Incorrect calculation in Linux kernel - CVE-2026-93219
Published: September 25, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an incorrect minimum interval calculation in the sun4i clockevent timer driver when processing timer events. A local user can trigger timer events to cause a denial of service.
The issue can leave the next timer event stuck during oneshot, high-resolution, or nohz timer operation.
Affected software
How to mitigate CVE-2026-93219
External References
- https://git.kernel.org/stable/c/0cc4b14d7401d50e53a01f1554147ee075ee6943
- https://git.kernel.org/stable/c/151eb52f8712017c8f7b00bb2305e8916cb9e3dc
- https://git.kernel.org/stable/c/53a3bc024b8e5d284468cce84957cded5f859f98
- https://git.kernel.org/stable/c/753a220084dfc4d737f2ab9eaddc9a01a397edd7
- https://git.kernel.org/stable/c/bf38be01d43c4e4ca903aff7236d8486a950a252
- https://git.kernel.org/stable/c/d21808328225ab8cee46885bf9a0dffcefbe630e
- https://git.kernel.org/stable/c/ebba4d0aeba0e8eb3a9676380fc2652de8ab1c44
- https://git.kernel.org/stable/c/f0efafcdf6eec1f3361bfd8c811420198f55c8bb