Junglewise Threat Intelligence

CVE-2026-43286: Linux Kernel resource leak in mm/hugetlb subpool management

CVE-2026-43286 · Severity: info · CVSS 3.3 · Published 2026-05-08

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A flaw in the Linux kernel's memory management system can cause certain memory pools (HugeTLB subpools) to become permanently unusable. This occurs when failed memory requests incorrectly increment a usage counter that never resets, eventually hitting a maximum limit even when no memory is actually being used. This can lead to a denial-of-service condition for applications that rely on large memory pages.

Technical details

A vulnerability in the mm/hugetlb component of the Linux kernel arises from an incorrect accounting of 'used_hpages' in HugeTLB subpools. When a global memory reservation fails after a subpool reservation has already been partially accounted for, the 'used_hpages' counter remains elevated. Because this counter tracks both subpool and global consumption, repeated failed allocation attempts cause the counter to leak until it reaches the 'max_hpages' limit. Once the limit is reached, the subpool is rendered unusable for future allocations, even if no pages are actually in use. The issue was introduced by a previous fix for an underflow error and has been resolved by ensuring failed global reservations are properly uncharged from the subpool's used counter.

Affected products

  • Linux Linux Kernel All versions prior to the fix in 2026-02-12

Timeline

  • 2026-01-16: disclosed: Initial patch submission by Joshua Hahn
  • 2026-02-12: patched: Mainline kernel patch committed by Andrew Morton
  • 2026-05-08: advisory: CVE-2026-43286 published

References

Related threats