From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 0B10B366566 for ; Sat, 15 Aug 2026 06:18:23 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786774704; cv=none; b=GxZ5bHjIVU3sd2eBsQfk9cms5SsjeXBdMvE0mECYrWJMocTjTFmnOVajyBjQpXercHMT5j7A/ubd40u+IZK55BbyvTfh3uSIRclokvE7mThAczeOvV7o7DF/wsYsFzo1hcXkgWAakFNy6B1My9sjfll9dAfyhqpKgsHJX+xj5HM= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786774704; c=relaxed/simple; bh=ICka7vk1gOl8RtHCcYMJ7rLosHGLJZUICo8Fh0i7qcs=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=oxSsPXtw5STEexcLCLBmh6ImLI7wzl+W1csdOAk0izHH67K8tELyW3gGCQmSB83ltkeza0OlssFz8K5BgzwCYVJuSCUo1IKw2FF/fj16ko9Hi/Bs1IhKEjv2xbG0Z4QpwUmHS3bti6HVTn8h1x+B2FIir6jqtYY9ONRgLmkMmnw= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=XiJ4EIKJ; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="XiJ4EIKJ" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 606701F000E9; Sat, 15 Aug 2026 06:18:22 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1786774702; bh=if3jna5GRcBAMudgFNgN+Vh8Yl3JYN0GSGSDGCYNBhE=; h=From:To:Cc:Subject:Date:Reply-To; b=XiJ4EIKJiPuoNy4Vrc3alCXK1gZKWugbZU3oGrU4H32gXZ8OL9koQV8obn3eu8rY6 H+SF3e3JMG6OiWei1CC046D2HQjZBpY+HPjEu1bR7+W6UGZX6CpBebpdsAFpiZ5wK4 QjjJsMW5Y3wc3NPfEtOyzScnNFUrcOucWGV3ihaU= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-72244: gpu/buddy: bail out of try_harder when alignment cannot be honoured Date: Sat, 15 Aug 2026 15:05:23 +0900 Message-ID: <2026081551-CVE-2026-72244-983d@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=2751; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=XJ9XMq5e9IcikBmNK9kyb5WDJpTqsufkWVVpAu6fm3E=; b=owGbwMvMwCRo6H6F97bub03G02pJDFkNDBfCfpgkfz/Ka2VzpTx9adGeSQX/uiOWn6iIKH2b+ yrdY39dRywLgyATg6yYIsuXbTxH91ccUvQytD0NM4eVCWQIAxenAExEbgLDgrX7Zb2tO+bZ9d5u NtBJPL7V0ebVAoYFmzKDYqQ7VUr952xkF1gm/vCco9gfAA== X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: gpu/buddy: bail out of try_harder when alignment cannot be honoured The try_harder contiguous fallback could return a range whose start offset did not match the caller's min_block_size. When a candidate's start is misaligned, realign it: free the misaligned run and reallocate exactly @size at the next lower min_block_size boundary. This keeps the returned size unchanged with no surplus to trim, and rejects the request only when no aligned candidate fits. v2: align misaligned candidates down to min_block_size instead of bailing out, for both the RHS and LHS paths (Matthew). The Linux kernel CVE team has assigned CVE-2026-72244 to this issue. Affected and fixed versions =========================== Issue introduced in 6.7 with commit 0a1844bf0b532d84324453374ad6845f64066c28 and fixed in 6.12.101 with commit 4289531106ee175a6eb45db7d4f2734d1dae9887 Issue introduced in 6.7 with commit 0a1844bf0b532d84324453374ad6845f64066c28 and fixed in 6.18.42 with commit 7185c5262435b93e5eeffa647008992256b9c51a Issue introduced in 6.7 with commit 0a1844bf0b532d84324453374ad6845f64066c28 and fixed in 7.1.5 with commit 419d7d9306491f3e0e417cf794844c73cabee090 Issue introduced in 6.7 with commit 0a1844bf0b532d84324453374ad6845f64066c28 and fixed in 7.2-rc3 with commit 56bc6384314fb9ae98975fb2af8b143097ede3dc Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-72244 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: drivers/gpu/buddy.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/4289531106ee175a6eb45db7d4f2734d1dae9887 https://git.kernel.org/stable/c/7185c5262435b93e5eeffa647008992256b9c51a https://git.kernel.org/stable/c/419d7d9306491f3e0e417cf794844c73cabee090 https://git.kernel.org/stable/c/56bc6384314fb9ae98975fb2af8b143097ede3dc