sched/psi: Shut down rtpoll_timer in psi_cgroup_free()
Summary
| CVE | CVE-2026-74594 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-22 16:16:31 UTC |
| Updated | 2026-08-22 16:16:31 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
sched/psi: Shut down rtpoll_timer in psi_cgroup_free()
psi_schedule_rtpoll_work() is called locklessly from the scheduler hotpath
and can race psi_trigger_destroy() taking down the last rtpoll trigger under
rtpoll_trigger_lock:
psi_schedule_rtpoll_work() psi_trigger_destroy()
rcu_read_lock();
task = rcu_dereference(rtpoll_task);
rcu_assign_pointer(rtpoll_task, NULL);
timer_delete(&rtpoll_timer);
mod_timer(&rtpoll_timer, ...);
rcu_read_unlock();
synchronize_rcu();
kthread_stop(task_to_destroy);
The group can then be freed with the re-armed timer still pending, and
poll_timer_fn() runs on freed memory.
461daba06bdc ("psi: eliminate kthread_worker from psi trigger scheduling
mechanism") deleted the timer synchronously after the synchronize_rcu(),
which prevented this but raced trigger creation instead: the deletion could
cancel the timer that a new trigger set armed during the grace period and,
as creation also reinitialized the timer at the time, corrupt it.
8f91efd870ea ("psi: Fix race between psi_trigger_create/destroy") moved the
initialization into group_init() and the deletion into the locked section,
trading the creation races for the window above.
Neither placement in the destruction path works. A pending timer firing
while the group is alive is harmless though. poll_timer_fn() just wakes the
rtpoll waitqueue and doesn't re-arm itself. Bind the timer to the group's
lifetime instead and shut it down in psi_cgroup_free(). Nothing can arm it
by then. timer_shutdown_sync() because the timer is never armed again. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected 8f91efd870ea5d8bc10b0fcc9740db51cd4c0c83 1e5ca82eee59caca6988f9d6e859786aab8a5fa0 git |
Not specified |
| CNA |
Linux |
Linux |
affected 8f91efd870ea5d8bc10b0fcc9740db51cd4c0c83 310b5a537a78c358a4cd244bd767c1a517a05459 git |
Not specified |
| CNA |
Linux |
Linux |
affected 8f91efd870ea5d8bc10b0fcc9740db51cd4c0c83 806fcff98c1d7cb3c1dc0015e55ebdbe819e6b08 git |
Not specified |
| CNA |
Linux |
Linux |
affected 8f91efd870ea5d8bc10b0fcc9740db51cd4c0c83 8037c5b2b2a447df52542f4d8535895d837bdcbd git |
Not specified |
| CNA |
Linux |
Linux |
affected 8f91efd870ea5d8bc10b0fcc9740db51cd4c0c83 611e7821c4f83a671455658797336faecc3a5196 git |
Not specified |
| CNA |
Linux |
Linux |
affected 8f91efd870ea5d8bc10b0fcc9740db51cd4c0c83 5457025fa8ca3c0d2732109513de839e3e797190 git |
Not specified |
| CNA |
Linux |
Linux |
affected 6bfcb6178925b1fd28c102e53d403091b8f49396 git |
Not specified |
| CNA |
Linux |
Linux |
affected e1e5e263bbe0e6e9c3db36aa48a3c8acf546fa49 git |
Not specified |
| CNA |
Linux |
Linux |
affected 979965c33f734a1666af67900408f997ac669c23 git |
Not specified |
| CNA |
Linux |
Linux |
affected 5.10.50 5.11 semver |
Not specified |
| CNA |
Linux |
Linux |
affected 5.12.17 5.13 semver |
Not specified |
| CNA |
Linux |
Linux |
affected 5.13.2 5.14 semver |
Not specified |
| CNA |
Linux |
Linux |
affected 5.14 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 5.14 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.1.183 6.1.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.6.152 6.6.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.104 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.45 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.1.9 7.1.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/806fcff98c1d7cb3c1dc0015e55ebdbe819e6b08 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/611e7821c4f83a671455658797336faecc3a5196 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/5457025fa8ca3c0d2732109513de839e3e797190 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/1e5ca82eee59caca6988f9d6e859786aab8a5fa0 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/310b5a537a78c358a4cd244bd767c1a517a05459 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/8037c5b2b2a447df52542f4d8535895d837bdcbd |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.