In the Linux kernel, the following vulnerability has been resolved:
mm/vma: do not try to unmap a VMA if mmap_prepare() invoked from mmap()
The mmap_prepare hook functionality includes the ability to invoke mmap_prepare() from the mmap() hook of existing 'stacked' drivers, that is ones which are capable of calling the mmap hooks of other drivers/file systems (e.g. overlayfs, shm).
As part of the mmap_prepare action functionality, we deal with errors by unmapping the VMA should one arise. This works in the usual mmap_prepare case, as we invoke this action at the last moment, when the VMA is established in the maple tree.
However, the mmap() hook passes a not-fully-established VMA pointer to the caller (which is the motivation behind the mmap_prepare() work), which is detached.
So attempting to unmap a VMA in this state will be problematic, with the most obvious symptom being a warning in vma_mark_detached(), because the VMA is already detached.
It's also unncessary - the mmap() handler will clean up the VMA on error.
So to fix this issue, this patch propagates whether or not an mmap action is being completed via the compatibility layer or directly.
If the former, then we do not attempt VMA cleanup, if the latter, then we do.
This patch also updates the userland VMA tests to reflect the change.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat_linux | — | No solution exists | Jul 22, 2026 | Jul 19, 2026 |
| Ubuntu | — | Upgrade linux-image-7.0.0-2016-nvidia-bos-64kUpgrade linux-image-gcp-7.0Upgrade linux-image-7.0.0-1016-nvidiaUpgrade linux-image-nvidia-64k-hwe-26.04Upgrade linux-image-aws-64kUpgrade linux-image-oracleUpgrade linux-image-nvidia-hwe-26.04Upgrade linux-image-7.0.0-1010-azureUpgrade linux-image-7.0.0-1009-aws-64kUpgrade linux-image-aws-7.0Upgrade linux-image-raspi-realtime-7.0Upgrade linux-image-7.0.0-1015-raspiUpgrade linux-image-7.0.0-1015-raspi-realtimeUpgrade linux-image-aws-64k-7.0Upgrade linux-image-nvidia-bos-7.0Upgrade linux-image-gcp-64kUpgrade linux-image-7.0.0-1014-azureUpgrade linux-image-gcp-64k-7.0Upgrade linux-image-raspi-7.0Upgrade linux-image-7.0.0-1009-azure-fdeUpgrade linux-image-7.0.0-1010-ibmUpgrade linux-image-raspi-realtimeUpgrade linux-image-oracle-7.0Upgrade linux-image-gcpUpgrade linux-image-7.0.0-1008-oracleUpgrade linux-image-oracle-64k-7.0Upgrade linux-image-azure-fdeUpgrade linux-image-7.0.0-1009-awsUpgrade linux-image-azure-fde-7.0Upgrade linux-image-awsUpgrade linux-image-nvidia-bos-64kUpgrade linux-image-nvidia-7.0Upgrade linux-image-7.0.0-2016-nvidia-bosUpgrade linux-image-azureUpgrade linux-image-oracle-64kUpgrade linux-image-7.0.0-1011-gcp-64kUpgrade linux-image-nvidia-64kUpgrade linux-image-nvidia-bos-64k-7.0Upgrade linux-image-nvidiaUpgrade linux-image-7.0.0-1008-oracle-64kUpgrade linux-image-nvidia-64k-7.0Upgrade linux-image-ibmUpgrade linux-image-7.0.0-1011-gcpUpgrade linux-image-azure-7.0Upgrade linux-image-7.0.0-1016-nvidia-64kUpgrade linux-image-raspiUpgrade linux-image-ibm-7.0Upgrade linux-image-nvidia-bos | Jul 21, 2026 | Jul 20, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub