CVE-2026-80719

Source
https://cve.org/CVERecord?id=CVE-2026-80719
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80719.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-80719
Downstream
Published
2026-08-28T06:53:16.087Z
Modified
2026-08-29T03:47:17.228927313Z
Summary
mm: mglru: fix stale batch updates after memcg reparenting
Details

In the Linux kernel, the following vulnerability has been resolved:

mm: mglru: fix stale batch updates after memcg reparenting

The mglru page table walker batches per-generation size deltas in walk->nrpages while walking page tables without holding the lruvec lock. The resetbatch_size() later folds those deltas into walk->lruvec under the lruvec lock.

The page table walker can run concurrently with the memcg reparenting path as follows:

CPU0 CPU1 ==== ====

walkmm --> walkpagerange --> updatebatchsize --> walk->nrpages += delta

                          mem_cgroup_css_offline
                          --> memcg_reparent_objcgs
                              --> lock lruvec
                                  lru_gen_reparent_memcg
                                  --> reparent child folios to parent
                                  unlock lruvec

lock lruvec
reset_batch_size
--> child lrugen->nr_pages += delta

This will trigger the following warning in lrugenexit_memcg():

VM_WARN_ON_ONCE(memchr_inv(lruvec->lrugen.nr_pages, 0,
               sizeof(lruvec->lrugen.nr_pages)));

And the user-visible impact of underestimated nrpages in MGLRU was premature OOMs because MGLRU does not try to reclaim memory when nrpages reaches zero, but there are still more pages.

To fix it, make resetbatchsize() check CSS_DYING under RCU before flushing the pending batch. A non-dying memcg keeps the original lruvec stable against RCU-delayed offlining; a dying memcg redirects the deltas to the first non-dying ancestor.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80719.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
f304652609eae3814b0e9d11c75c0e0cb62da31f
Fixed
fceb6b7f3ddec6ea9fc11577f4cf1b2da73a3101
Fixed
de4660898b7aa7e03d3b120a6bfa6b26211e4e77

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80719.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
7.1.0
Fixed
7.1.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80719.json"