0.0
NA
CVE-2026-64419
mm/shrinker: do not hold RCU lock in shrinker_debugfs_count_show()
Description

In the Linux kernel, the following vulnerability has been resolved: mm/shrinker: do not hold RCU lock in shrinker_debugfs_count_show() Reading the debugfs "count" file of a memcg-aware shrinker can sleep inside an RCU read-side critical section: BUG: sleeping function called from invalid context at kernel/cgroup/rstat.c:421 RCU nest depth: 1, expected: 0 css_rstat_flush mem_cgroup_flush_stats zswap_shrinker_count shrinker_debugfs_count_show shrinker_debugfs_count_show() invokes the ->count_objects() callback under rcu_read_lock(). The zswap callback flushes memcg stats via css_rstat_flush(), which may sleep, so it must not run under RCU. The RCU lock is not needed here. mem_cgroup_iter() takes RCU internally and returns a memcg holding a css reference (dropped on the next iteration or by mem_cgroup_iter_break()), so the memcg stays alive without it. The shrinker is kept alive by the open debugfs file: shrinker_free() removes the debugfs entries via debugfs_remove_recursive(), which waits for in-flight readers to drain, before call_rcu(..., shrinker_free_rcu_cb). The sibling "scan" handler already invokes the sleeping ->scan_objects() callback with no RCU section. Drop the rcu_read_lock()/rcu_read_unlock().

INFO

Published Date :

July 25, 2026, 10:17 a.m.

Last Modified :

July 25, 2026, 10:17 a.m.

Remotely Exploit :

No

Source :

416baaa9-dc9f-4396-8d5f-8c081fb06d67
Affected Products

The following products are affected by CVE-2026-64419 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

No affected product recoded yet

Solution
Remove RCU lock in debugfs count show function to prevent sleeping.
  • Remove the RCU read lock in shrinker_debugfs_count_show.
  • Ensure shrinker_debugfs_count_show does not sleep.
  • Update kernel to version with fix.
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2026-64419 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2026-64419 weaknesses.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-64419 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2026-64419 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Jul. 25, 2026

    Action Type Old Value New Value
    Added Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '5035ebc644aec92d55d1bbfe042f35341e4bffb5', 'lessThan': 'de5f69b8dae8698ac5e48dfcd30017887cdf4e5a', 'versionType': 'git'}, {'status': 'affected', 'version': '5035ebc644aec92d55d1bbfe042f35341e4bffb5', 'lessThan': 'e441cbfbd0eaa6404278e985033c33caba4db767', 'versionType': 'git'}, {'status': 'affected', 'version': '5035ebc644aec92d55d1bbfe042f35341e4bffb5', 'lessThan': '2fed79f0fe8c8d28a972c290dbfd693c3546c8c4', 'versionType': 'git'}, {'status': 'affected', 'version': '5035ebc644aec92d55d1bbfe042f35341e4bffb5', 'lessThan': '560e21e8ccff813e84d05f6500907c549a3d6985', 'versionType': 'git'}, {'status': 'affected', 'version': '5035ebc644aec92d55d1bbfe042f35341e4bffb5', 'lessThan': '86237e56091e70f09c0fbf217f9d9c0e08f556c4', 'versionType': 'git'}, {'status': 'affected', 'version': '5035ebc644aec92d55d1bbfe042f35341e4bffb5', 'lessThan': 'b902890c62d200b3509cb5e09cf1e0a66553c128', 'versionType': 'git'}], 'programFiles': ['mm/shrinker_debug.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '6.0'}, {'status': 'unaffected', 'version': '0', 'lessThan': '6.0', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.1.178', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.145', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.96', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.39', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.4', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2-rc1', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['mm/shrinker_debug.c'], 'defaultStatus': 'affected'}]
    Added Description In the Linux kernel, the following vulnerability has been resolved: mm/shrinker: do not hold RCU lock in shrinker_debugfs_count_show() Reading the debugfs "count" file of a memcg-aware shrinker can sleep inside an RCU read-side critical section: BUG: sleeping function called from invalid context at kernel/cgroup/rstat.c:421 RCU nest depth: 1, expected: 0 css_rstat_flush mem_cgroup_flush_stats zswap_shrinker_count shrinker_debugfs_count_show shrinker_debugfs_count_show() invokes the ->count_objects() callback under rcu_read_lock(). The zswap callback flushes memcg stats via css_rstat_flush(), which may sleep, so it must not run under RCU. The RCU lock is not needed here. mem_cgroup_iter() takes RCU internally and returns a memcg holding a css reference (dropped on the next iteration or by mem_cgroup_iter_break()), so the memcg stays alive without it. The shrinker is kept alive by the open debugfs file: shrinker_free() removes the debugfs entries via debugfs_remove_recursive(), which waits for in-flight readers to drain, before call_rcu(..., shrinker_free_rcu_cb). The sibling "scan" handler already invokes the sleeping ->scan_objects() callback with no RCU section. Drop the rcu_read_lock()/rcu_read_unlock().
    Added Reference https://git.kernel.org/stable/c/2fed79f0fe8c8d28a972c290dbfd693c3546c8c4
    Added Reference https://git.kernel.org/stable/c/560e21e8ccff813e84d05f6500907c549a3d6985
    Added Reference https://git.kernel.org/stable/c/86237e56091e70f09c0fbf217f9d9c0e08f556c4
    Added Reference https://git.kernel.org/stable/c/b902890c62d200b3509cb5e09cf1e0a66553c128
    Added Reference https://git.kernel.org/stable/c/de5f69b8dae8698ac5e48dfcd30017887cdf4e5a
    Added Reference https://git.kernel.org/stable/c/e441cbfbd0eaa6404278e985033c33caba4db767
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.