« Volver al listado

CVE-2026-93074

Estado: RecibidaAlta (7.8)—

In the Linux kernel, the following vulnerability has been resolved:

dax/fsdev: use __va(phys) for kaddr in direct_access

Use __va(phys) instead of virt_addr + linear_offset for the kaddr return in __fsdev_dax_direct_access(). The previous code added a device-linear byte offset to virt_addr (which is __va of ranges[0]), but for multi-range devices with physical gaps between ranges, this linear arithmetic crosses the gap and produces a wrong kernel virtual address. Using __va(phys) where phys comes from dax_pgoff_to_phys() is correct for any range layout because the direct map translates each physical address independently.

Leer descripción completaMostrar menos

This leaves dev_dax->virt_addr write-only, so remove the field (suggested by Dave Jiang).

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad local (AV:L, PR:L) en kernel que permite corrupción de memoria mediante acceso directo incorrecto a direcciones virtuales, posibilitando lectura y manipulación de datos con altos privilegios.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-93074",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "759455848df0b9ac3acabdbedcdc4a55af67935f",
              "lessThan": "7b642bd3d39105eef4d5908970726c5fda291b53",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "759455848df0b9ac3acabdbedcdc4a55af67935f",
              "lessThan": "ff7c73fca793bd5c29a15ba735b0886f62f3a840",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/dax/dax-private.h",
            "drivers/dax/fsdev.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7.1"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "7.1",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/dax/dax-private.h",
            "drivers/dax/fsdev.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:18:01.337",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/7b642bd3d39105eef4d5908970726c5fda291b53",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ff7c73fca793bd5c29a15ba735b0886f62f3a840",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndax/fsdev: use __va(phys) for kaddr in direct_access\n\nUse __va(phys) instead of virt_addr + linear_offset for the kaddr\nreturn in __fsdev_dax_direct_access(). The previous code added a\ndevice-linear byte offset to virt_addr (which is __va of ranges[0]),\nbut for multi-range devices with physical gaps between ranges, this\nlinear arithmetic crosses the gap and produces a wrong kernel virtual\naddress. Using __va(phys) where phys comes from dax_pgoff_to_phys()\nis correct for any range layout because the direct map translates\neach physical address independently.\n\nThis leaves dev_dax->virt_addr write-only, so remove the field\n(suggested by Dave Jiang)."
    }
  ],
  "lastModified": "2026-09-18T18:18:20.197",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}