Reliance on undefined behavior in Linux kernel - CVE-2026-93788

 

Reliance on undefined behavior in Linux kernel - CVE-2026-93788

Published: September 25, 2026


Vulnerability identifier: #VU152104
CSH Severity: Low
CVSS v4: 0 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-93788
CWE-ID: CWE-758
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an attacker with physical access to trigger undefined behavior.

The vulnerability exists due to improper bounds checking in the WGDS table revision index handling when processing WGDS tables reporting an invalid revision value. An attacker with physical access can cause the kernel to process a WGDS table with an invalid revision value to trigger undefined behavior.


Affected software

Linux kernel

How to mitigate CVE-2026-93788

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins