CVE-2026-89593
Received Received - Intake

Memory Corruption in Linux Kernel HugeTLB

Vulnerability report for CVE-2026-89593, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-14

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: hugetlb: only adjust reservation during unmapping if mapcount is 0 Since df7a6d1f6405, __unmap_hugepage_range can adjust reservations. In the case of folio mapped in both a parent and a child, if the parent unmaps the range first, the reservation adjustment will result in an underflow of the reserved count. Once the child unmaps the range, the count is restored. Change __unmap_hugepage_range() to check the mapcount before adjusting the reservation.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-14
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-09-30
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Linux kernel vulnerability where a bug in memory management can cause incorrect adjustments to memory reservations. When a memory page is mapped in both a parent and child process, unmapping it in the parent first may lead to an underflow in reserved memory counts. Later, when the child unmaps the page, the count is restored, causing potential instability or crashes.

Detection Guidance

This vulnerability is specific to the Linux kernel's hugetlb implementation and requires kernel-level inspection. Detection involves checking kernel logs for hugetlb reservation underflow errors or verifying if your kernel version includes the fix (commit df7a6d1f6405). Use commands like 'dmesg | grep hugetlb' or 'uname -a' to check kernel version and logs.

Impact Analysis

This vulnerability could lead to system instability, crashes, or unexpected behavior in applications using huge memory pages. It may cause memory management issues, potentially affecting performance or causing applications to fail.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or similar standards as it is a low-level kernel memory management issue without documented impact on data protection or privacy controls.

Mitigation Strategies

Update the Linux kernel to a patched version that includes the fix for this vulnerability. The specific commit df7a6d1f6405 addresses the issue by modifying __unmap_hugepage_range to check mapcount before adjusting reservations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89593. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart