Improper Validation of Specified Quantity in Input in Linux kernel - CVE-2026-93237
Published: September 25, 2026
Vulnerability details
The vulnerability allows a local privileged user to corrupt page tables and cause a denial of service.
The vulnerability exists due to improper bounds checking in LoongArch physical memory range handling when allocating ZONE_DEVICE regions. A local privileged user can trigger allocation of a ZONE_DEVICE region outside the vmemmap window to corrupt page tables and cause a denial of service.
The issue affects configurations where cpu_pabits is lower than MAX_PHYSMEM_BITS.