Description
In the Linux kernel, the following vulnerability has been resolved:

cxl/features: Reject Set Features output buffer smaller than the header

cxlctl_set_feature() sizes its output buffer from the user's
fwctl_rpc.out_len but never checks it is large enough to hold even the
fwctl_rpc_cxl_out header. With out_len == 0 , kvzalloc() returns
ZERO_SIZE_PTR, which passes the !rpc_out check, the subsequent
rpc_out->size = 0 then writes through the poison pointer.

Reject requests whose output buffer can't hold the response header,
before allocating. The Set Feature reply carries no payload, so the
header is all that is required.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The kernel component cxlctl_set_feature() allocates an output buffer based on a user‑supplied size but fails to verify that the buffer is large enough to hold the required response header. When the size is zero the allocator returns a zero‑length pointer that passes a null check, after which the code writes into that pointer, causing a null‑pointer dereference and a kernel panic. This constitutes a local denial of service at the kernel level.

Affected Systems

All Linux kernel implementations that include the unpatched cxl/features module are affected. No specific kernel version range is provided in the advisory; the vulnerability exists until the patch that introduces the output‑buffer size check is applied.

Risk and Exploitability

The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a very low expected exploitation probability. Based on the description, it is inferred that the attack vector is local, requiring access to the cxlctl interface and local user privileges; remote exploitation would be unlikely without additional privilege escalation. The severity is primarily to availability, as the flaw results in a kernel crash.

Generated by OpenCVE AI on September 19, 2026 at 12:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the patch which validates the output buffer size before allocation.
  • Restrict access to the cxlctl device so that only trusted processes or privileged users can invoke the Set Features operation, for example by configuring SELinux, AppArmor, or sysctl limits.
  • If an immediate kernel upgrade is not possible, monitor system stability and consider disabling the CXL feature in the kernel configuration until a patched kernel is available.

Generated by OpenCVE AI on September 19, 2026 at 12:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-476

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: cxl/features: Reject Set Features output buffer smaller than the header cxlctl_set_feature() sizes its output buffer from the user's fwctl_rpc.out_len but never checks it is large enough to hold even the fwctl_rpc_cxl_out header. With out_len == 0 , kvzalloc() returns ZERO_SIZE_PTR, which passes the !rpc_out check, the subsequent rpc_out->size = 0 then writes through the poison pointer. Reject requests whose output buffer can't hold the response header, before allocating. The Set Feature reply carries no payload, so the header is all that is required.
Title cxl/features: Reject Set Features output buffer smaller than the header
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:10:59.686Z

Reserved: 2026-09-17T15:57:05.661Z

Link: CVE-2026-93078

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:01.743

Modified: 2026-09-17T17:18:01.743

Link: CVE-2026-93078

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T14:00:14Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-476

    NULL Pointer Dereference