CVE Vulnerabilities

CVE-2026-53314

Published: Jun 26, 2026 | Modified: Jun 26, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

In the Linux kernel, the following vulnerability has been resolved:

padata: Put CPU offline callback in ONLINE section to allow failure

syzbot reported the following warning:

DEAD callback error for CPU1
WARNING: kernel/cpu.c:1463 at _cpu_down+0x759/0x1020 kernel/cpu.c:1463, CPU#0: syz.0.1960/14614

at commit 4ae12d8bd9a8 (Merge tag kbuild-fixes-7.0-2 of git://git.kernel.org/pub/scm/linux/kernel/git/kbuild/linux) which tglx traced to padata_cpu_dead() given its the only sub-CPUHP_TEARDOWN_CPU callback that returns an error.

Failure isnt allowed in hotplug states before CPUHP_TEARDOWN_CPU so move the CPU offline callback to the ONLINE section where failure is possible.

References