VDUSE: avoid leaking information to userspace

Summary

CVECVE-2026-72305
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-08-15 06:22:03 UTC
Updated2026-08-23 13:16:43 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: VDUSE: avoid leaking information to userspace The bounceing is not necessarily page aligned, so current VDUSE can leak kernel information through mapping bounce pages to userspace. Allocate bounce pages with __GFP_ZERO to avoid leaking information to userspace.

Risk And Classification

EPSS: 0.002000000 probability, percentile 0.101960000 (date 2026-08-17)

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 8c773d53fb7b64267b0f55c1d3517cb8c5e29b3c 41e27a6aca608c9e04f091c29c420d03fafe0313 git Not specified
CNA Linux Linux affected 8c773d53fb7b64267b0f55c1d3517cb8c5e29b3c 3ae878f262bd1445c8c31511856a99962a05fe16 git Not specified
CNA Linux Linux affected 8c773d53fb7b64267b0f55c1d3517cb8c5e29b3c fde25641cbddd0c084e3320d08f755e7e6acfae5 git Not specified
CNA Linux Linux affected 8c773d53fb7b64267b0f55c1d3517cb8c5e29b3c 5e88c1bc3a41d9a260dd42bae8ad18fd4f35bbe1 git Not specified
CNA Linux Linux affected 8c773d53fb7b64267b0f55c1d3517cb8c5e29b3c 690fb82c4122f8c2656fa4f842275132771b68b9 git Not specified
CNA Linux Linux affected 8c773d53fb7b64267b0f55c1d3517cb8c5e29b3c 00335df9da2011e095f846d645cc2e9fd2907659 git Not specified
CNA Linux Linux affected 8c773d53fb7b64267b0f55c1d3517cb8c5e29b3c 9c1523803445ee0348f62b77793266dd981596e0 git Not specified
CNA Linux Linux affected 5.15 Not specified
CNA Linux Linux unaffected 5.15 semver Not specified
CNA Linux Linux unaffected 5.15.217 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.184 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.148 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.101 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.42 6.18.* semver Not specified
CNA Linux Linux unaffected 7.1.5 7.1.* semver Not specified
CNA Linux Linux unaffected 7.2 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/fde25641cbddd0c084e3320d08f755e7e6acfae5 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/41e27a6aca608c9e04f091c29c420d03fafe0313 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/3ae878f262bd1445c8c31511856a99962a05fe16 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/690fb82c4122f8c2656fa4f842275132771b68b9 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/00335df9da2011e095f846d645cc2e9fd2907659 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/9c1523803445ee0348f62b77793266dd981596e0 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/5e88c1bc3a41d9a260dd42bae8ad18fd4f35bbe1 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report