Description
In the Linux kernel, the following vulnerability has been resolved:

platform/x86: dell-privacy: Fix race condition

Accessing priv->features_present needs to happen with the list mutex
being held, otherwise priv can be freed at any moment.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Use‑After‑Free via race condition
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a race condition in the Linux kernel Dell privacy module on x86, where the structure priv->features_present is accessed without holding the list mutex. This allows a privileged user to free the priv object while it is still being accessed, leading to a use‑after‑free that can crash the kernel or enable execution of arbitrary code in kernel mode. The weakness is identified as a race condition (CWE-362) and a use‑after‑free (CWE-416).

Affected Systems

All Linux kernel releases that contain the vulnerable code and have not yet incorporated the fix commit (239ae86b7c97341f49d2ba32037ee3ddbaf0f1ab or later). The exact affected kernel versions are not enumerated in the data, but any distribution shipping a kernel prior to the patch should be considered vulnerable.

Risk and Exploitability

The EPSS score is below 1 %, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. No public exploit has been documented. However, because the flaw can lead to kernel privilege escalation or denial of service, the risk remains high if an attacker obtains local or root access. Based on the description, it is inferred that the exploit requires local or root access. The CVSS score is not defined in the provided data, but the nature of the bug suggests a high impact should it be exploited locally.

Generated by OpenCVE AI on September 19, 2026 at 07:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that incorporates the race‑condition patch referenced in commit 239ae86b7c97341f49d2ba32037ee3ddbaf0f1ab or later.
  • Rebuild any custom kernels with the updated source, ensuring that the list mutex is held before accessing priv->features_present.
  • Restart the system to load the patched kernel and monitor system logs for kernel panics or anomalies that may indicate residual race conditions.

Generated by OpenCVE AI on September 19, 2026 at 07:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362
CWE-416

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: platform/x86: dell-privacy: Fix race condition Accessing priv->features_present needs to happen with the list mutex being held, otherwise priv can be freed at any moment.
Title platform/x86: dell-privacy: Fix race condition
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:11:34.019Z

Reserved: 2026-09-17T16:02:15.087Z

Link: CVE-2026-93131

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:07.923

Modified: 2026-09-17T17:18:07.923

Link: CVE-2026-93131

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T16:15:13Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

  • CWE-416

    Use After Free