In the Linux kernel, the following vulnerability has been resolved:
posix-cpu-timers: Use u64 multiplication in updaterlimitcpu()
updaterlimitcpu() converts the RLIMIT_CPU value to nanoseconds with
u64 nsecs = rlim_new * NSEC_PER_SEC;
On 32-bit kernels both rlimnew (unsigned long) and NSECPERSEC (1000000000L) are 32-bit, so the multiplication is performed in unsigned long and truncated for rlimnew > 4 seconds before being widened to u64.
The same file already casts to u64 for the matching computation in checkprocesstimers():
u64 softns = (u64)soft * NSEC_PER_SEC;
As a result, the truncated value is installed into the CPUCLOCKPROF expiry cache (nextevt), causing the process CPU timer to be programmed to fire prematurely for any RLIMITCPU soft limit >= 5 seconds. The actual SIGXCPU/SIGKILL decision in checkprocesstimers() already casts to u64 and is therefore correct, so limit enforcement is not broken; only the expiry-cache programming is wrong. Apply the same cast here so both paths convert rlim_cur identically.
64-bit kernels are unaffected.
{
"cna_assigner": "Linux",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72068.json"
}