CVE-2026-72357

Source
https://cve.org/CVERecord?id=CVE-2026-72357
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72357.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72357
Downstream
Published
2026-08-15T05:55:58.124Z
Modified
2026-08-18T03:56:42.422270814Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
uprobes/x86: Use proper mm_struct in __in_uprobe_trampoline
Details

In the Linux kernel, the following vulnerability has been resolved:

uprobes/x86: Use proper mm_struct in __inuprobetrampoline

In the unregister path we use __inuprobetrampoline check with current->mm for the VMA lookup, which is wrong, because we are in the tracer context, not the traced process.

Add mm_struct pointer argument to _inuprobetrampoline and changing related callers to pass proper mmstruct pointer.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72357.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
ba2bfc97b4629b10bd8d02b36e04f3932a04cac4
Fixed
c9170c83b0e0fc2065a4c2bca5bf1f90c5880156
Fixed
1acddd3e22dd6912dd5d54f80462405a1f1e6bae
Fixed
169328645663bae30e9abad4012d52441e085a71

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72357.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.18.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72357.json"