Description
In the Linux kernel, the following vulnerability has been resolved:

cxl/region: Fix use-after-free in find_pos_and_ways() error path

The error path releases its reference to a switch decoder before
logging an error that includes the decoder name. If the released
reference is the last one, the decoder can be freed before the error
message accesses its name.

Drop the reference after the error is reported.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Use‑After‑Free in the Linux kernel's CXL region code can lead to memory corruption and potential denial of service or privilege escalation.
Action: Apply Patch
AI Analysis

Impact

In the Linux kernel the find_pos_and_ways() error path releases a reference to a switch decoder before logging the error message that includes the decoder name. If that reference was the last one the decoder can be freed before the log accesses its name, creating a classic use‑after‑free race. An attacker who can trigger the error could cause a crash or corrupt kernel memory, potentially allowing escalation of privileges or denial of service. The vulnerability arose from an incorrect order of reference release and error reporting.

Affected Systems

The flaw exists in the Linux kernel for all versions that contain the CXL region code path before the patch from commit 15da704b7. The CPE identifies the product as the Linux kernel generically; no specific version list is provided, so all pre‑patch kernels running the affected code are impacted.

Risk and Exploitability

The CVSS score is not listed, but the EPSS score of less than 1% indicates a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves a privileged or local process that can exercise CXL region operations, as the bug is in kernel space. Exploitation would require inducing the specific error path, which is nontrivial but could be achieved via crafted device or driver interactions. Overall the risk is moderate: high severity if exploited, but low likelihood under current threat landscape.

Generated by OpenCVE AI on September 19, 2026 at 09:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to the latest version that contains the fix from commit 15da704b7
  • If an immediate kernel update is not possible, disable or restrict access to CXL region functionality or the affected device drivers to prevent the error path from being triggered
  • Monitor kernel logs for errors referencing "cxl region" or decoder names to detect potential exploitation attempts or inadvertent crashes

Generated by OpenCVE AI on September 19, 2026 at 09:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: cxl/region: Fix use-after-free in find_pos_and_ways() error path The error path releases its reference to a switch decoder before logging an error that includes the decoder name. If the released reference is the last one, the decoder can be freed before the error message accesses its name. Drop the reference after the error is reported.
Title cxl/region: Fix use-after-free in find_pos_and_ways() error path
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:10:00.333Z

Reserved: 2026-09-16T12:21:13.870Z

Link: CVE-2026-92484

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:50.473

Modified: 2026-09-17T17:17:50.473

Link: CVE-2026-92484

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T10:00:07Z

Weaknesses