Junglewise Threat Intelligence

CVE-2026-80729: Linux kernel memory management uninitialized state in folio split

CVE-2026-80729 · Severity: info · Published 2026-09-03

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's memory management system has a bug in how large memory pages ("folios") are split into smaller pieces. When splitting pages in the cache, the workingset tracking system is not properly initialized, which can cause the kernel to trigger warning checks during memory reclamation. This is a data structure consistency issue rather than a security vulnerability, though it can cause system instability.

Technical details

This vulnerability is a missing initialization in the folio splitting code (mm/huge_memory.c). When __folio_split() splits a folio, it does not call mapping_set_update() on the xa_state, leaving the xa_lru field unset. This allows a live, memcg-charged xa_node to exist without being linked into the mapping's shadow_nodes list_lru. During memory reclamation, when the kernel walks the list_lru structures, it encounters this unlinked node and triggers VM_WARN_ON(!css_is_dying()), indicating a kernel warning condition. The fix involves calling mapping_set_update(&xas, mapping) to properly initialize both the workingset update callback and shadow_nodes list_lru on the xa_state. The vulnerability affects the folio splitting code path and requires no external access—it is triggered internally during memory management operations.

Affected products

  • Linux Linux kernel affected versions vary; fix applies to multiple stable series

Timeline

  • 2026-09-03: disclosed: CVE-2026-80729 published on NVD
  • 2026-08-04: patched: Patch committed upstream by Andrew Morton
  • 2026-08-19: patched: Backported to stable kernels by Greg Kroah-Hartman

References

Related threats