Junglewise Threat Intelligence

CVE-2026-64419: Linux kernel invalid sleep context in shrinker debugfs interface

CVE-2026-64419 · Severity: info · CVSS 0 · Published 2026-07-25

Technologies: Linux. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's memory management subsystem. When an administrator or authorized user attempts to read specific debug information related to memory usage, the system may encounter an internal error because it tries to perform a task that requires waiting while in a state where waiting is not allowed. This could lead to a system crash or instability, potentially causing a denial of service.

Technical details

The vulnerability is a programming error in mm/shrinker_debug.c where shrinker_debugfs_count_show() incorrectly holds an RCU read-side lock while invoking the count_objects() callback. In certain configurations, such as with zswap, this callback triggers css_rstat_flush(), which is a sleeping function. Calling a sleeping function within an RCU critical section is an invalid context in the Linux kernel. An attacker with access to debugfs could trigger this condition to cause a kernel BUG and subsequent system instability. The fix involves removing the unnecessary RCU lock, as the memory control group (memcg) and shrinker lifetimes are already managed by other mechanisms during the debugfs operation.

Affected products

  • Linux Linux 6.0 to 6.9.x

Timeline

  • 2026-06-10: disclosed: Initial patch submitted by Shakeel Butt
  • 2026-07-18: patched: Patch committed to stable tree by Greg Kroah-Hartman
  • 2026-07-25: advisory: CVE published in NVD dataset

References