PT-2026-90471 · Linux · Linux
CVE-2026-89755
·
Publicado
2026-09-11
·
Atualizado
2026-09-11
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
mm/migrate device: clear stale mapping after freeing swapcache
migrate device pages() reads the folio mapping before calling
folio free swap(). When folio free swap() succeeds, the folio is removed
from the swap cache, but the saved mapping still points to swap space.
Passing the stale mapping to folio migrate mapping() makes it use the
mapped-folio path for a folio that is no longer in swapcache. It can then
operate on swap space.i pages with invalid reference accounting,
eventually triggering a folio reference count BUG.
After a successful split, nr still contains the number of pages in the
original large folio, although each resulting page is now a separate
order-0 folio. Reset nr to 1 so each split folio is processed separately,
including its own swapcache removal and mapping lookup.
Refresh the saved mapping after folio free swap() so the current folio
state is used during migration.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux