* CVE-2026-72181: mips: sched: Fix CPUMASK_OFFSTACK memory corruption
@ 2026-08-15 6:04 Greg Kroah-Hartman
0 siblings, 0 replies; only message in thread
From: Greg Kroah-Hartman @ 2026-08-15 6:04 UTC (permalink / raw)
To: linux-cve-announce; +Cc: Greg Kroah-Hartman
From: Greg Kroah-Hartman <gregkh@kernel.org>
Description
===========
In the Linux kernel, the following vulnerability has been resolved:
mips: sched: Fix CPUMASK_OFFSTACK memory corruption
This patch addresses a critical memory management flaw. When
CONFIG_CPUMASK_OFFSTACK is enabled, cpumask_var_t is a pointer.
Consequently, sizeof(new_mask) evaluates to the pointer size, causing
copy_from_user() to clobber the mask pointer. Furthermore, the old
logic performed copy_from_user() before allocating the mask.
Fix this by allocating new_mask first. To handle variable-sized user
masks correctly, use cpumask_size() to truncate overly large user masks
or pad undersized masks with zeros before copying the data directly into
the allocated buffer.
The Linux kernel CVE team has assigned CVE-2026-72181 to this issue.
Affected and fixed versions
===========================
Issue introduced in 2.6.23 with commit 295cbf6d63165fe4253cf1d9ceadcda47a318b48 and fixed in 5.15.212 with commit d20ee42f8226607b5693b2bc2f115ca2d270221a
Issue introduced in 2.6.23 with commit 295cbf6d63165fe4253cf1d9ceadcda47a318b48 and fixed in 6.1.178 with commit 15ba8053fe4162c933855f1676fb321cdb6251c7
Issue introduced in 2.6.23 with commit 295cbf6d63165fe4253cf1d9ceadcda47a318b48 and fixed in 6.6.145 with commit 3446ffb5d03c36f9ce88ede7ca5be319a2968d96
Issue introduced in 2.6.23 with commit 295cbf6d63165fe4253cf1d9ceadcda47a318b48 and fixed in 6.12.97 with commit 87a56c1e8e36d06ebe8640432f911538ded7827d
Issue introduced in 2.6.23 with commit 295cbf6d63165fe4253cf1d9ceadcda47a318b48 and fixed in 6.18.40 with commit 1caee6e084a96ada94658f261ced377d85af3f03
Issue introduced in 2.6.23 with commit 295cbf6d63165fe4253cf1d9ceadcda47a318b48 and fixed in 7.1.5 with commit a1dd41d00c57efb1fbc6f361c5f48c9d00cca51c
Issue introduced in 2.6.23 with commit 295cbf6d63165fe4253cf1d9ceadcda47a318b48 and fixed in 7.2-rc1 with commit 98e37db4a34d3af3fb2f4648295c25b5e40b20e3
Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.
Unaffected versions might change over time as fixes are backported to
older supported kernel versions. The official CVE entry at
https://cve.org/CVERecord/?id=CVE-2026-72181
will be updated if fixes are backported, please check that for the most
up to date information about this issue.
Affected files
==============
The file(s) affected by this issue are:
arch/mips/kernel/mips-mt-fpaff.c
Mitigation
==========
The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes. Individual
changes are never tested alone, but rather are part of a larger kernel
release. Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all. If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
https://git.kernel.org/stable/c/d20ee42f8226607b5693b2bc2f115ca2d270221a
https://git.kernel.org/stable/c/15ba8053fe4162c933855f1676fb321cdb6251c7
https://git.kernel.org/stable/c/3446ffb5d03c36f9ce88ede7ca5be319a2968d96
https://git.kernel.org/stable/c/87a56c1e8e36d06ebe8640432f911538ded7827d
https://git.kernel.org/stable/c/1caee6e084a96ada94658f261ced377d85af3f03
https://git.kernel.org/stable/c/a1dd41d00c57efb1fbc6f361c5f48c9d00cca51c
https://git.kernel.org/stable/c/98e37db4a34d3af3fb2f4648295c25b5e40b20e3
^ permalink raw reply [flat|nested] only message in thread
only message in thread, other threads:[~2026-08-15 6:15 UTC | newest]
Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-15 6:04 CVE-2026-72181: mips: sched: Fix CPUMASK_OFFSTACK memory corruption Greg Kroah-Hartman
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.