From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 68F994A4EE6 for ; Thu, 24 Sep 2026 15:30:59 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790263861; cv=none; b=lo3Zz/S9Q761Z5hqlv3I+bUOC2FqSt5DEgJtsd/GqUU5Pzt+MDVTKtKioVf+VPFqDhVrquWtR+3mWe+xqOHYxMvDrreWZ+xbPn1BzvUHKH514YKcdLnaU82ftEw9O2bt9Itrr0hmfpdEXg1Y3hOwP/Few2uw+/iZh0KlBf0lG8o= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790263861; c=relaxed/simple; bh=4GCsfvU8DoUQTpa8huXcITWHmzeSiuHHWWvW6TlEBlg=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=uaENkwv0Z0DkkimJfskOsP/JXn8fazIrg5TszYh4P+Pn3cfyGifocRzAkLAQ49fNGcErRawfSp5LA5qatTeZ42XqnfTG6n1eqrbGpd9fKgUUIGwSEMhpuuzuqzJxrr8tT7gyQ4u/Ifs5rw3mfedGzhE4agq2x/btrrqFZ0n9tbQ= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=EiZjOp0S; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="EiZjOp0S" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 9FFEF1F000FF; Thu, 24 Sep 2026 15:30:56 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1790263859; bh=+49dn79huhFTtQBJ1Zerpy6WUzukYclmY80E6dic0uc=; h=From:To:Cc:Subject:Date:Reply-To; b=EiZjOp0S8N23uF5my4/GfODuLp0KXdi9vKIW45fIPsQzVsC0qM7NRdVGap/bYTgv0 G/FqQbsdwQchA7Ed1eia833JtkIiUydin14uaqxlJgC5jW8bDxBaKrbDsKfYSwY4YT Zr/F2EyboX0zW/dkQNcTwCX1vLPXmUqWDaZh4odU= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-93232: mm/hugetlb: fix boot panic with CONFIG_DEBUG_VM and HVO bootmem pages Date: Thu, 24 Sep 2026 17:28:48 +0200 Message-ID: <2026092442-CVE-2026-93232-708e@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=3914; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=WCzlDsiPo2unWlLTrNVZePINIU5FAJaCZH4kg+prLCE=; b=owGbwMvMwCRo6H6F97bub03G02pJDFlbHVd9v68eb2SzeeZeru2p7WW5KgxLHrMdS9MpXWgVL 7PO9M36jlgWBkEmBlkxRZYv23iO7q84pOhlaHsaZg4rE8gQBi5OAZjIgscMcziEL603vNBitfje sut2Sq/cvGfnTmZY0C/HMuFZm6B8Xd3cZMdJQp+cle+3AgA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix boot panic with CONFIG_DEBUG_VM and HVO bootmem pages Patch series "mm: Refactor bootmem gigantic hugepage allocation", v4. This series is split out from the earlier larger series "mm: Generalize HVO for HugeTLB and device DAX" [1]. It collects the first 19 patches of that series as a standalone set of fixes and preparatory cleanups around bootmem HugeTLB handling, sparse initialization ordering, and related vmemmap setup. The first patches fix a few bugs found while reviewing the existing code, including incorrect bootmem HVO handling, wrong vmemmap registration arguments, a powerpc compound-vmemmap tracking bug, and too-late initialization of gigantic bootmem HugeTLB struct pages. The rest of the series reorders early memory initialization so the relevant zone state is available before sparse and HugeTLB boot-time setup runs, then simplifies the remaining bootmem gigantic hugepage allocation path and removes code made obsolete by that rework. At a high level: - patches [1-4] fix boot-time and arch-specific bugs - patches [5-12] reorder and simplify sparse/mm/hugetlb early init - patches [13-19] refactor bootmem gigantic hugepage allocation and remove obsolete helpers and state This patch (of 19): Commit 622026e87c40 ("mm/hugetlb: remove fake head pages") switched HVO to reuse per-zone shared tail pages from zone->vmemmap_tails[]. Those shared tail pages were initialized in hugetlb_vmemmap_init(), but bootmem HugeTLB folios are prepared earlier from gather_bootmem_prealloc(). With hugetlb_free_vmemmap=on, prep_and_add_bootmem_folios() can access pageblock flags on bootmem HugeTLB pages whose mirrored tail struct pages already point to the shared tail page. On CONFIG_DEBUG_VM kernels, get_pfnblock_bitmap_bitidx() then dereferences the still-uninitialized shared tail page and can panic during boot. Initialize zone->vmemmap_tails[] from gather_bootmem_prealloc(), before bootmem HugeTLB folios are processed, and drop the later initialization from hugetlb_vmemmap_init(). This bug only affects CONFIG_DEBUG_VM kernels, where the relevant assertion is evaluated. The Linux kernel CVE team has assigned CVE-2026-93232 to this issue. Affected and fixed versions =========================== Issue introduced in 7.1 with commit 622026e87c4019e609010811757e31193cc23847 and fixed in 7.2.4 with commit 2ddf429e25cf8415d9c308f07e64012026bd4d77 Issue introduced in 7.1 with commit 622026e87c4019e609010811757e31193cc23847 and fixed in 7.3-rc1 with commit c0caeceb0c3899dc42844d3979093b27d1434108 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-93232 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: mm/hugetlb.c mm/hugetlb_vmemmap.c mm/sparse-vmemmap.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/2ddf429e25cf8415d9c308f07e64012026bd4d77 https://git.kernel.org/stable/c/c0caeceb0c3899dc42844d3979093b27d1434108