Junglewise Threat Intelligence

CVE-2026-46318: Linux Kernel resource leak in hugetlbfs mmap_prepare

CVE-2026-46318 · Severity: info · CVSS 0 · Published 2026-06-09

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A memory management issue was identified in the Linux kernel's hugetlbfs component, which handles large memory pages. An error in how the system prepares memory mappings could lead to a resource leak (specifically a VMA lock) if a memory allocation fails at a specific stage. While primarily a technical stability issue, such leaks can eventually impact system performance or reliability.

Technical details

A vulnerability was identified in the hugetlbfs implementation of the Linux kernel related to the 'mmap_prepare' stage. The root cause was incorrect handling of hugetlb Virtual Memory Area (VMA) lock allocations; specifically, if a memory allocation failed after 'mmap_prepare' was invoked but before completion, the allocated lock could be leaked. This was addressed by reverting the transition to 'mmap_prepare' for hugetlbfs and returning to the standard '.mmap' hook. The fix ensures that VMA flags and locks are managed in a state where the VMA is not yet linked to the tree, preventing rmap races and ensuring proper cleanup on failure.

Affected products

  • Linux Linux Kernel 6.9

Timeline

  • 2026-05-12: disclosed: Initial patch submitted to revert the problematic code.
  • 2026-06-09: patched: Patch committed to stable tree.
  • 2026-06-09: advisory: CVE-2026-46318 published.

References

Related threats