๐Ÿ” CVE Alert

CVE-2026-89986

UNKNOWN 0.0

mm/mempolicy: fix sleeping allocation in alloc_pages_bulk_weighted_interleave()

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: mm/mempolicy: fix sleeping allocation in alloc_pages_bulk_weighted_interleave() syzbot reported a sleeping function called from invalid context splat in bucket_table_alloc(). When rhashtable_insert_slow() rehashes the table under rcu_read_lock(), it calls bucket_table_alloc(..., GFP_ATOMIC | __GFP_NOWARN). If the bucket table allocation uses vmalloc, __vmalloc_node_range_noprof() invokes vm_area_alloc_pages() -> alloc_pages_bulk_mempolicy_noprof() with the passed GFP_ATOMIC flags. If the current task has an MPOL_WEIGHTED_INTERLEAVE mempolicy, alloc_pages_bulk_weighted_interleave() is called and currently hardcodes GFP_KERNEL when allocating the temporary weights array, triggering a might_alloc() splat in atomic/RCU contexts. Pass the gfp flags (masked with GFP_RECLAIM_MASK to strip page-allocator zone modifiers like __GFP_HIGHMEM) received by alloc_pages_bulk_weighted_interleave() to kmalloc() instead of hardcoding GFP_KERNEL. Since the weights buffer is immediately initialized in full, kmalloc() is sufficient.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 16, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
fa3bea4e1f8202d787709b7e3654eb0a99aed758 < bcb3d0c867ee40dc48e9c085bf328fbc679b6656 fa3bea4e1f8202d787709b7e3654eb0a99aed758 < 0ceda28f371df9e0bbdaa29214f71fe8298f23d8 fa3bea4e1f8202d787709b7e3654eb0a99aed758 < 2943f1f4b7f2816177060eb9f551f2e6d8b629ba fa3bea4e1f8202d787709b7e3654eb0a99aed758 < 540e583b66d6402bf556fde5e53c817a54c1afe5
Linux / Linux
6.9

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/bcb3d0c867ee40dc48e9c085bf328fbc679b6656 git.kernel.org: https://git.kernel.org/stable/c/0ceda28f371df9e0bbdaa29214f71fe8298f23d8 git.kernel.org: https://git.kernel.org/stable/c/2943f1f4b7f2816177060eb9f551f2e6d8b629ba git.kernel.org: https://git.kernel.org/stable/c/540e583b66d6402bf556fde5e53c817a54c1afe5