Junglewise Threat Intelligence

CVE-2026-89758: Linux kernel memory policy NULL pointer dereference via device-private PMD

CVE-2026-89758 · Severity: high · CVSS 7.8 · Published 2026-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A flaw in the Linux kernel's memory management system can cause a system crash or unexpected behavior when userspace applications request memory policy changes on GPU-migrated memory. An attacker can trigger this by using GPU drivers and memory management operations, potentially leading to denial of service or silent data corruption.

Technical details

The vulnerability exists in the mm/mempolicy subsystem's queue_folios_pmd() function, which handles PMD-level page table entries during memory policy operations. Since GPU drivers using HMM (Heterogeneous Memory Management) can migrate transparent huge pages (THPs) to device memory, leaving device-private PMD entries, the code fails to check whether a PMD is present before dereferencing it as a folio pointer. The pmd_trans_huge_lock() check returns true for non-present huge PMDs, allowing the vulnerable code path to be reached. An attacker can trigger this via mbind(), migrate_pages(), or set_mempolicy_home_node() syscalls on memory ranges containing device-private PMDs, resulting in NULL pointer dereference, VM_BUG_ON() assertion failures, or silent LRU list corruption. The patch adds a non-present PMD check before folio lookup, mirroring existing logic in queue_folios_pte_range().

Affected products

  • Linux kernel since commit 368076f52ebe (Linux 5.14+)

Timeline

  • 2026-09-11: disclosed

Related threats