Executive brief
The Linux kernel contains a race condition in how it manages write-protection markers on large ("hugetlb") memory pages used by userfaultfd. When the kernel attempts to mark these pages as write-protected, it can lose important hardware updates (Dirty or Accessed flags) that track memory modifications, potentially causing data consistency issues or incorrect memory tracking for applications relying on userfaultfd functionality.
Technical details
The vulnerability is a race condition in make_uffd_wp_huge_pte() within fs/proc/task_mmu.c. The function attempts to set the UFFD_WP bit on a present HugeTLB PTE by reading a PTE snapshot and then calling huge_ptep_modify_prot_commit() without first calling huge_ptep_modify_prot_start(). The start helper atomically clears the PTE entry to prevent the hardware from modifying it during the operation. Without this call, the hardware can set Dirty or Accessed bits between the snapshot read and the commit, causing those updates to be lost when the stale snapshot is written back. The non-hugetlb sibling function make_uffd_wp_pte() implements the correct pattern using ptep_modify_prot_start()/ptep_modify_prot_commit(). The fix mirrors this pattern for the present-PTE branch, while the migration entry case (non-present) is unaffected since there is no hardware update race.
Affected products
- Linux Linux kernel affected versions prior to fix
Timeline
- 2026-08-15: disclosed
- 2026-08-15: patched: Fix provided in patch series