cxl/features: Clamp Get Feature output size to the remaining buffer
Published Sep 17, 2026
No CVSS score
EPSS 0.21%
Description
cxl_get_feature() reads a feature in a loop but passes a fixed size_out as the output capacity every iteration. On the last partial iteration the buffer has less room left, so a device that returns more than asked can overflow feat_out.
Use the per-iter size data_to_rd_size, which already tracks the remaining room, as the output capacity.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 6.15StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<6.15
- Version 6.18.52StatusunaffectedConstraints<=6.18.*
- Version 7.2.6StatusunaffectedConstraints<=7.2.*
- Version 7.3-rc1StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-82187 Advisory
- https://git.kernel.org/stable/c/2aeb21fe557ef154f0cdf4f9745ebd8d5b31ca83
- https://git.kernel.org/stable/c/b8abbd5c2928fd839dab702244cc57b228ab43aa
- https://git.kernel.org/stable/c/ca95b15a0760e7724e61addbdd61050be13b6406
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Sep 17, 2026
Updated Sep 17, 2026
Reserved Sep 17, 2026
Link CVE-2026-93077
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2026-82187 Assigner Linux
Published Sep 17, 2026
Updated Sep 17, 2026
Exploited since n/a
Link EUVD-2026-82187