« Volver al listado

CVE-2026-72028

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

riscv: probes: save original sp in rethook trampoline

Reading a word from the stack in a kretprobe crashes a risc-v kernel.

In regs_get_kernel_stack_nth, regs->sp contains an arbitrary value.

arch_rethook_trampoline saves the registers from the probed function in a struct pt_regs. sp is not saved. Instead, sp is decremented for arch_rethook_trampoline's local stack.

Fix this crash and save the original sp along with the other registers. Use a0 as a temporary register, it is overwritten anyway.

[pjw@kernel.org: added Fixes tag; cc'ed stable]

Detalles técnicos trazas, registros y código del informe original
$ cd /sys/kernel/tracing/
$ echo 'r n_tty_write $stack0' > dynamic_events
$ echo 1 > events/kprobes/enable
Unable to handle kernel paging request at virtual address 0000000200000128
...
[<ffffffff80016d16>] regs_get_kernel_stack_nth+0x26/0x38
[<ffffffff80177196>] process_fetch_insn+0x3ee/0x760
[<ffffffff80177836>] kretprobe_trace_func+0x116/0x1f0
[<ffffffff8017795a>] kretprobe_dispatcher+0x4a/0x58
[<ffffffff8013572e>] kretprobe_rethook_handler+0x5e/0x90
[<ffffffff80180838>] rethook_trampoline_handler+0x70/0x108
[<ffffffff8001ba32>] arch_rethook_trampoline_callback+0x12/0x1c
[<ffffffff8001ba84>] arch_rethook_trampoline+0x48/0x94
[<ffffffff8067872a>] tty_write+0x1a/0x30

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-72028",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "c22b0bcb1dd024cb9caad9230e3a387d8b061df5",
              "lessThan": "5da5cf48a432e30ded8d58087854e5383a36eff1",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c22b0bcb1dd024cb9caad9230e3a387d8b061df5",
              "lessThan": "c386e1c591d72eab58ee2e69105c8cbc70928857",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c22b0bcb1dd024cb9caad9230e3a387d8b061df5",
              "lessThan": "2faf0198168d2017cb528a79f76c560fda3b6e94",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c22b0bcb1dd024cb9caad9230e3a387d8b061df5",
              "lessThan": "91b4d76dd07f1a1f20f73dfebb42ba04ac911a56",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c22b0bcb1dd024cb9caad9230e3a387d8b061df5",
              "lessThan": "bc7b086a45521a986a49045907f017e3e46c763e",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "arch/riscv/kernel/probes/rethook_trampoline.S"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.12"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.12",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.6.145",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.97",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.40",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "arch/riscv/kernel/probes/rethook_trampoline.S"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-15T06:21:01.953",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/2faf0198168d2017cb528a79f76c560fda3b6e94",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/5da5cf48a432e30ded8d58087854e5383a36eff1",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/91b4d76dd07f1a1f20f73dfebb42ba04ac911a56",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/bc7b086a45521a986a49045907f017e3e46c763e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c386e1c591d72eab58ee2e69105c8cbc70928857",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nriscv: probes: save original sp in rethook trampoline\n\nReading a word from the stack in a kretprobe crashes a risc-v kernel.\n\n$ cd /sys/kernel/tracing/\n$ echo 'r n_tty_write $stack0' > dynamic_events\n$ echo 1 > events/kprobes/enable\nUnable to handle kernel paging request at virtual address 0000000200000128\n...\n[<ffffffff80016d16>] regs_get_kernel_stack_nth+0x26/0x38\n[<ffffffff80177196>] process_fetch_insn+0x3ee/0x760\n[<ffffffff80177836>] kretprobe_trace_func+0x116/0x1f0\n[<ffffffff8017795a>] kretprobe_dispatcher+0x4a/0x58\n[<ffffffff8013572e>] kretprobe_rethook_handler+0x5e/0x90\n[<ffffffff80180838>] rethook_trampoline_handler+0x70/0x108\n[<ffffffff8001ba32>] arch_rethook_trampoline_callback+0x12/0x1c\n[<ffffffff8001ba84>] arch_rethook_trampoline+0x48/0x94\n[<ffffffff8067872a>] tty_write+0x1a/0x30\n\nIn regs_get_kernel_stack_nth, regs->sp contains an arbitrary value.\n\narch_rethook_trampoline saves the registers from the probed function in a\nstruct pt_regs. sp is not saved. Instead, sp is decremented for\narch_rethook_trampoline's local stack.\n\nFix this crash and save the original sp along with the other registers.\nUse a0 as a temporary register, it is overwritten anyway.\n\n[pjw@kernel.org: added Fixes tag; cc'ed stable]"
    }
  ],
  "lastModified": "2026-08-17T06:18:00.533",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}