Linux hwe edge: In the Linux kernel, the following vulnerability has been resolved: Revert "mm/hugetlbfs: update hugetlbfs to use mmap_prepare" This reverts commit… (CVE-2026-46318)
A vulnerability in the Linux kernel related to the hugetlbfs subsystem was resolved by reverting a problematic patch that mishandled lock allocation during mmap_prepare. The issue could cause a lock leak if allocation failed after mmap_prepare was called. This vulnerability affects various Linux kernel versions prior to specific 7.0.0-xx releases. The vulnerability has a CVSS score of 5.5 with an impact on availability. A patch is available and included in updated Linux kernel packages for Ubuntu 26.04 LTS and related variants.
AI Analysis
Technical Summary
The vulnerability (CVE-2026-46318) in the Linux kernel's hugetlbfs subsystem was introduced by a patch that updated hugetlbfs to use mmap_prepare. This patch incorrectly handled the allocation of the hugetlb VMA lock during mmap_prepare, potentially causing a lock leak if allocation failed after mmap_prepare was called. The fix involved reverting the problematic patch to allow a proper rework of the implementation. The vulnerability affects multiple Linux kernel versions prior to 7.0.0-28.28 and related builds. The issue does not risk merge conflicts causing similar problems due to VMA_DONTEXPAND_BIT being set for hugetlb mappings. The vulnerability has a CVSS 3.1 score of 5.5 (AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H), indicating a local attacker with low privileges could cause an availability impact. The vendor advisory confirms a patch is available and recommends updating to fixed package versions.
Potential Impact
This vulnerability can cause a lock leak in the hugetlbfs subsystem of the Linux kernel, potentially impacting system availability. There is no confidentiality or integrity impact reported. The attack vector is local with low complexity and requires low privileges. No known exploits in the wild have been reported. The vulnerability affects system stability and could lead to denial of service conditions.
Mitigation Recommendations
A patch is available and has been released in updated Linux kernel packages for Ubuntu 26.04 LTS and related variants. Users should update their systems to the fixed package versions listed in the vendor advisory and reboot to apply the changes. Due to an ABI change, recompilation and reinstallation of third-party kernel modules may be required. Follow the vendor's update instructions carefully to ensure full remediation.
Linux hwe edge: In the Linux kernel, the following vulnerability has been resolved: Revert "mm/hugetlbfs: update hugetlbfs to use mmap_prepare" This reverts commit… (CVE-2026-46318)
Description
A vulnerability in the Linux kernel related to the hugetlbfs subsystem was resolved by reverting a problematic patch that mishandled lock allocation during mmap_prepare. The issue could cause a lock leak if allocation failed after mmap_prepare was called. This vulnerability affects various Linux kernel versions prior to specific 7.0.0-xx releases. The vulnerability has a CVSS score of 5.5 with an impact on availability. A patch is available and included in updated Linux kernel packages for Ubuntu 26.04 LTS and related variants.
