Memory corruption in Linux kernel - CVE-2026-93046
Published: September 18, 2026
Vulnerability identifier: #VU150984
CSH Severity: Low
CVSS v4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-93046
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to access memory out of bounds.
The vulnerability exists due to improper bounds checking in software_node_get_reference_args() when handling a reference argument index value of UINT_MAX. A local user can provide an index value of UINT_MAX to access memory out of bounds.
Affected software
Linux kernel
How to mitigate CVE-2026-93046
Install security update from vendor's repository.
Linux kernel - update to 7.0 rc3
External References
- https://git.kernel.org/stable/c/0631384eadebc66d92d2dd72d57a0263c3877bee
- https://git.kernel.org/stable/c/231bbc04c58f115a505bf3b668ec69ef40a1773b
- https://git.kernel.org/stable/c/4ebf96d5f834aba7f6d0397db4c421f6078171b9
- https://git.kernel.org/stable/c/6cde06887487b4febd14658c9a246616abcc0097
- https://git.kernel.org/stable/c/849076df15129e47dd8db751fa18489419ffea56
- https://git.kernel.org/stable/c/b2fa4e8c7e4a33e02e6aaa8f6df72f84cf4aed75
- https://git.kernel.org/stable/c/ba3dedcf3bd47017307595a7e54924198f018246
- https://git.kernel.org/stable/c/df5466412b362db7adfa78e3e092fe07ac6769a4