CVE-2026-93240
In the Linux kernel, the following vulnerability has been resolved:
memcg: make the v1 soft limit knob inert
The v1 soft limit has been deprecated since v6.12 and nobody has reported depending on it. Start the removal by decoupling the interface from the implementation: keep memory.soft_limit_in_bytes, but ignore writes to it and always report the maximum value on read similar to what memory.kmem.limit_in_bytes already does.
Writes are still parsed, so malformed input keeps returning -EINVAL. The knob now also behaves the same everywhere: it used to return -EOPNOTSUPP on PREEMPT_RT, where soft limit reclaim has always been disabled.
Leer descripción completaMostrar menos
This also fixes the syzbot report linked below. Soft limit reclaim is the only caller that runs shrink_lruvec() from kswapd against a specific memcg, so it is the only way to reach lru_gen_shrink_lruvec() and in turn set_mm_walk(), which warns when called from kswapd.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.22%
- Percentil entre todas las CVEs puntuadas: 11
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-93240",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "e9d4e1ee788097484606c32122f146d802a9c5fb",
"lessThan": "72fb67f6e0e5d78e4f34cf9929d1afdb0fd54203",
"versionType": "git"
},
{
"status": "affected",
"version": "e9d4e1ee788097484606c32122f146d802a9c5fb",
"lessThan": "0a90e268cce7023f34087bfa4affb42e29ff5f45",
"versionType": "git"
},
{
"status": "affected",
"version": "e9d4e1ee788097484606c32122f146d802a9c5fb",
"lessThan": "5ec8f629a300cc40e746d6178f724bdff7683fa7",
"versionType": "git"
},
{
"status": "affected",
"version": "e9d4e1ee788097484606c32122f146d802a9c5fb",
"lessThan": "a3417097fb107cea3358b19bcbb4eb655fd67f8c",
"versionType": "git"
}
],
"programFiles": [
"Documentation/admin-guide/cgroup-v1/memory.rst",
"mm/memcontrol-v1.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.3"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.3",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.12.110",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.51",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.5",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"Documentation/admin-guide/cgroup-v1/memory.rst",
"mm/memcontrol-v1.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-24T16:17:19.827",
"references": [
{
"url": "https://git.kernel.org/stable/c/0a90e268cce7023f34087bfa4affb42e29ff5f45",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/5ec8f629a300cc40e746d6178f724bdff7683fa7",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/72fb67f6e0e5d78e4f34cf9929d1afdb0fd54203",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a3417097fb107cea3358b19bcbb4eb655fd67f8c",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmemcg: make the v1 soft limit knob inert\n\nThe v1 soft limit has been deprecated since v6.12 and nobody has reported\ndepending on it. Start the removal by decoupling the interface from the\nimplementation: keep memory.soft_limit_in_bytes, but ignore writes to it\nand always report the maximum value on read similar to what\nmemory.kmem.limit_in_bytes already does.\n\nWrites are still parsed, so malformed input keeps returning -EINVAL. The\nknob now also behaves the same everywhere: it used to return -EOPNOTSUPP\non PREEMPT_RT, where soft limit reclaim has always been disabled.\n\nThis also fixes the syzbot report linked below. Soft limit reclaim is the\nonly caller that runs shrink_lruvec() from kswapd against a specific\nmemcg, so it is the only way to reach lru_gen_shrink_lruvec() and in turn\nset_mm_walk(), which warns when called from kswapd."
}
],
"lastModified": "2026-09-25T13:17:18.003",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}