Description
In the Linux kernel, the following vulnerability has been resolved:

mm/huge_memory: preserve pmd_swp_uffd_wp on device-private PMD downgrade

change_non_present_huge_pmd() rewrites a writable device-private PMD swap
entry into a readable one without carrying pmd_swp_uffd_wp() across. The
PTE-level change_softleaf_pte() does this correctly; mirror that here,
matching what copy_huge_pmd() does for the fork path. Without the carry,
a plain mprotect() over a UFFD_WP-marked device-private THP strips the bit
and the trap is bypassed on swap-in.
Published: 2026-08-15
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An oversight in the Linux kernel’s huge memory management permits a user to drop the UFFD_WP write‑protection flag from a device‑private huge page mapping during a PMD downgrade. When an mprotect call removes write protection from a THP that is managed by userfaultfd, the kernel fails to propagate the break‑on‑write flag, thereby bypassing the fault trap on swap‑in. This flaw effectively gives write access to memory regions that should remain protected, allowing a malicious actor to corrupt data or execute code in a kernel or privileged context.

Affected Systems

The vulnerability affects all releases of the Linux kernel that contain the buggy algorithm in mm/huge_memory, specifically systems using device‑private huge pages (THPs). All vendor supplies of the Linux kernel (for example, Linux:Linux) are potentially affected, because the patch is applied at the core kernel level.

Risk and Exploitability

The flaw is local to systems that run code with the ability to invoke mprotect on device‑private THPs and to attach a userfaultfd to those pages. The EPSS score is < 1% and the vulnerability is not listed in CISA’s KEV catalog, suggesting limited public exploitation data. If an attacker can reach the application’s memory space with sufficient privileges, however, the ability to remove write protection and bypass fault handling could provide a high‑impact arbitrary memory write. The CVSS score is 5.5, but the analysis indicates a serious potential for privilege elevation or kernel corruption if successfully leveraged.

Generated by OpenCVE AI on August 22, 2026 at 10:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to the latest stable release that incorporates the mm/huge_memory patch.
  • If an immediate kernel upgrade is impossible, disable device‑private huge page mappings by setting `sysctl vm.nr_hugepages=0` and ensuring no process maps such pages; additionally block the `userfaultfd` system call for untrusted processes, for example, with a seccomp filter or by removing the capability from those processes.
  • After applying these changes, audit the system with commands like `cat /proc/[pid]/maps` or `cat /proc/meminfo` to confirm that device‑private THPs are no longer in use, and monitor kernel logs for any suspicious memory protection changes.

Generated by OpenCVE AI on August 22, 2026 at 10:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 22 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-665

Wed, 19 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-281
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Sat, 15 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-665

Sat, 15 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: mm/huge_memory: preserve pmd_swp_uffd_wp on device-private PMD downgrade change_non_present_huge_pmd() rewrites a writable device-private PMD swap entry into a readable one without carrying pmd_swp_uffd_wp() across. The PTE-level change_softleaf_pte() does this correctly; mirror that here, matching what copy_huge_pmd() does for the fork path. Without the carry, a plain mprotect() over a UFFD_WP-marked device-private THP strips the bit and the trap is bypassed on swap-in.
Title mm/huge_memory: preserve pmd_swp_uffd_wp on device-private PMD downgrade
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-17T05:09:43.031Z

Reserved: 2026-08-09T03:40:39.910Z

Link: CVE-2026-72180

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:21:36.293

Modified: 2026-08-17T06:18:18.527

Link: CVE-2026-72180

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-15T00:00:00Z

Links: CVE-2026-72180 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T10:45:03Z

Weaknesses
  • CWE-281

    Improper Preservation of Permissions