{"id":"CVE-2026-93266","published":"2026-09-24T16:17:23.453","lastModified":"2026-09-24T16:17:23.453","description":"In the Linux kernel, the following vulnerability has been resolved:\n\narm64: RSI: fix field-spanning write warning in attestation token init\n\nThe challenge is passed in registers a1 through a8. However, copying to\n&regs.a1 makes FORTIFY treat the destination as the single a1 field,\nresulting in a field-spanning write warning. [1]\n\nOverlay the SMCCC register structure with an RSI-specific argument\nlayout and copy the challenge into an explicit 64-byte array. This keeps\nthe existing a1-a8 argument encoding while giving the copy a correctly\nsized destination object.\n\n[1]\nmemcpy: detected field-spanning write (size 64) of single field \"&regs.a1\" at ./arch/arm64/include/asm/rsi_cmds.h:119 (size 8)\nWARNING: ./arch/arm64/include/asm/rsi_cmds.h:119 at rsi_attestation_token_init+0xdc/0xf8 [arm_cca_guest], CPU#0: cat/3314","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/221049874b6a78c7d87bc826581b0695cd338e2b","tags":[]},{"url":"https://git.kernel.org/stable/c/d29a8ee271da17b5e32d7a76a9c78d43f66447ca","tags":[]},{"url":"https://git.kernel.org/stable/c/e505092cb200d430d5b8d8d3e926d45f29474ba3","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}