SB2026091840 - Use of Out-of-range Pointer Offset in Linux kernel csky kernel
Published: September 18, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use of Out-of-range Pointer Offset (CVE-ID: CVE-2026-93167)
CWE-ID: CWE-823 - Use of Out-of-range Pointer Offset
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to incorrect stack offset handling in the C-SKY syscall trace path when tracing system calls with fifth or sixth arguments. A local user can trace a process executing a system call with five or six arguments to cause a denial of service.
The issue is limited to the C-SKY ABIv2 syscall trace path.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/31c81b376e5f058c7f2c94f69719cf7caec2fc3f
- https://git.kernel.org/stable/c/343aa5275484d627c921a42e8e115cae366be5de
- https://git.kernel.org/stable/c/64e3ec7a71d3b715e2567f19f64207f04999bb0c
- https://git.kernel.org/stable/c/863fa63fd1491f201ac819f805a8db98d2a32c3d
- https://git.kernel.org/stable/c/a776afa89424570bfa637ebf812ca281a5732904
- https://git.kernel.org/stable/c/abb81e5ce7d995baa41556b8125fa59e28ba3be8
- https://git.kernel.org/stable/c/e71a3dc5b8d2ea4d9cfbdb135d6b7777de84212e
- https://git.kernel.org/stable/c/e9ae8e86eed68bea5d2670eadf61938a43bd2263