{"id":"CVE-2026-80718","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-80718","summary":"mm/percpu-km: fix bitmap overflow and accounting in pcpu_create_chunk()","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/percpu-km: fix bitmap overflow and accounting in pcpu_create_chunk()\n\nIn pcpu_create_chunk(), nr_pages is the total contiguous backing\nallocation, i.e., nr_units * pcpu_unit_pages, but pcpu_chunk_populated()\nuses it to set chunk->populated, whose size is pcpu_unit_pages, bitmap. \nSince bit N in chunk->populated means page offset N inside every unit is\nbacked.  When nr_units > 1, the function writes beyond chunk->populated. \nFix it by using chunk->nr_pages.\n\nIt also fixes the global pcpu_nr_empty_pop_pages accounting, since\npcpu_balance_free() only iterates up to chunk->nr_pages.\n\nCommit a63d4ac4ab609 (\"percpu: make percpu-km set chunk->populated bitmap\nproperly\") introduced the bitmap overflow issue.  Later, commit\nb539b87fed37f (\"percpu: implmeent pcpu_nr_empty_pop_pages and\nchunk->nr_populated\") added pcpu_nr_empty_pop_pages and caused the\naccounting issue.","published":"2026-08-28T06:53:15.490Z","modified":"2026-08-30T03:48:21.483691267Z","cvss":{"score":7.8,"severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Linux","name":"Kernel","fixedVersion":"5.10.265"}],"fix":null,"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/01504da375f5b19df195cb1cb1cf1dd184318f97"},{"type":"WEB","url":"https://git.kernel.org/stable/c/32134cf9211b83bed9076d0739c5906fbea4c763"},{"type":"WEB","url":"https://git.kernel.org/stable/c/5c7fc39bf19abb38a996aaad77b3e3a8f48581c3"},{"type":"WEB","url":"https://git.kernel.org/stable/c/5f43d2c1bea280dcdfabaf156c25e7402fb8039f"},{"type":"WEB","url":"https://git.kernel.org/stable/c/6fc7da2a052f2825fff785e860e67183f5acaaba"},{"type":"WEB","url":"https://git.kernel.org/stable/c/89b1b79c308818a715e75f28744b70d8940a07c9"},{"type":"WEB","url":"https://git.kernel.org/stable/c/92c43ac3c2b09eb16162e8144e73c00b7c3e29d6"},{"type":"WEB","url":"https://git.kernel.org/stable/c/a6940b84c8c035da465b7165fdfcfb005545724e"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80718.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-80718"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-30T03:48:21.483691267Z"}}