CVE-2026-72011

Summary

In the Linux kernel, the following vulnerability has been resolved:

s390/diag: Add missing array_index_nospec() call to memtop_get_page_count()

'level' is user space controlled and used to read from an array. Add the missing array_index_nospec() call to prevent speculative execution.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux0d30871739ab433e114b0058f08b6b1c7b816f7e < c6b4d454865a81ceea1422243aaaedc363b6f713affected
LinuxLinux0d30871739ab433e114b0058f08b6b1c7b816f7e < 83fe36f81200b7a85f8efe0a68a4e58be84d5f64affected
LinuxLinux0d30871739ab433e114b0058f08b6b1c7b816f7e < b7577fe4c47a31ca7c99714c53244a44af03cdfeaffected
LinuxLinux6.14affected
LinuxLinux0 < 6.14unaffected
LinuxLinux6.18.40 <= 6.18.*unaffected
LinuxLinux7.1.5 <= 7.1.*unaffected
LinuxLinux7.2-rc3 <= *unaffected

Weaknesses

References