700da6b44",
"status": "affected",
"version": "a081c13e39b5c17052a7b46fafa61019c4c110ff",
"versionType": "git"
},
{
"lessThan": "c97b5265cc47775f77fd2a23d6bde0426997b233",
"status": "affected",
"version": "a081c13e39b5c17052a7b46fafa61019c4c110ff",
"versionType": "git"
},
{
"lessThan": "084af0253673425ce2ae62e3c7f74f0dd023711b",
"status": "affected",
"version": "a081c13e39b5c17052a7b46fafa61019c4c110ff",
"versionType": "git"
},
{
"lessThan": "72815741715bd41556dac5eeb068bf0f8af06ee7",
"status": "affected",
"version": "a081c13e39b5c17052a7b46fafa61019c4c110ff",
"versionType": "git"
},
{
"lessThan": "b0aa3e8e2ab4ca92adb28a3ef41873b3363b8676",
"status": "affected",
"version": "a081c13e39b5c17052a7b46fafa61019c4c110ff",
"versionType": "git"
},
{
"lessThan": "c1dea15f819cded9b3faf58f8bec72323568b6e6",
"status": "affected",
"version": "a081c13e39b5c17052a7b46fafa61019c4c110ff",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/scsi/libiscsi_tcp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.29"
},
{
"lessThan": "2.6.29",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.29",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.29",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.29",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "2.6.29",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "2.6.29",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "2.6.29",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "2.6.29",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.29",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer\n\niscsi_tcp_hdr_dissect() receives the data segment of several PDU types\ninto the fixed-size conn-\u003edata buffer, which is allocated for\nISCSI_DEF_MAX_RECV_SEG_LEN (8192) bytes. For the LOGIN_RSP, TEXT_RSP,\nREJECT and ASYNC_EVENT opcodes the dissect path already rejects a PDU\nwhose DataSegmentLength exceeds that buffer.\n\nThe SCSI Command Response (ISCSI_OP_SCSI_CMD_RSP) path also copies its\ndata segment (sense/response data) into conn-\u003edata via\niscsi_tcp_data_recv_prep(), but it does so without the same check. The\nonly upstream bound on in.datalen is conn-\u003emax_recv_dlength, the\ninitiator\u0027s advertised MaxRecvDataSegmentLength, which is commonly\nnegotiated well above 8192 (open-iscsi defaults to 262144). A target\nthat returns a SCSI Response with a DataSegmentLength between 8193 and\nmax_recv_dlength therefore overflows the 8192-byte conn-\u003edata buffer.\n\nOnce the same bound applies, ISCSI_OP_SCSI_CMD_RSP is handled exactly\nlike those responses: bound the data segment, receive it into conn-\u003edata\nwhen present, and otherwise complete the PDU with no data. Fold the\nopcode into that case group rather than duplicating the check."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - A malicious or compromised iSCSI target delivers crafted SCSI Command Response PDUs over the established TCP iSCSI session; reception flows through iscsi_sw_tcp_recv/iscsi_tcp_recv_skb into iscsi_tcp_hdr_dissect without local access.\nAC:L - The attacker controls the target and can set DataSegmentLength between 8193 and negotiated max_recv_dlength (open-iscsi commonly 262144) on SCSI_CMD_RSP for any outstanding command ITT; no races or victim-specific heap layout are required.\nPR:N - No privileges on the victim host are needed; a remote attacker acting as or MITMing the iSCSI target sends malicious responses after session login, independent of victim user accounts or capabilities.\nUI:N - On systems with persistent iSCSI sessions (cloud VMs, SAN-boot hosts, Kubernetes iSCSI volumes), exploitation triggers automatically during normal SCSI I/O when command responses are received; no victim action is needed at attack time.\nS:U - Heap corruption is confined to the kernel iSCSI initiator on the affected host; successful exploitation yields kernel compromise or DoS within the same security authority, not a VM escape or cross-boundary scope change.\nC:H - iscsi_tcp_segment_recv memcpy writes up to max_recv_dlength bytes into an 8192-byte conn-\u003edata buffer, causing a large heap overflow whose controlled corruption can be leveraged for arbitrary kernel memory disclosure.\nI:H - Attacker-controlled response data is copied past the fixed conn-\u003edata allocation via iscsi_tcp_data_recv_prep/iscsi_segment_init_linear, enabling heap metadata/object corruption exploitable for arbitrary kernel write and privilege escalation.\nA:H - Overflowing the conn-\u003edata heap buffer can immediately corrupt adjacent kernel allocations and cause oops/panic; a malicious target can repeatedly trigger this on active sessions to deny storage availability."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:38:57.393Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a51812842084fd390590ab8dc0431f10c73ddc56"
},
{
"url": "https://git.kernel.org/stable/c/a8f94cc9f0e5759252551be3a172960c57f21f54"
},
{
"url": "https://git.kernel.org/stable/c/f1a3a51fc5dba0e99532379665069f1700da6b44"
},
{
"url": "https://git.kernel.org/stable/c/c97b5265cc47775f77fd2a23d6bde0426997b233"
},
{
"url": "https://git.kernel.org/stable/c/084af0253673425ce2ae62e3c7f74f0dd023711b"
},
{
"url": "https://git.kernel.org/stable/c/72815741715bd41556dac5eeb068bf0f8af06ee7"
},
{
"url": "https://git.kernel.org/stable/c/b0aa3e8e2ab4ca92adb28a3ef41873b3363b8676"
},
{
"url": "https://git.kernel.org/stable/c/c1dea15f819cded9b3faf58f8bec72323568b6e6"
}
],
"title": "scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74556",
"datePublished": "2026-08-15T12:28:01.359Z",
"dateReserved": "2026-08-15T05:44:03.916Z",
"dateUpdated": "2026-08-19T16:38:57.393Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68367 (GCVE-0-2026-68367)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: f_tcm: synchronize delayed set_alt with teardown
The f_tcm set_alt() path defers endpoint setup to a work item and
completes the delayed status response from process context. The delayed
work uses f_tcm private state and may complete the setup request after
disconnect or function teardown has already moved on.
Cancel and drain the delayed set_alt work when the function is unbound or
freed. For disable paths, which are reached under the composite device
lock, use a small state machine and a non-sleeping cancellation path
instead of cancel_work_sync(). If the work is already running, mark it
cancelled and let the worker own the cleanup; otherwise tcm_disable() can
cancel the queued work and clean up immediately.
Also serialize the final delayed-status completion with the cancellation
check while holding the composite device lock. This prevents a disconnect
from clearing delayed_status while the worker is about to complete the
control request.
Validation reproduced this kernel report:
BUG: KASAN: slab-use-after-free in tcm_delayed_set_alt+0x6c/0xef0
Call Trace:
<TASK>
dump_stack_lvl+0x66/0xa0
print_report+0xce/0x630
? tcm_delayed_set_alt+0x6c/0xef0
? srso_alias_return_thunk+0x5/0xfbef5
? __virt_addr_valid+0x188/0x320
? tcm_delayed_set_alt+0x6c/0xef0
kasan_report+0xe0/0x110
? tcm_delayed_set_alt+0x6c/0xef0
tcm_delayed_set_alt+0x6c/0xef0
? __pfx_tcm_delayed_set_alt+0x10/0x10
? process_one_work+0x4cb/0xb90
? rcu_is_watching+0x20/0x50
? tcm_delayed_set_alt+0x9/0xef0
process_one_work+0x4d7/0xb90
? __pfx_process_one_work+0x10/0x10
? srso_alias_return_thunk+0x5/0xfbef5
? __list_add_valid_or_report+0x37/0xf0
? __pfx_tcm_delayed_set_alt+0x10/0x10
? srso_alias_return_thunk+0x5/0xfbef5
worker_thread+0x2d8/0x570
? __pfx_worker_thread+0x10/0x10
kthread+0x1ad/0x1f0
? __pfx_kthread+0x10/0x10
ret_from_fork+0x3c9/0x540
? __pfx_ret_from_fork+0x10/0x10
? srso_alias_return_thunk+0x5/0xfbef5
? __switch_to+0x2e9/0x730
? __pfx_kthread+0x10/0x10
ret_from_fork_asm+0x1a/0x30
</TASK>
Allocated by task 544:
kasan_save_stack+0x33/0x60
kasan_save_track+0x14/0x30
__kasan_kmalloc+0x8f/0xa0
tcm_alloc+0x68/0x180
usb_get_function+0x36/0x60
config_usb_cfg_link+0x125/0x1b0
configfs_symlink+0x322/0x890
vfs_symlink+0xc2/0x270
filename_symlinkat+0x295/0x2f0
__x64_sys_symlinkat+0x62/0x90
do_syscall_64+0x115/0x6a0
entry_SYSCALL_64_after_hwframe+0x77/0x7f
Freed by task 661:
kasan_save_stack+0x33/0x60
kasan_save_track+0x14/0x30
kasan_save_free_info+0x3b/0x60
__kasan_slab_free+0x43/0x70
kfree+0x2f9/0x530
config_usb_cfg_unlink+0x173/0x1e0
configfs_unlink+0x1fa/0x340
vfs_unlink+0x15c/0x510
filename_unlinkat+0x2ba/0x450
__x64_sys_unlinkat+0x63/0x90
do_syscall_64+0x115/0x6a0
entry_SYSCALL_64_after_hwframe+0x77/0x7f
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: c52661d60f636d17e26ad834457db333bd1df494 Version: c52661d60f636d17e26ad834457db333bd1df494 Version: c52661d60f636d17e26ad834457db333bd1df494 Version: c52661d60f636d17e26ad834457db333bd1df494 Version: c52661d60f636d17e26ad834457db333bd1df494 Version: c52661d60f636d17e26ad834457db333bd1df494 Version: c52661d60f636d17e26ad834457db333bd1df494 Version: c52661d60f636d17e26ad834457db333bd1df494 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/gadget/function/f_tcm.c",
"drivers/usb/gadget/function/tcm.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "8fb317058d165c88f3344f59439c14872c162b3c",
"status": "affected",
"version": "c52661d60f636d17e26ad834457db333bd1df494",
"versionType": "git"
},
{
"lessThan": "90431d8523c0c1c9f8e3e3f0895727063f93da85",
"status": "affected",
"version": "c52661d60f636d17e26ad834457db333bd1df494",
"versionType": "git"
},
{
"lessThan": "ee07d09419f1c59c74f73107aa08444f2f2fc6c8",
"status": "affected",
"version": "c52661d60f636d17e26ad834457db333bd1df494",
"versionType": "git"
},
{
"lessThan": "3118bb872c7dff653294f193d5328a476619e04d",
"status": "affected",
"version": "c52661d60f636d17e26ad834457db333bd1df494",
"versionType": "git"
},
{
"lessThan": "a6eb5a0ae7cd313cfd7df78decd8f43b64c68703",
"status": "affected",
"version": "c52661d60f636d17e26ad834457db333bd1df494",
"versionType": "git"
},
{
"lessThan": "f282242906c12fd476b86757afba51f211d4f959",
"status": "affected",
"version": "c52661d60f636d17e26ad834457db333bd1df494",
"versionType": "git"
},
{
"lessThan": "4c6c6a5588b9a2f8437fb794e852d05fa60ebe53",
"status": "affected",
"version": "c52661d60f636d17e26ad834457db333bd1df494",
"versionType": "git"
},
{
"lessThan": "79e2d75725c85607f8a9d87ae9cace62a19f767d",
"status": "affected",
"version": "c52661d60f636d17e26ad834457db333bd1df494",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/usb/gadget/function/f_tcm.c",
"drivers/usb/gadget/function/tcm.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.5"
},
{
"lessThan": "3.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: f_tcm: synchronize delayed set_alt with teardown\n\nThe f_tcm set_alt() path defers endpoint setup to a work item and\ncompletes the delayed status response from process context. The delayed\nwork uses f_tcm private state and may complete the setup request after\ndisconnect or function teardown has already moved on.\n\nCancel and drain the delayed set_alt work when the function is unbound or\nfreed. For disable paths, which are reached under the composite device\nlock, use a small state machine and a non-sleeping cancellation path\ninstead of cancel_work_sync(). If the work is already running, mark it\ncancelled and let the worker own the cleanup; otherwise tcm_disable() can\ncancel the queued work and clean up immediately.\n\nAlso serialize the final delayed-status completion with the cancellation\ncheck while holding the composite device lock. This prevents a disconnect\nfrom clearing delayed_status while the worker is about to complete the\ncontrol request.\n\nValidation reproduced this kernel report:\nBUG: KASAN: slab-use-after-free in tcm_delayed_set_alt+0x6c/0xef0\n\nCall Trace:\n \u003cTASK\u003e\n dump_stack_lvl+0x66/0xa0\n print_report+0xce/0x630\n ? tcm_delayed_set_alt+0x6c/0xef0\n ? srso_alias_return_thunk+0x5/0xfbef5\n ? __virt_addr_valid+0x188/0x320\n ? tcm_delayed_set_alt+0x6c/0xef0\n kasan_report+0xe0/0x110\n ? tcm_delayed_set_alt+0x6c/0xef0\n tcm_delayed_set_alt+0x6c/0xef0\n ? __pfx_tcm_delayed_set_alt+0x10/0x10\n ? process_one_work+0x4cb/0xb90\n ? rcu_is_watching+0x20/0x50\n ? tcm_delayed_set_alt+0x9/0xef0\n process_one_work+0x4d7/0xb90\n ? __pfx_process_one_work+0x10/0x10\n ? srso_alias_return_thunk+0x5/0xfbef5\n ? __list_add_valid_or_report+0x37/0xf0\n ? __pfx_tcm_delayed_set_alt+0x10/0x10\n ? srso_alias_return_thunk+0x5/0xfbef5\n worker_thread+0x2d8/0x570\n ? __pfx_worker_thread+0x10/0x10\n kthread+0x1ad/0x1f0\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x3c9/0x540\n ? __pfx_ret_from_fork+0x10/0x10\n ? srso_alias_return_thunk+0x5/0xfbef5\n ? __switch_to+0x2e9/0x730\n ? __pfx_kthread+0x10/0x10\n ret_from_fork_asm+0x1a/0x30\n \u003c/TASK\u003e\n\nAllocated by task 544:\n kasan_save_stack+0x33/0x60\n kasan_save_track+0x14/0x30\n __kasan_kmalloc+0x8f/0xa0\n tcm_alloc+0x68/0x180\n usb_get_function+0x36/0x60\n config_usb_cfg_link+0x125/0x1b0\n configfs_symlink+0x322/0x890\n vfs_symlink+0xc2/0x270\n filename_symlinkat+0x295/0x2f0\n __x64_sys_symlinkat+0x62/0x90\n do_syscall_64+0x115/0x6a0\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nFreed by task 661:\n kasan_save_stack+0x33/0x60\n kasan_save_track+0x14/0x30\n kasan_save_free_info+0x3b/0x60\n __kasan_slab_free+0x43/0x70\n kfree+0x2f9/0x530\n config_usb_cfg_unlink+0x173/0x1e0\n configfs_unlink+0x1fa/0x340\n vfs_unlink+0x15c/0x510\n filename_unlinkat+0x2ba/0x450\n __x64_sys_unlinkat+0x63/0x90\n do_syscall_64+0x115/0x6a0\n entry_SYSCALL_64_after_hwframe+0x77/0x7f"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:18.779Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/8fb317058d165c88f3344f59439c14872c162b3c"
},
{
"url": "https://git.kernel.org/stable/c/90431d8523c0c1c9f8e3e3f0895727063f93da85"
},
{
"url": "https://git.kernel.org/stable/c/ee07d09419f1c59c74f73107aa08444f2f2fc6c8"
},
{
"url": "https://git.kernel.org/stable/c/3118bb872c7dff653294f193d5328a476619e04d"
},
{
"url": "https://git.kernel.org/stable/c/a6eb5a0ae7cd313cfd7df78decd8f43b64c68703"
},
{
"url": "https://git.kernel.org/stable/c/f282242906c12fd476b86757afba51f211d4f959"
},
{
"url": "https://git.kernel.org/stable/c/4c6c6a5588b9a2f8437fb794e852d05fa60ebe53"
},
{
"url": "https://git.kernel.org/stable/c/79e2d75725c85607f8a9d87ae9cace62a19f767d"
}
],
"title": "usb: gadget: f_tcm: synchronize delayed set_alt with teardown",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68367",
"datePublished": "2026-08-10T12:03:44.600Z",
"dateReserved": "2026-07-30T09:28:09.385Z",
"dateUpdated": "2026-08-23T12:46:18.779Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68352 (GCVE-0-2026-68352)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: ath6kl: fix OOB read from firmware IE lengths in connect event
The firmware-controlled beacon_ie_len, assoc_req_len, and assoc_resp_len
fields in ath6kl_wmi_connect_event_rx() are not validated against the
buffer length. Their sum (up to 765) can exceed the actual WMI event
data, causing out-of-bounds reads during IE parsing and state corruption
of wmi->is_wmm_enabled.
Add a check that the total IE length fits within the buffer.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 Version: bdcd81707973cf8aa9305337166f8ee842a050d4 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/ath/ath6kl/wmi.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "7cae33e3e09a080db96e3a8980c2c8d288318320",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "1eeed9efc9a40e0635e910c37fee86543041b4e1",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "a38d7d6376b295245b53bc98b7ca682c027abaf7",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "1c690f7c4c5b37108ac8c98b94ce1b3c655a4f5e",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "d70c0a850c21b57a6f46ce363860203389bbeaa6",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "33b5342d2080657054ddf89ef1199b426a37dae8",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "94e1bfcefe8264a207c2fda2febb954e70a34b42",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
},
{
"lessThan": "6b47b29730de3232b919d8362749f6814c5f2a33",
"status": "affected",
"version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/ath/ath6kl/wmi.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.2"
},
{
"lessThan": "3.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath6kl: fix OOB read from firmware IE lengths in connect event\n\nThe firmware-controlled beacon_ie_len, assoc_req_len, and assoc_resp_len\nfields in ath6kl_wmi_connect_event_rx() are not validated against the\nbuffer length. Their sum (up to 765) can exceed the actual WMI event\ndata, causing out-of-bounds reads during IE parsing and state corruption\nof wmi-\u003eis_wmm_enabled.\n\nAdd a check that the total IE length fits within the buffer."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The malformed connect event is produced from the 802.11 association exchange with the peer AP, so a rogue/evil-twin AP or frame-injecting attacker within radio range of the ath6kl station supplies the oversized IE lengths; no local access is needed but the attacker must share the wireless link layer.\nAC:L - The attacker controls the beacon/assoc-request/assoc-response IE content and declared lengths and can force repeated (re)association or roaming with deauth frames until the connect event is emitted, so triggering is reliable and repeatable with no conditions outside the attacker\u0027s control.\nPR:N - No credentials or local account are required; the connect event is processed as part of establishing the link with an attacker-controlled AP, before any user-level authorization on the victim system is involved.\nUI:N - No victim action is needed \u2014 a station with a saved profile auto-associates, and the SME_CONNECTED roam path (cfg80211_roamed) processes the same event while the station is already connected, entirely attacker-driven.\nS:U - The out-of-bounds read, the corrupted wmi-\u003eis_wmm_enabled state and any resulting crash are all confined to the kernel of the affected host; no VM, IOMMU or sandbox boundary is crossed.\nC:H - Up to 765 bytes of adjacent kernel heap past the WMI event buffer are read and then exported to userspace: copied into the cfg80211 BSS IE cache (readable via unprivileged nl80211 GET_SCAN) and delivered as req_ie/resp_ie in cfg80211_connect_result()/cfg80211_roamed(), a repeatable kernel memory disclosure rather than a few stray bytes.\nI:L - There is no out-of-bounds write, but out-of-bounds bytes drive driver state: wmi-\u003eis_wmm_enabled is set from memory beyond the buffer and bogus IE data is inserted into the cfg80211 BSS cache, giving limited attacker-influenced modification of kernel-held data.\nA:H - The IE walk dereferences up to 765 bytes past the received skb and can run off the end of the allocation into unmapped memory (or trip KASAN/DEBUG_PAGEALLOC), producing a kernel oops/panic that the adjacent attacker can retrigger at will."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:55.758Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/7cae33e3e09a080db96e3a8980c2c8d288318320"
},
{
"url": "https://git.kernel.org/stable/c/1eeed9efc9a40e0635e910c37fee86543041b4e1"
},
{
"url": "https://git.kernel.org/stable/c/a38d7d6376b295245b53bc98b7ca682c027abaf7"
},
{
"url": "https://git.kernel.org/stable/c/1c690f7c4c5b37108ac8c98b94ce1b3c655a4f5e"
},
{
"url": "https://git.kernel.org/stable/c/d70c0a850c21b57a6f46ce363860203389bbeaa6"
},
{
"url": "https://git.kernel.org/stable/c/33b5342d2080657054ddf89ef1199b426a37dae8"
},
{
"url": "https://git.kernel.org/stable/c/94e1bfcefe8264a207c2fda2febb954e70a34b42"
},
{
"url": "https://git.kernel.org/stable/c/6b47b29730de3232b919d8362749f6814c5f2a33"
}
],
"title": "wifi: ath6kl: fix OOB read from firmware IE lengths in connect event",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68352",
"datePublished": "2026-08-10T12:03:29.304Z",
"dateReserved": "2026-07-30T09:28:09.384Z",
"dateUpdated": "2026-08-19T16:33:55.758Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64507 (GCVE-0-2026-64507)
Vulnerability from cvelistv5
Published
2026-07-25 08:52
Modified
2026-08-19 16:28
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
x86/bugs: Enable IBPB flush on BPF JIT allocation
Enable hardening against JIT spraying when Spectre-v2 mitigations are in
use. Specifically, issue an IBPB flush on BPF JIT memory reuse. Skip
enabling the IBPB flush if the BPF dispatcher is already using a retpoline
sequence.
This hardening applies only when BPF-JIT is in use. Guard the enabling
under CONFIG_BPF_JIT so that bugs.c still builds with CONFIG_BPF_JIT=n.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 57631054fae6dcc9c892ae6310b58bbb6f6e5048 Version: 57631054fae6dcc9c892ae6310b58bbb6f6e5048 Version: 57631054fae6dcc9c892ae6310b58bbb6f6e5048 Version: 57631054fae6dcc9c892ae6310b58bbb6f6e5048 Version: 57631054fae6dcc9c892ae6310b58bbb6f6e5048 Version: 57631054fae6dcc9c892ae6310b58bbb6f6e5048 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"arch/x86/include/asm/nospec-branch.h",
"arch/x86/kernel/cpu/bugs.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "25dbcd31781e2bc3cd63d873af1fcd06f863a126",
"status": "affected",
"version": "57631054fae6dcc9c892ae6310b58bbb6f6e5048",
"versionType": "git"
},
{
"lessThan": "cb27f3bf915cc0f20fc0c48da9059304e39ebd35",
"status": "affected",
"version": "57631054fae6dcc9c892ae6310b58bbb6f6e5048",
"versionType": "git"
},
{
"lessThan": "9354248fc1c33a844ca1872761f6668b393e8c37",
"status": "affected",
"version": "57631054fae6dcc9c892ae6310b58bbb6f6e5048",
"versionType": "git"
},
{
"lessThan": "8a4c8af9ae67eb072d90d1b339f14d27a82bd2a1",
"status": "affected",
"version": "57631054fae6dcc9c892ae6310b58bbb6f6e5048",
"versionType": "git"
},
{
"lessThan": "52440e15d9628f8f239373c0f2e5e8f92feea2df",
"status": "affected",
"version": "57631054fae6dcc9c892ae6310b58bbb6f6e5048",
"versionType": "git"
},
{
"lessThan": "a3af84b0fa00ead01fcd0e28b5d773ff25990a0d",
"status": "affected",
"version": "57631054fae6dcc9c892ae6310b58bbb6f6e5048",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"arch/x86/include/asm/nospec-branch.h",
"arch/x86/kernel/cpu/bugs.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.18"
},
{
"lessThan": "5.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.18",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/bugs: Enable IBPB flush on BPF JIT allocation\n\nEnable hardening against JIT spraying when Spectre-v2 mitigations are in\nuse. Specifically, issue an IBPB flush on BPF JIT memory reuse. Skip\nenabling the IBPB flush if the BPF dispatcher is already using a retpoline\nsequence.\n\nThis hardening applies only when BPF-JIT is in use. Guard the enabling\nunder CONFIG_BPF_JIT so that bugs.c still builds with CONFIG_BPF_JIT=n."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:28:18.513Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/25dbcd31781e2bc3cd63d873af1fcd06f863a126"
},
{
"url": "https://git.kernel.org/stable/c/cb27f3bf915cc0f20fc0c48da9059304e39ebd35"
},
{
"url": "https://git.kernel.org/stable/c/9354248fc1c33a844ca1872761f6668b393e8c37"
},
{
"url": "https://git.kernel.org/stable/c/8a4c8af9ae67eb072d90d1b339f14d27a82bd2a1"
},
{
"url": "https://git.kernel.org/stable/c/52440e15d9628f8f239373c0f2e5e8f92feea2df"
},
{
"url": "https://git.kernel.org/stable/c/a3af84b0fa00ead01fcd0e28b5d773ff25990a0d"
}
],
"title": "x86/bugs: Enable IBPB flush on BPF JIT allocation",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64507",
"datePublished": "2026-07-25T08:52:01.008Z",
"dateReserved": "2026-07-19T15:36:31.793Z",
"dateUpdated": "2026-08-19T16:28:18.513Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64434 (GCVE-0-2026-64434)
Vulnerability from cvelistv5
Published
2026-07-25 08:51
Modified
2026-08-19 16:28
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref
l2cap_chan_timeout() runs asynchronously and accesses chan->conn. If
the connection is torn down while the timer is running or pending,
chan->conn can be freed, leading to a use-after-free when the timer
worker attempts to lock conn->lock:
| BUG: KASAN: slab-use-after-free in instrument_atomic_read_write include/linux/instrumented.h:112 [inline]
| BUG: KASAN: slab-use-after-free in atomic_long_try_cmpxchg_acquire include/linux/atomic/atomic-instrumented.h:4456 [inline]
| BUG: KASAN: slab-use-after-free in __mutex_trylock_fast kernel/locking/mutex.c:161 [inline]
| BUG: KASAN: slab-use-after-free in mutex_lock+0x4f/0xa0 kernel/locking/mutex.c:318
| Write of size 8 at addr ffff8881298d9550 by task kworker/2:1/83
|
| CPU: 2 UID: 0 PID: 83 Comm: kworker/2:1 Not tainted 7.1.0-rc6-next-20260601-dirty #6 PREEMPT(full)
| Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.17.0-debian-1.17.0-1 04/01/2014
| Workqueue: events l2cap_chan_timeout
| Call Trace:
| <TASK>
| instrument_atomic_read_write include/linux/instrumented.h:112 [inline]
| atomic_long_try_cmpxchg_acquire include/linux/atomic/atomic-instrumented.h:4456 [inline]
| __mutex_trylock_fast kernel/locking/mutex.c:161 [inline]
| mutex_lock+0x4f/0xa0 kernel/locking/mutex.c:318
| l2cap_chan_timeout+0x5d/0x1b0 net/bluetooth/l2cap_core.c:422
| process_one_work kernel/workqueue.c:3326 [inline]
| process_scheduled_works+0x7c8/0xfb0 kernel/workqueue.c:3409
| worker_thread+0x8a9/0xcf0 kernel/workqueue.c:3490
| kthread+0x346/0x430 kernel/kthread.c:436
| ret_from_fork+0x1a3/0x470 arch/x86/kernel/process.c:158
| ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245
| </TASK>
|
| Allocated by task 320:
| l2cap_conn_add+0xa7/0x820 net/bluetooth/l2cap_core.c:7075
| l2cap_connect_cfm+0xdb/0xd70 net/bluetooth/l2cap_core.c:7452
| hci_connect_cfm include/net/bluetooth/hci_core.h:2139 [inline]
| hci_remote_features_evt+0x52f/0x9f0 net/bluetooth/hci_event.c:3760
| hci_event_func net/bluetooth/hci_event.c:7796 [inline]
| hci_event_packet+0x561/0xa70 net/bluetooth/hci_event.c:7847
| hci_rx_work+0x370/0x890 net/bluetooth/hci_core.c:4040
| process_one_work kernel/workqueue.c:3326 [inline]
| process_scheduled_works+0x7c8/0xfb0 kernel/workqueue.c:3409
| worker_thread+0x8a9/0xcf0 kernel/workqueue.c:3490
| kthread+0x346/0x430 kernel/kthread.c:436
| ret_from_fork+0x1a3/0x470 arch/x86/kernel/process.c:158
| ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245
|
| Freed by task 322:
| hci_disconn_cfm include/net/bluetooth/hci_core.h:2154 [inline]
| hci_conn_hash_flush+0x101/0x1f0 net/bluetooth/hci_conn.c:2736
| hci_dev_close_sync+0x889/0xde0 net/bluetooth/hci_sync.c:5405
| hci_dev_do_close net/bluetooth/hci_core.c:502 [inline]
| hci_unregister_dev+0x1f7/0x370 net/bluetooth/hci_core.c:2679
| vhci_release+0x12a/0x180 drivers/bluetooth/hci_vhci.c:690
| __fput+0x369/0x890 fs/file_table.c:510
| task_work_run+0x160/0x1d0 kernel/task_work.c:233
| get_signal+0xf5b/0x1120 kernel/signal.c:2810
| arch_do_signal_or_restart+0x4d/0x600 arch/x86/kernel/signal.c:337
| __exit_to_user_mode_loop kernel/entry/common.c:64 [inline]
| exit_to_user_mode_loop+0x85/0x510 kernel/entry/common.c:98
| do_syscall_64+0x263/0x3d0 arch/x86/entry/syscall_64.c:100
| entry_SYSCALL_64_after_hwframe+0x77/0x7f
|
| The buggy address belongs to the object at ffff8881298d9400
| which belongs to the cache kmalloc-512 of size 512
| The buggy address is located 336 bytes inside of
| freed 512-byte region [ffff8881298d9400, ffff8881298d9600)
Fix it by having chan->conn hold a reference to l2cap_conn (via
l2cap_conn_get) when the channel is added to the connection, and
releasing it in the channel destructor. This ensures the l2cap_conn
remains alive as long as the channel exists.
A new FLAG_DEL channel flag is introduced to indicate that the ch
---truncated---
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 3634cbdc2eb414b69ffa752ddbe5e0458518e321 Version: e1c100e2d61bd8c718b7d91fe3e050780a9bf72d Version: deb8493a8fa599f6c95e2465b12bfdfb7f94a1d9 Version: 89dec92041717b027216e110599e4f6d6c921b79 Version: 50dfec218808b148ab4247b1858031b7a32015c5 Version: 859d3ace791ed878ae9ba5522c7844d960da8f88 Version: 8c8e620467a7b51562dbcefbd1f09f288d7d710d Version: 8c8e620467a7b51562dbcefbd1f09f288d7d710d Version: 7555fd885a0603f50e49a655850a1f2bd8a25398 Version: 5.10.259 ≤ Version: 5.15.210 ≤ Version: 6.1.176 ≤ Version: 6.6.143 ≤ Version: 6.12.93 ≤ Version: 6.18.35 ≤ Version: 7.0.12 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"include/net/bluetooth/l2cap.h",
"net/bluetooth/l2cap_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "8f90405a4a6f1f1880dc07996b47bf57c712bd8a",
"status": "affected",
"version": "3634cbdc2eb414b69ffa752ddbe5e0458518e321",
"versionType": "git"
},
{
"lessThan": "32d783cafb46ff3ca58e6f9fd62c9c5f35eaf26b",
"status": "affected",
"version": "e1c100e2d61bd8c718b7d91fe3e050780a9bf72d",
"versionType": "git"
},
{
"lessThan": "8922c7940bae9ce4b1736dddb6362370793835c2",
"status": "affected",
"version": "deb8493a8fa599f6c95e2465b12bfdfb7f94a1d9",
"versionType": "git"
},
{
"lessThan": "91047a4396a8b1857a6f712a90cf33ec0012b189",
"status": "affected",
"version": "89dec92041717b027216e110599e4f6d6c921b79",
"versionType": "git"
},
{
"lessThan": "0b0e2bf39cf99e458d991b9df253727e036a7d7d",
"status": "affected",
"version": "50dfec218808b148ab4247b1858031b7a32015c5",
"versionType": "git"
},
{
"lessThan": "d3b739db5dc6f688a60d56da872fabaf65246032",
"status": "affected",
"version": "859d3ace791ed878ae9ba5522c7844d960da8f88",
"versionType": "git"
},
{
"lessThan": "50c38d9f42a529691e4e67ea9cedf4f0bfc8d277",
"status": "affected",
"version": "8c8e620467a7b51562dbcefbd1f09f288d7d710d",
"versionType": "git"
},
{
"lessThan": "b66774b48dd98f07254951f74ea6f513efe7ff8b",
"status": "affected",
"version": "8c8e620467a7b51562dbcefbd1f09f288d7d710d",
"versionType": "git"
},
{
"status": "affected",
"version": "7555fd885a0603f50e49a655850a1f2bd8a25398",
"versionType": "git"
},
{
"lessThan": "5.10.265",
"status": "affected",
"version": "5.10.259",
"versionType": "semver"
},
{
"lessThan": "5.15.216",
"status": "affected",
"version": "5.15.210",
"versionType": "semver"
},
{
"lessThan": "6.1.183",
"status": "affected",
"version": "6.1.176",
"versionType": "semver"
},
{
"lessThan": "6.6.145",
"status": "affected",
"version": "6.6.143",
"versionType": "semver"
},
{
"lessThan": "6.12.97",
"status": "affected",
"version": "6.12.93",
"versionType": "semver"
},
{
"lessThan": "6.18.39",
"status": "affected",
"version": "6.18.35",
"versionType": "semver"
},
{
"lessThan": "7.1",
"status": "affected",
"version": "7.0.12",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"include/net/bluetooth/l2cap.h",
"net/bluetooth/l2cap_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "7.1"
},
{
"lessThan": "7.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.10.259",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.15.210",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "6.1.176",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "6.6.143",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "6.12.93",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "6.18.35",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "7.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "7.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "7.0.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref\n\nl2cap_chan_timeout() runs asynchronously and accesses chan-\u003econn. If\nthe connection is torn down while the timer is running or pending,\nchan-\u003econn can be freed, leading to a use-after-free when the timer\nworker attempts to lock conn-\u003elock:\n\n| BUG: KASAN: slab-use-after-free in instrument_atomic_read_write include/linux/instrumented.h:112 [inline]\n| BUG: KASAN: slab-use-after-free in atomic_long_try_cmpxchg_acquire include/linux/atomic/atomic-instrumented.h:4456 [inline]\n| BUG: KASAN: slab-use-after-free in __mutex_trylock_fast kernel/locking/mutex.c:161 [inline]\n| BUG: KASAN: slab-use-after-free in mutex_lock+0x4f/0xa0 kernel/locking/mutex.c:318\n| Write of size 8 at addr ffff8881298d9550 by task kworker/2:1/83\n|\n| CPU: 2 UID: 0 PID: 83 Comm: kworker/2:1 Not tainted 7.1.0-rc6-next-20260601-dirty #6 PREEMPT(full)\n| Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.17.0-debian-1.17.0-1 04/01/2014\n| Workqueue: events l2cap_chan_timeout\n| Call Trace:\n| \u003cTASK\u003e\n| instrument_atomic_read_write include/linux/instrumented.h:112 [inline]\n| atomic_long_try_cmpxchg_acquire include/linux/atomic/atomic-instrumented.h:4456 [inline]\n| __mutex_trylock_fast kernel/locking/mutex.c:161 [inline]\n| mutex_lock+0x4f/0xa0 kernel/locking/mutex.c:318\n| l2cap_chan_timeout+0x5d/0x1b0 net/bluetooth/l2cap_core.c:422\n| process_one_work kernel/workqueue.c:3326 [inline]\n| process_scheduled_works+0x7c8/0xfb0 kernel/workqueue.c:3409\n| worker_thread+0x8a9/0xcf0 kernel/workqueue.c:3490\n| kthread+0x346/0x430 kernel/kthread.c:436\n| ret_from_fork+0x1a3/0x470 arch/x86/kernel/process.c:158\n| ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245\n| \u003c/TASK\u003e\n|\n| Allocated by task 320:\n| l2cap_conn_add+0xa7/0x820 net/bluetooth/l2cap_core.c:7075\n| l2cap_connect_cfm+0xdb/0xd70 net/bluetooth/l2cap_core.c:7452\n| hci_connect_cfm include/net/bluetooth/hci_core.h:2139 [inline]\n| hci_remote_features_evt+0x52f/0x9f0 net/bluetooth/hci_event.c:3760\n| hci_event_func net/bluetooth/hci_event.c:7796 [inline]\n| hci_event_packet+0x561/0xa70 net/bluetooth/hci_event.c:7847\n| hci_rx_work+0x370/0x890 net/bluetooth/hci_core.c:4040\n| process_one_work kernel/workqueue.c:3326 [inline]\n| process_scheduled_works+0x7c8/0xfb0 kernel/workqueue.c:3409\n| worker_thread+0x8a9/0xcf0 kernel/workqueue.c:3490\n| kthread+0x346/0x430 kernel/kthread.c:436\n| ret_from_fork+0x1a3/0x470 arch/x86/kernel/process.c:158\n| ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245\n|\n| Freed by task 322:\n| hci_disconn_cfm include/net/bluetooth/hci_core.h:2154 [inline]\n| hci_conn_hash_flush+0x101/0x1f0 net/bluetooth/hci_conn.c:2736\n| hci_dev_close_sync+0x889/0xde0 net/bluetooth/hci_sync.c:5405\n| hci_dev_do_close net/bluetooth/hci_core.c:502 [inline]\n| hci_unregister_dev+0x1f7/0x370 net/bluetooth/hci_core.c:2679\n| vhci_release+0x12a/0x180 drivers/bluetooth/hci_vhci.c:690\n| __fput+0x369/0x890 fs/file_table.c:510\n| task_work_run+0x160/0x1d0 kernel/task_work.c:233\n| get_signal+0xf5b/0x1120 kernel/signal.c:2810\n| arch_do_signal_or_restart+0x4d/0x600 arch/x86/kernel/signal.c:337\n| __exit_to_user_mode_loop kernel/entry/common.c:64 [inline]\n| exit_to_user_mode_loop+0x85/0x510 kernel/entry/common.c:98\n| do_syscall_64+0x263/0x3d0 arch/x86/entry/syscall_64.c:100\n| entry_SYSCALL_64_after_hwframe+0x77/0x7f\n|\n| The buggy address belongs to the object at ffff8881298d9400\n| which belongs to the cache kmalloc-512 of size 512\n| The buggy address is located 336 bytes inside of\n| freed 512-byte region [ffff8881298d9400, ffff8881298d9600)\n\nFix it by having chan-\u003econn hold a reference to l2cap_conn (via\nl2cap_conn_get) when the channel is added to the connection, and\nreleasing it in the channel destructor. This ensures the l2cap_conn\nremains alive as long as the channel exists.\n\nA new FLAG_DEL channel flag is introduced to indicate that the ch\n---truncated---"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - An unauthenticated Bluetooth peer within radio range can reach the vulnerable worker by creating a half-configured L2CAP channel and subsequently terminating the ACL connection.\nAC:L - The attacker controls both channel creation and connection teardown, can leave the 40-second channel timer armed, and can repeat or parallelize attempts to win the race.\nPR:N - The BR/EDR signaling path processes incoming L2CAP requests before application acceptance, and an SDP listener permits this path without pairing or authentication.\nUI:N - Exploitation requires no victim action because an already-running Bluetooth service and the kernel independently process the connection, timer, and disconnection.\nS:U - The UAF compromises the host kernel within the same security authority and does not inherently cross a VM, IOMMU, or comparable boundary.\nC:H - The freed kmalloc object can be reclaimed with attacker-influenced contents, allowing the UAF to support kernel-memory disclosure primitives.\nI:H - The worker performs mutex writes into the freed allocation, enabling heap corruption and potentially arbitrary write or kernel control-flow hijacking after heap grooming.\nA:H - The stale mutex access can corrupt memory, trigger an oops or panic, and can be retriggered by a nearby Bluetooth peer."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:28:16.061Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/8f90405a4a6f1f1880dc07996b47bf57c712bd8a"
},
{
"url": "https://git.kernel.org/stable/c/32d783cafb46ff3ca58e6f9fd62c9c5f35eaf26b"
},
{
"url": "https://git.kernel.org/stable/c/8922c7940bae9ce4b1736dddb6362370793835c2"
},
{
"url": "https://git.kernel.org/stable/c/91047a4396a8b1857a6f712a90cf33ec0012b189"
},
{
"url": "https://git.kernel.org/stable/c/0b0e2bf39cf99e458d991b9df253727e036a7d7d"
},
{
"url": "https://git.kernel.org/stable/c/d3b739db5dc6f688a60d56da872fabaf65246032"
},
{
"url": "https://git.kernel.org/stable/c/50c38d9f42a529691e4e67ea9cedf4f0bfc8d277"
},
{
"url": "https://git.kernel.org/stable/c/b66774b48dd98f07254951f74ea6f513efe7ff8b"
}
],
"title": "Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64434",
"datePublished": "2026-07-25T08:51:09.066Z",
"dateReserved": "2026-07-19T15:36:31.787Z",
"dateUpdated": "2026-08-19T16:28:16.061Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74564 (GCVE-0-2026-74564)
Vulnerability from cvelistv5
Published
2026-08-15 12:28
Modified
2026-08-19 16:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
netfilter: xt_hashlimit: validate hashtable supports XT_HASHLIMIT_RATE_MATCH
The XT_HASHLIMIT_RATE_MATCH flag mode changes the semantics of the
dsthash_ent structure which represents an entry in the hashtable. There
is a union area which uses a different layout to express the rate match
mode.
Update .checkentry path to validate the XT_HASHLIMIT_RATE_MATCH mode
flag is requested by two or more different rules that refer to the same
hashtable. Otherwise, uninitialized access to the burst field in the
union is possible.
Reject the use of the XT_HASHLIMIT_RATE_MATCH mode flag if set on by
revision less than 3 too.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: bea74641e3786d51dcf1175527cc1781420961c9 Version: bea74641e3786d51dcf1175527cc1781420961c9 Version: bea74641e3786d51dcf1175527cc1781420961c9 Version: bea74641e3786d51dcf1175527cc1781420961c9 Version: bea74641e3786d51dcf1175527cc1781420961c9 Version: bea74641e3786d51dcf1175527cc1781420961c9 Version: bea74641e3786d51dcf1175527cc1781420961c9 Version: bea74641e3786d51dcf1175527cc1781420961c9 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/netfilter/xt_hashlimit.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "402befce5854c195058cf4bab7c78ca286068a26",
"status": "affected",
"version": "bea74641e3786d51dcf1175527cc1781420961c9",
"versionType": "git"
},
{
"lessThan": "dee686b5e7f21180538ff719867702f411c8eb5c",
"status": "affected",
"version": "bea74641e3786d51dcf1175527cc1781420961c9",
"versionType": "git"
},
{
"lessThan": "f76ab783e7d8d33e33dd7dfa697297f70d57b0e8",
"status": "affected",
"version": "bea74641e3786d51dcf1175527cc1781420961c9",
"versionType": "git"
},
{
"lessThan": "24683fea1f06bd3bd2707b99460e859bc6464c22",
"status": "affected",
"version": "bea74641e3786d51dcf1175527cc1781420961c9",
"versionType": "git"
},
{
"lessThan": "32ec8d4aba2cf22e12bdc28df8c4bd833c195fc0",
"status": "affected",
"version": "bea74641e3786d51dcf1175527cc1781420961c9",
"versionType": "git"
},
{
"lessThan": "d186f77d18bdfb252d401ff992ca3001a6a65a0f",
"status": "affected",
"version": "bea74641e3786d51dcf1175527cc1781420961c9",
"versionType": "git"
},
{
"lessThan": "06a76334243ccd875a981aa8bb46c0f931ef1e3b",
"status": "affected",
"version": "bea74641e3786d51dcf1175527cc1781420961c9",
"versionType": "git"
},
{
"lessThan": "305b63e1402267459fdabb183af4527f6799eebf",
"status": "affected",
"version": "bea74641e3786d51dcf1175527cc1781420961c9",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/netfilter/xt_hashlimit.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.14"
},
{
"lessThan": "4.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "4.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: xt_hashlimit: validate hashtable supports XT_HASHLIMIT_RATE_MATCH\n\nThe XT_HASHLIMIT_RATE_MATCH flag mode changes the semantics of the\ndsthash_ent structure which represents an entry in the hashtable. There\nis a union area which uses a different layout to express the rate match\nmode.\n\nUpdate .checkentry path to validate the XT_HASHLIMIT_RATE_MATCH mode\nflag is requested by two or more different rules that refer to the same\nhashtable. Otherwise, uninitialized access to the burst field in the\nunion is possible.\n\nReject the use of the XT_HASHLIMIT_RATE_MATCH mode flag if set on by\nrevision less than 3 too."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires installing conflicting xt_hashlimit iptables rules via the IPT_SO_SET_REPLACE netlink path (CAP_NET_ADMIN), which is local netfilter configuration per kernel CVSS guidance; the uninitialized burst read occurs later during packet matching in hashlimit_mt_common().\nAC:L - An attacker with CAP_NET_ADMIN can deterministically install two rules sharing one hashtable name\u2014one standard hashlimit and one with XT_HASHLIMIT_RATE_MATCH\u2014so the first packet evaluated by both rules triggers uninitialized burst access without races or external timing.\nPR:L - Installing iptables hashlimit rules requires CAP_NET_ADMIN, which unprivileged users can obtain in their own network namespace via user namespaces (unshare -Urn) on common Linux distributions, containers, and Kubernetes workloads with NET_ADMIN capability.\nUI:N - No victim interaction is required; once the conflicting hashlimit rules are installed, the attacker fully controls exploitation by sending network packets that traverse the affected iptables hooks (INPUT, FORWARD, PREROUTING).\nS:U - Impact is confined to kernel netfilter hashlimit state and packet-filtering decisions within the target network namespace; it does not cross a VM, container-to-host, or IOMMU security boundary.\nC:H - The rate-match path reads an uninitialized burst field from kmem_cache-allocated dsthash_ent entries whose standard-mode initialization only writes the first 24 bytes of the rateinfo union, exposing stale kernel slab heap contents.\nI:H - Cross-mode union aliasing causes rate-match logic to read uninitialized burst and write current_rate/prev_window over credit/credit_cap/cost fields, corrupting shared hashtable entries and enabling arbitrary firewall match verdict manipulation (type confusion).\nA:N - The vulnerability causes uninitialized memory reads and union field corruption affecting match results, but does not trigger kernel oops, panic, hang, or host-level denial of service; impact is incorrect packet classification rather than system crash."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:39:04.869Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/402befce5854c195058cf4bab7c78ca286068a26"
},
{
"url": "https://git.kernel.org/stable/c/dee686b5e7f21180538ff719867702f411c8eb5c"
},
{
"url": "https://git.kernel.org/stable/c/f76ab783e7d8d33e33dd7dfa697297f70d57b0e8"
},
{
"url": "https://git.kernel.org/stable/c/24683fea1f06bd3bd2707b99460e859bc6464c22"
},
{
"url": "https://git.kernel.org/stable/c/32ec8d4aba2cf22e12bdc28df8c4bd833c195fc0"
},
{
"url": "https://git.kernel.org/stable/c/d186f77d18bdfb252d401ff992ca3001a6a65a0f"
},
{
"url": "https://git.kernel.org/stable/c/06a76334243ccd875a981aa8bb46c0f931ef1e3b"
},
{
"url": "https://git.kernel.org/stable/c/305b63e1402267459fdabb183af4527f6799eebf"
}
],
"title": "netfilter: xt_hashlimit: validate hashtable supports XT_HASHLIMIT_RATE_MATCH",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74564",
"datePublished": "2026-08-15T12:28:06.392Z",
"dateReserved": "2026-08-15T05:44:03.916Z",
"dateUpdated": "2026-08-19T16:39:04.869Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80681 (GCVE-0-2026-80681)
Vulnerability from cvelistv5
Published
2026-08-28 06:52
Modified
2026-08-29 06:22
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
vxlan: re-fetch eth header after route_shortcircuit()
Before route_shortcircuit(), the eth header pointer is cached from eth_hdr(skb).
Inside route_shortcircuit(), pskb_may_pull() can be called, which may
reallocate skb->head.
In this case, returning to vxlan_xmit() leaves the cached eth pointer pointing to
freed memory, leading to a use-after-free when dereferencing eth->h_dest.
Fix this by updating eth = eth_hdr(skb) after calling route_shortcircuit().
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ae8840825605f36f98f247323edc150e761cb64e Version: ae8840825605f36f98f247323edc150e761cb64e Version: ae8840825605f36f98f247323edc150e761cb64e Version: ae8840825605f36f98f247323edc150e761cb64e Version: ae8840825605f36f98f247323edc150e761cb64e Version: ae8840825605f36f98f247323edc150e761cb64e Version: ae8840825605f36f98f247323edc150e761cb64e Version: ae8840825605f36f98f247323edc150e761cb64e |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/vxlan/vxlan_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "6375093eb45cd7d89f1945f939eeae3b29d79f56",
"status": "affected",
"version": "ae8840825605f36f98f247323edc150e761cb64e",
"versionType": "git"
},
{
"lessThan": "1b7f7b653e3557690047c62f03b80a24ea5a58a5",
"status": "affected",
"version": "ae8840825605f36f98f247323edc150e761cb64e",
"versionType": "git"
},
{
"lessThan": "bf045341dfb3e767f0ff94cf240ce3c371973bd4",
"status": "affected",
"version": "ae8840825605f36f98f247323edc150e761cb64e",
"versionType": "git"
},
{
"lessThan": "2355c8c26d2aa1b4385b369e67202e47d460d555",
"status": "affected",
"version": "ae8840825605f36f98f247323edc150e761cb64e",
"versionType": "git"
},
{
"lessThan": "1511631b7cfc4152b10a0a9d04c7a0bf2ddf4585",
"status": "affected",
"version": "ae8840825605f36f98f247323edc150e761cb64e",
"versionType": "git"
},
{
"lessThan": "1235e017aa11cf01e91b613c4c5ed6aa28934fff",
"status": "affected",
"version": "ae8840825605f36f98f247323edc150e761cb64e",
"versionType": "git"
},
{
"lessThan": "c9dceac9e1c7c772c43c732fc0d325e72835801a",
"status": "affected",
"version": "ae8840825605f36f98f247323edc150e761cb64e",
"versionType": "git"
},
{
"lessThan": "1395a676ec15a0a02a2a6d86602324f2d5fd41d5",
"status": "affected",
"version": "ae8840825605f36f98f247323edc150e761cb64e",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/vxlan/vxlan_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.10"
},
{
"lessThan": "3.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nvxlan: re-fetch eth header after route_shortcircuit()\n\nBefore route_shortcircuit(), the eth header pointer is cached from eth_hdr(skb).\n\nInside route_shortcircuit(), pskb_may_pull() can be called, which may\nreallocate skb-\u003ehead.\n\nIn this case, returning to vxlan_xmit() leaves the cached eth pointer pointing to\nfreed memory, leading to a use-after-free when dereferencing eth-\u003eh_dest.\n\nFix this by updating eth = eth_hdr(skb) after calling route_shortcircuit()."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug is in vxlan_xmit(), reached when the kernel transmits packets out a VXLAN netdev via routing, bridging, or overlay forwarding; remote peers can inject IPv4/IPv6 Ethernet frames that traverse this TX path on cloud, Kubernetes, and data-center VXLAN deployments.\nAC:L - An attacker controlling overlay or forwarded traffic can reliably meet RSC prerequisites (router FDB entry, IPv4/IPv6 ethertype, neighbour MAC mismatch, cloned/nonlinear skb) so route_shortcircuit() calls pskb_may_pull/skb_cow_head and reallocates skb-\u003ehead, invalidating the cached eth pointer.\nPR:N - Exploitation requires only sending network traffic processed by an existing VXLAN interface with RSC enabled, not host administrator credentials; remote overlay peers and unauthenticated senders whose packets are forwarded through VXLAN need no elevated privileges on the target.\nUI:N - The use-after-free is triggered automatically during kernel packet transmit processing in vxlan_xmit() with no action required from a local user or administrator beyond normal network operation on a VXLAN-enabled host.\nS:U - The stale eth_hdr pointer causes heap use-after-free within the kernel\u0027s own memory domain during VXLAN transmit processing; impact is standard in-kernel memory corruption and does not inherently cross VM, container, or IOMMU security boundaries.\nC:H - After route_shortcircuit() reallocates skb-\u003ehead, vxlan_xmit() dereferences the stale eth pointer for eth-\u003eh_dest, constituting a heap use-after-free read that can disclose adjacent freed slab contents and support further kernel memory disclosure primitives.\nI:H - Use-after-free of the Ethernet header buffer in skb head memory enables attacker-controlled reuse of freed kmalloc slabs, a well-established path to heap grooming and arbitrary kernel memory corruption or control-flow hijacking beyond the immediate MAC header read.\nA:H - Dereferencing a freed skb head pointer in vxlan_xmit() can cause an immediate kernel oops or panic from invalid memory access, and UAF heap corruption routinely destabilizes or crashes the system even when full exploitation is not pursued."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-29T06:22:07.840Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/6375093eb45cd7d89f1945f939eeae3b29d79f56"
},
{
"url": "https://git.kernel.org/stable/c/1b7f7b653e3557690047c62f03b80a24ea5a58a5"
},
{
"url": "https://git.kernel.org/stable/c/bf045341dfb3e767f0ff94cf240ce3c371973bd4"
},
{
"url": "https://git.kernel.org/stable/c/2355c8c26d2aa1b4385b369e67202e47d460d555"
},
{
"url": "https://git.kernel.org/stable/c/1511631b7cfc4152b10a0a9d04c7a0bf2ddf4585"
},
{
"url": "https://git.kernel.org/stable/c/1235e017aa11cf01e91b613c4c5ed6aa28934fff"
},
{
"url": "https://git.kernel.org/stable/c/c9dceac9e1c7c772c43c732fc0d325e72835801a"
},
{
"url": "https://git.kernel.org/stable/c/1395a676ec15a0a02a2a6d86602324f2d5fd41d5"
}
],
"title": "vxlan: re-fetch eth header after route_shortcircuit()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80681",
"datePublished": "2026-08-28T06:52:48.896Z",
"dateReserved": "2026-08-26T14:34:25.783Z",
"dateUpdated": "2026-08-29T06:22:07.840Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68138 (GCVE-0-2026-68138)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-23 12:45
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/sched: serialize qdisc_rtab_list against concurrent get/put
qdisc_get_rtab() and qdisc_put_rtab() mutate the process-global singly
linked list qdisc_rtab_list and a plain non-atomic 'int refcnt' with no
lock. This was only safe because every caller historically held the RTNL
mutex, which serialized all rate-table lookups, inserts and frees.
That invariant no longer holds. cls_flower sets
TCF_PROTO_OPS_DOIT_UNLOCKED, so tc_new_tfilter() keeps rtnl_held == false
for it and sets TCA_ACT_FLAGS_NO_RTNL. That flag propagates through
tcf_exts_validate_ex() -> tcf_action_init() -> tcf_action_init_1() ->
tcf_police_init(), which calls qdisc_get_rtab()/qdisc_put_rtab() with the
RTNL mutex NOT held. Two RTM_NEWTFILTER requests on different CPUs, each
adding a flower filter with a police action carrying the same rate, then
race on qdisc_rtab_list and on the non-atomic refcnt, leading to a
use-after-free / double-free of the kmalloc-2k struct qdisc_rate_table.
qdisc_rtab_list is a single global (not per-netns), so the corrupted
object is shared system-wide.
BUG: KASAN: slab-use-after-free in qdisc_put_rtab+0x12f/0x160
qdisc_put_rtab+0x12f/0x160
tcf_police_init+0xda9/0x1590
tcf_action_init_1+0x460/0x6b0
tcf_action_init+0x439/0xa40
tcf_exts_validate_ex+0x42d/0x550
fl_change+0xddd/0x7da0
tc_new_tfilter+0xaa7/0x2420
rtnetlink_rcv_msg+0x95e/0xe90
which belongs to the cache kmalloc-2k of size 2048
Protect qdisc_rtab_list and the refcount with a dedicated spinlock. The
(sleeping, GFP_KERNEL) allocation in qdisc_get_rtab() is performed before
taking the lock; if a concurrent inserter added an identical table in the
meantime the freshly allocated one is freed under the lock, so no
duplicate is leaked. qdisc_put_rtab() now decrements the refcount and
unlinks under the same lock.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 470502de5bdb1ed0def643a4458593a40b8f6b66 Version: 470502de5bdb1ed0def643a4458593a40b8f6b66 Version: 470502de5bdb1ed0def643a4458593a40b8f6b66 Version: 470502de5bdb1ed0def643a4458593a40b8f6b66 Version: 470502de5bdb1ed0def643a4458593a40b8f6b66 Version: 470502de5bdb1ed0def643a4458593a40b8f6b66 Version: 470502de5bdb1ed0def643a4458593a40b8f6b66 Version: 470502de5bdb1ed0def643a4458593a40b8f6b66 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/sched/sch_api.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "1b050d09dd1a0ddae83bf012cf4956b7a960235f",
"status": "affected",
"version": "470502de5bdb1ed0def643a4458593a40b8f6b66",
"versionType": "git"
},
{
"lessThan": "6e0241f6cbb149d926ee8efee2c734fea71452cf",
"status": "affected",
"version": "470502de5bdb1ed0def643a4458593a40b8f6b66",
"versionType": "git"
},
{
"lessThan": "f93c89392bd3b180b5b7abc6fdae8e3dd667a313",
"status": "affected",
"version": "470502de5bdb1ed0def643a4458593a40b8f6b66",
"versionType": "git"
},
{
"lessThan": "4131dd0b6f67acddd616ed7c244e1d3eedd46e7b",
"status": "affected",
"version": "470502de5bdb1ed0def643a4458593a40b8f6b66",
"versionType": "git"
},
{
"lessThan": "d981098b76756ed71666a27518eeb69883657c43",
"status": "affected",
"version": "470502de5bdb1ed0def643a4458593a40b8f6b66",
"versionType": "git"
},
{
"lessThan": "8ddc2eb0d2da9c83f54f1e5720525b461b8480c4",
"status": "affected",
"version": "470502de5bdb1ed0def643a4458593a40b8f6b66",
"versionType": "git"
},
{
"lessThan": "fb29e1b41052488ee3f2d115d4a870497ebd7f7d",
"status": "affected",
"version": "470502de5bdb1ed0def643a4458593a40b8f6b66",
"versionType": "git"
},
{
"lessThan": "f43ee0c0730d6191629b5ee1ceae27b1ebfdc047",
"status": "affected",
"version": "470502de5bdb1ed0def643a4458593a40b8f6b66",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/sched/sch_api.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.1"
},
{
"lessThan": "5.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.46",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: serialize qdisc_rtab_list against concurrent get/put\n\nqdisc_get_rtab() and qdisc_put_rtab() mutate the process-global singly\nlinked list qdisc_rtab_list and a plain non-atomic \u0027int refcnt\u0027 with no\nlock. This was only safe because every caller historically held the RTNL\nmutex, which serialized all rate-table lookups, inserts and frees.\n\nThat invariant no longer holds. cls_flower sets\nTCF_PROTO_OPS_DOIT_UNLOCKED, so tc_new_tfilter() keeps rtnl_held == false\nfor it and sets TCA_ACT_FLAGS_NO_RTNL. That flag propagates through\ntcf_exts_validate_ex() -\u003e tcf_action_init() -\u003e tcf_action_init_1() -\u003e\ntcf_police_init(), which calls qdisc_get_rtab()/qdisc_put_rtab() with the\nRTNL mutex NOT held. Two RTM_NEWTFILTER requests on different CPUs, each\nadding a flower filter with a police action carrying the same rate, then\nrace on qdisc_rtab_list and on the non-atomic refcnt, leading to a\nuse-after-free / double-free of the kmalloc-2k struct qdisc_rate_table.\nqdisc_rtab_list is a single global (not per-netns), so the corrupted\nobject is shared system-wide.\n\n BUG: KASAN: slab-use-after-free in qdisc_put_rtab+0x12f/0x160\n qdisc_put_rtab+0x12f/0x160\n tcf_police_init+0xda9/0x1590\n tcf_action_init_1+0x460/0x6b0\n tcf_action_init+0x439/0xa40\n tcf_exts_validate_ex+0x42d/0x550\n fl_change+0xddd/0x7da0\n tc_new_tfilter+0xaa7/0x2420\n rtnetlink_rcv_msg+0x95e/0xe90\n which belongs to the cache kmalloc-2k of size 2048\n\nProtect qdisc_rtab_list and the refcount with a dedicated spinlock. The\n(sleeping, GFP_KERNEL) allocation in qdisc_get_rtab() is performed before\ntaking the lock; if a concurrent inserter added an identical table in the\nmeantime the freshly allocated one is freed under the lock, so no\nduplicate is leaked. qdisc_put_rtab() now decrements the refcount and\nunlinks under the same lock."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached only via local RTM_NEWTFILTER rtnetlink messages (tc flower filter with police action) through rtnetlink_rcv_msg\u2192tc_new_tfilter\u2192fl_change\u2192tcf_police_init\u2192qdisc_get_rtab/qdisc_put_rtab; no remote packet or network protocol path exists.\nAC:L - cls_flower is TCF_PROTO_OPS_DOIT_UNLOCKED, so concurrent RTM_NEWTFILTER requests run without RTNL; the attacker controls both racing threads/CPUs and can repeatedly install flower filters with identical police rate tables to deterministically hit the global qdisc_rtab_list/refcnt race.\nPR:L - Non-GET rtnetlink handlers require netlink_net_capable(CAP_NET_ADMIN); this is namespace-scoped, so an unprivileged local user obtains CAP_NET_ADMIN via user namespaces (unshare -Urn), sets up clsact/ingress, and installs flower+police rules without init-namespace root.\nUI:N - Exploitation is fully self-contained: the attacker issues the concurrent tc/netlink commands from its own processes and needs no victim to mount filesystems, click links, or perform any other interactive action.\nS:U - Impact is heap corruption and UAF/double-free in kernel kmalloc-2k slabs within the same kernel security authority; although qdisc_rtab_list is global across netns, this is standard kernel memory corruption/privilege escalation, not a VM, IOMMU, or sandbox boundary escape.\nC:H - Concurrent non-atomic refcnt and list updates cause slab use-after-free/double-free of struct qdisc_rate_table (KASAN-confirmed in qdisc_put_rtab); freed 2KB objects are attacker-influenceable via kmalloc timing and are classically weaponizable for arbitrary kernel memory disclosure.\nI:H - The race corrupts a process-global singly linked list and can double-free a kmalloc-2k qdisc_rate_table, yielding classic heap metadata/object corruption primitives that can be developed into arbitrary kernel writes and local privilege escalation/code execution.\nA:H - Demonstrated KASAN slab-use-after-free in qdisc_put_rtab on the error/teardown path, and concurrent double-free of the same rate table can panic the kernel; the trigger is repeatable at will with concurrent netlink requests and causes task death or system-wide instability."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:45:55.796Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/1b050d09dd1a0ddae83bf012cf4956b7a960235f"
},
{
"url": "https://git.kernel.org/stable/c/6e0241f6cbb149d926ee8efee2c734fea71452cf"
},
{
"url": "https://git.kernel.org/stable/c/f93c89392bd3b180b5b7abc6fdae8e3dd667a313"
},
{
"url": "https://git.kernel.org/stable/c/4131dd0b6f67acddd616ed7c244e1d3eedd46e7b"
},
{
"url": "https://git.kernel.org/stable/c/d981098b76756ed71666a27518eeb69883657c43"
},
{
"url": "https://git.kernel.org/stable/c/8ddc2eb0d2da9c83f54f1e5720525b461b8480c4"
},
{
"url": "https://git.kernel.org/stable/c/fb29e1b41052488ee3f2d115d4a870497ebd7f7d"
},
{
"url": "https://git.kernel.org/stable/c/f43ee0c0730d6191629b5ee1ceae27b1ebfdc047"
}
],
"title": "net/sched: serialize qdisc_rtab_list against concurrent get/put",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68138",
"datePublished": "2026-08-10T11:59:01.744Z",
"dateReserved": "2026-07-30T09:28:09.370Z",
"dateUpdated": "2026-08-23T12:45:55.796Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68229 (GCVE-0-2026-68229)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: cedrus: skip invalid H.264 reference list entries
Cedrus consumes H.264 ref_pic_list0/ref_pic_list1 entries from the
stateless slice control and later uses their indices to look up
decode->dpb[] in _cedrus_write_ref_list().
Rejecting such controls in cedrus_try_ctrl() would break existing
userspace, since stateless H.264 reference lists may legitimately carry
out-of-range indices for missing references. Instead, guard the actual
DPB lookup in Cedrus and skip entries whose indices do not fit the fixed
V4L2_H264_NUM_DPB_ENTRIES array.
This keeps the fix local to the driver use site and avoids out-of-bounds
reads from malformed or unsupported reference list entries.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: e000e1fa4bdbd783149e7f97cf3be61e1c0bab8c Version: e000e1fa4bdbd783149e7f97cf3be61e1c0bab8c Version: e000e1fa4bdbd783149e7f97cf3be61e1c0bab8c Version: e000e1fa4bdbd783149e7f97cf3be61e1c0bab8c Version: e000e1fa4bdbd783149e7f97cf3be61e1c0bab8c Version: e000e1fa4bdbd783149e7f97cf3be61e1c0bab8c Version: e000e1fa4bdbd783149e7f97cf3be61e1c0bab8c Version: e000e1fa4bdbd783149e7f97cf3be61e1c0bab8c |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/staging/media/sunxi/cedrus/cedrus_h264.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a6a109771c51920beb620f30778c29da823cc34c",
"status": "affected",
"version": "e000e1fa4bdbd783149e7f97cf3be61e1c0bab8c",
"versionType": "git"
},
{
"lessThan": "7ff6f728a2433b420bb372cb0e8a4eea3f2e1a4b",
"status": "affected",
"version": "e000e1fa4bdbd783149e7f97cf3be61e1c0bab8c",
"versionType": "git"
},
{
"lessThan": "1db34683b0fbbcb3bc162380c11514ea0a44e8ab",
"status": "affected",
"version": "e000e1fa4bdbd783149e7f97cf3be61e1c0bab8c",
"versionType": "git"
},
{
"lessThan": "2ee8327c85b3ac7b532d2d6a1e3a295d5ad7414a",
"status": "affected",
"version": "e000e1fa4bdbd783149e7f97cf3be61e1c0bab8c",
"versionType": "git"
},
{
"lessThan": "0af8945fcae742d099f59f3c725eb67235953a31",
"status": "affected",
"version": "e000e1fa4bdbd783149e7f97cf3be61e1c0bab8c",
"versionType": "git"
},
{
"lessThan": "9924cb548ee7753a6473997949c3ec48092de0b0",
"status": "affected",
"version": "e000e1fa4bdbd783149e7f97cf3be61e1c0bab8c",
"versionType": "git"
},
{
"lessThan": "e53112c2de88982e66c369aee2120d5efd78df30",
"status": "affected",
"version": "e000e1fa4bdbd783149e7f97cf3be61e1c0bab8c",
"versionType": "git"
},
{
"lessThan": "10358ea986c3c85516d1c8206486464f79d36e76",
"status": "affected",
"version": "e000e1fa4bdbd783149e7f97cf3be61e1c0bab8c",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/staging/media/sunxi/cedrus/cedrus_h264.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.10"
},
{
"lessThan": "5.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: cedrus: skip invalid H.264 reference list entries\n\nCedrus consumes H.264 ref_pic_list0/ref_pic_list1 entries from the\nstateless slice control and later uses their indices to look up\ndecode-\u003edpb[] in _cedrus_write_ref_list().\n\nRejecting such controls in cedrus_try_ctrl() would break existing\nuserspace, since stateless H.264 reference lists may legitimately carry\nout-of-range indices for missing references. Instead, guard the actual\nDPB lookup in Cedrus and skip entries whose indices do not fit the fixed\nV4L2_H264_NUM_DPB_ENTRIES array.\n\nThis keeps the fix local to the driver use site and avoids out-of-bounds\nreads from malformed or unsupported reference list entries."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached only through the local V4L2 interface on the cedrus video device node (/dev/videoN) via VIDIOC_S_EXT_CTRLS plus QBUF/STREAMON ioctls. There is no remote or network-facing path to the stateless H.264 decoder.\nAC:L - The attacker fully and deterministically controls the out-of-range value: ref_pic_list0/1[i].index is a u8 copied verbatim from the control payload with no validation, so any index in 16..255 immediately produces the out-of-bounds dpb[] access on the next decode run. No race, timing, or uncontrollable memory-layout condition is involved.\nPR:L - Only an unprivileged local account with access to the cedrus video device node is needed (typically the \u0027video\u0027 group, or the media/camera service on Android and embedded Allwinner devices). No capability, CAP_SYS_ADMIN, or root check exists anywhere on the path \u2014 cedrus_try_ctrl() validates only SPS chroma format and bit depth.\nUI:N - The attacking process performs the entire sequence itself \u2014 open the device, set the crafted H.264 slice-params control, queue buffers, start streaming. No victim action, file open, or media mount is required.\nS:U - The out-of-bounds read stays within the kernel\u0027s own memory and security authority; no VM, IOMMU, or sandbox boundary is crossed. This is a standard in-kernel driver memory-safety defect.\nC:H - decode-\u003edpb[] holds 16 32-byte entries at the start of a ~560-byte control allocation, so an attacker-chosen index up to 255 reads at offset 8160 \u2014 about 7.6 KB of adjacent kernel heap beyond the object. The read flags/reference_ts values are consumed by the ACTIVE test and vb2_find_buffer() timestamp lookup, giving an attacker-steerable oracle over unrelated kernel heap contents.\nI:N - The defect is purely a read: num_ref is bounded to V4L2_H264_REF_LIST_LEN by v4l2-ctrls-core.c, so the sram_array[CEDRUS_MAX_REF_IDX] stores stay in bounds, and only a legitimately-looked-up buffer position is written to hardware SRAM. No kernel memory is modified out of bounds.\nA:H - Reading several kilobytes past the end of a slab object can walk off the slab page into an unmapped or poisoned region, and trips KASAN/hardening checks, producing a kernel oops. The trigger is trivially repeatable from an unprivileged process, so the crash can be induced at will."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:32:01.546Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a6a109771c51920beb620f30778c29da823cc34c"
},
{
"url": "https://git.kernel.org/stable/c/7ff6f728a2433b420bb372cb0e8a4eea3f2e1a4b"
},
{
"url": "https://git.kernel.org/stable/c/1db34683b0fbbcb3bc162380c11514ea0a44e8ab"
},
{
"url": "https://git.kernel.org/stable/c/2ee8327c85b3ac7b532d2d6a1e3a295d5ad7414a"
},
{
"url": "https://git.kernel.org/stable/c/0af8945fcae742d099f59f3c725eb67235953a31"
},
{
"url": "https://git.kernel.org/stable/c/9924cb548ee7753a6473997949c3ec48092de0b0"
},
{
"url": "https://git.kernel.org/stable/c/e53112c2de88982e66c369aee2120d5efd78df30"
},
{
"url": "https://git.kernel.org/stable/c/10358ea986c3c85516d1c8206486464f79d36e76"
}
],
"title": "media: cedrus: skip invalid H.264 reference list entries",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68229",
"datePublished": "2026-08-10T12:00:51.935Z",
"dateReserved": "2026-07-30T09:28:09.376Z",
"dateUpdated": "2026-08-19T16:32:01.546Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64543 (GCVE-0-2026-64543)
Vulnerability from cvelistv5
Published
2026-07-27 20:10
Modified
2026-08-19 16:28
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
tipc: fix use-after-free of the discoverer in tipc_disc_rcv()
bearer_disable() frees b->disc with tipc_disc_delete()'s plain kfree(),
but tipc_disc_rcv() still dereferences b->disc in RX softirq under
rcu_read_lock() (tipc_udp_recv -> tipc_rcv -> tipc_disc_rcv).
L2 bearers are safe thanks to the synchronize_net() in
tipc_disable_l2_media(), but the UDP bearer defers that call to the
cleanup_bearer() workqueue, so the discoverer is freed with no grace
period:
BUG: KASAN: slab-use-after-free in tipc_disc_rcv (net/tipc/discover.c:149)
Read of size 8 at addr ffff88802348b728 by task poc_tipc/184
<IRQ>
tipc_disc_rcv (net/tipc/discover.c:149)
tipc_rcv (net/tipc/node.c:2126)
tipc_udp_recv (net/tipc/udp_media.c:391)
udp_rcv (net/ipv4/udp.c:2643)
ip_local_deliver_finish (net/ipv4/ip_input.c:241)
</IRQ>
Freed by task 181:
kfree (mm/slub.c:6565)
bearer_disable (net/tipc/bearer.c:418)
tipc_nl_bearer_disable (net/tipc/bearer.c:1001)
The bearer is freed with kfree_rcu(); free the discoverer the same way.
Add an rcu_head to struct tipc_discoverer and free it and its skb from an
RCU callback.
Because the RCU callback (tipc_disc_free_rcu) lives in module text, a
call_rcu() that is still pending when the tipc module is unloaded would
invoke a freed function. Add an rcu_barrier() to tipc_exit() after the
bearer subsystem has been torn down, so all pending discoverer callbacks
have run before the module text goes away.
Reachable from an unprivileged user namespace: the TIPCv2 genl family is
netnsok and its bearer commands have no GENL_ADMIN_PERM. Needs CONFIG_TIPC
and CONFIG_TIPC_MEDIA_UDP.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 25b0b9c4e835ffaa65b61c3efe2e28acf84d0259 Version: 25b0b9c4e835ffaa65b61c3efe2e28acf84d0259 Version: 25b0b9c4e835ffaa65b61c3efe2e28acf84d0259 Version: 25b0b9c4e835ffaa65b61c3efe2e28acf84d0259 Version: 25b0b9c4e835ffaa65b61c3efe2e28acf84d0259 Version: 25b0b9c4e835ffaa65b61c3efe2e28acf84d0259 Version: 25b0b9c4e835ffaa65b61c3efe2e28acf84d0259 Version: 25b0b9c4e835ffaa65b61c3efe2e28acf84d0259 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/tipc/core.c",
"net/tipc/discover.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "380413cdfd29fb9fa486c82889132b680c4983c5",
"status": "affected",
"version": "25b0b9c4e835ffaa65b61c3efe2e28acf84d0259",
"versionType": "git"
},
{
"lessThan": "f05b3f4c78370469286879c765f5a1dd39dbcd32",
"status": "affected",
"version": "25b0b9c4e835ffaa65b61c3efe2e28acf84d0259",
"versionType": "git"
},
{
"lessThan": "4da2ac7749411971e1b222b992da5a172ce45f98",
"status": "affected",
"version": "25b0b9c4e835ffaa65b61c3efe2e28acf84d0259",
"versionType": "git"
},
{
"lessThan": "5e215bf1c47fdddf8203a0fe80a0ed594065f101",
"status": "affected",
"version": "25b0b9c4e835ffaa65b61c3efe2e28acf84d0259",
"versionType": "git"
},
{
"lessThan": "ec7d54d8cc1723921d671e3272b427c96366506f",
"status": "affected",
"version": "25b0b9c4e835ffaa65b61c3efe2e28acf84d0259",
"versionType": "git"
},
{
"lessThan": "a0c5fdeb5fa257f8c6d469af266bc087cb5de6a2",
"status": "affected",
"version": "25b0b9c4e835ffaa65b61c3efe2e28acf84d0259",
"versionType": "git"
},
{
"lessThan": "b65289e1c3f352a9f92c6e19713ddd647e033253",
"status": "affected",
"version": "25b0b9c4e835ffaa65b61c3efe2e28acf84d0259",
"versionType": "git"
},
{
"lessThan": "1579342d71133da7f00daa02c75cebec7372097b",
"status": "affected",
"version": "25b0b9c4e835ffaa65b61c3efe2e28acf84d0259",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/tipc/core.c",
"net/tipc/discover.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.17"
},
{
"lessThan": "4.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.17",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: fix use-after-free of the discoverer in tipc_disc_rcv()\n\nbearer_disable() frees b-\u003edisc with tipc_disc_delete()\u0027s plain kfree(),\nbut tipc_disc_rcv() still dereferences b-\u003edisc in RX softirq under\nrcu_read_lock() (tipc_udp_recv -\u003e tipc_rcv -\u003e tipc_disc_rcv).\n\nL2 bearers are safe thanks to the synchronize_net() in\ntipc_disable_l2_media(), but the UDP bearer defers that call to the\ncleanup_bearer() workqueue, so the discoverer is freed with no grace\nperiod:\n\n BUG: KASAN: slab-use-after-free in tipc_disc_rcv (net/tipc/discover.c:149)\n Read of size 8 at addr ffff88802348b728 by task poc_tipc/184\n \u003cIRQ\u003e\n tipc_disc_rcv (net/tipc/discover.c:149)\n tipc_rcv (net/tipc/node.c:2126)\n tipc_udp_recv (net/tipc/udp_media.c:391)\n udp_rcv (net/ipv4/udp.c:2643)\n ip_local_deliver_finish (net/ipv4/ip_input.c:241)\n \u003c/IRQ\u003e\n Freed by task 181:\n kfree (mm/slub.c:6565)\n bearer_disable (net/tipc/bearer.c:418)\n tipc_nl_bearer_disable (net/tipc/bearer.c:1001)\n\nThe bearer is freed with kfree_rcu(); free the discoverer the same way.\nAdd an rcu_head to struct tipc_discoverer and free it and its skb from an\nRCU callback.\n\nBecause the RCU callback (tipc_disc_free_rcu) lives in module text, a\ncall_rcu() that is still pending when the tipc module is unloaded would\ninvoke a freed function. Add an rcu_barrier() to tipc_exit() after the\nbearer subsystem has been torn down, so all pending discoverer callbacks\nhave run before the module text goes away.\n\nReachable from an unprivileged user namespace: the TIPCv2 genl family is\nnetnsok and its bearer commands have no GENL_ADMIN_PERM. Needs CONFIG_TIPC\nand CONFIG_TIPC_MEDIA_UDP."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The free side is only reachable through the local TIPCv2 generic-netlink `BEARER_DISABLE` command (or netns teardown); a remote peer can supply the discovery packet that performs the use-after-free access but cannot itself cause `bearer_disable()` to run, so the complete attack requires local access.\nAC:L - The attacker controls both sides of the race \u2014 one thread floods TIPC discovery packets at the bearer\u0027s UDP port while another disables the bearer \u2014 and `bearer_disable()` clears `b-\u003eup` and then `kfree()`s the discoverer with no synchronization whatsoever, leaving a wide window that a multi-CPU packet flood hits reliably (a working PoC exists).\nPR:L - `tipc_genl_family` is `.netnsok = true` and the bearer enable/disable ops carry no `GENL_ADMIN_PERM` or other capability check, so an unprivileged user can do everything inside `unshare -Urn` after autoloading tipc via `socket(AF_TIPC, ...)`.\nUI:N - The attacking process performs both the bearer disable and the packet injection itself; no victim action or cooperating user is involved.\nS:U - The corruption stays within the kernel\u0027s own security authority \u2014 no VM, IOMMU, or hypervisor boundary is crossed.\nC:H - `d-\u003enet` is read from the freed slab object and dereferenced as a `struct net *`; after reclaiming the kmalloc-192 allocation with sprayed data the attacker gains a controlled-pointer dereference chain usable for arbitrary kernel memory disclosure.\nI:H - `msg_set_prevnode(buf_msg(d-\u003eskb), sugg_addr)` writes a wire-controlled 32-bit value through the dangling `d-\u003eskb` pointer, and `tipc_disc_add_dest()` takes a spinlock and increments a counter in freed memory \u2014 together a controlled-address/controlled-value write suitable for control-flow hijacking.\nA:H - The use-after-free reliably produces a KASAN slab-use-after-free in softirq context and, on production kernels, a corrupted-pointer dereference or spinlock manipulation on reclaimed memory leading to kernel panic."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:28:28.342Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/380413cdfd29fb9fa486c82889132b680c4983c5"
},
{
"url": "https://git.kernel.org/stable/c/f05b3f4c78370469286879c765f5a1dd39dbcd32"
},
{
"url": "https://git.kernel.org/stable/c/4da2ac7749411971e1b222b992da5a172ce45f98"
},
{
"url": "https://git.kernel.org/stable/c/5e215bf1c47fdddf8203a0fe80a0ed594065f101"
},
{
"url": "https://git.kernel.org/stable/c/ec7d54d8cc1723921d671e3272b427c96366506f"
},
{
"url": "https://git.kernel.org/stable/c/a0c5fdeb5fa257f8c6d469af266bc087cb5de6a2"
},
{
"url": "https://git.kernel.org/stable/c/b65289e1c3f352a9f92c6e19713ddd647e033253"
},
{
"url": "https://git.kernel.org/stable/c/1579342d71133da7f00daa02c75cebec7372097b"
}
],
"title": "tipc: fix use-after-free of the discoverer in tipc_disc_rcv()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64543",
"datePublished": "2026-07-27T20:10:35.565Z",
"dateReserved": "2026-07-19T15:36:31.795Z",
"dateUpdated": "2026-08-19T16:28:28.342Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2025-38117 (GCVE-0-2025-38117)
Vulnerability from cvelistv5
Published
2025-07-03 08:35
Modified
2026-08-23 12:45
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: MGMT: Protect mgmt_pending list with its own lock
This uses a mutex to protect from concurrent access of mgmt_pending
list which can cause crashes like:
==================================================================
BUG: KASAN: slab-use-after-free in hci_sock_get_channel+0x60/0x68 net/bluetooth/hci_sock.c:91
Read of size 2 at addr ffff0000c48885b2 by task syz.4.334/7318
CPU: 0 UID: 0 PID: 7318 Comm: syz.4.334 Not tainted 6.15.0-rc7-syzkaller-g187899f4124a #0 PREEMPT
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2025
Call trace:
show_stack+0x2c/0x3c arch/arm64/kernel/stacktrace.c:466 (C)
__dump_stack+0x30/0x40 lib/dump_stack.c:94
dump_stack_lvl+0xd8/0x12c lib/dump_stack.c:120
print_address_description+0xa8/0x254 mm/kasan/report.c:408
print_report+0x68/0x84 mm/kasan/report.c:521
kasan_report+0xb0/0x110 mm/kasan/report.c:634
__asan_report_load2_noabort+0x20/0x2c mm/kasan/report_generic.c:379
hci_sock_get_channel+0x60/0x68 net/bluetooth/hci_sock.c:91
mgmt_pending_find+0x7c/0x140 net/bluetooth/mgmt_util.c:223
pending_find net/bluetooth/mgmt.c:947 [inline]
remove_adv_monitor+0x44/0x1a4 net/bluetooth/mgmt.c:5445
hci_mgmt_cmd+0x780/0xc00 net/bluetooth/hci_sock.c:1712
hci_sock_sendmsg+0x544/0xbb0 net/bluetooth/hci_sock.c:1832
sock_sendmsg_nosec net/socket.c:712 [inline]
__sock_sendmsg net/socket.c:727 [inline]
sock_write_iter+0x25c/0x378 net/socket.c:1131
new_sync_write fs/read_write.c:591 [inline]
vfs_write+0x62c/0x97c fs/read_write.c:684
ksys_write+0x120/0x210 fs/read_write.c:736
__do_sys_write fs/read_write.c:747 [inline]
__se_sys_write fs/read_write.c:744 [inline]
__arm64_sys_write+0x7c/0x90 fs/read_write.c:744
__invoke_syscall arch/arm64/kernel/syscall.c:35 [inline]
invoke_syscall+0x98/0x2b8 arch/arm64/kernel/syscall.c:49
el0_svc_common+0x130/0x23c arch/arm64/kernel/syscall.c:132
do_el0_svc+0x48/0x58 arch/arm64/kernel/syscall.c:151
el0_svc+0x58/0x17c arch/arm64/kernel/entry-common.c:767
el0t_64_sync_handler+0x78/0x108 arch/arm64/kernel/entry-common.c:786
el0t_64_sync+0x198/0x19c arch/arm64/kernel/entry.S:600
Allocated by task 7037:
kasan_save_stack mm/kasan/common.c:47 [inline]
kasan_save_track+0x40/0x78 mm/kasan/common.c:68
kasan_save_alloc_info+0x44/0x54 mm/kasan/generic.c:562
poison_kmalloc_redzone mm/kasan/common.c:377 [inline]
__kasan_kmalloc+0x9c/0xb4 mm/kasan/common.c:394
kasan_kmalloc include/linux/kasan.h:260 [inline]
__do_kmalloc_node mm/slub.c:4327 [inline]
__kmalloc_noprof+0x2fc/0x4c8 mm/slub.c:4339
kmalloc_noprof include/linux/slab.h:909 [inline]
sk_prot_alloc+0xc4/0x1f0 net/core/sock.c:2198
sk_alloc+0x44/0x3ac net/core/sock.c:2254
bt_sock_alloc+0x4c/0x300 net/bluetooth/af_bluetooth.c:148
hci_sock_create+0xa8/0x194 net/bluetooth/hci_sock.c:2202
bt_sock_create+0x14c/0x24c net/bluetooth/af_bluetooth.c:132
__sock_create+0x43c/0x91c net/socket.c:1541
sock_create net/socket.c:1599 [inline]
__sys_socket_create net/socket.c:1636 [inline]
__sys_socket+0xd4/0x1c0 net/socket.c:1683
__do_sys_socket net/socket.c:1697 [inline]
__se_sys_socket net/socket.c:1695 [inline]
__arm64_sys_socket+0x7c/0x94 net/socket.c:1695
__invoke_syscall arch/arm64/kernel/syscall.c:35 [inline]
invoke_syscall+0x98/0x2b8 arch/arm64/kernel/syscall.c:49
el0_svc_common+0x130/0x23c arch/arm64/kernel/syscall.c:132
do_el0_svc+0x48/0x58 arch/arm64/kernel/syscall.c:151
el0_svc+0x58/0x17c arch/arm64/kernel/entry-common.c:767
el0t_64_sync_handler+0x78/0x108 arch/arm64/kernel/entry-common.c:786
el0t_64_sync+0x198/0x19c arch/arm64/kernel/entry.S:600
Freed by task 6607:
kasan_save_stack mm/kasan/common.c:47 [inline]
kasan_save_track+0x40/0x78 mm/kasan/common.c:68
kasan_save_free_info+0x58/0x70 mm/kasan/generic.c:576
poison_slab_object mm/kasan/common.c:247 [inline]
__kasan_slab_free+0x68/0x88 mm/kasan/common.c:264
kasan_slab_free include/linux/kasan.h:233 [inline
---truncated---
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"include/net/bluetooth/hci_core.h",
"net/bluetooth/hci_core.c",
"net/bluetooth/mgmt.c",
"net/bluetooth/mgmt_util.c",
"net/bluetooth/mgmt_util.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "7b5958332f20dc66b19be564c402dbc21b927a81",
"status": "affected",
"version": "a380b6cff1a2d2139772e88219d08330f84d0381",
"versionType": "git"
},
{
"lessThan": "bdd56875c6926d8009914f427df71797693e90d4",
"status": "affected",
"version": "a380b6cff1a2d2139772e88219d08330f84d0381",
"versionType": "git"
},
{
"lessThan": "4e83f2dbb2bf677e614109df24426c4dded472d4",
"status": "affected",
"version": "a380b6cff1a2d2139772e88219d08330f84d0381",
"versionType": "git"
},
{
"lessThan": "d7882db79135c829a922daf3571f33ea1e056ae3",
"status": "affected",
"version": "a380b6cff1a2d2139772e88219d08330f84d0381",
"versionType": "git"
},
{
"lessThan": "6fe26f694c824b8a4dbf50c635bee1302e3f099c",
"status": "affected",
"version": "a380b6cff1a2d2139772e88219d08330f84d0381",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"include/net/bluetooth/hci_core.h",
"net/bluetooth/hci_core.c",
"net/bluetooth/mgmt.c",
"net/bluetooth/mgmt_util.c",
"net/bluetooth/mgmt_util.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.1"
},
{
"lessThan": "4.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.94",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.34",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.15.*",
"status": "unaffected",
"version": "6.15.3",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "6.16",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.94",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.34",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.15.3",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.16",
"versionStartIncluding": "4.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: MGMT: Protect mgmt_pending list with its own lock\n\nThis uses a mutex to protect from concurrent access of mgmt_pending\nlist which can cause crashes like:\n\n==================================================================\nBUG: KASAN: slab-use-after-free in hci_sock_get_channel+0x60/0x68 net/bluetooth/hci_sock.c:91\nRead of size 2 at addr ffff0000c48885b2 by task syz.4.334/7318\n\nCPU: 0 UID: 0 PID: 7318 Comm: syz.4.334 Not tainted 6.15.0-rc7-syzkaller-g187899f4124a #0 PREEMPT\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2025\nCall trace:\n show_stack+0x2c/0x3c arch/arm64/kernel/stacktrace.c:466 (C)\n __dump_stack+0x30/0x40 lib/dump_stack.c:94\n dump_stack_lvl+0xd8/0x12c lib/dump_stack.c:120\n print_address_description+0xa8/0x254 mm/kasan/report.c:408\n print_report+0x68/0x84 mm/kasan/report.c:521\n kasan_report+0xb0/0x110 mm/kasan/report.c:634\n __asan_report_load2_noabort+0x20/0x2c mm/kasan/report_generic.c:379\n hci_sock_get_channel+0x60/0x68 net/bluetooth/hci_sock.c:91\n mgmt_pending_find+0x7c/0x140 net/bluetooth/mgmt_util.c:223\n pending_find net/bluetooth/mgmt.c:947 [inline]\n remove_adv_monitor+0x44/0x1a4 net/bluetooth/mgmt.c:5445\n hci_mgmt_cmd+0x780/0xc00 net/bluetooth/hci_sock.c:1712\n hci_sock_sendmsg+0x544/0xbb0 net/bluetooth/hci_sock.c:1832\n sock_sendmsg_nosec net/socket.c:712 [inline]\n __sock_sendmsg net/socket.c:727 [inline]\n sock_write_iter+0x25c/0x378 net/socket.c:1131\n new_sync_write fs/read_write.c:591 [inline]\n vfs_write+0x62c/0x97c fs/read_write.c:684\n ksys_write+0x120/0x210 fs/read_write.c:736\n __do_sys_write fs/read_write.c:747 [inline]\n __se_sys_write fs/read_write.c:744 [inline]\n __arm64_sys_write+0x7c/0x90 fs/read_write.c:744\n __invoke_syscall arch/arm64/kernel/syscall.c:35 [inline]\n invoke_syscall+0x98/0x2b8 arch/arm64/kernel/syscall.c:49\n el0_svc_common+0x130/0x23c arch/arm64/kernel/syscall.c:132\n do_el0_svc+0x48/0x58 arch/arm64/kernel/syscall.c:151\n el0_svc+0x58/0x17c arch/arm64/kernel/entry-common.c:767\n el0t_64_sync_handler+0x78/0x108 arch/arm64/kernel/entry-common.c:786\n el0t_64_sync+0x198/0x19c arch/arm64/kernel/entry.S:600\n\nAllocated by task 7037:\n kasan_save_stack mm/kasan/common.c:47 [inline]\n kasan_save_track+0x40/0x78 mm/kasan/common.c:68\n kasan_save_alloc_info+0x44/0x54 mm/kasan/generic.c:562\n poison_kmalloc_redzone mm/kasan/common.c:377 [inline]\n __kasan_kmalloc+0x9c/0xb4 mm/kasan/common.c:394\n kasan_kmalloc include/linux/kasan.h:260 [inline]\n __do_kmalloc_node mm/slub.c:4327 [inline]\n __kmalloc_noprof+0x2fc/0x4c8 mm/slub.c:4339\n kmalloc_noprof include/linux/slab.h:909 [inline]\n sk_prot_alloc+0xc4/0x1f0 net/core/sock.c:2198\n sk_alloc+0x44/0x3ac net/core/sock.c:2254\n bt_sock_alloc+0x4c/0x300 net/bluetooth/af_bluetooth.c:148\n hci_sock_create+0xa8/0x194 net/bluetooth/hci_sock.c:2202\n bt_sock_create+0x14c/0x24c net/bluetooth/af_bluetooth.c:132\n __sock_create+0x43c/0x91c net/socket.c:1541\n sock_create net/socket.c:1599 [inline]\n __sys_socket_create net/socket.c:1636 [inline]\n __sys_socket+0xd4/0x1c0 net/socket.c:1683\n __do_sys_socket net/socket.c:1697 [inline]\n __se_sys_socket net/socket.c:1695 [inline]\n __arm64_sys_socket+0x7c/0x94 net/socket.c:1695\n __invoke_syscall arch/arm64/kernel/syscall.c:35 [inline]\n invoke_syscall+0x98/0x2b8 arch/arm64/kernel/syscall.c:49\n el0_svc_common+0x130/0x23c arch/arm64/kernel/syscall.c:132\n do_el0_svc+0x48/0x58 arch/arm64/kernel/syscall.c:151\n el0_svc+0x58/0x17c arch/arm64/kernel/entry-common.c:767\n el0t_64_sync_handler+0x78/0x108 arch/arm64/kernel/entry-common.c:786\n el0t_64_sync+0x198/0x19c arch/arm64/kernel/entry.S:600\n\nFreed by task 6607:\n kasan_save_stack mm/kasan/common.c:47 [inline]\n kasan_save_track+0x40/0x78 mm/kasan/common.c:68\n kasan_save_free_info+0x58/0x70 mm/kasan/generic.c:576\n poison_slab_object mm/kasan/common.c:247 [inline]\n __kasan_slab_free+0x68/0x88 mm/kasan/common.c:264\n kasan_slab_free include/linux/kasan.h:233 [inline\n---truncated---"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable code is reached only through local syscalls \u2014 `socket()`/`bind()` on an AF_BLUETOOTH HCI socket bound to HCI_CHANNEL_CONTROL followed by `write()`/`sendmsg()` into `hci_mgmt_cmd()`. Although this is the Bluetooth subsystem, the mgmt interface is a local control API and no over-the-air data from an adjacent peer drives either side of the race.\nAC:L - The attacker controls both sides of the race: one thread issues MGMT_OP_SET_POWERED (whose completion frees the pending command and its socket from the hci_cmd_sync workqueue) while another spams commands such as MGMT_OP_REMOVE_ADV_MONITOR that traverse the same unlocked list. syzbot reproduced this reliably and confirmed the fix on two separate reports.\nPR:L - Binding the control channel requires no capability, and the mgmt commands involved require the HCI_SOCK_TRUSTED flag granted by CAP_NET_ADMIN \u2014 a capability held by non-root Bluetooth daemons (e.g. Android\u0027s bluetooth UID), which is exactly the low-privileged component an attacker lands in after compromising the remote-facing stack. This matches the CNA precedent for the identical mgmt_pending list bug class (CVE-2026-31511).\nUI:N - The attacker triggers the race entirely from its own threads via socket writes; no victim action, mount, or file open is needed.\nS:U - The use-after-free corrupts kernel heap state within the same kernel security authority, giving local privilege escalation rather than crossing a VM, IOMMU, or sandbox boundary.\nC:H - `hci_sock_get_channel()` reads freed `struct sock` memory, and because `hci_sk_proto` has no dedicated slab the object is allocated with plain kmalloc into a sprayable general-purpose cache; a groomed reclaim lets `pending_find()` return a command with a dangling `sk`, after which `mgmt_cmd_status()`/`mgmt_cmd_complete()` operate on attacker-shaped memory, yielding kernel information disclosure.\nI:H - Concurrent `list_del`/`list_add_tail` on `hdev-\u003emgmt_pending` with no lock corrupts the doubly-linked list, and `list_del` on a stale entry writes attacker-influenced pointers into freed memory; combined with operations on a freed, function-pointer-laden `struct sock`, this provides write and control-flow-hijack primitives.\nA:H - The bug is a KASAN-confirmed slab-use-after-free that oopses the kernel, and the accompanying list corruption and potential double free of the pending command reliably panic the system."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:45:21.364Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/7b5958332f20dc66b19be564c402dbc21b927a81"
},
{
"url": "https://git.kernel.org/stable/c/bdd56875c6926d8009914f427df71797693e90d4"
},
{
"url": "https://git.kernel.org/stable/c/4e83f2dbb2bf677e614109df24426c4dded472d4"
},
{
"url": "https://git.kernel.org/stable/c/d7882db79135c829a922daf3571f33ea1e056ae3"
},
{
"url": "https://git.kernel.org/stable/c/6fe26f694c824b8a4dbf50c635bee1302e3f099c"
}
],
"title": "Bluetooth: MGMT: Protect mgmt_pending list with its own lock",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2025-38117",
"datePublished": "2025-07-03T08:35:25.060Z",
"dateReserved": "2025-04-16T04:51:23.986Z",
"dateUpdated": "2026-08-23T12:45:21.364Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74469 (GCVE-0-2026-74469)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-19 16:37
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
sctp: prevent peer transport count overflow
sctp_assoc_add_peer() increments the association's 16-bit transport_count
for every new unique peer. Adding the 65,536th transport wraps the count to
zero.
SCTP sock_diag uses transport_count to reserve the INET_DIAG_PEERS payload,
then copies one sockaddr_storage for every entry in transport_addr_list.
After the wrap, a diagnostic dump reserves an empty payload and writes
8 MiB of peer addresses past the skb tail.
Reject a new unique peer when transport_count has reached U16_MAX. Perform
the check after the existing-peer lookup so a duplicate address continues
to return its existing transport at the limit.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 8f840e47f190cbe61a96945c13e9551048d42cef Version: 8f840e47f190cbe61a96945c13e9551048d42cef Version: 8f840e47f190cbe61a96945c13e9551048d42cef Version: 8f840e47f190cbe61a96945c13e9551048d42cef Version: 8f840e47f190cbe61a96945c13e9551048d42cef Version: 8f840e47f190cbe61a96945c13e9551048d42cef Version: 8f840e47f190cbe61a96945c13e9551048d42cef Version: 8f840e47f190cbe61a96945c13e9551048d42cef |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/sctp/associola.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b453e00da1211e997b82743d28af7714c59c05c8",
"status": "affected",
"version": "8f840e47f190cbe61a96945c13e9551048d42cef",
"versionType": "git"
},
{
"lessThan": "dfea32dd76f390e3155177b0038cc47b01386198",
"status": "affected",
"version": "8f840e47f190cbe61a96945c13e9551048d42cef",
"versionType": "git"
},
{
"lessThan": "80f48523a0fe42db2e7375dff4e38a25c117090a",
"status": "affected",
"version": "8f840e47f190cbe61a96945c13e9551048d42cef",
"versionType": "git"
},
{
"lessThan": "546221b86ceeba0d8fec92d46a0604bb7b62be07",
"status": "affected",
"version": "8f840e47f190cbe61a96945c13e9551048d42cef",
"versionType": "git"
},
{
"lessThan": "09e722030e8148ba4ed1e42c6b2ea57bda9f9895",
"status": "affected",
"version": "8f840e47f190cbe61a96945c13e9551048d42cef",
"versionType": "git"
},
{
"lessThan": "4ba5bf7ed50f235ea4581de8e7a0002f4ed287b0",
"status": "affected",
"version": "8f840e47f190cbe61a96945c13e9551048d42cef",
"versionType": "git"
},
{
"lessThan": "6201cd1d70f1670c5b31ac506e7ab2fa7b8e7f75",
"status": "affected",
"version": "8f840e47f190cbe61a96945c13e9551048d42cef",
"versionType": "git"
},
{
"lessThan": "bd0e9289e2642f6a5c54faad304ce0f41e926d22",
"status": "affected",
"version": "8f840e47f190cbe61a96945c13e9551048d42cef",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/sctp/associola.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.7"
},
{
"lessThan": "4.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: prevent peer transport count overflow\n\nsctp_assoc_add_peer() increments the association\u0027s 16-bit transport_count\nfor every new unique peer. Adding the 65,536th transport wraps the count to\nzero.\n\nSCTP sock_diag uses transport_count to reserve the INET_DIAG_PEERS payload,\nthen copies one sockaddr_storage for every entry in transport_addr_list.\nAfter the wrap, a diagnostic dump reserves an empty payload and writes\n8 MiB of peer addresses past the skb tail.\n\nReject a new unique peer when transport_count has reached U16_MAX. Perform\nthe check after the existing-peer lookup so a duplicate address continues\nto return its existing transport at the limit."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - Remote SCTP peers add unique transports via INIT address parameters and ASCONF ADD_IP chunks processed in sctp_assoc_add_peer(); this is network ingress on SCTP servers (telecom, signaling gateways) before any local diagnostic action.\nAC:L - An attacker controlling an SCTP association can script 65536 unique peer addresses via connectx, repeated ASCONF ADD_IP, or INIT parameters; no race or victim-specific state is required beyond reaching the transport limit.\nPR:L - The heap overflow is triggered via NETLINK_SOCK_DIAG (ss/netlink), reachable by unprivileged users; SCTP socket creation and connectx need no capabilities beyond a normal local account (including user namespaces).\nUI:N - Exploitation requires no victim interaction; the attacker drives transport accumulation and issues the diagnostic dump themselves.\nS:U - Impact is kernel heap corruption within the same kernel security boundary; this is not a VM escape, sandbox breakout, or cross-authority scope change.\nC:H - When transport_count wraps to zero, inet_diag_msg_sctpaddrs_fill() reserves no space but iterates all 65536 transports, writing ~8 MiB past the skb tail and enabling adjacent kernel heap reads.\nI:H - The same diag path performs a massive out-of-bounds write of sockaddr_storage entries past the allocated skb buffer, corrupting adjacent kernel heap objects and enabling control-flow hijacking.\nA:H - Corrupting sk_buff heap metadata and adjacent allocations via an ~8 MiB out-of-bounds write can cause kernel oops, panic, or hang, meeting high availability impact."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:37:15.198Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b453e00da1211e997b82743d28af7714c59c05c8"
},
{
"url": "https://git.kernel.org/stable/c/dfea32dd76f390e3155177b0038cc47b01386198"
},
{
"url": "https://git.kernel.org/stable/c/80f48523a0fe42db2e7375dff4e38a25c117090a"
},
{
"url": "https://git.kernel.org/stable/c/546221b86ceeba0d8fec92d46a0604bb7b62be07"
},
{
"url": "https://git.kernel.org/stable/c/09e722030e8148ba4ed1e42c6b2ea57bda9f9895"
},
{
"url": "https://git.kernel.org/stable/c/4ba5bf7ed50f235ea4581de8e7a0002f4ed287b0"
},
{
"url": "https://git.kernel.org/stable/c/6201cd1d70f1670c5b31ac506e7ab2fa7b8e7f75"
},
{
"url": "https://git.kernel.org/stable/c/bd0e9289e2642f6a5c54faad304ce0f41e926d22"
}
],
"title": "sctp: prevent peer transport count overflow",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74469",
"datePublished": "2026-08-15T12:27:06.873Z",
"dateReserved": "2026-08-15T05:44:03.902Z",
"dateUpdated": "2026-08-19T16:37:15.198Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72114 (GCVE-0-2026-72114)
Vulnerability from cvelistv5
Published
2026-08-15 05:52
Modified
2026-08-19 16:36
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
can: bcm: validate frame length in bcm_rx_setup() for RTR replies
bcm_tx_setup() validates cf->len against the CAN/CAN FD DLC limits
before installing frames for TX_SETUP, but bcm_rx_setup() never did
the same for the RTR-reply frame configured via RX_SETUP with
RX_RTR_FRAME.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/can/bcm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "cc1f9569f1c1adf74fa69d6f716a31b58a2fc6ce",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "204f2b232717bc470ddb9e1da1d27dd9c6ef0caa",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "e061624c0a86c3c26a2bf017e432fbc93ad68f3a",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "7d966cdee006911d3957e1a4e72cb93c39cd8c1e",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "1b475c0c72f44622a320a4386ce9e76f85e69bc7",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "deb6a697cce3f021e731df543597f37a5e54caab",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "59bfddea64159594feb62ef11b7d7a33c8ee3783",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "62ec41f364648be79d54d94d0d240ee326948afd",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/can/bcm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.25"
},
{
"lessThan": "2.6.25",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.25",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: bcm: validate frame length in bcm_rx_setup() for RTR replies\n\nbcm_tx_setup() validates cf-\u003elen against the CAN/CAN FD DLC limits\nbefore installing frames for TX_SETUP, but bcm_rx_setup() never did\nthe same for the RTR-reply frame configured via RX_SETUP with\nRX_RTR_FRAME."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The missing validation is in bcm_rx_setup(), reached only via local PF_CAN SOCK_DGRAM CAN_BCM syscalls (socket/connect/sendmsg RX_SETUP with RX_RTR_FRAME); it is not triggered by remote IP services or by CAN bus traffic alone.\nAC:L - An attacker reliably installs a malformed RTR-reply frame with a single RX_SETUP sendmsg and can trigger bcm_can_tx() by sending or waiting for a matching RTR on the bound interface, with no races or layout dependencies beyond their control.\nPR:L - can_create(), bcm_connect(), and bcm_sendmsg() perform no capability checks; any local user with access to a CAN interface (including vcan created with CAP_NET_ADMIN in an unprivileged user namespace) can open BCM sockets and program RX_SETUP RTR replies.\nUI:N - Exploitation requires only the attacker opening a BCM socket and sending RX_SETUP messages; no victim interaction such as mounting filesystems or opening files is needed once local CAN access exists.\nS:U - Impact is kernel memory corruption and unauthorized CAN frame transmission within the same host security domain; it does not cross VM, container, or IOMMU boundaries even when frames reach an adjacent vehicle or industrial CAN segment.\nC:H - Unvalidated cf-\u003elen values are stored in op-\u003eframes and later passed to bcm_can_tx()/can_send(); many CAN driver ndo_start_xmit paths memcpy(cf-\u003edata, cf-\u003elen) trusting len, enabling out-of-bounds kernel reads when invalid lengths bypass or race skb validation.\nI:H - Attacker-controlled len in the RTR-reply frame can drive out-of-bounds memcpy writes in CAN USB/SPI/hardware xmit paths and inject attacker-crafted frame payloads onto safety-critical automotive, factory, or embedded CAN buses when RTR requests are answered.\nA:H - Out-of-bounds accesses in CAN driver transmit paths from trusted-but-invalid len values can cause kernel WARN/Oops/panic on hardened builds, and repeated malformed RTR-reply transmission attempts can wedge TX queues or disrupt CAN service on affected systems."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:36:00.857Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/cc1f9569f1c1adf74fa69d6f716a31b58a2fc6ce"
},
{
"url": "https://git.kernel.org/stable/c/204f2b232717bc470ddb9e1da1d27dd9c6ef0caa"
},
{
"url": "https://git.kernel.org/stable/c/e061624c0a86c3c26a2bf017e432fbc93ad68f3a"
},
{
"url": "https://git.kernel.org/stable/c/7d966cdee006911d3957e1a4e72cb93c39cd8c1e"
},
{
"url": "https://git.kernel.org/stable/c/1b475c0c72f44622a320a4386ce9e76f85e69bc7"
},
{
"url": "https://git.kernel.org/stable/c/deb6a697cce3f021e731df543597f37a5e54caab"
},
{
"url": "https://git.kernel.org/stable/c/59bfddea64159594feb62ef11b7d7a33c8ee3783"
},
{
"url": "https://git.kernel.org/stable/c/62ec41f364648be79d54d94d0d240ee326948afd"
}
],
"title": "can: bcm: validate frame length in bcm_rx_setup() for RTR replies",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72114",
"datePublished": "2026-08-15T05:52:54.750Z",
"dateReserved": "2026-08-09T03:40:39.906Z",
"dateUpdated": "2026-08-19T16:36:00.857Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74601 (GCVE-0-2026-74601)
Vulnerability from cvelistv5
Published
2026-08-22 15:31
Modified
2026-08-25 05:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ring-buffer: Use current_context for safe per-CPU buffer swap
The ring_buffer_swap_cpu() function currently checks the per-CPU
committing counter to determine if a buffer is actively being written to
before performing the swap. However, there exists a race window where
this check can be bypassed:
ring_buffer_lock_reserve
cpu_buffer = buffer->buffers[cpu]; // cpu_buffer_a
rb_reserve_next_event
rb_start_commit // inc committing
if (unlikely(READ_ONCE(cpu_buffer->buffer) != buffer)) {...}
__rb_reserve_next
rb_move_tail
rb_end_commit(cpu_buffer); // dec committing => 0
/* interrupt hits here, successfully swaps! */
local_inc(&cpu_buffer->committing);
ring_buffer_unlock_commit
cpu_buffer = buffer->buffers[cpu]; // cpu_buffer_b
rb_commit
rb_end_commit
RB_WARN_ON(cpu_buffer, !local_read(&cpu_buffer->committing))
// triggers warning
The committing counter can temporarily drop to 0 during a single write
operation (within rb_move_tail), creating a window where swap can
succeed even though the write is still in progress. This leads to
inconsistent buffer state and triggers the RB_WARN_ON in rb_commit().
Replace the committing counter check with current_context checks, which
are set at the entry of ring_buffer_lock_reserve() and remain valid
throughout the entire write operation, providing a reliable indicator of
buffer busy state during swap.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 4239c38fe0b3847e1e6d962c74b41b08ba0e2990 Version: 4239c38fe0b3847e1e6d962c74b41b08ba0e2990 Version: 4239c38fe0b3847e1e6d962c74b41b08ba0e2990 Version: 4239c38fe0b3847e1e6d962c74b41b08ba0e2990 Version: 4239c38fe0b3847e1e6d962c74b41b08ba0e2990 Version: 4239c38fe0b3847e1e6d962c74b41b08ba0e2990 Version: 4239c38fe0b3847e1e6d962c74b41b08ba0e2990 Version: 4239c38fe0b3847e1e6d962c74b41b08ba0e2990 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"kernel/trace/ring_buffer.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "26662bc8fced1d668fa1aa146eda085bfc67bd0b",
"status": "affected",
"version": "4239c38fe0b3847e1e6d962c74b41b08ba0e2990",
"versionType": "git"
},
{
"lessThan": "6b524e6b234e45c7f5f90d13b042c6f57f80105c",
"status": "affected",
"version": "4239c38fe0b3847e1e6d962c74b41b08ba0e2990",
"versionType": "git"
},
{
"lessThan": "597f279b7b4a06412e3d965e98cc36e181cdbede",
"status": "affected",
"version": "4239c38fe0b3847e1e6d962c74b41b08ba0e2990",
"versionType": "git"
},
{
"lessThan": "22709117d9ae95e52673685f98caac7c356a8227",
"status": "affected",
"version": "4239c38fe0b3847e1e6d962c74b41b08ba0e2990",
"versionType": "git"
},
{
"lessThan": "ad7e10c7ea89af45ac1bf1814855d45da472703d",
"status": "affected",
"version": "4239c38fe0b3847e1e6d962c74b41b08ba0e2990",
"versionType": "git"
},
{
"lessThan": "5b926fb04cb9ef3156dcf88c69a59d3d1a1c4f9f",
"status": "affected",
"version": "4239c38fe0b3847e1e6d962c74b41b08ba0e2990",
"versionType": "git"
},
{
"lessThan": "5e6e2a18c20e88167d414f666032792e8bf19b80",
"status": "affected",
"version": "4239c38fe0b3847e1e6d962c74b41b08ba0e2990",
"versionType": "git"
},
{
"lessThan": "f27bdc43077e4fcb5557dfc315ee8d91e741f483",
"status": "affected",
"version": "4239c38fe0b3847e1e6d962c74b41b08ba0e2990",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"kernel/trace/ring_buffer.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.5"
},
{
"lessThan": "4.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "4.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nring-buffer: Use current_context for safe per-CPU buffer swap\n\nThe ring_buffer_swap_cpu() function currently checks the per-CPU\ncommitting counter to determine if a buffer is actively being written to\nbefore performing the swap. However, there exists a race window where\nthis check can be bypassed:\n\n ring_buffer_lock_reserve\n cpu_buffer = buffer-\u003ebuffers[cpu]; // cpu_buffer_a\n rb_reserve_next_event\n rb_start_commit // inc committing\n if (unlikely(READ_ONCE(cpu_buffer-\u003ebuffer) != buffer)) {...}\n __rb_reserve_next\n rb_move_tail\n rb_end_commit(cpu_buffer); // dec committing =\u003e 0\n /* interrupt hits here, successfully swaps! */\n local_inc(\u0026cpu_buffer-\u003ecommitting);\n\n ring_buffer_unlock_commit\n cpu_buffer = buffer-\u003ebuffers[cpu]; // cpu_buffer_b\n rb_commit\n rb_end_commit\n RB_WARN_ON(cpu_buffer, !local_read(\u0026cpu_buffer-\u003ecommitting))\n // triggers warning\n\nThe committing counter can temporarily drop to 0 during a single write\noperation (within rb_move_tail), creating a window where swap can\nsucceed even though the write is still in progress. This leads to\ninconsistent buffer state and triggers the RB_WARN_ON in rb_commit().\n\nReplace the committing counter check with current_context checks, which\nare set at the entry of ring_buffer_lock_reserve() and remain valid\nthroughout the entire write operation, providing a reliable indicator of\nbuffer busy state during swap."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires local tracefs writes to snapshot or latency tracers; ring_buffer_swap_cpu() is only reached from update_max_tr_single() via tracing_snapshot_write or irqsoff/preemptoff tracers, with no network, adjacent, or physical entry path.\nAC:L - The attacker controls both sides of the race by enabling irqsoff/preemptoff tracing or hammering per_cpu/*/snapshot while generating trace events that cross page boundaries, reliably hitting the rb_move_tail window where committing briefly drops to zero.\nPR:L - tracing_check_open_get_tr() enforces only LOCKDOWN_TRACEFS and DAC with no capable() check; tracefs gid= mounts, Android/Perfetto/ChromeOS tracing groups, and container user+mount namespaces routinely grant unprivileged local write access to snapshot and current_tracer.\nUI:N - The attacker enables tracers and triggers buffer swaps through their own tracefs writes and syscalls; no victim cooperation, unrelated user action, or third-party interaction is required.\nS:U - Impact is corrupted kernel ring-buffer metadata and WARN_ON within the same kernel security domain; this is not a VM escape, IOMMU bypass, or cross-authority sandbox breakout.\nC:H - Swapping per-CPU buffers mid-write leaves ring_buffer_per_cpu page, tail, and commit state inconsistent across buffers; subsequent trace reads or commits can access wrong backing pages, constituting kernel-memory corruption with arbitrary-read potential.\nI:H - Mid-reservation buffer swap causes unlock_commit on the wrong cpu_buffer with mismatched tail/commit page pointers, corrupting ring-buffer page lists and write metadata in ways exploitable for heap corruption and control-flow manipulation.\nA:H - rb_end_commit() hits RB_WARN_ON triggering WARN_ON and disabling recording; corrupted ring-buffer page state from this swap race has caused kernel oops/panic in related ring_buffer_swap_cpu bugs, and panic_on_warn makes the WARN fatal."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:40:26.170Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/26662bc8fced1d668fa1aa146eda085bfc67bd0b"
},
{
"url": "https://git.kernel.org/stable/c/6b524e6b234e45c7f5f90d13b042c6f57f80105c"
},
{
"url": "https://git.kernel.org/stable/c/597f279b7b4a06412e3d965e98cc36e181cdbede"
},
{
"url": "https://git.kernel.org/stable/c/22709117d9ae95e52673685f98caac7c356a8227"
},
{
"url": "https://git.kernel.org/stable/c/ad7e10c7ea89af45ac1bf1814855d45da472703d"
},
{
"url": "https://git.kernel.org/stable/c/5b926fb04cb9ef3156dcf88c69a59d3d1a1c4f9f"
},
{
"url": "https://git.kernel.org/stable/c/5e6e2a18c20e88167d414f666032792e8bf19b80"
},
{
"url": "https://git.kernel.org/stable/c/f27bdc43077e4fcb5557dfc315ee8d91e741f483"
}
],
"title": "ring-buffer: Use current_context for safe per-CPU buffer swap",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74601",
"datePublished": "2026-08-22T15:31:50.092Z",
"dateReserved": "2026-08-15T05:44:03.919Z",
"dateUpdated": "2026-08-25T05:40:26.170Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2024-58095 (GCVE-0-2024-58095)
Vulnerability from cvelistv5
Published
2025-04-16 14:11
Modified
2026-09-02 12:49
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
jfs: add check read-only before txBeginAnon() call
Added a read-only check before calling `txBeginAnon` in `extAlloc`
and `extRecord`. This prevents modification attempts on a read-only
mounted filesystem, avoiding potential errors or crashes.
