CVE-2026-93262

Source
https://cve.org/CVERecord?id=CVE-2026-93262
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93262.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-93262
Downstream
Published
2026-09-24T15:52:01Z
Modified
2026-09-25T03:48:54Z
Summary
md/raid5-ppl: fix use-after-free in ppl_do_flush()
Details

In the Linux kernel, the following vulnerability has been resolved:

md/raid5-ppl: fix use-after-free in ppl_do_flush()

The loop in ppl_do_flush() continues iterating after calling ppl_io_unit_finished(), touching io->pending_flushes and leading to a use-after-free.

Add a break statement to stop the loop once io is freed.

Database specific
{
    "cna_assigner":  "Linux",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93262.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
1532d9e87e8b2377f12929f9e40724d5fbe6ecc5
Fixed
cf01f9413565e86673baf927291a088b6975692b
Fixed
e7505842f1329ece90cb9ea0db87772aeca44052
Fixed
b5123bf667ac29ddd8106f9ca7cc01316513ae66
Fixed
e77c80670f2c2bf491da9b173931e1da4677c23a
Fixed
8914c3d40870f16429a326e97e4016bedc6ede4c
Fixed
455b56209f9615c3902dcc398dd867abb5ade3ab
Fixed
fcf21df7d3c50c8ebeb0757df5d21b02dcae4218
Fixed
371f7a1b392edc8b7cf449cc7713179b588f2d0e

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93262.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.16.0
Fixed
5.10.270
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.221
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93262.json"