Out-of-bounds write in Linux kernel - CVE-2026-72025
Published: August 16, 2026
Vulnerability details
The vulnerability allows a local user to cause memory corruption.
The vulnerability exists due to an out-of-bounds write in the monwriter misc device when reusing data buffers with a different data length. A local user can submit crafted records with a changed data length to cause memory corruption.
By default, access to the device is restricted to root-only permissions.
Affected software
How to mitigate CVE-2026-72025
External References
- https://git.kernel.org/stable/c/01f3ce411711c2c919598ea25320a5a48f71edbc
- https://git.kernel.org/stable/c/036bc5661060702e798d215e81bb46da530965b3
- https://git.kernel.org/stable/c/096dff1247037d329c04b3a5be0ecdfb1c5c7ac6
- https://git.kernel.org/stable/c/2995ccec260caa9e85b3301a4aba1e66ed80ad74
- https://git.kernel.org/stable/c/759d91378203ea35fa9bca6726dcf0010de081fb
- https://git.kernel.org/stable/c/ae5347f3db1782c6118f6cc0d9fd8b1d43397db3
- https://git.kernel.org/stable/c/d39cf4a6d721b1ae21eb53bbf3e8cd984253d7ab
- https://git.kernel.org/stable/c/f0745496f7c171271cafd9457df3b914a483ddeb