CVE-2026-72011

Source
https://cve.org/CVERecord?id=CVE-2026-72011
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72011.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72011
Downstream
Published
2026-08-15T05:51:40.489Z
Modified
2026-08-16T03:48:30.684416145Z
Summary
s390/diag: Add missing array_index_nospec() call to memtop_get_page_count()
Details

In the Linux kernel, the following vulnerability has been resolved:

s390/diag: Add missing arrayindexnospec() call to memtopgetpage_count()

'level' is user space controlled and used to read from an array. Add the missing arrayindexnospec() call to prevent speculative execution.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72011.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0d30871739ab433e114b0058f08b6b1c7b816f7e
Fixed
c6b4d454865a81ceea1422243aaaedc363b6f713
Fixed
83fe36f81200b7a85f8efe0a68a4e58be84d5f64
Fixed
b7577fe4c47a31ca7c99714c53244a44af03cdfe

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72011.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.14.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72011.json"