Executive brief
A vulnerability in the Linux kernel's memory management system could allow for data corruption during specific memory migration tasks. This issue occurs when the system incorrectly identifies memory as writable when it should be read-only, potentially leading to inconsistent data states between parent and child processes. While primarily affecting systems using specialized hardware memory features, it represents a risk to data integrity and system stability.
Technical details
A vulnerability in set_pmd_migration_entry() within mm/huge_memory.c arises from the incorrect use of pmd_write(), pmd_soft_dirty(), and pmd_uffd_wp() on device-private PMD entries. On x86-64 architectures, the soft-dirty bit aliases with the write bit; consequently, the kernel may misinterpret soft-dirty status as a permission to write. This leads to a race or logic error where read-only migration entries are replaced with writable ones during RAM migration, causing AnonExclusive folio mapping count mismatches and potential memory corruption. The fix involves correctly referencing softleaf entry fields to determine writability and other flags.
Affected products
- Linux Linux 65edfda6f3f2 to 43e7f189769c512c843184a8a5892ac779a6bd90
Timeline
- 2026-06-01: patched: Initial fix committed to mainline kernel
- 2026-06-25: disclosed: CVE-2026-53155 published