CVE-2026-74599
CVE CVE-2026-74599EUVD EUVD-2026-64536Veröffentlicht 2026-08-22T15:31:48.000ZZuletzt geändert 2026-08-23T12:47:39.000Z
Was das Advisory beschreibt
In the Linux kernel, the following vulnerability has been resolved: mm/ptdump: always stabilise against page table freeing using init_mm Previous commits have established the invariant that kernel page table freeing is performed while an mmap read lock on init_mm is held, which fixes races between ptdump and kernel page table freeing over init_mm. However, x86 and arm64 can perform a ptdump over an mm other than init_mm via ptdump_walk_pgd() and since kernel memory ranges are shared across non-kernel mm's, this means that the race still exists for these cases. Fix this by acquiring a nested mmap write lock for init_mm in ptdump_walk_pgd(). This is safe as we take this after mmap write locking the mm, and nothing acquires the init_mm lock first before locking an arbitrary mm, so no deadlock is possible. Also update walk_page_range_debug() to assert that init_mm is write locked, add a comment explaining why and remove some redundant code, and eliminate the unnecessary and confusing invocation of walk_kernel_page_table_range(). We can safely remove the non-NULL check for walk.mm, as the mmap lock asserts would NULL pointer deref if it was (and of course no callers do this). The first point at which ptdump can race kernel page table freeing is commit b6bdb7517c3d ("mm/vmalloc: add interfaces to free unmapped page table"), so we target this in the Fixes tag.
Quelle: EUVD (ENISA), im Wortlaut der Meldung.
Produkte, die das Advisory nennt
Diese Angaben stammen aus der Meldung selbst, nicht aus einer Prüfung durch uns.
- Linux — Linux b6bdb7517c3d3f41f20e5c2948d6bc3f8897394e <76df4edf7d61ecb711bc517ff4c20a5e85c4e9f7; 4.15.14 <4.16; patch: 6.12.105; b6bdb7517c3d3f41f20e5c2948d6bc3f8897394e <cbd9583bb6f70733d0022a66d3546a15c76ae744; acdb4981644c8e31ccee294bdefff475c0cf587b; 4.9.91 <4.10; patch: 7.1.9; b6bdb7517c3d3f41f20e5c2948d6bc3f8897394e <4adc4c9a9a43d61fe476dfe10811f3df2e7e4106; 0454e2fad9306961540ee7e84da47a8e345b7d22; patch: 5.10.266; b6bdb7517c3d3f41f20e5c2948d6bc3f8897394e <b9c6d048bdfaae78d7d921b454f7de7baefaa2f0; patch: 6.18.45; patch: 0; b6bdb7517c3d3f41f20e5c2948d6bc3f8897394e <3c0391b9a774cc0854f3152e484a9d4835b12b40; 4.4.125 <4.5; 31895cfd79564111cdd5a9f48c5d491ae26a238e; patch: 6.6.153; 4.14.31 <4.15; b6bdb7517c3d3f41f20e5c2948d6bc3f8897394e <27c32e5538344b13c1505a08861e04620c125d47; patch: 5.15.217; 9c7f7bdb1932f8c1e5f80d32c717184701afe701; 4.16; patch: 7.2; b6bdb7517c3d3f41f20e5c2948d6bc3f8897394e <7f740664aec1f832953c2e6d9b8920cd6c8bcc0c
Die genannten Versionen sind die Angabe der Meldung. Patchlage vergleicht keine Versionsnummern und leitet aus ihnen keine Aussage ab — welche Version installiert ist, muss ein Mensch nachsehen.
Im Produktkatalog geführt
Für diese Produkte kann ein Bestand in Patchlage erfasst werden. Ein Advisory dazu erscheint am Morgen danach im Lagebericht.
- Linux — Linux
Betrifft das einen Ihrer Kundenbestände?
Diese Seite kann die Frage nicht beantworten — sie kennt Ihren Bestand nicht. Wer seine Umgebungen erfasst hat, bekommt die Antwort am Morgen nach der Veröffentlichung, zusammen mit einem Absatz, den er unverändert an den Kunden weitergeben kann.
28 Tage testenPatchlage meldet Treffer und Verdachtsfälle. Zu allem anderen sagt dieses System nichts — weder diese Seite noch der Lagebericht behauptet je, dass ein Bestand sicher ist.