Executive brief
The Linux kernel's memory page-walking code can incorrectly leave its internal state flag set to ACTION_AGAIN under certain conditions, causing it to re-walk and re-process memory regions. This leads to duplicate processing of memory callbacks and ultimately an out-of-bounds memory write, potentially allowing local attackers to corrupt kernel memory and crash the system or execute arbitrary code.
Technical details
A state management bug in the mm/pagewalk subsystem causes the walk->action flag to remain set to ACTION_AGAIN when a PMD entry is cleared and walk->ops->install_pte is not defined. This corrupts the page walk state machine, causing walk_pud_range() to retry the walk unnecessarily. The resulting duplicate callback invocations lead to duplicate memory operations, manifesting as slab-out-of-bounds writes in functions like __mincore_unmapped_range(). The vulnerability requires local code execution (a fuzzer can trigger it) and results in memory corruption exploitable for denial of service or privilege escalation. Patching involves correctly resetting walk->action to ACTION_SUBTREE when skipping to the next PMD entry.
Affected products
- Linux Linux Kernel before fix commit a7c7074b58d2
Timeline
- 2026-09-11: disclosed
- other: Root cause introduced in commit 3b89863c3fa4 which added walk->action == ACTION_AGAIN check to walk_pud_range()