PT-2026-106555 · Linux · Linux
CVE-2026-98226
·
Publicado
2026-10-06
·
Atualizado
2026-10-06
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
mm, swap: fix SWAP USAGE OFFLIST BIT collision with real usage count
SWAP USAGE OFFLIST BIT is embedded in the si->inuse pages usage counter,
and is meant to sit above any value that counter can reach. However, it
is defined from BITS PER TYPE(atomic t), so it is bit 30. On a system
with 4 KiB pages the flag collides with the usage count once that count
reaches 4 TiB.
swap usage in pages() masks bit 30 out, so whenever the real count has
that bit set, every caller of it reads 4 TiB low:
-
/proc/swaps understates Used by 4 TiB.
-
A raw count of exactly 2^30 masks to zero, so try to unuse() takes its "if (!swap usage in pages(si)) goto success;" early exit and swapoff tears the device down while pages are still swapped out. Nothing in the rest of swapoff aborts the teardown, so those pages are lost.
Independently of swapoff, the collision also corrupts the counter and the
plist. On a device in normal use, a free that leaves bit 30 set in the
count makes swap usage sub() see the flag where there is only count, and
call add to avail list(). It clears the bit with
fetch and(~SWAP USAGE OFFLIST BIT), leaving the stored count 4 TiB below
the real one, and calls plist add() on a device that is already listed,
tripping the WARN ON(!plist node empty(node)) in plist add() and linking
the node a second time.
Change the definition of SWAP USAGE OFFLIST BIT to be based on
atomic long t instead. Note that the usage counter field itself is of
this same type, so it is still a valid bit.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux