Time-of-check Time-of-use (TOCTOU) Race Condition in Linux kernel - CVE-2026-93216
Published: September 25, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a time-of-check to time-of-use race condition in print_page_owner_memcg() in mm/page_owner.c when a page is concurrently freed and reallocated. A local user can race page freeing and reallocation to trigger VM_BUG_ON assertions and cause a denial of service.
The issue affects builds configured with CONFIG_DEBUG_VM=y.