Description
In the Linux kernel, the following vulnerability has been resolved:

lib/test_hmm: fail dmirror_fault() when the mirrored mm is gone

dmirror_fault() is called from the dmirror_read() and dmirror_write()
retry loops after dmirror_do_read() or dmirror_do_write() finds a missing
device page table entry.

If the mirrored mm has already exited, mmget_not_zero() fails. The
current code returns 0 in that case, which tells the caller that faulting
succeeded even though no page was faulted and no device page table entry
was installed. The caller then retries the same address, hits -ENOENT
again, and can loop forever without making progress.

Return -EFAULT instead, so the ioctl fails when the mirrored mm is no
longer faultable.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service due to infinite retry loop in kernel mirror fault handling
Action: Patch Kernel
AI Analysis

Impact

The bug is triggered when dmirror_fault() is called after a missing device page table entry. If the mirrored mm has already exited, mmget_not_zero() fails, but the code returns 0, telling the caller that the fault succeeded. The caller retries the same address, hits -ENOENT again, and can loop forever. Returning -EFAULT instead would cause the ioctl to fail, preventing the endless loop. As a result, the system can hang, leading to a denial of service for processes that depend on the mirrored device.

Affected Systems

All Linux kernel releases that include the vulnerable dmirror_fault implementation, as indicated by the kernel CPE entry. The fault exists in any kernel image that has not incorporated the recent patch referenced by the commit list.

Risk and Exploitability

The EPSS score is reported as less than 1%, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a local or privileged user able to trigger kernel read/write operations on a device using the dmirror feature. No public exploit is known, but the infinite retry loop is a classic denial of service vector that can disrupt kernel operations.

Generated by OpenCVE AI on September 19, 2026 at 13:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a release that includes the dmirror_fault fix (see the supplied commit references).
  • If an immediate kernel upgrade is not possible, disable or remove devices that use the dmirror feature to avoid exercising the buggy code path.
  • Monitor kernel logs for dmirror_fault errors and reboot the system if a hang is detected.

Generated by OpenCVE AI on September 19, 2026 at 13:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-754

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: lib/test_hmm: fail dmirror_fault() when the mirrored mm is gone dmirror_fault() is called from the dmirror_read() and dmirror_write() retry loops after dmirror_do_read() or dmirror_do_write() finds a missing device page table entry. If the mirrored mm has already exited, mmget_not_zero() fails. The current code returns 0 in that case, which tells the caller that faulting succeeded even though no page was faulted and no device page table entry was installed. The caller then retries the same address, hits -ENOENT again, and can loop forever without making progress. Return -EFAULT instead, so the ioctl fails when the mirrored mm is no longer faultable.
Title lib/test_hmm: fail dmirror_fault() when the mirrored mm is gone
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:09:25.083Z

Reserved: 2026-09-11T19:38:34.810Z

Link: CVE-2026-90391

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:38.653

Modified: 2026-09-17T17:17:38.653

Link: CVE-2026-90391

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T17:45:17Z

Weaknesses
  • CWE-754

    Improper Check for Unusual or Exceptional Conditions