Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-93167— csky: Fix a4/a5 restoration in syscall trace path

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,已修复以下漏洞: csky:修复系统调用追踪路径中 a4/a5 寄存器的恢复问题 在系统调用追踪路径中,内核在调用系统调用处理程序前会从 重新加载系统调用参数。在 C-SKY ABIv2 架构下,第 5 个和第 6 个系统调用参数在调用 之前被作为栈参数准备就绪。 当前代码在加载 和 之前调整了 。由于这些偏移量是相对于原始 基址的,因此在修改 之后加载这两个值会导致读取错误的栈槽位。结果是,使用第 5 个或第 6 个参数的被追踪系统调用可能会接收到损坏的参数。 该问题可通过 观察到,它需要

AI Predicted 3.8 Difficulty: Hard EPSS 0.22% · P11

Possible ATT&CK Techniques 1 AI

T1105 · Ingress Tool Transfer

Affected Version Matrix 22

VendorProduct Version RangeStatus
Linux Linux e0bbb53843b5fdfe464b099217e3b9d97e8a75d7< e9ae8e86eed68bea5d2670eadf61938a43bd2263 affected
e0bbb53843b5fdfe464b099217e3b9d97e8a75d7< 64e3ec7a71d3b715e2567f19f64207f04999bb0c affected
e0bbb53843b5fdfe464b099217e3b9d97e8a75d7< 863fa63fd1491f201ac819f805a8db98d2a32c3d affected
e0bbb53843b5fdfe464b099217e3b9d97e8a75d7< e71a3dc5b8d2ea4d9cfbdb135d6b7777de84212e affected
e0bbb53843b5fdfe464b099217e3b9d97e8a75d7< 31c81b376e5f058c7f2c94f69719cf7caec2fc3f affected
e0bbb53843b5fdfe464b099217e3b9d97e8a75d7< a776afa89424570bfa637ebf812ca281a5732904 affected
e0bbb53843b5fdfe464b099217e3b9d97e8a75d7< 343aa5275484d627c921a42e8e115cae366be5de affected
e0bbb53843b5fdfe464b099217e3b9d97e8a75d7< abb81e5ce7d995baa41556b8125fa59e28ba3be8 affected
… +14 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-93167

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
csky: Fix a4/a5 restoration in syscall trace path
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: csky: Fix a4/a5 restoration in syscall trace path The syscall trace path reloads syscall arguments from pt_regs before calling the syscall handler. On C-SKY ABIv2, the 5th and 6th syscall arguments are prepared as stack arguments before invoking syscallid. The current code adjusts sp before loading LSAVE_A4 and LSAVE_A5. Since those offsets are relative to the original pt_regs base, loading them after changing sp fetches the wrong slots. As a result, traced syscalls that use the 5th or 6th argument may receive corrupted arguments. This is visible with mmap2(), which takes six arguments. A small PTRACE_SYSCALL reproducer opens a file and maps one page with: mmap(NULL, 4096, PROT_READ | PROT_EXEC, MAP_PRIVATE, fd, 0) Before the fix, the traced child fails the mmap and exits with 12. After the fix, the mapping succeeds and the child exits with 0. Fix the trace path by loading a4/a5 from pt_regs before changing sp. Tested on: ck860f, linux-4.19.15, C-SKY abiv2
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux e0bbb53843b5fdfe464b099217e3b9d97e8a75d7 ~ e9ae8e86eed68bea5d2670eadf61938a43bd2263 -
Linux Linux 5.7 -

II. Public POCs for CVE-2026-93167

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-93167

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-93167 (8)

Same Patch Batch · Linux · 2026-09-17 · 600 CVEs total

CVE-2026-92489 9.8 CRITICAL xfrm: Fix skb double-free in xfrm_dev_direct_output()
CVE-2026-90151 9.8 CRITICAL NFSv4: remove callback IDR entry on client allocation failure
CVE-2026-90235 9.8 CRITICAL sunrpc: xprtsock: annotate shared socket callbacks with READ_ONCE/WRITE_ONCE
CVE-2026-90104 9.8 CRITICAL NFSv4.1: zero referring call lists before decoding
CVE-2026-90173 9.8 CRITICAL smb: smbdirect: free completion queues with ib_free_cq()
CVE-2026-90110 9.4 CRITICAL inetpeer: randomize RB-tree node comparison using SipHash
CVE-2026-90230 9.1 CRITICAL nvmet: fix heap out-of-bounds read in nvmet_auth_negotiate()
CVE-2026-90413 9.1 CRITICAL IB/isert: reject login PDUs declaring more data than was received
CVE-2026-90414 9.1 CRITICAL IB/isert: reject PDUs declaring more data than was received
CVE-2026-90425 8.8 HIGH iommu/tegra241-cmdqv: Require exactly one Stream ID for a vSID
CVE-2026-93042 8.8 HIGH dmaengine: dw-edma: Terminate all descriptors without callbacks
CVE-2026-93189 8.8 HIGH HID: core: quiesce input in hid_hw_stop() to prevent use-after-free
CVE-2026-90329 8.8 HIGH HID: synchronize input before cleaning up a failed probe
CVE-2026-90357 8.8 HIGH wifi: mt76: mt7915: unlink TWT flow if the MCU rejects the agreement
CVE-2026-90256 8.8 HIGH Bluetooth: L2CAP: use proto_lock for l2cap_data to fix l2cap_disconn_ind
CVE-2026-90367 8.8 HIGH wifi: mt76: mt7996: hold dev->mt76.mutex while disabling tx worker in SER
CVE-2026-90381 8.8 HIGH wifi: mt76: fix handling channel context with different bands in mt76_switch_vif_chanctx()
CVE-2026-90379 8.8 HIGH wifi: mt76: mt7921: Add PCIe AER handler support to prevent system crash
CVE-2026-90380 8.8 HIGH wifi: mt76: mt792x: fix use-after-free in mt76_rx_poll_complete
CVE-2026-90371 8.8 HIGH wifi: mt76: fix RXDMAD_C buffer recycling race

Showing top 20 of 600 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-93167

No comments yet


Leave a comment