Description
In the Linux kernel, the following vulnerability has been resolved:

cxl/features: Reject Get Feature count larger than the output buffer

cxlctl_get_feature() sizes its output buffer from the user's
fwctl_rpc.out_len, but the device is told to write
cxl_mbox_get_feat_in.count bytes into rpc_out->payload, which is a
separate user-controlled value. Nothing bounds count against out_len, so
a small out_len with a large count overflows the kvzalloc()'d buffer.
A heap OOB write reachable from FWCTL_RPC.

Reject requests where count exceeds the available payload room, before
allocating.
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption
Action: Apply Patch
AI Analysis

Impact

The kernel function cxlctl_get_feature creates a buffer whose size is based on a user‑supplied out_len value and then writes a separate user‑controlled count of bytes into that buffer. Because count is not limited by an overrun of the allocated heap buffer, resulting in an out‑of‑bounds write that corrupts kernel memory. This could potentially allow a local attacker with access to the CXL device to gain higher privileges or execute arbitrary code at the kernel level.

Affected Systems

The defect is present in the Linux kernel as supplied by the vendor Linux:Linux. No specific kernel version range is cited by the CNA, so the vulnerability may exist in any kernel that includes the unguarded cxlctl_get_feature path before the commit that introduces the guard against the overflow.

Risk and Exploitability

The CVSS score of 7.8 indicates a moderate‑to‑high severity. The EPSS score of less than 1% suggests a very low likelihood of exploitation at present, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires a local user who can invoke cxlctl on a CXL device and supply both out_len and count values. Given the local‑only prerequisite and the specific conditions needed to overflow the buffer, the risk is mainly of local privilege escalation or kernel data corruption, with a low probability of widespread impact under current conditions.

Generated by OpenCVE AI on September 19, 2026 at 22:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the patch that bounds the count against the output length—see the referenced git commits for the exact changes.
  • Upgrade to a kernel release that incorporates this fix.
  • Restrict access to the CXL device, for example by adjusting device permissions so that only privileged users can use cxlctl, or by disabling the CXL feature in the kernel configuration until a patched kernel is available.

Generated by OpenCVE AI on September 19, 2026 at 22:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-122

Sat, 19 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-122

Sat, 19 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-122

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: cxl/features: Reject Get Feature count larger than the output buffer cxlctl_get_feature() sizes its output buffer from the user's fwctl_rpc.out_len, but the device is told to write cxl_mbox_get_feat_in.count bytes into rpc_out->payload, which is a separate user-controlled value. Nothing bounds count against out_len, so a small out_len with a large count overflows the kvzalloc()'d buffer. A heap OOB write reachable from FWCTL_RPC. Reject requests where count exceeds the available payload room, before allocating.
Title cxl/features: Reject Get Feature count larger than the output buffer
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:55:53.599Z

Reserved: 2026-09-17T15:57:05.661Z

Link: CVE-2026-93079

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:01.850

Modified: 2026-09-18T18:18:20.330

Link: CVE-2026-93079

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:45:06Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow