Description
In the Linux kernel, the following vulnerability has been resolved:

kho: make sure scratch size is always aligned by CMA_MIN_ALIGNMENT_BYTES

When using scratch_scale, the scratch sizes are rounded up to
CMA_MIN_ALIGNMENT_BYTES since they will be released as MIGRATE_CMA. This
is not done when using fixed scratch sizes via command line. This can
result in user specifying a size which is not aligned, and thus kernel
releasing a pageblock that is only partially scratch.

Do the rounding up for both cases in scratch_size_update().
Published: 2026-08-15
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Linux kernel’s kho memory allocation routine causes scratch page blocks to be rounded incorrectly when a fixed size is supplied from the command line, while a scaled size is rounded correctly. The result is that the kernel may release a page block that is only partly marked as scratch. This partial release can leave unused memory fragments within the block, which later allocations may reuse, potentially leading to memory corruption or data integrity issues. The vulnerability is not a direct code execution vector, but it can be exploited by a local attacker capable of setting scratch sizes or by malicious kernel modules that manipulate the allocation parameters.

Affected Systems

Any Linux kernel installation that has not incorporated the fix referenced in commit 0e39380a7. This includes generic Linux distributions where the kernel build process includes the older kho code path. Without version specifics from the CNA, all kernels that lack the patch are considered vulnerable, regardless of distribution or release level.

Risk and Exploitability

The CVSS score of 5.5 indicates moderate severity, while the EPSS score of < 1% suggests a low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog, further indicating it has not been widely exploited. Attackers would need local privileges or the ability to load kernel modules to manipulate scratch sizes, limiting the threat to environments where such access is granted. As a result, the risk remains moderate and should be addressed with an immediate patch.

Generated by OpenCVE AI on August 18, 2026 at 14:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the kernel to the latest patch set that includes the commit ensuring scratch size alignment (commit 0e39380a7).
  • If a kernel upgrade cannot be applied immediately, audit any scripts or modules that set scratch sizes and enforce rounding to CMA_MIN_ALIGNMENT_BYTES before the allocation is requested.
  • Restart or reload CMA‑dependent services to clear any partially freed memory until the kernel fix is applied.

Generated by OpenCVE AI on August 18, 2026 at 14:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-131
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Sat, 15 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-762

Sat, 15 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: kho: make sure scratch size is always aligned by CMA_MIN_ALIGNMENT_BYTES When using scratch_scale, the scratch sizes are rounded up to CMA_MIN_ALIGNMENT_BYTES since they will be released as MIGRATE_CMA. This is not done when using fixed scratch sizes via command line. This can result in user specifying a size which is not aligned, and thus kernel releasing a pageblock that is only partially scratch. Do the rounding up for both cases in scratch_size_update().
Title kho: make sure scratch size is always aligned by CMA_MIN_ALIGNMENT_BYTES
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-17T05:09:30.900Z

Reserved: 2026-08-09T03:40:39.910Z

Link: CVE-2026-72169

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:21:34.993

Modified: 2026-08-17T06:18:17.307

Link: CVE-2026-72169

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-15T00:00:00Z

Links: CVE-2026-72169 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T14:15:07Z

Weaknesses
  • CWE-131

    Incorrect Calculation of Buffer Size

  • CWE-762

    Mismatched Memory Management Routines