In the Linux kernel, the following vulnerability has been resolved:
userfaultfd: gate must_wait writability check on pte_present()
userfaultfd_must_wait() and userfaultfd_huge_must_wait() read the PTE without taking the page table lock and then apply pte_write() / huge_pte_write() to it. Those accessors decode bits from the present encoding only; on a swap or migration entry they read the offset bits that happen to share the same position and return an undefined result.
The intent of the check is "is this fault still WP-blocked?". A non-marker swap entry means the page is in transit -- the userfault context the original fault delivered against is no longer the same, and the swap-in or migration completion path will re-deliver a fresh fault if userspace still needs to handle it. Worst case under the current code the garbage write bit says "wait", and the thread stays asleep until a UFFDIO_WAKE that may never arrive.
Gate the writability check on pte_present() so the lockless re-check only inspects present-PTE bits when the entry is actually present. The non-present, non-marker case returns "don't wait" and lets the fault path retry.
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade kernel6.12-tools-develUpgrade kernel6.18-debuginfoUpgrade kernel-tools-develUpgrade python3-perf6.18-debuginfoUpgrade kernel6.18-debuginfo-common-x86_64Upgrade kernel6.18-tools-develUpgrade kernelUpgrade python3-perf-debuginfoUpgrade kernel6.18-toolsUpgrade kernel6.12-toolsUpgrade kernel-debuginfo-common-x86_64Upgrade kernel-modules-extra-commonUpgrade perf6.12Upgrade bpftool6.18-debuginfoUpgrade python3-perfUpgrade kernel-livepatch-6.1.180-225.360Upgrade perf6.18Upgrade python3-perf6.18Upgrade python3-perf6.12-debuginfoUpgrade microvm-kernel6.18Upgrade kernel6.18-headersUpgrade kernel6.12-tools-debuginfoUpgrade bpftoolUpgrade kernel6.18-tools-debuginfoUpgrade perf6.12-debuginfoUpgrade kernel6.12-debuginfoUpgrade kernel-livepatch-6.12.100-125.179Upgrade kernel6.18-develUpgrade kernel-toolsUpgrade kernel6.18-modules-extraUpgrade kernel6.18-debuginfo-common-aarch64Upgrade kernel6.12-modules-extra-commonUpgrade perf6.18-debuginfoUpgrade kernel6.12-headersUpgrade perf-debuginfoUpgrade kernel-debuginfoUpgrade kernel6.18-modules-extra-commonUpgrade kernel-livepatch-6.18.39-79.141Upgrade kernel-modules-extraUpgrade bpftool-debuginfoUpgrade bpftool6.12Upgrade kernel-headersUpgrade kernel6.12-debuginfo-common-aarch64Upgrade kernel-develUpgrade kernel6.12Upgrade bpftool6.18Upgrade kernel-tools-debuginfoUpgrade python3-perf6.12Upgrade perfUpgrade kernel6.12-debuginfo-common-x86_64Upgrade kernel-debuginfo-common-aarch64Upgrade kernel6.12-develUpgrade kernel6.12-modules-extraUpgrade kernel6.18Upgrade bpftool6.12-debuginfo | Aug 18, 2026 | Jul 25, 2026 |
| Debian | — | Upgrade linuxUpgrade linux-6.12Upgrade linux-6.1 | Jul 28, 2026 | Jul 28, 2026 |
| Redhat_linux | — | No solution exists | Jul 30, 2026 | Jul 25, 2026 |
| Ubuntu | — | Upgrade linux-image-raspi-7.0Upgrade linux-image-realtimeUpgrade linux-image-raspiUpgrade linux-image-awsUpgrade linux-image-gke-7.0Upgrade linux-image-generic-7.0Upgrade linux-image-nvidia-7.0Upgrade linux-image-nvidia-hwe-26.04Upgrade linux-image-realtime-64k-hwe-26.04Upgrade linux-image-nvidia-64k-hwe-26.04Upgrade linux-image-gcp-64kUpgrade linux-image-realtime-hwe-26.04Upgrade linux-image-nvidia-64kUpgrade linux-image-generic-hwe-26.04Upgrade linux-image-gke-64k-7.0Upgrade linux-image-oem-26.04Upgrade linux-image-gcp-64k-7.0Upgrade linux-image-oem-7.0Upgrade linux-image-nvidia-bosUpgrade linux-image-realtime-7.0Upgrade linux-image-7.0.0-1018-nvidiaUpgrade linux-image-gkeUpgrade linux-image-realtime-64kUpgrade linux-image-raspi-realtime-7.0Upgrade linux-image-7.0.0-1012-aws-64kUpgrade linux-image-7.0.0-1018-nvidia-64kUpgrade linux-image-generic-64k-7.0Upgrade linux-image-7.0.0-1011-gcp-64kUpgrade linux-image-aws-7.0Upgrade linux-image-7.0.0-1006-gke-64kUpgrade linux-image-nvidia-bos-64kUpgrade linux-image-gke-64kUpgrade linux-image-7.0.0-1019-raspiUpgrade linux-image-gke-64k-hwe-26.04Upgrade linux-image-7.0.0-1012-awsUpgrade linux-image-7.0.0-31-generic-64kUpgrade linux-image-7.0.0-2018-nvidia-bosUpgrade linux-image-oem-26.04aUpgrade linux-image-generic-hwe-24.04Upgrade linux-image-nvidia-bos-64k-7.0Upgrade linux-image-virtualUpgrade linux-image-gke-hwe-26.04Upgrade linux-image-7.0.0-1013-oemUpgrade linux-image-7.0.0-31-genericUpgrade linux-image-gcp-7.0Upgrade linux-image-ibm-7.0Upgrade linux-image-generic-64k-hwe-24.04Upgrade linux-image-gcpUpgrade linux-image-virtual-hwe-24.04Upgrade linux-image-7.0.0-1011-gcpUpgrade linux-image-raspi-realtimeUpgrade linux-image-nvidia-bos-7.0Upgrade linux-image-generic-64k-hwe-26.04Upgrade linux-image-7.0.0-1006-gkeUpgrade linux-image-7.0.0-31-realtime-64kUpgrade linux-image-7.0.0-31-realtimeUpgrade linux-image-oem-26.04bUpgrade linux-image-nvidia-64k-7.0Upgrade linux-image-7.0.0-1013-ibmUpgrade linux-image-genericUpgrade linux-image-7.0.0-2018-nvidia-bos-64kUpgrade linux-image-7.0.0-1019-raspi-realtimeUpgrade linux-image-realtime-64k-7.0Upgrade linux-image-nvidiaUpgrade linux-image-ibmUpgrade linux-image-virtual-7.0Upgrade linux-image-aws-64k-7.0Upgrade linux-image-generic-64kUpgrade linux-image-virtual-hwe-26.04Upgrade linux-image-aws-64k | Sep 14, 2026 | Sep 7, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jul 31, 2026 | Jul 25, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub