Out-of-bounds write in Linux kernel - CVE-2026-72030
Published: August 16, 2026
Vulnerability details
The vulnerability allows an attacker with physical access to cause a denial of service.
The vulnerability exists due to out-of-bounds read and out-of-bounds write in ata_dev_config_cpr() and the VPD page B9h emitter when processing a device-reported concurrent positioning ranges log. An attacker with physical access can connect a crafted device that reports an invalid concurrent positioning ranges count to cause a denial of service.
The issue can affect both parsing of the returned log data and emission of one descriptor per range into a fixed-size response buffer.
Affected software
How to mitigate CVE-2026-72030
External References
- https://git.kernel.org/stable/c/4c1e8ccd8655ee8cf1bcb1b7dfee72c9fa941fd4
- https://git.kernel.org/stable/c/4cb4b4dd8853c4ab3057efe238b2c34277772176
- https://git.kernel.org/stable/c/533a0b940f901c15e5cbbd4b5d66e871c209e8ce
- https://git.kernel.org/stable/c/b1607f0ee5f5e53e0aa66f41794085b7cc98f5d1
- https://git.kernel.org/stable/c/d43efd1b5d976203e6f1ef26f67e8b1a7bc2751b