PT-2026-93628 · Linux · Linux Kernel
CVE-2026-89987
·
Published
2026-09-16
·
Updated
2026-09-24
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists where the
zap huge pmd folio() function fails to propagate the pmd dirty bit to the folio during the zap process. In MAP SHARED tmpfs mappings, a read fault installs a writable pmd via do read fault(), but subsequent stores only set the hardware dirty bit in the pmd without calling folio mark dirty(). When the folio is unmapped via munmap() or exit mmap(), the zap huge pmd() function drops the pmd without transferring the dirty bit, leading to silent data loss. The system incorrectly identifies the shmem folio as clean, causing the reclaim process to free the data without writing it to swap. This occurs specifically when shmem Transparent Huge Pages (THP) and swap are enabled.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel