PT-2026-61387 · Linux · Linux
CVE-2026-64070
·
Publicado
2026-07-19
·
Atualizado
2026-07-19
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
powerpc/hv-gpci: fix preempt count leak in sysfs show paths
Four sysfs show() callbacks in hv-gpci take get cpu var(hv gpci reqb)
(which calls preempt disable()) but only call the matching put cpu var()
on the error path under the 'out:' label. Every successful read leaks
one preempt disable():
processor bus topology show()
processor config show()
affinity domain via virtual processor show()
affinity domain via domain show()
(affinity domain via partition show() was already correct.)
On a CONFIG PREEMPT=y kernel, repeated reads raise preempt count and
eventually return to userspace with preemption still disabled. The
next user-mode page fault then hits faulthandler disabled() == 1,
gets forced to SIGSEGV, and the resulting coredump trips
'BUG: scheduling while atomic' in call usermodehelper exec ->
wait for completion state -> schedule:
BUG: scheduling while atomic: //0x00000004
...
schedule bug+0x6c/0x90
schedule+0x58c/0x13a0
schedule+0x48/0x1a0
schedule timeout+0x104/0x170
wait for completion state+0x16c/0x330
call usermodehelper exec+0x254/0x2d0
vfs coredump+0x1050/0x2590
get signal+0xb9c/0xc80
do notify resume+0xf8/0x470
Add an out success label that calls put cpu var() before returning
the byte count, mirroring affinity domain via partition show().
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux