-

CVE-2026-93186

cxl/mbox: Clamp mailbox output allocation to the payload size

In the Linux kernel, the following vulnerability has been resolved:

cxl/mbox: Clamp mailbox output allocation to the payload size

CXL_MEM_SEND_COMMAND bounds the user's in.size to the mailbox payload
size but leaves out.size unbounded, then cxl_mbox_cmd_ctor() calls
kvzalloc(out.size). A large out.size drives a huge allocation, above
INT_MAX it WARNs and taints, and with panic_on_warn=1 it panics.

The transport __cxl_pci_mbox_send_cmd() already clamps the response copy
to min(out.size, payload_size, device len), so the output buffer is
never written beyond payload_size. Clamp the allocation to payload_size
too, matching the RAW path.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 583fa5e71caeb79e04e477e9837e2f7fa53b71e4
Version < f5d2bbf0300f46307948864fbb97bce5097f4fe2
Status affected
Version 583fa5e71caeb79e04e477e9837e2f7fa53b71e4
Version < 31d4841eca7c4b75751ca96d24339e19303337f2
Status affected
Version 583fa5e71caeb79e04e477e9837e2f7fa53b71e4
Version < b4e11c731d6bee3b87315e055a1ca417c92dc1fc
Status affected
Version 583fa5e71caeb79e04e477e9837e2f7fa53b71e4
Version < 8a13db9f899d149c3aab24abcb668121cfda5a4f
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.12
Status affected
Version 0
Version < 5.12
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.19% 0.085
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/f5d2bbf0300f46307948864fbb97bce5097f4fe2
https://git.kernel.org/stable/c/31d4841eca7c4b75751ca96d24339e19303337f2
https://git.kernel.org/stable/c/b4e11c731d6bee3b87315e055a1ca417c92dc1fc
https://git.kernel.org/stable/c/8a13db9f899d149c3aab24abcb668121cfda5a4f