{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-80748",
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "state": "PUBLISHED",
        "assignerShortName": "Linux",
        "dateReserved": "2026-08-26T14:34:25.790Z",
        "datePublished": "2026-09-03T08:26:29.532Z",
        "dateUpdated": "2026-09-04T04:58:28.127Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
                "shortName": "Linux",
                "dateUpdated": "2026-09-04T04:58:28.127Z"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmmc: loongson2: Fix sg iteration in data reorder functions\n\nIn ls2k0500_mmc_reorder_cmd_data() and ls2k2000_mmc_reorder_cmd_data(),\nthe for_each_sg() macro already iterates over the scatterlist entries,\nwith 'sg' pointing to the current entry. However, the code incorrectly\nuses '&sg[i]' and 'sg_dma_len(&sg[i])' inside the loop, which treats\n'sg' as an array base and indexes it again, leading to access of\nwrong sg entries (or out-of-bounds if the list is not an array)."
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "AV:L - The flaw is in the Loongson-2K MMC host driver reached via local block I/O and MMC ioctls (SD writes trigger SD_APP_SEND_NUM_WR_BLKS; card init issues SD_SWITCH/SCR), not via any network protocol; it affects LoongArch desktops, kiosks, and embedded systems with SD/eMMC slots.\nAC:L - An attacker with SD-backed storage access can reliably drive the post-DMA reorder path on every qualifying transfer; the double-indexed for_each_sg bug deterministically accesses wrong scatterlist entries whenever sg_len exceeds one, without races or uncontrollable memory layout.\nPR:L - Any unprivileged local user writing to an SD-backed filesystem or opening the mmc block device can trigger the vulnerable reorder functions; no CAP_SYS_ADMIN, init-namespace root, or user-namespace capability is required.\nUI:N - Exploitation requires only the attacker's own writes, MMC_IOC_CMD ioctl sequences, or kernel auto-enumeration after SD insertion; no separate victim mount, login, or cooperative action is needed.\nS:U - Scatterlist mis-indexing corrupts kernel heap memory within the host kernel security boundary; this is standard local privilege-escalation impact, not VM escape, IOMMU bypass, or cross-container authority change.\nC:H - sg_virt(&sg[i]) on a mis-advanced pointer reads from wrong or out-of-bounds scatterlist entries, exposing adjacent kernel memory; out-of-bounds reads are rated High and can leak pointers usable for further exploitation.\nI:H - The reorder loop writes bitrev8x4/cpu_to_be32-transformed values through the mis-indexed scatterlist pointer, performing out-of-bounds kernel memory writes that can corrupt adjacent objects and enable arbitrary code execution.\nA:H - Corrupting adjacent kernel structures via the out-of-bounds scatterlist write can cause immediate kernel oops or panic; memory corruption bugs in interrupt context are rated High availability impact even when not fully weaponized."
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "unaffected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "drivers/mmc/host/loongson2-mmc.c"
                    ],
                    "versions": [
                        {
                            "version": "2115772014bdac368317e997ed15016cf2792665",
                            "lessThan": "8f7f7a6d5aed8f346a1c936fba02033c73a337dc",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "2115772014bdac368317e997ed15016cf2792665",
                            "lessThan": "db368164383c46f256ed8152a41ae9300e615028",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "2115772014bdac368317e997ed15016cf2792665",
                            "lessThan": "00179ed9fbe07799676e2cb63c4e7f0e7cd80a5c",
                            "status": "affected",
                            "versionType": "git"
                        }
                    ]
                },
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "affected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "drivers/mmc/host/loongson2-mmc.c"
                    ],
                    "versions": [
                        {
                            "version": "6.17",
                            "status": "affected"
                        },
                        {
                            "version": "0",
                            "lessThan": "6.17",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.18.46",
                            "lessThanOrEqual": "6.18.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "7.1.10",
                            "lessThanOrEqual": "7.1.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "7.2",
                            "lessThanOrEqual": "*",
                            "status": "unaffected",
                            "versionType": "original_commit_for_fix"
                        }
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "operator": "OR",
                            "negate": false,
                            "cpeMatch": [
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.17",
                                    "versionEndExcluding": "6.18.46"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.17",
                                    "versionEndExcluding": "7.1.10"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.17",
                                    "versionEndExcluding": "7.2"
                                }
                            ]
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://git.kernel.org/stable/c/8f7f7a6d5aed8f346a1c936fba02033c73a337dc"
                },
                {
                    "url": "https://git.kernel.org/stable/c/db368164383c46f256ed8152a41ae9300e615028"
                },
                {
                    "url": "https://git.kernel.org/stable/c/00179ed9fbe07799676e2cb63c4e7f0e7cd80a5c"
                }
            ],
            "title": "mmc: loongson2: Fix sg iteration in data reorder functions",
            "x_generator": {
                "engine": "bippy-1.2.0"
            }
        }
    }
}