{"id":"CVE-2026-68480","summary":"x86/bugs: Make Safe-RET robust against interrupt injection","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nx86/bugs: Make Safe-RET robust against interrupt injection\n\nAn attacker injecting interrupts while the Safe-RET mitigation executes\non machines affected by SRSO can neutralize the safe return sequence,\npotentially leading to data leakage through speculative execution.\n\nFixup register state as if the Safe-RET sequence executed successfully\nby \"emulating\" it, in a manner of speaking, and avoid executing a RET\ninstruction after returning from the interrupt.","modified":"2026-10-09T18:26:42.170844770Z","published":"2026-08-06T17:36:43.654Z","related":["ALSA-2026:61887","ALSA-2026:63013","ALSA-2026:63014","ALSA-2026:63129","SUSE-SU-2026:23477-1","SUSE-SU-2026:23481-1","SUSE-SU-2026:23528-1","SUSE-SU-2026:23529-1","SUSE-SU-2026:23881-1","SUSE-SU-2026:23887-1","SUSE-SU-2026:23897-1","SUSE-SU-2026:23902-1","SUSE-SU-2026:4120-1","SUSE-SU-2026:4254-1","SUSE-SU-2026:4279-1","SUSE-SU-2026:4282-1","SUSE-SU-2026:4284-1","SUSE-SU-2026:4347-1","SUSE-SU-2026:4369-1","SUSE-SU-2026:4595-1","openSUSE-SU-2026:11476-1","openSUSE-SU-2026:21910-1"],"database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68480.json","cna_assigner":"Linux"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/52db77a13be224e09eb4ba6b4252ae8ab9085c2c"},{"type":"WEB","url":"https://git.kernel.org/stable/c/61649a2d61cb0dbc673f0f232f0f0c298bf50442"},{"type":"WEB","url":"https://git.kernel.org/stable/c/6703dba1d14cbd6647cd1ccfa3a3fa94b64dd096"},{"type":"WEB","url":"https://git.kernel.org/stable/c/7e7f81cf6f5ca3311e526308f55d7c54d3ba71f9"},{"type":"WEB","url":"https://git.kernel.org/stable/c/bfe7f9993467ba431b2731437949ac1e2634e771"},{"type":"WEB","url":"https://git.kernel.org/stable/c/d0208e08d64d99383e09852a76cc3038c5a4c3ab"},{"type":"WEB","url":"https://git.kernel.org/stable/c/dfefa3c51370f84acb643cddf98bb42c885d0483"},{"type":"WEB","url":"https://git.kernel.org/stable/c/e262f28a69ae9e0791248f93b0173c1d1f3e1d5d"},{"type":"WEB","url":"https://people.csail.mit.edu/mengjia/data/2026.USENIX.TONTOU.pdf"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68480.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-68480"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"3f9b7101bea1dcb63410c016ceb266f6e9f733c9"},{"fixed":"dfefa3c51370f84acb643cddf98bb42c885d0483"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"b35087763a44d1eb45857f799579a351332be505"},{"fixed":"52db77a13be224e09eb4ba6b4252ae8ab9085c2c"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"ac41e90d8daa8815d8bee774a1975435fbfe1ae7"},{"fixed":"d0208e08d64d99383e09852a76cc3038c5a4c3ab"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"fb3bd914b3ec28f5fb697ac55c4846ac2d542855"},{"fixed":"6703dba1d14cbd6647cd1ccfa3a3fa94b64dd096"},{"fixed":"e262f28a69ae9e0791248f93b0173c1d1f3e1d5d"},{"fixed":"bfe7f9993467ba431b2731437949ac1e2634e771"},{"fixed":"61649a2d61cb0dbc673f0f232f0f0c298bf50442"},{"fixed":"7e7f81cf6f5ca3311e526308f55d7c54d3ba71f9"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"5.10.189"},{"fixed":"5.10.264"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"5.15.125"},{"fixed":"5.15.215"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"6.1.44"},{"fixed":"6.1.182"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"6.4.9"},{"fixed":"6.5"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"acdc883eb61efbe01b954e782e1124790bd391a8"}]}],"versions":["v5.10.263","v5.10.262","v5.10.261","v5.10.260","v5.10.259","v5.10.258","v5.10.257","v5.10.256","v5.10.255","v5.10.254","v5.10.253","v5.10.252","v5.10.251","v5.10.250","v5.10.249","v5.10.248","v5.10.247","v5.10.246","v5.10.245","v5.10.244","v5.10.243","v5.10.242","v5.10.241","v5.10.240","v5.10.239