In the Linux kernel, the following vulnerability has been resolved: debugobjects: Don't call fill_pool() in early boot hardirq context When booting… (CVE-2026-53326)
A vulnerability in the Linux kernel debugobjects subsystem could cause a deadlock during early boot on ARM64 systems running a debug PREEMPT_RT kernel. The issue arises because interrupts can fire before the scheduler is enabled, leading to a lockdep warning and potential deadlock when fill_pool() is called in hard interrupt context. The vulnerability has been resolved by adding a helper to prevent pool filling in this context.
AI Analysis
Technical Summary
This vulnerability (CVE-2026-53326) affects the Linux kernel debugobjects component during early boot on ARM64 systems with debug PREEMPT_RT kernels. Interrupts enabled before the scheduler can trigger hard interrupt context handlers that call fill_pool(), potentially causing deadlocks due to lock dependencies. The fix involves introducing a can_fill_pool() helper and reordering exception rules to forbid allocations in hard interrupt context during early boot, preventing this deadlock scenario.
Potential Impact
The vulnerability can cause a deadlock during system boot on affected ARM64 debug PREEMPT_RT kernels, potentially leading to a denial of service by halting the boot process. There is no impact on confidentiality or integrity reported.
Mitigation Recommendations
A fix has been implemented in the Linux kernel to prevent fill_pool() calls in early boot hard interrupt context by adding a can_fill_pool() helper and adjusting exception rules. Users should apply the official kernel updates that include this fix once available. Patch status is not yet confirmed; check the vendor advisory for current remediation guidance.
In the Linux kernel, the following vulnerability has been resolved: debugobjects: Don't call fill_pool() in early boot hardirq context When booting… (CVE-2026-53326)
Description
A vulnerability in the Linux kernel debugobjects subsystem could cause a deadlock during early boot on ARM64 systems running a debug PREEMPT_RT kernel. The issue arises because interrupts can fire before the scheduler is enabled, leading to a lockdep warning and potential deadlock when fill_pool() is called in hard interrupt context. The vulnerability has been resolved by adding a helper to prevent pool filling in this context.
CVSS v3.1
Score 5.5medium
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CVE-2026-53326) affects the Linux kernel debugobjects component during early boot on ARM64 systems with debug PREEMPT_RT kernels. Interrupts enabled before the scheduler can trigger hard interrupt context handlers that call fill_pool(), potentially causing deadlocks due to lock dependencies. The fix involves introducing a can_fill_pool() helper and reordering exception rules to forbid allocations in hard interrupt context during early boot, preventing this deadlock scenario.
Potential Impact
The vulnerability can cause a deadlock during system boot on affected ARM64 debug PREEMPT_RT kernels, potentially leading to a denial of service by halting the boot process. There is no impact on confidentiality or integrity reported.
Mitigation Recommendations
A fix has been implemented in the Linux kernel to prevent fill_pool() calls in early boot hard interrupt context by adding a can_fill_pool() helper and adjusting exception rules. Users should apply the official kernel updates that include this fix once available. Patch status is not yet confirmed; check the vendor advisory for current remediation guidance.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-r6vx-43g9-hvqx
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-53326"]
- Ecosystems
- []
- Database Specific Severity
- null
- Cvss Version
- 3.1
Threat ID: 6a498a7327e9c7971936e9fd
Added to database: 07/04/2026, 22:34:27 UTC
Last enriched: 07/23/2026, 22:57:01 UTC
Last updated: 07/31/2026, 19:24:47 UTC
Views: 28
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.