Description
In the Linux kernel, the following vulnerability has been resolved:

mm/migrate_device: clear stale mapping after freeing swapcache

__migrate_device_pages() reads the folio mapping before calling
folio_free_swap(). When folio_free_swap() succeeds, the folio is removed
from the swap cache, but the saved mapping still points to swap_space.

Passing the stale mapping to folio_migrate_mapping() makes it use the
mapped-folio path for a folio that is no longer in swapcache. It can then
operate on swap_space.i_pages with invalid reference accounting,
eventually triggering a folio reference count BUG.

After a successful split, nr still contains the number of pages in the
original large folio, although each resulting page is now a separate
order-0 folio. Reset nr to 1 so each split folio is processed separately,
including its own swapcache removal and mapping lookup.

Refresh the saved mapping after folio_free_swap() so the current folio
state is used during migration.
Published: 2026-09-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel crash or system halt (inferred)
Action: Apply Patch
AI Analysis

Impact

The Linux kernel’s memory migration code incorrectly retains a stale swapcache mapping after a folio has been freed, leading to an invalid reference count assertion and a BUG. Based on the description, it is inferred that this flaw could trigger a kernel panic, potentially causing the system to halt abruptly and disrupting all operations on the affected host.

Affected Systems

All Linux kernel releases that compile the mm/migrate_device subsystem are impacted, as the vulnerability resides in kernel code that is present in standard indicates any Linux kernel release; no product‑specific version range is specified, so any kernel build susceptible to this code path is considered at risk until the patch is applied.

Risk and Exploitability

The CVSS score of 7.8 signals high severity. The EPSS of less than 1% indicates a very low likelihood of real‑world exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that an attacker would need local privilege or the ability to influence kernel memory layout to trigger the fault, while remote exploitation is unlikely because the flaw requires internal kernel operations.

Generated by OpenCVE AI on September 15, 2026 at 19:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the latest kernel update that includes the update to __migrate_device_pages and the refreshed mapping logic after folio_free_swap.
  • If a kernel update cannot be applied immediately, reduce the use of high‑throughput memory migration operations involving swapcache, such as limiting voluminous page migrations.
  • Enable logging and monitor dmesg or system journal entries for BUG or oops messages that indicate a bad reference count or kernel panic.

Generated by OpenCVE AI on September 15, 2026 at 19:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 21 Sep 2026 13:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: mm/migrate_device: clear stale mapping after freeing swapcache __migrate_device_pages() reads the folio mapping before calling folio_free_swap(). When folio_free_swap() succeeds, the folio is removed from the swap cache, but the saved mapping still points to swap_space. Passing the stale mapping to folio_migrate_mapping() makes it use the mapped-folio path for a folio that is no longer in swapcache. It can then operate on swap_space.i_pages with invalid reference accounting, eventually triggering a folio reference count BUG. After a successful split, nr still contains the number of pages in the original large folio, although each resulting page is now a separate order-0 folio. Reset nr to 1 so each split folio is processed separately, including its own swapcache removal and mapping lookup. Refresh the saved mapping after folio_free_swap() so the current folio state is used during migration.
Title mm/migrate_device: clear stale mapping after freeing swapcache
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-21T13:14:58.853Z

Reserved: 2026-09-11T19:38:34.763Z

Link: CVE-2026-89755

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:20:06.533

Modified: 2026-09-21T14:17:26.320

Link: CVE-2026-89755

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:46:58Z

Links: CVE-2026-89755 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T19:15:16Z

Weaknesses
  • CWE-825

    Expired Pointer Dereference