Missing Release of Resource after Effective Lifetime in Linux kernel - CVE-2026-93083
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to missing release of a resource after its effective lifetime in mailbox_chan_setup() when requesting an additional unidirectional TX receiver mailbox channel. A local user can initiate mailbox channel setup to cause a denial of service.
The primary mailbox channel remains busy for later probe attempts if the additional channel request fails.