Description
In the Linux kernel, the following vulnerability has been resolved:

misc: bcm-vk: Use acquire/release for msgq_inited

bcm_vk_sync_msgq() fills the message queue information and then sets
msgq_inited. Readers call bcm_vk_drv_access_ok() before accessing the
message queues and their cached queue information.

atomic_set()/atomic_read() do not order those accesses. A reader can see
msgq_inited set while still seeing stale queue information. Use release
when publishing the initialized queues and acquire when checking the gate.

Keep the clear in bcm_vk_blk_drv_access() as atomic_set(). It closes the
gate and does not publish queue state to readers.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel data integrity compromise due to improper message queue synchronization
Action: Immediate Patch
AI Analysis

Impact

In the Linux kernel's bcm_vk driver, the synchronization around the message queue initialization flag, msgq_inited, was implemented using atomic_set/atomic_read without proper acquire/release ordering. As a result, the flag can be set before the queue structure is fully populated, allowing readers to observe an initialized flag while still accessing stale or incomplete data. This race condition can lead to unpredictable behavior, data corruption, or incorrect driver operation, potentially creating a kernel state that an attacker might exploit to gain elevated privileges or cause a denial of service. The flaw is a classic concurrency issue related to improper initialization.

Affected Systems

This vulnerability affects any Linux system that builds and loads the bcm_vk driver within the kernel. No specific version bounds are provided, so all current and past kernel releases that compile this driver are potentially impacted. Vendors include Linux distributions that ship this driver as part of the kernel package. Because the kernel is the target, all machines running a kernel that is not patched by the referenced commit are susceptible.

Risk and Exploitability

The CVSS score is not specified, and the EPSS score is less than 1%, indicating a very low probability of exploitation at this time. The vulnerability is listed as not present in CISA’s KEV catalog. Exploitation would likely require local or elevated access to a system running the affected kernel configuration, and the exploitation surface is limited to scenarios that involve both the writer and reader of the bcm_vk message queue. Given the low prevalence and narrow attack surface, the risk remains moderate but not negligible. Monitoring for kernel updates and applying the patch is strongly recommended.

Generated by OpenCVE AI on September 19, 2026 at 09:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the bcm_vk synchronization fix committed in the referenced patches.
  • Uninstall or disable the bcm_vk kernel module if an immediate kernel upgrade is not possible, thereby removing the race condition from the kernel runtime.
  • For custom kernel builds, modify the bcm_vk driver to replace the atomic_set/atomic_read usage with proper acquire/release semantics around msgq_inited, ensuring the flag is set only after the queue data has been fully initialized.

Generated by OpenCVE AI on September 19, 2026 at 09:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-665

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: misc: bcm-vk: Use acquire/release for msgq_inited bcm_vk_sync_msgq() fills the message queue information and then sets msgq_inited. Readers call bcm_vk_drv_access_ok() before accessing the message queues and their cached queue information. atomic_set()/atomic_read() do not order those accesses. A reader can see msgq_inited set while still seeing stale queue information. Use release when publishing the initialized queues and acquire when checking the gate. Keep the clear in bcm_vk_blk_drv_access() as atomic_set(). It closes the gate and does not publish queue state to readers.
Title misc: bcm-vk: Use acquire/release for msgq_inited
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:10:41.716Z

Reserved: 2026-09-17T15:57:05.658Z

Link: CVE-2026-93052

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:58.657

Modified: 2026-09-17T17:17:58.657

Link: CVE-2026-93052

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T07:00:08Z

Weaknesses