In the Linux kernel, the following vulnerability has been resolved:
vmw_balloon: indicate success when effectively deflating during migration
When migrating a balloon page, we first deflate the old page to then inflate the new page.
However, if inflating the new page succeeded, we effectively deflated the old page, reducing the balloon size.
In that case, the migration actually worked: similar to migrating+ immediately deflating the new page. The old page will be freed back to the buddy.
Right now, the core will leave the page be marked as isolated (as we returned an error). When later trying to putback that page, we will run into the WARN_ON_ONCE() in balloon_page_putback().
That handling was changed in commit 3544c4faccb8 ("mm/balloon_compaction: stop using __ClearPageMovable()"); before that change, we would have tolerated that way of handling it.
To fix it, let's just return 0 in that case, making the core effectively just clear the "isolated" flag + freeing it back to the buddy as if the migration succeeded. Note that the new page will also get freed when the core puts the last reference.
Note that this also makes it all be more consistent: we will no longer unisolate the page in the balloon driver while keeping it marked as being isolated in migration core.
This was found by code inspection.
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Ubuntu | — | Upgrade linux-image-oracle-6.17Upgrade linux-image-6.17.0-1011-oemUpgrade linux-image-virtualUpgrade linux-image-oracle-64k-6.17Upgrade linux-image-azure-6.17Upgrade linux-image-awsUpgrade linux-image-gcp-64k-6.17Upgrade linux-image-6.17.0-14-generic-64kUpgrade linux-image-6.17.0-14-genericUpgrade linux-image-6.17.0-1007-aws-64kUpgrade linux-image-realtimeUpgrade linux-image-genericUpgrade linux-image-6.17.0-1008-azureUpgrade linux-image-6.17.0-1007-gcp-64kUpgrade linux-image-6.17.0-1007-gcpUpgrade linux-image-6.17.0-1008-raspiUpgrade linux-image-6.17.0-1007-awsUpgrade linux-image-oracleUpgrade linux-image-generic-6.17Upgrade linux-image-generic-64kUpgrade linux-image-oracle-64kUpgrade linux-image-aws-6.17Upgrade linux-image-generic-64k-6.17Upgrade linux-image-azureUpgrade linux-image-aws-64k-6.17Upgrade linux-image-6.17.0-1006-realtimeUpgrade linux-image-gcp-64kUpgrade linux-image-aws-64kUpgrade linux-image-raspiUpgrade linux-image-oem-6.17Upgrade linux-image-gcpUpgrade linux-image-6.17.0-1007-oracle-64kUpgrade linux-image-6.17.0-1007-oracleUpgrade linux-image-gcp-6.17Upgrade linux-image-realtime-6.17Upgrade linux-image-raspi-6.17Upgrade linux-image-virtual-6.17 | Feb 13, 2026 | Feb 12, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub