7.5

CVE-2026-89549

sunrpc: route to a populated pool in svc_pool_for_cpu()

In the Linux kernel, the following vulnerability has been resolved:

sunrpc: route to a populated pool in svc_pool_for_cpu()

svc_set_num_threads() spreads the requested threads evenly across the
service's pools (base = nrservs / sv_nrpools).  When a service runs
fewer threads than it has pools -- e.g. an nfsd configured with fewer
threads than the host has NUMA nodes while running in "pernode" or
"percpu" mode -- the trailing pools are left with no threads at all.

svc_xprt_enqueue() selects a pool from the CPU servicing the transport,
queues the transport on that pool's sp_xprts, and only wakes a thread
from the same pool.  Each thread services exclusively its own pool, so a
transport that lands on a threadless pool is enqueued on sp_xprts and
never picked up: the connection hangs indefinitely.

Have svc_pool_for_cpu() skip pools that currently have no threads,
falling back to the next populated pool.  This trades NUMA locality for
a guarantee that the work is actually serviced.  sp_nrthreads is only
updated under the service mutex; the lockless read here is a best-effort
routing hint, so annotate it with data_race().
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version bfd241600a3b0db4fe43c859f1460d0a958d924a
Version < 9accc25e5af0bac8479f6054e674b2c593c45281
Status affected
Version bfd241600a3b0db4fe43c859f1460d0a958d924a
Version < 6f66d38e2a6c78d48723ea17ad86135ec80ca24b
Status affected
Version bfd241600a3b0db4fe43c859f1460d0a958d924a
Version < d79d7b9e8acbb53e2d60f6b24afc13e2f15e691f
Status affected
Version bfd241600a3b0db4fe43c859f1460d0a958d924a
Version < edb20e8c03aebacb409968c99d046f509c6c485a
Status affected
Version bfd241600a3b0db4fe43c859f1460d0a958d924a
Version < 011479cf9a7657d4a3e7cc42a784ac63df594170
Status affected
Version bfd241600a3b0db4fe43c859f1460d0a958d924a
Version < 9d04d64ad192439835ed9884d767353061c3ed6f
Status affected
Version bfd241600a3b0db4fe43c859f1460d0a958d924a
Version < 8f766d2d0b4dabf54f8b35812df2b4f481d13316
Status affected
Version bfd241600a3b0db4fe43c859f1460d0a958d924a
Version < f6310491c4cdb88af73aa551ec9df1f10a90c709
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 2.6.19
Status affected
Version 0
Version < 2.6.19
Status unaffected
Version <= 5.10.*
Version 5.10.270
Status unaffected
Version <= 5.15.*
Version 5.15.221
Status unaffected
Version <= 6.1.*
Version 6.1.188
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.109
Status unaffected
Version <= 6.18.*
Version 6.18.50
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.63% 0.482
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/011479cf9a7657d4a3e7cc42a784ac63df594170
https://git.kernel.org/stable/c/9d04d64ad192439835ed9884d767353061c3ed6f
https://git.kernel.org/stable/c/8f766d2d0b4dabf54f8b35812df2b4f481d13316
https://git.kernel.org/stable/c/f6310491c4cdb88af73aa551ec9df1f10a90c709
https://git.kernel.org/stable/c/6f66d38e2a6c78d48723ea17ad86135ec80ca24b
https://git.kernel.org/stable/c/9accc25e5af0bac8479f6054e674b2c593c45281
https://git.kernel.org/stable/c/d79d7b9e8acbb53e2d60f6b24afc13e2f15e691f
https://git.kernel.org/stable/c/edb20e8c03aebacb409968c99d046f509c6c485a