Infinite loop in Linux kernel - CVE-2026-93097
Published: September 18, 2026
Vulnerability details
The vulnerability allows an attacker with physical access to cause a denial of service.
The vulnerability exists due to an infinite loop in the CXL poison list processing function when processing a device response containing an empty poison payload with the CXL_POISON_FLAG_MORE flag set. An attacker with physical access can cause a CXL device to return a crafted poison response to cause a denial of service.
Affected software
How to mitigate CVE-2026-93097
External References
- https://git.kernel.org/stable/c/42eab80981f4d2ac820e253e80ecf92f8cd91f69
- https://git.kernel.org/stable/c/6ad491cef1a812cf7b53aa769cd8869516c47362
- https://git.kernel.org/stable/c/86771c105293ca26bfcc320b4f60d32c137b54aa
- https://git.kernel.org/stable/c/8b301c4afbce4bc3f94528441d8d5ce1366504ad
- https://git.kernel.org/stable/c/e77594e0cea67ab1c2317a27aa77a744e26ad6a6