Junglewise Threat Intelligence

CVE-2026-53342: Linux kernel resource leak in ARM64 hot-removed page tables

CVE-2026-53342 · Severity: info · CVSS 0 · Published 2026-07-01

Technologies: Linux. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel affecting ARM64 systems during memory management operations. When memory is removed from a running system (hot-removal), the kernel fails to properly clean up internal page table structures. This can lead to system instability, incorrect memory statistics, or memory leaks, potentially impacting the reliability of high-availability servers.

Technical details

A resource management vulnerability exists in the Linux kernel's ARM64 memory management unit (MMU). Since commit 5e8eb9aeeda3, page-table allocations always invoke constructors (pagetable_*_ctor), which set the page type to PGTY_table and increment NR_PAGETABLE. However, the corresponding destructor (pagetable_dtor) was missing in the hot-plug removal path (free_hotplug_pgtable_page). This omission causes a 'Bad page state' warning in kernels with DEBUG_VM enabled because the page_type (sharing space with _mapcount) is not cleared. Additionally, it can lead to memory leaks of page table locks (PTL) when ALLOC_SPLIT_PTLOCKS is enabled. The issue is resolved by ensuring pagetable_dtor() is called before freeing the page.

Affected products

  • Linux Linux 6.16 to 6.18.35, 7.0.12

Timeline

  • 2026-07-01: advisory
  • 2026-07-01: disclosed
  • 2026-06-19: patched

References