Executive brief
The Linux kernel's bcm-vk driver (used for Broadcom VK accelerator devices) contained a race condition in message queue initialization. Without proper atomic ordering, threads could observe a ready signal while seeing stale queue data, potentially leading to use-after-free or data corruption when accessing device message queues. The fix adds proper acquire/release semantics to prevent this visibility ordering issue.
Technical details
The vulnerability is a memory ordering race condition in the bcm-vk misc driver's message queue initialization (drivers/misc/bcm-vk/bcm_vk_msg.c). The bcm_vk_sync_msgq() function wrote queue information and then set msgq_inited using atomic_set(), while readers checked msgq_inited using atomic_read() before accessing queues. These non-ordered atomics do not guarantee that readers see the published queue state before proceeding. An attacker or buggy code path could observe msgq_inited as set while still reading stale queue pointers, causing out-of-bounds access or use-after-free. The fix replaces atomic_set() with atomic_set_release() and atomic_read() with atomic_read_acquire() to enforce proper memory barriers. This is a correctness fix with no known active exploits; the impact depends on whether attacker-controlled code can trigger the race window.
Affected products
- Linux Linux kernel all versions up to patched
Timeline
- 2026-09-17: disclosed: CVE-2026-93052 published
- 2026-06-03: patched: Upstream patch commit 61b101c6a150057b6d512421ed108aed16e822ea by Gui-Dong Han
- 2026-09-14: patched: Stable kernel releases updated