Incorrect calculation in Linux kernel - CVE-2026-93074
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local user to access an incorrect kernel virtual address.
The vulnerability exists due to incorrect address calculation in __fsdev_dax_direct_access() when handling multi-range DAX devices with physical gaps between ranges. A local user can invoke direct access for an offset that crosses a physical gap to access an incorrect kernel virtual address.