PT-2026-93628 · Linux · Linux Kernel

CVE-2026-89987

·

Published

2026-09-16

·

Updated

2026-09-24

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists where the zap huge pmd folio() function fails to propagate the pmd dirty bit to the folio during the zap process. In MAP SHARED tmpfs mappings, a read fault installs a writable pmd via do read fault(), but subsequent stores only set the hardware dirty bit in the pmd without calling folio mark dirty(). When the folio is unmapped via munmap() or exit mmap(), the zap huge pmd() function drops the pmd without transferring the dirty bit, leading to silent data loss. The system incorrectly identifies the shmem folio as clean, causing the reclaim process to free the data without writing it to swap. This occurs specifically when shmem Transparent Huge Pages (THP) and swap are enabled.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-101499
CVE-2026-89987
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel