---
id: CVE-2026-93196
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  nvdimm: virtio_pmem: refcount requests for token lifetime

  KASAN reports slab-use-after-free in __wake_up_common():
  BUG: KASAN: slab-use-after-free in __wake_up_common+…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  nvdimm: virtio_pmem: refcount requests for token lifetime

  KASAN reports slab-use-after-free in __wake_up_common():
  BUG: KASAN: slab-use-after-free in __wake_up_common+…
severity: high
cvss: 8.4
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 6e84200c0a2994b991259d19450eee561029bf70 <
    be072a5d5e35f4bdf2da22f600b5d6dc6c5ff491
  - >-
    Linux >= 6e84200c0a2994b991259d19450eee561029bf70 <
    b1e740b9156621afd4c4aa66257f4dde8df1febe
  - >-
    Linux >= 6e84200c0a2994b991259d19450eee561029bf70 <
    e57140944b5a47a7fd5a142faab29a02af040bc8
  - Linux 5.3
published: '2026-09-17'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T18:18:24.743'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-93196'
references:
  - url: 'https://git.kernel.org/stable/c/b1e740b9156621afd4c4aa66257f4dde8df1febe'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/be072a5d5e35f4bdf2da22f600b5d6dc6c5ff491'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/e57140944b5a47a7fd5a142faab29a02af040bc8'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
epss: 0.00161
epssPercentile: 0.05734
ingestedAt: '2026-09-17T16:21:47.723Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

nvdimm: virtio_pmem: refcount requests for token lifetime

KASAN reports slab-use-after-free in __wake_up_common():
BUG: KASAN: slab-use-after-free in __wake_up_common+0x114/0x160
Read of size 8 at addr ffff88810fdcb710 by task swapper/0/0

CPU: 0 UID: 0 PID: 0 Comm: swapper/0 Not tainted
6.19.0-next-20260220-00006-g1eae5f204ec3 #4 PREEMPT(full)
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Arch Linux
1.17.0-2-2 04/01/2014
Call Trace:
 <IRQ>
 dump_stack_lvl+0x6d/0xb0
 print_report+0x170/0x4e2
 ? __pfx__raw_spin_lock_irqsave+0x10/0x10
 ? __virt_addr_valid+0x1dc/0x380
 kasan_report+0xbc/0xf0
 ? __wake_up_common+0x114/0x160
 ? __wake_up_common+0x114/0x160
 __wake_up_common+0x114/0x160
 ? __pfx__raw_spin_lock_irqsave+0x10/0x10
 __wake_up+0x36/0x60
 virtio_pmem_host_ack+0x11d/0x3b0
 ? sched_balance_domains+0x29f/0xb00
 ? __pfx_virtio_pmem_host_ack+0x10/0x10
 ? _raw_spin_lock_irqsave+0x98/0x100
 ? __pfx__raw_spin_lock_irqsave+0x10/0x10
 vring_interrupt+0x1c9/0x5e0
 ? __pfx_vp_interrupt+0x10/0x10
 vp_vring_interrupt+0x87/0x100
 ? __pfx_vp_interrupt+0x10/0x10
 __handle_irq_event_percpu+0x17f/0x550
 ? __pfx__raw_spin_lock+0x10/0x10
 handle_irq_event+0xab/0x1c0
 handle_fasteoi_irq+0x276/0xae0
 __common_interrupt+0x65/0x130
 common_interrupt+0x78/0xa0
 </IRQ>

virtio_pmem_host_ack() wakes a request that has already been freed by the
submitter.

This happens when the request token is still reachable via the virtqueue,
but virtio_pmem_flush() returns and frees it.

Fix the token lifetime by refcounting struct virtio_pmem_request.
virtio_pmem_flush() holds a submitter reference, and the virtqueue holds an
extra reference once the request is queued. The completion path drops the
virtqueue reference, and the submitter drops its reference before
returning.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