Call trace:
txBeginAnon+0xac/0x154
extAlloc+0xe8/0xdec fs/jfs/jfs_extent.c:78
jfs_get_block+0x340/0xb98 fs/jfs/inode.c:248
__block_write_begin_int+0x580/0x166c fs/buffer.c:2128
__block_write_begin fs/buffer.c:2177 [inline]
block_write_begin+0x98/0x11c fs/buffer.c:2236
jfs_write_begin+0x44/0x88 fs/jfs/inode.c:299
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/jfs/jfs_extent.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "97ac32b08442f5327867ad7d70d6ac6ebaa2a41a",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "93f11ab37f1c657f4265228ba3c2ff66bbefa24d",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "469bd67fc338e77d7585e4f20d4212afd44fefdc",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "47a99881ecc50ff2bf4e7a6c3058fe1704073df9",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "939dba7a6404d4ac88e2539cb21ac659f5757fd9",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "15469c408af2d7a52fb186a92f2f091b0f13b1fb",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "0176e69743ecc02961f2ae1ea42439cd2bf9ed58",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/jfs/jfs_extent.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.269",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.220",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.187",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.156",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.108",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.14.*",
"status": "unaffected",
"version": "6.14.2",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "6.15",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.269",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.220",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.187",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.156",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.108",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.14.2",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.15",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\njfs: add check read-only before txBeginAnon() call\n\nAdded a read-only check before calling `txBeginAnon` in `extAlloc`\nand `extRecord`. This prevents modification attempts on a read-only\nmounted filesystem, avoiding potential errors or crashes.\n\nCall trace:\n txBeginAnon+0xac/0x154\n extAlloc+0xe8/0xdec fs/jfs/jfs_extent.c:78\n jfs_get_block+0x340/0xb98 fs/jfs/inode.c:248\n __block_write_begin_int+0x580/0x166c fs/buffer.c:2128\n __block_write_begin fs/buffer.c:2177 [inline]\n block_write_begin+0x98/0x11c fs/buffer.c:2236\n jfs_write_begin+0x44/0x88 fs/jfs/inode.c:299"
}
],
"providerMetadata": {
"dateUpdated": "2026-09-02T12:49:15.494Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/97ac32b08442f5327867ad7d70d6ac6ebaa2a41a"
},
{
"url": "https://git.kernel.org/stable/c/93f11ab37f1c657f4265228ba3c2ff66bbefa24d"
},
{
"url": "https://git.kernel.org/stable/c/469bd67fc338e77d7585e4f20d4212afd44fefdc"
},
{
"url": "https://git.kernel.org/stable/c/47a99881ecc50ff2bf4e7a6c3058fe1704073df9"
},
{
"url": "https://git.kernel.org/stable/c/939dba7a6404d4ac88e2539cb21ac659f5757fd9"
},
{
"url": "https://git.kernel.org/stable/c/15469c408af2d7a52fb186a92f2f091b0f13b1fb"
},
{
"url": "https://git.kernel.org/stable/c/0176e69743ecc02961f2ae1ea42439cd2bf9ed58"
}
],
"title": "jfs: add check read-only before txBeginAnon() call",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2024-58095",
"datePublished": "2025-04-16T14:11:43.934Z",
"dateReserved": "2025-03-06T15:52:09.188Z",
"dateUpdated": "2026-09-02T12:49:15.494Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68359 (GCVE-0-2026-68359)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
hwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop
Calling hid_hw_stop() does not stop the device IO.
This results in a race condition between hid_input_report() and the point
immediately following the execution of hid_device_io_start() within
the driver probe function. If the probe operation fails after "io start"
has been initiated, this race condition will result in a UAF vulnerability.
Fix the problem by calling hid_device_io_stop() before calling
hid_hw_stop().
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 53e68c20aeb1e23419bed811aa3a309ceda200f9 Version: 53e68c20aeb1e23419bed811aa3a309ceda200f9 Version: 53e68c20aeb1e23419bed811aa3a309ceda200f9 Version: 53e68c20aeb1e23419bed811aa3a309ceda200f9 Version: 53e68c20aeb1e23419bed811aa3a309ceda200f9 Version: 53e68c20aeb1e23419bed811aa3a309ceda200f9 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/hwmon/nzxt-smart2.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "761249a3d92db83ae19670c4ecdf73c0a85bcb61",
"status": "affected",
"version": "53e68c20aeb1e23419bed811aa3a309ceda200f9",
"versionType": "git"
},
{
"lessThan": "185c0880397aee9def0af5a59ea65f22f37ad658",
"status": "affected",
"version": "53e68c20aeb1e23419bed811aa3a309ceda200f9",
"versionType": "git"
},
{
"lessThan": "a2a15de020597efbff84b4281dd472e5860b7e3e",
"status": "affected",
"version": "53e68c20aeb1e23419bed811aa3a309ceda200f9",
"versionType": "git"
},
{
"lessThan": "205cff797a94757ec88ba299c8e2bf2e1e3f4bbf",
"status": "affected",
"version": "53e68c20aeb1e23419bed811aa3a309ceda200f9",
"versionType": "git"
},
{
"lessThan": "18d7c523891004226bccdba39dd681eca22ceb8a",
"status": "affected",
"version": "53e68c20aeb1e23419bed811aa3a309ceda200f9",
"versionType": "git"
},
{
"lessThan": "59d104b54b0b42e30fd2a68d24ee5c49dcc54d1e",
"status": "affected",
"version": "53e68c20aeb1e23419bed811aa3a309ceda200f9",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/hwmon/nzxt-smart2.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.17"
},
{
"lessThan": "5.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.17",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop\n\nCalling hid_hw_stop() does not stop the device IO.\nThis results in a race condition between hid_input_report() and the point\nimmediately following the execution of hid_device_io_start() within\nthe driver probe function. If the probe operation fails after \"io start\"\nhas been initiated, this race condition will result in a UAF vulnerability.\n\nFix the problem by calling hid_device_io_stop() before calling\nhid_hw_stop()."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:08.117Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/761249a3d92db83ae19670c4ecdf73c0a85bcb61"
},
{
"url": "https://git.kernel.org/stable/c/185c0880397aee9def0af5a59ea65f22f37ad658"
},
{
"url": "https://git.kernel.org/stable/c/a2a15de020597efbff84b4281dd472e5860b7e3e"
},
{
"url": "https://git.kernel.org/stable/c/205cff797a94757ec88ba299c8e2bf2e1e3f4bbf"
},
{
"url": "https://git.kernel.org/stable/c/18d7c523891004226bccdba39dd681eca22ceb8a"
},
{
"url": "https://git.kernel.org/stable/c/59d104b54b0b42e30fd2a68d24ee5c49dcc54d1e"
}
],
"title": "hwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68359",
"datePublished": "2026-08-10T12:03:36.254Z",
"dateReserved": "2026-07-30T09:28:09.385Z",
"dateUpdated": "2026-08-19T16:34:08.117Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80722 (GCVE-0-2026-80722)
Vulnerability from cvelistv5
Published
2026-08-28 06:53
Modified
2026-08-29 06:22
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: validate individual TWT params before driver setup
ieee80211_process_rx_twt_action() only partially validates a received
S1G TWT setup frame before queueing it.
An individual agreement can therefore reach ieee80211_s1g_rx_twt_setup()
with twt->length too short for the full struct ieee80211_twt_params.
The individual path passes twt to drv_add_twt_setup(). Both the tracepoint
and the driver callback consume the complete parameters block, not merely
req_type. Do not pass a short individual agreement to the driver.
Broadcast agreements remain unchanged because they are rejected locally
after accessing only req_type.
[edit commit message to not overclaim lack of validation nor
understate driver impact]
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: f5a4c24e689f54e66201f04d343bdd2e8a1d7923 Version: f5a4c24e689f54e66201f04d343bdd2e8a1d7923 Version: f5a4c24e689f54e66201f04d343bdd2e8a1d7923 Version: f5a4c24e689f54e66201f04d343bdd2e8a1d7923 Version: f5a4c24e689f54e66201f04d343bdd2e8a1d7923 Version: f5a4c24e689f54e66201f04d343bdd2e8a1d7923 Version: f5a4c24e689f54e66201f04d343bdd2e8a1d7923 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/mac80211/s1g.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "92fcd0f30dc8e51f252589b082d46851d295cc1a",
"status": "affected",
"version": "f5a4c24e689f54e66201f04d343bdd2e8a1d7923",
"versionType": "git"
},
{
"lessThan": "09d60d1f72e6598241490eb6c4e97245af895c09",
"status": "affected",
"version": "f5a4c24e689f54e66201f04d343bdd2e8a1d7923",
"versionType": "git"
},
{
"lessThan": "ff558072d199c1d641d1561da622e67f780514de",
"status": "affected",
"version": "f5a4c24e689f54e66201f04d343bdd2e8a1d7923",
"versionType": "git"
},
{
"lessThan": "ade9e2f0f7f4d3089600ac2af8ef0b91746f923b",
"status": "affected",
"version": "f5a4c24e689f54e66201f04d343bdd2e8a1d7923",
"versionType": "git"
},
{
"lessThan": "b558e07708d886acfcf4b0391ed7a8546e81d326",
"status": "affected",
"version": "f5a4c24e689f54e66201f04d343bdd2e8a1d7923",
"versionType": "git"
},
{
"lessThan": "47fb04c3826e1f90271d405523043d6708b9072a",
"status": "affected",
"version": "f5a4c24e689f54e66201f04d343bdd2e8a1d7923",
"versionType": "git"
},
{
"lessThan": "0502d5077e419427d80f4d46ba95d0067f5fb916",
"status": "affected",
"version": "f5a4c24e689f54e66201f04d343bdd2e8a1d7923",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/mac80211/s1g.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.15"
},
{
"lessThan": "5.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: validate individual TWT params before driver setup\n\nieee80211_process_rx_twt_action() only partially validates a received\nS1G TWT setup frame before queueing it.\n\nAn individual agreement can therefore reach ieee80211_s1g_rx_twt_setup()\nwith twt-\u003elength too short for the full struct ieee80211_twt_params.\n\nThe individual path passes twt to drv_add_twt_setup(). Both the tracepoint\nand the driver callback consume the complete parameters block, not merely\nreq_type. Do not pass a short individual agreement to the driver.\nBroadcast agreements remain unchanged because they are rejected locally\nafter accessing only req_type.\n\n[edit commit message to not overclaim lack of validation nor\n understate driver impact]"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - Malformed S1G TWT setup action frames reach mac80211 via normal WiFi RX (driver -\u003e ieee80211_rx_h_action -\u003e ieee80211_process_rx_twt_action -\u003e ieee80211_s1g_rx_twt_setup); an adjacent attacker within radio range sends crafted 802.11 management frames to a vulnerable AP.\nAC:L - The attacker fully controls the TWT element length and payload; ieee80211_process_rx_twt_action() only validates two bytes of req_type before queueing, so a short individual agreement reliably reaches drv_add_twt_setup() without races or victim-specific timing.\nPR:N - No Linux privileges on the victim AP are required; exploitation needs only normal 802.11 association as a WiFi client to an S1G AP with twt_responder enabled and a driver implementing add_twt_setup (e.g. MediaTek mt7915/mt7996).\nUI:N - No deliberate victim action is needed beyond operating an S1G AP that accepts associated stations; the attacker directly injects the malformed TWT setup frame and mac80211 processes it automatically on receive.\nS:U - Impact is kernel/driver heap memory corruption on the AP host within the same security authority; it does not cross VM, IOMMU, or sandbox boundaries (standard kernel compromise scope).\nC:H - drv_add_twt_setup(), its tracepoint, and driver callbacks read the full ieee80211_twt_params (twt, min_twt_dur, mantissa, channel) beyond the validated skb bounds, causing out-of-bounds reads of adjacent skb/heap memory that can disclose kernel data.\nI:H - MediaTek add_twt_setup() handlers write twt_agrt fields (req_type, min_twt_dur, twt) past the undersized params block into skb tail/heap memory, providing out-of-bounds write primitives exploitable for further memory corruption or code execution.\nA:H - Out-of-bounds access in mac80211/driver TWT setup can kernel-oops the AP or hang/crash WiFi firmware when corrupted parameters are programmed into hardware TWT state from attacker-controlled short frames."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-29T06:22:38.281Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/92fcd0f30dc8e51f252589b082d46851d295cc1a"
},
{
"url": "https://git.kernel.org/stable/c/09d60d1f72e6598241490eb6c4e97245af895c09"
},
{
"url": "https://git.kernel.org/stable/c/ff558072d199c1d641d1561da622e67f780514de"
},
{
"url": "https://git.kernel.org/stable/c/ade9e2f0f7f4d3089600ac2af8ef0b91746f923b"
},
{
"url": "https://git.kernel.org/stable/c/b558e07708d886acfcf4b0391ed7a8546e81d326"
},
{
"url": "https://git.kernel.org/stable/c/47fb04c3826e1f90271d405523043d6708b9072a"
},
{
"url": "https://git.kernel.org/stable/c/0502d5077e419427d80f4d46ba95d0067f5fb916"
}
],
"title": "wifi: mac80211: validate individual TWT params before driver setup",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80722",
"datePublished": "2026-08-28T06:53:17.886Z",
"dateReserved": "2026-08-26T14:34:25.788Z",
"dateUpdated": "2026-08-29T06:22:38.281Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74669 (GCVE-0-2026-74669)
Vulnerability from cvelistv5
Published
2026-08-22 15:32
Modified
2026-08-25 05:41
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ipvs: clear IPv4 options after rebasing tunnel ICMP errors
ip_vs_in_icmp() rebases an skb from the outer ICMP packet to the
quoted original request before passing it to icmp_send(). However,
IPCB(skb)->opt still describes the outer IPv4 header.
A timestamp option in the outer header can therefore leave an offset
that points into the quoted transport header after the rebase.
__ip_options_echo() treats a byte at that stale location as the option
length and copies it into the fixed-size option storage on the
__icmp_send() stack, causing a stack out-of-bounds write.
Clear the stale option metadata after resetting the network header.
Keep the remaining control block fields, including the ingress
interface used by the ICMP response path.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e Version: f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e Version: f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e Version: f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e Version: f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e Version: f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e Version: f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e Version: f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/netfilter/ipvs/ip_vs_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "79ffa99202c944467e28b13b513bf2998732edff",
"status": "affected",
"version": "f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e",
"versionType": "git"
},
{
"lessThan": "c9413b50204738fbc429bb86bf01353c393a6c28",
"status": "affected",
"version": "f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e",
"versionType": "git"
},
{
"lessThan": "37c61b3745129cbd682c557b51345828120972e5",
"status": "affected",
"version": "f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e",
"versionType": "git"
},
{
"lessThan": "ed246dd85ebf27c1f6b7897834d40786c0ca3006",
"status": "affected",
"version": "f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e",
"versionType": "git"
},
{
"lessThan": "6f46fc460e9316062bdcdf89199eb5d7a33da33b",
"status": "affected",
"version": "f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e",
"versionType": "git"
},
{
"lessThan": "75eec935444db4af2123e0491936f6e273d7ea00",
"status": "affected",
"version": "f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e",
"versionType": "git"
},
{
"lessThan": "384b4dae14277d369221d187e9b3af56c79d2e50",
"status": "affected",
"version": "f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e",
"versionType": "git"
},
{
"lessThan": "e0ba936287dfe9783426aac27e5fd76fe35b38c9",
"status": "affected",
"version": "f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/netfilter/ipvs/ip_vs_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.7"
},
{
"lessThan": "3.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "3.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "3.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "3.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "3.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nipvs: clear IPv4 options after rebasing tunnel ICMP errors\n\nip_vs_in_icmp() rebases an skb from the outer ICMP packet to the\nquoted original request before passing it to icmp_send(). However,\nIPCB(skb)-\u003eopt still describes the outer IPv4 header.\n\nA timestamp option in the outer header can therefore leave an offset\nthat points into the quoted transport header after the rebase.\n__ip_options_echo() treats a byte at that stale location as the option\nlength and copies it into the fixed-size option storage on the\n__icmp_send() stack, causing a stack out-of-bounds write.\n\nClear the stale option metadata after resetting the network header.\nKeep the remaining control block fields, including the ingress\ninterface used by the ICMP response path."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug is hit when a remote peer sends a crafted ICMP error to an IPVS load balancer; processing occurs in the IPv4 LOCAL_IN/FORWARD netfilter path on received network packets before icmp_send().\nAC:L - An attacker can reliably trigger the path by opening IPVS tunnel traffic, then sending an ICMP error whose outer IPv4 header includes a timestamp option and whose quoted payload aligns bytes at the stale option offset to a large length.\nPR:N - Exploitation requires only the ability to send IPv4/ICMP to the target; the remote attacker needs no local account, capability, or authentication on the victim host.\nUI:N - No victim user action is required beyond normal exposure of an IPVS tunnel load balancer to the network; exploitation is driven entirely by attacker-sent packets.\nS:U - Impact is confined to kernel memory/stack corruption and privilege boundaries within the host kernel; it does not cross into another security authority such as a VM guest or separate sandbox domain.\nC:H - The stale IPCB option metadata drives __ip_options_echo() to memcpy() from attacker-influenced skb bytes into a 40-byte stack buffer, enabling out-of-bounds kernel memory access that can disclose stack/kernel data.\nI:H - The stack out-of-bounds write in __icmp_send() is attacker-controlled in length and content via crafted quoted headers, providing a standard memory-corruption primitive that can corrupt return addresses and enable arbitrary kernel code execution.\nA:H - Corrupting the __icmp_send() stack frame can immediately panic or oops the kernel during ICMP processing, causing complete loss of availability on the load balancer."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:41:24.114Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/79ffa99202c944467e28b13b513bf2998732edff"
},
{
"url": "https://git.kernel.org/stable/c/c9413b50204738fbc429bb86bf01353c393a6c28"
},
{
"url": "https://git.kernel.org/stable/c/37c61b3745129cbd682c557b51345828120972e5"
},
{
"url": "https://git.kernel.org/stable/c/ed246dd85ebf27c1f6b7897834d40786c0ca3006"
},
{
"url": "https://git.kernel.org/stable/c/6f46fc460e9316062bdcdf89199eb5d7a33da33b"
},
{
"url": "https://git.kernel.org/stable/c/75eec935444db4af2123e0491936f6e273d7ea00"
},
{
"url": "https://git.kernel.org/stable/c/384b4dae14277d369221d187e9b3af56c79d2e50"
},
{
"url": "https://git.kernel.org/stable/c/e0ba936287dfe9783426aac27e5fd76fe35b38c9"
}
],
"title": "ipvs: clear IPv4 options after rebasing tunnel ICMP errors",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74669",
"datePublished": "2026-08-22T15:32:40.221Z",
"dateReserved": "2026-08-15T05:44:03.924Z",
"dateUpdated": "2026-08-25T05:41:24.114Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80550 (GCVE-0-2026-80550)
Vulnerability from cvelistv5
Published
2026-08-26 14:37
Modified
2026-08-27 05:01
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
s390/vfio_ccw: Fix out of bounds check on CCW array
The routine ccwchain_calc_length() counts the number of channel
command words (CCWs) that are chained together in a single channel
program, and rejects anything larger than CCWCHAIN_LEN_MAX (256) CCWs.
The loop itself is "do..while (count < 257)", and while the logic in
is_cpa_within_range() correctly adjusts between the 0-index array of
CCWs and the count of CCWs starting at 1, this means it would look
at a possible 257th CCW before ending the loop and (correctly)
returning an error.
Fix this by restructuring the loop to break as soon as 256 CCWs
(thus indexes 0-255) are examined, without looking at memory
outside the range.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 0a19e61e6d4c6192077ead760ba0a2d350987d4c Version: 0a19e61e6d4c6192077ead760ba0a2d350987d4c Version: 0a19e61e6d4c6192077ead760ba0a2d350987d4c Version: 0a19e61e6d4c6192077ead760ba0a2d350987d4c Version: 0a19e61e6d4c6192077ead760ba0a2d350987d4c Version: 0a19e61e6d4c6192077ead760ba0a2d350987d4c Version: 0a19e61e6d4c6192077ead760ba0a2d350987d4c Version: 0a19e61e6d4c6192077ead760ba0a2d350987d4c |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/s390/cio/vfio_ccw_cp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "0282fb1c4b638eecfe2cc558092c460911d8f7e2",
"status": "affected",
"version": "0a19e61e6d4c6192077ead760ba0a2d350987d4c",
"versionType": "git"
},
{
"lessThan": "907adc667d902fafbdb2d740d57b55bd025dc4cd",
"status": "affected",
"version": "0a19e61e6d4c6192077ead760ba0a2d350987d4c",
"versionType": "git"
},
{
"lessThan": "f20be33d093ce7630c17ff7ed93caf7eaf8ac1a3",
"status": "affected",
"version": "0a19e61e6d4c6192077ead760ba0a2d350987d4c",
"versionType": "git"
},
{
"lessThan": "af3f80ca4c8b17f20f9e588def076288fdb49e65",
"status": "affected",
"version": "0a19e61e6d4c6192077ead760ba0a2d350987d4c",
"versionType": "git"
},
{
"lessThan": "499a8a66b1598bfab97182aed15e0f1646074a3d",
"status": "affected",
"version": "0a19e61e6d4c6192077ead760ba0a2d350987d4c",
"versionType": "git"
},
{
"lessThan": "4c2e1d359d7a2b82cdf3254e4e480af9417f99fb",
"status": "affected",
"version": "0a19e61e6d4c6192077ead760ba0a2d350987d4c",
"versionType": "git"
},
{
"lessThan": "d5d096cd9369e986d4e5153baa86b8b35c283e09",
"status": "affected",
"version": "0a19e61e6d4c6192077ead760ba0a2d350987d4c",
"versionType": "git"
},
{
"lessThan": "a005b7f1a491ffda61bff0fd0f6548f8986fb977",
"status": "affected",
"version": "0a19e61e6d4c6192077ead760ba0a2d350987d4c",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/s390/cio/vfio_ccw_cp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.12"
},
{
"lessThan": "4.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.46",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.10",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/vfio_ccw: Fix out of bounds check on CCW array\n\nThe routine ccwchain_calc_length() counts the number of channel\ncommand words (CCWs) that are chained together in a single channel\nprogram, and rejects anything larger than CCWCHAIN_LEN_MAX (256) CCWs.\n\nThe loop itself is \"do..while (count \u003c 257)\", and while the logic in\nis_cpa_within_range() correctly adjusts between the 0-index array of\nCCWs and the count of CCWs starting at 1, this means it would look\nat a possible 257th CCW before ending the loop and (correctly)\nreturning an error.\n\nFix this by restructuring the loop to break as soon as 256 CCWs\n(thus indexes 0-255) are examined, without looking at memory\noutside the range."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.9,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached only via local VFIO-ccw mediated-device write() on the I/O region (guest channel program relayed by QEMU into fsm_io_request\u2192cp_init\u2192ccwchain_calc_length); vfio-ccw has no network, adjacent-radio, or physical-bus entry point.\nAC:L - An attacker fully controls guest channel program content and can reliably submit 256 command-chained CCWs so ccwchain_calc_length() reaches the 257th iteration; no race, special timing, or uncontrollable heap layout is required beyond crafting the CCW chain.\nPR:N - A malicious KVM guest with an assigned vfio-ccw mediated subchannel needs no host credentials or capabilities; it triggers the bug by issuing normal guest I/O that QEMU forwards through VFIO, without init-namespace root or admin setup privileges at exploit time.\nUI:N - Exploitation requires only the attacker\u0027s own channel program submission through VFIO passthrough I/O once the device is assigned; no separate victim mount, click, or other user action is needed.\nS:C - Guest-supplied channel programs are parsed in the host kernel cp_init() path during vfio-ccw device passthrough on IBM Z/LinuxONE, so the out-of-bounds read crosses the guest-to-host VFIO virtualization boundary and can compromise hypervisor memory outside the VM security scope.\nC:H - ccwchain_calc_length() reads one struct ccw1 (8 bytes) past the 256-element guest_cp kmalloc buffer when all CCWs are chained, constituting a kernel heap out-of-bounds read of adjacent slab memory that per kernel guidance enables information disclosure primitives.\nI:N - The vulnerability is a single out-of-bounds read used only for chain/TIC validation before returning -EINVAL; it performs no out-of-bounds write and does not modify host or guest data, channel program state, or kernel control structures on the error path.\nA:L - The out-of-bounds read typically does not crash production kernels because the access stays within the same kmalloc slab page, but KASAN-instrumented or hardened builds can detect it and fault; availability impact is limited rather than a reliable host panic."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T05:01:38.029Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/0282fb1c4b638eecfe2cc558092c460911d8f7e2"
},
{
"url": "https://git.kernel.org/stable/c/907adc667d902fafbdb2d740d57b55bd025dc4cd"
},
{
"url": "https://git.kernel.org/stable/c/f20be33d093ce7630c17ff7ed93caf7eaf8ac1a3"
},
{
"url": "https://git.kernel.org/stable/c/af3f80ca4c8b17f20f9e588def076288fdb49e65"
},
{
"url": "https://git.kernel.org/stable/c/499a8a66b1598bfab97182aed15e0f1646074a3d"
},
{
"url": "https://git.kernel.org/stable/c/4c2e1d359d7a2b82cdf3254e4e480af9417f99fb"
},
{
"url": "https://git.kernel.org/stable/c/d5d096cd9369e986d4e5153baa86b8b35c283e09"
},
{
"url": "https://git.kernel.org/stable/c/a005b7f1a491ffda61bff0fd0f6548f8986fb977"
}
],
"title": "s390/vfio_ccw: Fix out of bounds check on CCW array",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80550",
"datePublished": "2026-08-26T14:37:19.956Z",
"dateReserved": "2026-08-26T14:34:25.766Z",
"dateUpdated": "2026-08-27T05:01:38.029Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80552 (GCVE-0-2026-80552)
Vulnerability from cvelistv5
Published
2026-08-26 14:37
Modified
2026-08-27 12:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
s390/vfio_ccw: Ensure index for read/write regions are within range
The introduction of the capability chain rightly clamped the
region indexes to the range of the capabilities itself, but
neglected to do so for the existing read/write regions which
should also be enforced.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: db8e5d17ac03a65e2e0ee0ba50bf61a99741d871 Version: db8e5d17ac03a65e2e0ee0ba50bf61a99741d871 Version: db8e5d17ac03a65e2e0ee0ba50bf61a99741d871 Version: db8e5d17ac03a65e2e0ee0ba50bf61a99741d871 Version: db8e5d17ac03a65e2e0ee0ba50bf61a99741d871 Version: db8e5d17ac03a65e2e0ee0ba50bf61a99741d871 Version: db8e5d17ac03a65e2e0ee0ba50bf61a99741d871 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/s390/cio/vfio_ccw_async.c",
"drivers/s390/cio/vfio_ccw_chp.c",
"drivers/s390/cio/vfio_ccw_ops.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "3acbedf5c0b8e0971f0de423c05cc02bbf6ddb99",
"status": "affected",
"version": "db8e5d17ac03a65e2e0ee0ba50bf61a99741d871",
"versionType": "git"
},
{
"lessThan": "d3b1e38404b22df5a1f93019f2bb656feaad5ae3",
"status": "affected",
"version": "db8e5d17ac03a65e2e0ee0ba50bf61a99741d871",
"versionType": "git"
},
{
"lessThan": "79ea5e0c4c8a9842ae85f45062d947b3297dfc07",
"status": "affected",
"version": "db8e5d17ac03a65e2e0ee0ba50bf61a99741d871",
"versionType": "git"
},
{
"lessThan": "d597fa1273802941c7801202135976fecc29672b",
"status": "affected",
"version": "db8e5d17ac03a65e2e0ee0ba50bf61a99741d871",
"versionType": "git"
},
{
"lessThan": "649badf3a2fd8929e40198603a2cb21b74c21700",
"status": "affected",
"version": "db8e5d17ac03a65e2e0ee0ba50bf61a99741d871",
"versionType": "git"
},
{
"lessThan": "988d9b5be3c2c4baf9457ce8e11b477e13eb9fcf",
"status": "affected",
"version": "db8e5d17ac03a65e2e0ee0ba50bf61a99741d871",
"versionType": "git"
},
{
"lessThan": "9f5f9a78fedc45bc29d6a0a64e3a3472361afae5",
"status": "affected",
"version": "db8e5d17ac03a65e2e0ee0ba50bf61a99741d871",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/s390/cio/vfio_ccw_async.c",
"drivers/s390/cio/vfio_ccw_chp.c",
"drivers/s390/cio/vfio_ccw_ops.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.2"
},
{
"lessThan": "5.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.218",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.218",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.46",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.10",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/vfio_ccw: Ensure index for read/write regions are within range\n\nThe introduction of the capability chain rightly clamped the\nregion indexes to the range of the capabilities itself, but\nneglected to do so for the existing read/write regions which\nshould also be enforced."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The flaw is reached only via local VFIO mediated-device syscalls (read/write on a vfio-ccw device fd and VFIO_DEVICE_GET_REGION_INFO ioctl); vfio-ccw has no network, Bluetooth, or physical-bus entry point.\nAC:L - An attacker with an open vfio-ccw fd can deterministically supply crafted file offsets encoding out-of-range region indexes to read/write/ioctl handlers, or race close/teardown against region access, without depending on uncontrollable kernel layout or rare timing.\nPR:L - Exploitation requires an opened vfio-ccw mdev device fd (typical QEMU/libvirt VM operator or delegated /dev/vfio holder on IBM Z passthrough); mdev creation is admin setup, but triggering the OOB paths needs only that delegated VFIO client, not init-namespace root.\nUI:N - No separate victim action is required beyond the attacker (or their QEMU process) issuing crafted VFIO read/write/ioctl calls on an already-assigned passthrough device; no mount, click, or other user cooperation is needed at trigger time.\nS:C - On IBM Z/LinuxONE, vfio-ccw exists to pass DASD/CCW subchannels into KVM guests; OOB region indexing in host read/write/ioctl corrupts hypervisor kernel memory outside the guest VM security boundary, enabling cross-tenant host compromise.\nC:H - Missing bounds checks and array_index_nospec on region[i] let out-of-range indexes make copy_to_user read from adjacent kernel heap/metadata beyond the region array, providing arbitrary kernel memory disclosure primitives.\nI:H - Out-of-range region indexes route copy_from_user writes to wrong kernel objects (cmd_region, schib_region, crw_region, or adjacent heap), enabling heap corruption and exploitable arbitrary kernel write or control-flow hijack.\nA:H - Out-of-bounds access to freed or invalid region metadata during concurrent device close, or corrupting vfio_ccw_private adjacent structures, can immediately oops or panic the host kernel."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T12:40:12.535Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/3acbedf5c0b8e0971f0de423c05cc02bbf6ddb99"
},
{
"url": "https://git.kernel.org/stable/c/d3b1e38404b22df5a1f93019f2bb656feaad5ae3"
},
{
"url": "https://git.kernel.org/stable/c/79ea5e0c4c8a9842ae85f45062d947b3297dfc07"
},
{
"url": "https://git.kernel.org/stable/c/d597fa1273802941c7801202135976fecc29672b"
},
{
"url": "https://git.kernel.org/stable/c/649badf3a2fd8929e40198603a2cb21b74c21700"
},
{
"url": "https://git.kernel.org/stable/c/988d9b5be3c2c4baf9457ce8e11b477e13eb9fcf"
},
{
"url": "https://git.kernel.org/stable/c/9f5f9a78fedc45bc29d6a0a64e3a3472361afae5"
}
],
"title": "s390/vfio_ccw: Ensure index for read/write regions are within range",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80552",
"datePublished": "2026-08-26T14:37:21.178Z",
"dateReserved": "2026-08-26T14:34:25.766Z",
"dateUpdated": "2026-08-27T12:40:12.535Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68156 (GCVE-0-2026-68156)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
libceph: refresh auth->authorizer_buf{,_len} after authorizer update
ceph_x_create_authorizer() caches au->buf->vec.iov_base and
au->buf->vec.iov_len in struct ceph_auth_handshake. These
cached values are then used by the messenger connect code when
sending the authorizer.
ceph_x_update_authorizer() can rebuild the authorizer when a newer
service ticket is available. If the rebuilt authorizer no longer
fits in the existing buffer, ceph_x_build_authorizer() drops its
reference to au->buf and allocates a new one. If this is the final
reference, ceph_buffer_put() frees the old ceph_buffer and its
vec.iov_base, but auth->authorizer_buf still points at that freed
memory.
A subsequent msgr1 reconnect can therefore queue the stale pointer
and trigger a KASAN slab-use-after-free in _copy_from_iter() while
tcp_sendmsg() copies the authorizer.
Refresh auth->authorizer_buf and auth->authorizer_buf_len after a
successful authorizer rebuild so the messenger sends the current
buffer.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 0bed9b5c523d577378b6f83eab5835fe30c27208 Version: 0bed9b5c523d577378b6f83eab5835fe30c27208 Version: 0bed9b5c523d577378b6f83eab5835fe30c27208 Version: 0bed9b5c523d577378b6f83eab5835fe30c27208 Version: 0bed9b5c523d577378b6f83eab5835fe30c27208 Version: 0bed9b5c523d577378b6f83eab5835fe30c27208 Version: 0bed9b5c523d577378b6f83eab5835fe30c27208 Version: 0bed9b5c523d577378b6f83eab5835fe30c27208 Version: 29c65a277a64645af853e8c9a9b3dda0ddc421e0 Version: d2c7223497cf8228416c70e3f4238ddd6c5bdf3c Version: 3.4.50 ≤ Version: 3.9.7 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ceph/auth_x.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "2334e9997308305ee4fd508fdfe6086c4150ed60",
"status": "affected",
"version": "0bed9b5c523d577378b6f83eab5835fe30c27208",
"versionType": "git"
},
{
"lessThan": "79a273df64238a4ade8b709689a78589f755b8ef",
"status": "affected",
"version": "0bed9b5c523d577378b6f83eab5835fe30c27208",
"versionType": "git"
},
{
"lessThan": "26f814187abceee90dbb29a02133adb4786fbb13",
"status": "affected",
"version": "0bed9b5c523d577378b6f83eab5835fe30c27208",
"versionType": "git"
},
{
"lessThan": "9d37aec9ffe4e743dabc3f84502e9723e17a30d4",
"status": "affected",
"version": "0bed9b5c523d577378b6f83eab5835fe30c27208",
"versionType": "git"
},
{
"lessThan": "75e82e8944ac1efe9fdb88bd2f14d9a031282bdf",
"status": "affected",
"version": "0bed9b5c523d577378b6f83eab5835fe30c27208",
"versionType": "git"
},
{
"lessThan": "0060ec912292a550198d8d18ac95b433c92a7091",
"status": "affected",
"version": "0bed9b5c523d577378b6f83eab5835fe30c27208",
"versionType": "git"
},
{
"lessThan": "5ecfcd5c05866f185357700b81b461dae4f5ebb2",
"status": "affected",
"version": "0bed9b5c523d577378b6f83eab5835fe30c27208",
"versionType": "git"
},
{
"lessThan": "937d61f86d377a3aa578adae7a3dfcecdddf9d89",
"status": "affected",
"version": "0bed9b5c523d577378b6f83eab5835fe30c27208",
"versionType": "git"
},
{
"status": "affected",
"version": "29c65a277a64645af853e8c9a9b3dda0ddc421e0",
"versionType": "git"
},
{
"status": "affected",
"version": "d2c7223497cf8228416c70e3f4238ddd6c5bdf3c",
"versionType": "git"
},
{
"lessThan": "3.5",
"status": "affected",
"version": "3.4.50",
"versionType": "semver"
},
{
"lessThan": "3.10",
"status": "affected",
"version": "3.9.7",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ceph/auth_x.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.10"
},
{
"lessThan": "3.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.4.50",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.9.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: refresh auth-\u003eauthorizer_buf{,_len} after authorizer update\n\nceph_x_create_authorizer() caches au-\u003ebuf-\u003evec.iov_base and\nau-\u003ebuf-\u003evec.iov_len in struct ceph_auth_handshake. These\ncached values are then used by the messenger connect code when\nsending the authorizer.\n\nceph_x_update_authorizer() can rebuild the authorizer when a newer\nservice ticket is available. If the rebuilt authorizer no longer\nfits in the existing buffer, ceph_x_build_authorizer() drops its\nreference to au-\u003ebuf and allocates a new one. If this is the final\nreference, ceph_buffer_put() frees the old ceph_buffer and its\nvec.iov_base, but auth-\u003eauthorizer_buf still points at that freed\nmemory.\n\nA subsequent msgr1 reconnect can therefore queue the stale pointer\nand trigger a KASAN slab-use-after-free in _copy_from_iter() while\ntcp_sendmsg() copies the authorizer.\n\nRefresh auth-\u003eauthorizer_buf and auth-\u003eauthorizer_buf_len after a\nsuccessful authorizer rebuild so the messenger sends the current\nbuffer."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - A compromised or malicious Ceph monitor/OSD delivers rotated cephx service tickets over TCP that increase secret_id and can enlarge the authorizer; on subsequent msgr1 reconnect the stale authorizer_buf is copied in tcp_sendmsg, so the UAF is reachable from the network peer without local syscall access.\nAC:L - An attacker controlling the Ceph cluster can deterministically issue a larger rotated ticket to force ceph_buffer realloc in ceph_x_update_authorizer, then trigger an msgr1 OSD/MDS/MON reconnect; no victim-specific memory layout or uncontrollable race is required.\nPR:N - Exploitation requires no privileges on the victim host; any kernel Ceph/RBD/CephFS client already connected to an attacker-controlled or compromised cluster is sufficient, matching other libceph client CVEs where the remote peer drives the bug.\nUI:N - After initial Ceph client setup, service-ticket rotation and messenger reconnects occur automatically; no further interactive user action is needed to reach the stale-buffer send path.\nS:U - The slab UAF corrupts kernel heap memory on the Ceph client host for local privilege escalation or crash, but does not cross VM, IOMMU, or container sandbox boundaries to another security authority.\nC:H - KASAN-confirmed slab use-after-free in _copy_from_iter during authorizer transmission reads freed kmalloc memory, which can disclose adjacent kernel pointers and is classed as exploitable arbitrary read per kernel UAF guidance.\nI:H - Freed authorizer buffers can be reclaimed with attacker-controlled data before reconnect, enabling heap corruption and control-flow hijack during the stale-pointer copy, consistent with kernel UAF write primitive scoring.\nA:H - The reported KASAN slab-use-after-free in tcp_sendmsg while copying the authorizer reliably causes kernel oops or panic on Ceph client reconnect, and remains repeatable whenever tickets are rotated and msgr1 reconnects."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:30:25.089Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/2334e9997308305ee4fd508fdfe6086c4150ed60"
},
{
"url": "https://git.kernel.org/stable/c/79a273df64238a4ade8b709689a78589f755b8ef"
},
{
"url": "https://git.kernel.org/stable/c/26f814187abceee90dbb29a02133adb4786fbb13"
},
{
"url": "https://git.kernel.org/stable/c/9d37aec9ffe4e743dabc3f84502e9723e17a30d4"
},
{
"url": "https://git.kernel.org/stable/c/75e82e8944ac1efe9fdb88bd2f14d9a031282bdf"
},
{
"url": "https://git.kernel.org/stable/c/0060ec912292a550198d8d18ac95b433c92a7091"
},
{
"url": "https://git.kernel.org/stable/c/5ecfcd5c05866f185357700b81b461dae4f5ebb2"
},
{
"url": "https://git.kernel.org/stable/c/937d61f86d377a3aa578adae7a3dfcecdddf9d89"
}
],
"title": "libceph: refresh auth-\u003eauthorizer_buf{,_len} after authorizer update",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68156",
"datePublished": "2026-08-10T11:59:22.514Z",
"dateReserved": "2026-07-30T09:28:09.371Z",
"dateUpdated": "2026-08-19T16:30:25.089Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68350 (GCVE-0-2026-68350)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: carl9170: fix OOB read from off-by-two in TX status handler
The bounds check in carl9170_tx_process_status() uses
`i > ((cmd->hdr.len / 2) + 1)` which is off by two, allowing
2 extra iterations past valid _tx_status entries when the firmware-
controlled hdr.ext exceeds hdr.len/2. Fix by using the correct
comparison `i >= (cmd->hdr.len / 2)`.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c Version: a84fab3cbfdc427e7d366f1cc844f27b2084c26c |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/ath/carl9170/tx.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "9bf8d8510b7bed20320dead0f8cdcf8e610ec8db",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "2c030c20f112bd8f6aa59d09501835605f01bf9d",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "73462e8e602047a03e538d971a79ad67a4ba9a5d",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "7ed0dce8613c92111d2a3836ced2ab03190ba20e",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "e8a862a3da457ddc50633c346dc645d559da09ae",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "fab6ff91d5b8c4af62e2ced42fb357fa3eb9fd59",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "423c836f934814b8fdbe53b24a79d021a0ee8454",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
},
{
"lessThan": "a3f42f1049ad80c65560d2b078ad426c3134f78d",
"status": "affected",
"version": "a84fab3cbfdc427e7d366f1cc844f27b2084c26c",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/ath/carl9170/tx.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.37"
},
{
"lessThan": "2.6.37",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.37",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: carl9170: fix OOB read from off-by-two in TX status handler\n\nThe bounds check in carl9170_tx_process_status() uses\n`i \u003e ((cmd-\u003ehdr.len / 2) + 1)` which is off by two, allowing\n2 extra iterations past valid _tx_status entries when the firmware-\ncontrolled hdr.ext exceeds hdr.len/2. Fix by using the correct\ncomparison `i \u003e= (cmd-\u003ehdr.len / 2)`."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:50.606Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/9bf8d8510b7bed20320dead0f8cdcf8e610ec8db"
},
{
"url": "https://git.kernel.org/stable/c/2c030c20f112bd8f6aa59d09501835605f01bf9d"
},
{
"url": "https://git.kernel.org/stable/c/73462e8e602047a03e538d971a79ad67a4ba9a5d"
},
{
"url": "https://git.kernel.org/stable/c/7ed0dce8613c92111d2a3836ced2ab03190ba20e"
},
{
"url": "https://git.kernel.org/stable/c/e8a862a3da457ddc50633c346dc645d559da09ae"
},
{
"url": "https://git.kernel.org/stable/c/fab6ff91d5b8c4af62e2ced42fb357fa3eb9fd59"
},
{
"url": "https://git.kernel.org/stable/c/423c836f934814b8fdbe53b24a79d021a0ee8454"
},
{
"url": "https://git.kernel.org/stable/c/a3f42f1049ad80c65560d2b078ad426c3134f78d"
}
],
"title": "wifi: carl9170: fix OOB read from off-by-two in TX status handler",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68350",
"datePublished": "2026-08-10T12:03:27.314Z",
"dateReserved": "2026-07-30T09:28:09.384Z",
"dateUpdated": "2026-08-19T16:33:50.606Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68158 (GCVE-0-2026-68158)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
libceph: Fix multiplication overflow in decode_new_up_state_weight()
If a message of type CEPH_MSG_OSD_MAP contains a (maliciously) corrupted
osdmap, out-of-bounds memory accesses may occur in
decode_new_up_state_weight(). This happens because the bounds check for
the new_state part is based on calculating its length depending on a len
value read from the incoming message. This calculation may overflow
leading to an incorrect bounds check. Subsequently, out-of-bounds reads
may occur when decoding this part.
This patch switches the multiplication to use check_mul_overflow() to
abort processing the osdmap if an overflow occurred. Therefore,
osdmaps/messages containing large values for len that result in a
multiplication overflow are treated as invalid.
[ idryomov: rename new_state_len -> new_state_item_size, formatting ]
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 930c532869774ebf8af9efe9484c597f896a7d46 Version: 930c532869774ebf8af9efe9484c597f896a7d46 Version: 930c532869774ebf8af9efe9484c597f896a7d46 Version: 930c532869774ebf8af9efe9484c597f896a7d46 Version: 930c532869774ebf8af9efe9484c597f896a7d46 Version: 930c532869774ebf8af9efe9484c597f896a7d46 Version: 930c532869774ebf8af9efe9484c597f896a7d46 Version: 930c532869774ebf8af9efe9484c597f896a7d46 Version: 1196c36fd53c3b1615eb02f986cb727b1dfc1047 Version: bbc3aa6b0e6050b2b2e04a08dd4d6423d576b196 Version: 6b96b2d473701b45df3fea8dd9796b6ec39e6d54 Version: 7405d73cea0d0e6c541f5c534078feeb46188844 Version: 8777c9f654637d56f4c4ca54eb1bc7c609b70085 Version: 6831c98ce0b8a3e88db64aa224372effd0dcc694 Version: 032951d32c13b7564dfba82758260cb7aa1149d2 Version: 14877928f10667a5606383885d004f7185f33718 Version: 3.10.103 ≤ Version: 3.12.63 ≤ Version: 3.14.75 ≤ Version: 3.16.39 ≤ Version: 3.18.39 ≤ Version: 4.1.30 ≤ Version: 4.4.17 ≤ Version: 4.6.6 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ceph/osdmap.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "2ceee3b77b83052648c40fef965f836fd7699d26",
"status": "affected",
"version": "930c532869774ebf8af9efe9484c597f896a7d46",
"versionType": "git"
},
{
"lessThan": "e4473751cc37db41f3f7da25d64a23e0c74570f1",
"status": "affected",
"version": "930c532869774ebf8af9efe9484c597f896a7d46",
"versionType": "git"
},
{
"lessThan": "f6961070c326bd158c38fa48756cde2bd78c4aaa",
"status": "affected",
"version": "930c532869774ebf8af9efe9484c597f896a7d46",
"versionType": "git"
},
{
"lessThan": "05c90e059269f087becfcce23348496085835c29",
"status": "affected",
"version": "930c532869774ebf8af9efe9484c597f896a7d46",
"versionType": "git"
},
{
"lessThan": "143ba49ead77ec483c0326f8aaad8649874e99c4",
"status": "affected",
"version": "930c532869774ebf8af9efe9484c597f896a7d46",
"versionType": "git"
},
{
"lessThan": "1732d89dfcd74f6fde9ce70900d316c4a151c153",
"status": "affected",
"version": "930c532869774ebf8af9efe9484c597f896a7d46",
"versionType": "git"
},
{
"lessThan": "bee4b5b53e7bff0467fd916cc44c9b190733c6bd",
"status": "affected",
"version": "930c532869774ebf8af9efe9484c597f896a7d46",
"versionType": "git"
},
{
"lessThan": "98917a499ec7064c14fc56d180a4fd636fc2784c",
"status": "affected",
"version": "930c532869774ebf8af9efe9484c597f896a7d46",
"versionType": "git"
},
{
"status": "affected",
"version": "1196c36fd53c3b1615eb02f986cb727b1dfc1047",
"versionType": "git"
},
{
"status": "affected",
"version": "bbc3aa6b0e6050b2b2e04a08dd4d6423d576b196",
"versionType": "git"
},
{
"status": "affected",
"version": "6b96b2d473701b45df3fea8dd9796b6ec39e6d54",
"versionType": "git"
},
{
"status": "affected",
"version": "7405d73cea0d0e6c541f5c534078feeb46188844",
"versionType": "git"
},
{
"status": "affected",
"version": "8777c9f654637d56f4c4ca54eb1bc7c609b70085",
"versionType": "git"
},
{
"status": "affected",
"version": "6831c98ce0b8a3e88db64aa224372effd0dcc694",
"versionType": "git"
},
{
"status": "affected",
"version": "032951d32c13b7564dfba82758260cb7aa1149d2",
"versionType": "git"
},
{
"status": "affected",
"version": "14877928f10667a5606383885d004f7185f33718",
"versionType": "git"
},
{
"lessThan": "3.11",
"status": "affected",
"version": "3.10.103",
"versionType": "semver"
},
{
"lessThan": "3.13",
"status": "affected",
"version": "3.12.63",
"versionType": "semver"
},
{
"lessThan": "3.15",
"status": "affected",
"version": "3.14.75",
"versionType": "semver"
},
{
"lessThan": "3.17",
"status": "affected",
"version": "3.16.39",
"versionType": "semver"
},
{
"lessThan": "3.19",
"status": "affected",
"version": "3.18.39",
"versionType": "semver"
},
{
"lessThan": "4.2",
"status": "affected",
"version": "4.1.30",
"versionType": "semver"
},
{
"lessThan": "4.5",
"status": "affected",
"version": "4.4.17",
"versionType": "semver"
},
{
"lessThan": "4.7",
"status": "affected",
"version": "4.6.6",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ceph/osdmap.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.7"
},
{
"lessThan": "4.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.10.103",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.12.63",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.14.75",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.16.39",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.18.39",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.1.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.6.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: Fix multiplication overflow in decode_new_up_state_weight()\n\nIf a message of type CEPH_MSG_OSD_MAP contains a (maliciously) corrupted\nosdmap, out-of-bounds memory accesses may occur in\ndecode_new_up_state_weight(). This happens because the bounds check for\nthe new_state part is based on calculating its length depending on a len\nvalue read from the incoming message. This calculation may overflow\nleading to an incorrect bounds check. Subsequently, out-of-bounds reads\nmay occur when decoding this part.\n\nThis patch switches the multiplication to use check_mul_overflow() to\nabort processing the osdmap if an overflow occurred. Therefore,\nosdmaps/messages containing large values for len that result in a\nmultiplication overflow are treated as invalid.\n\n[ idryomov: rename new_state_len -\u003e new_state_item_size, formatting ]"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - Malformed incremental osdmap data is delivered in CEPH_MSG_OSD_MAP over TCP from a Ceph monitor (mon_dispatch) or OSD (osd_dispatch) to libceph clients (CephFS/RBD), and the overflow is triggered while decoding received network bytes in osdmap_apply_incremental().\nAC:L - A compromised or attacker-controlled monitor/OSD can publish an incremental osdmap with epoch N+1 and a crafted new_state length that wraps the multiply, reliably bypassing bounds checks without races or victim-specific memory layout.\nPR:N - Exploitation requires no privileges on the victim host; a malicious cluster peer or on-path attacker that can deliver forged osdmaps to an already-connected kernel Ceph client needs no local account, capabilities, or user-namespace tricks.\nUI:N - Once a host is a Ceph client, osdmap subscriptions and updates are applied automatically by the kernel; no additional mount, open, or interactive step is needed at exploit time beyond the existing client session.\nS:U - Impact is confined to kernel memory and libceph client state on the Ceph client host (info leak, map corruption, crash, or privilege escalation); it does not cross VM, IOMMU, or sandbox boundaries to another security authority.\nC:H - Integer-overflow bypass lets decode_new_up_state_weight() run bare ceph_decode_32/8 loops past the message end, performing out-of-bounds reads of adjacent kernel heap/slack memory that can disclose pointers and other sensitive data.\nI:H - Misaligned decoding also drives attacker-controlled osd/xorstate/weight values into map-\u003eosd_weight[], map-\u003eosd_state[], and map-\u003eosd_addr[] updates (including memset), corrupting kernel osdmap state in ways usable for further exploitation.\nA:H - Unbounded out-of-bounds reads while parsing osdmaps can fault on unmapped pages and trigger kernel oops/panic; map corruption can also cause persistent client failure, repeatable on each malicious incremental map."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:30:30.014Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/2ceee3b77b83052648c40fef965f836fd7699d26"
},
{
"url": "https://git.kernel.org/stable/c/e4473751cc37db41f3f7da25d64a23e0c74570f1"
},
{
"url": "https://git.kernel.org/stable/c/f6961070c326bd158c38fa48756cde2bd78c4aaa"
},
{
"url": "https://git.kernel.org/stable/c/05c90e059269f087becfcce23348496085835c29"
},
{
"url": "https://git.kernel.org/stable/c/143ba49ead77ec483c0326f8aaad8649874e99c4"
},
{
"url": "https://git.kernel.org/stable/c/1732d89dfcd74f6fde9ce70900d316c4a151c153"
},
{
"url": "https://git.kernel.org/stable/c/bee4b5b53e7bff0467fd916cc44c9b190733c6bd"
},
{
"url": "https://git.kernel.org/stable/c/98917a499ec7064c14fc56d180a4fd636fc2784c"
}
],
"title": "libceph: Fix multiplication overflow in decode_new_up_state_weight()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68158",
"datePublished": "2026-08-10T11:59:24.675Z",
"dateReserved": "2026-07-30T09:28:09.371Z",
"dateUpdated": "2026-08-19T16:30:30.014Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68157 (GCVE-0-2026-68157)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
libceph: guard missing CRUSH type name lookup
Localized read selection can walk a parent bucket whose name exists in
the CRUSH map while its type has no matching entry in type_names.
get_immediate_parent() then dereferences a NULL type_cn and passes an
invalid pointer into strcmp(), causing a null-ptr-deref.
Skip such malformed parent buckets unless both the bucket name and type
name metadata are present. This keeps malformed hierarchy data from
crashing locality lookup and safely falls back to "not local".
[ idryomov: add WARN_ON_ONCE ]
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 117d96a04f007ce8fc2e292369056c3bd09f6f63 Version: 117d96a04f007ce8fc2e292369056c3bd09f6f63 Version: 117d96a04f007ce8fc2e292369056c3bd09f6f63 Version: 117d96a04f007ce8fc2e292369056c3bd09f6f63 Version: 117d96a04f007ce8fc2e292369056c3bd09f6f63 Version: 117d96a04f007ce8fc2e292369056c3bd09f6f63 Version: 117d96a04f007ce8fc2e292369056c3bd09f6f63 Version: 117d96a04f007ce8fc2e292369056c3bd09f6f63 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ceph/osdmap.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "cbfcba275326c8c7dae9acd8f4a0d4c316fdafb0",
"status": "affected",
"version": "117d96a04f007ce8fc2e292369056c3bd09f6f63",
"versionType": "git"
},
{
"lessThan": "8ff579ac03d6e9d17d6d9c8443110167c14a382d",
"status": "affected",
"version": "117d96a04f007ce8fc2e292369056c3bd09f6f63",
"versionType": "git"
},
{
"lessThan": "6a4b75d90f0cfbf22c14742ab35a803bc13f36ec",
"status": "affected",
"version": "117d96a04f007ce8fc2e292369056c3bd09f6f63",
"versionType": "git"
},
{
"lessThan": "c46d82c47afc968d6ee8ef4470fa2dd35b765c21",
"status": "affected",
"version": "117d96a04f007ce8fc2e292369056c3bd09f6f63",
"versionType": "git"
},
{
"lessThan": "3767c9f0c1bbd98dd25cb088356a0fc6c1f09f50",
"status": "affected",
"version": "117d96a04f007ce8fc2e292369056c3bd09f6f63",
"versionType": "git"
},
{
"lessThan": "4716a64b7cc2797741f7be4e283ace78a9dff37d",
"status": "affected",
"version": "117d96a04f007ce8fc2e292369056c3bd09f6f63",
"versionType": "git"
},
{
"lessThan": "db9cc9fd9660b2d69ee66f5a4cbec83c21a1c64d",
"status": "affected",
"version": "117d96a04f007ce8fc2e292369056c3bd09f6f63",
"versionType": "git"
},
{
"lessThan": "bbeae12fda3384a90fbebc8a19ba9d33f85b5361",
"status": "affected",
"version": "117d96a04f007ce8fc2e292369056c3bd09f6f63",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ceph/osdmap.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.8"
},
{
"lessThan": "5.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: guard missing CRUSH type name lookup\n\nLocalized read selection can walk a parent bucket whose name exists in\nthe CRUSH map while its type has no matching entry in type_names.\nget_immediate_parent() then dereferences a NULL type_cn and passes an\ninvalid pointer into strcmp(), causing a null-ptr-deref.\n\nSkip such malformed parent buckets unless both the bucket name and type\nname metadata are present. This keeps malformed hierarchy data from\ncrashing locality lookup and safely falls back to \"not local\".\n\n[ idryomov: add WARN_ON_ONCE ]"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - Malformed CRUSH hierarchy data is delivered to the kernel Ceph client in CEPH_MSG_OSD_MAP over TCP from a monitor or OSD peer, stored in libceph, and later triggers get_immediate_parent() during localized-read target selection on RBD/CephFS client I/O.\nAC:L - A compromised or attacker-controlled Ceph monitor can publish an osdmap whose CRUSH buckets have names but missing type_names entries; once applied, the NULL dereference is reliably hit on subsequent localize-read calc_target() paths without further attacker-controlled timing.\nPR:N - Exploitation requires no privileges on the victim host; any machine acting as a kernel Ceph client that receives a forged osdmap from a cluster peer over the network can be attacked without local capabilities or user-namespace tricks.\nUI:N - No victim user action is needed at exploitation time beyond the host already being a Ceph client with localized reads enabled; forged osdmaps are applied automatically and the crash fires on subsequent kernel client read or map-rescan operations.\nS:U - Impact is confined to kernel memory on the Ceph client host (crash or potential escalation within that host); it does not cross VM, IOMMU, or sandbox boundaries to other security authorities.\nC:N - The failure is a NULL pointer dereference when accessing type_cn-\u003ecn_name; there is no out-of-bounds read, use-after-free, or other memory corruption that could disclose kernel data.\nI:N - The bug causes a NULL pointer dereference crash only; no attacker-controlled write, heap corruption, or control-flow hijack primitive is created by this defect.\nA:H - The NULL pointer dereference in get_immediate_parent() during CRUSH locality lookup causes a kernel oops or panic, denying all service on the affected Ceph client host."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:30:27.540Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/cbfcba275326c8c7dae9acd8f4a0d4c316fdafb0"
},
{
"url": "https://git.kernel.org/stable/c/8ff579ac03d6e9d17d6d9c8443110167c14a382d"
},
{
"url": "https://git.kernel.org/stable/c/6a4b75d90f0cfbf22c14742ab35a803bc13f36ec"
},
{
"url": "https://git.kernel.org/stable/c/c46d82c47afc968d6ee8ef4470fa2dd35b765c21"
},
{
"url": "https://git.kernel.org/stable/c/3767c9f0c1bbd98dd25cb088356a0fc6c1f09f50"
},
{
"url": "https://git.kernel.org/stable/c/4716a64b7cc2797741f7be4e283ace78a9dff37d"
},
{
"url": "https://git.kernel.org/stable/c/db9cc9fd9660b2d69ee66f5a4cbec83c21a1c64d"
},
{
"url": "https://git.kernel.org/stable/c/bbeae12fda3384a90fbebc8a19ba9d33f85b5361"
}
],
"title": "libceph: guard missing CRUSH type name lookup",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68157",
"datePublished": "2026-08-10T11:59:23.692Z",
"dateReserved": "2026-07-30T09:28:09.371Z",
"dateUpdated": "2026-08-19T16:30:27.540Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80812 (GCVE-0-2026-80812)
Vulnerability from cvelistv5
Published
2026-09-04 15:13
Modified
2026-09-07 14:21
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ALSA: dummy: Check card index validity at probe
snd_dummy_probe() blindly trusts that the given devptr->id value is
within the proper card index range. It's OK for the devices the
driver itself creates at the module probe time, but if the device is
bound manually via sysfs interface, this could be -1 as "none", and
this leads to OOB access for index[] and other parameters.
Add a sanity check for the card index and warn/correct it if it's a
value out of the range.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 6e65c1cc4458b2784224759b6137a50d4f65e610 Version: 6e65c1cc4458b2784224759b6137a50d4f65e610 Version: 6e65c1cc4458b2784224759b6137a50d4f65e610 Version: 6e65c1cc4458b2784224759b6137a50d4f65e610 Version: 6e65c1cc4458b2784224759b6137a50d4f65e610 Version: 6e65c1cc4458b2784224759b6137a50d4f65e610 Version: 6e65c1cc4458b2784224759b6137a50d4f65e610 Version: 6e65c1cc4458b2784224759b6137a50d4f65e610 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"sound/drivers/dummy.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b7579e86afcec932e169d10e2d603abed8dd2fdf",
"status": "affected",
"version": "6e65c1cc4458b2784224759b6137a50d4f65e610",
"versionType": "git"
},
{
"lessThan": "4d0892a90b57f0e89b274c3f3c51c2fa17937c88",
"status": "affected",
"version": "6e65c1cc4458b2784224759b6137a50d4f65e610",
"versionType": "git"
},
{
"lessThan": "b20eb7ecbdaa3e649023fe41b177d90983ffb487",
"status": "affected",
"version": "6e65c1cc4458b2784224759b6137a50d4f65e610",
"versionType": "git"
},
{
"lessThan": "c9f10a001c243d1f069ebb0e2f4999ad4043a254",
"status": "affected",
"version": "6e65c1cc4458b2784224759b6137a50d4f65e610",
"versionType": "git"
},
{
"lessThan": "f20c2c32ec1c5c3526f29a03b487c55a5890996c",
"status": "affected",
"version": "6e65c1cc4458b2784224759b6137a50d4f65e610",
"versionType": "git"
},
{
"lessThan": "3dba0e92e18980cb5a4d70a9a263539ae4f0c7ec",
"status": "affected",
"version": "6e65c1cc4458b2784224759b6137a50d4f65e610",
"versionType": "git"
},
{
"lessThan": "690b721b9595f9a43395fd4047a832c42b5b6078",
"status": "affected",
"version": "6e65c1cc4458b2784224759b6137a50d4f65e610",
"versionType": "git"
},
{
"lessThan": "02442d5fe8ee365a084b055d4fa81a0c1abfc3fd",
"status": "affected",
"version": "6e65c1cc4458b2784224759b6137a50d4f65e610",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"sound/drivers/dummy.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.16"
},
{
"lessThan": "2.6.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.218",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.185",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.154",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.106",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.47",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.1",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.218",
"versionStartIncluding": "2.6.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.185",
"versionStartIncluding": "2.6.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.154",
"versionStartIncluding": "2.6.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.106",
"versionStartIncluding": "2.6.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.47",
"versionStartIncluding": "2.6.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.11",
"versionStartIncluding": "2.6.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.1",
"versionStartIncluding": "2.6.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "2.6.16",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: dummy: Check card index validity at probe\n\nsnd_dummy_probe() blindly trusts that the given devptr-\u003eid value is\nwithin the proper card index range. It\u0027s OK for the devices the\ndriver itself creates at the module probe time, but if the device is\nbound manually via sysfs interface, this could be -1 as \"none\", and\nthis leads to OOB access for index[] and other parameters.\n\nAdd a sanity check for the card index and warn/correct it if it\u0027s a\nvalue out of the range."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-07T14:21:14.907Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b7579e86afcec932e169d10e2d603abed8dd2fdf"
},
{
"url": "https://git.kernel.org/stable/c/4d0892a90b57f0e89b274c3f3c51c2fa17937c88"
},
{
"url": "https://git.kernel.org/stable/c/b20eb7ecbdaa3e649023fe41b177d90983ffb487"
},
{
"url": "https://git.kernel.org/stable/c/c9f10a001c243d1f069ebb0e2f4999ad4043a254"
},
{
"url": "https://git.kernel.org/stable/c/f20c2c32ec1c5c3526f29a03b487c55a5890996c"
},
{
"url": "https://git.kernel.org/stable/c/3dba0e92e18980cb5a4d70a9a263539ae4f0c7ec"
},
{
"url": "https://git.kernel.org/stable/c/690b721b9595f9a43395fd4047a832c42b5b6078"
},
{
"url": "https://git.kernel.org/stable/c/02442d5fe8ee365a084b055d4fa81a0c1abfc3fd"
}
],
"title": "ALSA: dummy: Check card index validity at probe",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80812",
"datePublished": "2026-09-04T15:13:32.732Z",
"dateReserved": "2026-08-26T14:34:25.794Z",
"dateUpdated": "2026-09-07T14:21:14.907Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74492 (GCVE-0-2026-74492)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-19 16:37
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
netfilter: ipset: do not update comments from kernel-side hash adds
mtype_resize() copies comment pointers with memcpy(), not the comment
objects themselves. During the window after an entry has been copied but
before the table swap and backlog replay, the old table is still
published for packet-side updates while the replacement-table entry
already holds the same ip_set_comment_rcu pointer.
If xt_SET --add-set ... --exist hits that old entry in this window,
mtype_add() calls ip_set_init_comment() even though packet-side adds
carry no comment payload. That call frees the shared comment through the
old entry, so the replacement-table entry now holds a stale pointer.
When the queued add is replayed on the new table, mtype_add() calls
ip_set_init_comment() again and strlen() dereferences the stale pointer.
Fix this in mtype_add() by skipping ip_set_init_comment() when
ext->target marks a packet-side add. Userspace adds still update
comments, while packet-side adds can no longer free comment storage
shared with a resize copy.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: f66ee0410b1c3481ee75e5db9b34547b4d582465 Version: f66ee0410b1c3481ee75e5db9b34547b4d582465 Version: f66ee0410b1c3481ee75e5db9b34547b4d582465 Version: f66ee0410b1c3481ee75e5db9b34547b4d582465 Version: f66ee0410b1c3481ee75e5db9b34547b4d582465 Version: f66ee0410b1c3481ee75e5db9b34547b4d582465 Version: f66ee0410b1c3481ee75e5db9b34547b4d582465 Version: f66ee0410b1c3481ee75e5db9b34547b4d582465 Version: 5dd9488ae41070b69d2f4acb580f77db5705f9ca Version: a469bab3386aebff33c59506f3a95e35b91118fd Version: 5.4.24 ≤ Version: 5.5.8 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/netfilter/ipset/ip_set_hash_gen.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "6f13f4d52d06986c18f12e8bffaab944dd27ceab",
"status": "affected",
"version": "f66ee0410b1c3481ee75e5db9b34547b4d582465",
"versionType": "git"
},
{
"lessThan": "f9d6cabff1fca010562dcdb0d22b296bdca3ba5a",
"status": "affected",
"version": "f66ee0410b1c3481ee75e5db9b34547b4d582465",
"versionType": "git"
},
{
"lessThan": "16bfa7be2d76ca1e0aacfa363482e1bf8ab5042a",
"status": "affected",
"version": "f66ee0410b1c3481ee75e5db9b34547b4d582465",
"versionType": "git"
},
{
"lessThan": "661ff9c0cfbe07f8eed920dde9f7781491738207",
"status": "affected",
"version": "f66ee0410b1c3481ee75e5db9b34547b4d582465",
"versionType": "git"
},
{
"lessThan": "c710e9bf38e4e71a8db85d26a0f70c0674664207",
"status": "affected",
"version": "f66ee0410b1c3481ee75e5db9b34547b4d582465",
"versionType": "git"
},
{
"lessThan": "4ae701848e4ba9e9713375fb7d82218cbd309da2",
"status": "affected",
"version": "f66ee0410b1c3481ee75e5db9b34547b4d582465",
"versionType": "git"
},
{
"lessThan": "77dbb248a5cc7a5270cd37bbb0b635bf059a872a",
"status": "affected",
"version": "f66ee0410b1c3481ee75e5db9b34547b4d582465",
"versionType": "git"
},
{
"lessThan": "f30415929be8aeb002d557c8d3f7ab2d2188003a",
"status": "affected",
"version": "f66ee0410b1c3481ee75e5db9b34547b4d582465",
"versionType": "git"
},
{
"status": "affected",
"version": "5dd9488ae41070b69d2f4acb580f77db5705f9ca",
"versionType": "git"
},
{
"status": "affected",
"version": "a469bab3386aebff33c59506f3a95e35b91118fd",
"versionType": "git"
},
{
"lessThan": "5.5",
"status": "affected",
"version": "5.4.24",
"versionType": "semver"
},
{
"lessThan": "5.6",
"status": "affected",
"version": "5.5.8",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/netfilter/ipset/ip_set_hash_gen.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.6"
},
{
"lessThan": "5.6",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.4.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.5.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: ipset: do not update comments from kernel-side hash adds\n\nmtype_resize() copies comment pointers with memcpy(), not the comment\nobjects themselves. During the window after an entry has been copied but\nbefore the table swap and backlog replay, the old table is still\npublished for packet-side updates while the replacement-table entry\nalready holds the same ip_set_comment_rcu pointer.\n\nIf xt_SET --add-set ... --exist hits that old entry in this window,\nmtype_add() calls ip_set_init_comment() even though packet-side adds\ncarry no comment payload. That call frees the shared comment through the\nold entry, so the replacement-table entry now holds a stale pointer.\nWhen the queued add is replayed on the new table, mtype_add() calls\nip_set_init_comment() again and strlen() dereferences the stale pointer.\n\nFix this in mtype_add() by skipping ip_set_init_comment() when\next-\u003etarget marks a packet-side add. Userspace adds still update\ncomments, while packet-side adds can no longer free comment storage\nshared with a resize copy."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.4,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached via the netfilter xt_SET packet path (set_target_* -\u003e ip_set_add -\u003e kadt -\u003e mtype_add) during skb processing in iptables hooks; kernel CNA guidance treats netfilter/ipset as Local even when triggering packets arrive from the network.\nAC:L - An attacker can drive both sides of the resize race by filling a comment-enabled hash set and concurrently sending packets that hit SET --add-set --exist while mtype_resize() copies entries, making the shared-comment UAF window repeatable rather than dependent on uncontrollable timing.\nPR:N - Exploitation requires only sending traffic that matches an already-installed SET --exist rule on a comment-enabled ipset during resize; no local account or CAP_NET_ADMIN is needed, though unprivileged user namespaces can also obtain CAP_NET_ADMIN to configure the full attack chain.\nUI:N - Triggering is fully automatic through netfilter packet handling once the vulnerable ipset/iptables configuration exists; the attacker does not need the victim to click, mount, or perform any deliberate action beyond ordinary packet delivery.\nS:U - The flaw corrupts kernel heap memory and can yield host privilege escalation, but it does not cross a distinct security authority such as a VM/host, container/host, or IOMMU boundary; impact remains within the same kernel security domain.\nC:H - Packet-side mtype_add() frees a shared ip_set_comment_rcu during resize, leaving duplicate entries with dangling pointers; backlog replay calls ip_set_init_comment() and strlen() on freed kmalloc memory, a classic UAF that can disclose arbitrary kernel data with heap grooming.\nI:H - The UAF over RCU-freed comment objects lets an attacker reclaim and control freed slab memory, providing a standard path to arbitrary kernel writes, metadata corruption, and control-flow hijack rather than a bounded or crash-only integrity effect.\nA:H - Stale comment pointer dereference during resize backlog replay can immediately kernel-oops/panic the host, and the underlying UAF heap corruption can crash or hang the system even when full exploitation is not attempted."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:37:48.078Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/6f13f4d52d06986c18f12e8bffaab944dd27ceab"
},
{
"url": "https://git.kernel.org/stable/c/f9d6cabff1fca010562dcdb0d22b296bdca3ba5a"
},
{
"url": "https://git.kernel.org/stable/c/16bfa7be2d76ca1e0aacfa363482e1bf8ab5042a"
},
{
"url": "https://git.kernel.org/stable/c/661ff9c0cfbe07f8eed920dde9f7781491738207"
},
{
"url": "https://git.kernel.org/stable/c/c710e9bf38e4e71a8db85d26a0f70c0674664207"
},
{
"url": "https://git.kernel.org/stable/c/4ae701848e4ba9e9713375fb7d82218cbd309da2"
},
{
"url": "https://git.kernel.org/stable/c/77dbb248a5cc7a5270cd37bbb0b635bf059a872a"
},
{
"url": "https://git.kernel.org/stable/c/f30415929be8aeb002d557c8d3f7ab2d2188003a"
}
],
"title": "netfilter: ipset: do not update comments from kernel-side hash adds",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74492",
"datePublished": "2026-08-15T12:27:21.365Z",
"dateReserved": "2026-08-15T05:44:03.906Z",
"dateUpdated": "2026-08-19T16:37:48.078Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74719 (GCVE-0-2026-74719)
Vulnerability from cvelistv5
Published
2026-08-22 15:33
Modified
2026-08-22 15:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/smc: fix qentry overwrite for CONFIRM_LINK and ADD_LINK_CONT in smc_llc_event_handler()
The SMC_LLC_CONFIRM_LINK / SMC_LLC_ADD_LINK_CONT branch in
smc_llc_event_handler() stores an incoming qentry into the local LLC flow
without first checking whether a qentry is already pending. If a malicious or
buggy peer sends a second CONFIRM_LINK or ADD_LINK_CONT request while a flow is
active and flow->qentry is already set, smc_llc_flow_qentry_set() overwrites the
pointer without freeing the previous allocation, leaking one kmalloc-96 object
per spurious message.
The sibling SMC_LLC_DELETE_LINK branch already has the correct !flow->qentry
guard. Apply the same guard to the CONFIRM_LINK/ADD_LINK_CONT branch so that a
duplicate message when qentry is already occupied falls through to break and is
freed by the kfree(qentry) at the out: label, rather than silently leaking the
existing allocation.
The response direction (smc_llc_rx_response()) is unaffected: it already guards
with flow->qentry at the equivalent site and drops duplicate responses
correctly.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 0fb0b02bd6fd26cba38002be4a6bbcae2228fd44 Version: 0fb0b02bd6fd26cba38002be4a6bbcae2228fd44 Version: 0fb0b02bd6fd26cba38002be4a6bbcae2228fd44 Version: 0fb0b02bd6fd26cba38002be4a6bbcae2228fd44 Version: 0fb0b02bd6fd26cba38002be4a6bbcae2228fd44 Version: 0fb0b02bd6fd26cba38002be4a6bbcae2228fd44 Version: 0fb0b02bd6fd26cba38002be4a6bbcae2228fd44 Version: 0fb0b02bd6fd26cba38002be4a6bbcae2228fd44 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/smc/smc_llc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "e384f3cba6ea709f5b2272b1770db4ce14047f78",
"status": "affected",
"version": "0fb0b02bd6fd26cba38002be4a6bbcae2228fd44",
"versionType": "git"
},
{
"lessThan": "a1e980d7a9e7ee6faf4f5fd7b450413b969af26d",
"status": "affected",
"version": "0fb0b02bd6fd26cba38002be4a6bbcae2228fd44",
"versionType": "git"
},
{
"lessThan": "e0eb87677c76b157cdf8eb7c1f19e56227165a33",
"status": "affected",
"version": "0fb0b02bd6fd26cba38002be4a6bbcae2228fd44",
"versionType": "git"
},
{
"lessThan": "06734dfeaeba886aab1bf147249195b888ac3e4d",
"status": "affected",
"version": "0fb0b02bd6fd26cba38002be4a6bbcae2228fd44",
"versionType": "git"
},
{
"lessThan": "c23c409228629107203d3c3e95fff1473173f1a6",
"status": "affected",
"version": "0fb0b02bd6fd26cba38002be4a6bbcae2228fd44",
"versionType": "git"
},
{
"lessThan": "10cb31b2b74cb664c6c95cf72364d7d5c483ab82",
"status": "affected",
"version": "0fb0b02bd6fd26cba38002be4a6bbcae2228fd44",
"versionType": "git"
},
{
"lessThan": "bfc336a9fbbf09805f3dfe25c195a4db90af2846",
"status": "affected",
"version": "0fb0b02bd6fd26cba38002be4a6bbcae2228fd44",
"versionType": "git"
},
{
"lessThan": "976245094925bab9bc39366b2e9ab44ffcde61d0",
"status": "affected",
"version": "0fb0b02bd6fd26cba38002be4a6bbcae2228fd44",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/smc/smc_llc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.8"
},
{
"lessThan": "5.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/smc: fix qentry overwrite for CONFIRM_LINK and ADD_LINK_CONT in smc_llc_event_handler()\n\nThe SMC_LLC_CONFIRM_LINK / SMC_LLC_ADD_LINK_CONT branch in\nsmc_llc_event_handler() stores an incoming qentry into the local LLC flow\nwithout first checking whether a qentry is already pending. If a malicious or\nbuggy peer sends a second CONFIRM_LINK or ADD_LINK_CONT request while a flow is\nactive and flow-\u003eqentry is already set, smc_llc_flow_qentry_set() overwrites the\npointer without freeing the previous allocation, leaking one kmalloc-96 object\nper spurious message.\n\nThe sibling SMC_LLC_DELETE_LINK branch already has the correct !flow-\u003eqentry\nguard. Apply the same guard to the CONFIRM_LINK/ADD_LINK_CONT branch so that a\nduplicate message when qentry is already occupied falls through to break and is\nfreed by the kfree(qentry) at the out: label, rather than silently leaking the\nexisting allocation.\n\nThe response direction (smc_llc_rx_response()) is unaffected: it already guards\nwith flow-\u003eqentry at the equivalent site and drops duplicate responses\ncorrectly."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-22T15:33:12.716Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/e384f3cba6ea709f5b2272b1770db4ce14047f78"
},
{
"url": "https://git.kernel.org/stable/c/a1e980d7a9e7ee6faf4f5fd7b450413b969af26d"
},
{
"url": "https://git.kernel.org/stable/c/e0eb87677c76b157cdf8eb7c1f19e56227165a33"
},
{
"url": "https://git.kernel.org/stable/c/06734dfeaeba886aab1bf147249195b888ac3e4d"
},
{
"url": "https://git.kernel.org/stable/c/c23c409228629107203d3c3e95fff1473173f1a6"
},
{
"url": "https://git.kernel.org/stable/c/10cb31b2b74cb664c6c95cf72364d7d5c483ab82"
},
{
"url": "https://git.kernel.org/stable/c/bfc336a9fbbf09805f3dfe25c195a4db90af2846"
},
{
"url": "https://git.kernel.org/stable/c/976245094925bab9bc39366b2e9ab44ffcde61d0"
}
],
"title": "net/smc: fix qentry overwrite for CONFIRM_LINK and ADD_LINK_CONT in smc_llc_event_handler()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74719",
"datePublished": "2026-08-22T15:33:12.716Z",
"dateReserved": "2026-08-15T05:44:03.929Z",
"dateUpdated": "2026-08-22T15:33:12.716Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72035 (GCVE-0-2026-72035)
Vulnerability from cvelistv5
Published
2026-08-15 05:51
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/sched: sch_taprio: Replace direct dequeue call with peek and qdisc_dequeue_peeked
When taprio's software path peeks a non-work-conserving child qdisc, the
child stashes the peeked skb in its gso_skb; taprio_dequeue_from_txq()
then takes the packet with a direct child ->dequeue() call, which ignores
that stash, orphans the peeked skb and desyncs the child's qlen/backlog.
With a qfq child this re-enters the child on an emptied list and
dereferences NULL, panicking the kernel from softirq on ordinary egress.
Take the packet through qdisc_dequeue_peeked(), as sch_red and sch_sfb
now do. The helper returns the child's stashed skb first and is a no-op
when there is none, so a work-conserving child is unaffected and the
gated path now consumes the skb whose length was charged to the budget.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 5a781ccbd19e4664babcbe4b4ead7aa2b9283d22 Version: 5a781ccbd19e4664babcbe4b4ead7aa2b9283d22 Version: 5a781ccbd19e4664babcbe4b4ead7aa2b9283d22 Version: 5a781ccbd19e4664babcbe4b4ead7aa2b9283d22 Version: 5a781ccbd19e4664babcbe4b4ead7aa2b9283d22 Version: 5a781ccbd19e4664babcbe4b4ead7aa2b9283d22 Version: 5a781ccbd19e4664babcbe4b4ead7aa2b9283d22 Version: 5a781ccbd19e4664babcbe4b4ead7aa2b9283d22 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/sched/sch_taprio.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "51f8af240aed903e988755af33d7491030b50ae9",
"status": "affected",
"version": "5a781ccbd19e4664babcbe4b4ead7aa2b9283d22",
"versionType": "git"
},
{
"lessThan": "17ab5f76f3899f67e5569722f334591f4b88b17b",
"status": "affected",
"version": "5a781ccbd19e4664babcbe4b4ead7aa2b9283d22",
"versionType": "git"
},
{
"lessThan": "f60d5c12e0551012cee5c272b0bcbcc78f7bb506",
"status": "affected",
"version": "5a781ccbd19e4664babcbe4b4ead7aa2b9283d22",
"versionType": "git"
},
{
"lessThan": "6ee5a7665a9080bcb05d703bf981a579436fd05e",
"status": "affected",
"version": "5a781ccbd19e4664babcbe4b4ead7aa2b9283d22",
"versionType": "git"
},
{
"lessThan": "18d580cb00c55805633bae45e90cf22ed6b8e424",
"status": "affected",
"version": "5a781ccbd19e4664babcbe4b4ead7aa2b9283d22",
"versionType": "git"
},
{
"lessThan": "e2b7ee61989f2d39df6c2cc06f9db1aea69bdb09",
"status": "affected",
"version": "5a781ccbd19e4664babcbe4b4ead7aa2b9283d22",
"versionType": "git"
},
{
"lessThan": "2dcebbd1ad2e180fe7b98bf346ced69a872e11e6",
"status": "affected",
"version": "5a781ccbd19e4664babcbe4b4ead7aa2b9283d22",
"versionType": "git"
},
{
"lessThan": "e056e1dfcddca877dd46d704e8ec9860cfc9ec44",
"status": "affected",
"version": "5a781ccbd19e4664babcbe4b4ead7aa2b9283d22",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/sched/sch_taprio.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.20"
},
{
"lessThan": "4.20",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.20",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: sch_taprio: Replace direct dequeue call with peek and qdisc_dequeue_peeked\n\nWhen taprio\u0027s software path peeks a non-work-conserving child qdisc, the\nchild stashes the peeked skb in its gso_skb; taprio_dequeue_from_txq()\nthen takes the packet with a direct child -\u003edequeue() call, which ignores\nthat stash, orphans the peeked skb and desyncs the child\u0027s qlen/backlog.\nWith a qfq child this re-enters the child on an emptied list and\ndereferences NULL, panicking the kernel from softirq on ordinary egress.\n\nTake the packet through qdisc_dequeue_peeked(), as sch_red and sch_sfb\nnow do. The helper returns the child\u0027s stashed skb first and is a no-op\nwhen there is none, so a work-conserving child is unaffected and the\ngated path now consumes the skb whose length was charged to the budget."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.2,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The fault is in taprio\u0027s software egress dequeue path (`__dev_queue_xmit` \u2192 `__qdisc_run` \u2192 `taprio_dequeue` \u2192 `taprio_dequeue_from_txq`) during ordinary packet transmission in softirq; on TSN/automotive/industrial gateways where taprio+qfq is already deployed, any remote peer can trigger it by sending traffic that causes egress through the gated queues.\nAC:L - Once taprio is configured with a non-work-conserving child such as qfq on the software path (no full offload, TXTIME_ASSIST disabled), peek followed by the incorrect direct `dequeue()` deterministically orphans the stashed skb, desyncs qlen/backlog, and re-enters qfq on an emptied list; the attacker fully controls triggering traffic with no uncontrollable races.\nPR:N - Installing taprio and grafting a qfq child requires CAP_NET_ADMIN via RTM_NEWQDISC, but on reasonably deployed TSN/industrial systems where operators have already configured this stack, triggering the bug requires only the ability to send packets through the affected interface\u2014no credentials or capabilities on the victim host.\nUI:N - Exploitation needs only attacker-generated network traffic (or any local sender) once the qdisc hierarchy exists; no victim login, mount, file open, or other interactive action is required at trigger time.\nS:U - The NULL dereference kernel panic and qdisc qlen/backlog corruption occur entirely within the host kernel\u0027s security authority; this is not a VM escape, container breakout, or IOMMU/DMA boundary bypass.\nC:N - The published failure mode is a NULL pointer dereference in qfq after taprio mishandles the peek stash; although the peeked skb is orphaned and child counters desync, there is no use-after-free, out-of-bounds read, or demonstrated arbitrary kernel memory disclosure primitive.\nI:L - Calling `child-\u003eops-\u003edequeue()` instead of `qdisc_dequeue_peeked()` orphans the peek-stashed skb and corrupts the child qdisc\u0027s qlen/backlog accounting before the fatal qfq re-entry, enabling attacker-driven mis-accounting of queued traffic on the affected egress path prior to panic.\nA:H - With a qfq child the desynchronized dequeue path dereferences NULL from softirq during ordinary egress, panicking the kernel; the condition is repeatable whenever gated transmission exercises the peek/dequeue mismatch, causing total host availability loss."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:29.870Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/51f8af240aed903e988755af33d7491030b50ae9"
},
{
"url": "https://git.kernel.org/stable/c/17ab5f76f3899f67e5569722f334591f4b88b17b"
},
{
"url": "https://git.kernel.org/stable/c/f60d5c12e0551012cee5c272b0bcbcc78f7bb506"
},
{
"url": "https://git.kernel.org/stable/c/6ee5a7665a9080bcb05d703bf981a579436fd05e"
},
{
"url": "https://git.kernel.org/stable/c/18d580cb00c55805633bae45e90cf22ed6b8e424"
},
{
"url": "https://git.kernel.org/stable/c/e2b7ee61989f2d39df6c2cc06f9db1aea69bdb09"
},
{
"url": "https://git.kernel.org/stable/c/2dcebbd1ad2e180fe7b98bf346ced69a872e11e6"
},
{
"url": "https://git.kernel.org/stable/c/e056e1dfcddca877dd46d704e8ec9860cfc9ec44"
}
],
"title": "net/sched: sch_taprio: Replace direct dequeue call with peek and qdisc_dequeue_peeked",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72035",
"datePublished": "2026-08-15T05:51:56.374Z",
"dateReserved": "2026-08-09T03:40:39.901Z",
"dateUpdated": "2026-08-23T12:46:29.870Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68209 (GCVE-0-2026-68209)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: sun4i-csi: Return queued buffers on start_streaming() failure
The vb2 framework hands buffers to the driver via buf_queue() before
calling start_streaming(). If start_streaming() returns an error
without first returning those buffers via vb2_buffer_done(),
vb2_start_streaming() fires WARN_ON(owned_by_drv_count) and the queued
buffers leak.
sun4i_csi_start_streaming() returned -EINVAL when no matching CSI
format could be found, before any setup (scratch buffer allocation,
pipeline start) had been performed. The remaining error paths already
converge on the err_clear_dma_queue label, which calls
return_all_buffers(..., VB2_BUF_STATE_QUEUED) under csi->qlock. Jump
to that label directly: the intermediate err_disable_device /
err_disable_pipeline / err_free_scratch_buffer labels are skipped,
which is correct because nothing they would undo has happened yet.
This mirrors the uvcvideo fix in commit 4cf3b6fd54eb ("media: uvcvideo:
Return queued buffers on start_streaming() failure").
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 577bbf23b758848f0c4a50d346460b690c753024 Version: 577bbf23b758848f0c4a50d346460b690c753024 Version: 577bbf23b758848f0c4a50d346460b690c753024 Version: 577bbf23b758848f0c4a50d346460b690c753024 Version: 577bbf23b758848f0c4a50d346460b690c753024 Version: 577bbf23b758848f0c4a50d346460b690c753024 Version: 577bbf23b758848f0c4a50d346460b690c753024 Version: 577bbf23b758848f0c4a50d346460b690c753024 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/platform/sunxi/sun4i-csi/sun4i_dma.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "29fce7bcb3b959f6d4fdcdff7d26330152fdf98d",
"status": "affected",
"version": "577bbf23b758848f0c4a50d346460b690c753024",
"versionType": "git"
},
{
"lessThan": "7c2c30e282745a83d332c3cf92d1c0bcc491ac54",
"status": "affected",
"version": "577bbf23b758848f0c4a50d346460b690c753024",
"versionType": "git"
},
{
"lessThan": "3c0bd793b0083fd4639ba7f60d1e7db8c8ac459a",
"status": "affected",
"version": "577bbf23b758848f0c4a50d346460b690c753024",
"versionType": "git"
},
{
"lessThan": "4872161e6fbe4e1783daea8bff79caddfae0fb82",
"status": "affected",
"version": "577bbf23b758848f0c4a50d346460b690c753024",
"versionType": "git"
},
{
"lessThan": "a8abecc638a7feb20b78fabd563b05e30c071331",
"status": "affected",
"version": "577bbf23b758848f0c4a50d346460b690c753024",
"versionType": "git"
},
{
"lessThan": "b5184b3f0e9d4cc47059ba1138c9a73d43d2493f",
"status": "affected",
"version": "577bbf23b758848f0c4a50d346460b690c753024",
"versionType": "git"
},
{
"lessThan": "668face37fdb6b6900645dc8777195498541c9a7",
"status": "affected",
"version": "577bbf23b758848f0c4a50d346460b690c753024",
"versionType": "git"
},
{
"lessThan": "bbba3e260a62810a717b4442a3bb96d0ec0f6309",
"status": "affected",
"version": "577bbf23b758848f0c4a50d346460b690c753024",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/platform/sunxi/sun4i-csi/sun4i_dma.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.4"
},
{
"lessThan": "5.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: sun4i-csi: Return queued buffers on start_streaming() failure\n\nThe vb2 framework hands buffers to the driver via buf_queue() before\ncalling start_streaming(). If start_streaming() returns an error\nwithout first returning those buffers via vb2_buffer_done(),\nvb2_start_streaming() fires WARN_ON(owned_by_drv_count) and the queued\nbuffers leak.\n\nsun4i_csi_start_streaming() returned -EINVAL when no matching CSI\nformat could be found, before any setup (scratch buffer allocation,\npipeline start) had been performed. The remaining error paths already\nconverge on the err_clear_dma_queue label, which calls\nreturn_all_buffers(..., VB2_BUF_STATE_QUEUED) under csi-\u003eqlock. Jump\nto that label directly: the intermediate err_disable_device /\nerr_disable_pipeline / err_free_scratch_buffer labels are skipped,\nwhich is correct because nothing they would undo has happened yet.\n\nThis mirrors the uvcvideo fix in commit 4cf3b6fd54eb (\"media: uvcvideo:\nReturn queued buffers on start_streaming() failure\")."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable code is reached only through local V4L2 ioctls (VIDIOC_S_FMT, VIDIOC_REQBUFS, VIDIOC_QBUF, VIDIOC_STREAMON) on the sun4i-csi /dev/videoN character device. There is no network, adjacent-network, or remote data path into sun4i_csi_start_streaming().\nAC:L - The attacker deterministically drives the sequence itself: configure the capture format, queue buffers, then issue STREAMON so the driver returns an error after vb2 has already handed the buffers over. No race, timing window, or memory layout outside the attacker\u0027s control is involved, and the sequence can be retried without limit.\nPR:L - sun4i_csi_open() and the entire queue/streamon path perform no capability checks; only an open file descriptor on the video node is needed, which udev grants to the active local user via the video group and 70-uaccess.rules (or the Android CAMERA context). That is ordinary unprivileged local access, not root.\nUI:N - The attacker performs the whole open/S_FMT/QBUF/STREAMON/REQBUFS sequence inside its own process. No victim action, cooperation, or pre-existing session state is required.\nS:U - The damage is confined to kernel heap and sun4i-csi driver state within the same OS security authority. Nothing crosses a hypervisor, IOMMU, or sandbox boundary.\nC:H - Buffers stay linked on csi-\u003ebuf_list after vb2 force-reclaims them, and the list head is only initialized once at probe. A later REQBUFS(0) or close frees those vb2 buffers while the driver still holds pointers, so sun4i_csi_buffer_fill_all()/return_all_buffers() read through freed slab objects the attacker can reclaim and shape, disclosing kernel heap contents.\nI:H - The stale list linkage yields list_add_tail()/list_del() operations on freed nodes, giving a write-what-where style list-corruption primitive, and the DMA fill path writes buffer addresses through the dangling entries. Under conservative memory-corruption scoring this is high integrity impact.\nA:H - The immediate effect is the WARN_ON(owned_by_drv_count) splat in vb2_start_streaming(), which panics on panic_on_warn systems, and the resulting dangling buf_list produces use-after-free oopses or slab corruption on the next streaming attempt or buffer release."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:31.902Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/29fce7bcb3b959f6d4fdcdff7d26330152fdf98d"
},
{
"url": "https://git.kernel.org/stable/c/7c2c30e282745a83d332c3cf92d1c0bcc491ac54"
},
{
"url": "https://git.kernel.org/stable/c/3c0bd793b0083fd4639ba7f60d1e7db8c8ac459a"
},
{
"url": "https://git.kernel.org/stable/c/4872161e6fbe4e1783daea8bff79caddfae0fb82"
},
{
"url": "https://git.kernel.org/stable/c/a8abecc638a7feb20b78fabd563b05e30c071331"
},
{
"url": "https://git.kernel.org/stable/c/b5184b3f0e9d4cc47059ba1138c9a73d43d2493f"
},
{
"url": "https://git.kernel.org/stable/c/668face37fdb6b6900645dc8777195498541c9a7"
},
{
"url": "https://git.kernel.org/stable/c/bbba3e260a62810a717b4442a3bb96d0ec0f6309"
}
],
"title": "media: sun4i-csi: Return queued buffers on start_streaming() failure",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68209",
"datePublished": "2026-08-10T12:00:28.245Z",
"dateReserved": "2026-07-30T09:28:09.374Z",
"dateUpdated": "2026-08-19T16:31:31.902Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68320 (GCVE-0-2026-68320)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid
sctp_auth_ep_add_chunkid() uses SCTP_NUM_CHUNK_TYPES (20) as the
capacity limit for ep->auth_chunk_list, allowing it to hold up to
20 chunk entries (param_hdr.length up to 24). However, the copy
destination asoc->c.auth_chunks in struct sctp_cookie is only
SCTP_AUTH_MAX_CHUNKS (16) entries (20 bytes). When more than 16
chunks are added, sctp_association_init() memcpy overflows the
destination by up to 4 bytes.
Fix by using SCTP_AUTH_MAX_CHUNKS as the capacity limit, matching
the destination capacity.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1f485649f52929d9937b346a920a522a7363e202 Version: 1f485649f52929d9937b346a920a522a7363e202 Version: 1f485649f52929d9937b346a920a522a7363e202 Version: 1f485649f52929d9937b346a920a522a7363e202 Version: 1f485649f52929d9937b346a920a522a7363e202 Version: 1f485649f52929d9937b346a920a522a7363e202 Version: 1f485649f52929d9937b346a920a522a7363e202 Version: 1f485649f52929d9937b346a920a522a7363e202 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/sctp/auth.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "3d22a7da2e264f407c729f33a0a346ff76108bc6",
"status": "affected",
"version": "1f485649f52929d9937b346a920a522a7363e202",
"versionType": "git"
},
{
"lessThan": "6837c1c19a259518974cbc5a52017646e3906564",
"status": "affected",
"version": "1f485649f52929d9937b346a920a522a7363e202",
"versionType": "git"
},
{
"lessThan": "54bb4c03fa17cdcb157c26c33e60a78cf32960f5",
"status": "affected",
"version": "1f485649f52929d9937b346a920a522a7363e202",
"versionType": "git"
},
{
"lessThan": "5a365f1e423444c5da7eb689a8661633dad43e48",
"status": "affected",
"version": "1f485649f52929d9937b346a920a522a7363e202",
"versionType": "git"
},
{
"lessThan": "886e28e14ab655012779016d251fef53d103aa12",
"status": "affected",
"version": "1f485649f52929d9937b346a920a522a7363e202",
"versionType": "git"
},
{
"lessThan": "11092d79eb2b7c0068382f72fc2416d1786bb2e0",
"status": "affected",
"version": "1f485649f52929d9937b346a920a522a7363e202",
"versionType": "git"
},
{
"lessThan": "b6ea3dda09eb4d5caf7bbc00f857688cf9e98255",
"status": "affected",
"version": "1f485649f52929d9937b346a920a522a7363e202",
"versionType": "git"
},
{
"lessThan": "ff04b26794a16a8a879eb4fd2c02c2d6b03850e9",
"status": "affected",
"version": "1f485649f52929d9937b346a920a522a7363e202",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/sctp/auth.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.24"
},
{
"lessThan": "2.6.24",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.24",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid\n\nsctp_auth_ep_add_chunkid() uses SCTP_NUM_CHUNK_TYPES (20) as the\ncapacity limit for ep-\u003eauth_chunk_list, allowing it to hold up to\n20 chunk entries (param_hdr.length up to 24). However, the copy\ndestination asoc-\u003ec.auth_chunks in struct sctp_cookie is only\nSCTP_AUTH_MAX_CHUNKS (16) entries (20 bytes). When more than 16\nchunks are added, sctp_association_init() memcpy overflows the\ndestination by up to 4 bytes.\n\nFix by using SCTP_AUTH_MAX_CHUNKS as the capacity limit, matching\nthe destination capacity."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The overflow condition can only be created locally: an attacker must call setsockopt(SCTP_AUTH_SUPPORTED) and then setsockopt(SCTP_AUTH_CHUNK) more than 16 times on an SCTP socket they own. A remote peer can trigger the memcpy by connecting to such a socket, but cannot itself populate the oversized chunk list.\nAC:L - The sequence is fully deterministic and entirely under attacker control \u2014 enable AUTH, add 17-20 distinct chunk IDs, then create an association via connect() or accept(); no race, timing window, or memory-layout condition is involved.\nPR:L - Creating an IPPROTO_SCTP socket and issuing SCTP_AUTH_SUPPORTED/SCTP_AUTH_CHUNK setsockopts requires no capability; sctp_setsockopt_auth_supported() enables AUTH per-endpoint regardless of the net.sctp.auth_enable sysctl, so any unprivileged local user reaches the bug.\nUI:N - The attacker performs every step from their own process \u2014 socket setup, setsockopt calls, and association establishment \u2014 with no action required from any other user or administrator.\nS:U - The corruption and the over-read are confined to the kernel\u0027s own SCTP association object; no other security authority or privilege domain is crossed.\nC:L - sctp_make_init()/sctp_make_init_ack() copy ntohs(auth_chunks-\u003elength) bytes from the 20-byte field, emitting up to 4 bytes past it (the adjacent raw_addr_list_len) inside the CHUNKS parameter of INIT/INIT-ACK sent to the remote peer \u2014 a real but small, strictly bounded out-of-bounds read.\nI:H - sctp_association_init() writes up to 4 bytes of fully attacker-chosen data (the chunk-ID values) past the end of asoc-\u003ec.auth_chunks into the adjacent kernel struct field, an out-of-bounds write of controlled content into kernel memory.\nA:H - On CONFIG_FORTIFY_SOURCE kernels the memcpy is flagged as a field-spanning write and emits a WARN, which is fatal on the widely used panic_on_warn configurations, and the out-of-bounds write itself corrupts SCTP association state; the trigger is cheap and repeatable by any local user."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:10.661Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/3d22a7da2e264f407c729f33a0a346ff76108bc6"
},
{
"url": "https://git.kernel.org/stable/c/6837c1c19a259518974cbc5a52017646e3906564"
},
{
"url": "https://git.kernel.org/stable/c/54bb4c03fa17cdcb157c26c33e60a78cf32960f5"
},
{
"url": "https://git.kernel.org/stable/c/5a365f1e423444c5da7eb689a8661633dad43e48"
},
{
"url": "https://git.kernel.org/stable/c/886e28e14ab655012779016d251fef53d103aa12"
},
{
"url": "https://git.kernel.org/stable/c/11092d79eb2b7c0068382f72fc2416d1786bb2e0"
},
{
"url": "https://git.kernel.org/stable/c/b6ea3dda09eb4d5caf7bbc00f857688cf9e98255"
},
{
"url": "https://git.kernel.org/stable/c/ff04b26794a16a8a879eb4fd2c02c2d6b03850e9"
}
],
"title": "sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68320",
"datePublished": "2026-08-10T12:02:55.144Z",
"dateReserved": "2026-07-30T09:28:09.382Z",
"dateUpdated": "2026-08-19T16:33:10.661Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74464 (GCVE-0-2026-74464)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-19 16:37
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: openvswitch: fix skb leak on flow key update failure during ct
ovs_ct_execute() always steals or frees the skb on failure while
ovs_flow_key_update() does not. So, if it fails and we return right
away, the skb ends up leaked.
Fix that by breaking instead and letting the common error handling
code at the bottom of the loop to free the skb properly.
This is a very unlikely scenario as it requires the packet to become
unparseable by applying a set of actions on a previously parseable skb,
but should be fixed nevertheless.
Reported by Sashiko.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ec0d043d05e6e3c0c2fac5de922c800c027c6386 Version: ec0d043d05e6e3c0c2fac5de922c800c027c6386 Version: ec0d043d05e6e3c0c2fac5de922c800c027c6386 Version: ec0d043d05e6e3c0c2fac5de922c800c027c6386 Version: ec0d043d05e6e3c0c2fac5de922c800c027c6386 Version: ec0d043d05e6e3c0c2fac5de922c800c027c6386 Version: ec0d043d05e6e3c0c2fac5de922c800c027c6386 Version: ec0d043d05e6e3c0c2fac5de922c800c027c6386 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/openvswitch/actions.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b77126b2915900f69f9fcf5d624a77c8e6d50c31",
"status": "affected",
"version": "ec0d043d05e6e3c0c2fac5de922c800c027c6386",
"versionType": "git"
},
{
"lessThan": "6cc523eaee72c4e91894136cff64946ae9de2cda",
"status": "affected",
"version": "ec0d043d05e6e3c0c2fac5de922c800c027c6386",
"versionType": "git"
},
{
"lessThan": "22e0ca88090d89c128078062186b03bb5fdc4f98",
"status": "affected",
"version": "ec0d043d05e6e3c0c2fac5de922c800c027c6386",
"versionType": "git"
},
{
"lessThan": "736e972f3f8a304158345223ac6e816166a467ce",
"status": "affected",
"version": "ec0d043d05e6e3c0c2fac5de922c800c027c6386",
"versionType": "git"
},
{
"lessThan": "e84dfaac50aab45ad8c670da43e3aa1f97bd2a41",
"status": "affected",
"version": "ec0d043d05e6e3c0c2fac5de922c800c027c6386",
"versionType": "git"
},
{
"lessThan": "e0ba8eaef2a0d02a7a485e6a7157e47272b65cea",
"status": "affected",
"version": "ec0d043d05e6e3c0c2fac5de922c800c027c6386",
"versionType": "git"
},
{
"lessThan": "393f3c72600ab6721d732a0ab245bc896c5b28fc",
"status": "affected",
"version": "ec0d043d05e6e3c0c2fac5de922c800c027c6386",
"versionType": "git"
},
{
"lessThan": "bc62e843bc48f933da765ce47079fd992e535794",
"status": "affected",
"version": "ec0d043d05e6e3c0c2fac5de922c800c027c6386",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/openvswitch/actions.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.3"
},
{
"lessThan": "4.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: openvswitch: fix skb leak on flow key update failure during ct\n\novs_ct_execute() always steals or frees the skb on failure while\novs_flow_key_update() does not. So, if it fails and we return right\naway, the skb ends up leaked.\n\nFix that by breaking instead and letting the common error handling\ncode at the bottom of the loop to free the skb properly.\n\nThis is a very unlikely scenario as it requires the packet to become\nunparseable by applying a set of actions on a previously parseable skb,\nbut should be fixed nevertheless.\n\nReported by Sashiko."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:37:05.367Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b77126b2915900f69f9fcf5d624a77c8e6d50c31"
},
{
"url": "https://git.kernel.org/stable/c/6cc523eaee72c4e91894136cff64946ae9de2cda"
},
{
"url": "https://git.kernel.org/stable/c/22e0ca88090d89c128078062186b03bb5fdc4f98"
},
{
"url": "https://git.kernel.org/stable/c/736e972f3f8a304158345223ac6e816166a467ce"
},
{
"url": "https://git.kernel.org/stable/c/e84dfaac50aab45ad8c670da43e3aa1f97bd2a41"
},
{
"url": "https://git.kernel.org/stable/c/e0ba8eaef2a0d02a7a485e6a7157e47272b65cea"
},
{
"url": "https://git.kernel.org/stable/c/393f3c72600ab6721d732a0ab245bc896c5b28fc"
},
{
"url": "https://git.kernel.org/stable/c/bc62e843bc48f933da765ce47079fd992e535794"
}
],
"title": "net: openvswitch: fix skb leak on flow key update failure during ct",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74464",
"datePublished": "2026-08-15T12:27:03.786Z",
"dateReserved": "2026-08-15T05:44:03.901Z",
"dateUpdated": "2026-08-19T16:37:05.367Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74701 (GCVE-0-2026-74701)
Vulnerability from cvelistv5
Published
2026-08-22 15:33
Modified
2026-08-25 05:41
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/openvswitch: check Ethernet header length in key_extract()
When a packet arrives on an ARPHRD_NONE device (e.g. TUN),
ovs_flow_key_extract() trusts the user-provided skb->protocol field: if
it is ETH_P_TEB, the packet is classified as MAC_PROTO_ETHERNET and
key_extract() is called without ensuring the skb has ETH_HLEN (14) bytes
of linear data. key_extract() unconditionally pulls 2 * ETH_ALEN bytes
for MAC addresses and parse_ethertype() pulls 2 more, either of which
triggers a kernel BUG in __skb_pull() when the linear area is too small.
kernel BUG at include/linux/skbuff.h:2848!
RIP: 0010:key_extract+0xa7e/0xd90 net/openvswitch/flow.c:933
ovs_flow_key_extract+0x419/0xa70
ovs_vport_receive+0x222/0x390
netdev_frame_hook+0x3e0/0x630
tun_get_user+0x2d0c/0x38e0
Fixed by calling check_header() in key_extract() before accessing the
Ethernet header.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 217ac77a3c2524d999730b2a80b61fcc2d0f734a Version: 217ac77a3c2524d999730b2a80b61fcc2d0f734a Version: 217ac77a3c2524d999730b2a80b61fcc2d0f734a Version: 217ac77a3c2524d999730b2a80b61fcc2d0f734a Version: 217ac77a3c2524d999730b2a80b61fcc2d0f734a Version: 217ac77a3c2524d999730b2a80b61fcc2d0f734a Version: 217ac77a3c2524d999730b2a80b61fcc2d0f734a Version: 217ac77a3c2524d999730b2a80b61fcc2d0f734a |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/openvswitch/flow.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "e85278afd4890dd190ba3c7a1b1a712b801c9fe1",
"status": "affected",
"version": "217ac77a3c2524d999730b2a80b61fcc2d0f734a",
"versionType": "git"
},
{
"lessThan": "81f9b09f0ea3ba9ab966dd17e9f32625a14555e9",
"status": "affected",
"version": "217ac77a3c2524d999730b2a80b61fcc2d0f734a",
"versionType": "git"
},
{
"lessThan": "831471718f6e19aed1a330b03b53190a90e06466",
"status": "affected",
"version": "217ac77a3c2524d999730b2a80b61fcc2d0f734a",
"versionType": "git"
},
{
"lessThan": "d8bea341b183190ce6c055ab0e64ab78eb9a7290",
"status": "affected",
"version": "217ac77a3c2524d999730b2a80b61fcc2d0f734a",
"versionType": "git"
},
{
"lessThan": "0b60b55652ba772b173dddc63f3851e1d2dd5927",
"status": "affected",
"version": "217ac77a3c2524d999730b2a80b61fcc2d0f734a",
"versionType": "git"
},
{
"lessThan": "a8139285c8925efe59af28a9169bb2fda91bff15",
"status": "affected",
"version": "217ac77a3c2524d999730b2a80b61fcc2d0f734a",
"versionType": "git"
},
{
"lessThan": "9b8cfbb58b85bfa7a78fac47fdc77396cd01f699",
"status": "affected",
"version": "217ac77a3c2524d999730b2a80b61fcc2d0f734a",
"versionType": "git"
},
{
"lessThan": "cf6f8b29befb92173659bcef6a441d274947bfae",
"status": "affected",
"version": "217ac77a3c2524d999730b2a80b61fcc2d0f734a",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/openvswitch/flow.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.10"
},
{
"lessThan": "4.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/openvswitch: check Ethernet header length in key_extract()\n\nWhen a packet arrives on an ARPHRD_NONE device (e.g. TUN),\novs_flow_key_extract() trusts the user-provided skb-\u003eprotocol field: if\nit is ETH_P_TEB, the packet is classified as MAC_PROTO_ETHERNET and\nkey_extract() is called without ensuring the skb has ETH_HLEN (14) bytes\nof linear data. key_extract() unconditionally pulls 2 * ETH_ALEN bytes\nfor MAC addresses and parse_ethertype() pulls 2 more, either of which\ntriggers a kernel BUG in __skb_pull() when the linear area is too small.\n\n kernel BUG at include/linux/skbuff.h:2848!\n RIP: 0010:key_extract+0xa7e/0xd90 net/openvswitch/flow.c:933\n ovs_flow_key_extract+0x419/0xa70\n ovs_vport_receive+0x222/0x390\n netdev_frame_hook+0x3e0/0x630\n tun_get_user+0x2d0c/0x38e0\n\nFixed by calling check_header() in key_extract() before accessing the\nEthernet header."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The crash is reached when a crafted skb is processed in ovs_flow_key_extract() via ovs_vport_receive(); the documented reproducer injects it through tun_get_user() (write to a TUN fd), and the alternate path is OVS_PACKET_CMD_EXECUTE netlink\u2014both require local syscall access, not remote packet delivery.\nAC:L - The attacker fully controls skb length, skb-\u003eprotocol (ETH_P_TEB), and linear versus fragmented layout; sending a sub-14-byte payload with ETH_P_TEB on an ARPHRD_NONE OVS port deterministically reaches key_extract() and triggers __skb_pull() BUG() without races or special heap layout.\nPR:L - Attaching an ARPHRD_NONE netdev to an OVS datapath and using OVS_PACKET_CMD_EXECUTE require CAP_NET_ADMIN (GENL_UNS_ADMIN_PERM, netnsok); CAP_NET_ADMIN is obtainable inside an unprivileged user+network namespace, and TUN injection likewise requires CAP_NET_ADMIN or a TUN fd granted by a privileged setup.\nUI:N - No victim interaction is required; once OVS bridges an ARPHRD_NONE port (e.g. TUN), the attacker triggers the bug by injecting a single malformed packet via write() or netlink without any other user action.\nS:U - Impact is a kernel BUG/panic in the same kernel security authority as the attacker; this is not a VM escape, IOMMU bypass, or cross-namespace privilege boundary crossing.\nC:H - Before the BUG, key_extract() calls ether_addr_copy() and parse_ethertype() on skb-\u003edata without validating ETH_HLEN, performing out-of-bounds reads of kernel skb buffer memory beyond the actual packet payload.\nI:H - Unchecked __skb_pull() on an undersized skb corrupts skb-\u003edata and skb-\u003elen metadata; this memory corruption of kernel packet state can be leveraged for further integrity violations beyond a simple controlled crash.\nA:H - The flaw triggers kernel BUG() at __skb_pull() in include/linux/skbuff.h, producing a kernel oops/panic and denying all system availability on affected hosts running Open vSwitch with ARPHRD_NONE ports."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:41:43.778Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/e85278afd4890dd190ba3c7a1b1a712b801c9fe1"
},
{
"url": "https://git.kernel.org/stable/c/81f9b09f0ea3ba9ab966dd17e9f32625a14555e9"
},
{
"url": "https://git.kernel.org/stable/c/831471718f6e19aed1a330b03b53190a90e06466"
},
{
"url": "https://git.kernel.org/stable/c/d8bea341b183190ce6c055ab0e64ab78eb9a7290"
},
{
"url": "https://git.kernel.org/stable/c/0b60b55652ba772b173dddc63f3851e1d2dd5927"
},
{
"url": "https://git.kernel.org/stable/c/a8139285c8925efe59af28a9169bb2fda91bff15"
},
{
"url": "https://git.kernel.org/stable/c/9b8cfbb58b85bfa7a78fac47fdc77396cd01f699"
},
{
"url": "https://git.kernel.org/stable/c/cf6f8b29befb92173659bcef6a441d274947bfae"
}
],
"title": "net/openvswitch: check Ethernet header length in key_extract()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74701",
"datePublished": "2026-08-22T15:33:01.585Z",
"dateReserved": "2026-08-15T05:44:03.927Z",
"dateUpdated": "2026-08-25T05:41:43.778Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74525 (GCVE-0-2026-74525)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-19 16:38
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: sxgbe: free TX rings on RX allocation failure
When RX descriptor ring allocation fails, init_dma_desc_rings() only
frees the partially allocated RX rings and returns. The TX rings that
were allocated earlier in the same function are leaked.
Rearrange error labels to clean up TX rings upon RX failures.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1edb9ca69e8a7988900fc0283e10550b5592164d Version: 1edb9ca69e8a7988900fc0283e10550b5592164d Version: 1edb9ca69e8a7988900fc0283e10550b5592164d Version: 1edb9ca69e8a7988900fc0283e10550b5592164d Version: 1edb9ca69e8a7988900fc0283e10550b5592164d Version: 1edb9ca69e8a7988900fc0283e10550b5592164d Version: 1edb9ca69e8a7988900fc0283e10550b5592164d Version: 1edb9ca69e8a7988900fc0283e10550b5592164d |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/samsung/sxgbe/sxgbe_main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "923389d0370b4117bd579784442e8450f9bb89be",
"status": "affected",
"version": "1edb9ca69e8a7988900fc0283e10550b5592164d",
"versionType": "git"
},
{
"lessThan": "a07a69f472fff1c6edf77ca97616381657a8444c",
"status": "affected",
"version": "1edb9ca69e8a7988900fc0283e10550b5592164d",
"versionType": "git"
},
{
"lessThan": "f52de3ea462229457334c9d3c0d95a7856908664",
"status": "affected",
"version": "1edb9ca69e8a7988900fc0283e10550b5592164d",
"versionType": "git"
},
{
"lessThan": "3563e2486dcd50a751dbcbc1de37e5186646dce6",
"status": "affected",
"version": "1edb9ca69e8a7988900fc0283e10550b5592164d",
"versionType": "git"
},
{
"lessThan": "b33644a4f6d8f127c62d7b39f24114d3d2499204",
"status": "affected",
"version": "1edb9ca69e8a7988900fc0283e10550b5592164d",
"versionType": "git"
},
{
"lessThan": "42b87cfd9666ef156637c90ff3f6f6dd9a5ad4cb",
"status": "affected",
"version": "1edb9ca69e8a7988900fc0283e10550b5592164d",
"versionType": "git"
},
{
"lessThan": "f2e5bb9fb710553e76a3be9097b448b4e73d8c92",
"status": "affected",
"version": "1edb9ca69e8a7988900fc0283e10550b5592164d",
"versionType": "git"
},
{
"lessThan": "c870f7e2890b9f78ac84515a9809cc5c183c975e",
"status": "affected",
"version": "1edb9ca69e8a7988900fc0283e10550b5592164d",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/samsung/sxgbe/sxgbe_main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.15"
},
{
"lessThan": "3.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "3.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "3.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "3.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "3.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: sxgbe: free TX rings on RX allocation failure\n\nWhen RX descriptor ring allocation fails, init_dma_desc_rings() only\nfrees the partially allocated RX rings and returns. The TX rings that\nwere allocated earlier in the same function are leaked.\n\nRearrange error labels to clean up TX rings upon RX failures."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:38:29.844Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/923389d0370b4117bd579784442e8450f9bb89be"
},
{
"url": "https://git.kernel.org/stable/c/a07a69f472fff1c6edf77ca97616381657a8444c"
},
{
"url": "https://git.kernel.org/stable/c/f52de3ea462229457334c9d3c0d95a7856908664"
},
{
"url": "https://git.kernel.org/stable/c/3563e2486dcd50a751dbcbc1de37e5186646dce6"
},
{
"url": "https://git.kernel.org/stable/c/b33644a4f6d8f127c62d7b39f24114d3d2499204"
},
{
"url": "https://git.kernel.org/stable/c/42b87cfd9666ef156637c90ff3f6f6dd9a5ad4cb"
},
{
"url": "https://git.kernel.org/stable/c/f2e5bb9fb710553e76a3be9097b448b4e73d8c92"
},
{
"url": "https://git.kernel.org/stable/c/c870f7e2890b9f78ac84515a9809cc5c183c975e"
}
],
"title": "net: sxgbe: free TX rings on RX allocation failure",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74525",
"datePublished": "2026-08-15T12:27:42.344Z",
"dateReserved": "2026-08-15T05:44:03.911Z",
"dateUpdated": "2026-08-19T16:38:29.844Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80799 (GCVE-0-2026-80799)
Vulnerability from cvelistv5
Published
2026-09-04 15:13
Modified
2026-09-04 15:13
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers
nfc_llcp_parse_gb_tlv() and nfc_llcp_parse_connection_tlv() contain
three related bugs in their TLV parsing loops:
1. 'offset' is declared u8 but tlv_array_len is u16. When TLV data
advances offset past 255 it silently wraps to zero, causing
infinite loops or double-processing of buffer data.
2. Before reading tlv[0] (type) and tlv[1] (length) there is no
check that offset+2 <= tlv_array_len. A truncated TLV causes
an OOB read of one byte past the buffer end.
3. After reading the length field, the value bytes are accessed
without checking offset+2+length <= tlv_array_len. A crafted
length=0xFF on a short buffer causes up to 255 bytes of OOB
read past the buffer end.
Both functions are reachable without authentication via
nfc_llcp_set_remote_gb() which feeds remote LLCP general bytes
directly into nfc_llcp_parse_gb_tlv() with no additional
validation.
Fix all three issues by widening offset from u8 to u16 and adding
bounds checks for both the TLV header and value field before each
access.
References
| URL | Tags | ||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 0be9de2ea01e8d52646e7310a7eef5459cf07ea8 Version: 3df40eb3a2ea58bf404a38f15a7a2768e4762cb0 Version: 3df40eb3a2ea58bf404a38f15a7a2768e4762cb0 Version: 3df40eb3a2ea58bf404a38f15a7a2768e4762cb0 Version: 3df40eb3a2ea58bf404a38f15a7a2768e4762cb0 Version: 3df40eb3a2ea58bf404a38f15a7a2768e4762cb0 Version: 3df40eb3a2ea58bf404a38f15a7a2768e4762cb0 Version: 3df40eb3a2ea58bf404a38f15a7a2768e4762cb0 Version: 3df40eb3a2ea58bf404a38f15a7a2768e4762cb0 Version: 1deacb5e031e289ca5636f2db4fcae6612c05d34 Version: 66a1be74230bbe098e651766c9a0cf4038db8442 Version: 5.10.188 ≤ Version: 4.19.291 ≤ Version: 5.4.251 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/nfc/llcp_commands.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "2c1456fe09ab1a5a9fe1d8339ca6d509589b56e1",
"status": "affected",
"version": "0be9de2ea01e8d52646e7310a7eef5459cf07ea8",
"versionType": "git"
},
{
"lessThan": "7f6f3d087c67a4346189ef2c36481455bbc59a74",
"status": "affected",
"version": "3df40eb3a2ea58bf404a38f15a7a2768e4762cb0",
"versionType": "git"
},
{
"lessThan": "9c47d667963542c3cf8e3007b7f10c0904d08238",
"status": "affected",
"version": "3df40eb3a2ea58bf404a38f15a7a2768e4762cb0",
"versionType": "git"
},
{
"lessThan": "a209334ed929941b20810c17c3a507445b0a7c85",
"status": "affected",
"version": "3df40eb3a2ea58bf404a38f15a7a2768e4762cb0",
"versionType": "git"
},
{
"lessThan": "382eaa770335acf4f16a5a55524500f2bb4207df",
"status": "affected",
"version": "3df40eb3a2ea58bf404a38f15a7a2768e4762cb0",
"versionType": "git"
},
{
"lessThan": "2d239590d1845a706304833d40dd6d4fec20ad88",
"status": "affected",
"version": "3df40eb3a2ea58bf404a38f15a7a2768e4762cb0",
"versionType": "git"
},
{
"lessThan": "e84cdfdc4a6c88e8b751144458f2e04e24415a28",
"status": "affected",
"version": "3df40eb3a2ea58bf404a38f15a7a2768e4762cb0",
"versionType": "git"
},
{
"lessThan": "875285a165fd3b402de2ab3be0deb355d6f4caf5",
"status": "affected",
"version": "3df40eb3a2ea58bf404a38f15a7a2768e4762cb0",
"versionType": "git"
},
{
"lessThan": "78b20c8eeacd2e44a2d8a4cb5316d3c521d90911",
"status": "affected",
"version": "3df40eb3a2ea58bf404a38f15a7a2768e4762cb0",
"versionType": "git"
},
{
"status": "affected",
"version": "1deacb5e031e289ca5636f2db4fcae6612c05d34",
"versionType": "git"
},
{
"status": "affected",
"version": "66a1be74230bbe098e651766c9a0cf4038db8442",
"versionType": "git"
},
{
"lessThan": "5.10.267",
"status": "affected",
"version": "5.10.188",
"versionType": "semver"
},
{
"lessThan": "4.20",
"status": "affected",
"version": "4.19.291",
"versionType": "semver"
},
{
"lessThan": "5.5",
"status": "affected",
"version": "5.4.251",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/nfc/llcp_commands.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.15"
},
{
"lessThan": "5.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.267",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.218",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.185",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.154",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.106",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.47",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.1",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.267",
"versionStartIncluding": "5.10.188",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.218",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.185",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.154",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.106",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.47",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.11",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.1",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.19.291",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.4.251",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: llcp: fix OOB read and u8 offset wrap in TLV parsers\n\nnfc_llcp_parse_gb_tlv() and nfc_llcp_parse_connection_tlv() contain\nthree related bugs in their TLV parsing loops:\n\n1. \u0027offset\u0027 is declared u8 but tlv_array_len is u16. When TLV data\n advances offset past 255 it silently wraps to zero, causing\n infinite loops or double-processing of buffer data.\n\n2. Before reading tlv[0] (type) and tlv[1] (length) there is no\n check that offset+2 \u003c= tlv_array_len. A truncated TLV causes\n an OOB read of one byte past the buffer end.\n\n3. After reading the length field, the value bytes are accessed\n without checking offset+2+length \u003c= tlv_array_len. A crafted\n length=0xFF on a short buffer causes up to 255 bytes of OOB\n read past the buffer end.\n\nBoth functions are reachable without authentication via\nnfc_llcp_set_remote_gb() which feeds remote LLCP general bytes\ndirectly into nfc_llcp_parse_gb_tlv() with no additional\nvalidation.\n\nFix all three issues by widening offset from u8 to u16 and adding\nbounds checks for both the TLV header and value field before each\naccess."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T15:13:13.311Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/2c1456fe09ab1a5a9fe1d8339ca6d509589b56e1"
},
{
"url": "https://git.kernel.org/stable/c/7f6f3d087c67a4346189ef2c36481455bbc59a74"
},
{
"url": "https://git.kernel.org/stable/c/9c47d667963542c3cf8e3007b7f10c0904d08238"
},
{
"url": "https://git.kernel.org/stable/c/a209334ed929941b20810c17c3a507445b0a7c85"
},
{
"url": "https://git.kernel.org/stable/c/382eaa770335acf4f16a5a55524500f2bb4207df"
},
{
"url": "https://git.kernel.org/stable/c/2d239590d1845a706304833d40dd6d4fec20ad88"
},
{
"url": "https://git.kernel.org/stable/c/e84cdfdc4a6c88e8b751144458f2e04e24415a28"
},
{
"url": "https://git.kernel.org/stable/c/875285a165fd3b402de2ab3be0deb355d6f4caf5"
},
{
"url": "https://git.kernel.org/stable/c/78b20c8eeacd2e44a2d8a4cb5316d3c521d90911"
}
],
"title": "nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80799",
"datePublished": "2026-09-04T15:13:13.311Z",
"dateReserved": "2026-08-26T14:34:25.793Z",
"dateUpdated": "2026-09-04T15:13:13.311Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68343 (GCVE-0-2026-68343)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
smb: client: validate DFS referral PathConsumed
parse_dfs_referrals() validates that the response contains the fixed
referral entry array and, on for-next, the per-referral string offsets.
However, the response also contains a PathConsumed value that is later
used for DFS path parsing.
If a malformed response provides a PathConsumed value larger than the
search name, later DFS parsing can advance beyond the end of the path.
Validate PathConsumed against the search name length before storing it in
the parsed referral.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 4ecce920e13ace16a5ba45efe8909946c28fb2ad Version: 4ecce920e13ace16a5ba45efe8909946c28fb2ad Version: 4ecce920e13ace16a5ba45efe8909946c28fb2ad Version: 4ecce920e13ace16a5ba45efe8909946c28fb2ad Version: 4ecce920e13ace16a5ba45efe8909946c28fb2ad Version: 4ecce920e13ace16a5ba45efe8909946c28fb2ad |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/smb/client/misc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "bfebe5110fd135d86d65a0a346e14c106b02028b",
"status": "affected",
"version": "4ecce920e13ace16a5ba45efe8909946c28fb2ad",
"versionType": "git"
},
{
"lessThan": "5b439f39f33ec15d319ced3b025e122346fba987",
"status": "affected",
"version": "4ecce920e13ace16a5ba45efe8909946c28fb2ad",
"versionType": "git"
},
{
"lessThan": "285bd4a5f3f156aa5869843b47a1b1380b774241",
"status": "affected",
"version": "4ecce920e13ace16a5ba45efe8909946c28fb2ad",
"versionType": "git"
},
{
"lessThan": "2fdd6d196c656b376cc251e1e9ff110b3ed522e1",
"status": "affected",
"version": "4ecce920e13ace16a5ba45efe8909946c28fb2ad",
"versionType": "git"
},
{
"lessThan": "9f88a99ed511651b2dc2177d6854b2d1b8322e75",
"status": "affected",
"version": "4ecce920e13ace16a5ba45efe8909946c28fb2ad",
"versionType": "git"
},
{
"lessThan": "f6f5ee2aa33b350c671721b965251c42cebb962e",
"status": "affected",
"version": "4ecce920e13ace16a5ba45efe8909946c28fb2ad",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/smb/client/misc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.11"
},
{
"lessThan": "4.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: validate DFS referral PathConsumed\n\nparse_dfs_referrals() validates that the response contains the fixed\nreferral entry array and, on for-next, the per-referral string offsets.\nHowever, the response also contains a PathConsumed value that is later\nused for DFS path parsing.\n\nIf a malformed response provides a PathConsumed value larger than the\nsearch name, later DFS parsing can advance beyond the end of the path.\n\nValidate PathConsumed against the search name length before storing it in\nthe parsed referral."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The tainted PathConsumed value comes directly from a GET_DFS_REFERRAL response received over TCP/445 from the SMB server, so a malicious or MITM-positioned server on the network fully controls the input to the vulnerable code.\nAC:L - The server simply sets an oversized PathConsumed (up to 65535, and it can also clear the SMB1 UNICODE flag to select the completely unvalidated branch); the resulting out-of-bounds walk past the path buffer is deterministic and needs no race or memory-layout luck.\nPR:N - The attacker is the remote server (or a MITM on an unsigned connection) and needs no account or privilege on the victim client; the client parses the referral response as part of establishing the connection.\nUI:N - DFS referral walks are performed automatically by autofs/systemd automounts, fstab mounts at boot and reconnect-driven remounts, so a forged referral can be delivered without any user action.\nS:U - The out-of-bounds access stays within the kernel\u0027s own memory and mount context on the client; no VM, IOMMU or sandbox boundary is crossed.\nC:H - prepath = full_path + path_consumed points past the end of the heap path string, and cifs_build_devname() strlen()s and copies from there, splicing adjacent kernel heap contents (up to ~64KB away) into the constructed UNC/prefixpath that is then observable via the mount source and /proc/mounts.\nI:N - The defect is purely an out-of-bounds read; all subsequent allocations and copies are sized from the same over-read string, so no kernel memory is written or corrupted.\nA:H - With PathConsumed up to 65535 the pointer can run far past a small slab object into an unmapped or guarded page, so strlen() on it oopses the mounting task (and panics on panic_on_oops systems)."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:43.025Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/bfebe5110fd135d86d65a0a346e14c106b02028b"
},
{
"url": "https://git.kernel.org/stable/c/5b439f39f33ec15d319ced3b025e122346fba987"
},
{
"url": "https://git.kernel.org/stable/c/285bd4a5f3f156aa5869843b47a1b1380b774241"
},
{
"url": "https://git.kernel.org/stable/c/2fdd6d196c656b376cc251e1e9ff110b3ed522e1"
},
{
"url": "https://git.kernel.org/stable/c/9f88a99ed511651b2dc2177d6854b2d1b8322e75"
},
{
"url": "https://git.kernel.org/stable/c/f6f5ee2aa33b350c671721b965251c42cebb962e"
}
],
"title": "smb: client: validate DFS referral PathConsumed",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68343",
"datePublished": "2026-08-10T12:03:19.939Z",
"dateReserved": "2026-07-30T09:28:09.384Z",
"dateUpdated": "2026-08-19T16:33:43.025Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2025-39901 (GCVE-0-2025-39901)
Vulnerability from cvelistv5
Published
2025-10-01 07:42
Modified
2026-08-19 16:27
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
i40e: remove read access to debugfs files
The 'command' and 'netdev_ops' debugfs files are a legacy debugging
interface supported by the i40e driver since its early days by commit
02e9c290814c ("i40e: debugfs interface").
Both of these debugfs files provide a read handler which is mostly useless,
and which is implemented with questionable logic. They both use a static
256 byte buffer which is initialized to the empty string. In the case of
the 'command' file this buffer is literally never used and simply wastes
space. In the case of the 'netdev_ops' file, the last command written is
saved here.
On read, the files contents are presented as the name of the device
followed by a colon and then the contents of their respective static
buffer. For 'command' this will always be "<device>: ". For 'netdev_ops',
this will be "<device>: <last command written>". But note the buffer is
shared between all devices operated by this module. At best, it is mostly
meaningless information, and at worse it could be accessed simultaneously
as there doesn't appear to be any locking mechanism.
We have also recently received multiple reports for both read functions
about their use of snprintf and potential overflow that could result in
reading arbitrary kernel memory. For the 'command' file, this is definitely
impossible, since the static buffer is always zero and never written to.
For the 'netdev_ops' file, it does appear to be possible, if the user
carefully crafts the command input, it will be copied into the buffer,
which could be large enough to cause snprintf to truncate, which then
causes the copy_to_user to read beyond the length of the buffer allocated
by kzalloc.
A minimal fix would be to replace snprintf() with scnprintf() which would
cap the return to the number of bytes written, preventing an overflow. A
more involved fix would be to drop the mostly useless static buffers,
saving 512 bytes and modifying the read functions to stop needing those as
input.
Instead, lets just completely drop the read access to these files. These
are debug interfaces exposed as part of debugfs, and I don't believe that
dropping read access will break any script, as the provided output is
pretty useless. You can find the netdev name through other more standard
interfaces, and the 'netdev_ops' interface can easily result in garbage if
you issue simultaneous writes to multiple devices at once.
In order to properly remove the i40e_dbg_netdev_ops_buf, we need to
refactor its write function to avoid using the static buffer. Instead, use
the same logic as the i40e_dbg_command_write, with an allocated buffer.
Update the code to use this instead of the static buffer, and ensure we
free the buffer on exit. This fixes simultaneous writes to 'netdev_ops' on
multiple devices, and allows us to remove the now unused static buffer
along with removing the read access.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"adp": [
{
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
}
},
{
"other": {
"content": {
"id": "CVE-2025-39901",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-01-14T19:29:38.664446Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-125",
"description": "CWE-125 Out-of-bounds Read",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-01-14T19:33:14.407Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/intel/i40e/i40e_debugfs.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "6fd8b30a5cb84d74015bc651799d1ab1e047946c",
"status": "affected",
"version": "02e9c290814cc143ceccecb14eac3e7a05da745e",
"versionType": "git"
},
{
"lessThan": "ef40d9411469306e524e7887c51b709377e6ef65",
"status": "affected",
"version": "02e9c290814cc143ceccecb14eac3e7a05da745e",
"versionType": "git"
},
{
"lessThan": "70d3dad7d5ad077965d7a63eed1942b7ba49bfb4",
"status": "affected",
"version": "02e9c290814cc143ceccecb14eac3e7a05da745e",
"versionType": "git"
},
{
"lessThan": "7d190963b80f4cd99d7008615600aa7cc993c6ba",
"status": "affected",
"version": "02e9c290814cc143ceccecb14eac3e7a05da745e",
"versionType": "git"
},
{
"lessThan": "9fcdb1c3c4ba134434694c001dbff343f1ffa319",
"status": "affected",
"version": "02e9c290814cc143ceccecb14eac3e7a05da745e",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/intel/i40e/i40e_debugfs.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.12"
},
{
"lessThan": "3.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.16.*",
"status": "unaffected",
"version": "6.16.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "6.17",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.46",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.16.6",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.17",
"versionStartIncluding": "3.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ni40e: remove read access to debugfs files\n\nThe \u0027command\u0027 and \u0027netdev_ops\u0027 debugfs files are a legacy debugging\ninterface supported by the i40e driver since its early days by commit\n02e9c290814c (\"i40e: debugfs interface\").\n\nBoth of these debugfs files provide a read handler which is mostly useless,\nand which is implemented with questionable logic. They both use a static\n256 byte buffer which is initialized to the empty string. In the case of\nthe \u0027command\u0027 file this buffer is literally never used and simply wastes\nspace. In the case of the \u0027netdev_ops\u0027 file, the last command written is\nsaved here.\n\nOn read, the files contents are presented as the name of the device\nfollowed by a colon and then the contents of their respective static\nbuffer. For \u0027command\u0027 this will always be \"\u003cdevice\u003e: \". For \u0027netdev_ops\u0027,\nthis will be \"\u003cdevice\u003e: \u003clast command written\u003e\". But note the buffer is\nshared between all devices operated by this module. At best, it is mostly\nmeaningless information, and at worse it could be accessed simultaneously\nas there doesn\u0027t appear to be any locking mechanism.\n\nWe have also recently received multiple reports for both read functions\nabout their use of snprintf and potential overflow that could result in\nreading arbitrary kernel memory. For the \u0027command\u0027 file, this is definitely\nimpossible, since the static buffer is always zero and never written to.\nFor the \u0027netdev_ops\u0027 file, it does appear to be possible, if the user\ncarefully crafts the command input, it will be copied into the buffer,\nwhich could be large enough to cause snprintf to truncate, which then\ncauses the copy_to_user to read beyond the length of the buffer allocated\nby kzalloc.\n\nA minimal fix would be to replace snprintf() with scnprintf() which would\ncap the return to the number of bytes written, preventing an overflow. A\nmore involved fix would be to drop the mostly useless static buffers,\nsaving 512 bytes and modifying the read functions to stop needing those as\ninput.\n\nInstead, lets just completely drop the read access to these files. These\nare debug interfaces exposed as part of debugfs, and I don\u0027t believe that\ndropping read access will break any script, as the provided output is\npretty useless. You can find the netdev name through other more standard\ninterfaces, and the \u0027netdev_ops\u0027 interface can easily result in garbage if\nyou issue simultaneous writes to multiple devices at once.\n\nIn order to properly remove the i40e_dbg_netdev_ops_buf, we need to\nrefactor its write function to avoid using the static buffer. Instead, use\nthe same logic as the i40e_dbg_command_write, with an allocated buffer.\nUpdate the code to use this instead of the static buffer, and ensure we\nfree the buffer on exit. This fixes simultaneous writes to \u0027netdev_ops\u0027 on\nmultiple devices, and allows us to remove the now unused static buffer\nalong with removing the read access."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:27:49.963Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/6fd8b30a5cb84d74015bc651799d1ab1e047946c"
},
{
"url": "https://git.kernel.org/stable/c/ef40d9411469306e524e7887c51b709377e6ef65"
},
{
"url": "https://git.kernel.org/stable/c/70d3dad7d5ad077965d7a63eed1942b7ba49bfb4"
},
{
"url": "https://git.kernel.org/stable/c/7d190963b80f4cd99d7008615600aa7cc993c6ba"
},
{
"url": "https://git.kernel.org/stable/c/9fcdb1c3c4ba134434694c001dbff343f1ffa319"
}
],
"title": "i40e: remove read access to debugfs files",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2025-39901",
"datePublished": "2025-10-01T07:42:48.606Z",
"dateReserved": "2025-04-16T07:20:57.146Z",
"dateUpdated": "2026-08-19T16:27:49.963Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68376 (GCVE-0-2026-68376)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
sctp: fix auth_hmacs array size in struct sctp_cookie
The auth_hmacs array in struct sctp_cookie is supposed to store a complete
SCTP_AUTH_HMAC_ALGO parameter, which consists of a struct sctp_paramhdr
followed by N HMAC identifiers.
However, the array size was calculated using an extra 2 bytes instead of
sizeof(struct sctp_paramhdr), which is 4 bytes. When four HMAC identifiers
are configured, the HMAC-ALGO parameter stored in the endpoint is larger
than the auth_hmacs buffer in the cookie.
As a result, sctp_association_init() copies beyond the end of auth_hmacs
when initializing the association, corrupting the adjacent auth_chunks
field. This can lead to an invalid HMAC identifier being accepted and later
cause an out-of-bounds read in sctp_auth_get_hmac().
Fix the array size calculation by including the full SCTP parameter header
size.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1f485649f52929d9937b346a920a522a7363e202 Version: 1f485649f52929d9937b346a920a522a7363e202 Version: 1f485649f52929d9937b346a920a522a7363e202 Version: 1f485649f52929d9937b346a920a522a7363e202 Version: 1f485649f52929d9937b346a920a522a7363e202 Version: 1f485649f52929d9937b346a920a522a7363e202 Version: 1f485649f52929d9937b346a920a522a7363e202 Version: 1f485649f52929d9937b346a920a522a7363e202 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"include/net/sctp/structs.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "317731d01b03c529809df36d3a7d149677a8729d",
"status": "affected",
"version": "1f485649f52929d9937b346a920a522a7363e202",
"versionType": "git"
},
{
"lessThan": "0528485f27016a42804abe01aa61b39d85fa803e",
"status": "affected",
"version": "1f485649f52929d9937b346a920a522a7363e202",
"versionType": "git"
},
{
"lessThan": "ee5e65964f456adfe14d526fba0bd055de98ecf3",
"status": "affected",
"version": "1f485649f52929d9937b346a920a522a7363e202",
"versionType": "git"
},
{
"lessThan": "0b4414e43e0861d67276031cc21401d7e87de3da",
"status": "affected",
"version": "1f485649f52929d9937b346a920a522a7363e202",
"versionType": "git"
},
{
"lessThan": "d0a59ba58578e2b330fff80a44fe519f3ba7d8c7",
"status": "affected",
"version": "1f485649f52929d9937b346a920a522a7363e202",
"versionType": "git"
},
{
"lessThan": "a8d20ba0ab518c9ccbcde258f25fc1ee6e51d5db",
"status": "affected",
"version": "1f485649f52929d9937b346a920a522a7363e202",
"versionType": "git"
},
{
"lessThan": "3aa40c3bccac2312ea7cf97f329190637f972b5d",
"status": "affected",
"version": "1f485649f52929d9937b346a920a522a7363e202",
"versionType": "git"
},
{
"lessThan": "e0b5252a59383b77d1b8dbeda00b7184dd95f4d3",
"status": "affected",
"version": "1f485649f52929d9937b346a920a522a7363e202",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"include/net/sctp/structs.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.24"
},
{
"lessThan": "2.6.24",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.24",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: fix auth_hmacs array size in struct sctp_cookie\n\nThe auth_hmacs array in struct sctp_cookie is supposed to store a complete\nSCTP_AUTH_HMAC_ALGO parameter, which consists of a struct sctp_paramhdr\nfollowed by N HMAC identifiers.\n\nHowever, the array size was calculated using an extra 2 bytes instead of\nsizeof(struct sctp_paramhdr), which is 4 bytes. When four HMAC identifiers\nare configured, the HMAC-ALGO parameter stored in the endpoint is larger\nthan the auth_hmacs buffer in the cookie.\n\nAs a result, sctp_association_init() copies beyond the end of auth_hmacs\nwhen initializing the association, corrupting the adjacent auth_chunks\nfield. This can lead to an invalid HMAC identifier being accepted and later\ncause an out-of-bounds read in sctp_auth_get_hmac().\n\nFix the array size calculation by including the full SCTP parameter header\nsize."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The out-of-bounds index is taken directly from the `hmac_id` field of an AUTH chunk received from a remote SCTP peer and processed in sctp_sf_eat_auth()/sctp_sf_authenticate(), which is the normal SCTP packet-receive path in net/sctp.\nAC:H - The overflow only occurs when the victim endpoint was configured with exactly four HMAC identifiers via setsockopt(SCTP_HMAC_IDENT); three or fewer fit the buffer exactly. That local socket configuration is beyond a remote attacker\u0027s control, though a local user can arrange it and then attack over loopback.\nPR:N - Once the endpoint is so configured, any peer that completes an ordinary SCTP handshake can send the malformed AUTH chunk; the bogus hmac_id is accepted and dereferenced before any shared-key or HMAC verification, so no credentials of any kind are needed.\nUI:N - The AUTH chunk is consumed automatically by the kernel SCTP state machine on packet receipt; no action by any local user or administrator is needed at attack time.\nS:U - The corruption and the subsequent out-of-bounds accesses are confined to kernel memory within the same security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - sctp_auth_get_hmac() reads far past the 4-entry sctp_hmac_list, and on kernels before the HMAC library conversion sctp_auth_calculate_hmac() reads a function-table pointer ~262 KB beyond the 4-pointer ep-\u003eauth_hmacs heap array; the accepted/rejected signature length acts as an oracle leaking the out-of-bounds value.\nI:H - The wild crypto_shash pointer fetched out of bounds is passed straight to crypto_shash_setkey()/crypto_shash_tfm_digest(), giving an attacker-groomable indirect call and write target; on current kernels a fixed 32-byte HMAC is written into a digest area sized from out-of-bounds data.\nA:H - Dereferencing an out-of-bounds heap pointer as a crypto transform, or writing a 32-byte digest into an undersized skb region, reliably oopses or panics the kernel, and the attack can be repeated on every association."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:35.759Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/317731d01b03c529809df36d3a7d149677a8729d"
},
{
"url": "https://git.kernel.org/stable/c/0528485f27016a42804abe01aa61b39d85fa803e"
},
{
"url": "https://git.kernel.org/stable/c/ee5e65964f456adfe14d526fba0bd055de98ecf3"
},
{
"url": "https://git.kernel.org/stable/c/0b4414e43e0861d67276031cc21401d7e87de3da"
},
{
"url": "https://git.kernel.org/stable/c/d0a59ba58578e2b330fff80a44fe519f3ba7d8c7"
},
{
"url": "https://git.kernel.org/stable/c/a8d20ba0ab518c9ccbcde258f25fc1ee6e51d5db"
},
{
"url": "https://git.kernel.org/stable/c/3aa40c3bccac2312ea7cf97f329190637f972b5d"
},
{
"url": "https://git.kernel.org/stable/c/e0b5252a59383b77d1b8dbeda00b7184dd95f4d3"
}
],
"title": "sctp: fix auth_hmacs array size in struct sctp_cookie",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68376",
"datePublished": "2026-08-10T12:03:54.666Z",
"dateReserved": "2026-07-30T09:28:09.386Z",
"dateUpdated": "2026-08-19T16:34:35.759Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74672 (GCVE-0-2026-74672)
Vulnerability from cvelistv5
Published
2026-08-22 15:32
Modified
2026-08-23 12:47
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
mm/vmalloc: acquire init_mm lock on huge vmap to avoid ptdump UAF
Patch series "mm: fix UAF caused by race between ptdump and vmap pgtable
freeing", v6.
Kernel page table walkers fall into two broad categories - those ranges
where no exclusion is required via walk_kernel_page_table_range_lockless()
and those where exclusion is required via walk_kernel_page_table_range()
or walk_page_range_debug().
The former category is used only by arm64 arch code operating on ranges it
both wholly owns and does not concurrently write.
The latter category consists of kernel page table walkers operating on
ranges that are wholly owned (but which need exclusion against concurrent
writers).
The lock used for exclusion is the mmap lock, and for kernel ranges this
is the mmap lock on init_mm.
ptdump is a special case being both the only user of
walk_page_range_debug(), and the only case in which it walks ranges it
does not own.
This presents a problem, as page tables may be freed under ptdump. And
indeed there is a use-after-free bug in the kernel as a result, which this
series addresses.
vmap promotes page tables to huge leaf entries where possible, freeing the
lower page table when it does. It does this with no meaningful locks held
against concurrent ptdump walks.
As a result, use-after-free can currently occur. This series addresses
the issue by having the vmap huge promotion logic acquire the mmap read
lock while both setting the huge page table entry and freeing the prior
leaf page table.
The ptdump code already acquires the mmap write lock, so by doing so we
ensure that the ptdump walker only ever observes either the huge page
table entry or the existing page table entry, and nothing is freed
underneath it.
A mitigation for this issue was already applied for arm64 in commit
fa93b45fd397 ("arm64: Enable vmalloc-huge with ptdump"), which this series
has to deal with carefully.
This mitigation resolves the issue by acquiring the mmap read lock on
init_mm on vmap page table free if a ptdump is in progress.
However the fix in this series would cause a deadlock if we were to simply
apply it for arm64 without also reverting the change.
This is because vmap may acquire the read lock before ptdump attempts to
acquire the write lock, which then gets queued, and rwsem starvation rules
mean that the (unacknowledged) nested mmap read lock in the arm64 code
would also block, meaning the original read lock is never released and
thus deadlock.
This series works around this by #ifndef CONFIG_ARM64'ing the mmap read
lock in vmap logic, then partially reverting commit fa93b45fd397 ("arm64:
Enable vmalloc-huge with ptdump"), keeping the enablement of huge vmap
support, and removing the ifdeffery with the partial revert patch.
There are related issues that are also addressed in this series:
* x86 page attribute logic, specifically Change Page Attributes (CPA),
implements a feature whereby huge ranges can be collapsed into huge leaf
entries. This can similarly cause a UAF when done in parallel with a
ptdump walk, so similarly acquire the init_mm mmap lock to avoid this.
* The CPA logic allows concurrent page table manipulation and CPA
collapse, meaning the former risks accessing a page table the latter
frees. Fix this by acquiring mmap write lock on init_mm across the
whole CPA collapse operation and read lock on the page table
manipulation.
* x86 and arm64 permit walks of non-kernel mm's (both allowing efi mm
walks, and in x86's case arbitrary mm's), so we ensure kernel mappings
remain stable by locking the init_mm as well as the mm being walked.
The ordering of patches is established for both strict dependencies (the
arm64 partial revert in particular has to be done after the vmap changes)
and logical ones (the non-kernel mm fix only makes sense once the vmap/CPA
fixes are in place).
This patch (of 3):
Currently there is a nasty ra
---truncated---
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: b6bdb7517c3d3f41f20e5c2948d6bc3f8897394e Version: b6bdb7517c3d3f41f20e5c2948d6bc3f8897394e Version: b6bdb7517c3d3f41f20e5c2948d6bc3f8897394e Version: b6bdb7517c3d3f41f20e5c2948d6bc3f8897394e Version: b6bdb7517c3d3f41f20e5c2948d6bc3f8897394e Version: b6bdb7517c3d3f41f20e5c2948d6bc3f8897394e Version: 31895cfd79564111cdd5a9f48c5d491ae26a238e Version: 9c7f7bdb1932f8c1e5f80d32c717184701afe701 Version: acdb4981644c8e31ccee294bdefff475c0cf587b Version: 0454e2fad9306961540ee7e84da47a8e345b7d22 Version: 4.4.125 ≤ Version: 4.9.91 ≤ Version: 4.14.31 ≤ Version: 4.15.14 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"include/linux/mmap_lock.h",
"mm/pagewalk.c",
"mm/vmalloc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "39c6772b56a6bbdd62794833f74232971d94d7c9",
"status": "affected",
"version": "b6bdb7517c3d3f41f20e5c2948d6bc3f8897394e",
"versionType": "git"
},
{
"lessThan": "8d7f560f4b0482d469de962fbe4b59c37561052e",
"status": "affected",
"version": "b6bdb7517c3d3f41f20e5c2948d6bc3f8897394e",
"versionType": "git"
},
{
"lessThan": "7ac8a333dd41ba5e1b4e8c6edbc48b15446c5468",
"status": "affected",
"version": "b6bdb7517c3d3f41f20e5c2948d6bc3f8897394e",
"versionType": "git"
},
{
"lessThan": "c5bf8cd148cfea948cfa3db71da427294b20db0f",
"status": "affected",
"version": "b6bdb7517c3d3f41f20e5c2948d6bc3f8897394e",
"versionType": "git"
},
{
"lessThan": "3cc26c8907db0f5d1ff8043b5851ee572e9b3c98",
"status": "affected",
"version": "b6bdb7517c3d3f41f20e5c2948d6bc3f8897394e",
"versionType": "git"
},
{
"lessThan": "26444eb71465c9934d9d418ef69c43f61185329b",
"status": "affected",
"version": "b6bdb7517c3d3f41f20e5c2948d6bc3f8897394e",
"versionType": "git"
},
{
"status": "affected",
"version": "31895cfd79564111cdd5a9f48c5d491ae26a238e",
"versionType": "git"
},
{
"status": "affected",
"version": "9c7f7bdb1932f8c1e5f80d32c717184701afe701",
"versionType": "git"
},
{
"status": "affected",
"version": "acdb4981644c8e31ccee294bdefff475c0cf587b",
"versionType": "git"
},
{
"status": "affected",
"version": "0454e2fad9306961540ee7e84da47a8e345b7d22",
"versionType": "git"
},
{
"lessThan": "4.5",
"status": "affected",
"version": "4.4.125",
"versionType": "semver"
},
{
"lessThan": "4.10",
"status": "affected",
"version": "4.9.91",
"versionType": "semver"
},
{
"lessThan": "4.15",
"status": "affected",
"version": "4.14.31",
"versionType": "semver"
},
{
"lessThan": "4.16",
"status": "affected",
"version": "4.15.14",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"include/linux/mmap_lock.h",
"mm/pagewalk.c",
"mm/vmalloc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.16"
},
{
"lessThan": "4.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "4.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "4.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "4.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "4.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "4.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.4.125",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.9.91",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.14.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.15.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/vmalloc: acquire init_mm lock on huge vmap to avoid ptdump UAF\n\nPatch series \"mm: fix UAF caused by race between ptdump and vmap pgtable\nfreeing\", v6.\n\nKernel page table walkers fall into two broad categories - those ranges\nwhere no exclusion is required via walk_kernel_page_table_range_lockless()\nand those where exclusion is required via walk_kernel_page_table_range()\nor walk_page_range_debug().\n\nThe former category is used only by arm64 arch code operating on ranges it\nboth wholly owns and does not concurrently write.\n\nThe latter category consists of kernel page table walkers operating on\nranges that are wholly owned (but which need exclusion against concurrent\nwriters).\n\nThe lock used for exclusion is the mmap lock, and for kernel ranges this\nis the mmap lock on init_mm.\n\nptdump is a special case being both the only user of\nwalk_page_range_debug(), and the only case in which it walks ranges it\ndoes not own.\n\nThis presents a problem, as page tables may be freed under ptdump. And\nindeed there is a use-after-free bug in the kernel as a result, which this\nseries addresses.\n\nvmap promotes page tables to huge leaf entries where possible, freeing the\nlower page table when it does. It does this with no meaningful locks held\nagainst concurrent ptdump walks.\n\nAs a result, use-after-free can currently occur. This series addresses\nthe issue by having the vmap huge promotion logic acquire the mmap read\nlock while both setting the huge page table entry and freeing the prior\nleaf page table.\n\nThe ptdump code already acquires the mmap write lock, so by doing so we\nensure that the ptdump walker only ever observes either the huge page\ntable entry or the existing page table entry, and nothing is freed\nunderneath it.\n\nA mitigation for this issue was already applied for arm64 in commit\nfa93b45fd397 (\"arm64: Enable vmalloc-huge with ptdump\"), which this series\nhas to deal with carefully.\n\nThis mitigation resolves the issue by acquiring the mmap read lock on\ninit_mm on vmap page table free if a ptdump is in progress.\n\nHowever the fix in this series would cause a deadlock if we were to simply\napply it for arm64 without also reverting the change.\n\nThis is because vmap may acquire the read lock before ptdump attempts to\nacquire the write lock, which then gets queued, and rwsem starvation rules\nmean that the (unacknowledged) nested mmap read lock in the arm64 code\nwould also block, meaning the original read lock is never released and\nthus deadlock.\n\nThis series works around this by #ifndef CONFIG_ARM64\u0027ing the mmap read\nlock in vmap logic, then partially reverting commit fa93b45fd397 (\"arm64:\nEnable vmalloc-huge with ptdump\"), keeping the enablement of huge vmap\nsupport, and removing the ifdeffery with the partial revert patch.\n\nThere are related issues that are also addressed in this series:\n\n* x86 page attribute logic, specifically Change Page Attributes (CPA),\n implements a feature whereby huge ranges can be collapsed into huge leaf\n entries. This can similarly cause a UAF when done in parallel with a\n ptdump walk, so similarly acquire the init_mm mmap lock to avoid this.\n\n* The CPA logic allows concurrent page table manipulation and CPA\n collapse, meaning the former risks accessing a page table the latter\n frees. Fix this by acquiring mmap write lock on init_mm across the\n whole CPA collapse operation and read lock on the page table\n manipulation.\n\n* x86 and arm64 permit walks of non-kernel mm\u0027s (both allowing efi mm\n walks, and in x86\u0027s case arbitrary mm\u0027s), so we ensure kernel mappings\n remain stable by locking the init_mm as well as the mm being walked.\n\nThe ordering of patches is established for both strict dependencies (the\narm64 partial revert in particular has to be done after the vmap changes)\nand logical ones (the non-kernel mm fix only makes sense once the vmap/CPA\nfixes are in place).\n\n\nThis patch (of 3):\n\nCurrently there is a nasty ra\n---truncated---"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:47:58.392Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/39c6772b56a6bbdd62794833f74232971d94d7c9"
},
{
"url": "https://git.kernel.org/stable/c/8d7f560f4b0482d469de962fbe4b59c37561052e"
},
{
"url": "https://git.kernel.org/stable/c/7ac8a333dd41ba5e1b4e8c6edbc48b15446c5468"
},
{
"url": "https://git.kernel.org/stable/c/c5bf8cd148cfea948cfa3db71da427294b20db0f"
},
{
"url": "https://git.kernel.org/stable/c/3cc26c8907db0f5d1ff8043b5851ee572e9b3c98"
},
{
"url": "https://git.kernel.org/stable/c/26444eb71465c9934d9d418ef69c43f61185329b"
}
],
"title": "mm/vmalloc: acquire init_mm lock on huge vmap to avoid ptdump UAF",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74672",
"datePublished": "2026-08-22T15:32:42.210Z",
"dateReserved": "2026-08-15T05:44:03.925Z",
"dateUpdated": "2026-08-23T12:47:58.392Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74467 (GCVE-0-2026-74467)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-19 16:37
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
s390/qeth: Check CAP_NET_ADMIN for private ioctls
Gate the SIOCDEVPRIVATE ioctl commands SIOC_QETH_ADP_SET_SNMP_CONTROL,
SIOC_QETH_GET_CARD_TYPE and SIOC_QETH_QUERY_OAT with CAP_NET_ADMIN
capable check to ensure unprivileged users cannot invoke them.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 18787eeebd7129ecf4960876d24f349682207783 Version: 18787eeebd7129ecf4960876d24f349682207783 Version: 18787eeebd7129ecf4960876d24f349682207783 Version: 18787eeebd7129ecf4960876d24f349682207783 Version: 18787eeebd7129ecf4960876d24f349682207783 Version: 18787eeebd7129ecf4960876d24f349682207783 Version: 18787eeebd7129ecf4960876d24f349682207783 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/s390/net/qeth_core_main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "8fb69547924bbb3d7c900a0d7d137a7234db3f5f",
"status": "affected",
"version": "18787eeebd7129ecf4960876d24f349682207783",
"versionType": "git"
},
{
"lessThan": "3ea5210db058347481c93849786982f874f7be2d",
"status": "affected",
"version": "18787eeebd7129ecf4960876d24f349682207783",
"versionType": "git"
},
{
"lessThan": "4e48168825818bf4a13c743582227d15f1d30d04",
"status": "affected",
"version": "18787eeebd7129ecf4960876d24f349682207783",
"versionType": "git"
},
{
"lessThan": "b40c74262f7e1e601221cebccdbdb2b392ff9976",
"status": "affected",
"version": "18787eeebd7129ecf4960876d24f349682207783",
"versionType": "git"
},
{
"lessThan": "bd63c7879eaa87f1958f7ee027813356fcd9ff11",
"status": "affected",
"version": "18787eeebd7129ecf4960876d24f349682207783",
"versionType": "git"
},
{
"lessThan": "93a0a846ec59a88e0c402878a15357a5ce430eb4",
"status": "affected",
"version": "18787eeebd7129ecf4960876d24f349682207783",
"versionType": "git"
},
{
"lessThan": "d211028bac1bd0fff0026bfa2a8328e5b78cd0e6",
"status": "affected",
"version": "18787eeebd7129ecf4960876d24f349682207783",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/s390/net/qeth_core_main.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.15"
},
{
"lessThan": "5.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/qeth: Check CAP_NET_ADMIN for private ioctls\n\nGate the SIOCDEVPRIVATE ioctl commands SIOC_QETH_ADP_SET_SNMP_CONTROL,\nSIOC_QETH_GET_CARD_TYPE and SIOC_QETH_QUERY_OAT with CAP_NET_ADMIN\ncapable check to ensure unprivileged users cannot invoke them."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires a local ioctl(2) on a qeth network interface via socket(SIOCDEVPRIVATE+5..+7); the path is sock_ioctl() -\u003e dev_ioctl() -\u003e dev_siocdevprivate() -\u003e qeth_siocdevprivate() with no remote packet or network protocol entry point.\nAC:L - Any local user who can open an AF_INET socket and name a qeth netdev can invoke these ioctls deterministically; no races, special memory layout, or rare kernel configuration is required beyond s390 hardware with qeth present.\nPR:L - The bug is missing CAP_NET_ADMIN in qeth_siocdevprivate(); generic SIOCDEVPRIVATE handling in dev_ioctl() performs no capability check, so any unprivileged local account on an IBM Z/LinuxONE LPAR can reach these handlers without root or namespace-granted admin rights.\nUI:N - Exploitation needs only the attacker opening a socket and issuing ioctl against a qeth interface; no victim login, mount, or other interactive action is required on a shared mainframe guest.\nS:U - Impact stays within kernel/driver control of the local OSA/QDIO adapter and does not cross a VM, container, or IOMMU security boundary; this is standard local privilege and hardware-management misuse, not a guest-to-host escape.\nC:H - SIOC_QETH_QUERY_OAT and SIOC_QETH_ADP_SET_SNMP_CONTROL copy OSA Express firmware response buffers (link attributes, adapter operational data, SNMP MIB objects, card-type details) to unprivileged userspace, disclosing network hardware management information normally restricted to administrators.\nI:H - SIOC_QETH_ADP_SET_SNMP_CONTROL accepts attacker-controlled qeth_snmp_cmd request/data and forwards IPA_SETADP_SET_SNMP_CONTROL commands to OSA firmware, letting unprivileged users alter adapter SNMP/management state on production IBM Z network interfaces.\nA:H - Handlers honor attacker-chosen buffer sizes (kzalloc(udata_len) in qeth_snmp_command and vzalloc(buffer_len) in qeth_query_oat_command without upper bounds), enabling repeated large allocations for kernel memory exhaustion/OOM, and malformed IPA commands can disrupt adapter operation."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:37:10.278Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/8fb69547924bbb3d7c900a0d7d137a7234db3f5f"
},
{
"url": "https://git.kernel.org/stable/c/3ea5210db058347481c93849786982f874f7be2d"
},
{
"url": "https://git.kernel.org/stable/c/4e48168825818bf4a13c743582227d15f1d30d04"
},
{
"url": "https://git.kernel.org/stable/c/b40c74262f7e1e601221cebccdbdb2b392ff9976"
},
{
"url": "https://git.kernel.org/stable/c/bd63c7879eaa87f1958f7ee027813356fcd9ff11"
},
{
"url": "https://git.kernel.org/stable/c/93a0a846ec59a88e0c402878a15357a5ce430eb4"
},
{
"url": "https://git.kernel.org/stable/c/d211028bac1bd0fff0026bfa2a8328e5b78cd0e6"
}
],
"title": "s390/qeth: Check CAP_NET_ADMIN for private ioctls",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74467",
"datePublished": "2026-08-15T12:27:05.635Z",
"dateReserved": "2026-08-15T05:44:03.902Z",
"dateUpdated": "2026-08-19T16:37:10.278Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74476 (GCVE-0-2026-74476)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-23 12:47
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
veth: convert frag_list skbs before running XDP
A frag_list skb can reach veth with data_len set but nr_frags zero.
veth_convert_skb_to_xdp_buff() only converts skbs that are shared,
locked, have frags[], or do not have enough headroom. It later uses
skb_is_nonlinear() to decide whether to set XDP_FLAGS_HAS_FRAGS and
xdp_frags_size.
That exposes frag_list data to XDP as if it were stored in frags[], but
frags[] is empty. AF_XDP copy mode can then trust the bogus XDP fragment
metadata, walk an empty fragment entry, and crash in memcpy() from
__xsk_rcv().
Route non-linear skbs through skb_pp_cow_data() before exposing them to
XDP, and only advertise XDP frags when the resulting skb has frags[].
skb_copy_bits() already handles frag_list input, and skb_pp_cow_data()
builds frags[] output with skb_add_rx_frag(), which is the
representation XDP multi-buffer expects.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 718a18a0c8a67f97781e40bdef7cdd055c430996 Version: 718a18a0c8a67f97781e40bdef7cdd055c430996 Version: 718a18a0c8a67f97781e40bdef7cdd055c430996 Version: 718a18a0c8a67f97781e40bdef7cdd055c430996 Version: 718a18a0c8a67f97781e40bdef7cdd055c430996 Version: 718a18a0c8a67f97781e40bdef7cdd055c430996 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/veth.c",
"net/core/skbuff.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "0be3632597b8349d43a7dc4244b492dc62a05998",
"status": "affected",
"version": "718a18a0c8a67f97781e40bdef7cdd055c430996",
"versionType": "git"
},
{
"lessThan": "04958dba44dc795dc79ce2fcbc117821bbbd6542",
"status": "affected",
"version": "718a18a0c8a67f97781e40bdef7cdd055c430996",
"versionType": "git"
},
{
"lessThan": "5c1c15c540fc45820ce3033c319151ec891bc10a",
"status": "affected",
"version": "718a18a0c8a67f97781e40bdef7cdd055c430996",
"versionType": "git"
},
{
"lessThan": "b24ba0bbffe3e23eb2f6838881c1fabcb29fb9fb",
"status": "affected",
"version": "718a18a0c8a67f97781e40bdef7cdd055c430996",
"versionType": "git"
},
{
"lessThan": "f9c1fff857e93be709c8b52ed1a643f37bd82c66",
"status": "affected",
"version": "718a18a0c8a67f97781e40bdef7cdd055c430996",
"versionType": "git"
},
{
"lessThan": "d0d6415963040c401e7a7e4e482a698ba52448cb",
"status": "affected",
"version": "718a18a0c8a67f97781e40bdef7cdd055c430996",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/veth.c",
"net/core/skbuff.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.18"
},
{
"lessThan": "5.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.18",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nveth: convert frag_list skbs before running XDP\n\nA frag_list skb can reach veth with data_len set but nr_frags zero.\nveth_convert_skb_to_xdp_buff() only converts skbs that are shared,\nlocked, have frags[], or do not have enough headroom. It later uses\nskb_is_nonlinear() to decide whether to set XDP_FLAGS_HAS_FRAGS and\nxdp_frags_size.\n\nThat exposes frag_list data to XDP as if it were stored in frags[], but\nfrags[] is empty. AF_XDP copy mode can then trust the bogus XDP fragment\nmetadata, walk an empty fragment entry, and crash in memcpy() from\n__xsk_rcv().\n\nRoute non-linear skbs through skb_pp_cow_data() before exposing them to\nXDP, and only advertise XDP frags when the resulting skb has frags[].\nskb_copy_bits() already handles frag_list input, and skb_pp_cow_data()\nbuilds frags[] output with skb_add_rx_frag(), which is the\nrepresentation XDP multi-buffer expects."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug is hit when a received skb traverses veth XDP processing; in cloud/container deployments (e.g. Cloudflare-style edge nodes) remote traffic routed to a veth peer with XDP+AF_XDP can deliver the malformed frag_list skb without local access.\nAC:L - An attacker can reliably supply the required frag_list skb (data_len\u003e0, nr_frags=0) by transmitting from the veth peer via sockets or GRO aggregation, controlling packet size, timing, and content without depending on uncontrollable kernel state.\nPR:N - Remote exploitation needs no attacker privileges when ingress traffic reaches a veth that already has an XDP program redirecting to an AF_XDP socket; only network-delivered skbs trigger veth_convert_skb_to_xdp_buff() and the faulty __xsk_rcv() path.\nUI:N - No victim user action is required beyond normal network traffic reaching the veth interface; exploitation is automatic once a qualifying frag_list skb is received and redirected to AF_XDP copy mode.\nS:U - The flaw causes kernel memory reads and crashes within the host kernel security boundary; it does not cross VM, hypervisor, or IOMMU isolation boundaries.\nC:H - Bogus XDP_FLAGS_HAS_FRAGS metadata makes __xsk_rcv() memcpy from uninitialized frags[] entries via skb_frag_address(), enabling out-of-bounds kernel memory reads into the AF_XDP receive buffer before faulting.\nI:N - The failure mode is a kernel-side memcpy read using invalid fragment metadata; data is copied into the attacker\u0027s AF_XDP ring buffer rather than corrupting kernel or other tenants\u0027 memory for integrity purposes.\nA:H - The commit and code path confirm a kernel crash when __xsk_rcv() follows bogus fragment metadata and memcpy faults on an invalid frags[] source address, causing oops/panic and denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:47:22.315Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/0be3632597b8349d43a7dc4244b492dc62a05998"
},
{
"url": "https://git.kernel.org/stable/c/04958dba44dc795dc79ce2fcbc117821bbbd6542"
},
{
"url": "https://git.kernel.org/stable/c/5c1c15c540fc45820ce3033c319151ec891bc10a"
},
{
"url": "https://git.kernel.org/stable/c/b24ba0bbffe3e23eb2f6838881c1fabcb29fb9fb"
},
{
"url": "https://git.kernel.org/stable/c/f9c1fff857e93be709c8b52ed1a643f37bd82c66"
},
{
"url": "https://git.kernel.org/stable/c/d0d6415963040c401e7a7e4e482a698ba52448cb"
}
],
"title": "veth: convert frag_list skbs before running XDP",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74476",
"datePublished": "2026-08-15T12:27:11.309Z",
"dateReserved": "2026-08-15T05:44:03.903Z",
"dateUpdated": "2026-08-23T12:47:22.315Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74478 (GCVE-0-2026-74478)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-19 16:37
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
um: vector: fix use-after-free in vector_mmsg_rx()
When vector_mmsg_rx() discards a packet whose overlay header fails
verify_header(), it frees the skb and continues the loop:
if (header_check < 0) {
dev_kfree_skb_irq(skb);
vp->estats.rx_encaps_errors++;
continue;
}
The normal and short-packet paths fall through to the bottom of the
loop body, which clears the consumed slot and advances the cursors:
(*skbuff_vector) = NULL;
mmsg_vector++;
skbuff_vector++;
The verify_header() < 0 path skips that via continue, so the freed skb
is left in skbuff_vector[] and the cursors do not advance. The next
iteration reads the same slot, gets the freed skb, and frees it again,
producing a refcount underflow / use-after-free in the RX path.
Discard the slot the same way the other paths do before continuing.
Only transports whose verify_header() can return negative are affected:
GRE and L2TPv3 do so on a cookie/session-id mismatch (raw/tap do not),
so any peer on such a transport can trigger it without authentication.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 49da7e64f33e80edffb1a9eeb230fa4c3f42dffb Version: 49da7e64f33e80edffb1a9eeb230fa4c3f42dffb Version: 49da7e64f33e80edffb1a9eeb230fa4c3f42dffb Version: 49da7e64f33e80edffb1a9eeb230fa4c3f42dffb Version: 49da7e64f33e80edffb1a9eeb230fa4c3f42dffb Version: 49da7e64f33e80edffb1a9eeb230fa4c3f42dffb Version: 49da7e64f33e80edffb1a9eeb230fa4c3f42dffb Version: 49da7e64f33e80edffb1a9eeb230fa4c3f42dffb |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"arch/um/drivers/vector_kern.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "967c779c9853d2a1cc9cd8e61d300250c348f3d9",
"status": "affected",
"version": "49da7e64f33e80edffb1a9eeb230fa4c3f42dffb",
"versionType": "git"
},
{
"lessThan": "a7bc015bb798c525e7a82dd14225c6aeb994274b",
"status": "affected",
"version": "49da7e64f33e80edffb1a9eeb230fa4c3f42dffb",
"versionType": "git"
},
{
"lessThan": "7dc9781e320d664c9bdd50003c9acfddf363d1e1",
"status": "affected",
"version": "49da7e64f33e80edffb1a9eeb230fa4c3f42dffb",
"versionType": "git"
},
{
"lessThan": "4b9601595e8b6b5d18878cac0aeabc687d241111",
"status": "affected",
"version": "49da7e64f33e80edffb1a9eeb230fa4c3f42dffb",
"versionType": "git"
},
{
"lessThan": "67d58ab4f2ccf7145f3da07e025735a09c79de1b",
"status": "affected",
"version": "49da7e64f33e80edffb1a9eeb230fa4c3f42dffb",
"versionType": "git"
},
{
"lessThan": "180ff4c81faf01ec4e06082c9daa7c40518ead89",
"status": "affected",
"version": "49da7e64f33e80edffb1a9eeb230fa4c3f42dffb",
"versionType": "git"
},
{
"lessThan": "804b681002ead233abf49a3efd681f5468a835f9",
"status": "affected",
"version": "49da7e64f33e80edffb1a9eeb230fa4c3f42dffb",
"versionType": "git"
},
{
"lessThan": "af421e9aed3920c7ac88c24daa48606c7112feca",
"status": "affected",
"version": "49da7e64f33e80edffb1a9eeb230fa4c3f42dffb",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"arch/um/drivers/vector_kern.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.17"
},
{
"lessThan": "4.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.17",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\num: vector: fix use-after-free in vector_mmsg_rx()\n\nWhen vector_mmsg_rx() discards a packet whose overlay header fails\nverify_header(), it frees the skb and continues the loop:\n\n\tif (header_check \u003c 0) {\n\t\tdev_kfree_skb_irq(skb);\n\t\tvp-\u003eestats.rx_encaps_errors++;\n\t\tcontinue;\n\t}\n\nThe normal and short-packet paths fall through to the bottom of the\nloop body, which clears the consumed slot and advances the cursors:\n\n\t(*skbuff_vector) = NULL;\n\tmmsg_vector++;\n\tskbuff_vector++;\n\nThe verify_header() \u003c 0 path skips that via continue, so the freed skb\nis left in skbuff_vector[] and the cursors do not advance. The next\niteration reads the same slot, gets the freed skb, and frees it again,\nproducing a refcount underflow / use-after-free in the RX path.\n\nDiscard the slot the same way the other paths do before continuing.\n\nOnly transports whose verify_header() can return negative are affected:\nGRE and L2TPv3 do so on a cookie/session-id mismatch (raw/tap do not),\nso any peer on such a transport can trigger it without authentication."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug is reached from remotely sent GRE or L2TPv3 packets processed by vector_mmsg_rx() via recvmmsg on the tunnel socket; the fix commit states any peer on those transports can trigger it without authentication.\nAC:L - An attacker reliably triggers verify_header() failure with a wrong GRE key or L2TPv3 session/cookie, and sending two or more malformed packets in one recvmmsg batch causes immediate double-free of the same skb without races or special memory layout.\nPR:N - No privileges on the UML instance are required; exploitation needs only the ability to send network packets on the configured GRE/L2TPv3 transport, and overlay keys/cookies are not authenticated security controls.\nUI:N - Exploitation is driven entirely by remote packets delivered to the vector netdev RX path and requires no victim user or administrator action beyond the interface already being up.\nS:U - The use-after-free corrupts sk_buff memory inside the UML kernel network driver and does not by itself cross a VM, IOMMU, or host-kernel security boundary.\nC:H - The refcount underflow/use-after-free leaves a dangling sk_buff pointer that can be reallocated and read through standard heap grooming, giving an arbitrary kernel memory disclosure primitive.\nI:H - Reclaiming the freed sk_buff enables attacker-controlled contents in kernel heap objects and can be leveraged for arbitrary write or control-flow hijack in the UML kernel context.\nA:H - The double-free in the RX path can immediately oops or panic the UML kernel, and an unauthenticated remote peer can retrigger the condition by sending additional malformed tunnel packets."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:37:30.555Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/967c779c9853d2a1cc9cd8e61d300250c348f3d9"
},
{
"url": "https://git.kernel.org/stable/c/a7bc015bb798c525e7a82dd14225c6aeb994274b"
},
{
"url": "https://git.kernel.org/stable/c/7dc9781e320d664c9bdd50003c9acfddf363d1e1"
},
{
"url": "https://git.kernel.org/stable/c/4b9601595e8b6b5d18878cac0aeabc687d241111"
},
{
"url": "https://git.kernel.org/stable/c/67d58ab4f2ccf7145f3da07e025735a09c79de1b"
},
{
"url": "https://git.kernel.org/stable/c/180ff4c81faf01ec4e06082c9daa7c40518ead89"
},
{
"url": "https://git.kernel.org/stable/c/804b681002ead233abf49a3efd681f5468a835f9"
},
{
"url": "https://git.kernel.org/stable/c/af421e9aed3920c7ac88c24daa48606c7112feca"
}
],
"title": "um: vector: fix use-after-free in vector_mmsg_rx()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74478",
"datePublished": "2026-08-15T12:27:12.549Z",
"dateReserved": "2026-08-15T05:44:03.903Z",
"dateUpdated": "2026-08-19T16:37:30.555Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80807 (GCVE-0-2026-80807)
Vulnerability from cvelistv5
Published
2026-09-04 15:13
Modified
2026-09-04 15:13
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
nilfs2: reject invalid block index in GC ioctl
Syzbot reported list corruption caused by a double list_add_tail() call on
bh->b_assoc_buffers within nilfs_lookup_dirty_data_buffers().
Analysis revealed that the root cause was the insertion of a page/folio
with a page index of ULONG_MAX into the page cache via the GC ioctl.
filemap_get_folios_tag(), called by nilfs_lookup_dirty_data_buffers(),
repeatedly detects a dirty folio with a page index of ULONG_MAX due to
index wrap-around, leading to duplicate processing of dirty buffers.
As a preparatory step, the GC ioctl loads the page/folio of the block to
be moved during GC and inserts it into the page cache based on information
in the nilfs_vdesc structure passed as an argument. Normally, this does
not cause issues because the user-space GC library configures the
nilfs_vdesc structure properly. However, since there is no range check on
the parameters determining the page index, a request with artificially
crafted parameters -- such as those generated by Syzbot -- can result in a
page/folio being inserted with a page index of ULONG_MAX, triggering the
above problem.
This resolves the issue by checking the ranges of 'vd_offset' and
'vd_vblocknr' in the nilfs_vdesc structure that determine the page index,
thereby preventing the invalid page/folio insertions.
References
| URL | Tags | ||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 7942b919f7321f95a777d396ff7894a7a83dc9b0 Version: 7942b919f7321f95a777d396ff7894a7a83dc9b0 Version: 7942b919f7321f95a777d396ff7894a7a83dc9b0 Version: 7942b919f7321f95a777d396ff7894a7a83dc9b0 Version: 7942b919f7321f95a777d396ff7894a7a83dc9b0 Version: 7942b919f7321f95a777d396ff7894a7a83dc9b0 Version: 7942b919f7321f95a777d396ff7894a7a83dc9b0 Version: 7942b919f7321f95a777d396ff7894a7a83dc9b0 Version: 7942b919f7321f95a777d396ff7894a7a83dc9b0 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/nilfs2/ioctl.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "898404cdf882d7b54f1132f75570984ca3214796",
"status": "affected",
"version": "7942b919f7321f95a777d396ff7894a7a83dc9b0",
"versionType": "git"
},
{
"lessThan": "ba8a8b563a28d358c45c62a306d421434a058648",
"status": "affected",
"version": "7942b919f7321f95a777d396ff7894a7a83dc9b0",
"versionType": "git"
},
{
"lessThan": "3bd064ccc70b85f9a3d53aece29dc8473be5a226",
"status": "affected",
"version": "7942b919f7321f95a777d396ff7894a7a83dc9b0",
"versionType": "git"
},
{
"lessThan": "a5e776e2937581d67ec5b9b4d27b0f70d7baa6b1",
"status": "affected",
"version": "7942b919f7321f95a777d396ff7894a7a83dc9b0",
"versionType": "git"
},
{
"lessThan": "68aa9ab6f8f2895713aa6ddf781463ed8ea5ba44",
"status": "affected",
"version": "7942b919f7321f95a777d396ff7894a7a83dc9b0",
"versionType": "git"
},
{
"lessThan": "e447f7edb99bd00cec63d6f3049e2e5074946f71",
"status": "affected",
"version": "7942b919f7321f95a777d396ff7894a7a83dc9b0",
"versionType": "git"
},
{
"lessThan": "ec6ddf271dfa4c7e3147bc2c8b2bad4315f316a1",
"status": "affected",
"version": "7942b919f7321f95a777d396ff7894a7a83dc9b0",
"versionType": "git"
},
{
"lessThan": "fbcfb75c20d71a5b542ad4ac3b79d10b997c8152",
"status": "affected",
"version": "7942b919f7321f95a777d396ff7894a7a83dc9b0",
"versionType": "git"
},
{
"lessThan": "a1735eae55448bc79c2da6593455791e886f6ed8",
"status": "affected",
"version": "7942b919f7321f95a777d396ff7894a7a83dc9b0",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/nilfs2/ioctl.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.30"
},
{
"lessThan": "2.6.30",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.269",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.220",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.187",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.156",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.108",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.47",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.1",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.269",
"versionStartIncluding": "2.6.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.220",
"versionStartIncluding": "2.6.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.187",
"versionStartIncluding": "2.6.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.156",
"versionStartIncluding": "2.6.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.108",
"versionStartIncluding": "2.6.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.47",
"versionStartIncluding": "2.6.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.11",
"versionStartIncluding": "2.6.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.1",
"versionStartIncluding": "2.6.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "2.6.30",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: reject invalid block index in GC ioctl\n\nSyzbot reported list corruption caused by a double list_add_tail() call on\nbh-\u003eb_assoc_buffers within nilfs_lookup_dirty_data_buffers().\n\nAnalysis revealed that the root cause was the insertion of a page/folio\nwith a page index of ULONG_MAX into the page cache via the GC ioctl.\nfilemap_get_folios_tag(), called by nilfs_lookup_dirty_data_buffers(),\nrepeatedly detects a dirty folio with a page index of ULONG_MAX due to\nindex wrap-around, leading to duplicate processing of dirty buffers.\n\nAs a preparatory step, the GC ioctl loads the page/folio of the block to\nbe moved during GC and inserts it into the page cache based on information\nin the nilfs_vdesc structure passed as an argument. Normally, this does\nnot cause issues because the user-space GC library configures the\nnilfs_vdesc structure properly. However, since there is no range check on\nthe parameters determining the page index, a request with artificially\ncrafted parameters -- such as those generated by Syzbot -- can result in a\npage/folio being inserted with a page index of ULONG_MAX, triggering the\nabove problem.\n\nThis resolves the issue by checking the ranges of \u0027vd_offset\u0027 and\n\u0027vd_vblocknr\u0027 in the nilfs_vdesc structure that determine the page index,\nthereby preventing the invalid page/folio insertions."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T15:13:23.605Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/898404cdf882d7b54f1132f75570984ca3214796"
},
{
"url": "https://git.kernel.org/stable/c/ba8a8b563a28d358c45c62a306d421434a058648"
},
{
"url": "https://git.kernel.org/stable/c/3bd064ccc70b85f9a3d53aece29dc8473be5a226"
},
{
"url": "https://git.kernel.org/stable/c/a5e776e2937581d67ec5b9b4d27b0f70d7baa6b1"
},
{
"url": "https://git.kernel.org/stable/c/68aa9ab6f8f2895713aa6ddf781463ed8ea5ba44"
},
{
"url": "https://git.kernel.org/stable/c/e447f7edb99bd00cec63d6f3049e2e5074946f71"
},
{
"url": "https://git.kernel.org/stable/c/ec6ddf271dfa4c7e3147bc2c8b2bad4315f316a1"
},
{
"url": "https://git.kernel.org/stable/c/fbcfb75c20d71a5b542ad4ac3b79d10b997c8152"
},
{
"url": "https://git.kernel.org/stable/c/a1735eae55448bc79c2da6593455791e886f6ed8"
}
],
"title": "nilfs2: reject invalid block index in GC ioctl",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80807",
"datePublished": "2026-09-04T15:13:23.605Z",
"dateReserved": "2026-08-26T14:34:25.794Z",
"dateUpdated": "2026-09-04T15:13:23.605Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68137 (GCVE-0-2026-68137)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/x25: fix use-after-free in x25_kill_by_neigh()
x25_kill_by_neigh() walks the global X.25 socket list looking for sockets
attached to a terminating neighbour. x25_list_lock protects list membership
while the lookup is in progress, but it does not pin a socket's lifetime
after the lock is dropped.
The function currently drops x25_list_lock before calling lock_sock(s). A
concurrent close can run x25_release(), remove the same socket from
x25_list, and drop the last socket reference in that window. The neighbour
teardown path can then lock or inspect a freed struct sock/struct x25_sock.
Take sock_hold(s) while x25_list_lock still proves that the list entry is
live, then drop the temporary reference after the socket has been locked,
rechecked, and released. Recheck x25_sk(s)->neighbour after lock_sock(),
because another path may have disconnected the socket before this path
acquired the socket lock. Restart the list walk after each disconnect
because the list lock was dropped and the previous iterator state may no
longer be valid.
A QEMU/KASAN run against origin/master reproduced a slab-use-after-free in
x25_kill_by_neigh().
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 5c94b6205e87411dbe9dc1ca088eb36b8837fb47 Version: 409570a619c1cda2e0fde6018a256b9e3d3ba0ee Version: 7781607938c8371d4c2b243527430241c62e39c2 Version: 7781607938c8371d4c2b243527430241c62e39c2 Version: 7781607938c8371d4c2b243527430241c62e39c2 Version: 7781607938c8371d4c2b243527430241c62e39c2 Version: 7781607938c8371d4c2b243527430241c62e39c2 Version: 7781607938c8371d4c2b243527430241c62e39c2 Version: dffc859d1d9560da594e4282091781b8d2715f00 Version: 858642789ada1b48630f322e59416ca9fca3e6b7 Version: 4c240c5a105557e4546d0836e694868f22fd09b0 Version: 9acf05b4e7b55fdb712ef7b331dbce5bcd391d0f Version: 4a279d7ee1c65411b4055ecd428b8aa2b1711c1f Version: 671529db75e6be777bb1c76aa07c2bdd2992be6d Version: 5.10.110 ≤ Version: 5.15.33 ≤ Version: 4.9.311 ≤ Version: 4.14.276 ≤ Version: 4.19.238 ≤ Version: 5.4.189 ≤ Version: 5.16.19 ≤ Version: 5.17.2 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/x25/af_x25.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "db6b04f6d65549bb1c7bc8e64a92e7b7d03be676",
"status": "affected",
"version": "5c94b6205e87411dbe9dc1ca088eb36b8837fb47",
"versionType": "git"
},
{
"lessThan": "5e8a754ac2009a88a7b99ab61eab6296eed360f3",
"status": "affected",
"version": "409570a619c1cda2e0fde6018a256b9e3d3ba0ee",
"versionType": "git"
},
{
"lessThan": "c98a454d1a9e1bd09d5fd55a7aa589b199340b88",
"status": "affected",
"version": "7781607938c8371d4c2b243527430241c62e39c2",
"versionType": "git"
},
{
"lessThan": "3f4fe26c20c30bd5a2e2583e80685def0b27858c",
"status": "affected",
"version": "7781607938c8371d4c2b243527430241c62e39c2",
"versionType": "git"
},
{
"lessThan": "610678d4be94b619c751572e8a58de705592cd07",
"status": "affected",
"version": "7781607938c8371d4c2b243527430241c62e39c2",
"versionType": "git"
},
{
"lessThan": "ec6d91a1bf2ebd767d3d43f6d249ee0ed3f4558a",
"status": "affected",
"version": "7781607938c8371d4c2b243527430241c62e39c2",
"versionType": "git"
},
{
"lessThan": "9aabda553184346f74810e2ee1d96920b4612e3f",
"status": "affected",
"version": "7781607938c8371d4c2b243527430241c62e39c2",
"versionType": "git"
},
{
"lessThan": "5499e0602d2faafd42c580d25f615903c3fbe11b",
"status": "affected",
"version": "7781607938c8371d4c2b243527430241c62e39c2",
"versionType": "git"
},
{
"status": "affected",
"version": "dffc859d1d9560da594e4282091781b8d2715f00",
"versionType": "git"
},
{
"status": "affected",
"version": "858642789ada1b48630f322e59416ca9fca3e6b7",
"versionType": "git"
},
{
"status": "affected",
"version": "4c240c5a105557e4546d0836e694868f22fd09b0",
"versionType": "git"
},
{
"status": "affected",
"version": "9acf05b4e7b55fdb712ef7b331dbce5bcd391d0f",
"versionType": "git"
},
{
"status": "affected",
"version": "4a279d7ee1c65411b4055ecd428b8aa2b1711c1f",
"versionType": "git"
},
{
"status": "affected",
"version": "671529db75e6be777bb1c76aa07c2bdd2992be6d",
"versionType": "git"
},
{
"lessThan": "5.10.265",
"status": "affected",
"version": "5.10.110",
"versionType": "semver"
},
{
"lessThan": "5.15.216",
"status": "affected",
"version": "5.15.33",
"versionType": "semver"
},
{
"lessThan": "4.10",
"status": "affected",
"version": "4.9.311",
"versionType": "semver"
},
{
"lessThan": "4.15",
"status": "affected",
"version": "4.14.276",
"versionType": "semver"
},
{
"lessThan": "4.20",
"status": "affected",
"version": "4.19.238",
"versionType": "semver"
},
{
"lessThan": "5.5",
"status": "affected",
"version": "5.4.189",
"versionType": "semver"
},
{
"lessThan": "5.17",
"status": "affected",
"version": "5.16.19",
"versionType": "semver"
},
{
"lessThan": "5.18",
"status": "affected",
"version": "5.17.2",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/x25/af_x25.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.18"
},
{
"lessThan": "5.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.10.110",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.15.33",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.9.311",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.14.276",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.19.238",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.4.189",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.16.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.17.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/x25: fix use-after-free in x25_kill_by_neigh()\n\nx25_kill_by_neigh() walks the global X.25 socket list looking for sockets\nattached to a terminating neighbour. x25_list_lock protects list membership\nwhile the lookup is in progress, but it does not pin a socket\u0027s lifetime\nafter the lock is dropped.\n\nThe function currently drops x25_list_lock before calling lock_sock(s). A\nconcurrent close can run x25_release(), remove the same socket from\nx25_list, and drop the last socket reference in that window. The neighbour\nteardown path can then lock or inspect a freed struct sock/struct x25_sock.\n\nTake sock_hold(s) while x25_list_lock still proves that the list entry is\nlive, then drop the temporary reference after the socket has been locked,\nrechecked, and released. Recheck x25_sk(s)-\u003eneighbour after lock_sock(),\nbecause another path may have disconnected the socket before this path\nacquired the socket lock. Restart the list walk after each disconnect\nbecause the list lock was dropped and the previous iterator state may no\nlonger be valid.\n\nA QEMU/KASAN run against origin/master reproduced a slab-use-after-free in\nx25_kill_by_neigh()."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - x25_kill_by_neigh() is invoked from the net stack when inbound X.25 link-control frames (RESTART_REQUEST/CONFIRMATION with LCI 0, or IFACE_DISCONNECT) are processed on ARPHRD_X25 interfaces via the ETH_P_X25 packet handler, the normal WAN-facing path in telecom/banking/industrial X.25 deployments.\nAC:L - This is a use-after-free race between neighbour teardown and socket close(); an attacker controls both sides by racing close() on an AF_X25 socket against RESTART/terminate frames they send, and KASAN reproduced the slab-UAF under controlled testing.\nPR:N - A remote X.25 peer on the WAN needs no Linux credentials to deliver RESTART/terminate frames that reach x25_kill_by_neigh(); exploitation races that path against any local X.25 consumer closing sockets, without the attacker holding privileges on the victim host.\nUI:N - No victim user interaction is required beyond normal automated X.25 service operation (accepting calls, reconnecting, or closing sessions) that can be timed against remotely injected link-control frames.\nS:U - The vulnerability corrupts kernel heap memory within the host kernel security boundary; it does not cross VM, container, or IOMMU isolation boundaries.\nC:H - Use-after-free on struct sock/x25_sock lets an attacker influence reuse of freed slab objects, enabling arbitrary kernel memory disclosure per CNA guidance for kernel UAF bugs.\nI:H - Use-after-free on socket structures can be leveraged through heap shaping into arbitrary kernel writes, privilege escalation, or code execution per CNA guidance for kernel UAF bugs.\nA:H - The bug is a confirmed slab use-after-free in kernel context (KASAN-reproduced) that can oops or panic the kernel during lock_sock()/x25_disconnect() even before full exploit development."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:29:54.672Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/db6b04f6d65549bb1c7bc8e64a92e7b7d03be676"
},
{
"url": "https://git.kernel.org/stable/c/5e8a754ac2009a88a7b99ab61eab6296eed360f3"
},
{
"url": "https://git.kernel.org/stable/c/c98a454d1a9e1bd09d5fd55a7aa589b199340b88"
},
{
"url": "https://git.kernel.org/stable/c/3f4fe26c20c30bd5a2e2583e80685def0b27858c"
},
{
"url": "https://git.kernel.org/stable/c/610678d4be94b619c751572e8a58de705592cd07"
},
{
"url": "https://git.kernel.org/stable/c/ec6d91a1bf2ebd767d3d43f6d249ee0ed3f4558a"
},
{
"url": "https://git.kernel.org/stable/c/9aabda553184346f74810e2ee1d96920b4612e3f"
},
{
"url": "https://git.kernel.org/stable/c/5499e0602d2faafd42c580d25f615903c3fbe11b"
}
],
"title": "net/x25: fix use-after-free in x25_kill_by_neigh()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68137",
"datePublished": "2026-08-10T11:59:00.740Z",
"dateReserved": "2026-07-30T09:28:09.370Z",
"dateUpdated": "2026-08-19T16:29:54.672Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68338 (GCVE-0-2026-68338)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/packet: avoid fanout hook re-registration after unregister
packet_set_ring() temporarily detaches a socket from packet delivery while
reconfiguring its ring. It records the previous running state, clears
po->num, unregisters the protocol hook when needed, drops po->bind_lock,
and later restores po->num and re-registers the hook from the saved
was_running value.
That unlocked window can race with NETDEV_UNREGISTER. The notifier can
observe the socket as not running, skip __unregister_prot_hook(), and
invalidate the per-socket binding by setting po->ifindex to -1 and clearing
po->prot_hook.dev. A one-member fanout group can still retain its shared
fanout hook device pointer. When packet_set_ring() resumes, re-registering
solely from the stale was_running state can re-add the fanout hook after
the device has been unregistered.
Treat po->ifindex == -1 as an invalidated binding after reacquiring
po->bind_lock. This is distinct from ifindex 0, the normal
unbound/wildcard state: ifindex -1 marks an existing device binding that
was invalidated when the device was unregistered. Restore po->num as
before, but do not re-register the hook if device unregister already
detached the socket.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: dc99f600698dcac69b8f56dda9a8a00d645c5ffc Version: dc99f600698dcac69b8f56dda9a8a00d645c5ffc Version: dc99f600698dcac69b8f56dda9a8a00d645c5ffc Version: dc99f600698dcac69b8f56dda9a8a00d645c5ffc Version: dc99f600698dcac69b8f56dda9a8a00d645c5ffc Version: dc99f600698dcac69b8f56dda9a8a00d645c5ffc Version: dc99f600698dcac69b8f56dda9a8a00d645c5ffc Version: dc99f600698dcac69b8f56dda9a8a00d645c5ffc |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/packet/af_packet.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "acb40ebfa5c4d62f84339fcbf713f2a9fd033a71",
"status": "affected",
"version": "dc99f600698dcac69b8f56dda9a8a00d645c5ffc",
"versionType": "git"
},
{
"lessThan": "c820f4b7f2fa38f8769db0d0cefdd94e2721504d",
"status": "affected",
"version": "dc99f600698dcac69b8f56dda9a8a00d645c5ffc",
"versionType": "git"
},
{
"lessThan": "4628efbdc7affd094181f5263e65c1062e31f15f",
"status": "affected",
"version": "dc99f600698dcac69b8f56dda9a8a00d645c5ffc",
"versionType": "git"
},
{
"lessThan": "80ec024d53a05c60ad1d08968dcf745f10c1665c",
"status": "affected",
"version": "dc99f600698dcac69b8f56dda9a8a00d645c5ffc",
"versionType": "git"
},
{
"lessThan": "0a052e0808e015e68144a9877e6ef42b952c49fa",
"status": "affected",
"version": "dc99f600698dcac69b8f56dda9a8a00d645c5ffc",
"versionType": "git"
},
{
"lessThan": "1bc55c29cd85818e9052f17deb287d5a11fb817f",
"status": "affected",
"version": "dc99f600698dcac69b8f56dda9a8a00d645c5ffc",
"versionType": "git"
},
{
"lessThan": "a885387dae7986a55bae5c77a15bdd447f64e9b9",
"status": "affected",
"version": "dc99f600698dcac69b8f56dda9a8a00d645c5ffc",
"versionType": "git"
},
{
"lessThan": "50aff80475abd3533eef4320477037e6fcc6b56e",
"status": "affected",
"version": "dc99f600698dcac69b8f56dda9a8a00d645c5ffc",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/packet/af_packet.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.1"
},
{
"lessThan": "3.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/packet: avoid fanout hook re-registration after unregister\n\npacket_set_ring() temporarily detaches a socket from packet delivery while\nreconfiguring its ring. It records the previous running state, clears\npo-\u003enum, unregisters the protocol hook when needed, drops po-\u003ebind_lock,\nand later restores po-\u003enum and re-registers the hook from the saved\nwas_running value.\n\nThat unlocked window can race with NETDEV_UNREGISTER. The notifier can\nobserve the socket as not running, skip __unregister_prot_hook(), and\ninvalidate the per-socket binding by setting po-\u003eifindex to -1 and clearing\npo-\u003eprot_hook.dev. A one-member fanout group can still retain its shared\nfanout hook device pointer. When packet_set_ring() resumes, re-registering\nsolely from the stale was_running state can re-add the fanout hook after\nthe device has been unregistered.\n\nTreat po-\u003eifindex == -1 as an invalidated binding after reacquiring\npo-\u003ebind_lock. This is distinct from ifindex 0, the normal\nunbound/wildcard state: ifindex -1 marks an existing device binding that\nwas invalidated when the device was unregistered. Restore po-\u003enum as\nbefore, but do not re-register the hook if device unregister already\ndetached the socket."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is triggered through local syscalls \u2014 creating an AF_PACKET socket, PACKET_FANOUT/bind setsockopt, PACKET_RX_RING setsockopt, and a netlink device unregister \u2014 with no remote packet processing involved.\nAC:L - The attacker controls both sides of the race: it issues the packet_set_ring() reconfiguration and deletes the bound netdev in its own netns, and the unlocked window spans synchronize_net() plus the ring swap, making it wide and reliably winnable.\nPR:L - AF_PACKET requires CAP_NET_RAW and device unregistration CAP_NET_ADMIN, but an unprivileged user obtains both via user+network namespaces (unshare -Urn) and can create and delete veth/dummy devices there.\nUI:N - The attacker performs every step itself \u2014 socket setup, ring reconfiguration and device teardown \u2014 with no action required from any other user.\nS:U - The stale hook registration and resulting corruption stay within the kernel\u0027s own security authority; no hypervisor, IOMMU or other trust boundary is crossed.\nC:H - The fanout packet_type is left linked into a net_device that is being torn down, a dangling registration on soon-to-be-freed memory; such stale-pointer state in the ptype lists can be leveraged for kernel memory disclosure.\nI:H - The dangling list node in the freed net_device\u0027s ptype list yields a list_del write into freed memory when the hook is later removed, a controllable write primitive typical of use-after-free exploitation.\nA:H - The re-added hook makes netdev_run_todo() hit BUG_ON(!list_empty(\u0026dev-\u003eptype_all)) while RTNL is held, oopsing the kernel and permanently wedging all further network configuration \u2014 a repeatable, unprivileged host-wide denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:38.308Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/acb40ebfa5c4d62f84339fcbf713f2a9fd033a71"
},
{
"url": "https://git.kernel.org/stable/c/c820f4b7f2fa38f8769db0d0cefdd94e2721504d"
},
{
"url": "https://git.kernel.org/stable/c/4628efbdc7affd094181f5263e65c1062e31f15f"
},
{
"url": "https://git.kernel.org/stable/c/80ec024d53a05c60ad1d08968dcf745f10c1665c"
},
{
"url": "https://git.kernel.org/stable/c/0a052e0808e015e68144a9877e6ef42b952c49fa"
},
{
"url": "https://git.kernel.org/stable/c/1bc55c29cd85818e9052f17deb287d5a11fb817f"
},
{
"url": "https://git.kernel.org/stable/c/a885387dae7986a55bae5c77a15bdd447f64e9b9"
},
{
"url": "https://git.kernel.org/stable/c/50aff80475abd3533eef4320477037e6fcc6b56e"
}
],
"title": "net/packet: avoid fanout hook re-registration after unregister",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68338",
"datePublished": "2026-08-10T12:03:14.549Z",
"dateReserved": "2026-07-30T09:28:09.384Z",
"dateUpdated": "2026-08-19T16:33:38.308Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80828 (GCVE-0-2026-80828)
Vulnerability from cvelistv5
Published
2026-09-04 15:54
Modified
2026-09-04 15:54
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ALSA: usb-audio: Complete cleanup after system-resume errors
A failed system resume can leave the card unusable until reboot.
usb_audio_resume() jumps to err_out when snd_usb_pcm_resume() or
snd_usb_mixer_resume() fails. The error path skips the out: block, which
restores D0 and decrements chip->num_suspended_intf.
The card stays in SNDRV_CTL_POWER_D3hot, so later control access blocks in
snd_power_ref_and_wait(). USB core logs an interface resume callback error.
It does not retry that callback, so a later callback cannot complete the
skipped cleanup.
usb_audio_suspend() increments num_suspended_intf before returning success.
A system-resume callback must consume the system-suspend count even if a
component resume fails. Otherwise, the stranded count skews later suspend
and resume cycles.
Do not apply this cleanup to runtime-resume errors. Runtime PM can retry
-EAGAIN or -EBUSY without another suspend callback. The count must continue
to describe that suspended interface. Other runtime-resume errors latch
runtime_error in the PM core and do not cause an immediate callback retry.
Both parts of the system-resume error path are longstanding. Commit
88a8516a2128a ("ALSA: usbaudio: implement USB autosuspend") introduced
err_out past the D0 restore. Commit 862b2509d157c ("ALSA: usb-audio: Fix
inconsistent card PM state after resume") later moved
num_suspended_intf-- into the out: block. The error path now skips both
operations.
No third-party code is needed to reach the error path.
snd_usb_mixer_resume() ends in snd_usb_mixer_activate(), which returns the
result of usb_submit_urb() for devices that have a mixer status URB. Its
mixer->private_resume hook can also fail through scarlett2_init_notify().
snd_usb_pcm_resume() issues a SET_CUR request to a UAC3 power domain. It
can return -EPIPE or -EIO when the device stalls the request.
Route a component error through out: only when system_suspend is nonzero.
Continue to return runtime-resume errors through err_out. Later component
resume stages remain skipped. The original error still reaches USB core.
A later transfer can fail if the device did not recover.
I reproduced the system-resume failure on an Audient iD14 MkI with an
out-of-tree diagnostic mixer resume hook. An injected -EIO on the unpatched
core left control readers in uninterruptible sleep in
snd_power_ref_and_wait() until a reboot. With this patch, the same failure
restored control access. A second system suspend and resume also succeeded
after I disabled fault injection.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 88a8516a2128a6d078a106ead48092240e8a138f Version: 88a8516a2128a6d078a106ead48092240e8a138f Version: 88a8516a2128a6d078a106ead48092240e8a138f Version: 88a8516a2128a6d078a106ead48092240e8a138f Version: 88a8516a2128a6d078a106ead48092240e8a138f Version: 88a8516a2128a6d078a106ead48092240e8a138f Version: 88a8516a2128a6d078a106ead48092240e8a138f Version: 88a8516a2128a6d078a106ead48092240e8a138f |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"sound/usb/card.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "3fa521c3c54b42e16cad8ade76551113a783752b",
"status": "affected",
"version": "88a8516a2128a6d078a106ead48092240e8a138f",
"versionType": "git"
},
{
"lessThan": "3f06f3f5b16212f180764654a9398ff5f7a855c8",
"status": "affected",
"version": "88a8516a2128a6d078a106ead48092240e8a138f",
"versionType": "git"
},
{
"lessThan": "f1c05c41d07b874635d681ae328d13ec550470c5",
"status": "affected",
"version": "88a8516a2128a6d078a106ead48092240e8a138f",
"versionType": "git"
},
{
"lessThan": "5a625fc2284e35f33693efd9534aebaca3b005d4",
"status": "affected",
"version": "88a8516a2128a6d078a106ead48092240e8a138f",
"versionType": "git"
},
{
"lessThan": "6d3e202670b819c414076a5d07dffac8a39274ad",
"status": "affected",
"version": "88a8516a2128a6d078a106ead48092240e8a138f",
"versionType": "git"
},
{
"lessThan": "6c94877b6bab9185898bcad4b082ff5592558921",
"status": "affected",
"version": "88a8516a2128a6d078a106ead48092240e8a138f",
"versionType": "git"
},
{
"lessThan": "d1f643b1c0258bd519146f7a342bbb394d413912",
"status": "affected",
"version": "88a8516a2128a6d078a106ead48092240e8a138f",
"versionType": "git"
},
{
"lessThan": "1739a976312e110c93a8dee66a1cdf893a1b187e",
"status": "affected",
"version": "88a8516a2128a6d078a106ead48092240e8a138f",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"sound/usb/card.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.39"
},
{
"lessThan": "2.6.39",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.220",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.187",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.156",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.108",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.49",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.13",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.3",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.220",
"versionStartIncluding": "2.6.39",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.187",
"versionStartIncluding": "2.6.39",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.156",
"versionStartIncluding": "2.6.39",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.108",
"versionStartIncluding": "2.6.39",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.49",
"versionStartIncluding": "2.6.39",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.13",
"versionStartIncluding": "2.6.39",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.3",
"versionStartIncluding": "2.6.39",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "2.6.39",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: usb-audio: Complete cleanup after system-resume errors\n\nA failed system resume can leave the card unusable until reboot.\nusb_audio_resume() jumps to err_out when snd_usb_pcm_resume() or\nsnd_usb_mixer_resume() fails. The error path skips the out: block, which\nrestores D0 and decrements chip-\u003enum_suspended_intf.\n\nThe card stays in SNDRV_CTL_POWER_D3hot, so later control access blocks in\nsnd_power_ref_and_wait(). USB core logs an interface resume callback error.\nIt does not retry that callback, so a later callback cannot complete the\nskipped cleanup.\n\nusb_audio_suspend() increments num_suspended_intf before returning success.\nA system-resume callback must consume the system-suspend count even if a\ncomponent resume fails. Otherwise, the stranded count skews later suspend\nand resume cycles.\n\nDo not apply this cleanup to runtime-resume errors. Runtime PM can retry\n-EAGAIN or -EBUSY without another suspend callback. The count must continue\nto describe that suspended interface. Other runtime-resume errors latch\nruntime_error in the PM core and do not cause an immediate callback retry.\n\nBoth parts of the system-resume error path are longstanding. Commit\n88a8516a2128a (\"ALSA: usbaudio: implement USB autosuspend\") introduced\nerr_out past the D0 restore. Commit 862b2509d157c (\"ALSA: usb-audio: Fix\ninconsistent card PM state after resume\") later moved\nnum_suspended_intf-- into the out: block. The error path now skips both\noperations.\n\nNo third-party code is needed to reach the error path.\nsnd_usb_mixer_resume() ends in snd_usb_mixer_activate(), which returns the\nresult of usb_submit_urb() for devices that have a mixer status URB. Its\nmixer-\u003eprivate_resume hook can also fail through scarlett2_init_notify().\nsnd_usb_pcm_resume() issues a SET_CUR request to a UAC3 power domain. It\ncan return -EPIPE or -EIO when the device stalls the request.\n\nRoute a component error through out: only when system_suspend is nonzero.\nContinue to return runtime-resume errors through err_out. Later component\nresume stages remain skipped. The original error still reaches USB core.\nA later transfer can fail if the device did not recover.\n\nI reproduced the system-resume failure on an Audient iD14 MkI with an\nout-of-tree diagnostic mixer resume hook. An injected -EIO on the unpatched\ncore left control readers in uninterruptible sleep in\nsnd_power_ref_and_wait() until a reboot. With this patch, the same failure\nrestored control access. A second system suspend and resume also succeeded\nafter I disabled fault injection."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T15:54:32.894Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/3fa521c3c54b42e16cad8ade76551113a783752b"
},
{
"url": "https://git.kernel.org/stable/c/3f06f3f5b16212f180764654a9398ff5f7a855c8"
},
{
"url": "https://git.kernel.org/stable/c/f1c05c41d07b874635d681ae328d13ec550470c5"
},
{
"url": "https://git.kernel.org/stable/c/5a625fc2284e35f33693efd9534aebaca3b005d4"
},
{
"url": "https://git.kernel.org/stable/c/6d3e202670b819c414076a5d07dffac8a39274ad"
},
{
"url": "https://git.kernel.org/stable/c/6c94877b6bab9185898bcad4b082ff5592558921"
},
{
"url": "https://git.kernel.org/stable/c/d1f643b1c0258bd519146f7a342bbb394d413912"
},
{
"url": "https://git.kernel.org/stable/c/1739a976312e110c93a8dee66a1cdf893a1b187e"
}
],
"title": "ALSA: usb-audio: Complete cleanup after system-resume errors",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80828",
"datePublished": "2026-09-04T15:54:32.894Z",
"dateReserved": "2026-08-26T14:34:25.795Z",
"dateUpdated": "2026-09-04T15:54:32.894Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80679 (GCVE-0-2026-80679)
Vulnerability from cvelistv5
Published
2026-08-28 06:52
Modified
2026-08-28 06:52
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
s390/dasd: Fix potential NULL pointer dereference
dasd_release_space() checks the implementation of the is_ese()
discipline function before calling it to determine if a given device is
an ESE DASD.
The current usage of the logical AND operator will lead to a NULL
pointer dereference as the function is called even if the function
pointer is NULL.
Fix this by using the logical OR operator.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 91dc4a197569230683ca8bad551e655a4bf14c30 Version: 91dc4a197569230683ca8bad551e655a4bf14c30 Version: 91dc4a197569230683ca8bad551e655a4bf14c30 Version: 91dc4a197569230683ca8bad551e655a4bf14c30 Version: 91dc4a197569230683ca8bad551e655a4bf14c30 Version: 91dc4a197569230683ca8bad551e655a4bf14c30 Version: 91dc4a197569230683ca8bad551e655a4bf14c30 Version: 91dc4a197569230683ca8bad551e655a4bf14c30 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/s390/block/dasd_ioctl.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "dbf2ae34d2f1390a9fc1abf3dce7f809e022caae",
"status": "affected",
"version": "91dc4a197569230683ca8bad551e655a4bf14c30",
"versionType": "git"
},
{
"lessThan": "3000367a512b1283ca52230bf21f8c91dfbec45b",
"status": "affected",
"version": "91dc4a197569230683ca8bad551e655a4bf14c30",
"versionType": "git"
},
{
"lessThan": "cdc7b73d0c5a9cd6360b4f8c36eae23b02097e4c",
"status": "affected",
"version": "91dc4a197569230683ca8bad551e655a4bf14c30",
"versionType": "git"
},
{
"lessThan": "e156c70c505c6c9adce3b7be5a82025f00544709",
"status": "affected",
"version": "91dc4a197569230683ca8bad551e655a4bf14c30",
"versionType": "git"
},
{
"lessThan": "3453a993a3f14c1684560ecf26585046976f6ac6",
"status": "affected",
"version": "91dc4a197569230683ca8bad551e655a4bf14c30",
"versionType": "git"
},
{
"lessThan": "86cdfd061509bcde84f3145f7221ba64e3e53b1f",
"status": "affected",
"version": "91dc4a197569230683ca8bad551e655a4bf14c30",
"versionType": "git"
},
{
"lessThan": "96b8e09b09539f252a5eeea6baebd93c2e3779bd",
"status": "affected",
"version": "91dc4a197569230683ca8bad551e655a4bf14c30",
"versionType": "git"
},
{
"lessThan": "9973026f572db6b67570cadc30942f3014e41079",
"status": "affected",
"version": "91dc4a197569230683ca8bad551e655a4bf14c30",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/s390/block/dasd_ioctl.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.3"
},
{
"lessThan": "5.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/dasd: Fix potential NULL pointer dereference\n\ndasd_release_space() checks the implementation of the is_ese()\ndiscipline function before calling it to determine if a given device is\nan ESE DASD.\n\nThe current usage of the logical AND operator will lead to a NULL\npointer dereference as the function is called even if the function\npointer is NULL.\n\nFix this by using the logical OR operator."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-28T06:52:47.682Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/dbf2ae34d2f1390a9fc1abf3dce7f809e022caae"
},
{
"url": "https://git.kernel.org/stable/c/3000367a512b1283ca52230bf21f8c91dfbec45b"
},
{
"url": "https://git.kernel.org/stable/c/cdc7b73d0c5a9cd6360b4f8c36eae23b02097e4c"
},
{
"url": "https://git.kernel.org/stable/c/e156c70c505c6c9adce3b7be5a82025f00544709"
},
{
"url": "https://git.kernel.org/stable/c/3453a993a3f14c1684560ecf26585046976f6ac6"
},
{
"url": "https://git.kernel.org/stable/c/86cdfd061509bcde84f3145f7221ba64e3e53b1f"
},
{
"url": "https://git.kernel.org/stable/c/96b8e09b09539f252a5eeea6baebd93c2e3779bd"
},
{
"url": "https://git.kernel.org/stable/c/9973026f572db6b67570cadc30942f3014e41079"
}
],
"title": "s390/dasd: Fix potential NULL pointer dereference",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80679",
"datePublished": "2026-08-28T06:52:47.682Z",
"dateReserved": "2026-08-26T14:34:25.783Z",
"dateUpdated": "2026-08-28T06:52:47.682Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68360 (GCVE-0-2026-68360)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop
Calling hid_hw_stop() does not stop the device IO.
This results in a race condition between hid_input_report() and the point
immediately following the execution of hid_device_io_start() within
the driver probe function. If the probe operation fails after "io start"
has been initiated, this race condition will result in a UAF vulnerability.
Fix the problem by calling hid_device_io_stop() before calling
hid_hw_stop().
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 40c3a445422579db8ad96c234dbe6c0ab3f6b936 Version: 40c3a445422579db8ad96c234dbe6c0ab3f6b936 Version: 40c3a445422579db8ad96c234dbe6c0ab3f6b936 Version: 40c3a445422579db8ad96c234dbe6c0ab3f6b936 Version: 40c3a445422579db8ad96c234dbe6c0ab3f6b936 Version: 40c3a445422579db8ad96c234dbe6c0ab3f6b936 Version: 40c3a445422579db8ad96c234dbe6c0ab3f6b936 Version: 40c3a445422579db8ad96c234dbe6c0ab3f6b936 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/hwmon/corsair-cpro.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "3df2b67793babbea7951b5f601d6df891c63b5d8",
"status": "affected",
"version": "40c3a445422579db8ad96c234dbe6c0ab3f6b936",
"versionType": "git"
},
{
"lessThan": "5e07f292ab5591bf4f588aa7abd22ec86c25d076",
"status": "affected",
"version": "40c3a445422579db8ad96c234dbe6c0ab3f6b936",
"versionType": "git"
},
{
"lessThan": "6c5f31fdf28455a7fd573bda452c80b7b6700247",
"status": "affected",
"version": "40c3a445422579db8ad96c234dbe6c0ab3f6b936",
"versionType": "git"
},
{
"lessThan": "0975c42ed2a3bf32125a920e5d19194289126210",
"status": "affected",
"version": "40c3a445422579db8ad96c234dbe6c0ab3f6b936",
"versionType": "git"
},
{
"lessThan": "c7757db58957ac20cdec6ce575dbd44a6375664e",
"status": "affected",
"version": "40c3a445422579db8ad96c234dbe6c0ab3f6b936",
"versionType": "git"
},
{
"lessThan": "56d2deb6448378118dbe68c4fbb3fbae5f65b18c",
"status": "affected",
"version": "40c3a445422579db8ad96c234dbe6c0ab3f6b936",
"versionType": "git"
},
{
"lessThan": "1a634f464d6153dfa4d7e73a3d78236b65a64ee9",
"status": "affected",
"version": "40c3a445422579db8ad96c234dbe6c0ab3f6b936",
"versionType": "git"
},
{
"lessThan": "94c87871b051d7ad758828a805215a2ec194512a",
"status": "affected",
"version": "40c3a445422579db8ad96c234dbe6c0ab3f6b936",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/hwmon/corsair-cpro.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.9"
},
{
"lessThan": "5.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop\n\nCalling hid_hw_stop() does not stop the device IO.\nThis results in a race condition between hid_input_report() and the point\nimmediately following the execution of hid_device_io_start() within\nthe driver probe function. If the probe operation fails after \"io start\"\nhas been initiated, this race condition will result in a UAF vulnerability.\n\nFix the problem by calling hid_device_io_stop() before calling\nhid_hw_stop()."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:10.569Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/3df2b67793babbea7951b5f601d6df891c63b5d8"
},
{
"url": "https://git.kernel.org/stable/c/5e07f292ab5591bf4f588aa7abd22ec86c25d076"
},
{
"url": "https://git.kernel.org/stable/c/6c5f31fdf28455a7fd573bda452c80b7b6700247"
},
{
"url": "https://git.kernel.org/stable/c/0975c42ed2a3bf32125a920e5d19194289126210"
},
{
"url": "https://git.kernel.org/stable/c/c7757db58957ac20cdec6ce575dbd44a6375664e"
},
{
"url": "https://git.kernel.org/stable/c/56d2deb6448378118dbe68c4fbb3fbae5f65b18c"
},
{
"url": "https://git.kernel.org/stable/c/1a634f464d6153dfa4d7e73a3d78236b65a64ee9"
},
{
"url": "https://git.kernel.org/stable/c/94c87871b051d7ad758828a805215a2ec194512a"
}
],
"title": "hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68360",
"datePublished": "2026-08-10T12:03:37.298Z",
"dateReserved": "2026-07-30T09:28:09.385Z",
"dateUpdated": "2026-08-19T16:34:10.569Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80901 (GCVE-0-2026-80901)
Vulnerability from cvelistv5
Published
2026-09-04 17:11
Modified
2026-09-04 17:11
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ipvs: fix the checksum validations
ip_vs_in_icmp_v6() is missing checksum validation for ICMPv6
packets from clients. In fact, as for TCP/UDP we should
validate the checksum for ICMP packets only when we
mangle the packets on MASQ or on reply for tunnel.
Also, Sashiko points out that handle_response_icmp() being
common for IPv4 and IPv6 is missing the pseudo-header
calculation while validating ICMPv6 messages from real
servers which is a problem if checksum is not validated
by the hardware.
Fix the problems by creating ip_vs_checksum_common_check()
helper and use it for TCP/UDP/ICMP both for IPv4 and IPv6.
Rely on the nf_checksum() for validating the ICMP messages
but use it also for TCP and UDP.
Use correct IP offset for IP_VS_DBG_RL_PKT for TCP/UDP/SCTP.
IPVS packets (TCP/UDP/SCTP/ICMP) do not need checksum
validation on LOCAL_OUT (local clients or local real
servers) and on FORWARD (traffic from servers on LAN).
Do it only on LOCAL_IN, in case nf_checksum() is not
called on PRE_ROUTING.
Also, ip_vs_checksum_complete() can be marked static.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 2a3b791e6e1169f374224d164738e9f7be703d77 Version: 2a3b791e6e1169f374224d164738e9f7be703d77 Version: 2a3b791e6e1169f374224d164738e9f7be703d77 Version: 2a3b791e6e1169f374224d164738e9f7be703d77 Version: 2a3b791e6e1169f374224d164738e9f7be703d77 Version: 2a3b791e6e1169f374224d164738e9f7be703d77 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"include/net/ip_vs.h",
"net/netfilter/ipvs/ip_vs_core.c",
"net/netfilter/ipvs/ip_vs_proto_sctp.c",
"net/netfilter/ipvs/ip_vs_proto_tcp.c",
"net/netfilter/ipvs/ip_vs_proto_udp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "d418d73acf8be62744dc47359dfdde8c2148845d",
"status": "affected",
"version": "2a3b791e6e1169f374224d164738e9f7be703d77",
"versionType": "git"
},
{
"lessThan": "b3869d9b54e76dff64118dee4c8fd9302fcd5171",
"status": "affected",
"version": "2a3b791e6e1169f374224d164738e9f7be703d77",
"versionType": "git"
},
{
"lessThan": "9cbe2c0fdb71904ee929b1851cdc1c73341a03c0",
"status": "affected",
"version": "2a3b791e6e1169f374224d164738e9f7be703d77",
"versionType": "git"
},
{
"lessThan": "00eb23829fd08df1b5e057cb6b625996a70e7e65",
"status": "affected",
"version": "2a3b791e6e1169f374224d164738e9f7be703d77",
"versionType": "git"
},
{
"lessThan": "5558a85add073215b298f3e044ff9a6d86d714ae",
"status": "affected",
"version": "2a3b791e6e1169f374224d164738e9f7be703d77",
"versionType": "git"
},
{
"lessThan": "e876b75b9020a97bbdc79721e7fc749024891c65",
"status": "affected",
"version": "2a3b791e6e1169f374224d164738e9f7be703d77",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"include/net/ip_vs.h",
"net/netfilter/ipvs/ip_vs_core.c",
"net/netfilter/ipvs/ip_vs_proto_sctp.c",
"net/netfilter/ipvs/ip_vs_proto_tcp.c",
"net/netfilter/ipvs/ip_vs_proto_udp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.28"
},
{
"lessThan": "2.6.28",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "2.6.28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.28",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nipvs: fix the checksum validations\n\nip_vs_in_icmp_v6() is missing checksum validation for ICMPv6\npackets from clients. In fact, as for TCP/UDP we should\nvalidate the checksum for ICMP packets only when we\nmangle the packets on MASQ or on reply for tunnel.\n\nAlso, Sashiko points out that handle_response_icmp() being\ncommon for IPv4 and IPv6 is missing the pseudo-header\ncalculation while validating ICMPv6 messages from real\nservers which is a problem if checksum is not validated\nby the hardware.\n\nFix the problems by creating ip_vs_checksum_common_check()\nhelper and use it for TCP/UDP/ICMP both for IPv4 and IPv6.\nRely on the nf_checksum() for validating the ICMP messages\nbut use it also for TCP and UDP.\n\nUse correct IP offset for IP_VS_DBG_RL_PKT for TCP/UDP/SCTP.\n\nIPVS packets (TCP/UDP/SCTP/ICMP) do not need checksum\nvalidation on LOCAL_OUT (local clients or local real\nservers) and on FORWARD (traffic from servers on LAN).\nDo it only on LOCAL_IN, in case nf_checksum() is not\ncalled on PRE_ROUTING.\n\nAlso, ip_vs_checksum_complete() can be marked static."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T17:11:15.780Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/d418d73acf8be62744dc47359dfdde8c2148845d"
},
{
"url": "https://git.kernel.org/stable/c/b3869d9b54e76dff64118dee4c8fd9302fcd5171"
},
{
"url": "https://git.kernel.org/stable/c/9cbe2c0fdb71904ee929b1851cdc1c73341a03c0"
},
{
"url": "https://git.kernel.org/stable/c/00eb23829fd08df1b5e057cb6b625996a70e7e65"
},
{
"url": "https://git.kernel.org/stable/c/5558a85add073215b298f3e044ff9a6d86d714ae"
},
{
"url": "https://git.kernel.org/stable/c/e876b75b9020a97bbdc79721e7fc749024891c65"
}
],
"title": "ipvs: fix the checksum validations",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80901",
"datePublished": "2026-09-04T17:11:15.780Z",
"dateReserved": "2026-08-26T14:34:25.800Z",
"dateUpdated": "2026-09-04T17:11:15.780Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72063 (GCVE-0-2026-72063)
Vulnerability from cvelistv5
Published
2026-08-15 05:52
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
gpio: tegra: do not call pinctrl for GPIO direction
tegra_gpio_direction_input() and tegra_gpio_direction_output() already
program the GPIO controller direction registers directly. The additional
pinctrl_gpio_direction_input/output() calls do not add a Tegra pinctrl
operation, because the Tegra pinmux ops provide GPIO request/free
handling but no gpio_set_direction hook.
The extra call still enters the pinctrl core and takes pctldev->mutex.
Shared GPIO users can call the direction path while holding their
per-line spinlock, so this otherwise redundant pinctrl direction call can
sleep in an atomic context.
This was found by our static analysis tool and then confirmed by manual
review of tegra_gpio_probe(), the Tegra GPIO direction callbacks and the
Tegra pinctrl ops. The reviewed path has a default non-sleeping
struct gpio_chip while the direction callback still enters the pinctrl
mutex path.
A directed runtime validation kept the same non-sleeping chip registration
and drove:
gpio_shared_proxy_direction_output()
gpiod_direction_output_raw_commit()
tegra_gpio_direction_output()
pinctrl_gpio_direction_output()
Lockdep reported a sleep-in-atomic warning with the shared GPIO spinlock
held and pinctrl_get_device_gpio_range() plus tegra_gpio_direction_output()
on the stack.
Do not mark the whole chip as can_sleep to paper over this: can_sleep
describes whether get()/set() may sleep, and Tegra value access is MMIO.
Remove the redundant pinctrl direction calls and keep pinctrl involvement
in the existing request/free path.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 11da905412833d9b369a6a09a401f87149d674dc Version: 11da905412833d9b369a6a09a401f87149d674dc Version: 11da905412833d9b369a6a09a401f87149d674dc Version: 11da905412833d9b369a6a09a401f87149d674dc Version: 11da905412833d9b369a6a09a401f87149d674dc Version: 11da905412833d9b369a6a09a401f87149d674dc Version: 11da905412833d9b369a6a09a401f87149d674dc Version: 11da905412833d9b369a6a09a401f87149d674dc |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpio/gpio-tegra.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "89904b4f1dc0f9550c3f206dcdfceed0b7ce7c49",
"status": "affected",
"version": "11da905412833d9b369a6a09a401f87149d674dc",
"versionType": "git"
},
{
"lessThan": "d3b92d16e1c4debec7526b6dbb2d98d0aeed796b",
"status": "affected",
"version": "11da905412833d9b369a6a09a401f87149d674dc",
"versionType": "git"
},
{
"lessThan": "616188becd4a208afbae1653fc5241e1748bae80",
"status": "affected",
"version": "11da905412833d9b369a6a09a401f87149d674dc",
"versionType": "git"
},
{
"lessThan": "e57a4845b0da60a7b9f052160878097826320954",
"status": "affected",
"version": "11da905412833d9b369a6a09a401f87149d674dc",
"versionType": "git"
},
{
"lessThan": "cd17c5a1d9f186b57e9e2949be427803b7110a5c",
"status": "affected",
"version": "11da905412833d9b369a6a09a401f87149d674dc",
"versionType": "git"
},
{
"lessThan": "ac761e66708d51dac35c4c7f1891ea991dc788f0",
"status": "affected",
"version": "11da905412833d9b369a6a09a401f87149d674dc",
"versionType": "git"
},
{
"lessThan": "628c63f96f4564fa145f602af2d41daf9532201f",
"status": "affected",
"version": "11da905412833d9b369a6a09a401f87149d674dc",
"versionType": "git"
},
{
"lessThan": "d3e91a95b2b0fc6336dbf3ec90d831a1654d2720",
"status": "affected",
"version": "11da905412833d9b369a6a09a401f87149d674dc",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpio/gpio-tegra.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.1"
},
{
"lessThan": "5.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ngpio: tegra: do not call pinctrl for GPIO direction\n\ntegra_gpio_direction_input() and tegra_gpio_direction_output() already\nprogram the GPIO controller direction registers directly. The additional\npinctrl_gpio_direction_input/output() calls do not add a Tegra pinctrl\noperation, because the Tegra pinmux ops provide GPIO request/free\nhandling but no gpio_set_direction hook.\n\nThe extra call still enters the pinctrl core and takes pctldev-\u003emutex.\nShared GPIO users can call the direction path while holding their\nper-line spinlock, so this otherwise redundant pinctrl direction call can\nsleep in an atomic context.\n\nThis was found by our static analysis tool and then confirmed by manual\nreview of tegra_gpio_probe(), the Tegra GPIO direction callbacks and the\nTegra pinctrl ops. The reviewed path has a default non-sleeping\nstruct gpio_chip while the direction callback still enters the pinctrl\nmutex path.\n\nA directed runtime validation kept the same non-sleeping chip registration\nand drove:\n\n gpio_shared_proxy_direction_output()\n gpiod_direction_output_raw_commit()\n tegra_gpio_direction_output()\n pinctrl_gpio_direction_output()\n\nLockdep reported a sleep-in-atomic warning with the shared GPIO spinlock\nheld and pinctrl_get_device_gpio_range() plus tegra_gpio_direction_output()\non the stack.\n\nDo not mark the whole chip as can_sleep to paper over this: can_sleep\ndescribes whether get()/set() may sleep, and Tegra value access is MMIO.\nRemove the redundant pinctrl direction calls and keep pinctrl involvement\nin the existing request/free path."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:39.651Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/89904b4f1dc0f9550c3f206dcdfceed0b7ce7c49"
},
{
"url": "https://git.kernel.org/stable/c/d3b92d16e1c4debec7526b6dbb2d98d0aeed796b"
},
{
"url": "https://git.kernel.org/stable/c/616188becd4a208afbae1653fc5241e1748bae80"
},
{
"url": "https://git.kernel.org/stable/c/e57a4845b0da60a7b9f052160878097826320954"
},
{
"url": "https://git.kernel.org/stable/c/cd17c5a1d9f186b57e9e2949be427803b7110a5c"
},
{
"url": "https://git.kernel.org/stable/c/ac761e66708d51dac35c4c7f1891ea991dc788f0"
},
{
"url": "https://git.kernel.org/stable/c/628c63f96f4564fa145f602af2d41daf9532201f"
},
{
"url": "https://git.kernel.org/stable/c/d3e91a95b2b0fc6336dbf3ec90d831a1654d2720"
}
],
"title": "gpio: tegra: do not call pinctrl for GPIO direction",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72063",
"datePublished": "2026-08-15T05:52:17.315Z",
"dateReserved": "2026-08-09T03:40:39.903Z",
"dateUpdated": "2026-08-23T12:46:39.651Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64139 (GCVE-0-2026-64139)
Vulnerability from cvelistv5
Published
2026-07-19 15:40
Modified
2026-08-23 12:45
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix SID memory leak in set_posix_acl_entries_dacl() on overflow
Commit 299f962c0b02 ("ksmbd: use check_add_overflow() to prevent u16
DACL size overflow") added check_add_overflow() guards that break out
of the ACE-building loops in set_posix_acl_entries_dacl() when the
accumulated DACL size would wrap past 65535.
However, each iteration allocates a struct smb_sid via kmalloc_obj()
at the top of the loop and relies on the kfree(sid) call at the end
of the loop body (the 'pass_same_sid' label in the first loop, and
the explicit kfree at the tail of the second loop) to release it.
The newly introduced 'break' statements bypass those kfree() calls,
leaking the sid buffer every time an overflow is detected.
A malicious or malformed file with enough POSIX ACL entries to trip
the overflow check will leak one or more struct smb_sid allocations
on every request that touches the file's DACL, providing a trivial
kernel memory exhaustion vector.
Free sid before breaking out of the loops to plug the leak.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 41e53a773db6342ac9a689ee5ba635c31744c9f0 Version: 8d5729350b236896f51379588d9a690b7fafb8db Version: e1955a94b6f17f4b058afa955a6f187eb3ed7615 Version: 5e7b8f3c539d69b2ed5f2408e2f75e68ce7eef43 Version: ef7902be3f215b6bf7babe4dc9dd9a7d57dad7a7 Version: 299f962c0b02d048fb45d248b4da493d03f3175d |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/smb/server/smbacl.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "9b0a8985b419a71ee1cc9c0cc6a9e1bb7815a2c5",
"status": "affected",
"version": "41e53a773db6342ac9a689ee5ba635c31744c9f0",
"versionType": "git"
},
{
"lessThan": "9d378e17c864da08c3a4df41dae92cfa6468b00a",
"status": "affected",
"version": "8d5729350b236896f51379588d9a690b7fafb8db",
"versionType": "git"
},
{
"lessThan": "519fb0a42ce5d7e46935577309fb282a5f2c6ea3",
"status": "affected",
"version": "e1955a94b6f17f4b058afa955a6f187eb3ed7615",
"versionType": "git"
},
{
"lessThan": "0e198f09cb2a554c04de0fea4e790f1250a943ca",
"status": "affected",
"version": "5e7b8f3c539d69b2ed5f2408e2f75e68ce7eef43",
"versionType": "git"
},
{
"lessThan": "eced48cb08f07393a5ea770fdd1026452883c3ad",
"status": "affected",
"version": "ef7902be3f215b6bf7babe4dc9dd9a7d57dad7a7",
"versionType": "git"
},
{
"lessThan": "af92ee994cc7f7e83a41c2025f32257a2f82a7ef",
"status": "affected",
"version": "299f962c0b02d048fb45d248b4da493d03f3175d",
"versionType": "git"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/smb/server/smbacl.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "6.1.184",
"status": "affected",
"version": "6.1.175",
"versionType": "semver"
},
{
"lessThan": "6.6.142",
"status": "affected",
"version": "6.6.136",
"versionType": "semver"
},
{
"lessThan": "6.12.92",
"status": "affected",
"version": "6.12.84",
"versionType": "semver"
},
{
"lessThan": "6.18.34",
"status": "affected",
"version": "6.18.25",
"versionType": "semver"
},
{
"lessThan": "7.0.11",
"status": "affected",
"version": "7.0.2",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "6.1.175",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.142",
"versionStartIncluding": "6.6.136",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.92",
"versionStartIncluding": "6.12.84",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.34",
"versionStartIncluding": "6.18.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "7.0.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix SID memory leak in set_posix_acl_entries_dacl() on overflow\n\nCommit 299f962c0b02 (\"ksmbd: use check_add_overflow() to prevent u16\nDACL size overflow\") added check_add_overflow() guards that break out\nof the ACE-building loops in set_posix_acl_entries_dacl() when the\naccumulated DACL size would wrap past 65535.\n\nHowever, each iteration allocates a struct smb_sid via kmalloc_obj()\nat the top of the loop and relies on the kfree(sid) call at the end\nof the loop body (the \u0027pass_same_sid\u0027 label in the first loop, and\nthe explicit kfree at the tail of the second loop) to release it.\nThe newly introduced \u0027break\u0027 statements bypass those kfree() calls,\nleaking the sid buffer every time an overflow is detected.\n\nA malicious or malformed file with enough POSIX ACL entries to trip\nthe overflow check will leak one or more struct smb_sid allocations\non every request that touches the file\u0027s DACL, providing a trivial\nkernel memory exhaustion vector.\n\nFree sid before breaking out of the loops to plug the leak."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:45:33.681Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/9b0a8985b419a71ee1cc9c0cc6a9e1bb7815a2c5"
},
{
"url": "https://git.kernel.org/stable/c/9d378e17c864da08c3a4df41dae92cfa6468b00a"
},
{
"url": "https://git.kernel.org/stable/c/519fb0a42ce5d7e46935577309fb282a5f2c6ea3"
},
{
"url": "https://git.kernel.org/stable/c/0e198f09cb2a554c04de0fea4e790f1250a943ca"
},
{
"url": "https://git.kernel.org/stable/c/eced48cb08f07393a5ea770fdd1026452883c3ad"
},
{
"url": "https://git.kernel.org/stable/c/af92ee994cc7f7e83a41c2025f32257a2f82a7ef"
}
],
"title": "ksmbd: fix SID memory leak in set_posix_acl_entries_dacl() on overflow",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64139",
"datePublished": "2026-07-19T15:40:32.459Z",
"dateReserved": "2026-07-19T07:54:57.037Z",
"dateUpdated": "2026-08-23T12:45:33.681Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68451 (GCVE-0-2026-68451)
Vulnerability from cvelistv5
Published
2026-08-13 13:59
Modified
2026-08-19 16:35
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
s390/zcrypt: Validate length for CCA ECC private key requests
cca_ecc2protkey() derives the copy length for the CPRB parameter
block directly from the length field in the key token. Reject the
request early if the token length exceeds the available space in the
parameter block.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: fa6999e326fe7851ecbd572b8cb9be8e930ebf41 Version: fa6999e326fe7851ecbd572b8cb9be8e930ebf41 Version: fa6999e326fe7851ecbd572b8cb9be8e930ebf41 Version: fa6999e326fe7851ecbd572b8cb9be8e930ebf41 Version: fa6999e326fe7851ecbd572b8cb9be8e930ebf41 Version: fa6999e326fe7851ecbd572b8cb9be8e930ebf41 Version: fa6999e326fe7851ecbd572b8cb9be8e930ebf41 Version: fa6999e326fe7851ecbd572b8cb9be8e930ebf41 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/s390/crypto/zcrypt_ccamisc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "7dc306ff7c4d951582adaae65e0aee9fb4968dbe",
"status": "affected",
"version": "fa6999e326fe7851ecbd572b8cb9be8e930ebf41",
"versionType": "git"
},
{
"lessThan": "447a37a6bef11bfd3645069e380460b11386e2b9",
"status": "affected",
"version": "fa6999e326fe7851ecbd572b8cb9be8e930ebf41",
"versionType": "git"
},
{
"lessThan": "f0831f13c42c1261d449dcee8a035e1c6cd9fcaa",
"status": "affected",
"version": "fa6999e326fe7851ecbd572b8cb9be8e930ebf41",
"versionType": "git"
},
{
"lessThan": "dd25bd9b0f36849808bd7625dcc59dd4c1aeef3e",
"status": "affected",
"version": "fa6999e326fe7851ecbd572b8cb9be8e930ebf41",
"versionType": "git"
},
{
"lessThan": "ecc3b8691c1935f9f3e4eb964ab11e40fdec17f5",
"status": "affected",
"version": "fa6999e326fe7851ecbd572b8cb9be8e930ebf41",
"versionType": "git"
},
{
"lessThan": "013a4484f061a2b41f052e25c0015203287e63f1",
"status": "affected",
"version": "fa6999e326fe7851ecbd572b8cb9be8e930ebf41",
"versionType": "git"
},
{
"lessThan": "8fa3e9435a13c335efb63fb4f4e77531a0031159",
"status": "affected",
"version": "fa6999e326fe7851ecbd572b8cb9be8e930ebf41",
"versionType": "git"
},
{
"lessThan": "a9ae0f6dd45c3ccc1d69363f7aea8af179122730",
"status": "affected",
"version": "fa6999e326fe7851ecbd572b8cb9be8e930ebf41",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/s390/crypto/zcrypt_ccamisc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.10"
},
{
"lessThan": "5.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/zcrypt: Validate length for CCA ECC private key requests\n\ncca_ecc2protkey() derives the copy length for the CPRB parameter\nblock directly from the length field in the key token. Reject the\nrequest early if the token length exceeds the available space in the\nparameter block."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached through the `/dev/pkey` misc device via the PKEY_KBLOB2PROTK/PROTK2/PROTK3 ioctls, requiring local access to the s390 system; there is no remote or network-facing path into cca_ecc2protkey().\nAC:L - The attacker fully controls both the overflow length and the overflowing bytes by crafting the ECC key token\u0027s `len` field and blob contents, and the memcpy executes deterministically on every call with no race, timing, or layout precondition.\nPR:L - The pkey misc device is registered with mode 0666 and pkey_unlocked_ioctl performs no capability check, so any unprivileged local user (or a container/sandbox process with the node visible) can issue the ioctl.\nUI:N - The attacker triggers the overflow entirely from its own ioctl call; no action by another user or administrator is needed.\nS:U - The heap corruption occurs in kernel memory within the same security authority; no VM, IOMMU, or other trust boundary is crossed by the overflow itself.\nC:H - The controlled slab overflow can overwrite adjacent kernel objects (pointers, lengths, credentials) with attacker-chosen data, which is readily leveraged into arbitrary kernel memory disclosure, including protected/secure key material handled by this subsystem.\nI:H - memcpy() writes up to ~7 KB of fully attacker-controlled data past a kmalloc\u0027d CPRB buffer, giving a classic controlled heap out-of-bounds write usable for corrupting neighbouring slab objects and achieving privilege escalation or control-flow hijack.\nA:H - Even without reliable exploitation, the oversized memcpy smashes the slab and neighbouring allocations, causing memory corruption, SLUB/redzone BUG detonations, oops or kernel panic, repeatedly triggerable by an unprivileged user."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:35:48.084Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/7dc306ff7c4d951582adaae65e0aee9fb4968dbe"
},
{
"url": "https://git.kernel.org/stable/c/447a37a6bef11bfd3645069e380460b11386e2b9"
},
{
"url": "https://git.kernel.org/stable/c/f0831f13c42c1261d449dcee8a035e1c6cd9fcaa"
},
{
"url": "https://git.kernel.org/stable/c/dd25bd9b0f36849808bd7625dcc59dd4c1aeef3e"
},
{
"url": "https://git.kernel.org/stable/c/ecc3b8691c1935f9f3e4eb964ab11e40fdec17f5"
},
{
"url": "https://git.kernel.org/stable/c/013a4484f061a2b41f052e25c0015203287e63f1"
},
{
"url": "https://git.kernel.org/stable/c/8fa3e9435a13c335efb63fb4f4e77531a0031159"
},
{
"url": "https://git.kernel.org/stable/c/a9ae0f6dd45c3ccc1d69363f7aea8af179122730"
}
],
"title": "s390/zcrypt: Validate length for CCA ECC private key requests",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68451",
"datePublished": "2026-08-13T13:59:53.674Z",
"dateReserved": "2026-07-30T09:28:09.395Z",
"dateUpdated": "2026-08-19T16:35:48.084Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2025-39833 (GCVE-0-2025-39833)
Vulnerability from cvelistv5
Published
2025-09-16 13:08
Modified
2026-09-02 12:49
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
mISDN: hfcpci: Fix warning when deleting uninitialized timer
With CONFIG_DEBUG_OBJECTS_TIMERS unloading hfcpci module leads
to the following splat:
[ 250.215892] ODEBUG: assert_init not available (active state 0) object: ffffffffc01a3dc0 object type: timer_list hint: 0x0
[ 250.217520] WARNING: CPU: 0 PID: 233 at lib/debugobjects.c:612 debug_print_object+0x1b6/0x2c0
[ 250.218775] Modules linked in: hfcpci(-) mISDN_core
[ 250.219537] CPU: 0 UID: 0 PID: 233 Comm: rmmod Not tainted 6.17.0-rc2-g6f713187ac98 #2 PREEMPT(voluntary)
[ 250.220940] Hardware name: QEMU Ubuntu 24.04 PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
[ 250.222377] RIP: 0010:debug_print_object+0x1b6/0x2c0
[ 250.223131] Code: fc ff df 48 89 fa 48 c1 ea 03 80 3c 02 00 75 4f 41 56 48 8b 14 dd a0 4e 01 9f 48 89 ee 48 c7 c7 20 46 01 9f e8 cb 84d
[ 250.225805] RSP: 0018:ffff888015ea7c08 EFLAGS: 00010286
[ 250.226608] RAX: 0000000000000000 RBX: 0000000000000005 RCX: ffffffff9be93a95
[ 250.227708] RDX: 1ffff1100d945138 RSI: 0000000000000008 RDI: ffff88806ca289c0
[ 250.228993] RBP: ffffffff9f014a00 R08: 0000000000000001 R09: ffffed1002bd4f39
[ 250.230043] R10: ffff888015ea79cf R11: 0000000000000001 R12: 0000000000000001
[ 250.231185] R13: ffffffff9eea0520 R14: 0000000000000000 R15: ffff888015ea7cc8
[ 250.232454] FS: 00007f3208f01540(0000) GS:ffff8880caf5a000(0000) knlGS:0000000000000000
[ 250.233851] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[ 250.234856] CR2: 00007f32090a7421 CR3: 0000000004d63000 CR4: 00000000000006f0
[ 250.236117] Call Trace:
[ 250.236599] <TASK>
[ 250.236967] ? trace_irq_enable.constprop.0+0xd4/0x130
[ 250.237920] debug_object_assert_init+0x1f6/0x310
[ 250.238762] ? __pfx_debug_object_assert_init+0x10/0x10
[ 250.239658] ? __lock_acquire+0xdea/0x1c70
[ 250.240369] __try_to_del_timer_sync+0x69/0x140
[ 250.241172] ? __pfx___try_to_del_timer_sync+0x10/0x10
[ 250.242058] ? __timer_delete_sync+0xc6/0x120
[ 250.242842] ? lock_acquire+0x30/0x80
[ 250.243474] ? __timer_delete_sync+0xc6/0x120
[ 250.244262] __timer_delete_sync+0x98/0x120
[ 250.245015] HFC_cleanup+0x10/0x20 [hfcpci]
[ 250.245704] __do_sys_delete_module+0x348/0x510
[ 250.246461] ? __pfx___do_sys_delete_module+0x10/0x10
[ 250.247338] do_syscall_64+0xc1/0x360
[ 250.247924] entry_SYSCALL_64_after_hwframe+0x77/0x7f
Fix this by initializing hfc_tl timer with DEFINE_TIMER macro.
Also, use mod_timer instead of manual timeout update.
References
| URL | Tags | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"containers": {
"adp": [
{
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 5.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
}
},
{
"other": {
"content": {
"id": "CVE-2025-39833",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-01-14T18:18:25.755383Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-908",
"description": "CWE-908 Use of Uninitialized Resource",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-01-14T18:22:57.060Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/isdn/hardware/mISDN/hfcpci.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "d8be1288e398ccda2dc590fdaa0551f192f6a1c6",
"status": "affected",
"version": "87c5fa1bb42624254a2013cbbc3b170d6017f5d6",
"versionType": "git"
},
{
"lessThan": "75194165e65018c581b128379b91b0b2d64638d9",
"status": "affected",
"version": "87c5fa1bb42624254a2013cbbc3b170d6017f5d6",
"versionType": "git"
},
{
"lessThan": "544ffd62ddd093c71150e4d4c542f98153fb8e46",
"status": "affected",
"version": "87c5fa1bb42624254a2013cbbc3b170d6017f5d6",
"versionType": "git"
},
{
"lessThan": "43fc5da8133badf17f5df250ba03b9d882254845",
"status": "affected",
"version": "87c5fa1bb42624254a2013cbbc3b170d6017f5d6",
"versionType": "git"
},
{
"lessThan": "97766512a9951b9fd6fc97f1b93211642bb0b220",
"status": "affected",
"version": "87c5fa1bb42624254a2013cbbc3b170d6017f5d6",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/isdn/hardware/mISDN/hfcpci.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.29"
},
{
"lessThan": "2.6.29",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.187",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.156",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.108",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.16.*",
"status": "unaffected",
"version": "6.16.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "6.17",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.187",
"versionStartIncluding": "2.6.29",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.156",
"versionStartIncluding": "2.6.29",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.108",
"versionStartIncluding": "2.6.29",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.16.5",
"versionStartIncluding": "2.6.29",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.17",
"versionStartIncluding": "2.6.29",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmISDN: hfcpci: Fix warning when deleting uninitialized timer\n\nWith CONFIG_DEBUG_OBJECTS_TIMERS unloading hfcpci module leads\nto the following splat:\n\n[ 250.215892] ODEBUG: assert_init not available (active state 0) object: ffffffffc01a3dc0 object type: timer_list hint: 0x0\n[ 250.217520] WARNING: CPU: 0 PID: 233 at lib/debugobjects.c:612 debug_print_object+0x1b6/0x2c0\n[ 250.218775] Modules linked in: hfcpci(-) mISDN_core\n[ 250.219537] CPU: 0 UID: 0 PID: 233 Comm: rmmod Not tainted 6.17.0-rc2-g6f713187ac98 #2 PREEMPT(voluntary)\n[ 250.220940] Hardware name: QEMU Ubuntu 24.04 PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\n[ 250.222377] RIP: 0010:debug_print_object+0x1b6/0x2c0\n[ 250.223131] Code: fc ff df 48 89 fa 48 c1 ea 03 80 3c 02 00 75 4f 41 56 48 8b 14 dd a0 4e 01 9f 48 89 ee 48 c7 c7 20 46 01 9f e8 cb 84d\n[ 250.225805] RSP: 0018:ffff888015ea7c08 EFLAGS: 00010286\n[ 250.226608] RAX: 0000000000000000 RBX: 0000000000000005 RCX: ffffffff9be93a95\n[ 250.227708] RDX: 1ffff1100d945138 RSI: 0000000000000008 RDI: ffff88806ca289c0\n[ 250.228993] RBP: ffffffff9f014a00 R08: 0000000000000001 R09: ffffed1002bd4f39\n[ 250.230043] R10: ffff888015ea79cf R11: 0000000000000001 R12: 0000000000000001\n[ 250.231185] R13: ffffffff9eea0520 R14: 0000000000000000 R15: ffff888015ea7cc8\n[ 250.232454] FS: 00007f3208f01540(0000) GS:ffff8880caf5a000(0000) knlGS:0000000000000000\n[ 250.233851] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 250.234856] CR2: 00007f32090a7421 CR3: 0000000004d63000 CR4: 00000000000006f0\n[ 250.236117] Call Trace:\n[ 250.236599] \u003cTASK\u003e\n[ 250.236967] ? trace_irq_enable.constprop.0+0xd4/0x130\n[ 250.237920] debug_object_assert_init+0x1f6/0x310\n[ 250.238762] ? __pfx_debug_object_assert_init+0x10/0x10\n[ 250.239658] ? __lock_acquire+0xdea/0x1c70\n[ 250.240369] __try_to_del_timer_sync+0x69/0x140\n[ 250.241172] ? __pfx___try_to_del_timer_sync+0x10/0x10\n[ 250.242058] ? __timer_delete_sync+0xc6/0x120\n[ 250.242842] ? lock_acquire+0x30/0x80\n[ 250.243474] ? __timer_delete_sync+0xc6/0x120\n[ 250.244262] __timer_delete_sync+0x98/0x120\n[ 250.245015] HFC_cleanup+0x10/0x20 [hfcpci]\n[ 250.245704] __do_sys_delete_module+0x348/0x510\n[ 250.246461] ? __pfx___do_sys_delete_module+0x10/0x10\n[ 250.247338] do_syscall_64+0xc1/0x360\n[ 250.247924] entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nFix this by initializing hfc_tl timer with DEFINE_TIMER macro.\nAlso, use mod_timer instead of manual timeout update."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-02T12:49:22.578Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/d8be1288e398ccda2dc590fdaa0551f192f6a1c6"
},
{
"url": "https://git.kernel.org/stable/c/75194165e65018c581b128379b91b0b2d64638d9"
},
{
"url": "https://git.kernel.org/stable/c/544ffd62ddd093c71150e4d4c542f98153fb8e46"
},
{
"url": "https://git.kernel.org/stable/c/43fc5da8133badf17f5df250ba03b9d882254845"
},
{
"url": "https://git.kernel.org/stable/c/97766512a9951b9fd6fc97f1b93211642bb0b220"
}
],
"title": "mISDN: hfcpci: Fix warning when deleting uninitialized timer",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2025-39833",
"datePublished": "2025-09-16T13:08:50.192Z",
"dateReserved": "2025-04-16T07:20:57.140Z",
"dateUpdated": "2026-09-02T12:49:22.578Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80572 (GCVE-0-2026-80572)
Vulnerability from cvelistv5
Published
2026-08-26 14:37
Modified
2026-08-27 12:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Input: byd - synchronize timer deletion before freeing private data
byd_disconnect() uses timer_delete() before freeing the driver's private
data. This does not wait for a running byd_clear_touch() callback, which
dereferences the private data and its psmouse pointer. A callback racing
with disconnect can therefore access the private data after it has been
freed. The timer can also still be re-armed by byd_process_byte() while
the disconnect is in progress.
Use timer_shutdown_sync() before freeing the private data: it waits for
a running callback and turns any later re-arm attempt into a no-op.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 2d5f5611dd0de52e9a52b56391a7049a52184e72 Version: 2d5f5611dd0de52e9a52b56391a7049a52184e72 Version: 2d5f5611dd0de52e9a52b56391a7049a52184e72 Version: 2d5f5611dd0de52e9a52b56391a7049a52184e72 Version: 2d5f5611dd0de52e9a52b56391a7049a52184e72 Version: 2d5f5611dd0de52e9a52b56391a7049a52184e72 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/input/mouse/byd.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "84b205297fa15f97510342221d8c9a0119711478",
"status": "affected",
"version": "2d5f5611dd0de52e9a52b56391a7049a52184e72",
"versionType": "git"
},
{
"lessThan": "28d984a66b9e14be74986167b6ad40b5e0daf19a",
"status": "affected",
"version": "2d5f5611dd0de52e9a52b56391a7049a52184e72",
"versionType": "git"
},
{
"lessThan": "ee944a706a18322b4a2599eebe8040a2994e928f",
"status": "affected",
"version": "2d5f5611dd0de52e9a52b56391a7049a52184e72",
"versionType": "git"
},
{
"lessThan": "8dbfd8e32a13e116790780ed0be82b5a05eb9916",
"status": "affected",
"version": "2d5f5611dd0de52e9a52b56391a7049a52184e72",
"versionType": "git"
},
{
"lessThan": "2e509ef60ee41a2da0deb062c262bb530143fb37",
"status": "affected",
"version": "2d5f5611dd0de52e9a52b56391a7049a52184e72",
"versionType": "git"
},
{
"lessThan": "c83e79c0842ed29860648bcce5022ef0ba5001c6",
"status": "affected",
"version": "2d5f5611dd0de52e9a52b56391a7049a52184e72",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/input/mouse/byd.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.6"
},
{
"lessThan": "4.6",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.185",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.154",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.106",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.185",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.154",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.106",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.46",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.10",
"versionStartIncluding": "4.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nInput: byd - synchronize timer deletion before freeing private data\n\nbyd_disconnect() uses timer_delete() before freeing the driver\u0027s private\ndata. This does not wait for a running byd_clear_touch() callback, which\ndereferences the private data and its psmouse pointer. A callback racing\nwith disconnect can therefore access the private data after it has been\nfreed. The timer can also still be re-armed by byd_process_byte() while\nthe disconnect is in progress.\n\nUse timer_shutdown_sync() before freeing the private data: it waits for\na running callback and turns any later re-arm attempt into a no-op."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Reachable from local PS/2 input: BYD packets enter via serio_interrupt() from built-in touchpad hardware or userio-emulated SERIO_8042 port; byd_process_byte()/byd_disconnect() are not network-exposed.\nAC:L - An attacker can arm the 64ms byd_clear_touch timer via touch/relative packets while concurrently closing userio or unbinding the port to invoke byd_disconnect(), controlling both sides of the disconnect/timer race.\nPR:L - Exploitation needs only local access to the PS/2 touchpad or /dev/userio to inject packets and trigger teardown; no init-namespace root, CAP_SYS_ADMIN, or write access to psmouse sysfs is required.\nUI:N - The attacker supplies touchpad traffic and drives device disconnect/emulation teardown themselves; no separate victim interaction (mount, plug-in approval, or click) is needed.\nS:U - Corruption stays within the host kernel address space during PS/2 driver teardown; it is standard local privilege escalation, not a guest-to-host or sandbox boundary crossing.\nC:H - byd_clear_touch() dereferences freed byd_data (priv-\u003epsmouse) and can read attacker-reclaimed slab contents, enabling kernel pointer disclosure and broader arbitrary read primitives typical of heap use-after-free bugs.\nI:H - The timer callback writes into freed byd_data fields and may call input/report helpers through a stale psmouse pointer, giving heap corruption and a path to arbitrary kernel writes or control-flow hijacking.\nA:H - Racing the timer with disconnect can cause invalid pointer dereferences, use-after-free access, kernel oops, or panic during input teardown; the condition is repeatable by re-arming the timer."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T12:40:19.284Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/84b205297fa15f97510342221d8c9a0119711478"
},
{
"url": "https://git.kernel.org/stable/c/28d984a66b9e14be74986167b6ad40b5e0daf19a"
},
{
"url": "https://git.kernel.org/stable/c/ee944a706a18322b4a2599eebe8040a2994e928f"
},
{
"url": "https://git.kernel.org/stable/c/8dbfd8e32a13e116790780ed0be82b5a05eb9916"
},
{
"url": "https://git.kernel.org/stable/c/2e509ef60ee41a2da0deb062c262bb530143fb37"
},
{
"url": "https://git.kernel.org/stable/c/c83e79c0842ed29860648bcce5022ef0ba5001c6"
}
],
"title": "Input: byd - synchronize timer deletion before freeing private data",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80572",
"datePublished": "2026-08-26T14:37:33.141Z",
"dateReserved": "2026-08-26T14:34:25.768Z",
"dateUpdated": "2026-08-27T12:40:19.284Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2025-40054 (GCVE-0-2025-40054)
Vulnerability from cvelistv5
Published
2025-10-28 11:48
Modified
2026-08-23 12:45
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
f2fs: fix UAF issue in f2fs_merge_page_bio()
As JY reported in bugzilla [1],
Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000
pc : [0xffffffe51d249484] f2fs_is_cp_guaranteed+0x70/0x98
lr : [0xffffffe51d24adbc] f2fs_merge_page_bio+0x520/0x6d4
CPU: 3 UID: 0 PID: 6790 Comm: kworker/u16:3 Tainted: P B W OE 6.12.30-android16-5-maybe-dirty-4k #1 5f7701c9cbf727d1eebe77c89bbbeb3371e895e5
Tainted: [P]=PROPRIETARY_MODULE, [B]=BAD_PAGE, [W]=WARN, [O]=OOT_MODULE, [E]=UNSIGNED_MODULE
Workqueue: writeback wb_workfn (flush-254:49)
Call trace:
f2fs_is_cp_guaranteed+0x70/0x98
f2fs_inplace_write_data+0x174/0x2f4
f2fs_do_write_data_page+0x214/0x81c
f2fs_write_single_data_page+0x28c/0x764
f2fs_write_data_pages+0x78c/0xce4
do_writepages+0xe8/0x2fc
__writeback_single_inode+0x4c/0x4b4
writeback_sb_inodes+0x314/0x540
__writeback_inodes_wb+0xa4/0xf4
wb_writeback+0x160/0x448
wb_workfn+0x2f0/0x5dc
process_scheduled_works+0x1c8/0x458
worker_thread+0x334/0x3f0
kthread+0x118/0x1ac
ret_from_fork+0x10/0x20
[1] https://bugzilla.kernel.org/show_bug.cgi?id=220575
The panic was caused by UAF issue w/ below race condition:
kworker
- writepages
- f2fs_write_cache_pages
- f2fs_write_single_data_page
- f2fs_do_write_data_page
- f2fs_inplace_write_data
- f2fs_merge_page_bio
- add_inu_page
: cache page #1 into bio & cache bio in
io->bio_list
- f2fs_write_single_data_page
- f2fs_do_write_data_page
- f2fs_inplace_write_data
- f2fs_merge_page_bio
- add_inu_page
: cache page #2 into bio which is linked
in io->bio_list
write
- f2fs_write_begin
: write page #1
- f2fs_folio_wait_writeback
- f2fs_submit_merged_ipu_write
- f2fs_submit_write_bio
: submit bio which inclues page #1 and #2
software IRQ
- f2fs_write_end_io
- fscrypt_free_bounce_page
: freed bounced page which belongs to page #2
- inc_page_count( , WB_DATA_TYPE(data_folio), false)
: data_folio points to fio->encrypted_page
the bounced page can be freed before
accessing it in f2fs_is_cp_guarantee()
It can reproduce w/ below testcase:
Run below script in shell #1:
for ((i=1;i>0;i++)) do xfs_io -f /mnt/f2fs/enc/file \
-c "pwrite 0 32k" -c "fdatasync"
Run below script in shell #2:
for ((i=1;i>0;i++)) do xfs_io -f /mnt/f2fs/enc/file \
-c "pwrite 0 32k" -c "fdatasync"
So, in f2fs_merge_page_bio(), let's avoid using fio->encrypted_page after
commit page into internal ipu cache.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 0b20fcec8651569935a10afe03fedc0b812d044e Version: 0b20fcec8651569935a10afe03fedc0b812d044e Version: 0b20fcec8651569935a10afe03fedc0b812d044e Version: 0b20fcec8651569935a10afe03fedc0b812d044e Version: 0b20fcec8651569935a10afe03fedc0b812d044e Version: 0b20fcec8651569935a10afe03fedc0b812d044e Version: 0b20fcec8651569935a10afe03fedc0b812d044e |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/f2fs/data.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "1f7b44b4a2b2939f08b279cbb9e6b5dcb8ffea32",
"status": "affected",
"version": "0b20fcec8651569935a10afe03fedc0b812d044e",
"versionType": "git"
},
{
"lessThan": "e193d8953647c8b575830852aa5ea0995b98d2b1",
"status": "affected",
"version": "0b20fcec8651569935a10afe03fedc0b812d044e",
"versionType": "git"
},
{
"lessThan": "410337c2301ae78a081e1b5ebbe8ec374fef4cb6",
"status": "affected",
"version": "0b20fcec8651569935a10afe03fedc0b812d044e",
"versionType": "git"
},
{
"lessThan": "68e094232dfe5027c4fd2dcded93d2d6800bae04",
"status": "affected",
"version": "0b20fcec8651569935a10afe03fedc0b812d044e",
"versionType": "git"
},
{
"lessThan": "7dd611131d82d7fc4212b555eb1103160bdad302",
"status": "affected",
"version": "0b20fcec8651569935a10afe03fedc0b812d044e",
"versionType": "git"
},
{
"lessThan": "01118321e0c8a5f3ece57d0d377bfc92d83cd210",
"status": "affected",
"version": "0b20fcec8651569935a10afe03fedc0b812d044e",
"versionType": "git"
},
{
"lessThan": "edf7e9040fc52c922db947f9c6c36f07377c52ea",
"status": "affected",
"version": "0b20fcec8651569935a10afe03fedc0b812d044e",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/f2fs/data.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.5"
},
{
"lessThan": "5.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.17.*",
"status": "unaffected",
"version": "6.17.3",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "6.18",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.17.3",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18",
"versionStartIncluding": "5.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix UAF issue in f2fs_merge_page_bio()\n\nAs JY reported in bugzilla [1],\n\nUnable to handle kernel NULL pointer dereference at virtual address 0000000000000000\npc : [0xffffffe51d249484] f2fs_is_cp_guaranteed+0x70/0x98\nlr : [0xffffffe51d24adbc] f2fs_merge_page_bio+0x520/0x6d4\nCPU: 3 UID: 0 PID: 6790 Comm: kworker/u16:3 Tainted: P B W OE 6.12.30-android16-5-maybe-dirty-4k #1 5f7701c9cbf727d1eebe77c89bbbeb3371e895e5\nTainted: [P]=PROPRIETARY_MODULE, [B]=BAD_PAGE, [W]=WARN, [O]=OOT_MODULE, [E]=UNSIGNED_MODULE\nWorkqueue: writeback wb_workfn (flush-254:49)\nCall trace:\n f2fs_is_cp_guaranteed+0x70/0x98\n f2fs_inplace_write_data+0x174/0x2f4\n f2fs_do_write_data_page+0x214/0x81c\n f2fs_write_single_data_page+0x28c/0x764\n f2fs_write_data_pages+0x78c/0xce4\n do_writepages+0xe8/0x2fc\n __writeback_single_inode+0x4c/0x4b4\n writeback_sb_inodes+0x314/0x540\n __writeback_inodes_wb+0xa4/0xf4\n wb_writeback+0x160/0x448\n wb_workfn+0x2f0/0x5dc\n process_scheduled_works+0x1c8/0x458\n worker_thread+0x334/0x3f0\n kthread+0x118/0x1ac\n ret_from_fork+0x10/0x20\n\n[1] https://bugzilla.kernel.org/show_bug.cgi?id=220575\n\nThe panic was caused by UAF issue w/ below race condition:\n\nkworker\n- writepages\n - f2fs_write_cache_pages\n - f2fs_write_single_data_page\n - f2fs_do_write_data_page\n - f2fs_inplace_write_data\n - f2fs_merge_page_bio\n - add_inu_page\n : cache page #1 into bio \u0026 cache bio in\n io-\u003ebio_list\n - f2fs_write_single_data_page\n - f2fs_do_write_data_page\n - f2fs_inplace_write_data\n - f2fs_merge_page_bio\n - add_inu_page\n : cache page #2 into bio which is linked\n in io-\u003ebio_list\n\t\t\t\t\t\twrite\n\t\t\t\t\t\t- f2fs_write_begin\n\t\t\t\t\t\t: write page #1\n\t\t\t\t\t\t - f2fs_folio_wait_writeback\n\t\t\t\t\t\t - f2fs_submit_merged_ipu_write\n\t\t\t\t\t\t - f2fs_submit_write_bio\n\t\t\t\t\t\t : submit bio which inclues page #1 and #2\n\n\t\t\t\t\t\tsoftware IRQ\n\t\t\t\t\t\t- f2fs_write_end_io\n\t\t\t\t\t\t - fscrypt_free_bounce_page\n\t\t\t\t\t\t : freed bounced page which belongs to page #2\n - inc_page_count( , WB_DATA_TYPE(data_folio), false)\n : data_folio points to fio-\u003eencrypted_page\n the bounced page can be freed before\n accessing it in f2fs_is_cp_guarantee()\n\nIt can reproduce w/ below testcase:\nRun below script in shell #1:\nfor ((i=1;i\u003e0;i++)) do xfs_io -f /mnt/f2fs/enc/file \\\n-c \"pwrite 0 32k\" -c \"fdatasync\"\n\nRun below script in shell #2:\nfor ((i=1;i\u003e0;i++)) do xfs_io -f /mnt/f2fs/enc/file \\\n-c \"pwrite 0 32k\" -c \"fdatasync\"\n\nSo, in f2fs_merge_page_bio(), let\u0027s avoid using fio-\u003eencrypted_page after\ncommit page into internal ipu cache."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached through ordinary local filesystem syscalls (write/pwrite plus fdatasync) on a mounted f2fs volume, driving the writeback kworker into f2fs_merge_page_bio(); no network or remote peer data is involved.\nAC:L - The attacker controls both sides of the race \u2014 one thread\u0027s writeback caches the encrypted bounce page in the IPU bio list while a second thread\u0027s f2fs_write_begin \u2192 f2fs_folio_wait_writeback submits that same bio and frees the bounce page \u2014 and the commit supplies a trivial two-shell reproducer loop, so it can be hit reliably by repetition.\nPR:L - Only an unprivileged local user with write access to a file in an fscrypt-encrypted directory on f2fs is needed; this is the default state for every app on Android/ChromeOS f2fs /data, and elsewhere any user can set a v2 encryption policy on their own directory without CAP_SYS_ADMIN.\nUI:N - No victim action is required \u2014 the attacker\u0027s own two processes perform all writes and syncs against an already-mounted filesystem, and the racing writeback kworker runs automatically.\nS:U - The freed object, the corrupted accounting counters and the faulting code all live within the kernel\u0027s own security authority; no VM, IOMMU or sandbox boundary is crossed.\nC:H - This is a use-after-free read of a freed fscrypt bounce-page descriptor whose contents are reused by whatever next owns that page, and the stale pointer read from it is dereferenced, giving an attacker-influenceable wild read of kernel memory that leaks into observable filesystem accounting state.\nI:H - Use-after-free of a mempool page that can be recycled into arbitrary kernel allocations makes heap grooming and control over the dereferenced pointer feasible, and the garbage value directly corrupts persistent sbi-\u003enr_pages writeback accounting, wedging checkpoint state machine decisions such as f2fs_stop_checkpoint.\nA:H - The bug is confirmed in the wild to panic the kernel with a NULL pointer dereference in f2fs_is_cp_guaranteed() from the writeback kworker, and a mismatched WB_DATA_TYPE increment leaves F2FS_WB_CP_DATA permanently non-zero, hanging f2fs_wait_on_all_pages() in an uninterruptible loop so sync/umount never complete."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:45:24.871Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/1f7b44b4a2b2939f08b279cbb9e6b5dcb8ffea32"
},
{
"url": "https://git.kernel.org/stable/c/e193d8953647c8b575830852aa5ea0995b98d2b1"
},
{
"url": "https://git.kernel.org/stable/c/410337c2301ae78a081e1b5ebbe8ec374fef4cb6"
},
{
"url": "https://git.kernel.org/stable/c/68e094232dfe5027c4fd2dcded93d2d6800bae04"
},
{
"url": "https://git.kernel.org/stable/c/7dd611131d82d7fc4212b555eb1103160bdad302"
},
{
"url": "https://git.kernel.org/stable/c/01118321e0c8a5f3ece57d0d377bfc92d83cd210"
},
{
"url": "https://git.kernel.org/stable/c/edf7e9040fc52c922db947f9c6c36f07377c52ea"
}
],
"title": "f2fs: fix UAF issue in f2fs_merge_page_bio()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2025-40054",
"datePublished": "2025-10-28T11:48:29.073Z",
"dateReserved": "2025-04-16T07:20:57.157Z",
"dateUpdated": "2026-08-23T12:45:24.871Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64583 (GCVE-0-2026-64583)
Vulnerability from cvelistv5
Published
2026-08-06 07:06
Modified
2026-08-23 12:45
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown
The Broadcom BDC UDC driver registers its IRQ handler with
devm_request_irq() in bdc_udc_init(), so the IRQ is released by devm
only after bdc_remove() returns. devm releases resources in reverse
LIFO order, but bdc_remove() runs bdc_udc_exit() and bdc_hw_exit() ->
bdc_mem_free() manually before returning: bdc_udc_exit() tears down
individual endpoint objects via bdc_free_ep(), while bdc_hw_exit() ->
bdc_mem_free() frees and NULLs the DMA-coherent status-report ring
(bdc->srr.sr_bds) and kfree()s bdc->bdc_ep_array. Both happen while
the IRQ handler (bdc_udc_interrupt, requested with IRQF_SHARED)
remains deliverable in the window up to the post-remove devm
free_irq().
On receipt of a shared interrupt in that window, bdc_udc_interrupt()
dereferences bdc->srr.sr_bds[bdc->srr.dqp_index] (NULL or freed DMA)
and dispatches sr_handler callbacks that index into bdc_ep_array,
causing a NULL-deref or use-after-free.
The same window affects the delayed_work bdc->func_wake_notify, which is
armed from the IRQ handler via bdc_sr_uspc() -> handle_link_state_change()
-> schedule_delayed_work() and may self-rearm from its own callback
bdc_func_wake_timer(). No cancel exists anywhere in the driver, so a
queued work item that fires after bdc_remove() returns and the bdc
structure is devm-freed dereferences freed memory.
Replace devm_request_irq() with request_irq() and add an explicit
free_irq(bdc->irq, bdc) in bdc_remove(). Clear BDC_GIE before
free_irq() to stop the device from asserting interrupts, then
free_irq() drains any in-flight handler, then cancel_delayed_work_sync()
drains the func_wake_notify delayed work. This ordering ensures the
IRQ handler and delayed work cannot interfere with the subsequent
endpoint and DMA teardown in bdc_udc_exit() and bdc_hw_exit(). Wire the
matching free_irq() into the bdc_udc_init() error path so the IRQ is
released on probe failure, and route the bdc_init_ep() failure through
err0 instead of returning directly.
This issue was found by an in-house static analysis tool.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: efed421a94e62a7ddbc76acba4312b70e4be958f Version: efed421a94e62a7ddbc76acba4312b70e4be958f Version: efed421a94e62a7ddbc76acba4312b70e4be958f Version: efed421a94e62a7ddbc76acba4312b70e4be958f Version: efed421a94e62a7ddbc76acba4312b70e4be958f Version: efed421a94e62a7ddbc76acba4312b70e4be958f Version: efed421a94e62a7ddbc76acba4312b70e4be958f Version: efed421a94e62a7ddbc76acba4312b70e4be958f |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/gadget/udc/bdc/bdc_core.c",
"drivers/usb/gadget/udc/bdc/bdc_udc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "eac1107e54679db2df2c36d8bba3b66d3ab6cbcd",
"status": "affected",
"version": "efed421a94e62a7ddbc76acba4312b70e4be958f",
"versionType": "git"
},
{
"lessThan": "0b0b76e31b3991a899ae724eb97d359de0c0f1b1",
"status": "affected",
"version": "efed421a94e62a7ddbc76acba4312b70e4be958f",
"versionType": "git"
},
{
"lessThan": "3fe181952b8a1aeb167d4503c794c0f5050f08ed",
"status": "affected",
"version": "efed421a94e62a7ddbc76acba4312b70e4be958f",
"versionType": "git"
},
{
"lessThan": "1a1d7158420df6b8fa1efc0cdd6ab704801a4fc8",
"status": "affected",
"version": "efed421a94e62a7ddbc76acba4312b70e4be958f",
"versionType": "git"
},
{
"lessThan": "f6fc21ec7ccd83726ba766d73d0b8cc03e726475",
"status": "affected",
"version": "efed421a94e62a7ddbc76acba4312b70e4be958f",
"versionType": "git"
},
{
"lessThan": "dcf3e2f164435b5844706cb8eefef29ebee0eedb",
"status": "affected",
"version": "efed421a94e62a7ddbc76acba4312b70e4be958f",
"versionType": "git"
},
{
"lessThan": "d4964a74717107697999f48bcb4e80a9c0679a27",
"status": "affected",
"version": "efed421a94e62a7ddbc76acba4312b70e4be958f",
"versionType": "git"
},
{
"lessThan": "0583f2fbf8f86ae3a0ce054f96783dd83e65d9bb",
"status": "affected",
"version": "efed421a94e62a7ddbc76acba4312b70e4be958f",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/usb/gadget/udc/bdc/bdc_core.c",
"drivers/usb/gadget/udc/bdc/bdc_udc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.19"
},
{
"lessThan": "3.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown\n\nThe Broadcom BDC UDC driver registers its IRQ handler with\ndevm_request_irq() in bdc_udc_init(), so the IRQ is released by devm\nonly after bdc_remove() returns. devm releases resources in reverse\nLIFO order, but bdc_remove() runs bdc_udc_exit() and bdc_hw_exit() -\u003e\nbdc_mem_free() manually before returning: bdc_udc_exit() tears down\nindividual endpoint objects via bdc_free_ep(), while bdc_hw_exit() -\u003e\nbdc_mem_free() frees and NULLs the DMA-coherent status-report ring\n(bdc-\u003esrr.sr_bds) and kfree()s bdc-\u003ebdc_ep_array. Both happen while\nthe IRQ handler (bdc_udc_interrupt, requested with IRQF_SHARED)\nremains deliverable in the window up to the post-remove devm\nfree_irq().\n\nOn receipt of a shared interrupt in that window, bdc_udc_interrupt()\ndereferences bdc-\u003esrr.sr_bds[bdc-\u003esrr.dqp_index] (NULL or freed DMA)\nand dispatches sr_handler callbacks that index into bdc_ep_array,\ncausing a NULL-deref or use-after-free.\n\nThe same window affects the delayed_work bdc-\u003efunc_wake_notify, which is\narmed from the IRQ handler via bdc_sr_uspc() -\u003e handle_link_state_change()\n-\u003e schedule_delayed_work() and may self-rearm from its own callback\nbdc_func_wake_timer(). No cancel exists anywhere in the driver, so a\nqueued work item that fires after bdc_remove() returns and the bdc\nstructure is devm-freed dereferences freed memory.\n\nReplace devm_request_irq() with request_irq() and add an explicit\nfree_irq(bdc-\u003eirq, bdc) in bdc_remove(). Clear BDC_GIE before\nfree_irq() to stop the device from asserting interrupts, then\nfree_irq() drains any in-flight handler, then cancel_delayed_work_sync()\ndrains the func_wake_notify delayed work. This ordering ensures the\nIRQ handler and delayed work cannot interfere with the subsequent\nendpoint and DMA teardown in bdc_udc_exit() and bdc_hw_exit(). Wire the\nmatching free_irq() into the bdc_udc_init() error path so the IRQ is\nreleased on probe failure, and route the bdc_init_ep() failure through\nerr0 instead of returning directly.\n\nThis issue was found by an in-house static analysis tool."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable window opens on local BDC platform-driver teardown (sysfs unbind/rmmod \u2192 bdc_remove), not on parsing USB host packets; that matches other USB gadget/UDC teardown UAFs scored AV:L and is higher severity than Physical.\nAC:L - The attacker controls remove/bind retries; a pending func_wake_notify (never cancelled before the fix) runs deterministically on the post-remove freed bdc, and IRQF_SHARED plus USB activity can also hit the IRQ window during teardown.\nPR:L - Highest reasonable exposure is a local account managing the gadget/UDC on Android or Broadcom STB systems where platform unbind is delegated beyond init-namespace root; uncertain Low vs High, so Low per the overestimate rule.\nUI:N - The attacker performs driver remove and any prior link-state activity that arms func_wake_notify themselves; no separate victim mount, open, or other interaction is required.\nS:U - NULL-deref/use-after-free of sr_bds, bdc_ep_array, and the delayed-work bdc object stays inside the host kernel authority and does not cross a VM, IOMMU, or sandbox boundary.\nC:H - Use-after-free of the DMA status-report ring, endpoint array, and the bdc object via IRQ/work handlers allows reclaim/spray and disclosure of kernel memory, which per UAF guidance is High.\nI:H - The same UAF paths write through freed endpoint/status structures and run delayed work on a freed bdc, enabling heap corruption and control-flow hijack suitable for privilege escalation.\nA:H - Dereferencing NULL/freed sr_bds in hard-IRQ context or executing bdc_func_wake_timer on a post-remove freed bdc causes kernel oops/panic, so availability impact is High."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:45:42.500Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/eac1107e54679db2df2c36d8bba3b66d3ab6cbcd"
},
{
"url": "https://git.kernel.org/stable/c/0b0b76e31b3991a899ae724eb97d359de0c0f1b1"
},
{
"url": "https://git.kernel.org/stable/c/3fe181952b8a1aeb167d4503c794c0f5050f08ed"
},
{
"url": "https://git.kernel.org/stable/c/1a1d7158420df6b8fa1efc0cdd6ab704801a4fc8"
},
{
"url": "https://git.kernel.org/stable/c/f6fc21ec7ccd83726ba766d73d0b8cc03e726475"
},
{
"url": "https://git.kernel.org/stable/c/dcf3e2f164435b5844706cb8eefef29ebee0eedb"
},
{
"url": "https://git.kernel.org/stable/c/d4964a74717107697999f48bcb4e80a9c0679a27"
},
{
"url": "https://git.kernel.org/stable/c/0583f2fbf8f86ae3a0ce054f96783dd83e65d9bb"
}
],
"title": "usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64583",
"datePublished": "2026-08-06T07:06:25.335Z",
"dateReserved": "2026-07-19T15:36:31.798Z",
"dateUpdated": "2026-08-23T12:45:42.500Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64270 (GCVE-0-2026-64270)
Vulnerability from cvelistv5
Published
2026-07-25 08:49
Modified
2026-08-23 12:45
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Input: mms114 - reject an oversized device packet size
mms114_interrupt() reads a packet of touch data from the device into a
fixed-size on-stack buffer
struct mms114_touch touch[MMS114_MAX_TOUCH];
which holds MMS114_MAX_TOUCH (10) events of MMS114_EVENT_SIZE (8) bytes,
i.e. 80 bytes. The length of the I2C read into it is taken verbatim from
the device:
packet_size = mms114_read_reg(data, MMS114_PACKET_SIZE);
if (packet_size <= 0)
goto out;
...
error = __mms114_read_reg(data, MMS114_INFORMATION, packet_size,
(u8 *)touch);
packet_size is a single device register byte (0x0F) and the only check
is the lower bound packet_size <= 0; it is never bounded against the
size of touch[]. A malfunctioning, malicious or counterfeit controller
(or an attacker tampering with the I2C bus) can report a packet_size of
up to 255, so __mms114_read_reg() writes up to 175 bytes past the end of
touch[] on the IRQ-thread stack: a stack out-of-bounds write that can
overwrite the stack canary, saved registers and the return address.
A well-formed device never reports more than the buffer holds, so reject
an oversized packet and drop the report, consistent with the handler's
other error paths, rather than reading past the buffer.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 07b8481d4aff73d6f451f25e74ea10240ff5131e Version: 07b8481d4aff73d6f451f25e74ea10240ff5131e Version: 07b8481d4aff73d6f451f25e74ea10240ff5131e Version: 07b8481d4aff73d6f451f25e74ea10240ff5131e Version: 07b8481d4aff73d6f451f25e74ea10240ff5131e Version: 07b8481d4aff73d6f451f25e74ea10240ff5131e Version: 07b8481d4aff73d6f451f25e74ea10240ff5131e Version: 07b8481d4aff73d6f451f25e74ea10240ff5131e |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/input/touchscreen/mms114.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "040843281eebfa110d08fd7fb083fe6cb55cea14",
"status": "affected",
"version": "07b8481d4aff73d6f451f25e74ea10240ff5131e",
"versionType": "git"
},
{
"lessThan": "39b12daf1adb80f9595fdfe584961deb80860cbb",
"status": "affected",
"version": "07b8481d4aff73d6f451f25e74ea10240ff5131e",
"versionType": "git"
},
{
"lessThan": "d99ba93c35ff2d5276e9c2632967481bd53a79d0",
"status": "affected",
"version": "07b8481d4aff73d6f451f25e74ea10240ff5131e",
"versionType": "git"
},
{
"lessThan": "5d2ea15ba03bf17ed143ff1a0995a4206edc3fb6",
"status": "affected",
"version": "07b8481d4aff73d6f451f25e74ea10240ff5131e",
"versionType": "git"
},
{
"lessThan": "b78150729762d47c14fe29a2582bdca5568e62b8",
"status": "affected",
"version": "07b8481d4aff73d6f451f25e74ea10240ff5131e",
"versionType": "git"
},
{
"lessThan": "8301c335305344d4da4ab9442b6a399dacfe5b8d",
"status": "affected",
"version": "07b8481d4aff73d6f451f25e74ea10240ff5131e",
"versionType": "git"
},
{
"lessThan": "f3d5e77b27fded71dcb97f409262bf0abba0410e",
"status": "affected",
"version": "07b8481d4aff73d6f451f25e74ea10240ff5131e",
"versionType": "git"
},
{
"lessThan": "66725039f7090afe14c31bd259e2059a68f04023",
"status": "affected",
"version": "07b8481d4aff73d6f451f25e74ea10240ff5131e",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/input/touchscreen/mms114.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.6"
},
{
"lessThan": "3.6",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "3.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "3.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "3.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "3.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "3.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "3.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "3.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nInput: mms114 - reject an oversized device packet size\n\nmms114_interrupt() reads a packet of touch data from the device into a\nfixed-size on-stack buffer\n\n\tstruct mms114_touch touch[MMS114_MAX_TOUCH];\n\nwhich holds MMS114_MAX_TOUCH (10) events of MMS114_EVENT_SIZE (8) bytes,\ni.e. 80 bytes. The length of the I2C read into it is taken verbatim from\nthe device:\n\n\tpacket_size = mms114_read_reg(data, MMS114_PACKET_SIZE);\n\tif (packet_size \u003c= 0)\n\t\tgoto out;\n\t...\n\terror = __mms114_read_reg(data, MMS114_INFORMATION, packet_size,\n\t\t\t(u8 *)touch);\n\npacket_size is a single device register byte (0x0F) and the only check\nis the lower bound packet_size \u003c= 0; it is never bounded against the\nsize of touch[]. A malfunctioning, malicious or counterfeit controller\n(or an attacker tampering with the I2C bus) can report a packet_size of\nup to 255, so __mms114_read_reg() writes up to 175 bytes past the end of\ntouch[] on the IRQ-thread stack: a stack out-of-bounds write that can\noverwrite the stack canary, saved registers and the return address.\n\nA well-formed device never reports more than the buffer holds, so reject\nan oversized packet and drop the report, consistent with the handler\u0027s\nother error paths, rather than reading past the buffer."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:45:36.926Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/040843281eebfa110d08fd7fb083fe6cb55cea14"
},
{
"url": "https://git.kernel.org/stable/c/39b12daf1adb80f9595fdfe584961deb80860cbb"
},
{
"url": "https://git.kernel.org/stable/c/d99ba93c35ff2d5276e9c2632967481bd53a79d0"
},
{
"url": "https://git.kernel.org/stable/c/5d2ea15ba03bf17ed143ff1a0995a4206edc3fb6"
},
{
"url": "https://git.kernel.org/stable/c/b78150729762d47c14fe29a2582bdca5568e62b8"
},
{
"url": "https://git.kernel.org/stable/c/8301c335305344d4da4ab9442b6a399dacfe5b8d"
},
{
"url": "https://git.kernel.org/stable/c/f3d5e77b27fded71dcb97f409262bf0abba0410e"
},
{
"url": "https://git.kernel.org/stable/c/66725039f7090afe14c31bd259e2059a68f04023"
}
],
"title": "Input: mms114 - reject an oversized device packet size",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64270",
"datePublished": "2026-07-25T08:49:17.541Z",
"dateReserved": "2026-07-19T15:36:31.775Z",
"dateUpdated": "2026-08-23T12:45:36.926Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74648 (GCVE-0-2026-74648)
Vulnerability from cvelistv5
Published
2026-08-22 15:32
Modified
2026-08-25 05:41
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
staging: rtl8723bs: validate monitor transmit frame lengths
rtw_cfg80211_monitor_if_xmit_entry() removes the radiotap header and
then reads the 802.11 frame control field without checking that a base
802.11 header remains.
The data path also pulls the calculated 802.11, QoS and SNAP header
span before confirming that the skb contains it. A truncated frame can
therefore cause out-of-bounds reads or leave insufficient data for the
Ethernet address writes.
Reject frames that do not contain the base 802.11 header and data
frames that do not contain their complete calculated header span.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b Version: 554c0a3abf216c991c5ebddcdb2c08689ecd290b |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/staging/rtl8723bs/os_dep/ioctl_cfg80211.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "f03398d835f5249c49546f0eb0d0df6792b95d5f",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "a3ac6d849de5f7abe14761d741bbb843ac793454",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "7edd3adb0c80d70b4237640275c559610f438476",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "c5e5d78743992e235b76d2ebe5a403d60315aa8a",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "7b0f62d2986a28e5e4188366bc2f4e2868b14790",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "8b3e4ed9c35d3d3b64fcc23f4a1f22b37c1865b1",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "bd88f6289b7e483216a9c1df15a0460ef9b02cb6",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
},
{
"lessThan": "6829665d050983907b560173e49dcc6c11cb2730",
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/staging/rtl8723bs/os_dep/ioctl_cfg80211.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.12"
},
{
"lessThan": "4.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: rtl8723bs: validate monitor transmit frame lengths\n\nrtw_cfg80211_monitor_if_xmit_entry() removes the radiotap header and\nthen reads the 802.11 frame control field without checking that a base\n802.11 header remains.\n\nThe data path also pulls the calculated 802.11, QoS and SNAP header\nspan before confirming that the skb contains it. A truncated frame can\ntherefore cause out-of-bounds reads or leave insufficient data for the\nEthernet address writes.\n\nReject frames that do not contain the base 802.11 header and data\nframes that do not contain their complete calculated header span."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The flaw is only reachable via local userspace transmitting crafted radiotap skbs to the rtl8723bs monitor netdev ndo_start_xmit handler (cfg80211 NEW_INTERFACE + packet socket/dev_queue_xmit); remote WiFi peers cannot drive this transmit-only parsing path.\nAC:L - An attacker fully controls monitor TX skb length and 802.11 header fields after the fixed 14-byte radiotap prefix; sending a truncated frame (e.g., radiotap-only or short DATA header) reliably triggers the missing bounds checks without races or layout dependencies.\nPR:L - Exploitation requires creating a monitor virtual interface via nl80211 (GENL_UNS_ADMIN_PERM/CAP_NET_ADMIN) and injecting frames via CAP_NET_RAW packet sockets; per kernel CNA guidance these capabilities are PR:L when obtainable through user namespaces on embedded rtl8723bs systems.\nUI:N - No victim interaction is required once the attacker can create or access the monitor interface; exploitation is a direct syscall/netlink and packet-socket operation without needing the user to connect, mount, or approve an action.\nS:U - Impact is confined to kernel memory corruption and privilege escalation within the host kernel running the rtl8723bs SDIO WiFi driver; it does not cross VM, container, or IOMMU security boundaries.\nC:H - Reading dot11_hdr-\u003eframe_control and memcpy of addr1/addr2 without verifying at least 24 bytes remain after radiotap removal causes out-of-bounds kernel reads of adjacent skb and kmalloc memory, enabling information disclosure.\nI:H - On the DATA path, skb_pull and subsequent memcpy of 12-byte Ethernet addresses into skb-\u003edata without ensuring sufficient tail room can write past the skb buffer end, providing exploitable heap corruption for arbitrary kernel writes.\nA:H - Out-of-bounds reads and writes in kernel softirq transmit context on SDIO WiFi embedded devices (CHIP, Intel Compute Stick, ARM SBCs) can trigger kernel oops, panic, or hang, causing complete loss of availability."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:41:06.779Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/f03398d835f5249c49546f0eb0d0df6792b95d5f"
},
{
"url": "https://git.kernel.org/stable/c/a3ac6d849de5f7abe14761d741bbb843ac793454"
},
{
"url": "https://git.kernel.org/stable/c/7edd3adb0c80d70b4237640275c559610f438476"
},
{
"url": "https://git.kernel.org/stable/c/c5e5d78743992e235b76d2ebe5a403d60315aa8a"
},
{
"url": "https://git.kernel.org/stable/c/7b0f62d2986a28e5e4188366bc2f4e2868b14790"
},
{
"url": "https://git.kernel.org/stable/c/8b3e4ed9c35d3d3b64fcc23f4a1f22b37c1865b1"
},
{
"url": "https://git.kernel.org/stable/c/bd88f6289b7e483216a9c1df15a0460ef9b02cb6"
},
{
"url": "https://git.kernel.org/stable/c/6829665d050983907b560173e49dcc6c11cb2730"
}
],
"title": "staging: rtl8723bs: validate monitor transmit frame lengths",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74648",
"datePublished": "2026-08-22T15:32:24.858Z",
"dateReserved": "2026-08-15T05:44:03.923Z",
"dateUpdated": "2026-08-25T05:41:06.779Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74463 (GCVE-0-2026-74463)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-19 16:37
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
i2c: jz4780: Cache host clock rate at probe to prevent CCF prepare_lock deadlock
Fix a severe AB/BA deadlock between the Common Clock Framework (CCF)
and the I2C adapter lock, which triggers when an I2C-controlled clock
generator client (like the Si5351) is registered or modified under the CCF.
During an i2c client clock (generator) frequency change, the CCF acquires its global
'prepare_lock' mutex and the driver calls i2c_transfer() to update the client's
chip registers, stalling for the adapter's I2C bus lock.
Concurrently, an independent, parallel transfer on the same bus (e.g., a GPIO
expander handling LEDs) can hold the I2C adapter lock. Inside this parallel
transfer path, jz4780_i2c_set_speed() calls clk_get_rate() on the host
controller's input clock to calculate bus timings. This call attempts to acquire
the blocked CCF 'prepare_lock', creating a circular dependency that freezes
the system.
The jz4780 host controller clock itself is static and never changes at runtime.
However, calling clk_get_rate() inside the active transfer path introduces
an unnecessary dependency on the CCF internal locks.
Eliminate this synchronous clk_get_rate() call from the active transfer
path by caching the static host peripheral clock rate once - inside the private
jz4780_i2c structure during jz4780_i2c_probe(). Update jz4780_i2c_set_speed()
to use this cached value, safely decoupling active I2C transactions from the
CCF internal locks without any risk of stale timings.
Assisted-by web based Google AI (pinpointing the bug and writing the message).
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ba92222ed63a12d09120df9b92f56cc990abac19 Version: ba92222ed63a12d09120df9b92f56cc990abac19 Version: ba92222ed63a12d09120df9b92f56cc990abac19 Version: ba92222ed63a12d09120df9b92f56cc990abac19 Version: ba92222ed63a12d09120df9b92f56cc990abac19 Version: ba92222ed63a12d09120df9b92f56cc990abac19 Version: ba92222ed63a12d09120df9b92f56cc990abac19 Version: ba92222ed63a12d09120df9b92f56cc990abac19 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/i2c/busses/i2c-jz4780.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "cc111696ef420f6bb552b2526530067977f0b406",
"status": "affected",
"version": "ba92222ed63a12d09120df9b92f56cc990abac19",
"versionType": "git"
},
{
"lessThan": "f96a719d9f8a797105ec5cacf568ab128e33391f",
"status": "affected",
"version": "ba92222ed63a12d09120df9b92f56cc990abac19",
"versionType": "git"
},
{
"lessThan": "deffad5bb4f8b4f09e46252f24754ddc9960b244",
"status": "affected",
"version": "ba92222ed63a12d09120df9b92f56cc990abac19",
"versionType": "git"
},
{
"lessThan": "14429dc1c756c35e106f01ff09cadccb82f5531d",
"status": "affected",
"version": "ba92222ed63a12d09120df9b92f56cc990abac19",
"versionType": "git"
},
{
"lessThan": "b6cb47e186abba85a3b08aa3023067ab82577286",
"status": "affected",
"version": "ba92222ed63a12d09120df9b92f56cc990abac19",
"versionType": "git"
},
{
"lessThan": "19b783335d62e7a2367436a6e1f1b37da1878360",
"status": "affected",
"version": "ba92222ed63a12d09120df9b92f56cc990abac19",
"versionType": "git"
},
{
"lessThan": "aa1944b52d6492c48bdd17046578aa0d953546e6",
"status": "affected",
"version": "ba92222ed63a12d09120df9b92f56cc990abac19",
"versionType": "git"
},
{
"lessThan": "d99607c888f26e8a4e9fe9772860cef4aff86bb4",
"status": "affected",
"version": "ba92222ed63a12d09120df9b92f56cc990abac19",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/i2c/busses/i2c-jz4780.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.1"
},
{
"lessThan": "4.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: jz4780: Cache host clock rate at probe to prevent CCF prepare_lock deadlock\n\nFix a severe AB/BA deadlock between the Common Clock Framework (CCF)\nand the I2C adapter lock, which triggers when an I2C-controlled clock\ngenerator client (like the Si5351) is registered or modified under the CCF.\n\nDuring an i2c client clock (generator) frequency change, the CCF acquires its global\n\u0027prepare_lock\u0027 mutex and the driver calls i2c_transfer() to update the client\u0027s\nchip registers, stalling for the adapter\u0027s I2C bus lock.\n\nConcurrently, an independent, parallel transfer on the same bus (e.g., a GPIO\nexpander handling LEDs) can hold the I2C adapter lock. Inside this parallel\ntransfer path, jz4780_i2c_set_speed() calls clk_get_rate() on the host\ncontroller\u0027s input clock to calculate bus timings. This call attempts to acquire\nthe blocked CCF \u0027prepare_lock\u0027, creating a circular dependency that freezes\nthe system.\n\nThe jz4780 host controller clock itself is static and never changes at runtime.\n\nHowever, calling clk_get_rate() inside the active transfer path introduces\nan unnecessary dependency on the CCF internal locks.\n\nEliminate this synchronous clk_get_rate() call from the active transfer\npath by caching the static host peripheral clock rate once - inside the private\njz4780_i2c structure during jz4780_i2c_probe(). Update jz4780_i2c_set_speed()\nto use this cached value, safely decoupling active I2C transactions from the\nCCF internal locks without any risk of stale timings.\n\nAssisted-by web based Google AI (pinpointing the bug and writing the message)."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:37:02.602Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/cc111696ef420f6bb552b2526530067977f0b406"
},
{
"url": "https://git.kernel.org/stable/c/f96a719d9f8a797105ec5cacf568ab128e33391f"
},
{
"url": "https://git.kernel.org/stable/c/deffad5bb4f8b4f09e46252f24754ddc9960b244"
},
{
"url": "https://git.kernel.org/stable/c/14429dc1c756c35e106f01ff09cadccb82f5531d"
},
{
"url": "https://git.kernel.org/stable/c/b6cb47e186abba85a3b08aa3023067ab82577286"
},
{
"url": "https://git.kernel.org/stable/c/19b783335d62e7a2367436a6e1f1b37da1878360"
},
{
"url": "https://git.kernel.org/stable/c/aa1944b52d6492c48bdd17046578aa0d953546e6"
},
{
"url": "https://git.kernel.org/stable/c/d99607c888f26e8a4e9fe9772860cef4aff86bb4"
}
],
"title": "i2c: jz4780: Cache host clock rate at probe to prevent CCF prepare_lock deadlock",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74463",
"datePublished": "2026-08-15T12:27:03.176Z",
"dateReserved": "2026-08-15T05:44:03.901Z",
"dateUpdated": "2026-08-19T16:37:02.602Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80792 (GCVE-0-2026-80792)
Vulnerability from cvelistv5
Published
2026-09-04 15:13
Modified
2026-09-04 15:13
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ipv6: fix use-after-free in ip6_finish_output2()
ip6_finish_output2() caches a pointer to the IPv6 destination
address (daddr) before invoking lwtunnel_xmit(). The LWT-BPF
transmit path or other encapsulation operations within
lwtunnel_xmit() can reallocate the skb head, freeing the memory
that daddr points to. When lwtunnel_xmit() returns
LWTUNNEL_XMIT_CONTINUE, the function continues to use the stale
daddr pointer to compute the nexthop and to look up or create the
neighbour entry. This results in a use-after-free read, which can
leak sensitive kernel data, pollute the neighbour table with
arbitrary values, misdirect traffic, or crash the system.
Fix this by re-fetching the IPv6 header and the destination
address pointer after lwtunnel_xmit() returns
LWTUNNEL_XMIT_CONTINUE, ensuring that the subsequent nexthop
computation and neighbour lookup operate on valid memory.
References
| URL | Tags | ||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 4132c4ad00ddbf3a175ea0d2c775b662a32f4c85 Version: e415ed3a4b8b246ee5e9d109ff5153efcf96b9f2 Version: e415ed3a4b8b246ee5e9d109ff5153efcf96b9f2 Version: e415ed3a4b8b246ee5e9d109ff5153efcf96b9f2 Version: e415ed3a4b8b246ee5e9d109ff5153efcf96b9f2 Version: e415ed3a4b8b246ee5e9d109ff5153efcf96b9f2 Version: e415ed3a4b8b246ee5e9d109ff5153efcf96b9f2 Version: e415ed3a4b8b246ee5e9d109ff5153efcf96b9f2 Version: e415ed3a4b8b246ee5e9d109ff5153efcf96b9f2 Version: 1598154fd28ffa4a55beae1970475fd6776554b6 Version: 5.10.233 ≤ Version: 5.4.289 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ipv6/ip6_output.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "75e0a544ebe9af663ef53ca21e9e9185c51fb54a",
"status": "affected",
"version": "4132c4ad00ddbf3a175ea0d2c775b662a32f4c85",
"versionType": "git"
},
{
"lessThan": "c95f01b78266828a57060d754fcbfc92123a98ed",
"status": "affected",
"version": "e415ed3a4b8b246ee5e9d109ff5153efcf96b9f2",
"versionType": "git"
},
{
"lessThan": "d960881b9312e781a3429aabceb223ce6b7c882f",
"status": "affected",
"version": "e415ed3a4b8b246ee5e9d109ff5153efcf96b9f2",
"versionType": "git"
},
{
"lessThan": "087ee0d914aaae929f1660c9ca878e367655ba1a",
"status": "affected",
"version": "e415ed3a4b8b246ee5e9d109ff5153efcf96b9f2",
"versionType": "git"
},
{
"lessThan": "3c770ac4e6f07af7c7b40c474a3efc61ffed7862",
"status": "affected",
"version": "e415ed3a4b8b246ee5e9d109ff5153efcf96b9f2",
"versionType": "git"
},
{
"lessThan": "3dc98e5fe82d069dd29b124ffbdb679331dfea43",
"status": "affected",
"version": "e415ed3a4b8b246ee5e9d109ff5153efcf96b9f2",
"versionType": "git"
},
{
"lessThan": "99219c82804f266189388e8bf1cf5135d10d5515",
"status": "affected",
"version": "e415ed3a4b8b246ee5e9d109ff5153efcf96b9f2",
"versionType": "git"
},
{
"lessThan": "73a187384a8c8b983c7fea046d716b6752a1e7a3",
"status": "affected",
"version": "e415ed3a4b8b246ee5e9d109ff5153efcf96b9f2",
"versionType": "git"
},
{
"lessThan": "d0d48d999b0eee6bb176ef4e39d9be868fa80f7e",
"status": "affected",
"version": "e415ed3a4b8b246ee5e9d109ff5153efcf96b9f2",
"versionType": "git"
},
{
"status": "affected",
"version": "1598154fd28ffa4a55beae1970475fd6776554b6",
"versionType": "git"
},
{
"lessThan": "5.10.267",
"status": "affected",
"version": "5.10.233",
"versionType": "semver"
},
{
"lessThan": "5.5",
"status": "affected",
"version": "5.4.289",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ipv6/ip6_output.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.15"
},
{
"lessThan": "5.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.267",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.218",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.185",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.154",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.106",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.47",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.1",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.267",
"versionStartIncluding": "5.10.233",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.218",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.185",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.154",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.106",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.47",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.11",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.1",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.4.289",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: fix use-after-free in ip6_finish_output2()\n\nip6_finish_output2() caches a pointer to the IPv6 destination\naddress (daddr) before invoking lwtunnel_xmit(). The LWT-BPF\ntransmit path or other encapsulation operations within\nlwtunnel_xmit() can reallocate the skb head, freeing the memory\nthat daddr points to. When lwtunnel_xmit() returns\nLWTUNNEL_XMIT_CONTINUE, the function continues to use the stale\ndaddr pointer to compute the nexthop and to look up or create the\nneighbour entry. This results in a use-after-free read, which can\nleak sensitive kernel data, pollute the neighbour table with\narbitrary values, misdirect traffic, or crash the system.\n\nFix this by re-fetching the IPv6 header and the destination\naddress pointer after lwtunnel_xmit() returns\nLWTUNNEL_XMIT_CONTINUE, ensuring that the subsequent nexthop\ncomputation and neighbour lookup operate on valid memory."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T15:13:04.537Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/75e0a544ebe9af663ef53ca21e9e9185c51fb54a"
},
{
"url": "https://git.kernel.org/stable/c/c95f01b78266828a57060d754fcbfc92123a98ed"
},
{
"url": "https://git.kernel.org/stable/c/d960881b9312e781a3429aabceb223ce6b7c882f"
},
{
"url": "https://git.kernel.org/stable/c/087ee0d914aaae929f1660c9ca878e367655ba1a"
},
{
"url": "https://git.kernel.org/stable/c/3c770ac4e6f07af7c7b40c474a3efc61ffed7862"
},
{
"url": "https://git.kernel.org/stable/c/3dc98e5fe82d069dd29b124ffbdb679331dfea43"
},
{
"url": "https://git.kernel.org/stable/c/99219c82804f266189388e8bf1cf5135d10d5515"
},
{
"url": "https://git.kernel.org/stable/c/73a187384a8c8b983c7fea046d716b6752a1e7a3"
},
{
"url": "https://git.kernel.org/stable/c/d0d48d999b0eee6bb176ef4e39d9be868fa80f7e"
}
],
"title": "ipv6: fix use-after-free in ip6_finish_output2()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80792",
"datePublished": "2026-09-04T15:13:04.537Z",
"dateReserved": "2026-08-26T14:34:25.793Z",
"dateUpdated": "2026-09-04T15:13:04.537Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68181 (GCVE-0-2026-68181)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
mei: bus: access mei_device under device_lock on cleanup
Fix couple of problems in mei_cl_bus_dev_release():
mei_cl_flush_queues() is running without lock.
bus->file_list access after mei_dev_bus_put(bus) can become a
use-after-free if this was the last reference to bus.
Protect queues cleanup and WARN traversal by device lock there
to avoid the concurrent access problems.
Move WARN traversal before mei_dev_bus_put(bus).
This file uses bus variable name for mei_device, adjust
code of mei_cl_bus_dev_release() to use bus variable too.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 6f2a6ef86b23a30b92ad57981de537bce67bfa45 Version: 24f4ceeaeee7983c07590149556a0e33efe2ec90 Version: 612c8d21ce6e37b73f3106aec7ffa35959d40261 Version: 35e8a426b16adbecae7a4e0e3c00fc8d0273db53 Version: 35e8a426b16adbecae7a4e0e3c00fc8d0273db53 Version: 35e8a426b16adbecae7a4e0e3c00fc8d0273db53 Version: 2f29dce5a5ae06a7db32e4491d72269329a86eeb Version: 28de6ca5276a94b0589ae1bf026b89fa0eaf14c0 Version: 6.1.149 ≤ Version: 6.6.103 ≤ Version: 6.12.43 ≤ Version: 6.15.11 ≤ Version: 6.16.2 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/misc/mei/bus.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "02e3a755086db847d795f2593ebc45e8ee4f1755",
"status": "affected",
"version": "6f2a6ef86b23a30b92ad57981de537bce67bfa45",
"versionType": "git"
},
{
"lessThan": "441559d4c595f839b39f0ab6a4ae628427c2fd9e",
"status": "affected",
"version": "24f4ceeaeee7983c07590149556a0e33efe2ec90",
"versionType": "git"
},
{
"lessThan": "c88c030a324c9018b77894a19b2564eb66862020",
"status": "affected",
"version": "612c8d21ce6e37b73f3106aec7ffa35959d40261",
"versionType": "git"
},
{
"lessThan": "59dd34854202d9a3faaa87a85205e553fe7150e1",
"status": "affected",
"version": "35e8a426b16adbecae7a4e0e3c00fc8d0273db53",
"versionType": "git"
},
{
"lessThan": "7cf79e8d682fe93777268f029668ce5e214237fd",
"status": "affected",
"version": "35e8a426b16adbecae7a4e0e3c00fc8d0273db53",
"versionType": "git"
},
{
"lessThan": "f112ea910e554d58b4b39a4492b7d302f0f4204f",
"status": "affected",
"version": "35e8a426b16adbecae7a4e0e3c00fc8d0273db53",
"versionType": "git"
},
{
"status": "affected",
"version": "2f29dce5a5ae06a7db32e4491d72269329a86eeb",
"versionType": "git"
},
{
"status": "affected",
"version": "28de6ca5276a94b0589ae1bf026b89fa0eaf14c0",
"versionType": "git"
},
{
"lessThan": "6.1.184",
"status": "affected",
"version": "6.1.149",
"versionType": "semver"
},
{
"lessThan": "6.6.148",
"status": "affected",
"version": "6.6.103",
"versionType": "semver"
},
{
"lessThan": "6.12.101",
"status": "affected",
"version": "6.12.43",
"versionType": "semver"
},
{
"lessThan": "6.16",
"status": "affected",
"version": "6.15.11",
"versionType": "semver"
},
{
"lessThan": "6.17",
"status": "affected",
"version": "6.16.2",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/misc/mei/bus.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.17"
},
{
"lessThan": "6.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "6.1.149",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "6.6.103",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "6.12.43",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "6.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "6.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.15.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.16.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmei: bus: access mei_device under device_lock on cleanup\n\nFix couple of problems in mei_cl_bus_dev_release():\n\nmei_cl_flush_queues() is running without lock.\nbus-\u003efile_list access after mei_dev_bus_put(bus) can become a\nuse-after-free if this was the last reference to bus.\n\nProtect queues cleanup and WARN traversal by device lock there\nto avoid the concurrent access problems.\nMove WARN traversal before mei_dev_bus_put(bus).\n\nThis file uses bus variable name for mei_device, adjust\ncode of mei_cl_bus_dev_release() to use bus variable too."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:04.934Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/02e3a755086db847d795f2593ebc45e8ee4f1755"
},
{
"url": "https://git.kernel.org/stable/c/441559d4c595f839b39f0ab6a4ae628427c2fd9e"
},
{
"url": "https://git.kernel.org/stable/c/c88c030a324c9018b77894a19b2564eb66862020"
},
{
"url": "https://git.kernel.org/stable/c/59dd34854202d9a3faaa87a85205e553fe7150e1"
},
{
"url": "https://git.kernel.org/stable/c/7cf79e8d682fe93777268f029668ce5e214237fd"
},
{
"url": "https://git.kernel.org/stable/c/f112ea910e554d58b4b39a4492b7d302f0f4204f"
}
],
"title": "mei: bus: access mei_device under device_lock on cleanup",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68181",
"datePublished": "2026-08-10T11:59:52.724Z",
"dateReserved": "2026-07-30T09:28:09.373Z",
"dateUpdated": "2026-08-23T12:46:04.934Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68100 (GCVE-0-2026-68100)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-23 12:45
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: validate num_subauth when copying ACE in set_ntacl_dacl
set_ntacl_dacl() copies each ACE from the attacker-controlled stored
security descriptor verbatim into the response DACL without checking
sid.num_subauth. The ACE bytes (including an unchecked num_subauth)
originate from an authenticated SMB2_SET_INFO(SecInfo=DACL) that is
stored raw via ksmbd_vfs_set_sd_xattr(); parse_dacl() rejects a bad ACE
with `break` rather than an error, so parse_sec_desc() still returns
success and the malformed SD reaches the xattr intact.
On a subsequent SMB2_QUERY_INFO(SecInfo=DACL) for an inode carrying a
POSIX access ACL, build_sec_desc() -> set_ntacl_dacl() ->
set_posix_acl_entries_dacl() walks the copied ACEs and reads
ntace->sid.sub_auth[ntace->sid.num_subauth - 1]
with num_subauth taken straight from the stored SD. Since sub_auth[]
is fixed at SID_MAX_SUB_AUTHORITIES (15), a crafted num_subauth (e.g.
255) drives an out-of-bounds heap read of ~1 KB with an offset fully
controlled by an authenticated client.
The sibling functions already gate this field:
parse_dacl() -- num_subauth == 0 || > SID_MAX_SUB_AUTHORITIES
parse_sid() -- num_subauth > SID_MAX_SUB_AUTHORITIES
smb_copy_sid() -- min_t(u8, num_subauth, SID_MAX_SUB_AUTHORITIES)
set_ntacl_dacl() is the lone inconsistent path that omits the check.
Add the same num_subauth validation in set_ntacl_dacl() before copying
the ACE, matching the gate already enforced by parse_dacl().
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 Version: e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 Version: e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 Version: e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 Version: e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 Version: e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/smb/server/smbacl.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "26cb845e22a00c85bf566337417fa33492395f10",
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"versionType": "git"
},
{
"lessThan": "e31fada5143784bc05c7ae44c79eed9b7a2e147e",
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"versionType": "git"
},
{
"lessThan": "fb3dc8e6da46a1ccad1956cda57de29d9b3033e0",
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"versionType": "git"
},
{
"lessThan": "b6d3cc6a524416dfdb2b47e4bba2e7e20011d056",
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"versionType": "git"
},
{
"lessThan": "5acbd3012fd4a7ccfebd91ea6f784120084eb897",
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"versionType": "git"
},
{
"lessThan": "47f0b34f6bc98ed85bfdc293e8f3e432ec24958d",
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/smb/server/smbacl.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.15"
},
{
"lessThan": "5.15",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: validate num_subauth when copying ACE in set_ntacl_dacl\n\nset_ntacl_dacl() copies each ACE from the attacker-controlled stored\nsecurity descriptor verbatim into the response DACL without checking\nsid.num_subauth. The ACE bytes (including an unchecked num_subauth)\noriginate from an authenticated SMB2_SET_INFO(SecInfo=DACL) that is\nstored raw via ksmbd_vfs_set_sd_xattr(); parse_dacl() rejects a bad ACE\nwith `break` rather than an error, so parse_sec_desc() still returns\nsuccess and the malformed SD reaches the xattr intact.\n\nOn a subsequent SMB2_QUERY_INFO(SecInfo=DACL) for an inode carrying a\nPOSIX access ACL, build_sec_desc() -\u003e set_ntacl_dacl() -\u003e\nset_posix_acl_entries_dacl() walks the copied ACEs and reads\n\n ntace-\u003esid.sub_auth[ntace-\u003esid.num_subauth - 1]\n\nwith num_subauth taken straight from the stored SD. Since sub_auth[]\nis fixed at SID_MAX_SUB_AUTHORITIES (15), a crafted num_subauth (e.g.\n255) drives an out-of-bounds heap read of ~1 KB with an offset fully\ncontrolled by an authenticated client.\n\nThe sibling functions already gate this field:\n parse_dacl() -- num_subauth == 0 || \u003e SID_MAX_SUB_AUTHORITIES\n parse_sid() -- num_subauth \u003e SID_MAX_SUB_AUTHORITIES\n smb_copy_sid() -- min_t(u8, num_subauth, SID_MAX_SUB_AUTHORITIES)\nset_ntacl_dacl() is the lone inconsistent path that omits the check.\n\nAdd the same num_subauth validation in set_ntacl_dacl() before copying\nthe ACE, matching the gate already enforced by parse_dacl()."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - ksmbd is the in-kernel SMB3 server on TCP/445; both SMB2_SET_INFO(SecInfo=DACL) and SMB2_QUERY_INFO(SecInfo=DACL) are handled from remote SMB2 PDUs in smb2_set_info()/smb2_query_info() via ksmbd_conn_handler_loop(), with no local syscall or physical access required.\nAC:L - Once ksmbd is running with ACL-xattr shares, an attacker deterministically plants a malformed DACL via SET_INFO and triggers the read on QUERY_INFO; num_subauth fully controls the OOB offset, with no race, timing window, or victim-dependent memory layout required.\nPR:L - SMB2_SET_INFO/QUERY_INFO require a valid post-authentication session (smb2_check_user_session) and SET_INFO SECURITY additionally requires FILE_WRITE_DAC/FILE_WRITE_OWNER on the open handle; this is a low-privilege authenticated SMB client, not a pre-auth or root-only path.\nUI:N - Exploitation is driven entirely by the attacker\u0027s own SMB2 SET_INFO and QUERY_INFO requests over the network; no local user, administrator, or victim client must perform any separate action.\nS:U - The out-of-bounds read and any resulting disclosure or crash occur entirely within kernel ksmbd server memory on the host; no VM, IOMMU, container, or other security-boundary escape is involved.\nC:H - Crafted num_subauth (e.g. 255) makes set_posix_acl_entries_dacl() index far past the 15-element sub_auth[] array, performing an attacker-offset-controlled ~1 KB out-of-bounds kernel heap read whose value is compared during DACL rebuild, enabling kernel memory disclosure.\nI:N - The defect is an out-of-bounds read during ACE deduplication; no kernel memory is written, no attacker-controlled data is persisted beyond the intentionally stored security descriptor, and no code-execution or arbitrary-write primitive is introduced.\nA:H - An unchecked multi-hundred-byte read past the smb_ace SID sub_auth array can cross slab/object boundaries and fault on hardened or KASAN builds; any unvalidated kernel out-of-bounds access is treated as capable of oops/panic and full host denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:45:50.170Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/26cb845e22a00c85bf566337417fa33492395f10"
},
{
"url": "https://git.kernel.org/stable/c/e31fada5143784bc05c7ae44c79eed9b7a2e147e"
},
{
"url": "https://git.kernel.org/stable/c/fb3dc8e6da46a1ccad1956cda57de29d9b3033e0"
},
{
"url": "https://git.kernel.org/stable/c/b6d3cc6a524416dfdb2b47e4bba2e7e20011d056"
},
{
"url": "https://git.kernel.org/stable/c/5acbd3012fd4a7ccfebd91ea6f784120084eb897"
},
{
"url": "https://git.kernel.org/stable/c/47f0b34f6bc98ed85bfdc293e8f3e432ec24958d"
}
],
"title": "ksmbd: validate num_subauth when copying ACE in set_ntacl_dacl",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68100",
"datePublished": "2026-08-10T11:58:15.233Z",
"dateReserved": "2026-07-30T09:28:09.368Z",
"dateUpdated": "2026-08-23T12:45:50.170Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2023-53706 (GCVE-0-2023-53706)
Vulnerability from cvelistv5
Published
2025-10-22 13:23
Modified
2026-08-23 12:45
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
mm/vmemmap/devdax: fix kernel crash when probing devdax devices
commit 4917f55b4ef9 ("mm/sparse-vmemmap: improve memory savings for
compound devmaps") added support for using optimized vmmemap for devdax
devices. But how vmemmap mappings are created are architecture specific.
For example, powerpc with hash translation doesn't have vmemmap mappings
in init_mm page table instead they are bolted table entries in the
hardware page table
vmemmap_populate_compound_pages() used by vmemmap optimization code is not
aware of these architecture-specific mapping. Hence allow architecture to
opt for this feature. I selected architectures supporting
HUGETLB_PAGE_OPTIMIZE_VMEMMAP option as also supporting this feature.
This patch fixes the below crash on ppc64.
BUG: Unable to handle kernel data access on write at 0xc00c000100400038
Faulting instruction address: 0xc000000001269d90
Oops: Kernel access of bad area, sig: 11 [#1]
LE PAGE_SIZE=64K MMU=Hash SMP NR_CPUS=2048 NUMA pSeries
Modules linked in:
CPU: 7 PID: 1 Comm: swapper/0 Not tainted 6.3.0-rc5-150500.34-default+ #2 5c90a668b6bbd142599890245c2fb5de19d7d28a
Hardware name: IBM,9009-42G POWER9 (raw) 0x4e0202 0xf000005 of:IBM,FW950.40 (VL950_099) hv:phyp pSeries
NIP: c000000001269d90 LR: c0000000004c57d4 CTR: 0000000000000000
REGS: c000000003632c30 TRAP: 0300 Not tainted (6.3.0-rc5-150500.34-default+)
MSR: 8000000000009033 <SF,EE,ME,IR,DR,RI,LE> CR: 24842228 XER: 00000000
CFAR: c0000000004c57d0 DAR: c00c000100400038 DSISR: 42000000 IRQMASK: 0
....
NIP [c000000001269d90] __init_single_page.isra.74+0x14/0x4c
LR [c0000000004c57d4] __init_zone_device_page+0x44/0xd0
Call Trace:
[c000000003632ed0] [c000000003632f60] 0xc000000003632f60 (unreliable)
[c000000003632f10] [c0000000004c5ca0] memmap_init_zone_device+0x170/0x250
[c000000003632fe0] [c0000000005575f8] memremap_pages+0x2c8/0x7f0
[c0000000036330c0] [c000000000557b5c] devm_memremap_pages+0x3c/0xa0
[c000000003633100] [c000000000d458a8] dev_dax_probe+0x108/0x3e0
[c0000000036331a0] [c000000000d41430] dax_bus_probe+0xb0/0x140
[c0000000036331d0] [c000000000cef27c] really_probe+0x19c/0x520
[c000000003633260] [c000000000cef6b4] __driver_probe_device+0xb4/0x230
[c0000000036332e0] [c000000000cef888] driver_probe_device+0x58/0x120
[c000000003633320] [c000000000cefa6c] __device_attach_driver+0x11c/0x1e0
[c0000000036333a0] [c000000000cebc58] bus_for_each_drv+0xa8/0x130
[c000000003633400] [c000000000ceefcc] __device_attach+0x15c/0x250
[c0000000036334a0] [c000000000ced458] bus_probe_device+0x108/0x110
[c0000000036334f0] [c000000000ce92dc] device_add+0x7fc/0xa10
[c0000000036335b0] [c000000000d447c8] devm_create_dev_dax+0x1d8/0x530
[c000000003633640] [c000000000d46b60] __dax_pmem_probe+0x200/0x270
[c0000000036337b0] [c000000000d46bf0] dax_pmem_probe+0x20/0x70
[c0000000036337d0] [c000000000d2279c] nvdimm_bus_probe+0xac/0x2b0
[c000000003633860] [c000000000cef27c] really_probe+0x19c/0x520
[c0000000036338f0] [c000000000cef6b4] __driver_probe_device+0xb4/0x230
[c000000003633970] [c000000000cef888] driver_probe_device+0x58/0x120
[c0000000036339b0] [c000000000cefd08] __driver_attach+0x1d8/0x240
[c000000003633a30] [c000000000cebb04] bus_for_each_dev+0xb4/0x130
[c000000003633a90] [c000000000cee564] driver_attach+0x34/0x50
[c000000003633ab0] [c000000000ced878] bus_add_driver+0x218/0x300
[c000000003633b40] [c000000000cf1144] driver_register+0xa4/0x1b0
[c000000003633bb0] [c000000000d21a0c] __nd_driver_register+0x5c/0x100
[c000000003633c10] [c00000000206a2e8] dax_pmem_init+0x34/0x48
[c000000003633c30] [c0000000000132d0] do_one_initcall+0x60/0x320
[c000000003633d00] [c0000000020051b0] kernel_init_freeable+0x360/0x400
[c000000003633de0] [c000000000013764] kernel_init+0x34/0x1d0
[c000000003633e50] [c00000000000de14] ret_from_kernel_thread+0x5c/0x64
References
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"include/linux/mm.h",
"mm/mm_init.c",
"mm/sparse-vmemmap.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "87349cf6818c4a0be00d49a13572f20a9e17887d",
"status": "affected",
"version": "4917f55b4ef963e2d2288fe4eb651728be8db406",
"versionType": "git"
},
{
"lessThan": "8f4603588acf5807aa1f1b4b1ea2b0365acd71f0",
"status": "affected",
"version": "4917f55b4ef963e2d2288fe4eb651728be8db406",
"versionType": "git"
},
{
"lessThan": "87a7ae75d7383afa998f57656d1d14e2a730cc47",
"status": "affected",
"version": "4917f55b4ef963e2d2288fe4eb651728be8db406",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"include/linux/mm.h",
"mm/mm_init.c",
"mm/sparse-vmemmap.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.19"
},
{
"lessThan": "5.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.3.*",
"status": "unaffected",
"version": "6.3.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "6.4",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.3.5",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.4",
"versionStartIncluding": "5.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/vmemmap/devdax: fix kernel crash when probing devdax devices\n\ncommit 4917f55b4ef9 (\"mm/sparse-vmemmap: improve memory savings for\ncompound devmaps\") added support for using optimized vmmemap for devdax\ndevices. But how vmemmap mappings are created are architecture specific. \nFor example, powerpc with hash translation doesn\u0027t have vmemmap mappings\nin init_mm page table instead they are bolted table entries in the\nhardware page table\n\nvmemmap_populate_compound_pages() used by vmemmap optimization code is not\naware of these architecture-specific mapping. Hence allow architecture to\nopt for this feature. I selected architectures supporting\nHUGETLB_PAGE_OPTIMIZE_VMEMMAP option as also supporting this feature.\n\nThis patch fixes the below crash on ppc64.\n\nBUG: Unable to handle kernel data access on write at 0xc00c000100400038\nFaulting instruction address: 0xc000000001269d90\nOops: Kernel access of bad area, sig: 11 [#1]\nLE PAGE_SIZE=64K MMU=Hash SMP NR_CPUS=2048 NUMA pSeries\nModules linked in:\nCPU: 7 PID: 1 Comm: swapper/0 Not tainted 6.3.0-rc5-150500.34-default+ #2 5c90a668b6bbd142599890245c2fb5de19d7d28a\nHardware name: IBM,9009-42G POWER9 (raw) 0x4e0202 0xf000005 of:IBM,FW950.40 (VL950_099) hv:phyp pSeries\nNIP: c000000001269d90 LR: c0000000004c57d4 CTR: 0000000000000000\nREGS: c000000003632c30 TRAP: 0300 Not tainted (6.3.0-rc5-150500.34-default+)\nMSR: 8000000000009033 \u003cSF,EE,ME,IR,DR,RI,LE\u003e CR: 24842228 XER: 00000000\nCFAR: c0000000004c57d0 DAR: c00c000100400038 DSISR: 42000000 IRQMASK: 0\n....\nNIP [c000000001269d90] __init_single_page.isra.74+0x14/0x4c\nLR [c0000000004c57d4] __init_zone_device_page+0x44/0xd0\nCall Trace:\n[c000000003632ed0] [c000000003632f60] 0xc000000003632f60 (unreliable)\n[c000000003632f10] [c0000000004c5ca0] memmap_init_zone_device+0x170/0x250\n[c000000003632fe0] [c0000000005575f8] memremap_pages+0x2c8/0x7f0\n[c0000000036330c0] [c000000000557b5c] devm_memremap_pages+0x3c/0xa0\n[c000000003633100] [c000000000d458a8] dev_dax_probe+0x108/0x3e0\n[c0000000036331a0] [c000000000d41430] dax_bus_probe+0xb0/0x140\n[c0000000036331d0] [c000000000cef27c] really_probe+0x19c/0x520\n[c000000003633260] [c000000000cef6b4] __driver_probe_device+0xb4/0x230\n[c0000000036332e0] [c000000000cef888] driver_probe_device+0x58/0x120\n[c000000003633320] [c000000000cefa6c] __device_attach_driver+0x11c/0x1e0\n[c0000000036333a0] [c000000000cebc58] bus_for_each_drv+0xa8/0x130\n[c000000003633400] [c000000000ceefcc] __device_attach+0x15c/0x250\n[c0000000036334a0] [c000000000ced458] bus_probe_device+0x108/0x110\n[c0000000036334f0] [c000000000ce92dc] device_add+0x7fc/0xa10\n[c0000000036335b0] [c000000000d447c8] devm_create_dev_dax+0x1d8/0x530\n[c000000003633640] [c000000000d46b60] __dax_pmem_probe+0x200/0x270\n[c0000000036337b0] [c000000000d46bf0] dax_pmem_probe+0x20/0x70\n[c0000000036337d0] [c000000000d2279c] nvdimm_bus_probe+0xac/0x2b0\n[c000000003633860] [c000000000cef27c] really_probe+0x19c/0x520\n[c0000000036338f0] [c000000000cef6b4] __driver_probe_device+0xb4/0x230\n[c000000003633970] [c000000000cef888] driver_probe_device+0x58/0x120\n[c0000000036339b0] [c000000000cefd08] __driver_attach+0x1d8/0x240\n[c000000003633a30] [c000000000cebb04] bus_for_each_dev+0xb4/0x130\n[c000000003633a90] [c000000000cee564] driver_attach+0x34/0x50\n[c000000003633ab0] [c000000000ced878] bus_add_driver+0x218/0x300\n[c000000003633b40] [c000000000cf1144] driver_register+0xa4/0x1b0\n[c000000003633bb0] [c000000000d21a0c] __nd_driver_register+0x5c/0x100\n[c000000003633c10] [c00000000206a2e8] dax_pmem_init+0x34/0x48\n[c000000003633c30] [c0000000000132d0] do_one_initcall+0x60/0x320\n[c000000003633d00] [c0000000020051b0] kernel_init_freeable+0x360/0x400\n[c000000003633de0] [c000000000013764] kernel_init+0x34/0x1d0\n[c000000003633e50] [c00000000000de14] ret_from_kernel_thread+0x5c/0x64"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:45:16.955Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/87349cf6818c4a0be00d49a13572f20a9e17887d"
},
{
"url": "https://git.kernel.org/stable/c/8f4603588acf5807aa1f1b4b1ea2b0365acd71f0"
},
{
"url": "https://git.kernel.org/stable/c/87a7ae75d7383afa998f57656d1d14e2a730cc47"
}
],
"title": "mm/vmemmap/devdax: fix kernel crash when probing devdax devices",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2023-53706",
"datePublished": "2025-10-22T13:23:43.228Z",
"dateReserved": "2025-10-22T13:21:37.346Z",
"dateUpdated": "2026-08-23T12:45:16.955Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80570 (GCVE-0-2026-80570)
Vulnerability from cvelistv5
Published
2026-08-26 14:37
Modified
2026-08-27 05:01
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Input: synaptics-rmi4 - zero report size on F54 work error
In rmi_f54_work(), if an error occurs during report request or command
verification, the code jumped directly to the 'error' label, bypassing
the 'abort' label where f54->report_size was normally zeroed out.
This left f54->report_size containing its previous successful payload
size. If a user then altered the V4L2 format to a smaller size, and a
subsequent run failed, rmi_f54_buffer_queue() would copy the stale,
larger payload size into the shrunken V4L2 buffer, causing a heap
buffer overflow.
Fix this by merging the 'abort' and 'error' labels into a single 'out'
exit path, and ensuring that f54->report_size is always set to 0 on
failure by checking for error and zeroing the local report_size first.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d Version: 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d Version: 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d Version: 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d Version: 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d Version: 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d Version: 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d Version: 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/input/rmi4/rmi_f54.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "62079c17ec07d64362bec367ee7a525b0dbf6bf9",
"status": "affected",
"version": "3a762dbd5347514c3cb2ac756a92a3d1c7646a2d",
"versionType": "git"
},
{
"lessThan": "79521ed3cc9ea48476666ccacf45ecd6954b29a4",
"status": "affected",
"version": "3a762dbd5347514c3cb2ac756a92a3d1c7646a2d",
"versionType": "git"
},
{
"lessThan": "c669c64ab71afa7b467c4d7e18f6a05e96b97a1f",
"status": "affected",
"version": "3a762dbd5347514c3cb2ac756a92a3d1c7646a2d",
"versionType": "git"
},
{
"lessThan": "77749685e55da19b187df215b5da4080842ca5c7",
"status": "affected",
"version": "3a762dbd5347514c3cb2ac756a92a3d1c7646a2d",
"versionType": "git"
},
{
"lessThan": "c6cfda79f26c69e97db9805808c3b44d02227b4b",
"status": "affected",
"version": "3a762dbd5347514c3cb2ac756a92a3d1c7646a2d",
"versionType": "git"
},
{
"lessThan": "b28593a05afdd812b590e1045b5bd862a5869225",
"status": "affected",
"version": "3a762dbd5347514c3cb2ac756a92a3d1c7646a2d",
"versionType": "git"
},
{
"lessThan": "88c8174d72900d77fbdf2f527d54b6ff2da876a8",
"status": "affected",
"version": "3a762dbd5347514c3cb2ac756a92a3d1c7646a2d",
"versionType": "git"
},
{
"lessThan": "dc76c3c8e8ad09362b8c1561f3928288c15cba2e",
"status": "affected",
"version": "3a762dbd5347514c3cb2ac756a92a3d1c7646a2d",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/input/rmi4/rmi_f54.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.9"
},
{
"lessThan": "4.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.46",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.10",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nInput: synaptics-rmi4 - zero report size on F54 work error\n\nIn rmi_f54_work(), if an error occurs during report request or command\nverification, the code jumped directly to the \u0027error\u0027 label, bypassing\nthe \u0027abort\u0027 label where f54-\u003ereport_size was normally zeroed out.\n\nThis left f54-\u003ereport_size containing its previous successful payload\nsize. If a user then altered the V4L2 format to a smaller size, and a\nsubsequent run failed, rmi_f54_buffer_queue() would copy the stale,\nlarger payload size into the shrunken V4L2 buffer, causing a heap\nbuffer overflow.\n\nFix this by merging the \u0027abort\u0027 and \u0027error\u0027 labels into a single \u0027out\u0027\nexit path, and ensuring that f54-\u003ereport_size is always set to 0 on\nfailure by checking for error and zeroing the local report_size first."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires local V4L2 ioctls on the synaptics-rmi4 F54 diagnostics node (/dev/v4l-touch*); open/STREAMON/QBUF drives rmi_f54_buffer_queue() memcpy() using stale f54-\u003ereport_size. There is no network, Bluetooth, or physical-bus injection path to this code.\nAC:L - An attacker can capture a large F54 report, stop streaming, switch VIDIOC_S_INPUT to a smaller report type, then re-stream and retry until rmi_f54_work() takes the error goto (timeout or register-read failure); ioctl timing is attacker-controlled and no uncontrollable victim state is required.\nPR:L - Triggering the overflow needs only permission to open the registered VFL_TYPE_TOUCH device and issue standard V4L2 capture ioctls; on typical laptop, kiosk, and Android deployments this is granted to unprivileged local users via video/input device policy without init-namespace root.\nUI:N - No cooperative victim action is required; the attacker opens the diagnostics node, performs the capture/input-change/re-stream sequence, and queues buffers themselves. No other user must mount filesystems, plug devices, or perform GUI actions at exploit time.\nS:U - The flaw corrupts kernel heap memory via vb2 vmalloc buffers in the F54 V4L2 driver on the same host; impact stays within the kernel security authority and does not by itself cross VM, IOMMU, or sandbox boundaries.\nC:H - On worker failure f54-\u003ereport_size retains the prior successful payload size, so memcpy() can write up to roughly twice the newly allocated V4L2 buffer into adjacent vmalloc heap memory, enabling disclosure or corruption of neighboring kernel objects.\nI:H - The stale-size memcpy in rmi_f54_buffer_queue() is a controlled kernel heap buffer overflow that can corrupt adjacent vmalloc objects and be developed into arbitrary memory write or code-execution primitives, not merely a bounded data change.\nA:H - Writing far beyond the shrunken V4L2 capture buffer can corrupt critical kernel heap metadata or adjacent structures, causing kernel oops or panic on affected laptops, kiosks, and embedded touch systems even without full exploit development."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T05:01:54.209Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/62079c17ec07d64362bec367ee7a525b0dbf6bf9"
},
{
"url": "https://git.kernel.org/stable/c/79521ed3cc9ea48476666ccacf45ecd6954b29a4"
},
{
"url": "https://git.kernel.org/stable/c/c669c64ab71afa7b467c4d7e18f6a05e96b97a1f"
},
{
"url": "https://git.kernel.org/stable/c/77749685e55da19b187df215b5da4080842ca5c7"
},
{
"url": "https://git.kernel.org/stable/c/c6cfda79f26c69e97db9805808c3b44d02227b4b"
},
{
"url": "https://git.kernel.org/stable/c/b28593a05afdd812b590e1045b5bd862a5869225"
},
{
"url": "https://git.kernel.org/stable/c/88c8174d72900d77fbdf2f527d54b6ff2da876a8"
},
{
"url": "https://git.kernel.org/stable/c/dc76c3c8e8ad09362b8c1561f3928288c15cba2e"
}
],
"title": "Input: synaptics-rmi4 - zero report size on F54 work error",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80570",
"datePublished": "2026-08-26T14:37:31.940Z",
"dateReserved": "2026-08-26T14:34:25.768Z",
"dateUpdated": "2026-08-27T05:01:54.209Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80708 (GCVE-0-2026-80708)
Vulnerability from cvelistv5
Published
2026-08-28 06:53
Modified
2026-08-28 06:53
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
s390/zcrypt: Fix missing mem scrub at clear key import in cca_clr2cipherkey()
The helper function _ip_cprb_helper() uses internal buffer memory for
building and processing CPRBs. After use this buffer was never
scrubbed which could lead to leaving for example clear key material in
memory which could be exposed via tricky reuse of this same memory.
Extend the _ip_cprb_helper() function with another parameter 'scrub'
used to steer scrubbing of this buffer. So now the caller has the
opportunity to decide if scrubbing is needed or not.
Extend the clear key to secure key token import process in function
cca_clr2cipherkey() to tell the helper function from above to scrub
the cprb buffer when the clear key value is part of the request data.
Add explicit scrubbing on return from function cca_clr2cipherkey() for
the random EXOR buffer and the cprb buffer.
Overall this cleans the internal used buffer in case of clear key
import to prevent sensitive data to get exposed.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 4bc123b18ce6ae6c42c69d0456b5acbd2f7bc8bd Version: 4bc123b18ce6ae6c42c69d0456b5acbd2f7bc8bd Version: 4bc123b18ce6ae6c42c69d0456b5acbd2f7bc8bd Version: 4bc123b18ce6ae6c42c69d0456b5acbd2f7bc8bd Version: 4bc123b18ce6ae6c42c69d0456b5acbd2f7bc8bd Version: 4bc123b18ce6ae6c42c69d0456b5acbd2f7bc8bd Version: 4bc123b18ce6ae6c42c69d0456b5acbd2f7bc8bd Version: 4bc123b18ce6ae6c42c69d0456b5acbd2f7bc8bd |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/s390/crypto/zcrypt_ccamisc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "8e1c0def77b7450be0ed607ed0d7bae629d30020",
"status": "affected",
"version": "4bc123b18ce6ae6c42c69d0456b5acbd2f7bc8bd",
"versionType": "git"
},
{
"lessThan": "be7ae07fb745d1cf575b03a178a055b0a2859364",
"status": "affected",
"version": "4bc123b18ce6ae6c42c69d0456b5acbd2f7bc8bd",
"versionType": "git"
},
{
"lessThan": "4e26d0d72bfdec311f12acfa0c6b7fbeb6a343d3",
"status": "affected",
"version": "4bc123b18ce6ae6c42c69d0456b5acbd2f7bc8bd",
"versionType": "git"
},
{
"lessThan": "7dd6e556dbfc91d3d511cfd1015d2dad42608010",
"status": "affected",
"version": "4bc123b18ce6ae6c42c69d0456b5acbd2f7bc8bd",
"versionType": "git"
},
{
"lessThan": "b453003ae6a869f5bdf025b5519cbb38295ae4f1",
"status": "affected",
"version": "4bc123b18ce6ae6c42c69d0456b5acbd2f7bc8bd",
"versionType": "git"
},
{
"lessThan": "fbb0410986e8ad214121e51a4a28c3d0a10b7644",
"status": "affected",
"version": "4bc123b18ce6ae6c42c69d0456b5acbd2f7bc8bd",
"versionType": "git"
},
{
"lessThan": "ebfbb9ac7adbb1e3556100b54a27e8a9b102feac",
"status": "affected",
"version": "4bc123b18ce6ae6c42c69d0456b5acbd2f7bc8bd",
"versionType": "git"
},
{
"lessThan": "01476391aecef36a3b789ee844357b22fbc90665",
"status": "affected",
"version": "4bc123b18ce6ae6c42c69d0456b5acbd2f7bc8bd",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/s390/crypto/zcrypt_ccamisc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.4"
},
{
"lessThan": "5.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/zcrypt: Fix missing mem scrub at clear key import in cca_clr2cipherkey()\n\nThe helper function _ip_cprb_helper() uses internal buffer memory for\nbuilding and processing CPRBs. After use this buffer was never\nscrubbed which could lead to leaving for example clear key material in\nmemory which could be exposed via tricky reuse of this same memory.\n\nExtend the _ip_cprb_helper() function with another parameter \u0027scrub\u0027\nused to steer scrubbing of this buffer. So now the caller has the\nopportunity to decide if scrubbing is needed or not.\n\nExtend the clear key to secure key token import process in function\ncca_clr2cipherkey() to tell the helper function from above to scrub\nthe cprb buffer when the clear key value is part of the request data.\n\nAdd explicit scrubbing on return from function cca_clr2cipherkey() for\nthe random EXOR buffer and the cprb buffer.\n\nOverall this cleans the internal used buffer in case of clear key\nimport to prevent sensitive data to get exposed."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-28T06:53:08.843Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/8e1c0def77b7450be0ed607ed0d7bae629d30020"
},
{
"url": "https://git.kernel.org/stable/c/be7ae07fb745d1cf575b03a178a055b0a2859364"
},
{
"url": "https://git.kernel.org/stable/c/4e26d0d72bfdec311f12acfa0c6b7fbeb6a343d3"
},
{
"url": "https://git.kernel.org/stable/c/7dd6e556dbfc91d3d511cfd1015d2dad42608010"
},
{
"url": "https://git.kernel.org/stable/c/b453003ae6a869f5bdf025b5519cbb38295ae4f1"
},
{
"url": "https://git.kernel.org/stable/c/fbb0410986e8ad214121e51a4a28c3d0a10b7644"
},
{
"url": "https://git.kernel.org/stable/c/ebfbb9ac7adbb1e3556100b54a27e8a9b102feac"
},
{
"url": "https://git.kernel.org/stable/c/01476391aecef36a3b789ee844357b22fbc90665"
}
],
"title": "s390/zcrypt: Fix missing mem scrub at clear key import in cca_clr2cipherkey()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80708",
"datePublished": "2026-08-28T06:53:08.843Z",
"dateReserved": "2026-08-26T14:34:25.787Z",
"dateUpdated": "2026-08-28T06:53:08.843Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80814 (GCVE-0-2026-80814)
Vulnerability from cvelistv5
Published
2026-09-04 15:13
Modified
2026-09-07 14:21
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
rndis_host: add overflow check in rndis_rx_fixup()
Add an overflow check to ensure that data_offset + data_len + 8 does not
wrap, which would enable an OOB read of the USB data buffer.
References
| URL | Tags | ||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 64e049102d3de3e61409cb6019403a9e689dfda6 Version: 64e049102d3de3e61409cb6019403a9e689dfda6 Version: 64e049102d3de3e61409cb6019403a9e689dfda6 Version: 64e049102d3de3e61409cb6019403a9e689dfda6 Version: 64e049102d3de3e61409cb6019403a9e689dfda6 Version: 64e049102d3de3e61409cb6019403a9e689dfda6 Version: 64e049102d3de3e61409cb6019403a9e689dfda6 Version: 64e049102d3de3e61409cb6019403a9e689dfda6 Version: 64e049102d3de3e61409cb6019403a9e689dfda6 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/usb/rndis_host.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "2140db1232af04b92faa6c4a2a40df6371ea89ff",
"status": "affected",
"version": "64e049102d3de3e61409cb6019403a9e689dfda6",
"versionType": "git"
},
{
"lessThan": "8ca3bd404d076495ed0b274b65971c57b6fd5ac0",
"status": "affected",
"version": "64e049102d3de3e61409cb6019403a9e689dfda6",
"versionType": "git"
},
{
"lessThan": "f8e6fde5db87f855e99b200e392467274f0eb9d7",
"status": "affected",
"version": "64e049102d3de3e61409cb6019403a9e689dfda6",
"versionType": "git"
},
{
"lessThan": "10a6b99079697c5027b25352e882bdf54fef702a",
"status": "affected",
"version": "64e049102d3de3e61409cb6019403a9e689dfda6",
"versionType": "git"
},
{
"lessThan": "c5398ce6db7647b7004d73a3102ccc25fb4bb596",
"status": "affected",
"version": "64e049102d3de3e61409cb6019403a9e689dfda6",
"versionType": "git"
},
{
"lessThan": "e971d956353d382ee2185d71c47b538501a43f76",
"status": "affected",
"version": "64e049102d3de3e61409cb6019403a9e689dfda6",
"versionType": "git"
},
{
"lessThan": "be7dc3650f799a253df4edd4fe230fc9ea4be063",
"status": "affected",
"version": "64e049102d3de3e61409cb6019403a9e689dfda6",
"versionType": "git"
},
{
"lessThan": "2ded89ca77fae1da6886fe94831acfe4d6aa80b1",
"status": "affected",
"version": "64e049102d3de3e61409cb6019403a9e689dfda6",
"versionType": "git"
},
{
"lessThan": "965a251f23ff69cfb4486974d4532e9bb551c7fc",
"status": "affected",
"version": "64e049102d3de3e61409cb6019403a9e689dfda6",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/usb/rndis_host.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.14"
},
{
"lessThan": "2.6.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.267",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.218",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.185",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.154",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.106",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.47",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.1",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.267",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.218",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.185",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.154",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.106",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.47",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.11",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.1",
"versionStartIncluding": "2.6.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "2.6.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nrndis_host: add overflow check in rndis_rx_fixup()\n\nAdd an overflow check to ensure that data_offset + data_len + 8 does not\nwrap, which would enable an OOB read of the USB data buffer."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-07T14:21:16.493Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/2140db1232af04b92faa6c4a2a40df6371ea89ff"
},
{
"url": "https://git.kernel.org/stable/c/8ca3bd404d076495ed0b274b65971c57b6fd5ac0"
},
{
"url": "https://git.kernel.org/stable/c/f8e6fde5db87f855e99b200e392467274f0eb9d7"
},
{
"url": "https://git.kernel.org/stable/c/10a6b99079697c5027b25352e882bdf54fef702a"
},
{
"url": "https://git.kernel.org/stable/c/c5398ce6db7647b7004d73a3102ccc25fb4bb596"
},
{
"url": "https://git.kernel.org/stable/c/e971d956353d382ee2185d71c47b538501a43f76"
},
{
"url": "https://git.kernel.org/stable/c/be7dc3650f799a253df4edd4fe230fc9ea4be063"
},
{
"url": "https://git.kernel.org/stable/c/2ded89ca77fae1da6886fe94831acfe4d6aa80b1"
},
{
"url": "https://git.kernel.org/stable/c/965a251f23ff69cfb4486974d4532e9bb551c7fc"
}
],
"title": "rndis_host: add overflow check in rndis_rx_fixup()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80814",
"datePublished": "2026-09-04T15:13:34.711Z",
"dateReserved": "2026-08-26T14:34:25.794Z",
"dateUpdated": "2026-09-07T14:21:16.493Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80709 (GCVE-0-2026-80709)
Vulnerability from cvelistv5
Published
2026-08-28 06:53
Modified
2026-08-29 06:22
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
s390/zcrypt: Fix wrong domain value verification with EP11 CPRBs
There is a wrong upper limit check for the domain value when an EP11
CPRB is processed for sending to a crypto card. This check is only
active on custom device nodes but may lead to access heap memory
behind perms->adm when an administrative CPRB is sent.
Add correct limit (AP_DOMAINS = 256) checking to fix this.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: cfd68b33094e1a92249850ff3c3c92ae9112a541 Version: cfd68b33094e1a92249850ff3c3c92ae9112a541 Version: cfd68b33094e1a92249850ff3c3c92ae9112a541 Version: cfd68b33094e1a92249850ff3c3c92ae9112a541 Version: cfd68b33094e1a92249850ff3c3c92ae9112a541 Version: cfd68b33094e1a92249850ff3c3c92ae9112a541 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/s390/crypto/zcrypt_api.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "4589f742718d0256ea6dd1f5a78be6e689bdb8aa",
"status": "affected",
"version": "cfd68b33094e1a92249850ff3c3c92ae9112a541",
"versionType": "git"
},
{
"lessThan": "b505dcc8307d64468b463dfad45a03bf865c637e",
"status": "affected",
"version": "cfd68b33094e1a92249850ff3c3c92ae9112a541",
"versionType": "git"
},
{
"lessThan": "13e53d6ae1c3b2ff1be75b9ef09be26f4ec3ce15",
"status": "affected",
"version": "cfd68b33094e1a92249850ff3c3c92ae9112a541",
"versionType": "git"
},
{
"lessThan": "672b12940e3f1336dfed5287412a71500adf2a76",
"status": "affected",
"version": "cfd68b33094e1a92249850ff3c3c92ae9112a541",
"versionType": "git"
},
{
"lessThan": "1223477ca88e2396eca440919d0ca8754df79bd5",
"status": "affected",
"version": "cfd68b33094e1a92249850ff3c3c92ae9112a541",
"versionType": "git"
},
{
"lessThan": "983279d7f86ade73db86f886e09172dd567031b5",
"status": "affected",
"version": "cfd68b33094e1a92249850ff3c3c92ae9112a541",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/s390/crypto/zcrypt_api.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.18"
},
{
"lessThan": "5.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.18",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/zcrypt: Fix wrong domain value verification with EP11 CPRBs\n\nThere is a wrong upper limit check for the domain value when an EP11\nCPRB is processed for sending to a crypto card. This check is only\nactive on custom device nodes but may lead to access heap memory\nbehind perms-\u003eadm when an administrative CPRB is sent.\nAdd correct limit (AP_DOMAINS = 256) checking to fix this."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Reached only via ZSENDEP11CPRB ioctl on an s390 zcrypt custom zcdn character device (zcrypt_unlocked_ioctl -\u003e zsendep11cprb_ioctl -\u003e _zcrypt_send_ep11_cprb); no network, radio, or physical-bus entry path exists.\nAC:L - A local attacker with a permitted zcdn fd fully controls ep11_urb/CPRB target_id and the admin flag; domain values 256-65534 reliably trigger the flawed test_bit_inv() past perms-\u003eadm without races or conditions outside attacker control.\nPR:L - Exploitation requires local access to a custom zcdn node with ZSENDEP11CPRB enabled in ioctlmask; IBM Z/LinuxONE deployments routinely delegate such restricted crypto device access to non-root service accounts, not init-namespace root alone.\nUI:N - The attacker triggers the flaw by issuing ZSENDEP11CPRB with a crafted administrative EP11 CPRB from their own process; no separate victim action such as mounting a filesystem or opening a file is required.\nS:U - Impact is kernel heap out-of-bounds read and bypass of per-device admin-domain filtering within the host kernel address space; it does not cross a VM, IOMMU, or other changed security-authority boundary.\nC:H - Using domain 256-65534 with an admin CPRB makes test_bit_inv() index beyond the 256-bit perms-\u003eadm bitmap, reading adjacent kmalloc heap memory behind the zcdn_device allocation.\nI:H - If the out-of-bounds read observes a set bit, the admask admin-domain check passes and unauthorized EP11 administrative CPRBs can reach crypto control domains outside the device\u0027s intended permissions.\nA:H - Large crafted domain values make test_bit_inv() read far beyond the zcdn_device kmalloc object, which can access unmapped memory and provoke a kernel oops or panic during the ioctl path."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-29T06:22:25.717Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/4589f742718d0256ea6dd1f5a78be6e689bdb8aa"
},
{
"url": "https://git.kernel.org/stable/c/b505dcc8307d64468b463dfad45a03bf865c637e"
},
{
"url": "https://git.kernel.org/stable/c/13e53d6ae1c3b2ff1be75b9ef09be26f4ec3ce15"
},
{
"url": "https://git.kernel.org/stable/c/672b12940e3f1336dfed5287412a71500adf2a76"
},
{
"url": "https://git.kernel.org/stable/c/1223477ca88e2396eca440919d0ca8754df79bd5"
},
{
"url": "https://git.kernel.org/stable/c/983279d7f86ade73db86f886e09172dd567031b5"
}
],
"title": "s390/zcrypt: Fix wrong domain value verification with EP11 CPRBs",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80709",
"datePublished": "2026-08-28T06:53:09.439Z",
"dateReserved": "2026-08-26T14:34:25.787Z",
"dateUpdated": "2026-08-29T06:22:25.717Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68405 (GCVE-0-2026-68405)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock
ieee80211_do_stop() removes AP_VLAN packets from the parent AP
ps->bc_buf while holding ps->bc_buf.lock with IRQs disabled. It then
calls ieee80211_free_txskb() before dropping the lock.
ieee80211_free_txskb() is not just a passive SKB release. For SKBs with
TX status state it can report a dropped frame through cfg80211/nl80211,
and that path can reach netlink tap transmit. This is the same reason
the pending queue cleanup in ieee80211_do_stop() already unlinks SKBs
under the queue lock and frees them after IRQ state is restored.
The buggy scenario involves two paths, with each column showing the
order within that path:
AP_VLAN management TX: AP_VLAN stop:
1. attach ACK-status state 1. clear the running state
2. queue a multicast SKB on 2. take ps->bc_buf.lock with IRQs
parent ps->bc_buf disabled
3. unlink the AP_VLAN SKB
4. call ieee80211_free_txskb()
Unlink matching AP_VLAN SKBs from ps->bc_buf under the existing lock,
but move them to a local free queue. Drop the lock and restore IRQ state
before calling ieee80211_free_txskb().
