SB20260925141 - Resource exhaustion in Linux kernel mm



SB20260925141 - Resource exhaustion in Linux kernel mm

Published: September 25, 2026

Security Bulletin ID SB20260925141
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Partial DoS

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Resource exhaustion (CVE-ID: CVE-2026-93241)

CWE-ID: CWE-400 - Resource exhaustion

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper handling of memory charges for OOM victims in the memory cgroup charge handling logic when an OOM victim continues charging memory after the OOM reaper has set MMF_OOM_SKIP. A local user can cause exiting threads to serialize on oom_lock to cause a denial of service.

Exploitation requires an OOM-killed multithreaded process and OOM reaper failure caused by mmap_lock contention.


Remediation

Install update from vendor's website.