mm/huge_memory: use correct flags for device private PMD entry
In the Linux kernel, the following vulnerability has been resolved: mm/huge_memory: use correct flags for device private PMD entry Commit 65edfda6f3f2 ("mm/rmap: extend rmap and migration support device-private entries") updated set_pmd_migration_entry() to use pmdp_huge_get_and_clear() in the softleaf case, but made no further adjustments to the function itself. Therefore this function continues to incorrectly use pmd_write(), pmd_soft_dirty() and pmd_uffd_wp() to determine whether the installed migration entry should be marked writable, softdirty or uffd-wp respectively. Whilst all are incorrect, the most problematic of these is pmd_write(), as this can lead to corrupted rmap state. On x86-64 _PAGE_SWP_SOFT_DIRTY is aliased to _PAGE_RW. So calling pmd_write() on a softleaf will return the softdirty state encoded in the entry, assuming CONFIG_MEM_SOFT_DIRTY was enabled. This was observed when running the hmm.hmm_device_private.anon_write_child selftest: 1. The test faults in a range then migrates it such that a device-private THP range is established. 2. The parent then migrates it to a device-private writable PMD entry whose folio is entirely AnonExclusive with entire_mapcount=1, softdirty set (accidentally correct write state). 3. The parent forks and the PMD entries are set to device-private read only entries, entire_mapcount=2, softdirty still set. 4. [BUG] The child writes to the range then migrates to RAM - intending to install non-writable migration entries - but replacing parent and child PMD mappings with WRITABLE entries due to misinterpreting the softdirty bit. 5. In remove_migration_pmd(), if !softleaf_is_migration_read(entry) we set the RMAP_EXCLUSIVE flag when calling folio_add_anon_rmap_pmd() for both parent and child, which are therefore AnonExclusive. 6. [SPLAT] Child sets migrated folio entire_mapcount=1, parent sets entire_mapcount=2 and we end up with an AnonExclusive folio with entire_mapcount=2! Assert fires in __folio_add_anon_rmap(): VM_WARN_ON_FOLIO(folio_test_large(folio) && folio_entire_mapcount(folio) > 1 && PageAnonExclusive(cur_page), folio) This patch fixes the issue by correctly referencing the softleaf entry fields for writable, softdirty and uffd-wp in set_pmd_migration_entry(). It also only updates A/D flags if the entry is present as these are otherwise not meaningful for a softleaf entry. This patch also flips the if (!present) { ... } else { ... } logic in set_pmd_migration_entry() so it is easier to understand, and adds some comments to make things clearer. I was able to bisect this to commit 775465fd26a3 ("lib/test_hmm: add zone device private THP test infrastructure") which first exposes this bug as it was the commit that permitted test_hmm to generate the test. However commit 65edfda6f3f2 ("mm/rmap: extend rmap and migration support device-private entries") is the commit that actually enabled this behaviour.
- Yayın
- 25 Haz 2026
- Güncelleme
- 7 Tem 2026
- EPSS
- %0,1 · 1. yüzdelik
- CWE
- —
Takip etmek için giriş yap · Takip ettiğin kayıt KEV’e girer, istismarı çıkar ya da güncellenirse bildirim alırsın.
Rapor araçları
Aksiyon skoru
22
İzleyin
Şimdilik düşük öncelik.
- CVSS
- 22 / 40 · 5.5 / 10
- CISA KEV
- 0 / 30 · Listede değil
- EPSS
- 0 / 30 · %0,1
Etkilenen sistemler
| Üretici | Ürün | CPE |
|---|---|---|
| linux | linux kernel | cpe:2.3:o:linux:linux_kernel |
Etkilenen sürümler
NVD sürüm aralıkları (katalogdaki ürünler için). Stack’ine sürümle eklersen eşleşme bunlarla yapılır.
- linux linux kernel6.19 ve sonrası · 7.0.13 öncesi
- linux linux kernel7.1
Üreticinin bildirdiği sürümler
Kaydı açan otorite (Linux) tarafından bildirilen etkilenen sürüm aralıkları. NVD'nin CPE analizinden bağımsızdır ve genellikle ondan önce gelir.
Linux Linux
- 6.19etkilenir
- 65edfda6f3f2e58f757485a056e4f1775a1404a8 ve sonrası · d7251c8d3f7cea76543abac6cf4ed15582c10846 öncesietkilenir · git
- 65edfda6f3f2e58f757485a056e4f1775a1404a8 ve sonrası · 43e7f189769c512c843184a8a5892ac779a6bd90 öncesietkilenir · git
- 6.19 öncesietkilenmez · semver
- 7.0.13 ve sonrası · 7.0.* dahil öncesietkilenmez · semver
- 7.1 ve sonrasıetkilenmez · original_commit_for_fix
Paket düzeyi etkilenme
OSV ve GitHub Advisory verisi: ekosistem, paket ve aralık. SBOM eşleşmesi bu tabloyu kullanır.
| Ekosistem | Paket | Etkilenen aralık | Düzeltme |
|---|---|---|---|
| Debian:14 | linux | 7.0.13-1 öncesi | 7.0.13-1 |
Aynı üründe
linux: tüm kayıtlarAynı birincil ürünün en yüksek skorlu diğer kayıtları.
