-

CVE-2026-93077

cxl/features: Clamp Get Feature output size to the remaining buffer

In the Linux kernel, the following vulnerability has been resolved:

cxl/features: Clamp Get Feature output size to the remaining buffer

cxl_get_feature() reads a feature in a loop but passes a fixed size_out
as the output capacity every iteration. On the last partial iteration
the buffer has less room left, so a device that returns more than asked
can overflow feat_out.

Use the per-iter size data_to_rd_size, which already tracks the
remaining room, as the output capacity.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 5e5ac21f629de796ab5d598b59c5e468c6fe4f95
Version < b8abbd5c2928fd839dab702244cc57b228ab43aa
Status affected
Version 5e5ac21f629de796ab5d598b59c5e468c6fe4f95
Version < ca95b15a0760e7724e61addbdd61050be13b6406
Status affected
Version 5e5ac21f629de796ab5d598b59c5e468c6fe4f95
Version < 2aeb21fe557ef154f0cdf4f9745ebd8d5b31ca83
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.15
Status affected
Version 0
Version < 6.15
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.099
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/b8abbd5c2928fd839dab702244cc57b228ab43aa
https://git.kernel.org/stable/c/ca95b15a0760e7724e61addbdd61050be13b6406
https://git.kernel.org/stable/c/2aeb21fe557ef154f0cdf4f9745ebd8d5b31ca83