CVE-2026-98373
Received Received - Intake

Memory Corruption in Linux Kernel via mremap

Vulnerability report for CVE-2026-98373, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: preserve mremap address delta when skipping page tables move_hugetlb_page_tables() optimizes mremap() by advancing to the last entry in the page table when the source page table does not exist, either initially or after unsharing a PMD table. The common loop increment then steps to the first entry in the next page table. However, the code advances both the source and destination addresses to the last entries in their respective page tables, which is wrong. The destination address must be advanced only by the same amount as the source address. If the source and destination offsets within their page tables differ, the destination address can be advanced too far, causing follow-up issues. Fix this by advancing the destination address by the source advance distance. With a reproducer, we were able to trigger a kernel panic on x86-64. With this fix in place, we can no longer reproduce the issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 5 associated CPEs
Vendor Product Version / Range
Linux Linux e95a9851787bbb3cd4deb40fe8bab03f731852d1
Linux Linux e95a9851787bbb3cd4deb40fe8bab03f731852d1
Linux Linux e95a9851787bbb3cd4deb40fe8bab03f731852d1
Linux Linux e95a9851787bbb3cd4deb40fe8bab03f731852d1
Linux Linux 6.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Linux kernel vulnerability in the memory management subsystem. It involves incorrect handling of page table addresses during the mremap() system call for huge pages. The bug causes the destination address to advance too far when copying page tables, potentially leading to memory corruption or kernel panic.

Detection Guidance

This vulnerability is specific to the Linux kernel's memory management (mm/hugetlb) and requires kernel-level detection. There are no direct network or system commands to detect it as it is a kernel bug. Monitoring kernel logs for crashes or panics related to hugetlb or mremap operations may indicate exploitation. Check for kernel version and apply patches if vulnerable.

Impact Analysis

If exploited, this could crash the system (kernel panic) or corrupt memory, leading to instability or security issues. It primarily affects systems using huge pages in memory management operations.

Compliance Impact

This vulnerability in the Linux kernel could lead to kernel panics, which may cause system instability or crashes. Such instability could potentially disrupt data processing or storage operations, indirectly affecting compliance with standards like GDPR or HIPAA that require reliable data handling and availability.

Mitigation Strategies

Apply the latest Linux kernel update that includes the fix for this vulnerability. If updating is not immediately possible, consider disabling hugetlb features temporarily or restricting access to mremap operations. Monitor system stability and kernel logs for signs of crashes or unusual behavior.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-98373. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart