Description
In the Linux kernel, the following vulnerability has been resolved:

mm/mempolicy: fix sleeping allocation in alloc_pages_bulk_weighted_interleave()

syzbot reported a sleeping function called from invalid context splat in
bucket_table_alloc().

When rhashtable_insert_slow() rehashes the table under rcu_read_lock(), it
calls bucket_table_alloc(..., GFP_ATOMIC | __GFP_NOWARN). If the bucket
table allocation uses vmalloc, __vmalloc_node_range_noprof() invokes
vm_area_alloc_pages() -> alloc_pages_bulk_mempolicy_noprof() with the
passed GFP_ATOMIC flags.

If the current task has an MPOL_WEIGHTED_INTERLEAVE mempolicy,
alloc_pages_bulk_weighted_interleave() is called and currently hardcodes
GFP_KERNEL when allocating the temporary weights array, triggering a
might_alloc() splat in atomic/RCU contexts.

Pass the gfp flags (masked with GFP_RECLAIM_MASK to strip page-allocator
zone modifiers like __GFP_HIGHMEM) received by
alloc_pages_bulk_weighted_interleave() to kmalloc() instead of hardcoding
GFP_KERNEL. Since the weights buffer is immediately initialized in full,
kmalloc() is sufficient.
Published: 2026-09-16
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via kernel crash
Action: Immediate Patch
AI Analysis

Impact

During rehashing of a hash table under read-side critical section, a memory allocation request that can block is performed. The kernel mistakenly hardcodes the allocation flag GFP_KERNEL for a temporary weights array when the task has a weighted interleave memory policy. This causes a sleeping allocation inside an atomic or RCU context, leading to a potential kernel panic and system instability. The flaw does not provide direct remote code execution but can disrupt service by crashing the kernel, which is a severe impact on availability.

Affected Systems

The vulnerability affects the Linux kernel core, including all distributions running the affected kernel versions. No explicit version range is listed, so any kernel that contains the unpatched behavior is at risk.

Risk and Exploitability

The CVSS score of 7.8 indicates high risk, but the EPSS score of less than 1% suggests that exploitation is unlikely under current conditions. The bug is not listed in CISA’s KEV catalog, implying no known widespread exploitation. Attacks would require triggering kernel hash table rehash operations, which are generally part of normal kernel functionality and not easily controllable by external actors. Consequently, the risk is high but the exploitation probability is low, and the vulnerability primarily threatens local or system-wide availability.

Generated by OpenCVE AI on September 18, 2026 at 03:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest stable Linux kernel that includes the patch from commit 0ceda28f371df9e0bbdaa29214f71fe8298f23d8
  • If a kernel update cannot be applied immediately, use a kernel that avoids or limits rhashtable operations, such as configuring the system not to use weighted interleave memory policies or disabling kernel features that trigger hash table rehashing
  • Enable kernel crash dumping and monitoring to detect and recover from any accidental panics caused by this bug

Generated by OpenCVE AI on September 18, 2026 at 03:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-674
CWE-749

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: mm/mempolicy: fix sleeping allocation in alloc_pages_bulk_weighted_interleave() syzbot reported a sleeping function called from invalid context splat in bucket_table_alloc(). When rhashtable_insert_slow() rehashes the table under rcu_read_lock(), it calls bucket_table_alloc(..., GFP_ATOMIC | __GFP_NOWARN). If the bucket table allocation uses vmalloc, __vmalloc_node_range_noprof() invokes vm_area_alloc_pages() -> alloc_pages_bulk_mempolicy_noprof() with the passed GFP_ATOMIC flags. If the current task has an MPOL_WEIGHTED_INTERLEAVE mempolicy, alloc_pages_bulk_weighted_interleave() is called and currently hardcodes GFP_KERNEL when allocating the temporary weights array, triggering a might_alloc() splat in atomic/RCU contexts. Pass the gfp flags (masked with GFP_RECLAIM_MASK to strip page-allocator zone modifiers like __GFP_HIGHMEM) received by alloc_pages_bulk_weighted_interleave() to kmalloc() instead of hardcoding GFP_KERNEL. Since the weights buffer is immediately initialized in full, kmalloc() is sufficient.
Title mm/mempolicy: fix sleeping allocation in alloc_pages_bulk_weighted_interleave()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:41:02.502Z

Reserved: 2026-09-11T19:38:34.779Z

Link: CVE-2026-89986

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:09.653

Modified: 2026-09-16T15:18:22.557

Link: CVE-2026-89986

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T04:00:03Z

Weaknesses
  • CWE-674

    Uncontrolled Recursion

  • CWE-749

    Exposed Dangerous Method or Function