SB2026090576 - Incorrect calculation in Linux kernel trace
Published: September 5, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Incorrect calculation (CVE-ID: CVE-2026-80876)
CWE-ID: CWE-682 - Incorrect Calculation
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause incorrect ring-buffer event data length reporting.
The vulnerability exists due to an improper length calculation in ring_buffer_event_length() when handling small ring-buffer events on architectures with forced 8-byte alignment. A local user can trigger processing of small ring-buffer events to cause incorrect ring-buffer event data length reporting.
The issue was observed on a riscv64 kernel with CONFIG_HAVE_64BIT_ALIGNED_ACCESS enabled.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/14057268e79654c3e8ea2c9b5204cb9644b2964d
- https://git.kernel.org/stable/c/24c3fa71f9947b0e1f3b954db1b769b44140192e
- https://git.kernel.org/stable/c/3a63a11897c7ba32d1be7a3fdbc48a8b01cf4992
- https://git.kernel.org/stable/c/7c9f0ccf9f04142458d2ac3d39414f4acae242f0
- https://git.kernel.org/stable/c/c37e0a4b79a6bbb96ce5ffe279d7c001e20529e0
- https://git.kernel.org/stable/c/cfada73fabe2ccc06ec77fe2ceaa088689213326
- https://git.kernel.org/stable/c/dbcb8635b1eb7603818591cf745c7b1d714f7ac6
- https://git.kernel.org/stable/c/ec5e96aee75d27779b9a860307679f13f33adb0c