Junglewise Threat Intelligence

CVE-2026-72412: Linux kernel s390/mm _PAGE_UNUSED pte bit handling memory corruption

CVE-2026-72412 · Severity: critical · CVSS 9.3 · Published 2026-08-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel on IBM s390 architecture has a memory management bug where incorrect handling of a page table flag can cause guest virtual machines running on KVM to suffer data corruption. KVM sets a "page unused" flag when it unmaps guest pages, but the kernel was incorrectly throwing out pages marked with this flag even when they were actively in use, leading to loss or corruption of guest data.

Technical details

This is a memory management bug in the s390 architecture's page table handling. The _PAGE_UNUSED softbit is intended to signal that a page can be discarded rather than swapped, but KVM sets this bit on userspace PTEs for unused guest pages without a mechanism to clear it when pages become active again. The vulnerable code in set_ptes() and other PTE-setting paths failed to clear this bit, causing actively-used pages to be incorrectly marked for discarding. The fix ensures the _PAGE_UNUSED bit is cleared whenever a present PTE is set, and restricts setting the bit only to present PTEs in gmap_helper_try_set_pte_unused(). This is a local vulnerability affecting virtualization environments running on s390 systems; no network attack vector exists.

Affected products

  • Linux Linux kernel 5.0 and later (s390 architecture)

Timeline

  • 2026-08-15: disclosed
  • 2026-06-23: patched

References

Related threats