CVE-2026-80661
In the Linux kernel, the following vulnerability has been resolved:
ufs: core: tracing: Do not dereference pointers in TP_printk()
The trace events in drivers/ufs/core/ufs_trace.h were converted to take a pointer to the hba structure as an argument for the tracepoint and then in TP_printk() the printing of the dev_name from the ring buffer was converted to using the dev dereferenced pointer from the hba saved pointer.
This is not allowed as the TP_printk() is executed at the time the trace event is read from /sys/kernel/tracing/trace file. That can happen literally, seconds, minutes, hours, weeks, days, or even months later! There is no guarantee that the hba pointer will still exist by the time it is dereferenced when the "trace" file is read.
Leer descripción completaMostrar menos
Instead, save the device name from the hba pointer at the time the tracepoint is called and place it into the ring buffer event. Then the TP_printk() can read the name directly from the ring buffer and remove the possibility that it will read a freed pointer and crash the kernel.
This was detected when testing the trace event code that looks for TP_printk() parameters doing illegal derferences[1]
[1] https://lore.kernel.org/all/20260630184836.74d477b6@gandalf.local.home/
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.17%
- Percentil entre todas las CVEs puntuadas: 6
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1068Exploitation for Privilege Escalationprivilege escalation85 % - Impacto principal
T1499.004Application or System Exploitationimpact80 %
Vulnerabilidad local en kernel de Linux (AV:L, PR:L) que causa dereferencia de puntero liberado al leer eventos de tracing, resultando en DoS (crash) o escalada de privilegios según contexto de explotación.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-80661",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "583e518e7100362e3937b583976f9470c39d1db2",
"lessThan": "e497fef9ad7e913f52de6f97e818f56915e96164",
"versionType": "git"
},
{
"status": "affected",
"version": "583e518e7100362e3937b583976f9470c39d1db2",
"lessThan": "2510434307a224078302019e52ab3c863fbe87fb",
"versionType": "git"
},
{
"status": "affected",
"version": "583e518e7100362e3937b583976f9470c39d1db2",
"lessThan": "535fcf4b8a261fbb8cc4f91e4597343c135a90f2",
"versionType": "git"
}
],
"programFiles": [
"drivers/ufs/core/ufs_trace.h"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.15"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.15",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/ufs/core/ufs_trace.h"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-08-28T08:16:51.290",
"references": [
{
"url": "https://git.kernel.org/stable/c/2510434307a224078302019e52ab3c863fbe87fb",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/535fcf4b8a261fbb8cc4f91e4597343c135a90f2",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/e497fef9ad7e913f52de6f97e818f56915e96164",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nufs: core: tracing: Do not dereference pointers in TP_printk()\n\nThe trace events in drivers/ufs/core/ufs_trace.h were converted to take a\npointer to the hba structure as an argument for the tracepoint and then in\nTP_printk() the printing of the dev_name from the ring buffer was\nconverted to using the dev dereferenced pointer from the hba saved\npointer.\n\nThis is not allowed as the TP_printk() is executed at the time the trace\nevent is read from /sys/kernel/tracing/trace file. That can happen\nliterally, seconds, minutes, hours, weeks, days, or even months later!\nThere is no guarantee that the hba pointer will still exist by the time it\nis dereferenced when the \"trace\" file is read.\n\nInstead, save the device name from the hba pointer at the time the\ntracepoint is called and place it into the ring buffer event. Then the\nTP_printk() can read the name directly from the ring buffer and remove the\npossibility that it will read a freed pointer and crash the kernel.\n\nThis was detected when testing the trace event code that looks for\nTP_printk() parameters doing illegal derferences[1]\n\n[1] https://lore.kernel.org/all/20260630184836.74d477b6@gandalf.local.home/"
}
],
"lastModified": "2026-08-29T07:16:48.547",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}