Linux Kernel RCU Tasks Rude Grace-Period Optimization Race Condition Vulnerability

Vulnerability

A race condition vulnerability has been identified in the Linux kernel's RCU tasks mechanism, specifically within the grace-period processing for secondary CPUs. During the booting of these CPUs, the online CPU mask is not stable, leading to a transient online mask that can cause improper scheduling. This issue was observed in version 5.17.0-rc3-v8+ on the Raspberry Pi 4 Model B.

Impact

The vulnerability can lead to a race condition where the RCU Tasks Rude grace-period processing is improperly synchronized, potentially causing missed or delayed task completions on secondary CPUs during the boot process.

Remediation

The vulnerability has been addressed in the official Linux kernel repository. Users should upgrade to the latest stable version of the Linux kernel where this issue has been fixed.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
0.6
exploitability
5.0
remediation
0.0
relevance
0.0
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.