CVE-2024-43892 is a race condition in the Linux kernel memory control group (memcg) subsystem's mem_cgroup_idr ID registry. Although ID allocation and replacement are synchronized through cgroup_mutex, removal was not protected against concurrent execution. Concurrent idr_remove() calls, or races between removal and allocation or replacement, can leave a valid memory cgroup absent from the registry or assign one ID to multiple valid memory cgroups. When one memory cgroup sharing an ID is offlined, it can clean up list_lru state required by the others, leading to kernel crashes during subsequent list_lru operations.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Linux kernel memory-control-group (memcg) concurrency flaw in access to mem_cgroup_idr that can cause list_lru-related kernel crashes/denial of service. The referenced Google COS sys-kernel/lakitu-kernel-6_1 update fixes it in version 18244.236.5 or later.
Linux kernel memory-control-group flaw caused by insufficient protection for concurrent access to mem_cgroup_idr.
Linux kernel memory-control-group concurrent-access flaw.
Linux kernel memory-control-group concurrent-access race flaw.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.