CVE-2026-93196
Gravedad CVSS v3.1:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
17/09/2026
Última modificación:
03/10/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
nvdimm: virtio_pmem: refcount requests for token lifetime<br />
<br />
KASAN reports slab-use-after-free in __wake_up_common():<br />
BUG: KASAN: slab-use-after-free in __wake_up_common+0x114/0x160<br />
Read of size 8 at addr ffff88810fdcb710 by task swapper/0/0<br />
<br />
CPU: 0 UID: 0 PID: 0 Comm: swapper/0 Not tainted<br />
6.19.0-next-20260220-00006-g1eae5f204ec3 #4 PREEMPT(full)<br />
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Arch Linux<br />
1.17.0-2-2 04/01/2014<br />
Call Trace:<br />
<br />
dump_stack_lvl+0x6d/0xb0<br />
print_report+0x170/0x4e2<br />
? __pfx__raw_spin_lock_irqsave+0x10/0x10<br />
? __virt_addr_valid+0x1dc/0x380<br />
kasan_report+0xbc/0xf0<br />
? __wake_up_common+0x114/0x160<br />
? __wake_up_common+0x114/0x160<br />
__wake_up_common+0x114/0x160<br />
? __pfx__raw_spin_lock_irqsave+0x10/0x10<br />
__wake_up+0x36/0x60<br />
virtio_pmem_host_ack+0x11d/0x3b0<br />
? sched_balance_domains+0x29f/0xb00<br />
? __pfx_virtio_pmem_host_ack+0x10/0x10<br />
? _raw_spin_lock_irqsave+0x98/0x100<br />
? __pfx__raw_spin_lock_irqsave+0x10/0x10<br />
vring_interrupt+0x1c9/0x5e0<br />
? __pfx_vp_interrupt+0x10/0x10<br />
vp_vring_interrupt+0x87/0x100<br />
? __pfx_vp_interrupt+0x10/0x10<br />
__handle_irq_event_percpu+0x17f/0x550<br />
? __pfx__raw_spin_lock+0x10/0x10<br />
handle_irq_event+0xab/0x1c0<br />
handle_fasteoi_irq+0x276/0xae0<br />
__common_interrupt+0x65/0x130<br />
common_interrupt+0x78/0xa0<br />
<br />
<br />
virtio_pmem_host_ack() wakes a request that has already been freed by the<br />
submitter.<br />
<br />
This happens when the request token is still reachable via the virtqueue,<br />
but virtio_pmem_flush() returns and frees it.<br />
<br />
Fix the token lifetime by refcounting struct virtio_pmem_request.<br />
virtio_pmem_flush() holds a submitter reference, and the virtqueue holds an<br />
extra reference once the request is queued. The completion path drops the<br />
virtqueue reference, and the submitter drops its reference before<br />
returning.
Impacto
Puntuación base 3.x
8.40
Gravedad 3.x
ALTA


