Executive brief
A vulnerability in the Linux kernel's process management could allow a local user to cause a system stall or crash. The issue occurs when the system handles multiple new processes (forks) simultaneously, leading to a synchronization error in how the kernel tracks memory identifiers. This can result in the operating system becoming unresponsive, impacting the availability of services and applications running on the affected machine.
Technical details
A race condition exists in the Linux kernel scheduler's MMCID implementation where a newly forked task is accounted as an MMCID user before it becomes visible in the process thread list. If a concurrent fork triggers a CID fixup (mm_cid_fixup_tasks_to_cpus) while the first task is in this 'invisible' state, the fixup fails to account for the first task's allocated CID. This leads to a state where subsequent scheduling attempts fail to acquire a valid CID, resulting in a kernel stall. The fix involves moving the sched_mm_cid_fork() call to occur after the task is visible in the thread and task lists. This is addressed in the stable kernel branches.
Affected products
- Linux Linux Kernel 6.19 to 6.19.9, 7.0-rc1 to 7.0-rc3
Timeline
- 2026-03-10: patched: Initial patch authored by Thomas Gleixner
- 2026-05-08: disclosed: CVE published by kernel.org
- 2026-05-22: advisory: NVD analysis and CVSS assignment completed