CVE-2026-72305: Linux
EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: VDUSE: avoid leaking information to userspace The bounceing is not necessarily page aligned, so current VDUSE can leak kernel information through mapping bounce pages to userspace. Allocate bounce pages with __GFP_ZERO to avoid leaking information to userspace.
Affected products
- Linux Linux: from 5.15, before 5.15.217 (fixed in 5.15.217); from 5.16, before 6.1.184 (fixed in 6.1.184); from 6.2, before 6.6.148 (fixed in 6.6.148); from 6.7, before 6.12.101 (fixed in 6.12.101); from 6.13, before 6.18.42 (fixed in 6.18.42); from 6.19, before 7.1.5 (fixed in 7.1.5)
Published 2026-08-15. Last modified 2026-08-23.