PT-2026-106555 · Linux · Linux

CVE-2026-98226

·

Published

2026-10-06

·

Updated

2026-10-06

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
mm, swap: fix SWAP USAGE OFFLIST BIT collision with real usage count
SWAP USAGE OFFLIST BIT is embedded in the si->inuse pages usage counter, and is meant to sit above any value that counter can reach. However, it is defined from BITS PER TYPE(atomic t), so it is bit 30. On a system with 4 KiB pages the flag collides with the usage count once that count reaches 4 TiB.
swap usage in pages() masks bit 30 out, so whenever the real count has that bit set, every caller of it reads 4 TiB low:
  • /proc/swaps understates Used by 4 TiB.
  • A raw count of exactly 2^30 masks to zero, so try to unuse() takes its "if (!swap usage in pages(si)) goto success;" early exit and swapoff tears the device down while pages are still swapped out. Nothing in the rest of swapoff aborts the teardown, so those pages are lost.
Independently of swapoff, the collision also corrupts the counter and the plist. On a device in normal use, a free that leaves bit 30 set in the count makes swap usage sub() see the flag where there is only count, and call add to avail list(). It clears the bit with fetch and(~SWAP USAGE OFFLIST BIT), leaving the stored count 4 TiB below the real one, and calls plist add() on a device that is already listed, tripping the WARN ON(!plist node empty(node)) in plist add() and linking the node a second time.
Change the definition of SWAP USAGE OFFLIST BIT to be based on atomic long t instead. Note that the usage counter field itself is of this same type, so it is still a valid bit.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98226

Affected Products

Linux