Out-of-bounds write in Linux kernel - CVE-2026-72380
Published: August 15, 2026
Vulnerability details
The vulnerability allows a local user to cause memory corruption.
The vulnerability exists due to an out-of-bounds write in pvcalls_front_event_handler() when processing a backend-supplied ring response with an out-of-range req_id. A local user can supply a crafted backend response to cause memory corruption.
The issue affects the Xen pvcalls frontend in deployments where the frontend does not trust its backend.
Affected software
Ubuntu
linux-nvidia-tegra (Ubuntu package)
How to mitigate CVE-2026-72380
linux-nvidia-tegra (Ubuntu package) - update to 6.8.0-1035.38