CVSS v3.1
Score 5.5medium
Affected software
pkg:deb/ubuntu/[email protected]~16.04.1?arch=source&distro=xenialpkg:deb/ubuntu/[email protected]?arch=source&distro=bionicpkg:deb/ubuntu/[email protected]?arch=source&distro=bionicpkg:deb/ubuntu/[email protected]?arch=source&distro=bionicpkg:deb/ubuntu/[email protected]?arch=source&distro=bionicpkg:deb/ubuntu/[email protected]~18.04.2?arch=source&distro=bionicpkg:deb/ubuntu/[email protected]?arch=source&distro=bionicpkg:deb/ubuntu/[email protected]~18.04.1?arch=source&distro=bionicpkg:deb/ubuntu/[email protected]?arch=source&distro=bionicpkg:deb/ubuntu/[email protected]~18.04.1?arch=source&distro=bionicpkg:deb/ubuntu/[email protected]~18.04.1?arch=source&distro=bionicpkg:deb/ubuntu/[email protected]?arch=source&distro=bionicpkg:deb/ubuntu/[email protected]~18.04.2?arch=source&distro=bionicpkg:deb/ubuntu/[email protected]?arch=source&distro=bionicpkg:deb/ubuntu/[email protected]?arch=source&distro=bionicpkg:deb/ubuntu/[email protected]~18.04.1?arch=source&distro=bionicpkg:deb/ubuntu/[email protected]~20.04.1?arch=source&distro=focalpkg:deb/ubuntu/[email protected]~20.04.1?arch=source&distro=focalpkg:deb/ubuntu/[email protected]~20.04.1?arch=source&distro=focalpkg:deb/ubuntu/[email protected]~20.04.2?arch=source&distro=focalpkg:deb/ubuntu/[email protected]~20.04.1?arch=source&distro=focalpkg:deb/ubuntu/[email protected]~20.04.1?arch=source&distro=focalpkg:deb/ubuntu/[email protected]+cvm1.1?arch=source&distro=focalpkg:deb/ubuntu/[email protected]~20.04.3?arch=source&distro=focalpkg:deb/ubuntu/[email protected]~20.04.1?arch=source&distro=focalpkg:deb/ubuntu/[email protected]?arch=source&distro=focalpkg:deb/ubuntu/[email protected]?arch=source&distro=focalpkg:deb/ubuntu/[email protected]~20.04.1?arch=source&distro=focalpkg:deb/ubuntu/[email protected]?arch=source&distro=focalpkg:deb/ubuntu/[email protected]~20.04.1?arch=source&distro=focalpkg:deb/ubuntu/[email protected]~20.04.1?arch=source&distro=focalpkg:deb/ubuntu/[email protected]~20.04.1?arch=source&distro=focalpkg:deb/ubuntu/[email protected]~20.04.1?arch=source&distro=focalpkg:deb/ubuntu/[email protected]?arch=source&distro=focalpkg:deb/ubuntu/[email protected]?arch=source&distro=focalpkg:deb/ubuntu/[email protected]?arch=source&distro=focalpkg:deb/ubuntu/[email protected]?arch=source&distro=focalpkg:deb/ubuntu/[email protected]?arch=source&distro=focalpkg:deb/ubuntu/[email protected]~20.04.1?arch=source&distro=focalpkg:deb/ubuntu/[email protected]~20.04.1?arch=source&distro=focalpkg:deb/ubuntu/[email protected]~20.04.1?arch=source&distro=focalpkg:deb/ubuntu/[email protected]?arch=source&distro=focalpkg:deb/ubuntu/[email protected]?arch=source&distro=focalpkg:deb/ubuntu/[email protected]?arch=source&distro=focalpkg:deb/ubuntu/[email protected]~20.04.1?arch=source&distro=focalpkg:deb/ubuntu/[email protected]~22.04.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.2?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.2.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.1.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]?arch=source&distro=jammypkg:deb/ubuntu/[email protected]?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]?arch=source&distro=jammypkg:deb/ubuntu/[email protected]?arch=source&distro=jammypkg:deb/ubuntu/[email protected]?arch=source&distro=jammypkg:deb/ubuntu/[email protected]?arch=source&distro=jammypkg:deb/ubuntu/[email protected]?arch=source&distro=jammypkg:deb/ubuntu/[email protected]?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]?arch=source&distro=jammypkg:deb/ubuntu/[email protected]?