« Volver al listado

CVE-2026-93239

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

arm64: mm: Fix the lockless page-table walk in show_pte()

show_pte() walks page tables locklessly and can run with interrupts enabled. A concurrent teardown can free a table page while it is being walked. It can also clear a parent entry after show_pte() checked it; the regular pXd_offset() helpers then reread the cleared entry and can derive a bogus lower-level pointer and fault again.

Use the lockless offset helpers with the saved parent entries, as gup_fast() does, and pass the saved PMD to pte_offset_map().

For task page tables, arm64 selects MMU_GATHER_RCU_TABLE_FREE. Disable local interrupts around the walk to hold off RCU-deferred table frees and block the tlb_remove_table_sync_one() IPI until the walk is finished.

Leer descripción completaMostrar menos

Place the IRQ guard after the header print. This does not make the output a consistent snapshot, but prevents the task page-table walk from dereferencing a released table page or deriving a pointer from a different parent value.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-93239",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "1d18c47c735e8adfe531fc41fae31e98f86b68fe",
              "lessThan": "08d931a0a850ad16a64f2cd23a19f40795cdbdf7",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1d18c47c735e8adfe531fc41fae31e98f86b68fe",
              "lessThan": "b28fe65a36b8209b6adcf2722c7ce974cf9ac8d1",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1d18c47c735e8adfe531fc41fae31e98f86b68fe",
              "lessThan": "68cbd70795dd8c06e7ccdc4eb0b74c5b180076c3",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1d18c47c735e8adfe531fc41fae31e98f86b68fe",
              "lessThan": "0f05d95b99164a9ccc4cf4a4920e0ff0228138ad",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1d18c47c735e8adfe531fc41fae31e98f86b68fe",
              "lessThan": "a77644d009dece1104b6fcc6e322b0e4503db0d6",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "arch/arm64/mm/fault.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.7"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "3.7",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.6.157",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.51",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "arch/arm64/mm/fault.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-24T16:17:19.690",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/08d931a0a850ad16a64f2cd23a19f40795cdbdf7",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/0f05d95b99164a9ccc4cf4a4920e0ff0228138ad",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/68cbd70795dd8c06e7ccdc4eb0b74c5b180076c3",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a77644d009dece1104b6fcc6e322b0e4503db0d6",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b28fe65a36b8209b6adcf2722c7ce974cf9ac8d1",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\narm64: mm: Fix the lockless page-table walk in show_pte()\n\nshow_pte() walks page tables locklessly and can run with interrupts\nenabled. A concurrent teardown can free a table page while it is being\nwalked. It can also clear a parent entry after show_pte() checked it; the\nregular pXd_offset() helpers then reread the cleared entry and can derive a\nbogus lower-level pointer and fault again.\n\nUse the lockless offset helpers with the saved parent entries, as\ngup_fast() does, and pass the saved PMD to pte_offset_map().\n\nFor task page tables, arm64 selects MMU_GATHER_RCU_TABLE_FREE. Disable\nlocal interrupts around the walk to hold off RCU-deferred table frees and\nblock the tlb_remove_table_sync_one() IPI until the walk is finished.\n\nPlace the IRQ guard after the header print. This does not make the output a\nconsistent snapshot, but prevents the task page-table walk from\ndereferencing a released table page or deriving a pointer from a different\nparent value."
    }
  ],
  "lastModified": "2026-09-24T16:17:19.690",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}