Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: debugobjects: Don't call fill_pool() in early boot hardirq context When booting a debug PREEMPT_RT kernel on an ARM64 system, a "inconsistent {HARDIRQ-ON-W} -> {IN-HARDIRQ-W} usage" lockdep warning message was reported to the console. During early boot, interrupts are enabled before the scheduler is enabled. In this window (before SYSTEM_SCHEDULING is set) interrupts can fire and in the hard interrupt context handler attempt to fill the pool This can lead to a deadlock when the interrupt occurred when the interrupt hits a region which holds a lock that is required to be taken in the allocation path. Add a new can_fill_pool() helper and reorder the exception rule and forbid this scenario by excluding allocations from hard interrupt context.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 6.19, < 7.0.13 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/0d046ae106255cba5eb83b23f78ee93f3620247dPatch
- https://git.kernel.org/stable/c/27335c50014102e9077b784ebd314954286afcabPatch
- https://git.kernel.org/stable/c/3cc90ea0dd0fb1f8db577dcdc027fc46c06049f6Patch
- https://git.kernel.org/stable/c/44b8b03a9fb5c575548fc72c674653d6baba142aPatch
- https://git.kernel.org/stable/c/5d95f6b267f3d7fe54f42a3b224bb4a3d3990b41Patch
- https://git.kernel.org/stable/c/7bc71bdb1c1526c7f02a6adab324394ff1327b0aPatch
FAQ
What is CVE-2026-53326?
CVE-2026-53326 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: debugobjects: Don't call fill_pool() in early boot hardirq context When booting a debug PREEMPT_RT kernel on an ARM64 system, a "i...
How severe is CVE-2026-53326?
CVE-2026-53326 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-53326?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.