7.8

CVE-2026-80718

mm/percpu-km: fix bitmap overflow and accounting in pcpu_create_chunk()

In the Linux kernel, the following vulnerability has been resolved:

mm/percpu-km: fix bitmap overflow and accounting in pcpu_create_chunk()

In pcpu_create_chunk(), nr_pages is the total contiguous backing
allocation, i.e., nr_units * pcpu_unit_pages, but pcpu_chunk_populated()
uses it to set chunk->populated, whose size is pcpu_unit_pages, bitmap. 
Since bit N in chunk->populated means page offset N inside every unit is
backed.  When nr_units > 1, the function writes beyond chunk->populated. 
Fix it by using chunk->nr_pages.

It also fixes the global pcpu_nr_empty_pop_pages accounting, since
pcpu_balance_free() only iterates up to chunk->nr_pages.

Commit a63d4ac4ab609 ("percpu: make percpu-km set chunk->populated bitmap
properly") introduced the bitmap overflow issue.  Later, commit
b539b87fed37f ("percpu: implmeent pcpu_nr_empty_pop_pages and
chunk->nr_populated") added pcpu_nr_empty_pop_pages and caused the
accounting issue.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version a63d4ac4ab6094c051a5a240260d16117a7a2f86
Version < 5f43d2c1bea280dcdfabaf156c25e7402fb8039f
Status affected
Version a63d4ac4ab6094c051a5a240260d16117a7a2f86
Version < 92c43ac3c2b09eb16162e8144e73c00b7c3e29d6
Status affected
Version a63d4ac4ab6094c051a5a240260d16117a7a2f86
Version < 6fc7da2a052f2825fff785e860e67183f5acaaba
Status affected
Version a63d4ac4ab6094c051a5a240260d16117a7a2f86
Version < 01504da375f5b19df195cb1cb1cf1dd184318f97
Status affected
Version a63d4ac4ab6094c051a5a240260d16117a7a2f86
Version < a6940b84c8c035da465b7165fdfcfb005545724e
Status affected
Version a63d4ac4ab6094c051a5a240260d16117a7a2f86
Version < 32134cf9211b83bed9076d0739c5906fbea4c763
Status affected
Version a63d4ac4ab6094c051a5a240260d16117a7a2f86
Version < 5c7fc39bf19abb38a996aaad77b3e3a8f48581c3
Status affected
Version a63d4ac4ab6094c051a5a240260d16117a7a2f86
Version < 89b1b79c308818a715e75f28744b70d8940a07c9
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 3.18
Status affected
Version 0
Version < 3.18
Status unaffected
Version <= 5.10.*
Version 5.10.265
Status unaffected
Version <= 5.15.*
Version 5.15.216
Status unaffected
Version <= 6.1.*
Version 6.1.183
Status unaffected
Version <= 6.6.*
Version 6.6.151
Status unaffected
Version <= 6.12.*
Version 6.12.103
Status unaffected
Version <= 6.18.*
Version 6.18.44
Status unaffected
Version <= 7.1.*
Version 7.1.8
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.12% 0.021
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/5f43d2c1bea280dcdfabaf156c25e7402fb8039f
https://git.kernel.org/stable/c/92c43ac3c2b09eb16162e8144e73c00b7c3e29d6
https://git.kernel.org/stable/c/6fc7da2a052f2825fff785e860e67183f5acaaba
https://git.kernel.org/stable/c/01504da375f5b19df195cb1cb1cf1dd184318f97
https://git.kernel.org/stable/c/a6940b84c8c035da465b7165fdfcfb005545724e
https://git.kernel.org/stable/c/32134cf9211b83bed9076d0739c5906fbea4c763
https://git.kernel.org/stable/c/5c7fc39bf19abb38a996aaad77b3e3a8f48581c3
https://git.kernel.org/stable/c/89b1b79c308818a715e75f28744b70d8940a07c9