Race condition in Linux kernel - CVE-2026-93782
Published: September 25, 2026
Vulnerability details
The vulnerability allows a local user to write response data to an unrelated userspace object.
The vulnerability exists due to a race condition in vhost-scsi ioctl handling when replacing the memory table while commands are in flight. A local user can submit commands and issue VHOST_SET_MEM_TABLE to write response data to an unrelated userspace object.