7.8

CVE-2026-89986

mm/mempolicy: fix sleeping allocation in alloc_pages_bulk_weighted_interleave()

In the Linux kernel, the following vulnerability has been resolved:

mm/mempolicy: fix sleeping allocation in alloc_pages_bulk_weighted_interleave()

syzbot reported a sleeping function called from invalid context splat in
bucket_table_alloc().

When rhashtable_insert_slow() rehashes the table under rcu_read_lock(), it
calls bucket_table_alloc(..., GFP_ATOMIC | __GFP_NOWARN).  If the bucket
table allocation uses vmalloc, __vmalloc_node_range_noprof() invokes
vm_area_alloc_pages() -> alloc_pages_bulk_mempolicy_noprof() with the
passed GFP_ATOMIC flags.

If the current task has an MPOL_WEIGHTED_INTERLEAVE mempolicy,
alloc_pages_bulk_weighted_interleave() is called and currently hardcodes
GFP_KERNEL when allocating the temporary weights array, triggering a
might_alloc() splat in atomic/RCU contexts.

Pass the gfp flags (masked with GFP_RECLAIM_MASK to strip page-allocator
zone modifiers like __GFP_HIGHMEM) received by
alloc_pages_bulk_weighted_interleave() to kmalloc() instead of hardcoding
GFP_KERNEL.  Since the weights buffer is immediately initialized in full,
kmalloc() is sufficient.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version fa3bea4e1f8202d787709b7e3654eb0a99aed758
Version < bcb3d0c867ee40dc48e9c085bf328fbc679b6656
Status affected
Version fa3bea4e1f8202d787709b7e3654eb0a99aed758
Version < 0ceda28f371df9e0bbdaa29214f71fe8298f23d8
Status affected
Version fa3bea4e1f8202d787709b7e3654eb0a99aed758
Version < 2943f1f4b7f2816177060eb9f551f2e6d8b629ba
Status affected
Version fa3bea4e1f8202d787709b7e3654eb0a99aed758
Version < 540e583b66d6402bf556fde5e53c817a54c1afe5
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.9
Status affected
Version 0
Version < 6.9
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.51
Status unaffected
Version <= 7.2.*
Version 7.2.5
Status unaffected
Version <= *
Version 7.3-rc2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.059
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/bcb3d0c867ee40dc48e9c085bf328fbc679b6656
https://git.kernel.org/stable/c/0ceda28f371df9e0bbdaa29214f71fe8298f23d8
https://git.kernel.org/stable/c/2943f1f4b7f2816177060eb9f551f2e6d8b629ba
https://git.kernel.org/stable/c/540e583b66d6402bf556fde5e53c817a54c1afe5