---
cve: "CVE-2026-64419"
severity: "LOW"
cvss: 3.1
epss: "17%"
vendor: "Linux"
kev: false
exploited: false
published: "2026-07-25 10:17:25"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-06T19:21:52+02:00"
---

# CVE-2026-64419

> 3.1 LOW

## Beschreibung

In the Linux kernel, the following vulnerability has been resolved:

mm/shrinker: do not hold RCU lock in shrinker_debugfs_count_show()

Reading the debugfs "count" file of a memcg-aware shrinker can sleep
inside an RCU read-side critical section:

  BUG: sleeping function called from invalid context at kernel/cgroup/rstat.c:421
  RCU nest depth: 1, expected: 0
   css_rstat_flush
   mem_cgroup_flush_stats
   zswap_shrinker_count
   shrinker_debugfs_count_show

shrinker_debugfs_count_show() invokes the ->count_objects() callback under
rcu_read_lock().  The zswap callback flushes memcg stats via
css_rstat_flush(), which may sleep, so it must not run under RCU.

The RCU lock is not needed here.  mem_cgroup_iter() takes RCU internally
and returns a memcg holding a css reference (dropped on the next iteration
or by mem_cgroup_iter_break()), so the memcg stays alive without it.  The
shrinker is kept alive by the open debugfs file: shrinker_free() removes
the debugfs entries via debugfs_remove_recursive(), which waits for
in-flight readers to drain, before call_rcu(..., shrinker_free_rcu_cb). 
The sibling "scan" handler already invokes the sleeping ->scan_objects()
callback with no RCU section.

Drop the rcu_read_lock()/rcu_read_unlock().

## Patch verfügbar (OSV)

- Kernel ≥ 6.1.178
- Kernel ≥ 6.6.145
- Kernel ≥ 6.12.96
- Kernel ≥ 6.18.39
- Kernel ≥ 7.1.4

## Referenzen

- <https://git.kernel.org/stable/c/de5f69b8dae8698ac5e48dfcd30017887cdf4e5a>
- <https://git.kernel.org/stable/c/e441cbfbd0eaa6404278e985033c33caba4db767>
- <https://git.kernel.org/stable/c/2fed79f0fe8c8d28a972c290dbfd693c3546c8c4>
- <https://git.kernel.org/stable/c/560e21e8ccff813e84d05f6500907c549a3d6985>
- <https://git.kernel.org/stable/c/86237e56091e70f09c0fbf217f9d9c0e08f556c4>
- <https://git.kernel.org/stable/c/b902890c62d200b3509cb5e09cf1e0a66553c128>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-64419) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
