Executive brief
A race condition was identified in the Linux kernel's memory management system. This flaw occurs when the system is setting up or tearing down memory control groups, potentially leading to a system crash or unpredictable behavior. While technical in nature, such vulnerabilities can impact the stability and availability of servers running affected Linux distributions.
Technical details
A race condition exists in mm/shrinker.c within the Linux kernel due to improper serialization between expand_shrinker_info() and alloc_shrinker_info(). The vulnerability occurs because alloc_shrinker_info() drops the shrinker_mutex before freeing partially initialized shrinker_info arrays during an error path. This allows a concurrent expansion operation to access and attempt to copy data from an array that is simultaneously being freed, resulting in a double-free or use-after-free (UAF) scenario. The fix involves ensuring that teardown remains serialized under the shrinker_mutex until the memory cgroup is fully online or no longer visible.
Affected products
- Linux Linux 307bececcd12 to b9a280a9a454, 6465ff3ce651, 284c267f013e, 65476d31d805
Timeline
- 2026-06-17: disclosed: Initial patch submission by Qi Zheng
- 2026-07-18: patched: Commits merged into stable branches
- 2026-07-25: advisory: NVD publication of CVE-2026-64418