Description
In the Linux kernel, the following vulnerability has been resolved:

cxl/features: Clamp Get Feature output size to the remaining buffer

cxl_get_feature() reads a feature in a loop but passes a fixed size_out
as the output capacity every iteration. On the last partial iteration
the buffer has less room left, so a device that returns more than asked
can overflow feat_out.

Use the per-iter size data_to_rd_size, which already tracks the
remaining room, as the output capacity.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

cxl_get_feature reads a feature in a loop but incorrectly passes a fixed output size for each iteration, causing the buffer to overflow when a device returns more data than expected on a partial pass. The overflow corrupts kernel memory, which can lead to arbitrary code execution with kernel privileges. The vulnerability is a classic buffer overflow that directly compromises the confidentiality, integrity, and availability of the system.

Affected Systems

The flaw exists in the Linux kernel’s cxl/features implementation. No specific kernel versions are listed, so any kernel containing this code path and enabling CXL support is potentially vulnerable until the patch is applied. Users of CXL‑enabled devices on any Linux distribution should consider their systems affected.

Risk and Exploitability

The EPSS score is less than 1 % and the vulnerability is not listed in the CISA KEV catalog, suggesting a low probability of initial exploitation. However, the impact of a successful exploit is high, and the flaw can be triggered by interacting with a CXL device that returns oversized data. Attackers would need to target a specific device or environment; the vector is likely local or remote depending on device access.

Generated by OpenCVE AI on September 19, 2026 at 09:11 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the patch for the cxl feature output size clamp.
  • If the system does not require CXL support, disable CXL in the kernel configuration or through the boot loader to eliminate the attack surface.
  • Configure device firmware to respect the maximum output size or limit device visibility to trusted processes to avoid oversized data returns.

Generated by OpenCVE AI on September 19, 2026 at 09:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: cxl/features: Clamp Get Feature output size to the remaining buffer cxl_get_feature() reads a feature in a loop but passes a fixed size_out as the output capacity every iteration. On the last partial iteration the buffer has less room left, so a device that returns more than asked can overflow feat_out. Use the per-iter size data_to_rd_size, which already tracks the remaining room, as the output capacity.
Title cxl/features: Clamp Get Feature output size to the remaining buffer
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:10:59.026Z

Reserved: 2026-09-17T15:57:05.661Z

Link: CVE-2026-93077

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:01.643

Modified: 2026-09-17T17:18:01.643

Link: CVE-2026-93077

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T13:45:15Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer