Executive brief
A memory leak vulnerability was identified in the Linux kernel's memory management subsystem. When the system attempts to move large memory pages between different types of storage (such as system RAM and specialized device memory), a failure in certain checks could cause the system to lose track of allocated memory. Over time, this could lead to decreased system performance or instability as available memory is exhausted.
Technical details
A memory leak exists in the Linux kernel's mm/migrate_device.c within the migrate_vma_insert_huge_pmd_page() function. The vulnerability is caused by an improper error handling path where a page table allocated via pte_alloc_one() is not released if a PMD check failure occurs, specifically when jumping to the unlock_abort label. An attacker or a series of system events triggering THP (Transparent Huge Page) migration of zone device pages could repeatedly trigger this leak. This results in the gradual consumption of kernel memory. The issue has been resolved by adding a free_abort label to ensure pte_free() is called during these error conditions.
Affected products
- Linux Linux 6.19, 7.0.12
Timeline
- 2026-05-01: other: Patch submitted by developer
- 2026-07-19: disclosed: CVE published