CVE-2026-89759
Received Received - Intake

Soft Lockup in Linux Kernel kmemleak

Vulnerability report for CVE-2026-89759, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-11

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: mm/kmemleak: avoid soft lockup when scanning task stacks Patch series "mm/kmemleak: avoid soft lockup when scanning task", v3. kmemleak_scan() scans every task stack under one rcu_read_lock() with no reschedule point, which can trip the soft lockup watchdog on hosts with very many threads. That prints the following message, depending on the workload+host configuration: watchdog: BUG: soft lockup - CPU#35 stuck for 22s! [kmemleak:537] scan_block kmemleak_scan kmemleak_scan_thread kthread Patch 1 walks the tasks with find_ge_pid() so the scan reschedules between tasks Patches 2-3 let the scan loops stop early once a scan is interrupted. This patch (of 3): kmemleak_scan() walks every thread and scans its kernel stack under a single rcu_read_lock() with no reschedule point. On a host with very many threads -- amplified by KASAN/lockdep in debug builds -- this loop can hog a CPU long enough to trip the soft lockup watchdog: watchdog: BUG: soft lockup - CPU#35 stuck for 22s! [kmemleak:537] scan_block kmemleak_scan kmemleak_scan_thread kthread A cond_resched() cannot be added directly: the loop runs inside an RCU read-side critical section. Walk the tasks one PID at a time with find_ge_pid(), taking the RCU read lock only to look up and pin each task. The stack is then scanned with no lock held, so cond_resched() runs between tasks and the scan stops early on scan_should_stop(). This follows the next_tgid()/task_seq_get_next() iteration pattern and keeps each RCU critical section short.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-11
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-10-01
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves kmemleak_scan() scanning every task stack under a single RCU read lock without rescheduling points. On systems with many threads, this can cause the CPU to hang long enough to trigger the soft lockup watchdog, leading to system instability or crashes.

Detection Guidance

This vulnerability is detected by monitoring for soft lockup messages in system logs. Check for messages like 'BUG: soft lockup - CPU# stuck for 22s! [kmemleak:537]' in /var/log/messages or dmesg output.

Impact Analysis

The vulnerability can cause system freezes or crashes on hosts with many threads, especially in debug builds with KASAN or lockdep enabled. This may lead to service disruptions or require manual intervention to recover the system.

Compliance Impact

This vulnerability does not directly affect compliance with standards like GDPR or HIPAA as it is a soft lockup issue in the Linux kernel's kmemleak component. It may indirectly impact compliance if system availability is compromised during kmemleak scans on systems with many threads, potentially affecting data processing or access controls.

Mitigation Strategies

Apply the Linux kernel patches provided in the vulnerability description. Specifically, update to a kernel version that includes the fix for kmemleak_scan() to avoid soft lockups during stack scanning.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89759. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart