← Voltar à pesquisa de CVEs

CVE-2026-31466

Linux Kernel

Descrição

In the Linux kernel, the following vulnerability has been resolved: mm/huge_memory: fix folio isn-t locked in softleaf_to_folio() On arm64 server, we found folio that get from migration entry isn-t locked in softleaf_to_folio(). This issue triggers when mTHP splitting and zap_nonpresent_ptes() races, and the root cause is lack of memory barrier in softleaf_to_folio(). The race is as follows: CPU0 CPU1 deferred_split_scan() zap_nonpresent_ptes() lock folio split_folio() unmap_folio() change ptes to migration entries __split_folio_to_order() softleaf_to_folio() set flags(including PG_locked) for tail pages folio = pfn_folio(softleaf_to_pfn(entry)) smp_wmb() VM_WARN_ON_ONCE(!folio_test_locked(folio)) prep_compound_page() for tail pages In __split_folio_to_order(), smp_wmb() guarantees page flags of tail pages are visible before the tail page becomes non-compound. smp_wmb() should be paired with smp_rmb() in softleaf_to_folio(), which is missed. As a result, if zap_nonpresent_ptes() access...

CVSS 4.7EPSS 0.094%Risco 0.47
Ver fonte
Publicação
2026-04-22 14:16:42
Versões afetadas
unknown
Tipo
Core software
Vetor
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Sistemas operativos
Linux