GHSA-h73p-49j7-j757HighCVSS 7.8

In the Linux kernel, the following vulnerability has been resolved: mm: hugetlb: fix UAF in...

Published
December 8, 2025
Last Modified
August 4, 2026

🔗 CVE IDs covered (1)

📋 Description

In the Linux kernel, the following vulnerability has been resolved:

mm: hugetlb: fix UAF in hugetlb_handle_userfault

The vma_lock and hugetlb_fault_mutex are dropped before handling userfault and reacquire them again after handle_userfault(), but reacquire the vma_lock could lead to UAF[1,2] due to the following race,

hugetlb_fault hugetlb_no_page /unlock vma_lock / hugetlb_handle_userfault handle_userfault / unlock mm->mmap_lock/ vm_mmap_pgoff do_mmap mmap_region munmap_vma_range /* clean old vma / / lock vma_lock again <--- UAF / / unlock vma_lock */

Since the vma_lock will unlock immediately after hugetlb_handle_userfault(), let's drop the unneeded lock and unlock in hugetlb_handle_userfault() to fix the issue.

[1] https://lore.kernel.org/linux-mm/[email protected]/ [2] https://lore.kernel.org/linux-mm/[email protected]/

🔗 References (7)