s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

CVE-2026-93216

📛 CVE Title

mm/page_owner: use memcg_data snapshot to avoid TOCTOU in print_page_owner_memcg()

Description

In the Linux kernel, the following vulnerability has been resolved: mm/page_owner: use memcg_data snapshot to avoid TOCTOU in print_page_owner_memcg() print_page_owner_memcg() reads page->memcg_data via READ_ONCE() at the start to guard against tail pages and NULL data. However, it later re-reads page->memcg_data locklessly in two places: 1: page_memcg_check(page) 2: PageMemcgKmem(page) (via folio_memcg_kmem(), which includes VM_BUG_ON assertions for tail pages and MEMCG_DATA_OBJEXTS) If the page is concurrently freed and reallocated as a THP tail page or slab page between these calls, the VM_BUG_ON assertions can trigger on CONFIG_DEBUG_VM=y builds, crashing the kernel. Fix both TOCTOU issues by using the memcg_data snapshot throughout.

Overview

State
PUBLISHED
Assigner (CNA)
Linux
CVSS severity
—
CVSS score
—
CVSS vector
—
Effective score
no score available from CNA, NVD, or AI yet
CWE(s)
—
Reserved
2026-09-17
Published
2026-09-24 15:10 UTC
Last updated
2026-09-24 15:10 UTC
Source
https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/93xxx/CVE-2026-93216.json

NVD / KEV / EPSS data refreshed 2026-09-25 04:32 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.

AI-forensic CVSS estimate

Used only when a CVE has no official CVSS from its CNA or NVD. An LLM estimates the v3.1 base score from the description; a HIGH/CRITICAL estimate promotes the CVE to a Threat.

No AI estimate yet — it runs automatically once NVD has been checked, or click the button above.

European Union Vulnerability Database ENISA EUVD

ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.

EUVD ID
EUVD-2026-85945
Assigner
Linux
Published
Sep 24, 2026, 3:10:38 PM
Updated
Sep 24, 2026, 3:10:38 PM
EUVD base score
0.0 / 10
EUVD-reported EPSS
0.0000
Vendors
Linux
Products
Linux (patch: 0)
Linux (fcf8935832b86d3437f00e732c6d0d4d2819d6a9 <90f095b816e25c6a9e4446d299bac5007fdcb3df)
Linux (5.18)
Linux (fcf8935832b86d3437f00e732c6d0d4d2819d6a9 <46761406e14381dc35f498c247a87565b87ea2ef)
Linux (patch: 7.2.4)
Linux (patch: 7.3-rc1)
Aliases
GHSA-rrh5-8w69-2q6j

ENISA description: In the Linux kernel, the following vulnerability has been resolved: mm/page_owner: use memcg_data snapshot to avoid TOCTOU in print_page_owner_memcg() print_page_owner_memcg() reads page->memcg_data via READ_ONCE() at the start to guard against tail pages and NULL data. However, it later re-reads page->memcg_data locklessly in two places: 1: page_memcg_check(page) 2: PageMemcgKmem(page) (via folio_memcg_kmem(), which includes VM_BUG_ON assertions for tail pages and MEMCG_DATA_OBJEXTS) If the page is concurrently freed and reallocated as a THP tail page or slab page between these calls, the VM_BUG_ON assertions can trigger on CONFIG_DEBUG_VM=y builds, crashing the kernel. Fix both TOCTOU issues by using the memcg_data snapshot throughout.

EUVD references (2)

Affected products (2)

VendorProductVersionsPlatforms
Linux Linux fcf8935832b86d3437f00e732c6d0d4d2819d6a9 (affected), fcf8935832b86d3437f00e732c6d0d4d2819d6a9 (affected) —
Linux Linux 5.18 (affected), 0 (unaffected), 7.2.4 (unaffected), 7.3-rc1 (unaffected) —

Vendor references (2)

References embedded in the original CVE record by the assigning CNA.

Web references (0)

DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.

No web references attached yet.

Remediations (10)

  • web:blog.checkpoint.com

    CVE - 2026 -93616 is a newly discovered zero-day vulnerability in Security Management, and a fix is available now as part of this advisory. Fixes are available for both vulnerabilities. Customers running affected versions should install the applicable fixes immediately. Affected versions and remediation instructions are detailed below.

    2026-09-25 10:45 UTC
  • web:labs.beazley.security

    Executive Summary On September 22 nd, 2026 , Check Point released emergency hotfixes for a critical vulnerability in its Management Server products and confirmed that attackers had already exploited it as a zero-day. Tracked as CVE - 2026 -93616, the vulnerability allows an unauthenticated remote attacker to traverse outside the intended directory in the Management web service and upload scripts ...

