PT-2026-34242 · Linux+1 · Linux Kernel+1

Nicholas Carlini

·

Published

2026-04-22

·

Updated

2026-05-01

·

CVE-2026-6386

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the kernel's handling of protection keys for address ranges. The subroutine responsible for updating page table entries fails to account for 1GB largepage mappings created via the shm create largepage(3) interface, incorrectly treating page directory page entries as pointers to other page table pages. An unprivileged user can exploit this by causing the pmap pkru update range() function to treat userspace memory as a page table page, allowing the overwrite of memory that should otherwise be inaccessible. This issue is under active exploitation and can lead to unauthorized access and data breaches.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Permission

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-6386

Affected Products

Freebsd
Linux Kernel