CVE-2026-97942
In the Linux kernel, the following vulnerability has been resolved:
x86/alternatives: Exclude text poking against change_page_attr()
From time to time, the following BUG can be observed in the x86 alternatives patching code [0]:
which matches the following BUG_ON() in alternative.c:
/* * If something went wrong, crash and burn since recovery paths are not * implemented. */ BUG_ON(!pages[0] || (cross_page_boundary && !pages[1]));
This can happen if vmalloc_to_page() fails, for any reason. Such can happen if text poking races with CPA, which can possibly result in the collapsing of page tables (or breaking of PMD hugepages).
Leer descripción completaMostrar menos
It is not a problem for most users of vmalloc_to_page() (they solely own the vmalloc'd range) but, when CONFIG_ARCH_HAS_EXECMEM_ROX=y, various modules own a single execmem vmalloc range, and can call set_memory_*() in parallel on it. This can happen to race against __text_poke and cause havoc in vmalloc_to_page().
Fix it by excluding against CPA using the init_mm mmap read lock.
[ dhansen: Fix up SoB ordering. The actual code flow here was: Pedro=>Lorenzo=>Mike=>Me which is reflected in the SoB chain now. I *believe* Mike simply picked up Lorenzo's update to Pedro's post from the Link ]
Detalles técnicos trazas, registros y código del informe original
> kernel BUG at arch/x86/kernel/alternative.c:2576! > Oops: invalid opcode: 0000 [#1] SMP NOPTI > CPU: 0 UID: 0 PID: 355 Comm: (udev-worker) Not tainted 7.1.3-1-default #1 PREEMPT(full) openSUSE Tumbleweed 8c1795b03ec64f997e57a8ad38b1161e3b98da64 > Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS unknown 02/02/2022 > RIP: 0010:__text_poke+0x2aa/0x450 > Call Trace: > <TASK> > smp_text_poke_batch_finish+0x2a7/0x320 > __static_call_transform+0xb7/0x220 > arch_static_call_transform+0x5b/0xb0 > __static_call_init+0xe9/0x270 > static_call_module_notify+0x11f/0x150 > notifier_call_chain+0x61/0xe0 > blocking_notifier_call_chain_robust+0x63/0xc0 > load_module+0x1c92/0x20c0 > init_module_from_file+0xd8/0x140 > idempotent_init_module+0x100/0x2f0 > __x64_sys_finit_module+0x71/0xe0 > do_syscall_64+0xe1/0x610 > entry_SYSCALL_64_after_hwframe+0x76/0x7e
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.20%
- Percentil entre todas las CVEs puntuadas: 9
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-97942",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "64f6a4e10c05ed527f0f24b7954964255e0d3535",
"lessThan": "281e6f536f2f3f95d91938c5bd7ba9bcb4c1049d",
"versionType": "git"
},
{
"status": "affected",
"version": "64f6a4e10c05ed527f0f24b7954964255e0d3535",
"lessThan": "89c60435b90d32ab5e3a39da3ae73d463d07debe",
"versionType": "git"
},
{
"status": "affected",
"version": "64f6a4e10c05ed527f0f24b7954964255e0d3535",
"lessThan": "1587d3394e254639cc36516256031334095e6ef3",
"versionType": "git"
}
],
"programFiles": [
"arch/x86/kernel/alternative.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.15"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.15",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.18.53",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.7",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc4",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"arch/x86/kernel/alternative.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-25T11:17:21.633",
"references": [
{
"url": "https://git.kernel.org/stable/c/1587d3394e254639cc36516256031334095e6ef3",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/281e6f536f2f3f95d91938c5bd7ba9bcb4c1049d",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/89c60435b90d32ab5e3a39da3ae73d463d07debe",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/alternatives: Exclude text poking against change_page_attr()\n\nFrom time to time, the following BUG can be observed\nin the x86 alternatives patching code [0]:\n\n > kernel BUG at arch/x86/kernel/alternative.c:2576!\n > Oops: invalid opcode: 0000 [#1] SMP NOPTI\n > CPU: 0 UID: 0 PID: 355 Comm: (udev-worker) Not tainted 7.1.3-1-default #1 PREEMPT(full) openSUSE Tumbleweed 8c1795b03ec64f997e57a8ad38b1161e3b98da64\n > Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS unknown 02/02/2022\n > RIP: 0010:__text_poke+0x2aa/0x450\n > Call Trace:\n > <TASK>\n > smp_text_poke_batch_finish+0x2a7/0x320\n > __static_call_transform+0xb7/0x220\n > arch_static_call_transform+0x5b/0xb0\n > __static_call_init+0xe9/0x270\n > static_call_module_notify+0x11f/0x150\n > notifier_call_chain+0x61/0xe0\n > blocking_notifier_call_chain_robust+0x63/0xc0\n > load_module+0x1c92/0x20c0\n > init_module_from_file+0xd8/0x140\n > idempotent_init_module+0x100/0x2f0\n > __x64_sys_finit_module+0x71/0xe0\n > do_syscall_64+0xe1/0x610\n > entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nwhich matches the following BUG_ON() in alternative.c:\n\n\t/*\n\t * If something went wrong, crash and burn since recovery paths are not\n\t * implemented.\n\t */\n\tBUG_ON(!pages[0] || (cross_page_boundary && !pages[1]));\n\nThis can happen if vmalloc_to_page() fails, for any reason. Such can happen\nif text poking races with CPA, which can possibly result in the collapsing\nof page tables (or breaking of PMD hugepages). It is not a problem for most\nusers of vmalloc_to_page() (they solely own the vmalloc'd range) but, when\nCONFIG_ARCH_HAS_EXECMEM_ROX=y, various modules own a single execmem vmalloc\nrange, and can call set_memory_*() in parallel on it. This can happen to\nrace against __text_poke and cause havoc in vmalloc_to_page().\n\nFix it by excluding against CPA using the init_mm mmap read lock.\n\n[ dhansen: Fix up SoB ordering. The actual code flow here was:\n\t Pedro=>Lorenzo=>Mike=>Me which is reflected in the SoB chain\n\t now. I *believe* Mike simply picked up Lorenzo's update to\n\t Pedro's post from the Link ]"
}
],
"lastModified": "2026-09-25T11:17:21.633",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}