Resource exhaustion in Linux kernel - CVE-2026-93241

 

Resource exhaustion in Linux kernel - CVE-2026-93241

Published: September 25, 2026


Vulnerability identifier: #VU152165
CSH Severity: Low
CVSS v4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-93241
CWE-ID: CWE-400
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper handling of memory charges for OOM victims in the memory cgroup charge handling logic when an OOM victim continues charging memory after the OOM reaper has set MMF_OOM_SKIP. A local user can cause exiting threads to serialize on oom_lock to cause a denial of service.

Exploitation requires an OOM-killed multithreaded process and OOM reaper failure caused by mmap_lock contention.


Affected software

Linux kernel

How to mitigate CVE-2026-93241

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins