{"id":"CVE-2026-93196","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvdimm: virtio_pmem: refcount requests for token lifetime\n\nKASAN reports slab-use-after-free in __wake_up_common():\nBUG: KASAN: slab-use-after-free in __wake_up_common+…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvdimm: virtio_pmem: refcount requests for token lifetime\n\nKASAN reports slab-use-after-free in __wake_up_common():\nBUG: KASAN: slab-use-after-free in __wake_up_common+…","severity":"high","cvss":8.4,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","vendor":"Linux","product":"Linux","affected":["Linux >= 6e84200c0a2994b991259d19450eee561029bf70 < be072a5d5e35f4bdf2da22f600b5d6dc6c5ff491","Linux >= 6e84200c0a2994b991259d19450eee561029bf70 < b1e740b9156621afd4c4aa66257f4dde8df1febe","Linux >= 6e84200c0a2994b991259d19450eee561029bf70 < e57140944b5a47a7fd5a142faab29a02af040bc8","Linux 5.3"],"published":"2026-09-17","updated":"2026-09-18","sourceUpdated":"2026-09-18T18:18:24.743","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-93196","references":[{"url":"https://git.kernel.org/stable/c/b1e740b9156621afd4c4aa66257f4dde8df1febe","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/be072a5d5e35f4bdf2da22f600b5d6dc6c5ff491","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e57140944b5a47a7fd5a142faab29a02af040bc8","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"epss":0.00161,"epssPercentile":0.05735,"ingestedAt":"2026-09-17T16:21:47.723Z","slug":"CVE-2026-93196","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnvdimm: virtio_pmem: refcount requests for token lifetime\n\nKASAN reports slab-use-after-free in __wake_up_common():\nBUG: KASAN: slab-use-after-free in __wake_up_common+0x114/0x160\nRead of size 8 at addr ffff88810fdcb710 by task swapper/0/0\n\nCPU: 0 UID: 0 PID: 0 Comm: swapper/0 Not tainted\n6.19.0-next-20260220-00006-g1eae5f204ec3 #4 PREEMPT(full)\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Arch Linux\n1.17.0-2-2 04/01/2014\nCall Trace:\n <IRQ>\n dump_stack_lvl+0x6d/0xb0\n print_report+0x170/0x4e2\n ? __pfx__raw_spin_lock_irqsave+0x10/0x10\n ? __virt_addr_valid+0x1dc/0x380\n kasan_report+0xbc/0xf0\n ? __wake_up_common+0x114/0x160\n ? __wake_up_common+0x114/0x160\n __wake_up_common+0x114/0x160\n ? __pfx__raw_spin_lock_irqsave+0x10/0x10\n __wake_up+0x36/0x60\n virtio_pmem_host_ack+0x11d/0x3b0\n ? sched_balance_domains+0x29f/0xb00\n ? __pfx_virtio_pmem_host_ack+0x10/0x10\n ? _raw_spin_lock_irqsave+0x98/0x100\n ? __pfx__raw_spin_lock_irqsave+0x10/0x10\n vring_interrupt+0x1c9/0x5e0\n ? __pfx_vp_interrupt+0x10/0x10\n vp_vring_interrupt+0x87/0x100\n ? __pfx_vp_interrupt+0x10/0x10\n __handle_irq_event_percpu+0x17f/0x550\n ? __pfx__raw_spin_lock+0x10/0x10\n handle_irq_event+0xab/0x1c0\n handle_fasteoi_irq+0x276/0xae0\n __common_interrupt+0x65/0x130\n common_interrupt+0x78/0xa0\n </IRQ>\n\nvirtio_pmem_host_ack() wakes a request that has already been freed by the\nsubmitter.\n\nThis happens when the request token is still reachable via the virtqueue,\nbut virtio_pmem_flush() returns and frees it.\n\nFix the token lifetime by refcounting struct virtio_pmem_request.\nvirtio_pmem_flush() holds a submitter reference, and the virtqueue holds an\nextra reference once the request is queued. The completion path drops the\nvirtqueue reference, and the submitter drops its reference before\nreturning.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":46,"depthScoreParts":{"impact":46.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":207421,"id":"CVE-2026-93196","ts":1789757345939,"field":"cvss","old":null,"new":"8.4"},{"seq":207420,"id":"CVE-2026-93196","ts":1789757345939,"field":"severity","old":"none","new":"high"}]}