-

CVE-2026-97942

x86/alternatives: Exclude text poking against change_page_attr()

In the Linux kernel, the following vulnerability has been resolved:

x86/alternatives: Exclude text poking against change_page_attr()

From time to time, the following BUG can be observed
in the x86 alternatives patching code [0]:

  > kernel BUG at arch/x86/kernel/alternative.c:2576!
  > Oops: invalid opcode: 0000 [#1] SMP NOPTI
  > CPU: 0 UID: 0 PID: 355 Comm: (udev-worker) Not tainted 7.1.3-1-default #1 PREEMPT(full) openSUSE Tumbleweed  8c1795b03ec64f997e57a8ad38b1161e3b98da64
  > Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS unknown 02/02/2022
  > RIP: 0010:__text_poke+0x2aa/0x450
  > Call Trace:
  >  <TASK>
  >  smp_text_poke_batch_finish+0x2a7/0x320
  >  __static_call_transform+0xb7/0x220
  >  arch_static_call_transform+0x5b/0xb0
  >  __static_call_init+0xe9/0x270
  >  static_call_module_notify+0x11f/0x150
  >  notifier_call_chain+0x61/0xe0
  >  blocking_notifier_call_chain_robust+0x63/0xc0
  >  load_module+0x1c92/0x20c0
  >  init_module_from_file+0xd8/0x140
  >  idempotent_init_module+0x100/0x2f0
  >  __x64_sys_finit_module+0x71/0xe0
  >  do_syscall_64+0xe1/0x610
  >  entry_SYSCALL_64_after_hwframe+0x76/0x7e

which matches the following BUG_ON() in alternative.c:

	/*
	 * If something went wrong, crash and burn since recovery paths are not
	 * implemented.
	 */
	BUG_ON(!pages[0] || (cross_page_boundary && !pages[1]));

This can happen if vmalloc_to_page() fails, for any reason. Such can happen
if text poking races with CPA, which can possibly result in the collapsing
of page tables (or breaking of PMD hugepages). It is not a problem for most
users of vmalloc_to_page() (they solely own the vmalloc'd range) but, when
CONFIG_ARCH_HAS_EXECMEM_ROX=y, various modules own a single execmem vmalloc
range, and can call set_memory_*() in parallel on it. This can happen to
race against __text_poke and cause havoc in vmalloc_to_page().

Fix it by excluding against CPA using the init_mm mmap read lock.

[ dhansen: Fix up SoB ordering. The actual code flow here was:
	   Pedro=>Lorenzo=>Mike=>Me which is reflected in the SoB chain
	   now. I *believe* Mike simply picked up Lorenzo's update to
	   Pedro's post from the Link ]
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 64f6a4e10c05ed527f0f24b7954964255e0d3535
Version < 281e6f536f2f3f95d91938c5bd7ba9bcb4c1049d
Status affected
Version 64f6a4e10c05ed527f0f24b7954964255e0d3535
Version < 89c60435b90d32ab5e3a39da3ae73d463d07debe
Status affected
Version 64f6a4e10c05ed527f0f24b7954964255e0d3535
Version < 1587d3394e254639cc36516256031334095e6ef3
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.15
Status affected
Version 0
Version < 6.15
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= 7.2.*
Version 7.2.7
Status unaffected
Version <= *
Version 7.3-rc4
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.086
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/281e6f536f2f3f95d91938c5bd7ba9bcb4c1049d
https://git.kernel.org/stable/c/89c60435b90d32ab5e3a39da3ae73d463d07debe
https://git.kernel.org/stable/c/1587d3394e254639cc36516256031334095e6ef3