CVE-2026-68187
In the Linux kernel, the following vulnerability has been resolved:
exec: fix unsigned loop counter wrap in transfer_args_to_stack()
The stop value is derived from bprm->p >> PAGE_SHIFT. The index variable is an unsigned long. If bprm->p drops below PAGE_SIZE and stop becomes zero the loop condition index >= stop is always true.
After the index == 0 iteration the decrement wraps to ULONG_MAX and bprm->page[ULONG_MAX] reads sizeof(void *) bytes in front of the array. The pointer has wrapped to -1. That garbage pointer is then passed to kmap_local_page() and PAGE_SIZE bytes are copied from wherever that lands into the stack of the process being created. And the loop doesn't terminate either...
Leer descripción completaMostrar menos
Getting there only requires bprm->p < PAGE_SIZE. On !MMU bprm_set_stack_limit() and bprm_hit_stack_limit() are empty. So the only constraint on how far bprm->p is pushed down is valid_arg_len(), i.e. that each individual string still fits in what is left.
bprm->p starts at PAGE_SIZE * MAX_ARG_PAGES - sizeof(void *) so a single argument or environment string of a little over 31 pages leaves it in the first page:
This is an arcane bug but we should still fix it.
Count down from MAX_ARG_PAGES so the loop ends when index reaches stop, stop == 0 included. The iterations performed are unchanged for every other value of stop.
Only CONFIG_MMU=n builds are affected, transfer_args_to_stack() is used by binfmt_flat and binfmt_elf_fdpic on nommu only.
The loop predates git history. commit 7e7ec6a93434 ("elf_fdpic_transfer_args_to_stack(): make it generic") only moved it from binfmt_elf_fdpic.c into fs/exec.c and narrowed the copy to the used part of the first page. The condition and the decrement are unchanged from 2.6.12-rc2.
Detalles técnicos trazas, registros y código del informe original
Oops - load access fault [#1] CPU: 0 UID: 0 PID: 1 Comm: victim Not tainted 7.2.0-rc4 #1 epc : __memcpy+0xd4/0xf8 ra : transfer_args_to_stack+0xaa/0xae s4 : ffffffffffffffff s2 : 0000000000000000 a1 : ffffffdc98000000 a2 : 0000000000001000 status: 0000000a00001880 badaddr: ffffffdc98000000 cause: 0000000000000005 [<801a5324>] __memcpy+0xd4/0xf8 [<800d5f6a>] load_flat_binary+0x43a/0x65e [<800a2de4>] bprm_execve+0x1d4/0x316 [<800a351a>] do_execveat_common+0x12e/0x138 [<800a3d44>] __riscv_sys_execve+0x38/0x4e Kernel panic - not syncing: Fatal exception in interrupt
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.22%
- Percentil entre todas las CVEs puntuadas: 11
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/16cc4f5c1c4b9e45eca7f7deefa5410a292db599
- https://git.kernel.org/stable/c/2bc6bf70d41055377f390d06f0f3521deb62fd3b
- https://git.kernel.org/stable/c/55fa2c7f2b15583d1a2fe1b5abcc24377359339f
- https://git.kernel.org/stable/c/66e20942890a383eb39b2009a2ceb4c2ebec37ef
- https://git.kernel.org/stable/c/67cf5cdad823afb0530d6d0341fbf4ca07e93a09
- https://git.kernel.org/stable/c/a9eb5c4949008034909bc34ecfa0843ecc1d0ab3
- https://git.kernel.org/stable/c/c62bb00caba66e01fb578d5f0302f247dc64930a
- https://git.kernel.org/stable/c/dfc2a00742af4cb7251c1a8fbce4fbae3cc0de4e
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-68187",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"lessThan": "a9eb5c4949008034909bc34ecfa0843ecc1d0ab3",
"versionType": "git"
},
{
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"lessThan": "67cf5cdad823afb0530d6d0341fbf4ca07e93a09",
"versionType": "git"
},
{
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"lessThan": "66e20942890a383eb39b2009a2ceb4c2ebec37ef",
"versionType": "git"
},
{
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"lessThan": "c62bb00caba66e01fb578d5f0302f247dc64930a",
"versionType": "git"
},
{
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"lessThan": "dfc2a00742af4cb7251c1a8fbce4fbae3cc0de4e",
"versionType": "git"
