CVE-2026-72305EPSS p10.8%
CVE-2026-72305CVE-2026-72305
Description
In the Linux kernel, the following vulnerability has been resolved:
VDUSE: avoid leaking information to userspace
The bounceing is not necessarily page aligned, so current VDUSE can
leak kernel information through mapping bounce pages to
userspace. Allocate bounce pages with __GFP_ZERO to avoid leaking
information to userspace.
Scoring
| EPSS | 0.21% probability of exploitation · percentile 10.8% · 2026-10-06T12:00:23Z |
| Last modified | 2026-08-23 |