CVE-2026-64415CWE-667

CVE-2026-64415

Medium · published July 25, 2026

CVSS v3.1
5.5
EPSS
0%
Percentile
0.7
In the wild
Unconfirmed
What it is

In the Linux kernel, the following vulnerability has been resolved:

mm/swap: add cond_resched() in swap_reclaim_full_clusters to prevent softlockup

We hit a real softlockup in an internal stress test environment. The

workload was LTP memory/swap stress on a large arm64 machine, with 320

CPUs, about 1TB memory and an 8.6GB swap device. The system was under

heavy load and the swap device had a large number of full clusters. The

softlockup was triggered during a stress test after about 3 days.

So, add periodic cond_resched() calls during large full_clusters

reclaim operations to prevent softlockup issues.

Detailed call trace as follow:

PID: 3817773 TASK: ffff0883bb28b780 CPU: 48 COMMAND: "kworker/48:7"

#0 [ffff800080183d10] __crash_kexec at ffffa4c1361e5de4

#1 [ffff800080183d90] panic at ffffa4c1360d5e9c

#2 [ffff800080183e20] watchdog_timer_fn at ffffa4c136231fa8

...

#16 [ffff8000c4ad3cb0] swap_cache_del_folio at ffffa4c1363e1614

#17 [ffff8000c4ad3ce0] __try_to_reclaim_swap at ffffa4c1363e4bfc

#18 [ffff8000c4ad3d40] swap_reclaim_full_clusters at ffffa4c1363e5474

#19 [ffff8000c4ad3da0] swap_reclaim_work at ffffa4c1363e550c

#20 [ffff8000c4ad3dc0] process_one_work at ffffa4c136102edc

#21 [ffff8000c4ad3e10] worker_thread at ffffa4c136103398

#22 [ffff8000c4ad3e70] kthread at ffffa4c13610d95c

The record
Technical detail
CVSS v3.1
5.5 · MEDIUM
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS v4.0
Not supplied
EPSS
0.00094 · 0.7th percentile
Weakness
CWE-667 · Improper Locking
Published
2026-07-25T14:17Z
Affected products (6)
ProductVersionsFixed in
linux/linux_kernel≥ 6.12.1, < 6.12.966.12.96
linux/linux_kernel≥ 6.13, < 6.18.396.18.39
linux/linux_kernel≥ 6.19, < 7.1.47.1.4
linux/linux_kernelall versions
linux/linux_kernelall versions
linux/linux_kernelall versions
References (4)
EPSS history
Timeline
  • 25 JUL 08:50Z
    mm/swap: add cond_resched() in swap_reclaim_full_clusters to prevent softlockup
    cvelistv5