From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8FE42511202 for ; Fri, 4 Sep 2026 16:49:12 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788540553; cv=none; b=LQ3Z96Se/zmR1j2J/A5pJO+DKzUW9/vKAu8dEFiVSLNsLbIIZW6vJUPPAsBvc+lEa0XIakn0sf5r2bAU2ft54+FqrckpqnpEwvz4+gJFhYVSDQQalaYb/azZ9Zj0cIv/eGSjHAYsus2gDIT1G/td8FZFEkYJptqar6PTH5s2XYE= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788540553; c=relaxed/simple; bh=7NfOhFNj9G3UUfBn7ORM2YzCpZZ6AeFZvY5qA0OcWWM=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=kbFgz1lQoHxkrSl1n95RFXcRTxJf31XduBBYPsLV5CmlwuKaJqGprLpPKjKtaQLuzFuS29m+B/S3LW3IGPdPyxbtWhSSJ/+5r1llf6q6qmtv6wELF4wYCl1viOu+ZLK0XqhNybR2xxnqAhYA3PBxEDGLiLWHShM7K9dXB4DpaFs= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=TieDY7p9; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="TieDY7p9" Received: by smtp.kernel.org (Postfix) with ESMTPSA id A19471F00A3D; Fri, 4 Sep 2026 16:49:10 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1788540552; bh=4hYk3FI1Yhv1rw4ZlnDHYAQVpwFHsM9hw7diK8DbZiU=; h=From:To:Cc:Subject:Date:Reply-To; b=TieDY7p9m7FLA/6pEsba+FPSkmblXObye8Hn7nttexwRRan94u4/I1crpAUSU0LmZ UYtuPYLJ+Lj1REtv3I1Ek8oZQTHfRe6PsGjyfyu59qpj3NhDPj/Q9qji1NnN3jbkVr D2YHpwdJaqJfE8FS/WBKfETUIRQGxHkGKYjuer6Q= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-80876: ring-buffer: Fix event length with forced 8-byte alignment Date: Fri, 4 Sep 2026 18:46:43 +0200 Message-ID: <2026090435-CVE-2026-80876-8d4a@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=4574; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=4yStbBQ9YH7nfnSak2QK4a6k9bURHp/PPL9FqJ0VqOY=; b=owGbwMvMwCRo6H6F97bub03G02pJDFmzvr4Jml9fo8k0Z0PTRFaRa21hd8zfWl+Mby2dyuFQt VxFa86bjlgWBkEmBlkxRZYv23iO7q84pOhlaHsaZg4rE8gQBi5OAZhIsgDDgrWB9gu/vr4fZJqX MpNvd+NZKZm3exnmh2+NXZR48Et054v+lk9Vdc3tv/NDAA== X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Fix event length with forced 8-byte alignment When RB_FORCE_8BYTE_ALIGNMENT is true, rb_calculate_event_length() reserves the space of event->array[0] for placing the data length and rb_update_event() stores the data length in event->array[0] accordingly. As a result the whole event length will add extra 4 bytes for sizeof(event.array[0]) unconditionally. But ring_buffer_event_length() only subtracts the sizeof(event->array[0]) for events larger than RB_MAX_SMALL_DATA + sizeof(event->array[0]). As a result, small events on architectures with RB_FORCE_8BYTE_ALIGNMENT=true report a data length that is 4 bytes larger than expected. To fix it, add the RB_FORCE_8BYTE_ALIGNMENT as a condition to subtract the size of that length field whenever RB_FORCE_8BYTE_ALIGNMENT is true. This issue is observed in a riscv64 kernel with CONFIG_HAVE_64BIT_ALIGNED_ACCESS set to y, when we run ftrace selftest trace_marker_raw.tc, we get the weird log: for cases where the id is 1..100, the number of data field is 8*N, but once id exceeds 100, the number of data field becomes 8*N+4: # 1 buf: 58 00 00 00 80 5e d1 63 (number of data field is 8*1) ... # a buf: 58 ... (number of data field is 8*2) ... # 64 buf: 58 ... (number of data field is 8*13) # 65 buf: 58 ... (number of data field is 8*13+4) After applying this change, the number of data field keeps being 8*N+4 consistently. The Linux kernel CVE team has assigned CVE-2026-80876 to this issue. Affected and fixed versions =========================== Issue introduced in 2.6.34 with commit 2271048d1b3b0aabf83d25b29c20646dcabedc05 and fixed in 5.10.261 with commit 7c9f0ccf9f04142458d2ac3d39414f4acae242f0 Issue introduced in 2.6.34 with commit 2271048d1b3b0aabf83d25b29c20646dcabedc05 and fixed in 5.15.212 with commit 24c3fa71f9947b0e1f3b954db1b769b44140192e Issue introduced in 2.6.34 with commit 2271048d1b3b0aabf83d25b29c20646dcabedc05 and fixed in 6.1.178 with commit 14057268e79654c3e8ea2c9b5204cb9644b2964d Issue introduced in 2.6.34 with commit 2271048d1b3b0aabf83d25b29c20646dcabedc05 and fixed in 6.6.145 with commit dbcb8635b1eb7603818591cf745c7b1d714f7ac6 Issue introduced in 2.6.34 with commit 2271048d1b3b0aabf83d25b29c20646dcabedc05 and fixed in 6.12.97 with commit cfada73fabe2ccc06ec77fe2ceaa088689213326 Issue introduced in 2.6.34 with commit 2271048d1b3b0aabf83d25b29c20646dcabedc05 and fixed in 6.18.40 with commit ec5e96aee75d27779b9a860307679f13f33adb0c Issue introduced in 2.6.34 with commit 2271048d1b3b0aabf83d25b29c20646dcabedc05 and fixed in 7.1.5 with commit 3a63a11897c7ba32d1be7a3fdbc48a8b01cf4992 Issue introduced in 2.6.34 with commit 2271048d1b3b0aabf83d25b29c20646dcabedc05 and fixed in 7.2 with commit c37e0a4b79a6bbb96ce5ffe279d7c001e20529e0 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-80876 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: kernel/trace/ring_buffer.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/7c9f0ccf9f04142458d2ac3d39414f4acae242f0 https://git.kernel.org/stable/c/24c3fa71f9947b0e1f3b954db1b769b44140192e https://git.kernel.org/stable/c/14057268e79654c3e8ea2c9b5204cb9644b2964d https://git.kernel.org/stable/c/dbcb8635b1eb7603818591cf745c7b1d714f7ac6 https://git.kernel.org/stable/c/cfada73fabe2ccc06ec77fe2ceaa088689213326 https://git.kernel.org/stable/c/ec5e96aee75d27779b9a860307679f13f33adb0c https://git.kernel.org/stable/c/3a63a11897c7ba32d1be7a3fdbc48a8b01cf4992 https://git.kernel.org/stable/c/c37e0a4b79a6bbb96ce5ffe279d7c001e20529e0