In the Linux kernel, the following vulnerability has been resolved:
mm/mempolicy: fix get_nodes out of bound access
When user specified more nodes than supported, get_nodes will access nmask array out of bounds.
CVSS Details
- CVSS 3.1 Base Score: 7.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade kernel-tools-debuginfoUpgrade python-perfUpgrade perfUpgrade kernel-tools-develUpgrade kernel-develUpgrade perf-debuginfoUpgrade kernel-debuginfo-common-aarch64Upgrade bpftool-debuginfoUpgrade kernel-toolsUpgrade kernelUpgrade kernel-debuginfoUpgrade python-perf-debuginfoUpgrade bpftoolUpgrade kernel-livepatch-5.15.69-37.134Upgrade kernel-debuginfo-common-x86_64Upgrade kernel-headers | May 20, 2026 | May 20, 2026 |
| Debian | — | Upgrade linux | Jun 20, 2025 | Jun 20, 2025 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 18, 2025 |
| Ubuntu | — | Upgrade linux-oracle-5.15Upgrade linux-nvidiaUpgrade linux-kvmUpgrade linux-lowlatencyUpgrade linux-azure-5.15Upgrade linux-ibmUpgrade linuxUpgrade linux-gkeopUpgrade linux-oracleUpgrade linux-intel-iotg-5.15Upgrade linux-realtimeUpgrade linux-raspiUpgrade linux-gcpUpgrade linux-azureUpgrade linux-awsUpgrade linux-aws-5.15Upgrade linux-lowlatency-hwe-5.15Upgrade linux-gkeUpgrade linux-riscv-5.15Upgrade linux-hwe-5.15Upgrade linux-gcp-5.15Upgrade linux-intel-iotg | Jun 26, 2025 | Jun 18, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub