CVE-2026-80560
CVE CVE-2026-80560EUVD EUVD-2026-66475Published 2026-08-26T14:37:25.000ZLast changed 2026-08-27T05:01:48.000ZCVSS 7.8
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: openrisc: signal: do not restore privileged SR bits on sigreturn restore_sigcontext() copies the whole supervision register (SR) from the signal frame and only clears SPR_SR_SM before the value is reloaded into the hardware SR (through ESR and l.rfe) on the return to user space. All other SR bits are left under user control. An unprivileged task can thus return from a signal handler through a crafted sigframe that clears SPR_SR_DME. With the data MMU disabled the CPU performs no translation or protection on data accesses, so the task gains read and write access to arbitrary physical memory, a local privilege escalation. SPR_SR_IME, SPR_SR_SUMRA, SPR_SR_LEE, SPR_SR_EPH and the cache-enable bits are exposed the same way. The ptrace GPR regset already refuses any change to SR for exactly this reason. Restore only the arithmetic flag bits (F, CY, OV) from the signal frame and take every privileged control bit from the SR the kernel saved on signal entry. Verified with qemu-system-or1k -M or1k-sim: before this change an unprivileged PoC clears SPR_SR_DME in rt_sigreturn and writes a marker to physical address 0x03000000 (beyond the kernel's mem=32M); afterwards the same PoC receives SIGSEGV and physical memory is unchanged.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux ac689eb7f9d4e270d1365853b82eece669387e2c <cd8b43a71755c516f5c1f265a103438ae9ab15be; 3.1; patch: 7.1.10; ac689eb7f9d4e270d1365853b82eece669387e2c <a88d688be8d7f03cbf927f2ab454ea9fa58d2979; patch: 6.6.153; patch: 5.10.266; patch: 6.1.184; ac689eb7f9d4e270d1365853b82eece669387e2c <b4d73c3848bae9084fa8b9b2aa76d99a7d8eb17d; patch: 5.15.217; patch: 6.18.46; ac689eb7f9d4e270d1365853b82eece669387e2c <32ef1b30ad736519f7a207bcc2986f3d4129d972; patch: 6.12.105; ac689eb7f9d4e270d1365853b82eece669387e2c <89a91b30685c0493b0fa2b47d0ab41061a63069d; ac689eb7f9d4e270d1365853b82eece669387e2c <212fc482ddd7f9ccdd74a05eab1cac849350dcd6; patch: 0; ac689eb7f9d4e270d1365853b82eece669387e2c <cf1b5514ddf9df098ce7e3741fc9679fd85a4ec6; ac689eb7f9d4e270d1365853b82eece669387e2c <bc2e24ba6e167ccf374a197457aa5640a802f429; patch: 7.2
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.