Resource exhaustion in Linux kernel - CVE-2026-93241
Published: September 25, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper handling of memory charges for OOM victims in the memory cgroup charge handling logic when an OOM victim continues charging memory after the OOM reaper has set MMF_OOM_SKIP. A local user can cause exiting threads to serialize on oom_lock to cause a denial of service.
Exploitation requires an OOM-killed multithreaded process and OOM reaper failure caused by mmap_lock contention.