CVE-2026-80729
N/A
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
mm/huge_memory: initialise workingset state before folio split
xas_try_split() adds __GFP_ACCOUNT for page-cache xa_nodes, but __folio_split() leaves the xa_state's xa_lru unset. That lets a live, memcg-charged xa_node exist without being linked into the mapping's shadow_nodes list_lru; when reclaim later walks the list_lru it trips VM_WARN_ON(!css_is_dying()).
Use mapping_set_update() to install both the workingset update callback and the shadow_nodes list_lru on the xa_state.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 58729c04cf1092b87aeef0bf0998c9e2e4771133 < d858f7c9fc514f1d9d3be7d00b2dd4e2f2383b55 | affected |
| Linux | Linux | 58729c04cf1092b87aeef0bf0998c9e2e4771133 < aca1f2d5de17e138bc6c4859126b77e516b82541 | affected |
| Linux | Linux | 6.15 | affected |
| Linux | Linux | 0 < 6.15 | unaffected |
| Linux | Linux | 7.1.9 <= 7.1.* | unaffected |
| Linux | Linux | 7.2 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/d858f7c9fc514f1d9d3be7d00b2dd4e2f2383b55
- https://git.kernel.org/stable/c/aca1f2d5de17e138bc6c4859126b77e516b82541
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.