← All Advisories

CVE-2026-93240

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-93240

Key Details

CVECVE-2026-93240
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

memcg: make the v1 soft limit knob inert

The v1 soft limit has been deprecated since v6.12 and nobody has reported

depending on it. Start the removal by decoupling the interface from the

implementation: keep memory.soft_limit_in_bytes, but ignore writes to it

and always report the maximum value on read similar to what

memory.kmem.limit_in_bytes already does.

Writes are still parsed, so malformed input keeps returning -EINVAL. The

knob now also behaves the same everywhere: it used to return -EOPNOTSUPP

on PREEMPT_RT, where soft limit reclaim has always been disabled.

This also fixes the syzbot report linked below. Soft limit reclaim is the

only caller that runs shrink_lruvec() from kswapd against a specific

memcg, so it is the only way to reach lru_gen_shrink_lruvec() and in turn

set_mm_walk(), which warns when called from kswapd. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-93240
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-93240