Junglewise Threat Intelligence

CVE-2026-64415: Linux Kernel soft lockup in swap_reclaim_full_clusters

CVE-2026-64415 · Severity: info · CVSS 4.1 · Published 2026-07-25

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's memory management system can cause a system to become unresponsive or crash under heavy load. This occurs when the system is managing large amounts of memory and swap space, leading to a 'soft lockup' where the processor is stuck in a loop and cannot perform other tasks. This could result in a service outage or system instability in high-performance computing environments.

Technical details

A soft lockup vulnerability exists in the Linux kernel's mm/swap component within the swap_reclaim_full_clusters function. On large-scale systems (e.g., 320 CPUs, 1TB RAM), heavy memory stress can cause the swap reclaim process to iterate through a large number of full clusters without yielding the CPU. This lack of scheduling points triggers the kernel's watchdog timer, leading to a kernel panic. The fix introduces periodic cond_resched() calls within the reclaim loop to ensure the CPU can handle other tasks. This is primarily reachable under local stress conditions and impacts system availability.

Affected products

  • Linux Linux Kernel 6.12, 6.18, 7.1

Timeline

  • 2026-05-06: disclosed: Initial patch submission by Zijiang Huang
  • 2026-07-18: patched: Commits merged into stable branches
  • 2026-07-25: advisory: CVE-2026-64415 published

References

Related threats