CVE-2026-68474

HIGHCVSS 7.8/10EPSS 0.21%

Last modified

CVE-2026-68474 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: powerpc/spufs: fix out-of-bounds access in spufs_mem_mmap_access() spufs_mem_mmap_access() computes the local store offset as address - vma->vm_start, but bounds-checks it against vma->vm_end instead of the local store size. On 64-bit, offset is always well below vma->vm_end, so the clamp never fires and len stays unbounded against the LS_SIZE buffer returned by ctx->ops->get_ls(). Reject offsets at or beyond LS_SIZE and clamp len to the remaining space, mirroring the guard already used by spufs_mem_mmap_fault() and spufs_ps_fault().. EPSS estimates a 0.21% chance of exploitation in the next 30 days.

Description

In the Linux kernel, the following vulnerability has been resolved: powerpc/spufs: fix out-of-bounds access in spufs_mem_mmap_access() spufs_mem_mmap_access() computes the local store offset as address - vma->vm_start, but bounds-checks it against vma->vm_end instead of the local store size. On 64-bit, offset is always well below vma->vm_end, so the clamp never fires and len stays unbounded against the LS_SIZE buffer returned by ctx->ops->get_ls(). Reject offsets at or beyond LS_SIZE and clamp len to the remaining space, mirroring the guard already used by spufs_mem_mmap_fault() and spufs_ps_fault().

Metrics

EPSS Probability
0.21%

11.6th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= a352894d07059649398c4769dc8b645e1a1dad88, < aa7aa8ba40c089762d821e3987aaae19e1f5705c; >= a352894d07059649398c4769dc8b645e1a1dad88, < d479a7711f8ff127946467b910d947bd971b94ed; >= a352894d07059649398c4769dc8b645e1a1dad88, < 9d3569bfdceda69d5ffd5148901e57b69954d9ef; >= a352894d07059649398c4769dc8b645e1a1dad88, < d97a8f3668949a8a9d1f6202f8c53446f2d89aa7; >= a352894d07059649398c4769dc8b645e1a1dad88, < 913feef74354c653f10ecd4631df7618a95c49c2; >= a352894d07059649398c4769dc8b645e1a1dad88, < 3c1e92f75e11a11492b8cb901fceeb9f16ae6415; >= a352894d07059649398c4769dc8b645e1a1dad88, < 4efa313b15925bdd864784865d6585174979294b; >= a352894d07059649398c4769dc8b645e1a1dad88, < 47b87f469a35b5ffc81c16eee6b13a9b6c8d55c6
LinuxLinux2.6.27

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-68474?
In the Linux kernel, the following vulnerability has been resolved: powerpc/spufs: fix out-of-bounds access in spufs_mem_mmap_access() spufs_mem_mmap_access() computes the local store offset as address - vma->vm_start, but bounds-checks it against vma->vm_end instead of the local store size. On 64-bit, offset is always well below vma->vm_end, so the clamp never fires and len stays unbounded against the LS_SIZE buffer returned by ctx->ops->get_ls(). Reject offsets at or beyond LS_SIZE and clamp len to the remaining space, mirroring the guard already used by spufs_mem_mmap_fault() and spufs_ps_fault().
How severe is CVE-2026-68474?
CVE-2026-68474 has a CVSS score of 7.8/10 (HIGH severity). The EPSS model estimates a 0.21% probability of exploitation in the next 30 days.
How do I fix CVE-2026-68474?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-68474?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST