Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-80916— kcov: fix data corruption and race conditions on PREEMPT_RT

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,以下漏洞已被修复: kcov:修复 PREEMPT_RT 上的数据损坏和竞争条件 syzbot 报告了在 PREEMPT_RT 内核上出现 KCOV 状态损坏的问题。原因是用于保存/恢复远程 KCOV 状态的临时存储空间当前被分配为 per-CPU(每 CPU)区域。 在 PREEMPT_RT 内核中,软中断处理程序(softirq handlers)作为可抢占的任务线程运行(例如 ksoftirqd)。如果一个软中断上下文抢占了一个正在运行远程 KCOV 会话的任务,它会安全地将该任务的状

AI Predicted 5.5 Difficulty: Moderate

Affected Version Matrix 20

VendorProduct Version RangeStatus
Linux Linux 5ff3b30ab57da82d8db4f14662a2858cabfbc2c0< ef7048d8a614c5f5a9b20513a5428101a744514e affected
5ff3b30ab57da82d8db4f14662a2858cabfbc2c0< 8ed3ddf23d39bf5338406bd9f8863d44748cf6ce affected
5ff3b30ab57da82d8db4f14662a2858cabfbc2c0< 5dc59fc959b2b5742985d7ef24bccd1868217dc2 affected
5ff3b30ab57da82d8db4f14662a2858cabfbc2c0< a2fb8222cde23b0001812ed3acb7c0ea36dd94e2 affected
5ff3b30ab57da82d8db4f14662a2858cabfbc2c0< 18799e858b407bf355383c9dd6c06477aa437134 affected
5ff3b30ab57da82d8db4f14662a2858cabfbc2c0< e11f5b48c82703242a3be7a7ae4b4940b4cb4610 affected
5ff3b30ab57da82d8db4f14662a2858cabfbc2c0< 22670d1552fe155822b2abf91f920925f7d067b4 affected
5ff3b30ab57da82d8db4f14662a2858cabfbc2c0< f8c9a3ec36b4ee3d4701b9be08f40e7bfbf89761 affected
… +12 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-80916

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
kcov: fix data corruption and race conditions on PREEMPT_RT
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: kcov: fix data corruption and race conditions on PREEMPT_RT syzbot is reporting KCOV state corruption on PREEMPT_RT kernels, for the temporary storage used for saving/restoring remote KCOV state is currently allocated as the per-CPU area. On PREEMPT_RT kernels, softirq handlers run as preemptible task threads (e.g., ksoftirqd). If a softirq context preempts a task running a remote KCOV session, it safely saves the task's state into the per-CPU area. However, if that softirq thread is subsequently preempted by a higher- priority softirq thread on the same CPU, the second softirq will overwrite the same per-CPU area, permanently destroying the original task's KCOV state. Fix this data corruption by moving the temporary storage from the per-CPU area to the per-thread area. Since each softirq thread now owns its own task context, nested softirq preemption no longer causes data overwrites. Note that while the temporary storage is now on a per-thread basis, the per-CPU kcov_percpu_data.lock must be retained, for we need to ensure that kcov_remote_start() and kcov_remote_stop() operate atomically without racing against asynchronous interrupts that manipulate the current task's KCOV state. It is likely that GFP_KERNEL allocation by vmalloc_node() in kcov_init() has already called panic() before returning NULL, for there will be no OOM-killable userspace processes when __init function of built-in module runs. But this patch also fixes crashing the kernel when vmalloc_node() in kcov_init() returned NULL, for kcov_init() left per-CPU irq_area == NULL but kcov_remote_start() depends on per-CPU irq_area != NULL, resulting in (1) doing vmalloc() in kcov_remote_start() despite !in_task() context (2) out-of-array-bounds access if (1) succeeded but kcov->remote_size < CONFIG_KCOV_IRQ_AREA_SIZE (3) always leak memory allocated by (1), eventually killing all OOM-killable userspace processes problems.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 5ff3b30ab57da82d8db4f14662a2858cabfbc2c0 ~ ef7048d8a614c5f5a9b20513a5428101a744514e -
Linux Linux 5.8 -

II. Public POCs for CVE-2026-80916

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-80916

登录查看更多情报信息。

Patches & Fixes for CVE-2026-80916 (8)

Other References for CVE-2026-80916 (1)

Same Patch Batch · Linux · 2026-09-09 · 12 CVEs total

CVE-2026-80925 vlan: fix skb_under_panic and races when toggling HW VLAN offload
CVE-2026-80924 crypto: krb5 - use kfree_sensitive() for derived key buffers
CVE-2026-80923 xhci: dbgtty: Fix unregister on tty_register_driver() failure
CVE-2026-80922 crypto: qcom-rng - Allow zero as a random number
CVE-2026-80921 KVM: s390: vsie: zero stale crypto bits
CVE-2026-80920 io_uring: defer eventfd signaling when queued from a wakeup handler
CVE-2026-80919 drm/amdgpu: fix recursive ww_mutex acquire in amdgpu_devcoredump_format
CVE-2026-80918 HID: core: fix number/pointer type confusion on long items
CVE-2026-80917 PCI: host-generic: Fix NULL pointer dereference on 32-bit CAM systems
CVE-2026-80915 drm/xe: Fix DPT allocation paths.
CVE-2026-80914 Bluetooth: ISO: fix use-after-free of listener socket in iso_conn_ready

IV. Related Vulnerabilities

V. Comments for CVE-2026-80916

No comments yet


Leave a comment