← All Advisories

CVE-2026-93229

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-93229

Key Details

CVECVE-2026-93229
CVSS Score / Version7.1 (High) / CVSS v3.1
Updated2026-09-25
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is none; availability impact is high.
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

nfsd: add missing read barrier to rpc_status_get dumpit seqcount retry

The hand-rolled seqcount-like protocol in nfsd_nl_rpc_status_get_dumpit()

is missing a read memory barrier (smp_rmb) before its second counter

check. The standard kernel read_seqcount_retry() includes smp_rmb()

to ensure that all data reads complete before the counter is re-checked.

Without this barrier, on weakly-ordered architectures (ARM, POWER),

the CPU may reorder field reads past the second counter check, making

the retry logic ineffective: it could observe a consistent counter pair

while reading fields that have been concurrently modified by the writer.

Add smp_rmb() before the second counter check to order the field reads

ahead of it, matching the barrier semantics of the standard seqcount

read-side. The begin-side smp_load_acquire() already pairs with the

smp_store_release() in nfsd_dispatch(); with the smp_rmb() now ordering

the field reads, the retry check no longer needs acquire semantics and

reads the counter with a plain READ_ONCE(), as read_seqcount_retry()

does.

[ cel: Use READ_ONCE instead of smp_load_acquire() ] (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-93229
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-93229