Description
In the Linux kernel, the following vulnerability has been resolved:

hugetlb: only adjust reservation during unmapping if mapcount is 0

Since df7a6d1f6405, __unmap_hugepage_range can adjust reservations. In
the case of folio mapped in both a parent and a child, if the parent
unmaps the range first, the reservation adjustment will result in an
underflow of the reserved count. Once the child unmaps the range, the
count is restored. Change __unmap_hugepage_range() to check the mapcount
before adjusting the reservation.
Published: 2026-09-11
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Memory reservation underflow
Action: Apply patch
AI Analysis

Impact

The Linux kernel’s huge page unmapping routine incorrectly decrements a reservation counter without first verifying that the mapping is the last reference. When a page is mapped in a parent and child and the parent unmaps first, the counter underflows. This bug results in corrupted reservation bookkeeping, affecting the kernel’s memory accounting. The flaw is an integer underflow (CWE‑191).

Affected Systems

All Linux kernel releases prior to the patch commit are affected. The vulnerability exists in the generic Linux kernel and applies regardless of distribution or build variant.

Risk and Exploitability

The CVSS score of 7.1 indicates a medium‑high severity. Exploitation requires a process that can map and unmap huge pages, a capability normally restricted to privileged users or to processes running with CAP_SYS_ADMIN. The EPSS score of less than 1% implies a low likelihood of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. the underflow.

Generated by OpenCVE AI on September 15, 2026 at 21:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that includes the commit fixing the reservation adjustment guard.
  • If using a custom kernel, backport the upstream patch to the current kernel version.
  • Reboot the system after installing the updated kernel to ensure the issue is resolved.

Generated by OpenCVE AI on September 15, 2026 at 21:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-191
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: hugetlb: only adjust reservation during unmapping if mapcount is 0 Since df7a6d1f6405, __unmap_hugepage_range can adjust reservations. In the case of folio mapped in both a parent and a child, if the parent unmaps the range first, the reservation adjustment will result in an underflow of the reserved count. Once the child unmaps the range, the count is restored. Change __unmap_hugepage_range() to check the mapcount before adjusting the reservation.
Title hugetlb: only adjust reservation during unmapping if mapcount is 0
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:01:16.035Z

Reserved: 2026-09-11T19:38:34.730Z

Link: CVE-2026-89593

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:43.920

Modified: 2026-09-14T13:19:13.207

Link: CVE-2026-89593

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:44:56Z

Links: CVE-2026-89593 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T21:45:17Z

Weaknesses
  • CWE-191

    Integer Underflow (Wrap or Wraparound)