Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2026-72412

9.3 · CRITICAL
Published Aug 15, 2026 EPSS 0.18% (8th pctl)

Overview

CVE-2026-72412 is a critical-severity vulnerability. It was published on August 15, 2026 and has a CVSS 3.1 base score of 9.3 (CRITICAL).

This vulnerability has a CVSS 3.1 base score of 9.3, rated CRITICAL. It requires local or adjacent network access to exploit. No authentication or special privileges are required for exploitation.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

s390/mm: Fix handling of _PAGE_UNUSED pte bit

The _PAGE_UNUSED softbit should not really be lying around. Its sole

purpose is to signal to try_to_unmap_one() and try_to_migrate_one()

that the page can be discarded instead of being moved / swapped.

KVM has no way to know why a page is being unmapped, so it sets the bit

on userspace ptes corresponding to unused guest pages every time they

get unmapped. KVM has no reasonable way to clear the bit once the page

is in use again.

While set_ptes() checks and clears the bit, other paths that set new

ptes did not. This led to used pages being thrown out as if they were

unused, causing guest corruption.

Fix the issue by clearing the _PAGE_UNUSED bit for present ptes in

set_pte(), i.e. whenever a present pte is getting set. The check in

set_ptes() is then redundant and can be removed.

Also fix gmap_helper_try_set_pte_unused() to only set the bit if the

pte is present; the _P

Remediation

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Frequently Asked Questions

What is CVE-2026-72412?

CVE-2026-72412 is a critical-severity vulnerability. It was published on August 15, 2026 and has a CVSS 3.1 base score of 9.3 (CRITICAL).

How severe is CVE-2026-72412?

This vulnerability has a CVSS 3.1 base score of 9.3, rated CRITICAL. It requires local or adjacent network access to exploit. No authentication or special privileges are required for exploitation.

How do I fix or remediate CVE-2026-72412?

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2026-72412?

CyberStrike's AI-powered security agents can automatically detect CVE-2026-72412 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.