Improper control of a resource through its lifetime in Linux kernel - #VU134242
Published: June 10, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper handling of scratch-buffer reuse in extract_iter_to_sg in lib/scatterlist.c when extracting a user buffer into a scatterlist that already contains entries. A local user can supply a user buffer while reusing a populated scatterlist to cause a denial of service.
The issue occurs only when the scatterlist already contains existing entries before extraction begins.
Remediation
Sources
- https://git.kernel.org/stable/c/07b7d66e65d9cfe6b9c2c34aa22cfcaac37a5c45
- https://git.kernel.org/stable/c/3f17500e86d730c76db638bb3ae52f9b5e496c76
- https://git.kernel.org/stable/c/8fbba6829057979149d1b37d65690c037f3ddf4d
- https://git.kernel.org/stable/c/9d38756d0a93b66163554219fa9c3365f40c4035
- https://git.kernel.org/stable/c/e5e22fc9963469e678c4f4bb38d26adcec107f1e