Junglewise Threat Intelligence

CVE-2026-93186: Linux kernel CXL mailbox unbounded allocation denial of service

CVE-2026-93186 · Severity: info · CVSS 0 · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's CXL (Compute Express Link) mailbox interface failed to validate user-supplied output buffer sizes, allowing a local attacker to request huge memory allocations that could exhaust system resources and trigger kernel warnings or panics. This affects systems with CXL-capable hardware where unprivileged processes can invoke the CXL_MEM_SEND_COMMAND ioctl.

Technical details

The vulnerability is an unbounded allocation issue in drivers/cxl/core/mbox.c. The CXL_MEM_SEND_COMMAND ioctl bounds the user's input buffer size but leaves the output buffer size (out.size) unchecked. The code then calls kvzalloc(out.size) without validation, allowing a user to request allocations larger than available memory. Allocations above INT_MAX trigger kernel warnings and memory tainting; with panic_on_warn=1 enabled, this causes a kernel panic. The fix clamps the output allocation to the payload_size using min_t(). The vulnerability requires local access to invoke the ioctl but no additional privileges. The patch was committed upstream on 2026-06-29 and backported to stable kernels.

Affected products

  • Linux Linux kernel Affected versions prior to fix commit 8a13db9f899d149c3aab24abcb668121cfda5a4f

Timeline

  • 2026-09-17: disclosed: CVE-2026-93186 published
  • 2026-06-29: patched: Upstream commit 8a13db9f899d149c3aab24abcb668121cfda5a4f merged
  • 2026-09-14: patched: Backported to stable kernels

References

Related threats