{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-93096","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-17T16:02:15.084Z","datePublished":"2026-09-17T16:11:10.359Z","dateUpdated":"2026-09-17T16:11:10.359Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-17T16:11:10.359Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncxl/features: Serialize multi-part Get/Set Feature transfers\n\nA Get or Set Feature payload larger than the mailbox payload size is\nsplit into several mailbox commands. mbox_mutex only serializes\nindividual mailbox commands and is dropped between iterations of these\nloops. Nothing serializes the multi-part transfer as a whole.\ncxl_get_feature() and cxl_set_feature() are reachable concurrently\nfrom fwctl (per-fd RPCs run under a read-held registration lock) and\nfrom the EDAC scrub/ECS/repair paths, so two transfers to the same\nmailbox can interleave their parts and corrupt the device's transfer\ncontext.\n\nAdd a per-mailbox feat_mutex and hold it across the whole transfer in\nboth functions. It nests outside mbox_mutex (which is taken inside\ncxl_internal_send_cmd()), and is taken nowhere else, so no lock-ordering\ninversion is introduced."}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/cxl/core/features.c","drivers/cxl/core/mbox.c","include/cxl/mailbox.h"],"versions":[{"version":"5e5ac21f629de796ab5d598b59c5e468c6fe4f95","lessThan":"7682b617db1f19bc606b5f1badadcf1e63a87b14","status":"affected","versionType":"git"},{"version":"5e5ac21f629de796ab5d598b59c5e468c6fe4f95","lessThan":"77b814c1832fde018c30357b4ec3fcdaa91a1c10","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/cxl/core/features.c","drivers/cxl/core/mbox.c","include/cxl/mailbox.h"],"versions":[{"version":"6.15","status":"affected"},{"version":"0","lessThan":"6.15","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.15","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.15","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/7682b617db1f19bc606b5f1badadcf1e63a87b14"},{"url":"https://git.kernel.org/stable/c/77b814c1832fde018c30357b4ec3fcdaa91a1c10"}],"title":"cxl/features: Serialize multi-part Get/Set Feature transfers","x_generator":{"engine":"bippy-1.2.0"}}}}