In the Linux kernel, the following vulnerability has been resolved:
mm/util: don't read __page2 for order-1 folios in snapshotpage()
snapshot_page() currently reads _page2 after checking nrpages > 1, but it should only do so when nrpages > 2.
If an order-1 folio is allocated at the end of a vmemmap section, _page2 will not exist and reading it will cause a fault.
During DLPAR memory remove on a 22 TB ppc64le LPAR, snapshot_page() oopsed on the page isolation path while reading an order-1 folio's _page2 from an adjacent absent section (unmapped vmemmap).
Fix this to avoid reading memmap that doesn't exist (e.g., a vmemmap hole).
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80685.json",
"cna_assigner": "Linux"
}