CVE-2026-64248
Received Received - Intake

RCU Grace Period Hang in Linux Kernel Due to Missing CPU Death Notification

Vulnerability report for CVE-2026-64248, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-24

Last updated on: 2026-07-24

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: MIPS: smp: report dying CPU to RCU in stop_this_cpu() smp_send_stop() parks all secondary CPUs in stop_this_cpu(). The function marks the CPU offline for the scheduler via set_cpu_online(false) but never informs RCU, so RCU keeps expecting a quiescent state from CPUs that are now spinning forever with interrupts disabled. As long as nothing waits for an RCU grace period after smp_send_stop() this is harmless, which is why it went unnoticed. Since commit 91840be8f710 ("irq_work: Fix use-after-free in irq_work_single() on PREEMPT_RT") however, irq_work_sync() calls synchronize_rcu() on architectures without an irq_work self-IPI, i.e. where arch_irq_work_has_interrupt() returns false. That is the asm-generic default used by MIPS. Any irq_work_sync() issued in the reboot/shutdown path after smp_send_stop() then blocks on a grace period that can never complete, hanging the reboot: WARNING: CPU: 0 PID: 15 at kernel/irq_work.c:144 irq_work_queue_on ... rcu: INFO: rcu_sched detected stalls on CPUs/tasks: rcu: Offline CPU 1 blocking current GP. rcu: Offline CPU 2 blocking current GP. rcu: Offline CPU 3 blocking current GP. This issue was noticed on several Realtek MIPS switch SoCs (MIPS interAptiv) and came up during kernel bump downstream in OpenWrt from 6.18.33 to 6.18.34, after the backport of the patch to the 6.18 stable branch. The patch also has been backported all the way back to 6.1. Call rcutree_report_cpu_dead() once interrupts are disabled, mirroring the generic CPU-hotplug offline path, so RCU stops waiting on the parked CPUs and grace periods can still complete. MIPS shuts down all CPUs here without going through the CPU-hotplug mechanism, so this report is not otherwise issued. Reporting a dying CPU to RCU outside the regular hotplug offline path is not unprecedented: arm64 does the same in cpu_die_early(). There it is an exception for a CPU that was coming online and is aborting bringup, rather than the default shutdown action as on MIPS.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-24
Last Modified
2026-07-24
Generated
2026-07-24
AI Q&A
2026-07-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
linux linux_kernel From 6.18.34 (inc)
linux linux_kernel From 6.1 (inc)
linux linux_kernel to 6.18.34 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Linux kernel's MIPS architecture. When smp_send_stop() is called to stop secondary CPUs, it marks them offline for the scheduler but fails to inform RCU (Read-Copy-Update). RCU continues expecting a quiescent state from these parked CPUs, which are spinning with interrupts disabled. This can cause a system hang during reboot if irq_work_sync() calls synchronize_rcu() after smp_send_stop().

Detection Guidance

This vulnerability is specific to the Linux kernel's MIPS architecture and may not have direct detection commands. However, if you suspect the issue, monitor for kernel warnings during reboot or shutdown, particularly RCU stalls or CPU offline messages. Check kernel logs for errors like 'Offline CPU blocking current GP' after smp_send_stop() is called.

Impact Analysis

If you use a MIPS-based system (like certain Realtek switch SoCs), this vulnerability could cause the system to hang during reboot or shutdown. This disrupts normal operations and requires a hard reset to recover.

Compliance Impact

This vulnerability does not directly affect compliance with standards like GDPR or HIPAA. It is a kernel-level issue causing system hangs during shutdown on MIPS systems, which could indirectly impact availability requirements in compliance frameworks by causing unexpected downtime.

Mitigation Strategies

Apply the kernel patch that adds rcutree_report_cpu_dead() to report dying CPUs to RCU. Update to a fixed kernel version (6.1 or later with the backport). If using OpenWrt, upgrade to version 6.18.34 or later. Ensure no irq_work_sync() calls occur after smp_send_stop() during shutdown.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-64248. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart