Out-of-bounds read in Linux kernel - CVE-2026-72135
Published: August 16, 2026
Vulnerability details
The vulnerability allows a local user to disclose sensitive information and corrupt kernel memory.
The vulnerability exists due to an out-of-bounds read and out-of-bounds write in the TPM character device read path when processing positional read operations with a pending response. A local user can issue a crafted pread request with a large offset to disclose sensitive information and corrupt kernel memory.
The issue affects the sequential command/response TPM device interface after a command has left a response pending.
Affected software
openEuler
kernel
bpftool
bpftool-debuginfo
kernel-debuginfo
kernel-debugsource
kernel-devel
kernel-headers
kernel-source
kernel-tools
kernel-tools-debuginfo
kernel-tools-devel
perf
perf-debuginfo
python3-perf
python3-perf-debuginfo
How to mitigate CVE-2026-72135
kernel - update to 5.10.0-330.0.0.231
bpftool - update to 5.10.0-330.0.0.231
bpftool-debuginfo - update to 5.10.0-330.0.0.231
kernel-debuginfo - update to 5.10.0-330.0.0.231
kernel-debugsource - update to 5.10.0-330.0.0.231
kernel-devel - update to 5.10.0-330.0.0.231
kernel-headers - update to 5.10.0-330.0.0.231
kernel-source - update to 5.10.0-330.0.0.231
kernel-tools - update to 5.10.0-330.0.0.231
kernel-tools-debuginfo - update to 5.10.0-330.0.0.231
kernel-tools-devel - update to 5.10.0-330.0.0.231
perf - update to 5.10.0-330.0.0.231
perf-debuginfo - update to 5.10.0-330.0.0.231
python3-perf - update to 5.10.0-330.0.0.231
python3-perf-debuginfo - update to 5.10.0-330.0.0.231
External References
- https://git.kernel.org/stable/c/21a13f932972bc9836f58c44fcd47c62abdecd95
- https://git.kernel.org/stable/c/232dcf908eb7eb9d8046a9597975caf44270966e
- https://git.kernel.org/stable/c/947b773caaa548672184df025271b29bdc80b0f1
- https://git.kernel.org/stable/c/9c513dabd4540f811585a2087f23069767a284da
- https://git.kernel.org/stable/c/ada4b9a5087ea7f30dd8e4c6411a4fb6547eb1ed
- https://git.kernel.org/stable/c/dda695fab5e21f923d29e8cb01df256468ddfbd1
- https://git.kernel.org/stable/c/ed0ffc2c016629e40ba041ed0424a772d8b02e2c
- https://git.kernel.org/stable/c/f20d61c22bcaf172d6790b6500e3838e532e71c8