« Volver al listado

CVE-2026-97941

Estado: RecibidaAlta (7.8)—

In the Linux kernel, the following vulnerability has been resolved:

mm/slab: take n->list_lock in __slab_try_return_freelist() to avoid race

Commit ba7425312607 ("mm, slab: add an optimistic __slab_try_return_freelist()") incorrectly assumed that nobody has freed an object to the slab as long as slab->freelist is NULL and cmpxchg succeeds.

However, as reported by Hyunwoo Kim [1], other CPUs might have freed an object to the slab, insert the slab to the partial list, then allocated an object from the slab, and be in the middle of removing the slab from the list under n->list_lock.

Since __refill_objects_node() puts the slab back on pc.slabs outside n->list_lock, it might insert the slab into that list while the slab is concurrently being removed from n->partial. This led to a list corruption [1]:

Leer descripción completaMostrar menos

This is a classic ABA problem where cmpxchg succeeds but the state has changed since __refill_objects_node() took the freelist from the slab.

As Vlastimil Babka mentioned [2], it should be rare to return more than one slab (due to the racy read of slab->counters in get_partial_node_bulk()). Therefore, instead of introducing additional complexity, acquire and release n->list_lock twice in the worst case.

Return the slab directly to the partial list and hold n->list_lock across the cmpxchg and add_partial(). This is similar to the initial version of commit ba7425312607 [3]. This is enough to avoid the race as the list manipulation is serialized by n->list_lock. While at it, bring back unlikely() hint now that the condition is unlikely.

Detalles técnicos trazas, registros y código del informe original
  list_add corruption. next->prev should be prev
  (ffff888100000248), but was dead000000000122.
  (next=ffffea000416e410).
  kernel BUG at lib/list_debug.c:29!
  Oops: invalid opcode: 0000 [#1] SMP NOPTI
  CPU: 1 UID: 65534 PID: 144 Comm: poc Not tainted
  7.2.0-16172-gcf72cbb39da8-dirty #1 PREEMPT(lazy)
  RIP: 0010:__list_add_valid_or_report+0x80/0xd0
  ...
  Call Trace:
   alloc_from_new_slab+0x183/0x300
   ___slab_alloc+0x31c/0x890
   __kmalloc_noprof+0x3d4/0x800
   lsm_blob_alloc+0x2d/0x50
   security_msg_msg_alloc+0x26/0x90
   load_msg+0x1aa/0x210
   do_msgsnd+0x91/0x800
   do_syscall_64+0x109/0x5d0
   entry_SYSCALL_64_after_hwframe+0x77/0x7f
  ...
  Kernel panic - not syncing: Fatal exception

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad de race condition en kernel Linux (AV:L, PR:L) explotable localmente para escalada de privilegios. Impacto: DoS por corrupción de memoria y fuga de información de kernel.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-97941",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "ba742531260782a2646bc031f9a12cafebc22594",
              "lessThan": "570a6aaf6b52c6ec098f4811cdb52b1496f13d15",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ba742531260782a2646bc031f9a12cafebc22594",
              "lessThan": "4a724bcf5d703e18957397914d79156fa2cf1174",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "mm/slub.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7.2"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "7.2",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.2.7",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc3",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "mm/slub.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-25T11:17:21.517",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/4a724bcf5d703e18957397914d79156fa2cf1174",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/570a6aaf6b52c6ec098f4811cdb52b1496f13d15",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/slab: take n->list_lock in __slab_try_return_freelist() to avoid race\n\nCommit ba7425312607 (\"mm, slab: add an optimistic\n__slab_try_return_freelist()\") incorrectly assumed that nobody has freed\nan object to the slab as long as slab->freelist is NULL and cmpxchg\nsucceeds.\n\nHowever, as reported by Hyunwoo Kim [1], other CPUs might have freed\nan object to the slab, insert the slab to the partial list, then\nallocated an object from the slab, and be in the middle of removing\nthe slab from the list under n->list_lock.\n\nSince __refill_objects_node() puts the slab back on pc.slabs\noutside n->list_lock, it might insert the slab into that list while\nthe slab is concurrently being removed from n->partial.\nThis led to a list corruption [1]:\n\n  list_add corruption. next->prev should be prev\n  (ffff888100000248), but was dead000000000122.\n  (next=ffffea000416e410).\n  kernel BUG at lib/list_debug.c:29!\n  Oops: invalid opcode: 0000 [#1] SMP NOPTI\n  CPU: 1 UID: 65534 PID: 144 Comm: poc Not tainted\n  7.2.0-16172-gcf72cbb39da8-dirty #1 PREEMPT(lazy)\n  RIP: 0010:__list_add_valid_or_report+0x80/0xd0\n  ...\n  Call Trace:\n   alloc_from_new_slab+0x183/0x300\n   ___slab_alloc+0x31c/0x890\n   __kmalloc_noprof+0x3d4/0x800\n   lsm_blob_alloc+0x2d/0x50\n   security_msg_msg_alloc+0x26/0x90\n   load_msg+0x1aa/0x210\n   do_msgsnd+0x91/0x800\n   do_syscall_64+0x109/0x5d0\n   entry_SYSCALL_64_after_hwframe+0x77/0x7f\n  ...\n  Kernel panic - not syncing: Fatal exception\n\nThis is a classic ABA problem where cmpxchg succeeds but the state has\nchanged since __refill_objects_node() took the freelist from the slab.\n\nAs Vlastimil Babka mentioned [2], it should be rare to return more than\none slab (due to the racy read of slab->counters in\nget_partial_node_bulk()). Therefore, instead of introducing additional\ncomplexity, acquire and release n->list_lock twice in the worst case.\n\nReturn the slab directly to the partial list and hold n->list_lock\nacross the cmpxchg and add_partial(). This is similar to the initial\nversion of commit ba7425312607 [3]. This is enough to avoid the race as\nthe list manipulation is serialized by n->list_lock. While at it,\nbring back unlikely() hint now that the condition is unlikely."
    }
  ],
  "lastModified": "2026-09-25T15:18:02.843",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}