CVE-2026-89755
Gravedad CVSS v3.1:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
11/09/2026
Última modificación:
21/09/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
mm/migrate_device: clear stale mapping after freeing swapcache<br />
<br />
__migrate_device_pages() reads the folio mapping before calling<br />
folio_free_swap(). When folio_free_swap() succeeds, the folio is removed<br />
from the swap cache, but the saved mapping still points to swap_space.<br />
<br />
Passing the stale mapping to folio_migrate_mapping() makes it use the<br />
mapped-folio path for a folio that is no longer in swapcache. It can then<br />
operate on swap_space.i_pages with invalid reference accounting,<br />
eventually triggering a folio reference count BUG.<br />
<br />
After a successful split, nr still contains the number of pages in the<br />
original large folio, although each resulting page is now a separate<br />
order-0 folio. Reset nr to 1 so each split folio is processed separately,<br />
including its own swapcache removal and mapping lookup.<br />
<br />
Refresh the saved mapping after folio_free_swap() so the current folio<br />
state is used during migration.
Impacto
Puntuación base 3.x
7.80
Gravedad 3.x
ALTA


