PT-2026-93544 · Linux · Linux Kernel
CVE-2026-89903
·
Published
2026-09-16
·
Updated
2026-09-24
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions 6.3 and later
Description
An issue exists in the LoongArch architecture where the rethook trampoline incorrectly saves and restores the
$r21 ($u0) register, which serves as the percpu base. When rethook trampoline handler() triggers a schedule via preempt enable notrace(), a task may migrate to a different CPU. If the original percpu base stored in the frame is restored on the new CPU, it poisons the $r21 register. This causes subsequent this cpu *() accesses—including runqueues, RCU per-CPU data, timer tick programming, and FPU ownership—to target the incorrect CPU's percpu area. Under heavy preemptible load with kretprobes, this can lead to scheduler and timer state corruption, resulting in scheduling-while-atomic errors, RCU warnings, or hard lockups where CPUs park in the idle loop without re-arming the constant timer.Recommendations
Remove the save and restore operations of the
$r21 register within the rethook trampoline.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel