« Volver al listado

CVE-2026-89756

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

mm/migrate: report RCU-tasks quiescent states in migrate_pages_batch()

migrate_pages_batch() unmaps each folio before moving it, and every unmap runs the mmu_notifier invalidate callbacks. On KVM hosts try_to_migrate() ends up in kvm_mmu_notifier_invalidate_range_start() -> tdp_mmu_zap_leafs(), which is expensive, so unmapping a large batch keeps the CPU busy for a long time.

The loop already calls cond_resched(), but on PREEMPTION kernels that is a no-op, and involuntary preemption is not a Tasks-RCU quiescent state.

A long batch therefore never reports a quiescent state, and the migrating task (e.g. kcompactd) becomes a Tasks-RCU holdout, stalling the Tasks-RCU grace period for minutes, which is common at Meta fleet:

Leer descripción completaMostrar menos

Use cond_resched_tasks_rcu_qs() so a quiescent state is reported even when cond_resched() does nothing.

This has also been discussed at [1]

Detalles técnicos trazas, registros y código del informe original
  INFO: rcu_tasks detected stalls on tasks:
  0000000055349ecc: .. nvcsw: 1157401/1157401 holdout: 1 idle_cpu: -1/56 task:kcompactd0      state:R  running task
  Call Trace:
   tdp_mmu_zap_leafs
   tdp_mmu_next_root
   gfn_to_pfn_cache_invalidate_start
   kvm_mmu_notifier_invalidate_range_start
   __mmu_notifier_invalidate_range_start
   try_to_migrate_one
   try_to_migrate
   migrate_pages_batch
   migrate_pages
   compact_zone
   compact_node
   kcompactd
   kthread

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-89756",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "8315f42295d2667a7f942f154b73a86fd7cb2227",
              "lessThan": "8c6d63d434ebb85c6cf3dac1e70a171b183c6614",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8315f42295d2667a7f942f154b73a86fd7cb2227",
              "lessThan": "4757542649af56d894e25e30f57cd497dffad53f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8315f42295d2667a7f942f154b73a86fd7cb2227",
              "lessThan": "4996a7bc01ef35570664854dac2530c604981039",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8315f42295d2667a7f942f154b73a86fd7cb2227",
              "lessThan": "5dc0daff0341c6baba19c38f47d299ac831d7e99",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8315f42295d2667a7f942f154b73a86fd7cb2227",
              "lessThan": "66734981b4d3c105223a13c827c9c73be18d91ad",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8315f42295d2667a7f942f154b73a86fd7cb2227",
              "lessThan": "efe8f86c0916f0f74eea74ae21a3b37f728c6bad",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "mm/migrate.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.18"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "3.18",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.1.188",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.157",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.109",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.50",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.4",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "mm/migrate.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-11T20:20:06.643",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/4757542649af56d894e25e30f57cd497dffad53f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/4996a7bc01ef35570664854dac2530c604981039",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/5dc0daff0341c6baba19c38f47d299ac831d7e99",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/66734981b4d3c105223a13c827c9c73be18d91ad",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8c6d63d434ebb85c6cf3dac1e70a171b183c6614",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/efe8f86c0916f0f74eea74ae21a3b37f728c6bad",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/migrate: report RCU-tasks quiescent states in migrate_pages_batch()\n\nmigrate_pages_batch() unmaps each folio before moving it, and every\nunmap runs the mmu_notifier invalidate callbacks.  On KVM hosts\ntry_to_migrate() ends up in kvm_mmu_notifier_invalidate_range_start() ->\ntdp_mmu_zap_leafs(), which is expensive, so unmapping a large batch keeps\nthe CPU busy for a long time.\n\nThe loop already calls cond_resched(), but on PREEMPTION kernels that is\na no-op, and involuntary preemption is not a Tasks-RCU quiescent state.\n\nA long batch therefore never reports a quiescent state, and the\nmigrating task (e.g. kcompactd) becomes a Tasks-RCU holdout, stalling the\nTasks-RCU grace period for minutes, which is common at Meta fleet:\n\n  INFO: rcu_tasks detected stalls on tasks:\n  0000000055349ecc: .. nvcsw: 1157401/1157401 holdout: 1 idle_cpu: -1/56 task:kcompactd0      state:R  running task\n  Call Trace:\n   tdp_mmu_zap_leafs\n   tdp_mmu_next_root\n   gfn_to_pfn_cache_invalidate_start\n   kvm_mmu_notifier_invalidate_range_start\n   __mmu_notifier_invalidate_range_start\n   try_to_migrate_one\n   try_to_migrate\n   migrate_pages_batch\n   migrate_pages\n   compact_zone\n   compact_node\n   kcompactd\n   kthread\n\nUse cond_resched_tasks_rcu_qs() so a quiescent state is reported even\nwhen cond_resched() does nothing.\n\nThis has also been discussed at [1]"
    }
  ],
  "lastModified": "2026-09-14T13:19:24.170",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}