CVE-2026-98224

Summary

In the Linux kernel, the following vulnerability has been resolved:

mm/vma: correctly unaccount on mmap_prepare() failure

__mmap_setup() accounts memory for relevant mappings via:

security_vm_enough_memory_mm() -> __vm_enough_memory() -> vm_acct_memory()

If __mmap_setup() fails, this indicates that this accounting did not take place, and thus it's appropriate for __mmap_region() to jump to abort_munmap.

However if call_mmap_prepare() fails, it also jumps there and any accounted memory is not correctly unaccounted.

Fix this by handling each error separately.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxc84bf6dd2b836b49bb2662668ff1692350d28236 < fb5400bff669c8bad3d4ec09287d9b461e89e5f1affected
LinuxLinuxc84bf6dd2b836b49bb2662668ff1692350d28236 < 8fdc521d438fbf0d22c13d51d55d5dd82d7202b2affected
LinuxLinuxc84bf6dd2b836b49bb2662668ff1692350d28236 < 6cc27d82196385fe06853319f74312a7d8019726affected
LinuxLinux6.16affected
LinuxLinux0 < 6.16unaffected
LinuxLinux6.18.54 <= 6.18.*unaffected
LinuxLinux7.2.8 <= 7.2.*unaffected
LinuxLinux7.3-rc4 <= *unaffected

Weaknesses

References