    2026-09-25 10:45 UTC
  • web:securityaffairs.com

    Check Point fixes an actively exploited flaw that lets unauthenticated attackers upload and run scripts on vulnerable Security Management Servers. Check Point has released emergency hotfixes for CVE - 2026 -93616, a critical path traversal flaw in its Security Management Server. Attackers can abuse the ...

    2026-09-25 10:45 UTC
  • web:securityarsenal.com

    CISA has added CVE - 2026 -93616 to the KEV catalog: an unauthenticated path traversal in Check Point Security Management, Log Server, and SmartEvent enabling arbitrary script execution. Patch and hunt now.

    2026-09-25 10:45 UTC
  • web:securityonline.info

    A critical exploited Check Point Management vulnerability ( CVE - 2026 -93616) allows attackers to execute arbitrary scripts. Secure your servers now.

    2026-09-25 10:45 UTC
  • web:socprime.com

    Can CVE - 2026 -93616 still affect me in 2026 ? Yes. Systems running vulnerable Check Point releases remain exposed until the dedicated security fix or applicable Jumbo Hotfix is installed. The vulnerability has already been exploited in real attacks, so organizations should patch immediately and investigate systems that were exposed before ...

    2026-09-25 10:45 UTC
  • web:www.esecurityplanet.com

    Check Point patched CVE - 2026 -93616 after zero-day attacks. See affected Security Management versions, fixed builds, mitigations , and defender actions.

    2026-09-25 10:45 UTC
  • web:www.hexnode.com

    Why Patching Check Point CVE - 2026 -93616 Is Only the First Step Installing the applicable Check Point fix remediates CVE - 2026 -93616, but it does not establish whether exploitation occurred before remediation . Check Point separately directs customers to its hunting guidance and indicators of compromise to check for compromise.

    2026-09-25 10:45 UTC
  • web:www.rescana.com

    Check Point Security Gateway and Management CVE - 2026 -85102 and CVE - 2026 -93616 are critical CVSS 9.8 flaws added to CISA KEV on September 22, 2026 . Patch both planes and run forensic triage.

    2026-09-25 10:45 UTC
  • web:www.wiz.io

    Understand the critical aspects of CVE - 2026 -93616 with a detailed vulnerability assessment, exploitation potential, affected technologies, and remediation guidance.

    2026-09-25 10:45 UTC

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

Raw JSON

The full cvelistV5 record. Download as CVE-2026-93216.json.

{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "mm/page_owner.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "46761406e14381dc35f498c247a87565b87ea2ef",
              "status": "affected",
              "version": "fcf8935832b86d3437f00e732c6d0d4d2819d6a9",
              "versionType": "git"
            },
            {
              "lessThan": "90f095b816e25c6a9e4446d299bac5007fdcb3df",
              "status": "affected",
              "version": "fcf8935832b86d3437f00e732c6d0d4d2819d6a9",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "mm/page_owner.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.18"
            },
            {
              "lessThan": "5.18",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "7.2.*",
              "status": "unaffected",
              "version": "7.2.4",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.2.4",
                  "versionStartIncluding": "5.18",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.3-rc1",
                  "versionStartIncluding": "5.18",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/page_owner: use memcg_data snapshot to avoid TOCTOU in print_page_owner_memcg()\n\nprint_page_owner_memcg() reads page->memcg_data via READ_ONCE() at the\nstart to guard against tail pages and NULL data.  However, it later\nre-reads page->memcg_data locklessly in two places:\n\n1: page_memcg_check(page)\n\n2: PageMemcgKmem(page) (via folio_memcg_kmem(), which includes\n   VM_BUG_ON assertions for tail pages and MEMCG_DATA_OBJEXTS)\n\nIf the page is concurrently freed and reallocated as a THP tail page or\nslab page between these calls, the VM_BUG_ON assertions can trigger on\nCONFIG_DEBUG_VM=y builds, crashing the kernel.\n\nFix both TOCTOU issues by using the memcg_data snapshot throughout."
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-24T15:10:38.702Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/46761406e14381dc35f498c247a87565b87ea2ef"
        },
        {
          "url": "https://git.kernel.org/stable/c/90f095b816e25c6a9e4446d299bac5007fdcb3df"
        }
      ],
      "title": "mm/page_owner: use memcg_data snapshot to avoid TOCTOU in print_page_owner_memcg()",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-93216",
    "datePublished": "2026-09-24T15:10:38.702Z",
    "dateReserved": "2026-09-17T16:02:15.093Z",
    "dateUpdated": "2026-09-24T15:10:38.702Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}