{"id":"CVE-2025-39953","summary":"cgroup: split cgroup_destroy_wq into 3 workqueues","details":"In the Linux kernel, the following vulnerability has been resolved:\n\ncgroup: split cgroup_destroy_wq into 3 workqueues\n\nA hung task can occur during [1] LTP cgroup testing when repeatedly\nmounting/unmounting perf_event and net_prio controllers with\nsystemd.unified_cgroup_hierarchy=1. The hang manifests in\ncgroup_lock_and_drain_offline() during root destruction.\n\nRelated case:\ncgroup_fj_function_perf_event cgroup_fj_function.sh perf_event\ncgroup_fj_function_net_prio cgroup_fj_function.sh net_prio\n\nCall Trace:\n\tcgroup_lock_and_drain_offline+0x14c/0x1e8\n\tcgroup_destroy_root+0x3c/0x2c0\n\tcss_free_rwork_fn+0x248/0x338\n\tprocess_one_work+0x16c/0x3b8\n\tworker_thread+0x22c/0x3b0\n\tkthread+0xec/0x100\n\tret_from_fork+0x10/0x20\n\nRoot Cause:\n\nCPU0                            CPU1\nmount perf_event                umount net_prio\ncgroup1_get_tree                cgroup_kill_sb\nrebind_subsystems               // root destruction enqueues\n\t\t\t\t// cgroup_destroy_wq\n// kill all perf_event css\n                                // one perf_event css A is dying\n                                // css A offline enqueues cgroup_destroy_wq\n                                // root destruction will be executed first\n                                css_free_rwork_fn\n                                cgroup_destroy_root\n                                cgroup_lock_and_drain_offline\n                                // some perf descendants are dying\n                                // cgroup_destroy_wq max_active = 1\n                                // waiting for css A to die\n\nProblem scenario:\n1. CPU0 mounts perf_event (rebind_subsystems)\n2. CPU1 unmounts net_prio (cgroup_kill_sb), queuing root destruction work\n3. A dying perf_event CSS gets queued for offline after root destruction\n4. Root destruction waits for offline completion, but offline work is\n   blocked behind root destruction in cgroup_destroy_wq (max_active=1)\n\nSolution:\nSplit cgroup_destroy_wq into three dedicated workqueues:\ncgroup_offline_wq – Handles CSS offline operations\ncgroup_release_wq – Manages resource release\ncgroup_free_wq – Performs final memory deallocation\n\nThis separation eliminates blocking in the CSS free path while waiting for\noffline operations to complete.\n\n[1] https://github.com/linux-test-project/ltp/blob/master/runtest/controllers","modified":"2026-03-20T12:43:07.148817Z","published":"2025-10-04T07:31:13.237Z","related":["MGASA-2025-0309","MGASA-2025-0310"],"database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/39xxx/CVE-2025-39953.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/05e0b03447cf215ec384210441b34b7a3b16e8b0"},{"type":"WEB","url":"https://git.kernel.org/stable/c/4a1e3ec28e8062cd9f339aa6a942df9c5bcb6811"},{"type":"WEB","url":"https://git.kernel.org/stable/c/79f919a89c9d06816dbdbbd168fa41d27411a7f9"},{"type":"WEB","url":"https://git.kernel.org/stable/c/993049c9b1355c78918344a6403427d53f9ee700"},{"type":"WEB","url":"https://git.kernel.org/stable/c/a0c896bda7077aa5005473e2c5b3c27173313b4c"},{"type":"WEB","url":"https://git.kernel.org/stable/c/cabadd7fd15f97090f752fd22dd7f876a0dc3dc4"},{"type":"WEB","url":"https://git.kernel.org/stable/c/ded4d207a3209a834b6831ceec7f39b934c74802"},{"type":"WEB","url":"https://git.kernel.org/stable/c/f2795d1b92506e3adf52a298f7181032a1525e04"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/39xxx/CVE-2025-39953.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-39953"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"334c3679ec4b2b113c35ebe37d2018b112dd5013"},{"fixed":"cabadd7fd15f97090f752fd22dd7f876a0dc3dc4"},{"fixed":"a0c896bda7077aa5005473e2c5b3c27173313b4c"},{"fixed":"f2795d1b92506e3adf52a298f7181032a1525e04"},{"fixed":"993049c9b1355c78918344a6403427d53f9ee700"},{"fixed":"4a1e3ec28e8062cd9f339aa6a942df9c5bcb6811"},{"fixed":"ded4d207a3209a834b6831ceec7f39b934c74802"},{"fixed":"05e0b03447cf215ec384210441b34b7a3b16e8b0"},{"fixed":"79f919a89c9d06816dbdbbd168fa41d27411a7f9"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-39953.json"}}],"schema_version":"1.7.5"}