PT-2026-94993 · Linux · Linux Kernel

CVE-2026-93197

·

Published

2026-09-17

·

Updated

2026-09-24

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the memory cgroup (memcg) management where LRU size accounting is copied instead of moved during reparenting. When a memory cgroup is offlined, the lruvec reparent lru() function and lru gen reparent memcg() for MGLRU credit the parent with the child's per-zone lru zone size[] but fail to clear the child's copy. This leaves a stale value on the child cgroup. Because dying cgroups are not freed immediately, shrink lruvec() continues to be called, causing get scan count() to read a phantom counter via lruvec lru size(). This results in the scan loop processing an empty list repeatedly or, under MGLRU, causing count shadow nodes() to over-budget the shadow node limit. In one observed instance on a 251 GiB host, this led to phantom counters describing 476 GiB of memory across 57 cgroups. The issue also affects LRU UNEVICTABLE size accounting. The fix requires the invariant that a folio's objcg remains the same as its node to prevent lruvec del folio() from underflowing and triggering a system bug.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-93197
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel