Description
In the Linux kernel, the following vulnerability has been resolved:

fs/proc/task_mmu: do not warn on seeing non-migration pmd entry

Patch series "mm/hmm: A fix and a selftest", v3.

Patch 1 fixes a stale warning present from the time when only migration
softleaf entries were supported at the PMD level.

Patch 2 adds some code into hmm-tests.c which exercises the pagemap path
for PMD device-private entries.


This patch (of 2):

pagemap_pmd_range_thp() warns if a non-present PMD is not a migration
entry. This became false once device-private entries at the PMD level
were added.

Therefore, remove the stale migration-only assertion.
Published: 2026-08-15
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Linux kernel originally emitted a stale warning when the proc/task_mmu module encountered a non‑present PMD that was not a migration entry. With the addition of device‑private PMD entries, the condition that only allowed migration entries became incorrect, producing a false warning. This bug does not allow attackers to compromise confidentiality, integrity, or availability; it merely generates misleading diagnostic output.

Affected Systems

The affected product is the Linux kernel. Kernels that have the older proc/task_mmu logic, before inclusion of the mm/hmm: A fix and a selftest patch series v3, are potentially impacted. No specific version range is provided, so all releases prior to the patch may exhibit the stale warning.

Risk and Exploitability

Because the warning is purely informational and unrelated to any security boundary, the risk remains low. The CVSS score is 5.5, the EPSS score is < 1%, and it is not listed in the CISA KEV catalog. There is no known attack vector or exploitation path, so the bug does not pose a security threat.

Generated by OpenCVE AI on August 18, 2026 at 14:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the kernel patch series 'mm/hmm: A fix and a selftest', v3, which removes the stale PMD migration check; the patch can be obtained from the commit URLs included in the advisory.
  • Rebuild and install the updated kernel so that the new pagemap path handling is incorporated.
  • If an upgrade is not feasible, temporarily suppress the warning by editing fs/proc/task_mmu.c to delete or comment the stale assertion that checks for migration-only PMD entries, then rebuild the kernel.

Generated by OpenCVE AI on August 18, 2026 at 14:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-617
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Low


Sat, 15 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-703

Sat, 15 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: fs/proc/task_mmu: do not warn on seeing non-migration pmd entry Patch series "mm/hmm: A fix and a selftest", v3. Patch 1 fixes a stale warning present from the time when only migration softleaf entries were supported at the PMD level. Patch 2 adds some code into hmm-tests.c which exercises the pagemap path for PMD device-private entries. This patch (of 2): pagemap_pmd_range_thp() warns if a non-present PMD is not a migration entry. This became false once device-private entries at the PMD level were added. Therefore, remove the stale migration-only assertion.
Title fs/proc/task_mmu: do not warn on seeing non-migration pmd entry
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-17T05:09:35.315Z

Reserved: 2026-08-09T03:40:39.910Z

Link: CVE-2026-72173

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:21:35.460

Modified: 2026-08-17T06:18:17.793

Link: CVE-2026-72173

cve-icon Redhat

Severity : Low

Publid Date: 2026-08-15T00:00:00Z

Links: CVE-2026-72173 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T14:15:07Z

Weaknesses
  • CWE-617

    Reachable Assertion

  • CWE-703

    Improper Check or Handling of Exceptional Conditions