{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-74518","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-15T05:44:03.910Z","datePublished":"2026-08-15T12:27:37.480Z","dateUpdated":"2026-08-19T16:38:19.402Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-19T16:38:19.402Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/hugetlb: fix list corruption in allocate_file_region_entries()\n\nallocate_file_region_entries() tops up resv->region_cache with freshly\nallocated file_region descriptors.  The allocation uses GFP_KERNEL, so\nresv->lock is dropped around it: the new entries are gathered on a\nstack-local list head, allocated_regions, and spliced into\nresv->region_cache once the lock is re-acquired.\n\nThe splice used list_splice(), which moves the entries but does not\nre-initialize the source head, so allocated_regions is left pointing at an\nentry that now lives on resv->region_cache.  The top-up runs in a while\nloop that re-checks the cache deficit after re-acquiring the lock.  For a\nshared mapping the resv_map is shared by every mapper of the hugetlbfs\ninode, so a concurrent region_chg()/region_add()/region_del() on the same\nresv_map can consume cache entries during the unlocked window and force a\nsecond iteration.  That iteration calls list_add() on the stale head and\ncorrupts the list; with CONFIG_DEBUG_LIST the __list_add_valid() check\ntrips:\n\n  list_add corruption. next->prev should be prev (ffffc900011ff7f8),\n  but was ffff88814c281460. (next=ffff88814c545640).\n  kernel BUG at lib/list_debug.c:31!\n   allocate_file_region_entries+0x191/0x420\n   region_chg+0x267/0x300\n   hugetlb_reserve_pages+0x387/0xc80\n   hugetlbfs_file_mmap+0x2ce/0x3f0\n   mmap_region+0x1348/0x1a80\n   do_mmap+0x85e/0xb90\n   vm_mmap_pgoff+0x18c/0x330\n   ksys_mmap_pgoff+0x2a1/0x3e0\n   do_syscall_64+0xd7/0x420\n\nWithout CONFIG_DEBUG_LIST the bad list_add() silently links a kernel-stack\naddress into resv->region_cache, leading to later use-after-free.\n\nThis was observed as a real host panic on a dense KVM host where a QEMU\nguest-RAM hugetlbfs file was mapped MAP_SHARED by both QEMU and a separate\nSPDK/DPDK vhost-user target, generating concurrent region_* traffic on one\nshared resv_map.\n\nUse list_splice_init() so the source head is re-initialized empty after\neach splice, making the retry loop safe."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The bug is reached only through local hugetlb reservation paths (mmap/memfd_create/fault syscalls into region_chg/region_add/region_del); no network protocol or remote packet handler invokes allocate_file_region_entries().\nAC:L - Exploitation needs a race while resv->lock is dropped during GFP_KERNEL allocation, but an attacker can spawn concurrent MAP_SHARED mappers/faulters on one hugetlb inode and controls both sides of that race.\nPR:L - Unprivileged local users can trigger this via memfd_create(MFD_HUGETLB) plus MAP_SHARED mmap/fault activity, or by mapping accessible shared hugetlbfs files, without init-namespace root or special capabilities.\nUI:N - No victim interaction is required; the attacker drives the needed concurrent syscalls and shared hugetlb mappings themselves to hit the corrupted list splice retry path.\nS:U - Impact is kernel hugetlb resv_map list/memory corruption on the host; it does not by itself cross a VM, IOMMU, or separate security-authority boundary even though KVM/DPDK hosts are a prime deployment.\nC:H - Without CONFIG_DEBUG_LIST, stale list_splice leaves a kernel-stack pointer in resv->region_cache, producing later use-after-free that can be turned into arbitrary kernel memory read/disclosure primitives.\nI:H - Corrupted region_cache pointers let subsequent region_add/region_del/cache operations write through attacker-influenced list links, enabling heap metadata corruption and potential arbitrary kernel write or code execution.\nA:H - Real host panics were reported on dense KVM hugetlb workloads; DEBUG_LIST kernels BUG on list_add corruption, and default builds can crash from UAF while walking the poisoned region_cache."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["mm/hugetlb.c"],"versions":[{"version":"d3ec7b6e09e512ba902b86bcca2c512fb06d492f","lessThan":"01b8569233e47693d6ff7efa96d9854c55f936fc","status":"affected","versionType":"git"},{"version":"d3ec7b6e09e512ba902b86bcca2c512fb06d492f","lessThan":"9c5fdffc5e1ce84403c58289ee72697051803bf7","status":"affected","versionType":"git"},{"version":"d3ec7b6e09e512ba902b86bcca2c512fb06d492f","lessThan":"f3e54f6a5e1681f83d13e8716bc92ef5ecf121d3","status":"affected","versionType":"git"},{"version":"d3ec7b6e09e512ba902b86bcca2c512fb06d492f","lessThan":"62e1c2741a4d923d9854efd5927a6212aad7a187","status":"affected","versionType":"git"},{"version":"d3ec7b6e09e512ba902b86bcca2c512fb06d492f","lessThan":"587a0accc2b4fccc5cf7baf0fe34e50efde51f9c","status":"affected","versionType":"git"},{"version":"d3ec7b6e09e512ba902b86bcca2c512fb06d492f","lessThan":"126a70bf1a08ddc9d79c471ebdaa2b08cfbab8df","status":"affected","versionType":"git"},{"version":"d3ec7b6e09e512ba902b86bcca2c512fb06d492f","lessThan":"ac1bb7fd45088d0db57a22ce7729f258ebd63cf5","status":"affected","versionType":"git"},{"version":"d3ec7b6e09e512ba902b86bcca2c512fb06d492f","lessThan":"dd9623f58ec702a07b2d67179d6fcea79c52231a","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["mm/hugetlb.c"],"versions":[{"version":"5.10","status":"affected"},{"version":"0","lessThan":"5.10","status":"unaffected","versionType":"semver"},{"version":"5.10.265","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.151","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.103","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.44","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.8","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.10","versionEndExcluding":"5.10.265"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.10","versionEndExcluding":"5.15.216"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.10","versionEndExcluding":"6.1.183"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.10","versionEndExcluding":"6.6.151"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.10","versionEndExcluding":"6.12.103"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.10","versionEndExcluding":"6.18.44"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.10","versionEndExcluding":"7.1.8"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.10","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/01b8569233e47693d6ff7efa96d9854c55f936fc"},{"url":"https://git.kernel.org/stable/c/9c5fdffc5e1ce84403c58289ee72697051803bf7"},{"url":"https://git.kernel.org/stable/c/f3e54f6a5e1681f83d13e8716bc92ef5ecf121d3"},{"url":"https://git.kernel.org/stable/c/62e1c2741a4d923d9854efd5927a6212aad7a187"},{"url":"https://git.kernel.org/stable/c/587a0accc2b4fccc5cf7baf0fe34e50efde51f9c"},{"url":"https://git.kernel.org/stable/c/126a70bf1a08ddc9d79c471ebdaa2b08cfbab8df"},{"url":"https://git.kernel.org/stable/c/ac1bb7fd45088d0db57a22ce7729f258ebd63cf5"},{"url":"https://git.kernel.org/stable/c/dd9623f58ec702a07b2d67179d6fcea79c52231a"}],"title":"mm/hugetlb: fix list corruption in allocate_file_region_entries()","x_generator":{"engine":"bippy-1.2.0"}}}}