Local service interruption via dm-ioctl buffer overflow
Published Aug 15, 2026 · Updated Aug 15, 2026
Buffer overflow in Linux kernel dm-ioctl before 6.6.145, 6.12.97, 6.18.40, and 7.1.5 allows local users to interrupt service. The list_version_get_info function reserves 12 bytes using sizeof(tt->version) but writes three version integers and the next field, totaling 16 bytes, into the output buffer. Reaching the ioctl path requires local low-privilege access; the documented consequence is an availability interruption, with no reported data disclosure or modification.
Summary
What happened
Buffer overflow in Linux kernel dm-ioctl before 6.6.145, 6.12.97, 6.18.40, and 7.1.5 allows local users to interrupt service. The list_version_get_info function reserves 12 bytes using sizeof(tt->version) but writes three version integers and the next field, totaling 16 bytes, into the output buffer. Reaching the ioctl path requires local low-privilege access; the documented consequence is an availability interruption, with no reported data disclosure or modification.
The record
- CVE
- CVE-2026-72106
- Published
- Aug 15, 2026
- Updated
- Aug 15, 2026
- Vendor
- The Linux Kernel Organization
- Product
- Linux
- Classifications
- T1499
- Attack vector
- local
- Privileges
- authenticated
Timeline
How it unfolded
- Aug 15, 2026CVE publishedPublication date reported by the CVE source.
- Aug 15, 2026Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=0 <6.12.97
- Affected versionversion=0 <6.18.40
- Affected versionversion=0 <6.6.145
- Affected versionversion=0 <7.1.5
- Affected versionversion=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <29536a9ff146d9bbd618959857ed2e691cda1d21
- Affected versionversion=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <76c6f845dc0c614304a6e6ee619b552f97cf24b3
- Affected versionversion=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <d61c12573ed9768690fdcb2bc38846a1bcb01358
- Affected versionversion=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <df50c24c6447c18886ed126d3d81cc7e155ea8b6
- Affected versionversion=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <e0f5842c4e2a7dbefb52a2dc6711789bc6963e55
What conditions does exploitation require?
What is affected?
Published CVSS scores
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
No public exploit references are available in this record.
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo