-
CVE-2026-72174
- EPSS 0.2%
- Veröffentlicht 15.08.2026 05:53:39
- Zuletzt bearbeitet 17.08.2026 06:18:17
- Erkennungen
fs/proc/task_mmu: fix hugetlb self-deadlock in pagemap_scan_pte_hole()
In the Linux kernel, the following vulnerability has been resolved:
fs/proc/task_mmu: fix hugetlb self-deadlock in pagemap_scan_pte_hole()
A PAGEMAP_SCAN ioctl requesting PM_SCAN_WP_MATCHING on a hugetlb VMA hangs
the calling thread, unkillably, as soon as the scan reaches an unpopulated
part of the range:
do_pagemap_scan()
walk_page_range()
walk_hugetlb_range()
hugetlb_vma_lock_read() # take the vma lock for read ...
pagemap_scan_pte_hole() # ... ->pte_hole() for a hole
uffd_wp_range()
change_protection()
hugetlb_change_protection()
hugetlb_vma_lock_write() # ... and block taking it for write
walk_hugetlb_range() holds the hugetlb vma lock for read across the whole
walk. A present entry goes to ->hugetlb_entry(); an unpopulated one goes
to ->pte_hole(), i.e. pagemap_scan_pte_hole(). To write-protect the hole
that handler calls uffd_wp_range(), which on a hugetlb VMA reaches
hugetlb_change_protection() and takes the same vma lock for write. The
thread then blocks in down_write() waiting for the read lock it is itself
holding.
The populated path avoids this: pagemap_scan_hugetlb_entry()
write-protects the entry inline under the page-table lock and never enters
hugetlb_change_protection().
Do the same for holes. Fault in the page table and install the uffd-wp
marker directly with make_uffd_wp_huge_pte() under the page-table lock,
rather than routing through uffd_wp_range(). That is the same sequence
hugetlb_change_protection() runs for an unpopulated entry, minus the vma
write lock -- which is safe to skip because PMD sharing is disabled on
uffd-wp VMAs (hugetlb_unshare_all_pmds() runs at registration), leaving
nothing for that lock to serialise against.Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
52526ca7fdb905a768a93f8faa418e9b988fc34b
Version <
a6ac03652d9edc30c2912037ac83beb42cc67f8e
Status
affected
Version
52526ca7fdb905a768a93f8faa418e9b988fc34b
Version <
43b987ed35be9be21a303d1036d4241fec9943df
Status
affected
Version
52526ca7fdb905a768a93f8faa418e9b988fc34b
Version <
18b8a9700610299819d21fd0ea85d24726d17f65
Status
affected
Version
52526ca7fdb905a768a93f8faa418e9b988fc34b
Version <
e92d92bbafb264dc0518d52b846a3c07ed8d523f
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
6.7
Status
affected
Version
0
Version <
6.7
Status
unaffected
Version <=
6.12.*
Version
6.12.97
Status
unaffected
Version <=
6.18.*
Version
6.18.40
Status
unaffected
Version <=
7.1.*
Version
7.1.5
Status
unaffected
Version <=
*
Version
7.2
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.2% | 0.102 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/a6ac03652d9edc30c2912037ac83beb42cc67f8e
https://git.kernel.org/stable/c/43b987ed35be9be21a303d1036d4241fec9943df
https://git.kernel.org/stable/c/18b8a9700610299819d21fd0ea85d24726d17f65
https://git.kernel.org/stable/c/e92d92bbafb264dc0518d52b846a3c07ed8d523f