Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-64248

Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
24/07/2026
Última modificación:
24/07/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> MIPS: smp: report dying CPU to RCU in stop_this_cpu()<br /> <br /> smp_send_stop() parks all secondary CPUs in stop_this_cpu(). The function<br /> marks the CPU offline for the scheduler via set_cpu_online(false) but<br /> never informs RCU, so RCU keeps expecting a quiescent state from CPUs<br /> that are now spinning forever with interrupts disabled.<br /> <br /> As long as nothing waits for an RCU grace period after smp_send_stop()<br /> this is harmless, which is why it went unnoticed. Since commit<br /> 91840be8f710 ("irq_work: Fix use-after-free in irq_work_single() on PREEMPT_RT")<br /> however, irq_work_sync() calls synchronize_rcu() on architectures without<br /> an irq_work self-IPI, i.e. where arch_irq_work_has_interrupt() returns<br /> false. That is the asm-generic default used by MIPS. Any irq_work_sync()<br /> issued in the reboot/shutdown path after smp_send_stop() then blocks on<br /> a grace period that can never complete, hanging the reboot:<br /> <br /> WARNING: CPU: 0 PID: 15 at kernel/irq_work.c:144 irq_work_queue_on<br /> ...<br /> rcu: INFO: rcu_sched detected stalls on CPUs/tasks:<br /> rcu: Offline CPU 1 blocking current GP.<br /> rcu: Offline CPU 2 blocking current GP.<br /> rcu: Offline CPU 3 blocking current GP.<br /> <br /> This issue was noticed on several Realtek MIPS switch SoCs (MIPS<br /> interAptiv) and came up during kernel bump downstream in OpenWrt from<br /> 6.18.33 to 6.18.34, after the backport of the patch to the 6.18 stable<br /> branch. The patch also has been backported all the way back to 6.1.<br /> <br /> Call rcutree_report_cpu_dead() once interrupts are disabled, mirroring the<br /> generic CPU-hotplug offline path, so RCU stops waiting on the parked CPUs<br /> and grace periods can still complete. MIPS shuts down all CPUs here<br /> without going through the CPU-hotplug mechanism, so this report is not<br /> otherwise issued. Reporting a dying CPU to RCU outside the regular hotplug<br /> offline path is not unprecedented: arm64 does the same in cpu_die_early().<br /> There it is an exception for a CPU that was coming online and is aborting<br /> bringup, rather than the default shutdown action as on MIPS.

Impacto