CVE-2026-98223
Received Received - Intake

Memory Leak in Linux Kernel Filemap

Vulnerability report for CVE-2026-98223, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: mm: filemap: retain mapped dropbehind folios Fault-around can map ready dropbehind folios without going through the normal page-cache lookup that clears dropbehind. A mapping represents a competing cached user, so retain the folio instead of forcibly unmapping it when writeback completes. For a mapped folio, folio_unmap_invalidate() can call unmap_mapping_folio(), which takes i_mmap_rwsem and may sleep. Retaining mapped folios avoids this path when folio_end_dropbehind() runs in non-preemptible task context. Tal was able to trigger a sleeping-in-atomic warning due to this [1]. Unmapped dropbehind folios continue through the existing invalidation path.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
Linux Linux fb7d3bc4149395c1ae99029c852eab6c28fc3c88
Linux Linux fb7d3bc4149395c1ae99029c852eab6c28fc3c88
Linux Linux fb7d3bc4149395c1ae99029c852eab6c28fc3c88
Linux Linux 6.14

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Linux kernel vulnerability where mapped dropbehind folios could be incorrectly unmapped during writeback. Fault-around code maps these folios without clearing dropbehind, leading to a sleeping-in-atomic warning when folio_unmap_invalidate() tries to take i_mmap_rwsem in non-preemptible context.

Detection Guidance

This vulnerability is specific to the Linux kernel's memory management and does not have direct network detection methods. Monitoring kernel logs for sleeping-in-atomic warnings or related mm subsystem errors may indicate exploitation. Check for kernel messages with dmesg or journalctl.

Impact Analysis

This vulnerability could cause system instability or crashes due to sleeping in atomic context, potentially leading to kernel panics or unexpected behavior in systems running affected Linux kernel versions.

Mitigation Strategies

Apply the latest Linux kernel patches or updates that address this issue. If immediate patching is not possible, monitor system stability and performance for signs of memory management issues. Consider isolating affected systems if they exhibit unusual behavior.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-98223. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart