VDB

CVE-2026-89593

CVE-2026-89593 PUBLISHED CVSS 7.1 HIGH

Reported by Linux · Published September 11, 2026

In the Linux kernel, the following vulnerability has been resolved: hugetlb: only adjust reservation during unmapping if mapcount is 0 Since df7a6d1f6405, __unmap_hugepage_range can adjust reservations. In the case of folio mapped in both a parent and a child, if the parent unmaps the range first, the reservation adjustment will result in an underflow of the reserved count. Once the child unmaps the range, the count is restored. Change __unmap_hugepage_range() to check the mapcount before adjusting the reservation.

EPSS 0.12% · 2.5th percentile

Risk Scores

CVSS 3.1
7.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
EPSS Score
0.12%
2.5th percentile

Affected Products

VendorProductVersions
LinuxLinuxdf7a6d1f64056aec572162c5d35ed9ff86ece6f3, df7a6d1f64056aec572162c5d35ed9ff86ece6f3, df7a6d1f64056aec572162c5d35ed9ff86ece6f3
LinuxLinux6.9, 0, 6.12.110
LinuxLinux7.3-rc1, 7.3-rc1, df7a6d1f64056aec572162c5d35ed9ff86ece6f3
linuxlinux_kernel6.9, 6.9, 6.9

Timeline

  • Sep 11, 2026 Coalition ESS Score
  • Sep 11, 2026 CVE Published
  • Sep 12, 2026 EPSS Score
  • Sep 13, 2026 EPSS Score
  • Sep 14, 2026 CVE Updated
  • Sep 15, 2026 EPSS Score

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›