Use of Out-of-range Pointer Offset in Linux kernel - CVE-2026-93167
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to incorrect stack offset handling in the C-SKY syscall trace path when tracing system calls with fifth or sixth arguments. A local user can trace a process executing a system call with five or six arguments to cause a denial of service.
The issue is limited to the C-SKY ABIv2 syscall trace path.
Affected software
How to mitigate CVE-2026-93167
External References
- https://git.kernel.org/stable/c/31c81b376e5f058c7f2c94f69719cf7caec2fc3f
- https://git.kernel.org/stable/c/343aa5275484d627c921a42e8e115cae366be5de
- https://git.kernel.org/stable/c/64e3ec7a71d3b715e2567f19f64207f04999bb0c
- https://git.kernel.org/stable/c/863fa63fd1491f201ac819f805a8db98d2a32c3d
- https://git.kernel.org/stable/c/a776afa89424570bfa637ebf812ca281a5732904
- https://git.kernel.org/stable/c/abb81e5ce7d995baa41556b8125fa59e28ba3be8
- https://git.kernel.org/stable/c/e71a3dc5b8d2ea4d9cfbdb135d6b7777de84212e
- https://git.kernel.org/stable/c/e9ae8e86eed68bea5d2670eadf61938a43bd2263