{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-80748","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-26T14:34:25.790Z","datePublished":"2026-09-03T08:26:29.532Z","dateUpdated":"2026-09-04T04:58:28.127Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-04T04:58:28.127Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmmc: loongson2: Fix sg iteration in data reorder functions\n\nIn ls2k0500_mmc_reorder_cmd_data() and ls2k2000_mmc_reorder_cmd_data(),\nthe for_each_sg() macro already iterates over the scatterlist entries,\nwith 'sg' pointing to the current entry. However, the code incorrectly\nuses '&sg[i]' and 'sg_dma_len(&sg[i])' inside the loop, which treats\n'sg' as an array base and indexes it again, leading to access of\nwrong sg entries (or out-of-bounds if the list is not an array)."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The flaw is in the Loongson-2K MMC host driver reached via local block I/O and MMC ioctls (SD writes trigger SD_APP_SEND_NUM_WR_BLKS; card init issues SD_SWITCH/SCR), not via any network protocol; it affects LoongArch desktops, kiosks, and embedded systems with SD/eMMC slots.\nAC:L - An attacker with SD-backed storage access can reliably drive the post-DMA reorder path on every qualifying transfer; the double-indexed for_each_sg bug deterministically accesses wrong scatterlist entries whenever sg_len exceeds one, without races or uncontrollable memory layout.\nPR:L - Any unprivileged local user writing to an SD-backed filesystem or opening the mmc block device can trigger the vulnerable reorder functions; no CAP_SYS_ADMIN, init-namespace root, or user-namespace capability is required.\nUI:N - Exploitation requires only the attacker's own writes, MMC_IOC_CMD ioctl sequences, or kernel auto-enumeration after SD insertion; no separate victim mount, login, or cooperative action is needed.\nS:U - Scatterlist mis-indexing corrupts kernel heap memory within the host kernel security boundary; this is standard local privilege-escalation impact, not VM escape, IOMMU bypass, or cross-container authority change.\nC:H - sg_virt(&sg[i]) on a mis-advanced pointer reads from wrong or out-of-bounds scatterlist entries, exposing adjacent kernel memory; out-of-bounds reads are rated High and can leak pointers usable for further exploitation.\nI:H - The reorder loop writes bitrev8x4/cpu_to_be32-transformed values through the mis-indexed scatterlist pointer, performing out-of-bounds kernel memory writes that can corrupt adjacent objects and enable arbitrary code execution.\nA:H - Corrupting adjacent kernel structures via the out-of-bounds scatterlist write can cause immediate kernel oops or panic; memory corruption bugs in interrupt context are rated High availability impact even when not fully weaponized."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/mmc/host/loongson2-mmc.c"],"versions":[{"version":"2115772014bdac368317e997ed15016cf2792665","lessThan":"8f7f7a6d5aed8f346a1c936fba02033c73a337dc","status":"affected","versionType":"git"},{"version":"2115772014bdac368317e997ed15016cf2792665","lessThan":"db368164383c46f256ed8152a41ae9300e615028","status":"affected","versionType":"git"},{"version":"2115772014bdac368317e997ed15016cf2792665","lessThan":"00179ed9fbe07799676e2cb63c4e7f0e7cd80a5c","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/mmc/host/loongson2-mmc.c"],"versions":[{"version":"6.17","status":"affected"},{"version":"0","lessThan":"6.17","status":"unaffected","versionType":"semver"},{"version":"6.18.46","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.10","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.17","versionEndExcluding":"6.18.46"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.17","versionEndExcluding":"7.1.10"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.17","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/8f7f7a6d5aed8f346a1c936fba02033c73a337dc"},{"url":"https://git.kernel.org/stable/c/db368164383c46f256ed8152a41ae9300e615028"},{"url":"https://git.kernel.org/stable/c/00179ed9fbe07799676e2cb63c4e7f0e7cd80a5c"}],"title":"mmc: loongson2: Fix sg iteration in data reorder functions","x_generator":{"engine":"bippy-1.2.0"}}}}