In the Linux kernel, the following vulnerability has been resolved:
powerpc/64s: Fix unmap race with PMD migration entries
The following race is possible with migration swap entries or device-private THP entries. e.g. when move_pages is called on a PMD THP page, then there maybe an intermediate state, where PMD entry acts as a migration swap entry (pmd_present() is true). Then if an munmap happens at the same time, then this VM_BUG_ON() can happen in pmdp_huge_get_and_clear_full().
This patch fixes that.
Thread A: move_pages() syscall add_folio_for_migration() mmap_read_lock(mm) folio_isolate_lru(folio) mmap_read_unlock(mm)
do_move_pages_to_node() migrate_pages() try_to_migrate_one() spin_lock(ptl) set_pmd_migration_entry() pmdp_invalidate() # PMD: _PAGE_INVALID | _PAGE_PTE | pfn set_pmd_at() # PMD: migration swap entry (pmd_present=0) spin_unlock(ptl) [page copy phase] # <--- RACE WINDOW -->
Thread B: munmap() mmap_write_downgrade(mm) unmap_vmas() -> zap_pmd_range() zap_huge_pmd() __pmd_trans_huge_lock() pmd_is_huge(): # !pmd_present && !pmd_none -> TRUE (swap entry) pmd_lock() -> # spin_lock(ptl), waits for Thread A to release ptl pmdp_huge_get_and_clear_full() VM_BUG_ON(!pmd_present(*pmdp)) # HITS!
[ 287.738700][ T1867] ------------[ cut here ]------------ [ 287.743843][ T1867] kernel BUG at arch/powerpc/mm/book3s64/pgtable.c:187! cpu 0x0: Vector: 700 (Program Check) at [c00000044037f4f0] pc: c000000000094ca4: pmdp_huge_get_and_clear_full+0x6c/0x23c lr: c000000000645dec: zap_huge_pmd+0xb0/0x868 sp: c00000044037f790 msr: 800000000282b033 current = 0xc0000004032c1a00 paca = 0xc000000004fe0000 irqmask: 0x03 irq_happened: 0x09 pid = 1867, comm = a.out kernel BUG at :187! Linux version 6.19.0-12136-g14360d4f917c-dirty (powerpc64le-linux-gnu-gcc (Debian 12.2.0-14) 12.2.0, GNU ld (GNU Binutils for Debian) 2.40) #27 SMP PREEMPT Sun Feb 22 10:38:56 IST 2026 enter ? for help [link register ] c000000000645dec zap_huge_pmd+0xb0/0x868 [c00000044037f790] c00000044037f7d0 (unreliable) [c00000044037f7d0] c000000000645dcc zap_huge_pmd+0x90/0x868 [c00000044037f840] c0000000005724cc unmap_page_range+0x176c/0x1f40 [c00000044037fa00] c000000000572ea0 unmap_vmas+0xb0/0x1d8 [c00000044037fa90] c0000000005af254 unmap_region+0xb4/0x128 [c00000044037fb50] c0000000005af400 vms_complete_munmap_vmas+0x138/0x310 [c00000044037fbe0] c0000000005b0f1c do_vmi_align_munmap+0x1ec/0x238 [c00000044037fd30] c0000000005b3688 __vm_munmap+0x170/0x1f8 [c00000044037fdf0] c000000000587f74 sys_munmap+0x2c/0x40 [c00000044037fe10] c000000000032668 system_call_exception+0x128/0x350 [c00000044037fe50] c00000000000d05c system_call_vectored_common+0x15c/0x2ec ---- Exception: 3000 (System Call Vectored) at 0000000010064a2c SP (7fff9b1ee9c0) is in userspace 0:mon> zh
commit a30b48bf1b24 ("mm/migrate_device: implement THP migration of zone device pages"), enabled migration for device-private PMD entries. Hence this is one other path where this warning could get trigger from.
