CVE-2026-72138
In the Linux kernel, the following vulnerability has been resolved:
xen/gntdev: fix error handling in ioctl
When gntdev_ioctl_map_grant_ref() fails to copy the operation result back to userspace after successfully adding the mapping to the list, the error path returns -EFAULT without releasing the reference acquired by gntdev_alloc_map(). The mapping remains in priv->maps with a refcount of 1, causing a memory leak and a dangling list entry.
Additionally, gntdev_add_map() may modify map->index to avoid overlap with existing mappings. Therefore, the index returned to userspace must be obtained after gntdev_add_map() completes.
Leer descripción completaMostrar menos
Fix this by holding the mutex across gntdev_add_map(), retrieving the correct index, and copy_to_user(). If copy_to_user() fails, remove the mapping from the list and release the reference while still holding the lock.
Fix these issues by properly handling all error cases.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.22%
- Percentil entre todas las CVEs puntuadas: 11
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/16d3ccdabb8dee9be2cdcd6d3f9a125572ec0454
- https://git.kernel.org/stable/c/18a693733f7ad004e1ab0466693121ca70cd95dd
- https://git.kernel.org/stable/c/1dd9cb98fe228e017fff9efb33862ff38c741b65
- https://git.kernel.org/stable/c/311011f8cc206c5af2877b03e3f627ee1b8fe024
- https://git.kernel.org/stable/c/45ca1afe2fd14c04e37227e79d3f8455831d8408
- https://git.kernel.org/stable/c/52dc40ef0cfee6ae89b7524967e73f0ba37906d7
- https://git.kernel.org/stable/c/6883269a323609f68f6faa903f8f8ff3d191cec8
- https://git.kernel.org/stable/c/6df926130aee6cab9b5d2e5b7862e49ccac348dc
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-72138",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "68b025c813c2eb41ff25628e3d4952d5185eb1a4",
"lessThan": "52dc40ef0cfee6ae89b7524967e73f0ba37906d7",
"versionType": "git"
},
{
"status": "affected",
"version": "68b025c813c2eb41ff25628e3d4952d5185eb1a4",
"lessThan": "1dd9cb98fe228e017fff9efb33862ff38c741b65",
"versionType": "git"
},
{
"status": "affected",
"version": "68b025c813c2eb41ff25628e3d4952d5185eb1a4",
"lessThan": "6df926130aee6cab9b5d2e5b7862e49ccac348dc",
"versionType": "git"
},
{
"status": "affected",
"version": "68b025c813c2eb41ff25628e3d4952d5185eb1a4",
"lessThan": "311011f8cc206c5af2877b03e3f627ee1b8fe024",
"versionType": "git"
},
{
"status": "affected",
"version": "68b025c813c2eb41ff25628e3d4952d5185eb1a4",
"lessThan": "18a693733f7ad004e1ab0466693121ca70cd95dd",
"versionType": "git"
},
{
"status": "affected",
"version": "68b025c813c2eb41ff25628e3d4952d5185eb1a4",
"lessThan": "16d3ccdabb8dee9be2cdcd6d3f9a125572ec0454",
"versionType": "git"
},
{
"status": "affected",
"version": "68b025c813c2eb41ff25628e3d4952d5185eb1a4",
"lessThan": "6883269a323609f68f6faa903f8f8ff3d191cec8",
"versionType": "git"
},
{
"status": "affected",
"version": "68b025c813c2eb41ff25628e3d4952d5185eb1a4",
"lessThan": "45ca1afe2fd14c04e37227e79d3f8455831d8408",
"versionType": "git"
}
],
"programFiles": [
"drivers/xen/gntdev.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.39"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "2.6.39",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/xen/gntdev.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-08-15T06:21:31.337",
"references": [
{
"url": "https://git.kernel.org/stable/c/16d3ccdabb8dee9be2cdcd6d3f9a125572ec0454",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/18a693733f7ad004e1ab0466693121ca70cd95dd",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/1dd9cb98fe228e017fff9efb33862ff38c741b65",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/311011f8cc206c5af2877b03e3f627ee1b8fe024",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/45ca1afe2fd14c04e37227e79d3f8455831d8408",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/52dc40ef0cfee6ae89b7524967e73f0ba37906d7",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/6883269a323609f68f6faa903f8f8ff3d191cec8",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/6df926130aee6cab9b5d2e5b7862e49ccac348dc",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nxen/gntdev: fix error handling in ioctl\n\nWhen gntdev_ioctl_map_grant_ref() fails to copy the operation result\nback to userspace after successfully adding the mapping to the list,\nthe error path returns -EFAULT without releasing the reference\nacquired by gntdev_alloc_map(). The mapping remains in priv->maps\nwith a refcount of 1, causing a memory leak and a dangling list\nentry.\n\nAdditionally, gntdev_add_map() may modify map->index to avoid overlap\nwith existing mappings. Therefore, the index returned to userspace\nmust be obtained after gntdev_add_map() completes.\n\nFix this by holding the mutex across gntdev_add_map(), retrieving\nthe correct index, and copy_to_user(). If copy_to_user() fails,\nremove the mapping from the list and release the reference while\nstill holding the lock.\n\n\nFix these issues by properly handling all error cases."
}
],
"lastModified": "2026-08-17T06:18:13.703",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}