{"id":"AZL-103559","summary":"CVE-2026-93240 affecting package kernel 6.6.157.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nmemcg: make the v1 soft limit knob inert\n\nThe v1 soft limit has been deprecated since v6.12 and nobody has reported\ndepending on it.  Start the removal by decoupling the interface from the\nimplementation: keep memory.soft_limit_in_bytes, but ignore writes to it\nand always report the maximum value on read similar to what\nmemory.kmem.limit_in_bytes already does.\n\nWrites are still parsed, so malformed input keeps returning -EINVAL.  The\nknob now also behaves the same everywhere: it used to return -EOPNOTSUPP\non PREEMPT_RT, where soft limit reclaim has always been disabled.\n\nThis also fixes the syzbot report linked below.  Soft limit reclaim is the\nonly caller that runs shrink_lruvec() from kswapd against a specific\nmemcg, so it is the only way to reach lru_gen_shrink_lruvec() and in turn\nset_mm_walk(), which warns when called from kswapd.","modified":"2026-09-25T14:15:43.349858255Z","published":"2026-09-24T16:17:19Z","upstream":["CVE-2026-93240"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93240"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.157.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-103559.json"}}],"schema_version":"1.9.0"}