« Volver al listado

CVE-2026-90046

Estado: RecibidaAlta (7.8)—

In the Linux kernel, the following vulnerability has been resolved:

mm/page_alloc: don't spin_trylock() in NMI on UP

Patch series "mm/page_alloc: fixes for free_pages_nolock() on RT/UP".

Pre-existing bugs found by Sashiko during review of this other series: https://lore.kernel.org/all/20260703-alloc-trylock-v5-0-c87b714e19d3@google.com/

I have not reproduced these bugs, and I suspect there is no real-world user that is affected by them.

This patch (of 2):

As noted in can_spin_trylock(), using this is unsafe in this context. commit 620b46ed6ae17 ("mm/page_alloc: return NULL early from alloc_frozen_pages_nolock() in NMI on UP") fixed this on the alloc side but missed the free side.

Leer descripción completaMostrar menos

Impact: If BPF programs using these features in NMI (probably tracing) are present on non-SMP builds this might crash the kernel and is probably exploitable by local attackers for privilege escalation.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad local en kernel (AV:L/PR:L) explotable para escalada de privilegios. El crash del kernel en UP/NMI permite DoS y potencial ejecución con privilegios elevados por atacante local.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90046",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "8c57b687e8331eb80e302a2c528b18b966a9ac7a",
              "lessThan": "06c76d3c389ff504052f64b1acee44651bd847fa",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8c57b687e8331eb80e302a2c528b18b966a9ac7a",
              "lessThan": "68a069b407303e71db371df85036101e8ff59280",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8c57b687e8331eb80e302a2c528b18b966a9ac7a",
              "lessThan": "3105ae628fb785d48b49256468be4f21a7b3cfc0",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "mm/page_alloc.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.15"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.15",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.18.51",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "mm/page_alloc.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-16T11:17:17.867",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/06c76d3c389ff504052f64b1acee44651bd847fa",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/3105ae628fb785d48b49256468be4f21a7b3cfc0",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/68a069b407303e71db371df85036101e8ff59280",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/page_alloc: don't spin_trylock() in NMI on UP\n\nPatch series \"mm/page_alloc: fixes for free_pages_nolock() on RT/UP\".\n\nPre-existing bugs found by Sashiko during review of this other series:\nhttps://lore.kernel.org/all/20260703-alloc-trylock-v5-0-c87b714e19d3@google.com/\n\nI have not reproduced these bugs, and I suspect there is no real-world\nuser that is affected by them.\n\n\nThis patch (of 2):\n\nAs noted in can_spin_trylock(), using this is unsafe in this context. \ncommit 620b46ed6ae17 (\"mm/page_alloc: return NULL early from\nalloc_frozen_pages_nolock() in NMI on UP\") fixed this on the alloc side\nbut missed the free side.\n\nImpact: If BPF programs using these features in NMI (probably tracing) are\npresent on non-SMP builds this might crash the kernel and is probably\nexploitable by local attackers for privilege escalation."
    },
    {
      "lang": "es",
      "value": "En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:\n\nmm/page_alloc: no usar spin_trylock() en NMI en UP\n\nSerie de parches 'mm/page_alloc: correcciones para free_pages_nolock() en RT/UP'.\n\nErrores preexistentes encontrados por Sashiko durante la revisión de esta otra serie:\nHTTPS://lore.kernel.org/all/20260703-alloc-trylock-v5-0-c87b714e19d3@google.com/\n\nNo he reproducido estos errores, y sospecho que no hay ningún usuario del mundo real afectado por ellos.\n\nEste parche (de 2):\n\nComo se señala en can_spin_trylock(), usar esto es inseguro en este contexto.\nEl commit 620b46ed6ae17 ('mm/page_alloc: devolver NULL temprano desde alloc_frozen_pages_nolock() en NMI en UP') solucionó esto en el lado de asignación, pero pasó por alto el lado de liberación.\n\nImpacto: Si los programas BPF que utilizan estas características en NMI (probablemente rastreo) están presentes en compilaciones no SMP, esto podría bloquear el kernel y probablemente sea explotable por atacantes locales para la escalada de privilegios."
    }
  ],
  "lastModified": "2026-09-28T23:10:00.143",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}