CVE-2026-92495

Source
https://cve.org/CVERecord?id=CVE-2026-92495
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92495.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-92495
Downstream
Published
2026-09-17T16:10:10Z
Modified
2026-09-18T03:48:40Z
Summary
RDMA/bnxt_re: Clear VM_MAYWRITE on DBR/toggle page mmap
Details

In the Linux kernel, the following vulnerability has been resolved:

RDMA/bnxt_re: Clear VM_MAYWRITE on DBR/toggle page mmap

bnxt_re_mmap() rejects VM_WRITE for the DBR_PAGE and TOGGLE_PAGE mmap flags, but a read-only mapping can still retain VM_MAYWRITE. nd later be upgraded with mprotect(PROT_WRITE). This can bypass the write check that only runs at mmap time.

Clear VM_MAYWRITE before vm_insert_page() in the shared DBR/toggle-page branch, matching the existing policy that userspace writes are not expected for these pages.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92495.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
ea222485788208cd79bad42d25aae9232b33a934
Fixed
5361fb1e5bc246f9a2c0721543f72c8dac200769
Fixed
13e7861809ef9e7e720ff5f0af1d4293a6d0a9b4
Fixed
0afbfe019c881483337d9f8304e678af05ebe7cc
Fixed
518df61b9b0a5b288dfa72c87246045329c18b8c
Fixed
9b66c9af7172ffcf727214fa0ebe9a5e1ed6eb16

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92495.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.6.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92495.json"