CVE-2026-93097 PUBLISHED

cxl/mbox: Break poison list loop on an empty payload

Assigner: Linux
Reserved: 17.09.2026 Published: 17.09.2026 Updated: 17.09.2026

In the Linux kernel, the following vulnerability has been resolved:

cxl/mbox: Break poison list loop on an empty payload

A device that returns count == 0 with CXL_POISON_FLAG_MORE set on every iteration never advances nr_records, so the max_errors guard never trips and the do/while loops forever while holding poison.mutex. That hangs the sysfs-triggered scan thread and blocks all subsequent poison operations on the device. The existing "Protect against an uncleared _FLAG_MORE" guard was intended to bound a misbehaving device but does not cover the count == 0 case.

Stop the loop on an empty payload so a malfunctioning or malicious device cannot wedge the poison scan.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from ed83f7ca398b3798b82c1d5d1113011c0e5a2198 to 86771c105293ca26bfcc320b4f60d32c137b54aa (excl.)
  • affected from ed83f7ca398b3798b82c1d5d1113011c0e5a2198 to 42eab80981f4d2ac820e253e80ecf92f8cd91f69 (excl.)
  • affected from ed83f7ca398b3798b82c1d5d1113011c0e5a2198 to 6ad491cef1a812cf7b53aa769cd8869516c47362 (excl.)
  • affected from ed83f7ca398b3798b82c1d5d1113011c0e5a2198 to e77594e0cea67ab1c2317a27aa77a744e26ad6a6 (excl.)
  • affected from ed83f7ca398b3798b82c1d5d1113011c0e5a2198 to 8b301c4afbce4bc3f94528441d8d5ce1366504ad (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.4 is affected
  • unaffected from 0 to 6.4 (excl.)
  • unaffected from 6.6.157 to 6.6.* (incl.)
  • unaffected from 6.12.110 to 6.12.* (incl.)
  • unaffected from 6.18.52 to 6.18.* (incl.)
  • unaffected from 7.2.6 to 7.2.* (incl.)
  • unaffected from 7.3-rc1 to * (incl.)

References