Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-74599— mm/ptdump: always stabilise against page table freeing using init_mm

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,已解决以下漏洞: mm/ptdump:始终通过使用 init_mm 来防止页面表被释放时的竞态条件 先前的提交已确立一个不变式:内核页面表的释放操作是在持有对 的 mmap 读锁期间执行的。这修复了 与内核页面表释放之间关于 的竞态条件。 然而,x86 和 arm64 架构可以通过 对除 以外的其他内存描述符(mm)执行 ptdump 操作。由于内核内存范围在非内核 mm 之间是共享的,这意味着在这些情况下竞态条件仍然存在。 通过在 中获取 的嵌套 mmap 写锁来解决此问题。 这是安全的,

AI Predicted 5.5 Difficulty: Moderate EPSS 0.21% · P11

Possible ATT&CK Techniques 2 AI

T1003 · OS Credential Dumping T1179

Affected Version Matrix 24

VendorProduct Version RangeStatus
Linux Linux b6bdb7517c3d3f41f20e5c2948d6bc3f8897394e< 3c0391b9a774cc0854f3152e484a9d4835b12b40 affected
b6bdb7517c3d3f41f20e5c2948d6bc3f8897394e< cbd9583bb6f70733d0022a66d3546a15c76ae744 affected
b6bdb7517c3d3f41f20e5c2948d6bc3f8897394e< 76df4edf7d61ecb711bc517ff4c20a5e85c4e9f7 affected
b6bdb7517c3d3f41f20e5c2948d6bc3f8897394e< b9c6d048bdfaae78d7d921b454f7de7baefaa2f0 affected
b6bdb7517c3d3f41f20e5c2948d6bc3f8897394e< 7f740664aec1f832953c2e6d9b8920cd6c8bcc0c affected
b6bdb7517c3d3f41f20e5c2948d6bc3f8897394e< 4adc4c9a9a43d61fe476dfe10811f3df2e7e4106 affected
b6bdb7517c3d3f41f20e5c2948d6bc3f8897394e< 27c32e5538344b13c1505a08861e04620c125d47 affected
31895cfd79564111cdd5a9f48c5d491ae26a238e affected
… +16 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-74599

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
mm/ptdump: always stabilise against page table freeing using init_mm
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: mm/ptdump: always stabilise against page table freeing using init_mm Previous commits have established the invariant that kernel page table freeing is performed while an mmap read lock on init_mm is held, which fixes races between ptdump and kernel page table freeing over init_mm. However, x86 and arm64 can perform a ptdump over an mm other than init_mm via ptdump_walk_pgd() and since kernel memory ranges are shared across non-kernel mm's, this means that the race still exists for these cases. Fix this by acquiring a nested mmap write lock for init_mm in ptdump_walk_pgd(). This is safe as we take this after mmap write locking the mm, and nothing acquires the init_mm lock first before locking an arbitrary mm, so no deadlock is possible. Also update walk_page_range_debug() to assert that init_mm is write locked, add a comment explaining why and remove some redundant code, and eliminate the unnecessary and confusing invocation of walk_kernel_page_table_range(). We can safely remove the non-NULL check for walk.mm, as the mmap lock asserts would NULL pointer deref if it was (and of course no callers do this). The first point at which ptdump can race kernel page table freeing is commit b6bdb7517c3d ("mm/vmalloc: add interfaces to free unmapped page table"), so we target this in the Fixes tag.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux b6bdb7517c3d3f41f20e5c2948d6bc3f8897394e ~ 3c0391b9a774cc0854f3152e484a9d4835b12b40 -
Linux Linux 4.16 -

II. Public POCs for CVE-2026-74599

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-74599

登录查看更多情报信息。

Patches & Fixes for CVE-2026-74599 (7)

Same Patch Batch · Linux · 2026-08-22 · 150 CVEs total

CVE-2026-74705 10.0 CRITICAL udp: fix potential use-after-free in tunnel segmentation
CVE-2026-74612 10.0 CRITICAL veth: fix skb length accounting after XDP frag adjustment
CVE-2026-74617 9.8 CRITICAL dibs: initialise dibs->lock in dibs_dev_alloc()
CVE-2026-74591 9.8 CRITICAL mm/filemap: __filemap_add_folio() restore index before retrying
CVE-2026-74662 9.8 CRITICAL inet: frags: publish queues before arming timer
CVE-2026-74628 9.8 CRITICAL net/x25: fix use-after-free of the socket by its timers
CVE-2026-74611 9.8 CRITICAL tls: rx: restore msg_iter before TLS 1.3 optimistic retry
CVE-2026-74669 9.8 CRITICAL ipvs: clear IPv4 options after rebasing tunnel ICMP errors
CVE-2026-74587 9.8 CRITICAL sctp: fix use-after-free of cached ASCONF chunk
CVE-2026-74588 9.8 CRITICAL sctp: keep chunk->transport in step with the list it is queued on
CVE-2026-74586 9.8 CRITICAL sctp: clear new_transport when removing a peer
CVE-2026-74730 9.8 CRITICAL NFS: Pin the 'struct nfs_server' during a FREE_STATEID call
CVE-2026-74616 9.8 CRITICAL xdp: reject clones that overrun skb_shared_info tailroom
CVE-2026-74727 9.8 CRITICAL ovpn: skip rehash for peers already removed from by_id
CVE-2026-74608 9.8 CRITICAL smb: client: Fix use-after-free in cifs_try_adding_channels()
CVE-2026-74688 9.8 CRITICAL sctp: clear control chunk transport if it is being removed
CVE-2026-74723 9.8 CRITICAL btrfs: lzo: reject inline extents without valid headers
CVE-2026-74597 9.8 CRITICAL ip6_tunnel: clear skb2->cb[] in ip6ip6_err()
CVE-2026-74712 9.3 CRITICAL vdpa/mlx5: Fix buffer length in create_direct_keys()
CVE-2026-74665 9.1 CRITICAL net: fix skb length accounting after generic XDP frag adjustment

Showing top 20 of 150 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-74599

No comments yet


Leave a comment