PT-2026-93627 · Linux · Linux Kernel

CVE-2026-89986

·

Published

2026-09-16

·

Updated

2026-09-24

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the memory policy management where a sleeping function is called from an invalid context. When rhashtable insert slow() rehashes a table under rcu read lock(), it invokes bucket table alloc() with GFP ATOMIC flags. If the allocation uses vmalloc, it leads to alloc pages bulk weighted interleave() being called for tasks with an MPOL WEIGHTED INTERLEAVE memory policy. The function incorrectly hardcodes GFP KERNEL when allocating a temporary weights array, which triggers a might alloc() splat in atomic or RCU contexts. This occurs because GFP KERNEL allows the process to sleep, which is prohibited in these specific contexts.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-89986
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel