CVE-2026-89756
In the Linux kernel, the following vulnerability has been resolved:
mm/migrate: report RCU-tasks quiescent states in migrate_pages_batch()
migrate_pages_batch() unmaps each folio before moving it, and every unmap runs the mmu_notifier invalidate callbacks. On KVM hosts try_to_migrate() ends up in kvm_mmu_notifier_invalidate_range_start() -> tdp_mmu_zap_leafs(), which is expensive, so unmapping a large batch keeps the CPU busy for a long time.
The loop already calls cond_resched(), but on PREEMPTION kernels that is a no-op, and involuntary preemption is not a Tasks-RCU quiescent state.
A long batch therefore never reports a quiescent state, and the migrating task (e.g. kcompactd) becomes a Tasks-RCU holdout, stalling the Tasks-RCU grace period for minutes, which is common at Meta fleet:
Leer descripción completaMostrar menos
Use cond_resched_tasks_rcu_qs() so a quiescent state is reported even when cond_resched() does nothing.
This has also been discussed at [1]
Detalles técnicos trazas, registros y código del informe original
INFO: rcu_tasks detected stalls on tasks: 0000000055349ecc: .. nvcsw: 1157401/1157401 holdout: 1 idle_cpu: -1/56 task:kcompactd0 state:R running task Call Trace: tdp_mmu_zap_leafs tdp_mmu_next_root gfn_to_pfn_cache_invalidate_start kvm_mmu_notifier_invalidate_range_start __mmu_notifier_invalidate_range_start try_to_migrate_one try_to_migrate migrate_pages_batch migrate_pages compact_zone compact_node kcompactd kthread
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.19%
- Percentil entre todas las CVEs puntuadas: 8
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/4757542649af56d894e25e30f57cd497dffad53f
- https://git.kernel.org/stable/c/4996a7bc01ef35570664854dac2530c604981039
- https://git.kernel.org/stable/c/5dc0daff0341c6baba19c38f47d299ac831d7e99
- https://git.kernel.org/stable/c/66734981b4d3c105223a13c827c9c73be18d91ad
- https://git.kernel.org/stable/c/8c6d63d434ebb85c6cf3dac1e70a171b183c6614
- https://git.kernel.org/stable/c/efe8f86c0916f0f74eea74ae21a3b37f728c6bad
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-89756",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "8315f42295d2667a7f942f154b73a86fd7cb2227",
"lessThan": "8c6d63d434ebb85c6cf3dac1e70a171b183c6614",
"versionType": "git"
},
{
"status": "affected",
"version": "8315f42295d2667a7f942f154b73a86fd7cb2227",
"lessThan": "4757542649af56d894e25e30f57cd497dffad53f",
"versionType": "git"
},
{
"status": "affected",
"version": "8315f42295d2667a7f942f154b73a86fd7cb2227",
"lessThan": "4996a7bc01ef35570664854dac2530c604981039",
"versionType": "git"
},
{
"status": "affected",
"version": "8315f42295d2667a7f942f154b73a86fd7cb2227",
"lessThan": "5dc0daff0341c6baba19c38f47d299ac831d7e99",
"versionType": "git"
},
{
"status": "affected",
"version": "8315f42295d2667a7f942f154b73a86fd7cb2227",
"lessThan": "66734981b4d3c105223a13c827c9c73be18d91ad",
"versionType": "git"
},
{
"status": "affected",
"version": "8315f42295d2667a7f942f154b73a86fd7cb2227",
"lessThan": "efe8f86c0916f0f74eea74ae21a3b37f728c6bad",
"versionType": "git"
}
],
"programFiles": [
"mm/migrate.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "3.18"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "3.18",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.1.188",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.157",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.109",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.50",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.4",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"mm/migrate.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-11T20:20:06.643",
"references": [
{
"url": "https://git.kernel.org/stable/c/4757542649af56d894e25e30f57cd497dffad53f",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/4996a7bc01ef35570664854dac2530c604981039",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/5dc0daff0341c6baba19c38f47d299ac831d7e99",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/66734981b4d3c105223a13c827c9c73be18d91ad",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/8c6d63d434ebb85c6cf3dac1e70a171b183c6614",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/efe8f86c0916f0f74eea74ae21a3b37f728c6bad",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/migrate: report RCU-tasks quiescent states in migrate_pages_batch()\n\nmigrate_pages_batch() unmaps each folio before moving it, and every\nunmap runs the mmu_notifier invalidate callbacks. On KVM hosts\ntry_to_migrate() ends up in kvm_mmu_notifier_invalidate_range_start() ->\ntdp_mmu_zap_leafs(), which is expensive, so unmapping a large batch keeps\nthe CPU busy for a long time.\n\nThe loop already calls cond_resched(), but on PREEMPTION kernels that is\na no-op, and involuntary preemption is not a Tasks-RCU quiescent state.\n\nA long batch therefore never reports a quiescent state, and the\nmigrating task (e.g. kcompactd) becomes a Tasks-RCU holdout, stalling the\nTasks-RCU grace period for minutes, which is common at Meta fleet:\n\n INFO: rcu_tasks detected stalls on tasks:\n 0000000055349ecc: .. nvcsw: 1157401/1157401 holdout: 1 idle_cpu: -1/56 task:kcompactd0 state:R running task\n Call Trace:\n tdp_mmu_zap_leafs\n tdp_mmu_next_root\n gfn_to_pfn_cache_invalidate_start\n kvm_mmu_notifier_invalidate_range_start\n __mmu_notifier_invalidate_range_start\n try_to_migrate_one\n try_to_migrate\n migrate_pages_batch\n migrate_pages\n compact_zone\n compact_node\n kcompactd\n kthread\n\nUse cond_resched_tasks_rcu_qs() so a quiescent state is reported even\nwhen cond_resched() does nothing.\n\nThis has also been discussed at [1]"
}
],
"lastModified": "2026-09-14T13:19:24.170",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}