CVE-2026-80727: x86/mce: Set up the polling timer before CMCI discovery
In the Linux kernel, the following vulnerability has been resolved:
x86/mce: Set up the polling timer before CMCI discovery
I hit the following on one of my machines:
mce: CPU0 BANK15 CMCI inherited storm ------------[ cut here ]------------ ODEBUG: assertinit not available (active state 0) object: (ptrval) object type: timerlist hint: 0x0 WARNING: lib/debugobjects.c:632 at debugobjectassertinit+0x178/0x230, CPU#0: swapper/0/0 CPU: 0 UID: 0 PID: 0 Comm: swapper/0 Not tainted 7.2.0-rc5 #3 PREEMPTLAZY RIP: 0010:debugobjectassertinit+0x18f/0x230 Call Trace: <TASK> modtimer mcetimerkick cmcidiscover intelinitcmci mceintelfeatureinit mcheckcpuinit identifycpu identifybootcpu archcpufinalizeinit startkernel
A second splat follows right after, from timersetup() finding that same timer already queued:
ODEBUG: init active (active state 0) object: (ptrval) object type: timerlist hint: stubtimer+0x0/0x10
This is happening because CMCI storm detection is trying to modify the timer before latter was properly set up.
Set up the timer first. mcheckcpusetuptimer() only calls timersetup(), and depends on neither the generic nor the vendor init.
[ bp: Massage commit message. ]
Affected Software
Event History
Frequently Asked Questions
What conditions trigger this issue?
The issue is triggered when CMCI storm detection attempts to modify the machine-check polling timer before that timer has been initialized. The reported path involves CMCI discovery during CPU machine-check initialization.
What symptoms indicate that a system may be affected?
Affected systems may log an "mce: CPU0 BANK15 CMCI inherited storm" message followed by debugobjects warnings. The warnings include "assert_init not available" from debug_object_assert_init and may be followed by a timer_setup() warning that the same timer is already queued.
What is the available remediation?
Apply a Linux kernel update containing the fix that initializes the polling timer before CMCI discovery. The provided stable kernel references identify commits carrying the correction.