---
id: CVE-2026-93097
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  cxl/mbox: Break poison list loop on an empty payload

  A device that returns count == 0 with CXL_POISON_FLAG_MORE set on every
  iteration never advances nr_records, so th…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  cxl/mbox: Break poison list loop on an empty payload

  A device that returns count == 0 with CXL_POISON_FLAG_MORE set on every
  iteration never advances nr_records, so th…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= ed83f7ca398b3798b82c1d5d1113011c0e5a2198 <
    86771c105293ca26bfcc320b4f60d32c137b54aa
  - >-
    Linux >= ed83f7ca398b3798b82c1d5d1113011c0e5a2198 <
    42eab80981f4d2ac820e253e80ecf92f8cd91f69
  - >-
    Linux >= ed83f7ca398b3798b82c1d5d1113011c0e5a2198 <
    6ad491cef1a812cf7b53aa769cd8869516c47362
  - >-
    Linux >= ed83f7ca398b3798b82c1d5d1113011c0e5a2198 <
    e77594e0cea67ab1c2317a27aa77a744e26ad6a6
  - >-
    Linux >= ed83f7ca398b3798b82c1d5d1113011c0e5a2198 <
    8b301c4afbce4bc3f94528441d8d5ce1366504ad
  - Linux 6.4
published: '2026-09-17'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T17:18:03.843'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-93097'
references:
  - url: 'https://git.kernel.org/stable/c/42eab80981f4d2ac820e253e80ecf92f8cd91f69'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/6ad491cef1a812cf7b53aa769cd8869516c47362'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/86771c105293ca26bfcc320b4f60d32c137b54aa'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/8b301c4afbce4bc3f94528441d8d5ce1366504ad'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/e77594e0cea67ab1c2317a27aa77a744e26ad6a6'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-17T16:21:47.758Z'
epss: 0.002
epssPercentile: 0.10108
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

cxl/mbox: Break poison list loop on an empty payload

A device that returns count == 0 with CXL_POISON_FLAG_MORE set on every
iteration never advances nr_records, so the max_errors guard never
trips and the do/while loops forever while holding poison.mutex. That
hangs the sysfs-triggered scan thread and blocks all subsequent poison
operations on the device. The existing "Protect against an uncleared
_FLAG_MORE" guard was intended to bound a misbehaving device but does
not cover the count == 0 case.

Stop the loop on an empty payload so a malfunctioning or malicious
device cannot wedge the poison scan.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
