CVE-2026-64415
Last modified
CVE-2026-64415 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: mm/swap: add cond_resched() in swap_reclaim_full_clusters to prevent softlockup We hit a real softlockup in an internal stress test environment. The workload was LTP memory/swap stress on a large arm64 machine, with 320 CPUs, about 1TB memory and an 8.6GB swap device. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: mm/swap: add cond_resched() in swap_reclaim_full_clusters to prevent softlockup We hit a real softlockup in an internal stress test environment. The workload was LTP memory/swap stress on a large arm64 machine, with 320 CPUs, about 1TB memory and an 8.6GB swap device. The system was under heavy load and the swap device had a large number of full clusters. The softlockup was triggered during a stress test after about 3 days. So, add periodic cond_resched() calls during large full_clusters reclaim operations to prevent softlockup issues. Detailed call trace as follow: PID: 3817773 TASK: ffff0883bb28b780 CPU: 48 COMMAND: "kworker/48:7" #0 [ffff800080183d10] __crash_kexec at ffffa4c1361e5de4 #1 [ffff800080183d90] panic at ffffa4c1360d5e9c #2 [ffff800080183e20] watchdog_timer_fn at ffffa4c136231fa8 ... #16 [ffff8000c4ad3cb0] swap_cache_del_folio at ffffa4c1363e1614 #17 [ffff8000c4ad3ce0] __try_to_reclaim_swap at ffffa4c1363e4bfc #18 [ffff8000c4ad3d40] swap_reclaim_full_clusters at ffffa4c1363e5474 #19 [ffff8000c4ad3da0] swap_reclaim_work at ffffa4c1363e550c #20 [ffff8000c4ad3dc0] process_one_work at ffffa4c136102edc #21 [ffff8000c4ad3e10] worker_thread at ffffa4c136103398 #22 [ffff8000c4ad3e70] kthread at ffffa4c13610d95c
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 5168a68eb78fa1c67a8b2d31d0642c7fd866cc12, < 60cbe67d1342f34b66df1c2ee328e3cd333767d7; >= 5168a68eb78fa1c67a8b2d31d0642c7fd866cc12, < 69c0e6246575b780ae0d3f411c749bcf13c221f3; >= 5168a68eb78fa1c67a8b2d31d0642c7fd866cc12, < 2a55fdf9f746a1a6ced7fd62ea1080b8a917e0b0; >= 5168a68eb78fa1c67a8b2d31d0642c7fd866cc12, < 66366d291f666ddeda5f8c84f253e308de3e6b55 |
| Linux | Linux | 6.12 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-64415?
How severe is CVE-2026-64415?
How do I fix CVE-2026-64415?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-6441The Canto plugin for WordPress is vulnerable to Missing Auth…4.3
- CVE-2026-64410In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-64411In the Linux kernel, the following vulnerability has been re…7.1
- CVE-2026-64412In the Linux kernel, the following vulnerability has been re…7.1
- CVE-2026-64413In the Linux kernel, the following vulnerability has been re…7
- CVE-2026-64414In the Linux kernel, the following vulnerability has been re…7.5
- CVE-2026-64416In the Linux kernel, the following vulnerability has been re…
- CVE-2026-64417In the Linux kernel, the following vulnerability has been re…
- CVE-2026-64418In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-64419In the Linux kernel, the following vulnerability has been re…
- CVE-2026-6442Improper validation of bash commands in Snowflake Cortex Cod…8.3
- CVE-2026-64420In the Linux kernel, the following vulnerability has been re…7
Are you affected by CVE-2026-64415?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
