CVE-2026-80748
7.8Linux · Kernel
A memory safety vulnerability exists in the Linux kernel Loongson2 MMC driver, where incorrect scatterlist iteration leads to out of bounds memory access.
Executive summary
A high severity memory corruption vulnerability in the Linux kernel Loongson2 MMC driver could allow a local attacker to achieve elevated system privileges or cause a system crash.
Vulnerability
The vulnerability is caused by improper use of the for_each_sg macro within the ls2k0500_mmc_reorder_cmd_data and ls2k2000_mmc_reorder_cmd_data functions. An attacker with local access and low privileges can trigger an out of bounds memory access by exploiting the incorrect pointer arithmetic used during scatterlist iteration.
Business impact
The potential for unauthorized memory access, data integrity compromise, and system instability poses a significant risk to operational continuity. With a CVSS score of 7.8, this vulnerability is classified as High severity, reflecting the impact on confidentiality, integrity, and availability for compromised systems. Even though access is restricted to local users, the ability to manipulate kernel memory can lead to full system compromise.
Remediation
Immediate Action: Update the Linux kernel to version 6.18.46, 7.1.10, or later versions where the fix is integrated.
Proactive Monitoring: Monitor system logs for kernel oops or segmentation faults that may indicate failed exploitation attempts or unexpected driver behavior.
Compensating Controls: Restrict local shell access to untrusted users and ensure that system hardware access is strictly limited to authorized processes to minimize the attack surface.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high impact of kernel level vulnerabilities, organizations utilizing Loongson2 hardware should prioritize applying the provided kernel patches. Administrators should verify the current kernel version via the uname command and schedule maintenance windows to ensure the security of the underlying operating system environment.
More Linux CVEs all →
History
CVE Brief tracked this CVE 4 days before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 7.8 (3.1)
- Analyst report written
- Published in the daily brief high section, early-warning entry