Executive brief
The Linux kernel CXL (Compute Express Link) subsystem manages memory regions used by high-performance interconnected devices. A race condition allowed userspace to delete a region while the kernel was creating or configuring it, violating internal locking assumptions and potentially causing memory management inconsistencies or system instability.
Technical details
This is a race condition (CWE-362) in the CXL region management code where the lock protecting region lifecycle was insufficiently scoped. The vulnerable component is the region creation and deletion handlers in drivers/cxl/core/region.c. An unprivileged local user with access to CXL device sysfs interfaces can trigger region creation, then immediately delete it via userspace before the kernel completes the attach_target() or device_add() operations. This violates the kernel's assumption that a region remains registered through cxl_add_to_region() completion and that devm_add_action_or_reset() operates on a live cxl_region structure. The fix expands the mutex lock scope (renamed regions_lock) to cover the entire critical period from region construction through action registration, preventing concurrent deletion during these windows.
Affected products
- Linux Linux kernel affected versions include at least 5.x through 7.x series (specific version range not precisely specified in advisory)
Timeline
- 2026-08-15: disclosed: Published in NVD
- 2026-05-19: patched: Patch authored by Dan Williams; committed upstream and to stable trees