SB20260925141 - Resource exhaustion in Linux kernel mm
Published: September 25, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Resource exhaustion (CVE-ID: CVE-2026-93241)
CWE-ID: CWE-400 - Resource exhaustion
CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper handling of memory charges for OOM victims in the memory cgroup charge handling logic when an OOM victim continues charging memory after the OOM reaper has set MMF_OOM_SKIP. A local user can cause exiting threads to serialize on oom_lock to cause a denial of service.
Exploitation requires an OOM-killed multithreaded process and OOM reaper failure caused by mmap_lock contention.
Remediation
Install update from vendor's website.