WARNING: kernel/softirq.c:430 at __local_bh_enable_ip
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 397a7a24ef8c2967a3e8090013f9c54714110c48 Version: 397a7a24ef8c2967a3e8090013f9c54714110c48 Version: 397a7a24ef8c2967a3e8090013f9c54714110c48 Version: 397a7a24ef8c2967a3e8090013f9c54714110c48 Version: 397a7a24ef8c2967a3e8090013f9c54714110c48 Version: 397a7a24ef8c2967a3e8090013f9c54714110c48 Version: 397a7a24ef8c2967a3e8090013f9c54714110c48 Version: 397a7a24ef8c2967a3e8090013f9c54714110c48 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/mac80211/iface.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "0d2619e708e2ef02ba1c91642ea261d3f19d8f9a",
"status": "affected",
"version": "397a7a24ef8c2967a3e8090013f9c54714110c48",
"versionType": "git"
},
{
"lessThan": "659a81b62a61440b85e02c09903be861ae7679e5",
"status": "affected",
"version": "397a7a24ef8c2967a3e8090013f9c54714110c48",
"versionType": "git"
},
{
"lessThan": "aa01ef0ebbc3289154229ef58e65baf289eb9789",
"status": "affected",
"version": "397a7a24ef8c2967a3e8090013f9c54714110c48",
"versionType": "git"
},
{
"lessThan": "be9dfcb0654c1f6c0fce7ba2a909683bb6f1e0ef",
"status": "affected",
"version": "397a7a24ef8c2967a3e8090013f9c54714110c48",
"versionType": "git"
},
{
"lessThan": "962f755a47d7ec3bbf6c709697d7f4c5f798441d",
"status": "affected",
"version": "397a7a24ef8c2967a3e8090013f9c54714110c48",
"versionType": "git"
},
{
"lessThan": "a424985c3ef2a87ce6057a853e18d0c441a86be8",
"status": "affected",
"version": "397a7a24ef8c2967a3e8090013f9c54714110c48",
"versionType": "git"
},
{
"lessThan": "4b8abf43bf34791c99d99dc3be13f897adefc461",
"status": "affected",
"version": "397a7a24ef8c2967a3e8090013f9c54714110c48",
"versionType": "git"
},
{
"lessThan": "f3858d5b1432098c1936e03d6e03dd0e33facf60",
"status": "affected",
"version": "397a7a24ef8c2967a3e8090013f9c54714110c48",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/mac80211/iface.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.9"
},
{
"lessThan": "3.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock\n\nieee80211_do_stop() removes AP_VLAN packets from the parent AP\nps-\u003ebc_buf while holding ps-\u003ebc_buf.lock with IRQs disabled. It then\ncalls ieee80211_free_txskb() before dropping the lock.\n\nieee80211_free_txskb() is not just a passive SKB release. For SKBs with\nTX status state it can report a dropped frame through cfg80211/nl80211,\nand that path can reach netlink tap transmit. This is the same reason\nthe pending queue cleanup in ieee80211_do_stop() already unlinks SKBs\nunder the queue lock and frees them after IRQ state is restored.\n\nThe buggy scenario involves two paths, with each column showing the\norder within that path:\n\nAP_VLAN management TX: AP_VLAN stop:\n1. attach ACK-status state 1. clear the running state\n2. queue a multicast SKB on 2. take ps-\u003ebc_buf.lock with IRQs\n parent ps-\u003ebc_buf disabled\n 3. unlink the AP_VLAN SKB\n 4. call ieee80211_free_txskb()\n\nUnlink matching AP_VLAN SKBs from ps-\u003ebc_buf under the existing lock,\nbut move them to a local free queue. Drop the lock and restore IRQ state\nbefore calling ieee80211_free_txskb().\n\nWARNING: kernel/softirq.c:430 at __local_bh_enable_ip"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:57.265Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/0d2619e708e2ef02ba1c91642ea261d3f19d8f9a"
},
{
"url": "https://git.kernel.org/stable/c/659a81b62a61440b85e02c09903be861ae7679e5"
},
{
"url": "https://git.kernel.org/stable/c/aa01ef0ebbc3289154229ef58e65baf289eb9789"
},
{
"url": "https://git.kernel.org/stable/c/be9dfcb0654c1f6c0fce7ba2a909683bb6f1e0ef"
},
{
"url": "https://git.kernel.org/stable/c/962f755a47d7ec3bbf6c709697d7f4c5f798441d"
},
{
"url": "https://git.kernel.org/stable/c/a424985c3ef2a87ce6057a853e18d0c441a86be8"
},
{
"url": "https://git.kernel.org/stable/c/4b8abf43bf34791c99d99dc3be13f897adefc461"
},
{
"url": "https://git.kernel.org/stable/c/f3858d5b1432098c1936e03d6e03dd0e33facf60"
}
],
"title": "wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68405",
"datePublished": "2026-08-10T12:04:25.241Z",
"dateReserved": "2026-07-30T09:28:09.390Z",
"dateUpdated": "2026-08-19T16:34:57.265Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74688 (GCVE-0-2026-74688)
Vulnerability from cvelistv5
Published
2026-08-22 15:32
Modified
2026-08-25 05:41
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
sctp: clear control chunk transport if it is being removed
sctp_make_heartbeat_ack() caches the destination transport in
chunk->transport without taking a reference. When src_out_of_asoc_ok is
enabled, the HEARTBEAT ACK may remain queued on control_chunk_list instead
of being transmitted immediately.
If the peer transport is removed while the chunk is still queued,
sctp_assoc_rm_peer() drops the transport and schedules it for RCU freeing,
but only clears cached transport pointers in out_chunk_list. The queued
control chunk therefore retains a dangling transport pointer.
Once an ASCONF_ACK clears the suppression and the queued control chunk is
transmitted, SCTP dereferences the stale transport pointer, leading to a
use-after-free.
Fix this by also clearing chunk->transport for queued control chunks in
control_chunk_list when removing the transport.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 8a07eb0a50aebc8c95478d49c28c7f8419a26cef Version: 8a07eb0a50aebc8c95478d49c28c7f8419a26cef Version: 8a07eb0a50aebc8c95478d49c28c7f8419a26cef Version: 8a07eb0a50aebc8c95478d49c28c7f8419a26cef Version: 8a07eb0a50aebc8c95478d49c28c7f8419a26cef Version: 8a07eb0a50aebc8c95478d49c28c7f8419a26cef Version: 8a07eb0a50aebc8c95478d49c28c7f8419a26cef Version: 8a07eb0a50aebc8c95478d49c28c7f8419a26cef |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/sctp/associola.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "dbb3f418a8665ffb0514e1a9520ab6a1c5d4d886",
"status": "affected",
"version": "8a07eb0a50aebc8c95478d49c28c7f8419a26cef",
"versionType": "git"
},
{
"lessThan": "fad4766a74220fe579c6fcaa10ba01c23529814f",
"status": "affected",
"version": "8a07eb0a50aebc8c95478d49c28c7f8419a26cef",
"versionType": "git"
},
{
"lessThan": "936658ec41c28c397ef390140e02d4c91ade92f0",
"status": "affected",
"version": "8a07eb0a50aebc8c95478d49c28c7f8419a26cef",
"versionType": "git"
},
{
"lessThan": "8de65194a04d2552cd39b6c67d942d490f22d174",
"status": "affected",
"version": "8a07eb0a50aebc8c95478d49c28c7f8419a26cef",
"versionType": "git"
},
{
"lessThan": "6160e756db81d6cb63e3e2952efcf6c5134be385",
"status": "affected",
"version": "8a07eb0a50aebc8c95478d49c28c7f8419a26cef",
"versionType": "git"
},
{
"lessThan": "18d704bdd809377dfd81a3c2f42426763b5da227",
"status": "affected",
"version": "8a07eb0a50aebc8c95478d49c28c7f8419a26cef",
"versionType": "git"
},
{
"lessThan": "4d6b9cac6df5e0cfef1a66b3edd7aebdb9e4b7e7",
"status": "affected",
"version": "8a07eb0a50aebc8c95478d49c28c7f8419a26cef",
"versionType": "git"
},
{
"lessThan": "c9158ceaf27780ef64534ad72f44ffde3f8ccc49",
"status": "affected",
"version": "8a07eb0a50aebc8c95478d49c28c7f8419a26cef",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/sctp/associola.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.1"
},
{
"lessThan": "3.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "3.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: clear control chunk transport if it is being removed\n\nsctp_make_heartbeat_ack() caches the destination transport in\nchunk-\u003etransport without taking a reference. When src_out_of_asoc_ok is\nenabled, the HEARTBEAT ACK may remain queued on control_chunk_list instead\nof being transmitted immediately.\n\nIf the peer transport is removed while the chunk is still queued,\nsctp_assoc_rm_peer() drops the transport and schedules it for RCU freeing,\nbut only clears cached transport pointers in out_chunk_list. The queued\ncontrol chunk therefore retains a dangling transport pointer.\n\nOnce an ASCONF_ACK clears the suppression and the queued control chunk is\ntransmitted, SCTP dereferences the stale transport pointer, leading to a\nuse-after-free.\n\nFix this by also clearing chunk-\u003etransport for queued control chunks in\ncontrol_chunk_list when removing the transport."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug is reached from remotely received SCTP packets (HEARTBEAT, ASCONF, ASCONF_ACK) processed in sctp_rcv() and the association input state machine on internet-facing SCTP servers and telecom endpoints.\nAC:L - A remote SCTP peer controls packet sequencing and can send HEARTBEAT while src_out_of_asoc_ok blocks transmission, remove transports via ASCONF DEL_IP, then trigger flush when ASCONF_ACK clears suppression.\nPR:N - Exploitation requires only a network-reachable established SCTP association; the attacker needs no Linux credentials, capabilities, or namespaces\u2014only the ability to send valid SCTP traffic to the target.\nUI:N - No victim user action is required; the use-after-free is triggered entirely by SCTP protocol messages sent by a remote peer during normal association operation or address migration.\nS:U - Impact is confined to kernel memory corruption and privilege escalation within the host kernel; it does not cross VM, container, or IOMMU security boundaries.\nC:H - Stale chunk-\u003etransport pointers dereference RCU-freed sctp_transport objects in sctp_outq_select_transport() and sctp_packet_transmit(), a use-after-free that enables arbitrary kernel memory disclosure via heap grooming.\nI:H - Use-after-free of sctp_transport allows controlled reuse of freed kmalloc objects, providing a standard path to arbitrary kernel writes and local privilege escalation or remote code execution in kernel context.\nA:H - Dereferencing the freed transport during control-chunk transmission can immediately kernel oops or panic the system; use-after-free bugs inherently threaten availability even when full exploitation is not attempted."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:41:32.712Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/dbb3f418a8665ffb0514e1a9520ab6a1c5d4d886"
},
{
"url": "https://git.kernel.org/stable/c/fad4766a74220fe579c6fcaa10ba01c23529814f"
},
{
"url": "https://git.kernel.org/stable/c/936658ec41c28c397ef390140e02d4c91ade92f0"
},
{
"url": "https://git.kernel.org/stable/c/8de65194a04d2552cd39b6c67d942d490f22d174"
},
{
"url": "https://git.kernel.org/stable/c/6160e756db81d6cb63e3e2952efcf6c5134be385"
},
{
"url": "https://git.kernel.org/stable/c/18d704bdd809377dfd81a3c2f42426763b5da227"
},
{
"url": "https://git.kernel.org/stable/c/4d6b9cac6df5e0cfef1a66b3edd7aebdb9e4b7e7"
},
{
"url": "https://git.kernel.org/stable/c/c9158ceaf27780ef64534ad72f44ffde3f8ccc49"
}
],
"title": "sctp: clear control chunk transport if it is being removed",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74688",
"datePublished": "2026-08-22T15:32:53.423Z",
"dateReserved": "2026-08-15T05:44:03.926Z",
"dateUpdated": "2026-08-25T05:41:32.712Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74549 (GCVE-0-2026-74549)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-19 16:38
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
hwmon: (nct6775-core) Prevent access to unsupported weight registers
Sashiko reports:
During initialization of the nct6116 chip, the driver sets data->pwm_num
to 5. However, it assigns several NCT6106 register arrays (such as
NCT6106_REG_WEIGHT_DUTY_STEP, NCT6106_REG_WEIGHT_TEMP_SEL, and
NCT6106_REG_WEIGHT_TEMP_*) to data->REG_PWM and data->REG_WEIGHT_TEMP.
These arrays only contain 3 elements.
In nct6775_update_pwm(), the driver iterates up to data->pwm_num. If
data->has_pwm has bits 3 or 4 set (which is structurally possible for
nct6116), the loop attempts to read elements at index 3 and 4 from these
3-element arrays. This results in a global out-of-bounds read, which can
be caught by KASAN.
Furthermore, the driver uses these garbage out-of-bounds values as
hardware register addresses for subsequent read and write operations. This
leads to invalid hardware register access, potentially causing hardware
misconfiguration or system crashes.
The underlying problem is that the chip does support up to five fan
control channels, but only the first three support weight control.
Fix the problem by extending the affected weight register arrays with
zeroed fields. The driver uses zeroed register addresses to determine
if a register is supported or not, and skips accesses for unsupported
registers.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 29c7cb485b321c024dedc168bcbb04451176b163 Version: 29c7cb485b321c024dedc168bcbb04451176b163 Version: 29c7cb485b321c024dedc168bcbb04451176b163 Version: 29c7cb485b321c024dedc168bcbb04451176b163 Version: 29c7cb485b321c024dedc168bcbb04451176b163 Version: 29c7cb485b321c024dedc168bcbb04451176b163 Version: 29c7cb485b321c024dedc168bcbb04451176b163 Version: 29c7cb485b321c024dedc168bcbb04451176b163 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/hwmon/nct6775-core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "0d11b2a10269ace29832f584d207ff3768f79dc5",
"status": "affected",
"version": "29c7cb485b321c024dedc168bcbb04451176b163",
"versionType": "git"
},
{
"lessThan": "4a77f1d72c6db04cbbfab0250292ac71fdea5f0a",
"status": "affected",
"version": "29c7cb485b321c024dedc168bcbb04451176b163",
"versionType": "git"
},
{
"lessThan": "513d847f7a95bbdbeaaf55fb942c38992587734f",
"status": "affected",
"version": "29c7cb485b321c024dedc168bcbb04451176b163",
"versionType": "git"
},
{
"lessThan": "25b528816f5d83be5236dc182692369e8c9402b0",
"status": "affected",
"version": "29c7cb485b321c024dedc168bcbb04451176b163",
"versionType": "git"
},
{
"lessThan": "689082a4cb166a7ae9729f7b12339e69fdad6c52",
"status": "affected",
"version": "29c7cb485b321c024dedc168bcbb04451176b163",
"versionType": "git"
},
{
"lessThan": "1b722740ac5c2b2070f9ba922f4e0f227faf0246",
"status": "affected",
"version": "29c7cb485b321c024dedc168bcbb04451176b163",
"versionType": "git"
},
{
"lessThan": "4ad2972ef0e1bd1018ad7a72661a4636ed7daecc",
"status": "affected",
"version": "29c7cb485b321c024dedc168bcbb04451176b163",
"versionType": "git"
},
{
"lessThan": "d0b704e569ac3b8416d8e02270cdc9bf830ed395",
"status": "affected",
"version": "29c7cb485b321c024dedc168bcbb04451176b163",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/hwmon/nct6775-core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.4"
},
{
"lessThan": "5.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "5.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (nct6775-core) Prevent access to unsupported weight registers\n\nSashiko reports:\n\nDuring initialization of the nct6116 chip, the driver sets data-\u003epwm_num\nto 5. However, it assigns several NCT6106 register arrays (such as\nNCT6106_REG_WEIGHT_DUTY_STEP, NCT6106_REG_WEIGHT_TEMP_SEL, and\nNCT6106_REG_WEIGHT_TEMP_*) to data-\u003eREG_PWM and data-\u003eREG_WEIGHT_TEMP.\nThese arrays only contain 3 elements.\n\nIn nct6775_update_pwm(), the driver iterates up to data-\u003epwm_num. If\ndata-\u003ehas_pwm has bits 3 or 4 set (which is structurally possible for\nnct6116), the loop attempts to read elements at index 3 and 4 from these\n3-element arrays. This results in a global out-of-bounds read, which can\nbe caught by KASAN.\n\nFurthermore, the driver uses these garbage out-of-bounds values as\nhardware register addresses for subsequent read and write operations. This\nleads to invalid hardware register access, potentially causing hardware\nmisconfiguration or system crashes.\n\nThe underlying problem is that the chip does support up to five fan\ncontrol channels, but only the first three support weight control.\nFix the problem by extending the affected weight register arrays with\nzeroed fields. The driver uses zeroed register addresses to determine\nif a register is supported or not, and skips accesses for unsupported\nregisters."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires local access to hwmon sysfs under /sys/class/hwmon/; any read or write of sensor attributes invokes nct6775_update_device() and reaches the vulnerable nct6775_update_pwm() path via the platform Super I/O driver.\nAC:L - On affected NCT6116 systems with PWM channels 4-5 enabled (has_pwm bits 3-4), triggering is reliable by reading or writing any exposed hwmon attribute; no race or special victim state is required beyond standard sysfs access.\nPR:L - Fan and PWM sysfs attributes are created with mode 0644 and the driver performs no capability or permission checks beyond standard file permissions, so any unprivileged local user can trigger the vulnerable update and store paths.\nUI:N - No victim interaction is required; the attacker directly reads or writes hwmon sysfs files to invoke nct6775_update_pwm() and associated store handlers without needing another user to perform any action.\nS:U - The vulnerability corrupts kernel driver state and on-chip Super I/O fan/thermal registers on the same host; it does not cross a VM, container, or IOMMU security boundary to impact a separate authority.\nC:H - Indexing past the three-element NCT6106 weight register arrays causes a global out-of-bounds read in kernel .rodata (KASAN-detectable), and the resulting bogus register addresses drive unintended hardware reads whose values are cached and returned through sysfs.\nI:H - Out-of-bounds indices supply valid but incorrect Super I/O register addresses (e.g. auto-temperature registers of other PWM channels) to nct6775_write_value() via writable 0644 sysfs stores, enabling cross-channel fan/thermal misconfiguration.\nA:H - Misdirected reads and writes to wrong Super I/O control registers can corrupt active fan/thermal management on industrial/embedded systems with five PWM channels, potentially causing kernel faults, thermal emergency shutdown, or sustained denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:38:42.442Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/0d11b2a10269ace29832f584d207ff3768f79dc5"
},
{
"url": "https://git.kernel.org/stable/c/4a77f1d72c6db04cbbfab0250292ac71fdea5f0a"
},
{
"url": "https://git.kernel.org/stable/c/513d847f7a95bbdbeaaf55fb942c38992587734f"
},
{
"url": "https://git.kernel.org/stable/c/25b528816f5d83be5236dc182692369e8c9402b0"
},
{
"url": "https://git.kernel.org/stable/c/689082a4cb166a7ae9729f7b12339e69fdad6c52"
},
{
"url": "https://git.kernel.org/stable/c/1b722740ac5c2b2070f9ba922f4e0f227faf0246"
},
{
"url": "https://git.kernel.org/stable/c/4ad2972ef0e1bd1018ad7a72661a4636ed7daecc"
},
{
"url": "https://git.kernel.org/stable/c/d0b704e569ac3b8416d8e02270cdc9bf830ed395"
}
],
"title": "hwmon: (nct6775-core) Prevent access to unsupported weight registers",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74549",
"datePublished": "2026-08-15T12:27:56.993Z",
"dateReserved": "2026-08-15T05:44:03.915Z",
"dateUpdated": "2026-08-19T16:38:42.442Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80906 (GCVE-0-2026-80906)
Vulnerability from cvelistv5
Published
2026-09-04 17:19
Modified
2026-09-04 17:19
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: packet: fix wrong transport_header when sending VLAN-tagged frame
In packet_parse_headers(), when processing a VLAN-tagged frame,
skb_set_network_header() is called to advance network_header past the
VLAN tag to the inner protocol header. skb_probe_transport_header() is
then called with skb->protocol still set to the outer VLAN EtherType
(e.g. ETH_P_8021Q), while nhoff (derived from skb_network_offset())
already points past the VLAN tag to the inner protocol header.
In __skb_flow_dissect(), proto is initialized to ETH_P_8021Q and nhoff
points past the VLAN tag. When the dissector hits case ETH_P_8021Q, it
reads a struct vlan_hdr at nhoff via __skb_header_pointer(), but that
offset contains the inner protocol header (e.g. an IP header). The bytes
are misinterpreted as a VLAN header, yielding a garbage encapsulated
EtherType that matches no known protocol. The dissector returns false,
so skb_probe_transport_header() never calls skb_set_transport_header(),
leaving transport_header at its uninitialized sentinel value (~0U).
Move skb_probe_transport_header() to before skb_set_network_header(). At
the time skb_probe_transport_header() is called, network_header still
points to the VLAN header, so nhoff correctly points to the VLAN header.
The flow dissector can then parse the VLAN header, extract the inner
EtherType, and advance nhoff to the inner protocol header, allowing
transport_header to be set correctly.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: c2137d565ceb505de69593c181a0543bc4083838 Version: 9ff46c36df2e0a1ac352f2f4038eaf3f0f7361b8 Version: dfed913e8b55a0c2c4906f1242fd38fd9a116e49 Version: dfed913e8b55a0c2c4906f1242fd38fd9a116e49 Version: dfed913e8b55a0c2c4906f1242fd38fd9a116e49 Version: dfed913e8b55a0c2c4906f1242fd38fd9a116e49 Version: dfed913e8b55a0c2c4906f1242fd38fd9a116e49 Version: dfed913e8b55a0c2c4906f1242fd38fd9a116e49 Version: ad3f90a9c4a2c74bb3711f2031bffda4ec44c849 Version: 5.10.163 ≤ Version: 5.15.87 ≤ Version: 5.4.229 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/packet/af_packet.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a4b82de96d465ddb44bc931145c0fa80c4fe9c9c",
"status": "affected",
"version": "c2137d565ceb505de69593c181a0543bc4083838",
"versionType": "git"
},
{
"lessThan": "fa86bc52ea8ba981f74f851fd61e2a3d3bc0feac",
"status": "affected",
"version": "9ff46c36df2e0a1ac352f2f4038eaf3f0f7361b8",
"versionType": "git"
},
{
"lessThan": "5479eb9b355f44745d7ccfe112386bd4f96eceea",
"status": "affected",
"version": "dfed913e8b55a0c2c4906f1242fd38fd9a116e49",
"versionType": "git"
},
{
"lessThan": "e451e20adb869a983a21dda158625f024142e61f",
"status": "affected",
"version": "dfed913e8b55a0c2c4906f1242fd38fd9a116e49",
"versionType": "git"
},
{
"lessThan": "6971cf319263d6a1b4096f9248aca9e57d77a1eb",
"status": "affected",
"version": "dfed913e8b55a0c2c4906f1242fd38fd9a116e49",
"versionType": "git"
},
{
"lessThan": "f9297abbcaba760b7a7b9d63b839f607f738013e",
"status": "affected",
"version": "dfed913e8b55a0c2c4906f1242fd38fd9a116e49",
"versionType": "git"
},
{
"lessThan": "6386a6ffa2efba2965ed8e4fa303582c0b76a215",
"status": "affected",
"version": "dfed913e8b55a0c2c4906f1242fd38fd9a116e49",
"versionType": "git"
},
{
"lessThan": "01fdecc0480d916c799dbee584833a4a37e94d06",
"status": "affected",
"version": "dfed913e8b55a0c2c4906f1242fd38fd9a116e49",
"versionType": "git"
},
{
"status": "affected",
"version": "ad3f90a9c4a2c74bb3711f2031bffda4ec44c849",
"versionType": "git"
},
{
"lessThan": "5.10.266",
"status": "affected",
"version": "5.10.163",
"versionType": "semver"
},
{
"lessThan": "5.15.217",
"status": "affected",
"version": "5.15.87",
"versionType": "semver"
},
{
"lessThan": "5.5",
"status": "affected",
"version": "5.4.229",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/packet/af_packet.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.19"
},
{
"lessThan": "5.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "5.10.163",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.15.87",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.46",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.10",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.4.229",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: packet: fix wrong transport_header when sending VLAN-tagged frame\n\nIn packet_parse_headers(), when processing a VLAN-tagged frame,\nskb_set_network_header() is called to advance network_header past the\nVLAN tag to the inner protocol header. skb_probe_transport_header() is\nthen called with skb-\u003eprotocol still set to the outer VLAN EtherType\n(e.g. ETH_P_8021Q), while nhoff (derived from skb_network_offset())\nalready points past the VLAN tag to the inner protocol header.\n\nIn __skb_flow_dissect(), proto is initialized to ETH_P_8021Q and nhoff\npoints past the VLAN tag. When the dissector hits case ETH_P_8021Q, it\nreads a struct vlan_hdr at nhoff via __skb_header_pointer(), but that\noffset contains the inner protocol header (e.g. an IP header). The bytes\nare misinterpreted as a VLAN header, yielding a garbage encapsulated\nEtherType that matches no known protocol. The dissector returns false,\nso skb_probe_transport_header() never calls skb_set_transport_header(),\nleaving transport_header at its uninitialized sentinel value (~0U).\n\nMove skb_probe_transport_header() to before skb_set_network_header(). At\nthe time skb_probe_transport_header() is called, network_header still\npoints to the VLAN header, so nhoff correctly points to the VLAN header.\nThe flow dissector can then parse the VLAN header, extract the inner\nEtherType, and advance nhoff to the inner protocol header, allowing\ntransport_header to be set correctly."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T17:19:16.531Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a4b82de96d465ddb44bc931145c0fa80c4fe9c9c"
},
{
"url": "https://git.kernel.org/stable/c/fa86bc52ea8ba981f74f851fd61e2a3d3bc0feac"
},
{
"url": "https://git.kernel.org/stable/c/5479eb9b355f44745d7ccfe112386bd4f96eceea"
},
{
"url": "https://git.kernel.org/stable/c/e451e20adb869a983a21dda158625f024142e61f"
},
{
"url": "https://git.kernel.org/stable/c/6971cf319263d6a1b4096f9248aca9e57d77a1eb"
},
{
"url": "https://git.kernel.org/stable/c/f9297abbcaba760b7a7b9d63b839f607f738013e"
},
{
"url": "https://git.kernel.org/stable/c/6386a6ffa2efba2965ed8e4fa303582c0b76a215"
},
{
"url": "https://git.kernel.org/stable/c/01fdecc0480d916c799dbee584833a4a37e94d06"
}
],
"title": "net: packet: fix wrong transport_header when sending VLAN-tagged frame",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80906",
"datePublished": "2026-09-04T17:19:16.531Z",
"dateReserved": "2026-08-26T14:34:25.800Z",
"dateUpdated": "2026-09-04T17:19:16.531Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80788 (GCVE-0-2026-80788)
Vulnerability from cvelistv5
Published
2026-09-04 15:12
Modified
2026-09-07 14:21
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
nvmet-tcp: Do not WARN on remotely-controlled oversized SGL allocations
When fuzzing the nvme target code, I tripped a kernel warning in
nvmet_tcp_map_data() because the length passed into the allocator is
controlled by the remote initiator.
A remote initiator that sends a command with an SGL claiming a huge
number, can create a scatterlist and iovec allocation of over 1 million
entries, which causes the backing kmalloc call to exceed MAX_PAGE_ORDER
and then the page allocator will trip on a WARN_ON_ONCE_GFP() message:
WARNING: mm/page_alloc.c:5280 __alloc_frozen_pages_noprof
Workqueue: nvmet_tcp_wq nvmet_tcp_io_work
...
sgl_alloc_order
nvmet_tcp_map_data
nvmet_tcp_try_recv_pdu
As it's never good to trip a kernel warning remotely due to many systems
having panic-on-warn enabled, let's silence it by just add GFP_NOWARN to
the allocation flags.
References
| URL | Tags | ||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 872d26a391da92ed8f0c0f5cb5fef428067b7f30 Version: 872d26a391da92ed8f0c0f5cb5fef428067b7f30 Version: 872d26a391da92ed8f0c0f5cb5fef428067b7f30 Version: 872d26a391da92ed8f0c0f5cb5fef428067b7f30 Version: 872d26a391da92ed8f0c0f5cb5fef428067b7f30 Version: 872d26a391da92ed8f0c0f5cb5fef428067b7f30 Version: 872d26a391da92ed8f0c0f5cb5fef428067b7f30 Version: 872d26a391da92ed8f0c0f5cb5fef428067b7f30 Version: 872d26a391da92ed8f0c0f5cb5fef428067b7f30 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/nvme/target/tcp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "8d01f0d0e96485e39ad89b859ef85e1dc3020465",
"status": "affected",
"version": "872d26a391da92ed8f0c0f5cb5fef428067b7f30",
"versionType": "git"
},
{
"lessThan": "7b6a54d4e7b0da423c2b53ed293fd36b16c0b19e",
"status": "affected",
"version": "872d26a391da92ed8f0c0f5cb5fef428067b7f30",
"versionType": "git"
},
{
"lessThan": "e7077e6c45423dd2bb7de7b5fc4b018a8e6c4741",
"status": "affected",
"version": "872d26a391da92ed8f0c0f5cb5fef428067b7f30",
"versionType": "git"
},
{
"lessThan": "86cc450022473c4a29b43a09f3ec22a9ef566dac",
"status": "affected",
"version": "872d26a391da92ed8f0c0f5cb5fef428067b7f30",
"versionType": "git"
},
{
"lessThan": "c509f20be1cabda3087810bb2d658d66b3f31f35",
"status": "affected",
"version": "872d26a391da92ed8f0c0f5cb5fef428067b7f30",
"versionType": "git"
},
{
"lessThan": "9c95f7e66c62ee6c6abedcf1c04311f430ff5833",
"status": "affected",
"version": "872d26a391da92ed8f0c0f5cb5fef428067b7f30",
"versionType": "git"
},
{
"lessThan": "7fd6da0f28932442b51658bac4ff55565ca9b377",
"status": "affected",
"version": "872d26a391da92ed8f0c0f5cb5fef428067b7f30",
"versionType": "git"
},
{
"lessThan": "9b770e40bc00381e5ebf53653de5776773415be3",
"status": "affected",
"version": "872d26a391da92ed8f0c0f5cb5fef428067b7f30",
"versionType": "git"
},
{
"lessThan": "737a3b535247226f6e1a7988fd9d6e63e7d6fc71",
"status": "affected",
"version": "872d26a391da92ed8f0c0f5cb5fef428067b7f30",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/nvme/target/tcp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.0"
},
{
"lessThan": "5.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.267",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.218",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.185",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.154",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.106",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.47",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.1",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.267",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.218",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.185",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.154",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.106",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.47",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.11",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.1",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "5.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet-tcp: Do not WARN on remotely-controlled oversized SGL allocations\n\nWhen fuzzing the nvme target code, I tripped a kernel warning in\nnvmet_tcp_map_data() because the length passed into the allocator is\ncontrolled by the remote initiator.\n\nA remote initiator that sends a command with an SGL claiming a huge\nnumber, can create a scatterlist and iovec allocation of over 1 million\nentries, which causes the backing kmalloc call to exceed MAX_PAGE_ORDER\nand then the page allocator will trip on a WARN_ON_ONCE_GFP() message:\n\n WARNING: mm/page_alloc.c:5280 __alloc_frozen_pages_noprof\n Workqueue: nvmet_tcp_wq nvmet_tcp_io_work\n ...\n sgl_alloc_order\n nvmet_tcp_map_data\n nvmet_tcp_try_recv_pdu\n\nAs it\u0027s never good to trip a kernel warning remotely due to many systems\nhaving panic-on-warn enabled, let\u0027s silence it by just add GFP_NOWARN to\nthe allocation flags."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-07T14:21:13.376Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/8d01f0d0e96485e39ad89b859ef85e1dc3020465"
},
{
"url": "https://git.kernel.org/stable/c/7b6a54d4e7b0da423c2b53ed293fd36b16c0b19e"
},
{
"url": "https://git.kernel.org/stable/c/e7077e6c45423dd2bb7de7b5fc4b018a8e6c4741"
},
{
"url": "https://git.kernel.org/stable/c/86cc450022473c4a29b43a09f3ec22a9ef566dac"
},
{
"url": "https://git.kernel.org/stable/c/c509f20be1cabda3087810bb2d658d66b3f31f35"
},
{
"url": "https://git.kernel.org/stable/c/9c95f7e66c62ee6c6abedcf1c04311f430ff5833"
},
{
"url": "https://git.kernel.org/stable/c/7fd6da0f28932442b51658bac4ff55565ca9b377"
},
{
"url": "https://git.kernel.org/stable/c/9b770e40bc00381e5ebf53653de5776773415be3"
},
{
"url": "https://git.kernel.org/stable/c/737a3b535247226f6e1a7988fd9d6e63e7d6fc71"
}
],
"title": "nvmet-tcp: Do not WARN on remotely-controlled oversized SGL allocations",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80788",
"datePublished": "2026-09-04T15:12:59.912Z",
"dateReserved": "2026-08-26T14:34:25.793Z",
"dateUpdated": "2026-09-07T14:21:13.376Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68302 (GCVE-0-2026-68302)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-19 16:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
amt: re-read skb header pointers after every pull
Several AMT receive and transmit paths cache a pointer into the skb head
(ip_hdr(), ipv6_hdr(), eth_hdr() or the AMT message header) and then call
a helper that can reallocate that head before the cached pointer is used
again. pskb_may_pull(), ip_mc_may_pull(), ipv6_mc_may_pull(),
iptunnel_pull_header(), ip_mc_check_igmp() and ipv6_mc_check_mld() can all
free the old head and move the data, so a pointer taken before the call
dangles afterwards and the later access is a use-after-free of the freed
head.
The affected sites are:
amt_rcv() caches ip_hdr() before amt_parse_type() pulls, then reads
iph->saddr.
amt_dev_xmit() caches ip_hdr()/ipv6_hdr() before ip_mc_check_igmp()/
ipv6_mc_check_mld() and pskb_may_pull(), then reads the group address.
amt_multicast_data_handler() caches eth_hdr() before pskb_may_pull(),
then writes the L2 header.
amt_membership_query_handler() caches the AMT header, the outer and
inner eth_hdr() and ip_hdr() before iptunnel_pull_header() and several
pulls, then reads and writes them.
amt_igmpv3_report_handler() and amt_mldv2_report_handler() cache
ip_hdr()/ipv6_hdr() and the current group record and read the record
count from the report header inside the record loop, across the
*_mc_may_pull() calls.
amt_update_handler() caches ip_hdr() and the AMT membership-update
header before pskb_may_pull(), iptunnel_pull_header(),
ip_mc_check_igmp() and the report handler, then reads iph->daddr and
amtmu->nonce / amtmu->response_mac.
Fix each site by either snapshotting the scalar that is used after the
pull before the first pull runs, or re-deriving the header pointer from
the skb after the last pull that can move the head. Values that are
stable across the pull (source and group address, the response MAC and
nonce, the record count, the outer source MAC) are snapshotted; pointers
that are written through or read repeatedly are re-derived.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: cbc21dc1cfe949e37b2a54c71511579f1899e8d4 Version: cbc21dc1cfe949e37b2a54c71511579f1899e8d4 Version: cbc21dc1cfe949e37b2a54c71511579f1899e8d4 Version: cbc21dc1cfe949e37b2a54c71511579f1899e8d4 Version: cbc21dc1cfe949e37b2a54c71511579f1899e8d4 Version: cbc21dc1cfe949e37b2a54c71511579f1899e8d4 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/amt.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "37ff890f9c18dfbcf57e17199901d4fd1e4c174e",
"status": "affected",
"version": "cbc21dc1cfe949e37b2a54c71511579f1899e8d4",
"versionType": "git"
},
{
"lessThan": "9005b221cb1f9c3c1a2ef656fb0e8fa80c0a187e",
"status": "affected",
"version": "cbc21dc1cfe949e37b2a54c71511579f1899e8d4",
"versionType": "git"
},
{
"lessThan": "7746d588d42a4ac0117b68ed8e9b22a9da53dfb7",
"status": "affected",
"version": "cbc21dc1cfe949e37b2a54c71511579f1899e8d4",
"versionType": "git"
},
{
"lessThan": "ca0e8b661957f777591efe874cd9d9a63619cd99",
"status": "affected",
"version": "cbc21dc1cfe949e37b2a54c71511579f1899e8d4",
"versionType": "git"
},
{
"lessThan": "7f48e3ddad8e97545b25788b8203b3a539df1621",
"status": "affected",
"version": "cbc21dc1cfe949e37b2a54c71511579f1899e8d4",
"versionType": "git"
},
{
"lessThan": "3656a79f94c471827a08f2cacce5f94ad5e52c24",
"status": "affected",
"version": "cbc21dc1cfe949e37b2a54c71511579f1899e8d4",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/amt.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.16"
},
{
"lessThan": "5.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.16",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\namt: re-read skb header pointers after every pull\n\nSeveral AMT receive and transmit paths cache a pointer into the skb head\n(ip_hdr(), ipv6_hdr(), eth_hdr() or the AMT message header) and then call\na helper that can reallocate that head before the cached pointer is used\nagain. pskb_may_pull(), ip_mc_may_pull(), ipv6_mc_may_pull(),\niptunnel_pull_header(), ip_mc_check_igmp() and ipv6_mc_check_mld() can all\nfree the old head and move the data, so a pointer taken before the call\ndangles afterwards and the later access is a use-after-free of the freed\nhead.\n\nThe affected sites are:\n\n amt_rcv() caches ip_hdr() before amt_parse_type() pulls, then reads\n iph-\u003esaddr.\n\n amt_dev_xmit() caches ip_hdr()/ipv6_hdr() before ip_mc_check_igmp()/\n ipv6_mc_check_mld() and pskb_may_pull(), then reads the group address.\n\n amt_multicast_data_handler() caches eth_hdr() before pskb_may_pull(),\n then writes the L2 header.\n\n amt_membership_query_handler() caches the AMT header, the outer and\n inner eth_hdr() and ip_hdr() before iptunnel_pull_header() and several\n pulls, then reads and writes them.\n\n amt_igmpv3_report_handler() and amt_mldv2_report_handler() cache\n ip_hdr()/ipv6_hdr() and the current group record and read the record\n count from the report header inside the record loop, across the\n *_mc_may_pull() calls.\n\n amt_update_handler() caches ip_hdr() and the AMT membership-update\n header before pskb_may_pull(), iptunnel_pull_header(),\n ip_mc_check_igmp() and the report handler, then reads iph-\u003edaddr and\n amtmu-\u003enonce / amtmu-\u003eresponse_mac.\n\nFix each site by either snapshotting the scalar that is used after the\npull before the first pull runs, or re-deriving the header pointer from\nthe skb after the last pull that can move the head. Values that are\nstable across the pull (source and group address, the response MAC and\nnonce, the record count, the outer source MAC) are snapshotted; pointers\nthat are written through or read repeatedly are re-derived."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - AMT is a routable UDP tunnel (port 2268); all affected handlers run from amt_rcv(), the UDP encap receive callback, on packets from arbitrary remote hosts across the internet. No same-segment requirement exists.\nAC:L - The attacker chooses the packet sizes and fragmentation that make the skb non-linear or cloned, so the pskb_may_pull()/iptunnel_pull_header()/ip_mc_check_igmp() calls deterministically reallocate the skb head and strand the cached pointers; no race or uncontrollable state is involved.\nPR:N - AMT has no authentication: amt_request_handler() creates a tunnel for any source IP and returns the nonce/response MAC to the sender, so an unauthenticated remote host can complete the handshake and then reach the vulnerable update/report paths; gateway paths need only a spoofed relay source address.\nUI:N - Exploitation is entirely driven by inbound UDP packets processed in softirq context; no local user action or interaction is required on the target relay or gateway.\nS:U - The use-after-free corrupts kernel heap memory within the same kernel security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - Stale header pointers are read after the head is freed, so freed heap contents are consumed as source/group addresses and record counts, and are copied into the destination MAC of frames delivered up the stack, leaking reallocated kernel memory to the attacker; UAF reads generally enable broader disclosure.\nI:H - amt_multicast_data_handler() and amt_membership_query_handler() write through the dangling pointers (eth-\u003eh_proto, ip_eth_mc_map()/ipv6_eth_mc_map() into eth-\u003eh_dest, ether_addr_copy of h_source), giving an attacker-influenced heap write into freed and likely reallocated memory, a classic control-flow hijack primitive.\nA:H - Use-after-free reads and writes on a freed skb head corrupt the slab and readily cause KASAN splats, oopses, or kernel panic, and the packets triggering it can be sent repeatedly by an unauthenticated remote attacker."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:32:55.916Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/37ff890f9c18dfbcf57e17199901d4fd1e4c174e"
},
{
"url": "https://git.kernel.org/stable/c/9005b221cb1f9c3c1a2ef656fb0e8fa80c0a187e"
},
{
"url": "https://git.kernel.org/stable/c/7746d588d42a4ac0117b68ed8e9b22a9da53dfb7"
},
{
"url": "https://git.kernel.org/stable/c/ca0e8b661957f777591efe874cd9d9a63619cd99"
},
{
"url": "https://git.kernel.org/stable/c/7f48e3ddad8e97545b25788b8203b3a539df1621"
},
{
"url": "https://git.kernel.org/stable/c/3656a79f94c471827a08f2cacce5f94ad5e52c24"
}
],
"title": "amt: re-read skb header pointers after every pull",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68302",
"datePublished": "2026-08-10T12:02:36.313Z",
"dateReserved": "2026-07-30T09:28:09.381Z",
"dateUpdated": "2026-08-19T16:32:55.916Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80567 (GCVE-0-2026-80567)
Vulnerability from cvelistv5
Published
2026-08-26 14:37
Modified
2026-08-26 14:37
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Input: synaptics-rmi4 - propagate F54 worker errors to V4L2 queue
Previously, rmi_f54_buffer_queue() waited for the worker thread to
finish but ignored whether it succeeded. If the worker failed (e.g.,
due to a timeout or register read failure), the queue thread would
silently return success, delivering stale or uninitialized memory to
userspace.
Add a 'report_error' field to struct f54_data to store the worker's exit
status. Check this field in rmi_f54_buffer_queue() after the worker
finishes, and mark the buffer as VB2_BUF_STATE_ERROR if an error
occurred.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d Version: 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d Version: 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d Version: 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d Version: 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d Version: 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d Version: 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d Version: 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/input/rmi4/rmi_f54.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "305c24ee25b6e08ac9f4c5f697e823cc638c38da",
"status": "affected",
"version": "3a762dbd5347514c3cb2ac756a92a3d1c7646a2d",
"versionType": "git"
},
{
"lessThan": "7d33b752e0df385b285492b74699fc73b6becdfb",
"status": "affected",
"version": "3a762dbd5347514c3cb2ac756a92a3d1c7646a2d",
"versionType": "git"
},
{
"lessThan": "be56730b547737151f24357d832b04aaa93755d5",
"status": "affected",
"version": "3a762dbd5347514c3cb2ac756a92a3d1c7646a2d",
"versionType": "git"
},
{
"lessThan": "2b0403fb7e28f65883cd03814b62c9aa9bc7f04d",
"status": "affected",
"version": "3a762dbd5347514c3cb2ac756a92a3d1c7646a2d",
"versionType": "git"
},
{
"lessThan": "6741a8c21d98088b7f2d9f4f86a706d311ce34a2",
"status": "affected",
"version": "3a762dbd5347514c3cb2ac756a92a3d1c7646a2d",
"versionType": "git"
},
{
"lessThan": "70f9aad3943559af6f32cb303744f35c05ce9cf1",
"status": "affected",
"version": "3a762dbd5347514c3cb2ac756a92a3d1c7646a2d",
"versionType": "git"
},
{
"lessThan": "9bbd3682f8a3e064271547133c37fcb17668d860",
"status": "affected",
"version": "3a762dbd5347514c3cb2ac756a92a3d1c7646a2d",
"versionType": "git"
},
{
"lessThan": "8786d74bf50e6797b6f655eb381ef6b25451161f",
"status": "affected",
"version": "3a762dbd5347514c3cb2ac756a92a3d1c7646a2d",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/input/rmi4/rmi_f54.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.9"
},
{
"lessThan": "4.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.46",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.10",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nInput: synaptics-rmi4 - propagate F54 worker errors to V4L2 queue\n\nPreviously, rmi_f54_buffer_queue() waited for the worker thread to\nfinish but ignored whether it succeeded. If the worker failed (e.g.,\ndue to a timeout or register read failure), the queue thread would\nsilently return success, delivering stale or uninitialized memory to\nuserspace.\n\nAdd a \u0027report_error\u0027 field to struct f54_data to store the worker\u0027s exit\nstatus. Check this field in rmi_f54_buffer_queue() after the worker\nfinishes, and mark the buffer as VB2_BUF_STATE_ERROR if an error\noccurred."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-26T14:37:30.152Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/305c24ee25b6e08ac9f4c5f697e823cc638c38da"
},
{
"url": "https://git.kernel.org/stable/c/7d33b752e0df385b285492b74699fc73b6becdfb"
},
{
"url": "https://git.kernel.org/stable/c/be56730b547737151f24357d832b04aaa93755d5"
},
{
"url": "https://git.kernel.org/stable/c/2b0403fb7e28f65883cd03814b62c9aa9bc7f04d"
},
{
"url": "https://git.kernel.org/stable/c/6741a8c21d98088b7f2d9f4f86a706d311ce34a2"
},
{
"url": "https://git.kernel.org/stable/c/70f9aad3943559af6f32cb303744f35c05ce9cf1"
},
{
"url": "https://git.kernel.org/stable/c/9bbd3682f8a3e064271547133c37fcb17668d860"
},
{
"url": "https://git.kernel.org/stable/c/8786d74bf50e6797b6f655eb381ef6b25451161f"
}
],
"title": "Input: synaptics-rmi4 - propagate F54 worker errors to V4L2 queue",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80567",
"datePublished": "2026-08-26T14:37:30.152Z",
"dateReserved": "2026-08-26T14:34:25.768Z",
"dateUpdated": "2026-08-26T14:37:30.152Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68093 (GCVE-0-2026-68093)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-19 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after hotplug
If a vCPU stays scheduled out (or blocked) while the last pCPU it ran
on goes through a hotplug cycle (online->offline->online), and the vCPU
then resumes execution on the same pCPU, then it is possible for it to
run with an ASID that has now been assigned to a different vCPU,
resulting in stale TLB translations being used.
svm_enable_virtualization_cpu() resets asid_generation to 1 and sets
next_asid to max_asid + 1 on every CPU online event, including hotplug
cycles. Because next_asid starts beyond the pool boundary, the first
call to new_asid() after an online event always wraps the pool,
incrementing asid_generation to 2 and assigning ASIDs starting from
min_asid.
Consider two vCPUs from different VMs, vCPU-A pinned to CPU-X holding
asid_generation=2 and ASID=N from before the hotplug event:
1. CPU-X goes offline and back online: asid_generation resets to 1,
next_asid = max_asid + 1.
2. One or more vCPUs migrate to CPU-X and call new_asid(), wrapping
the pool and consuming ASIDs starting from min_asid. Eventually
vCPU-B from a different VM is assigned asid_generation=2, ASID=N
— the same ASID that vCPU-A held before the hotplug.
3. vCPU-A enters pre_svm_run() on CPU-X: current_vmcb->cpu is
unchanged so the migration branch is skipped. Its saved
asid_generation=2 matches sd->asid_generation=2, so the generation
check silently passes and vCPU-A continues running with ASID=N —
the same ASID just freshly assigned to vCPU-B.
Both vCPUs from different VMs now run on CPU-X with the same ASID,
causing them to share NPT TLB entries and producing stale translations.
The collision manifests as a KVM internal error (Suberror: 1, emulation
failure). The NPT page fault reports a faulting GPA far outside the
VM's physical memory range — a sign of stale TLB translations being
used. KVM falls back to instruction emulation, which fails on
FPU/XSave instructions (XRSTOR, STMXCSR) that the emulator does not
implement.
Fix this by incrementing asid_generation instead of resetting it to 1
in svm_enable_virtualization_cpu(). On module load, asid_generation
starts at 0 (memset) and the increment produces 1, identical to the
old behaviour. On subsequent hotplug cycles the generation advances
beyond any value a vCPU previously observed on this CPU, so the
generation check in pre_svm_run() reliably forces new_asid() on every
vCPU after every hotplug cycle.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 774c47f1d78e373a6bd2964f4e278d1ce26c21cb Version: 774c47f1d78e373a6bd2964f4e278d1ce26c21cb Version: 774c47f1d78e373a6bd2964f4e278d1ce26c21cb Version: 774c47f1d78e373a6bd2964f4e278d1ce26c21cb Version: 774c47f1d78e373a6bd2964f4e278d1ce26c21cb Version: 774c47f1d78e373a6bd2964f4e278d1ce26c21cb |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"arch/x86/kvm/svm/svm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "2028b81321dc757b6875b99c10d908e349c141e2",
"status": "affected",
"version": "774c47f1d78e373a6bd2964f4e278d1ce26c21cb",
"versionType": "git"
},
{
"lessThan": "60283726f2845bd78b95efbd0e50b93944780477",
"status": "affected",
"version": "774c47f1d78e373a6bd2964f4e278d1ce26c21cb",
"versionType": "git"
},
{
"lessThan": "7508916b4b55d6f5ecc68cd09774dabd3a6b4440",
"status": "affected",
"version": "774c47f1d78e373a6bd2964f4e278d1ce26c21cb",
"versionType": "git"
},
{
"lessThan": "0f33b1c457c2199ed130b92cc2ff363a3f7b9415",
"status": "affected",
"version": "774c47f1d78e373a6bd2964f4e278d1ce26c21cb",
"versionType": "git"
},
{
"lessThan": "6b542d116acecb83a1ca34e8eace304cff6a4ec9",
"status": "affected",
"version": "774c47f1d78e373a6bd2964f4e278d1ce26c21cb",
"versionType": "git"
},
{
"lessThan": "25f744ffa0c8e799e06250ce2e618367b166b0d4",
"status": "affected",
"version": "774c47f1d78e373a6bd2964f4e278d1ce26c21cb",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"arch/x86/kvm/svm/svm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.21"
},
{
"lessThan": "2.6.21",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.21",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.21",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.21",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.21",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.21",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.21",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after hotplug\n\nIf a vCPU stays scheduled out (or blocked) while the last pCPU it ran\non goes through a hotplug cycle (online-\u003eoffline-\u003eonline), and the vCPU\nthen resumes execution on the same pCPU, then it is possible for it to\nrun with an ASID that has now been assigned to a different vCPU,\nresulting in stale TLB translations being used.\n\nsvm_enable_virtualization_cpu() resets asid_generation to 1 and sets\nnext_asid to max_asid + 1 on every CPU online event, including hotplug\ncycles. Because next_asid starts beyond the pool boundary, the first\ncall to new_asid() after an online event always wraps the pool,\nincrementing asid_generation to 2 and assigning ASIDs starting from\nmin_asid.\n\nConsider two vCPUs from different VMs, vCPU-A pinned to CPU-X holding\nasid_generation=2 and ASID=N from before the hotplug event:\n\n 1. CPU-X goes offline and back online: asid_generation resets to 1,\n next_asid = max_asid + 1.\n\n 2. One or more vCPUs migrate to CPU-X and call new_asid(), wrapping\n the pool and consuming ASIDs starting from min_asid. Eventually\n vCPU-B from a different VM is assigned asid_generation=2, ASID=N\n \u2014 the same ASID that vCPU-A held before the hotplug.\n\n 3. vCPU-A enters pre_svm_run() on CPU-X: current_vmcb-\u003ecpu is\n unchanged so the migration branch is skipped. Its saved\n asid_generation=2 matches sd-\u003easid_generation=2, so the generation\n check silently passes and vCPU-A continues running with ASID=N \u2014\n the same ASID just freshly assigned to vCPU-B.\n\nBoth vCPUs from different VMs now run on CPU-X with the same ASID,\ncausing them to share NPT TLB entries and producing stale translations.\n\nThe collision manifests as a KVM internal error (Suberror: 1, emulation\nfailure). The NPT page fault reports a faulting GPA far outside the\nVM\u0027s physical memory range \u2014 a sign of stale TLB translations being\nused. KVM falls back to instruction emulation, which fails on\nFPU/XSave instructions (XRSTOR, STMXCSR) that the emulator does not\nimplement.\n\nFix this by incrementing asid_generation instead of resetting it to 1\nin svm_enable_virtualization_cpu(). On module load, asid_generation\nstarts at 0 (memset) and the increment produces 1, identical to the\nold behaviour. On subsequent hotplug cycles the generation advances\nbeyond any value a vCPU previously observed on this CPU, so the\ngeneration check in pre_svm_run() reliably forces new_asid() on every\nvCPU after every hotplug cycle."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:29:15.060Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/2028b81321dc757b6875b99c10d908e349c141e2"
},
{
"url": "https://git.kernel.org/stable/c/60283726f2845bd78b95efbd0e50b93944780477"
},
{
"url": "https://git.kernel.org/stable/c/7508916b4b55d6f5ecc68cd09774dabd3a6b4440"
},
{
"url": "https://git.kernel.org/stable/c/0f33b1c457c2199ed130b92cc2ff363a3f7b9415"
},
{
"url": "https://git.kernel.org/stable/c/6b542d116acecb83a1ca34e8eace304cff6a4ec9"
},
{
"url": "https://git.kernel.org/stable/c/25f744ffa0c8e799e06250ce2e618367b166b0d4"
}
],
"title": "KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after hotplug",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68093",
"datePublished": "2026-08-10T11:58:05.933Z",
"dateReserved": "2026-07-30T09:28:09.367Z",
"dateUpdated": "2026-08-19T16:29:15.060Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68132 (GCVE-0-2026-68132)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-23 12:45
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
super: fix emergency thaw deadlock on frozen block devices
do_thaw_all_callback() calls bdev_thaw() while holding sb->s_umount
exclusively. If the block device was frozen via bdev_freeze() dropping
the last block layer freeze reference calls fs_bdev_thaw() which
reacquires s_umount:
do_thaw_all_callback(sb)
super_lock_excl(sb) # holds sb->s_umount
bdev_thaw(sb->s_bdev)
mutex_lock(&bdev->bd_fsfreeze_mutex)
# bd_fsfreeze_count drops 1 -> 0
bd_holder_ops->thaw == fs_bdev_thaw
get_bdev_super(bdev)
bdev_super_lock(bdev, true)
super_lock(sb, true)
down_write(&sb->s_umount) # same task: deadlock
The emergency thaw worker deadlocks against itself holding both
s_umount and bd_fsfreeze_mutex. That fscks any subsequent unmount,
freeze, or thaw of that filesystem and block device.
[ 81.878470] sysrq: Show Blocked State
[ 81.880140] task:kworker/0:1 state:D stack:0 pid:11 tgid:11 ppid:2 task_flags:0x4208060 flags:0x00080000
[ 81.884876] Workqueue: events do_thaw_all
[ 81.886656] Call Trace:
[ 81.887759] <TASK>
[ 81.888763] __schedule+0x579/0x1420
[ 81.890372] schedule+0x3a/0x100
[ 81.891794] schedule_preempt_disabled+0x15/0x30
[ 81.893848] rwsem_down_write_slowpath+0x1ea/0x900
[ 81.895191] ? __pfx_do_thaw_all_callback+0x10/0x10
[ 81.896528] down_write+0xbd/0xc0
[ 81.897505] super_lock+0x91/0x180
[ 81.898457] ? __mutex_lock+0xa99/0x1140
[ 81.900748] ? __mutex_unlock_slowpath+0x1f/0x400
[ 81.902069] bdev_super_lock+0x5b/0x150
[ 81.903132] get_bdev_super+0x10/0x60
[ 81.904042] fs_bdev_thaw+0x23/0xf0
[ 81.904755] bdev_thaw+0x82/0x100
[ 81.905484] do_thaw_all_callback+0x2c/0x50
[ 81.906298] __iterate_supers+0x5d/0x130
[ 81.907067] do_thaw_all+0x20/0x40
[ 81.907739] process_one_work+0x206/0x5e0
[ 81.908545] worker_thread+0x1e2/0x3c0
[ 81.909339] ? __pfx_worker_thread+0x10/0x10
[ 81.910171] kthread+0xf4/0x130
[ 81.910799] ? __pfx_kthread+0x10/0x10
[ 81.911528] ret_from_fork+0x2e2/0x3b0
[ 81.912259] ? __pfx_kthread+0x10/0x10
[ 81.913010] ret_from_fork_asm+0x1a/0x30
[ 81.913806] </TASK>
bdev_super_lock() even documents the violated requirement with
lockdep_assert_not_held(&sb->s_umount).
Acquiring bd_fsfreeze_mutex under s_umount also inverts the
bd_fsfreeze_mutex vs. s_umount ordering established by
bdev_{freeze,thaw}() and can thus ABBA against a concurrent block-layer
freeze even when the recursive path isn't hit.
Fix this by not holding s_umount around the bdev_thaw() loop at all. Pin
the superblock with an active reference instead as
filesystems_freeze_callback() does. The active reference keeps the
superblock from being shut down and so ->s_bdev stays valid without
holding s_umount. The block-layer-held freeze is dropped by
fs_bdev_thaw() with FREEZE_MAY_NEST | FREEZE_HOLDER_USERSPACE exactly as
a regular unfreeze would and thaw_super_locked() handles
filesystem-level freezes as before.
The emergency thaw path has deadlocked like this in one form or
another for a long long time but the current exclusively-held
shape dates back to commit [1] where thaw_bdev() already ended in
thaw_super() with s_umount held by do_thaw_all_callback().
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 08fdc8a0138afaf324296a342f32ad26ec465e43 Version: 08fdc8a0138afaf324296a342f32ad26ec465e43 Version: 08fdc8a0138afaf324296a342f32ad26ec465e43 Version: 08fdc8a0138afaf324296a342f32ad26ec465e43 Version: 08fdc8a0138afaf324296a342f32ad26ec465e43 Version: 08fdc8a0138afaf324296a342f32ad26ec465e43 Version: 08fdc8a0138afaf324296a342f32ad26ec465e43 Version: 08fdc8a0138afaf324296a342f32ad26ec465e43 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/super.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "96248aeddde794227a49af1a332a1e21b3c15d56",
"status": "affected",
"version": "08fdc8a0138afaf324296a342f32ad26ec465e43",
"versionType": "git"
},
{
"lessThan": "c202aa03388fd1889b7aa4f7d677c49e22cd9700",
"status": "affected",
"version": "08fdc8a0138afaf324296a342f32ad26ec465e43",
"versionType": "git"
},
{
"lessThan": "2a1127c1c58b4f15a93f2fd56ff7c2c3d611d5c5",
"status": "affected",
"version": "08fdc8a0138afaf324296a342f32ad26ec465e43",
"versionType": "git"
},
{
"lessThan": "05536cad35f27b520d4b6f0e57c8cc5bfb6b0502",
"status": "affected",
"version": "08fdc8a0138afaf324296a342f32ad26ec465e43",
"versionType": "git"
},
{
"lessThan": "99719b5da9320ed344daee87d9c73d321a98f252",
"status": "affected",
"version": "08fdc8a0138afaf324296a342f32ad26ec465e43",
"versionType": "git"
},
{
"lessThan": "63d78b546eefc38ad9898dc839bfc94811ede547",
"status": "affected",
"version": "08fdc8a0138afaf324296a342f32ad26ec465e43",
"versionType": "git"
},
{
"lessThan": "4c483644d1a7709efe7d1be7dbf88cf4008a7864",
"status": "affected",
"version": "08fdc8a0138afaf324296a342f32ad26ec465e43",
"versionType": "git"
},
{
"lessThan": "749d7aa0377aae32af8c0a4ad43371e7bf830ab5",
"status": "affected",
"version": "08fdc8a0138afaf324296a342f32ad26ec465e43",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/super.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.17"
},
{
"lessThan": "4.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.17",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsuper: fix emergency thaw deadlock on frozen block devices\n\ndo_thaw_all_callback() calls bdev_thaw() while holding sb-\u003es_umount\nexclusively. If the block device was frozen via bdev_freeze() dropping\nthe last block layer freeze reference calls fs_bdev_thaw() which\nreacquires s_umount:\n\n do_thaw_all_callback(sb)\n super_lock_excl(sb) # holds sb-\u003es_umount\n bdev_thaw(sb-\u003es_bdev)\n mutex_lock(\u0026bdev-\u003ebd_fsfreeze_mutex)\n # bd_fsfreeze_count drops 1 -\u003e 0\n bd_holder_ops-\u003ethaw == fs_bdev_thaw\n get_bdev_super(bdev)\n bdev_super_lock(bdev, true)\n super_lock(sb, true)\n down_write(\u0026sb-\u003es_umount) # same task: deadlock\n\nThe emergency thaw worker deadlocks against itself holding both\ns_umount and bd_fsfreeze_mutex. That fscks any subsequent unmount,\nfreeze, or thaw of that filesystem and block device.\n\n [ 81.878470] sysrq: Show Blocked State\n [ 81.880140] task:kworker/0:1 state:D stack:0 pid:11 tgid:11 ppid:2 task_flags:0x4208060 flags:0x00080000\n [ 81.884876] Workqueue: events do_thaw_all\n [ 81.886656] Call Trace:\n [ 81.887759] \u003cTASK\u003e\n [ 81.888763] __schedule+0x579/0x1420\n [ 81.890372] schedule+0x3a/0x100\n [ 81.891794] schedule_preempt_disabled+0x15/0x30\n [ 81.893848] rwsem_down_write_slowpath+0x1ea/0x900\n [ 81.895191] ? __pfx_do_thaw_all_callback+0x10/0x10\n [ 81.896528] down_write+0xbd/0xc0\n [ 81.897505] super_lock+0x91/0x180\n [ 81.898457] ? __mutex_lock+0xa99/0x1140\n [ 81.900748] ? __mutex_unlock_slowpath+0x1f/0x400\n [ 81.902069] bdev_super_lock+0x5b/0x150\n [ 81.903132] get_bdev_super+0x10/0x60\n [ 81.904042] fs_bdev_thaw+0x23/0xf0\n [ 81.904755] bdev_thaw+0x82/0x100\n [ 81.905484] do_thaw_all_callback+0x2c/0x50\n [ 81.906298] __iterate_supers+0x5d/0x130\n [ 81.907067] do_thaw_all+0x20/0x40\n [ 81.907739] process_one_work+0x206/0x5e0\n [ 81.908545] worker_thread+0x1e2/0x3c0\n [ 81.909339] ? __pfx_worker_thread+0x10/0x10\n [ 81.910171] kthread+0xf4/0x130\n [ 81.910799] ? __pfx_kthread+0x10/0x10\n [ 81.911528] ret_from_fork+0x2e2/0x3b0\n [ 81.912259] ? __pfx_kthread+0x10/0x10\n [ 81.913010] ret_from_fork_asm+0x1a/0x30\n [ 81.913806] \u003c/TASK\u003e\n\nbdev_super_lock() even documents the violated requirement with\nlockdep_assert_not_held(\u0026sb-\u003es_umount).\n\nAcquiring bd_fsfreeze_mutex under s_umount also inverts the\nbd_fsfreeze_mutex vs. s_umount ordering established by\nbdev_{freeze,thaw}() and can thus ABBA against a concurrent block-layer\nfreeze even when the recursive path isn\u0027t hit.\n\nFix this by not holding s_umount around the bdev_thaw() loop at all. Pin\nthe superblock with an active reference instead as\nfilesystems_freeze_callback() does. The active reference keeps the\nsuperblock from being shut down and so -\u003es_bdev stays valid without\nholding s_umount. The block-layer-held freeze is dropped by\nfs_bdev_thaw() with FREEZE_MAY_NEST | FREEZE_HOLDER_USERSPACE exactly as\na regular unfreeze would and thaw_super_locked() handles\nfilesystem-level freezes as before.\n\nThe emergency thaw path has deadlocked like this in one form or\nanother for a long long time but the current exclusively-held\nshape dates back to commit [1] where thaw_bdev() already ended in\nthaw_super() with s_umount held by do_thaw_all_callback()."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:45:53.613Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/96248aeddde794227a49af1a332a1e21b3c15d56"
},
{
"url": "https://git.kernel.org/stable/c/c202aa03388fd1889b7aa4f7d677c49e22cd9700"
},
{
"url": "https://git.kernel.org/stable/c/2a1127c1c58b4f15a93f2fd56ff7c2c3d611d5c5"
},
{
"url": "https://git.kernel.org/stable/c/05536cad35f27b520d4b6f0e57c8cc5bfb6b0502"
},
{
"url": "https://git.kernel.org/stable/c/99719b5da9320ed344daee87d9c73d321a98f252"
},
{
"url": "https://git.kernel.org/stable/c/63d78b546eefc38ad9898dc839bfc94811ede547"
},
{
"url": "https://git.kernel.org/stable/c/4c483644d1a7709efe7d1be7dbf88cf4008a7864"
},
{
"url": "https://git.kernel.org/stable/c/749d7aa0377aae32af8c0a4ad43371e7bf830ab5"
}
],
"title": "super: fix emergency thaw deadlock on frozen block devices",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68132",
"datePublished": "2026-08-10T11:58:55.196Z",
"dateReserved": "2026-07-30T09:28:09.370Z",
"dateUpdated": "2026-08-23T12:45:53.613Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74495 (GCVE-0-2026-74495)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-19 16:37
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
igbvf: Fix leak in TX DMA error cleanup
If an error is encountered while mapping TX buffers, the driver should
unmap any buffers already mapped for that skb.
Because count is incremented before each frag mapping, it will always
match the correct number of unmappings needed when dma_error is reached.
Decrementing count before the while loop in dma_error causes an
off-by-one error. If any mapping was successful before an unsuccessful
mapping, exactly one DMA mapping (the head) would leak.
This bug was introduced by a 2010 fix for an endless loop in dma_error.
All other affected drivers have already been fixed.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: c1fa347f20f17f14a4a1575727fa24340e8a9117 Version: c1fa347f20f17f14a4a1575727fa24340e8a9117 Version: c1fa347f20f17f14a4a1575727fa24340e8a9117 Version: c1fa347f20f17f14a4a1575727fa24340e8a9117 Version: c1fa347f20f17f14a4a1575727fa24340e8a9117 Version: c1fa347f20f17f14a4a1575727fa24340e8a9117 Version: c1fa347f20f17f14a4a1575727fa24340e8a9117 Version: c1fa347f20f17f14a4a1575727fa24340e8a9117 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/intel/igbvf/netdev.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "e42b7225c45f57b42306b80cdd3bda202bae7293",
"status": "affected",
"version": "c1fa347f20f17f14a4a1575727fa24340e8a9117",
"versionType": "git"
},
{
"lessThan": "e3ed89c257f6361f13df23023cd10ace830330ad",
"status": "affected",
"version": "c1fa347f20f17f14a4a1575727fa24340e8a9117",
"versionType": "git"
},
{
"lessThan": "56726ff12cb6759ab90d6f5332c2377aeca7d249",
"status": "affected",
"version": "c1fa347f20f17f14a4a1575727fa24340e8a9117",
"versionType": "git"
},
{
"lessThan": "31089f4eab42e0fc248ec80c26f9b0bad59ba4cc",
"status": "affected",
"version": "c1fa347f20f17f14a4a1575727fa24340e8a9117",
"versionType": "git"
},
{
"lessThan": "bc25d56c03e41c10bc4b40e99ca5d7b941675c04",
"status": "affected",
"version": "c1fa347f20f17f14a4a1575727fa24340e8a9117",
"versionType": "git"
},
{
"lessThan": "845a9cdd9b03b7b6fa8de3ee80579780350a7f65",
"status": "affected",
"version": "c1fa347f20f17f14a4a1575727fa24340e8a9117",
"versionType": "git"
},
{
"lessThan": "df07003b5a6c6c9fce60d765d6a3da815a74c41c",
"status": "affected",
"version": "c1fa347f20f17f14a4a1575727fa24340e8a9117",
"versionType": "git"
},
{
"lessThan": "0565052b7e2f436b7f1541f4849da96dc0aa7a0e",
"status": "affected",
"version": "c1fa347f20f17f14a4a1575727fa24340e8a9117",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/ethernet/intel/igbvf/netdev.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.33"
},
{
"lessThan": "2.6.33",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.33",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.33",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.33",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "2.6.33",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "2.6.33",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "2.6.33",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "2.6.33",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.33",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nigbvf: Fix leak in TX DMA error cleanup\n\nIf an error is encountered while mapping TX buffers, the driver should\nunmap any buffers already mapped for that skb.\n\nBecause count is incremented before each frag mapping, it will always\nmatch the correct number of unmappings needed when dma_error is reached.\nDecrementing count before the while loop in dma_error causes an\noff-by-one error. If any mapping was successful before an unsuccessful\nmapping, exactly one DMA mapping (the head) would leak.\n\nThis bug was introduced by a 2010 fix for an endless loop in dma_error.\nAll other affected drivers have already been fixed."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug is in the igbvf VF transmit path reached whenever egress skbs are queued, including fragmented replies or forwarded traffic from remote peers on SR-IOV cloud/tenant networks with internet-facing VFs.\nAC:L - No race is required; an attacker can repeatedly drive fragmented TX skbs and SWIOTLB/DMA-mapping pressure until skb_frag_dma_map fails after a successful head map, deterministically hitting the off-by-one dma_error cleanup.\nPR:N - Reaching ndo_start_xmit via normal sockets on the VF requires no kernel capabilities; co-tenant or internet-facing traffic can induce the leaky dma_error path without local credentials on the victim.\nUI:N - No victim interaction is needed beyond the VF carrying traffic; the leak occurs automatically in dma_error cleanup during transmit once mapping failure conditions are met.\nS:U - Impact is confined to the kernel/DMA resources of the guest or host running igbvf and does not by itself cross a hypervisor, IOMMU isolation, or separate security authority boundary.\nC:H - The error path frees the skb while its head DMA/IOMMU mapping remains in buffer_info, so freed pages can be reallocated while still mapped, enabling plausible kernel memory disclosure via stale DMA state.\nI:H - Reusing the descriptor slot without unmapping the leaked head mapping corrupts driver/IOMMU metadata and accumulates orphan mappings, a defensible path to driver heap corruption or write primitives.\nA:H - Each leaked TX DMA/IOMMU mapping consumes finite SWIOTLB/IOMMU resources; repeated triggering can exhaust mappings and break transmit or disable the VF entirely."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:37:53.097Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/e42b7225c45f57b42306b80cdd3bda202bae7293"
},
{
"url": "https://git.kernel.org/stable/c/e3ed89c257f6361f13df23023cd10ace830330ad"
},
{
"url": "https://git.kernel.org/stable/c/56726ff12cb6759ab90d6f5332c2377aeca7d249"
},
{
"url": "https://git.kernel.org/stable/c/31089f4eab42e0fc248ec80c26f9b0bad59ba4cc"
},
{
"url": "https://git.kernel.org/stable/c/bc25d56c03e41c10bc4b40e99ca5d7b941675c04"
},
{
"url": "https://git.kernel.org/stable/c/845a9cdd9b03b7b6fa8de3ee80579780350a7f65"
},
{
"url": "https://git.kernel.org/stable/c/df07003b5a6c6c9fce60d765d6a3da815a74c41c"
},
{
"url": "https://git.kernel.org/stable/c/0565052b7e2f436b7f1541f4849da96dc0aa7a0e"
}
],
"title": "igbvf: Fix leak in TX DMA error cleanup",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74495",
"datePublished": "2026-08-15T12:27:23.229Z",
"dateReserved": "2026-08-15T05:44:03.906Z",
"dateUpdated": "2026-08-19T16:37:53.097Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74505 (GCVE-0-2026-74505)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-19 16:38
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ALSA: 6fire: Fix UAF at error handling during probe
Although 6fire driver had a few fixes for dealing with the early error
handling during the probe phase, it forgot a pending URB before
freeing the resources, which may lead to a UAF.
This patch addresses it by doing the almost same cleanup procedure
like the normal disconnect phase at the error path.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: c6d43ba816d1cf1d125bfbfc938f2a28a87facf9 Version: c6d43ba816d1cf1d125bfbfc938f2a28a87facf9 Version: c6d43ba816d1cf1d125bfbfc938f2a28a87facf9 Version: c6d43ba816d1cf1d125bfbfc938f2a28a87facf9 Version: c6d43ba816d1cf1d125bfbfc938f2a28a87facf9 Version: c6d43ba816d1cf1d125bfbfc938f2a28a87facf9 Version: c6d43ba816d1cf1d125bfbfc938f2a28a87facf9 Version: c6d43ba816d1cf1d125bfbfc938f2a28a87facf9 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"sound/usb/6fire/chip.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "d41bfea14ee6e063a953f6e72046088737c4e66c",
"status": "affected",
"version": "c6d43ba816d1cf1d125bfbfc938f2a28a87facf9",
"versionType": "git"
},
{
"lessThan": "8b7ecb2446845fa8d1f1ce9aac6307caac50cfd5",
"status": "affected",
"version": "c6d43ba816d1cf1d125bfbfc938f2a28a87facf9",
"versionType": "git"
},
{
"lessThan": "a0bb5b9d39e54888385dc399c899223299201fe6",
"status": "affected",
"version": "c6d43ba816d1cf1d125bfbfc938f2a28a87facf9",
"versionType": "git"
},
{
"lessThan": "49bc7741cd2761c703a292dc69245041ae8a67bd",
"status": "affected",
"version": "c6d43ba816d1cf1d125bfbfc938f2a28a87facf9",
"versionType": "git"
},
{
"lessThan": "2de734dcbb210bd59983e13d36988acbcc122194",
"status": "affected",
"version": "c6d43ba816d1cf1d125bfbfc938f2a28a87facf9",
"versionType": "git"
},
{
"lessThan": "11e2953d9f4c7c3d2af94a889c2d805c537d633f",
"status": "affected",
"version": "c6d43ba816d1cf1d125bfbfc938f2a28a87facf9",
"versionType": "git"
},
{
"lessThan": "630c8d6a93cbd9b2a207f1a67ef1fd21af098b0c",
"status": "affected",
"version": "c6d43ba816d1cf1d125bfbfc938f2a28a87facf9",
"versionType": "git"
},
{
"lessThan": "a54bf16965f896415c3337bc4fbb40fb11941d99",
"status": "affected",
"version": "c6d43ba816d1cf1d125bfbfc938f2a28a87facf9",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"sound/usb/6fire/chip.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.39"
},
{
"lessThan": "2.6.39",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.39",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.39",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.39",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "2.6.39",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "2.6.39",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "2.6.39",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "2.6.39",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.39",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: 6fire: Fix UAF at error handling during probe\n\nAlthough 6fire driver had a few fixes for dealing with the early error\nhandling during the probe phase, it forgot a pending URB before\nfreeing the resources, which may lead to a UAF.\n\nThis patch addresses it by doing the almost same cleanup procedure\nlike the normal disconnect phase at the error path."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:38:02.508Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/d41bfea14ee6e063a953f6e72046088737c4e66c"
},
{
"url": "https://git.kernel.org/stable/c/8b7ecb2446845fa8d1f1ce9aac6307caac50cfd5"
},
{
"url": "https://git.kernel.org/stable/c/a0bb5b9d39e54888385dc399c899223299201fe6"
},
{
"url": "https://git.kernel.org/stable/c/49bc7741cd2761c703a292dc69245041ae8a67bd"
},
{
"url": "https://git.kernel.org/stable/c/2de734dcbb210bd59983e13d36988acbcc122194"
},
{
"url": "https://git.kernel.org/stable/c/11e2953d9f4c7c3d2af94a889c2d805c537d633f"
},
{
"url": "https://git.kernel.org/stable/c/630c8d6a93cbd9b2a207f1a67ef1fd21af098b0c"
},
{
"url": "https://git.kernel.org/stable/c/a54bf16965f896415c3337bc4fbb40fb11941d99"
}
],
"title": "ALSA: 6fire: Fix UAF at error handling during probe",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74505",
"datePublished": "2026-08-15T12:27:29.436Z",
"dateReserved": "2026-08-15T05:44:03.908Z",
"dateUpdated": "2026-08-19T16:38:02.508Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68196 (GCVE-0-2026-68196)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: wilc1000: validate assoc response length before subtracting header
wilc_parse_assoc_resp_info() computes the trailing IE length as
ies_len = buffer_len - sizeof(*res);
without first checking that buffer_len is at least sizeof(struct
wilc_assoc_resp) (6 bytes). buffer_len is the length reported for a
received association response (host_int_parse_assoc_resp_info() passes
hif_drv->assoc_resp / assoc_resp_info_len straight in) and must be
validated before the driver accesses the fixed header.
For a frame shorter than the 6-byte fixed header, the subtraction wraps.
For a four-byte response the result is truncated to a u16 ies_len of
65534, so kmemdup() then attempts to copy 65534 bytes starting at
buffer + sizeof(*res), beyond the valid association-response data
(CWE-125). A response shorter than four bytes can also cause an
out-of-bounds read of res->status_code at offsets 2 and 3.
Reject frames too short to hold the fixed header before touching the
header or computing ies_len. Also set the connection status to a failure
on this path: the caller falls through to a
"conn_info->status == WLAN_STATUS_SUCCESS" check after the parser
returns, so leaving the status untouched could let a malformed short
response be treated as a successful association.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: c5c77ba18ea66aa05441c71e38473efb787705a4 Version: c5c77ba18ea66aa05441c71e38473efb787705a4 Version: c5c77ba18ea66aa05441c71e38473efb787705a4 Version: c5c77ba18ea66aa05441c71e38473efb787705a4 Version: c5c77ba18ea66aa05441c71e38473efb787705a4 Version: c5c77ba18ea66aa05441c71e38473efb787705a4 Version: c5c77ba18ea66aa05441c71e38473efb787705a4 Version: c5c77ba18ea66aa05441c71e38473efb787705a4 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/microchip/wilc1000/hif.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "d79b92417f33424ff23dad76716ed8f2cefb1083",
"status": "affected",
"version": "c5c77ba18ea66aa05441c71e38473efb787705a4",
"versionType": "git"
},
{
"lessThan": "b81d0ea9e1daa215b3da68c1f4f6fb07940c2f6a",
"status": "affected",
"version": "c5c77ba18ea66aa05441c71e38473efb787705a4",
"versionType": "git"
},
{
"lessThan": "8d50acf5420de0c4da99c2d634731c9d3164a755",
"status": "affected",
"version": "c5c77ba18ea66aa05441c71e38473efb787705a4",
"versionType": "git"
},
{
"lessThan": "584c8954ad55f8b09b475be6db710fe40ceb988c",
"status": "affected",
"version": "c5c77ba18ea66aa05441c71e38473efb787705a4",
"versionType": "git"
},
{
"lessThan": "4d410320e8ae5933e651660c9fadc1d380309e23",
"status": "affected",
"version": "c5c77ba18ea66aa05441c71e38473efb787705a4",
"versionType": "git"
},
{
"lessThan": "e511e93abd6eeedcd5b3c55516241f414fbde64a",
"status": "affected",
"version": "c5c77ba18ea66aa05441c71e38473efb787705a4",
"versionType": "git"
},
{
"lessThan": "8ccdf8c8de87a9580df37c3c1ec53ba88cedef65",
"status": "affected",
"version": "c5c77ba18ea66aa05441c71e38473efb787705a4",
"versionType": "git"
},
{
"lessThan": "4c4c97b60a5e978121d9ee8cb0ab3916e5d6a8de",
"status": "affected",
"version": "c5c77ba18ea66aa05441c71e38473efb787705a4",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/microchip/wilc1000/hif.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.2"
},
{
"lessThan": "4.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: wilc1000: validate assoc response length before subtracting header\n\nwilc_parse_assoc_resp_info() computes the trailing IE length as\n\n\ties_len = buffer_len - sizeof(*res);\n\nwithout first checking that buffer_len is at least sizeof(struct\nwilc_assoc_resp) (6 bytes). buffer_len is the length reported for a\nreceived association response (host_int_parse_assoc_resp_info() passes\nhif_drv-\u003eassoc_resp / assoc_resp_info_len straight in) and must be\nvalidated before the driver accesses the fixed header.\n\nFor a frame shorter than the 6-byte fixed header, the subtraction wraps.\nFor a four-byte response the result is truncated to a u16 ies_len of\n65534, so kmemdup() then attempts to copy 65534 bytes starting at\nbuffer + sizeof(*res), beyond the valid association-response data\n(CWE-125). A response shorter than four bytes can also cause an\nout-of-bounds read of res-\u003estatus_code at offsets 2 and 3.\n\nReject frames too short to hold the fixed header before touching the\nheader or computing ies_len. Also set the connection status to a failure\non this path: the caller falls through to a\n\"conn_info-\u003estatus == WLAN_STATUS_SUCCESS\" check after the parser\nreturns, so leaving the status untouched could let a malformed short\nresponse be treated as a successful association."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - Exploitation requires a rogue WiFi AP to send a malformed 802.11 Association Response over the air during STA join; per kernel guidance WiFi frame injection is Adjacent, not routable Network.\nAC:L - The attacker fully controls the rogue AP and can craft sub-6-byte association responses with SUCCESS status; once the victim initiates or auto-rejoins association, the malformed frame reliably reaches the parser.\nPR:N - No privileges on the victim are required; a remote attacker operating a rogue AP triggers the bug during the standard pre-authentication WiFi association handshake without local access or credentials.\nUI:N - Exploitation does not require per-attempt user action when devices auto-reconnect to a saved SSID or join an evil-twin AP broadcasting a known network name, which is common on embedded/IoT WILC1000 deployments.\nS:U - The vulnerability is confined to kernel memory and driver state on the affected host; impact does not cross a security boundary such as VM escape, sandbox escape, or IOMMU/DMA isolation bypass.\nC:H - Integer underflow drives kmemdup() to copy up to ~65534 bytes past the 512-byte assoc_resp buffer, leaking adjacent kernel heap data that is forwarded to userspace via cfg80211_connect_bss() response IEs.\nI:L - Beyond the OOB read, a malformed short response can leave conn_info-\u003estatus as WLAN_STATUS_SUCCESS and report a bogus successful association, corrupting the device\u0027s connection integrity without granting arbitrary kernel write.\nA:H - The oversized kmemdup() memcpy reads far beyond the kmalloc-backed assoc_resp array, which can fault on unmapped memory and cause a kernel oops or panic; repeated triggers also impose severe memory pressure."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:13.791Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/d79b92417f33424ff23dad76716ed8f2cefb1083"
},
{
"url": "https://git.kernel.org/stable/c/b81d0ea9e1daa215b3da68c1f4f6fb07940c2f6a"
},
{
"url": "https://git.kernel.org/stable/c/8d50acf5420de0c4da99c2d634731c9d3164a755"
},
{
"url": "https://git.kernel.org/stable/c/584c8954ad55f8b09b475be6db710fe40ceb988c"
},
{
"url": "https://git.kernel.org/stable/c/4d410320e8ae5933e651660c9fadc1d380309e23"
},
{
"url": "https://git.kernel.org/stable/c/e511e93abd6eeedcd5b3c55516241f414fbde64a"
},
{
"url": "https://git.kernel.org/stable/c/8ccdf8c8de87a9580df37c3c1ec53ba88cedef65"
},
{
"url": "https://git.kernel.org/stable/c/4c4c97b60a5e978121d9ee8cb0ab3916e5d6a8de"
}
],
"title": "wifi: wilc1000: validate assoc response length before subtracting header",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68196",
"datePublished": "2026-08-10T12:00:14.686Z",
"dateReserved": "2026-07-30T09:28:09.374Z",
"dateUpdated": "2026-08-19T16:31:13.791Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74461 (GCVE-0-2026-74461)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-19 16:37
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
i2c: imx: Cancel hrtimer before clearing slave pointer
In i2c_imx_unreg_slave(), the slave pointer is set to NULL after
disabling interrupts. However, a pending interrupt might already
have started the hrtimer (i2c_imx_slave_timeout) before the pointer
was cleared. If the hrtimer fires after i2c_imx->slave is set to
NULL, the timer callback i2c_imx_slave_finish_op() will call
i2c_imx_slave_event() with a NULL slave pointer, which results in a
use-after-free / NULL pointer dereference.
Fix by canceling the hrtimer and waiting for it to complete after
disabling interrupts, before clearing the slave pointer.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: f7414cd6923fd7f78e57086fc964ba2dc25db5c1 Version: f7414cd6923fd7f78e57086fc964ba2dc25db5c1 Version: f7414cd6923fd7f78e57086fc964ba2dc25db5c1 Version: f7414cd6923fd7f78e57086fc964ba2dc25db5c1 Version: f7414cd6923fd7f78e57086fc964ba2dc25db5c1 Version: f7414cd6923fd7f78e57086fc964ba2dc25db5c1 Version: f7414cd6923fd7f78e57086fc964ba2dc25db5c1 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/i2c/busses/i2c-imx.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "e3da77bdb4015051656bb472c295656bbea03b6f",
"status": "affected",
"version": "f7414cd6923fd7f78e57086fc964ba2dc25db5c1",
"versionType": "git"
},
{
"lessThan": "470fe15fb3bb2eba6629be301ca7e991ee3cfb7e",
"status": "affected",
"version": "f7414cd6923fd7f78e57086fc964ba2dc25db5c1",
"versionType": "git"
},
{
"lessThan": "a8a1f9ac3d763e721586f15479ef9140b216ddf3",
"status": "affected",
"version": "f7414cd6923fd7f78e57086fc964ba2dc25db5c1",
"versionType": "git"
},
{
"lessThan": "753060f2b77ff2f386addbd3ecadb95b9f90cddd",
"status": "affected",
"version": "f7414cd6923fd7f78e57086fc964ba2dc25db5c1",
"versionType": "git"
},
{
"lessThan": "affd62f5719a78135b7441aa49c8cab3c3b5e838",
"status": "affected",
"version": "f7414cd6923fd7f78e57086fc964ba2dc25db5c1",
"versionType": "git"
},
{
"lessThan": "dab4762ee7f3fd0a01980d5407ba48d0261d3bff",
"status": "affected",
"version": "f7414cd6923fd7f78e57086fc964ba2dc25db5c1",
"versionType": "git"
},
{
"lessThan": "6ac7702b6cc2b94aaed9ef2d95bfbefcdc90061f",
"status": "affected",
"version": "f7414cd6923fd7f78e57086fc964ba2dc25db5c1",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/i2c/busses/i2c-imx.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.11"
},
{
"lessThan": "5.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: imx: Cancel hrtimer before clearing slave pointer\n\nIn i2c_imx_unreg_slave(), the slave pointer is set to NULL after\ndisabling interrupts. However, a pending interrupt might already\nhave started the hrtimer (i2c_imx_slave_timeout) before the pointer\nwas cleared. If the hrtimer fires after i2c_imx-\u003eslave is set to\nNULL, the timer callback i2c_imx_slave_finish_op() will call\ni2c_imx_slave_event() with a NULL slave pointer, which results in a\nuse-after-free / NULL pointer dereference.\n\nFix by canceling the hrtimer and waiting for it to complete after\ndisabling interrupts, before clearing the slave pointer."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.4,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is in the imx I2C slave teardown path reached via i2c_slave_unregister during local driver removal on embedded i.MX systems; exploitation requires local proximity to trigger concurrent I2C bus activity on the same controller.\nAC:L - The attacker controls both sides of the race by generating I2C slave traffic to arm/restart the 30us hrtimer while unregister runs, and can retry rapidly across repeated teardown cycles until the window is hit.\nPR:N - No Linux credentials are required when an attacker with physical access to an exposed I2C bus races automated system maintenance (OTA, service restart, driver reload) that calls i2c_slave_unregister on imx slave backends.\nUI:N - Exploitation does not require victim interaction; automated firmware updates or service restarts that unregister the slave driver are sufficient to create the teardown side of the race.\nS:U - Impact is confined to kernel memory corruption and crash on the same host; this is not a VM escape, IOMMU bypass, or cross-security-authority boundary.\nC:H - The timer callback invokes i2c_slave_event with a NULL/freed slave pointer (use-after-free), a memory safety violation that can be leveraged for arbitrary kernel memory read primitives per CVSS UAF guidance.\nI:H - Use-after-free in the slave event callback path can enable heap manipulation and arbitrary kernel write or control-flow hijack, not merely a deterministic NULL dereference crash.\nA:H - Triggering i2c_slave_event with a NULL slave causes kernel oops/panic, and the original patch series notes the last_slave_event loop in i2c_imx_slave_finish_op can hang the system."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:37:00.344Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/e3da77bdb4015051656bb472c295656bbea03b6f"
},
{
"url": "https://git.kernel.org/stable/c/470fe15fb3bb2eba6629be301ca7e991ee3cfb7e"
},
{
"url": "https://git.kernel.org/stable/c/a8a1f9ac3d763e721586f15479ef9140b216ddf3"
},
{
"url": "https://git.kernel.org/stable/c/753060f2b77ff2f386addbd3ecadb95b9f90cddd"
},
{
"url": "https://git.kernel.org/stable/c/affd62f5719a78135b7441aa49c8cab3c3b5e838"
},
{
"url": "https://git.kernel.org/stable/c/dab4762ee7f3fd0a01980d5407ba48d0261d3bff"
},
{
"url": "https://git.kernel.org/stable/c/6ac7702b6cc2b94aaed9ef2d95bfbefcdc90061f"
}
],
"title": "i2c: imx: Cancel hrtimer before clearing slave pointer",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74461",
"datePublished": "2026-08-15T12:27:01.924Z",
"dateReserved": "2026-08-15T05:44:03.901Z",
"dateUpdated": "2026-08-19T16:37:00.344Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74660 (GCVE-0-2026-74660)
Vulnerability from cvelistv5
Published
2026-08-22 15:32
Modified
2026-08-25 05:41
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
netfilter: ebt_nflog: pin the NFLOG backend
nf_log_unregister() runs after the per-net teardown so its final RCU
grace period also drains readers that obtained the logger from a per-net
binding. However, ebt_nflog passes an explicit ULOG log type to
nf_log_packet() without holding a reference on the selected logger module,
unlike the xt_NFLOG and nft_log frontends.
An ebtables nflog rule can therefore remain callable while nfnetlink_log
is unloaded. The resulting interleaving is:
CPU 0 CPU 1
nfnetlink_log_fini()
unregister_pernet_subsys()
kfree(nfnl_log_pernet(net))
ebt_nflog_tg()
nf_log_packet()
nfulnl_log_packet()
instance_lookup_get_rcu()
The global ULOG logger is still registered at this point, so CPU 1
dereferences the per-net state after CPU 0 has freed it. KASAN reported:
BUG: KASAN: slab-use-after-free in instance_lookup_get_rcu
Read of size 8 at addr ff110001052e6210 by task poc/92
Call Trace:
instance_lookup_get_rcu+0x1ce/0x1f0 [nfnetlink_log]
nfulnl_log_packet+0x248/0x2fb0 [nfnetlink_log]
nf_log_packet+0x204/0x300
ebt_nflog_tg+0x351/0x550
ebt_do_table+0xedf/0x22b0
Allocated by task 90:
__kmalloc_noprof+0x186/0x470
ops_init+0x6d/0x420
register_pernet_operations+0x2f6/0x670
register_pernet_subsys+0x23/0x40
Freed by task 93:
kfree+0x131/0x3c0
ops_undo_list+0x3e3/0x700
unregister_pernet_operations+0x232/0x490
unregister_pernet_subsys+0x1c/0x30
nfnetlink_log_fini+0x34/0x450 [nfnetlink_log]
Acquire the ULOG logger module reference when an ebt_nflog rule is
validated and release it when the rule is destroyed. Request the NFLOG
backend for legacy callers when needed, matching xt_NFLOG. This prevents
module teardown until all ebt_nflog rules have stopped using the logger.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: c83fa19603bdaeef17b815713dbbe3230c8a34ee Version: c83fa19603bdaeef17b815713dbbe3230c8a34ee Version: c83fa19603bdaeef17b815713dbbe3230c8a34ee Version: c83fa19603bdaeef17b815713dbbe3230c8a34ee Version: c83fa19603bdaeef17b815713dbbe3230c8a34ee Version: c83fa19603bdaeef17b815713dbbe3230c8a34ee Version: c83fa19603bdaeef17b815713dbbe3230c8a34ee Version: c83fa19603bdaeef17b815713dbbe3230c8a34ee |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/bridge/netfilter/ebt_nflog.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "3bcce49d617c593c7606083bfdb464a1761fa68d",
"status": "affected",
"version": "c83fa19603bdaeef17b815713dbbe3230c8a34ee",
"versionType": "git"
},
{
"lessThan": "394d7939c6b2b9e6bea0844c89efb5913168d898",
"status": "affected",
"version": "c83fa19603bdaeef17b815713dbbe3230c8a34ee",
"versionType": "git"
},
{
"lessThan": "2cac4294f184c9bc19ff82552c62b80498694c39",
"status": "affected",
"version": "c83fa19603bdaeef17b815713dbbe3230c8a34ee",
"versionType": "git"
},
{
"lessThan": "9d8a94b48b393885e7f876c8ef68ed4da5012078",
"status": "affected",
"version": "c83fa19603bdaeef17b815713dbbe3230c8a34ee",
"versionType": "git"
},
{
"lessThan": "6809379a860b9fccbb5435bf08343f6d081ac68d",
"status": "affected",
"version": "c83fa19603bdaeef17b815713dbbe3230c8a34ee",
"versionType": "git"
},
{
"lessThan": "47a119ec8a7e2d5c8c4e86fb1a56c4e696e500fb",
"status": "affected",
"version": "c83fa19603bdaeef17b815713dbbe3230c8a34ee",
"versionType": "git"
},
{
"lessThan": "e2ab7e878bdbe80104c879c31fd2d82a476703b8",
"status": "affected",
"version": "c83fa19603bdaeef17b815713dbbe3230c8a34ee",
"versionType": "git"
},
{
"lessThan": "30825970339c107bacaf7f61af90fcdb1f597ca1",
"status": "affected",
"version": "c83fa19603bdaeef17b815713dbbe3230c8a34ee",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/bridge/netfilter/ebt_nflog.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.12"
},
{
"lessThan": "4.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: ebt_nflog: pin the NFLOG backend\n\nnf_log_unregister() runs after the per-net teardown so its final RCU\ngrace period also drains readers that obtained the logger from a per-net\nbinding. However, ebt_nflog passes an explicit ULOG log type to\nnf_log_packet() without holding a reference on the selected logger module,\nunlike the xt_NFLOG and nft_log frontends.\n\nAn ebtables nflog rule can therefore remain callable while nfnetlink_log\nis unloaded. The resulting interleaving is:\n\n CPU 0 CPU 1\n nfnetlink_log_fini()\n unregister_pernet_subsys()\n kfree(nfnl_log_pernet(net))\n ebt_nflog_tg()\n nf_log_packet()\n nfulnl_log_packet()\n instance_lookup_get_rcu()\n\nThe global ULOG logger is still registered at this point, so CPU 1\ndereferences the per-net state after CPU 0 has freed it. KASAN reported:\n\n BUG: KASAN: slab-use-after-free in instance_lookup_get_rcu\n Read of size 8 at addr ff110001052e6210 by task poc/92\n Call Trace:\n instance_lookup_get_rcu+0x1ce/0x1f0 [nfnetlink_log]\n nfulnl_log_packet+0x248/0x2fb0 [nfnetlink_log]\n nf_log_packet+0x204/0x300\n ebt_nflog_tg+0x351/0x550\n ebt_do_table+0xedf/0x22b0\n Allocated by task 90:\n __kmalloc_noprof+0x186/0x470\n ops_init+0x6d/0x420\n register_pernet_operations+0x2f6/0x670\n register_pernet_subsys+0x23/0x40\n Freed by task 93:\n kfree+0x131/0x3c0\n ops_undo_list+0x3e3/0x700\n unregister_pernet_operations+0x232/0x490\n unregister_pernet_subsys+0x1c/0x30\n nfnetlink_log_fini+0x34/0x450 [nfnetlink_log]\n\nAcquire the ULOG logger module reference when an ebt_nflog rule is\nvalidated and release it when the rule is destroyed. Request the NFLOG\nbackend for legacy callers when needed, matching xt_NFLOG. This prevents\nmodule teardown until all ebt_nflog rules have stopped using the logger."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The UAF is reached through ebtables setsockopt rule installation and nfnetlink_log module teardown (local administrative paths); per kernel CNA guidance, netfilter/ebtables bugs are scored Local even when bridge hook evaluation can be driven by forwarded frames.\nAC:L - The KASAN reproducer uses a deterministic two-thread race between nfnetlink_log_fini() module removal and concurrent bridge traffic through an active ebt_nflog rule; the attacker controls both the unload timing and packet generation without depending on uncontrollable victim state.\nPR:L - Installing an ebt_nflog rule requires CAP_NET_ADMIN in the socket network namespace, obtainable by unprivileged users via user+network namespaces (unshare -Urn); the documented PoC races module teardown concurrently with rule-driven traffic, matching standard CNA treatment for ebtables/netfilter paths.\nUI:N - No victim interaction is required beyond the attacker\u0027s own ebtables configuration, module unload coordination, and bridge traffic generation to hit the active nflog target during the teardown window.\nS:U - The slab use-after-free corrupts host kernel memory within the same security authority; this is not a VM escape, container breakout across an IOMMU boundary, or other cross-scope privilege transition.\nC:H - KASAN confirmed a slab use-after-free read in instance_lookup_get_rcu() against freed nfnl_log_pernet state; UAF on the per-net instance hash table enables attacker-influenced heap reads and disclosure of adjacent kernel memory contents.\nI:H - Use-after-free on the nfnl_log_pernet structure and nfulnl_instance objects provides standard heap grooming primitives; freed slab reuse can redirect subsequent logging operations into attacker-controlled data for arbitrary kernel writes or control-flow hijack.\nA:H - The UAF read on freed per-net logging state can immediately trigger a kernel BUG/oops (as reported by KASAN) and reliably causes denial of service; repeated bridge traffic during module teardown can panic the affected host."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:41:14.285Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/3bcce49d617c593c7606083bfdb464a1761fa68d"
},
{
"url": "https://git.kernel.org/stable/c/394d7939c6b2b9e6bea0844c89efb5913168d898"
},
{
"url": "https://git.kernel.org/stable/c/2cac4294f184c9bc19ff82552c62b80498694c39"
},
{
"url": "https://git.kernel.org/stable/c/9d8a94b48b393885e7f876c8ef68ed4da5012078"
},
{
"url": "https://git.kernel.org/stable/c/6809379a860b9fccbb5435bf08343f6d081ac68d"
},
{
"url": "https://git.kernel.org/stable/c/47a119ec8a7e2d5c8c4e86fb1a56c4e696e500fb"
},
{
"url": "https://git.kernel.org/stable/c/e2ab7e878bdbe80104c879c31fd2d82a476703b8"
},
{
"url": "https://git.kernel.org/stable/c/30825970339c107bacaf7f61af90fcdb1f597ca1"
}
],
"title": "netfilter: ebt_nflog: pin the NFLOG backend",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74660",
"datePublished": "2026-08-22T15:32:33.677Z",
"dateReserved": "2026-08-15T05:44:03.924Z",
"dateUpdated": "2026-08-25T05:41:14.285Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68155 (GCVE-0-2026-68155)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
libceph: Reject monmaps advertising zero monitors
A message of type CEPH_MSG_MON_MAP contains a monmap that is sent from a
monitor to the client. This monmap contains information about the
existing monitors in the cluster. Currently, a monmap indicating that
there are zero monitors in the cluster is treated as valid. However, it
is impossible to have zero monitors in the cluster and still receive a
valid monmap from a monitor. Therefore, such a monmap must be corrupted
and should be treated as invalid. Furthermore, a monmap with a monitor
count of zero can subsequently crash the client when attempting to open
a session with a monitor in __open_session(). This happens because the
"BUG_ON(monc->monmap->num_mon < 1)" assertion in pick_new_mon() is
triggered.
This patch extends a check in ceph_monmap_decode() to also reject
arriving mon_maps with num_mon == 0 rather than only with
num_mon > CEPH_MAX_MON.
[ idryomov: drop "log output for unusual values of num_mon" part ]
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ba75bb98cfb93b62c54af25bf67ff90857264bbe Version: ba75bb98cfb93b62c54af25bf67ff90857264bbe Version: ba75bb98cfb93b62c54af25bf67ff90857264bbe Version: ba75bb98cfb93b62c54af25bf67ff90857264bbe Version: ba75bb98cfb93b62c54af25bf67ff90857264bbe Version: ba75bb98cfb93b62c54af25bf67ff90857264bbe Version: ba75bb98cfb93b62c54af25bf67ff90857264bbe |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ceph/mon_client.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "caf082ef8609a6ac26159ce115f55ab7d00231a3",
"status": "affected",
"version": "ba75bb98cfb93b62c54af25bf67ff90857264bbe",
"versionType": "git"
},
{
"lessThan": "e3ccd4ecab09b22f507f49cb7ed9990c7158ceab",
"status": "affected",
"version": "ba75bb98cfb93b62c54af25bf67ff90857264bbe",
"versionType": "git"
},
{
"lessThan": "0591a15815b498be628a937146e44487d599ba33",
"status": "affected",
"version": "ba75bb98cfb93b62c54af25bf67ff90857264bbe",
"versionType": "git"
},
{
"lessThan": "cd0d41bc569632eaaeccde9d2a6bc919ec00c407",
"status": "affected",
"version": "ba75bb98cfb93b62c54af25bf67ff90857264bbe",
"versionType": "git"
},
{
"lessThan": "e67e8b694872c9bc66996040f9de9242f6236ed9",
"status": "affected",
"version": "ba75bb98cfb93b62c54af25bf67ff90857264bbe",
"versionType": "git"
},
{
"lessThan": "3b249546f59c3d6d3592c10657f82bc3f1faa07c",
"status": "affected",
"version": "ba75bb98cfb93b62c54af25bf67ff90857264bbe",
"versionType": "git"
},
{
"lessThan": "40480eee361ed9676b3f844d532ac28b47251634",
"status": "affected",
"version": "ba75bb98cfb93b62c54af25bf67ff90857264bbe",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ceph/mon_client.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.34"
},
{
"lessThan": "2.6.34",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.34",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: Reject monmaps advertising zero monitors\n\nA message of type CEPH_MSG_MON_MAP contains a monmap that is sent from a\nmonitor to the client. This monmap contains information about the\nexisting monitors in the cluster. Currently, a monmap indicating that\nthere are zero monitors in the cluster is treated as valid. However, it\nis impossible to have zero monitors in the cluster and still receive a\nvalid monmap from a monitor. Therefore, such a monmap must be corrupted\nand should be treated as invalid. Furthermore, a monmap with a monitor\ncount of zero can subsequently crash the client when attempting to open\na session with a monitor in __open_session(). This happens because the\n\"BUG_ON(monc-\u003emonmap-\u003enum_mon \u003c 1)\" assertion in pick_new_mon() is\ntriggered.\n\nThis patch extends a check in ceph_monmap_decode() to also reject\narriving mon_maps with num_mon == 0 rather than only with\nnum_mon \u003e CEPH_MAX_MON.\n\n[ idryomov: drop \"log output for unusual values of num_mon\" part ]"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug is reached when libceph decodes CEPH_MSG_MON_MAP from a remote Ceph monitor over the kernel client\u0027s established TCP/msgr2 session (mon_dispatch -\u003e ceph_monc_handle_map -\u003e ceph_monmap_decode), which is a network protocol attack surface on CephFS/RBD/cloud nodes.\nAC:L - An attacker who can send monitor protocol messages only needs to set num_mon=0 in the monmap; once accepted, any later session reopen (keepalive timeout, hunt, or connection fault) deterministically hits BUG_ON in pick_new_mon without races or special memory layout.\nPR:N - In the highest-impact scenario a malicious or compromised Ceph monitor (or equivalent authenticated cluster peer) sends the malformed monmap to already-connected kernel clients; the attacker needs no local privileges on the victim host.\nUI:N - After a Ceph client session exists, monmap updates are delivered and processed automatically by the kernel monitor client; no further mount, open, or other victim interaction is required to accept the bad map and later crash on reconnect.\nS:U - Exploitation causes a kernel BUG/panic within the same kernel security domain and does not cross VM, container, IOMMU, or other security boundaries.\nC:N - The failure mode is a BUG_ON assertion in pick_new_mon when num_mon is zero; there is no memory corruption, out-of-bounds access, or other information disclosure primitive on the vulnerable path.\nI:N - Accepting num_mon==0 only stores an empty monmap and later triggers a deliberate kernel BUG; attacker input does not corrupt or modify arbitrary kernel memory or enable code execution.\nA:H - BUG_ON(monc-\u003emonmap-\u003enum_mon \u003c 1) in pick_new_mon during __open_session causes a kernel oops/panic, fully denying availability of the affected host until reboot."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:30:22.933Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/caf082ef8609a6ac26159ce115f55ab7d00231a3"
},
{
"url": "https://git.kernel.org/stable/c/e3ccd4ecab09b22f507f49cb7ed9990c7158ceab"
},
{
"url": "https://git.kernel.org/stable/c/0591a15815b498be628a937146e44487d599ba33"
},
{
"url": "https://git.kernel.org/stable/c/cd0d41bc569632eaaeccde9d2a6bc919ec00c407"
},
{
"url": "https://git.kernel.org/stable/c/e67e8b694872c9bc66996040f9de9242f6236ed9"
},
{
"url": "https://git.kernel.org/stable/c/3b249546f59c3d6d3592c10657f82bc3f1faa07c"
},
{
"url": "https://git.kernel.org/stable/c/40480eee361ed9676b3f844d532ac28b47251634"
}
],
"title": "libceph: Reject monmaps advertising zero monitors",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68155",
"datePublished": "2026-08-10T11:59:21.200Z",
"dateReserved": "2026-07-30T09:28:09.371Z",
"dateUpdated": "2026-08-19T16:30:22.933Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68446 (GCVE-0-2026-68446)
Vulnerability from cvelistv5
Published
2026-08-12 00:07
Modified
2026-08-19 16:35
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/vmwgfx: Validate vmw_surface_metadata::array_size
This field comes from userspace and should be validated against specific
limits depending on which Shader Model (SM) is available.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 504901dbb0b565fcbe466b0c56f3131586df5afd Version: 504901dbb0b565fcbe466b0c56f3131586df5afd Version: 504901dbb0b565fcbe466b0c56f3131586df5afd Version: 504901dbb0b565fcbe466b0c56f3131586df5afd Version: 504901dbb0b565fcbe466b0c56f3131586df5afd Version: 504901dbb0b565fcbe466b0c56f3131586df5afd Version: 504901dbb0b565fcbe466b0c56f3131586df5afd Version: 504901dbb0b565fcbe466b0c56f3131586df5afd |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/vmwgfx/vmwgfx_surface.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "e949adf2d42678fb391a41db277e2fcb12090566",
"status": "affected",
"version": "504901dbb0b565fcbe466b0c56f3131586df5afd",
"versionType": "git"
},
{
"lessThan": "0403cec2aff8037bc246cf9a0831eb169ddcd9df",
"status": "affected",
"version": "504901dbb0b565fcbe466b0c56f3131586df5afd",
"versionType": "git"
},
{
"lessThan": "aded8463466ede7a7fbd1bbf821756c67c83e89b",
"status": "affected",
"version": "504901dbb0b565fcbe466b0c56f3131586df5afd",
"versionType": "git"
},
{
"lessThan": "5ff94e1279176b539d451e3e754fdcbd1a8d520a",
"status": "affected",
"version": "504901dbb0b565fcbe466b0c56f3131586df5afd",
"versionType": "git"
},
{
"lessThan": "71779fe8bf403a9b3e28dc59229fa556db32d35d",
"status": "affected",
"version": "504901dbb0b565fcbe466b0c56f3131586df5afd",
"versionType": "git"
},
{
"lessThan": "b1379f0c42b88cb60b9f3757eb5d1e73ad460ed8",
"status": "affected",
"version": "504901dbb0b565fcbe466b0c56f3131586df5afd",
"versionType": "git"
},
{
"lessThan": "6910ccaf41678f7761ba2e57d72b77d056320b4d",
"status": "affected",
"version": "504901dbb0b565fcbe466b0c56f3131586df5afd",
"versionType": "git"
},
{
"lessThan": "a4f55260f7f7d4dc4d0ee55063dfb0c457b77991",
"status": "affected",
"version": "504901dbb0b565fcbe466b0c56f3131586df5afd",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/vmwgfx/vmwgfx_surface.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.7"
},
{
"lessThan": "5.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vmwgfx: Validate vmw_surface_metadata::array_size\n\nThis field comes from userspace and should be validated against specific\nlimits depending on which Shader Model (SM) is available."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached through the DRM_IOCTL_VMW_GB_SURFACE_CREATE/_EXT ioctls on the vmwgfx render node (/dev/dri/renderD128), i.e. local access to the device file on a VMware guest; no network or physical access is involved.\nAC:L - The attacker directly supplies array_size, mip_levels and base_size in a single ioctl and can deterministically choose values that wrap the 32-bit size/subresource computations; no race or uncontrolled precondition is required.\nPR:L - Both ioctls are registered DRM_RENDER_ALLOW, so an unprivileged local user (or containerized workload) holding the normal render-node permissions can call them without DRM master, root, or any capability.\nUI:N - Exploitation is entirely attacker-driven via ioctl calls on an already-open render node; no action by another user or administrator is needed.\nS:U - The unvalidated value corrupts guest kernel memory and device-command state within the same kernel security authority; no VM/IOMMU or sandbox boundary is crossed by the flaw itself.\nC:H - The wrapped res-\u003eguest_memory_size makes the backing buffer far smaller than the surface the host device is told to service, and the undersized dirty-\u003eboxes array is indexed out of bounds, giving out-of-bounds reads of adjacent kernel heap data that can be leaked back through surface contents.\nI:H - The u32 overflows in vmw_surface_get_serialized_size() and num_layers*num_mip yield an undersized backing BO and dirty-tracking array, producing controlled out-of-bounds heap writes (SVGA3dBox data and device DMA past the buffer) usable for heap corruption and privilege escalation.\nA:H - Out-of-bounds writes past kvzalloc\u0027d dirty trackers and BO-sized mismatches reliably corrupt kernel heap metadata, causing oopses/panics; huge array_size values also drive enormous allocations, so a local user can crash the guest kernel."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:35:40.576Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/e949adf2d42678fb391a41db277e2fcb12090566"
},
{
"url": "https://git.kernel.org/stable/c/0403cec2aff8037bc246cf9a0831eb169ddcd9df"
},
{
"url": "https://git.kernel.org/stable/c/aded8463466ede7a7fbd1bbf821756c67c83e89b"
},
{
"url": "https://git.kernel.org/stable/c/5ff94e1279176b539d451e3e754fdcbd1a8d520a"
},
{
"url": "https://git.kernel.org/stable/c/71779fe8bf403a9b3e28dc59229fa556db32d35d"
},
{
"url": "https://git.kernel.org/stable/c/b1379f0c42b88cb60b9f3757eb5d1e73ad460ed8"
},
{
"url": "https://git.kernel.org/stable/c/6910ccaf41678f7761ba2e57d72b77d056320b4d"
},
{
"url": "https://git.kernel.org/stable/c/a4f55260f7f7d4dc4d0ee55063dfb0c457b77991"
}
],
"title": "drm/vmwgfx: Validate vmw_surface_metadata::array_size",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68446",
"datePublished": "2026-08-12T00:07:37.385Z",
"dateReserved": "2026-07-30T09:28:09.395Z",
"dateUpdated": "2026-08-19T16:35:40.576Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80730 (GCVE-0-2026-80730)
Vulnerability from cvelistv5
Published
2026-09-03 08:21
Modified
2026-09-03 08:21
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ring-buffer: Fix crash passing ERR_PTR to kthread_stop()
In test_ringbuffer()'s out_free cleanup loop, the check
`!rb_threads[cpu]` only catches NULL entries and misses entries that
hold an ERR_PTR.
rb_threads[] is static, so unassigned slots are NULL. But when
kthread_run_on_cpu() fails for a cpu, it stores ERR_PTR(-ENOMEM) (or
-EINTR) in rb_threads[cpu] before the creation loop jumps to out_free.
That entry is non-NULL, so the old `!ptr` check does not break, and the
cleanup proceeds to call kthread_stop() on the ERR_PTR. kthread_stop()
then dereferences the bogus pointer, crashing the kernel during the
late_initcall self-test.
crash logs:
BUG: kernel NULL pointer dereference, address: 000000000000001c
Oops: 0002 [#1] SMP NOPTI
CPU: 1 PID: 1 Comm: swapper/0 Not tainted 7.2.0-rc6-dirty #7 PREEMPT(lazy)
RIP: 0010:kthread_stop+0x2e/0x220
RBX: fffffffffffffff4
CR2: 000000000000001c
Call Trace:
<TASK>
test_ringbuffer+0x1ec/0x650
do_one_initcall+0x6c/0x2c0
kernel_init_freeable+0x21d/0x420
kernel_init+0x15/0x1c0
ret_from_fork+0x21b/0x320
</TASK>
Kernel panic - not syncing: Fatal exception
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 64ed3a049e3e81b801e7c5bb052416152443f585 Version: 64ed3a049e3e81b801e7c5bb052416152443f585 Version: 64ed3a049e3e81b801e7c5bb052416152443f585 Version: 64ed3a049e3e81b801e7c5bb052416152443f585 Version: 64ed3a049e3e81b801e7c5bb052416152443f585 Version: 64ed3a049e3e81b801e7c5bb052416152443f585 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"kernel/trace/ring_buffer.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "51d78fad30dd9ae45721224103662bdbcf210096",
"status": "affected",
"version": "64ed3a049e3e81b801e7c5bb052416152443f585",
"versionType": "git"
},
{
"lessThan": "93e7044b548a72022208595d2c1b188bb225ce83",
"status": "affected",
"version": "64ed3a049e3e81b801e7c5bb052416152443f585",
"versionType": "git"
},
{
"lessThan": "8532983c312e8b875d7c9e440f8ee4674ea4b711",
"status": "affected",
"version": "64ed3a049e3e81b801e7c5bb052416152443f585",
"versionType": "git"
},
{
"lessThan": "6dd7a06894d6d3dc84319bd0b7d1a7c27df9d902",
"status": "affected",
"version": "64ed3a049e3e81b801e7c5bb052416152443f585",
"versionType": "git"
},
{
"lessThan": "3ea2fd344d93e3cf9503739b09fd702c0d8f8f0b",
"status": "affected",
"version": "64ed3a049e3e81b801e7c5bb052416152443f585",
"versionType": "git"
},
{
"lessThan": "91542863abade2fd4f2b361991f5386ad9d19c8c",
"status": "affected",
"version": "64ed3a049e3e81b801e7c5bb052416152443f585",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"kernel/trace/ring_buffer.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.17"
},
{
"lessThan": "5.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "5.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.17",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nring-buffer: Fix crash passing ERR_PTR to kthread_stop()\n\nIn test_ringbuffer()\u0027s out_free cleanup loop, the check\n`!rb_threads[cpu]` only catches NULL entries and misses entries that\nhold an ERR_PTR.\n\nrb_threads[] is static, so unassigned slots are NULL. But when\nkthread_run_on_cpu() fails for a cpu, it stores ERR_PTR(-ENOMEM) (or\n-EINTR) in rb_threads[cpu] before the creation loop jumps to out_free.\nThat entry is non-NULL, so the old `!ptr` check does not break, and the\ncleanup proceeds to call kthread_stop() on the ERR_PTR. kthread_stop()\nthen dereferences the bogus pointer, crashing the kernel during the\nlate_initcall self-test.\n\ncrash logs:\n BUG: kernel NULL pointer dereference, address: 000000000000001c\n Oops: 0002 [#1] SMP NOPTI\n CPU: 1 PID: 1 Comm: swapper/0 Not tainted 7.2.0-rc6-dirty #7 PREEMPT(lazy)\n RIP: 0010:kthread_stop+0x2e/0x220\n RBX: fffffffffffffff4\n CR2: 000000000000001c\n Call Trace:\n \u003cTASK\u003e\n test_ringbuffer+0x1ec/0x650\n do_one_initcall+0x6c/0x2c0\n kernel_init_freeable+0x21d/0x420\n kernel_init+0x15/0x1c0\n ret_from_fork+0x21b/0x320\n \u003c/TASK\u003e\n Kernel panic - not syncing: Fatal exception"
}
],
"providerMetadata": {
"dateUpdated": "2026-09-03T08:21:48.325Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/51d78fad30dd9ae45721224103662bdbcf210096"
},
{
"url": "https://git.kernel.org/stable/c/93e7044b548a72022208595d2c1b188bb225ce83"
},
{
"url": "https://git.kernel.org/stable/c/8532983c312e8b875d7c9e440f8ee4674ea4b711"
},
{
"url": "https://git.kernel.org/stable/c/6dd7a06894d6d3dc84319bd0b7d1a7c27df9d902"
},
{
"url": "https://git.kernel.org/stable/c/3ea2fd344d93e3cf9503739b09fd702c0d8f8f0b"
},
{
"url": "https://git.kernel.org/stable/c/91542863abade2fd4f2b361991f5386ad9d19c8c"
}
],
"title": "ring-buffer: Fix crash passing ERR_PTR to kthread_stop()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80730",
"datePublished": "2026-09-03T08:21:48.325Z",
"dateReserved": "2026-08-26T14:34:25.789Z",
"dateUpdated": "2026-09-03T08:21:48.325Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68395 (GCVE-0-2026-68395)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is registered
sata_dwc_enable_interrupts() is called before platform_get_irq() and
ata_host_activate(), leaving the SATA controller's interrupt mask
enabled without a registered handler. If a later step fails (irq
request, phy init, etc.) or if the controller asserts an interrupt
during probe, the irq line may fire with no handler, causing a
spurious interrupt storm.
Move sata_dwc_enable_interrupts() after ata_host_activate() so that
interrupts are only unmasked once the handler is registered and the
core is fully initialized.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 62936009f35a6659cc3ebe0d90c754182d60da73 Version: 62936009f35a6659cc3ebe0d90c754182d60da73 Version: 62936009f35a6659cc3ebe0d90c754182d60da73 Version: 62936009f35a6659cc3ebe0d90c754182d60da73 Version: 62936009f35a6659cc3ebe0d90c754182d60da73 Version: 62936009f35a6659cc3ebe0d90c754182d60da73 Version: 62936009f35a6659cc3ebe0d90c754182d60da73 Version: 62936009f35a6659cc3ebe0d90c754182d60da73 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/ata/sata_dwc_460ex.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "60b922442e9c208832e2699f128ef078f9f50faa",
"status": "affected",
"version": "62936009f35a6659cc3ebe0d90c754182d60da73",
"versionType": "git"
},
{
"lessThan": "d031957a6284e03c709f95cb8fc6f8891d4432ba",
"status": "affected",
"version": "62936009f35a6659cc3ebe0d90c754182d60da73",
"versionType": "git"
},
{
"lessThan": "8fbad29f399ba11c3b070ef5baf1c4b3e13ed838",
"status": "affected",
"version": "62936009f35a6659cc3ebe0d90c754182d60da73",
"versionType": "git"
},
{
"lessThan": "fbe7df5d3a3aed2456667a4825e4ff98d6df6ca4",
"status": "affected",
"version": "62936009f35a6659cc3ebe0d90c754182d60da73",
"versionType": "git"
},
{
"lessThan": "23d4c50fdc0dfe3ad4f9647a3b7d486de807dcda",
"status": "affected",
"version": "62936009f35a6659cc3ebe0d90c754182d60da73",
"versionType": "git"
},
{
"lessThan": "daa80b422ed920a3c0c45153020b0ad7af7fb5a5",
"status": "affected",
"version": "62936009f35a6659cc3ebe0d90c754182d60da73",
"versionType": "git"
},
{
"lessThan": "5d0797d6940b8dc894f950c52f7af0b42cb55ed0",
"status": "affected",
"version": "62936009f35a6659cc3ebe0d90c754182d60da73",
"versionType": "git"
},
{
"lessThan": "4bbc16a353a98023e5ddfca7c1fc0e49971cf4d0",
"status": "affected",
"version": "62936009f35a6659cc3ebe0d90c754182d60da73",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/ata/sata_dwc_460ex.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.36"
},
{
"lessThan": "2.6.36",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.36",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.36",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.36",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.36",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.36",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.36",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.36",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.36",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is registered\n\nsata_dwc_enable_interrupts() is called before platform_get_irq() and\nata_host_activate(), leaving the SATA controller\u0027s interrupt mask\nenabled without a registered handler. If a later step fails (irq\nrequest, phy init, etc.) or if the controller asserts an interrupt\nduring probe, the irq line may fire with no handler, causing a\nspurious interrupt storm.\n\nMove sata_dwc_enable_interrupts() after ata_host_activate() so that\ninterrupts are only unmasked once the handler is registered and the\ncore is fully initialized."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:45.284Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/60b922442e9c208832e2699f128ef078f9f50faa"
},
{
"url": "https://git.kernel.org/stable/c/d031957a6284e03c709f95cb8fc6f8891d4432ba"
},
{
"url": "https://git.kernel.org/stable/c/8fbad29f399ba11c3b070ef5baf1c4b3e13ed838"
},
{
"url": "https://git.kernel.org/stable/c/fbe7df5d3a3aed2456667a4825e4ff98d6df6ca4"
},
{
"url": "https://git.kernel.org/stable/c/23d4c50fdc0dfe3ad4f9647a3b7d486de807dcda"
},
{
"url": "https://git.kernel.org/stable/c/daa80b422ed920a3c0c45153020b0ad7af7fb5a5"
},
{
"url": "https://git.kernel.org/stable/c/5d0797d6940b8dc894f950c52f7af0b42cb55ed0"
},
{
"url": "https://git.kernel.org/stable/c/4bbc16a353a98023e5ddfca7c1fc0e49971cf4d0"
}
],
"title": "ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is registered",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68395",
"datePublished": "2026-08-10T12:04:14.545Z",
"dateReserved": "2026-07-30T09:28:09.389Z",
"dateUpdated": "2026-08-19T16:34:45.284Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80583 (GCVE-0-2026-80583)
Vulnerability from cvelistv5
Published
2026-08-26 14:37
Modified
2026-08-27 12:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ASoC: codecs: lpass-tx-macro: Fix enum kcontrol accesses
The "DEC0 MODE" to "DEC7 MODE" controls are enumerated, but
tx_macro_dec_mode_get() and tx_macro_dec_mode_put() access their
value through ucontrol->value.integer.value[0] (a long) instead of
ucontrol->value.enumerated.item[0] (an unsigned int).
This same pattern was fixed in the sibling drivers by
commit bcfe5f76cc40 ("ASoC: codecs: rx-macro: fix accessing array
out of bounds for enum type") and
commit 0ea5eff7c606 ("ASoC: codecs: va-macro: fix accessing array
out of bounds for enum type"), but tx-macro was missed.
On 64-bit kernels built with CONFIG_SND_CTL_DEBUG, the elem value
sanity check catches the 4 bytes written past the enumerated item
and every read of these controls fails with -EINVAL:
snd-sm8250 sound: control 2:0:0:DEC0 MODE:0: access overflow
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: c39667ddcfc516fee084e449179d54430a558298 Version: c39667ddcfc516fee084e449179d54430a558298 Version: c39667ddcfc516fee084e449179d54430a558298 Version: c39667ddcfc516fee084e449179d54430a558298 Version: c39667ddcfc516fee084e449179d54430a558298 Version: c39667ddcfc516fee084e449179d54430a558298 Version: c39667ddcfc516fee084e449179d54430a558298 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"sound/soc/codecs/lpass-tx-macro.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "dbc81b518f6936131bfd858be71cd4295136809c",
"status": "affected",
"version": "c39667ddcfc516fee084e449179d54430a558298",
"versionType": "git"
},
{
"lessThan": "f84f2c81d792cf1e65571108a3bdd2c29e09e995",
"status": "affected",
"version": "c39667ddcfc516fee084e449179d54430a558298",
"versionType": "git"
},
{
"lessThan": "48b76879f5bfc8584b99052510ac645c6ade8d2b",
"status": "affected",
"version": "c39667ddcfc516fee084e449179d54430a558298",
"versionType": "git"
},
{
"lessThan": "2ed3601e9db08fbdb071bd3d7bd8f115d6d871b0",
"status": "affected",
"version": "c39667ddcfc516fee084e449179d54430a558298",
"versionType": "git"
},
{
"lessThan": "b6baab796d11fb84c0e9444ffca91af5eab22c25",
"status": "affected",
"version": "c39667ddcfc516fee084e449179d54430a558298",
"versionType": "git"
},
{
"lessThan": "3ee3c26ceee562079596abc9bc3307dd56dab4ed",
"status": "affected",
"version": "c39667ddcfc516fee084e449179d54430a558298",
"versionType": "git"
},
{
"lessThan": "1ba381759e45d5d0442452cfa5c42e836191a568",
"status": "affected",
"version": "c39667ddcfc516fee084e449179d54430a558298",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"sound/soc/codecs/lpass-tx-macro.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.12"
},
{
"lessThan": "5.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.218",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.185",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.154",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.106",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.47",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.218",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.185",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.154",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.106",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.47",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.10",
"versionStartIncluding": "5.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: codecs: lpass-tx-macro: Fix enum kcontrol accesses\n\nThe \"DEC0 MODE\" to \"DEC7 MODE\" controls are enumerated, but\ntx_macro_dec_mode_get() and tx_macro_dec_mode_put() access their\nvalue through ucontrol-\u003evalue.integer.value[0] (a long) instead of\nucontrol-\u003evalue.enumerated.item[0] (an unsigned int).\n\nThis same pattern was fixed in the sibling drivers by\ncommit bcfe5f76cc40 (\"ASoC: codecs: rx-macro: fix accessing array\nout of bounds for enum type\") and\ncommit 0ea5eff7c606 (\"ASoC: codecs: va-macro: fix accessing array\nout of bounds for enum type\"), but tx-macro was missed.\n\nOn 64-bit kernels built with CONFIG_SND_CTL_DEBUG, the elem value\nsanity check catches the 4 bytes written past the enumerated item\nand every read of these controls fails with -EINVAL:\n\n snd-sm8250 sound: control 2:0:0:DEC0 MODE:0: access overflow"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires local SNDRV_CTL_IOCTL_ELEM_READ or SNDRV_CTL_IOCTL_ELEM_WRITE on /dev/snd/controlC* through snd_ctl_ioctl() to tx_macro_dec_mode_get/put(); the Qualcomm LPASS TX macro audio codec driver has no network, Bluetooth, or physical-input attack path.\nAC:L - A single ioctl targeting DEC0-7 MODE deterministically triggers the 8-byte integer access against a 4-byte enumerated field on 64-bit kernels; the attacker controls both sides with no race, timing, or memory-layout dependency.\nPR:L - snd_ctl_open() performs no capability check; exploitation needs only local access to /dev/snd/controlC*, typically granted to the audio group on Qualcomm sc8250/sc8280 Chromebooks and Linux dev boards where this driver is present, not real root.\nUI:N - Once the attacker has ALSA control-device access they issue elem read/write ioctls themselves to DEC MODE controls; no separate victim action such as plugging hardware or opening a file is required.\nS:U - The out-of-bounds ctl-value access and resulting microphone ADC mode corruption remain within the host kernel and Qualcomm audio subsystem; there is no crossing of VM, container, or IOMMU security boundaries.\nC:H - tx_macro_dec_mode_put() reads ucontrol-\u003evalue.integer.value[0] (8 bytes) for ENUM controls, performing a 4-byte out-of-bounds read past enumerated.item[0]; per kernel CVSS guidance out-of-bounds reads are scored High even when bounded.\nI:H - tx_macro_dec_mode_get() writes 8 bytes via integer.value[0], overflowing enumerated.item[0] by 4 bytes in kernel memory; put stores values into tx-\u003edec_mode[] that program CDC_TXn_ADC_MODE on phone/Chromebook microphones, constituting memory corruption scored High.\nA:H - With CONFIG_SND_CTL_DEBUG every DEC0-7 MODE read fails with -EINVAL (access overflow), denying microphone ADC queries; on production 64-bit aarch64 builds the 4-byte union overrun corrupts ctl values and can break Qualcomm LPASS TX audio capture availability."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T12:40:21.902Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/dbc81b518f6936131bfd858be71cd4295136809c"
},
{
"url": "https://git.kernel.org/stable/c/f84f2c81d792cf1e65571108a3bdd2c29e09e995"
},
{
"url": "https://git.kernel.org/stable/c/48b76879f5bfc8584b99052510ac645c6ade8d2b"
},
{
"url": "https://git.kernel.org/stable/c/2ed3601e9db08fbdb071bd3d7bd8f115d6d871b0"
},
{
"url": "https://git.kernel.org/stable/c/b6baab796d11fb84c0e9444ffca91af5eab22c25"
},
{
"url": "https://git.kernel.org/stable/c/3ee3c26ceee562079596abc9bc3307dd56dab4ed"
},
{
"url": "https://git.kernel.org/stable/c/1ba381759e45d5d0442452cfa5c42e836191a568"
}
],
"title": "ASoC: codecs: lpass-tx-macro: Fix enum kcontrol accesses",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80583",
"datePublished": "2026-08-26T14:37:39.704Z",
"dateReserved": "2026-08-26T14:34:25.769Z",
"dateUpdated": "2026-08-27T12:40:21.902Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80752 (GCVE-0-2026-80752)
Vulnerability from cvelistv5
Published
2026-09-03 08:26
Modified
2026-09-04 04:58
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Input: psxpad-spi - set driver data before use
psxpad_spi_suspend() retrieves the controller state with
spi_get_drvdata(), but probe never stores it, so suspend dereferences a
NULL pointer. Store it during probe.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 8be193c7b1f44d3f4dcb27107df0831709c2deb1 Version: 8be193c7b1f44d3f4dcb27107df0831709c2deb1 Version: 8be193c7b1f44d3f4dcb27107df0831709c2deb1 Version: 8be193c7b1f44d3f4dcb27107df0831709c2deb1 Version: 8be193c7b1f44d3f4dcb27107df0831709c2deb1 Version: 8be193c7b1f44d3f4dcb27107df0831709c2deb1 Version: 8be193c7b1f44d3f4dcb27107df0831709c2deb1 Version: 8be193c7b1f44d3f4dcb27107df0831709c2deb1 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/input/joystick/psxpad-spi.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "e980066e434a9c74ff1665ed9140427e95b0ee7c",
"status": "affected",
"version": "8be193c7b1f44d3f4dcb27107df0831709c2deb1",
"versionType": "git"
},
{
"lessThan": "1bba6bd6861b1e0c8ecf20cd1892f0d3877c02a2",
"status": "affected",
"version": "8be193c7b1f44d3f4dcb27107df0831709c2deb1",
"versionType": "git"
},
{
"lessThan": "86531cdfb3a03213e2569deed5195412a4e3f7ee",
"status": "affected",
"version": "8be193c7b1f44d3f4dcb27107df0831709c2deb1",
"versionType": "git"
},
{
"lessThan": "da6b8b05db0cf43e0cc198431fa8ee9739b3b817",
"status": "affected",
"version": "8be193c7b1f44d3f4dcb27107df0831709c2deb1",
"versionType": "git"
},
{
"lessThan": "1edcb7ffee7ac4dc35cbe5bbd0e27bac3614ebe4",
"status": "affected",
"version": "8be193c7b1f44d3f4dcb27107df0831709c2deb1",
"versionType": "git"
},
{
"lessThan": "8d622c58205adbc8af19864e277386528b671345",
"status": "affected",
"version": "8be193c7b1f44d3f4dcb27107df0831709c2deb1",
"versionType": "git"
},
{
"lessThan": "62e25677d1440085381b047ec4984be9b6793759",
"status": "affected",
"version": "8be193c7b1f44d3f4dcb27107df0831709c2deb1",
"versionType": "git"
},
{
"lessThan": "732f38c36059e68ba3b4b89c56911d777fd3185c",
"status": "affected",
"version": "8be193c7b1f44d3f4dcb27107df0831709c2deb1",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/input/joystick/psxpad-spi.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.12"
},
{
"lessThan": "4.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.46",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.10",
"versionStartIncluding": "4.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nInput: psxpad-spi - set driver data before use\n\npsxpad_spi_suspend() retrieves the controller state with\nspi_get_drvdata(), but probe never stores it, so suspend dereferences a\nNULL pointer. Store it during probe."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.4,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The fault is reached only via the kernel system-sleep PM path (suspend/hibernate) calling dpm_suspend() -\u003e psxpad_spi_suspend(); it is not triggered by network traffic, wireless frames, or SPI packet handling from a remote peer.\nAC:L - On embedded retro consoles/arcade cabinets with a probed psxpad-spi controller, every system suspend deterministically calls psxpad_spi_suspend() with NULL drvdata and faults in psxpad_set_motor_level(); no race, heap layout, or rare timing is required beyond CONFIG_JOYSTICK_PSXPAD_SPI hardware being present.\nPR:N - No Linux account is required on typical embedded/kiosk deployments: ACPI power-button sleep, lid-close policies, or automated idle suspend invoke the PM path without authenticated local userspace, and user namespaces cannot substitute for triggering host system sleep.\nUI:N - Exploitation requires only initiating or allowing a system suspend/hibernate cycle (power button, logind, or policy-driven sleep); no separate victim action such as opening a file, mounting a filesystem, or plugging in a controller at attack time is needed once the SPI pad is bound.\nS:U - The NULL dereference and resulting kernel oops/panic occur entirely within the same host kernel that owns the psxpad-spi driver; there is no VM escape, IOMMU/DMA boundary bypass, or cross-security-authority impact.\nC:H - psxpad_spi_suspend() passes a NULL pad into psxpad_set_motor_level(), which performs kernel stores through a NULL structure pointer; this memory-unsafe dereference class can disclose kernel memory during fault/Oops handling or on mappings where low addresses are reachable, not merely a silent crash.\nI:H - The suspend path attempts writes to pad-\u003emotor1level and pad-\u003emotor2level via a NULL base pointer, constituting attempted kernel memory corruption that can yield further write primitives or control-flow hijack on configurations without strict NULL-page protection, beyond immediate denial of service.\nA:H - The NULL pointer dereference in psxpad_set_motor_level() during psxpad_spi_suspend() causes a kernel Oops/panic that aborts or corrupts the suspend sequence, denying availability of a clean sleep/resume cycle on affected systems."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T04:58:32.588Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/e980066e434a9c74ff1665ed9140427e95b0ee7c"
},
{
"url": "https://git.kernel.org/stable/c/1bba6bd6861b1e0c8ecf20cd1892f0d3877c02a2"
},
{
"url": "https://git.kernel.org/stable/c/86531cdfb3a03213e2569deed5195412a4e3f7ee"
},
{
"url": "https://git.kernel.org/stable/c/da6b8b05db0cf43e0cc198431fa8ee9739b3b817"
},
{
"url": "https://git.kernel.org/stable/c/1edcb7ffee7ac4dc35cbe5bbd0e27bac3614ebe4"
},
{
"url": "https://git.kernel.org/stable/c/8d622c58205adbc8af19864e277386528b671345"
},
{
"url": "https://git.kernel.org/stable/c/62e25677d1440085381b047ec4984be9b6793759"
},
{
"url": "https://git.kernel.org/stable/c/732f38c36059e68ba3b4b89c56911d777fd3185c"
}
],
"title": "Input: psxpad-spi - set driver data before use",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80752",
"datePublished": "2026-09-03T08:26:31.962Z",
"dateReserved": "2026-08-26T14:34:25.790Z",
"dateUpdated": "2026-09-04T04:58:32.588Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80569 (GCVE-0-2026-80569)
Vulnerability from cvelistv5
Published
2026-08-26 14:37
Modified
2026-08-27 05:01
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Input: synaptics-rmi4 - bound the F54 report size to the allocated buffer
rmi_f54_work() reads a diagnostics report from the device into
f54->report_data, sizing the transfer with rmi_f54_get_report_size():
report_size = rmi_f54_get_report_size(f54);
...
for (i = 0; i < report_size; i += F54_REPORT_DATA_SIZE) {
int size = min(F54_REPORT_DATA_SIZE, report_size - i);
...
rmi_read_block(.., f54->report_data + i, size);
}
report_data is allocated once at probe from F54's own electrode counts
(array3_size(f54->num_tx_electrodes, f54->num_rx_electrodes, sizeof(u16))),
but rmi_f54_get_report_size() computes the size from
drv_data->num_*_electrodes when those are set, i.e. from the F55
function's electrode counts. Both counts come straight from device
queries (F54 and F55 each report up to 255 electrodes) and nothing
constrains the F55 counts to the F54 ones.
A malicious or malfunctioning RMI4 device that reports larger F55
electrode counts than its F54 counts makes report_size exceed the
allocation, so the read loop writes past report_data (and the V4L2
dequeue memcpy() then reads past it). On conforming hardware the F55
configured electrodes are a subset of the F54 physical electrodes, so
report_size never exceeds the buffer and well-behaved devices are
unaffected.
Record the allocation size and reject a report that does not fit,
mirroring the existing zero-size check.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: c762cc68b6a12eedebefc156ea4838e54804e2eb Version: c762cc68b6a12eedebefc156ea4838e54804e2eb Version: c762cc68b6a12eedebefc156ea4838e54804e2eb Version: c762cc68b6a12eedebefc156ea4838e54804e2eb Version: c762cc68b6a12eedebefc156ea4838e54804e2eb Version: c762cc68b6a12eedebefc156ea4838e54804e2eb Version: c762cc68b6a12eedebefc156ea4838e54804e2eb Version: c762cc68b6a12eedebefc156ea4838e54804e2eb |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/input/rmi4/rmi_f54.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "6b3bdd44d4cd7d5e35de1d0f06d4930f3cecd403",
"status": "affected",
"version": "c762cc68b6a12eedebefc156ea4838e54804e2eb",
"versionType": "git"
},
{
"lessThan": "b2f596f00d27703ce09167201ba57f55be8d2f9a",
"status": "affected",
"version": "c762cc68b6a12eedebefc156ea4838e54804e2eb",
"versionType": "git"
},
{
"lessThan": "b3932101c9c457148038392bc977f9b31e125a86",
"status": "affected",
"version": "c762cc68b6a12eedebefc156ea4838e54804e2eb",
"versionType": "git"
},
{
"lessThan": "12be3c6ca9589afd6ade41a59c761866e526634d",
"status": "affected",
"version": "c762cc68b6a12eedebefc156ea4838e54804e2eb",
"versionType": "git"
},
{
"lessThan": "42eaf0e6f79c487f419737314cf0760f7331d368",
"status": "affected",
"version": "c762cc68b6a12eedebefc156ea4838e54804e2eb",
"versionType": "git"
},
{
"lessThan": "6b06aab79ff166d5781ce792d91acc2e58b1770b",
"status": "affected",
"version": "c762cc68b6a12eedebefc156ea4838e54804e2eb",
"versionType": "git"
},
{
"lessThan": "b7b9a8b1c303b62371698e396654d6724c79cb74",
"status": "affected",
"version": "c762cc68b6a12eedebefc156ea4838e54804e2eb",
"versionType": "git"
},
{
"lessThan": "49c5adc2b7d6e43c5cf033e1c86fdb9c16ababb1",
"status": "affected",
"version": "c762cc68b6a12eedebefc156ea4838e54804e2eb",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/input/rmi4/rmi_f54.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.10"
},
{
"lessThan": "4.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.46",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.10",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nInput: synaptics-rmi4 - bound the F54 report size to the allocated buffer\n\nrmi_f54_work() reads a diagnostics report from the device into\nf54-\u003ereport_data, sizing the transfer with rmi_f54_get_report_size():\n\n\treport_size = rmi_f54_get_report_size(f54);\n\t...\n\tfor (i = 0; i \u003c report_size; i += F54_REPORT_DATA_SIZE) {\n\t\tint size = min(F54_REPORT_DATA_SIZE, report_size - i);\n\t\t...\n\t\trmi_read_block(.., f54-\u003ereport_data + i, size);\n\t}\n\nreport_data is allocated once at probe from F54\u0027s own electrode counts\n(array3_size(f54-\u003enum_tx_electrodes, f54-\u003enum_rx_electrodes, sizeof(u16))),\nbut rmi_f54_get_report_size() computes the size from\ndrv_data-\u003enum_*_electrodes when those are set, i.e. from the F55\nfunction\u0027s electrode counts. Both counts come straight from device\nqueries (F54 and F55 each report up to 255 electrodes) and nothing\nconstrains the F55 counts to the F54 ones.\n\nA malicious or malfunctioning RMI4 device that reports larger F55\nelectrode counts than its F54 counts makes report_size exceed the\nallocation, so the read loop writes past report_data (and the V4L2\ndequeue memcpy() then reads past it). On conforming hardware the F55\nconfigured electrodes are a subset of the F54 physical electrodes, so\nreport_size never exceeds the buffer and well-behaved devices are\nunaffected.\n\nRecord the allocation size and reject a report that does not fit,\nmirroring the existing zero-size check."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation is reached through local V4L2 ioctls on the synaptics-rmi4 F54 touch diagnostics video node (/dev/video*); streaming a report drives rmi_f54_buffer_queue() into rmi_f54_work(), which performs the unchecked copy. A malicious on-bus RMI4 device is the precondition, but the syscall path is Local.\nAC:L - After probe with mismatched F54/F55 electrode counts, an attacker with access to the V4L2 node can select a 16-bit report type and queue buffers to deterministically trigger a multi-kilobyte heap overflow; no race or fragile layout assumptions are required beyond device-reported sizes.\nPR:L - Triggering the overflow requires only permission to open the registered VFL_TYPE_TOUCH video device and issue standard V4L2 capture ioctls; no CAP_SYS_ADMIN or root capability is needed where seat/session policy grants video or input device access to an unprivileged local user.\nUI:N - No victim interaction is required beyond the attacker opening the diagnostics node and starting capture; no other user must mount filesystems, plug devices, or perform cooperative actions at exploit time.\nS:U - Impact is confined to host kernel memory within the same security boundary; this is a kernel heap corruption in the input driver and does not inherently provide VM escape, IOMMU bypass, or cross-sandbox authority change.\nC:H - rmi_f54_work() performs an out-of-bounds write past devm-allocated report_data, and rmi_f54_buffer_queue() memcpy() can read past that buffer into the userspace capture buffer, leaking adjacent kmalloc/slab contents including potentially sensitive kernel pointers.\nI:H - The device-driven read loop writes up to roughly 130 KiB past report_data (255x255x2 minus the F54-sized allocation), supplying attacker-influenced report bytes that can corrupt adjacent heap objects and enable control-flow hijacking or privilege escalation primitives.\nA:H - Corrupting adjacent slab memory via the out-of-bounds write can immediately panic or oops the kernel; the overflow is repeatable on each queued V4L2 buffer while the mismatched device remains present."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T05:01:53.135Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/6b3bdd44d4cd7d5e35de1d0f06d4930f3cecd403"
},
{
"url": "https://git.kernel.org/stable/c/b2f596f00d27703ce09167201ba57f55be8d2f9a"
},
{
"url": "https://git.kernel.org/stable/c/b3932101c9c457148038392bc977f9b31e125a86"
},
{
"url": "https://git.kernel.org/stable/c/12be3c6ca9589afd6ade41a59c761866e526634d"
},
{
"url": "https://git.kernel.org/stable/c/42eaf0e6f79c487f419737314cf0760f7331d368"
},
{
"url": "https://git.kernel.org/stable/c/6b06aab79ff166d5781ce792d91acc2e58b1770b"
},
{
"url": "https://git.kernel.org/stable/c/b7b9a8b1c303b62371698e396654d6724c79cb74"
},
{
"url": "https://git.kernel.org/stable/c/49c5adc2b7d6e43c5cf033e1c86fdb9c16ababb1"
}
],
"title": "Input: synaptics-rmi4 - bound the F54 report size to the allocated buffer",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80569",
"datePublished": "2026-08-26T14:37:31.338Z",
"dateReserved": "2026-08-26T14:34:25.768Z",
"dateUpdated": "2026-08-27T05:01:53.135Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68206 (GCVE-0-2026-68206)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: v4l2-ctrls: validate HEVC active reference counts
HEVC slice parameters are shared stateless V4L2 controls, but the common
validation path does not verify the active L0/L1 reference counts before
driver-specific code consumes them.
The original report came from Cedrus, but the active count bounds are
not Cedrus-specific. Validate them in the common HEVC slice control path
so stateless HEVC drivers get the same basic guarantees as soon as the
control is queued.
Do not reject ref_idx_l0/ref_idx_l1 entries here. Existing userspace may
use out-of-range sentinel values such as 0xff for missing references, and
some hardware can use that information for concealment. Keep this common
check limited to the active reference counts.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d395a78db9eabd12633b39e05c80e803543b6590 Version: d395a78db9eabd12633b39e05c80e803543b6590 Version: d395a78db9eabd12633b39e05c80e803543b6590 Version: d395a78db9eabd12633b39e05c80e803543b6590 Version: d395a78db9eabd12633b39e05c80e803543b6590 Version: d395a78db9eabd12633b39e05c80e803543b6590 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/v4l2-core/v4l2-ctrls-core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "3299c3905f3fb439ebd892658b87bc76c93ae116",
"status": "affected",
"version": "d395a78db9eabd12633b39e05c80e803543b6590",
"versionType": "git"
},
{
"lessThan": "9a998cc1c348769262d433acb7d238c5fac4b2e0",
"status": "affected",
"version": "d395a78db9eabd12633b39e05c80e803543b6590",
"versionType": "git"
},
{
"lessThan": "dbaf0e0023e2f9332c5164822def7f80b7d2c5ef",
"status": "affected",
"version": "d395a78db9eabd12633b39e05c80e803543b6590",
"versionType": "git"
},
{
"lessThan": "3068ab802fc98b121dcb451e1f7f4d338ffc7a19",
"status": "affected",
"version": "d395a78db9eabd12633b39e05c80e803543b6590",
"versionType": "git"
},
{
"lessThan": "b01df98a6669d2b67d8aed816021b327fd905998",
"status": "affected",
"version": "d395a78db9eabd12633b39e05c80e803543b6590",
"versionType": "git"
},
{
"lessThan": "afbe4bc252d90a6f8fad869b06d5430f615f22f9",
"status": "affected",
"version": "d395a78db9eabd12633b39e05c80e803543b6590",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/v4l2-core/v4l2-ctrls-core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.14"
},
{
"lessThan": "5.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: v4l2-ctrls: validate HEVC active reference counts\n\nHEVC slice parameters are shared stateless V4L2 controls, but the common\nvalidation path does not verify the active L0/L1 reference counts before\ndriver-specific code consumes them.\n\nThe original report came from Cedrus, but the active count bounds are\nnot Cedrus-specific. Validate them in the common HEVC slice control path\nso stateless HEVC drivers get the same basic guarantees as soon as the\ncontrol is queued.\n\nDo not reject ref_idx_l0/ref_idx_l1 entries here. Existing userspace may\nuse out-of-range sentinel values such as 0xff for missing references, and\nsome hardware can use that information for concealment. Keep this common\ncheck limited to the active reference counts."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The control is only settable through VIDIOC_S_EXT_CTRLS on the local V4L2 stateless decoder node (/dev/videoN), followed by QBUF/STREAMON on the same fd. There is no network or remote path into the HEVC slice-params control.\nAC:L - The attacker supplies num_ref_idx_l0/l1_active_minus1 verbatim as a u8; any value in 16..254 deterministically drives the loops in cedrus_h265_is_low_delay() and rkvdec_hevc set_ps_field() out of bounds on the very next decode run. No race, timing window, or uncontrollable memory layout is involved.\nPR:L - Only an unprivileged local account holding the video device node is required (typically the \u0027video\u0027 group, or the media/codec service reachable from sandboxed apps on Android and embedded Allwinner/Rockchip devices). cedrus_try_ctrl() checks only SPS chroma format and bit depth; no capability or root check exists on the path.\nUI:N - The attacking process performs the whole sequence itself: open the decoder, set the crafted HEVC slice-params control, queue buffers and start streaming. No victim action, media file, or mount is needed.\nS:U - The out-of-bounds accesses stay inside the kernel\u0027s own slab and DMA memory within the same security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - decode_params-\u003edpb[] holds 16 16-byte entries at the tail of a ~336-byte control allocation, so an index up to 255 reads roughly 3.8 KB of adjacent kernel heap; the pred-weight loops likewise read 240 bytes past slice_params. Those OOB bytes are fed into decoder SRAM and steer the low-delay decision, giving an attacker-steerable oracle over unrelated kernel memory.\nI:H - In rkvdec-hevc, REF_PIC_IDX_L0(i)/REF_PIC_LONG_TERM_L1(i) with i up to 255 resolve to bit offset ~1276 in an 8-word rkvdec_rps_packet, so set_ps_field() performs an out-of-bounds write of attacker-chosen bits at an attacker-chosen offset into (and past the end of) the coherent DMA priv_tbl, corrupting hardware descriptor state and adjacent memory.\nA:H - Reading several kilobytes past a slab object can walk into an unmapped or poisoned region and trips KASAN/hardening checks, while the rkvdec out-of-bounds write corrupts the DMA table handed to the decoder; either yields a kernel oops or wedged hardware, repeatable at will from an unprivileged process."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:26.837Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/3299c3905f3fb439ebd892658b87bc76c93ae116"
},
{
"url": "https://git.kernel.org/stable/c/9a998cc1c348769262d433acb7d238c5fac4b2e0"
},
{
"url": "https://git.kernel.org/stable/c/dbaf0e0023e2f9332c5164822def7f80b7d2c5ef"
},
{
"url": "https://git.kernel.org/stable/c/3068ab802fc98b121dcb451e1f7f4d338ffc7a19"
},
{
"url": "https://git.kernel.org/stable/c/b01df98a6669d2b67d8aed816021b327fd905998"
},
{
"url": "https://git.kernel.org/stable/c/afbe4bc252d90a6f8fad869b06d5430f615f22f9"
}
],
"title": "media: v4l2-ctrls: validate HEVC active reference counts",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68206",
"datePublished": "2026-08-10T12:00:25.309Z",
"dateReserved": "2026-07-30T09:28:09.374Z",
"dateUpdated": "2026-08-19T16:31:26.837Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74666 (GCVE-0-2026-74666)
Vulnerability from cvelistv5
Published
2026-08-22 15:32
Modified
2026-08-27 12:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
packet: synchronize pressure clearing with ring reconfiguration
packet_set_ring() updates the RX ring state under sk_receive_queue.lock,
but used to publish the tpacket receive mode through po->prot_hook.func
after releasing that lock. packet_poll() and packet_recvmsg() can then
run the pressure clearing path after the ring has been cleared while
still seeing tpacket_rcv, causing __packet_rcv_has_room() to dereference
stale or NULL ring storage.
Move the existing receive hook assignment into the same
sk_receive_queue.lock section as the ring state update. Keep the
assignment otherwise unchanged, including on TX ring reconfiguration, to
avoid adding behavior changes that are not required for the fix.
Serialize packet_recvmsg() pressure clearing with the same queue lock
only after PACKET_SOCK_PRESSURE has been observed. If the flag is clear
and the socket has moved away from tpacket_rcv, packet_set_ring() has
already detached the socket and waited for synchronize_net(), so no new
packet input can set the flag again.
packet_poll() already holds sk_receive_queue.lock, so it uses the new
unlocked helper directly.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 2ccdbaa6d55b0656244ba57c4b56765a0af76c0a Version: 2ccdbaa6d55b0656244ba57c4b56765a0af76c0a Version: 2ccdbaa6d55b0656244ba57c4b56765a0af76c0a Version: 2ccdbaa6d55b0656244ba57c4b56765a0af76c0a Version: 2ccdbaa6d55b0656244ba57c4b56765a0af76c0a Version: 2ccdbaa6d55b0656244ba57c4b56765a0af76c0a Version: 2ccdbaa6d55b0656244ba57c4b56765a0af76c0a Version: 2ccdbaa6d55b0656244ba57c4b56765a0af76c0a |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/packet/af_packet.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "bf3c8e86bc8ad111be3f3136125e255344bcb3da",
"status": "affected",
"version": "2ccdbaa6d55b0656244ba57c4b56765a0af76c0a",
"versionType": "git"
},
{
"lessThan": "8cfb2e71926a682f36c4240067d424074dd8f70f",
"status": "affected",
"version": "2ccdbaa6d55b0656244ba57c4b56765a0af76c0a",
"versionType": "git"
},
{
"lessThan": "f015c9de92b731814059a343b765c60c0196225c",
"status": "affected",
"version": "2ccdbaa6d55b0656244ba57c4b56765a0af76c0a",
"versionType": "git"
},
{
"lessThan": "cf8189b82bb93f219ab740e0346c919ad65ada62",
"status": "affected",
"version": "2ccdbaa6d55b0656244ba57c4b56765a0af76c0a",
"versionType": "git"
},
{
"lessThan": "ad740b4990347521f0db260d381f9f74e7b340ba",
"status": "affected",
"version": "2ccdbaa6d55b0656244ba57c4b56765a0af76c0a",
"versionType": "git"
},
{
"lessThan": "2c7b5eb87b2b288cdbde825f21d2b83b2f5da747",
"status": "affected",
"version": "2ccdbaa6d55b0656244ba57c4b56765a0af76c0a",
"versionType": "git"
},
{
"lessThan": "a08196c3cc105947746ec21309edfbb60275fcdb",
"status": "affected",
"version": "2ccdbaa6d55b0656244ba57c4b56765a0af76c0a",
"versionType": "git"
},
{
"lessThan": "1a35da325cac4d5bcad76a2aa943408a6f1d9000",
"status": "affected",
"version": "2ccdbaa6d55b0656244ba57c4b56765a0af76c0a",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/packet/af_packet.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.2"
},
{
"lessThan": "4.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.267",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.218",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.185",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.267",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.218",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.185",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\npacket: synchronize pressure clearing with ring reconfiguration\n\npacket_set_ring() updates the RX ring state under sk_receive_queue.lock,\nbut used to publish the tpacket receive mode through po-\u003eprot_hook.func\nafter releasing that lock. packet_poll() and packet_recvmsg() can then\nrun the pressure clearing path after the ring has been cleared while\nstill seeing tpacket_rcv, causing __packet_rcv_has_room() to dereference\nstale or NULL ring storage.\n\nMove the existing receive hook assignment into the same\nsk_receive_queue.lock section as the ring state update. Keep the\nassignment otherwise unchanged, including on TX ring reconfiguration, to\navoid adding behavior changes that are not required for the fix.\n\nSerialize packet_recvmsg() pressure clearing with the same queue lock\nonly after PACKET_SOCK_PRESSURE has been observed. If the flag is clear\nand the socket has moved away from tpacket_rcv, packet_set_ring() has\nalready detached the socket and waited for synchronize_net(), so no new\npacket input can set the flag again.\n\npacket_poll() already holds sk_receive_queue.lock, so it uses the new\nunlocked helper directly."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is hit only from local AF_PACKET syscalls\u2014setsockopt(PACKET_RX_RING) racing poll(2)/recvmsg(2) pressure clearing in packet_poll()/packet_recvmsg()\u2014not from remote packet receive paths like ksmbd, nfsd, or the TCP/IP stack.\nAC:L - The attacker controls both race sides: one thread polls/recvmsg while PACKET_SOCK_PRESSURE is set, another tears down the RX ring via PACKET_RX_RING; packet_set_ring()\u0027s synchronize_net() window makes the stale tpacket_rcv vs NULL/freed pg_vec mismatch reliably winnable.\nPR:L - packet_create() requires ns_capable(net-\u003euser_ns, CAP_NET_RAW); unprivileged users obtain CAP_NET_RAW via user+network namespaces (unshare -Urn) or container defaults (Docker NET_RAW), without init-namespace root.\nUI:N - No victim action is required; the attacker creates the AF_PACKET socket, configures the mmap RX ring, fills it to set PACKET_SOCK_PRESSURE, and races ring teardown against its own poll/recvmsg calls.\nS:U - Stale/NULL ring dereferences corrupt kernel heap state on the same host; this is standard kernel memory corruption within one security authority, not a VM escape, IOMMU bypass, or other cross-boundary scope change.\nC:H - __packet_rcv_has_room() follows tpacket_rcv and dereferences rb-\u003epg_vec or prb_bdqc block pointers after packet_set_ring() cleared/freed the ring, yielding NULL-dereference or use-after-free reads of ring metadata and mmap-backed pages.\nI:H - Freed ring storage and stale prb_bdqc/pkbdq pointers remain attacker-influenced through mmap and concurrent ring operations, providing a controllable kernel heap use-after-free write primitive typical of AF_PACKET ring reconfiguration races.\nA:H - NULL pg_vec indexing in packet_lookup_frame() or stale block access in prb_lookup_block() from the pressure-clearing path causes an immediate kernel oops/panic, giving any qualifying local attacker repeatable host-wide denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T12:40:00.544Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/bf3c8e86bc8ad111be3f3136125e255344bcb3da"
},
{
"url": "https://git.kernel.org/stable/c/8cfb2e71926a682f36c4240067d424074dd8f70f"
},
{
"url": "https://git.kernel.org/stable/c/f015c9de92b731814059a343b765c60c0196225c"
},
{
"url": "https://git.kernel.org/stable/c/cf8189b82bb93f219ab740e0346c919ad65ada62"
},
{
"url": "https://git.kernel.org/stable/c/ad740b4990347521f0db260d381f9f74e7b340ba"
},
{
"url": "https://git.kernel.org/stable/c/2c7b5eb87b2b288cdbde825f21d2b83b2f5da747"
},
{
"url": "https://git.kernel.org/stable/c/a08196c3cc105947746ec21309edfbb60275fcdb"
},
{
"url": "https://git.kernel.org/stable/c/1a35da325cac4d5bcad76a2aa943408a6f1d9000"
}
],
"title": "packet: synchronize pressure clearing with ring reconfiguration",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74666",
"datePublished": "2026-08-22T15:32:38.098Z",
"dateReserved": "2026-08-15T05:44:03.924Z",
"dateUpdated": "2026-08-27T12:40:00.544Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80863 (GCVE-0-2026-80863)
Vulnerability from cvelistv5
Published
2026-09-04 15:55
Modified
2026-09-04 15:55
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
RDMA/rxe: Fix OOB in free_rd_atomic_resources()
free_rd_atomic_resources() iterates using qp->attr.max_dest_rd_atomic.
Updating max_dest_rd_atomic before freeing the old array can make the
free path walk past the old allocation and trigger a slab out-of-bounds
write catched by KASAN:
==================================================================
BUG: KASAN: slab-out-of-bounds in free_rd_atomic_resource drivers/infiniband/sw/rxe/rxe_qp.c:180 [inline]
BUG: KASAN: slab-out-of-bounds in free_rd_atomic_resources drivers/infiniband/sw/rxe/rxe_qp.c:171 [inline]
BUG: KASAN: slab-out-of-bounds in free_rd_atomic_resources drivers/infiniband/sw/rxe/rxe_qp.c:163 [inline]
BUG: KASAN: slab-out-of-bounds in rxe_qp_from_attr+0x1e88/0x2150 drivers/infiniband/sw/rxe/rxe_qp.c:712
Write of size 4 at addr ffff88802b8dddb8 by task syz.3.451/11063
CPU: 0 UID: 0 PID: 11063 Comm: syz.3.451 Not tainted 7.1.0 #2 PREEMPT(full)
Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
Call Trace:
<TASK>
__dump_stack lib/dump_stack.c:94 [inline]
dump_stack_lvl+0x10e/0x1f0 lib/dump_stack.c:120
print_address_description mm/kasan/report.c:378 [inline]
print_report+0xf7/0x600 mm/kasan/report.c:482
kasan_report+0xe4/0x120 mm/kasan/report.c:595
free_rd_atomic_resource drivers/infiniband/sw/rxe/rxe_qp.c:180 [inline]
free_rd_atomic_resources drivers/infiniband/sw/rxe/rxe_qp.c:171 [inline]
free_rd_atomic_resources drivers/infiniband/sw/rxe/rxe_qp.c:163 [inline]
rxe_qp_from_attr+0x1e88/0x2150 drivers/infiniband/sw/rxe/rxe_qp.c:712
rxe_modify_qp+0x1e2/0x530 drivers/infiniband/sw/rxe/rxe_verbs.c:623
ib_security_modify_qp+0x223/0xfa0 drivers/infiniband/core/security.c:625
_ib_modify_qp+0x333/0xec0 drivers/infiniband/core/verbs.c:1915
modify_qp+0x13ca/0x1940 drivers/infiniband/core/uverbs_cmd.c:1932
ib_uverbs_modify_qp+0xcb/0x120 drivers/infiniband/core/uverbs_cmd.c:1958
ib_uverbs_write+0xb86/0x1030 drivers/infiniband/core/uverbs_main.c:680
vfs_write+0x2aa/0x1070 fs/read_write.c:686
ksys_write+0x1f8/0x250 fs/read_write.c:740
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0x116/0x800 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7fefc75a70cd
Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 90 f3 0f 1e fa 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b0 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007fefc8495018 EFLAGS: 00000246 ORIG_RAX: 0000000000000001
RAX: ffffffffffffffda RBX: 00007fefc7835fa0 RCX: 00007fefc75a70cd
RDX: 0000000000000078 RSI: 0000200000000240 RDI: 0000000000000007
RBP: 00007fefc764f10f R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 00007fefc7836038 R14: 00007fefc7835fa0 R15: 00007ffcf0586aa0
</TASK>
Allocated by task 11063:
kasan_save_stack+0x33/0x60 mm/kasan/common.c:57
kasan_save_track+0x14/0x30 mm/kasan/common.c:78
poison_kmalloc_redzone mm/kasan/common.c:398 [inline]
__kasan_kmalloc+0xaa/0xb0 mm/kasan/common.c:415
kasan_kmalloc include/linux/kasan.h:263 [inline]
__do_kmalloc_node mm/slub.c:5296 [inline]
__kmalloc_noprof+0x32a/0x850 mm/slub.c:5308
kmalloc_noprof include/linux/slab.h:954 [inline]
kzalloc_noprof include/linux/slab.h:1188 [inline]
alloc_rd_atomic_resources drivers/infiniband/sw/rxe/rxe_qp.c:155 [inline]
rxe_qp_from_attr+0x3f8/0x2150 drivers/infiniband/sw/rxe/rxe_qp.c:714
rxe_modify_qp+0x1e2/0x530 drivers/infiniband/sw/rxe/rxe_verbs.c:623
ib_security_modify_qp+0x223/0xfa0 drivers/infiniband/core/security.c:625
_ib_modify_qp+0x333/0xec0 drivers/infiniband/core/verbs.c:1915
modify_qp+0x13ca/0x1940 drivers/infiniband/core/uverbs_cmd.c:1932
ib_uverbs_modify_qp+0xcb/0x120 drivers/infiniband/core/uverbs_cmd.c:1958
ib_uverbs_write+0xb86/0x1030 drivers/infiniband/core/uverbs_ma
---truncated---
References
| URL | Tags | ||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: b6bbee0d2438a2c9c7525f5bd7047a8b2ce4f38f Version: b6bbee0d2438a2c9c7525f5bd7047a8b2ce4f38f Version: b6bbee0d2438a2c9c7525f5bd7047a8b2ce4f38f Version: b6bbee0d2438a2c9c7525f5bd7047a8b2ce4f38f Version: b6bbee0d2438a2c9c7525f5bd7047a8b2ce4f38f Version: b6bbee0d2438a2c9c7525f5bd7047a8b2ce4f38f Version: b6bbee0d2438a2c9c7525f5bd7047a8b2ce4f38f Version: b6bbee0d2438a2c9c7525f5bd7047a8b2ce4f38f Version: b6bbee0d2438a2c9c7525f5bd7047a8b2ce4f38f |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/sw/rxe/rxe_qp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "142c8165b7974b40fa62c393653edb5c00b8b5fe",
"status": "affected",
"version": "b6bbee0d2438a2c9c7525f5bd7047a8b2ce4f38f",
"versionType": "git"
},
{
"lessThan": "30b90b55201902b2b8edcdbe2315ccd4c7547002",
"status": "affected",
"version": "b6bbee0d2438a2c9c7525f5bd7047a8b2ce4f38f",
"versionType": "git"
},
{
"lessThan": "9b7d66ea88ae9395e42766b94a5c717b158b940a",
"status": "affected",
"version": "b6bbee0d2438a2c9c7525f5bd7047a8b2ce4f38f",
"versionType": "git"
},
{
"lessThan": "f5e6580a3a16a83c743ad5a7c16922854a0d8b71",
"status": "affected",
"version": "b6bbee0d2438a2c9c7525f5bd7047a8b2ce4f38f",
"versionType": "git"
},
{
"lessThan": "bc6e943794515d2a8417b02597a27bd377468d04",
"status": "affected",
"version": "b6bbee0d2438a2c9c7525f5bd7047a8b2ce4f38f",
"versionType": "git"
},
{
"lessThan": "bdf5deccfbf9f556a08d1d2ef52e9e48f969e53e",
"status": "affected",
"version": "b6bbee0d2438a2c9c7525f5bd7047a8b2ce4f38f",
"versionType": "git"
},
{
"lessThan": "4e5f753e8c280278c09f68fe728abf846e2bdfc1",
"status": "affected",
"version": "b6bbee0d2438a2c9c7525f5bd7047a8b2ce4f38f",
"versionType": "git"
},
{
"lessThan": "d219e7a8eed3802970c3e4d243d79c70ef0a31bf",
"status": "affected",
"version": "b6bbee0d2438a2c9c7525f5bd7047a8b2ce4f38f",
"versionType": "git"
},
{
"lessThan": "de329533792a373186d79dca1ca120f8fa0afd05",
"status": "affected",
"version": "b6bbee0d2438a2c9c7525f5bd7047a8b2ce4f38f",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/sw/rxe/rxe_qp.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.9"
},
{
"lessThan": "4.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.269",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.220",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.187",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.156",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.108",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.49",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.13",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.3",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.269",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.220",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.187",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.156",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.108",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.49",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.13",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.3",
"versionStartIncluding": "4.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "4.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/rxe: Fix OOB in free_rd_atomic_resources()\n\nfree_rd_atomic_resources() iterates using qp-\u003eattr.max_dest_rd_atomic.\nUpdating max_dest_rd_atomic before freeing the old array can make the\nfree path walk past the old allocation and trigger a slab out-of-bounds\nwrite catched by KASAN:\n==================================================================\nBUG: KASAN: slab-out-of-bounds in free_rd_atomic_resource drivers/infiniband/sw/rxe/rxe_qp.c:180 [inline]\nBUG: KASAN: slab-out-of-bounds in free_rd_atomic_resources drivers/infiniband/sw/rxe/rxe_qp.c:171 [inline]\nBUG: KASAN: slab-out-of-bounds in free_rd_atomic_resources drivers/infiniband/sw/rxe/rxe_qp.c:163 [inline]\nBUG: KASAN: slab-out-of-bounds in rxe_qp_from_attr+0x1e88/0x2150 drivers/infiniband/sw/rxe/rxe_qp.c:712\nWrite of size 4 at addr ffff88802b8dddb8 by task syz.3.451/11063\n\nCPU: 0 UID: 0 PID: 11063 Comm: syz.3.451 Not tainted 7.1.0 #2 PREEMPT(full)\nHardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\nCall Trace:\n \u003cTASK\u003e\n __dump_stack lib/dump_stack.c:94 [inline]\n dump_stack_lvl+0x10e/0x1f0 lib/dump_stack.c:120\n print_address_description mm/kasan/report.c:378 [inline]\n print_report+0xf7/0x600 mm/kasan/report.c:482\n kasan_report+0xe4/0x120 mm/kasan/report.c:595\n free_rd_atomic_resource drivers/infiniband/sw/rxe/rxe_qp.c:180 [inline]\n free_rd_atomic_resources drivers/infiniband/sw/rxe/rxe_qp.c:171 [inline]\n free_rd_atomic_resources drivers/infiniband/sw/rxe/rxe_qp.c:163 [inline]\n rxe_qp_from_attr+0x1e88/0x2150 drivers/infiniband/sw/rxe/rxe_qp.c:712\n rxe_modify_qp+0x1e2/0x530 drivers/infiniband/sw/rxe/rxe_verbs.c:623\n ib_security_modify_qp+0x223/0xfa0 drivers/infiniband/core/security.c:625\n _ib_modify_qp+0x333/0xec0 drivers/infiniband/core/verbs.c:1915\n modify_qp+0x13ca/0x1940 drivers/infiniband/core/uverbs_cmd.c:1932\n ib_uverbs_modify_qp+0xcb/0x120 drivers/infiniband/core/uverbs_cmd.c:1958\n ib_uverbs_write+0xb86/0x1030 drivers/infiniband/core/uverbs_main.c:680\n vfs_write+0x2aa/0x1070 fs/read_write.c:686\n ksys_write+0x1f8/0x250 fs/read_write.c:740\n do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]\n do_syscall_64+0x116/0x800 arch/x86/entry/syscall_64.c:94\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\nRIP: 0033:0x7fefc75a70cd\nCode: ff c3 66 2e 0f 1f 84 00 00 00 00 00 90 f3 0f 1e fa 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 \u003c48\u003e 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b0 ff ff ff f7 d8 64 89 01 48\nRSP: 002b:00007fefc8495018 EFLAGS: 00000246 ORIG_RAX: 0000000000000001\nRAX: ffffffffffffffda RBX: 00007fefc7835fa0 RCX: 00007fefc75a70cd\nRDX: 0000000000000078 RSI: 0000200000000240 RDI: 0000000000000007\nRBP: 00007fefc764f10f R08: 0000000000000000 R09: 0000000000000000\nR10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000\nR13: 00007fefc7836038 R14: 00007fefc7835fa0 R15: 00007ffcf0586aa0\n \u003c/TASK\u003e\n\nAllocated by task 11063:\n kasan_save_stack+0x33/0x60 mm/kasan/common.c:57\n kasan_save_track+0x14/0x30 mm/kasan/common.c:78\n poison_kmalloc_redzone mm/kasan/common.c:398 [inline]\n __kasan_kmalloc+0xaa/0xb0 mm/kasan/common.c:415\n kasan_kmalloc include/linux/kasan.h:263 [inline]\n __do_kmalloc_node mm/slub.c:5296 [inline]\n __kmalloc_noprof+0x32a/0x850 mm/slub.c:5308\n kmalloc_noprof include/linux/slab.h:954 [inline]\n kzalloc_noprof include/linux/slab.h:1188 [inline]\n alloc_rd_atomic_resources drivers/infiniband/sw/rxe/rxe_qp.c:155 [inline]\n rxe_qp_from_attr+0x3f8/0x2150 drivers/infiniband/sw/rxe/rxe_qp.c:714\n rxe_modify_qp+0x1e2/0x530 drivers/infiniband/sw/rxe/rxe_verbs.c:623\n ib_security_modify_qp+0x223/0xfa0 drivers/infiniband/core/security.c:625\n _ib_modify_qp+0x333/0xec0 drivers/infiniband/core/verbs.c:1915\n modify_qp+0x13ca/0x1940 drivers/infiniband/core/uverbs_cmd.c:1932\n ib_uverbs_modify_qp+0xcb/0x120 drivers/infiniband/core/uverbs_cmd.c:1958\n ib_uverbs_write+0xb86/0x1030 drivers/infiniband/core/uverbs_ma\n---truncated---"
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T15:55:17.668Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/142c8165b7974b40fa62c393653edb5c00b8b5fe"
},
{
"url": "https://git.kernel.org/stable/c/30b90b55201902b2b8edcdbe2315ccd4c7547002"
},
{
"url": "https://git.kernel.org/stable/c/9b7d66ea88ae9395e42766b94a5c717b158b940a"
},
{
"url": "https://git.kernel.org/stable/c/f5e6580a3a16a83c743ad5a7c16922854a0d8b71"
},
{
"url": "https://git.kernel.org/stable/c/bc6e943794515d2a8417b02597a27bd377468d04"
},
{
"url": "https://git.kernel.org/stable/c/bdf5deccfbf9f556a08d1d2ef52e9e48f969e53e"
},
{
"url": "https://git.kernel.org/stable/c/4e5f753e8c280278c09f68fe728abf846e2bdfc1"
},
{
"url": "https://git.kernel.org/stable/c/d219e7a8eed3802970c3e4d243d79c70ef0a31bf"
},
{
"url": "https://git.kernel.org/stable/c/de329533792a373186d79dca1ca120f8fa0afd05"
}
],
"title": "RDMA/rxe: Fix OOB in free_rd_atomic_resources()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80863",
"datePublished": "2026-09-04T15:55:17.668Z",
"dateReserved": "2026-08-26T14:34:25.798Z",
"dateUpdated": "2026-09-04T15:55:17.668Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74631 (GCVE-0-2026-74631)
Vulnerability from cvelistv5
Published
2026-08-22 15:32
Modified
2026-08-25 05:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: smc: fix splice entry lifetime imbalance in smc_rx_splice
smc_rx_splice() passes pages to splice_to_pipe() before taking the
references that cover the lifetime of each splice entry. In the
VM-backed RMB path, splice_to_pipe() may drop unqueued entries through
smc_rx_spd_release(), while queued entries are released later via the
pipe buffer callback.
The old post-splice accounting also derives the number of queued VM pages
from an offset mutated while building the descriptor, and a multi-page
splice pairs one sock_hold() with multiple sock_put() calls.
Take the page and socket references for every candidate entry before
splice_to_pipe(), and drop the matching private state, page reference,
and socket reference from smc_rx_spd_release() for entries that never
get queued. This fixes a refcount imbalance that can underflow page
refcounts and trigger a use-after-free.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 9014db202cb764b8e14c53e7bacc81f9a1a2ba7f Version: 9014db202cb764b8e14c53e7bacc81f9a1a2ba7f Version: 9014db202cb764b8e14c53e7bacc81f9a1a2ba7f Version: 9014db202cb764b8e14c53e7bacc81f9a1a2ba7f Version: 9014db202cb764b8e14c53e7bacc81f9a1a2ba7f Version: 9014db202cb764b8e14c53e7bacc81f9a1a2ba7f Version: 9014db202cb764b8e14c53e7bacc81f9a1a2ba7f Version: 9014db202cb764b8e14c53e7bacc81f9a1a2ba7f |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/smc/smc_rx.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "7ddc7af2ae7fc5a0c0635b245c0824c8b76de5cb",
"status": "affected",
"version": "9014db202cb764b8e14c53e7bacc81f9a1a2ba7f",
"versionType": "git"
},
{
"lessThan": "07ad246529d136d5ef441d5ab4c305d132ff3090",
"status": "affected",
"version": "9014db202cb764b8e14c53e7bacc81f9a1a2ba7f",
"versionType": "git"
},
{
"lessThan": "c841789e456ec6751342fa800639ce8e82ff0e6b",
"status": "affected",
"version": "9014db202cb764b8e14c53e7bacc81f9a1a2ba7f",
"versionType": "git"
},
{
"lessThan": "af02c67ce654356c58db20a0bb2db33ace3b07a8",
"status": "affected",
"version": "9014db202cb764b8e14c53e7bacc81f9a1a2ba7f",
"versionType": "git"
},
{
"lessThan": "ca8342b5fc24c249fdb998468f6a168b457c67e5",
"status": "affected",
"version": "9014db202cb764b8e14c53e7bacc81f9a1a2ba7f",
"versionType": "git"
},
{
"lessThan": "0b7d54cedea5cb158e21925ae0c6c2f5c87ed2a0",
"status": "affected",
"version": "9014db202cb764b8e14c53e7bacc81f9a1a2ba7f",
"versionType": "git"
},
{
"lessThan": "4515c78f4d9fd577270f012efeb062ea58b3682d",
"status": "affected",
"version": "9014db202cb764b8e14c53e7bacc81f9a1a2ba7f",
"versionType": "git"
},
{
"lessThan": "5d9686af2976741bbd79b150d1c9e60b81e7f12e",
"status": "affected",
"version": "9014db202cb764b8e14c53e7bacc81f9a1a2ba7f",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/smc/smc_rx.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.18"
},
{
"lessThan": "4.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.18",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: smc: fix splice entry lifetime imbalance in smc_rx_splice\n\nsmc_rx_splice() passes pages to splice_to_pipe() before taking the\nreferences that cover the lifetime of each splice entry. In the\nVM-backed RMB path, splice_to_pipe() may drop unqueued entries through\nsmc_rx_spd_release(), while queued entries are released later via the\npipe buffer callback.\n\nThe old post-splice accounting also derives the number of queued VM pages\nfrom an offset mutated while building the descriptor, and a multi-page\nsplice pairs one sock_hold() with multiple sock_put() calls.\n\nTake the page and socket references for every candidate entry before\nsplice_to_pipe(), and drop the matching private state, page reference,\nand socket reference from smc_rx_spd_release() for entries that never\nget queued. This fixes a refcount imbalance that can underflow page\nrefcounts and trigger a use-after-free."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.4,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - smc_rx_splice is only reached via splice()/tee() on an SMC socket FD (syscall -\u003e smc_splice_read -\u003e smc_rx_recvmsg with pipe set); remote SMC peers can supply receive-buffer data but cannot execute the vulnerable splice path without a local process invoking splice on that socket.\nAC:L - The attacker controls splice length, can nearly fill the destination pipe to force splice_to_pipe to drop unqueued entries via smc_rx_spd_release, and can hit the multi-page VM-backed RMB path (smcr_buf_type or mixed-buffer vmalloc fallback); no timing race or external victim state is required.\nPR:N - Exploitation requires only completing an SMC session as a network peer to a victim that reads with splice (common zero-copy SMC pattern); no local account, capabilities, or namespace-admin rights on the victim host are needed beyond normal remote connectivity to the SMC service.\nUI:N - No per-exploit victim action is needed beyond an application already using splice on SMC receive; a malicious peer can deliver the receive data while the victim\u0027s normal automated splice path triggers the refcount imbalance without prompts or manual steps.\nS:U - Impact is kernel page refcount underflow and use-after-free within the same kernel security boundary, enabling privilege escalation or crash on the host; it does not cross VM, IOMMU, or sandbox authority boundaries.\nC:H - Refcount imbalance lets smc_rx_spd_release and pipe-buffer teardown free pages while still referenced, creating a UAF on RMB pages that can be turned into arbitrary kernel memory disclosure via heap reuse and spraying.\nI:H - Corrupted page lifetime and dangling pipe_buffer state enable heap metadata corruption and arbitrary kernel writes from the UAF primitive, supporting control-flow hijacking and local privilege escalation.\nA:H - Page refcount underflow and UAF during splice teardown can cause immediate kernel oops/panic; repeated splice from an SMC peer reliably triggers denial-of-service even when full exploitation is not attempted."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:40:55.722Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/7ddc7af2ae7fc5a0c0635b245c0824c8b76de5cb"
},
{
"url": "https://git.kernel.org/stable/c/07ad246529d136d5ef441d5ab4c305d132ff3090"
},
{
"url": "https://git.kernel.org/stable/c/c841789e456ec6751342fa800639ce8e82ff0e6b"
},
{
"url": "https://git.kernel.org/stable/c/af02c67ce654356c58db20a0bb2db33ace3b07a8"
},
{
"url": "https://git.kernel.org/stable/c/ca8342b5fc24c249fdb998468f6a168b457c67e5"
},
{
"url": "https://git.kernel.org/stable/c/0b7d54cedea5cb158e21925ae0c6c2f5c87ed2a0"
},
{
"url": "https://git.kernel.org/stable/c/4515c78f4d9fd577270f012efeb062ea58b3682d"
},
{
"url": "https://git.kernel.org/stable/c/5d9686af2976741bbd79b150d1c9e60b81e7f12e"
}
],
"title": "net: smc: fix splice entry lifetime imbalance in smc_rx_splice",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74631",
"datePublished": "2026-08-22T15:32:12.334Z",
"dateReserved": "2026-08-15T05:44:03.922Z",
"dateUpdated": "2026-08-25T05:40:55.722Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64580 (GCVE-0-2026-64580)
Vulnerability from cvelistv5
Published
2026-08-05 08:09
Modified
2026-08-19 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
xfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst()
On the error path where in6_dev_get(dev) returns NULL, xfrm6_fill_dst()
releases the device reference with netdev_put() but leaves
xdst->u.dst.dev set. dst_destroy() later calls netdev_put(dst->dev)
again, so the same net_device reference is released twice, underflowing
its refcount (ref_tracker WARNING + "unregister_netdevice: waiting for
<dev> to become free").
Clear xdst->u.dst.dev after the netdev_put(), the same way the XFRM
device-offload paths xfrm_dev_state_add() and xfrm_dev_policy_add() in
net/xfrm/xfrm_device.c NULL ->dev when releasing the reference on error.
ref_tracker: reference already released.
ref_tracker: allocated in:
xfrm6_fill_dst (net/ipv6/xfrm6_policy.c:86)
...
udpv6_sendmsg (net/ipv6/udp.c:1696)
...
ref_tracker: freed in:
xfrm6_fill_dst (net/ipv6/xfrm6_policy.c:90)
...
WARNING: lib/ref_tracker.c:322 at ref_tracker_free+0x58b/0x780
dst_destroy (net/core/dst.c:115)
rcu_core
handle_softirqs
...
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 84c4a9dfbf430861e7588d95ae3ff61535dca351 Version: 84c4a9dfbf430861e7588d95ae3ff61535dca351 Version: 84c4a9dfbf430861e7588d95ae3ff61535dca351 Version: 84c4a9dfbf430861e7588d95ae3ff61535dca351 Version: 84c4a9dfbf430861e7588d95ae3ff61535dca351 Version: 84c4a9dfbf430861e7588d95ae3ff61535dca351 Version: a7e22d0c0e81dde129a51ee413644124f4b59954 Version: 01b0d887f67a388fb2a658ee2bdd74e5ba146818 Version: a98124aac0b5adc5de8ae54f11322781cb4d85c3 Version: e27b7bee743d921f037b1da6f071237345bef7c1 Version: 3.0.79 ≤ Version: 3.2.46 ≤ Version: 3.4.46 ≤ Version: 3.9.3 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/ipv6/xfrm6_policy.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "97e032e5733e49471fb73de117ea2ac1ac7c479a",
"status": "affected",
"version": "84c4a9dfbf430861e7588d95ae3ff61535dca351",
"versionType": "git"
},
{
"lessThan": "df6856c2dda9187601d29b5fbd7a81b3b178cedf",
"status": "affected",
"version": "84c4a9dfbf430861e7588d95ae3ff61535dca351",
"versionType": "git"
},
{
"lessThan": "43de8a49335e611adb271bbd52e84dfbc11fc185",
"status": "affected",
"version": "84c4a9dfbf430861e7588d95ae3ff61535dca351",
"versionType": "git"
},
{
"lessThan": "ff636d7b7cba6dea82ecf580415ea57f2c1a11b6",
"status": "affected",
"version": "84c4a9dfbf430861e7588d95ae3ff61535dca351",
"versionType": "git"
},
{
"lessThan": "e078da1b4e11390cff3201c19a9a1fe70c5b934f",
"status": "affected",
"version": "84c4a9dfbf430861e7588d95ae3ff61535dca351",
"versionType": "git"
},
{
"lessThan": "136992de9bb91871084ae52d172610541c76e4d2",
"status": "affected",
"version": "84c4a9dfbf430861e7588d95ae3ff61535dca351",
"versionType": "git"
},
{
"status": "affected",
"version": "a7e22d0c0e81dde129a51ee413644124f4b59954",
"versionType": "git"
},
{
"status": "affected",
"version": "01b0d887f67a388fb2a658ee2bdd74e5ba146818",
"versionType": "git"
},
{
"status": "affected",
"version": "a98124aac0b5adc5de8ae54f11322781cb4d85c3",
"versionType": "git"
},
{
"status": "affected",
"version": "e27b7bee743d921f037b1da6f071237345bef7c1",
"versionType": "git"
},
{
"lessThan": "3.1",
"status": "affected",
"version": "3.0.79",
"versionType": "semver"
},
{
"lessThan": "3.3",
"status": "affected",
"version": "3.2.46",
"versionType": "semver"
},
{
"lessThan": "3.5",
"status": "affected",
"version": "3.4.46",
"versionType": "semver"
},
{
"lessThan": "3.10",
"status": "affected",
"version": "3.9.3",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/ipv6/xfrm6_policy.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.10"
},
{
"lessThan": "3.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.0.79",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.2.46",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.4.46",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.9.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst()\n\nOn the error path where in6_dev_get(dev) returns NULL, xfrm6_fill_dst()\nreleases the device reference with netdev_put() but leaves\nxdst-\u003eu.dst.dev set. dst_destroy() later calls netdev_put(dst-\u003edev)\nagain, so the same net_device reference is released twice, underflowing\nits refcount (ref_tracker WARNING + \"unregister_netdevice: waiting for\n\u003cdev\u003e to become free\").\n\nClear xdst-\u003eu.dst.dev after the netdev_put(), the same way the XFRM\ndevice-offload paths xfrm_dev_state_add() and xfrm_dev_policy_add() in\nnet/xfrm/xfrm_device.c NULL -\u003edev when releasing the reference on error.\n\n ref_tracker: reference already released.\n ref_tracker: allocated in:\n xfrm6_fill_dst (net/ipv6/xfrm6_policy.c:86)\n ...\n udpv6_sendmsg (net/ipv6/udp.c:1696)\n ...\n ref_tracker: freed in:\n xfrm6_fill_dst (net/ipv6/xfrm6_policy.c:90)\n ...\n WARNING: lib/ref_tracker.c:322 at ref_tracker_free+0x58b/0x780\n dst_destroy (net/core/dst.c:115)\n rcu_core\n handle_softirqs\n ..."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached on the local IPv6 outbound path (udpv6_sendmsg \u2192 xfrm_lookup \u2192 xfrm6_fill_dst) after configuring XFRM policy/state via netlink or IPV6_XFRM_POLICY; a remote peer cannot drive that configuration or the device state that makes in6_dev_get fail.\nAC:L - An attacker in their own netns can create interfaces, install IPv6 XFRM policy/state, generate matching UDP traffic, and concurrently drop MTU below IPV6_MIN_MTU or unregister the device to clear ip6_ptr, so they control both sides of the window that hits the error path; once entered, the double netdev_put is deterministic.\nPR:L - XFRM configuration requires CAP_NET_ADMIN via netlink_net_capable/sockopt_ns_capable, which is ns_capable() in the netns user_ns, so an unprivileged user obtains it with unshare -Urn rather than real init-namespace root.\nUI:N - No victim action is required; the attacker configures XFRM, manipulates their own netdevs, and sends packets entirely with their own processes.\nS:U - The impact is kernel net_device refcount corruption within the same host kernel authority; this is ordinary local privilege-escalation/DoS territory, not a VM escape or IOMMU/sandbox boundary cross.\nC:H - The leftover dst.dev causes a second netdev_put in dst_destroy, underflowing the net_device refcount and enabling use-after-free of the device object, which per kernel UAF guidance yields a high confidentiality/info-disclosure primitive.\nI:H - A net_device refcount underflow/UAF is heap memory corruption that can be shaped via reuse/spraying into arbitrary write or control-flow hijack, so integrity impact is high.\nA:H - Even without full exploitation, the double put triggers ref_tracker warnings and can oops/panic or hang device unregister (unregister_netdevice waiting for the device to become free), so availability impact is high."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:29:07.038Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/97e032e5733e49471fb73de117ea2ac1ac7c479a"
},
{
"url": "https://git.kernel.org/stable/c/df6856c2dda9187601d29b5fbd7a81b3b178cedf"
},
{
"url": "https://git.kernel.org/stable/c/43de8a49335e611adb271bbd52e84dfbc11fc185"
},
{
"url": "https://git.kernel.org/stable/c/ff636d7b7cba6dea82ecf580415ea57f2c1a11b6"
},
{
"url": "https://git.kernel.org/stable/c/e078da1b4e11390cff3201c19a9a1fe70c5b934f"
},
{
"url": "https://git.kernel.org/stable/c/136992de9bb91871084ae52d172610541c76e4d2"
}
],
"title": "xfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64580",
"datePublished": "2026-08-05T08:09:34.946Z",
"dateReserved": "2026-07-19T15:36:31.798Z",
"dateUpdated": "2026-08-19T16:29:07.038Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80767 (GCVE-0-2026-80767)
Vulnerability from cvelistv5
Published
2026-09-04 15:12
Modified
2026-09-04 15:12
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
HID: sensor: custom: Fix use-after-free in enable_sensor
enable_sensor_store() can call set_power_report_state(), which
dereferences sensor_inst->power_state and sensor_inst->report_state.
These pointers refer to entries in sensor_inst->fields.
Create the field attributes before exposing the enable_sensor sysfs
attribute, so enable_sensor cannot be accessed before the state it
depends on has been initialized.
On remove, delete enable_sensor before freeing the field attributes,
so a concurrent sysfs write cannot dereference freed memory through
power_state or report_state.
References
| URL | Tags | ||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 4a7de0519df5e8fb89cef6ee062330ffe4b50a4d Version: 4a7de0519df5e8fb89cef6ee062330ffe4b50a4d Version: 4a7de0519df5e8fb89cef6ee062330ffe4b50a4d Version: 4a7de0519df5e8fb89cef6ee062330ffe4b50a4d Version: 4a7de0519df5e8fb89cef6ee062330ffe4b50a4d Version: 4a7de0519df5e8fb89cef6ee062330ffe4b50a4d Version: 4a7de0519df5e8fb89cef6ee062330ffe4b50a4d Version: 4a7de0519df5e8fb89cef6ee062330ffe4b50a4d Version: 4a7de0519df5e8fb89cef6ee062330ffe4b50a4d |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/hid/hid-sensor-custom.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c2be74b0272b7f8f60739e7aaf0d36c0befe7136",
"status": "affected",
"version": "4a7de0519df5e8fb89cef6ee062330ffe4b50a4d",
"versionType": "git"
},
{
"lessThan": "d7cbea1d342a16ec96d9eb3d7bd0ba2d4b2f2855",
"status": "affected",
"version": "4a7de0519df5e8fb89cef6ee062330ffe4b50a4d",
"versionType": "git"
},
{
"lessThan": "d37ff4e3635c18af907f25712596f8ccec323751",
"status": "affected",
"version": "4a7de0519df5e8fb89cef6ee062330ffe4b50a4d",
"versionType": "git"
},
{
"lessThan": "2ce90cfc6646a32100feabd7110ae0352aa01167",
"status": "affected",
"version": "4a7de0519df5e8fb89cef6ee062330ffe4b50a4d",
"versionType": "git"
},
{
"lessThan": "244a1cb638370490ed74a8adb5cc3f1212602e32",
"status": "affected",
"version": "4a7de0519df5e8fb89cef6ee062330ffe4b50a4d",
"versionType": "git"
},
{
"lessThan": "8406d4b69d48bc72fb6f8812a65a17a1f903440b",
"status": "affected",
"version": "4a7de0519df5e8fb89cef6ee062330ffe4b50a4d",
"versionType": "git"
},
{
"lessThan": "c0757f10610542d763bd0bf9bda455b78afeef0b",
"status": "affected",
"version": "4a7de0519df5e8fb89cef6ee062330ffe4b50a4d",
"versionType": "git"
},
{
"lessThan": "7bb79a3cf45e0805aef74457e19deb77e18cf196",
"status": "affected",
"version": "4a7de0519df5e8fb89cef6ee062330ffe4b50a4d",
"versionType": "git"
},
{
"lessThan": "ad8fb82b04422f49530d2aa2753cc81d1c60102c",
"status": "affected",
"version": "4a7de0519df5e8fb89cef6ee062330ffe4b50a4d",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/hid/hid-sensor-custom.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.1"
},
{
"lessThan": "4.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.267",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.218",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.185",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.154",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.106",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.47",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.1",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.267",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.218",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.185",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.154",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.106",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.47",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.11",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.1",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "4.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: sensor: custom: Fix use-after-free in enable_sensor\n\nenable_sensor_store() can call set_power_report_state(), which\ndereferences sensor_inst-\u003epower_state and sensor_inst-\u003ereport_state.\nThese pointers refer to entries in sensor_inst-\u003efields.\n\nCreate the field attributes before exposing the enable_sensor sysfs\nattribute, so enable_sensor cannot be accessed before the state it\ndepends on has been initialized.\n\nOn remove, delete enable_sensor before freeing the field attributes,\nso a concurrent sysfs write cannot dereference freed memory through\npower_state or report_state."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T15:12:39.363Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c2be74b0272b7f8f60739e7aaf0d36c0befe7136"
},
{
"url": "https://git.kernel.org/stable/c/d7cbea1d342a16ec96d9eb3d7bd0ba2d4b2f2855"
},
{
"url": "https://git.kernel.org/stable/c/d37ff4e3635c18af907f25712596f8ccec323751"
},
{
"url": "https://git.kernel.org/stable/c/2ce90cfc6646a32100feabd7110ae0352aa01167"
},
{
"url": "https://git.kernel.org/stable/c/244a1cb638370490ed74a8adb5cc3f1212602e32"
},
{
"url": "https://git.kernel.org/stable/c/8406d4b69d48bc72fb6f8812a65a17a1f903440b"
},
{
"url": "https://git.kernel.org/stable/c/c0757f10610542d763bd0bf9bda455b78afeef0b"
},
{
"url": "https://git.kernel.org/stable/c/7bb79a3cf45e0805aef74457e19deb77e18cf196"
},
{
"url": "https://git.kernel.org/stable/c/ad8fb82b04422f49530d2aa2753cc81d1c60102c"
}
],
"title": "HID: sensor: custom: Fix use-after-free in enable_sensor",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80767",
"datePublished": "2026-09-04T15:12:39.363Z",
"dateReserved": "2026-08-26T14:34:25.791Z",
"dateUpdated": "2026-09-04T15:12:39.363Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64192 (GCVE-0-2026-64192)
Vulnerability from cvelistv5
Published
2026-07-20 16:27
Modified
2026-08-23 12:45
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized
When CONFIG_BPF_LSM=y is set, BPF inode storage maps
(BPF_MAP_TYPE_INODE_STORAGE) are compiled into the kernel. However,
if the BPF LSM is not explicitly enabled at boot time (e.g. omitted
from the "lsm=" boot parameter), lsm_prepare() is never executed for
the BPF LSM.
Consequently, the BPF inode security blob offset
(bpf_lsm_blob_sizes.lbs_inode) is never initialized and remains at
its default compiled size of 8 bytes instead of being updated to a
valid offset past the reserved struct rcu_head (typically 16 bytes
or more).
When a privileged user creates and updates a BPF_MAP_TYPE_INODE_STORAGE
map, bpf_inode() evaluates inode->i_security + 8. This erroneously
aliases the struct rcu_head.func callback pointer at the beginning
of the inode->i_security blob. During subsequent map element cleanup
or inode destruction, writing NULL to owner_storage clears the queued
RCU callback pointer. When rcu_do_batch() later executes the queued
callback, it attempts an instruction fetch at address 0x0, triggering
an immediate kernel panic.
Fix this by introducing a global bpf_lsm_initialized boolean flag
marked with __ro_after_init. Set this flag to true inside bpf_lsm_init()
when the LSM framework successfully registers the BPF LSM. Gate map
allocation in inode_storage_map_alloc() on this flag, returning
-EOPNOTSUPP if the BPF LSM is in turn uninitialized.
This fail-fast approach prevents userspace from allocating inode
storage maps when the supporting BPF LSM infrastructure is absent,
avoiding zombie map states.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 8ea636848aca35b9f97c5b5dee30225cf2dd0fe6 Version: 8ea636848aca35b9f97c5b5dee30225cf2dd0fe6 Version: 8ea636848aca35b9f97c5b5dee30225cf2dd0fe6 Version: 8ea636848aca35b9f97c5b5dee30225cf2dd0fe6 Version: 8ea636848aca35b9f97c5b5dee30225cf2dd0fe6 Version: 8ea636848aca35b9f97c5b5dee30225cf2dd0fe6 Version: 8ea636848aca35b9f97c5b5dee30225cf2dd0fe6 Version: 8ea636848aca35b9f97c5b5dee30225cf2dd0fe6 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"include/linux/bpf_lsm.h",
"kernel/bpf/bpf_inode_storage.c",
"security/bpf/hooks.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "413b14b9623a2e6ee131c2b2152b304aeb04e378",
"status": "affected",
"version": "8ea636848aca35b9f97c5b5dee30225cf2dd0fe6",
"versionType": "git"
},
{
"lessThan": "a6d634f794c808a261eac7d5af023a7e06b9ecd8",
"status": "affected",
"version": "8ea636848aca35b9f97c5b5dee30225cf2dd0fe6",
"versionType": "git"
},
{
"lessThan": "721f669853bdbf46b475a81bb5d05d610f8c19de",
"status": "affected",
"version": "8ea636848aca35b9f97c5b5dee30225cf2dd0fe6",
"versionType": "git"
},
{
"lessThan": "5337eebdf8c5d4810b1913047f078d2815d5645f",
"status": "affected",
"version": "8ea636848aca35b9f97c5b5dee30225cf2dd0fe6",
"versionType": "git"
},
{
"lessThan": "de984ea883405420fdc416ae8964b752df586970",
"status": "affected",
"version": "8ea636848aca35b9f97c5b5dee30225cf2dd0fe6",
"versionType": "git"
},
{
"lessThan": "267fdd9b6530c399dfd996e1a0a7628b45baf9f0",
"status": "affected",
"version": "8ea636848aca35b9f97c5b5dee30225cf2dd0fe6",
"versionType": "git"
},
{
"lessThan": "c76b8abce575e0c6e4096957220b4515ed847d89",
"status": "affected",
"version": "8ea636848aca35b9f97c5b5dee30225cf2dd0fe6",
"versionType": "git"
},
{
"lessThan": "a6f0643e4f63cfaa0d5d4a69de4f132eac4b8fe4",
"status": "affected",
"version": "8ea636848aca35b9f97c5b5dee30225cf2dd0fe6",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"include/linux/bpf_lsm.h",
"kernel/bpf/bpf_inode_storage.c",
"security/bpf/hooks.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.10"
},
{
"lessThan": "5.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "5.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized\n\nWhen CONFIG_BPF_LSM=y is set, BPF inode storage maps\n(BPF_MAP_TYPE_INODE_STORAGE) are compiled into the kernel. However,\nif the BPF LSM is not explicitly enabled at boot time (e.g. omitted\nfrom the \"lsm=\" boot parameter), lsm_prepare() is never executed for\nthe BPF LSM.\n\nConsequently, the BPF inode security blob offset\n(bpf_lsm_blob_sizes.lbs_inode) is never initialized and remains at\nits default compiled size of 8 bytes instead of being updated to a\nvalid offset past the reserved struct rcu_head (typically 16 bytes\nor more).\n\nWhen a privileged user creates and updates a BPF_MAP_TYPE_INODE_STORAGE\nmap, bpf_inode() evaluates inode-\u003ei_security + 8. This erroneously\naliases the struct rcu_head.func callback pointer at the beginning\nof the inode-\u003ei_security blob. During subsequent map element cleanup\nor inode destruction, writing NULL to owner_storage clears the queued\nRCU callback pointer. When rcu_do_batch() later executes the queued\ncallback, it attempts an instruction fetch at address 0x0, triggering\nan immediate kernel panic.\n\nFix this by introducing a global bpf_lsm_initialized boolean flag\nmarked with __ro_after_init. Set this flag to true inside bpf_lsm_init()\nwhen the LSM framework successfully registers the BPF LSM. Gate map\nallocation in inode_storage_map_alloc() on this flag, returning\n-EOPNOTSUPP if the BPF LSM is in turn uninitialized.\n\nThis fail-fast approach prevents userspace from allocating inode\nstorage maps when the supporting BPF LSM infrastructure is absent,\navoiding zombie map states."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:45:34.754Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/413b14b9623a2e6ee131c2b2152b304aeb04e378"
},
{
"url": "https://git.kernel.org/stable/c/a6d634f794c808a261eac7d5af023a7e06b9ecd8"
},
{
"url": "https://git.kernel.org/stable/c/721f669853bdbf46b475a81bb5d05d610f8c19de"
},
{
"url": "https://git.kernel.org/stable/c/5337eebdf8c5d4810b1913047f078d2815d5645f"
},
{
"url": "https://git.kernel.org/stable/c/de984ea883405420fdc416ae8964b752df586970"
},
{
"url": "https://git.kernel.org/stable/c/267fdd9b6530c399dfd996e1a0a7628b45baf9f0"
},
{
"url": "https://git.kernel.org/stable/c/c76b8abce575e0c6e4096957220b4515ed847d89"
},
{
"url": "https://git.kernel.org/stable/c/a6f0643e4f63cfaa0d5d4a69de4f132eac4b8fe4"
}
],
"title": "bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64192",
"datePublished": "2026-07-20T16:27:51.720Z",
"dateReserved": "2026-07-19T07:54:57.040Z",
"dateUpdated": "2026-08-23T12:45:34.754Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68269 (GCVE-0-2026-68269)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-19 16:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/i915/gem: Add missing nospec on parallel submit slot
Add missing Spectre mitigation for userspace controlled parallel
submission slot.
Discovered using AI-assisted static analysis confirmed by Intel
Product Security.
(cherry picked from commit 15b9353deff3cf72331c387780de3cf9c316b643)
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: e5e32171a2cf1e434d4f88e12467f3e47d0ec618 Version: e5e32171a2cf1e434d4f88e12467f3e47d0ec618 Version: e5e32171a2cf1e434d4f88e12467f3e47d0ec618 Version: e5e32171a2cf1e434d4f88e12467f3e47d0ec618 Version: e5e32171a2cf1e434d4f88e12467f3e47d0ec618 Version: e5e32171a2cf1e434d4f88e12467f3e47d0ec618 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/i915/gem/i915_gem_context.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "0ac3bab10c62997727a0a90f819a27d337347f93",
"status": "affected",
"version": "e5e32171a2cf1e434d4f88e12467f3e47d0ec618",
"versionType": "git"
},
{
"lessThan": "4a27275d275971c9ea29d3d240ea4a224ad368a2",
"status": "affected",
"version": "e5e32171a2cf1e434d4f88e12467f3e47d0ec618",
"versionType": "git"
},
{
"lessThan": "be393175306694de5da1d1a23a8ea4149baa09f1",
"status": "affected",
"version": "e5e32171a2cf1e434d4f88e12467f3e47d0ec618",
"versionType": "git"
},
{
"lessThan": "45db277b2e1e34bcc99a0852026791108339ec3e",
"status": "affected",
"version": "e5e32171a2cf1e434d4f88e12467f3e47d0ec618",
"versionType": "git"
},
{
"lessThan": "c41a54619e95f860bf2950dd679ab353380ecd2b",
"status": "affected",
"version": "e5e32171a2cf1e434d4f88e12467f3e47d0ec618",
"versionType": "git"
},
{
"lessThan": "914a76a9f08366434bf595700f62026b7a19a9cc",
"status": "affected",
"version": "e5e32171a2cf1e434d4f88e12467f3e47d0ec618",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/i915/gem/i915_gem_context.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.16"
},
{
"lessThan": "5.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.16",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/i915/gem: Add missing nospec on parallel submit slot\n\nAdd missing Spectre mitigation for userspace controlled parallel\nsubmission slot.\n\nDiscovered using AI-assisted static analysis confirmed by Intel\nProduct Security.\n\n(cherry picked from commit 15b9353deff3cf72331c387780de3cf9c316b643)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:32:30.915Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/0ac3bab10c62997727a0a90f819a27d337347f93"
},
{
"url": "https://git.kernel.org/stable/c/4a27275d275971c9ea29d3d240ea4a224ad368a2"
},
{
"url": "https://git.kernel.org/stable/c/be393175306694de5da1d1a23a8ea4149baa09f1"
},
{
"url": "https://git.kernel.org/stable/c/45db277b2e1e34bcc99a0852026791108339ec3e"
},
{
"url": "https://git.kernel.org/stable/c/c41a54619e95f860bf2950dd679ab353380ecd2b"
},
{
"url": "https://git.kernel.org/stable/c/914a76a9f08366434bf595700f62026b7a19a9cc"
}
],
"title": "drm/i915/gem: Add missing nospec on parallel submit slot",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68269",
"datePublished": "2026-08-10T12:01:44.575Z",
"dateReserved": "2026-07-30T09:28:09.378Z",
"dateUpdated": "2026-08-19T16:32:30.915Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68182 (GCVE-0-2026-68182)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
comedi: comedi_parport: deal with premature interrupt
Syzbot reported a general protection fault in
`comedi_get_is_subdevice_running()`, which was called from the interrupt
handler `parport_interrupt()` in the "comedi_parport" driver, but it
does not currently have a C reproducer for the problem. It's
probably due to a premature interrupt for one of two reasons:
1. The driver sets up the interrupt handler before the comedi subdevices
used by the interrupt handler have been allocated, but does not
disable the interrupt in the parallel port's CTRL register first.
2. The driver uses a user-supplied I/O port base address which Syzbot
would have supplied, but it might not be backed by real parallel port
hardware.
Change the initialization order in the driver's comedi "attach" handler
(`parport_attach()`) so that the hardware registers are initialized
before the interrupt handler is requested. This should prevent
premature interrupts occurring for real hardware.
Also add a test to the interrupt handler to ensure the comedi device is
fully attached and return early if it isn't.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 241ab6ad7108e51c67881f7881c5e46f0400cdb1 Version: 241ab6ad7108e51c67881f7881c5e46f0400cdb1 Version: 241ab6ad7108e51c67881f7881c5e46f0400cdb1 Version: 241ab6ad7108e51c67881f7881c5e46f0400cdb1 Version: 241ab6ad7108e51c67881f7881c5e46f0400cdb1 Version: 241ab6ad7108e51c67881f7881c5e46f0400cdb1 Version: 241ab6ad7108e51c67881f7881c5e46f0400cdb1 Version: 241ab6ad7108e51c67881f7881c5e46f0400cdb1 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/comedi/drivers/comedi_parport.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "6ed34611e569fc1a1169905c5228fd0eb2806c1b",
"status": "affected",
"version": "241ab6ad7108e51c67881f7881c5e46f0400cdb1",
"versionType": "git"
},
{
"lessThan": "48ef18e5eb6b8a9c546038b2ab89a841fcd97fe7",
"status": "affected",
"version": "241ab6ad7108e51c67881f7881c5e46f0400cdb1",
"versionType": "git"
},
{
"lessThan": "a88b25db815ff6edace81b0bb0f4a201133bd215",
"status": "affected",
"version": "241ab6ad7108e51c67881f7881c5e46f0400cdb1",
"versionType": "git"
},
{
"lessThan": "b061bb4dca49fd93063359d3805387235818778c",
"status": "affected",
"version": "241ab6ad7108e51c67881f7881c5e46f0400cdb1",
"versionType": "git"
},
{
"lessThan": "086a9ae3c5df63ec11033a8c0b3f6a1fd295ddd1",
"status": "affected",
"version": "241ab6ad7108e51c67881f7881c5e46f0400cdb1",
"versionType": "git"
},
{
"lessThan": "cf26dd2d841583c54a87005c4934b92fddb930c3",
"status": "affected",
"version": "241ab6ad7108e51c67881f7881c5e46f0400cdb1",
"versionType": "git"
},
{
"lessThan": "5d059ce0e6a2f6f8b97273499d47b8f917097b48",
"status": "affected",
"version": "241ab6ad7108e51c67881f7881c5e46f0400cdb1",
"versionType": "git"
},
{
"lessThan": "17221216ae8ce6a24e8a4e787382e3ebc81b88a8",
"status": "affected",
"version": "241ab6ad7108e51c67881f7881c5e46f0400cdb1",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/comedi/drivers/comedi_parport.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.29"
},
{
"lessThan": "2.6.29",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.29",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.29",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.29",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.29",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.29",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.29",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.29",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.29",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncomedi: comedi_parport: deal with premature interrupt\n\nSyzbot reported a general protection fault in\n`comedi_get_is_subdevice_running()`, which was called from the interrupt\nhandler `parport_interrupt()` in the \"comedi_parport\" driver, but it\ndoes not currently have a C reproducer for the problem. It\u0027s\nprobably due to a premature interrupt for one of two reasons:\n\n1. The driver sets up the interrupt handler before the comedi subdevices\n used by the interrupt handler have been allocated, but does not\n disable the interrupt in the parallel port\u0027s CTRL register first.\n2. The driver uses a user-supplied I/O port base address which Syzbot\n would have supplied, but it might not be backed by real parallel port\n hardware.\n\nChange the initialization order in the driver\u0027s comedi \"attach\" handler\n(`parport_attach()`) so that the hardware registers are initialized\nbefore the interrupt handler is requested. This should prevent\npremature interrupts occurring for real hardware.\n\nAlso add a test to the interrupt handler to ensure the comedi device is\nfully attached and return early if it isn\u0027t."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:30:47.491Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/6ed34611e569fc1a1169905c5228fd0eb2806c1b"
},
{
"url": "https://git.kernel.org/stable/c/48ef18e5eb6b8a9c546038b2ab89a841fcd97fe7"
},
{
"url": "https://git.kernel.org/stable/c/a88b25db815ff6edace81b0bb0f4a201133bd215"
},
{
"url": "https://git.kernel.org/stable/c/b061bb4dca49fd93063359d3805387235818778c"
},
{
"url": "https://git.kernel.org/stable/c/086a9ae3c5df63ec11033a8c0b3f6a1fd295ddd1"
},
{
"url": "https://git.kernel.org/stable/c/cf26dd2d841583c54a87005c4934b92fddb930c3"
},
{
"url": "https://git.kernel.org/stable/c/5d059ce0e6a2f6f8b97273499d47b8f917097b48"
},
{
"url": "https://git.kernel.org/stable/c/17221216ae8ce6a24e8a4e787382e3ebc81b88a8"
}
],
"title": "comedi: comedi_parport: deal with premature interrupt",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68182",
"datePublished": "2026-08-10T11:59:53.793Z",
"dateReserved": "2026-07-30T09:28:09.373Z",
"dateUpdated": "2026-08-19T16:30:47.491Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80763 (GCVE-0-2026-80763)
Vulnerability from cvelistv5
Published
2026-09-04 15:12
Modified
2026-09-04 15:12
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci_event: validate LE Set CIG Parameters response
The Command Complete dispatch validates only the fixed part of the LE Set
CIG Parameters response. After that part is pulled from the skb,
hci_cc_le_set_cig_params() trusts num_handles and reads each entry in the
trailing handle array.
Matching num_handles against the command's num_cis does not guarantee
that the response contains the advertised handles. A truncated response
from a malfunctioning controller can therefore make the handler read
beyond the skb data.
Validate that the remaining skb data contains all advertised handles.
Include this in the existing response validation so malformed responses
also follow the established CIG failure handling.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 26afbd826ee326e63a334c37fd45e82e50a615ec Version: 26afbd826ee326e63a334c37fd45e82e50a615ec Version: 26afbd826ee326e63a334c37fd45e82e50a615ec Version: 26afbd826ee326e63a334c37fd45e82e50a615ec Version: 26afbd826ee326e63a334c37fd45e82e50a615ec Version: 26afbd826ee326e63a334c37fd45e82e50a615ec Version: 26afbd826ee326e63a334c37fd45e82e50a615ec |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/bluetooth/hci_event.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "9e05783d0bb96a7b853cc058a7c7de2dc4a62154",
"status": "affected",
"version": "26afbd826ee326e63a334c37fd45e82e50a615ec",
"versionType": "git"
},
{
"lessThan": "26741d178f31932c9018b36b7953e6dc391436a4",
"status": "affected",
"version": "26afbd826ee326e63a334c37fd45e82e50a615ec",
"versionType": "git"
},
{
"lessThan": "a34df5c4a439cfc04565fa5be608ed1e53134f1f",
"status": "affected",
"version": "26afbd826ee326e63a334c37fd45e82e50a615ec",
"versionType": "git"
},
{
"lessThan": "e3f82e8f2a5915f533b57a065e9a045aa2ee03bc",
"status": "affected",
"version": "26afbd826ee326e63a334c37fd45e82e50a615ec",
"versionType": "git"
},
{
"lessThan": "d83ecb7b96105d932dabaa56ccd7418c25fb7cbb",
"status": "affected",
"version": "26afbd826ee326e63a334c37fd45e82e50a615ec",
"versionType": "git"
},
{
"lessThan": "6fc540e835dddb518cef3ff522b780f701cd03df",
"status": "affected",
"version": "26afbd826ee326e63a334c37fd45e82e50a615ec",
"versionType": "git"
},
{
"lessThan": "0acd4eeb4b225b9bebbf9ef96cc10cdd79b94899",
"status": "affected",
"version": "26afbd826ee326e63a334c37fd45e82e50a615ec",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/bluetooth/hci_event.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.0"
},
{
"lessThan": "6.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.187",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.154",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.106",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.47",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.1",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.187",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.154",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.106",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.47",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.11",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.1",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "6.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_event: validate LE Set CIG Parameters response\n\nThe Command Complete dispatch validates only the fixed part of the LE Set\nCIG Parameters response. After that part is pulled from the skb,\nhci_cc_le_set_cig_params() trusts num_handles and reads each entry in the\ntrailing handle array.\n\nMatching num_handles against the command\u0027s num_cis does not guarantee\nthat the response contains the advertised handles. A truncated response\nfrom a malfunctioning controller can therefore make the handler read\nbeyond the skb data.\n\nValidate that the remaining skb data contains all advertised handles.\nInclude this in the existing response validation so malformed responses\nalso follow the established CIG failure handling."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T15:12:35.652Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/9e05783d0bb96a7b853cc058a7c7de2dc4a62154"
},
{
"url": "https://git.kernel.org/stable/c/26741d178f31932c9018b36b7953e6dc391436a4"
},
{
"url": "https://git.kernel.org/stable/c/a34df5c4a439cfc04565fa5be608ed1e53134f1f"
},
{
"url": "https://git.kernel.org/stable/c/e3f82e8f2a5915f533b57a065e9a045aa2ee03bc"
},
{
"url": "https://git.kernel.org/stable/c/d83ecb7b96105d932dabaa56ccd7418c25fb7cbb"
},
{
"url": "https://git.kernel.org/stable/c/6fc540e835dddb518cef3ff522b780f701cd03df"
},
{
"url": "https://git.kernel.org/stable/c/0acd4eeb4b225b9bebbf9ef96cc10cdd79b94899"
}
],
"title": "Bluetooth: hci_event: validate LE Set CIG Parameters response",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80763",
"datePublished": "2026-09-04T15:12:35.652Z",
"dateReserved": "2026-08-26T14:34:25.791Z",
"dateUpdated": "2026-09-04T15:12:35.652Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2025-38206 (GCVE-0-2025-38206)
Vulnerability from cvelistv5
Published
2025-07-04 13:37
Modified
2026-09-02 12:49
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
exfat: fix double free in delayed_free
The double free could happen in the following path.
exfat_create_upcase_table()
exfat_create_upcase_table() : return error
exfat_free_upcase_table() : free ->vol_utbl
exfat_load_default_upcase_table : return error
exfat_kill_sb()
delayed_free()
exfat_free_upcase_table() <--------- double free
This patch set ->vol_util as NULL after freeing it.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1acf1a564b6034b5af1e7fb23cb98cb3bb4f6003 Version: 1acf1a564b6034b5af1e7fb23cb98cb3bb4f6003 Version: 1acf1a564b6034b5af1e7fb23cb98cb3bb4f6003 Version: 1acf1a564b6034b5af1e7fb23cb98cb3bb4f6003 Version: 1acf1a564b6034b5af1e7fb23cb98cb3bb4f6003 Version: 1acf1a564b6034b5af1e7fb23cb98cb3bb4f6003 Version: 1acf1a564b6034b5af1e7fb23cb98cb3bb4f6003 |
||
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2025-11-03T17:35:27.691Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"url": "https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html"
}
],
"title": "CVE Program Container"
},
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2025-38206",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-06-10T20:42:19.143911Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-06-11T18:44:21.826Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/exfat/nls.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "13d8de1b6568dcc31a95534ced16bc0c9a67bc15",
"status": "affected",
"version": "1acf1a564b6034b5af1e7fb23cb98cb3bb4f6003",
"versionType": "git"
},
{
"lessThan": "66e84439ec2af776ce749e8540f8fdd257774152",
"status": "affected",
"version": "1acf1a564b6034b5af1e7fb23cb98cb3bb4f6003",
"versionType": "git"
},
{
"lessThan": "ea27703eb0efbadcd45b9949526160ed90536a72",
"status": "affected",
"version": "1acf1a564b6034b5af1e7fb23cb98cb3bb4f6003",
"versionType": "git"
},
{
"lessThan": "ac65f76db9b2ff3fbc9e198c0e9aaf81b111b7d0",
"status": "affected",
"version": "1acf1a564b6034b5af1e7fb23cb98cb3bb4f6003",
"versionType": "git"
},
{
"lessThan": "29abaf93357f4a7d083cf399d4306999e20db31d",
"status": "affected",
"version": "1acf1a564b6034b5af1e7fb23cb98cb3bb4f6003",
"versionType": "git"
},
{
"lessThan": "d3cef0e7a5c1aa6217c51faa9ce8ecac35d6e1fd",
"status": "affected",
"version": "1acf1a564b6034b5af1e7fb23cb98cb3bb4f6003",
"versionType": "git"
},
{
"lessThan": "1f3d9724e16d62c7d42c67d6613b8512f2887c22",
"status": "affected",
"version": "1acf1a564b6034b5af1e7fb23cb98cb3bb4f6003",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/exfat/nls.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.7"
},
{
"lessThan": "5.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.239",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.186",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.187",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.156",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.108",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.15.*",
"status": "unaffected",
"version": "6.15.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "6.16",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.239",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.186",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.187",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.156",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.108",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.15.4",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.16",
"versionStartIncluding": "5.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nexfat: fix double free in delayed_free\n\nThe double free could happen in the following path.\n\nexfat_create_upcase_table()\n exfat_create_upcase_table() : return error\n exfat_free_upcase_table() : free -\u003evol_utbl\n exfat_load_default_upcase_table : return error\n exfat_kill_sb()\n delayed_free()\n exfat_free_upcase_table() \u003c--------- double free\nThis patch set -\u003evol_util as NULL after freeing it."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached only through the local `mount(2)`/`fsconfig(2)` path on a block device holding a crafted exfat image (removable media, loop device, or USB stick on a kiosk/Android handset). There is no remote or network data path into `exfat_create_upcase_table()`.\nAC:L - The attacker deterministically forces the first free by crafting an upcase-table dentry with a bad checksum, and can drive the required `kvcalloc` failure by generating memory/vmalloc pressure while repeatedly re-mounting the image, so success is not gated on conditions outside their influence. Consistent with prior kernel CNA scoring of allocation-failure-dependent bugs, this is Low.\nPR:L - exfat is the standard removable-media filesystem on Android and desktop Linux, where vold and udisks2 auto-mount attacker-supplied SD cards and USB sticks on behalf of the unprivileged seat/session user, so no elevated credentials are needed to reach `exfat_fill_super`. This matches the Low value assigned to the other exfat mount-time image-parsing CVEs.\nUI:N - On auto-mounting systems the crafted volume is parsed by the kernel as soon as the attacker attaches the media, and a local user with removable-media or loop-mount rights performs the entire sequence from their own process. No separate victim action is required.\nS:U - The freed `sbi-\u003evol_utbl` allocation and the resulting corruption are entirely within the kernel\u0027s own security authority. No VM, IOMMU, or sandbox boundary is crossed.\nC:H - The second `kvfree()` occurs in an RCU callback long after the first, so the 128 KiB region can be reallocated to an unrelated kernel object that is then released while still referenced, giving the attacker a page/vmap-level use-after-free usable as an arbitrary kernel-memory read primitive. Double-free-class corruption is scored High.\nI:H - Freeing memory that has already been reassigned lets the attacker spray controlled data into pages or vmap areas still in use by other subsystems (kernel stacks, BPF allocations, slab metadata), yielding a write primitive and control-flow hijack potential. This is full memory corruption, not a benign accounting error.\nA:H - Even without exploitation, the double free triggers a page-allocator/vfree corruption `BUG`/`WARN` in an RCU callback context or corrupts freelists, producing a kernel oops or panic. With `panic_on_warn` set, the \"Trying to vfree() nonexistent vm area\" path is an immediate full system panic."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-02T12:49:18.688Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/13d8de1b6568dcc31a95534ced16bc0c9a67bc15"
},
{
"url": "https://git.kernel.org/stable/c/66e84439ec2af776ce749e8540f8fdd257774152"
},
{
"url": "https://git.kernel.org/stable/c/ea27703eb0efbadcd45b9949526160ed90536a72"
},
{
"url": "https://git.kernel.org/stable/c/ac65f76db9b2ff3fbc9e198c0e9aaf81b111b7d0"
},
{
"url": "https://git.kernel.org/stable/c/29abaf93357f4a7d083cf399d4306999e20db31d"
},
{
"url": "https://git.kernel.org/stable/c/d3cef0e7a5c1aa6217c51faa9ce8ecac35d6e1fd"
},
{
"url": "https://git.kernel.org/stable/c/1f3d9724e16d62c7d42c67d6613b8512f2887c22"
}
],
"title": "exfat: fix double free in delayed_free",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2025-38206",
"datePublished": "2025-07-04T13:37:25.966Z",
"dateReserved": "2025-04-16T04:51:23.994Z",
"dateUpdated": "2026-09-02T12:49:18.688Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68476 (GCVE-0-2026-68476)
Vulnerability from cvelistv5
Published
2026-08-15 05:51
Modified
2026-09-02 12:49
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ipvs: reload ip header after head reallocation
__ip_vs_get_out_rt() calls skb_ensure_writable() which may
reallocate skb->head.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 8d8e20e2d7bba8c50e64e0eca1cb83956f468e49 Version: 8d8e20e2d7bba8c50e64e0eca1cb83956f468e49 Version: 8d8e20e2d7bba8c50e64e0eca1cb83956f468e49 Version: 8d8e20e2d7bba8c50e64e0eca1cb83956f468e49 Version: 8d8e20e2d7bba8c50e64e0eca1cb83956f468e49 Version: 8d8e20e2d7bba8c50e64e0eca1cb83956f468e49 Version: 8d8e20e2d7bba8c50e64e0eca1cb83956f468e49 Version: 8d8e20e2d7bba8c50e64e0eca1cb83956f468e49 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/netfilter/ipvs/ip_vs_xmit.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "4f2d1151421520d7ae16ca8d367d0ca09f5dfbd7",
"status": "affected",
"version": "8d8e20e2d7bba8c50e64e0eca1cb83956f468e49",
"versionType": "git"
},
{
"lessThan": "657118cad620172dfd8f6ed5717fd75c0d1f7a5a",
"status": "affected",
"version": "8d8e20e2d7bba8c50e64e0eca1cb83956f468e49",
"versionType": "git"
},
{
"lessThan": "a10f5080afbed242640f2984328de25f84557da1",
"status": "affected",
"version": "8d8e20e2d7bba8c50e64e0eca1cb83956f468e49",
"versionType": "git"
},
{
"lessThan": "ac6ac3d35bfc0ade9d17d354c84e503a946ebdab",
"status": "affected",
"version": "8d8e20e2d7bba8c50e64e0eca1cb83956f468e49",
"versionType": "git"
},
{
"lessThan": "e51687fc56c2e39ea6e9532925f1aabd4d529f61",
"status": "affected",
"version": "8d8e20e2d7bba8c50e64e0eca1cb83956f468e49",
"versionType": "git"
},
{
"lessThan": "3fb7edd2018bb1ad0a68157383d9b9dac33dd645",
"status": "affected",
"version": "8d8e20e2d7bba8c50e64e0eca1cb83956f468e49",
"versionType": "git"
},
{
"lessThan": "ad1e14710b360bda087ebf9fb82460eb5ef775de",
"status": "affected",
"version": "8d8e20e2d7bba8c50e64e0eca1cb83956f468e49",
"versionType": "git"
},
{
"lessThan": "a2f57827bf7c695b8c72dc4511cae8e86582369d",
"status": "affected",
"version": "8d8e20e2d7bba8c50e64e0eca1cb83956f468e49",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/netfilter/ipvs/ip_vs_xmit.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.10"
},
{
"lessThan": "4.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.269",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.220",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.187",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.269",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.220",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.187",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nipvs: reload ip header after head reallocation\n\n__ip_vs_get_out_rt() calls skb_ensure_writable() which may\nreallocate skb-\u003ehead."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The flaw is in ip_vs_bypass_xmit() on the IPVS netfilter receive path (NF_INET_LOCAL_IN/FORWARD); remote IPv4 packets to a configured virtual-server VIP reach ip_vs_in_hook() and ip_vs_leave() without local syscalls or ioctl.\nAC:L - Once cache_bypass is enabled on a fwmark IPVS service with no backend, an attacker can repeatedly send traffic to the VIP; cloned skbs (common with bridging, mirroring, or shared receive buffers) make skb_ensure_writable() reallocate skb-\u003ehead deterministically.\nPR:N - Exploitation requires only sending IP packets to the load balancer VIP; IPVS/cache_bypass configuration is an operator prerequisite on the target, not a Linux capability the remote attacker must hold.\nUI:N - No victim interaction is required; kernel processing of attacker-crafted network packets on the IPVS bypass transmit path alone triggers the stale header pointer use after skb head reallocation.\nS:U - Impact is kernel heap corruption and load-balancer compromise within the host kernel security domain; it does not cross VM, container, or IOMMU boundaries to another security authority.\nC:H - After pskb_expand_head() frees the old skb-\u003ehead, ip_send_check() uses the stale iph pointer and ip_fast_csum() reads attacker-influenced bytes from freed kmalloc memory, a classic use-after-free information disclosure primitive.\nI:H - ip_send_check() writes through the stale iph pointer (zeroing and updating the checksum field) into freed/reallocated slab memory, enabling heap corruption and potential arbitrary kernel write or control-flow hijack primitives.\nA:H - Writing and reading through a stale IP header pointer after skb head reallocation can corrupt adjacent kernel heap objects or dereference freed memory, causing kernel oops, panic, or hang and repeatable denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-02T12:49:42.932Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/4f2d1151421520d7ae16ca8d367d0ca09f5dfbd7"
},
{
"url": "https://git.kernel.org/stable/c/657118cad620172dfd8f6ed5717fd75c0d1f7a5a"
},
{
"url": "https://git.kernel.org/stable/c/a10f5080afbed242640f2984328de25f84557da1"
},
{
"url": "https://git.kernel.org/stable/c/ac6ac3d35bfc0ade9d17d354c84e503a946ebdab"
},
{
"url": "https://git.kernel.org/stable/c/e51687fc56c2e39ea6e9532925f1aabd4d529f61"
},
{
"url": "https://git.kernel.org/stable/c/3fb7edd2018bb1ad0a68157383d9b9dac33dd645"
},
{
"url": "https://git.kernel.org/stable/c/ad1e14710b360bda087ebf9fb82460eb5ef775de"
},
{
"url": "https://git.kernel.org/stable/c/a2f57827bf7c695b8c72dc4511cae8e86582369d"
}
],
"title": "ipvs: reload ip header after head reallocation",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68476",
"datePublished": "2026-08-15T05:51:32.170Z",
"dateReserved": "2026-07-30T09:28:09.396Z",
"dateUpdated": "2026-09-02T12:49:42.932Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68246 (GCVE-0-2026-68246)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-19 16:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu/gfx11: replace BUG_ON() with WARN_ON()
There's no need to crash the kernel for these cases.
(cherry picked from commit daa62107452d2451787c4248ca38fa2d1a0cbefd)
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 3d879e81f0f9ed5d33b5eda0fe5226c884bb8073 Version: 3d879e81f0f9ed5d33b5eda0fe5226c884bb8073 Version: 3d879e81f0f9ed5d33b5eda0fe5226c884bb8073 Version: 3d879e81f0f9ed5d33b5eda0fe5226c884bb8073 Version: 3d879e81f0f9ed5d33b5eda0fe5226c884bb8073 Version: 3d879e81f0f9ed5d33b5eda0fe5226c884bb8073 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/gfx_v11_0.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "cac8002c675eda7d0d567871287201932857576c",
"status": "affected",
"version": "3d879e81f0f9ed5d33b5eda0fe5226c884bb8073",
"versionType": "git"
},
{
"lessThan": "96b6d68f2b5a208e4d8f1e4a932ec424655e1267",
"status": "affected",
"version": "3d879e81f0f9ed5d33b5eda0fe5226c884bb8073",
"versionType": "git"
},
{
"lessThan": "7aeef42b657d930f3b639220e62120ac1bf058a1",
"status": "affected",
"version": "3d879e81f0f9ed5d33b5eda0fe5226c884bb8073",
"versionType": "git"
},
{
"lessThan": "dfd9bf09fd8fe81f113a5c7e88bfd99f2499542f",
"status": "affected",
"version": "3d879e81f0f9ed5d33b5eda0fe5226c884bb8073",
"versionType": "git"
},
{
"lessThan": "625f301e01bf89694466fdaa1f9904e2c62eb8f2",
"status": "affected",
"version": "3d879e81f0f9ed5d33b5eda0fe5226c884bb8073",
"versionType": "git"
},
{
"lessThan": "0eebcab1ea2a77f086a04108f386f82ee3496022",
"status": "affected",
"version": "3d879e81f0f9ed5d33b5eda0fe5226c884bb8073",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/gfx_v11_0.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.19"
},
{
"lessThan": "5.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/gfx11: replace BUG_ON() with WARN_ON()\n\nThere\u0027s no need to crash the kernel for these cases.\n\n(cherry picked from commit daa62107452d2451787c4248ca38fa2d1a0cbefd)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:32:13.526Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/cac8002c675eda7d0d567871287201932857576c"
},
{
"url": "https://git.kernel.org/stable/c/96b6d68f2b5a208e4d8f1e4a932ec424655e1267"
},
{
"url": "https://git.kernel.org/stable/c/7aeef42b657d930f3b639220e62120ac1bf058a1"
},
{
"url": "https://git.kernel.org/stable/c/dfd9bf09fd8fe81f113a5c7e88bfd99f2499542f"
},
{
"url": "https://git.kernel.org/stable/c/625f301e01bf89694466fdaa1f9904e2c62eb8f2"
},
{
"url": "https://git.kernel.org/stable/c/0eebcab1ea2a77f086a04108f386f82ee3496022"
}
],
"title": "drm/amdgpu/gfx11: replace BUG_ON() with WARN_ON()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68246",
"datePublished": "2026-08-10T12:01:12.489Z",
"dateReserved": "2026-07-30T09:28:09.377Z",
"dateUpdated": "2026-08-19T16:32:13.526Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68294 (GCVE-0-2026-68294)
Vulnerability from cvelistv5
Published
2026-08-10 12:02
Modified
2026-08-19 16:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: qrtr: restrict socket creation to the initial network namespace
QRTR keeps its entire port and node state in module-global variables
that are not partitioned per network namespace: qrtr_local_nid is a
single global node id (always 1) and qrtr_ports is a single global
xarray. qrtr_port_lookup() and qrtr_local_enqueue() operate on that
global state with no network-namespace check, and qrtr_create() places
no restriction on the namespace a socket is created in.
As a result an unprivileged process that creates an AF_QIPCRTR socket
in a separate network namespace, e.g. via
unshare(CLONE_NEWUSER | CLONE_NEWNET), can send QRTR datagrams -
including control-plane messages such as QRTR_TYPE_NEW_SERVER - to QRTR
sockets owned by another namespace, and vice versa. The receiving
socket sees such a message as coming from node id 1, indistinguishable
from a legitimate local client, breaking the isolation that network
namespaces are expected to provide.
QRTR is a transport to global hardware endpoints (the modem and other
remote processors) and has no per-namespace semantics; its in-kernel
name service already creates its socket in init_net only. Confine the
socket family to the initial network namespace, as other
non-namespace-aware socket families do (see llc_ui_create() and the
ieee802154 socket code).
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: bdabad3e363d825ddf9679dd431cca0b2c30f881 Version: bdabad3e363d825ddf9679dd431cca0b2c30f881 Version: bdabad3e363d825ddf9679dd431cca0b2c30f881 Version: bdabad3e363d825ddf9679dd431cca0b2c30f881 Version: bdabad3e363d825ddf9679dd431cca0b2c30f881 Version: bdabad3e363d825ddf9679dd431cca0b2c30f881 Version: bdabad3e363d825ddf9679dd431cca0b2c30f881 Version: bdabad3e363d825ddf9679dd431cca0b2c30f881 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/qrtr/af_qrtr.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "7814f6a3415cad38aa8d6dfc573df778260d66aa",
"status": "affected",
"version": "bdabad3e363d825ddf9679dd431cca0b2c30f881",
"versionType": "git"
},
{
"lessThan": "2d22b94a154ccb9755dddfff802fe3e2b1adbab5",
"status": "affected",
"version": "bdabad3e363d825ddf9679dd431cca0b2c30f881",
"versionType": "git"
},
{
"lessThan": "8d351fe0654a20c9f95a61b05d24ebe6d4be3fbb",
"status": "affected",
"version": "bdabad3e363d825ddf9679dd431cca0b2c30f881",
"versionType": "git"
},
{
"lessThan": "4b95e1f0d6e6342c427cb341ee18a894b146b789",
"status": "affected",
"version": "bdabad3e363d825ddf9679dd431cca0b2c30f881",
"versionType": "git"
},
{
"lessThan": "f488116df769bdaf89c93371350e49e12133e70f",
"status": "affected",
"version": "bdabad3e363d825ddf9679dd431cca0b2c30f881",
"versionType": "git"
},
{
"lessThan": "8150c48fb978e01689f94ed80148f8a7499ae571",
"status": "affected",
"version": "bdabad3e363d825ddf9679dd431cca0b2c30f881",
"versionType": "git"
},
{
"lessThan": "659b9b4f194bb56b9903cc95e786ef1d438baa7d",
"status": "affected",
"version": "bdabad3e363d825ddf9679dd431cca0b2c30f881",
"versionType": "git"
},
{
"lessThan": "3b536db8fb32da9e9c62f2bb45e2e319331f0426",
"status": "affected",
"version": "bdabad3e363d825ddf9679dd431cca0b2c30f881",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/qrtr/af_qrtr.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.7"
},
{
"lessThan": "4.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: qrtr: restrict socket creation to the initial network namespace\n\nQRTR keeps its entire port and node state in module-global variables\nthat are not partitioned per network namespace: qrtr_local_nid is a\nsingle global node id (always 1) and qrtr_ports is a single global\nxarray. qrtr_port_lookup() and qrtr_local_enqueue() operate on that\nglobal state with no network-namespace check, and qrtr_create() places\nno restriction on the namespace a socket is created in.\n\nAs a result an unprivileged process that creates an AF_QIPCRTR socket\nin a separate network namespace, e.g. via\nunshare(CLONE_NEWUSER | CLONE_NEWNET), can send QRTR datagrams -\nincluding control-plane messages such as QRTR_TYPE_NEW_SERVER - to QRTR\nsockets owned by another namespace, and vice versa. The receiving\nsocket sees such a message as coming from node id 1, indistinguishable\nfrom a legitimate local client, breaking the isolation that network\nnamespaces are expected to provide.\n\nQRTR is a transport to global hardware endpoints (the modem and other\nremote processors) and has no per-namespace semantics; its in-kernel\nname service already creates its socket in init_net only. Confine the\nsocket family to the initial network namespace, as other\nnon-namespace-aware socket families do (see llc_ui_create() and the\nieee802154 socket code)."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires local access to issue socket()/sendmsg() syscalls on an AF_QIPCRTR socket from within a network namespace on the target system; there is no remote packet path into qrtr_create().\nAC:L - The attack is fully deterministic: unshare(CLONE_NEWUSER|CLONE_NEWNET), create an AF_QIPCRTR socket (module autoloads via net-pf-42), and sendmsg() to node 1. No race, no memory-layout dependency, no victim state required.\nPR:L - Any unprivileged local user can create the required network namespace via unshare(CLONE_NEWUSER|CLONE_NEWNET), and a containerized process is already in one; the CAP_NET_ADMIN check at qrtr_port_assign() only gates low/control ports and is not needed for this attack.\nUI:N - The attacker performs all steps itself; no action by any other user or administrator is required to trigger the cross-namespace delivery.\nS:C - The flaw defeats the network-namespace confinement boundary itself: a process sandboxed in its own netns reaches the init_net global QRTR control plane, the in-kernel name service, and host-owned sockets, impacting resources under a different security authority than the attacker\u0027s container.\nC:H - By spoofing QRTR_TYPE_NEW_SERVER to the name service, a confined attacker registers itself as a well-known service so legitimate host clients direct their QMI traffic to it, and it can address modem/remote-processor endpoints directly, exposing sensitive telephony data it was isolated from.\nI:H - The attacker can inject arbitrary control-plane messages (NEW_SERVER, DEL_SERVER, BYE, DEL_CLIENT) that the receiver cannot distinguish from a legitimate node-1 client, corrupting the global service registry and allowing forged replies to host clients and commands to the modem.\nA:H - A single spoofed QRTR_TYPE_BYE makes ctrl_cmd_bye() delete every server registered on the local node and broadcast their removal, and the QRTR_NS_MAX_SERVERS/MAX_LOOKUPS limits can be exhausted, causing complete and repeatable loss of QRTR/modem IPC service for the whole system."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:32:43.629Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/7814f6a3415cad38aa8d6dfc573df778260d66aa"
},
{
"url": "https://git.kernel.org/stable/c/2d22b94a154ccb9755dddfff802fe3e2b1adbab5"
},
{
"url": "https://git.kernel.org/stable/c/8d351fe0654a20c9f95a61b05d24ebe6d4be3fbb"
},
{
"url": "https://git.kernel.org/stable/c/4b95e1f0d6e6342c427cb341ee18a894b146b789"
},
{
"url": "https://git.kernel.org/stable/c/f488116df769bdaf89c93371350e49e12133e70f"
},
{
"url": "https://git.kernel.org/stable/c/8150c48fb978e01689f94ed80148f8a7499ae571"
},
{
"url": "https://git.kernel.org/stable/c/659b9b4f194bb56b9903cc95e786ef1d438baa7d"
},
{
"url": "https://git.kernel.org/stable/c/3b536db8fb32da9e9c62f2bb45e2e319331f0426"
}
],
"title": "net: qrtr: restrict socket creation to the initial network namespace",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68294",
"datePublished": "2026-08-10T12:02:27.423Z",
"dateReserved": "2026-07-30T09:28:09.380Z",
"dateUpdated": "2026-08-19T16:32:43.629Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80574 (GCVE-0-2026-80574)
Vulnerability from cvelistv5
Published
2026-08-26 14:37
Modified
2026-08-27 05:01
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Input: focaltech - fix array out-of-bounds in focaltech_process_rel_packet
Make finger2 (and also finger1) unsigned, so that if the finger index in
the packet is 0 then subtracting 1 creates an array index which overflows
above the existing check for FOC_MAX_FINGERS, as the existing comment says
it should, instead of writing to state->fingers[-1].
