CVE-2026-72018

Summary

In the Linux kernel, the following vulnerability has been resolved:

dibs: loopback: validate offset and size in move_data()

The loopback move_data() performs a memcpy into the registered DMB without checking whether offset + size exceeds the DMB length. Unlike real ISM hardware, which enforces memory region bounds natively, the software loopback has no such protection.

A peer-supplied out-of-bounds offset or oversized write would result in an OOB write past the allocated kernel buffer. Add an explicit bounds check before the memcpy to reject such requests with -EINVAL.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxf7a22071dbf316c982fb44308874bd7ad9ac2091 < ee188a6b264b71315a67f1b9470faad308b730d2affected
LinuxLinuxf7a22071dbf316c982fb44308874bd7ad9ac2091 < b2f426a9a22886071966432ede8fceafffe12b8caffected
LinuxLinuxf7a22071dbf316c982fb44308874bd7ad9ac2091 < 94fe0ab01b480b52bd8f977edbd845ef375d69fdaffected
LinuxLinuxf7a22071dbf316c982fb44308874bd7ad9ac2091 < 78237e3c0720fcc6eb9b87e90fd70f63eeca886faffected
LinuxLinux6.10affected
LinuxLinux0 < 6.10unaffected
LinuxLinux6.12.97 <= 6.12.*unaffected
LinuxLinux6.18.40 <= 6.18.*unaffected
LinuxLinux7.1.5 <= 7.1.*unaffected
LinuxLinux7.2-rc3 <= *unaffected

Weaknesses

References