Description
In the Linux kernel, the following vulnerability has been resolved:

mm/vmscan: report RCU-tasks quiescent states in shrink_lruvec()

I am seeing some rcu_tasks stalls in the Meta fleet during reclaim.

INFO: rcu_tasks detected stalls on tasks:
0000000088620d09: .. nvcsw: 6735/6735 holdout: 1 idle_cpu: -1/8
task:GlobalCPUThread state:R running task pid:2552016 tgid:2524552
Call Trace:
shrink_lruvec
mem_cgroup_iter
shrink_node
do_try_to_free_pages
try_to_free_pages
__alloc_frozen_pages_noprof
alloc_pages_noprof
pte_alloc_one
__pte_alloc
handle_mm_fault

Nothing promises direct reclaim returns in bounded time, and the scan loop
in shrink_lruvec() only calls cond_resched(), which is a no-op on
PREEMPTION kernels. Involuntary preemption is not a Tasks-RCU quiescent
state, so the reclaiming task never reports one and becomes a holdout.

Upgrade it to cond_resched_tasks_rcu_qs(), which reports a quiescent state
even when cond_resched() does nothing.

PS: This has been discussed in [1]
Published: 2026-09-11
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Memory Reclamation Stall
Action: Patch
AI Analysis

Impact

In the Linux kernel, the memory‑management function shrink_lruvec() does not report a quiescent state for RCU‑tasks on PREEMPTION kernels when cond_resched() is a no‑op. During page reclamation the function stalls, leaving RCU tasks in a holdout state and preventing the kernel from freeing pages. This can lead to increased memory pressure and degraded system performance, potentially causing application or system instability due to exhausted resources. The vulnerability is a Resource Exhaustion flaw (CWE‑821) and does not provide direct remote code execution or authentication bypass.

Affected Systems

The defect is present in the Linux kernel source, meaning all distributions and vendors shipping an unpatched kernel contain it. Any kernel version that still uses the old shrink_lruvec() implementation is potentially affected until the upstream patch that replaces cond_resched() with cond_resched_tasks_rcu_qs() is applied.

Risk and Exploitability

The CVSS score of 4.7 indicates moderate severity, and the EPSS score is below 1 percent, suggesting a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local kernel code execution, requiring the attacker to have kernel privileges or to deliver a payload that forces high memory reclamation activity. Based on the description, it is inferred that an adversary would need local access on the host to exploit the flaw. In the absence of such access the impact on stability warrants remediation.

Generated by OpenCVE AI on September 15, 2026 at 19:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply an updated Linux kernel that patches shrink_lruvec() to use cond_resched_tasks_rcu_qs()
  • If a vendor update is not available, compile the upstream patch that replaces cond_resched() with cond_resched_tasks_rcu_qs() and rebuild the kernel
  • Continue to monitor RCU task stall metrics (e.g., via /sys/kernel/debug/rcu/rcu_stats) to confirm the issue is resolved

Generated by OpenCVE AI on September 15, 2026 at 19:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-821
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: mm/vmscan: report RCU-tasks quiescent states in shrink_lruvec() I am seeing some rcu_tasks stalls in the Meta fleet during reclaim. INFO: rcu_tasks detected stalls on tasks: 0000000088620d09: .. nvcsw: 6735/6735 holdout: 1 idle_cpu: -1/8 task:GlobalCPUThread state:R running task pid:2552016 tgid:2524552 Call Trace: shrink_lruvec mem_cgroup_iter shrink_node do_try_to_free_pages try_to_free_pages __alloc_frozen_pages_noprof alloc_pages_noprof pte_alloc_one __pte_alloc handle_mm_fault Nothing promises direct reclaim returns in bounded time, and the scan loop in shrink_lruvec() only calls cond_resched(), which is a no-op on PREEMPTION kernels. Involuntary preemption is not a Tasks-RCU quiescent state, so the reclaiming task never reports one and becomes a holdout. Upgrade it to cond_resched_tasks_rcu_qs(), which reports a quiescent state even when cond_resched() does nothing. PS: This has been discussed in [1]
Title mm/vmscan: report RCU-tasks quiescent states in shrink_lruvec()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:02:33.152Z

Reserved: 2026-09-11T19:38:34.763Z

Link: CVE-2026-89753

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:20:06.270

Modified: 2026-09-14T13:19:24.033

Link: CVE-2026-89753

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:46:56Z

Links: CVE-2026-89753 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T20:00:08Z

Weaknesses
  • CWE-821

    Incorrect Synchronization