---
id: CVE-2026-93073
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  dax: read holder_ops once in dax_holder_notify_failure()

  dax_holder_notify_failure() reads dax_dev->holder_ops twice without
  READ_ONCE() -- once for the NULL check and…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  dax: read holder_ops once in dax_holder_notify_failure()

  dax_holder_notify_failure() reads dax_dev->holder_ops twice without
  READ_ONCE() -- once for the NULL check and…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 8012b866085523758780850087102421dbcce522 <
    1661b9bf78def01a8c96409569772d9b2592f4ba
  - >-
    Linux >= 8012b866085523758780850087102421dbcce522 <
    0a42180d5410c98829ee72d1d426fb7faf9e6873
  - >-
    Linux >= 8012b866085523758780850087102421dbcce522 <
    ee1251621d1c7cf3155c6704542cbb358d799968
  - >-
    Linux >= 8012b866085523758780850087102421dbcce522 <
    6a37acecc7c29136235cbc446a1b89e81414344b
  - >-
    Linux >= 8012b866085523758780850087102421dbcce522 <
    eb412f80311fc7ab6eb3203091a3fe59a5e9fd30
  - >-
    Linux >= 8012b866085523758780850087102421dbcce522 <
    7ae9d15bdcde0f2955ae13b6a95587f9e23b2359
  - Linux 6.0
published: '2026-09-17'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T17:18:01.207'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-93073'
references:
  - url: 'https://git.kernel.org/stable/c/0a42180d5410c98829ee72d1d426fb7faf9e6873'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/1661b9bf78def01a8c96409569772d9b2592f4ba'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/6a37acecc7c29136235cbc446a1b89e81414344b'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/7ae9d15bdcde0f2955ae13b6a95587f9e23b2359'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/eb412f80311fc7ab6eb3203091a3fe59a5e9fd30'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/ee1251621d1c7cf3155c6704542cbb358d799968'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-17T16:21:47.764Z'
epss: 0.0018
epssPercentile: 0.06705
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

dax: read holder_ops once in dax_holder_notify_failure()

dax_holder_notify_failure() reads dax_dev->holder_ops twice without
READ_ONCE() -- once for the NULL check and once for the indirect
notify_failure() call. A concurrent fs_put_dax() can clear holder_ops
between the two reads, so the check can observe a non-NULL pointer while
the call dereferences NULL. (kill_dax() also clears holder_ops, but only
after synchronize_srcu(), so it cannot race a reader that is inside
dax_read_lock(); fs_put_dax() does no such synchronization.)

Fetch holder_ops once into a local with READ_ONCE() so the NULL check and
the indirect call observe the same value.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
