OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-93260

HIGH · CVSS 7.4 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-09-24 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's handling of inter-processor interrupts (IPIs) in the PowerPC architecture, specifically during the initialization process where it can lead to a use-after-free condition. If the initialization of IPIs fails, the system may still attempt to use a pointer to a freed memory area, potentially resulting in system instability or exploitation. Organizations utilizing Linux on PowerPC systems should prioritize this issue to ensure their kernel is updated and protected against potential exploitation scenarios.

CVE
CVE-2026-93260
Severity
HIGH
CVSS
7.4
EPSS
0.13%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: powerpc/xive: propagate IPI init errors to prevent use-after-free When xive_init_ipis() fails (e.g. irq_domain_alloc_irqs() fails), the error path frees the global xive_ipis array. However, xive_smp_probe() previously ignored this failure and proceeded to call xive_setup_cpu_ipi(), which dereferences the already-freed xive_ipis pointer -- a use-after-free. Now that xive_smp_probe() returns int (previous patch), propagate the error from xive_init_ipis() and xive_setup_cpu_ipi() through xive_smp_probe(). Check the return value in both pnv_smp_probe() and pSeries_smp_probe() so that IPI setup is aborted cleanly on failure, avoiding the use-after-free.