CVE-2026-93232

Source
https://cve.org/CVERecord?id=CVE-2026-93232
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93232.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-93232
Downstream
Published
2026-09-24T15:29:22Z
Modified
2026-09-25T03:48:53Z
Summary
mm/hugetlb: fix boot panic with CONFIG_DEBUG_VM and HVO bootmem pages
Details

In the Linux kernel, the following vulnerability has been resolved:

mm/hugetlb: fix boot panic with CONFIG_DEBUG_VM and HVO bootmem pages

Patch series "mm: Refactor bootmem gigantic hugepage allocation", v4.

This series is split out from the earlier larger series "mm: Generalize HVO for HugeTLB and device DAX" [1]. It collects the first 19 patches of that series as a standalone set of fixes and preparatory cleanups around bootmem HugeTLB handling, sparse initialization ordering, and related vmemmap setup.

The first patches fix a few bugs found while reviewing the existing code, including incorrect bootmem HVO handling, wrong vmemmap registration arguments, a powerpc compound-vmemmap tracking bug, and too-late initialization of gigantic bootmem HugeTLB struct pages.

The rest of the series reorders early memory initialization so the relevant zone state is available before sparse and HugeTLB boot-time setup runs, then simplifies the remaining bootmem gigantic hugepage allocation path and removes code made obsolete by that rework.

At a high level:

  • patches [1-4] fix boot-time and arch-specific bugs
  • patches [5-12] reorder and simplify sparse/mm/hugetlb early init
  • patches [13-19] refactor bootmem gigantic hugepage allocation and remove obsolete helpers and state

This patch (of 19):

Commit 622026e87c40 ("mm/hugetlb: remove fake head pages") switched HVO to reuse per-zone shared tail pages from zone->vmemmap_tails[].

Those shared tail pages were initialized in hugetlb_vmemmap_init(), but bootmem HugeTLB folios are prepared earlier from gather_bootmem_prealloc(). With hugetlb_free_vmemmap=on, prep_and_add_bootmem_folios() can access pageblock flags on bootmem HugeTLB pages whose mirrored tail struct pages already point to the shared tail page. On CONFIG_DEBUG_VM kernels, get_pfnblock_bitmap_bitidx() then dereferences the still-uninitialized shared tail page and can panic during boot.

Initialize zone->vmemmap_tails[] from gather_bootmem_prealloc(), before bootmem HugeTLB folios are processed, and drop the later initialization from hugetlb_vmemmap_init().

This bug only affects CONFIG_DEBUG_VM kernels, where the relevant assertion is evaluated.

Database specific
{
    "cna_assigner":  "Linux",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93232.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
622026e87c4019e609010811757e31193cc23847
Fixed
2ddf429e25cf8415d9c308f07e64012026bd4d77
Fixed
c0caeceb0c3899dc42844d3979093b27d1434108

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93232.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
7.1.0
Fixed
7.2.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93232.json"