","v5.10.238","v5.10.237","v5.10.236","v5.10.235","v5.10.234","v5.10.233","v5.10.232","v5.10.231","v5.10.230","v5.10.229","v5.10.228","v5.10.227","v5.10.226","v5.10.225","v5.10.224","v5.10.223","v5.10.222","v5.10.221","v5.10.220","v5.10.219","v5.10.218","v5.10.217","v5.10.216","v5.10.215","v5.10.214","v5.10.213","v5.10.212","v5.10.211","v5.10.210","v5.10.209","v5.10.208","v5.10.207","v5.10.206","v5.10.205","v5.10.204","v5.10.203","v5.10.202","v5.10.201","v5.10.200","v5.10.199","v5.10.198","v5.10.197","v5.10.196","v5.10.195","v5.10.194","v5.10.193","v5.10.192","v5.10.191","v5.10.190","v5.10.189","v5.15.214","v5.15.213","v5.15.212","v5.15.211","v5.15.210","v5.15.209","v5.15.208","v5.15.207","v5.15.206","v5.15.205","v5.15.204","v5.15.203","v5.15.202","v5.15.201","v5.15.200","v5.15.199","v5.15.198","v5.15.197","v5.15.196","v5.15.195","v5.15.194","v5.15.193","v5.15.192","v5.15.191","v5.15.190","v5.15.189","v5.15.188","v5.15.187","v5.15.186","v5.15.185","v5.15.184","v5.15.183","v5.15.182","v5.15.181","v5.15.180","v5.15.179","v5.15.178","v5.15.177","v5.15.176","v5.15.175","v5.15.174","v5.15.173","v5.15.172","v5.15.171","v5.15.170","v5.15.169","v5.15.168","v5.15.167","v5.15.166","v5.15.165","v5.15.164","v5.15.163","v5.15.162","v5.15.161","v5.15.160","v5.15.159","v5.15.158","v5.15.157","v5.15.156","v5.15.155","v5.15.154","v5.15.153","v5.15.152","v5.15.151","v5.15.150","v5.15.149","v5.15.148","v5.15.147","v5.15.146","v5.15.145","v5.15.144","v5.15.143","v5.15.142","v5.15.141","v5.15.140","v5.15.139","v5.15.138","v5.15.137","v5.15.136","v5.15.135","v5.15.134","v5.15.133","v5.15.132","v5.15.131","v5.15.130","v5.15.129","v5.15.128","v5.15.127","v5.15.126","v5.15.125","v6.1.181","v6.1.180","v6.1.179","v6.1.178","v6.1.177","v6.1.176","v6.1.175","v6.1.174","v6.1.173","v6.1.172","v6.1.171","v6.1.170","v6.1.169","v6.1.168","v6.1.167","v6.1.166","v6.1.165","v6.1.164","v6.1.163","v6.1.162","v6.1.161","v6.1.160","v6.1.159","v6.1.158","v6.1.157","v6.1.156","v6.1.155","v6.1.154","v6.1.153","v6.1.152","v6.1.151","v6.1.150","v6.1.149","v6.1.148","v6.1.147","v6.1.146","v6.1.145","v6.1.144","v6.1.143","v6.1.142","v6.1.141","v6.1.140","v6.1.139","v6.1.138","v6.1.137","v6.1.136","v6.1.135","v6.1.134","v6.1.133","v6.1.132","v6.1.131","v6.1.130","v6.1.129","v6.1.128","v6.1.127","v6.1.126","v6.1.125","v6.1.124","v6.1.123","v6.1.122","v6.1.121","v6.1.120","v6.1.119","v6.1.118","v6.1.117","v6.1.116","v6.1.115","v6.1.114","v6.1.113","v6.1.112","v6.1.111","v6.1.110","v6.1.109","v6.1.108","v6.1.107","v6.1.106","v6.1.105","v6.1.104","v6.1.103","v6.1.102","v6.1.101","v6.1.100","v6.1.99","v6.1.98","v6.1.97","v6.1.96","v6.1.95","v6.1.94","v6.1.93","v6.1.92","v6.1.91","v6.1.90","v6.1.89","v6.1.88","v6.1.87","v6.1.86","v6.1.85","v6.1.84","v6.1.83","v6.1.82","v6.1.81","v6.1.80","v6.1.79","v6.1.78","v6.1.77","v6.1.76","v6.1.75","v6.1.74","v6.1.73","v6.1.72","v6.1.71","v6.1.70","v6.1.69","v6.1.68","v6.1.67","v6.1.66","v6.1.65","v6.1.64","v6.1.63","v6.1.62","v6.1.61","v6.1.60","v6.1.59","v6.1.58","v6.1.57","v6.1.56","v6.1.55","v6.1.54","v6.1.53","v6.1.52","v6.1.51","v6.1.50","v6.1.49","v6.1.48","v6.1.47","v6.1.46","v6.1.45","v6.1.44","v6.4.16","v6.4.15","v6.4.14","v6.4.13","v6.4.12","v6.4.11","v6.4.10","v6.4.9"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68480.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.10.264"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.215"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.182"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.150"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.5.0"},{"fixed":"6.12.102"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.18.43"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"7.1.7"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68480.json"}}],"schema_version":"1.9.0"}