« Volver al listado

CVE-2026-93253

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

sched/isolation: Defer freeing of cpumask memblock memory to initcall

When testing a linux-next kernel with commit 59bd1d914bb5 ("memblock: warn when freeing reserved memory before memory map is initialized"), the following warning was hit when there was a "nohz_full" kernel boot parameter.

IOW, we shouldn't free memblock allocated memory so early in the boot process when memory map isn't fully initialized in deferred_init_memmap().

Fix it by saving the housekeeping cpumask memblock memory to be freed into a llist free list in housekeeping_init() and add a new housekeeping_late_init() helper to defer the actual freeing of memblock memory to when initcall's are being processed.

Leer descripción completaMostrar menos

The cpumask memblock memory is treated as a llist_node with the size of a "long" type which is also smallest cpumask size that can be allocated.

The non-atomic version of the llist APIs are used as there is no contention.

This commit depends on the presence of commit 7c2eee9c1367 ("memblock: don't touch memblock arrays when memblock_free() is called late") to prevent a KASAN UAF bug report [1].

[1] https://lore.kernel.org/lkml/20260505051821.1107133-1-longman@redhat.com/

Detalles técnicos trazas, registros y código del informe original
  Cannot free reserved memory because of deferred initialization of the memory map
  WARNING: mm/memblock.c:904 at __free_reserved_area+0xde/0xf0, CPU#0: swapper/0/0
    :
  Call Trace:
   <TASK>
   memblock_phys_free+0xcb/0x100
   housekeeping_init+0x14c/0x170
   start_kernel+0x207/0x450
   x86_64_start_reservations+0x24/0x30
   x86_64_start_kernel+0xda/0xe0
   common_startup_64+0x13e/0x141
   </TASK>

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-93253",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "27c3a5967f054ab666704cb28f2aeb18ca07cab7",
              "lessThan": "811fdac2d1bdf0b0d3fda262aac288ddd13a1422",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "27c3a5967f054ab666704cb28f2aeb18ca07cab7",
              "lessThan": "2b58c749b8c5244e259a0230bc57b10b010dc545",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "kernel/sched/isolation.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7.0"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "7.0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "kernel/sched/isolation.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-24T16:17:21.640",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/2b58c749b8c5244e259a0230bc57b10b010dc545",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/811fdac2d1bdf0b0d3fda262aac288ddd13a1422",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsched/isolation: Defer freeing of cpumask memblock memory to initcall\n\nWhen testing a linux-next kernel with commit 59bd1d914bb5 (\"memblock:\nwarn when freeing reserved memory before memory map is initialized\"),\nthe following warning was hit when there was a \"nohz_full\" kernel boot\nparameter.\n\n  Cannot free reserved memory because of deferred initialization of the memory map\n  WARNING: mm/memblock.c:904 at __free_reserved_area+0xde/0xf0, CPU#0: swapper/0/0\n    :\n  Call Trace:\n   <TASK>\n   memblock_phys_free+0xcb/0x100\n   housekeeping_init+0x14c/0x170\n   start_kernel+0x207/0x450\n   x86_64_start_reservations+0x24/0x30\n   x86_64_start_kernel+0xda/0xe0\n   common_startup_64+0x13e/0x141\n   </TASK>\n\nIOW, we shouldn't free memblock allocated memory so early\nin the boot process when memory map isn't fully initialized in\ndeferred_init_memmap().\n\nFix it by saving the housekeeping cpumask memblock memory to be\nfreed into a llist free list in housekeeping_init() and add a new\nhousekeeping_late_init() helper to defer the actual freeing of memblock\nmemory to when initcall's are being processed. The cpumask memblock\nmemory is treated as a llist_node with the size of a \"long\" type which\nis also smallest cpumask size that can be allocated.\n\nThe non-atomic version of the llist APIs are used as there is no\ncontention.\n\nThis commit depends on the presence of commit 7c2eee9c1367 (\"memblock:\ndon't touch memblock arrays when memblock_free() is called late\")\nto prevent a KASAN UAF bug report [1].\n\n [1] https://lore.kernel.org/lkml/20260505051821.1107133-1-longman@redhat.com/"
    }
  ],
  "lastModified": "2026-09-24T16:17:21.640",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}