CVE-2026-72011: s390/diag: Add missing array_index_nospec() call to memtop_get_page_count()
Published Aug 15, 2026
·Updated
In the Linux kernel, the following vulnerability has been resolved:
s390/diag: Add missing arrayindexnospec() call to memtopgetpagecount()
'level' is user space controlled and used to read from an array. Add the missing arrayindexnospec() call to prevent speculative execution.
Affected Software
1 affected component
Linux Linux kernel
Event History
Aug 15, 2026
CVE Published
via MITRE·05:51 AM
Data Sourced
via MITRE·05:51 AM
Description
Data Sourced
via NVD·06:20 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2026-72011?
CVE-2026-72011 has a risk rating of 37.
2
How do I fix CVE-2026-72011?
To fix CVE-2026-72011, ensure that your Linux kernel is updated to the latest version that includes the fix for this vulnerability.
3
What does CVE-2026-72011 affect?
CVE-2026-72011 affects the Linux kernel, specifically regarding the memtop_get_page_count() function in s390/diag.
4
What is the main issue addressed by CVE-2026-72011?
CVE-2026-72011 addresses a missing array_index_nospec() call that could lead to speculative execution vulnerabilities.
5
When was CVE-2026-72011 published?
CVE-2026-72011 was published on August 15, 2026.