Description
In the Linux kernel, the following vulnerability has been resolved:

cxl/features: Serialize multi-part Get/Set Feature transfers

A Get or Set Feature payload larger than the mailbox payload size is
split into several mailbox commands. mbox_mutex only serializes
individual mailbox commands and is dropped between iterations of these
loops. Nothing serializes the multi-part transfer as a whole.
cxl_get_feature() and cxl_set_feature() are reachable concurrently
from fwctl (per-fd RPCs run under a read-held registration lock) and
from the EDAC scrub/ECS/repair paths, so two transfers to the same
mailbox can interleave their parts and corrupt the device's transfer
context.

Add a per-mailbox feat_mutex and hold it across the whole transfer in
both functions. It nests outside mbox_mutex (which is taken inside
cxl_internal_send_cmd()), and is taken nowhere else, so no lock-ordering
inversion is introduced.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Device Integrity Compromise
Action: Immediate Patch
AI Analysis

Impact

This kernel flaw allows concurrent Get/Set Feature operations on the same CXL mailbox to interleave, bypassing the mailbox mutex protection and converting a single mailbox command into several split commands. The resulting race condition corrupts the device's transfer context, which can lead to incorrect device state or failure of subsequent operations. An attacker who can trigger overlapping transfers—such as a privileged local user or a compromised driver—could exploit this issue to cause device misbehavior or a denial‑of‑service condition.

Affected Systems

All Linux kernels that include the cxl/features subsystem, including the mainstream distributions, are affected until the per‑mailbox feat_mutex patch is applied. The vulnerability is intentionally present in any kernel that contains the cxl driver, as the CPE identifies all Linux kernel releases.

Risk and Exploitability

The EPSS score of less than 1% suggests a very low overall probability of exploitation in the general population. The vulnerability is not listed in the CISA KEV catalog, but its impact on device integrity makes it a serious risk if an attacker has sufficient local privileges or can run code with kernel or driver‑level access. Exploitation requires concurrent CXL operations on the same mailbox, which is feasible only when the kernel is running normally and the driver is active.

Generated by OpenCVE AI on September 19, 2026 at 09:05 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Linux kernel update that contains the feat_mutex fix adding per‑mailbox serialization to all Get/Set Feature operations.
  • If a kernel upgrade is not immediately possible, temporarily disable EDAC scrub/ECS/repair paths that may invoke concurrent CXL feature operations until the patch is applied.
  • Configure CXL feature requests to stay within the maximum mailbox payload size so that payloads are not split into multiple commands, avoiding the race condition.

Generated by OpenCVE AI on September 19, 2026 at 09:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: cxl/features: Serialize multi-part Get/Set Feature transfers A Get or Set Feature payload larger than the mailbox payload size is split into several mailbox commands. mbox_mutex only serializes individual mailbox commands and is dropped between iterations of these loops. Nothing serializes the multi-part transfer as a whole. cxl_get_feature() and cxl_set_feature() are reachable concurrently from fwctl (per-fd RPCs run under a read-held registration lock) and from the EDAC scrub/ECS/repair paths, so two transfers to the same mailbox can interleave their parts and corrupt the device's transfer context. Add a per-mailbox feat_mutex and hold it across the whole transfer in both functions. It nests outside mbox_mutex (which is taken inside cxl_internal_send_cmd()), and is taken nowhere else, so no lock-ordering inversion is introduced.
Title cxl/features: Serialize multi-part Get/Set Feature transfers
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:11:10.359Z

Reserved: 2026-09-17T16:02:15.084Z

Link: CVE-2026-93096

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:03.713

Modified: 2026-09-17T17:18:03.713

Link: CVE-2026-93096

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T14:30:07Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')