CVE-2026-92484 PUBLISHED

cxl/region: Fix use-after-free in find_pos_and_ways() error path

Assigner: Linux
Reserved: 16.09.2026 Published: 17.09.2026 Updated: 17.09.2026

In the Linux kernel, the following vulnerability has been resolved:

cxl/region: Fix use-after-free in find_pos_and_ways() error path

The error path releases its reference to a switch decoder before logging an error that includes the decoder name. If the released reference is the last one, the decoder can be freed before the error message accesses its name.

Drop the reference after the error is reported.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 9d90ab45d3d393532b7fa62d6a6b7ebbde9cf5fc to 68edf359b0b45cad2654510c1ca257079b241aa5 (excl.)
  • affected from b3dc5c735a754142831f705068fcfa77551724ff to b38ca9ce8c7d9b8151bb9e4770404c5e39600a48 (excl.)
  • affected from d90acdf49e18029cfe4194475c45ef143657737a to f54b96e8aadbfc7f2a1b26df349ef9b062c47d2e (excl.)
  • affected from d90acdf49e18029cfe4194475c45ef143657737a to 8f7683ce37a53eeabd721941517341d2eef2cf3c (excl.)
  • affected from d90acdf49e18029cfe4194475c45ef143657737a to 15da704b732332cc1e8f121f624e5e6c05124c5d (excl.)
  • Version 8ad454d3050a40fd616d481e48d1aebb27d9951e is affected
  • affected from 6.6.96 to 6.6.157 (excl.)
  • affected from 6.12.36 to 6.12.110 (excl.)
  • affected from 6.15.5 to 6.16 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.16 is affected
  • unaffected from 0 to 6.16 (excl.)
  • unaffected from 6.6.157 to 6.6.* (incl.)
  • unaffected from 6.12.110 to 6.12.* (incl.)
  • unaffected from 6.18.52 to 6.18.* (incl.)
  • unaffected from 7.2.6 to 7.2.* (incl.)
  • unaffected from 7.3-rc1 to * (incl.)

References