news.mlab.sh
Vulnerabilities
Vulnerability

CVE-2026-68480

Reference data from vuln.mlab.sh, coverage from our own index.

CVSS
8.8 High
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS
0.23%
Risk score
12.5
Published
2026-08-06
Status
Published

In the Linux kernel, the following vulnerability has been resolved: x86/bugs: Make Safe-RET robust against interrupt injection An attacker injecting interrupts while the Safe-RET mitigation executes on machines affected by SRSO can neutralize the safe return sequence, potentially leading to data leakage through speculative execution. Fixup register state as if the Safe-RET sequence executed successfully by "emulating" it, in a manner of speaking, and avoid executing a RET instruction after returning from the interrupt. An attacker executing code on affected system could inject an interrupt at a precise moment to disrupt "Safe RET", the default Linux mitigation for speculative Return Overflow (SRSO), which could potentially weaken that protection and may result in information disclosure.

Weaknesses

CWE-201

Coverage 1

Advisories and references