Reliance on undefined behavior in Linux kernel - CVE-2026-93259

 

Reliance on undefined behavior in Linux kernel - CVE-2026-93259

Published: September 25, 2026


Vulnerability identifier: #VU152142
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-93259
CWE-ID: CWE-758
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an incorrect inline assembly clobber list in the powerpc interrupt-handling functions call_do_irq() and call_do_softirq() when executing the affected stack-switching calls in CONFIG_PPC_KERNEL_PCREL mode. A local user can trigger the affected interrupt-handling paths to cause a denial of service.

Newer GCC versions can allocate values spanning the calls to r2, exposing register corruption when the called functions modify that register.


Affected software

Linux kernel

How to mitigate CVE-2026-93259

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins