CVE-2026-74337
In the Linux kernel, the following vulnerability has been resolved:
bpf: Fix NMI/tracepoint re-entry deadlock on lru locks
NMI and tracepoint BPF programs can re-enter the per-CPU or global LRU lock that bpf_lru_pop_free()/push_free() already hold on the same CPU, AA-deadlocking. Lockdep reports "inconsistent {INITIAL USE} -> {IN-NMI}" on &l->lock (syzbot c69a0a2c816716f1e0d5) and "possible recursive locking detected" on &loc_l->lock (syzbot 18b26edb69b2e19f3b33).
Prior trylock and rqspinlock based fixes (see links) were nacked because compromised on reliability.
This patch converts every LRU lock site to rqspinlock_t and adds a recovery path for some failure windows to avoid node leaks.
Leer descripción completaMostrar menos
Failure recovery:
- Cross-CPU steal: skip the victim's locked loc_l, try next CPU.
Detalles técnicos trazas, registros y código del informe original
- *_pop_free top-level: return NULL; prealloc_lru_pop() already treats that as no-free-element (-ENOMEM). - Post-steal local lock fail: publish stolen node to lockless per-CPU free_llist; next pop on this CPU picks it up. - push_free fail: mark node pending_free=1. __local_list_flush(), __local_list_pop_pending() reclaim the node from pending_list. __bpf_lru_list_shrink_inactive() reclaims the node from inactive list. Nodes from active list are reclaimed by __bpf_lru_list_shrink() or after __bpf_lru_list_rotate_active() demotes it to the inactive.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 10
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-74337",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "3a08c2fd763450a927d1130de078d6f9e74944fb",
"lessThan": "8b0510cc3a4a000d4ed1a56cd96231f3d3ba94c5",
"versionType": "git"
},
{
"status": "affected",
"version": "3a08c2fd763450a927d1130de078d6f9e74944fb",
"lessThan": "440a2fdbb40608d55a7b11f2be53592a3785131d",
"versionType": "git"
},
{
"status": "affected",
"version": "3a08c2fd763450a927d1130de078d6f9e74944fb",
"lessThan": "89edbdfc5d0308cef57b71359331de5c4ddbf763",
"versionType": "git"
}
],
"programFiles": [
"kernel/bpf/bpf_lru_list.c",
"kernel/bpf/bpf_lru_list.h"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "4.10"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "4.10",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"kernel/bpf/bpf_lru_list.c",
"kernel/bpf/bpf_lru_list.h"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-08-15T06:22:34.623",
"references": [
{
"url": "https://git.kernel.org/stable/c/440a2fdbb40608d55a7b11f2be53592a3785131d",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/89edbdfc5d0308cef57b71359331de5c4ddbf763",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/8b0510cc3a4a000d4ed1a56cd96231f3d3ba94c5",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix NMI/tracepoint re-entry deadlock on lru locks\n\nNMI and tracepoint BPF programs can re-enter the per-CPU or global\nLRU lock that bpf_lru_pop_free()/push_free() already hold on the\nsame CPU, AA-deadlocking. Lockdep reports \"inconsistent\n{INITIAL USE} -> {IN-NMI}\" on &l->lock (syzbot c69a0a2c816716f1e0d5)\nand \"possible recursive locking detected\" on &loc_l->lock (syzbot\n18b26edb69b2e19f3b33).\n\nPrior trylock and rqspinlock based fixes (see links) were nacked\nbecause compromised on reliability.\n\nThis patch converts every LRU lock site to rqspinlock_t and adds a\nrecovery path for some failure windows to avoid node leaks.\n\nFailure recovery:\n\n - *_pop_free top-level: return NULL; prealloc_lru_pop() already\n treats that as no-free-element (-ENOMEM).\n\n - Cross-CPU steal: skip the victim's locked loc_l, try next CPU.\n\n - Post-steal local lock fail: publish stolen node to lockless\n per-CPU free_llist; next pop on this CPU picks it up.\n\n - push_free fail: mark node pending_free=1. __local_list_flush(),\n __local_list_pop_pending() reclaim the node from pending_list.\n __bpf_lru_list_shrink_inactive() reclaims the node from inactive\n list. Nodes from active list are reclaimed by __bpf_lru_list_shrink()\n or after __bpf_lru_list_rotate_active() demotes it to the inactive."
}
],
"lastModified": "2026-08-17T06:19:28.157",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}