Race condition in Linux kernel - CVE-2026-93052
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local user to access message queues using stale cached queue information.
The vulnerability exists due to improper synchronization in the bcm-vk message queue initialization and driver access checks when initializing message queues concurrently with driver access. A local user can race message queue initialization with driver access to access message queues using stale cached queue information.
Affected software
How to mitigate CVE-2026-93052
External References
- https://git.kernel.org/stable/c/1df3926ed8771edf286ff753428b243f334e6041
- https://git.kernel.org/stable/c/4984277bc43f84d7506346a09b29af138246d54a
- https://git.kernel.org/stable/c/61b101c6a150057b6d512421ed108aed16e822ea
- https://git.kernel.org/stable/c/679cfada6868723ccf162ec3b78c7402ff2405bf
- https://git.kernel.org/stable/c/a45d6dd3c11e921882a2e74c7c8710b975f2eaa7
- https://git.kernel.org/stable/c/bab66a9e30e39a06f3463b19f8c704386dfd5268
- https://git.kernel.org/stable/c/f7a8f4cbc8cede0be55220367dc52b126e2d39e5