CVE-2026-89753
Last modified
CVE-2026-89753 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: mm/vmscan: report RCU-tasks quiescent states in shrink_lruvec() I am seeing some rcu_tasks stalls in the Meta fleet during reclaim. INFO: rcu_tasks detected stalls on tasks: 0000000088620d09: .. nvcsw: 6735/6735 holdout: 1 idle_cpu: -1/8 task:GlobalCPUThread state:R running task pid:2552016 tgid:2524552 Call Trace: shrink_lruvec mem_cgroup_iter shrink_node do_try_to_free_pages try_to_free_pages __alloc_frozen_pages_noprof alloc_pages_noprof pte_alloc_one __pte_alloc handle_mm_fault Nothing promises direct reclaim returns in bounded time, and the scan loop in shrink_lruvec() only calls cond_resched(), which is a no-op on PREEMPTION kernels. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: mm/vmscan: report RCU-tasks quiescent states in shrink_lruvec() I am seeing some rcu_tasks stalls in the Meta fleet during reclaim. INFO: rcu_tasks detected stalls on tasks: 0000000088620d09: .. nvcsw: 6735/6735 holdout: 1 idle_cpu: -1/8 task:GlobalCPUThread state:R running task pid:2552016 tgid:2524552 Call Trace: shrink_lruvec mem_cgroup_iter shrink_node do_try_to_free_pages try_to_free_pages __alloc_frozen_pages_noprof alloc_pages_noprof pte_alloc_one __pte_alloc handle_mm_fault Nothing promises direct reclaim returns in bounded time, and the scan loop in shrink_lruvec() only calls cond_resched(), which is a no-op on PREEMPTION kernels. Involuntary preemption is not a Tasks-RCU quiescent state, so the reclaiming task never reports one and becomes a holdout. Upgrade it to cond_resched_tasks_rcu_qs(), which reports a quiescent state even when cond_resched() does nothing. PS: This has been discussed in [1]
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 8315f42295d2667a7f942f154b73a86fd7cb2227, < 4f50593c9cbc883d8c9b50148a3e8a8b1fd35f57; >= 8315f42295d2667a7f942f154b73a86fd7cb2227, < 4cdc1bdf40944de5c6b118fef07ad23f07844338; >= 8315f42295d2667a7f942f154b73a86fd7cb2227, < a67a00a70a7c8309ca47ea157ef3e8ed3d268f5b; >= 8315f42295d2667a7f942f154b73a86fd7cb2227, < 029c9408049f7f582230322057b7075bea594fd5; >= 8315f42295d2667a7f942f154b73a86fd7cb2227, < b5391676c61d94ffe3272dcf6723738b802f79e8; >= 8315f42295d2667a7f942f154b73a86fd7cb2227, < 3fd50239986302cb050d3649351bcec00fa9d5ab; >= 8315f42295d2667a7f942f154b73a86fd7cb2227, < cf3ba0911a1cf8680371ff113b90088edd01d2bb; >= 8315f42295d2667a7f942f154b73a86fd7cb2227, < 25f52e81216884a7444bf07a606691feb09a94e3 |
| Linux | Linux | 3.18 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-89753?
How severe is CVE-2026-89753?
How do I fix CVE-2026-89753?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-89748In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-89749In the Linux kernel, the following vulnerability has been re…
- CVE-2026-8975Memory safety bugs present in Firefox ESR 115.35, Firefox ES…8.8
- CVE-2026-89750In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-89751In the Linux kernel, the following vulnerability has been re…
- CVE-2026-89752In the Linux kernel, the following vulnerability has been re…
- CVE-2026-89754In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-89755In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-89756In the Linux kernel, the following vulnerability has been re…
- CVE-2026-89757In the Linux kernel, the following vulnerability has been re…
- CVE-2026-89758In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-89759In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2026-89753?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
