PT-2026-94864 · Linux · Linux Kernel
CVE-2026-93066
·
Published
2026-09-17
·
Updated
2026-09-28
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A use-after-free issue exists in the x86 memory management PAT (Page Attribute Table) implementation. The problem occurs when loading and unloading modules concurrently on multiple CPUs. Specifically, the
cpa collapse large pages() function rebuilds a leaf PMD (Page Middle Directory) from 4K PTEs (Page Table Entries) and frees the old PTE-table pages. Simultaneously, the change page attr() function may fetch a PTE pointer via lookup address in pgd attr() and later attempt to write to it using set pte atomic(). If the PTE-table page is freed by the collapse process before the write occurs, it leads to memory corruption or a fatal fault. This happens because the TLB flush does not synchronize with page-table walkers running with interrupts enabled.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel