VYPR
Medium severity5.5NVD Advisory· Published Jul 1, 2026· Updated Jul 23, 2026

CVE-2026-53326

CVE-2026-53326

Description

In the Linux kernel, the following vulnerability has been resolved:

debugobjects: Don't call fill_pool() in early boot hardirq context

When booting a debug PREEMPT_RT kernel on an ARM64 system, a "inconsistent {HARDIRQ-ON-W} -> {IN-HARDIRQ-W} usage" lockdep warning message was reported to the console.

During early boot, interrupts are enabled before the scheduler is enabled. In this window (before SYSTEM_SCHEDULING is set) interrupts can fire and in the hard interrupt context handler attempt to fill the pool

This can lead to a deadlock when the interrupt occurred when the interrupt hits a region which holds a lock that is required to be taken in the allocation path.

Add a new can_fill_pool() helper and reorder the exception rule and forbid this scenario by excluding allocations from hard interrupt context.

Affected products

10
  • Linux/Kernel9 versions
    cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*+ 8 more
    • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: >=6.19,<7.0.13
    • cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:7.1:rc7:*:*:*:*:*:*
    • (no CPE)
  • osv-coords
    Range: >= 6.19.0, < 7.0.13

Patches

Vulnerability mechanics

References

6

News mentions

1