Race condition in Linux kernel - CVE-2026-68090
Published: August 13, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in debugobjects in lib/debugobjects.c when handling object activation or initialization assertions during a concurrent out-of-memory disable. A local user can trigger debug object operations while forcing a concurrent memory exhaustion condition to cause a denial of service.
The issue can cause a valid timer object to become nonfunctional through an unintended fixup path.
Affected software
Ubuntu
linux (Ubuntu package)
linux-gcp-7.0 (Ubuntu package)
linux-oem-7.0 (Ubuntu package)
How to mitigate CVE-2026-68090
linux (Ubuntu package) - addressed in versions 7.0.0-31.31, 7.0.0-31.31.1, 7.0.0-31.31~24.04.1, 7.0.0-1006.7, 7.0.0-1011.11~24.04.1, 7.0.0-1012.12, 7.0.0-1012.12~24.04.1
linux-gcp-7.0 (Ubuntu package) - update to 7.0.0-1011.11~24.04.1
linux-oem-7.0 (Ubuntu package) - update to 7.0.0-1013.13
External References
- https://git.kernel.org/stable/c/1f4f02b336c3be125c8fcf87df73db2e0e028b8b
- https://git.kernel.org/stable/c/203a965bf2ab43130778d8214fb0c3c8c2d19cdf
- https://git.kernel.org/stable/c/23da32e88627e63e0864f59f4c63a2dc0ab851a3
- https://git.kernel.org/stable/c/2d5e320b7ab9b25229ac4331541964a58b5e1d29
- https://git.kernel.org/stable/c/b81dde13cc163450dcb402dcc915ef13ba241e01
- https://git.kernel.org/stable/c/c00164c9e7fa6145886ad666806cb5347895de5c
- https://git.kernel.org/stable/c/d663fbf28b2eebe665bb9cf828d7d528e5a8707e
- https://git.kernel.org/stable/c/e2e255d07723c330dded8e576ce28a8d23a692ce