VDB
CVE-2026-89593
CVE-2026-89593
PUBLISHED
CVSS 7.1 HIGH
Reported by Linux · Published September 11, 2026
In the Linux kernel, the following vulnerability has been resolved: hugetlb: only adjust reservation during unmapping if mapcount is 0 Since df7a6d1f6405, __unmap_hugepage_range can adjust reservations. In the case of folio mapped in both a parent and a child, if the parent unmaps the range first, the reservation adjustment will result in an underflow of the reserved count. Once the child unmaps the range, the count is restored. Change __unmap_hugepage_range() to check the mapcount before adjusting the reservation.
EPSS 0.12% · 2.5th percentile
Risk Scores
CVSS 3.1
7.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
EPSS Score
0.12%
2.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | df7a6d1f64056aec572162c5d35ed9ff86ece6f3, df7a6d1f64056aec572162c5d35ed9ff86ece6f3, df7a6d1f64056aec572162c5d35ed9ff86ece6f3 |
| Linux | Linux | 6.9, 0, 6.12.110 |
| Linux | Linux | 7.3-rc1, 7.3-rc1, df7a6d1f64056aec572162c5d35ed9ff86ece6f3 |
| linux | linux_kernel | 6.9, 6.9, 6.9 |
Timeline
- Sep 11, 2026 Coalition ESS Score
- Sep 11, 2026 CVE Published
- Sep 12, 2026 EPSS Score
- Sep 13, 2026 EPSS Score
- Sep 14, 2026 CVE Updated
- Sep 15, 2026 EPSS Score