« Volver al listado

CVE-2026-92495

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

RDMA/bnxt_re: Clear VM_MAYWRITE on DBR/toggle page mmap

bnxt_re_mmap() rejects VM_WRITE for the DBR_PAGE and TOGGLE_PAGE mmap flags, but a read-only mapping can still retain VM_MAYWRITE. nd later be upgraded with mprotect(PROT_WRITE). This can bypass the write check that only runs at mmap time.

Clear VM_MAYWRITE before vm_insert_page() in the shared DBR/toggle-page branch, matching the existing policy that userspace writes are not expected for these pages.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-92495",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "ea222485788208cd79bad42d25aae9232b33a934",
              "lessThan": "5361fb1e5bc246f9a2c0721543f72c8dac200769",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ea222485788208cd79bad42d25aae9232b33a934",
              "lessThan": "13e7861809ef9e7e720ff5f0af1d4293a6d0a9b4",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ea222485788208cd79bad42d25aae9232b33a934",
              "lessThan": "0afbfe019c881483337d9f8304e678af05ebe7cc",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ea222485788208cd79bad42d25aae9232b33a934",
              "lessThan": "518df61b9b0a5b288dfa72c87246045329c18b8c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ea222485788208cd79bad42d25aae9232b33a934",
              "lessThan": "9b66c9af7172ffcf727214fa0ebe9a5e1ed6eb16",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/infiniband/hw/bnxt_re/ib_verbs.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.6"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.6",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.6.157",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/infiniband/hw/bnxt_re/ib_verbs.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:17:51.670",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0afbfe019c881483337d9f8304e678af05ebe7cc",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/13e7861809ef9e7e720ff5f0af1d4293a6d0a9b4",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/518df61b9b0a5b288dfa72c87246045329c18b8c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/5361fb1e5bc246f9a2c0721543f72c8dac200769",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9b66c9af7172ffcf727214fa0ebe9a5e1ed6eb16",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/bnxt_re: Clear VM_MAYWRITE on DBR/toggle page mmap\n\nbnxt_re_mmap() rejects VM_WRITE for the DBR_PAGE and TOGGLE_PAGE mmap\nflags, but a read-only mapping can still retain VM_MAYWRITE. nd later\nbe upgraded with mprotect(PROT_WRITE). This can bypass the write check\nthat only runs at mmap time.\n\nClear VM_MAYWRITE before vm_insert_page() in the shared DBR/toggle-page\nbranch, matching the existing policy that userspace writes are not\nexpected for these pages."
    }
  ],
  "lastModified": "2026-09-17T17:17:51.670",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}