{"id":"CVE-2026-90046","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/page_alloc: don't spin_trylock() in NMI on UP\n\nPatch series \"mm/page_alloc: fixes for free_pages_nolock() on RT/UP\".\n\nPre-existing bugs found by Sashiko during revie…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/page_alloc: don't spin_trylock() in NMI on UP\n\nPatch series \"mm/page_alloc: fixes for free_pages_nolock() on RT/UP\".\n\nPre-existing bugs found by Sashiko during revie…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","vendor":"Linux","product":"Linux","affected":["Linux >= 8c57b687e8331eb80e302a2c528b18b966a9ac7a < 06c76d3c389ff504052f64b1acee44651bd847fa","Linux >= 8c57b687e8331eb80e302a2c528b18b966a9ac7a < 68a069b407303e71db371df85036101e8ff59280","Linux >= 8c57b687e8331eb80e302a2c528b18b966a9ac7a < 3105ae628fb785d48b49256468be4f21a7b3cfc0","Linux 6.15"],"published":"2026-09-16","updated":"2026-09-16","sourceUpdated":"2026-09-16T15:18:27.317","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-90046","references":[{"url":"https://git.kernel.org/stable/c/06c76d3c389ff504052f64b1acee44651bd847fa","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3105ae628fb785d48b49256468be4f21a7b3cfc0","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/68a069b407303e71db371df85036101e8ff59280","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-16T10:53:53.927Z","epss":0.00143,"epssPercentile":0.0398,"slug":"CVE-2026-90046","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nmm/page_alloc: don't spin_trylock() in NMI on UP\n\nPatch series \"mm/page_alloc: fixes for free_pages_nolock() on RT/UP\".\n\nPre-existing bugs found by Sashiko during review of this other series:\nhttps://lore.kernel.org/all/20260703-alloc-trylock-v5-0-c87b714e19d3@google.com/\n\nI have not reproduced these bugs, and I suspect there is no real-world\nuser that is affected by them.\n\n\nThis patch (of 2):\n\nAs noted in can_spin_trylock(), using this is unsafe in this context. \ncommit 620b46ed6ae17 (\"mm/page_alloc: return NULL early from\nalloc_frozen_pages_nolock() in NMI on UP\") fixed this on the alloc side\nbut missed the free side.\n\nImpact: If BPF programs using these features in NMI (probably tracing) are\npresent on non-SMP builds this might crash the kernel and is probably\nexploitable by local attackers for privilege escalation.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":204978,"id":"CVE-2026-90046","ts":1789570700876,"field":"cvss","old":null,"new":"7.8"},{"seq":204977,"id":"CVE-2026-90046","ts":1789570700876,"field":"severity","old":"none","new":"high"}]}