← Back to search

CVE-2026-93284

8.8 HIGH

Published 2026-09-24 · Updated 2026-09-25

AI risk analysis

Summary
The flaw lies in the Linux kernel's DRM pagemap handling, where DMA unmapping pages are not properly managed, leading to potential memory corruption or privilege escalation if exploited.
Exploitability
Exploitation requires specific timing and kernel context, making it moderately difficult. The vulnerability arises when the migration cleanup occurs before DMA unmapping.
Blast radius
If exploited, this could lead to severe system instability, data corruption, or privilege escalation, impacting the integrity and security of the system.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to the specific version 5.19.1 or later, as published in the advisory.
kernelmemoryprivilege-escalation

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

In the Linux kernel, the following vulnerability has been resolved: drm/pagemap: dma-unmap pages before handling migration errors drm_pagemap_migrate_unmap_pages() relies on the pages array to determine which pages require DMA unmapping. However, drm_pagemap_migration_unlock_put_pages() clears the array as part of its cleanup, leaving drm_pagemap_migrate_unmap_pages() with no valid page information if it is called afterward. Call drm_pagemap_migrate_unmap_pages() before drm_pagemap_migration_unlock_put_pages() so the pages array remains valid during DMA unmapping.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.