SB2026090993 - Memory corruption in Linux kernel lib
Published: September 9, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Memory corruption (CVE-ID: CVE-2026-80916)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper handling of allocation failure in KCOV initialization and remote-start handling when remote KCOV collection is initiated after initialization buffer allocation fails. A local user can invoke remote KCOV collection from a non-task context to cause a denial of service.
Out-of-bounds access requires the configured remote coverage size to be smaller than CONFIG_KCOV_IRQ_AREA_SIZE.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/18799e858b407bf355383c9dd6c06477aa437134
- https://git.kernel.org/stable/c/22670d1552fe155822b2abf91f920925f7d067b4
- https://git.kernel.org/stable/c/2eed77fdcb0cc48e8eccb2bcd4b7f2c6d650e84c
- https://git.kernel.org/stable/c/5dc59fc959b2b5742985d7ef24bccd1868217dc2
- https://git.kernel.org/stable/c/8ed3ddf23d39bf5338406bd9f8863d44748cf6ce
- https://git.kernel.org/stable/c/a2fb8222cde23b0001812ed3acb7c0ea36dd94e2
- https://git.kernel.org/stable/c/e11f5b48c82703242a3be7a7ae4b4940b4cb4610
- https://git.kernel.org/stable/c/ef7048d8a614c5f5a9b20513a5428101a744514e
- https://git.kernel.org/stable/c/f8c9a3ec36b4ee3d4701b9be08f40e7bfbf89761