Junglewise Threat Intelligence

CVE-2026-80719: Linux kernel MGLRU stale batch updates after memcg reparenting

CVE-2026-80719 · Severity: info · Published 2026-08-28

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's memory management subsystem (MGLRU) contains a race condition in how it tracks memory pages during process group restructuring. When memory groups are reorganized, stale batch updates can cause incorrect page counts, leading to premature out-of-memory errors and system stability issues even when sufficient memory is available.

Technical details

The vulnerability is a race condition in the MGLRU (Multi-Generational Lru) page table walker. The walker batches per-generation size deltas in walk->nr_pages without holding the lruvec lock, then later applies these deltas under lock via reset_batch_size(). During concurrent memcg reparenting, the page table walker can update stale lruvec references after a memcg has begun offline, causing underestimated nr_pages counts. This results in MGLRU skipping memory reclamation when nr_pages reaches zero despite additional reclaimable pages existing. The fix adds a CSS_DYING check under RCU in reset_batch_size() to redirect deltas to the first non-dying ancestor, preventing stale updates. No authentication or user interaction is required; the condition is triggered by normal kernel memory management operations.

Affected products

  • Linux Linux kernel <unknown>

Timeline

  • 2026-08-28: disclosed
  • patched: Fix: make reset_batch_size() check CSS_DYING under RCU before flushing pending batch

Related threats