CVE-2026-89966
In the Linux kernel, the following vulnerability has been resolved:
mm/hugetlb_cma: fix null nodemask dereference in hugetlb_cma_alloc_frozen_folio
alloc_buddy_hugetlb_folio_with_mpol() can pass a NULL nodemask to alloc_fresh_hugetlb_folio() as a fallback to allocate from all nodes. If order is gigantic, alloc_fresh_hugetlb_folio() propagates the NULL nodemask down to hugetlb_cma_alloc_frozen_folio() via alloc_gigantic_frozen_folio().
Additionally, hugetlb_cma_alloc_frozen_folio() previously attempted allocation on hugetlb_cma[nid] without verifying if nid is included in the caller's nodemask. Adding a node_isset(nid, *nodemask) check ensures the initial preferred node allocation honors the memory policy / nodemask.
Leer descripción completaMostrar menos
However, hugetlb_cma_alloc_frozen_folio() dereferences the nodemask in node_isset(nid, *nodemask) and for_each_node_mask(node, *nodemask), leading to a null pointer dereference kernel panic when nodemask is NULL.
Fix this by checking if nodemask is NULL in hugetlb_cma_alloc_frozen_folio() and defaulting it to cpuset_current_mems_allowed. Enclose the allocation attempts within the cpuset seqcount retry loop so that if the cpuset changes concurrently during allocation, the attempts are retried using the updated nodemask. This ensures that the initial node check and fallback loop safely honor the task's cpuset without violating cpuset constraints or causing NULL pointer dereferences or unexpected allocation failures.
From a userspace perspective, this bug allows an unprivileged user to crash the kernel (trigger a panic) by requesting a gigantic hugepage allocation with MPOL_PREFERRED_MANY on a system where CMA is only configured on a subset of NUMA nodes.
This can be reproduced by booting a VM with two NUMA nodes, restricting CMA to Node 1 (e.g., hugetlb_cma=1:1G default_hugepagesz=1G hugepagesz=1G hugepages=0), and running a program that allocates a 1GB hugepage area without reserving, restricts allocation to Node 0 using mbind() with MPOL_PREFERRED_MANY, and triggers a page fault:
This results in a NULL pointer dereference:
Detalles técnicos trazas, registros y código del informe original
void *ptr = mmap(NULL, 1UL << 30, PROT_READ | PROT_WRITE,
MAP_PRIVATE | MAP_ANONYMOUS | MAP_HUGETLB |
MAP_HUGE_1GB | MAP_NORESERVE, -1, 0);
unsigned long nodemask = 1; /* Node 0 */
mbind(ptr, 1UL << 30, MPOL_PREFERRED_MANY, &nodemask,
sizeof(nodemask) * 8, 0);
memset(ptr, 0, 1UL << 30); /* Trigger fault */
BUG: kernel NULL pointer dereference, address: 0000000000000000
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
Oops: Oops: 0000 [#1] SMP NOPTI
RIP: 0010:hugetlb_cma_alloc_frozen_folio+0x75/0x120
Call Trace:
<TASK>
only_alloc_fresh_hugetlb_folio.isra.0+0x2c/0x160
alloc_surplus_hugetlb_folio+0x6d/0x100
alloc_hugetlb_folio+0x3c5/0x660
hugetlb_no_page+0x3d9/0x650CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.20%
- Percentil entre todas las CVEs puntuadas: 9
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-89966",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "eb02f14c4a2bf4c242d91c4a5d7fb57c3c0ad1b1",
"lessThan": "10f616ef06c5bd2d656a0eebaf73f9b09d150c24",
"versionType": "git"
},
{
"status": "affected",
"version": "eb02f14c4a2bf4c242d91c4a5d7fb57c3c0ad1b1",
"lessThan": "7b8a8ae4dd176a232e973017d2aa3c536a7275e2",
"versionType": "git"
}
],
"programFiles": [
"mm/hugetlb_cma.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.19"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.19",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "7.2.5",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"mm/hugetlb_cma.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-16T11:17:07.160",
"references": [
{
"url": "https://git.kernel.org/stable/c/10f616ef06c5bd2d656a0eebaf73f9b09d150c24",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/7b8a8ae4dd176a232e973017d2aa3c536a7275e2",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/hugetlb_cma: fix null nodemask dereference in hugetlb_cma_alloc_frozen_folio\n\nalloc_buddy_hugetlb_folio_with_mpol() can pass a NULL nodemask to\nalloc_fresh_hugetlb_folio() as a fallback to allocate from all nodes. If\norder is gigantic, alloc_fresh_hugetlb_folio() propagates the NULL\nnodemask down to hugetlb_cma_alloc_frozen_folio() via\nalloc_gigantic_frozen_folio().\n\nAdditionally, hugetlb_cma_alloc_frozen_folio() previously attempted\nallocation on hugetlb_cma[nid] without verifying if nid is included in the\ncaller's nodemask. Adding a node_isset(nid, *nodemask) check ensures the\ninitial preferred node allocation honors the memory policy / nodemask.\n\nHowever, hugetlb_cma_alloc_frozen_folio() dereferences the nodemask in\nnode_isset(nid, *nodemask) and for_each_node_mask(node, *nodemask),\nleading to a null pointer dereference kernel panic when nodemask is NULL.\n\nFix this by checking if nodemask is NULL in\nhugetlb_cma_alloc_frozen_folio() and defaulting it to\ncpuset_current_mems_allowed. Enclose the allocation attempts within the\ncpuset seqcount retry loop so that if the cpuset changes concurrently\nduring allocation, the attempts are retried using the updated nodemask. \nThis ensures that the initial node check and fallback loop safely honor\nthe task's cpuset without violating cpuset constraints or causing NULL\npointer dereferences or unexpected allocation failures.\n\nFrom a userspace perspective, this bug allows an unprivileged user to\ncrash the kernel (trigger a panic) by requesting a gigantic hugepage\nallocation with MPOL_PREFERRED_MANY on a system where CMA is only\nconfigured on a subset of NUMA nodes.\n\nThis can be reproduced by booting a VM with two NUMA nodes, restricting\nCMA to Node 1 (e.g., hugetlb_cma=1:1G default_hugepagesz=1G hugepagesz=1G\nhugepages=0), and running a program that allocates a 1GB hugepage area\nwithout reserving, restricts allocation to Node 0 using mbind() with\nMPOL_PREFERRED_MANY, and triggers a page fault:\n\n void *ptr = mmap(NULL, 1UL << 30, PROT_READ | PROT_WRITE,\n MAP_PRIVATE | MAP_ANONYMOUS | MAP_HUGETLB |\n MAP_HUGE_1GB | MAP_NORESERVE, -1, 0);\n unsigned long nodemask = 1; /* Node 0 */\n mbind(ptr, 1UL << 30, MPOL_PREFERRED_MANY, &nodemask,\n sizeof(nodemask) * 8, 0);\n memset(ptr, 0, 1UL << 30); /* Trigger fault */\n\nThis results in a NULL pointer dereference:\n\n BUG: kernel NULL pointer dereference, address: 0000000000000000\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n Oops: Oops: 0000 [#1] SMP NOPTI\n RIP: 0010:hugetlb_cma_alloc_frozen_folio+0x75/0x120\n Call Trace:\n <TASK>\n only_alloc_fresh_hugetlb_folio.isra.0+0x2c/0x160\n alloc_surplus_hugetlb_folio+0x6d/0x100\n alloc_hugetlb_folio+0x3c5/0x660\n hugetlb_no_page+0x3d9/0x650"
}
],
"lastModified": "2026-09-16T11:17:07.160",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}