In the Linux kernel, the following vulnerability has been resolved:
mips: sched: Fix CPUMASK_OFFSTACK memory corruption
This patch addresses a critical memory management flaw. When
CONFIG_CPUMASK_OFFSTACK is enabled, cpumask_var_t is a pointer.
Consequently, sizeof(new_mask) evaluates to the pointer size, causing
copy_from_user() to clobber the mask pointer. Furthermore, the old
logic performed copy_from_user() before allocating the mask.
Fix this by allocating new_mask first. To handle variable-sized user
masks correctly, use cpumask_size() to truncate overly large user masks
or pad undersized masks with zeros before copying the data directly into
the allocated buffer.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-15 06:21
Updated : 2026-08-19 17:21
NVD link : CVE-2026-72181
Mitre link : CVE-2026-72181
CVE.ORG link : CVE-2026-72181
JSON object : View
Products Affected
No product.
CWE
No CWE.
