CVE-2026-72169. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
CISA KEVNot listedBased on the latest collected catalog
EPSS0.2%Estimated 30-day exploitation probability
Ransomware useNot markedCISA KEV ransomware field
Threat actors0Source-linked actor relationships
Overview
What is CVE-2026-72169?
In the Linux kernel, the following vulnerability has been resolved:
kho: make sure scratch size is always aligned by CMA_MIN_ALIGNMENT_BYTES
When using scratch_scale, the scratch sizes are rounded up to CMA_MIN_ALIGNMENT_BYTES since they will be released as MIGRATE_CMA. This is not done when using fixed scratch sizes via command line.
This can result in user specifying a size which is not aligned, and thus kernel releasing a pageblock that is only partially scratch.
Do the rounding up for both cases in scratch_size_update().