CVE-2026-89757
Received Received - Intake

Memory Corruption in Linux Kernel mm/mglru

Vulnerability report for CVE-2026-89757, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-11

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: mm/mglru: fix and remove redundant unevictable folio handling sort_folio() has a shortcut for moving folios that are no longer evictable but are still sitting on a generation list. However, this shortcut is buggy. It does not follow the PG_lru usage convention, and it has a more serious issue. Unevictable folios are not threaded on lists[LRU_UNEVICTABLE], so that folio->lru can be reused to hold folio->mlock_count (see the comment in lruvec_init()). Hence lruvec_add_folio() skips the list_add() for them, and every other place that turns a folio unevictable initialises mlock_count explicitly: lru_add() sets it to 0, __mlock_folio() and __mlock_new_folio() set it to !!folio_test_mlocked(folio). sort_folio() sets nothing, and the lru_gen_del_folio() right above it may have already poisoned folio->lru via list_del(), so mlock_count ends up aliasing LIST_POISON2, which reads as 0x122, i.e. 290. The result is user visible. On munlock, __munlock_folio() decrements that bogus count, finds it still non-zero and bails out before clearing PG_mlocked, so the folio remains unevictable and the Mlocked accounting stays inflated until the folio is freed. The shortcut also touches the LRU flags in the wrong order. It calls lru_gen_del_folio() while PG_lru is still set, so a concurrent folio_test_clear_lru() (e.g. compaction, folio_isolate_lru()) can succeed on a folio that has already been taken off the generation list, which may lead to unexpected behavior. So fix it by isolating them as common folios and letting the generic shrink path cull them. This matches the classical LRU behavior, and there should be no visible effect on the generic eviction or isolation behavior. There is no performance concern either, such a folio goes through this once, and then it is off the generation lists for good.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-11
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-09-30
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves incorrect handling of unevictable folios in the memory management subsystem. A bug in sort_folio() causes mlock_count to alias LIST_POISON2, leading to incorrect accounting and leaving folios in an unevictable state even after munlock. This results in inflated Mlocked accounting and potential unexpected behavior due to improper LRU flag handling.

Detection Guidance

This vulnerability is specific to the Linux kernel's memory management and does not have direct network or system detection commands. It requires kernel source code analysis or runtime debugging to identify. Monitor kernel logs for unusual memory handling or unevictable folio issues.

Impact Analysis

The vulnerability may cause memory accounting errors where unevictable folios remain locked in memory indefinitely, leading to inflated Mlocked statistics. This could result in reduced system performance or unexpected behavior during memory operations like compaction or folio isolation.

Compliance Impact

This vulnerability does not directly affect compliance with standards like GDPR or HIPAA as it is a low-level memory management issue in the Linux kernel. It may indirectly impact compliance if the affected system is used to process or store sensitive data, but the vulnerability itself is not a compliance violation.

Mitigation Strategies

Apply the latest Linux kernel patches from your distribution to resolve the mm/mglru issue. Reboot the system after patching to ensure the updated kernel is active. Monitor system performance and memory usage for anomalies.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89757. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart