Out-of-bounds read in Linux kernel - CVE-2026-80685
Published: August 28, 2026
Vulnerability details
The vulnerability allows a local attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in snapshot_page() when processing an order-1 folio allocated at the end of a vmemmap section. A local attacker can trigger the page isolation path to cause a denial of service.
Exploitation requires an order-1 folio to be located adjacent to an absent vmemmap section.