Junglewise Threat Intelligence

CVE-2026-64477: Linux Kernel out-of-bounds access in x86 resctrl during CPU offline

CVE-2026-64477 · Severity: info · CVSS 0 · Published 2026-07-25

Technologies: Linux. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's resource control (resctrl) subsystem on x86 systems. This issue occurs when a processor is being taken offline on systems with Sub-NUMA Clustering (SNC) enabled, potentially leading to an unstable system state or crash. While primarily a stability concern, it affects how the operating system manages hardware resources and monitoring data.

Technical details

An out-of-bounds access vulnerability exists in the Linux kernel's x86 resctrl monitoring domain logic. When a monitoring domain is offlined, its cpu_mask is cleared; however, the 'limbo handler' (responsible for clearing busy RMID states) may still attempt to read the RMID. On SNC-enabled systems, converting a logical RMID to a physical RMID requires a NUMA node ID derived from the domain's CPU mask. Because the mask is empty during offlining, the query uses an invalid CPU ID (nr_cpu_ids), leading to an out-of-bounds access. The fix refactors the limbo handler to skip RMID reads during forced domain offlining and adds a safety check to the RMID reader.

Affected products

  • Linux Linux 6.11, 6.12.96

Timeline

  • 2026-07-25: disclosed
  • 2026-07-25: advisory

References