Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-97525— x86/mm/pat: Allocate split page tables as kernel page tables

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,已修复以下漏洞: x86/mm/pat:将拆分页表作为内核页表进行分配 当 CPA(当前页属性)代码执行大页拆分( )时,PTE 是直接分配的,而未经过标准的页表分配例程(如 )。 这意味着页表构造函数永远不会被调用,页表也不会被标记为内核页表。 前者导致与该页表关联的 folio 未被标记为页表(因为从未调用 ,因此也未调用 ),同时统计信息也未更新以反映这一事实(未调用 )。 后者问题——未能将页表标记为内核页表(从未调用 )——更为严重。 自以下提交以来: ("mm: introduc

CVSS 8.2 · High EPSS 0.17% · P5

Affected Version Matrix 9

VendorProduct Version RangeStatus
Linux Linux b3039c526f3e1744db0cbb7ae1f0213f5e27d3f4< 84e0cd79d57f06b872154eb5d8f610584133f260 affected
5ba2f0a1556479638ac11a3c201421f5515e89f5< 922873cf4fc34124215070a8ad391bf831538bb9 affected
5ba2f0a1556479638ac11a3c201421f5515e89f5< 9e4a3ec3411bb6bb59e3c1f29b75609f1e87aac4 affected
6.18.7< 6.18.53 affected
6.19 affected
< 6.19 unaffected
6.18.53≤ 6.18.* unaffected
7.2.7≤ 7.2.* unaffected
… +1 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-97525

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
x86/mm/pat: Allocate split page tables as kernel page tables
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: x86/mm/pat: Allocate split page tables as kernel page tables A PTE is allocated directly without going through the standard page table allocation routines (such as pte_alloc_one_kernel()) when the CPA code splits a large page (__split_large_page()). This means the page table constructor is never called nor is the page table marked as a kernel page table. The former results in the folio associated with the page table not being marked as a page table (__pagetable_ctor() is never called thus neither is __folio_set_pgtable()) nor are statistics updated to reflect it (lruvec_stat_add_folio() is never called). The latter issue of failing to mark the page table as a kernel page table (ptdesc_set_kernel() is never called) is far more problematic. Since commit: 5ba2f0a15564 ("mm: introduce deferred freeing for kernel page tables") kernel page table freeing has been batched and since the subsequent commit: e37d5a2d60a3 ("iommu/sva: invalidate stale IOTLB entries for kernel address space") IOTLB cache entries for kernel page tables have been invalidated upon being freed. Since split page tables are freed without this invalidation, the IOTLB can contain stale entries for them. Resolve the issue by using the ordinary PTE allocation API at split time. This results in these kernel page tables invoking a page table constructor, and thus requires a page table destructor. Destructors are not always present, like for early allocated direct map page tables). Conditionally call pagetable_dtor_free() if the PG_table folio flag for the ptdesc is set, otherwise we free the page table via pagetable_free(). Regardless of which path is taken page tables marked as kernel page tables, which now includes split page tables, take the correct route through pagetable_free_kernel(). There is a user-visible side effect in that split page tables will appear in nr_page_table_pages in /proc/vmstat (as do other kernel page tables allocated after early boot), however this is a positive change. This issue started being markedly problematic after commit: 5ba2f0a15564 ("mm: introduce deferred freeing for kernel page tables") so choose this as the Fixes target. [ dhansen: rephrase in imperative mood ]
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux b3039c526f3e1744db0cbb7ae1f0213f5e27d3f4 ~ 84e0cd79d57f06b872154eb5d8f610584133f260 -
Linux Linux 6.19 -

II. Public POCs for CVE-2026-97525

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-97525

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-97525 (3)

Same Patch Batch · Linux · 2026-09-25 · 372 CVEs total

CVE-2026-100075 9.8 CRITICAL RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters
CVE-2026-97957 8.8 HIGH net: hinic: fix mailbox segment buffer overflow
CVE-2026-97527 8.8 HIGH scsi: qla2xxx: Serialize NVMe unsol ctx list with a per-fcport lock
CVE-2026-97528 8.8 HIGH scsi: qla2xxx: Unlink NVMe unsol ctx before freeing on LS reject error
CVE-2026-97555 8.8 HIGH smb: client: fix heap overflow in DACL owner/group rewrite
CVE-2026-98115 8.8 HIGH ksmbd: safely drain sessions during logoff
CVE-2026-97573 8.1 HIGH bnxt_en: Handle buffer allocation failure in bnxt_rx_ring_reset()
CVE-2026-97570 8.1 HIGH bnxt_en: Bound SW TPA IDs to prevent crashes
CVE-2026-98070 8.1 HIGH net/rds: acquire RDS_IN_XMIT in rds_tcp_reset_callbacks()
CVE-2026-98069 8.1 HIGH net/rds: acquire the fastpath locks in rds_conn_shutdown()
CVE-2026-98130 8.1 HIGH sctp: fix a TOCTOU race in SCTP_CMD_TIMER_START
CVE-2026-97578 7.8 HIGH media: verisilicon: rockchip: guard VPU981 AV1 divisor and tile buffer
CVE-2026-97548 7.8 HIGH xfs: fix the rtrmap and rtrefcount _maxlevels_ondisk functions
CVE-2026-98052 7.8 HIGH net: bcmasp: clear txcb->last before writing each descriptor
CVE-2026-97611 7.8 HIGH net: openvswitch: fix use-after-free of the flow table mask array
CVE-2026-97612 7.8 HIGH net: mpls: clear inner_protocol when the last label is popped
CVE-2026-98073 7.8 HIGH net: Remove conflicting altnames for dying netns in __dev_change_net_namespace().
CVE-2026-97602 7.8 HIGH inet: frags: invalidate queues before flushing them
CVE-2026-98112 7.8 HIGH ksmbd: fix listener task lifetime on netdev events
CVE-2026-97579 7.8 HIGH media: mediatek: vcodec: bound AV1 tile-start copy to the array capacity

Showing top 20 of 372 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-97525

No comments yet


Leave a comment