Deadlock in Linux kernel - CVE-2026-72174
Published: August 16, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a self-deadlock in pagemap_scan_pte_hole() when processing a PAGEMAP_SCAN ioctl with PM_SCAN_WP_MATCHING on a hugetlb VMA that reaches an unpopulated range. A local user can issue a crafted PAGEMAP_SCAN ioctl request to cause a denial of service.
The calling thread may hang in an unkillable state when the scan reaches an unpopulated part of the hugetlb range.