CVE-2026-72181

Source
https://cve.org/CVERecord?id=CVE-2026-72181
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72181.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72181
Downstream
Published
2026-08-15T05:53:44Z
Modified
2026-08-21T03:30:21Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
mips: sched: Fix CPUMASK_OFFSTACK memory corruption
Details

In the Linux kernel, the following vulnerability has been resolved:

mips: sched: Fix CPUMASK_OFFSTACK memory corruption

This patch addresses a critical memory management flaw. When CONFIG_CPUMASK_OFFSTACK is enabled, cpumask_var_t is a pointer. Consequently, sizeof(new_mask) evaluates to the pointer size, causing copy_from_user() to clobber the mask pointer. Furthermore, the old logic performed copy_from_user() before allocating the mask.

Fix this by allocating new_mask first. To handle variable-sized user masks correctly, use cpumask_size() to truncate overly large user masks or pad undersized masks with zeros before copying the data directly into the allocated buffer.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72181.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
295cbf6d63165fe4253cf1d9ceadcda47a318b48
Fixed
2f7730c03a9deea3ba7a1c980070d363b4ea2046
Fixed
d20ee42f8226607b5693b2bc2f115ca2d270221a
Fixed
15ba8053fe4162c933855f1676fb321cdb6251c7
Fixed
3446ffb5d03c36f9ce88ede7ca5be319a2968d96
Fixed
87a56c1e8e36d06ebe8640432f911538ded7827d
Fixed
1caee6e084a96ada94658f261ced377d85af3f03
Fixed
a1dd41d00c57efb1fbc6f361c5f48c9d00cca51c
Fixed
98e37db4a34d3af3fb2f4648295c25b5e40b20e3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72181.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.23
Fixed
5.10.265
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.212
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72181.json"