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~24.04.1?arch=source&distro=noblepkg:deb/ubuntu/[email protected]~24.04.1?arch=source&distro=noblepkg:deb/ubuntu/[email protected]~24.04.1?arch=source&distro=noblepkg:deb/ubuntu/[email protected]~24.04.1?arch=source&distro=noblepkg:deb/ubuntu/[email protected]~24.04.1?arch=source&distro=noblepkg:deb/ubuntu/[email protected]~24.04.1?arch=source&distro=noblepkg:deb/ubuntu/[email protected]~24.04.1?arch=source&distro=noblepkg:deb/ubuntu/[email protected]~24.04.1?arch=source&distro=noblepkg:deb/ubuntu/[email protected]?arch=source&distro=noblepkg:deb/ubuntu/[email protected]~24.04.1?arch=source&distro=noblepkg:deb/ubuntu/[email protected]?arch=source&distro=noblepkg:deb/ubuntu/[email protected]?arch=source&distro=noblepkg:deb/ubuntu/[email protected]?arch=source&distro=noblepkg:deb/ubuntu/[email protected]~24.04.1?arch=source&distro=noblepkg:deb/ubuntu/[email protected]?arch=source&distro=noblepkg:deb/ubuntu/[email protected]?arch=source&distro=noblepkg:deb/ubuntu/[email protected]?arch=source&distro=noblepkg:deb/ubuntu/[email protected]~24.04.1?arch=source&distro=noblepkg:deb/ubuntu/[email protected]?arch=source&distro=bluefield/noblepkg:deb/ubuntu/[email protected]~24.04.1?arch=source&distro=realtime/noblepkg:deb/ubuntu/[email protected]?arch=source&distro=resolutepkg:deb/ubuntu/[email protected]?arch=source&distro=resolutepkg:deb/ubuntu/[email protected]?arch=source&distro=resolutepkg:deb/ubuntu/[email protected]?arch=source&distro=resolutepkg:deb/ubuntu/[email protected]?arch=source&distro=resolutepkg:deb/ubuntu/[email protected]?arch=source&distro=resolutepkg:deb/ubuntu/[email protected]?arch=source&distro=resolutepkg:deb/ubuntu/[email protected]?arch=source&distro=resolutepkg:deb/ubuntu/[email protected]?arch=source&distro=resolutepkg:deb/ubuntu/[email protected]?arch=source&distro=resolutepkg:deb/ubuntu/[email protected]?arch=source&distro=resolutepkg:deb/ubuntu/[email protected]?arch=source&distro=resolutepkg:deb/ubuntu/[email protected]?arch=source&distro=resolutepkg:deb/ubuntu/[email protected]?arch=source&distro=resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability (CVE-2026-46318) in the Linux kernel's hugetlbfs subsystem was introduced by a patch that updated hugetlbfs to use mmap_prepare. This patch incorrectly handled the allocation of the hugetlb VMA lock during mmap_prepare, potentially causing a lock leak if allocation failed after mmap_prepare was called. The fix involved reverting the problematic patch to allow a proper rework of the implementation. The vulnerability affects multiple Linux kernel versions prior to 7.0.0-28.28 and related builds. The issue does not risk merge conflicts causing similar problems due to VMA_DONTEXPAND_BIT being set for hugetlb mappings. The vulnerability has a CVSS 3.1 score of 5.5 (AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H), indicating a local attacker with low privileges could cause an availability impact. The vendor advisory confirms a patch is available and recommends updating to fixed package versions.
Potential Impact
This vulnerability can cause a lock leak in the hugetlbfs subsystem of the Linux kernel, potentially impacting system availability. There is no confidentiality or integrity impact reported. The attack vector is local with low complexity and requires low privileges. No known exploits in the wild have been reported. The vulnerability affects system stability and could lead to denial of service conditions.
Mitigation Recommendations
A patch is available and has been released in updated Linux kernel packages for Ubuntu 26.04 LTS and related variants. Users should update their systems to the fixed package versions listed in the vendor advisory and reboot to apply the changes. Due to an ABI change, recompilation and reinstallation of third-party kernel modules may be required. Follow the vendor's update instructions carefully to ensure full remediation.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-46318
- Osv Schema Version
- 1.7.0
- Ecosystems
- ["Ubuntu:16.04:LTS","Ubuntu:18.04:LTS","Ubuntu:20.04:LTS","Ubuntu:22.04:LTS","Ubuntu:24.04:LTS","Ubuntu:Nvidia-BlueField:24.04:LTS","Ubuntu:Pro:Realtime:24.04:LTS","Ubuntu:26.04:LTS"]
- Cvss Version
- 4.0
Threat ID: 6a5a018691ae9bcd3f8049d5
Added to database: 07/17/2026, 10:18:46 UTC
Last enriched: 09/07/2026, 23:52:06 UTC
Last updated: 09/14/2026, 22:01:34 UTC
Views: 20
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.