In the Linux kernel, the following vulnerability has been resolved:
x86/mm: Fix freeing of PMD-sized vmemmap pages
Commit bf9e4e30f353 ("x86/mm: use pagetable_free()"), switched from freeing non-boot page tables through __freepages() to pagetablefree().
However, the function is also called to free vmemmap pages.
Given that vmemmap pages are not page tables, already the pageptdesc(page) is wrong. But worse, pagetablefree() calls:
__free_pages(page, compound_order(page));
Since vmemmap pages are not compound pages (see vmemmapallocblock()) -- except for HVO, which doesn't apply here -- only first page of a PMD-sized vmemmap page is freed, leaking the other ones.
Fix it by properly decoupling pagetable and vmemmap freeing. freepagetable() no longer has to mess with SECTIONINFO, as only the vmemmap is marked like that in registerpagebootmem_memmap().
The indentation in removepmdtable() is messed up. Fix that while touching it.
Bootmem info handling will soon be fixed up. For now, handle it similar to free_pagetable(), just avoiding the ifdef.
[ dhansen: changelog munging. More imperative voice ]
{
"cna_assigner": "Linux",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64302.json"
}