{"id":"CVE-2026-89756","summary":"mm/migrate: report RCU-tasks quiescent states in migrate_pages_batch()","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/migrate: report RCU-tasks quiescent states in migrate_pages_batch()\n\nmigrate_pages_batch() unmaps each folio before moving it, and every\nunmap runs the mmu_notifier invalidate callbacks.  On KVM hosts\ntry_to_migrate() ends up in kvm_mmu_notifier_invalidate_range_start() -\u003e\ntdp_mmu_zap_leafs(), which is expensive, so unmapping a large batch keeps\nthe CPU busy for a long time.\n\nThe loop already calls cond_resched(), but on PREEMPTION kernels that is\na no-op, and involuntary preemption is not a Tasks-RCU quiescent state.\n\nA long batch therefore never reports a quiescent state, and the\nmigrating task (e.g. kcompactd) becomes a Tasks-RCU holdout, stalling the\nTasks-RCU grace period for minutes, which is common at Meta fleet:\n\n  INFO: rcu_tasks detected stalls on tasks:\n  0000000055349ecc: .. nvcsw: 1157401/1157401 holdout: 1 idle_cpu: -1/56 task:kcompactd0      state:R  running task\n  Call Trace:\n   tdp_mmu_zap_leafs\n   tdp_mmu_next_root\n   gfn_to_pfn_cache_invalidate_start\n   kvm_mmu_notifier_invalidate_range_start\n   __mmu_notifier_invalidate_range_start\n   try_to_migrate_one\n   try_to_migrate\n   migrate_pages_batch\n   migrate_pages\n   compact_zone\n   compact_node\n   kcompactd\n   kthread\n\nUse cond_resched_tasks_rcu_qs() so a quiescent state is reported even\nwhen cond_resched() does nothing.\n\nThis has also been discussed at [1]","modified":"2026-09-25T18:27:37.203984224Z","published":"2026-09-11T19:46:59.093Z","related":["openSUSE-SU-2026:11880-1"],"database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89756.json","cna_assigner":"Linux"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/4757542649af56d894e25e30f57cd497dffad53f"},{"type":"WEB","url":"https://git.kernel.org/stable/c/4996a7bc01ef35570664854dac2530c604981039"},{"type":"WEB","url":"https://git.kernel.org/stable/c/5dc0daff0341c6baba19c38f47d299ac831d7e99"},{"type":"WEB","url":"https://git.kernel.org/stable/c/66734981b4d3c105223a13c827c9c73be18d91ad"},{"type":"WEB","url":"https://git.kernel.org/stable/c/8c6d63d434ebb85c6cf3dac1e70a171b183c6614"},{"type":"WEB","url":"https://git.kernel.org/stable/c/efe8f86c0916f0f74eea74ae21a3b37f728c6bad"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89756.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89756"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"8315f42295d2667a7f942f154b73a86fd7cb2227"},{"fixed":"8c6d63d434ebb85c6cf3dac1e70a171b183c6614"},{"fixed":"4757542649af56d894e25e30f57cd497dffad53f"},{"fixed":"4996a7bc01ef35570664854dac2530c604981039"},{"fixed":"5dc0daff0341c6baba19c38f47d299ac831d7e99"},{"fixed":"66734981b4d3c105223a13c827c9c73be18d91ad"},{"fixed":"efe8f86c0916f0f74eea74ae21a3b37f728c6bad"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-89756.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.18.0"},{"fixed":"6.1.188"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.157"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.109"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.50"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.2.4"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-89756.json"}}],"schema_version":"1.9.0"}