Executive brief
The Linux kernel's CXL (Compute Express Link) mailbox interface failed to validate user-supplied output buffer sizes, allowing a local attacker to request huge memory allocations that could exhaust system resources and trigger kernel warnings or panics. This affects systems with CXL-capable hardware where unprivileged processes can invoke the CXL_MEM_SEND_COMMAND ioctl.
Technical details
The vulnerability is an unbounded allocation issue in drivers/cxl/core/mbox.c. The CXL_MEM_SEND_COMMAND ioctl bounds the user's input buffer size but leaves the output buffer size (out.size) unchecked. The code then calls kvzalloc(out.size) without validation, allowing a user to request allocations larger than available memory. Allocations above INT_MAX trigger kernel warnings and memory tainting; with panic_on_warn=1 enabled, this causes a kernel panic. The fix clamps the output allocation to the payload_size using min_t(). The vulnerability requires local access to invoke the ioctl but no additional privileges. The patch was committed upstream on 2026-06-29 and backported to stable kernels.
Affected products
- Linux Linux kernel Affected versions prior to fix commit 8a13db9f899d149c3aab24abcb668121cfda5a4f
Timeline
- 2026-09-17: disclosed: CVE-2026-93186 published
- 2026-06-29: patched: Upstream commit 8a13db9f899d149c3aab24abcb668121cfda5a4f merged
- 2026-09-14: patched: Backported to stable kernels