CVE-2026-53109
Publication date:
24/06/2026
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
powerpc/pgtable-frag: Fix bad page state in pte_frag_destroy<br />
<br />
powerpc uses pt_frag_refcount as a reference counter for tracking it&#39;s<br />
pte and pmd page table fragments. For PTE table, in case of Hash with<br />
64K pagesize, we have 16 fragments of 4K size in one 64K page.<br />
<br />
Patch series [1] "mm: free retracted page table by RCU"<br />
added pte_free_defer() to defer the freeing of PTE tables when<br />
retract_page_tables() is called for madvise MADV_COLLAPSE on shmem<br />
range.<br />
[1]: https://lore.kernel.org/all/7cd843a9-aa80-14f-5eb2-33427363c20@google.com/<br />
<br />
pte_free_defer() sets the active flag on the corresponding fragment&#39;s<br />
folio & calls pte_fragment_free(), which reduces the pt_frag_refcount.<br />
When pt_frag_refcount reaches 0 (no active fragment using the folio), it<br />
checks if the folio active flag is set, if set, it calls call_rcu to<br />
free the folio, it the active flag is unset then it calls pte_free_now().<br />
<br />
Now, this can lead to following problem in a corner case...<br />
<br />
[ 265.351553][ T183] BUG: Bad page state in process a.out pfn:20d62<br />
[ 265.353555][ T183] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x20d62<br />
[ 265.355457][ T183] flags: 0x3ffff800000100(active|node=0|zone=0|lastcpupid=0x7ffff)<br />
[ 265.358719][ T183] raw: 003ffff800000100 0000000000000000 5deadbeef0000122 0000000000000000<br />
[ 265.360177][ T183] raw: 0000000000000000 c0000000119caf58 00000000ffffffff 0000000000000000<br />
[ 265.361438][ T183] page dumped because: PAGE_FLAGS_CHECK_AT_FREE flag(s) set<br />
[ 265.362572][ T183] Modules linked in:<br />
[ 265.364622][ T183] CPU: 0 UID: 0 PID: 183 Comm: a.out Not tainted 6.18.0-rc3-00141-g1ddeaaace7ff-dirty #53 VOLUNTARY<br />
[ 265.364785][ T183] Hardware name: IBM pSeries (emulated by qemu) POWER10 (architected) 0x801200 0xf000006 of:SLOF,git-ee03ae pSeries<br />
[ 265.364908][ T183] Call Trace:<br />
[ 265.364955][ T183] [c000000011e6f7c0] [c000000001cfaa18] dump_stack_lvl+0x130/0x148 (unreliable)<br />
[ 265.365202][ T183] [c000000011e6f7f0] [c000000000794758] bad_page+0xb4/0x1c8<br />
[ 265.365384][ T183] [c000000011e6f890] [c00000000079c020] __free_frozen_pages+0x838/0xd08<br />
[ 265.365554][ T183] [c000000011e6f980] [c0000000000a70ac] pte_frag_destroy+0x298/0x310<br />
[ 265.365729][ T183] [c000000011e6fa30] [c0000000000aa764] arch_exit_mmap+0x34/0x218<br />
[ 265.365912][ T183] [c000000011e6fa80] [c000000000751698] exit_mmap+0xb8/0x820<br />
[ 265.366080][ T183] [c000000011e6fc30] [c0000000001b1258] __mmput+0x98/0x300<br />
[ 265.366244][ T183] [c000000011e6fc80] [c0000000001c81f8] do_exit+0x470/0x1508<br />
[ 265.366421][ T183] [c000000011e6fd70] [c0000000001c95e4] do_group_exit+0x88/0x148<br />
[ 265.366602][ T183] [c000000011e6fdc0] [c0000000001c96ec] pid_child_should_wake+0x0/0x178<br />
[ 265.366780][ T183] [c000000011e6fdf0] [c00000000003a270] system_call_exception+0x1b0/0x4e0<br />
[ 265.366958][ T183] [c000000011e6fe50] [c00000000000d05c] system_call_vectored_common+0x15c/0x2ec<br />
<br />
The bad page state error occurs when such a folio gets freed (with<br />
active flag set), from do_exit() path in parallel.<br />
<br />
... this can happen when the pte fragment was allocated from this folio,<br />
but when all the fragments get freed, the pte_frag_refcount still had some<br />
unused fragments. Now, if this process exits, with such folio as it&#39;s cached<br />
pte_frag in mm->context, then during pte_frag_destroy(), we simply call<br />
pagetable_dtor() and pagetable_free(), meaning it doesn&#39;t clear the<br />
active flag. This, can lead to the above bug. Since we are anyway in<br />
do_exit() path, then if the refcount is 0, then I guess it should be<br />
ok to simply clear the folio active flag before calling pagetable_dtor()<br />
& pagetable_free().
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026