Description
In the Linux kernel, the following vulnerability has been resolved:

ARM: 9485/1: mm: acquire mmap write lock around show_pte() for user faults

When CONFIG_DEBUG_USER=y, and cmdline "user_debug=31" is set,
a user fault may trigger show_pte() without any lock.
If another thread in the same process concurrently calls munmap(),
the page table pages may be freed while show_pte() is still traversing
them, causing a use-after-free in show_pte().

If CONFIG_ARM_LPAE=y, this may cause a kernel panic if the pages table
of PMD are freed when show_pte() is running.

Acquire mmap_write_lock() around show_pte() for user faults to fix the
contention.

For user faults, additionally restrict that show_pte() is called only
when the addr is a user-space address (addr < TASK_SIZE). This is because
the lock of tsk->mm only protects the virtual memory of user address space,
furthermore, dumping the page tables of a kernel-space address for user
faults is unnecessary and may have security implications.

Keep everything unchanged for kernel faults, because the kernel is
already in the "oops" state, acquiring a lock may risk a deadlock.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Use‑After‑Free leading to kernel panic (denial of service).
Action: Immediate Patch
AI Analysis

Impact

A concurrent user fault can call show_pte() without acquiring the mmap write lock when CONFIG_DEBUG_USER is enabled and user_debug=31 is set. If another thread in the same process calls munmap() at the same time, the page table structures may be freed while show_pte() is still reading them, yielding a use‑after‑free. On ARM systems compiled with CONFIG_ARM_LPAE, this race can trigger a kernel panic as the PMD page table is released during the fault handling. The flaw does not provide direct code execution, but it can destabilize the operating system and may allow a local attacker to repeatedly crash the machine.

Affected Systems

The issue exists in all Linux kernel releases that contain the affected mm/show_pte code path prior to the commit that adds mmap_write_lock. It is relevant to every vendor and distribution that uses the mainstream Linux kernel with CONFIG_DEBUG_USER enabled. The specific affected kernel versions are not enumerated in the advisory, so any kernel built from source that has not yet applied the patch is potentially vulnerable.

Risk and Exploitability

The vulnerability has an EPSS score of less than 1 % and is not listed as a CISA Known Exploited Vulnerability, indicating a relatively low public exploitation probability. Nonetheless, the impact of a kernel panic is high, as it results in a denial of service for the local user or any process running on the machine. Because the flaw requires a race condition between user‑fault handling and munmap() within the same process, a local attacker can trigger the failure by orchestrating such a timing window, for example by launching multiple threads that fault and unmap concurrently. Given the lack of a publicly known exploit and the low EPSS, the overall threat is moderate to high, but it is still urgent to apply the kernel patch to eliminate the race condition.

Generated by OpenCVE AI on September 19, 2026 at 04:03 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel patch that adds mmap_write_lock around show_pte for user faults, or upgrade to the latest Linux kernel release that contains the fix.
  • Disable CONFIG_DEBUG_USER or remove the user_debug=31 command‑line option in production systems to avoid the fault path that requires the missing lock.
  • If an immediate kernel update is not possible, monitor the system for kernel panics triggered by page‑fault handling and limit the use of applications that cause frequent concurrent faults and munmap calls.

Generated by OpenCVE AI on September 19, 2026 at 04:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ARM: 9485/1: mm: acquire mmap write lock around show_pte() for user faults When CONFIG_DEBUG_USER=y, and cmdline "user_debug=31" is set, a user fault may trigger show_pte() without any lock. If another thread in the same process concurrently calls munmap(), the page table pages may be freed while show_pte() is still traversing them, causing a use-after-free in show_pte(). If CONFIG_ARM_LPAE=y, this may cause a kernel panic if the pages table of PMD are freed when show_pte() is running. Acquire mmap_write_lock() around show_pte() for user faults to fix the contention. For user faults, additionally restrict that show_pte() is called only when the addr is a user-space address (addr < TASK_SIZE). This is because the lock of tsk->mm only protects the virtual memory of user address space, furthermore, dumping the page tables of a kernel-space address for user faults is unnecessary and may have security implications. Keep everything unchanged for kernel faults, because the kernel is already in the "oops" state, acquiring a lock may risk a deadlock.
Title ARM: 9485/1: mm: acquire mmap write lock around show_pte() for user faults
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:08:26.455Z

Reserved: 2026-09-11T19:38:34.799Z

Link: CVE-2026-90303

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:27.887

Modified: 2026-09-17T17:17:27.887

Link: CVE-2026-90303

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T04:15:13Z

Weaknesses

No weakness.