Race condition in Linux kernel - CVE-2026-89752
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in the memory.high and memory.max limit update handlers when concurrently updating memory cgroup limits through separate open files. A local user can lower a memory.max limit and restore it through another open file to cause a denial of service.
Exploitation requires a cgroup populated with anonymous memory and swapping disabled.