{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-93266","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-17T16:02:15.097Z","datePublished":"2026-09-24T15:52:05.559Z","dateUpdated":"2026-09-24T15:52:05.559Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-24T15:52:05.559Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\narm64: RSI: fix field-spanning write warning in attestation token init\n\nThe challenge is passed in registers a1 through a8. However, copying to\n&regs.a1 makes FORTIFY treat the destination as the single a1 field,\nresulting in a field-spanning write warning. [1]\n\nOverlay the SMCCC register structure with an RSI-specific argument\nlayout and copy the challenge into an explicit 64-byte array. This keeps\nthe existing a1-a8 argument encoding while giving the copy a correctly\nsized destination object.\n\n[1]\nmemcpy: detected field-spanning write (size 64) of single field \"&regs.a1\" at ./arch/arm64/include/asm/rsi_cmds.h:119 (size 8)\nWARNING: ./arch/arm64/include/asm/rsi_cmds.h:119 at rsi_attestation_token_init+0xdc/0xf8 [arm_cca_guest], CPU#0: cat/3314"}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["arch/arm64/include/asm/rsi_cmds.h"],"versions":[{"version":"b880a80011f56880f32bde47fc6af313359f926b","lessThan":"e505092cb200d430d5b8d8d3e926d45f29474ba3","status":"affected","versionType":"git"},{"version":"b880a80011f56880f32bde47fc6af313359f926b","lessThan":"d29a8ee271da17b5e32d7a76a9c78d43f66447ca","status":"affected","versionType":"git"},{"version":"b880a80011f56880f32bde47fc6af313359f926b","lessThan":"221049874b6a78c7d87bc826581b0695cd338e2b","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["arch/arm64/include/asm/rsi_cmds.h"],"versions":[{"version":"6.13","status":"affected"},{"version":"0","lessThan":"6.13","status":"unaffected","versionType":"semver"},{"version":"6.18.52","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.13","versionEndExcluding":"6.18.52"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.13","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.13","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/e505092cb200d430d5b8d8d3e926d45f29474ba3"},{"url":"https://git.kernel.org/stable/c/d29a8ee271da17b5e32d7a76a9c78d43f66447ca"},{"url":"https://git.kernel.org/stable/c/221049874b6a78c7d87bc826581b0695cd338e2b"}],"title":"arm64: RSI: fix field-spanning write warning in attestation token init","x_generator":{"engine":"bippy-1.2.0"}}}}