CVE-2026-93239
In the Linux kernel, the following vulnerability has been resolved:
arm64: mm: Fix the lockless page-table walk in show_pte()
show_pte() walks page tables locklessly and can run with interrupts enabled. A concurrent teardown can free a table page while it is being walked. It can also clear a parent entry after show_pte() checked it; the regular pXd_offset() helpers then reread the cleared entry and can derive a bogus lower-level pointer and fault again.
Use the lockless offset helpers with the saved parent entries, as gup_fast() does, and pass the saved PMD to pte_offset_map().
For task page tables, arm64 selects MMU_GATHER_RCU_TABLE_FREE. Disable local interrupts around the walk to hold off RCU-deferred table frees and block the tlb_remove_table_sync_one() IPI until the walk is finished.
Leer descripción completaMostrar menos
Place the IRQ guard after the header print. This does not make the output a consistent snapshot, but prevents the task page-table walk from dereferencing a released table page or deriving a pointer from a different parent value.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.20%
- Percentil entre todas las CVEs puntuadas: 9
- Fecha de la puntuación: 4/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/08d931a0a850ad16a64f2cd23a19f40795cdbdf7
- https://git.kernel.org/stable/c/0f05d95b99164a9ccc4cf4a4920e0ff0228138ad
- https://git.kernel.org/stable/c/68cbd70795dd8c06e7ccdc4eb0b74c5b180076c3
- https://git.kernel.org/stable/c/a77644d009dece1104b6fcc6e322b0e4503db0d6
- https://git.kernel.org/stable/c/b28fe65a36b8209b6adcf2722c7ce974cf9ac8d1
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-93239",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "1d18c47c735e8adfe531fc41fae31e98f86b68fe",
"lessThan": "08d931a0a850ad16a64f2cd23a19f40795cdbdf7",
"versionType": "git"
},
{
"status": "affected",
"version": "1d18c47c735e8adfe531fc41fae31e98f86b68fe",
"lessThan": "b28fe65a36b8209b6adcf2722c7ce974cf9ac8d1",
"versionType": "git"
},
{
"status": "affected",
"version": "1d18c47c735e8adfe531fc41fae31e98f86b68fe",
"lessThan": "68cbd70795dd8c06e7ccdc4eb0b74c5b180076c3",
"versionType": "git"
},
{
"status": "affected",
"version": "1d18c47c735e8adfe531fc41fae31e98f86b68fe",
"lessThan": "0f05d95b99164a9ccc4cf4a4920e0ff0228138ad",
"versionType": "git"
},
{
"status": "affected",
"version": "1d18c47c735e8adfe531fc41fae31e98f86b68fe",
"lessThan": "a77644d009dece1104b6fcc6e322b0e4503db0d6",
"versionType": "git"
}
],
"programFiles": [
"arch/arm64/mm/fault.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "3.7"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "3.7",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.6.157",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.110",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.51",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.5",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"arch/arm64/mm/fault.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-24T16:17:19.690",
"references": [
{
"url": "https://git.kernel.org/stable/c/08d931a0a850ad16a64f2cd23a19f40795cdbdf7",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/0f05d95b99164a9ccc4cf4a4920e0ff0228138ad",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/68cbd70795dd8c06e7ccdc4eb0b74c5b180076c3",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a77644d009dece1104b6fcc6e322b0e4503db0d6",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/b28fe65a36b8209b6adcf2722c7ce974cf9ac8d1",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\narm64: mm: Fix the lockless page-table walk in show_pte()\n\nshow_pte() walks page tables locklessly and can run with interrupts\nenabled. A concurrent teardown can free a table page while it is being\nwalked. It can also clear a parent entry after show_pte() checked it; the\nregular pXd_offset() helpers then reread the cleared entry and can derive a\nbogus lower-level pointer and fault again.\n\nUse the lockless offset helpers with the saved parent entries, as\ngup_fast() does, and pass the saved PMD to pte_offset_map().\n\nFor task page tables, arm64 selects MMU_GATHER_RCU_TABLE_FREE. Disable\nlocal interrupts around the walk to hold off RCU-deferred table frees and\nblock the tlb_remove_table_sync_one() IPI until the walk is finished.\n\nPlace the IRQ guard after the header print. This does not make the output a\nconsistent snapshot, but prevents the task page-table walk from\ndereferencing a released table page or deriving a pointer from a different\nparent value."
}
],
"lastModified": "2026-09-24T16:17:19.690",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}