7.8
CVE-2026-90046
- EPSS 0.14%
- Veröffentlicht 16.09.2026 10:33:43
- Zuletzt bearbeitet 28.09.2026 23:10:00
- Erkennungen
mm/page_alloc: don't spin_trylock() in NMI on UP
In the Linux kernel, the following vulnerability has been resolved:
mm/page_alloc: don't spin_trylock() in NMI on UP
Patch series "mm/page_alloc: fixes for free_pages_nolock() on RT/UP".
Pre-existing bugs found by Sashiko during review of this other series:
https://lore.kernel.org/all/20260703-alloc-trylock-v5-0-c87b714e19d3@google.com/
I have not reproduced these bugs, and I suspect there is no real-world
user that is affected by them.
This patch (of 2):
As noted in can_spin_trylock(), using this is unsafe in this context.
commit 620b46ed6ae17 ("mm/page_alloc: return NULL early from
alloc_frozen_pages_nolock() in NMI on UP") fixed this on the alloc side
but missed the free side.
Impact: If BPF programs using these features in NMI (probably tracing) are
present on non-SMP builds this might crash the kernel and is probably
exploitable by local attackers for privilege escalation.Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
8c57b687e8331eb80e302a2c528b18b966a9ac7a
Version <
06c76d3c389ff504052f64b1acee44651bd847fa
Status
affected
Version
8c57b687e8331eb80e302a2c528b18b966a9ac7a
Version <
68a069b407303e71db371df85036101e8ff59280
Status
affected
Version
8c57b687e8331eb80e302a2c528b18b966a9ac7a
Version <
3105ae628fb785d48b49256468be4f21a7b3cfc0
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
6.15
Status
affected
Version
0
Version <
6.15
Status
unaffected
Version <=
6.18.*
Version
6.18.51
Status
unaffected
Version <=
7.2.*
Version
7.2.5
Status
unaffected
Version <=
*
Version
7.3-rc1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.14% | 0.04 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
https://git.kernel.org/stable/c/06c76d3c389ff504052f64b1acee44651bd847fa
https://git.kernel.org/stable/c/68a069b407303e71db371df85036101e8ff59280
https://git.kernel.org/stable/c/3105ae628fb785d48b49256468be4f21a7b3cfc0