{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-74594","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-15T05:44:03.919Z","datePublished":"2026-08-22T15:31:44.894Z","dateUpdated":"2026-08-25T05:40:21.246Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-25T05:40:21.246Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsched/psi: Shut down rtpoll_timer in psi_cgroup_free()\n\npsi_schedule_rtpoll_work() is called locklessly from the scheduler hotpath\nand can race psi_trigger_destroy() taking down the last rtpoll trigger under\nrtpoll_trigger_lock:\n\n  psi_schedule_rtpoll_work()        psi_trigger_destroy()\n\n  rcu_read_lock();\n  task = rcu_dereference(rtpoll_task);\n                                    rcu_assign_pointer(rtpoll_task, NULL);\n                                    timer_delete(&rtpoll_timer);\n  mod_timer(&rtpoll_timer, ...);\n  rcu_read_unlock();\n                                    synchronize_rcu();\n                                    kthread_stop(task_to_destroy);\n\nThe group can then be freed with the re-armed timer still pending, and\npoll_timer_fn() runs on freed memory.\n\n461daba06bdc (\"psi: eliminate kthread_worker from psi trigger scheduling\nmechanism\") deleted the timer synchronously after the synchronize_rcu(),\nwhich prevented this but raced trigger creation instead: the deletion could\ncancel the timer that a new trigger set armed during the grace period and,\nas creation also reinitialized the timer at the time, corrupt it.\n8f91efd870ea (\"psi: Fix race between psi_trigger_create/destroy\") moved the\ninitialization into group_init() and the deletion into the locked section,\ntrading the creation races for the window above.\n\nNeither placement in the destruction path works. A pending timer firing\nwhile the group is alive is harmless though. poll_timer_fn() just wakes the\nrtpoll waitqueue and doesn't re-arm itself. Bind the timer to the group's\nlifetime instead and shut it down in psi_cgroup_free(). Nothing can arm it\nby then. timer_shutdown_sync() because the timer is never armed again."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - Reachable only via local kernel interfaces: writing cgroup *.pressure or /proc/pressure/*, closing the trigger fd, and removing the cgroup; the race involves scheduler hotpath callbacks, not any network protocol.\nAC:L - The attacker controls both race participants—closing/destroying the last privileged PSI trigger while concurrently driving psi_schedule_rtpoll_work() via cgroup task scheduling or the psimon worker—so the mod_timer-after-timer_delete window is reliably winnable.\nPR:L - The vulnerable rtpoll path requires CAP_SYS_RESOURCE (non-2s PSI windows); that capability is available to an unprivileged user who creates a user namespace, and cgroup pressure files are writable under delegated cgroup v2 hierarchies in that namespace.\nUI:N - Exploitation is fully self-driven: the attacker creates the trigger, races its teardown against scheduler activity, and deletes the cgroup; no separate victim action such as mounting a filesystem or opening a file is required.\nS:U - Impact is confined to kernel memory corruption and potential local privilege escalation within the same kernel security authority; it does not cross a VM, container runtime, or IOMMU trust boundary.\nC:H - After psi_cgroup_free() the pending rtpoll_timer fires poll_timer_fn() on a freed psi_group, a classic use-after-free that can expose or corrupt adjacent slab contents and be developed into arbitrary kernel memory read primitives.\nI:H - poll_timer_fn() performs atomic_set() on group->rtpoll_wakeup and wake_up_interruptible() on group->rtpoll_wait after the psi_group is freed, giving attacker-influenced writes into a recycled kmem object suitable for control-flow hijacking.\nA:H - Timer execution on freed psi_group memory can cause immediate kernel oops/panic from invalid pointer dereferences or list corruption, and the race can be retriggered for sustained denial of service on shared cloud/container hosts."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["kernel/sched/psi.c"],"versions":[{"version":"6bfcb6178925b1fd28c102e53d403091b8f49396","lessThan":"4addb102154b7cf6e2310ccbe20c3c08619e520d","status":"affected","versionType":"git"},{"version":"8f91efd870ea5d8bc10b0fcc9740db51cd4c0c83","lessThan":"894a9300d7fb2e2951da92e565ae6de7ddfb0a69","status":"affected","versionType":"git"},{"version":"8f91efd870ea5d8bc10b0fcc9740db51cd4c0c83","lessThan":"1e5ca82eee59caca6988f9d6e859786aab8a5fa0","status":"affected","versionType":"git"},{"version":"8f91efd870ea5d8bc10b0fcc9740db51cd4c0c83","lessThan":"310b5a537a78c358a4cd244bd767c1a517a05459","status":"affected","versionType":"git"},{"version":"8f91efd870ea5d8bc10b0fcc9740db51cd4c0c83","lessThan":"806fcff98c1d7cb3c1dc0015e55ebdbe819e6b08","status":"affected","versionType":"git"},{"version":"8f91efd870ea5d8bc10b0fcc9740db51cd4c0c83","lessThan":"8037c5b2b2a447df52542f4d8535895d837bdcbd","status":"affected","versionType":"git"},{"version":"8f91efd870ea5d8bc10b0fcc9740db51cd4c0c83","lessThan":"611e7821c4f83a671455658797336faecc3a5196","status":"affected","versionType":"git"},{"version":"8f91efd870ea5d8bc10b0fcc9740db51cd4c0c83","lessThan":"5457025fa8ca3c0d2732109513de839e3e797190","status":"affected","versionType":"git"},{"version":"e1e5e263bbe0e6e9c3db36aa48a3c8acf546fa49","status":"affected","versionType":"git"},{"version":"979965c33f734a1666af67900408f997ac669c23","status":"affected","versionType":"git"},{"version":"5.10.50","lessThan":"5.10.266","status":"affected","versionType":"semver"},{"version":"5.12.17","lessThan":"5.13","status":"affected","versionType":"semver"},{"version":"5.13.2","lessThan":"5.14","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["kernel/sched/psi.c"],"versions":[{"version":"5.14","status":"affected"},{"version":"0","lessThan":"5.14","status":"unaffected","versionType":"semver"},{"version":"5.10.266","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.217","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.10.50","versionEndExcluding":"5.10.266"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.14","versionEndExcluding":"5.15.217"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.14","versionEndExcluding":"6.1.183"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.14","versionEndExcluding":"6.6.152"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.14","versionEndExcluding":"6.12.104"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.14","versionEndExcluding":"6.18.45"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.14","versionEndExcluding":"7.1.9"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.14","versionEndExcluding":"7.2"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.12.17"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.13.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/4addb102154b7cf6e2310ccbe20c3c08619e520d"},{"url":"https://git.kernel.org/stable/c/894a9300d7fb2e2951da92e565ae6de7ddfb0a69"},{"url":"https://git.kernel.org/stable/c/1e5ca82eee59caca6988f9d6e859786aab8a5fa0"},{"url":"https://git.kernel.org/stable/c/310b5a537a78c358a4cd244bd767c1a517a05459"},{"url":"https://git.kernel.org/stable/c/806fcff98c1d7cb3c1dc0015e55ebdbe819e6b08"},{"url":"https://git.kernel.org/stable/c/8037c5b2b2a447df52542f4d8535895d837bdcbd"},{"url":"https://git.kernel.org/stable/c/611e7821c4f83a671455658797336faecc3a5196"},{"url":"https://git.kernel.org/stable/c/5457025fa8ca3c0d2732109513de839e3e797190"}],"title":"sched/psi: Shut down rtpoll_timer in psi_cgroup_free()","x_generator":{"engine":"bippy-1.2.0"}}}}