← All Advisories

CVE-2026-93196

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-93196

Key Details

CVECVE-2026-93196
CVSS Score / Version8.4 (High) / CVSS v3.1
Updated2026-10-03
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

nvdimm: virtio_pmem: refcount requests for token lifetime

KASAN reports slab-use-after-free in __wake_up_common():

BUG: KASAN: slab-use-after-free in __wake_up_common+0x114/0x160

Read of size 8 at addr ffff88810fdcb710 by task swapper/0/0

CPU: 0 UID: 0 PID: 0 Comm: swapper/0 Not tainted

6.19.0-next-20260220-00006-g1eae5f204ec3 #4 PREEMPT(full)

Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Arch Linux

1.17.0-2-2 04/01/2014

Call Trace:

<IRQ>

dump_stack_lvl+0x6d/0xb0

print_report+0x170/0x4e2

? __pfx__raw_spin_lock_irqsave+0x10/0x10

? __virt_addr_valid+0x1dc/0x380

kasan_report+0xbc/0xf0

? __wake_up_common+0x114/0x160

? __wake_up_common+0x114/0x160

__wake_up_common+0x114/0x160

? __pfx__raw_spin_lock_irqsave+0x10/0x10

__wake_up+0x36/0x60

virtio_pmem_host_ack+0x11d/0x3b0

? sched_balance_domains+0x29f/0xb00

? __pfx_virtio_pmem_host_ack+0x10/0x10

? _raw_spin_lock_irqsave+0x98/0x100

? __pfx__raw_spin_lock_irqsave+0x10/0x10

vring_interrupt+0x1c9/0x5e0

? __pfx_vp_interrupt+0x10/0x10

vp_vring_interrupt+0x87/0x100

? __pfx_vp_interrupt+0x10/0x10

__handle_irq_event_percpu+0x17f/0x550

? __pfx__raw_spin_lock+0x10/0x10

handle_irq_event+0xab/0x1c0

handle_fasteoi_irq+0x276/0xae0

__common_interrupt+0x65/0x130

common_interrupt+0x78/0xa0

</IRQ>

virtio_pmem_host_ack() wakes a request that has already been freed by the

submitter.

This happens when the request token is still reachable via the virtqueue,

but virtio_pmem_flush() returns and frees it.

Fix the token lifetime by refcounting struct virtio_pmem_request.

virtio_pmem_flush() holds a submitter reference, and the virtqueue holds an

extra reference once the request is queued. The completion path drops the

virtqueue reference, and the submitter drops its reference before

returning. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-93196
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-93196