Executive brief
A vulnerability was identified in the Linux kernel's memory management for PowerPC systems. It occurs when the system incorrectly handles the cleanup of page table fragments during a process exit, potentially leading to an unstable system state or 'bad page' errors. This could impact system reliability and availability for users running Linux on PowerPC hardware.
Technical details
A race condition or improper state management exists in the PowerPC-specific pte_frag_destroy() function. PowerPC uses pt_frag_refcount to track page table fragments; when pte_free_defer() is used (e.g., during MADV_COLLAPSE), it sets an 'active' flag on the folio. If a process exits while fragments are still cached in mm->context, pte_frag_destroy() may free the folio without clearing this active flag, triggering a 'Bad page state' BUG in the kernel. The fix involves explicitly clearing the folio active flag before calling the page table destructor and freeing the memory.
Affected products
- Linux Linux Kernel 6.18.0-rc3-00141-g1ddeaaace7ff-dirty
Timeline
- 2026-03-09: other: Patch authored
- 2026-05-23: patched: Patch committed to stable tree
- 2026-06-24: advisory: CVE published