« Volver al listado

CVE-2026-90305

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

ARM: 9483/1: select HAVE_POSIX_CPU_TIMERS_TASK_WORK

Commit c6e61c06d606 ("ARM: 9463/1: Allow to enable RT") enabled PREEMPT_RT on ARM but did not select HAVE_POSIX_CPU_TIMERS_TASK_WORK. This leaves CONFIG_POSIX_CPU_TIMERS_TASK_WORK disabled, so CPU timers expire in hard IRQ context.

On PREEMPT_RT this makes run_posix_cpu_timers() take the sleeping sighand->siglock:

ARM handles TIF_NOTIFY_RESUME on all return-to-user paths, including v7-M. ARM32 KVM host support was removed by commit 541ad0150ca4 ("arm: Remove 32bit KVM host support"), so the select need not be conditional on KVM.

Leer descripción completaMostrar menos

Select it to defer POSIX CPU timer expiry to task context.

Reproduced with setrlimit(RLIMIT_CPU, ...) and a busy loop. The same path is used by setitimer(ITIMER_PROF or ITIMER_VIRTUAL) and POSIX CPU timers created with timer_create().

Detalles técnicos trazas, registros y código del informe original
  BUG: sleeping function called from invalid context at spinlock_rt.c:48
    rt_spin_lock from lock_task_sighand
    lock_task_sighand from run_posix_cpu_timers
    run_posix_cpu_timers from update_process_times

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90305",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "c6e61c06d6061750597e79c598acb5dead44c35b",
              "lessThan": "8de56782d6e5ba7a9f8c820342dccde65502f93f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c6e61c06d6061750597e79c598acb5dead44c35b",
              "lessThan": "8a58a41100ea377e978d99600ec24a9bd0273662",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "arch/arm/Kconfig"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7.1"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "7.1",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "arch/arm/Kconfig"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:17:28.163",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/8a58a41100ea377e978d99600ec24a9bd0273662",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8de56782d6e5ba7a9f8c820342dccde65502f93f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nARM: 9483/1: select HAVE_POSIX_CPU_TIMERS_TASK_WORK\n\nCommit c6e61c06d606 (\"ARM: 9463/1: Allow to enable RT\") enabled PREEMPT_RT\non ARM but did not select HAVE_POSIX_CPU_TIMERS_TASK_WORK. This leaves\nCONFIG_POSIX_CPU_TIMERS_TASK_WORK disabled, so CPU timers expire in hard\nIRQ context.\n\nOn PREEMPT_RT this makes run_posix_cpu_timers() take the sleeping\nsighand->siglock:\n\n  BUG: sleeping function called from invalid context at spinlock_rt.c:48\n    rt_spin_lock from lock_task_sighand\n    lock_task_sighand from run_posix_cpu_timers\n    run_posix_cpu_timers from update_process_times\n\nARM handles TIF_NOTIFY_RESUME on all return-to-user paths, including v7-M.\nARM32 KVM host support was removed by commit 541ad0150ca4 (\"arm: Remove\n32bit KVM host support\"), so the select need not be conditional on KVM.\n\nSelect it to defer POSIX CPU timer expiry to task context.\n\nReproduced with setrlimit(RLIMIT_CPU, ...) and a busy loop. The same path\nis used by setitimer(ITIMER_PROF or ITIMER_VIRTUAL) and POSIX CPU timers\ncreated with timer_create()."
    }
  ],
  "lastModified": "2026-09-17T17:17:28.163",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}