AZL-102893

See a problem?
Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-102893.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-102893
Upstream
Published
2026-09-17T17:18:12Z
Modified
2026-09-18T14:16:35Z
Summary
CVE-2026-93172 affecting package kernel 6.6.150.1-1
Details

In the Linux kernel, the following vulnerability has been resolved:

mm/mm_init: handle alloc_percpu failure in free_area_init_core_hotplug

We miss a failed allocation check for pgdat->per_cpu_nodestats, which results in a NULL deref when we offset into the per-cpu area.

Propagate -ENOMEM up the stack and leave per_cpu_nodestats pointing at boot_nodestats so a later online can retry the allocation.

hotadd_init_pgdat() returns NULL on failure, which __try_online_node() already maps to -ENOMEM.

On failure nothing needs to be unwound:

  • the node is never marked online
  • per_cpu_nodestats is left pointing at boot_nodestats
  • __add_memory_resource() cleans up pending memblock resources
  • later online attempts retry the per_cpu_nodestats allocation
References

Affected packages

Azure Linux:3 / kernel

Package

Name
kernel
Purl
pkg:rpm/azure-linux/kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
6.6.150.1-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-102893.json"