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 05be1d079ec0b3691783e4384b1ada82149ff7d2 Version: 05be1d079ec0b3691783e4384b1ada82149ff7d2 Version: 05be1d079ec0b3691783e4384b1ada82149ff7d2 Version: 05be1d079ec0b3691783e4384b1ada82149ff7d2 Version: 05be1d079ec0b3691783e4384b1ada82149ff7d2 Version: 05be1d079ec0b3691783e4384b1ada82149ff7d2 Version: 05be1d079ec0b3691783e4384b1ada82149ff7d2 Version: 05be1d079ec0b3691783e4384b1ada82149ff7d2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/input/mouse/focaltech.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "063b4c6a6f3fc01bca085c442000c9c100fdbd93",
"status": "affected",
"version": "05be1d079ec0b3691783e4384b1ada82149ff7d2",
"versionType": "git"
},
{
"lessThan": "bb502d79acb9ac1e0a77fa8bc7b7b4729140b11f",
"status": "affected",
"version": "05be1d079ec0b3691783e4384b1ada82149ff7d2",
"versionType": "git"
},
{
"lessThan": "ca92c98b806839c108995b2bbff7061515bdfb53",
"status": "affected",
"version": "05be1d079ec0b3691783e4384b1ada82149ff7d2",
"versionType": "git"
},
{
"lessThan": "81b07470cb2937ceb74b00be88151582a322433b",
"status": "affected",
"version": "05be1d079ec0b3691783e4384b1ada82149ff7d2",
"versionType": "git"
},
{
"lessThan": "6f6d5fe29efdf5001bc146fc292e6592cace93eb",
"status": "affected",
"version": "05be1d079ec0b3691783e4384b1ada82149ff7d2",
"versionType": "git"
},
{
"lessThan": "83c265bfc084d77e2171d4b67362150ab38c935b",
"status": "affected",
"version": "05be1d079ec0b3691783e4384b1ada82149ff7d2",
"versionType": "git"
},
{
"lessThan": "1842e47126816e56d30c4f856f9854fd7831066c",
"status": "affected",
"version": "05be1d079ec0b3691783e4384b1ada82149ff7d2",
"versionType": "git"
},
{
"lessThan": "296736076b3fd078742651c719555a488624023a",
"status": "affected",
"version": "05be1d079ec0b3691783e4384b1ada82149ff7d2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/input/mouse/focaltech.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.0"
},
{
"lessThan": "4.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.46",
"versionStartIncluding": "4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.10",
"versionStartIncluding": "4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nInput: focaltech - fix array out-of-bounds in focaltech_process_rel_packet\n\nMake finger2 (and also finger1) unsigned, so that if the finger index in\nthe packet is 0 then subtracting 1 creates an array index which overflows\nabove the existing check for FOC_MAX_FINGERS, as the existing comment says\nit should, instead of writing to state-\u003efingers[-1]."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.4,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - FocalTech FOC_REL packets reach focaltech_process_rel_packet through i8042/serio hardware interrupts, ps2_interrupt, psmouse_receive_byte, and focaltech_process_byte with no syscall gate; any local user on a laptop with an integrated FocalTech PS/2 touchpad can deliver the triggering bytes by normal touchpad use.\nAC:L - When the second relative finger index is 0, a documented valid case for odd finger counts, signed underflow makes finger2 -1 pass the FOC_MAX_FINGERS bound test and causes a reliable out-of-bounds write on every such packet without races or attacker-uncontrollable memory layout.\nPR:N - No Linux account, capability, or namespace privilege is required; the integrated touchpad feeds bytes directly into the kernel interrupt handler during normal operation, including at the login screen before authentication.\nUI:N - An attacker with brief local access can trigger the corrupting multitouch gestures directly on the touchpad; exploitation does not depend on a separate victim performing an unusual action beyond touching the device.\nS:U - The vulnerability corrupts kmalloc-allocated focaltech_data within the host kernel psmouse driver; impact is standard in-kernel memory corruption rather than crossing a guest/host, VM, or IOMMU security boundary.\nC:H - Out-of-bounds += writes to fingers[-1].x and fingers[-1].y corrupt adjacent focaltech_data fields such as y_max in kernel heap memory; this class of heap corruption can be leveraged for kernel information disclosure.\nI:H - Attacker-influenced PS/2 packet bytes supply signed 8-bit deltas that repeatedly perform out-of-bounds writes immediately before fingers[0], enabling progressive corruption of neighboring driver state and potential privilege escalation.\nA:H - Corrupting kmalloc-allocated driver state via fingers[-1] can destabilize the input subsystem or adjacent heap objects, causing kernel oops, panic, or repeatable denial of service on affected laptops."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T05:01:56.362Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/063b4c6a6f3fc01bca085c442000c9c100fdbd93"
},
{
"url": "https://git.kernel.org/stable/c/bb502d79acb9ac1e0a77fa8bc7b7b4729140b11f"
},
{
"url": "https://git.kernel.org/stable/c/ca92c98b806839c108995b2bbff7061515bdfb53"
},
{
"url": "https://git.kernel.org/stable/c/81b07470cb2937ceb74b00be88151582a322433b"
},
{
"url": "https://git.kernel.org/stable/c/6f6d5fe29efdf5001bc146fc292e6592cace93eb"
},
{
"url": "https://git.kernel.org/stable/c/83c265bfc084d77e2171d4b67362150ab38c935b"
},
{
"url": "https://git.kernel.org/stable/c/1842e47126816e56d30c4f856f9854fd7831066c"
},
{
"url": "https://git.kernel.org/stable/c/296736076b3fd078742651c719555a488624023a"
}
],
"title": "Input: focaltech - fix array out-of-bounds in focaltech_process_rel_packet",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80574",
"datePublished": "2026-08-26T14:37:34.353Z",
"dateReserved": "2026-08-26T14:34:25.768Z",
"dateUpdated": "2026-08-27T05:01:56.362Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68335 (GCVE-0-2026-68335)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
rds: drop incoming messages that cross network namespace boundaries
rds_find_bound() looks up the destination socket using a global
rhashtable keyed solely on (addr, port, scope_id). Network namespaces
are not part of the key, so a sender in netns A can deliver an incoming
message (inc) to a socket that lives in a different netns B.
When this happens, inc->i_conn points to an rds_connection whose c_net
is netns A, but the receiving rs lives in netns B. Once the child
process that created netns A exits, cleanup_net() calls
rds_loop_exit_net() -> rds_loop_kill_conns() -> rds_conn_destroy(),
freeing that connection. If the survivor socket in netns B still holds
the inc, any subsequent dereference of inc->i_conn is a use-after-free.
There are two dangerous sites in rds_clear_recv_queue():
1. inc->i_conn->c_lcong (offset 88 of freed rds_connection, size 200)
read via rds_recv_rcvbuf_delta() -- confirmed by KASAN.
2. inc->i_conn->c_trans->inc_free(inc) (function pointer at offset 80)
called via rds_inc_put() when the inc refcount reaches zero -- same
race window, potential call-through-freed-object primitive.
The bug is reachable from unprivileged user namespaces
(CLONE_NEWUSER + CLONE_NEWNET), available since Linux 3.8.
Fix this by rejecting the delivery in rds_recv_incoming() when the
socket returned by rds_find_bound() belongs to a different network
namespace than the connection that carried the message. Use the
existing rds_conn_net() / sock_net() helpers and net_eq() for the
comparison.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: c809195f5523dd4d09403bbb1c9732d548aa0d1e Version: c809195f5523dd4d09403bbb1c9732d548aa0d1e Version: c809195f5523dd4d09403bbb1c9732d548aa0d1e Version: c809195f5523dd4d09403bbb1c9732d548aa0d1e Version: c809195f5523dd4d09403bbb1c9732d548aa0d1e Version: c809195f5523dd4d09403bbb1c9732d548aa0d1e Version: c809195f5523dd4d09403bbb1c9732d548aa0d1e Version: c809195f5523dd4d09403bbb1c9732d548aa0d1e Version: c827073c95fde388bc65fe5227f944eaf859b9f0 Version: 4.17.19 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/rds/recv.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "742ff6f02545212e991cd8b45011e40d2c2ef25a",
"status": "affected",
"version": "c809195f5523dd4d09403bbb1c9732d548aa0d1e",
"versionType": "git"
},
{
"lessThan": "abff41fd928328bbf3dda1140beb2e61fa424ccd",
"status": "affected",
"version": "c809195f5523dd4d09403bbb1c9732d548aa0d1e",
"versionType": "git"
},
{
"lessThan": "03c574112e5d066df0ddce36d7438e850bcf3050",
"status": "affected",
"version": "c809195f5523dd4d09403bbb1c9732d548aa0d1e",
"versionType": "git"
},
{
"lessThan": "1e2e2d9806944fe485824d617c8b7c78116c22db",
"status": "affected",
"version": "c809195f5523dd4d09403bbb1c9732d548aa0d1e",
"versionType": "git"
},
{
"lessThan": "cfb3ce07b705e486e022a2f2b1242b48f13981ff",
"status": "affected",
"version": "c809195f5523dd4d09403bbb1c9732d548aa0d1e",
"versionType": "git"
},
{
"lessThan": "9591042533140dfe6608d9344806d567dcd39d02",
"status": "affected",
"version": "c809195f5523dd4d09403bbb1c9732d548aa0d1e",
"versionType": "git"
},
{
"lessThan": "0f8690e3869109cd5803ccb400889d20a0b54e0e",
"status": "affected",
"version": "c809195f5523dd4d09403bbb1c9732d548aa0d1e",
"versionType": "git"
},
{
"lessThan": "5521ae71e32a8069ed4ca6e792179dc57bc43ab2",
"status": "affected",
"version": "c809195f5523dd4d09403bbb1c9732d548aa0d1e",
"versionType": "git"
},
{
"status": "affected",
"version": "c827073c95fde388bc65fe5227f944eaf859b9f0",
"versionType": "git"
},
{
"lessThan": "4.18",
"status": "affected",
"version": "4.17.19",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/rds/recv.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.18"
},
{
"lessThan": "4.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.17.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nrds: drop incoming messages that cross network namespace boundaries\n\nrds_find_bound() looks up the destination socket using a global\nrhashtable keyed solely on (addr, port, scope_id). Network namespaces\nare not part of the key, so a sender in netns A can deliver an incoming\nmessage (inc) to a socket that lives in a different netns B.\n\nWhen this happens, inc-\u003ei_conn points to an rds_connection whose c_net\nis netns A, but the receiving rs lives in netns B. Once the child\nprocess that created netns A exits, cleanup_net() calls\nrds_loop_exit_net() -\u003e rds_loop_kill_conns() -\u003e rds_conn_destroy(),\nfreeing that connection. If the survivor socket in netns B still holds\nthe inc, any subsequent dereference of inc-\u003ei_conn is a use-after-free.\n\nThere are two dangerous sites in rds_clear_recv_queue():\n 1. inc-\u003ei_conn-\u003ec_lcong (offset 88 of freed rds_connection, size 200)\n read via rds_recv_rcvbuf_delta() -- confirmed by KASAN.\n 2. inc-\u003ei_conn-\u003ec_trans-\u003einc_free(inc) (function pointer at offset 80)\n called via rds_inc_put() when the inc refcount reaches zero -- same\n race window, potential call-through-freed-object primitive.\n\nThe bug is reachable from unprivileged user namespaces\n(CLONE_NEWUSER + CLONE_NEWNET), available since Linux 3.8.\n\nFix this by rejecting the delivery in rds_recv_incoming() when the\nsocket returned by rds_find_bound() belongs to a different network\nnamespace than the connection that carried the message. Use the\nexisting rds_conn_net() / sock_net() helpers and net_eq() for the\ncomparison."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires local syscall access: the attacker must create RDS sockets and a network namespace (CLONE_NEWUSER|CLONE_NEWNET), then trigger namespace teardown to free the connection. A remote RDS peer cannot drive the netns-destruction half of the sequence, so the vulnerability is reachable only locally.\nAC:L - The attacker controls the entire sequence deterministically \u2014 bind a socket in one netns, send a loopback RDS message from a second netns so the inc is queued cross-netns, then exit that netns to free inc-\u003ei_conn. No race must be won and no uncontrollable precondition exists; the UAF is confirmed reproducible under KASAN.\nPR:L - Only an unprivileged local user account is required; the needed CAP_NET_ADMIN for creating and configuring the second network namespace is obtained inside a user namespace the attacker owns, as the commit explicitly notes (\"reachable from unprivileged user namespaces\").\nUI:N - The attacker performs every step \u2014 socket creation, cross-netns send, namespace teardown, and the subsequent read/close that dereferences the freed connection \u2014 with no action from any other user or administrator.\nS:U - The use-after-free corrupts kernel memory within the same kernel security authority; there is no crossing of a hypervisor, IOMMU, or comparable trust boundary.\nC:H - The stale inc-\u003ei_conn is dereferenced to read c_lcong from a freed 200-byte rds_connection, and the freed slot can be reclaimed with attacker-groomed data, giving a use-after-free read primitive usable to disclose kernel memory contents.\nI:H - rds_inc_put() calls inc-\u003ei_conn-\u003ec_trans-\u003einc_free(inc) through a function pointer at offset 80 of the freed object \u2014 an indirect call through freed memory that the commit calls a \"call-through-freed-object primitive\", which after heap reclamation is a control-flow hijack path leading to arbitrary kernel modification.\nA:H - Dereferencing the freed rds_connection in rds_clear_recv_queue() and calling through its freed transport vtable reliably corrupts kernel state and panics the machine (KASAN-confirmed use-after-free), causing a full denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:33:33.100Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/742ff6f02545212e991cd8b45011e40d2c2ef25a"
},
{
"url": "https://git.kernel.org/stable/c/abff41fd928328bbf3dda1140beb2e61fa424ccd"
},
{
"url": "https://git.kernel.org/stable/c/03c574112e5d066df0ddce36d7438e850bcf3050"
},
{
"url": "https://git.kernel.org/stable/c/1e2e2d9806944fe485824d617c8b7c78116c22db"
},
{
"url": "https://git.kernel.org/stable/c/cfb3ce07b705e486e022a2f2b1242b48f13981ff"
},
{
"url": "https://git.kernel.org/stable/c/9591042533140dfe6608d9344806d567dcd39d02"
},
{
"url": "https://git.kernel.org/stable/c/0f8690e3869109cd5803ccb400889d20a0b54e0e"
},
{
"url": "https://git.kernel.org/stable/c/5521ae71e32a8069ed4ca6e792179dc57bc43ab2"
}
],
"title": "rds: drop incoming messages that cross network namespace boundaries",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68335",
"datePublished": "2026-08-10T12:03:11.547Z",
"dateReserved": "2026-07-30T09:28:09.383Z",
"dateUpdated": "2026-08-19T16:33:33.100Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74577 (GCVE-0-2026-74577)
Vulnerability from cvelistv5
Published
2026-08-15 12:28
Modified
2026-08-19 16:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: mpls: initialize rtm_tos in mpls_getroute()
mpls_getroute() builds the RTM_NEWROUTE reply to an RTM_GETROUTE
request by filling a struct rtmsg allocated from an skb whose data
area is not zeroed (alloc_skb(NLMSG_GOODSIZE, ...)). It sets every
field of the header except rtm_tos:
r = nlmsg_data(nlh);
r->rtm_family = AF_MPLS;
r->rtm_dst_len = 20;
r->rtm_src_len = 0;
r->rtm_table = RT_TABLE_MAIN;
r->rtm_type = RTN_UNICAST;
r->rtm_scope = RT_SCOPE_UNIVERSE;
r->rtm_protocol = rt->rt_protocol;
r->rtm_flags = 0;
struct rtmsg has no padding, so the one uninitialised byte rtm_tos
(offset 3) is copied straight to user space on recvmsg(), leaking a
byte of uninitialised heap memory. This is in contrast to
mpls_dump_route(), which fills the very same header and does set
rtm_tos = 0.
Initialize rtm_tos to 0, matching mpls_dump_route().
Reproduced with KMSAN by adding an MPLS route and issuing a
non-RTM_F_FIB_MATCH RTM_GETROUTE for its label:
BUG: KMSAN: kernel-infoleak in _copy_to_iter+0x36c/0x33f0
_copy_to_iter+0x36c/0x33f0
__skb_datagram_iter+0x196/0x12c0
skb_copy_datagram_iter+0x5b/0x210
netlink_recvmsg+0x37b/0xef0
...
Uninit was created at:
__alloc_skb+0x8ca/0x10e0
mpls_getroute+0x1280/0x3a40
rtnetlink_rcv_msg+0x1138/0x15a0
...
Byte 19 of 64 is uninitialized
(byte 19 = nlmsghdr(16) + rtmsg offset 3 = rtm_tos)
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 397fc9e5cefee0c33b86811fbddb0decb7288c52 Version: 397fc9e5cefee0c33b86811fbddb0decb7288c52 Version: 397fc9e5cefee0c33b86811fbddb0decb7288c52 Version: 397fc9e5cefee0c33b86811fbddb0decb7288c52 Version: 397fc9e5cefee0c33b86811fbddb0decb7288c52 Version: 397fc9e5cefee0c33b86811fbddb0decb7288c52 Version: 397fc9e5cefee0c33b86811fbddb0decb7288c52 Version: 397fc9e5cefee0c33b86811fbddb0decb7288c52 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/mpls/af_mpls.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "248718fd88b146d8bdc7610ecd1eb4cd16e0b5a1",
"status": "affected",
"version": "397fc9e5cefee0c33b86811fbddb0decb7288c52",
"versionType": "git"
},
{
"lessThan": "466b474a8deb0c93b5280c6d261e5eda6482eca7",
"status": "affected",
"version": "397fc9e5cefee0c33b86811fbddb0decb7288c52",
"versionType": "git"
},
{
"lessThan": "ba56f88aab18d982f2a21f11390f4d8a8897782a",
"status": "affected",
"version": "397fc9e5cefee0c33b86811fbddb0decb7288c52",
"versionType": "git"
},
{
"lessThan": "95651461cf77cc6590fa08c87667717e5dcfa55d",
"status": "affected",
"version": "397fc9e5cefee0c33b86811fbddb0decb7288c52",
"versionType": "git"
},
{
"lessThan": "1fea5ff0eb4aa7e951bb3d380248566c473aa377",
"status": "affected",
"version": "397fc9e5cefee0c33b86811fbddb0decb7288c52",
"versionType": "git"
},
{
"lessThan": "a5cdd2407dd890f741f59b8367e4c6c101cce154",
"status": "affected",
"version": "397fc9e5cefee0c33b86811fbddb0decb7288c52",
"versionType": "git"
},
{
"lessThan": "2dc2fffc704a4365cae1aae078ba62223aaeff93",
"status": "affected",
"version": "397fc9e5cefee0c33b86811fbddb0decb7288c52",
"versionType": "git"
},
{
"lessThan": "295dd295e2137e10e9a5b1891d97e0f08de76f03",
"status": "affected",
"version": "397fc9e5cefee0c33b86811fbddb0decb7288c52",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/mpls/af_mpls.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.13"
},
{
"lessThan": "4.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mpls: initialize rtm_tos in mpls_getroute()\n\nmpls_getroute() builds the RTM_NEWROUTE reply to an RTM_GETROUTE\nrequest by filling a struct rtmsg allocated from an skb whose data\narea is not zeroed (alloc_skb(NLMSG_GOODSIZE, ...)). It sets every\nfield of the header except rtm_tos:\n\n\tr = nlmsg_data(nlh);\n\tr-\u003ertm_family\t = AF_MPLS;\n\tr-\u003ertm_dst_len\t= 20;\n\tr-\u003ertm_src_len\t= 0;\n\tr-\u003ertm_table\t= RT_TABLE_MAIN;\n\tr-\u003ertm_type\t= RTN_UNICAST;\n\tr-\u003ertm_scope\t= RT_SCOPE_UNIVERSE;\n\tr-\u003ertm_protocol = rt-\u003ert_protocol;\n\tr-\u003ertm_flags\t= 0;\n\nstruct rtmsg has no padding, so the one uninitialised byte rtm_tos\n(offset 3) is copied straight to user space on recvmsg(), leaking a\nbyte of uninitialised heap memory. This is in contrast to\nmpls_dump_route(), which fills the very same header and does set\nrtm_tos = 0.\n\nInitialize rtm_tos to 0, matching mpls_dump_route().\n\nReproduced with KMSAN by adding an MPLS route and issuing a\nnon-RTM_F_FIB_MATCH RTM_GETROUTE for its label:\n\n BUG: KMSAN: kernel-infoleak in _copy_to_iter+0x36c/0x33f0\n _copy_to_iter+0x36c/0x33f0\n __skb_datagram_iter+0x196/0x12c0\n skb_copy_datagram_iter+0x5b/0x210\n netlink_recvmsg+0x37b/0xef0\n ...\n Uninit was created at:\n __alloc_skb+0x8ca/0x10e0\n mpls_getroute+0x1280/0x3a40\n rtnetlink_rcv_msg+0x1138/0x15a0\n ...\n Byte 19 of 64 is uninitialized\n\n(byte 19 = nlmsghdr(16) + rtmsg offset 3 = rtm_tos)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:39:14.107Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/248718fd88b146d8bdc7610ecd1eb4cd16e0b5a1"
},
{
"url": "https://git.kernel.org/stable/c/466b474a8deb0c93b5280c6d261e5eda6482eca7"
},
{
"url": "https://git.kernel.org/stable/c/ba56f88aab18d982f2a21f11390f4d8a8897782a"
},
{
"url": "https://git.kernel.org/stable/c/95651461cf77cc6590fa08c87667717e5dcfa55d"
},
{
"url": "https://git.kernel.org/stable/c/1fea5ff0eb4aa7e951bb3d380248566c473aa377"
},
{
"url": "https://git.kernel.org/stable/c/a5cdd2407dd890f741f59b8367e4c6c101cce154"
},
{
"url": "https://git.kernel.org/stable/c/2dc2fffc704a4365cae1aae078ba62223aaeff93"
},
{
"url": "https://git.kernel.org/stable/c/295dd295e2137e10e9a5b1891d97e0f08de76f03"
}
],
"title": "net: mpls: initialize rtm_tos in mpls_getroute()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74577",
"datePublished": "2026-08-15T12:28:14.408Z",
"dateReserved": "2026-08-15T05:44:03.917Z",
"dateUpdated": "2026-08-19T16:39:14.107Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-45963 (GCVE-0-2026-45963)
Vulnerability from cvelistv5
Published
2026-05-27 12:18
Modified
2026-09-02 12:49
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ASoC: nau8821: Cancel delayed work on component remove
Attempting to unload the driver while a jack detection work is pending
would likely crash the kernel when it is eventually scheduled for
execution:
[ 1984.896308] BUG: unable to handle page fault for address: ffffffffc10c2a20
[...]
[ 1984.896388] Hardware name: Valve Jupiter/Jupiter, BIOS F7A0131 01/30/2024
[ 1984.896396] Workqueue: events nau8821_jdet_work [snd_soc_nau8821]
[ 1984.896414] RIP: 0010:__mutex_lock+0x9f/0x11d0
[...]
[ 1984.896504] Call Trace:
[ 1984.896511] <TASK>
[ 1984.896524] ? snd_soc_dapm_disable_pin+0x26/0x60 [snd_soc_core]
[ 1984.896572] ? snd_soc_dapm_disable_pin+0x26/0x60 [snd_soc_core]
[ 1984.896596] snd_soc_dapm_disable_pin+0x26/0x60 [snd_soc_core]
[ 1984.896622] nau8821_jdet_work+0xeb/0x1e0 [snd_soc_nau8821]
[ 1984.896636] process_one_work+0x211/0x590
[ 1984.896649] ? srso_return_thunk+0x5/0x5f
[ 1984.896670] worker_thread+0x1cd/0x3a0
Cancel unscheduled jdet_work or wait for its execution to finish before
the component driver gets removed.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: aab1ad11d69fa7f35cb88105614ea7911598e1d6 Version: aab1ad11d69fa7f35cb88105614ea7911598e1d6 Version: aab1ad11d69fa7f35cb88105614ea7911598e1d6 Version: aab1ad11d69fa7f35cb88105614ea7911598e1d6 Version: aab1ad11d69fa7f35cb88105614ea7911598e1d6 Version: aab1ad11d69fa7f35cb88105614ea7911598e1d6 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"sound/soc/codecs/nau8821.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "cd6b991de3e0b68560fe98dc739672747d2e4204",
"status": "affected",
"version": "aab1ad11d69fa7f35cb88105614ea7911598e1d6",
"versionType": "git"
},
{
"lessThan": "36fb28fa033f6544d81f1cc056b27d0c0bf26d4f",
"status": "affected",
"version": "aab1ad11d69fa7f35cb88105614ea7911598e1d6",
"versionType": "git"
},
{
"lessThan": "9210ae708ddead67f55610342ea03fe9d4de6005",
"status": "affected",
"version": "aab1ad11d69fa7f35cb88105614ea7911598e1d6",
"versionType": "git"
},
{
"lessThan": "13d20517bee1c9b69c7750026c61e7ec021080a4",
"status": "affected",
"version": "aab1ad11d69fa7f35cb88105614ea7911598e1d6",
"versionType": "git"
},
{
"lessThan": "3955767ec39dcc0358470ffe6535703e2b7fd815",
"status": "affected",
"version": "aab1ad11d69fa7f35cb88105614ea7911598e1d6",
"versionType": "git"
},
{
"lessThan": "dbd3fd05cddfdeec1e49b0a66269881c09eebd17",
"status": "affected",
"version": "aab1ad11d69fa7f35cb88105614ea7911598e1d6",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"sound/soc/codecs/nau8821.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.16"
},
{
"lessThan": "5.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.187",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.156",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.108",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.49",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.19.*",
"status": "unaffected",
"version": "6.19.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.0",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.187",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.156",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.108",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.49",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.19.4",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0",
"versionStartIncluding": "5.16",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: nau8821: Cancel delayed work on component remove\n\nAttempting to unload the driver while a jack detection work is pending\nwould likely crash the kernel when it is eventually scheduled for\nexecution:\n\n[ 1984.896308] BUG: unable to handle page fault for address: ffffffffc10c2a20\n[...]\n[ 1984.896388] Hardware name: Valve Jupiter/Jupiter, BIOS F7A0131 01/30/2024\n[ 1984.896396] Workqueue: events nau8821_jdet_work [snd_soc_nau8821]\n[ 1984.896414] RIP: 0010:__mutex_lock+0x9f/0x11d0\n[...]\n[ 1984.896504] Call Trace:\n[ 1984.896511] \u003cTASK\u003e\n[ 1984.896524] ? snd_soc_dapm_disable_pin+0x26/0x60 [snd_soc_core]\n[ 1984.896572] ? snd_soc_dapm_disable_pin+0x26/0x60 [snd_soc_core]\n[ 1984.896596] snd_soc_dapm_disable_pin+0x26/0x60 [snd_soc_core]\n[ 1984.896622] nau8821_jdet_work+0xeb/0x1e0 [snd_soc_nau8821]\n[ 1984.896636] process_one_work+0x211/0x590\n[ 1984.896649] ? srso_return_thunk+0x5/0x5f\n[ 1984.896670] worker_thread+0x1cd/0x3a0\n\nCancel unscheduled jdet_work or wait for its execution to finish before\nthe component driver gets removed."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-02T12:49:32.465Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/cd6b991de3e0b68560fe98dc739672747d2e4204"
},
{
"url": "https://git.kernel.org/stable/c/36fb28fa033f6544d81f1cc056b27d0c0bf26d4f"
},
{
"url": "https://git.kernel.org/stable/c/9210ae708ddead67f55610342ea03fe9d4de6005"
},
{
"url": "https://git.kernel.org/stable/c/13d20517bee1c9b69c7750026c61e7ec021080a4"
},
{
"url": "https://git.kernel.org/stable/c/3955767ec39dcc0358470ffe6535703e2b7fd815"
},
{
"url": "https://git.kernel.org/stable/c/dbd3fd05cddfdeec1e49b0a66269881c09eebd17"
}
],
"title": "ASoC: nau8821: Cancel delayed work on component remove",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-45963",
"datePublished": "2026-05-27T12:18:21.228Z",
"dateReserved": "2026-05-13T15:03:33.089Z",
"dateUpdated": "2026-09-02T12:49:32.465Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68186 (GCVE-0-2026-68186)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
binfmt_misc: set have_execfd only once the interpreter is opened
load_misc_binary() raises bprm->have_execfd as soon as it sees the 'O'
(or 'C') flag. This happens well before it opens the interpreter. If
that open fails the flag stays set on the bprm. binfmt_misc is at the
head of the format list so an interpreter open failure that returns
-ENOEXEC lets the search fall through to a later format. This means it
runs the matched binary directly having never staged an interpreter. So
bprm->executable is NULL while have_execfd falsely claims a descriptor
is present.
Consequently, begin_new_exec() dereferences the missing executable:
would_dump(bprm, bprm->executable);
and NULL derefs. Had it not, the hand-off later in the same function
would have failed anyway. FD_ADD(0, bprm->executable) rejects a NULL
file with -ENOMEM. Both sites are past the point of no return so the
exec cannot be unwound either way.
This can be reached by unprivileged users as binfmt_misc can be mounted
in user namespaces. So a user can register an 'O' entry whose
interpreter lives on a FUSE mount, have the FUSE server fail the open
with -ENOEXEC and execute a native ELF file that matches the entry.
have_execfd only means anything alongside the executable it describes
which is not set until the interpreter has been opened and staged.
So lets raise it there, next to execfd_creds, which is already set at
that point. An open failure now leaves it clear, so the fallback format
derives credentials from the binary and emits no AT_EXECFD, as it would
for any native exec. The argv rewrite load_misc_binary() performs before
the open is still not undone. This means the binary sees the interpreter
path in argv[0] and its own path in argv[1] but that predates this
change and only became observable once the exec stopped faulting.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: bc2bf338d54b7aadaed49bb45b9e10d4592b2a46 Version: bc2bf338d54b7aadaed49bb45b9e10d4592b2a46 Version: bc2bf338d54b7aadaed49bb45b9e10d4592b2a46 Version: bc2bf338d54b7aadaed49bb45b9e10d4592b2a46 Version: bc2bf338d54b7aadaed49bb45b9e10d4592b2a46 Version: bc2bf338d54b7aadaed49bb45b9e10d4592b2a46 Version: bc2bf338d54b7aadaed49bb45b9e10d4592b2a46 Version: bc2bf338d54b7aadaed49bb45b9e10d4592b2a46 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/binfmt_misc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a8e9e9450df44e9dd529ec5beff283f48f4f4b97",
"status": "affected",
"version": "bc2bf338d54b7aadaed49bb45b9e10d4592b2a46",
"versionType": "git"
},
{
"lessThan": "a261dc49d99681c9c71f38d16e31812dc3e30412",
"status": "affected",
"version": "bc2bf338d54b7aadaed49bb45b9e10d4592b2a46",
"versionType": "git"
},
{
"lessThan": "40c09b7a1d4e0a4866042c87c2bd911bb57566c8",
"status": "affected",
"version": "bc2bf338d54b7aadaed49bb45b9e10d4592b2a46",
"versionType": "git"
},
{
"lessThan": "0f19d54e2524f0bf183b82f365ae4e49b4a2f788",
"status": "affected",
"version": "bc2bf338d54b7aadaed49bb45b9e10d4592b2a46",
"versionType": "git"
},
{
"lessThan": "2dd0298905e97795a9c5ec30cf5b41975f821632",
"status": "affected",
"version": "bc2bf338d54b7aadaed49bb45b9e10d4592b2a46",
"versionType": "git"
},
{
"lessThan": "1cd4e9b7967dab48c9f79a00b06ffff7208c0993",
"status": "affected",
"version": "bc2bf338d54b7aadaed49bb45b9e10d4592b2a46",
"versionType": "git"
},
{
"lessThan": "5ccc99d58f94fad258c9c375715b3974e48620e8",
"status": "affected",
"version": "bc2bf338d54b7aadaed49bb45b9e10d4592b2a46",
"versionType": "git"
},
{
"lessThan": "bbf5f639918dc011aaf60aab8480218758ee68c5",
"status": "affected",
"version": "bc2bf338d54b7aadaed49bb45b9e10d4592b2a46",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/binfmt_misc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.8"
},
{
"lessThan": "5.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbinfmt_misc: set have_execfd only once the interpreter is opened\n\nload_misc_binary() raises bprm-\u003ehave_execfd as soon as it sees the \u0027O\u0027\n(or \u0027C\u0027) flag. This happens well before it opens the interpreter. If\nthat open fails the flag stays set on the bprm. binfmt_misc is at the\nhead of the format list so an interpreter open failure that returns\n-ENOEXEC lets the search fall through to a later format. This means it\nruns the matched binary directly having never staged an interpreter. So\nbprm-\u003eexecutable is NULL while have_execfd falsely claims a descriptor\nis present.\n\nConsequently, begin_new_exec() dereferences the missing executable:\n\n would_dump(bprm, bprm-\u003eexecutable);\n\nand NULL derefs. Had it not, the hand-off later in the same function\nwould have failed anyway. FD_ADD(0, bprm-\u003eexecutable) rejects a NULL\nfile with -ENOMEM. Both sites are past the point of no return so the\nexec cannot be unwound either way.\n\nThis can be reached by unprivileged users as binfmt_misc can be mounted\nin user namespaces. So a user can register an \u0027O\u0027 entry whose\ninterpreter lives on a FUSE mount, have the FUSE server fail the open\nwith -ENOEXEC and execute a native ELF file that matches the entry.\n\nhave_execfd only means anything alongside the executable it describes\nwhich is not set until the interpreter has been opened and staged.\nSo lets raise it there, next to execfd_creds, which is already set at\nthat point. An open failure now leaves it clear, so the fallback format\nderives credentials from the binary and emits no AT_EXECFD, as it would\nfor any native exec. The argv rewrite load_misc_binary() performs before\nthe open is still not undone. This means the binary sees the interpreter\npath in argv[0] and its own path in argv[1] but that predates this\nchange and only became observable once the exec stopped faulting."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:30:54.269Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a8e9e9450df44e9dd529ec5beff283f48f4f4b97"
},
{
"url": "https://git.kernel.org/stable/c/a261dc49d99681c9c71f38d16e31812dc3e30412"
},
{
"url": "https://git.kernel.org/stable/c/40c09b7a1d4e0a4866042c87c2bd911bb57566c8"
},
{
"url": "https://git.kernel.org/stable/c/0f19d54e2524f0bf183b82f365ae4e49b4a2f788"
},
{
"url": "https://git.kernel.org/stable/c/2dd0298905e97795a9c5ec30cf5b41975f821632"
},
{
"url": "https://git.kernel.org/stable/c/1cd4e9b7967dab48c9f79a00b06ffff7208c0993"
},
{
"url": "https://git.kernel.org/stable/c/5ccc99d58f94fad258c9c375715b3974e48620e8"
},
{
"url": "https://git.kernel.org/stable/c/bbf5f639918dc011aaf60aab8480218758ee68c5"
}
],
"title": "binfmt_misc: set have_execfd only once the interpreter is opened",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68186",
"datePublished": "2026-08-10T11:59:58.299Z",
"dateReserved": "2026-07-30T09:28:09.373Z",
"dateUpdated": "2026-08-19T16:30:54.269Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68194 (GCVE-0-2026-68194)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio buses
PKT_TYPE_TXRX_NOTIFY is an mmio-only event, but mt7921_rx_check() and
mt7921_queue_rx_skb() dispatch it to mt7921_mac_tx_free() on every bus.
mt7921_mac_tx_free() cleans the DMA tx queues with
mt76_queue_tx_cleanup(), which calls queue_ops->tx_cleanup(). Only the
mmio queue ops implement that callback; on USB and SDIO it is NULL, so
a TXRX_NOTIFY there calls a NULL pointer in the RX worker:
BUG: kernel NULL pointer dereference, address: 0000000000000000
RIP: 0010:0x0
Call Trace:
mt7921_mac_tx_free+0x64/0x310 [mt7921_common]
mt7921_rx_check+0x5f/0xf0 [mt7921_common]
mt76u_rx_worker+0x1b9/0x620 [mt76_usb]
Drop the event on non-mmio buses via mt76_is_mmio(), as in
commit 5683e1488aa9 ("wifi: mt76: connac: do not check WED status for
non-mmio devices").
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 48fab5bbef4092d925ab3214773ad12e68807223 Version: 48fab5bbef4092d925ab3214773ad12e68807223 Version: 48fab5bbef4092d925ab3214773ad12e68807223 Version: 48fab5bbef4092d925ab3214773ad12e68807223 Version: 48fab5bbef4092d925ab3214773ad12e68807223 Version: 48fab5bbef4092d925ab3214773ad12e68807223 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/mediatek/mt76/mt7921/mac.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "7003a2cbddd7917933c1f169c7874cfa6ab852c3",
"status": "affected",
"version": "48fab5bbef4092d925ab3214773ad12e68807223",
"versionType": "git"
},
{
"lessThan": "ef2ee5f820c3ef87643b51e960c20b4a14d8336b",
"status": "affected",
"version": "48fab5bbef4092d925ab3214773ad12e68807223",
"versionType": "git"
},
{
"lessThan": "ecf995b828191829ba4a87169bccabcbeb5c9c32",
"status": "affected",
"version": "48fab5bbef4092d925ab3214773ad12e68807223",
"versionType": "git"
},
{
"lessThan": "263816e92e8d66c81c98ccab2b5d2191ed08ec71",
"status": "affected",
"version": "48fab5bbef4092d925ab3214773ad12e68807223",
"versionType": "git"
},
{
"lessThan": "24475d2ddc8d8dfd82f4d2be0d951401f86911a6",
"status": "affected",
"version": "48fab5bbef4092d925ab3214773ad12e68807223",
"versionType": "git"
},
{
"lessThan": "da4082e91acabc1498611ed8ccc53f0610baefc6",
"status": "affected",
"version": "48fab5bbef4092d925ab3214773ad12e68807223",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/wireless/mediatek/mt76/mt7921/mac.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.16"
},
{
"lessThan": "5.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.16",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio buses\n\nPKT_TYPE_TXRX_NOTIFY is an mmio-only event, but mt7921_rx_check() and\nmt7921_queue_rx_skb() dispatch it to mt7921_mac_tx_free() on every bus.\nmt7921_mac_tx_free() cleans the DMA tx queues with\nmt76_queue_tx_cleanup(), which calls queue_ops-\u003etx_cleanup(). Only the\nmmio queue ops implement that callback; on USB and SDIO it is NULL, so\na TXRX_NOTIFY there calls a NULL pointer in the RX worker:\n\n BUG: kernel NULL pointer dereference, address: 0000000000000000\n RIP: 0010:0x0\n Call Trace:\n mt7921_mac_tx_free+0x64/0x310 [mt7921_common]\n mt7921_rx_check+0x5f/0xf0 [mt7921_common]\n mt76u_rx_worker+0x1b9/0x620 [mt76_usb]\n\nDrop the event on non-mmio buses via mt76_is_mmio(), as in\ncommit 5683e1488aa9 (\"wifi: mt76: connac: do not check WED status for\nnon-mmio devices\")."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:09.017Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/7003a2cbddd7917933c1f169c7874cfa6ab852c3"
},
{
"url": "https://git.kernel.org/stable/c/ef2ee5f820c3ef87643b51e960c20b4a14d8336b"
},
{
"url": "https://git.kernel.org/stable/c/ecf995b828191829ba4a87169bccabcbeb5c9c32"
},
{
"url": "https://git.kernel.org/stable/c/263816e92e8d66c81c98ccab2b5d2191ed08ec71"
},
{
"url": "https://git.kernel.org/stable/c/24475d2ddc8d8dfd82f4d2be0d951401f86911a6"
},
{
"url": "https://git.kernel.org/stable/c/da4082e91acabc1498611ed8ccc53f0610baefc6"
}
],
"title": "wifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio buses",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68194",
"datePublished": "2026-08-10T12:00:12.245Z",
"dateReserved": "2026-07-30T09:28:09.374Z",
"dateUpdated": "2026-08-19T16:31:09.017Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80890 (GCVE-0-2026-80890)
Vulnerability from cvelistv5
Published
2026-09-04 17:11
Modified
2026-09-04 17:11
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
sctp: reject stale cookies with mismatched verification tags
sctp_unpack_cookie() skips cookie expiration checks whenever an
association already exists. This is broader than the exception in
RFC 9260 Section 5.2.4.
For an existing association, Section 5.2.4 permits an expired State
Cookie only when both Verification Tags in the cookie match the current
association. Otherwise, the packet SHOULD be discarded and a Stale
Cookie ERROR MUST be sent.
The broad check lets an expired Action A restart cookie reach
sctp_sf_do_dupcook_a(). In a runtime test with the default 60 second
cookie lifetime, replaying such a cookie after 65 seconds returned a
COOKIE-ACK and restarted the association.
Check cookie expiration unless both Verification Tags match. This
preserves the Action D exception for a lost COOKIE ACK while rejecting
expired cookies in all other cases.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/sctp/sm_make_chunk.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "f6e3cc296372accad4ee57405195021231ef4bcb",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "c151daba0ceb1fb068a215b07de89fb1eb5f87bc",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "817cffdbdbdf50e1f2b016599d1897de3ca54964",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "61baa5020b0afb41bfd97f8f6ce5e336c4a4546e",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "c68557a49e960dbcdede22c7a9b488603078b8b4",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "a0d1693923f41d6f49083aa2446686aed09d1d79",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "35c279113498d19a8734e2aae67b951b9b20f634",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "9d8da8e0a9bce4a340af60dd0446bc7eb8d07587",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/sctp/sm_make_chunk.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: reject stale cookies with mismatched verification tags\n\nsctp_unpack_cookie() skips cookie expiration checks whenever an\nassociation already exists. This is broader than the exception in\nRFC 9260 Section 5.2.4.\n\nFor an existing association, Section 5.2.4 permits an expired State\nCookie only when both Verification Tags in the cookie match the current\nassociation. Otherwise, the packet SHOULD be discarded and a Stale\nCookie ERROR MUST be sent.\n\nThe broad check lets an expired Action A restart cookie reach\nsctp_sf_do_dupcook_a(). In a runtime test with the default 60 second\ncookie lifetime, replaying such a cookie after 65 seconds returned a\nCOOKIE-ACK and restarted the association.\n\nCheck cookie expiration unless both Verification Tags match. This\npreserves the Action D exception for a lost COOKIE ACK while rejecting\nexpired cookies in all other cases."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T17:11:06.742Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/f6e3cc296372accad4ee57405195021231ef4bcb"
},
{
"url": "https://git.kernel.org/stable/c/c151daba0ceb1fb068a215b07de89fb1eb5f87bc"
},
{
"url": "https://git.kernel.org/stable/c/817cffdbdbdf50e1f2b016599d1897de3ca54964"
},
{
"url": "https://git.kernel.org/stable/c/61baa5020b0afb41bfd97f8f6ce5e336c4a4546e"
},
{
"url": "https://git.kernel.org/stable/c/c68557a49e960dbcdede22c7a9b488603078b8b4"
},
{
"url": "https://git.kernel.org/stable/c/a0d1693923f41d6f49083aa2446686aed09d1d79"
},
{
"url": "https://git.kernel.org/stable/c/35c279113498d19a8734e2aae67b951b9b20f634"
},
{
"url": "https://git.kernel.org/stable/c/9d8da8e0a9bce4a340af60dd0446bc7eb8d07587"
}
],
"title": "sctp: reject stale cookies with mismatched verification tags",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80890",
"datePublished": "2026-09-04T17:11:06.742Z",
"dateReserved": "2026-08-26T14:34:25.799Z",
"dateUpdated": "2026-09-04T17:11:06.742Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68227 (GCVE-0-2026-68227)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: cx231xx: fix devres lifetime
USB drivers bind to USB interfaces and any device managed resources
should have their lifetime tied to the interface rather than parent USB
device. This avoids issues like memory leaks when drivers are unbound
without their devices being physically disconnected (e.g. on probe
deferral or configuration changes).
Fix the driver state lifetime so that it is released on driver unbind.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 184a82784d50ad82aadc3917a3bdd8314a0e9b9b Version: 184a82784d50ad82aadc3917a3bdd8314a0e9b9b Version: 184a82784d50ad82aadc3917a3bdd8314a0e9b9b Version: 184a82784d50ad82aadc3917a3bdd8314a0e9b9b Version: 184a82784d50ad82aadc3917a3bdd8314a0e9b9b Version: 184a82784d50ad82aadc3917a3bdd8314a0e9b9b Version: 184a82784d50ad82aadc3917a3bdd8314a0e9b9b Version: 184a82784d50ad82aadc3917a3bdd8314a0e9b9b |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/media/usb/cx231xx/cx231xx-cards.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "1770fc4e2b47b1185e6f688d4012bc91f7543854",
"status": "affected",
"version": "184a82784d50ad82aadc3917a3bdd8314a0e9b9b",
"versionType": "git"
},
{
"lessThan": "c07f535bcdd3f956d4c32085535368f46ba99ba0",
"status": "affected",
"version": "184a82784d50ad82aadc3917a3bdd8314a0e9b9b",
"versionType": "git"
},
{
"lessThan": "0ea4b6fd49f7bed3a7e2b8734c15d9699dabe26f",
"status": "affected",
"version": "184a82784d50ad82aadc3917a3bdd8314a0e9b9b",
"versionType": "git"
},
{
"lessThan": "a373f1a5137e96549a795e7fb9efb5de0ae1d065",
"status": "affected",
"version": "184a82784d50ad82aadc3917a3bdd8314a0e9b9b",
"versionType": "git"
},
{
"lessThan": "c5ccb01eb1107acb6aab8ce8fe5a523f215c837e",
"status": "affected",
"version": "184a82784d50ad82aadc3917a3bdd8314a0e9b9b",
"versionType": "git"
},
{
"lessThan": "f468b7ee5d6332b01e6c538179a4c720e6dae93b",
"status": "affected",
"version": "184a82784d50ad82aadc3917a3bdd8314a0e9b9b",
"versionType": "git"
},
{
"lessThan": "e797e252bfb3d0d4b3d38e4faef817e05869c240",
"status": "affected",
"version": "184a82784d50ad82aadc3917a3bdd8314a0e9b9b",
"versionType": "git"
},
{
"lessThan": "7d6358ab02866e5b7ed8d3a00805297617bbb0ec",
"status": "affected",
"version": "184a82784d50ad82aadc3917a3bdd8314a0e9b9b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/media/usb/cx231xx/cx231xx-cards.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.17"
},
{
"lessThan": "3.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.17",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: cx231xx: fix devres lifetime\n\nUSB drivers bind to USB interfaces and any device managed resources\nshould have their lifetime tied to the interface rather than parent USB\ndevice. This avoids issues like memory leaks when drivers are unbound\nwithout their devices being physically disconnected (e.g. on probe\ndeferral or configuration changes).\n\nFix the driver state lifetime so that it is released on driver unbind."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:59.091Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/1770fc4e2b47b1185e6f688d4012bc91f7543854"
},
{
"url": "https://git.kernel.org/stable/c/c07f535bcdd3f956d4c32085535368f46ba99ba0"
},
{
"url": "https://git.kernel.org/stable/c/0ea4b6fd49f7bed3a7e2b8734c15d9699dabe26f"
},
{
"url": "https://git.kernel.org/stable/c/a373f1a5137e96549a795e7fb9efb5de0ae1d065"
},
{
"url": "https://git.kernel.org/stable/c/c5ccb01eb1107acb6aab8ce8fe5a523f215c837e"
},
{
"url": "https://git.kernel.org/stable/c/f468b7ee5d6332b01e6c538179a4c720e6dae93b"
},
{
"url": "https://git.kernel.org/stable/c/e797e252bfb3d0d4b3d38e4faef817e05869c240"
},
{
"url": "https://git.kernel.org/stable/c/7d6358ab02866e5b7ed8d3a00805297617bbb0ec"
}
],
"title": "media: cx231xx: fix devres lifetime",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68227",
"datePublished": "2026-08-10T12:00:49.821Z",
"dateReserved": "2026-07-30T09:28:09.376Z",
"dateUpdated": "2026-08-19T16:31:59.091Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74683 (GCVE-0-2026-74683)
Vulnerability from cvelistv5
Published
2026-08-22 15:32
Modified
2026-08-25 05:23
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Input: evdev - sanitize event type index when fetching event masks
The user-supplied event type index passed to EVIOCGMASK / EVIOCSMASK
ioctls is used to index the static counts array in evdev_get_mask_cnt()
and client evmasks array in evdev_get_mask().
While the event type is architecturally bounded by EV_CNT, speculative
execution may mispredict bounds checks and perform out-of-bounds loads.
Sanitize the event type index in evdev_get_mask_cnt() branchlessly using
array_index_mask_nospec(). This clamps the index to 0 for safe array
access and forces the returned count to 0 speculatively when the index
is out of bounds.
We do not need additional array_index_nospec() calls in evdev_get_mask()
because evdev_get_mask_cnt() speculatively forces the count (and
resulting xfer_size) to 0 for out-of-bounds types, preventing any
speculative memory access to client evmasks array.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 06a16293f71927f756dcf37558a79c0b05a91641 Version: 06a16293f71927f756dcf37558a79c0b05a91641 Version: 06a16293f71927f756dcf37558a79c0b05a91641 Version: 06a16293f71927f756dcf37558a79c0b05a91641 Version: 06a16293f71927f756dcf37558a79c0b05a91641 Version: 06a16293f71927f756dcf37558a79c0b05a91641 Version: 06a16293f71927f756dcf37558a79c0b05a91641 Version: 06a16293f71927f756dcf37558a79c0b05a91641 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/input/evdev.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c79b08d8fa230871a3634e34a66e591ac2d084ef",
"status": "affected",
"version": "06a16293f71927f756dcf37558a79c0b05a91641",
"versionType": "git"
},
{
"lessThan": "f27fa9b39f925d26e034a1f382cb45523138f4ae",
"status": "affected",
"version": "06a16293f71927f756dcf37558a79c0b05a91641",
"versionType": "git"
},
{
"lessThan": "f3fc329acad9a71b3c077237cbac20670d2358c8",
"status": "affected",
"version": "06a16293f71927f756dcf37558a79c0b05a91641",
"versionType": "git"
},
{
"lessThan": "5db341189bb7ff041d570dbe36ecca7e32913927",
"status": "affected",
"version": "06a16293f71927f756dcf37558a79c0b05a91641",
"versionType": "git"
},
{
"lessThan": "433913b4a92214d76e9f0c03ad9128fec943d5f8",
"status": "affected",
"version": "06a16293f71927f756dcf37558a79c0b05a91641",
"versionType": "git"
},
{
"lessThan": "4034ef247a9dde3f56660b01f0c3280dac6b1274",
"status": "affected",
"version": "06a16293f71927f756dcf37558a79c0b05a91641",
"versionType": "git"
},
{
"lessThan": "810e1883d4815f29c30d900ad7333d03cc2515d1",
"status": "affected",
"version": "06a16293f71927f756dcf37558a79c0b05a91641",
"versionType": "git"
},
{
"lessThan": "3abd29c61d2ef37c4102cf755b18be53bb9dbea6",
"status": "affected",
"version": "06a16293f71927f756dcf37558a79c0b05a91641",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/input/evdev.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.4"
},
{
"lessThan": "4.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "4.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "4.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "4.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "4.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nInput: evdev - sanitize event type index when fetching event masks\n\nThe user-supplied event type index passed to EVIOCGMASK / EVIOCSMASK\nioctls is used to index the static counts array in evdev_get_mask_cnt()\nand client evmasks array in evdev_get_mask().\n\nWhile the event type is architecturally bounded by EV_CNT, speculative\nexecution may mispredict bounds checks and perform out-of-bounds loads.\n\nSanitize the event type index in evdev_get_mask_cnt() branchlessly using\narray_index_mask_nospec(). This clamps the index to 0 for safe array\naccess and forces the returned count to 0 speculatively when the index\nis out of bounds.\n\nWe do not need additional array_index_nospec() calls in evdev_get_mask()\nbecause evdev_get_mask_cnt() speculatively forces the count (and\nresulting xfer_size) to 0 for out-of-bounds types, preventing any\nspeculative memory access to client evmasks array."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:23:19.336Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c79b08d8fa230871a3634e34a66e591ac2d084ef"
},
{
"url": "https://git.kernel.org/stable/c/f27fa9b39f925d26e034a1f382cb45523138f4ae"
},
{
"url": "https://git.kernel.org/stable/c/f3fc329acad9a71b3c077237cbac20670d2358c8"
},
{
"url": "https://git.kernel.org/stable/c/5db341189bb7ff041d570dbe36ecca7e32913927"
},
{
"url": "https://git.kernel.org/stable/c/433913b4a92214d76e9f0c03ad9128fec943d5f8"
},
{
"url": "https://git.kernel.org/stable/c/4034ef247a9dde3f56660b01f0c3280dac6b1274"
},
{
"url": "https://git.kernel.org/stable/c/810e1883d4815f29c30d900ad7333d03cc2515d1"
},
{
"url": "https://git.kernel.org/stable/c/3abd29c61d2ef37c4102cf755b18be53bb9dbea6"
}
],
"title": "Input: evdev - sanitize event type index when fetching event masks",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74683",
"datePublished": "2026-08-22T15:32:50.192Z",
"dateReserved": "2026-08-15T05:44:03.926Z",
"dateUpdated": "2026-08-25T05:23:19.336Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72113 (GCVE-0-2026-72113)
Vulnerability from cvelistv5
Published
2026-08-15 05:52
Modified
2026-08-19 16:35
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
can: bcm: add missing device refcount for CAN filter removal
sashiko-bot remarked a problem with a concurrent device unregistration
in isotp.c which also is present in the bcm.c code. A former fix for raw.c
commit c275a176e4b6 ("can: raw: add missing refcount for memory leak fix")
introduced a netdevice_tracker which solves the issue for bcm.c too.
bcm_release(), bcm_delete_rx_op() and bcm_notifier() relied on
dev_get_by_index(ifindex) to re-find the device for an rx_op before
unregistering its filter. If a concurrent NETDEV_UNREGISTER has already
unlisted the device from the ifindex table, that lookup fails and
can_rx_unregister() is silently skipped, leaving a stale CAN filter
pointing at the soon-to-be-freed bcm_op/socket.
Hold a netdev_hold()/netdev_put() tracked reference on op->rx_reg_dev
from the moment the rx filter is registered in bcm_rx_setup() until it
is unregistered in bcm_rx_unreg(), and use that reference directly in
bcm_release() and bcm_delete_rx_op() instead of re-looking the device
up by ifindex.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 Version: ffd980f976e7fd666c2e61bf8ab35107efd11828 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/can/bcm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "bd5232663524e94cc5aad861dca11e3db8e2ab6f",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "ee8b36d0faca08f35b889b6e9aa850695e5b8ba9",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "dcaee869913c7210cd47ed0a8f27349d7bdcdb7b",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "84aa4807816e405c1bf87114fc63e06d244281ef",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "633bda66fbf309f5de5e1ad6defe8e6b1d77a20f",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "b024c21c9066f6957b7d4a8f2037e4b000c5e041",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "04d23061bbf18d5d81022eb21e9d32e99d24468d",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
},
{
"lessThan": "d59948293ea34b6337ce2b5febab8510de70048c",
"status": "affected",
"version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/can/bcm.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.25"
},
{
"lessThan": "2.6.25",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "2.6.25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.25",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: bcm: add missing device refcount for CAN filter removal\n\nsashiko-bot remarked a problem with a concurrent device unregistration\nin isotp.c which also is present in the bcm.c code. A former fix for raw.c\ncommit c275a176e4b6 (\"can: raw: add missing refcount for memory leak fix\")\nintroduced a netdevice_tracker which solves the issue for bcm.c too.\n\nbcm_release(), bcm_delete_rx_op() and bcm_notifier() relied on\ndev_get_by_index(ifindex) to re-find the device for an rx_op before\nunregistering its filter. If a concurrent NETDEV_UNREGISTER has already\nunlisted the device from the ifindex table, that lookup fails and\ncan_rx_unregister() is silently skipped, leaving a stale CAN filter\npointing at the soon-to-be-freed bcm_op/socket.\n\nHold a netdev_hold()/netdev_put() tracked reference on op-\u003erx_reg_dev\nfrom the moment the rx filter is registered in bcm_rx_setup() until it\nis unregistered in bcm_rx_unreg(), and use that reference directly in\nbcm_release() and bcm_delete_rx_op() instead of re-looking the device\nup by ifindex."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires local syscalls (socket/sendmsg/close) on PF_CAN/CAN_BCM and concurrent netdev teardown via netlink; the flaw is in local filter cleanup, not remote IP packet handling.\nAC:L - An attacker can reliably win the race by concurrently closing the BCM socket or issuing RX_DELETE while deleting the bound vcan/CAN interface from the same user namespace.\nPR:L - BCM sockets need no special capability, and CAP_NET_ADMIN for creating/deleting vcan interfaces is obtainable by unprivileged users via user namespaces (unshare -Urn).\nUI:N - No victim interaction is required; exploitation is fully attacker-driven through BCM socket setup, concurrent netdev removal, and subsequent CAN traffic to hit the stale filter.\nS:U - Impact is confined to kernel memory corruption and privilege escalation within the same security authority; it does not cross VM, container, or IOMMU boundaries.\nC:H - Stale CAN filters leave a use-after-free on freed bcm_op structures; bcm_rx_handler dereferences attacker-influenced freed memory, enabling arbitrary kernel memory disclosure via heap grooming.\nI:H - The UAF in bcm_rx_handler provides write primitives over freed bcm_op fields (timers, frame buffers, socket pointers), enabling control-flow hijacking and arbitrary kernel code execution.\nA:H - Accessing the freed bcm_op from bcm_rx_handler causes kernel oops/panic; UAF is inherently crash-prone even before full exploitation."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:35:58.404Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/bd5232663524e94cc5aad861dca11e3db8e2ab6f"
},
{
"url": "https://git.kernel.org/stable/c/ee8b36d0faca08f35b889b6e9aa850695e5b8ba9"
},
{
"url": "https://git.kernel.org/stable/c/dcaee869913c7210cd47ed0a8f27349d7bdcdb7b"
},
{
"url": "https://git.kernel.org/stable/c/84aa4807816e405c1bf87114fc63e06d244281ef"
},
{
"url": "https://git.kernel.org/stable/c/633bda66fbf309f5de5e1ad6defe8e6b1d77a20f"
},
{
"url": "https://git.kernel.org/stable/c/b024c21c9066f6957b7d4a8f2037e4b000c5e041"
},
{
"url": "https://git.kernel.org/stable/c/04d23061bbf18d5d81022eb21e9d32e99d24468d"
},
{
"url": "https://git.kernel.org/stable/c/d59948293ea34b6337ce2b5febab8510de70048c"
}
],
"title": "can: bcm: add missing device refcount for CAN filter removal",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72113",
"datePublished": "2026-08-15T05:52:54.001Z",
"dateReserved": "2026-08-09T03:40:39.906Z",
"dateUpdated": "2026-08-19T16:35:58.404Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-64582 (GCVE-0-2026-64582)
Vulnerability from cvelistv5
Published
2026-08-05 11:25
Modified
2026-08-19 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
RDMA/rxe: Fix a use-after-free problem in rxe_mmap
rxe_mmap() removes a rxe_mmap_info struct from the pending_mmaps list
and releases pending_lock while the struct's kref is still at 1:
list_del_init(&ip->pending_mmaps);
spin_unlock_bh(&rxe->pending_lock); /* ref == 1, no lock held */
ret = remap_vmalloc_range(vma, ip->obj, 0); /* walks PTEs */
[...]
rxe_vma_open(vma); /* kref_get, ref → 2 */
remap_vmalloc_range_partial() walks PTEs without any lock.
A concurrent DESTROY_CQ ioctl on another CPU calls:
kref_put(&q->ip->ref, rxe_mmap_release) /* ref 1→0 */
vfree(ip->obj) /* clears vmalloc PTEs mid-walk */
kfree(ip) /* frees rxe_mmap_info */
This yields:
1. Kernel crash, vmalloc_to_page() returns NULL when vfree wins the
per-PTE race -> vm_insert_page(NULL) → GPF in validate_page_before_insert
2. Page UAF, vmalloc_to_page() reads a stale PTE before vfree clears
it. User VMA holds a PTE to a free'd page which might eventually get
reallocated later by vmalloc which allows the attacker to get a clean
page-level UAF.
It is worth noting that even though a page-level UAF is possible given
the strong primitive, it is statistically very difficult to achieve
given the very short time window (after the last insert_page and before
the kref_get).
The call trace are as below:
Oops: general protection fault, probably for non-canonical address 0xdffffc0000000001: 0000 [#1] SMP KASAN NOPTI
KASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f]
CPU: 0 UID: 1000 PID: 413 Comm: poc Not tainted 7.0.0-rc5-dirty #28 PREEMPT(lazy)
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014
RIP: 0010:validate_page_before_insert+0x32/0x300
Code: e5 41 57 41 56 49 89 fe 41 55 41 54 53 48 89 f3 e8 93 b5 a3 ff 48 8d 7b 08 48 b8 00 00 00 00 00 fc ff df 48 89 fa 48 c1 ea 03 <80> 3c 02 00 0f 85 7b 02 00 00 4c 8b 63 08 31 ff 4d 89 e5 41 83 e5
RSP: 0018:ffff88811b15f2f0 EFLAGS: 00000202
RAX: dffffc0000000000 RBX: 0000000000000000 RCX: 0000000000000000
RDX: 0000000000000001 RSI: 0000000000000000 RDI: 0000000000000008
RBP: ffff88811b15f318 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000000 R12: ffff8881181eee00
R13: 0000000000000000 R14: ffff8881181eee00 R15: ffff8881181eee20
FS: 00007b1e000f76c0(0000) GS:ffff8884268e0000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007b1e00a24ac0 CR3: 0000000116eb3000 CR4: 00000000000006f0
Call Trace:
<TASK>
insert_page+0x8f/0x190
? __pfx_insert_page+0x10/0x10
? kasan_save_alloc_info+0x38/0x60
vm_insert_page+0x2e7/0x400
remap_vmalloc_range_partial+0x212/0x3e0
remap_vmalloc_range+0x6e/0xb0
? __kasan_check_write+0x14/0x30
rxe_mmap+0x2e9/0x5d0
ib_uverbs_mmap+0x1ad/0x2c0
__mmap_region+0x12c2/0x2ad0
? __pfx___mmap_region+0x10/0x10
? __sanitizer_cov_trace_switch+0x58/0xb0
? mas_prev_slot+0x360/0x39c0
? __sanitizer_cov_trace_switch+0x58/0xb0
? mas_next_slot+0x1e5b/0x2f40
? __sanitizer_cov_trace_cmp8+0x18/0x30
? unmapped_area_topdown+0x4dd/0x610
? kfree+0x1b1/0x440
? free_cpumask_var+0x16/0x30
? __kasan_slab_free+0x7d/0xa0
? __sanitizer_cov_trace_cmp8+0x18/0x30
mmap_region+0x2e6/0x3c0
do_mmap+0xa3e/0x12a0
? __pfx_do_mmap+0x10/0x10
? __kasan_check_write+0x14/0x30
? down_write_killable+0xba/0x160
? __pfx_down_write_killable+0x10/0x10
? __sanitizer_cov_trace_cmp4+0x16/0x30
vm_mmap_pgoff+0x2d4/0x4a0
? __pfx_vm_mmap_pgoff+0x10/0x10
? fget+0x1bf/0x270
ksys_mmap_pgoff+0x40c/0x690
? __sanitizer_cov_trace_const_cmp4+0x16/0x30
? __pfx_ksys_mmap_pgoff+0x10/0x10
? __kasan_check_write+0x14/0x30
? _raw_spin_trylock+0xbb/0x130
? __pfx__raw_spin_trylock+0x10/0x10
__x64_sys_mmap+0x135/0x1e0
x64_sys_c
---truncated---
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 8700e3e7c4857d28ebaa824509934556da0b3e76 Version: 8700e3e7c4857d28ebaa824509934556da0b3e76 Version: 8700e3e7c4857d28ebaa824509934556da0b3e76 Version: 8700e3e7c4857d28ebaa824509934556da0b3e76 Version: 8700e3e7c4857d28ebaa824509934556da0b3e76 Version: 8700e3e7c4857d28ebaa824509934556da0b3e76 Version: 8700e3e7c4857d28ebaa824509934556da0b3e76 Version: 8700e3e7c4857d28ebaa824509934556da0b3e76 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/sw/rxe/rxe_mmap.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b810352d0916796dabe633cdb9adee9863ab4911",
"status": "affected",
"version": "8700e3e7c4857d28ebaa824509934556da0b3e76",
"versionType": "git"
},
{
"lessThan": "aef5ea8578f97f2701039600846a8bcf5f21e863",
"status": "affected",
"version": "8700e3e7c4857d28ebaa824509934556da0b3e76",
"versionType": "git"
},
{
"lessThan": "3371f2036e0f970166bbb624e25bba46d32fa18e",
"status": "affected",
"version": "8700e3e7c4857d28ebaa824509934556da0b3e76",
"versionType": "git"
},
{
"lessThan": "665fb7d22a700c66a78db0cf88c6e6a649aba9d0",
"status": "affected",
"version": "8700e3e7c4857d28ebaa824509934556da0b3e76",
"versionType": "git"
},
{
"lessThan": "e038d42cc09ca1da9d3568ce8ae062b2bfb3bc0e",
"status": "affected",
"version": "8700e3e7c4857d28ebaa824509934556da0b3e76",
"versionType": "git"
},
{
"lessThan": "e59a6aa89e0fcd1d0707832eb4654fd9ae7d31e6",
"status": "affected",
"version": "8700e3e7c4857d28ebaa824509934556da0b3e76",
"versionType": "git"
},
{
"lessThan": "3525987a392536f31a484833af258971af63b24c",
"status": "affected",
"version": "8700e3e7c4857d28ebaa824509934556da0b3e76",
"versionType": "git"
},
{
"lessThan": "35744ab3d03c5fca8c1752f53fc8fc674e14c561",
"status": "affected",
"version": "8700e3e7c4857d28ebaa824509934556da0b3e76",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/sw/rxe/rxe_mmap.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.8"
},
{
"lessThan": "4.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "4.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/rxe: Fix a use-after-free problem in rxe_mmap\n\nrxe_mmap() removes a rxe_mmap_info struct from the pending_mmaps list\nand releases pending_lock while the struct\u0027s kref is still at 1:\n\n list_del_init(\u0026ip-\u003epending_mmaps);\n spin_unlock_bh(\u0026rxe-\u003epending_lock); /* ref == 1, no lock held */\n ret = remap_vmalloc_range(vma, ip-\u003eobj, 0); /* walks PTEs */\n [...]\n rxe_vma_open(vma); /* kref_get, ref \u2192 2 */\n remap_vmalloc_range_partial() walks PTEs without any lock.\n\nA concurrent DESTROY_CQ ioctl on another CPU calls:\n\n kref_put(\u0026q-\u003eip-\u003eref, rxe_mmap_release) /* ref 1\u21920 */\n vfree(ip-\u003eobj) /* clears vmalloc PTEs mid-walk */\n kfree(ip) /* frees rxe_mmap_info */\n\nThis yields:\n\n 1. Kernel crash, vmalloc_to_page() returns NULL when vfree wins the\n per-PTE race -\u003e vm_insert_page(NULL) \u2192 GPF in validate_page_before_insert\n\n 2. Page UAF, vmalloc_to_page() reads a stale PTE before vfree clears\n it. User VMA holds a PTE to a free\u0027d page which might eventually get\n reallocated later by vmalloc which allows the attacker to get a clean\n page-level UAF.\n\n It is worth noting that even though a page-level UAF is possible given\n the strong primitive, it is statistically very difficult to achieve\n given the very short time window (after the last insert_page and before\n the kref_get).\n\nThe call trace are as below:\n\n Oops: general protection fault, probably for non-canonical address 0xdffffc0000000001: 0000 [#1] SMP KASAN NOPTI\n KASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f]\n CPU: 0 UID: 1000 PID: 413 Comm: poc Not tainted 7.0.0-rc5-dirty #28 PREEMPT(lazy)\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014\n RIP: 0010:validate_page_before_insert+0x32/0x300\n Code: e5 41 57 41 56 49 89 fe 41 55 41 54 53 48 89 f3 e8 93 b5 a3 ff 48 8d 7b 08 48 b8 00 00 00 00 00 fc ff df 48 89 fa 48 c1 ea 03 \u003c80\u003e 3c 02 00 0f 85 7b 02 00 00 4c 8b 63 08 31 ff 4d 89 e5 41 83 e5\n RSP: 0018:ffff88811b15f2f0 EFLAGS: 00000202\n RAX: dffffc0000000000 RBX: 0000000000000000 RCX: 0000000000000000\n RDX: 0000000000000001 RSI: 0000000000000000 RDI: 0000000000000008\n RBP: ffff88811b15f318 R08: 0000000000000000 R09: 0000000000000000\n R10: 0000000000000000 R11: 0000000000000000 R12: ffff8881181eee00\n R13: 0000000000000000 R14: ffff8881181eee00 R15: ffff8881181eee20\n FS: 00007b1e000f76c0(0000) GS:ffff8884268e0000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 00007b1e00a24ac0 CR3: 0000000116eb3000 CR4: 00000000000006f0\n Call Trace:\n \u003cTASK\u003e\n insert_page+0x8f/0x190\n ? __pfx_insert_page+0x10/0x10\n ? kasan_save_alloc_info+0x38/0x60\n vm_insert_page+0x2e7/0x400\n remap_vmalloc_range_partial+0x212/0x3e0\n remap_vmalloc_range+0x6e/0xb0\n ? __kasan_check_write+0x14/0x30\n rxe_mmap+0x2e9/0x5d0\n ib_uverbs_mmap+0x1ad/0x2c0\n __mmap_region+0x12c2/0x2ad0\n ? __pfx___mmap_region+0x10/0x10\n ? __sanitizer_cov_trace_switch+0x58/0xb0\n ? mas_prev_slot+0x360/0x39c0\n ? __sanitizer_cov_trace_switch+0x58/0xb0\n ? mas_next_slot+0x1e5b/0x2f40\n ? __sanitizer_cov_trace_cmp8+0x18/0x30\n ? unmapped_area_topdown+0x4dd/0x610\n ? kfree+0x1b1/0x440\n ? free_cpumask_var+0x16/0x30\n ? __kasan_slab_free+0x7d/0xa0\n ? __sanitizer_cov_trace_cmp8+0x18/0x30\n mmap_region+0x2e6/0x3c0\n do_mmap+0xa3e/0x12a0\n ? __pfx_do_mmap+0x10/0x10\n ? __kasan_check_write+0x14/0x30\n ? down_write_killable+0xba/0x160\n ? __pfx_down_write_killable+0x10/0x10\n ? __sanitizer_cov_trace_cmp4+0x16/0x30\n vm_mmap_pgoff+0x2d4/0x4a0\n ? __pfx_vm_mmap_pgoff+0x10/0x10\n ? fget+0x1bf/0x270\n ksys_mmap_pgoff+0x40c/0x690\n ? __sanitizer_cov_trace_const_cmp4+0x16/0x30\n ? __pfx_ksys_mmap_pgoff+0x10/0x10\n ? __kasan_check_write+0x14/0x30\n ? _raw_spin_trylock+0xbb/0x130\n ? __pfx__raw_spin_trylock+0x10/0x10\n __x64_sys_mmap+0x135/0x1e0\n x64_sys_c\n---truncated---"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Triggered via local mmap on /dev/infiniband/uverbsN (ib_uverbs_mmap\u2192rxe_mmap) racing DESTROY_CQ/QP/SRQ ioctls; not reachable from RoCE/UDP packet processing.\nAC:L - Attacker controls both sides\u2014mmap of the pending CQ/QP/SRQ queue buffer and concurrent destroy that kref_puts to rxe_mmap_release\u2014and can retry unboundedly; PoC shows reliable crash.\nPR:L - uverbs_devnode() publishes /dev/infiniband/uverbs* as 0666 with no capability checks on create/mmap/destroy; once Soft-RoCE exists (admin setup), any unprivileged user (PoC UID 1000) can exploit.\nUI:N - Attacker opens uverbs, creates a CQ/QP/SRQ, then races mmap with destroy from its own threads; no victim action required.\nS:U - UAF corrupts kernel heap/vmalloc within the host kernel authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - Race frees rxe_mmap_info and vfree\u0027s the queue while remap_vmalloc_range still walks it; stale PTEs can leave a user VMA mapped to reallocated pages, enabling page-level UAF reads.\nI:H - Same page-level UAF / freed-object control yields write primitives via remapped freed pages and heap reuse, sufficient for control-flow hijacking per UAF guidance.\nA:H - Concurrent vfree during PTE walk returns NULL to vm_insert_page, causing the documented GPF/oops in validate_page_before_insert; crash is reliably repeatable."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:29:09.006Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b810352d0916796dabe633cdb9adee9863ab4911"
},
{
"url": "https://git.kernel.org/stable/c/aef5ea8578f97f2701039600846a8bcf5f21e863"
},
{
"url": "https://git.kernel.org/stable/c/3371f2036e0f970166bbb624e25bba46d32fa18e"
},
{
"url": "https://git.kernel.org/stable/c/665fb7d22a700c66a78db0cf88c6e6a649aba9d0"
},
{
"url": "https://git.kernel.org/stable/c/e038d42cc09ca1da9d3568ce8ae062b2bfb3bc0e"
},
{
"url": "https://git.kernel.org/stable/c/e59a6aa89e0fcd1d0707832eb4654fd9ae7d31e6"
},
{
"url": "https://git.kernel.org/stable/c/3525987a392536f31a484833af258971af63b24c"
},
{
"url": "https://git.kernel.org/stable/c/35744ab3d03c5fca8c1752f53fc8fc674e14c561"
}
],
"title": "RDMA/rxe: Fix a use-after-free problem in rxe_mmap",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64582",
"datePublished": "2026-08-05T11:25:29.082Z",
"dateReserved": "2026-07-19T15:36:31.798Z",
"dateUpdated": "2026-08-19T16:29:09.006Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68377 (GCVE-0-2026-68377)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/sched: act_tunnel_key: Defer dst_release to RCU callback
Fix a race-condition use-after-free in tunnel_key_release_params().
The function releases the metadata_dst of the old params synchronously
via dst_release() while deferring the params struct free with
kfree_rcu(). A concurrent tunnel_key_act() reader on the datapath may
still hold the old params pointer (under rcu_read_lock_bh) and proceed
to call dst_clone(¶ms->tcft_enc_metadata->dst) after the writer's
dst_release has already pushed the dst's rcuref to RCUREF_DEAD.
zdi-disclosures@trendmicro.com produced a poc which i (and Victor) verified
that KASAN reports:
==================================================================
BUG: KASAN: slab-use-after-free in instrument_atomic_read_write include/linux/instrumented.h:112
BUG: KASAN: slab-use-after-free in atomic_sub_return_release include/linux/atomic/atomic-instrumented.h:326
BUG: KASAN: slab-use-after-free in __rcuref_put include/linux/rcuref.h:109
BUG: KASAN: slab-use-after-free in rcuref_put include/linux/rcuref.h:173
BUG: KASAN: slab-use-after-free in dst_release+0x5b/0x370 net/core/dst.c:168
Write of size 4 at addr ffff88806158de40 by task poc/9388
CPU: 0 UID: 0 PID: 9388 Comm: poc Tainted: G W 7.1.0-rc7 #7 PREEMPT(lazy)
Tainted: [W]=WARN
Hardware name: QEMU Ubuntu 25.10 PC v2 (i440FX + PIIX, + 10.1 machine, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
Call Trace:
<TASK>
__dump_stack lib/dump_stack.c:94
dump_stack_lvl+0x100/0x190 lib/dump_stack.c:120
print_address_description mm/kasan/report.c:378
print_report+0x139/0x4ad mm/kasan/report.c:482
kasan_report+0xe4/0x1d0 mm/kasan/report.c:595
check_region_inline mm/kasan/generic.c:186
kasan_check_range+0x125/0x200 mm/kasan/generic.c:200
instrument_atomic_read_write include/linux/instrumented.h:112
atomic_sub_return_release include/linux/atomic/atomic-instrumented.h:326
__rcuref_put include/linux/rcuref.h:109
rcuref_put include/linux/rcuref.h:173
dst_release+0x5b/0x370 net/core/dst.c:168
refdst_drop include/net/dst.h:272
skb_dst_drop include/net/dst.h:284
skb_release_head_state+0x293/0x400 net/core/skbuff.c:1163
skb_release_all net/core/skbuff.c:1187
[..]
Allocated by task 9391:
kasan_save_stack+0x30/0x50 mm/kasan/common.c:57
kasan_save_track+0x14/0x30 mm/kasan/common.c:78
poison_kmalloc_redzone mm/kasan/common.c:398
__kasan_kmalloc+0x9a/0xb0 mm/kasan/common.c:415
kasan_kmalloc include/linux/kasan.h:263
__do_kmalloc_node mm/slub.c:5296
__kmalloc_noprof+0x2f1/0x830 mm/slub.c:5308
kmalloc_noprof include/linux/slab.h:954
kzalloc_noprof include/linux/slab.h:1188
offload_action_alloc+0x2f/0x130 net/core/flow_offload.c:35
tcf_action_offload_add_ex+0x1ba/0x880 net/sched/act_api.c:258
tcf_action_offload_add net/sched/act_api.c:293
tcf_action_init+0x66e/0xa20 net/sched/act_api.c:1547
tcf_action_add+0xf6/0x5d0 net/sched/act_api.c:2101
[..]
Freed by task 9391:
kasan_save_stack+0x30/0x50 mm/kasan/common.c:57
kasan_save_track+0x14/0x30 mm/kasan/common.c:78
kasan_save_free_info+0x3b/0x70 mm/kasan/generic.c:584
poison_slab_object mm/kasan/common.c:253
__kasan_slab_free+0x6b/0x90 mm/kasan/common.c:285
kasan_slab_free include/linux/kasan.h:235
slab_free_hook mm/slub.c:2689
slab_free mm/slub.c:6251
kfree+0x21f/0x6b0 mm/slub.c:6566
tcf_action_offload_add_ex+0x4ad/0x880 net/sched/act_api.c:284
tcf_action_offload_add net/sched/act_api.c:293
tcf_action_init+0x66e/0xa20 net/sched/act_api.c:1547
tcf_action_add+0xf6/0x5d0 net/sched/act_api.c:2101
The buggy address belongs to the object at ffff88806158de00
which belongs to the cache kmalloc-256 of size 256
The buggy address is located 64 bytes inside of
freed 256-byte region [ffff88806158de00, ffff88806158df00)
The buggy address belongs to the physical page:
page: refcount:0 mapcount:0 mapping:0000000000000000 index:0xffff88806158d600 pfn:0x6158c
head: order:1 mapcount:0 entire_map
---truncated---
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 9174c3df1cd181c14913138d50ccbe539bb08335 Version: 9174c3df1cd181c14913138d50ccbe539bb08335 Version: 9174c3df1cd181c14913138d50ccbe539bb08335 Version: 9174c3df1cd181c14913138d50ccbe539bb08335 Version: 9174c3df1cd181c14913138d50ccbe539bb08335 Version: 9174c3df1cd181c14913138d50ccbe539bb08335 Version: 9174c3df1cd181c14913138d50ccbe539bb08335 Version: 9174c3df1cd181c14913138d50ccbe539bb08335 Version: 02239e797ac75f89a05622a27d04695f08c1ca89 Version: ca9b7a65a2c97579fcdd509d454d48e3a5c49af8 Version: 4.19.19 ≤ Version: 4.20.6 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/sched/act_tunnel_key.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b5931f020b681fdcb9378262d89b61cb3c7ebbf8",
"status": "affected",
"version": "9174c3df1cd181c14913138d50ccbe539bb08335",
"versionType": "git"
},
{
"lessThan": "389d03992dabb80488228e8119b9dd6d0f58e1a6",
"status": "affected",
"version": "9174c3df1cd181c14913138d50ccbe539bb08335",
"versionType": "git"
},
{
"lessThan": "676ad6aa7cec89a08d2a5ce3cd5959e313f29733",
"status": "affected",
"version": "9174c3df1cd181c14913138d50ccbe539bb08335",
"versionType": "git"
},
{
"lessThan": "531dbb5bb98e52ad26be7e90f9f8bec707c5bd0e",
"status": "affected",
"version": "9174c3df1cd181c14913138d50ccbe539bb08335",
"versionType": "git"
},
{
"lessThan": "2200a00ff247f70f5dcdb4e6f14b0d48ddac5467",
"status": "affected",
"version": "9174c3df1cd181c14913138d50ccbe539bb08335",
"versionType": "git"
},
{
"lessThan": "fed1b1ddab41a0e7a462ac690a0c8af6ff793624",
"status": "affected",
"version": "9174c3df1cd181c14913138d50ccbe539bb08335",
"versionType": "git"
},
{
"lessThan": "2791a501da508b704a617b4dba29db54a65bc9f7",
"status": "affected",
"version": "9174c3df1cd181c14913138d50ccbe539bb08335",
"versionType": "git"
},
{
"lessThan": "f1f5c8a3955f8fda3f84ed883ac8daa1847e724c",
"status": "affected",
"version": "9174c3df1cd181c14913138d50ccbe539bb08335",
"versionType": "git"
},
{
"status": "affected",
"version": "02239e797ac75f89a05622a27d04695f08c1ca89",
"versionType": "git"
},
{
"status": "affected",
"version": "ca9b7a65a2c97579fcdd509d454d48e3a5c49af8",
"versionType": "git"
},
{
"lessThan": "4.20",
"status": "affected",
"version": "4.19.19",
"versionType": "semver"
},
{
"lessThan": "4.21",
"status": "affected",
"version": "4.20.6",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/sched/act_tunnel_key.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.0"
},
{
"lessThan": "5.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.19.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.20.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: act_tunnel_key: Defer dst_release to RCU callback\n\nFix a race-condition use-after-free in tunnel_key_release_params().\n\nThe function releases the metadata_dst of the old params synchronously\nvia dst_release() while deferring the params struct free with\nkfree_rcu(). A concurrent tunnel_key_act() reader on the datapath may\nstill hold the old params pointer (under rcu_read_lock_bh) and proceed\nto call dst_clone(\u0026params-\u003etcft_enc_metadata-\u003edst) after the writer\u0027s\ndst_release has already pushed the dst\u0027s rcuref to RCUREF_DEAD.\n\nzdi-disclosures@trendmicro.com produced a poc which i (and Victor) verified\nthat KASAN reports:\n\n==================================================================\nBUG: KASAN: slab-use-after-free in instrument_atomic_read_write include/linux/instrumented.h:112\nBUG: KASAN: slab-use-after-free in atomic_sub_return_release include/linux/atomic/atomic-instrumented.h:326\nBUG: KASAN: slab-use-after-free in __rcuref_put include/linux/rcuref.h:109\nBUG: KASAN: slab-use-after-free in rcuref_put include/linux/rcuref.h:173\nBUG: KASAN: slab-use-after-free in dst_release+0x5b/0x370 net/core/dst.c:168\nWrite of size 4 at addr ffff88806158de40 by task poc/9388\n\nCPU: 0 UID: 0 PID: 9388 Comm: poc Tainted: G W 7.1.0-rc7 #7 PREEMPT(lazy)\nTainted: [W]=WARN\nHardware name: QEMU Ubuntu 25.10 PC v2 (i440FX + PIIX, + 10.1 machine, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\nCall Trace:\n \u003cTASK\u003e\n __dump_stack lib/dump_stack.c:94\n dump_stack_lvl+0x100/0x190 lib/dump_stack.c:120\n print_address_description mm/kasan/report.c:378\n print_report+0x139/0x4ad mm/kasan/report.c:482\n kasan_report+0xe4/0x1d0 mm/kasan/report.c:595\n check_region_inline mm/kasan/generic.c:186\n kasan_check_range+0x125/0x200 mm/kasan/generic.c:200\n instrument_atomic_read_write include/linux/instrumented.h:112\n atomic_sub_return_release include/linux/atomic/atomic-instrumented.h:326\n __rcuref_put include/linux/rcuref.h:109\n rcuref_put include/linux/rcuref.h:173\n dst_release+0x5b/0x370 net/core/dst.c:168\n refdst_drop include/net/dst.h:272\n skb_dst_drop include/net/dst.h:284\n skb_release_head_state+0x293/0x400 net/core/skbuff.c:1163\n skb_release_all net/core/skbuff.c:1187\n[..]\nAllocated by task 9391:\n kasan_save_stack+0x30/0x50 mm/kasan/common.c:57\n kasan_save_track+0x14/0x30 mm/kasan/common.c:78\n poison_kmalloc_redzone mm/kasan/common.c:398\n __kasan_kmalloc+0x9a/0xb0 mm/kasan/common.c:415\n kasan_kmalloc include/linux/kasan.h:263\n __do_kmalloc_node mm/slub.c:5296\n __kmalloc_noprof+0x2f1/0x830 mm/slub.c:5308\n kmalloc_noprof include/linux/slab.h:954\n kzalloc_noprof include/linux/slab.h:1188\n offload_action_alloc+0x2f/0x130 net/core/flow_offload.c:35\n tcf_action_offload_add_ex+0x1ba/0x880 net/sched/act_api.c:258\n tcf_action_offload_add net/sched/act_api.c:293\n tcf_action_init+0x66e/0xa20 net/sched/act_api.c:1547\n tcf_action_add+0xf6/0x5d0 net/sched/act_api.c:2101\n[..]\nFreed by task 9391:\n kasan_save_stack+0x30/0x50 mm/kasan/common.c:57\n kasan_save_track+0x14/0x30 mm/kasan/common.c:78\n kasan_save_free_info+0x3b/0x70 mm/kasan/generic.c:584\n poison_slab_object mm/kasan/common.c:253\n __kasan_slab_free+0x6b/0x90 mm/kasan/common.c:285\n kasan_slab_free include/linux/kasan.h:235\n slab_free_hook mm/slub.c:2689\n slab_free mm/slub.c:6251\n kfree+0x21f/0x6b0 mm/slub.c:6566\n tcf_action_offload_add_ex+0x4ad/0x880 net/sched/act_api.c:284\n tcf_action_offload_add net/sched/act_api.c:293\n tcf_action_init+0x66e/0xa20 net/sched/act_api.c:1547\n tcf_action_add+0xf6/0x5d0 net/sched/act_api.c:2101\n\nThe buggy address belongs to the object at ffff88806158de00\n which belongs to the cache kmalloc-256 of size 256\nThe buggy address is located 64 bytes inside of\n freed 256-byte region [ffff88806158de00, ffff88806158df00)\n\nThe buggy address belongs to the physical page:\npage: refcount:0 mapcount:0 mapping:0000000000000000 index:0xffff88806158d600 pfn:0x6158c\nhead: order:1 mapcount:0 entire_map\n---truncated---"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable window is opened via the tc/rtnetlink RTM_NEWACTION path (`tc action replace ... tunnel_key set`) and closed by locally generated traffic through a clsact/ingress filter, both requiring local system access rather than remote packets.\nAC:L - The attacker controls both sides of the race \u2014 one thread repeatedly replaces the tunnel_key action while another pumps packets through the filter \u2014 and can widen the window with qdisc backlog, so the UAF is reliably reproducible (a ZDI PoC reproduced it under KASAN).\nPR:L - The action-add path is gated only by netlink_capable(skb, CAP_NET_ADMIN), which is namespace-relative and obtainable by any unprivileged user via `unshare -Urn`; the packet side runs in the attacker\u0027s own netns.\nUI:N - Both the netlink action replace and the packet transmission that dereferences the stale params are performed entirely by the attacker\u0027s own processes; no victim action is involved.\nS:U - The corruption is confined to kernel heap memory within the same security authority; there is no VM, IOMMU, or sandbox boundary crossed.\nC:H - The freed metadata_dst sits in the general-purpose kmalloc-256 cache and remains attached to an skb, so tx paths read tunnel metadata out of reclaimed memory, giving an attacker who sprays the slab a route to disclose kernel data and defeat KASLR.\nI:H - The stale dst_clone/skb_dst_drop pair performs atomic 4-byte read-modify-write operations on a freed, attacker-reclaimable slab object, yielding a refcount-corruption primitive that is a well-established stepping stone to arbitrary write and privilege escalation.\nA:H - The use-after-free reliably corrupts slab memory and triggers KASAN-reported faults; unmitigated it causes kernel oops or panic, and the race can be repeated at will by an unprivileged user."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:38.220Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b5931f020b681fdcb9378262d89b61cb3c7ebbf8"
},
{
"url": "https://git.kernel.org/stable/c/389d03992dabb80488228e8119b9dd6d0f58e1a6"
},
{
"url": "https://git.kernel.org/stable/c/676ad6aa7cec89a08d2a5ce3cd5959e313f29733"
},
{
"url": "https://git.kernel.org/stable/c/531dbb5bb98e52ad26be7e90f9f8bec707c5bd0e"
},
{
"url": "https://git.kernel.org/stable/c/2200a00ff247f70f5dcdb4e6f14b0d48ddac5467"
},
{
"url": "https://git.kernel.org/stable/c/fed1b1ddab41a0e7a462ac690a0c8af6ff793624"
},
{
"url": "https://git.kernel.org/stable/c/2791a501da508b704a617b4dba29db54a65bc9f7"
},
{
"url": "https://git.kernel.org/stable/c/f1f5c8a3955f8fda3f84ed883ac8daa1847e724c"
}
],
"title": "net/sched: act_tunnel_key: Defer dst_release to RCU callback",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68377",
"datePublished": "2026-08-10T12:03:55.643Z",
"dateReserved": "2026-07-30T09:28:09.386Z",
"dateUpdated": "2026-08-19T16:34:38.220Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80783 (GCVE-0-2026-80783)
Vulnerability from cvelistv5
Published
2026-09-04 15:12
Modified
2026-09-04 15:12
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
HID: magicmouse: prevent unbounded recursion in magicmouse_raw_event()
magicmouse_raw_event() handles DOUBLE_REPORT_ID (0xf7) packets, which pack
two touch reports into one, by splitting the packet and calling itself on
each half. The only guard against runaway recursion is a "size < 1" check,
which stops zero-sized calls but does not bound the recursion depth.
A malicious HID device that matches this driver can send a report starting
with DOUBLE_REPORT_ID and filled with the sequence [0xf7, 0x00]. Each level
consumes two bytes and recurses on the remainder, so an incoming report of
up to HID_MAX_BUFFER_SIZE (16 KiB) drives roughly 8000 nested calls. That
easily exhausts the 16 KiB kernel stack, leading to a stack overflow: a
panic with CONFIG_VMAP_STACK, or memory corruption without it.
A double report only ever wraps two normal reports; it is never
legitimately nested. Refuse to re-enter the DOUBLE_REPORT_ID case from a
recursive call so the recursion depth is bounded to two, while all valid
packets keep being parsed exactly as before.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: a462230e16acc8664145216da3c928d03556691a Version: a462230e16acc8664145216da3c928d03556691a Version: a462230e16acc8664145216da3c928d03556691a Version: a462230e16acc8664145216da3c928d03556691a Version: a462230e16acc8664145216da3c928d03556691a Version: a462230e16acc8664145216da3c928d03556691a Version: a462230e16acc8664145216da3c928d03556691a Version: a462230e16acc8664145216da3c928d03556691a |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/hid/hid-magicmouse.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "26c45abed62536aabf4033fb6d64cf72e93374e9",
"status": "affected",
"version": "a462230e16acc8664145216da3c928d03556691a",
"versionType": "git"
},
{
"lessThan": "8a10a624996f16628234306b46f0cf36707d78bd",
"status": "affected",
"version": "a462230e16acc8664145216da3c928d03556691a",
"versionType": "git"
},
{
"lessThan": "d16df755b4493b6d37803c628b2c621d096796a8",
"status": "affected",
"version": "a462230e16acc8664145216da3c928d03556691a",
"versionType": "git"
},
{
"lessThan": "bec338b07beb883726b32192c8f01c601bc76fda",
"status": "affected",
"version": "a462230e16acc8664145216da3c928d03556691a",
"versionType": "git"
},
{
"lessThan": "70589b0c005db003f6d8ae4db3c4d54fed7b83e4",
"status": "affected",
"version": "a462230e16acc8664145216da3c928d03556691a",
"versionType": "git"
},
{
"lessThan": "a33a596d3ad8dfe6c96a368097a028abeee16c17",
"status": "affected",
"version": "a462230e16acc8664145216da3c928d03556691a",
"versionType": "git"
},
{
"lessThan": "d095de37f78c5f32a4252ef0f99b84ba76550b86",
"status": "affected",
"version": "a462230e16acc8664145216da3c928d03556691a",
"versionType": "git"
},
{
"lessThan": "db8d634128d2ba88d79c0b601e983ebe14bb0519",
"status": "affected",
"version": "a462230e16acc8664145216da3c928d03556691a",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/hid/hid-magicmouse.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.37"
},
{
"lessThan": "2.6.37",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.220",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.187",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.156",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.108",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.49",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.1",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.220",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.187",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.156",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.108",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.49",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.11",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.1",
"versionStartIncluding": "2.6.37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "2.6.37",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: magicmouse: prevent unbounded recursion in magicmouse_raw_event()\n\nmagicmouse_raw_event() handles DOUBLE_REPORT_ID (0xf7) packets, which pack\ntwo touch reports into one, by splitting the packet and calling itself on\neach half. The only guard against runaway recursion is a \"size \u003c 1\" check,\nwhich stops zero-sized calls but does not bound the recursion depth.\n\nA malicious HID device that matches this driver can send a report starting\nwith DOUBLE_REPORT_ID and filled with the sequence [0xf7, 0x00]. Each level\nconsumes two bytes and recurses on the remainder, so an incoming report of\nup to HID_MAX_BUFFER_SIZE (16 KiB) drives roughly 8000 nested calls. That\neasily exhausts the 16 KiB kernel stack, leading to a stack overflow: a\npanic with CONFIG_VMAP_STACK, or memory corruption without it.\n\nA double report only ever wraps two normal reports; it is never\nlegitimately nested. Refuse to re-enter the DOUBLE_REPORT_ID case from a\nrecursive call so the recursion depth is bounded to two, while all valid\npackets keep being parsed exactly as before."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T15:12:54.859Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/26c45abed62536aabf4033fb6d64cf72e93374e9"
},
{
"url": "https://git.kernel.org/stable/c/8a10a624996f16628234306b46f0cf36707d78bd"
},
{
"url": "https://git.kernel.org/stable/c/d16df755b4493b6d37803c628b2c621d096796a8"
},
{
"url": "https://git.kernel.org/stable/c/bec338b07beb883726b32192c8f01c601bc76fda"
},
{
"url": "https://git.kernel.org/stable/c/70589b0c005db003f6d8ae4db3c4d54fed7b83e4"
},
{
"url": "https://git.kernel.org/stable/c/a33a596d3ad8dfe6c96a368097a028abeee16c17"
},
{
"url": "https://git.kernel.org/stable/c/d095de37f78c5f32a4252ef0f99b84ba76550b86"
},
{
"url": "https://git.kernel.org/stable/c/db8d634128d2ba88d79c0b601e983ebe14bb0519"
}
],
"title": "HID: magicmouse: prevent unbounded recursion in magicmouse_raw_event()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80783",
"datePublished": "2026-09-04T15:12:54.859Z",
"dateReserved": "2026-08-26T14:34:25.792Z",
"dateUpdated": "2026-09-04T15:12:54.859Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-43491 (GCVE-0-2026-43491)
Vulnerability from cvelistv5
Published
2026-05-19 10:44
Modified
2026-08-19 16:27
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: qrtr: ns: Limit the maximum server registration per node
Current code does no bound checking on the number of servers added per
node. A malicious client can flood NEW_SERVER messages and exhaust memory.
Fix this issue by limiting the maximum number of server registrations to
256 per node. If the NEW_SERVER message is received for an old port, then
don't restrict it as it will get replaced. While at it, also rate limit
the error messages in the failure path of qrtr_ns_worker().
Note that the limit of 256 is chosen based on the current platform
requirements. If requirement changes in the future, this limit can be
increased.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 0c2204a4ad710d95d348ea006f14ba926e842ffd Version: 0c2204a4ad710d95d348ea006f14ba926e842ffd Version: 0c2204a4ad710d95d348ea006f14ba926e842ffd Version: 0c2204a4ad710d95d348ea006f14ba926e842ffd Version: 0c2204a4ad710d95d348ea006f14ba926e842ffd Version: 0c2204a4ad710d95d348ea006f14ba926e842ffd Version: 0c2204a4ad710d95d348ea006f14ba926e842ffd Version: 0c2204a4ad710d95d348ea006f14ba926e842ffd |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/qrtr/ns.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b48fc702b20233b809f01053232c3cd5083c97b4",
"status": "affected",
"version": "0c2204a4ad710d95d348ea006f14ba926e842ffd",
"versionType": "git"
},
{
"lessThan": "991c431077b19176d3fe3bb54054c063776a8cdc",
"status": "affected",
"version": "0c2204a4ad710d95d348ea006f14ba926e842ffd",
"versionType": "git"
},
{
"lessThan": "94914731ca0b99899dceadd80d2df00584a688ca",
"status": "affected",
"version": "0c2204a4ad710d95d348ea006f14ba926e842ffd",
"versionType": "git"
},
{
"lessThan": "e6f6cd501fb54060940a6eb3f4103eeb5e426ae7",
"status": "affected",
"version": "0c2204a4ad710d95d348ea006f14ba926e842ffd",
"versionType": "git"
},
{
"lessThan": "3efaad55cad1ded429e3a873bfece389058a526b",
"status": "affected",
"version": "0c2204a4ad710d95d348ea006f14ba926e842ffd",
"versionType": "git"
},
{
"lessThan": "35fb4a0c077c5d1049c2628b769e0a1b1e65df0d",
"status": "affected",
"version": "0c2204a4ad710d95d348ea006f14ba926e842ffd",
"versionType": "git"
},
{
"lessThan": "868202aa2adae427060a42d5bd663b4d782ec02c",
"status": "affected",
"version": "0c2204a4ad710d95d348ea006f14ba926e842ffd",
"versionType": "git"
},
{
"lessThan": "d5ee2ff98322337951c56398e79d51815acbf955",
"status": "affected",
"version": "0c2204a4ad710d95d348ea006f14ba926e842ffd",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/qrtr/ns.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.7"
},
{
"lessThan": "5.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.140",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.86",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.27",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.140",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.86",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.27",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.4",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1",
"versionStartIncluding": "5.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: qrtr: ns: Limit the maximum server registration per node\n\nCurrent code does no bound checking on the number of servers added per\nnode. A malicious client can flood NEW_SERVER messages and exhaust memory.\n\nFix this issue by limiting the maximum number of server registrations to\n256 per node. If the NEW_SERVER message is received for an old port, then\ndon\u0027t restrict it as it will get replaced. While at it, also rate limit\nthe error messages in the failure path of qrtr_ns_worker().\n\nNote that the limit of 256 is chosen based on the current platform\nrequirements. If requirement changes in the future, this limit can be\nincreased."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:27:59.057Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b48fc702b20233b809f01053232c3cd5083c97b4"
},
{
"url": "https://git.kernel.org/stable/c/991c431077b19176d3fe3bb54054c063776a8cdc"
},
{
"url": "https://git.kernel.org/stable/c/94914731ca0b99899dceadd80d2df00584a688ca"
},
{
"url": "https://git.kernel.org/stable/c/e6f6cd501fb54060940a6eb3f4103eeb5e426ae7"
},
{
"url": "https://git.kernel.org/stable/c/3efaad55cad1ded429e3a873bfece389058a526b"
},
{
"url": "https://git.kernel.org/stable/c/35fb4a0c077c5d1049c2628b769e0a1b1e65df0d"
},
{
"url": "https://git.kernel.org/stable/c/868202aa2adae427060a42d5bd663b4d782ec02c"
},
{
"url": "https://git.kernel.org/stable/c/d5ee2ff98322337951c56398e79d51815acbf955"
}
],
"title": "net: qrtr: ns: Limit the maximum server registration per node",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-43491",
"datePublished": "2026-05-19T10:44:23.832Z",
"dateReserved": "2026-05-01T14:12:56.013Z",
"dateUpdated": "2026-08-19T16:27:59.057Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-23394 (GCVE-0-2026-23394)
Vulnerability from cvelistv5
Published
2026-03-25 10:33
Modified
2026-08-19 16:27
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
af_unix: Give up GC if MSG_PEEK intervened.
Igor Ushakov reported that GC purged the receive queue of
an alive socket due to a race with MSG_PEEK with a nice repro.
This is the exact same issue previously fixed by commit
cbcf01128d0a ("af_unix: fix garbage collect vs MSG_PEEK").
After GC was replaced with the current algorithm, the cited
commit removed the locking dance in unix_peek_fds() and
reintroduced the same issue.
The problem is that MSG_PEEK bumps a file refcount without
interacting with GC.
Consider an SCC containing sk-A and sk-B, where sk-A is
close()d but can be recv()ed via sk-B.
The bad thing happens if sk-A is recv()ed with MSG_PEEK from
sk-B and sk-B is close()d while GC is checking unix_vertex_dead()
for sk-A and sk-B.
GC thread User thread
--------- -----------
unix_vertex_dead(sk-A)
-> true <------.
\
`------ recv(sk-B, MSG_PEEK)
invalidate !! -> sk-A's file refcount : 1 -> 2
close(sk-B)
-> sk-B's file refcount : 2 -> 1
unix_vertex_dead(sk-B)
-> true
Initially, sk-A's file refcount is 1 by the inflight fd in sk-B
recvq. GC thinks sk-A is dead because the file refcount is the
same as the number of its inflight fds.
However, sk-A's file refcount is bumped silently by MSG_PEEK,
which invalidates the previous evaluation.
At this moment, sk-B's file refcount is 2; one by the open fd,
and one by the inflight fd in sk-A. The subsequent close()
releases one refcount by the former.
Finally, GC incorrectly concludes that both sk-A and sk-B are dead.
One option is to restore the locking dance in unix_peek_fds(),
but we can resolve this more elegantly thanks to the new algorithm.
The point is that the issue does not occur without the subsequent
close() and we actually do not need to synchronise MSG_PEEK with
the dead SCC detection.
When the issue occurs, close() and GC touch the same file refcount.
If GC sees the refcount being decremented by close(), it can just
give up garbage-collecting the SCC.
Therefore, we only need to signal the race during MSG_PEEK with
a proper memory barrier to make it visible to the GC.
Let's use seqcount_t to notify GC when MSG_PEEK occurs and let
it defer the SCC to the next run.
This way no locking is needed on the MSG_PEEK side, and we can
avoid imposing a penalty on every MSG_PEEK unnecessarily.
Note that we can retry within unix_scc_dead() if MSG_PEEK is
detected, but we do not do so to avoid hung task splat from
abusive MSG_PEEK calls.
References
| URL | Tags | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 61a75360dca93c945ef6bd757f8b8a96f39b77cb Version: 7b1ffbd3b22e755d481d49647dcb7c5cfbde5844 Version: 118f457da9ed58a79e24b73c2ef0aa1987241f0e Version: 118f457da9ed58a79e24b73c2ef0aa1987241f0e Version: 118f457da9ed58a79e24b73c2ef0aa1987241f0e Version: 118f457da9ed58a79e24b73c2ef0aa1987241f0e Version: 6.1.141 ≤ Version: 6.6.93 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/unix/af_unix.c",
"net/unix/af_unix.h",
"net/unix/garbage.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "980999a96e1ad043f1197606e5d637219cb102b9",
"status": "affected",
"version": "61a75360dca93c945ef6bd757f8b8a96f39b77cb",
"versionType": "git"
},
{
"lessThan": "3106f326f67c03dd9da4ca64663d11e40138cf40",
"status": "affected",
"version": "7b1ffbd3b22e755d481d49647dcb7c5cfbde5844",
"versionType": "git"
},
{
"lessThan": "e3dd56fb5683ba80bf8d7a2f9aa21cfa53f05202",
"status": "affected",
"version": "118f457da9ed58a79e24b73c2ef0aa1987241f0e",
"versionType": "git"
},
{
"lessThan": "72cf49ad50c16270b52bc512d9c2df5743922968",
"status": "affected",
"version": "118f457da9ed58a79e24b73c2ef0aa1987241f0e",
"versionType": "git"
},
{
"lessThan": "37dd7ab332396eb8dd80b2dc7ea4b61abf767436",
"status": "affected",
"version": "118f457da9ed58a79e24b73c2ef0aa1987241f0e",
"versionType": "git"
},
{
"lessThan": "e5b31d988a41549037b8d8721a3c3cae893d8670",
"status": "affected",
"version": "118f457da9ed58a79e24b73c2ef0aa1987241f0e",
"versionType": "git"
},
{
"lessThan": "6.1.183",
"status": "affected",
"version": "6.1.141",
"versionType": "semver"
},
{
"lessThan": "6.6.142",
"status": "affected",
"version": "6.6.93",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/unix/af_unix.c",
"net/unix/af_unix.h",
"net/unix/garbage.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.10"
},
{
"lessThan": "6.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.142",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.92",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.23",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.19.*",
"status": "unaffected",
"version": "6.19.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.0",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "6.1.141",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.142",
"versionStartIncluding": "6.6.93",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.92",
"versionStartIncluding": "6.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.23",
"versionStartIncluding": "6.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.19.10",
"versionStartIncluding": "6.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0",
"versionStartIncluding": "6.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\naf_unix: Give up GC if MSG_PEEK intervened.\n\nIgor Ushakov reported that GC purged the receive queue of\nan alive socket due to a race with MSG_PEEK with a nice repro.\n\nThis is the exact same issue previously fixed by commit\ncbcf01128d0a (\"af_unix: fix garbage collect vs MSG_PEEK\").\n\nAfter GC was replaced with the current algorithm, the cited\ncommit removed the locking dance in unix_peek_fds() and\nreintroduced the same issue.\n\nThe problem is that MSG_PEEK bumps a file refcount without\ninteracting with GC.\n\nConsider an SCC containing sk-A and sk-B, where sk-A is\nclose()d but can be recv()ed via sk-B.\n\nThe bad thing happens if sk-A is recv()ed with MSG_PEEK from\nsk-B and sk-B is close()d while GC is checking unix_vertex_dead()\nfor sk-A and sk-B.\n\n GC thread User thread\n --------- -----------\n unix_vertex_dead(sk-A)\n -\u003e true \u003c------.\n \\\n `------ recv(sk-B, MSG_PEEK)\n invalidate !! -\u003e sk-A\u0027s file refcount : 1 -\u003e 2\n\n close(sk-B)\n -\u003e sk-B\u0027s file refcount : 2 -\u003e 1\n unix_vertex_dead(sk-B)\n -\u003e true\n\nInitially, sk-A\u0027s file refcount is 1 by the inflight fd in sk-B\nrecvq. GC thinks sk-A is dead because the file refcount is the\nsame as the number of its inflight fds.\n\nHowever, sk-A\u0027s file refcount is bumped silently by MSG_PEEK,\nwhich invalidates the previous evaluation.\n\nAt this moment, sk-B\u0027s file refcount is 2; one by the open fd,\nand one by the inflight fd in sk-A. The subsequent close()\nreleases one refcount by the former.\n\nFinally, GC incorrectly concludes that both sk-A and sk-B are dead.\n\nOne option is to restore the locking dance in unix_peek_fds(),\nbut we can resolve this more elegantly thanks to the new algorithm.\n\nThe point is that the issue does not occur without the subsequent\nclose() and we actually do not need to synchronise MSG_PEEK with\nthe dead SCC detection.\n\nWhen the issue occurs, close() and GC touch the same file refcount.\nIf GC sees the refcount being decremented by close(), it can just\ngive up garbage-collecting the SCC.\n\nTherefore, we only need to signal the race during MSG_PEEK with\na proper memory barrier to make it visible to the GC.\n\nLet\u0027s use seqcount_t to notify GC when MSG_PEEK occurs and let\nit defer the SCC to the next run.\n\nThis way no locking is needed on the MSG_PEEK side, and we can\navoid imposing a penalty on every MSG_PEEK unnecessarily.\n\nNote that we can retry within unix_scc_dead() if MSG_PEEK is\ndetected, but we do not do so to avoid hung task splat from\nabusive MSG_PEEK calls."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:27:54.571Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/980999a96e1ad043f1197606e5d637219cb102b9"
},
{
"url": "https://git.kernel.org/stable/c/3106f326f67c03dd9da4ca64663d11e40138cf40"
},
{
"url": "https://git.kernel.org/stable/c/e3dd56fb5683ba80bf8d7a2f9aa21cfa53f05202"
},
{
"url": "https://git.kernel.org/stable/c/72cf49ad50c16270b52bc512d9c2df5743922968"
},
{
"url": "https://git.kernel.org/stable/c/37dd7ab332396eb8dd80b2dc7ea4b61abf767436"
},
{
"url": "https://git.kernel.org/stable/c/e5b31d988a41549037b8d8721a3c3cae893d8670"
}
],
"title": "af_unix: Give up GC if MSG_PEEK intervened.",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-23394",
"datePublished": "2026-03-25T10:33:18.180Z",
"dateReserved": "2026-01-13T15:37:46.011Z",
"dateUpdated": "2026-08-19T16:27:54.571Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68278 (GCVE-0-2026-68278)
Vulnerability from cvelistv5
Published
2026-08-10 12:01
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/dp/mst: fix buffer overflows in sideband chunk accumulation
drm_dp_sideband_append_payload() has three related bugs when processing
device-provided sideband reply data:
1. Zero-length curchunk_len underflow: msg_len is a 6-bit field taken
directly from the DP sideband header. If a device sends msg_len=0,
curchunk_len is set to zero. The condition (curchunk_idx >= curchunk_len)
is immediately true, and curchunk_len-1 wraps to 255 (u8 underflow).
drm_dp_msg_data_crc4() reads 255 bytes from chunk[48], then memcpy()
writes 255 bytes into msg[], both far out of bounds.
2. chunk[48] overflow: curchunk_len can reach 63 (6-bit field). chunk[] is
only 48 bytes. Multi-iteration payload assembly appends 16-byte blocks
until curchunk_idx reaches curchunk_len, writing up to 15 bytes past
the end of chunk[] into msg[].
3. msg[256] overflow: each chunk contributes (curchunk_len-1) bytes to
msg[]. No check ensures curlen + (curchunk_len-1) stays within msg[256],
so the memcpy can spill into adjacent struct fields.
All three are reachable from any DP MST device that can forge sideband
reply messages on a physical connection.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd Version: ad7f8a1f9ced7f049f9b66d588723f243a7034cd |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/display/drm_dp_mst_topology.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ef2ecb6cf268debf3890df99fea01b6452dcf78e",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "d4e05dedb252ed3e540a0c9be511e427f098110a",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "4d5109075a787de28c9e89940f9dee45269f91fa",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "53937a2787d29c7a460e984dc4f20ff6ac91dc65",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "ef0dbcc200c3389f1f781ab181932a97e54b51af",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "1e5827839ad0ceb0079d1560c321fa3656b54f21",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "a6366b551079c79bf7bdbadd74c97358bcfe2d58",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
},
{
"lessThan": "55bd5e685bda455b9b50c835f8c8442d52a344a3",
"status": "affected",
"version": "ad7f8a1f9ced7f049f9b66d588723f243a7034cd",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/display/drm_dp_mst_topology.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.17"
},
{
"lessThan": "3.17",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.17",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/dp/mst: fix buffer overflows in sideband chunk accumulation\n\ndrm_dp_sideband_append_payload() has three related bugs when processing\ndevice-provided sideband reply data:\n\n1. Zero-length curchunk_len underflow: msg_len is a 6-bit field taken\n directly from the DP sideband header. If a device sends msg_len=0,\n curchunk_len is set to zero. The condition (curchunk_idx \u003e= curchunk_len)\n is immediately true, and curchunk_len-1 wraps to 255 (u8 underflow).\n drm_dp_msg_data_crc4() reads 255 bytes from chunk[48], then memcpy()\n writes 255 bytes into msg[], both far out of bounds.\n\n2. chunk[48] overflow: curchunk_len can reach 63 (6-bit field). chunk[] is\n only 48 bytes. Multi-iteration payload assembly appends 16-byte blocks\n until curchunk_idx reaches curchunk_len, writing up to 15 bytes past\n the end of chunk[] into msg[].\n\n3. msg[256] overflow: each chunk contributes (curchunk_len-1) bytes to\n msg[]. No check ensures curlen + (curchunk_len-1) stays within msg[256],\n so the memcpy can spill into adjacent struct fields.\n\nAll three are reachable from any DP MST device that can forge sideband\nreply messages on a physical connection."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:15.450Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ef2ecb6cf268debf3890df99fea01b6452dcf78e"
},
{
"url": "https://git.kernel.org/stable/c/d4e05dedb252ed3e540a0c9be511e427f098110a"
},
{
"url": "https://git.kernel.org/stable/c/4d5109075a787de28c9e89940f9dee45269f91fa"
},
{
"url": "https://git.kernel.org/stable/c/53937a2787d29c7a460e984dc4f20ff6ac91dc65"
},
{
"url": "https://git.kernel.org/stable/c/ef0dbcc200c3389f1f781ab181932a97e54b51af"
},
{
"url": "https://git.kernel.org/stable/c/1e5827839ad0ceb0079d1560c321fa3656b54f21"
},
{
"url": "https://git.kernel.org/stable/c/a6366b551079c79bf7bdbadd74c97358bcfe2d58"
},
{
"url": "https://git.kernel.org/stable/c/55bd5e685bda455b9b50c835f8c8442d52a344a3"
}
],
"title": "drm/dp/mst: fix buffer overflows in sideband chunk accumulation",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68278",
"datePublished": "2026-08-10T12:01:54.285Z",
"dateReserved": "2026-07-30T09:28:09.379Z",
"dateUpdated": "2026-08-23T12:46:15.450Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80830 (GCVE-0-2026-80830)
Vulnerability from cvelistv5
Published
2026-09-04 15:54
Modified
2026-09-07 14:21
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
usb: core: Add lock to usb_wakeup_notification()
Add a spin lock to usb_wakeup notification to prevent a race condition
with dereferencing freed memory. This could be hit by the xHCI driver as
it calls this function from an IRQ and could race with the
hub_disconnect() function, which properly grabs this lock to protect the
state of the device.
