CVE-2026-89753

Summary

In the Linux kernel, the following vulnerability has been resolved:

mm/vmscan: report RCU-tasks quiescent states in shrink_lruvec()

I am seeing some rcu_tasks stalls in the Meta fleet during reclaim.

INFO: rcu_tasks detected stalls on tasks: 0000000088620d09: .. nvcsw: 6735/6735 holdout: 1 idle_cpu: -1/8 task:GlobalCPUThread state:R running task pid:2552016 tgid:2524552 Call Trace: shrink_lruvec mem_cgroup_iter shrink_node do_try_to_free_pages try_to_free_pages __alloc_frozen_pages_noprof alloc_pages_noprof pte_alloc_one __pte_alloc handle_mm_fault

Nothing promises direct reclaim returns in bounded time, and the scan loop in shrink_lruvec() only calls cond_resched(), which is a no-op on PREEMPTION kernels. Involuntary preemption is not a Tasks-RCU quiescent state, so the reclaiming task never reports one and becomes a holdout.

Upgrade it to cond_resched_tasks_rcu_qs(), which reports a quiescent state even when cond_resched() does nothing.

PS: This has been discussed in [1]

Affected Software

VendorProductVersion RangeStatus
LinuxLinux1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < b5391676c61d94ffe3272dcf6723738b802f79e8affected
LinuxLinux1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 3fd50239986302cb050d3649351bcec00fa9d5abaffected
LinuxLinux1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < cf3ba0911a1cf8680371ff113b90088edd01d2bbaffected
LinuxLinux1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 25f52e81216884a7444bf07a606691feb09a94e3affected
LinuxLinux0 < 6.12.109affected
LinuxLinux0 < 6.18.50affected
LinuxLinux0 < 7.2.4affected
LinuxLinux6.12.109 <= 6.12.*unaffected
LinuxLinux6.18.50 <= 6.18.*unaffected
LinuxLinux7.2.4 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References