Skip to content
Noroxi
CVE-2026-68090· NVD / CVE Program· CNA Linux

debugobjects: Plug race against a concurrent OOM disable

In the Linux kernel, the following vulnerability has been resolved: debugobjects: Plug race against a concurrent OOM disable syzbot reported a puzzling splat: WARNING: kernel/time/hrtimer.c:443 at stub_timer+0xa/0x20 stub_timer() is installed as timer callback function in hrtimer_fixup_assert_init(), which is invoked when debug_object_assert_init() can't find a shadow object. In that case debug objects emits a warning about it before invoking the fixup. Though the provided console log lacks this warning and instead has the following a few seconds before the splat: ODEBUG: Out of memory. ODEBUG disabled So the object was looked up in debug_object_assert_init() and the lookup failed due a concurrent out of memory situation which disabled debug objects and freed the shadow objects: debug_object_assert_init() if (!debug_objects_enabled) return; obj = alloc(); if (!obj) { // Out of memory debug_objects_enabled = false; free_objects(); obj = lookup_or_alloc(); // The lookup failed because the other side // removed the objects, so this returns // an error code as the object in question // is not statically initialized if (!IS_ERR_OR_NULL(obj)) return; if (!obj) { debug_oom(); return; } print(...) if (!debug_objects_enabled) return; fixup(...) The debug object splat is skipped because debug_objects_enabled is false, but the fixup callback is invoked unconditionally, which makes the timer disfunctional. This is only a problem in debug_object_assert_init() and debug_object_activate() as both have to handle statically initialized objects and therefore must handle the error pointer return case gracefully. All other places only handle the found/not found case and the NULL pointer return is a signal for OOM. Otherwise they get a valid shadow object. Plug the hole by checking whether debug objects are still enabled before invoking the print and fixup function in those two places.

—No exploit Fix available
Published
Aug 10, 2026
Updated
Aug 17, 2026
EPSS
0.2% · 11th percentile
CWE
—
Follow this CVE

Sign in to follow · You’ll be notified if a followed record enters KEV, gets an exploit or is updated.

Report tools

JSON

Action score

0

Monitor

Low priority for now.

CVSS
0 / 40 · —
CISA KEV
0 / 30 · Not listed
EPSS
0 / 30 · 0.2%

Noroxi analysis

No Noroxi analysis for this record yet

We don't hand-write analysis for the hundreds of thousands of vulnerabilities in the database; that wouldn't be honest. For notable, high-impact vulnerabilities our team writes the mechanism, detection and remediation steps.

We use this product, ask for help

Affected systems

—

Versions reported by the vendor

Affected version ranges reported by the assigning authority (Linux). Independent of NVD's CPE analysis and usually ahead of it.

  • Linux Linux

    • 3.3affected
    • b84d435cc228e87951f3bbabf6cc4a5f25d5fb16 and later · before 2d5e320b7ab9b25229ac4331541964a58b5e1d29affected · git
    • b84d435cc228e87951f3bbabf6cc4a5f25d5fb16 and later · before 203a965bf2ab43130778d8214fb0c3c8c2d19cdfaffected · git
    • b84d435cc228e87951f3bbabf6cc4a5f25d5fb16 and later · before 23da32e88627e63e0864f59f4c63a2dc0ab851a3affected · git
    • b84d435cc228e87951f3bbabf6cc4a5f25d5fb16 and later · before d663fbf28b2eebe665bb9cf828d7d528e5a8707eaffected · git
    • b84d435cc228e87951f3bbabf6cc4a5f25d5fb16 and later · before e2e255d07723c330dded8e576ce28a8d23a692ceaffected · git
    • b84d435cc228e87951f3bbabf6cc4a5f25d5fb16 and later · before c00164c9e7fa6145886ad666806cb5347895de5caffected · git
    • b84d435cc228e87951f3bbabf6cc4a5f25d5fb16 and later · before 1f4f02b336c3be125c8fcf87df73db2e0e028b8baffected · git
    • b84d435cc228e87951f3bbabf6cc4a5f25d5fb16 and later · before b81dde13cc163450dcb402dcc915ef13ba241e01affected · git
    • before 3.3not affected · semver

Package-level exposure

OSV and GitHub Advisory data: ecosystem, package and range. SBOM matching uses this table.

EcosystemPackageAffected rangeFix
Debian:12linuxbefore 6.1.180-16.1.180-1
Debian:13linuxbefore 6.12.96-16.12.96-1
Debian:14linuxbefore 7.1.4-17.1.4-1

Other highest-scoring records for the same primary product.

  • CVE-2026-74705udp: fix potential use-after-free in tunnel segmentation
    40Plan
  • CVE-2026-74612veth: fix skb length accounting after XDP frag adjustment
    40Plan
  • CVE-2026-74475vxlan: use neigh_ha_snapshot() in route_shortcircuit()
    40Plan
  • CVE-2026-74309vdpa/octeon_ep: fix IRQ-to-ring mapping in interrupt handler
    40Plan
  • CVE-2026-74280crypto: marvell/octeontx - fix DMA cleanup using wrong loop index
    40Plan
  • CVE-2026-74279crypto: cavium/cpt - fix DMA cleanup using wrong loop index
    40Plan

Remediation

Which version to upgrade to

Fix versions compiled from the vendor, package registries and Microsoft. Verify the vendor's note before upgrading.

Product / packageFixed versionSource
Linux Linux1f4f02b336c3be125c8fcf87df73db2e0e028b8bVendor (CNA)
Linux Linux203a965bf2ab43130778d8214fb0c3c8c2d19cdfVendor (CNA)
Linux Linux23da32e88627e63e0864f59f4c63a2dc0ab851a3Vendor (CNA)
Linux Linux2d5e320b7ab9b25229ac4331541964a58b5e1d29Vendor (CNA)
Linux Linuxb81dde13cc163450dcb402dcc915ef13ba241e01Vendor (CNA)
Linux Linuxc00164c9e7fa6145886ad666806cb5347895de5cVendor (CNA)
Linux Linuxd663fbf28b2eebe665bb9cf828d7d528e5a8707eVendor (CNA)
Linux Linuxe2e255d07723c330dded8e576ce28a8d23a692ceVendor (CNA)
azl3 kernel 6.6.143.1-1 on Azure Linux 3.06.6.150.1-1 · CBL-Mariner ReleasesMicrosoft (MSRC)
debian:linux6.1.180-1 · Debian:12Package registry (OSV)

Exploit status

No known public exploit

No public exploit has been observed yet. That doesn't mean you're safe, only that the bar is a little higher.

Research context

For pentesters and researchers: attack profile, score disagreement, timeline, patch commits, credits, variant and chain candidates, bug bounty scope. All derived from existing data; no exploit code.

Timeline

From publication to today: proof of concept, Metasploit module, CISA KEV and fix record. Dates are as reported by the sources.

No dated events beyond publication.

EPSS, last 120 days

FIRST EPSS daily score; only changes of 0.01 or more are recorded (step chart).

Patch and commit links

Commit, PR and diff links among the references. A starting point for patch-diffing and variant hunting; fixes, not exploits.

No commit or PR link among the references.

Finders, reporters and analysts named in the CNA record. Click a name for that researcher’s other records.

No credits in the CNA record.

Variant candidates

Same product, same weakness class, within 18 months. If the patch missed the root cause, the sibling bug is here.

No nightly-computed relations.

Chain candidates

An authentication bypass and a privilege-requiring bug in the same product, published close together: combined they may become an unauthenticated path.

—

Bug bounty scope

No known public program.

Source: bounty-targets-data (public HackerOne, Bugcrowd, Intigriti, YesWeHack listings).

National notice (Türkiye Cybersecurity Directorate / USOM)

Official security notices citing this record; remediation advice is on the agency's page.

All national notices →

Technical details

No CVSS vector for this record, so attack conditions can't be derived.

Weakness class (CWE)

—

Attack context

MITRE CAPEC attack patterns and ATT&CK techniques for this weakness class (CWE). A starting point for detection rules and threat hunting.

MITRE has no CAPEC/ATT&CK mapping for this CWE.

Change log

  1. Fix✗ → ✓

For records you follow, these changes also arrive as notifications. →

References

All records