Junglewise Threat Intelligence

CVE-2026-72174: Linux kernel hugetlb self-deadlock in pagemap_scan_pte_hole

CVE-2026-72174 · Severity: info · Published 2026-08-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A flaw in the Linux kernel's memory scanning mechanism can cause user applications to hang indefinitely when scanning large memory pages (hugetlb). An attacker can trigger this deadlock through a specific system call (PAGEMAP_SCAN ioctl), causing a denial of service by freezing the affected process without the ability to kill it.

Technical details

This is a self-deadlock vulnerability in the hugetlb page table walk code (fs/proc/task_mmu.c). The vulnerability occurs when walk_hugetlb_range() holds the hugetlb VMA lock for read, and then pagemap_scan_pte_hole() attempts to write-protect unpopulated entries by calling uffd_wp_range(), which tries to acquire the same VMA lock for write. The thread blocks in down_write() waiting for a read lock it already holds. The fix avoids routing through uffd_wp_range() for holes by directly installing the uffd-wp marker under the page-table lock using make_uffd_wp_huge_pte(), matching the approach used for populated entries. This eliminates the VMA write lock acquisition and is safe because PMD sharing is already disabled on uffd-wp VMAs.

Affected products

  • Linux Linux kernel unfixed versions prior to the pagemap_scan_pte_hole() fix

Timeline

  • 2026-08-15: disclosed
  • 2026-08-15: patched: Fix applied via commit resolving hugetlb vma lock deadlock

Related threats