Junglewise Threat Intelligence

CVE-2026-89754: Linux kernel memory walk action state leak in pagewalk

CVE-2026-89754 · Severity: high · CVSS 7.8 · Published 2026-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's memory page-walking code can incorrectly leave its internal state flag set to ACTION_AGAIN under certain conditions, causing it to re-walk and re-process memory regions. This leads to duplicate processing of memory callbacks and ultimately an out-of-bounds memory write, potentially allowing local attackers to corrupt kernel memory and crash the system or execute arbitrary code.

Technical details

A state management bug in the mm/pagewalk subsystem causes the walk->action flag to remain set to ACTION_AGAIN when a PMD entry is cleared and walk->ops->install_pte is not defined. This corrupts the page walk state machine, causing walk_pud_range() to retry the walk unnecessarily. The resulting duplicate callback invocations lead to duplicate memory operations, manifesting as slab-out-of-bounds writes in functions like __mincore_unmapped_range(). The vulnerability requires local code execution (a fuzzer can trigger it) and results in memory corruption exploitable for denial of service or privilege escalation. Patching involves correctly resetting walk->action to ACTION_SUBTREE when skipping to the next PMD entry.

Affected products

  • Linux Linux Kernel before fix commit a7c7074b58d2

Timeline

  • 2026-09-11: disclosed
  • other: Root cause introduced in commit 3b89863c3fa4 which added walk->action == ACTION_AGAIN check to walk_pud_range()

Related threats