CVE-2026-89986

Source
https://cve.org/CVERecord?id=CVE-2026-89986
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89986.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-89986
Downstream
Published
2026-09-16T10:33:01Z
Modified
2026-09-17T03:47:20Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
mm/mempolicy: fix sleeping allocation in alloc_pages_bulk_weighted_interleave()
Details

In the Linux kernel, the following vulnerability has been resolved:

mm/mempolicy: fix sleeping allocation in alloc_pages_bulk_weighted_interleave()

syzbot reported a sleeping function called from invalid context splat in bucket_table_alloc().

When rhashtable_insert_slow() rehashes the table under rcu_read_lock(), it calls bucket_table_alloc(..., GFP_ATOMIC | __GFP_NOWARN). If the bucket table allocation uses vmalloc, __vmalloc_node_range_noprof() invokes vm_area_alloc_pages() -> alloc_pages_bulk_mempolicy_noprof() with the passed GFP_ATOMIC flags.

If the current task has an MPOL_WEIGHTED_INTERLEAVE mempolicy, alloc_pages_bulk_weighted_interleave() is called and currently hardcodes GFP_KERNEL when allocating the temporary weights array, triggering a might_alloc() splat in atomic/RCU contexts.

Pass the gfp flags (masked with GFP_RECLAIM_MASK to strip page-allocator zone modifiers like __GFP_HIGHMEM) received by alloc_pages_bulk_weighted_interleave() to kmalloc() instead of hardcoding GFP_KERNEL. Since the weights buffer is immediately initialized in full, kmalloc() is sufficient.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89986.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
fa3bea4e1f8202d787709b7e3654eb0a99aed758
Fixed
bcb3d0c867ee40dc48e9c085bf328fbc679b6656
Fixed
0ceda28f371df9e0bbdaa29214f71fe8298f23d8
Fixed
2943f1f4b7f2816177060eb9f551f2e6d8b629ba
Fixed
540e583b66d6402bf556fde5e53c817a54c1afe5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89986.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.9.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.51
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89986.json"