CVE-2026-64419 Details
Description
In the Linux kernel, the following vulnerability has been resolved: mm/shrinker: do not hold RCU lock in shrinker_debugfs_count_show() Reading the debugfs "count" file of a memcg-aware shrinker can sleep inside an RCU read-side critical section: BUG: sleeping function called from invalid context at kernel/cgroup/rstat.c:421 RCU nest depth: 1, expected: 0 css_rstat_flush mem_cgroup_flush_stats zswap_shrinker_count shrinker_debugfs_count_show shrinker_debugfs_count_show() invokes the ->count_objects() callback under rcu_read_lock(). The zswap callback flushes memcg stats via css_rstat_flush(), which may sleep, so it must not run under RCU. The RCU lock is not needed here. mem_cgroup_iter() takes RCU internally and returns a memcg holding a css reference (dropped on the next iteration or by mem_cgroup_iter_break()), so the memcg stays alive without it. The shrinker is kept alive by the open debugfs file: shrinker_free() removes the debugfs entries via debugfs_remove_recursive(), which waits for in-flight readers to drain, before call_rcu(..., shrinker_free_rcu_cb). The sibling "scan" handler already invokes the sleeping ->scan_objects() callback with no RCU section. Drop the rcu_read_lock()/rcu_read_unlock().
A vulnerability in the Linux kernel's memory shrinker debugfs interface can lead to improper handling of read-copy-update (RCU) locks. Specifically, the 'count' file of a memory cgroup-aware shrinker can invoke sleeping functions while under an RCU read-lock, which is not allowed. This issue arises because the zswap shrinker callback, which flushes memory cgroup statistics, can sleep and must not be executed within an RCU context. The vulnerability affects the Linux kernel stable tree and has been addressed by removing the unnecessary RCU lock in the shrinker debugfs count handler.
The vulnerability has been fixed in the Linux kernel. Users should upgrade to the latest version where this issue has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/2fed79f0fe8c8d28a972c290dbfd693c3546c8c4 | kernel.org | Patch |
| https://git.kernel.org/stable/c/560e21e8ccff813e84d05f6500907c549a3d6985 | kernel.org | Patch |
| https://git.kernel.org/stable/c/86237e56091e70f09c0fbf217f9d9c0e08f556c4 | kernel.org | Patch |
| https://git.kernel.org/stable/c/b902890c62d200b3509cb5e09cf1e0a66553c128 | kernel.org | Patch |
| https://git.kernel.org/stable/c/de5f69b8dae8698ac5e48dfcd30017887cdf4e5a | kernel.org | Patch |
| https://git.kernel.org/stable/c/e441cbfbd0eaa6404278e985033c33caba4db767 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 6.0, < 6.1.178 >= 6.2, < 6.6.145 >= 6.7, < 6.12.96 >= 6.13, < 6.18.39 >= 6.19, < 7.1.4 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 4, 2026 | Initial Analysis | [email protected] |
| Aug 17, 2026 | CVE Modified | kernel.org |
| Jul 25, 2026 | New CVE Received | kernel.org |