Junglewise Threat Intelligence

CVE-2026-68438: Linux kernel SMP CSD lock race condition causing system hang

CVE-2026-68438 · Severity: info · Published 2026-08-12

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's inter-processor communication system (SMP) has a race condition in CSD (Call Stack Data) lock handling that can cause CPUs to deadlock or trigger soft-lockup panics. When debugging is enabled, multiple CPUs can corrupt shared data structures used to queue work across processors, resulting in system hangs that block critical operations like TLB shootdowns.

Technical details

The vulnerability is a race condition in the csd_lock() function within kernel/smp.c. When CSD lock debugging is enabled, the smp_call_function_single() routine can allow multiple CPUs to concurrently access and modify the same destination CPU's CSD structure. The original non-atomic read-modify-write of CSD_FLAG_LOCK allows two senders to both see the lock as unlocked, acquire it, and corrupt the linked list node by making node->next point to itself. This leaves the target CPU stuck in an infinite loop while walking call_single_queue, blocking synchronous work such as TLB shootdowns and triggering soft-lockup warnings or kernel panics. The fix replaces the non-atomic lock acquisition with try_cmpxchg_acquire() in debug mode, making CSD_FLAG_LOCK a proper atomic lock only when it can be shared, while preserving the fast path for non-debug builds.

Affected products

  • Linux Linux kernel Affected versions with CSD lock debugging enabled (CONFIG_CSD_LOCK_WAIT_DEBUG)

Timeline

  • 2026-08-12: disclosed: Published in NVD
  • 2026-07-15: patched: Fix committed upstream by Chuyi Zhou
  • 2026-08-03: other: Backported to stable kernels

References

Related threats