AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-72181

UNKNOWN · CVSS N/A

Source: NVD + CISA KEV + EPSS · Published 2026-08-15 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel when the CONFIG_CPUMASK_OFFSTACK option is enabled, leading to potential memory corruption due to improper handling of user-provided CPU masks. This flaw can result in the overwriting of critical memory areas, which may compromise system stability and security. Organizations utilizing Linux systems with this configuration should prioritize applying the patch to mitigate the risk of exploitation.

CVE
CVE-2026-72181
Severity
UNKNOWN
CVSS
N/A
EPSS
N/A
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: mips: sched: Fix CPUMASK_OFFSTACK memory corruption This patch addresses a critical memory management flaw. When CONFIG_CPUMASK_OFFSTACK is enabled, cpumask_var_t is a pointer. Consequently, sizeof(new_mask) evaluates to the pointer size, causing copy_from_user() to clobber the mask pointer. Furthermore, the old logic performed copy_from_user() before allocating the mask. Fix this by allocating new_mask first. To handle variable-sized user masks correctly, use cpumask_size() to truncate overly large user masks or pad undersized masks with zeros before copying the data directly into the allocated buffer.