misc: bcm-vk: Use acquire/release for msgq_inited

Summary

CVECVE-2026-93052
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-09-17 17:17:58 UTC
Updated2026-09-17 17:17:58 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: misc: bcm-vk: Use acquire/release for msgq_inited bcm_vk_sync_msgq() fills the message queue information and then sets msgq_inited. Readers call bcm_vk_drv_access_ok() before accessing the message queues and their cached queue information. atomic_set()/atomic_read() do not order those accesses. A reader can see msgq_inited set while still seeing stale queue information. Use release when publishing the initialized queues and acquire when checking the gate. Keep the clear in bcm_vk_blk_drv_access() as atomic_set(). It closes the gate and does not publish queue state to readers.

Risk And Classification

EPSS: 0.002050000 probability, percentile 0.109430000 (date 2026-09-18)

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 111d746bb4767ad476f80fe49067e3df3d9a9375 bab66a9e30e39a06f3463b19f8c704386dfd5268 git Not specified
CNA Linux Linux affected 111d746bb4767ad476f80fe49067e3df3d9a9375 679cfada6868723ccf162ec3b78c7402ff2405bf git Not specified
CNA Linux Linux affected 111d746bb4767ad476f80fe49067e3df3d9a9375 f7a8f4cbc8cede0be55220367dc52b126e2d39e5 git Not specified
CNA Linux Linux affected 111d746bb4767ad476f80fe49067e3df3d9a9375 1df3926ed8771edf286ff753428b243f334e6041 git Not specified
CNA Linux Linux affected 111d746bb4767ad476f80fe49067e3df3d9a9375 a45d6dd3c11e921882a2e74c7c8710b975f2eaa7 git Not specified
CNA Linux Linux affected 111d746bb4767ad476f80fe49067e3df3d9a9375 4984277bc43f84d7506346a09b29af138246d54a git Not specified
CNA Linux Linux affected 111d746bb4767ad476f80fe49067e3df3d9a9375 61b101c6a150057b6d512421ed108aed16e822ea git Not specified
CNA Linux Linux affected 5.12 Not specified
CNA Linux Linux unaffected 5.12 semver Not specified
CNA Linux Linux unaffected 5.15.221 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.188 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.157 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.110 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.52 6.18.* semver Not specified
CNA Linux Linux unaffected 7.2.6 7.2.* semver Not specified
CNA Linux Linux unaffected 7.3-rc1 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/61b101c6a150057b6d512421ed108aed16e822ea 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/4984277bc43f84d7506346a09b29af138246d54a 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/f7a8f4cbc8cede0be55220367dc52b126e2d39e5 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/bab66a9e30e39a06f3463b19f8c704386dfd5268 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/679cfada6868723ccf162ec3b78c7402ff2405bf 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/1df3926ed8771edf286ff753428b243f334e6041 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/a45d6dd3c11e921882a2e74c7c8710b975f2eaa7 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report