SB2026081308 - Race condition in Linux kernel lib
Published: August 13, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Race condition (CVE-ID: CVE-2026-68090)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in debugobjects in lib/debugobjects.c when handling object activation or initialization assertions during a concurrent out-of-memory disable. A local user can trigger debug object operations while forcing a concurrent memory exhaustion condition to cause a denial of service.
The issue can cause a valid timer object to become nonfunctional through an unintended fixup path.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/1f4f02b336c3be125c8fcf87df73db2e0e028b8b
- https://git.kernel.org/stable/c/203a965bf2ab43130778d8214fb0c3c8c2d19cdf
- https://git.kernel.org/stable/c/23da32e88627e63e0864f59f4c63a2dc0ab851a3
- https://git.kernel.org/stable/c/2d5e320b7ab9b25229ac4331541964a58b5e1d29
- https://git.kernel.org/stable/c/b81dde13cc163450dcb402dcc915ef13ba241e01
- https://git.kernel.org/stable/c/c00164c9e7fa6145886ad666806cb5347895de5c
- https://git.kernel.org/stable/c/d663fbf28b2eebe665bb9cf828d7d528e5a8707e
- https://git.kernel.org/stable/c/e2e255d07723c330dded8e576ce28a8d23a692ce