Junglewise Threat Intelligence

CVE-2026-53153: Linux Kernel list corruption in mm/list_lru during memcg reparenting

CVE-2026-53153 · Severity: info · CVSS 0 · Published 2026-06-25

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A race condition was identified in the Linux kernel's memory management system during the decommissioning of memory control groups (memcgs). This flaw could allow concurrent system processes to corrupt internal linked lists, potentially leading to system instability or crashes. The issue occurs when the system incorrectly reassigns memory tracking lists to a parent group before ensuring all active operations on the dying group have finished.

Technical details

A race condition exists in memcg_reparent_list_lrus() where the xarray entry for a dying memcg is cleared before its per-node lists are reparented. This creates a window where a concurrent list_lru_del() operation may see a NULL xarray entry and incorrectly acquire the parent's per-node lock while the item is still physically linked to the child's list. If another thread simultaneously holds the child's lock, both threads may modify the same list pointers under different locks, leading to memory corruption. The fix involves reversing the operation order: reparenting the lists and marking them dead before clearing the xarray entry. Patches have been released for various stable kernel branches including 6.18.x and 7.0.x.

Affected products

  • Linux Linux Kernel 6.13, 6.18.36, 7.0.13, 7.1

Timeline

  • 2026-06-01: disclosed: Initial patch submission by Shakeel Butt
  • 2026-06-25: advisory: CVE-2026-53153 published in NVD

References

Related threats