Executive brief
A vulnerability in the Linux kernel's memory management system can lead to internal data corruption on systems configured without Symmetric Multi-Processing (SMP). This issue occurs when the system's page allocation process is interrupted, potentially allowing for system instability or unauthorized access to sensitive information. The flaw primarily affects single-processor systems or specific embedded configurations.
Technical details
A race condition exists in mm/page_alloc.c when the kernel is compiled with SMP=n. In the drain_page_zone() function, the code enters a critical section protected by spin_lock(&pcp->lock) without disabling interrupts. If an interrupt occurs during this section and attempts a spin_trylock() on the same lock, the SMP=n spinlock implementation (which treats trylock as a no-op that always succeeds) fails to prevent nested access. This leads to corruption of the pcp structure. The fix introduces local wrappers that upgrade spin_lock to spin_lock_irqsave on non-SMP systems to ensure atomicity against interrupts.
Affected products
- Linux Linux Kernel 6.1.57 to 6.1.162, 6.2.1 to 6.6.122, 6.7 to 6.12.67, 6.13 to 6.18.7
Timeline
- 2026-01-05: patched: Initial patch authored by Vlastimil Babka
- 2026-01-31: disclosed: CVE published
References
- https://git.kernel.org/stable/c/038a102535eb49e10e93eafac54352fcc5d78847
- https://git.kernel.org/stable/c/3098f8f7c7b0686c74827aec42a2c45e69801ff8
- https://git.kernel.org/stable/c/4a04ff9cd816e7346fcc8126f00ed80481f6569d
- https://git.kernel.org/stable/c/68688fc4eab007834b4c2d740214423ba2a335a8
- https://git.kernel.org/stable/c/df63d31e9ae02e2f6cd96147779e4ed7cd0e75f6
- https://cert-portal.siemens.com/productcert/html/ssa-253495.html