CVE-2026-93073

Source
https://cve.org/CVERecord?id=CVE-2026-93073
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93073.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-93073
Downstream
Published
2026-09-17T16:10:56Z
Modified
2026-09-19T03:47:27Z
Summary
dax: read holder_ops once in dax_holder_notify_failure()
Details

In the Linux kernel, the following vulnerability has been resolved:

dax: read holder_ops once in dax_holder_notify_failure()

dax_holder_notify_failure() reads dax_dev->holder_ops twice without READ_ONCE() -- once for the NULL check and once for the indirect notify_failure() call. A concurrent fs_put_dax() can clear holder_ops between the two reads, so the check can observe a non-NULL pointer while the call dereferences NULL. (kill_dax() also clears holder_ops, but only after synchronize_srcu(), so it cannot race a reader that is inside dax_read_lock(); fs_put_dax() does no such synchronization.)

Fetch holder_ops once into a local with READ_ONCE() so the NULL check and the indirect call observe the same value.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93073.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
8012b866085523758780850087102421dbcce522
Fixed
1661b9bf78def01a8c96409569772d9b2592f4ba
Fixed
0a42180d5410c98829ee72d1d426fb7faf9e6873
Fixed
ee1251621d1c7cf3155c6704542cbb358d799968
Fixed
6a37acecc7c29136235cbc446a1b89e81414344b
Fixed
eb412f80311fc7ab6eb3203091a3fe59a5e9fd30
Fixed
7ae9d15bdcde0f2955ae13b6a95587f9e23b2359

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93073.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.0.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93073.json"