---
id: CVE-2026-93099
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  fs/resctrl: Fix UAF from worker threads when domains are removed

  The mbm_handle_overflow() and cqm_handle_limbo() workers read event counters
  and may sleep while doing…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  fs/resctrl: Fix UAF from worker threads when domains are removed

  The mbm_handle_overflow() and cqm_handle_limbo() workers read event counters
  and may sleep while doing…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 24247aeeabe99eab13b798ccccc2dec066dd6f07 <
    b86dbfe4583bf134932a6cc45bf25b12c10a0b2f
  - >-
    Linux >= 24247aeeabe99eab13b798ccccc2dec066dd6f07 <
    2566b5cd6a275c124e8f154fef6e815f92ec8d5c
  - Linux 4.14
published: '2026-09-17'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T17:18:04.110'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-93099'
references:
  - url: 'https://git.kernel.org/stable/c/2566b5cd6a275c124e8f154fef6e815f92ec8d5c'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/b86dbfe4583bf134932a6cc45bf25b12c10a0b2f'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-17T16:21:47.757Z'
epss: 0.00189
epssPercentile: 0.08806
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

fs/resctrl: Fix UAF from worker threads when domains are removed

The mbm_handle_overflow() and cqm_handle_limbo() workers read event counters
and may sleep while doing so. They are scheduled via delayed_work embedded in
struct rdt_l3_mon_domain. Architecture allocates and frees these domains from
CPU hotplug callbacks under cpus_write_lock(), and the workers acquire
cpus_read_lock() to keep the domain alive across their access.

A use-after-free can occur when a worker is blocked waiting for
cpus_read_lock() while the hotplug core holds cpus_write_lock(): the
architecture frees the rdt_l3_mon_domain that contains the worker's
work_struct. When the worker unblocks, the container_of() it performs on the
embedded work pointer dereferences freed memory.

Drop cpus_read_lock() from the workers and instead drain pending and in-flight
work synchronously before the architecture can free the domain.  Since
architecture offlines the domain under cpus_write_lock() after it has been
unlinked from the RCU list and a grace period has elapsed, no new work can be
scheduled. The cancel only needs to wait out existing work.  Drop
rdtgroup_mutex during CPU offline around cancel_delayed_work_sync() so that
a worker waiting on the mutex can complete before re-pinning the work on
a different CPU.

When offlining a CPU the architecture may iterate over resources in any order.
For example, the MBA control domain may be offlined before or after
a corresponding L3 monitor domain. Ensure that resctrl fs cancels the workers
no matter what order the architecture offlines the domains.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
