Memory corruption in Linux kernel - CVE-2026-80916
Published: September 9, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper handling of allocation failure in KCOV initialization and remote-start handling when remote KCOV collection is initiated after initialization buffer allocation fails. A local user can invoke remote KCOV collection from a non-task context to cause a denial of service.
Out-of-bounds access requires the configured remote coverage size to be smaller than CONFIG_KCOV_IRQ_AREA_SIZE.
Affected software
How to mitigate CVE-2026-80916
External References
- https://git.kernel.org/stable/c/18799e858b407bf355383c9dd6c06477aa437134
- https://git.kernel.org/stable/c/22670d1552fe155822b2abf91f920925f7d067b4
- https://git.kernel.org/stable/c/2eed77fdcb0cc48e8eccb2bcd4b7f2c6d650e84c
- https://git.kernel.org/stable/c/5dc59fc959b2b5742985d7ef24bccd1868217dc2
- https://git.kernel.org/stable/c/8ed3ddf23d39bf5338406bd9f8863d44748cf6ce
- https://git.kernel.org/stable/c/a2fb8222cde23b0001812ed3acb7c0ea36dd94e2
- https://git.kernel.org/stable/c/e11f5b48c82703242a3be7a7ae4b4940b4cb4610
- https://git.kernel.org/stable/c/ef7048d8a614c5f5a9b20513a5428101a744514e
- https://git.kernel.org/stable/c/f8c9a3ec36b4ee3d4701b9be08f40e7bfbf89761