{"api_version":"1","generated_at":"2026-07-24T21:50:55+00:00","cve":"CVE-2026-64211","urls":{"html":"https://cve.report/CVE-2026-64211","api":"https://cve.report/api/cve/CVE-2026-64211.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-64211","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-64211"},"summary":{"title":"srcu: Don't queue workqueue handlers to never-online CPUs","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsrcu: Don't queue workqueue handlers to never-online CPUs\n\nWhile an srcu_struct structure is in the midst of switching from CPU-0\nto all-CPUs state, it can attempt to invoke callbacks for CPUs that\nhave never been online.  Worse yet, it can attempt in invoke callbacks\nfor CPUs that never will be online, even including imaginary CPUs not in\ncpu_possible_mask.  This can cause hangs on s390, which is not set up to\ndeal with workqueue handlers being scheduled on such CPUs.  This commit\ntherefore causes Tree SRCU to refrain from queueing workqueue handlers\non CPUs that have not yet (and might never) come online.\n\nBecause callbacks are not invoked on CPUs that have not been\nonline, it is an error to invoke call_srcu(), synchronize_srcu(), or\nsynchronize_srcu_expedited() on a CPU that is not yet fully online.\nHowever, it turns out to be less code to redirect the callbacks\nfrom too-early invocations of call_srcu() than to warn about such\ninvocations.  This commit therefore also redirects callbacks queued on\nnot-yet-fully-online CPUs to the boot CPU.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-07-24 16:16:48","updated_at":"2026-07-24 16:16:48"},"problem_types":[],"metrics":[],"references":[{"url":"https://git.kernel.org/stable/c/593889c401426004bd0ea0f6d4fcece728b03420","name":"https://git.kernel.org/stable/c/593889c401426004bd0ea0f6d4fcece728b03420","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/a4153538fcd2361c4e0039eb103265492d26044e","name":"https://git.kernel.org/stable/c/a4153538fcd2361c4e0039eb103265492d26044e","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-64211","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-64211","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 61bbcfb50514a8a94e035a7349697a3790ab4783 a4153538fcd2361c4e0039eb103265492d26044e git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 61bbcfb50514a8a94e035a7349697a3790ab4783 593889c401426004bd0ea0f6d4fcece728b03420 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 7.0","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.0 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.0.11 7.0.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["kernel/rcu/srcutree.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"a4153538fcd2361c4e0039eb103265492d26044e","status":"affected","version":"61bbcfb50514a8a94e035a7349697a3790ab4783","versionType":"git"},{"lessThan":"593889c401426004bd0ea0f6d4fcece728b03420","status":"affected","version":"61bbcfb50514a8a94e035a7349697a3790ab4783","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["kernel/rcu/srcutree.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"7.0"},{"lessThan":"7.0","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"7.0.*","status":"unaffected","version":"7.0.11","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.1","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.0.11","versionStartIncluding":"7.0","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1","versionStartIncluding":"7.0","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsrcu: Don't queue workqueue handlers to never-online CPUs\n\nWhile an srcu_struct structure is in the midst of switching from CPU-0\nto all-CPUs state, it can attempt to invoke callbacks for CPUs that\nhave never been online.  Worse yet, it can attempt in invoke callbacks\nfor CPUs that never will be online, even including imaginary CPUs not in\ncpu_possible_mask.  This can cause hangs on s390, which is not set up to\ndeal with workqueue handlers being scheduled on such CPUs.  This commit\ntherefore causes Tree SRCU to refrain from queueing workqueue handlers\non CPUs that have not yet (and might never) come online.\n\nBecause callbacks are not invoked on CPUs that have not been\nonline, it is an error to invoke call_srcu(), synchronize_srcu(), or\nsynchronize_srcu_expedited() on a CPU that is not yet fully online.\nHowever, it turns out to be less code to redirect the callbacks\nfrom too-early invocations of call_srcu() than to warn about such\ninvocations.  This commit therefore also redirects callbacks queued on\nnot-yet-fully-online CPUs to the boot CPU."}],"providerMetadata":{"dateUpdated":"2026-07-24T15:23:01.889Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/a4153538fcd2361c4e0039eb103265492d26044e"},{"url":"https://git.kernel.org/stable/c/593889c401426004bd0ea0f6d4fcece728b03420"}],"title":"srcu: Don't queue workqueue handlers to never-online CPUs","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-64211","datePublished":"2026-07-24T15:23:01.889Z","dateReserved":"2026-07-19T15:36:31.769Z","dateUpdated":"2026-07-24T15:23:01.889Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-07-24 16:16:48","lastModifiedDate":"2026-07-24 16:16:48","problem_types":[],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"64211","Ordinal":"1","Title":"srcu: Don't queue workqueue handlers to never-online CPUs","CVE":"CVE-2026-64211","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"64211","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nsrcu: Don't queue workqueue handlers to never-online CPUs\n\nWhile an srcu_struct structure is in the midst of switching from CPU-0\nto all-CPUs state, it can attempt to invoke callbacks for CPUs that\nhave never been online.  Worse yet, it can attempt in invoke callbacks\nfor CPUs that never will be online, even including imaginary CPUs not in\ncpu_possible_mask.  This can cause hangs on s390, which is not set up to\ndeal with workqueue handlers being scheduled on such CPUs.  This commit\ntherefore causes Tree SRCU to refrain from queueing workqueue handlers\non CPUs that have not yet (and might never) come online.\n\nBecause callbacks are not invoked on CPUs that have not been\nonline, it is an error to invoke call_srcu(), synchronize_srcu(), or\nsynchronize_srcu_expedited() on a CPU that is not yet fully online.\nHowever, it turns out to be less code to redirect the callbacks\nfrom too-early invocations of call_srcu() than to warn about such\ninvocations.  This commit therefore also redirects callbacks queued on\nnot-yet-fully-online CPUs to the boot CPU.","Type":"Description","Title":"srcu: Don't queue workqueue handlers to never-online CPUs"}]}}}