CVE-2026-72168

Source
https://cve.org/CVERecord?id=CVE-2026-72168
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72168.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72168
Downstream
Published
2026-08-15T05:53:34Z
Modified
2026-09-04T03:47:13Z
Summary
mtd: maps: vmu-flash: fix fault in unaligned fixup
Details

In the Linux kernel, the following vulnerability has been resolved:

mtd: maps: vmu-flash: fix fault in unaligned fixup

Use kzalloc_obj() / kzalloc_objs() to allocate the memcard structs, instead of kmalloc_obj() / kmalloc_objs() to prevent access to uninitialized data.

Fixes runtime error: Fault in unaligned fixup: 0000 [#1] at mtd_get_fact_prot_info.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72168.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
47a72688fae7298e1ad5fdc9bff7e04b6a549620
Fixed
01928835d80829e615a492aa66c629b953ec7bef
Fixed
19360c25135fccb6bbafbee49a5f66baf9a311af
Fixed
455519f6b70f46ac6cbf41a75ac76ec5e59040f2
Fixed
79d1661502c6e4b6f626185cef72cf2fa78116e1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72168.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.30
Fixed
6.12.101
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.42
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72168.json"