7.8
CVE-2026-89755
- EPSS 0.14%
- Veröffentlicht 11.09.2026 19:46:58
- Zuletzt bearbeitet 21.09.2026 14:17:26
- Erkennungen
mm/migrate_device: clear stale mapping after freeing swapcache
In the Linux kernel, the following vulnerability has been resolved: mm/migrate_device: clear stale mapping after freeing swapcache __migrate_device_pages() reads the folio mapping before calling folio_free_swap(). When folio_free_swap() succeeds, the folio is removed from the swap cache, but the saved mapping still points to swap_space. Passing the stale mapping to folio_migrate_mapping() makes it use the mapped-folio path for a folio that is no longer in swapcache. It can then operate on swap_space.i_pages with invalid reference accounting, eventually triggering a folio reference count BUG. After a successful split, nr still contains the number of pages in the original large folio, although each resulting page is now a separate order-0 folio. Reset nr to 1 so each split folio is processed separately, including its own swapcache removal and mapping lookup. Refresh the saved mapping after folio_free_swap() so the current folio state is used during migration.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
df263d9a7dffee94ca5391120ee3b0587efa07f1
Version <
4fa91f7bbc4135240b67daac03fc17d9e180a331
Status
affected
Version
df263d9a7dffee94ca5391120ee3b0587efa07f1
Version <
8ffedc6573a665cdc31ebe47eae7b32b78d0df83
Status
affected
Version
df263d9a7dffee94ca5391120ee3b0587efa07f1
Version <
34a00895d032a414830d41106a09329ae6c251b6
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
6.6
Status
affected
Version
0
Version <
6.6
Status
unaffected
Version <=
6.12.*
Version
6.12.111
Status
unaffected
Version <=
7.2.*
Version
7.2.4
Status
unaffected
Version <=
*
Version
7.3-rc1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.14% | 0.04 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
https://git.kernel.org/stable/c/8ffedc6573a665cdc31ebe47eae7b32b78d0df83
https://git.kernel.org/stable/c/34a00895d032a414830d41106a09329ae6c251b6
https://git.kernel.org/stable/c/4fa91f7bbc4135240b67daac03fc17d9e180a331