Always-Incorrect Control Flow Implementation in Linux kernel - CVE-2026-64514
Published: July 27, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper handling of non-present page table entries in userfaultfd_must_wait() and userfaultfd_huge_must_wait() when checking writability during userfaultfd write-protect fault handling. A local user can trigger a fault involving a swap or migration entry to cause a denial of service.
In the worst case, the affected thread may remain asleep waiting for a wake event that never arrives.
Affected software
How to mitigate CVE-2026-64514
External References
- https://git.kernel.org/stable/c/29e6f952c5fb7dc1d6b90fe5b7f36063d44ddae0
- https://git.kernel.org/stable/c/5f4dbdb0a87596214076b20b94f2b71b522170b3
- https://git.kernel.org/stable/c/60d696a037eeeedfb57756dfe7ec08a1587c8631
- https://git.kernel.org/stable/c/710183888174639a15fcec16cd1af766b8480bb7
- https://git.kernel.org/stable/c/8e80af52db652fbc41320eee45a4f73bc029faf2
- https://git.kernel.org/stable/c/a5700a4c1c9099ac2ac73fe8a09cf059972e0d2f
- https://git.kernel.org/stable/c/a6e9a4939e359599701b1da351e84f72e021443a
- https://git.kernel.org/stable/c/d4026417e8184d13850a0bad4d96ceb6ed9f7152