Improper control of a resource through its lifetime in Linux kernel - CVE-2026-93181

 

Improper control of a resource through its lifetime in Linux kernel - CVE-2026-93181

Published: September 18, 2026


Vulnerability identifier: #VU150810
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-93181
CWE-ID: CWE-664
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local privileged user to disrupt uncore event collection.

The vulnerability exists due to improper resource lifetime management in the Intel x86 uncore event handling code when CPUs transition online or offline. A local privileged user can trigger CPU online or offline events to disrupt uncore event collection.

On systems with one CPU per die, an uncore box can remain uninitialized.


Affected software

Linux kernel

How to mitigate CVE-2026-93181

Install security update from vendor's repository.


External References

Related Security Bulletins