SB20260918175 - Race condition in Linux kernel misc bcm-vk driver
Published: September 18, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Race condition (CVE-ID: CVE-2026-93052)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to access message queues using stale cached queue information.
The vulnerability exists due to improper synchronization in the bcm-vk message queue initialization and driver access checks when initializing message queues concurrently with driver access. A local user can race message queue initialization with driver access to access message queues using stale cached queue information.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/1df3926ed8771edf286ff753428b243f334e6041
- https://git.kernel.org/stable/c/4984277bc43f84d7506346a09b29af138246d54a
- https://git.kernel.org/stable/c/61b101c6a150057b6d512421ed108aed16e822ea
- https://git.kernel.org/stable/c/679cfada6868723ccf162ec3b78c7402ff2405bf
- https://git.kernel.org/stable/c/a45d6dd3c11e921882a2e74c7c8710b975f2eaa7
- https://git.kernel.org/stable/c/bab66a9e30e39a06f3463b19f8c704386dfd5268
- https://git.kernel.org/stable/c/f7a8f4cbc8cede0be55220367dc52b126e2d39e5