CVE-2026-92495
Published Sep 17, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Clear VM_MAYWRITE on DBR/toggle page mmap bnxt_re_mmap() rejects VM_WRITE for the DBR_PAGE and TOGGLE_PAGE mmap flags, but a read-only mapping can still retain VM_MAYWRITE. nd later be upgraded with mprotect(PROT_WRITE). This can bypass the write check that only runs at mmap time. Clear VM_MAYWRITE before vm_insert_page() in the shared DBR/toggle-page branch, matching the existing policy that userspace writes are not expected for these pages.
Is your site exposed to CVE-2026-92495?
Run a free security scan — no signup, results in seconds.
References
Other References
https://git.kernel.org/stable/c/0afbfe019c881483337d9f8304e678af05ebe7cc
https://git.kernel.org/stable/c/13e7861809ef9e7e720ff5f0af1d4293a6d0a9b4
https://git.kernel.org/stable/c/518df61b9b0a5b288dfa72c87246045329c18b8c
https://git.kernel.org/stable/c/5361fb1e5bc246f9a2c0721543f72c8dac200769
https://git.kernel.org/stable/c/9b66c9af7172ffcf727214fa0ebe9a5e1ed6eb16
Frequently Asked Questions
What is CVE-2026-92495? +
In the Linux kernel, the following vulnerability has been resolved:
RDMA/bnxt_re: Clear VM_MAYWRITE on DBR/toggle page mmap
bnxt_re_mmap() rejects VM_WRITE for the DBR_PAGE and TOGGLE_PAGE mmap
flags, but a read-only mapping can still retain VM_MAYWRITE. nd later
be upgraded with mprotect(PROT_WRITE). This can bypass the write check
that only runs at mmap time.
Clear VM_MAYWRITE before vm_insert_page() in the shared DBR/toggle-page
branch, matching the existing policy that userspace writes are not
expected for these pages.
How do I check if I'm vulnerable to CVE-2026-92495? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.