๐Ÿ” CVE Alert

CVE-2026-93186

UNKNOWN 0.0

cxl/mbox: Clamp mailbox output allocation to the payload size

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: cxl/mbox: Clamp mailbox output allocation to the payload size CXL_MEM_SEND_COMMAND bounds the user's in.size to the mailbox payload size but leaves out.size unbounded, then cxl_mbox_cmd_ctor() calls kvzalloc(out.size). A large out.size drives a huge allocation, above INT_MAX it WARNs and taints, and with panic_on_warn=1 it panics. The transport __cxl_pci_mbox_send_cmd() already clamps the response copy to min(out.size, payload_size, device len), so the output buffer is never written beyond payload_size. Clamp the allocation to payload_size too, matching the RAW path.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
583fa5e71caeb79e04e477e9837e2f7fa53b71e4 < f5d2bbf0300f46307948864fbb97bce5097f4fe2 583fa5e71caeb79e04e477e9837e2f7fa53b71e4 < 31d4841eca7c4b75751ca96d24339e19303337f2 583fa5e71caeb79e04e477e9837e2f7fa53b71e4 < b4e11c731d6bee3b87315e055a1ca417c92dc1fc 583fa5e71caeb79e04e477e9837e2f7fa53b71e4 < 8a13db9f899d149c3aab24abcb668121cfda5a4f
Linux / Linux
5.12

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/f5d2bbf0300f46307948864fbb97bce5097f4fe2 git.kernel.org: https://git.kernel.org/stable/c/31d4841eca7c4b75751ca96d24339e19303337f2 git.kernel.org: https://git.kernel.org/stable/c/b4e11c731d6bee3b87315e055a1ca417c92dc1fc git.kernel.org: https://git.kernel.org/stable/c/8a13db9f899d149c3aab24abcb668121cfda5a4f