CVE-2026-93052
In the Linux kernel, the following vulnerability has been resolved: misc: bcm-vk: Use acquire/release for msgq_inited bcm_vk_sync_msgq() fills the message queue information and then sets msgq_inited. Readers call bcm_vk_drv_access_ok() before accessing the message queues and their cached queue information. atomic_set()/atomic_read() do not order those accesses. A reader can see msgq_inited set while still seeing stale queue information. Use release when publishing the initialized queues and acquire when checking the gate. Keep the clear in bcm_vk_blk_drv_access() as atomic_set(). It closes the gate and does not publish queue state to readers.
What this means for your business
What to do
- 1Ask your IT team or provider whether any of your systems use the affected product.
- 2If you do, follow the vendor's guidance. No patch reference has been published yet.
Not sure if your company is exposed?
Fastnexa’s certified penetration testers can check whether attackers could use this flaw, or others like it, against your websites, apps and network. The full test is free for our first 10 founding clients until 31 December 2026.
Scoring
- CVSS
- Not yet scored
- Assigned by
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Dates
- Published
- 2026-09-17
- Last modified
- 2026-09-17
- Sources
- NVD
References
- https://git.kernel.org/stable/c/1df3926ed8771edf286ff753428b243f334e6041
- https://git.kernel.org/stable/c/4984277bc43f84d7506346a09b29af138246d54a
- https://git.kernel.org/stable/c/61b101c6a150057b6d512421ed108aed16e822ea
- https://git.kernel.org/stable/c/679cfada6868723ccf162ec3b78c7402ff2405bf
- https://git.kernel.org/stable/c/a45d6dd3c11e921882a2e74c7c8710b975f2eaa7
- https://git.kernel.org/stable/c/bab66a9e30e39a06f3463b19f8c704386dfd5268
- https://git.kernel.org/stable/c/f7a8f4cbc8cede0be55220367dc52b126e2d39e5