Description
In the Linux kernel, the following vulnerability has been resolved:

dax/fsdev: clear vmemmap_shift when binding static pgmap

Clear pgmap->vmemmap_shift for static DAX devices. When rebinding a static
device from device_dax (which may set vmemmap_shift based on alignment) to
fsdev_dax, the stale vmemmap_shift persists on the shared pgmap. Explicitly
zero it before devm_memremap_pages() so the vmemmap is built for order-0
folios as fsdev requires.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel Memory Corruption
Action: Update Kernel
AI Analysis

Impact

The bug was introduced when rebinding a static DAX device from the device_dax path to the fsdev_dax path. Because the vmemmap_shift field was not cleared, a stale value persisted on a shared page map, causing the kernel to build an incorrect virtual memory map for order‑0 folios. This incorrect map can lead to memory corruption or kernel exceptions during DAX operations.

Affected Systems

The vulnerability resides in the Linux kernel and affects any kernel that contains the faulty rebinding logic. As no specific version range is listed, all kernel releases prior to the patch that introduced the proper zeroing of vmemmap_shift are potentially impacted.

Risk and Exploitability

The EPSS score is lower than 1%, indicating a very low probability of exploitation in the field. The vulnerability is not yet listed in the CISA KEV catalog, so it is not a known exploit. Because the flaw involves internal kernel state the attack vector is likely local and requires triggering the rebind of a static DAX device, which would typically demand privileged access. Despite the low exploitation likelihood, an unpatched kernel could suffer severe instability or data loss if the condition were triggered.

Generated by OpenCVE AI on September 19, 2026 at 06:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a Linux kernel update that includes the patch clearing vmemmap_shift for static DAX devices
  • If an immediate kernel upgrade is not possible, configure your system to avoid rebinding static DAX devices between device_dax and fsdev_dax until the patch is applied
  • Monitor dmesg and system logs for signs of kernel panics or memory corruption related to DAX activity

Generated by OpenCVE AI on September 19, 2026 at 06:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-120
CWE-665

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: dax/fsdev: clear vmemmap_shift when binding static pgmap Clear pgmap->vmemmap_shift for static DAX devices. When rebinding a static device from device_dax (which may set vmemmap_shift based on alignment) to fsdev_dax, the stale vmemmap_shift persists on the shared pgmap. Explicitly zero it before devm_memremap_pages() so the vmemmap is built for order-0 folios as fsdev requires.
Title dax/fsdev: clear vmemmap_shift when binding static pgmap
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:10:58.370Z

Reserved: 2026-09-17T15:57:05.661Z

Link: CVE-2026-93076

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:01.540

Modified: 2026-09-17T17:18:01.540

Link: CVE-2026-93076

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T05:30:16Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

  • CWE-665

    Improper Initialization