Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-64419

Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
25/07/2026
Última modificación:
25/07/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> mm/shrinker: do not hold RCU lock in shrinker_debugfs_count_show()<br /> <br /> Reading the debugfs "count" file of a memcg-aware shrinker can sleep<br /> inside an RCU read-side critical section:<br /> <br /> BUG: sleeping function called from invalid context at kernel/cgroup/rstat.c:421<br /> RCU nest depth: 1, expected: 0<br /> css_rstat_flush<br /> mem_cgroup_flush_stats<br /> zswap_shrinker_count<br /> shrinker_debugfs_count_show<br /> <br /> shrinker_debugfs_count_show() invokes the -&gt;count_objects() callback under<br /> rcu_read_lock(). The zswap callback flushes memcg stats via<br /> css_rstat_flush(), which may sleep, so it must not run under RCU.<br /> <br /> The RCU lock is not needed here. mem_cgroup_iter() takes RCU internally<br /> and returns a memcg holding a css reference (dropped on the next iteration<br /> or by mem_cgroup_iter_break()), so the memcg stays alive without it. The<br /> shrinker is kept alive by the open debugfs file: shrinker_free() removes<br /> the debugfs entries via debugfs_remove_recursive(), which waits for<br /> in-flight readers to drain, before call_rcu(..., shrinker_free_rcu_cb). <br /> The sibling "scan" handler already invokes the sleeping -&gt;scan_objects()<br /> callback with no RCU section.<br /> <br /> Drop the rcu_read_lock()/rcu_read_unlock().

Impacto