Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-93208— kasan: fix cache shrink race with CPU hotplug

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,已解决以下漏洞: kasan:修复 CPU 热插拔与缓存收缩之间的竞态条件 首先在所有在线 CPU 上调用 。每个回调函数将属于该缓存的对象从 移动到该 CPU 的 (收缩列表)中,以便稍后在任务上下文中释放这些对象。 在持有 的情况下调用清除隔离路径,但 并未持有该锁。因此,后者可能与 CPU 脱机操作发生竞态,具体如下: 留在 CPU1 的 中的对象未被返还给 slab 分配器。这可能导致 无法释放本应被清除的空 slab。如果 CPU1 保持脱机状态,后续的 也会跳过该列表,并报告缓存

AI Predicted 5.5 Difficulty: Theoretical EPSS 0.17% · P6

Possible ATT&CK Techniques 1 AI

T1690 · Prevent Command History Logging

Affected Version Matrix 12

VendorProduct Version RangeStatus
Linux Linux 07d067e4f2ceb72b9f681995cc53828caaba9e6e< 7cd164f0e1bab0f8dd125c92ed4f19bbd6b92a4a affected
07d067e4f2ceb72b9f681995cc53828caaba9e6e< 709c3646545e0a1f99a5816384c633f6552c5a98 affected
07d067e4f2ceb72b9f681995cc53828caaba9e6e< 30e8cb8598aa41b1b9f8803081d2ae5e5369c0f3 affected
07d067e4f2ceb72b9f681995cc53828caaba9e6e< 3119d58e4ef8719d669911d38a53fc00086ac48b affected
07d067e4f2ceb72b9f681995cc53828caaba9e6e< 8790303cbaac52a11dfed4aab261f8ea60682525 affected
5.19 affected
< 5.19 unaffected
6.6.157≤ 6.6.* unaffected
… +4 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-93208

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
kasan: fix cache shrink race with CPU hotplug
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: kasan: fix cache shrink race with CPU hotplug kasan_quarantine_remove_cache() first invokes per_cpu_remove_cache() on all online CPUs. Each callback moves objects belonging to the cache from cpu_quarantine to the CPU's shrink_qlist, where they can later be freed from task context. kmem_cache_destroy() invokes the quarantine removal path while holding cpus_read_lock(), but kmem_cache_shrink() does not. The latter can therefore race with CPU offlining as follows: kmem_cache_shrink() CPU hotplug ------------------- ----------- on_each_cpu() CPU1 moves objects to CPU1's shrink_qlist on_each_cpu() returns CPU1 goes offline kasan_cpu_offline() drains cpu_quarantine leaves shrink_qlist untouched for_each_online_cpu() skips CPU1 The objects left on CPU1's shrink_qlist are not returned to the slab allocator. This may prevent kmem_cache_shrink() from releasing slabs that would otherwise become empty. If CPU1 remains offline, a later kmem_cache_destroy() also skips the list and can report that the cache still contains objects. An intermittent occurrence was observed with a virtio-9p filesystem. The mount and umount commands both returned 0, but the kernel logged the following during the userspace-triggered teardown: [ 2994.380134][ T111] BUG 9p-fcall-cache-1 (Tainted: G B ): Objects remaining on __kmem_cache_shutdown() [ 2994.381140][ T111] Object 0xff11000004361118 @offset=4376 [ 2994.381607][ T111] Allocated in p9_fcall_init+0x201/0x400 age=19564 cpu=1 pid=104 [ 2994.382591][ T111] p9_fcall_init+0x201/0x400 [ 2994.382810][ T111] p9_tag_alloc+0x12f/0x700 [ 2994.382982][ T111] p9_client_prepare_req+0x102/0x3e0 [ 2994.383165][ T111] p9_client_rpc+0x1ab/0xa50 [ 2994.383334][ T111] p9_client_getattr_dotl+0xb0/0x1a0 [ 2994.383515][ T111] v9fs_vfs_getattr_dotl+0x115/0x360 [ 2994.383719][ T111] vfs_getattr_nosec+0x22c/0x3a0 [ 2994.383910][ T111] vfs_statx+0xd7/0x170 [ 2994.384062][ T111] vfs_fstatat+0x45/0x80 [ 2994.384215][ T111] __do_sys_newfstatat+0x84/0xe0 [ 2994.384386][ T111] do_syscall_64+0x115/0x6a0 [ 2994.384566][ T111] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 2994.399720][ T111] WARNING: mm/slub.c:1244 at __kmem_cache_shutdown+0x363/0x500, CPU#0: busybox/111 [ 2994.405655][ T111] Call Trace: [ 2994.406325][ T111] kmem_cache_destroy+0x73/0x1b0 [ 2994.406630][ T111] p9_client_destroy+0x271/0x3c0 [ 2994.407210][ T111] v9fs_session_close+0x3c/0x260 [ 2994.407409][ T111] v9fs_kill_super+0x48/0x90 [ 2994.407584][ T111] deactivate_locked_super+0xa3/0x160 [ 2994.407778][ T111] cleanup_mnt+0x1dd/0x3e0 Thus, a successful umount left objects in the 9p fcall cache and prevented the cache from being destroyed cleanly. Per-CPU shrink_qlist storage exists for every possible CPU, and each list is protected by its own raw spinlock. Iterate over possible CPUs so that a list populated before its CPU went offline is drained as well. for_each_possible_cpu() can do more work than for_each_online_cpu(), but this change only affects CONFIG_KASAN_GENERIC kernels. The extra work is limited to cache shrink and cache destruction paths and does not affect the normal allocation/free fast path. It adds one raw-spinlock-protected scan of each possible CPU's shrink list. These lists are normally empty; a non-empty list is traversed to remove objects belonging to the cache being shrunk or destroyed.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 07d067e4f2ceb72b9f681995cc53828caaba9e6e ~ 7cd164f0e1bab0f8dd125c92ed4f19bbd6b92a4a -
Linux Linux 5.19 -

II. Public POCs for CVE-2026-93208

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-93208

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-93208 (5)

Same Patch Batch · Linux · 2026-09-24 · 234 CVEs total

CVE-2026-93207 9.8 CRITICAL SUNRPC: Zero rpc_gss_wire_cred at svcauth_gss_decode_credbody() entry
CVE-2026-97413 9.8 CRITICAL RDMA/rtrs-srv: Fix integer underflow in process_read and process_write
CVE-2026-93228 9.1 CRITICAL svcrdma: Reject Write/Reply chunks with segcount 0
CVE-2026-93793 8.8 HIGH wifi: iwlwifi: mvm: validate TX_CMD response layout
CVE-2026-93799 8.8 HIGH wifi: iwlwifi: mvm: validate sta_id in BA window status notif
CVE-2026-93790 8.8 HIGH wifi: iwlwifi: mvm: fix out-of-bounds tid_data access in BA notif
CVE-2026-93806 8.8 HIGH wifi: cfg80211: validate assoc response length before status and IE access
CVE-2026-97442 8.8 HIGH wifi: ath11k: fix invalid data access in ath11k_dp_rx_h_undecap_nwifi
CVE-2026-97409 8.8 HIGH nvme-fc: Do not cancel requests in io target before it is initialized
CVE-2026-97509 8.8 HIGH thunderbolt: Keep XDomain reference during the lifetime of a service
CVE-2026-93280 8.8 HIGH greybus: audio: bound the topology section sizes against the fetched size
CVE-2026-93284 8.8 HIGH drm/pagemap: dma-unmap pages before handling migration errors
CVE-2026-97451 8.4 HIGH ACPICA: Fix integer overflow in acpi_ex_opcode_3A_1T_1R() (mid_op)
CVE-2026-97452 8.4 HIGH ACPICA: Prevent adding invalid references
CVE-2026-97455 8.4 HIGH ACPICA: Fix use-after-free in acpi_ds_terminate_control_method()
CVE-2026-97450 8.4 HIGH ACPICA: validate handler object type in two places
CVE-2026-93827 8.4 HIGH virtio-fs: avoid double-free on failed queue setup
CVE-2026-97433 8.2 HIGH nvme: validate FDP configuration descriptor sizes
CVE-2026-93787 8.1 HIGH smb: client: bound dirent name against end of SMB response in cifs_filldir
CVE-2026-93224 8.1 HIGH svcrdma: Fix unmatched rn_unregister on failed accept

Showing top 20 of 234 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-93208

No comments yet


Leave a comment