CVE-2026-23134

MEDIUM

Linux Kernel - Denial of Service via kmalloc_nolock() Context Check Bypass

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: slab: fix kmalloc_nolock() context check for PREEMPT_RT On PREEMPT_RT kernels, local_lock becomes a sleeping lock. The current check in kmalloc_nolock() only verifies we're not in NMI or hard IRQ context, but misses the case where preemption is disabled. When a BPF program runs from a tracepoint with preemption disabled (preempt_count > 0), kmalloc_nolock() proceeds to call local_lock_irqsave() which attempts to acquire a sleeping lock, triggering: BUG: sleeping function called from invalid context in_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 6128 preempt_count: 2, expected: 0 Fix this by checking !preemptible() on PREEMPT_RT, which directly expresses the constraint that we cannot take a sleeping lock when preemption is disabled. This encompasses the previous checks for NMI and hard IRQ contexts while also catching cases where preemption is disabled.

Scores

CVSS v3 5.5
EPSS 0.0002
EPSS Percentile 5.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

Status published
Products (9)
linux/Kernel 6.18.0 - 6.18.8linux
Linux/Linux < 6.18
Linux/Linux 6.18
Linux/Linux 6.18.8 - 6.18.*
Linux/Linux 6.19
Linux/Linux af92793e52c3a99b828ed4bdd277fd3e11c18d08 - 99a3e3a1cfc93b8fe318c0a3a5cfb01f1d4ad53c
Linux/Linux af92793e52c3a99b828ed4bdd277fd3e11c18d08 - f60ba4a97ae3f94e4818722ed2e4d260bbb17b44
linux/linux_kernel 6.19 rc1 (6 CPE variants)
linux/linux_kernel 6.18 - 6.18.8
Published Feb 14, 2026
Tracked Since Feb 18, 2026