Information disclosure in Linux kernel - CVE-2026-72402

 

Information disclosure in Linux kernel - CVE-2026-72402

Published: August 15, 2026


Vulnerability identifier: #VU143044
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-72402
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to improper access control in the BPF verifier log output in print_bpf_insn() when printing ldimm64 instructions with pointer-bearing pseudo sources. A local user can trigger verifier logging of crafted BPF instructions to disclose sensitive information.

The issue occurs when pointer leaks are not allowed but certain pseudo source types are still resolved to kernel pointer values before the verifier log prints the instruction.


Affected software

Linux kernel
Debian Linux
linux (Debian package)

How to mitigate CVE-2026-72402

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
linux (Debian package) - update to 6.12.111-1

External References

Related Security Bulletins