← All Advisories

CVE-2026-90046

Last refreshed2026-10-10

Status: UPDATED  |  Advisory ID: CVE-2026-90046

Key Details

CVECVE-2026-90046
CVSS Score / Version7.8 (High) / CVSS v3.1
Updated2026-09-28
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsLinux Kernel

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux Kernel
SubsystemsOT Supporting Infrastructure
SectorsAll Sectors

What to Know

In the Linux kernel, the following vulnerability has been resolved:

mm/page_alloc: don't spin_trylock() in NMI on UP

Patch series "mm/page_alloc: fixes for free_pages_nolock() on RT/UP".

Pre-existing bugs found by Sashiko during review of this other series:

https://lore.kernel.org/all/[email protected]/

I have not reproduced these bugs, and I suspect there is no real-world

user that is affected by them.

This patch (of 2):

As noted in can_spin_trylock(), using this is unsafe in this context.

commit 620b46ed6ae17 ("mm/page_alloc: return NULL early from

alloc_frozen_pages_nolock() in NMI on UP") fixed this on the alloc side

but missed the free side.

Impact: If BPF programs using these features in NMI (probably tracing) are

present on non-SMP builds this might crash the kernel and is probably

exploitable by local attackers for privilege escalation. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-90046
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-90046