UNKNOWN NVD
CVE-2026-93079
In the Linux kernel, the following vulnerability has been resolved: cxl/features: Reject Get Feature count larger than the output buffer cxlctl_get_feature()
In the Linux kernel, the following vulnerability has been resolved:
cxl/features: Reject Get Feature count larger than the output buffer
cxlctl_get_feature() sizes its output buffer from the user's
fwctl_rpc.out_len, but the device is told to write
cxl_mbox_get_feat_in.count bytes into rpc_out->payload, which is a
separate user-controlled value. Nothing bounds count against out_len, so
a small out_len with a large count overflows the kvzalloc()'d buffer.
A heap OOB write reachable from FWCTL_RPC.
Reject requests where count exceeds the available payload room, before
allocating.
References
- https://git.kernel.org/stable/c/329ea475581c647a680a6937e353c1a6e2534b40
- https://git.kernel.org/stable/c/3f02031a0a53de0d3ef066c92d0486b2b11be40c
- https://git.kernel.org/stable/c/4bf6bac375076ced2fa4b3fef8739bd985f93456
This unknown severity vulnerability was published on 2026-09-17 via NVD.
vulnfeed aggregates 13500 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.