Answer in brief
CVE-2026-74594 records a Unknown severity vulnerability in sched/psi: Shut down rtpoll_timer in psi_cgroup_free(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=8f91efd870ea5d8bc10b0fcc9740db51cd4c0c83 <1e5ca82eee59caca6988f9d6e859786aab8a5fa0 || >=8f91efd870ea5d8bc10b0fcc9740db51cd4c0c83 <310b5a537a78c358a4cd244bd767c1a517a05459 || >=8f91efd870ea5d8bc10b0fcc9740db51cd4c0c83 <806fcff98c1d7cb3c1dc0015e55ebdbe819e6b08 || >=8f91efd870ea5d8bc10b0fcc9740db51cd4c0c83 <8037c5b2b2a447df52542f4d8535895d837bdcbd || >=8f91efd870ea5d8bc10b0fcc9740db51cd4c0c83 <611e7821c4f83a671455658797336faecc3a5196 || >=8f91efd870ea5d8bc10b0fcc9740db51cd4c0c83 <5457025fa8ca3c0d2732109513de839e3e797190 || 6bfcb6178925b1fd28c102e53d403091b8f49396 || e1e5e263bbe0e6e9c3db36aa48a3c8acf546fa49 || 979965c33f734a1666af67900408f997ac669c23 || >=5.10.50 <5.11 || >=5.12.17 <5.13 || >=5.13.2 <5.14 | 1e5ca82eee59caca6988f9d6e859786aab8a5fa0, 310b5a537a78c358a4cd244bd767c1a517a05459, 806fcff98c1d7cb3c1dc0015e55ebdbe819e6b08, 8037c5b2b2a447df52542f4d8535895d837bdcbd, 611e7821c4f83a671455658797336faecc3a5196, 5457025fa8ca3c0d2732109513de839e3e797190, 5.11, 5.13, 5.14 |
| Linux/Linuxgeneric | 5.14 | Not reported |
Published upstream
Aug 22, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 22, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 22, 2026
In the Linux kernel, the following vulnerability has been resolved: sched/psi: Shut down rtpoll_timer in psi_cgroup_free() psi_schedule_rtpoll_work() is called locklessly from the scheduler hotpath and can race psi_trigger_destroy() taking down the last rtpoll trigger under rtpoll_trigger_lock: psi_schedule_rtpoll_work() psi_trigger_destroy() rcu_read_lock(); task = rcu_dereference(rtpoll_task); rcu_assign_pointer(rtpoll_task, NULL); timer_delete(&rtpoll_timer); mod_timer(&rtpoll_timer, ...); rcu_read_unlock(); synchronize_rcu(); kthread_stop(task_to_destroy); The group can then be freed with the re-armed timer still pending, and poll_timer_fn() runs on freed memory. 461daba06bdc ("psi: eliminate kthread_worker from psi trigger scheduling mechanism") deleted the timer synchronously after the synchronize_rcu(), which prevented this but raced trigger creation instead: the deletion could cancel the timer that a new trigger set armed during the grace period and, as creation also reinitialized the timer at the time, corrupt it. 8f91efd870ea ("psi: Fix race between psi_trigger_create/destroy") moved the initialization into group_init() and the deletion into the locked section, trading the creation races for the window above. Neither placement in the destruction path works. A pending timer firing while the group is alive is harmless though. poll_timer_fn() just wakes the rtpoll waitqueue and doesn't re-arm itself. Bind the timer to the group's lifetime instead and shut it down in psi_cgroup_free(). Nothing can arm it by then. timer_shutdown_sync() because the timer is never armed again.
Quoted source text, attributed separately from HOL analysis.