CVE-2026-53153
published 2026-06-25CVE-2026-53153: In the Linux kernel, the following vulnerability has been resolved: mm/list_lru: drain before clearing xarray entry on reparent memcg_reparent_list_lrus()…
PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.10%
1.0th percentile
In the Linux kernel, the following vulnerability has been resolved:
mm/list_lru: drain before clearing xarray entry on reparent
memcg_reparent_list_lrus() clears the dying memcg's xarray entry with
xas_store(&xas, NULL) before reparenting its per-node lists into the
parent. This opens a window where a concurrent list_lru_del() arriving
for the dying memcg sees xa_load() == NULL, walks to the parent in
lock_list_lru_of_memcg(), takes the parent's per-node lock, and calls
list_del_init() on an item still physically linked on the dying memcg's
list.
If another in-flight thread holds the dying memcg's per-node lock at the
same moment (another list_lru_del, or a list_lru_walk_one running an
isolate callback), both threads modify ->next/->prev pointers on the same
physical list under different locks. Adjacent items can corrupt each
other's links.
Fix it by reversing the order: reparent each per-node list and mark the
child's list lru dead and then clear the xarray entry. Any concurrent
list_lru op that finds the still-set xarray entry either takes the dying
memcg's per-node lock (synchronizing with the drain) or sees LONG_MIN and
walks to the parent, where the items now live.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux | — | — |
| linux | linux | >= fb56fdf8b9a2f7397f8a83dce50189f3f0cf71af < c19ff4351214f059349788e13e70e74325831ff6 | c19ff4351214f059349788e13e70e74325831ff6 |
| linux | linux | >= fb56fdf8b9a2f7397f8a83dce50189f3f0cf71af < 2b66496d794e98f7aeec7688573051f22ec40bac | 2b66496d794e98f7aeec7688573051f22ec40bac |
| linux | linux | >= fb56fdf8b9a2f7397f8a83dce50189f3f0cf71af < 98733f3f0becb1ae0701d021c1748e974e5fa55c | 98733f3f0becb1ae0701d021c1748e974e5fa55c |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 6.13 < 6.18.36 | 6.18.36 |
| linux | linux_kernel | >= 6.19 < 7.0.13 | 7.0.13 |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Linux Kernel up to 6.18.35/7.0.12 mm memcg_reparent_list_lrus Next improper synchronization (Nessus ID 323591 / WID-SEC-2026-2077)
vuldb·2026-06-29·CVSS 7.8
CVE-2026-53153 [HIGH] Linux Kernel up to 6.18.35/7.0.12 mm memcg_reparent_list_lrus Next improper synchronization (Nessus ID 323591 / WID-SEC-2026-2077)
A vulnerability was found in Linux Kernel up to 6.18.35/7.0.12. It has been rated as critical. This affects the function memcg_reparent_list_lrus of the component mm. The manipulation of the argument Next leads to improper synchronization.
This vulnerability is listed as CVE-2026-53153. The attack must be carried out from within the local network. There is no available exploit.
Upgrading the affected component is advised.
GHSA
In the Linux kernel, the following vulnerability has been resolved: mm/list_lru: drain before clearing xarray entry on reparent memcg_reparent_list_lrus() clears the dying memcg's xarray entry with
ghsa_unreviewed·2026-06-25
CVE-2026-53153 In the Linux kernel, the following vulnerability has been resolved: mm/list_lru: drain before clearing xarray entry on reparent memcg_reparent_list_lrus() clears the dying memcg's xarray entry with
In the Linux kernel, the following vulnerability has been resolved:
mm/list_lru: drain before clearing xarray entry on reparent
memcg_reparent_list_lrus() clears the dying memcg's xarray entry with
xas_store(&xas, NULL) before reparenting its per-node lists into the
parent. This opens a window where a concurrent list_lru_del() arriving
for the dying memcg sees xa_load() == NULL, walks to the parent in
lock_list_lru_of_memcg(), takes the parent's per-node lock, and calls
list_del_init() on an item still physically linked on the dying memcg's
list.
If another in-flight thread holds the dying memcg's per-node lock at the
same moment (another list_lru_del, or a list_lru_walk_one running an
isolate callback), both threads modify ->next/->prev pointers on the same
physical list under differen
Red Hat
kernel: mm/list_lru: drain before clearing xarray entry on reparent
vendor_redhat·2026-06-25·CVSS 7.0
CVE-2026-53153 [HIGH] CWE-820 kernel: mm/list_lru: drain before clearing xarray entry on reparent
kernel: mm/list_lru: drain before clearing xarray entry on reparent
In the Linux kernel, the following vulnerability has been resolved:
mm/list_lru: drain before clearing xarray entry on reparent
memcg_reparent_list_lrus() clears the dying memcg's xarray entry with
xas_store(&xas, NULL) before reparenting its per-node lists into the
parent. This opens a window where a concurrent list_lru_del() arriving
for the dying memcg sees xa_load() == NULL, walks to the parent in
lock_list_lru_of_memcg(), takes the parent's per-node lock, and calls
list_del_init() on an item still physically linked on the dying memcg's
list.
If another in-flight thread holds the dying memcg's per-node lock at the
same moment (another list_lru_del, or a list_lru_walk_one running an
isolate callback), both threads modi
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/2b66496d794e98f7aeec7688573051f22ec40bachttps://git.kernel.org/stable/c/98733f3f0becb1ae0701d021c1748e974e5fa55chttps://git.kernel.org/stable/c/c19ff4351214f059349788e13e70e74325831ff6https://access.redhat.com/security/cve/CVE-2026-53153https://bugzilla.redhat.com/show_bug.cgi?id=2492790https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53153.json
2026-06-25
Published