CVE-2026-93074

Summary

In the Linux kernel, the following vulnerability has been resolved:

dax/fsdev: use __va(phys) for kaddr in direct_access

Use __va(phys) instead of virt_addr + linear_offset for the kaddr return in __fsdev_dax_direct_access(). The previous code added a device-linear byte offset to virt_addr (which is __va of ranges[0]), but for multi-range devices with physical gaps between ranges, this linear arithmetic crosses the gap and produces a wrong kernel virtual address. Using __va(phys) where phys comes from dax_pgoff_to_phys() is correct for any range layout because the direct map translates each physical address independently.

This leaves dev_dax->virt_addr write-only, so remove the field (suggested by Dave Jiang).

Affected Software

VendorProductVersion RangeStatus
LinuxLinux759455848df0b9ac3acabdbedcdc4a55af67935f < 7b642bd3d39105eef4d5908970726c5fda291b53affected
LinuxLinux759455848df0b9ac3acabdbedcdc4a55af67935f < ff7c73fca793bd5c29a15ba735b0886f62f3a840affected
LinuxLinux7.1affected
LinuxLinux0 < 7.1unaffected
LinuxLinux7.2.6 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References