CVE-2026-93123
In the Linux kernel, the following vulnerability has been resolved:
serial: qcom-geni: do not advance stale DMA completions
The qcom GENI serial DMA TX completion path advances the transmit fifo by the number of bytes recorded in port->tx_remaining.
If uart_flush_buffer() runs after the hardware has completed a DMA transfer but before the DMA completion interrupt has been handled, the serial core resets the transmit fifo while port->tx_remaining still describes the old DMA transfer.
A previous fix avoided advancing an empty fifo by checking that the fifo length is at least tx_remaining. That still does not distinguish the old DMA payload from new bytes written after the flush.
Leer descripción completaMostrar menos
If userspace writes new data before the stale DMA completion interrupt is handled, the fifo can again contain at least tx_remaining bytes and the stale completion can advance and discard those new bytes.
Mark an in-flight DMA transfer stale when the transmit fifo is flushed. The later completion still unprepares the original DMA mapping using the saved length, but it no longer advances the transmit fifo.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 10
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-93123",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "2aaa43c7077833301c237684cd7bc9ae5e3dec95",
"lessThan": "231c84fe7ec40e4a06c398c0591d5b8e823d68e1",
"versionType": "git"
},
{
"status": "affected",
"version": "2aaa43c7077833301c237684cd7bc9ae5e3dec95",
"lessThan": "c02d030747c46da33faf406dd772ef91100efa27",
"versionType": "git"
},
{
"status": "affected",
"version": "2aaa43c7077833301c237684cd7bc9ae5e3dec95",
"lessThan": "59faa59c25a0a098fbc86275408d7c8405015702",
"versionType": "git"
},
{
"status": "affected",
"version": "2aaa43c7077833301c237684cd7bc9ae5e3dec95",
"lessThan": "7ea38c49e7178960926657863299face6dc0e1b0",
"versionType": "git"
}
],
"programFiles": [
"drivers/tty/serial/qcom_geni_serial.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.3"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.3",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.12.110",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.52",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.6",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/tty/serial/qcom_geni_serial.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-17T17:18:07.020",
"references": [
{
"url": "https://git.kernel.org/stable/c/231c84fe7ec40e4a06c398c0591d5b8e823d68e1",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/59faa59c25a0a098fbc86275408d7c8405015702",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/7ea38c49e7178960926657863299face6dc0e1b0",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c02d030747c46da33faf406dd772ef91100efa27",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nserial: qcom-geni: do not advance stale DMA completions\n\nThe qcom GENI serial DMA TX completion path advances the transmit fifo by\nthe number of bytes recorded in port->tx_remaining.\n\nIf uart_flush_buffer() runs after the hardware has completed a DMA\ntransfer but before the DMA completion interrupt has been handled, the\nserial core resets the transmit fifo while port->tx_remaining still\ndescribes the old DMA transfer.\n\nA previous fix avoided advancing an empty fifo by checking that the fifo\nlength is at least tx_remaining. That still does not distinguish the old\nDMA payload from new bytes written after the flush. If userspace writes\nnew data before the stale DMA completion interrupt is handled, the fifo\ncan again contain at least tx_remaining bytes and the stale completion\ncan advance and discard those new bytes.\n\nMark an in-flight DMA transfer stale when the transmit fifo is flushed.\nThe later completion still unprepares the original DMA mapping using the\nsaved length, but it no longer advances the transmit fifo."
}
],
"lastModified": "2026-09-17T17:18:07.020",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}