Description
In the Linux kernel, the following vulnerability has been resolved:

mm/migrate_device: avoid out-of-bounds writes for compound folios

migrate_device_range() and migrate_device_pfns() clear the entries
following a compound folio so that the PFN arrays retain their
page-granular representation.

If a compound folio extends beyond the end of the caller-provided range,
the loops clear all following folio entries without limiting them to the
number of slots remaining in the npages-sized array, causing an
out-of-bounds write.

Do not proceed with a compound folio if its page-granular representation
does not fit entirely in the remaining PFN array. If this happens, drop
any reference and lock acquired for the folio, clear the remaining
entries, and stop collecting.

Observed with a KASAN x86 QEMU kernel using the HMM migrate_anon_huge_zero
selftest. Closing /dev/hmm_dmirror0 after migrating an anonymous huge
page to device memory exercises:

dmirror_fops_release()
-> dmirror_device_evict_chunk()
-> migrate_device_range()
Published: 2026-09-16
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Out-of-bounds memory write
Action: Immediate Patch
AI Analysis

Impact

The flaw occurs in the Linux kernel’s mm/migrate_device component, where functions migrate_device_range() and migrate_device_pfns() clear entries for compound folios without enforcing bounds on the PFN array. If a compound folio extends beyond the caller‑supplied range, the loops write outside the allocated array, causing an out-of-bounds memory corruption. This corruption affects kernel memory integrity, which could compromise system stability and security. The kernel documentation does not explicitly state that the resulting corruption could enable privilege escalation; however, as kernel memory corruption is a typical precondition for privilege escalation, this possibility is inferred from the nature of the bug.

Affected Systems

Linux kernel versions containing the unpatched migrate_device code are at risk. The CVE lists Linux:Linux in the product table, indicating all Linux kernel releases are potentially affected until the patch is applied. The vulnerability was observed in a KASAN‑instrumented x86 QEMU kernel during a heavy device memory migration self‑test that exercised /dev/hmm_dmirror0.

Risk and Exploitability

The CVSS score of 7.8 denotes high severity, and the EPSS score of less than 1% indicates a low probability of widespread exploitation at this time. The vulnerability is not catalogued in the CISA KEV list. The attack vector is inferred to involve triggering a device memory migration through interfaces such as /dev/hmm_dmirror0; the exact method an attacker would need to use is not detailed in the description, so this inference is explicitly noted. Monitoring for signs of malicious migration activity and restricting device access can mitigate the risk until a corrective kernel update is applied.

Generated by OpenCVE AI on September 18, 2026 at 07:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the system to a Linux kernel build that contains the patch for migrate_device bounds checking.
  • If a kernel upgrade cannot be performed immediately, disable or restrict access to the /dev/hmm_dmirror0 interface that exercises migration by removing or blocking the device node or limiting its permissions.
  • Deploy kernel debugging or memory‑sanitization tools such as KASAN and monitor system logs for anomalous memory corruption events that might indicate exploitation attempts.

Generated by OpenCVE AI on September 18, 2026 at 07:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: mm/migrate_device: avoid out-of-bounds writes for compound folios migrate_device_range() and migrate_device_pfns() clear the entries following a compound folio so that the PFN arrays retain their page-granular representation. If a compound folio extends beyond the end of the caller-provided range, the loops clear all following folio entries without limiting them to the number of slots remaining in the npages-sized array, causing an out-of-bounds write. Do not proceed with a compound folio if its page-granular representation does not fit entirely in the remaining PFN array. If this happens, drop any reference and lock acquired for the folio, clear the remaining entries, and stop collecting. Observed with a KASAN x86 QEMU kernel using the HMM migrate_anon_huge_zero selftest. Closing /dev/hmm_dmirror0 after migrating an anonymous huge page to device memory exercises: dmirror_fops_release() -> dmirror_device_evict_chunk() -> migrate_device_range()
Title mm/migrate_device: avoid out-of-bounds writes for compound folios
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:40:44.952Z

Reserved: 2026-09-11T19:38:34.778Z

Link: CVE-2026-89967

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:07.283

Modified: 2026-09-16T15:18:20.980

Link: CVE-2026-89967

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T07:30:05Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer