Out-of-bounds write in Linux kernel - CVE-2026-93078
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper validation of output buffer size in cxlctl_set_feature() when handling Set Features requests with a too-small output buffer. A local user can submit a Set Features request with an undersized output buffer to cause a denial of service.