Junglewise Threat Intelligence

CVE-2026-46279: Linux kernel uninitialized codetag in mm/alloc_tag

CVE-2026-46279 · Severity: info · CVSS 0 · Published 2026-06-08

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A technical issue was identified in the Linux kernel's memory management system during the system startup process. Certain memory pages allocated very early in the boot sequence were not properly tagged, which could lead to system warnings or instability when those pages are later reclaimed by security or debugging tools. This primarily affects systems running specific kernel debugging configurations and does not typically impact standard production environments.

Technical details

A race condition or initialization ordering issue exists in the Linux kernel's 'mm/alloc_tag' component. During boot, 'page_ext' is initialized relatively late; pages allocated via the buddy allocator before this point (e.g., during 'init_section_page_ext') lack an associated codetag. When these pages are later freed or reclaimed by KASAN, the missing codetag reference triggers a kernel warning ('alloc_tag was not set'). The fix introduces a global array to track these early PFNs and clears their codetags once 'page_ext' is fully initialized. This issue is primarily visible when 'CONFIG_MEM_ALLOC_PROFILING_DEBUG' is enabled.

Affected products

  • Linux Linux kernel 7.0.0-rc4

Timeline

  • 2026-03-31: patched: Initial patch submitted by Hao Ge
  • 2026-06-08: disclosed: CVE-2026-46279 published

References

Related threats