Answer in brief
CVE-2026-72305 records a Unknown severity vulnerability in VDUSE: avoid leaking information to userspace. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=8c773d53fb7b64267b0f55c1d3517cb8c5e29b3c <fde25641cbddd0c084e3320d08f755e7e6acfae5 || >=8c773d53fb7b64267b0f55c1d3517cb8c5e29b3c <5e88c1bc3a41d9a260dd42bae8ad18fd4f35bbe1 || >=8c773d53fb7b64267b0f55c1d3517cb8c5e29b3c <690fb82c4122f8c2656fa4f842275132771b68b9 || >=8c773d53fb7b64267b0f55c1d3517cb8c5e29b3c <00335df9da2011e095f846d645cc2e9fd2907659 || >=8c773d53fb7b64267b0f55c1d3517cb8c5e29b3c <9c1523803445ee0348f62b77793266dd981596e0 | fde25641cbddd0c084e3320d08f755e7e6acfae5, 5e88c1bc3a41d9a260dd42bae8ad18fd4f35bbe1, 690fb82c4122f8c2656fa4f842275132771b68b9, 00335df9da2011e095f846d645cc2e9fd2907659, 9c1523803445ee0348f62b77793266dd981596e0 |
| Linux/Linuxgeneric | 5.15 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: VDUSE: avoid leaking information to userspace The bounceing is not necessarily page aligned, so current VDUSE can leak kernel information through mapping bounce pages to userspace. Allocate bounce pages with __GFP_ZERO to avoid leaking information to userspace.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-72305 records a Unknown severity vulnerability in VDUSE: avoid leaking information to userspace. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=8c773d53fb7b64267b0f55c1d3517cb8c5e29b3c <fde25641cbddd0c084e3320d08f755e7e6acfae5 || >=8c773d53fb7b64267b0f55c1d3517cb8c5e29b3c <5e88c1bc3a41d9a260dd42bae8ad18fd4f35bbe1 || >=8c773d53fb7b64267b0f55c1d3517cb8c5e29b3c <690fb82c4122f8c2656fa4f842275132771b68b9 || >=8c773d53fb7b64267b0f55c1d3517cb8c5e29b3c <00335df9da2011e095f846d645cc2e9fd2907659 || >=8c773d53fb7b64267b0f55c1d3517cb8c5e29b3c <9c1523803445ee0348f62b77793266dd981596e0 | fde25641cbddd0c084e3320d08f755e7e6acfae5, 5e88c1bc3a41d9a260dd42bae8ad18fd4f35bbe1, 690fb82c4122f8c2656fa4f842275132771b68b9, 00335df9da2011e095f846d645cc2e9fd2907659, 9c1523803445ee0348f62b77793266dd981596e0 |
| Linux/Linuxgeneric | 5.15 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: VDUSE: avoid leaking information to userspace The bounceing is not necessarily page aligned, so current VDUSE can leak kernel information through mapping bounce pages to userspace. Allocate bounce pages with __GFP_ZERO to avoid leaking information to userspace.
Quoted source text, attributed separately from HOL analysis.