Back

HIGH

mm/mempolicy: fix sleeping allocation in alloc_pages_bulk_weighted_interleave()

Published Sep 16, 2026

Description

syzbot reported a sleeping function called from invalid context splat in bucket_table_alloc().

When rhashtable_insert_slow() rehashes the table under rcu_read_lock(), it calls bucket_table_alloc(..., GFP_ATOMIC | __GFP_NOWARN). If the bucket table allocation uses vmalloc, __vmalloc_node_range_noprof() invokes vm_area_alloc_pages() -> alloc_pages_bulk_mempolicy_noprof() with the passed GFP_ATOMIC flags.

If the current task has an MPOL_WEIGHTED_INTERLEAVE mempolicy, alloc_pages_bulk_weighted_interleave() is called and currently hardcodes GFP_KERNEL when allocating the temporary weights array, triggering a might_alloc() splat in atomic/RCU contexts.

Pass the gfp flags (masked with GFP_RECLAIM_MASK to strip page-allocator zone modifiers like __GFP_HIGHMEM) received by alloc_pages_bulk_weighted_interleave() to kmalloc() instead of hardcoding GFP_KERNEL. Since the weights buffer is immediately initialized in full, kmalloc() is sufficient.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (0)

No CWE recorded.

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Sep 16, 2026
Updated Sep 16, 2026
Reserved Sep 11, 2026
NVD
Status Received
Modified Sep 16, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner Linux
Published Sep 16, 2026
Updated Sep 16, 2026
Exploited since n/a
EUVD-2026-80594