7.8
CVE-2026-63950
- EPSS 0.16%
- Veröffentlicht 19.07.2026 14:55:43
- Zuletzt bearbeitet 27.07.2026 17:44:23
- CVE-Watchlists
- Unerledigt
mm/rmap: initialize nr_pages to 1 at loop start in try_to_unmap_one
In the Linux kernel, the following vulnerability has been resolved: mm/rmap: initialize nr_pages to 1 at loop start in try_to_unmap_one Initialize nr_pages to 1 at the start of each loop iteration, like folio_referenced_one() does. Without this, nr_pages computed by a previous folio_unmap_pte_batch() call can be reused on a later iteration that does not run folio_unmap_pte_batch() again. mmap a 64K large folio with MAP_ANONYMOUS | MAP_DROPPABLE, then call madvise(MADV_FREE), then make the last page device-exclusive via HMM_DMIRROR_EXCLUSIVE. Trigger node reclaim through sysfs. Now, in try_to_unmap_one(), we will first clear the first 15 out of 16 entries mapping the lazyfree folio. This will set nr_pages to 15. In the next pvmw walk, this nr_pages gets reused on a device-exclusive pte, thus potentially corrupting folio refcount/mapcount. At the moment, I have a userspace program which can make the kernel spit out a trace, but the blow up is in folio_referenced_one(), because there are existing bugs in the interaction between device-private and rmap (which too I am investigating). I did a one liner kernel change to avoid going into folio_referenced_one(), and the kernel blows up at folio_remove_rmap_ptes in try_to_unmap_one which is what I wanted. Note that the bug is there not since file folio batching but lazyfree folio batching, since device-exclusive only works for anonymous folios. Userspace visible effect is simply kernel crashing somewhere due to refcount/mapcount corruption.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
354dffd29575cdf13154e8fb787322354aa9efc4
Version <
0fcc34d0d8fefca4fea349e45c10e3a3d90350eb
Status
affected
Version
354dffd29575cdf13154e8fb787322354aa9efc4
Version <
f611db9b771b2b6775357555d2517af044fca4f0
Status
affected
Version
354dffd29575cdf13154e8fb787322354aa9efc4
Version <
3f8968e9cbf95d5d87d32218906cab0b9b9eddbe
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
6.15
Status
affected
Version
0
Version <
6.15
Status
unaffected
Version <=
6.18.*
Version
6.18.35
Status
unaffected
Version <=
7.0.*
Version
7.0.12
Status
unaffected
Version <=
*
Version
7.1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.16% | 0.058 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
https://git.kernel.org/stable/c/0fcc34d0d8fefca4fea349e45c10e3a3d90350eb
https://git.kernel.org/stable/c/f611db9b771b2b6775357555d2517af044fca4f0
https://git.kernel.org/stable/c/3f8968e9cbf95d5d87d32218906cab0b9b9eddbe