Executive brief
The Linux kernel's huge page memory management contains a charge/uncharge mismatch in cgroup tracking that causes memory accounting errors. When huge pages are allocated with reservations, the reserved charge is tracked using the wrong cgroup pointer, causing the system to decrement counters for the wrong memory group when pages are freed. This leads to negative accounting values and kernel warnings, potentially affecting container isolation and resource limits on systems using hugetlb.
Technical details
The vulnerability is a logic error in alloc_hugetlb_folio() where a single h_cg pointer is reused for both reserved and non-reserved cgroup charges. When map_chg is set, hugetlb_cgroup_charge_cgroup_rsvd() stores the reserved charge target in h_cg, but the immediately following hugetlb_cgroup_charge_cgroup() call overwrites h_cg with the non-reserved pointer. This causes hugetlb_cgroup_commit_charge_rsvd() to commit the wrong cgroup pointer to the folio. On folio free, the mismatch causes free_huge_folio() to decrement counters in the wrong cgroup, resulting in page_counter underflow warnings. The attack vector is local; a user can trigger this via large memory allocations with reserved mappings. The fix introduces a separate h_cg_rsvd pointer to keep reserved and non-reserved charge paths independent.
Affected products
- Linux Linux kernel multiple versions (introduced by commit 08cf9faf7558, patched in linux-5.15.y, linux-6.x.y, and other stable series as of 2026-07-24
Timeline
- 2026-08-15: disclosed
- 2026-05-28: patched: upstream fix merged in mainline
- 2026-07-24: patched: backported to stable kernel series