CVE-2026-72174
Received Received - Intake

Deadlock in Linux Kernel's HugeTLB PageMap Scan

Vulnerability report for CVE-2026-72174, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-15

Last updated on: 2026-08-17

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: fs/proc/task_mmu: fix hugetlb self-deadlock in pagemap_scan_pte_hole() A PAGEMAP_SCAN ioctl requesting PM_SCAN_WP_MATCHING on a hugetlb VMA hangs the calling thread, unkillably, as soon as the scan reaches an unpopulated part of the range: do_pagemap_scan() walk_page_range() walk_hugetlb_range() hugetlb_vma_lock_read() # take the vma lock for read ... pagemap_scan_pte_hole() # ... ->pte_hole() for a hole uffd_wp_range() change_protection() hugetlb_change_protection() hugetlb_vma_lock_write() # ... and block taking it for write walk_hugetlb_range() holds the hugetlb vma lock for read across the whole walk. A present entry goes to ->hugetlb_entry(); an unpopulated one goes to ->pte_hole(), i.e. pagemap_scan_pte_hole(). To write-protect the hole that handler calls uffd_wp_range(), which on a hugetlb VMA reaches hugetlb_change_protection() and takes the same vma lock for write. The thread then blocks in down_write() waiting for the read lock it is itself holding. The populated path avoids this: pagemap_scan_hugetlb_entry() write-protects the entry inline under the page-table lock and never enters hugetlb_change_protection(). Do the same for holes. Fault in the page table and install the uffd-wp marker directly with make_uffd_wp_huge_pte() under the page-table lock, rather than routing through uffd_wp_range(). That is the same sequence hugetlb_change_protection() runs for an unpopulated entry, minus the vma write lock -- which is safe to skip because PMD sharing is disabled on uffd-wp VMAs (hugetlb_unshare_all_pmds() runs at registration), leaving nothing for that lock to serialise against.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-15
Last Modified
2026-08-17
Generated
2026-09-04
AI Q&A
2026-08-15
EPSS Evaluated
2026-09-03
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel causes a deadlock when using the PAGEMAP_SCAN ioctl with PM_SCAN_WP_MATCHING on a hugetlb VMA. The thread hangs unkillably when scanning an unpopulated memory range because the vma lock is held for read while trying to acquire it for write in pagemap_scan_pte_hole().

Detection Guidance

This vulnerability can be detected by checking for hangs or unresponsive processes when using the PAGEMAP_SCAN ioctl with PM_SCAN_WP_MATCHING on hugetlb VMAs. Monitor system logs for processes stuck in 'D' state (uninterruptible sleep) during hugetlb memory scans.

Impact Analysis

The vulnerability can cause system hangs or unresponsive processes when performing memory scans on hugetlb VMAs. This may lead to denial of service as affected threads cannot be terminated and system resources are tied up.

Compliance Impact

This vulnerability causes a system hang during hugetlb VMA scans, which could lead to denial of service. For compliance standards like GDPR or HIPAA, such disruptions may impact availability of critical systems, potentially violating requirements for timely access to personal or health data.

Mitigation Strategies

Apply the Linux kernel patch that fixes the hugetlb self-deadlock in pagemap_scan_pte_hole(). Avoid using PAGEMAP_SCAN ioctl with PM_SCAN_WP_MATCHING on hugetlb VMAs until patched. Monitor for affected processes and restart them if they become unresponsive.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-72174. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart