CVE-2026-23195

Source
https://cve.org/CVERecord?id=CVE-2026-23195
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-23195.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-23195
Downstream
Published
2026-02-14T16:27:21.621Z
Modified
2026-04-02T13:12:13.612468Z
Summary
cgroup/dmem: avoid pool UAF
Details

In the Linux kernel, the following vulnerability has been resolved:

cgroup/dmem: avoid pool UAF

An UAF issue was observed:

BUG: KASAN: slab-use-after-free in pagecounteruncharge+0x65/0x150 Write of size 8 at addr ffff888106715440 by task insmod/527

CPU: 4 UID: 0 PID: 527 Comm: insmod 6.19.0-rc7-next-20260129+ #11 Tainted: [O]=OOTMODULE Call Trace: <TASK> dumpstacklvl+0x82/0xd0 kasanreport+0xca/0x100 kasancheckrange+0x39/0x1c0 pagecounteruncharge+0x65/0x150 dmemcgroupuncharge+0x1f/0x260

Allocated by task 527:

Freed by task 0:

The buggy address belongs to the object at ffff888106715400 which belongs to the cache kmalloc-512 of size 512 The buggy address is located 64 bytes inside of freed 512-byte region [ffff888106715400, ffff888106715600)

The buggy address belongs to the physical page:

Memory state around the buggy address: ffff888106715300: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc ffff888106715380: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc

ffff888106715400: fa fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb ^ ffff888106715480: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb ffff888106715500: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb

The issue occurs because a pool can still be held by a caller after its associated memory region is unregistered. The current implementation frees the pool even if users still hold references to it (e.g., before uncharge operations complete).

This patch adds a reference counter to each pool, ensuring that a pool is only freed when its reference count drops to zero.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/23xxx/CVE-2026-23195.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
b168ed458ddecc176f3b9a1f4bcd83d7a4541c14
Fixed
d3081353acaa6a638dcf75726066ea556a2de8d5
Fixed
99a2ef500906138ba58093b9893972a5c303c734

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-23195.json"