CVE-2026-68187
Last modified
CVE-2026-68187 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: exec: fix unsigned loop counter wrap in transfer_args_to_stack() The stop value is derived from bprm->p >> PAGE_SHIFT. The index variable is an unsigned long.
Description
In the Linux kernel, the following vulnerability has been resolved: exec: fix unsigned loop counter wrap in transfer_args_to_stack() The stop value is derived from bprm->p >> PAGE_SHIFT. The index variable is an unsigned long. If bprm->p drops below PAGE_SIZE and stop becomes zero the loop condition index >= stop is always true. After the index == 0 iteration the decrement wraps to ULONG_MAX and bprm->page[ULONG_MAX] reads sizeof(void *) bytes in front of the array. The pointer has wrapped to -1. That garbage pointer is then passed to kmap_local_page() and PAGE_SIZE bytes are copied from wherever that lands into the stack of the process being created. And the loop doesn't terminate either... Getting there only requires bprm->p < PAGE_SIZE. On !MMU bprm_set_stack_limit() and bprm_hit_stack_limit() are empty. So the only constraint on how far bprm->p is pushed down is valid_arg_len(), i.e. that each individual string still fits in what is left. bprm->p starts at PAGE_SIZE * MAX_ARG_PAGES - sizeof(void *) so a single argument or environment string of a little over 31 pages leaves it in the first page: Oops - load access fault [#1] CPU: 0 UID: 0 PID: 1 Comm: victim Not tainted 7.2.0-rc4 #1 epc : __memcpy+0xd4/0xf8 ra : transfer_args_to_stack+0xaa/0xae s4 : ffffffffffffffff s2 : 0000000000000000 a1 : ffffffdc98000000 a2 : 0000000000001000 status: 0000000a00001880 badaddr: ffffffdc98000000 cause: 0000000000000005 [<801a5324>] __memcpy+0xd4/0xf8 [<800d5f6a>] load_flat_binary+0x43a/0x65e [<800a2de4>] bprm_execve+0x1d4/0x316 [<800a351a>] do_execveat_common+0x12e/0x138 [<800a3d44>] __riscv_sys_execve+0x38/0x4e Kernel panic - not syncing: Fatal exception in interrupt This is an arcane bug but we should still fix it. Count down from MAX_ARG_PAGES so the loop ends when index reaches stop, stop == 0 included. The iterations performed are unchanged for every other value of stop. Only CONFIG_MMU=n builds are affected, transfer_args_to_stack() is used by binfmt_flat and binfmt_elf_fdpic on nommu only. The loop predates git history. commit 7e7ec6a93434 ("elf_fdpic_transfer_args_to_stack(): make it generic") only moved it from binfmt_elf_fdpic.c into fs/exec.c and narrowed the copy to the used part of the first page. The condition and the decrement are unchanged from 2.6.12-rc2.
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2, < c62bb00caba66e01fb578d5f0302f247dc64930a; >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2, < dfc2a00742af4cb7251c1a8fbce4fbae3cc0de4e; >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2, < 2bc6bf70d41055377f390d06f0f3521deb62fd3b; >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2, < 55fa2c7f2b15583d1a2fe1b5abcc24377359339f; >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2, < 16cc4f5c1c4b9e45eca7f7deefa5410a292db599 |
| Linux | Linux | 2.6.12 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-68187?
How severe is CVE-2026-68187?
How do I fix CVE-2026-68187?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-68181In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68182In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68183In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68184In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68185In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68186In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68188In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68189In the Linux kernel, the following vulnerability has been re…
- CVE-2026-6819HKUDS OpenHarness prior to PR #156 remediation exposes plugi…8.8
- CVE-2026-68190In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68191In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68192In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2026-68187?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
