PT-2026-94895 · Linux · Linux Kernel
CVE-2026-93099
·
Published
2026-09-17
·
Updated
2026-09-28
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A use-after-free issue exists in the resctrl file system. The
mbm handle overflow() and cqm handle limbo() workers, which are scheduled via delayed work embedded in struct rdt l3 mon domain, may sleep while reading event counters. A race condition occurs when a worker is blocked waiting for cpus read lock() while the hotplug core holds cpus write lock(), leading the architecture to free the rdt l3 mon domain containing the worker's work struct. Upon unblocking, the container of() operation on the embedded work pointer dereferences freed memory.Recommendations
As a temporary mitigation, restrict the use of CPU hotplugging features that trigger the removal of resctrl domains until the system is updated to a version containing the fix.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel