Description
In the Linux kernel, the following vulnerability has been resolved:

hugetlbfs: release subpool on fill_super failure

hugetlbfs_fill_super() allocates a hugepage subpool when size or min_size
mount options are specified. hugepage_new_subpool() may also reserve huge
pages for min_size.

If root dentry creation fails after the subpool is created, the failure
path frees the subpool with kfree(). This bypasses hugepage_put_subpool()
and can leave min_size reservations charged.

Use hugepage_put_subpool() on the failure path, matching the normal
put_super path.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

In the Linux kernel, a flaw occurs when hugetlbfs is mounted with size or min_size options. The mount routine allocates a hugepage subpool, but if the creation of the root dentry fails, the failure path frees the subpool with kfree(), bypassing the standard hugepage_put_subpool() cleanup. The result is that the allocated subpool's min_size reservations remain charged, potentially exhausting the system's hugepage pool. This is an uncontrolled resource consumption issue described by CWE‑400. Based on the description, it is inferred that the vulnerability is triggered only when a filesystem is mounted, requiring sufficient privileges to perform the mount operation. The attack vector is thus local with privileged access.

Affected Systems

The vulnerability affects any Linux kernel that implements hugetlbfs with the described free path. No specific kernel release numbers are listed, so all current and historical kernels before the patch may be impacted. Users who mount hugetlbfs with size or min_size options and encounter a mount failure are at risk. Workloads that rely on hugetlbfs might become blocked when the hugepage pool is depleted. The absence of explicit version coverage means the impact is inferred to apply to all kernel versions containing the affected code path. The CVE description does not list affected product variants; thus the inference covers all Linux kernels exposing hugetlbfs.

Risk and Exploitability

The risk can be rated high because a local attacker with privileges to mount filesystems could trigger the failure path and deplete hugepages, leading to denial of service for the system. The EPSS score is below 1%, and the vulnerability is not listed in the CISA KEV catalog. The exploit requires privileged access and therefore is most relevant to administrators controlling privileged accounts. The patch introduces a proper call to hugepage_put_subpool() on failure, eliminating the leak. Based on the EPSS score and lack of known exploitation records, the likelihood of exploitation remains low, but the impact remains severe if successful. The analysis infers that remote exploitation is unlikely due to the need for privileged mount access. The CVE data does not provide exploit code, so this conclusion is based on inference.

Generated by OpenCVE AI on September 19, 2026 at 14:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the kernel to a version that includes the patch that adds hugepage_put_subpool() to the failure path of hugetlbfs_fill_super
  • If an immediate kernel upgrade is not possible, refrain from mounting hugetlbfs with size or min_size options until the issue is fixed
  • If hugetlbfs is not needed for critical workloads, consider disabling it or limiting its use to reduce the attack surface

Generated by OpenCVE AI on September 19, 2026 at 14:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: hugetlbfs: release subpool on fill_super failure hugetlbfs_fill_super() allocates a hugepage subpool when size or min_size mount options are specified. hugepage_new_subpool() may also reserve huge pages for min_size. If root dentry creation fails after the subpool is created, the failure path frees the subpool with kfree(). This bypasses hugepage_put_subpool() and can leave min_size reservations charged. Use hugepage_put_subpool() on the failure path, matching the normal put_super path.
Title hugetlbfs: release subpool on fill_super failure
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:08:13.356Z

Reserved: 2026-09-11T19:38:34.797Z

Link: CVE-2026-90283

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:25.063

Modified: 2026-09-17T17:17:25.063

Link: CVE-2026-90283

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T14:45:14Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption