Description
In the Linux kernel, the following vulnerability has been resolved:

powerpc/mm: fix wrong addr_pfn tracking in compound vmemmap population

vmemmap_populate_compound_pages() uses addr_pfn to determine the PFN
offset within a compound page and to decide whether the current vmemmap
slot should be populated as a head page mapping or should reuse a tail
page mapping.

However, addr_pfn is advanced manually in parallel with addr. The loop
itself progresses in vmemmap address space, so each PAGE_SIZE step in addr
covers PAGE_SIZE / sizeof(struct page) struct page slots. Since addr_pfn
is compared against nr_pages in data-PFN units, it should advance by the
same number of PFNs. The existing manual increments do not match that and
therefore do not reliably track the PFN corresponding to the current addr.

As a result, pfn_offset can be computed from the wrong PFN and the code
can make the head/tail decision for the wrong compound-page position.

Fix this by deriving addr_pfn directly from the current vmemmap address
instead of carrying it as loop state.
Published: 2026-09-16
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The Linux kernel flaw involves incorrect tracking of the page frame number during compound page population, causing the system to determine head or tail page mappings with a wrong PFN offset. This mis‑alignment can result in the kernel mapping incorrect memory pages, potentially leading to a kernel panic or other forms of memory corruption that abruptly halt services. The weakness is a logical error in pointer/index handling that compromises the integrity of the kernel’s memory manager.

Affected Systems

All Linux kernel releases that did not yet include the addr_pfn tracking fix are affected. Vendor information is limited to the Linux kernel and no specific version ranges are listed in the advisory.

Risk and Exploitability

The CVSS score of 7.8 classifies the vulnerability as high, though the EPSS score of less than 1% indicates a very low likelihood of widespread exploitation at present. The flaw is not listed in CISA’s KEV catalog. Because the issue lies within kernel’s memory allocation routines, a local attacker or any process that triggers compound page use could potentially exploit the bug, though it may require code execution at kernel level or privilege escalation to fully control the scenario. The attack vector is inferred to be local or within trusted kernel modules, as the bug operates during normal kernel memory management.

Generated by OpenCVE AI on September 18, 2026 at 04:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the addr_pfn tracking fix.
  • If an immediate kernel upgrade is not possible, apply the patch changes from the commit references provided in the advisory to your kernel source and rebuild.
  • After patching, verify that the function vmemmap_populate_compound_pages now computes addr_pfn directly from the current vmemmap address.
  • Reboot the system to clear any corrupted memory mappings that may have persisted before the patch.

Generated by OpenCVE AI on September 18, 2026 at 04:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-129

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: powerpc/mm: fix wrong addr_pfn tracking in compound vmemmap population vmemmap_populate_compound_pages() uses addr_pfn to determine the PFN offset within a compound page and to decide whether the current vmemmap slot should be populated as a head page mapping or should reuse a tail page mapping. However, addr_pfn is advanced manually in parallel with addr. The loop itself progresses in vmemmap address space, so each PAGE_SIZE step in addr covers PAGE_SIZE / sizeof(struct page) struct page slots. Since addr_pfn is compared against nr_pages in data-PFN units, it should advance by the same number of PFNs. The existing manual increments do not match that and therefore do not reliably track the PFN corresponding to the current addr. As a result, pfn_offset can be computed from the wrong PFN and the code can make the head/tail decision for the wrong compound-page position. Fix this by deriving addr_pfn directly from the current vmemmap address instead of carrying it as loop state.
Title powerpc/mm: fix wrong addr_pfn tracking in compound vmemmap population
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:40:41.979Z

Reserved: 2026-09-11T19:38:34.778Z

Link: CVE-2026-89961

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:06.570

Modified: 2026-09-16T15:18:20.703

Link: CVE-2026-89961

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T04:15:02Z

Weaknesses
  • CWE-129

    Improper Validation of Array Index