{"id":"CVE-2026-72168","summary":"mtd: maps: vmu-flash: fix fault in unaligned fixup","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nmtd: maps: vmu-flash: fix fault in unaligned fixup\n\nUse kzalloc_obj() / kzalloc_objs() to allocate the memcard structs,\ninstead of kmalloc_obj() / kmalloc_objs() to prevent access to\nuninitialized data.\n\nFixes runtime error: Fault in unaligned fixup: 0000 [#1] at\nmtd_get_fact_prot_info.","modified":"2026-09-04T03:47:13.883943898Z","published":"2026-08-15T05:53:34.868Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72168.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/01928835d80829e615a492aa66c629b953ec7bef"},{"type":"WEB","url":"https://git.kernel.org/stable/c/19360c25135fccb6bbafbee49a5f66baf9a311af"},{"type":"WEB","url":"https://git.kernel.org/stable/c/455519f6b70f46ac6cbf41a75ac76ec5e59040f2"},{"type":"WEB","url":"https://git.kernel.org/stable/c/79d1661502c6e4b6f626185cef72cf2fa78116e1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72168.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-72168"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"47a72688fae7298e1ad5fdc9bff7e04b6a549620"},{"fixed":"01928835d80829e615a492aa66c629b953ec7bef"},{"fixed":"19360c25135fccb6bbafbee49a5f66baf9a311af"},{"fixed":"455519f6b70f46ac6cbf41a75ac76ec5e59040f2"},{"fixed":"79d1661502c6e4b6f626185cef72cf2fa78116e1"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72168.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.6.30"},{"fixed":"6.12.101"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.42"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.1.5"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72168.json"}}],"schema_version":"1.9.0"}