PT-2026-94896 · Linux · Linux Kernel
CVE-2026-93100
·
Published
2026-09-17
·
Updated
2026-09-28
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A use-after-free issue exists in the
fs/resctrl component. The problem occurs due to a race condition between the fallback freer in the rdtgroup kn put() function and the primary bulk teardown paths free all child rdtgrp() and rmdir all sub(). Specifically, rdtgroup kn put() uses atomic dec and test() outside the rdtgroup mutex to check the waitcount variable. A concurrent caller of the bulk teardown paths can observe the waitcount as zero, call rdtgroup remove(), and free the structure via kfree(). This leads to a use-after-free when rdtgroup kn put() subsequently reads the flags variable, and may result in a double-free if the memory satisfies the RDT DELETED flag check.Recommendations
As a temporary mitigation, restrict access to the
fs/resctrl filesystem to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel