Description
In the Linux kernel, the following vulnerability has been resolved:

crash_dump: release keyring reference at the correct time

restore_dm_crypt_keys_to_thread_keyring() gets a reference to the user
keyring before restoring the saved dm-crypt keys.

The same keyring reference is then passed to add_key_to_keyring() for each
saved key, but add_key_to_keyring() drops that reference on every call.
This is only balanced when exactly one key is restored. With multiple
keys, the keyring reference is dropped too many times and may trigger a
refcount underflow or use-after-free.

When more than five keys are restored, a refcount underflow/use-after-free
warning can be triggered.

The early error paths after lookup_user_key() also return without dropping
the keyring reference.

Keep ownership of the keyring reference in
restore_dm_crypt_keys_to_thread_keyring(), drop it once on all exit paths,
and make add_key_to_keyring() only use the reference without consuming it.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel crash or potential remote code execution
Action: Immediate Patch
AI Analysis

Impact

The likely impact, as inferred from the description, is that the underflow may cause a kernel crash or create a use‑after‑free that could be exploited, but the advisory does not confirm a successful code execution path. The vulnerability involves a reference count underflow and potential use‑after‑free in the Linux kernel's keyring handling. When restore_dm_crypt_keys_to_thread_keyring() obtains a reference to a user keyring and passes it to add_key_to_keyring() for many keys, the reference is dropped an extra time. If more than five keys are restored, this can result in a refcount underflow, triggering a warning or a kernel crash. A use‑after‑free of the keyring object could allow an attacker to execute arbitrary code or crash the system, compromising confidentiality, integrity, and availability.

Affected Systems

Affected systems are machines running the Linux kernel. No specific kernel versions are enumerated in the advisory, so all kernel releases that contain the old implementation are potentially vulnerable unless patched. The problem is present in the core kernel code that handles dm‑crypt key restoration.

Risk and Exploitability

Based on the description, it is inferred that the attack vector is local privileged or an environment that can manipulate dm‑crypt keyring contents. The EPSS score is less than 1 %, indicating a very low probability of exploitation at present, and the flaw is not listed in CISA’s KEV catalog. Without an official patch cited, the likelihood of a publicly available exploit remains low. The vulnerability would require the attacker to trigger dm‑crypt key restoration with multiple keys, which is probable only in environments that use disk encryption and have the ability to influence the keyring contents, implying a likely local privileged attack vector.

Generated by OpenCVE AI on September 19, 2026 at 08:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a Linux kernel version that includes the crash_dump keyring handling fix.
  • If an upgrade is not immediately possible, restrict dm‑crypt operations to restore a single key at a time or disable automatic key restoration when multiple keys are present.
  • Monitor kernel logs for "refcount underflow" or keyring‑related crash messages and apply local restrictions on keyring usage or dm‑crypt key counts.

Generated by OpenCVE AI on September 19, 2026 at 08:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: crash_dump: release keyring reference at the correct time restore_dm_crypt_keys_to_thread_keyring() gets a reference to the user keyring before restoring the saved dm-crypt keys. The same keyring reference is then passed to add_key_to_keyring() for each saved key, but add_key_to_keyring() drops that reference on every call. This is only balanced when exactly one key is restored. With multiple keys, the keyring reference is dropped too many times and may trigger a refcount underflow or use-after-free. When more than five keys are restored, a refcount underflow/use-after-free warning can be triggered. The early error paths after lookup_user_key() also return without dropping the keyring reference. Keep ownership of the keyring reference in restore_dm_crypt_keys_to_thread_keyring(), drop it once on all exit paths, and make add_key_to_keyring() only use the reference without consuming it.
Title crash_dump: release keyring reference at the correct time
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:11:17.136Z

Reserved: 2026-09-17T16:02:15.085Z

Link: CVE-2026-93106

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:04.953

Modified: 2026-09-17T17:18:04.953

Link: CVE-2026-93106

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T19:45:11Z

Weaknesses