Out-of-bounds write in Linux kernel - CVE-2026-93077
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local user to write beyond the feature output buffer.
The vulnerability exists due to improper bounds checking in cxl_get_feature() when a CXL device returns more feature data than requested during a partial read iteration. A local user can cause a CXL device to return more feature data than requested to write beyond the feature output buffer.