CVE-2026-72357
7.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Summary
In the Linux kernel, the following vulnerability has been resolved:
uprobes/x86: Use proper mm_struct in __in_uprobe_trampoline
In the unregister path we use __in_uprobe_trampoline check with current->mm for the VMA lookup, which is wrong, because we are in the tracer context, not the traced process.
Add mm_struct pointer argument to __in_uprobe_trampoline and changing related callers to pass proper mm_struct pointer.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | ba2bfc97b4629b10bd8d02b36e04f3932a04cac4 < c9170c83b0e0fc2065a4c2bca5bf1f90c5880156 | affected |
| Linux | Linux | ba2bfc97b4629b10bd8d02b36e04f3932a04cac4 < 1acddd3e22dd6912dd5d54f80462405a1f1e6bae | affected |
| Linux | Linux | ba2bfc97b4629b10bd8d02b36e04f3932a04cac4 < 169328645663bae30e9abad4012d52441e085a71 | affected |
| Linux | Linux | 6.18 | affected |
| Linux | Linux | 0 < 6.18 | unaffected |
| Linux | Linux | 6.18.40 <= 6.18.* | unaffected |
| Linux | Linux | 7.1.5 <= 7.1.* | unaffected |
| Linux | Linux | 7.2 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/c9170c83b0e0fc2065a4c2bca5bf1f90c5880156
- https://git.kernel.org/stable/c/1acddd3e22dd6912dd5d54f80462405a1f1e6bae
- https://git.kernel.org/stable/c/169328645663bae30e9abad4012d52441e085a71
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.