CVE-2026-93106
CVE CVE-2026-93106EUVD EUVD-2026-82214Published 2026-09-17T16:11:17.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: crash_dump: release keyring reference at the correct time restore_dm_crypt_keys_to_thread_keyring() gets a reference to the user keyring before restoring the saved dm-crypt keys. The same keyring reference is then passed to add_key_to_keyring() for each saved key, but add_key_to_keyring() drops that reference on every call. This is only balanced when exactly one key is restored. With multiple keys, the keyring reference is dropped too many times and may trigger a refcount underflow or use-after-free. When more than five keys are restored, a refcount underflow/use-after-free warning can be triggered. The early error paths after lookup_user_key() also return without dropping the keyring reference. Keep ownership of the keyring reference in restore_dm_crypt_keys_to_thread_keyring(), drop it once on all exit paths, and make add_key_to_keyring() only use the reference without consuming it.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 62f17d9df6924cf805de5ae970470615c1c8d9f2 <b0f7343a002f9c8b8378011f60482c76f3216dfd; patch: 7.2.6; patch: 6.18.52; 62f17d9df6924cf805de5ae970470615c1c8d9f2 <ed566979f99c5516cad45a76ae25e2a4928ffb67; patch: 7.3-rc1; 6.16; patch: 0; 62f17d9df6924cf805de5ae970470615c1c8d9f2 <ada2e5a44e99113e08ad9b7b71396c6c572204da
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.