« Volver al listado

CVE-2026-89593

Estado: RecibidaAlta (7.1)—

In the Linux kernel, the following vulnerability has been resolved:

hugetlb: only adjust reservation during unmapping if mapcount is 0

Since df7a6d1f6405, __unmap_hugepage_range can adjust reservations. In the case of folio mapped in both a parent and a child, if the parent unmaps the range first, the reservation adjustment will result in an underflow of the reserved count. Once the child unmaps the range, the count is restored. Change __unmap_hugepage_range() to check the mapcount before adjusting the reservation.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad local en kernel Linux (AV:L, PR:L) que causa underflow de contador de reserva de hugetlb, resultando en DoS por agotamiento de recursos.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-89593",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.1,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "df7a6d1f64056aec572162c5d35ed9ff86ece6f3",
              "lessThan": "b0b1b9ca80b795ed2223e76dd787db7067121fb9",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "df7a6d1f64056aec572162c5d35ed9ff86ece6f3",
              "lessThan": "a3c65af20cceb7f997847727636b4017326f845d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "df7a6d1f64056aec572162c5d35ed9ff86ece6f3",
              "lessThan": "0f001491e5a2ec69aa9d5dd6b799e5742245f9ea",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "df7a6d1f64056aec572162c5d35ed9ff86ece6f3",
              "lessThan": "5120b1e048d48596ffaec1a8412012a91adba73b",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "mm/hugetlb.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.9"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.9",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.50",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.4",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "mm/hugetlb.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-11T20:19:43.920",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0f001491e5a2ec69aa9d5dd6b799e5742245f9ea",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/5120b1e048d48596ffaec1a8412012a91adba73b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a3c65af20cceb7f997847727636b4017326f845d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b0b1b9ca80b795ed2223e76dd787db7067121fb9",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nhugetlb: only adjust reservation during unmapping if mapcount is 0\n\nSince df7a6d1f6405, __unmap_hugepage_range can adjust reservations.  In\nthe case of folio mapped in both a parent and a child, if the parent\nunmaps the range first, the reservation adjustment will result in an\nunderflow of the reserved count.  Once the child unmaps the range, the\ncount is restored.  Change __unmap_hugepage_range() to check the mapcount\nbefore adjusting the reservation."
    }
  ],
  "lastModified": "2026-09-14T13:19:13.207",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}