Junglewise Threat Intelligence

CVE-2026-64302: Linux Kernel memory leak in x86 vmemmap page freeing

CVE-2026-64302 · Severity: info · CVSS 0 · Published 2026-07-25

Technologies: Linux. Vendors: Linux.

Executive brief

A memory management issue was identified in the Linux kernel affecting x86 systems. The system incorrectly handles the release of certain memory structures (vmemmap pages), leading to a memory leak where only a small portion of the memory is actually freed. Over time, this could lead to system instability or resource exhaustion as memory is consumed and not returned to the system.

Technical details

The vulnerability stems from a regression introduced in the x86/mm subsystem where vmemmap pages were incorrectly passed to pagetable_free(). Because vmemmap pages are not compound pages, pagetable_free()—which relies on compound_order(page)—only frees the first page of a PMD-sized block. This results in a kernel memory leak. The fix decouples pagetable and vmemmap freeing by introducing free_vmemmap_pages() to correctly handle non-compound vmemmap page blocks. The issue primarily affects x86_64 systems during memory hot-unplug or similar operations where vmemmap regions are removed.

Affected products

  • Linux Linux 6.18.7 to 6.18.39, 6.19

Timeline

  • 2026-04-29: disclosed: Initial patch submitted by David Hildenbrand
  • 2026-07-18: patched: Fix committed to stable branches
  • 2026-07-25: advisory: CVE-2026-64302 published

References