SB20260925118 - Reliance on undefined behavior in Linux kernel powerpc kernel
Published: September 25, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Reliance on undefined behavior (CVE-ID: CVE-2026-93259)
CWE-ID: CWE-758 - Reliance on Undefined, Unspecified, or Implementation-Defined Behavior
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an incorrect inline assembly clobber list in the powerpc interrupt-handling functions call_do_irq() and call_do_softirq() when executing the affected stack-switching calls in CONFIG_PPC_KERNEL_PCREL mode. A local user can trigger the affected interrupt-handling paths to cause a denial of service.
Newer GCC versions can allocate values spanning the calls to r2, exposing register corruption when the called functions modify that register.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/00be69070d91d2be978e752bb117a0a4db0e1281
- https://git.kernel.org/stable/c/602ee44415f3eaa7893f7fc488c7c1d4a0bdbd7a
- https://git.kernel.org/stable/c/7b0093b638c8f2b94b0778a69fd1ccad54299b29
- https://git.kernel.org/stable/c/90d953002cf0b233dd053a0e7cb67ab79cebd0e3
- https://git.kernel.org/stable/c/dcc442a49c0f540193910dacdca7506bcadc7ec5