CVE-2026-53326 Details
Description
In the Linux kernel, the following vulnerability has been resolved: debugobjects: Don't call fill_pool() in early boot hardirq context When booting a debug PREEMPT_RT kernel on an ARM64 system, a "inconsistent {HARDIRQ-ON-W} -> {IN-HARDIRQ-W} usage" lockdep warning message was reported to the console. During early boot, interrupts are enabled before the scheduler is enabled. In this window (before SYSTEM_SCHEDULING is set) interrupts can fire and in the hard interrupt context handler attempt to fill the pool This can lead to a deadlock when the interrupt occurred when the interrupt hits a region which holds a lock that is required to be taken in the allocation path. Add a new can_fill_pool() helper and reorder the exception rule and forbid this scenario by excluding allocations from hard interrupt context.
A vulnerability exists in the Linux kernel's debug PREEMPT_RT configuration on ARM64 systems. During early boot, interrupts are enabled before the scheduler, allowing hard interrupts to occur and attempt to refill a debug objects pool. This can cause a deadlock if the interrupt interferes with a locked region needed for allocation. The issue arises from the 'fill_pool()' function being called in a hard interrupt context, which can lead to lock inversions and potential deadlocks. The vulnerability affects several versions of the Linux kernel.
The vulnerability has been addressed by adding a 'can_fill_pool()' helper function to manage pool refills more safely. Users should upgrade to the latest patched version of the Linux kernel.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/0d046ae106255cba5eb83b23f78ee93f3620247d | kernel.org | Patch |
| https://git.kernel.org/stable/c/27335c50014102e9077b784ebd314954286afcab | kernel.org | Patch |
| https://git.kernel.org/stable/c/3cc90ea0dd0fb1f8db577dcdc027fc46c06049f6 | kernel.org | Patch |
| https://git.kernel.org/stable/c/44b8b03a9fb5c575548fc72c674653d6baba142a | kernel.org | Patch |
| https://git.kernel.org/stable/c/5d95f6b267f3d7fe54f42a3b224bb4a3d3990b41 | kernel.org | Patch |
| https://git.kernel.org/stable/c/7bc71bdb1c1526c7f02a6adab324394ff1327b0a | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-667 | Improper Locking | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 6.19, < 7.0.13 7.1 rc1 7.1 rc2 7.1 rc3 7.1 rc4 7.1 rc5 7.1 rc6 7.1 rc7 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 23, 2026 | Initial Analysis | [email protected] |
| Jul 4, 2026 | CVE Modified | kernel.org |
| Jul 1, 2026 | New CVE Received | kernel.org |