CVE-2026-93186
CVE CVE-2026-93186EUVD EUVD-2026-82294Published 2026-09-17T16:12:12.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: cxl/mbox: Clamp mailbox output allocation to the payload size CXL_MEM_SEND_COMMAND bounds the user's in.size to the mailbox payload size but leaves out.size unbounded, then cxl_mbox_cmd_ctor() calls kvzalloc(out.size). A large out.size drives a huge allocation, above INT_MAX it WARNs and taints, and with panic_on_warn=1 it panics. The transport __cxl_pci_mbox_send_cmd() already clamps the response copy to min(out.size, payload_size, device len), so the output buffer is never written beyond payload_size. Clamp the allocation to payload_size too, matching the RAW path.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 583fa5e71caeb79e04e477e9837e2f7fa53b71e4 <b4e11c731d6bee3b87315e055a1ca417c92dc1fc; patch: 6.18.52; patch: 7.2.6; 5.12; patch: 6.12.110; patch: 0; 583fa5e71caeb79e04e477e9837e2f7fa53b71e4 <31d4841eca7c4b75751ca96d24339e19303337f2; 583fa5e71caeb79e04e477e9837e2f7fa53b71e4 <f5d2bbf0300f46307948864fbb97bce5097f4fe2; patch: 7.3-rc1; 583fa5e71caeb79e04e477e9837e2f7fa53b71e4 <8a13db9f899d149c3aab24abcb668121cfda5a4f
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.