In the Linux kernel, the following vulnerability has been resolved: mm: fix incorrect flush address in direct page table reclaim When zap_pte_range… (CVE-2026-74674)
A vulnerability in the Linux kernel's memory management subsystem was fixed involving an incorrect flush address used during direct page table reclaim. The flaw caused the kernel to flush the wrong address in the translation lookaside buffer (TLB), potentially allowing CPUs to cache references to freed page tables. This could lead to rare segmentation faults or speculative execution issues on some architectures. The issue is mitigated on many x86 systems due to how TLB flush instructions behave, but AMD systems and Intel systems using INVPCID are more susceptible. No known exploits are reported, and no CVSS score is assigned.
AI Analysis
Technical Summary
The Linux kernel vulnerability CVE-2026-74674 involves an incorrect address used in the zap_pte_range function when reclaiming page tables. Specifically, the pte_free_tlb call flushes the TLB at an address one past the end of the page table range, which is incorrect. This can cause CPUs to retain cached references to freed page tables, potentially leading to segmentation faults or speculative execution hazards. The impact varies by architecture: on x86 systems without KPTI, the flush instruction (INVLPG) flushes all paging-structure caches, mitigating the issue; however, on AMD systems and Intel systems using INVPCID, the flush only affects the target address, increasing risk. The flaw was fixed by correcting the flush address to ensure proper TLB invalidation. The complexity of the zap_pte_range control flow contributed to the bug. This vulnerability may explain certain observed crashes in software like ripgrep. No active exploitation is known.
Potential Impact
If triggered, the vulnerability can cause CPUs to cache stale references to freed page tables, which may result in segmentation faults or speculative execution of invalid memory references. On some architectures, this could lead to system instability or security risks related to speculative execution. However, on many x86 systems, the impact is mitigated by the behavior of the INVLPG instruction. AMD systems and Intel systems using INVPCID are more vulnerable. No known exploits in the wild have been reported.
Mitigation Recommendations
A fix for this vulnerability has been implemented in the Linux kernel. Users and administrators should apply the official kernel updates that include the corrected flush address in zap_pte_range to ensure proper TLB invalidation. Patch status is not explicitly confirmed in the provided data; therefore, check the vendor or kernel mailing list advisories for the exact fixed kernel versions and apply updates accordingly.
In the Linux kernel, the following vulnerability has been resolved: mm: fix incorrect flush address in direct page table reclaim When zap_pte_range… (CVE-2026-74674)
Description
A vulnerability in the Linux kernel's memory management subsystem was fixed involving an incorrect flush address used during direct page table reclaim. The flaw caused the kernel to flush the wrong address in the translation lookaside buffer (TLB), potentially allowing CPUs to cache references to freed page tables. This could lead to rare segmentation faults or speculative execution issues on some architectures. The issue is mitigated on many x86 systems due to how TLB flush instructions behave, but AMD systems and Intel systems using INVPCID are more susceptible. No known exploits are reported, and no CVSS score is assigned.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel vulnerability CVE-2026-74674 involves an incorrect address used in the zap_pte_range function when reclaiming page tables. Specifically, the pte_free_tlb call flushes the TLB at an address one past the end of the page table range, which is incorrect. This can cause CPUs to retain cached references to freed page tables, potentially leading to segmentation faults or speculative execution hazards. The impact varies by architecture: on x86 systems without KPTI, the flush instruction (INVLPG) flushes all paging-structure caches, mitigating the issue; however, on AMD systems and Intel systems using INVPCID, the flush only affects the target address, increasing risk. The flaw was fixed by correcting the flush address to ensure proper TLB invalidation. The complexity of the zap_pte_range control flow contributed to the bug. This vulnerability may explain certain observed crashes in software like ripgrep. No active exploitation is known.
Potential Impact
If triggered, the vulnerability can cause CPUs to cache stale references to freed page tables, which may result in segmentation faults or speculative execution of invalid memory references. On some architectures, this could lead to system instability or security risks related to speculative execution. However, on many x86 systems, the impact is mitigated by the behavior of the INVLPG instruction. AMD systems and Intel systems using INVPCID are more vulnerable. No known exploits in the wild have been reported.
Mitigation Recommendations
A fix for this vulnerability has been implemented in the Linux kernel. Users and administrators should apply the official kernel updates that include the corrected flush address in zap_pte_range to ensure proper TLB invalidation. Patch status is not explicitly confirmed in the provided data; therefore, check the vendor or kernel mailing list advisories for the exact fixed kernel versions and apply updates accordingly.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-h8c5-5mw2-4jr4
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-74674"]
- Ecosystems
- []
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a8a27f1acd9273b499bc7bc
Added to database: 08/22/2026, 22:51:29 UTC
Last enriched: 08/23/2026, 00:09:32 UTC
Last updated: 08/23/2026, 01:12:09 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.