Executive brief
The Linux kernel's BPF (Berkeley Packet Filter) subsystem uses LRU (Least Recently Used) caches to manage memory efficiently for BPF programs. NMI (Non-Maskable Interrupt) and tracepoint handlers can cause the system to deadlock when they re-enter the same memory management locks that are already held, freezing kernel operations and requiring a restart to recover.
Technical details
The vulnerability is a recursive deadlock (AA-deadlock) in the BPF LRU list implementation, where NMI and tracepoint BPF programs re-enter per-CPU or global LRU locks already held by bpf_lru_pop_free() and bpf_lru_push_free() functions on the same CPU. Lockdep detected "inconsistent {INITIAL USE} -> {IN-NMI}" and "possible recursive locking detected" conditions. The fix converts all LRU lock sites from spinlock_t to rqspinlock_t (requestor/owner queue spinlock) and implements failure recovery paths to prevent node leaks and avoid complete deadlock. Attack vector is local (requires ability to load and trigger NMI/tracepoint BPF programs), and the impact is denial of service through kernel deadlock. A patch is available in Linux kernel mainline.
Affected products
- Linux Linux kernel All versions with BPF LRU list implementation (approximately 4.0 and later, particularly stable kernels before mid-2026)
Timeline
- 2026-08-15: disclosed
- 2026-06-07: patched