CVE-2026-64248
Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
24/07/2026
Última modificación:
24/07/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
MIPS: smp: report dying CPU to RCU in stop_this_cpu()<br />
<br />
smp_send_stop() parks all secondary CPUs in stop_this_cpu(). The function<br />
marks the CPU offline for the scheduler via set_cpu_online(false) but<br />
never informs RCU, so RCU keeps expecting a quiescent state from CPUs<br />
that are now spinning forever with interrupts disabled.<br />
<br />
As long as nothing waits for an RCU grace period after smp_send_stop()<br />
this is harmless, which is why it went unnoticed. Since commit<br />
91840be8f710 ("irq_work: Fix use-after-free in irq_work_single() on PREEMPT_RT")<br />
however, irq_work_sync() calls synchronize_rcu() on architectures without<br />
an irq_work self-IPI, i.e. where arch_irq_work_has_interrupt() returns<br />
false. That is the asm-generic default used by MIPS. Any irq_work_sync()<br />
issued in the reboot/shutdown path after smp_send_stop() then blocks on<br />
a grace period that can never complete, hanging the reboot:<br />
<br />
WARNING: CPU: 0 PID: 15 at kernel/irq_work.c:144 irq_work_queue_on<br />
...<br />
rcu: INFO: rcu_sched detected stalls on CPUs/tasks:<br />
rcu: Offline CPU 1 blocking current GP.<br />
rcu: Offline CPU 2 blocking current GP.<br />
rcu: Offline CPU 3 blocking current GP.<br />
<br />
This issue was noticed on several Realtek MIPS switch SoCs (MIPS<br />
interAptiv) and came up during kernel bump downstream in OpenWrt from<br />
6.18.33 to 6.18.34, after the backport of the patch to the 6.18 stable<br />
branch. The patch also has been backported all the way back to 6.1.<br />
<br />
Call rcutree_report_cpu_dead() once interrupts are disabled, mirroring the<br />
generic CPU-hotplug offline path, so RCU stops waiting on the parked CPUs<br />
and grace periods can still complete. MIPS shuts down all CPUs here<br />
without going through the CPU-hotplug mechanism, so this report is not<br />
otherwise issued. Reporting a dying CPU to RCU outside the regular hotplug<br />
offline path is not unprecedented: arm64 does the same in cpu_die_early().<br />
There it is an exception for a CPU that was coming online and is aborting<br />
bringup, rather than the default shutdown action as on MIPS.
Impacto
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/6eda71977ee11c222f8ad4cae4d18d50448e56f4
- https://git.kernel.org/stable/c/9f3f3bdc6d9dac1a5a8262ee7ad0f2ff1527a7e7
- https://git.kernel.org/stable/c/9fef09df42df55ab819b285ea892e0fc1b95a9c4
- https://git.kernel.org/stable/c/e1919d026706544cb6e7251ec06e908edd6f34ee
- https://git.kernel.org/stable/c/f8a1ef884013dc99f712d3eb75624c7cd3fd94f6
- https://git.kernel.org/stable/c/f9b57a0015c241274651f4b36627f56b1b5a8651