- CVE-2022-0847A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe KEV89Hemen
- CVE-2021-22555Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACEKEV85Hemen
- CVE-2016-5195Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect haKEV83Hemen
- CVE-2019-13272In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to creKEV77Bu hafta
- CVE-2013-6282The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not validate certain addKEV77Bu hafta
- CVE-2013-2094The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, which allows loKEV77Bu hafta
Düzeltme
Hangi sürüme geçmeli
Üretici, paket deposu ve Microsoft kayıtlarından derlenen düzeltme sürümleri. Yükseltmeden önce üreticinin notunu doğrulayın.
| Ürün / paket | Düzeltilmiş sürüm | Kaynak |
|---|---|---|
| Linux Linux | 43e7f189769c512c843184a8a5892ac779a6bd90 | Üretici (CNA) |
| Linux Linux | d7251c8d3f7cea76543abac6cf4ed15582c10846 | Üretici (CNA) |
| debian:linux | 7.0.13-1 · Debian:14 | Paket deposu (OSV) |
İstismar durumu
Bilinen kamuya açık istismar yok
Şu an kamuya açık bir istismar görülmedi. Bu, güvende olduğunuz anlamına gelmez; yalnızca eşiğin biraz daha yüksek olduğunu gösterir.
Araştırma bağlamı
Pentester ve araştırmacı için: saldırı profili, puan anlaşmazlığı, zaman çizelgesi, yama commit’leri, kredi, varyant ve zincir adayları, bug bounty kapsamı. Hepsi mevcut veriden türetilir; istismar kodu içermez.
Zaman çizelgesi
Yayından bugüne: kavram kanıtı, Metasploit modülü, CISA KEV ve düzeltme kaydı. Tarihler kaynakların bildirdiği tarihlerdir.
Yayın dışında tarihli olay yok.
FIRST EPSS günlük puanı; yalnızca 0,01 ve üstü değişimler kaydedilir (adım grafiği).
Yama ve commit bağlantıları
Referanslardaki commit, PR ve diff adresleri. Patch-diff ve varyant avı için başlangıç noktası; istismar değil, düzeltmedir.
Referanslarda commit ya da PR bağlantısı yok.
Kredi
Tüm araştırmacılarCNA kaydında adı geçen bulan, bildiren ve analistler. Ada tıkla, aynı araştırmacının diğer kayıtlarını gör.
CNA kaydında kredi yok.
Varyant adayları
Aynı üründe aynı zafiyet sınıfı, 18 ay içinde. Yama kök nedeni kapatmadıysa kardeş hata burada olur.
Gece hesaplanan ilişki yok.
Zincir adayları
Aynı üründe kimlik doğrulama atlatma ile yetki isteyen bir açık kısa aralıkla yayımlanmış: birlikte kimlik doğrulamasız bir yola dönüşebilir.
—
Bug bounty kapsamı
Bilinen herkese açık program yok.
Kaynak: bounty-targets-data (HackerOne, Bugcrowd, Intigriti, YesWeHack herkese açık listeleri).
Teknik detay
Saldırı koşulları
- Sisteme yerel erişimi olan biri tetikleyebilir.
- Düşük yetkili bir hesap yeterli.
- Kullanıcının bir şey yapması gerekmez.
- Özel bir koşul gerekmez; tekrarlanabilir.
Başarılı olursa
- Gizlilik
- yok
- Bütünlük
- yok
- Erişilebilirlik
- yüksek · hizmet durdurulabilir
- Saldırı vektörü
- Yerel
- Karmaşıklık
- Düşük
- Gereken yetki
- Düşük
- Kullanıcı etkileşimi
- Gerekmez
- Kapsam
- Değişmez
- Gizlilik etkisi
- Yok
- Bütünlük etkisi
- Yok
- Erişilebilirlik etkisi
- Yüksek
Zayıflık sınıfı (CWE)
—
CVSS vektörü
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvd-primary
Saldırı bağlamı
Bu zafiyet sınıfının (CWE) MITRE CAPEC saldırı desenleri ve ATT&CK teknikleri. Tespit kuralı ve tehdit avı için başlangıç noktası.
Bu CWE için MITRE'de CAPEC/ATT&CK eşlemesi yok.
Noroxi analizi
Bu kayıt için henüz Noroxi analizi yok
385 binden fazla zafiyetin tamamına elle analiz yazmıyoruz; bu dürüst olmazdı. Öne çıkan ve sahada etkisi olan zafiyetler için mekanizma, tespit ve kapatma adımlarını ekibimiz yazıyor.
Bu ürünü kullanıyoruz, yardım isteyinDeğişiklik günlüğü
- Düzeltme✗ → ✓
Takip ettiğiniz kayıtlarda bu değişiklikler bildirim olarak da gelir. →
Referanslar
- git.kernel.org/stable/c/43e7f189769c512c843184a8a5892ac779a6bd90
- git.kernel.org/stable/c/d7251c8d3f7cea76543abac6cf4ed15582c10846
Üretici bildirimleri ve resmî kayıtlar. İstismar/PoC bağlantıları bilinçli olarak dışarıda bırakıldı.