Junglewise Threat Intelligence

CVE-2026-74337: Linux kernel BPF LRU lock deadlock in NMI/tracepoint handlers

CVE-2026-74337 · Severity: info · CVSS 6.5 · Published 2026-08-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's BPF (Berkeley Packet Filter) subsystem uses LRU (Least Recently Used) caches to manage memory efficiently for BPF programs. NMI (Non-Maskable Interrupt) and tracepoint handlers can cause the system to deadlock when they re-enter the same memory management locks that are already held, freezing kernel operations and requiring a restart to recover.

Technical details

The vulnerability is a recursive deadlock (AA-deadlock) in the BPF LRU list implementation, where NMI and tracepoint BPF programs re-enter per-CPU or global LRU locks already held by bpf_lru_pop_free() and bpf_lru_push_free() functions on the same CPU. Lockdep detected "inconsistent {INITIAL USE} -> {IN-NMI}" and "possible recursive locking detected" conditions. The fix converts all LRU lock sites from spinlock_t to rqspinlock_t (requestor/owner queue spinlock) and implements failure recovery paths to prevent node leaks and avoid complete deadlock. Attack vector is local (requires ability to load and trigger NMI/tracepoint BPF programs), and the impact is denial of service through kernel deadlock. A patch is available in Linux kernel mainline.

Affected products

  • Linux Linux kernel All versions with BPF LRU list implementation (approximately 4.0 and later, particularly stable kernels before mid-2026)

Timeline

  • 2026-08-15: disclosed
  • 2026-06-07: patched

References

Related threats