PT-2026-84928 · Linux · Linux
CVE-2026-80730
·
Publicado
2026-09-03
·
Atualizado
2026-09-03
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
ring-buffer: Fix crash passing ERR PTR to kthread stop()
In test ringbuffer()'s out free cleanup loop, the check
!rb threads[cpu] only catches NULL entries and misses entries that
hold an ERR PTR.rb threads[] is static, so unassigned slots are NULL. But when
kthread run on cpu() fails for a cpu, it stores ERR PTR(-ENOMEM) (or
-EINTR) in rb threads[cpu] before the creation loop jumps to out free.
That entry is non-NULL, so the old
!ptr check does not break, and the
cleanup proceeds to call kthread stop() on the ERR PTR. kthread stop()
then dereferences the bogus pointer, crashing the kernel during the
late initcall self-test.crash logs:
BUG: kernel NULL pointer dereference, address: 000000000000001c
Oops: 0002 [#1] SMP NOPTI
CPU: 1 PID: 1 Comm: swapper/0 Not tainted 7.2.0-rc6-dirty #7 PREEMPT(lazy)
RIP: 0010:kthread stop+0x2e/0x220
RBX: fffffffffffffff4
CR2: 000000000000001c
Call Trace:
test ringbuffer+0x1ec/0x650
do one initcall+0x6c/0x2c0
kernel init freeable+0x21d/0x420
kernel init+0x15/0x1c0
ret from fork+0x21b/0x320
Kernel panic - not syncing: Fatal exception
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux