CVE-2026-89756
Last modified
CVE-2026-89756 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: mm/migrate: report RCU-tasks quiescent states in migrate_pages_batch() migrate_pages_batch() unmaps each folio before moving it, and every unmap runs the mmu_notifier invalidate callbacks. On KVM hosts try_to_migrate() ends up in kvm_mmu_notifier_invalidate_range_start() -> tdp_mmu_zap_leafs(), which is expensive, so unmapping a large batch keeps the CPU busy for a long time. The loop already calls cond_resched(), but on PREEMPTION kernels that is a no-op, and involuntary preemption is not a Tasks-RCU quiescent state. A long batch therefore never reports a quiescent state, and the migrating task (e.g. EPSS estimates a 0.19% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: mm/migrate: report RCU-tasks quiescent states in migrate_pages_batch() migrate_pages_batch() unmaps each folio before moving it, and every unmap runs the mmu_notifier invalidate callbacks. On KVM hosts try_to_migrate() ends up in kvm_mmu_notifier_invalidate_range_start() -> tdp_mmu_zap_leafs(), which is expensive, so unmapping a large batch keeps the CPU busy for a long time. The loop already calls cond_resched(), but on PREEMPTION kernels that is a no-op, and involuntary preemption is not a Tasks-RCU quiescent state. A long batch therefore never reports a quiescent state, and the migrating task (e.g. kcompactd) becomes a Tasks-RCU holdout, stalling the Tasks-RCU grace period for minutes, which is common at Meta fleet: INFO: rcu_tasks detected stalls on tasks: 0000000055349ecc: .. nvcsw: 1157401/1157401 holdout: 1 idle_cpu: -1/56 task:kcompactd0 state:R running task Call Trace: tdp_mmu_zap_leafs tdp_mmu_next_root gfn_to_pfn_cache_invalidate_start kvm_mmu_notifier_invalidate_range_start __mmu_notifier_invalidate_range_start try_to_migrate_one try_to_migrate migrate_pages_batch migrate_pages compact_zone compact_node kcompactd kthread Use cond_resched_tasks_rcu_qs() so a quiescent state is reported even when cond_resched() does nothing. This has also been discussed at [1]
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 8315f42295d2667a7f942f154b73a86fd7cb2227, < 8c6d63d434ebb85c6cf3dac1e70a171b183c6614; >= 8315f42295d2667a7f942f154b73a86fd7cb2227, < 4757542649af56d894e25e30f57cd497dffad53f; >= 8315f42295d2667a7f942f154b73a86fd7cb2227, < 4996a7bc01ef35570664854dac2530c604981039; >= 8315f42295d2667a7f942f154b73a86fd7cb2227, < 5dc0daff0341c6baba19c38f47d299ac831d7e99; >= 8315f42295d2667a7f942f154b73a86fd7cb2227, < 66734981b4d3c105223a13c827c9c73be18d91ad; >= 8315f42295d2667a7f942f154b73a86fd7cb2227, < efe8f86c0916f0f74eea74ae21a3b37f728c6bad |
| Linux | Linux | 3.18 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-89756?
How severe is CVE-2026-89756?
How do I fix CVE-2026-89756?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-89750In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-89751In the Linux kernel, the following vulnerability has been re…
- CVE-2026-89752In the Linux kernel, the following vulnerability has been re…
- CVE-2026-89753In the Linux kernel, the following vulnerability has been re…
- CVE-2026-89754In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-89755In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-89757In the Linux kernel, the following vulnerability has been re…
- CVE-2026-89758In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-89759In the Linux kernel, the following vulnerability has been re…
- CVE-2026-8976The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, N…4.3
- CVE-2026-89760In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-89761In the Linux kernel, the following vulnerability has been re…7.8
Are you affected by CVE-2026-89756?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
