CVE-2026-93074 PUBLISHED

dax/fsdev: use __va(phys) for kaddr in direct_access

Assigner: Linux
Reserved: 17.09.2026 Published: 17.09.2026 Updated: 17.09.2026

In the Linux kernel, the following vulnerability has been resolved:

dax/fsdev: use __va(phys) for kaddr in direct_access

Use __va(phys) instead of virt_addr + linear_offset for the kaddr return in __fsdev_dax_direct_access(). The previous code added a device-linear byte offset to virt_addr (which is __va of ranges[0]), but for multi-range devices with physical gaps between ranges, this linear arithmetic crosses the gap and produces a wrong kernel virtual address. Using __va(phys) where phys comes from dax_pgoff_to_phys() is correct for any range layout because the direct map translates each physical address independently.

This leaves dev_dax->virt_addr write-only, so remove the field (suggested by Dave Jiang).

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 759455848df0b9ac3acabdbedcdc4a55af67935f to 7b642bd3d39105eef4d5908970726c5fda291b53 (excl.)
  • affected from 759455848df0b9ac3acabdbedcdc4a55af67935f to ff7c73fca793bd5c29a15ba735b0886f62f3a840 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 7.1 is affected
  • unaffected from 0 to 7.1 (excl.)
  • unaffected from 7.2.6 to 7.2.* (incl.)
  • unaffected from 7.3-rc1 to * (incl.)

References