Description
In the Linux kernel, the following vulnerability has been resolved:

dax/fsdev: use __va(phys) for kaddr in direct_access

Use __va(phys) instead of virt_addr + linear_offset for the kaddr
return in __fsdev_dax_direct_access(). The previous code added a
device-linear byte offset to virt_addr (which is __va of ranges[0]),
but for multi-range devices with physical gaps between ranges, this
linear arithmetic crosses the gap and produces a wrong kernel virtual
address. Using __va(phys) where phys comes from dax_pgoff_to_phys()
is correct for any range layout because the direct map translates
each physical address independently.

This leaves dev_dax->virt_addr write-only, so remove the field
(suggested by Dave Jiang).
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Incorrect kernel virtual address resolution that may destabilize the kernel
Action: Apply patch
AI Analysis

Impact

In the Linux kernel, the function __fsdev_dax_direct_access calculates a kernel virtual address for a DAX device by adding a linear offset to a base address instead of translating the physical address directly. For devices that provide multiple non‑contiguous physical ranges, this arithmetic can cross a gap and produce an invalid kernel virtual address. The resulting address misresolution could cause corrupt kernel memory accesses or system crashes. The weakness corresponds to CWE‑409, which involves race conditions or time‑of‑check to time‑of‑use errors that can be triggered when a system computes an address based on outdated or incorrect information.

Affected Systems

All Linux kernel builds that include the dax/fsdev subsystem. Any distribution or custom kernel that has not incorporated commit 7b642bd3… and its patch is affected. No explicit version list is provided.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity, while the EPSS score of less than 1% reflects a very low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. Exploitation appears to require direct interaction with a DAX device that has multiple physical ranges, implying a privileged or local scenario. No evidence of remote exploitation exists.

Generated by OpenCVE AI on September 19, 2026 at 22:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor patch that replaces the linear arithmetic with __va(phys), thereby preventing the address misresolution and the race condition described by CWE‑409
  • Restrict direct access to DAX devices to privileged users only; disabling or limiting this capability reduces the attack surface for potential race‑condition exploits
  • Validate that any physical address used for direct access falls within the defined DAX range before mapping, a defensive practice that mitigates CWE‑409 by ensuring checks occur before use

Generated by OpenCVE AI on September 19, 2026 at 22:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-409

Sat, 19 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-409

Sat, 19 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-409

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: dax/fsdev: use __va(phys) for kaddr in direct_access Use __va(phys) instead of virt_addr + linear_offset for the kaddr return in __fsdev_dax_direct_access(). The previous code added a device-linear byte offset to virt_addr (which is __va of ranges[0]), but for multi-range devices with physical gaps between ranges, this linear arithmetic crosses the gap and produces a wrong kernel virtual address. Using __va(phys) where phys comes from dax_pgoff_to_phys() is correct for any range layout because the direct map translates each physical address independently. This leaves dev_dax->virt_addr write-only, so remove the field (suggested by Dave Jiang).
Title dax/fsdev: use __va(phys) for kaddr in direct_access
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:55:52.238Z

Reserved: 2026-09-17T15:57:05.661Z

Link: CVE-2026-93074

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:01.337

Modified: 2026-09-18T18:18:20.197

Link: CVE-2026-93074

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:45:06Z

Weaknesses
  • CWE-409

    Improper Handling of Highly Compressed Data (Data Amplification)