CVE-2026-72047

Source
https://cve.org/CVERecord?id=CVE-2026-72047
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72047.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72047
Downstream
Published
2026-08-15T05:52:05.510Z
Modified
2026-08-18T03:31:24.221524944Z
Summary
ieee802154: ca8210: fix pointer truncation in kfifo on 64-bit
Details

In the Linux kernel, the following vulnerability has been resolved:

ieee802154: ca8210: fix pointer truncation in kfifo on 64-bit

ca8210testintdriverwrite() and ca8210testintuserread() exchange a kmalloc'd buffer pointer through a struct kfifo, but pass a literal '4' as the byte count to kfifoin()/kfifoout().

This is correct on 32-bit (pointer = 4 bytes), but on 64-bit only the low 4 bytes of the 8-byte pointer are written into the FIFO. The reader then reads back 4 bytes into an 8-byte local pointer variable, leaving the upper 4 bytes uninitialized stack data. The first dereference of the reconstructed pointer (fifo_buffer[1]) accesses an arbitrary kernel address and generally results in an oops.

Use sizeof(fifo_buffer) so the byte count matches pointer width on every architecture.

The driver has no architecture restriction in Kconfig, so any 64-bit build with CONFIGIEEE802154CA8210_DEBUGFS=y is exposed. Issue has been latent since the driver was added in 2017 because it is most commonly deployed on 32-bit MCUs.

Found via a custom Coccinelle semantic patch hunting for short-byte kfifo I/O on byte-mode kfifos used to shuttle pointers.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72047.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
ded845a781a578dfb0b5b2c138e5a067aa3b1242
Fixed
2c1664ccfae653979b38788211240b5a1ee317ed
Fixed
093aacb0c56d5c693e3169a0224062e77c3fd0c0
Fixed
87dab14a4f68895d6f4d798e6ee3556cd64e8c72
Fixed
1fe2643d0b24ca3cdd61a31a45c2d3233dc6cbfe
Fixed
65dc342274a01616f5c17105f7360a3b4bfd7a3d
Fixed
2059c28bd725beded01277cdf1f67be33e714323
Fixed
d8ce67fa6a5e6929f5414e933ff9665176c2bce6
Fixed
6d7f7bcf225b2d566176bf6229dbd1252940cb3c

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72047.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.12.0
Fixed
5.10.261
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.212
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72047.json"