Description
In the Linux kernel, the following vulnerability has been resolved:

mm: mglru: fix stale batch updates after memcg reparenting

The mglru page table walker batches per-generation size deltas in
walk->nr_pages while walking page tables without holding the lruvec lock.
The reset_batch_size() later folds those deltas into walk->lruvec under
the lruvec lock.

The page table walker can run concurrently with the memcg reparenting path
as follows:

CPU0 CPU1
==== ====

walk_mm
--> walk_page_range
--> update_batch_size
--> walk->nr_pages += delta

mem_cgroup_css_offline
--> memcg_reparent_objcgs
--> lock lruvec
lru_gen_reparent_memcg
--> reparent child folios to parent
unlock lruvec

lock lruvec
reset_batch_size
--> child lrugen->nr_pages += delta

This will trigger the following warning in lru_gen_exit_memcg():

VM_WARN_ON_ONCE(memchr_inv(lruvec->lrugen.nr_pages, 0,
sizeof(lruvec->lrugen.nr_pages)));

And the user-visible impact of underestimated nr_pages in MGLRU was
premature OOMs because MGLRU does not try to reclaim memory when nr_pages
reaches zero, but there are still more pages.

To fix it, make reset_batch_size() check CSS_DYING under RCU before
flushing the pending batch. A non-dying memcg keeps the original lruvec
stable against RCU-delayed offlining; a dying memcg redirects the deltas
to the first non-dying ancestor.
Published: 2026-08-28
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An inconsistency in the Linux kernel’s memory‑group LRU (mglru) page table walker caused an under‑count of resident pages when a memory cgroup is reparented while the walker is executing. The walker updates per‑generation deltas without holding the lruvec lock, and a later reset_batch_size() merges those deltas while holding the lock. If the reparenting path proceeds concurrently, the reset function may add the delta to a child’s lru_gen after the child has been marked dying, leading to a stale batch update. The result is that the accounting for active pages under a memcg underestimates the true number of pages, which triggers a premature OOM condition because the kernel believes the group has no pages to reclaim when it in fact still holds many.

Affected Systems

All current Linux kernel releases that contain the vulnerable mglru implementation are affected, as the CVE does not list a specific version range. The issue lies in the generic kernel memory‑management code and is not limited to a particular architecture or distribution. Any system running a kernel version that has not applied the fix will be susceptible to the under‑counting bug.

Risk and Exploitability

The CVSS score and EPSS metric are not provided, but the nature of the flaw suggests a local denial of service–type risk. Based on the description, it is inferred that an attacker who can trigger a memcg reparenting while a page table walk is in progress—for example, by manipulating memory‑cgroup configuration in a privileged process—could cause the system to mis‑account memory and experience an out‑of‑memory kill that terminates unrelated processes. No public exploit has been reported and the vulnerability is not listed in the CISA KEV catalog; however, the underlying problem is a kernel‑level resource‑counting error, so mitigations rely on applying the kernel update that introduces a check for a dying CSS before flushing the pending batch.

Generated by OpenCVE AI on August 28, 2026 at 12:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the commit fixing the mglru stale batch update bug.
  • If an immediate kernel update is not possible, restrict the use of memory‑cgroup reparenting operations—disable dynamic memcg reparenting or prevent transitions that might trigger the bug until the patch is applied.
  • After the patch is applied, monitor system logs for out‑of‑memory events and confirm that the VM_WARN_ON_ONCE warning related to lrugen->nr_pages no longer appears.

Generated by OpenCVE AI on August 28, 2026 at 12:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 13:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400

Fri, 28 Aug 2026 11:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400

Fri, 28 Aug 2026 07:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: mm: mglru: fix stale batch updates after memcg reparenting The mglru page table walker batches per-generation size deltas in walk->nr_pages while walking page tables without holding the lruvec lock. The reset_batch_size() later folds those deltas into walk->lruvec under the lruvec lock. The page table walker can run concurrently with the memcg reparenting path as follows: CPU0 CPU1 ==== ==== walk_mm --> walk_page_range --> update_batch_size --> walk->nr_pages += delta mem_cgroup_css_offline --> memcg_reparent_objcgs --> lock lruvec lru_gen_reparent_memcg --> reparent child folios to parent unlock lruvec lock lruvec reset_batch_size --> child lrugen->nr_pages += delta This will trigger the following warning in lru_gen_exit_memcg(): VM_WARN_ON_ONCE(memchr_inv(lruvec->lrugen.nr_pages, 0, sizeof(lruvec->lrugen.nr_pages))); And the user-visible impact of underestimated nr_pages in MGLRU was premature OOMs because MGLRU does not try to reclaim memory when nr_pages reaches zero, but there are still more pages. To fix it, make reset_batch_size() check CSS_DYING under RCU before flushing the pending batch. A non-dying memcg keeps the original lruvec stable against RCU-delayed offlining; a dying memcg redirects the deltas to the first non-dying ancestor.
Title mm: mglru: fix stale batch updates after memcg reparenting
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-28T06:53:16.087Z

Reserved: 2026-08-26T14:34:25.788Z

Link: CVE-2026-80719

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-28T08:16:57.720

Modified: 2026-08-28T08:16:57.720

Link: CVE-2026-80719

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T13:00:04Z

Weaknesses

No weakness.