๐Ÿ” CVE Alert

CVE-2026-72028

UNKNOWN 0.0

riscv: probes: save original sp in rethook trampoline

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: riscv: probes: save original sp in rethook trampoline Reading a word from the stack in a kretprobe crashes a risc-v kernel. $ cd /sys/kernel/tracing/ $ echo 'r n_tty_write $stack0' > dynamic_events $ echo 1 > events/kprobes/enable Unable to handle kernel paging request at virtual address 0000000200000128 ... [<ffffffff80016d16>] regs_get_kernel_stack_nth+0x26/0x38 [<ffffffff80177196>] process_fetch_insn+0x3ee/0x760 [<ffffffff80177836>] kretprobe_trace_func+0x116/0x1f0 [<ffffffff8017795a>] kretprobe_dispatcher+0x4a/0x58 [<ffffffff8013572e>] kretprobe_rethook_handler+0x5e/0x90 [<ffffffff80180838>] rethook_trampoline_handler+0x70/0x108 [<ffffffff8001ba32>] arch_rethook_trampoline_callback+0x12/0x1c [<ffffffff8001ba84>] arch_rethook_trampoline+0x48/0x94 [<ffffffff8067872a>] tty_write+0x1a/0x30 In regs_get_kernel_stack_nth, regs->sp contains an arbitrary value. arch_rethook_trampoline saves the registers from the probed function in a struct pt_regs. sp is not saved. Instead, sp is decremented for arch_rethook_trampoline's local stack. Fix this crash and save the original sp along with the other registers. Use a0 as a temporary register, it is overwritten anyway. [[email protected]: added Fixes tag; cc'ed stable]

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 15, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
c22b0bcb1dd024cb9caad9230e3a387d8b061df5 < 5da5cf48a432e30ded8d58087854e5383a36eff1 c22b0bcb1dd024cb9caad9230e3a387d8b061df5 < c386e1c591d72eab58ee2e69105c8cbc70928857 c22b0bcb1dd024cb9caad9230e3a387d8b061df5 < 2faf0198168d2017cb528a79f76c560fda3b6e94 c22b0bcb1dd024cb9caad9230e3a387d8b061df5 < 91b4d76dd07f1a1f20f73dfebb42ba04ac911a56 c22b0bcb1dd024cb9caad9230e3a387d8b061df5 < bc7b086a45521a986a49045907f017e3e46c763e
Linux / Linux
5.12

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/5da5cf48a432e30ded8d58087854e5383a36eff1 git.kernel.org: https://git.kernel.org/stable/c/c386e1c591d72eab58ee2e69105c8cbc70928857 git.kernel.org: https://git.kernel.org/stable/c/2faf0198168d2017cb528a79f76c560fda3b6e94 git.kernel.org: https://git.kernel.org/stable/c/91b4d76dd07f1a1f20f73dfebb42ba04ac911a56 git.kernel.org: https://git.kernel.org/stable/c/bc7b086a45521a986a49045907f017e3e46c763e