Integer underflow in Linux kernel - CVE-2026-89593
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to cause incorrect huge-page reservation accounting.
The vulnerability exists due to an integer underflow in __unmap_hugepage_range() in the hugetlb memory-management component when unmapping a parent range whose folio remains mapped by a child. A local user can unmap the parent range before the child range to cause the reserved count to underflow.
The reserved count is restored when the child unmaps the range.