CVE-2026-72412
In the Linux kernel, the following vulnerability has been resolved:
s390/mm: Fix handling of _PAGE_UNUSED pte bit
The _PAGE_UNUSED softbit should not really be lying around. Its sole purpose is to signal to try_to_unmap_one() and try_to_migrate_one() that the page can be discarded instead of being moved / swapped.
KVM has no way to know why a page is being unmapped, so it sets the bit on userspace ptes corresponding to unused guest pages every time they get unmapped. KVM has no reasonable way to clear the bit once the page is in use again.
While set_ptes() checks and clears the bit, other paths that set new ptes did not. This led to used pages being thrown out as if they were unused, causing guest corruption.
Leer descripción completaMostrar menos
Fix the issue by clearing the _PAGE_UNUSED bit for present ptes in set_pte(), i.e. whenever a present pte is getting set. The check in set_ptes() is then redundant and can be removed.
Also fix gmap_helper_try_set_pte_unused() to only set the bit if the pte is present; the _PAGE_UNUSED bit is only defined for present ptes and thus should not be set for non-present ptes.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Puntuación base: 9.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.18%
- Percentil entre todas las CVEs puntuadas: 7
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1068Exploitation for Privilege Escalationprivilege escalation85 % - Impacto principal
T1565.001Stored Data Manipulationimpact75 % - Impacto secundario
T1499.004Application or System Exploitationimpact65 %
Acceso local sin interacción (AV:L/PR:N/UI:N) en kernel Linux → T1068. Corrupción de memoria de páginas en uso causada por manipulación de bits PTE → manipulación de datos (T1565.001). Impacto secundario de disponibilidad por corrupción que causa fallos.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-72412",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 9.3,
"attackVector": "LOCAL",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 6,
"exploitabilityScore": 2.5
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "c98175b7917fa81cd499b1527c4a57fd7d36711e",
"lessThan": "fda07c8e4b54b9105f1ca73f0adea7b244d405f4",
"versionType": "git"
},
{
"status": "affected",
"version": "c98175b7917fa81cd499b1527c4a57fd7d36711e",
"lessThan": "d4bb00704a66024502261fa7a523c07420249fea",
"versionType": "git"
}
],
"programFiles": [
"arch/s390/include/asm/pgtable.h",
"arch/s390/mm/gmap_helpers.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "7.0"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "7.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"arch/s390/include/asm/pgtable.h",
"arch/s390/mm/gmap_helpers.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-08-15T06:22:14.817",
"references": [
{
"url": "https://git.kernel.org/stable/c/d4bb00704a66024502261fa7a523c07420249fea",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/fda07c8e4b54b9105f1ca73f0adea7b244d405f4",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/mm: Fix handling of _PAGE_UNUSED pte bit\n\nThe _PAGE_UNUSED softbit should not really be lying around. Its sole\npurpose is to signal to try_to_unmap_one() and try_to_migrate_one()\nthat the page can be discarded instead of being moved / swapped.\n\nKVM has no way to know why a page is being unmapped, so it sets the bit\non userspace ptes corresponding to unused guest pages every time they\nget unmapped. KVM has no reasonable way to clear the bit once the page\nis in use again.\n\nWhile set_ptes() checks and clears the bit, other paths that set new\nptes did not. This led to used pages being thrown out as if they were\nunused, causing guest corruption.\n\nFix the issue by clearing the _PAGE_UNUSED bit for present ptes in\nset_pte(), i.e. whenever a present pte is getting set. The check in\nset_ptes() is then redundant and can be removed.\n\nAlso fix gmap_helper_try_set_pte_unused() to only set the bit if the\npte is present; the _PAGE_UNUSED bit is only defined for present ptes\nand thus should not be set for non-present ptes."
}
],
"lastModified": "2026-08-17T06:19:08.060",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}