CVE-2026-72485
In the Linux kernel, the following vulnerability has been resolved:
coresight: platform: defer connection counter increment until alloc succeeds
coresight_add_out_conn() increments nr_outconns before calling devm_krealloc_array() and again before devm_kmalloc(). If either allocation fails, the counter is already bumped while the corresponding array entry is NULL or uninitialized garbage.
coresight_add_in_conn() has the same problem with nr_inconns and devm_krealloc_array().
In both cases the probe returns -ENOMEM, which causes coresight_get_platform_data() to call coresight_release_platform_data() for cleanup.
Leer descripción completaMostrar menos
That function iterates up to nr_outconns (or nr_inconns) entries and dereferences each pointer unconditionally, hitting the NULL or garbage entry and panicking instead of failing gracefully.
Fix by moving the counter increments to after all allocations succeed, so the struct is always consistent on any error path.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.17%
- Percentil entre todas las CVEs puntuadas: 6
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1068Exploitation for Privilege Escalationprivilege escalation75 % - Impacto principal
T1499.004Application or System Exploitationimpact65 %
Vulnerabilidad local en el kernel Linux (AV:L, PR:L) que provoca pánico del sistema por derreferencias nulas/no inicializadas durante limpieza de memoria, causando DoS. Escalada de privilegios con contexto de usuario.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/09c44549820df67048be3ba19c723bac72ebb98e
- https://git.kernel.org/stable/c/1563ae33dc4f5ebac96b93af2ef72e72aaaa31ae
- https://git.kernel.org/stable/c/8ca9adc805884d3bb5038082462577f86c2c4a10
- https://git.kernel.org/stable/c/aed6915c2f304ed34281856c53e374483c71b68b
- https://git.kernel.org/stable/c/dd3c9e1c9858c797ba78f4ca6c0fc663eeac6d72
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-72485",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "3d4ff657e454f8dba3e5e268e731e6e28c6031c1",
"lessThan": "dd3c9e1c9858c797ba78f4ca6c0fc663eeac6d72",
"versionType": "git"
},
{
"status": "affected",
"version": "3d4ff657e454f8dba3e5e268e731e6e28c6031c1",
"lessThan": "aed6915c2f304ed34281856c53e374483c71b68b",
"versionType": "git"
},
{
"status": "affected",
"version": "3d4ff657e454f8dba3e5e268e731e6e28c6031c1",
"lessThan": "09c44549820df67048be3ba19c723bac72ebb98e",
"versionType": "git"
},
{
"status": "affected",
"version": "3d4ff657e454f8dba3e5e268e731e6e28c6031c1",
"lessThan": "8ca9adc805884d3bb5038082462577f86c2c4a10",
"versionType": "git"
},
{
"status": "affected",
"version": "3d4ff657e454f8dba3e5e268e731e6e28c6031c1",
"lessThan": "1563ae33dc4f5ebac96b93af2ef72e72aaaa31ae",
"versionType": "git"
}
],
"programFiles": [
"drivers/hwtracing/coresight/coresight-platform.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.5"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.5",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.6.158",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.111",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.53",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/hwtracing/coresight/coresight-platform.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-08-15T06:22:22.767",
"references": [
{
"url": "https://git.kernel.org/stable/c/09c44549820df67048be3ba19c723bac72ebb98e",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/1563ae33dc4f5ebac96b93af2ef72e72aaaa31ae",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/8ca9adc805884d3bb5038082462577f86c2c4a10",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/aed6915c2f304ed34281856c53e374483c71b68b",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/dd3c9e1c9858c797ba78f4ca6c0fc663eeac6d72",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncoresight: platform: defer connection counter increment until alloc succeeds\n\ncoresight_add_out_conn() increments nr_outconns before calling\ndevm_krealloc_array() and again before devm_kmalloc(). If either\nallocation fails, the counter is already bumped while the corresponding\narray entry is NULL or uninitialized garbage.\n\ncoresight_add_in_conn() has the same problem with nr_inconns and\ndevm_krealloc_array().\n\nIn both cases the probe returns -ENOMEM, which causes\ncoresight_get_platform_data() to call coresight_release_platform_data()\nfor cleanup. That function iterates up to nr_outconns (or nr_inconns)\nentries and dereferences each pointer unconditionally, hitting the NULL\nor garbage entry and panicking instead of failing gracefully.\n\nFix by moving the counter increments to after all allocations succeed,\nso the struct is always consistent on any error path."
}
],
"lastModified": "2026-10-03T11:17:37.860",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}