CVE-2026-93239

Source
https://cve.org/CVERecord?id=CVE-2026-93239
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93239.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-93239
Downstream
Published
2026-09-24T15:34:27Z
Modified
2026-09-25T03:48:54Z
Summary
arm64: mm: Fix the lockless page-table walk in show_pte()
Details

In the Linux kernel, the following vulnerability has been resolved:

arm64: mm: Fix the lockless page-table walk in show_pte()

show_pte() walks page tables locklessly and can run with interrupts enabled. A concurrent teardown can free a table page while it is being walked. It can also clear a parent entry after show_pte() checked it; the regular pXd_offset() helpers then reread the cleared entry and can derive a bogus lower-level pointer and fault again.

Use the lockless offset helpers with the saved parent entries, as gup_fast() does, and pass the saved PMD to pte_offset_map().

For task page tables, arm64 selects MMU_GATHER_RCU_TABLE_FREE. Disable local interrupts around the walk to hold off RCU-deferred table frees and block the tlb_remove_table_sync_one() IPI until the walk is finished.

Place the IRQ guard after the header print. This does not make the output a consistent snapshot, but prevents the task page-table walk from dereferencing a released table page or deriving a pointer from a different parent value.

Database specific
{
    "cna_assigner":  "Linux",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93239.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
1d18c47c735e8adfe531fc41fae31e98f86b68fe
Fixed
08d931a0a850ad16a64f2cd23a19f40795cdbdf7
Fixed
b28fe65a36b8209b6adcf2722c7ce974cf9ac8d1
Fixed
68cbd70795dd8c06e7ccdc4eb0b74c5b180076c3
Fixed
0f05d95b99164a9ccc4cf4a4920e0ff0228138ad
Fixed
a77644d009dece1104b6fcc6e322b0e4503db0d6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93239.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.7.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.51
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93239.json"