7.8
CVE-2026-74594
- EPSS 0.18%
- Veröffentlicht 22.08.2026 16:16:31
- Zuletzt bearbeitet 25.08.2026 06:18:34
- CVE-Watchlists
- Unerledigt
sched/psi: Shut down rtpoll_timer in psi_cgroup_free()
In the Linux kernel, the following vulnerability has been resolved:
sched/psi: Shut down rtpoll_timer in psi_cgroup_free()
psi_schedule_rtpoll_work() is called locklessly from the scheduler hotpath
and can race psi_trigger_destroy() taking down the last rtpoll trigger under
rtpoll_trigger_lock:
psi_schedule_rtpoll_work() psi_trigger_destroy()
rcu_read_lock();
task = rcu_dereference(rtpoll_task);
rcu_assign_pointer(rtpoll_task, NULL);
timer_delete(&rtpoll_timer);
mod_timer(&rtpoll_timer, ...);
rcu_read_unlock();
synchronize_rcu();
kthread_stop(task_to_destroy);
The group can then be freed with the re-armed timer still pending, and
poll_timer_fn() runs on freed memory.
461daba06bdc ("psi: eliminate kthread_worker from psi trigger scheduling
mechanism") deleted the timer synchronously after the synchronize_rcu(),
which prevented this but raced trigger creation instead: the deletion could
cancel the timer that a new trigger set armed during the grace period and,
as creation also reinitialized the timer at the time, corrupt it.
8f91efd870ea ("psi: Fix race between psi_trigger_create/destroy") moved the
initialization into group_init() and the deletion into the locked section,
trading the creation races for the window above.
Neither placement in the destruction path works. A pending timer firing
while the group is alive is harmless though. poll_timer_fn() just wakes the
rtpoll waitqueue and doesn't re-arm itself. Bind the timer to the group's
lifetime instead and shut it down in psi_cgroup_free(). Nothing can arm it
by then. timer_shutdown_sync() because the timer is never armed again.Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
6bfcb6178925b1fd28c102e53d403091b8f49396
Version <
4addb102154b7cf6e2310ccbe20c3c08619e520d
Status
affected
Version
8f91efd870ea5d8bc10b0fcc9740db51cd4c0c83
Version <
894a9300d7fb2e2951da92e565ae6de7ddfb0a69
Status
affected
Version
8f91efd870ea5d8bc10b0fcc9740db51cd4c0c83
Version <
1e5ca82eee59caca6988f9d6e859786aab8a5fa0
Status
affected
Version
8f91efd870ea5d8bc10b0fcc9740db51cd4c0c83
Version <
310b5a537a78c358a4cd244bd767c1a517a05459
Status
affected
Version
8f91efd870ea5d8bc10b0fcc9740db51cd4c0c83
Version <
806fcff98c1d7cb3c1dc0015e55ebdbe819e6b08
Status
affected
Version
8f91efd870ea5d8bc10b0fcc9740db51cd4c0c83
Version <
8037c5b2b2a447df52542f4d8535895d837bdcbd
Status
affected
Version
8f91efd870ea5d8bc10b0fcc9740db51cd4c0c83
Version <
611e7821c4f83a671455658797336faecc3a5196
Status
affected
Version
8f91efd870ea5d8bc10b0fcc9740db51cd4c0c83
Version <
5457025fa8ca3c0d2732109513de839e3e797190
Status
affected
Version
e1e5e263bbe0e6e9c3db36aa48a3c8acf546fa49
Status
affected
Version
979965c33f734a1666af67900408f997ac669c23
Status
affected
Version
5.10.50
Version <
5.10.266
Status
affected
Version
5.12.17
Version <
5.13
Status
affected
Version
5.13.2
Version <
5.14
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
5.14
Status
affected
Version
0
Version <
5.14
Status
unaffected
Version <=
5.10.*
Version
5.10.266
Status
unaffected
Version <=
5.15.*
Version
5.15.217
Status
unaffected
Version <=
6.1.*
Version
6.1.183
Status
unaffected
Version <=
6.6.*
Version
6.6.152
Status
unaffected
Version <=
6.12.*
Version
6.12.104
Status
unaffected
Version <=
6.18.*
Version
6.18.45
Status
unaffected
Version <=
7.1.*
Version
7.1.9
Status
unaffected
Version <=
*
Version
7.2
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.18% | 0.072 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
https://git.kernel.org/stable/c/1e5ca82eee59caca6988f9d6e859786aab8a5fa0
https://git.kernel.org/stable/c/310b5a537a78c358a4cd244bd767c1a517a05459
https://git.kernel.org/stable/c/4addb102154b7cf6e2310ccbe20c3c08619e520d
https://git.kernel.org/stable/c/5457025fa8ca3c0d2732109513de839e3e797190
https://git.kernel.org/stable/c/611e7821c4f83a671455658797336faecc3a5196
https://git.kernel.org/stable/c/8037c5b2b2a447df52542f4d8535895d837bdcbd
https://git.kernel.org/stable/c/806fcff98c1d7cb3c1dc0015e55ebdbe819e6b08
https://git.kernel.org/stable/c/894a9300d7fb2e2951da92e565ae6de7ddfb0a69