« Volver al listado

CVE-2026-80916

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

kcov: fix data corruption and race conditions on PREEMPT_RT

syzbot is reporting KCOV state corruption on PREEMPT_RT kernels, for the temporary storage used for saving/restoring remote KCOV state is currently allocated as the per-CPU area.

On PREEMPT_RT kernels, softirq handlers run as preemptible task threads (e.g., ksoftirqd). If a softirq context preempts a task running a remote KCOV session, it safely saves the task's state into the per-CPU area. However, if that softirq thread is subsequently preempted by a higher- priority softirq thread on the same CPU, the second softirq will overwrite the same per-CPU area, permanently destroying the original task's KCOV state.

Leer descripción completaMostrar menos

Fix this data corruption by moving the temporary storage from the per-CPU area to the per-thread area. Since each softirq thread now owns its own task context, nested softirq preemption no longer causes data overwrites.

Note that while the temporary storage is now on a per-thread basis, the per-CPU kcov_percpu_data.lock must be retained, for we need to ensure that kcov_remote_start() and kcov_remote_stop() operate atomically without racing against asynchronous interrupts that manipulate the current task's KCOV state.

It is likely that GFP_KERNEL allocation by vmalloc_node() in kcov_init() has already called panic() before returning NULL, for there will be no OOM-killable userspace processes when __init function of built-in module runs. But this patch also fixes crashing the kernel when vmalloc_node() in kcov_init() returned NULL, for kcov_init() left per-CPU irq_area == NULL but kcov_remote_start() depends on per-CPU irq_area != NULL, resulting in

problems.

Detalles técnicos trazas, registros y código del informe original
  (1) doing vmalloc() in kcov_remote_start() despite !in_task() context

  (2) out-of-array-bounds access if (1) succeeded but
      kcov->remote_size < CONFIG_KCOV_IRQ_AREA_SIZE

  (3) always leak memory allocated by (1), eventually killing all
      OOM-killable userspace processes

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-80916",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5ff3b30ab57da82d8db4f14662a2858cabfbc2c0",
              "lessThan": "ef7048d8a614c5f5a9b20513a5428101a744514e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5ff3b30ab57da82d8db4f14662a2858cabfbc2c0",
              "lessThan": "8ed3ddf23d39bf5338406bd9f8863d44748cf6ce",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5ff3b30ab57da82d8db4f14662a2858cabfbc2c0",
              "lessThan": "5dc59fc959b2b5742985d7ef24bccd1868217dc2",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5ff3b30ab57da82d8db4f14662a2858cabfbc2c0",
              "lessThan": "a2fb8222cde23b0001812ed3acb7c0ea36dd94e2",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5ff3b30ab57da82d8db4f14662a2858cabfbc2c0",
              "lessThan": "18799e858b407bf355383c9dd6c06477aa437134",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5ff3b30ab57da82d8db4f14662a2858cabfbc2c0",
              "lessThan": "e11f5b48c82703242a3be7a7ae4b4940b4cb4610",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5ff3b30ab57da82d8db4f14662a2858cabfbc2c0",
              "lessThan": "22670d1552fe155822b2abf91f920925f7d067b4",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5ff3b30ab57da82d8db4f14662a2858cabfbc2c0",
              "lessThan": "f8c9a3ec36b4ee3d4701b9be08f40e7bfbf89761",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5ff3b30ab57da82d8db4f14662a2858cabfbc2c0",
              "lessThan": "2eed77fdcb0cc48e8eccb2bcd4b7f2c6d650e84c",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "include/linux/sched.h",
            "kernel/kcov.c",
            "lib/Kconfig.debug"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.8"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.8",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.269",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.220",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.185",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.154",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.106",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.47",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.11",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.1",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "include/linux/sched.h",
            "kernel/kcov.c",
            "lib/Kconfig.debug"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-09T17:17:46.513",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/18799e858b407bf355383c9dd6c06477aa437134",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/22670d1552fe155822b2abf91f920925f7d067b4",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/2eed77fdcb0cc48e8eccb2bcd4b7f2c6d650e84c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/5dc59fc959b2b5742985d7ef24bccd1868217dc2",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8ed3ddf23d39bf5338406bd9f8863d44748cf6ce",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a2fb8222cde23b0001812ed3acb7c0ea36dd94e2",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e11f5b48c82703242a3be7a7ae4b4940b4cb4610",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ef7048d8a614c5f5a9b20513a5428101a744514e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f8c9a3ec36b4ee3d4701b9be08f40e7bfbf89761",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nkcov: fix data corruption and race conditions on PREEMPT_RT\n\nsyzbot is reporting KCOV state corruption on PREEMPT_RT kernels, for the\ntemporary storage used for saving/restoring remote KCOV state is currently\nallocated as the per-CPU area.\n\nOn PREEMPT_RT kernels, softirq handlers run as preemptible task threads\n(e.g., ksoftirqd). If a softirq context preempts a task running a remote\nKCOV session, it safely saves the task's state into the per-CPU area.\nHowever, if that softirq thread is subsequently preempted by a higher-\npriority softirq thread on the same CPU, the second softirq will overwrite\nthe same per-CPU area, permanently destroying the original task's KCOV\nstate.\n\nFix this data corruption by moving the temporary storage from the per-CPU\narea to the per-thread area. Since each softirq thread now owns its own\ntask context, nested softirq preemption no longer causes data overwrites.\n\nNote that while the temporary storage is now on a per-thread basis, the\nper-CPU kcov_percpu_data.lock must be retained, for we need to ensure that\nkcov_remote_start() and kcov_remote_stop() operate atomically without\nracing against asynchronous interrupts that manipulate the current task's\nKCOV state.\n\nIt is likely that GFP_KERNEL allocation by vmalloc_node() in kcov_init()\nhas already called panic() before returning NULL, for there will be no\nOOM-killable userspace processes when __init function of built-in module\nruns. But this patch also fixes crashing the kernel when vmalloc_node()\nin kcov_init() returned NULL, for kcov_init() left per-CPU irq_area == NULL\nbut kcov_remote_start() depends on per-CPU irq_area != NULL, resulting in\n\n  (1) doing vmalloc() in kcov_remote_start() despite !in_task() context\n\n  (2) out-of-array-bounds access if (1) succeeded but\n      kcov->remote_size < CONFIG_KCOV_IRQ_AREA_SIZE\n\n  (3) always leak memory allocated by (1), eventually killing all\n      OOM-killable userspace processes\n\nproblems."
    }
  ],
  "lastModified": "2026-09-09T17:17:46.513",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}