------------[ cut here ]------------ WARNING: arch/powerpc/mm/book3s64/hash_pgtable.c:199 at hash__pmd_hugepage_update+0x48/0x284, CPU#3: hmm-tests/1905 Modules linked in: test_hmm CPU: 3 UID: 0 PID: 1905 Comm: hmm-tests Tainted: G B W L N 7.0.0-rc1-01438-g7e2f0ee7581c #21 PREEMPT Tainted: [B]=BAD_PAGE, [W]=WARN, [L]=SOFTLOCKUP, [N]=TEST Hardware name: IBM pSeries (emulated by qemu) POWER10 (architected) 0x801200 0xf000006 of:SLOF,git-ee03ae pSeries NIP [c000000000096b70] hash__pmd_hugepage_update+0x48/0x284 LR [c000000000096e7c] hash__pmdp_huge_get_and_clear+0xd0/0xd4 Call Trace: [c000000604707670] [c000000004e102b8] 0xc000000004e102b8 (unreliable) [c000000604707700] [c00000000064ec3c] set_pmd_migration_entry+0x414/0x498 [c000000604707760] [c00000000063e5a4] migrate_vma_col ---truncated---
CVSS Details
- CVSS 3.1 Base Score: 4.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Jun 24, 2026 |
| Ubuntu | — | Upgrade linux-image-generic-64k-hwe-26.04Upgrade linux-image-gkeUpgrade linux-image-nvidia-hwe-26.04Upgrade linux-image-7.0.0-2016-nvidia-bos-64kUpgrade linux-image-7.0.0-28-genericUpgrade linux-image-aws-64kUpgrade linux-image-generic-hwe-26.04Upgrade linux-image-nvidia-bos-64kUpgrade linux-image-nvidia-bosUpgrade linux-image-gke-7.0Upgrade linux-image-7.0.0-1008-gcpUpgrade linux-image-7.0.0-1010-ibmUpgrade linux-image-nvidiaUpgrade linux-image-oracleUpgrade linux-image-7.0.0-1016-nvidiaUpgrade linux-image-aws-64k-7.0Upgrade linux-image-azureUpgrade linux-image-7.0.0-1010-azureUpgrade linux-image-gcp-64k-7.0Upgrade linux-image-raspi-7.0Upgrade linux-image-realtime-64kUpgrade linux-image-realtime-7.0Upgrade linux-image-generic-7.0Upgrade linux-image-7.0.0-28-generic-64kUpgrade linux-image-gke-64k-7.0Upgrade linux-image-7.0.0-1015-raspi-realtimeUpgrade linux-image-nvidia-bos-7.0Upgrade linux-image-7.0.0-1008-gcp-64kUpgrade linux-image-7.0.0-1009-aws-64kUpgrade linux-image-oem-24.04Upgrade linux-image-gke-hwe-26.04Upgrade linux-image-aws-7.0Upgrade linux-image-gke-64kUpgrade linux-image-gcp-64kUpgrade linux-image-7.0.0-1003-gke-64kUpgrade linux-image-raspi-realtime-7.0Upgrade linux-image-realtimeUpgrade linux-image-oem-26.04aUpgrade linux-image-genericUpgrade linux-image-7.0.0-1014-azureUpgrade linux-image-7.0.0-1015-raspiUpgrade linux-image-gke-64k-hwe-26.04Upgrade linux-image-generic-64kUpgrade linux-image-raspiUpgrade linux-image-realtime-64k-7.0Upgrade linux-image-7.0.0-1008-oracle-64kUpgrade linux-image-azure-fde-7.0Upgrade linux-image-virtual-7.0Upgrade linux-image-7.0.0-1003-gkeUpgrade linux-image-awsUpgrade linux-image-7.0.0-1008-oracleUpgrade linux-image-oem-7.0Upgrade linux-image-nvidia-64k-hwe-26.04Upgrade linux-image-generic-hwe-24.04Upgrade linux-image-generic-64k-7.0Upgrade linux-image-oem-26.04Upgrade linux-image-azure-7.0Upgrade linux-image-7.0.0-1011-gcpUpgrade linux-image-7.0.0-1009-azure-fdeUpgrade linux-image-oem-24.04cUpgrade linux-image-nvidia-64kUpgrade linux-image-azure-fdeUpgrade linux-image-7.0.0-1011-gcp-64kUpgrade linux-image-oem-24.04dUpgrade linux-image-oem-24.04bUpgrade linux-image-oem-24.04aUpgrade linux-image-oracle-7.0Upgrade linux-image-nvidia-64k-7.0Upgrade linux-image-gcp-7.0Upgrade linux-image-gcpUpgrade linux-image-virtual-hwe-26.04Upgrade linux-image-virtualUpgrade linux-image-nvidia-bos-64k-7.0Upgrade linux-image-generic-64k-hwe-24.04Upgrade linux-image-raspi-realtimeUpgrade linux-image-realtime-hwe-26.04Upgrade linux-image-7.0.0-1009-oemUpgrade linux-image-virtual-hwe-24.04Upgrade linux-image-7.0.0-28-realtimeUpgrade linux-image-7.0.0-28-realtime-64kUpgrade linux-image-7.0.0-1016-nvidia-64kUpgrade linux-image-nvidia-7.0Upgrade linux-image-ibm-7.0Upgrade linux-image-oracle-64kUpgrade linux-image-7.0.0-2016-nvidia-bosUpgrade linux-image-7.0.0-1009-awsUpgrade linux-image-realtime-64k-hwe-26.04Upgrade linux-image-ibmUpgrade linux-image-oracle-64k-7.0 | Jul 20, 2026 | Jun 24, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub