PT-2026-64523 · Linux · Linux

CVE-2026-64302

·

Published

2026-07-25

·

Updated

2026-07-25

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
x86/mm: Fix freeing of PMD-sized vmemmap pages
Commit bf9e4e30f353 ("x86/mm: use pagetable free()"), switched from freeing non-boot page tables through free pages() to pagetable free().
However, the function is also called to free vmemmap pages.
Given that vmemmap pages are not page tables, already the page ptdesc(page) is wrong. But worse, pagetable free() calls:
 free pages(page, compound order(page));
Since vmemmap pages are not compound pages (see vmemmap alloc block()) -- except for HVO, which doesn't apply here -- only first page of a PMD-sized vmemmap page is freed, leaking the other ones.
Fix it by properly decoupling pagetable and vmemmap freeing. free pagetable() no longer has to mess with SECTION INFO, as only the vmemmap is marked like that in register page bootmem memmap().
The indentation in remove pmd table() is messed up. Fix that while touching it.
Bootmem info handling will soon be fixed up. For now, handle it similar to free pagetable(), just avoiding the ifdef.
[ dhansen: changelog munging. More imperative voice ]
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-64302

Affected Products

Linux