PT-2026-93544 · Linux · Linux Kernel

CVE-2026-89903

·

Published

2026-09-16

·

Updated

2026-09-24

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions 6.3 and later
Description An issue exists in the LoongArch architecture where the rethook trampoline incorrectly saves and restores the $r21 ($u0) register, which serves as the percpu base. When rethook trampoline handler() triggers a schedule via preempt enable notrace(), a task may migrate to a different CPU. If the original percpu base stored in the frame is restored on the new CPU, it poisons the $r21 register. This causes subsequent this cpu *() accesses—including runqueues, RCU per-CPU data, timer tick programming, and FPU ownership—to target the incorrect CPU's percpu area. Under heavy preemptible load with kretprobes, this can lead to scheduler and timer state corruption, resulting in scheduling-while-atomic errors, RCU warnings, or hard lockups where CPUs park in the idle loop without re-arming the constant timer.
Recommendations Remove the save and restore operations of the $r21 register within the rethook trampoline.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-101280
CVE-2026-89903
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel