« Volver al listado

CVE-2026-89986

Estado: RecibidaAlta (7.8)—

In the Linux kernel, the following vulnerability has been resolved:

mm/mempolicy: fix sleeping allocation in alloc_pages_bulk_weighted_interleave()

syzbot reported a sleeping function called from invalid context splat in bucket_table_alloc().

When rhashtable_insert_slow() rehashes the table under rcu_read_lock(), it calls bucket_table_alloc(..., GFP_ATOMIC | __GFP_NOWARN). If the bucket table allocation uses vmalloc, __vmalloc_node_range_noprof() invokes vm_area_alloc_pages() -> alloc_pages_bulk_mempolicy_noprof() with the passed GFP_ATOMIC flags.

If the current task has an MPOL_WEIGHTED_INTERLEAVE mempolicy, alloc_pages_bulk_weighted_interleave() is called and currently hardcodes GFP_KERNEL when allocating the temporary weights array, triggering a might_alloc() splat in atomic/RCU contexts.

Leer descripción completaMostrar menos

Pass the gfp flags (masked with GFP_RECLAIM_MASK to strip page-allocator zone modifiers like __GFP_HIGHMEM) received by alloc_pages_bulk_weighted_interleave() to kmalloc() instead of hardcoding GFP_KERNEL. Since the weights buffer is immediately initialized in full, kmalloc() is sufficient.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad de escalada de privilegios local en kernel Linux mediante condición de carrera en asignación de memoria con MPOL_WEIGHTED_INTERLEAVE, permitiendo denegación de servicio o corrupción de memoria desde contexto con PR:L.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-89986",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "fa3bea4e1f8202d787709b7e3654eb0a99aed758",
              "lessThan": "bcb3d0c867ee40dc48e9c085bf328fbc679b6656",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "fa3bea4e1f8202d787709b7e3654eb0a99aed758",
              "lessThan": "0ceda28f371df9e0bbdaa29214f71fe8298f23d8",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "fa3bea4e1f8202d787709b7e3654eb0a99aed758",
              "lessThan": "2943f1f4b7f2816177060eb9f551f2e6d8b629ba",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "fa3bea4e1f8202d787709b7e3654eb0a99aed758",
              "lessThan": "540e583b66d6402bf556fde5e53c817a54c1afe5",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "mm/mempolicy.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.9"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.9",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.51",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "mm/mempolicy.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-16T11:17:09.653",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0ceda28f371df9e0bbdaa29214f71fe8298f23d8",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/2943f1f4b7f2816177060eb9f551f2e6d8b629ba",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/540e583b66d6402bf556fde5e53c817a54c1afe5",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/bcb3d0c867ee40dc48e9c085bf328fbc679b6656",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/mempolicy: fix sleeping allocation in alloc_pages_bulk_weighted_interleave()\n\nsyzbot reported a sleeping function called from invalid context splat in\nbucket_table_alloc().\n\nWhen rhashtable_insert_slow() rehashes the table under rcu_read_lock(), it\ncalls bucket_table_alloc(..., GFP_ATOMIC | __GFP_NOWARN).  If the bucket\ntable allocation uses vmalloc, __vmalloc_node_range_noprof() invokes\nvm_area_alloc_pages() -> alloc_pages_bulk_mempolicy_noprof() with the\npassed GFP_ATOMIC flags.\n\nIf the current task has an MPOL_WEIGHTED_INTERLEAVE mempolicy,\nalloc_pages_bulk_weighted_interleave() is called and currently hardcodes\nGFP_KERNEL when allocating the temporary weights array, triggering a\nmight_alloc() splat in atomic/RCU contexts.\n\nPass the gfp flags (masked with GFP_RECLAIM_MASK to strip page-allocator\nzone modifiers like __GFP_HIGHMEM) received by\nalloc_pages_bulk_weighted_interleave() to kmalloc() instead of hardcoding\nGFP_KERNEL.  Since the weights buffer is immediately initialized in full,\nkmalloc() is sufficient."
    }
  ],
  "lastModified": "2026-09-16T15:18:22.557",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}