CVE-2026-93254

Source
https://cve.org/CVERecord?id=CVE-2026-93254
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93254.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-93254
Downstream
Published
2026-09-24T15:51:40Z
Modified
2026-09-25T03:48:53Z
Summary
arm64: entry: Avoid unnecessary local_irq_disable() on kernel exit
Details

In the Linux kernel, the following vulnerability has been resolved:

arm64: entry: Avoid unnecessary local_irq_disable() on kernel exit

Currently, when exiting to kernel mode, we attempt involuntary preemption. The preemption logic expects IRQs to be disabled, which is why we call local_irq_disable() before attempting preemption.

However, depending on the context, local_irq_disable() may be unnecessary:

  • __el1_irq(), the non-NMI EL1 IRQ path, already has IRQs disabled, so local_irq_disable() is redundant.

  • irqentry_exit_to_kernel_mode_preempt() immediately returns when exiting from an NMI-like context, so calling local_irq_disable() beforehand is unnecessary work.

Furthermore, it confuses the pNMI state tracking when we are in a context with interrupts disabled and the GIC_PRIO_PSR_I_SET bit is set in the PMR, leading to a warning when CONFIG_ARM64_DEBUG_PRIORITY_MASKING=y:

 WARNING: ./arch/arm64/include/asm/irqflags.h:63 at arm64_exit_to_kernel_mode+0xb8/0xc0, CPU#40: retsnoop/31805
 CPU: 40 UID: 0 PID: 31805 Comm: retsnoop Not tainted 7.2.0-rc6-next-20260805 #7 PREEMPTLAZY
 pstate: 234013c9 (nzCv DAIF +PAN -UAO +TCO +DIT +SSBS BTYPE=--)
 pc : arm64_exit_to_kernel_mode (arch/arm64/kernel/entry-common.c:63)
 lr : el1_abort (arch/arm64/kernel/entry-common.c:323)
 pmr: 000000f0
 Call trace:
  arm64_exit_to_kernel_mode (arch/arm64/kernel/entry-common.c:63) (P)
  el1_abort (arch/arm64/kernel/entry-common.c:323)
  el1h_64_sync_handler (arch/arm64/kernel/entry-common.c:449)
  el1h_64_sync (arch/arm64/kernel/entry.S:589)
  [...]

Split arm64_exit_to_kernel_mode() into preempt, non-preempt, and dispatch parts so that we can avoid this extra work where it is not needed and avoid breaking the pNMI tracking logic.

Database specific
{
    "cna_assigner":  "Linux",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93254.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
ae654112eac05f316ef31587fc55e4d7160d0086
Fixed
49a61174186bed25d439ff37400c7ce5e3603e73
Fixed
39aebe0e89469c2904e60b1e977e0d4dbf33326b

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93254.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
7.1.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93254.json"