-

CVE-2026-93230

mm/hugetlb: initialize gigantic bootmem hugepage struct pages earlier

In the Linux kernel, the following vulnerability has been resolved:

mm/hugetlb: initialize gigantic bootmem hugepage struct pages earlier

Gigantic bootmem HugeTLB pages are currently initialized from
hugetlb_init(), but page_alloc_init_late() runs earlier and walks
pageblocks to determine zone contiguity.

If a bootmem HugeTLB region is marked noinit, set_zone_contiguous() can
observe still-uninitialized struct pages through
__pageblock_pfn_to_page().  This may not trigger an immediate failure, but
it can make set_zone_contiguous() compute the wrong zone contiguity state.
If extra poisoned-page checks are added in this path, such as
PF_POISONED_CHECK() in page_zone_id(), it can also trigger an early boot
panic.

Initialize gigantic bootmem HugeTLB struct pages from
page_alloc_init_late(), before zone contiguity is evaluated, so later page
allocator setup only sees valid struct page state.  This also makes the
initialization order more natural, as struct pages should be initialized
before later code inspects them.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version fde1c4ecf91640e5a95ec36b71ec2e8ec379ce40
Version < 09505232eced5f1c42902d8f28740f070c3fc6dc
Status affected
Version fde1c4ecf91640e5a95ec36b71ec2e8ec379ce40
Version < 29968bc7aefb3cf1e72aa7c5f52697a6b0527094
Status affected
Version fde1c4ecf91640e5a95ec36b71ec2e8ec379ce40
Version < b1b7c045e808c761b1cc8c19b3040fadedda3fef
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.7
Status affected
Version 0
Version < 6.7
Status unaffected
Version <= 6.18.*
Version 6.18.51
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.052
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/09505232eced5f1c42902d8f28740f070c3fc6dc
https://git.kernel.org/stable/c/29968bc7aefb3cf1e72aa7c5f52697a6b0527094
https://git.kernel.org/stable/c/b1b7c045e808c761b1cc8c19b3040fadedda3fef