7.8

CVE-2026-74518

mm/hugetlb: fix list corruption in allocate_file_region_entries()

In the Linux kernel, the following vulnerability has been resolved:

mm/hugetlb: fix list corruption in allocate_file_region_entries()

allocate_file_region_entries() tops up resv->region_cache with freshly
allocated file_region descriptors.  The allocation uses GFP_KERNEL, so
resv->lock is dropped around it: the new entries are gathered on a
stack-local list head, allocated_regions, and spliced into
resv->region_cache once the lock is re-acquired.

The splice used list_splice(), which moves the entries but does not
re-initialize the source head, so allocated_regions is left pointing at an
entry that now lives on resv->region_cache.  The top-up runs in a while
loop that re-checks the cache deficit after re-acquiring the lock.  For a
shared mapping the resv_map is shared by every mapper of the hugetlbfs
inode, so a concurrent region_chg()/region_add()/region_del() on the same
resv_map can consume cache entries during the unlocked window and force a
second iteration.  That iteration calls list_add() on the stale head and
corrupts the list; with CONFIG_DEBUG_LIST the __list_add_valid() check
trips:

  list_add corruption. next->prev should be prev (ffffc900011ff7f8),
  but was ffff88814c281460. (next=ffff88814c545640).
  kernel BUG at lib/list_debug.c:31!
   allocate_file_region_entries+0x191/0x420
   region_chg+0x267/0x300
   hugetlb_reserve_pages+0x387/0xc80
   hugetlbfs_file_mmap+0x2ce/0x3f0
   mmap_region+0x1348/0x1a80
   do_mmap+0x85e/0xb90
   vm_mmap_pgoff+0x18c/0x330
   ksys_mmap_pgoff+0x2a1/0x3e0
   do_syscall_64+0xd7/0x420

Without CONFIG_DEBUG_LIST the bad list_add() silently links a kernel-stack
address into resv->region_cache, leading to later use-after-free.

This was observed as a real host panic on a dense KVM host where a QEMU
guest-RAM hugetlbfs file was mapped MAP_SHARED by both QEMU and a separate
SPDK/DPDK vhost-user target, generating concurrent region_* traffic on one
shared resv_map.

Use list_splice_init() so the source head is re-initialized empty after
each splice, making the retry loop safe.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version d3ec7b6e09e512ba902b86bcca2c512fb06d492f
Version < 01b8569233e47693d6ff7efa96d9854c55f936fc
Status affected
Version d3ec7b6e09e512ba902b86bcca2c512fb06d492f
Version < 9c5fdffc5e1ce84403c58289ee72697051803bf7
Status affected
Version d3ec7b6e09e512ba902b86bcca2c512fb06d492f
Version < f3e54f6a5e1681f83d13e8716bc92ef5ecf121d3
Status affected
Version d3ec7b6e09e512ba902b86bcca2c512fb06d492f
Version < 62e1c2741a4d923d9854efd5927a6212aad7a187
Status affected
Version d3ec7b6e09e512ba902b86bcca2c512fb06d492f
Version < 587a0accc2b4fccc5cf7baf0fe34e50efde51f9c
Status affected
Version d3ec7b6e09e512ba902b86bcca2c512fb06d492f
Version < 126a70bf1a08ddc9d79c471ebdaa2b08cfbab8df
Status affected
Version d3ec7b6e09e512ba902b86bcca2c512fb06d492f
Version < ac1bb7fd45088d0db57a22ce7729f258ebd63cf5
Status affected
Version d3ec7b6e09e512ba902b86bcca2c512fb06d492f
Version < dd9623f58ec702a07b2d67179d6fcea79c52231a
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 5.10
Status affected
Version 0
Version < 5.10
Status unaffected
Version <= 5.10.*
Version 5.10.265
Status unaffected
Version <= 5.15.*
Version 5.15.216
Status unaffected
Version <= 6.1.*
Version 6.1.183
Status unaffected
Version <= 6.6.*
Version 6.6.151
Status unaffected
Version <= 6.12.*
Version 6.12.103
Status unaffected
Version <= 6.18.*
Version 6.18.44
Status unaffected
Version <= 7.1.*
Version 7.1.8
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.13% 0.027
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/62e1c2741a4d923d9854efd5927a6212aad7a187
https://git.kernel.org/stable/c/587a0accc2b4fccc5cf7baf0fe34e50efde51f9c
https://git.kernel.org/stable/c/126a70bf1a08ddc9d79c471ebdaa2b08cfbab8df
https://git.kernel.org/stable/c/ac1bb7fd45088d0db57a22ce7729f258ebd63cf5
https://git.kernel.org/stable/c/dd9623f58ec702a07b2d67179d6fcea79c52231a
https://git.kernel.org/stable/c/01b8569233e47693d6ff7efa96d9854c55f936fc
https://git.kernel.org/stable/c/9c5fdffc5e1ce84403c58289ee72697051803bf7
https://git.kernel.org/stable/c/f3e54f6a5e1681f83d13e8716bc92ef5ecf121d3