Impact
The vulnerability originates from the missing RCU‑tasks quiescent state reporting in migrate_pages_batch(). Because cond_resched() is no‑op on PREEMPT kernels, large page‑migration batches keep a task (e.g., kcompactd) as an RCU hold‑out, preventing the grace period from ending. This stalls all Tasks‑RCU read side, causing latency and resource starvation when the grace period times out. The weakness is classified as CWE‑821, indicating weak scheduling for RCU release.
Affected Systems
The flaw exists in the Linux kernel for all configurations that enable PREEMPT and perform large migrate_pages_batch() operations, with particularly vulnerable. It impacts Linux kernel installations prior to the commit that adds cond_resched_tasks_rcu_qs() for batch migration. All affected kernel versions that support PREEMPT and substantial compaction tasks are therefore on the description, it is inferred that the vulnerability arises when large migrate_pages_batch() operations occur on PREEMPT kernels. The Linux kernel’s migrate_pages_batch() function does not report a Tasks‑RCU quiescent state during large memory‑migration batches on PREEMPT kernels. Because cond_resched() becomes a no‑op as kcompactd remains a holdout for the grace period. This blockage keeps the RCU grace period from ending for minutes, leading to amplified latency and resource starvation for RCU‑dependent operations. The weakness is classified as CWE‑821 (Weak Scheduling for RCU Release).
Risk and Exploitability
The CVSS score of 4.7 indicates moderate severity, but the EPSS of <1% and the lack of a CISA KEV listing suggest a low likelihood of exploitation. An attacker would need to trigger sustained, large‑batch page migrations, which configuration adjustments. The vulnerability does not provide code execution or data exfiltration; its primary risk is service degradation from prolonged RCU grace‑period stalls, detectable via the “rcu_tasks detected stalls” message in kernel logs.
OpenCVE Enrichment
Debian DSA