7.8

CVE-2026-93079

cxl/features: Reject Get Feature count larger than the output buffer

In the Linux kernel, the following vulnerability has been resolved:

cxl/features: Reject Get Feature count larger than the output buffer

cxlctl_get_feature() sizes its output buffer from the user's
fwctl_rpc.out_len, but the device is told to write
cxl_mbox_get_feat_in.count bytes into rpc_out->payload, which is a
separate user-controlled value. Nothing bounds count against out_len, so
a small out_len with a large count overflows the kvzalloc()'d buffer.
A heap OOB write reachable from FWCTL_RPC.

Reject requests where count exceeds the available payload room, before
allocating.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 5908f3ed6dc209e5c824e63afda7545805f75a7e
Version < 3f02031a0a53de0d3ef066c92d0486b2b11be40c
Status affected
Version 5908f3ed6dc209e5c824e63afda7545805f75a7e
Version < 329ea475581c647a680a6937e353c1a6e2534b40
Status affected
Version 5908f3ed6dc209e5c824e63afda7545805f75a7e
Version < 4bf6bac375076ced2fa4b3fef8739bd985f93456
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.15
Status affected
Version 0
Version < 6.15
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.058
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/3f02031a0a53de0d3ef066c92d0486b2b11be40c
https://git.kernel.org/stable/c/329ea475581c647a680a6937e353c1a6e2534b40
https://git.kernel.org/stable/c/4bf6bac375076ced2fa4b3fef8739bd985f93456