Reliance on undefined behavior in Linux kernel - CVE-2026-93259
Published: September 25, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an incorrect inline assembly clobber list in the powerpc interrupt-handling functions call_do_irq() and call_do_softirq() when executing the affected stack-switching calls in CONFIG_PPC_KERNEL_PCREL mode. A local user can trigger the affected interrupt-handling paths to cause a denial of service.
Newer GCC versions can allocate values spanning the calls to r2, exposing register corruption when the called functions modify that register.
Affected software
How to mitigate CVE-2026-93259
External References
- https://git.kernel.org/stable/c/00be69070d91d2be978e752bb117a0a4db0e1281
- https://git.kernel.org/stable/c/602ee44415f3eaa7893f7fc488c7c1d4a0bdbd7a
- https://git.kernel.org/stable/c/7b0093b638c8f2b94b0778a69fd1ccad54299b29
- https://git.kernel.org/stable/c/90d953002cf0b233dd053a0e7cb67ab79cebd0e3
- https://git.kernel.org/stable/c/dcc442a49c0f540193910dacdca7506bcadc7ec5