PT-2026-97953 · Linux · Linux

CVE-2026-93266

·

Published

2026-09-24

·

Updated

2026-09-24

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
arm64: RSI: fix field-spanning write warning in attestation token init
The challenge is passed in registers a1 through a8. However, copying to &regs.a1 makes FORTIFY treat the destination as the single a1 field, resulting in a field-spanning write warning. [1]
Overlay the SMCCC register structure with an RSI-specific argument layout and copy the challenge into an explicit 64-byte array. This keeps the existing a1-a8 argument encoding while giving the copy a correctly sized destination object.
[1] memcpy: detected field-spanning write (size 64) of single field "&regs.a1" at ./arch/arm64/include/asm/rsi cmds.h:119 (size 8) WARNING: ./arch/arm64/include/asm/rsi cmds.h:119 at rsi attestation token init+0xdc/0xf8 [arm cca guest], CPU#0: cat/3314
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-93266

Affected Products

Linux