Database/Kernel, userspace & hypervisor
Linux slab allocator: ABA race in the optimistic freelist return corrupts the partial list
Impact
The optimistic __slab_try_return_freelist() path assumed a NULL slab->freelist plus a successful cmpxchg meant nobody had freed into the slab, but another CPU can free, insert the slab onto the partial list, allocate again and be mid-removal under n->list_lock. __refill_objects_node() then re-inserts the same slab while it is being removed, corrupting the node partial list - the reporter's trace is a list_add corruption BUG from a plain msgsnd() syscall, hit as an unprivileged user (UID 65534 in the report). This is the core allocator, so it is reachable from any workload on the node, not a niche subsystem, and the known outcome is an immediate kernel panic taking every job on the GPU host with it. Note the trace is against a 7.2-rc tree - the flawed optimization arrived in commit ba7425312607, so only kernels carrying it are affected.
Who can reach it
Local unprivileged user on the node, through ordinary allocation-heavy syscalls; no GPU or device access needed. Any tenant with code execution qualifies. Requires a kernel that includes the __slab_try_return_freelist optimization.
What to do
Check whether your kernel carries commit ba7425312607; if it does, install a build with the list_lock fix and reboot the node. If your kernels predate that optimization - most current LTS lines - you are not affected and no window is needed. There is no runtime mitigation for a core allocator race.
References
Related entries
- Linux AMD IOMMU: sign-discarding error check lets nested domains use an unallocated domain IDCVE-2026-98002 · Linux kernel iommu/amd (amd_iommu_alloc_domain_nested error check)High
- Linux kernel virtio-gpu: unvalidated EDID block offset lets a malicious backend read past a kernel bufferCVE-2026-68255 · Linux kernel drm/virtio (virtio_get_edid_block response bounds)High
- Linux kernel (drivers/pci): The option-ROM parser trusts the header and data-structure offsets it reads out of theCVE-2026-72487 · Linux kernel (drivers/pci)High
- Xen qemu-xen-traditional device model hw/pt-msi.c (MSI-X passthrough): Buffer overflow on the MSI-X table write pathCVE-2015-8554 · Xen qemu-xen-traditional device model hw/pt-msi.c (MSI-X passthrough)High
- Linux kernel RDS net/rds/recv.c - rds_inc_info_copy: A structure member is left uninitialised before the RDS messageCVE-2016-5244 · Linux kernel RDS net/rds/recv.c - rds_inc_info_copyHigh
- QEMU (virtio-net): Heap use-after-free in virtio_net_receive_rcu - guest-to-host code execution in the QEMU processCVE-2021-3748 · QEMU (virtio-net)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.