« Volver al listado

CVE-2026-93134

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

printk: Fix possible console use-after-free

When emitting a record via legacy printing, it is possible that a handover to another legacy printing context occurs. When a context has performed a handover, the console SRCU read lock is released and the pointer to the console struct might now be invalid. Therefore, after calling nbcon_legacy_emit_next_record() or console_emit_next_record(), it is necessary to check if a handover occurred _before_ further @con usage.

Sashiko pointed out that console_flush_one_record() was not doing this.

Leer descripción completaMostrar menos

In console_flush_one_record(), after emitting a record, move the further usage of @con after the handover check.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-93134",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "c158834b223fbfab3a14855ac203b8d9cddbbefd",
              "lessThan": "f0104a7b730de32eefb3d4a27279592b5504ad59",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c158834b223fbfab3a14855ac203b8d9cddbbefd",
              "lessThan": "fbf9bb81b21537ede387a31cc586f1d2ce66a74e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c158834b223fbfab3a14855ac203b8d9cddbbefd",
              "lessThan": "8f194dee0c0d1223255bae1429e1939882f540fc",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c158834b223fbfab3a14855ac203b8d9cddbbefd",
              "lessThan": "36630cafbeede0b64c370edb2f7b4094327ee1e0",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "kernel/printk/printk.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.12"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.12",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "kernel/printk/printk.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:18:08.260",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/36630cafbeede0b64c370edb2f7b4094327ee1e0",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8f194dee0c0d1223255bae1429e1939882f540fc",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f0104a7b730de32eefb3d4a27279592b5504ad59",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/fbf9bb81b21537ede387a31cc586f1d2ce66a74e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nprintk: Fix possible console use-after-free\n\nWhen emitting a record via legacy printing, it is possible that a handover\nto another legacy printing context occurs. When a context has performed a\nhandover, the console SRCU read lock is released and the pointer to the\nconsole struct might now be invalid. Therefore, after calling\nnbcon_legacy_emit_next_record() or console_emit_next_record(), it is\nnecessary to check if a handover occurred _before_ further @con usage.\n\nSashiko pointed out that console_flush_one_record() was not doing this.\n\nIn console_flush_one_record(), after emitting a record, move the further\nusage of @con after the handover check."
    }
  ],
  "lastModified": "2026-09-17T17:18:08.260",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}