Description
In the Linux kernel, the following vulnerability has been resolved:

mm/page_alloc: don't spin_trylock() in NMI on UP

Patch series "mm/page_alloc: fixes for free_pages_nolock() on RT/UP".

Pre-existing bugs found by Sashiko during review of this other series:
https://lore.kernel.org/all/20260703-alloc-trylock-v5-0-c87b714e19d3@google.com/

I have not reproduced these bugs, and I suspect there is no real-world
user that is affected by them.


This patch (of 2):

As noted in can_spin_trylock(), using this is unsafe in this context.
commit 620b46ed6ae17 ("mm/page_alloc: return NULL early from
alloc_frozen_pages_nolock() in NMI on UP") fixed this on the alloc side
but missed the free side.

Impact: If BPF programs using these features in NMI (probably tracing) are
present on non-SMP builds this might crash the kernel and is probably
exploitable by local attackers for privilege escalation.
Published: 2026-09-16
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

The flaw is triggered when the Linux kernel attempts to acquire a spinlock during a Non‑Maskable Interrupt on a single‑processor configuration. The kernel incorrectly calls spin_trylock() in this context, which can lead to a crash or deadlock when the free_pages_nolock path is exercised. A local attacker can exploit this by executing a BPF program or other tracing code that uses the affected allocation routines while an NMI is pending, causing a system crash and potentially enabling privilege escalation.

Affected Systems

The vulnerability exists in all Linux kernel releases that support non‑SMP (UP) builds prior to the patch series “mm/page_alloc: fixes for free_pages_nolock() on RT/UP.” It affects every vendor that ships the kernel for single‑processor systems. Versions older than the patch are considered vulnerable; no specific version numbers are supplied in the data.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity. The EPSS score is below 1 %, suggesting that exploitation is technically possible but unlikely in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation would require local access, likely via a privileged user or a compromised application that can load malicious BPF code. The attack vector is local, and while the probability of exploitation is low, the impact of a kernel crash and privilege escalation is severe.

Generated by OpenCVE AI on September 18, 2026 at 05:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the kernel to a version that includes the mm/page_alloc patch series which fixes free_pages_nolock handling on RT/UP builds.
  • If upgrading is not feasible, disable NMI‑based BPF or tracing functionality on UP builds, or configure the kernel to avoid calling alloc_frozen_pages_nolock during NMIs.
  • For custom kernels, backport the commits from the patch series (including commit 620b46ed6ae17) to apply the fix.
  • Verify that the kernel is not configured for SMP on single‑processor systems or that NMIs are isolated from user‑space code that can trigger the bug.

Generated by OpenCVE AI on September 18, 2026 at 05:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 05:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: mm/page_alloc: don't spin_trylock() in NMI on UP Patch series "mm/page_alloc: fixes for free_pages_nolock() on RT/UP". Pre-existing bugs found by Sashiko during review of this other series: https://lore.kernel.org/all/20260703-alloc-trylock-v5-0-c87b714e19d3@google.com/ I have not reproduced these bugs, and I suspect there is no real-world user that is affected by them. This patch (of 2): As noted in can_spin_trylock(), using this is unsafe in this context. commit 620b46ed6ae17 ("mm/page_alloc: return NULL early from alloc_frozen_pages_nolock() in NMI on UP") fixed this on the alloc side but missed the free side. Impact: If BPF programs using these features in NMI (probably tracing) are present on non-SMP builds this might crash the kernel and is probably exploitable by local attackers for privilege escalation.
Title mm/page_alloc: don't spin_trylock() in NMI on UP
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:42:01.386Z

Reserved: 2026-09-11T19:38:34.783Z

Link: CVE-2026-90046

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:17.867

Modified: 2026-09-28T23:10:00.143

Link: CVE-2026-90046

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T05:30:04Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')