Description
In the Linux kernel, the following vulnerability has been resolved:

cxl/mbox: Clamp mailbox output allocation to the payload size

CXL_MEM_SEND_COMMAND bounds the user's in.size to the mailbox payload
size but leaves out.size unbounded, then cxl_mbox_cmd_ctor() calls
kvzalloc(out.size). A large out.size drives a huge allocation, above
INT_MAX it WARNs and taints, and with panic_on_warn=1 it panics.

The transport __cxl_pci_mbox_send_cmd() already clamps the response copy
to min(out.size, payload_size, device len), so the output buffer is
never written beyond payload_size. Clamp the allocation to payload_size
too, matching the RAW path.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (Kernel Panic)
Action: Apply Patch
AI Analysis

Impact

The vulnerability arises when the Linux kernel allocates an output buffer for a CXL mailbox command without limiting the size to the payload size. An attacker can request a command that specifies a very large out.size value, causing the kernel to allocate an excessively large buffer. If the allocation exceeds INT_MAX, the kernel issues a warning, taints the system, and if panic_on_warn is enabled, the kernel will panic. This results in a denial of service that brings the entire system offline. The weakness is an uncontrolled memory allocation that is not validated against the maximum payload size.

Affected Systems

Linux kernel releases, with no specific version information provided in the advisory. The issue applies to all builds that include the cxl/mbox mailbox code path.

Risk and Exploitability

The EPSS score is less than one percent, indicating that known exploitation activity is rare. The vulnerability is not listed in CISA's KEV catalog. Exploitation requires the ability to send a CXL command with a crafted large out.size value, which typically implies local privilege or a compromised kernel module. While the risk of successful exploitation is low, the impact is high because a single panic can crash the kernel. The likely attack vector is a local privileged attacker or an attacker who can control a CXL device driver.

Generated by OpenCVE AI on September 19, 2026 at 08:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that contains the patch in the cxl/mbox code path.
  • If an immediate update is not possible, set the kernel parameter panic_on_warn to 0 to prevent kernel crashes, accepting the warning behavior.
  • Limit the privileges of processes that can load or interact with CXL device drivers, and consider using SELinux or AppArmor to enforce strict access controls.

Generated by OpenCVE AI on September 19, 2026 at 08:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-188

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: cxl/mbox: Clamp mailbox output allocation to the payload size CXL_MEM_SEND_COMMAND bounds the user's in.size to the mailbox payload size but leaves out.size unbounded, then cxl_mbox_cmd_ctor() calls kvzalloc(out.size). A large out.size drives a huge allocation, above INT_MAX it WARNs and taints, and with panic_on_warn=1 it panics. The transport __cxl_pci_mbox_send_cmd() already clamps the response copy to min(out.size, payload_size, device len), so the output buffer is never written beyond payload_size. Clamp the allocation to payload_size too, matching the RAW path.
Title cxl/mbox: Clamp mailbox output allocation to the payload size
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:12:12.121Z

Reserved: 2026-09-17T16:02:15.091Z

Link: CVE-2026-93186

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:14.683

Modified: 2026-09-17T17:18:14.683

Link: CVE-2026-93186

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T21:30:16Z

Weaknesses
  • CWE-188

    Reliance on Data/Memory Layout