Race condition in Linux kernel - CVE-2026-93096
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local user to corrupt the device's transfer context.
The vulnerability exists due to a race condition in cxl_get_feature() and cxl_set_feature() when concurrent multi-part Get or Set Feature transfers are processed. A local user can issue concurrent feature requests to corrupt the device's transfer context.
The issue affects transfers whose payloads exceed the mailbox payload size.