Executive brief
A vulnerability was identified in the Linux kernel's memory management system affecting ARM64 systems using Memory Tagging Extension (MTE). When certain security features are enabled to clear memory during deletion, the system may fail to properly reset security tags for large memory blocks (huge zero folios). This could allow a local user to see leftover security tags from previous processes, potentially weakening memory protections or leaking information about how memory was previously used.
Technical details
A vulnerability in the Linux kernel's page allocator (mm/page_alloc.c) occurs when init_on_free is enabled on ARM64 systems utilizing the Memory Tagging Extension (MTE). The issue stems from the __GFP_ZEROTAGS flag logic, which skips clearing tag memory during allocation if the page content was already zeroed during the free path. While standard pages are typically initialized via set_pte_at(), huge zero folios mapped through special PMDs bypass this secondary initialization. Consequently, stale tags from previous allocations are exposed to userspace. The fix involves decoupling __GFP_ZEROTAGS from __GFP_ZERO and ensuring tag_clear_highpages() is explicitly instructed whether to clear page content or only the tags. Patches have been merged into the stable kernel tree.
Affected products
- Linux Linux Kernel adfb6609c680 to 738d18f1da35, 2f2aec5120b9, 6a288a4ddb4a
Timeline
- 2026-04-21: disclosed: Initial patch submission by David Hildenbrand
- 2026-06-01: patched: Patch committed to stable tree by Greg Kroah-Hartman
- 2026-07-19: advisory: CVE-2026-64130 published