SB20260727154 - Improper locking in Linux kernel mm
Published: July 27, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper locking (CVE-ID: CVE-2026-64419)
CWE-ID: CWE-667 - Improper Locking
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper lock handling in shrinker_debugfs_count_show() when reading the debugfs "count" file of a memcg-aware shrinker. A local user can read the debugfs file to cause a denial of service.
The issue occurs because a callback may sleep while executing inside an RCU read-side critical section.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/2fed79f0fe8c8d28a972c290dbfd693c3546c8c4
- https://git.kernel.org/stable/c/560e21e8ccff813e84d05f6500907c549a3d6985
- https://git.kernel.org/stable/c/86237e56091e70f09c0fbf217f9d9c0e08f556c4
- https://git.kernel.org/stable/c/b902890c62d200b3509cb5e09cf1e0a66553c128
- https://git.kernel.org/stable/c/de5f69b8dae8698ac5e48dfcd30017887cdf4e5a
- https://git.kernel.org/stable/c/e441cbfbd0eaa6404278e985033c33caba4db767