CVE-2026-72154
Received Received - Intake

OpenRISC Jump Label SMP Cache Syncing Fix

Vulnerability report for CVE-2026-72154, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-15

Last updated on: 2026-08-17

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: openrisc: Fix jump_label smp syncing The original commit 8c30b0018f9d ("openrisc: Add jump label support") copies from arm64 and does not properly consider how icache invalidation on remote cores works in OpenRISC. On OpenRISC remote icaches need to be invalidated otherwise static key's may remain state after updating. Fix SMP cache syncing by: 1. Properly invalidate remote core icaches on SMP systems by using icache_all_inv. The old code uses kick_all_cpus_sync() which runs a no-op IPI function call on remote CPU's which does execute a lot of code and flushes many cache lines in the process, but does not flush all and it's not correct on OpenRISC. 2. For architectures that do not have WRITETHROUGH caches be sure to flush the dcache after patching. To test this I first reproduced the issue using a custom test module [0]. The test confirmed that some icache lines maintained stale static_key code sequences after calling static_branch_enable(). After this patch there are no longer jump_label coherency issues. [0] https://github.com/stffrdhrn/or1k-utils/tree/master/tests/smp_static_key_test

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-15
Last Modified
2026-08-17
Generated
2026-09-04
AI Q&A
2026-08-15
EPSS Evaluated
2026-09-03
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
openrisc linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel affects the OpenRISC architecture. It involves improper handling of instruction cache (icache) invalidation during SMP (symmetric multiprocessing) operations. When static keys are updated, remote CPU cores may retain stale code in their icaches, leading to potential inconsistencies in kernel execution paths.

Detection Guidance

This vulnerability is specific to the OpenRISC architecture in the Linux kernel and relates to icache invalidation issues during static key updates. Detection requires kernel-level inspection rather than network scanning. Check if your system uses OpenRISC architecture and examine kernel logs for static key-related errors or icache coherency issues during SMP operations.

Impact Analysis

This vulnerability could cause kernel instability or incorrect behavior on OpenRISC-based systems with multiple CPU cores. It may lead to crashes, data corruption, or security issues if stale kernel code executes after updates. Systems using static keys for feature toggles or performance optimizations are most affected.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or similar standards. It is a low-level kernel issue related to icache invalidation in OpenRISC architectures, which could lead to incorrect execution of static keys but does not involve data handling, privacy, or security controls typically regulated by these standards.

Mitigation Strategies

Apply the kernel patch that fixes the icache invalidation issue for OpenRISC. Update to a Linux kernel version that includes the fix for commit 8c30b0018f9d or later. If using a custom kernel, ensure proper icache_all_inv implementation is present for OpenRISC SMP systems.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-72154. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart