PT-2026-61267 · Linux+1 · Linux Kernel+1

CVE-2026-63950

·

Published

2026-07-19

·

Updated

2026-09-07

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the try to unmap one() function within the memory management subsystem. The nr pages variable is not properly initialized at the start of each loop iteration. This allows a value computed by a previous folio unmap pte batch() call to be reused in subsequent iterations where the function is not called again. This can lead to the corruption of folio refcount and mapcount, resulting in a kernel crash. The issue is triggered when using madvise(MADV FREE) on a large anonymous folio and making the last page device-exclusive via HMM DMIRROR EXCLUSIVE during node reclaim.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-63950
USN-8593-1
USN-8603-1
USN-8618-1
USN-8663-1
USN-8664-1
USN-8728-1

Affected Products

Linux Kernel
Ubuntu