Description
In the Linux kernel, the following vulnerability has been resolved:

mm/migrate: report RCU-tasks quiescent states in migrate_pages_batch()

migrate_pages_batch() unmaps each folio before moving it, and every
unmap runs the mmu_notifier invalidate callbacks. On KVM hosts
try_to_migrate() ends up in kvm_mmu_notifier_invalidate_range_start() ->
tdp_mmu_zap_leafs(), which is expensive, so unmapping a large batch keeps
the CPU busy for a long time.

The loop already calls cond_resched(), but on PREEMPTION kernels that is
a no-op, and involuntary preemption is not a Tasks-RCU quiescent state.

A long batch therefore never reports a quiescent state, and the
migrating task (e.g. kcompactd) becomes a Tasks-RCU holdout, stalling the
Tasks-RCU grace period for minutes, which is common at Meta fleet:

INFO: rcu_tasks detected stalls on tasks:
0000000055349ecc: .. nvcsw: 1157401/1157401 holdout: 1 idle_cpu: -1/56 task:kcompactd0 state:R running task
Call Trace:
tdp_mmu_zap_leafs
tdp_mmu_next_root
gfn_to_pfn_cache_invalidate_start
kvm_mmu_notifier_invalidate_range_start
__mmu_notifier_invalidate_range_start
try_to_migrate_one
try_to_migrate
migrate_pages_batch
migrate_pages
compact_zone
compact_node
kcompactd
kthread

Use cond_resched_tasks_rcu_qs() so a quiescent state is reported even
when cond_resched() does nothing.

This has also been discussed at [1]
Published: 2026-09-11
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: RCU grace‑period stall causing system performance degradation
Action: Apply Patch
AI Analysis

Impact

The vulnerability originates from the missing RCU‑tasks quiescent state reporting in migrate_pages_batch(). Because cond_resched() is no‑op on PREEMPT kernels, large page‑migration batches keep a task (e.g., kcompactd) as an RCU hold‑out, preventing the grace period from ending. This stalls all Tasks‑RCU read side, causing latency and resource starvation when the grace period times out. The weakness is classified as CWE‑821, indicating weak scheduling for RCU release.

Affected Systems

The flaw exists in the Linux kernel for all configurations that enable PREEMPT and perform large migrate_pages_batch() operations, with particularly vulnerable. It impacts Linux kernel installations prior to the commit that adds cond_resched_tasks_rcu_qs() for batch migration. All affected kernel versions that support PREEMPT and substantial compaction tasks are therefore on the description, it is inferred that the vulnerability arises when large migrate_pages_batch() operations occur on PREEMPT kernels. The Linux kernel’s migrate_pages_batch() function does not report a Tasks‑RCU quiescent state during large memory‑migration batches on PREEMPT kernels. Because cond_resched() becomes a no‑op as kcompactd remains a holdout for the grace period. This blockage keeps the RCU grace period from ending for minutes, leading to amplified latency and resource starvation for RCU‑dependent operations. The weakness is classified as CWE‑821 (Weak Scheduling for RCU Release).

Risk and Exploitability

The CVSS score of 4.7 indicates moderate severity, but the EPSS of <1% and the lack of a CISA KEV listing suggest a low likelihood of exploitation. An attacker would need to trigger sustained, large‑batch page migrations, which configuration adjustments. The vulnerability does not provide code execution or data exfiltration; its primary risk is service degradation from prolonged RCU grace‑period stalls, detectable via the “rcu_tasks detected stalls” message in kernel logs.

Generated by OpenCVE AI on September 15, 2026 at 19:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the kernel to a version that incorporates the cond_resched_tasks_rcu_qs() patch for migrate_pages_batch() as referenced in the kernel commit advisory.
  • If an immediate update cannot be applied, reduce migration batch size or lower vm/compact_reclaim_ratio to avoid long compaction operations that can stall the grace period.
  • Continuously monitor kernel logs for the “rcu_tasks detected stalls” entry to confirm that holdouts no longer occur after applying the patch or configuration changes.

Generated by OpenCVE AI on September 15, 2026 at 19:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-821
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: mm/migrate: report RCU-tasks quiescent states in migrate_pages_batch() migrate_pages_batch() unmaps each folio before moving it, and every unmap runs the mmu_notifier invalidate callbacks. On KVM hosts try_to_migrate() ends up in kvm_mmu_notifier_invalidate_range_start() -> tdp_mmu_zap_leafs(), which is expensive, so unmapping a large batch keeps the CPU busy for a long time. The loop already calls cond_resched(), but on PREEMPTION kernels that is a no-op, and involuntary preemption is not a Tasks-RCU quiescent state. A long batch therefore never reports a quiescent state, and the migrating task (e.g. kcompactd) becomes a Tasks-RCU holdout, stalling the Tasks-RCU grace period for minutes, which is common at Meta fleet: INFO: rcu_tasks detected stalls on tasks: 0000000055349ecc: .. nvcsw: 1157401/1157401 holdout: 1 idle_cpu: -1/56 task:kcompactd0 state:R running task Call Trace: tdp_mmu_zap_leafs tdp_mmu_next_root gfn_to_pfn_cache_invalidate_start kvm_mmu_notifier_invalidate_range_start __mmu_notifier_invalidate_range_start try_to_migrate_one try_to_migrate migrate_pages_batch migrate_pages compact_zone compact_node kcompactd kthread Use cond_resched_tasks_rcu_qs() so a quiescent state is reported even when cond_resched() does nothing. This has also been discussed at [1]
Title mm/migrate: report RCU-tasks quiescent states in migrate_pages_batch()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:02:34.256Z

Reserved: 2026-09-11T19:38:34.763Z

Link: CVE-2026-89756

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:20:06.643

Modified: 2026-09-14T13:19:24.170

Link: CVE-2026-89756

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:46:59Z

Links: CVE-2026-89756 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T20:00:08Z

Weaknesses
  • CWE-821

    Incorrect Synchronization