Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-80893— mm/hugetlb: fix swap entry corruption when clearing uffd-wp at fork()

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会开源的一个操作系统内核。 Linux kernel存在安全漏洞,该漏洞源于mm/hugetlb中copy_hugetlb_page_range()函数在fork()时使用huge_pte_clear_uffd_wp()清除迁移条目和hwpoison条目的uffd-wp位,该操作作用于普通PTE位位置,导致交换条目中编码的PFN偏移两个页面,可能破坏复制到子进程的页表条目。

AI Predicted 5.5 Difficulty: Moderate EPSS 0.17% · P7

Possible ATT&CK Techniques 1 AI

T1069 · Permission Groups Discovery

Affected Version Matrix 14

VendorProduct Version RangeStatus
Linux Linux bc70fbf269fdff410b0b6d75c3770b9f59117b90< f1b1311c0352873137768bac5a126e491271a747 affected
bc70fbf269fdff410b0b6d75c3770b9f59117b90< 69cb5825d9988c7944bc9f1dc08cb233655405a7 affected
bc70fbf269fdff410b0b6d75c3770b9f59117b90< 8b0de7005b148738d79d6c45594d566489948a68 affected
bc70fbf269fdff410b0b6d75c3770b9f59117b90< 2b9a07002c2f296aa6a9c591213933d3492e3089 affected
bc70fbf269fdff410b0b6d75c3770b9f59117b90< 2fa11c60c9c06bafc19cf4d9efdaa36a38079e87 affected
bc70fbf269fdff410b0b6d75c3770b9f59117b90< 83abe2fd5b3aeb3123b5408a5a91709c5538fb23 affected
5.19 affected
< 5.19 unaffected
… +6 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-80893

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
mm/hugetlb: fix swap entry corruption when clearing uffd-wp at fork()
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix swap entry corruption when clearing uffd-wp at fork() copy_hugetlb_page_range() clears the uffd-wp bit of migration and hwpoison entries with huge_pte_clear_uffd_wp(), which operates on the present-PTE bit position. Swap entries keep the uffd-wp state elsewhere -- the migration branch reads and sets it with pte_swp_uffd_wp() and pte_swp_mkuffd_wp() -- and the present-PTE position falls into the swap payload. On x86-64 it lands in the inverted swap offset, where a naturally-aligned hugetlb PFN always has the affected bit set, so the clear advances the encoded PFN by two pages. No userfaultfd needs to be involved: the clear is guarded only by the child VMA not being uffd-wp registered, so a plain fork() with an in-flight hugetlb migration entry (or a poisoned hugetlb page) corrupts the entry copied into the child. Instrumenting the clear and forking after MADV_HWPOISON on a 2MB anon hugetlb page shows: offset before=120e00 offset after =120e02 The fallout is mostly latent: rmap walks match migration entries by folio range and remove_migration_pte() rebuilds the PTE from the folio, so a within-folio PFN skew heals once migration completes. But any path that re-encodes the corrupted offset -- e.g. hugetlb_change_protection() rewriting a writable migration entry via make_readable_migration_entry(swp_offset(entry)) -- propagates it. Migration entries legitimately carry uffd-wp, so clear it with pte_swp_clear_uffd_wp(), matching copy_nonpresent_pte() and move_huge_pte(). A hwpoison entry, on the other hand, never carries the uffd-wp bit: it is installed fresh by make_hwpoison_entry() (try_to_unmap_one() does not preserve uffd-wp on the hwpoison path) and hugetlb_change_protection() leaves hwpoison entries untouched. There was nothing to clear there, only the corruption, so drop the clear entirely.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会开源的一个操作系统内核。 Linux kernel存在安全漏洞,该漏洞源于mm/hugetlb中copy_hugetlb_page_range()函数在fork()时使用huge_pte_clear_uffd_wp()清除迁移条目和hwpoison条目的uffd-wp位,该操作作用于普通PTE位位置,导致交换条目中编码的PFN偏移两个页面,可能破坏复制到子进程的页表条目。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux bc70fbf269fdff410b0b6d75c3770b9f59117b90 ~ f1b1311c0352873137768bac5a126e491271a747 -
Linux Linux 5.19 -

II. Public POCs for CVE-2026-80893

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-80893

登录查看更多情报信息。

Patches & Fixes for CVE-2026-80893 (5)

Other References for CVE-2026-80893 (1)

Same Patch Batch · Linux · 2026-09-04 · 156 CVEs total

CVE-2026-80864 RDMA/rxe: Fix responder UAF on IB_QP_MAX_DEST_RD_ATOMIC modify_qp
CVE-2026-80855 fuse: fix invalidate lock leak on open O_TRUNC DAX failure
CVE-2026-80856 fuse: fix invalidate lock leak on setattr writeback failure
CVE-2026-80857 fuse: wait for FR_FINISHED on abort_on_kill to prevent use-after-free
CVE-2026-80858 fuse: publish io-uring queues with release semantics
CVE-2026-80859 fuse: fix missing barrier when checking io-uring readiness
CVE-2026-80860 fuse: fix race between interrupt and resend
CVE-2026-80861 usb: xhci: bail out of setup if the controller is inaccessible
CVE-2026-80862 nvme-tcp: fix usage of page_frag_cache
CVE-2026-80863 RDMA/rxe: Fix OOB in free_rd_atomic_resources()
CVE-2026-80869 ntfs: bound the attribute-list entry in ntfs_read_inode_mount()
CVE-2026-80873 KVM: arm64: nv: Write ESR_EL2 for injected nested SError exceptions
CVE-2026-80872 ALSA: hda/tas2781: Cancel async firmware request at unbind
CVE-2026-80871 crypto: xilinx-trng - Remove crypto_rng interface
CVE-2026-80870 drm/amdkfd: Validate CRIU-restored IDs before idr_alloc
CVE-2026-80867 alpha/PCI: Add security_locked_down() check to pci_mmap_resource()
CVE-2026-80865 bpf: Add missing access_ok call to copy_user_syms
CVE-2026-80866 tipc: avoid busy looping in tipc_exit_net()
CVE-2026-80854 usb: gadget: f_tcm: keep port count until LUN teardown completes
CVE-2026-80868 ntfs3: Allocate iomap inline_data using alloc_page

Showing top 20 of 156 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-80893

No comments yet


Leave a comment