Description
In the Linux kernel, the following vulnerability has been resolved:

ARM: 9483/1: select HAVE_POSIX_CPU_TIMERS_TASK_WORK

Commit c6e61c06d606 ("ARM: 9463/1: Allow to enable RT") enabled PREEMPT_RT
on ARM but did not select HAVE_POSIX_CPU_TIMERS_TASK_WORK. This leaves
CONFIG_POSIX_CPU_TIMERS_TASK_WORK disabled, so CPU timers expire in hard
IRQ context.

On PREEMPT_RT this makes run_posix_cpu_timers() take the sleeping
sighand->siglock:

BUG: sleeping function called from invalid context at spinlock_rt.c:48
rt_spin_lock from lock_task_sighand
lock_task_sighand from run_posix_cpu_timers
run_posix_cpu_timers from update_process_times

ARM handles TIF_NOTIFY_RESUME on all return-to-user paths, including v7-M.
ARM32 KVM host support was removed by commit 541ad0150ca4 ("arm: Remove
32bit KVM host support"), so the select need not be conditional on KVM.

Select it to defer POSIX CPU timer expiry to task context.

Reproduced with setrlimit(RLIMIT_CPU, ...) and a busy loop. The same path
is used by setitimer(ITIMER_PROF or ITIMER_VIRTUAL) and POSIX CPU timers
created with timer_create().
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel instability caused by sleeping function invoked in interrupt context leading to system hang or crash
Action: Immediate Patch
AI Analysis

Impact

This vulnerability arises when the Linux ARM kernel is compiled with PREEMPT_RT enabled but the option HAVE_POSIX_CPU_TIMERS_TASK_WORK is left disabled. The result is that CPU timers expire in hard IRQ context, causing the run_posix_cpu_timers routine to acquire the task sighand->siglock while in an invalid sleeping state. This triggers a BUG condition and can lead to a kernel panic or system hang, thereby impacting availability.

Affected Systems

The flaw affects all Linux kernel builds that support ARM architectures and are compiled with the PREEMPT_RT patchset. Specifically, any kernel configuration that enables PREEMPT_RT yet fails to select HAVE_POSIX_CPU_TIMERS_TASK_WORK is vulnerable. The issue is present in generic Linux kernels for ARM, including ARM64 and ARM32, and would apply to hosted environments such as KVM when ARM32 host support is present, but that support was removed in later commits.

Risk and Exploitability

The CVSS severity is not explicitly provided, but the nature of the bug—kernel panic from sleeping in interrupt context—is a high‑severity flaw. The EPSS score is less than 1%, indicating low probability of exploitation in the wild, and the vulnerability is not listed in CISA KEV. The likely attack vector would require privileged access to trigger CPU timers under PREEMPT_RT, such as via a setrlimit(RLIMIT_CPU) abuse or by eliciting timer_create calls. However, due to the contextual requirement and the low EPSS, immediate remediation is advised rather than relying on detection of exploit attempts.

Generated by OpenCVE AI on September 19, 2026 at 15:04 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Enable the kernel configuration option HAVE_POSIX_CPU_TIMERS_TASK_WORK when building a kernel with PREEMPT_RT enabled.
  • Rebuild and deploy the updated kernel to all affected ARM‑based systems.
  • If real‑time performance is not required, disable PREEMPT_RT to avoid hard IRQ context issues with CPU timers.

Generated by OpenCVE AI on September 19, 2026 at 15:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-665

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ARM: 9483/1: select HAVE_POSIX_CPU_TIMERS_TASK_WORK Commit c6e61c06d606 ("ARM: 9463/1: Allow to enable RT") enabled PREEMPT_RT on ARM but did not select HAVE_POSIX_CPU_TIMERS_TASK_WORK. This leaves CONFIG_POSIX_CPU_TIMERS_TASK_WORK disabled, so CPU timers expire in hard IRQ context. On PREEMPT_RT this makes run_posix_cpu_timers() take the sleeping sighand->siglock: BUG: sleeping function called from invalid context at spinlock_rt.c:48 rt_spin_lock from lock_task_sighand lock_task_sighand from run_posix_cpu_timers run_posix_cpu_timers from update_process_times ARM handles TIF_NOTIFY_RESUME on all return-to-user paths, including v7-M. ARM32 KVM host support was removed by commit 541ad0150ca4 ("arm: Remove 32bit KVM host support"), so the select need not be conditional on KVM. Select it to defer POSIX CPU timer expiry to task context. Reproduced with setrlimit(RLIMIT_CPU, ...) and a busy loop. The same path is used by setitimer(ITIMER_PROF or ITIMER_VIRTUAL) and POSIX CPU timers created with timer_create().
Title ARM: 9483/1: select HAVE_POSIX_CPU_TIMERS_TASK_WORK
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:08:27.742Z

Reserved: 2026-09-11T19:38:34.800Z

Link: CVE-2026-90305

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:28.163

Modified: 2026-09-17T17:17:28.163

Link: CVE-2026-90305

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T15:15:14Z

Weaknesses