Executive brief
A technical issue was identified in the Linux kernel's memory management system during the process of cleaning up memory used by hardware devices. While this primarily results in system warnings during process shutdown, it stems from an incorrect assumption about how private memory is tracked. This could potentially lead to instability in specialized environments using device-private memory, such as those with high-performance GPUs or accelerators.
Technical details
A logic error existed in mm/memory.c where the unmap path used vma_is_anonymous() to verify assumptions about device-private/exclusive entries, which are only supported for anonymous folios. While anonymous VMAs only contain anonymous folios, the reverse is not true; anonymous folios can exist within private file-backed mappings. This discrepancy allowed devices to migrate folios to device-private memory that the unmap path later flagged as unexpected, triggering a WARN_ON in unmap_page_range(). The fix synchronizes the check to use folio_test_anon() in zap_nonpresent_ptes(), matching the logic used in __migrate_device_pages() and make_device_exclusive().
Affected products
- Linux Linux kernel 7.0.0+
Timeline
- 2026-05-01: disclosed: Initial patch submission by Alistair Popple
- 2026-06-01: patched: Patch committed to stable tree
- 2026-07-19: advisory: CVE-2026-64131 published
References
- https://git.kernel.org/stable/c/2fff0cdd942261497fb8922a194b4da3315ae864
- https://git.kernel.org/stable/c/52f72b3f8f6fa64abb71b711962b97f1f6aced1c
- https://git.kernel.org/stable/c/a825691b804b35141aaf4eac91003a70846e316d
- https://git.kernel.org/stable/c/be3f38d05cc5a7c3f13e51994c5dd043ab604d28
- https://git.kernel.org/stable/c/e7af1b15c884ed12bb69da11aec095045d861ee8
- https://git.kernel.org/stable/c/e81446b559db4c98a6c2c5e039ac9cb23658432e