CVE-2026-93254

Summary

In the Linux kernel, the following vulnerability has been resolved:

arm64: entry: Avoid unnecessary local_irq_disable() on kernel exit

Currently, when exiting to kernel mode, we attempt involuntary preemption. The preemption logic expects IRQs to be disabled, which is why we call local_irq_disable() before attempting preemption.

However, depending on the context, local_irq_disable() may be unnecessary:

  • __el1_irq(), the non-NMI EL1 IRQ path, already has IRQs disabled, so local_irq_disable() is redundant.

  • irqentry_exit_to_kernel_mode_preempt() immediately returns when exiting from an NMI-like context, so calling local_irq_disable() beforehand is unnecessary work.

Furthermore, it confuses the pNMI state tracking when we are in a context with interrupts disabled and the GIC_PRIO_PSR_I_SET bit is set in the PMR, leading to a warning when CONFIG_ARM64_DEBUG_PRIORITY_MASKING=y:

 WARNING: ./arch/arm64/include/asm/irqflags.h:63 at arm64_exit_to_kernel_mode+0xb8/0xc0, CPU#40: retsnoop/31805
 CPU: 40 UID: 0 PID: 31805 Comm: retsnoop Not tainted 7.2.0-rc6-next-20260805 #7 PREEMPTLAZY
 pstate: 234013c9 (nzCv DAIF +PAN -UAO +TCO +DIT +SSBS BTYPE=--)
 pc : arm64_exit_to_kernel_mode (arch/arm64/kernel/entry-common.c:63)
 lr : el1_abort (arch/arm64/kernel/entry-common.c:323)
 pmr: 000000f0
 Call trace:
  arm64_exit_to_kernel_mode (arch/arm64/kernel/entry-common.c:63) (P)
  el1_abort (arch/arm64/kernel/entry-common.c:323)
  el1h_64_sync_handler (arch/arm64/kernel/entry-common.c:449)
  el1h_64_sync (arch/arm64/kernel/entry.S:589)
  [...]

Split arm64_exit_to_kernel_mode() into preempt, non-preempt, and dispatch parts so that we can avoid this extra work where it is not needed and avoid breaking the pNMI tracking logic.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxae654112eac05f316ef31587fc55e4d7160d0086 < 49a61174186bed25d439ff37400c7ce5e3603e73affected
LinuxLinuxae654112eac05f316ef31587fc55e4d7160d0086 < 39aebe0e89469c2904e60b1e977e0d4dbf33326baffected
LinuxLinux7.1affected
LinuxLinux0 < 7.1unaffected
LinuxLinux7.2.6 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References