Incorrect calculation in Linux kernel - CVE-2026-93197
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to incorrect LRU size accounting in lruvec_reparent_lru() and lru_gen_reparent_memcg() when reparenting LRU folios during memory cgroup offlining. A local user can offline a memory cgroup to cause a denial of service.
The offlined cgroup can retain stale LRU size counters while it remains subject to memory-cgroup iteration and reclaim scanning.