CVE-2026-93079
Received
Received - Intake
BaseFortify
Vulnerability report for CVE-2026-93079, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-17
Last updated on: 2026-09-18
Assigner: kernel.org
Description
Description
In the Linux kernel, the following vulnerability has been resolved:
cxl/features: Reject Get Feature count larger than the output buffer
cxlctl_get_feature() sizes its output buffer from the user's
fwctl_rpc.out_len, but the device is told to write
cxl_mbox_get_feat_in.count bytes into rpc_out->payload, which is a
separate user-controlled value. Nothing bounds count against out_len, so
a small out_len with a large count overflows the kvzalloc()'d buffer.
A heap OOB write reachable from FWCTL_RPC.
Reject requests where count exceeds the available payload room, before
allocating.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Linux | Linux | 5908f3ed6dc209e5c824e63afda7545805f75a7e |
| Linux | Linux | 5908f3ed6dc209e5c824e63afda7545805f75a7e |
| Linux | Linux | 5908f3ed6dc209e5c824e63afda7545805f75a7e |
| Linux | Linux | 6.15 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |