Linux Kernel NMI page_alloc spin_trylock flaw: local privilege escalation
CVE-2026-90046 Published on September 16, 2026
mm/page_alloc: don't spin_trylock() in NMI on UP
In the Linux kernel, the following vulnerability has been resolved:
mm/page_alloc: don't spin_trylock() in NMI on UP
Patch series "mm/page_alloc: fixes for free_pages_nolock() on RT/UP".
Pre-existing bugs found by Sashiko during review of this other series:
https://lore.kernel.org/all/20260703-alloc-trylock-v5-0-c87b714e19d3@google.com/
I have not reproduced these bugs, and I suspect there is no real-world
user that is affected by them.
This patch (of 2):
As noted in can_spin_trylock(), using this is unsafe in this context.
commit 620b46ed6ae17 ("mm/page_alloc: return NULL early from
alloc_frozen_pages_nolock() in NMI on UP") fixed this on the alloc side
but missed the free side.
Impact: If BPF programs using these features in NMI (probably tracing) are
present on non-SMP builds this might crash the kernel and is probably
exploitable by local attackers for privilege escalation.
Products Associated with CVE-2026-90046
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version 8c57b687e8331eb80e302a2c528b18b966a9ac7a and below 06c76d3c389ff504052f64b1acee44651bd847fa is affected.
- Version 8c57b687e8331eb80e302a2c528b18b966a9ac7a and below 68a069b407303e71db371df85036101e8ff59280 is affected.
- Version 8c57b687e8331eb80e302a2c528b18b966a9ac7a and below 3105ae628fb785d48b49256468be4f21a7b3cfc0 is affected.
- Version 6.15 is affected.
- Before 6.15 is unaffected.
- Version 6.18.51, <= 6.18.* is unaffected.
- Version 7.2.5, <= 7.2.* is unaffected.
- Version 7.3-rc1, <= * is unaffected.