Uncontrolled Memory Allocation in Linux kernel - CVE-2026-93186
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to uncontrolled memory allocation in the CXL mailbox command constructor cxl_mbox_cmd_ctor() when processing CXL_MEM_SEND_COMMAND requests with an oversized output size. A local user can submit a command with a large output size to cause a denial of service.
A system panic requires panic_on_warn=1.