CVE-2026-90305
In the Linux kernel, the following vulnerability has been resolved:
ARM: 9483/1: select HAVE_POSIX_CPU_TIMERS_TASK_WORK
Commit c6e61c06d606 ("ARM: 9463/1: Allow to enable RT") enabled PREEMPT_RT on ARM but did not select HAVE_POSIX_CPU_TIMERS_TASK_WORK. This leaves CONFIG_POSIX_CPU_TIMERS_TASK_WORK disabled, so CPU timers expire in hard IRQ context.
On PREEMPT_RT this makes run_posix_cpu_timers() take the sleeping sighand->siglock:
ARM handles TIF_NOTIFY_RESUME on all return-to-user paths, including v7-M. ARM32 KVM host support was removed by commit 541ad0150ca4 ("arm: Remove 32bit KVM host support"), so the select need not be conditional on KVM.
Read full descriptionShow less
Select it to defer POSIX CPU timer expiry to task context.
Reproduced with setrlimit(RLIMIT_CPU, ...) and a busy loop. The same path is used by setitimer(ITIMER_PROF or ITIMER_VIRTUAL) and POSIX CPU timers created with timer_create().
Technical details traces, logs and code from the original report
BUG: sleeping function called from invalid context at spinlock_rt.c:48
rt_spin_lock from lock_task_sighand
lock_task_sighand from run_posix_cpu_timers
run_posix_cpu_timers from update_process_timesCVSS
NVD hasn't assigned a CVSS score to this CVE (common since the April 2026 policy change).
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.20%
- Percentile among all scored CVEs: 9
- Score date: 10/5/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.
References
Raw JSON (NVD)
Show
{
"id": "CVE-2026-90305",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "c6e61c06d6061750597e79c598acb5dead44c35b",
"lessThan": "8de56782d6e5ba7a9f8c820342dccde65502f93f",
"versionType": "git"
},
{
"status": "affected",
"version": "c6e61c06d6061750597e79c598acb5dead44c35b",
"lessThan": "8a58a41100ea377e978d99600ec24a9bd0273662",
"versionType": "git"
}
],
"programFiles": [
"arch/arm/Kconfig"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "7.1"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "7.1",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "7.2.6",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"arch/arm/Kconfig"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-17T17:17:28.163",
"references": [
{
"url": "https://git.kernel.org/stable/c/8a58a41100ea377e978d99600ec24a9bd0273662",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/8de56782d6e5ba7a9f8c820342dccde65502f93f",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nARM: 9483/1: select HAVE_POSIX_CPU_TIMERS_TASK_WORK\n\nCommit c6e61c06d606 (\"ARM: 9463/1: Allow to enable RT\") enabled PREEMPT_RT\non ARM but did not select HAVE_POSIX_CPU_TIMERS_TASK_WORK. This leaves\nCONFIG_POSIX_CPU_TIMERS_TASK_WORK disabled, so CPU timers expire in hard\nIRQ context.\n\nOn PREEMPT_RT this makes run_posix_cpu_timers() take the sleeping\nsighand->siglock:\n\n BUG: sleeping function called from invalid context at spinlock_rt.c:48\n rt_spin_lock from lock_task_sighand\n lock_task_sighand from run_posix_cpu_timers\n run_posix_cpu_timers from update_process_times\n\nARM handles TIF_NOTIFY_RESUME on all return-to-user paths, including v7-M.\nARM32 KVM host support was removed by commit 541ad0150ca4 (\"arm: Remove\n32bit KVM host support\"), so the select need not be conditional on KVM.\n\nSelect it to defer POSIX CPU timer expiry to task context.\n\nReproduced with setrlimit(RLIMIT_CPU, ...) and a busy loop. The same path\nis used by setitimer(ITIMER_PROF or ITIMER_VIRTUAL) and POSIX CPU timers\ncreated with timer_create()."
}
],
"lastModified": "2026-09-17T17:17:28.163",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}