Executive brief
The Linux kernel's ARM architecture fault handlers were not enabling interrupts before sending signals for unhandled user-mode faults. This incompatibility with PREEMPT_RT (a real-time kernel variant) could cause system instability when user programs trigger certain CPU faults, such as via the bkpt instruction in configurations without performance event support.
Technical details
This is a bug fix addressing a missing interrupt enable in the ARM data abort and prefetch abort handlers (do_DataAbort() and do_PrefetchAbort() in arch/arm/mm/fault.c). PREEMPT_RT requires interrupts to be enabled when sending signals via force_sig_fault(). When unhandled user-space faults occur and the interrupt state is not explicitly restored by the fault handler hook, force_sig_fault() would be called with interrupts disabled, violating PREEMPT_RT constraints. The fix adds local_irq_enable() calls after detecting unhandled user-mode faults. The vulnerability could be triggered by executing the bkpt instruction in user space when CONFIG_PERF_EVENTS is disabled. The fix has been patched in the upstream Linux kernel.
Affected products
- Linux Linux kernel Affects ARM architecture implementations, fix available upstream
Timeline
- 2026-09-17: disclosed
- 2026-08-05: patched: Upstream patch committed