Junglewise Threat Intelligence

CVE-2026-93073: Linux kernel dax race condition in holder_ops

CVE-2026-93073 · Severity: info · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's DAX (Direct Access) subsystem contains a race condition in the failure notification handler that can cause a NULL pointer dereference. When the kernel attempts to notify filesystems of memory failures in direct-access storage, a concurrent cleanup operation can clear the handler pointer between the NULL check and the actual call, resulting in a crash that disrupts system availability.

Technical details

The vulnerability is a classic time-of-check-time-of-use (TOCTOU) race condition in the dax_holder_notify_failure() function within drivers/dax/super.c. The code reads the holder_ops pointer twice without using READ_ONCE(): once for a NULL check and once for the indirect function call. A concurrent fs_put_dax() call can clear holder_ops between these two reads, causing the NULL check to pass while the subsequent dereference accesses NULL. The root cause is missing memory barrier semantics (READ_ONCE) to prevent compiler optimizations that could reload the value. The attack requires local access to trigger concurrent fs_put_dax() and dax_holder_notify_failure() operations. The fix fetches holder_ops once into a local variable using READ_ONCE() to ensure both the check and call observe the same value. Patches are available in kernel stable branches.

Affected products

  • Linux Linux kernel Multiple versions (patched in linux-6.0.y and later stable branches)

Timeline

  • 2026-06-15: other: Patch authored by John Groves
  • 2026-09-14: patched: Patch committed to stable tree

References

Related threats