PT-2026-38934 · Linux · Linux Kernel

Published

2026-05-08

·

Updated

2026-05-15

·

CVE-2026-43292

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description When CONFIG PAGE OWNER is enabled, freeing KASAN shadow pages during vmalloc cleanup triggers expensive stack unwinding that acquires RCU read locks. Processing a large purge list without rescheduling can cause a task to hold the CPU for extended periods, leading to RCU stalls and potential Out-Of-Memory (OOM) conditions. This occurs in the purge vmap node() and kasan release vmalloc node() functions, where iterating through numerous vmap area entries and freeing associated shadow pages creates an unbounded RCU critical section because each call to kasan release vmalloc() triggers save stack() for page owner tracking.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

CVE-2026-43292

Affected Products

Linux Kernel