CVE-2026-89903
CVE CVE-2026-89903EUVD EUVD-2026-80503Published 2026-09-16T10:32:03.000ZLast changed 2026-09-16T14:39:51.000ZCVSS 7.8
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: LoongArch: Do not save/restore percpu base register in rethook trampoline The rethook trampoline saves $r21 ($u0), the percpu base, into its frame at entry and restores it at exit. Inbetween rethook_trampoline_handler() may schedule via preempt_enable_notrace(). If the task migrates to another CPU, the frame's $r21 holds the old CPU's percpu base, and restoring it poisons $r21 on the new CPU. Until the next user->kernel transition heals $r21, all this_cpu_*() accesses (runqueues, RCU per-CPU data, timer tick programming, FPU ownership) hit the wrong CPU's percpu area. Under kretprobe-heavy preemptible load this can corrupt scheduler and timer state: scheduling-while-atomic splats, wrong-CPU RCU warnings, WARN_ON_ONCE(rq != this_rq()) in nohz_balance_exit_idle(), and CPUs parking in the idle loop with the constant timer never re-armed (hard lockup). Reproduces on a Loongson-3A6000 with kretprobes on VFS paths plus heavy file churn (OS install / unsquashfs). By convention $r21 always holds the current CPU's percpu base in kernel mode: SAVE_SOME() at exception entry reloads it only when coming from user mode, and RESTORE_SOME() restores it only when returning to user mode; the context-switch path never writes it. Therefore the live $r21 at trampoline exit is already correct, and nothing inbetween can change it legitimately (kernel C code cannot write a global register variable). The same flaw existed even in the pre-rethook kretprobe trampoline since v6.3; it was carried over when rethook replaced it. Drop both the save and the restore here. Drop the restore is enough to solve the issue, and drop the save is to keep the code tidy and no need to clear it.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 3f5536860086d906b01ec5ed68cf50c7edcc40af <a03b5e7483ad2c33ba5dd2adb8552e84bfee8fe2; patch: 6.12.110; patch: 7.3-rc2; 3f5536860086d906b01ec5ed68cf50c7edcc40af <c3f2feace5e4f4b01b68b9f947b19adb4155c32e; 6.3; patch: 6.6.157; patch: 7.2.5; 3f5536860086d906b01ec5ed68cf50c7edcc40af <c048b0a3c0836c4b1bef4b51d355d27090bf6790; 3f5536860086d906b01ec5ed68cf50c7edcc40af <8f15e95b438bc6b3c9f23a33c9a0d0678ebd1dc8; 3f5536860086d906b01ec5ed68cf50c7edcc40af <266ffc92e68593759adfe3d58f188773d32782c3; patch: 6.18.51; patch: 0
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.