Junglewise Threat Intelligence

CVE-2026-90304: Linux kernel ARM interrupt handling in fault handlers

CVE-2026-90304 · Severity: info · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's ARM architecture fault handlers were not enabling interrupts before sending signals for unhandled user-mode faults. This incompatibility with PREEMPT_RT (a real-time kernel variant) could cause system instability when user programs trigger certain CPU faults, such as via the bkpt instruction in configurations without performance event support.

Technical details

This is a bug fix addressing a missing interrupt enable in the ARM data abort and prefetch abort handlers (do_DataAbort() and do_PrefetchAbort() in arch/arm/mm/fault.c). PREEMPT_RT requires interrupts to be enabled when sending signals via force_sig_fault(). When unhandled user-space faults occur and the interrupt state is not explicitly restored by the fault handler hook, force_sig_fault() would be called with interrupts disabled, violating PREEMPT_RT constraints. The fix adds local_irq_enable() calls after detecting unhandled user-mode faults. The vulnerability could be triggered by executing the bkpt instruction in user space when CONFIG_PERF_EVENTS is disabled. The fix has been patched in the upstream Linux kernel.

Affected products

  • Linux Linux kernel Affects ARM architecture implementations, fix available upstream

Timeline

  • 2026-09-17: disclosed
  • 2026-08-05: patched: Upstream patch committed

References

Related threats