Executive brief
A vulnerability in the Linux kernel's networking component can cause the system to hang or become unresponsive when certain high-performance network polling features are enabled. This occurs because the system fails to properly manage internal housekeeping tasks during heavy network traffic, leading to a 'stall' that can disrupt operations and stop security tools from starting. An attacker could potentially exploit this to cause a denial-of-service condition.
Technical details
A vulnerability in the Linux kernel's NAPI threaded polling mechanism causes RCU (Read-Copy Update) task stalls. When threaded busypoll is enabled, the 'last_qs' (quiescent state) timestamp is incorrectly reset on every invocation of 'napi_threaded_poll_loop'. Because this loop rarely iterates more than once in busypoll mode, the 'rcu_softirq_qs_periodic' function fails to report a quiescent state, as it requires the timestamp to be at least 100ms old. This leads to grace period stalls, which can cause system hangs or prevent tools like bpftrace from initializing. The fix involves moving the 'last_qs' state to the outer 'napi_threaded_poll' function to ensure proper tracking across loop invocations.
Affected products
- Linux Linux Kernel 6.19 to 6.19.9
Timeline
- 2026-02-27: other: Patch authored
- 2026-05-08: disclosed: CVE published
- 2026-05-08: advisory