๐Ÿ” CVE Alert

CVE-2026-80876

UNKNOWN 0.0

ring-buffer: Fix event length with forced 8-byte alignment

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Fix event length with forced 8-byte alignment When RB_FORCE_8BYTE_ALIGNMENT is true, rb_calculate_event_length() reserves the space of event->array[0] for placing the data length and rb_update_event() stores the data length in event->array[0] accordingly. As a result the whole event length will add extra 4 bytes for sizeof(event.array[0]) unconditionally. But ring_buffer_event_length() only subtracts the sizeof(event->array[0]) for events larger than RB_MAX_SMALL_DATA + sizeof(event->array[0]). As a result, small events on architectures with RB_FORCE_8BYTE_ALIGNMENT=true report a data length that is 4 bytes larger than expected. To fix it, add the RB_FORCE_8BYTE_ALIGNMENT as a condition to subtract the size of that length field whenever RB_FORCE_8BYTE_ALIGNMENT is true. This issue is observed in a riscv64 kernel with CONFIG_HAVE_64BIT_ALIGNED_ACCESS set to y, when we run ftrace selftest trace_marker_raw.tc, we get the weird log: for cases where the id is 1..100, the number of data field is 8*N, but once id exceeds 100, the number of data field becomes 8*N+4: # 1 buf: 58 00 00 00 80 5e d1 63 (number of data field is 8*1) ... # a buf: 58 ... (number of data field is 8*2) ... # 64 buf: 58 ... (number of data field is 8*13) # 65 buf: 58 ... (number of data field is 8*13+4) After applying this change, the number of data field keeps being 8*N+4 consistently.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 4, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
2271048d1b3b0aabf83d25b29c20646dcabedc05 < 7c9f0ccf9f04142458d2ac3d39414f4acae242f0 2271048d1b3b0aabf83d25b29c20646dcabedc05 < 24c3fa71f9947b0e1f3b954db1b769b44140192e 2271048d1b3b0aabf83d25b29c20646dcabedc05 < 14057268e79654c3e8ea2c9b5204cb9644b2964d 2271048d1b3b0aabf83d25b29c20646dcabedc05 < dbcb8635b1eb7603818591cf745c7b1d714f7ac6 2271048d1b3b0aabf83d25b29c20646dcabedc05 < cfada73fabe2ccc06ec77fe2ceaa088689213326 2271048d1b3b0aabf83d25b29c20646dcabedc05 < ec5e96aee75d27779b9a860307679f13f33adb0c 2271048d1b3b0aabf83d25b29c20646dcabedc05 < 3a63a11897c7ba32d1be7a3fdbc48a8b01cf4992 2271048d1b3b0aabf83d25b29c20646dcabedc05 < c37e0a4b79a6bbb96ce5ffe279d7c001e20529e0
Linux / Linux
2.6.34

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/7c9f0ccf9f04142458d2ac3d39414f4acae242f0 git.kernel.org: https://git.kernel.org/stable/c/24c3fa71f9947b0e1f3b954db1b769b44140192e git.kernel.org: https://git.kernel.org/stable/c/14057268e79654c3e8ea2c9b5204cb9644b2964d git.kernel.org: https://git.kernel.org/stable/c/dbcb8635b1eb7603818591cf745c7b1d714f7ac6 git.kernel.org: https://git.kernel.org/stable/c/cfada73fabe2ccc06ec77fe2ceaa088689213326 git.kernel.org: https://git.kernel.org/stable/c/ec5e96aee75d27779b9a860307679f13f33adb0c git.kernel.org: https://git.kernel.org/stable/c/3a63a11897c7ba32d1be7a3fdbc48a8b01cf4992 git.kernel.org: https://git.kernel.org/stable/c/c37e0a4b79a6bbb96ce5ffe279d7c001e20529e0