CVE-2026-72025
In the Linux kernel, the following vulnerability has been resolved:
s390/monwriter: Reject buffer reuse with different data length
When data buffers are reused, e.g. for interval sample records, the first record determines the data length, and the size of the buffer for user copy. Current monwriter code does not check if the data length was changed for subsequent records, which also would never happen for valid user programs.
However, a malicious user could change the data length, resulting in out of bounds user copy to the kernel buffer, and memory corruption. By default, the monwriter misc device is created with root-only permissions, so practical impact is typically low.
Leer descripción completaMostrar menos
Fix this by checking for changed data length and rejecting such records.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.22%
- Percentil entre todas las CVEs puntuadas: 11
- Fecha de la puntuación: 4/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/01f3ce411711c2c919598ea25320a5a48f71edbc
- https://git.kernel.org/stable/c/036bc5661060702e798d215e81bb46da530965b3
- https://git.kernel.org/stable/c/096dff1247037d329c04b3a5be0ecdfb1c5c7ac6
- https://git.kernel.org/stable/c/2995ccec260caa9e85b3301a4aba1e66ed80ad74
- https://git.kernel.org/stable/c/759d91378203ea35fa9bca6726dcf0010de081fb
- https://git.kernel.org/stable/c/ae5347f3db1782c6118f6cc0d9fd8b1d43397db3
- https://git.kernel.org/stable/c/d39cf4a6d721b1ae21eb53bbf3e8cd984253d7ab
- https://git.kernel.org/stable/c/f0745496f7c171271cafd9457df3b914a483ddeb
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-72025",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "31b58088292c7f00f0b81088bfb557285b0b6247",
"lessThan": "096dff1247037d329c04b3a5be0ecdfb1c5c7ac6",
"versionType": "git"
},
{
"status": "affected",
"version": "31b58088292c7f00f0b81088bfb557285b0b6247",
"lessThan": "d39cf4a6d721b1ae21eb53bbf3e8cd984253d7ab",
"versionType": "git"
},
{
"status": "affected",
"version": "31b58088292c7f00f0b81088bfb557285b0b6247",
"lessThan": "759d91378203ea35fa9bca6726dcf0010de081fb",
"versionType": "git"
},
{
"status": "affected",
"version": "31b58088292c7f00f0b81088bfb557285b0b6247",
"lessThan": "036bc5661060702e798d215e81bb46da530965b3",
"versionType": "git"
},
{
"status": "affected",
"version": "31b58088292c7f00f0b81088bfb557285b0b6247",
"lessThan": "01f3ce411711c2c919598ea25320a5a48f71edbc",
"versionType": "git"
},
{
"status": "affected",
"version": "31b58088292c7f00f0b81088bfb557285b0b6247",
"lessThan": "f0745496f7c171271cafd9457df3b914a483ddeb",
"versionType": "git"
},
{
"status": "affected",
"version": "31b58088292c7f00f0b81088bfb557285b0b6247",
"lessThan": "ae5347f3db1782c6118f6cc0d9fd8b1d43397db3",
"versionType": "git"
},
{
"status": "affected",
"version": "31b58088292c7f00f0b81088bfb557285b0b6247",
"lessThan": "2995ccec260caa9e85b3301a4aba1e66ed80ad74",
"versionType": "git"
}
],
"programFiles": [
"drivers/s390/char/monwriter.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.19"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "2.6.19",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/s390/char/monwriter.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-08-15T06:21:01.580",
"references": [
{
"url": "https://git.kernel.org/stable/c/01f3ce411711c2c919598ea25320a5a48f71edbc",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/036bc5661060702e798d215e81bb46da530965b3",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/096dff1247037d329c04b3a5be0ecdfb1c5c7ac6",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/2995ccec260caa9e85b3301a4aba1e66ed80ad74",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/759d91378203ea35fa9bca6726dcf0010de081fb",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/ae5347f3db1782c6118f6cc0d9fd8b1d43397db3",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/d39cf4a6d721b1ae21eb53bbf3e8cd984253d7ab",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/f0745496f7c171271cafd9457df3b914a483ddeb",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/monwriter: Reject buffer reuse with different data length\n\nWhen data buffers are reused, e.g. for interval sample records, the\nfirst record determines the data length, and the size of the buffer for\nuser copy. Current monwriter code does not check if the data length was\nchanged for subsequent records, which also would never happen for valid\nuser programs.\n\nHowever, a malicious user could change the data length, resulting in out\nof bounds user copy to the kernel buffer, and memory corruption. By\ndefault, the monwriter misc device is created with root-only permissions,\nso practical impact is typically low.\n\nFix this by checking for changed data length and rejecting such records."
}
],
"lastModified": "2026-08-18T07:16:52.647",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}