{"id":"CVE-2026-93167","title":"In the Linux kernel, the following vulnerability has been resolved:\n\ncsky: Fix a4/a5 restoration in syscall trace path\n\nThe syscall trace path reloads syscall arguments from pt_regs before\ncalling the syscall handler","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\ncsky: Fix a4/a5 restoration in syscall trace path\n\nThe syscall trace path reloads syscall arguments from pt_regs before\ncalling the syscall handler. On C-SKY ABIv2, the…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= e0bbb53843b5fdfe464b099217e3b9d97e8a75d7 < e9ae8e86eed68bea5d2670eadf61938a43bd2263","Linux >= e0bbb53843b5fdfe464b099217e3b9d97e8a75d7 < 64e3ec7a71d3b715e2567f19f64207f04999bb0c","Linux >= e0bbb53843b5fdfe464b099217e3b9d97e8a75d7 < 863fa63fd1491f201ac819f805a8db98d2a32c3d","Linux >= e0bbb53843b5fdfe464b099217e3b9d97e8a75d7 < e71a3dc5b8d2ea4d9cfbdb135d6b7777de84212e","Linux >= e0bbb53843b5fdfe464b099217e3b9d97e8a75d7 < 31c81b376e5f058c7f2c94f69719cf7caec2fc3f","Linux >= e0bbb53843b5fdfe464b099217e3b9d97e8a75d7 < a776afa89424570bfa637ebf812ca281a5732904","Linux >= e0bbb53843b5fdfe464b099217e3b9d97e8a75d7 < 343aa5275484d627c921a42e8e115cae366be5de","Linux >= e0bbb53843b5fdfe464b099217e3b9d97e8a75d7 < abb81e5ce7d995baa41556b8125fa59e28ba3be8","Linux 108681048cf728a8570e036c34ebd7daa43133b4","Linux 3a5837c692918c229baf63fe7950965d27c48ac2","Linux >= 5.4.47 < 5.5","Linux >= 5.6.19 < 5.7","Linux 5.7"],"published":"2026-09-17","updated":"2026-09-17","sourceUpdated":"2026-09-17T17:18:12.243","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-93167","references":[{"url":"https://git.kernel.org/stable/c/31c81b376e5f058c7f2c94f69719cf7caec2fc3f","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/343aa5275484d627c921a42e8e115cae366be5de","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/64e3ec7a71d3b715e2567f19f64207f04999bb0c","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/863fa63fd1491f201ac819f805a8db98d2a32c3d","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a776afa89424570bfa637ebf812ca281a5732904","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/abb81e5ce7d995baa41556b8125fa59e28ba3be8","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e71a3dc5b8d2ea4d9cfbdb135d6b7777de84212e","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e9ae8e86eed68bea5d2670eadf61938a43bd2263","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-17T16:21:47.732Z","epss":0.00211,"epssPercentile":0.1159,"slug":"CVE-2026-93167","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\ncsky: Fix a4/a5 restoration in syscall trace path\n\nThe syscall trace path reloads syscall arguments from pt_regs before\ncalling the syscall handler. On C-SKY ABIv2, the 5th and 6th syscall\narguments are prepared as stack arguments before invoking syscallid.\n\nThe current code adjusts sp before loading LSAVE_A4 and LSAVE_A5. Since\nthose offsets are relative to the original pt_regs base, loading them\nafter changing sp fetches the wrong slots. As a result, traced syscalls\nthat use the 5th or 6th argument may receive corrupted arguments.\n\nThis is visible with mmap2(), which takes six arguments. A small\nPTRACE_SYSCALL reproducer opens a file and maps one page with:\n\n  mmap(NULL, 4096, PROT_READ | PROT_EXEC, MAP_PRIVATE, fd, 0)\n\nBefore the fix, the traced child fails the mmap and exits with 12.\nAfter the fix, the mapping succeeds and the child exits with 0.\n\nFix the trace path by loading a4/a5 from pt_regs before changing sp.\n\nTested on: ck860f, linux-4.19.15, C-SKY abiv2\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}