{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-93074","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-17T15:57:05.661Z","datePublished":"2026-09-17T16:10:57.051Z","dateUpdated":"2026-09-18T17:55:52.238Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-18T17:55:52.238Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndax/fsdev: use __va(phys) for kaddr in direct_access\n\nUse __va(phys) instead of virt_addr + linear_offset for the kaddr\nreturn in __fsdev_dax_direct_access(). The previous code added a\ndevice-linear byte offset to virt_addr (which is __va of ranges[0]),\nbut for multi-range devices with physical gaps between ranges, this\nlinear arithmetic crosses the gap and produces a wrong kernel virtual\naddress. Using __va(phys) where phys comes from dax_pgoff_to_phys()\nis correct for any range layout because the direct map translates\neach physical address independently.\n\nThis leaves dev_dax->virt_addr write-only, so remove the field\n(suggested by Dave Jiang)."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The wrong kaddr is computed in __fsdev_dax_direct_access() from a device pgoff supplied by dax_iomap_pgoff() during local VFS DAX I/O (dax_iomap_rw, dax_zero_iter, dax_fault_iter). No network protocol carries that pgoff.\nAC:L - Once a gapped multi-range fsdev_dax device is bound, any I/O whose pgoff dax_pgoff_to_phys() places in a later range makes virt_addr+offset a deterministic wrong linear-map address; the attacker chooses the file offset that yields that pgoff, with no race.\nPR:L - dax_match_type() never auto-binds DAXDRV_FSDEV_TYPE (admin new_id) and fs_dax_get() is the mount-time holder, but dax_direct_access() then has no capability check, so an unprivileged user with file access on the mounted FS-DAX tree reaches the bad kaddr via read/write/fallocate.\nUI:N - The attacker triggers the bad kaddr solely by their own read, write, fallocate, or page-fault on files they can already open; this is not attacker-supplied media that a victim must mount.\nS:U - dax_copy_from_iter(), dax_copy_to_iter(), and fsdev_write_dax() use the wrong host-kernel __va() pointer; impact stays in the host kernel and does not cross a KVM, IOMMU, or other VM-escape boundary.\nC:H - dax_iomap_iter() calls dax_copy_to_iter() from virt_addr+offset, which for a later range is __va of the physical gap (another dax mapping in the same region, or System RAM), so a file read discloses that memory.\nI:H - dax_copy_from_iter() and fsdev_dax_zero_page_range()'s fsdev_write_dax() write attacker bytes or PAGE_SIZE zeros through the same wrong kaddr into the gap, giving a kernel write into adjacent DAX or RAM.\nA:H - memcpy_flushcache() or copy through a kaddr that lands in an unmapped gap oopses the kernel; even a successful wrong-address write can panic by corrupting adjacent structures."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/dax/dax-private.h","drivers/dax/fsdev.c"],"versions":[{"version":"759455848df0b9ac3acabdbedcdc4a55af67935f","lessThan":"7b642bd3d39105eef4d5908970726c5fda291b53","status":"affected","versionType":"git"},{"version":"759455848df0b9ac3acabdbedcdc4a55af67935f","lessThan":"ff7c73fca793bd5c29a15ba735b0886f62f3a840","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/dax/dax-private.h","drivers/dax/fsdev.c"],"versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.1","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.1","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/7b642bd3d39105eef4d5908970726c5fda291b53"},{"url":"https://git.kernel.org/stable/c/ff7c73fca793bd5c29a15ba735b0886f62f3a840"}],"title":"dax/fsdev: use __va(phys) for kaddr in direct_access","x_generator":{"engine":"bippy-1.2.0"}}}}