A vulnerability in the Linux kernel's memory management subsystem involving incorrect handling of device-private huge page migration entries can… (CVE-2026-53155)
A vulnerability in the Linux kernel's memory management subsystem involving incorrect handling of device-private huge page migration entries can lead to corrupted reverse mapping (rmap) state. The issue arises from improper use of flags in set_pmd_migration_entry(), causing writable migration entries to be incorrectly installed. This can trigger kernel assertions and potential instability. The vulnerability was introduced by a commit enabling device-private entries and is exposed by a specific selftest scenario.
AI Analysis
Technical Summary
The Linux kernel vulnerability (CVE-2026-53155) involves the mm/huge_memory subsystem where set_pmd_migration_entry() incorrectly uses pmd_write(), pmd_soft_dirty(), and pmd_uffd_wp() to determine writable, softdirty, and uffd-wp states for device-private PMD entries. This leads to writable migration entries being installed when they should not be, corrupting the reverse mapping state. The issue manifests during device-private huge page migration, causing an assertion failure due to inconsistent folio map counts and exclusive flags. The root cause was a commit that extended rmap and migration support for device-private entries but did not adjust flag handling accordingly. The patch corrects flag references and updates logic to only modify A/D flags if the entry is present.
Potential Impact
The vulnerability does not affect confidentiality or integrity directly but can cause kernel memory management corruption leading to system instability or crashes (availability impact). Specifically, it can trigger kernel assertions and folio state inconsistencies during device-private huge page migration, potentially causing denial of service conditions.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official patch or fix links are provided in the available data. Users should monitor Linux kernel updates for a fix addressing this issue. Until then, cautious use of device-private huge page migration features is advised.
A vulnerability in the Linux kernel's memory management subsystem involving incorrect handling of device-private huge page migration entries can… (CVE-2026-53155)
Description
A vulnerability in the Linux kernel's memory management subsystem involving incorrect handling of device-private huge page migration entries can lead to corrupted reverse mapping (rmap) state. The issue arises from improper use of flags in set_pmd_migration_entry(), causing writable migration entries to be incorrectly installed. This can trigger kernel assertions and potential instability. The vulnerability was introduced by a commit enabling device-private entries and is exposed by a specific selftest scenario.
CVSS v3.1
Score 5.5medium
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel vulnerability (CVE-2026-53155) involves the mm/huge_memory subsystem where set_pmd_migration_entry() incorrectly uses pmd_write(), pmd_soft_dirty(), and pmd_uffd_wp() to determine writable, softdirty, and uffd-wp states for device-private PMD entries. This leads to writable migration entries being installed when they should not be, corrupting the reverse mapping state. The issue manifests during device-private huge page migration, causing an assertion failure due to inconsistent folio map counts and exclusive flags. The root cause was a commit that extended rmap and migration support for device-private entries but did not adjust flag handling accordingly. The patch corrects flag references and updates logic to only modify A/D flags if the entry is present.
Potential Impact
The vulnerability does not affect confidentiality or integrity directly but can cause kernel memory management corruption leading to system instability or crashes (availability impact). Specifically, it can trigger kernel assertions and folio state inconsistencies during device-private huge page migration, potentially causing denial of service conditions.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official patch or fix links are provided in the available data. Users should monitor Linux kernel updates for a fix addressing this issue. Until then, cautious use of device-private huge page migration features is advised.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-7xgx-c4jr-vfq9
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-53155"]
- Ecosystems
- []
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6a4e4ef2c9d9e3dbe328a42d
Added to database: 07/08/2026, 13:21:54 UTC
Last enriched: 07/08/2026, 13:43:04 UTC
Last updated: 07/31/2026, 19:24:47 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.