CVE-2026-89756
Received Received - Intake

Memory Corruption in Linux Kernel Task Migration

Vulnerability report for CVE-2026-89756, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-11

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: mm/migrate: report RCU-tasks quiescent states in migrate_pages_batch() migrate_pages_batch() unmaps each folio before moving it, and every unmap runs the mmu_notifier invalidate callbacks. On KVM hosts try_to_migrate() ends up in kvm_mmu_notifier_invalidate_range_start() -> tdp_mmu_zap_leafs(), which is expensive, so unmapping a large batch keeps the CPU busy for a long time. The loop already calls cond_resched(), but on PREEMPTION kernels that is a no-op, and involuntary preemption is not a Tasks-RCU quiescent state. A long batch therefore never reports a quiescent state, and the migrating task (e.g. kcompactd) becomes a Tasks-RCU holdout, stalling the Tasks-RCU grace period for minutes, which is common at Meta fleet: INFO: rcu_tasks detected stalls on tasks: 0000000055349ecc: .. nvcsw: 1157401/1157401 holdout: 1 idle_cpu: -1/56 task:kcompactd0 state:R running task Call Trace: tdp_mmu_zap_leafs tdp_mmu_next_root gfn_to_pfn_cache_invalidate_start kvm_mmu_notifier_invalidate_range_start __mmu_notifier_invalidate_range_start try_to_migrate_one try_to_migrate migrate_pages_batch migrate_pages compact_zone compact_node kcompactd kthread Use cond_resched_tasks_rcu_qs() so a quiescent state is reported even when cond_resched() does nothing. This has also been discussed at [1]

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-11
Generated
2026-09-12
AI Q&A
2026-09-12
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Linux kernel's memory migration process. When moving large batches of memory pages, the system fails to report quiescent states to the Tasks-RCU mechanism. This causes the Tasks-RCU grace period to stall for extended periods, potentially minutes, as the migrating task (like kcompactd) becomes a holdout.

Detection Guidance

Detection involves monitoring for Tasks-RCU stalls, particularly during memory compaction tasks like kcompactd. Check kernel logs for messages indicating RCU stall conditions or Tasks-RCU holdouts. Commands include: dmesg | grep -i 'rcu_tasks' or dmesg | grep -i 'holdout'. Monitor system performance during memory-intensive operations.

Impact Analysis

This could lead to system freezes or delays during memory-intensive operations like compaction. Systems running memory-heavy workloads may experience reduced performance or unresponsiveness until the stalled RCU grace period completes.

Mitigation Strategies

Apply the Linux kernel patch that introduces cond_resched_tasks_rcu_qs() in migrate_pages_batch(). Update to a kernel version containing this fix. If immediate patching is not possible, reduce memory compaction workloads or adjust compaction parameters to minimize batch sizes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89756. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart