PT-2026-94877 · Linux · Linux Kernel

CVE-2026-93079

·

Published

2026-09-17

·

Updated

2026-09-28

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A heap out-of-bounds write exists in the cxlctl get feature() function. The issue occurs because the output buffer is sized based on the fwctl rpc.out len value provided by the user, while the device is instructed to write a number of bytes specified by cxl mbox get feat in.count, which is also user-controlled. Since there is no validation to ensure count does not exceed out len, a small out len combined with a large count can overflow the buffer allocated via kvzalloc(). This flaw is reachable from FWCTL RPC.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-93079
OPENSUSE-SU-2026:11893-1

Affected Products

Linux Kernel