CVE-2026-93259
Received Received - Intake

Register Corruption in Linux Kernel PCREL Mode

Vulnerability report for CVE-2026-93259, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-24

Last updated on: 2026-09-24

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: powerpc/irq: Fix missing r2 clobber in PCREL inline assembly In CONFIG_PPC_KERNEL_PCREL mode, r2 is no longer reserved for the TOC pointer and is available as a caller-saved register [0]. Both call_do_irq() and call_do_softirq() use inline assembly to call functions with stack switching, but fail to list r2 in their clobber lists. This causes the compiler to assume r2 is preserved across these calls, leading to register corruption when the called functions (__do_irq and __do_softirq) clobber r2. As a result of this kernel crash during interrupt handling is seen and the kernel fails to boot: BUG: Unable to handle kernel data access on write at 0xc000000404697638 Faulting instruction address: 0xc0000000000181ec Oops: Kernel access of bad area, sig: 11 [#1] NIP [c0000000000181ec] __do_IRQ+0x6c/0xc0 With older GCC, the compiler would conservatively allocate callee-saved registers (like r31) for values spanning function calls, accidentally avoiding the bug: <__do_IRQ>: 00 00 00 60 nop a6 02 08 7c mflr r0 f8 ff e1 fb std r31,-8(r1) f0 ff c1 fb std r30,-16(r1) 2d 03 10 06 pla r31,53297316 ... 3d e8 ff 4b bl c0000000000165ac <__do_irq> 00 00 21 e8 ld r1,0(r1) 28 00 4d e9 ld r10,40(r13) 40 00 21 38 addi r1,r1,64 2a f9 aa 7f stdx r29,r10,r31 With newer GCC 14, the compiler uses r2 for such values, exposing the missing clobber specification: <__do_IRQ>: 00 00 00 60 nop a6 02 08 7c mflr r0 f0 ff c1 fb std r30,-16(r1) f8 ff e1 fb std r31,-8(r1) 29 02 10 06 pla r2,36252592 # c0000000022aadc0 <__irq_regs> ... 85 dc ff 4b bl c000000000015ee0 <__do_irq> 00 00 21 e8 ld r1,0(r1) 28 00 2d e9 ld r9,40(r13) 30 00 21 38 addi r1,r1,48 2a 11 c9 7f stdx r30,r9,r2 Fix this by adding r2 to the clobber list for both call_do_irq() and call_do_softirq() when CONFIG_PPC_KERNEL_PCREL is enabled. [0]: https://www.mail-archive.com/gcc-patches@gcc.gnu.org/msg313226.html

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-24
Last Modified
2026-09-24
Generated
2026-09-25
AI Q&A
2026-09-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Linux kernel vulnerability affecting powerpc systems with CONFIG_PPC_KERNEL_PCREL enabled. It involves missing register clobber declarations in inline assembly for interrupt handling functions. The r2 register, normally reserved for the TOC pointer, is used as a caller-saved register in this mode. The bug causes register corruption when calling functions like __do_irq and __do_softirq, leading to kernel crashes during interrupt handling.

Detection Guidance

This vulnerability affects the Linux kernel specifically when CONFIG_PPC_KERNEL_PCREL is enabled on PowerPC systems. Detection requires checking kernel logs for crashes during interrupt handling or boot failures with messages like 'Unable to handle kernel data access' or 'Kernel access of bad area'. Inspect kernel configuration for CONFIG_PPC_KERNEL_PCREL and verify if the kernel version matches the affected code paths.

Impact Analysis

This vulnerability can cause kernel crashes during interrupt handling, resulting in system instability or failure to boot. Systems using affected Linux kernel versions with CONFIG_PPC_KERNEL_PCREL enabled may experience unexpected crashes, data corruption, or denial of service when interrupts occur.

Compliance Impact

This vulnerability is a low-level kernel crash in the Linux powerpc architecture due to register corruption during interrupt handling. It does not directly affect compliance with standards like GDPR or HIPAA, as those focus on data protection, privacy, and security controls rather than kernel stability.

Mitigation Strategies

Apply the kernel patch that adds r2 to the clobber list for call_do_irq() and call_do_softirq() when CONFIG_PPC_KERNEL_PCREL is enabled. Rebuild and install the updated kernel. If using a distribution kernel, check for and install available updates from your vendor. Ensure CONFIG_PPC_KERNEL_PCREL is disabled if not required.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-93259. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart