« Volver al listado

CVE-2026-89759

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

mm/kmemleak: avoid soft lockup when scanning task stacks

Patch series "mm/kmemleak: avoid soft lockup when scanning task", v3.

kmemleak_scan() scans every task stack under one rcu_read_lock() with no reschedule point, which can trip the soft lockup watchdog on hosts with very many threads.

That prints the following message, depending on the workload+host configuration:

Patch 1 walks the tasks with find_ge_pid() so the scan reschedules between tasks

Patches 2-3 let the scan loops stop early once a scan is interrupted.

This patch (of 3):

Leer descripción completaMostrar menos

kmemleak_scan() walks every thread and scans its kernel stack under a single rcu_read_lock() with no reschedule point. On a host with very many threads -- amplified by KASAN/lockdep in debug builds -- this loop can hog a CPU long enough to trip the soft lockup watchdog:

A cond_resched() cannot be added directly: the loop runs inside an RCU read-side critical section.

Walk the tasks one PID at a time with find_ge_pid(), taking the RCU read lock only to look up and pin each task. The stack is then scanned with no lock held, so cond_resched() runs between tasks and the scan stops early on scan_should_stop(). This follows the next_tgid()/task_seq_get_next() iteration pattern and keeps each RCU critical section short.

Detalles técnicos trazas, registros y código del informe original
      watchdog: BUG: soft lockup - CPU#35 stuck for 22s! [kmemleak:537]
       scan_block
       kmemleak_scan
       kmemleak_scan_thread
       kthread

  watchdog: BUG: soft lockup - CPU#35 stuck for 22s! [kmemleak:537]
   scan_block
   kmemleak_scan
   kmemleak_scan_thread
   kthread

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-89759",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "c4b28963fd79457315783b3b0f21c01eb88cfdc1",
              "lessThan": "9a1b12c06c192290b8479de48f66f1e75d89c4b7",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c4b28963fd79457315783b3b0f21c01eb88cfdc1",
              "lessThan": "3fc8044251de21555fb02c365fa681bab8b0db55",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c4b28963fd79457315783b3b0f21c01eb88cfdc1",
              "lessThan": "1838c704bcb4fd3556cf67513c6f97a39099e35c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c4b28963fd79457315783b3b0f21c01eb88cfdc1",
              "lessThan": "5d10d4e19e6daa487f0cd0ea6cba472325de92f9",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "mm/kmemleak.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.10"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.10",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.109",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.50",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.4",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "mm/kmemleak.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-11T20:20:06.997",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/1838c704bcb4fd3556cf67513c6f97a39099e35c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/3fc8044251de21555fb02c365fa681bab8b0db55",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/5d10d4e19e6daa487f0cd0ea6cba472325de92f9",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9a1b12c06c192290b8479de48f66f1e75d89c4b7",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/kmemleak: avoid soft lockup when scanning task stacks\n\nPatch series \"mm/kmemleak: avoid soft lockup when scanning task\", v3.\n\nkmemleak_scan() scans every task stack under one rcu_read_lock() with no\nreschedule point, which can trip the soft lockup watchdog on hosts with\nvery many threads.\n\nThat prints the following message, depending on the workload+host\nconfiguration:\n\n      watchdog: BUG: soft lockup - CPU#35 stuck for 22s! [kmemleak:537]\n       scan_block\n       kmemleak_scan\n       kmemleak_scan_thread\n       kthread\n\nPatch 1 walks the tasks with find_ge_pid() so the scan reschedules between\ntasks\n\nPatches 2-3 let the scan loops stop early once a scan is interrupted.\n\n\nThis patch (of 3):\n\nkmemleak_scan() walks every thread and scans its kernel stack under a\nsingle rcu_read_lock() with no reschedule point.  On a host with very many\nthreads -- amplified by KASAN/lockdep in debug builds -- this loop can hog\na CPU long enough to trip the soft lockup watchdog:\n\n  watchdog: BUG: soft lockup - CPU#35 stuck for 22s! [kmemleak:537]\n   scan_block\n   kmemleak_scan\n   kmemleak_scan_thread\n   kthread\n\nA cond_resched() cannot be added directly: the loop runs inside an RCU\nread-side critical section.\n\nWalk the tasks one PID at a time with find_ge_pid(), taking the RCU read\nlock only to look up and pin each task.  The stack is then scanned with no\nlock held, so cond_resched() runs between tasks and the scan stops early\non scan_should_stop().  This follows the next_tgid()/task_seq_get_next()\niteration pattern and keeps each RCU critical section short."
    }
  ],
  "lastModified": "2026-09-11T20:20:06.997",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}