Deadlock in Linux kernel - CVE-2026-64374
Published: July 27, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a live lock condition in the linux kernel scheduler RT_PUSH_IPI logic when handling RT task migration and repeated inter-processor interrupts on non-PREEMPT_RT systems. A local user can trigger heavy networking activity and wake RT tasks to cause a denial of service.
The issue occurs on non-PREEMPT_RT systems when softirqs execute for long periods and prevent the target CPU from returning to task context.
Affected software
How to mitigate CVE-2026-64374
External References
- https://git.kernel.org/stable/c/44aae426dbfd51286f7eb601cfa14bc32164812a
- https://git.kernel.org/stable/c/4bd0da48fbc1dbef6774175129107fbbdd353e26
- https://git.kernel.org/stable/c/860aaff72c8446fed5e576249e19952883a18885
- https://git.kernel.org/stable/c/89237c8fc15d8016a194076e648ccb57d75e65ae
- https://git.kernel.org/stable/c/a18f80bf5359238c4f067d691b96af00286fdd89
- https://git.kernel.org/stable/c/b99f04ae3d200d2f8844aa29145bd18eccbeecde
- https://git.kernel.org/stable/c/d8312a56d9a162e3ec76476aa487e7d20bc602e9
- https://git.kernel.org/stable/c/dd29c017aed628076e915fe4cdfb5392fd4c5cab