« Volver al listado

CVE-2026-80718

Estado: RecibidaAlta (7.8)—

In the Linux kernel, the following vulnerability has been resolved:

mm/percpu-km: fix bitmap overflow and accounting in pcpu_create_chunk()

In pcpu_create_chunk(), nr_pages is the total contiguous backing allocation, i.e., nr_units * pcpu_unit_pages, but pcpu_chunk_populated() uses it to set chunk->populated, whose size is pcpu_unit_pages, bitmap. Since bit N in chunk->populated means page offset N inside every unit is backed. When nr_units > 1, the function writes beyond chunk->populated. Fix it by using chunk->nr_pages.

It also fixes the global pcpu_nr_empty_pop_pages accounting, since pcpu_balance_free() only iterates up to chunk->nr_pages.

Leer descripción completaMostrar menos

Commit a63d4ac4ab609 ("percpu: make percpu-km set chunk->populated bitmap properly") introduced the bitmap overflow issue. Later, commit b539b87fed37f ("percpu: implmeent pcpu_nr_empty_pop_pages and chunk->nr_populated") added pcpu_nr_empty_pop_pages and caused the accounting issue.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad local en kernel (AV:L, PR:L) sin interacción del usuario que permite escalada de privilegios mediante overflow de bitmap en memoria del kernel percpu, con acceso confidencial, integridad y disponibilidad (C:H, I:H, A:H).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-80718",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "a63d4ac4ab6094c051a5a240260d16117a7a2f86",
              "lessThan": "5f43d2c1bea280dcdfabaf156c25e7402fb8039f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "a63d4ac4ab6094c051a5a240260d16117a7a2f86",
              "lessThan": "92c43ac3c2b09eb16162e8144e73c00b7c3e29d6",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "a63d4ac4ab6094c051a5a240260d16117a7a2f86",
              "lessThan": "6fc7da2a052f2825fff785e860e67183f5acaaba",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "a63d4ac4ab6094c051a5a240260d16117a7a2f86",
              "lessThan": "01504da375f5b19df195cb1cb1cf1dd184318f97",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "a63d4ac4ab6094c051a5a240260d16117a7a2f86",
              "lessThan": "a6940b84c8c035da465b7165fdfcfb005545724e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "a63d4ac4ab6094c051a5a240260d16117a7a2f86",
              "lessThan": "32134cf9211b83bed9076d0739c5906fbea4c763",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "a63d4ac4ab6094c051a5a240260d16117a7a2f86",
              "lessThan": "5c7fc39bf19abb38a996aaad77b3e3a8f48581c3",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "a63d4ac4ab6094c051a5a240260d16117a7a2f86",
              "lessThan": "89b1b79c308818a715e75f28744b70d8940a07c9",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "mm/percpu-km.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.18"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "3.18",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.265",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.216",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.183",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.151",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.103",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.44",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.8",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "mm/percpu-km.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-28T08:16:57.563",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/01504da375f5b19df195cb1cb1cf1dd184318f97",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/32134cf9211b83bed9076d0739c5906fbea4c763",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/5c7fc39bf19abb38a996aaad77b3e3a8f48581c3",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/5f43d2c1bea280dcdfabaf156c25e7402fb8039f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6fc7da2a052f2825fff785e860e67183f5acaaba",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/89b1b79c308818a715e75f28744b70d8940a07c9",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/92c43ac3c2b09eb16162e8144e73c00b7c3e29d6",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a6940b84c8c035da465b7165fdfcfb005545724e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/percpu-km: fix bitmap overflow and accounting in pcpu_create_chunk()\n\nIn pcpu_create_chunk(), nr_pages is the total contiguous backing\nallocation, i.e., nr_units * pcpu_unit_pages, but pcpu_chunk_populated()\nuses it to set chunk->populated, whose size is pcpu_unit_pages, bitmap. \nSince bit N in chunk->populated means page offset N inside every unit is\nbacked.  When nr_units > 1, the function writes beyond chunk->populated. \nFix it by using chunk->nr_pages.\n\nIt also fixes the global pcpu_nr_empty_pop_pages accounting, since\npcpu_balance_free() only iterates up to chunk->nr_pages.\n\nCommit a63d4ac4ab609 (\"percpu: make percpu-km set chunk->populated bitmap\nproperly\") introduced the bitmap overflow issue.  Later, commit\nb539b87fed37f (\"percpu: implmeent pcpu_nr_empty_pop_pages and\nchunk->nr_populated\") added pcpu_nr_empty_pop_pages and caused the\naccounting issue."
    }
  ],
  "lastModified": "2026-08-29T07:16:53.323",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}