Impact
The Linux kernel bug caused the dirty state of pages that are part of a MAP_SHARED tmpfs mapping to be lost when the range is unmapped. The dirty flag is normally propagated so that reclaim can write the page to swap. Because the pmd dirty bit was not copied to the folio in certain cases, reclaim treated the page as clean, skipped swapping it out, and freed the data, resulting in the next access returning zeroed memory. This silent data loss can affect any process that relies on a shared tmpfs segment across an unmap, such as a cache handed between process generations via /dev/shm. The vulnerability does not allow arbitrary code execution but compromises data integrity.
Affected Systems
All Linux kernel versions released before the patch that fixed mm/huge_memory, particularly those that enable shmem Transparent Huge Pages and use swap space. Any system that creates MAP_SHARED tmpfs mappings with THP turned on is susceptible.
Risk and Exploitability
The CVSS score is not provided, but the bug leads to serious silent data loss. The EPSS score is below 1 %, indicating a very low probability of exploitation in the wild. The vulnerability is not listed in CISA KEV, suggesting it has not been observed in active attacks yet. The likely attack vector is local: an attacker who can manipulate shared tmpfs memory and trigger unmapping and reclaim on a host with THP and swap enabled could cause data loss. Overall, the risk is moderate to high in environments where the conditions above are present, but the exploitation probability remains low.
OpenCVE Enrichment