Improper locking in Linux kernel - CVE-2026-64419
Published: July 27, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper lock handling in shrinker_debugfs_count_show() when reading the debugfs "count" file of a memcg-aware shrinker. A local user can read the debugfs file to cause a denial of service.
The issue occurs because a callback may sleep while executing inside an RCU read-side critical section.
Affected software
Ubuntu
linux (Ubuntu package)
linux-azure (Ubuntu package)
linux-gcp-7.0 (Ubuntu package)
linux-oracle-7.0 (Ubuntu package)
linux-oem-7.0 (Ubuntu package)
linux-azure-7.0 (Ubuntu package)
How to mitigate CVE-2026-64419
linux (Ubuntu package) - addressed in versions 7.0.0-31.31, 7.0.0-31.31.1, 7.0.0-31.31~24.04.1, 7.0.0-1006.7, 7.0.0-1011.11~24.04.1, 7.0.0-1012.12, 7.0.0-1012.12~24.04.1
linux-azure (Ubuntu package) - addressed in versions 7.0.0-1011.11, 7.0.0-1014.14
linux-gcp-7.0 (Ubuntu package) - update to 7.0.0-1011.11~24.04.1
linux-oracle-7.0 (Ubuntu package) - update to 7.0.0-1011.11~24.04.1
linux-oem-7.0 (Ubuntu package) - update to 7.0.0-1013.13
linux-azure-7.0 (Ubuntu package) - update to 7.0.0-1014.14~24.04.1
External References
- https://git.kernel.org/stable/c/2fed79f0fe8c8d28a972c290dbfd693c3546c8c4
- https://git.kernel.org/stable/c/560e21e8ccff813e84d05f6500907c549a3d6985
- https://git.kernel.org/stable/c/86237e56091e70f09c0fbf217f9d9c0e08f556c4
- https://git.kernel.org/stable/c/b902890c62d200b3509cb5e09cf1e0a66553c128
- https://git.kernel.org/stable/c/de5f69b8dae8698ac5e48dfcd30017887cdf4e5a
- https://git.kernel.org/stable/c/e441cbfbd0eaa6404278e985033c33caba4db767