CVE-2026-72306

UnknownEPSS 0.21%

Last modified

CVE-2026-72306 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: vduse: Fix race in vduse_dev_msg_sync and vduse_dev_read_iter There is one race case in vduse_dev_msg_sync and vduse_dev_read_iter: vduse_dev_read_iter(): lock(msg_lock); dequeue_msg(send_list); unlock(msg_lock); vduse_dev_msg_sync(): wait_timeout() finish lock(msg_lock); check msg->complete is false list_del(msg); <- double list_del() crash! To fix this case, we shall ensure vduse_msg is on send_list or recv_list outside the msg_lock critical section.. EPSS estimates a 0.21% chance of exploitation in the next 30 days.

Description

In the Linux kernel, the following vulnerability has been resolved: vduse: Fix race in vduse_dev_msg_sync and vduse_dev_read_iter There is one race case in vduse_dev_msg_sync and vduse_dev_read_iter: vduse_dev_read_iter(): lock(msg_lock); dequeue_msg(send_list); unlock(msg_lock); vduse_dev_msg_sync(): wait_timeout() finish lock(msg_lock); check msg->complete is false list_del(msg); <- double list_del() crash! To fix this case, we shall ensure vduse_msg is on send_list or recv_list outside the msg_lock critical section.

Metrics

EPSS Probability
0.21%

12.2th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= c8a6153b6c59d95c0e091f053f6f180952ade91e, < c83ad3dfa6d9953d5ce6839416bf5a1bfc50285a; >= c8a6153b6c59d95c0e091f053f6f180952ade91e, < 09723f26ed801c083e914cec4cc0e1af4b933dc7; >= c8a6153b6c59d95c0e091f053f6f180952ade91e, < d7e7c813834c6c05c26033456ab7169e2f9c99eb; >= c8a6153b6c59d95c0e091f053f6f180952ade91e, < 3755965adbb617f4283ac6ccd351ed0676843cba; >= c8a6153b6c59d95c0e091f053f6f180952ade91e, < d8715b5a8fdb23fef576700e71d0c253dbeddad4; >= c8a6153b6c59d95c0e091f053f6f180952ade91e, < 8062ff9d366c4bc4ae775e14eac9a769f20c60dd; >= c8a6153b6c59d95c0e091f053f6f180952ade91e, < ae9c13b6fd79087cc5a216ee1649b6f012c2a238
LinuxLinux5.15

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-72306?
In the Linux kernel, the following vulnerability has been resolved: vduse: Fix race in vduse_dev_msg_sync and vduse_dev_read_iter There is one race case in vduse_dev_msg_sync and vduse_dev_read_iter: vduse_dev_read_iter(): lock(msg_lock); dequeue_msg(send_list); unlock(msg_lock); vduse_dev_msg_sync(): wait_timeout() finish lock(msg_lock); check msg->complete is false list_del(msg); <- double list_del() crash! To fix this case, we shall ensure vduse_msg is on send_list or recv_list outside the msg_lock critical section.
How severe is CVE-2026-72306?
Severity scoring for CVE-2026-72306 is pending analysis. The EPSS model estimates a 0.21% probability of exploitation in the next 30 days.
How do I fix CVE-2026-72306?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-72306?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST