From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 9C2E7481643 for ; Fri, 4 Sep 2026 17:14:51 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788542092; cv=none; b=ReG/5V9k6NtiEUzLsZHtM5KbuYKwSOt7AsFl5O09ymRZvQtVSHnB1NuA8wfKhc9V3KCrlPUzgWL3J3/Whxfcn11fXY6M4sfGiA8H4dMWWBvrsbtxiQNOGutCXulqZXGvXT2QrZq3fZ/jzKXU+1dXmCCz22rci4BZGOQnJFz7iiY= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788542092; c=relaxed/simple; bh=fTor/8PrHnFrrJ6brIgAUyAhS6be5PgbsyM5PZ9Jrys=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=jmdPpP1+4f4Upitzatdtggpjtsk+QXyvH6KNJ9DFkkn/dUbXucw2lYpyOyXWI5UXk1rD8Ei3FWEHArKJDWCfEbNB9MHh4sUqYOXt4RwyKCfcStXU9P+9WZDZfk12VgeYmxleH8xEmDArTxNRO5LvW/7M3VHASGHkZQTIyzwsoQE= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=z7Ep8n/0; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="z7Ep8n/0" Received: by smtp.kernel.org (Postfix) with ESMTPSA id A4ED91F00A3D; Fri, 4 Sep 2026 17:14:50 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1788542091; bh=4L7PRBTCpmu3gKpgW38Wth+m+zuWMphqy0NR4H8O/cc=; h=From:To:Cc:Subject:Date:Reply-To; b=z7Ep8n/00yVL1HEbtGAblsk5gRRLuEIj1OEcl8tgzAArhHc9Cg8+b5gxXsT11F8Ez j5HtyGcKVKNB0kb5RIAV0dMPy+33M0SsWIkPUH43I3QjjDWHFSk7j3KqunAiIuKD+Y sw/105kTEdI/w46SDgaJiSfuQWZaZxqaakccuAOE= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-80893: mm/hugetlb: fix swap entry corruption when clearing uffd-wp at fork() Date: Fri, 4 Sep 2026 19:09:34 +0200 Message-ID: <2026090430-CVE-2026-80893-abce@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=4495; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=f6Vut6dtnsYOthzN+ruN4O/4BN7M0vIM1FESY5Tnf/s=; b=owGbwMvMwCRo6H6F97bub03G02pJDFmzfnudai3Kns96eUrzvC7VU8bqCz5N3nx1X/1OuXMCE ZfPbrpZ1hHLwiDIxCArpsjyZRvP0f0VhxS9DG1Pw8xhZQIZwsDFKQATia9imJ/fsfr+P33V6UlL vux/9PqJlaaZVCnDgql/JDLr7i06FsLUo7InzuKG3GHbqQA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix swap entry corruption when clearing uffd-wp at fork() copy_hugetlb_page_range() clears the uffd-wp bit of migration and hwpoison entries with huge_pte_clear_uffd_wp(), which operates on the present-PTE bit position. Swap entries keep the uffd-wp state elsewhere -- the migration branch reads and sets it with pte_swp_uffd_wp() and pte_swp_mkuffd_wp() -- and the present-PTE position falls into the swap payload. On x86-64 it lands in the inverted swap offset, where a naturally-aligned hugetlb PFN always has the affected bit set, so the clear advances the encoded PFN by two pages. No userfaultfd needs to be involved: the clear is guarded only by the child VMA not being uffd-wp registered, so a plain fork() with an in-flight hugetlb migration entry (or a poisoned hugetlb page) corrupts the entry copied into the child. Instrumenting the clear and forking after MADV_HWPOISON on a 2MB anon hugetlb page shows: offset before=120e00 offset after =120e02 The fallout is mostly latent: rmap walks match migration entries by folio range and remove_migration_pte() rebuilds the PTE from the folio, so a within-folio PFN skew heals once migration completes. But any path that re-encodes the corrupted offset -- e.g. hugetlb_change_protection() rewriting a writable migration entry via make_readable_migration_entry(swp_offset(entry)) -- propagates it. Migration entries legitimately carry uffd-wp, so clear it with pte_swp_clear_uffd_wp(), matching copy_nonpresent_pte() and move_huge_pte(). A hwpoison entry, on the other hand, never carries the uffd-wp bit: it is installed fresh by make_hwpoison_entry() (try_to_unmap_one() does not preserve uffd-wp on the hwpoison path) and hugetlb_change_protection() leaves hwpoison entries untouched. There was nothing to clear there, only the corruption, so drop the clear entirely. The Linux kernel CVE team has assigned CVE-2026-80893 to this issue. Affected and fixed versions =========================== Issue introduced in 5.19 with commit bc70fbf269fdff410b0b6d75c3770b9f59117b90 and fixed in 6.1.183 with commit f1b1311c0352873137768bac5a126e491271a747 Issue introduced in 5.19 with commit bc70fbf269fdff410b0b6d75c3770b9f59117b90 and fixed in 6.6.151 with commit 69cb5825d9988c7944bc9f1dc08cb233655405a7 Issue introduced in 5.19 with commit bc70fbf269fdff410b0b6d75c3770b9f59117b90 and fixed in 6.12.103 with commit 8b0de7005b148738d79d6c45594d566489948a68 Issue introduced in 5.19 with commit bc70fbf269fdff410b0b6d75c3770b9f59117b90 and fixed in 6.18.44 with commit 2b9a07002c2f296aa6a9c591213933d3492e3089 Issue introduced in 5.19 with commit bc70fbf269fdff410b0b6d75c3770b9f59117b90 and fixed in 7.1.8 with commit 2fa11c60c9c06bafc19cf4d9efdaa36a38079e87 Issue introduced in 5.19 with commit bc70fbf269fdff410b0b6d75c3770b9f59117b90 and fixed in 7.2 with commit 83abe2fd5b3aeb3123b5408a5a91709c5538fb23 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-80893 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: mm/hugetlb.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/f1b1311c0352873137768bac5a126e491271a747 https://git.kernel.org/stable/c/69cb5825d9988c7944bc9f1dc08cb233655405a7 https://git.kernel.org/stable/c/8b0de7005b148738d79d6c45594d566489948a68 https://git.kernel.org/stable/c/2b9a07002c2f296aa6a9c591213933d3492e3089 https://git.kernel.org/stable/c/2fa11c60c9c06bafc19cf4d9efdaa36a38079e87 https://git.kernel.org/stable/c/83abe2fd5b3aeb3123b5408a5a91709c5538fb23