Description
In the Linux kernel, the following vulnerability has been resolved:

dax: read holder_ops once in dax_holder_notify_failure()

dax_holder_notify_failure() reads dax_dev->holder_ops twice without
READ_ONCE() -- once for the NULL check and once for the indirect
notify_failure() call. A concurrent fs_put_dax() can clear holder_ops
between the two reads, so the check can observe a non-NULL pointer while
the call dereferences NULL. (kill_dax() also clears holder_ops, but only
after synchronize_srcu(), so it cannot race a reader that is inside
dax_read_lock(); fs_put_dax() does no such synchronization.)

Fetch holder_ops once into a local with READ_ONCE() so the NULL check and
the indirect call observe the same value.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The Linux kernel function dax_holder_notify_failure() reads the dax_dev->holder_ops pointer twice without proper memory ordering. A concurrent fs_put_dax() can clear this pointer between the NULL check and the dereference, leading to an indirect null pointer dereference that crashes the kernel. This defect falls under the CWE-476 (Null Pointer Dereference) and CWE-362 (Concurrent Modification of Data with No Synchronization). The resulting kernel crash can cause a service interruption or require a system reboot, but it does not provide remote code execution or direct privilege escalation.

Affected Systems

All versions of the Linux kernel that include the DAX (Direct Access) subsystem and have not been updated to a version where dax_holder_notify_failure() stores holder_ops once with READ_ONCE(). The impact covers all Linux distributions that ship the affected kernel code.

Risk and Exploitability

The EPSS score for this vulnerability is less than 1% and it is not listed in the CISA KEV catalog, indicating a very low probability of exploitation under current threat intelligence. The CVSS score is not specified, but the risk is assessed as low to moderate due to the necessity of a local race condition and the lack of a known efficient attack vector. Nevertheless, the crash can jeopardize availability in mission‑critical environments, making timely remediation advisable.

Generated by OpenCVE AI on September 19, 2026 at 06:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version where dax_holder_notify_failure() fetches holder_ops once using READ_ONCE()
  • If an immediate kernel upgrade is not feasible, disable DAX support by removing the ‘direct‑access’ option from the kernel configuration or adding ‘nomount=container’ to the boot parameters to prevent the use of DAX until the patch is applied
  • Monitor system logs for repeated E2BIG or panic messages that may indicate a null pointer dereference in the DAX subsystem

Generated by OpenCVE AI on September 19, 2026 at 06:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362
CWE-476

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: dax: read holder_ops once in dax_holder_notify_failure() dax_holder_notify_failure() reads dax_dev->holder_ops twice without READ_ONCE() -- once for the NULL check and once for the indirect notify_failure() call. A concurrent fs_put_dax() can clear holder_ops between the two reads, so the check can observe a non-NULL pointer while the call dereferences NULL. (kill_dax() also clears holder_ops, but only after synchronize_srcu(), so it cannot race a reader that is inside dax_read_lock(); fs_put_dax() does no such synchronization.) Fetch holder_ops once into a local with READ_ONCE() so the NULL check and the indirect call observe the same value.
Title dax: read holder_ops once in dax_holder_notify_failure()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:10:56.405Z

Reserved: 2026-09-17T15:57:05.661Z

Link: CVE-2026-93073

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:01.207

Modified: 2026-09-17T17:18:01.207

Link: CVE-2026-93073

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T13:45:15Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

  • CWE-476

    NULL Pointer Dereference