Back

MEDIUM

posix-cpu-timers: Use u64 multiplication in update_rlimit_cpu()

Published Aug 15, 2026

Description

update_rlimit_cpu() converts the RLIMIT_CPU value to nanoseconds with

u64 nsecs = rlim_new * NSEC_PER_SEC;

On 32-bit kernels both rlim_new (unsigned long) and NSEC_PER_SEC (1000000000L) are 32-bit, so the multiplication is performed in unsigned long and truncated for rlim_new > 4 seconds before being widened to u64.

The same file already casts to u64 for the matching computation in check_process_timers():

u64 softns = (u64)soft * NSEC_PER_SEC;

As a result, the truncated value is installed into the CPUCLOCK_PROF expiry cache (nextevt), causing the process CPU timer to be programmed to fire prematurely for any RLIMIT_CPU soft limit >= 5 seconds. The actual SIGXCPU/SIGKILL decision in check_process_timers() already casts to u64 and is therefore correct, so limit enforcement is not broken; only the expiry-cache programming is wrong. Apply the same cast here so both paths convert rlim_cur identically.

64-bit kernels are unaffected.

Affected products

Remediation

No remediation recorded yet.

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Aug 15, 2026
Updated Aug 17, 2026
Reserved Aug 9, 2026
NVD
Status Received
Modified Aug 17, 2026
Red Hat
Severity Low
Public date Aug 15, 2026