CVE-2026-72066

Source
https://cve.org/CVERecord?id=CVE-2026-72066
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72066.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72066
Downstream
Published
2026-08-15T05:52:19Z
Modified
2026-08-21T03:30:10Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
cpu: hotplug: Bound hotplug states sysfs output
Details

In the Linux kernel, the following vulnerability has been resolved:

cpu: hotplug: Bound hotplug states sysfs output

states_show() adds CPU hotplug state names into a single sysfs buffer using sprintf(). With enough registered states, this can write past the end of the PAGE_SIZE buffer.

Use sysfs_emit_at() so output is bounded.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72066.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
98f8cdce1db580b99fce823a48eea2cb2bdb261e
Fixed
27481cf4365a6ff5c9be3590143e7ed434000266
Fixed
2408be459c70ef4250da1a9e50f5478e6b250d61
Fixed
de4d3d8ae17dc8b4cf8c59436c4b7e2dc2491635
Fixed
998f66e9ce320f3433f60b948e3698b744754a46
Fixed
61a73a123ac7a7fbc57382531f8cb7092d569aba
Fixed
6cb15b81ff545840048fb0e1a6e827d560dbf367
Fixed
631d53102da9f469c96b882b770336bec095b833
Fixed
86f436567f2516a0083b210bedc933544826a2c3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72066.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.6.0
Fixed
5.10.265
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.212
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72066.json"