{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  mm/migrate: report RCU-tasks quiescent states in migrate_pages_batch()  migrate_pages_batch() unmaps each folio before moving it, and every unmap runs the mmu_notifier invalidate callbacks.  On KVM hosts try_to_migrate() ends up in kvm_mmu_notifier_invalidate_range_start() -\u003e tdp_mmu_zap_leafs(), which is expensive, so unmapping a large batch keeps the CPU busy for a long time.  The loop already calls cond_resched(), but on PREEMPTION kernels that is a no-op, and involuntary preemption is not a Tasks-RCU quiescent state.  A long batch therefore never reports a quiescent state, and the migrating task (e.g. kcompactd) becomes a Tasks-RCU holdout, stalling the Tasks-RCU grace period for minutes, which is common at Meta fleet:    INFO: rcu_tasks detected stalls on tasks:   0000000055349ecc: .. nvcsw: 1157401/1157401 holdout: 1 idle_cpu: -1/56 task:kcompactd0      state:R  running task   Call Trace:    tdp_mmu_zap_leafs    tdp_mmu_next_root    gfn_to_pfn_cache_invalidate_start    kvm_mmu_notifier_invalidate_range_start    __mmu_notifier_invalidate_range_start    try_to_migrate_one    try_to_migrate    migrate_pages_batch    migrate_pages    compact_zone    compact_node    kcompactd    kthread  Use cond_resched_tasks_rcu_qs() so a quiescent state is reported even when cond_resched() does nothing.  This has also been discussed at [1]",
  "id": "DEBIAN-CVE-2026-89756",
  "modified": "2026-09-15T08:47:27.214457236Z",
  "published": "2026-09-11T20:20:06.643Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-89756"
    }
  ],
  "upstream": [
    "CVE-2026-89756"
  ]
}