CVE-2026-72174
Last modified
CVE-2026-72174 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: fs/proc/task_mmu: fix hugetlb self-deadlock in pagemap_scan_pte_hole() A PAGEMAP_SCAN ioctl requesting PM_SCAN_WP_MATCHING on a hugetlb VMA hangs the calling thread, unkillably, as soon as the scan reaches an unpopulated part of the range: do_pagemap_scan() walk_page_range() walk_hugetlb_range() hugetlb_vma_lock_read() # take the vma lock for read ... pagemap_scan_pte_hole() # ... ->pte_hole() for a hole uffd_wp_range() change_protection() hugetlb_change_protection() hugetlb_vma_lock_write() # ... EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: fs/proc/task_mmu: fix hugetlb self-deadlock in pagemap_scan_pte_hole() A PAGEMAP_SCAN ioctl requesting PM_SCAN_WP_MATCHING on a hugetlb VMA hangs the calling thread, unkillably, as soon as the scan reaches an unpopulated part of the range: do_pagemap_scan() walk_page_range() walk_hugetlb_range() hugetlb_vma_lock_read() # take the vma lock for read ... pagemap_scan_pte_hole() # ... ->pte_hole() for a hole uffd_wp_range() change_protection() hugetlb_change_protection() hugetlb_vma_lock_write() # ... and block taking it for write walk_hugetlb_range() holds the hugetlb vma lock for read across the whole walk. A present entry goes to ->hugetlb_entry(); an unpopulated one goes to ->pte_hole(), i.e. pagemap_scan_pte_hole(). To write-protect the hole that handler calls uffd_wp_range(), which on a hugetlb VMA reaches hugetlb_change_protection() and takes the same vma lock for write. The thread then blocks in down_write() waiting for the read lock it is itself holding. The populated path avoids this: pagemap_scan_hugetlb_entry() write-protects the entry inline under the page-table lock and never enters hugetlb_change_protection(). Do the same for holes. Fault in the page table and install the uffd-wp marker directly with make_uffd_wp_huge_pte() under the page-table lock, rather than routing through uffd_wp_range(). That is the same sequence hugetlb_change_protection() runs for an unpopulated entry, minus the vma write lock -- which is safe to skip because PMD sharing is disabled on uffd-wp VMAs (hugetlb_unshare_all_pmds() runs at registration), leaving nothing for that lock to serialise against.
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 52526ca7fdb905a768a93f8faa418e9b988fc34b, < a6ac03652d9edc30c2912037ac83beb42cc67f8e; >= 52526ca7fdb905a768a93f8faa418e9b988fc34b, < 43b987ed35be9be21a303d1036d4241fec9943df; >= 52526ca7fdb905a768a93f8faa418e9b988fc34b, < 18b8a9700610299819d21fd0ea85d24726d17f65; >= 52526ca7fdb905a768a93f8faa418e9b988fc34b, < e92d92bbafb264dc0518d52b846a3c07ed8d523f |
| Linux | Linux | 6.7 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-72174?
How severe is CVE-2026-72174?
How do I fix CVE-2026-72174?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-72169In the Linux kernel, the following vulnerability has been re…
- CVE-2026-7217A security vulnerability has been detected in Deepractice Pr…5.5
- CVE-2026-72170In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-72171In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-72172In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-72173In the Linux kernel, the following vulnerability has been re…
- CVE-2026-72175In the Linux kernel, the following vulnerability has been re…7.1
- CVE-2026-72176In the Linux kernel, the following vulnerability has been re…
- CVE-2026-72177In the Linux kernel, the following vulnerability has been re…
- CVE-2026-72178In the Linux kernel, the following vulnerability has been re…
- CVE-2026-72179In the Linux kernel, the following vulnerability has been re…
- CVE-2026-7218A vulnerability was detected in Totolink N300RT 3.4.0-B20250…7.3
Are you affected by CVE-2026-72174?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
