« Volver al listado

CVE-2026-80719

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

mm: mglru: fix stale batch updates after memcg reparenting

The mglru page table walker batches per-generation size deltas in walk->nr_pages while walking page tables without holding the lruvec lock. The reset_batch_size() later folds those deltas into walk->lruvec under the lruvec lock.

The page table walker can run concurrently with the memcg reparenting path as follows:

CPU0 CPU1 ==== ====

This will trigger the following warning in lru_gen_exit_memcg():

And the user-visible impact of underestimated nr_pages in MGLRU was premature OOMs because MGLRU does not try to reclaim memory when nr_pages reaches zero, but there are still more pages.

Leer descripción completaMostrar menos

To fix it, make reset_batch_size() check CSS_DYING under RCU before flushing the pending batch. A non-dying memcg keeps the original lruvec stable against RCU-delayed offlining; a dying memcg redirects the deltas to the first non-dying ancestor.

Detalles técnicos trazas, registros y código del informe original
walk_mm
--> walk_page_range
    --> update_batch_size
        --> walk->nr_pages += delta

                              mem_cgroup_css_offline
                              --> memcg_reparent_objcgs
                                  --> lock lruvec
                                      lru_gen_reparent_memcg
                                      --> reparent child folios to parent
                                      unlock lruvec

    lock lruvec
    reset_batch_size
    --> child lrugen->nr_pages += delta

	VM_WARN_ON_ONCE(memchr_inv(lruvec->lrugen.nr_pages, 0,
				   sizeof(lruvec->lrugen.nr_pages)));

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-80719",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "f304652609eae3814b0e9d11c75c0e0cb62da31f",
              "lessThan": "fceb6b7f3ddec6ea9fc11577f4cf1b2da73a3101",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f304652609eae3814b0e9d11c75c0e0cb62da31f",
              "lessThan": "de4660898b7aa7e03d3b120a6bfa6b26211e4e77",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "include/linux/memcontrol.h",
            "mm/vmscan.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7.1"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "7.1",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.1.8",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "include/linux/memcontrol.h",
            "mm/vmscan.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-28T08:16:57.720",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/de4660898b7aa7e03d3b120a6bfa6b26211e4e77",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/fceb6b7f3ddec6ea9fc11577f4cf1b2da73a3101",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm: mglru: fix stale batch updates after memcg reparenting\n\nThe mglru page table walker batches per-generation size deltas in\nwalk->nr_pages while walking page tables without holding the lruvec lock. \nThe reset_batch_size() later folds those deltas into walk->lruvec under\nthe lruvec lock.\n\nThe page table walker can run concurrently with the memcg reparenting path\nas follows:\n\nCPU0                           CPU1\n====                           ====\n\nwalk_mm\n--> walk_page_range\n    --> update_batch_size\n        --> walk->nr_pages += delta\n\n                              mem_cgroup_css_offline\n                              --> memcg_reparent_objcgs\n                                  --> lock lruvec\n                                      lru_gen_reparent_memcg\n                                      --> reparent child folios to parent\n                                      unlock lruvec\n\n    lock lruvec\n    reset_batch_size\n    --> child lrugen->nr_pages += delta\n\nThis will trigger the following warning in lru_gen_exit_memcg():\n\n\tVM_WARN_ON_ONCE(memchr_inv(lruvec->lrugen.nr_pages, 0,\n\t\t\t\t   sizeof(lruvec->lrugen.nr_pages)));\n\nAnd the user-visible impact of underestimated nr_pages in MGLRU was\npremature OOMs because MGLRU does not try to reclaim memory when nr_pages\nreaches zero, but there are still more pages.\n\nTo fix it, make reset_batch_size() check CSS_DYING under RCU before\nflushing the pending batch.  A non-dying memcg keeps the original lruvec\nstable against RCU-delayed offlining; a dying memcg redirects the deltas\nto the first non-dying ancestor."
    }
  ],
  "lastModified": "2026-08-28T08:16:57.720",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}