Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-93206— PCI/proc: Use file_ns_capable() when checking config space read access

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,已修复以下漏洞: PCI/proc:在检查配置空间读访问权限时使用 根据 的结果来决定可读取的配置空间范围。该检查验证的是调用 的系统任务(task)的凭据(credentials),而非打开该文件的进程的凭据。 而 sysfs 中的等效函数 自提交 (“pci:从 sysfs 文件打开时检查配置空间的权限,以读取设备相关的配置空间”)起,已开始检查打开文件的进程的凭据。因此,特权进程可以打开配置空间文件,并将文件描述符传递给非特权进程(例如,运行具有分配设备的 KVM 来宾的进程),从而使

AI Predicted 5.5 Difficulty: Moderate EPSS 0.19% · P8

Possible ATT&CK Techniques 1 AI

T1528 · Steal Application Access Token

Affected Version Matrix 18

VendorProduct Version RangeStatus
Linux Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< 8a3a54aa3e65ed76f8560a387243a7738ae0cb1c affected
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< 5c7ab4ca66f0880cffc3735555ea719dd5253726 affected
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< 53407535d49ec034e476121020b5c878f0d92e18 affected
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< e7730acd6a01c5931a3afb83639810ff2fb9cc92 affected
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< 77272b7fd0e472086fd626a1fcd11da625822cc2 affected
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< c2d4174f492458ecdcdef309243624999612d526 affected
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< 6351e94076329dab517ea94c115e15c4d8459381 affected
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< f82f53e75eff382fc8f56b73279b54f7cf5a5c65 affected
… +10 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-93206

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
PCI/proc: Use file_ns_capable() when checking config space read access
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: PCI/proc: Use file_ns_capable() when checking config space read access proc_bus_pci_read() decides how much of the config space is readable based on capable(CAP_SYS_ADMIN), which checks the credentials of the task calling read(), not the credentials of the process that opened the file. The sysfs equivalent, pci_read_config(), has checked the credentials of the opening process since commit de139a339395 ("pci: check caps from sysfs file open to read device dependent config space"), so a privileged process can open the config space file and pass the file descriptor to an unprivileged process (for example, a process running a KVM guest with an assigned device), which can then read the entire config space. The check was subsequently routed through the LSM framework in commit 47970b1b2aa6 ("pci: use security_capable() when checking capablities during config space read") and converted to the dedicated helper in commit ab0fa82b2df9 ("pci-sysfs: use proper file capability helper function"). Thus, the two interfaces check the same capability against different credentials. Checking the credentials of the task calling read() makes the outcome depend on who reads rather than who opened, so the restriction is bypassed whenever a more privileged process reads through the descriptor. Checking the credentials recorded in file->f_cred settles the decision at open() time and ties it to the file, where it cannot change with the caller. Use file_ns_capable() to check CAP_SYS_ADMIN against the credentials in effect when the file was opened, bringing the procfs interface in line with the sysfs behaviour. As a result, a file descriptor opened by a privileged process and passed to an unprivileged one now allows the entire config space to be read through procfs, matching sysfs.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 ~ 8a3a54aa3e65ed76f8560a387243a7738ae0cb1c -
Linux Linux 2.6.12 -

II. Public POCs for CVE-2026-93206

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-93206

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-93206 (7)

Other References for CVE-2026-93206 (1)

Same Patch Batch · Linux · 2026-09-24 · 234 CVEs total

CVE-2026-93207 9.8 CRITICAL SUNRPC: Zero rpc_gss_wire_cred at svcauth_gss_decode_credbody() entry
CVE-2026-97413 9.8 CRITICAL RDMA/rtrs-srv: Fix integer underflow in process_read and process_write
CVE-2026-93228 9.1 CRITICAL svcrdma: Reject Write/Reply chunks with segcount 0
CVE-2026-93793 8.8 HIGH wifi: iwlwifi: mvm: validate TX_CMD response layout
CVE-2026-93799 8.8 HIGH wifi: iwlwifi: mvm: validate sta_id in BA window status notif
CVE-2026-93790 8.8 HIGH wifi: iwlwifi: mvm: fix out-of-bounds tid_data access in BA notif
CVE-2026-93806 8.8 HIGH wifi: cfg80211: validate assoc response length before status and IE access
CVE-2026-97442 8.8 HIGH wifi: ath11k: fix invalid data access in ath11k_dp_rx_h_undecap_nwifi
CVE-2026-97409 8.8 HIGH nvme-fc: Do not cancel requests in io target before it is initialized
CVE-2026-97509 8.8 HIGH thunderbolt: Keep XDomain reference during the lifetime of a service
CVE-2026-93280 8.8 HIGH greybus: audio: bound the topology section sizes against the fetched size
CVE-2026-93284 8.8 HIGH drm/pagemap: dma-unmap pages before handling migration errors
CVE-2026-97451 8.4 HIGH ACPICA: Fix integer overflow in acpi_ex_opcode_3A_1T_1R() (mid_op)
CVE-2026-97452 8.4 HIGH ACPICA: Prevent adding invalid references
CVE-2026-97455 8.4 HIGH ACPICA: Fix use-after-free in acpi_ds_terminate_control_method()
CVE-2026-97450 8.4 HIGH ACPICA: validate handler object type in two places
CVE-2026-93827 8.4 HIGH virtio-fs: avoid double-free on failed queue setup
CVE-2026-97433 8.2 HIGH nvme: validate FDP configuration descriptor sizes
CVE-2026-93787 8.1 HIGH smb: client: bound dirent name against end of SMB response in cifs_filldir
CVE-2026-93224 8.1 HIGH svcrdma: Fix unmatched rn_unregister on failed accept

Showing top 20 of 234 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-93206

No comments yet


Leave a comment