CVE-2026-64131

Source
https://cve.org/CVERecord?id=CVE-2026-64131
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64131.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-64131
Downstream
Published
2026-07-19T15:40:26.854Z
Modified
2026-07-21T03:47:50.666603994Z
Summary
mm/memory: fix spurious warning when unmapping device-private/exclusive pages
Details

In the Linux kernel, the following vulnerability has been resolved:

mm/memory: fix spurious warning when unmapping device-private/exclusive pages

Device private and exclusive entries are only supported for anonymous folios. This condition is tested in __migratedevicepages() and makedeviceexclusive() using foliotestanon(). However the unmap path tests this assumption using vmaisanonymous().

This is wrong because whilst anonymous VMAs can only contain folios where foliotestanon() is true the opposite relation does not hold. A folio for which foliotestanon() is true does not imply vmaisanonymous() is true. Such a condition can occur if for example a folio is part of a private filebacked mapping.

In this case vmaisanonymous() is false as the mapping is filebacked, but foliotestanon() may be true, thus permitting devices to migrate the folio to device private memory. This can lead to the following spurious warnings during process teardown:

[ 772.737706] ------------[ cut here ]------------ [ 772.739201] WARNING: mm/memory.c:1754 at unmappagerange.cold+0x26/0x18a, CPU#17: hmm-tests/2041 [ 772.742050] Modules linked in: testhmm nvidiauvm(O) nvidia(O) [ 772.743959] CPU: 17 UID: 0 PID: 2041 Comm: hmm-tests Tainted: G W O 7.0.0+ #387 PREEMPT(full) [ 772.747104] Tainted: [W]=WARN, [O]=OOTMODULE [ 772.748509] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.17.0-0-gb52ca86e094d-prebuilt.qemu.org 04/01/2014 [ 772.752117] RIP: 0010:unmappagerange.cold+0x26/0x18a [ 772.753780] Code: 7e fe ff ff 48 89 4c 24 78 4c 89 44 24 38 e8 f2 ff b1 00 48 8b 4c 24 78 4c 8b 44 24 38 48 8b 44 24 18 48 83 78 48 00 74 04 90 <0f> 0b 90 48 89 ca b8 ff ff 37 00 48 c1 ea 03 48 c1 e0 2a 80 3c 02 [ 772.759602] RSP: 0018:ffff888112607550 EFLAGS: 00010286 [ 772.761310] RAX: ffff88811bbf4dc0 RBX: dffffc0000000000 RCX: ffffea03e9bfffd8 [ 772.763583] RDX: 1ffff1102377e9c1 RSI: 0000000000000008 RDI: ffff88811bbf4e08 [ 772.765914] RBP: 0000000000000006 R08: ffff8881059f7448 R09: ffffed10224c0e68 [ 772.768184] R10: ffff888112607347 R11: 0000000000000001 R12: 0000000000000001 [ 772.770461] R13: ffffea03e9bfffc0 R14: ffff888112607908 R15: ffffea03e9bfffc0 [ 772.772782] FS: 00007f327caa2780(0000) GS:ffff888427b7d000(0000) knlGS:0000000000000000 [ 772.775328] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 772.777187] CR2: 00007f327ca89000 CR3: 00000001994d5000 CR4: 00000000000006f0 [ 772.779135] Call Trace: [ 772.779792] <TASK> [ 772.780317] ? dmirrorintervalinvalidate+0x1a3/0x290 [testhmm] [ 772.781873] ? vmnormalpage_pud+0x2b0/0x2b0 [ 772.782992] ? __rwlockinit+0x150/0x150 [ 772.784006] ? lockrelease+0x216/0x2b0 [ 772.785008] ? __mmunotifierinvalidaterangestart+0x505/0x6e0 [ 772.786522] ? lock_release+0x216/0x2b0 [ 772.787498] ? unmapsinglevma+0xb6/0x210 [ 772.788573] unmapvmas+0x27d/0x520 [ 772.789506] ? unmapsinglevma+0x210/0x210 [ 772.790607] ? masupdategap.part.0+0x620/0x620 [ 772.791834] unmapregion+0x19e/0x350 [ 772.792769] ? removevma+0x130/0x130 [ 772.793684] ? masallocnodes+0x1f2/0x300 [ 772.794730] vmscompletemunmapvmas+0x8c1/0xe20 [ 772.795926] ? unmapregion+0x350/0x350 [ 772.796917] dovmialignmunmap+0x36a/0x4e0 [ 772.798018] ? lockrelease+0x216/0x2b0 [ 772.799024] ? vmashrink+0x620/0x620 [ 772.799983] dovmimunmap+0x150/0x2c0 [ 772.800939] __vmmunmap+0x161/0x2c0 [ 772.801872] ? expanddownwards+0xd60/0xd60 [ 772.802948] ? clockevents_programevent+0x1ef/0x540 [ 772.804217] ? lockrelease+0x216/0x2b0 [ 772.805158] _x64sysmunmap+0x59/0x80 [ 772.805776] dosyscall64+0xfc/0x670 [ 772.806336] ? irqentryexit+0xda/0x580 [ 772.806976] entrySYSCALL64afterhwframe+0x4b/0x53 [ 772.807772] RIP: 0033:0x7f327cbb2717 [ 772.808323] Code: 73 01 c3 48 8b 0d f9 76 0d 00 f7 d8 64 89 01 48 83 c8 ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 b8 0b 00 00 00 0f 05 <48> 3d 01 f0 ff ---truncated---

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64131.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
999dad824c39ed14dee7c4412aae531ba9e74a90
Fixed
e81446b559db4c98a6c2c5e039ac9cb23658432e
Fixed
e7af1b15c884ed12bb69da11aec095045d861ee8
Fixed
a825691b804b35141aaf4eac91003a70846e316d
Fixed
2fff0cdd942261497fb8922a194b4da3315ae864
Fixed
52f72b3f8f6fa64abb71b711962b97f1f6aced1c
Fixed
be3f38d05cc5a7c3f13e51994c5dd043ab604d28

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64131.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.19.0
Fixed
6.1.176
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.143
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.93
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.34
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.0.11

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64131.json"