{"id":"CVE-2026-97941","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/slab: take n->list_lock in __slab_try_return_freelist() to avoid race\n\nCommit ba7425312607 (\"mm, slab: add an optimistic\n__slab_try_return_freelist()\") incorrectly a…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/slab: take n->list_lock in __slab_try_return_freelist() to avoid race\n\nCommit ba7425312607 (\"mm, slab: add an optimistic\n__slab_try_return_freelist()\") incorrectly a…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","vendor":"Linux","product":"Linux","affected":["Linux >= ba742531260782a2646bc031f9a12cafebc22594 < 570a6aaf6b52c6ec098f4811cdb52b1496f13d15","Linux >= ba742531260782a2646bc031f9a12cafebc22594 < 4a724bcf5d703e18957397914d79156fa2cf1174","Linux 7.2"],"published":"2026-09-25","updated":"2026-09-25","sourceUpdated":"2026-09-25T15:18:02.843","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-97941","references":[{"url":"https://git.kernel.org/stable/c/4a724bcf5d703e18957397914d79156fa2cf1174","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/570a6aaf6b52c6ec098f4811cdb52b1496f13d15","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-25T11:06:38.882Z","slug":"CVE-2026-97941","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nmm/slab: take n->list_lock in __slab_try_return_freelist() to avoid race\n\nCommit ba7425312607 (\"mm, slab: add an optimistic\n__slab_try_return_freelist()\") incorrectly assumed that nobody has freed\nan object to the slab as long as slab->freelist is NULL and cmpxchg\nsucceeds.\n\nHowever, as reported by Hyunwoo Kim [1], other CPUs might have freed\nan object to the slab, insert the slab to the partial list, then\nallocated an object from the slab, and be in the middle of removing\nthe slab from the list under n->list_lock.\n\nSince __refill_objects_node() puts the slab back on pc.slabs\noutside n->list_lock, it might insert the slab into that list while\nthe slab is concurrently being removed from n->partial.\nThis led to a list corruption [1]:\n\n  list_add corruption. next->prev should be prev\n  (ffff888100000248), but was dead000000000122.\n  (next=ffffea000416e410).\n  kernel BUG at lib/list_debug.c:29!\n  Oops: invalid opcode: 0000 [#1] SMP NOPTI\n  CPU: 1 UID: 65534 PID: 144 Comm: poc Not tainted\n  7.2.0-16172-gcf72cbb39da8-dirty #1 PREEMPT(lazy)\n  RIP: 0010:__list_add_valid_or_report+0x80/0xd0\n  ...\n  Call Trace:\n   alloc_from_new_slab+0x183/0x300\n   ___slab_alloc+0x31c/0x890\n   __kmalloc_noprof+0x3d4/0x800\n   lsm_blob_alloc+0x2d/0x50\n   security_msg_msg_alloc+0x26/0x90\n   load_msg+0x1aa/0x210\n   do_msgsnd+0x91/0x800\n   do_syscall_64+0x109/0x5d0\n   entry_SYSCALL_64_after_hwframe+0x77/0x7f\n  ...\n  Kernel panic - not syncing: Fatal exception\n\nThis is a classic ABA problem where cmpxchg succeeds but the state has\nchanged since __refill_objects_node() took the freelist from the slab.\n\nAs Vlastimil Babka mentioned [2], it should be rare to return more than\none slab (due to the racy read of slab->counters in\nget_partial_node_bulk()). Therefore, instead of introducing additional\ncomplexity, acquire and release n->list_lock twice in the worst case.\n\nReturn the slab directly to the partial list and hold n->list_lock\nacross the cmpxchg and add_partial(). This is similar to the initial\nversion of commit ba7425312607 [3]. This is enough to avoid the race as\nthe list manipulation is serialized by n->list_lock. While at it,\nbring back unlikely() hint now that the condition is unlikely.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":210946,"id":"CVE-2026-97941","ts":1790349117962,"field":"cvss","old":null,"new":"7.8"},{"seq":210945,"id":"CVE-2026-97941","ts":1790349117962,"field":"severity","old":"none","new":"high"}]}