CVE-2026-93216
📛 CVE Title
mm/page_owner: use memcg_data snapshot to avoid TOCTOU in print_page_owner_memcg()
Description
In the Linux kernel, the following vulnerability has been resolved: mm/page_owner: use memcg_data snapshot to avoid TOCTOU in print_page_owner_memcg() print_page_owner_memcg() reads page->memcg_data via READ_ONCE() at the start to guard against tail pages and NULL data. However, it later re-reads page->memcg_data locklessly in two places: 1: page_memcg_check(page) 2: PageMemcgKmem(page) (via folio_memcg_kmem(), which includes VM_BUG_ON assertions for tail pages and MEMCG_DATA_OBJEXTS) If the page is concurrently freed and reallocated as a THP tail page or slab page between these calls, the VM_BUG_ON assertions can trigger on CONFIG_DEBUG_VM=y builds, crashing the kernel. Fix both TOCTOU issues by using the memcg_data snapshot throughout.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- Linux
- CVSS severity
- —
- CVSS score
- —
- CVSS vector
- —
- Effective score
- no score available from CNA, NVD, or AI yet
- CWE(s)
- —
- Reserved
- 2026-09-17
- Published
- 2026-09-24 15:10 UTC
- Last updated
- 2026-09-24 15:10 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/93xxx/CVE-2026-93216.json
NVD / KEV / EPSS data refreshed 2026-09-25 04:32 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
AI-forensic CVSS estimate
Used only when a CVE has no official CVSS from its CNA or NVD. An LLM estimates the v3.1 base score from the description; a HIGH/CRITICAL estimate promotes the CVE to a Threat.
No AI estimate yet — it runs automatically once NVD has been checked, or click the button above.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2026-85945 - Assigner
- Linux
- Published
- Sep 24, 2026, 3:10:38 PM
- Updated
- Sep 24, 2026, 3:10:38 PM
- EUVD base score
- 0.0 / 10
- EUVD-reported EPSS
- 0.0000
- Vendors
- Linux
- Products
-
Linux (patch: 0)Linux (fcf8935832b86d3437f00e732c6d0d4d2819d6a9 <90f095b816e25c6a9e4446d299bac5007fdcb3df)Linux (5.18)Linux (fcf8935832b86d3437f00e732c6d0d4d2819d6a9 <46761406e14381dc35f498c247a87565b87ea2ef)Linux (patch: 7.2.4)Linux (patch: 7.3-rc1)
- Aliases
-
GHSA-rrh5-8w69-2q6j
ENISA description: In the Linux kernel, the following vulnerability has been resolved: mm/page_owner: use memcg_data snapshot to avoid TOCTOU in print_page_owner_memcg() print_page_owner_memcg() reads page->memcg_data via READ_ONCE() at the start to guard against tail pages and NULL data. However, it later re-reads page->memcg_data locklessly in two places: 1: page_memcg_check(page) 2: PageMemcgKmem(page) (via folio_memcg_kmem(), which includes VM_BUG_ON assertions for tail pages and MEMCG_DATA_OBJEXTS) If the page is concurrently freed and reallocated as a THP tail page or slab page between these calls, the VM_BUG_ON assertions can trigger on CONFIG_DEBUG_VM=y builds, crashing the kernel. Fix both TOCTOU issues by using the memcg_data snapshot throughout.
Affected products (2)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Linux | Linux |
fcf8935832b86d3437f00e732c6d0d4d2819d6a9 (affected),
fcf8935832b86d3437f00e732c6d0d4d2819d6a9 (affected)
|
— |
| Linux | Linux |
5.18 (affected),
0 (unaffected),
7.2.4 (unaffected),
7.3-rc1 (unaffected)
|
— |
Vendor references (2)
References embedded in the original CVE record by the assigning CNA.
Web references (0)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
No web references attached yet.
Remediations (10)
-
web:blog.checkpoint.com
CVE - 2026 -93616 is a newly discovered zero-day vulnerability in Security Management, and a fix is available now as part of this advisory. Fixes are available for both vulnerabilities. Customers running affected versions should install the applicable fixes immediately. Affected versions and remediation instructions are detailed below.
2026-09-25 10:45 UTC -
web:labs.beazley.security
Executive Summary On September 22 nd, 2026 , Check Point released emergency hotfixes for a critical vulnerability in its Management Server products and confirmed that attackers had already exploited it as a zero-day. Tracked as CVE - 2026 -93616, the vulnerability allows an unauthenticated remote attacker to traverse outside the intended directory in the Management web service and upload scripts ...
