CVE-2026-72168: mtd: maps: vmu-flash: fix fault in unaligned fixup
In the Linux kernel, the following vulnerability has been resolved:
mtd: maps: vmu-flash: fix fault in unaligned fixup
Use kzallocobj() / kzallocobjs() to allocate the memcard structs, instead of kmallocobj() / kmallocobjs() to prevent access to uninitialized data.
Fixes runtime error: Fault in unaligned fixup: 0000 [#1] at mtdgetfactprotinfo.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Update the vmu-flash memcard struct allocation in mtd_get_fact_prot_info to use kzalloc_obj() / kzalloc_objs() rather than kmalloc_obj() / kmalloc_objs() to prevent use of uninitialized data.
Linux kernel (mtd: maps: vmu-flash) Memory allocation for memcard structs (kmalloc_obj/kmalloc_objs -> kzalloc_obj/kzalloc_objs) = Use kzalloc_obj()/kzalloc_objs() instead of kmalloc_obj()/kmalloc_objs()
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72168?
The severity of CVE-2026-72168 is classified as risk 17.
How do I fix CVE-2026-72168?
To fix CVE-2026-72168, update the Linux kernel to use kzalloc_obj() / kzalloc_objs() for allocating memcard structs.
What systems are affected by CVE-2026-72168?
CVE-2026-72168 affects systems running specific versions of the Linux kernel that implement the mtd: maps: vmu-flash functionality.
What is the impact of CVE-2026-72168?
The impact of CVE-2026-72168 could lead to a runtime error caused by accessing uninitialized data.
When was CVE-2026-72168 published?
CVE-2026-72168 was published on August 15, 2026.