{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-64181","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-07-19T07:54:57.039Z","datePublished":"2026-07-19T15:41:04.455Z","dateUpdated":"2026-08-05T12:39:56.626Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T12:39:56.626Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm: fix __vm_normal_page() to handle missing support for pmd_special()/pud_special()\n\nOn x86 32-bit with THP enabled, zap_huge_pmd() is seen to generate a\n\"WARNING: mm/memory.c:735 at __vm_normal_page+0x6a/0x7d\", from the\nVM_WARN_ON_ONCE(is_zero_pfn(pfn) || is_huge_zero_pfn(pfn)); followed by\n\"BUG: Bad rss-counter state\"s, then later \"BUG: Bad page state\"s when\nreclaim gets to call shrink_huge_zero_folio_scan().\n\nIt's as if the _PAGE_SPECIAL bit never got set in the huge_zero pmd: and\nindeed, whereas pte_special() and pte_mkspecial() are subject to a\ndedicated CONFIG_ARCH_HAS_PTE_SPECIAL, pmd_special() and pmd_mkspecial()\nare subject to CONFIG_ARCH_SUPPORTS_PMD_PFNMAP, which is never enabled on\nany 32-bit architecture.\n\nWhile the problem was exposed through commit d80a9cb1a64a\n(\"mm/huge_memory: add and use normal_or_softleaf_folio_pmd()\"), it was an\noversight in commit af38538801c6 (\"mm/memory: factor out common code from\nvm_normal_page_*()\") and would result in other problems:\n* huge zero folio accounted in smaps, pagemap (PAGE_IS_FILE) and\n  numamaps as file-backed THP\n* folio_walk_start() returning the folio even without FW_ZEROPAGE set.\n  Callers seem to tolerate that, though.\n\n... and triggering the VM_WARN_ON_ONE(), although never reported so far.\n\nTo fix it, teach vm_normal_page_pmd()/vm_normal_page_pud() to consider\nwhether pmd_special/pud_special is actually implemented."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The bug is reached only through local memory-management syscalls (mmap, madvise, munmap, process teardown) that walk page tables and call zap_huge_pmd() → vm_normal_page_pmd() → __vm_normal_page(); there is no network, adjacent, or physical attack path.\nAC:L - On affected 32-bit THP configurations an unprivileged attacker can deterministically create a huge zero PMD (mmap + MADV_HUGEPAGE + read fault) and trigger the bug (munmap or MADV_DONTNEED) without races or conditions outside their control.\nPR:L - Exploitation requires only an unprivileged local user manipulating their own address space via standard syscalls; no root, capabilities, or authentication is needed.\nUI:N - No victim interaction is required; the attacker fully controls the memory mappings and the syscalls that trigger page-table zapping.\nS:U - Impact is confined to kernel memory-management corruption and accounting within the kernel security boundary; this is not a VM escape, IOMMU bypass, or cross-authority sandbox escape.\nC:H - Misclassifying the shared huge zero folio as a normal page corrupts global rmap/mapcount state on a system-wide singleton folio, triggers VM_WARN/BUG checks, and misreports mappings in /proc/pagemap and smaps—memory corruption with plausible information-disclosure leverage.\nI:H - Incorrect rmap removal and RSS accounting on the global huge_zero_folio corrupts kernel memory metadata system-wide; callers such as KSM (vm_normal_page_pmd) may treat the zero folio as a normal anonymous folio, enabling cross-mapping integrity corruption beyond the attacker's VMA.\nA:H - The bug triggers VM_WARN_ON_ONCE, \"BUG: Bad rss-counter state\" on mm teardown, and \"BUG: Bad page state\" during shrink_huge_zero_folio_scan() reclaim, any of which can crash or destabilize the kernel on affected systems."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["mm/memory.c"],"versions":[{"version":"af38538801c6a97565b44700ee6695d7d60ad779","lessThan":"62153767e8fc3889bc6508e9ffe927aaf64c4334","status":"affected","versionType":"git"},{"version":"af38538801c6a97565b44700ee6695d7d60ad779","lessThan":"9052ea2ee2233be5d4786b8909151ca2bfbedf99","status":"affected","versionType":"git"},{"version":"af38538801c6a97565b44700ee6695d7d60ad779","lessThan":"c0c6ccd9828c3a1950623b546fa57292a77b5c73","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["mm/memory.c"],"versions":[{"version":"6.18","status":"affected"},{"version":"0","lessThan":"6.18","status":"unaffected","versionType":"semver"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","status":"unaffected","versionType":"semver"},{"version":"7.1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.18","versionEndExcluding":"6.18.34"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.18","versionEndExcluding":"7.0.11"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.18","versionEndExcluding":"7.1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/62153767e8fc3889bc6508e9ffe927aaf64c4334"},{"url":"https://git.kernel.org/stable/c/9052ea2ee2233be5d4786b8909151ca2bfbedf99"},{"url":"https://git.kernel.org/stable/c/c0c6ccd9828c3a1950623b546fa57292a77b5c73"}],"title":"mm: fix __vm_normal_page() to handle missing support for pmd_special()/pud_special()","x_generator":{"engine":"bippy-1.2.0"}}}}