2026-09-25 10:45 UTC -
web:securityaffairs.com
Check Point fixes an actively exploited flaw that lets unauthenticated attackers upload and run scripts on vulnerable Security Management Servers. Check Point has released emergency hotfixes for CVE - 2026 -93616, a critical path traversal flaw in its Security Management Server. Attackers can abuse the ...
2026-09-25 10:45 UTC -
web:securityarsenal.com
CISA has added CVE - 2026 -93616 to the KEV catalog: an unauthenticated path traversal in Check Point Security Management, Log Server, and SmartEvent enabling arbitrary script execution. Patch and hunt now.
2026-09-25 10:45 UTC -
web:securityonline.info
A critical exploited Check Point Management vulnerability ( CVE - 2026 -93616) allows attackers to execute arbitrary scripts. Secure your servers now.
2026-09-25 10:45 UTC -
web:socprime.com
Can CVE - 2026 -93616 still affect me in 2026 ? Yes. Systems running vulnerable Check Point releases remain exposed until the dedicated security fix or applicable Jumbo Hotfix is installed. The vulnerability has already been exploited in real attacks, so organizations should patch immediately and investigate systems that were exposed before ...
2026-09-25 10:45 UTC -
web:www.esecurityplanet.com
Check Point patched CVE - 2026 -93616 after zero-day attacks. See affected Security Management versions, fixed builds, mitigations , and defender actions.
2026-09-25 10:45 UTC -
web:www.hexnode.com
Why Patching Check Point CVE - 2026 -93616 Is Only the First Step Installing the applicable Check Point fix remediates CVE - 2026 -93616, but it does not establish whether exploitation occurred before remediation . Check Point separately directs customers to its hunting guidance and indicators of compromise to check for compromise.
2026-09-25 10:45 UTC -
web:www.rescana.com
Check Point Security Gateway and Management CVE - 2026 -85102 and CVE - 2026 -93616 are critical CVSS 9.8 flaws added to CISA KEV on September 22, 2026 . Patch both planes and run forensic triage.
2026-09-25 10:45 UTC -
web:www.wiz.io
Understand the critical aspects of CVE - 2026 -93616 with a detailed vulnerability assessment, exploitation potential, affected technologies, and remediation guidance.
2026-09-25 10:45 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2026-93216.json.
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"mm/page_owner.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "46761406e14381dc35f498c247a87565b87ea2ef",
"status": "affected",
"version": "fcf8935832b86d3437f00e732c6d0d4d2819d6a9",
"versionType": "git"
},
{
"lessThan": "90f095b816e25c6a9e4446d299bac5007fdcb3df",
"status": "affected",
"version": "fcf8935832b86d3437f00e732c6d0d4d2819d6a9",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"mm/page_owner.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.18"
},
{
"lessThan": "5.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.4",
"versionStartIncluding": "5.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "5.18",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/page_owner: use memcg_data snapshot to avoid TOCTOU in print_page_owner_memcg()\n\nprint_page_owner_memcg() reads page->memcg_data via READ_ONCE() at the\nstart to guard against tail pages and NULL data. However, it later\nre-reads page->memcg_data locklessly in two places:\n\n1: page_memcg_check(page)\n\n2: PageMemcgKmem(page) (via folio_memcg_kmem(), which includes\n VM_BUG_ON assertions for tail pages and MEMCG_DATA_OBJEXTS)\n\nIf the page is concurrently freed and reallocated as a THP tail page or\nslab page between these calls, the VM_BUG_ON assertions can trigger on\nCONFIG_DEBUG_VM=y builds, crashing the kernel.\n\nFix both TOCTOU issues by using the memcg_data snapshot throughout."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-24T15:10:38.702Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/46761406e14381dc35f498c247a87565b87ea2ef"
},
{
"url": "https://git.kernel.org/stable/c/90f095b816e25c6a9e4446d299bac5007fdcb3df"
}
],
"title": "mm/page_owner: use memcg_data snapshot to avoid TOCTOU in print_page_owner_memcg()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-93216",
"datePublished": "2026-09-24T15:10:38.702Z",
"dateReserved": "2026-09-17T16:02:15.093Z",
"dateUpdated": "2026-09-24T15:10:38.702Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}