Deadlock in Linux kernel - CVE-2026-72174

 

Deadlock in Linux kernel - CVE-2026-72174

Published: August 16, 2026


Vulnerability identifier: #VU143419
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-72174
CWE-ID: CWE-833
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a self-deadlock in pagemap_scan_pte_hole() when processing a PAGEMAP_SCAN ioctl with PM_SCAN_WP_MATCHING on a hugetlb VMA that reaches an unpopulated range. A local user can issue a crafted PAGEMAP_SCAN ioctl request to cause a denial of service.

The calling thread may hang in an unkillable state when the scan reaches an unpopulated part of the hugetlb range.


Affected software

Linux kernel

How to mitigate CVE-2026-72174

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins