PT-2026-97875 · Linux · Linux Kernel
CVE-2026-93208
·
Published
2026-09-24
·
Updated
2026-09-28
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A race condition exists in the Linux kernel between cache shrinking and CPU hotplugging. The function
kmem cache shrink() does not hold cpus read lock(), allowing it to race with CPU offlining. When a CPU goes offline, the kasan cpu offline() function drains the cpu quarantine but leaves the shrink qlist untouched. Consequently, objects remaining on the shrink qlist of an offline CPU are not returned to the slab allocator, which may prevent the release of empty slabs. This can lead to situations where kmem cache destroy() reports that a cache still contains objects even after a successful teardown, as seen in incidents involving virtio-9p filesystems. This issue specifically affects kernels with CONFIG KASAN GENERIC enabled.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel