Junglewise Threat Intelligence

CVE-2026-93164: Linux kernel uprobes/x86 redzone clobbering

CVE-2026-93164 · Severity: info · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's uprobe optimization mechanism could corrupt temporary data stored in the CPU's redzone area (a reserved memory region used by compiled code) when attaching dynamic tracing probes to applications. This vulnerability could cause unpredictable application behavior or crashes when uprobes are actively used for debugging or performance monitoring.

Technical details

The vulnerability exists in the x86-64 uprobe optimization code, which uses a 5-byte NOP instruction as the base for optimized tracing probes. The optimized probe's call instruction storing the return address on the stack could corrupt the redzone area (the 128 bytes below the stack pointer) where user-space code may store temporary data without adjusting RSP. The fix moves optimized uprobes to a 10-byte NOP foundation and inserts a LEA instruction (lea -0x80(%rsp), %rsp) before the call to escape the redzone area. The patch implements careful atomic instruction rewriting sequences during optimization and unoptimization phases to ensure thread safety. This is a kernel-level fix with no known public exploits; the issue affects systems with active uprobe-based tracing or performance monitoring tools.

Affected products

  • Linux Linux kernel affected versions not explicitly specified in advisory

Timeline

  • 2026-09-17: disclosed

Related threats