},
{
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"lessThan": "2bc6bf70d41055377f390d06f0f3521deb62fd3b",
"versionType": "git"
},
{
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"lessThan": "55fa2c7f2b15583d1a2fe1b5abcc24377359339f",
"versionType": "git"
},
{
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"lessThan": "16cc4f5c1c4b9e45eca7f7deefa5410a292db599",
"versionType": "git"
}
],
"programFiles": [
"fs/exec.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "2.6.12",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"fs/exec.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-08-10T13:20:05.870",
"references": [
{
"url": "https://git.kernel.org/stable/c/16cc4f5c1c4b9e45eca7f7deefa5410a292db599",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/2bc6bf70d41055377f390d06f0f3521deb62fd3b",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/55fa2c7f2b15583d1a2fe1b5abcc24377359339f",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/66e20942890a383eb39b2009a2ceb4c2ebec37ef",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/67cf5cdad823afb0530d6d0341fbf4ca07e93a09",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a9eb5c4949008034909bc34ecfa0843ecc1d0ab3",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c62bb00caba66e01fb578d5f0302f247dc64930a",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/dfc2a00742af4cb7251c1a8fbce4fbae3cc0de4e",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nexec: fix unsigned loop counter wrap in transfer_args_to_stack()\n\nThe stop value is derived from bprm->p >> PAGE_SHIFT. The index variable\nis an unsigned long. If bprm->p drops below PAGE_SIZE and stop becomes\nzero the loop condition index >= stop is always true.\n\nAfter the index == 0 iteration the decrement wraps to ULONG_MAX and\nbprm->page[ULONG_MAX] reads sizeof(void *) bytes in front of the array.\nThe pointer has wrapped to -1. That garbage pointer is then passed to\nkmap_local_page() and PAGE_SIZE bytes are copied from wherever that\nlands into the stack of the process being created. And the loop doesn't\nterminate either...\n\nGetting there only requires bprm->p < PAGE_SIZE. On !MMU\nbprm_set_stack_limit() and bprm_hit_stack_limit() are empty. So the only\nconstraint on how far bprm->p is pushed down is valid_arg_len(), i.e.\nthat each individual string still fits in what is left.\n\nbprm->p starts at PAGE_SIZE * MAX_ARG_PAGES - sizeof(void *) so a\nsingle argument or environment string of a little over 31 pages leaves\nit in the first page:\n\n Oops - load access fault [#1]\n CPU: 0 UID: 0 PID: 1 Comm: victim Not tainted 7.2.0-rc4 #1\n epc : __memcpy+0xd4/0xf8\n ra : transfer_args_to_stack+0xaa/0xae\n s4 : ffffffffffffffff s2 : 0000000000000000\n a1 : ffffffdc98000000 a2 : 0000000000001000\n status: 0000000a00001880 badaddr: ffffffdc98000000 cause: 0000000000000005\n [<801a5324>] __memcpy+0xd4/0xf8\n [<800d5f6a>] load_flat_binary+0x43a/0x65e\n [<800a2de4>] bprm_execve+0x1d4/0x316\n [<800a351a>] do_execveat_common+0x12e/0x138\n [<800a3d44>] __riscv_sys_execve+0x38/0x4e\n Kernel panic - not syncing: Fatal exception in interrupt\n\nThis is an arcane bug but we should still fix it.\n\nCount down from MAX_ARG_PAGES so the loop ends when index reaches stop,\nstop == 0 included. The iterations performed are unchanged for every\nother value of stop.\n\nOnly CONFIG_MMU=n builds are affected, transfer_args_to_stack() is used\nby binfmt_flat and binfmt_elf_fdpic on nommu only.\n\nThe loop predates git history. commit 7e7ec6a93434\n(\"elf_fdpic_transfer_args_to_stack(): make it generic\") only moved it\nfrom binfmt_elf_fdpic.c into fs/exec.c and narrowed the copy to the used\npart of the first page. The condition and the decrement are unchanged\nfrom 2.6.12-rc2."
}
],
"lastModified": "2026-08-19T17:20:34.860",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}