« Volver al listado

CVE-2026-72138

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

xen/gntdev: fix error handling in ioctl

When gntdev_ioctl_map_grant_ref() fails to copy the operation result back to userspace after successfully adding the mapping to the list, the error path returns -EFAULT without releasing the reference acquired by gntdev_alloc_map(). The mapping remains in priv->maps with a refcount of 1, causing a memory leak and a dangling list entry.

Additionally, gntdev_add_map() may modify map->index to avoid overlap with existing mappings. Therefore, the index returned to userspace must be obtained after gntdev_add_map() completes.

Leer descripción completaMostrar menos

Fix this by holding the mutex across gntdev_add_map(), retrieving the correct index, and copy_to_user(). If copy_to_user() fails, remove the mapping from the list and release the reference while still holding the lock.

Fix these issues by properly handling all error cases.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-72138",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "68b025c813c2eb41ff25628e3d4952d5185eb1a4",
              "lessThan": "52dc40ef0cfee6ae89b7524967e73f0ba37906d7",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "68b025c813c2eb41ff25628e3d4952d5185eb1a4",
              "lessThan": "1dd9cb98fe228e017fff9efb33862ff38c741b65",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "68b025c813c2eb41ff25628e3d4952d5185eb1a4",
              "lessThan": "6df926130aee6cab9b5d2e5b7862e49ccac348dc",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "68b025c813c2eb41ff25628e3d4952d5185eb1a4",
              "lessThan": "311011f8cc206c5af2877b03e3f627ee1b8fe024",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "68b025c813c2eb41ff25628e3d4952d5185eb1a4",
              "lessThan": "18a693733f7ad004e1ab0466693121ca70cd95dd",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "68b025c813c2eb41ff25628e3d4952d5185eb1a4",
              "lessThan": "16d3ccdabb8dee9be2cdcd6d3f9a125572ec0454",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "68b025c813c2eb41ff25628e3d4952d5185eb1a4",
              "lessThan": "6883269a323609f68f6faa903f8f8ff3d191cec8",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "68b025c813c2eb41ff25628e3d4952d5185eb1a4",
              "lessThan": "45ca1afe2fd14c04e37227e79d3f8455831d8408",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/xen/gntdev.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "2.6.39"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "2.6.39",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.261",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.212",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.178",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.145",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.97",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.40",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/xen/gntdev.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-15T06:21:31.337",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/16d3ccdabb8dee9be2cdcd6d3f9a125572ec0454",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/18a693733f7ad004e1ab0466693121ca70cd95dd",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/1dd9cb98fe228e017fff9efb33862ff38c741b65",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/311011f8cc206c5af2877b03e3f627ee1b8fe024",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/45ca1afe2fd14c04e37227e79d3f8455831d8408",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/52dc40ef0cfee6ae89b7524967e73f0ba37906d7",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6883269a323609f68f6faa903f8f8ff3d191cec8",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6df926130aee6cab9b5d2e5b7862e49ccac348dc",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nxen/gntdev: fix error handling in ioctl\n\nWhen gntdev_ioctl_map_grant_ref() fails to copy the operation result\nback to userspace after successfully adding the mapping to the list,\nthe error path returns -EFAULT without releasing the reference\nacquired by gntdev_alloc_map(). The mapping remains in priv->maps\nwith a refcount of 1, causing a memory leak and a dangling list\nentry.\n\nAdditionally, gntdev_add_map() may modify map->index to avoid overlap\nwith existing mappings. Therefore, the index returned to userspace\nmust be obtained after gntdev_add_map() completes.\n\nFix this by holding the mutex across gntdev_add_map(), retrieving\nthe correct index, and copy_to_user(). If copy_to_user() fails,\nremove the mapping from the list and release the reference while\nstill holding the lock.\n\n\nFix these issues by properly handling all error cases."
    }
  ],
  "lastModified": "2026-08-17T06:18:13.703",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}