References
| URL | Tags | ||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 4ee823b83bc9851743fab756c76b27d6a1e2472b Version: 4ee823b83bc9851743fab756c76b27d6a1e2472b Version: 4ee823b83bc9851743fab756c76b27d6a1e2472b Version: 4ee823b83bc9851743fab756c76b27d6a1e2472b Version: 4ee823b83bc9851743fab756c76b27d6a1e2472b Version: 4ee823b83bc9851743fab756c76b27d6a1e2472b Version: 4ee823b83bc9851743fab756c76b27d6a1e2472b Version: 4ee823b83bc9851743fab756c76b27d6a1e2472b Version: 4ee823b83bc9851743fab756c76b27d6a1e2472b |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/core/hub.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a7a16167991c88016acef720927400404039d850",
"status": "affected",
"version": "4ee823b83bc9851743fab756c76b27d6a1e2472b",
"versionType": "git"
},
{
"lessThan": "975ef630393c07fcbebf94f4d97043161b77a6ce",
"status": "affected",
"version": "4ee823b83bc9851743fab756c76b27d6a1e2472b",
"versionType": "git"
},
{
"lessThan": "71cfda2fdf78041a01e9d94143baa79feabbdbf6",
"status": "affected",
"version": "4ee823b83bc9851743fab756c76b27d6a1e2472b",
"versionType": "git"
},
{
"lessThan": "04ab260407972e631c86f2bc576cd8e64d65b325",
"status": "affected",
"version": "4ee823b83bc9851743fab756c76b27d6a1e2472b",
"versionType": "git"
},
{
"lessThan": "bf2288583b4e072bdff17a233963619e4bc7a8b5",
"status": "affected",
"version": "4ee823b83bc9851743fab756c76b27d6a1e2472b",
"versionType": "git"
},
{
"lessThan": "d80b946804674069db7ce6657319a71cf8eeaa5a",
"status": "affected",
"version": "4ee823b83bc9851743fab756c76b27d6a1e2472b",
"versionType": "git"
},
{
"lessThan": "960ca456faf61824b178f47967340300b24183db",
"status": "affected",
"version": "4ee823b83bc9851743fab756c76b27d6a1e2472b",
"versionType": "git"
},
{
"lessThan": "7c48aa0c1e79116b8af4b988d16ee29b427d6491",
"status": "affected",
"version": "4ee823b83bc9851743fab756c76b27d6a1e2472b",
"versionType": "git"
},
{
"lessThan": "e263e18a9e7b1ff3e7301f0801c6ff87c31adfb6",
"status": "affected",
"version": "4ee823b83bc9851743fab756c76b27d6a1e2472b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/usb/core/hub.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.4"
},
{
"lessThan": "3.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.269",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.220",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.187",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.156",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.108",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.49",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.13",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.3",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.269",
"versionStartIncluding": "3.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.220",
"versionStartIncluding": "3.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.187",
"versionStartIncluding": "3.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.156",
"versionStartIncluding": "3.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.108",
"versionStartIncluding": "3.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.49",
"versionStartIncluding": "3.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.13",
"versionStartIncluding": "3.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.3",
"versionStartIncluding": "3.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "3.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: core: Add lock to usb_wakeup_notification()\n\nAdd a spin lock to usb_wakeup notification to prevent a race condition\nwith dereferencing freed memory. This could be hit by the xHCI driver as\nit calls this function from an IRQ and could race with the\nhub_disconnect() function, which properly grabs this lock to protect the\nstate of the device."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-07T14:21:22.046Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a7a16167991c88016acef720927400404039d850"
},
{
"url": "https://git.kernel.org/stable/c/975ef630393c07fcbebf94f4d97043161b77a6ce"
},
{
"url": "https://git.kernel.org/stable/c/71cfda2fdf78041a01e9d94143baa79feabbdbf6"
},
{
"url": "https://git.kernel.org/stable/c/04ab260407972e631c86f2bc576cd8e64d65b325"
},
{
"url": "https://git.kernel.org/stable/c/bf2288583b4e072bdff17a233963619e4bc7a8b5"
},
{
"url": "https://git.kernel.org/stable/c/d80b946804674069db7ce6657319a71cf8eeaa5a"
},
{
"url": "https://git.kernel.org/stable/c/960ca456faf61824b178f47967340300b24183db"
},
{
"url": "https://git.kernel.org/stable/c/7c48aa0c1e79116b8af4b988d16ee29b427d6491"
},
{
"url": "https://git.kernel.org/stable/c/e263e18a9e7b1ff3e7301f0801c6ff87c31adfb6"
}
],
"title": "usb: core: Add lock to usb_wakeup_notification()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80830",
"datePublished": "2026-09-04T15:54:35.169Z",
"dateReserved": "2026-08-26T14:34:25.796Z",
"dateUpdated": "2026-09-07T14:21:22.046Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74658 (GCVE-0-2026-74658)
Vulnerability from cvelistv5
Published
2026-08-22 15:32
Modified
2026-08-22 15:32
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
futex: Prevent robust futex exit race some more
A robust futex unlock stores 0 over the whole futex value - wiping
FUTEX_WAITERS - and wakes a single waiter. That wakeup is a one-shot
notification: the protocol relies on its recipient to either acquire the
futex (and eventually unlock while aware of the remaining contention) or
re-arm FUTEX_WAITERS before sleeping again. If the woken waiter is killed
before it can do either, the kernel must jump in and wake the next task
down the line.
This is a known complication of the futex protocol with a previous
partial fix in commit ca16d5bee598 ("futex: Prevent robust futex exit
race"). Unfortunately, that fix is insufficient.
If a third task re-acquired the futex through the uncontended fast
path in the meantime, the notification is lost: robust exit processing
sees that it is owned by another task and does nothing, while the new
owner sees no FUTEX_WAITERS when it unlocks and wakes nobody.
The remaining waiters sleep forever behind a free futex:
A owns the futex, B and C sleep in FUTEX_WAIT
uval == A | FUTEX_WAITERS
A robust unlock: store 0, FUTEX_WAKE(1) wakes B
uval == 0
D fast path acquire: cmpxchg(0 -> D)
uval == D, no FUTEX_WAITERS
B killed before acting on the wakeup
B exit walk, pending op: owner D != B -> no action
D unlock: no FUTEX_WAITERS -> no wake
C sleeps forever
This is clearly a shortcoming in the implementation, which fails to keep
the FUTEX_WAITERS bit consistent.
Work around this by augmenting the robust list exit processing to also
perform the extra wakeup if the futex word is owned by another thread but
FUTEX_WAITERS is not set.
This does not fix the problem of a non-contended take over/release and free
sequence, which has been discussed for years and has been addressed by
commit 3ca9595d9fb6 ("futex: Add support for unlocking robust futexes") and
subsequent changes, but failed to take the problem described above into
account.
A more complete solution which is based on the in kernel unlock of
contended robust futexes has been discussed in the context of this change
and should show up in mainline sooner than later.
[ tglx: Amend change log slightly and fixup coding style ]
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ca16d5bee59807bf04deaab0a8eccecd5061528c Version: ca16d5bee59807bf04deaab0a8eccecd5061528c Version: ca16d5bee59807bf04deaab0a8eccecd5061528c Version: ca16d5bee59807bf04deaab0a8eccecd5061528c Version: ca16d5bee59807bf04deaab0a8eccecd5061528c Version: ca16d5bee59807bf04deaab0a8eccecd5061528c Version: ca16d5bee59807bf04deaab0a8eccecd5061528c Version: ca16d5bee59807bf04deaab0a8eccecd5061528c Version: 8dd558881e0f4d6942c19bd8f7b1a7c19becb59e Version: b90aa237f469c3575190a5e6a855b76ad1d2ce94 Version: 3e24098da750991f75819069c79e090dfd029219 Version: 2819f4030f43057238992a4adcd950d7c95aff65 Version: 2c60b44d8ba9d62c2693d2692f118177f212b1a8 Version: 82ca3ab31b9cf23b86436a85381e4c5757bc6b80 Version: 3.16.82 ≤ Version: 4.9.264 ≤ Version: 4.14.158 ≤ Version: 4.19.87 ≤ Version: 5.3.14 ≤ Version: 5.4.1 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"kernel/futex/core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "83b0f71d5a313a765754acab51d2ecc5de76e0b9",
"status": "affected",
"version": "ca16d5bee59807bf04deaab0a8eccecd5061528c",
"versionType": "git"
},
{
"lessThan": "a1c2b7b86a946b6b172bce44d74553da2323a36c",
"status": "affected",
"version": "ca16d5bee59807bf04deaab0a8eccecd5061528c",
"versionType": "git"
},
{
"lessThan": "33bfa85458105d6169ebdb697f692b8bb8025bae",
"status": "affected",
"version": "ca16d5bee59807bf04deaab0a8eccecd5061528c",
"versionType": "git"
},
{
"lessThan": "aa5c571901c6b22b58373693a4bf889ecab11ff5",
"status": "affected",
"version": "ca16d5bee59807bf04deaab0a8eccecd5061528c",
"versionType": "git"
},
{
"lessThan": "925628656b73b70930972ccde421de4f758d8650",
"status": "affected",
"version": "ca16d5bee59807bf04deaab0a8eccecd5061528c",
"versionType": "git"
},
{
"lessThan": "7b8c53263f8878bdd12c87e147ac6feca5c05211",
"status": "affected",
"version": "ca16d5bee59807bf04deaab0a8eccecd5061528c",
"versionType": "git"
},
{
"lessThan": "7cf710e70f9bb8ea75f759ebed09871801315992",
"status": "affected",
"version": "ca16d5bee59807bf04deaab0a8eccecd5061528c",
"versionType": "git"
},
{
"lessThan": "6d4514ca9cdf61fec4ec634cf50386f6f7e69748",
"status": "affected",
"version": "ca16d5bee59807bf04deaab0a8eccecd5061528c",
"versionType": "git"
},
{
"status": "affected",
"version": "8dd558881e0f4d6942c19bd8f7b1a7c19becb59e",
"versionType": "git"
},
{
"status": "affected",
"version": "b90aa237f469c3575190a5e6a855b76ad1d2ce94",
"versionType": "git"
},
{
"status": "affected",
"version": "3e24098da750991f75819069c79e090dfd029219",
"versionType": "git"
},
{
"status": "affected",
"version": "2819f4030f43057238992a4adcd950d7c95aff65",
"versionType": "git"
},
{
"status": "affected",
"version": "2c60b44d8ba9d62c2693d2692f118177f212b1a8",
"versionType": "git"
},
{
"status": "affected",
"version": "82ca3ab31b9cf23b86436a85381e4c5757bc6b80",
"versionType": "git"
},
{
"lessThan": "3.17",
"status": "affected",
"version": "3.16.82",
"versionType": "semver"
},
{
"lessThan": "4.10",
"status": "affected",
"version": "4.9.264",
"versionType": "semver"
},
{
"lessThan": "4.15",
"status": "affected",
"version": "4.14.158",
"versionType": "semver"
},
{
"lessThan": "4.20",
"status": "affected",
"version": "4.19.87",
"versionType": "semver"
},
{
"lessThan": "5.4",
"status": "affected",
"version": "5.3.14",
"versionType": "semver"
},
{
"lessThan": "5.5",
"status": "affected",
"version": "5.4.1",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"kernel/futex/core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.5"
},
{
"lessThan": "5.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.16.82",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.9.264",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.14.158",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.19.87",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.3.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.4.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfutex: Prevent robust futex exit race some more\n\nA robust futex unlock stores 0 over the whole futex value - wiping\nFUTEX_WAITERS - and wakes a single waiter. That wakeup is a one-shot\nnotification: the protocol relies on its recipient to either acquire the\nfutex (and eventually unlock while aware of the remaining contention) or\nre-arm FUTEX_WAITERS before sleeping again. If the woken waiter is killed\nbefore it can do either, the kernel must jump in and wake the next task\ndown the line.\n\nThis is a known complication of the futex protocol with a previous\npartial fix in commit ca16d5bee598 (\"futex: Prevent robust futex exit\nrace\"). Unfortunately, that fix is insufficient.\n\nIf a third task re-acquired the futex through the uncontended fast\npath in the meantime, the notification is lost: robust exit processing\nsees that it is owned by another task and does nothing, while the new\nowner sees no FUTEX_WAITERS when it unlocks and wakes nobody.\nThe remaining waiters sleep forever behind a free futex:\n\n A owns the futex, B and C sleep in FUTEX_WAIT\n uval == A | FUTEX_WAITERS\n A robust unlock: store 0, FUTEX_WAKE(1) wakes B\n uval == 0\n D fast path acquire: cmpxchg(0 -\u003e D)\n uval == D, no FUTEX_WAITERS\n B killed before acting on the wakeup\n B exit walk, pending op: owner D != B -\u003e no action\n D unlock: no FUTEX_WAITERS -\u003e no wake\n C sleeps forever\n\nThis is clearly a shortcoming in the implementation, which fails to keep\nthe FUTEX_WAITERS bit consistent.\n\nWork around this by augmenting the robust list exit processing to also\nperform the extra wakeup if the futex word is owned by another thread but\nFUTEX_WAITERS is not set.\n\nThis does not fix the problem of a non-contended take over/release and free\nsequence, which has been discussed for years and has been addressed by\ncommit 3ca9595d9fb6 (\"futex: Add support for unlocking robust futexes\") and\nsubsequent changes, but failed to take the problem described above into\naccount.\n\nA more complete solution which is based on the in kernel unlock of\ncontended robust futexes has been discussed in the context of this change\nand should show up in mainline sooner than later.\n\n[ tglx: Amend change log slightly and fixup coding style ]"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-22T15:32:32.190Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/83b0f71d5a313a765754acab51d2ecc5de76e0b9"
},
{
"url": "https://git.kernel.org/stable/c/a1c2b7b86a946b6b172bce44d74553da2323a36c"
},
{
"url": "https://git.kernel.org/stable/c/33bfa85458105d6169ebdb697f692b8bb8025bae"
},
{
"url": "https://git.kernel.org/stable/c/aa5c571901c6b22b58373693a4bf889ecab11ff5"
},
{
"url": "https://git.kernel.org/stable/c/925628656b73b70930972ccde421de4f758d8650"
},
{
"url": "https://git.kernel.org/stable/c/7b8c53263f8878bdd12c87e147ac6feca5c05211"
},
{
"url": "https://git.kernel.org/stable/c/7cf710e70f9bb8ea75f759ebed09871801315992"
},
{
"url": "https://git.kernel.org/stable/c/6d4514ca9cdf61fec4ec634cf50386f6f7e69748"
}
],
"title": "futex: Prevent robust futex exit race some more",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74658",
"datePublished": "2026-08-22T15:32:32.190Z",
"dateReserved": "2026-08-15T05:44:03.924Z",
"dateUpdated": "2026-08-22T15:32:32.190Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68402 (GCVE-0-2026-68402)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: cfg80211: bound element ID read when checking non-inheritance
cfg80211_is_element_inherited() reads the first data octet of the
candidate element (id = elem->data[0]) to look it up in an extension
non-inheritance list. It does so after testing elem->id, but without
verifying that the element actually has a data octet. A zero-length
extension element (WLAN_EID_EXTENSION with length 0) therefore makes it
read one octet past the end of the element.
_ieee802_11_parse_elems_full() runs this check for every element of a
frame once a non-inheritance context exists -- e.g. while parsing a
per-STA profile of a Multi-Link element in a (re)association response,
or a non-transmitted BSS profile -- so a crafted frame from an AP can
trigger a one-octet slab-out-of-bounds read during element parsing:
BUG: KASAN: slab-out-of-bounds in cfg80211_is_element_inherited
Read of size 1 ... in net/wireless/scan.c
Return early (treat the element as inherited) when an extension element
carries no data, mirroring the existing handling of empty ID lists.
The bug was found by fuzzing ieee802_11_parse_elems_full() under KASAN.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3 Version: f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3 Version: f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3 Version: f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3 Version: f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3 Version: f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3 Version: f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3 Version: f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/wireless/scan.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "521dd5fe6d12b0d3c275f919738dc3a07117f4a5",
"status": "affected",
"version": "f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3",
"versionType": "git"
},
{
"lessThan": "24154c172246ae3f0e69bb17c9111095685ceedc",
"status": "affected",
"version": "f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3",
"versionType": "git"
},
{
"lessThan": "2d31ebb26a14f103c9cdc5287fb20cb2d4bde901",
"status": "affected",
"version": "f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3",
"versionType": "git"
},
{
"lessThan": "20c308d9a57722801961f816395bf825f7bde6bc",
"status": "affected",
"version": "f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3",
"versionType": "git"
},
{
"lessThan": "84bd907361c56fbd5523eceb2682cb39da059bd5",
"status": "affected",
"version": "f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3",
"versionType": "git"
},
{
"lessThan": "11ac7a5e75f5132f1778e0c60981d30dc29fb869",
"status": "affected",
"version": "f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3",
"versionType": "git"
},
{
"lessThan": "ddf2773bcc8e49a43c561f22ec1e7924215d7947",
"status": "affected",
"version": "f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3",
"versionType": "git"
},
{
"lessThan": "cb8afea4655ff004fa7feee825d5c79783525383",
"status": "affected",
"version": "f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/wireless/scan.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.2"
},
{
"lessThan": "5.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: cfg80211: bound element ID read when checking non-inheritance\n\ncfg80211_is_element_inherited() reads the first data octet of the\ncandidate element (id = elem-\u003edata[0]) to look it up in an extension\nnon-inheritance list. It does so after testing elem-\u003eid, but without\nverifying that the element actually has a data octet. A zero-length\nextension element (WLAN_EID_EXTENSION with length 0) therefore makes it\nread one octet past the end of the element.\n\n_ieee802_11_parse_elems_full() runs this check for every element of a\nframe once a non-inheritance context exists -- e.g. while parsing a\nper-STA profile of a Multi-Link element in a (re)association response,\nor a non-transmitted BSS profile -- so a crafted frame from an AP can\ntrigger a one-octet slab-out-of-bounds read during element parsing:\n\n BUG: KASAN: slab-out-of-bounds in cfg80211_is_element_inherited\n Read of size 1 ... in net/wireless/scan.c\n\nReturn early (treat the element as inherited) when an extension element\ncarries no data, mirroring the existing handling of empty ID lists.\n\nThe bug was found by fuzzing ieee802_11_parse_elems_full() under KASAN."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The malformed element arrives in an 802.11 management frame (beacon, probe response, ML probe response or (re)association response) processed by mac80211\u0027s element parser, so the attacker must be a rogue/spoofing AP within radio range of the victim station.\nAC:L - The attacker fully controls the frame contents and simply appends a zero-length WLAN_EID_EXTENSION element inside a frame that already establishes a non-inheritance context (multi-BSSID non-transmitted profile or a Multi-Link per-STA profile), which reliably triggers the over-read every time.\nPR:N - Beacons, probe responses and association responses are parsed before or independently of any authentication or key establishment, so an unauthenticated attacker with no credentials on the network can deliver the crafted frame.\nUI:N - Stations parse beacons and probe/association responses automatically as part of scanning, roaming and staying associated; no action by the device owner is needed for the crafted frame to be processed.\nS:U - The out-of-bounds read stays within the kernel\u0027s own memory and security authority; no other component or privilege domain is crossed.\nC:L - The read is a single octet past the end of the slab object, and its value is only compared against the non-inheritance ID list, influencing whether an element is parsed \u2014 this leaks at most a narrow side-channel oracle about one adjacent heap byte rather than arbitrary memory.\nI:N - The defect is purely a read; no kernel memory is written or corrupted, and the only consequence is a possibly wrong inherit/skip decision for one element in a frame the attacker already controls.\nA:H - The slab out-of-bounds access is fatal on KASAN, hardened or debug-allocator kernels (the bug was reported as a KASAN slab-out-of-bounds splat), and can be re-triggered at will by an adjacent unauthenticated attacker to repeatedly panic the machine."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:52.049Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/521dd5fe6d12b0d3c275f919738dc3a07117f4a5"
},
{
"url": "https://git.kernel.org/stable/c/24154c172246ae3f0e69bb17c9111095685ceedc"
},
{
"url": "https://git.kernel.org/stable/c/2d31ebb26a14f103c9cdc5287fb20cb2d4bde901"
},
{
"url": "https://git.kernel.org/stable/c/20c308d9a57722801961f816395bf825f7bde6bc"
},
{
"url": "https://git.kernel.org/stable/c/84bd907361c56fbd5523eceb2682cb39da059bd5"
},
{
"url": "https://git.kernel.org/stable/c/11ac7a5e75f5132f1778e0c60981d30dc29fb869"
},
{
"url": "https://git.kernel.org/stable/c/ddf2773bcc8e49a43c561f22ec1e7924215d7947"
},
{
"url": "https://git.kernel.org/stable/c/cb8afea4655ff004fa7feee825d5c79783525383"
}
],
"title": "wifi: cfg80211: bound element ID read when checking non-inheritance",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68402",
"datePublished": "2026-08-10T12:04:22.113Z",
"dateReserved": "2026-07-30T09:28:09.389Z",
"dateUpdated": "2026-08-19T16:34:52.049Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80706 (GCVE-0-2026-80706)
Vulnerability from cvelistv5
Published
2026-08-28 06:53
Modified
2026-08-29 06:22
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
can: softing: fw_parse(): validate firmware record spans
fw_parse() reads a fixed record header, a firmware-provided payload,
and a trailing checksum without knowing the end of the firmware blob. A
truncated record can therefore make those reads exceed the blob.
The same record also supplies addresses and lengths for writes into
DPRAM. The generic loader uses wrap-prone mixed signed arithmetic for its
bounds check, while the application loader does not bound the staging
copy at all.
Pass the firmware end to the parser and validate the full source record.
Use a signed wide offset for generic DPRAM records and validate the
application staging span against the mapped DPRAM before copying.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 03fd3cf5a179da12e6bee5e9d74b648aff68dc4c Version: 03fd3cf5a179da12e6bee5e9d74b648aff68dc4c Version: 03fd3cf5a179da12e6bee5e9d74b648aff68dc4c Version: 03fd3cf5a179da12e6bee5e9d74b648aff68dc4c Version: 03fd3cf5a179da12e6bee5e9d74b648aff68dc4c Version: 03fd3cf5a179da12e6bee5e9d74b648aff68dc4c Version: 03fd3cf5a179da12e6bee5e9d74b648aff68dc4c Version: 03fd3cf5a179da12e6bee5e9d74b648aff68dc4c |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/can/softing/softing_fw.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "f6d9a6a9512430b395a1940d7b216394fd02d30b",
"status": "affected",
"version": "03fd3cf5a179da12e6bee5e9d74b648aff68dc4c",
"versionType": "git"
},
{
"lessThan": "84c850b08fc0d671c245144b619683129b55690a",
"status": "affected",
"version": "03fd3cf5a179da12e6bee5e9d74b648aff68dc4c",
"versionType": "git"
},
{
"lessThan": "d0eac0ea7cf493e787fd7b4a556e43ef03cb4b50",
"status": "affected",
"version": "03fd3cf5a179da12e6bee5e9d74b648aff68dc4c",
"versionType": "git"
},
{
"lessThan": "ae588e5b9cc268de1aabf30f939f0870717ca164",
"status": "affected",
"version": "03fd3cf5a179da12e6bee5e9d74b648aff68dc4c",
"versionType": "git"
},
{
"lessThan": "ad331e26fd213a19fee0de18cdacd67b7ff5b478",
"status": "affected",
"version": "03fd3cf5a179da12e6bee5e9d74b648aff68dc4c",
"versionType": "git"
},
{
"lessThan": "2ee477e541a6d5e434d6a4041c6b677ab42e1d82",
"status": "affected",
"version": "03fd3cf5a179da12e6bee5e9d74b648aff68dc4c",
"versionType": "git"
},
{
"lessThan": "808ed899dcf8bdef66894fda5eb7ee4bb0eb8dc1",
"status": "affected",
"version": "03fd3cf5a179da12e6bee5e9d74b648aff68dc4c",
"versionType": "git"
},
{
"lessThan": "856d6cb04e5407523566b075841dcd6423757d1c",
"status": "affected",
"version": "03fd3cf5a179da12e6bee5e9d74b648aff68dc4c",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/can/softing/softing_fw.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.38"
},
{
"lessThan": "2.6.38",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.38",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.38",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.38",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "2.6.38",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "2.6.38",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "2.6.38",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "2.6.38",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.38",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: softing: fw_parse(): validate firmware record spans\n\nfw_parse() reads a fixed record header, a firmware-provided payload,\nand a trailing checksum without knowing the end of the firmware blob. A\ntruncated record can therefore make those reads exceed the blob.\n\nThe same record also supplies addresses and lengths for writes into\nDPRAM. The generic loader uses wrap-prone mixed signed arithmetic for its\nbounds check, while the application loader does not bound the staging\ncopy at all.\n\nPass the firmware end to the parser and validate the full source record.\nUse a signed wide offset for generic DPRAM records and validate the\napplication staging span against the mapped DPRAM before copying."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Malformed firmware is consumed only via request_firmware() from the local firmware search path during softing_pdev_probe/softing_card_boot; CAN frames, network protocols, and bus traffic never reach fw_parse(), so exploitation requires local presence on the host loading the blob.\nAC:L - The attacker fully controls record type, addr, len, and payload in the Structured Binary Format file; a truncated final record or integer-wrapping addr/len values deterministically bypass the old bounds checks and trigger out-of-bounds reads/writes on every probe without races or layout luck.\nPR:L - fw_parse() performs no capability or credential checks, firmware paths under /lib/firmware/softing-4.6/ are writable by vendor/OTA accounts on many embedded and diagnostic deployments, and the sysfs firmware fallback loader exposes world-writable loading/data during request_firmware(), so a low-privileged local user can supply the malicious image.\nUI:N - Once the crafted blob is in place, parsing runs automatically from softing_card_boot during PCMCIA/platform probe on card insert or module bind; the attacker can trigger reload by reinserting the card or reloading softingcs themselves without requiring a separate victim action.\nS:U - The out-of-bounds reads and MMIO/DPRAM writes corrupt host kernel memory and the mapped Softing card region only; this is not a VM escape, IOMMU bypass, or other cross-security-authority breakout.\nC:H - fw_parse() reads record headers, variable-length payloads, and trailing checksums past the firmware buffer end, performing an out-of-bounds kernel read of adjacent vmalloc/kmalloc memory that can disclose sensitive kernel contents beyond a few bytes.\nI:H - Records supply addr and len used in memcpy_toio() into card DPRAM; the pre-fix mixed signed/unsigned bounds check could wrap and softing_load_app_fw staged copies without any DPRAM bound, enabling attacker-controlled out-of-bounds MMIO writes exploitable for memory corruption.\nA:H - Out-of-bounds MMIO writes past the ioremap window and out-of-bounds firmware-buffer reads readily fault on unmapped pages or corrupt critical DPRAM state, producing kernel oops/panic and denying use of the CAN interface on probe."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-29T06:22:23.266Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/f6d9a6a9512430b395a1940d7b216394fd02d30b"
},
{
"url": "https://git.kernel.org/stable/c/84c850b08fc0d671c245144b619683129b55690a"
},
{
"url": "https://git.kernel.org/stable/c/d0eac0ea7cf493e787fd7b4a556e43ef03cb4b50"
},
{
"url": "https://git.kernel.org/stable/c/ae588e5b9cc268de1aabf30f939f0870717ca164"
},
{
"url": "https://git.kernel.org/stable/c/ad331e26fd213a19fee0de18cdacd67b7ff5b478"
},
{
"url": "https://git.kernel.org/stable/c/2ee477e541a6d5e434d6a4041c6b677ab42e1d82"
},
{
"url": "https://git.kernel.org/stable/c/808ed899dcf8bdef66894fda5eb7ee4bb0eb8dc1"
},
{
"url": "https://git.kernel.org/stable/c/856d6cb04e5407523566b075841dcd6423757d1c"
}
],
"title": "can: softing: fw_parse(): validate firmware record spans",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80706",
"datePublished": "2026-08-28T06:53:07.640Z",
"dateReserved": "2026-08-26T14:34:25.787Z",
"dateUpdated": "2026-08-29T06:22:23.266Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80908 (GCVE-0-2026-80908)
Vulnerability from cvelistv5
Published
2026-09-04 17:19
Modified
2026-09-07 14:21
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: Reject UVD message with dimensions above 4096
Fixes potential overflow in DPB size calculations.
(cherry picked from commit 05e1387d151f71569fbe122d2c89f9db0c21dc10)
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d38ceaf99ed015f2a0b9af3499791bd3a3daae21 Version: d38ceaf99ed015f2a0b9af3499791bd3a3daae21 Version: d38ceaf99ed015f2a0b9af3499791bd3a3daae21 Version: d38ceaf99ed015f2a0b9af3499791bd3a3daae21 Version: d38ceaf99ed015f2a0b9af3499791bd3a3daae21 Version: d38ceaf99ed015f2a0b9af3499791bd3a3daae21 Version: d38ceaf99ed015f2a0b9af3499791bd3a3daae21 Version: d38ceaf99ed015f2a0b9af3499791bd3a3daae21 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/amdgpu_uvd.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "8bae80eaed00e7ae28412a3cdf590f4beca72294",
"status": "affected",
"version": "d38ceaf99ed015f2a0b9af3499791bd3a3daae21",
"versionType": "git"
},
{
"lessThan": "9adc5e25f31d7ee7dfc18814499b6e3a6d402904",
"status": "affected",
"version": "d38ceaf99ed015f2a0b9af3499791bd3a3daae21",
"versionType": "git"
},
{
"lessThan": "382bef781ff441ce8055bdada57b8c291dc0fd30",
"status": "affected",
"version": "d38ceaf99ed015f2a0b9af3499791bd3a3daae21",
"versionType": "git"
},
{
"lessThan": "8435d41afcf2bc31ecee213ef651c12bd1a16d38",
"status": "affected",
"version": "d38ceaf99ed015f2a0b9af3499791bd3a3daae21",
"versionType": "git"
},
{
"lessThan": "f7af372d3b892b95dd3cd1c6acf29daa39ba076d",
"status": "affected",
"version": "d38ceaf99ed015f2a0b9af3499791bd3a3daae21",
"versionType": "git"
},
{
"lessThan": "339deb76ee4859ea973e435c9a9a4a4fefc29338",
"status": "affected",
"version": "d38ceaf99ed015f2a0b9af3499791bd3a3daae21",
"versionType": "git"
},
{
"lessThan": "17fbb996c05f2190e0fa20927ca0b9804d481b02",
"status": "affected",
"version": "d38ceaf99ed015f2a0b9af3499791bd3a3daae21",
"versionType": "git"
},
{
"lessThan": "8c9aebcdd9f46f7a14b98d6ab18574b7a48fbb08",
"status": "affected",
"version": "d38ceaf99ed015f2a0b9af3499791bd3a3daae21",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/amdgpu_uvd.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.2"
},
{
"lessThan": "4.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.46",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.10",
"versionStartIncluding": "4.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Reject UVD message with dimensions above 4096\n\nFixes potential overflow in DPB size calculations.\n\n(cherry picked from commit 05e1387d151f71569fbe122d2c89f9db0c21dc10)"
}
],
"providerMetadata": {
"dateUpdated": "2026-09-07T14:21:30.299Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/8bae80eaed00e7ae28412a3cdf590f4beca72294"
},
{
"url": "https://git.kernel.org/stable/c/9adc5e25f31d7ee7dfc18814499b6e3a6d402904"
},
{
"url": "https://git.kernel.org/stable/c/382bef781ff441ce8055bdada57b8c291dc0fd30"
},
{
"url": "https://git.kernel.org/stable/c/8435d41afcf2bc31ecee213ef651c12bd1a16d38"
},
{
"url": "https://git.kernel.org/stable/c/f7af372d3b892b95dd3cd1c6acf29daa39ba076d"
},
{
"url": "https://git.kernel.org/stable/c/339deb76ee4859ea973e435c9a9a4a4fefc29338"
},
{
"url": "https://git.kernel.org/stable/c/17fbb996c05f2190e0fa20927ca0b9804d481b02"
},
{
"url": "https://git.kernel.org/stable/c/8c9aebcdd9f46f7a14b98d6ab18574b7a48fbb08"
}
],
"title": "drm/amdgpu: Reject UVD message with dimensions above 4096",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80908",
"datePublished": "2026-09-04T17:19:19.155Z",
"dateReserved": "2026-08-26T14:34:25.801Z",
"dateUpdated": "2026-09-07T14:21:30.299Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68160 (GCVE-0-2026-68160)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps()
ceph_handle_caps() reads snap_trace_len from the wire-format
ceph_mds_caps header and uses it unconditionally to build a fake
end pointer (snaptrace + snaptrace_len) that is later handed to
ceph_update_snap_trace() in the CEPH_CAP_OP_IMPORT case:
snaptrace = h + 1;
snaptrace_len = le32_to_cpu(h->snap_trace_len);
p = snaptrace + snaptrace_len;
...
case CEPH_CAP_OP_IMPORT:
if (snaptrace_len) {
...
if (ceph_update_snap_trace(mdsc, snaptrace,
snaptrace + snaptrace_len,
false, &realm)) { ... }
ceph_update_snap_trace() then decodes a struct ceph_mds_snap_realm
from snaptrace using ceph_decode_need(&p, e, sizeof(*ri), bad)
with the attacker-supplied fake end e == snaptrace + snaptrace_len.
With snaptrace_len == 0xFFFFFFFF the bound check is trivially
satisfied, ri = p reads sizeof(struct ceph_mds_snap_realm) past
the legitimate msg->front buffer, and ri->num_snaps /
ri->num_prior_parent_snaps then drive further out-of-bounds
reads of the encoded snap arrays.
The eleven msg_version >= 2 .. msg_version >= 12 decoder blocks
above the op switch each catch this OOB through their
ceph_decode_*_safe() / ceph_decode_need() helpers, but they sit
behind a hdr.version-gated if, so a malicious or compromised
MDS that sets msg->hdr.version = 1 reaches the IMPORT path with
no version-gated decoder having validated snap_trace_len. The
shape has been present since ceph_handle_caps() was introduced.
Validate snap_trace_len against the message front buffer before
consuming it, using the canonical ceph_decode_need() / ceph_has_room()
helper. The helper bounds the length with subtraction (n <= end - p,
guarded by end >= p) rather than pointer addition, so it is wrap-safe
for the attacker-controlled u32 length on 32-bit builds where
p + snap_trace_len could overflow the address space. This matches the
rest of the ceph decode path (e.g. the pool_ns_len check a few lines
below), and the existing goto bad cleanup already covers this exit
path.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: a8599bd821d084d04a3290fffae1071624ec00ea Version: a8599bd821d084d04a3290fffae1071624ec00ea Version: a8599bd821d084d04a3290fffae1071624ec00ea Version: a8599bd821d084d04a3290fffae1071624ec00ea Version: a8599bd821d084d04a3290fffae1071624ec00ea Version: a8599bd821d084d04a3290fffae1071624ec00ea Version: a8599bd821d084d04a3290fffae1071624ec00ea Version: a8599bd821d084d04a3290fffae1071624ec00ea |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/ceph/caps.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "f913192fc782288e060dafc329b2346934be34cc",
"status": "affected",
"version": "a8599bd821d084d04a3290fffae1071624ec00ea",
"versionType": "git"
},
{
"lessThan": "0c011137194036424e974677e0f1592e22a33d8c",
"status": "affected",
"version": "a8599bd821d084d04a3290fffae1071624ec00ea",
"versionType": "git"
},
{
"lessThan": "cc93f68a31c9b831abf2db8647b5f5b10329d793",
"status": "affected",
"version": "a8599bd821d084d04a3290fffae1071624ec00ea",
"versionType": "git"
},
{
"lessThan": "9081c71796724ffe96cba253f68fbe42363c5295",
"status": "affected",
"version": "a8599bd821d084d04a3290fffae1071624ec00ea",
"versionType": "git"
},
{
"lessThan": "03b417afce19ee6b6e61f1bbbbebac924c9f36d1",
"status": "affected",
"version": "a8599bd821d084d04a3290fffae1071624ec00ea",
"versionType": "git"
},
{
"lessThan": "a4228b93706fb74a484e6ffb271c1cc2af3a2ddb",
"status": "affected",
"version": "a8599bd821d084d04a3290fffae1071624ec00ea",
"versionType": "git"
},
{
"lessThan": "71893c342a26bcff92eaab0b2b75d64aed19308a",
"status": "affected",
"version": "a8599bd821d084d04a3290fffae1071624ec00ea",
"versionType": "git"
},
{
"lessThan": "4dbc71bcaf9a30abf3920a4e2cc4ed33bba78c02",
"status": "affected",
"version": "a8599bd821d084d04a3290fffae1071624ec00ea",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/ceph/caps.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.34"
},
{
"lessThan": "2.6.34",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "2.6.34",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.34",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps()\n\nceph_handle_caps() reads snap_trace_len from the wire-format\nceph_mds_caps header and uses it unconditionally to build a fake\nend pointer (snaptrace + snaptrace_len) that is later handed to\nceph_update_snap_trace() in the CEPH_CAP_OP_IMPORT case:\n\n snaptrace = h + 1;\n snaptrace_len = le32_to_cpu(h-\u003esnap_trace_len);\n p = snaptrace + snaptrace_len;\n ...\n case CEPH_CAP_OP_IMPORT:\n if (snaptrace_len) {\n ...\n if (ceph_update_snap_trace(mdsc, snaptrace,\n snaptrace + snaptrace_len,\n false, \u0026realm)) { ... }\n\nceph_update_snap_trace() then decodes a struct ceph_mds_snap_realm\nfrom snaptrace using ceph_decode_need(\u0026p, e, sizeof(*ri), bad)\nwith the attacker-supplied fake end e == snaptrace + snaptrace_len.\nWith snaptrace_len == 0xFFFFFFFF the bound check is trivially\nsatisfied, ri = p reads sizeof(struct ceph_mds_snap_realm) past\nthe legitimate msg-\u003efront buffer, and ri-\u003enum_snaps /\nri-\u003enum_prior_parent_snaps then drive further out-of-bounds\nreads of the encoded snap arrays.\n\nThe eleven msg_version \u003e= 2 .. msg_version \u003e= 12 decoder blocks\nabove the op switch each catch this OOB through their\nceph_decode_*_safe() / ceph_decode_need() helpers, but they sit\nbehind a hdr.version-gated if, so a malicious or compromised\nMDS that sets msg-\u003ehdr.version = 1 reaches the IMPORT path with\nno version-gated decoder having validated snap_trace_len. The\nshape has been present since ceph_handle_caps() was introduced.\n\nValidate snap_trace_len against the message front buffer before\nconsuming it, using the canonical ceph_decode_need() / ceph_has_room()\nhelper. The helper bounds the length with subtraction (n \u003c= end - p,\nguarded by end \u003e= p) rather than pointer addition, so it is wrap-safe\nfor the attacker-controlled u32 length on 32-bit builds where\np + snap_trace_len could overflow the address space. This matches the\nrest of the ceph decode path (e.g. the pool_ns_len check a few lines\nbelow), and the existing goto bad cleanup already covers this exit\npath."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - CEPH_MSG_CLIENT_CAPS is received over the kernel Ceph messenger TCP connection from an MDS peer; mds_dispatch() passes it directly to ceph_handle_caps(), so a malicious or compromised MDS (or on-path attacker on an unsigned msgr session) reaches the bug with network data alone.\nAC:L - The attacker fully controls msg-\u003ehdr.version and snap_trace_len in the caps header; setting version=1 bypasses all version-gated decoders and snap_trace_len=0xFFFFFFFF yields a fake end pointer that reliably defeats ceph_decode_need(), with no race or memory-layout dependency.\nPR:N - Exploitation requires only the ability to send crafted caps messages as the remote MDS peer on an established session; the attacker needs no account, mount privilege, or other credentials on the victim host beyond the client already being connected to that cluster.\nUI:N - Once CephFS is mounted and the MDS session is open, CEPH_CAP_OP_IMPORT caps messages are delivered and processed automatically during normal cap migration and MDS failover; no additional local user action is needed at exploit time beyond prior cluster connectivity.\nS:U - The out-of-bounds read and resulting snap-realm corruption affect only the kernel CephFS client\u2019s internal state within the same kernel security authority; there is no VM escape, sandbox breakout, or cross-authority boundary crossing.\nC:H - ceph_update_snap_trace() decodes struct ceph_mds_snap_realm and snap arrays using an attacker-supplied fake end pointer, reading sizeof(*ri) and further attacker-influenced extents past the legitimate msg-\u003efront buffer into adjacent kernel memory without copying to userspace.\nI:H - Out-of-bounds kernel memory is interpreted as snap-realm metadata and copied via dup_array() into newly allocated kernel heap structures (realm-\u003esnaps, realm-\u003eprior_parent_snaps), corrupting authoritative snap state and providing a memory-corruption primitive that could be leveraged for further kernel compromise.\nA:H - Out-of-bounds reads can fault on unmapped pages causing a kernel oops; the ceph_update_snap_trace() error path issues WARN(1), fences I/O via CEPH_MOUNT_FENCE_IO, and can close all MDS sessions\u2014effects an attacker can trigger repeatedly at will."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:30:32.455Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/f913192fc782288e060dafc329b2346934be34cc"
},
{
"url": "https://git.kernel.org/stable/c/0c011137194036424e974677e0f1592e22a33d8c"
},
{
"url": "https://git.kernel.org/stable/c/cc93f68a31c9b831abf2db8647b5f5b10329d793"
},
{
"url": "https://git.kernel.org/stable/c/9081c71796724ffe96cba253f68fbe42363c5295"
},
{
"url": "https://git.kernel.org/stable/c/03b417afce19ee6b6e61f1bbbbebac924c9f36d1"
},
{
"url": "https://git.kernel.org/stable/c/a4228b93706fb74a484e6ffb271c1cc2af3a2ddb"
},
{
"url": "https://git.kernel.org/stable/c/71893c342a26bcff92eaab0b2b75d64aed19308a"
},
{
"url": "https://git.kernel.org/stable/c/4dbc71bcaf9a30abf3920a4e2cc4ed33bba78c02"
}
],
"title": "ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68160",
"datePublished": "2026-08-10T11:59:26.741Z",
"dateReserved": "2026-07-30T09:28:09.371Z",
"dateUpdated": "2026-08-19T16:30:32.455Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68115 (GCVE-0-2026-68115)
Vulnerability from cvelistv5
Published
2026-08-10 11:58
Modified
2026-08-19 16:29
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu/gfx10: replace BUG_ON() with WARN_ON()
There's no need to crash the kernel for these cases.
(cherry picked from commit ac6f00beb658239bced4aaed9efbb04a35348d48)
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: a644d85a5cd4efbb1eb62751ef8a98a70d9794bc Version: a644d85a5cd4efbb1eb62751ef8a98a70d9794bc Version: a644d85a5cd4efbb1eb62751ef8a98a70d9794bc Version: a644d85a5cd4efbb1eb62751ef8a98a70d9794bc Version: a644d85a5cd4efbb1eb62751ef8a98a70d9794bc Version: a644d85a5cd4efbb1eb62751ef8a98a70d9794bc Version: a644d85a5cd4efbb1eb62751ef8a98a70d9794bc Version: a644d85a5cd4efbb1eb62751ef8a98a70d9794bc |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/gfx_v10_0.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "a5de4c9065db8653a3af8a1d4cf5f3c0024c480a",
"status": "affected",
"version": "a644d85a5cd4efbb1eb62751ef8a98a70d9794bc",
"versionType": "git"
},
{
"lessThan": "e994f4391b574bd57e7ac183ab93c3d60e8d4d55",
"status": "affected",
"version": "a644d85a5cd4efbb1eb62751ef8a98a70d9794bc",
"versionType": "git"
},
{
"lessThan": "5c23b018c64f9e8f28e407f313616dccd51b684f",
"status": "affected",
"version": "a644d85a5cd4efbb1eb62751ef8a98a70d9794bc",
"versionType": "git"
},
{
"lessThan": "793cdf17ddf9dc662a94cae86ce005565ef3c1c2",
"status": "affected",
"version": "a644d85a5cd4efbb1eb62751ef8a98a70d9794bc",
"versionType": "git"
},
{
"lessThan": "6c8cfdc2321c1284dc4320ac148867ea8f6419bd",
"status": "affected",
"version": "a644d85a5cd4efbb1eb62751ef8a98a70d9794bc",
"versionType": "git"
},
{
"lessThan": "7e22de67e545d0f72595514d3a66675e9d074adc",
"status": "affected",
"version": "a644d85a5cd4efbb1eb62751ef8a98a70d9794bc",
"versionType": "git"
},
{
"lessThan": "2929a932b0d70f481dbcb6994181544b07913de0",
"status": "affected",
"version": "a644d85a5cd4efbb1eb62751ef8a98a70d9794bc",
"versionType": "git"
},
{
"lessThan": "d06c4173a7c38c7a39e98859f839ce714c7af2c9",
"status": "affected",
"version": "a644d85a5cd4efbb1eb62751ef8a98a70d9794bc",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/gfx_v10_0.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.3"
},
{
"lessThan": "5.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/gfx10: replace BUG_ON() with WARN_ON()\n\nThere\u0027s no need to crash the kernel for these cases.\n\n(cherry picked from commit ac6f00beb658239bced4aaed9efbb04a35348d48)"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:29:26.881Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/a5de4c9065db8653a3af8a1d4cf5f3c0024c480a"
},
{
"url": "https://git.kernel.org/stable/c/e994f4391b574bd57e7ac183ab93c3d60e8d4d55"
},
{
"url": "https://git.kernel.org/stable/c/5c23b018c64f9e8f28e407f313616dccd51b684f"
},
{
"url": "https://git.kernel.org/stable/c/793cdf17ddf9dc662a94cae86ce005565ef3c1c2"
},
{
"url": "https://git.kernel.org/stable/c/6c8cfdc2321c1284dc4320ac148867ea8f6419bd"
},
{
"url": "https://git.kernel.org/stable/c/7e22de67e545d0f72595514d3a66675e9d074adc"
},
{
"url": "https://git.kernel.org/stable/c/2929a932b0d70f481dbcb6994181544b07913de0"
},
{
"url": "https://git.kernel.org/stable/c/d06c4173a7c38c7a39e98859f839ce714c7af2c9"
}
],
"title": "drm/amdgpu/gfx10: replace BUG_ON() with WARN_ON()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68115",
"datePublished": "2026-08-10T11:58:33.594Z",
"dateReserved": "2026-07-30T09:28:09.369Z",
"dateUpdated": "2026-08-19T16:29:26.881Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74628 (GCVE-0-2026-74628)
Vulnerability from cvelistv5
Published
2026-08-22 15:32
Modified
2026-08-27 12:39
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/x25: fix use-after-free of the socket by its timers
The x25 timers are armed with mod_timer() and cancelled with
timer_delete(), so a pending timer holds no reference on the socket and a
cancel does not wait for a callback already running on another CPU.
x25_heartbeat_expiry() also rearms unconditionally, so it can reinstall
sk->sk_timer after __x25_destroy_socket() has passed its cancel point.
The following __sock_put() frees the socket while the timer is still
queued, and the next expiry uses freed memory. KASAN reports a
slab-use-after-free on the kmalloc-2k object freed by close().
timer_delete_sync() cannot be used here: x25_heartbeat_expiry() and
x25_timer_expiry() both reach the cancels from inside the timer they
would wait on, through __x25_destroy_socket() and x25_disconnect().
Arm the timers with sk_reset_timer() and cancel them with sk_stop_timer()
so that an armed timer owns a reference, and release it in both expiry
handlers. Rearm the heartbeat only while sk_hashed(sk) is still true,
since __x25_destroy_socket() unlinks the socket before dropping it. Arm
the deferred destroy timer the same way and drop its reference in
x25_destroy_timer().
Reproduced on net with KASAN, with the heartbeat period shortened so the
window recurs. With this patch the reproducer no longer triggers a
report and /proc/net/x25 drains.
Discovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/x25/af_x25.c",
"net/x25/x25_timer.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ba925a2e98ce967a0e71c5bcbcf5dbd3facaf0c8",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "6b79659590f0f82a9b8efd2ffd55ec6399ebfc33",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "fdd9ac50b9b61ef2b2d52c5156aff788be91454d",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "1fc9f6d2c7c9fdb341bfe8ca449c990632299ea6",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "3c4919be5d910db4beebca420953858606fba7d8",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "4bc522b33438fefc3272840ae5988771863a4f1f",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "e92c7e2b41d1528a830bc64c5e4e46dfa8133dda",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "2195424c3da2ef1829a63b807e3a900a90e57d85",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/x25/af_x25.c",
"net/x25/x25_timer.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.267",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.267",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/x25: fix use-after-free of the socket by its timers\n\nThe x25 timers are armed with mod_timer() and cancelled with\ntimer_delete(), so a pending timer holds no reference on the socket and a\ncancel does not wait for a callback already running on another CPU.\n\nx25_heartbeat_expiry() also rearms unconditionally, so it can reinstall\nsk-\u003esk_timer after __x25_destroy_socket() has passed its cancel point.\nThe following __sock_put() frees the socket while the timer is still\nqueued, and the next expiry uses freed memory. KASAN reports a\nslab-use-after-free on the kmalloc-2k object freed by close().\n\ntimer_delete_sync() cannot be used here: x25_heartbeat_expiry() and\nx25_timer_expiry() both reach the cancels from inside the timer they\nwould wait on, through __x25_destroy_socket() and x25_disconnect().\n\nArm the timers with sk_reset_timer() and cancel them with sk_stop_timer()\nso that an armed timer owns a reference, and release it in both expiry\nhandlers. Rearm the heartbeat only while sk_hashed(sk) is still true,\nsince __x25_destroy_socket() unlinks the socket before dropping it. Arm\nthe deferred destroy timer the same way and drop its reference in\nx25_destroy_timer().\n\nReproduced on net with KASAN, with the heartbeat period shortened so the\nwindow recurs. With this patch the reproducer no longer triggers a\nreport and /proc/net/x25 drains.\n\nDiscovered by XBOW, triaged by Baul Lee \u003cbaul.lee@xbow.com\u003e"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - Remote X.25 frames reach x25_lapb_receive_frame() on init_net gateways, where unauthenticated CALL_REQUEST/CLEAR handling arms heartbeat timers and drives server socket teardown through __x25_destroy_socket() during close.\nAC:L - The attacker controls both sides of the race by opening/closing sockets or sending concurrent connect/clear traffic, repeatedly forcing __x25_destroy_socket() against sk_timer callbacks that re-arm via mod_timer().\nPR:N - X.25 call setup and clearing are unauthenticated on the wire; a remote peer can create sockets via CALL_REQUEST and force teardown without any local account or CAP_NET_ADMIN.\nUI:N - Exploitation requires no end-user action; automated server handling of remote X.25 connect/clear suffices to reach the vulnerable close/timer path.\nS:U - Impact stays within kernel memory via standard slab UAF on the AF_X25 socket object; this is not a guest/host or IOMMU boundary escape.\nC:H - KASAN reports slab-use-after-free on the kmalloc-2k socket freed by close(), and UAF on struct sock gives attacker-controlled reuse enabling arbitrary kernel memory disclosure.\nI:H - Use-after-free of the socket structure enables heap grooming and corrupting freed object contents for control-flow or arbitrary kernel writes/code execution.\nA:H - The freed socket timer expiry dereferences released memory and can oops/panic the kernel; UAF reliably threatens system availability even before full exploitation."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T12:39:49.703Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ba925a2e98ce967a0e71c5bcbcf5dbd3facaf0c8"
},
{
"url": "https://git.kernel.org/stable/c/6b79659590f0f82a9b8efd2ffd55ec6399ebfc33"
},
{
"url": "https://git.kernel.org/stable/c/fdd9ac50b9b61ef2b2d52c5156aff788be91454d"
},
{
"url": "https://git.kernel.org/stable/c/1fc9f6d2c7c9fdb341bfe8ca449c990632299ea6"
},
{
"url": "https://git.kernel.org/stable/c/3c4919be5d910db4beebca420953858606fba7d8"
},
{
"url": "https://git.kernel.org/stable/c/4bc522b33438fefc3272840ae5988771863a4f1f"
},
{
"url": "https://git.kernel.org/stable/c/e92c7e2b41d1528a830bc64c5e4e46dfa8133dda"
},
{
"url": "https://git.kernel.org/stable/c/2195424c3da2ef1829a63b807e3a900a90e57d85"
}
],
"title": "net/x25: fix use-after-free of the socket by its timers",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74628",
"datePublished": "2026-08-22T15:32:10.135Z",
"dateReserved": "2026-08-15T05:44:03.921Z",
"dateUpdated": "2026-08-27T12:39:49.703Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68183 (GCVE-0-2026-68183)
Vulnerability from cvelistv5
Published
2026-08-10 11:59
Modified
2026-08-19 16:30
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
firmware: stratix10-svc: fix memory leaks and list corruption bugs
Fix a memory leak when gen_pool_alloc() fails by freeing pmem on the error
path. Switch pmem allocation from devm_kzalloc() to kzalloc() with
explicit kfree() in the free path to match its list-managed lifetime.
Remove the erroneous list_del(&svc_data_mem) which corrupted the list head
on failed lookups.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 7ca5ce896524f5292e610b27d168269e5ab74951 Version: 7ca5ce896524f5292e610b27d168269e5ab74951 Version: 7ca5ce896524f5292e610b27d168269e5ab74951 Version: 7ca5ce896524f5292e610b27d168269e5ab74951 Version: 7ca5ce896524f5292e610b27d168269e5ab74951 Version: 7ca5ce896524f5292e610b27d168269e5ab74951 Version: 7ca5ce896524f5292e610b27d168269e5ab74951 Version: 7ca5ce896524f5292e610b27d168269e5ab74951 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/firmware/stratix10-svc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "76cff60d7fcb08da537f529bf32a0927bb17265f",
"status": "affected",
"version": "7ca5ce896524f5292e610b27d168269e5ab74951",
"versionType": "git"
},
{
"lessThan": "b9206568e08424fd817a4aeca4f944e241d2f530",
"status": "affected",
"version": "7ca5ce896524f5292e610b27d168269e5ab74951",
"versionType": "git"
},
{
"lessThan": "5df709d59227994888d7dbb7ea6c83316f0b79c0",
"status": "affected",
"version": "7ca5ce896524f5292e610b27d168269e5ab74951",
"versionType": "git"
},
{
"lessThan": "95f702e372964aff486338783f49e28a40a53127",
"status": "affected",
"version": "7ca5ce896524f5292e610b27d168269e5ab74951",
"versionType": "git"
},
{
"lessThan": "fff6e5ff0318315998b540896537eaaa2ebf9f7b",
"status": "affected",
"version": "7ca5ce896524f5292e610b27d168269e5ab74951",
"versionType": "git"
},
{
"lessThan": "4f2db41a09eba7a45abd140bb86ffc519c191886",
"status": "affected",
"version": "7ca5ce896524f5292e610b27d168269e5ab74951",
"versionType": "git"
},
{
"lessThan": "8e93a083456d78f6b0aa1f58d2b0c7071a2a7a47",
"status": "affected",
"version": "7ca5ce896524f5292e610b27d168269e5ab74951",
"versionType": "git"
},
{
"lessThan": "9119ceb76e987c2ec2b549ea100e3268ce3a1c7c",
"status": "affected",
"version": "7ca5ce896524f5292e610b27d168269e5ab74951",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/firmware/stratix10-svc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.0"
},
{
"lessThan": "5.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: stratix10-svc: fix memory leaks and list corruption bugs\n\nFix a memory leak when gen_pool_alloc() fails by freeing pmem on the error\npath. Switch pmem allocation from devm_kzalloc() to kzalloc() with\nexplicit kfree() in the free path to match its list-managed lifetime.\nRemove the erroneous list_del(\u0026svc_data_mem) which corrupted the list head\non failed lookups."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:30:49.896Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/76cff60d7fcb08da537f529bf32a0927bb17265f"
},
{
"url": "https://git.kernel.org/stable/c/b9206568e08424fd817a4aeca4f944e241d2f530"
},
{
"url": "https://git.kernel.org/stable/c/5df709d59227994888d7dbb7ea6c83316f0b79c0"
},
{
"url": "https://git.kernel.org/stable/c/95f702e372964aff486338783f49e28a40a53127"
},
{
"url": "https://git.kernel.org/stable/c/fff6e5ff0318315998b540896537eaaa2ebf9f7b"
},
{
"url": "https://git.kernel.org/stable/c/4f2db41a09eba7a45abd140bb86ffc519c191886"
},
{
"url": "https://git.kernel.org/stable/c/8e93a083456d78f6b0aa1f58d2b0c7071a2a7a47"
},
{
"url": "https://git.kernel.org/stable/c/9119ceb76e987c2ec2b549ea100e3268ce3a1c7c"
}
],
"title": "firmware: stratix10-svc: fix memory leaks and list corruption bugs",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68183",
"datePublished": "2026-08-10T11:59:54.836Z",
"dateReserved": "2026-07-30T09:28:09.373Z",
"dateUpdated": "2026-08-19T16:30:49.896Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68223 (GCVE-0-2026-68223)
Vulnerability from cvelistv5
Published
2026-08-10 12:00
Modified
2026-08-19 16:31
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: meson: vdec: Fix memory leak in error path of vdec_open
The vdec_open() function previously jumped directly to
err_m2m_release when vdec_init_ctrls() failed, skipping
release of the m2m context. This caused a resource leak.
Fix it by introducing a proper err_m2m_ctx_release label
that calls v4l2_m2m_ctx_release(sess->m2m_ctx) before
releasing the m2m device.
This was identified via kmemleak:
unreferenced object 0xffff0000205d6878 (size 8):
comm "v4l_id", pid 5289, jiffies 4294938580
hex dump (first 8 bytes):
40 d2 49 18 00 00 ff ff @.I.....
backtrace (crc d3204599):
kmemleak_alloc+0xc8/0xf0
__kvmalloc_node_noprof+0x60c/0x850
v4l2_ctrl_handler_init_class+0x1b4/0x2e8 [videodev]
vdec_open+0x1f4/0x788 [meson_vdec]
v4l2_open+0x144/0x460 [videodev]
chrdev_open+0x1ac/0x500
do_dentry_open+0x3f0/0xfe8
vfs_open+0x68/0x320
do_open+0x2d8/0x9a8
path_openat+0x1d0/0x4f0
do_filp_open+0x190/0x380
do_sys_openat2+0xf8/0x1b0
__arm64_sys_openat+0x13c/0x1e8
invoke_syscall+0xdc/0x268
el0_svc_common.constprop.0+0x178/0x258
do_el0_svc+0x4c/0x70
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 3e7f51bd96077acad6acd7b45668f65b44233c4e Version: 3e7f51bd96077acad6acd7b45668f65b44233c4e Version: 3e7f51bd96077acad6acd7b45668f65b44233c4e Version: 3e7f51bd96077acad6acd7b45668f65b44233c4e Version: 3e7f51bd96077acad6acd7b45668f65b44233c4e Version: 3e7f51bd96077acad6acd7b45668f65b44233c4e Version: 3e7f51bd96077acad6acd7b45668f65b44233c4e Version: 3e7f51bd96077acad6acd7b45668f65b44233c4e |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/staging/media/meson/vdec/vdec.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "5f97120d1a50c9efffe54425fac42bb7ef13ac86",
"status": "affected",
"version": "3e7f51bd96077acad6acd7b45668f65b44233c4e",
"versionType": "git"
},
{
"lessThan": "fb77d6f4580f316c9148b942af0028ee489d121e",
"status": "affected",
"version": "3e7f51bd96077acad6acd7b45668f65b44233c4e",
"versionType": "git"
},
{
"lessThan": "d9058a19731036c03a779bfe8c3ca0d9aa198599",
"status": "affected",
"version": "3e7f51bd96077acad6acd7b45668f65b44233c4e",
"versionType": "git"
},
{
"lessThan": "c6cd08a71a630f19b10c318e76e3c56e1dd10e00",
"status": "affected",
"version": "3e7f51bd96077acad6acd7b45668f65b44233c4e",
"versionType": "git"
},
{
"lessThan": "2cf0171ad594860e31723c671e37824ce12c01ea",
"status": "affected",
"version": "3e7f51bd96077acad6acd7b45668f65b44233c4e",
"versionType": "git"
},
{
"lessThan": "1391b75bf0119b5d37f1c1c3078d452a01967f9b",
"status": "affected",
"version": "3e7f51bd96077acad6acd7b45668f65b44233c4e",
"versionType": "git"
},
{
"lessThan": "99f3527bd1a27ff798d59177ed045b0dd87deaef",
"status": "affected",
"version": "3e7f51bd96077acad6acd7b45668f65b44233c4e",
"versionType": "git"
},
{
"lessThan": "940f161f734b25f175a95d2684c2021f6323693a",
"status": "affected",
"version": "3e7f51bd96077acad6acd7b45668f65b44233c4e",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/staging/media/meson/vdec/vdec.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.3"
},
{
"lessThan": "5.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: meson: vdec: Fix memory leak in error path of vdec_open\n\nThe vdec_open() function previously jumped directly to\nerr_m2m_release when vdec_init_ctrls() failed, skipping\nrelease of the m2m context. This caused a resource leak.\n\nFix it by introducing a proper err_m2m_ctx_release label\nthat calls v4l2_m2m_ctx_release(sess-\u003em2m_ctx) before\nreleasing the m2m device.\n\nThis was identified via kmemleak:\nunreferenced object 0xffff0000205d6878 (size 8):\n comm \"v4l_id\", pid 5289, jiffies 4294938580\n hex dump (first 8 bytes):\n 40 d2 49 18 00 00 ff ff @.I.....\n backtrace (crc d3204599):\n kmemleak_alloc+0xc8/0xf0\n __kvmalloc_node_noprof+0x60c/0x850\n v4l2_ctrl_handler_init_class+0x1b4/0x2e8 [videodev]\n vdec_open+0x1f4/0x788 [meson_vdec]\n v4l2_open+0x144/0x460 [videodev]\n chrdev_open+0x1ac/0x500\n do_dentry_open+0x3f0/0xfe8\n vfs_open+0x68/0x320\n do_open+0x2d8/0x9a8\n path_openat+0x1d0/0x4f0\n do_filp_open+0x190/0x380\n do_sys_openat2+0xf8/0x1b0\n __arm64_sys_openat+0x13c/0x1e8\n invoke_syscall+0xdc/0x268\n el0_svc_common.constprop.0+0x178/0x258\n do_el0_svc+0x4c/0x70"
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:31:54.081Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/5f97120d1a50c9efffe54425fac42bb7ef13ac86"
},
{
"url": "https://git.kernel.org/stable/c/fb77d6f4580f316c9148b942af0028ee489d121e"
},
{
"url": "https://git.kernel.org/stable/c/d9058a19731036c03a779bfe8c3ca0d9aa198599"
},
{
"url": "https://git.kernel.org/stable/c/c6cd08a71a630f19b10c318e76e3c56e1dd10e00"
},
{
"url": "https://git.kernel.org/stable/c/2cf0171ad594860e31723c671e37824ce12c01ea"
},
{
"url": "https://git.kernel.org/stable/c/1391b75bf0119b5d37f1c1c3078d452a01967f9b"
},
{
"url": "https://git.kernel.org/stable/c/99f3527bd1a27ff798d59177ed045b0dd87deaef"
},
{
"url": "https://git.kernel.org/stable/c/940f161f734b25f175a95d2684c2021f6323693a"
}
],
"title": "media: meson: vdec: Fix memory leak in error path of vdec_open",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68223",
"datePublished": "2026-08-10T12:00:44.123Z",
"dateReserved": "2026-07-30T09:28:09.375Z",
"dateUpdated": "2026-08-19T16:31:54.081Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68417 (GCVE-0-2026-68417)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-19 16:35
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
RDMA/siw: publish QP after initialization
siw_create_qp() currently calls siw_qp_add() before the queues, CQ
pointers, state, completion, and device list entry are ready. A QPN
lookup can therefore reach a QP that is still being constructed.
Move siw_qp_add() to the end of siw_create_qp(), after QP
initialization and before adding the QP to the siw device list.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: f29dd55b0236f7a26a4b9dd69186e3c04266797b Version: f29dd55b0236f7a26a4b9dd69186e3c04266797b Version: f29dd55b0236f7a26a4b9dd69186e3c04266797b Version: f29dd55b0236f7a26a4b9dd69186e3c04266797b Version: f29dd55b0236f7a26a4b9dd69186e3c04266797b Version: f29dd55b0236f7a26a4b9dd69186e3c04266797b Version: f29dd55b0236f7a26a4b9dd69186e3c04266797b |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/sw/siw/siw_verbs.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "3c9d128219964dcea897bf6139b88242e987be8f",
"status": "affected",
"version": "f29dd55b0236f7a26a4b9dd69186e3c04266797b",
"versionType": "git"
},
{
"lessThan": "3ff82e3841ecab1ff38d5817c969a019d266c83c",
"status": "affected",
"version": "f29dd55b0236f7a26a4b9dd69186e3c04266797b",
"versionType": "git"
},
{
"lessThan": "36e91a58397ca8c978e38a0bf389f0c6113fa8ca",
"status": "affected",
"version": "f29dd55b0236f7a26a4b9dd69186e3c04266797b",
"versionType": "git"
},
{
"lessThan": "74912ad168f87d6b2b670a87987bb302d6e64aa1",
"status": "affected",
"version": "f29dd55b0236f7a26a4b9dd69186e3c04266797b",
"versionType": "git"
},
{
"lessThan": "fcc9d50022bcdb1f9f7ed04955c72b4a7355af3d",
"status": "affected",
"version": "f29dd55b0236f7a26a4b9dd69186e3c04266797b",
"versionType": "git"
},
{
"lessThan": "52f9fcb191143448df55fd215ff09c5207fed43e",
"status": "affected",
"version": "f29dd55b0236f7a26a4b9dd69186e3c04266797b",
"versionType": "git"
},
{
"lessThan": "bb27fcc67c429d97f785c92c35a6c5adebb05d7f",
"status": "affected",
"version": "f29dd55b0236f7a26a4b9dd69186e3c04266797b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/infiniband/sw/siw/siw_verbs.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.3"
},
{
"lessThan": "5.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/siw: publish QP after initialization\n\nsiw_create_qp() currently calls siw_qp_add() before the queues, CQ\npointers, state, completion, and device list entry are ready. A QPN\nlookup can therefore reach a QP that is still being constructed.\n\nMove siw_qp_add() to the end of siw_create_qp(), after QP\ninitialization and before adding the QP to the siw device list."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires local access to the RDMA character devices (/dev/infiniband/uverbsN for create_qp and /dev/infiniband/rdma_cm for the QPN lookup); no network packet reaches the racing code path without a local trigger first.\nAC:L - The attacker controls both sides of the race: one thread issues create_qp while another issues rdma_connect/rdma_accept with an attacker-supplied qp_num, and QPNs from xa_alloc(XA_FLAGS_ALLOC1) are predictable. The post-publish failure can be made deterministic by passing a short udata-\u003eoutlen, so the window is wide and repeatable at will.\nPR:L - Any unprivileged local user with access to the siw uverbs and rdma_cm character devices can create QPs and issue rdma_connect/rdma_accept with an arbitrary qp_num; no capability check gates siw_create_qp, siw_connect or siw_accept.\nUI:N - The attacker drives both the QP creation and the concurrent QPN lookup from its own threads; no action by any other user or administrator is needed.\nS:U - The corruption is confined to kernel memory managed by the same kernel security authority; there is no crossing of a VM, IOMMU or sandbox boundary.\nC:H - The siw_qp object can be kfree\u0027d by the ib core error path while the CM thread still holds a reference, giving a use-after-free on a slab object the attacker can groom and read back through QP/CM state, enabling disclosure of arbitrary kernel memory.\nI:H - After the free, siw_free_qp() performs list_del(\u0026qp-\u003edevq), vfree() of four pointer fields and siw_put_tx_cpu(qp-\u003etx_cpu) using values read from reallocated attacker-controlled memory, yielding arbitrary-pointer free, list-unlink writes and out-of-range per-CPU decrements suitable for control-flow hijacking.\nA:H - Even without exploitation the race reliably causes kernel crashes: NULL sendq/recvq/scq/rcq dereferences, list_del on an uninitialized devq head, waits on an uninitialized qp_free completion, and use-after-free oopses."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:35:15.087Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/3c9d128219964dcea897bf6139b88242e987be8f"
},
{
"url": "https://git.kernel.org/stable/c/3ff82e3841ecab1ff38d5817c969a019d266c83c"
},
{
"url": "https://git.kernel.org/stable/c/36e91a58397ca8c978e38a0bf389f0c6113fa8ca"
},
{
"url": "https://git.kernel.org/stable/c/74912ad168f87d6b2b670a87987bb302d6e64aa1"
},
{
"url": "https://git.kernel.org/stable/c/fcc9d50022bcdb1f9f7ed04955c72b4a7355af3d"
},
{
"url": "https://git.kernel.org/stable/c/52f9fcb191143448df55fd215ff09c5207fed43e"
},
{
"url": "https://git.kernel.org/stable/c/bb27fcc67c429d97f785c92c35a6c5adebb05d7f"
}
],
"title": "RDMA/siw: publish QP after initialization",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68417",
"datePublished": "2026-08-10T12:04:37.936Z",
"dateReserved": "2026-07-30T09:28:09.391Z",
"dateUpdated": "2026-08-19T16:35:15.087Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72253 (GCVE-0-2026-72253)
Vulnerability from cvelistv5
Published
2026-08-15 05:54
Modified
2026-08-23 12:47
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_conntrack_sip: validate skb_dst() before accessing it
tc ingress and openvswitch do not guarantee routing information to be
available. These subsystems use the conntrack helper infrastructure, and
the SIP helper relies on the skb_dst() to be present if
sip_external_media is set to 1 (which is disabled by default as a module
parameter).
This effectively disables the sip_external_media toggle for these
subsystems without resulting in a crash.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: cae3a2627520c3795b54533c5328b77af3405dbe Version: cae3a2627520c3795b54533c5328b77af3405dbe Version: cae3a2627520c3795b54533c5328b77af3405dbe Version: cae3a2627520c3795b54533c5328b77af3405dbe Version: cae3a2627520c3795b54533c5328b77af3405dbe Version: cae3a2627520c3795b54533c5328b77af3405dbe Version: cae3a2627520c3795b54533c5328b77af3405dbe Version: cae3a2627520c3795b54533c5328b77af3405dbe |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/netfilter/nf_conntrack_sip.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "7866116a040b3a23fb094e7d8f7ea3d61b3ac70b",
"status": "affected",
"version": "cae3a2627520c3795b54533c5328b77af3405dbe",
"versionType": "git"
},
{
"lessThan": "c5ef7228be04518d95591fc5369a9c554b19756d",
"status": "affected",
"version": "cae3a2627520c3795b54533c5328b77af3405dbe",
"versionType": "git"
},
{
"lessThan": "0aec339694a56e263d4b22475ff7211d40900830",
"status": "affected",
"version": "cae3a2627520c3795b54533c5328b77af3405dbe",
"versionType": "git"
},
{
"lessThan": "e64a48c50a1ff565a98c6a98d82b5b942868e76e",
"status": "affected",
"version": "cae3a2627520c3795b54533c5328b77af3405dbe",
"versionType": "git"
},
{
"lessThan": "c199ed687c00841daf60e9d131976958583a8c09",
"status": "affected",
"version": "cae3a2627520c3795b54533c5328b77af3405dbe",
"versionType": "git"
},
{
"lessThan": "09755dc62b026076b1d47f83489eb0547c8135e0",
"status": "affected",
"version": "cae3a2627520c3795b54533c5328b77af3405dbe",
"versionType": "git"
},
{
"lessThan": "b843a96252f672332837ea2ecb7c8db0acf68e20",
"status": "affected",
"version": "cae3a2627520c3795b54533c5328b77af3405dbe",
"versionType": "git"
},
{
"lessThan": "e5e24a365a5e024efef63cc49abb345fbd4852c5",
"status": "affected",
"version": "cae3a2627520c3795b54533c5328b77af3405dbe",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/netfilter/nf_conntrack_sip.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.3"
},
{
"lessThan": "4.3",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_conntrack_sip: validate skb_dst() before accessing it\n\ntc ingress and openvswitch do not guarantee routing information to be\navailable. These subsystems use the conntrack helper infrastructure, and\nthe SIP helper relies on the skb_dst() to be present if\nsip_external_media is set to 1 (which is disabled by default as a module\nparameter).\n\nThis effectively disables the sip_external_media toggle for these\nsubsystems without resulting in a crash."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - Remote attackers reach set_expected_rtp_rtcp() by sending crafted SIP/SDP (e.g., INVITE) through Open vSwitch or tc ingress ct(helper=sip) on internet-facing VoIP SBC/NFV gateways where packets are conntrack-processed before skb_dst routing metadata is attached.\nAC:L - Once sip_external_media=1, sip_direct_media=0, and the SIP helper are configured on OVS/tc ingress, the attacker fully controls SIP/SDP contents to reach the skb_dst(skb)-\u003edev dereference without races or conditions outside their control.\nPR:N - Exploitation requires no privileges on the victim host; a remote SIP peer only needs to deliver malicious signaling to an already-configured OVS/tc SIP ALG with sip_external_media enabled, with no authentication or local access.\nUI:N - No victim user interaction is required; the kernel SIP helper parses attacker-supplied SIP/SDP during conntrack processing in softirq without any user action beyond normal automated packet handling.\nS:U - A NULL pointer dereference in nf_conntrack_sip causes a kernel oops/panic within the same kernel security domain on the gateway; it does not cross VM, IOMMU, or sandbox boundaries.\nC:N - The failure is a direct NULL pointer dereference from skb_dst(skb) being NULL on tc/OVS ingress paths; there is no use-after-free, out-of-bounds read, or other memory disclosure primitive.\nI:N - Accessing skb_dst(skb)-\u003edev when skb_dst is NULL cannot modify memory or hijack control flow beyond the immediate fault; CVSS guidance assigns None for pure NULL-deref crashes without write capability.\nA:H - The invalid skb_dst dereference in set_expected_rtp_rtcp() during SIP SDP processing causes a kernel oops/panic-class fault, denying availability on the VoIP gateway until reboot; the crash is reliably reproducible with crafted SIP traffic."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:47:08.038Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/7866116a040b3a23fb094e7d8f7ea3d61b3ac70b"
},
{
"url": "https://git.kernel.org/stable/c/c5ef7228be04518d95591fc5369a9c554b19756d"
},
{
"url": "https://git.kernel.org/stable/c/0aec339694a56e263d4b22475ff7211d40900830"
},
{
"url": "https://git.kernel.org/stable/c/e64a48c50a1ff565a98c6a98d82b5b942868e76e"
},
{
"url": "https://git.kernel.org/stable/c/c199ed687c00841daf60e9d131976958583a8c09"
},
{
"url": "https://git.kernel.org/stable/c/09755dc62b026076b1d47f83489eb0547c8135e0"
},
{
"url": "https://git.kernel.org/stable/c/b843a96252f672332837ea2ecb7c8db0acf68e20"
},
{
"url": "https://git.kernel.org/stable/c/e5e24a365a5e024efef63cc49abb345fbd4852c5"
}
],
"title": "netfilter: nf_conntrack_sip: validate skb_dst() before accessing it",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72253",
"datePublished": "2026-08-15T05:54:41.490Z",
"dateReserved": "2026-08-09T03:40:39.915Z",
"dateUpdated": "2026-08-23T12:47:08.038Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68450 (GCVE-0-2026-68450)
Vulnerability from cvelistv5
Published
2026-08-12 00:51
Modified
2026-08-19 16:35
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
btrfs: free mapping node on duplicate reloc root insert
__add_reloc_root() allocates a mapping_node before inserting it into
rc->reloc_root_tree. If rb_simple_insert() finds an existing entry, it
returns the existing rb_node and leaves the newly allocated node unlinked.
The error path then returns -EEXIST without freeing the new node. Since
the node was never inserted into reloc_root_tree, the later cleanup in
put_reloc_control() cannot find it either.
Free the newly allocated node before returning -EEXIST.
The callers currently assert that -EEXIST should not happen, so this is a
defensive cleanup for an unexpected duplicate insert path. If the path is
ever reached, the local allocation should still be released.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 57a304cfd43b2b4a5b44b8f5dc026abb34183068 Version: 57a304cfd43b2b4a5b44b8f5dc026abb34183068 Version: 57a304cfd43b2b4a5b44b8f5dc026abb34183068 Version: 57a304cfd43b2b4a5b44b8f5dc026abb34183068 Version: 57a304cfd43b2b4a5b44b8f5dc026abb34183068 Version: 57a304cfd43b2b4a5b44b8f5dc026abb34183068 Version: 57a304cfd43b2b4a5b44b8f5dc026abb34183068 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/btrfs/relocation.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "29d9746812d8b7c37d594f484e994fd552c3ec33",
"status": "affected",
"version": "57a304cfd43b2b4a5b44b8f5dc026abb34183068",
"versionType": "git"
},
{
"lessThan": "b7c5b8e1d5f0779dfbabc3068b7ac0f12e53b3a8",
"status": "affected",
"version": "57a304cfd43b2b4a5b44b8f5dc026abb34183068",
"versionType": "git"
},
{
"lessThan": "92bedc0455552b42ada1a1f42b0e3a8593cdfccc",
"status": "affected",
"version": "57a304cfd43b2b4a5b44b8f5dc026abb34183068",
"versionType": "git"
},
{
"lessThan": "14a8be9428435ee17f17fae7991215c246b7fd43",
"status": "affected",
"version": "57a304cfd43b2b4a5b44b8f5dc026abb34183068",
"versionType": "git"
},
{
"lessThan": "797dc567146c7e3c4f8d9680e4fbc76e0a6d9151",
"status": "affected",
"version": "57a304cfd43b2b4a5b44b8f5dc026abb34183068",
"versionType": "git"
},
{
"lessThan": "ae0629ff9ccb836416ada129f4edc7efea6eaaad",
"status": "affected",
"version": "57a304cfd43b2b4a5b44b8f5dc026abb34183068",
"versionType": "git"
},
{
"lessThan": "6a8269b6459ed870a8156c106a0f597383907872",
"status": "affected",
"version": "57a304cfd43b2b4a5b44b8f5dc026abb34183068",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/btrfs/relocation.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.13"
},
{
"lessThan": "5.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: free mapping node on duplicate reloc root insert\n\n__add_reloc_root() allocates a mapping_node before inserting it into\nrc-\u003ereloc_root_tree. If rb_simple_insert() finds an existing entry, it\nreturns the existing rb_node and leaves the newly allocated node unlinked.\n\nThe error path then returns -EEXIST without freeing the new node. Since\nthe node was never inserted into reloc_root_tree, the later cleanup in\nput_reloc_control() cannot find it either.\n\nFree the newly allocated node before returning -EEXIST.\n\nThe callers currently assert that -EEXIST should not happen, so this is a\ndefensive cleanup for an unexpected duplicate insert path. If the path is\never reached, the local allocation should still be released."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:35:45.490Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/29d9746812d8b7c37d594f484e994fd552c3ec33"
},
{
"url": "https://git.kernel.org/stable/c/b7c5b8e1d5f0779dfbabc3068b7ac0f12e53b3a8"
},
{
"url": "https://git.kernel.org/stable/c/92bedc0455552b42ada1a1f42b0e3a8593cdfccc"
},
{
"url": "https://git.kernel.org/stable/c/14a8be9428435ee17f17fae7991215c246b7fd43"
},
{
"url": "https://git.kernel.org/stable/c/797dc567146c7e3c4f8d9680e4fbc76e0a6d9151"
},
{
"url": "https://git.kernel.org/stable/c/ae0629ff9ccb836416ada129f4edc7efea6eaaad"
},
{
"url": "https://git.kernel.org/stable/c/6a8269b6459ed870a8156c106a0f597383907872"
}
],
"title": "btrfs: free mapping node on duplicate reloc root insert",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68450",
"datePublished": "2026-08-12T00:51:48.970Z",
"dateReserved": "2026-07-30T09:28:09.395Z",
"dateUpdated": "2026-08-19T16:35:45.490Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74456 (GCVE-0-2026-74456)
Vulnerability from cvelistv5
Published
2026-08-15 12:26
Modified
2026-08-19 16:36
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
can: peak_usb: peak_usb_start(): fix double free of transfer buffer on URB submit error
In peak_usb_start(), each RX URB transfer buffer is allocated with kmalloc()
and the URB is flagged URB_FREE_BUFFER so that the final usb_free_urb() also
frees the transfer buffer.
If usb_submit_urb() fails, the error path frees the buffer explicitly with
kfree(buf) and then calls usb_free_urb(urb). Because URB_FREE_BUFFER is set,
usb_free_urb() -> urb_destroy() frees the same buffer a second time, a double
free of the transfer buffer.
BUG: KASAN: double-free in usb_free_urb.part.0+0x91/0xb0
Free of addr ffff8881069ccb80 by task trigger.sh/285
Call Trace:
kfree+0x113/0x3c0
usb_free_urb.part.0+0x91/0xb0
Drop the redundant kfree(buf); usb_free_urb() already releases the transfer
buffer. This mirrors commit 03819abbeb11 ("net: usb: lan78xx: Fix double free
issue with interrupt buffer allocation").
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: bb4785551f64e18b2c8bb15a3bd2b22f5ebf624d Version: bb4785551f64e18b2c8bb15a3bd2b22f5ebf624d Version: bb4785551f64e18b2c8bb15a3bd2b22f5ebf624d Version: bb4785551f64e18b2c8bb15a3bd2b22f5ebf624d Version: bb4785551f64e18b2c8bb15a3bd2b22f5ebf624d Version: bb4785551f64e18b2c8bb15a3bd2b22f5ebf624d Version: bb4785551f64e18b2c8bb15a3bd2b22f5ebf624d Version: bb4785551f64e18b2c8bb15a3bd2b22f5ebf624d |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/can/usb/peak_usb/pcan_usb_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "914c3b8fa175acf8476ad31cf04e308638e3578e",
"status": "affected",
"version": "bb4785551f64e18b2c8bb15a3bd2b22f5ebf624d",
"versionType": "git"
},
{
"lessThan": "5f2fa5840c34d3a558c57855781be75e03bef752",
"status": "affected",
"version": "bb4785551f64e18b2c8bb15a3bd2b22f5ebf624d",
"versionType": "git"
},
{
"lessThan": "b9088d581fff971a7eb1628f8dcc30df6cfef4dc",
"status": "affected",
"version": "bb4785551f64e18b2c8bb15a3bd2b22f5ebf624d",
"versionType": "git"
},
{
"lessThan": "525640b93d3e5f82f4ebea4730f4e0cf799522ba",
"status": "affected",
"version": "bb4785551f64e18b2c8bb15a3bd2b22f5ebf624d",
"versionType": "git"
},
{
"lessThan": "4bb3325075138dd5346b71589a959878b564dc0b",
"status": "affected",
"version": "bb4785551f64e18b2c8bb15a3bd2b22f5ebf624d",
"versionType": "git"
},
{
"lessThan": "92d0de80ca2223b9c7da78020155b6cb27824cc0",
"status": "affected",
"version": "bb4785551f64e18b2c8bb15a3bd2b22f5ebf624d",
"versionType": "git"
},
{
"lessThan": "dfb17bf04a764462000f11258a7c06aa92d1f261",
"status": "affected",
"version": "bb4785551f64e18b2c8bb15a3bd2b22f5ebf624d",
"versionType": "git"
},
{
"lessThan": "9b3d5a6d952c38bbcf07f903cbeadefdb56b9bc9",
"status": "affected",
"version": "bb4785551f64e18b2c8bb15a3bd2b22f5ebf624d",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/can/usb/peak_usb/pcan_usb_core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.4"
},
{
"lessThan": "3.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.151",
"versionStartIncluding": "3.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.103",
"versionStartIncluding": "3.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.44",
"versionStartIncluding": "3.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.8",
"versionStartIncluding": "3.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: peak_usb: peak_usb_start(): fix double free of transfer buffer on URB submit error\n\nIn peak_usb_start(), each RX URB transfer buffer is allocated with kmalloc()\nand the URB is flagged URB_FREE_BUFFER so that the final usb_free_urb() also\nfrees the transfer buffer.\n\nIf usb_submit_urb() fails, the error path frees the buffer explicitly with\nkfree(buf) and then calls usb_free_urb(urb). Because URB_FREE_BUFFER is set,\nusb_free_urb() -\u003e urb_destroy() frees the same buffer a second time, a double\nfree of the transfer buffer.\n\n BUG: KASAN: double-free in usb_free_urb.part.0+0x91/0xb0\n Free of addr ffff8881069ccb80 by task trigger.sh/285\n\n Call Trace:\n kfree+0x113/0x3c0\n usb_free_urb.part.0+0x91/0xb0\n\nDrop the redundant kfree(buf); usb_free_urb() already releases the transfer\nbuffer. This mirrors commit 03819abbeb11 (\"net: usb: lan78xx: Fix double free\nissue with interrupt buffer allocation\")."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The flaw is only reached when a privileged local actor brings the PEAK CAN netdev up via rtnetlink/ioctl (peak_usb_ndo_open\u2192peak_usb_start); CAN-bus traffic and remote protocols never call this setup path, but the entry is a local syscall rather than USB packet processing.\nAC:L - Any usb_submit_urb() failure on RX setup deterministically hits the broken error path; an attacker can reliably force -ENODEV/-ENOENT by disconnecting/resetting the adapter or presenting a rogue PEAK-class gadget while repeatedly running ip link set canX up/down.\nPR:L - Bringing the CAN interface up requires CAP_NET_ADMIN on RTM_SETLINK (rtnl_setlink/netif_open), which is Low under CNA guidance; on automotive/industrial diagnostic hosts this is commonly held by technician/service accounts even though unauthenticated remote attackers cannot reach the path.\nUI:N - No separate victim interaction is needed beyond the attacker (or their malware) issuing the privileged link-up that enters peak_usb_start; they can also script repeated up/down cycles while manipulating USB state themselves.\nS:U - The double-free corrupts host kernel kmalloc slab state within the peak_usb driver scope and does not by itself cross a security boundary such as VM escape, container breakout, or IOMMU bypass.\nC:H - This is a kmalloc RX-buffer double-free with URB_FREE_BUFFER set; per CNA guidance such heap double-free/UAF-class bugs enable controlled reallocation and arbitrary kernel memory disclosure, not merely a bounded leak.\nI:H - Freeing the same 64\u20132048 byte RX slab object twice corrupts SLUB freelist/metadata and provides a standard heap corruption primitive that can be groomed into arbitrary kernel writes or control-flow hijacking.\nA:H - KASAN already reports a double-free in usb_free_urb() on this path; even without full exploitation, allocator corruption typically causes kernel BUG/oops/panic and repeated trigger cycles can deny CAN/USB service on shared diagnostic systems."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:36:51.237Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/914c3b8fa175acf8476ad31cf04e308638e3578e"
},
{
"url": "https://git.kernel.org/stable/c/5f2fa5840c34d3a558c57855781be75e03bef752"
},
{
"url": "https://git.kernel.org/stable/c/b9088d581fff971a7eb1628f8dcc30df6cfef4dc"
},
{
"url": "https://git.kernel.org/stable/c/525640b93d3e5f82f4ebea4730f4e0cf799522ba"
},
{
"url": "https://git.kernel.org/stable/c/4bb3325075138dd5346b71589a959878b564dc0b"
},
{
"url": "https://git.kernel.org/stable/c/92d0de80ca2223b9c7da78020155b6cb27824cc0"
},
{
"url": "https://git.kernel.org/stable/c/dfb17bf04a764462000f11258a7c06aa92d1f261"
},
{
"url": "https://git.kernel.org/stable/c/9b3d5a6d952c38bbcf07f903cbeadefdb56b9bc9"
}
],
"title": "can: peak_usb: peak_usb_start(): fix double free of transfer buffer on URB submit error",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74456",
"datePublished": "2026-08-15T12:26:58.808Z",
"dateReserved": "2026-08-15T05:44:03.900Z",
"dateUpdated": "2026-08-19T16:36:51.237Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74675 (GCVE-0-2026-74675)
Vulnerability from cvelistv5
Published
2026-08-22 15:32
Modified
2026-08-25 05:41
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
vt: stabilize tty reference in kbd_keycode with tty_port_tty_get
kbd_keycode() reads vc->port.tty without acquiring a tty reference,
racing against con_shutdown() which clears port.tty under a different
lock. Use tty_port_tty_get()/tty_kref_put() to hold a proper reference
for the duration the tty pointer is needed.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/tty/vt/keyboard.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "b84fd400f80adf4d1c88fbce50ae1cf2f8119e65",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "38400673c9bfb39cfc87539e1a072087e98f4e4f",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "cab5a342f0589334046741006d8a280514f94235",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "38a0aa593ebc275aea6f79534d07f44e43768ce6",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "3f6b1d3fcfc26dc3fc85262f753439df93b055b4",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "b664592e9ba8c47c9e23408db7ba52eb9f946c8a",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "cc4a1a2ce0c58eafd477effb055863935260ddc1",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
},
{
"lessThan": "e25d47a526939ad44b75f778b8a7500562b84fc1",
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/tty/vt/keyboard.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"lessThan": "2.6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.152",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.104",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.152",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.104",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.45",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.9",
"versionStartIncluding": "2.6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nvt: stabilize tty reference in kbd_keycode with tty_port_tty_get\n\nkbd_keycode() reads vc-\u003eport.tty without acquiring a tty reference,\nracing against con_shutdown() which clears port.tty under a different\nlock. Use tty_port_tty_get()/tty_kref_put() to hold a proper reference\nfor the duration the tty pointer is needed."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable code is reached only through local virtual-console and input paths: kbd_keycode runs from the VT keyboard input handler on key/key-repeat events while con_shutdown runs during final close(2) on /dev/ttyN; there is no network, Bluetooth-only, or remote-protocol reachability to both sides of the race.\nAC:L - The attacker controls both race participants: one thread can loop open/close a console tty to drive release_tty/con_shutdown while another holds a key for repeat events (down==2) or injects EV_KEY via uinput, retrying until kbd_keycode uses a freed tty_struct.\nPR:L - No real-root capability is required; a console-logged-in user with normal DAC access to /dev/ttyN (typical tty-group membership) can close their VT tty and generate foreground key events, and vt_ioctl grants perm to the controlling-tty owner without CAP_SYS_TTY_CONFIG.\nUI:N - The attacker performs every step from its own console session\u2014opening/closing the VT tty and generating key or key-repeat input\u2014so no separate victim or administrator action is required.\nS:U - The slab use-after-free corrupts kernel heap memory within the same kernel security authority; it does not cross a VM, IOMMU, or sandbox boundary.\nC:H - After the tty is freed, kbd_keycode reads freed tty_struct fields (termios for L_ECHO and optionally tty-\u003eops via tty_chars_in_buffer), giving a use-after-free read primitive and enabling disclosure of kernel memory once the slab object is reclaimed.\nI:H - The path writes tty-\u003edriver_data on a freed tty_struct and may indirect-call through tty-\u003eops in tty_chars_in_buffer, enabling heap spray and control-flow hijack for arbitrary kernel modification or privilege escalation.\nA:H - Use-after-free on tty_struct reliably produces kernel oops or panic on illegal dereference through freed memory, and the open/close versus key-repeat race can be retriggered at will for repeatable denial of service."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T05:41:27.811Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/b84fd400f80adf4d1c88fbce50ae1cf2f8119e65"
},
{
"url": "https://git.kernel.org/stable/c/38400673c9bfb39cfc87539e1a072087e98f4e4f"
},
{
"url": "https://git.kernel.org/stable/c/cab5a342f0589334046741006d8a280514f94235"
},
{
"url": "https://git.kernel.org/stable/c/38a0aa593ebc275aea6f79534d07f44e43768ce6"
},
{
"url": "https://git.kernel.org/stable/c/3f6b1d3fcfc26dc3fc85262f753439df93b055b4"
},
{
"url": "https://git.kernel.org/stable/c/b664592e9ba8c47c9e23408db7ba52eb9f946c8a"
},
{
"url": "https://git.kernel.org/stable/c/cc4a1a2ce0c58eafd477effb055863935260ddc1"
},
{
"url": "https://git.kernel.org/stable/c/e25d47a526939ad44b75f778b8a7500562b84fc1"
}
],
"title": "vt: stabilize tty reference in kbd_keycode with tty_port_tty_get",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74675",
"datePublished": "2026-08-22T15:32:44.493Z",
"dateReserved": "2026-08-15T05:44:03.925Z",
"dateUpdated": "2026-08-25T05:41:27.811Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80534 (GCVE-0-2026-80534)
Vulnerability from cvelistv5
Published
2026-08-26 14:37
Modified
2026-08-27 12:40
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
xfs: fix ilock leak on error in xfs_dq_get_next_id
xfs_dq_get_next_id() takes the quota inode ILOCK before calling
xfs_iread_extents(). If xfs_iread_extents() fails, the function returns
immediately without releasing the lock, leaking the quota inode ILOCK.
This can leave the quota inode locked and cause subsequent quota
operations to hang.
Fix this by jumping to a common unlock path on error instead of returning
directly.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: bda250dbaf39f67f8910e183853e4e6a9e5ce899 Version: bda250dbaf39f67f8910e183853e4e6a9e5ce899 Version: bda250dbaf39f67f8910e183853e4e6a9e5ce899 Version: bda250dbaf39f67f8910e183853e4e6a9e5ce899 Version: bda250dbaf39f67f8910e183853e4e6a9e5ce899 Version: bda250dbaf39f67f8910e183853e4e6a9e5ce899 Version: bda250dbaf39f67f8910e183853e4e6a9e5ce899 Version: bda250dbaf39f67f8910e183853e4e6a9e5ce899 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/xfs/xfs_dquot.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "e4c05ebd01e910bccd4f7e9517c7353982e27763",
"status": "affected",
"version": "bda250dbaf39f67f8910e183853e4e6a9e5ce899",
"versionType": "git"
},
{
"lessThan": "6401b99a285cd4cfb2949ba44675541b91ad7e4f",
"status": "affected",
"version": "bda250dbaf39f67f8910e183853e4e6a9e5ce899",
"versionType": "git"
},
{
"lessThan": "0865e4fca02e418fd2423fae9a887dee87b778a1",
"status": "affected",
"version": "bda250dbaf39f67f8910e183853e4e6a9e5ce899",
"versionType": "git"
},
{
"lessThan": "ed8bfb43de71213cfdbbe833b2c2817250e18b1a",
"status": "affected",
"version": "bda250dbaf39f67f8910e183853e4e6a9e5ce899",
"versionType": "git"
},
{
"lessThan": "e270d539b8a2e0cb8f617fee47a7b083c0088361",
"status": "affected",
"version": "bda250dbaf39f67f8910e183853e4e6a9e5ce899",
"versionType": "git"
},
{
"lessThan": "514a5d42d4188fc5f1499a8d654c717ebf981193",
"status": "affected",
"version": "bda250dbaf39f67f8910e183853e4e6a9e5ce899",
"versionType": "git"
},
{
"lessThan": "08bed2b67d2ee79d3e138c344d8dcfa4c9b26a38",
"status": "affected",
"version": "bda250dbaf39f67f8910e183853e4e6a9e5ce899",
"versionType": "git"
},
{
"lessThan": "63320a0f70f66f311f4bccff3af0719c2119f46c",
"status": "affected",
"version": "bda250dbaf39f67f8910e183853e4e6a9e5ce899",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/xfs/xfs_dquot.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.13"
},
{
"lessThan": "4.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.267",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.267",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.46",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.10",
"versionStartIncluding": "4.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nxfs: fix ilock leak on error in xfs_dq_get_next_id\n\nxfs_dq_get_next_id() takes the quota inode ILOCK before calling\nxfs_iread_extents(). If xfs_iread_extents() fails, the function returns\nimmediately without releasing the lock, leaking the quota inode ILOCK.\nThis can leave the quota inode locked and cause subsequent quota\noperations to hang.\n\nFix this by jumping to a common unlock path on error instead of returning\ndirectly."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T12:40:03.205Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/e4c05ebd01e910bccd4f7e9517c7353982e27763"
},
{
"url": "https://git.kernel.org/stable/c/6401b99a285cd4cfb2949ba44675541b91ad7e4f"
},
{
"url": "https://git.kernel.org/stable/c/0865e4fca02e418fd2423fae9a887dee87b778a1"
},
{
"url": "https://git.kernel.org/stable/c/ed8bfb43de71213cfdbbe833b2c2817250e18b1a"
},
{
"url": "https://git.kernel.org/stable/c/e270d539b8a2e0cb8f617fee47a7b083c0088361"
},
{
"url": "https://git.kernel.org/stable/c/514a5d42d4188fc5f1499a8d654c717ebf981193"
},
{
"url": "https://git.kernel.org/stable/c/08bed2b67d2ee79d3e138c344d8dcfa4c9b26a38"
},
{
"url": "https://git.kernel.org/stable/c/63320a0f70f66f311f4bccff3af0719c2119f46c"
}
],
"title": "xfs: fix ilock leak on error in xfs_dq_get_next_id",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80534",
"datePublished": "2026-08-26T14:37:10.378Z",
"dateReserved": "2026-08-26T14:34:25.764Z",
"dateUpdated": "2026-08-27T12:40:03.205Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68480 (GCVE-0-2026-68480)
Vulnerability from cvelistv5
Published
2026-08-06 17:36
Modified
2026-08-18 06:56
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
x86/bugs: Make Safe-RET robust against interrupt injection
An attacker injecting interrupts while the Safe-RET mitigation executes
on machines affected by SRSO can neutralize the safe return sequence,
potentially leading to data leakage through speculative execution.
Fixup register state as if the Safe-RET sequence executed successfully
by "emulating" it, in a manner of speaking, and avoid executing a RET
instruction after returning from the interrupt.
References
| URL | Tags | ||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 3f9b7101bea1dcb63410c016ceb266f6e9f733c9 Version: b35087763a44d1eb45857f799579a351332be505 Version: ac41e90d8daa8815d8bee774a1975435fbfe1ae7 Version: fb3bd914b3ec28f5fb697ac55c4846ac2d542855 Version: fb3bd914b3ec28f5fb697ac55c4846ac2d542855 Version: fb3bd914b3ec28f5fb697ac55c4846ac2d542855 Version: fb3bd914b3ec28f5fb697ac55c4846ac2d542855 Version: fb3bd914b3ec28f5fb697ac55c4846ac2d542855 Version: acdc883eb61efbe01b954e782e1124790bd391a8 Version: 5.10.189 ≤ Version: 5.15.125 ≤ Version: 6.1.44 ≤ Version: 6.4.9 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"arch/x86/entry/entry_64.S",
"arch/x86/include/asm/nospec-branch.h",
"arch/x86/kernel/cpu/bugs.c",
"arch/x86/lib/retpoline.S"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "dfefa3c51370f84acb643cddf98bb42c885d0483",
"status": "affected",
"version": "3f9b7101bea1dcb63410c016ceb266f6e9f733c9",
"versionType": "git"
},
{
"lessThan": "52db77a13be224e09eb4ba6b4252ae8ab9085c2c",
"status": "affected",
"version": "b35087763a44d1eb45857f799579a351332be505",
"versionType": "git"
},
{
"lessThan": "d0208e08d64d99383e09852a76cc3038c5a4c3ab",
"status": "affected",
"version": "ac41e90d8daa8815d8bee774a1975435fbfe1ae7",
"versionType": "git"
},
{
"lessThan": "6703dba1d14cbd6647cd1ccfa3a3fa94b64dd096",
"status": "affected",
"version": "fb3bd914b3ec28f5fb697ac55c4846ac2d542855",
"versionType": "git"
},
{
"lessThan": "e262f28a69ae9e0791248f93b0173c1d1f3e1d5d",
"status": "affected",
"version": "fb3bd914b3ec28f5fb697ac55c4846ac2d542855",
"versionType": "git"
},
{
"lessThan": "bfe7f9993467ba431b2731437949ac1e2634e771",
"status": "affected",
"version": "fb3bd914b3ec28f5fb697ac55c4846ac2d542855",
"versionType": "git"
},
{
"lessThan": "61649a2d61cb0dbc673f0f232f0f0c298bf50442",
"status": "affected",
"version": "fb3bd914b3ec28f5fb697ac55c4846ac2d542855",
"versionType": "git"
},
{
"lessThan": "7e7f81cf6f5ca3311e526308f55d7c54d3ba71f9",
"status": "affected",
"version": "fb3bd914b3ec28f5fb697ac55c4846ac2d542855",
"versionType": "git"
},
{
"status": "affected",
"version": "acdc883eb61efbe01b954e782e1124790bd391a8",
"versionType": "git"
},
{
"lessThan": "5.10.264",
"status": "affected",
"version": "5.10.189",
"versionType": "semver"
},
{
"lessThan": "5.15.215",
"status": "affected",
"version": "5.15.125",
"versionType": "semver"
},
{
"lessThan": "6.1.182",
"status": "affected",
"version": "6.1.44",
"versionType": "semver"
},
{
"lessThan": "6.5",
"status": "affected",
"version": "6.4.9",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"arch/x86/entry/entry_64.S",
"arch/x86/include/asm/nospec-branch.h",
"arch/x86/kernel/cpu/bugs.c",
"arch/x86/lib/retpoline.S"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.5"
},
{
"lessThan": "6.5",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.264",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.215",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.182",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.150",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.102",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.43",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.7",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.264",
"versionStartIncluding": "5.10.189",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.215",
"versionStartIncluding": "5.15.125",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.182",
"versionStartIncluding": "6.1.44",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.150",
"versionStartIncluding": "6.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.102",
"versionStartIncluding": "6.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.43",
"versionStartIncluding": "6.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.7",
"versionStartIncluding": "6.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.4.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/bugs: Make Safe-RET robust against interrupt injection\n\nAn attacker injecting interrupts while the Safe-RET mitigation executes\non machines affected by SRSO can neutralize the safe return sequence,\npotentially leading to data leakage through speculative execution.\n\nFixup register state as if the Safe-RET sequence executed successfully\nby \"emulating\" it, in a manner of speaking, and avoid executing a RET\ninstruction after returning from the interrupt."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-18T06:56:07.999Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/dfefa3c51370f84acb643cddf98bb42c885d0483"
},
{
"url": "https://git.kernel.org/stable/c/52db77a13be224e09eb4ba6b4252ae8ab9085c2c"
},
{
"url": "https://git.kernel.org/stable/c/d0208e08d64d99383e09852a76cc3038c5a4c3ab"
},
{
"url": "https://git.kernel.org/stable/c/6703dba1d14cbd6647cd1ccfa3a3fa94b64dd096"
},
{
"url": "https://git.kernel.org/stable/c/e262f28a69ae9e0791248f93b0173c1d1f3e1d5d"
},
{
"url": "https://git.kernel.org/stable/c/bfe7f9993467ba431b2731437949ac1e2634e771"
},
{
"url": "https://git.kernel.org/stable/c/61649a2d61cb0dbc673f0f232f0f0c298bf50442"
},
{
"url": "https://git.kernel.org/stable/c/7e7f81cf6f5ca3311e526308f55d7c54d3ba71f9"
},
{
"url": "https://people.csail.mit.edu/mengjia/data/2026.USENIX.TONTOU.pdf"
}
],
"title": "x86/bugs: Make Safe-RET robust against interrupt injection",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68480",
"datePublished": "2026-08-06T17:36:43.654Z",
"dateReserved": "2026-07-30T09:28:09.397Z",
"dateUpdated": "2026-08-18T06:56:07.999Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-72142 (GCVE-0-2026-72142)
Vulnerability from cvelistv5
Published
2026-08-15 05:53
Modified
2026-08-23 12:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
i2c: imx: fix locked bus on SMBus block-read of 0 (atomic)
SMBus 3.1 6.5.7 allows a Block Read byte count of 0, but the atomic
(polling) path rejects it as -EPROTO. Worse, it returns without a
NACK+STOP: the next receive cycle has already started, so the target
keeps holding SDA and the bus stays stuck until a power cycle for
this i2c controller.
Reading I2DR to obtain the count likewise arms the next byte on the
count > I2C_SMBUS_BLOCK_MAX path, which also returned -EPROTO directly
and left the bus held.
Handle both: NACK the in-flight dummy byte (TXAK) and extend msgs->len so
the existing last-byte handling emits STOP; the dummy byte is discarded.
A count of 0 is a valid empty block read; a count above
I2C_SMBUS_BLOCK_MAX is still reported as -EPROTO, but only after the bus
has been released.
The interrupt-driven path has the same flaw from a later commit and is
fixed separately, as it carries a different Fixes: tag and stable range.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 8e8782c71595a5ad29e234ce6b3d2fce787fb07a Version: 8e8782c71595a5ad29e234ce6b3d2fce787fb07a Version: 8e8782c71595a5ad29e234ce6b3d2fce787fb07a Version: 8e8782c71595a5ad29e234ce6b3d2fce787fb07a Version: 8e8782c71595a5ad29e234ce6b3d2fce787fb07a Version: 8e8782c71595a5ad29e234ce6b3d2fce787fb07a Version: 8e8782c71595a5ad29e234ce6b3d2fce787fb07a Version: 8e8782c71595a5ad29e234ce6b3d2fce787fb07a |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/i2c/busses/i2c-imx.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "0f29df3c3d607a9dbc14aed0e45504ced4d2e7ec",
"status": "affected",
"version": "8e8782c71595a5ad29e234ce6b3d2fce787fb07a",
"versionType": "git"
},
{
"lessThan": "38d4947431b2410850409fda016b2ac9f640a4dd",
"status": "affected",
"version": "8e8782c71595a5ad29e234ce6b3d2fce787fb07a",
"versionType": "git"
},
{
"lessThan": "e3e8b02d4773cfc5ad561d2e5505efde36c6927a",
"status": "affected",
"version": "8e8782c71595a5ad29e234ce6b3d2fce787fb07a",
"versionType": "git"
},
{
"lessThan": "016ef0f6ca4bc9bf0330ac41bd2ea349759643e3",
"status": "affected",
"version": "8e8782c71595a5ad29e234ce6b3d2fce787fb07a",
"versionType": "git"
},
{
"lessThan": "c882e8cc68fb993700dc21fd6e754001e6297934",
"status": "affected",
"version": "8e8782c71595a5ad29e234ce6b3d2fce787fb07a",
"versionType": "git"
},
{
"lessThan": "6d2c973926d0612360693bc559be2ffde836151b",
"status": "affected",
"version": "8e8782c71595a5ad29e234ce6b3d2fce787fb07a",
"versionType": "git"
},
{
"lessThan": "60ed00d46616a9232e42ea7a3e3c0273d7cf7543",
"status": "affected",
"version": "8e8782c71595a5ad29e234ce6b3d2fce787fb07a",
"versionType": "git"
},
{
"lessThan": "cb2fc37857693b55909fb77dc2c87cfbc1cdc476",
"status": "affected",
"version": "8e8782c71595a5ad29e234ce6b3d2fce787fb07a",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/i2c/busses/i2c-imx.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.16"
},
{
"lessThan": "3.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.16",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: imx: fix locked bus on SMBus block-read of 0 (atomic)\n\nSMBus 3.1 6.5.7 allows a Block Read byte count of 0, but the atomic\n(polling) path rejects it as -EPROTO. Worse, it returns without a\nNACK+STOP: the next receive cycle has already started, so the target\nkeeps holding SDA and the bus stays stuck until a power cycle for\nthis i2c controller.\n\nReading I2DR to obtain the count likewise arms the next byte on the\ncount \u003e I2C_SMBUS_BLOCK_MAX path, which also returned -EPROTO directly\nand left the bus held.\n\nHandle both: NACK the in-flight dummy byte (TXAK) and extend msgs-\u003elen so\nthe existing last-byte handling emits STOP; the dummy byte is discarded.\nA count of 0 is a valid empty block read; a count above\nI2C_SMBUS_BLOCK_MAX is still reported as -EPROTO, but only after the bus\nhas been released.\n\nThe interrupt-driven path has the same flaw from a later commit and is\nfixed separately, as it carries a different Fixes: tag and stable range."
}
],
"providerMetadata": {
"dateUpdated": "2026-08-23T12:46:51.665Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/0f29df3c3d607a9dbc14aed0e45504ced4d2e7ec"
},
{
"url": "https://git.kernel.org/stable/c/38d4947431b2410850409fda016b2ac9f640a4dd"
},
{
"url": "https://git.kernel.org/stable/c/e3e8b02d4773cfc5ad561d2e5505efde36c6927a"
},
{
"url": "https://git.kernel.org/stable/c/016ef0f6ca4bc9bf0330ac41bd2ea349759643e3"
},
{
"url": "https://git.kernel.org/stable/c/c882e8cc68fb993700dc21fd6e754001e6297934"
},
{
"url": "https://git.kernel.org/stable/c/6d2c973926d0612360693bc559be2ffde836151b"
},
{
"url": "https://git.kernel.org/stable/c/60ed00d46616a9232e42ea7a3e3c0273d7cf7543"
},
{
"url": "https://git.kernel.org/stable/c/cb2fc37857693b55909fb77dc2c87cfbc1cdc476"
}
],
"title": "i2c: imx: fix locked bus on SMBus block-read of 0 (atomic)",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-72142",
"datePublished": "2026-08-15T05:53:15.489Z",
"dateReserved": "2026-08-09T03:40:39.908Z",
"dateUpdated": "2026-08-23T12:46:51.665Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80559 (GCVE-0-2026-80559)
Vulnerability from cvelistv5
Published
2026-08-26 14:37
Modified
2026-08-27 05:01
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
Input: sur40 - fix input device registration ordering
In sur40_probe(), input_register_device() was previously called early before
the V4L2 video device and vb2_queue components were fully initialized. If
userspace opened the input device immediately upon registration, sur40_open()
would trigger and start the sur40_poll() worker thread. This worker thread
invokes sur40_process_video() and accesses the uninitialized vb2_queue
structure, leading to a data race and potential system crash.
Furthermore, if V4L2 or video registration failed after input_register_device()
succeeded, the error path fell through to calling input_free_device() on a
successfully registered device instead of input_unregister_device(), corrupting
input core state.
Move input_register_device() to the very end of sur40_probe(). This ensures
the V4L2 and video queue structures are fully initialized before polling can
start, and naturally resolves the error path bug since input_free_device()
is now only called when input registration has not yet occurred.
To maintain strict LIFO (Last-In, First-Out) teardown ordering, also move
input_unregister_device() to the very beginning of sur40_disconnect(). This
guarantees that the input polling worker thread is stopped before V4L2
video components or control handlers are unregistered.
References
| URL | Tags | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: e831cd251fb91d6c25352d322743db0d17ea11dd Version: e831cd251fb91d6c25352d322743db0d17ea11dd Version: e831cd251fb91d6c25352d322743db0d17ea11dd Version: e831cd251fb91d6c25352d322743db0d17ea11dd Version: e831cd251fb91d6c25352d322743db0d17ea11dd Version: e831cd251fb91d6c25352d322743db0d17ea11dd Version: e831cd251fb91d6c25352d322743db0d17ea11dd Version: e831cd251fb91d6c25352d322743db0d17ea11dd |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/input/touchscreen/sur40.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "cd4ecce2fd87760c0ad9a9d28c9fc62ea1dbfd3d",
"status": "affected",
"version": "e831cd251fb91d6c25352d322743db0d17ea11dd",
"versionType": "git"
},
{
"lessThan": "dab741c9da72102a37cc1020a929051b7c45f9fb",
"status": "affected",
"version": "e831cd251fb91d6c25352d322743db0d17ea11dd",
"versionType": "git"
},
{
"lessThan": "764b507be7b51787e1f577ca3bf0bab7efe81ff8",
"status": "affected",
"version": "e831cd251fb91d6c25352d322743db0d17ea11dd",
"versionType": "git"
},
{
"lessThan": "3e8ed76a4f3572e637653f0654cccdf617903231",
"status": "affected",
"version": "e831cd251fb91d6c25352d322743db0d17ea11dd",
"versionType": "git"
},
{
"lessThan": "83aa12f9f2468a4fbef027c09224dc1011850fb0",
"status": "affected",
"version": "e831cd251fb91d6c25352d322743db0d17ea11dd",
"versionType": "git"
},
{
"lessThan": "5c1c5227c93f18cd329dd754b4df5e0e2daece1e",
"status": "affected",
"version": "e831cd251fb91d6c25352d322743db0d17ea11dd",
"versionType": "git"
},
{
"lessThan": "beb9b0bd6e6e23f5e9e42b7ef890a50f57f1f3aa",
"status": "affected",
"version": "e831cd251fb91d6c25352d322743db0d17ea11dd",
"versionType": "git"
},
{
"lessThan": "9da976eb649c9e2f588a4499410e4d8af687925f",
"status": "affected",
"version": "e831cd251fb91d6c25352d322743db0d17ea11dd",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/input/touchscreen/sur40.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.1"
},
{
"lessThan": "4.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.46",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.10",
"versionStartIncluding": "4.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nInput: sur40 - fix input device registration ordering\n\nIn sur40_probe(), input_register_device() was previously called early before\nthe V4L2 video device and vb2_queue components were fully initialized. If\nuserspace opened the input device immediately upon registration, sur40_open()\nwould trigger and start the sur40_poll() worker thread. This worker thread\ninvokes sur40_process_video() and accesses the uninitialized vb2_queue\nstructure, leading to a data race and potential system crash.\n\nFurthermore, if V4L2 or video registration failed after input_register_device()\nsucceeded, the error path fell through to calling input_free_device() on a\nsuccessfully registered device instead of input_unregister_device(), corrupting\ninput core state.\n\nMove input_register_device() to the very end of sur40_probe(). This ensures\nthe V4L2 and video queue structures are fully initialized before polling can\nstart, and naturally resolves the error path bug since input_free_device()\nis now only called when input registration has not yet occurred.\n\nTo maintain strict LIFO (Last-In, First-Out) teardown ordering, also move\ninput_unregister_device() to the very beginning of sur40_disconnect(). This\nguarantees that the input polling worker thread is stopped before V4L2\nvideo components or control handlers are unregistered."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation is via open() on /dev/input/eventX (evdev -\u003e input_open_device -\u003e sur40_open -\u003e sur40_poll -\u003e sur40_process_video) racing sur40_probe() before vb2_queue_init(); on permanently installed PixelSense/SUR40 kiosk tables no physical USB access is needed at attack time.\nAC:L - The attacker controls both sides of the race by monitoring udev/inotify for the new input node and immediately opening it during USB hotplug or reboot probe; polling starts synchronously in input_dev_poller_start, making the uninitialized vb2_queue access reliably triggerable without uncontrollable kernel preconditions.\nPR:L - Triggering sur40_open requires only local userspace access to the evdev node (typically membership in the input group or equivalent kiosk-app privileges opening /dev/input/event*), not real root in the init namespace; user namespaces cannot substitute for this device access.\nUI:N - No victim interaction is required beyond the attacker\u0027s own actions; they can open the input device themselves (or rely on an auto-opening compositor during reconnect) and time the race during probe without needing another user to touch the screen or perform any action.\nS:U - Impact is confined to kernel memory corruption and crashes within the host input/USB driver context on the same system; it does not cross VM, container, or IOMMU security boundaries despite potential local privilege escalation as a follow-on.\nC:H - Concurrent access to a partially initialized vb2_queue is a kernel data race that can read uninitialized queue state, and the probe error path calls input_free_device() on a registered device, corrupting input-core linked lists\u2014both are memory-corruption primitives leverageable for kernel information disclosure.\nI:H - The input_free_device() misuse corrupts global input-core list state (definite kernel structure corruption), and racing poll against vb2_queue_init can invoke vb2_buffer_done and list operations on uninitialized queue internals, enabling exploitable heap/control-structure writes.\nA:H - The fix commit explicitly cites a data race on the uninitialized vb2_queue leading to system crash; corrupting input-core registration state or racing teardown during USB disconnect can cause kernel oops/panic and deny service on interactive SUR40/PixelSense deployments."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T05:01:47.768Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/cd4ecce2fd87760c0ad9a9d28c9fc62ea1dbfd3d"
},
{
"url": "https://git.kernel.org/stable/c/dab741c9da72102a37cc1020a929051b7c45f9fb"
},
{
"url": "https://git.kernel.org/stable/c/764b507be7b51787e1f577ca3bf0bab7efe81ff8"
},
{
"url": "https://git.kernel.org/stable/c/3e8ed76a4f3572e637653f0654cccdf617903231"
},
{
"url": "https://git.kernel.org/stable/c/83aa12f9f2468a4fbef027c09224dc1011850fb0"
},
{
"url": "https://git.kernel.org/stable/c/5c1c5227c93f18cd329dd754b4df5e0e2daece1e"
},
{
"url": "https://git.kernel.org/stable/c/beb9b0bd6e6e23f5e9e42b7ef890a50f57f1f3aa"
},
{
"url": "https://git.kernel.org/stable/c/9da976eb649c9e2f588a4499410e4d8af687925f"
}
],
"title": "Input: sur40 - fix input device registration ordering",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80559",
"datePublished": "2026-08-26T14:37:25.371Z",
"dateReserved": "2026-08-26T14:34:25.767Z",
"dateUpdated": "2026-08-27T05:01:47.768Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
Loading…
Loading…
Sightings
| Author | Source | Type | Date |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…