CVE-2026-68480 Details
Description
In the Linux kernel, the following vulnerability has been resolved: x86/bugs: Make Safe-RET robust against interrupt injection An attacker injecting interrupts while the Safe-RET mitigation executes on machines affected by SRSO can neutralize the safe return sequence, potentially leading to data leakage through speculative execution. Fixup register state as if the Safe-RET sequence executed successfully by "emulating" it, in a manner of speaking, and avoid executing a RET instruction after returning from the interrupt.
A vulnerability in the Linux kernel's handling of the Safe-RET mitigation on x86 architectures can be exploited by injecting interrupts. This interference can neutralize the Safe-RET sequence, potentially leading to data leakage through speculative execution. The issue arises on machines affected by the Speculative Return Stack Overflow (SRSO) vulnerability, where an attacker can disrupt the Safe-RET process and manipulate the return sequence.
Users can update to the latest version of the Linux kernel where this vulnerability has been addressed. Instructions for downloading the patched version are available on the Linux kernel's official website.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
No affected product data is available for this CVE.
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 18, 2026 | CVE Modified | kernel.org |
| Aug 17, 2026 | CVE Modified | kernel.org |
| Aug 11, 2026 | CVE Modified | kernel.org |
| Aug 9, 2026 | CVE Modified | kernel.org |
| Aug 7, 2026 | CVE Modified | kernel.org |
| Aug 6, 2026 | New CVE Received | kernel.org |