CVE-2026-74273
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
cxl/region: Block region delete during region creation
Expand the range lock, rename it "regions_lock", to disable region deletion in the critical period between construct_region() and attach_target(), as well as the period between device_add() and registering the remove actions.
Otherwise, userspace can confuse the kernel. It can violate the assumption the region stays registered through the completion of cxl_add_to_region(). It can violate the assumption that devm_add_action_or_reset() is working with a live 'struct cxl_region'.
It is ok for the region to disappear outside of those windows as that mirrors device hotplug flows where the proper locks are held.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | a32320b71f085f8d82afedcf285f1682c8c00aed < b0b6a9c65cb72c901fdcc6ae83d7afd70cdca1b8 | affected |
| Linux | Linux | a32320b71f085f8d82afedcf285f1682c8c00aed < d91feb88692e81b00cd22f0125cfcd04970b4a0b | affected |
| Linux | Linux | 6.3 | affected |
| Linux | Linux | 0 < 6.3 | unaffected |
| Linux | Linux | 7.1.5 <= 7.1.* | unaffected |
| Linux | Linux | 7.2 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/b0b6a9c65cb72c901fdcc6ae83d7afd70cdca1b8
- https://git.kernel.org/stable/c/d91feb88692e81b00cd22f0125cfcd04970b4a0b
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.