CVE-2026-93078
In the Linux kernel, the following vulnerability has been resolved:
cxl/features: Reject Set Features output buffer smaller than the header
cxlctl_set_feature() sizes its output buffer from the user's fwctl_rpc.out_len but never checks it is large enough to hold even the fwctl_rpc_cxl_out header. With out_len == 0 , kvzalloc() returns ZERO_SIZE_PTR, which passes the !rpc_out check, the subsequent rpc_out->size = 0 then writes through the poison pointer.
Reject requests whose output buffer can't hold the response header, before allocating. The Set Feature reply carries no payload, so the header is all that is required.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 10
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-93078",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "eb5dfcb9e36d0e46089fec777d911313c1876fa3",
"lessThan": "1281dc84c81577b51e2b61c24617c9f44b2cdb99",
"versionType": "git"
},
{
"status": "affected",
"version": "eb5dfcb9e36d0e46089fec777d911313c1876fa3",
"lessThan": "16b7c99eff030c6ea11ca24efa4b9f989cc74093",
"versionType": "git"
},
{
"status": "affected",
"version": "eb5dfcb9e36d0e46089fec777d911313c1876fa3",
"lessThan": "cde18d6c1d913a67ab0afd3d9475ece4be79da50",
"versionType": "git"
}
],
"programFiles": [
"drivers/cxl/core/features.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.15"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.15",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.18.52",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.6",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/cxl/core/features.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-17T17:18:01.743",
"references": [
{
"url": "https://git.kernel.org/stable/c/1281dc84c81577b51e2b61c24617c9f44b2cdb99",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/16b7c99eff030c6ea11ca24efa4b9f989cc74093",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/cde18d6c1d913a67ab0afd3d9475ece4be79da50",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncxl/features: Reject Set Features output buffer smaller than the header\n\ncxlctl_set_feature() sizes its output buffer from the user's\nfwctl_rpc.out_len but never checks it is large enough to hold even the\nfwctl_rpc_cxl_out header. With out_len == 0 , kvzalloc() returns\nZERO_SIZE_PTR, which passes the !rpc_out check, the subsequent\nrpc_out->size = 0 then writes through the poison pointer.\n\nReject requests whose output buffer can't hold the response header,\nbefore allocating. The Set Feature reply carries no payload, so the\nheader is all that is required."
}
],
"lastModified": "2026-09-17T17:18:01.743",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}