Race condition in Linux kernel - CVE-2026-97925
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local privileged user to cause a denial of service.
The vulnerability exists due to a race condition in tick broadcast device handling when a broadcast device is replaced concurrently with tick broadcast operations. A local privileged user can cause a detached clock event device to be armed, triggering a kernel BUG.
The BUG condition occurs when the original broadcast device has a restricted interrupt-affinity mask and the last CPU in that mask goes offline.