CVE-2026-72441

Source
https://cve.org/CVERecord?id=CVE-2026-72441
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72441.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72441
Downstream
Published
2026-08-15T05:56:53.305Z
Modified
2026-08-18T03:31:18.606680965Z
Summary
ieee802154: fix kernel-infoleak in dgram_recvmsg()
Details

In the Linux kernel, the following vulnerability has been resolved:

ieee802154: fix kernel-infoleak in dgram_recvmsg()

KMSAN reported a kernel-infoleak in moveaddrto_user():

BUG: KMSAN: kernel-infoleak in instrumentcopytouser include/linux/instrumented.h:131 [inline] BUG: KMSAN: kernel-infoleak in inlinecopytouser include/linux/uaccess.h:205 [inline] BUG: KMSAN: kernel-infoleak in copytouser+0xcc/0x120 lib/usercopy.c:26 instrumentcopytouser include/linux/instrumented.h:131 [inline] inlinecopytouser include/linux/uaccess.h:205 [inline] copytouser+0xcc/0x120 lib/usercopy.c:26 copytouser include/linux/uaccess.h:236 [inline] moveaddrto_user+0x2e7/0x440 net/socket.c:302 ____sysrecvmsg+0x232/0x610 net/socket.c:2925 ... Uninit was stored to memory at: ieee802154addrtosa include/net/ieee802154netdev.h:369 [inline] dgramrecvmsg+0xa09/0xbe0 net/ieee802154/socket.c:739

The issue occurs because the pan_id field of struct ieee802154_addr is left uninitialized when the address mode is IEEE802154_ADDR_NONE. The execution flow is as follows:

  1. __ieee802154_rx_handle_packet() declares a local struct ieee802154_hdr hdr on the stack.
  2. ieee802154_hdr_pull() calls ieee802154_hdr_get_addr() to parse the source and destination addresses into this structure.
  3. If the address mode is IEEE802154_ADDR_NONE, ieee802154_hdr_get_addr() previously only set the mode field, leaving the pan_id field containing uninitialized stack memory.
  4. This uninitialized pan_id is later copied into a struct sockaddr_ieee802154 in dgram_recvmsg() via ieee802154_addr_to_sa().
  5. Finally, move_addr_to_user() copies the socket address structure to user space, leaking the uninitialized bytes.

Fix this by using memset to zero out the address structure in ieee802154_hdr_get_addr() when the mode is IEEE802154_ADDR_NONE.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72441.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
94b4f6c21cf54029377a0645675a9d81b6cf890d
Fixed
a2ee1a038a16e286d084bc293a7522d010a59ec3
Fixed
09cfe665f2c5d7a8a5ed4d6b487434a011325368
Fixed
c88e687e44cb9c7690f5039a5a5941dba1f6a204
Fixed
71b5add66c51d6764325de5f2e300bbf4f39e7a6
Fixed
fc8766467b53335220b4b594ba15bc8f8cee0c76
Fixed
de3bd9809af7555611334cb6a071806744430ef7
Fixed
f14802465f5956baafe5f4b4541eb626b06b41f1
Fixed
4db86f8ab11b5a41bfc36680be837e6ac1375ec6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72441.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.15.0
Fixed
5.10.261
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.212
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72441.json"